Bonum Certa Men Certa

For Real Security, Use CentOS -- Never RHEL -- and Run Neither on Amazon's Servers

Red Hat logo



Summary: Never run Red Hat's "Enterprise Linux", which cannot be trusted because of NSA involvement; Amazon, which pays Microsoft for RHEL and works with the CIA, should never be used for hosting

SEVERAL years ago CentOS almost died; now it's being embraced by Red Hat and one pundit from tech tabloid ZDNet is moving to CentOS Linux on the desktop [1,2].



CentOS is still in the news [3], with the CentOS project leader (Karanbir Singh) giving an interview to the Linux Foundation [4]. We trust CentOS, whereas trusting Red Hat is hard. RHEL is binary and based on news from half a decade ago, the NSA is said to be involved in the building process, as well as SUSE's, whereas CentOS is built from source (publicly visible). Microsoft and the NSA do the same thing with Windows and it's now confirmed that Windows has NSA backdoors.

Earlier this month vulnerabilities in RHEL's openssl and RHEL's gnupg [5,6], contributed even less to trust. RHEL is so standard in the industry that it would probably be simpler than other distributions to exploit; the NSA may as well have off-the-shelf exploits for all major RHEL releases, which are deployed in many countries' servers (even so-called 'rogue' countries). Based on the NSA leaks, Fedora -- not RHEL -- is being used by the NSA itself to run its spying operations (e.g. collecting radio signals from afar). Fedora is not truly binary-compatible and its source code makes secrets hard to keep.

Lastly, mind the latest of Red Hat's Fog Computing hype [7,8], including the CIA's partner Amazon that's lumped onto Red Hat [9,10] as part of a conference [11,12]. Avoid Amazon at all costs. It's a malicious trap for many reasons. Amazon also pays Microsoft for RHEL after a patent deal with Microsoft, as we pointed out years ago. Suffice to say, Microsoft's servers are as bad as Amazon's for privacy.

RHEL and its derivatives continue to be deployed in many large networks of systems [13], so it's clear why the NSA would drool over the possibility of back doors in RHEL. Watch out for that. Given the way NSA infiltrated standards bodies and other institutions, it's not impossible that there are even moles at Red Hat or Fedora. There used to be some at Microsoft (we know about those who got caught).

Red Hat's CEO is now telling his story in a Red Hat site [14] and one needs to remember who he used to work for (close to Boeing, which is primarily an army company), not just the country he is based on (hence the rules that apply to him, especially when he wishes to appeal to government contractors, DoD/Pentagon etc. which are the most lucrative contracts).

It should be noted that my Web sites are mostly running CentOS and the same goes for the host of Techrights, who focuses on security. With CentOS you can get the source code and redistribute; with Red Hat's RHEL you can't (it's sold as binary).

There is definitely a good reason to trust CentOS security more than RHEL security. As for Oracle ("Unbreakable"), well... just read Ellison's public statements in support of the NSA (never mind the company's roots and the CIA). That tells a lot.

The bottom line is, blind faith in binary distributions is a bad thing. Blind faith in NSA partners (Red Hat collaborates with the NSA not just in SELinux) is even worse.

Related/contextual items from the news:



  1. Taking the long view: Why I'm moving to CentOS Linux on the desktop


  2. Is CentOS ready for the Linux desktop?
    CentOS is a very interesting and different choice for a desktop distribution. I haven't heard of many people using it that way. Whenever somebody brings it up it's usually within the context of running a server.


  3. Fedora and CentOS Updates, Linux for Security, and Top Seven


  4. CentOS Project Leader Karanbir Singh Opens Up on Red Hat Deal
    In the 10 years since the CentOS project was launched there has been no board of directors, or legal team, or commercial backing. The developers who labored to build the community-led version of Red Hat Enterprise Linux (RHEL) worked largely unpaid (though some took a few consulting gigs on the side.) They had a few hundred dollars in their bank account to pay for event t-shirts and that was it. And the project's direction was decided based on the developers' immediate needs, not a grand vision of future technology.


  5. Red Hat: 2014:0015-01: openssl: Important Advisory
  6. Red Hat: 2014:0016-01: gnupg: Moderate Advisory


  7. Red Hat Invests in Open Source IaaS, Cloud Talent


  8. Red Hat Academy Expands Training, Includes OpenStack Coursework


  9. Red Hat Launches Test Drives on AWS
    At its annual Partner conference in Scottsdale, Arizona this week Red Hat (RHT) announced new Test Drives on Amazon Web Services (AWS) with three Red Hat partners – CITYTECH, Shadow-Soft, and Vizuri. Through the AWS Test Drive program, users can quickly and easily explore and deploy ready-made solutions built on Red Hat technologies.



  10. Why Red Hat Needs OpenStack ... And AWS
    OpenStack, the cloud's community darling, desperately needs leadership, and Red Hat seems the ideal leader. But OpenStack isn't the only needy party here. As good as Red Hat's growth has been over the last decade, it pales in comparison to that of VMware, a later entrant that has grown much faster than Red Hat. And the open source leader still trails well behind Microsoft.


  11. Google, Amazon Clouds Invade Red Hat Partner Conference
    Google Cloud Platform and Amazon Web Services executives are set to address Red Hat Partner Conference attendees on Jan. 13 in Arizona. No doubt, the keynotes will seek to ensure Linux resellers understand how to move customer workloads into the Google and AWS public clouds, respectively.


  12. 7 Surprises At Red Hat Partner Conference 2014


  13. How to deploy OSSEC across a large network of systems from RPMs


  14. Teens and their first job: How to get on the path to a happy career
    I grew up in the 1980s in Columbus, Georgia. You needed a car to get around, so I did not work until I could drive. Within months of getting my driver's license, I got my first job as a part-time computer programmer for a stockbroker.


Comments

Recent Techrights' Posts

"Open" "AI" is Going Bankrupt, Appealing for Government Bailout
The writings have been on the wall for years
"Secure Boot": Stop Trying to Boot Into GNU/Linux, Use Vista 11 Instead
It's all about reducing the user's cybersecurity under the false guise of improving it
LowEndBox Resorts to Ableism to Smear Software Freedom
Not some "low-level" pundit but an administrator
This Coming Thursday EPO Staff Meets Online to Discuss the Salaries Going Down While Stoned Managers Increase Their Own
compensation going down relative to inflation and other factors
Misinformation of IBM Spread via LLM Slop
Since a lot of sites now rely on LLMs we can expect the corporations' lies to be perpetuated by bots. That includes the myths of IBM Red Hat.
 
Governments That Financially Benefit (Profit) From the EPO Have a Long History of Covering Up Fraud and Corruption at the EPO
Many people are aware of it, even some of the biggest EPO stakeholders
Our Time in London
10 Days Ago We Were Down in London
Giving Red Hat a Second Life and Second Chance: Drop the LLM Slop, Stop Publishing Promotion of LLMs or Text Made by LLMs
For Red Hat to earn more trust it needs to quit participating in the biggest "pump and dump" pyramid scheme since the 1990s
Gemini Links 09/11/2025: Garden Room Complete, FreeBSD 15.0 on the ThinkPad T480, and Known Gemini Caspules Sorted by Number of URLs
Links for the day
Links 09/11/2025: Fung-wong Strikes Maharlika, "Open" "AI" Wants Taxpayers to Give It Bailout Money
Links for the day
Links 09/11/2025: "Avoid MSI Graphics Like the Plague", Harms of Social Control Media More Widely Recognised
Links for the day
Rocky Linux's Embrace of Mindless Cargo Cults Will Harm Rocky Linux in the Long Run
focus on technology, not marketing that defrauds many people and plagiarises many producers
Many of Red Hat's Official Blog Posts Seem to be Fake, Written at Least Partly by Bots (LLM Slop)
Can one trust Red Hat on technical things if it cannot even write words?
Suggestions Regarding Techrights Search
In some cases, Daily Links also serve to obscure our original articles
Reaffirming Rumours of More Microsoft Layoffs, Halo Impacted, XBox Business Winding Down
XBox has a huge target painted on its bum
This is What We Always Wanted to Spend Our Time on
2026 will probably be our most productive ever
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, November 08, 2025
IRC logs for Saturday, November 08, 2025
IBM is Destroying Red Hat (by Extension, It Also Harms GNU/Linux)
IBM is where things come to die, more so in the past decade or so
Austrian Media Coverage of Luis Berenguer's (Top EPO Official) Getting Busted for Cocaine
This wasn't some rich tourist caught by cops, it was a local official whom they busted
Gemini Links 09/11/2025: File Managers and DPC Commissioner
Links for the day
Links 08/11/2025: Climate Talk Unfruitful, OldVersion.com Archive Facing Shutdown
Links for the day
IBM is Eliminating Red Hat Like It Eliminated Tivoli and Eliminated Cognos
Be wary of IBM
Quitting One's Job Isn't Forbidden, Right?
it's important to remind people that leaving one's job is perfectly OK
Being Absent/Missing From Social Control Media is Not a Sign of Weakness
Broadly speaking, social control media is for losers
Empathy Online
I recently learned from someone that running his Web site might hurt some feelings, even if the writings are truthful
Our Site Search Increases Our Editorial and Informational Independence
Implementing our search facility is a long-term investment
Advocates of GNU/Linux and the Uphill Battles Behind Us
GNU/Linux felt like "activism" 20 years ago. Now it's mainstream.
Cybersecurity Means Real Security, Not Back Doors
Standing our ground on technology and cybersecurity is an uncompromisable stance
Links 08/11/2025: Disinformation Crisis, Denmark Recognises Threats Associated With Social Control Media
Links for the day
The Free Software Foundation (FSF) is Besieged for the Times It Does the Right Things
As that upsets rich people's interests (and they were, at times, sponsors)
Links 08/11/2025: Technical and Financial GAFAM Woes and Arrests of Journalists by Despots
Links for the day
Like SUSE, IBM Red Hat Seems to be Using LLM Slop to Write Fake (Bot-Generated) Blog Posts
IBM Red Hat keeps promoting slop
Corruption is a Reality, It's Not a Dirty or a Strong Word
Corruption is a topic some newspapers shy away from
How German Media Covered Cocainegate at The European Patent Office (EPO)
At some point we'll ask that same press to revisit the issue and this time comment on the EPO connection
Our Launch of Techrights Search Has Been Successful (So Far)
There are about 50,000 articles indexed there, going 19+ years back
Daniel Pocock Explains Social Engineering in Debian and Other Communities Increasingly Controlled by "Barons"
Communities are not corporations
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, November 07, 2025
IRC logs for Friday, November 07, 2025
Rosanna Yuen & GNOME community triple tricked
Reprinted with permission from Daniel Pocock
Adrian & Diana von Bidder-Senn, Debian: detailed history of a death
Reprinted with permission from Daniel Pocock
Crypto AG tricked ETH Zurich student internship
Reprinted with permission from Daniel Pocock
An Old Story of Fraud at the EPO in the Netherlands (and How the Dutch Government Facilitated It)
We've already mentioned several other scandals where the the Dutch government engaged in fraud and passive corruption
Voicing Concerns About European Patent Office (EPO) in Rijswijk
The report is dated yesterday
Gemini Links 08/11/2025: KeePassRX and Pluribus
Links for the day
IBM Layoffs Not Done, Terminations of Staff in India, Brazil, and Mexico Reported
This hopefully answers questions such as, "do the layoffs only impact US and Canada?"
Slopwatch: Brian Fagioli Targets "Linux" With LLMs, Google News Helps Blame "Linux" for Amazon WorkSpaces Flaws
Tonight's slopfest
Gemini Links 07/11/2025: Switzerland, k3s, and Privacy
Links for the day
Links 07/11/2025: Software Patents Squashed, Stock Markets Wobble Over Slop Uncertainties
Links for the day
A 19th Anniversary and High-Impact Exclusives
The end of 2025 will be very difficult for EPO management
The Register MS, Payroll First
GNU/Linux is a growing platform
Links 07/11/2025: US Government Shutdown Imperils Critical Functions, Slop in "AI" Clothing Debunked Some More, Bubble's Implosion Ongoing/Imminent According to Experts
Links for the day
Gemini Links 07/11/2025: No Goodbyes, Homelab, Mouse Keys / Pointer Keys
Links for the day
12 Years for Justice is Far Too Slow (and More People, Especially Women, Are Hurt)
Why do police departments and legal systems fail to protect women?
Before Freenode Collapsed Its Staff (the People Who Now Run Libera.Chat) Were Censoring/Silencing Some Free Software Supporters
We still have this issue in the Free software community
Freenode and irc.com Are Still Around
It emulates retro terminals
We Don't Compete, We Analyse and Report
Principles are so much better than money and they're something money can never acquire
Red Hat is Also Laying Off Staff in India
Red Hat is a dishonest company
All We Want to See is Any Form of Accountability in Europe's Largest Institutions
Because people at the top of institutions should never be above the law!
Finding Recent Talks of Richard Stallman
We already have many pages, documents, and media files. Organising them and helping people find them is the next Big Task.
Richard Stallman First Speaker at Ethereum Cypherpunk Congress the Weekend After This Coming Weekend
He'll be speaking over the Net
Diversity at Red Hat
Remember to judge corporations by their actions, not some Web pages with words in them
First the Python Software Foundation (PSF) Attacked Its Most Productive Volunteers. Now It Attacks Its Funding Sources.
The U.S. National Science Foundation (NSF) rejected by PSF
News of Substance About the EPO's Substance Abuse (Cocaine)
EPO Cocaine Chronicles - link to archived BILD article and photos
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, November 06, 2025
IRC logs for Thursday, November 06, 2025
On Midlife Crises
Focus on the sabotage, not politics
Hallmark of Fake News: "Single-digit" (Percentage) and 1% Isn't the Same Thing
apparently "rebalancing" is the new layoffs euphemism
Links 07/11/2025: Patent Trolls Target Germany, Celebrities Visit Ukraine
Links for the day
Misinformation/Disinformation Disguised as Information About GNU General Public Licenses (GNU GPL) Usage
GPL-type licences (reciprocal obligations) remain dominant
Slopwatch: LinuxSecurity, Brian Fagioli, and Google News Boosting WebProNews (All Slopfarms)
Those slopfarms just saturate the Web with misinformation and mindless chaff
Techrights and Tux Machines at Over 40
19 years of Techrights and 21+ years of Tux Machines
IBM Mass Layoffs This Week Not Limited to North America, Red Hat Staff Terminated
Do not relocate for a company that sees you as nothing but a number or a "human resource"
Coming Soon: More Proof of Cocaine Use at Europe's Second-Largest Institution
Stay tuned
Entering Our 20th Year
...and still looking for answers