Bonum Certa Men Certa

Red Hat Makes an Error by Liaising With Proprietary Software Firm and Source of FUD, Supposedly for 'Security'

Don't feed black ducks

Feeding ducks
Yours truly feeding the ducks
near home earlier this year (summer)



Summary: Red Hat's cooperation with Black Duck serves to legitimise a terrible business model, wherein fear of FOSS is being accentuated and proprietary software 'solutions' are being offered

YESTERDAY we became aware of Red Hat turning to Microsoft's friend, Black Duck. It happened with little prior warning and announced with the press release calling it a "[c]ollaboration to help developers, customers and partners build and run trusted, secure applications with Red Hat container technologies" (as if these are inherently less secure than some proprietary software).



What the articles fail to mention is that Black Duck's former top manager is from Red Hat and he came back to Red Hat after his stint at this FUD firm (see the old press release titled "Black Duck Software CEO Tim Yeaton Rejoins Red Hat to Lead Newly-Formed Infrastructure Group"). Well, the doors basically revolved, twice even. Maybe that's why Red Hat came to Black Duck, legitimising what is effectively a parasite inside the FOSS world.

"What the articles fail to mention is that Black Duck's former top manager is from Red Hat and he came back to Red Hat after his stint at this FUD firm..."We have already found some puff pieces about, saying little more than the press release. One of them says that "Red Hat has collaborated with Black Duck Software to establish a secure and trusted model for containerized application delivery by providing verification that application containers are free from known vulnerabilities and include only certified content. This validation is a major step forward in enabling enterprise-ready application containers, and builds upon the strengths of each company – Red Hat’s position in container technologies and solutions, including its platform and certification strategy, and Black Duck’s position as the provider of comprehensive identification and earliest notification technologies of open source vulnerabilities."

In its marketing, Black Duck would have us believe that FOSS is terrible at security, even though proprietary software has back doors 'baked in' intentionally. NSA et al don't 'break into' Windows any more than Microsoft does; they're allowed access, by design, intent, and agenda. Days ago we showed how marketers from Black Duck had claimed that it can cost $25,000 to fix a bug in FOSS.

As of early this morning, this new relationship received press coverage from Serdar Yegulalp (writing for IDG), Sean Michael Kerner for QuinStreet and Steven J. Vaughan-Nichols for CBS. The way Vaughan-Nichols put it, "Red Hat and Black Duck want to make sure that when you run a container, it's really the container you want to run and not a rogue package."

"In many ways, Black Duck is successful as a marketing company, much like polygraph merchants (among other popular scams like homeopathy)."It sounds good on the surface, but is a proprietary dependence healthy in the long term? Based on Vaughan-Nichols, this isn't a short-term engagement. "In the long run," he explains (writing from Red Hat's town), "the companies plan to include Black Duck technologies as a component of Red Hat's container certification."

There are some lazy publications that ended up throwing the self-promotional promotional press release around. The Indian English-speaking press sort of rewrote the press release to make it look more original. Where are the sceptics? Where is the genuine reporting? All we see are puff pieces that relay claims made in a press release.

In many ways, Black Duck is successful as a marketing company, much like polygraph merchants (among other popular scams like homeopathy).

Recent Techrights' Posts

Things Will Only Get Better (as We Go Backwards)
It only gets better. If you go back in time.
UK High Court Shows SRA is Totally Useless in Curbing SLAPPs, This Has Impact on Our Reporting on the SRA Next Week
We'll carry on our coverage and soon finish the current series that so we can get on with more time-sensitive ones
 
Gemini Links 22/09/2026: Scout Night, Cybernetic Capitalism, and Thoughts on Companies Forcing People to Adopt Plagiarism Engines
Links for the day
Links 22/09/2026: "An Arsenal of Surveillance" and Slop Bots Suggest Starting Wars
Links for the day
SLAPP Censorship - Part 193 Out of 200: Breaks GNU and Linux, Tries to Silence Critics, Loses All Money, Looks for Microsoft Allies and Sponsors
The latest emotional knee-jerk reactions serve to confirm what we have long said
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, September 21, 2026
IRC logs for Monday, September 21, 2026
Links 21/09/2026: "Lies of the Hey Hi (AI) Industry" and Solar Power Is Getting Cheap
Links for the day
Gemini Links 21/09/2026: Equinox and Beginner's Guide to Gemini
Links for the day
Links 21/09/2026: "Back On My Bicycle" and American Regime's War on Media Escalates Further
Links for the day
SLAPP Censorship - Part 192 Out of 200: The Hired Guns of Garrett and Graveley Sent Us USB Sticks (One to Me, One to My Wife) Showing Lozza Talking to Garrett About Censoring/Deplatforming Techrights the Same Time Graveley Was Copy-Pasting Garrett's Lawsuit
Next year we plan to bring this matter to the Court of Appeal
Linux Kernel Becoming a Slopfest - Part 6 - Seeing Who Contaminates Linux With Slop (And Also Admits It)
Today we begin looking at some culprits
2026: The Year Galleries Realised the Need to Flag or Cull Slop Images
Society needs to shun slopfarms, people who use LLM slop (for anything at all), companies that use bots (which they dub "agents"), and so-called 'coders' who volley garbage into project and software hubs
Software Freedom Day Celebrated in 5 or 6 Continent
Software Freedom Day (SFD) 2026 was big this year
SLAPP Censorship - Part 191 Out of 200: Garrett, Graveley and Lozza
They talk to and coordinate with one another
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, September 20, 2026
IRC logs for Sunday, September 20, 2026
Gemini Links 21/09/2026: Digital Hoarder, GTD, Minimalism vs Digital Minimalism, Rejection of LLMs
Links for the day
Links 20/09/2026: "Google Now Asking For Users’ Video Selfies" and Energy Prices Set to Rise
Links for the day
Enjoy the Giving/Sharing, Not Taking
We've long supported what we believed in, even with the little money we had
Links 20/09/2026: Amazon Layoffs, Flock 'Buyouts' (Silent Layoffs)
Links for the day
USCIS and Microsoft Rumours: Curbs on Lowering Salaries by Importing Cheaper Replacements?
It seems like Microsoft's mass layoffs and efforts to cheapen the workforce face obstacles
Gemini Links 20/09/2026: "Music While Working" and Radio Silence
Links for the day
Clownflare Data From Canada
We've like to think many people are attempting to install GNU/Linux over the weekend
SLAPP Censorship - Part 190 Out of 200: Plagiarism, Back Doors, and Sabotage of Linux
This can go on for a decade or longer
Linux Kernel Becoming a Slopfest - Part 5 - Kernel Dependency on Plagiarism Giant Microsoft is a Death Blow to Any Kernel
Microsoft is bringing copyright-infringing slop into Linux
GNU/Linux Has Grown a Lot Lately
Based on Clownflare
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 19, 2026
IRC logs for Saturday, September 19, 2026