EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

12.14.09

Microsoft Hides Its Own Flaws, Cheats Customers

Posted in Deception, Microsoft, Security, Windows at 6:48 am by Dr. Roy Schestowitz

Haha, very funny pig
Even swine flu vaccines are delivered
more quickly than Microsoft patches

Summary: Microsoft delivers patches only after customers are attacked (despite having prior warnings) and then cheats when it comes to the number of patches it issues

ACCORDING TO PC Magazine, Microsoft neglects to look for its own bugs.

Sotirov noted that it’s TippingPoint’s and VeriSign’s customers who were paying for this research and that Microsoft should be paying too. Surely, I asked, Microsoft does vulnerability research on their own product. At this point another famous researcher, Dino Dai Zovi, piped in to say no: “Apple is the only vendor that I know of that releases patches for vulns found internally.”

This rang true; I know I’ve read Apple advisories that credited internal research and I couldn’t recall a Microsoft advisory that credited their own. I looked and not a single vulnerability disclosure (so far) in 2009 was credited explicitly to Microsoft. I asked Microsoft about it.

Their answer… Well, of course they look for and find these things, but not so much.

Microsoft’s negligence may justify lawsuits. To make matters worse, Microsoft lies about security, usually by hiding known flaws. The following new report from IDG is very damaging: “Microsoft knew of just-patched IE zero-day for months”

Microsoft may not have hustled as fast as researchers thought when the company patched a zero-day bug in Internet Explorer (IE) just 18 days after exploit code went public.

According to VeriSign iDefense, Microsoft had information about the browser bug nearly six months before the researcher dubbed “K4mr4n” posted attack code to the Bugtraq security mailing list on Nov. 20.

More hidden patches have just arrived.

Microsoft Releases Surprise Advisory

Hidden behind the Patch Tuesday updates, Microsoft released two separate security advisories and one set of updates that were not mentioned in the advance notification.

Regarding the latest Internet Explorer (IE) flaw that we wrote about before [1, 2, 3], Microsoft gives too little, too late, and being a zero-day flaw, damage has already been done.

Probably the most important update for most users is the one for Internet Explorer, which corrects five critical flaws in IE 6, 7 and 8. These are vulnerabilities that attackers could exploit to quietly install malicious software on your machine if you browse with IE to a hacked or booby-trapped site.

This only justifies the use of non-IE Web browsers. The way in which Microsoft delivers security updates is already being exploited [1, 2] to actually push malware rather than a fix.

Malware distributors continue resorting to the fake software update lure for their email spam campaigns. The latest attack poses as a notification regarding a Windows security bulletin, which links to a malicious executable.

The rogue emails impersonate Steve Lipner, Microsoft’s Director of Security Assurance, who allegedly informs the receiver about a high-priority security update for all versions of Windows. “Please notice that Microsoft company has recently issued a Security Update for OS Microsoft Windows. The update applies to the following OS versions: Microsoft Windows 2000, Microsoft Windows Millenium [sic], Microsoft Windows XP, Microsoft Windows Vista and Microsoft Windows 7,” the fake message reads.

It remains the job of some GNU/Linux-powered gateways to keep Windows more secure.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. IRC Proceedings: Sunday, February 16, 2020

    IRC logs for Sunday, February 16, 2020



  2. Links 16/2/2020: MX Linux 19.1 and MyPaint 2.0

    Links for the day



  3. IRC Proceedings: Saturday, February 15, 2020

    IRC logs for Saturday, February 15, 2020



  4. Guest Article: Au Revoir, GNU/Linux

    "Funny how OSI just ended up being another vehicle for their takeover of the computing world..."



  5. Former Microsoft Employee: ZDNet is Owned by Microsoft (and Others) in Some Senses

    A noteworthy message we've received from someone who knows Microsoft from the inside



  6. Links 15/2/2020: Blender 2.82, Qt 5.15 Alpha and NetBSD 9.0 Released

    Links for the day



  7. Microsoft Views 'Open Source' as a Zero-Cost Heist Opportunity (Making Proprietary Software/Spyware Using Other People's Free Labour)

    Making GPL-licensed (copyleft) software and hosting it outside Microsoft’s jaws is the best way to counter the abusive monopolist, which still says it “loves” what it is actually attacking



  8. Did Microsoft 'Buy' ZDNet?

    A look at what ZDNet tells its readers (screenshot from this morning) and a rare look at how its writers are censored/suppressed



  9. Anatomy of a Crime and Protection From Prosecution

    It’s hard to forget what António Campinos hides for his friend



  10. Today's EPO is a Fraud Managed by Frauds

    Beneath the scandals associated with systematic abuse against staff, union-busting (silencing whistleblowers) and en masse granting of invalid patents — the hallmark of grotesque maladministration — lie a bunch of even greater crimes



  11. IRC Proceedings: Friday, February 14, 2020

    IRC logs for Friday, February 14, 2020



  12. One Need Only Look at ZDNet's 'Linux' Section to Understand It's a Microsoft Propaganda Operation

    A timely new snapshot (or screenshot) that demonstrates what ZDNet became after hiring Microsoft employees as ‘journalists’ and censoring on behalf of Microsoft, defaming Free software figures and so on



  13. Links 14/2/2020: New Release of KStars, OpenSSH 8.2, Rhythmbox 3.4.4, Flatpak 1.6.2

    Links for the day



  14. The Uselessness of Social Control Media and Why We Need RSS Feeds' Resurgence More Than Ever

    Social control media became pure noise or misinformation, usually in pursuit of financial expansion alone, and it is also a censorship machine which discourages not falsehoods but unconventional thinking



  15. Another New 'Clown' for the UPC 'Circus'

    A former writer of IPPro Magazine (which seems to be defunct now) reports another shuffle -- perhaps the fifth in a few years -- of "IP" [sic] Minister for the UK; it doesn't bode well for the Unified Patent Court (UPC)



  16. IRC Proceedings: Thursday, February 13, 2020

    IRC logs for Thursday, February 13, 2020



  17. Links 13/2/2020: Ubuntu 18.04.4 LTS, Septor 2020, Endless OS 3.7.7, Wayland 1.18.0, KDE Plasma 5.18 and GTK 3.98 Released

    Links for the day



  18. The Microsoft Propaganda Model

    Classic new examples (real screenshots) of how Microsoft-funded media entraps people looking for information about "Linux" to actually push Microsoft talking points and marketing, cover-up, face-saving lies etc.



  19. What's Evil is Forcing People to Use Something They Don't Want and Typically Dislike

    The difference between Google Search and Microsoft is that many people actually want to use Google (and don't have to)



  20. 2020: The Year Microsoft Became Honest... About Being Corrupt and Criminal

    Microsoft is destroying any past attempts to portray itself as a reformed company or 'recovering criminal'; nothing is really changing and everyone has noticed



  21. Free Software is Being Abandoned by Opponents of Software Patents and It's Being Attacked by Patent Trolls

    The Electronic Frontier Foundation (EFF) is rotting away as an advocate against software patents; Patents on algorithms are still being granted (even when courts repeatedly reject these) and Red Hat's Chief Patent Counsel remains Manny Schecter, one of the loudest proponents of such patents (citing the likes of Adam Mossoff this week, in effect Koch operatives); this is a very big problem because Free software projects come under a barrage of lawsuits, using patents like those IBM lobbies ferociously to legitimise



  22. IRC Proceedings: Wednesday, February 12, 2020

    IRC logs for Wednesday, February 12, 2020



  23. Links 12/2/2020: KDE Neon 5.18, Tails 4.3 and WordPress 5.4 Beta

    Links for the day



  24. IRC Proceedings: Tuesday, February 11, 2020

    IRC logs for Tuesday, February 11, 2020



  25. Links 11/2/2020: New Firefox and KDE Plasma

    Links for the day



  26. Sometimes ILO-AT is Good for Nothing But Law Firms in or Around Switzerland

    ILO-AT’s latest judgements are out. But ILO — and by extension the UN — are still morally deficient and they give the impression that don’t care about people (or that ILO is in bed with the same businesses WIPO (UN) serves, i.e. no better than WB/IMF).



  27. The European Patent Office Continues to Violate the European Patent Convention (EPC) With Impunity While the European Commission Lets That Happen

    The European Commission (and Union) can be seen as increasingly complicit in the EPO's abuses; this means that the EPO has become a liability or source of accountability for the integrity of Europe as a bloc



  28. IRC Proceedings: Monday, February 10, 2020

    IRC logs for Monday, February 10, 2020



  29. EPO Staff Representatives to Challenge Ridiculous and Unnecessary Austerity Measures

    The EPO's President of Nepotism "is currently finalizing his “package” of financial measures in order to reduce an alleged coverage gap of 5.8 B€ following a heavily biased and flawed Financial Study," according to EPO staff representatives who have already demonstrated it's a fake crisis that distracts from the real crisis and profound corruption



  30. You're Almost Guaranteed to Lose the Argument When You Call People Who Plant Seeds 'Pirates'

    The EPO's patent maximalists are damaging the reputation of the institution and harm its perceived legitimacy (people are getting fed up instead of fed)


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts