Bonum Certa Men Certa

Secret Deals -- Not GnuTLS -- a Threat to GNU/Linux Security

Summary: Shifted focus (diversion towards non-issues like the GnuTLS flaw) and what we really need to watch out for when it comes to surveillance on GNU/Linux users

Cryptology is a funny thing. It's an instrument of control (through predictive information. espionage, blackmail and so on). That's more or less the thesis of a popular book from Wikileaks folks, titled "Cypherpunks". Held in the hands of ordinary citizens, cryptology gives citizens power. Abused in the hands of freelance thugs [1] or state-sanctioned thugs like the NSA, cryptology helps guard the thugs (secrecy) and expose citizens who are only ever 'enjoying' fake cryptology, such as Microsoft's and RSA's. Now that Apple is receiving horrible publicity for breaking cryptology around the same time Apple joined PRISM there is some dodgy attempt to divert attention towards GNU/Linux, even if GnuTLS flaws are already patched and GnuTLS is not so widely adopted, not to mention the fact that is not used for very sensitive transactions such as banking [2]. The Linux Foundation was also quick to rebut the FUD [3], stating that "some were quick to point out that Linux distributions were not vulnerable to this particular issue" (contrary to corporate media reports).



What remains much bigger an issue, other than weak passwords (human error), is closed-sourced and proprietary hardware that may or may not incorporate Linux [4], such as my Home Hub from BT (which is rumoured to have back doors, based on some British press). A lot of what we've learned from the NSA leaks is that secret deals and collusion with companies is what's responsible for back doors, not something which is visible at source code level. It is also what makes Red Hat, an NSA partner, difficult to trust these days [1, 2, 3]. The NSA reportedly asked Torvalds for back doors in Linux [1, 2, 3, 4]. Social engineering, bribes from the CIA in exchange for access (as reported in mainstream media) and even cracking is how spies get their way. They need not rely on programmers' errors.

Related/contextual items from the news:


  1. Two in five Brits cough up for CryptoLocker ransomware's demands
    Researchers from the University of Kent quizzed a total of 48 people who had been affected by CryptoLocker. Of the sample, 17 said they paid the ransom and 31 said they did not.


  2. GnuTLS: Big internal bugs, few real-world problems


  3. What is the GnuTLS Bug and How to Protect Your Linux System From It
    It seems that it's only been a few weeks since we all heard of a nasty certificate validation error in Apple's software, a.k.a. the infamous "double goto fail" bug. While some were quick to point out that Linux distributions were not vulnerable to this particular issue, wiser heads cautioned that a similar bug could be potentially lurking in software used on Linux.


  4. More than 300,000 routers in homes and small businesses hacked
    Team Cymru, the US-based security outfit which published the report, said that the network of hacked routers is one of the biggest of its kind that has been discovered, with most of the hacked routers in Columbia, India, Italy, Thailand, and Vietnam.




Recent Techrights' Posts

More Microsoft Corruption and Cover-ups
The key point here is that Microsoft is a corrupt company that bribes officials and breaks every law in the books, then lies about it, covers things up, even bribes publishers to participate in the cover-up
Microsoft Fired Hundreds of Workers Days Before Thanksgiving
Maybe it's time for Microsoft shareholders to reassess the true wealth and well-being of Microsoft as a company
Ireland Goes to Polls, Here's Daniel Pocock's Leaflet (Running as Independent in Dublin Bay South)
He seems to be the only geek running for Office
Deny the Shopping Holiday, Celebrate the Real Holiday
Buy Nothing Day
 
Links 29/11/2024: China Tensions and Big Bounties for Invalidation of Software Patents
Links for the day
Daniel Pocock Explains Why People Should Vote for Him Today (General Election 2024)
Polling day in Ireland
[Meme] Microsoft and Bill Gates Controlling Media Coverage
Cautionary tale
Typical Microsoft Bully (Paid by Microsoft)
Some Microsoft staff doesn't know boundaries
Threats, Attacks on Women, and Other Tactics of Microsofters Will Always Backfire
California: An Epicentre of Psychosis Influenced by Silicon Valley?
Rejecting Fake Holidays
In the US, today is the day after Thanksgiving and nothing els
8GB Swiss Archive offered to Irish voters by Dáil candidate
Mr Pocock doesn't take orders from cyberbullies
Daniel Pocock: Why you should follow my RSS or Atom feed, Irish elections, everybody wins
Reprinted with permission from Daniel Pocock
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, November 28, 2024
IRC logs for Thursday, November 28, 2024
CNX Software Selling Out to Microsoft For Deny Friday
Hardly the first time they do this
Links 28/11/2024: F.T.C. Launches Antitrust Investigation Into Microsoft, Bluesky Concerns
Links for the day
Gemini Links 28/11/2024: Fighting Evil and Games With “Content”
Links for the day
Microsoft Canonical: Proprietary Spyware in 'Community' Clothing
Some years ago Canonical decided to restore the mere appearance of being run like a democracy or a community
Stories About Microsoft and "Hey Hi" (LLMs Actually) 'Written' by Microsoft "Hey Hi" Chatbots With 'Linux' Thrown in for SEO Purposes
self-promotional Microsoft nonsense
Links 28/11/2024: Pakistan Turmoil, TuxCare Changes, and More 'Open'AI Problems
Links for the day
Links 28/11/2024: Privacy, DNS, and Python
Links for the day
[Meme] When Social Control Media is Over
Any deathbed regrets?
Death of Human Interaction
How much are future generations being "damaged" by premature introduction of skinnerboxes and, perhaps more importantly, is there any "safe" age?
Dr. Andy Farnell: "Electronic Voting" is a Solution to a Problem That Doesn't Exist
The arguments are similar to ones that we've made for years
The Linux Foundation (Fronting for Microsoft and Bill Gates, Not Linux) Makes Cyberspace Less Secure
Security is not the goal
[Meme] The Most Important Things When Committing Crimes
pronouns
The EPO's General Consultative Committee (GCC) Meeting Last Month Sought to Remove Genders (But It's Nearly Impossible in French and German)
there are so many major problems at the EPO; this one seems like a minor distraction and perhaps one that suits corrupt management (misdirection of anger)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, November 27, 2024
IRC logs for Wednesday, November 27, 2024
Links 27/11/2024: “Writing Month”, "Cybertorture", and Qualcomm Trouble
Links for the day
Gemini Links 27/11/2024: How the Exoteric Relates to the Esoteric, a Look at BASIC
Links for the day
Materialistic Culture of Fake Possessions and Fake Popularity
Fake popularity is part of a "chicken and egg" thing
If the Reputation of the European Union for Rule of Law Has Diminished, Blame EPO and the German (Also the Dutch) Government for Facilitating It
We'll soon publish some new EPO material
[Meme] Same Thing, Different Job Title
"Server sysadmin; Clown computing consultant"
Imagine Patents on Musical Compositions and Cooking Recipes
The very existence of software patents must come to an end
"Latest Technology News" in BetaNews is Press Release SPAM (or LLM Slop, Marketing, Fake 'Review')
What they call "reviews" are just ads
[Meme] Kramer is Done
Devuan is turning 10
There Are More Devuan-Based Distros of GNU/Linux Each Year
"The Veteran Unix Admin collective salutes you"
Go Offline for a Bit
yup!
Windows Falls to All-Time Low (12%) in Gabon
Gabon's data from statCounter shows this
[Meme] When Words Come to Mean the Opposite
"Keep the 'dumb' stuff, be smart about it"
In Defence of Analog (Sometimes Digital and/or "Smart" is Objectively a Lot Worse)
This past weekend (2-3 days) I spent a few hours per day saving us 250 - 400 pounds in repair bills
It Takes Microsoft Over a Day to Restore 'Microsoft 365' (360, 5 Days of Downtime)
Microsoft/Windows TCO will always be huge
[Meme] In Some Countries, Android (Linux) is Already 'the Standard'
"Wait. Sorry, we don't do Windows here, we barely use laptops."
In Gambia, According to statCounter, Windows "Market Share" is Down to 3%
in some countries Windows is already down to 1%
In Defence of CDs...
Let's say that some environmentalists focus only on visible things like plastics
This Holiday Season Dump Companies That Offload Everything to Skinnerbox "Apps", Un-Encrypted E-mail, and 'Webapps' (Proprietary JS Applications in 'Web Site' Clothing)
bot disservice
The Web is Becoming Social Control Media Junk and Fake Text Crafted by Machines (Boosted by Social Control Media via Bots Which Game Visibility/Popularity)
The misinformation machines are being increasingly automated to promote dictators and bigots
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, November 26, 2024
IRC logs for Tuesday, November 26, 2024
When Social Control Media in the European Union is Controlled by BRICS
Who controls TikTok?
Links 27/11/2024: Zoom Waning (Stock Falls), More Microsoft Shutdowns, and European Commission Flags Bluesky for Breaches
Links for the day