Bonum Certa Men Certa

Microsoft's Browser Ballot is Broken Again and Internet Explorer 8 is Critically Flawed

Voter
Poor man's ballot?



Summary: Microsoft makes it difficult to install a Web browser other than its already-installed and already-flawed Internet Explorer 8

THE BROWSER BALLOT has already been through many changes since it was first introduced. Microsoft kept cheating or simply left some self-serving bugs in tact. We wrote about the subject in:



  1. Browser Ballot Critique
  2. Microsoft's Fake “Choice” Campaign is Back
  3. Microsoft Claimed to be Cheating in Web Browsers Ballot
  4. Microsoft Loses Impact in the Web Despite Unfair Ballot Placements
  5. Given Choice, Customers Reject Microsoft
  6. Microsoft is Still Cheating in Browser Ballot -- Claim


Rob Weir from IBM shows that Microsoft's ballot, which it was forced to implement in order to avoid fines (a lot of the press still gets it wrong by characterising it as Microsoft fairness), is simply broken. See the screenshots in Weir's blog as they are self explanatory.

A few weeks ago I wrote about Microsoft’s “browser choice” ballot page in Europe, which in its debut used a flawed algorithm when attempting to perform a “random shuffle” of the browser choices, a feature specifically called for in their agreement with the EU. This bug was fixed soon after it was reported. But I recently received an email from a correspondent going by the name “Skoon” who reported a more serious bug, but one that is seen only in the Polish-language translation of the ballot choice screen.


In other news, there is a major new flaw in Microsoft’s Internet Explorer 8. [via]

The cross-site scripting filter that ships with Microsoft’s Internet Explorer 8 browser can be abused by attackers to launch cross-site scripting attacks on websites and web pages that would otherwise be immune to this threat.

According to a presentation at this year’s Black Hat Europe conference, the issue introduces security problems at several high-profile websites, including Microsoft’s own Bing.com (screenshot), Google.com, Wikipedia.org, Twitter.com (screenshot) and just about any site that lets IE 8 users create profiles.


Yes, Microsoft's browser is still lagging when it comes to security due to negligence and incompetence [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12]. But it's not entirely surprising that while 4 governments encouraged their citizens to abandon Internet Explorer this year, the MSBBC continues to produce Microsoft adverts, including the many Internet Explorer endorsements that we find in the MSBBC [1, 2, 3, 4, 5, 6] on a regular basis (and occasionally report those for scrutiny). Our reader ThistleWeb has more to say about the MSBBC's latest Infomercial:

I saw this promo piece in the BBC about the launch of Microsoft's new Fix-it service and a few things spring to mind. The first is that Microsoft have a long track record of causing more problems than they fix when applying updates. They set Windows to download and apply all critical updates without user intervention. So when a user goes to shut down their PC they have no idea if they have to hang around for 15 mins so that Windows can apply it's updates or not. Similarly they have no idea if those updates will cause a problem when they next start up their PC.

The second is that Microsoft have a history of abusing the term "critical" and slipping in programs like the Orwellian titled WGA (Windows Genuine Advantage). This was apparently a feature a large number of their customers were screaming out for and Microsoft being a listening, concerned company felt they had no choice but to provide; if you believe Micorosoft's PR about it. WGA checks regularly if the copy of Windows it's running on is licensed or unlicensed. If it deems that install of Windows to be unlicensed it causes no end of hassle for the user by disabling services, rebooting, nagware messages about "please contact Microsoft to buy a Windows product key". It's no advantage to customers, only to Microsoft. Yet this has been defined by Microsoft as a "critical" update. To me "critical" means "your PC is at immediate risk without this update".


We have written about this before; in fact, Microsoft marks as "critical" anything that's critical to Microsoft, not to the user. This is probably why one in two Windows PCs is still estimated to be a zombie.

Recent Techrights' Posts

Techrights Headlines as Semaphore
"If you are hearing this, thank you"
 
Gemini Links 01/04/2025: XKCDpunk and worldclock.py
Links for the day
50 Years of Sabotage and a Gut Punch to Computer Science (and Science in General)
Will we get back to science-based computing rather than cult-like following?
3 Months in 2025, 4 Waves of Mass Layoffs at Microsoft, Now Offices Shut Down Permanently
"A recent visit by the South China Morning Post confirmed that the office was dark, unoccupied, and had its logo removed."
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, March 31, 2025
IRC logs for Monday, March 31, 2025
Links 31/03/2025: China Tensions, Bombs Falling in Myanmar After Earthquake
Links for the day
Gemini Links 31/03/2025: Falling Out of Love With Tech, Sunsetting openSNP
Links for the day
R.T.O. at IBM in Texas and Atlanta (State of Georgia) Expected as "Soft Layoffs" Catalyst This Coming Year
It also sounds like more IBM layoffs are in the making
Law Firms Can Also Lose Their Licence for Clearly Misusing It
The bottom line is, never made the false assumption that because you can pile up SLAPPs in a docket you will not suffer from bad reputation or even get disbarred
Link between institutional abuse, Swiss jurists, Debianism and FSFE
Reprinted with permission from Daniel Pocock
LLM Slop Piggybacking News About GNU/Linux and Distorting It
new examples
Links 31/03/2025: Press and Democracy Under Further Attacks in the US, Attitudes Towards Slop Sour
Links for the day
Open Source Initiative (OSI) Privacy Fiasco in Detail: The OSI Does Not Respect Anybody's Privacy
The surveillance mafia that bans dissent or key people (even co-founders) with dissenting views
Gemini Links 31/03/2025: More X-Filesposting and Dreaming in Emacs
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, March 30, 2025
IRC logs for Sunday, March 30, 2025
Links 30/03/2025: Security Breaches, Crackdowns on Dissent/Rival Politicians
Links for the day
Gemini Links 30/03/2025: London Soundtrack Festival, Superbloom, gmiCAPTCHA
Links for the day
Phasing Out Vista 10 in Nations Where ~90% of Windows Users Still Rely on It
Recipe for another Microsoft disaster
The Cost of Pursuing the Much-Needed Reform/Shield Against Strategic Lawsuits Against Public Participation (SLAPPs)
“It is curious that physical courage should be so common in the world and moral courage so rare.”
The LLM Bubble is About to Implode, Gimmicks and Financial Shell Games Cannot Prevent That, Only Delay It
To inflate the bubble MElon is now doing the classic trick of buying from oneself for a fictional value
Links 30/03/2025: Contagious Ideas, Signal Leak, and Squashing Lousy Patents
Links for the day
Links 30/03/2025: "Quantum Randomness" and "F-1 Visa Revoked" in US
Links for the day
Gemini Links 30/03/2025: US as a Threat, Returning to the WWW
Links for the day
Links 30/03/2025: Judge Blocks Dismantling Of VOA, Turkey Arrested Many Journalists
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, March 29, 2025
IRC logs for Saturday, March 29, 2025