Bonum Certa Men Certa

Get Rid of Back Doors, Don't Obsess Over Bounties and Other Corporate PR Stunts (or Needless Reboot Rituals)

posted by Roy Schestowitz on Apr 23, 2025,
updated Apr 25, 2025

DO NOT TALK TO COMPUTERS

Recent: Unlike GAFAM, Free Software Serves You, It Does Not Serve Governments and MElons (Overlapping Forces)

Security as a term has mostly lost its meaning due to repeated misuse for many years. Jessica Lyons recently explained how back doors got framed as a Chinese attack; maybe just don't put back doors in there to begin with? No? Too much to ask for?

What is a lot of modern "security" (gimmicks) anyway?

It is not genuine security but some "security product" (or appliance or service) that is proprietary, opaque and itself contains - hence adds even more - security holes, right?

Keep "buying" (licensing) or "subscribing" to our snake-oil, say the peddlers.

Paper pushers who call themselves managers meet "compliance requirements" by signing some contracts without actually improving anything at a technical level.

Consider the new article, "Submit ransomware intel, earn up to $10k from new program" by Jessica Lyons at The Register (she's quite in-depth by the way, no shallow parroting of GAFAM claims).

As associate who read her article said that the money would be more effective if spent on migration away from Windows (back doors at many levels). "It's not altruistic," Lyons notes. "The bulk of the ransomware info being submitted will go to improve Halcyon's anti-ransomware engine, rather than automatically ending up in a publicly available database for all network defenders to freely access."

Yes, Halcyon (there are several companies with that name, hence a bit hard to keep track).

Selling "security" is like selling "hey hi" (AI). It's just some buzzword these days and last year, in a public talk, Richard Stallman openly complained about both.

We're seeing a lot of shallow articles about security not every day but many times each day, even on holidays and during weekends. Here's a shallow new article entitled "Severance: what the hit show can teach us about cyber security and human risk" by Oli Buckley ("Professor in Cyber Security, Loughborough University"; he's no Ross Anderson). Recall Why We Can't Teach Cybersecurity by Dr. Andy Farnell. Buckley's article is sci-fi nonsense and there's also a comment there to the same effect (only one comment). To quote:

As someone who has researched insider threats for the last decade I can’t help but see Severance as a cautionary tale of what happens when we try to eliminate threats without understanding people.

If he "researched insider threats for the last decade", then he'd know that insider threats, such as leakers or rogue staff, aren't a matter of computer security. They're a staffing issue. It's also about non-digital practices (e.g. physical access and physical devices going in and out; remember what Edward Snowden did).

However the more worrying piece that I saw today was "Android Improves Its Security" by Bruce "Schneier on Security", linking to GAFAM megaphones and some such; oh, dear! If we pursue real security, should we not start by not having Google at all? It is doable by the way, and moreover it changes the attack surface through system diversity (no predictable or uniform way to exploit stack overflows for instance).

Schneier basically subscribes to nonsense, just because some article he saw online said something.

It basically seems like Google is now adopting the Microsoft Doctrine - something along the lines of just reboot, reboot, reboot as "security". It's really lame and the EFF's (Board) Schneier whistles along like all security boils down to is lots of reboots while Google works for the NSA and reportedly lets the FBI have remote microphone access (for about a decade already, the credible source being WSJ).

A friend has called it voodoo and superstition in place of actual procedures and methods, linking to this reminder about the origins of ctrl-alt-del (typically reboot, even today): ""I may have invented it, but Bill made it famous," Bradley said in an interview previously, leaving Bill Gates looking rather awkward. To this day the combination still exists..."

Apparently security now means devices "reboot themselves after sitting unused for 3 days", or to quote the body of Conde Nast's shallow piece:

A silent update rolling out to virtually all Android devices will make your phone more secure, and all you have to do is not touch it for a few days. The new feature implements auto-restart of a locked device, which will make your personal data harder to extract. It's coming as part of a Google Play Services update, though, so there's nothing you can do to speed along the process.

Seems like utter nonsense or really terrible design made to harvest data, not protect the device's carrier. Google is still in control of the process and as a public sponsor of Donald Trump we can assume he and his rogue agencies/enablers get access to all the data too. They can access cameras, microphones etc.

It should be noted that about a decade ago we saw dragnet surveillance wherein everyone possessing an Android device within some "suspicious" radius got subjected to 'deep state' scrutiny. How's that for security? Feeling safe now? Being one in 10,000 or so people flagged as "suspects" for merely dragging some Android 'phone' into the 'wrong' radius?

A friend spoke of "multiple dragnets. There were several stories about that lately."

This is becoming the norm.

It should not. But it does.

OK, whatever. "I'm addicted to my phone!"

But don't worry, this is all about security. Google is totally all about security because it runs PR events and stunts with monetary bounties (less than 0.001% of its revenue).

According to Google, all one needs for security is frequent reboots! Problem solved.

This is the uptime on my main laptop right now:

roy@vonick:~$ uptime
 15:53:37 up 561 days, 21:38, 39 users,  load average: 0.90, 0.77, 0.66

And the secondary laptop right now:

roy@bubi:~$ uptime
 15:54:12 up 496 days,  7:06,  3 users,  load average: 7.48, 7.27, 7.18

Just because I haven't rebooted since 2023 does not mean I'm at a high risk level; both are isolated from the Net for the most part, over almost all ports, and nevertheless they do get updated. The Microsoft media - and ridiculous LLM slop that follows/echoes it - wants people to think that because you can download malware from Microsoft it means that OpenSSH and Linux are dangerous. It's not just awkward logic but sheer dishonesty and malicious spin [1, 2].

Cybersecurity is now a resistance movement by Dr. Farnell is his latest article, which speaks a bit about politics. We'll leave politics out of it here. Those issues (like security) ought not be "partisan". They affect everybody similarly.

Farnell, like Ross Anderson, values real security. To quote what Farnell wrote about Anderson earlier this month: "Ross was not liked by the university to which he devoted his life. The fact is they wanted rid of him by forced retirement. At an institution taking funding from Elon Musk and some morally questionable technology organisations, Ross ruffled feathers with his plain integrity. He was not, however, an "activist" - which made the integrity all the more galling for some. [...] Ross gave his time and attention to people. But he did not do so indiscriminately, and I therefore suspect something even more profound; that Ross eschewed status - a heresy and remarkable position to hold in a place like Cambridge University. Many recounted lengthy, deep email exchanges with Ross, even if they felt like a "lowly nobody" or academic "outsider", as was my own experience. [...] Inevitably politics was in the air. Though students spoke highly of Cambridge University's inclusion improvements, diversity and LGBTQ+ society, expressing feelings of being able to "be themselves", some noticed it still falls short of reflecting the real makeup of the UK and it's neither race nor underlying class issues which still require attention but more complex problems of representatively including all mindsets. The questions remain; Security for who? Security from whom or what? Security to what end? [...] We know from so many comments that Ross was uncomfortable with and challenged the sources of research funding. We noticed a lack of willingness from the UK academics to talk about issues with Big Tech and the unfolding US situation, something that the US academics were surprisingly happy to discuss. Research funding from UK government and charities has been in decline since 2010 and while our government have the facility, equipment and talent to really lead in cybersecurity and AI, instead we take donations from SpaceX and the like to build the AI centre. This leads to biased research. That said, it seems Cambridge last took funding from them in 2015, 10 years ago now, and have since distanced themselves from Musk especially in the last year. Cambridge University Press even published a paper last year about Musk pushing academics off Twitter."

Lots more in there. Don't bother with corporate media (such as the Jeff Bezos-owned "journal of record") if you want to understand real security. As a part of GAFAM and sponsor of the Cheeto/MElon regime, Bezos wants back doors, not security. He values only his own privacy, as does Bill Gates.

Other Recent Techrights' Posts

IBM RAs (or PIPs) in London, England?
They try to keep the lid on it
The Solicitors Regulation Authority (SRA) Delusion - Part IV - Machos in Charge of the House (and System), Even If the Faces Are Female (Optics)
basically a Windows/Microsoft (US) shop
Brett Wilson LLP Seems to Have Done for Roberto Foa What It Did a Year Earlier for the Serial Strangler from Microsoft
Repeat abusers (of the legal system) will misuse it as long as regulators do nothing
Where We Stand With the Winter Series
We'll need to protect names and sources
Gemini Links 10/02/2026: "The Last Messiah", Discord for Adults
Links for the day
 
Links 10/02/2026: Media Freedom Feels Dead in Hong Kong and Grammys, Superbowl Becoming Politics
Links for the day
Kyndryl CFO Harsh Chugh Comes From IBM (17+ Years)
Who would want such a position?
International Buybacks Machines
Will the current US administration/regime look into IBM's accounting or only its mini me's?
IBM Could be the Next Kyndryl, a Dinosaur With Accounting Fraud
Many shareholders (or even pension funds) are taking a big hit today
Ian Murdock Died in San Francisco 10 Years Ago. Cops Led to His Death.
10 years ago Ian Murdock died after cops had messed him up
US/Europe divergence: health & safety, criminality & Debian harassment culture: Open Digital Ecosystems submission F33370170
Reprinted with permission from Daniel Pocock
Links 10/02/2026: Splinternets and "Meta Goes to Trial in a New Mexico Child Safety Case"
Links for the day
Russia and China Best Off Without GAFAM
What if they abandoned GAFAM?
Will Finns Put Out the Online Cigarettes?
More people recognise that the child porn site formerly known as "Twitter" and Cheeto/Pooh-tin controlled TikTok are no longer trustworthy
As the US Economy Sags Microsoft Layoffs Carry on (Now in Larger Waves Like 15,000 Per Season or 30,000+ Per Year)
They try to avoid "negative" topics
GNU/Linux at 3.99% in Australia
now that Australians can no longer keep Vista 10
Microsoft Windows Falling
analytics.usa.gov Shows Rapid Erosion of Windows Market Share Since 'End of 10' (Vista 10)
Microsoft Windows Hits All-Time Low in The Netherlands in 2026
Europe needs to rid itself or wean itself off GAFAM
SRA: SLAPPs From Russian War Criminals and American Men Who Strangle Women Are Acceptable
The SRA, by inaction, is complicit in this
From Weber Shandwick (Microsoft PR) to Brett Wilson LLP (Hired Gun of the Serial Strangler of Microsoft)
they basically tried to charge me a lot of money for a PR project of someone who strangled women
The Solicitors Regulation Authority (SRA) is Not a Regulator, It's Part of the Litigation "Industry" in the UK (They Overlap Each Other)
Does nothing except talk about SLAPPs
In Finland, Microsoft Falls Behind Yandex (Russia)
Bing has had many layoffs in recent years
Security More Advanced in Geminispace Than on the Web (Bloat)
For real security, use Geminispace capsules, not Web sites
Slop at Microsoft is a Miserable Failure, Now Microsoft Takes the "Vista Route" (Paying People to Say Good Things About It)
This is brainwash, it's meant to delay the implosion of the bubble
Rumours About February 2026 Microsoft Layoffs: Silent Layoffs or 30,000 Culled Tomorrow
Sooner or later (and soon) Microsoft will need to say something and file some WARN notifications
GNU/Linux at 12% in Guam, Based on statCounter (Compared to 2-3% a Year Ago)
Guam's "uptick" in GNU/Linux usage started weeks after "end of 10"
Fighting Slop With the Public Domain (and Why Slopfarms Perish Faster Than New Ones Appear)
We can combat the nonsense by producing more human-made works until the slop bubble implodes
After Employee Reviews at IBM Staff Expects Another Large Wave of PIPs and "RAs" (Layoffs)
From what we can see in the "public Web"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, February 09, 2026
IRC logs for Monday, February 09, 2026
Is Europe Abandoning Digital Opium?
GAFAM-controlled social control media
Mobbing at the European Patent Office (EPO) - Part V - Strongest Strike Under António Campinos
SUEPO Munich is also reminding people of the threat of PIPs
Microslop is Slop, Slop is Considered "Quality"
no wonder Microsoft's stuff breaks down so often
thelayoff.com Deletes On-Topic Discussions (Layoffs) While Leaving in Tact Pro-Corporate Trolling Made by LLMs (Slop)
Who at thelayoff.com deems spam made by LLMs (slop) to be on-topic and unworthy of zapping, whereas actually on-topic and authentic threads get routinely deleted?
Gemini Links 09/02/2026: Great Salt Lake Ecological Observatory and Offpunk 3.0 "A Community is Born" Release
Links for the day
Links 09/02/2026: Mass Plagiarism and Pollution/FakeCoin Company Nvidia Contacted Anna’s Archives, Narges Mohammadi Gets Second Prison Sentence
Links for the day
GNU/Linux May Have Grown to 7% in Equatorial Guinea
Has there been some kind of mass migration there or is this just noise in the data?
Links 09/02/2026: Russia Intentionally Killing Civilians, Jimmy Lai Effectively Sentenced for Life for Publishing News
Links for the day
Microsoft Competitions, Addictions, and Popularity Contests Are Not Going to Help Perl, They'll Waste Everybody's Time and Give Microsoft More Control Over Its Competition
Microsoft does not like Perl
A Can of WORMS - Part IV - They Would Even Attack RMS for Criticising Autocrats (Saying This is "Politics")
Conforming to society's perceived expectations isn't how effective activism can ever be done or was ever done in the recent past
Gemini Links 09/02/2026: The Exploration Myth and Making JavaScript Fun
Links for the day
EPO Outrage and Maintaining the Pressure
A vending machine does not fall over after a first push
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, February 08, 2026
IRC logs for Sunday, February 08, 2026
"Low Performer" and "Underperformer" as Harmful Misnomers That Damage a Company's Reputation
Misnomers need to be avoided or called out
Expensive errors: Forbes Gold price, $44 billion Bitcoin given away by Bithumb, South Korea
Reprinted with permission from Daniel Pocock
Links 08/02/2026: Microsoft OSI (Openwashing Lobby) in Europe, Raised Against Social Control Media Provocateurs in EU
Links for the day
The Open Source Initiative (OSI) Lobbies for Microsoft in the EU, Promoting Proprietary Lock-in
OSI pushing and selling Microsoft and GitHub. OSI is Microsoft front group.
Getting the European Court of Justice to Annul the Illegal and Unconstitutional Unified Patent Kangaroo Court (UPC)
We're still working on it
Finland's Dependence on GAFAM (US) Needs to be Lessened, EU Must Follow This Path
It's unwise to make one's entire national infrastructure (computer systems) dependent on a regime which compares its black citizens to monkeys and assassinates nonviolent dissenters
Links 08/02/2026: Microsoft GitHub as Burden on Developers and "The Chomsky Epstein Files"
Links for the day
Gemini Links 08/02/2026: "Doing Not Much Tweaking" and "Reclaiming Digital Agency"
Links for the day
Forbes: BitCoin, Cryptocurrency pages removed from investment database, links stop working
Reprinted with permission from Daniel Pocock
Bitcoin warning followed immediately by network outage
Reprinted with permission from Daniel Pocock
Money Funneled to Protection of Software Freedom, But Nothing Really Lost
Crossposted from personal site
They Tell Us Slop Replaces Workers, But the Reality Is, US Debt Has Surged 2,300 Billion Dollars in Six Months (the Economy is Collapsing)
Oligarchy already entertains the option of running away to (or colonising) some other planet without pitchforks and "unwashed masses"
Mozilla Firefox Sinks to Just 1.5% in the United States
According to analytics.usa.gov
We're Still Fast
The site is even faster than the BBC's despite being on shoestring budget with only a small technical team
Gemini Protocol is Not a Waste of Time of Effort
We see more and more GNU/Linux- or BSD-focused bloggers turning to Gemini
Our Gemini Protocol Support Turns 5 Today
today is a rare anniversary for us
In Today's World, One Must be Tough and Principled to Get Ahead Morally
But not financially (sellouts)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, February 07, 2026
IRC logs for Saturday, February 07, 2026
The Right Wing in the United States Does Not Support Free Speech, It Supports Its Own Speech
Free speech is often opposed by those who also oppose Free software
IRC is a Lot Better Than Social Control Media (They're Not the Same at All)
A good social analogy for IRC is, there are many buildings with a party in each building
Microsoft 'Open' 'AI' is 'Dead Meat'
Or 0xDEADBEEF as some geeks might call it
When Identifying "Low Performers" and "PIPs" Aren't About Improving Performance But Reinforcing a Clique in Your Company/Organisation
It's very troubling to see once-respectable brands like IBM and institutions like the EPO resorting to this
Slop and Flop (IBM), Slopfarms and Hybrids (Linuxiac)
Did Bobby Borisov assume he would never get caught?
Crowdfunding vs Bitcoins: donations are better investment than digital tulip mania
Reprinted with permission from Daniel Pocock