Bonum Certa Men Certa

Kaspersky Slams Windows for Insecurity, Microsoft Delivers Bad Patches and Leaves Windows Exposed

Eugene Kaspersky



Summary: Security guru Eugene Kaspersky has harsh words for Microsoft, which still fails to secure its platform and even patch software without breaking it

IT HAS been another tough week for Windows, which simply cannot be secured, not even with 'snake oil' software that's called "anti-virus" (unless the placebo effect counts).



A few months ago we wrote about Microsoft being allowed into Ford cars. There are already security concerns about that at Ford. They worry about Windows/WiFi in the car getting hijacked.

“Sadly, we live in a world where Microsoft pressures journalists to misreport incidents.”We wish to discuss for a moment an interesting phenomenon. When a car breaks down (let us say a Toyota), the news will say a Toyota car is having issues, it won't say that cars in general have issues. That's because the market is full of choices. Yes, choices, diversity, not "fragmentation" as Microsoft would probably put it. If "Windows" is embedded in PCs, then Windows can become interchangeable and synonymous with "computing". Then, people would not realise what's really wrong and that they also have better choices. Sadly, we live in a world where Microsoft pressures journalists to misreport incidents. Taken from a long discussion we've had by E-mails for a few days now, consider the fact that we have documented examples where journalists received mail from Microsoft's PR agencies (e.g. W-E) to tell them off and ask them to change articles about Windows security. The Inquirer is good in that regard because without much reluctance it spilled the beans when that happened. We have given articles from them where content was being tempered by Microsoft PR agencies, whose job was to spin the vulnerabilities in Vista.

Reporters who are contacted because they describe Windows security problems as just "computer problems" often cite the "popularity" myth of Windows as the cause. It's PR. Given the widespread use of GNU/Linux in servers and devices everywhere, people should struggle to reason about lack of cracking as related to "popularity". Windows is not popular by the way, it's just ubiquitous*. Moreover, Microsoft commissions and manufactures its own 'studies' where it hides flaws and reports bogus numbers. There are many examples to that effect.

Here is what Eugene Kaspersky said about Windows earlier this month:

Security chief Eugene Kaspersky has launched a scathing attack on Microsoft's security record.

[...]


There are already some new examples of Microsoft's poor patching. Last week Microsoft delivered broken/rogue security patches and later admitted the problem which had the following effect:

Microsoft confirmed today that a security update for its Excel spreadsheet had turned English text in an important Windows tool into Chinese.

The admission was the second in the past two days from Microsoft's Office team of a gaffe involving a recent security update.


How does Microsoft break languages while fixing a security problem? One might remark that this implies poor software design.

Speaking of Office, this area is in a state of transition in an economy where people use Free software or access software in the form of a service. Don Reisinger, typically a troll/baiter who writes bizarre reversals of truths at CNET, explains some of the issues and Microsoft resorts to more AstroTurfing by offering money to those who create "viral Office 2010 videos" for YouTube.

Want a chance to win $10,000 for your small Seattle business or start-up? The Greater Seattle Chamber of Commerce and Microsoft have partnered up in a contest for making videos about Office 2010.


In case it sounds familiar, it should. Microsoft also hires people to post comments favourable to Windows in social networking sites.

Anyway, going back to the subject of insecurity, someone writes a guest post at ZDNet about "the cadence of Microsoft security patches" and ECT notes that Windows is already vulnerable again, as usual.

The expected batch of patches wasn't the only thing Windows users got with Microsoft's latest Patch Tuesday update. The set of fixes was accompanied by a warning about an unpatched zero-day exploit for Internet Explorer.


All that Microsoft can offer is a workaround:

Microsoft has revised their advisory for the newest IE 0Day vulnerability to note that working exploit code is now available and that they are aware of "targeted attacks attempting to use this vulnerability." They have also created "Microsoft Fix it" links to disable and re-enable the vulnerable software components.


The Inquirer wrote:

The flaw in Internet Exploder versions 6 and 7 allows an attacker to take control of a victim's computer.


Internet Explorer was the cause of a lot of damage earlier this year [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12]. In 4 countries, authorities recommended that citizens abandon Internet Explorer. ____ * It's more about reminding reporters that people choose to buy a computer, they don't choose to buy Windows. Calling Windows "popular" is like calling cockroaches "popular" because there are many of them out there. It ought to be one of those things that people should train themselves to avoid saying because Windows is not "popular".

Recent Techrights' Posts

Passkeys Are Vendor Lock-in and Imperialism, Not Security, So Escape Them Before They Latch Onto Your Workflows
This is their 'grand vision' of computing. You merely 'rent' what you assumed you truly bought to own.
Let's Put Slop In the Casket Once and for All (Call Out the Sites and People Who Produce and Spread Slop)
Together, through a movement of integrity and solidarity, we can marginalise the spread of slop in all its forms, including code
Windows Down in the Largest Countries, Microsoft Cannot Dodge This Reality Forever
Talking about "clown" and "hey hi" (AI) - sometimes "Quantum" - is like telling bedtime stories to infantile investors who don't understand those buzzwords
Microsoft Says Demand/Budget for "AI" is Decreasing, Bing is Also Moving Down and Down This Year ("Bing Chat" Was an Utter Failure, People Want Sites, Not Slop)
Skype is about to shut down, XBox will likely die soon
Data Shows Largest EU Economies Shifting to GNU/linux
all-time highs
Microsoft President Panics Over Europe's Abandonment of Microsoft/GAFAM/Trump's USA, These Figures Show Us Why
Microsoft is bluffing
Microsoft Windows Falls Below Quarter in "Market Share" (While Microsoft Fakes Rising Dominance... in Buzzwords and Fake Accounting)
Cooking the books while Windows gets 'cooked'
 
Why Law Firms and Courts in Particular Should Dump Microsoft
Giving a notoriously corrupt and chronically law-breaking company control over one's systems and data is a recipe for disaster
Gemini Links 03/05/2025: Showerhead Mod and Micro Dosing on LSD
Links for the day
Links 03/05/2025: Bribery in Dutch Microsoft DC Probe, Zuckerberg Conflates Slop With 'Friends'
Links for the day
Today is World Press Freedom Day, 3rd of May
2025 World Press Freedom Day
Gemini Protocol's Momentum Ahead of Its 6th Anniversary (Next Month)
The more capsules go online, the more people participate in writing, not just reading
Corporate Media, a Cheerleader of Wall Street Facade, Spent Days Saying "META" and "MSFT" Lifted "the Market", But Their Debt Soared
Facebook's debt has never been higher
Microsoft Windows Falls to a Meager 9% "Market Share" in South Africa While GNU/Linux Rises Above 5% in Desktops/Laptops
South Africa is where the founder of Ubuntu (or Canonical) comes from
Links 03/05/2025: Australian Election and manpage for Gemini Considered
Links for the day
Links 03/05/2025: UK Arrests for Bribery Connected to Microsoft Datacentres
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, May 02, 2025
IRC logs for Friday, May 02, 2025
Not Just an OSU Open Source Lab Issue
Prominent and very prolific news sites about Linux ask for help
GNU/Linux Has Risen to All-Time High in South America, Windows Has Fallen a Lot Due to Android
What will the rest of the year bring?
Richard Stallman (RMS) Says US "Magats" Have Destroyed Press Freedom in the US
Now they're exporting their attacks on the media to the UK
In Africa, GNU/Linux Rose From 3% to 4% in Just Two Months
So says statCounter anyway... What will it be like by the end of this year?
Gemini Links 02/05/2025: Bandcamp and Spying "Smart Glasses"
Links for the day
Asia is Running Away From USA-ware (Trump or 'Tariff Regime'), Including Microsoft Windows
The nationalism harms Microsoft
Links 02/05/2025: Expedia Group Undergoes Layoffs, Twitter Exodus in Europe
Links for the day
Techrights Statement: The Solution is Not More Censorship or Moving to Another Mastodon Instance, the Core Problem is Social Control Media Including Mastodon
Censorship typically leads to additional (new) issues
Good News, Bad News: Groklaw is Back Online, SoylentNews Apparently Loses Editor
Jan ought to change the resignation into a mere pause
Manchester Computing Centre (MCC) Made the First GNU/Linux Distro, But You Probably Never Heard of It
People like Owen are barely remembered, not because they didn't do valuable work but because they didn't suck up to "The Establishment"
Online Mobs and Crabs: Doing to Fabrice Bellard What They Did to Richard Stallman and Linus Torvalds
They just don't want skilled people to be productive
E-mail is Not HTML, Web Pages Aren't a Form of E-mail
as an associate remains us, always use "plain text, it was good enough for Shakespeare"
Slopwatch: Stigma-Baiting by the Serial Sloppers and Latest Garbage From the Slopfarm LinuxSecurity.com (Also Slopping Away at "OpenBSD" With SEO SPAM Made by LLMs)
Microsoft et al are trying to profit from blurring away information
Links 02/05/2025: Mineral Selloff and Chinese Sanctions
Links for the day
Gemini Links 02/05/2025: Hens and Tmux
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, May 01, 2025
IRC logs for Thursday, May 01, 2025
Gopher/Gemini Links 01/05/2025: Slop/LLM Bot Troubles and Driving Angry
Links for the day
Links 01/05/2025: Apple Lies to Courts, European Patents Thrown Out by British Courts Again
Links for the day
Microsoft's CEO is Hyping Up 'AI' (Plagiarism) to Distract From Falling Interest in It and Missed Expectations (Investors Run Out of Patience as Reality Does Not Meet or Match Early False Promises)
Microsoft clearly needs 1) a distraction and 2) hype about "AI"
No, Microsoft, Plagiarism is Not "AI"
"Satya Nadella says as much as 30% of Microsoft code is written by AI"
Microsoft Has Become Almost Extinct in Web Servers, Netcraft Now Ranks It in Only One Category (Microsoft Down Sharply), Deranked/Outranked in All the Rest
Microsoft used to be in all categories, now it's in just one
Gemini Links 01/05/2025: Small Web and Going Offline
Links for the day
Microsoft Has Hundred of Layoffs Again, Same Week as the Company's Fake Results
those people were in effect Microsoft employees, just classified as contractors
Sirius Open Source in Court
I personally was a witness and an alibi
What GNU/Linux Means to Us
Linux without freedom is like becoming a vegetarian "except on special occasions"
Links 01/05/2025: Slop Blowback, Social Control Media as Vehicle of "Sextortion"
Links for the day
Disinformation and Marketing Spam From and For OIN (GAFAM's and IBM's Weapon Against Free Software Activists and Reformists Against Software Patents)
All in all, this anniversary is just a PR stunt with revisionism
Some of the Evidence We'll Be Relying Upon in the Lawsuits Against Matthew J. Garrett
Finally facing the consequences for his actions
Symptom or Hallmark of Ponzi Schemes: Microsoft Says It Gains Over 100 Million Dollars in "Goodwill" and Its Speculative "Value" Nearly Doubled to $119,329,000,000 in the Past Year Alone
Total liabilities are now over $240,000,000,000
Gemini Links 01/05/2025: Trying OpenBSD and Usenet Reborn Released
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, April 30, 2025
IRC logs for Wednesday, April 30, 2025