The blog

Internet Explorer Compatibility Evaluator

Microsoft’s browser development group has released a new Internet Explorer Compatibility Evaluator:

IECE is designed to help IT professionals evaluate changes in behavior of web applications and web sites caused by the new security features in Windows XP with Service Pack 2 (SP2) and test for compatibility when moving from Windows XP to Windows XP Service Pack 2. It does this by:

  • Identifying issues and blocks to web site functionality
  • Identifying the cause of a block and specific details to identify the location of the problem

After installing Windows XP with SP2 and IECE, you can begin testing web sites and web applications. When a security feature blocks an action, new information will be entered in the test log including details such as:

  • A time stamp
  • The URL where the block occurred
  • The security feature involved
  • The URL zone
  • A link to information on how to fix this error
  • Automatic mitigation (if available)

If you design Web sites, this should be very helpful.

Still more details on the TiVo-Comcast deal

Via Shelly Palmer, here’s the text of TiVo’s 8-K with the SEC, which lays out more details about its deal with Comcast. It doesn’t contain any financial terms (those will presumably be in the full agreement, which will be filed as an attachment with the upcoming 10–K).

Everything up to this point has been press releases and spin. This document is filed under threat of criminal penalties for misstatements or omissions. So it’s worth a careful read. I went back and read this sentence twice:

Pursuant to our agreement, we have agreed to develop a TiVo-branded software solution for deployment on Comcast’s DVR platforms, which would enable any TiVo-specific DVR and networking features requested by Comcast, such as WishList^™ searches, Season Pass^™ recordings, home media features, and TiVoToGo^™ transfers.

What does “any TiVo-specific features … requested by Comcast” mean? Does Comcast get to decide which TiVo features get passed along to its customers? If I read this correctly, the agreement gives Comcast a veto power similar to what DirecTV has used to restrict deployment of features from the Series 2 platform.

Online storage made simple

Back in the dot-com heyday, I reviewed five online file-storage services for an article on a Web site that long ago crumbled into pixel dust. Two years later, only one of those companies was still in business. Most people, it turned out, weren’t willing to pay for the privilege of saving files to a distant server.

Fast-forward to 2005, and take a look at Box.net. This new online service, barely a month old, is trying to revive the online-storage business. I was skeptical at first, but after a few days of using the service I think they might have what it takes to stick around.

Continue reading “Online storage made simple” →

What does TiVo really get from the Comcast deal?

I just read the Comcast press release to see exactly what sort of deal Tom Rogers negotiated for TiVo:

Under the terms of the agreement, Comcast and TiVo will work together to develop a version of the TiVo service that will be made available on Comcast’s current primary DVR platform. New software will be developed by TiVo and will be incorporated into Comcast’s existing network platforms. The new service will be marketed with the TiVo brand, and is expected to be available on Comcast’s DVR products in a majority of Comcast markets in mid-to-late 2006.

This long-term, non-exclusive partnership will provide millions of Comcast customers with the opportunity to choose the TiVo service, including TiVo’s award-winning user interface and features like Season Pass(TM) and WishList(TM), as an additional option. In addition, the service will showcase TiVo’s home networking, multimedia, and broadband capabilities.

My interpretation:

  • “a version of the TiVo service” = Comcast gets to pick and choose the features it wants to offer
  • “available on Comcast’s current primary DVR platform” = TiVo will have to make the software run on a Motorola or Scientific Atlanta DVR box
  • “New software will be developed by TiVo” = some elements of the TiVo interface
  • “long-term, non-exclusive partnership” = Comcast will use its deals with other suppliers (including Microsoft) to play hardball in negotiations, making it difficult for TiVo to make money on the service
  • “the opportunity to choose the TiVo service” = you’ll have to pay extra

TiVo is negotiating from a position of weakness, and it’s not likely they were able to squeeze out too many terms that are in their favor. The devil is in the details, of course, but this press release clearly positions TiVo as a “premium service.” Cable customers who choose the Comcast DVR are already paying for basic service. Can TiVo really be successful with a business model that depends on customers paying an extra monthly fee on top of an already-high cable bill? I suspect most people will choose to see whether they can tolerate the basic DVR service and will only pay for the upgrade if the experience is unbearable.

Update: The New York Times says TiVo service will indeed cost extra: “The new deal calls for TiVo to create software that can be downloaded and run on the Motorola video recording set-top boxes. It would be offered for a higher monthly fee than the generic Comcast version, which would still be available.”

 And the Seattle P-I has a quote from Shari Glusker, a group product marketing manager in Microsoft’s TV division, who confirms that competition will be alive and well: “The partnership between TiVo and Comcast is not limiting to us in any way. While for both basic and ‘power user’ DVR functionality, TiVo and Foundation Edition are very close feature-to-feature, Foundation Edition is a much more comprehensive digital TV software solution that enables operators to give their customers simple and elegantly integrated control of advanced digital TV services like VOD, DVR, HDTV and Interactive Program Guides. That makes Foundation Edition a very compelling solution for the operator that wants to be competitive in the long run.”

Search the top blogs

Via Search Engine Watch comes this news of a Top Blogs Search feature at A9.com, the experimental search engine from Amazon.com.

Search a constantly updated set of recent blog entries from over three hundred of the most influential English language blogs on the web.

Imagine my (pleasant) surprise when I searched for “Firefox” and an entry from this blog popped up.

You can add the Top Blogs search as a column at A9.com. For an overview of how this search engine works, see Why use A9.com?

Oh, and here’s a money-saving tip: If you’ve been meaning to experiment with A9.com, try launching your searches from the Amazon.com home page after signing in. Do this once or twice a day for a few days and you’ll earn a 1.57% discount on Amazon purchases. (Why 1.57%? I have no idea. But who am I to turn down an easy discount?)

More on the TiVo-Comcast deal

Tivo_logoTiVo’s stock went up 70% yesterday on the news that it had signed a deal with Comcast. But is it really a good deal for TiVo? This revealing paragraph was in The New York Times this morning:

The Comcast deal, completed late Monday, was spearheaded by Tom Rogers, a former executive of NBC Cable, who is now vice chairman of TiVo’s board. In an interview yesterday, Mr. Rogers said that the economics of the current deal were better for TiVo than the one it had walked away from last year.

“Each side gained a greater appreciation of how working together would be a benefit,” he said.

TiVo fans and stockholders might want to look carefully at Tom Rogers’ track record on earlier deals. It’s not a pretty sight.

Continue reading “More on the TiVo-Comcast deal” →

Uh-oh. Some people don’t like criticism of Firefox

In the comments to yesterday’s post on spyware being delivered to Firefox users, Suzi of Spyware Warrior says:

Excellent analysis and write up, Ed. Your write up is quite a contrast with this newsletter from Spywareinfo.com.

I’d be interested in your comments regarding the editor’s article on Firefox and spyware.

The newsletter article that Suzi refers to was written by Mike Healan. I received a copy of it via e-mail earlier this week and considered referring to it in my original write-up. I chose not to do so in that post, because I wanted to stay focused on the technical issues. And the Spyware Weekly newsletter isn’t that well read (it’s apparently not a weekly, either, based on the five-week gap between the two most recent issues.)

But now that the article in question has been picked up by Chris Pirillo’s extraordinarily popular Lockergnome (in a post titled “False Claims of Firefox Spyware Epidemic”), I guess it deserves some comment. [Update: The Lockergnome story has now been pulled and replaced with an apology and a call for Mr. Healan to issue a correction.] 

Mike Healan’s article is, to put it mildly, shrill. After a few ad hominem attacks, complete with scare quotes, he gets to the meat of his argument:

What is truly sad here is that the news sites I mentioned earlier are portraying this as a spyware targeting and infecting the Firefox web browser. These news sites are doing a grave disservice to their readers by misleading them. This is not a problem with Firefox or with any other web browser.

The article doesn’t actually include any quotes from other reports, nor does the text link to any other discussion. Presumably, the two links at the end of his column are what Healan is referring to as “slander” and “libelous nonsense.”

My frustration with this is that people are calling it a problem with Firefox. That is patently untrue. Every single browser is going to pop up a similar warning when it encounters this particular Java applet. If this had been labeled a problem with all web browsers, it still would be untrue, but at least it would not slander a particular browser. The people publishing this libelous nonsense should be ashamed of themselves and should print a prominent correction.

Ah. So any criticism of Firefox is libel and slander, and whoever publishes any criticism or commentary should in turn be criticized. I see. Of course, if you’re going to write stuff like this, you should actually do some testing first. Although a Java-based exploit could infect any browser, this particular one is intelligent. The page in question actually looks at the browser type first. If the browser is Internet Explorer, it offers an ActiveX control. If the browser is Firefox, it uses Java. So Healan’s assertion that “every single browser is going to pop up a similar warning when it encounters this particular Java applet” is wrong. One might even call it “nonsense.”

Go back and read my analysis based on testing of the specific exploit. Firefox offers to install the Java plug-in. This plug-in, which is integrated into the Firefox browser, pops up a Security dialog box when you load a Web page in Firefox. If the user clicks Yes, the software gets installed on their system. This is the same sort of social-engineering attack that users of Internet Explorer have been wrestling with for years.

I doubt that Mike Healan has written a single line of code for the Mozilla Foundation, but he seems to take criticism of Firefox personally. Fortunately, the security professionals at the companies that develop this code don’t seem so defensive. According to eWeek, “Sun and Mozilla developers are currently working jointly to secure the browser and JRE’s ability to execute the code.”

Look, any program that allows you to connect to the Internet has the potential to be a vector for viruses and deceptive software. Any program the size of Firefox will have bugs and security holes in it. There’s already been an update that includes some important security patches. As new issues are identified, they should be dealt with promptly and openly. If people in the community think they’re doing the Mozilla Foundation a service by trying to shout down criticism or legitimate discussion of security issues, they’re wrong.

How to Destroy the Earth

Start your day with some light reading: this remarkably complete treatise on methods and materials for completely getting rid of the Earth. The good news is that it won’t be easy.

Destroying the Earth is harder than you may have been led to believe.

You’ve seen the action movies where the bad guy threatens to destroy the Earth. You’ve heard people on the news claiming that the next nuclear war or cutting down rainforests or persisting in releasing hideous quantities of pollution into the atmosphere threatens to end the world.

Fools.

The Earth was built to last. It is a 4,550,000,000-year-old, 5,973,600,000,000,000,000,000-tonne ball of iron. It has taken more devastating asteroid hits in its lifetime than you’ve had hot dinners, and lo, it still orbits merrily. So my first piece of advice to you, dear would-be Earth-destroyer, is: do NOT think this will be easy.

This is not a guide for wusses whose aim is merely to wipe out humanity. I (Sam Hughes) can in no way guarantee the complete extinction of the human race via any of these methods, real or imaginary.

Humanity is wily and resourceful, and many of the methods outlined below will take many years to even become available, let alone implement, by which time mankind may well have spread to other planets; indeed, other star systems. If total human genocide is your ultimate goal, you are reading the wrong document. There are far more efficient ways of doing this, many which are available and feasible RIGHT NOW. Nor is this a guide for those wanting to annihilate everything from single-celled life upwards, render Earth uninhabitable or simply conquer it. These are trivial goals in comparison.

This is a guide for those who do not want the Earth to be there anymore.

It is meticulously footnoted and wickedly funny. It also, for some strange reason, makes me want to see The Hitchhiker’s Guide to the Galaxy, which is, not surprisingly, listed in the footnotes.

Hh_guide

Via Bruce Schneier