There have been a lot of write-ups on this topic on Raymond Chen's blog, here is a good example:
There have been a lot of write-ups on this topic on Raymond Chen's blog, here is a good example:
The link you provide as an example suggests that this sort of thing might be done to facilitate testing, but again, that doesn't seem to be a compelling reason for not fixing it now - 'ship what you test' is a good principle, but it does not preempt 'fix known security holes.'
There was a month when 50%+ of the traffic on full-disclosure@ was just one person repeatedly announcing newly discovered problems with various Windows software that all involved search-path problems ("DLL hijacking" or related issues).
There's at least one author who is super keen on using the phrase "binary planting" to refer to a similar class of attacks.
I doubt this was intentional at first, but the fact that they don't want to fix it is very fishy.
To anyone going "but what if they replace the binary!" well then they've already gotten past the air-tight hatchway.