Bonum Certa Men Certa

Pulling an SCO Using Security Firms?

The Fortify "Get the Facts" campaign (against Free software) was only mentioned very briefly here. It came in the form of a warning (it was also included in some link digests).



Security companies are funny creatures because they naturally love insecure software. They love breaking software apart and fear means business to them. Lying is never a problem, no matter the consequences. Moreover, Free software, which is inherently more secure, is a true danger to the business model of security agents, so they fight without tact or mercy [1, 2, 3].

Some concerned people, such as Sean at Internet News, truly wondered what Fortify had in mind. Why would it attack Free software so suddenly? Groklaw found this one, which is merely a possibility, not an explantion. It's a vanity page bearing the headline: "FORTIFY-MICROSOFT ALLIANCE."

Microsoft and Fortify Software are enabling software developers and testers to build and deliver more secure applications. Visual Studio 2005 Team Edition for Software Testers offers an easy-to-use yet powerful framework for testing. Fortify leverages this infrastructure and adds Web application security testing capabilities. The combination of the two effectively brings basic security testing out of the realm of specialized experts and into the hands of software testers. In addition, Fortify provides its award-winning source code analysis capabilities to Visual Studio Team Edition for Developers so security flaws discovered in development and testing can be diagnosed and fixed quickly. Working closely with the Visual Studio team has enabled Fortify Software to incorporate its innovative software security capabilities within the powerful Visual Studio


Groklaw adds: "Yes, folks. This partner of Microsoft is the same Fortify Software that put out that "study" that concluded that "Open Source" (but actually only Java) is risky." It smells like a case of fitting data to an hypothesis and a sensationalist conclusion, and at the same time hitting two rivals of Microsoft: Java and Free software.

They didn't assess proprietary equivalents. They wanted to encourage businesses to buy products from them. Furthermore, according to this, once/if you looked closely, you would find that proprietary products were shown to be more -- not less -- defective than Free software. So what has Fortify really proven?

Her main points:

1. There are other security toolkits other than Fortify. Just because you don’t use their system doesn’t mean you don’t care. 2. When reading vendor-sponsored studies consider the source. Always a wise move. 3. Open source projects in Fortify’s Open Review report fewer defects per thousand lines of code than proprietary products in the same review. I didn’t know that.


Fortify may also have some junk software patents, such as this one on "security testing".

Fortify SCA helps security, testing and development teams pinpoint and eliminate security vulnerabilities in software applications. Fortify's patent-pending technology delivers the most accurate and reliable results with low false positives..


“There should really be an index somewhere to tell who's with who.”Watch who Fortify built an alliance with: Wipro, another Microsoft partner that's joint to it by the hip and lobbies for OOXML -- all against India's interests [1, 2, 3, 4, 5].

Fortify lives in a not-so-healthy neighbourhood of proprietary software companies that combat Free software and encourage software patents.

The apple doesn't fall so far from the tree.

With money on the table, there is no trust. Will you also believe OpenLogic and Black Duck, for example, despite being headed by former Microsoft employees? They sell open source fear. There should really be an index somewhere to tell who's with who. It would help tremendously.

Comments

Recent Techrights' Posts

Figures of Note: Tesla's Debt Has More Than Doubled in Two Years and It's a Symptom of a Fake Economic Order
Cash infusions by taxpayers can create "billionaires" who aren't "job creators" (see what happened to Twitter) and bring no benefits to these taxpayers, only poverty
today's howtos
some older leftovers
 
BetaNews is Still a Shrine of Microsoft, and Casually Also an LLM Slop Factory
Fake articles, anti-Linux FUD, and Microsoft propaganda make a sound "business model"?
[Meme] Cyber Monday is Not a Thing; There's No Such Thing (It's a Corporate SPAM Campaign Plaguing the Web)
Enough with these fake 'holidays' that billionaires (business oligarchs) keep inventing to make more money at other people's expense (debt)
Software Freedom Conservancy (SFC) and Linux Foundation: Same Mentality of Revisionism and Plunder
Lie about history and then 'cash in'
[Meme] Software Freedom Conservancy (SFC) Begs You for Donations
How does one even spend 20,000 dollars per month???
Why Software Freedom Conservancy Does Not Deserve Money (Karen Sandler is Already a Millionaire and Her Organisation Attacks Free Software Leaders)
These people speak for "Big Money" interests, not for freedom
On the internet [sic] (Lowercase), They Spread Misinformation About the Internet
Hugh Grant remembers what happened before he was born
Richard Stallman Was Getting Honorary Doctorates Almost Every Year Until 'Cancel Culture' Stepped in, Distracting From Jeffrey Epstein's Ties to Bill Gates
This finally ended... earlier this year (October)
Self-Deprecating Attacks on RMS
Drew DeVault seems to have deleted all of his social control media accounts
When Bills Are Rising, Whereas the Demand Isn't (OpenAI is Insolvent)
Latest month on record shows traffic fell about 3 times lower than earlier this year
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, December 01, 2024
IRC logs for Sunday, December 01, 2024
Links 02/12/2024: Climate, Sportwashing, and Software Patents
Links for the day
Gemini Links 02/12/2024: Words and Apologies, Being Rude, and Geminauts 0.1.0 Release
Links for the day
The Microsoft OSI: All the Latest Blog Posts Are Written by Microsoft Operative Salaried by Microsoft
OSI is truly occupied. Microsoft more or less 'bought' the OSI...
Links 01/12/2024: Russian Police Raiding Gay Bars, Zelensky Wants NATO Membership
Links for the day
Gemini Links 01/12/2024: Recycling and Interest in Computers
Links for the day
Links 01/12/2024: 23andMe's DNA Bubble Imploded, Web Server Survey Shows Microsoft Nosediving
Links for the day
Vulture funds war-gaming Ireland loss of corporation tax revenue, Donald Trump
Reprinted with permission from Daniel Pocock
Gerry Hutch & Debian: suicide by Monk?
Reprinted with permission from Daniel Pocock
Gerry 'The Monk' Hutch: criminals vs geeks, multinationals vs Ireland
Reprinted with permission from Daniel Pocock
"Microsoft suffered the next largest loss, down by 634,406 sites (-3.24%)"
Microsoft is now in only 2 of the 5 tables; over time Microsoft slips out of visibility in more categories
The Post Offices Have Turned Into Trash. They Swallow Packages and Only Spit Them Out If You Get Lucky.
Nom nom nom
Four Years of Videos (Self-Hosted, Not Social Control Multimedia)
Seeing how the "hey hi" (AI) hype spreads to GulagTube and ruins GulagTube, we're glad we need not worry about Google (Gulag) policing our "content" via supposedly 'free' (not really) platforms, such as GulagTube, the social control (multi)media "market leader"
[Meme] Hiding From Bullies Not the Solution
‘The only thing necessary for the triumph [of evil] is for good men to do nothing.’
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, November 30, 2024
IRC logs for Saturday, November 30, 2024
If You Support Free - is in Freedom/Libre - Software, Then Support the Free Software Foundation (FSF)
2024 was the most productive year so far
CNN's Front Page is About 250 Times Heavier Than Techrights' (Also Far Slower)
Those who value performance and users' experience will give bloat the boot
[Meme] What 'Social Justice Warrior' Has Come to Mean by 2024
People who have long called themselves "SJW" aren't exactly any of those things
We Already Know What Makes Techrights So Attractive to Online Abuse and Cybercrimes
Techrights helps explain how to dismantle the 'cancel culture' against Free software (it also names the key perpetrators)
Microsoft Controlling Apache by Proxy/ies
This is a broader attack on what "Open Source" actually means
Two Years Later Sirius Open Source is Basically Dead (With a Zombie Web Site)
1 day from now it's exactly 2 years since Rianne and I resigned
[Meme] The Internet is More Fragile Than They Are Willing to Admit
If your site ready for a war on pipes and cables?
In Case Undersea Cables Are Cut...
The issue has been somewhat of a taboo - mostly overlooked or entirely ignored at times of peace
IBM is More Than 60 Billion Dollars in Debt (Which It Cannot Pay Back)
IBM debt is growing
IBM and Microsoft Fake Headcount in Exactly the Same Way (While Mass Layoffs Persist and Real Revenue Falls, Not Just Compared to Inflation Rates)
They convert profits into fake 'growth' instead of cashing in (so debt continues to soar), in effect gaming the system based on misleading metrics
Daniel Pocock Moved Up Two Spots in the Political Battles
He has made a statement about it
Links 30/11/2024: Cable Cuts Under Investigation, America’s Cemeteries Are Rewilding, Panda Protection Money Misused
Links for the day
Understanding Irish general election 2024 results Dublin Bay South
Reprinted with permission from Daniel Pocock
Links 30/11/2024: Social Control Media Under Growing Scrutiny, Patent Propaganda Sites Still Promote a Fake Court (UPC)
Links for the day
Gemini Links 30/11/2024: SIGINT Foo and Hooking Up an Old Serial Terminal to a NetBSD Machine Over USB
Links for the day
Apache Software Foundation, Already Infiltrated by Microsoft for Well Over a Decade, Still Controlled by Proprietary Giants With Openwashing Agents
No wonder things get outsourced to Microsoft's proprietary prison (GitHub)
Tux Machines Turning Twenty a Half
Contact us if you want to join us and live not far from Manchester
Stable at Over 4% and 400+ Days' Uptime
Hopefully some time this weekend we'll find enough time to upload party photos (this site turning 18)
With a Month Left to Raise Money the Free Software Foundation (FSF) Has Already Raised 56,000 Dollars
December starts tomorrow
The Irish Have Voted, We'll Soon Know How Many Voted for a Debian Developer and Free Software Specialist
Dublin Bay South results
[Meme] The Word Security Has Been Redefined
"See what the media tells us?"
Proving Yet Again That Techrights Was Right About UEFI 'Secure Boot' All Along (Since 2012)
'Secure Boot' or 'secure' boot is about anything but security
[Meme] Growing Up and Becoming Sceptical
Social control media is a toxic weapon against what's true
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, November 29, 2024
IRC logs for Friday, November 29, 2024
Reporting Information and Facts at Times of War (and Information Wars), Dissent of Merit and Scepticism//Critical Skills Impermissible
The world is full of white-collar crime, so the more people report, the better
Links 30/11/2024: More Strongarming and Threats to Taiwan, Ananda Krishnan is Dead
Links for the day