EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

04.02.14

Red Hat Should Keep Its Distance From NSA Facilitator Microsoft

Posted in Microsoft, Red Hat, Security, Windows at 6:27 am by Dr. Roy Schestowitz

Dragonfly

Summary: Criticism of Red Hat’s increasing proximity to some of the very same bits of proprietary software which are accompanied by back doors (for the NSA)

THE DANGERS of Microsoft are very real, as a former foe of Microsoft, Novell, helped prove. Five years ago Red Hat consented to playing an active part in Microsoft VM hosts, despite knowing (even back then) about Microsoft’s relationship with the NSA, which meant that VMs running RHEL would be accessible (to the NSA) from the back door, Microsoft Windows.

There are many back doors in Windows and therefore in Hyper-V, which sits on top of Windows (back doors further down the stack). Microsoft tells the NSA about these back doors. To give the latest example of back doors, see this new report [2] which says: “Nearly 30 days after reports of a zero-day flaw being exploited in the wild, Microsoft will finally patch this critical vulnerability.”

Relying on Microsoft for technology means that one should also expect and accept back doors. A reader showed us this new article, claiming that “Mono [is] infecting Android,” but it’s not just Android. Even Red Hat is now making such mistakes, in addition to hiring from Microsoft for management of virtualisation. Based on [2,3], Red Hat now accommodates Microsoft .NET applications, despite them being proprietary and potential back doors. A week or so ago some speculated that Microsoft might buy Red Hat (one day) [4,5] and yesterday we found the article “Why Microsoft Will Pick Off Red Hat” (logic of investors, not technical people).

Microsoft is now knowingly abandoning hundreds of millions of Windows users, leaving them with permanent back doors [6,7], so why should Red Hat trust Microsoft .NET applications or anything that comes from Microsoft, including Hyper-V? Articles like [8-10] remind us that in GNU/Linux the main flaw is human error (not changing default passwords or not applying patches, which Red Hat is making easier to apply without any downtime [11]).

The bottom line is, Red Hat’s relationship with the NSA withstanding, it oughtn’t connect too much to Microsoft components like .NET and Hyper-V because these constitute back doors that jeopardise security of GNU/Linux users.

Related/contextual items from the news:

  1. Microsoft to Fix an Internet Explorer Zero-Day Flaw
  2. Red Hat Adds Microsoft .NET to Its OpenShift PaaS
  3. A Red Hat stunner: ‘Miccosoft .NET apps on OpenShift’ Yes, you read correctly

    On Wednesday, Working with Uhuru Software, Red Hat is now incorporate a rival Microsoft product – .NET – to its three-year-old OpenShift platform-as-a-service. Really? Red Hat even published a blog to explain what’s going on to those who might find the concept a bit unbelievable.

    Chris Morgan, the OpenShift Partner Ecosystem Technical Director for Red Hat, wrote the blog – and even he acknowledged the incredulity of it all that something from Microsoft, which for years has been an enemy of Red Hat, Linux and Open Source, would be incorporated into OpenShift.

  4. An Indecent Proposal: Microsoft and Red Hat?
  5. Reviews, Indecent Proposal, and Ubuntu Graduation

    Today brings two new reviews. Jesse Smith reviews Linux Mint Debian Edition 201403 in today’s Distrowatch Weekly and Jamie Watson posts his latest hands-on. Steven J. Vaughan-Nichols says folks don’t care about operating systems anymore. Matt Hartley has a few suggestions for those ready to graduate from Ubuntu. All this and more in tonight’s Linux news review.

    Jesse Smith tested the latest LMDE in this week’s Distrowatch Weekly. He found a few bugs but Smith says it “lives up to its description” of having “rough edges.” With all its “nasty surprises” Smith suggests folks just stick with the Ubuntu-based version of Mint. But see his full review for all the details.

  6. Perspective: Microsoft risks security reputation ruin by retiring XP

    A decade ago, Microsoft kicked off SDL, or Security Development Lifecycle, a now-widely-adopted process designed to bake security into software, and began building what has become an unmatched reputation in how a vendor writes more secure code, keeps customers informed about security issues, and backs that up with regular patches.

  7. Positive Feedback: M$ Uses XP To Publish The Insecurity Of Using That Other OS
  8. Flaws In People And Their Software
  9. Red Hat Risk Reflex (The Linux Security Flaw That Isn’t)

    News headlines screaming that yet another Microsoft Windows vulnerability has been discovered, is in the wild or has just been patched are two a penny. Such has it ever been. News headlines declaring that a ‘major security problem’ has been found with Linux are a different kettle of fish. So when reports of an attack that could circumvent verification of X.509 security certificates, and by so doing bypass both secure sockets layer (SSL) and Transport Layer Security (TLS) website protection, people sat up and took notice. Warnings have appeared that recount how the vulnerability can impact upon Debian, Red Hat and Ubuntu distributions. Red Hat itself issued an advisory warning that “GnuTLS did not correctly handle certain errors that could occur during the verification of an X.509 certificate, causing it to incorrectly report a successful verification… An attacker could use this flaw to create a specially crafted certificate that could be accepted by GnuTLS as valid.” In all, at least 200 operating systems actually use GnuTLS when it comes to implementing SSL and TLS and the knock-on effect could mean that web applications and email alike are vulnerable to attack. And it’s all Linux’s fault. Or is it?

  10. Linux Bugs, Bugs Everywhere

    “We are seeing a lot of crypto bugs surfacing lately because these libraries are suddenly getting a lot of review thanks to Snowden’s revelations,” suggested blogger Chris Traver. “I think one has to separate the crypto bugs from others because they are occurring in a different context. “From what I have read about gnutls, though, it seems to me that this is probably the tip of the iceberg.”

  11. Introducing kpatch: Dynamic Kernel Patching

    In upstream development news, the kernel team here at Red Hat has been working on a dynamic kernel patching project called kpatch for several months. At long last, the project has reached a point where we feel it’s ready for a wider audience and are very excited to announce that we’ve released the kpatch code under GPLv2.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. SIPO (China's Patent Office) Taken Over by Patent Maximalists

    A look at China's race to the bottom (decline in quality) when it comes to patents, assuming quite wrongly that quantity is more important than quality and severe penalties for perceived infringement will spur innovation



  2. The Alice Case Continues to Smash Software Patents (This Time OpenTV's); Will the EPO Ever Pay Attention?

    The potency or the grip of software patents in the United States is quickly eroding, but the EPO continues to act as though software patents are legitimate



  3. EPO Staff Responds to Team Battistelli's Expansion to Include French Economic Propagandist on the Payroll

    With strings attached (like string puppets of Battistelli in various units including the Investigative Unit), can the new Chief Economist, who is French and paid by Battistelli, ever be trusted?



  4. UPC: To Understand Who Would Benefit From It Just Look at Who's Promoting It (Like TPP)

    The UPC, which is designed to aid patent trolls and aggressors (and their lawyers), is still being advanced by the EPO and some misinformed (but loyal to these former groups) politicians



  5. Trolls Molestos: Rovi (del famoso Angry Birds) Ayuda al Más Largo Troll de Patentes de Microsoft Intellectual Ventures (Corregido)

    Alguna vez conocido como hacedor de juegos y más tarde como vigilancia en masa en jugadores, Rovi ahora se ESTA ALIANDO CON EL MÁS GRANDE TROLL DE PATENTES



  6. Estadísticas de Invalidación de Patentes y Costos de Litigación de Patentes (incluso si son falsas) Muestran que la Esfera de Patentes y los Estándares de Examinación son un Probleman, No Sólo en Los Estados Unidos

    Demasiadas falsas patentes que no deberían haber sido otorgadas en primer lugar y fraudulentes jucios de patentes que terminan en favor del acusado sirve para mostrar el costo externo (o externalidad) cuando set trata de un bajisímo sistema de patentes que se esfuerza en otorgar muchas patentes irrespectivamente de su mérito.



  7. The 'Offenses' of EPO Staff Representatives Boil Down to Truth-Telling

    Dutch television examined the documents of the mock 'trials' against SUEPO leaders and concluded that whistle-blowing (i.e. exposing abuses by EPO management), not misconduct, is the reason for overzealous dismissals



  8. Rumours About Dismissal of Benoît Battistelli and New Letter From Union Syndicale Federale Blasting Battistelli's Behaviour

    hings have been heating up since the dismissal of staff representatives at the European Patent Office (EPO) and some even spread rumours about withdrawal/dismissal of the EPO's President



  9. VirnetX Case Against Apple Shows Not the Problem With Patent Trolls But With Software Patents

    What the media really ought to be talking about after the high-profile VirnetX case, rather than obsess about the status of Apple or patent trolls in the Eastern District of Texas



  10. Diápositivas de Nueva Charla Explican la Connección Entre la Corte De Patentes Unitarias (UPC) y Patentes de Software

    Benjamín Henrion habló el pasado Domingo acerca de las patentes de software europeas -una presentación que habla de la Corte Unitaria de Patentes, por la que la OEP aboga sin cesar y que es lo que significa para las patentes de software.



  11. Las Políticas de Microsoft Alienan Incluso a los Hinchas Más Acérrimos de Microsoft, Incluyendo Pro-Microsoft Web Sites

    El agresivo comportamiento de Microsoft y su BAJA CALIDAD DE PRODUCTOS dejan algunos de sus últimos restos de ´hinchas´ descorazonados y molestos.



  12. Links 6/2/2016: CoreOS Rocket 1.0, Scientific Linux 7.2

    Links for the day



  13. Maybe It's Time for Class Action Lawsuits Against Microsoft for Forced Vista 10 'Upgrades', Which Were Definitely No Accident

    The sheer arrogance of Microsoft, which silently changes the operating system on people's computers (without their consent), makes lawsuits imperative, not just a possibility



  14. Readers' Article: A Strange Conspiracy of Silence in the German Media (Part II)

    Željko Topić's allegedly dark background, which includes a suicide, a retreat of potential witnesses, German funds in Topić's private bank account and several more interesting bits



  15. Links 5/2/2016: Wine 1.9.3, Slackware 14.2 Beta 2

    Links for the day



  16. Links 4/2/2016: Red Hat Upgraded, Ubuntu Tablet

    Links for the day



  17. The Siege Continues: Patent Lawyers Want More Patents, Including Software Patents, In Spite of Alice

    Lawyers who make money from patent disputes make rather apparent their aspirations, which include patent saturation even in domains that are patents-exempt



  18. European Patent Office Pretends It's Business as Usual and Prepares New Vanity Pieces

    The PR strategy of the EPO, whose destructive patent strategy continues unabated (for now), latches onto Colombia and strives to manufacture mythology wherein the public, patent examiners and patent applicants are all very happy with the EPO



  19. The 'International' Trade Commission Imposes/Reinforces Software Patents to Establish Another Embargo

    The International [sic] Trade Commission is meddling in competition and allowing a US giant, Cisco in this case, to potentially block rivals (no imports from abroad) using software patents



  20. Readers' Article: A Strange Conspiracy of Silence in the German Media (Part I)

    The views of some of our readers regarding reluctance in the German media to challenge the EPO's violations of German law, probably because Germany benefits from being a host nation of the EPO



  21. Benoît Battistelli's EPO: From Show Trials and Mock Trials to a Self-Aggrandising Propaganda Event Later Today in Rijswijk

    A headsup from a reader regarding today's highly misleading event in Rijswijk (e.g. to mislead the media or seed positive media coverage in the Netherlands) and how it was set up



  22. Caricature of the Day: EPO President

    New caricature about Benoît Battistelli, his bodyguards, and the assault on free speech at the European Patent Office



  23. Company Known as European Patent Office Provides Tips on How to Patent Software in Europe

    The European Patent Office (EPO) uses its attendance at CeBIT, which is a corporate expo, to promote software patents in spite of the European Patent Convention (EPC)



  24. Links 3/2/2016: Dell GNU/Linux Laptop, Wine 1.8.1

    Links for the day



  25. The Most Detailed Explanation (Yet) of What's Wrong With the EPO

    The EPO's insistence that it remains above the law is not only coming under fire by the media but is also being challenged based on people who are familiar with the applicability of law to international organisations



  26. Angry Trolls: Rovi (of Angry Birds Fame) Helps Microsoft's Largest Anti-Linux Patent Troll, Intellectual Ventures (Corrected)

    nce known as a game maker and later made notorious for mass surveillance on gamers, Rovi now liaises with the world's largest patent troll



  27. Patent Invalidation Statistics and Cost of Patent Litigation (Even If Bogus) Show That Patent Scope and Examination Standards a Problem in Europe, Not Just the US

    Far too many bogus patents (patents that should not be granted in the first place) and spurious patent lawsuits that end up in favour of the defendant serve to show the external cost (or externality) when it comes to low-quality patent systems that strive to grant a lot of patents irrespective of merit



  28. Es Oficial: Por Medio de Entrismo, Microsoft Ha Convertido a la Pro-Linux Nokia en un Parásito de Patentes Anti-Linux

    Microsoft ha convertido a Nokia en un troll de patentes que ahora ataca a Linux y Android.



  29. Richard Stallman: Patentes Europeas de Software Regresan con la Corte Unitaria de Patentes (UPC)

    Debates acerca de la UPC estan siendo peleados por profesionales de software (entidades prácticantes) y elementos PARÁSITICOS como los abogados de patentes.



  30. SUEPO (EPO Staff Union) Appears to Have Launched a New and Improved Web Site After Attempts to Crush ('Decapitate') SUEPO

    SUEPO, the largest staff union of the European Patent Office, shows signs of strength rather than signs of weakness amidst attacks on the staff and a lot of media coverage, political interventions, and much more


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts