Eye on Security: Red Hat Explains Why Windows is Less Secure, New Windows 0-Day Attack
- Dr. Roy Schestowitz
- 2010-07-01 13:46:45 UTC
- Modified: 2010-07-01 13:46:45 UTC
Summary: Comparative security news from this week
●
Open Source is Inherently More Secure, Says Red Hat (Microsoft
admits silent patching it never discloses)
But in the closed source world, you have to trust your vendor completely. All you get to see are binaries, so you have no way of knowing how they were built. President Reagan was fond of saying to Soviet leader Mikhail Gorbachev, "Trust, but verify." With proprietary software, you simply have to trust.
Microsoft, for example, pushes out security updates on the second Tuesday of every month. Bressers said they can't do that. Microsoft has the advantage of hiding security flaws and working on them at their leisure, but with open source software, that's not possible because everyone can see that there's a problem and they expect it to be fixed right away.
And if a security hole isn't plugged quickly enough, you can fix it yourself, Bressers explained.
An example of the power of open source is the ping of death bug. Back in the late 1990s someone figured out that if you send a giant ICMP packet to a computer, just about any computer, it will crash. The bug affected every operating system, routers, printers, etc. When the problem was discovered, the open source Linux operating system had the bug squashed in about 2 hours, Bressers recalled. The closed source operating system vendors, however, took days, weeks and even months to make and distribute a patch for the ping of death.
●
Microsoft: 10,000 PCs hit with new Windows XP zero-day attack
Nearly a month after a Google engineer released details of a new Windows XP flaw, criminals have dramatically ramped up online attacks that leverage the bug.
Microsoft reported Wednesday that it has now logged more than 10,000 attacks. "At first, we only saw legitimate researchers testing innocuous proof-of-concepts. Then, early on June 15th, the first real public exploits emerged," Microsoft said in a blog posting.
●
New Windows Live Messenger has same old privacy problems
Why do I get the impression that some folks at Microsoft just don’t get it?
●
Privacy problems persist in latest Windows Messenger 2011 beta [
via]
Earlier versions of Messenger played fast and loose with your privacy. The new Live Messenger 2011, currently in beta, suffers from some of the same defects
Recent Techrights' Posts
- Brian Fagioli's Latest "Linux" Article Appears to be Fake
- Another form of plagiarism/ripoff using bots?
- [Meme] When the People Who Falsely Accuse You of Pedophilia Turn Out to be Projecting
- When you attack something or someone using falsehoods, as happens a lot to Richard Stallman (RMS), there's risk that the attacks will backfire, badly
- Why I Continue to Believe That at the End Software Freedom Will Win
- a short and incomplete list of factors which I believe contribute to the sentiment that we can - and will - win the battles over hearts and minds in the "Tech" realm
- Technology: rights or responsibilities? - Part X
- By Dr. Andy Farnell
-
- Saving What's Left of Decent and Independent Journalism on the Web
- We increasingly (over time) try to make local copies (hosted on our server) of important documents; it's hard to rely on third parties
- [Meme] Microsoft's Latest Marketing Pitch
- "Stop Being Poor; buy a new PC with TPMs"
- In South Africa, a Very Large Nation, Web Developers Can Already Ignore Microsoft Browsers (Edge Measured Below 3% in 55 Nations)
- The dumb assumption you must naively test with Microsoft browsers is no longer applicable in a lot of places
- Open Source Initiative (OSI) is the Voice of Bill Gates and Satya Nadella
- Not hard to see what they've done with the money
- Microsoft Boasts That Its (Microsoft-Sponsored) "Open Source AI" Propaganda Got Cited in Media (That's Just What the Money Did)
- This is a grotesque openwashing campaign
- In Many Places Around the World, Perhaps as Expected, Yandex is Nearly Bigger Than Microsoft (Like in Several African Countries)
- Microsoft may soon fall to "third place" in search
- Keeping Productive This Christmas
- We've (pre)paid for hosting till almost January 2026 and fully back on the saddle
- IBM and Canonical Leave Money on the Table Because Microsoft Pays Them Not to Compete and Instead Market Windows, WSL, Microsoft 'Clown Computing', and TPMs
- Where are the regulators?
- Other Editors Who Agree "Hey Hi" (AI) is Just Hype But Won't Say So Publicly as It Might Upset Key Sponsors
- Some media would gladly participate in a scam to make money
- IBM (and Red Hat) is a Patent Troll, Still Leveraging Software Patents to Extract Money Out of Other Companies by Suing Them
- Basically, when it comes to patents, IBM is demonstrably part of the problem, not the solution
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Tuesday, December 17, 2024
- IRC logs for Tuesday, December 17, 2024
- In Some Countries, Such as Greece, Almost 80% of Windows Users Are on Vista 10 and About 85% Need to Move to GNU/Linux for Security Patches
- Vista 11 was a failure
- [Meme] They Don't Want the Public to Know What "Responsible Encryption" Really Means
- They also blame "China" for their own back doors (because China learned how to exploit those)
- The Linux Foundation's Certificate Authority (CA) Significantly and Suspiciously Raises the Number of Certificates It Issues (Quantity Increase/Inflation) by Lessening Their Lifetime in the Name of 'Security' (That Barely Makes Sense!)
- LE made 3 months the "standard" for most, soon to become just 6 days instead of 6 months?
- Links 17/12/2024: More China Sanctions, GOP Scheming to Prop Up Fentanylware (TikTok)
- Links for the day
- Gemini Links 17/12/2024: The Streisand Effect and Productivity-systems Desiderata
- Links for the day
- Links 17/12/2024: More "Tesla Autopilot" and "Hey Hi" (AI) Blunders
- Links for the day
- Instead of Promoting GNU/Linux (or Ubuntu) Ahead of Vista 10's EoL Canonical is Marketing Microsoft's Proprietary Software
- It's like Canonical employs people who work for Microsoft, not for Canonical
- Links 17/12/2024: Many Abuses by Microsoft and War Updates From Ukraine
- Links for the day
- Content Management Systems (CMS) Bloat/ Static Site Generators (SSG) Trouble
- some Web site management stories
- DEI Room at fedoraproject.org Pretty Much Dead
- We're not against diversity but against its weaponisation by greedy people who do not value diversity at all
- The "Latest Technology News" at BetaNews is Slop About Slop
- This is at the very top of the "news" (front page) at the moment
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, December 16, 2024
- IRC logs for Monday, December 16, 2024
- Gemini Links 16/12/2024: Invisibles and 20 Years of GNU/Linux on the Desktop
- Links for the day
- Microsoft's Windows Fell From 98% to Less Than 15% (in 15 Years in Africa)
- Operating System Market Share Africa
- Swaziland: GNU/Linux Leaps to 7.24%, Based on statCounter
- Remember that Microsoft had many layoffs this year in Africa
- A Birthday Wish
- My birthday is a few hours away
- [Meme] Definitely Not Your Role Models
- Hypocrite Neckbeard Meme
- Changes or Variation of Logo at the FSF as 40th Anniversary is Near (Months Away)
- Next year the FSF turns 40
- Mobile Usage Nearly 90% in Maharlika (Philippines)?
- Microsoft has become just a footnote
- Push Back and Become More Vocal for LLM Abuse and Misuse to Stop
- We hope that more people out there (sites too) will call out the people who saturate particular topics on the Web with machine-generated junk
- The Media Failed to Hold GAFAM Accountable (and Now It Suffers From It and For It)
- This recognition of the problem emboldens us to carry on
- Botswana: New Highs for GNU/Linux, All-Time Lows for Microsoft
- No wonder Microsoft has so many layoffs in Africa this year
- Links 16/12/2024: Skinnerboxes ("Smart" "Phones") and Control Social Media Blamed for Fights
- Links for the day
- Reminder: The Microsoft Person Who Used OpenAI for En Masse GPL Violations Told the Whistleblower to Kill Herself
- The evidence (real message)
- Links 16/12/2024: emacs, Drawabox, “You Should Have Your Own Website”
- Links for the day
- In Some Parts of the World, Like Central America and South America, Microsoft is Irrelevant on the Web
- Nadella has bet the farm on a Ponzi scheme
- [Meme] Microsoft is Not a Country
- Reporting crimes is essential for democracy
- There's Not Much Time Left for President Biden to Pardon Julian Assange and Signal to Journalists That Exposing States' Crimes or Rich People's Misbehaviour is Lawful
- Apathy towards this is part of the problem
- Image Fusion is Not 'AI' (LLMs Aren't Either)
- Such fakes can (and always could) be done by a digital artist, it's just a little more expensive and time-consuming
- GNU/Linux at New Highs in Bosnia And Herzegovina
- Quite a few Balkan nations show high adoption rates for GNU/Linux
- From Scientists to Pigeons: The EPO Has Turned Patent Examination Into a Process Made by Computers and Improperly Trained Staff Which Doesn't Meet the Requirements of the European Patent Convention (EPC)
- Might as well abolish this entire system if this is the current trajectory
- Razik Menidjel Will No Longer be Chief Operating Officer Operations at the EPO
- What does the EPC say about slop and should it be updated to deal with trouble such as slop?
- Underpaid and Inexperienced Workers Overwhelm the EPO, Granting Many Invalid Patents and Placing Pressure on Veteran Examiners
- So-called "production" (giving monopolies) pressure is "compromising the quality of our products" [sic] according to a new report
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, December 15, 2024
- IRC logs for Sunday, December 15, 2024
Comments
saulgoode
2010-07-01 14:10:44
Not just trust the vendor, but also those with whom they've shared the source code (subcontractors, governments, large corporate clients, etc).
It is noteworthy that there were claims that the recent attack on Google stemmed from sources within the Chinese government (with whom MS shares its source code), it is not that surprising that Google would quickly put an end to a situation where the malware authors get to see the Windows source code and they do not.
Dr. Roy Schestowitz
2010-07-01 14:17:26