Bonum Certa Men Certa

Symantec Lies About GNU/Linux

Kent Hovind mug shot
Symantec: the Kent Hovind of security?
(mug shot of Kent Hovind courtesy of Escambia
County Sheriff's Office after his arrest)



Summary: In order to sell some products, Symantec spreads GNU/Linux fear based on misinformation

EVERY once in a while Symantec aims its FUD pistol at some innocent element of computing which Symantec claims has a problem (and Symantec of course offers a solution to this problem). We have already explained this business strategy (using examples that misuse Free software [1, 2]), which characterises many quacks and pseudo-science. That's why we put Kent Hovind at the top, for those who still wonder.



An issue which we discussed earlier today in IRC is the latest stunt from Symantec, which is probably best deconstructed and explained by Slashdot user "superapecommando" who submits:

The latest MessageLabs Intelligence Report from Symantec Hosted Services is filled with interesting and useful information regarding the current state of malware and e-mail borne threats as well as the trends over time. Of particular interest to me is the assertion in the report that "any given Linux machine is five times more likely to be sending spam than any given Windows machine."

A pretty clear case of sensationalist metrics from a company which wants to sell their hosted security solutions to Linux box admins. But one interesting thing that comes out of the story is that many of the security researchers believe that misconfigured POSTFIX and SENDMAIL installations are cloaking the actual amount of spam coming from infected Windows hosts.


Desktops that unleash vast amounts of SPAM actually run Windows and one in two Windows PCs is believed/estimated to be a zombie (either active or not). GNU/Linux drives many mail servers, so if it obeys a request from a Windows zombie, then it will deliver SPAM. Should GNU/Linux therefore be blamed? Of course not. It's just very good at delivering mail.

“GNU/Linux drives many mail servers, so if it obeys a request from a Windows zombie, then it will deliver SPAM.”Quoting Symantec a little further from its 'report' (which assumes bogus numbers about the market share of GNU/Linux), "by calculating a ratio of spam from a given operating system compared to the market share, we can get a “spam index” which shows relative to its market share, the likelihood that a particular computer is sending spam, based on its operating system. In the current spam climate, this index shows that relative to its market share, any given Linux machine is five times more likely to be sending spam than any given Windows machine..."

Another translation was sent to us by a reader who says: "Despite a total lack of evidence and being unable to detect the source OS of spam, we conclude that Linux machines are sending more SPAM because there are less of them."

As our IRC logs will show later today (fragment posted below), there are even better explanations for that.




Techrights logo

IRC: #boycottnovell @ FreeNode: May 9th, 2010

Join us now at the IRC channel.

tessier__http://www.v3.co.uk/v3/news/2262681/botnets-exploit-linux-ownersMay 10 09:29
tessier__Someone is smoking crack.May 10 09:29
tessier__crapMay 10 09:31
schestowitzWindows is not used much for E-mailMay 10 09:31
tessier__There is something fishy about that websiteMay 10 09:31
schestowitzWhich one?May 10 09:31
schestowitzV3?May 10 09:31
tessier__Not intentionally, no. But that's what the botnets are doing with Windows: sending mailMay 10 09:31
tessier__YeahMay 10 09:31
schestowitzVNUNEt?May 10 09:31
tessier__Have you heard of v3 before?May 10 09:31
tessier__I never have.May 10 09:31
schestowitzYesMay 10 09:31
schestowitzLinux relays spamMay 10 09:32
schestowitzIt runs mail serversMay 10 09:32
schestowitzIt does what it's supposed to doMay 10 09:32
schestowitzWhich is to relay requestsMay 10 09:32
tessier__I cannot post a comment on that site. The captcha does not work. No matter what you put in there it does not accept it.May 10 09:32
tessier__Linux by default is not an open relay.May 10 09:32
schestowitzI wonder what sends those requests thoughMay 10 09:32
tessier__No distro ships their mail servers that way.May 10 09:32
schestowitzIt's spammersMay 10 09:32
tessier__it will deliver the spam to you that someone injected via a Windows box though.May 10 09:33
schestowitzThey use open relaysMay 10 09:33
schestowitzRunning Linux because it's betterMay 10 09:33
tessier__Open relays are hard to find these days.May 10 09:33
schestowitzThey get blacklistedMay 10 09:33
tessier__And spammers don't run open relays either. They don't want other spammers stealing their resources.May 10 09:33
schestowitzWhat was that list that gather IPs of spam relays?May 10 09:33
schestowitzmany services used to look it up and in 2008 it had sustainability issuesMay 10 09:33
tessier__Whenever I have investigated IP addresses that were sending me spam it was Windows boxes.May 10 09:33
tessier__There are lots of DNSBLsMay 10 09:34
tessier__And they operate quite successfullyMay 10 09:34
tessier__SORBS is one of the big ones these daysMay 10 09:34
schestowitzI can't recall the one I think about. Articles about it were widespread 2 years ago.May 10 09:34
*schestowitz creates http://techrights.org/wiki/index.php/FacebookMay 10 09:35
TechrightsTitle: Facebook - Techrights .::. Size~: 12.91 KBMay 10 09:35
tessier__There have been quite a fewMay 10 09:35
-BNtwitter/#boycottnovell-[popey] Mark proposes that 10.10 is released on Sunday 10th October 2010. Where 101010 = 42 = Meaning of Life / Universe / Everything!May 10 09:37
-BNtwitter/#boycottnovell-[nsisodiya] need a student volunteer for modifying C++ book #schoolosMay 10 09:40
*benJIman has quit (Ping timeout: 252 seconds)May 10 09:42
-BNtwitter/#boycottnovell-[popey] There will be no public ISO of #Ubuntu Light with Unity, but will be tailored specifically for OEMs.May 10 09:49
-BNtwitter/#boycottnovell-[davidgerard] From @cracked - 5 Insane File Sharing Panics from Before the Internet - http://tinyurl.com/2ubthnwMay 10 09:53
TechrightsTitle: 5 Insane File Sharing Panics from Before the Internet | Cracked.com .::. Size~: 81.74 KBMay 10 09:53
-BNtwitter/#boycottnovell-[satipera] Liberal Democrat negotiations with Labour look likely if Brown goes quickly.May 10 09:55
*narendra (~79f5e1b0@gateway/web/freenode/x-xaqdkqksysommyyc) has joined #boycottnovellMay 10 10:08
narendrawhere I can upload secrect document anonymousy ? May 10 10:08
narendrawikileaks is not working i think !!May 10 10:08
tessier__http://موقع.وزارة-الاتصالات.مصر/Default.aspxMay 10 10:16
tessier__Awesome.May 10 10:16
*benJIman (~benji@benjiweber.co.uk) has joined #boycottnovellMay 10 10:17
MinceRi'm not so enthusiastic about it.May 10 10:17
*benJIman has quit (Client Quit)May 10 10:17
tessier__Why not?May 10 10:17
*benJIman (~benji@benjiweber.co.uk) has joined #boycottnovellMay 10 10:17
MinceRbecause it allows even more domains that are difficult to type, read and compareMay 10 10:18
MinceRIDN already lets you create identical-looking but distinct domains that can confuse users trying to check whether a certificate really applies to a supposedly secure connection.May 10 10:18
MinceRdomain names used to be easy to handle (as such names should be)May 10 10:19
MinceR7bit US-ASCII should have been enough.May 10 10:19
tessier__SSL CA was broken from the beginning anyway. This doesn't make things any worse.May 10 10:21
tessier__Everyone just clicks ok regardless.May 10 10:21
tessier__Although I am curious to know how you would work that sort of thing into a bind zone file.May 10 10:21
MinceRno, not everyone.May 10 10:26

Comments

Recent Techrights' Posts

The "Nazi Bars"
We don't condone or condemn the label "Nazi Bar"
TV Programmes in Geminispace
Sort of like teletext except more cross-platform
Techrights' Assessment of Red Hat Layoffs in 2025 (Yes, They Happened!)
In short, Red Hat layoffs did occur this year, but even when they did the media did not mention these (and those would count as "IBM" regardless)
The GPU Bubble (GPUs Marketed by Useless Slop)
"they're selling GPUs for the sake of selling GPUs"
Formalities Officers at the EPO Face Uncertain Future, Administration Gets Asked About That
They're being too polite (perhaps) to people whose agenda is detrimental not just to the EPO but also the EPC
EPO General Consultative Committee (GCC) Agenda: Reduction of Staff's Salaries (Compared to Inflation)
knocking salaries down some more
 
Links 18/11/2025: "Bitcoin Showing Signs of Severe Collapse" and CEOs of GAFAM Finally Speak About a Slop Bubble
Links for the day
Apparent Red Hat Layoffs in "AI" (Supposedly a Strategic Area for IBM)
What is going on there?
Gemini Protocol as a Growing Source of Audience (Mostly Technical People)
Clients for Gemini Protocol are available for almost every platform imaginable
EPO Change May be Afoot, Keep Pushing and Hold Those Feet to the Fire
Backlash is brewing and societal trends reinforce backlash right now
Links 18/11/2025: CISA Advisories, Climate, "U.S. Layoffs Surge and Blaming AI is Part of the Smokescreen"
Links for the day
Gemini Links 18/11/2025: "Block Them All", Annex, Signed Commits, and "Cryptography of the Internet"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, November 17, 2025
IRC logs for Monday, November 17, 2025
Right Under the Nose of Mainstream Media
That the media fails to cover the matter mostly speaks volumes about the media
Spanish Focus Coming Soon and Maturity of Site Search
We'll soon be focusing on Spain
Slopwatch: LLM Slopfarms Seem to be Slowing Down Somewhat
LLM addiction is a very unhealthy addiction
Thailand: Windows Down Sharply, Microsoft Loses Share to GNU/Linux
the Thai economy is strategic and relatively important in the region
Gaming Journalist and Guru Jason Schreier Says Microsoft is Indeed Behaving Like It Exits the Console Market
Remember that many shops no longer sell or stock XBox
Links 17/11/2025: ‘Agentic OS’ Backlash and Facebook ('Meta') Loses Yann Le Cun
Links for the day
Gemini Links 17/11/2025: Technology's Harm in Schools, 3D Printer Blurb
Links for the day
Coming Soon: EPO Trip in Spain
António Campinos being 'Marcosed'
Links 17/11/2025: "You Don't Need Animations" and Blocking Copyright-Infringing Sites Inevitably Goes Wrong
Links for the day
The Register MS: Slop is "FOMO" (Fear of Missing Out), FOMO is Funding Us
even former management (Editor in Chief of The Register MS) admitted to me it was aware of this issue
What's 4Chan and Why It's So Problematic
Incels and losers converge around online echo chambers
Difficult to Win Arguments When the Simple Facts Are Not on One's Side
Starting arguments over things when you know the facts (unlike money!) aren't on your side is a dumb move that can only ever result in severe loss of credibility
Python is Attempting an Outreach to African-Americans, Microsoft Lunduke Has a Problem With That
Did he manage to brainwash himself into this ideology wherein bigotry is in fact tolerance, inclusion, equity?
Tribalism Injures Projects
In Free software communities, there are many species and "breeds". Some developers are happy to work with everyone else based upon technical merit
IBM is Googlebombing Its Way Out of Trouble and Criticism
IBM is a dying giant
No, There is Nothing Impressive About Slop Plagiarism-Enabled, Computer-Generated Images in Your Web Site...
When people use slop they do not broadcast an embrace of innovation; they merely signal they're lazy, unethical, and unscrupulous
After Denial (of the Issues) Comes Censorship
Every critic of the status quo is "racist" and every criticism is "racism"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, November 16, 2025
IRC logs for Sunday, November 16, 2025
Intel, Facing Mass Layoffs (Including Many Key Engineers Who Work on Linux Kernel), is Pushing for Slop Inside Linux
replacing proper, well-tested code (and documentation thereof) with slop
More People Want to Quit Windows (Vista 10 is "End of Life"), Restricted Boot (UEFI) Makes That Harder
It's widely agreed (a consensus) that Restricted Boot is a bad thing for GNU/Linux
IRCNow Helped Techrights
If you want to gain more independence or "sovereignty" over your communications and need help setting things up (no prior experience setting up/configuring IRC), go to IRCNow
How We Managed to Make IRC Inclusive and Free Speech-Tolerant Without Banning People
People in IRC seldom agree on everything, more so if politics are aired and especially in the wrong context/s
UEFI 'Restricted Boot' Will Usher in Rootkits Into Linux
Those of us who understand and value what it means to truly own our devices should definitely be alarmed by these trends
Plan for European Patent Office (EPO) Coverage This Month, Next Month, and Next Year
How much longer can European politicians ignore all this corruption?
Germany-Based Focus Online is Apparently Covering Up Cocaine Use at Europe's Second-Largest Institution, the European Patent Office
More contact details for the German press - Focus online
opensource.net Dead Since Middle of Summer, opensource.org (OSI) Still Leaderless
At the moment the brand "Open Source" is misused so heavily that we have considered adding a new category to our Daily Links, focusing a lot less on "Open" and more on software freedom as a concept
Photos From Richard Stallman's Talk in Argentina Earlier Today (Remote Talk)
Dr. Stallman's talk went ahead
Slopwatch: Google News Full of Slop
Google News has serious problems
Gemini Links 16/11/2025: The Cure for Slop, Rapsberry Pi Zero 2 W, and POSIX from Ada
Links for the day
NHS Data Breach Caused by Proprietary Software, as Usual, The Register MS Blames "Hackers" and "Cybercriminal Gang"
Nothing will get solved unless we have a rethink and media quits using the "hacker" narrative, which shifts blame from the holes to those who merely exploit them
IBM is Vanishing (First Moving, Then Going Away Completely)
Salary reduction is only the first step
Links 16/11/2025: Japan-China Tensions Grow, Surveillance Giant Google Checked for Breach of the Digital Markets Act (DMA)
Links for the day
Links 16/11/2025: Censorship Battles and Margaret Sullivan Speaks
Links for the day
German Media and German Politicians: Working for the Public or Manipulating the Public?
The "common person" does not have printing presses
Informing the Public of Suppressed Facts
We are all in this together
Canadian Linus Meets Finnish-American Linus
LTT does have a very large audience, which it can steer away from Microsoft and Windows
The UK's Online Safety Act (OSA) Discourages Technological Entities, Including Free Software Projects, Being Based in or Near the UK
When it comes to IRC hosting, we never had any serious speech restrictions imposed upon us by the UK
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, November 15, 2025
IRC logs for Saturday, November 15, 2025
Father of GNU Giving Keynote Talk Today, Father of Linux Collaborating With Linus Tech Tips (LTT)
Some time soon we can expect Linus Tech Tips (LTT) / Linus Media Group / Linus Gabriel Sebastian to produce something with Torvalds
Gemini Links 16/11/2025: Emacs Font Fun and UI x TUI x CLI
Links for the day