EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

02.09.17

OpenSUSE’s (or SUSE’s) Refusal to Publicly Acknowledge It Got Cracked Shows Face-Saving Arrogance Just Like Novell’s

Posted in Deception, Novell, OpenSUSE, Security, Servers, SLES/SLED at 6:16 am by Dr. Roy Schestowitz

SUSE (or MicroFocus) won’t even tell customers when its systems are in fact compromised

Novell cuffs

Summary: The same old and very notorious behaviour we found in Novell persists at SUSE under MicroFocus leadership; security neglected and keeping up appearances more important than honesty

TECHRIGHTS wrote many thousands of articles about Novell. We know Novell extremely well and we have documented its terrible behaviour for over half a decade, well before we began focusing on the EPO for example. As we shall show later, in a separate post, Microsoft’s and Novell’s “IP Peace of Mind” is making a comeback (as of last night), but right now we wish to focus on the crack I first wrote about on Monday (it has since then generated some press coverage, e.g. [1-3] below).

“Remember that no evidence has been presented by SUSE and moreover the gross negligence here is a bad sign in general.”A lot of people still miss the key point. IDG even went ahead with a rather misleading headline, as did Softpedia; rather than state the actual news (that OpenSUSE got cracked) the title says or overstates the ‘damage control’ from SUSE, diverting attention to what was not affected rather than what was affected (a politician’s trick). We used to see lots of that kind of spin back in the Novell days and the 2 articles below, having sought comment from SUSE, give SUSE the benefit of the doubt here. Remember that no evidence has been presented by SUSE and moreover the gross negligence here is a bad sign in general. That’s just “faith-based” security. My article about it was so short that it was mostly a screenshot, yet we understand that further coverage is on its way. So let’s elaborate a little. “They were using an outdated version of WordPress and got zapped,” one person wrote to me after I had published my findings. “It was just the front-end, no code was touched.” But says who? SUSE? Can we believe them?

“Nobody has yet covered that issue as properly as we hoped (poor security practices at SUSE) and the fact that they COMPLETELY FAILED or refused to publicly acknowledge what had happened is a serious aspect of it.”Whatever caused the defacement, it shows that they lost control of their platform. They did get cracked. Softpedia reported that “openSUSE devs immediately restored the news.opensuse.org website from a recent backup” (so the back end too appears to have been compromised).

Nobody has yet covered that issue as properly as we hoped (poor security practices at SUSE) and the fact that they COMPLETELY FAILED or refused to publicly acknowledge what had happened is a serious aspect of it. We waited patiently to see if an announcement would be made by then, even a reassurance that users should not worry. But nothing came out! To this date (half a week later). They attempted to cover it up, which is BAD BAD BAD. For a so-called “Enterprise-Grade” thing which SUSE tries to market itself as (selling SLE*) this is a serious breach of trust. Who would trust SUSE now?

“If someone injected a back door inside SLED and SLES, SUSE would probably say not a thing, only belatedly removing it and then lying about the whole thing, just like Microsoft does.”3 news sites and my own site wrote about it, but not a single word has been uttered by SUSE. They know they got cracked and they are not telling anyone, except when journalists ask them for comment (and press them with evidence).

OpenSUSE has a history of security issues in its sites (see “openSUSE Forum Hacked; 79500 Users Data Compromised” from 2014). Where are the reporters who are willing to ask SUSE some tough questions? Don’t let this slide. If someone injected a back door inside SLED and SLES, SUSE would probably say not a thing, only belatedly removing it and then lying about the whole thing, just like Microsoft does.

In the news:

  1. Kurdish Hacker Posts Anti-ISIS Message on openSUSE’s Website, Data Remains Safe

    Softpedia was informed by Dr. Roy Schestowitz that the openSUSE News (news.opensuse.org) website got defaced by Kurdish hacker MuhmadEmad on the day of February 6, 2017.

    It would appear that the server where the news.opensuse.org website is hosted is isolated from the rest of openSUSE’s infrastructure, which means that the hacker did not have access to any contributor data, such as email and passwords, nor to the ISO images of the openSUSE Linux operating system.

    We already talked with openSUSE Chairman Richard Brown, who confirms for Softpedia that the offered openSUSE downloads remain safe and consistent, and users should not worry about anything. The vigilant openSUSE devs immediately restored the news.opensuse.org website from a recent backup, so everything is operating normally at this time.

  2. OpenSUSE site hacked; quickly restored

    The openSUSE team acted quickly to restore the site. When I talked to Richard Brown, openSUSE chairman, he said that “the server that hosts ‘news.opensuse.org’ is isolated from the majority of openSUSE infrastructure by design, so there was no breach of any other part of openSUSEs infrastructure, especially our build, test and download systems. Our offered downloads remain safe and consistent and there was no breach of any openSUSE contributor data.”

    The team is still investigating the reason for the breach so I don’t have much information. The site ran a WordPress install and it seems that WordPress was compromised.

    This site is not managed by the SUSE or openSUSE team. It is handled by the IT team of MicroFocus. However, Brown said that SUSE management certainly doesn’t want any such incident to happen again and they are considering moving the site to the infrastructure managed by SUSE and openSUSE team.

  3. Best Distros, openSUSE Whoops, Debian 9 One Step Closer

    In the latest Linux news, the news.opensuse.org got hacked and displayed “KurDish HaCk3rS WaS Here” for a while Monday and while the site has been restored, no comment on the hack has been issued. Elsewhere, Debian 9.0 has entered its final freeze in the last steps in preparations for release. FOSS Force has named their winner for top distro of 2016 and Swapnil Bhartiya shared his picks for the best for 2017. Blogger DarkDuck said MX-16 Xfce is “very close to the ideal” and Alwan Rosyidi found Solus OS is giving Elementary OS a run for its money. Phoronix.com’s Michael Larabel explained why he uses Fedora and Jeremy Garcia announced the winners of the 2016 LinuxQuestions.org Members Choice Awards.

    [...]

    openSUSE’s news portal was compromised Monday by a hacker or group of hackers called MuhmadEmad, via the message left in its place. A Kurdish flag with the message “HaCkeD by MuhmadEmad – KurDish HaCk3rS WaS Here” was displayed for hours before it was taken down and the site’s content restored. Roy Schestowitz has a screen capture and said that openSUSE has not yet publicly acknowledged the hack. Swapnil Bhartiya spoke to Richard Brown, openSUSE chairman, who said that site was isolated from most SUSE infrastructure, especially the distribution code. There was no breach of any contributor data either. The site in question is run by MicroFocus, but all are investigating to make sure it’s an isolated incident.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 20/10/2019: GNU/Linux at Penn Manor School District, Wine-Staging 4.18, Xfce 4.16 Development, FreeBSD 12.1 RC2

    Links for the day



  2. Guest Post: Understanding Autism for More Complete Inclusion

    "...assuming that autistic people are all the same isn't only technically wrong, it is misleading and leads to harmful and needless misunderstandings."



  3. Guest Post: Free Software Freedom is Not a Freedom of Choice

    The concept of "Freedom of Choice" and how the ruling class uses it to give a false impression of "Freedom"



  4. Guest Post: Free Software Developers and Pursuing 'Market Share'

    "The only people interested in software freedom are (almost always) free software developers. And users are interested in freedom to a very limited extent: the "free beer" side. Even many free software developers are only interested in the "free beer" part of free software."



  5. The Assertion That Microsoft Uses Communist Tactics Against GNU/Linux and Free/Libre Software

    A study of Taistoism might help understand how Free/libre software is being undermined



  6. European Patent Office and US Patent and Trademark Office Cranks Discovered Buzzwords, Stopped Worrying, Started Granting Patents They Know to be Fake

    The world's patent repositories are being saturated with loads of junk patents or patents that have no legal bearing but can still be leveraged for extortion purposes; the EPO is resorting to lies and artificially-elevated buzzwords to justify granting such fake (yet ruinous) patents



  7. IRC Proceedings: Saturday, October 19, 2019

    IRC logs for Saturday, October 19, 2019



  8. “The True Hypocrite is the One Who Ceases to Perceive His Deception, the One Who Lies With Sincerity,” Said André Paul Guillaume Gide (Nobel Prize in Literature)

    Lies flow like water in the realm of EPO and its publishers, whose sole role is dissemination of deliberate falsehoods, misnomers and misinformation



  9. The EPO Cannot Guard Fake European Patents From Scrutiny (in the Long Run)

    Legal certainty associated with newly-granted European Patents is already pretty low and as long as the EPO refuses to acknowledge that its courts (or boards) lack autonomy the EPO merely brushes a growing problem under the rug



  10. Links 19/10/2019: DeX Discontinued, DXVK 1.4.3 and Wine 4.18 Released

    Links for the day



  11. 'Corporate Linux' Will Not Protect Software Freedom

    The corporate model is inherently not compatible with software that users themselves fully control (or Software Freedom in general), so we must rely on another model of sovereignty over code and compiled code (binaries)



  12. IRC Proceedings: Friday, October 18, 2019

    IRC logs for Friday, October 18, 2019



  13. 26,000 Posts

    We want to thank those who help spread the word; it gives us moral support and morale.



  14. The Myth of 'Analysts'

    People with exaggerated roles (exaggerated by corporate media and corporations that control them) distort public perceptions about their clients; they're in effect just elevated marketing or Public Relations (PR) operatives



  15. The FSF Has Two Acting Presidents Now

    Alexandre Oliva, who acted as a sort of deputy of Richard Stallman in recent weeks, sheds some much-needed light on the current situation



  16. Should Anybody Dictate the Free Software Movement?

    "There's a great myth, as Jagadees reminds us, that advocacy doesn't produce software. That myth is corporate, and proper advocacy has at times produced the greatest software in the history of computing. If we want great Free software to continue, we need advocacy more than ever."



  17. Links 18/10/2019: More KDE Events and OpenBSD 6.6

    Links for the day



  18. We Don't Know Who Will Run the Free Software Foundation, But We Know Who Will Run the GNU Project

    Software Freedom is under a heavy and perhaps unprecedented attack; some people out there are paid by the attackers to celebrate this attack and defame people (cheering for corporate takeover under the blanket of “Open Source”), but the founder of the Free software movement remains alive, well, and very much active



  19. New EPO Meme: Who Wants to Make Billions From a 'Public' Monopoly?

    What was supposed to be a cash-balanced patent office became a money-making monster that fakes ‘crises’ to attack hard-working examiners



  20. EmacsConf Without Richard Stallman

    Now that emacs is being 'rebranded' this kind of meme seems apt



  21. IRC Proceedings: Thursday, October 17, 2019

    IRC logs for Thursday, October 17, 2019



  22. Guest Article: In the Absence of Richard Stallman OEM Source Software ('Open Source') is Trying to Hijack Even Emacs

    "Now they have to create some fictional history. No need to worry."



  23. Guest Article: Techies Should Not Dictate the Free Software Movement

    "We should start a second phase of the Free software movement that's making good software and putting users at the center."



  24. Links 17/10/2019: Ubuntu Turns 15, New Codename Revealed, Ubuntu 19.10 is Out

    Links for the day



  25. Free as in Free Speech (Restrictions May Apply)

    When limits of speech are not safety-related rules but political correctness or conformism



  26. There Won't be Patent Justice Until Patent Trolling Becomes Completely and Totally Extinct

    SLAPP-like behaviour and extortion/blackmail tactics using patent monopolies are a stain on the patent system; it's time to adopt measures to stop these things once and for all, bearing in mind they're inherently antithetical to the goal/s of the patent system and therefore discourage public support for this whole system



  27. EPO Staff Union and Staff Representatives Ought to Demand EPO Stops Bullying Publishers and Censoring Their Sites

    An often neglected if not forgotten aspect of EPO tyranny is the war on information itself; EPO management continues to show hostility towards journalism and disdain for true information



  28. Bribes, Lies, Fundamental Violations of the Law and Cover-Up: This is Today's European Patent Office

    It has gotten extremely difficult to hold the conspirators accountable for turning Europe’s patent office into a ‘printing machine’ of the litigation industry and amassing vast amounts of money (to be passed to private, for-profit companies)



  29. The Free Software Foundation (FSF) Lost Almost Half (3 Out of 8) Board Members in Only One Month

    As the old saying goes, a picture (or screenshot) is worth a thousand words



  30. IRC Proceedings: Wednesday, October 16, 2019

    IRC logs for Wednesday, October 16, 2019


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts