MacDailyNews - Where Mac news comes first

MacDailyNews Poll

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

Macworld UK

TUAW

MacRumors

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Wed, Oct 08, 2008 - 03:48 AM EDT  —  AAPL: 89.16 (-8.98, -9.15%)  |  NASDAQ: 1754.88 (-108.08, -5.8%)

Microsoft tries to turn its own security flaw into commercial gain
Friday, February 25, 2005 - 11:08 AM EDT

"It looks like Microsoft tried to get a little benefit for itself when it repaired a serious security flaw," Stephen H. Wildstrom reports for BusinessWeek. In early February, "Microsoft released a patch for a 'critical' vulnerability in MSN Messenger [that] went a bit further than was strictly necessary. During the course of installing of the update, the user is offered several options unrelated to security, one of which is 'Make MSN My Home Page.' It is checked by default. So if you don't pay close attention -- and you should always pay close attention to these options when doing any sort of installation -- the next time you start IE, your home page will have changed. This is perilously close to the browser hijacking that's a characteristic of many spyware programs."

"Microsoft should be ashamed of itself for trying to turn its own security flaw to its commercial gain. There's no reason to believe that customers installing a mandatory security fix also want to change their browser home page to an MSN portal, and there's even less excuse for trying to spring a change on the unwary," Wildstrom reports. "Interestingly, the test version of Microsoft's new AntiSpyware program does something similar. When it detects a browser hijacking, it attempts to change the home page to MSN rather than to a blank page or a page of the user's choosing, in effect, hijacking the already hijacked page. It's Microsoft's privilege to set MSN as the default home page for Internet Explorer, but if the customer decides to change the setting, Microsoft should respect the choice and stop looking for sneaky ways to change it back."

Full article here.

MacDailyNews Take: Anyone on Earth surprised?

  • Social Web
  • E-mail






Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: ( = registered)

Feb 25, 05 - 12:17 pm Comment from: Jovian Mac User

Beep Beep!!

On Jupiter, we're not surprised either.

P.S. When are Apple going to open iTMS Callisto?

Beep Beep!!

MDN Magic Word "Attack".

The chanc-es of any-thing com-ing from Mars....areamilliontoone he seeeeed.

Feb 25, 05 - 12:26 pm Comment from: DudeMac

Do you remember when Microsoft use to weld the MSN icon to the Windows desktop? My old Win95 PC had that problem. It was when I downloaded Internet Explorer 4 and installed (back in the '90s of course) and it installed that MSN (Orange and White) icon to the desktop that you couldn't delete, you actually had to go into the Registry to get rid of it.

It seems that Microsoft's tactics haven't changed.

Feb 25, 05 - 12:28 pm Comment from: JadisOne

I swear, I HATE Microsoft. The deviant behavior is going to ultimately be its demise.

Feb 25, 05 - 12:28 pm Comment from: Brian Stucki

I will give them one thing. i was glad to see them have an option in their antispyware to turn it back to MSN as the homepage. Sure it was a problem them made in the first place. But when I run the Microsoft Antispyware on all the computers at work I am glad that it gives as option to return all the defaults to MSN and Microsoft stuff. It really saves the hijacked Explorers

(Yes, I know that this is a whole different matter. As for the topic at hand? I think it's poo poo.)

Feb 25, 05 - 12:33 pm Comment from: Rob

Yeah but he didn't think Mars had any water

Feb 25, 05 - 12:46 pm Comment from: Drool Tunes

All your homepage are belong to us . . .

Feb 25, 05 - 12:54 pm Comment from: Sure Am Relieved

I'm not up on the lastest legislation, but isn't there anti-spyware legislation in place whereby spyware authors can be charged?

If so, Microsoft should be charged - this is beyond shameful.

Why is it that aggressive, rip the meat off the bones lawyers become completely chicken when it comes to Microsoft?

magic word: amount - what amount of money is needed to get lawyers to do the right thing here? Have you checked m$'s bank balance?

(uncanny how applicable these magic words often are)

Feb 25, 05 - 01:09 pm Comment from: username

You know, I like to look at how a CEO looks, I think that the way they take care of themselves is a reflection on how they take care of their company.

Steve Jobs looks in great shape, he is slim, tall, and during almost all of every keynote I have ever seen him do, he was standing and walking around the whole time. He is a vegetarian, something that requires a lot of work to maintain (I know, I've tried). When you look at him, you get this sense that you are really going to like him.

Bill Gates is thin, pale, and has almost no muscle on his body. During his keynote, he was sitting down, slouched over, pointing at things and making all of his gestures in the small bubble around his face (a good indication that someone is lying).

Feb 25, 05 - 01:11 pm Comment from: SOLAR FLARE

What can I say - TYPICAL MICROSOFT!

And they wonder why they get sued!

A classic example of their covert way of taking over market share - Google should sue their ass over this!!!

Just made me remember why I have always used macs!!

Feb 25, 05 - 01:17 pm Comment from: One guy from Finland

Who cares...

Everybody buys Macs today. Nobody buys PC´s.

Feb 25, 05 - 01:20 pm Comment from: SOLAR FLARE

The sole purpose of this is to take away market share away from Googles search technology.

Surprise, surprise - guess what is at the top of the MSN homepage... yep you guessed it - MICROSOFTS NEW SEARCH OPTION!

Feb 25, 05 - 01:32 pm Comment from: Mac512

So is this part of MS's new branding program...they need a new agency. The ads running on TV to change are way so lame. Now they want to change you without knowing it. Brother Gates is the Orwellian character me thinks.

Feb 25, 05 - 01:32 pm Comment from: G-Spank

Ths is AWESOME! It shows that MS hasn't learned anythying and the ship will continue to sink. By the time they learn the lesson, Apple will have 30-40 percent marketshare..

Feb 25, 05 - 02:18 pm Comment from: Jack A

Microsoft being sneaky and unscrupulous. So what's new?

Feb 25, 05 - 02:28 pm Comment from: The Duke

Who is this Microsoft that everyone is talking about? They must be in the computer business, right? Oh wait, they make that second rate media player I deleted from my Mac the other day. I wonder why I installed that to begin with?

Feb 25, 05 - 02:41 pm Comment from: Peter

Well...

In their defense, keep in mind what the situation is. The browser has been hijacked--the home page points somewhere it shouldn't. You certainly do not want the browser to keep pointing at that page because it's likely that it will re-infect the machine. You don't want it to point at an empty page because that will confuse people who are used to the page coming up with at least some data. (Tech support call: "I ran your clean-up program and now I can't get data off the internet. When I run Internet Explorer, a blank page comes up.")

It should come up with a page that can be assured of not re-infecting the machine. That's MSN.com.

Feb 25, 05 - 02:46 pm Comment from: notatotalsucker

This crap from MS just takes the cake. And they are still getting away with it. Dumb-ass users seriously don't give a @!#$ obviously. They just put up with it. I don't know how many times I've been nearly screwed over by such tactics when I install MS stuff.

The fact that MS has to resort to such tactics suggests an inferiority complex.

I hope Apple doesn't start doing this crap (haven't noticed in the past and there's no reason to assume they will in future). I do remember a long time ago Apple tying you into their stuff...e.g. you needed their keyboards etc, but things have certainly changed on that front. However, with the amount of software they are producing lately, it seems Apple made products are the way to go anywya (but this is hardly something to complain about - if software from the likes of Microsoft, Adobe, Macromedia etc. won't improve their products, who's fault is that??)

Feb 25, 05 - 02:51 pm Comment from: loki

Aren't they also trying to profit from their lack of OS security? Apple doesn't make anti-virus or anti-spyware because their OS needs no such things. Microsoft on the other hand are releasing what are pretty much third party applications to fix the wholes in Windows from the outside....

Feb 25, 05 - 02:55 pm Comment from: DaddySteve

For the fun of it, I just did a Microsoft Search for my name. It showed some photo awards I won, some news pages with my photos, even my SETI statistics. But unlike every other search engine that put it on top, it made NO mention of my .mac photo pages.
This is not a criticism, it did find some cool new stuff, I just thought it was interesting.

Feb 25, 05 - 02:56 pm Comment from: Jerry T

I hate to say but I agree with Peter on this one.

A blank page would have most users (not all of course) thinking the "internet" is turned off some how. Most users only know how to log on and do the few tasks they need to do. Nothing more.

And MSN is the only site that M$ can direct to that they control the content. Why would they direct users to someone else’s wares.

If apple.com is down for maintenance, they don't direct users to Alienware.

Feb 25, 05 - 03:27 pm Comment from: Smithy

LOL Guy from Finland LOL

I agree with username about the condition of the CEO and the state of the company - SJ looks good, Steve Ballmer looks like a heart attack waiting to happen.

Anyway, like someone said above, no one buys PC's anymore, everybody buys Macs.

Feb 25, 05 - 03:30 pm Comment from: ed

Jerry T and Peter:
What are you talking about? This is an MSN Messenger patch for an exploitation that has nothing whatsoever to do with Internet Explorer. There is no good reason to change the IE homepage setting, other than for a cheap marketing ploy to get people to accidently try their search engine and to take advantage of the unwary who don't know how to change these sorts of settings back. I think it's horrendous, but fortunately since BusinessWeek picked it up it may backfire on them.

Feb 25, 05 - 03:34 pm Comment from: Jerry T

ED-

My apologies, I miss read. I thought this was some kind of IE "and" messenger spyware fix.

Feb 25, 05 - 03:38 pm Comment from: Jerry T

My statement above only applies to "hijacked" browser fixes.

No company, even M$ can be expected to direct people to a competitor.

Feb 25, 05 - 07:40 pm Comment from: John

LOL NO!

Feb 25, 05 - 09:17 pm Comment from: Peter

"This is an MSN Messenger patch for an exploitation that has nothing whatsoever to do with Internet Explorer."

Ed, from the article:

"When [Microsoft Antispyware] detects a browser hijacking, it attempts to change the home page to MSN rather than to a blank page or a page of the user's choosing, in effect, hijacking the already hijacked page."

As for the problem with MSN Messenger, I agree with author that this is somewhat bogus. About the only defense is, again, it could be that the MSN Messenger security flaw caused people's home pages to be compromised. Though, frankly, the "Make MSN My Home Page" should not be checked by default.

Feb 25, 05 - 10:43 pm Comment from: Less is More

They probably figure it's gonna get hijacked again straight-away so ... what the hell ... let's get MSN in there for a few minutes. C'mon M$, you can do better than that: Eliminate the option to change a user's homepage in Exploder and set it to MSN permanently!

Feb 26, 05 - 02:28 am Comment from: retro cat

Sometimes I think I am being too hard on Microsoft, that my disgust at the company is unfair.

Then they do something like this, and I am reminded that Microsoft really is scum.

This makes me want to puke.

But then I remember I am a Mac guy now, and these aren't my problems anymore. I just hope iWork 06 is good enough to drop Microsoft once and for all.

Oct 26, 05 - 05:27 pm Comment from: Haywood Jablowmi

Why didn't the author provide a means to correct the problem?

Micro$oft can you open your mouth with out showing any teeth? good... you're hired...

Reader feedback page 1 of 1 pages:

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my personal information   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below: