EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

06.14.14

Small Bugfixes Become Big News in the Age When Fear (of FOSS) Sells

Posted in Free/Libre Software, FUD, Security at 3:57 am by Dr. Roy Schestowitz

Attempts to belittle the “eyeballs on the code” motto

Eye

Summary: Another week brings another set of bugfixes, which some choose to characterise as a very big deal despite evidence to the contrary

WHEN one has an agenda one can accentuate a particular side by covering it excessively. To be frank, not only FOSS-hostile circles are to be blamed for security hype; even some FOSS-friendly sites are releasing articles like “Linux Malware And Antivirus” or cover every security fix as though it’s major news. Consider just the past few days in Softpedia: A Steam OS bugfix is news and the same goes for Ubuntu because these projects make attractive headlines, especially after the whole “Heartbleed” hype [1, 2, 3]. Guess who was behind it: the firm of Microsoft’s ‘Former’ Security Chief. GnuTLS was subjected to the same treatment by the same Microsoft-connected firm because like any project it has bugfixes [1, 2], never mind the real security issues (back doors in proprietary software like Windows).

Amid some of the latest reports from Microsoft-friendly sources and FOSS-friendly sources like SJVN (we cited two of these articles before) we should keep in mind that not all bugs are created equal and if we let every bugfix in a project like Linux or OpenSSL become major news, then we will lose sight of the real issue, which is proprietary software having bugs by design, to facilitate intrusion.

Kevin Poulsen, who did some Wikileaks-hostile coverage back in the days, correctly points out that “After Heartbleed, We’re Overreacting to Bugs That Aren’t a Big Deal”. Here is how his article begins:

Here’s something else to blame on last April’s Heartbleed security bug: It smeared the line between security holes that users can do something about, and those we can’t. Getting that distinction right is going to be crucial as we weather a storm of vulnerabilities and hacks that shows no sign of abating.

Last week the OpenSSL Foundation announced it was patching six newly discovered vulnerabilities in the same software that Heartbleed lived in. The first reaction from many of us was a groan–here we go again. Heartbleed triggered what was probably the single largest mass-password change in history: In response to the bug, some 86 million internet users in the U.S. alone changed at least one password or deleted an internet account. The thought of a repeat was (and is) shudder-inducing.

Be aware that there’s a disturbing trend right now, where so-called ‘security’ firms (opportunists/attention whores) or media companies try to exploit general security paranoia (or privacy concerns) to ‘sell’ us stories about ‘gaping holes’; the reality is usually just some routine bugfixes, wrapped up by those who have agenda. Dan Goodin and the Microsoft-connected firm (which even branded a bug) are some of the worst in this regard.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Boycotting Micro Focus International

    Microsoft's "Partner of the Year" is taking over the patron of SUSE and all of Novell's remains, except the patents (Microsoft has already grabbed those)



  2. Vesna Stilin's Remarks on Željko Topić: Part XI

    Vesna Stilin speaks about her confrontation with EPO Vice-President Željko Topić, who has criminal lawsuits against him in Croatia



  3. Links 22/11/2014: Linux Mint 17.1, Ubuntu MATE

    Links for the day



  4. Links 21/11/2014: Problems at Debian, Jolla Tablet

    Links for the day



  5. Links 18/11/2014: Linux 3.18 RC 5, New DigiKam

    Links for the day



  6. Special Report: Many Criminal Charges Against EPO Vice-President Željko Topić

    The abuses of Željko Topić, who has gained notoriety in his home country, are rapidly becoming public knowledge across all of Europe



  7. Links 16/11/2014: Xfdesktop 4.10.3, GNU Hello 2.10

    Links for the day



  8. Microsoft is Going Into the Anti-Whistleblowing Business, Dodges Criticism Over 19-Year Bug Door in Windows

    With Aorato acquisition Microsoft helps protect the criminals (from whistleblowers) and with lies about .NET Microsoft distracts from a bug that has facilitated remote access into Windows (by those in the know) for nearly two decades



  9. Reaffirming Microsoft's Long-Known Hostility Towards Net Neutrality, Microsoft Crashed Juniper

    Steve Ballmer is ranting against net neutrality and Juniper's business is in trouble after a lot of executives from Microsoft took over most top positions there



  10. Another Massive Step Towards Elimination of Software Patents as Even CAFC Rules Against Them

    After SCOTUS gets involved in the Ultramercial case, the CAFC finally decides to actually serve justice rather than dogma



  11. The GOP's Patent Reform Plan Not Effective Enough to Stop Massive Patent Trolls Like Microsoft/Nokia

    The corporations-serving GOP says that it wants a patent reform, but another reminder is needed of the futility of the suggested changes



  12. How the EPO's Executive Branch (Battistelli and Topić) Banned Scrutiny and Created Authoritarian Model of Control: Part X

    A look at highly dubious moves by EPO President Battistelli and his right-hand man Topić, whose abuses are becoming hard to oversee or even report



  13. Links 15/11/2014: Linux Mint 17.1 Release Candidate, Popcorn Time 0.3.5

    Links for the day



  14. IRC Proceedings: October 26th, 2014 – November 8th, 2014

    Many IRC logs



  15. The Terrible Joke Which is Microsoft 'Loving' Linux: Nightmares With UEFI 'Secure' Boot (i.e. Windows Monopoly Imposed) Continue to Affect GNU/Linux Users

    A reminder of Microsoft's sheer hostility towards GNU/Linux and long-reaching sabotage of GNU/Linux installations



  16. Patent Lawyers Worry About Section 101 in 'Alice' (and Other Patent News)

    A quick roundup of news of interest regarding software patents



  17. Will Write for FUD (Against FOSS)

    Black Duck rears its ugly head again, serving to show that it is in the business of changing perceptions and not in the information or analysis business



  18. Debunking Several Days of Never-Ending Lies About Microsoft and .NET

    .NET is not "Open Source", it cannot be forked (there remains patent threat), Visual Studio is still completely proprietary and it is expected to come to other platforms only because Windows has lost its dominance and Microsoft wants to perpetually control APIs (with software patents) and hence reign over developers



  19. Links 14/11/2014: LibreOffice 4.3.4, Ads Now in Firefox

    Links for the day



  20. Links 14/11/2014: GNOME 3.14.2, PulseAudio 6.0

    Links for the day



  21. Microsoft Windows is Still Designed as a Paradise of Back Doors, Intrusion, Wiretaps, and Interception

    At many levels -- from communication to storage and encryption -- Windows is designed for the very opposite of security



  22. Forget the FUD About Bash and OpenSSL, Microsoft Windows Blamed for Massive Credit Cards Heist

    Home Depot learns its lesson from a Microsoft Windows disaster, but it stays with proprietary software rather than move to software that is actively audited by many people and is inherently better maintained (Free/libre software)



  23. Windows 'Update' and NSA Back Doors, Including a 19-Year Bug Door in Microsoft Windows

    The back doors-enabled Microsoft Windows is being revealed and portrayed as the Swiss cheese that it really is after massive holes are discovered (mostly to be buried by a .NET propaganda blitz)



  24. Revealed: Microsoft is Trying to Corrupt the UK in Order to Eliminate Its OpenDocument Format-Oriented Standards Policy

    Microsoft interference with Britain's preference for ODF is now confirmed, thanks to a valuable news report from Computer Weekly; OOXML lock-in is being unleashed by Microsoft on Android users



  25. Links 13/11/2014: Ubuntu MATE 14.04.1 LTS, New KDE Plasma

    Links for the day



  26. .NET is NOT "Open Source", But Microsoft's Minions Shamelessly Openwash It Right Now

    The openwashing of .NET continues with yet another publicity stunt that is intended to lock in developers



  27. Links 11/11/2014: GNOME Trademark Dispute Settled, Mozilla Embraces Tor

    Links for the day



  28. Patent Reform Subversion After Republican (GOP) 'Win' in US Senate

    The Grand Corporations Party, or the political party which serves large businesses that are funding it, continues to just focus on a mirage of a 'reform' rather than tackle the real issues where culprits include very large businesses such as Microsoft and Apple



  29. Microsoft-Armed Patent Troll MOSAID (Now Conversant) Wants to Sweep up More Patents for Litigation

    Reports about patent trolls and scope of patents serve to show what the foes of Free software are up to right now



  30. When Courts in the US Attack the Right to Reuse APIs

    Challenging the clueless ruling from the Court of Appeals for the Federal Circuit in the United States (very pro-software patents and anti-computer science), notable programmers write to the highest court


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts