The blog

Got a Tablet PC? Get this add-on

Scoble points to the Experience Pack for Windows XP Tablet PC Edition 2005, which was just released today. I’ve just upgraded the hard drive on my Toshiba Portege 3500 to 80GB (up from 40GB), so I’ll have enough room to bring along some recorded TV from my Media Center when I travel, so this tool is especially nice:

Easily copy media files from your home computer (running Windows XP Home, Professional, or Media Center Edition) to your Tablet PC with Media Transfer. Queue up your favorite music, movies, and digital photo albums and copy them over a wired or wireless network. Then off you go, fully stocked with entertainment.

There’s some other interesting stuff too. Definitely worth a look.

Tip of the day: Give your taskbar twice as much room

This is one of my all-time favorite Windows tips, and it’s one of the first customizations I make on a new computer.

After you open more than three or four programs, you’ll have trouble seeing which file or program goes with each taskbar button. Here’s a great solution: increase the height of the taskbar to two lines (or even three), so you can see more buttons. Aim the mouse pointer at the top edge of the taskbar until it turns to a two-headed arrow, then drag up to create an extra row. If your screen resolution is 1024 X 768, you have room for at least two rows; at higher resolutions, you can comfortably use three rows.

After you finish this tweak, you’ll be able to see more taskbar buttons and their text labels. You’ll also find that the small icons in the Quick Launch bar and the system notification area (the “tray” at the right of the taskbar) stack up as well, giving you a lot more room in these areas, too. Even the clock changes appearance. With a two-line taskbar, you see today’s day and date along with the current time.

You may need to unlock the taskbar before you can make any changes. To do so, right-click the system clock and clear the check mark next to Lock the Taskbar). You may also need to “unhide” the Quick Launch bar (right-click any empty space on the taskbar, click the Toolbars menu, and select the Quick Launch option). Drag the right edge of the Quick Launch bar to make it wide enough to hold your icons. Remember to lock the taskbar after you finish.

How I use Gmail (new invitations available too!)

Gmail just doubled its storage limit to 2GB, with the promise of more to come. I use my Gmail account for a very specific purpose. I have e-mail newsletters and summaries of daily postings from my favorite newsgroups delivered to that address. I use filters to automatically tag each entry (the equivalent of moving it to a folder) and archive it (so my inbox isn’t cluttered). The advantage is that I have an easily accessible, searchable archive of this material, which is often useful for my professional research.

For searching through Windows-related newsgroups, I prefer Microsoft’s Web-based reader. (Bookmark this site, because it’s hard to get to from Microsoft’s main site.)

For newsgroups in other areas, or for those I want to follow daily, I set up a subscription in Google Groups and have either an abridged version or a full digest sent to my Gmail account. When I’m looking for information on a specific topic in that area, I can search using my Gmail account and find exactly what I’m looking for).

By the way, I have 50 more Gmail invitations to hand out. If you want one, send an email to edbott (at) gmail.com.

Bloglines unveils new translation

I just received this news release from Bloglines:

Bloglines, the world’s most popular free online service for searching, subscribing, publishing and sharing news feeds, blogs and rich web content, today opened the doors of its service to audiences beyond our solar system with a new translation in Klingon, the galaxy’s fastest-spreading invented language.

“The custom of sharing grand stories of conquest and battle has a long standing history among the Klingon people,” said Mark Fletcher, founder of Bloglines. “Blogging is simply an easy way to continue the tradition while stuck in deep space, away from your family. We feel that presenting Bloglines in the Warrior Tongue was long overdue.”

Klingon marks the eighth language translation for Bloglines, joining Chinese, English, French, German, Japanese, Portuguese and Spanish. To navigate Bloglines in Klingon, simply select the language from the menu on the left hand side of the Bloglines home page. To find out more about the Klingon language, visit http://www.kli.org/ or check with your local Klingon embassy. Qapla’!

I wish I knew how to say April Fool’s in Klingon.

Two tuners in your Media Center PC

Peter Near reports that Hauppauge’s PVR-500 now actually supports dual set-top boxes:

The Hauppauge PVR-500 was one of, if not the first dual tuner card on the market for MCE 2005. Many people were quickly disappointed to find that it only offers dual tuning for those using analog cable. Anyone who wanted to connect dual set-top-boxes was out of luck.

They have now released a new daughtercard that allows you to now connect dual STBs to the PVR-500. The new card installs into a PCI slot next door to the tuner card and provides additional connectors for audio and video from a second STB.

As it happens, I have a WinTV-PVR-500MCE, and it will indeed accept a second set-top box. (For a list of all the pieces in my Media Center setup, click here.) The undocumented workaround is to connect the first tuner using the coax output from the first set-top box, and the second tuner using the S-video and stereo audio connectors. I had all sorts of hassles during initial setup although I eventually got it working and it’s been rock solid since those first few days; this odd cabling may be part of the problem. It was also extremely difficult to squeeze the Hauppauge card into the tight confines of the Shuttle small-form-factor case I’m using.

The Media Center PC works extremely well with two tuners. If you’re thinking of investing in a Media Center, this is the only way to go. The system is smart enough to switch effortlessly between them, as long as both are connected to identical signal sources (in other words, you can’t have a straight cable into one tuner and a single set-top box on the second one).

I’ve been seeing some picture degradation on my MCE recordings and I’ve been meaning to run some tests to see if there’s a difference between the two tuners. I think I’ll get one of these daughtercards and see if it makes a difference. Peter mentions the EVGA dual tuner card, which has dual S-Video inputs, but that’s gotten a thumbs-down in posts at The Green Button and at HTPCNews.com. I’d love to see ATI come out with a two-tuner version of the TV Wonder Elite. (But the real killer would be a CableCard-equipped HDTV-compatible dual-tuner card, which is, alas, science fiction at this point.

Thanks for the pointer, Peter!

Is this new Firefox feature a security hole?

Earlier today I posted an item about the “link prefetch” feature recently introduced in Firefox and used by Google for all searches run using Firefox.

To see exactly how this works, I performed a simple experiment.

First, I completely deleted the contents of the Cache folder in my Firefox profile. I left the directory window visible on the screen, opened Firefox, and went to the Firefox home page. After it finished loading, I refreshed the contents of the Cache folder window and observed that there were now a few small files there.

Next, I created a simple HTML page consisting of a single sentence. That sentence contained a hyperlink to a large (2.56MB) executable file on a third-party Web site. In the source code for the page I created, just before the hyperlink, I added a LINK tag using the REL=”prefetch” type, as documented in the Mozilla Link Prefetching FAQ. I uploaded this page, which was 369 bytes in size, to my Web site.

Finally, I returned to Firefox and typed in the URL of the test page I created. My tiny page loaded immediately, and over the course of the next few seconds I watched one file in the Cache folder grow to approximately 2.6MB in size. When I clicked the link to the executable file on my test page, the Firefox Downloads window appeared and almost instantly displayed the message that the download was complete. That’s not surprising, because the executable file was already in my cache.

Let me repeat that: I clicked on a link in one page, and Firefox silently, without any indication to me, downloaded a large executable file in the background and placed it in my browser’s cache.

I repeated the experiment with a much larger executable file (10MB) from a different third-party Web site, using a completely clean Firefox profile. Same result.

If you were to click on the link to my test page using Firefox, that executable code would be on your computer, downloaded from a site you never chose to visit. Now, let me be clear: That code isn’t an immediate danger. There’s no way I’m aware of for it to execute. At least not now. But if I were a bad guy, I’d be working my tail off to figure out how to get that code to execute – or to trick you into running it. I’d also be looking at other creative ways to exploit the fact that I can get you to download scripts and other content from a third-party site that you never even realized you visited. And I would surely be thinking of how I could get my pages to appear at the top of a Google search window, where they would automatically be prefetched by Firefox.

This is not a good thing.

Update: In a comment to my previous post, Alex Halderman, a PhD student in computer science at Princeton, notes that the privacy issue is a legitimate one but the security issue is less worrisome than I might fear. He writes:

There are lots of ways a site can cause your browser to load a page from another site without your knowledge: JavaScript tricks, hidden frames, etc.  For legitimate uses, prefetching is preferable to these other methods, since the browser can be smart about only prefetching during idle periods.  Disabling the prefetch feature will preclude these benefits without actually preventing malicious sites from loading remote pages.

On the other hand, well intentioned sites like Google need to be careful about what prefetching they cause for precisely the reasons Ed cites.  Google’s users trust it not to place embarrassing content in their caches or to connect their browsers to disreputable sites.  Google says only certain sites are prefetched, and I’ll bet these concerns enter into their selection algorithm.

Prefetching is also unlikely to exacerbate a vulnerability that “allows code to be executed automatically from a page that triggers a buffer overflow or exploits an unpatched scripting exploit.” The prefetched page is not rendered and any scripts it contains are not interpreted until the user actually follows a link to it.  Only the HTTP and caching code is exposed to the prefetched data, and these relatively simple modules are less likely to contain exploitable holes.

I missed the part where Google says only certain sites are prefetched. I’ll have to look more closely at that.

Update 2: OK, I looked at the Google FAQ for Webmasters, which says, “Google only inserts this tag when there is a high likelihood that the user will click on the top result, but clearly this heuristic is not right 100% of the time.” I don’t see anything that suggests any concern for the privacy of the user or whether the content in the top-rated link is work-safe.

Update 3: Some interesting discussion of the issue here.

A new assortment of daily tips starts next week

Beginning Monday, April 4, you’ll find a new daily tip feature on this site. I’ve already prepared the first week’s worth and set them up to be served automatically every weekday, first thing in the morning. Yes, I know there are other Windows tips sites out there. My goal with this one is to avoid rehashing the same old stuff and to come up with advice that’s fresh and different, whether you’re a novice or a jaded PC user with more than a decade’s experience, like me.

I plan to set up a separate RSS feed for this collection. When it’s ready, I’ll post the URL here. I also welcome suggestions. If you’ve got an idea, feel free to post it in the comments here.

What inspired me to start this up now? Last week I had a chance to review the archives of this site, and I cringed when I read through the collection of Windows tips that I had saved from another Web site. They were created way back in 2000 and 2001, and with a few exceptions they haven’t been updated since then. A few are still useful, but many are relevant only to users of Windows 95/98/Me. I’ve removed the links to that tip collection from my archives. I’ll be deleting the pages themselves shortly and replacing them with a pointer to the new collection.

How bad is this writing? It’s so bad…

Paul Boutin has the winners of this year’s Bulwer-Lytton awards (named in honor of the novelist responsible for the prototypical worst opening line in history: “It was a dark and stormy night.”)

Here’s #10:

“As a scientist, Throckmorton knew that if he were ever to break wind in the echo chamber, he would never hear the end of it.”

Go read the rest. This year’s winners are an excellent crop. Of course, by excellent, I mean wretchedly bad.

WaPo’s new security blog finds a Firefox flaw

The Washington Post has just rolled out a new blog, Security Fix. In one of the first posts, Brian Krebs describes an e-mail he received recently, which was forwarded by someone who was concerned about phishing scams:

The phishing e-mail my contact sent tried to hijack my computer in addition to directing my browser to a Web site designed to look like it was operated by a small British bank. After I got done yelling at him for sending this little nastygram without warning me, I got to looking at it a bit more closely.

In this particular phishing scam, simply clicking anywhere in the HTML e-mail caused my Firefox browser to begin downloading a file while the fake site loaded in the background. Needless to say, I killed the download immediately.

I wish Brian had provided more details, but in any event this doesn’t sound like a good thing.

Oh, and kudos to the WaPo for putting the full text of this blog in their RSS feed.

Google adds a (dangerous) Firefox tune-up

From the Google Blog:

Now Google’s faster than ever on Firefox and Mozilla browsers. When you do a search on these browsers, we instruct them to download your top search result in advance, so if you click on it, you’ll get to that page even more quickly.

I’m not so sure I like this idea. It’s basically the “I feel lucky” option with an extra click. On a broadband connection, would I even notice the difference? On a dial-up connection, which I had to suffer with last week, it would impose a performance penalty. I’d prefer it if this were an option.

And why only for Firefox? Is there a technical reason why this can’t be done for another browser?

Updated: The more I think about this, the less I like it. What if the top search result contains content that is objectionable? If I do a perfectly legitimate search on my work computer, I have the option to avoid downloading that page based on its summary and title. But if the page downloads for me, it goes through my company’s proxy servers, where it gets logged as something I downloaded. It’s also cached on my computer. If that page happens to include porn or other unwanted content, I could get in serious trouble and even lose my job, even though I am completely innocent.

Google Help explains how to disable this feature in Firefox:

  1. Type “about:config” the address bar.
  2. Scroll down to the setting “network.prefetch-next” and set the value to “False”.

The default should be off, not on, in my opinion. A browser should never, ever download content from a site that you didn’t specifically choose to visit. What are Google’s developers thinking?

Updated again: In the comments, James Grimmelmann points out:

I agree with you that this combination is dangerous and that it should probably not be on by default for users. But I think the mistake is the browser’s, not Google’s.

After reading the Mozilla Prefetching FAQ, I think James is right. I’m particularly disturbed by this part:

A web page provides a set of prefetching hints to the browser, and after the browser is finished loading the page, it begins silently prefetching specified documents and stores them in its cache… Will Mozilla prefetch documents from a different host? Yes. There is no same-origin restriction for link prefetching.  Limiting prefetching to only URLs from the the same server would not offer any increased browser security.

So, if I understand this correctly, a Web page designer can stuff a whole bunch of links into a page and tag them with the “prefetch” relation type. If I click on that page, all those links will begin downloading to my computer automatically, even if they are on other servers. And if I do a Google search using Firefox, this will happen automatically for the first page in the search results list.

I really, really don’t like this. It’s especially ugly if someone identifies a browser flaw that allows code to be executed automatically from a page that triggers a buffer overflow or exploits an unpatched scripting exploit.

Yet another update: See this follow-up article.