03.10.10

Gemini version available ♊︎

Microsoft and Insecurity: Vulnerabilities, Botnets, and a Whole Lot of Nerve

Posted in Apple, Free/Libre Software, GNU/Linux, Microsoft, Security, Windows at 4:29 am by Dr. Roy Schestowitz

Hand on glass

Summary: Windows insecurity a matter of persistence, Windows botnets a lost cause, and Microsoft’s staff interferes with security policy

From One Critical Vulnerability to Another

THE security problems in Windows are a never-ending problem. Those patches that we mentioned last week arrived on Patch Tuesday, as usual. Here are some of last week’s articles about it [1, 2, 3, 4] and indication that Microsoft may be silencing researchers again:

Microsoft Exploits Talk Dropped From RSA Agenda

An RSA Conference presentation on Microsoft (NSDQ:MSFT) application hacks and exploits that was originally slated for Tuesday was canceled, although it’s unclear why.

An RSA Conference spokesperson told Channelweb.com on Tuesday that the session appears to have been canceled in early January, but didn’t offer a reason for the cancellation. A Microsoft spokesperson declined to comment on whether the session was canceled at Microsoft’s behest.

Whether Microsoft was behind this or not, the company definitely had been doing such things before. There’s security through obscurity and security through gagging. And in other news, “Microsoft resumes XP patch distribution; says rootkit remover coming soon”

In mid-February, Microsoft halted automatic distribution of one of its Windows patches, blaming the interaction of the patch with already-present malware on users’ systems for a rash of blue-screen-of-death reports among XP users.

Microsoft would love to just blame “a rootkit”, but this was caused by lack of security in the first place. It is a circular trap that still has Microsoft deserving at least some of the blame. This problem was also covered in [1, 2].

In other news, we soon learn that “patchy Windows patching leaves users insecure,” according to Secunia.

Windows users need to patch their systems an average of every five days to stay ahead of security vulnerabilities, according to a study this week.

The numbers come from a company called Secunia which just happens to be developing an all-in-one patching tool to reduce update headaches for consumers.

Stats from the two million existing users of Secunia’s free Personal Software Inspector tool show the average home user needs an average of 75 patches from 22 different vendors to be fully secure. The complexity of patching means that most users are not even in the race, meaning that hackers hoping to exploit software vulnerabilities to infect vulnerable systems stay well ahead of the game.

Matters are further complicated by the variety of different update mechanisms applied by differing suppliers.

Secunia says that “The core of this patching issue is that the software industry has, so far, failed to come up with a unified patching solution that can help home users on a large scale; that is, encompassing all software programs” and as our reader put it, “Doesn’t Linux have a one-stop-shop for the distro? As long as you stick with the official “repository”, everything can be automatically updated, including the apps.”

From One Windows Botnet to Another

Microsoft has a new zero-day vulnerability in its hands and the attempt to suspend Windows botnets is of course futile. There are just too many Windows botnets out there.

Spamhaus: Microsoft’s botnet cull had little effect

Microsoft’s takedown of the Waledac botnet has not been effective, according to some security researchers.

The throttling of Waledac, which Microsoft claimed to have achieved by means of legal action last week, has led to no appreciable reduction of junk mail coming from the botnet, anti-spam organisation Spamhaus told ZDNet UK on Tuesday.

We wrote about the Waledac takedown in [1, 2, 3]. Here is more new information about it:

Well, criticism has come from two main areas: Firstly, as Jose Nazario of Arbor Networks Inc. , a security solutions provider, told The Wall Street Journal, the Internet addresses that Microsoft’s lawsuit brought down could be a small percentage of those used by hackers to control the network. “The botnet will survive in many cases,” said Nazario.

And Richard Cox, the chief information officer at anti-spam service Spamhaus told ComputerWorld: “If this did affect spam, we haven’t noticed… Waledac was not a high threat; it’s less than 1% of spam traffic.”

On the face of it, Microsoft Windows may rely on Free software to secure the Web from itself.

From Microsoft to Apple

Apple is suing Linux (we covered this in [1, 2, 3, 4, 5]). Apple becomes more of a fighting company (an aggressor), not a pacifier.

Apple is also hiring from Microsoft, based on this report about Window Snyder.

Window Snyder’s first day at Apple was Monday, according to PC World. While it noted that Apple was the “third browser-maker in the past five years that has employed Snyder,” it did not indicate whether she would work on the Safari browser or some other technology for the Cupertino, Calif., company.

Microsoft was spreading lies about Firefox (and sometimes GNU/Linux too), but even Snyder, who had worked for Microsoft, told them off for it*. It all happened when she worked for Mozilla, but she luckily left after using her Mozilla hat to praise Microsoft. She is going to Apple now.

From US DOJ to Microsoft

Microsoft’s fairly new hire from the US DOJ is upsetting many people. Scott Charney’s remarks [1, 2, 3] led to some strong reactions. “Blow me,” says this one article from iStockAnalyst to Microsoft:

In short, these machines are infested (not infected, infested) because their operating system has historically been full of security holes (this has improved, especially in Windows 7, to be fair.)

So what does Microsoft propose?

So who would foot the bill? “Maybe markets will make it work,” Charney said. But an Internet usage tax might be the way to go. “You could say it’s a public safety issue and do it with general taxation,” he said.

That’s nice.

Sell an insecure operating system and then get someone else to pay a tax because they bought an arguably-defective product you sold?
How about this instead Microsoft?

For each computer infested, the publisher of the operating system sold to that user is assessed a fine of US $100,000 by the Department of Justice.

Here is what The Atlantic argues:

Most opponents of a tax would say that software companies should be responsible for paying, since it’s their responsibility to develop a safe product. Indeed, some criticize Microsoft for advocating a tax as an excuse to spend less of their own money developing safer software.

Also see:

Microsoft’s Ideas for Making PCs Safer

Microsoft’s Scott Charney Calls For Disrupting Cybercrime Activities

Microsoft Security Chief proposes taxes to protect the Internet

Microsoft moots digital healthcare tax

Microsoft’s Ideas for Making PCs Safer

Microsoft and the Incredible ‘Internet Usage Tax’

Say It Ain’t So, Microsoft

Maybe Microsoft Vice President for Trustworthy Computing Scott Charney wanted to see if his audience was really awake. Maybe he entered a time warp and thought it was April 1st. Maybe someone gave him a funny cookie. Or maybe he really didn’t think it would be sheer lunacy to suggest levying an Internet tax on Americans to pay for cybersecurity.

[...]

What Were You Thinking, Scott?

Not satisfied with blaming and seeking to punish the victim, Charney then went on to suggest the imposition of a tax on Internet users to ensure cybersecurity.

“You could say it’s a public safety issue and do it with general taxation,” he said.

Really, Scott? Why should we the users pay for the ineptness of software vendors? And please, don’t give me that tired routine about the bad guys being out there always looking for flaws.

Let’s take an analogy from real life. When you’re a kid your parents tell you the rules for living safely. Don’t talk to strangers or take candy from them. Look both ways before you cross the street. Don’t walk down dark streets or alleys at night. Never walk between a parked van and the wall, especially at night. Keep your doors locked.

Even some Microsoft boosters disagree with Microsoft on this, whereas most are unable to sincerely criticise it [1, 2, 3].
______
* Microsoft hates real numbers, so it manufactures its own.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

DecorWhat Else is New


  1. Links 01/02/2023: Stables Kernels and Upcoming COSMIC From System76

    Links for the day



  2. IRC Proceedings: Tuesday, January 31, 2023

    IRC logs for Tuesday, January 31, 2023



  3. Links 31/01/2023: Catchup Again, Wayland in Xfce 4.20

    Links for the day



  4. Links 31/01/2023: elementary OS 7

    Links for the day



  5. Intimidation Against Nitrux Development Team Upsets the Community and Makes the Media Less Trustworthy

    Nitrux is being criticised for being “very unappealing”; but a look behind the scenes reveals an angry reviewer (habitual mouthpiece of the Linux Foundation and Linux foes) trying to intimidate Nitrux developers, who are unpaid volunteers rather than “corporate” developers



  6. Links 31/01/2023: GNOME 44 Wallpapers and Alpha

    Links for the day



  7. Free and Open Source Software Developers' European Meeting (FOSDEM) and KU Leuven Boosting Americans and Cancellers of the Father of Free Software

    The Free Software Foundation (FSF) and its founder, Richard M. Stallman (RMS), along with the SFLC one might add, have been under a siege by the trademark-abusing FSFE and SFC; Belgium helps legitimise the ‘fakes’



  8. Techrights in the Next 5 or 10 Years

    Now that I’m free from the shackles of a company (it deteriorated a lot after grabbing Gates Foundation money under an NDA) the site Techrights can flourish and become more active



  9. 60 Days of Articles About Sirius 'Open Source' and the Long Road Ahead

    The Sirius ‘Open Source’ series ended after 60 days (parts published every day except the day my SSD died completely and very suddenly); the video above explains what’s to come and what lessons can be learned from the 21-year collective experience (my wife and I; work periods combined) in a company that still claims, in vain, to be “Open Source”



  10. IRC Proceedings: Monday, January 30, 2023

    IRC logs for Monday, January 30, 2023



  11. Taking Techrights to the Next Level in 2023

    I've reached a state of "closure" when it comes to my employer (almost 12 years for me, 9+ years for my wife); expect Techrights to become more active than ever before and belatedly publish important articles, based on longstanding investigations that take a lot of effort



  12. The ISO Delusion: When the Employer Doesn’t Realise That Outsourcing Clients' Passwords to LassPass After Security Breaches Is a Terrible Idea

    The mentality or the general mindset at Sirius ‘Open Source’ was not compatible with that of security conscientiousness and it seemed abundantly clear that paper mills (e.g. ISO certification) cannot compensate for that



  13. Links 30/01/2023: Plasma Mobile 23.01 and GNU Taler 0.9.1

    Links for the day



  14. EPO Management Isn't Listening to Staff, It's Just Trying to Divide and Demoralise the Staff Instead

    “On 18 January 2023,” the staff representatives tell European Patent Office (EPO) colleagues, “the staff representation met with the administration in a Working Group on the project “Bringing Teams Together”. It was the first meeting since the departure of PD General Administration and the radical changes made to the project. We voiced the major concerns of staff, the organization chaos and unrest caused by the project among teams and made concrete proposals.”



  15. Links 30/01/2023: Coreboot 4.19 and Budgie 10.7

    Links for the day



  16. IRC Proceedings: Sunday, January 29, 2023

    IRC logs for Sunday, January 29, 2023



  17. [Meme] With Superheroes Like These...

    Ever since the new managers arrived the talent has fled the company that falsely credits itself with "Open Source"



  18. Not Tolerating Proprietary 'Bossware' in the Workplace (or at Home in Case of Work-From-Home)

    The company known as Sirius ‘Open Source’ generally rejected… Open Source. Today’s focus was the migration to Slack.



  19. The ISO Delusion: A Stack of Proprietary Junk (Slack) Failing Miserably

    When the company where I worked for nearly 12 years spoke of pragmatism it was merely making excuses to adopt proprietary software at the expense of already-working and functional Free software



  20. Debian 11 on My Main Rig: So Far Mostly OK, But Missing Some Software From Debian 10

    Distributions of GNU/Linux keep urging us to move to the latest, but is the latest always the greatest? On Friday my Debian 10 drive died, so I started moving to Debian 11 on a new drive and here's what that did to my life.



  21. Stigmatising GNU/Linux for Not Withstanding Hardware Failures

    Nowadays "the news" is polluted with a lot of GNU/Linux-hostile nonsense; like with patents, the signal-to-noise ratio is appalling and here we deal with a poor 'report' about "Linux servers" failing to work



  22. Microsofters Inside Sirius 'Open Source'

    Sirius ‘Open Source’ has been employing incompetent managers for years — a sentiment shared among colleagues by the way; today we examine some glaring examples with redacted communications to prove it



  23. Links 29/01/2023: GNOME 43.3 Fixes and Lots About Games

    Links for the day



  24. The Hey Hype Machine

    "Hey Hype" or "Hey Hi" (AI) has been dominating the press lately and a lot of that seems to boil down to paid-for marketing; we need to understand what's truly going on and not be distracted by the substance-less hype



  25. IRC Proceedings: Saturday, January 28, 2023

    IRC logs for Saturday, January 28, 2023



  26. Unmasking AI

    A guest article by Andy Farnell



  27. The ISO Delusion/Sirius Corporation: A 'Tech' Company Run by Non-Technical People

    Sirius ‘Open Source’ was hiring people who brought to the company a culture of redundant tasks and unwanted, even hostile technology; today we continue to tell the story of a company run by the CEO whose friends and acquaintances did severe damage



  28. Links 28/01/2023: Lots of Catching Up (Had Hardware Crash)

    Links for the day



  29. IRC Proceedings: Friday, January 27, 2023

    IRC logs for Friday, January 27, 2023



  30. Microsoft DuckDuckGo Falls to Lowest Share in 2 Years After Being Widely Exposed as Microsoft Proxy, Fake 'Privacy'

    DuckDuckGo, according to this latest data from Statcounter, fell from about 0.71% to just 0.58%; all the gains have been lost amid scandals, such as widespread realisation that DuckDuckGo is a Microsoft informant, curated by Microsoft and hosted by Microsoft (Bing is meanwhile laying off many people, but the media isn’t covering that or barely bothers)


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts