Bonum Certa Men Certa

Firefox 93 Disables Triple DES and Doesn’t Mention NSA Backdoors. Windows 11 Continues Degrading VPNs With It If They Use the Native APIs.

Guest post by Ryan, reprinted with permission from the original

Summary: Firefox 93 has finally disabled the NSA-backdoored and weak Triple DES encryption when you connect to “secure” websites.

In their blog post, Mozilla imply that all that’s wrong with it is that it’s obsolete and seen better days, however, the US National Security Agency was involved and weakened the entire scheme to the point where they could easily break it, but thought that nobody else could for a while.



Flash forward to today, and Triple DES can be easily attacked using many known weaknesses and, if you know the terrible security track record of the OpenSSL project, they dropped it by default (and you’d have to turn it back on) in 2016.



What’s amusing, is that Microsoft and their pet lap dogs over at the Linux (Destroying) Foundation, which has little to do with Linux anymore and more to do with producing mountains of whitepapers using indecipherable buzzwords, technobabble, and treknobabble that would probably make Laura Callahan blush, got together with other companies and poured money into OpenSSL. Lots of money.



And the result of this money is…….. that we’re still stuck with a bloated train wreck that has a lot of obsolete code and security issues.



Some GNU/Linux distros tried switching to LibreSSL, but that turned out to be an even bigger disaster in some ways because the OpenBSD people consider the Apache 2 license to be “non-Free” because it doesn’t allow patent trolls to give you a program and then sue you for using it, and since OpenSSL is now under that license, it means they can’t just pull code from it, and pretty much all hope of remaining API/ABI compatible or something close to it went out the window.



"Still, just one of the many lingering security problems regarding Triple DES is that the Windows 10 and now, “11” operating systems continue to use it despite it being known for years to be bugdoored by NSA and vulnerable to known attacks and providing weak security, if you use the built-in implementation of IKEv2 to connect to a virtual private network."And although OpenSSL is a crucial component of every Windows OS out there, anything that goes wrong with it is a “Linux bug” in the media. That’s not an accident. It’s a deliberate red herring.



Still, just one of the many lingering security problems regarding Triple DES is that the Windows 10 and now, “11” operating systems continue to use it despite it being known for years to be bugdoored by NSA and vulnerable to known attacks and providing weak security, if you use the built-in implementation of IKEv2 to connect to a virtual private network. This is one reason why no decent VPN company will touch Windows’ included VPN services and usually bundle OpenVPN or, now, Wireguard.



Microsoft is still out there pretending to give a shit about security, when this is happening. Windows “11” has been a complete disaster of performance-killing bugs, especially for gamers and people who use the AMD Ryzen CPU platform, and that’s assuming folks can even get it to install in the first place.



Internally, Windows rots away and continues its ride into the sunset as a legacy platform, which oddly can now be used by only 15-20% of all PCs out there. Meaning, there’s never been a better time to get away from it.



Yes, that’s right, while the overwhelming majority of PCs out there can install GNU/Linux distributions, Microsoft has deliberately made most of them “incompatible” with a blacklist, or slowed them down with “bugs” so that users go “Welp, time to buy new stuff again!”.



"Microsoft usually sabotages their older products so that people holding out on them or trying to use them on newer computers to forestall having to deal with the latest bloat, bugs, backdoors, and other bullshit give up and throw in the towel."There’s about to be a fire sale of cheap used computers that will run GNU/Linux fine. Many people fall for this old chestnut every few years and never learn.



Microsoft usually sabotages their older products so that people holding out on them or trying to use them on newer computers to forestall having to deal with the latest bloat, bugs, backdoors, and other bullshit give up and throw in the towel.



They talk about “new silicon” (CPUs) “being designed” for their latest OS, but people were installing Windows 7 on Skylake stuff that came with Windows 10, and the only thing that got in the way was Microsoft disabling Windows Update at a certain point if you did.



This goes way back, I’m told, to at least Windows 95.



Hey, Nathan Lineback would probably know. He was doing just about anything to keep Windows 95 trucking along, including figuring out how to use USB thumb drives on it and getting Seamonkey 2.0 to work. Which is oddly dedicated to a Microsoft OS from decades past (for a guy who otherwise seems to hate everything they’ve done), but oh well.



They are easily one of the most dishonest and disreputable companies on the planet. Why, oh why, do people insist on using this?

Recent Techrights' Posts

World Press Freedom Day: WIPO censors Debian suicide cluster
Reprinted with permission from Daniel Pocock
Links 07/05/2024: Pulitzer for Supreme Court Expose, New Threats to Media Reported
Links for the day
Berlin police declined to investigate FSFE Nazi comparisons
Reprinted with permission from Daniel Pocock
 
Only Weeks After Microsoft Closed Offices and Studios It is Closing Several More (Many Layoffs, Still Deeply Debt-Saddled)
When the sad news writes itself
Bolivarian Republic Of Venezuela: GNU/Linux Reaches 9% (ChromeOS Included)
Venezuela must have lost interest in some American proprietary software when users were locked out of their own data (Adobe) and the costs could no longer be justified
[Video] Microsoft is Like Big Oil, Big Tobacco, and Other Perpetrators of Fear, Uncertainty, Doubt/Fear-mongering
openwashing, Microsoft lobbying, and Microsoft subsidies (e.g. bailouts in the form of 'defence' contracts)
Security & Debian: Urgent: New Feed URLs after another WIPO censorship
Reprinted with permission from Daniel Pocock
Gemini Links 07/05/2024: Smashing Windows (Moving to GNU/Linux) and Mastodon Time-wasting
Links for the day
Links 07/05/2024: Cheap EVs and Cloudflare Layoffs
Links for the day
[Meme] Communities Governed by Parasitic Elements and Girlfriends (Who Can't Understand Those Communities)
Karen Sandler and Molly de Blanc present at DebConf18
[Meme] You Can't Kill an Idea (or Facts)
Thankfully, in Western societies, there's still due process, rule of law etc. You don't just hire assassins or imprison critics
[Meme] Software in the Public Interest (SPI), Inc, Values Articles of Daniel Pocock at ~$5,000 Each (and Fails to Hide the Facts)
we are laughing, not grieving
IRC Proceedings: Monday, May 06, 2024
IRC logs for Monday, May 06, 2024
Over at Tux Machines...
GNU/Linux news for the past day
[Meme] About 2,564 Internet Sites Now at Risk of Hostile Takeover by Microsoft-Sponsored Software in the Public Interest (SPI)
WIPO censors Debian suicide cluster
Links 07/05/2024: Burning Plastic Waste, Facebook Censoring Politicians
Links for the day
Gemini Links 07/05/2024: Smashing Windows (Microsoft Losing Users to GNU/Linux), Sixty Years of BASIC
Links for the day
Southern Asia is All Android (Majority) Now
It's looking better (almost) every month
Windows Already Down to 1% "Market Share" in Some Countries
it is a dying breed
Tesla Has Become a Ponzi Scheme or a 'Meme Stock'
They tell us Tesla is "worth" almost twice as much as a company that sold about 30 times more cars
For People at Red Hat "Job is at Risk"
Red Hat is consulting some notorious firms to implement cuts
Linux.com Became Mostly Dead, de Facto Marketing Site of "Linux" Foundation Products (Unrelated to Linux)
what has happened to the authoritative domain Linux.com
Microsoft GitHub: A Hair Salon Where You Get Awards for Nothing (NFT Vanity)
People aren't defined by some private (proprietary) database and Microsoft does not universally "score" developers
In Europe, Android is Bigger Than Windows (Android Now Measured at 45.1% Worldwide)
Right now in statCounter...
Links 06/05/2024: Al Jazeera Raided, Wildfire Season Coming
Links for the day
On Character Assassination Tactics
The people who leverage these dirty politics typically champion projection tactics
Links 06/05/2024: Scams and Politics
Links for the day
Gemini Links 06/05/2024: Reading and Computers
Links for the day
United States Entering the $100 Trillion Debt Trap, We Compare GAFAM Debt
Google's debt is about 6 times less than Amazon's
GitLab's Losses Grew From $172,311,000 to $424,174,000 Per Annum
Letting this company have control over your (or your company's) development/code forge may cost you a lot in the future
statCounter's Latest: Android Bouncing to New All-Time Highs, Windows Down to Unprecedented Lows
Android rising
Can't Bear the Thought We're Happy and Productive
If someone is now harassing online friends, attacking the wife, attacking my family (not just attacking and defaming people I know online) there are legal ramifications
IRC Proceedings: Sunday, May 05, 2024
IRC logs for Sunday, May 05, 2024
Over at Tux Machines...
GNU/Linux news for the past day
Erinn Clark & Debian: Justice or another Open Source vendetta?
Reprinted with permission from disguised.work
Death of Michael Anthony Bordlee, New Orleans, Louisiana
Reprinted with permission from disguised.work
The Revolution Continues
Today we've published over 20 pages and tomorrow we expect more or less the same
Death of Dr Alex Blewitt, UK
Reprinted with permission from disguised.work
Software Freedom Conservancy (SFC), Inc. vs. Vizio, Inc. Is Costing the Free Software Foundation Money
FSF subpoena and deposition
Following the Herd (or HURD)
Society advances owing to people who think differently and promote positive change, not corporate shills
They Try to Replace the Creators of GNU/Linux and Hijack Their Word, Work, and Reputation
gnu.org is down at the moment; now I'm told it's back but very slow. DDoS?
Thiemo Seufer & Debian deaths: examining accidents and suicides
Reprinted with permission from disguised.work
Links 05/05/2024: Political Cyberattacks From Russia and Google Getting a Lot Worse
Links for the day
Gemini Links 05/05/2024: Infobesity and Profectus Beta 1.0
Links for the day
Running This Site Mostly a Joyful Activity
The real problem or the thing that we need to cancel is this "Cancel Culture"
Australia Has Finally Joined the "4% Club" (ChromeOS+GNU/Linux)
statCounter stats
Debian as a Hazardous Workplace Where No Accountability Exists (Nor Salaries)
systematic exploitation of skilled developers by free 'riders' (or freeloaders) like Google, IBM, and Microsoft
Clownflare Isn't Free and Its CEO Openly Boasted They'd Start Charging Everyone to Offset the Considerable Losses (It's a Trap, It's Just Bait)
Clownflare has collapsed
Apple Delivered Very Disappointing Results, Said It Would Buy Its Own Shares (Nobody Will Check This), Company's Debt Now Exceeds Its Monetary Assets
US debt is now 99.98 trillion dollars
FSFE Still Boasts About Working Underage People for No Pay
without even paying them
IRC Proceedings: Saturday, May 04, 2024
IRC logs for Saturday, May 04, 2024
Over at Tux Machines...
GNU/Linux news for the past day
The Persecution of Richard Stallman
WebM version of a new video
Molly de Blanc has been terminated, Magdalen Berns' knockout punch and the Wizard of Oz
Reprinted with permission from disguised.work
[Meme] IBM's Idea of Sharing (to IBM)
the so-called founder of IBM worshiped and saluted Adolf Hitler himself
Neil McGovern & Debian: GNOME and Mollygate
Reprinted with permission from disguised.work