EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

09.05.10

U.S. Military Hit by Windows, Learns Nothing From Microsoft Negligence

Posted in Apple, Free/Libre Software, Microsoft, Security, Windows at 8:34 pm by Dr. Roy Schestowitz

Flag and tank

Summary: Failures to name the culprit after a serious military intrusion; new examples where Microsoft knowingly ignores and leaves open holes inside Windows

“LOOKS Like Microsoft is Doing Damage Control on Virus Attacks” was the title of this post from last week. There has been a hot debate about it recently, but owing to Slashdot spin not much was done to call out Windows. The DOD/Pentagon ought to say more about the role of Microsoft software, but even the original article from Wired only speaks about “worm” and “USB”/”flash drive”, neglecting to say that only Windows can be affected. Here’s the opening:

In the fall of 2008, a variant of a three year-old, relatively-benign worm began winding its way through the U.S. military’s networks, spread by troops using thumb drives and other removable storage media. Now, the Pentagon says the infiltration — first reported by Danger Room — was a deliberate attack, launched by foreign spies. It’s a claim that some of the troops who worked to contain the worm are finding hard to back up.

In the upcoming issue of Foreign Affairs, Deputy Defense Secretary William Lynn writes that the worm entered the military’s classified systems “when an infected flash drive was inserted into a U.S. military laptop at a base in the Middle East. The flash drive’s malicious computer code, placed there by a foreign intelligence agency, uploaded itself onto a network run by the U.S. Central Command.”

Why could Slashdot not state that this is a Windows issue? Should one just assume (magically, by default) that when no operating system is mentioned it must be Microsoft Windows? They do name and shame the operating system when it’s not Windows.

Slashdot should know better because only yesterday it wrote about a data-stealing bug which is specific to Internet Explorer 8 (Windows only): [via]

There’s an unpatched vulnerability in Internet Explorer 8 that enables simple data-stealing attacks by Web-based attackers and could lead to an attacker hijacking a user’s authenticated session on a third-party site. The flaw, which a researcher said may have been known since 2008, lies in the way that IE 8 handles CSS style sheets.

We have written a great deal this year about Microsoft negligence [1, 2, 3] that led to security disasters, e.g. after Microsoft had ignored known Internet Explorer flaws for 6 months [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12] (Microsoft is the worst in the regard, so Google banned Windows earlier this year).

“Researcher told Microsoft of Windows apps zero-day bugs 6 months ago,” says this new headline from Gregg Keizer [1, 2], who adds yet another example of Microsoft ignoring problems for half a year (not even automatic patchers/trackers would help in such cases). Some things just never change.

Microsoft has said this year that for improved security users should consider moving to 64-bit Windows, but “Rootkit with Blue Screen history now targets 64-bit Windows,” says this news headline.

A new version of the malware that crippled Windows PCs last February sidesteps safeguards designed to block rootkits from hijacking machines running 64-bit editions of Windows, researchers said Thursday.

Proprietary software for Windows is another problem (Adobe and Apple being prime examples), but Free software too, e.g. Mozilla Firefox, may sometimes suffer only from flaws that are inherited from Windows, not Linux/UNIX. Microsoft in the stack is a real troublemaker and Apple is not helping:

A security researcher has uncovered a new vulnerability in Apple QuickTime that can be used to bypass some security protections in Microsoft Windows.

Code needs to be openly audited/auditable to be trustworthy. Why did the U.S. military make the mistake of relying on Windows?

“Thanks to Mr. Gates, we now know that an open Internet with protocols anyone can implement is communism; it was set up by that famous communist agent, the US Department of Defense.”

Richard Stallman

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

A Single Comment

  1. twitter said,

    September 5, 2010 at 10:59 pm

    Gravatar

    Windows use by the US military is the result of corruption. Competent people, such as Richard Clarke, and institutions like West Point, know that Microsoft is insecure. Instructors from the US Military Academy at West Point say they use “as little Windows as possible”. Clarke blames US military use on “a small army of lobbyists” and knows how insecure the OS is but would use the problem to bring government control to the internet and computing. It would be better to continue with the original design of the Internet, robustness trough redundancy, diversity and freedom.

What Else is New


  1. Links 23/5/2012: printerd, Mageia 2 Released

    Links for the day



  2. Links 22/5/2012: Google/Motorola Deal Secured, Chrome Passes IE

    Links for the day



  3. Links - Explorer Goes Down, Oracle Judge is Coder





  4. Links 21/5/2012: Linux 3.4 Released, Dream Studio 12.04

    Links for the day



  5. Articles Against Software Patents and Patent Trolls

    An accumulation of recent articles on matters such as patent trolls, which mostly use software patents based on a recent survey



  6. New Zealand (NZ) Patent Debates Expand

    The kiwi (NZ) press turns its attention to a patent controversy other than the question of software patenting



  7. AOL Helps Microsoft Infiltrate, Harm Open Source Communities, Feeds Facebook With Google-Hostile Patents

    Microsoft is preying on AOL funds and patents



  8. 'Piracy' and 'Discount' Propaganda Used to Kick Free Software Out of Governments in Favour of Microsoft Deals

    A look at new tactics and moves which omit freedom and autonomy from nations foreign to Microsoft



  9. Sun: Interoperability More Important Than Patents

    An old position paper from Sun Microsystems helps shows a certain resistance to patents such as those which Oracle uses against Android



  10. In Motorola Case, Microsoft Boosters Use Slashdot for Anti-Linux/Android Patent Propaganda

    Covering what's right/correct -- not what's wrong/incorrect -- about the Microsoft case against Motorola/Android



  11. Microsoft Tax on Everything

    The company which hardly pays any tax is busy trying to tax GNU/Linux, Android, and all hardware in the OEM channel



  12. Links 19/5/2012: Mandriva Linux Freed, New Linux Mint RC

    Links for the day



  13. Apple Patent Wars Make Android Devices Less Attractive, Everyone Suffers

    Bits of patent news regarding Apple and its patents



  14. Defeat for Software Patents in the United Kingdom

    Wise words from a prominent Linux figure and news from the UK



  15. BSA and IDC Systematically Lie to the Public, Distort Press Coverage

    IDC and the Business Software Alliance (BSA) liaise once again in order to give ammunition to lobbyists of proprietary and copyright conglomerates



  16. Links 17/5/2012: “Bio Computer” Runs Linux, Raspberry Pi Grows

    Links for the day



  17. IRC Proceedings: May 11th-May 16th, 2012

    IRC logs for May 11th, 2012 (and subsequent days until May 16th)



  18. IRC Proceedings: May 5th-May 10th, 2012

    IRC logs for May 5th, 2012 (and subsequent days until May 10th)



  19. IRC Proceedings: April 29th-May 4th, 2012

    IRC logs for April 29th, 2012 (and subsequent days until May 4th)



  20. Android Under Patent Attacks From Nokia, Microsoft, and Oracle

    A roundup of patent news involving Android and the US patent/copyright system, which facilitates ridiculous patents or lawsuits over APIs



  21. Helping OpenSUSE is Helping Microsoft Tax GNU/Linux

    A short wave of calls to refrain from OpenSUSE promotion, which through the upstream is helping Microsoft, the sponsor



  22. Microsoft May Face Federal Action for Blocking Rival Web Browsers on ARM

    Mozilla's call for action is taken seriously by people at The Hill (Washington)



  23. Links 16/5/2012: 125,000 GNU/Linux Machines for Pakistani Students, Android 4.0 Rollouts

    Links for the day



  24. Links 15/5/2012: Linux 3.4 is Near, Mandriva to Have More Releases

    Links for the day



  25. Links - TPP Meeting Infiltrated, More Protest Needed.





  26. Europe Rules Against Monopolies on APIs

    The case against Android notwithstanding, the highest European court rules that APIs cannot be covered by copyrights



  27. Microsoft Versus Education

    A bit of news/commentary on Microsoft in education (indoctrination)



  28. Patents Are Never 'Open Source'

    The disinformation tactic which ascribes patents to FOSS as seen in the news



  29. Signs of Progress: Work for Microsoft, Get Ostracised From Panels/Public Consultations

    Convinced monopolist Microsoft has its moles' voice invalidated, based on the conflict of interest (Microsoft versus the public)



  30. Links 14/5/2012: Linux Kernel 3.3.5, Wine 1.5.4

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts