Bonum Certa Men Certa

Microsoft's Insecure-by-Design (Sometimes With Back Doors) 'Contributions' to OpenSSH

Making a mockery out of the spirit of OpenBSD, having given money to OpenBSD

Manchester church Vulnerability (need for money) found in the Church of BSD



Summary: Microsoft is seemingly disrupting the high standards of the OpenSSH project (and by extension OpenBSD and Free/libre software), as its focus on security is ludicrous at best

LAST week, in our daily links, over a dozen links were included about a new revelations of flaws in a hugely popular encryption method. A paper presented by award-winning academics demonstrated a serious weakness. OpenSSH was among the alleged targets, potentially allowing spies to infiltrate, intercept and decrypt communications/data relayed over SSH. The philosophy and principles (UNIX) of OpenSSH had kept it strong for a very long time.



"Knowing the role that social engineering plays in weakening encryption, the last thing one needs right now is PRISM pioneer (first company) and a back doors proponent like Microsoft inside the OpenSSH community."Those who keep abreast of privacy news (including NSA leaks) will know that there is an aggressive effort to crack SSH. Some ciphers were recently phased out or deprecated as a result. Knowing the role that social engineering plays in weakening encryption, the last thing one needs right now is PRISM pioneer (first company) and a back doors proponent like Microsoft inside the OpenSSH community. As we pointed out earlier this year, OpenSSH is being subjected to E.E.E. (embrace, extend, extinguish) treatment from Microsoft [1, 2] because money talks. Microsoft has a lot of money (despite losses in the billions) and OpenBSD is underfunded, hence desperate for money.

Secure channels and Microsoft Windows are incompatible concepts. It cannot be done because Windows itself has back doors, allowing penetration at root (Administrator) level. Microsoft is now pushing its back-doored, insecure-by-design APIs into the SSH project and also puts people's keys on boxes with such inherent insecurities. How terrible a recipe is that? Is OpenBSD willing to compromise its credibility and reputation just because Microsoft gave it a 'generous' payment (some would call it a bribe)?

According to this update from Microsoft, they now intend to:

Leverage Windows crypto api’s instead of OpenSSL/LibreSSL and run as Windows Service...


People in the comments (not deleted, at least not yet) rightly post complaints. One said: "I don't think I like that your replacing an open source SSL with a closed source Windows crypto api."

Another commenter said: "Do I see a trap here?! If the Windows port uses the closed source crypto api is the whole OpenSource OpenSSH-idea then still intact?"

"Microsoft takes something that's not its own and then 'bastardises' it, making it an inferior 'Windows thing' which spreads only because of the network effect or illegal bundling."iophk told us: "How much key code can they replace with dodgy homebrew and still be allowed to use the same name? Without the crypto, it is not the same software and merely a derivative."

Well, that's just how E.E.E. has historically worked. Microsoft takes something that's not its own and then 'bastardises' it, making it an inferior 'Windows thing' which spreads only because of the network effect or illegal bundling.

iophk has also pointed out to us that Roger A. Grimes, who works for Microsoft and IDG (news publisher) at the same time (clearly a conflict of interests), presents a false dichotomy, "freedom or security" (right there in the headline). Computer security is never the goal at Microsoft; they want back doors for so-called 'national security' (i.e. state power with remote access to citizens' PCs).

"The first rule of zero-days is no one talks about zero-days," reads this new headline (remember that Microsoft wilfully enables NSA access through zero-days).

"If Microsoft cannot honour Free software and respect the APIs of OpenBSD, OpenSSH, OpenSSL etc. then maybe it's time to tell Microsoft to take back its 'bribe' money and go away, leaving OpenSSH alone (and secure)."Microsoft's E.E.E. tactics are becoming a big threat not just to GNU/Linux but also to BSD and Free software as a whole. Microsoft now tries to become a GNU/Linux host, despite its known record of scanning every single file (claiming to do so because of child pornography) and colluding with the government for warrantless access to data stored on servers.

The E.E.E. against GNU/Linux is perhaps best demonstrated by this new article about how Microsoft tries to take over Big Data (a lot of data, sometimes incredibly sensitive) on GNU/Linux servers. "Last month Microsoft did something extraordinary," says the author, "something which demonstrates how completely the company has changed since its third CEO, Satya Nadella, took over."

Satya Nadella just turned the company into more of a surveillance company, as Vista 10 serves to remind us. He continues to attack GNU/Linux in many ways (including patent extortion) while saying that Microsoft "loves Linux' (a lie as big as a lie can get).

If Microsoft cannot honour Free software and respect the APIs of OpenBSD, OpenSSH, OpenSSL etc. then maybe it's time to tell Microsoft to take back its 'bribe' money and go away, leaving OpenSSH alone (and secure). Almost every distribution of GNU/Linux comes with OpenSSH. Microsoft is a wolf in sheep's clothing and it has no room inside FOSS until it quits attacking FOSS and collaborating with abusive espionage agencies like GCHQ and the NSA.

Recent Techrights' Posts

GNU/Linux Above 7% in Bulgaria, Rising Just Like in Most of Europe
Up to 7%, not counting Chromebooks
Data Shows Largest EU Economies Shifting to GNU/Linux
all-time highs
statCounter Says Only One in 6 Web-Connected Clients in Hungary Are Using Windows, iOS Almost Bigger Than Windows Now
Hungary is a cautionary tale in the world of European (or Russian) politics
Many Reports About Microsoft's Financial Report/Performance Are False, Fake News, Churnalism/Parroting, and LLM Slop (Machine-Generated Lies)
Even if you see a thousand sites saying that Microsoft is performing well ask yourself why the company is rushing to fire tens of thousands of workers and cancelling datacentres
 
Links 05/05/2025: Breaches, Environment, and Conflicts
Links for the day
SUSE the Company Now Uses LLM Slop to 'Write' Its Blog, What Does That Tell Us About SUSE?
There are many giveaways
Richard Stallman is in Alicante Today to Give a Talk, Czech Republic in Two Days (Wednesday)
Of course he can deliver the talk in Spanish
Gemini Links 05/05/2025: XL Bullies and Luddites
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, May 04, 2025
IRC logs for Sunday, May 04, 2025
Links 04/05/2025: Science, Conflicts, and Monopolies
Links for the day
Links 04/05/2025: FCC Turning Into MAGA’s Censoring Machine, SEC Pressured to Delist Chinese Companies
Links for the day
Gemini Links 04/05/2025: Historical Artifacts and Date Calculations in POSIX Shell
Links for the day
In the First 3 Months of 2025 GAFAM Debt Rose by More Than $14.4 Billion
That's based on their official statements
10-Step Strategy to Get BRETT WILSON LLP ("Gun for Hire"), Microsoft's Serial Strangler, and the Serial Defamer to Compensate Techrights and Tux Machines for Years of SLAPPs and Abusive Litigation
There's no room or capacity for forgiveness here; enablers and protectors of crime need to be scuttled and pay up in full
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, May 03, 2025
IRC logs for Saturday, May 03, 2025
Microsoft's Debt Grew 2.1 Billion Dollars in the Past 3 Months Alone or 8.2 Billion in the Past Half a Year
That's very different from what the mainstream press tells the public, including shareholders
Happy 20th Birthday to OpenDocument Format (ODF)
nowadays many companies use "online" "webapps" to collaborate on various things
Links 03/05/2025: Amazon and Apple Problems (the A's in GAFAM), Hard to Hide Any Longer; Australia’s Election
Links for the day
Why Law Firms and Courts in Particular Should Dump Microsoft
Giving a notoriously corrupt and chronically law-breaking company control over one's systems and data is a recipe for disaster
Gemini Links 03/05/2025: Showerhead Mod and Micro Dosing on LSD
Links for the day
Links 03/05/2025: Bribery in Dutch Microsoft DC Probe, Zuckerberg Conflates Slop With 'Friends'
Links for the day
Passkeys Are Vendor Lock-in and Imperialism, Not Security, So Escape Them Before They Latch Onto Your Workflows
This is their 'grand vision' of computing. You merely 'rent' what you assumed you truly bought to own.
Today is World Press Freedom Day, 3rd of May
2025 World Press Freedom Day
Gemini Protocol's Momentum Ahead of Its 6th Anniversary (Next Month)
The more capsules go online, the more people participate in writing, not just reading
Corporate Media, a Cheerleader of Wall Street Facade, Spent Days Saying "META" and "MSFT" Lifted "the Market", But Their Debt Soared
Facebook's debt has never been higher
Microsoft Windows Falls to a Meager 9% "Market Share" in South Africa While GNU/Linux Rises Above 5% in Desktops/Laptops
South Africa is where the founder of Ubuntu (or Canonical) comes from
Let's Put Slop In the Casket Once and for All (Call Out the Sites and People Who Produce and Spread Slop)
Together, through a movement of integrity and solidarity, we can marginalise the spread of slop in all its forms, including code
Windows Down in the Largest Countries, Microsoft Cannot Dodge This Reality Forever
Talking about "clown" and "hey hi" (AI) - sometimes "Quantum" - is like telling bedtime stories to infantile investors who don't understand those buzzwords
Links 03/05/2025: Australian Election and manpage for Gemini Considered
Links for the day
Links 03/05/2025: UK Arrests for Bribery Connected to Microsoft Datacentres
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, May 02, 2025
IRC logs for Friday, May 02, 2025