11.16.09

Gemini version available ♊︎

Microsoft Won’t Secure Firefox/Chrome Users, Shows More Negligence

Posted in Microsoft, Security, Vista 7, Windows at 9:19 am by Dr. Roy Schestowitz

Web browser icons

Summary: ActiveX required by Microsoft’s OneCare; investigation into Vista 7 vulnerabilities a case of “too little, too late”

MICROSOFT pretends to have changed for the better. It pretends that it allows users of Windows to use Web browsers other than Internet Explorer, but the following post — artistically titled “Microsoft being a Onecare [Wanker]“ — suggests otherwise:

For starters, it uses an ActiveX control – Internet Explorer required in other words – that’s annoyingly hard to install. You get warnings galore from Windows 7′s UAC and IE about popups and do you really really really want to install something that has the potential to roger your system well and truly?

ActiveX was designed to restrict competition by supplanting Web standards. It ended up becoming one of the biggest security nightmares out there and Novell supports this.

Here is the new story of a man who has just been fired because of these practices from Microsoft:

Linux Contractor Fired for Using Firefox/Linux

[...]

The irony? The “compentency test” was a Security & Privacy test from the four letter credit card company that HAD to be taken on MS Windows with IE?

I’ll let you be the ones to point out the obvious…the fact that this large computer/server company with three letters in their name is reportedly a “friend to Linux”. I’ll let you talk about how a Linux Professional who uses Linux as their desktop environment was denied access to employment. Employment that was based on his knowledge of Linux. Yeah, the server side…but still…

Now let’s brag about how much ground Linux has made…

And a Linux Project Manager for said company asking the question:

“What’s this Foxfire thing?”

As a secondary item of news, some days ago we argued for Microsoft liability when it comes to the latest Vista 7 vulnerability. Microsoft deserves to be accused of negligence and the following article implies deception too.

Is Microsoft Overhyping Security In Windows 7?

[...]

Microsoft has been aggressively marketing the security improvements in Windows 7, but some security experts believe this strategy could leave the software giant open to some unpleasant repercussions.

Vista 7 has been breached before and to give some examples of insecurity, we have:

Now there is the SMB flaw that Microsoft finally acknowledges.

Microsoft on Friday said it is working on a fix for a vulnerability in the Server Message Block file-sharing protocol in Windows 7 and Windows Server 2008 Release 2 that could be used to remotely crash a computer.

It really took them too long, having waited for attack code to appear before properly investigating. That’s negligence and it is irresponsible. Gregg Keizer writes:

The zero-day vulnerability was first reported by Canadian researcher Laurent Gaffie last Wednesday, when he revealed the bug and posted proof-of-concept attack code to the Full Disclosure security mailing list and his blog. According to Gaffie, exploiting the flaw crashes Windows 7 and Server 2008 R2 systems so thoroughly that the only recourse is to manually power off the computers.

Why has Microsoft waited so long before looking into the problem? Could it be that lack of security and increased fear help Microsoft sell more ‘solutions’ to those very same problems? As we showed some days ago, is clearly profiting from Conficker, for example.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

A Single Comment

  1. Needs Sunlight said,

    November 16, 2009 at 11:17 am

    Gravatar

    A verdict of Negligence would assume a competency or willingness to fix the problem. Likely neither are present in any measurable quantity.

    From the outside it looks more like a case of further anti-competitive behavior.

DecorWhat Else is New


  1. Links 30/05/2023: LibreOffice 7.6 in Review and More Digital Restrictions (DRM) From HP

    Links for the day



  2. Gemini Links 30/05/2023: Curl Still Missing the Point?

    Links for the day



  3. IRC Proceedings: Monday, May 29, 2023

    IRC logs for Monday, May 29, 2023



  4. MS (Mark Shuttleworth) as a Microsoft Salesperson

    Canonical isn’t working for GNU/Linux or for Ubuntu; it’s working for “business partners” (WSL was all along about promoting Windows)



  5. First Speaker in Event for GNU at 40 Called for Resignation/Removal of GNU's Founder

    It’s good that the FSF prepares an event to celebrate GNU’s 40th anniversary, but readers told us that the speakers list is unsavoury, especially the first one (a key participant in the relentless campaign of defamation against the person who started both GNU and the FSF; the "FSFE" isn't even permitted to use that name)



  6. When Jokes Became 'Rude' (or Disingenuously Misinterpreted by the 'Cancel Mob')

    A new and more detailed explanation of what the wordplay around "pleasure card" actually meant



  7. Site Updates and Plans Ahead

    A quick look at or a roundup of what we've been up to, what we plan to publish in the future, what topics we shall focus on very soon, and progress moving to Alpine Linux



  8. Links 29/05/2023: Snap and PipeWire Plans as Vendor Lock-in

    Links for the day



  9. Gemini Links 29/05/2023: GNU/Linux Pains and More

    Links for the day



  10. Links 29/05/2023: Election in Fedora, Unifont 15.0.04

    Links for the day



  11. Gemini Links 29/05/2023: Rosy Crow 1.1.1 and Smolver 1.2.1 Released

    Links for the day



  12. IRC Proceedings: Sunday, May 28, 2023

    IRC logs for Sunday, May 28, 2023



  13. Daniel Stenberg Knows Almost Nothing About Gemini and He's Likely Just Protecting His Turf (HTTP/S)

    The man behind Curl, Daniel Stenberg, criticises Gemini; but it's not clear if he even bothered trying it (except very briefly) or just read some inaccurate, one-sided blurbs about it



  14. Links 29/05/2023: Videos Catchup and Gemini FUD

    Links for the day



  15. Links 28/05/2023: Linux 6.4 RC4 and MX Linux 23 Beta

    Links for the day



  16. Gemini Links 28/05/2023: Itanium Day, GNUnet DHT, and More

    Links for the day



  17. Links 28/05/2023: eGates System Collapses, More High TCO Stories (Microsoft Windows)

    Links for the day



  18. IRC Proceedings: Saturday, May 27, 2023

    IRC logs for Saturday, May 27, 2023



  19. No More Twitter, Mastodon, and Diaspora for Tux Machines (Goodbye to Social Control Media)

    People would benefit from mass abandonment of such pseudo-social pseudo-media.



  20. Links 28/05/2023: New Wine and More

    Links for the day



  21. Links 27/05/2023: Plans Made for GNU's 40th Anniversary

    Links for the day



  22. Social Control Media Needs to be Purged and We Need to Convince Others to Quit It Too (to Protect Ourselves as Individuals and as a Society)

    With the Tux Machines anniversary (19 years) just days away we seriously consider abandoning all social control media accounts of that site, including Mastodon and Diaspora; social control networks do far more harm than good and they’ve gotten a lot worse over time



  23. Anonymously Travelling: Still Feasible?

    The short story is that in the UK it's still possible to travel anonymously by bus, tram, and train (even with shades, hat and mask/s on), but how long for? Or how much longer have we got before this too gets banned under the false guise of "protecting us" (or "smart"/"modern")?



  24. With EUIPO in Focus, and Even an EU Kangaroo Tribunal, EPO Corruption (and Cross-Pollination With This EU Agency) Becomes a Major Liability/Risk to the EU

    With the UPC days away (an illegal and unconstitutional kangaroo court system, tied to the European Union in spite of critical deficiencies) it’s curious to see EPO scandals of corruption spilling over to the European Union already



  25. European Patent Office (EPO) Management Not Supported by the EPO's Applicants, So Why Is It Still There?

    This third translation in the batch is an article similar to the prior one, but the text is a bit different (“Patente ohne Wert”)



  26. EPO Applicants Complain That Patent Quality Sank and EPO Management Isn't Listening (Nor Caring)

    SUEPO has just released 3 translations of new articles in German (here is the first of the batch); the following is the second of the three (“Kritik am Europäischen Patentamt – Patente ohne Wert?”)



  27. German Media About Industry Patent Quality Charter (IPQC) and the European Patent Office (EPO)

    SUEPO has just released 3 translations of new articles in German; this is the first of the three (“Industrie kritisiert Europäisches Patentamt”)



  28. Geminispace Continues to Grow Even If (or When) Stéphane Bortzmeyer Stops Measuring Its Growth

    A Gemini crawler called Lupa (Free/libre software) has been used for years by Stéphane Bortzmeyer to study Gemini and report on how the community was evolving, especially from a technical perspective; but his own instance of Lupa has produced no up-to-date results for several weeks



  29. Links 27/05/2023: Goodbyes to Tina Turner

    Links for the day



  30. HMRC: You Can Click and Type to Report Crime, But No Feedback or Reference Number Given

    The crimes of Sirius ‘Open Source’ were reported 7 days ago to HMRC (equivalent to the IRS in the US, more or less); but there has been no visible progress and no tracking reference is given to identify the report


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts