Bonum Certa Men Certa

Eye on Security: 'Fun' with Zombies, Press Ignorance, and Bizarre Solutions

"Our products just aren't engineered for security."

--Brian Valentine, Microsoft executive



Microsoft software is not exactly renowned for being secure, despite attempts to manipulate journalists. The software is notorious for being deficient or defective. To Microsoft, security and networking were an afterthought, not a design consideration, as shown here. Granted, trouble should be anticipated.



Zombies Conundrum



Stories about Windows zombies are a dime a dozen, just like zombie nodes. It is estimated that about 320 million Windows PCs are zombies. Here is the latest story on this never-ending (and very costly) battle.

Researchers at Trend reported that 500,000 unique hosts have been infected across the globe. Macalintal said that because of the behavior of the worm, he expected to see the botnet grow bigger and produce more variants.


That's small potatoes compared to the whole, but it just happens to be a new example. Not so long ago we witnessed hospitals and army bases becoming botnets, as well. It's a hugely serious subject that results in many untold deaths.

Insecure by Design



As prior links demonstrate (we strive to avoid repetition), it is agreed even by Microsoft's biggest of fans that Windows fails at security because it's just bad at it. It's nothing to do with market share and those lies are running thin. In the following new article, Microsoft's security model comes under fire.

When Microsoft released an emergency patch last month for a critical vulnerability in the server service in Windows, administrators and security teams in enterprises around the world scrambled to test the fix, schedule downtime and get the patch distributed as quickly as possible. If ever there was an occasion to use all due haste in deploying a patch, this was it. Not only was the vulnerability present in every supported version of Windows, but Microsoft officials had warned that it was a prime candidate for a worm.


Here is another one from the news.

Security Manager's Journal: When is a patch not really a patch?



[...]

If you don't reboot a Windows server after a patch is applied, the patch doesn't take effect, but SMS doesn't notice that failure to reboot. This insistence on rebooting is one of the things I dislike about Windows. In the Unix world, all that's usually required is that a particular process be restarted.


There has been lots of chatter about a flaw in Mozilla Firefox, but like many previous ones, this new vulnerability only applies to Windows, where Firefox inherits some risky behaviour which it sometimes attempts to mimic due to necessity. Why isn't the press covering this properly?

Bad, wicked Firefox, bad wicked open source...except that this trojan *only* works on Windows...which means it's bad wicked Windows, yet again. But the article never mentions this, of course.

[...]

And yes, you guessed it, it only works on Windows. So that bit about "[t]he most remarkable feature of the episode may not be the breach of security, but the cost of dealing with it" is really about the cost of using Windows - well, it's The Economist, what do you expect, accuracy? When will they ever learn?


As Glyn Moody shows, there are rare exceptions among the reporters.

The Web Vector



Adding to a mountain of reasons for infection:

1. Facebook hit by virus

"Koobface" that uses the social network's messaging system to infect PCs, then tries to gather sensitive information such as credit card numbers.


2. Most recent Windows infections result from the same simple trick

BitDefender's Top 10 E-Threats Report identifies just one type of attack as being responsible for more than a third of Windows infections in the past month: fake anti-virus scans, also known as scareware.


Attacking the Outcome, Not the Cause



Here is a good and short article titled "Punishment vs. Prevention."

Finally, I feel compelled to issue the warning, "Be careful what you wish for, because you might just get it." If the government takes over Internet security, there is sure to be a large amount of new regulation imposed. And this could mean security companies like F-Secure would have to devote a lot of resources towards compliance. I think it would be much better for us to take responsibility for finding solutions ourselves.


This is a hot topic at the moment because concerned authorities ponder tackling the zombies issues by making punishment for those caught a lot more severe. But it's totally the wrong way of addressing the issue. As Carla argues very rightly: ""Instead of Throwing Everyone In Jail, Fix Your Lousy Products"

Have any of them-- has one single vendor, whether it's Symantec or Trend or McAfee or F-Secure or anyone-- ever said "Quit throwing your money down a rathole-- stop using Windows, or at least don't put it on the Internet"? Wouldn't that little tidbit of honesty be refreshing? But no, they'll never do that. If the same conditions existed in, say, the small home appliances industry people would be getting electrocuted by their toasters and hair dryers every day, and the manufacturers would advise them to learn correct handling of live wires, and a thriving industry of insulated safety garments would prey on the survivors. If they made safety gear for swimmers it would be so bulky and uncomfortable they either wouldn't use it, or they would drown under the weight of it.

Following current trends, anyone who criticized them would be persecuted under the DMCA.


Instead of pointing a finger at those who produce and sell shoddy software, those who suffer are blamed for negligence and stricter rules are devised as means of punishment (false cure), not prevention. It won't work. The systems need to be changed, as opposed to just their side-effects.

Recent Techrights' Posts

Saudi Arabia: GNU/Linux Rose From 0.1% to 2.9% (Not Counting Chromebooks)
Notice how steep an increase
"It's recommended to disable Secure Boot for a smoother experience."
Published a few days ago
GNU/Linux Now Measured at Almost 10% in Iraq, Even Higher Than Apple
So says/sees statCounter this month
Microsoft is Political Interference
a subject that very seldom comes up in political debates
'Stochastic Parrots' is a Good Description of a Passing Fad
We did several series explaining what they are and why they won't (or can't) work as advertised
An Important Goal Has Been Accomplished Already
Stubborn activists need to insist on a future where computer users actually control the computers they own
GNU/Linux up to 5% in Ireland, Not Counting Chromebooks
statCounter is an Irish
The War on Free Software Reporters - Part III - Doxing and LARPing
LARPing is an issue I've had to deal with for nearly 20 years
 
Evri Killed Customer Support in Favour of a 100% Useless Chatbot That Wastes Your Time, Solves Nothing, and Gaslights You
They used to be known as Hermes UK; changing the name won't help dodge bad reputation
[Meme] "Make It Seem Like a Social Justice Issue"
Among Us Meeting meme
Janus Atienza (UNIX Men) Seems to Have Resorted to Garbage From LLMs, Disguised as 'Linux' 'Articles'...
Two examples from the past 24 hours (that's all of them)
[Meme] Steve Ballmer Explains WSL
"I have 3 words for you."
Help of Cover Issues of Interest
To be eagle-eyed and on top of issues we depend on input, including pointers
Free Software Foundation Has a New Recruit, Anouk Rozestraten
We only recently learned why the FSF no longer mentions public talks of its founder
[Meme] Microsoft Politicians
Microsoft gets to decide who can and cannot speak to representatives (politicians)
Windows Has Fallen to Just 11.9% in India (on Desktops/Laptops GNU/Linux Rose to 15%, on All Device Types Android Rose to All-Time High of Over 78%)
So only about 1 in 9 Web requests in India comes from Windows
Birds Don't Understand They're Free (Until Someone Cages Them)
In order to advocate and advance Software Freedom we'll need to illuminate the underlying problem/s
GNU/Linux is Hungry in Hungary
"GIVE DE MONEY BACK TO THE HUNGARY PEOPLE"
[Meme] Daniel Pocock Against GAFAM Interference in Irish Politics (for Tax Evasion and More)
Ireland rugby: Out of my way, I'm richer than you are
They're Trying to Kill the Internet Archive (and Wayback Machine). The Internet Archive Needs Your Help.
donate to the Internet Archive
A Record Week and Another Historic Day Next Monday
7 days from now the sister site turns 20
What GAFAM-Funded Organisations Tell You About Mr. Pocock is Untrue
Pocock, like Julian Assange, isn't the bad guy here. But some powerful people want you to think that he is.
Mr Pocock for Midlands-North-West (Ireland)
Mr Pocock has been vilified by those whom he exposed
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, June 02, 2024
IRC logs for Sunday, June 02, 2024
Egypt: GNU/Linux Exceeds 6%, Windows Down to All-Time Low of 5%
Not counting ChromeOS
Gemini Links 03/06/2024: Maturity and Tenstorrent
Links for the day
In the Month of May 2024 the OSI's Blog Was Almost 100% Microsoft Lobbying, Microsoft Staff, Microsoft Proprietary Software, and Microsoft Events
Entryism complete. RIP, OSI.
Gemini Links 02/06/2024: Delayed Disappointment
Links for the day
statCounter: GNU/Linux on More Than 1 in 5 Desktops/Laptops
Desktop Operating System Market Share Norway
Reminder: The First CEO of IBM (Owner of Red Hat) Was "Convicted on Extortion" (According to Edwin Black, Author of "IBM and the Holocaust")
Red Hat is not a liberal company
GNU/Linux Market Share in Turkey Now Exceeds 10%, According to StatCounter
StatCounter (or statCounter) shows considerable increases
GNU/Linux in Germany: The Seven Percent
The historical data shows that it wasn't always like this
Slovenia: Windows Becomes Minority Market Share This Month
It finally happened. Android is now measured as bigger than Windows.
statCounter: Bing Has Lost Market Share Since the Chatbot Hype, in Europe Yandex Nearly Exceeds Bing Now
Bing also had many layoffs (not that the media bothered covering that); we must debunk Microsoft's baseless claims and deliberate lies/hype
Microsoft Windows Falls Below 10% in Africa, Down to About 20% in Asia
The future isn't Windows
Taiwan Can Defend Its Autonomy Better by Avoiding Microsoft (Back Doors)
Maybe it's just a coincidence that GNU/Linux "took off" when Hong Kong lost its perceived independence from China
The War on Free Software Reporters - Part IV - Impersonation and Menacing Behaviour, Defamation Under One's Own Name
Such serial defamation (that went on for a very long time) is coordinated and relentless
Links 02/06/2024: Workers' Strikes and a Warming World
Links for the day
Microsoft Falls to All-Time Low of 25% in Operating Systems
If Android is counted, Windows is in trouble as it's down to all-time low of 25%
Steam Survey: GNU/Linux Up, But Canonical's Ubuntu Declining
big increases for GNU/Linux, Arch Linux gaining at Ubuntu's expense
Guardian Digital, Inc (linuxsecurity.com) Leveraging Microsoft Chatbots to SPAM for Microsoft (Googlebombing "Linux")?
Welcome to the Web in 2024. Search for "Linux" news, get Windows garbage.
Smallest Number of New Debian Developers in More Than 2 Years
Maybe Debian should recognise there's a problem instead of trying to censor - at humongous expense - those who speak about the problem
Slashdot's "Linux" Section is Reposting Press Releases for Red Hat
Is this being paid for?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, June 01, 2024
IRC logs for Saturday, June 01, 2024
Links 01/06/2024: Microsoft Chaffbot Broken Out of Control
Links for the day
The Media Finally Admits (on a Regular Basis) That LLMs Suck
They could not replace medical doctors, teachers, lawyers etc.
Why We're Taking Things Up a Notch
Expect about 20 articles a day this year
Sites That Cover WSL Are Helping Microsoft's Attack on GNU/Linux
Calling out the typical culprits
Plans for June
We'll try to publish Daily Links every time we have enough of these
Links 01/06/2024: Ukraine Updates, MongoDB Collapses
Links for the day
Gemini Links 01/06/2024: MNT Pocket Reform, Gemini and Content Length
Links for the day
Links 01/06/2024: WeblogPoMo2024, Pentagon’s Increasing Reliance on (i.e. Bailouts to) Microsoft
Links for the day
Twitter is (in Many Ways) Already Dead
Put an 'X' on it
Posts About Free Software, BSD, and GNU/Linux
Focus shifts have occasionally been discussed here over the years
After Softpedia Pushed Out Its Linux News Editor - and Effectively Killed the Linux Section - it Killed the Whole News Section (Altogether)
So they've killed Linux coverage, then their whole "news" section died
Their Goal is Control, Not Security (and Their Staff Advocates Fake Security or Pricey Gimmicks That Disempower the Users)
Those companies just want control, or simply domination over users (and their computers)
[Meme] The Lowest Standards of Security
No need for any qualifications
IRC Proceedings: Friday, May 31, 2024
IRC logs for Friday, May 31, 2024
Over at Tux Machines...
GNU/Linux news for the past day
Cybersecurity is a structural not behavioural problem.
Reprinted with permission from Cyber|Show
Free Software is the Future, Open Source is Just Openwashing (Proprietary With a False Marketing Twist)
Also see postopen.org
Society Has Been Destabilised by Social Control Networks
Is it time to get rid of them, if not by sanctions/bans then simply by popular boycotts?
Gemini Turns 5 This Month
As long as Geminispace exists and is accessed by enough people, Gemini Protocol will continue to matter
Links 01/06/2024: More Crackdowns in Hong Kong, Street Named After Navalny
Links for the day