Eye on Security: Red Hat Explains Why Windows is Less Secure, New Windows 0-Day Attack
- Dr. Roy Schestowitz
- 2010-07-01 13:46:45 UTC
- Modified: 2010-07-01 13:46:45 UTC
Summary: Comparative security news from this week
●
Open Source is Inherently More Secure, Says Red Hat (Microsoft
admits silent patching it never discloses)
But in the closed source world, you have to trust your vendor completely. All you get to see are binaries, so you have no way of knowing how they were built. President Reagan was fond of saying to Soviet leader Mikhail Gorbachev, "Trust, but verify." With proprietary software, you simply have to trust.
Microsoft, for example, pushes out security updates on the second Tuesday of every month. Bressers said they can't do that. Microsoft has the advantage of hiding security flaws and working on them at their leisure, but with open source software, that's not possible because everyone can see that there's a problem and they expect it to be fixed right away.
And if a security hole isn't plugged quickly enough, you can fix it yourself, Bressers explained.
An example of the power of open source is the ping of death bug. Back in the late 1990s someone figured out that if you send a giant ICMP packet to a computer, just about any computer, it will crash. The bug affected every operating system, routers, printers, etc. When the problem was discovered, the open source Linux operating system had the bug squashed in about 2 hours, Bressers recalled. The closed source operating system vendors, however, took days, weeks and even months to make and distribute a patch for the ping of death.
●
Microsoft: 10,000 PCs hit with new Windows XP zero-day attack
Nearly a month after a Google engineer released details of a new Windows XP flaw, criminals have dramatically ramped up online attacks that leverage the bug.
Microsoft reported Wednesday that it has now logged more than 10,000 attacks. "At first, we only saw legitimate researchers testing innocuous proof-of-concepts. Then, early on June 15th, the first real public exploits emerged," Microsoft said in a blog posting.
●
New Windows Live Messenger has same old privacy problems
Why do I get the impression that some folks at Microsoft just don’t get it?
●
Privacy problems persist in latest Windows Messenger 2011 beta [
via]
Earlier versions of Messenger played fast and loose with your privacy. The new Live Messenger 2011, currently in beta, suffers from some of the same defects
Recent Techrights' Posts
- Finland Needs to Dump Microsoft (Microslop) for National Security Reasons and the Same is True for Hundreds of Countries
- "I don't see why Ryssäs would want Finns to use microslop products..."
- Fight Til the End
- This comes to show that persistence pays off
-
- Working in the Shell (and Fish)
- Yesterday we spent about 5 hours on the shells and fish
- The Corrupt Lecture the Non-Corrupt - Part XXVI - Campinos Has Put Unfit-for-Employment Drug Addicts in Charge of the European Patent Office (EPO)
- How many months has Campinos got left before the delegates show him the door?
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, May 17, 2026
- IRC logs for Sunday, May 17, 2026
- Gemini Links 18/05/2026: Poetry, Sauna, and GNU Taler
- Links for the day
- "The Society of Media Lawyers" (UK) is a Truly Malicious Anti-Media Lobby Which Helps Rich/Abusive Americans and Hostile Countries Attack Actual Media Workers in the UK
- They typically source their money from aboard to besiege domestic actors (like honest journalists or independent outlets that document suppressed beats/topics)
- Slop Still Waning, Its Momentum is Driven by Companies That Stand to Lose a Lot (or Everything) When the Bubble Pops
- When it comes to LLM slop disguised as news, it's just not working out
- Gemini Links 17/05/2026: arXiv Brings Down the Hammer, UnderPOWERed, and Slopping With Tcl/Tk
- Links for the day
- Links 17/05/2026: Amazon Employees Herded Into Slop, Taiwan Sold Down the River by Cheeto
- Links for the day
- Links 17/05/2026: Society of Media Lawyers (Brett Wilson LLP et al) Lobby for More SLAPPs in the UK, “Courage in Journalism Award” Given in Oppressive Country
- Links for the day
- Cyber Show UK is Already Available Over Gemini Protocol
- This past week the total number of active Gemini capsules hit all-time records several times
- SLAPP Censorship - Part 79 Out of 200: They Will Soon Reach the 100 KG (Kilograms) Milestone; Wheelbarrows, Not Justice (Quantity of Legal Papers Sent to Us)
- It's about the quality, not quantity (unless your sole aim is to drown out or "flood the zone")
- The Corrupt Lecture the Non-Corrupt - Part XXV - Not Bringing Intelligence to the EPO, Not 'Artificial Intelligence' Either (But Intelligence-Eroding Drugs)
- The EPO was meant to be about science and law. In practice, however, it's about breaking the law and being stoned.
- The Cyber Show on Why Coding is Important and Slop Cannot Change or Replace That
- Hand-crafting one's site has plenty of advantages
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, May 16, 2026
- IRC logs for Saturday, May 16, 2026
- Gemini Links 17/05/2026: Music Theory, Reticulum Git Repos, and Releasing Kiln
- Links for the day
- Links 16/05/2026: Cuba Plunges Into Darkness (Energy Wasted by Nonsense), Googlebooks as Slop Nonsense (Energy Waste and Time Wasted)
- Links for the day
- Links 16/05/2026: Climate Issues, Free Speech, and Monopolies/Monopsonies
- Links for the day
- Gemini Links 16/05/2026: Retreat and Devuan Manuals
- Links for the day
- SLAPP Censorship - Part 78 Out of 200: Slandering Me for Saying the Truth About Graveley and Garrett's Abuse of Processes, Stacking Dockets
- These are the sorts of things British taxpayers ought to talk about
- "AI" Became a New Name or Placeholder for Debt
- Because they will only ever lose money for this thing with "tokens" or "potential"
- "Microsoft Goodwill and Intangible Assets" Down Two Years in a Row, According to Microsoft
- Microsoft cannot sell these, so what is their real relevance?
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, May 15, 2026
- IRC logs for Friday, May 15, 2026
- IBM: Shares Down 30%, Mass Layoffs, IBM Says "Goodwill" Grew by 10% to Over a Third of the Company's Total "Worth"
- According to IBM
- Microsoft LinkedIn Layoffs "Very Likely Higher" Than 1,000 People
- Microsoft is bleeding
Comments
saulgoode
2010-07-01 14:10:44
Not just trust the vendor, but also those with whom they've shared the source code (subcontractors, governments, large corporate clients, etc).
It is noteworthy that there were claims that the recent attack on Google stemmed from sources within the Chinese government (with whom MS shares its source code), it is not that surprising that Google would quickly put an end to a situation where the malware authors get to see the Windows source code and they do not.
Dr. Roy Schestowitz
2010-07-01 14:17:26