Bonum Certa Men Certa

Back Doors/Bug Doors in All Versions of Microsoft Windows Need a Name, a Logo, and Branding Too

Microsoft gets a free pass for insecurity

Michael S. Rogers "I don’t want a back door. I want a front door." -- Director of the National Security Agency (NSA), only days ago



Summary: All versions of Microsoft Windows are found to have been insecure since 1997, but the bug responsible for this is not named as candidate for back door access, let alone named (with logo and marketing) like far less severe bugs in Free/libre software such as OpenSSL

WHILE many journalists still refuse to call out Windows (see this new piece from Dan Goodin, who writes about crackers hoarding Windows hosts by the millions -- in botnets -- while mentioning the word "Windows" only once, very deep inside the article), some have no choice by to acknowledge that not every single computer runs Windows and therefore we should call out Windows when it's clearly to blame.



"This wouldn't be the first time it happens; recall how Google had to alert Microsoft for 3 months about a serious flaw while Microsoft did absolutely nothing (as if the intention was to keep Windows insecure, albeit secretly, very much like Apple)."Although there is no "branding" yet (as Microsoft buddies from a a Microsoft-linked firm like to do to Free/libre software bugs), there is a very serious bug in all versions of Windows (even the one still in development) that Microsoft's allies at the NSA must be very happy about, especially as the bug is 18 years old (meaning that Windows has allowed remote access since 1997, or around the time Microsoft was seeking to appease the US government after it had shamelessly broken many laws).

The bug was found not by Microsoft but by this team (press release), which probably has no access to Windows source code. This wouldn't be the first time it happens; recall how Google had to alert Microsoft for 3 months about a serious flaw while Microsoft did absolutely nothing (as if the intention was to keep Windows insecure, albeit secretly, very much like Apple).

ISPs should now restrict or ban Windows use, as it poses a huge risk (botnets and DDOS, never mind risk to all data stored on machines running Windows). Here is some early coverage of this [1, 2], some correctly emphasising that it's a 18-year-old vulnerability [1, 2].

Let's see if this starts a big debate about the insecurity of proprietary software (as other bugs with "branding" did to Free software, by means of gross generalisation). This "New Security Flaw Spans All Versions Of Windows" (similar wording in this headline). 18 years, eh? It even predates 9/11. It's older than some readers of this Web site.

Watch this disgraceful piece titled "Will Microsoft’s Security Measures in Windows 10 Tarnish Open-Source Development?"

Yes, it's more propaganda; The disingenuous openwashing of Windows continues, as we'll show in our next post.

"Our products just aren't engineered for security."

--Brian Valentine, Microsoft executive



Recent Techrights' Posts

Father of GNU Giving Keynote Talk Today, Father of Linux Collaborating With Linus Tech Tips (LTT)
Some time soon we can expect Linus Tech Tips (LTT) / Linus Media Group / Linus Gabriel Sebastian to produce something with Torvalds
LLM Slop is an Addiction One Can Quit
Sites that crossed over to "the dark side" (slop) can still return, and even fully regain the trust lost by betraying people with 'botspew'.
BILD is Apparently Covering Up Cocaine Use at Europe's Second-Largest Institution, the European Patent Office, as It's Based on Germany
Journalist contact details
 
German Media and German Politicians: Working for the Public or Manipulating the Public?
The "common person" does not have printing presses
Informing the Public of Suppressed Facts
We are all in this together
Canadian Linus Meets Finnish-American Linus
LTT does have a very large audience, which it can steer away from Microsoft and Windows
The UK's Online Safety Act (OSA) Discourages Technological Entities, Including Free Software Projects, Being Based in or Near the UK
When it comes to IRC hosting, we never had any serious speech restrictions imposed upon us by the UK
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, November 15, 2025
IRC logs for Saturday, November 15, 2025
Gemini Links 16/11/2025: Emacs Font Fun and UI x TUI x CLI
Links for the day
Flagging or Labelling LLM Slop Meaningfully to Discourage the Practice
We're still refining the annotation for better contrast
Techrights Site Search Pushed to 'Stable'
we've just added it to the navigation menu and footer
Situation Publishing's DevClass (Sister Site of The Register MS, Run by MS Tim) Has Been Abandoned, Microsoft's MS Tim Now Interjects Anti-Linux Directly Into The Register MS
Not only does this sell Microsoft; it's also googlebombing - as before - the real "maui" (or "MauiKit" in Linux).
Many IBM Workers to Become Unemployed a Few Weeks - Maybe Just Days - Before Christmas
as one last humiliating exercise IBM pimps/trots them out in social control media, telling "happy" stories
Slopwatch: LinuxSecurity, WebProNews, and Linux Journal (Slopfarms)
More fake articles about "Linux"
Links 15/11/2025: Openwashing of Kubernetes and Austerity Planned for Canada
Links for the day
Links 15/11/2025: "Small Web, Big Voice" and China Cracking Down on Slop
Links for the day
Links 15/11/2025: Science, Conflicts, and International Politics
Links for the day
Annus Horribilis at the European Patent Office (EPO)
The article explains how the EPO "Cocainegate" scandal is turning 2025 into an Annus Horribilis for Campinos
Links 15/11/2025: Latest in "Component Abuse Challenge" and Qt Keeps Promoting LLM Slop
Links for the day
Gemini Links 15/11/2025: Egoism, Misunderstood Universe, DeX, and "Why desktop Linux is growing"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, November 14, 2025
IRC logs for Friday, November 14, 2025
Richard Stallman Talk Tomorrow in Ethereum Cypherpunk Congress 2
It's not clear if a livestream of some kind will exist
Many "Last Days" at IBM on Allegedly the "Last Day" for IBM to RA People This Quarter
"Last day" is "social media code" for "got laid off", more so at IBM because they compel people to act like it's a happy departure with gratitude, photos and so on
Slopwatch: Almost a Majority of Google News is Now Slopfarms (Fake Sites, Fake Articles)
Google News is noise
Gemini Links 14/11/2025: Boredom, "Twenty Percent Cooler", and Moving From Windows to Artix
Links for the day
Links 14/11/2025: YouTube's Trap for Publishers, Lack of Accountability a Growing Legal Matter/Concern
Links for the day
Many Times in the Past We Said That Microsoft Lunduke Was Becoming a Spokesperson/Voice for - and Occasionally Weaponising - 4Chan. He's Proving Us Right This Week.
Stay away
The Register MS is Profiting From Pyramid Schemes Run by Americans
We cannot help but feel disgusted by what this publisher became
IBM: Hiring, Then Disposing of, Unpaid or Low-Paid European Staff to Spread or Play Up Buzzwords and Hype
Like Google With "Summer of Code", this seems like a low-cost marketing stunt more than anything substantial
Casual Reminder That We Also Publish GNU/Linux Stories and News Coverage in Tux Machines
Without trust in our robustness (including fearlessness, not just success in protecting stories and sources) we'd not have come this far, nor would I devote my life to it
The Europe Conversation: The EPO Has Cocaine at the High-Level Management and Isn't Denying It
Now we plan to ensure the matter is properly documented in European press
Links 14/11/2025: Goddard Space Center Abused by the White House, Jeffrey Epstein Scandal Expands (Cheetos Need Distraction)
Links for the day
Corporate Media Helps IBM Relay Vapourware (Misinformation/Fake News)
They compensate with words for a lack of compelling products
Hacking on Recipes
Maybe, in due course perhaps, we can also release some of our own cooking recipes or "forks"
Web Searches Far Too Polluted, Gamed by LLM Slop and "Plagiarised Information Synthesis Systems" (PISS)
old articles are already getting difficult to find in mainstream search engines, even if they are still online
Privacy-respecting Metasearch Engine SearX/SearXNG Still Jailed by Microsoft
The official site and code still sadly controlled by Microsoft
"AI" is a Lie. It Always Was. What They Call "AI" Is Not.
This MSM does no favours to the economy
Our First Week of Our Twentieth Year
My wife and I have had a very productive week here and in Tux Machines
Links 14/11/2025: Sleep Research, France to Suspend Pension 'Reform' Law, and Linux Foundation's Latest Openwashing
Links for the day
Gemini Links 14/11/2025: KDE vs XFCE and Leaving the Web
Links for the day
Google Admits It Lost Control of Slop (While Google Itself is Selling Slop, Currently Under the Name "Gemini" Instead of "Bard")
Slop is nothing to be celebrated
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, November 13, 2025
IRC logs for Thursday, November 13, 2025
Mozilla Handed Over Control Over Firefox to Microsoft, Now Firefox is Preloaded With Microsoft Spyware and It's Proprietary
Who would still want to download Firefox?
Slopwatch: LinuxSecurity, Brian Fagioli, and WebProNews
becoming a slopfarm is a site's suicide
"Sponsored Posts" in The Register MS
That's The Register MS in 2025
IBM RAs in India (Apparently)
IBM is a bad place to work
Another Richard Stallman Talk in Two Days
His talk will be a remote talk, as he won't be travelling to Argentina