Bonum Certa Men Certa

Microsoft Wants to Remove (or Deprecate) PuTTY From Windows and Replace It With Proprietary Microsoft Software

What would Simon Tatham say?

Simon Tatham



Summary: The most prominent NSA partner wants to 'contribute' to OpenSSH, one of the thorns in the side of spies all around the world

MICROSOFT has just made this bizarre "Looking Forward" announcement, with no timetable. It's about OpenSSH.



"I haven't read the page or even tried to load the link," told us a reader, "but the URL if legit says a lot of bad if they are now targeting and may corrupt that community. Connecting to or from a Windows machine defeats the purpose of the program."

PowerShell was recently mentioned in the context of Microsoft's attempt to openwash it, trying to get UNIX/Linux people addicted to it. PowerShell is proprietary software and it is using Microsoft APIs, conventions, etc. No security-conscientious person (especially computer professional) should ever use it.

A very misleading headline from IDG says that making proprietary software devour OpenSSH is "love". IDG extended this nonsense to several sites which it owns and many people read it there first because of this spamming/repetition/googlebombing [1, 2]. There was later (due to lesser visibility, no spamming) some additional ZDNet's coverage from Linux-oriented journalists and some Linux-oriented sites like Softpedia's Linux section and Phoronix, which wrote: "In the Windows world it has been traditional to use a program such as PuTTY to remotely manage Unix boxes from Windows clients, but no more."

“Like porting a hardened steel padlock to a paper bag.”
      --iophk
Well, so it's more like an unnecessary move then, at the very least because of PuTTY (there are other reasons which we can name another day). What at all is Microsoft contributing here? PuTTY has worked for well over a decade (I first used it around 2001). It was adequately adapted/updated to all versions of Windows as there was market need/demand.

There was pro-Microsoft slant in Microsoft-supportive sites [1, 2] and increasingly (over time) Microsoft-leaning sites such as Slashdot (see coverage) or The Register (see coverage). These used to be pro-FOSS, but that was before Microsoft influence, boosters, money etc. got funneled in.

Our reader iophk, quoting Microsoft Peter as saying that "Microsoft is going to work with {sic} and contribute to {sic} OpenSSH, the de facto standard SSH implementation in the Unix world, to bring its SSH client and server to Windows," criticises this worrisome move. "Like porting a hardened steel padlock to a paper bag," to use his analogy. So a platform with back doors can compromise a network which the NSA, based on Snowden's leak, has not been so successful penetrating (some improvements have been made since there, like deprecation of old ciphers, not deliberately-compromised ciphers like those which Microsoft uses). We have legitimate reasons to be concerned when the first PRISM company and NSA ally (Microsoft) says it wants to 'contribute'. Even when a company like Red Hat wants to alter SSH we dread it a bit because of Red Hat's own relationship with its big client, the Department of Defence, as we have explained before [1, 2, 3, 4]. OpenSSH is a BSD project and the licence too is different, not just the philosophy (OpenBSD is exceptionally strict).

Recent Techrights' Posts

Small Codebase is Typically Safer (More Aftermarket Snakeoil Means More Holes)
Rust is just more code
Spending Christmas Pasting Microsoft's Chatbot Garbage - Anti-Linux and Anti-BSD FUD - Into LinuxSecurity.com (Under the Guise of 'Article')
In 2025 we need to tackle this problem
 
Happy Birthday to Linus Torvalds (55)
he's not the "git" which bashers and haters say he is
'LaunchLibre' and Introducing People to Software Freedom While They're Still Young
announcement from "carmenmaris"
With 5 Days Left (Sans Time Extension, Which is Expected) FSF Has Already Raised 60% of the Money It Sought
Technically 59.6485%
Links 27/12/2024: Ongoing Demise of Real Healthcare, Gemlog Cleanup, Fingers Point to Russia After Passenger Plane Crash
Links for the day
Links 27/12/2024: Perfect Desk, Banning Cellphones, Many Cables Cut Near Finland
Links for the day
Gemini Links 27/12/2024: Slop and Self-hosting
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, December 26, 2024
IRC logs for Thursday, December 26, 2024
Microsoft Openwashing Stunts Initiative (OSI) is A Vulture in "Open" Clothing
it's quite telling that the OSI isn't protecting the Open Source Definition
Gemini Links 25/12/2024: Reality Bites and Gopher Thanks
Links for the day
Links 26/12/2024: Japan-China Mitigations and Mozambique Prison Escape (1,500 Prisoners)
Links for the day
2025 Will be Fought and Fraught With LLM Slop or Fake 'Articles' (Former Media/News Sites Turning to Marketing Spam)
The elephant in the room?
Links 26/12/2024: Ukraine's Energy Supplies Bombed on Christmas Day, Energy Lines Cut/Disrupted in the Baltic Sea Again
Links for the day
Gemini Links 26/12/2024: Rot Economy, Self-hosted Tinylogs
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, December 25, 2024
IRC logs for Wednesday, December 25, 2024
[Meme] Time to Also Investigate Bill Gaetz
Investigation overdue
IBM Has Almost Obliterated or Killed the Entire Fedora Community (Not IBM Staff)
Remaining Fedora insiders are well aware of this, but bringing this up (an "accusation" against IBM) might be a CoC violation
Links 25/12/2024: Fentanylware (TikTok) Scams and "Zelle Scams Lead to $870M Loss"
Links for the day
Brittany Day Can Rest and Let Microsoft/Chatbots Write Fake 'Articles' About "Linux" This Christmas
Who said people don't work on Christmas? Chatbots or plagiarism-as-a-service work 24/7, every day of the year except during Microsoft downtimes
Links 25/12/2024: Windows TCO Brought to SSH, Terence Eden 'Retires'
Links for the day
Links 25/12/2024: Latest Report Front Microsoft Splinter Group, War Updates
Links for the day
Links 25/12/2024: Hong Kong Attacks Activists During Holidays, Xerox to Buy Lexmark
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, December 24, 2024
IRC logs for Tuesday, December 24, 2024
Gemini Links 25/12/2024: Open Source Social and No Search
Links for the day