11.10.09

Microsoft Lies About Security

Posted in Free/Libre Software, FUD, Microsoft, Security, Windows at 8:56 am by Dr. Roy Schestowitz

Guerra al capitol

Summary: Security propaganda from Microsoft tackled yet again in light of this week’s security FUD against Free software

AS WE showed two years ago, Microsoft knowingly hides security problems in its software and sometimes fixes these problems without reporting it to the public. It can be very frequent a routine. This way, when outsiders compare the number of security problems across different products/vendors, they merely compare apples and oranges (Red Hat and Firefox are popular victims of such disinformation). Microsoft is cheating.

Earlier this week Slashdot revealed that Microsoft’s attitude when it comes to security of its on-line services is more or less the same. To make matters worse, Microsoft is trying to gag those who know the truth. From Slashdot’s summary:

Microsoft Tries To Censor Bing Vulnerability

Microsoft’s bing search engine has a vulnerability with its cash-back promotion, which impacts both merchants and customers. In traditional Microsoft fashion, the company has responded to the author of the breaking bing cashback expoit with a cease & desist letter, rather than by fixing the underlying security problem.

Here is the original post.

The purpose of my post was to show an implementation problem, not to encourage defrauding Microsoft. I am surprised they would go through this much trouble to make me take down information that is obvious to anyone reading their documentation. I don’t like dealing with lawyers, so I’ve decided to comply with their request. The post is gone. I will still write a “non-technical” post on all the problems I see with Bing Cashback in the next few days.

The reason why hundreds of millions of Windows PCs are zombies is not just because of negligent users; it’s also because of a company that puts its image and its profits before the safety of computer users. It would shamelessly lie to the public as long as its shareholders’ interests are obeyed. Suffice to say, Free software does not have the same inherent deficiency which is a conflict of interests (honesty versus selfishness). Apache is a good example of this.

According to The Register, botmasters have found new ways of sending instructions to Windows zombies. It’s not the fault of Google, which merely stores arbitrary strings of texts like many other services.

Cyber criminals’ love affair with cloud computing just got steamier with the discovery that Google’s AppEngine was tapped to act as the master control channel that feeds commands to large networks of infected computers.

Sadly enough, we are all left at a dangerous state where cyberwar is said to be imminent, with hordes of Windows zombies recruited to such a task.

CBS News reports that cyber war is a reality that, according to cyber experts, the US will have to be prepared for – and soon.

It is worth adding that the US presidency now has the legal power to shut off the Internet and physical bombing of botmasters is one of the proposed strategies shall disaster strike.

“Security — including national security — must never be put in proprietary hands.”What does Microsoft do about this? It serves the interests of shareholders, which means pretending that Windows (and other Microsoft products) is secure, even by fabrication and outright lies. Security — including national security — must never be put in proprietary hands. It is a recipe for disaster.

One of our readers, pointing to this old gem about password encryption, remarks: “It’s pathetic to see how much Gates has been able to hold back computing. His current antics are not new. However, now his antics involve much more outsourced marketing and tremendous investment in lobbying firms.

Related posts:

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

This post is also available in Gemini over at:

gemini://gemini.techrights.org/2009/11/10/microsoft-propaganda-re-security/

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

8 Comments

  1. Yuhong Bao said,

    November 10, 2009 at 5:20 pm

    Gravatar

    “It’s not the fault of Google, which merely stores arbitrary strings of texts like many other services.”
    And it is not the fault of Microsoft either, who just makes an OS that can run any program, including malware. But if the zombie programs take advantage of things like security vulnerabilities or holes in Windows, that is certainly MS’s fault, and on that here is a quote by Woody:
    From http://www.askwoody.com/2009/autorun-patch-kb-967715-mess/:
    “(Remember, this is the worm that has drawn a $250,000 bounty from Microsoft – and the folks at MS can’t even plug one of its simplest infection vectors.)”

    Roy Schestowitz Reply:

    This worm was the fault of Microsoft; it exploited a massive flaw.

    Yuhong Bao Reply:

    Yep, actually several security flaws in Windows, which are all MS’s fault. And yep, that is what the last quote exactly was about. But to be honest the Linux desktop had it’s share of similarly stupid features as well:
    http://lwn.net/Articles/178409/
    http://lwn.net/Articles/178411/
    http://www.geekzone.co.nz/foobar/6229
    http://www.geekzone.co.nz/foobar/6236
    http://lwn.net/Articles/318755/

    Yuhong Bao Reply:

    More link on this:
    http://lwn.net/Articles/320707/
    http://it.slashdot.org/article.pl?sid=09/02/17/1526244

    Yuhong Bao Reply:

    BTW, on Vista the security flaws are less severe, because Vista has ASLR which prevents one of the flaws from being exploited, and the AutoPlay dialog also got changed in Vista so it is easier to tell that the AutoPlay entry created by the worm is fake. Recent versions of Linux has ASLR too, as well as Mac OS X.

    Roy Schestowitz Reply:

    Don’t forget that Linux usually gets its software (‘alien’ files) from trusted repositories.

    Yuhong Bao Reply:

    Yep, I remember Autopackage aiming to change this, but it kind of failed, I think.

    Roy Schestowitz Reply:

    It’s probably to do with how proprietary software is sold, not distributed. Marketplace/Store paradigm is growing though, especially in phones.

What Else is New


  1. Was Microsoft Ever First in the Market?

    Confronting the false belief that Microsoft ever innovates anything of significance or is "first" in some market/s



  2. Links 1/8/2021: 4MLinux 37.0, IBM Fluff, and USMCA Update

    Links for the day



  3. Microsoft Knows That When Shareholders Realise Azure Has Failed the Whole Boat Will Sink

    The paranoia at Microsoft is well justified; they've been lying to shareholders to inflate share prices and they don't really deliver the goods, just false hopes and unfulfilled promises



  4. [Meme] Nobody and Nothing Harms Europe's Reputation Like the EPO Does

    Europe’s second-largest institution, the EPO, has caused severe harm/damage to Europe’s economy and reputation; its attacks on the courts and on justice itself (even on constitutions in the case of UPC — another attempt to override the law and introduce European software patents) won’t be easily forgotten; SUEPO has meanwhile (on Saturday, link at the bottom in German) reminded people that Benoît Battistelli and António Campinos have driven away the EPO’s most valuable workers or moral compass



  5. IRC Proceedings: Saturday, July 31, 2021

    IRC logs for Saturday, July 31, 2021



  6. [Meme] When it Comes to Server Share, Microsoft Azure is Minuscule (But Faking It)

    Don't believe the lies told by Microsoft's charlatans and frauds; Azure has been a total failure and that's why there are layoffs as well



  7. [Meme] Mozilla Has Turned From Technical to Marketing

    Way back, long before Mozilla and Firefox got hijacked by politics (turning Mozilla into a VPN reseller that lies about its stance on privacy), geeks were driving the company, not corporate lawyers and spying/marketing people



  8. Over 1,500 (Known/Unorphaned) Gemini Capsules and Over 160,000 Page Requests in gemini.techrights.org During July

    Techrights is expanding at gemini:// (Gemini space) and over 1,500 capsules are reported to have been found (less than 4 months ago it was about 1,000)



  9. Links 31/7/2021: Kernel Additions and Linux Mint 20.3 Release Date

    Links for the day



  10. Microsoft Azure Stagnating

    Reprinted with permission from Mitchel Lewis, former Microsoft employee



  11. For 17 Days (and Counting) António Campinos Has Failed to Respond to Call for Compliance With the Law

    Team Campinos has been so arrogant and so evasive that there’s no indication (yet) that it will follow court orders (Willy ‘Guillaume’ Minnoye openly bragged about ignoring court orders and he's still cheering for the EPO's abuses); therefore, staff of the EPO takes collective action



  12. Raw: Elodie Bergot Breaking the Law by Threatening Against the Exercise of Fundamental Rights

    Over the years we saw a number of rude letters from Elodie Bergot, the grossly under-qualified spouse of a friend of Vichyite Benoît Battistelli; most of these we never published (we already have these and can always publish if the need arises), but those paranoid and insecure “Mafia”-like ‘cabal’ need to be exposed for the mobsters they are; for nearly a decade they’ve illegally bullied EPO staff in clear violation of the law (and for over 3 years António Campinos has kept those bullies on board); why does Europe do nothing and why is it never holding high-profile abusers accountable (only low-level facilitators)? Is it because the EU too is being infiltrated by them?



  13. Linspire Should Be Avoided in 2021 Just Like It Was Avoided 14 Years Ago

    The brand "Linspire" was brought back, but the agenda seems to be more or less the same, namely pushing proprietary software and serving Microsoft's commercial agenda (in 'Linux' clothing)



  14. The Death of Freenode Would Be Freenode's Own Fault

    Freenode is going dark and now it’s asking people to create accounts at IRC.com (just to get back into the network that they may have already occupied for decades) as if Freenode owns “IRC” as a whole



  15. Links 31/7/2021: KDE Progress and Activision Catastrophe

    Links for the day



  16. IRC Proceedings: Friday, July 30, 2021

    IRC logs for Friday, July 30, 2021



  17. The Smartest Meter of All

    Yesterday a lady came over to take our power readings (electric/gas meter); secure these people's jobs as they help protect people's privacy (dignity) at home



  18. [Meme] A Web of False Dichotomies

    A reminder that Techrights is fully available (all blog posts and wiki pages) in gemini://



  19. Freenode Shrinks by Another Quarter and Gemini Continues to Grow (For Techrights at Least)

    Freenode continues to perish faster than we've imagined; it's a good thing that we've had contingencies set up; regarding the monopolised and increasingly centralised Web, we're still making baby steps towards weaning ourselves off it



  20. Links 31/7/2021: Wine 6.14 and Chrome 93 Beta

    Links for the day



  21. European Media Does Not Care About Europe's Second-Largest Institution Crushing Basic Laws and Fundamental Rights

    New video about the latest publication from SUEPO (the EPO’s staff union); it was published yesterday, seeing that the “Mafia” (what EPO staff actually calls the management!) hasn’t done anything to comply with a wide-ranging set of court rulings from ILO-AT; why has the media said nothing about this and what does that say about today’s media? The material is all in the public domain, in widely understood languages, and SUEPO spoke about it more than 3 weeks ago.



  22. Links 30/7/2021: Distro Comparisons and Tootle Introduced

    Links for the day



  23. [Meme] Enforcing ILO-AT Rulings...

    We’re still waiting for a statement — any statement (direct or indirect) — from EPO management, seeing that almost a month has passed



  24. 'Open Source' as a Failed Initiative

    A closer look at the dire state of the Open Source Initiative, or OSI, which no longer protects Open Source (let alone software freedom) but instead helps openwashing, Microsoft entrapment, and a coup against the FSF



  25. [Meme] Rowan and António Sittin' on a Tree...

    How much longer can Team Campinos keep issuing tons of noisy and self-congratulatory puff pieces to (perhaps) distract from the elephant in the 10th floor of the Isar building (EPO HQ)? Staff won't wait for eternity.



  26. IRC Proceedings: Thursday, July 29, 2021

    IRC logs for Thursday, July 29, 2021



  27. Half the People in This Letter Are IBM Employees

    IBM seems to be continuing its war on the FSF because IBM wants to own everything (CentOS being ‘canned’ was just part of the plan)



  28. The OSI Song

    The sad demise of OSI, which has become little but a front group of proprietary software companies in pursuit of openwashing services (and outsourcing to proprietary disservices looking to eradicate copyleft)



  29. [Meme] OSI is Doing Just Fine

    So what if OSI is run by someone who raised money from Microsoft (to sell Microsoft a keynote slot in a copyleft event — the thing that Microsoft attacks through GitHub!) while funnelling the OSI's funds to a serial GPL violator?



  30. The OSI's Defunct Elections (Privacy Breach), Conflict of Interest (Nicholson), and Other Lingering Problems

    The above, together with an email from the OSI below, serves to show they’re re-running a bad election and — yet worse! — there appears to be a conflict of interest implicating the OSI’s sole member of staff!


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts