Bonum Certa Men Certa

Red Hat Should Keep Its Distance From NSA Facilitator Microsoft

Dragonfly



Summary: Criticism of Red Hat's increasing proximity to some of the very same bits of proprietary software which are accompanied by back doors (for the NSA)

THE DANGERS of Microsoft are very real, as a former foe of Microsoft, Novell, helped prove. Five years ago Red Hat consented to playing an active part in Microsoft VM hosts, despite knowing (even back then) about Microsoft's relationship with the NSA, which meant that VMs running RHEL would be accessible (to the NSA) from the back door, Microsoft Windows.



There are many back doors in Windows and therefore in Hyper-V, which sits on top of Windows (back doors further down the stack). Microsoft tells the NSA about these back doors. To give the latest example of back doors, see this new report [2] which says: "Nearly 30 days after reports of a zero-day flaw being exploited in the wild, Microsoft will finally patch this critical vulnerability."

Relying on Microsoft for technology means that one should also expect and accept back doors. A reader showed us this new article, claiming that "Mono [is] infecting Android," but it's not just Android. Even Red Hat is now making such mistakes, in addition to hiring from Microsoft for management of virtualisation. Based on [2,3], Red Hat now accommodates Microsoft .NET applications, despite them being proprietary and potential back doors. A week or so ago some speculated that Microsoft might buy Red Hat (one day) [4,5] and yesterday we found the article "Why Microsoft Will Pick Off Red Hat" (logic of investors, not technical people).

Microsoft is now knowingly abandoning hundreds of millions of Windows users, leaving them with permanent back doors [6,7], so why should Red Hat trust Microsoft .NET applications or anything that comes from Microsoft, including Hyper-V? Articles like [8-10] remind us that in GNU/Linux the main flaw is human error (not changing default passwords or not applying patches, which Red Hat is making easier to apply without any downtime [11]).

The bottom line is, Red Hat's relationship with the NSA withstanding, it oughtn't connect too much to Microsoft components like .NET and Hyper-V because these constitute back doors that jeopardise security of GNU/Linux users.

Related/contextual items from the news:
  1. Microsoft to Fix an Internet Explorer Zero-Day Flaw


  2. Red Hat Adds Microsoft .NET to Its OpenShift PaaS
  3. A Red Hat stunner: 'Miccosoft .NET apps on OpenShift' Yes, you read correctly
    On Wednesday, Working with Uhuru Software, Red Hat is now incorporate a rival Microsoft product - .NET - to its three-year-old OpenShift platform-as-a-service. Really? Red Hat even published a blog to explain what's going on to those who might find the concept a bit unbelievable.

    Chris Morgan, the OpenShift Partner Ecosystem Technical Director for Red Hat, wrote the blog - and even he acknowledged the incredulity of it all that something from Microsoft, which for years has been an enemy of Red Hat, Linux and Open Source, would be incorporated into OpenShift.


  4. An Indecent Proposal: Microsoft and Red Hat?


  5. Reviews, Indecent Proposal, and Ubuntu Graduation
    Today brings two new reviews. Jesse Smith reviews Linux Mint Debian Edition 201403 in today's Distrowatch Weekly and Jamie Watson posts his latest hands-on. Steven J. Vaughan-Nichols says folks don't care about operating systems anymore. Matt Hartley has a few suggestions for those ready to graduate from Ubuntu. All this and more in tonight's Linux news review.

    Jesse Smith tested the latest LMDE in this week's Distrowatch Weekly. He found a few bugs but Smith says it "lives up to its description" of having "rough edges." With all its "nasty surprises" Smith suggests folks just stick with the Ubuntu-based version of Mint. But see his full review for all the details.


  6. Perspective: Microsoft risks security reputation ruin by retiring XP
    A decade ago, Microsoft kicked off SDL, or Security Development Lifecycle, a now-widely-adopted process designed to bake security into software, and began building what has become an unmatched reputation in how a vendor writes more secure code, keeps customers informed about security issues, and backs that up with regular patches.
  7. Positive Feedback: M$ Uses XP To Publish The Insecurity Of Using That Other OS


  8. Flaws In People And Their Software
  9. Red Hat Risk Reflex (The Linux Security Flaw That Isn't)
    News headlines screaming that yet another Microsoft Windows vulnerability has been discovered, is in the wild or has just been patched are two a penny. Such has it ever been. News headlines declaring that a 'major security problem' has been found with Linux are a different kettle of fish. So when reports of an attack that could circumvent verification of X.509 security certificates, and by so doing bypass both secure sockets layer (SSL) and Transport Layer Security (TLS) website protection, people sat up and took notice. Warnings have appeared that recount how the vulnerability can impact upon Debian, Red Hat and Ubuntu distributions. Red Hat itself issued an advisory warning that "GnuTLS did not correctly handle certain errors that could occur during the verification of an X.509 certificate, causing it to incorrectly report a successful verification... An attacker could use this flaw to create a specially crafted certificate that could be accepted by GnuTLS as valid." In all, at least 200 operating systems actually use GnuTLS when it comes to implementing SSL and TLS and the knock-on effect could mean that web applications and email alike are vulnerable to attack. And it's all Linux's fault. Or is it?


  10. Linux Bugs, Bugs Everywhere
    "We are seeing a lot of crypto bugs surfacing lately because these libraries are suddenly getting a lot of review thanks to Snowden's revelations," suggested blogger Chris Traver. "I think one has to separate the crypto bugs from others because they are occurring in a different context. "From what I have read about gnutls, though, it seems to me that this is probably the tip of the iceberg."
  11. Introducing kpatch: Dynamic Kernel Patching
    In upstream development news, the kernel team here at Red Hat has been working on a dynamic kernel patching project called kpatch for several months. At long last, the project has reached a point where we feel it’s ready for a wider audience and are very excited to announce that we’ve released the kpatch code under GPLv2.


Recent Techrights' Posts

All-Time Lows for Windows in Spain and Portugal
data which became publicly available less than 24 hours ago in statCounter
 
India Needs to Recognise That the World Wide Web is Monoculture in India
In the US, a judge with Indian roots dealt with a case related to this; why won't India?
All-Time Lows for Windows Down Under
seeing the demise of Windows in Australia (historically a slow or low adopter of GNU/Linux) is good news
Linux Kernel Tainted by Software Patents That Make Linux Worse and the 'Linux' Foundation is Compiling Bribes to Enable This (Promotion of Monopolies and Tolerance of Software Patenting)
Why you need to reboot when a serious bug is found in Linux? "Licencing"...
IBM's Kyndryl Accounting Fraud Explained and More Recently the Insiders Talk About Mass Layoffs
Judging by how the media totally ignored 800+ layoffs at IBM's Confluent and 400+ layoffs at Red Hat a few weeks ago don't expect to hear anything about Kyndryl layoffs
Links 03/05/2026: Water Shortages Crises and Slop Fakes "Are Coming for Your Bank Account" (Slop-Enabled Fraud)
Links for the day
The Corrupt Lecture the Non-Corrupt - Part XI - EPO 'Products' to Cement Asian and American Monopolies
Only a fool would believe Lame Duck Campinos
Microsoft Windows Falls Below 9% in South Africa
As one can expect, GNU/Linux is measured as going up in France
Gemini Links 03/05/2026: The Black Side of the Web, LiveJournal, Chimarrão
Links for the day
A Month Since Mass Layoffs at Red Hat (400+ Engineers Laid Off), The Media Didn't Cover It
We are very concerned about the state of the media
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, May 02, 2026
IRC logs for Saturday, May 02, 2026
Gemini Links 02/05/2026: Strange Psychosis and TUIs
Links for the day
Links 02/05/2026: Microsoft Has Begun Rebranding Vista 11 as 'XBox' (Because the Console is Dying), Slop Rejected by Oscars
Links for the day
IBM's CEO 10 Years Ago in IBM-Sponsored Forbes: "For those willing to embrace [blockchains], the future will indeed be bright."
How well did this prediction materialise?
SLAPP Censorship - Part 64 Out of 200: Not Amused by Repeated Threats (to "Shut Down" My "Existence" While Mentioning My Wife Too)
it's about censorship
RightsCon Cancellation as a Data Point in a World Gone Astray
RightsCon should not even be controversial
The NHS is Under Attack by Anthropic and Microsoft (or Their Lemmings That Infect the NHS)
They are kidding themselves if they seriously believe Web-facing source code repositories are the real threat to patients
cPanel is Not Linux, cPanel is Proprietary Software
It's fair to say I've used cPanel for 23 years
Links 02/05/2026: Gen Z is Turning Against Slop and OpenAI/Microsoft Rift Explained
Links for the day
Storage and Memory Prices Are Rising Not Because of High Demand (Production Can Match Demand), It's Partly Because of Price-Fixing (Same as Food Price Increases)
Sophisticated robberies are still robberies
Thousands of Layoffs at IBM, So IBM Pays Mainstream Media to Claim That IBM is Hiring (Paid Lies)
This is a story about the media failing us, not just IBM failing as a company
A Look at DataStax Bluewashing (IBM and Layoffs)
IBM is a place that many people leave or get pushed out of
Gemini Links 02/05/2026: Leaving Session, Alhena 5.5.7, and Slop Failing Customers
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, May 01, 2026
IRC logs for Friday, May 01, 2026
Links 01/05/2026: Microsoft 'Headcount' Decreasing, Apple Quietly Killing Vision Pro
Links for the day
Oracle's Debt Grew by Over 50 Billion Dollars in 6 Months
Larry Ellison spent a lot of money buying a lot of the corporate media
In Praise of Debian
30 hours ago we began an upgrade
What Linus (Torvalds, the Linux Dude) Meant by "Show Me the Code"
"Show Me the Code" is a common cultural reference
Yes, GNU/Linux Can Run on Playstation 5, But Don't Buy It, Learn From Sony's Past of Rootkit and PS3 Betrayal
Millions of Playstation 3 owners will never forget what Sony did to them
XBox Will Not Last Much Longer, XBox Chief Admits Problems
Microsoft's latest "results"
Dealing With Demagogue in Free Software
Don't spread their ideology and never participate in any of their projects
What May 1 Means to Us (and to Many Others)
To me, May 1 means something
Microsoft Lunduke is 'Pulling a Garrett' by Turning Technical and Legal Debate Over Rust Into a 'Trans Debate'
Don't fall for the demagogue
Links 01/05/2026: Regulatory Trouble for Apple, Now Even Mozilla Pushes Back Against Google
Links for the day
Microsoft "Buyout" Offer is Less Than One Year's Salary
So our assumption about this was correct
The Corrupt Lecture the Non-Corrupt - Part X - European Patent Office Managers Have Crossed Red Lines, According to Themselves
The girlfriend of the President of the European Patent Office (EPO) is trying to muzzle EPO critics
Techrights is Still Growing, Attacking Techrights Does Not Weaken the Community
Bullying us for 2+ years does not result in fear, it results in us feeling more emboldened and motivated
SLAPP Censorship - Part 63 Out of 200: Graveley as a Stripped-Down Version of Garrett in the Particulars of Claim (5RB Barrister Could Do This in One Minute)
Lazily and sloppily, it looks like the barrister took Garrett's claims and tweaked them a little (shortened) for Graveley
Lots of People Leave IBM, Today IBM Has About 1,000 Workers Fewer Than Yesterday
Confluent "last day" for 800+ people
Been a Very Busy Week
Next week, as we have no upgrades to prepare for, we should be able to publish at the usual pace of 20+ pages per day
In New Letter Sent to Chair and Heads of Delegation of the Administrative Council of the European Patent Organisation the Staff Union Explains How to End European Patent Office Strikes
If Campinos continues to behave as he does right now, the Council can show him the door
Links 01/05/2026: Poems and Continuous Privacy Policy
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 30, 2026
IRC logs for Thursday, April 30, 2026
Microsoft Debt Rose Almost $50 Billion Since We Moved to Debian
GAFAM has a new name for debt