Bonum Certa Men Certa

ISP Under Unfortunate 'DDOS Attack' by Microsoft Corporation; Liability of Software Debated in Europe

Stranded



Summary: Microsoft servers run amok and questions about liability return

SIMON PHIPPS has just found this very interesting message about an ISP which was brought down to its knees by "Windows Update". It is actually a recurring issue that affects networks in all sorts of ways (e.g. global Skype downtime).

We were facing a distributed denial of service attack from the world's largest "botnet:" Microsoft's "Windows Update."

[...]

As Spider-Man creator Stan Lee once noted, "with great power comes great responsibility." Microsoft, by virtue of its control over Windows-based PCs, has the ability to shut down the entire Internet at will -- and must be careful not to do it, inadvertently, by turning 90% of the world's PCs into a "zombie army."

Furthermore, content delivery networks such as Akamai, which distributes Microsoft's updates, must not be allowed to discriminate against smaller providers by making updates uncacheable (at least by a standards-conforming Web cache) and then denying smaller ISPs access to a cache that WILL cache them.


This is reminiscent of past incidents (see [1] and [2] at the bottom of this post). Yesterday we wrote about FAA where the damage of Microsoft's security, reliability and stability track record seems immense (in a very negative way). Now we find this from UC Berkeley right at the top of the news.

University of California, Berkeley, officials said Friday that hackers infiltrated restricted computer databases, putting at risk health and other personal information on 160,000 students, alumni and others.


Can liability put an end to this? That's the question the European Commission is asking and Glyn Moody reports on this matter.

Should Software Developers Be Liable for their Code?



Should Microsoft pay for the billions of dollars of damage that flaws in its software have caused around the world? It might have to, if a new European Commission consumer protection proposal becomes law. Although that sounds an appealing prospect, one knock-on consequence could be that open source coders would also be liable for any damage that errors in their software caused.

Here's what the European Commission is proposing:

A priority area for possible EU action is "extending the principles of consumer protection rules to cover licensing agreements of products like software downloaded for virus protection, games or other licensed content", according to the commissioners' agenda. "Licensing should guarantee consumers the same basic rights as when they purchase a good: the right to get a product that works with fair commercial conditions."

EU consumer commissioner Kuneva said that more accountability for software makers, and for companies providing digital services, would lead to greater consumer choice.


We have already covered this issue of liability and a reader wrote to us yesterday and offered his opinion too:

I suppose that this means that it is soon possible for the new administration to use military force to deal with Microsofters, if they don't dismantle their movement voluntarily:

Pentagon girds for cyber warfare

Official: No options ‘off the table’ for U.S. response to cyber attacks

Not so long ago, someone (or some group) did the electronic equivalent of cutting holes in the perimiter fence and taking out the guard towers by deploying Microsoft products inside a US Army base inside Afghanistan. The damage was quite bad as a result, and maybe the corrective actions were kept quiet and in-house, but certainly there is a paper trail leading back to those who brought MS products into the base.

In a recent speech, President Obama mentioned that US workers must come first. If that priority is followed, then it leads to removal of threats to US workers. Considering that the conficker Windows worm cost over $ 9.1 billion in the first three months, and that is on par with the other Windows worms, the 100's of billions saved over a few years by getting rid of any last trace of MS can easily pay for a new tech sector *and* a new economy.



Should Microsoft be made responsible and liable for damages caused by its software? Would this serve as a preventive measure? ____ [1] Are we being DOS attacked by a Microsoft employee?

Now I find it funny that a person that lives about 5 minutes from Redmond which is the headquarters of Microsoft is DOS attacking us and I don't believe that this is a coincidence.


[2] Bots Helped To Boost Microsoft Live Search Gains

In a blog post, Compete analyst Steve Willis attributed Microsoft's search gains to prizes awarded to users participating in Live Search Club, which features games that post queries to Microsoft's search engine.

[...]

Microsoft is essentially being DDoSed by thousands of people hundreds of times per minute, but they are mistaking this rise in traffic for people actually using Live Search."


Recent Techrights' Posts

"Rust People" Are a Threat to BSD Too (the Licence Isn't the Main Issue, Nor is the Proprietary Microsoft Hosting)
BSDs aren't written in Rust, so BSD developers should buckle up
Sami Tikkanen Explains Rust Language and Its Goals
"Sompi" (the nickname of Sami Tikkanen) has weighed in
Mauritius: Windows at All-Time Low, Down From 96% to 17%
Put in simple terms, people choose to connect from the "phone" (running Linux), not some laptop running Windows
Many IBM Layoffs Reported Today in Europe and North America
there's definitely a lot going on today
The GNU Manifesto is 40. Here's the Original Print (1985).
Some unpleasant people want to replace GNU with Microsoft-controlled (GitHub) Rust copycats
Unixmen Seems to Have Died After Turning Into a Slopfarm and Spamfarm, Is LinuxSecurity.com Next?
Better to not publish anything at all than to resort to fake garbage.
What Happened to the Open Source Initiative (OSI) Elections: More People Begin to Speak Out
Kuhn set another bonfire ablaze
2025 Rumours of IBM Layoffs in Marketing Likely True, Online Powwow Drops More Clues
Expect over 10,000 layoffs this year (at IBM alone)
 
Facts on the Case Already Disclosed by US Authorities
NGOs in the UK (several keep abreast of this, judging every recent move) are truly unimpressed
The Times Group (and The Times of India) Basically Died Again
This time a death by LLM slop/plagiarism
The Death of The Economic Times (India Times): LLM Slop Presented as 'Articles', Containing Errors and Revisionism
They'd be better off shutting down operations with some dignity than resort to bots giving the false impression (illusion) of authorship
In Belgium, Android is Finally Measured as Bigger Than Windows
In Belgium, the lobbying capital of Microsoft, it wasn't easy to get there
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, March 18, 2025
IRC logs for Tuesday, March 18, 2025
Links 19/03/2025: Gardening Season and the Web Without an Audience
Links for the day
Links 18/03/2025: ‘Meritless’ Defamation Suit Thrown Out, InterDigital Software Patents Headed for the Bin Too
Links for the day
These Strange Web Statistics From The Bahamas Show Windows Falling From 93% to Less Than 5%
There are about half a million there
Gemini Links 18/03/2025: Weather and Resisting "MAGA"
Links for the day
Links 18/03/2025: New Apple Blunders and Windows Disliked by Users
Links for the day
Once Again 'Losing Track' of Who the Clients Are, The Serial Harasser and Strangler from Microsoft
Timing is everything
Android (With Linux) Rises to Record Highs in Hong Kong and in Macao
Looking quite bad for Microsoft
Distractions. Distractions Everywhere.
distracting from the real solution
EPO Concerns About the Education and Childcare Allowance Reform (ECAR) and School Liaison Officer (SLO)
The public deserves to know as it impacts thousands of families
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, March 17, 2025
IRC logs for Monday, March 17, 2025
Links 17/03/2025: Weather Changing and Connecting Docker to Localhost
Links for the day
Microsoft Windows Barely Exists in Haiti Anymore
This trend in Haiti is a "story in progress"
The EPO Might Face Critical 'Brain Drain' (Abandonment by the Most Experienced Patent Examiners) This Year
"a number of colleagues might feel compelled to inform the Administration before the end of May 2025 of their intention to retire as of 1 December 2025."
Links 17/03/2025: Forced Labour and Memory on Tenstorrent
Links for the day
Links 17/03/2025: Live Nation’s DOJ Antitrust Battle Carries on, as Does the Demise of the "Hey Hi" Bubble
Links for the day
Links 17/03/2025: "Badly Misled About Covid" and "Gag of America"
Links for the day
The Lie or Half-Truth of Clownflare (or Equivalents) Improving Things
It may seem "cheap" (temporarily) and "fast", but that's just bait
Free Speech Around the World is Curtailed in the Name of "Protecting Us"
We have spent many years speaking about how to combat this trend
Enshittification of Online Media
Now more than ever we must fight for independent press
War Readiness Means Removing Every Windows Installation and CALEA-Compliant Equipment
Finland is vulnerable for a whole bunch of reasons
Reporting Facts is Not a Privacy Violation
Techrights has long valued and defended privacy
In the Russian Federation (Russia), Microsoft Isn't Even the 1%
the government builds "homegrown" (not pertinent parts of them) distros with which to replace Microsoft, not just Windows
Gemini Links 17/03/2025: "Hack the Planet", Klingnauer Stausee, and Enshittification
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, March 16, 2025
IRC logs for Sunday, March 16, 2025