EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

11.13.14

Windows ‘Update’ and NSA Back Doors, Including a 19-Year Bug Door in Microsoft Windows

Posted in Microsoft, Security, Windows at 12:22 pm by Dr. Roy Schestowitz

Summary: The back doors-enabled Microsoft Windows is being revealed and portrayed as the Swiss cheese that it really is after massive holes are discovered (mostly to be buried by a .NET propaganda blitz)

Windows ‘Update’, which essentially translates into Microsoft manipulating binaries on people’s machines without any changelog (at least not in source code form), is making the news again this month. Windows ‘Update’ is happening quite often (a monthly recurrence), but this time there is a lot to say about it.

The British NHS, which holds full medical records of very many individuals, recently received a lot of flack for sticking with an unsupported operating system that was released when I was a teenager instead of upgrading to recently-built Free software like GNU/Linux. Guess what happened to the NHS? “NHS XP patch scratch leaves patient records wide open to HACKERS” says the British press, meaning that not only the NSA gets access to NHS data:

Thousands of patient records could be left exposed to hackers, as up to 20 NHS trusts have failed to put an agreement in place with Microsoft to extend security support for Windows XP via a patch, The Register can reveal.

Another story of a botched update of Windows says that “Crypto attack that hijacked Windows Update goes mainstream in Amazon Cloud”:

Underscoring just how broken the widely used MD5 hashing algorithm is, a software engineer racked up just 65 cents in computing fees to replicate the type of attack a powerful nation-state used in 2012 to hijack Microsoft’s Windows Update mechanism.

That’s what one gets when using weak ciphers that the NSA promotes and Microsoft willingly spreads. Windows Update is a dangerous tool for many reasons not just because it is bricking Linux devices these days but because it’s a tool that gives the NSA a lot of power. Before an update kicks in the NSA is given information that allows it to take full control of PCs with Windows, remotely even (this is done every month). This may sound benign until one learns about Stuxnet (weaponised malware of the NSA) and considers this latest Patch Tuesday:

Microsoft is issuing the largest number of monthly security advisories since June 2011, five of them critical and affecting all supported versions of Windows. And applying the patches will be time consuming, experts say.

“Next week will tell us how many CVEs are involved but suffice to say, this patch load will be a big impact to the enterprise,” says Russ Ernst, the director of product management for Lumension.

CBS, being not just a proponent of espionage, mass surveillance, assassination and violent wars but also a proponent of back doors, had its site ZDNet downplay the above. “So far in calendar year 2014,” it said, “Microsoft has fixed 215 vulnerabilities in Internet Explorer” (lots of potential NSA back doors). Then come some lame excuses and damage control from Microsoft in the update, trying to make its bad record look like a positive, neglecting that fact that Microsoft has been secretly patching holes to yield fake numbers and give a false sense of security. Here is the full summary:

So far in calendar year 2014, Microsoft has fixed 215 vulnerabilities in Internet Explorer, with more coming out today. There have been security updates to Internet Explorer every month this year except for January.

This other report, titled “Potentially catastrophic bug bites all versions of Windows. Patch now”, does not entertain the possibility of back/bug doors in Microsoft Windows being exploited, despite that fact that Microsoft already told the NSA (prodifing exploit knowledge), which undoubtedly engages in illegal intrusions/cracking. A report from IDG notes that this bug is nearly two decades old and add that only “[w]ith help from IBM, Microsoft has patched a critical Windows vulnerability that flew under the radar for nearly two decades. ”

“How many times might this flaw have been exploited by now?”So IBM, despite having no access to source code (as far as we can tell), was perhaps the only reason why Microsoft addressed this issue two decades late, eh? How many times might this flaw have been exploited by now? A reader of us, alluding to that nonsense .NET PR, explains: “Perhaps a big reason for the PR teams trumpeting the open-core or freemium model?”

It sure serves as a good distraction. When Windows XP support (patches) came to an end a Microsoft-connected firm immediately (on the very same day) started throwing brands and logos in relation to an OpenSSL bug, stealing the show and spreading FUD for many months, generalising it so as to appear like a serious, inherent issue in FOSS.

Watch this critical remote code execution flaw in Windows. It is extremely serious, but there is no logo or brand for it (unlike FOSS FUD like “Heartbleed” or “Shellshock” — with a brand that was even perpetuated by the Russia-based Mandriva the other day).

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Hey, Where's Red Hat (IBM)?

    Red Hat is conspicuously silent at these critical times (in its home country); Must be too busy hailing and cashing in on Trump's military (state) while dishing out shallow and self-contradictory diversity PR/fluff…



  2. Microsoft's Latest Vapourware About Supercomputers

    Microsoft has spent almost two decades dropping supercomputers vapourware on the media, but those misinformation dumps always turn out to be 100% hot air, no substance



  3. 2020: A Time for Resolutions or Revolutions?

    There are nonviolent means by which the current system can be corrected; we need to convince peers and relatives to change the way they behave and not cooperate with unjust elements of the system



  4. IRC Proceedings: Tuesday, June 02, 2020

    IRC logs for Tuesday, June 02, 2020



  5. The Gates Press (GatesGate) -- Part I: Lost the Job After Writing an Article Critical of Bill Gates for Attacking Some Actual, Legitimate Charities (Because They Had Spread GNU/Linux)

    The sociopaths from the fake 'charity' of Bill Gates would go to great lengths to squash criticism and also to eliminate critics; this series tells the story of some of those personally affected



  6. Don't Fall for the Spin, Microsoft is Laying Off Workers and It's Not Just Because of the Pandemic





  7. All They Want is Litigation, Not Innovation

    It's getting difficult to ignore or to overlook the fact that the 'litigation lobby' (the likes of Team UPC and today's EPO management, guided by groups like the Licensing Executives Society International) doesn't care about innovation and is in fact looking to profit by crushing innovation



  8. Reminder: Microsoft Profits From Crushing Protesters for Donald Trump

    Don't lose sight of the fact that what's going on in the United States right now is very profitable to Microsoft



  9. No, GNU/Linux Isn't at 3% and Windows Isn't at Over 90%, Either

    This ludicrous idea that "Linux" (however one defines it) enjoys just 3% of the "market" is false and it should be treated as laughable spin (it is being widely promoted this week, often by Microsoft boosters looking to make charts where Windows stays at above 90% and Vista 10 is 'gaining'... at the expense of Windows)



  10. Links 3/6/2020: Devuan Beowulf 3.0.0 and Tails 4.7 Released

    Links for the day



  11. Links 2/6/2020: New Firefox Release (77), Debian-based MX Linux 19.2, KDevelop 5.5.2, GNU/Linux Growth on Desktops/Laptops

    Links for the day



  12. Techrights Can Figure Out Source Protection/Anonymisation Whilst Operating Very Transparently

    We're still quite radically transparent whilst at the same time enjoying 100% source protection record; we're also improving the software we use to publish more quickly and efficiently



  13. IRC Proceedings: Monday, June 01, 2020

    IRC logs for Monday, June 01, 2020



  14. This is How GNU Finally Dies

    "Brace for when GNU falls the way that OSI, FSF, FSFE, Mozilla, and the Linux Foundation did."



  15. Latest Microsoft Layoffs Spun as 'Innovation' (There's Always a Positive PR Angle)

    The public is expected to simply ignore the fact that Microsoft is laying off employees (again); instead we're expected to think it's all about Microsoft being very brilliant and innovative



  16. Microsoft Playing the Victim, Irrationally 'Hated' by Victims of Its Abuse

    We're meant to believe that those whom Microsoft bribes against are the opinionated 'haters' and Microsoft is a victim of 'hate'



  17. Links 1/6/2020: Linux 5.7, FOSSlife Born, LibreOffice 7.0 Beta1, Linux Mint 20 Making Early Promises

    Links for the day



  18. Linux Without Linus

    The Linux Foundation seems to be acting like Linus (Linux founder) is somewhat of a liability (forcing him to take a ‘break’ from his own project) while taking even the most notorious proposals from corporations, including those that called Linux a “cancer”



  19. What It Would Take for Linus Torvalds to Leave Linux Foundation Without the Linux Trademark and Without Linux

    It's nice to think that the founder of Linux can just take his project and walk away, moving elsewhere, i.e. away from the Microsoft-employed executives who now "boss" him; but it's not that simple anymore



  20. The Past Does Not Go Away, Except From Short-Term Memories

    People who are drunk on power and money (sometimes not even their own money) like to portray themselves as the very opposite of what they are; but in the age of the Internet it's difficult to make the general public simply forget the past and "move on..."



  21. IRC Proceedings: Sunday, May 31, 2020

    IRC logs for Sunday, May 31, 2020



  22. Links 1/6/2020: OpenMandriva Lx 4.1 2020.05, Linux Lite 5.0 Release, FreeBSD 11.4 RC2

    Links for the day



  23. It's a Common Mistake and Common Misconception/Error to Treat Microsoft as Just Another 'Large Company' (or 'Big Tech')

    What's wrong about Microsoft isn't its size; what's wrong with Microsoft is its behaviour, which isn't just illegal (crimes are the norm) but also hugely unethical



  24. Lessons of Michael Arrington (About Microsoft)

    Microsoft and Bill Gates have a long history bullying their critics; the quote above (or below) shows how even people who advertise with Microsoft are becoming the target of abuse



  25. 'Best' of Both Worlds: GNU/Linux Freedom + Malware With Keyloggers and DRM

    Running a Microsoft-controlled GNU/Linux instance under Vista 10 ("Windows Subsystem for Linux") in the age of virtual machines, dual boot and containers makes as much sense as chopping some carrots to go with the veal meal to appease vegetarian diners



  26. First They Bribe the Employer, Media Lynch Mobs May Follow

    The 'cancel culture' lynch mobs, which leverage social causes (or marginalised groups), remain a convenient means by which to oust one's political/business opposition; but money too is a massive contributing factor and the more one has of it, the easier it is to control media narrative and subversive focus



  27. Upcoming Series Teaser: The Bribery Operation of William Henry Gates III

    Bribery goes a very long way when it comes to the megalomaniac who pays the media to portray him as the world's most generous person



  28. Windows Ransomware Must Not be Unspeakable When People Die in Large Numbers Due to That (and Windows Has Intentional Back Doors)

    Loss of electronic patient records, ransom and downtime among the severe consequences of deploying Microsoft inside hospitals; yet the media rarely names the real culprit (manslaughter charges theoretically possible) and nobody gets punished except those who offer real solutions



  29. IRC Proceedings: Saturday, May 30, 2020

    IRC logs for Saturday, May 30, 2020



  30. Burning the House That Richard Stallman (RMS) Built: An Open Letter to GNU Maintainers Who Opposed RMS

    An open letter to people who petitioned RMS to step down and who outsource GNU projects to Microsoft (GitHub)


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts