EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

11.19.08

Liability for Software When Life is at Stake

Posted in Europe, Law, Microsoft, Security, UNIX, Windows at 9:48 am by Dr. Roy Schestowitz

A few months ago we used the London Stock Exchange (LSE) as an example of hugely costly Microsoft failures. The stock market crashed in the technical sense and Microsoft, along with those who are informed or responsible, dodged questions about the problem, which recurs once in several months. That was about money, but this time around it’s about people’s welfare, health, and even lives.

With roughly 320,000,000 zombie PCs out there, how can any sane person put Windows in mission-critical settings like a hospital? Well, that’s just what some people do. They apparently learned nothing from a hospital near Microsoft Corporation turning into a massive botnet and it’s happening again, this time in London. Yesterday’s reports indicate that 3 hospitals were shut down due to Windows virus infections:

BBC: Computer virus affects hospitals

Three London hospitals have been forced to shut down their entire computer systems for at least 24 hours after being hit by a virus.

The Register: PC virus forces three London hospitals into computer shutdown

Three London Hospitals shut down their computer systems on Tuesday in response to a computer virus infection.

[...]

The infection at Barts and London Trust was reportedly caused by the Mytob worm, which contains built-in spyware functionality. Mytob spreads by email and has the ability to plant backdoor software on compromised Windows PCs.

Database leaks are only natural to expect. This means that any person’s personal information and health record can make its way into a hot BitTorrent within hours. It’s wonderful, is it not?

“This means that any person’s personal information and health record can make its way into a hot BitTorrent within hours.”We have already produced and provided some evidence to show that Windows is insecure by design and probably irreparable. Unless it’s overhauled radically or reimplemented from scratch, it can never benefit from several decades of UNIX doctrine, mostly trials and errors which made a robust, scientifically-backed model.

With Microsoft whistleblowers crying foul about critical failures and then getting sacked, one can’t help wondering how Microsoft perceives liability. Appended below are several fairly recent articles about liability, bad software, dangers in healthcare, and questionable EULAs.

For information about the NHS and Microsoft, see this page (to avoid needlessly repeating old references).

_____
[1] Experts are calling for product liability for software

“Product liability does not apply to software,” Gerald Spindler of the Faculty of Law of the University of Göttingen complained. “But what if a whole company comes to a standstill due to faulty software?” he mused.

[2] “Microsoft’s 10Q Risk Factors Lists Conceivable Liability for Data Leaks

Improper disclosure of personal data could result in liability and harm our reputation. We store and process significant amounts of personally identifiable information. It is possible that our security controls over personal data, our training of employees and vendors on data security, and other practices we follow may not prevent the improper disclosure of personally identifiable information. Such disclosure could harm our reputation and subject us to liability under laws that protect personal data, resulting in increased costs or loss of revenue. Our software products also enable our customers to store and process personal data. Perceptions that our products do not adequately protect the privacy of personal information could inhibit sales of our products.

[3] Linux guru argues against security liability

Alan Cox, one of the leading Linux kernel developers, has told a House of Lords hearing that neither open- nor closed-source developers should be liable for the security of the code they write.

[4] New banking code cracks down on out-of-date software

The banking industry has re-affirmed a policy that makes online banking customers responsible for losses if they have out of date anti-virus or anti-phishing protection. New Banking Codes for consumers and businesses took effect on Monday.

[5] Secure web browsing through Live Linux distros

Banking isn’t the be-all and end-all: there’s many other reasons you’d want a secure system, separate from what’s on the hard disk, besides Internet banking. Traveller’s can’t necessarily trust the integrity of a computer in an Internet cafe.

[6] Online banking fraud ‘up 8,000%’

The UK has seen an 8,000% increase in fake internet banking scams in the past two years, the government’s financial watchdog has warned.

The Financial Services Authority (FSA) told peers it was “very concerned” about the growth in “phishing”.

[7] Swedish bank hit by ‘biggest ever’ online heist

Haxdoor typically installs keyloggers to record keystrokes, and hides itself using a rootkit. The payload of the .ki variant of the Trojan was activated when users attempted to log in to the Nordea online banking site. According to the bank, users were redirected to a false home page, where they entered important log-in information, including log-in numbers.

[8] Microsoft confirms OneCare zaps Outlook, Outlook Express e-mail

Microsoft Corp. has acknowledged that a bug in its Windows Live OneCare security suite has been causing users’ e-mail to vanish from Outlook and Outlook Express.

[9] In zombies we trust

A little over a year ago, I wrote an editorial where in back-of-the-envelope style (.pdf) I estimated that perhaps 15-30% of all privately owned computers were no longer under the sole control of their owner. In the intervening months, I received a certain amount of hate mail but in those intervening months Vint Cert guessed 20-40%, Microsoft said 2/3rds, and IDC suggested 3/4ths. It is thus a conservative risk position to assume that any random counterparty stands a fair chance of being already compromised.

[10] Your data or your life

As unlikely and alarmist as this sounds, it could really happen. Intracare is the publisher of a popular practice management system called Dr. Notes. When some doctors balked at a drastic increase in their annual software lease, they were cut off from accessing their own patients? information.

This situation is completely unconscionable. There can be no truly open doctor-patient relationship when an unrelated third party is the de facto owner of and gatekeeper to all related data.

[11] Use Health Vault, Lose Your Rights

Microsoft has announced (NY Times Article) Health Vault. What should have followed here is a review of the service by my actually trying it.

[...]

Heard enough? So had I. I’m absolutely going to pass on Health Vault. In addition to looking like the Microsoft Passport debacle redux, this is a very one-sided contract. They can harm you but you cannot harm them. There is no way for any 3rd party to verify that their privacy and security software works.

[12] Microsoft Healthvault Patient Safety in Question

One topic I’ve not seen addressed is the safety and effectiveness of the data within HV – and I don’t mean “safety” as in the data is secure from unauthorized access or misuse. I mean “safety” as in the utilization of data stored in HV by other applications won’t result in an unsatisfactory patient outcome, you know, like death or injury.

[13] HealthVault: No Commitments and a Sleeping Watchdog.

Has Microsoft committed to keeping the promises that it has already made? No, just the opposite. Their privacy policy concludes:“We may occasionally update this privacy statement”

Which means that when the commitments that Microsoft has made regarding HealthVault become inconvenient, they will simply change them.

[14] HealthVault: Failing the seven generations test

…My mother died of ovarian cancer. My grandmother took a drug while my mother was in utero that increase the chances that my mother would get ovarian cancer. Any consideration given to my mothers genetic propensity to get cancer must take into account this environmental influence…My grandmothers medical record will remain relevant for at least five generations…How long should we be keeping our electronic medical records? We should ensure that they are available for the next seven generations…A private, for-profit, corporation is an inappropriate storehouse for records that the next seven generations will need. Corporations do not last long enough. Consider the Dow Jones Industrial Average, of the original 12 companies that made up the index, only one is still listed…

[...]

But this is still Microsoft we are talking about, which all things being equal, is especially bad. Microsoft has a history of abusing standards, and using those abuses to enable and extend its monopolies. In short they have a history of “being evil” in exactly the sort of way that we cannot afford to have impact our healthcare records.

[15] Bill Gates: Vista is so secure it could run life support systems

While on a visit in Romania, where Bill Gates participated in the celebration of 10 years since the Microsoft branch has been running there, and the launch of Vista, Microsoft?s president declared that, with the right ammount of administration, the new Vista could run life support systems in hospitals.

[16] Do Microsoft’s EULAs have any real legal basis?

“Microsoft has no special exemption from the sale of goods act.” Well, no, probably not – but it might still be selling you “services” instead of “goods”. But the real point to remember is that it doesn’t matter a jot what the “logical” position is, it is what the courts decide that matters.

As far as I know, no one has tested Microsoft’s EULAs in a UK court and, until someone does, Microsoft will just go on assuming that they work. And I don’t fancy the risk of taking on Microsoft’s expensive lawyers in court myself…

[17] EULA La Vista, Baby

Well, I’ve taken a good look at the license agreement — I had insomnia — and I’ve discovered some clauses that will freeze your blood, curl your hair, and do your nails.

[18] Vista’s EULA Product Activation Worries

Mark Rasch looks at the license agreement for Windows Vista and how its product activation component, which can disable operation of the computer, may be like walking on thin ice.

[...]

“Does the Microsoft EULA adequately tell you what will happen if you don’t activate the product or if you can’t establish that it is genuine? Well, not exactly. It does tell you that some parts of the product won’t work – but it also ambiguously says that the product itself won’t work. Moreover, it allows Microsoft, through fine print in a generally unread and non negotiable agreement, to create an opportunity for economic extortion.”

[19] MSN Music Debacle Highlights EULA Dangers

MSN Music’s EULA is a case in point. When active, MSN Music’s webpage touted that customers could “choose their device and know its going to work”.

But when customers went to purchase songs, they were shown legalese that stated the download service and the content provided were sold without warrantee. In other words, Microsoft doesn’t promise you that the service or the music will work, or that you will always have access to music you bought. The flashy advertising promised your music, your way, but the fine print said, our way or the highway.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email
  • Google Bookmarks

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

3 Comments

  1. David Gerard said,

    November 19, 2008 at 9:58 am

    Gravatar

    I was particularly pleased to see in the Daily Telegraph report mention of the fact that this is a Windows virus. Every time there’s a press report of a computer virus outbreak that doesn’t mention this fact, I think there should be many letters written pointing out that there are no Mac or Linux viruses in the wild, despite repeated attempts at scaremongering by insecurity companies.

  2. Roy Schestowitz said,

    November 19, 2008 at 10:03 am

    Gravatar

    The BBC did not mention this. The Register did. It figures. ;-)

    Microsoft BBC

  3. Needs Sunlight said,

    November 20, 2008 at 9:18 am

    Gravatar

    It’s more than just the viruses that M$ is vulnerable to. The products just aren’t stable for mission critical use. When you look at the server and infrastructure products from M$ it’s even worse.

    Nowadays, pretty much every time I have contact with hospital information systems MS problems rear their ugly head. People I know have on multiple occasions not had their medical records available. Mostly this an annoyance and means they don’t get proper treatment. However, in a different situation, that could mean easily life or death. Hospital staff I interview *lose* over 10 hours per week to Windows-specific failures. That’s the functional equivalent of a > 20% downsizing in service…

    Top heads of departments, already with high workloads and high pressure, go without e-mail and rely on phone and fax. This is because instead of using a mail server (like simta, sendmail, postfix, etc) or collaborative software (like Zimbra, Kolab or Citadel) they use MS. Result? Critical messages lost or delayed.

    In worse cases even the phone is not a refuge. When MS products infect voice mail, replacing mature, stable technologies, then even the phone is not reliable. Again, a phone call, call forwarding and voice mail *are* serious matters of life and death in a hospital. Normally, Asterisk, Meridian, Definity or many other proven systems are used.

    When enough people lose kids, grandparents and elderly parents to lost messages, blocked phones, or unavailable or corrupted medical records, the damage will already have been done.

    Eventually Gates, Ballmer, Allichin, and the whole lot can be said to be party to manslaughter or similar. However, the real blame here and now lands on those making, actively or through inaction, the decision to allow M$ in the hospital.

What Else is New


  1. Links 5/7/2020: Slackel 7.3 Mate Beta and GNOME Gingerblue

    Links for the day



  2. Technological Progress? Only If We Assume The Wrong Things...

    When we're told that we're all dumb we're being given increasingly dumb technology (and they tell us dumber is better)



  3. Linux Foundation Still Owned and Controlled Largely -- and More Over Time -- by Surveillance Companies (Openwashing Services for Bad Practices and Bad Actors)

    The Linux Foundation‘s growing role in spying or the focus on data-mining operations is an eternal reminder or warning that the Foundation follows power and money, not freedom or ethics (it began as a salary-paying venture, crowdfunding among large corporations which conduct mass surveillance)



  4. Sharing is Caring, as Those Who Share Usually Care

    Going back to our human roots, people who cooperate and collaborate are vastly more likely to survive and thrive; Free software is almost guaranteed to become the norm when/once everyone demands it (proprietary software is too divisive, supremacist and even racist)



  5. Systems Can Crash and People Can Die by Changing Language (Even in Parameter and Function Space) to Appease Activists

    It seems clear that Intel takes the lead in trying to change Linux not in technical means but purely social means; even when (and where) that can compromise the robustness of the kernel (Intel is nowadays known for profoundly defective chips with back doors)



  6. António Campinos Should Speak to Peasants, Not Litigation Lawyers

    Mr. Campinos does not work for campinos but against campinos; he represents the people who sue or threaten them using ludicrous patents that should never have been granted (e.g. in Ethiopia)



  7. Christine Lambrecht (German Minister of Justice and Consumer Protection) Ignores the Fact That Even Patent Experts Reject the Unitary Patent (UPC)

    The debacle single-handedly caused by and attributable to Christine Lambrecht, who is eager to appease litigation lawyers, is made yet worse by the fact that people in this domain/profession reject what she's trying to ram down people's throats



  8. [Humour] The Linux Foundation is Not Even Using Linux

    The Linux Foundation does not support Linux except in name; it is important to remember that



  9. Microsoft Loves Power

    An explanation of why Microsoft says it loves this and that; Microsoft lacks the capacity to love or to express empathy as it's always about self gratification or coercion, nothing else



  10. IRC Proceedings: Saturday, July 04, 2020

    IRC logs for Saturday, July 04, 2020



  11. Indoors Society, Shut the Windows

    Times are changing in all sorts of ways; it seems like GNU/Linux and other Free/libre operating systems may emerge as winners when the 'dust settles'



  12. Allegation That Microsoft Adopted the Mentality of Suicide Bombers Against Linux, Leaks Reveal

    Looking at leaked E-mails from around the time Microsoft used Cyanogen as a 'proxy', we're finding some stunning admissions or speculation about the real motivations



  13. [Humour] A Union in Whose Interests?

    The union-busting 'yellow union' (the one that helped Benoît Battistelli marginalise SUEPO) is unable to represent staff any longer



  14. FFPE EPO Has Rendered Itself Obsolete by Liaising With Benoît Battistelli

    FFPE EPO has been left out of staff representation, demonstrating that liaising with the oppressor is a self-deprecating move which must be avoided (the only remaining potent union is SUEPO)



  15. Links 4/7/2020: LibreOffice 7.0 'Personal Edition', Atari VCS Coming Soon

    Links for the day



  16. [Humour/Meme] The 'New' Edge (Chrome Copycat) is Already Dead, So Microsoft is Trying to Just Kill the Competition

    Edge market share is so minuscule that it doesn’t even make it into this chart (it’s in “other”); no wonder Microsoft now bullies Windows users into using it, for users reject it even after months of endless advertising/AstroTurfing and aggressive exploitation/appropriation



  17. Fourth of July in the United Kingdom and the United States

    In these bizarre times Independence Day is still being celebrated, even as so many people are out of work, running out of hope and being fed xenophobia in social control media with a racist 'celebrity' president (the "user in chief")



  18. [Humour] Bigger is Always Better When You're a Deluded Maximalist

    The EPO totally lost sight of its mission; it's just speeding everything up, very carelessly, not minding quality and accuracy/certainty/legal validity



  19. 'Managing Intellectual Property' Managing to Become Uncritical Parrot of EPO Management

    Managing to amplify the EPO's lies isn't hard; one just needs to copy, paste, edit a little; then they call it 'journalism', irrespective of the proven track record of EPO management lying to staff and to the media



  20. IRC Proceedings: Friday, July 03, 2020

    IRC logs for Friday, July 03, 2020



  21. Monopoly Abuse, Still: Microsoft Pays Projects to Embrace/Move to C#, GitHub and Visual Studio

    Microsoft's greatest of efforts to lull regulators into inaction and fool us all into thinking that things have changed are undone by actual behaviour, which is abusive, anti-competitive and just... typical Microsoft



  22. Links 4/7/2020: Grml 2020.06 and diffoscope 150 Released

    Links for the day



  23. [Humour/Meme] Don't Let a COVID Crisis Go to Waste When You're Eager to Find Excuses for Many Layoffs and Shutdowns

    Microsoft business units that were defunct (long-failing, well before COVID-19) are being thrown out and Microsoft exploits a virus to rationalise these decisions while spicing up media coverage with "Hey Hi" (AI) and "virtual" experience or Facebook (to give the false impression that nothing really goes away)



  24. Free Software Tackles Political Issues. Political Tactics Are Also Being Weaponised Against Free Software.

    Divide-and-rule tactics seem to have been exploited to weaken collaborative work on Free/libre software; the response to these tactics needs to start with realisation that this is going on (even if it's done in a somewhat clandestine nature)



  25. Offence and Racism

    o those in positions of power and privilege (financial) you are controllable by guilt; dividing us and causing us to feel guilt and fear (over potential offence) is a powerful social control mechanism and pretext for dismissal, censorship, humiliation



  26. Links 3/7/2020: TrueNAS 12 Beta 1, Librem 13 Product Line

    Links for the day



  27. [Humour] European Patents Only Useful Outside the Legal Framework?

    Patents that aren't valid in the eyes of courts would best serve patent trolls that settle out of courts, en masse



  28. Microsoft's Share in Web Servers Rapidly Falls to Just 4.5% (Falling More Than 5% in a Single Month)

    Microsoft's share as measured at Netcraft (de facto authority in this area) is rapidly declining; expect IIS to go the way of the dodo some time in the coming years



  29. The Lock-downs Are Over and Still Zero Media Coverage About EPO Scandals and Corruption

    The appalling state of journalism in Europe (and to some extent in the world at large) means that the EPO's management can get away with all sorts of horrible crimes and fraud; the silencing of the media is, in its own right, quite scandalous



  30. IRC Proceedings: Thursday, July 02, 2020

    IRC logs for Thursday, July 02, 2020


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts