Bonum Certa Men Certa

Richard Stallman Was Right and What Happened in XZ Wasn't a "Linux" or Free Software Problem, It Was Social Engineering (This Happens in Proprietary Software Too and, in This Case, It Was Enabled by Microsoft's Proprietary Social Control Media Disguised as 'Codeforge')

posted by Roy Schestowitz on Apr 02, 2024

Fractal image with penguin drawing

The truth isn't convenient to snakeoil vendors and charlatans who speak of "secure" boot while using proprietary GitHub (controlled by NSA)

THE Web - and even Geminispace - is already full of articles on this topic (we caught and collected about 100 so far; obviously there's lots more, not only in English). We've had plenty of time to assess and digest the facts, not the drama, and we want to remind readers that Richard Stallman (RMS) used to include in his talks (over 10 years ago) a section on how people who worked for Microsoft in Asia put back doors in the code and then got caught. It is possible more existed and never got caught.

RMS was right. He spoke about back doors well before the Edward Snowden NSA and GCHQ leaks. Techrights already included links to such RMS talks in 2008. Maybe even 2007. This is well documented, both in text and in videos.

So headlines such as this are misleading:

Malicious xz backdoor reveals fragility of open source; This also happens in proprietary software, but unreported to us

No, it's not a "FOSS" or "Open Source" issue; "This also happens in proprietary software, but unreported to us," as the above says. They try to cover this up and we cannot see commit details/author, so who the heck knows the full, ugly truth? The PR people? Whose task is to belittle or hide embarrassments?

An associate of ours insists that the xz incident was essentially social engineering; "other projects have lone developers, meaning that the code is more vulnerable because only a single person needs to be replaced / cancelled to get at the repository."

We don't suppose that in the sea/ocean of hundreds if not thousands of blog posts people will notice, but in the first day of us writing about it the primary article got 1618 non-bot reads and in the sister site 1696 non-bot reads. Sadly the loudest and best funded sites get more visibility. The crowd in Phoronix Forums shouts down pro-Linux people now (we saw that!); Phoronix itself plays a considerable role in pro-Microsoft propaganda and some of the FUD, including the above (Phoronix increasingly sucks basically).

When it comes to xz, we've reached the point of topic fatigue, so no matter how important or valuable a contribution people have to this issue, not many people will pay attention anymore due to the volume and the perception that consensus about it is old and settled.

Our associate explains that Microsoft is "hyping xz to FUD the open source development model in general and the resulting software specifically. Though there is a problem: Debian failed to drop xz when the number of active developers on it went down to 1."

"A well-practiced preventative method would have stopped the bug in its tracks. Do like OpenBSD does and have two other developers review and audit each patch. So that sets the minimum level at 3 for any project to stay in use. Simply put, the mistake is also technical as xz is an inferior archival format compared to other compression methods. So three strikes there."

We will once again write regarding the xz incident (it's hyped up for several reasons) when the dust 'settles', but having seen several sites that borrow from old tactics ("heartbleed"), that might take weeks. "Log4j" (or Shell) was still mentioned years after it had been patched and the Linux Foundation gleefully participated in the FUD. Yes, for years! Remember what they're trying to sell (clue: not Linux).

An associate thinks it'll be a few days before it is timely to "analyze the xz incident", but maybe that's optimistic. "Mostly it is the reaction and spin which should be examined," he said. We still collect links and we will use those later (we add many "Ed" or editorial comments along the way, so it is annotated a bit).

For the time being people can see the editorial comments... (these comments try to rebut key points, repeatedly, in few words)

Other Recent Techrights' Posts

If Your Company Lost About 30% of Its 'Value' in 3 Months, Then Maybe It Was Never Worth What You Claimed
Does that make sense?
Pleroma is Dying
The last social control media that I joined was Pleroma
Asia and Social Control Media
statCounter reckons it's down from over 10% to just 3% since it began tracking those things
Anonymous Threats Against My Wife and Against Yours Truly
Promoting GNU/Linux and condemning people who attack GNU/Linux is not a crime
Decades-Long Microsofter (Darryl K. Taft) and TIOBE Conflate Microsoft GitHub (Proprietary) With FOSS in Microsoft-Sponsored 'News' Site
We do not intend to do a lengthy debunking because we covered this subject several times in the past
Microsoft Cuts Continue, Visitor Center in Redmond Shut Down
This goes on and on, leading up to the next giant wave of mass layoffs
IBM Bubble Deflating After James Kavanaugh's Accounting Trick With 'Toxic Assets' Comes Under SEC Scrutiny
If something goes up based on false speculations, bonus numbers and self-serving lies, then it'll come back down, eventually...
 
IBM is Becoming "Garbage In, Garbage Out" (GIGO) "Just like Arvind and Krabanaugh." (CEO and CFO, Respectively)
There are some decent new comments about IBM this morning
Gemini Links 13/02/2026: Square Function with Diode Network and Calls Against Discord
Links for the day
Links 13/02/2026: SUSE Uses Microsoft Internally, MElon's Company Helps Turn Epstein Files Into Child Abuse (After the Pornography Scandals)
Links for the day
African Browser Choices Show a Growing Problem in the World Wide Web
World Wide Web (WWW) becoming little but a transport layer for a particular proprietary application (Google Chrome) [...] we're back to the late 1990s
If You Want Digital Freedom, Then Follow Richard Stallman, the "Linux" Brand Has Changed and OSI is Microsoft (GitHub)
If you want something stable and predictable, then stick with GNU, the GPL, and GCC
Solicitors Disciplinary Tribunal and SRA Failing to Curb SLAPPs Against People Who Expose Wrongdoing
We'll soon show messages that we transmitted to politicians
Beware the Latest IBM SPAM, IBM is Already Down "After Hours"
After a harsh day in Wall Street IBM's shares area already down again (after trading hours)
Radicalism in Our Communities is Mostly Corporate, Not Grassroots
Infiltration and systematic destruction can be shallowly painted as "inducing manners"
Life Gets Better After Social Control Media
Don't become part of these experiments
statCounter Suggests Americans Are Dumping Social Control Media
Are Americans getting fed up with social control media and quitting in droves?
Back Doors and Fake Security
They've militarised everything, even people's home computers
Cost-Cutting and Book-Cooking at IBM
It's like cutting salaries by more than 50%
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, February 12, 2026
IRC logs for Thursday, February 12, 2026
Mainstream Media Intentionally Ignoring EPO Strikes
“EPO on Strike!”
Jeffrey Epstein crypto disclosure: uncanny timing, Bitcoin demise, pump-and-dump, ponzi schemes
Reprinted with permission from Daniel Pocock
Gemini Links 12/02/2026: Avoiding Coffee, Trying Ubuntu, and "Open Source Robot"
Links for the day
Microsoft Slop CEO Speaks of Layoffs
They will go along with the "replaced by AI" baloney
In Systematic Contempt of the British High Court, Brett Wilson LLP Spent Two Years Lying to Courts and Breaking Rules Against Us
We criticise Brett Wilson LLP quite lot because of its conduct
IBM Kyndryl as "Aggressive “Enron” Accounting"
IBM Kyndryl continues to nosedive today
Relationships evidence: Tiago, Tassia, Thais, Antonio & Debian favoritism, nepotism
Reprinted with permission from Daniel Pocock
Debian pregnancy cluster: why it is public interest
Reprinted with permission from Daniel Pocock
The EPO's Corruption and Violation of Rules is Spreading to the United Kingdom (Software Patents)
Yesterday a letter was sent to the chief regarding salaries while reminding him of the next strike, which is only 11 days away
State of the Slop, Slopfarms Containment
Slopfarms still exist this year, but their visibility is limited
IBM Continues Tanking Today, Already $58+ Lower Than Recent High, Insiders Explain Why
The same CFO from the inception of Kyndryl is still the CFO at IBM
Links 12/02/2026: Pushback Against, "NATO Is Expected to Step Up Arctic Security"
Links for the day
Links 12/02/2026: "Microsoft Just Forked Windows" and Windows Notepad is a Giant Security Hole
Links for the day
Put Criminals in Prison, Not People Who Report the Crimes
Can people be sent to prison for opposing crime?
Windows Has Become Increasingly Irrelevant
There's a very massive wave of layoffs coming Microsoft's way
Our Most Successful Year Ever
The hired guns in London are eager to turn the UK into another China
Slopfarms Waning, But Not Extinct Yet
Metrics show that usage of LLMs is declining
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, February 11, 2026
IRC logs for Wednesday, February 11, 2026
IBM's Stock is Crashing
If it follows the trajectory of its satellite Kyndryl, it can fall and reach as low as $75
Gemini Links 11/02/2026: Sunny Morning and "KiCad Aims to Ease Linux Installation"
Links for the day
Microsoft Loses Ground in Switzerland
One issue is, Google and Apple seem to gain at Microsoft's expense
Microsoft Layoffs Must be Very Near (and Very Large)
just like IBM
Bringing Attention/Awareness of EPO Corruption and Cocaine Use to the Mainstream Media
What has Europe become? Prey to vultures?
The Solicitors Regulation Authority (SRA) Delusion - Part V - Everyone Seems to Agree That SRA is a Sham
We're going to start a new series soon
A Can of WORMS - Part V - Up Next: The Comeback of RMS in the United States
Guess who funds the cancellers
Threats From 'Former' Red Hat (Now IBM) Staff While IBM's Likely Accounting Fraud Attracts Public Scrutiny
We must be getting "warm"
Matthew J. Garrett Has Just Sent a Threat to Put My Wife and I in Prison Because His Own Spouse Says He's a Rapist
What really intimidates him is his own spouse
Gemini Links 11/02/2026: Terminator Trilogy and Lagrange in the Apple App Store
Links for the day
Links 11/02/2026: Fentanylware (CheeTok) for ICE, Jimmy Lai Shows Journalism Became 'Crime' in Hong Kong
Links for the day
With Firefox Measured at 2% in the United Kingdom Time is Running Out for Web Site Support for Gecko/Servo Users
The open Web is rapidly dying while Mozilla celebrates and champions slop
Lawsuit reactions: EFF behaviour reveals zombification, censorship
Reprinted with permission from Daniel Pocock
Links 11/02/2026: $700 Billion Slop Bill, Social Control Media Under Political Fire for Deliberate Health Harms
Links for the day
Amended Input From Software Freedom Institute for EU Consultation on Free Software
"On 3 February 2026 Software Freedom Institute lodged a submission with the European Commission's inquiry into Open Digital Ecosystems"
Mobbing at the European Patent Office (EPO) - Part VI - Attacks on Staff and Attacks on the Law Merit Another New Series
new series coming shortly
Nadella's Mindless PR Spam Ahead of the Layoffs 'Snowball' (Adding Up Batches) Turning Into an Avalanche
Based on recent observations, the more puff pieces we see about Nadella, the closer we get to Microsoft "pulling the trigger" on mass layoffs
When Happens to Red Hat If (or When) IBM Collapses
IBM is in flux because its CFO is now implicated in what seems like accounting fraud
IBM's Financial Engineering (Accounting Fraud) Shell, Kyndryl Holdings Inc, is Insolvent
If this was done by the very same people who still run IBM, can we expect any better from "Sugar Daddy" IBM?
2026 a Very Productive Year and We Have Many Big Stories to Tell
maybe we'll produce 8,000 new articles/pages by year's end
Clownflare is in Trouble as Its Debt More Than Doubled in Less Than a Year, Expect Further Enshittification
Clownflare isn't free
After the Next Wave of Microsoft Layoffs Washington State Could be #1 for US Layoffs
Microsoft Corp shares were down yesterday
EPO's Local Staff Committee The Hague (LSCTH): The EPO is Generally “Managed by Excel” (Microsoft)
The current management has basically defined corruption to be "success"
With an IBM Company Down Over 75% After Apparent Accounting Fraud the IBM Insiders Want Answers From James Krabanaugh
He has no technical qualifications
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, February 10, 2026
IRC logs for Tuesday, February 10, 2026