Eye on Security: Red Hat Explains Why Windows is Less Secure, New Windows 0-Day Attack
- Dr. Roy Schestowitz
- 2010-07-01 13:46:45 UTC
- Modified: 2010-07-01 13:46:45 UTC
Summary: Comparative security news from this week
●
Open Source is Inherently More Secure, Says Red Hat (Microsoft
admits silent patching it never discloses)
But in the closed source world, you have to trust your vendor completely. All you get to see are binaries, so you have no way of knowing how they were built. President Reagan was fond of saying to Soviet leader Mikhail Gorbachev, "Trust, but verify." With proprietary software, you simply have to trust.
Microsoft, for example, pushes out security updates on the second Tuesday of every month. Bressers said they can't do that. Microsoft has the advantage of hiding security flaws and working on them at their leisure, but with open source software, that's not possible because everyone can see that there's a problem and they expect it to be fixed right away.
And if a security hole isn't plugged quickly enough, you can fix it yourself, Bressers explained.
An example of the power of open source is the ping of death bug. Back in the late 1990s someone figured out that if you send a giant ICMP packet to a computer, just about any computer, it will crash. The bug affected every operating system, routers, printers, etc. When the problem was discovered, the open source Linux operating system had the bug squashed in about 2 hours, Bressers recalled. The closed source operating system vendors, however, took days, weeks and even months to make and distribute a patch for the ping of death.
●
Microsoft: 10,000 PCs hit with new Windows XP zero-day attack
Nearly a month after a Google engineer released details of a new Windows XP flaw, criminals have dramatically ramped up online attacks that leverage the bug.
Microsoft reported Wednesday that it has now logged more than 10,000 attacks. "At first, we only saw legitimate researchers testing innocuous proof-of-concepts. Then, early on June 15th, the first real public exploits emerged," Microsoft said in a blog posting.
●
New Windows Live Messenger has same old privacy problems
Why do I get the impression that some folks at Microsoft just don’t get it?
●
Privacy problems persist in latest Windows Messenger 2011 beta [
via]
Earlier versions of Messenger played fast and loose with your privacy. The new Live Messenger 2011, currently in beta, suffers from some of the same defects
Recent Techrights' Posts
- This is How Microsoft's XBox and Entire Consoles (If Not Gaming) Ventures Will Ultimately Die
- Ensure you can blame "Tariffs" (politics)? If not "hey hi", the fashionable go-to excuse when businesses fail?
- The Complaint About Brett Wilson LLP - Part II - UK SLAPPs for Americans, SLAPPs for Profit
- Brett Wilson LLP has a track record of this kind
- Cloudflare Gives Us All Another Reason to Boycott Cloudflare
- If Cloudflare wants to use its vast surveillance network (which is what it does as a CDN) to foist paywalls and maybe something worse (like DRM on top), then Cloudflare should be more widely rejected as a company
- Someone Expiring Certificates on the Day of the 9/11 Attacks is Not Someone I Would Want Controlling My PC (or Deciding What's Authorised for Booting)
- "social justice warriors"
- More Microsoft-Red Hat Cross-Pollination as the Company Loses a Managing Director
- some people move from Microsoft to Red Hat and some do the opposite
-
- Punching People Doesn't Work
- It makes nobody any safer
- Look Ma, No "Cloud"
- So far this year we've had an almost perfect uptime
- Links 24/09/2025: Autism Blame-Shifting and Typhoon Ragasa Enters China
- Links for the day
- Buying From Oneself is Not Business Success
- This isn't at all a joking matter even if you already laugh at the whole thing because your pension, savings etc. are tied to this scam at some level
- What They Really Hate David Heinemeier Hansson (DHH) for
- Nothing to do with code
- Smart People Won't Buy 'Smart' Cars
- Imagine trying to sell someone a house (proper home) while insisting that it'll need to be demolished 5 or 10 years later, then rebuilt again from scratch on the same vacant lot
- The Relationship Between IBM Red Hat and Microsoft, Visualised
- This metaphor goes a long way (projects, collaborations, and outsourcing
- The Complaint About Brett Wilson LLP - Part III - Spying on Reporters' Families, Chaining Cases for Microsoft Employees Who Demand Censorship of Facts (Even Politely Expressed)
- the time seems right to wrap up this introductory series
- Links 24/09/2025: "NASA Moving Out of Entire Buildings as It's Gutted" and Purge of Online Critics (Opposing Fascism Becomes Unlawful)
- Links for the day
- Science is Under Attack
- Oligarchy prefers a dumbed-down population
- The Solicitors Regulation Authority (SRA) Has Reportedly Failed People With Wrong Advice
- At the moment the SRA has a PR blunder
- The Man Suing Brett Wilson LLP and Gervase de Wilde (5RB)
- Now he's probably using the (almost) 200,000 pounds he's supposed to receive to sue Brett Wilson LLP and former colleagues/partners
- Slopwatch: A World Wide Web That's Rotting for Companies That Won't Even Exist in a Few Years
- some of the junk Google News is promoting
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Tuesday, September 23, 2025
- IRC logs for Tuesday, September 23, 2025
- Links 24/09/2025: Qt Creator 18 Beta, Microsoft Cannot Bail Out "ChatGPT" Anymore, China and US Intensify Censorship
- Links for the day
- Gemini Links 24/09/2025: Gemlogs and Politics
- Links for the day
- Links 23/09/2025: Japan Limits Uses of Skinnerboxes ('Smartphones') With Toxic "Apps", Fentanylware (TikTok) Tapped by "MAGAts"
- Links for the day
- Brett Wilson LLP Has Just Been Sued (by Their Own Clients!)
- Vladimir and Alla Yanpolsky sued Brett Wilson LLP in BL-2025-001167 at the end of last week
- Mayday: Optus emergency calling crisis
- Reprinted with permission from Daniel Pocock
- Links 23/09/2025: Massive Data Breach, Slop Versus Productivity, and Vista 11 Update Breaks Things Again
- Links for the day
- Code of Censorship
- Extortion is peace
- The Free Software Foundation (FSF) Has Un-cancelled the Best People, Just in Time for the Big 4-0
- Mr. Oliva should have been there all along (since 2019)
- Most "Modern" Technology Makes You Slower and Dumber
- Because proprietary software makes you worse off
- "What Comes After Free Software?" Wrongly Insinuates We've Reached the Goal (Prison is Not the Goal)
- The oil tycoons use similar tactics against environmentalists, giving them fake "wins"
- Making More Work Space
- I learned the hard way that less is more in circumstances where more means distraction
- MAHA is a Lie, Public Officials Never Valued Citizens' Health (They Still Value Private Businesses, Their Sponsors)
- Reject demagogues
- Free Software Foundation (FSF) Has a New Press Kit for the Weekend After Next Weekend (40th Anniversary)
- miles better than social [sic] media [sic] quips, moderated by narcissists and oil tycoons.
- Microsoft Had Two Waves of Mass Layoffs This Month (That We Know of) and It'll Get Worse for Microsoft Soon
- Will the axe fall again by month's end?
- Gemini Links 23/09/2025: Happy Equinox, Photronic Arts, and Perception Cognition
- Links for the day
- Lessons We've Learned After 17 Years of American Hosting
- GAFAM is "all-in" with the "Trump agenda"
- Back to Normal Now, We Plan to Do More In-Depth Series (or Multi-part Stories)
- Articles (or series thereof) that contain philosophy are important to us
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, September 22, 2025
- IRC logs for Monday, September 22, 2025
- Microsoft Media is Panicking Amid Mass Layoffs Every Month, H-1B Fees, and "Seattle’s Tech Scene in Trouble"
- In "late stage Microsoft", copyleft becomes proprietary
- The Next Wave of IBM/Red Hat Layoffs Being Discussed Already
- Red Hat is sort of disappearing the way Tivoli did
- New Techrights Turns 2
- Today starts the third year of the SSG-based Techrights
- What Scares Them the Most is Independent News Sites That They Cannot Control and Censor
- Wikileaks was a good example of this
- If You Don't Control Your Online Platform, Then Someone Else is Controlling You
- be (or become) independent
- Oracle Started This Year With Slop. Then It Stopped.
- Passing fads are like this
- Distros That Run on PCs Made 20 Years Ago and Don't Use Systemd
- Betas for now
- The Solicitors Regulation Authority (SRA) Has a Policy on Racism and Sexism
- In then future we'll show the misogyny and racial slurs
- The Complaint About Brett Wilson LLP - Part I - Abusing British Women on Behalf of American Men Who Abuse American Women
- Transparency is important to us, so we've decided to make this series
- Slopwatch: Google News and the Evident Slopfarm Infestation
- This is what people get about Linux when they query Google for Linux
- Links 22/09/2025: Murdochs Might Join Fentanylware (TikTok) 'Investors' (Masters), United Kingdom Recognises Palestinian Statehood
- Links for the day
- Gemini Links 22/09/2025: Esperanto Music History and Apps For Android
- Links for the day
- Links 22/09/2025: More American 'Censorship' (Retaliation for Journalism), Cheeto "Might Be Losing His Race Against Time"
- Links for the day
- The Blob Slop
- Give me more words, give me some text
- The 50-Pound Note Experiment and the "War on Cash"
- Britain is actually seeing a rebound in cash payments, and it's not a temporary phenomenon
- Slopwatch: Blaming the Victims for Microsoft's Failures and Plagiarising Phoronix
- That's what Google has been reduced to: slop and slopfarms
- Links 22/09/2025: Breaches, Windows TCO, and Arrests
- Links for the day
- Gemini Links 22/09/2025: Rabbit Hole and DeGoogling Fairphone
- Links for the day
- Links 22/09/2025: Russian War Planes Invade NATO Airspace While Dihydroxyacetone Man Escalates Attack on Free Speech Because of Critics
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, September 21, 2025
- IRC logs for Sunday, September 21, 2025
Comments
saulgoode
2010-07-01 14:10:44
Not just trust the vendor, but also those with whom they've shared the source code (subcontractors, governments, large corporate clients, etc).
It is noteworthy that there were claims that the recent attack on Google stemmed from sources within the Chinese government (with whom MS shares its source code), it is not that surprising that Google would quickly put an end to a situation where the malware authors get to see the Windows source code and they do not.
Dr. Roy Schestowitz
2010-07-01 14:17:26