EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

03.05.14

Panic Over Transport Layer Security (TLS) Flaw Which is Already Patched

Posted in GNU/Linux, Security at 12:44 pm by Dr. Roy Schestowitz

Bad news sells better

Summary: What the media is not really telling us about the GnuTLS vulnerability

The corporate press has shown its ignorance by characterising GNU as “Linux” and describing an already-patched flaw as the worst thing since proprietary software. Some went as far as suggesting that the NSA was behind it [1] and Muktware rebutted [2] the seminal article [3] which started a lot of the panic (at the time of writing there are dozens of articles about this, but we don’t need to feed them with links). What we have here is another case of Dan Goodin creating panic in the Microsoft-friendly Ars, just as he had done when he worked for the Microsoft-friendly The Register. The only shocking thing is the amount of press coverage this received. PGP/GPG, OpenSSH, OpenSSL etc. were previously named here for flaws that had been found (in the context of Red Hat and the NSA [1, 2, 3]). These are not so uncommon. One just needs to keep up to date (patched) — one that which Apple’s customers cannot do. They can’t even write their own patches.

Related/contextual items from the news:

  1. NSA did it again? This time GnuTLS fails to check malicious certificates
  2. Yes there was a security hole in Linux, but Red Hat already fixed it

    Originally reported by Ars Technica, the fix was available by the time the general public was made aware of it. It’s actually fairly similar to a certain security hole that lived for a year and could have allowed for exploits to be used in the wild.

  3. Critical crypto bug leaves Linux, hundreds of apps open to eavesdropping

    The bug in the GnuTLS library makes it trivial for attackers to bypass secure sockets layer (SSL) and Transport Layer Security (TLS) protections available on websites that depend on the open source package. Initial estimates included in Internet discussions such as this one indicate that more than 200 different operating systems or applications rely on GnuTLS to implement crucial SSL and TLS operations, but it wouldn’t be surprising if the actual number is much higher. Web applications, e-mail programs, and other code that use the library are vulnerable to exploits that allow attackers monitoring connections to silently decode encrypted traffic passing between end users and servers.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 22/8/2014: Linux Foundation LFCS, LFCE

    Links for the day



  2. UPS Burned by Microsoft Windows, Gives Away Massive Number of Credit Card Details

    UPS is the latest victim of Microsoft's shoddy back door with software on top of it (Windows); attempts to blame FOSS for data compromise actually divert attention from the real culprit, which is proprietary software



  3. Microsoft's Funding of ALEC and Other Systemic Corruption

    Microsoft role in writing of laws by proxy, via groups such as ALEC



  4. Microsoft is Still Preying on British Taxpayers, Playing Politics

    Some news from the UK showing how Microsoft uses politics to extract money out of taxpayers, irrespective of their preferences



  5. Microsoft's Patent Troll Intellectual Ventures is Collapsing as 20% of Staff Laid Off

    More good news regarding the demise of patents as Microsoft's leading patent proxy is collapsing more rapidly than anyone ever imagined and software patents too are collectively doubted



  6. Links 21/8/2014: Conferences of Linux Foundation, Elephone Emerges

    Links for the day



  7. Links 20/8/2014: Linux Event, GNOME Milestone

    Links for the day



  8. Corruption Watch: Microsoft Lobbying Designed to Kill Chile's Free Software Policy and Promote Microsoft With Subsidies, More Dirty Tricks Emerge in Munich

    icrosoft is systematically attacking migrations to GNU, Linux and Free software, using dirty tricks, as always



  9. Vista 8 Such a Disaster That Even Microsoft Cannot Cope With It, Vapourware Tactics Start Early

    Microsoft's Windows-powered services are failing and Windows gets bricked by Microsoft patches, whereupon we are seeing yet more of Microsoft's vapourware tactics (focusing in imaginary, non-existent versions of Windows)



  10. On BlackBerry and Other Patent Trolls

    A roundup regarding patent trolls, starting with the bigger and latest joiner, BlackBerry's new patents apparatus



  11. Links 19/8/2014: Humble Jumbo Bundle 2 Betrayal, Mercedes-Benz Runs GNU/Linux

    Links for the day



  12. BlackBerry -- Like Microsoft Nokia -- Could be the Next Patent Proxy Troll

    BlackBerry is restructuring for patent assertion (i.e. trolling) in the wake of some alliances with Microsoft



  13. After Microsoft's Soft Bribe Some Non-Technical Deputy Does Not Like Free Software, Microsoft-Linked Media Responds to This Non-News by Making Bogus Claims of Munich Leaving GNU/Linux (Updated)

    The subversive forces that have secretly been attacking Munich over its migration to GNU/Linux (Microsoft press, Gartner, and even HP) are back to doing it while China and Russia follow Munich's lead



  14. Gates Foundation CFO Quits and Debate About Revolving Doors Recalled Amid Systematic and Shrewd Bribery of Public Officials

    More officials step out of the Gates Foundation and their destination is not known yet; Gates continues to corrupt the public sector with his money so as to increase personal gain at taxpayers' expense



  15. Links 19/8/2014: GNU/Linux Raves and Alternative to Proprietary Voice Chat

    Links for the day



  16. Links 18/8/2014: Linux 3.17 RC1, Escalation in Ferguson

    Links for the day



  17. Gartner Group Advocates Using Defective Software With Back Doors

    Despite strong evidence that Microsoft has been complicit in illegal surveillance, Gartner continues to recommend the use of Windows and other espionage-ready Microsoft software



  18. The Microsoft Patent Trolls: Android Extortion, Vringo Versus Google, and Intellectual Ventures

    Roundup of news about patent aggression by Microsoft and some of its proxies



  19. Links 16/8/2014: Microsoft Linux, US Government Turns to Free Software

    Links for the day



  20. Links 15/8/2014: Reiser4 in Headlines Again, GNOME and KDE Events Finish

    Links for the day



  21. Links 14/8/2014: Kernel Summit Coming, KMix on KDE Frameworks 5

    Links for the day



  22. Shameless Microsoft Spin is Blaming China for Microsoft's Misconduct and Back Doors While Justifying Massive Losses in Hardware (Made in China)

    A new look at how Microsoft-friendly media takes negative Microsoft news and turns that news into some kind of scandals where Microsoft is the victim



  23. Microsoft Spin in the Media Evokes 'New Microsoft' and New Back Doors

    Some new examples of Microsoft boosters rewriting history, characterising Microsoft as a FOSS champion, and generally weak/shallow reporting on Microsoft's audio/video surveillance software



  24. Links 13/8/2014: GNU/Linux as Winner, New Snowden Interview

    Links for the day



  25. Reader's Article: Skype Spying Reaches New Levels of Blatant

    Forced 'upgrades' of Skype give useds [sic.] of Skype more than they asked for



  26. The Problem is Software Patents (and Scope), Not Patent Trolls Who Abuse Them Just Like Large Corporations

    Reminder of the dangers of losing sight of the real patent problem, which is the patents themselves, not necessarily those who use them



  27. Fraud in the USPTO and CAFC Helped Apple Launch Frivolous Patent Lawsuits Against Linux/Android, Based on New Withdrawals

    Inherent corruption in the US system has aided Apple's assault on east Asian electronics giants that use Linux at the core of their products



  28. Investigation Reveals That USPTO is Corrupt, Time to Abolish It or Annul Nearly a Million Patents

    Corruption is found at the heart of the USPTO and the USPTO works hard to hide it, despite attempt by whistleblowers to bring this corruption to light



  29. Links 13/8/2014: Red Hat Enterprise Linux 6.6 Beta, Tizen in Watches

    Links for the day



  30. Links 12/8/2014: Chromebooks Surge, OpenGL in the Headlines

    Links for the day


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts