EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

02.09.17

OpenSUSE’s (or SUSE’s) Refusal to Publicly Acknowledge It Got Cracked Shows Face-Saving Arrogance Just Like Novell’s

Posted in Deception, Novell, OpenSUSE, Security, Servers, SLES/SLED at 6:16 am by Dr. Roy Schestowitz

SUSE (or MicroFocus) won’t even tell customers when its systems are in fact compromised

Novell cuffs

Summary: The same old and very notorious behaviour we found in Novell persists at SUSE under MicroFocus leadership; security neglected and keeping up appearances more important than honesty

TECHRIGHTS wrote many thousands of articles about Novell. We know Novell extremely well and we have documented its terrible behaviour for over half a decade, well before we began focusing on the EPO for example. As we shall show later, in a separate post, Microsoft’s and Novell’s “IP Peace of Mind” is making a comeback (as of last night), but right now we wish to focus on the crack I first wrote about on Monday (it has since then generated some press coverage, e.g. [1-3] below).

“Remember that no evidence has been presented by SUSE and moreover the gross negligence here is a bad sign in general.”A lot of people still miss the key point. IDG even went ahead with a rather misleading headline, as did Softpedia; rather than state the actual news (that OpenSUSE got cracked) the title says or overstates the ‘damage control’ from SUSE, diverting attention to what was not affected rather than what was affected (a politician’s trick). We used to see lots of that kind of spin back in the Novell days and the 2 articles below, having sought comment from SUSE, give SUSE the benefit of the doubt here. Remember that no evidence has been presented by SUSE and moreover the gross negligence here is a bad sign in general. That’s just “faith-based” security. My article about it was so short that it was mostly a screenshot, yet we understand that further coverage is on its way. So let’s elaborate a little. “They were using an outdated version of WordPress and got zapped,” one person wrote to me after I had published my findings. “It was just the front-end, no code was touched.” But says who? SUSE? Can we believe them?

“Nobody has yet covered that issue as properly as we hoped (poor security practices at SUSE) and the fact that they COMPLETELY FAILED or refused to publicly acknowledge what had happened is a serious aspect of it.”Whatever caused the defacement, it shows that they lost control of their platform. They did get cracked. Softpedia reported that “openSUSE devs immediately restored the news.opensuse.org website from a recent backup” (so the back end too appears to have been compromised).

Nobody has yet covered that issue as properly as we hoped (poor security practices at SUSE) and the fact that they COMPLETELY FAILED or refused to publicly acknowledge what had happened is a serious aspect of it. We waited patiently to see if an announcement would be made by then, even a reassurance that users should not worry. But nothing came out! To this date (half a week later). They attempted to cover it up, which is BAD BAD BAD. For a so-called “Enterprise-Grade” thing which SUSE tries to market itself as (selling SLE*) this is a serious breach of trust. Who would trust SUSE now?

“If someone injected a back door inside SLED and SLES, SUSE would probably say not a thing, only belatedly removing it and then lying about the whole thing, just like Microsoft does.”3 news sites and my own site wrote about it, but not a single word has been uttered by SUSE. They know they got cracked and they are not telling anyone, except when journalists ask them for comment (and press them with evidence).

OpenSUSE has a history of security issues in its sites (see “openSUSE Forum Hacked; 79500 Users Data Compromised” from 2014). Where are the reporters who are willing to ask SUSE some tough questions? Don’t let this slide. If someone injected a back door inside SLED and SLES, SUSE would probably say not a thing, only belatedly removing it and then lying about the whole thing, just like Microsoft does.

In the news:

  1. Kurdish Hacker Posts Anti-ISIS Message on openSUSE’s Website, Data Remains Safe

    Softpedia was informed by Dr. Roy Schestowitz that the openSUSE News (news.opensuse.org) website got defaced by Kurdish hacker MuhmadEmad on the day of February 6, 2017.

    It would appear that the server where the news.opensuse.org website is hosted is isolated from the rest of openSUSE’s infrastructure, which means that the hacker did not have access to any contributor data, such as email and passwords, nor to the ISO images of the openSUSE Linux operating system.

    We already talked with openSUSE Chairman Richard Brown, who confirms for Softpedia that the offered openSUSE downloads remain safe and consistent, and users should not worry about anything. The vigilant openSUSE devs immediately restored the news.opensuse.org website from a recent backup, so everything is operating normally at this time.

  2. OpenSUSE site hacked; quickly restored

    The openSUSE team acted quickly to restore the site. When I talked to Richard Brown, openSUSE chairman, he said that “the server that hosts ‘news.opensuse.org’ is isolated from the majority of openSUSE infrastructure by design, so there was no breach of any other part of openSUSEs infrastructure, especially our build, test and download systems. Our offered downloads remain safe and consistent and there was no breach of any openSUSE contributor data.”

    The team is still investigating the reason for the breach so I don’t have much information. The site ran a WordPress install and it seems that WordPress was compromised.

    This site is not managed by the SUSE or openSUSE team. It is handled by the IT team of MicroFocus. However, Brown said that SUSE management certainly doesn’t want any such incident to happen again and they are considering moving the site to the infrastructure managed by SUSE and openSUSE team.

  3. Best Distros, openSUSE Whoops, Debian 9 One Step Closer

    In the latest Linux news, the news.opensuse.org got hacked and displayed “KurDish HaCk3rS WaS Here” for a while Monday and while the site has been restored, no comment on the hack has been issued. Elsewhere, Debian 9.0 has entered its final freeze in the last steps in preparations for release. FOSS Force has named their winner for top distro of 2016 and Swapnil Bhartiya shared his picks for the best for 2017. Blogger DarkDuck said MX-16 Xfce is “very close to the ideal” and Alwan Rosyidi found Solus OS is giving Elementary OS a run for its money. Phoronix.com’s Michael Larabel explained why he uses Fedora and Jeremy Garcia announced the winners of the 2016 LinuxQuestions.org Members Choice Awards.

    [...]

    openSUSE’s news portal was compromised Monday by a hacker or group of hackers called MuhmadEmad, via the message left in its place. A Kurdish flag with the message “HaCkeD by MuhmadEmad – KurDish HaCk3rS WaS Here” was displayed for hours before it was taken down and the site’s content restored. Roy Schestowitz has a screen capture and said that openSUSE has not yet publicly acknowledged the hack. Swapnil Bhartiya spoke to Richard Brown, openSUSE chairman, who said that site was isolated from most SUSE infrastructure, especially the distribution code. There was no breach of any contributor data either. The site in question is run by MicroFocus, but all are investigating to make sure it’s an isolated incident.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email
  • Slashdot

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. IRC Proceedings: Friday, September 18, 2020

    IRC logs for Friday, September 18, 2020



  2. Links 19/9/2020: Taiwins 0.2 and a Call for Ubuntu Community Council Nominations

    Links for the day



  3. One Year Later Richard Stallman Needs to be Un-cancelled and Attention Turned to the Real Perpetrator of MIT Scandals

    The sheer hypocrisy, treating Stallman as the real nuisance to MIT when it was in fact Bill Gates who trafficked money through convicted sex criminals (to MIT); justice needs to be belatedly restored



  4. ZDNet's 'Linux' Section Isn't About Linux But About Microsoft

    ZDNet's so-called 'Linux' section isn't really about GNU/Linux; it's just the site's usual Microsoft propaganda, bought and paid for by Microsoft



  5. Debian's Network of Gossip and Gossipmongering in Debian-Private

    Reprinted with permission from Debian Community News



  6. More EPO Disclosures: An Explanation of How an EPO Survey Plots to Dismantle the EPO's Staff

    Dismantling the Office for the benefit of a bunch of private companies (taking over various duties of EPO staff) seems like the management's goal; included in image form (and text) below is today's publication. There's a PDF with text (not OCR) but it contains metadata.



  7. Forced Confessions and Thought Control in Debian

    Reprinted with permission from Debian Community News



  8. [Meme] You Cannot Elect/Vote Corporations Out of Power (Eternal Vigilance is Required)

    Based on early polls, Biden will be president-elect in about a month and a half; but it’s important to remember that the election (if honoured by the current tenant of the White House) won’t be the end of corporate abuse of power in the same sense that driving Microsoft out of business won’t miraculously mean that Free software ‘won’ (we have a lot more to confront still)



  9. Debian Volunteers Disallowed and Forbidden From Talking About Politics (Unlike Debian's Aristocracy That Handles All the Money From Sponsors)

    Reprinted with permission from Debian Community News



  10. Political Compass for Free Software (and Those Who Attack Software Freedom)

    With RMS (the father of the movement) betrayed from multiple angles (OSI, Linux Foundation etc.) it’s probably important to depict what’s going on, quasi-politically speaking



  11. Richard Stallman Has Not Changed His Tune at All

    Richard Stallman's (RMS) principled views regarding software go back to the days of zeroes and ones; his position 35 years ago was almost indistinguishable from today's position



  12. IRC Proceedings: Thursday, September 17, 2020

    IRC logs for Thursday, September 17, 2020



  13. Keith Packard: Richard Stallman Was Right (About the GPL)

    A 2020 video (before lock-downs) from the brain behind X11 and various lesser-known projects



  14. The Quandary of 'Ethical' Sponsors and One's Ability to Criticise Them (Otherwise It's a Potential Bribe in Exchange for Censorship of Critics)

    When Free software advocacy groups are indebted to companies that greatly harm people's freedom (including privacy) we have to ask ourselves questions regarding morality and ethics because money isn't inherently evil, it depends who or where it comes from (on what implicit conditions)



  15. When Attempting to Run for Debian Project Leader (DPL), Only to Realise the Process is Rigged (and Censored) to Protect Past Leaders

    Reprinted with permission from Debian Community News



  16. [Meme] Linux Foundation Does Not Represent Linux Users

    With only one truly technical person inside the Linux Foundation Board (it got a lot worse in 2020) it seems safe to call it 95%+ corporate gerrymandering with no signs of improving any time soon; it’s all about letting hostile corporations change Linux rather than allowing Linux to change the world



  17. Somebody Needs to Talk About Free Software Politics

    The world of Free software is full of politics; it's impossible to be completely apolitical in it and just like "office politics" or "corporate politics" a lot boils down to deception, manipulation, exchange of favours (sometimes bribes) and we must talk about those things if we're ever going to seriously tackle abuse



  18. 2020 Elections: No, It's Not About Russia

    The Biden/Trump false dichotomy (perpetuating the two-party system monopoly/duopoly) borrows from Russophobic tactics and fact-free shaming



  19. Nepotism and Conflicts of Interest in Free Software

    Reprinted with permission from Debian Community News



  20. Links 17/9/2020: Qt Creator 4.13.1, Linux 5.8.10 and Mesa 20.1.8 Released

    Links for the day



  21. Codes of Contradiction

    Reprinted with permission from Debian Community News



  22. [Meme] Two Dictators: When Jimmy Met Satya

    Jim Zemlin’s Linux Foundation has sold Linux to a bunch of Linux-hostile dictators



  23. Germany Would Violate 3 International Agreements With the Unitary Patent, Says FFII

    Open Letter to the Bundesrat: “Germany will violate 3 international agreements with the Unitary Patent”



  24. Expulsions by Vendettas

    Reprinted with permission from Debian Community News



  25. [Meme] António Campinos Fools Nobody at the EPO Anymore

    António Campinos, President of the EPO, is failing to hide who or what he really is; he’s not even trying anymore



  26. EPO Gradually Becomes a Set of Private Corporations (Some Aren't Even European and Work Against Europeans)

    The sale of the EPO, piece-wise so to speak, is accelerating under the leadership of the new President, who also helps cover up serious financial misconduct by Benoît Battistelli, who arranged this job for him



  27. IRC Proceedings: Wednesday, September 16, 2020

    IRC logs for Wednesday, September 16, 2020



  28. Links 17/9/2020: GNOME 3.38 and LabPlot 2.8

    Links for the day



  29. Cliques That Form and Nepotistically Control Debian (Whilst Ousting Challengers and Intimidating Influential Contributors)

    Reprinted with permission from Debian Community News



  30. How Unix Works (Explanation by Its Founding Fathers)

    An early look at the system which decades later took over the entire world (as a prototype or as a concept and de facto standard at least); it's partly relevant to the systemd debate


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts