EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

05.09.09

U.S. Federal Aviation Administration (Windows Shop) Gets Cracked Again

Posted in Microsoft, Security, Windows at 6:34 am by Dr. Roy Schestowitz

Loading

Corollary: People may start caring about computer security not when businesses become less productive but when disaster eventually strikes

WE’VE already shown that the U.S. Federal Aviation Administration (FAA) is relying on a great deal of Windows [1, 2], so it’s not surprising to find it getting cracked again. From the news:

i. FAA admits problems with hackers

According to CNET, the US Federal Aviation Administration has admitted that hackers have broken into the air traffic control mission-support systems several times in recent years. In one case they managed to become ‘insiders’ to the network.

ii. Report: Hackers broke into FAA air traffic control systems

Hackers have broken into the air traffic control mission-support systems of the U.S. Federal Aviation Administration several times in recent years, according to an Inspector General report sent to the FAA this week.

Also in the news in recent days:

i. Researchers Release Bootkit Code Targeting Windows 7

Dubbed Vbootkit 2.0, the software was first presented by researchers Vipin Kumar and Nitin Kumar at the Hack In The Box security conference in Dubai in April. At the conference, the two researchers demonstrated how attackers could circumvent security features implemented in the kernel and gain control over Windows 7 (x64).

ii. Microsoft to patch ‘critical’ PowerPoint hole

Microsoft plans to patch a hole in its PowerPoint presentation program, the company said in an advanced bulletin that was notable because it contained only a single update.

iii. Botnet master hits the kill switch, takes down 100,000 PCs

Those behind the Zeus botnet recently decided to press the big red button, bluescreening 100,000 computers around the globe. Security experts aren’t sure why yet, although they have some ideas.

iv. Windows and Viruses – Made for each other

This is the screenshot of the cnet’s download.com which shows the most popular downloads for windows. The first five positions are taken by anti-virus software :-). Sadly there is no ‘Linux’ download section but ‘Mac’ has a place.

v. Microsoft ‘fixes’ its malware problem

Computerworld has an Microsoft WGA/WAT spokesman quoted as saying: “When we went out and talked to customers, we found that activation was the concept that resonated most strongly with them”.

The quote ends there, but may have ended: “…Like memories of the first time they were kicked in the groin.”

In any case, Microsoft’s draconian licensing enforcement ‘technology’ is malware by its own definition. And it’s forced on the user through EULAs of questionable legality.

There is no advantage to it for the user, only advantages for Microsoft. And renaming it won’t make it more attractive to users or any more palatable.

Maybe someday, smart users will stop buying software products that have a built-in remote off switch.

Name changes never resolve problems, except for perceptual problems.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

6 Comments

  1. Needs Sunlight said,

    May 9, 2009 at 7:11 am

    Gravatar

    Keep in mind, the FAA knows better and has experienced at least one Windows- based shutdown of the World’s eighth largest economy:

    http://www.techworld.com/opsys/news/index.cfm?newsid=2275

    http://www.securityfocus.com/news/9729

    http://www.ccsce.com/pdf/Numbers_CA_Rank.pdf

    FWIW, California is ranked just behind Italy.

    Roy Schestowitz Reply:

    Yes, it’s a Windows problem.

    The Los Angeles Times reported that the outage was the result of a worker neglecting to perform a monthly reset of a Windows-based control system, resulting in its automatic shutdown after 49.7 days of operation. A backup system also failed.

    Microsoft server crash nearly causes 800-plane pile-up

    twitter Reply:

    The FAA has made some tennative moves away from M$, but apparently has not made the jump to sanity. In 2006, they moved some servers to Red Hat. In 2007 they said no to Vista and considered dumping Windows completely for GNU/Linux. The FAA’s CIO, David Bowen, was quoted at the time about “business case” and problems with compatibility and continued availability of XP rather than security and freedom. He mentions security here but OS is not part of the discussion. A sane discussion would be about getting Windows out of airports entirely because a single compromised machine can do a lot of damage. Every airport I visit has M$ junk prominently placed, often with big error messages displayed instead of information. The FAA has the authority to fix this and should.

    When reading these stories, it is difficult to know if the incompetence comes from the reporter or the FAA. Bowen’s background is in economics and business which is decried, somewhat unfairly here. An older CV is published here. No mention of computing languages or development is made, which may be why it has taken him so long to see the value of free software despite managing so many computers over the last 25 years. He has a guilty hand in the health care mess, having come from Blue Shield. Still, we know how well managed most of the press is when it comes to M$ trash. It is no more surprising to find smears against anyone in power who considers moving to GNU/Linux than it is to find complete incompetents in power. At this point, competent people not only realize what a security disaster Windows is, they realize how it is designed to never properly interact with other systems. Competent people do what Lowes did, they migrate completely away and do so at once. Bowes has indicated he thinks this way, but it is impossible to tell through the reporting that I have found.

  2. ricardo nunes said,

    May 9, 2009 at 7:43 am

    Gravatar

    OSOR – The Swiss company Skysoft has started development of Albatross, a set of open source applications for air traffic controllers. The project’s website was unveiled on 16 March.

    The software will be published under a GNU Public Licence. The company has not yet decided which version of the GPL will be used.
    http://www.osor.eu/news/company-opens-development-airport-traffic-management-software

  3. Al said,

    May 12, 2009 at 1:54 am

    Gravatar

    It is the incompetence of the security and administration that causes theese problems everys single time. And you people think running open source is a good idea for these morons?? If they can not properly administer a Windows environment how the hell do you expect them to to deal with Linux or Unix??? Please tell me?? So the Windows bashing may be all well and good but let’s get the facts strait in any one of the cases like this you had incompetent people as the cause.. When a competent staff and sound policy is in place Windows is just as secure as Linux! Is it much more expensive? Yes … Does it offer the freedom? No…. But do not blame Windows for complete incompetence!!!!

    Hey we are talking about government here so incompetence is a given!!!

    Think about it the FAA is bueracracy and the follow the government model…

    Spend way more than neccessary… Hire any moron that is related or a friend the let them give their moron friends and relatives jobs… Next pay them entirely to much for doing far to little … After that let them take off whenever they want, throw in double time and a half holiday pay for every holiday possible…. Then when it goes wrong blame the taxypayers and corporations!!!

    Yet so many seem to embrace this idea shouting while they rob us blind knowing our taxes are going sky high in the future no matter what you make and yet we shout YES WE CAN…

    Give in to the Obama/Gates (General Electric,NBC,Microsoft) connection….

    Roy Schestowitz Reply:

    NBC ‘news’ is a wholly separate issue. :-)

What Else is New


  1. The Latest EPO Victim Card (Played by Željko Topić) Should be Treated as Seriously as Those Bogus Claims of Violence by a Judge (Updated)

    In its desperate pursuit of a narrative wherein the staff of the EPO is violent and aggressive the management of the EPO, renowned for institutional aggression, finds (or claims to have found) a little tampering with a bicycle



  2. Links 25/5/2016: Nginx 1.11, F1 2015 Coming to GNU/Linux Tomorrow

    Links for the day



  3. The Media Starts Informing the European Public About the Downsides of UPC While EPO Accelerates Its Lobbying for Ratification

    The EPO's shameless UPC promotion takes another step forward as the European press outlets (even television channels) begin to explore the secret deal that's negotiated by patent lawyers (with corporate clients) and patent offices, not the public or any public interest groups



  4. Some Details About How the EPO's President is Rumoured to be 'Buying' Votes and Why It's Grounds/Basis for “Immediate Dismissal”

    Some background information and a detailed explanation of the systemic financial dependency, created by Battistelli at the cost of €13 million or more, which prevents effective oversight of Battistelli



  5. How the Patent Lawyers' Microcosm Continues to Boost Software Patents Filth by Misdirecting Readers, Relying on Highly Selective Coverage

    Under the guise of reporting/analysis/advice the community of patent lawyers is effectively lobbying to make software patents popular and widely-accepted again, based on one single case which they wish to make 'the' precedent



  6. Documents Show Zagreb Police Department in Investigation of Vice-President of the European Patent Office

    Željko Topić's troubles in Croatia, where he faces many criminal charges, may soon become an extraordinary burden for the EPO, which distances itself from it all mostly by attacking staff that 'dares' to bring up the subject



  7. [ES] Interrumpiendo la Propagánda Distractante de Battistelli: los Empleados de la EPO Protestará de Nuevo en una Quincena

    La exágerada extravagancia (desperdicio de dinero) en la Ceremonia de Premiación al Inventor Europeo de la EPO tendrá que competir por atención de los medios con miles de empleados de la EPO (en todaslas sedes de la EPO) marchándo en las calles para protestar por los abusos de la EPO



  8. Windows and Microsoft's Other 'Burning Platforms'

    It's not just Windows for phones that's reaching minuscule market share levels but also Windows, but Microsoft is skilled at hiding this (cannibalising Windows using something people do not even want, then counting that cannibal, Vista 10)



  9. Links 24/5/2016: CRYENGINE Source Code is Out on GitHub, Jono Bacon Leaves GitHub

    Links for the day



  10. Links 23/5/2016: GNOME 3.22, Calculate Linux 15.17

    Links for the day



  11. 'Celebrity' Patent Trolls and the Elusive Battle Against Patent Trolls (or Eastern District of Texas Courts) Rather Than Software Patents

    Some of last week's more important reports, which serve to demonstrate how the system is attempting to tackle a side-effect of software patents rather than the patents themselves (their irrational scope)



  12. The Circus of Patent 'Reporting' (by Omission) on the Subject of Software Patents in the US and USPTO Bias

    look at some of the latest oddities in the US patent system and much of the reporting about software patenting (more or less monopolised by those who profit from it, not harmed by it)



  13. IP3 Demonstrates That Today's Patent Systems Devolve Into a Conglomerates' Game, Won't Protect the Mythical Small Inventor

    Multinational corporations bring together their shared interests and steer the increasingly-inseparable patent systems according to their needs and goals, but has anyone even noticed?



  14. Disrupting Battistelli's Distracting Propaganda: EPO Staff to Protest Again in About a Fortnight

    The overly extravagant (waste of money) EPO European Inventor Award will have to compete for media attention with thousands of EPO staff (in all EPO sites) marching in the streets to protest against the EPO's abuses



  15. Corrupting Democracy? Growing Frequency of Rumours That the EPO's President Battistelli is 'Buying' Votes of Small Member States

    Several sources suggest that rather than appease the Administrative Council by taking corrective action Battistelli and his notorious 'circle' now work hard to remove opposition from the Administrative Council, especially where this is easier a task to accomplish (politically or economically)



  16. [ES] Los Mitos de la EPO ‘Calidad’ de Patentes y de ‘Creación’ de Patentes: Basados en Ventas de Cafe y Trauma

    La carrera hacia el fondo, o la ridícula asumpción de Battistelli de que otorgar más y más patentenes más rápidamente (e.g. usando PACE) sería beneficióso a largo término, puede guíar al final colapse del valor de la EPO y la pérdida de su lárgamente ganada reputación a nivel mundial



  17. Links 22/5/2016: Systemd 230, Debian Installer Alpha 6

    Links for the day



  18. EPO Patent 'Quality' and 'Patent Creation' Myth: Capsule-Based Coffee Sales and Trauma

    The race to the bottom, or Battistelli's ludicrous assumption that granting more and more patents faster (e.g. using PACE) would be beneficial in the long run, may lead to the ultimate collapse of the EPO's value and demise of its long-earned reputation worldwide



  19. Guest Post: How Vista 10 Imposes Itself on Users of Windows

    A reader's experience being nagged by Microsoft, as documented and explained by this reader



  20. [ES] El Notorio Tirano de la EPO, Benoît Battistelli, Se Reune Con Otros Tiranos, Reportes de Que ‘Limpia’ el Consejo Administrativo

    El régimen de Battistelli, talvez la fuente de verguénza más grande, alegadamente está “cortejándo países pequeños/corruptos para asegurárse de que los delegados que votarón contra él serán remplazados”



  21. [ES] Comentadores Anónimos Debaten Si la EPO de Battistelli Puede Revocar las Pensiones de Empleados Que Se Atreveen — GASP — a Buscar Empleo Alternativo

    Una mirada a las causas de desesperación e imensa presión en la EPO, donde las pensiónes pueden ser cortadas como medio de represália y la gente puede ser negada empleo aún después de dejar la Oficina Europea de Patentes (EPO)



  22. [ES] Otra Casi Vacía Presentación de la EPO en La Hague

    El propagandístico “estudio social” de Battistelli (básicamente un montón de engañosas afirmacionesdisfrazadas como ‘investigación’) ayuda a demostrar que los empleados de la EPO no tiene absolutamente fe en la gerencia



  23. Links 21/5/2016: Manjaro Linux RC, Flock 2016 Schedule

    Links for the day



  24. USPTO Ignores a Lot of Cases Against Software Patents to Justify Resumption of More Software Patenting

    The US patent system (USPTO) is so obsessed with granting as many patents as possible -- even bogus patents in areas that are no longer patent-eligible -- that its guidelines are further perturbed and whose appeals board is massively overwhelmed/overworked/understaffed



  25. Notorious EPO Tyrant, Benoît Battistelli, Meets Other Tyrants, Reportedly 'Cleanses' the Administrative Council

    The Battistelli regime, perhaps the biggest embarrassment of Europe right now, is allegedly "courting smaller countries to make sure the delegates who voted against him will be replaced"



  26. Links 20/5/2016: Purism Tablet, ChromeOS PCs Outsell 'Mac'-Branded PCs

    Links for the day



  27. CAFC Rules Against Software Patents But Witness With Horror the Silence From Patent Lawyers (Bias by Omission)

    In an effort to protect software patents in the United States, where these patents came from in the first place (and continue to spread from), patent lawyers pretend not to see cases where software patents get invalidated and instead focus on the rare exception



  28. It's All Just Artificial Distractions From EPO Management, 'Yellow' Union Comes Under Scrutiny Again

    What's happening inside the EPO these days and what meaningless rubbish the management of the EPO would rather have the media obsessed with



  29. Anonymous Commenters Debate Whether Battistelli's EPO Can Revoke Pensions of Dismissed Employees Who Dare -- GASP -- Find Alternative Employment

    A look at causes for desperation and immense pressure at the EPO, where pensions can be cut as means of reprisal and people can be denied employment even after they leave the European Patent Office (EPO)



  30. Australian Productivity Commission's Research Calls for Ban on Software Patents, Davies Collison Cave Calls for Complaints Against This Finding

    As the push against software patents grows in Australia, much to the chagrin of Australian software developers, Davies Collison Cave (patent law firm) publicly calls for opposition, calling its side "the truth" and pretending it represents "Australian innovators."


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts