The blog

How to fumble a security update

Microsoft’s response to the current flap over “poisoned” Windows Media files is a case study in how not to respond to a security issue. On February 15, Microsoft issued two updates to Windows Media Player 10 – a comprehensive roll-up that changes the version number from 3646 to 3802, and a smaller patch that reportedly adds “additional integrity checks to the DRM [digital rights management] system.” Members of the company’s public relations team then made the rounds of the mainstream PC press announcing that the problem was solved.

No, it wasn’t. Based on my analysis, the current “fix” is inadequate, and many if not most Windows users remain unprotected from an important security flaw.

Continue reading “How to fumble a security update” →

Grateful Dead goes digital – with no DRM

Syf_headerLove the Grateful Dead? Now you can get any of the recordings in their live Dick’s Picks series over the Internet. Single songs (up to 10 minutes long, which cuts out most of the extended jams the band is famous for) are available at the iTunes store. Full tracks are available at the Grateful Dead store in 128K and 256K MP3 and lossless (FLAC) formats. The lower-quality MP3 formats cost less than the higher-quality MP3s, and the lossless files cost a few bucks more. But the prices are still not bad – $23.50 for a 4–CD set, with no shipping or handling.

I thought this explanation from the band’s production company was pretty classy:

We’ve been on the cutting edge of music distribution for more than 30 years, and the evolution to digital sharing is not surprising. Dead Heads have always honored ethical standards in their sharing, and we think this offering represents a great combination — it’s easy to use and it’s legal.

Digital sharing. Ethical standards. Legal. What a refreshing bunch of words to see in the same paragraph. Too bad the rest of the music industry can’t get on board.

An update on the Windows Media Player security snafu

eWeek’s Ryan Naraine has an excellent update on the “poisoned Windows Media files” controversy that I’ve been covering here for the past few weeks. (See this post for a roundup of the confusion over the WMP10 update; and see “Someone at Microsoft doesn’t get it,” which I posted on January 14, for details on the problem itself and Microsoft’s response.) Ryan writes:

Redmond has hemmed and hawed on its response to the threat and the circumstances of the latest admission isn’t sitting well with security researchers.

When the first red flag was raised in early January, Microsoft made it clear that the use of rigged .wmv files to exploit the DRM (digital rights management) mechanism was not a software flaw.

A week later, the company reversed course and promised new versions of WMP within 30 days. “While this issue is not the result of any exploit of Windows Media DRM, we do recognize it may cause problems for some of our customers,” the company said in a statement. To help mitigate these problems, Microsoft said the software would be tweaked to “allow the end-user more control over when and how any pop-ups display in the license acquisition process.”

I’ve just re-tested some samples of the infected Windows Media files using the latest build of Windows Media Player 10. I can’t see any difference in behavior. Meanwhile, as Ben Edelman has already documented, anyone using Windows Media Player 9 Series is still at risk, and the Windows Media Player 10 update is not listed as a Critical Update. Microsoft now says they will issue a “down-level patch” for Windows Media Player 9 users. No word on when it will be available.

Ben and I are quoted extensively in this story. As I told eWeek, I can’t figure out why no one from Microsoft bothered to call or e-mail Ben, Eric L. Howes, or me, back in January, when all of us had conducted extensive tests and published our findings. I’m also baffled that Microsoft’s Security Response Center hasn’t taken ownership of this problem. As I told eWeek, “If Windows Media Player is going to be a part of the operating system, it has to play by the same rules as the rest of the Windows team.” That means taking reports like this one seriously and making sure the update actually fixes the problem.

Comment spam under control

Since this blog opened for business in December 2002, y’all have left 700 or so comments. But the number of comments that haven’t been posted is more interesting. For several months last fall, I stopped accepting any new comments, while I figured out the best way to cope with comment spammers. I settled on MT-Blacklist, an add-in to the Movable Type software that runs this blog. Since December 15, 2004, here’s how effective it’s been.

Comment_spam_stats

That’s an average of 146 blocked comments per day, 90% of them rejected automatically. I honestly don’t know what I would do without this add-in.

I’m also not sure what I would do if I ever met a comment spammer face to face.

Why is IE7 such a big freakin’ secret?

The Internet Explorer team has a weblog, but unlike so many of their counterparts in other Microsoft product groups they seem allergic to actually using it for more than teasers and marketing doublespeak. Yesterday’s post on IE7 Platforms and Outlook Express is unfortunately typical:

We currently plan to make IE7 available for Windows XP SP2 and later. This will therefore include availability not only for the 32bit version of Windows XP SP2 but also for Windows XP Professional x64 Edition and Windows Server 2003 SP1 both of which are due to be released soon. As Dean commented in his original IE7 post on this blog we have heard the requests for support of Windows 2000 but have nothing to announce at this time…

We’ll share more details about IE7 as we get further along with the project.

No, no, no! The time to share more details about your thinking is now. Tell us what you have planned. Give us a rough idea of timelines. If you’ve heard widespread requests from the community and you don’t plan to address them, tell us why you won’t or can’t do those things. You have several hundred million customers. Why not share a little bit more?

The Longhorn team has been talking publicly about its plans for a couple of years. There are Longhorn road maps that spell out exactly what the broad outlines of the product will be. The IE7 team is a few months away from releasing a beta, which means they probably already have locked-down feature lists and quite a bit of code written. And yet they act like their product plans are classified Double Top Secret, Eyes Only.

The “we have heard the requests for support of Windows 2000 but have nothing to announce at this time” line is especially galling. Translated, it means, “Yeah, we’ve been thinking about this, but we’re not going to tell you a word about why we might or might not do it. At some point in the future, we’ll announce a decision, and it’ll be too late for you to do anything about it. Now please stop bothering us, we’re busy writing code.”

IE has a lousy reputation right now, which is why IE7 has been pushed into this year instead of waiting until next year. Want to rehabilitate the browser’s reputation? Start by trusting your customers.

Update: Be sure to read the comments posted at this entry on the IEBlog. I’m not the only one who thinks the IE7 team needs a double dose of cluefulness. In fact, I was pretty gentle, compared to commenters who said:

  • “This post is weak arrogant and full of hot air”
  • “Stop treating your readers with so little respect. Please blog more professionally. If you don’t have time because you’re working on IE7 I suggest you hire a full-time IE marketing type person who will post regularly and actually answer questions and respond to comments (not just for IEBlog, but elsewhere too). In fact, do it anyway, IE badly needs people with ‘marketing skills’.”
  • “I want you to win me back to IE, but you aren’t trying very hard.”
  • “ieblog, OTOH, just posts ‘We can’t say anything about anything’ repeatedly. This is absolutely ridiculous, there’s plenty to talk about without going anywhere NEAR future releases. I’ve seen dozens of good suggestions for blog posts on here. Sort it out.
    PS Your competition blogs far better than you:
    http://feedhouse.mozillazine.org/”

How fast is Firefox growing?

It’s all in the headline, and who you want to listen to.

VNUNet.com: Firefox market share rockets

ZDNet UK: Firefox’ growth starts to slip

Mozilla’s Asa Dotzler notes that Firefox has been downloaded more than 25 million times since its 1.0 release last November and says: “As Firefox and other Gecko-based browsers push toward 10%, IE has finally fallen under the 90% mark for the first time in WebSideStory’s tracking history.”

But a closer reading of the report from WebSideStory (a leading Web metrics firm that specializes in this measurement) tells a slightly different story. In his analysis, WebSideStory CEO Jeff Lunsford notes:

We track usage rather than downloads, however, and are seeing that the growth in Firefox’s usage has slowed slightly since its big surge in November. This is probably to be expected as we move beyond the early adopter segment. Growing concern over potential security holes in the browser might be another factor to consider. Back in December 2004, it seemed Firefox was a lock to reach 10 percent by mid-2005, ahead of the reported year end goal of the Mozilla Foundation. Given the latest growth rates, the year end target still appears attainable, but a mid-year achievement is unlikely unless we see increased marketing activity from the Mozilla Foundation.

For what it’s worth I’ve been using Firefox as my everyday browser for the past few months, but I’ll probably switch to the latest release of Maxthon (formerly MyIE2) this week. And of course I’m very interested in seeing what’s in the IE7 beta due in a few short months.

How to collect mail-in rebates

A Mail-In Rebate Junkie shares his secrets:

I am a mail-in rebate junkie.  I have saved thousands of dollars through rebate offers.  It’s a great way to get products at a reduced price, or sometimes even free!  But I often question whether it’s worth my time.  And apparently, I’m not alone.  Web sites such as the ones here, here and here show that there is a high degree of universal frustration with the mail-in rebate process.
 
But that’s exactly what makes the mail-in rebate process so rewarding and exciting!  The harder it is, the more discouraging it is for most people, and therefore fewer people wind up filing for or getting the rebates.  And if fewer people get them, that means that the companies can afford to be more generous in the rebates that they offer — a bonanza for the true mail-in rebate warriors such as ourselves.  So after years of climbing the rebate learning curve, I’ve decided to share my experiences, so that all of my fellow rebate junkies can benefit.

Most of this stuff is just plain common sense, but it’s a good checklist. Personally, I go out of my way not to buy a product if it has a mail-in rebate these days. I’ll make an exception for something like the Audiovox SMT5600 Smartphone or the Motorola MPx220 Smartphone, both of which have $150 rebates from Amazon and are on the short list for my next phone (I had an SMT5600, but Judy’s using it now). Trying to get $10 off on an antivirus program or $20 off on a new hard drive just feels like a sucker’s game to me. I’d rather just find a good price and be done with it.

(Via the indispensable Andrew Tobias, whose RSS feed is here.)

An easy solution to the AutoLink mess

Google’s new toolbar (which is still in beta) has caused a bunch of kerfuffle with its new AutoLink feature. AutoLink does to Web pages what Microsoft wanted to do with its Smart Tags nearly five years ago. Every time you visit a page, the toolbar checks to see whether anything on the page looks like an address, or a book’s ISBN number (which identifies it in online catalogs), or a FedEx or UPS tracking number.

Autolink_btnIf it finds anything in those classes of information, it changes the AutoLink toolbar button to read Show Map or Show Book Info. You click the button on the new Google toolbar and – auto-magically! – it changes the addresses, ISBN numbers, or what-have-you to links. Book links take you to Amazon.com, map links take you to Google Maps (unless you open the Options dialog box and change the setting to point to Yahoo Maps or Mapquest instead).

Just for fun, I visited the Web site of Book Soup, a wonderful independent bookseller in Hollywood. The home page lists more than 50 top-selling signed books, each with an ISBN number in the write-up. Links at the top of the page take you to listing of in-store evenets, including upcoming book signings that feature Joan Collins, Jane Fonda, and Lauren Bacall. Each write-up has a biography of the author and an ISBN number for the book that author will sign. In my browser window, a few pixels above the Book Soup logo on each oif these pages, is the Google toolbar with its enticing button that reads Show Book Info. Click it, and all of the Book Soup ISBNs get turned into links to the same book at Amazon.com. If you owned an independent bookstore, how would you like someone giving your visitors a tool that fills your carefully designed pages with links that point to your biggest competitor?

Continue reading “An easy solution to the AutoLink mess” →

A leading maker of spam software goes offline

How do spammers send out millions of messages at a time? One tool is a program called Send-Safe, which is marketed and sold by a company in Russia. Some have speculated, in fact, that the program’s makers are directly or indirectly related to the authors of the Mydoom, Bagle, and Sobig viruses.

Today, F-Secure reports that the company’s flagship Web site has been shut down. The details are interesting reading:

There are some interesting developments going on with the Send-Safe spamming tool. Together with tools like “Mailerboy” and “Darkmailer”, Send-Safe is one of the most popular tools used by spammers to send spam. Send-Safe even includes a built-in support for sending the spam via home machines infected with viruses like Mydoom, Bagle and Sobig.Whois info of send-safe.com

Various antispam organizations and authorities have tried to fight the company behind Send-Safe with little results. The company is run by Mr. Ruslan Ibragimov, operating just outside downtown Moscow.

Especially our friends at Spamhaus have aggressively tried getting the website http://www.send-safe.com shut down. Suprisingly, the site has apparently been hosted by MCI Worldcom – one of the largest service providers in the world.

But now something is finally happening, as the website has disappeared.

The screen shots provide a fascinating window into how this stuff works. If you’re a computer security wonk, the F-Secure News from the Lab blog should be in your list of must-read RSS feeds.

Windows Product Activation: The FUD continues

Geek News Central writes this morning:

Customers who purchase a computer from 20 of the industry’s leading manufacturers will have to phone home to Microsoft and announce their intention to use the operating system that came with the computer they just bought.

No, they won’t. Details here and here.

Likewise, ComputerWorld Canada writes:

Starting February 28, the company said, customers who want to re-install Windows XP would need to call a customer service representative to activate the operating system.

This one is technically true but extremely misleading. If you reinstall Windows XP using the original CD on the original computer, you don’t need to activate it, over the Internet or over the phone. The implication is that everyone who buys a PC from a major OEM will have to jump through hoops every time they have to reinstall their operating system, and that’s simply not the case.

I’m not trying to pick on these two publications or the many others that have gotten this story wrong. Microsoft has done an absolutely terrible job of publicizing the details of this change. Whoever is in charge of media relations for this new initiative has dropped the ball completely.

The worst part is that this sort of misinformation gets widely dispersed and it also gets picked up and cached by Google. In short order, it becomes conventional wisdom. It must be true, because it’s been printed in so many places.