04.21.10

Microsoft’s Browser Ballot is Broken Again and Internet Explorer 8 is Critically Flawed

Posted in Antitrust, Europe, Microsoft, Security, Windows at 2:56 am by Dr. Roy Schestowitz

Voter
Poor man’s ballot?

Summary: Microsoft makes it difficult to install a Web browser other than its already-installed and already-flawed Internet Explorer 8

THE BROWSER BALLOT has already been through many changes since it was first introduced. Microsoft kept cheating or simply left some self-serving bugs in tact. We wrote about the subject in:

  1. Browser Ballot Critique
  2. Microsoft’s Fake “Choice” Campaign is Back
  3. Microsoft Claimed to be Cheating in Web Browsers Ballot
  4. Microsoft Loses Impact in the Web Despite Unfair Ballot Placements
  5. Given Choice, Customers Reject Microsoft
  6. Microsoft is Still Cheating in Browser Ballot — Claim

Rob Weir from IBM shows that Microsoft’s ballot, which it was forced to implement in order to avoid fines (a lot of the press still gets it wrong by characterising it as Microsoft fairness), is simply broken. See the screenshots in Weir’s blog as they are self explanatory.

A few weeks ago I wrote about Microsoft’s “browser choice” ballot page in Europe, which in its debut used a flawed algorithm when attempting to perform a “random shuffle” of the browser choices, a feature specifically called for in their agreement with the EU. This bug was fixed soon after it was reported. But I recently received an email from a correspondent going by the name “Skoon” who reported a more serious bug, but one that is seen only in the Polish-language translation of the ballot choice screen.

In other news, there is a major new flaw in Microsoft’s Internet Explorer 8. [via]

The cross-site scripting filter that ships with Microsoft’s Internet Explorer 8 browser can be abused by attackers to launch cross-site scripting attacks on websites and web pages that would otherwise be immune to this threat.

According to a presentation at this year’s Black Hat Europe conference, the issue introduces security problems at several high-profile websites, including Microsoft’s own Bing.com (screenshot), Google.com, Wikipedia.org, Twitter.com (screenshot) and just about any site that lets IE 8 users create profiles.

Yes, Microsoft’s browser is still lagging when it comes to security due to negligence and incompetence [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12]. But it’s not entirely surprising that while 4 governments encouraged their citizens to abandon Internet Explorer this year, the MSBBC continues to produce Microsoft adverts, including the many Internet Explorer endorsements that we find in the MSBBC [1, 2, 3, 4, 5, 6] on a regular basis (and occasionally report those for scrutiny). Our reader ThistleWeb has more to say about the MSBBC’s latest Infomercial:

I saw this promo piece in the BBC about the launch of Microsoft’s new Fix-it service and a few things spring to mind. The first is that Microsoft have a long track record of causing more problems than they fix when applying updates. They set Windows to download and apply all critical updates without user intervention. So when a user goes to shut down their PC they have no idea if they have to hang around for 15 mins so that Windows can apply it’s updates or not. Similarly they have no idea if those updates will cause a problem when they next start up their PC.

The second is that Microsoft have a history of abusing the term “critical” and slipping in programs like the Orwellian titled WGA (Windows Genuine Advantage). This was apparently a feature a large number of their customers were screaming out for and Microsoft being a listening, concerned company felt they had no choice but to provide; if you believe Micorosoft’s PR about it. WGA checks regularly if the copy of Windows it’s running on is licensed or unlicensed. If it deems that install of Windows to be unlicensed it causes no end of hassle for the user by disabling services, rebooting, nagware messages about “please contact Microsoft to buy a Windows product key”. It’s no advantage to customers, only to Microsoft. Yet this has been defined by Microsoft as a “critical” update. To me “critical” means “your PC is at immediate risk without this update”.

We have written about this before; in fact, Microsoft marks as “critical” anything that’s critical to Microsoft, not to the user. This is probably why one in two Windows PCs is still estimated to be a zombie.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

This post is also available in Gemini over at:

gemini://gemini.techrights.org/2010/04/21/ballot-js-simply-broken/

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 14/5/2021: KDE Plasma 5.22 Beta and GNOME 40 in Gentoo

    Links for the day



  2. Audio: “Unjust Computing Clamps Down” by Richard Stallman

    The FSF has finally uploaded the LibrePlanet talk of Richard Stallman



  3. Links 13/5/2021: KDE Gear 21.04.1 and LibreOffice 7.0.6

    Links for the day



  4. The EPO's War on Justice and Assault on the Law -- Part 4: The President of the Boards of Appeal

    A deeper look into the ‘sausage factory’ that is EPO tribunals certainly helps us understand the inherent bias of many decisions, including a recent decision on European software patents like a controversial simulation patent



  5. Judging the Judges

    Today we shall take a closer look at Carl Josefsson, a person who shall become a figure of interest if he sends EPO courts to the United States in clear violation of the EPC (looking to rubber-stamp an unlawful decision already made before this case even started)



  6. When EU Authorities Tell You to Complain to the EPO Itself About EPO Privacy Violations...

    “Kafkaesque” at the EPO; Kafka could do a whole novel about the flirtations with or affairs of ‘justice’ at the EPO



  7. The Need for Reliable Governance at Freenode

    Why the current and high-profile (albeit somewhat covert) owner of the network, who seems to care about Free software (it has made him very wealthy), should put the whole thing in reliable hands and not attempt to 'monetise' it in any way



  8. IRC Proceedings: Wednesday, May 12, 2021

    IRC logs for Wednesday, May 12, 2021



  9. Andrew Lee of Private Internet Access/London Trust Media Increasingly Owns and Controls Freenode (Updatedx2)

    The details about Freenode ownership and control are explained in a resignation letter urging users to move to another network



  10. [Meme] eBPF is Not Microsoft's, But It's Certainly Googlebombed by Microsoft

    eBPF isn't Microsoft's. But sites that work closely with Microsoft keep mentioning that term as if Microsoft created it and champions it (typical tactics).



  11. Links 13/5/2021: OpenSUSE Leap 15.3 on Finer Hardware, AMI Dabbling in Free Firmware

    Links for the day



  12. The EPO's War on Justice and Assault on the Law -- Part 3: The Current Line-up

    The composition of the Enlarged Board for case no. G 1/21



  13. System76’s First Keyboard Packs in Plenty of Surprises

    Putting the genie back in the bottle is hard, and moreover the corrective post from Joey Sneddon may cause a bit of a 'Streisand Effect'



  14. Links 12/5/2021: HAProxy Data Plane API 2.3 and Mousepad 0.5.5

    Links for the day



  15. IBM is Destroying Red Hat, Squeezing Red Hat's Work for Cash, Laying Off Staff, and Asking Staff to Resign

    Layoffs are not a new thing at IBM (hardly so in the past couple of decades or more), but they're oversensitive about the Red Hat agenda



  16. [Meme] Longing for the Original IP Kat...

    It would be nice to see more posts critical of injustice at the EPO, as we've just noted



  17. The EPO's War on Justice and Assault on the Law -- Part 2: Just Another Pro Forma Rubber-Stamping Exercise?

    Half a decade after Benoît Battistelli ‘kidnapped’ and then defamed judges (it started in 2014) António Campinos has done nothing to restore lawfulness at the EPO, as controversial referral case G 1/21 shows; in fact, they recently approved European software patents after pressure from Campinos himself



  18. Why I'm Using Just a Landline and Recalling My Richard Stallman (RMS) Interview on Working Locally or How the Signal Processor in Phones is a De Facto Back Door

    A longer-than-expected rant about what mobile phones have turned into and a look back at (or listen to) what Richard Stallman (RMS) told me way back in 2013



  19. The European Campinos Award

    The campinos (peasants) of Europe shall gather around for another ceremony championing farmers and nurses... or not



  20. Personal Thoughts About the EPO 'Kangaroo Court' Scandal

    Some unscripted and unedited thoughts about the current EPO scandal/series, which shows intervention such as stacking by António Campinos, continuing the tradition of Benoît Battistelli with his attacks on justice itself



  21. Doing Justice by Reporting Injustice

    Europe's second-largest institution, helped by Europe's largest, is engaging in a massive attack on the very concept of the Rule of Law and incredibly enough the so-called 'press' (or 'media') doesn't report on it



  22. IRC Proceedings: Tuesday, May 11, 2021

    IRC logs for Tuesday, May 11, 2021



  23. Links 12/5/2021: New Audacity and Musescore Owner Named, Microsoft May Lose "JEDI" (Trump's 'Bailout Package')

    Links for the day



  24. The EPO's War on Justice and Assault on the Law -- Part 1: Rumours of a Kangaroo Court at EPOnia

    EPO's President Benoît Battistelli viciously attacked judges and slandered judges; António Campinos adopts a more 'soft power' approach, but nevertheless the impact is the same



  25. Bill Gates Exposed

    While publishers like ZDNet worked hard (on Microsoft's budget) to distract us from real scandals many nefarious things were happening; are we witnessing the fall of Gates?



  26. Welcome to ZDNet's 'Linux' Section...

    ZDNet, which defamed RMS to help distract from Bill Gates scandals, is doing what the sponsors (IBM, Microsoft, Linux Foundation) pay for



  27. Europe's Second-Largest Institution, the EPO, is Partly Based in the United States

    The EPO has outsourced its operations, including its 'courts', to the United States; this seems to be the so-called 'New Normal'



  28. You Look for Linux News and Instead It's Microsoft Noise and Openwashing

    Imagine trying to go about doing your own 'business', only to be confronted by paid-for plugs (sponsored) by the people trying to undercut/undermine your business; welcome to "Linux" in 2021



  29. Links 11/5/2021: Maui 1.2.2 and Tor Releases

    Links for the day



  30. The Next Generation of Free Software (or Software Freedom) Activism, Tackling Newer Problems

    New challenges as labour rights and human rights are further eroded, thanks to 'high' 'tech' with its very 'innovative' 'features'


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts