Bonum Certa Men Certa

Microsoft Back Door in Windows (All Versions) Intentionally Left Open For Over a Year, Existed for 15 Years

Summary: It has become more obvious that Windows back doors are there by design (or knowingly left there by intention) even after Snowden's NSA leaks

THERE ARE SOME corporate media reports about Microsoft patches, but few realise the significance of it. Microsoft tells the NSA about unpatched holes in Windows and other Microsoft software, which is the equivalent of giving the NSA back door access.



As we noted some weeks ago, evidence shows that Microsoft doesn't care about security and it is evidently the same with Apple. They both sat on known flaws that were critical for longer than 3 months, refusing to patch them. Both proprietary software companies, which together command the lion's share of laptop and desktop operating systems, simply refused to close back doors and only decided to do something at the very belated end because the public finally knew about them (Google let is be known).

"Both proprietary software companies, which together command the lion's share of laptop and desktop operating systems, simply refused to close back doors and only decided to do something at the very belated end because the public finally knew about them (Google let is be known)."Dan Goodin, who typically spends his 'journalism' career bashing Free software over security, has finally decided to shift some focus and write about a massive Windows flaw. It's a major one, no doubt; But no name, no "branding"...

In Goodin's own words:

Microsoft just patched a 15-year-old bug that in some cases allows attackers to take complete control of PCs running all supported versions of Windows. The critical vulnerability will remain unpatched in Windows Server 2003, leaving that version wide open for the remaining five months Microsoft pledged to continue supporting it.

The flaw, which took Microsoft more than 12 months to fix, affects all users who connect to business, corporate, or government networks using the Active Directory service. The database is built into Windows and acts as a combination traffic cop and security guard, granting specific privileges to authorized users and mapping where on a local network various resources are available. The bug—which Microsoft classifies as MS15-011 and the researcher who first reported it calls Jasbug—allows attackers who are in a position to monitor traffic passing between the user and the Active Directory network to launch a man-in-the-middle exploit that executes malicious code on vulnerable machines.


The significant part is in the second paragraph above ("took Microsoft more than 12 months to fix"). We can interpret that as saying that the hole, which NSA used for over a year for back door access (because Mirosoft told the NSA about it), is finally being acknowledged to the public. Therein lies the 'magic' of proprietary software. Is the NSA now 'done' cracking all the world's networks that have Windows in them? Is it now 'safe' to finally close this back door?

Microsoft Windows is an utter joke when it comes to security, as Microsoft's own actions serve to show. Back doors surely look like the goal, not an error. Windows was recently used to crack Sony years after the NSA had cracked North Korea's network. Those who knowingly used an operating system with back doors can't blame anyone other than themselves and perhaps Microsoft/NSA. Misplaced blame these days typically names China, Russia, or North Korea.

Remember that Microsoft leaves security holes open/in fact anyway, no matter if versions of Windows are supported or not (upgrades are neither simple nor free). As Goodin's former employer puts it:

What happens six months from now, on 14 July? That's the date Microsoft issues its last security fix ever for Window Server 2003 – the end of extended support from the server operating system's maker.


The article states that many servers will basically be left with permanent back doors. Many of them contain customers' (or patients') data.

As Robert Pogson put it, "Server 2003, which is due to go without support this summer won’t be fixed for a recent Patch Tuesday revelation of a vulnerability built-in by design a decade ago and impossible to fix without breaking everything…"

He concludes correctly: "Maybe it’s time people switched to GNU/Linux, an operating system not designed by salesmen. It’s not perfect but at least the bugs are fixable."

Yes, even bugs with special names, logos, and "branding" -- those that the corporate media loves to hype up.

Recent Techrights' Posts

OpenBSD Says That Even on Linux, Wayland Still Has a Number of Rough Edges (But IBM Wants to Make X Extinct)
IBM tries to impose unready software on users
Professor Eben Moglen on How Social Control Media Metabolises Humans and Constraints Freedom of Thought
Nothing of value would be lost if all these data-harvesting giants (profiling people) vanished overnight
 
Media Cannot Tell the Difference Between Microsoft and Iran
a platform with back doors
Links 28/11/2023: New Zealand's Big Tobacco Pivot and Google Mass-Deleting Accounts
Links for the day
Justice is Still the Main Goal
The skulduggery seems to implicate not only Microsoft
[Teaser] Next Week's Part in the Series About Anti-Free Software Militants
an effort to 'cancel' us and spy on us
Over at Tux Machines...
GNU/Linux news
Permacomputing
This work is licensed under a Creative Commons Attribution 4.0 International License
IRC Proceedings: Monday, November 27, 2023
IRC logs for Monday, November 27, 2023
When Microsoft Blocks Your Access to Free Software
"Linux is a cancer that attaches itself in an intellectual property sense to everything it touches." [Chicago Sun-Times]
Techrights Statement on 'Cancel Culture' Going Out of Control
relates to a discussion we had in IRC last night
Stuff People Write About Linux
revisionist pieces
Links 28/11/2023: Rosy Crow 1.4.3 and Google Drive Data Loss
Links for the day
Links 27/11/2023: Australian Wants Tech Companies Under Grip
Links for the day
Over at Tux Machines...
GNU/Linux news
Links 27/11/2023: Underwater Data Centres and Gemini, BSD Style!
Links for the day
[Meme] Leaning Towards the Big Corporate CoC
Or leaning to "the green" (money)
Software Freedom Conservancy Inc in 2022: Almost Half a Million Bucks for Three People Who Attack Richard Stallman and Defame Linus Torvalds
Follow the money
[Meme] Identity Theft and Forgery
Coming soon...
Microsoft Has Less Than 1,000 Mail (MX) Servers Left, It's Virtually Dead in That Area (0.19% of the Market)
Exim at 254,000 servers, Postfix at 150,774, Microsoft down to 824
The Web is Dying, Sites Must Evolve or Die Too
Nowadays when things become "Web-based" it sometimes means more hostile and less open than before
Still Growing, Still Getting Faster
Articles got considerably longer too (on average)
In India, the One Percent is Microsoft and Mozilla
India is where a lot of software innovations and development happen, so this kind of matters a lot
Feeding False Information Using Sockpuppet Accounts and Imposters
online militants try every trick in the book, even illegal stuff
What News Industry???
Marketing, spam, and chatbots
IRC Proceedings: Sunday, November 26, 2023
IRC logs for Sunday, November 26, 2023
The Software Freedom Law Center's Eben Moglen Explains That We Already Had Free Software Almost Everywhere Before (Half a Century Ago)
how code was shared in the 1970s and 80s
When the So-called 'Cancel Culture' Sees Everything in Free Software Through the Scopes of 'Sex' (Because It Cannot Argue on Technical or Legal Grounds)
Losing the plot
Links 26/11/2023: Debunking So-called G.A.I. and Sierra Leone's National Curfew
Links for the day
In the 'Phoronix Universe', Single Job Openings at AMD Are News, But Not ~400 Layoffs
like a classifieds section
Over at Tux Machines...
GNU/Linux news
Microsoft Shamelessly Attacks Both Git and Projects in GitHub, Using Plagiarism in "AI" Clothing (Exit GitHub Now!)
A mountain of plagiarism
Microsoft Loses Market Share, Market Price of Windows Plunges to Almost Nothing (28 Dollars for Vista 10)
GNU/Linux has grown so potent that Microsoft now charges only dozens of bucks for Vista 10
Professor Eben Moglen Stands with Snowden While Moglen's 'Critics' (Microsofters) Keep Defaming Prominent Whistleblowers
Don't listen to Microsoft liars and weasels, who merely try to "replace" Moglen and override his message
"Check Point" + Microsoft Partnerships Extend to Anti-GNU/Linux FUD
a close partner/pusher of Microsoft tries to alter the narrative (change reality itself)
IRC Proceedings: Saturday, November 25, 2023
IRC logs for Saturday, November 25, 2023
Links 26/11/2023: Fresh Concerns Over North Korea Satellite Ambitions and South China Sea Patrols
Links for the day
Eben Moglen Explains the Connection Between FSF and SFLC (Both of Which Under Attack by Microsofters)
Old clip