Bonum Certa Men Certa

Despite Security Lies and Security Failures, Microsoft Instructs Worldwide Cybersecurity Summit

Protect your money
Billions or trillions of dollars are lost or saved based on one's security



Summary: Microsoft is telling lies about the number of flaws in its software, it admits failing to secure its software (statistics indicate exacerbation), and yet, Scott 'Windows zombie tax' Charney gets to tell participants of the Worldwide Cybersecurity Summit what to do next

IN OUR most recent post about Windows insecurity news we showed that nothing is improving at Microsoft when it comes to security. It's only the messages (engagements with the public) that seemingly change. Last week we wrote about Microsoft pretending that it supports standards, which is an utter lie only PR can buy. Here is part of the PR where Microsoft joins Apple [1, 2, 3, 4, 5] in its attack on Flash, not just its attack on Theora, which we covered in:





Microsoft -- like Apple -- is being denounced for the hypocrite that it is:

MS criticises Adobe over security and performance. Physician, heal thyself!


Let's not forget that Microsoft does exactly the same thing as Adobe (only with limited platform support) whenever it markets Silver Lie. Microsoft went further than that when .NET toys got secretly injected into Firefox without permission, thus creating security and performance issues without users' consent.

Microsoft is also being somewhat hypocritical when it makes some statements as covered in the article "Adapt or die, Microsoft warns business".

Microsoft has failed to adapt to a connected world and a world of computing mobility. Now it has debt to repay.

Addressing the subject of security, Microsoft spreads lies with its secret patches, which probably mean that there are fake figures in this latest 'security' report where Microsoft is conveniently blaming "ISVs" for security problems in Windows. The 'Microsoft press' plays along with this talking point and other publications are trying to make it an excuse for expensive Microsoft "upgrades", which Microsoft urges/advocates using withdrawal of support. How ruthless and deceiving. Here is an example of Microsoft's tactics:

The bottom line comes down to this: if your company plans to stay with XP well into 2011 and you're still using IE6, you've got to upgrade that browser. Knowing that IE9 won't support XP, you can safely move to IE8 knowing it's the end of the line for IE on XP. Or, you can move to Firefox, Chrome, Safari, or Opera -- but a company that's still stuck on IE6 isn't likely to be that adventurous. The web developers of the world will be happy with anything that gets you off IE6.


It is a "bait and switch" manoeuvre in a sense. Microsoft did the same thing to Windows 2000 users some years ago, for no practical reasons except the profit motive.

Going back to the hidden patches scam, can anyone believe that Microsoft is patching with just two "critical" bulletins? For several years Microsoft has been hiding its flaws and patching them silently for vanity purposes.

Microsoft on Tuesday will issue two critical bulletins that will fix vulnerabilities in Windows and Office, which if exploited successfully, could allow a remote attacker to take control of the computer, the company said Thursday.


There were also some broken patches which needed to be re-released.

Let's consider this news in light of last week's reports, such as:



The allegations are so serious that Microsoft could not afford to keep quiet without a carefully-crafted piece of spin. Here are the latest excuses from Microsoft (it's the psychology of lying without technically lying):

Note that a policy such as this implies that Microsoft will not patch known, internally-discovered vulnerabilities if an externally-sourced vulnerability of the same or lesser severity is not available for the silent patch to piggyback on. They'll sit on it, and we won't know for how long because they don't document it.


Utter spin. Groklaw has just found this new article which nicely explains Microsoft's lies in this case:

#3 Tell the truth, misleadingly. The hardest lies to catch are those which aren't actually lies. You're telling the truth, but in a way that leaves a false impression. Technically, it's only a prevarication - about half a sin. A 1990 study of pathological liars in New York City found that those who could avoid follow-up questions were significantly more successful at their deceptions.


Microsoft has also added a formal statement to The Register's article on the subject (silent patching) because it received a lot of attention. Apologists of Microsoft also left comments trying to defend what Microsoft did there. It means it's extremely damaging.

“Microsoft's security record continues to be poor simply because Microsoft does not handle security issues properly, having for example ignored known flaws for 5 months until a disaster came.”In other insecurity news, SharePoint 2007 has a 0-day vulnerability (meaning that it's already under attack). Microsoft has confirmed this [1, 2] and only issued a "workaround" rather than a solution [1, 2, 3]. As this one blogger puts it, there is "no SharePoint fix" and it says nothing about Microsoft's hiding of patches and flaws (clustering them is possible if one wants to crunch the numbers). How many flaws does Microsoft patch in SharePoint silently? In this case, Microsoft had no choice but to publicise it (someone beat Microsoft to it).

Microsoft's security record continues to be poor simply because Microsoft does not handle security issues properly, having for example ignored known flaws for 5 months until a disaster came [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12]. That's just negligence [1, 2, 3].

As a result of such negligence, IDG reports that "Conficker found on 25% of enterprise Windows PCs," according to Microsoft.

Conficker was far and away the most prevalent threat found on Windows machines in the second half of 2009 in the enterprise, Microsoft says. The company's security tools cleaned the Conficker worm from one quarter of enterprise Windows machines.


"25% of enterprise Windows PCs" is a lot of computers. But then again, for several years now we have known that hundreds of millions of Windows zombies were out there waiting to be commandeered. Google says that fake antivirus software is 15 percent of all malware. That's what happens when Windows refuses to implement repositories like GNU/Linux does. GNU/Linux has had that for ages and it keeps it more bulletproof.

Going back to Microsoft's own figures, even Microsoft admits that it's getting worse for Windows in practical terms:

Microsoft Sees Infected PC Numbers Climbing



[...]

The numbers of PCs cleaned by Microsoft's anti-malware software worldwide during the second half of 2009 continued to trend upward, suggesting that more PCs are getting infected in total, according to the company's latest Security Intelligence Report (SIR).


More here.

It's interesting that even Microsoft admits that it's failing to tackle the problem it created (or helped create).

Microsoft's Charney, the former government (ish) person who wants charge Mac and GNU/Linux users for Microsoft to clean up its own mess [1, 2, 3, 4, 5, 6, 7] is now intervening in international affairs, based on this AP report:

"Lots of times, there's confusion in these treaty negotiations because of lack of clarity about which problems they're trying to solve," said Scott Charney, vice president of Microsoft Corp.'s Trustworthy Computing Group, before a speech at the Worldwide Cybersecurity Summit.

[...]

Charney, of Microsoft, believes cyber threats should be better differentiated. He proposes four categories: conventional computer crimes, military espionage, economic espionage and cyberwarfare. That approach, he argues, would make it easier to craft defenses and to discuss international solutions to each problem.


What is Microsoft doing in a Worldwide Cybersecurity Summit? And why does it tell the world how to address these issues that it itself helped create? Microsoft cannot even issue disclosures of its own flaws (because it lies pathologically), so why should anyone believe Charney and maybe implement his outrageous idea of taxing all computer/Internet users for damage caused by Windows botnets? Microsoft should be held liable for knowingly refusing to patch known flaws.

Comments

Recent Techrights' Posts

Politicians Ought to Invite Dr. Richard Stallman and Prof. Eben Moglen to Speak About Policies, Licensing, Digital Sovereignty
Is there something in Europe other than RMS' talk this coming Monday (that we're not yet aware of)?
Good Explanation of Why IBM Has Chosen to Conceal Mass Layoffs (of 'Expensive' Staff) as "R.T.O." (Even For People Who Never Worked at the Office to Which They're Ordered to "Return")
Many remaining IBM (or Red Hat) workers in Europe are in "cheaper" places such as Brno
Microsoft's Serial Strangler and Matthew J. Garrett Join Forces in Trying to Gag Techrights (for Exposing Microsoft Corruption and Crimes Against Women)
Whose terrible idea was it?
Free University of Bozen-Bolzano Proud to Host Free Software Talk by Richard Stallman
ahead of Monday's talk
Slopwatch: Anti-Linux Machine-Generated FUD (LLM Slop) From GBHackers, CybersecurityNews, and Guardian Digital, Inc (Google News Promotes Slop Plagiarism, Misinformation)
Companies that lie try to drown out the signal with falsehoods
 
Links 22/02/2025: OpenAI Plans to Possibly Abandon Microsoft, Facebook Doubles Execs' Bonuses While Sacking Thousands
Links for the day
Gemini Links 22/02/2025: Weekend Chill and Programming Thoughts
Links for the day
Links 22/02/2025: Labour Department Investigates Microsoft Infosys Amid Mass Layoffs, Large Law Firms Caught Red Handed With LLM Slop (Defrauding Clients and Courts)
Links for the day
Gemini Links 22/02/2025: Analog Stuff, Sigil, and SSGs
Links for the day
Microsoft's Market Share in Cameroon Falls to New Lows
This means a lot of Android users (iOS is about 4 times smaller), but Android does not mean freedom
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, February 21, 2025
IRC logs for Friday, February 21, 2025
The Streisand Effect is Real
So don't be evil. Also, don't strangle women.
Links 21/02/2025: Linux Foundation Openwashing, Microsoft Copilot Goes Down
Links for the day
Links 21/02/2025: Doomscrolling and European Ham Radio Show
Links for the day
Links 21/02/2025: TikTok Layoffs, WebOS Software Patents in Bad Hands
Links for the day
Gemini Links 21/02/2025: Web Browsers, Mechanical Shortcuts, and Internet Hygiene
Links for the day
Richard Stallman 'Only' Founded the FSF
there's no reason to be upset at the FSF for keeping their founder in the Board
Techrights Disconnected From the United States Two Years Ago
Did people really need to wait for the US government to become this hostile towards the media before recognising the threat?
Before Trying Censorship by Extortion the Serial Strangler From Microsoft Literally Begged Us to Delete Pages
This is very clearly just a broad campaign of intimidation
Hype Watch: Weeks After Microsoft Disappointed Investors With "Hey Hi" It's Trying Some "Quantum" Hype (Adding Impractical Vapourware to Accompany This Hype and Even LLM Slop in 'News' Clothing)
Remember "metaverse"? What happened to media hype about "blockchain" and "IoT"?
Report About February Mass Layoffs at Microsoft (Third Wave of Microsoft Layoffs in 2025) Comes Back From the Dead
Yesterday we wrote about an article in CRN (reporting Microsoft layoffs) being removed without any reasons specified
Links 21/02/2025: Myanmar Scam Centre and Disruptions at USPTO
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, February 20, 2025
IRC logs for Thursday, February 20, 2025
gbhackers.com is Not Hackers, It's LLM Slop Outputs (Fake 'Articles') That Attack 'True Hackers'
A site called linuxsecurity.com keeps doing this and now we see the slopfarm gbhackers.com doing the same
Gemini Links 20/02/2025: Law of Warming and Cooling, Health, and Devlog
Links for the day
linuxsecurity.com Continues to Spread Lies or Machine-Generated FUD (Microsoft LLMs Likely the Source) About OpenSSH and Linux
this LLM problem is global
Links 20/02/2025: Microsoft Infosys Layoffs and IRS Layoffs (Good News for Rich Tax Evaders)
Links for the day
IBM Layoffs in Europe Already Happening or Underway (UK and Spain). They Try Not to Call These "Layoffs".
"CIO" in particular was repeatedly mentioned lately, as was Consulting
People Who Came From Microsoft Demanding Removal of Articles About Them, About Microsoft, and About Microsoft GitHub is "Generous" (According to Them)
Imagine choosing a law firm that borrows money in the same year just to avoid overdraft in the bank!
Possibly a Third Round of Mass Layoffs at Microsoft in 2025 ("Cloud Solution Architects, Customer Roles"), Report Removed or Censored
This is literally the top story for "microsoft layoffs" right now
Instead of 'DoS Protection' Cloudflare is Allegedly Conducting 'DoS Attacks' on Users of Browsers Other Than Firefox and GAFAM's DRM Sandboxes (Chrome, Safari and Others)
If you value the Web, you will avoid Cloudflare
Mixing Real With Fake in One 'Article' (by "Director of Content, Help Net Security")
From what we can gather, he got machines to generate some slop for him
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, February 19, 2025
IRC logs for Wednesday, February 19, 2025