Bonum Certa Men Certa

Beware the Distortion of Terms Like 'Supply Chain', 'Zero Day', and 'Back Door' (New FUD Patterns Against Free Software, a Distraction From the Real Culprits)

Proprietary software is being protected by 'googlebombing' tactics; the biggest weaknesses of proprietary software are being spun as a key problem with "Open Source" and proprietary software's shortcomings are being blamed on the alternative to it

Linux Foundation: repeat what Microsoft says

Summary: Microsofters spread misinformation/disinformation about Free software and security thereof; the corruption (bribery) of organisations such as the so-called 'Linux' Foundation means that Microsoft's misinformation/disinformation now comes out of the mouths of the supposed opposition, too

THE Daily Links in this site habitually add some "Ed"(itorial) comments to highlight FUD (Fear, Uncertainty, Doubt/fear-mongering) and offer some quick response to it. How much can publishers lie for the likes of Microsoft or VMware before those publishers perish due to a lack of credibility and, in turn, a lack of audience?

Earlier today we posted some more examples of this kind in Daily Links. Not a day goes by without several such 'incidents' (misinformation/disinformation).

"The real "supply chain" trouble is Microsoft and proprietary software..."In this post we highlight 3 recent patterns we've noticed. They are semantic lies.

Recently, a Microsoft front group called "Linux Foundation" kept using terms like "supply chain". Years ago nobody used this term in relation to Free software and then Microsoft bought a lot of the so-called 'supply chain', in the form of GitHub and then NPM. Would anyone trust the integrity of code and binaries from a platform controlled by Microsoft and the NSA, whose CSO is a decades-long NSA veteran?

The real "supply chain" trouble is Microsoft and proprietary software; you can't audit what you're getting and it might be intentionally back-doored, taking advantage of this opacity. So why pretend this is a "FOSS" issue?

"If something was fixed or was already patched upstream before disclosure, then it is not a 0-day."Speaking of back-doored code or executables, "backdoor" means not a backdoor anymore. Microsoft-controlled media distorted the term and kept mentioning it in false contexts. Nowadays it just means a server got compromised and then the person who took control of it installed some more stuff. But that's malware and it says nothing about how the malware got on the system in the first place (unless there was an actual back door).

Many would say that servers can be hijacked using critical and remotely-exploitable flaws, set aside bad passwords (those are typically a human failure). But that leads us to the distortion of the definition of "zero day" (or 0-day). If something was fixed or was already patched upstream before disclosure, then it is not a 0-day. If it starts getting exploited the moment it is disclosed, then it's a "1-day". But looking around the Web today, we found several examples of lies to that effect. The media keeps badmouthing Zimbra, but this seems to be a way to distract from several critical Microsoft flaws, including those affecting Exchange. Those are actively being exploited, according to a very recent report. the Zimbra issue is old news (about a month old) and servers have already been patched by responsible administrators, such as my colleagues. Although it seems like the Zimbra hole might be a new one, the last patch partly addresses it. Do not forget that CISA released a list with three Microsoft holes that are actively exploited, including in Exchange, so why shift/divert to talking about Zimbra rather than Exchange? Are they trying to reinforce some false perception that moving away from Exchange would mean equally bad or even worse security?

"The scenario, as per Dan Goodin et al (even sued for defamation already, for utterly poor reporting on security), is nowhere as grim as the Microsoft Exchange situation."What's bothersome here is the repeated distortion of the term "zero day". An associate told us that "'they' must be really worried about the advance of FOSS to spread so much dated FUD about Zimbra and other projects. One giveaway is the use of the marketing phrase "zero-day". That used to mean an exploit that was in active use before the vendor admitted to it existing. Now it just means bug with an exploit."

The scenario, as per Dan Goodin et al (even sued for defamation already, for utterly poor reporting on security), is nowhere as grim as the Microsoft Exchange situation. We already saw that Microsoft goes on for months and months without patching known Exchange flaws, even when it is fully informed that such flaws are actively being exploited already.

Zimbra does E-mail, so that helps distract from what Microsoft is doing, with the real zero days, the real back doors, and the real supply chain crisis. Microsoft monopolises this chain (it's proprietary) and refuses to fix it, leaving the victims helpless. This must be intentional. Or as out associate put it, "paid-for back doors on behalf of those that pay enough, or more specifically bug doors. Those are exploitable bugs about which the payers are informed long in advance of Microsoft getting around to patching them."

"Zimbra does E-mail, so that helps distract from what Microsoft is doing, with the real zero days, the real back doors, and the real supply chain crisis."It's the Windows [sic] of opportunity... Edward Snowden has already provided ample evidence of this. Microsoft keeps giving the NSA and FBI enough time to install a RAT or bootkit before the patches get deployed (too late). "And the FSB and just about any similar agency in all the other Internet-connected countries in the world," our associate noted.

So we're meant to think that the real crisis is Free software and Microsoft lobbyists then push for new, discriminatory laws that stigmatise "Open Source". New zero-day in Microsoft products? Unpatched for months while exploits circulate for months? So the Microsoft shills focus on the something that is "open source"... and repeat endlessly the terms which aren't even applicable to it.

"CISA is a Microsoft reseller working out of the DHS offices," our associated concluded, "which itself is a fraud."

Recent Techrights' Posts

A farewell to Finland, an occupied territory
Finland, Finland, Finland
The Real Reason Censorship is Attempted Against Us (and Against Others Too)
Microsoft's Windows market monopoly was in trouble
You Are Not The Only One
Reprinted with permission from Cyber Show (C|S)
GNU/Linux in Monaco: From 0.3% to Almost 6%
Monaco is a small country
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, May 22, 2024
IRC logs for Wednesday, May 22, 2024
Microsoft Has Lost Cote D'ivoire (Ivory Coast), Where Android Now Exceeds 60% of the Operating Systems' 'Market Share'
According to statCounter anyway
The Rumour Said Later Today Red Hat (IBM) Might Announce Layoffs
Let's see what happens later today (or next week)
Governments That Fail Journalism
Australia is known for giving us pure garbage like Rupert Murdoch
Windows Has Fallen From 'Grace'
When you tell people that Microsoft watches their every move in Windows many of them will freak out and ask for alternatives
Serbia: GNU/Linux at Almost 4% (or Beyond if ChromeOS is Counted)
considerable growth for GNU/Linux
Links 22/05/2024: China in Other Countries' Islands, Growing Threat of Piracy
Links for the day
Gemini Links 22/05/2024: Freedom Through Limitation, Cloud Photos
Links for the day
Canonical Supports Monopoly
more of the same
Links 22/05/2024: "Copilot+" as Mass Surveillance and Microsoft Defying Consent in Scarlett Johansson's Case
Links for the day
[Meme] Escalating After Failures
4 stages of cancel culture
Red Hat Had 2+ Days to Deny Reports of Impending Layoffs. But Red Hat Chose to Keep Silent.
Red Hat DOES NOT deny layoffs on the way
Microsoft-Connected Person Was Threatening to Sue Me and to Sue My Wife (Because His Feelings Were Hurt After Had He Spent More Than a Decade Defaming Me and Violating My Family's Dignity, Privacy)
litigation was chosen and we shall defend everything we wrote
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, May 21, 2024
IRC logs for Tuesday, May 21, 2024
Attempts to Sink the Free Software Movement (Under the Guise of Saving It)
We can see who's being drowned
Czech Republic: Windows Down From 98% to 43%, GNU/Linux Rises to Over 3%
modest gains for GNU/Linux
Links 22/05/2024: Pixar Layoffs and More Speculation About Microsoft Shutdowns/Layoffs (Ninja Theory)
Links for the day
Microsoft-Connected Sites Trying to Shift Attention Away From Microsoft's Megabreach Only Days Before Important If Not Unprecedented Grilling by the US Government?
Why does the mainstream media not entertain the possibility a lot of these talking points are directed out of Redmond?
Gemini Links 21/05/2024: Caesar II for MS-DOS and Reinventing the Assertion Wheel
Links for the day
Internal Memos/Communications Hinting at "a New, But Masked, Round of Layoffs" at Red Hat
A negative outlook heads of a long weekend
Nigeria: Windows Down to 6%, Android at All-Time High of 77%
Google is becoming the "new monopoly" in some places
[Video] Microsoft's Attack on Education
Microsoft's cult-like activities and overt entryism
[Meme] Money In, No Money Out (Granting Loads of Invalid European Patents)
EPO production?
Staff Representation at the EPO Has Just Explained to Heads of Delegations (National Delegates) Why the EPO's Financial Study is Another Hoax
Here we are again 5 years later
Canonical and Red Hat Are Not Competing With Microsoft Anymore
What a shame they hired so many people from Microsoft...
Links 21/05/2024: "Hating Apple Goes Mainstream", Lots of Coverage About Julian Assange Ruling
Links for the day
Gemini Links 21/05/2024: Losing Fats and Modern XMPP
Links for the day
Microsoft Windows Used to Have Nearly 100% in China and Now Google Has 50% (With Android)
Will China bring about a faster "fall" for Microsoft?
Pursuing a Case With No Prospects (Because It's "Funny")
the perpetrators are taking a firm that's considered notorious
GNU/Linux Growing Worldwide (the Story So Far!)
Microsoft is unable to stop GNU/Linux
GNU/Linux in Honduras: From 0.28% to 6%
Honduras remains somewhat of a hotspot
Good News From Manchester and London, Plus High Productivity in Techrights
what has happened and what's coming
[Video] The 'Linux' Foundation Cannot be Repaired Anymore (It Sold Out)
We might need to accept that the Linux Foundation lost its way
Links 21/05/2024: Tesla Layoffs and Further Free Speech Perils Online
Links for the day
Gemini Links 21/05/2024: New Gemini Reader and Gemini Games
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, May 20, 2024
IRC logs for Monday, May 20, 2024