Bonum Certa Men Certa

Liability for Software When Life is at Stake

A few months ago we used the London Stock Exchange (LSE) as an example of hugely costly Microsoft failures. The stock market crashed in the technical sense and Microsoft, along with those who are informed or responsible, dodged questions about the problem, which recurs once in several months. That was about money, but this time around it's about people's welfare, health, and even lives.



With roughly 320,000,000 zombie PCs out there, how can any sane person put Windows in mission-critical settings like a hospital? Well, that's just what some people do. They apparently learned nothing from a hospital near Microsoft Corporation turning into a massive botnet and it's happening again, this time in London. Yesterday's reports indicate that 3 hospitals were shut down due to Windows virus infections:

BBC: Computer virus affects hospitals

Three London hospitals have been forced to shut down their entire computer systems for at least 24 hours after being hit by a virus.


The Register: PC virus forces three London hospitals into computer shutdown

Three London Hospitals shut down their computer systems on Tuesday in response to a computer virus infection.

[...]

The infection at Barts and London Trust was reportedly caused by the Mytob worm, which contains built-in spyware functionality. Mytob spreads by email and has the ability to plant backdoor software on compromised Windows PCs.


Database leaks are only natural to expect. This means that any person's personal information and health record can make its way into a hot BitTorrent within hours. It's wonderful, is it not?

“This means that any person's personal information and health record can make its way into a hot BitTorrent within hours.”We have already produced and provided some evidence to show that Windows is insecure by design and probably irreparable. Unless it's overhauled radically or reimplemented from scratch, it can never benefit from several decades of UNIX doctrine, mostly trials and errors which made a robust, scientifically-backed model.

With Microsoft whistleblowers crying foul about critical failures and then getting sacked, one can't help wondering how Microsoft perceives liability. Appended below are several fairly recent articles about liability, bad software, dangers in healthcare, and questionable EULAs.

For information about the NHS and Microsoft, see this page (to avoid needlessly repeating old references).

_____ [1] Experts are calling for product liability for software

"Product liability does not apply to software," Gerald Spindler of the Faculty of Law of the University of Göttingen complained. "But what if a whole company comes to a standstill due to faulty software?" he mused.


[2] "Microsoft's 10Q Risk Factors Lists Conceivable Liability for Data Leaks

Improper disclosure of personal data could result in liability and harm our reputation. We store and process significant amounts of personally identifiable information. It is possible that our security controls over personal data, our training of employees and vendors on data security, and other practices we follow may not prevent the improper disclosure of personally identifiable information. Such disclosure could harm our reputation and subject us to liability under laws that protect personal data, resulting in increased costs or loss of revenue. Our software products also enable our customers to store and process personal data. Perceptions that our products do not adequately protect the privacy of personal information could inhibit sales of our products.


[3] Linux guru argues against security liability

Alan Cox, one of the leading Linux kernel developers, has told a House of Lords hearing that neither open- nor closed-source developers should be liable for the security of the code they write.


[4] New banking code cracks down on out-of-date software

The banking industry has re-affirmed a policy that makes online banking customers responsible for losses if they have out of date anti-virus or anti-phishing protection. New Banking Codes for consumers and businesses took effect on Monday.


[5] Secure web browsing through Live Linux distros

Banking isn't the be-all and end-all: there's many other reasons you'd want a secure system, separate from what's on the hard disk, besides Internet banking. Traveller's can't necessarily trust the integrity of a computer in an Internet cafe.


[6] Online banking fraud 'up 8,000%'

The UK has seen an 8,000% increase in fake internet banking scams in the past two years, the government's financial watchdog has warned.

The Financial Services Authority (FSA) told peers it was "very concerned" about the growth in "phishing".


[7] Swedish bank hit by 'biggest ever' online heist

Haxdoor typically installs keyloggers to record keystrokes, and hides itself using a rootkit. The payload of the .ki variant of the Trojan was activated when users attempted to log in to the Nordea online banking site. According to the bank, users were redirected to a false home page, where they entered important log-in information, including log-in numbers.


[8] Microsoft confirms OneCare zaps Outlook, Outlook Express e-mail

Microsoft Corp. has acknowledged that a bug in its Windows Live OneCare security suite has been causing users' e-mail to vanish from Outlook and Outlook Express.


[9] In zombies we trust

A little over a year ago, I wrote an editorial where in back-of-the-envelope style (.pdf) I estimated that perhaps 15-30% of all privately owned computers were no longer under the sole control of their owner. In the intervening months, I received a certain amount of hate mail but in those intervening months Vint Cert guessed 20-40%, Microsoft said 2/3rds, and IDC suggested 3/4ths. It is thus a conservative risk position to assume that any random counterparty stands a fair chance of being already compromised.


[10] Your data or your life

As unlikely and alarmist as this sounds, it could really happen. Intracare is the publisher of a popular practice management system called Dr. Notes. When some doctors balked at a drastic increase in their annual software lease, they were cut off from accessing their own patients? information.

This situation is completely unconscionable. There can be no truly open doctor-patient relationship when an unrelated third party is the de facto owner of and gatekeeper to all related data.


[11] Use Health Vault, Lose Your Rights

Microsoft has announced (NY Times Article) Health Vault. What should have followed here is a review of the service by my actually trying it.

[...]

Heard enough? So had I. I'm absolutely going to pass on Health Vault. In addition to looking like the Microsoft Passport debacle redux, this is a very one-sided contract. They can harm you but you cannot harm them. There is no way for any 3rd party to verify that their privacy and security software works.


[12] Microsoft Healthvault Patient Safety in Question

One topic I've not seen addressed is the safety and effectiveness of the data within HV - and I don't mean "safety" as in the data is secure from unauthorized access or misuse. I mean "safety" as in the utilization of data stored in HV by other applications won't result in an unsatisfactory patient outcome, you know, like death or injury.


[13] HealthVault: No Commitments and a Sleeping Watchdog.

Has Microsoft committed to keeping the promises that it has already made? No, just the opposite. Their privacy policy concludes:“We may occasionally update this privacy statement”

Which means that when the commitments that Microsoft has made regarding HealthVault become inconvenient, they will simply change them.


[14] HealthVault: Failing the seven generations test

...My mother died of ovarian cancer. My grandmother took a drug while my mother was in utero that increase the chances that my mother would get ovarian cancer. Any consideration given to my mothers genetic propensity to get cancer must take into account this environmental influence...My grandmothers medical record will remain relevant for at least five generations...How long should we be keeping our electronic medical records? We should ensure that they are available for the next seven generations...A private, for-profit, corporation is an inappropriate storehouse for records that the next seven generations will need. Corporations do not last long enough. Consider the Dow Jones Industrial Average, of the original 12 companies that made up the index, only one is still listed...

[...]

But this is still Microsoft we are talking about, which all things being equal, is especially bad. Microsoft has a history of abusing standards, and using those abuses to enable and extend its monopolies. In short they have a history of “being evil” in exactly the sort of way that we cannot afford to have impact our healthcare records.


[15] Bill Gates: Vista is so secure it could run life support systems

While on a visit in Romania, where Bill Gates participated in the celebration of 10 years since the Microsoft branch has been running there, and the launch of Vista, Microsoft?s president declared that, with the right ammount of administration, the new Vista could run life support systems in hospitals.


[16] Do Microsoft's EULAs have any real legal basis?

"Microsoft has no special exemption from the sale of goods act." Well, no, probably not - but it might still be selling you "services" instead of "goods". But the real point to remember is that it doesn't matter a jot what the "logical" position is, it is what the courts decide that matters.

As far as I know, no one has tested Microsoft's EULAs in a UK court and, until someone does, Microsoft will just go on assuming that they work. And I don't fancy the risk of taking on Microsoft's expensive lawyers in court myself...


[17] EULA La Vista, Baby

Well, I've taken a good look at the license agreement -- I had insomnia -- and I've discovered some clauses that will freeze your blood, curl your hair, and do your nails.


[18] Vista's EULA Product Activation Worries

Mark Rasch looks at the license agreement for Windows Vista and how its product activation component, which can disable operation of the computer, may be like walking on thin ice.

[...]

"Does the Microsoft EULA adequately tell you what will happen if you don't activate the product or if you can't establish that it is genuine? Well, not exactly. It does tell you that some parts of the product won't work - but it also ambiguously says that the product itself won't work. Moreover, it allows Microsoft, through fine print in a generally unread and non negotiable agreement, to create an opportunity for economic extortion."


[19] MSN Music Debacle Highlights EULA Dangers

MSN Music’s EULA is a case in point. When active, MSN Music's webpage touted that customers could “choose their device and know its going to work”.

But when customers went to purchase songs, they were shown legalese that stated the download service and the content provided were sold without warrantee. In other words, Microsoft doesn't promise you that the service or the music will work, or that you will always have access to music you bought. The flashy advertising promised your music, your way, but the fine print said, our way or the highway.


Comments

Recent Techrights' Posts

Google Has Mass Layoffs (Again), But the Problem is Vastly Larger
started as a rumour about January 2025
Electronic Frontier Foundation Defends Companies That Attack Free Speech Online (Follow the Money)
One might joke that today's EFF has basically adopted the same stance as Donald Trump and has a "warm spot" for BRICS propaganda
 
Links 21/12/2024: EU on Solidarity with Ukraine, Focus on Illegal and Unconstitutional Patent Court in the EU (UPC)
Links for the day
[Meme] Microsofters at the End of David's Leash
Hand holding the leash. Whose?
Deciphering Matt's Take on WordPress, Which is Under Attack From Microsofters-Funded Aggravator
the money sponsoring the legal attacks on WordPress and on Matt is connected very closely to Microsoft
Gemini Links 21/12/2024: Projections, Dead Web ('Webapps' Replacing Pages), and Presentation of Pi-hole
Links for the day
American Samoa One of the Sovereign States Where Windows Has Fallen Below 1% (and Stays Below It)
the latest data plotted in LibreOffice
[Meme] Brian's Ravioli
An article per minute?
Links 21/12/2024: "Hey Hi" (AI) or LLM Bubble Criticised by Mainstream Media, Oligarchs Try to Control and Shut Down US Government
Links for the day
LLM Slop is Ruining the Media and Ruining the Web, Ignoring the Problem or the Principal Culprits (or the Slop Itself) Is Not Enough
We need to encourage calling out the culprits (till they stop this poor conduct or misconduct)
Christmas FUD From Microsoft, Smearing "SSH" When the Real Issue is Microsoft Windows
And since Microsoft's software contains back doors, only a fool would allow any part of SSH on Microsoft's environments, which should be presumed compromised
Paywalls, Bots, Spam, and Spyware is "Future of the Media" According to UK Press Gazette
"managers want more LLM slop"
On BetaNews Latest Technology News: "We are moderately confident this text was [LLM Chatbot] generated"
The future of newsrooms or another site circling down the drain with spam, slop, or both?
"The Real New Year" is Now
Happy solstice
Microsoft OSI Reads Techrights Closely
Microsoft OSI has also fraudulently attempted to censor Techrights several times over the years
"Warning About IBM's Labor Practices"
IBM is not growing and its revenue is just "borrowed" from companies it is buying; a lot of this revenue gets spent paying the interest on considerable debt
[Meme] The Easier Way to Make Money
With patents...
The Curse (to Microsoft) of the Faroe Islands
The common factor there seems to be Apple
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, December 20, 2024
IRC logs for Friday, December 20, 2024
Gemini Links 21/12/2024: Death of Mike Case, Slow and Sudden End of the Web
Links for the day
Links 20/12/2024: Security Patches, Openwashing by Open Source Initiative, Prison Sentence for Bitcoin Charlatan and Fraud
Links for the day
Another Terrible Month for Microsoft in Web Servers
Consistent downward curve
LLM Slop Disguised as Journalism: The Latest Threat to the Web
A lot of it is to do with proprietary GitHub, i.e. Microsoft
Gemini Links 20/12/2024: Regulation and Implementing Graphics
Links for the day
Links 20/12/2024: Windows Breaks Itself, Mass Layoffs Coming to Google Again (Big Wave)
Links for the day
Microsoft: "Upgrade" to Vista 11 Today, We'll Brick Your Audio and You Cannot Prevent This
Windows Update is obligatory, so...
The Unspeakable National Security Threat: Plasticwares as the New Industrial Standard
Made to last or made to be as cheap as possible? Meritocracy or industrial rat races are everywhere now.
Microsoft's All-Time Lows in Macao and Hong Kong
Microsoft is having a hard time in China, not only for political reasons
[Meme] "It Was Like a Nuclear Winter"
This won't happen again, will it?
If You Know That Hey Hi (AI) is Hype, Then Stop Participating in It
bogus narrative of "Hey Hi (AI) arms race" and "era/age of Hey Hi" and "Hey Hi Revolution"
Bangladesh (Population Close to 200 Million) Sees Highest GNU/Linux Adoption Levels Ever
Microsoft barely has a grip on this country. It used to.
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, December 19, 2024
IRC logs for Thursday, December 19, 2024
Gemini Links 19/12/2024: Fast Year Passes and Advent of Code Ongoing
Links for the day
Twitter is Going to Fall Out of Top 100 Domains as Clownflare (DNS MitM) Sees It
evidence of Twitter's (X's) collapse
[Meme] Making Choices at the EPO
Decisions, decisions...
'Dark Patterns' or a Trap at the European Patent Office (EPO)
insincere if not malicious E-mail from the EPO's dictators
There's an Abundance of Articles About the New Release of Kali Linux, But This One is a Fake
It can add nothing except casual misinformation (fed back into the model to reinforce lies)
Large and Significant Error Correction in South America?
Windows now has less than half what Android achieved in terms of "market share"
IBM's Leadership Ruining Lives of People Who Thought Working for IBM Would be OK
Nobody gets fire-lined for buying IBM?
The United States' Authorities Ought to Become Enforcers of the General Public License (GPL) for National Security's Sake
US federal agencies ought to pursue availability of code and GPL compliance (copyleft), not bans
The Problem of Microsoft Security Problems is Microsoft (the Solution is to Quit Microsoft) and "Salt Typhoon" Coverage Must Name CALEA Back Doors
Name the holes, not those who exploit them.
A "Year of Efficiency"
No, we don't mean layoffs
Links 19/12/2024: Astronaut Record and Observer Absorbed
Links for the day
Links 19/12/2024: Seven Dirty Words and Isle Release v0.0.3 (Alpha)
Links for the day
Links 19/12/2024: Nurses Besieged by "Apps", More Harms of Social Control Media Illuminated
Links for the day
15 Countries Where Yandex is Already Seen to be Bigger Than Microsoft (in Search)
Georgia, Syrian Arab Republic, Cyprus, Moldova, Ukraine, Armenia, Azerbaijan, Kyrgyz Republic, Uzbekistan, Kazakhstan, Turkmenistan, Tajikistan, Belarus, Turkey, and Russia
Links 19/12/2024: Magnitude 7.3 Earthquake and Privacy Camp
Links for the day
Gemini Links 19/12/2024: Port Of Miami Explosion, TurboQOA, Gnus
Links for the day
Fake Articles About 'Linux'
Dated yesterday
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, December 18, 2024
IRC logs for Wednesday, December 18, 2024