EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS


The Increasing Danger of Back Doors in Standards and Binary Blobs

Posted in Apple, GNU/Linux, Microsoft, Security at 9:06 am by Dr. Roy Schestowitz

Summary: The risk of back doors in GNU/Linux comes not from source code but from blobs, back room deals, the build process, and bogus standards with weaknesses cleverly shoehorned into them

IT HAS BEEN a while since we last wrote about Mr. Srinivasan from Microsoft-Novell. Suffice to say, Novell did a lot for Microsoft and some former staff of Novell continues to work for Microsoft (either directly or indirectly). One gift from Novell to Microsoft was OOXML inside FOSS/OOo. Another was Mono and let’s not forget intrusion into Linux itself. Robert Pogson goes as far as saying that Microsoft “Hacked Linux!”

“My configuration,” Pogson argues, “has CONFIG_HYPERV not set. The code in question is Copyright 2010, Novell (mshyperv.c), and Copyright 2009, M$ (vmbus_drv.c). K. Y. Srinivasan is listed as one of the authours on both. I’m not about to run that other OS on Beast, but thank you, Thomas Gleixner, for fixing things.” (see this link)

Performance issues overlook the much bigger problem — a problem which we addressed several times before. We already know that the NSA is pursuing back doors in Linux [1, 2, 3, 4] and as we pointed out before, the NSA might already have some.

incidentally, as we have shown before, Yahoo was fighting against NSA surveillance in court. When Microsoft took over Yahoo it became apparent that Yahoo stopped fighting and soon became part of PRISM. While some new reports suggest that Yahoo might be ready to escape Microsoft “Yahoo is still in NSA’s pocket though even if they break free of Microsoft,” explains iophk.

Likewise, even if Linux does not engage with Microsoft, the code from Microsoft remains stuck inside Linux and even if there are no back doors in the code itself, this connects to a system, Hyper-V, which is developed by a back doors specialist (Microsoft). There are binary-level back doors from which to access GNU/Linux systems because if the host machine runs Windows, then we already know that the NSA has access. A nearby company that I once visited, UKFast (the UK’s largest ‘cloud’ provider), runs GNU/Linux servers under HyperV, based on what they told me. How insane is that?! GCHO must love it!

Adding to some concerns about back doors, NSA ally and PRISM partner Apple turns out to have hidden a back door. As Think Progress puts it, “Apple quietly released a major update Friday to fix a security glitch in its iOS 7 systems. But independent security experts say the seemingly routine update covers up what arguably could be Apple’s biggest security lapse, exposing iPhone, iPad and iPod Touch users to hackers.”

Whether it’s a back door or just direct access does not matter, but it enables Apple to dance around important questions. It works across several Apple platforms, even desktop platforms [1].

As iophk put it, in relation to this other new article [2] “Potential problems with an official back door in HTTP 2.0, though only in a proposed draft so far. But because of the ways certificates are currently (mis-)managed, this kind of interception of HTTPS is already easy.”

“See one example with four steps,” he added, pointing to [3] from the OpenBSD mailing lists.

It’s not as though GNU/Linux is immune to back doors (Debian has some new security advisories [4,5]), but at least with access to source code the back doors remain very shallow and too risky/difficult for malicious/covert entities to hide. It’s when proprietary software gets added that we lose the ability to ascertain security and privacy.

Related/contextual items from the news:

  1. Apple SSL Vulnerability Affects OSX Too
  2. No, I Don’t Trust You! — One of the Most Alarming Internet Proposals I’ve Ever Seen

    If you care about Internet security, especially what we call “end-to-end” security free from easy snooping by ISPs, carriers, or other intermediaries, heads up! You’ll want to pay attention to this.

    You’d think that with so many concerns these days about whether the likes of AT&T, Verizon, and other telecom companies can be trusted not to turn our data over to third parties whom we haven’t authorized, that a plan to formalize a mechanism for ISP and other “man-in-the-middle” snooping would be laughed off the Net.

    But apparently the authors of IETF (Internet Engineering Task Force) Internet-Draft “Explicit Trusted Proxy in HTTP/2.0″ (14 Feb 2014) haven’t gotten the message.

    What they propose for the new HTTP/2.0 protocol is nothing short of officially sanctioned snooping.

  3. relayd SSL interception

    This mail includes a quite detailed explanation of the attached diff that adds support for SSL Interception (“SSL-MITM”) to relayd. If you don’t want to read the story, just skip to the configuration example and diff below.

  4. Debian: 2862-1: chromium-browser: Multiple vulnerabilities
  5. Debian: 2861-1: file: denial of service
Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New

  1. The Serious Implication of Controversial FTI Consulting Contract: Every Press Article About EPO Could Have Been Paid for by EPO

    With nearly one million dollars dedicated in just one single year to reputation laundering, one can imagine that a lot of media coverage won't be objective, or just be synthetic EPO promotion, seeded by the EPO or its peripheral PR agents

  2. EPO: We Have Always Been at War With Europe (or Europeans)

    The European Patent Office (EPO) with its dubious attacks on free speech inside Europe further unveiled for the European public to see (as well as the international community, which oughtn't show any respect to the EPO, a de facto tyranny at the heart of Europe)

  3. What Everyone Needs to Know About the EPO's New War on Journalism

    A detailed list of facts or observations regarding the EPO's newfound love for censorship, even imposed on outside entities, including bloggers (part one of several to come)

  4. EPO Did Not Want to Take Down One Techrights Article, It Wanted to Take Down Many Articles Using Intimidation, SLAPPing, and Psychological Manipulation Late on a Friday Night

    Recalling the dirty tactics by which the European Patent Office sought to remove criticism of its dirty secret deals with large corporations, for whom it made available and was increasingly offering preferential treatment

  5. The European Private Office: What Was Once a Public Service is Now Crony Capitalism With Private Contractors

    The increasing privatisation of the European Patent Office (EPO), resembling what happens in the UK to the NHS, shows that the real goal is to crush the quality of the service and instead serve a bunch of rich and powerful interests, in defiance of the original goals of this well-funded (by taxpayers) organisation

  6. Microsoft Once Again Disregards People's Settings and Abuses Them, Again Pretends It's Just an Accident

    A conceited corporation, Microsoft, shows not only that it exploits its botnet to forcibly download massive binaries without consent but also that it vainly overrides people's privacy settings to spy on these people, sometimes with help from malicious hardware vendors such as Dell or Lenovo

  7. When the EPO Liaised With Capone (Literally) to Silence Bloggers, Delete Articles

    A dissection of the EPO's current media strategy, which involves not only funneling money into the media but also actively silencing opposing views

  8. Blogger Who Wrote About the EPO's Abuses Retires

    Bloggers' independent rebuttal capability against a media apparatus that is deep in the EPO's pocket is greatly diminished as Jeremy Phillips suddenly retires

  9. Leaked: EPO Award of €880,000 “in Order to Address the Media Presence of the EPO” (Reputation Laundering)

    The European Patent Office, a public body, wastes extravagant amounts of money on public relations (for 'damage control', like FIFA's) in an effort to undermine critics, not only among staff (internally) but also among the media (externally)

  10. Links 27/11/2015: KDE Plasma 5.5 Plans, Oracle Linux 7.2

    Links for the day

  11. Documents Needed: Contract or Information About EPO PR/Media Campaign to Mislead the World

    Rumour that the EPO spends almost as much as a million US dollars “with some selected press agencies to refurbish the image of the EPO”

  12. Guest Post: The EPO, EPC, Unitary Patent and the Money Issue

    Remarks on the Unitary Patent (UP) and the lesser-known aspects of the EPO and EPC, where the “real issue is money, about which very little is discussed in public...”

  13. Saving the Integrity of the European Patent Office (EPO)

    Some timely perspective on what's needed at the European Patent Office, which was detabilised by 'virtue' of making tyrants its official figureheads

  14. A Call for Bloggers and Journalists: Did EPO Intimidate and Threaten You Too? Please Speak Out.

    An effort to discover just how many people out there have been subjected to censorship and/or self-censorship by EPO aggression against the media

  15. European Patent Office (EPO) a “Kingdom Above the EU Countries, a Tyranny With ZERO Accountability”

    Criticism of the EPO's thuggish behaviour and endless efforts to crush dissenting voices by all means available, even when these means are in clear violation of international or European laws

  16. Links 26/11/2015: The $5 Raspberry Pi Zero, Running Sans Systemd Gets Hard

    Links for the day

  17. EPO Management Needs to Finally Recognise That It Itself is the Issue, Not the Staff or the Unions

    A showing of dissent even from the representatives whom the EPO tightly controls and why the latest union-busting goes a lot further than most people realise

  18. Even the EPO Central Staff Committee is Unhappy With EPO Management

    The questions asked by the Central Staff Committee shared for the public to see that not only a single union is concerned about the management's behaviour

  19. The Broken Window Economics of Patent Trolls Are Already Coming to Europe

    The plague which is widely known as patent trolls (non-practicing entities that prey on practicing companies) is being spread to Europe, owing in part to misguided policies and patent maximalists

  20. Debunking the EPO's Latest Marketing Nonsense From Les Échos and More on Benoît Battistelli's Nastygram to French Politician

    Our detailed remarks about French brainwash from the EPO's media partner (with Benoît Battistelli extensively quoted) and the concerns increasingly raised by French politicians, who urge for national or even continental intervention

  21. The Sun King Delusion: The Views of Techrights Are Just a Mirror of EPO Staff Unions

    Tackling some emerging spin we have seen coming from Battistelli's private letters -- spin which strives to project the views of Techrights onto staff unions and why it's very hypocritical a form of spin

  22. Links 25/11/2015: Webconverger 33.1, Netrunner 17 Released

    Links for the day

  23. United They Stand: FFPE-EPO Supports Suspended Staff Representatives From SUEPO

    An obscure union from the Dutch side of things at the EPO is expressing support for the suspended colleagues from SUEPO (more German than Dutch)

  24. Censoring WIPR Article About Censorship by EPO

    A testament to how terrified journalists have become when it comes to EPO coverage, to the point of deleting entire paragraphs

  25. Censorship at the EPO Escalates: Now We Have Threats to Sue Publishers

    Having already blocked Techrights, the EPO's management proceeds to further suppressions of speech, impeding its staff's access to independently-distributed information (neither ordinary staff nor management)

  26. Response to Bogus Accusations That EPO Staff Protests Are Really an Attempt to Derail UPC

    Common myths about staff protests in the European Patent Office (EPO) debunked, with some additional background and general perspective on recent events, the unitary patent (UPC) and so on

  27. New Heise Article Makes It Clear That 'Nazi'-Themed Accusations Against the Suspended Board Judge Were Insufficiently Substantiated

    The personal attacks on a judge who was illegally suspended (a so-called 'house ban') increasingly look like the management's own campaign of defamation, mostly intended to marginalise and punish a judge who spoke about serious charges against VP4 (Željko Topić)

  28. Links 24/11/2015: Asus Chromebit CS10, Second Linux 4.4 RC

    Links for the day

  29. European Central Bank Staff Committee Adds to Growing Pressure on Abusive EPO Management

    The staff representatives of the European Central Bank E-mail their colleagues -- with European Central Bank managers' approval -- regarding the European Patent Office and its attacks on staff unions

  30. Gross Violation of Workers' Rights in EPO: Denial of Christmas Vacation/Leave for Slower Workers

    A look at an E-mail from within the EPO which shows how Christmas is used to squeeze staff, urging them to work even faster (despite speed gains) or lose their Christmas leave


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time


Recent Posts