Bonum Certa Men Certa

Security FUD Against Free Software Resurfaces, Using Promotional Branding From a Microsoft-Linked Firm, So Red Hat Finally Responds

Bugs
Image courtesy of Red Hat



Summary: Old news is 'new' again, as Microsoft-friendly media decides to keep knocking hard on the reputation of Free software, using words rather than substance

A YEAR ago there was a curious (first of its kind for Free/Open Source software) "branding" of a 2-year-old FOSS bug by a Microsoft-linked firm that did not even find the bug. An engineer from Google had found it and sought to responsibly disclose it so as to patch it properly before the Microsoft-linked opportunists blew off the lid and called it "Heartbleed", set up a Web site to 'celebrate' the bug, and even made a professionally-prepared logo for it. This whole "Heartbleed" nonsense -- however serious it may have been for a day -- was blown out of all proportions in the media and tarnished the name of Free software because it was so 'successfully' marketed, even to non-technical people. It was a branding 'success' which many firms would later attempt to emulate, though never with the same degree of 'success' (where success means bamboozling the public, especially non-technical decision-making people).

"Microsoft must be laughing quite hard seeing all that media manipulation.""Dear journalists," I said earlier today in social media (Diapora), "bugs don't have birthdays. Stop finding excuses to bring "Heartbleed" BS (MS name for old bug) to headlines." I spoke to one author about it and challenged him for floating these "Heartbleed" logos and brands yet again. To us it seems quite evident that Microsoft keeps attacking Free software and GNU/Linux like no time before; it's just more subtle and hidden in more sophisticated ways. The person who heads the incognito firm that's known only for the "Heartbleed" brand (they control the brand) came from Microsoft (he was head of security there) and also from the FBI, whose stance on encryption is widely known by now; they actively seek to break security of software, so knowing about the 2-year-old OpenSSL bug would make sense. Some reputable media reports said that the NSA had known about this bug for about a year before it was known to the public and the NSA cooperates with the FBI on breaking software security, sharing personal (illegally intercepted) data, etc.

Anyway, the same publication (as above) also floated the "Heartbleed" nonsense in another article today. Would they do just about anything to keep it in headlines? Even a year later? They are now citing some firm called Venafi (never heard of it before), which basically relies on misleading misuse of statistics. It's FUD from a company that tries to make money from perceived dangers and accentuates these dangers in an effort to acquire clients. What kind of 'journalism' is this? incidentally, Black Duck is now joining the list of such parasitic companies, with new hires and multiple press releases, so clearly it's a growth area and the Microsoft link is easy to see. It is FUD season again this spring as more publications now float this whole nonsense. This is hardly journalism, it's just throwback.

Thankfully enough, Red Hat demonstrates what "branding" of FOSS bugs practically means, even using the image above. There is no correlation between the naming of bugs and their severity, but press coverage sure loves a good brand. This is an important (albeit belated) response from Red Hat to "branding" of a FOSS bug by Microsoft-linked firms like the one behind "Heartbleed".

"It’s been almost a year since the OpenSSL Heartbleed vulnerability," says Red Hat, "a flaw which started a trend of the branded vulnerability, changing the way security vulnerabilities affecting open-source software are being reported and perceived. Vulnerabilities are found and fixed all the time, and just because a vulnerability gets a name and a fancy logo doesn’t mean it is of real risk to users."

Well, Microsoft folks sure squeezed everything they could from this bug, seeking to discredit not just OpenSSL but the whole development process of Free software (due to just one small bug, or a few lines of code). And Microsoft still pretends that it is warming up to Open Source? Who are these frauds kidding?

There's a lot of companies which continue to use platforms with back doors, such as Windows, but the Wintel-oriented media would rather we just obsess over this one bug from one year ago (which was patched as soon as it became publicly-known).

We are rather disappointed to see a decent journalist like Sean Michael Kerner, along with colleagues at eWEEK, swallowing the bait and serving to promote the misleading claims to advertise this company that controls the "Heartbleed" brand, among other opportunists (like fish swimming around a shark for some leftovers). Microsoft must be laughing quite hard seeing all that media manipulation.

Recent Techrights' Posts

Snooping EPO Management, Sniffing Up Every Staff Action
It this a problem for whistleblowers? Of course.
Don't Do That
Options do exist. People should exercise freedom.
Iran Has Debunked GAFAM and Cloud Computing as Safety of Data
Cloud of smoke?
SLAPP Censorship - Part 188 Out of 200: Used, Then Discarded, by Microsoft (as We Predicted All Along, It's Always Like That)
The longer they carry on with it, the more scandalous this will get
43rd Anniversary of the GNU Project Announcement
Coming soon
SLAPP Censorship - Part 187 Out of 200: Reminding Ourselves of the Great Damage Garrett Did to Linux (for Microsoft)
he rejects freedom
 
Illegal and Unconstitutional Tribunal That SLAPPs Critics Does the Illegal and Unconstitutional: It "Rubberstamps Software Patents"
This is not a legal system. This is mafia.
Privilege in 'Linux' Foundation (Double Standards) and What the FSF Should Avoid Doing
If RMS can talk about politics, others too should be able to talk about politics
Seems Like Many Microsoft Layoffs Are Going On Right Now (Forever Layoffs)
Like IBM, Microsoft hopes shareholders will not know of morale and financial problems
More Threats From the Person of Restricted Boot Infamy
Remember this is the man who is the principal purveyor of restricted boot and who landed restricted boot in Linux
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 17, 2026
IRC logs for Thursday, September 17, 2026
Linux Kernel Becoming a Slopfest - Part 3 - Besieged by LLM Bots, Now Hiding Behind a Wall of JavaScript
The series began 3 days ago
Gemini Links 18/09/2026: Modern Linguistic, Boxing, Turning 40, and Solar MiniServer
Links for the day
Links 17/09/2026: Studio Closures and Negative Rumours About Microsoft XBox Again
Links for the day
What's Wrong with Microsoft's GitHub, New Article by Jacob Bachmeyer and Richard Stallman
licensed under a Creative Commons Attribution-NoDerivatives 4.0 International License
EBay is Going to Die Soon
Users will flee
Red Hat PIPs. The Only Question is, How Many?
Insiders know what's coming soon
This Week The Register MS Published a Page With "AI" 34 Times in It and It Was, as Usual, Paid SPAM!
Does The Register MS understand that it is doing harm to its audience (for temporary gains)?
General Assembly (Meeting of All Staff) Starts in Hour Ago to Discuss Strikes at Europe's Second-Largest Institution (EPO), Strikes to Last Until End of 2026 (If Not Further)
The media absolutely does not cover this and that's intentional
Cancel Culture is a Cancer That Harms Democracy, Justice, and Science. It's Designed to Help Corporations Vanish Their Critics.
"Codes of Conduct" sounds benign; in practice, however, it is not
Links 17/09/2026: Class Action Lawsuit Over GAFAM's "NameTag" and Automattic Hides What It Did to CEO Mullenweg (or Why)
Links for the day
Gemini Links 17/09/2026: Google Signals the End, ROOPHLOCH Coverage, EBay Uses Offensive Bots to Falsely Accuse Users of Stuff
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, September 16, 2026
IRC logs for Wednesday, September 16, 2026
IBM's Anderon Another Opportunity for Debt-Loading, Publicity Stunts, Maybe Hidden Layoffs
Anderon is like Theranos
In Praise of 7 Years of Alex Oliva in the FSF, Not IBM
Thank you, Mr. Oliva, for 7 years of uncompressing advocacy and perseverance
SLAPP Censorship - Part 186 Out of 200: Love (Always Commands)
This coming Friday we celebrate our wedding anniversary
With Half of September Finished Clownflare Radar Sees GNU/Linux at 7% "Market Share"
On desktops/laptops
Linux Kernel Becoming a Slopfest - Part 2 - Bribes From Slop Pushers Divide Us
Money can and does divide people
Gemini Links 16/09/2026: Cards, Nature, and Conspiracy Theorists
Links for the day
Links 16/09/2026: Proprietary Chatbots Company Lets Humans Moderate Chatbots, "Putin Looking to See How Far he Can Push NATO"
Links for the day
The Only Still-Supported Version of Windows Breaks Itself (Again), the Microsoft Layoffs Will Carry on in Secret
In the US they marked about 7% for removal just this past summer
Wikileaks Turns 20 Just 18 Days From Now
it's fair to say they've endured online, but aren't lively/active
The Cyber Show Debunks the Alleged Intelligence in Slop
It's shorter than usual
Expecting Failure
Some things would not happen to technology (tech) experts because they know how things work and what to expect (or watch out for)
Links 16/09/2026: US Running Low/Out of Some Ammo Due to Wars, Slop Bots "Are Using an Outrageous Amount of Electricity"
Links for the day
"AI Slowdown" is Code Word for Bubble Imploding (Trying to Make This Slowdown Seem Wilful, an Act of Safety and Responsibility)
They help one another by inflating the bubble and making false excuses when expansion stalls
SLAPP Censorship - Part 185 Out of 200: What Reputation?
Helping monopolies and working for monopolies never made anybody popular
Gemini Links 16/09/2026: Slovenia, Catastrophe Ethics, and ROOPHLOCH 2026
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 15, 2026
IRC logs for Tuesday, September 15, 2026