Bonum Certa Men Certa

GBHackers On Security is Trash and It Should Probably Be Ignored (It Trash-talks Linux and SSH Based on Nothing at All)

posted by Roy Schestowitz on Dec 27, 2023,
updated Dec 27, 2023

Dialing up the Fear, Uncertainty, Doubt (FUD)

Guitar Pedal

THE Web site called "Hacker News" (no, not that censorious hub but the so-called 'news' site) is pure trash, just like "LinuxSecurity", which has just advertised itself [1] and is habitually spewing anti-Linux messages, even when totally misplacing the blame. A lot of so-called 'security' 'news' sites are like this and it's because they're run by nontechnical or barely technical people who try to sell something.

Consider this new example [2] from "GBHackers On Security". It gives readers the false impression there is something inherently wrong with SSH because hostile, unauthorised people can gain SSH access if they get a username/password combination some other way and it is also the fault of Linux... somehow.

Hackers Attacking Linux SSH Servers to Deploy Scanner Malware; Hackers often target Linux SSH servers due to their widespread use in hosting critical services, and the following loopholes make them vulnerable, providing opportunities...

Some basic research might say something like (maybe as a headline): "Compromised passwords used to access servers remotely" (do keep your passwords safe or use key-based login/s).

I used to think (or simply assume) "GB" in the site's name indicated British-ness but judging by the names in the site (never mind the sensationalism like pictures of evil aliens) it is probably Indian, just like "Hacker News". The above is by Tushar Subhra Dutta. They basically produce a high volume of low-quality, false, sensationalist junk. And no, it's not racist to point this out; my Indian friends say there's this notoriety in English-speaking sites run by Indians. A lot of SEO, chatbots etc.

Earlier this year Techrights covered many similar examples of SSH FUD (e.g. [1, 2]) - typically blaming some weak passwords like "helloworld" on SSH rather than the true culprits. Bad passwords can be taken advantage of in parallel dictionary-based attacks. Instead of focusing on one potentially well-protected server you knock on about a millions servers serially until some very common password is found to be used over port 22 (or similar).

Patched GNU/Linux is secure. OpenSSH is very secure and very selective in what new code it introduces.

_______

  1. LinuxSecurity Offers Vital Insights On Automated Linux Patch Management & Improved Security [Ed: They also spread Linux-hostile FUD in their site]
  2. Hackers Attacking Linux SSH Servers to Deploy Scanner Malware [Ed: The issue here is neither Linux nor SSH. The article itself admits it's "stolen SSH credentials." An easy way to steal SSH credentials is to look for SSH users on Windows, which has back doors and ample attack surface.]

    Threat actors deploy malware on Linux servers after logging in with stolen SSH credentials.

Other Recent Techrights' Posts

Links 13/12/2024: Military Buildup Around Taiwan, More Health Problems Associated With Social Control Media Illuminated
Links for the day
[Teaser] The EPO is Still Calling Monopolies "Products"
Coming soon
Why We Cover the Topics That We've Long Focused on (by Choice)
We'll continue to cover suppressed issues because such issues are usually obstructed
[Meme] The Reasonable Man
"The reasonable man adapts himself to the world"
International Troll Alert by Helen Plews
Helen Plews from Cybershow has this new article
The FSF (Free Software Foundation, Inc.) Can Reach Its Funding Goal of $400,000. This Bothers the Imposters and Foes of the FSF.
Software Freedom is something we must perpetually fight for
Linux Foundation Pays for LLM Slop (Puff Pieces Made by Bots) About the Linux Foundation
The so-called Linux Foundation is responsible for the production of spam and slop
General Consultative Committee (GCC) Meeting at the European Patent Office (EPO) Shows Existing Problems
the "real problems" and why "digitalisation" doesn't solve them
 
Gemini Links 13/12/2024: "Virtue Signaling", Gopher, HTML and the 90s Web Aesthetic
Links for the day
Maybe - and Hopefully - More News Sites Will Go "Static" (More New Material Published But Established Pages Served Directly From the File System)
Keeping things simple and light is important for the sake of scaling
[Meme] Vendor Capture for 'Civility's Sake'
"I CoCed him already"
Anonymity for Sources
At the moment we can learn about stories in person or in encrypted voice chat
What Topics We Prioritise
On fishing for topics to cover
Oligarch-Owned Media Twists the Narrative and Demands More Surveillance
Corruption is the real issue here
Windows Falls to Single-Digit "Market Share" in Benin
Windows has fallen even further
[Meme] Doing Online Activism in Social Control Media
Dictators have always loved lists
Gemini Links 13/12/2024: Creative Moods, Berkeley DB, and More
Links for the day
Microsoft Windows Falls to New All-Time Low in Guatemala (Less Than a Quarter)
When it comes to operating systems, we don't think we've mentioned it before
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, December 12, 2024
IRC logs for Thursday, December 12, 2024
[Meme] Leave My /home Alone
A new version of Systemd
There's a New Version of Lagrange (Gemini Reader) and Its Developer is Making an IDE/Editor
I share or reciprocate almost anything I can through Gemini Protocol
Nick's Job at OSI: Promote Microsoft, Promote Proprietary Software
This is what Microsoft pays him to do
[Meme] Award-Winning Back-stabbing Opportunists
part of the rebel alliance
Azerbaijan Rejects Microsoft
Azerbaijan seems to have very little interest in Microsoft
[Meme] You Just Grab Him by the CoC
Sponsors of Python Software Foundation... "You don't like Python's corporate sponsor?"
Explaining What Deb Nicholson Does to the Python Software Foundation
Of course the OSI, which Nicholson also occupied, still helps Microsoft attack copyleft
IBM Said to Be Firing People Days Before Christmas
IBM is entering taboo territories
Microsoft Falls to Just 11% in Ivory Coast
Microsoft tried hard to catch up in mobile
Links 12/12/2024: Shell Settles With Greenpeace, DOJ Whistleblower Pilot Program
Links for the day
Gemini Links 12/12/2024: AuraGem TV and Advent of Code 2024
Links for the day
Fake "Linux" News, Produced by Microsoft Chatbots in 'Brittany Day' or "LinuxSecurity" Clothing
She's back at it
Microsoft OSI Promoting GitHub, Which is Proprietary and a Massive GPL Violator
OSI works for Microsoft, speaks for Microsoft, promotes proprietary software
Links 12/12/2024: Another 'Self-driving' Cars Dead End, Infowars Sale Blocked by Court
Links for the day
Links 12/12/2024: "Hey Hi" Hype Debunked, ActivityPub and Gemini Software on Same Server
Links for the day
Google Has Only Solidified Its Search Monopoly in Africa Since Microsoft's Chatbot/LLM Hype Started
Africa is basically a "Failed Market" to Microsoft
[Teaser] EPO is Running Out of Brains
EPO has been in the business of offering fake patents
South Korea Has Its Own Alternative to IBM's Proprietary RHEL
Owing to the Open Enterprise Linux Association (OpenELA)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, December 11, 2024
IRC logs for Wednesday, December 11, 2024
Fresh Rumour of Wave of IBM Layoffs Less Than a Fortnight Before Xmas Day
Unverified and anonymous
Links 11/12/2024: Additional Surveillance Ambitions and Cyberattacks on Sudanese Media
Links for the day
Links 11/12/2024: More Google Layoffs Rumoured for January, 'Linux' Foundation Colonises India
Links for the day
Mozilla's Firefox is Floundering, in the United Kingdom Its Share Fell to 2% This Month
HTTPS is becoming little but a transport layer for Chrome-like browsers, i.e. proprietary things with DRM and perhaps attestation (which means you cannot modify them; you'd get blocked for trying)
Protecting People From So-called 'Social Media' is Not Censorship (No More Than Banning or Restricting Access to Cigarettes is 'Censorship')
it's not censorship when the thing you are censoring [sic] is itself a censorship powerhouse operated by a foreign and hostile nation (or oligarchs of Musk's nature)
[Meme] Solving Real Problems With So-called 'Social Media'?
Feeding and medically treating animals helps, unlike "likes"
Links 11/12/2024: Climate Warming, 'People Can Fly' Layoffs
Links for the day
Gemini Links 11/12/2024: LLMs as Plagiarism, Advent of Code 2024 Momentum
Links for the day
In United Arab Emirates (UAE), Microsoft Now on One in 8 Internet-Connected Devices?
Web-connected clients are becoming scarce that run Microsoft operating systems (Windows)
IBM and Microsoft Hats at Linux Foundation
"Fedora Project Leader Matthew Miller: A change of hats!"
IBM's Latest Fedora Divestment Speaks for Itself
Microsoft must be very pleased with what IBM is doing
Why is UK Press Gazette Jingoistic About Plagiarists and LLM Slop Disguised as Journalism?
Press Gazette appears to be participating in the attack on honest journalism
EPO is Corrupt Like Always, What Changed is the Lack of Media Coverage (No Transparency Means No Democracy)
We need to revive online media and encourage dissent
[Meme] How NOT to Do Activism Online
So many self-professed liberals continue participating and driving traffic (ads) in X
In Central Africa, Which is Bigger Than Europe, Windows is About 5% in Terms of "Market Share"
they apparently got so fed up with colonialism
Communicating Outside of Skinnerboxes and Social Control Media
Tackling collective isolation and miscommunication (or communications being controlled by middlemen)
Number of Libera.Chat Users (Simultaneously Online) Falls to Lowest Figure in Over 3 Years
Notice the downward trend/curve in recent months
[Meme] Social Control Media is NOT Free Speech
It's time to discard that stupid argument that banning an abusive censor is "censorship"
Banning Not Only TikTok... if Not for FOMOC (Fear of Missing on Constituents)
It's a sort of addiction by peer pressure
Shedding Light on How the EPO Sheds Off Staff in Order to Grant Loads of Invalid (Fake) Patents in Europe
The people who decide on these policies lack a background in science
Montenegro's Share of GNU/Linux Reaches All-Time High
We don't really know why, but that's just what the data from statCounter suggests
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, December 10, 2024
IRC logs for Tuesday, December 10, 2024