EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

09.05.10

U.S. Military Hit by Windows, Learns Nothing From Microsoft Negligence

Posted in Apple, Free/Libre Software, Microsoft, Security, Windows at 8:34 pm by Dr. Roy Schestowitz

Flag and tank

Summary: Failures to name the culprit after a serious military intrusion; new examples where Microsoft knowingly ignores and leaves open holes inside Windows

“LOOKS Like Microsoft is Doing Damage Control on Virus Attacks” was the title of this post from last week. There has been a hot debate about it recently, but owing to Slashdot spin not much was done to call out Windows. The DOD/Pentagon ought to say more about the role of Microsoft software, but even the original article from Wired only speaks about “worm” and “USB”/”flash drive”, neglecting to say that only Windows can be affected. Here’s the opening:

In the fall of 2008, a variant of a three year-old, relatively-benign worm began winding its way through the U.S. military’s networks, spread by troops using thumb drives and other removable storage media. Now, the Pentagon says the infiltration — first reported by Danger Room — was a deliberate attack, launched by foreign spies. It’s a claim that some of the troops who worked to contain the worm are finding hard to back up.

In the upcoming issue of Foreign Affairs, Deputy Defense Secretary William Lynn writes that the worm entered the military’s classified systems “when an infected flash drive was inserted into a U.S. military laptop at a base in the Middle East. The flash drive’s malicious computer code, placed there by a foreign intelligence agency, uploaded itself onto a network run by the U.S. Central Command.”

Why could Slashdot not state that this is a Windows issue? Should one just assume (magically, by default) that when no operating system is mentioned it must be Microsoft Windows? They do name and shame the operating system when it’s not Windows.

Slashdot should know better because only yesterday it wrote about a data-stealing bug which is specific to Internet Explorer 8 (Windows only): [via]

There’s an unpatched vulnerability in Internet Explorer 8 that enables simple data-stealing attacks by Web-based attackers and could lead to an attacker hijacking a user’s authenticated session on a third-party site. The flaw, which a researcher said may have been known since 2008, lies in the way that IE 8 handles CSS style sheets.

We have written a great deal this year about Microsoft negligence [1, 2, 3] that led to security disasters, e.g. after Microsoft had ignored known Internet Explorer flaws for 6 months [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12] (Microsoft is the worst in the regard, so Google banned Windows earlier this year).

“Researcher told Microsoft of Windows apps zero-day bugs 6 months ago,” says this new headline from Gregg Keizer [1, 2], who adds yet another example of Microsoft ignoring problems for half a year (not even automatic patchers/trackers would help in such cases). Some things just never change.

Microsoft has said this year that for improved security users should consider moving to 64-bit Windows, but “Rootkit with Blue Screen history now targets 64-bit Windows,” says this news headline.

A new version of the malware that crippled Windows PCs last February sidesteps safeguards designed to block rootkits from hijacking machines running 64-bit editions of Windows, researchers said Thursday.

Proprietary software for Windows is another problem (Adobe and Apple being prime examples), but Free software too, e.g. Mozilla Firefox, may sometimes suffer only from flaws that are inherited from Windows, not Linux/UNIX. Microsoft in the stack is a real troublemaker and Apple is not helping:

A security researcher has uncovered a new vulnerability in Apple QuickTime that can be used to bypass some security protections in Microsoft Windows.

Code needs to be openly audited/auditable to be trustworthy. Why did the U.S. military make the mistake of relying on Windows?

“Thanks to Mr. Gates, we now know that an open Internet with protocols anyone can implement is communism; it was set up by that famous communist agent, the US Department of Defense.”

Richard Stallman

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email
  • Slashdot

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

A Single Comment

  1. twitter said,

    September 5, 2010 at 10:59 pm

    Gravatar

    Windows use by the US military is the result of corruption. Competent people, such as Richard Clarke, and institutions like West Point, know that Microsoft is insecure. Instructors from the US Military Academy at West Point say they use “as little Windows as possible”. Clarke blames US military use on “a small army of lobbyists” and knows how insecure the OS is but would use the problem to bring government control to the internet and computing. It would be better to continue with the original design of the Internet, robustness trough redundancy, diversity and freedom.

What Else is New


  1. Faking 'Progress' to Distract From True Justice or From a Full, Meaningful Reform

    Activism for truly meaningful change doesn't stop at superficialities and cosmetic changes (which merely give a false sense/impression of accomplishment, resulting in inaction); we need to regularly consider how to dismantle injustice, not based on the criteria set by oligarchs-owned media, rallying gullible mobs to appease only big egos



  2. IRC Proceedings: Thursday, September 24, 2020

    IRC logs for Thursday, September 24, 2020



  3. Richard Stallman: New Interview About Privacy (Published This Morning)

    “The last few months have put data protection back in the spotlight. During a crisis of this kind, do we have to choose between safety and privacy? We talked about this with Richard Stallman, digital privacy activist and the founder of the Free Software Movement,” RT says



  4. Links 25/9/2020: PostgreSQL 13, DragonFly 5.8.2 and Python 3.8.6

    Links for the day



  5. Code of Ethics Versus Code of Conduct in Action

    Reprinted from Daniel Pocock's Web site



  6. Linux Foundation: “Transformation Through Open Source” is Proprietary Software That Rejects Linux

    The Linux Foundation, run by proprietary software companies that don’t really care about Linux, is still a lot more about openwashing (perception management techniques) than about “Open Source” or even Linux (which most of the Foundation rejects)



  7. Links 24/9/2020: KaOS 2020.09, Arch Conf 2020 Coming, IBM Z Day 2020 Ends

    Links for the day



  8. At ZDNet, in 2020, “Linux” Means Microsoft and Windows

    The incredible charade of ZDNet carries on; the site whose parent company went bust last December isn’t even trying to hide its true agenda



  9. Red Hat is Spamming People in Order to Promote Its Sites and Its Products, Subscribing People to Mass-Marketing Lists Without the Recipients' Consent

    "Engagements" from Red Hat; have the IBM-led marketing people gone overboard, subscribing lots of people to marketing spam without bothering to ask for consent?



  10. “If I'm the Father of Open Source, It Was Done by Artificial Insemination With Stolen Sperm”

    The father of the Free software movement, Richard Stallman, is being wrongly compared to some patron of an “open source” ‘movement’ (an early effort to cancel Stallman and the FSF), which is basically a hostile corporations-led ploy these days



  11. IRC Proceedings: Wednesday, September 23, 2020

    IRC logs for Wednesday, September 23, 2020



  12. The Second Wave (of Free/Libre Software)

    Despite some major setbacks and new threats to digital freedom (autonomy is perhaps a more suitable term), progress is being made and activism must adapt to tackle newer trends



  13. Exploring the Relationship Between Red Hat and Microsoft: They're Barely Even Rivals Anymore

    The ‘older Microsoft’ (serial monopolist IBM) bought Red Hat, but evidence shows that one would be wrong to assume Red Hat really competes against Microsoft (any more than Novell did; there’s a strong relationship)



  14. Microsoft Lost More Than 15 Million Web Domains in One Month!

    Microsoft's presence on the Web is being reduced to ridiculously low levels; sooner or later Microsoft will turn from 'king' of parked (unused) domains to master of nothing



  15. Links 23/9/2020: Lenovo's Deeper GNU/Linux Dive and Tor Browser 10/Tails 4.10

    Links for the day



  16. IRC Proceedings: Tuesday, September 22, 2020

    IRC logs for Tuesday, September 22, 2020



  17. The Latest Greenwashing Campaign by the EPO is Just 'Chinese Propaganda'

    When the EPO speaks of “innovation” and “clean energy transition” it means nothing but patents on batteries, in effect monopolies being granted in Europe (to a lot of Asian — not European — companies)



  18. Links 23/9/2020: Librem 14 Shipping in December, Linux Journal Returns, Istio 1.6.10 Released, Release Candidate 3 of LLVM 11.0

    Links for the day



  19. Welcome Back, Linux Journal!

    Linux Journal is coming back under the ownership/umbrella of Slashdot folks, who are sadly preoccupied and obsessed with Microsoft talking points and PR campaigns



  20. What the Efforts to Remove Dr. Stallman Reveal About the Agenda of Large Corporations (Looking to Absorb the Competition, Remove Freedom, Spread Proprietary Software in 'Open' Clothing)

    Richard Stallman's (RMS) positions and foresight are usually correct; at the moment we're losing access to key people whose leadership positions are essential for the independence of cornerstone projects



  21. Links 22/9/2020: Tails 4.11, Linux Lite 5.2 RC1

    Links for the day



  22. Minimalism for Maximisation of Productivity and Clutter Mitigation

    Unfortunately, GNU/Linux (especially the latter, Linux) embraces bloat and anti-features in pursuit of sales (appeasing large corporations, not users’ needs), reducing the modularity, reliability and productivity of computer systems in the name of helping “dumb” users (they keep telling us people are very dumb and those who disagree are “elitist” and “extremist” or even “neckbeards” — in effect insulting every person out there)



  23. IRC Proceedings: Monday, September 21, 2020

    IRC logs for Monday, September 21, 2020



  24. Post-Coronavirus Linux.com Became Nothing But a SPAM Site

    As per the Linux Foundation‘s very own brochure, scripted and fake ‘interviews’ are to be produced and then edited/negotiated (before publication) with the sponsor… in Linux.com as the platform. This is corruption (or marketing, one might call them de facto ads presented as fake ‘articles’).



  25. Erosion of Free Speech and Tolerance of Opposing Viewpoints in Free Software Communities

    The concept of free speech is being reinvented by oversensitive people who nowadays expand the list of exclusions/exemptions (from scope of 'permissible' speech) to politics and criticism of large and highly abusive corporations



  26. Links 21/9/2020: PlasmaShell With Vulkan, Plasma Beta Review Day, OpenMediaVault 5.5.11

    Links for the day



  27. Guest Post: The Worrying State of Political Judgement in Free Software Communities

    A look at what Mozilla has become and what that teaches us about the Web and about software



  28. Links 21/9/2020: KTechLab 0.50.0, Linux 5.9 RC6

    Links for the day



  29. IRC Proceedings: Sunday, September 20, 2020

    IRC logs for Sunday, September 20, 2020



  30. Git is Free Software, GitHub is Proprietary Trap

    More and more people all around the world understand that putting their fruit of labour in Microsoft's proprietary (but 'free') prison is misguided; the only vault they have is for human beings, not code


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts