Bonum Certa Men Certa

Microsoft Claims Credit for Failing in Security

Servers rack - amateur



Summary: Latest security issues and systematic deception, mostly from Microsoft and its various boosters across the Web (giving credit to Microsoft after Microsoft messed up)

Gratis as in Lock-in



A FEW days ago we wrote about Microsoft's attempt at disconnecting the air supply from third-party AV vendors, at least in small businesses. This would only decrease security due to monoculture, decreased competition, and lack of incentive to improve. The funny thing here is that Microsoft sells a vulnerable operating system and then claims to be distributing "free of charge" (only to some people) what ought to have been a characteristic of the operating system, not an add-on. The spinners from Seattle call it a "free" anti-virus software and what's meant by free is not freedom. It's free as in gratis, with lock-in. It decreases one's personal freedom and also impedes freedom of choice. A better headline than "Free Anti-Virus Protection Spurs More Robust Options" would be "Free-of-charge Anti-Virus Pseudo-protection Depresses More Robust Options".



Watch the Indian press turning the whole thing into Vista 7 promotion: "IT major Microsoft has launched a campaign to help computer users identify threats to their systems and how their networks can be made secure using Original Windows 7 that now comes with the advantage of Microsoft Security Essentials."

So Microsoft wants to dump Security Essentials on the market (as expected by many people all along) and already we learn that "Scareware Apes Microsoft Security Essentials". Microsoft has always performed very poorly among the security products already available and well established. "Anti-virus systems get tested" says The Inquirer which gives the following details:

A NUMBER of the most common anti-virus security systems have had a beady eye passed over their effectiveness and fitness for purpose in an assessment.

The study, which was carried out by the Austrian AV Comparatives group, looked at twenty products from the main providers that volunteered to take part.

We do not know who if anyone refused, but AV Comparatives said that it had limited test subjects to no more than twenty and required that participants adhered to its undisclosed criteria.


"Over half of all apps have security holes," claims Veracode (which we mentioned in [1, 2]).

More than half of all software applications failed to meet an acceptable level of security, according to a study based on real-world code audits by application security firm Veracode.

Around 57 per cent of applications failed to pass muster when first submitted to Veracode’s cloud-based testing service. A similar 56 per cent of finance-related applications failed first testing by Veracode’s security audit. The quality of the code used in many business-critical banking and insurance operations was simply not up to snuff.


ASP.NET Under Attack, Spin



In security news, the other major issue last week was the Microsoft ASP.NET vulnerability, which we wrote about in [1, 2, 3, 4].

“Is this really praise-worthy, especially when someone responds to flaws which the same someone is responsible for?”The ASP.NET problem alarmed Microsoft a great deal and the PR spin strives to make Microsoft be seen as responsive. An advisory was quickly issued [1, 2, 3] because of bad publicity and because it was already being exploited (a demo existed). There is only a temporary fix, not a permanent one. There are third-party fixes.

So, once again Microsoft pays attention to flaws a tad too late and then scrambles to limit damage it could probably prevent. Is this really praise-worthy, especially when someone responds to flaws which the same someone is responsible for?

Just like in the case of Russian spin [1, 2], Microsoft is trying to make itself look like the saviour rather than the problem. Lee Pender of the Microsoft boosters is trying to make Microsoft look good by painting it as responsive and responsible. To quote: "Well, late last week, we got an update from a Microsoft spokesperson who wanted to tell us that Microsoft hasn't just buried its head in the sand on Stuxnet."

We wrote about Stuxnet in [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14].

Microsoft-Police



Over in Australia, Microsoft is involving the police right now (funded by taxpayers) [1, 2, 3, 5]. It's about a computer scam that affects Microsoft.

Twitter and Fog Computing



The other day we wrote about the major problem Twitter.com was having. Half a million Twitter users are said to be affected by a Twitter worm and Slashdot discusses the matter before and after the patching. Here are "the names and faces behind the 'onMouseOver' Twitter worm attack". It's one of those risks of Fog Computing. Even a teenager turns out to have been smart enough to do it.

But later, some mischievous users of the site started using the exploit to make people "retweet" infected messages (when they hovered over a tweet with the code inserted) that they had not authorised.


The guy is Australian, so will the police get involved? Or does the Australian police get involved only to help Microsoft?

Recent Techrights' Posts

Adrian & Diana von Bidder-Senn, Debian: detailed history of a death
Reprinted with permission from Daniel Pocock
Rust Keeps Breaking Ubuntu in All Sorts of Extraordinary Ways (and All Distros Based on Ubuntu Will Break Also)
The FSF's stance on this is unclear
With Net Income of One Billion Dollars Tesla Claims It Can Pay a Fake Founder (Who Paid for This Lie) 1,000 Billions
What does this tell us about Wall Street?
The 'Politics' of Operating Systems (or Exclusion for Inclusion's Sake)
This whole 'wrongthink' policing is getting out of hand
The Internet is Becoming Dead or a Zombie
The Internet is becoming like a giant botfarm
Gemini Links 10/11/2025: Homelabs and KeePassRX Manual Now Available
Links for the day
 
Links 11/11/2025: Slop Ruins Music, Facebook "to Discontinue Like and Comment Buttons on Third-Party Websites"
Links for the day
The Voice of Microsoft
Marketing disguised as a science
"MIT Technology Review Insights" is the Selling of Ponzi Schemes for Sponsors (MIT Lacks Integrity)
Just like IBM, they're chaining buzzwords now
Boot-locking Laptops and Desktops After Falsely Marketing That As 'Security' and Not Obligatory
If anyone can confirm this to us
GNU/Linux Cannot Buy Fake Journalism and It Won't Bribe Large Publishers
Free software developers don't purchase "sponsored" placements and that will never change
Static Site Generators (SSGs) Save You Lots of Money and Problems
We've basically reduced the environmental/carbon footprint of the site by a factor of ~100 (2 orders of magnitude)
IBM Does Not Care About Families, Communities, and Even Its Own Workers
Red Hat isn't a family and to believe that it is would be the makeup of cults
Too Much of Today's Web is Fake, Not Just Fake News
We'll continue to advocate for adoption of Gemini Protocol
Simulating a Downtime Tomorrow Night
It is expected that network redundancy will make this maintenance invisible to us, but IRC hangups or general slowness are still a possibility
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, November 10, 2025
IRC logs for Monday, November 10, 2025
Links 11/11/2025: Conflicts and Politics From National Broadcasters
Links for the day
Gemini Links 11/11/2025: Poetry and Electronics Studies
Links for the day
Apple's Debt Grew by About 16 Billion Dollars This Past Year, "Disappointing iPhone Sales" Reported
People who buy Apple's goods based on some false notion that Apple is "cool" or ethical or "underdog" (late 90s) aren't just living in the past; they're fools
Turning Down Proprietary Software is About Making Society Better
We should not be tempted to shame people for merely trying to keep programmers honest and human rights-respecting
Debian GNU/Linux Became the Most Popular (Most Distros Are Based on It) Owing to Richard Stallman
New presentation
A Day for Poppies
This site will run as usual today. We continue our fight for Software Freedom.
"Modern" Doesn't Mean Better, It Typically Just Means Newer
RMS demonised as someone who rejects "modern society" ("rejecting modern society") by a site that uses slop extensively
The Cocaine Patent Office - Part IV: European Patent Office to Come Under Media and Political Scrutiny
We'll persist until we get some answers
63-Page Response to the EPO's Effort to Decrease the Salaries of Workers While EPO Management Snorts Cocaine for 20,000 Euros a Month
"Read more in these written comments we sent to the members of the GCC"
Response to Another New Hit Piece About Richard Stallman (RMS)
We see similar smears floating about and tackling them can help not only RMS but anyone who thinks similarly about computers
Shrinking and Cheapening the Workforce: the Future of Red Hat and IBM
Does Red Hat cheapen the workforce?
Links 10/11/2025: BBC Turmoil and Iranian Drought Crisis
Links for the day
The Register MS Still Occasionally Uses Slop
some articles don't use real images
Links 10/11/2025: "Scam Altman Gets Served Subpoena" and "China will Rule Renewable Energy"
Links for the day
ubuntupit.com Has Paused the LLM Slop (for Now)
No slopfarm ever offered any real value
More Media Coverage From Austria Regarding Cocaine Use by EPO Management
The ultimate goal is full accountability
Ponzi Economics and the Media's Role in Defending Ponzi Economics
We occasionally notice weak or almost-non-existent coverage regarding the economy
Links 10/11/2025: Very High Windows TCO and XBox Continues to Languish
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, November 09, 2025
IRC logs for Sunday, November 09, 2025
Governments That Financially Benefit (Profit) From the EPO Have a Long History of Covering Up Fraud and Corruption at the EPO
Many people are aware of it, even some of the biggest EPO stakeholders
Our Time in London
10 Days Ago We Were Down in London
Giving Red Hat a Second Life and Second Chance: Drop the LLM Slop, Stop Publishing Promotion of LLMs or Text Made by LLMs
For Red Hat to earn more trust it needs to quit participating in the biggest "pump and dump" pyramid scheme since the 1990s
Gemini Links 09/11/2025: Garden Room Complete, FreeBSD 15.0 on the ThinkPad T480, and Known Gemini Caspules Sorted by Number of URLs
Links for the day
Links 09/11/2025: Fung-wong Strikes Maharlika, "Open" "AI" Wants Taxpayers to Give It Bailout Money
Links for the day
Links 09/11/2025: "Avoid MSI Graphics Like the Plague", Harms of Social Control Media More Widely Recognised
Links for the day
Rocky Linux's Embrace of Mindless Cargo Cults Will Harm Rocky Linux in the Long Run
focus on technology, not marketing that defrauds many people and plagiarises many producers
Many of Red Hat's Official Blog Posts Seem to be Fake, Written at Least Partly by Bots (LLM Slop)
Can one trust Red Hat on technical things if it cannot even write words?
Suggestions Regarding Techrights Search
In some cases, Daily Links also serve to obscure our original articles
"Open" "AI" is Going Bankrupt, Appealing for Government Bailout
The writings have been on the wall for years
Reaffirming Rumours of More Microsoft Layoffs, Halo Impacted, XBox Business Winding Down
XBox has a huge target painted on its bum
"Secure Boot": Stop Trying to Boot Into GNU/Linux, Use Vista 11 Instead
It's all about reducing the user's cybersecurity under the false guise of improving it
This is What We Always Wanted to Spend Our Time on
2026 will probably be our most productive ever
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, November 08, 2025
IRC logs for Saturday, November 08, 2025
LowEndBox Resorts to Ableism to Smear Software Freedom
Not some "low-level" pundit but an administrator
IBM is Destroying Red Hat (by Extension, It Also Harms GNU/Linux)
IBM is where things come to die, more so in the past decade or so
Austrian Media Coverage of Luis Berenguer's (Top EPO Official) Getting Busted for Cocaine
This wasn't some rich tourist caught by cops, it was a local official whom they busted
This Coming Thursday EPO Staff Meets Online to Discuss the Salaries Going Down While Stoned Managers Increase Their Own
compensation going down relative to inflation and other factors
Misinformation of IBM Spread via LLM Slop
Since a lot of sites now rely on LLMs we can expect the corporations' lies to be perpetuated by bots. That includes the myths of IBM Red Hat.
Gemini Links 09/11/2025: File Managers and DPC Commissioner
Links for the day