Bonum Certa Men Certa

Microsoft Thinks That Tax and Arrests Will Make Up for Security Flaws in Windows

No trespassing sign



Summary: Scott Charney from Microsoft wants some money because of security crises and others jail the exploiters rather than actually fix the issue they exploit

LET'S give some credit to Microsoft. It's a very comical company. One of its satirists, Mr. Charney, has been making many good people laugh when he started preaching about help to Microsoft through taxpayers' money. It began several months ago [1, 2, 3, 4, 5, 6, 7, 8, 9] and earlier this month he took the stage again [1, 2], telling a sob story and then appealing for donations. His employer created a monster with a back door and it cannot seem to get this monster under control anymore (it only keeps getting worse).



Over the weekend we presented yet another rebuttal and assorted reactions. Here are some more that caught our eye:

i. The day that Microsoft wore a tinfoil hat and shouted la, la, la

Let me run that past you again: if your computer (or network) gets infected by some malware and ends up being part of a botnet, quite possibly courtesy of some zero-day exploit taking advantage of a Windows vulnerability, then that computer (or network) should be forcibly disconnected and put into some kind of cyber-quarantine using an adapted public health model.

Charney clearly hasn’t thought this through. In his speech at the International Security Solutions Europe (ISSE) Conference in Berlin, and also in the accompanying Microsoft white paper “Collective Defense: Applying Public Health Models to the Internet” he pushes the whole public health model approach as a solution to the online security threat. Charney likens an infected computer to an infected individual who puts others at risk by not getting vaccinated, and argues that a public health model which tracks and controls the spread of infection, quarantining folk to reduce the spread, is the answer in the IT world.


ii. Microsoft Proposes Government Licencing of Internet Access

iii. The Sheer Hypocrisy of Redmond's Stab at Internet Health

One of the benefits of being an 800-pound gorilla in this world is that you can use your strength and influence to help others.

So, apparently, seems to be the altruistic thinking at Microsoft (Nasdaq: MSFT) these days. Not content to rule the world -- or at least try to -- with its Windows desktop dominance, the software behemoth has now apparently paused to propose a way to tackle the Internet's malware problems too.


The fundamental issue here is that Microsoft wants the public to cover up the costs of its own disaster. What does it think it is? BP?

Anyway, for Microsoft to think that an Internet tax can bring about a solution is to totally ignore the fact that this money will do nothing to actually fix the root of the issue, namely Windows. And why should the public ever take the burden? Microsoft hardly pays any tax and according to Associated Press, it wants to pay even less.

In a statement released Wednesday, executives for the Boeing Co. and Microsoft Corp. say I-1098 would harm businesses by raising costs for suppliers and making it harder to attract talent.


They already reject local talent and offer no benefits because it's cheaper. That's just more baseless lobbying and an increasing number of citizens of Seattle/Washington comprehend this over time.

Let's go back to the original subject. Under similar posts from the weekend [1, 2] -- ones about the Zeus plague [1, 2, 3, 4, 5] and the arrests it led to -- that's again an example where rather than addressing the security issues in Windows, the side-effects get handled. "Zeus Arrests Won't End Fraud" is the headline of this new article which challenges the approach:

U.S. officials have charged 92 suspects believed to have been involved in cyber attacks that stole $70 million from bank accounts over the last four years. Meanwhile, authorities in London arrested 19 people who allegedly stole more than $9 million in just over three months using the same malware. Police in the Ukraine arrested five suspects on September 30.

But will 116 arrests make a dent into the international banking fraud being perpetrated via Zeus? Don't get your hopes up, say industry experts.


Microsoft has been trying to get attention off Windows insecurity and it's working quite well because the media no longer deals with Windows as an issue. The next post will be dedicated to Stuxnet, which is an excellent new example of the severe damages sometimes caused by Windows.

Comments

Recent Techrights' Posts

"Many Applications Labelled as "Cybersecurity" and Given a Veneer of Legitimacy Are Really "Weaponised" and Abusive Code"
New from Dr. Andy Farnell
Security Advisory: Debian falls for social engineering hacks
Reprinted with permission from Daniel Pocock
The High Cost of Making Scepticism of Proprietary Voting Machines a "Trump" and "Conspiracy Theory" Territory
Time to get back to paper? Or read an old paper?
 
Donald Trump as Censor in Chief Can Now Leverage Censorship Companies and Fake Protection Disguised as 'Security'
Centralised CAs were trouble all along
Technology: rights or responsibilities? - Part VI
By Dr. Andy Farnell
A Death of a News Industry
A theme we explored thrice today
Deciphering Centralised CAs and Why Their Demise Should be a Goal
Encryption in transmission is good; but who controls the key exchange and certification/authentication/validation?
Links 08/11/2024: Strikes, Recessions, and Slowdowns
Links for the day
[Teaster] [Meme] New Ways of Wrecking (NWoW)
The EPO
Gateway for News and Blogs
In the long run, this site and its sister site (less overlap between them now) should hopefully become a popular destination for people who look for information, not chaff
Going Even Faster
We hope the site will be faster soon
Psychopaths Who Reaffirm Our Work's Value
Psychopaths and sociopaths lack empathy, so they're willing to go very far and stoop as low as they deem necessary
[Meme] How Low Can You Go at the European Patent Office?
Not just in terms of patent quality
More Cuts/End to Benefits for EPO Workers (Europe's Working Conditions Incompatible With the European Patent Convention)
"The Office is now reviving it but plans to introduce new cuts on benefits"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, November 07, 2024
IRC logs for Thursday, November 07, 2024
Gemini Links 08/11/2024: US Election, RetroChallenge 2024, and More
Links for the day
[Meme] Questioning Proprietary Software? Not OK...
A disaster long in the making
Links 07/11/2024: HTTP/3, Health Research, and Punditry
Links for the day
Gemini Links 07/11/2024: On Writing Publicly and Record Player Table
Links for the day
Open Source Security Foundation (OpenSSF) Hosted SOSS as Microsoft Propaganda Platform With Microsoft Front Group OSI
They essentially promote what they're attacking under false pretences [...] OSI is deeply corrupt. It's more toxic than arsenic.
Anti-Linux FUD, Now in LLM Form, Thanks to Brittany Day
They attack Linux with chatbots
[Meme] When You Discredit People Who Discredit Secret Code
proprietary systems with hundreds of millions of transistors (and hundreds of millions of lines of code)
Links 07/11/2024: Online Manipulation in Social Control Media, Election Deniers, and More
Links for the day
Gemini Links 07/11/2024: emacs-guix and File Hoarding
Links for the day
[Meme] Election Day at the European Patent Office
Less than 60 minutes left to cast your vote
Staff Union of the European Patent Office (SUEPO) Election Ending Today
In one hour
[Meme] When the Patent Office Does Illegal Things and Staff Speaks Out
many leaks received today
Today We Got an Early Birthday Gift
Exciting times
[Meme] Going Too Far to the Left Can Breed Militant Ideology
Some people can never be appeased because they prefer not to be appeased
Apple's Debt Has Skyrocketed While Gimmicks Like Vision Pro Failed
In Apple's case, the debt is almost double the "Cash on Hand", which isn't even cash
FSF Expressed No Preference Regarding Presidential Candidates (Its Founder Did)
Because he is a principled person, he does not prioritise loyalty to customers or employers (money)
A President Trump is Excellent News to Microsoft
His racist policies gave lots of contracts to Microsoft
Who Next on the Linux Foundation's 'Kill List'?
Remember that only about 2% of the "Linux" Foundation's budget goes to Linux
Links 07/11/2024: Facebook Scams, Journalists on Strike
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, November 06, 2024
IRC logs for Wednesday, November 06, 2024
Microsoft-Connected Publishers Want Us to Think That Linux is Some Sort of a Virus and a "Backdoor"
"The problem is with windows and the attack vector is via Windows"
We've Made it to 18! Here's to Another 18!
Going on for another 18 years means until some time at the end of 2042
Links 07/11/2024: Political Angst and Laptop Issues
Links for the day
Even LKML Subjected to Slop/SPAM by Guardian Digital, Inc (linuxsecurity.com)
They're really awful
Links 06/11/2024: BPF in RFC 9669, More Facebook Fines for Privacy Abuses
Links for the day
Gemini Links 06/11/2024: Political Shock and Hermaic Encouragement
Links for the day
Planet Debian Allows Politics (But It Depends on Your Opinions and Debian's Big Sponsors)
Planet Debian is OK with politics... as long as all your political opinions are the "correct" ones and you add cute animals
What Makes RMS Such an Attractive Target ('Discreditisation' Campaigns)
Don't be so easily fooled
The Biggest OEMs or Vendors of GNU/Linux Stopped Competing With Microsoft (Which Pays Them to Promote Windows, Too)
Where are the competition authorities (or regulators for that matter)?
Let's Encrypt Falls to a New Low of Only 0.6% of Gemini Capsules Known to Lupa
In Gemini Protocol, certificates for encryption are required, but centralised Certificate Authorities (CAs) aren't needed
Computer-Generator Crap Flooding the Web, the Latest Example About "Linux"
Here's today's example
Links 06/11/2024: Election Disinformation and Legal Actions
Links for the day
Gemini Links 06/11/2024: Stargazing and Death on Hallowe'en
Links for the day
Would You Trust a Liar?
Why lie about the authorship?
Mass Layoffs at Mozilla Announced During US Elections
Maybe nobody will notice?
[Meme] Announcing "Results" Before Everyone Even "Played"
There is a "tech" angle to otherwise political news
US Polls Close in One Minute (Social Control Media Does Not Care, Will Not Wait)
US election results will be known in about 2 days
Concentration and Centralisation Versus Aggregation or Syndication
KDE has a history of burying old sites
Social Control Media, Even Hours Before Polls Have Closed
Has social control media controlled by CPC (TikTok) and the Trumpmobile guy (Musk's "X") done enough to convince people not to even vote (based on presumptive "results", presented a long time before all polls have closed)?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, November 05, 2024
IRC logs for Tuesday, November 05, 2024
Wayland Pains in Community-Led Distros of GNU/Linux
Few people and companies use Wayland; there's hardly any technical or practical reason to choose it
IBM Still Conflating Microsoft With 'Security'
As a meme
Sanctions Cause Fragmentation in Software
some Chinese Linux developers are already subjected to restrictions similar to Russians'
Web Failing With Slop, Even in 'Linux' Sites (LLM Spam)
Add SEO prompting to the mix and the Web becomes a pool of slop, not knowledge
[Meme] State of the World Wide Web and Online Journalism
Technically a failure (DRM) and cannot even get basic things right
Trump's signature policy, building a wall, copied from Irish-Australian student politician
Reprinted with permission from Daniel Pocock
Linus Torvalds' self-deprecating LKML CoC mail linked to Hitler's first writing: Gemlich letter
Reprinted with permission from Daniel Pocock
[Meme] Turning 18 in One Day
just one more day