Bonum Certa Men Certa

More Microsoft Cashback Flaws, Cashback Actually a Throwback, Internet Explorer Gets More New Flaws (Zero-Day)

Cash register



Summary: Microsoft's plan to "bribe" users of its search engine are flawed and are actually costing more than they save; New risks for Internet Explorer users

LAST WEEK we wrote about a Cashback flaw that led Microsoft to intimidating and harassing a blogger rather than fixing the problem [1, 2]. Mike Masnick writes about this leading to the revelation of only more problems.



I'd been meaning to write this up for about a week, but finally got it around to it, just in time to add some additional info. First up, though, comes the news that Microsoft's legal department demanded a blogger remove a blog post about flaws in Bing's Cashback offer (Microsoft's attempt to bribe users to search via Bing instead of Google). One of the methods for the cashback offer involved pixel tracking, and blogger Samir Meghani noted that this was easily gamed to post fake transactions to your account. He also noted problems with the way Microsoft used sequential IDs, allowing potential scammers to "deny cashback rebates to legitimate users by using up available order ID numbers." Instead of dealing with these flaws, Microsoft lawyers sent a cease-and-desist and forced the blog post offline. I'm actually quite surprised this hasn't received a lot more attention.


According to this new report, Bing cashback can actually be negative, i.e. only giving an illusion of savings.

So, if I go directly to butterflyphoto.com, I pay $699 with 0% cashback. If I use Bing Cashback, I pay $758 with 2% cashback, or $742.84. Using Bing cashback has actually cost me $43.84, giving an effective cashback rate of -6.27%. Yes, negative cashback! Is this legal? False advertising? I don’t know, but it’s pretty sketchy.

The problem doesn’t end there. Using Bing has tainted my web browser. Butterfly Photo set a three month cookie on my computer to indicate that I came from Bing. Any product I look at for the next three months may show a different price than I’d get by going there directly. Just clicking a Bing link means three months of potentially negative cashback, without me ever realizing it. I’m actually afraid to use their service even just to write this, because it may cost me money in the future. If you’ve been thinking about trying out Bing Cashback, you may want to rethink that.

To be fair to Microsoft, they aren’t offering negative cashback on every item at every store, but I know of more than a few instances. Let’s see if/when they decide to remove this “feature.”


So, it turns out that there is this other flaw in Cashback, albeit of a different kind. And a few days ago we wrote about an Internet Explorer 6/7 zero-day flaw which Microsoft finally confirms.

Microsoft has published Security Advisory (977981), confirming reports of a "zero day" vulnerability in Internet Explorer 6 SP1 and IE7. If you were thinking of upgrading to IE8, this would be a good time to do it. Microsoft says there have been no known attempts to exploit the security hole, but this could change at any time.


Another major bug in Internet Explorer is said to have just leaked private details from 50 million PDF files.

A bug in Microsoft's Internet Explorer browser is causing more than 50 million files stored online to leak potentially sensitive information that could compromise user privacy, a security researcher said.


As another last item, Cameron Neylon is quoted as follows: "would you...contribute to a survey on tech uptake...survey only available to those using Windows and IE"

Glyn Moody asks: "possible bias?"

Well, of course. Many surveys are just like that. By selecting the population that they reach they can impact ("cook") the outcome. Microsoft does this a lot to discredit competition.

Recent Techrights' Posts

[Video] LinuxFest Northwest is Letting GAFAM Take Over (and Why It's Hard to Resist)
Microsoft and LinuxFest Northwest
 
[Meme] Free Society Requires Free Press
The Assange decision is now less than a week away (after several delays and demand for shallow 'assurances')
CyberShow Goes "Live"
The CyberShow has a similar worldview (on technology and ethics) to ours
Latest Status of Site Archives (Static Pages)
article listings are reaching a near-final form
IRC Proceedings: Tuesday, May 14, 2024
IRC logs for Tuesday, May 14, 2024
Over at Tux Machines...
GNU/Linux news for the past day
Today's Talk by Richard Stallman Going Ahead as Planned
That talk will be in French
At This Pace (and Rate) It Won't Take Long for Android to Unseat Windows in Russia
Operating System Market Share Russian Federation
[Video] The High Cost of High-Level Tools and High-Level Programming Languages
Windows and Microsoft-style teaching remain a barrier to simple programming
Linux and Linux Foundation Leftovers
Some more Linux news
Africa is Still Android
Operating System Market Share Africa: May 2024
Windows Falls to 10% in Uganda, It Was 94% in 2010
Microsoft fell from market dominance to (soon) single digit (percent-wise).
Grouping Our Archives by Week
No more 'numbers lottery', the clustering is based on dates
Links 14/05/2024: Bounties on Terrible Patents, China Censors Dissidents Internationally via Attack Dogs
Links for the day
Gemini Links 14/05/2024: Server Failure Swallows rawtext.club
Links for the day
Links 14/05/2024: SoftBank and ARM Chasing Hype, "Why Are You Working?"
Links for the day
Links 14/05/2024: Microsoft Edelman Works for Climate Change Deniers, NATO Draws a Cyber Red Line in Tensions With Russia
Links for the day
Feasibility of Self-Hosting is About More Than Speeds
Speed helps, but the Internet (Net) is a global, interconnected system that no single person or company or government fully controls
EPO: Language of Conflict
A letter about this has already been sent
IRC Proceedings: Monday, May 13, 2024
IRC logs for Monday, May 13, 2024
Over at Tux Machines...
GNU/Linux news for the past day
Watching Our Videos Before We Write Articles for Them
It has long been possible
Microsoft is Measured at Lower Than Apple in Niger (Of Course Android Dominates)
Niger's OS share (as measured by Web sites) is subjected to significant fluctuations because it's not highly connected
Refuting the Ludicrous, Laughable Idea I Don't (or Cannot) Code
I've written code for 30 years
[Meme] "Talk is Cheap. Show Me the Code." - Linus Torvalds
be like Chad
Windows in Chad: Going Extinct
From 100% to 1%?
Doing the Site From Home (What I Always Wanted to Do)
Even some of the hosting was done from home (since 2020)
[Video] Systemd Helps Microsoft Break Apart Linux and Hijack the Vocabulary
Systemd and Halloween Documents
Links 13/05/2024: Melinda French Gates Quits Gates Foundation After Leaving Husband Over Strong Jeffrey Epstein Ties
Links for the day
Slashdot Parrots Microsoft/Red Hat PR, Sponsored by Microsoft/Red Hat
The editorial work by "EditorDavid" leaves much to be desired
Links 13/05/2024: Clown Computing Failing Again, Navalny Posthumously Awarded Prize
Links for the day
FSF-EEE (FSFE) and Microsoft, or How Microsoft Keeps Paying the Fake 'FSF Europe'
The FSF-EEE is not even authorised to use the name FSFE
[Meme] Unconstitutional Proceedings in Foreign Languages for the Benefit of Corporations Outside Europe
Why does the UPC even exist?
Android Rises to 59% Market Share in Hungary, Windows Falls to All-Time Low
GNU/Linux in Hungary Reaches 3.5%
Approaching Our 3,000th Post (After Moving to a Static Site Generator Back in September)
the main purpose is to enable people to catch up
[Video] The Microsoft Crisis Isn't Over (More Mass Layoffs Planned)
We saw many attempts at suppressing information lately
Don’t Use Disney Minus. (Disney “Plus”)
Reprinted with permission from Ryan Farmer
Links 13/05/2024: Wikimedia Rides Hype Wave, XBox Expected to Go Through More Layoffs This Summer (July)
Links for the day
Gemini Links 13/05/2024: Kingdom of the Dead and Narrative Adventure Game Gem
Links for the day
When Lunatics Attack Your Family (Especially Women)
The attacks on my wife and my mom are rather revealing. These are acts of extreme misogyny.
Visually Enhanced Interviews With ESR and RMS on Free Software (With French)
Nom de code - Linux
IRC Proceedings: Sunday, May 12, 2024
IRC logs for Sunday, May 12, 2024
Over at Tux Machines...
GNU/Linux news for the past day
GNU/Linux Rises to Record High in Macao
iOS and Android are very big there
Debian: Let's Pretend We Never Knew Daniel Pocock
Ad hominem is what happens when the message is hard to dispute