Bonum Certa Men Certa

Microsoft and Insecurity: Vulnerabilities, Botnets, and a Whole Lot of Nerve

Hand on glass



Summary: Windows insecurity a matter of persistence, Windows botnets a lost cause, and Microsoft's staff interferes with security policy

From One Critical Vulnerability to Another



THE security problems in Windows are a never-ending problem. Those patches that we mentioned last week arrived on Patch Tuesday, as usual. Here are some of last week's articles about it [1, 2, 3, 4] and indication that Microsoft may be silencing researchers again:



Microsoft Exploits Talk Dropped From RSA Agenda



An RSA Conference presentation on Microsoft (NSDQ:MSFT) application hacks and exploits that was originally slated for Tuesday was canceled, although it's unclear why.

An RSA Conference spokesperson told Channelweb.com on Tuesday that the session appears to have been canceled in early January, but didn't offer a reason for the cancellation. A Microsoft spokesperson declined to comment on whether the session was canceled at Microsoft's behest.


Whether Microsoft was behind this or not, the company definitely had been doing such things before. There's security through obscurity and security through gagging. And in other news, "Microsoft resumes XP patch distribution; says rootkit remover coming soon"

In mid-February, Microsoft halted automatic distribution of one of its Windows patches, blaming the interaction of the patch with already-present malware on users’ systems for a rash of blue-screen-of-death reports among XP users.


Microsoft would love to just blame "a rootkit", but this was caused by lack of security in the first place. It is a circular trap that still has Microsoft deserving at least some of the blame. This problem was also covered in [1, 2].

In other news, we soon learn that "patchy Windows patching leaves users insecure," according to Secunia.

Windows users need to patch their systems an average of every five days to stay ahead of security vulnerabilities, according to a study this week.

The numbers come from a company called Secunia which just happens to be developing an all-in-one patching tool to reduce update headaches for consumers.

Stats from the two million existing users of Secunia's free Personal Software Inspector tool show the average home user needs an average of 75 patches from 22 different vendors to be fully secure. The complexity of patching means that most users are not even in the race, meaning that hackers hoping to exploit software vulnerabilities to infect vulnerable systems stay well ahead of the game.

Matters are further complicated by the variety of different update mechanisms applied by differing suppliers.


Secunia says that "The core of this patching issue is that the software industry has, so far, failed to come up with a unified patching solution that can help home users on a large scale; that is, encompassing all software programs" and as our reader put it, "Doesn't Linux have a one-stop-shop for the distro? As long as you stick with the official "repository", everything can be automatically updated, including the apps."

From One Windows Botnet to Another



Microsoft has a new zero-day vulnerability in its hands and the attempt to suspend Windows botnets is of course futile. There are just too many Windows botnets out there.

Spamhaus: Microsoft's botnet cull had little effect



Microsoft's takedown of the Waledac botnet has not been effective, according to some security researchers.

The throttling of Waledac, which Microsoft claimed to have achieved by means of legal action last week, has led to no appreciable reduction of junk mail coming from the botnet, anti-spam organisation Spamhaus told ZDNet UK on Tuesday.


We wrote about the Waledac takedown in [1, 2, 3]. Here is more new information about it:

Well, criticism has come from two main areas: Firstly, as Jose Nazario of Arbor Networks Inc. , a security solutions provider, told The Wall Street Journal, the Internet addresses that Microsoft’s lawsuit brought down could be a small percentage of those used by hackers to control the network. "The botnet will survive in many cases," said Nazario.

And Richard Cox, the chief information officer at anti-spam service Spamhaus told ComputerWorld: "If this did affect spam, we haven't noticed… Waledac was not a high threat; it's less than 1% of spam traffic.”


On the face of it, Microsoft Windows may rely on Free software to secure the Web from itself.

From Microsoft to Apple



Apple is suing Linux (we covered this in [1, 2, 3, 4, 5]). Apple becomes more of a fighting company (an aggressor), not a pacifier.

Apple is also hiring from Microsoft, based on this report about Window Snyder.

Window Snyder's first day at Apple was Monday, according to PC World. While it noted that Apple was the "third browser-maker in the past five years that has employed Snyder," it did not indicate whether she would work on the Safari browser or some other technology for the Cupertino, Calif., company.


Microsoft was spreading lies about Firefox (and sometimes GNU/Linux too), but even Snyder, who had worked for Microsoft, told them off for it*. It all happened when she worked for Mozilla, but she luckily left after using her Mozilla hat to praise Microsoft. She is going to Apple now.

From US DOJ to Microsoft



Microsoft's fairly new hire from the US DOJ is upsetting many people. Scott Charney's remarks [1, 2, 3] led to some strong reactions. "Blow me," says this one article from iStockAnalyst to Microsoft:

In short, these machines are infested (not infected, infested) because their operating system has historically been full of security holes (this has improved, especially in Windows 7, to be fair.)

So what does Microsoft propose?

So who would foot the bill? "Maybe markets will make it work," Charney said. But an Internet usage tax might be the way to go. "You could say it's a public safety issue and do it with general taxation," he said.

That's nice.

Sell an insecure operating system and then get someone else to pay a tax because they bought an arguably-defective product you sold? How about this instead Microsoft?

For each computer infested, the publisher of the operating system sold to that user is assessed a fine of US $100,000 by the Department of Justice.


Here is what The Atlantic argues:

Most opponents of a tax would say that software companies should be responsible for paying, since it's their responsibility to develop a safe product. Indeed, some criticize Microsoft for advocating a tax as an excuse to spend less of their own money developing safer software.


Also see:

Microsoft's Ideas for Making PCs Safer

Microsoft's Scott Charney Calls For Disrupting Cybercrime Activities

Microsoft Security Chief proposes taxes to protect the Internet

Microsoft moots digital healthcare tax

Microsoft's Ideas for Making PCs Safer

Microsoft and the Incredible 'Internet Usage Tax'

Say It Ain't So, Microsoft

Maybe Microsoft Vice President for Trustworthy Computing Scott Charney wanted to see if his audience was really awake. Maybe he entered a time warp and thought it was April 1st. Maybe someone gave him a funny cookie. Or maybe he really didn't think it would be sheer lunacy to suggest levying an Internet tax on Americans to pay for cybersecurity.

[...]

What Were You Thinking, Scott?

Not satisfied with blaming and seeking to punish the victim, Charney then went on to suggest the imposition of a tax on Internet users to ensure cybersecurity.

"You could say it's a public safety issue and do it with general taxation," he said.

Really, Scott? Why should we the users pay for the ineptness of software vendors? And please, don't give me that tired routine about the bad guys being out there always looking for flaws.

Let's take an analogy from real life. When you're a kid your parents tell you the rules for living safely. Don't talk to strangers or take candy from them. Look both ways before you cross the street. Don't walk down dark streets or alleys at night. Never walk between a parked van and the wall, especially at night. Keep your doors locked.


Even some Microsoft boosters disagree with Microsoft on this, whereas most are unable to sincerely criticise it [1, 2, 3]. ______ * Microsoft hates real numbers, so it manufactures its own.

Recent Techrights' Posts

GNU/Linux Growing Worldwide (the Story So Far!)
Microsoft is unable to stop GNU/Linux
Red Hat Loves Microsoft Monopoly (and Proprietary Surveillance With Back Doors)
full posting history in RedHat.com
Microsoft-Connected Sites Trying to Shift Attention Away From Microsoft's Megabreach Only Days Before Important If Not Unprecedented Grilling by the US Government?
Why does the mainstream media not entertain the possibility a lot of these talking points are directed out of Redmond?
Windows Has Fallen Below 5% in Iraq, GNU/Linux Surged Beyond 7% Based on statCounter's Stats
Must be something going on!
Read "Google Is Not What It Seems" by Julian Assange
In this extract from his new book When Google Met Wikileaks, WikiLeaks' publisher Julian Assange describes the special relationship between Google, Hillary Clinton and the State Department -- and what that means for the future of the internet
Julian Assange: Factual Timeline From an Online Friend
a friend's account
Breaking News: Assange Wins Right to Challenge Extradition to the US
This is great news, but maybe the full legal text will reveal some caveat
 
Pursuing a Case With No Prospects (Because It's "Funny")
the perpetrators are taking a firm that's considered notorious
GNU/Linux in Honduras: From 0.28% to 6%
Honduras remains somewhat of a hotspot
Good News From Manchester and London, Plus High Productivity in Techrights
what has happened and what's coming
[Video] The 'Linux' Foundation Cannot be Repaired Anymore (It Sold Out)
We might need to accept that the Linux Foundation lost its way
Links 21/05/2024: Tesla Layoffs and Further Free Speech Perils Online
Links for the day
Gemini Links 21/05/2024: New Gemini Reader and Gemini Games
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, May 20, 2024
IRC logs for Monday, May 20, 2024
[Video] Just Let Julian Assange Go Back to Australia
Assange needs to be freed
Microsoft Windows Used to Have Nearly 100% in China and Now Google Has 50% (With Android)
Will China bring about a faster "fall" for Microsoft?
The WWW declares the end of Google
Reprinted with permission from Cyber|Show
Gemini Links 20/05/2024: CMSs and Lua "Post to midnight.pub" Script Alternative
Links for the day
Brodie Robertson - Never Criticise The Linux Foundation Expenses (With Transcript)
Transcript included
Links 20/05/2024: Protests and Aggression by Beijing
Links for the day
Can an election campaign succeed without social media accounts?
Reprinted with permission from Daniel Pocock
Fact check: relation to Julian Assange, founded Wikileaks at University of Melbourne and Arjen Kamphuis
Reprinted with permission from Daniel Pocock
Gambia: Windows Down to 5% Overall, 50% on Desktops/Laptops
Windows was measured at 94% in 2015
Links 20/05/2024: Microsoft Layoffs and Shutdowns, RTO as Silent Layoffs
Links for the day
The Issue With Junk Traffic in Geminispace (Gemini Protocol)
Some people have openly complained that their capsule was getting hammered by bot
Peter Eckersley, Laura Smyth & the rushed closure of dial-up Internet in Australian universities
Reprinted with permission from Daniel Pocock
Brittany Day, Plagiarist in Chief (Chatbot Slinger)
3 articles in the front page of LXer.com right now are chatbot spew
Guardian Digital, Inc (linuxsecurity.com) Has Resorted to Plagiarism by Chatbots, Flooding the World Wide Web With Fake 'Articles' Wrongly Attributed to Brittany Day
busted
[Meme] Bullying the Victims
IBM: crybully of the year 2024
Ian.Community Should be Safer From Trademark Censorship
We wish to discuss this matter very quickly
Microsoft and Its Vicious Attack Dogs (Attacking Women or Wives in Particular)
Sad, pathetic, destructive people
Upcoming Series About the Campaign to 'Disappear' the Father of GNU/Linux
Today we have Julian Assange's fate to focus on
A Month From Now Gemini Protocol Turns 5
June 20
Colombia: From Less Than 0.5% to Nearly 4% for GNU/Linux
it's not limited to this one country
Rumour: Well Overdue Red Hat Layoffs to be Announced in About 3 Days
we know they've planned the layoffs for a while
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, May 19, 2024
IRC logs for Sunday, May 19, 2024
Gemini Links 20/05/2024: Updated Noto Fontpacks and gemfeed2atom
Links for the day
GNU/Linux in Georgia: Looking Good
Windows down from 99% to less than 33%
Tomorrow is a Historic Day for Press Freedom in the UK
Take note of the Julian Assange case
Hiding in a Forest Without a Phone and Hiding Behind the First Amendment in the United States (US)
some serial defamer is trying to invert the narrative
Links 19/05/2024: Iran's President Lost in Helicopter Crash, WikiLeaks’ Julian Assange Awaits Decisions in Less Than a Day
Links for the day
Links 19/05/2024: Microsoft Investigated in Europe
Links for the day
4 Old Articles About Microsoft/IBM SystemD
old but still relevant
Firefox Has Fallen to 2% in New Zealand
At around 2%, at least in the US (2% or below this threshold), there's no longer an obligation to test sites for any Gecko-based browser
Winning Streak
Free software prevalence
Links 19/05/2024: Conflicts, The Press, and Spotify Lawsuit
Links for the day
GNU/Linux+ChromeOS at Over 7% in New Zealand
It's also the home of several prominent GNU/Linux advocates
libera.chat (Libera Chat) Turns 3 Today
Freenode in the meantime continues to disintegrate
[Teaser] Freenode NDA Expires in a Few Weeks (What Really Happened 3 Years Ago)
get ready
GNU/Linux is Already Mainstream, But Microsoft is Still Trying to Sabotage That With Illegal Activities and Malicious Campaigns of Lies
To help GNU/Linux grow we'll need to tackle tough issues and recognise Microsoft is a vicious obstacle
Slovenia's Adoption of GNU/Linux in 2024
Whatever the factor/s may be, if these figures are true, then it's something to keep an eye on in the future
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, May 18, 2024
IRC logs for Saturday, May 18, 2024
Links 19/05/2024: Profectus Beta 1.2
Links for the day