Bonum Certa Men Certa

Microsoft Claims Credit for Failing in Security

Servers rack - amateur



Summary: Latest security issues and systematic deception, mostly from Microsoft and its various boosters across the Web (giving credit to Microsoft after Microsoft messed up)

Gratis as in Lock-in



A FEW days ago we wrote about Microsoft's attempt at disconnecting the air supply from third-party AV vendors, at least in small businesses. This would only decrease security due to monoculture, decreased competition, and lack of incentive to improve. The funny thing here is that Microsoft sells a vulnerable operating system and then claims to be distributing "free of charge" (only to some people) what ought to have been a characteristic of the operating system, not an add-on. The spinners from Seattle call it a "free" anti-virus software and what's meant by free is not freedom. It's free as in gratis, with lock-in. It decreases one's personal freedom and also impedes freedom of choice. A better headline than "Free Anti-Virus Protection Spurs More Robust Options" would be "Free-of-charge Anti-Virus Pseudo-protection Depresses More Robust Options".



Watch the Indian press turning the whole thing into Vista 7 promotion: "IT major Microsoft has launched a campaign to help computer users identify threats to their systems and how their networks can be made secure using Original Windows 7 that now comes with the advantage of Microsoft Security Essentials."

So Microsoft wants to dump Security Essentials on the market (as expected by many people all along) and already we learn that "Scareware Apes Microsoft Security Essentials". Microsoft has always performed very poorly among the security products already available and well established. "Anti-virus systems get tested" says The Inquirer which gives the following details:

A NUMBER of the most common anti-virus security systems have had a beady eye passed over their effectiveness and fitness for purpose in an assessment.

The study, which was carried out by the Austrian AV Comparatives group, looked at twenty products from the main providers that volunteered to take part.

We do not know who if anyone refused, but AV Comparatives said that it had limited test subjects to no more than twenty and required that participants adhered to its undisclosed criteria.


"Over half of all apps have security holes," claims Veracode (which we mentioned in [1, 2]).

More than half of all software applications failed to meet an acceptable level of security, according to a study based on real-world code audits by application security firm Veracode.

Around 57 per cent of applications failed to pass muster when first submitted to Veracode’s cloud-based testing service. A similar 56 per cent of finance-related applications failed first testing by Veracode’s security audit. The quality of the code used in many business-critical banking and insurance operations was simply not up to snuff.


ASP.NET Under Attack, Spin



In security news, the other major issue last week was the Microsoft ASP.NET vulnerability, which we wrote about in [1, 2, 3, 4].

“Is this really praise-worthy, especially when someone responds to flaws which the same someone is responsible for?”The ASP.NET problem alarmed Microsoft a great deal and the PR spin strives to make Microsoft be seen as responsive. An advisory was quickly issued [1, 2, 3] because of bad publicity and because it was already being exploited (a demo existed). There is only a temporary fix, not a permanent one. There are third-party fixes.

So, once again Microsoft pays attention to flaws a tad too late and then scrambles to limit damage it could probably prevent. Is this really praise-worthy, especially when someone responds to flaws which the same someone is responsible for?

Just like in the case of Russian spin [1, 2], Microsoft is trying to make itself look like the saviour rather than the problem. Lee Pender of the Microsoft boosters is trying to make Microsoft look good by painting it as responsive and responsible. To quote: "Well, late last week, we got an update from a Microsoft spokesperson who wanted to tell us that Microsoft hasn't just buried its head in the sand on Stuxnet."

We wrote about Stuxnet in [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14].

Microsoft-Police



Over in Australia, Microsoft is involving the police right now (funded by taxpayers) [1, 2, 3, 5]. It's about a computer scam that affects Microsoft.

Twitter and Fog Computing



The other day we wrote about the major problem Twitter.com was having. Half a million Twitter users are said to be affected by a Twitter worm and Slashdot discusses the matter before and after the patching. Here are "the names and faces behind the 'onMouseOver' Twitter worm attack". It's one of those risks of Fog Computing. Even a teenager turns out to have been smart enough to do it.

But later, some mischievous users of the site started using the exploit to make people "retweet" infected messages (when they hovered over a tweet with the code inserted) that they had not authorised.


The guy is Australian, so will the police get involved? Or does the Australian police get involved only to help Microsoft?

Recent Techrights' Posts

No Allure in Omarchy, the Political Hyenas Only Give it More Free Publicity
To me, Omarchy seems like a weak project because of the slop (an HR problem)
Don't Let Bastards and Haters Grind You Down
They say "jealousy is the sincerest form of flattery"
Goodbye, Dolly
This week we say "goodbye, Dolly."
How Many Web Requests From "Linux"...
If one was to assert that "Linux == Android" or "Android == Linux" (it's not that simple), then "Linux" already accounts for about 30% of Web requests
 
Links 26/08/2026: Patent Troll InterDigital Utilises Software Patents in Unconstitutional Court, "WikiHow Launches Copyright Infringement Suit Against" LLM Plagiarism
Links for the day
The Register MS Has New Fake Article ("SPONSORED FEATURE") With "AI" 21 Times In It
The Register MS is one among many culprits
Gemini Links 26/08/2026: “Doomsday Clock”, Rwanda Genocide, and Boasting About Using LLMs Instead of Writing Code (Due to Employer's Pressure)
Links for the day
Twitter is Not an API or a Communication Site, It's a Really Bad Site That Forces You to be Enslaved by Its Algorithm (Amplifying Its Owner's Worldviews)
the crackdown on Nitter means we should all avoid accessing or linking to x.com (Twitter)
GNU/Linux Rose in Caribbean Islands
combined population is measured at 44,182,048
IBM's Quantum Computing Lies Explained Again by Sabine Hossenfelder
To become a CEO at IBM one must lie
Controlling Culture and Social Behaviour by Digital Locks
if you don't fully control the technology in your possession, then you're not using that technology, this technology covertly uses you
Links 26/08/2026: Election Bribery (aka Vote-Buying) Deemed "OK" in the US, "Nitter is Shutting Down After a Cease and Desist Letter" by MElon
Links for the day
Analogue So Much Better and Faster
From what we can gather, the tram ticketing system does not use Windows; we never saw it crashing or rebooting (or showing some Windows logo) in decades, so we assume it runs some kind of Linux
Linux Today Dumped All Social Control Media Last December
Linux Today seems to have concluded that all Social Control Media is just a waste of time
Don't Say X.com is OK Because People Can Access It by Alternative Means
Can Mozilla please clarify who inside Mozilla greenlit a return to X.com?
The Reach of techrights.org Is Increasing
We are on the side of women victims
SLAPP Censorship - Part 162 Out of 200: An Outline of Events
An outline of events
Pushed to Live
We still have some other work - stuff related to the editing of pages - which is work in progress and has been subjected to testing for many months
GNU/Linux Measured at 10% in Germany, Based on Cloudflare
It's peaking late at night
Richard Stallman's GNU Project Began 42 Years Ago With GNU Emacs and More
GNU Project announced almost 43 years ago (next month it's the anniversary)
Fake Articles "Sponsored by HPE" Published in The Register MS
Selling proprietary products as 'alternatives' to other proprietary products
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, August 25, 2026
IRC logs for Tuesday, August 25, 2026
Gemini Links 26/08/2026: Journal Plans and Extending Finger Protocol
Links for the day
An Explainer About Injunctions Done Wrong - Part I - Saving Money Where Money Cannot be Saved
Of course Garrett not being able to afford his own case is a key factor here
Links 25/08/2026: "U.S. Marines Cancel Drill With South Korea", "UK Prime Minister Burnham Arrives in Ukraine"
Links for the day
Not for the First Time This Week, Site Called "It's FOSS" is Promoting Software That is NOT FOSS (And It Knows It)
Is this an editorial choice? Advertising? What is it?
Gemini Links 25/08/2026: Geometry and FidoNet History, "Goodbye I2P and Yggdrasil, Welcome Telnet!"
Links for the day
Links 25/08/2026: Microsoft Salaries Leaked Again, "Oasis Photograph Sparks Copyright Lawsuit"
Links for the day
Microsoft Trots Out Its Propaganda Agent Preston Gralla to Make It Sound Like Microsoft Breaks Up With China (Reality: Microsoft Got Dumped by China)
This discredits any publisher that plays along
GNU/Linux Did Not Start in 1991 and America Wasn't Discovered by Europeans
it'll be 43 next month
SLAPP Censorship - Part 161 Out of 200: Low Standards in Defamation Cases Just Muddy the Waters and Distract From Legitimate Cases
The judge at the trial said that Garrett's case was a waste of the court's money
Rolling Out Some Changes Soon
To the regular reader no change will be seen
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, August 24, 2026
IRC logs for Monday, August 24, 2026
Gemini Links 25/08/2026: Separated by Plexiglass, Low-Tech Information Networks, Jörg Rippel Comes to Geminispace
Links for the day
The Tragedy of Software Developers Making Up Narratives and Making Excuses for Plagiarism (of Their Own Work, Too)
one lingering issue is that many who vote in Debian GRs receive money from slop companies
Evri Makes Us Optimistic About the Collapse of the Slop Pyramid Scheme (Bubble)
Do not be seduced by false promises of "automation" or "intelligence" where only automation may exist but no intelligence at all
Congrats to Linux.org for Adopting or Getting Back to IRC
This is the way the Net ought to work and was originally designed to work [...] IRC as a protocol turns 38 this month
Links 24/08/2026: "Journalism Can Help Expose Bad Science And Trigger Real-World Change"; Further Suppression and Censorship in China/HK
Links for the day
Gemini Links 24/08/2026: Soul Mentality, Words to Live by, Mozz.us Gemlog Resumes, Smol Conversations
Links for the day
Today The Register MS Published Greenwashing Spam for the Slop Pyramid Scheme, It Mentions "AI" 29 Times
More people need to talk about the role of the media in this pyramid scheme
Slop Plagiarism and Chatbots Are Killing Evri (They Infuriate and Insult Clients)
Slop destroys companies and leads to misery (miserable clients, time-wasting)
Links 24/08/2026: Re-defining the IndieWeb and "Data Center Backlash Bursts Into the Midterms"
Links for the day
The Issue With Omarchy is the Slop, the Politics Are a Side Issue
Those corporations do not oppose slop, they participate in it
In South Korea, Steady Increases for GNU/Linux
authorities said they would migrate to GNU/Linux or consider moving in that direction
SLAPP Censorship - Part 160 Out of 200: In Astounding Repetition of Last Year, Brett Wilson LLP Deliberately Ignores Holidays of People It is Attacking and Crushes Principles of Access to Justice
Disconnected from the law
Links 24/08/2026: Vision and Skill, Doing Good, Chiperia Project
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, August 23, 2026
IRC logs for Sunday, August 23, 2026