Bonum Certa Men Certa

Firefox 93 Disables Triple DES and Doesn’t Mention NSA Backdoors. Windows 11 Continues Degrading VPNs With It If They Use the Native APIs.

Guest post by Ryan, reprinted with permission from the original

Summary: Firefox 93 has finally disabled the NSA-backdoored and weak Triple DES encryption when you connect to “secure” websites.

In their blog post, Mozilla imply that all that’s wrong with it is that it’s obsolete and seen better days, however, the US National Security Agency was involved and weakened the entire scheme to the point where they could easily break it, but thought that nobody else could for a while.



Flash forward to today, and Triple DES can be easily attacked using many known weaknesses and, if you know the terrible security track record of the OpenSSL project, they dropped it by default (and you’d have to turn it back on) in 2016.



What’s amusing, is that Microsoft and their pet lap dogs over at the Linux (Destroying) Foundation, which has little to do with Linux anymore and more to do with producing mountains of whitepapers using indecipherable buzzwords, technobabble, and treknobabble that would probably make Laura Callahan blush, got together with other companies and poured money into OpenSSL. Lots of money.



And the result of this money is…….. that we’re still stuck with a bloated train wreck that has a lot of obsolete code and security issues.



Some GNU/Linux distros tried switching to LibreSSL, but that turned out to be an even bigger disaster in some ways because the OpenBSD people consider the Apache 2 license to be “non-Free” because it doesn’t allow patent trolls to give you a program and then sue you for using it, and since OpenSSL is now under that license, it means they can’t just pull code from it, and pretty much all hope of remaining API/ABI compatible or something close to it went out the window.



"Still, just one of the many lingering security problems regarding Triple DES is that the Windows 10 and now, “11” operating systems continue to use it despite it being known for years to be bugdoored by NSA and vulnerable to known attacks and providing weak security, if you use the built-in implementation of IKEv2 to connect to a virtual private network."And although OpenSSL is a crucial component of every Windows OS out there, anything that goes wrong with it is a “Linux bug” in the media. That’s not an accident. It’s a deliberate red herring.



Still, just one of the many lingering security problems regarding Triple DES is that the Windows 10 and now, “11” operating systems continue to use it despite it being known for years to be bugdoored by NSA and vulnerable to known attacks and providing weak security, if you use the built-in implementation of IKEv2 to connect to a virtual private network. This is one reason why no decent VPN company will touch Windows’ included VPN services and usually bundle OpenVPN or, now, Wireguard.



Microsoft is still out there pretending to give a shit about security, when this is happening. Windows “11” has been a complete disaster of performance-killing bugs, especially for gamers and people who use the AMD Ryzen CPU platform, and that’s assuming folks can even get it to install in the first place.



Internally, Windows rots away and continues its ride into the sunset as a legacy platform, which oddly can now be used by only 15-20% of all PCs out there. Meaning, there’s never been a better time to get away from it.



Yes, that’s right, while the overwhelming majority of PCs out there can install GNU/Linux distributions, Microsoft has deliberately made most of them “incompatible” with a blacklist, or slowed them down with “bugs” so that users go “Welp, time to buy new stuff again!”.



"Microsoft usually sabotages their older products so that people holding out on them or trying to use them on newer computers to forestall having to deal with the latest bloat, bugs, backdoors, and other bullshit give up and throw in the towel."There’s about to be a fire sale of cheap used computers that will run GNU/Linux fine. Many people fall for this old chestnut every few years and never learn.



Microsoft usually sabotages their older products so that people holding out on them or trying to use them on newer computers to forestall having to deal with the latest bloat, bugs, backdoors, and other bullshit give up and throw in the towel.



They talk about “new silicon” (CPUs) “being designed” for their latest OS, but people were installing Windows 7 on Skylake stuff that came with Windows 10, and the only thing that got in the way was Microsoft disabling Windows Update at a certain point if you did.



This goes way back, I’m told, to at least Windows 95.



Hey, Nathan Lineback would probably know. He was doing just about anything to keep Windows 95 trucking along, including figuring out how to use USB thumb drives on it and getting Seamonkey 2.0 to work. Which is oddly dedicated to a Microsoft OS from decades past (for a guy who otherwise seems to hate everything they’ve done), but oh well.



They are easily one of the most dishonest and disreputable companies on the planet. Why, oh why, do people insist on using this?

Recent Techrights' Posts

Microsoft-Sponsored Xenophobia and Nationalism
IBM is very similar in this regard
Tentative Summary of Things to Publish in Project 2030
I'll still be in my forties by then
 
Links 21/09/2025: "Hey Hi" (Hype) Under Fire, Fakes Identified; Tesla Burns Family
Links for the day
Google's Software is Malware and Malware in Mobile Devices
Originally posted by Rob Musial
Links 20/09/2025: Hegemony Coming to a Close, Luigi Mangione Ruled Not Terrorist
Links for the day
Gemini Links 21/09/2025: "Charlie Kirk Was a Hateful Piece of Shit" and Slop Code Attempted by Microsofter
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 20, 2025
IRC logs for Saturday, September 20, 2025
Gemini Links 20/09/2025: Snowy Photos and utism is a Spectrum
Links for the day
Vintage is Sometimes Better
Why can't we get back to "simple" if (or where) "simple" means better?
Climate Breakdown Means We'll be Publishing More, Not Less
Press freedom will be a common, recurring theme
Our 5-Year Geminispace Anniversary is Coming Up
I still remember when Gemini Protocol was quite new
It's Right to Point Out Violence From the Right
Violence is a recurring theme
Web Browsers That "Do Hey Hi" (AI)
State-of-the-art plagiarism or "autocomplete on steroids" (not coined by us, nevertheless a nice description) don't have much/any prospect
Links 20/09/2025: Hardware Projects in View, Some Independent Publishers About Russia Prosper After Cheeto Cuts Funding
Links for the day
Gemini Links 20/09/2025: Options and TV Time Machine
Links for the day
Links 20/09/2025: Retrocomputer, Antique Phone Experience, and More
Links for the day
Links 20/09/2025: Internet Shutdowns, Media Censorship, and Climate Worries
Links for the day
About 700 New Gemini Capsules in 13 Months (or 54 Per Month)
4.8K would represent a 20% increase
Rust People: Drain the Swap, You're Holding It Wrong
Does Rust make sense?
Techrights the Name Turns 15
About 6 weeks from now we turn 19
Microsoft is Running Out of Time and Floating Fake Figures, Fake Projects, Fake Narratives, Fake Excuses
Also, a lot of Microsoft's "revenue" claims are circular financing (i.e. Microsoft buying from itself, which means Ponzi-like fraud)
Slopwatch: LinuxSecurity, linuxconfig.org, and Plagiarised Phoronix
Many articles out there are nowadays fake
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, September 19, 2025
IRC logs for Friday, September 19, 2025
Gemini Links 20/09/2025: Navigating the Pressures of Modern Life and SpellBinding Accidentally Wrote Another Gemini Server
Links for the day
Links 19/09/2025: Press Freedom Dying in US, Anti-Austerity Strikes in France, and Alan Rusbridger to Leave 'Prospect'
Links for the day
European Patent Office Illegally Gutting and Outsourcing Its Functions, Acting Like an Above-the-Law Commercial Business (It Won't Stop at Formalities Officers (FOs) and Classification Slop at the EPO)
breaking/violating laws and conventions
Offloading to the Sister Site
In the interest of not overwhelming readers
Links 19/09/2025: Coffee Club and "SpellBinding is Now Absurdly Fast"
Links for the day
Links 19/09/2025: Lobbyist of American GAFAM Becomes Data Protection Commissioner in Europe
Links for the day
Links 19/09/2025: Media Freedom Ceases to Exist in US, "Consider Dropping Twitter/X"
Links for the day
Gemini Links 19/09/2025: Thinking and Insect Bites
Links for the day
Microsoft E.E.E.: Git Will Now (or Very Soon) Fully Depend on Rust, Which is Controlled by Microsoft
Microsoft now makes Git dependent on Rust, or making Git dependent on GitHub, which is proprietary
The Right to Punch People (Apparently)
At Brett Wilson, Brett's job title is "Head of Crime" and Wilson normalises calls for violence
Slop or Fake Articles Have Turned Linux Journal From a Pioneering/Trailblazing "Linux" Magazine Into a Nuisance
some sites with former reputation - good reputation - turn into cesspools
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 18, 2025
IRC logs for Thursday, September 18, 2025