Bonum Certa Men Certa

Beware the Distortion of Terms Like 'Supply Chain', 'Zero Day', and 'Back Door' (New FUD Patterns Against Free Software, a Distraction From the Real Culprits)

Proprietary software is being protected by 'googlebombing' tactics; the biggest weaknesses of proprietary software are being spun as a key problem with "Open Source" and proprietary software's shortcomings are being blamed on the alternative to it

Linux Foundation: repeat what Microsoft says



Summary: Microsofters spread misinformation/disinformation about Free software and security thereof; the corruption (bribery) of organisations such as the so-called 'Linux' Foundation means that Microsoft's misinformation/disinformation now comes out of the mouths of the supposed opposition, too

THE Daily Links in this site habitually add some "Ed"(itorial) comments to highlight FUD (Fear, Uncertainty, Doubt/fear-mongering) and offer some quick response to it. How much can publishers lie for the likes of Microsoft or VMware before those publishers perish due to a lack of credibility and, in turn, a lack of audience?



Earlier today we posted some more examples of this kind in Daily Links. Not a day goes by without several such 'incidents' (misinformation/disinformation).

"The real "supply chain" trouble is Microsoft and proprietary software..."In this post we highlight 3 recent patterns we've noticed. They are semantic lies.

Recently, a Microsoft front group called "Linux Foundation" kept using terms like "supply chain". Years ago nobody used this term in relation to Free software and then Microsoft bought a lot of the so-called 'supply chain', in the form of GitHub and then NPM. Would anyone trust the integrity of code and binaries from a platform controlled by Microsoft and the NSA, whose CSO is a decades-long NSA veteran?

The real "supply chain" trouble is Microsoft and proprietary software; you can't audit what you're getting and it might be intentionally back-doored, taking advantage of this opacity. So why pretend this is a "FOSS" issue?

"If something was fixed or was already patched upstream before disclosure, then it is not a 0-day."Speaking of back-doored code or executables, "backdoor" means not a backdoor anymore. Microsoft-controlled media distorted the term and kept mentioning it in false contexts. Nowadays it just means a server got compromised and then the person who took control of it installed some more stuff. But that's malware and it says nothing about how the malware got on the system in the first place (unless there was an actual back door).

Many would say that servers can be hijacked using critical and remotely-exploitable flaws, set aside bad passwords (those are typically a human failure). But that leads us to the distortion of the definition of "zero day" (or 0-day). If something was fixed or was already patched upstream before disclosure, then it is not a 0-day. If it starts getting exploited the moment it is disclosed, then it's a "1-day". But looking around the Web today, we found several examples of lies to that effect. The media keeps badmouthing Zimbra, but this seems to be a way to distract from several critical Microsoft flaws, including those affecting Exchange. Those are actively being exploited, according to a very recent report. the Zimbra issue is old news (about a month old) and servers have already been patched by responsible administrators, such as my colleagues. Although it seems like the Zimbra hole might be a new one, the last patch partly addresses it. Do not forget that CISA released a list with three Microsoft holes that are actively exploited, including in Exchange, so why shift/divert to talking about Zimbra rather than Exchange? Are they trying to reinforce some false perception that moving away from Exchange would mean equally bad or even worse security?

"The scenario, as per Dan Goodin et al (even sued for defamation already, for utterly poor reporting on security), is nowhere as grim as the Microsoft Exchange situation."What's bothersome here is the repeated distortion of the term "zero day". An associate told us that "'they' must be really worried about the advance of FOSS to spread so much dated FUD about Zimbra and other projects. One giveaway is the use of the marketing phrase "zero-day". That used to mean an exploit that was in active use before the vendor admitted to it existing. Now it just means bug with an exploit."

The scenario, as per Dan Goodin et al (even sued for defamation already, for utterly poor reporting on security), is nowhere as grim as the Microsoft Exchange situation. We already saw that Microsoft goes on for months and months without patching known Exchange flaws, even when it is fully informed that such flaws are actively being exploited already.

Zimbra does E-mail, so that helps distract from what Microsoft is doing, with the real zero days, the real back doors, and the real supply chain crisis. Microsoft monopolises this chain (it's proprietary) and refuses to fix it, leaving the victims helpless. This must be intentional. Or as out associate put it, "paid-for back doors on behalf of those that pay enough, or more specifically bug doors. Those are exploitable bugs about which the payers are informed long in advance of Microsoft getting around to patching them."

"Zimbra does E-mail, so that helps distract from what Microsoft is doing, with the real zero days, the real back doors, and the real supply chain crisis."It's the Windows [sic] of opportunity... Edward Snowden has already provided ample evidence of this. Microsoft keeps giving the NSA and FBI enough time to install a RAT or bootkit before the patches get deployed (too late). "And the FSB and just about any similar agency in all the other Internet-connected countries in the world," our associate noted.

So we're meant to think that the real crisis is Free software and Microsoft lobbyists then push for new, discriminatory laws that stigmatise "Open Source". New zero-day in Microsoft products? Unpatched for months while exploits circulate for months? So the Microsoft shills focus on the something that is "open source"... and repeat endlessly the terms which aren't even applicable to it.

"CISA is a Microsoft reseller working out of the DHS offices," our associated concluded, "which itself is a fraud."

Recent Techrights' Posts

Links 20/04/2026: Chatbots Motivate Manslaughter, GAFAM’s ‘Tobacco Moment’
Links for the day
The Corrupt Lecture the Non-Corrupt - Part II - It's About Politics, Not Science
Tomorrow we'll discuss what the cocaine proponents (or apologists) deem to be "ethics"
SLAPP Censorship - Part 52 Out of 200: Phil Golding Appointed Bar Standards Board (BSB) Chief, Misogyny Must End
How many rules will they "bend" or even breach?
 
FOSS Linux (fosslinux.com) Has Become a Slopfarm
Slopfarming is the last incarnation of sites that die or are dead
Gemini Links 21/04/2026: NeoVim, GeminiMDB, and Another New Gemini Client (Called Titan II)
Links for the day
Links 21/04/2026: Internet Shutdowns, Bluesky Crippled by DDoS Attack
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, April 20, 2026
IRC logs for Monday, April 20, 2026
3,400 Gemini Capsules Accessible and Known to Lupa, A Geminispace Crawler
We're about to exceed 3,400 some time soon
When and Why I Quit Writing "Classical" GNU/Linux Advocacy Articles
I'd love to write more about why GNU/Linux is great [...] We always try to cover unique issues and break stories (exclusives)
IBM Had Mass Layoffs Every Month This Year (Including at HashiCorp, Confluent, and Red Hat), 'Results' Due in 2 Days' Time
IBM's "media partners" seem to be engaging (propaganda and puff piece) ahead of the serenade to Wall Street
Dr. Andy Farnell on Privacy Failings and Shallow Media Coverage
Bad media paves the way for failed societies
Gemini Links 20/04/2026: Fahrenheit 451, Small Web Advocacy, and Offgrid Holdout
Links for the day
Debian Has a New Project Leader (DPL)
We plan to upgrade Debian some time this month
This Morning The Register MS Published SPAM With "AI" 36 Times in It. This is What The Register MS is Paid to Publish.
It's selling out to Ponzi schemers
Throwing Rocks in Houses of Glass
Lots of "virtue-signalling" against ICE
Links 20/04/2026: Brave Origin Nightly, Scuttling USAID Gives 'Soft Power' to China, and White House Gives Money to Russia (Through Oil Sales)
Links for the day
EPO Cocainegate Escalates - Part II - "Cocaine Communication Manager" Luis Berenguer is Back Without Punishment
Latest on Luis Berenguer
Gemini Links 20/04/2026: "I Hate Computers" and "Why I de-Googled"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, April 19, 2026
IRC logs for Sunday, April 19, 2026
If You're Against War, Why Would You Pay IBM Red Hat?
Red Hat's largest clients aren't geeks; they're militaries
Uplifting Mood in Manchester
Looking behind - and ahead - after a day of relaxation
SLAPP Censorship - Part 51 Out of 200: On Perjury and What It Means to Take Third-Party Funding to Attack Reporter and His Family (in Another Continent)
threats of prison sent to my wife
The Corrupt Lecture the Non-Corrupt - Part I - EPO Management Talks About "Ethics" While Cocaine Users Run the Office
Let's start with the basics
EPO Cocainegate Escalates - Part I - Cocaine Abuse in Family of Campinos (President’s Office)
at the EPO's management you can do illegal drugs and still represent Europe's second-largest institution
Gemini Links 19/04/2026: Big Brother and the Telescreen, Syncing Gemini Capsule With a Makefile
Links for the day
Links 19/04/2026: Introducing “Fighting Fascism” Podcast and Kyiv Mass Shooting
Links for the day
Links 19/04/2026: Mass Layoffs at GAFAM Again (10% Laid Off), Azure Capacity Problems (Enshittification)
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, April 18, 2026
IRC logs for Saturday, April 18, 2026