EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

02.09.17

OpenSUSE’s (or SUSE’s) Refusal to Publicly Acknowledge It Got Cracked Shows Face-Saving Arrogance Just Like Novell’s

Posted in Deception, Novell, OpenSUSE, Security, Servers, SLES/SLED at 6:16 am by Dr. Roy Schestowitz

SUSE (or MicroFocus) won’t even tell customers when its systems are in fact compromised

Novell cuffs

Summary: The same old and very notorious behaviour we found in Novell persists at SUSE under MicroFocus leadership; security neglected and keeping up appearances more important than honesty

TECHRIGHTS wrote many thousands of articles about Novell. We know Novell extremely well and we have documented its terrible behaviour for over half a decade, well before we began focusing on the EPO for example. As we shall show later, in a separate post, Microsoft’s and Novell’s “IP Peace of Mind” is making a comeback (as of last night), but right now we wish to focus on the crack I first wrote about on Monday (it has since then generated some press coverage, e.g. [1-3] below).

“Remember that no evidence has been presented by SUSE and moreover the gross negligence here is a bad sign in general.”A lot of people still miss the key point. IDG even went ahead with a rather misleading headline, as did Softpedia; rather than state the actual news (that OpenSUSE got cracked) the title says or overstates the ‘damage control’ from SUSE, diverting attention to what was not affected rather than what was affected (a politician’s trick). We used to see lots of that kind of spin back in the Novell days and the 2 articles below, having sought comment from SUSE, give SUSE the benefit of the doubt here. Remember that no evidence has been presented by SUSE and moreover the gross negligence here is a bad sign in general. That’s just “faith-based” security. My article about it was so short that it was mostly a screenshot, yet we understand that further coverage is on its way. So let’s elaborate a little. “They were using an outdated version of WordPress and got zapped,” one person wrote to me after I had published my findings. “It was just the front-end, no code was touched.” But says who? SUSE? Can we believe them?

“Nobody has yet covered that issue as properly as we hoped (poor security practices at SUSE) and the fact that they COMPLETELY FAILED or refused to publicly acknowledge what had happened is a serious aspect of it.”Whatever caused the defacement, it shows that they lost control of their platform. They did get cracked. Softpedia reported that “openSUSE devs immediately restored the news.opensuse.org website from a recent backup” (so the back end too appears to have been compromised).

Nobody has yet covered that issue as properly as we hoped (poor security practices at SUSE) and the fact that they COMPLETELY FAILED or refused to publicly acknowledge what had happened is a serious aspect of it. We waited patiently to see if an announcement would be made by then, even a reassurance that users should not worry. But nothing came out! To this date (half a week later). They attempted to cover it up, which is BAD BAD BAD. For a so-called “Enterprise-Grade” thing which SUSE tries to market itself as (selling SLE*) this is a serious breach of trust. Who would trust SUSE now?

“If someone injected a back door inside SLED and SLES, SUSE would probably say not a thing, only belatedly removing it and then lying about the whole thing, just like Microsoft does.”3 news sites and my own site wrote about it, but not a single word has been uttered by SUSE. They know they got cracked and they are not telling anyone, except when journalists ask them for comment (and press them with evidence).

OpenSUSE has a history of security issues in its sites (see “openSUSE Forum Hacked; 79500 Users Data Compromised” from 2014). Where are the reporters who are willing to ask SUSE some tough questions? Don’t let this slide. If someone injected a back door inside SLED and SLES, SUSE would probably say not a thing, only belatedly removing it and then lying about the whole thing, just like Microsoft does.

In the news:

  1. Kurdish Hacker Posts Anti-ISIS Message on openSUSE’s Website, Data Remains Safe

    Softpedia was informed by Dr. Roy Schestowitz that the openSUSE News (news.opensuse.org) website got defaced by Kurdish hacker MuhmadEmad on the day of February 6, 2017.

    It would appear that the server where the news.opensuse.org website is hosted is isolated from the rest of openSUSE’s infrastructure, which means that the hacker did not have access to any contributor data, such as email and passwords, nor to the ISO images of the openSUSE Linux operating system.

    We already talked with openSUSE Chairman Richard Brown, who confirms for Softpedia that the offered openSUSE downloads remain safe and consistent, and users should not worry about anything. The vigilant openSUSE devs immediately restored the news.opensuse.org website from a recent backup, so everything is operating normally at this time.

  2. OpenSUSE site hacked; quickly restored

    The openSUSE team acted quickly to restore the site. When I talked to Richard Brown, openSUSE chairman, he said that “the server that hosts ‘news.opensuse.org’ is isolated from the majority of openSUSE infrastructure by design, so there was no breach of any other part of openSUSEs infrastructure, especially our build, test and download systems. Our offered downloads remain safe and consistent and there was no breach of any openSUSE contributor data.”

    The team is still investigating the reason for the breach so I don’t have much information. The site ran a WordPress install and it seems that WordPress was compromised.

    This site is not managed by the SUSE or openSUSE team. It is handled by the IT team of MicroFocus. However, Brown said that SUSE management certainly doesn’t want any such incident to happen again and they are considering moving the site to the infrastructure managed by SUSE and openSUSE team.

  3. Best Distros, openSUSE Whoops, Debian 9 One Step Closer

    In the latest Linux news, the news.opensuse.org got hacked and displayed “KurDish HaCk3rS WaS Here” for a while Monday and while the site has been restored, no comment on the hack has been issued. Elsewhere, Debian 9.0 has entered its final freeze in the last steps in preparations for release. FOSS Force has named their winner for top distro of 2016 and Swapnil Bhartiya shared his picks for the best for 2017. Blogger DarkDuck said MX-16 Xfce is “very close to the ideal” and Alwan Rosyidi found Solus OS is giving Elementary OS a run for its money. Phoronix.com’s Michael Larabel explained why he uses Fedora and Jeremy Garcia announced the winners of the 2016 LinuxQuestions.org Members Choice Awards.

    [...]

    openSUSE’s news portal was compromised Monday by a hacker or group of hackers called MuhmadEmad, via the message left in its place. A Kurdish flag with the message “HaCkeD by MuhmadEmad – KurDish HaCk3rS WaS Here” was displayed for hours before it was taken down and the site’s content restored. Roy Schestowitz has a screen capture and said that openSUSE has not yet publicly acknowledged the hack. Swapnil Bhartiya spoke to Richard Brown, openSUSE chairman, who said that site was isolated from most SUSE infrastructure, especially the distribution code. There was no breach of any contributor data either. The site in question is run by MicroFocus, but all are investigating to make sure it’s an isolated incident.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Patents on Abstract Things and on Life (or Patents Which Threaten Lives) Merely Threaten the Very Legitimacy of Patent Offices, Including EPO

    Patent Hubris and maximalism pose a threat or a major risk to the very system that they claim to be championing; by reducing the barrier to entry (i.e. introducing low-quality or socially detrimental patents) they merely embolden ardent critics who demand patent systems as a whole be abolished; the EPO is nowadays a leading example of it



  2. Links 10/12/2018: Linux 4.20 RC6 and Git 2.20

    Links for the day



  3. US Courts Make the United States' Patent System Sane Again

    35 U.S.C. § 101 (Section 101), the Patent Trial and Appeal Board (PTAB) and other factors are making the patent system in the US a lot more sane



  4. Today's USPTO Grants a Lot of Fake Patents, Software Patents That Courts Would Invalidate

    The 35 U.S.C. § 101 effect is very much real; patents on abstract/nonphysical ideas get invalidated en masse (in courts/PTAB) and Director Andrei Iancu refuses to pay attention as if he's above the law and court rulings don't apply to him



  5. A Month After Microsoft Claimed Patent 'Truce' Its Patent Trolls Keep Attacking Microsoft's Rivals

    Microsoft's legal department relies on its vultures (to whom it passes money and patents) to sue its rivals; but other than that, Microsoft is a wonderful company!



  6. Good News: US Supreme Court Rejects Efforts to Revisit Alice, Most Software Patents to Remain Worthless

    35 U.S.C. § 101 will likely remain in tact for a long time to come; courts have come to grips with the status quo, as even the Federal Circuit approves the large majority of invalidations by the Patent Trial and Appeal Board’s (PTAB) panels, initiated by inter partes reviews (IPRs)



  7. Florian Müller's Article About SEPs and the EPO

    Report from the court in Munich, where the EPO is based



  8. EPO Vice-President Željko Topić in New Article About Corruption in Croatia

    The Croatian newspaper 7Dnevno has an outline of what Željko Topić has done in Croatia and in the EPO in Munich; it argues that this seriously erodes Croatia's national brand/identity



  9. The Quality of European Patents Continues to Deteriorate Under António Campinos and Software Patents Are Advocated Every Day

    The EPC in the European Patent Office and 35 U.S.C. § 101 in the USPTO annul most if not all software patents; under António Campinos, however, software patents are being granted in Europe and the USPTO exploits similar tricks



  10. Team UPC is Still Spreading False Rumours in an Effort to Trick Politicians and Pressure Judges

    Abuses at the European Patent Office, political turmoil and an obvious legislative coup by a self-serving occupation that produces nothing have already doomed the Unitary Patent or Unified Patent Court (UPC); so now we deal with complete fabrications from Team UPC as they're struggling to make something out of nothing, anonymously smearing opposition to the UPC and anonymously making stuff up



  11. Patents on Life and Patents That Kill the Poor Would Only Delegitimise the European Patent Office

    After Mayo, Myriad and other SCOTUS cases (the basis of 35 U.S.C. § 101) the U.S. Patent and Trademark Office is reluctant to grant patents on life; the European Patent Office (EPO), however, goes in the opposite direction, even in defiance of the European Patent Convention



  12. EPO 'Untapped Potential'

    "Campinos is diligently looking for ways to further increase the Office’s output without increasing the number of examiners," says the EPO-FLIER team



  13. Links 9/12/2018: New Linux Stable Releases (Notably Linux 4.19.8), RC Coming, and Unifont 11.0.03

    Links for the day



  14. Links 8/12/2018: Mesa 18.3.0, Mageia 7 Beta, WordPress 5.0

    Links for the day



  15. The European Patent Organisation is Like a Private Club and Roland Grossenbacher is Back in It

    In the absence of Benoît Battistelli quality control at the EPO is still not effective; patents are being granted like the sole goal is to increase so-called 'production' (or profit), appeals are being subjected to threats from Office management, and external courts (courts that assess patents outside the jurisdiction of the Office/Organisation) are being targeted with a long-sought replacement like the Unified Patent Court, or UPC (Unitary Patent)



  16. Links 7/12/2018: GNU Guix, GuixSD 0.16.0, GCC 7.4, PHP 7.3.0 Released

    Links for the day



  17. The Federal Circuit's Decision on Ancora Technologies v HTC America is the Rare Exception, Not the Norm

    Even though the PTAB does not automatically reject every patent when 35 U.S.C. § 101 gets invoked we're supposed to think that somehow things are changing in favour of patent maximalists; but all they do is obsess over something old (as old as a month ago) and hardly controversial



  18. The European Patent Office Remains a Lawless Place Where Judges Are Afraid of the Banker in Chief

    With the former banker Campinos replacing the politician Battistelli and seeking to have far more powers it would be insane for the German Constitutional Court to ever allow anything remotely like the UPC; sites that are sponsored by Team UPC, however, try to influence outcomes, pushing patent maximalism and diminishing the role of patent judges



  19. Many of the Same People Are Still in Charge of the European Patent Office Even Though They Broke the Law

    "EPO’s art collection honoured with award," the EPO writes, choosing to distract from what actually goes on at the Office and has never been properly dealt with



  20. Links 6/12/2018: FreeNAS 11.2, Mesa 18.3 Later Today, Fedora Elections

    Links for the day



  21. EPO, in Its Patent Trolls-Infested Forum, Admits It is Granting Bogus Software Patents Under the Guise of 'Blockchain'

    Yesterday's embarrassing event of the EPO was a festival of the litigation giants and trolls, who shrewdly disguise patents on algorithms using all sorts of fashionable words that often don't mean anything (or deviate greatly from their original meanings)



  22. The Patent Litigation Bubble is Imploding in the US While the UPC Dies in Europe

    The meta-industry which profits from feuds, disputes, threats and blackmail isn't doing too well; even in Europe, where it worked hard for a number of years to institute a horrible litigation system which favours global plaintiffs (patent trolls, opportunists and monopolists), these things are going up in flames



  23. Links 5/12/2018: Epic Games Store, CrossOver 18.1.0, Important Kubernetes Patch

    Links for the day



  24. Links 4/12/2018: LibrePCB 0.1.0, SQLite 3.26.0, PhysX Code

    Links for the day



  25. EPO Management Keeps Embarrassing Itself, UPC More Dead Than Before, and Nokia Turns Aggressive

    The EPO’s race to the bottom of patent quality continues, it’s now complemented by direct association with patent trolls and law stands in their way (for they repeatedly violate the law)



  26. The Intellectual Property Owners Association (IPO) and IBM Are Part of the Software Patents Problem in the United States

    IBM's special role in lobbying for software patents (and against PTAB) needs to be highlighted; even Ethereum’s co-founder isn't happy about IBM's meddling in the blockchain space (with help from Hyperledger/Linux Foundation)



  27. The Patent Trial and Appeal Board (PTAB) Not Falling for Attempts to Prevent It From Instituting Challenges

    In the face of patent maximalists' endless efforts to derail patent quality the tribunal keeps calm and carries on smashing bad patents



  28. Links 2/12/2018: Linux 4.20 RC5, Snapcraft 3.0, VirtualBox 6.0 Beta 3

    Links for the day



  29. The Patent Microcosm Hopes That the Federal Circuit Will Get 'Tired' of Rejecting Software Patents

    Trolls-friendly sites aren't tolerating this court's habit of saying "no" to software patents; the Chief Judge meanwhile acknowledges that they're being overrun by a growing number of cases/appeals



  30. 35 U.S.C. § 101 Continues to Crush Software Patents and Even Microsoft Joins 'the Fun'

    The Court of Appeals for the Federal Circuit (CAFC) and even courts below it continue to throw out software patents or send them back to PTAB and lower courts; there is virtually nothing for patent maximalists to celebrate any longer


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts