EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

05.31.10

Microsoft Finally Admits Numbers of Vulnerabilities It Reports Are Fake

Posted in Deception, GNU/Linux, Microsoft, Red Hat, Security, Servers, Windows at 6:14 am by Dr. Roy Schestowitz

Microsoft lies

Summary: Mike Reavey, the director of the Microsoft Security Response Center, admits that Microsoft is silently patching vulnerabilities without ever reporting the problem

IT’S official. Microsoft is a liar. Again. Now there is even admission from Microsoft, confirming an issue which we first raised some weeks ago. Whenever Microsoft says it patches x number of flaws with y number of patches/bulletins, Microsoft ought to be assumed to be lying. Microsoft’s silent patching is a subject we have been covering for years and it helps explain why one in two Windows PCs is believed to be a zombie PC, despite Microsoft’s claims that all of its flaws are being addressed. All those fake comparisons against platforms like Red Hat Enterprise Linux (where Microsoft stacks up and aggregates numbers of flaws) can be thrown into the wastebasket. If convincing proof is needed, here it is. Microsoft first tried to spin it (for weeks) and now it gives up and tells the truth.

Microsoft Official Admits to Quiet Security Patching

Microsoft doesn’t report all security vulnerabilities that it fixes in its software. Bug comparisons between vendors therefore paint an incorrect picture.

“We don’t document every issue found,” Mike Reavey, director of the Microsoft Security Response Center (MSRC), said at a meeting with reporters at the company’s corporate headquarters in Redmond, Washington.

Microsoft will issue a Common Vulnerabilities and Exposures (CVE) number to a vulnerability for flaws that share the same severity, have an attack vector and a workaround. If several flaws share all the same properties, they will not be reported separately, Reavey said.

The nondisclosure of fixes was brought to light early this month by a company called Core Security Technologies. After studying the Microsoft patches MS10-024 and MS10-028, it noticed three silent fixes. Security bulletin MS10-028 addressed a flaw that would expose a user of Microsoft Visio to a buffer overflow attack, which would allow an attacker to take over control of the system.

Finally. Thanks for the honesty. So how much damage has been caused by Microsoft’s lies so far. Microsoft has been denying this for years, but not exactly denying, either. It was spinning and avoiding the actual question. It’s the art of lying without practically lying, just evading. Adobe is at least honest about its proprietary software being insecure garbage. As far as we are aware, Adobe hasn’t a long history of systematic lying, unlike Microsoft.

“Microsoft smacks patch-blocking rootkit second time,” says another new report from Gregg Keizer.

For the second month in a row, Microsoft has tried to eradicate a mutating rootkit that has blocked some Windows users from installing security updates.

Here is another one (also here):

Jerry Bryant, a group manager with the Microsoft Security Response Center (MSRC), said his team is looking into Raskin’s claims, but hinted that Microsoft wouldn’t be patching IE anytime soon. “I wouldn’t classify this as a ‘vulnerability’ though,” Bryant said in an e-mail answer to questions.

The followup says:

Will browser makers patch this? Unlikely. Microsoft’s Jerry Bryant, a general manager at the company’s security response center, said the issue isn’t a security vulnerability per se, and that Internet Explorer (IE) falls for the scam because that’s the way browsers work.

“Working with [Raskin's] proof-of-concept, as written, is expected,” he said in an e-mail Tuesday when asked whether Microsoft had a fix in mind for IE.

Let’s remember how much damage was caused this year because Microsoft had refused to patch known Internet Explorer flaws for five months [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12]. Where is the liability [1, 2, 3, 4, 5]? Watch what it happening in Denver right now.

Denver officials have asked the FBI, Denver police and Microsoft Corp. to help them identify the person or people who have hacked into the city’s website twice in the past week.

If Microsoft gets involved, then it almost must be a Windows server.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

A Single Comment

  1. twitter said,

    June 1, 2010 at 5:52 pm

    Gravatar

    Microsoft was cornered in two ways. First, people noticed a “silent patch”. The more fundamental bust, however, is that no one with a clue ever believed the “get the facts” propaganda. Only someone with a financial interest will tell you that Windows and GNU/Linux security are equivalent. Only someone without free software experience will believe them.

    Microsoft will go on telling the same lies. “Get the Facts” was not some kind of subtle spin. It was a direct lie, constructed of fabricated evidence, relentlessly pushed anywhere and everywhere people with computer purchasing power and developers had a discussion. Each point of the lie was refuted almost as many times. Someone might get fired for getting caught and Microsoft will keep telling the world that Windows is the most secure software ever.

What Else is New


  1. China Bashing is Grounded in Fear (That They Can Simply Do Better Than the West)

    The atmosphere of hate towards China — fuelled partly by a white supremacist in the White House — is unhelpful and insulting; dignity and understanding is the way to go



  2. IRC Proceedings: Tuesday, February 18, 2020

    IRC logs for Tuesday, February 18, 2020



  3. FFII Press Release: Germany Can No Longer Ratify the Unitary Patent Due to Brexit and the Established AETR Case-law, says FFII

    Germany cannot ratify the current Unitary Patent due to Brexit and the established AETR case-law. The ratification of the UPC (Unified Patent Court) by Germany would constitute a violation of the AETR case-law, which was used during the EPLA negotiations in 2006 to consider a deal with non-EU countries, such as Switzerland.



  4. DRM (Proprietary Software) Already Makes Mozilla Firefox Broken, Unreliable, Undependable (Dependent on Binary Blobs)

    More people are beginning to realise that Mozilla resorted to self-harming DRM and self-inflicted damage that impacts Firefox; can Mozilla (re)join the anti-DRM coalitions?



  5. EPO and Other Patent Updates Over RSS

    Site syndication (over RSS feeds or XML/Atom) is vastly better than what became popular in recent years (censored, centralised, discriminatory "Social Control Media"); here are some feeds of interest



  6. When It Comes to a Unitary Patent System, Bad (or Intentionally Dishonest) Legal Advice Has Become the Norm

    The Unified Patent Court and Unitary Patent (UPC and UP, respectively) reinforce the old saying about lawyers being liars, doing anything to attract clients (to take their money); the UPC is basically dead, but fiction, falsehoods and outrageous fantasies still find their way into Web sites of law firms



  7. Links 19/2/2020: KDE Plasma 5.18.1, GNOME 3.36 Beta 2 and WordPress 5.4 Beta 2

    Links for the day



  8. Is Linux Foundation a Microsoft Branch Now?

    The so-called ‘Linux’ Foundation (LF) nowadays helps Microsoft cement its monopoly — the very opposite of what ages ago it said the LF would do



  9. Are Songs Property? And Maths Also Property? Artificial Monopolies Are Not Property...

    Patent maximalists continue to face stronger arguments from their sceptics, who rightly allege that words are being intentionally misused and numbers fabricated so as to distort underlying facts



  10. Battistelli Blocked Techrights at EPO (Banned for More Than 5 Years), So CEIPI Won't Respect Access to Information Either

    The use of censorship to confront people who talk about (not even expose) corruption isn't novel; but the adoption of this approach in Europe (not just places like Russia and China) is definitely noteworthy



  11. IRC Proceedings: Monday, February 17, 2020

    IRC logs for Monday, February 17, 2020



  12. Links 18/2/2020: Linux 5.6 RC2, Wine 5.2, GNU Social Contract and Sparky 2020.02 Special Editions

    Links for the day



  13. IRC Proceedings: Sunday, February 16, 2020

    IRC logs for Sunday, February 16, 2020



  14. Links 16/2/2020: MX Linux 19.1 and MyPaint 2.0

    Links for the day



  15. IRC Proceedings: Saturday, February 15, 2020

    IRC logs for Saturday, February 15, 2020



  16. Guest Article: Au Revoir, GNU/Linux

    "Funny how OSI just ended up being another vehicle for their takeover of the computing world..."



  17. Former Microsoft Employee: ZDNet is Owned by Microsoft (and Others) in Some Senses

    A noteworthy message we've received from someone who knows Microsoft from the inside



  18. Links 15/2/2020: Blender 2.82, Qt 5.15 Alpha and NetBSD 9.0 Released

    Links for the day



  19. Microsoft Views 'Open Source' as a Zero-Cost Heist Opportunity (Making Proprietary Software/Spyware Using Other People's Free Labour)

    Making GPL-licensed (copyleft) software and hosting it outside Microsoft’s jaws is the best way to counter the abusive monopolist, which still says it “loves” what it is actually attacking



  20. Did Microsoft 'Buy' ZDNet?

    A look at what ZDNet tells its readers (screenshot from this morning) and a rare look at how its writers are censored/suppressed



  21. Anatomy of a Crime and Protection From Prosecution

    It’s hard to forget what António Campinos hides for his friend



  22. Today's EPO is a Fraud Managed by Frauds

    Beneath the scandals associated with systematic abuse against staff, union-busting (silencing whistleblowers) and en masse granting of invalid patents — the hallmark of grotesque maladministration — lie a bunch of even greater crimes



  23. IRC Proceedings: Friday, February 14, 2020

    IRC logs for Friday, February 14, 2020



  24. One Need Only Look at ZDNet's 'Linux' Section to Understand It's a Microsoft Propaganda Operation

    A timely new snapshot (or screenshot) that demonstrates what ZDNet became after hiring Microsoft employees as ‘journalists’ and censoring on behalf of Microsoft, defaming Free software figures and so on



  25. Links 14/2/2020: New Release of KStars, OpenSSH 8.2, Rhythmbox 3.4.4, Flatpak 1.6.2

    Links for the day



  26. The Uselessness of Social Control Media and Why We Need RSS Feeds' Resurgence More Than Ever

    Social control media became pure noise or misinformation, usually in pursuit of financial expansion alone, and it is also a censorship machine which discourages not falsehoods but unconventional thinking



  27. Another New 'Clown' for the UPC 'Circus'

    A former writer of IPPro Magazine (which seems to be defunct now) reports another shuffle -- perhaps the fifth in a few years -- of "IP" [sic] Minister for the UK; it doesn't bode well for the Unified Patent Court (UPC)



  28. IRC Proceedings: Thursday, February 13, 2020

    IRC logs for Thursday, February 13, 2020



  29. Links 13/2/2020: Ubuntu 18.04.4 LTS, Septor 2020, Endless OS 3.7.7, Wayland 1.18.0, KDE Plasma 5.18 and GTK 3.98 Released

    Links for the day



  30. The Microsoft Propaganda Model

    Classic new examples (real screenshots) of how Microsoft-funded media entraps people looking for information about "Linux" to actually push Microsoft talking points and marketing, cover-up, face-saving lies etc.


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts