EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

08.08.08

Another Reason to Avoid Mono: Security

Posted in GNU/Linux, Microsoft, Mono, Novell, Security, Windows at 5:27 pm by Dr. Roy Schestowitz

“At Microsoft I learned the truth about ActiveX and COM and I got very interested in it inmediately [sic].”

Miguel de Icaza

For reasons and factors that make OOXML not secure, Mono is a security hazard as well. For those who are not yet convinced, there is this brand-new article which highlights the architectural failures of .NET and their impact on security. Read it.

Two security researchers have developed a new technique that essentially bypasses all of the memory protection safeguards in the Windows Vista operating system, an advance that many in the security community say will have far-reaching implications not only for Microsoft, but also on how the entire technology industry thinks about attacks.

Also in the news today is this alarming issue of 7 “critical” flaws (the highest level of severity) in Microsoft software.

Does anyone want GNU/Linux to inherit this nightmare? Is this something which belongs in the operating system which NASA, the NSA and the Department of Defense use? What about the cost implications? Beyond the issue of acquisition cost also exist the costs of maintenance, repair, and damage control. Losses incurred by leaks (espionage) and data loss are sometimes invaluable.

A few hours ago, one reader sent us the following message regarding the consequences of poor security.


Note that the bad engineering promoted by Bill Gates and his movement is probably costing Joe Sixpack upwards of 8 hours lost effort per week from malware, instability and poor interoperability. With the US in the economic situation it is in, that may be enough to knock the floor out of the recession. The failure that is Microsoft Vista may be the last straw and take down what’s left of the economy.

“The failure that is Microsoft Vista may be the last straw and take down what’s left of the economy.”Until recently, Microsoft people have been able to stifle security information. However, the EFF’s recent win paves the way forward for better technology to become more visible.

I look forward to the seeing Back-To-School Security Packets in Walmart, Best Buy, and others consisting of Xubuntu CDs.

The last 10 years have shown us nothing if not that FOSS helps make your business more recession-proof.

What we have here is an old and odd spin trotted out yet another time. The spin tries to be negative, but at the end of the day, use of FOSS has boosted the economy there by some $60 billion on unnecessary sunk costs.

Further, since were FOSS tends to lead, it leads due to better performance, quality, interoperability and maintenance, not just cost. So that leads to secondary and tertiary savings. After all, if the IT team is not having to spend all its time chasing fires, it can be far more than $60 billion in savings once the total cost of ownership is settled.

Sure a small wedge of the software sellers might have lost, but the large part of the pie consists of software users. We win here.

____
1) “EFF Wins Protection for Security Researchers” (2007)

2) “Vista’s Security Rendered Completely Useless by New Exploit” (2008)
“… a technique that can be used to bypass all memory
protection safeguards that Microsoft built into Windows
Vista…”
“… the work is a major breakthrough and there is very little
that Microsoft can do to fix the problems…”

3) “This Bug Man Is a Pest” (2008)
“…His syllabus is partly a veiled attack on McAfee,
Symantec and their ilk, whose $100 consumer products he
sees as mostly useless. If college students can beat
these antivirus programs, he argues, what good are they
for the people and businesses spending nearly $5 billion
a year on them? …”

4) “USENIX WOOT07, Exploiting Concurrency Vulnerabilities in System Call Wrappers, and the Evil Genius” (2007)


For those wondering about highly-restrained criticism of Microsoft/Windows security, a mandatory background would be the smear campaigns against security researchers. Smear campaigns are something that Microsoft is intimately familiar with [1, 2, 3, 4, 5, 6, 7, 8, 9]. Remember the Geer saga, too [1, 2] (little more in [1, 2, 3]). He lost his job for saying the truth about Microsoft’s security shortcomings and the horrific state of the Web, caused largely by Microsoft and its back doors.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. The Media Starts Informing the European Public About the Downsides of UPC While EPO Accelerates Its Lobbying for Ratification

    The EPO's shameless UPC promotion takes another step forward as the European press outlets (even television channels) begin to explore the secret deal that's negotiated by patent lawyers (with corporate clients) and patent offices, not the public or any public interest groups



  2. Some Details About How the EPO's President is Rumoured to be 'Buying' Votes and Why It's Grounds/Basis for “Immediate Dismissal”

    Some background information and a detailed explanation of the systemic financial dependency, created by Battistelli at the cost of €13 million or more, which prevents effective oversight of Battistelli



  3. How the Patent Lawyers' Microcosm Continues to Boost Software Patents Filth by Misdirecting Readers, Relying on Highly Selective Coverage

    nder the guise of reporting/analysis/advice the community of patent lawyers is effectively lobbying to make software patents popular and widely-accepted again, based on one single case which they wish to make 'the' precedent



  4. Documents Show Zagreb Police Department in Investigation of Vice-President of the European Patent Office

    Željko Topić's troubles in Croatia, where he faces many criminal charges, may soon become an extraordinary burden for the EPO, which distances itself from it all mostly by attacking staff that 'dares' to bring up the subject



  5. [ES] Interrumpiendo la Propagánda Distractante de Battistelli: los Empleados de la EPO Protestará de Nuevo en una Quincena

    La exágerada extravagancia (desperdicio de dinero) en la Ceremonia de Premiación al Inventor Europeo de la EPO tendrá que competir por atención de los medios con miles de empleados de la EPO (en todaslas sedes de la EPO) marchándo en las calles para protestar por los abusos de la EPO



  6. Windows and Microsoft's Other 'Burning Platforms'

    It's not just Windows for phones that's reaching minuscule market share levels but also Windows, but Microsoft is skilled at hiding this (cannibalising Windows using something people do not even want, then counting that cannibal, Vista 10)



  7. Links 24/5/2016: CRYENGINE Source Code is Out on GitHub, Jono Bacon Leaves GitHub

    Links for the day



  8. Links 23/5/2016: GNOME 3.22, Calculate Linux 15.17

    Links for the day



  9. 'Celebrity' Patent Trolls and the Elusive Battle Against Patent Trolls (or Eastern District of Texas Courts) Rather Than Software Patents

    Some of last week's more important reports, which serve to demonstrate how the system is attempting to tackle a side-effect of software patents rather than the patents themselves (their irrational scope)



  10. The Circus of Patent 'Reporting' (by Omission) on the Subject of Software Patents in the US and USPTO Bias

    look at some of the latest oddities in the US patent system and much of the reporting about software patenting (more or less monopolised by those who profit from it, not harmed by it)



  11. IP3 Demonstrates That Today's Patent Systems Devolve Into a Conglomerates' Game, Won't Protect the Mythical Small Inventor

    Multinational corporations bring together their shared interests and steer the increasingly-inseparable patent systems according to their needs and goals, but has anyone even noticed?



  12. Disrupting Battistelli's Distracting Propaganda: EPO Staff to Protest Again in About a Fortnight

    The overly extravagant (waste of money) EPO European Inventor Award will have to compete for media attention with thousands of EPO staff (in all EPO sites) marching in the streets to protest against the EPO's abuses



  13. Corrupting Democracy? Growing Frequency of Rumours That the EPO's President Battistelli is 'Buying' Votes of Small Member States

    Several sources suggest that rather than appease the Administrative Council by taking corrective action Battistelli and his notorious 'circle' now work hard to remove opposition from the Administrative Council, especially where this is easier a task to accomplish (politically or economically)



  14. [ES] Los Mitos de la EPO ‘Calidad’ de Patentes y de ‘Creación’ de Patentes: Basados en Ventas de Cafe y Trauma

    La carrera hacia el fondo, o la ridícula asumpción de Battistelli de que otorgar más y más patentenes más rápidamente (e.g. usando PACE) sería beneficióso a largo término, puede guíar al final colapse del valor de la EPO y la pérdida de su lárgamente ganada reputación a nivel mundial



  15. Links 22/5/2016: Systemd 230, Debian Installer Alpha 6

    Links for the day



  16. EPO Patent 'Quality' and 'Patent Creation' Myth: Capsule-Based Coffee Sales and Trauma

    The race to the bottom, or Battistelli's ludicrous assumption that granting more and more patents faster (e.g. using PACE) would be beneficial in the long run, may lead to the ultimate collapse of the EPO's value and demise of its long-earned reputation worldwide



  17. Guest Post: How Vista 10 Imposes Itself on Users of Windows

    A reader's experience being nagged by Microsoft, as documented and explained by this reader



  18. [ES] El Notorio Tirano de la EPO, Benoît Battistelli, Se Reune Con Otros Tiranos, Reportes de Que ‘Limpia’ el Consejo Administrativo

    El régimen de Battistelli, talvez la fuente de verguénza más grande, alegadamente está “cortejándo países pequeños/corruptos para asegurárse de que los delegados que votarón contra él serán remplazados”



  19. [ES] Comentadores Anónimos Debaten Si la EPO de Battistelli Puede Revocar las Pensiones de Empleados Que Se Atreveen — GASP — a Buscar Empleo Alternativo

    Una mirada a las causas de desesperación e imensa presión en la EPO, donde las pensiónes pueden ser cortadas como medio de represália y la gente puede ser negada empleo aún después de dejar la Oficina Europea de Patentes (EPO)



  20. [ES] Otra Casi Vacía Presentación de la EPO en La Hague

    El propagandístico “estudio social” de Battistelli (básicamente un montón de engañosas afirmacionesdisfrazadas como ‘investigación’) ayuda a demostrar que los empleados de la EPO no tiene absolutamente fe en la gerencia



  21. Links 21/5/2016: Manjaro Linux RC, Flock 2016 Schedule

    Links for the day



  22. USPTO Ignores a Lot of Cases Against Software Patents to Justify Resumption of More Software Patenting

    The US patent system (USPTO) is so obsessed with granting as many patents as possible -- even bogus patents in areas that are no longer patent-eligible -- that its guidelines are further perturbed and whose appeals board is massively overwhelmed/overworked/understaffed



  23. Notorious EPO Tyrant, Benoît Battistelli, Meets Other Tyrants, Reportedly 'Cleanses' the Administrative Council

    The Battistelli regime, perhaps the biggest embarrassment of Europe right now, is allegedly "courting smaller countries to make sure the delegates who voted against him will be replaced"



  24. Links 20/5/2016: Purism Tablet, ChromeOS PCs Outsell 'Mac'-Branded PCs

    Links for the day



  25. CAFC Rules Against Software Patents But Witness With Horror the Silence From Patent Lawyers (Bias by Omission)

    In an effort to protect software patents in the United States, where these patents came from in the first place (and continue to spread from), patent lawyers pretend not to see cases where software patents get invalidated and instead focus on the rare exception



  26. It's All Just Artificial Distractions From EPO Management, 'Yellow' Union Comes Under Scrutiny Again

    What's happening inside the EPO these days and what meaningless rubbish the management of the EPO would rather have the media obsessed with



  27. Anonymous Commenters Debate Whether Battistelli's EPO Can Revoke Pensions of Dismissed Employees Who Dare -- GASP -- Find Alternative Employment

    A look at causes for desperation and immense pressure at the EPO, where pensions can be cut as means of reprisal and people can be denied employment even after they leave the European Patent Office (EPO)



  28. Australian Productivity Commission's Research Calls for Ban on Software Patents, Davies Collison Cave Calls for Complaints Against This Finding

    As the push against software patents grows in Australia, much to the chagrin of Australian software developers, Davies Collison Cave (patent law firm) publicly calls for opposition, calling its side "the truth" and pretending it represents "Australian innovators."



  29. Links 19/5/2016: Wine-Staging 1.9.10, Android N

    Links for the day



  30. Another Almost Empty EPO Presentation at The Hague

    The propagandistic "social study" of Battistelli (basically a lot of misleading claims disguised as 'research') helps demonstrate that EPO staff has absolutely no faith in the management


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts