Bonum Certa Men Certa

Panic Over Transport Layer Security (TLS) Flaw Which is Already Patched

Bad news sells better

Summary: What the media is not really telling us about the GnuTLS vulnerability

The corporate press has shown its ignorance by characterising GNU as "Linux" and describing an already-patched flaw as the worst thing since proprietary software. Some went as far as suggesting that the NSA was behind it [1] and Muktware rebutted [2] the seminal article [3] which started a lot of the panic (at the time of writing there are dozens of articles about this, but we don't need to feed them with links). What we have here is another case of Dan Goodin creating panic in the Microsoft-friendly Ars, just as he had done when he worked for the Microsoft-friendly The Register. The only shocking thing is the amount of press coverage this received. PGP/GPG, OpenSSH, OpenSSL etc. were previously named here for flaws that had been found (in the context of Red Hat and the NSA [1, 2, 3]). These are not so uncommon. One just needs to keep up to date (patched) -- one that which Apple's customers cannot do. They can't even write their own patches.



Related/contextual items from the news:


  1. NSA did it again? This time GnuTLS fails to check malicious certificates


  2. Yes there was a security hole in Linux, but Red Hat already fixed it
    Originally reported by Ars Technica, the fix was available by the time the general public was made aware of it. It’s actually fairly similar to a certain security hole that lived for a year and could have allowed for exploits to be used in the wild.


  3. Critical crypto bug leaves Linux, hundreds of apps open to eavesdropping
    The bug in the GnuTLS library makes it trivial for attackers to bypass secure sockets layer (SSL) and Transport Layer Security (TLS) protections available on websites that depend on the open source package. Initial estimates included in Internet discussions such as this one indicate that more than 200 different operating systems or applications rely on GnuTLS to implement crucial SSL and TLS operations, but it wouldn't be surprising if the actual number is much higher. Web applications, e-mail programs, and other code that use the library are vulnerable to exploits that allow attackers monitoring connections to silently decode encrypted traffic passing between end users and servers.

Recent Techrights' Posts

statCounter: New Record Highs for GNU/Linux in Its Birthplace
So Microsoft is in a tough place
Links 02/02/2025: Website Revamps, Blogging About Blogging, and Self-Harming Tariff Wars (Higher Prices)
Links for the day
 
statCounter's Numbers Make Sense Given Microsoft's Falling Windows/Client Revenue
There are already articles (some last week) saying that XBox should just be ended
About 1 in 10 Laptops/Desktops in Venezuela and Cuba Uses GNU/Linux
statCounter says GNU/Linux now exceeds 10% in Cuba
At Microsoft, Promoting Back Doors, Proprietary Lock-in and Mass Surveillance Under the Guise of Diversity ("Microsoft Philanthropy Team")
Microsoft staff enters NGOs to lobby for Microsoft and sell for Microsoft
statCounter: Android Share in Operating Systems, Per Country
Towards the bottom there are poorer countries
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, February 02, 2025
IRC logs for Sunday, February 02, 2025
Copyleft is the Way to Go (Unless You're an Unpaid Volunteer of GAFAM)
The GPL 'family' of licences is very old and those licences were last revised in 2007
statCounter: In Canada, New Lows for Windows and Bing is Perishing
Windows has fallen to about 60% in desktops/laptops
Yandex Has Nearly Caught Up With Microsoft Internationally, Bing Falls to Pre-LLM Hype Levels
Of course we've been saying all along that this would happen
Germany's 'Share' of GNU/Linux Rises to All-Time High Based on This Surveyor
Many public services have made the move to GNU/Linux
Microsoft Uses the Mindset of Drug Dealers and Pays 'News' Sites to Sell 'Drugs'
Microsoft pays publishers to spread the illusion that the only viable option for developers and non-developers is "drugs" like Visual Studio and Microsoft Office, respectively
Windows Going South in the "Global South" (Africa and More)
Microsoft has long been shameless about using the tactics of drug dealers
Sharp Drop for Microsoft Windows This Month, Based on statCounter
Facebook meanwhile censors GNU/Linux advocacy
3 Months Ago Lupa Saw 4,200+ Unique Gemini Capsules; Now It Sees Nearly 4,400
many bots target our capsule (129,152 Gemini requests yesterday alone)
Gemini Links 02/02/2025: Geminispace Targeted by Chatbots, Gabbro 0.1.1 Released
Links for the day
Oracle's Debt Soars to 100 Billion Dollars (12 Billion Added in Just 9 Months!) While Larry Ellison Backs Fascism for Bailouts, Graft, and "Contracts"
Including attempts to gain control of TikTok, owing to the corrupt dictator long promoted by Larry Ellison (also via Twitter takeover)
Links 02/02/2025: Union-Busting and Censorship by Executions
Links for the day
Gemini Links 02/02/2025: Limits Pushing, Free Software Absolutism, and Why Gemini Matters
Links for the day
Slopwatch: BetaNews and linuxsecurity.com Have Just Published More Fake 'Articles' About "Linux"
There's probably more "Linux" slop out there, but we do our best to identify it on a daily basis
Richard Stallman Has Another Talk in India Tomorrow, at Least Fourth India Talks in Recent Days
In the past month he has given at least half a dozen talks
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, February 01, 2025
IRC logs for Saturday, February 01, 2025
Links 01/02/2025: Chinese and American Censorship, Cloud-[sic]Native Targeted by Software Patents
Links for the day
Links 01/02/2025: Belated Happy New Year 2025 and Gabbro 0.1.2
Links for the day
Hiring for Tech Roles Based on Perceived Loyalty is No Better Than Hiring to Meet Diversity Quotas
What we're seeing right now is a national security disaster and it is almost purely about technology
S.E.O. SPAM by Serial Sloppers With L.L.M. Garbage is Hurting Linux
We continue to run Slopwatch
Links 01/02/2025: Administrative Chaos and Aviation Disasters Persist
Links for the day
Arrested: Albanian Outreachy whistleblowers, Sonny Piers GNOME & Debian connections
Reprinted with permission from Daniel Pocock
Links 1/2/2025: LLM Hype Revisited, Linuxwashing by Oumi
Links for the day
Growing Evidence That the Patent Industry Has Become a Major Scam
Seeing that the patent "industry" has turned to serious crimes (sometimes to cover up corruption) and seeing that the net negative is clearer for all to see, people who argue for abolition of all patents will have a field day
IBM Says That Half of Its "Assets" is Basically Pure Fiction ("Goodwill")
It times get tough, IBM can sell "Goodwill" at the local pawn shop and pay back the lenders, right?
Planet Ubuntu Overrun by LLM Slop? Faizul "Piju" 9M2PJU Seems to be Publishing Fake Articles About "Linux"...
Maybe it is "assisted" by LLM slop, but slop is slop and it introduces many problems
Gemini Links 01/02/2025: LLMs, Analog Computer, and BorgBackup
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, January 31, 2025
IRC logs for Friday, January 31, 2025