Update: Microsoft says it expects to fight against suit becoming class action
Plaintiff is L.A. woman who was victim of identity theft
IDG News Service - SAN FRANCISCO -- A 50-year-old Los Angeles mother of two who fell victim to hackers has sued Microsoft Corp., seeking damages and an order requiring the vendor to improve its security notification system.
The suit, filed Tuesday in Los Angeles Superior Court, claims that Microsoft's "eclipsing dominance in desktop software has created a global security risk" and that the world's computer networks are now susceptible to "massive, cascading failures." The vendor is charged with violating California laws because of unfair and deceptive business practices.
The case was filed on behalf of the Los Angeles woman, but a request has been filed to certify the case as a class action, said Dana Taschner, the Newport Beach, Calif., lawyer who filed the suit.
"We represent an individual plaintiff, who is also seeking to be a class representative on behalf of all U.S. purchasers of Microsoft operating system software," he said.
Microsoft spokeswoman Stacy Drake said the company received the complaint and is reviewing it. Based on an initial review, Microsoft plans to fight the attempt to certify a class action, Drake said. Microsoft also believes the lawsuit "misses the point." The problems caused by viruses and hackers are the result of criminal acts by the people who write viruses and break into computers, she said.
Getting class certification is crucial for the case, according to Eugene Crew, a partner at Townsend and Townsend and Crew LLP, a San Francisco firm that successfully brought a class-action suit against Microsoft for overcharging for software in California.
"If Microsoft can prevent the class from being certified, that will kill the case in the crib. An individual proceeding on his own could not afford to proceed with the case just to recover the damages that he alone suffered," Crew said.
Parts of the lawsuit repeat the arguments by seven prominent IT security researchers in a report released last month. That report argued that reliance by "nearly everyone" on Microsoft products has created monolithic IT infrastructures that are less secure than relying on multiple operating systems (see story).
The Los Angeles woman suing Microsoft was a victim of identity theft, Taschner said. "She works on her home computer, and somehow her system was hacked and her name and Social Security number were used to access bank accounts and other services," he said. "She has been trying to clean up the mess."
Microsoft makes it too hard for consumers such as the plaintiff to secure their systems, Taschner said. "We are asking the court to issue an order requiring Microsoft to give better notice. The hackers are faster on the uptake than the consumer; in a strange way, the Microsoft alerts are actually causing more harm than good."
The suit mentions the Blaster worm that wreaked havoc in August, despite the fact that Microsoft in July had warned of and issued a software patch for the software bug exploited by the worm.
Microsoft's Drake said the company has made security a top priority and is committed to developing the most secure software possible and making it easier for customers to protect themselves against attacks "launched by malicious lawbreakers."
Taschner said he expects the Los Angeles Superior Court to respond to his filings next week.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Gov't Legislation/Regulation White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Gov't Legislation/Regulation Webcasts