Eye on Security: Red Hat Explains Why Windows is Less Secure, New Windows 0-Day Attack
- Dr. Roy Schestowitz
- 2010-07-01 13:46:45 UTC
- Modified: 2010-07-01 13:46:45 UTC
Summary: Comparative security news from this week
●
Open Source is Inherently More Secure, Says Red Hat (Microsoft
admits silent patching it never discloses)
But in the closed source world, you have to trust your vendor completely. All you get to see are binaries, so you have no way of knowing how they were built. President Reagan was fond of saying to Soviet leader Mikhail Gorbachev, "Trust, but verify." With proprietary software, you simply have to trust.
Microsoft, for example, pushes out security updates on the second Tuesday of every month. Bressers said they can't do that. Microsoft has the advantage of hiding security flaws and working on them at their leisure, but with open source software, that's not possible because everyone can see that there's a problem and they expect it to be fixed right away.
And if a security hole isn't plugged quickly enough, you can fix it yourself, Bressers explained.
An example of the power of open source is the ping of death bug. Back in the late 1990s someone figured out that if you send a giant ICMP packet to a computer, just about any computer, it will crash. The bug affected every operating system, routers, printers, etc. When the problem was discovered, the open source Linux operating system had the bug squashed in about 2 hours, Bressers recalled. The closed source operating system vendors, however, took days, weeks and even months to make and distribute a patch for the ping of death.
●
Microsoft: 10,000 PCs hit with new Windows XP zero-day attack
Nearly a month after a Google engineer released details of a new Windows XP flaw, criminals have dramatically ramped up online attacks that leverage the bug.
Microsoft reported Wednesday that it has now logged more than 10,000 attacks. "At first, we only saw legitimate researchers testing innocuous proof-of-concepts. Then, early on June 15th, the first real public exploits emerged," Microsoft said in a blog posting.
●
New Windows Live Messenger has same old privacy problems
Why do I get the impression that some folks at Microsoft just don’t get it?
●
Privacy problems persist in latest Windows Messenger 2011 beta [
via]
Earlier versions of Messenger played fast and loose with your privacy. The new Live Messenger 2011, currently in beta, suffers from some of the same defects
Recent Techrights' Posts
- 10 Easy Steps to Follow for Digital Sovereignty in Nations That Distrust GAFAM et al
- When "enough is enough"
- Dr. Andy Farnell Explains Why Slop Companies Like Anthropic and Microsoft 'Open' 'AI' Basically Plunder and Rob People
- This article was published last night at around 10
-
- Salvadorans' Usage of GNU/Linux Measured at Record Levels
- All-time high
- Links 22/01/2026: Ubisoft Layoffs Disguised as "RTO", US "Congress Wants To Hand Your Parenting To GAFAM", Americans' Image Tarnished Among Canadians (Now Planning to "Repel US Invasion")
- Links for the day
- No, the Problem at IBM/Red Hat Isn't Diversity
- Microsoft Lunduke also openly shows his admiration for Pedo Cheeto
- Do Not Link to Linuxiac Anymore, Linuxiac Became a Slopfarm
- now Linuxiac is slop
- Richard Stallman (RMS) at Georgia Tech Tomorrow
- After the talk we'll write a lot about "cancel culture" and online mobs fostered and emboldened in social control media
- Software Patents by Any Other Name
- There is no such thing as "AI" patents
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Wednesday, January 21, 2026
- IRC logs for Wednesday, January 21, 2026
- The "Alicante Mafia" - Part VIII - Salary Cuts to Staff, 100,000 Euros to Managers Busted Using Cocaine (for Doing Absolutely Nothing, Just Pretending to be "Sick")
- Today we look at slides from the union
- Gemini Links 22/01/2026: Forest Monk, Aurora Observation, and Arduino Officially Launches the More Powerful Arduino UNO Q 4GB Single-Board Computer
- Links for the day
- Next Week is Close Enough for Wall Street Storytelling About 'Efficiency' by Layoffs for "AI"
- This coming week GAFAM and others will tell some creative tales about how "AI" something something...
- Google News Still a Feeder of Slop About "Linux", Which Became Rarer in 2026
- Our main concern these days is what happened to Linuxiac. Bobby Borisov became a chatbots addict.
- Links 21/01/2026: "Snap Settles Lawsuit on Social Media Addiction" and Attempts in the US to Revive Software Patents
- Links for the day
- Links 21/01/2026: Microsoft 'Open' 'Hey Hi' in More Trouble, US Has "Brown Shirts" Problem
- Links for the day
- Yesterday Afternoon The Register MS Published Paid Microsoft SPAM Disguised as an Article About "AI PCs"
- The Register MS cannot help itself, can it? [...] Follow the money.
- Microsoft's XBox is in Effect Dead Already, Now It's a Streaming and Advertising Platform
- Expect many layoffs soon
- Richard Stallman's Talk at Georgia Tech is Just 2 Days Away
- We're still curious to see how malicious people (or trolls) in social control media will try to slant his talk as "bad"
- EPO's Web Site Misused for Propaganda About Illegal Kangaroo Courts to Distract From EPO Scandals and Judicial Crisis in Europe
- UPC is illegal and unconstitutional
- The "Alicante Mafia" - Part VII - The Industrial Actions Began Yesterday, Here's Why
- The "Alicante Mafia" might not last much longer
- Gemini Links 21/01/2026: Edible Circuits and "Sayonara HTTP"
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Tuesday, January 20, 2026
- IRC logs for Tuesday, January 20, 2026
- IBM Hides Its Own Destruction (and Red Hat's)
- It's like scenes out of '1984', which is what a now-famous advertisement from Apple compared IBM to
- LLM Slop Not Dead Yet, Examples of Slop About "Linux"
- We wish to see the totals down to zero
- Links 20/01/2026: Cheeto Blackmails France Into 'Peace' While Looking to Annex EU, Mass Layoffs in Capgemini (Microsoft Reseller/Promoter) in France
- Links for the day
- Gemini Links 20/01/2026: Boxing and "Inbox Zero" Success
- Links for the day
- Windows and Slop Declining While Microsoft Silences Critics
- Microsoft tries to suppress facts while faking 'demand' by imposing slop on everybody, everywhere
- openai.com Traffic Said to Have Fallen 50% in the Past Three Months, Reports Say It Nearly Ran Out of Money to Borrow
- After the slop frenzy all we'll have left is environmental destruction
- IBM Kills OzLabs, Signalling An Attack on Free Software (a Sign for Red Hat)
- ibiblio also appears to have died (or experiences critical issues)
- Red Hat Vice President Leaving After Nearly Two Decades
- IBM's culture of secrecy is not compatible with Free software
- Links 20/01/2026: "ChatGPT Health" (Latest Distraction From Being Insolvent) Flops and Raises Concerns, "The U.S. Military Faces a Reckoning on Greenland"
- Links for the day
- Rudeness and Vulgarity Won't Stop Journalism About Free Software
- we seem to be on the right path
- Readers Pleased With Layout Changes
- Two days ago we began improving clarity and accessibility in the site
- IBM Plans for Layoffs Becoming Clearer With "Employee Reviews"
- Of course this impacts Red Hat as well
- IBM is Outsourcing Red Hat's Fedora to Slop to 'Save Money'
- If IBM cared about quality rather than alleged "cost savings" (cutting corners), it would assign more IBM staff to Fedora, but instead the exact opposite happened, with the likes of Cotton and Miller removed from the project
- European Patent Office (EPO) Industrial Actions Formally Start in Two Hours
- As per the latest (revised) action plan, today workers will slow down their work and limit patent grants
- Microsoft Under Fresh Investigation by the Italian Competition Authority
- In 2025 we kept a running tally of 30,000+ Microsoft layoffs, so 40k this year would not be unthinkable
- The "Alicante Mafia" - Part VI - More Strikes Planned at the EPO, Starting This Month
- Yesterday we said that friends of Berenguer or inside Berenguer's circle may have left
- Gemini Links 20/01/2026: New Tea, Using a Roku at a Hotel, and "Voltage-Based Power Management for Any Raspberry Pi"
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, January 19, 2026
- IRC logs for Monday, January 19, 2026
Comments
saulgoode
2010-07-01 14:10:44
Not just trust the vendor, but also those with whom they've shared the source code (subcontractors, governments, large corporate clients, etc).
It is noteworthy that there were claims that the recent attack on Google stemmed from sources within the Chinese government (with whom MS shares its source code), it is not that surprising that Google would quickly put an end to a situation where the malware authors get to see the Windows source code and they do not.
Dr. Roy Schestowitz
2010-07-01 14:17:26