Bonum Certa Men Certa

Debunking the Idea of 'Secure' Windows (or Proprietary Software, by Extension)

"The continuous and broad peer-review enabled by publicly available source code supports software reliability and security efforts through the identification and elimination of defects that might otherwise go unrecognized by a more limited core development team."

--CIO David Wennergren, Department of Defense (October 2009)



Summary: Microsoft has a new charade, centered around lobbying hubs such as Brussels, to give non-technical people the false impression of Windows 'security'

GIVEN the special relationship between Microsoft and the NSA (proven by NSA leaks), one might expect no sane government (or even company) to do business with Microsoft ever again. But after some show trials (e.g. in Ireland), public lobbying, and the many lies spread through corporate media (puff pieces) some actually do view Microsoft as antagonising the NSA -- a nice and convenient myth if you can get yourself to believe it.



Dr. Glyn Moody wrote a response to Microsoft's publicity stunt which tries to sell the impression that Windows and other Microsoft software do not have back doors, despite admissions to the contrary. Microsoft is pretending that Windows is secure using the 'Transparency Centre' farce. Here is some of Moody's response to it:

The issue of back doors and the possibility that software companies have been cooperating with the NSA to undermine the security of their products has become particularly sensitive in the wake of Edward Snowden's revelations about the surveillance activities of the NSA and GCHQ. One of the earliest leaked documents concerned the Prism programme, which apparently showed that the NSA had direct access to the systems of all the top US software and Internet companies.

On a presentation slide indicating the dates when Prism began for each "provider," Microsoft is listed as the very first, starting in 2007. In response, Brad Smith, General Counsel & Executive Vice President, Legal and Corporate Affairs, Microsoft, denied that the NSA had "direct and unfettered access to our customer’s data." He insisted: "Microsoft only pulls and then provides the specific data mandated by the relevant legal demand."

Soon after the Prism story appeared, a report from Bloomberg claimed that Microsoft "provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix." In an article published this week by The Intercept discussing criticisms of Microsoft's BitLocker disk encryption program, the company was asked to respond to Bloomberg's allegations from 2013. A Microsoft spokesperson said that sharing bugs was simply part of the GSP, and that "its intention is to be transparent, not to aid spy agencies in making malicious software."

According to the original Bloomberg article, however, that's exactly what the NSA used them for: specifically, they "allowed the U.S. to exploit vulnerabilities in software sold to foreign governments." Asked about "instances in which Microsoft built methods to bypass its security and about backdoors generally", the spokesperson also told The Intercept that Microsoft "doesn’t consider complying with legitimate legal requests backdoors."

The opening of the Transparency Centre in Brussels is evidence that Microsoft is worried that some in Europe still have their doubts about whether its software can be trusted. Microsoft's Thomlinson described the move as "the latest step … to enhance the transparency of our software code and continue building trust with governments around the world." He also said that there needs to be "a high level of openness and cooperation between public and private sectors."


Microsoft's back doors in its software do not need to be built into the binaries. Microsoft can add them when it's time to update, it can use security holes (which it tells the NSA about before they are fixed), and it uses bogus encryption -- as it does -- to completely beat the purpose of secure messaging or massage-passing. Moreover, nobody supervises the build process of Windows, except the NSA. There is no telling what is being compiled and how. There is no telling what happens before binaries are installed on computers (en route), where hard drives and various other hardware have back doors (as revealed by NSA leaks) that 'hook' onto Windows like a hand inside a glove. Proprietary software cannot be trusted, not in this 'transparency' sense. It might, however, be just enough to fool some non-technical people.

Recent Techrights' Posts

[Meme] Not About How Many Locks One Adds
Some people try to point their fingers in all the wrong directions now that a new patch is available for rsync
Total Lock-down Ambitions - Part I - DRM and TPM Need Not be the Future of Computing, There's Another Way
Who is being restricted? Us, the users.
New Upcoming Series About DRM and TPM
We'll do our best to name and explain some of the alternatives that are still available
More Microsoft Cuts and Layoffs (Microsoft Media Mole Jordan Novet Tries to Float "Hiring Freezes" Spin After the "Headcount" Spin Failed)
As one might expect...
 
It Was Only a Matter of Time
We're going to pursue justice
[Meme] "Well, He’s Dead So," Bill Gates Tells the Media (Which He Pays) About His Close Friend Jeffrey Epstein
Does the police in San Francisco cover up crimes instead of solving them?
The Rumour Was Right, Today is the Second Large Wave of Microsoft Layoffs in 2025
It has only been two weeks since the year began
The Free Software Foundation (FSF) Has Had a Good 2025 Already (Its "Year 40")
FSF will reach $400,000
Computer Users Aren't Zoo Animals
Animals don't belong inside cages in zoos, either
[Meme] His Existence is Proof It's Not Infeasible
We salute the FSF's original mission
Links 15/01/2025: Efforts to End Wars and 'Newsflation'
Links for the day
Gemini Links 15/01/2025: Abandoning Windows for GNU/Linux, SIS Progress Update
Links for the day
Links 15/01/2025: Social Control Media Spreading Lies, TikTok Banned in 4 Days
Links for the day
Microsoft Breaks Linux Again
Does it even care? It's selling Windows.
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, January 14, 2025
IRC logs for Tuesday, January 14, 2025
Links 14/01/2025: Vaccination Hesitancy Problems and Kangaroo Courts (UPC)
Links for the day
Gemini Links 14/01/2025: Introduction to GrapheneOS and Small Internet
Links for the day
Dr. Miriam Bastian From the Free Software Foundation (FSF) Gives a Talk in a Couple of Weeks at FOSDEM (Brussels, Belgium)
It's good to see people from all around the world and with very different backgrounds united around digital philosophy
Andy Farnell on Eating Your Own Dog Food
focuses on security but goes beyond that
EPO Uses the Misnomer "AI" to Attack Software Developers in Europe
The EPO is nowadays a huge pile of crimes
The European Patent Office’s (EPO) Communication on "Reform" is "Incomplete and Misleading," Says the Central Staff Committee at the EPO
This puts Europe at risk and makes it more vulnerable
[Meme] How to Lose Social Life (While Pretending to Still Have It)
Talk to people, not to microphones
Android (or AOSP) is More Free Than iOS, Both in Practice (as OEM Bundles) Both Are User-Hostile
In a perfect world, people would choose and deploy software that is entirely made up of reciprocally-licensed bits
Neuroscience of Consciousness Paper: Why Social Control Media and Proprietary Spyware Harm Your Health
"Software Freedom turns out to be good for your health"
Access to the Source Code of the Programs You're Using Matters (Even If You're Not a Coder and Cannot Fix Bugs)
Companies like Microsoft tell us that full access to all the code isn't important
Guardian Digital (linuxsecurity.com) Publishes Fake Articles About Linux and About (for) 'Linux' Foundation Openwashing
Brittany Day is at it again
Links 14/01/2025: LA Crisis and EU, UK Respond to "X.com" Threat From South African Oligarch
Links for the day
The Word About the Upcoming Talk by Richard Stallman - Scheduled for Friday This Week - Has Spread ("The Cost of Freedom," Lausanne, Switzerland)
So the word is spreading
"AI Music" is Not Music and It's Hardly "AI" Either
Synthetic garbage is a solution in search of a problem
Webspam in BetaNews
Not only is it marketing SPAM
[Meme] 13 Years a Slave of Microsoft
Might makes right?
Gemini Links 14/01/2025: The Gemtext Print Hurdle and New Game: Fill!
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, January 13, 2025
IRC logs for Monday, January 13, 2025
Links 13/01/2025: Conflicts, Prisoner Exchange, and Homes on Fire
Links for the day
Angola: Microsoft Windows Falls Below 10%
Microsoft has a really bad 2024 in Africa
[Meme] Twitter ("X") Has Been Grooming Radicals Since 2022
Musk's very own "grooming gang"
[Meme] What Free Speech Ought to Mean
It does not sound like RMS suggests anything other than quitting social control media
Gemini Links 13/01/2025: RestFest, Yule, and Deedum
Links for the day
Modern Web Browsers as Web Censorship Software
We continue to recommend Geminispace
Two Weeks From Now Dr. Richard Stallman Speaks at The Summit of Future 2025 (India)
he will be giving a "Keynote Address" in India
Microsoft is Tight With Money: It's About the Salaries ('Cost' of the Workers)
a question of cost, not skill
Google Got People Sort of Addicted to Android So It Can Cash in (Services, App Store, Advertising) Decades Later
This is not software freedom
The Free Software Foundation Reaches 370k Dollars in Funding, Due Date is January 17th When Richard Stallman is Guest of Honour in Lausanne (Switzerland)
Even fellow board members seem unaware of it
Record Lows for Windows (Microsoft) in Botswana
The market share of Vista 11 is seen as going down
Preserving Deleted Articles About Bill Gates Talking Like a Drug Dealer About Computer Users
Now it's 2025. Different challenge.
Links 13/01/2025: Disinformation, Social Control Media Actively Promoting Nazism, and Catchup With Ukraine
Links for the day
Microsoft Front Group Starts the Year by Championing Underage (or Child) Labour
the fake 'FSF'
TPM Boosters Inside Debian (TPM Isn't About Security, It is About Control Over Users and Their Machines)
We're not rushing to any conclusions
Aaron Swartz Died 12 Years Ago After a Vicious Government Campaign to Stop Him
The Aaron Swartz story is a reminder of the importance of having verifiable/verified information out there for the general public to see
Links 13/01/2025: GitLab Enshittification and Minimalism and Efficiency with Gemini Protocol
Links for the day
Links 13/01/2025: Hardware, Health, and Conflicts
Links for the day
Chatbots Are Not Data-Driven, They're Human-Censored and Rely on Wage Slaves (and Sometimes Unpaid Volunteers)
This is the Microsoft wage slavery
Microsoft Appears to Have Fallen to Only 15% in Maldives
This is a problem for Microsoft
Rumours of IBM Canada Layoffs
We'll keep a vigilant eye on this
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, January 12, 2025
IRC logs for Sunday, January 12, 2025