Software Review The biggest risk with Windows: LOLBINS

Reviews reflect the reviewer's setup and methods. Check the evidence and limitations.
Thread details
Content created by
PC Security Channel
Never got a compromised installer before; looks that stats are wrong, common with AI-generated copied text.
Stats are not wrong.

What is protecting you is not you, your brain, nor your behaviors. It is probability that is protecting you from yourself.

Plus, there is absolutely nothing wrong with AI, using AI, and using it to save a huge amount of time and effort. AI makes everything much more efficient and faster. AI is an entirely legitimate "cheat code" and anyone who does not use it at this late stage is foolish or just plain stubborn or idealistic - which is fine - yet still foolish.
 
Since billions of people are involved, and billions of devices, the old dinosaur thinking of "Users want to use stuff" and allowing them to do it just that imperils everyone. The new paradigm has to shift to treating people like sheep, a surveillance state, hardware and application designs along with curated software ecosystems (like the Apple model) that give people much fewer options.

Such a system would hardly be 1984 dystopia or draconian as it sounds. It is about proper vetting of software at a larger, centralized scale than leaving the vetting up to individual companies and their very different ecosystems. For example, Google could care less if you are a crypto investor with a few million Euros in Bitcoin and you lose it all because you were dumb and downloaded a malicious Chrome browser extension that Google never reviewed. Nobody is going to hold Google responsible for your actions; it is 100% on the user.

That said, it will not change because corporations, governments, and industries earn too much profit from the current system. The more insecure the digital world is, the greater the profitability.

Plus, cannot take away toys from people that want to play with software; not enough space in mental health units and psychiatric wards. Can't be mucking up the mental ward system. That would be operationally unsound.
So is it people's fault or goverments' and in industries'? I see that you are contradicting yourself. If governments industries make more profits then it is in their favour to make systems less secure, so please tell me how this is users' fault?
 
Never got a compromised installer before; looks that stats are wrong, common with AI-generated copied text.
When leveraged effectively, AI can yield highly accurate insights. The key lies in skillfully navigating the model's parameters to optimize its output, as well as knowing how to direct the system toward the most relevant data source.

Markdown (GitHub flavored):
| Metric          | Vendor Stat                                    | Official Stat (NIST / FBI / Verizon)                   |
|-----------------|------------------------------------------------|--------------------------------------------------------|
| Daily Volume    | "30,000 websites hacked daily"                 | ~2,200 Verified Incidents Reported Daily               |
|                 | (Outdated 2013 Statistic)                      | (Source: FBI IC3 2024/25 Data)                         |
|-----------------|------------------------------------------------|--------------------------------------------------------|
| Supply Chain    | "45% of orgs impacted"                         | 30% of all breaches involve a third party              |
|                 | (2021 Prediction)                              | (Source: Verizon DBIR 2025 - Forensic Fact)            |
|-----------------|------------------------------------------------|--------------------------------------------------------|
| Education Risk  | "1 in 7 websites compromised"                  | 1,075 Confirmed Incidents in Education Sector          |
|                 | (Reflectiz Scan Data)                          | (Source: Verizon DBIR 2025)                            |

The claim that "30,000 websites are hacked daily" is a "zombie statistic" originally sourced from a 2013 Sophos Security report. It is widely considered obsolete in 2026.

The threat landscape has shifted from "website infections" to "identity attacks." While automated bots attempt millions of attacks per day (Microsoft alone blocks ~600 million daily), the number of successful compromises is different.

According to current FBI Internet Crime Complaint Center (IC3) data, there are approximately 2,200 verified cybercrime incidents reported daily in the US.

I have replaced the marketing figure (30,000) with the government-verified figure (2,200+ daily incidents) to reflect actual victimization rates rather than automated noise.

The statistics in the provided image (e.g., "1 in 7 Education sites") are Vendor Data, derived from automated scans of potential vulnerabilities. In contrast, Official Data (like the Verizon DBIR or NIST) counts forensically confirmed data breaches. Vendor data is better for assessing risk exposure, while official data is better for assessing historical loss.
 
Last edited by a moderator:
Percentage?
1768849534492.png

So neglectable, your real life observation is in line with the numbers provided by AI
 
Last edited by a moderator:
Agree; 10% stated by bazang mean when I have 20 apps installed on my PC, during the my life time, I will get two or more compromised app installers, inspite of downloading such installers from the official websites.

I did not have a single compromised app installer from official websites during the 51 years of living on this planet.
 
Last edited by a moderator:
So is it people's fault or goverments' and in industries'? I see that you are contradicting yourself. If governments industries make more profits then it is in their favour to make systems less secure, so please tell me how this is users' fault?
I never said that anybody intends or makes systems less secure by design. And governments have nothing to do with it. There is no government (not even the batshit stupid EU) that is willing to do anything more than add very modest security patch requirements onto some, not all, software publishers. No government is willing to tank the entire economy with regulations to keep users secure - at least not in the way that you think it should be done.

The reason does not matter. Virtually in all cases, 100% of the responsibility is the user's to secure the system.

No software publisher is going to go beyond a certain point to make their code secure and accommodate whatever system you have concocted. Securing that system is on you - the user. Always has been. Always will be.

You want Microsoft to be held responsible and accountable, then the "Fok Yoo" will come with a huge price tag. Windows will cost $500 or maybe even more for the Home edition. Then Microsoft will charge yearly subscription fees for security patches and hotfixes.

What parts of any of this did you not understand (it applies to all software publishers, not just Microsoft)?:

When you read a Microsoft Service Agreement or Windows EULA (End User License Agreement). You are paying for a product, yet the contract essentially says, "If this breaks your computer or loses your data, it's not our fault."

This "100% responsibility" model isn't just a Microsoft quirk; it is the industry standard for almost all commercial software. There are three primary reasons—legal, economic, and technical—why these agreements are written this way.

1. The "As-Is" Legal Shield​

Software is rarely sold as a "guaranteed product" in the same way a toaster is. Instead, it is legally classified as a license to use code. Because code is infinitely complex, Microsoft uses "As-Is" and "Where-Available" clauses to disclaim all warranties.
  • Implied Warranties: In standard commerce, there is an "implied warranty of merchantability" (the product must do what it says it does). Microsoft explicitly disclaims this to prevent users from suing if a bug causes a minor inconvenience or a major system crash.
  • Limitation of Liability: Most agreements cap Microsoft’s financial responsibility at the amount you actually paid for the software. If Windows crashes and costs a business millions in lost revenue, Microsoft’s legal "shield" ensures they are only liable for the $100–$200 cost of the license.

2. The Problem of "Correlated Risk"​

This is the biggest economic reason why software companies can't take 100% responsibility. Unlike a car manufacturer who might have a defect in 5,000 vehicles, a bug in Windows affects 1.4 billion devices simultaneously.
  • Systemic Failure: If Microsoft were legally responsible for every data loss or minute of downtime caused by a bug, a single bad update could result in trillions of dollars in claims—literally more money than exists in the company.
  • Insurability: No insurance company would ever insure a software developer if they were liable for all "consequential damages" (the indirect losses caused by a software failure).

3. The "Security is a Process" Argument​

Microsoft argues that they provide the tools, but you control the environment. They place security responsibility on you because they cannot control:
  • Human Error: If you click a phishing link or use "Password123," Microsoft argues they shouldn't be liable for the resulting breach.
  • Third-Party Software: Windows runs millions of different apps and drivers. If a 3rd-party printer driver creates a security hole, Microsoft uses their terms to ensure they aren't the ones being sued for the "weakest link" in your specific setup.

Summary of Responsibility​

FeatureWho is responsible?Why?
Code BugsUser (At your own risk)Avoids bankrupting the company over one error.
System SecurityUserMicrosoft cannot control your passwords or physical access.
Data BackupsUserStorage is local/private; Microsoft has no "custody" of it.
Initial LicensingMicrosoftThey must prove they have the right to sell you the code.
 
People that don't use AI are idiots.

Work smarter. Not harder.

But I learned everything by doing, while you and others are here asking us to do the work for you.
When I need the help of AI, I use it directly; I do not need a proxy to copy and past it for me.
I participate in the forum to read real-life experience.

And do appreciate to keep your AI-generated material for those who need to read, and not to reply to my posts at all; in return, I will do the same, and everybody live happily the way he like.
 
Spinning up an Intrusion Detection System (IDS) like Snort or Suricata is not comparable to copy-pasting a blocklist into a Pi-hole or toggling a setting in an ad blocker.

The average user doesn't track CVEs to reverse-engineer exploits. They track them to know when to patch. It is a maintenance schedule, not a capture-the-flag exercise. Smart users check CVE databases before purchase to see if that cheap IoT device is actually a structural liability waiting to join a botnet.

Your reliance on "rage bait" tactics is just noise pollution in a channel meant for structural maintenance. It’s the digital equivalent of banging on the pipes just to see if the tenants complain, it requires zero technical skill, offers no diagnostic value, and only proves you have too much free time and not enough discipline.
 
Agree with Bazang, work smarter not dumber. You can be troglodyte and not use A.I and not adapt to the future but the efficiency gains are enormous when used correctly.

On forums I like to post original content + personal opinions but even I can see the fast train that is A.I. coming and it's just going to streamline so many things.
 
So the template for answering posts in the forum, in favor of full disclosure, should be:

I am thinking of this : so i ask AI this question : here is the answer she gave : add my comments

You preserve originality by stating what you are thinking, and stating the question you asked of AI. And you add your own non-AI-generated comments.
 
Last edited:
Agree with Bazang, work smarter not dumber. You can be troglodyte and not use A.I and not adapt to the future but the efficiency gains are enormous when used correctly.

On forums I like to post original content + personal opinions but even I can see the fast train that is A.I. coming and it's just going to streamline so many things.
Or make "geniuses" out of idiots but they are always going to stay idiots.
 
Or make "geniuses" out of idiots but they are always going to stay idiots.
Your logic is the equivalent of a carpenter refusing to use a nail gun because "real men use hammers." You aren't defending intelligence, you are fetishizing manual labor.

Here is the structural reality. Tools amplify the user. If you give a force multiplier to a zero, the result is still zero. We agree on that, an idiot with a chatbot is just a faster idiot. But your refusal to acknowledge the utility of the tool doesn't prove you're a "genius", it just proves you're a legacy system waiting to be deprecated.

Refusing to adapt to the new standard environment isn't a badge of honor. It’s just obsolescence wrapped in arrogance. Enjoy your abacus while the rest of us are actually shipping code.
 
Your logic is the equivalent of a carpenter refusing to use a nail gun because "real men use hammers." You aren't defending intelligence, you are fetishizing manual labor.

Here is the structural reality. Tools amplify the user. If you give a force multiplier to a zero, the result is still zero. We agree on that, an idiot with a chatbot is just a faster idiot. But your refusal to acknowledge the utility of the tool doesn't prove you're a "genius", it just proves you're a legacy system waiting to be deprecated.

Refusing to adapt to the new standard environment isn't a badge of honor. It’s just obsolescence wrapped in arrogance. Enjoy your abacus while the rest of us are actually shipping code.
I pointed out a con of using AI. I use AI, so spare me from your nonsense. Is it your shift now or his?
 
I pointed out a con of using AI. I use AI, so spare me from your nonsense. Is it your shift now or his?
Your pivot from "AI creates idiots" to "I use AI" was executed with all the grace of a server rack tipping over. You are backpedaling. The "shift change" comment is just low-grade paranoia you're throwing out as chaff because your original argument failed a basic stress test.

In this trade, we look at the data, not the timestamp on the logs. If the logic holds up, it doesn't matter if it was written by a committee, a single admin, or a script. You are attacking the messenger because you can't dismantle the message. Stop auditing the personnel and start debugging your own contradictions.
 
I don't see it as backpeddling. The 'i use AI' is just a response to you calling him a carpenter who refuses to use a nail gun. And AI usage does sometimes make idots stay idoits. I don't see the connection between sentience 1 and sentence 2 and i fail to read an underlying motive.
 
Last edited:
I don't work so I guess I have no need for AI.
I have absolutely no need to use the latest and greatest thing just because everyone else is.
I do not read long winded AI answers here.
So I guess I'm a neanderthal, and I like it. ;)
Honestly AI disadvantages outweigh its advantage especially in education sector. Students no longer study or do research. Instead of asking AI for help, they ask AI to do the work for them.

But those who know how to use AI while keeping their work "authentic" are smart.
 
I don't work so I guess I have no need for AI.
i used AI to help me find Proven nutritional supplements for my disappearing memory. And it taught me to ask for 'double blind tests'. Not being a science student I didn't know about that before. So I ask her to find those tests after she told me about it. And it ended up finding omega-3 and vitamin B-12 (or was it B-3) that had many years of testing done with that requirement. And my pharmacist agrees. So AI is not solely useful for work-related situations.

And I find Gemini lazy. It told me about the scientific study method, but did not volunteer to search for me until I told it to go search, knowing full well during the session what I was looking for. Luckily I knew to ask for proof because I have read that the nutritional suppliment market is filled with products which only did 1 or 2 badly organzed studiies.

A smarter person would have just asked the pharmacist. :)
 
Last edited:

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top