The blog

Microsoft needs a Music Czar

Thomas Hawk points to this “personal note to Microsoft” from analyst Michael Gartenberg:

There’s no doubt that you must be frustrated. Really frustrated. After all, you were in digital music long before Apple. There were WMA players on the market long before iPod. In fact, Microsoft might have been dominant in digital music if it weren’t for that pesky little iPod thing (along with iTunes). Worse, Apple introduces a flash player years after anyone else, actually removes features and then has customers waiting 2-4 weeks to get one. Gladly waiting I might add and ignoring all those other devices your partners have brought to market. Let’s face it, you have all the tools to respond but at the moment, you seem to lack the leadership to tie it all together. You need to find someone to do for digital music what Martin Taylor is doing for Linux. You needs a master strategist that can deliver what folks like Brad Silverberg and Brad Chase did for Windows and Yusuf Mehdi did for IE back in the last century. In short, you need a digital music czar.

I would apply for this job in a heartbeat!

Firefox update is available

If you use Firefox, get Firefox 1.0.1. It includes some important security patches (including a fix that disabled IDN and thus neutralizes the security exploit I wrote about here). It’s a very small download and well worth it.

The release notes say: “Prior to installing Firefox 1.0.1, please ensure that the directory you’ve chosen to install into is clean and doesn’t contain any previous Firefox installations.” How many people do you think will actually read that? I predict most people will simply install over their existing installations.

More on Virus Hunter and BitDefender

Recently I reported on iDownload’com’s Virus Hunter, which bears a strong resemblance to the highly regarded BitDefender. (See “iDownload: A case history in unethical marketing” for more details.) I wrote to BitDefender and asked them to explain the relationship. Today, I received this reply from a spokesperson for BitDefender:

iDownload is indeed our partner and we license our technology to them; iDownload licenses further our technology to their customers under the name of Virus Hunter.

The marketing and sales operations are entirely iDownload’s responsibility (including refund policy, pricing etc). We have notified the company about the conditions under which the certifications can be used and hope such situations will be avoided in the future (as you see the respective references have been removed already).

Since I published my story two days ago, iDownload has removed the unauthorized reference to ICSA Labs.

Copy-protected CDs? Sadly, America shrugs…

eHomeUpgrade prints a press release from an organization that did a survey showing some consumers don’t mind having ridiculous restrictions placed on their rights to fairly use copyrighted material: Consumers Amenable to Music CDs With Copy Protection.

Contrary to widely held industry beliefs, U.S. consumers are not overwhelmingly antagonistic toward the concept of copy-restricted music CDs, provided these CDs come with the proper incentives, according to Parks Associates’ forthcoming report Digital Rights: Content Ownership and Distribution.

Among respondents in Parks Associates’ survey Profiles of PC Usage, when given a choice between a normal music CD and a “copy-once” CD priced $5 less, 33% of those who do not rip CDs and 27% who rip CDs preferred the copy-once CDs.”

Consumers are “not overwhelmingly antagonistic” toward copy-protected CDs. That is a pretty powerful piece of spinnin’, I must say. I shook my head as I read this cosmically stupid release, which appears to have been written to please some client who is not interested in facing reality. Please allow me to dismiss it with a few bullet points:

  • The survey says 27% of those who rip CDs were willing to take a $5 bribe that restricts their right to freely use the content on the CD. Dusting off my old slide rule, I calculated that 73% of respondents did not prefer this option. That’s a fairly large percentage of people who appear to think this idea is not so hot.
  • The opinions of those who do not rip CDs are irrelevant – and even so, the fact that only 33% of respondents would take the $5 discount was revealing.
  • Did anyone ask those taking this survey how they would feel if they learned that copy-protected CDs [have] had problems playing in some CD players and computers, prompting customer complaints and even recalls? If they knew this, would they still answer the same way?

Oh, and a 2004 poll shows that 34% of Americans think “the First Amendment goes too far in the rights it guarantees.” They’re wrong,  just like the people who said yes to this survey.

Fortunately, there are still plenty of artists who aren’t afraid of the idea that people might listen to and share their music. Today I heard an interview and live performance by Wilco on NPR’s Talk of the Nation that addressed this issue perfectly. Toward the end of the broadcast, host Neal Conan asked lead singer and songwriter Jeff Tweedy about the band’s decision to make their groundbreaking album Yankee Hotel Foxtrot available for download free on their Web site, and about their casul attitude toward fans who downloaded the follow-up CD A Ghost Is Born. Tweedy replied, “I just think that the arguments against those kinds of things are based on fear. I don’t think that as a band you should be afraid of people hearing your music and sharing it. I think it’s a great thing.”

iDownload: Follow the money

Yesterday I published two articles about iDownload.com, a company that makes a product called iSearch, which is installed using deceptive techniques. The company has recently sent cease-and-desist letters to the owners of several Web sites that referred to iSearch as “spyware” or “malware.” It also makes commercial security products, including Virus Hunter, which it sells using questionable techniques.

This morning I read the latest issue of the Windows Secret newsletter, which leads with an article by Brian Livingston that neatly sums up the issues with iDownload. I’ve done some of my own investigations, and the details collectively add up to a picture of exactly how the makers of this type of software get rich by preying on the innocent.

Continue reading “iDownload: Follow the money” →

More FUD about activation

This little bit of nonsense from Mac-centric freelance writer Ian Betteridge plopped into my RSS reader this morning: Activation becomes more annoying.

My eWeek colleague Mary Jo Foley takes a look at Microsoft’s decision to change Windows activation so that you will have no longer be able to activate via the Internet if you’re using a PC from one of the major vendors. While I can understand Microsoft’s reasons for this, it makes activation just slightly more irritating…

Which is followed by the familiar “get a Mac” coda.

Sounds horrible, doesn’t it? Oh, but wait. What Mr. Betteridge doesn’t know, because he isn’t really a Windows specialist, is that if you buy a new computer from one of these “major vendors,” you don’t have to activate it. The system manufacturer activates your copy of Windows when the computer is built. You can reinstall the operating system on that computer using the original Windows XP CD as many times as you want, with no activation required. You would need to call for activation only if one of the following circumstances were true:

  • You were trying to use the original installation CD on a different computer than the one it was purchased with. (That would be a violation of the license agreement, and that is the whole point of this change.)
  • You upgraded the system BIOS with a flash that didn’t include the System Locked Pre-installation information.
  • You replaced the motherboard with one from a different manufacturer that did not include the same BIOS.
  • You substantially changed the computer by replacing multiple components simultaneously. (A couple minor upgrades won’t do it; assuming the motherboard is from the same manufacturer, you would need to replace practically every other internal component to trigger this so-called out-of-tolerance condition.)
  • Your system has been infected by a virus that replaced the contents of the BIOS. (I can’t remember the last time I heard of one of these appearing outside of a virus-testing lab, and if you get a BIOS-level virus you have much bigger problems than activation.)

If one of these conditions is true, you will need to call a toll-free number to activate your installation. I’ve done this a few times and can report that the process typically takes less than 10 minutes. But most people who buy a computer from Dell or Gateway or HP or another of the world’s top 20 PC makers will never encounter the need to activate.

Back in 2001, when Windows XP was still in beta, I remember reading predictions that Windows Product Activation would be such an incovenience that it would result in catastrophic failure for the new OS. That didn’t happen. In fact, can you even remember the last time you thought about product activation? For most people, most of the time, it’s simply a non-issue. And that’s what this change will mean: nothing.

Update: Dell’s Web site offers a very clear explanation of the differences in activation between a retail copy (which requires Windows Product Activation) and an OEM copy that uses the System Locked Preinstallation technology. Although the specifics of this explanation apply to PowerEdge servers running Windows Server 2003, the exact same technology is used for Windows XP installations. I’ve highlighted the relevant section:

The Windows Server 2003 OS must be activated after installation. An OS installed manually using a Microsoft retail CD is activated through Windows Product Activation (WPA), which requires each installation of the OS to be activated either online or by phone through a Microsoft License Server clearinghouse.

The Windows Server 2003 CD that ships with PowerEdge servers has a built-in anti-piracy technology known as System Locked Preinstallation (SLP). The SLP feature enables administrators to bind the OS to a system’s specific hardware so that activating Windows Server 2003 is not necessary. When an SLP-enabled CD is used to install the OS, administrators need not type in a unique product key.

Because SLP-enabled CDs are designed only for clean installations of Windows Server 2003, administrators installing the OS using the CD should also boot from it. SLP is not supported while running setup.exe or winnt32.exe, because these executable files run from within an existing Windows environment.

An SLP implementation is transparent to the end user, without any noticeable difference from a manual installation using retail media. However, the SLP process works only on supported PowerEdge servers that ship with Windows Server 2003. In addition, any tampering with the SLP-enabled CD automatically invokes WPA. The SLP-enabled CD is available only for 32-bit versions of Windows Server 2003, not 64-bit versions.

This technology is available to all OEMs and is very widely used.

Update: I have posted a very detailed follow-up on the changes in Windows Product Activation and what it means for you.

iDownload: A case history in unethical marketing

Earlier today, I wrote about the efforts of a company called iDownload to suppress apparently accurate descriptions of their product by several anti-spyware activists.

Since that time, I have done more research on the company, and I can report exclusively that they have used the trademark of a widely respected security certification firm without authorization to sell a questionable product. Here are the details.

iDownload sells an assortment of what purport to be security products. If you visit their products page, you can see this logo and descriptive text for Virus Hunter:

Vh_logo

The company claims the product is certified by ICSA Labs. This is a prestigious honor and not lightly awarded. ICSA Labs is a division of CyberTrust, which was formed recently by a merger of TruSecure Corporation and BeTrusted. Its staff and management number some of the world’s foremost authorities on computer security and information technology. To earn ICSA Labs certification, a product must pass a series of stringent tests, and it can be removed if it fails the testing at any time.

When I reviewed the list of certified products at ICSA Labs’ Web site, I did not see any mention of Virus Hunter. So I fired off an e-mail to Larry Bridwell, Content Security Programs Manager for ICSA Labs. I received the following response within three minutes:

VirusHunter is NOT certified by ICSA Labs nor has it ever been submitted for testing.

We have sent a letter by post requesting that the certification claim be removed.

When I looked more closely at the Virus Hunter information pages, I found all the warning signs of an operation that should not be trusted:

  • No contact information for the company.
  • No details of the company’s management or ownership.
  • No privacy policy.
  • Exaggerated claims of security, including references to a nonexistent virus lab.
  • Appeals to fear: “DOWNLOAD NOW Hurry before you lose your system! If you have contracted a nasty virus, your system could be rotting away as you read this.”
  • Phony testimonials, including one claim that “Virus Hunter’s engine was awarded a perfect score…” with no link or even name of the source, only a date.

Vh_testimonial

The citation doesn’t mention the publication’s name, and a review of the leading publication that does tests of this sort, Virus Bulletin, does not turn up any tests of Virus Hunter – in its February 2004 issue or any other time. Interestingly, a legitimate product called BitDefender makes a remarkably similar claim in a press release on its site, dated in February 2004:

Bitdefender Standard was awarded the VB100, the Virus Bulletin certification that the product is able to detect all the viruses which are currently extant in the wild. Once again, BitDefender passed with flying colours, and the test team noticed an improvement in the overall detection rates from previous tests.

Is there a relationship between BitDefender and Virus Hunter? Yes, according to the Technology Integration section of the BitDefender Web site, which lists Virus Hunter as a “reference” on a list that includes legitimate companies like GFI, Laplink Software, and Sunbelt Software. In fact, Virus Hunter is identical to BitDefender Standard except for a few logos. See for yourself:

Vh_screen
Virus Hunter Professional (click for larger image)

Bit_def_std
Bit Defender Standard (click for larger image)

As you can see, they’re identical except for the logo, and the text in the linked “virus warnings” on the Virus Hunter Web site is absolutely identical to listings from the BitDefender encyclopedia, which is why I stated with confidence earlier that there is no “Virus Hunter labs.”

In fact, anyone who buys this version instead of the official BitDefender product is getting ripped off.

  • BitDefender Standard has a free 30–day trial. Virus Hunter doesn’t.
  • BitDefender Standard costs $29.95. Virus Hunter costs $34.95 for the download, and the company charges a mandatory shipping and handling fee of $4.95 for physical delivery of a CD to customers in the Continental United States. That’s a total of $10 more than the original BitDefender product.
  • BitDefender will accept a request for a refund. At the Virus Hunter site, the terms read: “iDownload maintains a strict no-refund policy.”

Vh_terms

Now, why would anyone want to do business with this company?

Oh, one more thing. IDownload sells its software through a secure Web site. I inspected their SSL certificate and was knocked over when I saw who had issued it:

Vh_cert

Yes, ChoicePoint, Inc., the same company that is currently “under fire for being duped into allowing criminals to access its massive database of personal information…” According to an Associated Press story, ChoicePoint has hired a retired Secret Service agent to help revamp its screening process and has “announced plans to rescreen 17,000 business customers to make sure they are legitimate.” I hope they look very closely at iDownload.