Bonum Certa Men Certa

Despite Security Lies and Security Failures, Microsoft Instructs Worldwide Cybersecurity Summit

Protect your money
Billions or trillions of dollars are lost or saved based on one's security



Summary: Microsoft is telling lies about the number of flaws in its software, it admits failing to secure its software (statistics indicate exacerbation), and yet, Scott 'Windows zombie tax' Charney gets to tell participants of the Worldwide Cybersecurity Summit what to do next

IN OUR most recent post about Windows insecurity news we showed that nothing is improving at Microsoft when it comes to security. It's only the messages (engagements with the public) that seemingly change. Last week we wrote about Microsoft pretending that it supports standards, which is an utter lie only PR can buy. Here is part of the PR where Microsoft joins Apple [1, 2, 3, 4, 5] in its attack on Flash, not just its attack on Theora, which we covered in:





Microsoft -- like Apple -- is being denounced for the hypocrite that it is:

MS criticises Adobe over security and performance. Physician, heal thyself!


Let's not forget that Microsoft does exactly the same thing as Adobe (only with limited platform support) whenever it markets Silver Lie. Microsoft went further than that when .NET toys got secretly injected into Firefox without permission, thus creating security and performance issues without users' consent.

Microsoft is also being somewhat hypocritical when it makes some statements as covered in the article "Adapt or die, Microsoft warns business".

Microsoft has failed to adapt to a connected world and a world of computing mobility. Now it has debt to repay.

Addressing the subject of security, Microsoft spreads lies with its secret patches, which probably mean that there are fake figures in this latest 'security' report where Microsoft is conveniently blaming "ISVs" for security problems in Windows. The 'Microsoft press' plays along with this talking point and other publications are trying to make it an excuse for expensive Microsoft "upgrades", which Microsoft urges/advocates using withdrawal of support. How ruthless and deceiving. Here is an example of Microsoft's tactics:

The bottom line comes down to this: if your company plans to stay with XP well into 2011 and you're still using IE6, you've got to upgrade that browser. Knowing that IE9 won't support XP, you can safely move to IE8 knowing it's the end of the line for IE on XP. Or, you can move to Firefox, Chrome, Safari, or Opera -- but a company that's still stuck on IE6 isn't likely to be that adventurous. The web developers of the world will be happy with anything that gets you off IE6.


It is a "bait and switch" manoeuvre in a sense. Microsoft did the same thing to Windows 2000 users some years ago, for no practical reasons except the profit motive.

Going back to the hidden patches scam, can anyone believe that Microsoft is patching with just two "critical" bulletins? For several years Microsoft has been hiding its flaws and patching them silently for vanity purposes.

Microsoft on Tuesday will issue two critical bulletins that will fix vulnerabilities in Windows and Office, which if exploited successfully, could allow a remote attacker to take control of the computer, the company said Thursday.


There were also some broken patches which needed to be re-released.

Let's consider this news in light of last week's reports, such as:



The allegations are so serious that Microsoft could not afford to keep quiet without a carefully-crafted piece of spin. Here are the latest excuses from Microsoft (it's the psychology of lying without technically lying):

Note that a policy such as this implies that Microsoft will not patch known, internally-discovered vulnerabilities if an externally-sourced vulnerability of the same or lesser severity is not available for the silent patch to piggyback on. They'll sit on it, and we won't know for how long because they don't document it.


Utter spin. Groklaw has just found this new article which nicely explains Microsoft's lies in this case:

#3 Tell the truth, misleadingly. The hardest lies to catch are those which aren't actually lies. You're telling the truth, but in a way that leaves a false impression. Technically, it's only a prevarication - about half a sin. A 1990 study of pathological liars in New York City found that those who could avoid follow-up questions were significantly more successful at their deceptions.


Microsoft has also added a formal statement to The Register's article on the subject (silent patching) because it received a lot of attention. Apologists of Microsoft also left comments trying to defend what Microsoft did there. It means it's extremely damaging.

“Microsoft's security record continues to be poor simply because Microsoft does not handle security issues properly, having for example ignored known flaws for 5 months until a disaster came.”In other insecurity news, SharePoint 2007 has a 0-day vulnerability (meaning that it's already under attack). Microsoft has confirmed this [1, 2] and only issued a "workaround" rather than a solution [1, 2, 3]. As this one blogger puts it, there is "no SharePoint fix" and it says nothing about Microsoft's hiding of patches and flaws (clustering them is possible if one wants to crunch the numbers). How many flaws does Microsoft patch in SharePoint silently? In this case, Microsoft had no choice but to publicise it (someone beat Microsoft to it).

Microsoft's security record continues to be poor simply because Microsoft does not handle security issues properly, having for example ignored known flaws for 5 months until a disaster came [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12]. That's just negligence [1, 2, 3].

As a result of such negligence, IDG reports that "Conficker found on 25% of enterprise Windows PCs," according to Microsoft.

Conficker was far and away the most prevalent threat found on Windows machines in the second half of 2009 in the enterprise, Microsoft says. The company's security tools cleaned the Conficker worm from one quarter of enterprise Windows machines.


"25% of enterprise Windows PCs" is a lot of computers. But then again, for several years now we have known that hundreds of millions of Windows zombies were out there waiting to be commandeered. Google says that fake antivirus software is 15 percent of all malware. That's what happens when Windows refuses to implement repositories like GNU/Linux does. GNU/Linux has had that for ages and it keeps it more bulletproof.

Going back to Microsoft's own figures, even Microsoft admits that it's getting worse for Windows in practical terms:

Microsoft Sees Infected PC Numbers Climbing



[...]

The numbers of PCs cleaned by Microsoft's anti-malware software worldwide during the second half of 2009 continued to trend upward, suggesting that more PCs are getting infected in total, according to the company's latest Security Intelligence Report (SIR).


More here.

It's interesting that even Microsoft admits that it's failing to tackle the problem it created (or helped create).

Microsoft's Charney, the former government (ish) person who wants charge Mac and GNU/Linux users for Microsoft to clean up its own mess [1, 2, 3, 4, 5, 6, 7] is now intervening in international affairs, based on this AP report:

"Lots of times, there's confusion in these treaty negotiations because of lack of clarity about which problems they're trying to solve," said Scott Charney, vice president of Microsoft Corp.'s Trustworthy Computing Group, before a speech at the Worldwide Cybersecurity Summit.

[...]

Charney, of Microsoft, believes cyber threats should be better differentiated. He proposes four categories: conventional computer crimes, military espionage, economic espionage and cyberwarfare. That approach, he argues, would make it easier to craft defenses and to discuss international solutions to each problem.


What is Microsoft doing in a Worldwide Cybersecurity Summit? And why does it tell the world how to address these issues that it itself helped create? Microsoft cannot even issue disclosures of its own flaws (because it lies pathologically), so why should anyone believe Charney and maybe implement his outrageous idea of taxing all computer/Internet users for damage caused by Windows botnets? Microsoft should be held liable for knowingly refusing to patch known flaws.

Comments

Recent Techrights' Posts

Mainstream Media is Paid to Link "AI" Criticism/Boosting to Jeffrey Epstein Enablers, in Effect Showing How Corrupt This Media Became
Many readers will have noticed what was a paid-for PR campaign of a global scale
 
If Linux Was Written in Rust, 80% or More of Linux Developers Would Not Understand It (Same If It's Composed by LLM Slop)
The licence (GPL) is not enough when there are ways to bypass it
Gemini Links 28/08/2026: Absurd Tomodachi Summer, Screen Piggery, and Jugulans 1.0.3 Released
Links for the day
Links 28/08/2026: "UK Power Grid Has a Phantom Data Center Problem" and "Growth at All Costs is Cancer"
Links for the day
SLAPP Censorship - Part 164 Out of 200: Patent Troll SLAPPs, Defamation Trolls, and Stranglers From America
You start to wonder if the core issue is insecurity
Rumours of More PIPs and Layoffs at Confluent Just Months After IBM Bought It
It is meanwhile apparent IBM will have mass layoffs next week (September)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, August 27, 2026
IRC logs for Thursday, August 27, 2026
After Many Waves of PIPs (Silent Layoffs) IBM Makes Non-Silent Layoffs, Effective Next Week (September)
What we heard is turning out to be true
Gemini Links 27/08/2026: Oklahoma, Tennessee, Haiku OS, Digital Resistance, and Staying Offline
Links for the day
Links 27/08/2026: Facebook to Pay Up to $17.1 Billion to Cover Up Known Harms, Nepal Landslide Kills Many
Links for the day
The Register MS Has Just Published Paid Spam That Says "AI" 19 Times
1.5 hours ago
RSS is King: Why Having Subscribers or Followers in Sites You Neither Own Nor Control is Loss of Autonomy and Search is Mostly Slop (Plagiarising Sites, Not Linking to Them)
Because digital connections in third parties aren't assets; they endow another party with tremendous power over people (e.g. MElon getting to decide who can and cannot reach people or what messages to "dim down")
Claims of Tens of Thousands of 'Silent Layoffs' at IBM (and Red Hat)
Looking at recent activity in thelayoff.com, about 80% of the comments and posts are about PIPs
Links 27/08/2026: "Flock’s CEO Is Lying to Cops" and Microsoft's GitHub Actions Breaks Down Again (Too Many Layoffs, Loss of Knowledge)
Links for the day
Clownflare Sees GNU/Linux and ChromeOS at Over 13% in Bahamas
Narrowing down to desktops and laptops, and judging by Web requests that go through Clownflare, many people there use GNU/Linux or Google's 'bastardised' version of it (with spyware preloaded)
Richard Stallman Complains That Linux Gives a Bad Name to GNU and Asks for Feedback on What's Wrong with Systemd (and Wayland)
Maybe some people want to send him a detailed, polite explanation
GNU/Linux Does Not Need Social Control Media to Succeed
When it comes to Social Control Media, Richard Stallman was right
Increasing Focus on Patent Injustices
We'll soon cover the EPO a lot more
SLAPP Censorship - Part 163 Out of 200: Attack on Computer Science and on Computer Security (or Associating Back Doors and Kill Switches With "Security")
Nowadays there are many who pretend to be security professionals
There's No "Next XBox"
Nothing comes ahead except layoffs and price hikes
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, August 26, 2026
IRC logs for Wednesday, August 26, 2026
Gemini Links 27/08/2026: Conditioning, Lagrange 1.21, and Computer Games
Links for the day
Links 26/08/2026: Patent Troll InterDigital Utilises Software Patents in Unconstitutional Court, "WikiHow Launches Copyright Infringement Suit Against" LLM Plagiarism
Links for the day
The Register MS Has New Fake Article ("SPONSORED FEATURE") With "AI" 21 Times In It
The Register MS is one among many culprits
Gemini Links 26/08/2026: “Doomsday Clock”, Rwanda Genocide, and Boasting About Using LLMs Instead of Writing Code (Due to Employer's Pressure)
Links for the day
No Allure in Omarchy, the Political Hyenas Only Give it More Free Publicity
To me, Omarchy seems like a weak project because of the slop (an HR problem)
Twitter is Not an API or a Communication Site, It's a Really Bad Site That Forces You to be Enslaved by Its Algorithm (Amplifying Its Owner's Worldviews)
the crackdown on Nitter means we should all avoid accessing or linking to x.com (Twitter)
Don't Let Bastards and Haters Grind You Down
They say "jealousy is the sincerest form of flattery"
GNU/Linux Rose in Caribbean Islands
combined population is measured at 44,182,048
IBM's Quantum Computing Lies Explained Again by Sabine Hossenfelder
To become a CEO at IBM one must lie
Controlling Culture and Social Behaviour by Digital Locks
if you don't fully control the technology in your possession, then you're not using that technology, this technology covertly uses you
Goodbye, Dolly
This week we say "goodbye, Dolly."
Links 26/08/2026: Election Bribery (aka Vote-Buying) Deemed "OK" in the US, "Nitter is Shutting Down After a Cease and Desist Letter" by MElon
Links for the day
Analogue So Much Better and Faster
From what we can gather, the tram ticketing system does not use Windows; we never saw it crashing or rebooting (or showing some Windows logo) in decades, so we assume it runs some kind of Linux
Linux Today Dumped All Social Control Media Last December
Linux Today seems to have concluded that all Social Control Media is just a waste of time
Don't Say X.com is OK Because People Can Access It by Alternative Means
Can Mozilla please clarify who inside Mozilla greenlit a return to X.com?
The Reach of techrights.org Is Increasing
We are on the side of women victims
SLAPP Censorship - Part 162 Out of 200: An Outline of Events
An outline of events
Pushed to Live
We still have some other work - stuff related to the editing of pages - which is work in progress and has been subjected to testing for many months
GNU/Linux Measured at 10% in Germany, Based on Cloudflare
It's peaking late at night
Richard Stallman's GNU Project Began 42 Years Ago With GNU Emacs and More
GNU Project announced almost 43 years ago (next month it's the anniversary)
Fake Articles "Sponsored by HPE" Published in The Register MS
Selling proprietary products as 'alternatives' to other proprietary products
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, August 25, 2026
IRC logs for Tuesday, August 25, 2026
Gemini Links 26/08/2026: Journal Plans and Extending Finger Protocol
Links for the day