Bonum Certa Men Certa

Security FUD Against Free Software Resurfaces, Using Promotional Branding From a Microsoft-Linked Firm, So Red Hat Finally Responds

Bugs
Image courtesy of Red Hat



Summary: Old news is 'new' again, as Microsoft-friendly media decides to keep knocking hard on the reputation of Free software, using words rather than substance

A YEAR ago there was a curious (first of its kind for Free/Open Source software) "branding" of a 2-year-old FOSS bug by a Microsoft-linked firm that did not even find the bug. An engineer from Google had found it and sought to responsibly disclose it so as to patch it properly before the Microsoft-linked opportunists blew off the lid and called it "Heartbleed", set up a Web site to 'celebrate' the bug, and even made a professionally-prepared logo for it. This whole "Heartbleed" nonsense -- however serious it may have been for a day -- was blown out of all proportions in the media and tarnished the name of Free software because it was so 'successfully' marketed, even to non-technical people. It was a branding 'success' which many firms would later attempt to emulate, though never with the same degree of 'success' (where success means bamboozling the public, especially non-technical decision-making people).

"Microsoft must be laughing quite hard seeing all that media manipulation.""Dear journalists," I said earlier today in social media (Diapora), "bugs don't have birthdays. Stop finding excuses to bring "Heartbleed" BS (MS name for old bug) to headlines." I spoke to one author about it and challenged him for floating these "Heartbleed" logos and brands yet again. To us it seems quite evident that Microsoft keeps attacking Free software and GNU/Linux like no time before; it's just more subtle and hidden in more sophisticated ways. The person who heads the incognito firm that's known only for the "Heartbleed" brand (they control the brand) came from Microsoft (he was head of security there) and also from the FBI, whose stance on encryption is widely known by now; they actively seek to break security of software, so knowing about the 2-year-old OpenSSL bug would make sense. Some reputable media reports said that the NSA had known about this bug for about a year before it was known to the public and the NSA cooperates with the FBI on breaking software security, sharing personal (illegally intercepted) data, etc.

Anyway, the same publication (as above) also floated the "Heartbleed" nonsense in another article today. Would they do just about anything to keep it in headlines? Even a year later? They are now citing some firm called Venafi (never heard of it before), which basically relies on misleading misuse of statistics. It's FUD from a company that tries to make money from perceived dangers and accentuates these dangers in an effort to acquire clients. What kind of 'journalism' is this? incidentally, Black Duck is now joining the list of such parasitic companies, with new hires and multiple press releases, so clearly it's a growth area and the Microsoft link is easy to see. It is FUD season again this spring as more publications now float this whole nonsense. This is hardly journalism, it's just throwback.

Thankfully enough, Red Hat demonstrates what "branding" of FOSS bugs practically means, even using the image above. There is no correlation between the naming of bugs and their severity, but press coverage sure loves a good brand. This is an important (albeit belated) response from Red Hat to "branding" of a FOSS bug by Microsoft-linked firms like the one behind "Heartbleed".

"It’s been almost a year since the OpenSSL Heartbleed vulnerability," says Red Hat, "a flaw which started a trend of the branded vulnerability, changing the way security vulnerabilities affecting open-source software are being reported and perceived. Vulnerabilities are found and fixed all the time, and just because a vulnerability gets a name and a fancy logo doesn’t mean it is of real risk to users."

Well, Microsoft folks sure squeezed everything they could from this bug, seeking to discredit not just OpenSSL but the whole development process of Free software (due to just one small bug, or a few lines of code). And Microsoft still pretends that it is warming up to Open Source? Who are these frauds kidding?

There's a lot of companies which continue to use platforms with back doors, such as Windows, but the Wintel-oriented media would rather we just obsess over this one bug from one year ago (which was patched as soon as it became publicly-known).

We are rather disappointed to see a decent journalist like Sean Michael Kerner, along with colleagues at eWEEK, swallowing the bait and serving to promote the misleading claims to advertise this company that controls the "Heartbleed" brand, among other opportunists (like fish swimming around a shark for some leftovers). Microsoft must be laughing quite hard seeing all that media manipulation.

Recent Techrights' Posts

The General Public License (GPL) Inspired the Web's Original Openness/Freedom, According to Tim Berners-Lee
"During the preceding year I had been trying to get CERN to release the intellectual property rights to the Web code under the General Public License (GPL) so that others could use it."
The Real Problem With Rust is Not "Wokeness" (It Never Was)
Don't feed the trolls who attack "Rust People" on political grounds
 
New Drone Footage Shows IBM is Dead (Parts of It)
The people who participated in IBM when IBM actually mattered probably have boasting rights, unlike people who work for IBM today
Michael Larabel Adds Slop Category to Phoronix, Quickly Realises That It's Worthless
Phoronix nowadays gets carried away; it made a new category to talk about slop and it decided to call it "intelligence" with some caricature of a brain (that's misleading)Phoronix nowadays gets carried away; it made a new category to talk about slop and it decided to call it "intelligence" with some caricature of a brain (that's misleading)
IBM: We Can't Make 'AI' (Voice Recognition) Do the Work of a McDonald's Teenager, So Let's Try the Same on Saudi Planes
IBM is lost. It's truly lost.
After 35 Years the World Wide Web, HTML, and HTTP Are Proprietary
HTTP/2 added a lot of complexity (it's just a Google protocol, based on SPDY originally), many image formats are proprietary and patented, HTML got 'replaced' by Java-Scripts [sic], and many URLs (the URL system was created in the early 90s) are just long strings for proprietary 'webapps'
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, December 20, 2025
IRC logs for Saturday, December 20, 2025
The Register MS Has Lowered Its Standards Considerably
Incidentally, we've only just noticed that "US editor for The Register since July 2025" has not been active for 4 weeks already
Scamfarms, Spamfarms, and Slopfarms in "Linux" Clothing
Today, Linux searches in Google News produced no slop at all. That's an improvement.
Did Bill Gates Lobby to Blur the Face of the Young Woman He Openly Braces (and Who Isn't His Wife)?
"This photo of of Microsoft co-founder Bill Gates with a woman whose face is blurred out is just one of 68 more photos and documents released today."
Links 20/12/2025: Microsoft Ruins Televisions, 'Epstein Files' Deeply Sanitised (to Protect Particular Culprits)
Links for the day
Gemini Links 20/12/2025: Merry Christmas 2025 and Running a Factorio Headless Server on FreeBSD with the Linuxulato
Links for the day
With 10 Days Left, the Free Software Foundation (FSF) Has Already Raised Close to $300,000 This Winter
they're besieged by despicable corporations and very despicable people
2025 in Numbers
What was very good about this year is that we truly got "into the rhythm" of publishing
More Microsoft Layoffs Coming Soon
When I spoke about Microsoft layoffs (routinely) I got very viciously attacked by Microsoft boosters
My Humble Assessment of the Future of Red Hat, A Company That IBM is Flushing Down the Loo
GNU/Linux will be OK without Red Hat, but shaping the future of it matters because we don't want companies like Valve (DRM) to set the agenda
Probably the Least Useful Gadgets, Ever
as if a "smart" thing worn on the wrist is the "new Rolex"
Former Manager at IBM Research (Yorktown) Says Why IBM is Doomed and the Anonymous Tipline (Speak Up) is a Trap
IBM isn't willing to change or to address internal issues
Links 20/12/2025: Fentanylware Becomes CheeTok and "Why Roomba Died"
Links for the day
Linux Foundation: Richard Stallman Developed Only a Software Licence
We already criticised this report several times last night
Impulsive Writing, Quotas, and Keeping Things as Concise as Feasible
A 10-word sentence being read by a million people can have the same impact or magnitude (exposure-wise) as a million-word book being read by just 10 people
Gemini Links 20/12/2025: Christmas Songs, Storms, and Old Web
Links for the day
Coming to Grips With a Lack of Future at IBM
Red Hat's future doesn't look bright under the auspices as they seem right now
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, December 19, 2025
IRC logs for Friday, December 19, 2025
Links 20/12/2025: Media Layoffs, a Third of Online Traffic is Bots
Links for the day
Barbados: Significant Gains for GNU/Linux
over 5% if one counts ChromeOS as well
Very Shallow LLM Slop for IBM Disguised as Journalism About a "Plan to Train 5 Million Learners in India by 2030" (Unverified Figures With Very Distant Future Date/Year)
The Web has become somewhat of a laughing stock
'Linux' Foundation: The Foundation Has Almost Nothing to Do With Linux, It Just Misuses the Name "Linux"
Only a tiny portion of the Foundation's budget actually goes to Linux
Austria vs GAFAM
another win against GAFAM
Microsoft Has Purchased Another Linux Foundation Seat
From the latest (new) report
No Electronics, No Clocks, No Phones
We're meant to think that more gadgets will make life easier
Gemini Links 19/12/2025: Great Website Rebuild of 2025 and Running OpenBSD in a Hostile Environment
Links for the day
Google News Helps Slopfarms (What's Left of Them)
Lately we've noticed that nothing in the RSS feeds we follow is burping out slop
Links 19/12/2025: Privacy International's Reports and Russian Assets in EU
Links for the day
Today, The Register MS is Parroting Marketing Spam for Ponzi Scheme ("AI") in Exchange for Money
The Register MS should be held accountable when the bubble pops
Red Hat Senior Engineering Manager Leaves (or Gets Pushed Out by IBM) After Nearly 20 Years at the Company
The recent massive wave of IBM layoffs impacted Red Hat and so will the next (impending, Q1) wave
Why We Got Told by Insiders That Almost Everyone at EPO Reads Techrights and Many at IBM Track IBM RAs Via Techrights
In a nutshell, we cover topics almost no other site dares touch
IBM Research Shutting Down Labs, Lots of Workers Laid Off (Even Days Before Christmas in Devout Catholic Country)
Heartless, soulless company
Links 19/12/2025: Windows TCO in NHS, "Locked Out of Apple Account Due to Gift Card"
Links for the day
Nearly Three Months Have Passed Since EPO Cocainegate and the EPO's Management Still Refuses to Talk About It
But it's clearly aware of it
Richard Stallman Explains Why Software Patents Are Really Bad and Very Much Unnecessary
"The relationship between patents and products varies between the fields"
The Copycats of the FSF Have Serious Problems
If you care about Software Freedom, then support the real thing
Once Again, Just in Time for Christmas, UEFI and Its Boot System Turn Out to be a Giant Bug Door (Also a Microsoft Remote Kill Switch)
This industry - even academia - has been deeply compromised
In Activism and Journalism, If You're Ineffective They Ignore You, When You Become Effective They Stalk and Harass You, Failing That They Threaten You
"the Wikileaks effect"
Google Has Begun Linking to commandlinux.com in Google News, But It Seems to be a Slopfarm
This is not innovation, it's sloppiness, laziness, and a modern form of plagiarism
Microsoft Reportedly Tries to Cause Top-Level Managers to Resign If they Don't Participate in the Ponzi Scheme
Apparently even executives who don't play along are given marching orders
Microsoft, Over 120 Billion Dollars in Debt, Prepares Next Round of Mass Layoffs (After Christmas)
Microsoft is not managing to pay back its debt
Links 19/12/2025: Scam Altman Humiliates Self in Public, Climate Alarm Sounded, Egyptian Economist Convicted Over "Social Control Media Posts Critical of the Government"
Links for the day
You Can Get Work Done With Lean Software
obviously!
"The War on Privacy" is Real
"He Built a Privacy Tool. Now He’s Going to Prison."
The Cost of Being Influential
The "tech world" and its monopoly enforcer (patent system) are sleepwalking into autocracy
More Shutdowns and Layoffs at IBM
if someone covers correct but suppressed information, then people will make an effort to find it
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, December 18, 2025
IRC logs for Thursday, December 18, 2025
EPO Violates Laws to Profit More From Invalid Patents, Then Cuts the Budget Allocated to Staff
taking away what was already promised to staff
Only a Few Examples of LLM Slop Found, Mostly via Google News
Is it fair to say that sites learned LLM slop does not offer any real value?