Bonum Certa Men Certa

Microsoft and Insecurity: Vulnerabilities, Botnets, and a Whole Lot of Nerve

Hand on glass



Summary: Windows insecurity a matter of persistence, Windows botnets a lost cause, and Microsoft's staff interferes with security policy

From One Critical Vulnerability to Another



THE security problems in Windows are a never-ending problem. Those patches that we mentioned last week arrived on Patch Tuesday, as usual. Here are some of last week's articles about it [1, 2, 3, 4] and indication that Microsoft may be silencing researchers again:



Microsoft Exploits Talk Dropped From RSA Agenda



An RSA Conference presentation on Microsoft (NSDQ:MSFT) application hacks and exploits that was originally slated for Tuesday was canceled, although it's unclear why.

An RSA Conference spokesperson told Channelweb.com on Tuesday that the session appears to have been canceled in early January, but didn't offer a reason for the cancellation. A Microsoft spokesperson declined to comment on whether the session was canceled at Microsoft's behest.


Whether Microsoft was behind this or not, the company definitely had been doing such things before. There's security through obscurity and security through gagging. And in other news, "Microsoft resumes XP patch distribution; says rootkit remover coming soon"

In mid-February, Microsoft halted automatic distribution of one of its Windows patches, blaming the interaction of the patch with already-present malware on users’ systems for a rash of blue-screen-of-death reports among XP users.


Microsoft would love to just blame "a rootkit", but this was caused by lack of security in the first place. It is a circular trap that still has Microsoft deserving at least some of the blame. This problem was also covered in [1, 2].

In other news, we soon learn that "patchy Windows patching leaves users insecure," according to Secunia.

Windows users need to patch their systems an average of every five days to stay ahead of security vulnerabilities, according to a study this week.

The numbers come from a company called Secunia which just happens to be developing an all-in-one patching tool to reduce update headaches for consumers.

Stats from the two million existing users of Secunia's free Personal Software Inspector tool show the average home user needs an average of 75 patches from 22 different vendors to be fully secure. The complexity of patching means that most users are not even in the race, meaning that hackers hoping to exploit software vulnerabilities to infect vulnerable systems stay well ahead of the game.

Matters are further complicated by the variety of different update mechanisms applied by differing suppliers.


Secunia says that "The core of this patching issue is that the software industry has, so far, failed to come up with a unified patching solution that can help home users on a large scale; that is, encompassing all software programs" and as our reader put it, "Doesn't Linux have a one-stop-shop for the distro? As long as you stick with the official "repository", everything can be automatically updated, including the apps."

From One Windows Botnet to Another



Microsoft has a new zero-day vulnerability in its hands and the attempt to suspend Windows botnets is of course futile. There are just too many Windows botnets out there.

Spamhaus: Microsoft's botnet cull had little effect



Microsoft's takedown of the Waledac botnet has not been effective, according to some security researchers.

The throttling of Waledac, which Microsoft claimed to have achieved by means of legal action last week, has led to no appreciable reduction of junk mail coming from the botnet, anti-spam organisation Spamhaus told ZDNet UK on Tuesday.


We wrote about the Waledac takedown in [1, 2, 3]. Here is more new information about it:

Well, criticism has come from two main areas: Firstly, as Jose Nazario of Arbor Networks Inc. , a security solutions provider, told The Wall Street Journal, the Internet addresses that Microsoft’s lawsuit brought down could be a small percentage of those used by hackers to control the network. "The botnet will survive in many cases," said Nazario.

And Richard Cox, the chief information officer at anti-spam service Spamhaus told ComputerWorld: "If this did affect spam, we haven't noticed… Waledac was not a high threat; it's less than 1% of spam traffic.”


On the face of it, Microsoft Windows may rely on Free software to secure the Web from itself.

From Microsoft to Apple



Apple is suing Linux (we covered this in [1, 2, 3, 4, 5]). Apple becomes more of a fighting company (an aggressor), not a pacifier.

Apple is also hiring from Microsoft, based on this report about Window Snyder.

Window Snyder's first day at Apple was Monday, according to PC World. While it noted that Apple was the "third browser-maker in the past five years that has employed Snyder," it did not indicate whether she would work on the Safari browser or some other technology for the Cupertino, Calif., company.


Microsoft was spreading lies about Firefox (and sometimes GNU/Linux too), but even Snyder, who had worked for Microsoft, told them off for it*. It all happened when she worked for Mozilla, but she luckily left after using her Mozilla hat to praise Microsoft. She is going to Apple now.

From US DOJ to Microsoft



Microsoft's fairly new hire from the US DOJ is upsetting many people. Scott Charney's remarks [1, 2, 3] led to some strong reactions. "Blow me," says this one article from iStockAnalyst to Microsoft:

In short, these machines are infested (not infected, infested) because their operating system has historically been full of security holes (this has improved, especially in Windows 7, to be fair.)

So what does Microsoft propose?

So who would foot the bill? "Maybe markets will make it work," Charney said. But an Internet usage tax might be the way to go. "You could say it's a public safety issue and do it with general taxation," he said.

That's nice.

Sell an insecure operating system and then get someone else to pay a tax because they bought an arguably-defective product you sold? How about this instead Microsoft?

For each computer infested, the publisher of the operating system sold to that user is assessed a fine of US $100,000 by the Department of Justice.


Here is what The Atlantic argues:

Most opponents of a tax would say that software companies should be responsible for paying, since it's their responsibility to develop a safe product. Indeed, some criticize Microsoft for advocating a tax as an excuse to spend less of their own money developing safer software.


Also see:

Microsoft's Ideas for Making PCs Safer

Microsoft's Scott Charney Calls For Disrupting Cybercrime Activities

Microsoft Security Chief proposes taxes to protect the Internet

Microsoft moots digital healthcare tax

Microsoft's Ideas for Making PCs Safer

Microsoft and the Incredible 'Internet Usage Tax'

Say It Ain't So, Microsoft

Maybe Microsoft Vice President for Trustworthy Computing Scott Charney wanted to see if his audience was really awake. Maybe he entered a time warp and thought it was April 1st. Maybe someone gave him a funny cookie. Or maybe he really didn't think it would be sheer lunacy to suggest levying an Internet tax on Americans to pay for cybersecurity.

[...]

What Were You Thinking, Scott?

Not satisfied with blaming and seeking to punish the victim, Charney then went on to suggest the imposition of a tax on Internet users to ensure cybersecurity.

"You could say it's a public safety issue and do it with general taxation," he said.

Really, Scott? Why should we the users pay for the ineptness of software vendors? And please, don't give me that tired routine about the bad guys being out there always looking for flaws.

Let's take an analogy from real life. When you're a kid your parents tell you the rules for living safely. Don't talk to strangers or take candy from them. Look both ways before you cross the street. Don't walk down dark streets or alleys at night. Never walk between a parked van and the wall, especially at night. Keep your doors locked.


Even some Microsoft boosters disagree with Microsoft on this, whereas most are unable to sincerely criticise it [1, 2, 3]. ______ * Microsoft hates real numbers, so it manufactures its own.

Recent Techrights' Posts

Gemini Links 11/01/2026: Scott Morgan and 'The Unix Way'
Links for the day
IBM to Be 'Reorganised'
The rich look for ways to 'monetise' what's left IBM
Dr. Andy Farnell Explains Why He'll Stop Sending E-mail to Microsoft and Gmail Users
The article is long and well worth reading
 
IBM SkillsBuild as Microsoft Training, Microsoft Vendor Lock-in, Microsoft Surveillance
Microsoft benefits from IBM's "training"
EPO People Power - Part XXXI - Almost No Crime is Possible Without Enablers and Complicit Colleagues
By the middle of January 2026 we'll have taken things up another gear
Aruba's GNU/Linux Adoption Seems to Have Reach All-Time High This Year
ChromeOS rose by a lot too
After the LLM Slop Frenzy...
In every way, slop is no better than spam
Links 11/01/2026: 'Nothing to Lose' in Iran and Kyiv Restores Electricity
Links for the day
Gemini Links 11/01/2026: "Late To The Party" and "Thinking About Software Licences"
Links for the day
Links 11/01/2026: Bob Weir and Stewart Cheifet Perish
Links for the day
Higher Adoption Rates of GNU/Linux in Cyprus in Recent Years
there are some Cypriots who are championing Free software
Microsoft's linkedin.com is Shrinking, Expect LinkedIn Layoffs to Carry on in 2026
Expect the mass layoffs and office closures to carry on there, maybe as early as next week
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, January 10, 2026
IRC logs for Saturday, January 10, 2026
Monday, January 12, Red Hat Layoffs Allegedly Planned
We'll update this post or follow up if or when we get more information
Slop Still Becoming Rare as Another Week Ends
Generally speaking, calm and quiet is desirable, it's what we hope for (an absence of slop, a lack of need to keep abreast of it, ultimately)
Links 10/01/2026: Iran Offline, Venezuelans Decry Civilian Casualties
Links for the day
GAFAM Wants War
Go war! Go bailouts! Go debt! Go Wall Street!
GNOME Foundation's Microsoft Developer Account
"Lately they're teaming up with Mozilla to eliminate middle click paste - something which I use continuously."
GNU/Linux and Chromebooks Rose to Almost 10% in Haiti
What's noteworthy is that this month GNU/Linux is measured at around 8% and ChromeOS at about 2%
Links 10/01/2026: "Abolish ICE or GTFO", Calls to Ban X/Twitter From Apple/Google App Stores (or Implement National Blocks) Over MElon Turning It Into Non-consensual Deepfake Porn Site
Links for the day
EPO People Power - Part XXX - New Year Starts, Cocainegate Still Discussed a Lot, António Campinos Desperate for Distraction From It
Why the sudden change or 'generosity'? [...] Actual cocaine addicts caused nervous breakdowns among sober people
2026 Might be the Year Microsoft Replaces Layoffs With Mass Firings (No Severance Payments to Dismissed Staff)
It's hard to "see" PIPs unless insiders blow the whistle
IBM and Microsoft Hiding Layoffs in Similar, Overlapping Ways
Performance Improvement Plans aplenty
IBM is a Cancer That Attaches Itself to Everything
Red Hat should have remained an independent company
Links 10/01/2026: STV Layoffs (Scottish TV), “CBS Evening News” in Chaos (Culls and Censorship by the US Regime)
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, January 09, 2026
IRC logs for Friday, January 09, 2026
Gemini Links 10/01/2026: Blackout, E-Waste, and Secondary Smartphone
Links for the day
Plot Twist: Microsoft MSN Relays Articles Hinting at or Pointing to Mass Layoffs Soon, Other Gossip
the narrative from Microsoft's "PR bunny" (Shaw) is showing mold already
Links 09/01/2026: Google and Character.AI Implicitly Accept Chatbots Kill Kids and GLP-1 ‘Slimming Pens’ Turn Out to be a Lot Worse Than Advertised
Links for the day
'Vibe Coding' is Not "AI", It's a Sewer, It is Junk
Linus Torvalds was wrong. 'Vibe coding' isn't good for anything.
GNU/Linux May be Approaching 10% "Market Share" in Montenegro
The surge started around 2021
At IBM, "Employee Reviews" (or Appraisals in the UK) Are a "Trojan Horse" for RAs (Mass Layoffs), a Waste of Time
comments from IBMer serve to suggest that appraisals can be precursors
Links 09/01/2026: Technical Blogging Lessons Learned and Google's Gmail Getting a Lot Worse
Links for the day
More IBM Layoffs in India
If IBM cannot afford to retain workers in India, then something is truly "out of control" at IBM
Escaping GAFAM Colonialism Requires Homegrown Free Software
GNU/Linux now measured at 3% in Zambia
Dr. Richard Stallman Has Done No Harm to the GNU Project or the FSF (He Had Benefited Both, Always, Even After the Attacks on Him Began)
Some people try to prevent Dr. Stallman from speaking or having a platform where many people can hear him
GNU/Linux at 4% in Saudi Arabia, Says statCounter
Some years ago Windows fell to a "market share" of just 11% there
Microsoft Isn't Denying the Mass Layoffs
Still silence from Microsoft
In Western Africa GNU/Linux Flirts With 5% Market Share
there's a gradual increase in GNU/Linux usage there
Gemini Links 09/01/2026: Pro1 X Repair and the Mercury Protocol
Links for the day
Links 09/01/2026: Cambodia and China Extradition, "NATO’s High-risk Patrols Near Ukraine"
Links for the day
No, Microsoft Did Not Deny the Q1 Mass Layoffs (Microsoft Can Delay These)
Maybe they disperse or delay the layoffs (changing plans), but the layoffs are going to happen
Only One Person in Charge of Fedora is Not IBM Staff
This is not a community project, it's just a way for IBM to onboard unpaid volunteers
This Is Not a Drill, GNU/Linux is Really Going 'Mainstream' on Laptops (and Desktops)
It is important to explain to people software freedom
IBM Albany Layoffs
not only did many in the site lose their job; there's more to come "and likely another one in February" (weeks from now)
EPO Workers' Industrial Action to Include Many Strikes, to Last Several Months
In some ways, The Hague and Bavaria are becoming almost indistinguishable from Moscow
EPO People Power - Part XXIX - Getting DER SPIEGEL, FAZ, Deutschlandfunk and Sueddeutsche Zeitung (SZ) to Cover EPO Scandals
We kindly ask our readers to contact their local media and urge it to cover the scandals
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, January 08, 2026
IRC logs for Thursday, January 08, 2026