Bonum Certa Men Certa

Microsoft Cannot Provide Security

Indecision



Summary: A roundup of security news showing what an utterly poor job Microsoft is doing when it comes to securing customers' systems and telling them the truth

WE HAVE not been covering these issues for several months now, but over the weekend there was time to catch up with about 2 months of security news. This post contains a concise summary of some key security problems Microsoft has been having, with fresh examples towards the end (a lot of bad news around the Christmas period).



Let us begin with the not-so-distant examples of DLL hijacking. "Most Microsoft DLL Hijacking Vulnerabilities Remain Unpatched" said this report which implied neglect and irresponsibility from Microsoft. They had not patched or addressed known problems, as usual.

Many new flaws were found in Windows, including one that evades Windows' UAC pseudo-security. There was a privilege escalation exploit and an issue with buggy Internet Explorer [1, 2], whose low quality gives crackers many opportunities to hurt its users. Over Christmas there were many headlines about an Internet Explorer zero-day warning [1, 2, 3, 4, 5, 6, 7, 8, 9]. Microsoft just warned about it but did not patch it. Microsoft also said that there was no exploit and soon enough it dealt with a second zero-day vulnerability. It did not take long for exploits to surface and IDG said that researchers revealed attack code for new IE zero-day vulnerability. It's important to remember that it's terrible to leave people in this state over the holidays. It prevents some people from taking a break or be mentally peaceful. Microsoft produced only a workaround, a hack [1, 2]. It wasn't a patch. Soon thereafter, on December 30th, it was announced that Microsoft was also warning about Microsoft Word attacks (which means that exploits exist too).

“The priority is reputation rather than the safety of systems. Microsoft's financial security comes before real security.”Microsoft deserves mocking for this. When there was previously an IE vulnerability the company produced nothing for months, until December according to IDG (also see this other IDG report or this report which says that "Microsoft's Patch Tuesday for November does not include a fix for a zero-day flaw in Internet Explorer"). Microsoft left users vulnerable for far too long simply because it could get away with it, under the assumption that many users are stuck with Windows. One must not allow Microsoft to fool the public by claiming its responses to be fastest because only a Microsoft spin site like Neowin would so conveniently ignore silent patches and recent studies on the subject. Neowin parrots Microsoft when it says that Microsoft patched 247 exploits in 2010. It's inaccurate because those numbers are fake. Many more patches were applied silently, in order to give Microsoft bragging opportunities (hinged on falsehoods). For PR reasons, Microsoft just does not deliver patches sometimes. The priority is reputation rather than the safety of systems. Microsoft's financial security comes before real security.

The matter of fact is, Microsoft can't even secure Windows itself. "Hackers hijack Microsoft's servers for fake-drug spam" said this recent headline and on the seventh of December Microsoft was warned of the "protected mode" flaws we mentioned earlier. This has not been addressed yet.

Security researchers have issued a warning to Microsoft that the much-vaunted Protected Mode introduced into Internet Explorer in recent releases offers little or no protection in its current form.


When it comes to patches, some people will reject them anyway, as yesterday's post about AP downtime ought to teach everyone.

Going about a month back, we also find reports relating to the handing of Windows sources code to Chinese hackers, which led to reports that we missed such as this one ("Chinese firm hired Blaster hacking group, says U.S. cable"), this one ("Leaked Cables: Chinese Hackers Used Microsoft Source Code To Attack Google & US Government"), or the redacted cable itself ("US embassy cables: China uses access to Microsoft source code to help plot cyber warfare, US fears"). How about this one ("China Used Microsoft Source Code To Hack Google -- And You?") which says:

A State Department cable released by WikiLeaks says the Chinese government used Microsoft source code in its attacks on Google and in its cyber warfare efforts in general. (Via The Guardian)

How did they get their hands on Microsoft's closely guarded source code, you might ask?

Well, two Chinese IT security companies, Topsec and Cnitsec, are licensed to access and use Microsoft's source code. In yet another example of incredibly blurred lines between the government and business in China, those companies gave the source code to the government.


Later in December, a Microsoft booster called Emil Protalinski spoke about Microsoft's largest Patch Tuesday ever and so did some other sites [1, 2]. We covered this at the time, but the important point to be made is that invisible patches are not being named or counted by Microsoft, so the real numbers can be much greater.

From older reports we also learned about the effects of Zeus [1, 2, 3, 4, 5, 6, 7, 8, 9, 10], which in a world where one in two Windows PCs is said to be a zombie PC is doing a lot of damage despite a token of response from Microsoft [1, 2]. The headlines are "Microsoft: Botnet infection plague continues despite wins" and "Zeus Trojan defeats Microsoft security tool". "Microsoft tool unable to detect new versions of Zeus" says another report.

Neil J. Rubenking writes to warn people that Passware found Bitlocker in Windows to be broken:

Password-recovery experts at Passware warned Friday that the security of Microsoft's Bitlocker whole-disk encryption is seriously compromised on a computer configured to use sleep mode. The same is true of the open-source TrueCrypt whole-disk encryption tool.


Now we come to some of the latest news. "Microsoft ActiveX Security Bugs 'Highly Critical'" said Ziff Davis some days ago:

Researchers at Secunia are warning users about ActiveX bugs the firm described as 'highly critical.' Microsoft is unaware of any attacks targeting the issues.

[...]

Besides the ActiveX bugs, the company is also investigating a denial-of-service issue impacting IIS FTP 7.5, which ships with Windows 7 and Windows Server 2008 R2. Proof of concept exploit code has already been made public, according to Nazim Lala, IIS security program manager at Microsoft.


It relates to an older report from the same publication:



With attack code public, Microsoft said it is investigating a report of a new vulnerability impacting Internet Explorer.


"Microsoft reports drop in data breaches" said this less-than-recent headline and shortly afterwards it turned out that Microsoft messed up in a major way. To name some headlines, "Microsoft Corporation Cloud Security Breached", "BPOS: a data leak in Microsoft’s cloud", "Microsoft BPOS cloud service hit with data breach", and "Microsoft Cloud Data Breach Heralds Things to Come". Quoting from that last one:

Microsoft announced that data contained within its Business Productivity Online Suite (BPOS) has been downloaded by non-authorized users, possibly making it the first major cloud-based data breach.

[...]

Encryption isn't the final word. Even encrypted data has a history of being compromised, usually due to bugs in the encryption software.

All of this means that, if your business is going to put data into the cloud, you will have to factor in the very real possibility it will be made public at some point. It will happen. It's just a matter of when, and what damage will be caused. It would be interesting to visit the offices of Microsoft, Google, and others to see if they eat their own dog food: Does Google rely on Google Docs for all of its hypersensitive business data? Somehow I suspect not, although I look forward to being proved wrong. There are laws in place covering data breaches, requiring companies to enforce reasonable security systems, but none of that amounts to a hill of beans once the data has escaped the cloud. And should stolen data be turned into a bit torrent, as appears to be the fashion at the moment, there's absolutely no chance of discreetly cleaning up by getting the data back from those who stole it.


Wired has just taken a "Four-Day Dive Into Stuxnet’s Heart", noting at least that it's a Windows problem:

It is a mark of the extreme oddity of the Stuxnet computer worm that Microsoft’s Windows vulnerability team learned of it first from an obscure Belarusian security company that even the Redmond security honchos had never heard of.

The sophisticated worm, which many computer experts believe was created as a specific attempt to sabotage Iran’s nuclear power plant centrifuges, has written a new chapter in the history of computer security. Written to affect the very Siemens components used at Iran’s facilities, some analysts have even speculated it may have been the work of a state, rather than of traditional underground virus writers.


For more about Stuxnet’s damage see the posts below.

  1. Ralph Langner Says Windows Malware Possibly Designed to Derail Iran's Nuclear Programme
  2. Windows Viruses Can be Politically Motivated Sometimes
  3. Who Needs Windows Back Doors When It's So Insecure?
  4. Windows Insecurity Becomes a Political Issue
  5. Windows, Stuxnet, and Public Stoning
  6. Stuxnet Grows Beyond Siemens-Windows Infections
  7. Has BP Already Abandoned Windows?
  8. Reports: Apple to Charge for (Security) Updates
  9. Windows Viruses Can be Politically Motivated Sometimes
  10. New Flaw in Windows Facilitates More DDOS Attacks
  11. Siemens is Bad for Industry, Partly Due to Microsoft
  12. Microsoft Security Issues in The British Press, Vista and Vista 7 No Panacea
  13. Microsoft's Negligence in Patching (Worst Amongst All Companies) to Blame for Stuxnet
  14. Microsoft Software: a Darwin Test for Incompetence
  15. Bad September for Microsoft Security, Symantec Buyout Rumours
  16. Microsoft Claims Credit for Failing in Security
  17. Many Windows Servers Being Abandoned; Minnesota Goes the Opposite Direction by Giving Microsoft Its Data
  18. Windows Users Still Under Attack From Stuxnet, Halo, and Zeus
  19. Security Propaganda From Microsoft: Villains Become Heroes
  20. Security Problems in iOS and Windows
  21. Eye on Security: BBC Propaganda, Rootkits, and Stuxnet in Iran's Nuclear Facilities
  22. Eye on Security: ClamAV Says Windows is a Virus, Microsoft Compromises Mac OS X, and Stuxnet Runs Wild
  23. Windows Kernel Vulnerability for Thanksgiving, Insecurity Used for Surveillance Again


Recent Techrights' Posts

Father of GNU Giving Keynote Talk Today, Father of Linux Collaborating With Linus Tech Tips (LTT)
Some time soon we can expect Linus Tech Tips (LTT) / Linus Media Group / Linus Gabriel Sebastian to produce something with Torvalds
LLM Slop is an Addiction One Can Quit
Sites that crossed over to "the dark side" (slop) can still return, and even fully regain the trust lost by betraying people with 'botspew'.
BILD is Apparently Covering Up Cocaine Use at Europe's Second-Largest Institution, the European Patent Office, as It's Based on Germany
Journalist contact details
 
NHS Data Breach Caused by Proprietary Software, as Usual, The Register MS Blames "Hackers" and "Cybercriminal Gang"
Nothing will get solved unless we have a rethink and media quits using the "hacker" narrative, which shifts blame from the holes to those who merely exploit them
IBM is Vanishing (First Moving, Then Going Away Completely)
Salary reduction is only the first step
Links 16/11/2025: Japan-China Tensions Grow, Surveillance Giant Google Checked for Breach of the Digital Markets Act (DMA)
Links for the day
Links 16/11/2025: Censorship Battles and Margaret Sullivan Speaks
Links for the day
German Media and German Politicians: Working for the Public or Manipulating the Public?
The "common person" does not have printing presses
Informing the Public of Suppressed Facts
We are all in this together
Canadian Linus Meets Finnish-American Linus
LTT does have a very large audience, which it can steer away from Microsoft and Windows
The UK's Online Safety Act (OSA) Discourages Technological Entities, Including Free Software Projects, Being Based in or Near the UK
When it comes to IRC hosting, we never had any serious speech restrictions imposed upon us by the UK
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, November 15, 2025
IRC logs for Saturday, November 15, 2025
Gemini Links 16/11/2025: Emacs Font Fun and UI x TUI x CLI
Links for the day
Flagging or Labelling LLM Slop Meaningfully to Discourage the Practice
We're still refining the annotation for better contrast
Techrights Site Search Pushed to 'Stable'
we've just added it to the navigation menu and footer
Situation Publishing's DevClass (Sister Site of The Register MS, Run by MS Tim) Has Been Abandoned, Microsoft's MS Tim Now Interjects Anti-Linux Directly Into The Register MS
Not only does this sell Microsoft; it's also googlebombing - as before - the real "maui" (or "MauiKit" in Linux).
Many IBM Workers to Become Unemployed a Few Weeks - Maybe Just Days - Before Christmas
as one last humiliating exercise IBM pimps/trots them out in social control media, telling "happy" stories
Slopwatch: LinuxSecurity, WebProNews, and Linux Journal (Slopfarms)
More fake articles about "Linux"
Links 15/11/2025: Openwashing of Kubernetes and Austerity Planned for Canada
Links for the day
Links 15/11/2025: "Small Web, Big Voice" and China Cracking Down on Slop
Links for the day
Links 15/11/2025: Science, Conflicts, and International Politics
Links for the day
Annus Horribilis at the European Patent Office (EPO)
The article explains how the EPO "Cocainegate" scandal is turning 2025 into an Annus Horribilis for Campinos
Links 15/11/2025: Latest in "Component Abuse Challenge" and Qt Keeps Promoting LLM Slop
Links for the day
Gemini Links 15/11/2025: Egoism, Misunderstood Universe, DeX, and "Why desktop Linux is growing"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, November 14, 2025
IRC logs for Friday, November 14, 2025
Richard Stallman Talk Tomorrow in Ethereum Cypherpunk Congress 2
It's not clear if a livestream of some kind will exist
Many "Last Days" at IBM on Allegedly the "Last Day" for IBM to RA People This Quarter
"Last day" is "social media code" for "got laid off", more so at IBM because they compel people to act like it's a happy departure with gratitude, photos and so on
Slopwatch: Almost a Majority of Google News is Now Slopfarms (Fake Sites, Fake Articles)
Google News is noise
Gemini Links 14/11/2025: Boredom, "Twenty Percent Cooler", and Moving From Windows to Artix
Links for the day
Links 14/11/2025: YouTube's Trap for Publishers, Lack of Accountability a Growing Legal Matter/Concern
Links for the day
Many Times in the Past We Said That Microsoft Lunduke Was Becoming a Spokesperson/Voice for - and Occasionally Weaponising - 4Chan. He's Proving Us Right This Week.
Stay away
The Register MS is Profiting From Pyramid Schemes Run by Americans
We cannot help but feel disgusted by what this publisher became
IBM: Hiring, Then Disposing of, Unpaid or Low-Paid European Staff to Spread or Play Up Buzzwords and Hype
Like Google With "Summer of Code", this seems like a low-cost marketing stunt more than anything substantial
Casual Reminder That We Also Publish GNU/Linux Stories and News Coverage in Tux Machines
Without trust in our robustness (including fearlessness, not just success in protecting stories and sources) we'd not have come this far, nor would I devote my life to it
The Europe Conversation: The EPO Has Cocaine at the High-Level Management and Isn't Denying It
Now we plan to ensure the matter is properly documented in European press
Links 14/11/2025: Goddard Space Center Abused by the White House, Jeffrey Epstein Scandal Expands (Cheetos Need Distraction)
Links for the day
Corporate Media Helps IBM Relay Vapourware (Misinformation/Fake News)
They compensate with words for a lack of compelling products
Hacking on Recipes
Maybe, in due course perhaps, we can also release some of our own cooking recipes or "forks"
Web Searches Far Too Polluted, Gamed by LLM Slop and "Plagiarised Information Synthesis Systems" (PISS)
old articles are already getting difficult to find in mainstream search engines, even if they are still online
Privacy-respecting Metasearch Engine SearX/SearXNG Still Jailed by Microsoft
The official site and code still sadly controlled by Microsoft
"AI" is a Lie. It Always Was. What They Call "AI" Is Not.
This MSM does no favours to the economy
Our First Week of Our Twentieth Year
My wife and I have had a very productive week here and in Tux Machines
Links 14/11/2025: Sleep Research, France to Suspend Pension 'Reform' Law, and Linux Foundation's Latest Openwashing
Links for the day
Gemini Links 14/11/2025: KDE vs XFCE and Leaving the Web
Links for the day
Google Admits It Lost Control of Slop (While Google Itself is Selling Slop, Currently Under the Name "Gemini" Instead of "Bard")
Slop is nothing to be celebrated
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, November 13, 2025
IRC logs for Thursday, November 13, 2025
Mozilla Handed Over Control Over Firefox to Microsoft, Now Firefox is Preloaded With Microsoft Spyware and It's Proprietary
Who would still want to download Firefox?
Slopwatch: LinuxSecurity, Brian Fagioli, and WebProNews
becoming a slopfarm is a site's suicide
"Sponsored Posts" in The Register MS
That's The Register MS in 2025
IBM RAs in India (Apparently)
IBM is a bad place to work
Another Richard Stallman Talk in Two Days
His talk will be a remote talk, as he won't be travelling to Argentina