EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

04.08.14

Former Chief Security Officer for Microsoft the Chairman of the Board of Firm Behind Heartbleed®

Posted in FUD, GNU/Linux, Security at 9:00 am by Dr. Roy Schestowitz

Dagger in the heart of OpenSSL

Heart Bleed

Summary: A serious conflict of interests that nobody in the media is talking about; Codenomicon is headed by Microsoft’s Howard A. Schmidt

SOMETHING fishy was in the news today (since early this morning), including articles from GNU/Linux-oriented journalists [1] and blogs [2], some of which pointed out that a vulnerability discovered and published irresponsibly by the firm headed by Microsoft’s former Chief Security Officer (we wrote about his actions before) are already “patched by all Linux distros”.

Now, looking at the site set up by his firm, you might not know this. It lists the names of many GNU/Linux distributions along with a nasty picture (the one above). This coordinated release (disclosure) of a vulnerability on the last day of Windows XP security patches (they are through unless one pays Microsoft a lot of money) is rather suspicious to us. It came with a trademark-like name, a dot-com Web site (yes .com), and soon we are guaranteed to see lots of FUD saying that GNU/Linux is not secure. We already know that the vulnerabilities industry is well inside Microsoft’s board and at highest level (look at John Thompson from Symantec; he is now Microsoft’s new chairman).

We don’t need to wait for the Microsoft press or a whisper campaign to use Heartbleed® to tell people (again) that Free software, Linux and GNU are very “bad” and are a danger for the Web (some suspect that this bug is the result of NSA intervention in code development — a subject we’ll tackle another day for sure).

“This is a man whose high-paying job required that he beats GNU/Linux at security.”Jacon Appelbaum (of Tor) says that this release was coordinated (with a date and everything) but not responsible at all because even the OpenSSL site, the FBI’s official site (whom Howard Schmidt worked with) and many more remain vulnerable. It should be noted that the flaw has existed for two years, so the timing of this disclosure is interesting. Not too long ago we showed what seemed like Microsoft's role in a campaign to paint GNU/Linux insecure and dangerous becuase of Windows XP's EOL. It was a baseless campaign of FUD, media manipulation, and distortion of facts, ignoring, as always, the elephant in the room (Windows).

For those who treat it like some innocent development at a random time in the news, remember that Howard A. Schmidt, the Chairman of the Board of Codenomicon, was the Chief Security Officer for Microsoft. He joined Codenomicon a year and a half ago. This is irresponsible disclosure and journalists who ignore the conflict of interests (namely Schmidt being the head after serving Microsoft) are equally irresponsible (for irresponsible journalism). They may unwittingly be playing a role in a “Scroogled”-like campaign.

Just go to Codenomicon’s Web site and find it described in large fonts as “A Member of the Microsoft Security Development Lifecycle (SDL) Pro Network” (in many pages). There are lots of pages like this one about involvement in Microsoft SDL.

So to summarise, what does Microsoft have to do with Heartbleed? We probably need to ask Howard Schmidt. This is a man whose high-paying job required that he beats GNU/Linux at security.

Related/contextual items from the news:

  1. Heartbleed: Serious OpenSSL zero day vulnerability revealed
  2. openssl heartbleed updates for Fedora 19 and 20
  3. Heartbleed, a serious OpenSSL bug; patched by all Linux distros

    A new vulnerability was announced in OpenSSL 1.0.1 that allows an attacker to reveal up to 64kB of memory to a connected client or server (CVE-2014-0160) which may consist of our X.509 certificates, user names and passwords, instant messages, emails and business critical documents and communication. According to OpenSSL Security Advisory report Neel Mehta from Google Security has discovered this bug.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 20/7/2019: Weston 7.0 Alpha, Nageru 1.9.0

    Links for the day



  2. Companies That Collapse Because the European Patent Office (EPO) Gave Them Fake Patents in a Hurry

    False hopes and false promises won’t do any favours to European Patents, whose legal certainty suffers because Campinos and Battistelli measure nothing but ‘production’ (quantity) rather than quality of patents



  3. Slack Committed a Very Major Crime That Can Cost Many Billions If Not Trillions in Damages for Years to Come

    The inevitable has happened to Slack, which no longer deserves to exist as a company; moreover, the people who ran the company must be held criminally accountable



  4. Demand for European Patents Will Continue to Decrease If a Lot of European Patents Turn Out to be Invalid, Worthless

    The EPO's abandonment of patent justice and quality (in pursuit of so-called 'production' targets) is likely to doom the Office as the whole or render it vastly less relevant to the rest of the world



  5. 35 U.S.C. § 101 Still in Tact in the United States and Software Patents Rot Away

    The United States, where the number of granted patents decreased last year, becomes more productive; there are more signs that patent maximalism (patent litigation, patent scope etc.) has receded



  6. Links 19/7/2019: Deepin 15.11 and GNU/Linux Back on GPD MicroPC

    Links for the day



  7. Violence is Not Free Speech and Laws Exist Against Violence

    Free speech is certainly under attack and the debate is being framed within the context of Nazism; but this overlooks the fact that there are actual death threats and calls for genocide in the mix



  8. Links 19/7/2019: Oracle Linux 8.0, Latte Dock 0.9 Beta and PCLinuxOS KDE Darkstar 2019.07

    Links for the day



  9. Why Does Jim Zemlin Publicly Congratulate Microsoft?

    The signs aren't particularly encouraging when one considers that the leadership of the Linux Foundation is a fan of Microsoft and sometimes connected to Microsoft



  10. 2 Days Later (Case in Progress) and Still Media Silence About G 2/19

    The very legitimacy of years' worth of rulings and the EPO's abusive attacks on judges are under the microscope; but the media isn't paying any attention, perhaps deliberately



  11. The 'Linux' Foundation is Acting Like a Microsoft ISV Now, Commitment to Linux and FOSS Deteriorates Even Further

    The Linux Foundation has just announced a new Microsoft-funded initiative that's pushing GitHub and CLAs (passing copyrights on code to corporations)



  12. Links 18/7/2019: OPNsense 19.7, Krita 4.2.3 and KDevelop 5.3.3 Released

    Links for the day



  13. Index: G 2/19 (Enlarged Board of Appeal, EPO)

    G 2/19 (Enlarged Board of Appeal, EPO)



  14. EPO Looney Tunes – Part 4: G 2/19 - Faites Vos Jeux…

    "Josefsson needs to bring in the “desired result” for his political masters in the Administrative Council if he wants to be in with a chance of reappointment."



  15. Media Not Interested in G 2/19, Which Demonstrates Patent Justice is Nowadays Impossible at the EPO

    The EPO spreads patent injustices to other countries and courts; the media is miraculously enough not interested, almost as though there's a coordinated blackout



  16. Librethreat Database Updated

    Database which keeps track of variants of attack vectors on Free/libre software now includes two more forms of threat



  17. A Look Back (and Forward) at Friendly Programming

    Historical perspective on computer languages and how to do better



  18. Red Hat's Freedom Reduced to Just Online Partner Enablement Network (OPEN) and Microsoft as a Close Partner; Canonical's Ubuntu Just an 'App' for Windows?

    Free software is being snapped up by proprietary software giants and patent bullies that treat it as little more than an 'add-on' for their proprietary offerings



  19. Linux Foundation Apparently Celebrates Sysadmin Day With a Microsoft Windows Site!

    The Linux Foundation shows ‘love’ to actual GNU/Linux (the real thing) by apparently rejecting it and badmouthing it



  20. EPO Looney Tunes – Part 3: The Legal Line-up for G 2/19

    The deck appears to have already been stacked for G 2/19, a decision on EPO judges' exile to Haar (veiled disciplinary action/collective punishment by those whom the judges are supposed to 'oversee')



  21. Links 17/7/2019: VirtualBox 6.0.10 and Mageia 7.1 Releases, Mint Betas

    Links for the day



  22. Links 16/7/2019: Btrfs Gets 'Cleaned Up', Clonezilla Live 2.6.2-15

    Links for the day



  23. EPO Looney Tunes - Part 2: The “Difficult Legacy” and Its Dark Historical Shadow

    Assuming that he was informed, then it seems fair to say that Battistell’s little “joke” at the expense of the Boards was in very bad taste



  24. EPO Noise Machine Turned On as Haar Hearing Kicks Off, Patrick Corcoran Defamed Again

    The EPO does not want people to hear about Haar; it just wants people to hear about how wonderful the EPO is and there are some who have just decided to slander Patrick Corcoran again



  25. Microsoft is 'Doing Kamikaze' (神風) on Linux

    An analogy for what the Linux (only in name!) Foundation and Microsoft mean to Linux — or by extension to GNU/Linux and Free software whose largest repository Microsoft took control of



  26. The 'New' Linux.com Sometimes Feels Like a Microsoft Promotion Site

    Anything that the ‘Linux’ Foundation touches seems to turn into its proprietors’ agenda; one of those proprietors is Microsoft, which has a "Jihad" against Linux



  27. IBM is a Threat to the Internet, Not Just to Software Development (Due to Software Patents Aggression)

    IBM continues its aggression against technology — a fact that’s even more distressing now that IBM calls the shots at Red Hat



  28. EPO Looney Tunes - Part 1: Is D-Day Approaching for Battistelli’s “Difficult Legacy”?

    European patent justice isn’t working within the premises of EPOnia; a bunch of ‘show trials’ may in fact turn out to be just that — a show



  29. Links 16/7/2019: LXD 3.15, Q4OS 3.8 and D9VK 0.13f

    Links for the day



  30. Links 15/7/2019: Vulkan 1.1.115 and Facebook Openwashing

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts