Bonum Certa Men Certa

Former Novell Staff Still Pushing the Linux Foundation Into Restricted Boot Territory, Ignoring the Real Threat (Back Doors)

Greg Kroah-Hartman
Photo by Sebastian Oliva



Summary: Back doors in code, embedded in blobs, and even shoehorned into encryption is the overlooked security threat, which gets pushed aside in favour of phantom threats which Microsoft 'sells' through former Novell staff (i.e. funded by Microsoft)

A MONTH or two ago we mostly ignored exaggerated (sexed-up) reports about something called "Hand of Thief". When there's a Windows security threat the press does not call out Windows, but when it relates to GNU/Linux then tabloids like ZDNet scream from the rooftops. This thing called "Hand of Thief" is basically a malicious program which GNU/Linux users need to install themselves in order for it to do malicious things. It is not a virus, it does not spread, and it hardly even uses social engineering to get itself installed. We cited some reports which stress these facts and now comes a belated one too [1]. LynuxWorks is now offering some "Linux rootkit detector" [2] as if rootkits on GNU/Linux are a common issue. In a sense, since the Linux Foundation seems to insist on helping UEFI restricted boot, we are led to the belief that bootkits are a common threat to Linux. As the Linux Foundation's site put it, as in the words of the employee it acquired from Novell:



Now that The Linux Foundation is a member of the UEFI.org group, I’ve been working on the procedures for how to boot a self-signed Linux kernel on a platform so that you do not have to rely on any external signing authority.


Greg K-H has been working on all sorts of other kernel-level projects that help Microsoft. He did this while being paid by Novell, which was in turn being given money by Microsoft. That's the power of money. Other former Novell employees also helped promote UEFI restricted boot, as we showed before. Rogue influence by Novell in the Linux Foundation is a subject we have written about for half a decade, showing numerous examples.

The bigger security issue right now might be back doors, which might also exist in Linux, even in encryption form [3] (giving away passwords over the network for example), so hard-to-crack passwords [4] might not be enough. Microsoft's and Sony's network compromises sure reveal the massive financial effects of system intrusions, so this subject should not be taken lightly.

UEFI restricted boot is actually a security threat, not a security solution, especially when a signature is provided and managed by some rogue company in the United States -- one which has been secretly in bed with the NSA. With UEFI restricted boot, hardware can be bricked remotely. In a way, UEFI restricted boot deserves the name "unsecure boot". In some devices it can block the user from accessing his/her own computer. Nobody should promote such treacherous computing.

Related/contextual items from the news:



  1. Hand of Thief, Not
    Linux's biggest vulnerability is the software that users install with full "superuser" privileges. If you just install applications from your distro's official repository, that's not a problem. But if you download software from dubious web sites, or if you add a mysterious repository to your package manager, you're opening yourself up for an infection. Always, always make sure you know what software you are installing, why you are installing it, and where it's from.


  2. Linux rootkit detector adds hardware punch to security scanning
    LynuxWorks is stepping up the battle with the release of the first hardware-based rootkit detection system powered by the LynxSecure separation kernel. Called the RDS5201, it combats and detects stealthy advanced persistent threats. Built on the LynxSecure 5.2 separation kernel and hypervisor, this small form factor appliance has been designed to offer a unique detection capability that complements traditional security mechanisms as they try to protect against the growing number and complexity of cyber threats.


  3. RSA warns developers not to use RSA products
    In today's news of the weird, RSA (a division of EMC) has recommended that developers desist from using the (allegedly) 'backdoored' Dual_EC_DRBG random number generator -- which happens to be the default in RSA's BSafe cryptographic toolkit. Youch.
  4. How-to make hard-to-crack passwords you can easily remember


  5. Australian who boasted of hacking to plead not guilty to charges stemming from raid
    Dylan Wheeler, who claimed in February to have breached Microsoft's and Sony's networks, has not been charged with hacking




Recent Techrights' Posts

Software Freedom Conservancy (SFC) Does Not Support Women, It Imitates Authentic Organisations, Embraces Misogynists, Then Projects
They try to monetise for personal gain at the expense of unpaid volunteers
When You're Evil and You're Publicly Attacking Something, That Something Will Become More Popular
when an oppressor becomes openly oppressive and does anything to squash/censor critics, the outcome will typically be detrimental to the oppressor
Links 10/08/2026: "Against Oligarch" and "The Invisible Women"
Links for the day
Social Control Media Deathwatch: After Nearly a Million Posts Sent EchoFeed Shuts Down
EchoFeed is hardly unique
When the LLM Chatbots Industry (Trillions in the Red) Quits Paying the Media for FOMO
fear of missing out, or FOMO for short
Microsoft Killing Morale
branding the process “inhumane” and “demoralizing”
Google's "AI Overview" as Proprietary Censorship Engine and Gatekeeper
People do not choose to use this, Google is just shoving that in people's faces, encouraging laziness and misinformation
SLAPP Censorship - Part 145 Out of 200: They Tried Hard to Hide the Fact Their Client Had Been Sued, Twice Even
A month ago Brett Wilson LLP tried to take my wife "to the side" (in effect isolated) to make her an offer
statCounter: GNU/Linux Up to 8.95% Globally
So the estimates are being "corrected" upwards, not downwards
Explaining How Someone Attempted to Cancel RMS This Year (and Failed)
The process itself involved debunking some falsehoods
Microsoft's "XBOX Ranks Last", IBM is Headed for Extinction
If Microsoft cannot dominate its own "home turf", what prospects are there elsewhere?
DebConf6 fight denied by Google artificial intelligence
Reprinted with permission from Daniel Pocock
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, August 09, 2026
IRC logs for Sunday, August 09, 2026
Gemini Links 10/08/2026: A Mild Monday, Sleepy Saturday, OUYA, and Moving to GNU/Linux
Links for the day
Links 09/08/2026: US Blackouts (Energy Wasted), Slop to Evade Accountability, and Software Patents Framed as "Hey Hi"
Links for the day
Gemini Links 09/08/2026: Parakeets in Britain and Rant About 'Modern' Washing Machines
Links for the day
Links 09/08/2026: Social Control Media Weaponises Immigration, Europe Suffers Severe Drought, and "Internet of Stuff" Explained
Links for the day
SLAPP Censorship - Part 144 Out of 200: The "Hired Guns" ("Media" at BW) Shrank Almost Three-Fold Since They Sued Us in 2024
No wonder they're so visibly outnumbered
10 Days Ago Red Hat Formally Terminated Employment of About 500 Technical Workers (the Media Didn't Mention This)
IBM has nothing left to do except fire people (in secret) whilst attacking sites that give these people a voice
Freenode Continues to Shed Off Servers and Users, Good Thing We Abandoned It
you cannot sell communities. It leads to chaos
Daniel Pocock in the Sunday Times (Today)
Expect the attacks (from Pocock's haters, motivated by envy) to intensify
Controlling One's Platform
We need to strive for or actively pursue a Web where everyone has their own platform/s and where censors ("moderators") have no direct control over these platforms
Improving the Static Site Generator (SSG), Fixing Bugs
Next month the site's SSG turns 3
Gemini Links 09/08/2026: Meatballs (1979), Gopher, RSS Experiment
Links for the day
2026: The Year Richard Stallman Came Back to American Campuses
There's more on the way
IBM's "Next Step" Program
Apparently close to 1,000 people being laid off by IBM wasn't worth reporting
XBox is Rotting Away, Technical Issues for Second Time in Two Weeks
XBox is dying
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 08, 2026
IRC logs for Saturday, August 08, 2026
Red Hat is in Need of a 'Jolla', as an IBM-Controlled Red Hat is Becoming Like the Microsoft-Infiltrated Nokia
Dying fast, partly by design
Gemini Links 08/08/2026: Gigs, Poems, SREs, and Shared Passion
Links for the day
If GNU/Linux Rising is Just "Bots" (It's Not, Many Surveys Show the Same), Why Does Microsoft Rush to Lie About System Requirements of Vista 11?
The real reason is, GNU/Linux is rising
Kompromat Tactics in GNU and Linux
Kompromat as a concept was covered here in the past in relation to Microsoft
SLAPP Censorship - Part 143 Out of 200: After Nearly 10 Attempts to Settle With Us and Over a Million Pounds Spent on Lawyers and Barristers
We are in no particular hurry
20 Years and 43 Years
GNU/Linux is not just code, it's a philosophy, licence (copyleft), and community
GNU/Linux Turns 43 Next Month, Many Distros Actively Maintained
A lot of Debian-based distros are still actively maintained (we talk about this in IRC this evening), so the stability of the Debian Project is important
Links 08/08/2026: GAFAM Colonialism "Paved Over Protected Wetlands", Slop Companies Hoard Software Patents as Debt Soars to Trillions
Links for the day
Links 08/08/2026: "Palantir Paid No Federal Income Tax" and "Who's Responsible for This Mess?"
Links for the day
Retained: The Time IBM's Red Hat Tried to Hijack or Take Offline Site of Critics, Failed on All Grounds (Meritless Action Intended to Harass Critics)
Replicated from adrforum.com
IBM's 'Final Solution': Censor Sites Not Controlled by IBM, Sites Where Dissent is Expressed
IBM has no culture of free speech
More Mass Layoffs Coming IBM's Way (Ones IBM Cannot Hide, Cannot Convince Enough People to Leave or Unjustifiably PIP Them When They Say No)
The company that was like a "father of modern computing" is now stingy when it comes to travel. Not a good sign.
What Will it Take for Mainstream Media to Report Silent or Secret Layoffs at IBM?
"Silent" or "secret" sometimes because the media won't cover them
Is the Future of IBM Red Hat Temporary Staff, Contractors?
They want cheap, obedient lemmings
Gemini Links 08/08/2026: Tribute to Lloyd Center, Radio Amateurism, Homeworlds
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, August 07, 2026
IRC logs for Friday, August 07, 2026