Tired of Playing Cyber Cop, Microsoft Looks For Partners In Crime Fighting
chicksdaddy writes: When it comes to fighting cybercrime, few companies can claim to have done as much as Redmond, Washington-based Microsoft, which spent the last five years as the Internet's Dirty Harry: using its size, legal muscle and wealth to single-handedly take down cyber criminal networks from Citadel, to Zeus to the recent seizure of servers belonging to the (shady) managed DNS provider NO-IP. The company's aggressive posture towards cyber crime outfits and the companies that enable them has earned it praise, but also criticism. That was the case last week after legitimate customers of NO-IP alleged that Microsoft's unilateral action had disrupted their business. There's evidence that those criticisms are hitting home – and that Microsoft may be growing weary of its role as judge, jury and executioner of online scams. Microsoft Senior Program Manager Holly Stewart gave a sober assessment of the software industry's fight against cyber criminal groups and other malicious actors. Speaking to a gathering of cyber security experts and investigators at the 26th annual FIRST Conference in Boston, she said that the company has doubts about the long term effectiveness of its botnet and malware takedowns.
need to crack down on the Russian government and others who just about look the other way.
If Microsoft hadn't built such insecure operating systems, the problem wouldn't be so big. This is the company that brought you Active-X, autorun, and the ability to invoke programs from spreadsheets and documents.
Few companies can claim to have caused as much cybercrime as Redmond.
dinner, dinner, dinner, dinner, dinner, dinner, dinner, dinner,
Batman
The new guys will make Microsoft look like the good cop. The no-ip service degradation was a minor inconvenience compared to what is yet to come. Lower your firewalls and surrender your sites.
Few companies can claim to have done as much fighting - or feeding - cybercrime.
There, fixed that for you.
recent seizure of servers belonging to the (shady) managed DNS provider NO-IP
That's blatantly libelous journalism right there.
1. Make email White-list based (with a choice to opt out), That will kill spam
2. Allow people to "lock" their machines so they will only download from curated sites., That will severely hurt malware sites.
3. Allow web browsers to 'block' sites/IPs on a per country basis, e.g. all of Ukraine, Russia,China,Brazil, etc, that will kill the redirect bots
4. Allow countries to place Tariffs on imported goods from countries that do not take positive action against cybercrime, nothing inspires politicians like a loss of money into the economy. Make it part of the UN, so if "proven" the UN can sanction ALL countries to add tariffs, no country can "Veto" this sanction.
5. Allow the courts to seek fines and restitution for losses from ISPs/individuals if they are notified of malware/bots and they do nothing about them, and that international cases get paid out by the offenders government (who then seeks to get the money back from the perpetrators).
6. Make 2 factor authentication the minimum standard for online activities.
So in America, Microsoft polices the internet. Who polices in real life? McDonalds? Disney?
I've used No-ip for non-mission-critical dynamic IP services and for domain registration for over 10 years. There's nothing "shady" about them.
They offer a free service that is sometimes exploited by criminals and are very responsive to reports of abuse.
Microsoft not only didn't report these criminals to no-ip- they actually sealed the court order so they could seize the domains before no-ip found out about it.
It boggles my mind that a vigilante corporation can get a court order to simply seize another companies assets.
As a "fighter" of crime, Microsoft would be in the featherweight category.
Using Microsoft's tools to fight cybercrime is bringing a knife to a gunfight.
After all, it's been found to be a criminal organization more than once in a court of law.
all the holes in Windows and commercial software that allow so many criminals to profit from the security holes?
by TheSpoom (715771) Uncaring Linux user here. I have nothing to add to this but please continue. *munches popcorn*
Microsoft has been writing poor quality software for my entire life.
The best programmers do not go to work for Microsoft. Maybe that was the case in the early 90's but it hasn't been true for decades.
To make matters worse, Microsoft does a lot of its programming in India. We all know that Indian programming is of poor quality, and the reason is not because Indian programmers are much less competent. It has more to do with the fact that in programming if two parties can't communicate completely unambiguously in one language then they have no hope of writing good software. Programmers have to be more than fluent in the language they speak with each other, they have to be scientifically precise.
People go to work for Microsoft because it's safe. There's no risk of the company going under. Risk minimizers don't write good software, because they're not very creative. They tend to keep patching up the same old crap rather than writing something new that works better.
At mature software companies hundreds of non-programmers are telling the programmers what to do, and it only gums up the works. You wind up not working efficiently, because you need too much sign off to get anything done. And once you get signoff, the hundreds of non-programmers are dictating your schedule, not quality of the code or whether it is completed to your satisfaction.
There is no one to clean up Microsoft's mess but themselves. Probably the best solution would be for the company to split up. The people who make the Xbox are probably weighed down by the rest of the company's ineptitude. I'd like to see those guys go their own way.
No-IP isn't shady any more than are steak knife manufacturers.
Can you imagine how this would sound coming from any other company?
Microsoft Looks For Partners In Crime
We need more take downs! Microsoft has known about the flaws in Windows, Office, HotMail, and Bing for many years. These services need to be seized immediately!
I would not be opposed to holding Microsoft Stockholders criminally responsible for this deliberate cooperation with criminals terrorists, and worse.
If You doubt that Microsoft works hand-in-hand with terrorists, just look at their criminal abuse of the judges on the 5th circuit who were tricked into taking down home security systems, security cameras etc. HOW MANY PEOPLE DIED BECAUSE OF MICROSOFT'S TAKEDOWN OF NO-IP.COM!?!?
Wouldn't providing a secure OS in the first place be better?
In other news, Google is the most popular site for finding <your choice of illegal material here>.
See what I did there? And how the reports of NO-IP's use for malicious software are meaningless?
The real "Libtards" are the Libertarians!
"When it comes to fighting cybercrime, few companies can claim to have done as much as Redmond, Washington-based Microsoft"
.. were not initially designed with Internet security" ref
Despite how much effort Microsoft retrospectively put into trying to change the historical facts. When it comes to causing cybercrime, few companies can claim to have done as much damage as Redmond, Washington-based Microsoft.
"Windows NT and its successors
what about the NSA? How much of this "cyber crime" is related to government monitoring. I like how the focus shifts to Russia and China at a time when the US is being criticized/ignored for leading an international spying ring! How much malware has hit the internet lead by governments working together, until its caught in the wild then they all blame each other or some group as the cause?
That's the real problem anymore, no one knows who is responsible for half the shit going on. Even better you can set-up fake groups in enemy countries to redirect any attention away from your objective. And MS seems to be behind a lot of bullshit lately after being targeted for allowing possible backdoors in its software.
They are always attacking the problem from the wrong end. They must. Once upon a time they did the right thing and tried to migrate to trusted repositories, but then they lost their nerve at the last moment and saved legacy app compatibility. Not that we trust them to fairly run the trusted repository either. They have not solved the problem because to them it is an intractable problem. The only effective solutions lead to Microsoft's demise.
Help stamp out iliturcy.
need to crack down on the Russian government
The Russian government? How about assigning responsibility where it belongs?
TFA is pure revisionist propaganda on the scale of editing Trotsky out of of pictures with Stalin. In reality, TFA should start:
When it comes to enabling cybercrime, few companies can claim to have done as much as Redmond, Washington-based Microsoft,
Plenty of us remember how fragile and colander-like most Microsoft OSs have been until VERY recently.
Creating a tool that not only aids security, but also speed, reliability, & even anonymity (more efficiently by FAR vs. browser addons + even shoring up DNS redirect weakness):
APK Hosts File Engine 9.0++ 32/64-bit:
http://start64.com/index.php?o...
(Details of benefits in link)
Summary:
---
A.) Hosts do more than:
1.) AdBlock ("souled-out" 2 Google/Crippled by default)
2.) Ghostery (Advertiser owned) - "Fox guards henhouse"
3.) Request Policy -> http://yro.slashdot.org/commen...
B.) Hosts add reliability vs. downed/redirected dns (& overcome redirects on sites, /. beta as an example).
C.) Hosts secure vs. malicious domains too -> http://tech.slashdot.org/comme... w/ less added "moving parts" complexity/room 4 breakdown,
D.) Hosts files yield more:
1.) Speed (adblock & hardcodes fav sites - faster than remote dns)
2.) Security (vs. malicious domains serving malcontent + block spam/phish & trackers)
3.) Reliability (vs. downed or Kaminsky redirect vulnerable dns, 99% = unpatched vs. it & worst @ isp level + weak vs Fastflux + dynamic dns botnets)
4.) Anonymity (vs. dns request logs + dnsbl's).
---
* Hosts do more w/ less (1 file) @ faster levels (ring 0) vs redundant inefficient addons (slowing slower ring 3 browsers) via filtering 4 the IP stack (coded in C, loads w/ os, & 1st net resolver queried w\ 45++ yrs.of optimization).
* Addons = more complex + slow browsers in message passing (use a few concurrently & see) & are nullified by native browser methods - It's how Clarityray is destroying Adblock.
* Addons slowup slower usermode browsers layering on more - & bloat RAM consumption too + hugely excessive cpu use (4++gb extra in FireFox https://blog.mozilla.org/nneth...)
Work w/ a native kernelmode part - hosts files (An integrated part of the ip stack)
APK
P.S.=> "The premise is quite simple: Take something designed by nature & reprogram it to make it work for the body rather than against it..." - Dr. Alice Krippen: "I am legend"
...apk
HAHAHAHAHAHAHAHAHAAHAHAHAHA
.... Wait really?
Nobody has done as much to enable cybercrime as Microsoft...
They cannot, they're too busy dealing with worthless information like mine.
My day
Ars Technica
TorrentFreak
Slashdot
check email
Path of Exile
OSU "rhythm game"
Netflix
I'm deadly right?
Since when does a corporation get to enforce laws? I've always been deeply disturbed by MS's role as a corporate police force, confiscating property and shutting down things. I know there is some loophole in the "cyber" laws that lets the government give them this power, but it's still disturbing that a corporation is taking over law enforcement like this. Microsoft is acting as a government, and being given powers no corporation should have.
When they're RIGHT too: How did I know that? This http://yro.slashdot.org/commen... since I had every single one of the bogus domains they seized LONG IN ADVANCE before they did what they did (to proof myself vs. such machinations, along with anyone else that used my program to do the same - PLUS to get more speed, reliability, & even anonymity as well as security too (vs. fastflux + dynamic DNS utilizing botnets)).
* :)
(My program does so, FAR more efficiently than the "so-called 'competition'" that's 'SOULED-OUT' & INFERIOR since they don't do a FRACTION of what hosts can @ faster levels of operation, in kernelmode, vs. slower messagepassing, memory overuse + CPU hogging usermode layering over already slower browsers, in addons (ala "Almost ALL Ads Blocked" - whose author wrote me by email stating "hosts are a shitty solution" & when I confronted him to PROVE that adblock could do more + more efficiently? HE OUTRIGHT RAN!)).
APK
P.S.=> From 1 of my 12 sources in the security community the complete NO-IP list was here July 2nd 2014 from one of my sources in fact -> http://yro.slashdot.org/commen... & MS' only "mistake" was underestimating the amount of traffic they were routing thru their servers, but they were FAR from "wrong" on the fact that NO-IP gets abused all to hell proven here http://blogs.cisco.com/securit... AND HERE http://labs.opendns.com/2013/0... ...
... apk
Microsoft,
Nobody asked you to play cyberpolice - you took that upon yourselves in an attempt to make yourselves look better after being the laughingstock of security experts for several decades. Lately you've been overstepping your bounds and now you're looking for other companies to join you so that you don't have to take all of the heat the next time you overstep your bounds. Good luck with that.
What we need is a government organization dedicated to keeping our networks safe. I'm thinking the exact opposite of the NSA, where instead of weakening our security and pushing to get back doors installed in everything they actually worked to protect us and promote national security.
It's like Martial Law being declared over the 2 Boston Marathon Bombers, ignoring the effects it had on all the 'normal' citizens.
In much the same way, it was lazy preventative measures that caused the need for such a drastic response.