EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

05.07.10

Why Microsoft’s Security Reports Are a Scam

Posted in Boycott Novell, Deception, Microsoft, Security at 3:32 am by Dr. Roy Schestowitz

Microsoft lies

Summary: Microsoft is caught lying again, by essentially patching serious flaws while hiding their very existence

TO PUT it bluntly but rather fairly or at least realistically, Microsoft is a company of systematic liars and nobody should ever trust a word that comes out of their mouths. They believe that these lies are acceptable because they serve some higher goal or that it’s a white lie when it helps one’s investors or bank account (or perceived sense of security). The examples we have given (e.g. [1, 2, 3, 4, 5]) are too many to list here exhaustively, so we won’t attempt to list such examples in a more compelling way.

One point that we stressed and demonstrated several years ago is that Microsoft fakes its reports when it comes to security; people buy their software based on false premises, lack of disclosure, and outright lies.

Putting aside several examples from several years ago, we now have some new examples where Microsoft gets caught (which is hard to achieve because the code is secret). As Slashdot summarised it:

“Microsoft silently patched three vulnerabilities last month, two of them affecting enterprise mission-critical Exchange mail servers, without calling out the bugs in the accompanying advisories, a security expert said on Thursday. Two of the three unannounced vulnerabilities, and the most serious of the trio, were packaged with MS10-024, an update to Exchange and Windows SMTP Service that Microsoft issued April 13 and tagged as ‘important,’ its second-highest threat ranking. Ivan Arce, CTO of Core Security Technologies, said Microsoft patched the bugs, but failed to disclose that it had done so — which could pose a problem. ‘They’re more important than the [two vulnerabilities] that Microsoft did disclose,’ said Arce. ‘That means [system] administrators may end up making the wrong decisions about applying the update. They need that information to assess the risk.’”

Here is the corresponding article.

Microsoft silently patched three vulnerabilities last month, two of them affecting enterprise mission-critical Exchange mail servers, without calling out the bugs in the accompanying advisories, a security expert said today.

Two of the three unannounced vulnerabilities, and the most serious of the trio, were packaged with MS10-024, an update to Exchange and Windows SMTP Service that Microsoft issued April 13 and tagged as “important,” its second-highest threat ranking.

According to Ivan Arce, the chief technology officer of Core Security Technologies, Microsoft patched the bugs, but failed to disclose that it had done so.

This has already been covered by The Register too:

A recent security patch from Microsoft silently fixed two severe bugs that were never disclosed even though they posed a risk to many of its customers, a security researcher said.

MS10-024 fixed two flaws that made it possible for adversaries to intercept victims’ email messages sent by Exchange and Windows SMTP service, Nicolás Economou, a researcher with Core Security said. But the bugs – which made it “trivial” to spoof responses to domain name system queries – weren’t disclosed and were never assigned a Common Vulnerabilities and Exposure identifier, sparking criticism that the critical bugs weren’t properly disclosed.

Next time Microsoft shows any comparisons involving a number of flaws or severity of flaws, refuse to accept them. Microsoft is the boy who cried “Wolf!” and the above serves as an example of behaviour that has gone on for years (rarely detected though because it’s hard).

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

2 Comments

  1. Yuhong Bao said,

    May 9, 2010 at 12:09 pm

    Gravatar

    Ars had an article about it:
    http://arstechnica.com/microsoft/news/2010/05/the-potential-dangers-of-microsofts-secret-patches.ars
    And MS is not the only culprit, from http://it.slashdot.org/comments.pl?sid=226603&cid=18365343 :
    “or if he finds it first it never gets announced (see the ntalkd scandal years ago).”

  2. Dr. Roy Schestowitz said,

    May 9, 2010 at 12:19 pm

    Gravatar

    Yuhong,

    I will write more about this tomorrow (with more references).

What Else is New


  1. Links 21/5/2012: Linux 3.4 Released, Dream Studio 12.04

    Links for the day



  2. Articles Against Software Patents and Patent Trolls

    An accumulation of recent articles on matters such as patent trolls, which mostly use software patents based on a recent survey



  3. New Zealand (NZ) Patent Debates Expand

    The kiwi (NZ) press turns its attention to a patent controversy other than the question of software patenting



  4. AOL Helps Microsoft Infiltrate, Harm Open Source Communities, Feeds Facebook With Google-Hostile Patents

    Microsoft is preying on AOL funds and patents



  5. 'Piracy' and 'Discount' Propaganda Used to Kick Free Software Out of Governments in Favour of Microsoft Deals

    A look at new tactics and moves which omit freedom and autonomy from nations foreign to Microsoft



  6. Sun: Interoperability More Important Than Patents

    An old position paper from Sun Microsystems helps shows a certain resistance to patents such as those which Oracle uses against Android



  7. In Motorola Case, Microsoft Boosters Use Slashdot for Anti-Linux/Android Patent Propaganda

    Covering what's right/correct -- not what's wrong/incorrect -- about the Microsoft case against Motorola/Android



  8. Microsoft Tax on Everything

    The company which hardly pays any tax is busy trying to tax GNU/Linux, Android, and all hardware in the OEM channel



  9. Links 19/5/2012: Mandriva Linux Freed, New Linux Mint RC

    Links for the day



  10. Apple Patent Wars Make Android Devices Less Attractive, Everyone Suffers

    Bits of patent news regarding Apple and its patents



  11. Defeat for Software Patents in the United Kingdom

    Wise words from a prominent Linux figure and news from the UK



  12. BSA and IDC Systematically Lie to the Public, Distort Press Coverage

    IDC and the Business Software Alliance (BSA) liaise once again in order to give ammunition to lobbyists of proprietary and copyright conglomerates



  13. Links 17/5/2012: “Bio Computer” Runs Linux, Raspberry Pi Grows

    Links for the day



  14. IRC Proceedings: May 11th-May 16th, 2012

    IRC logs for May 11th, 2012 (and subsequent days until May 16th)



  15. IRC Proceedings: May 5th-May 10th, 2012

    IRC logs for May 5th, 2012 (and subsequent days until May 10th)



  16. IRC Proceedings: April 29th-May 4th, 2012

    IRC logs for April 29th, 2012 (and subsequent days until May 4th)



  17. Android Under Patent Attacks From Nokia, Microsoft, and Oracle

    A roundup of patent news involving Android and the US patent/copyright system, which facilitates ridiculous patents or lawsuits over APIs



  18. Helping OpenSUSE is Helping Microsoft Tax GNU/Linux

    A short wave of calls to refrain from OpenSUSE promotion, which through the upstream is helping Microsoft, the sponsor



  19. Microsoft May Face Federal Action for Blocking Rival Web Browsers on ARM

    Mozilla's call for action is taken seriously by people at The Hill (Washington)



  20. Links 16/5/2012: 125,000 GNU/Linux Machines for Pakistani Students, Android 4.0 Rollouts

    Links for the day



  21. Links 15/5/2012: Linux 3.4 is Near, Mandriva to Have More Releases

    Links for the day



  22. Links - TPP Meeting Infiltrated, More Protest Needed.





  23. Europe Rules Against Monopolies on APIs

    The case against Android notwithstanding, the highest European court rules that APIs cannot be covered by copyrights



  24. Microsoft Versus Education

    A bit of news/commentary on Microsoft in education (indoctrination)



  25. Patents Are Never 'Open Source'

    The disinformation tactic which ascribes patents to FOSS as seen in the news



  26. Signs of Progress: Work for Microsoft, Get Ostracised From Panels/Public Consultations

    Convinced monopolist Microsoft has its moles' voice invalidated, based on the conflict of interest (Microsoft versus the public)



  27. Links 14/5/2012: Linux Kernel 3.3.5, Wine 1.5.4

    Links for the day



  28. Links 13/5/2012: Xfce 4.10, KDE 4.8.3, GNOME 3.5.1, GIMP 2.8

    Links for the day



  29. Software Patents and Trolls Devour Jobs While Microsoft Proxies Sue Android Companies

    An accumulation of news about software patents, patent parasites, and patent trolls



  30. Charles Manson, the Unabomber, and Microsoft




RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts