EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

12.27.10

Microsoft Cannot Offer Security on the Web, Either

Posted in Microsoft, Security, Windows at 1:36 am by Dr. Roy Schestowitz

Predator

Summary: Vultures keep circling not just Microsoft Windows but just about anything from the company, which failed to comprehend security

THERE are companies that increasingly decide to rely on online services, which they sometimes refer to as ‘the cloud’. There is a false assumption about security though. First of all, if one accesses these services from a Windows-running PC, one is not secure. In China, for example, hackers can access Windows source code, which was never written to be inspected in this way (and many security experts have not had the time to find errors in it prior to release). On the server side too Microsoft is failing based on the latest news:

1. Microsoft BPOS configuration screw up causes data disclosure

Customers of Microsoft’s Business Productivity Online Suite—a cloud-based suite including Exchange, SharePoint, LiveMeeting, and Office Communicator—may have had certain data leaked after a configuration error left their contact information exposed.

The configuration problem left information in customers’ Offline Address Books exposed to other customers. The Offline Address Book is an Exchange feature that allows Outlook users to download a copy of all the e-mail addresses and mailing list aliases that an organization uses, so that they can be used even when disconnected from Exchange. It’s e-mail addresses on those lists that could have been made available.

2. Microsoft BPOS cloud service hit with data breach

Company data belonging to customers of Microsoft’s hosted business suite BPOS has been accessed and downloaded by other users of the software.

The issue affected the Offline Address Book of customers of the Business Productivity Online Suite (BPOS) Standard suite.

Microsoft confirmed the data breach to Webwereld, a Dutch IDG publication.

This is far from being the first BPOS cockup [1, 2, 3] and putting that together with the botnet problem on the client side, there’s no reason to choose Microsoft over GNU/Linux with Google as host, for example. The European politicians recently began talking about Windows botnets, bringing up problems like Conficker and Stuxnet: [via Glyn Moody]

Inside the EU, damages from this botnet were reported in France, the UK and Germany. French fighter planes were unable to take off after military computers were infected by Conficker in January 2009. The German army reported in February 2009 that parts of its computer network were infected by Conficker, making the websites of the German army, and the Defence ministry unreachable and preventing them from being updated by their administrators. Certain IT services, including e-mails, were unavailable for weeks to the UK Ministry of Defence personnel in January/February 2009 after they were infected by the Conficker botnet.

In the last few days experts at international level have launched an alert for a new type of malicious computer warm called Stuxnet that is infecting a high number of power plants, pipelines and factories and could be used to control plant operations remotely. If confirmed, this would be the first case of a highly sophisticated botnet aimed at industrial targets, a development experts don’t hesitate to define ”the first directed cyber weapon”. Botnets like Stuxnet could give wrong information and orders to industrial plants and operate sabotage at several levels, causing severe damages.

Incidentally, there’s advice from Wayne Borean (“My Christmas gift to Windows Users” he calls it) which goes under the heading “Computer Security Suggestions For Microsoft Windows Users” and moving away from Windows is high up on the list. For those who don’t know yet, for Windows administrators it may have been a tough holiday, as usual (this happens every year at this time) because “Microsoft confirm[ed] critical un-patched Internet Explorer CSS vulnerability” just before Christmas:

The flaw could allow malicious users to run unauthorised code remotely inside the iexplore.exe process. Proof-of-concept code is currently available that exploits the vulnerability. The code bypasses ASLR and DEP security protections in Windows. Security firm Vupen warned of the vulnerability earlier this month.

Here is more about the zero-day exploit: [via]

A remote code execution vulnerability against Internet Explorer was announced recently, and a proof-of-concept exploit has already been added to the Metasploit products.

And finally, consider the following batch of news:

i. Malware Posing as Fake Desktop Utilities Instead of Phony Antivirus

Recently, researchers at GFI Software have noticed an increase in the number of fake security software scams purporting to be disk utilities that fix disk errors. Instead of listing Trojans, these security alerts pretend to find disk fragmentation or file system integrity problems.

ii. Bummed-out users give anti-virus bloatware the boot

One in four users turned off their anti-virus protection in response to performance problems after they installed security software, according to a survey by security software firm Avira.

The poll of users of the German anti-virus outfit, which like AVG and Avast offers free security software to consumers, also found that more than three in five (62.8 per cent) users had tried multiple anti-virus products over the last year.

The problem is not just Windows; it’s Microsoft products in general.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Shame on MapR for Pursuing Software Patents While Pretending to Stand for Free/Open Source Software

    The patents gold rush sees another company joining the 'fun', albeit this company should campaign hard against software patents rather than pursue any



  2. Doomsday Scenario in the Back Mirror as Michelle Lee Keeps Her Job (and Much-Needed Patent Reform) at the USPTO

    The future of patent reform, i.e. tackling overpatenting and patent trolls, looks somewhat more promising with today's confirmation of Lee's 'extended tenure' at the Office



  3. Links 19/1/2017: PulseAudio 10.0, Linux 4.9 Longterm Kernel

    Links for the day



  4. Corporate (Wall Street) Media Agrees That Brexit Dooms the Unitary Patent (UPC)

    The nonstop lies or the fake news about the UPC starting "real soon now" don't quite pass a reality check or a basic assessment based on fundamental concepts, such as the UPC's facilitation of subordination (to Europe) in the United Kingdom



  5. Farce of an 'Independence' for the Boards of Appeal as Another Ally of Benoît Battistelli Enters as Parasite Inside the 'Overseer'/Host

    The latest cluster of lies from the President of the European Patent Office (EPO) and direct refutation of false claims of independence for the Boards of Appeal, where the former Vice-Presidents can flock, just like the Mini Minion (Minnoye) of Battistelli



  6. Links 18/1/2017: Red Hat's OpenShift 3.4, Mozilla's New Logo/Branding

    Links for the day



  7. Union-Busting Action by Team Battistelli Takes Heavy Toll, Techrights Will Continue to Expose EPO Injustices to the World

    The Staff Union of the European Patent Office, SUEPO, which faced unprecedented and probably illegal (based on local laws) attacks, is being weakened by the worst President ever, whose own management team seems to be collapsing along with the institution he is destroying in just a few years



  8. A Lot More Fake News About the UPC, Trying to Convince People That the UK is Ratifying (It's Not, It Cannot)

    Response to some of the latest misleading (self-serving) whispers about the fate of the Unified Patent Court (UPC), which is in a deadlock due to Brexit



  9. Rumours Suggest That EPO Management is Aware of Decline in Patent Quality and is Thus Actively Lying About it to the Media/Public

    Whenever Battistelli brags about patent quality he may be consciously and deliberately lying through his teeth if the latest rumours are correct



  10. Links 17/1/2017: GIMP Plans, New Raspberry Pi Product

    Links for the day



  11. Resumption of EPO Propaganda ('Meet the President') Officially Starts Tomorrow

    Yet another one of these foolish 'Meet the President' stunts, scheduled to take place tomorrow morning



  12. Caricature: Battistelli's New Year's Resolution (More EPO Lies)

    The latest cartoon being circulated within the European Patent Office (EPO)



  13. Donald Trump Gives New Hope to Patent Aggressors and Patent Trolls

    Pessimism about the prospects of patent progress or patent reform in an age of staunchly pro-business Conservatives and glorification of protectionism



  14. More Fake News About the Unified Patent Court (UPC) Based on Lobbying Tactics From Bristows UPC and the Preparatory Committee

    Unified Patent Court (UPC) lobbying has gotten so bad that it now infiltrates general media outlets, where people are asked to just blindly assume that the UPC is coming and is inevitable, even though it's clearly in a limbo and is unlikely to see the light of day



  15. EPO Totally Silent for a Month, But Deep Inside There Are Serious Cracks

    The situation at the EPO seems to be pretty grim, even at the top-level management, and the EPO has gone into permanent silence mode



  16. Links 16/1/2017: Linux 4.10 RC4, Linux Mint 18.1 'Serena' KDE Edition Beta

    Links for the day



  17. 'Financial Director' Publishes Fake News About the Unitary Patent (UPC)

    Response to some of the latest UPC propaganda, which strives to misinform Financial Directors so as to enrich the author and his firm



  18. Independent and Untainted Web Sites About Patents Are Still Few and Rare

    Commentary about news sources that we rely on, as well as the known pitfalls or the vested interests deeply ingrained in them



  19. The 20% Rule: Patent Trolling Suffers Double-Digit Declines and Patent Troll Technicolor is Collapsing

    Significant demise or total catastrophe for the modus operandi (method) of going after companies with a pile of patents and threats of litigation



  20. US Supreme Court Did Not End Apple's Patent Disputes Over Android (Linux), More Cases Imminent

    An overview of some very recent news regarding the highest court in the United States, which has been dealing with cases that can determine the fate of Free/Open Source software in an age of patent uncertainty and patent thickets surrounding mobility



  21. Links 15/1/2017: Switching From OS X to GNU/Linux, Debian 8.7 Released

    Links for the day



  22. Number of New Patent Cases in the US Fell 25% Last Year, Thanks in Part to the Demise of Software Patent Trolls

    Litigation and prosecutions that rely on patents (failure to resolve disputes, e.g. by sharing ideas, out of court) is down very sharply, in part because firms that make nothing at all (just threaten and/or litigate) have been sinking after much-needed reform



  23. America Invents Act Improved Patent Quality, But Right Wingers Threaten to Make It Worse Again

    The past half a decade saw gradual improvement in assessment of patents in the United States, but there is a growing threat and pressure from the patent microcosm to restore patent maximalism and chaos



  24. PTAB -- Not Deterred by Courts -- Continues to Invalidate a Lot of Software Patents

    The Patent Trial and Appeal Board (PTAB) continues to make progress reforming the patent system by eliminating a lot of patents and setting an example (or new standards) for what is patent-eligible after Alice



  25. EPO Abuses Come Under Fire From Politicians in Luxembourg

    Luxembourg is the latest nation in which concerns about the EPO's serious abuses are brought up not only by the media but also by politicians



  26. Constitutionality as a Barrier and Brexit Barriers to UPC Keep the Whole Pipe Dream Deadlocked

    The UPC is still going nowhere fast, but the demise (or death) of the UPC as we know it must not be taken for granted



  27. Links 14/1/2017: Wine 2.0 RC5 and AryaLinux 2017 Released

    Links for the day



  28. Links 13/1/2017: Linux 4.9.3 and Linux 4.4.42

    Links for the day



  29. Brexit Means No UPC (Unified Patent Court)

    Now that Jo Johnson, Boris Johnson's brother, is officially declared the new minister for intellectual property in the UK everything that Lucy Neville-Rolfe wrote is as solid as paper bag on a rainy London day



  30. Patent Trolls and Software Patents: CloudTrade, Patent Practitioners Density, and Via Licensing

    Software patents armament from a British company, charted concentration of the patent microcosm in the United States, and US-leaning patent trolls that prey on China


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts