01.17.10

Gemini version available ♊︎

Microsoft Takes Responsibility for Internet Explorer Chaos, Conficker Damage Carries on

Posted in Europe, Google, Microsoft, Security, Windows at 8:21 am by Dr. Roy Schestowitz

Smart card

Summary: Just as Microsoft pretends that the attacks on Google are no big deal it turns out that Microsoft’s Internet Explorer is the sole culprit

“Adobe Flaw Wasn’t Part of Attack on Google,” says this latest news report from IDG and Microsoft is almost accepting liability by admitting that Internet Explorer is the culprit. “Cyberattacks are an unfortunate way of life,” said Microsoft CEO Steve Ballmer to CNBC regarding these attacks after his own incompetence caused these issues. This sums up a discussion (and at times heated argument) that we had in previous posts on the subject, namely:

  1. Microsoft Flaws — Not Adobe Flaws — Responsible for China’s Attack on Google; Microsoft Takes China’s Side, as Usual
  2. Chinese Google ‘Attack’ Involves Microsoft Windows Flaws
  3. Germany’s Office for Information Security Warns Against Microsoft’s Internet Explorer After China Attacks

Germany is paying for Conficker through the nose, so it only makes sense to advise against the use of Internet Explorer (they should go further and recommend GNU/Linux). According to this weekend’s news from IDG, Conficker is still alive and it’s kicking hard:

Conficker Still Striking Online

Russia and Brazil are now the top hotspots for global Internet attack traffic, Net giant Akamai has said in its latest threat report, placing most of the blame on the hardy Conficker worm.

Conficker Worm Hasn’t Gone Away, Akamai Says

Variants of the Conficker worm were still active and spreading during the third quarter, accounting for much of attack traffic on the Internet, according to Akamai Technologies.

“Although mainstream and industry media coverage of the Conficker worm and its variants has dropped significantly since peaking in the second quarter, it is clear from this data that the worm (and its variants) is apparently still quite active, searching out new systems to infect,” Akamai said in its State of the Internet report for the third quarter of 2009, released Thursday.

For those who think that Vista 7 will change anything, we’re appending some links below.

  1. Cybercrime Rises and Vista 7 is Already Open to Hijackers
  2. Vista 7: Broken Apart Before Arrival
  3. Department of Homeland Security ‘Poisoned’ by Microsoft; Vista 7 is Open to Hijackers Again
  4. Vista 7 Security “Cannot be Fixed. It’s a Design Problem.”
  5. Why Vista 7 Could be the Least Secure Operating System Ever
  6. Journalists Suggest Banning Windows, Maybe Suing Microsoft Over DDoS Attacks
  7. Vista 7 Vulnerable to Latest “Critical” Flaws
  8. Vista 7 Seemingly Affected by Several More “Critical” Flaws This Month
  9. Reason #1 to Avoid Vista 7: Insecurity
  10. Vista 7 Left Hijackable Again (Almost a Monthly Recurrence)
Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

13 Comments

  1. your_friend said,

    January 17, 2010 at 4:07 pm

    Gravatar

    [Thanks to Windows] Cyberattacks are an unfortunate [prevalent, debilitating, increasingly unsustainable and successful] way of life. How much will society pay for Windows?

  2. TheTruth said,

    January 17, 2010 at 7:02 pm

    Gravatar

    HAHAH, and google is supposed to be the FOSS/Linux love child, yet they are still hacked, linux and all !!!!! oh dear, poor poor linux.

    oh and what did the chinese steal, IP, I thought you hated IP ROY, you must be in great internal conflict.

    Trying to spin this as a positive for Linux, it’s a hard job but someone has to apply the spin.

    (how’s you job searching going, anyone willing to hite a zealot?).

    I cant wait to email you boss, and inform him about what you spend you’re entire life doing .. But I would not stoop so low, but you would,,, dont you ROY.. :)

    Mikko Reply:

    troll get out!

    your_friend Reply:

    People “hacked” several Gmail accounts, this is something that happens to Windows users every day. They also have their hotmail, yahoo, aol and bank accounts violated because Windows is so easy for criminals to break. The things that make it notable is that Google is accusing the Chinese government of targeting dissidents with malware and that the government has also used broken Windows machines for DDoS attacks against Google and other ISPs. All of these problems revolve around Windows, not GNU/Linux.

    This is a positive development for free software because it shows off some of the downsides of non free software. The US has used the same tactics on a more limited scale. The large scale of the problems in China, their more blatant political use and the involvement of a large and powerful US firm all point to broader coverage of these issues in the western world. As people are exposed both to the weakness of Windows and the results, they will want something better. That will be good for everyone.

    Finally, your talk about Roy’s job prospects are both ugly and poorly veiled threats.

    your_friend Reply:

    Brilliant, blame Google for Microsoft’s security flaws. I have to hand it to you for knowing exactly how Microsoft friendly news sources would spin this issue. I don’t think it’s going to work as governments and everyone else with a clue gives credit where credit is due. I have to hand it to you for being so well connected to Microsoft spin.

  3. TheTruth said,

    January 17, 2010 at 7:22 pm

    Gravatar

    Imagine, if you house was broken into, you call the police, they come around they look at your house, and they see there are no locked on any of the doors and windows and they are left open.

    The police say, yes you were broken into, but it’s you’re own stupid fault for leaving you’re house open. And putting huge adds all over you’re house saying “valuables held in here”.

    What you’re saying is that if you’re house was broken into and the theif used a hammer to break in, then it’s the hammers fault for the break in.

    Just mabey if you have critical data on you’re systems, you lock you’re doors, and make them so strong that a hammer will not break in.

    There is ONE group at fault here, and it’s GOOGLE.

    If you’re stupid enough to keep critical data on insecure systems, (in this case LINUX). that is YOUR fault.

    Sure the criminals have done wrong, but you dont have to make it so easy for them by leaving you’re house unlocked.

    But thats not nearly as interesting a spin as you would like ROY, that means you cannot blame you’re hate child MS for it.

    Google are trying to break into OS’s, applications and cloud, and they cant even protect THEIR OWN data, would you trust them to protect YOUR data.

    So you headline could read, “Man breaks into house, hammer found guilty of break and enter”.

    As usual ROY, you’re the running joker of the FOSS world. nothing more…

    (get a job).

    Mikko Reply:

    why are you here? stupid troll!

  4. Yuhong Bao said,

    January 17, 2010 at 9:03 pm

    Gravatar

    I already explained many of these, why you keep posting the links, particularly bad is “Vista 7 Security “Cannot be Fixed. It’s a Design Problem.””

    Roy Schestowitz Reply:

    Where did you explain this?

    Yuhong Bao Reply:

    Briefly in the comments, and a few times in IRC, in fact I just talked about it today on IRC.

    your_friend Reply:

    People believe that Windows will never be fixed because Windows has never been fixed despite repeated false promisses and lots of technical sounding BS. Roy pointed to an excellent article explaining the major design flaws. Can you point to a technical refutation of the points? Even if you did, it’s not worth anything because people have already broken Windows 7 like every other version of Windows.

  5. Yuhong Bao said,

    January 17, 2010 at 9:04 pm

    Gravatar

    In fact, one of the Conflicker’s exploit vectors did not affect Vista.

    your_friend Reply:

    The Microsoft spinners are busy defending microsoft business practices and Vista. Less spun sources recognize that all versions of Windows and all versions of IE are at fault. It looks like the latest round of security failure is being used by Microsoft to force upgrades. It is too bad for them that people are starting to realize that GNU/Linux is the practical upgrade path. Windows will never be secure.

    Roy has done a nice job of keeping up with this story:

    Germany Urges people to dump IE. It is too bad they did not go the Munich route.
    Microsoft blames Adobe and ignores Communist China’s repulsive human rights abuses. More disgusting was their spinner’s attempt to claim Google was exploiting other people’s revulsion for business advantage.
    China uses Windows botnets to harass dissidents, DDoS Google and other companies.
    Reality Calling

DecorWhat Else is New


  1. Links 16/05/2022: FreeBSD 13.1 and Inkscape 1.2 Released

    Links for the day



  2. Archiving Latest Posts in Geminispace (Like a Dated Web Directory But for Gemini)

    Earlier today we saw several more people crossing over from the World Wide Web to Gemini; we're trying to make a decent aggregator and archive for the rapidly-expanding Geminispace, which will soon have 2,500 capsules that are known to Lupa alone



  3. Microsoft Vidal Does Not Want to Listen (USPTO is Just for Megacorporations)

    Microsoft Vidal knows her real bosses. They’re international corporations (multinationals like Microsoft), not American people.



  4. Links 16/05/2022: China Advances on GNU/Linux and Maui 2.1.2 is Out

    Links for the day



  5. Jim Zemlin: Chief Revenue Officer in 'Linux' Seat-Selling Foundation

    Board seats in the Linux Foundation are basically a product on sale, based internal documents



  6. Reminder: Linux Foundation's Last IRS Filing is Very Old (Same Year the CFO Left)

    People really need to ask the Linux Foundation, directly, why its filings are years behind; this seems like a sensitive subject



  7. Linux Foundation Does Not Speak for GNU/Linux Users

    There's a serious problem in the "Linux" world as the so-called 'Linux' Foundation claims to speak for us (the GNU/Linux community) while in fact speaking against us (on the payroll of those looking to extinguish us)



  8. IBM's Lennart Poettering on Breaking Software for Pseudo Novelty

    Recently-uploaded ELCE 2011 clip shows a panel with Linus Torvalds, Alan Cox, Thomas Gleixner, Paul McKenney, and Lennart Poettering (relevant to novelty or perceived novelty that mostly degrades the experience of longtime users, e.g. Wayland and systemd)



  9. IRC Proceedings: Sunday, May 15, 2022

    IRC logs for Sunday, May 15, 2022



  10. Links 15/05/2022: Linux 5.18 RC7 and Calls for More Mass Surveillance

    Links for the day



  11. Audio: Mark Shuttleworth Marketed to Young Males, With Sexy Pictures

    The Web is rotting away, old links become broken links within months or years, so I’ve decided to encode a 3-minute segment of the whole as Ogg



  12. What a Difference Half a Decade Makes (When Linux Foundation is 'Having Fun')

    Media shaming campaigns may have taken their toll on the founder of Linux, who is now bossed by someone who rejects Linux and is married to a Microsoft booster. Like Richard Stallman under FSF guidance (and conditions for return, mostly for fear of further media assaults and attack dogs), he has become a more publicity-shy and private person. The Linux Foundation has in effect reduced the founder of what it’s called after (Linux) into a weekly release manager and mascot, whose brand it is gradually diluting/cheapening.



  13. Links 15/05/2022: GNU libiconv 1.17

    Links for the day



  14. [Meme] Unitary Patent and Unified Patent Court (UPC) Cannot Be Reconciled With the Law

    Unitary Patent and Unified Patent Court (UPC)? Impossible. But Team UPC counts on an endless torrent of fake news managing to convince you (and more importantly politicians) otherwise.



  15. Even Team Battistelli is Sometimes Admitting -- Out in Public! -- That Unified Patent Court (UPC) is Neither Legal Nor Desirable

    Daniel X. Thomas and other people who are “too old to punish” (consequences to their career profoundly minimised owing to seniority) are among those who push back against the Unitary Patent or Unified Patent Court (UPC); any sane person — not a career-climbing litigation zealot — can identify the pertinent facts and realise that what’s going on here is an injustice of unprecedented proportions in the patent discipline



  16. [Meme] Common Sense at EPO

    The European examiners who deal with patents prefer a system that works for science, for Europe, not for foreign megacorporations that amass millions of low-quality patents and weaponise these to discourage competition



  17. Patent Granting at the EPO Has Collapsed by 24% Owing to Much-Needed Industrial Action

    Seeing that the EPO’s management routinely violates the law and even the very legal basis of the EPO’s existence (it is a monopoly in Europe; no body has the authority to compete against it), the EPO’s examiners have embarked on a ‘Work-to-Rule’ campaign — working in compliance with the rules as defined 49 years ago and revised over the decades — and the European Patent Convention (EPC) takes priority over unlawful demands from middle and upper management; this is proving highly effective so far and it will carry on until demands are met, i.e. until the law is obeyed and staff is treated with respect/dignity



  18. [Meme] Milan is a Suburb in London

    As long as Italy is not the UK and London means London “proper” (not the French town called London) the UPCA is invalid and no matter how much Team UPC (and its puppets in EPO management) may plead, this whole system is bound to implode



  19. The Latest Propaganda Tactics of Team UPC: Pretending Unified Patent Court Already Exists and Unitary Patents Are Default When If Fact None Even Exists

    8 years ago Benoît Battistelli said that the UPC was imminent; now, after 4 years of António Campinos, it’s still not here and Team UPC speculators say it won’t happen this year, either; just like the EPO constantly lies (both to the public and to its very own staff) Team UPC continues to lie to itself (self-delusion) and to us; both also routinely break the law, engage in deliberate violations of longstanding conventions, and scrap constitutions, which in turn becomes a breaking point for the EU’s credibility and the legal profession



  20. Links 15/05/2022: More Azure Shutdowns and Windows Security Blunders Aplenty

    Links for the day



  21. IRC Proceedings: Saturday, May 14, 2022

    IRC logs for Saturday, May 14, 2022



  22. Links 15/05/2022: Pika Backup 0.4

    Links for the day



  23. Changes in the Site and the Capsule

    A 10-minute explanation of what we've been up to lately and what's changing; hopefully I'll have a lot more free time in months to come and we'll be able to produce about a dozen posts per day



  24. Links 14/05/2022: Alt Linux 10.0 Released

    Links for the day



  25. Links 14/05/2022: Builder GTK 4 Porting and Raspberry Pi Matrix Dashboard

    Links for the day



  26. Elon Musk is Right About Twitter Faking Its Importance and Using Doctored, Manipulated 'Stats' (or Bots) to Boost Valuation Based on Lies

    Today’s empirical proof that Twitter is totally faking its relevance and reach/influence, based on “Analytics” of my long-inactive account; the SEC will once again — quite likely as usual — let Musk get away with it, killing a company for personal gain as a temporary shareholder who amassed a ton of free publicity (he paid nothing at all and sent the company into a death spiral, pretty much in the same way Microsoft and Icahn did Yahoo! or Microsoft and Elop did Nokia)



  27. Who Brings Home the Bacon (Revenue), Sheela or James (Jim)?

    Sheela (yes, wife of the nontechnical Linux Foundation chief, who equates Microsoft critics with people who kick puppies) has a history working with several companies that are closely connected to Microsoft (not just Bakkt); can that be reconciled as not a conflict of interest?



  28. The 'Original' Linus Torvalds on Self-Hosting

    The fast-aging founder of Linux spoke as shown above (2005); so much has changed since then…



  29. IRC Proceedings: Friday, May 13, 2022

    IRC logs for Friday, May 13, 2022



  30. Links 13/05/2022: NetworkManager 1.38 and Pseudo-Security

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts