Bonum Certa Men Certa

Reader's Article: Microsoft Windows Hoses Homeland Security

Geodesic dome
Pentagons



Summary: DHS and Windows - affair revisited

WINDOWS CONTINUES to be a sordid, insecure mess. We will give some examples within days, but in the mean time, here is a new flaw in Internet Explorer 8, which Microsoft loves to pretend is secure:



"A nasty vulnerability exists in the latest Internet Explorer 8," Evans wrote. "I have been unsuccessful in persuading the vendor to issue a fix."

"The bug permits — for example — an arbitrary web site to force the victim to make tweets," he added.

The vulnerability may exist in other versions of IE and appears to be an extension of a cross-browser cross domain theft first documented by Evans via his scarybeastsecurity blog last December. Evans claims Microsoft has been aware of the bug since 2008, producing a harmless proof-of-concept exploit to illustrate his concerns.


A reader of ours has also just contributed the following short article: "Slashdot is running another story that fails to call out Windows. To be fair, neither did the Wired article or the Department of Homeland Security report itself. The last omission is inexcusable because DHS had all the information and should help US citizens make informed decisions by publishing instead of shielding Microsoft by obfuscating.

"There are tantalizing clues in the report and a damning indictment of Windows. The report The US Department of Homeland Security found more than a thousand serious vulnerabilities on their own network. Almost all of the holes were in applications run on Windows and flaws in Windows itself:

Overall, we identified 1,085 instances of high-risk vulnerabilities on the MOE [Mission Operating Environment]; 202 were unique across 174 MOE computers scanned. The majority of the high-risk vulnerabilities involved application [94%] and operating system [6%] and security software patches that had not been deployed ...The application vulnerabilities identified in our scans of the MOE, which NCSD uses for email service and access to NCPS Einstein data, include those involving Microsoft applications, Adobe Acrobat, and Sun Java. ... more exploitation attempts are recorded on application programs, especially email attacks that exploit vulnerabilities in commonly used software and programs such as Adobe and Microsoft Office. Though application attacks are on the rise, operating system ... Though application attacks are on the rise, operating system attacks are still a security concern; more than 90% of operating system attacks involve buffer overflow vulnerabilities against Windows operating systems.


"When someone says "email attacks" they are usually talking about a particular Windows client. Because the DHS did not break down applications by OS, readers are left guessing what they are talking about. Why bother to give the breakdown for the minority problem, OS, while leaving the majority of problems, applications, nebulous?

"We do know from the report that DHS is a Windows shop and that causes most of the problems. The agency flagellates itself for not following Federal Information Security Management Act (FISMA) requirements or their own policies and recommends they, "Implement a software management solution that will automatically deploy operating system and application security patches and updates on all MOE computer systems to mitigate current and future vulnerabilities." If they were using GNU/Linux, they would already have such a thing because every distribution comes with a package manager.

"Updates are nearly impossible on Windows but trivial with GNU/Linux. Updates for Windows are spread far and wide on vendor sites, often behind javascript and other barriers to automated discovery. Many vendors have auto update tools but many resemble spyware, introduce security problems of their own and running them all at once drains system resources. Worse, Microsoft is notorious for breaking Windows and other applications with their updates, and every large organization and software vendor ends up doing their own set of tests before they can roll out anything to users. This is an enormous duplication of effort not found in the cooperative world of GNU/Linux. Free software has no such barriers to discovery or copy, so all of the heavy lifting gets done by distributions' package manager that is already automated."

Does it not seem reasonable to suggest that DHS should abandon Windows? Sadly, it has former Microsoft seniors in house.

Recent Techrights' Posts

The Leaks Were Right: Mass Layoffs at Microsoft in May, Then Another Wave in June
Just as we've been saying for over a month
Last Article From Australia's Sam Varghese Was a Year Ago and It Covered the Release of Julian Assange, Who Will Apparently Come Back as 'Politician'
It'll soon be exactly 12 months
After Microsoft's Bankruptcy in Russia Android (Linux) Will Dominate Asia Completely
Windows probably peaked in "XP" or "2000"
India: Windows Falls to 50% in Desktops/Laptops and 8% Overall
laptops/desktops fell to 16% of the whole
statCounter: GNU/Linux Up to 4.7% "Market Share" This Month
30,000 Microsoft jobs may be eliminated by year's end
Microsoft is in Trouble and Microsofters Know It
"I've been happy on Win 3.11 for years."
Links 02/06/2025: Political Leftovers, DRM, and Patents
Links for the day
 
Linux is Already Dominant (Android), Let's Make GNU/Linux Dominant in Desktops/Laptops as Well
"Dr. Stallman recently warned everybody about Microsoft."
The Loyalty to Microsoft and the Salaries From Microsoft (Funding SLAPPs Against Techrights and Tux Machines)
Garrett always knows better. He knows everything best.
Windows Falls in Italy as GNU/Linux Jumps to 5%
Italy knows a thing or two about digital autonomy
Nigeria is All Android and Google
Windows down to almost nothing in Africa's largest population
Mass Layoffs at Microsoft (Second Wave) Not Limited to Redmond
"More layoffs at Microsoft as axe falls in Washington and California"
Gemini Links 03/06/2025: Forth System and "Common Lisp is a Dumpster"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, June 02, 2025
IRC logs for Monday, June 02, 2025
Hungary Seems Hungry for Linux
Windows down by a lot
Like in Europe, Bad News for Microsoft in US and Canada
If it loses those "regions", then what's left?
About 8 Waves of Mass Layoffs at Microsoft in 2025 (in Less Than 5 Months), Now Vista 11 "Market Share" Decreases
Really bad news for shareholders of Microsoft
statCounter Sees Bing "Share" Falling Over 0.5% in One Month, Now Lower Than Before the ChatGPT/Bing Chat Hype
Bing has been part of the mass layoffs for quite some time
Microsoft's Demise is a Global Phenomenon
mass layoffs justified using mindless buzzwords
All-Time Highs for GNU/Linux in EU and the UK, All-Time Lows for Microsoft
Combining ChromeOS and GNU/Linux, it adds up to and almost reaches 6%
[Video] New Introduction to Richard Stallman's Contributions Including GNU Emacs, GNU/Linux, and Software Freedom
from the channel previously bullied for supporting RMS
Links 02/06/2025: South Korea to Vote, Russia Blitzed From Within
Links for the day
Links 02/06/2025: Microsoft Spins Layoffs as "Slop", Frontier Settles Lawsuit
Links for the day
When You Publicly Boast About Wanting to Violently Attack People (Even Colleagues) Finding a Job Will Prove Difficult
there's a lesson to be learned here
The Web We Lost, the Information Lost Due to Microsoft's Attacks on Companies Like Yahoo! (Before the LLM Slop Frenzy)
When it comes to news sites, what can we say?
Covering Corruption in Poland, Including a War on Science (Due to Bad Politicians)
What we're about to show is that skilled and experienced scientists in Poland are besieged by bureaucrats
Gemini Links 02/06/2025: "Star Wars Day" and "Security Day"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, June 01, 2025
IRC logs for Sunday, June 01, 2025
The Openwashing Shills Initiative (OSI) - Part II: Lying to the IRS is a Big Issue
The OSI of today pretends to be something that it is not
Bloodlust and Love of Blades (Fascination With Murder) Nothing New Among Microsofters
Violence is not a joke and no group is magically entitled to make such "jokes"
Links 01/06/2025: Bird Flu, Food Price Inflation, and Growing US-China Hostilities
Links for the day
Links 01/06/2025: "Vibe Coding" Turns Out to be a Fraud and Amazon Merits Boycott, Argue Bloggers
Links for the day
Gemini Links 01/06/2025: "Stardust" and Ideal PC Setup
Links for the day
Links 01/06/2025: Windows TCO, Openwashing, "It's FOSS" Still Promoting Microsoft
Links for the day
Gemini Links 01/06/2025: Simplification and Networks Everywhere
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, May 31, 2025
IRC logs for Saturday, May 31, 2025