Bonum Certa Men Certa

Focus on the Windows Botnets (Microsoft/NSA Backdoors/Bugdoors as Culprits), Not the Weaknesses of the Protocols the Botnets Constantly Exploit (Quantity/Brute Force Always Defy Good Design at Scale)

posted by Roy Schestowitz on Oct 12, 2023

Street Sign Of Broadway

THE toxic garbage emitted or spewed out by Winbots - jargon for botnets running Windows - is a subject that was habitually explored prior to the days of Edward Snowden's NSA leaks. There were all sorts of catchy names for such botnets, or Internet-connected swarms that could enlist new Windows machines as soon as they were connected to the Internet (the Command and Control wasn't just Microsoft's "Windows Update").

A reader notes that all articles about DDoS via HTTP/2 blame the protocol and completely neglect mention of the Windows "Bot Nets (tm)" which make the attacks possible.

We saw and took note of about half a dozen such articles already. So far everything was so shallow and "reporters" just parroted what Google had said.

"HTTP/2 is not blameless," the reader clarifies, "but it is wrong to use it as a distraction from the Windows systems which have been (inappropriately) connected to the Net instead of replaced with secure systems."

We noticed the same around the start of the week, never naming the real issue. The real issue is those botnets. Anything can be defeated at a very large scale, even Clownflare. When Microsoft suffers security breaches it tries to blame users, admins, nation states, attackers etc. instead of admitting that the real issue is itself. Why were there so many holes and no patches in the first place? Who's really to blame here? If you leave your front door open and someone (unwanted/untrusted) walks in, shouldn't the house owner be scolded too?

Sadly we've seen no rebuttal to the spin and we didn't even see much press coverage about it (that's how slow news is, not to mention shallow and casually misleading). Instead, what we saw this morning is this piece distracting from the Windows botnet pandemic, speaking of Mirai (typically Windows) but tying it to "Linux" somehow (see "IZ1H9 Mirai campaign launches DDoS attacks on Linux-based routers"). It says "they can incorporate these newly compromised devices into their botnet, which lets them launch further DDoS and brute-force attacks."

Is Linux the issue here? Typically not. The next sentence right after that says: "FortiGuard strongly recommends that organizations promptly apply patches when available and always change default login credentials for devices."

Yes, because a passwords like "goodmorning" or "letmein" turn out to be the fault of Linux, right?

Other Recent Techrights' Posts

The FSF Board and FSF Beard
So the FSF's Board has grown
Law Firms Facing the Consequences for Patently Abusive Litigation on Behalf of Microsoft Employees Who Got Arrested for Strangulation and Had Done Even Worse Things
Having spent 1.5 years bullying me with patronising letters on behalf of Microsofters, last week they got served a massive bill and, in effect, lost the Hearing
LLMs Breaking Everything
Computing and the Net became a playground for scammers and "bros", like people who "invented" fake currencies and also try to tell us that LLMs spewing out things will have some real value
 
Links 22/06/2025: Giving Up on Smartphones and 'Jaws' at 50
Links for the day
Gemini Links 22/06/2025: Furniture Construction and Bubble for Comments
Links for the day
Links 22/06/2025: Windows TCO Tales and YouTube Getting More Hostile to Users
Links for the day
New Report From the EPO's Staff Representatives in The Hague (LSCTH) Reveals Many Unsolved Issues
Local Staff Committee The Hague (LSCTH) wrote to staff just before the weekend
Links 22/06/2025: More Slop Lawsuits (Copyrights) and "America’s Oligarch Problem"
Links for the day
Gemini Links 22/06/2025: Gigantic Toolchest and Annoying Bots
Links for the day
The Calling
Persist and persevere, justice will come your way
So Far Every BetaNews 'Article' is LLM Slop, So BetaNews is Officially Just a Slopfarm
They just don't seem to value what they have
IBM Rumour: Mass Layoffs (RAs) Lists Being Made for Consulting, With Effect in July 2025
Bogus companies with no viable products and no world-leading (in their field) staff are doomed to perish
Links 21/06/2025: Data Breach With 16 Billion Passwords, Dutch Government Recommends Children Under 15 Stay off TikTok and Instagram
Links for the day
Gemini Links 21/06/2025: Notes about Typst (and LaTeX) and Opos
Links for the day
Microsoft's Competition Tactics: Sabotage GNU/Linux Installs, Block Chrome
Edge is dying
1989: Free Software as "Open" Software (OSI Didn't Coin "Open Source", It Also Predates Linux)
"One man's fight for Free software"
The Microsoft OOXML Modus Operandi: Throw 1,000 Pages of Other People's Work for a Judge to Read Ahead of a One-Hour Meeting
No time to discuss this - that's the point
Formalities Officers (FOs) at the EPO Are in Trouble, Reveals Internal Report
We already know, based on an HR pattern we saw at IBM and elsewhere, that reallocating roles can be prerequisite for dismissal and those who do so expect many to resign anyway
The Web is Slop and FUD, Let's Go to Gemini Protocol
Lupa sees self-signed capsules at 92.4%
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, June 20, 2025
IRC logs for Friday, June 20, 2025
Links 21/06/2025: Phone Bans for Concerts, Tensions in Taiwan Strait
Links for the day
Gemini Links 21/06/2025: Spoilers, Public Yggdrasil Node, Changes to AuraGem Search
Links for the day
"Six years of Gemini!"
From gemini://geminiprotocol.net
Gemini Links 20/06/2025: Summer Updates and Hardware Failures
Links for the day
Links 20/06/2025: Google Shareholder Sues Google and Google Sued for Defamatory Slop ('Hey Hi') Word Salads ('Summaries')
Links for the day
Linux Journal Might Have Become the Latest Slopfarm Targeting "Linux", the Trends Are Concerning for Dying News Sites
They tarnish the Web with junk and then die
On "Learning to Code"
quality may suffer, plus things get bloated
Quick Points Regarding This Week's Court Hearing
it paves the way for us to squash all the SLAPPs from Microsofters
Common Mistake: Believing Social Control Media Will Document Your Writings/Thoughts and Search Engines Like Google Will Help You Find These
Many news sites wrongly assumed that posting directly to Twitter would be acceptable
The Manchester Bees and This Hot Summer
We have had a fantastic week so far this week
Gemini Protocol Enters Its Seventh Year, Growth Has Accelerated!
Maybe in June 20 2026 there will be over 3,500 active capsules?
Mastodon and the Fediverse Have an Issue: Liability for Content (Even in Other Instances) and Costs
self-hosting is the only logical path forward
Why Microsoft and Its 'Hey Hi' (Slop) Frenzy Fail While Sinking in Deep, Growing Debt
Right now, like Twitter around the time it was sold to MElon, "open" "hey hi" is a big pile of debt with a lot to pay for that debt (interest payments)
Europe is Leaving Microsoft, the Press Coverage Isn't Sufficiently Helpful
The news is generally positive, but the press coverage leaves so much to be desired
Slopwatch: Linuxsecurity, BetaNews, and Linux Journal
slippery slope
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, June 19, 2025
IRC logs for Thursday, June 19, 2025
Gemini Links 20/06/2025: Gemini Protocol Turns 6!
Links for the day