11.10.09

Gemini version available ♊︎

Microsoft Lies About Security

Posted in Free/Libre Software, FUD, Microsoft, Security, Windows at 8:56 am by Dr. Roy Schestowitz

Guerra al capitol

Summary: Security propaganda from Microsoft tackled yet again in light of this week’s security FUD against Free software

AS WE showed two years ago, Microsoft knowingly hides security problems in its software and sometimes fixes these problems without reporting it to the public. It can be very frequent a routine. This way, when outsiders compare the number of security problems across different products/vendors, they merely compare apples and oranges (Red Hat and Firefox are popular victims of such disinformation). Microsoft is cheating.

Earlier this week Slashdot revealed that Microsoft’s attitude when it comes to security of its on-line services is more or less the same. To make matters worse, Microsoft is trying to gag those who know the truth. From Slashdot’s summary:

Microsoft Tries To Censor Bing Vulnerability

Microsoft’s bing search engine has a vulnerability with its cash-back promotion, which impacts both merchants and customers. In traditional Microsoft fashion, the company has responded to the author of the breaking bing cashback expoit with a cease & desist letter, rather than by fixing the underlying security problem.

Here is the original post.

The purpose of my post was to show an implementation problem, not to encourage defrauding Microsoft. I am surprised they would go through this much trouble to make me take down information that is obvious to anyone reading their documentation. I don’t like dealing with lawyers, so I’ve decided to comply with their request. The post is gone. I will still write a “non-technical” post on all the problems I see with Bing Cashback in the next few days.

The reason why hundreds of millions of Windows PCs are zombies is not just because of negligent users; it’s also because of a company that puts its image and its profits before the safety of computer users. It would shamelessly lie to the public as long as its shareholders’ interests are obeyed. Suffice to say, Free software does not have the same inherent deficiency which is a conflict of interests (honesty versus selfishness). Apache is a good example of this.

According to The Register, botmasters have found new ways of sending instructions to Windows zombies. It’s not the fault of Google, which merely stores arbitrary strings of texts like many other services.

Cyber criminals’ love affair with cloud computing just got steamier with the discovery that Google’s AppEngine was tapped to act as the master control channel that feeds commands to large networks of infected computers.

Sadly enough, we are all left at a dangerous state where cyberwar is said to be imminent, with hordes of Windows zombies recruited to such a task.

CBS News reports that cyber war is a reality that, according to cyber experts, the US will have to be prepared for – and soon.

It is worth adding that the US presidency now has the legal power to shut off the Internet and physical bombing of botmasters is one of the proposed strategies shall disaster strike.

“Security — including national security — must never be put in proprietary hands.”What does Microsoft do about this? It serves the interests of shareholders, which means pretending that Windows (and other Microsoft products) is secure, even by fabrication and outright lies. Security — including national security — must never be put in proprietary hands. It is a recipe for disaster.

One of our readers, pointing to this old gem about password encryption, remarks: “It’s pathetic to see how much Gates has been able to hold back computing. His current antics are not new. However, now his antics involve much more outsourced marketing and tremendous investment in lobbying firms.

Related posts:

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

8 Comments

  1. Yuhong Bao said,

    November 10, 2009 at 5:20 pm

    Gravatar

    “It’s not the fault of Google, which merely stores arbitrary strings of texts like many other services.”
    And it is not the fault of Microsoft either, who just makes an OS that can run any program, including malware. But if the zombie programs take advantage of things like security vulnerabilities or holes in Windows, that is certainly MS’s fault, and on that here is a quote by Woody:
    From http://www.askwoody.com/2009/autorun-patch-kb-967715-mess/:
    “(Remember, this is the worm that has drawn a $250,000 bounty from Microsoft – and the folks at MS can’t even plug one of its simplest infection vectors.)”

    Roy Schestowitz Reply:

    This worm was the fault of Microsoft; it exploited a massive flaw.

    Yuhong Bao Reply:

    Yep, actually several security flaws in Windows, which are all MS’s fault. And yep, that is what the last quote exactly was about. But to be honest the Linux desktop had it’s share of similarly stupid features as well:
    http://lwn.net/Articles/178409/
    http://lwn.net/Articles/178411/
    http://www.geekzone.co.nz/foobar/6229
    http://www.geekzone.co.nz/foobar/6236
    http://lwn.net/Articles/318755/

    Yuhong Bao Reply:

    More link on this:
    http://lwn.net/Articles/320707/
    http://it.slashdot.org/article.pl?sid=09/02/17/1526244

    Yuhong Bao Reply:

    BTW, on Vista the security flaws are less severe, because Vista has ASLR which prevents one of the flaws from being exploited, and the AutoPlay dialog also got changed in Vista so it is easier to tell that the AutoPlay entry created by the worm is fake. Recent versions of Linux has ASLR too, as well as Mac OS X.

    Roy Schestowitz Reply:

    Don’t forget that Linux usually gets its software (‘alien’ files) from trusted repositories.

    Yuhong Bao Reply:

    Yep, I remember Autopackage aiming to change this, but it kind of failed, I think.

    Roy Schestowitz Reply:

    It’s probably to do with how proprietary software is sold, not distributed. Marketplace/Store paradigm is growing though, especially in phones.

DecorWhat Else is New


  1. IRC Proceedings: Thursday, March 30, 2023

    IRC logs for Thursday, March 30, 2023



  2. Links 31/03/2023: Ubuntu 23.04 Beta, Donald Trump Indicted, and Finland’s NATO Bid Progresses

    Links for the day



  3. Translating the Lies of António Campinos (EPO)

    António Campinos has read a lousy script full of holes and some of the more notorious EPO talking points; we respond below



  4. [Meme] Too Many Fake European Patents? So Start Fake European Courts for Patents.

    António Campinos, who sent EPO money to Belarus, insists that the EPO is doing well; nothing could be further from the truth and EPO corruption is actively threatening the EU (or its legitimacy)



  5. Thomas Magenheim-Hörmann in RedaktionsNetzwerk Deutschland About Declining Quality and Declining Validity of European Patents (for EPO and Illegal Kangaroo Courts)

    Companies are not celebrating the “production line” culture fostered by EPO management, which is neither qualified for the job nor wants to adhere to the law (it's intentionally inflating a bubble)



  6. Links 30/03/2023: HowTos and Political News

    Links for the day



  7. Links 30/03/2023: LibreOffice 7.5.2 and Linux 6.2.9

    Links for the day



  8. Links 30/03/2023: WordPress 6.2 “Dolphy” and OpenMandriva ROME 23.03

    Links for the day



  9. Sirius is Britain’s Most Respected and Best Established Open Source Business, According to Sirius Itself, So Why Defraud the Staff?

    Following today's part about the crimes of Sirius ‘Open Source’ another video seemed to be well overdue (those installments used to be daily); the video above explains to relevance to Techrights and how workers feel about being cheated by a company that presents itself as “Open Source” even to some of the highest and most prestigious public institutions in the UK



  10. IRC Proceedings: Wednesday, March 29, 2023

    IRC logs for Wednesday, March 29, 2023



  11. [Meme] Waiting for Standard Life to Deal With Pension Fraud

    The crimes of Sirius ‘Open Source’ were concealed with the authoritative name of Standard Life, combined with official papers from Standard Life itself; why does Standard Life drag its heels when questioned about this matter since the start of this year?



  12. Former Staff of Sirius Open Source Responds to Revelations About the Company's Crimes

    Crimes committed by the company that I left months ago are coming to light; today we share some reactions from other former staff (without naming anybody)



  13. Among Users in the World's Largest Population, Microsoft is the 1%

    A sobering look at India shows that Microsoft lost control of the country (Windows slipped to 16% market share while GNU/Linux grew a lot; Bing is minuscule; Edge fell to 1.01% and now approaches “decimal point” territories)



  14. In One City Alone Microsoft Fired Almost 3,000 Workers This Year (We're Still in March)

    You can tell a company isn’t doing well when amid mass layoffs it pays endless money to the media — not to actual workers — in order for this media to go crazy over buzzwords, chaffbots, and other vapourware (as if the company is a market leader and has a future for shareholders to look forward to, even if claims are exaggerated and there’s no business model)



  15. Links 29/03/2023: InfluxDB FDW 2.0.0 and Erosion of Human Rights

    Links for the day



  16. Links 29/03/2023: Parted 3.5.28 and Blender 3.5

    Links for the day



  17. Links 29/03/2023: New Finnix and EasyOS Kirkstone 5.2

    Links for the day



  18. IRC Proceedings: Tuesday, March 28, 2023

    IRC logs for Tuesday, March 28, 2023



  19. [Meme] Fraud Seems Standard to Standard Life

    Sirius ‘Open Source’ has embezzled and defrauded staff; now it is being protected (delaying and stonewalling tactics) by those who helped facilitate the robbery



  20. 3 Months to Progress Pension Fraud Investigations in the United Kingdom

    Based on our experiences and findings, one simply cannot rely on pension providers to take fraud seriously (we’ve been working as a group on this); all they want is the money and risk does not seem to bother them, even when there’s an actual crime associated with pension-related activities



  21. 36,000 Soon

    Techrights is still growing; in WordPress alone (not the entire site) we’re fast approaching 36,000 posts; in Gemini it’s almost 45,500 pages and our IRC community turns 15 soon



  22. Contrary to What Bribed (by Microsoft) Media Keeps Saying, Bing is in a Freefall and Bing Staff is Being Laid Off (No, Chatbots Are Not Search and Do Not Substitute Web Pages!)

    Chatbots/chaffbot media noise (chaff) needs to be disregarded; Microsoft has no solid search strategy, just lots and lots of layoffs that never end this year (Microsoft distracts shareholders with chaffbot hype/vapourware each time a wave of layoffs starts, giving financial incentives for publishers to not even mention these; right now it’s GitHub again, with NDAs signed to hide that it is happening)



  23. Full RMS Talk ('A Tour of Malicious Software') Uploaded 10 Hours Ago

    The talk is entitled "A tour of malicious software, with a typical cell phone as example." Richard Stallman is speaking about the free software movement and your freedom. His speech is nontechnical. The talk was given on March 17, 2023 in Somerville, MA.



  24. Links 28/03/2023: KPhotoAlbum 5.10.0 and QSoas 3.2

    Links for the day



  25. The Rumours Were Right: Many More Microsoft Layoffs This Week, Another Round of GitHub Layoffs

    Another round of GitHub layoffs (not the first [1, 2]; won’t be the last) and many more Microsoft layoffs; this isn’t related to the numbers disclosed by Microsoft back in January, but Microsoft uses or misuses NDAs to hide what’s truly going on



  26. All of Microsoft's Strategic Areas Have Layoffs This Year

    Microsoft’s supposedly strategic/future areas — gaming (trying to debt-load or offload debt to other companies), so-called ‘security’, “clown computing” (Azure), and “Hey Hi” (chaffbots etc.) — have all had layoffs this year; it’s clear that the company is having a serious existential crisis in spite of Trump’s and Biden’s bailouts (a wave of layoffs every month this year) and is just bluffing/stuffing the media with chaffbots cruft (puff pieces/misinformation) to keep shareholders distracted, asking them for patience and faking demand for the chaffbots (whilst laying off Bing staff, too)



  27. Links 28/03/2023: Pitivi 2023.03 is Out, Yet More Microsoft Layoffs (Now in Israel)

    Links for the day



  28. IRC Proceedings: Monday, March 27, 2023

    IRC logs for Monday, March 27, 2023



  29. Links 27/03/2023: GnuCash 5.0 and Ubuntu 20.04 LTS on Phones

    Links for the day



  30. Links 27/03/2023: Twitter Source Code Published (But Not Intentionally)

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts