Bonum Certa Men Certa

Microsoft Breaks the Web and Linux

Coffee time



Summary: How Microsoft uses 'security' to exclude Web sites and GNU Linux distributions

Microsoft does not comply with the Web. It does not adhere to standards, either. It rejects fine keys and prominent Web folks complain about it.



One writer explains that "[a]s of Oct. 9, 2012, longer key lengths are mandatory for all digital encryption certificates that touch Windows systems.

"That must make Microsoft some new foes.""This means that Internet Explorer will refuse to access websites that do not have RSA keys with minimum lengths of 1024 bits. You won't be able to exchange encrypted emails, run ActiveX controls or install applications on Windows. This isn't new, as Microsoft started making announcements about this well over a year ago."

Then there is this about Microsoft blocking Flash based on a private whitelist: "Yeah you read that right. I just received an interesting email from Brightcove (the video delivery guys) about issues with their Flash based solution and Windows 8 running the new Internet Explorer 10."

That must make Microsoft some new foes.

These things are actually less malicious than plugging proprietary software hooks into Linux to discourage use of Free and open source virtualisation even in GNU/Linux, not to mention UEFI, which Debian agrees is a very malicious move (there is no solution to it yet). Microsoft is knowingly complicating the process of installing GNU/Linux and ways exist for spinning it as benign or beneficial.

James Bottomley, who used to work on some Microsoft stuff on behalf of his former employer Novell (e.g. on Hyper-V), speaks of a new workaround that bloggers try to grasp.

Pogson states correctly that this should not be legal. Stallman agrees. To quote Pogson: "I don’t like any solution that depends on M$. If they can revoke that key, GNU/Linux falls down. They have messed up keys before either deliberately or through incompetence. Someone should sue M$ over this mess. It’s clearly anti-competitive. Also, this doesn’t look like a solution for servers."

Why should anyone be asking Microsoft for permission to use a computer which does not even have Windows?

"Pogson states correctly that this should not be legal."News about it sometimes misses the point, but Varghese writes: "Fifteen days from today, Windows 8 will go on sale; only hardware that is certified to work with this system will be able to boot it, with signed keys being used to determine whether a genuine system is being booted.

"This will put those who boot other operating systems at a disadvantage. Given this, the Linux Foundation has come up with a means of bypassing secure boot to enable users of open source operating systems to continue to boot on hardware certified for Windows 8."

He later criticises this, as he did several times in the past. It is an important issue that even conferences cover. Here is what one UEFI apologist wrote: "The plan for supporting UEFI Secure Boot in Fedora is still pretty much as originally planned, but it's dependent upon building a binary which has the Fedora key embedded, and then getting that binary signed by Microsoft. Easy enough for us to do, but not necessarily practical for smaller distributions. There's a few possible solutions for them."

Techrights' position on this is that UEFI is anticompetitive and antitrust should therefore be pursued. Let is all remind us that there is no reformed Microsoft, it is still the same unethical corporation.

Recent Techrights' Posts

Blizzard/Microsoft Unions Grow Ahead of Mass Layoffs at Microsoft, Apparently Starting Next Week (as Many as 30,000 Workers Laid Off by Year's End)
Microsoft already fired about 5,000-6,000 workers this year by our estimates; that's not counting resignations compelled through pressure (i.e. pushed, did not jump) and contractors
"Victory Day" - Part II: Abject Defeat to Hypocrites and Objectionable People Who Strangle Women Whilst on Microsoft's Payroll
Someone is going to have to pay for this; it won't be us
Rust Propaganda Now Amplified by Slopfarms Powered by Microsoft LLMs, Encouraging the Outsourcing of GNU/Linux Distros to Microsoft/GitHub/NSA (and a Shift Away From GPL/Copyleft)
Moving to Microsoft GitHub and adopting unfinished, untested code for highly critical bits
IBM is Rotting With "Zero Internal Jobs" and Many PIPs (Performance Improvement Plans) on the Way, Typically a Fast Track Towards Layoffs Without Severance
At risk of giving air(time) to tribal sentiments, the internal joke at IBM is that to IBM "AI" stands for "All Indian"
 
Links 10/05/2025: Germany Considers Smartphone Ban in Schools, Right to Repair Bills
Links for the day
Gemini Links 10/05/2025: Git Server and Great LLM DDoS of 2025
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, May 09, 2025
IRC logs for Friday, May 09, 2025
Links 09/05/2025: Inflation Rising and Rights to Protest Curtailed Some More
Links for the day
Gemini Links 09/05/2025: Good and Evil, LLMs Made the Web Worse Yet Again
Links for the day
European Patent Office (EPO) Faked "Revenue Expansion" by Granting Loads of Invalid, Illegal Patents; Staff Still Wants to Know Where That Money Went
Only about 30% of the EPO's patents are for EU entities/people
The Gerstnerisation of Microsoft: Seventh Wave of Microsoft Layoffs (Over 20,000 to be Cut) Allegedly Going to Start Shortly, Probably Start of Next Week, Microsoft Spreads Chaff and Noise Before the Big Axes Fall
we might be looking at about 50,000 people that Microsoft gets rid of this year
Links 09/05/2025: TeleMessage Blunder, More Distractions From Impending Mass Layoffs at Microsoft
Links for the day
GNU (and the FSF) Still Changing the World
Today, in 2025, GNU powers almost everything
Military-Grade Anti-Linux Microsoft Propaganda Using Microsoft LLMs in Fake 'News' Sites (Slopfarms)
This is part of a pattern
Links 09/05/2025: Analog Computer and First time at FOSDEM
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, May 08, 2025
IRC logs for Thursday, May 08, 2025
Links 08/05/2025: Mass Layoffs at Google Again, India/Pakistan Tensions Continue to Grow, New Pope (US) Selected
Links for the day
"Victory Day" - Part I: That is the Day Microsofters Who Assault Women Pay for Their Actions in Foreign Land (Using "Guns for Hire" Who Attack Their Own Country for American Dollars)
Adding a friend from Microsoft to the docket didn't help
Rust is Starting to Seem More Like Microsoft-hosted "Digital Maoism", Not a Legitimate Effort to Improve Security
Maybe this is very innocent, but they seem to have taken a solid, stable program from a high-profile Frenchman and looked for ways to marry it with GitHub, i.e. Microsoft/NSA
Gemini Links 08/05/2025: Practical Gemini Use Case, Shutdown of the Blanket Fort Webring
Links for the day
Links 08/05/2025: "Slop Presidency", US Government Defunds Public Broadcasting
Links for the day
Lasse Fister, Organiser of Libre Graphics Meeting, Points Out the Code of Conduct is Likely Violated by the Same People Who Promote Codes of Conduct (and Then Bully Him Into Cancelling a Keynote)
I am starting to see Lasse Fister as another victim
LLM Slop Attacks Not Only Sites of Free Software Projects But Also Bug Reporting Systems (Time-wasting, in Effect "DDoS")
Microsoft, the leading purveyor and promoter of slop, is a cancer
The Richard Stallman (RMS) "European Tour" Carries on In Spite of the Nuremberg Incident
Some people spoke about how they saw yesterday's talk
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, May 07, 2025
IRC logs for Wednesday, May 07, 2025