07.01.10

Gemini version available ♊︎

Eye on Security: Red Hat Explains Why Windows is Less Secure, New Windows 0-Day Attack

Posted in GNU/Linux, Microsoft, Red Hat, Security, Windows at 8:46 am by Dr. Roy Schestowitz

Knobsets

Summary: Comparative security news from this week

Open Source is Inherently More Secure, Says Red Hat (Microsoft admits silent patching it never discloses)

But in the closed source world, you have to trust your vendor completely. All you get to see are binaries, so you have no way of knowing how they were built. President Reagan was fond of saying to Soviet leader Mikhail Gorbachev, “Trust, but verify.” With proprietary software, you simply have to trust.

Microsoft, for example, pushes out security updates on the second Tuesday of every month. Bressers said they can’t do that. Microsoft has the advantage of hiding security flaws and working on them at their leisure, but with open source software, that’s not possible because everyone can see that there’s a problem and they expect it to be fixed right away.

And if a security hole isn’t plugged quickly enough, you can fix it yourself, Bressers explained.

An example of the power of open source is the ping of death bug. Back in the late 1990s someone figured out that if you send a giant ICMP packet to a computer, just about any computer, it will crash. The bug affected every operating system, routers, printers, etc. When the problem was discovered, the open source Linux operating system had the bug squashed in about 2 hours, Bressers recalled. The closed source operating system vendors, however, took days, weeks and even months to make and distribute a patch for the ping of death.

Microsoft: 10,000 PCs hit with new Windows XP zero-day attack

Nearly a month after a Google engineer released details of a new Windows XP flaw, criminals have dramatically ramped up online attacks that leverage the bug.

Microsoft reported Wednesday that it has now logged more than 10,000 attacks. “At first, we only saw legitimate researchers testing innocuous proof-of-concepts. Then, early on June 15th, the first real public exploits emerged,” Microsoft said in a blog posting.

New Windows Live Messenger has same old privacy problems

Why do I get the impression that some folks at Microsoft just don’t get it?

Privacy problems persist in latest Windows Messenger 2011 beta [via]

Earlier versions of Messenger played fast and loose with your privacy. The new Live Messenger 2011, currently in beta, suffers from some of the same defects

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

2 Comments

  1. saulgoode said,

    July 1, 2010 at 9:10 am

    Gravatar

    But in the closed source world, you have to trust your vendor completely. All you get to see are binaries, so you have no way of knowing how they were built.

    Not just trust the vendor, but also those with whom they’ve shared the source code (subcontractors, governments, large corporate clients, etc).

    It is noteworthy that there were claims that the recent attack on Google stemmed from sources within the Chinese government (with whom MS shares its source code), it is not that surprising that Google would quickly put an end to a situation where the malware authors get to see the Windows source code and they do not.

    Dr. Roy Schestowitz Reply:

    Let’s remember that one Chinese company that Microsoft let write its code was unethical enough (even criminal) to rip someone else’s work and rebrand it as Microsoft’s [1, 2, 3, 4].

DecorWhat Else is New


  1. EPO Home-Working (or 'Remote' Working or 'Teleworking') Isn't an Act of Generosity But of Exploitation

    Contrary to what staff may be led to believe, allowing folks to work from home is just a workaround (as the law forbids some human-to-human contact/interaction) and pretext for screwing the workers a little bit more while crushing basic rights, such as strike and protest abilities (exercising or expressing dissent)



  2. IRC Proceedings: Wednesday, October 27, 2021

    IRC logs for Wednesday, October 27, 2021



  3. [Meme] False Choices and False Dichotomy Designed for Self-Harm

    The self-serving EPO surveys, which Benoît Battistelli and António Campinos design to justify their own policies, have severe flaws in them



  4. Links 27/10/2021: XOrg Server 21.1 and Makulu Shift Ubuntu Variant Released

    Links for the day



  5. Links 27/10/2021: Murena for /e/ and Red Hat Condemned for Its Nationalism/Racism

    Links for the day



  6. [Meme] EPO Presidential Surveys

    The 'social democracy' of Benoît Battistelli and António Campinos as demonstrated by a controlled survey (controlled by the subject of the survey, EPO governance)



  7. 'Shaping the New Normal' Survey at the EPO Got 5,554 EPO Staff to Participate, But It Was Controlled by Liars With an Agenda

    Last year’s EPO ‘study’ (hogwash about “quality” and other unscientific junk) was likely biased by virtue of autocrats controlling it and exploiting it for nefarious agenda and brainwashing of national delegates. The Staff Union of the EPO (SUEPO) has a new survey in the making.



  8. Many of the National Delegations (or Delegates) in the EPO's Administrative Council Have No Understanding of What They Vote on

    One must consider the possibility that ignorance or gullibility (which lack of qualifications may entail) possibly became a contributing factor — malice and bribery aside — in systemic failure of the EPO’s governance



  9. The EPO’s Overseer/Overseen Collusion — Part XXV: The Balkan League - Fresh Blood or Same Old, Same Old?

    We take stock of "captured states" that voted in favour of unlawful "Strike Regulations"



  10. IRC Proceedings: Tuesday, October 26, 2021

    IRC logs for Tuesday, October 26, 2021



  11. Beatriz Busaniche Speaks Up in Defense of Richard Stallman

    Beatriz Busaniche sent us this comment in July 2021. She wrote it originally in Spanish. Here are both the original text and our translation to English.



  12. Links 26/10/2021: SUSE Linux Enterprise Micro 5.1 and Multi-Distro Benchmarks

    Links for the day



  13. Links 26/10/2021: Vulkan 1.1 Conformance for Raspberry Pi 4 and Tor Browser 10.5.10

    Links for the day



  14. [Meme] Sounds Legit

    When not cheating on the wife, the EPO‘s “doyen” cheats in the exams and makes it into the epi Council, in effect working “[t]owards a common understanding [sic] of quality” with “patent attorneys nominated as “assessors” by the EPO, epi and BusinessEurope” (notorious lobbyists for dictators, litigation, and monopolies, neither business nor science)



  15. [Meme] Mayoral Patent Office Chief

    As it turns out, political 'double-dipping' isn't just a thing in North Macedonia, Austria, and EPOnia



  16. Romania's Patent Office (OSIM): Nine Different Chiefs in Just Eight Years

    The Romanian State Office for Inventions and Trademarks (OSIM), being the equivalent of the U.S. Patent and Trademark Office (USPTO) in the sense that it covers both patents and trademarks, is a very flaky institution with no shortage of scandals; for our English-reading audiences we now have a summary of a decade’s worth of blunders and leadership changes



  17. The EPO’s Overseer/Overseen Collusion — Part XXIV: The Balkan League - Romania

    Romania’s patent office has been in flux this past decade, occasionally led by people with no relevant experience, but rather political connections (like EPO President António Campinos) and sometimes forged documents and fake degrees



  18. IRC Proceedings: Monday, October 25, 2021

    IRC logs for Monday, October 25, 2021



  19. [Meme] “Social Democracy” at the EPO

    Some comments on the current situation at the European Patent Office from Goran Gerasimovski, the new EPO Administrative Council delegate for North Macedonia and Social Democratic candidate for mayor of Centar (a municipality of Skopje)



  20. [Meme] António Campinos Visits the OSIM

    António Campinos visits OSIM Director-General Ionel Muscalu in February 2014



  21. [Meme] [Teaser] Meet the President

    Later today we shall see what Romania did for Battistelli



  22. Links 26/10/2021: Latte Dock 0.10.3 and Linux 5.15 RC7

    Links for the day



  23. Gemini Protocol's Originator: “I Continue to Care About This Project and I Care About the Community That Has Formed Around It.”

    'Solderpunk' is back from a long hiatus; this bodes well for Geminispace, which grew fast in spite of the conspicuous absence



  24. Bulgarian Like Bavarian Serfdom

    Bulgarian politics seem to have played a big role in selecting chiefs and delegates who backed Benoît Battistelli‘s unlawful proposals, which treat workers almost like slaves and ordinary citizens as disposable ‘collaterals’



  25. The EPO’s Overseer/Overseen Collusion — Part XXIII: The Balkan League - Bulgaria

    Today we examine the role of Bulgaria in Benoît Battistelli‘s liberticidal regime at the EPO (as well as under António Campinos, from 2018 to present) with particular focus on political machinations



  26. Links 25/10/2021: New Slackware64-current and a Look at Ubuntu Budgie

    Links for the day



  27. Links 25/10/2021: pg_statement_rollback 1.3 and Lots of Patent Catchup

    Links for the day



  28. Microsoft GitHub Exposé — Part III — A Story of Plagiarism and Likely Securities Fraud

    Today we tread slowly and take another step ahead, revealing the nature of only some among many problems that GitHub and Microsoft are hiding from the general public (to the point of spiking media reports)



  29. [Meme] [Teaser] Oligarchs-Controlled Patent Offices With Media Connections That Cover Up Corruption

    As we shall see later today, the ‘underworld’ in Bulgaria played a role or pulled the strings of politically-appointed administrators who guarded Benoît Battistelli‘s liberticidal regime at the EPO



  30. IRC Proceedings: Sunday, October 24, 2021

    IRC logs for Sunday, October 24, 2021


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts