Bonum Certa Men Certa

ASP.NET a Security Failure, Not Just a Patent Issue

I knew I should have stuck with freedom



Summary: Further new evidence that ASP.NET is a weak technology, Windows is extremely dangerous for use, and developers should replace it, not mimic it

Due to yet more security issues, any Mono and ASP.NET pusher at Novell ought to pay attention to deficiencies in the software it's mimicking. Here is the latest: [via]



'Padding Oracle' Crypto Attack Affects Millions of ASP.NET Apps



A pair of security researchers have implemented an attack that exploits the way that ASP.NET Web applications handle encrypted session cookies, a weakness that could enable an attacker to hijack users' online banking sessions and cause other severe problems in vulnerable applications. Experts say that the bug, which will be discussed in detail at the Ekoparty conference in Argentina this week, affects millions of Web applications.


That would not be the first such embarrassment. We gave other such examples before. Windows may be the least responsibly patched operating system, based on Microsoft's record as of late.

According to this new statement, things are getting worse than ever for Windows, security-wise.

Windows users are still the number one target: 99.4 percent of all new malware of the first half of this year was written for Microsoft’s operating system. The other 0.6% targeted systems that contain e.g. Unix or Java technologies.


Here is a further analysis/breakdown by Pogson (who also found this cripple-ware cartoon which we missed):

That other OS was the target of 98.5% of malware with a further 0.6% aimed at .NET for a total of 99.4%. The remaining 0.6% was mainly attacks on servers with various scripting and cracking attacks.


The "other OS" is Windows and .NET is there too. .NET is insecure in another sense for other reasons too, patent violations for example.

Recent Techrights' Posts

Bailing Out GAFAM, Giving Taxpayers' Money to Failing Companies, and Trying to Outlaw Lawsuits Against Them
What would the late Lincoln have said?
Men Who Abuse Women Should Never Spend Over 3 Years of the UK High Court's Time
This demonstrates that we need a reform in the UK
 
Gemini Links 25/08/2025: Empathy Towards Autistic People and Old Gadgets
Links for the day
Links 25/08/2025: Datacentres Versus Water Supplies and "The IPv6 Divide"
Links for the day
Links 25/08/2025: Data Breaches, Politics, and Financial Strain
Links for the day
GNU/Linux Distros Ought to Replace Firefox (and Firefox ESR) With Something Like LibreWolf
Perhaps it's come to replace Firefox
Father of Julian Assange Said the US Government Was Trying to Bankrupt WikiLeaks, Now the Assange Family Promotes Fake Currencies
Using the name for bad purposes?
Software Freedom Conservancy (SFC) Inc. Lost 2 Million Dollars Last Year and Its Chief Took a Salary Increase of Almost $6,000
Another year or two like this... and the SFC will be bankrupt [...] Hallmark of mismanagement
The "New Techrights" Turns Two Very Soon
Accomplishing something each year is what's important, not merely "finishing" another year
Gulf Nations Leave Microsoft Behind
How much lower will Microsoft stoop in an effort to raise money from oil-rich lenders?
How to Combat IRC Trolls (in Our Experience)
Today I want to share my experience (or knowledge) of how to deal with IRC trolls
The Register MS Needs to Stop Participating in the "Hey Hi" (AI) Hype, But It Gets Paid to Participate in This Hype
the publisher (The Register MS) wants to have it both ways
Gemini Links 24/08/2025: Living With Your Parents, Zürich Zoo, and Macondo
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, August 24, 2025
IRC logs for Sunday, August 24, 2025
Gemini Links 24/08/2025: Signal on OpenBSD and Keyboard Layouts Compared
Links for the day
Links 24/08/2025: Microsoft Settles Data Breach Lawsuits and Climate Change Causes Heatwaves, Water Shortages
Links for the day
CachyOS is Rising Fast, But Slopfarms Are 'Googlebombing' It
CachyOS receives more media attention
No Reason for Red Hat Relief Yet (Layoff Rumours)
the execution could be stalled, delayed, or scheduled for some time after people come back from holiday
GNU/Linux 6%, Windows 60% in Venezuela, Suggests statCounter
The cash cows are dying
Mass Layoffs Continue at Microsoft This Month (Remaining Workers See Conditions That Deteriorate)
So far this month (one week remaining) we saw at least two waves of layoffs at Microsoft
How SPAM E-mails With Windows-Centric Files Get Twisted as Linux Threats, Then Slopfarms Spread the Word
Fear, Uncertainty, Doubt/Fear-mongering/Dramatisation
Links 24/08/2025: Heatwaves Threaten Workers, Maldives Versus Press freedom
Links for the day
Gemini Links 24/08/2025: Digital Cameras and Printers
Links for the day
Links 24/08/2025: GAFAM Lie About Pollution and Slop's Carbon Footprint, The Guardian Says Slop ("Hey Hi") is a Bubble That Will Send Stock Markets Into a Freefall
Links for the day
80% of the Sponsored (Fake) Articles in The Register MS Are Promotions of Ponzi Schemes (Unethical Money), the Rest is Banned Chinese Business
Is that an ethical way to make money? No.
The UEFI Restricted Boot 'Time Bomb' is About to Go Off in a Few Weeks
Garrett was the first person to face sanctions (like muting) in our IRC channels because of his abuse; worse yet, he hijacked other people's names and then locked them out of their own accounts
Should Currys PCWorld Start Voiding Warranties of Users of Vista 11?
If a person's laptop has a mechanical issue, should this person replace GNU/Linux with Vista 11 for the repair shop? Only to damage the SSD?
Newer is Not Always Better, and It's Possible That 'Peak' is the Past
People creating their own platforms means progress, whereas centralisation (like moving from blogs to social control media) is the opposite of progress
LLM Hype is Sowing Destruction: It Contributes to DDoS Attacks and Makes the Web Less Accessible (JavaScript "R U Human?" Tests)
If it was googlebot, it would be possible to argue that you'd at least then get referral traffic from Google Search. With LLMs, all you get is plagiarised.
Links 24/08/2025: New York Times Talks About Hey Hi (AI) Bubble
Links for the day
Gemini Links 24/08/2025: Upgrading Debian and Mobile-indifferent Design
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 23, 2025
IRC logs for Saturday, August 23, 2025
Richard Stallman's Talk in Buenos Aires Scheduled for 16 November 2025 (a Month After FSF Turns 40)
they've just updated their site and Stallman is listed first
Nobody is "Replaced by AI", It's Just a Smokescreen for Jobs Being Eliminated by Lack of Money (Too Much Debt) and Offshoring
It's also why many make the jokes about the "I" in "AI" being "India" or "Indians"
Slopwatch: Linux Journal, WebProNews, LinuxSecurity, and the Serial Slopper
The bubble needs to burst, but even then the Web will be left with residues of these slopfarms
Links 23/08/2025: Science, War, and Important Win for the British Media Against SLAPPers Who Abuse Women
Links for the day
Gemini Links 23/08/2025: BaseLibre Numerical System and Back to Oldschool
Links for the day
"Deserved Victory" for "Women That Suffered"
"GNM defended its reporting as being both true and in the public interest and in a judgment on Friday"
The US Government is Now in the Business (Literally!) of Saving Microsoft and Intel
This means that President TACO/Cheeto now has greater financial incentive to also prop up Microsoft and Windows
Links 23/08/2025: onmicrosoft.com as Spam Cannon, The Cheeto-Intel Deal Is Official
Links for the day
Wired Complained About LLM Slop Only Days Before It Got Caught Doing That Itself
Never throw stones in a glass house
IBM "Value" Down 14.16% in a Month, Red Hat Layoffs Allegedly Discussed 12 Days Ago
"IBM is a dinosaur. Dinosaurs get extinct when the don't keep up."
We're Seeing More Countries Where Windows Isn't Even in Second Place Anymore (Third or Worse)
In a way, Microsoft can barely even hold onto second place anymore
Microsoft Workers on Canonical's Payroll
If you want something that's sort of like Ubuntu but is not controlled by Canonical, then look into Linux Mint, Debian, or LMDE
GNU/Linux Climbs to 4% in Sierra Leone
Sierra Leone isn't a very rich country (to say the least), but it's better off than some of its neighbours
The SLAPPS Run Out of Oxygen Because They're Abuse of Process
At the end of the day we plan to publish over 1,000 articles explaining what happened
The Register MS Gets Paid by the Employer of the Previous Editor in Chief to Promote the "AI" Ponzi Scheme, Which Does Considerable Damage to the Web and to Online Journalists
The Register MS can 'badmouth' slop all it wants; it gets paid to inflate this bubble. It's actively participating in it.
Soon It'll be Autumn, Time to Repair Things
Where they don't charge an arm and a leg
Doing Our Best to Cover Software Patents When the Mainstream Media Does Not
Even the FSF has its limits
Gemini Links 23/08/2025: August Questions and Network Solutions
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, August 22, 2025
IRC logs for Friday, August 22, 2025