Bonum Certa Men Certa

The Next OpenSSL Bug Will Likely Disappoint Those Who Believe the Linux-Hostile Media

Video download link | md5sum 4b7ddbb46fa6769b563d42abfd3763b2 Trusting the FUD Blindly Creative Commons Attribution-No Derivative Works 4.0



Summary: Fear, Uncertainty, and Doubt (FUD) campaigns have begun based on a lack of information rather than actual substance; Dramatisation of this kind merits a debate as the boy keeps crying "wolf!" in vain (because he sees a dog)

OVER the past 5 or so days we've included in Daily Links many articles about an upcoming patch for OpenSSL, not "imminently" as this was disclosed almost a week in advance, which is rather unusual (that long a timespan).



We've patiently been wanting to do a a response, waiting for insiders who can tell what the bug was or how severe it really was; we scolded some media for calling it "zero day" because as far as we can tell the term is misapplied, maybe even on purpose.

"A lot of the media reports, not privy to any details, trust the panic makers despite having no details. Where's the fact-checking?"So many speculative, uninformed and uninformative articles have mentioned the magic "FUDword", Heartbleed, still failing to recognise that it was a bug first discovered by Google and then hyped up by Microsofters to stigmatise Free software (we wrote a lot about this at the time). This was almost a decade ago; after that we saw many logos and sites (for pertinent bugs, not pieces of software) and even the occasional pranks after that, trying to reproduce that hype's success [sic] because FUD travels fast and some firms wanted to "make a name" for themselves.

People with access to information or special privileges already caution us that the advanced notice is more about hype than substance. A lot of the media reports, not privy to any details, trust the panic makers despite having no details. Where's the fact-checking?

Seeing how "Heartbleed" FUD was used by Microsoft for years (and "log4j" a year later, even by the anti-Linux Foundation), it seems likely that this is a campaign of drama, not a real security crisis. How many breaches will be caused by this? Time will tell, but probably not many (same as "Heartbleed", where reality didn't match the propaganda).

Recent Techrights' Posts

Topics We Lacked Time to Cover
Due to a Microsoft event (an annual malware fest for lobbying and marketing purposes) there was also a lot of Microsoft propaganda
EPO Education: Workers Resort to Legal Actions (Many Cases) Against the Administration
At the moment the casualties of EPO corruption include the EPO's own staff
 
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, November 22, 2024
IRC logs for Friday, November 22, 2024
Gemini Links 23/11/2024: 150 Day Streak in Duolingo and ICBMs
Links for the day
Links 22/11/2024: Dynamic Pricing Practice and Monopoly Abuses
Links for the day
Microsofters Try to Defund the Free Software Foundation (by Attacking Its Founder This Week) and They Tell People to Instead Give Money to Microsoft Front Groups
Microsoft people try to outspend their critics and harass them
[Meme] EPO for the Kids' Future (or Lack of It)
Patents can last two decades and grow with (or catch up with) the kids
Gemini Links 22/11/2024: ChromeOS, Search Engines, Regular Expressions
Links for the day
This Month is the 11th Month of This Year With Mass Layoffs at Microsoft (So Far It's Happening Every Month This Year, More Announced Hours Ago)
Now they even admit it
Links 22/11/2024: Software Patents Squashed, Russia Starts Using ICBMs
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, November 21, 2024
IRC logs for Thursday, November 21, 2024
Gemini Links 21/11/2024: Alphabetising 400 Books and Giving the Internet up
Links for the day
Links 21/11/2024: TikTok Fighting Bans, Bluesky Failing Users
Links for the day
Links 21/11/2024: SpaceX Repeatedly Failing (Taxpayers Fund Failure), Russian Disinformation Spreading
Links for the day
Richard Stallman Earned Two More Honorary Doctorates Last Month
Two more doctorate degrees
KillerStartups.com is an LLM Spam Site That Sometimes Covers 'Linux' (Spams the Term)
It only serves to distract from real articles
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, November 20, 2024
IRC logs for Wednesday, November 20, 2024