Bonum Certa Men Certa

Despite Media Propaganda About Security, Microsoft Windows Remains the Least Secure Operating System, by Design

"It is no exaggeration to say that the national security is€ also implicated by the efforts of hackers to break into€ computing networks. Computers, including many running Windows€ operating systems, are used throughout the United States€ Department of Defense and by the armed forces of the United€ States in Afghanistan and elsewhere."

--Jim Allchin, Microsoft



Summary: Amid highly misleading security-centric reports that rely on Microsoft's bogus number of vulnerabilities (Microsoft already admitted hiding many of them) Techrights presents recent news about Windows 'security'

WINDOWS is not a secure operating system. It's not intended to be, either (Microsoft's actions show that security is not the goal). One cannot ever patch NSA back doors safely. When these are patched, it's already too late and newer back doors remain in tact or are being added. Trusting Microsoft to secure Windows is misunderstanding the goal of Windows ('privileged' access) and as Stuxnet serves to remind us, the real owners of Windows are spy agencies, not people who use Windows (renting it from Microsoft in exchange for payments). See this new report titled "Stuxnet Redux: Microsoft patches Windows vuln left open for FIVE YEARS". It says that "[w]hile most of the attention this Patch Tuesday has been focused on the FREAK encryption vulnerability, Microsoft's latest batch of fixes also addresses another longstanding threat to Windows: Stuxnet." So they hadn't fixed it for so long and finally decided to do something about it? Knowing that espionage agencies were exploiting holes and taking control of PCs that have Windows installed? Wake up and smell the coffee. These actions speak volumes.



Adding insult to injury, last week we learned that "Microsoft RE-BORK[ED] Windows 7 patch after reboot loop horror". To quote the report itself: "Reports are emerging that a twice-issued Microsoft Windows 7 patch is still causing pain for users, with some claiming the fix is triggering continuous reboots.

"The patch was first issued as KB2949927 and withdrawn in October due to system faults, before being re-released this week as KB3033929."

So our conclusion is that even when Microsoft offers so-called 'patches' or 'security' there are negative consequences which are too risky to accept. For more information see this article titled "Problems reported with Microsoft patch KB 3002657, warning issued on KB 3046049". A lot of people are still using Windows XP, which receives no patches at all. Some genius, eh?

Some Web sites are now claiming that the NSA and fellow espionage operations have been largely responsible for the SSL hole someone dubbed "FREAK". Of course, despite media spin and a clear Microsoft role (perhaps inside knowledge becoming public), the flaw affects Windows as well (all versions) and Microsoft failed to properly address the problem when it was already known (advertised as public knowledge). "The response of Microsoft and cloud companies to the Freak vulnerability has been far too slow say commentators," according to one British news site/magazine which focused on security. CBS covered this only after it had been wrongly spun as a Linux and Apple issue. "Microsoft was late with the announcement so that the press could focus on Android and iOS and make it look like their problem," said iophk. Microsoft took many weeks to do anything, which gave enough time for passwords to be intercepted and for entire networks to be compromised. So again we are being reminded that Microsoft just doesn't take security seriously. While some reports try to frame Windows as most secure because Microsoft hides many flaws and games the numbers to make the competition look bad, anyone with experience in this area ought to see that Microsoft's encryption was always bogus, and very much by design! Here is another brand-new example of Microsoft 'security' in action: "Microsoft is scrambling to block a fraudulent HTTPS certificate that was issued for one of the company's Windows Live Web addresses lest it be used by attackers to mount convincing man-in-the-middle attacks."

Soon enough, based on some observers, Microsoft Windows-running "PC will become slower as it will serve the updates to another client."

It is a peer-to-peer approach that externalises cost and liability. Is Microsoft really trusting this to work better given the above reports about man-in-the-middle attacks and fraudulent HTTPS certificates? Platforms with back doors cannot ever be relied on for serving security to other systems. It's a collective compromise. Botmasters will love it!

Our last piece of relevant news deals with Pwn2Own. The headline says that "security [is] still a myth on Windows PCs" [via] and that it took just one day to crack Windows. To quote: "Day one of the 2015 Pwn2Own hacking contest in Vancouver, Canada, saw big wins for contestants and headaches for software makers: competing teams successfully exploited fresh vulnerabilities in Adobe Flash and Reader, Microsoft's Windows and Internet Explorer, and Mozilla's Firefox, to hijack PCs."

Was it Firefox on Windows as so often is the case? Not even Tor is secure on Windows. ⬆

Recent Techrights' Posts

Voice for the Impoverished
the country's leaders attack the country's own press
 
Slop-ware Is Not Newsworthy
LLMs are exceptionally loquacious and create large code bases
Links 11/10/2026: US Sides With Vladimir Putin, Convicted Felon Dubbed "Agent of a Foreign Power"
Links for the day
IRC Tracker Back in Order, Number of Known IRC Networks Continues to Increase
We don't know if our article helped trigger a resolution
Links 11/10/2026: "Execution TV" (Iran Aped by US) and ‘Digital Oblivion’ Caused by Slop Frenzy Online
Links for the day
Gemini Links 11/10/2026: Adults Dressing Up as Animals, 44th Birthday, and More
Links for the day
Running a Country's Economy by Borrowing Over $400,000,000,000 Per Month
This is the hallmark of an economy in irreversible decline
Brigading Against Women - Part XXVI - Trying to Deplatform Critics of Microsoft's Restricted Boot
Like James Bottomley, Matthew Garrett served Microsoft's agenda while employed and salaried by other companies
Anderon Is Not a Real Company, It's an IBM Bailout Dressed Up or Wrapped Up In Buzzwords
It certainly does seem like they receive money from taxpayers for nothing, or for IBM to do mass layoffs/closure at Albany under the guise of "making a new spinoff"...
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, October 10, 2026
IRC logs for Saturday, October 10, 2026
Gemini Links 10/10/2026: Radio Romania International, Avoiding GAFAM, Open Camera, and Another Palm
Links for the day
The 2026 Slop Prediction (Slopfarms Perishing)
Morality in the "digital world" has deteriorated profoundly
netsplit.de (Survey of IRC Networks and History) Only Partly Functional This Month
Get well soon, netsplit.de
Microsoft Cuts
GAFAM enshittification
NVIDIA Acts Like It Cannot Pay Salaries (Too Many Obligations, Sales in Circular Financing, or Basically Accounting Fraud)
Masters of acting as clients of themselves
Paying for elections, Reform UK illegal confession in High Court
Reprinted with permission from Daniel Pocock
Contemptuous Law Firm Accusing Others of Contempt of Court
Keeping a running tally can help
Links 10/10/2026: Let's Encrypt Making Changes (Problem for Small Sites/Operations), Quartz is Officially a Slopfarm (Busted)
Links for the day
Microsoft Abuses PERM and Lays Off Workers in India
The US government has made it easier for Microsoft to hide the mass layoffs
The GAFAM Elections in the United States
If the election is run by platforms that have back doors "baked-in" and if the communications are overseen by GAFAM, you would not have to be a "nutty MAGAt" to dispute the outcome
More GAFAM Layoffs (Late on Friday Night)
They say they are worth trillions, but they don't even make money
Male-Dominated EPO Fails to Have "Concrete Measures to Support Female Staff"
Being a female at the EPO is exceptionally hard
Brigading Against Women - Part XXV - No Anonymity for People Who Did Illegal Things
"Empathy is the sunlight to the vampire of culture."
Production Freeze at the European Patent Office (Opposing Monarchy, Institutional Maladministration and Corruption)
Eight reasons to participate
Links 10/10/2026: Microsoft 'Open' 'AI' Silencing Critics, "Data Centres are the New Front Line in the Russia-Ukraine War"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, October 09, 2026
IRC logs for Friday, October 09, 2026
Gemini Links 10/10/2026: Optimism, Stargazing, "Life Without Smartphone", and Fairphone 4
Links for the day
Links 09/10/2026: Stranded Busan Shark Still a 'Circus', Endangered Monkey Rescued, BBC Shells Out Money
Links for the day
Gemini Links 09/10/2026: Manifesto, Slop, Geminispace, and "Cryptography of the Internet"
Links for the day
Betanews is Still a Slopfarm, Articles About "Linux" Are Fake and Plagiarism by LLMs
Cheaters and plagiarists aren't journalists; they're people who rip off and harm journalists
The Register MS Sponsored to Hype Up "Datacenters" and "AI" (Bubble, Pyramid Scheme)
"Sponsored by Cisco" with "AI" 26 times in this page
James Bottomley Has Promoted Microsoft-Controlled Restricted ('Secure') Boot, His Blog Has Just Been Cracked
Does this meet IBM's and Microsoft's standards for "distinguished" (in security)?
Links 09/10/2026: "Internet Archive to Demo Wayback Machine at Friday’s Uniqlo Street Festival", France Wages Censorship War via DNS
Links for the day
Controlled Opposition
The underlying concept is hardly new
More Stallmans
We need more Stallmans, we don't need to change Stallman
SUEPO Munich (EPO Staff Union in the Main Headquarters) Opposes Monarchy ('Cocaine King' Campinos), Plans Online Meeting Next Week
They may have about 1,000 workers joining in
World Mental Health Day is Tomorrow and EPO Staff Talks About What the Job Does to Workers
In recent years we've written a great deal about mental health consideration in relation to work, with a focus on "IT"
GNU/Linux Flirts With 20% "Market Share" in North America Overnight
Who should we trust on GNU/Linux? Microsofters on an armchair or Cloudflare Radar?
You Definitely Do NOT Wish to Live Close to a Datacentre
put aside for a moment the noise, the pollution...
New Site Makes the Case Against Adoption of Omarchy, But Focuses Almost Entirely on Politics
Let's examine what the page says and what points it focuses on
Brigading Against Women - Part XXIV - Nobody's Name is Unspeakable
Names are not sacred
Microsoft is in Trouble (With the Regime It Sponsored)
It seems like Microsoft paying the existing regime/dictatorship wasn't enough
GGG Pot Calls the Kettle Black
"It means a situation in which somebody accuses someone else of a fault which the accuser shares, and therefore is an example of psychological projection, or hypocrisy. Use of the expression to discredit or deflect a claim of wrongdoing by attacking the originator of the claim for their own similar behaviour (rather than acknowledging the guilt of both) is the tu quoque logical fallacy."
In the United Kingdom, Rising Cost of Hardware Benefits GNU/Linux
GNU/Linux rose from about 4% to almost 6% in one year
Japanese Targets of Cyber Breaches or Insider Threats
Japanese government bureau and major firms experience data breaches
Gemini Links 09/10/2026: Optimism, Stargazing, and Solar MiniServer
Links for the day
The Microsoft Ban Should Go Further (Telecommunications Cybersecurity and Resilience Act Incompatible With Back Doors)
it's not difficult to see where to start
When Americans Export a 'Suicide Mission' to Other Continents
I worry that this culture of debt-taking and overconsumption is being spread from the US to Europe
The Register MS: "AI" Several Times in Same Headline, 31 Times in Page. The Register MS Was Paid to Do This.
The phenomenon is commercial (paid media), not scientific
The Outcome of Microsoft Ban Was Predictable
told you so
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, October 08, 2026
IRC logs for Thursday, October 08, 2026