Bonum Certa Men Certa

Sometimes Proprietary Software is Proprietary (Secret) Simply Because It is Not Good and Obfuscation Helps Hide Just How Ugly It Is

The story of FortiClient resembles what I've often encountered over the years with other proprietary VPNs (not of my choice)

Proprietary Software. You pay to be abused.



Summary: Why nonfree (or proprietary) software generally fails to catch up with Free/libre software -- at least on technical grounds -- and then makes up for it with marketing and FUD offensives (discrediting perfectly-functioning things, based on their perceived cost)

OVER the years I've encountered and used a lot of VPNs. It's one thing I'm quite familiar with, having configured and debugged VPNs quite a lot. At work, we use Free/libre VPNs that we host and manage ourselves (typically OpenVPN and IPSec/StrongSwan). But clients' choices of VPN are another matter. Occasionally I must access a client's GNU/Linux server to carry out maintenance, patching and software upgrades. It's quite a routine thing.



"Why is it that Free software generally works a lot more consistently than proprietary counterparts and why do some people pay a lot of money for VPN tools that not only cost a lot of money but need to be 'repurchased' (re-licensed) annually or any time one 'upgrades'?"VPN software varies from client to client and some VPN tools are so awful that it's not even funny. It can be painful. At times impossible!

Why is it that Free software generally works a lot more consistently than proprietary counterparts and why do some people pay a lot of money for VPN tools that not only cost a lot of money but need to be 'repurchased' (re-licensed) annually or any time one 'upgrades'? Suffice to say, many of these proprietary things have holes in them (kept under the rug), so one might actually be paying for additional security holes rather than security. Snowden's stash of leaks revealed some evidence to that effect.

"Much time down the drain."One might say I'm opinionated, but I'm not alone. It's not only me who complains by the way; a colleague explained that "[a]t the moment the only access we have for [client] is via a horrible proprietary VPN. You are only able to get clients for Windows and Mac officially, however an Ubuntu client has been found that works too. To make things more complicated it does not appear to work at all in Windows Server, meaning we can't provide access though the Windows [shared/remote virtual] box. If you have a Windows or Mac box, you can download the client from http://forticlient.com/ and the Ubuntu one can be found here https://forticlient.com/repoinfo..."

Well, nothing that I've tried allows me to access the client's network. Much time down the drain. You can try again and again (dealing with binary blobs). The FortiClient software is defective, however, as it shows an unimpressive blank window each time it starts (I tried other, more complicated things) and there's no way to debug this.

FortiClient
So-called 'Client'; Whose exactly? Spy agencies?



If I run this from the command line it says:

"Platform detected: fedora" (which is false by the way, it's not even an RPM-based distro, so I think they need to do more work on their client-side tools if it's advertised as cross-platform)

"The bottom line is, proprietary VPN software is utterly bad, it rarely prevents security incidents, and it is more like duct tape on top of something inherently broken."Our internal wiki indicates that we cannot access this over a virtual Windows Server, either. Because that too is not supported. What other access options may there be? And why need they complicate access to the point where they shut out people who merely try to keep their machines secure and up to date? As a Techrights associate recently noted, the whole concept behind VPN is flawed. It seems to assume that operating systems in use aren't safe if connected to the Web (there are NSA back doors, for starters), so complete separation and insulation from the network is seen as desirable. Later this year our combined lifetime for Tux Machines and Techrights will be 30 years. We're a high-profile target for attacks, Techrights in particular (many DDOS attacks over the years), but we never had any security incidents and we never used VPNs. We even gave up on so-called 2FA, knowing that it sounds better in theory than (how it works) in practice.

The bottom line is, proprietary VPN software is utterly bad, it rarely prevents security incidents, and it is more like duct tape on top of something inherently broken. Moreover, the quality of proprietary VPN software is utterly appalling. The same can be said about proprietary software other than VPNs, but these companies compensate for that with heavy marketing campaigns and waves of FUD directed at Free software counterparts.

Recent Techrights' Posts

Nat Friedman Had Left Microsoft GitHub Exactly One Week Before Matthew Garrett Sent His First SLAPP (Which Was an Empty Threat, He Was Abusing the Legal System of Another Continent to Terrorise Critics Who Had Just Unearthed Major Microsoft Scandals)
And it was likely talked about by his lawyers around the exact same time Nat Friedman was packing up
 
South Americans Are Saying Goodbye to Microsoft
We're hardly even "Cherry-Picking" or conveniently singling out one South American nation
Abuse Inside the Polish Patent Office (UPRP) - Part III: Data Protection Failures, Just Like at the European Patent Office (EPO)
Just less than a decade ago we showed that the EPO had illegally shared staff data with third parties
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, June 05, 2025
IRC logs for Thursday, June 05, 2025
Pushing Microsoft's Proprietary Trash/Trap as "Open" and "Linux" (Windows is 'Linux' Now?)
Maybe it's time to just stop saying "FOSS". The people who use that term are promoting Microsoft.
Slopwatch: Comparing Linux to Vermin, Attacking BSD With LLM Slop, and Helping Microsoft Demonise Linux/OpenBSD/SSH Over Weak User Passwords
Microsoft must be laughing its arse off, seeing how a bunch of Serial Sloppers (no skills, no comprehension, no integrity, no creativity) and slopfarms use Microsoft LLM to flood the Web with anti-Linux FUD
Links 05/06/2025: US Poised for Another $2.4 Trillion to Debt, Cops Want GAFAM Kill Switches
Links for the day
Links 05/06/2025: First US Spacewalk 60 Years Ago, GNU Octave 10.2.0 is Out
Links for the day
Scandinavia Saying Goodbye to Microsoft
The Danes have had enough of Microsoft
GNU/Linux Measured at 6% in Bangladesh, According to statCounter
Windows isn't growing, it's going away
Gemini Links 05/06/2025: Loop Earplugs Review and ANS Forth
Links for the day
Armenian Adoption of GNU/Linux
Russian influence in Armenian must be worrying to Microsoft
Abuse Inside the Polish Patent Office (UPRP) - Part II: Turning a Once-Respected Patent Office Into a Circus and Laughing Stock
It's not legal, but administrators who don't care about the law and don't fear the law would just go ahead and turn things to junk
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, June 04, 2025
IRC logs for Wednesday, June 04, 2025
Slopwatch: Mindless Slop Pieces, Fake Images and Text, Linux FUD on the Cheap
spewed out by Microsoft-controlled LLMs
Links 04/06/2025: Workers' Strikes, Sudan Exodus
Links for the day
Links 04/06/2025: Linux Foundation PR Spam and Lee Jae-myung Wins Election
Links for the day
Gemini Links 04/06/2025: Future Leaders of the World and Platforming Jordan Peterson
Links for the day
Links 04/06/2025: WSL Backfiring on Microsoft and "Disney, Microsoft Announce Massive Layoffs"
Links for the day
Our Case is a Very Easy Win, the SLAPPs From Microsofters Were a Grave Error, and Censoring Information Won't Work (It'll Only Ever Backfire)
Censoring is what people do when they lose the argument
Say the Truth, the Rest Will Follow
There's no guarantee that writing the truth will result in an audience (or readership), but over time - in the long run - people generally gravitate towards what they know or feel to be crude truth, not just what's comforting (albeit false or self-deluding, usually groupthink dictated from above)
How to Expose High-Level Corruption Without Getting in (Too Much) Trouble
Democracy depends on free press and freedom of the press depends on being able to safely publish (and keep available) material that bad people don't want to be known to anybody
In-Depth EPO Coverage at Techrights Turns Eleven
11 years is a very long time
Windows Measured Below 10% in Afghanistan, GNU/Linux Gaining a Lot
about 80% are Android (Linux) users, compared to only about 10% for Windows
Poland's Political Predicament and Social Control Media
Democracy and fake "tech" don't mix well; the latter tends to interfere with the former and that's why we get more "Putins" out there
EPO: Taking Away From the Staff to Give More to the Rich
The Central Staff Committee (CSC) wrote to EPO staff earlier this week
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, June 03, 2025
IRC logs for Tuesday, June 03, 2025
Abuse Inside the Polish Patent Office (UPRP) - Part I: It's a Lot Like the EPO
we can commence a series soon
Gemini Links 04/06/2025: Inescapable Questions and Quitting All "Oligarch Tech"
Links for the day