EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

03.10.10

Microsoft and Insecurity: Vulnerabilities, Botnets, and a Whole Lot of Nerve

Posted in Apple, Free/Libre Software, GNU/Linux, Microsoft, Security, Windows at 4:29 am by Dr. Roy Schestowitz

Hand on glass

Summary: Windows insecurity a matter of persistence, Windows botnets a lost cause, and Microsoft’s staff interferes with security policy

From One Critical Vulnerability to Another

THE security problems in Windows are a never-ending problem. Those patches that we mentioned last week arrived on Patch Tuesday, as usual. Here are some of last week’s articles about it [1, 2, 3, 4] and indication that Microsoft may be silencing researchers again:

Microsoft Exploits Talk Dropped From RSA Agenda

An RSA Conference presentation on Microsoft (NSDQ:MSFT) application hacks and exploits that was originally slated for Tuesday was canceled, although it’s unclear why.

An RSA Conference spokesperson told Channelweb.com on Tuesday that the session appears to have been canceled in early January, but didn’t offer a reason for the cancellation. A Microsoft spokesperson declined to comment on whether the session was canceled at Microsoft’s behest.

Whether Microsoft was behind this or not, the company definitely had been doing such things before. There’s security through obscurity and security through gagging. And in other news, “Microsoft resumes XP patch distribution; says rootkit remover coming soon”

In mid-February, Microsoft halted automatic distribution of one of its Windows patches, blaming the interaction of the patch with already-present malware on users’ systems for a rash of blue-screen-of-death reports among XP users.

Microsoft would love to just blame “a rootkit”, but this was caused by lack of security in the first place. It is a circular trap that still has Microsoft deserving at least some of the blame. This problem was also covered in [1, 2].

In other news, we soon learn that “patchy Windows patching leaves users insecure,” according to Secunia.

Windows users need to patch their systems an average of every five days to stay ahead of security vulnerabilities, according to a study this week.

The numbers come from a company called Secunia which just happens to be developing an all-in-one patching tool to reduce update headaches for consumers.

Stats from the two million existing users of Secunia’s free Personal Software Inspector tool show the average home user needs an average of 75 patches from 22 different vendors to be fully secure. The complexity of patching means that most users are not even in the race, meaning that hackers hoping to exploit software vulnerabilities to infect vulnerable systems stay well ahead of the game.

Matters are further complicated by the variety of different update mechanisms applied by differing suppliers.

Secunia says that “The core of this patching issue is that the software industry has, so far, failed to come up with a unified patching solution that can help home users on a large scale; that is, encompassing all software programs” and as our reader put it, “Doesn’t Linux have a one-stop-shop for the distro? As long as you stick with the official “repository”, everything can be automatically updated, including the apps.”

From One Windows Botnet to Another

Microsoft has a new zero-day vulnerability in its hands and the attempt to suspend Windows botnets is of course futile. There are just too many Windows botnets out there.

Spamhaus: Microsoft’s botnet cull had little effect

Microsoft’s takedown of the Waledac botnet has not been effective, according to some security researchers.

The throttling of Waledac, which Microsoft claimed to have achieved by means of legal action last week, has led to no appreciable reduction of junk mail coming from the botnet, anti-spam organisation Spamhaus told ZDNet UK on Tuesday.

We wrote about the Waledac takedown in [1, 2, 3]. Here is more new information about it:

Well, criticism has come from two main areas: Firstly, as Jose Nazario of Arbor Networks Inc. , a security solutions provider, told The Wall Street Journal, the Internet addresses that Microsoft’s lawsuit brought down could be a small percentage of those used by hackers to control the network. “The botnet will survive in many cases,” said Nazario.

And Richard Cox, the chief information officer at anti-spam service Spamhaus told ComputerWorld: “If this did affect spam, we haven’t noticed… Waledac was not a high threat; it’s less than 1% of spam traffic.”

On the face of it, Microsoft Windows may rely on Free software to secure the Web from itself.

From Microsoft to Apple

Apple is suing Linux (we covered this in [1, 2, 3, 4, 5]). Apple becomes more of a fighting company (an aggressor), not a pacifier.

Apple is also hiring from Microsoft, based on this report about Window Snyder.

Window Snyder’s first day at Apple was Monday, according to PC World. While it noted that Apple was the “third browser-maker in the past five years that has employed Snyder,” it did not indicate whether she would work on the Safari browser or some other technology for the Cupertino, Calif., company.

Microsoft was spreading lies about Firefox (and sometimes GNU/Linux too), but even Snyder, who had worked for Microsoft, told them off for it*. It all happened when she worked for Mozilla, but she luckily left after using her Mozilla hat to praise Microsoft. She is going to Apple now.

From US DOJ to Microsoft

Microsoft’s fairly new hire from the US DOJ is upsetting many people. Scott Charney’s remarks [1, 2, 3] led to some strong reactions. “Blow me,” says this one article from iStockAnalyst to Microsoft:

In short, these machines are infested (not infected, infested) because their operating system has historically been full of security holes (this has improved, especially in Windows 7, to be fair.)

So what does Microsoft propose?

So who would foot the bill? “Maybe markets will make it work,” Charney said. But an Internet usage tax might be the way to go. “You could say it’s a public safety issue and do it with general taxation,” he said.

That’s nice.

Sell an insecure operating system and then get someone else to pay a tax because they bought an arguably-defective product you sold?
How about this instead Microsoft?

For each computer infested, the publisher of the operating system sold to that user is assessed a fine of US $100,000 by the Department of Justice.

Here is what The Atlantic argues:

Most opponents of a tax would say that software companies should be responsible for paying, since it’s their responsibility to develop a safe product. Indeed, some criticize Microsoft for advocating a tax as an excuse to spend less of their own money developing safer software.

Also see:

Microsoft’s Ideas for Making PCs Safer

Microsoft’s Scott Charney Calls For Disrupting Cybercrime Activities

Microsoft Security Chief proposes taxes to protect the Internet

Microsoft moots digital healthcare tax

Microsoft’s Ideas for Making PCs Safer

Microsoft and the Incredible ‘Internet Usage Tax’

Say It Ain’t So, Microsoft

Maybe Microsoft Vice President for Trustworthy Computing Scott Charney wanted to see if his audience was really awake. Maybe he entered a time warp and thought it was April 1st. Maybe someone gave him a funny cookie. Or maybe he really didn’t think it would be sheer lunacy to suggest levying an Internet tax on Americans to pay for cybersecurity.

[...]

What Were You Thinking, Scott?

Not satisfied with blaming and seeking to punish the victim, Charney then went on to suggest the imposition of a tax on Internet users to ensure cybersecurity.

“You could say it’s a public safety issue and do it with general taxation,” he said.

Really, Scott? Why should we the users pay for the ineptness of software vendors? And please, don’t give me that tired routine about the bad guys being out there always looking for flaws.

Let’s take an analogy from real life. When you’re a kid your parents tell you the rules for living safely. Don’t talk to strangers or take candy from them. Look both ways before you cross the street. Don’t walk down dark streets or alleys at night. Never walk between a parked van and the wall, especially at night. Keep your doors locked.

Even some Microsoft boosters disagree with Microsoft on this, whereas most are unable to sincerely criticise it [1, 2, 3].
______
* Microsoft hates real numbers, so it manufactures its own.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 25/5/2019: Wine 4.9 Released, FreeBSD 11.3 Beta, Telegram Launches Fift

    Links for the day



  2. Links 24/5/2019: PostgreSQL 12 Beta 1 and Rust 1.35 Released

    Links for the day



  3. EPO Strikes Further Diminish Chances of UPC Ever Materialising (in Any Shape or Form)

    The EPO crumbles under the weight of its own corruption while an increasingly-insane Team UPC pretends all remains normal and a patent trolls-friendly system is ready to take off



  4. EPO Allegedly Becoming Insolvent (Pretext for Cuts), So Staff Gets Punished While Management Takes the Jackpot

    The corporate 'logic' at the EPO follows the "shareholders' value" propaganda line as if the EPO is a private company looking to maximise revenue rather than serve the public



  5. EPO President Still Not Obeying Courts' Rulings

    Federation of International Civil Service Associations (FICSA) sent a message to António Campinos yesterday (the same day SUEPO publicly made a call for strike)



  6. António Campinos Has Run Out of Time and EPO Staff is Going on Strike (Skipping Mere Protests)

    European Patent Office strikes are to resume; as SUEPO recently put it, people have come to accept that EPO leadership has not really changed and none of the underlying issues is being tackled



  7. Links 23/5/2019: Elisa 0.4.0, OpenSUSE Leap 15.1 Released

    Links for the day



  8. Links 22/5/2019: Mesa 19.0.5, Huawei and GNU/Linux, Curl 7.65.0, End of Antergos, Tails 3.14, ownCloud Server 10.2, Firefox 67.0

    Links for the day



  9. Quality of Patents is Going Down the Drain and Courts Have Certainly Noticed

    Uncertainty or lack of confidence in the patent system has reached appalling levels because heads of patent offices are just striving to grant as many patents as possible, irrespective of the underlying law



  10. EUIPO and EPO Abuses Growingly Inseparable

    'Musical chairs' at CEIPI and the EPO/EUIPO (Battistelli, Archambeau, Campinos) as well as joint reports never fail to reveal the extent to which EPO abuses are spreading



  11. Links 21/5/2019: China's GAFAM Exit, DragonFlyBSD 5.4.3

    Links for the day



  12. Links 20/5/2019: Linux 5.2 RC1, LibreOffice 6.3 Alpha, DXVK 1.2.1, Bison 3.4 Released

    Links for the day



  13. South Korea's Government Will Show If Microsoft Loves Linux or Just Attacks It Very Viciously Like It Did in Munich

    Microsoft's hatred of all things GNU/Linux is always put to the test when someone 'dares' use it outside Microsoft's control and cash cows (e.g. Azure and Vista 10/WSL); will Microsoft combat its longstanding urge to corrupt or oust officials with the courage to say "no" to Microsoft?



  14. Links 19/5/2019: KDE Applications 19.04.1 in FlatHub and GNU/Linux Adoption

    Links for the day



  15. The War on Patent Quality

    A look at the EPO's reluctance to admit errors and resistance to the EPC, which is its very founding document



  16. Watchtroll, Composed by Patent Trolls, Calls the American Patent System “Corrupt”

    Another very fine piece from Watchtroll comes from very fine patent trolls who cheer for Donald Trump as if he's the one who tackles corruption rather than spreading it



  17. Unified Patent Court Won't Happen Just Because the Litigation Microcosm Wants It

    Unified Patent Court (UPC) hopefuls are quote-mining and cherry-picking to manufacture the false impression that the UPC is just around the corner when in reality the UPC is pretty much dead (but not buried yet)



  18. Links 17/5/2019: South Korea's GNU/Linux Pivot, Linux 5.1.3

    Links for the day



  19. Q2 Midterm Weather Forecast for EPOnia, Part 4: Happy Birthday to the Kötter Group?

    This year the Kötter Group commemorates the 85th anniversary of its existence. But is it really a cause for celebration or would a less self-congratulatory approach be more fitting? And does it create the risk that a routine tendering exercise at the EPO will turn into Operation Charlie Foxtrot?



  20. Links 16/5/2019: Cockpit 194, VMware Acquires Bitnami, Another Wine Announcement and Krita 4.2.0 Beta

    Links for the day



  21. The EPO's Key Function -- Like the UPC's Vision -- Has Virtually Collapsed

    The EPO no longer issues good patents and staff is extremely unhappy; but the Office tries to create an alternate (false) reality and issues intentionally misleading statements



  22. Stanford's NPE Litigation Database Makes a Nice Addition in the Fight Against Software Patent Trolls

    As the United States of America becomes less trolls- and software patents-friendly (often conflated with plaintiff (un)friendliness) it's important to have accurate data which documents the numbers and motivates better policy; The NPE (troll) Litigation Database is a move towards that and it's free to access/use



  23. Q2 Midterm Weather Forecast for EPOnia, Part 3: “Ein kritikwürdiges Unternehmen”

    A brief account of some further controversies in which the Kötter Group has been involved and its strained relations with German trade unions such as Verdi



  24. EPO Had a Leakage Problem and Privacy of Stakeholders Was Compromised, Affecting at Least 100 Cases

    The confidentiality principle was compromised at the EPO and stakeholders weren't told about it (there was a coverup)



  25. Links 15/5/2019: More Linux Patches and More Known Intel Bugs

    Links for the day



  26. False Hope for Patent Maximalists and Litigation Zealots

    Patent litigation predators in the United States, along with Team UPC in Europe, are trying to manufacture optimistic predictions; a quick and rather shallow critical analysis reveals their lies and distortions



  27. The Race to the Bottom of Patent Quality at the EPO

    The EPO has become more like a rubber-stamper than a patent office — a fact that worries senior staff who witnessed this gradual and troublesome transition (from quality to raw quantity)



  28. Q2 Midterm Weather Forecast for EPOnia, Part 2: Meet the Kötters

    An introduction to the Kötter Group, the private security conglomerate which is lined up for the award of a juicy EUR 30 million contract for the provision of security services at the EPO



  29. Links 14/5/2019: Red Hat Satellite 6.5, NVIDIA 430.14 Linux Driver and New Security Bug (MDS)

    Links for the day



  30. Links 14/5/2019: GNU/Linux in Kerala, DXVK 1.2, KDE Frameworks 5.58.0 Released

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts