05.14.15

VENOM® is Not a Serious Bug, It’s Just a Marketing Campaign From CrowdStrike

Posted in Security at 10:47 am by Dr. Roy Schestowitz

Bugs
Image courtesy of Red Hat, demonstrating lack of correlation between severity and logos/brands

Summary: Many journalists bamboozled into becoming couriers of CrowdStrike, an insecurity firm which tries to market itself using a name and logo for a very old bug

THERE is a disproportionate level of coverage not of Free software but of bugs in Free software. We last wrote about it only days ago

A firm called CrowdStrike (who? Exactly!) is trying to emulate the ‘success’ of previous FUD campaigns. Now is the time to check who’s a real journalist (fact-checking) and who’s just serving PR campaigns like “VENOM”, a shameless FUD campaign from CrowdStrike.

The whole “VENOM” nonsense was covered in a good article titled “VENOM hype and pre-planned marketing campaign panned by experts”. To quote: “On Wednesday, CrowdStrike released details on CVE-2015-3456, also known as Venom. Venom is a vulnerability in the floppy drive emulation code used by many virtualization platforms.

“However, while it’s possible that a large number of systems are impacted by this flaw, it isn’t something that can be passively exploited.

“Several security experts discussed the flaw online, focusing on the marketing and the media attention that it generated – including some over-hyped headlines. Most media organizations were briefed ahead of time about the discovery and gagged by embargo until the Venom website launched, so they had plenty of time to write.

“Many media articles compared Venom to Heartbleed, which is an apples to oranges comparison. If anything, the only commonality is the fact that both flaws had a pre-planned marketing campaign.”

Here comes the “Heartbleed” brand. Yet again. They’re using names that are scary (even all caps, like “GHOST”) because it’s so much easier to sell than “CVE-2015-3456″. Journalists rarely have the technical knowledge to analyse a bug or a flaw, so they assume bugs and logos are indicative of severity.

This patch Tuesday Microsoft revealed 40+ vulnerabilities. Not a single one had a brand name, logo, etc. Here is how IDG covered 46 flaws publicly disclosed by Microsoft just for this Tuesday (Microsoft hides even more flaws). So many flaws were collectively covered in one article and yet there are no logos; none has any branding.

“VENOM” has become the latest example of what we call bugs with branding. This has got to stop because it corrupts journalism and makes the field of computer security almost synonymous with marketing or advertising. CrowdStrike used ALL CAPS (for emphasis rather than acronym) and connotation with poison to market itself, an insecurity firm, after finding a floppy drive bug from over a decade ago. There is a logo too (the first example we found of it), not just branding for this bug, dubbed “VENOM”.

Bug branding (turning number into branding-friendly FUD) seems to have adopted the ALL CAPS convention from “GHOST”, only for extra scare. This FUD has surfaced even in Linux-centric sites, which played along with the marketing campaign. Red Hat [1] and SJVN [2], even Phoronix [3] and Softpedia [4], have covered it by now, despite no focus on security news there.

Branding for bugs leads to stupid headlines that are more poetic than factual and are very light on facts. There is little substance there. This whole recipe (bug+brand name+logo=lots of publicity without much merit) has been repeatedly exploited to give a bad name to FOSS security. A lot of headlines try to connect this to the “Heartbleed” brand. Headlines that we have found so far (links below) include “New Venom bug hits data centers, but it’s hardly Heartbleed”, “Venom bug could allow hackers to take over cloud servers – and experts say it could be worse than Heartbleed”, “New Venom flaw may be worse than Heartbleed, researchers warn”, and “Venom vulnerability more dangerous than Heartbleed, targets most virtual machines”.

Zack Whittaker (former Microsoft staff) covered it like this in the CBS-owned tech tabloid, ZDNet: “Bigger than Heartbleed, ‘Venom’ security vulnerability threatens most datacenters”

Here is that “Heartbleed” brand again. “Please Stop Comparing Every Security Flaw to Heartbleed,” said one good headline from Gizmodo (that’s just how they covered this marketing campaign).

The word/brand “Heartbleed” was made up by a Microsoft-connected firm. Watch coverage from Microsoft-friendly sites and you will find headlines like: “Heartbleed, eat your heart out: VENOM vuln poisons countless VMs”

Dan Goodin, a foe of FOSS (from a security angle), brings in the NSA and Bitcoin to add FUD amid this branded bug/buzz. He wrote about the latest branded bug not once but twice (see links below). He is squeezing the most FOSS FUD out of it (opportunism). Kim Komando chose the headline “New bug taking over the Internet”. No sensationalism here? One press release said “Better Business Bureau Says Most Don’t Need to Worry” [about the branded bug], so there is some objectivity out there too, or an effort to calm people down.

Watch carefully how the bug is marketed in the media: Logo with SVG-like transparency; for a bug! Looks like it was prepared by graphics/marketing professionals. Are insecurity firms now liaising with marketing firms to professionally draw SVG logos for bugs? More logos for simple bugs (we found several, but one main logo) are circulating, usually with photos of snakes. See the complete list [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36] as of this morning. How much more of this FUD is going to circulate before journalists realise that they make a mountain out of a molehill?

Related/contextual items from the news:

  1. VENOM, don’t get bitten.

    CVE-2015-3456 (aka VENOM) is a security flaw in the QEMU’s Floppy Disk Controller (FDC) emulation. It can be exploited by a malicious guest user with access to the FDC I/O ports by issuing specially crafted FDC commands to the controller. It can result in guest controlled execution of arbitrary code in, and with privileges of, the corresponding QEMU process on the host. Worst case scenario this can be guest to host exit with the root privileges.

  2. For Venom security flaw, the fix is in: Patch your VM today

    The QEMU fix itself is now available in source code. Red Hat has been working on the fix since last week.

  3. VENOM Bug In QEMU Escapes VM Security
  4. 11-Year-Old Bug in Virtual Floppy Drive Code Allows Escape from Virtual Machines

    Popular virtualization platforms relying on the virtual Floppy Disk Controller code from QEMU (Quick Emulator) are susceptible to a vulnerability that allows executing code outside the guest machine.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

This post is also available in Gemini over at:

gemini://gemini.techrights.org/2015/05/14/venom-is-not-a-serious-bug-its-just-a-marketing-campaign-from-crowdstrike/

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Lots of Information in Sight, But Minimal Distraction

    How I keep focused on reading and writing whilst at the same time keeping an eye on important incidents, such as DDOS attacks and urgent messages coming in



  2. IRC Proceedings: Friday, April 16, 2021

    IRC logs for Friday, April 16, 2021



  3. Hate Letter Against FSF (Concern Trolls): 1415 Committers, Letter in Support of FSF (With Its Founder Back): 5116

    Taking into account people who asked for their names to be removed from the defamatory hate letter (inciting people, based on falsehoods), it's not impossible that the support letter really triples or quadruples it in terms of number of signatures



  4. Richard Stallman: Sharing is Good... We Need to Legalise It

    Dr. Richard Stallman, the Free Software Foundation's founder, explains his take on copyright and the artificial restriction being used against sharing



  5. Nadine Strossen and Hannah Wolfman-Jones Rebut Accusations Against Stallman and Choose Him as Coauthor

    "Here are her thoughts and the response she received from Nadine, extracted verbatim with their permission from the original article"



  6. Links 17/4/2021: GNOME 40 in Tumbleweed, Devuan 4.0 Alpha, Kate Editor Makes a Leap

    Links for the day



  7. EPO Staff Union Takes the EPO 'to Court' (the ILO's Tribunal, as the EPO Cannot be Taken to a Proper Court)

    The Staff Union of the EPO (SUEPO) Committees are preparing a legal battle over unlawful and unjust measures taken collectively against hard-working (overworked during pandemic) members of staff; the European public should support them



  8. The Latest Anti-RMS Coup Attempt Targets the GNU Project (Because the FSF Coup Has Clearly Failed) by Infringing and Disregarding Trademark Conventions

    A fake "GNU" (not the original GNU, just riding the coattails of the name "GNU") is trying to find/gain traction and we must oppose it because it's an extension of the very same coup attempt (same plotters) that manufactured a whole bunch of libel to incite people and blackmail the Free Software Foundation (FSF)



  9. Links 16/4/2021: Mozilla Dumping FTP, Corporations Still Concern-Trolling FSF

    Links for the day



  10. The EFF Attacks Software Freedom and Promotes Fake Privacy Linked to Microsoft

    Only weeks after attacking Software Freedom (the ad hominem way, which is easier) the EFF endorses a Microsoft-linked privacy abuse, misframing it as some sort of privacy champion



  11. Richard Stallman on How Corporate Media Limits What People Are Allowed to Think and Say (Updated)

    What the founder of the FSF told yours truly a number of years ago about the behaviour of corporate (funded and controlled by corporations) media



  12. Exposing Hard Truths is the First Step or the Path Towards Justice

    A reflection and a moment taken to set aside tribalism (shallow differences based on allegiances of personal comfort), for we need look back at actual facts — however inconvenient at times — and consider the reality of the situation



  13. IRC Proceedings: Thursday, April 15, 2021

    IRC logs for Thursday, April 15, 2021



  14. [Meme] Laundering Bribes as 'Cooperation Money'

    Germany has financial interest in ensuring that EPO abuses carry on and nobody holds the EPO accountable



  15. Articles in Support of Richard Stallman

    Reproduced with permission



  16. EPOLeaks on Misleading the Bundestag -- Part 20: Taking Stock

    Benoît Battistelli's legacy at the EPO is a legacy of corruption and cover-up; we take stock of how illegality was defended and persists to this day



  17. Links 15/4/2021: Zorin OS 16 Beta and Pushing Linux to GitHub- and Microsoft-Connected Rust

    Links for the day



  18. [Meme] Enemies With Common Interests

    The Software Freedom Movement (or Free Software Movement) has many enemies; some of them just hide in the shadows or speak out through shadowy front groups/NGOs that they semi-officially sponsor



  19. [Meme] Germany's Red Cash Cow

    EPO brings a lot of money to the German state. But at what cost to citizens and Germany’s public image?



  20. EPOLeaks on Misleading the Bundestag -- Part 19: The Deafening Silence of the Media

    "There has been speculation that Maas might have had his own political interest in protecting Battistelli and the Balkan Express because of certain allegations about financial irregularities involving the German Patents and Trademark Office (DPMA) which were doing the rounds at the time."



  21. The Indirection Game

    How to attack institutions and concepts by personifying them, then proceeding to character assassination based on lies and deliberate distortions



  22. Links 15/4/2021: LXQt 0.17, Proxmox Backup Server 1.1

    Links for the day



  23. The Patent Battles in Europe Are Connected to the War on GNU/Linux (as a Community-Led Effort)

    Monoplisers of GNU and Linux want us to think that OIN is the solution while they actively lobby for software patents in Europe and the people in charge of Europe’s second-largest institution and Europe’s largest patent office help them; this long video contains thoughts about news from the past couple of days



  24. Richard Stallman: Freedom is the Goal (Updated)

    What Richard Stallman (RMS) told me in person on his trip here



  25. IRC Proceedings: Wednesday, April 14, 2021

    IRC logs for Wednesday, April 14, 2021



  26. EPOLeaks on Misleading the Bundestag -- Part 18: Zero Tolerance for “Lawless Zones”?

    "It comes as no surprise that Maas appeared as a guest of honour at the European Inventor of the Year Boondoggle in Berlin in 2014 where he was seen on stage clapping along with the EPO President."



  27. Richard Stallman's Honors and Awards (and Why He Resigned in 2019)

    Reproduced with permission



  28. Links 14/4/2021: Alpine Releases and X.Org Server 1.20.11 Release (Security)

    Links for the day



  29. Links 14/4/2021: EasyOS Dunfell 2.7, Tor Browser 10.5a14

    Links for the day



  30. EPOLeaks on Misleading the Bundestag -- Part 17: Jawohl, Herr Minister!

    A French-German co-production of "Yes, Minister!" starring Raimund Lutz, Heiko Maas and Christoph Ernst. Directed by Benoît Battistell.


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts