11.10.09

Gemini version available ♊︎

Microsoft Lies About Security

Posted in Free/Libre Software, FUD, Microsoft, Security, Windows at 8:56 am by Dr. Roy Schestowitz

Guerra al capitol

Summary: Security propaganda from Microsoft tackled yet again in light of this week’s security FUD against Free software

AS WE showed two years ago, Microsoft knowingly hides security problems in its software and sometimes fixes these problems without reporting it to the public. It can be very frequent a routine. This way, when outsiders compare the number of security problems across different products/vendors, they merely compare apples and oranges (Red Hat and Firefox are popular victims of such disinformation). Microsoft is cheating.

Earlier this week Slashdot revealed that Microsoft’s attitude when it comes to security of its on-line services is more or less the same. To make matters worse, Microsoft is trying to gag those who know the truth. From Slashdot’s summary:

Microsoft Tries To Censor Bing Vulnerability

Microsoft’s bing search engine has a vulnerability with its cash-back promotion, which impacts both merchants and customers. In traditional Microsoft fashion, the company has responded to the author of the breaking bing cashback expoit with a cease & desist letter, rather than by fixing the underlying security problem.

Here is the original post.

The purpose of my post was to show an implementation problem, not to encourage defrauding Microsoft. I am surprised they would go through this much trouble to make me take down information that is obvious to anyone reading their documentation. I don’t like dealing with lawyers, so I’ve decided to comply with their request. The post is gone. I will still write a “non-technical” post on all the problems I see with Bing Cashback in the next few days.

The reason why hundreds of millions of Windows PCs are zombies is not just because of negligent users; it’s also because of a company that puts its image and its profits before the safety of computer users. It would shamelessly lie to the public as long as its shareholders’ interests are obeyed. Suffice to say, Free software does not have the same inherent deficiency which is a conflict of interests (honesty versus selfishness). Apache is a good example of this.

According to The Register, botmasters have found new ways of sending instructions to Windows zombies. It’s not the fault of Google, which merely stores arbitrary strings of texts like many other services.

Cyber criminals’ love affair with cloud computing just got steamier with the discovery that Google’s AppEngine was tapped to act as the master control channel that feeds commands to large networks of infected computers.

Sadly enough, we are all left at a dangerous state where cyberwar is said to be imminent, with hordes of Windows zombies recruited to such a task.

CBS News reports that cyber war is a reality that, according to cyber experts, the US will have to be prepared for – and soon.

It is worth adding that the US presidency now has the legal power to shut off the Internet and physical bombing of botmasters is one of the proposed strategies shall disaster strike.

“Security — including national security — must never be put in proprietary hands.”What does Microsoft do about this? It serves the interests of shareholders, which means pretending that Windows (and other Microsoft products) is secure, even by fabrication and outright lies. Security — including national security — must never be put in proprietary hands. It is a recipe for disaster.

One of our readers, pointing to this old gem about password encryption, remarks: “It’s pathetic to see how much Gates has been able to hold back computing. His current antics are not new. However, now his antics involve much more outsourced marketing and tremendous investment in lobbying firms.

Related posts:

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

8 Comments

  1. Yuhong Bao said,

    November 10, 2009 at 5:20 pm

    Gravatar

    “It’s not the fault of Google, which merely stores arbitrary strings of texts like many other services.”
    And it is not the fault of Microsoft either, who just makes an OS that can run any program, including malware. But if the zombie programs take advantage of things like security vulnerabilities or holes in Windows, that is certainly MS’s fault, and on that here is a quote by Woody:
    From http://www.askwoody.com/2009/autorun-patch-kb-967715-mess/:
    “(Remember, this is the worm that has drawn a $250,000 bounty from Microsoft – and the folks at MS can’t even plug one of its simplest infection vectors.)”

    Roy Schestowitz Reply:

    This worm was the fault of Microsoft; it exploited a massive flaw.

    Yuhong Bao Reply:

    Yep, actually several security flaws in Windows, which are all MS’s fault. And yep, that is what the last quote exactly was about. But to be honest the Linux desktop had it’s share of similarly stupid features as well:
    http://lwn.net/Articles/178409/
    http://lwn.net/Articles/178411/
    http://www.geekzone.co.nz/foobar/6229
    http://www.geekzone.co.nz/foobar/6236
    http://lwn.net/Articles/318755/

    Yuhong Bao Reply:

    More link on this:
    http://lwn.net/Articles/320707/
    http://it.slashdot.org/article.pl?sid=09/02/17/1526244

    Yuhong Bao Reply:

    BTW, on Vista the security flaws are less severe, because Vista has ASLR which prevents one of the flaws from being exploited, and the AutoPlay dialog also got changed in Vista so it is easier to tell that the AutoPlay entry created by the worm is fake. Recent versions of Linux has ASLR too, as well as Mac OS X.

    Roy Schestowitz Reply:

    Don’t forget that Linux usually gets its software (‘alien’ files) from trusted repositories.

    Yuhong Bao Reply:

    Yep, I remember Autopackage aiming to change this, but it kind of failed, I think.

    Roy Schestowitz Reply:

    It’s probably to do with how proprietary software is sold, not distributed. Marketplace/Store paradigm is growing though, especially in phones.

DecorWhat Else is New


  1. [Meme] [Teaser] Oligarchs-Controlled Patent Offices With Media Connections That Cover Up Corruption

    As we shall see later today, the ‘underworld’ in Bulgaria played a role or pulled the strings of politically-appointed administrators who guarded Benoît Battistelli‘s liberticidal regime at the EPO



  2. IRC Proceedings: Sunday, October 24, 2021

    IRC logs for Sunday, October 24, 2021



  3. Links 25/10/2021: EasyOS 3.1 and Bareflank 3.0

    Links for the day



  4. The Demolition of the EPO Was Made Possible With Assistance From Countries That Barely Have European Patents

    The legal basis of today's EPO has been crushed; a lot of this was made possible by countries with barely any stakes in the outcome



  5. The EPO’s Overseer/Overseen Collusion — Part XXII: The Balkan League - North Macedonia and Albania

    We continue to look at Benoît Battistelli‘s enablers at the EPO



  6. Links 24/10/2021: GPS Daemon (GPSD) Bug and Lots of Openwashing

    Links for the day



  7. Links 24/10/2021: XWayland 21.1.3 and Ubuntu Linux 22.04 LTS Daily Build

    Links for the day



  8. IRC Proceedings: Saturday, October 23, 2021

    IRC logs for Saturday, October 23, 2021



  9. Links 24/10/2021: Ceph Boss Sage Weil Resigns and Many GPL Enforcement Stories

    Links for the day



  10. GAFAM-Funded NPR Reports That Facebook Let Millions of People Like Trump Flout the So-called Rules. Not Just “a Few”.

    Guest post by Ryan, reprinted with permission



  11. Some Memes About What Croatia Means to the European Patent Office

    Before we proceed to other countries in the region, let’s not forget or let’s immortalise the role played by Croatia in the EPO (memes are memorable)



  12. Gangster Culture in the EPO

    The EPO‘s Administrative Council was gamed by a gangster from Croatia; today we start the segment of the series which deals with the Balkan region



  13. The EPO’s Overseer/Overseen Collusion — Part XXI: The Balkan League – The Doyen and His “Protégée”

    The EPO‘s circle of corruption in the Balkan region will be the focus of today’s (and upcoming) coverage, showing some of the controversial enablers of Benoît Battistelli and António Campinos, two deeply corrupt French officials who rapidly drive the Office into the ground for personal gain (at Europe’s expense!)



  14. Links 23/10/2021: FreeBSD 12.3 Beta, Wine 6.20, and NuTyX 21.10.0

    Links for the day



  15. IRC Proceedings: Friday, October 22, 2021

    IRC logs for Friday, October 22, 2021



  16. [Meme] [Teaser] Crime Express

    The series about Battistelli's "Strike Regulations" (20 parts thus far) culminates as the next station is the Balkan region



  17. Links 23/10/2021: Star Labs/StarLite, Ventoy 1.0.56

    Links for the day



  18. Gemini on Sourcehut and Further Expansion of Gemini Space

    Gemini protocol is becoming a widely adopted de facto standard for many who want to de-clutter the Internet by moving away from the World Wide Web and HTML (nowadays plagued by JavaScript, CSS, and many bloated frameworks that spy)



  19. Unlawful Regimes Even Hungary and Poland Would Envy

    There’s plenty of news reports about Polish and Hungarian heads of states violating human rights, but never can one find criticism of the EPO’s management doing the same (the mainstream avoids this subject altogether); today we examine how that area of Europe voted on the illegal "Strike Regulations" of Benoît Battistelli



  20. The EPO’s Overseer/Overseen Collusion — Part XX: The Visegrád Group

    The EPO‘s unlawful “Strike Regulations” (which helped Benoît Battistelli and António Campinos illegally crush or repress EPO staff) were supported by only one among 4 Visegrád delegates



  21. [Meme] IBM Has Paid ZDNet to Troll the Community

    Over the past few weeks ZDNet has constantly published courses with the word "master" in their headlines (we caught several examples; a few are shown above); years ago this was common, also in relation to IBM itself; clearly IBM thinks that the word is racially sensitive and offensive only when it's not IBM using the word and nowadays IBM pays ZDNet — sometimes proxying through the Linux Foundation — to relay this self-contradictory message whose objective is to shame programmers, Free software communities etc. (through guilt they can leverage more power and resort to projection tactics, sometimes outright slander which distracts)



  22. [Meme] ILO Designed to Fail: EPO Presidents Cannot be Held Accountable If ILOAT Takes Almost a Decade to Issue a Simple Ruling

    The recent ILOAT ruling (a trivial no-brainer) inadvertently reminds one of the severe weaknesses of ILOAT; what good is a system of accountability that issues rulings on decisions that are barely relevant anymore (or too late to correct)?



  23. Links 22/10/2021: Trump's AGPL Violations and Chrome 95 Released

    Links for the day



  24. [Meme] How Corporate Monopolies Demonise Critics of Their Technically and Legally Problematic 'Products'

    When the technical substance of some criticism stands (defensible based upon evidence), and is increasingly difficult to refute based on facts, make up some fictional issue — a straw man argument — and then respond to that phony issue based on no facts at all



  25. Links 22/10/2021: Global Encryption Day

    Links for the day



  26. [Meme] Speaking the Same Language

    Language inside the EPO is misleading. Francophones Benoît Battistelli and António Campinos casually misuse the word “social”.



  27. António Campinos Thinks Salary Reductions Months Before He Leaves is “Exceptional Social Gesture”

    Just as Benoît Battistelli had a profound misunderstanding of the concept of “social democracy” his mate seems to completely misunderstand what a “social gesture” is (should have asked his father)



  28. IRC Proceedings: Thursday, October 21, 2021

    IRC logs for Thursday, October 21, 2021



  29. Links 21/10/2021: MX Linux 21 and Git Contributors’ Summit in a Nutshell

    Links for the day



  30. [Meme] [Teaser] Miguel de Icaza on CEO of Microsoft GitHub

    Our ongoing series, which is very long, will shed much-needed light on GitHub and its goals (the dark side is a lot darker than people care to realise)


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts