Bonum Certa Men Certa

Former Chief Security Officer for Microsoft the Chairman of the Board of Firm Behind Heartbleed€®

Dagger in the heart of OpenSSL

Heart Bleed



Summary: A serious conflict of interests that nobody in the media is talking about; Codenomicon is headed by Microsoft's Howard A. Schmidt

SOMETHING fishy was in the news today (since early this morning), including articles from GNU/Linux-oriented journalists [1] and blogs [2], some of which pointed out that a vulnerability discovered and published irresponsibly by the firm headed by Microsoft's former Chief Security Officer (we wrote about his actions before) are already "patched by all Linux distros".



Now, looking at the site set up by his firm, you might not know this. It lists the names of many GNU/Linux distributions along with a nasty picture (the one above). This coordinated release (disclosure) of a vulnerability on the last day of Windows XP security patches (they are through unless one pays Microsoft a lot of money) is rather suspicious to us. It came with a trademark-like name, a dot-com Web site (yes .com), and soon we are guaranteed to see lots of FUD saying that GNU/Linux is not secure. We already know that the vulnerabilities industry is well inside Microsoft's board and at highest level (look at John Thompson from Symantec; he is now Microsoft's new chairman).

We don't need to wait for the Microsoft press or a whisper campaign to use Heartbleed€® to tell people (again) that Free software, Linux and GNU are very "bad" and are a danger for the Web (some suspect that this bug is the result of NSA intervention in code development -- a subject we'll tackle another day for sure).

"This is a man whose high-paying job required that he beats GNU/Linux at security."Jacon Appelbaum (of Tor) says that this release was coordinated (with a date and everything) but not responsible at all because even the OpenSSL site, the FBI's official site (whom Howard Schmidt worked with) and many more remain vulnerable. It should be noted that the flaw has existed for two years, so the timing of this disclosure is interesting. Not too long ago we showed what seemed like Microsoft's role in a campaign to paint GNU/Linux insecure and dangerous becuase of Windows XP's EOL. It was a baseless campaign of FUD, media manipulation, and distortion of facts, ignoring, as always, the elephant in the room (Windows).

For those who treat it like some innocent development at a random time in the news, remember that Howard A. Schmidt, the Chairman of the Board of Codenomicon, was the Chief Security Officer for Microsoft. He joined Codenomicon a year and a half ago. This is irresponsible disclosure and journalists who ignore the conflict of interests (namely Schmidt being the head after serving Microsoft) are equally irresponsible (for irresponsible journalism). They may unwittingly be playing a role in a "Scroogled"-like campaign.

Just go to Codenomicon's Web site and find it described in large fonts as "A Member of the Microsoft Security Development Lifecycle (SDL) Pro Network" (in many pages). There are lots of pages like this one about involvement in Microsoft SDL.

So to summarise, what does Microsoft have to do with Heartbleed? We probably need to ask Howard Schmidt. This is a man whose high-paying job required that he beats GNU/Linux at security.

Related/contextual items from the news:



  1. Heartbleed: Serious OpenSSL zero day vulnerability revealed


  2. openssl heartbleed updates for Fedora 19 and 20


  3. Heartbleed, a serious OpenSSL bug; patched by all Linux distros
    A new vulnerability was announced in OpenSSL 1.0.1 that allows an attacker to reveal up to 64kB of memory to a connected client or server (CVE-2014-0160) which may consist of our X.509 certificates, user names and passwords, instant messages, emails and business critical documents and communication. According to OpenSSL Security Advisory report Neel Mehta from Google Security has discovered this bug.




Recent Techrights' Posts

Newer Not Better: Treadmill Updates Cause Problems
after 2 years the un-updated machines still fine
SLAPP Censorship - Part 136 Out of 200: Lawyers That Get Paid to Mess About
They were already outnumbered and understaffed
 
Cuts at IBM, Allegedly More Shutdowns to Come, CEO Visits Complicit Media to Promote Lies and Products That Will Never Exist (Misleading Shareholders)
IBM is collapsing
Links 01/08/2026: GAFAM Falling Deep Into Trillion in (Secret) Debt to Keep the Slop Bubble From Popping Already, Anger Over "FIFA’s World Cup Privatisation Plan"
Links for the day
The Cyber Show on the Slop Bubble
new article about the implosion of the slop bubble
Links 01/08/2026: New York Times Trying to Inflate the Slop Pyramid Scheme (at Cost to Its Own Reputation) and "Iran Appears to Be Blasting Amazon Data Centers Off the Map"
Links for the day
Positive Political Momentum
Daniel Pocock is taken seriously by many people who contact us privately
Google "AI" is Plagiarism, the Case of Richard Stallman (RMS)
Why would anyone choose LLM slop over the originals, curated and fact-checked by domain experts?
Explaining That Software Patents Are Neither Legal Nor Desirable
Many of our readers work in the legal sector
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, July 31, 2026
IRC logs for Friday, July 31, 2026
Gemini Links 01/08/2026: Retirement, Bike Trips, Quake Stuff, Usenet Reborn
Links for the day
Links 31/07/2026: Microsoft Now Says Slop is Bad (LinkedIn Cracks Down on It), LinkedIn Narrows Down Size (No Expansion)
Links for the day
European Patent Office (EPO) Series: From Alicante to Munich: Another Smooth Ride
Campinos is intent on transforming what was originally envisaged as a temporary public office into his own permanent personal feather-bed
Daniel Pocock and the Important Observation About Threats of Cult-Like Behaviours (No Rationality, No Reason, Just "Mob Rule")
It's a threat to Europe's sovereignty
The "PIP Parade" of IBM's Lousy Management, Which Said "Blockchain" Was the Future
In a healthy company such a CEO would be punished for utterly wrong visions and predictions. Not at IBM...
SLAPP Censorship - Part 135 Out of 200: Limited Liability Partnership (LLP) That Does Not Disclose Financial Activities Before August
It certainly looks like they keep losing the remaining women that still exist in the firm
Links 31/07/2026: "Climate Cover-Up Continues" and Pesticides "Cook the Planet"
Links for the day
Datacentre 'Boom' Sceptics Aren't Luddites, They Recognise a Threat to Human Survival (Not Limited to Climate Change)
Archaeologists very well know that no species will survive forever
Microsoft's Claims Are Based on a Big Lie
the bubble is coming to its hard limits
Don't Lose Sight of the Impact of "End of 10" (Vista 10)
GNU/Linux has taken off fast
Microsoft's Debt Continues to Steadily Increase, Not Counting Hundreds of Billions in Secret/Hidden Debt
The mass layoffs will carry on, maybe labelled LITE
IBM is Circling Down the Drain, the 'Growth' Comes From Beancounting Tricks and Salary Cuts
IBM was down 2.17% yesterday
Microsoft's "Headcount" Distracts From How Big a Cull It Had This Month
It also speaks of numbers "[a]s of June 30" though the "buyouts" were effective July 1 and since then well over 10,000 workers have vanished
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, July 30, 2026
IRC logs for Thursday, July 30, 2026
Gemini Links 31/07/2026: Music, Journaling, and Longing
Links for the day
More Fake News From (and for) IBM, Nobody Ever Held Accountable for Fraud
Companies that turn a blind eye to their own corruption end up recruiting more corrupt people and sacking those who object to the corruption
Links 30/07/2026: Smol Document Server and More PalmOS-ing
Links for the day
Links 30/07/2026: Microsoft Refuting Its Own Slop Hype and "Amazon Is Gutting Its Hey Hi (AI) Division" (GAFAM Bubble)
Links for the day
Today The Register MS Published "AI" Spam and Fake Article by "Senior Technical Marketing Engineer"
unethical practices
Cult inquiry parliament leak fallout
Reprinted with permission from Daniel Pocock
Techrights Will Always Protect Sources
Our #1 priority is sources
European Patent Office (EPO) Series: Legal Concerns and Suspicions of Irregularities
complaints submitted to OLAF
The Era of Silence
So stay silent, remain hidden
GAFAM and IBM Dying in Massive Debt, Hence the Mass Layoffs (Increasingly Silent Layoffs That the Media Fails to Mention)
the integrity of this economy is only as good as its leaders or those who govern the market
TheLayoff.com Deletes Comment That Called IBM's Previous CEO, Ginni Rometty, "Gin 'n Tonic"
It is hard to believe the comment was deleted for being a duplicate (in another thread)
The Mainstream Media Continues to Overlook or Intentionally Ignore Hundreds of Billions in Hidden/Secret Microsoft Debt
the issue is that Microsoft's crisis is a lot greater and broader than this
SLAPP Censorship - Part 134 Out of 200: What "Majority Rules" Tell Us About the Litigant
we press on with this series
Overshoot Day Sites That Contribute to the Problem
Some of these are not even accessible (at all) without JavaScript
Microsoft May Have Gotten Rid of 8% of Its Workforce This Month
It's hard to know what's really going on because there's no transparency due to NDAs
Links 30/07/2026: "Age of Irrationality", Google Losing Money, and "House of Ellison is on the Brink"
Links for the day
Gemini Links 30/07/2026: Homeworlds Notes and Manuscript Submitted
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, July 29, 2026
IRC logs for Wednesday, July 29, 2026