02.09.17

OpenSUSE’s (or SUSE’s) Refusal to Publicly Acknowledge It Got Cracked Shows Face-Saving Arrogance Just Like Novell’s

Posted in Deception, Novell, OpenSUSE, Security, Servers, SLES/SLED at 6:16 am by Dr. Roy Schestowitz

SUSE (or MicroFocus) won’t even tell customers when its systems are in fact compromised

Novell cuffs

Summary: The same old and very notorious behaviour we found in Novell persists at SUSE under MicroFocus leadership; security neglected and keeping up appearances more important than honesty

TECHRIGHTS wrote many thousands of articles about Novell. We know Novell extremely well and we have documented its terrible behaviour for over half a decade, well before we began focusing on the EPO for example. As we shall show later, in a separate post, Microsoft’s and Novell’s “IP Peace of Mind” is making a comeback (as of last night), but right now we wish to focus on the crack I first wrote about on Monday (it has since then generated some press coverage, e.g. [1-3] below).

“Remember that no evidence has been presented by SUSE and moreover the gross negligence here is a bad sign in general.”A lot of people still miss the key point. IDG even went ahead with a rather misleading headline, as did Softpedia; rather than state the actual news (that OpenSUSE got cracked) the title says or overstates the ‘damage control’ from SUSE, diverting attention to what was not affected rather than what was affected (a politician’s trick). We used to see lots of that kind of spin back in the Novell days and the 2 articles below, having sought comment from SUSE, give SUSE the benefit of the doubt here. Remember that no evidence has been presented by SUSE and moreover the gross negligence here is a bad sign in general. That’s just “faith-based” security. My article about it was so short that it was mostly a screenshot, yet we understand that further coverage is on its way. So let’s elaborate a little. “They were using an outdated version of WordPress and got zapped,” one person wrote to me after I had published my findings. “It was just the front-end, no code was touched.” But says who? SUSE? Can we believe them?

“Nobody has yet covered that issue as properly as we hoped (poor security practices at SUSE) and the fact that they COMPLETELY FAILED or refused to publicly acknowledge what had happened is a serious aspect of it.”Whatever caused the defacement, it shows that they lost control of their platform. They did get cracked. Softpedia reported that “openSUSE devs immediately restored the news.opensuse.org website from a recent backup” (so the back end too appears to have been compromised).

Nobody has yet covered that issue as properly as we hoped (poor security practices at SUSE) and the fact that they COMPLETELY FAILED or refused to publicly acknowledge what had happened is a serious aspect of it. We waited patiently to see if an announcement would be made by then, even a reassurance that users should not worry. But nothing came out! To this date (half a week later). They attempted to cover it up, which is BAD BAD BAD. For a so-called “Enterprise-Grade” thing which SUSE tries to market itself as (selling SLE*) this is a serious breach of trust. Who would trust SUSE now?

“If someone injected a back door inside SLED and SLES, SUSE would probably say not a thing, only belatedly removing it and then lying about the whole thing, just like Microsoft does.”3 news sites and my own site wrote about it, but not a single word has been uttered by SUSE. They know they got cracked and they are not telling anyone, except when journalists ask them for comment (and press them with evidence).

OpenSUSE has a history of security issues in its sites (see “openSUSE Forum Hacked; 79500 Users Data Compromised” from 2014). Where are the reporters who are willing to ask SUSE some tough questions? Don’t let this slide. If someone injected a back door inside SLED and SLES, SUSE would probably say not a thing, only belatedly removing it and then lying about the whole thing, just like Microsoft does.

In the news:

  1. Kurdish Hacker Posts Anti-ISIS Message on openSUSE’s Website, Data Remains Safe

    Softpedia was informed by Dr. Roy Schestowitz that the openSUSE News (news.opensuse.org) website got defaced by Kurdish hacker MuhmadEmad on the day of February 6, 2017.

    It would appear that the server where the news.opensuse.org website is hosted is isolated from the rest of openSUSE’s infrastructure, which means that the hacker did not have access to any contributor data, such as email and passwords, nor to the ISO images of the openSUSE Linux operating system.

    We already talked with openSUSE Chairman Richard Brown, who confirms for Softpedia that the offered openSUSE downloads remain safe and consistent, and users should not worry about anything. The vigilant openSUSE devs immediately restored the news.opensuse.org website from a recent backup, so everything is operating normally at this time.

  2. OpenSUSE site hacked; quickly restored

    The openSUSE team acted quickly to restore the site. When I talked to Richard Brown, openSUSE chairman, he said that “the server that hosts ‘news.opensuse.org’ is isolated from the majority of openSUSE infrastructure by design, so there was no breach of any other part of openSUSEs infrastructure, especially our build, test and download systems. Our offered downloads remain safe and consistent and there was no breach of any openSUSE contributor data.”

    The team is still investigating the reason for the breach so I don’t have much information. The site ran a WordPress install and it seems that WordPress was compromised.

    This site is not managed by the SUSE or openSUSE team. It is handled by the IT team of MicroFocus. However, Brown said that SUSE management certainly doesn’t want any such incident to happen again and they are considering moving the site to the infrastructure managed by SUSE and openSUSE team.

  3. Best Distros, openSUSE Whoops, Debian 9 One Step Closer

    In the latest Linux news, the news.opensuse.org got hacked and displayed “KurDish HaCk3rS WaS Here” for a while Monday and while the site has been restored, no comment on the hack has been issued. Elsewhere, Debian 9.0 has entered its final freeze in the last steps in preparations for release. FOSS Force has named their winner for top distro of 2016 and Swapnil Bhartiya shared his picks for the best for 2017. Blogger DarkDuck said MX-16 Xfce is “very close to the ideal” and Alwan Rosyidi found Solus OS is giving Elementary OS a run for its money. Phoronix.com’s Michael Larabel explained why he uses Fedora and Jeremy Garcia announced the winners of the 2016 LinuxQuestions.org Members Choice Awards.

    [...]

    openSUSE’s news portal was compromised Monday by a hacker or group of hackers called MuhmadEmad, via the message left in its place. A Kurdish flag with the message “HaCkeD by MuhmadEmad – KurDish HaCk3rS WaS Here” was displayed for hours before it was taken down and the site’s content restored. Roy Schestowitz has a screen capture and said that openSUSE has not yet publicly acknowledged the hack. Swapnil Bhartiya spoke to Richard Brown, openSUSE chairman, who said that site was isolated from most SUSE infrastructure, especially the distribution code. There was no breach of any contributor data either. The site in question is run by MicroFocus, but all are investigating to make sure it’s an isolated incident.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

This post is also available in Gemini over at:

gemini://gemini.techrights.org/2017/02/09/microfocus-suse-hush-hush/

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 14/4/2021: EasyOS Dunfell 2.7, Tor Browser 10.5a14

    Links for the day



  2. EPOLeaks on Misleading the Bundestag -- Part 17: Jawohl, Herr Minister!

    A French-German co-production of "Yes, Minister!" starring Raimund Lutz, Heiko Maas and Christoph Ernst. Directed by Benoît Battistell.



  3. Over 1,000 EPO Workers Initiate Legal Challenge Against the EPO's Attack on Salaries (in Defiance of Assurances Made to Workers Who Relocate to Another Country With Whole Families)

    The EPO’s attack on workers and pensioners isn’t going ahead without challenge; while the “Mafia” (what EPO workers call the management) loots the organisation it takes away money from the workers — i.e. from besieged folks who do all the work and face growing workloads during a pandemic



  4. Who is Richard Stallman?

    Reproduced with permission



  5. IRC Proceedings: Tuesday, April 13, 2021

    IRC logs for Tuesday, April 13, 2021



  6. Links 13/4/2021: FreeBSD 13.0 Final, Slackware 15.0 GNU/Linux Beta Release and OpenMandriva Lx 4.3 Plans

    Links for the day



  7. IBM Stroking the Masters

    IBM continues to diminish its weakly-supported thesis about the word “Master” being inadequate in all contexts and IBM’s front group, the Linux Foundation, has just promoted more of that same self-serving agenda in the corporate media (screenshot below from 5 minutes ago)



  8. The 'Stallman Support' Web Site and How You Can Support Truth, Not Just Software Freedom

    The Stallman Support Dot Org Web site (stallmansupport.org, "In Support of Richard Stallman“), endorsed by Stallman himself, sets the record straight while the corporate media keeps peddling lies and distortions



  9. An Examination of Correspondence Between the Tweedledum-Tweedledee Duo, Lutz and Ernst

    A quick look at the letters and E-mails sent back and forth from the current VP5 and former VP5 of the EPO, Europe’s second-largest institution that the German government has let exist outside the rule/reach of any law



  10. EPOLeaks on Misleading the Bundestag -- Part 16: An Inimitable Duo

    How the efforts to reform the EPO's data protection framework were derailed by the actions of Lutz and Ernst



  11. How the GNU Operating System Really Started (Almost a Decade Before Linux Came Out)

    Later this year Linux turns 30, but Linux is just a component added to the GNU Operating System, developed a very long time earlier based on the design of UNIX (the mainstream media likes to distort that part of history); here’s the creator of the GNU Operating System, telling me his story here in the United Kingdom (we did many clips like these and this one seems very timely)



  12. Richard Stallman: The Other Things I Have to Say I Put on Stallman.org... Reject the Idea That You Have to Accept Something Like Facebook

    Transcript below



  13. An Ode to Dr. Ernst

    THE BUDGET is right...



  14. During Pandemic, With Rising Inflation, Corrupt EPO Management With Its 'Shadow Budget' Cracks Down on Education and Childcare Allowance

    While hoarding and misusing money (by basically granting lots of patents that ought not be granted) the management of the EPO hides it aside, then proceeds to crushing salaries and benefits of staff, even pensioners



  15. IRC Proceedings: Monday, April 12, 2021

    IRC logs for Monday, April 12, 2021



  16. In Support of Richard Stallman Normalizing Truth, Reason, Dialogue: Introduction

    Reproduced with permission.



  17. Lunduke: Stallman & The FSF Respond To The Mob!

    A video response in support of RMS



  18. Links 12/4/2021: RSS Guard 3.9.2 and IBM-Funded Hacks Keep Attacking RMS

    Links for the day



  19. EPOLeaks on Misleading the Bundestag -- Part 15: Different Strokes for Different Folks

    Dr. Ernst and Raimund Lutz colluded to protect EPO management from a much-needed investigation; Ernst has since then been rewarded with a do-nothing job by António Campinos



  20. EPO President Campinos Lying to JURI

    Benjamin Henrion recorded today's hearing and uploaded it. “Campinos,” according to him, claims that (to paraphrase) “London [is] irrelevant to get UPCA running” (that’s very obviously a lie), so what we have here is António Campinos lying on behalf of the entire EPO, just as Benoît Battistelli did. Campinos has decided to “have fun,” we’ve been told, speaking of UPCA “upper law” (which is meaningless junk) at around 51:00. He clearly didn’t come prepared and he mumbles a lot. What awful leadership for what was supposed to be the best of Europe’s science…



  21. Supporting RMS With a Meme!

    As the saying goes, a picture is worth a thousand words.



  22. If You Want to Support a Real Community...

    We’ve just mentioned the fake 'community' of openSUSE and now it’s time to examine what Fedora has truly become under IBM



  23. OpenSUSE Hates Your Freedom, But It Loves the Proprietary Software Reseller That Is the True 'Master' of OpenSUSE

    OpenSUSE is inclusive of Microsoft and other companies that attack human rights and [cref 141916 enable nationalists]; but apparently what bothers OpenSUSE very, very much is the people who started the operating system SUSE is selling



  24. Links 12/4/2021: Lagrange 1.3.2, Linux 5.12 RC7

    Links for the day



  25. IRC Proceedings: Sunday, April 11, 2021

    IRC logs for Sunday, April 11, 2021



  26. EPOLeaks on Misleading the Bundestag -- Part 14: The Notorious Revolving Door

    The Benoît Battistelli-António Campinos shuffle left some people in the EPO’s upper management better off; they’re being rewarded for complicity, so there’s no incentive to do the right thing but to do the wrong thing



  27. Links 11/4/2021: GnuPG 2.3.0, Linux 5.13 Additions

    Links for the day



  28. All EPO Articles Are Available Over Gemini Protocol

    For lighter and more privacy-preserving access to Techrights use the Gemini capsule instead of the Web site



  29. Judge and JURI

    The Committee on Legal Affairs, a.k.a JURI, meets the EPO tomorrow (in 24 hours); will abuses by António Campinos and Benoît Battistelli be brought up?



  30. EPOLeaks on Misleading the Bundestag -- Part 13: The Failed Promise of a “Good Governance” Guru…

    Before becoming an absent-minded Vice-President of António Campinos Christoph Ernst was posing as the very opposite of what he would become


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts