EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

03.07.14

Secret Deals — Not GnuTLS — a Threat to GNU/Linux Security

Posted in GNU/Linux, Security at 10:53 am by Dr. Roy Schestowitz

Summary: Shifted focus (diversion towards non-issues like the GnuTLS flaw) and what we really need to watch out for when it comes to surveillance on GNU/Linux users

Cryptology is a funny thing. It’s an instrument of control (through predictive information. espionage, blackmail and so on). That’s more or less the thesis of a popular book from Wikileaks folks, titled “Cypherpunks”. Held in the hands of ordinary citizens, cryptology gives citizens power. Abused in the hands of freelance thugs [1] or state-sanctioned thugs like the NSA, cryptology helps guard the thugs (secrecy) and expose citizens who are only ever ‘enjoying’ fake cryptology, such as Microsoft’s and RSA’s. Now that Apple is receiving horrible publicity for breaking cryptology around the same time Apple joined PRISM there is some dodgy attempt to divert attention towards GNU/Linux, even if GnuTLS flaws are already patched and GnuTLS is not so widely adopted, not to mention the fact that is not used for very sensitive transactions such as banking [2]. The Linux Foundation was also quick to rebut the FUD [3], stating that “some were quick to point out that Linux distributions were not vulnerable to this particular issue” (contrary to corporate media reports).

What remains much bigger an issue, other than weak passwords (human error), is closed-sourced and proprietary hardware that may or may not incorporate Linux [4], such as my Home Hub from BT (which is rumoured to have back doors, based on some British press). A lot of what we’ve learned from the NSA leaks is that secret deals and collusion with companies is what’s responsible for back doors, not something which is visible at source code level. It is also what makes Red Hat, an NSA partner, difficult to trust these days [1, 2, 3]. The NSA reportedly asked Torvalds for back doors in Linux [1, 2, 3, 4]. Social engineering, bribes from the CIA in exchange for access (as reported in mainstream media) and even cracking is how spies get their way. They need not rely on programmers’ errors.

Related/contextual items from the news:

  1. Two in five Brits cough up for CryptoLocker ransomware’s demands

    Researchers from the University of Kent quizzed a total of 48 people who had been affected by CryptoLocker. Of the sample, 17 said they paid the ransom and 31 said they did not.

  2. GnuTLS: Big internal bugs, few real-world problems
  3. What is the GnuTLS Bug and How to Protect Your Linux System From It

    It seems that it’s only been a few weeks since we all heard of a nasty certificate validation error in Apple’s software, a.k.a. the infamous “double goto fail” bug. While some were quick to point out that Linux distributions were not vulnerable to this particular issue, wiser heads cautioned that a similar bug could be potentially lurking in software used on Linux.

  4. More than 300,000 routers in homes and small businesses hacked

    Team Cymru, the US-based security outfit which published the report, said that the network of hacked routers is one of the biggest of its kind that has been discovered, with most of the hacked routers in Columbia, India, Italy, Thailand, and Vietnam.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email
  • Google Bookmarks

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. António Campinos Should Speak to Peasants, Not Litigation Lawyers

    Mr. Campinos does not work for campinos but against campinos; he represents the people who sue or threaten them using ludicrous patents that should never have been granted (e.g. in Ethiopia)



  2. Christine Lambrecht (German Minister of Justice and Consumer Protection) Ignores the Fact That Even Patent Experts Reject the Unitary Patent (UPC)

    The debacle single-handedly caused by and attributable to Christine Lambrecht, who is eager to appease litigation lawyers, is made yet worse by the fact that people in this domain/profession reject what she's trying to ram down people's throats



  3. [Humour] The Linux Foundation is Not Even Using Linux

    The Linux Foundation does not support Linux except in name; it is important to remember that



  4. Microsoft Loves Power

    An explanation of why Microsoft says it loves this and that; Microsoft lacks the capacity to love or to express empathy as it's always about self gratification or coercion, nothing else



  5. IRC Proceedings: Saturday, July 04, 2020

    IRC logs for Saturday, July 04, 2020



  6. Indoors Society, Shut the Windows

    Times are changing in all sorts of ways; it seems like GNU/Linux and other Free/libre operating systems may emerge as winners when the 'dust settles'



  7. Allegation That Microsoft Adopted the Mentality of Suicide Bombers Against Linux, Leaks Reveal

    Looking at leaked E-mails from around the time Microsoft used Cyanogen as a 'proxy', we're finding some stunning admissions or speculation about the real motivations



  8. [Humour] A Union in Whose Interests?

    The union-busting 'yellow union' (the one that helped Benoît Battistelli marginalise SUEPO) is unable to represent staff any longer



  9. FFPE EPO Has Rendered Itself Obsolete by Liaising With Benoît Battistelli

    FFPE EPO has been left out of staff representation, demonstrating that liaising with the oppressor is a self-deprecating move which must be avoided (the only remaining potent union is SUEPO)



  10. Links 4/7/2020: LibreOffice 7.0 'Personal Edition', Atari VCS Coming Soon

    Links for the day



  11. [Humour/Meme] The 'New' Edge (Chrome Copycat) is Already Dead, So Microsoft is Trying to Just Kill the Competition

    Edge market share is so minuscule that it doesn’t even make it into this chart (it’s in “other”); no wonder Microsoft now bullies Windows users into using it, for users reject it even after months of endless advertising/AstroTurfing and aggressive exploitation/appropriation



  12. Fourth of July in the United Kingdom and the United States

    In these bizarre times Independence Day is still being celebrated, even as so many people are out of work, running out of hope and being fed xenophobia in social control media with a racist 'celebrity' president (the "user in chief")



  13. [Humour] Bigger is Always Better When You're a Deluded Maximalist

    The EPO totally lost sight of its mission; it's just speeding everything up, very carelessly, not minding quality and accuracy/certainty/legal validity



  14. 'Managing Intellectual Property' Managing to Become Uncritical Parrot of EPO Management

    Managing to amplify the EPO's lies isn't hard; one just needs to copy, paste, edit a little; then they call it 'journalism', irrespective of the proven track record of EPO management lying to staff and to the media



  15. IRC Proceedings: Friday, July 03, 2020

    IRC logs for Friday, July 03, 2020



  16. Monopoly Abuse, Still: Microsoft Pays Projects to Embrace/Move to C#, GitHub and Visual Studio

    Microsoft's greatest of efforts to lull regulators into inaction and fool us all into thinking that things have changed are undone by actual behaviour, which is abusive, anti-competitive and just... typical Microsoft



  17. Links 4/7/2020: Grml 2020.06 and diffoscope 150 Released

    Links for the day



  18. [Humour/Meme] Don't Let a COVID Crisis Go to Waste When You're Eager to Find Excuses for Many Layoffs and Shutdowns

    Microsoft business units that were defunct (long-failing, well before COVID-19) are being thrown out and Microsoft exploits a virus to rationalise these decisions while spicing up media coverage with "Hey Hi" (AI) and "virtual" experience or Facebook (to give the false impression that nothing really goes away)



  19. Free Software Tackles Political Issues. Political Tactics Are Also Being Weaponised Against Free Software.

    Divide-and-rule tactics seem to have been exploited to weaken collaborative work on Free/libre software; the response to these tactics needs to start with realisation that this is going on (even if it's done in a somewhat clandestine nature)



  20. Offence and Racism

    o those in positions of power and privilege (financial) you are controllable by guilt; dividing us and causing us to feel guilt and fear (over potential offence) is a powerful social control mechanism and pretext for dismissal, censorship, humiliation



  21. Links 3/7/2020: TrueNAS 12 Beta 1, Librem 13 Product Line

    Links for the day



  22. [Humour] European Patents Only Useful Outside the Legal Framework?

    Patents that aren't valid in the eyes of courts would best serve patent trolls that settle out of courts, en masse



  23. Microsoft's Share in Web Servers Rapidly Falls to Just 4.5% (Falling More Than 5% in a Single Month)

    Microsoft's share as measured at Netcraft (de facto authority in this area) is rapidly declining; expect IIS to go the way of the dodo some time in the coming years



  24. The Lock-downs Are Over and Still Zero Media Coverage About EPO Scandals and Corruption

    The appalling state of journalism in Europe (and to some extent in the world at large) means that the EPO's management can get away with all sorts of horrible crimes and fraud; the silencing of the media is, in its own right, quite scandalous



  25. IRC Proceedings: Thursday, July 02, 2020

    IRC logs for Thursday, July 02, 2020



  26. “Microsoft's Deadly Love” by Alessandro Ebersol (Agent Smith)

    Full credit goes to PCLOS Magazine for publishing this good piece, which we’re reproducing



  27. Links 2/7/2020: Microsoft Partner Says GNU/Linux Share in Desktops/Laptops at 4% Even After Lock-downs, OpenSUSE Leap 15.2 and Mageia 8 Alpha 1 Released

    Links for the day



  28. Why People Should Never Ever Use DuckDuckGo

    DuckDuckGo is another privacy abuser in disguise; the above forum thread enumerates key reasons



  29. After 2 Years and 2 Days António Campinos is a Perfect Leader, Fostering EPO Abuses While Smiling

    EPO corruption persists, but this time the corruption enjoys better marketing/PR and complicit (or at best silent) media



  30. [Humour] As If Monopolies for Life Will Save People's Lives...

    The mentality of monopoly or the mindset of patent maximalism has been quick to exploit the deaths of half a million


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts