<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Conficker is Alive, Windows Vista is Critically Vulnerable and Microsoft Office Likewise</title>
	<atom:link href="http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/feed/" rel="self" type="application/rss+xml" />
	<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/</link>
	<description>Free Software Sentry – watching and reporting maneuvers of those threatened by software freedom</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:00:35 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: David Gerard</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-2/#comment-61471</link>
		<dc:creator>David Gerard</dc:creator>
		<pubDate>Thu, 02 Apr 2009 13:00:13 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-61471</guid>
		<description>However, Microsoft really does deliberately send through patches designed to disable machines. At least when Ubuntu fucks up (and as an Ubuntu user, I am entirely too aware of how good they are at this) it&#039;s not with deliberate malicious intent.</description>
		<content:encoded><![CDATA[<p>However, Microsoft really does deliberately send through patches designed to disable machines. At least when Ubuntu fucks up (and as an Ubuntu user, I am entirely too aware of how good they are at this) it&#8217;s not with deliberate malicious intent.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yggdrasil</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-2/#comment-61452</link>
		<dc:creator>Yggdrasil</dc:creator>
		<pubDate>Thu, 02 Apr 2009 03:23:48 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-61452</guid>
		<description>No, that is an overblown fear that some people have, but like many fears it&#039;s irrational.  Given the enormous number of Windows machines in place, problems due to updates are relatively small, though no software is perfect.

I specifically remember trying to update a Ubuntu distro to 8.10.  After it finished the machine rebooted, only to halt on the next boot complaining that it could not locate some file.  Had I been using this machine for anything important, I would have been royally screwed.  Updates &quot;can&quot; break installs or software on ANY OS.  That&#039;s the nature of computer software.  Problems with Windows will always seem worse since there are more Windows machines in use.

Try upgrading your Amiga 500 to OS 3.1, which includes having to replace a ROM chip, then find out your favorite game won&#039;t work.  Computers are complex machines.  To assume you will never have problems using some other OS or hardware platform is purely delusional.

For the record, in 12 years of using Windows machines, I have never had any update or security patch cause any serious problems.  That includes the machines owned by my parents and sister.  At the very worst, I might have had to update an older piece of software for some odd reason, but again.... that&#039;s normal.</description>
		<content:encoded><![CDATA[<p>No, that is an overblown fear that some people have, but like many fears it&#8217;s irrational.  Given the enormous number of Windows machines in place, problems due to updates are relatively small, though no software is perfect.</p>
<p>I specifically remember trying to update a Ubuntu distro to 8.10.  After it finished the machine rebooted, only to halt on the next boot complaining that it could not locate some file.  Had I been using this machine for anything important, I would have been royally screwed.  Updates &#8220;can&#8221; break installs or software on ANY OS.  That&#8217;s the nature of computer software.  Problems with Windows will always seem worse since there are more Windows machines in use.</p>
<p>Try upgrading your Amiga 500 to OS 3.1, which includes having to replace a ROM chip, then find out your favorite game won&#8217;t work.  Computers are complex machines.  To assume you will never have problems using some other OS or hardware platform is purely delusional.</p>
<p>For the record, in 12 years of using Windows machines, I have never had any update or security patch cause any serious problems.  That includes the machines owned by my parents and sister.  At the very worst, I might have had to update an older piece of software for some odd reason, but again&#8230;. that&#8217;s normal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roy Schestowitz</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-3/#comment-61443</link>
		<dc:creator>Roy Schestowitz</dc:creator>
		<pubDate>Thu, 02 Apr 2009 01:46:16 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-61443</guid>
		<description>Patches arrive &lt;a href=&quot;http://boycottnovell.com/2008/12/11/microsoft-patch-cycle/&quot; rel=&quot;nofollow&quot;&gt;when attacks commence&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>Patches arrive <a href="http://boycottnovell.com/2008/12/11/microsoft-patch-cycle/" rel="nofollow">when attacks commence</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jocaferro</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-3/#comment-61442</link>
		<dc:creator>jocaferro</dc:creator>
		<pubDate>Thu, 02 Apr 2009 01:44:17 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-61442</guid>
		<description>ooopppss, sorry
&quot;2000, XP, 2003 Server, Vista.&quot;
 - and 2008 Server too!</description>
		<content:encoded><![CDATA[<p>ooopppss, sorry<br />
&#8220;2000, XP, 2003 Server, Vista.&#8221;<br />
 &#8211; and 2008 Server too!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jocaferro</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-3/#comment-61440</link>
		<dc:creator>jocaferro</dc:creator>
		<pubDate>Thu, 02 Apr 2009 01:42:24 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-61440</guid>
		<description>March patch - MS09-006:
“This security update resolves several privately reported vulnerabilities in the Windows kernel. The most serious vulnerability could allow remote code execution if a user viewed a specially crafted EMF or WMF image file from an affected system.”

Yes, several (privately) vulnerabilities. Where?
Windows kernel!
2000, XP, 2003 Server, Vista.
An unpatched Windows computer is a serious problem since the moment everyone knows about it. In the MS/Windows world this situation can take months even years until all computers become patched!
How long MS (privately) know about this problem?
Or, how long MS (privately) know about many problems without caring for a patch?</description>
		<content:encoded><![CDATA[<p>March patch &#8211; MS09-006:<br />
“This security update resolves several privately reported vulnerabilities in the Windows kernel. The most serious vulnerability could allow remote code execution if a user viewed a specially crafted EMF or WMF image file from an affected system.”</p>
<p>Yes, several (privately) vulnerabilities. Where?<br />
Windows kernel!<br />
2000, XP, 2003 Server, Vista.<br />
An unpatched Windows computer is a serious problem since the moment everyone knows about it. In the MS/Windows world this situation can take months even years until all computers become patched!<br />
How long MS (privately) know about this problem?<br />
Or, how long MS (privately) know about many problems without caring for a patch?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gentoo User</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-3/#comment-61426</link>
		<dc:creator>Gentoo User</dc:creator>
		<pubDate>Wed, 01 Apr 2009 23:46:03 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-61426</guid>
		<description>&lt;a href=&quot;http://www.computerworld.com.au/article/216465/how_avoid_debian_ssh_key_attacks?fp=16&amp;fpid=1&quot; rel=&quot;nofollow&quot;&gt;This&lt;/a&gt; wasn&#039;t suppose to exist, either. But it does.</description>
		<content:encoded><![CDATA[<p><a href="http://www.computerworld.com.au/article/216465/how_avoid_debian_ssh_key_attacks?fp=16&amp;fpid=1" rel="nofollow">This</a> wasn&#8217;t suppose to exist, either. But it does.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roy Schestowitz</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-3/#comment-61421</link>
		<dc:creator>Roy Schestowitz</dc:creator>
		<pubDate>Wed, 01 Apr 2009 22:16:27 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-61421</guid>
		<description>People conveniently forget sometimes that this serious flaw was not supposed to exist in the first place.</description>
		<content:encoded><![CDATA[<p>People conveniently forget sometimes that this serious flaw was not supposed to exist in the first place.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Gerard</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-2/#comment-61420</link>
		<dc:creator>David Gerard</dc:creator>
		<pubDate>Wed, 01 Apr 2009 22:15:47 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-61420</guid>
		<description>Problem: Microsoft sends through too many patches that either (a) accidentally break things or (b) deliberately break things (WGA, which they just tried sending through again recently).

So people just don&#039;t trust Microsoft patches.</description>
		<content:encoded><![CDATA[<p>Problem: Microsoft sends through too many patches that either (a) accidentally break things or (b) deliberately break things (WGA, which they just tried sending through again recently).</p>
<p>So people just don&#8217;t trust Microsoft patches.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clump</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-2/#comment-61419</link>
		<dc:creator>Clump</dc:creator>
		<pubDate>Wed, 01 Apr 2009 22:08:25 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-61419</guid>
		<description>If your computer is and has been set to automatically update then your computer itself is OK. Then you only have to worry about the systems out there holding your personal information! 

You&#039;d think only a small percent of people wouldn&#039;t have this patch already, but it seems about 30% of Windows users haven&#039;t patched. North Americans will weather it better than Asians as most North American systems are patched while the big numbers of no-patch are in Asia, S. America etc.</description>
		<content:encoded><![CDATA[<p>If your computer is and has been set to automatically update then your computer itself is OK. Then you only have to worry about the systems out there holding your personal information! </p>
<p>You&#8217;d think only a small percent of people wouldn&#8217;t have this patch already, but it seems about 30% of Windows users haven&#8217;t patched. North Americans will weather it better than Asians as most North American systems are patched while the big numbers of no-patch are in Asia, S. America etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Caitlin</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-2/#comment-61370</link>
		<dc:creator>Caitlin</dc:creator>
		<pubDate>Wed, 01 Apr 2009 04:53:01 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-61370</guid>
		<description>Quite honestly, I thought it was some kind of scam for a cruel April Fools joke, but when I saw that it said in I believe, a CNN article &quot;IF YOU RECEIVED AN UPDATE FROM MICROSOFT FOR SECURITY UPDATES, YOU SHOULD BE FINE&quot; 

I immediately checked my Windows Update, and Lo and behold, the update was there. 

NOT INSTALLED.

It&#039;s now installing at 55% complete.</description>
		<content:encoded><![CDATA[<p>Quite honestly, I thought it was some kind of scam for a cruel April Fools joke, but when I saw that it said in I believe, a CNN article &#8220;IF YOU RECEIVED AN UPDATE FROM MICROSOFT FOR SECURITY UPDATES, YOU SHOULD BE FINE&#8221; </p>
<p>I immediately checked my Windows Update, and Lo and behold, the update was there. </p>
<p>NOT INSTALLED.</p>
<p>It&#8217;s now installing at 55% complete.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Gerard</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-2/#comment-60330</link>
		<dc:creator>David Gerard</dc:creator>
		<pubDate>Mon, 09 Mar 2009 13:08:18 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-60330</guid>
		<description>A patch was released, but unfortunately people don&#039;t trust Microsoft patches any more because they accidentally break things way too often. (Not to mention &lt;i&gt;deliberately&lt;/i&gt; sabotaging people&#039;s machines with Windows Genuine Advantage and suchlike.)

So people actually have to go through and check the machines. I had to do this at work (we have some Windows boxes for proprietary software that&#039;s a required part of our production chain; we&#039;re not happy about this). Ridiculously tedious.

Furthermore, the patch last year only patches the Internet transmission vector for Conficker - it doesn&#039;t actually disable the memory stick or CD vector (the autoplay problem).

[And may I say also how much autoplay sucks. I have a 500GB drive full of ripped CDs in FLAC - I plug it into a Windows XP box and it pauses for a minute while it tries to work out how to autoplay the thing. WHAT.]</description>
		<content:encoded><![CDATA[<p>A patch was released, but unfortunately people don&#8217;t trust Microsoft patches any more because they accidentally break things way too often. (Not to mention <i>deliberately</i> sabotaging people&#8217;s machines with Windows Genuine Advantage and suchlike.)</p>
<p>So people actually have to go through and check the machines. I had to do this at work (we have some Windows boxes for proprietary software that&#8217;s a required part of our production chain; we&#8217;re not happy about this). Ridiculously tedious.</p>
<p>Furthermore, the patch last year only patches the Internet transmission vector for Conficker &#8211; it doesn&#8217;t actually disable the memory stick or CD vector (the autoplay problem).</p>
<p>[And may I say also how much autoplay sucks. I have a 500GB drive full of ripped CDs in FLAC - I plug it into a Windows XP box and it pauses for a minute while it tries to work out how to autoplay the thing. WHAT.]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roy Schestowitz</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-2/#comment-60329</link>
		<dc:creator>Roy Schestowitz</dc:creator>
		<pubDate>Mon, 09 Mar 2009 13:07:50 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-60329</guid>
		<description>The dunce here is you, Dave.

If you had read this post carefully, then you would realise that you are mixing together two completely isolated parts of it (Vista vulnerability and Conficker).</description>
		<content:encoded><![CDATA[<p>The dunce here is you, Dave.</p>
<p>If you had read this post carefully, then you would realise that you are mixing together two completely isolated parts of it (Vista vulnerability and Conficker).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-2/#comment-60327</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Mon, 09 Mar 2009 13:03:03 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-60327</guid>
		<description>And not to mention of course that the vunerability used by the Conficker worm has already been patched last year.</description>
		<content:encoded><![CDATA[<p>And not to mention of course that the vunerability used by the Conficker worm has already been patched last year.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-1/#comment-60326</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Mon, 09 Mar 2009 13:01:58 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-60326</guid>
		<description>Wow, unbeleivable what an idiot you are Roy. 
You can&#039;t even read the simplest of security advisories.

The vunerability used by Conficker is NOT a critical vunerability for Vista.
It is only critical for windows XP !!!!

This blog is really a disgrace full of disinformation and lies !!!</description>
		<content:encoded><![CDATA[<p>Wow, unbeleivable what an idiot you are Roy.<br />
You can&#8217;t even read the simplest of security advisories.</p>
<p>The vunerability used by Conficker is NOT a critical vunerability for Vista.<br />
It is only critical for windows XP !!!!</p>
<p>This blog is really a disgrace full of disinformation and lies !!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Needs Sunlight</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-1/#comment-60317</link>
		<dc:creator>Needs Sunlight</dc:creator>
		<pubDate>Mon, 09 Mar 2009 09:35:19 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-60317</guid>
		<description>One word: racketeering

http://www.law.cornell.edu/uscode/html/uscode18/usc_sup_01_18_10_I_20_96.html</description>
		<content:encoded><![CDATA[<p>One word: racketeering</p>
<p><a href="http://www.law.cornell.edu/uscode/html/uscode18/usc_sup_01_18_10_I_20_96.html" rel="nofollow">http://www.law.cornell.edu/uscode/html/uscode18/usc_sup_01_18_10_I_20_96.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Gerard</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-1/#comment-60305</link>
		<dc:creator>David Gerard</dc:creator>
		<pubDate>Sun, 08 Mar 2009 22:12:07 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-60305</guid>
		<description>The Iceland MCP story has three Slashdot firehose links - &lt;a href=&quot;http://slashdot.org/firehose.pl?op=view&amp;id=3676189&quot; rel=&quot;nofollow&quot;&gt;1&lt;/a&gt;, &lt;a href=&quot;http://slashdot.org/firehose.pl?op=view&amp;id=3675823&quot; rel=&quot;nofollow&quot;&gt;2&lt;/a&gt;, &lt;a href=&quot;http://slashdot.org/firehose.pl?op=view&amp;id=3656025&quot; rel=&quot;nofollow&quot;&gt;3&lt;/a&gt; - please vote up!</description>
		<content:encoded><![CDATA[<p>The Iceland MCP story has three Slashdot firehose links &#8211; <a href="http://slashdot.org/firehose.pl?op=view&amp;id=3676189" rel="nofollow">1</a>, <a href="http://slashdot.org/firehose.pl?op=view&amp;id=3675823" rel="nofollow">2</a>, <a href="http://slashdot.org/firehose.pl?op=view&amp;id=3656025" rel="nofollow">3</a> &#8211; please vote up!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pcolon</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-1/#comment-60303</link>
		<dc:creator>pcolon</dc:creator>
		<pubDate>Sun, 08 Mar 2009 21:44:15 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-60303</guid>
		<description>@Jose_X: It&#039;s sounds like the old &quot;Whack-a-mole&quot; game.</description>
		<content:encoded><![CDATA[<p>@Jose_X: It&#8217;s sounds like the old &#8220;Whack-a-mole&#8221; game.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jose_X</title>
		<link>http://techrights.org/2009/03/08/conficker-alive-vista-office-flaws/comment-page-1/#comment-60287</link>
		<dc:creator>Jose_X</dc:creator>
		<pubDate>Sun, 08 Mar 2009 16:41:20 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-60287</guid>
		<description>&quot;Not engineered for security&quot; is why you have a zillion variants of bugs around. Do they &quot;patch&quot; one hole by moving it around to a different hiding place?

I&#039;m guessing their situation is horrible, but can you actually patch Windows against all the bugs at once, or will the different patches undue work done in other patches as these holes are moved around?

[I think the answer is that the above is true for some holes but not all. When you don&#039;t engineer for security, you have to crudely keep redefining names and numbers to keep the malware guessing.]</description>
		<content:encoded><![CDATA[<p>&#8220;Not engineered for security&#8221; is why you have a zillion variants of bugs around. Do they &#8220;patch&#8221; one hole by moving it around to a different hiding place?</p>
<p>I&#8217;m guessing their situation is horrible, but can you actually patch Windows against all the bugs at once, or will the different patches undue work done in other patches as these holes are moved around?</p>
<p>[I think the answer is that the above is true for some holes but not all. When you don't engineer for security, you have to crudely keep redefining names and numbers to keep the malware guessing.]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

