Bonum Certa Men Certa

“Microsoft Will Have Blood on Its Hands.”

Fertilizer



Summary: In the midst of Wikileaks drama we learn that an executions-savvy regime will benefit from Windows cracks

"Windooze insecurity puts Iranian dissidents in mortal danger," states the subject line of an anonymous USENET post, quoting this article. "A Dutch CA called DigiNotar," says the poster, "was hacked by Iranian hackers, likely with the intention of intercepting SSL traffic (Gmail, Facebook etc.) of Iranian activists and freedom fighters. I checked DigiNotar's website and guess what operating system they're using? You guessed it! WINDOOZE ASP.NET!!!



"So now Microsoft will have blood on its hands. Its insecure graphical-shell-pretending-to-be-an-operating-system is now possibly responsible for the deaths and prosecution of many Iranians!! [..] THIS COMPANY SHOULDN'T BE SPLIT UP, IT SHOULD BE SHUT DOWN"

“And as long as otherwise respectable companies insist on e-mailing me "slide shows" in the form of IrfanView .exe files because "it's so user-friendly", Windows will remain as secure as a wet paper bag.”
      --Richard Rasker
A more moderate Dutch poster, Richard Rasker, wrote separately: "I guess we've all heard how a Dutch Certificate Authority by the name of Diginotar, formerly used by even the Dutch IRS authority and countless city councils, has screwed up severely, when their systems were breached by Iranian hackers, who managed to poison the world with many hundreds of bogus certificates. Then they screwed up even more by hushing up about the hack for months -- a huge no-no in a world where trust is the highest good.

"And now it turns out that the screw-up has soared to even greater heights. In case you wondered what OS these people were using, here's the answer:

http://webwereld.nl/nieuws/107833/fox-it--diginotar-gebruikte-niet-eens-virusscanner.html

"For those who don't understand Dutch:

"Fox-IT: Diginotar didn't even use a virusscaner

Fox IT has delivered a devastating verdict on Diginotar's infrastructure. The company didn't adhere to agreements and procedures. Even elementary security measures were totally absent.

These are the conclusions from an investigation by Fox IT into the security breach at Diginotar, as passed by Webwereld and NU.nl through a governmental source. It turns out that all operations were taking place from within one single Windows domain. This made it possible to gain access to the certificate administration from any work station; logging in to one's work station was sufficient to get access to the systems. This is a mortal sin in the world of IT security. In addition, Diginotar was already aware of the abuse of its certificates as early as July.

No secure zones Even when issuing certificates for government use, standard security rules were trodden underfoot. The government's PKI computers operate from within a secure vault, and should never have been connected to Diginotar's network. Yet even on those machines, investigators found evidence that connections had been made to the Windows domain.

..." [no virus scanner ... no proper logging ... no strong password enforcement ... inadequate intrusion detection ... hackers got & used administrator rights ... certificates chucked in an easily accessible database ... etcetera]


"Now I won't say that this could never have happened in a Linux environment," notes Rasker, "but for a screw-up of these truly epic proportions, Windows is the OS of choice -- because it traditionally "makes things easy", and because Windows users are traditionally not used to working with proper permissions, secure networks and strong passwords.

"And as long as otherwise respectable companies insist on e-mailing me "slide shows" in the form of IrfanView .exe files because "it's so user-friendly", Windows will remain as secure as a wet paper bag. QED."

Recent Techrights' Posts

SLAPP Censorship - Part 189 Out of 200: A Terrible Idea to Condemn Projects for Using Slop 'Code' When Your Own Employer Does This (and Profits From Every Company Doing So) or to Call Distros 'Not Secure' While You Advance Back Doors
"I don’t want a back door. I want a front door."
 
Clownflare Data From Canada
We've like to think many people are attempting to install GNU/Linux over the weekend
SLAPP Censorship - Part 190 Out of 200: Plagiarism, Back Doors, and Sabotage of Linux
This can go on for a decade or longer
Linux Kernel Becoming a Slopfest - Part 5 - Kernel Dependency on Plagiarism Giant Microsoft is a Death Blow to Any Kernel
Microsoft is bringing copyright-infringing slop into Linux
GNU/Linux Has Grown a Lot Lately
Based on Clownflare
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 19, 2026
IRC logs for Saturday, September 19, 2026
Links 19/09/2026: Many Patents Become Candidates for Annulment and Linux [sic] Foundation Takes More Slop Money to Promote Malicious Bots
Links for the day
Gemini Links 19/09/2026: The Fundamental Human Assets, The History of Gopher's "i" Type, and ROOPHLOCH 2026
Links for the day
Links 19/09/2026: "OpenAI and Microsoft Knew They Were Starting a ‘Doom Loop’ [of Mass Plagiarism 'Normalised' by Brute Force] for the web", Calling It "Hey Hi"
Links for the day
8 Series Going on at the Moment in Techrights
4 series about SLAPPs and related matters
Linux Kernel Becoming a Slopfest - Part 4 - Outsourcing to Microsoft, Approaching 10 Gigabytes
Can we blame Microsoft for those DDoS attacks? Partly.
Software Freedom Day 2026 is Today, Week-long Celebration in Brazil
In Brazil, Clownflare reckons about 1 in 20 laptops/desktops might use GNU/Linux already
Red Hat Lost 2,000 Staff (Net Loss)
Maybe by year's end it'll be a 20% reduction
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, September 18, 2026
IRC logs for Friday, September 18, 2026
Gemini Links 18/09/2026: Setting Goals, Tiredness, and Admissions From LLM Purveyors It Was All Along About Building Plagiarism Engines Sold as "Intelligence"
Links for the day
Links 18/09/2026: Microsoft Boasted Slop is Just Copyright Infringement/Plagiarism, Floods in Europe
Links for the day
Slop Ruins Development and Reverse Engineering, It Rewards Retarded "Slop Kiddies" (to Quote Andy ‘TheFlow0’ Nguyen)
Slop is just a fatal cancer that kills the body, then dies with the body it killed
Internet Relay Chat (IRC) and Mailing Lists Are Still Better Than Discord, Slack, and Discourse
Discourse is "open" "bossware"
Links 18/09/2026: Disgust Over LLMs and Why "Agents" (Bots) Are Nothing More Than "Spam"
Links for the day
Software Freedom Day is Tomorrow
events coming
Illegal and Unconstitutional Tribunal That SLAPPs Critics Does the Illegal and Unconstitutional: It "Rubberstamps Software Patents"
This is not a legal system. This is mafia.
Privilege in 'Linux' Foundation (Double Standards) and What the FSF Should Avoid Doing
If RMS can talk about politics, others too should be able to talk about politics
Seems Like Many Microsoft Layoffs Are Going On Right Now (Forever Layoffs)
Like IBM, Microsoft hopes shareholders will not know of morale and financial problems
More Threats From the Person of Restricted Boot Infamy
Remember this is the man who is the principal purveyor of restricted boot and who landed restricted boot in Linux
Snooping EPO Management, Sniffing Up Every Staff Action
It this a problem for whistleblowers? Of course.
Don't Do That
Options do exist. People should exercise freedom.
Iran Has Debunked GAFAM and Cloud Computing as Safety of Data
Cloud of smoke?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 17, 2026
IRC logs for Thursday, September 17, 2026
SLAPP Censorship - Part 188 Out of 200: Used, Then Discarded, by Microsoft (as We Predicted All Along, It's Always Like That)
The longer they carry on with it, the more scandalous this will get
Linux Kernel Becoming a Slopfest - Part 3 - Besieged by LLM Bots, Now Hiding Behind a Wall of JavaScript
The series began 3 days ago
Gemini Links 18/09/2026: Modern Linguistic, Boxing, Turning 40, and Solar MiniServer
Links for the day