|

Vulnerability discussion around Microsoft brings up the question about responsibilities

Windows has been globally popular OS since the 90s. Although Microsoft has long faced criticism over its Windows operating system, dissatisfaction has peaked this year alongside the viral trend of the term ‘Microslop’. An increasing number of countries are seeking technological independence from American products. Privacy-oriented people probably have already read about the security a security researcher releasing GitHub repositories of multiple Microsoft zero-day exploits from beginning of this year. What makes the case especially interesting is that the researcher claims the exploits have already been reported to Microsoft without the company taking any action.

The zero-day exploits themselves are already concerning but they have also sparked a conversation about how companies address privacy threats for their users and clients. This leaves many questioning whether Microsoft is voluntarily ignoring security threats.

Microsoft is a company

Microsoft addresses common exploit attempts through security features that operate under a shared responsibility model. To give a general idea I’ll use SecureBoot, BitLocker and MFA as an example.

Secure Boot ensures a device only boots using trusted firmware and software signed by the Original Equipment Manufacturer (OEM) or Microsoft. It prevents rootkits from loading during startup.

BitLocker encrypts the storage drive to protect data at rest. It utilises the device’s TPM chip to automatically verify system integrity or requiring a PIN/password if configured.

MFA (Multi-Factor Authentication) verifies a user’s identity by requiring multiple independent pieces of evidence before granting access to network resources. Pieces of evidence are something you know (like a password), something you have (like a phone), or something you are (like a fingerprint)—ensuring that compromising one category does not compromise the others.

SecureBoot can be set from BIOS and this is where it’s the IT departments or customers responsibility to set up a BIOS password to prevent unauthorised access to change settings. Same logic goes to BitLocker – customer has responsibility of setting BitLocker up and handling security keys. Customer is also responsible of what info they use on MFA and switching the feature on at all in the first place. For companies it’s usually IT department handling security features but for consumers it’s the user. In many home user cases these features are left unused.

My point here is; Microsoft consistently structures its legal agreements to delegate security configuration and liability to the end user. It’s a company not a principle or a person.

The problem is bigger – from vulnerability discussion to surveillance

Educating users about forever changing security landscape is important. We need to have honest discussions about how compromising privacy actually affect on a wider scale as well as on personal level. I’m in the same boat with people that think surveillance has gone too far. Certainly not a fan of every fucking corporation getting my digital fingerprint. But there is only so much you can do at this point that it’s depressing.

Most Android phones require a Google account by default. While alternative operating systems exist they often break compatibility with banking and identity verification apps. Additionally, cell tower triangulation can determine a user’s location even without GPS, provided the phone has an active subscription.

Carrying two phones is neither cheap nor convenient—maybe I’ll just start leaving my phone at home more often.

So… What now?
Making companies respect privacy should be a stricter, legal requirement. Every time data is collected unnecessary it can still be added to the digital fingerprint making a person more vulnerable to cyber threats. Defaulting on that isn’t fair for users. I think when externalising security vulnerabilities that are disclosed companies are voluntarily making more targets to be exploited.


Read also: Windows Security and YellowKey exploit

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *