Bonum Certa Men Certa

Proprietary Software on Top of Proprietary Software (AV on Windows) Only an Illusion of Security

"Our products just aren't engineered for security."

--Brian Valentine, Microsoft executive



Summary: Remarks on the recent revelations about code and communication interceptions targeting insecurity firms and Microsoft's claim that 'transparency' alone would be enough to assure security

RECENT reports about state surveillance on anti-malware/virus software (which could not detect Stuxnet, for example, making this more like snake oil) have led to the claim that Microsoft Windows cannot be made secure, not even with additional 'security' software. "Security by obscurity" does not work when the state can see everything and also sponsors the world's biggest (and best funded) cybercrime operations. Windows is simply not designed to be secure and security is not the goal as the underlying design serves to prove. As Pogson put it this week:



Given That Other OS is just about everywhere and is helpless without anti-malware software, the NSA and others have studied the anti-malware software to exploit it as a back door to TOOS… Ironic, isn’t it?


Microsoft and security don't belong in the same sentence. As FOSS Force reminds us, this NSA ally with worst of spyware uses the “transparency centers” [1] sham that we wrote about earlier this month. They are replacing software freedom with "transparency" nonsense. They pretend that "transparency" somehow improves security. It doesn't.

The only way to perpetually and universally verify (by audit) the security of software, or pressure its maker/distributor to pursue genuine security at all times, is to ensure the software is Free software. Microsoft's longtime employee (on and off for years at a time) and occasional mole inside FOSS [1, 2, 3, 4] says that Free software has not won and even uses a picture of a pig to prove it or at least make his case (crass, but typical of him). Don't let these people shape the consensus; after the NSA leaks a lot of semi-technical people can easily understand that Free software is the only way to go. Secrecy, like secret (proprietary) code, is as trustworthy as politicians. It's time for proprietary software to go. Backbone infrastructure sure is heading towards Free software-only (as a matter of policy), as several consortia already serve to demonstrate. It's going to be a harsh reality for Microsoft.

Related/contextual items from the news:


  1. The NSA, Windows & Antivirus
    Poor Microsoft. The beleaguered company just can’t catch a break. We’ve already told you about how Snowden’s revelations have forced the pride of Redmond to spend who knows how many millions opening two “transparency centers” to allow government IT experts to pore through source code to prove there’s no back doors baked into Windows or other Microsoft products. Trouble is, while its engineers have been busy plastering over all traces of old back doors, they’ve left a side door standing wide open, waiting to be exploited.

    [...]

    The spooks have been reverse engineering. They’ve been dismantling Karpersky’s software, searching for weaknesses. They’ve been mining sensitive data by monitoring the email chatter between Kaspersky client and server software. In other words, while IT security folks outside the U.S. have been keeping a wary eye on their Windows servers while trusting their antivirus to be a tool to help them secure the unsecurable…well, their antivirus software has been being a Trojan in the truly Homeric sense of the word.

    [...]

    In the meantime, Windows becomes less safe by the minute for corporations and governments hoping to keep private data private. I’m certain that Red Hat, SUSE, and even Ubuntu are taking advantage.




Recent Techrights' Posts

A Month After "End of 10" analytics.usa.gov Says More People Use Vista 7 Than Use Vista 11
Does it get any more pathetic than this?
Techrights Protects Against Collective Amnesia (Forgetting History the Rich and Powerful Want Us to Forget or be Misled About)
Keeping full access to our material with a good search facility is a priority for us
Mainstream Media Compliments Techrights on Its Work
Google isn't "the Web" and this site isn't "the Web" either
LLMs Will Never Work, You Need to Type What You Know
Voice recognition is too imprecise to be practical or really save any time if you can type fast
IBM Will Carry on or Carry Out Mass Layoffs Until Tomorrow, Based on Unverified Claim (Silent Layoffs Under Secrecy Clauses/Deals)
Red Hat (as a "company" with a Web site) will probably never announce layoffs again
 
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, November 13, 2025
IRC logs for Thursday, November 13, 2025
Mozilla Handed Over Control Over Firefox to Microsoft, Now Firefox is Preloaded With Microsoft Spyware and It's Proprietary
Who would still want to download Firefox?
Slopwatch: LinuxSecurity, Brian Fagioli, and WebProNews
becoming a slopfarm is a site's suicide
"Sponsored Posts" in The Register MS
That's The Register MS in 2025
IBM RAs in India (Apparently)
IBM is a bad place to work
Another Richard Stallman Talk in Two Days
His talk will be a remote talk, as he won't be travelling to Argentina
Links 13/11/2025: "Fight for Control Over In-Car Technology" and "Climate Crisis is a Health Crisis"
Links for the day
Gemini Links 13/11/2025: Disbelief in the Moon Landings and Doom That Came to Scrolling
Links for the day
Links 13/11/2025: Ghost (E-mails) of Jeffrey Epstein Chases Cheeto, Uproar Over SLAPP Threats Against British Broadcasters
Links for the day
IBM Layoffs Seem to Have Reached Europe
Is it Europe's turn to fall on its sword?
A Lot of What's Left of the Online "Media" is Paid-for SPAM
How much of online media can people still trust?
Synopsys, Which Controls a Microsoft FUD Operation (Black Duck), to Lay Off Hundreds of Workers
Microsoft had plenty of layoffs this year, well over 30,000 in total, including at least two waves of layoffs last month
The EPO Has Spent Years Attacking European Media, Led by a Cocaine Addict (the EPO's Spokesperson)
The EPO silences critics
Prominent German Media Dares Not Mention Cocaine at the European Patent Office, Germany's "Cash Cow" (Seller of Monopolies for the Whole of Europe)
It seems like a case of the corrupt hiring the corrupt to bully those who speak about the corruption
Microsoft-Sponsored FSFE is Exploiting the Success of Jean-Baptiste Kempf to Market Itself and Its GAFAM-Funded Messaging (While Pretending to be "FSF" Europe)
No doubt Jean-Baptiste Kempf accomplished a lot (not limited to VLC) in not so many years
A Week of Techrights Search
Tomorrow it'll be one week since we turned 19
Your Computers Are Work and Entertainment Tools, Not a Fashion Statement
If you're into fashion, find another job or keep cruft out of the workplace
The Federation? Almost 90% of Its Users Have Quit Participating.
If one counts offline (historic) instances, it's even worse than this
Under IBM, Red Hat Isn't a Linux Company, It's Sold to Clients as "AI Company"
IBM is sacrificing Red Hat for Wall Street (share price)
It Looks Like Microsoft is Really Abandoning XBox (the Brand "XBox" Means Just an Online "Games Store" or Streaming)
Published last night
The Register MS Has Just Taken Money to Promote Microsoft Windows Under the Guise of "HEY HI" (AI)
Just 'consume' the ads disguised as "journalism" at The Register MS
Apple is Waning, Shows Data (Web Stats)
Is Apple doing as well as Apple-sponsored (paid to run Apple ads) claims?
IBM is a Buzzwords Vendor
Does anyone even pay attention to anything IBM promises these days?
It's Patently False That Apple Has Avoided Layoffs
be sceptical of people who say Apple hasn't got layoffs
IRC.com is Vendor-Locked (Freenode)
Web client
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, November 12, 2025
IRC logs for Wednesday, November 12, 2025
Slopwatch: Spam, Scams, and Plagiarised Information Synthesis Systems (LLMs)
The way things are going, LinuxSecurity might become entirely inactive
IBM "Trying to Memory Hole the RA With Positive News."
it's clear they have no real plan, just vapourware
Gemini Links 13/11/2025: Pictures From the Aurora and Cryptography of the Internet
Links for the day
Links 12/11/2025: Botulism Outbreak and Increased Russian Censorship
Links for the day
British Army Officer Said Ubuntu Needed to Abandon Sudo for Rust's Imitation of Sudo and You Can Guess What Happened Next...
The not-so-drop-in replacement
The Open Web Has Fallen, It's Just Chrome
We cannot envision any other rendering engine (or "base") making any measurable headway
Patients' Data Should Not be Outsourced to Any Party at All, Let's Redo the Storage Scheme
Far better than giving all our data to Microsoft and Palantir (US)
The EPO's Central Staff Committee Complains About the EPO's Management Faking "Production" (Monopolies) to Make More Money
The Central Staff Committee has a new communication
The Second-Largest Institution in Europe (EPO) is Playing With Fire and Now It Puts the Largest One (EU) at Risk
The EPO will have some more shake-ups
Ethical Consumer Could Use a Mention of "Ethical Software"
Maybe the Free Software Foundation (FSF) can get in touch with them
Links 12/11/2025: A US President (Insurrectionist) Attacking British Media, Hyundai's Digital Restrictions (DRM)
Links for the day
Gemini Links 12/11/2025: Trains in Switzerland, Software Survival, and More
Links for the day
The EPO's Own 'Drug Bust': Berenguer is Gone, But Who Else?
EPO latest news
Trying to Cancel People and Projects That You Don't Like by Changing the Focus to Politics
Don't fall for it
What Kind of Bubble is AI? We'll Find Out Very Soon
In 2022 and 2023 Cory Doctorow was one among many who asserted "AI" was a bubble
Mandrake's Gaël Duval Debunks Clickbait Nonsense From ZDNet, a Non-Coder Pushing Bot-Made 'Code' (Plagiarism Done Poorly)
"Why AI won't "Kill Open Source”
Improving Clarity When Presenting LLM Slop and Slop Images
There will likely be more changes (improvements) to improve the visibility of our labels
Groklaw Won't be the Latest (Nor the Last) Major Site We Lose
Many other sites will go offline; the more popular among those will get hijacked by rogue actors
Slopwatch Turns 1 Next Month
2024-12-14 is when Slopwatch began
The Issue With Firefox is Not Its Brand
Mozilla seems to be the biggest enemy of Firefox at this point
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, November 11, 2025
IRC logs for Tuesday, November 11, 2025