Bonum Certa Men Certa

The NHS is Under Attack by Anthropic and Microsoft (or Their Lemmings That Infect the NHS)

posted by Roy Schestowitz on May 02, 2026,
updated May 02, 2026

Palantir and Microsoft joining hands

...and by Palantir*

Having just covered severe issues in cPanel (proprietary software is a security liability for more reasons that Free software can ever be, as patches are monopolised) and said we'd discuss security in relation to the NHS, let's begin by stating that Anthropic is a truly malicious, villainous, evil, malignant, unethical and immoral company (don't mind the Cheeto spin; Anthropic is pure evil, irrespective of politics). Its paid-for media hype campaigns have done considerable damage and this past January Andy explained why the company is in effect a collection or well-paid collective of "pirates" who physically destroy literature. That it paid a bunch of bribes to the Linux Foundation (along with Microsoft) to promote slop possibly helps explain why Linus Torvalds accepts a sabotage (by slop) of his "first child/son" (Git was the second; he has 3 daughters too). Linux, as a kernel controlled indirectly by Sheela and James Zemlin, is in truly malicious hands - some of them are frauds and people who really belong in prison!

But we digress.

Anthropic weaponises shills and media operatives to spread claims about bugs, to mindlessly sell fear. Then, it tries to sell a solution (to its own FUD). They try to sell offensive slop, then defensive slop. It's outrageous, but that's exactly what this company does without bothering to disclose actual details (it just dramatises it all by saying "too dangerous to release"... then it 'leaks'... and nothing happens).

So what's happening right now, based on pure hype rather than facts, is explained in this blog post from Terence Eden ("NHS Goes To War Against Open Source"). The above links to two other sites that in turn link to this original one and elaborate upon it. There are more official sources, too**.

To be clear, this isn't the first time slop sabotages things, especially Free software. To give two recent examples, slop bug reports result in code being removed (because it's considered "not worth the time" to check if those are false positives; it's faster and cheaper to just cull the code) and many sites put JavaScript barriers (or outright block many Web clients), as slop bots are considered a nuisance (either for copyright reasons or wasteful loads induced by them). The latter, in turn, becomes a severe accessibility problem.

The NHS has long had a Microsoft problem. It's even worse than it sounds. Many Brits are nowadays reluctant to tell GPs anything about themselves; some of the moral GPs are reluctant to enter anything into their computer systems, either because of security concerns (data breaches) or concerns about "legitimate actors" like companies run by neonazis and selling/exploiting the data for nefarious purposes in an increasingly hostile distant continent.

In truth, NHS knows that proprietary software has severe security issues; how many times did hospitals and NHS clinics encounter catastrophic attacks, data loss, operational failures (people literally died) due to Microsoft/Windows TCO?

They are kidding themselves if they seriously believe Web-facing source code repositories are the real threat to patients.

____

* Some resources/references:

** This is a more official source than what many link to:

Lots of good possible quotes in the above link, including: "NHS England has issued new guidance to staff, which has been shared with New Scientist, that demands existing and future software be pulled from public view and kept behind closed doors. “All source code repositories must be private by default. Repositories must not be public unless there is an explicit and exceptional need, and public access has been formally approved,” says the new guidance. The deadline for making code private is 11 May."

This is the culprit: "NHS England’s guidance specifically points to Mythos as the cause for the new measures. “Public repositories materially increase the risk of unintended disclosure of source code, architectural decisions, configuration detail, and contextual information that may be exploited – particularly given rapid advancements in Al models capable of large-scale code ingestion, inference, and reasoning (e.g. developments such as the Mythos model),” it reads. “This red line establishes a default-closed posture for code while the organisation assesses the impact of these changes and ensures that any public publication of code is a deliberate, reviewed, and justified decision.”"

And one more (very important to quote) from the geek's site: "As I've written before, this is not the correct response to the purported threat by Mythos. Neither the AI Safety Institute nor the NCSC recommend this action. While there may be some increase in risk from AI security scanners, to shutter everything would be a gross overreaction. Nevertheless, that's what the NHS is preparing to do."

To summarise in a sentence or two what it is that Terrence actually points out regarding the attack, and why that it is a mistaken approach:

The majority of code repos published by the NHS are not meaningfully affected by any advance in security scanning. They're mostly data sets, internal tools, guidance, research tools, front-end design and the like. There is nothing in them which could realistically lead to a security incident.

When I was working at NHSX during the pandemic, we were so confident of the safety and necessity of open source, we made sure the Covid Contact Tracing app was open sourced the minute it was available to the public. That was a nationally mandated app, installed on millions of phones, subject to intense scrutiny from hostile powers - and yet, despite publishing the code, architecture and documentation, the open source code caused zero security incidents.

Furthermore, this new guidance is in direct contradiction to the UK's Tech Code of Practice point 3 "Be open and use open source" which insists on code being open.

My wife and I worked on NHS systems for a number of years and a lot of the code we dealt with was Free software. The machines were not world-facing, however, so there was no risk to data even if an attacker was aware of some flaw in some software.

When managers are clueless about technology we get corporate media controlled by GAFAM giving the decision-makers bad advice. And they fall for it every time.

Other Recent Techrights' Posts

Web Browsers Are for Rendering Web Page, They Shouldn't Become PDF Editors
Linus Torvalds is quickly learning and speaking about this
 
Links 20/05/2026: Mass Layoffs at NPR (Bought by the Ballmers and Bill Epsteingate), Starbucks Korea CEO Fired Over ‘Tank Day’ Ad
Links for the day
Gemini Links 20/05/2026: Advantage of CD Collections, Geminaut's View of Nostr, and SSL / TLS Certificates
Links for the day
IBM is Becoming a Pile of Expired Patents and Abandoned Buildings, Assets of Little Actual Value
Having laid off a ton of people, borrowed lots of money to fake growth (by acquisition), and sent some jobs to low-paid regions where innovation isn't done
Links 20/05/2026: Looting of Americans for "White Grievance Reparations Fund"; "Mark Zuckerberg Used Shell Companies to Bully Native Hawaiians"
Links for the day
SLAPP Censorship - Part 82 Out of 200: British Government Intervenes in the SLAPPs by Brett Wilson LLP
At this stage our matters are dealt with by a layer below that of the Prime Minister (adjacent to it)
LinkedIn Communications Reveal That LinkedIn - Like GitHub - Will Vanish Inside the Belly of Microsoft
This is definitely going to happen.
In Wall Street, Financial Difficulties Drive Shares Up
Wall Street doesn't work that way
The Corrupt Lecture the Non-Corrupt - Part XXVIII - European Patent Office (EPO) Guidebook Says Report Crimes Committed on EPO Premises. Some Did, But President Campinos Covers up for the Culprits.
The staff has long been on strike and the union (SUEPO) organised an enhanced day of action just two days ago
Gemini Links 20/05/2026: Fall of an Empire, "High Tech is a Social Exercise", and Big Cameras
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, May 19, 2026
IRC logs for Tuesday, May 19, 2026
LinkedIn Layoffs at Microsoft: Probably Well More Than 5% of Staff
In short, it's difficult to believe only 5% are impacted
It's Not Just a Widespread Theory, It's Apparently a Verified Fact: Home Appliances Not Made to Last Long
Washing machine repair man asserts that the machines sold a decade ago could maybe last a decade; now they last barely 5 years.
Torvalds Capitulated on Rust and Slop, Now He's Paying the Price
they are pushing Microsoft and slop for grifters and scammers
Whistleblowers Needed: We Are Seeing Many Layoffs in Red Hat (Not Just in China), We Want to Know More
Last week we learned about some people who said they had left Red Hat or are leaving Red Hat
Links 19/05/2026: More Obituaries for Peter G. Neumann, Taiwan Abandoned by Cheeto House for Don's Personal Gain
Links for the day
Links 19/05/2026: Online 'Storage' (Surveillance) Accounts Lower Thresholds (Gmail, Google Drive, and Google Photos), Slop Debacles Expand (False Promises Made to Staff Regarding Compensation)
Links for the day
SLAPP Censorship - Part 81 Out of 200: SLAPP Censorship Does Not Work If Your Sole Strategy is Revenge (and You Attack the Family)
Both yours and others'
Techrights at 20 (Soon)
It does not seek popularity or affirmation from "Establishment" outlets
We Pay More for Less, for Things That Last Less Time and Are Almost Impossible to Repair
Ever noticed how "modern" or "smart" TVs come with dumber and dumber (worse) controllers?
Vista 11 Turns 5 in a Couple of Months. Not Many People Use It.
It is the only supported version of Windows; many people move elsewhere
Head of GitHub Recently Left, Microsoft Need No Longer Report Mass Layoffs There (User Activity is Declining)
We've long said that LinkedIn and GitHub, which Microsoft bought, would likely end up like Skype
The Slop Bubble is Already Bursting
Slop is not desirable and the general public is growingly impatient, seeing that slop has improved nothing for them
Gemini Links 19/05/2026: Reliable Old Tech, Collection of Essays
Links for the day
The Corrupt Lecture the Non-Corrupt - Part XXVII - European Patent Office (EPO) Became a "Toxic Work Environment" When Cocaine Addicts Put in Charge
They are putting at risk colleagues by abusing them
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, May 18, 2026
IRC logs for Monday, May 18, 2026
Links 18/05/2026: Slop-induced Shortages, Solicitors Regulation Authority Says It's Unable to Deal With Complaints Load (So Regulation Does Not Really Exist)
Links for the day
Gemini Links 18/05/2026: Ghost Essay and World Wide Web Considered Broken
Links for the day
Cooperation and Collaboration, on a More Personal Level
Rianne, to me, isn't just a wife; she is also my best friend
IBM Has Payroll Problems (Just Like Microsoft)
It's a good thing that many nations around the world are, accordingly if not proactively, divesting from GAFAM
Links 18/05/2026: 25 Years of OLDaily and Dangers of "Living With Too Much Tech"
Links for the day
Trips to London
London isn't a bad place, but it's a long journey and we'd rather stay in Manchester and write about technology
SLAPP Censorship - Part 80 Out of 200: Having Run Out of Time to Meet a Judge's Deadline, Microsoft's Graveley Had Garrett's Lawyers Argued My ~190-Page Defence and CounterClaim (DCC) Was Unclear About My Position
Nothing could be further from the truth
Working in the Shell (and Fish)
Yesterday we spent about 5 hours on the shells and fish
The Corrupt Lecture the Non-Corrupt - Part XXVI - Campinos Has Put Unfit-for-Employment Drug Addicts in Charge of the European Patent Office (EPO)
How many months has Campinos got left before the delegates show him the door?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, May 17, 2026
IRC logs for Sunday, May 17, 2026
Gemini Links 18/05/2026: Poetry, Sauna, and GNU Taler
Links for the day