Bonum Certa Men Certa

Perfectl is Not New, It's Not News About Linux, Outdated Apache RocketMQ is Not Linux, and the Real News Should be Back Doors Like Windows and CALEA Blunder

posted by Roy Schestowitz on Oct 16, 2024

Bruce Schneier

Perfectl Malware: At least he did not say Linux

"The malware has been circulating since at least 2021."

What malware?

"Perfectl Malware".

Linux?

No, not really. Really? Yes, really. Not Linux.

We've patiently tracked this FUD for a while now. It has been tracked in this page since the fifth of October (10+ days already and they're not done with their marketing campaign yet).

We were reluctant to write about it as it would give the FUD even more publicity, but now Schneier on Security mentions it, so it's getting more exposure anyway.

As an associate put it: "found on 'many' Linux machines? Really? Never heard of it prior to this..."

So for 3+ years it has been on "many" machines and somehow nobody mentioned it?

Weird.

As per my editorial comments (going over a week back), it seems like a marketing campaign, not research, and in order to properly rebut what this private company (Spamnil did a lot of spam for this company, so you know they're spammers) says we've been checking its claims. "My guess is that the article and others like it," an associate says, "are part of a larger orchestrated smear campaign to disparage FOSS heading into the upcoming decisions regarding computer and network security by US Congress and The White House."

"The articles contain a lot of lies and disinformation, in particular they wrongly assert that "any" Linux system is vulnerable. CUPS is Apple. Apache RocketMQ is not Linux either..."

Schneier says: "Something this complex and impressive implies that a government is behind this. North Korea is the government we know that hacks cryptocurrency in order to fund its operations. But this feels too complex for that. I have no idea how to attribute this."

Don't even go that far. Check what the basis is...

As noted above, it seems like a marketing/FUD campaign.

The AMX-30 is a main battle tank designed by Ateliers de construction d'Issy-les-Moulineaux and first delivered to the French Army in August 1965. The first five tanks were issued to the 501st Régiment de Chars de Combat in August of that year.

"The attribution is to point to the disinformation campaign coming via Redmond," our associate opines. "Maybe it is all a distraction from China (and reading between the lines, Russia) exploiting the CALEA backdoors with impunity for all these years. The same interests which back CALEA hate the idea of a move from Windows because they'd lose their back doors. That China, Russia, and every other country in the world are also in and out of Windows systems like a cheap motel does not matter to them. They only care that they themselves can also get in on demand. That's harder on GNU/Linux and Linux in general for many reasons including but not limited to the lack of a monoculture. tldr; The CALEA breaches have been pushed out of the news cycle prematurely."

A lot of the anti-"Linux" (even when it's not Linux; or even not the fault of Linux) FUD comes at strategic times for Microsoft and sometimes comes directly from Microsoft staff (Xz for instance). It's difficult to ignore the pattern.

"Another theme to be debunked," the associate adds, "amidst the stream of aspersions, insinuations, and disinformation, is the false premise that Microsoft is any kind of authority."

Microsoft is the culprit, not the expert, but it is expert at infiltrating positions of authority, especially in government [1, 2, 3, 4], in order to undermine real security and instead peddle snake-oil and lies.

The associate calls it after-market boondoggles "in place of secure design" and takes note of hours-old "victim blaming" by Microsoft, which "continues into a new decade..." (it says "Microsoft wants tougher punishments for cybercriminals"; how about the holes that facilitate these cybercriminals?)

He further notes that "targeting != breach, unless Windows(tm) is involved" (in which case, the holes are deliberate).

In short, there's some dodgy private company trying to promote itself by trash-talking "Linux" for over 10 days already (many shallow pieces in "the media"). But it's not about Linux, it's about servers that haven't been patched for ages and it's the fault of some outdated programs installed on them. The timing of this FUD (or marketing from this company's perspective) is hard to brush aside.

It's almost like this dodgy private company is attempting to sell something.

The FUD source

Other Recent Techrights' Posts

When the Microsoft Aggressors Rely on Several Law Firms ('Attack Dogs', 'Guns for Hire'), Not Just One, Lawyering Up Against Techrights (Acting on Behalf of Americans Against UK Publishers)
From serving customers at some restaurant he has moved on to bullying people with demand letters
Polygamy, from Catholic Synod on Synodality to Social Control Media & Debian CyberPolygamy
Reprinted with permission from Daniel Pocock
Only a Third of or 1 in 3 Web-Connected Devices is a Desktop or Laptop, According to statCounter
we can expect Android to widen its lead
 
statCounter Estimates Only 1 in 300 Iranians Would Use Microsoft for Search
Iranians don't quite trust Microsoft
Gemini Links 24/06/2025: ftpd on FreeBSD and Online Small Web Magazine
Links for the day
Google News Does Great Harm by Promoting Slopfarms as Legitimate News Sites
Slopfarms are sites which are 100% LLM slop
Links 24/06/2025: Trouble at "Open" "AI" and ‘Siarhei is Free’
Links for the day
Gemini Links 24/06/2025: Stimulants and Subscription Costs for DRM
Links for the day
Links 24/06/2025: OpenAI [sic] May Soon Die (Too Much Debt) and Social Control Media Accused of Being Misinformation/Disinformation/Propaganda Amplifier
Links for the day
Nirbheek Chauhan in Planet GNOME Explains Why Wayland Pushers Are Losing
"A strange game. The only winning move is not to play."
The Days Are Getting Shorter, the First Half of 2025 is Almost Over
We're gratified to see significant increase in traffic and also positive feedback on the work we do
Turning GNU/Linux Into a Political Football
X (not the site) is Free software
X Server Still Works for Many People
A lot of people will grow suspicious of Wayland boosters/pushers if they persist and insist on using these tactics
Exactly a Week Ago "BetaNews Staff" Said "Betanews Is Growing Alongside You". Since Then Every Article (All by "Camila Nogueira") Has Been LLM Slop.
BetaNews is basically a slopfarm
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, June 23, 2025
IRC logs for Monday, June 23, 2025
The "Tarzan Effect" in Compilers and Software
What happens when you forcibly make things 'work', either by hacks or by disregarding warnings (like those that compilers tend to issue)?
Gemini Links 23/06/2025: Mass Tourism, Hair Love, and Google Gemini as a Googlebomb
Links for the day
Law Firm Burgess Mee Does Not Fully Deny Participating in Abusive Litigation for Serial Strangler From Microsoft
I am not unfamiliar with these tactics
The Modus Operandi of Wayland Pushers: Make It Political
do what I say or you're a nazi...
Links 23/06/2025: RFE/RL Contributor Vladyslav Yesypenko Released, Recording Industry Cutbacks
Links for the day
Brett Wilson LLP Solicitors (M): Over 99.9% of Our E-mail is Self-Marketing, We Send You 3.5MB E-mails for Less Than 1KB of Text
Why would tech people entrust legal matters to such people?
Peter Moon's (Computerworld) Interview With Richard Stallman
Stallman: If you want freedom don't follow Linus Torvalds
At What Point Does Outsourcing Constitute Malpractice?
Brett Wilson LLP's new staff page is misleading
United Arab Emirates (UAE) Sailing to GNU/Linux, According to statCounter
countries in that region will quickly learn the price of neglecting digital sovereignty
From Do Your Own Research to Do Your Own Search
The Web is full of garbage; search engines amplify this garbage
More People Moving to Geminispace?
at age 6+ Gemini Protocol seems to have gained some maturity and it seems like more people use it
Permutation in LLMs Does, Inevitably, Change Meanings and Therefore LLMs Cannot Properly Rephrase or Summarise Texts
LLMs lack actual grasp or comprehension of what they spew out
Links 23/06/2025: Many Security Breaches, Population Declines
Links for the day
Gemini Links 23/06/2025: "America at the Crossroads" and OpenWRT Surgery
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, June 22, 2025
IRC logs for Sunday, June 22, 2025
Pure Dove
Different means different, and sometimes those who "deviate" from "the norm" have a point
Censorship is a Sign of Weakness Which Invites More Censorship Attempts
revolutionaries don't succumb to pressure from bullies
Why It's Unlikely That LLM Slop Will Dominate the Web in the Long Run
Slopfarms will eventually perish (they have no actual value) and "survivors" on the Web will be sites that never depended on search engines and social control media
GNU/Linux in Argentina Now Measured Near 5%
Like in central Europe, they must be seeing an increasingly hostile US
BetaNews is Fake News, Composed by LLM Slop
nothing in BetaNews is written by humans anymore
Links 22/06/2025: Giving Up on Smartphones and 'Jaws' at 50
Links for the day
Gemini Links 22/06/2025: Furniture Construction and Bubble for Comments
Links for the day
Links 22/06/2025: Windows TCO Tales and YouTube Getting More Hostile to Users
Links for the day
The FSF Board and FSF Beard
So the FSF's Board has grown
Law Firms Facing the Consequences for Patently Abusive Litigation on Behalf of Microsoft Employees Who Got Arrested for Strangulation and Had Done Even Worse Things
Having spent 1.5 years bullying me with patronising letters on behalf of Microsofters, last week they got served a massive bill and, in effect, lost the Hearing
New Report From the EPO's Staff Representatives in The Hague (LSCTH) Reveals Many Unsolved Issues
Local Staff Committee The Hague (LSCTH) wrote to staff just before the weekend
LLMs Breaking Everything
Computing and the Net became a playground for scammers and "bros", like people who "invented" fake currencies and also try to tell us that LLMs spewing out things will have some real value
Links 22/06/2025: More Slop Lawsuits (Copyrights) and "America’s Oligarch Problem"
Links for the day
Gemini Links 22/06/2025: Gigantic Toolchest and Annoying Bots
Links for the day