Bonum Certa Men Certa

ASP.NET a Security Failure, Not Just a Patent Issue

I knew I should have stuck with freedom



Summary: Further new evidence that ASP.NET is a weak technology, Windows is extremely dangerous for use, and developers should replace it, not mimic it

Due to yet more security issues, any Mono and ASP.NET pusher at Novell ought to pay attention to deficiencies in the software it's mimicking. Here is the latest: [via]



'Padding Oracle' Crypto Attack Affects Millions of ASP.NET Apps



A pair of security researchers have implemented an attack that exploits the way that ASP.NET Web applications handle encrypted session cookies, a weakness that could enable an attacker to hijack users' online banking sessions and cause other severe problems in vulnerable applications. Experts say that the bug, which will be discussed in detail at the Ekoparty conference in Argentina this week, affects millions of Web applications.


That would not be the first such embarrassment. We gave other such examples before. Windows may be the least responsibly patched operating system, based on Microsoft's record as of late.

According to this new statement, things are getting worse than ever for Windows, security-wise.

Windows users are still the number one target: 99.4 percent of all new malware of the first half of this year was written for Microsoft’s operating system. The other 0.6% targeted systems that contain e.g. Unix or Java technologies.


Here is a further analysis/breakdown by Pogson (who also found this cripple-ware cartoon which we missed):

That other OS was the target of 98.5% of malware with a further 0.6% aimed at .NET for a total of 99.4%. The remaining 0.6% was mainly attacks on servers with various scripting and cracking attacks.


The "other OS" is Windows and .NET is there too. .NET is insecure in another sense for other reasons too, patent violations for example.

Recent Techrights' Posts

Linus Torvalds Cannot Easily 'Offend' Companies Anymore, But Weeks Ago He Explained Why (Linux Support and Hardware Documentation Has Significantly Improved)
new clip
Links 08/12/2023: Tidal and Simplilearn Layoffs
Links for the day
IRC Proceedings: Thursday, December 07, 2023
IRC logs for Thursday, December 07, 2023
[Video] The Media Facilitates Microsoft's Abuse, Bribes, and Growing Threats to National Security
The failure of the media to properly and independently explain what's happening will continue to doom the media
[Video] The Next Ten Years of Techrights in a World With Changing Threats and Technological Landscapes (or Trends That Are Buzzwords/Cargo Cults)
The video of today talks about the site's (and capsule's plan) for the future
Wikipedia is Vandalism, Brought to You by Microsoft and Bill Gates
Reprinted with permission from Ryan Farmer
Lennart Poettering and Fellow Microsofters Turn GNU/Linux Into Windows, Expect Poor Reliability With systemd-bsod
turning Linux into Microsoft Windows
The Effort to Silence (Squash) GNU/Linux Advocates and Press Coverage
If nobody even mentions it anymore, does it still exist?
Links 07/12/2023: Climate Events Occupied by Their Enemy, Workers Going on Strike
Links for the day
IRC Proceedings: Wednesday, December 06, 2023
IRC logs for Wednesday, December 06, 2023
A Googlebombing Campaign Targeting "Gemini" Takes on E-mail, Too
Google can do Googlebombing too (the term is even named after it)
[Video] Microsoft Without a So-called 'Common Carrier' (Windows Monoculture)
Windows Has Fallen
[Video] To Combat Efforts to Cancel or Kill the Career (and Reputation) of the People Who Made GNU/Linux We Must Rally the Community
nobody speaks better for projects and for licences than their own founders
Rumour: Major Finance Layoffs at Microsoft Next Week
If the rumour is true, we'll be hearing barely anything from the mainstream media next week
Links 07/12/2023: More EPO Patents Squashed, More Pfizer COVID-19 Vaccine "Glitches" Found
Links for the day
Still Not 'Canceled'
Ted Ts'o, Jan Kara, Linus Torvalds last month
Google is Googlebombing the Term "Gemini"
Could Google not pick a name that's already "taken"?
Links 06/12/2023: Bitcoin Rebound, China Downgraded by American Firm, Yahoo! Layoffs Again
Links for the day
Over at Tux Machines...
GNU/Linux news
Shooting the Messenger Using Bribes and Secrecy Bonds
We seem to live in a world where accountability for the rich and well-connected barely exists anymore
The Myth of an Aging (or Dying) GNU/Linux Leadership
Self-fulfilling prophecies as a tactic?
Links 06/12/2023: Many More December Layoffs
Links for the day
IRC Proceedings: Tuesday, December 05, 2023
IRC logs for Tuesday, December 05, 2023
PipeWire 1.0: Linux audio comes of age
Once upon a time, serious audio users like musicians and audio engineers had real trouble with Linux
This is How 'Linux' Foundation Presents Linux to the World
Right now it even picks Windows over Linux in some cases