Bonum Certa Men Certa

More Microsoft Cashback Flaws, Cashback Actually a Throwback, Internet Explorer Gets More New Flaws (Zero-Day)

Cash register



Summary: Microsoft's plan to "bribe" users of its search engine are flawed and are actually costing more than they save; New risks for Internet Explorer users

LAST WEEK we wrote about a Cashback flaw that led Microsoft to intimidating and harassing a blogger rather than fixing the problem [1, 2]. Mike Masnick writes about this leading to the revelation of only more problems.



I'd been meaning to write this up for about a week, but finally got it around to it, just in time to add some additional info. First up, though, comes the news that Microsoft's legal department demanded a blogger remove a blog post about flaws in Bing's Cashback offer (Microsoft's attempt to bribe users to search via Bing instead of Google). One of the methods for the cashback offer involved pixel tracking, and blogger Samir Meghani noted that this was easily gamed to post fake transactions to your account. He also noted problems with the way Microsoft used sequential IDs, allowing potential scammers to "deny cashback rebates to legitimate users by using up available order ID numbers." Instead of dealing with these flaws, Microsoft lawyers sent a cease-and-desist and forced the blog post offline. I'm actually quite surprised this hasn't received a lot more attention.


According to this new report, Bing cashback can actually be negative, i.e. only giving an illusion of savings.

So, if I go directly to butterflyphoto.com, I pay $699 with 0% cashback. If I use Bing Cashback, I pay $758 with 2% cashback, or $742.84. Using Bing cashback has actually cost me $43.84, giving an effective cashback rate of -6.27%. Yes, negative cashback! Is this legal? False advertising? I don’t know, but it’s pretty sketchy.

The problem doesn’t end there. Using Bing has tainted my web browser. Butterfly Photo set a three month cookie on my computer to indicate that I came from Bing. Any product I look at for the next three months may show a different price than I’d get by going there directly. Just clicking a Bing link means three months of potentially negative cashback, without me ever realizing it. I’m actually afraid to use their service even just to write this, because it may cost me money in the future. If you’ve been thinking about trying out Bing Cashback, you may want to rethink that.

To be fair to Microsoft, they aren’t offering negative cashback on every item at every store, but I know of more than a few instances. Let’s see if/when they decide to remove this “feature.”


So, it turns out that there is this other flaw in Cashback, albeit of a different kind. And a few days ago we wrote about an Internet Explorer 6/7 zero-day flaw which Microsoft finally confirms.

Microsoft has published Security Advisory (977981), confirming reports of a "zero day" vulnerability in Internet Explorer 6 SP1 and IE7. If you were thinking of upgrading to IE8, this would be a good time to do it. Microsoft says there have been no known attempts to exploit the security hole, but this could change at any time.


Another major bug in Internet Explorer is said to have just leaked private details from 50 million PDF files.

A bug in Microsoft's Internet Explorer browser is causing more than 50 million files stored online to leak potentially sensitive information that could compromise user privacy, a security researcher said.


As another last item, Cameron Neylon is quoted as follows: "would you...contribute to a survey on tech uptake...survey only available to those using Windows and IE"

Glyn Moody asks: "possible bias?"

Well, of course. Many surveys are just like that. By selecting the population that they reach they can impact ("cook") the outcome. Microsoft does this a lot to discredit competition.

Recent Techrights' Posts

Cheaters and Spammers Like These Do Real Damage to Real Sites (Like AnandTech)
So-called 'Linux' sites
The Only Article in Linux.com This Month Was Not an Article But a Link (and It's SPAM)
just a link to another site
We Turn Out to Have Been Right About Rust
Rust won't vanish completely; the hype will, just like with Haskell
The Creator of GNU/Linux is in His 70s and His Manifesto Turns 40 in Half a Year
if we care about science, history, truth, honesty etc. we must go back to GNU, GPL, GCC etc.
 
Links 31/08/2024: Kremlin Targets Galina Timchenko, AnandTech Saying Goodbye
Links for the day
Links 31/08/2024: IndieWeb Rebounding, Arlington National Cemetery Incident Reveals Fascism is on the Ballots
Links for the day
Gemini Links 31/08/2024: Receipts and Tab Cleaning
Links for the day
Red Hat is Reselling Microsoft Azure (Proprietary, Surveillance, Complete With Back Doors)
promoting Microsoft's control over your computing
[Meme] The Devil's Kitchen
"In des Teufels Kuche sein"
It's FOSS or It's Microsoft?
How to distract...
Terms of Service (TOS) Under Scrutiny - Part VIII - Medical Surveillance Growing in the Amazon
A recent presentation by a reader of ours
[Meme] Microsoft Wants You to Forget...
The gaslighting abusive spouse
Links 31/08/2024: Climate, Censorship, and Conflict (CCC)
Links for the day
Gemini Links 31/08/2024: Personal Posts and Social Control Media Cross-posting
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, August 30, 2024
IRC logs for Friday, August 30, 2024
GNU/Linux Has Reached 4% in Ghana (All-Time High)
Chromebooks seem to be doing well there
[Meme] Microsoft the Security Expert of the World
Microsoft, the top security authority of the world...
The Proportion of Mobile Devices Online (as Per Web Requests) Rises to All-time High and It's a Big Problem for Microsoft
Microsoft's Windows revenues are falling and it seems like those revenues will never recover
Links 30/08/2024: Serious Abuses Against Uyghurs and Dyson Abandons Frivolous Libel Claim Amid Mass Layoffs
Links for the day
So Far This Year Microsoft Had Mass Layoffs Every Month
Yes, even this month
Gemini Links 30/08/2024: Moral Panic Against Privacy, Liminal Times, and Gopher
Links for the day
Links 30/08/2024: Antidepressants Spoil the Water, War on Encryption Carries On
Links for the day
Microsoft Windows Plunged to Levels So Low in Montenegro That Even iOS Users Apparently Outnumber Windows Users Now. We Must Still Tackle Microsoft's Crimes in Europe, Holding the Corrupt and Their Collaborators Fully Accountable.
Or European Federation will become no better than the Russian Federation (it'll repeat unless crimes are prosecuted rather than rewarded)
Certificate Authority Let's Encrypt Plunges to 1.5% of Capsules in Geminispace (90% Rightly Sign Their Own Certificates)
fake "security" ploy isn't charming the adopters of Gemini (the protocol)
Gemini Links 30/08/2024: EDM Nonsense and Growthist Priorities
Links for the day
Terms of Service (TOS) Under Scrutiny - Part VII - Pharmacies in the Age of "Online" and "App" and "Gimme Dat!"
Today we talk about pharmacies
Microsoft is Still Hurting Badly From CrowdStrike-gate (Now It Plays Dirty to Bypass Technical People)
Well, clownstrike (CrowdStrike) isn't the sole culprit
California State Assembly Has Approved S.B. 1047, Which Can be Used Against Proprietary Software
Plus, sage old advice from Capt. Grace Hopper
Moving in Positive Directions
Some news updates and causes for restrained celebration
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, August 29, 2024
IRC logs for Thursday, August 29, 2024
Links 29/08/2024: Books Banned in China, Topics Banned Online
Links for the day
Gemini Links 29/08/2024: OpenBSD as a 'Desktop' and Entering Umlauts With a US Keyboard Layout
Links for the day
The Communications Workers of America (CWA) Versus Microsoft: Exposing Union-Hostile Practices, Contrary to Misleading Media Narrative Peddled for Months Amid Mass Layoffs and FTC Antitrust Scrutiny
Months ago the Microsoft-friendly media painted Microsoft as championing the right to unionise
A Vision for Sustainable Community Consciousness
Reprinted with permission from Thomas Grzybowski
Links 29/08/2024: Chinese Cyberattacks and TikTok Lawsuits
Links for the day
Gemini Links 29/08/2024: Nostalgia, Gemlog's Split, and Changelog
Links for the day
Links 29/08/2024: TV Surveillance and GAFAM Layoffs
Links for the day
Tough Times for Microsoft in Croatia
Windows is in a freefall there
[Meme] Because Newer is Not Always Better
Unless you're a data broker
Planning Ahead
The roadmap or publication schedule spans years, not days
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, August 28, 2024
IRC logs for Wednesday, August 28, 2024
Terms of Service (TOS) Under Scrutiny - Part VI - TVs That Transmit Personal Data Everywhere, Sometimes by 'Accident'
"the world of television surveillance."
Rumour: More Layoffs on the Way at IBM (Maybe Next Week)
came through minutes ago
Gemini Links 29/08/2024: New Software/Games for PalmOS in 2024, Therioxenia, Linkrot
Links for the day