Bonum Certa Men Certa

The Latest FOSS FUD Revolves Around Fakes and Bogus Arguments

Summary: How Free/Open Source Software (FOSS) gets discredited over "security", based on something which has nothing to do with FOSS and more to with human error or social engineering

THE reports from IDG make it sound as though FileZilla is a security threat [1,2] when it fact it is fakes that are a threat, as Sean pointed out to counter these allegations [3].



Yesterday we took note of the trend and two days ago we gave some examples of security-flavoured FUD against Android, of which there is plenty these days (and even today). Some of it is correctly being characterised as platform-agnostic [4]. This sometimes requires user intervention [5] or social engineering [6], so there's a lot more to be taken into account. When the OpenSSL project got compromised some weeks ago it was actually the fault of a weak password [7,8], but some of the media spread FUD about OpenSSL itself. Weak passwords are a common human error [9] and those who don't encrypt E-mails that contain passwords (they should!) only have themselves to blame [10,11]. To get an example of real vulnerability, consider Apple's Safari storing passwords in plain text [12]!!! GNU/Linux, by contrast, facilitates strong encryption and has protection against all sorts of attacks [13-14].

Blaming FOSS for issues that relate to social engineering is a common FUD pattern these days (like blaming Android for users installing malware they download outside repositories), but the real security issues are back doors like Microsoft's, security flukes like Apple's, and data leakage through so-called 'clouds' (which are typically promoted by proprietary software players, tightly connected to the crack-leaning NSA).

Related/contextual items from the news:



  1. FileZilla warns of large malware campaign


  2. FileZilla warns of large malware campaign


  3. FileZilla, Other Open-Source Software From 'Right' Sources Is Safe
    A basic tenant of open-source software security has long been the idea that since the code is open, anyone can look inside to see if there is something that shouldn't be there.


  4. Java-based malware driving DDoS botnet infects Windows, Mac, Linux devices
    The cross-platform HEUR:Backdoor.Java.Agent.a, as reported in a blog post published Tuesday by Kaspersky Lab, takes hold of computers by exploiting CVE-2013-2465, a critical Java vulnerability that Oracle patched in June. The security bug is present on Java 7 u21 and earlier. Once the bot has infected a computer, it copies itself to the autostart directory of its respective platform to ensure it runs whenever the machine is turned on. Compromised computers then report to an Internet relay chat channel that acts as a command and control server.


  5. Yahoo users exposed to malware attack
    Users clicking on some ads are redirected to sites armed with code that exploits vulnerabilities in Java and installs a variety of different malware.


  6. Password Security Requires Multiple Layers of Protection
    The gist of the story is that "123456" is now the most commonly used weak password—surpassing the use of the word "password."


  7. No hypervisor vulnerability exploited in OpenSSL site breach
    The OpenSSL Project confirmed that weak passwords used on the hosting infrastructure led to the compromise of its website, dispelling concerns...
  8. OpenSSL site defacement involving hypervisor hack rattles nerves (updated)
    Code repositories remained untouched in the December 29 hack, and the only outward sign of a breach was a defacement left on the OpenSSL.org home page. The compromise is nonetheless rattling some nerves. In a brief advisory last updated on New Year's Day, officials said "the attack was made via hypervisor through the hosting provider and not via any vulnerability in the OS configuration." The lack of additional details raised the question of whether the same weakness may have been exploited to target other sites that use the same service. After all, saying a compromise was achieved through a hypervisor vulnerability in the Web host of one of the Internet's most important sites isn't necessarily comforting news if the service or hypervisor platform is widely used by others.
  9. 7 sneak attacks used by today's most devious hackers


  10. 10,000 Top Passwords
    Back when I wrote Perfect Passwords, I generated a list of the top 500 worst (aka most common) passwords which seems to have propagated quite a bit across the internet, including being mentioned on Gizomodo, Boing Boing, Symantec, Laughing Squid and many other sites. Since then I have collected a large number of new passwords bringing my current list to about 6,000,000 unique username/password combos, including many of those that have been recently made public*.


  11. All Your Internet Are Belong To Iceland*
    All that being said, and given that the Luddite solution of forsaking the Internet may not be terribly practical, this is another reason to encrypt technical data that you are sending by email even if the recipient is a U.S. person firmly planted on U.S. soil. No, the encryption isn’t a defense to the violation, but it is at least a mitigating factor. Remember, as I posted last May, that the U.S. military thinks it can put ITAR-controlled technical data on a Chinese satellite if it’s encrypted; so if you don’t have anything else to say in your defense when an email with export controlled data accidentally wanders through Lithuania, you will at least have that. And maybe one day in the distant future, BIS and DDTC will admit that the Internet exists and that encryption works.


  12. Older Versions of Safari Store Login Info in Plain Text
    Older versions of Safari for Mac store unencrypted user login credentials in a plain text file, according to security firm Kaspersky (via ZDNet). Safari saves the information in order to restore a previous browsing session, reopening all sites, even those that require authentication using the browser's "Reopen All Windows from Last Session" functionality.


  13. Quantum crypto pitches for data centre links


  14. Linux Is the Only Way to Protect Against Potential Sound-Transmitted Malware


Recent Techrights' Posts

Silent Layoffs, Cool-down, and Cool-off: How GAFAM and IBM Operate (the Law Doesn't Apply to Them)
Laws? What laws?
 
People Who Enforce the GPL Banned From Linux Foundation Board (After Bribes From Prolific GPL Violators), Now They're Banned From Giving Talks at Events
about the "LF" ('Linux' Foundation)
Gemini Links 06/09/2026: The Slop Plagiarism 'Holy War' (Hype, Scam, Scheme), Burning CD-Rs, and Hardcopy Mono
Links for the day
Solicitors Regulation Authority (SRA) Inaction and Incompetence - Part IV - Insufficient Resources in the Face of Distributed Denial of Service (DDoS) by Lawyers
it's about 120KG
OpenStreetMap is the Future, Dictatorship is the Past
OpenStreetMap helped us check maps for transport, various overlays with addresses, and there was 0% reliance on GAFAM or "Google" anything
How Strikes at the European Patent Office Are Seen by Striking Staff in Berlin, Germany
We have some more EPO scandals to cover later this year and next year
Association for Computing Machinery Cites Techrights in Relation to GemText and Gemini Protocol
published yesterday, Open Access
Links 06/09/2026: More XBox Trouble (Microsoft Unrest, Many Silent Layoffs This Month), John Duffy as Next USPTO General Counsel
Links for the day
Gemini Links 06/09/2026: Avoiding 'Smart' 'Phones' and Setting up Gemini for the First Time
Links for the day
Links 06/09/2026: Sabotage by Slop and "What Happens If 'Open' 'AI' Dies?"
Links for the day
How Back Doors Became the 'Normal' or 'Norm'
"We also allowed a lethal monoculture to fester"
Solicitors Regulation Authority (SRA) Inaction and Incompetence - Part III - The SRA is Vastly Worse Than Brits Realise, We Have a "Wild West" in London
In the next part we'll begin looking at correspondence with the SRA
SRA and Manslaughter: How the SRA Contributed to Agony in Proprietary Software Scandals With Clear Misuse of "Without Prejudice"
Trying to prevent the public from finding out the criminal stuff that went on, resulting in many deaths
Canonical (or Ubuntu) Rejecting IRC Isn't the Widespread Trend
Internet Relay Chat (IRC) adoption still growing by some yardsticks
SLAPP Censorship - Part 173 Out of 200: Two Years
It was exactly 2 years ago that we filed lawsuits against Garrett
Linux of America
We could not help but notice GNU/Linux in North America yesterday
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 05, 2026
IRC logs for Saturday, September 05, 2026
Gemini Links 06/09/2026: Internet Limiting (Limited Time Allotted) and Solar MiniServer
Links for the day
Eight Months of Strikes in EPO, Organised by the Staff Union (SUEPO) Also in Berlin
In Berlin, only one member of staff voted against the action plan
Links 05/09/2026: "Let’s Stop Buying New Phone" and 'Open' 'AI' (Proprietary Slop) Drowning in Lawsuits
Links for the day
Gemini Links 05/09/2026: Polarization, Warped Maps, and Emacs rectangle-number-lines
Links for the day
Software Freedom, Even If Difficult to Attain Due to Outside Pressure, Does Make You Happier
Peer pressure and opinionated employers can make friends and staff more miserable if they dictate bad software
You Can Run GNU/Linux on a Desktop/Laptop for 1,000+ Days Nonstop
To me, the long uptime is a way of "marketing" GNU/Linux as robust and stable
Profiting From Global Warming (and Making More Money the More You Cause Warming)
Unregulated bank and pyramid scheme
SLAPP Censorship - Part 172 Out of 200: The Solicitors Regulation Authority (SRA) Complicit in the SLAPPs by Inaction (Didn't Even Study Any Evidence, Only Wasted Time and Budget)
"SRA placed into special measures due to 'disappointing standard of leadership'"
China Does Not Need American (US) Products Like GAFAM's
China has abundance of technical things it can leverage to preserve its autonomy
RMS Didn't Make Enough Backups
Making backups is important
Refresher: Why EPO Staff is on Strike This Year (Aside From the EPO Acting Like a Corrupt, Above-the-Law, For-Profit Corporation That Violates Its Own Charter)
One core issue at the EPO is erosion of purchasing power
Gemini Links 05/09/2026: Fireflies, Shore Pine, and ASCII Art
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, September 04, 2026
IRC logs for Friday, September 04, 2026
The Legal Services Board (LSB) Takes on Solicitors Regulation Authority (SRA) for Utter Failures, We'll Resume Our SRA Series to Illuminate How Bad the SRA Really Is
a quick overview of the latest news
Links 04/09/2026: Notorious Patent Trolls' Judge Enters the Private Sector (Corruption, Revolving Doors), Gloria Steinem's Life in Pictures
Links for the day
Gemini Links 04/09/2026: Worries, Upgrades, and CS Students
Links for the day
Richard Stallman's Web Site Back Online, But It Seems Like a 2-Months-Old Snapshot
Latest political notes are dated July 2 (2026)
SPAM Disguised as Benchmark or Comparison: The Register MS "PARTNER CONTENT" is Getting Weirder by the Month
Sites that promote fake 'coins' or pyramid schemes to their audience(s) aren't worth tolerating
PIPs at IBMs are Layoffs Because They're Impossible to Satisfy (or They Terminate Workers Despite Satisfying Them)
What insiders say
In the United Kingdom You Can No Longer Make the Assumption People Use Windows (or 'Smart' 'Phone')
As autumn arrives Microsoft faces a crisis
SLAPP Censorship - Part 171 Out of 200: Talking About Corruption and Violence Against Women
Today the Labour Party (UK) speaks about corruption
Warming Up for Investigative Journalism About the European Patent Office (EPO), Europe's Second-Largest and Probably Most Corrupt Institution in Europe
It continues to exploit diplomatic immunity for impunity
Microsoft Handing Out PIPs by the Thousands, Anxiety in GAFAM Building Up
Years ago I heard from people who pretended to be ill to avoid getting fired
BRICS in the Windows: Brazil's GNU/Linux Share (as Measured by CDN) Has Hit Highest Point in a Month
The largest Web CDN, Clownflare, sees GNU/Linux at 8.1% right now in Brazil
Corporate Media Will Always Glorify Its Owners (Corporations That Value Nothing But Capital)
Collecting "money" like it's a form of competition where they track "score"
We'll Never Do Slop!
Being against slop is not being "left behind"
Thieves Complain About the People They Steal From
"When you point the finger at someone, there are three fingers pointing back to you"
Links 04/09/2026: "The Rise of the Billionaire Lobby", the "Imperialist Delusions", and Digital Restrictions (DRM) From Nvidia
Links for the day
Buying From China
Nations must begin to speak about their digital sovereignty, which Free software is best equipped to grant and best positioned to assure in the face of outside resistance
GNU/Linux Continues to Grow in China
GNU/Linux reached its highest point in a month
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 03, 2026
IRC logs for Thursday, September 03, 2026
Gemini Links 04/09/2026: Forgotten Realms Avatar Series and Slop Plagiarism's Footprint in Gopher/Geminispace
Links for the day