Bonum Certa Men Certa

Proprietary Software on Top of Proprietary Software (AV on Windows) Only an Illusion of Security

"Our products just aren't engineered for security."

--Brian Valentine, Microsoft executive



Summary: Remarks on the recent revelations about code and communication interceptions targeting insecurity firms and Microsoft's claim that 'transparency' alone would be enough to assure security

RECENT reports about state surveillance on anti-malware/virus software (which could not detect Stuxnet, for example, making this more like snake oil) have led to the claim that Microsoft Windows cannot be made secure, not even with additional 'security' software. "Security by obscurity" does not work when the state can see everything and also sponsors the world's biggest (and best funded) cybercrime operations. Windows is simply not designed to be secure and security is not the goal as the underlying design serves to prove. As Pogson put it this week:



Given That Other OS is just about everywhere and is helpless without anti-malware software, the NSA and others have studied the anti-malware software to exploit it as a back door to TOOS… Ironic, isn’t it?


Microsoft and security don't belong in the same sentence. As FOSS Force reminds us, this NSA ally with worst of spyware uses the “transparency centers” [1] sham that we wrote about earlier this month. They are replacing software freedom with "transparency" nonsense. They pretend that "transparency" somehow improves security. It doesn't.

The only way to perpetually and universally verify (by audit) the security of software, or pressure its maker/distributor to pursue genuine security at all times, is to ensure the software is Free software. Microsoft's longtime employee (on and off for years at a time) and occasional mole inside FOSS [1, 2, 3, 4] says that Free software has not won and even uses a picture of a pig to prove it or at least make his case (crass, but typical of him). Don't let these people shape the consensus; after the NSA leaks a lot of semi-technical people can easily understand that Free software is the only way to go. Secrecy, like secret (proprietary) code, is as trustworthy as politicians. It's time for proprietary software to go. Backbone infrastructure sure is heading towards Free software-only (as a matter of policy), as several consortia already serve to demonstrate. It's going to be a harsh reality for Microsoft.

Related/contextual items from the news:


  1. The NSA, Windows & Antivirus
    Poor Microsoft. The beleaguered company just can’t catch a break. We’ve already told you about how Snowden’s revelations have forced the pride of Redmond to spend who knows how many millions opening two “transparency centers” to allow government IT experts to pore through source code to prove there’s no back doors baked into Windows or other Microsoft products. Trouble is, while its engineers have been busy plastering over all traces of old back doors, they’ve left a side door standing wide open, waiting to be exploited.

    [...]

    The spooks have been reverse engineering. They’ve been dismantling Karpersky’s software, searching for weaknesses. They’ve been mining sensitive data by monitoring the email chatter between Kaspersky client and server software. In other words, while IT security folks outside the U.S. have been keeping a wary eye on their Windows servers while trusting their antivirus to be a tool to help them secure the unsecurable…well, their antivirus software has been being a Trojan in the truly Homeric sense of the word.

    [...]

    In the meantime, Windows becomes less safe by the minute for corporations and governments hoping to keep private data private. I’m certain that Red Hat, SUSE, and even Ubuntu are taking advantage.




Recent Techrights' Posts

Behind the Scenes With Richard Stallman
If you support his ideas, even if you dislike him as a person, then you'll welcome his ability to speak about those ideas
 
European Patent Office (EPO) Strikes and Other Industrial Actions Are Working: Patent Application Grants Have Collapsed
Even before the strikes happened any day of the week
SLAPP Censorship - Part 49 Out of 200: Two Americans, One Case, Recycled for Low Budget at Brett Wilson LLP and 5RB Barristers
Change one character, bill the client tens or hundreds of thousands of US dollars
Pension Contribution Increases as Another Attack on Compensation for EPO Staff (Mostly Patent Examiners)
Pension contribution increases!
Almost 1,000 IBM Layoffs Not Newsworthy (Nobody Covers It), Unlike When Snap Does It and Mentions a Celebrated - or Reviled - Buzzword
not a word regarding IBM layoffs
Gemini Links 17/04/2026: "Many Problems and Inequities in the Legal System", "No Place to Hide"
Links for the day
Links 17/04/2026: SRA Breaks Its Own Rules as Solicitor Attempts Suicide, IPv6 Barely Hits 50% After 20+ Years
Links for the day
ActBlue former IT boss disappearance: Decklin Foster & Debian, Harvard suicide lab, Chris Gleason is wife, whistleblower or both?
Reprinted with permission from Daniel Pocock
Gemini Links 17/04/2026: Getting competent in NixOS and Alhena 5.5.6 Released
Links for the day
Links 17/04/2026: "We Cannot Lose Sight of Ukraine" and "When Leaders Should Resign"
Links for the day
GizChina Appears to Have Become a Slopfarm, I.e. Fake News Site With Fake Text
Don't waste a moment reading LLM slop, as at the very least it rewards plagiarism [...] Deemed to be slop also by two human beings, not just two scanners
Massive, Cross-Site Strike at the EPO Today
There's coordination across sites for maximal pressure
Dr. Andy Farnell Says "AI" is "Only a Marketing Term" for Things That Exist for "Entertainment Purposes Only"
distortion or misuse of the term (now buzzword/s) "AI"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 16, 2026
IRC logs for Thursday, April 16, 2026
Strikes at the EPO Carry on, Staff Union of the European Patent Office (SUEPO) Increases Pressure Ahead of Technical and Operational Support Committee (TOSC) Meeting Next Week
the local section The Hague (or SUEPO TH) wants to rally many staff members
Gemini Links 16/04/2026: LLM Nuisance, Identity Systems (Surveillance), and Why Windows is Failing
Links for the day
'Going Offline' is Not Primitivism
Computers are good at automation, but people are not robots
The Register MS Has Published Article With "AI" 18 Times in it, "Cloud" 9 Times. It Got Paid to Do This.
What happened to journalism?
In Europe, More People Turn to Russia for Answers, Not Microsoft
The future of computing doesn't look pretty
SLAPP Censorship - Part 48 Out of 200: Brett Wilson LLP and 5RB Copy-Pasting Bogus Claims for Violent Americans (Microsoft) Who Tell Women to Kill Themselves
Microsoft's Graveley telling his partner to kill herself is probably a crime
The EFF Is Hardly Doing Anything Anymore
Our series about the EFF has been brewing for over 2 years already
Microsoft Uses Slop to Bribe (at No Cost) Nations That Otherwise Would Move to GNU/Linux and IBM is Forcing Red Hat Staff to Use Slop
Life it too short to waste "consuming" slop
Links 16/04/2026: Roblox Launching ‘Roblox Kids’ Accounts and "Deepfake Nudes Crisis in Schools"
Links for the day
Red Hat Staff: IBM Red Hat Laid Off About 400 Engineers, the Media Did Not Cover This
The media is not doing its job or doing a really shoddy job
Gemini Links 16/04/2026: Nocturnal Pulse, Unpersoned Outlaws, and Monaspace Lagrange Fontpacks
Links for the day
Richard Stallman Lecture in GDC Auditorium in Austin, Texas
corporate power could not 'cancel' the man
It's Not About the Head, It's About the Masters (and Funding)
Regardless of who the OSI claims to be its leader, its masters are Microsoft, just follow the money
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, April 15, 2026
IRC logs for Wednesday, April 15, 2026
Links 15/04/2026: Geelong Corio Refinery Fire, Journalist Sentenced for "Insulting the President"
Links for the day
Gemini Links 15/04/2026: Organiding .bashrc with Imports, Oddμ as SSG
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, April 14, 2026
IRC logs for Tuesday, April 14, 2026