EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

02.03.09

Microsoft Adopts Malware Techniques to Advance .NET

Posted in Apple, Microsoft, Security, Windows at 9:38 am by Dr. Roy Schestowitz

LAST MONTH we very briefly mentioned what Apple had done to Mozilla/Firefox. It not only pretended that Firefox would die but it also used dirty techniques to push its non-Free software through the update mechanism for iTunes. This got Apple a lot of bad press and it relented.

Microsoft is not only doing the same thing. It’s doing something far more cheeky. It’s not only pushing unwanted (uncalled for) software into people’s desktops but it also injects that into a Free software competitor, namely Firefox, and to an extent also using its update mechanism to install Microsoft software that’s an impediment to cross-platform. Slashdot has a decent short overview of this widely-reported new situation.

While doing a weekly scrub of my Windows systems, which includes checking for driver updates and running virus scans, I found Firefox notifying me of a new add-on. It’s labelled ‘Microsoft .NET Framework Assistant,’ and it ‘Adds ClickOnce support and the ability to report installed .NET versions to the web server.’ The add-on could not be uninstalled in the usual way. A little Net searching turned up a number of sites offering advice on getting rid of the unrequested add-on.

This not only violates trust and fairness; it’s also a serious breach that can harm security. Speaking of which, Conficker keeps getting worse and worse, but the press hardly covers it anymore [1, 2].

The Microsoft RPC worm, known by many as Conficker/Downadup, has multiplied across corporate networks infecting an estimated 10 million machines. Though the damage has been minimal, the worst is yet to come, said researchers.

Conficker may have already killed people and now comes a formal report labeling this a “substantive failure.”

A worm attack that forced three London hospitals to shut down their computer networks late last year was entirely avoidable and represented a major failing by the organizations’ IT staff, according to an independent review of the incident.

Where life and death are at stake 24 hours a day, look what has happened because of Microsoft Windows viruses.

The PCs at St. Bartholomew’s, the Royal London Hospital and The London Chest Hospital were infected with Mytob, a mass-mailing worm also known as MyDoom. Emergency patients were temporarily diverted to other facilities, but officials said no personal data was lost.

This is not a joke, right? According to the report, “officials said no personal data was lost.” Were lives lost? Where is the liability when people die? How can this damage be measured?

Here is another new report: Data theft ‘cost a trillion US dollars’

INSECURITY outfit McAfee has told the World Economic Forum that data theft cost the world a trillion US dollars and if more work was not done to buy its products the figure could get worse.

Well, it figures. When almost 1 in 2 Windows PCs is a zombie, then the notion of “data theft” is like the notion of possession theft in a city where only half the buildings have doors.

“Our products just aren’t engineered for security.”

Brian Valentine, Microsoft executive

Open gate
In a world without windows and gates, who
needs to worry about breaches?

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

21 Comments

  1. ZiggyFish said,

    February 3, 2009 at 6:14 pm

    Gravatar

    It very interesting how the botnet controllers have not used these botnets to find exploits in encryption algorithms.

  2. Roy Schestowitz said,

    February 3, 2009 at 6:51 pm

    Gravatar

    If they already control so many PCs (and Secunia says 99% of Windows PCs are open to hijacking at all times), why even capture PCs at line/protocol level? It’s like breaking down a door when there’s an open window(s).

  3. Charles Norrie said,

    February 4, 2009 at 7:10 am

    Gravatar

    Instead of telling people how bad and even wicked Microsoft is, why not tell them how easy it is to install and use Linux systems, especially Ubuntu?

  4. Homer said,

    February 4, 2009 at 8:26 am

    Gravatar

    Because Roy and his chums feel elevated by their belief that everyone else is either clueless or evil.

  5. Jose_X said,

    February 4, 2009 at 8:58 am

    Gravatar

    [Charles Norrie] >> Instead of telling people how bad and even wicked Microsoft is, why not tell them how easy it is to install and use Linux systems, especially Ubuntu?

    You must be joking.. right?

    That’s like saying we should say how good are the shoes made by AAA Shoes Boutique, while failing to say anything about what a rotten SOB is Al Capone and his band of thugs that have been extorting anyone seen within a block of AAA Shoes Boutique.

    Dropping Microsoft, whether you go to Linux or to something else, is a plenty wonderful message to get out.

    Of course, it doesn’t help the Linux installation process that Microsoft keeps breaking the law throwing hurdles in front of Linux’ path through various levers deriving from their monopolies.

    ["Homer"] >> Because Roy and his chums feel elevated by their belief that everyone else is either clueless or evil.

    It’s so easy to spew garbage from the mouth when such garbage need not be backed by any evidence, so please support your comments if you don’t want to look foolish.. especially in light of all the evidence to the contrary.

    I take it you aren’t the same “[H]omer” that mans the irc channel on Freenode #boycottnovell. That guy seems a little more honest than you.

  6. Charles Norrie said,

    February 4, 2009 at 9:05 am

    Gravatar

    Dear Jose, I think we should try to balance the good news message about Linux with out trenchant statements on the bad guys! That’s all

  7. Jose_X said,

    February 4, 2009 at 9:09 am

    Gravatar

    >> Dear Jose, I think we should try to balance the good news message about Linux with out trenchant statements on the bad guys! That’s all

    That’s why I visit Linux Today as well as boycottnovell. The url should tip you off on the subject matter. Clearly the matter discussed on boycottnovell is very important.

  8. Roy Schestowitz said,

    February 4, 2009 at 9:10 am

    Gravatar

    “Homer” is not “[H]omer” or “Slated”.

    “Homer” seems likely to be an OpenSUSE guy.

  9. Jose_X said,

    February 4, 2009 at 9:13 am

    Gravatar

    Charles, boycottnovell actually does include lots of news links to Linux. Even if it didn’t, I don’t really see your point. It’s not like if a browser can’t go to more than one Linux website on the same day. Switch your browser, btw, if you are encountering that limitation.

  10. Roy Schestowitz said,

    February 4, 2009 at 9:16 am

    Gravatar

    Pro-FOSS/Linux articles by far outweigh analyses and criticisms, but we cover them daily in the form of links with snippets.

    Attacks on FOSS are a higher priority because they are a greater barrier to adoption than many other factors combined.

  11. Charles Norrie said,

    February 4, 2009 at 9:20 am

    Gravatar

    Dear Roy,

    Then why do I find that the average news article about Conficker if it says ‘if you have a Linux sytstem, you are not affected’ and then goes on to tell you how to use an anti-viral ptach or program to avoid that infection and doesn’t give you precise help to put Linux on your compuer (of whatever variety!)

    Charles

  12. Brian Assaf said,

    February 5, 2009 at 3:54 am

    Gravatar

    I’d like to field this question.

    Installation instructions for GNU/Linux and advocacy belongs in a separate article than a Windows worm and patch.

    If a Windows user wants to switch OS’s based on viruses/malware/security (in that case there would be very few users still on Windows) it would make sense to provide that as an obvious solution.

    But really, why not post a link to the articles in question?

    Maybe the author isn’t familiar with Linux, but wanted to be accurate and not imply it effects all PCs, just PC’s with Windows installed.

    Perhaps the mere mention of Linux will have someone use Google (which runs on that very thing) and google “Linux”

    If the article provides comments, such as this one, why not just mention it.

    “I use Ubuntu Linux, go to ubuntu.com”
    The site itself has a tour, and simple overview.

    I don’t think a paragraph in an article about another OS entirely would be satisfactory in the least.

    Not only that, many Linux distros can be burned to disc or copied to USB and booted from. Even without an install, so it really is necessary to point someone to a detailed and focused article on that.

    P.S. I would prefer honestly to never insult Windows or Microsoft products in general. But, MS has resorted to dirty tactics, and with the current lock-in and social inertia, sometimes you just have to point out just how it is, so that some will say:

    “Hey, why am I running this crap, I should check out an alternative”.

    I assure you there are happy Windows users with hijacked boxes, filled with malware, cracked software, DRM (i.e. WGA or Vista in general) just unaware of it.
    That may just be the push to get him or her to try something that isn’t frankly, an insulting OS.

  13. Roy Schestowitz said,

    February 5, 2009 at 4:35 am

    Gravatar

    You’re right. Someone raised a similar point before. Should we maybe add a banner somewhere in all pages… something that says “get GNU/Linux”?

  14. Jose_X said,

    February 5, 2009 at 8:13 am

    Gravatar

    >> something that says “get GNU/Linux”?

    It might be more fitting to recommend actual branded distros as well.. of course, distros whose patronage would be a positive to the wider Linux community (vs say to Microsoft).

    A distro rotation could be used, perhaps alongside the ads. Maybe even offer limited free ad space to distros where they can put their own messages. And I’m not insinuating that generic GNU/Linux should not be in the mix.

    Boycottnovell could have its own distro. I know I have brought this up before (on irc), but I haven’t yet gotten myself into a position to get back to technical work.

  15. Roy Schestowitz said,

    February 5, 2009 at 8:15 am

    Gravatar

    Shane has already created SueMe Linux.

  16. Jose_X said,

    February 5, 2009 at 8:55 am

    Gravatar

    Yes, I think Shane mentioned recently something along those lines.

    Where is the download button or torrent? What features does it have? How was it put together? I’m interested.

  17. Jose_X said,

    February 5, 2009 at 8:57 am

    Gravatar

    Thanks. Thanks a lot… I should have clicked before assuming you were a decent human being with tact. Thanks a lot.

    :-)

  18. Roy Schestowitz said,

    February 5, 2009 at 9:23 am

    Gravatar

    The main post is here, but the domain name was cyber-jacked.

  19. Shane Coyle said,

    February 5, 2009 at 9:25 am

    Gravatar

    SueMe had died, I don’t remember what it was based upon – probably Slackware or Gentoo – the main point of the site was it was ‘Disclosing your Balance Sheet Liabilities’, and prominently displayed Microsoft’s FUD claims regarding the number of their patents infringed by GNU/Linux systems right on the frontpage.

    That being said, it was fully functional, even if patent encumbered ;^ ). The domain was jettisoned during a financial crisis, (we had kept all of the boycott____ names, but I couldn’t afford ‘em all…)

    If there really is a desire, we could certainly spin something new up.

  20. Brian Assaf said,

    February 5, 2009 at 2:58 pm

    Gravatar

    Go for it Roy.

    I stumbled upon this site in a blog comment somewhere:

    http://www.getgnulinux.org/

    Looks very nice, and is quite simple to peruse. Recommends Ubuntu, Fedora, and gnewsense. I figure your site would not want to advocate SUSE. ;)

    Also, groklaw has a “switch to Linux” link on the side of the main page.

    http://www.groklaw.net/staticpages/index.php?page=2006061302494935

    It may indeed be worth while for boycottnovell to offer something like that.

  21. Roy Schestowitz said,

    February 5, 2009 at 4:43 pm

    Gravatar

    @Brian,

    Thanks. Yes, I linked to http://www.getgnulinux.org/ earlier on in a post and earlier today I also thought about doing what Groklaw did, probably in our Wiki.

What Else is New


  1. Links 21/3/2019: Wayland 1.17.0, Samba 4.10.0, OpenShot 2.4.4 and Zorin Beta

    Links for the day



  2. Team UPC (Unitary Patent) is a Headless Chicken

    Team UPC's propaganda about the Unified Patent Court (UPC) has become so ridiculous that the pertinent firms do not wish to be identified



  3. António Campinos Makes Up Claims About Patent Quality, Only to be Rebutted by Examiners, Union (Anyone But the 'Puff Pieces' Industry)

    Battistelli's propagandistic style and self-serving 'studies' carry on; the notion of patent quality has been totally discarded and is nowadays lied about as facts get 'manufactured', then disseminated internally and externally



  4. Links 20/3/2019: Google Announces ‘Stadia’, Tails 3.13

    Links for the day



  5. CEN and CENELEC Agreement With the EPO Shows That It's Definitely the European Commission's 'Department'

    With headlines such as “EPO to collaborate on raising SEP awareness” it is clear to see that the Office lacks impartiality and the European Commission cannot pretend that the EPO is “dafür bin ich nicht zuständig” or “da kenne ich mich nicht aus”



  6. Decisions Made Inside the European Patent Organisation (EPO) Lack Credibility Because Examiners and Judges Lack Independence

    The lawless, merciless, Mafia-like culture left by Battistelli continues to haunt judges and examiners; how can one ever trust the Office (or the Organisation at large) to deliver true justice in adherence or compliance with the EPC?



  7. Team UPC Buries Its Credibility Deeper in the Grave

    The three Frenchmen at the top do not mention the UPC anymore; but those who promote it for a living (because they gambled on leveraging it for litigation galore) aren't giving up and in the process they perpetuate falsehoods



  8. The EPO Has Sadly Taken a Side and It's the Patent Trolls' Side

    Abandoning the whole rationale behind patents, the Office now led for almost a year by António Campinos prioritises neither science nor technology; it's all about granting as many patents (European monopolies) as possible for legal activity (applications, litigation and so on)



  9. Where the USPTO Stands on the Subject of Abstract Software Patents

    Not much is changing as we approach Easter and software patents are still fool's gold in the United States, no matter if they get granted or not



  10. Links 19/3/2019: Jetson/JetBot, Linux 5.0.3, Kodi Foundation Joins The Linux Foundation, and Firefox 66

    Links for the day



  11. Links 18/3/2019: Solus 4, Linux 5.1 RC1, Mesa 18.3.5, OSI Individual Member Election Won by Microsoft

    Links for the day



  12. Microsoft and Its Patent Trolls Continue Their Patent War, Including the War on Linux

    Microsoft is still preying on GNU/Linux using patents, notably software patents; it wants billions of dollars served on a silver platter in spite of claims that it reached a “truce” by joining the Open Invention Network and joining the LOT Network



  13. Director Iancu Generally Viewed as a Lapdog of Patent Trolls

    As Director of the Office, Mr. Iancu, a Trump appointee, not only fails to curb patent trolls; he actively defends them and he lowers barriers in order to better equip them with bogus patents that courts would reject (if the targets of extortion could afford a day in court)



  14. Links 17/3/2019: Google Console and IBM-Red Hat Merger Delay?

    Links for the day



  15. To Team UPC the Unified Patent Court (UPC) Has Become a Joke and the European Patent Office (EPO) Never Mentions It Anymore

    The EPO's frantic rally to the very bottom of patent quality may be celebrated by obedient media and patent law firms; to people who actually produce innovative things, however, this should be a worrisome trend and thankfully courts are getting in the way of this nefarious agenda; one of these courts is the FCC in Germany



  16. Links 16/3/2019: Knoppix Release and SUSE Independence

    Links for the day



  17. Stopping António Campinos and His Software Patents Agenda (Not Legal in Europe) Would Require Independent Courts

    Software patents continue to be granted (new tricks, loopholes and buzzwords) and judges who can put an end to that are being actively assaulted by those who aren't supposed to have any authority whatsoever over them (for decisions to be impartially delivered)



  18. The Linux Foundation Needs to Speak Out Against Microsoft's Ongoing (Continued) Patent Shakedown of OEMs That Ship Linux

    Zemlin actively thanks Microsoft while taking Microsoft money; he meanwhile ignores how Microsoft viciously attacks Linux using patents, revealing the degree to which his foundation, the “Linux Foundation” (not about Linux anymore, better described as Zemlin’s PAC), has been compromised



  19. Links 15/3/2019: Linux 5.0.2, Sublime Text 3.2

    Links for the day



  20. The EPO and the USPTO Are Granting Fake Patents on Software, Knowing That Courts Would Reject These

    Office management encourages applicants to send over patent applications that are laughable while depriving examiners the freedom and the time they need to reject these; it means that loads of bogus patents are being granted, enshrined as weapons that trolls can use to extort small companies outside the courtroom



  21. CommunityBridge is a Cynical Microsoft-Funded Effort to Show Zemlin Works for 'Community', Not Microsoft

    After disbanding community participation in the Board (but there are Microsoft staff on the Board now) the "Linux Foundation" (or Zemlin PAC) continues to take Microsoft money and polishes or launders that as "community"



  22. Links 14/3/2019: GNOME 3.32 and Mesa 19.0.0 Released

    Links for the day



  23. EPO 'Results' Are, As Usual, Not Measured Correctly

    The supranational monopoly, a monopoly-granting authority, is being used by António Campinos to grant an insane amount of monopolies whose merit is dubious and whose impact on Europe will be a net negative



  24. Good News Everyone! UPC Ready to Go... in 2015!

    Benoît Battistelli is no longer in Office and his fantasy (patent lawyers' fantasy) is as elusive as ever; Team UPC is trying to associate opposition to UPC with the far right (AfD) once again



  25. Links 13/3/2019: Plasma 5.15.3,Chrome 73 and Many LF Press Releases

    Links for the day



  26. In the Age of Trumpism EFF Needs to Repeatedly Remind Director Iancu That He is Not a Judge and He Cannot Ignore the Courts

    The nonchalance and carelessness seen in Iancu's decision to just cherry-pick decisions/outcomes (basically ignoring caselaw) concerns technologists, who rightly view him as a 'mole' of the litigation 'industry' (which he came from)



  27. Links 12/3/2019: Sway 1.0 Released, Debian Feuds Carry On

    Links for the day



  28. Microsoft is Complaining About Android and Chrome OS (GNU/Linux) Vendor Not Paying for Microsoft Patents (Updated)

    Microsoft, which nowadays does the patent shakedown against GNU/Linux by proxy, is still moaning about companies that don’t pay ‘protection’ money (grounds for antitrust action or racketeering investigation)



  29. Watchtroll Has Redefined "Trolls" to Mean Those Who Oppose Software Patents (and Oppose Trolls), Not Those Who Leverage These for Blackmail Alone

    The controversial change to 35 U.S.C. § 101 guidance is being opposed by the public (US citizens who oppose American software patents), so patent maximalists like Janal Kalis (“PatentBuddy”) and extremists like Gene Quinn (Watchtroll) want us to believe that the public is just “EFF” and cannot think for itself



  30. EPO's Latest 'Results' Show That António Campinos Has Already Given Up on Patent Quality and is Just Another Battistelli

    The patent-granting machine that the EPO has become reports granting growth of unrealistic scale (unless no proper examination is actually carried out)


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts