EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

11.02.09

Microsoft Breaks the Law by Not Patching Windows as Per the Agreement

Posted in Law, Microsoft, Security, Windows at 4:35 am by Dr. Roy Schestowitz

Balance

Summary: Microsoft’s legal obligations are hanging in the balance while Windows 2000 does not receive security patches

ABOUT a month ago we showed that Microsoft broke its contract with the customers by refusing to patch Windows XP. As it turns out, Microsoft is doing this with Windows 2000 as well.

Our reader Ryan, who is a former Microsoft MVP and an expert in this area, wrote in IRC: “You should drive home a point that you aren’t when talking about Conficker and its brethren. Windows 2000 will be TEN YEARS OLD on February 17, 2010, and still manages to get at least a dozen security patches a month, even now. It’s a good way to point out that no matter how many patches you install, there’s always more vulnerabilities. Several thousand of them have been patched in Windows 2000 and it’s still regularly patched. You would think that the patch rate would have slowed down and the OS would have more or less settled by now, but it’s going to be patched from birth to abortion. You should also mention that companies won’t necessarily throw out Windows 2000 on their systems just because it’s out of support. From Wikipedia: ‘On 8 September 2009, Microsoft skipped patching two of the five security flaws that were addressed in the monthly security update, saying that patching one of the critical security flaws was “infeasible”.[93] According to the Microsoft Security Bulletin MS09-048, “The architecture to properly support TCP/IP protection does not exist on Microsoft Windows 2000 systems, making it infeasible to build the fix for Microsoft Windows 2000 Service Pack 4 to eliminate the vulnerability. To do so would require rearchitecting a very significant amount of the Microsoft Windows 2000 Service Pack 4 operating system, [...] there would be no assurance that applications designed to run on Microsoft Windows 2000 Service Pack 4 would continue to operate on the updated system.”‘ Windows 2000 not only shares all the vulnerabilities in XP, Microsoft has started refusing to patch some while the damned thing is still supported (to try and force an upgrade). It’s not the first time that Microsoft has refused a security patch for operating systems still in support, they left some critical Windows 98 and Windows NT 4 vulnerabilities unpatched, with a year left on the support lifecycle.

“In other words, Microsoft can flagrantly violate the hell out of their side of the agreement, but don’t you dare to step out of line or install Windows on two systems with one license.”
      –Ryan
“Windows 2000 is supported until July of 2010, meaning that per their support agreement, every security patch should be delivered on until then, so they’re violating their own support agreement, but insisting that you obey your obligations under their EULA. This is kind of like the times Microsoft was found violating their side of the privacy agreement in Windows Media Player 7 (they probably still do). In other words, Microsoft can flagrantly violate the hell out of their side of the agreement, but don’t you dare to step out of line or install Windows on two systems with one license.”

Fewa responds with: “Microsoft has always been an outlaw corporation. They only obey the laws that benefit them and disregard those that would dare limit their greed of monopoly. They even wish to impose on other those laws. It’s not just that; of course having the government totally hijacked for 6 years did not help. The democrats got a majority in 2006 (in the house).”

“8 years,” insists Ryan, “and I’d argue that they still do. Obama has packed the DOJ with more RIAA mafia types.” Here is a collection of references.

Ryan is not optimistic. “They’re one of the richest companies and have hundreds of lawyers,” he says. “You could sue them, in theory, but they could just stall forever.”

To summarise, writes Ryan: “What kind of confuses me is that according to Microsoft, breaking their EULA is “illegal”, but when they break their side of the agreement it’s OK as long as they can say “It would have been too much work to close that critical patch on Windows 2000.” It would be like me saying “Well, I installed the same copy of Windows on ten computers cause it would have been too much of a strain on my finances to buy 9 more licenses”; Same defense they’re trying, too much of a strain on limited resources, so it’s OK to break the agreement.”

In other news, Microsoft’s cryptology is broken again.

Microsoft releases fix for crypto patch

[...]

The ocsasnfix.exe (direct download) program is to fix the glitch both in the client and in the server. In a knowledgebase article, Microsoft describes how to run the program and what other actions may need to be taken.

Perhaps Microsoft could not just disable the features this time around [1, 2].

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

8 Comments

  1. Jose_X said,

    November 2, 2009 at 7:51 am

    Gravatar

    >> Our reader Ryan, who is a former Microsoft MVP and an expert in this area, wrote in IRC: “…Windows 2000 will be TEN YEARS OLD on February 17, 2010, and still manages to get at least a dozen security patches a month, even now. It’s a good way to point out that no matter how many patches you install, there’s always more vulnerabilities… You would think that the patch rate would have slowed down and the OS would have more or less settled by now, but it’s going to be patched from birth to abortion….”

    http://boycottnovell.com/2009/03/08/conficker-alive-vista-office-flaws/#comment-60287

    > Do they “patch” one hole by moving it around to a different hiding place?

    Rather than _fix_ a vulnerability, I’d almost wager that they keep the holes around but re-hide them. This would allow the holes/backdoors to keep existing but hide their location so that unauthorized sources can’t exploit them (at least not until these get rediscovered).

    Or maybe Microsoft developers are simply sloppy repeatedly at infinitum. All those smart people might be too wealthy to put in solid effort. We should help them regain their mojave by contributing less money to them.

    Really, perhaps it’s “too much work” to fix the vulnerabilities when a quick reshuffling would stop the current malware cold. The pressure is on to find fixes quickly. Who will know the difference anyway? Microsoft keeps the source code to themselves, and if the hole is rediscovered, it will simply appear as an new distinct vulnerability.

    Maturing software? What’s that?

    Alright, the hole shuffling might not be the norm. Who knows?

    Either way, it is a little scary to think what will happen when Microsoft’s profits aren’t large enough for their needs. What will become of your data on your PCs on their abandoned software?

    Will you get the locked proprietary data out of your systems before the virus and other malware completely decimate the host computers and everything on them?

    Will Microsoft promise to meet their contract security obligations when it’s no longer extremely profitable to do so? [I'm echoing the article]

    With Linux+FOSS [I have to mention this in case some readers don't know], there is a free upgrade path for life and the data is not locked. That’s at least two viable paths that can be taken no matter what (well, to an approximation since really old software source code is not looked at too much). Also, vulnerabilities (at least for important widely used software) usually aren’t simply moved around for convenience’s sake because those watching likely catch it right away and scream (or make the fixes themselves).

  2. Yuhong Bao said,

    November 2, 2009 at 11:03 am

    Gravatar

    “It’s not the first time that Microsoft has refused a security patch for operating systems still in support, they left some critical Windows 98 and Windows NT 4 vulnerabilities unpatched, with a year left on the support lifecycle.”
    Yea, I told you that what MS recently did to XP is not new.
    “Windows 2000 is supported until July of 2010, meaning that per their support agreement, every security patch should be delivered on until then, so they’re violating their own support agreement”
    See my comments to this article:
    http://boycottnovell.com/2009/09/21/windows-xp-security-eol/

  3. Yuhong Bao said,

    November 2, 2009 at 11:17 am

    Gravatar

    “> Do they “patch” one hole by moving it around to a different hiding place?
    Rather than _fix_ a vulnerability, I’d almost wager that they keep the holes around but re-hide them”
    This is the closest thing to this happening that I can find:
    http://vx.netlux.org/lib/apf00.html
    http://pferrie.tripod.com/papers/ani.pdf
    Note however that the support lifecycle and the EULA are not the same agreement. The latter is for licensing, the former is for support of the same software.

  4. Yuhong Bao said,

    November 2, 2009 at 11:20 am

    Gravatar

    I think a fair comparison is look at how many security holes are still being discovered in say Linux 2.4 years after it was released.

    Roy Schestowitz Reply:

    But Linux is just a kernel and Microsoft hides/lumps together flaws (it got caught).

    Yuhong Bao Reply:

    “Microsoft hides/lumps together flaws (it got caught). ”
    Really? But even if not, it is certainly not as simple as comparing numbers.

    Roy Schestowitz Reply:

    Yes, that’s another issue, one of granularity.

  5. TheTruth said,

    November 3, 2009 at 1:23 am

    Gravatar

    It;s so funny that you bright and ‘honest’ people do not know what a EULA IS !!!..

    It stands for END USER license agreement.

    That means it’s the agreement THE END USER enters into.

    If it was a “Software manufacturers license agreement” then you might (but probably not) have a case.

    But it’s an agreement the END USER enters into, not an agreement the software company signs onto.

    Microsoft is ___ NOT ___ repeat NOT the END USER..

    Go figure, that bright people or people who claim to “know” whats going on would make such an error.

    But for BN it’s expected… almost compulsory to warp, bend or just plain out break the truth..

    Oh and Yes, im Mutex, and yes Roy we all know you dont censor dissenters. But you do, and why ?? because you either dont like, or cannot asnwer even simple questions in relation to you supporting your wild, and untrue “claims”.

    And what OS are you using Roy ?? Linux ?? how do you cope with using linux with all that Novell code in the kernel ???

    How do you sleep at night knowing that every second of every day you are running code written by NOVELL..

    Oh thats right, you can pick and choose what you like in regards to your ’cause’.

    Sure it does not matter that a huge amount of the code you run all the time, was written by NOVELL.

    Why dont you create your own distro, and strip out all the NOVELL code, and replace it with your own.

    Oh thats right, you dont code do you, in fact you dont contribute to FOSS at all. you are hell bent on taking away linux and FOSS.

    Thats right, if all the NOVELL code on your computer suddenly went away, do you think it would still work…, Ill tell you, IT WONT..

    But somehow you can both boycott NOVELL and use their product ALL THE TIME. but in your mind that is ok,,, right ??

    And why are you so very scared of me Roy, what is it that I do that makes you feel so uneasy, is it because I CHECK YOUR ‘FACTS’. and when I see that you are lying I TELL YOU..

    My bad, I should of guessed you dont like to have people question your motives.

    Hows your PhD going ?? how many years ago did you finish it,, 2006?

    Gee Roy, it must be nice to mooch off Daddy and Mommy, and spend your life (waste your life) running your hate site.

    I see now you’ve also branched into politics, and anything else you dont agree with, including racist remarks about the President of the USA…

    You do understand that it would be much easier for you to state what you DO like, as opposed to stating what you HATE… as the list would be much smaller.

    But go on using your NOVELL code, all day every day, that very code that is hosting this web site, is FROM NOVELL…

    So how is that boycotting them ?? it’s not..

    but trying to talk logically to you is impossible, apart from you running a 3 minute mile when I start to question you..

    It’s funny, (or sad) how you can pick and choose what you use and hate and how they can be both the same thing…

    Roy,,, get a job, stop being a leech on humanity, and do something !!!!.

    Oh,, that would be “WORK” and you dont do that, BN is just too important for you to

    SUDO APT-GET A LIFE …

What Else is New


  1. Links 2/1/2017: Neptune 4.5.3 Release, Netrunner Desktop 17.01 Released

    Links for the day



  2. Teaser: Corruption Indictments Brought Against Vice-President of the European Patent Office (EPO)

    New trouble for Željko Topić in Strasbourg, making it yet another EPO Vice-President who is on shaky grounds and paving the way to managerial collapse/avalanche at the EPO



  3. 365 Days Later, German Justice Minister Heiko Maas Remains Silent and Thus Complicit in EPO Abuses on German Soil

    The utter lack of participation, involvement or even intervention by German authorities serve to confirm that the government of Germany is very much complicit in the EPO's abuses, by refusing to do anything to stop them



  4. Battistelli's Idea of 'Independent' 'External' 'Social' 'Study' is Something to BUY From Notorious Firm PwC

    The sham which is the so-called 'social' 'study' as explained by the Central Staff Committee last year, well before the results came out



  5. Europe Should Listen to SMEs Regarding the UPC, as Battistelli, Team UPC and the Select Committee Lie About It

    Another example of UPC promotion from within the EPO (a committee dedicated to UPC promotion), in spite of everything we know about opposition to the UPC from small businesses (not the imaginary ones which Team UPC claims to speak 'on behalf' of)



  6. Video: French State Secretary for Digital Economy Speaks Out Against Benoît Battistelli at Battistelli's PR Event

    Uploaded by SUEPO earlier today was the above video, which shows how last year's party (actually 2015) was spoiled for Battistelli by the French State Secretary for Digital Economy, Axelle Lemaire, echoing the French government's concern about union busting etc. at the EPO (only to be rudely censored by Battistelli's 'media partner')



  7. When EPO Vice-President, Who Will Resign Soon, Made a Mockery of the EPO

    Leaked letter from Willy Minnoye/management to the people who are supposed to oversee EPO management



  8. No Separation of Powers or Justice at the EPO: Reign of Terror by Battistelli Explained in Letter to the Administrative Council

    In violation of international labour laws, Team Battistelli marches on and engages in a union-busting race against the clock, relying on immunity to keep this gravy train rolling before an inevitable crash



  9. FFPE-EPO is a Zombie (if Not Dead) Yellow Union Whose Only de Facto Purpose Has Been Attacking the EPO's Staff Union

    A new year's reminder that the EPO has only one legitimate union, the Staff Union of the EPO (SUEPO), whereas FFPE-EPO serves virtually no purpose other than to attack SUEPO, more so after signing a deal with the devil (Battistelli)



  10. EPO Select Committee is Wrong About the Unitary Patent (UPC)

    The UPC is neither desirable nor practical, especially now that the EPO lowers patent quality; but does the Select Committee understand that?



  11. Links 1/1/2017: KDE Plasma 5.9 Coming, PelicanHPC 4.1

    Links for the day



  12. 2016: The Year EPO Staff Went on Strike, Possibly “Biggest Ever Strike in the History of the EPO.”

    A look back at a key event inside the EPO, which marked somewhat of a breaking point for Team Battistelli



  13. Open EPO Letter Bemoans Battistelli's Antisocial Autocracy Disguised/Camouflaged Under the Misleading Term “Social Democracy”

    Orwellian misuse of terms by the EPO, which keeps using the term "social democracy" whilst actually pushing further and further towards a totalitarian regime led by 'King' Battistelli



  14. EPO's Central Staff Committee Complains About Battistelli's Bodyguards Fetish and Corruption of the Media

    Even the EPO's Central Staff Committee (not SUEPO) understands that Battistelli brings waste and disgrace to the Office



  15. Translation of French Texts About Battistelli and His Awful Perception of Omnipotence

    The paradigm of totalitarian control, inability to admit mistakes and tendency to lie all the time is backfiring on the EPO rather than making it stronger



  16. 2016 in Review and Plans for 2017

    A look back and a quick look at the road ahead, as 2016 comes to an end



  17. Links 31/12/2016: Firefox 52 Improves Privacy, Tizen Comes to Middle East

    Links for the day



  18. Korea's Challenge of Abusive Patents, China's Race to the Bottom, and the United States' Gradual Improvement

    An outline of recent stories about patents, where patent quality is key, reflecting upon the population's interests rather than the interests of few very powerful corporations



  19. German Justice Minister Heiko Maas, Who Flagrantly Ignores Serious EPO Abuses, Helps Battistelli's Agenda ('Reform') With the UPC

    The role played by Heiko Maas in the UPC, which would harm businesses and people all across Europe, is becoming clearer and hence his motivation/desire to keep Team Battistelli in tact, in spite of endless abuses on German soil



  20. Links 30/12/2016: KDE for FreeBSD, Automotive Grade Linux UCB 3.0

    Links for the day



  21. Software Patents Continue to Collapse, But IBM, Watchtroll and David Kappos Continue to Deny and Antagonise It

    The latest facts and figures about software patents, compared to the spinmeisters' creed which they profit from (because they are in the litigation business)



  22. 2016 Was a Terrible Year for Patent Trolls and 2017 Will Probably be a Lot Worse for Them

    The US Supreme Court (SCOTUS) is planning to weigh in on a case which will quite likely drive patent trolls out of the Eastern District of Texas, where all the courts that are notoriously friendly towards them reside



  23. Fitbit’s Decision to Drop Patent Case Against Jawbone Shows Decreased Potency of Abstract Patents, Not Jawbone’s Weakness

    The scope of patents in the United States is rapidly tightening (meaning, fewer patents are deemed acceptable by the courts) and Fitbit’s patent case is the latest case to bite the dust



  24. The EPO Under Benoît Battistelli Makes the Mafia Look Like Rookies

    Pretending there is a violent, physical threat that is imminent, Paranoid in Chief Benoît Battistelli is alleged to have pursued weapons on EPO premises



  25. Links 29/12/2016: OpenELEC 7.0, Android Wear 2.0 Smartwatches Coming

    Links for the day



  26. Links 28/12/2016: OpenVPN 2.4, SeaMonkey 2.46

    Links for the day



  27. Bad Service at the European Patent Office (EPO) Escalated in the Form of Complaints to European Authorities/Politicians

    A look at actions taken at a political level against the EPO in spite of the EPO's truly awkward exemption from lawfulness or even minimal accountability



  28. No “New Life to Software Patents” in the US; That's Just Fiction Perpetuated by the Patent Microcosm

    Selective emphasis on very few cases and neglect of various other dimensions help create a parallel reality (or so-called 'fake news') where software patents are on the rebound



  29. Links 27/12/2016: Chakra GNU/Linux Updated, Preview of Fedora 26

    Links for the day



  30. Leaked: Letter to Quality Support (DQS) at the European Patent Office (EPO)

    Example of abysmal service at the EPO, where high staff turnover and unreasonable pressure from above may be leading to communication issues that harm stakeholders the most


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts