Bonum Certa Men Certa

Microsoft Claims Credit for Failing in Security

Servers rack - amateur



Summary: Latest security issues and systematic deception, mostly from Microsoft and its various boosters across the Web (giving credit to Microsoft after Microsoft messed up)

Gratis as in Lock-in



A FEW days ago we wrote about Microsoft's attempt at disconnecting the air supply from third-party AV vendors, at least in small businesses. This would only decrease security due to monoculture, decreased competition, and lack of incentive to improve. The funny thing here is that Microsoft sells a vulnerable operating system and then claims to be distributing "free of charge" (only to some people) what ought to have been a characteristic of the operating system, not an add-on. The spinners from Seattle call it a "free" anti-virus software and what's meant by free is not freedom. It's free as in gratis, with lock-in. It decreases one's personal freedom and also impedes freedom of choice. A better headline than "Free Anti-Virus Protection Spurs More Robust Options" would be "Free-of-charge Anti-Virus Pseudo-protection Depresses More Robust Options".



Watch the Indian press turning the whole thing into Vista 7 promotion: "IT major Microsoft has launched a campaign to help computer users identify threats to their systems and how their networks can be made secure using Original Windows 7 that now comes with the advantage of Microsoft Security Essentials."

So Microsoft wants to dump Security Essentials on the market (as expected by many people all along) and already we learn that "Scareware Apes Microsoft Security Essentials". Microsoft has always performed very poorly among the security products already available and well established. "Anti-virus systems get tested" says The Inquirer which gives the following details:

A NUMBER of the most common anti-virus security systems have had a beady eye passed over their effectiveness and fitness for purpose in an assessment.

The study, which was carried out by the Austrian AV Comparatives group, looked at twenty products from the main providers that volunteered to take part.

We do not know who if anyone refused, but AV Comparatives said that it had limited test subjects to no more than twenty and required that participants adhered to its undisclosed criteria.


"Over half of all apps have security holes," claims Veracode (which we mentioned in [1, 2]).

More than half of all software applications failed to meet an acceptable level of security, according to a study based on real-world code audits by application security firm Veracode.

Around 57 per cent of applications failed to pass muster when first submitted to Veracode’s cloud-based testing service. A similar 56 per cent of finance-related applications failed first testing by Veracode’s security audit. The quality of the code used in many business-critical banking and insurance operations was simply not up to snuff.


ASP.NET Under Attack, Spin



In security news, the other major issue last week was the Microsoft ASP.NET vulnerability, which we wrote about in [1, 2, 3, 4].

“Is this really praise-worthy, especially when someone responds to flaws which the same someone is responsible for?”The ASP.NET problem alarmed Microsoft a great deal and the PR spin strives to make Microsoft be seen as responsive. An advisory was quickly issued [1, 2, 3] because of bad publicity and because it was already being exploited (a demo existed). There is only a temporary fix, not a permanent one. There are third-party fixes.

So, once again Microsoft pays attention to flaws a tad too late and then scrambles to limit damage it could probably prevent. Is this really praise-worthy, especially when someone responds to flaws which the same someone is responsible for?

Just like in the case of Russian spin [1, 2], Microsoft is trying to make itself look like the saviour rather than the problem. Lee Pender of the Microsoft boosters is trying to make Microsoft look good by painting it as responsive and responsible. To quote: "Well, late last week, we got an update from a Microsoft spokesperson who wanted to tell us that Microsoft hasn't just buried its head in the sand on Stuxnet."

We wrote about Stuxnet in [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14].

Microsoft-Police



Over in Australia, Microsoft is involving the police right now (funded by taxpayers) [1, 2, 3, 5]. It's about a computer scam that affects Microsoft.

Twitter and Fog Computing



The other day we wrote about the major problem Twitter.com was having. Half a million Twitter users are said to be affected by a Twitter worm and Slashdot discusses the matter before and after the patching. Here are "the names and faces behind the 'onMouseOver' Twitter worm attack". It's one of those risks of Fog Computing. Even a teenager turns out to have been smart enough to do it.

But later, some mischievous users of the site started using the exploit to make people "retweet" infected messages (when they hovered over a tweet with the code inserted) that they had not authorised.


The guy is Australian, so will the police get involved? Or does the Australian police get involved only to help Microsoft?

Recent Techrights' Posts

Salaries Are Counted in Money, Not in Participation in the Employer's Scheme
articles greatly exaggerating GAFAM salaries
Even Linux Cannot Cope With Slop
Bots on the Web are truly obnoxious
 
SLAPP Censorship - Part 167 Out of 200: The Court of Appeal Might be the Next Step
Today is our last vacation day
German Government Sponsors IBM Because of GNU/Linux
Flatpak is sponsored by, run, and controlled by IBM
Richard Stallman Speaks to Christine Hall of FOSS Force, stallman.org is Down for Over a Day
interview does a good job addressing the hype about LLMs too
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, August 30, 2026
IRC logs for Sunday, August 30, 2026
Gemini Links 31/08/2026: Holidays, Stream of Consciousness, and Posting Online
Links for the day
Anniversaries Next Month
The month should be otherwise quiet and uneventful for us
Coding is Not Obsolete
we drown ourselves in chaff to meet "LOC" objectives while ignoring everything else
Microsoft Layoffs Perpetual But Silent, People Pushed Out Using Pressure or Incentive Schemes
Earlier this month we named some of the programs
Links 30/08/2026: Apple Rant and LLM (Slop) Scrapers Target Gemini Protocol and Gopher
Links for the day
Walls in Free Software
mind your own business and move on
What a Summer!
Tomorrow is the last day of this month
Links 30/08/2026: Soldiers in Niger Attack Presidential Palace and Airport, Nepali City Struggles to Handle the Many Dead Bodies
Links for the day
Clownflare Sees GNU/Linux Rising to 11% This Past Week
Is it the year of "Linux in China"?
Links 30/08/2026: Russian Strike on a Ukrainian Warehouse and Rhetoric Escalations
Links for the day
Gemini Links 30/08/2026: Photography, Paper Books, Linux Kernel and the Debian Projects Permitting Slop Plagiarism
Links for the day
Imagine a World Where Nobody Fights for Software (and Computing) Freedom
The community keeps fighting back, so some of these ambitions are delayed or watered down
FSF Has Grown (More Staff) After a Year of Financial Growth
On October 4 the FSF turns 41
GNU/Linux Has Become More Mainstream in the United Kingdom
It's a long weekend here and we guess some people dabble in GNU/Linux migrations, at least at home
SLAPP Censorship - Part 166 Out of 200: Garrett Wasn't Found Innocent Per Se, the Court Wanted More Evidence of Who Was Behind Particular Accounts Using Tor
It's complicated
Criminals Don't Obey Laws, California Does Not Enhance Online Safety
It has been a while since we last mentioned so-called 'age-verification' laws
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 29, 2026
IRC logs for Saturday, August 29, 2026
Links 29/08/2026: Stop the Hate, Goldfish Myths, and xmpp.nz
Links for the day
Links 29/08/2026: Wave of Social Control Media Bans, Suno Data Breach Class Actions
Links for the day
Links 29/08/2026: Microsoft GitHub Outage (Again), "Displaying Ads Directly on Your Monitor", and "Election Deniers Could Soon Control Elections"
Links for the day
IBM is "Taking the PIP" (Piss), People 'Retire' 'Voluntarily' to "Focus on Family"
IBM has a billion bucks for 'the butcher', but not a million dollars for critical projects and initiatives in Free software
It Should be Uncontroversial to Say That Social Control Media is a Weapon
Democracy is not compatible with the likes of Kapo-Berg and MElon controlling public discourse of billions
Misuse of Bots (Now Sold as "Agents", "Hey Hi", "Automation", and "Efficiency")
They even try to rebrand robotics as "hey hi" and try to sell slop as "work"
Debian: Plagiarism OK, Just be "Responsible" About It
The result isn't the worst, but it's not good either
Don't Let Them Kill Activism
Are the oligarchs shutting the lid on activism and whistleblowers?
SLAPP Censorship - Part 165 Out of 200: Two Years Since My Wife and I Sued
In early September 2024 we hit back
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, August 28, 2026
IRC logs for Friday, August 28, 2026
Gemini Links 29/08/2026: Death Notice, Systems Biology, and Gopher
Links for the day