Bonum Certa Men Certa

White House Asking Proprietary Software Companies That Add NSA Back Doors About Their Views on 'Open Source' Security

Video download link | md5sum 660351fe04a47c33611de299d17501b4 GAFAM Finger-pointing for White House Creative Commons Attribution-No Derivative Works 4.0



Summary: The US government wants us to think that in order to tackle security issues we need to reach out to the collective 'wisdom' of the very culprits who created the security mess in the first place (even by intention, for imperialistic objectives)

THE very same companies that back-door their own software (i.e. deliberately make their products not secure) have been asked by the American administration for their views on the security of Free software and security of such software, which isn't defective by design, maybe just by accident, occasionally.



We've already commented on this ludicrous situation in passing (in our Daily Links). The biggest National Security threat (Microsoft) is infiltrating panels on security, diverting attention away from the biggest threats to lesser threats, which are usually the solution, too. Lobbying? Outright political corruption? Both?

Either way, the above video concerns this new article, which is only one of many. We already listed about half a dozen earlier today. The author is so clueless that he calls the Linux Foundation the "Linux Open Source Foundation" and names IBM/Red Hat as if they're separate entities. The same for GitHub and Microsoft. To quote: "The full tech participant list includes Akamai, Amazon, Apache Software Foundation, Apple, Cloudflare, Facebook/Meta, GitHub, Google, IBM, Linux Open Source Foundation, Microsoft, Oracle, RedHat and VMware."

Of the above, only the Apache Software Foundation (ASF) actually speaks for Free/Open Source software. Yes, Zemlin's PAC is little but a front group for some of those other companies.

Why are all the companies invited (assuming Red Hat is just IBM) to discuss this matter dripping "conflict of interest" and how can this establish trust? Why don't they also discuss the threat posed by proprietary software? Some of the headlines that emerged afterwards want us to think that "Open Source" -- not Microsoft et al -- is the real "national security" threat. We'll omit links to those "reports"... (FUD)

“...any real plan has to eliminate Microsoft from both the desktop and the supporting infrastructure. That is a staffing problem, not a technical one.”
      --Techrights associate
"Speaking of politics," an associate noted today, "notice that the US' concern about critical infrastructure is shifting all of the blame and attention on to FOSS. At the same time only the big, proprietary vendors are invited to the planning sessions with the government. They bring in clowns instead of the big names. They should at least be consulting with Bruce Perens, Bruce Schneier, Dan Geer, Moxie Marlinspike, Eugene Spafford, Daniel Bernstein, Paul Vixie etc. (notice that Spaf's quote about Windows is now missing from pretty much every page that includes his old quotes...)"

And "even RMS and Linus Torvalds could add benefit if they had not been reframed as controversial by the attackers now moving in and out of DC. Wietse Venema is in the US too... Phil Zimmermann is still around too. Many of those involved in LibreSSL and OpenSSL are in the US as well... the list of knowledgeable, skilled, experienced people is long. No need for them to include any frauds, charlatans, or poseurs. But that's what we get when Microsoft reps got in on the campaign team. Microsoft created the problems, and therefore is unable to solve them and it would be inappropriate to even have them involved. There's a famous quote which goes approximately like this, "we cannot solve our problems with the same thinking we used to create them." As such Microsoft representatives have to be cleared from the room long, long before discussion can start. Ransomware is just one symptom of microsoftianism. Even if Windows is retained for a shorter period on the desktop, servers could run FreeBSD with OpenZFS.The snapshotting feature would make data restoration much less inconvenient. However, any real plan has to eliminate Microsoft from both the desktop and the supporting infrastructure. That is a staffing problem, not a technical one. Even Microsofters, such as Mitchel Lewis, observe that, but most don't dare speak up. I presume fear of NDAs and non-disparagement clauses in various contracts, especially terminations."

“Microsoft created the problems, and therefore is unable to solve them and it would be inappropriate to even have them involved.”
      --Techrights associate
The number of articles we saw about Log4j that cited Microsoft as if it was a security expert was truly worrying. Since when does Microsoft get to play "concern troll" about "Open Source"?

"About the disappearance of the Spafford quote," our associate noted: "It used to be cited everywhere but most of those sites are gone and the rest seem to have redacted just that one quote."

Recent Techrights' Posts

Certificate Authority Let's Encrypt Has Almost Gone Down to Zero, Nearly Totally Extinct in Geminispace, the Few Capsules Still Using It Are Spam/Dead/Stagnant
This represents another decrease for Let's Encrypt; the last decrease was last week
Trying to Silence Techrights Was a Huge Mistake
Peter Thiel attacked a publisher for asserting, correctly, that he was gay. Now everyone knows it.
 
Gemini Links 07/09/2025: Scanner, Slop, and Chadobear
Links for the day
The UEFI 9/11 is 3 Days Away
Nobody denies that bad things will happen
Google Versus Journalism
Google played a big role in the demise of news sites
Gemini Links 07/09/2025: Advertising, Decentralized Archival, and Outsourcing to Bezos
Links for the day
Not Much Left in News Cycles
To be very clear, this does not describe "Linux" anything; it's true in just about every facet of news, except the paid-for fake "journalism" about "hey hi" (sites getting paid explicitly to maintain or rekindle hype)
Throwing Away "Old" Computers (Mozilla and Other Climate Deniers)
Mozilla is not leftist
The UEFI 9/11 - Part VIII - Denial of Service and Selling Us WSL (Windows) Instead of "Risky" (Prone by Breakage by Microsoft) GNU/Linux
Restricted Boot (so-called 'SecureBoot') does not improve security. It is nothing but trouble. It's meant to trouble non-Windows users. In dual-boot setups, SecureBoot is a recipe for disaster because Microsoft keeps erasing or tampering with the boot sector, to paraphrase an associate
Slop is Extremely Rare in Geminispace, Slop Images Are Unheard Of (Despite Images Being Supported)
As long as Geminispace grows in terms of domains it's safe to predict the protocol will still be used in 2029 and hence Geminispace will turn 10
Links 07/09/2025: Robodebt Class Action, Fines, and Copyright Settlement
Links for the day
Links 07/09/2025: Yle Impersonated in Social Control Media, Boat-Attacking Orcas, Midjourney Sued Again
Links for the day
Slopwatch: LinuxSecurity, Linux Journal, and the Serial Slopper
Google won't tackle the issue because Google participates not only in relaying slop but also in generating lots of it
Links 07/09/2025: Google Fines in EU and "Your Internet Access Is at Risk"
Links for the day
Gemini Links 07/09/2025: Little Brother and Corporate Theatre
Links for the day
Links 07/09/2025: More Harms of Slop and Anthropic's Nightmare Scenario (Huge Legal Liabilities for Slop)
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 06, 2025
IRC logs for Saturday, September 06, 2025
Microsoft Sites Now Talking About September's Mass Layoffs at Microsoft
It's noteworthy that even Microsoft's MSN now covers the latest revelations about mass layoffs
Gemini Links 06/09/2025: SpellBinding Moving and "The Cloud" Ridiculed
Links for the day
Slopwatch: On "the Apology Industry", Chatbots (Punchbag for Customers), and Fake Articles About "Linux"
"news reporting priorities changed"
Links 06/09/2025: "Covid Incidence on the Rise" and Many Attacks on the Press Worldwide
Links for the day
The Register Bill
The Register MS - putting the "MS" in your centre of the universe
Analogies for "Memory Safety" in Rust
Don't worry, it's Rust! It can do anything!
Nobody Denies That SecureBoot Will Cause Problems After September 11
Not even Microsoft
Gemini Links 06/09/2025: Infinite Scrolling and Posting from Emacs
Links for the day
Links 06/09/2025: GitHub Meltdown Over Slop, "U.S. Jury Says Google Should Pay $425 Million in Privacy Lawsuit"
Links for the day
Despite Its Severe Financial Problems Gnome Foundation Inc Paid Rosanna Yuen Over 100,000 Dollars Last Year
maybe relocation should be considered
The "Left" and the Right"
It poisons everything
Mozilla and Rust Are Not Leftists
they're part of the mass consumerism machine
Disposable to Microsoft
There is an extensive set of people who got used by Microsoft, only to be thrown away a month later or a year later or a decade later
The UEFI 9/11 - Part VII - This Coming Week Many PCs Will Refuse to Boot "Linux" (Because of Microsoft's Expired Certificate)
The real solution is, disable "secure boot" or "SecureBoot" while it's still possible. [...] Just like submarine patents, a lot of this problem was "hibernating" for a while
The Thing Nobody in Red Hat Wants to Talk About Openly
There is a real sentiment or worry among Red Hatters, Europeans and Americans in particulars (because of higher salary expectations)
Slopwatch: Small Parade of Fake News About "Linux" and Scams Borrowing the Name (or Word) "Linux"
In practice, LLMs are a risk
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, September 05, 2025
IRC logs for Friday, September 05, 2025
Genini Links 05/09/2025: Community, ROOPHLOCH, and PITkit
Links for the day
Links 05/09/2025: Vaccine Sceptics Poison the Well, Two Exploited Vulnerabilities Patched in Android
Links for the day
Gemini Links 05/09/2025: Logitech Lift and DIY Gemini Servers
Links for the day
Links 05/09/2025: Sainsbury's Caught Spying on In-Store Shoppers and Microsoft "OpenAI is Using Legal Threats to Harass its Critics"
Links for the day
BASIC Predates Microsoft by Over a Decade, Microsoft-Controlled Sites Like The Register MS Don't Want You to Know This
The state of the media is really bad when it relies a lot on oligarchs' money and is appointing editors who are working for oligarchs
Brian Kernighan, "Only Third to Dennis Richie and Ken Thompson" (UNIX), Agreed With Someone Who Said Rust Was Just Hype, Should Not Replace C
17 hours ago
Reminder: Microsoft's "Secure Boot" Certificate for "Linux" Will be Expired in One Week
Many PCs won't manage to 'rotate' to another certificate
"Many of the Red Hat Employees Are Still Looking for Work"
Shame on IBM's CEO
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 04, 2025
IRC logs for Thursday, September 04, 2025
Microsoft Started With Code Literally From The Trash, Nothing Has Improved Since
The reality is, there are systems and code that are reliable. But they're not Microsoft's.
Hypothesis That New McKinsey/Microsoft Executive Inside Red Hat Will Outsource Research and Development Operations to India (Like They Do in IBM)
IBM is floundering
Slopwatch: Scams, Fake Articles About "Linux", Plagiarism, and Worse
Perhaps some time soon the LLMs or the "Big LLMs" will run out of money (to borrow) and go offline, leaving those slopfarms in a tough place