EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

05.31.10

Microsoft Finally Admits Numbers of Vulnerabilities It Reports Are Fake

Posted in Deception, GNU/Linux, Microsoft, Red Hat, Security, Servers, Windows at 6:14 am by Dr. Roy Schestowitz

Microsoft lies

Summary: Mike Reavey, the director of the Microsoft Security Response Center, admits that Microsoft is silently patching vulnerabilities without ever reporting the problem

IT’S official. Microsoft is a liar. Again. Now there is even admission from Microsoft, confirming an issue which we first raised some weeks ago. Whenever Microsoft says it patches x number of flaws with y number of patches/bulletins, Microsoft ought to be assumed to be lying. Microsoft’s silent patching is a subject we have been covering for years and it helps explain why one in two Windows PCs is believed to be a zombie PC, despite Microsoft’s claims that all of its flaws are being addressed. All those fake comparisons against platforms like Red Hat Enterprise Linux (where Microsoft stacks up and aggregates numbers of flaws) can be thrown into the wastebasket. If convincing proof is needed, here it is. Microsoft first tried to spin it (for weeks) and now it gives up and tells the truth.

Microsoft Official Admits to Quiet Security Patching

Microsoft doesn’t report all security vulnerabilities that it fixes in its software. Bug comparisons between vendors therefore paint an incorrect picture.

“We don’t document every issue found,” Mike Reavey, director of the Microsoft Security Response Center (MSRC), said at a meeting with reporters at the company’s corporate headquarters in Redmond, Washington.

Microsoft will issue a Common Vulnerabilities and Exposures (CVE) number to a vulnerability for flaws that share the same severity, have an attack vector and a workaround. If several flaws share all the same properties, they will not be reported separately, Reavey said.

The nondisclosure of fixes was brought to light early this month by a company called Core Security Technologies. After studying the Microsoft patches MS10-024 and MS10-028, it noticed three silent fixes. Security bulletin MS10-028 addressed a flaw that would expose a user of Microsoft Visio to a buffer overflow attack, which would allow an attacker to take over control of the system.

Finally. Thanks for the honesty. So how much damage has been caused by Microsoft’s lies so far. Microsoft has been denying this for years, but not exactly denying, either. It was spinning and avoiding the actual question. It’s the art of lying without practically lying, just evading. Adobe is at least honest about its proprietary software being insecure garbage. As far as we are aware, Adobe hasn’t a long history of systematic lying, unlike Microsoft.

“Microsoft smacks patch-blocking rootkit second time,” says another new report from Gregg Keizer.

For the second month in a row, Microsoft has tried to eradicate a mutating rootkit that has blocked some Windows users from installing security updates.

Here is another one (also here):

Jerry Bryant, a group manager with the Microsoft Security Response Center (MSRC), said his team is looking into Raskin’s claims, but hinted that Microsoft wouldn’t be patching IE anytime soon. “I wouldn’t classify this as a ‘vulnerability’ though,” Bryant said in an e-mail answer to questions.

The followup says:

Will browser makers patch this? Unlikely. Microsoft’s Jerry Bryant, a general manager at the company’s security response center, said the issue isn’t a security vulnerability per se, and that Internet Explorer (IE) falls for the scam because that’s the way browsers work.

“Working with [Raskin's] proof-of-concept, as written, is expected,” he said in an e-mail Tuesday when asked whether Microsoft had a fix in mind for IE.

Let’s remember how much damage was caused this year because Microsoft had refused to patch known Internet Explorer flaws for five months [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12]. Where is the liability [1, 2, 3, 4, 5]? Watch what it happening in Denver right now.

Denver officials have asked the FBI, Denver police and Microsoft Corp. to help them identify the person or people who have hacked into the city’s website twice in the past week.

If Microsoft gets involved, then it almost must be a Windows server.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

A Single Comment

  1. twitter said,

    June 1, 2010 at 5:52 pm

    Gravatar

    Microsoft was cornered in two ways. First, people noticed a “silent patch”. The more fundamental bust, however, is that no one with a clue ever believed the “get the facts” propaganda. Only someone with a financial interest will tell you that Windows and GNU/Linux security are equivalent. Only someone without free software experience will believe them.

    Microsoft will go on telling the same lies. “Get the Facts” was not some kind of subtle spin. It was a direct lie, constructed of fabricated evidence, relentlessly pushed anywhere and everywhere people with computer purchasing power and developers had a discussion. Each point of the lie was refuted almost as many times. Someone might get fired for getting caught and Microsoft will keep telling the world that Windows is the most secure software ever.

What Else is New


  1. Links 19/10/2017: Mesa 17.2.3, New Ubuntu Release, Samsung Flirts With GNU/Linux Desktops

    Links for the day



  2. Some of the USPTO's Most Ridiculous Patents Are Scrutinised by “Above the Law” While Dennis Crouch Attempts to Tarnish Alice

    Controversies over patent scope and level of novelty required for a patent; as usual, public interest groups try to restrict patent scope, whereas those who make money out of abundance of patents attempt to remove every barrier



  3. Microsoft's Software Patents Aggression in Court (Corel Again)

    Microsoft's tendency to not only abuse the competition but also to destroy it with patent lawsuits as seen in Corel's case



  4. The Spanish Supreme Court Rejects the EPO's “Problem and Solution Approach” While Quality of European Patents Nosedives

    European Patents (EPs) aren't what they used to be and their credibility is being further eroded and even detected as such



  5. Europe is Being Robbed by Team Battistelli and the UPC/PPH Would Make Things Worse

    The European Patent Office (EPO) has put litigation at the forefront, having implicitly decided to no longer bother with proper patent examination and instead issue lots of patents for judges and lawyers to argue about (at great expense to the public)



  6. Team UPC Continues to Promote Illusion of UPC Progress Where There's None

    The core members of Team UPC in the UK spread obvious falsehoods in the media, probably in an effort to attract 'business' (consultation regarding something that does not exist)



  7. António Campinos: A True EPO Reformer or More of the Same?

    More unfortunate reminders that Campinos and Battistelli don't quite diverge on the big issues, they're just more than two decades apart in age (but the same nationality)



  8. Juve Has Confirmed That António Campinos is French

    The relationship between Campinos and Battistelli has a nationality aspect to it, not even taking into account the interpersonal connection which goes a long way back



  9. The Darker Past of the Next President of the EPO - Part II: António Campinos at Banco Caixa Geral de Depósitos

    A look at the largely-hidden banking career of the next President of the EPO and the career of the person who competed with him for this position



  10. SUEPO to the Media, Regarding Campinos: “No Comment, It’s Too Dangerous”

    António Campinos, who is Benoît Battistelli's chosen successor at the EPO, as covered by German media earlier this month



  11. Staff Union of the EPO (SUEPO) Willing to Work With Campinos But Foresees Difficulties

    New message from SUEPO regarding Battistelli's successor of choice (Campinos)



  12. Links 18/10/2017: GTK+ 3.92, Microsoft Bug Doors Leaked

    Links for the day



  13. The Darker Past of the Next President of the EPO - Part I: Introduction

    Some new details about Mr. Campinos, who is Battistelli’s successor at the EPO



  14. Confessions of EPO Insiders Reveal That European Patents (EPs) Have Lost Their Legitimacy/Value Due to Battistelli's Policies

    A much-discussed topic at the EPO is now the ever-declining quality of granted patents, which make or break patent offices because quality justifies high costs (searches, applications, renewals and so on)



  15. Patent Firms From the United States Try Hard to Push the Unitary Patent (UPC), Which Would Foment Litigation Wars in Europe

    The UPC push seems to be coming from firms which not only fail to represent public interests but are not even European



  16. In the Age of Alice and PTAB There is No Reason to Pursue Software Patents in the United States (Not Anymore)

    The appeal board in the US (PTAB) combined with a key decision of the Supreme Court may mean that even at a very low cost software patents can be invalidated upon demand (petition) and, failing that, the courts will invalidate these



  17. IAM is Wrong, the Narrative Isn't Changing, Except in the Battistelli-Funded (at EPO's Expense) Financial Times

    The desperate attempts to change the narrative in the press culminate in nothing more than yet another misleading article from Rana Foroohar and some rants from Watchtroll



  18. The Federal Circuit Continues Squashing Software Patents

    Under the leadership of Sharon Prost the Court of Appeals for the Federal Circuit (CAFC) continues its war on software patents, making it very hard to remember the last time it tolerated any



  19. SUEPO Representatives Like Elizabeth Hardon Vindicated as Battistelli's Detrimental Effect on Patent Quality is Widely Confirmed

    Feedback regarding the awful refusal to acknowledge patent quality crisis at the EPO as well as the appointment of a President so close to Battistelli (who most likely assures continuation of his policies)



  20. Links 17/10/2017: KDE Frameworks 5.39.0, Safe Browsing in Epiphany

    Links for the day



  21. Judge Bryson Rules Against Allergan After It Used Native American Tribes to Dodge Scrutiny of Patents (IPRs); Senator Hatch Does Not Understand IPRs

    Having attempted to dodge inter partes reviews (IPRs) by latching onto sovereign immunity, Allergan loses a key case and Senator Hatch is meanwhile attempting to water down IPRs albeit at the same time bemoaning patent trolls (which IPRs help neutralise)



  22. Rumours That António Campinos Initially Had No Competition at All (for Battistelli's Succession) Are Confirmed

    Succession at the EPO (mostly French) shows that there's little room for optimism and Battistelli's people are too deeply entrenched in the upper echelons of the EPO



  23. EPO Stakeholders Complain That the New Chairman Does Not Grasp the Issues at the EPO (or Denies These)

    Some information from inside the EPO’s Administrative Council, whose Chairman is denying (at least to himself) some of the core issues that render the EPO less competitive in the international market



  24. Another Misleading Article Regarding Patents From Rana Foroohar at the Financial Times

    In an effort to promote the agenda of patent maximalists, many of whom are connected to the Financial Times, another deceiving report comes out



  25. Monika Ermert's Reports About the Crisis at the EPO and IP Kat's Uncharacteristically Shallow Coverage

    News from inside the Council shows conflict regarding the quality of European Patents (granted by the EPO under pressure from top-level management)



  26. Patent Troll VirnetX a Reminder to Apple That Software Patents Are a Threat to Apple Too

    VirnetX, a notorious patent troll, is poised to receive a huge sum of money from Apple and Qualcomm is trying to ban Apple products, serving to remind Apple of the detrimental impact of patents on Apple itself



  27. Links 16/10/2017: Linux 4.14 RC5, Debian 9.2.1, End of LibreOffice Conference 2017

    Links for the day



  28. The Systematic Erosion of Workers' Rights and Holidays at the EPO Goes Years Back

    The legitimacy of the staff's concerns at the EPO, having seen basic labour safeguards being shredded to pieces by Battistelli for a number of years (predating even the escalation of the conflict)



  29. Articles in English and German Speak About the Decline in Quality of European Patents (Granted by the EPO)

    Heise and The Register, two sites that have closely watched EPO affairs for a number of years, speak about the real problem which is declining patent quality (or rushed examination) -- a recipe for frivolous litigation in Europe



  30. Software Patents and Patent Trolls Not a Solved Issue, But the US is Getting There

    A media survey regarding software patents, which are being rejected in the US in spite of all the spin from law firms and bullies such as IBM


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts