The blog

Browser speed test: much ado about nothing

Slashdot posted a link to this big browser speed comparison, and now I’m seeing all sorts of people discussing it. My reaction? Ho-hum. The author starts his piece by saying, “There is a speed war on the web.” I don’t think so. Do you really care that Opera 7.54 can load a page from a warm start .11 second faster than Internet Explorer and .86 second faster than Firefox? There are so many factors that affect performance on the Web, most of which have nothing to do with the underlying browser code.

I’ll tip my hat to this guy’s patience and skill with a stopwatch, but all this proves to me is that all of the leading browsers are fast enough.

How to fix URL typo scams

At Slate, Paul Boutin offers an interesting set of suggestions on how to fix URL typo scams.

Various studies have estimated that 10 percent to 20 percent of all hand-entered URLs are mistyped, adding up to at least 20 million wrong numbers per day. From my own experience that sounds about right—I can spell just fine but I leave out characters, transpose them, or hit the wrong key at least 10 times a day. No wonder wave after wave of entrepreneurs have fought to tap that flow and turn it into cash.

[…]

So, are we just doomed to suffer one typo traffic scam after another? Only until someone makes a software program that lets me control what to do with my typos. Here’s a simple design spec. First, intercept obvious, punctuation-challenged goofs like wwwslate.com. Second, recognize when a URL isn’t resolved by domain-name servers by detecting when Internet Explorer, Paxfire, or any other known culprit tries to serve a landing page. Third, keep a database of typo-trap URLs like htobot.com. And lastly, I should be able to manually configure the software to handle my habitual mistakes—whenever I type markrobinson.com, give me markrobinson.org instead.

Interesting idea. Actually, I’m surprised there isn’t a Firefox extension for this already!

Trend Micro fails the spyware test

A little over a year ago, I evaluated five antivirus programs and decided to switch from Norton AntiVirus to Trend Micro’s PC-cillin. Since then I’ve been happy with its performance. It updates itself regularly, identifies and quarantines those virus-infected attachments that make it past my e-mail gateway, and is generally unobtrusive.

The latest version of the software, PC-cillin Internet Security 2005, includes a firewall, a spam-blocking module, and newly added detection capabilities for spyware and adware. Based on my experiences today, the program’s developers need to go back to the drawing board.

I clicked the Scan for Spyware button to see what would turn up. I know this system is completely clean, so imagine my surprise when it informed me that it had found “3 potential threat(s).”

Tm_spyware

My goodness, how could I have missed these horrible programs? How did they sneak past my defenses and infiltrate my computer? What are these threats, anyway? I selected the first item in the list and clicked the More Information button, which took me to Trend Micro’s Web site. There I read about ADW_IEHELPER.A:

This adware is usually dropped and installed by a Trojan as BHO.DLL. Trend Micro detects the said Trojan as TROJ_LINST.A.

Once installed, it waits for the user to browse the Internet, specifically using Internet Explorer. This adware then scans the Web pages accessed by the user and highlights certain words, usually commercial items. When the mouse runs over one of these highlighted words, it displays a link to an advertising Web page that sells the said highlighted item.

Unfortunately, nothing in the Trend Micro interface actually told me which file it had detected or where it was located. That’s especially troublesome given that the removal instructions required me to manually unregister the DLL by entering its full path. The Web page also listed 13 registry keys where this evil program would insinuate itself. Only one of those keys was actually on my computer – a reference to Bho.dll. That file wasn’t on my computer, but a file called SnagItBHO.dll was. It’s a perfectly legitimate add-in for the SnagIt screen-capture program (which I used to capture the screens in this article and have used for every book I’ve written in the last seven years). SnagIt added that registry key and then created values that pointed to its add-in file. Had I followed Trend Micro’s instructions to remove this file, it would have disabled a key feature of my screen-capture program.

What about the next item on the list? The Web page for ADW_BADBITOR.A included no description, only a list of aliases and a long list of IE Favorites, program files, and Registry keys associated with it. The list of aliases made it pretty clear that Trend Micro thought I had installed a version of the ugly Lop parasite or Ezula adware. Once again, most of the files and registry keys ostensibly associated with this threat were simply not on my system. The only ones that matched turned out to be perfectly legitimate components of the BitTorrent program. Presumably, Trend Micro would have zapped BitTorrent had I allowed it to remove this threat.

The final item on the list was easy to identify. I have installed the password-revealing program Snadboy’s Revelation on this system. Fortunately, I know what that program does and also know that I installed it. Unfortunately, the More Information link led to a non-existent page at Trend Micro’s Web site.

OK, now let’s imagine that I’m not a computer professional but instead I’m a concerned Windows user. How am I supposed to react to this report? If I simply trust the software and let it remove these supposed threats, I’ve disabled three perfectly legitimate programs. When they stop working, will I connect the dots? Or will I think that the spyware I removed from my system had done even more damage than I thought?

Everyone wants an all-in-one Windows security solution –  a single shrink-wrapped magic software bullet that can snuff out viruses, spyware, adware, Trojan horses, and every other conceivable form of malware. Unfortunately, my experience with Trend Micro’s software provides at least one data point to suggest that there’s no such animal yet.

By coincidence, I ran across two recent reviews of Trend Micro’s software online, both by way of the Security Mentor blog. PC World has a review of Internet security suites that gave Trend Micro top marks for its spyware scanning. The reviews are cursory at best, and Trend Micro earned its ranking because “in our tests only Trend Micro’s suite spotted spyware infections in the Registry.” Well, on my system those scans bore no relation to the actual presence of spyware, so I can’t give the same thumbs-up. This comparative review of antivirus software in Information Security from last October doesn’t mention spyware at all, but it does provide some interesting real-world experiences on how leading security software companies deal with customers.

I’ll continue using and recommending Trend Micro’s software as an antivirus tool. But for preventing and removing adware and spyware, don’t count on it.

Mac OS X on a PC?

Kent Pribbernow is trying to stir up trouble at Digital Media Thoughts:

In a recent interview with Forbes Magazine, Steve Jobs makes the surprising claim that three of the top PC makers are asking him to license OSX for use on their PCs.

Hmmm. That might have been a smart move to make five or 10 years ago, but not now. Anyway, it’s never going to happen. Who’s going to write all those device drivers?

On the other hand, I would love to be able to run OS X on my PC, in a virtual machine powered by VMWare or Virtual PC (which would them have to be renamed Virtual Mac, presumably). I suspect that it could be done with relative ease if you could get permission to clone the Mac firmware.

Protecting kids from Kazaa

In the comments to an earlier post, Ken asks:

Is there a way, e.g., a setting from within Internet Explorer, or perhaps his antivirus program (Norton, I think), to prevent his teenage daugher (the real culprit here) from downloading this especially malicious crudware in the first place?   

Sure there is, and I’ve done it for neighbors. This assumes, of course, that they’re using Windows XP and that they are willing to enforce some serious rules. Set the daughter up with a Limited user account (LUA). Give Mom or Dad the password to the Administrator account and tell them not to share it with the kid no matter what. A user who logs on with an LUA cannot install a software program that tries to write any files outside of their own user account. They can’t make changes to global security settings, and they can’t install add-ons for Internet Explorer. In other words, they can’t be tricked into installing adware, spyware, or viruses.

The kids will scream when they can’t do what all the other kewl kids are doing, but that’s just too bad. When I set this up at my friend’s house, the deal was that if her son wanted to install any program, he first had to research it and prove that it was safe, reliable, and trustworthy. Needless to say, Kazaa never made it back onto the machine, and I’ve never had to go back and clean up a single piece of spyware. Oh, and he just made the Dean’s list.

Using Norton AV? Get this fix

Earlier this week, Symantec published technical details of a security flaw that affects many of its consumer and enterprise products. (Read Symantec UPX Parsing Engine Heap Overflow for the gory details.)

If you use Norton AntiVirus 2003 or 2005, you’re OK. If you use Norton AntiVirus 2004 or Norton Internet Security 2004, you might need to download an update manually. I don’t have Norton installed here, but if I recall correctly the default settings for Symantec’s Live Update only deliver updates to virus definitions. You may need to run LiveUpdate manually to get the updated program code.

If there are any current Norton users out there who can fill in other details, please leave a comment.

Kazaa mess hits the mainstream

An Associated Press reporter picks up the Kazaa story I wrote about last week. For the most part, the details in the short AP story are the same as those I wrote about, although I hadn’t heard this one before:

Mary Still, a lawyer representing Sharman, said in an interview that users have the option of paying $29.95 for an adware-free version.

Sounds like extortion to me. You don’t like the mess we make of your computer? Pay up. Or else.

I will open a bottle of Champagne the day Kazaa disappears from the face of the earth.

More on Macs and viruses

Remember the old Melissa virus from Word 97? It was one of the first truly widespread macro viruses, appearing for the first time in March 1999. It did the usual stuff you expect from a mass-mailing worm, with one mildly amusing twist:

The virus activates if it is executed when the minutes of the hour match the day of the month; for example, 18:27 on the 27th day of a month. At this time the virus will insert the following phrase into the current open document in Word: “Twenty-two points, plus triple-word-score, plus fifty points for using all my letters. Game’s over. I’m outta here”. This text, as well as the alias name of the author of the virus, “Kwyjibo”, are all references to the popular cartoon TV series called “The Simpsons”.

In the course of updating the chapter of Windows Security Inside Out that covers viruses and other hostile software, I ran across this reference and decided to Google that particular snippet of text. Of course, I found plenty of references to the Melissa virus. But I also found lots of Word documents and PDF files that were inadvertently Simpson-ized by the virus and then posted to the Web, where they remain as a sort of memorial to this long-vanquished bit of hostile code.

Or at least I thought it was long-dead. Imagine my surprise to find this post on a Macintosh-oriented discussion board, dated December 28, 2004.

Strange message in MS Word

This is strange, some times the following shows up for no apparent reason:

“Twenty-two points, plus triple-word-score, plus fifty points for using all my letters. Game’s over. I’m outta here.”

I could be writing or saving and then poof! there it is…

Is this a programmers joke of some sort? I have to be careful not to send this off to a client embedded in a doc. This happens in the OSX version as well as earlier ones.

Any ideas? Any one else see this b4?

A little more Googling revealed that this particular virus was WM97/Melissa-X:

Melissa-X is an infected Microsoft Office 2001 file (Office 2000 for Macintosh). It appears that this virus variant came about when a Macintosh user who had a file infected with WM97/Melissa-X, saved it using Office 2001. The file (ANNIV.DOC) was then sent to a colleague running Microsoft Office 97 or 2000. When the file was opened the viral macro code ran (even though the file format was still Office 2001), and the mass-mailing part of the virus code executed.

[…]

The mass-mailing payload of Melissa-X does not work on Macintosh computers, although the virus can still replicate.

Apparently this particular strain appeared in early 2001. Viruses on a Mac. Who knew? For what it’s worth, the architectural changes in Office 2000 (Windows) and later versions completely eliminated macro viruses. And that poor Mac Melissa victim needs to get some security updates, too!

Another pointless Mac vs. PC debate

UC Berkeley professor Brad DeLong says, “Get a Mac!” Prof. DeLong, normally a smart and witty analyst, needs to go back to school on this one. His argument is based on a third-hand quotation from Robert Scoble (via Owen Thomas’s Ditherati, which in turn took the quote from the snarky and entertaining but not exactly reliable Register). Reportedly, Scoble said, “ “I shut down my Tablet PC most evenings and start it up from a fresh boot. Why do I do that? Because I’ve been using computers for 20 years and have learned that’s the best way to work.” Prof. DeLong’s response sounds like something you’d hear from a freshman about to start a food fight:

Snort. Guffaw. Chortle.

The idea that one dare not try to save the state of one’s system overnight…

It is indeed the best way to work if you have an operating system with nine fives of reliability. For those of us whose operating systems have five nines of reliability, however…

bradford% uptime
22:13 up 14 days, 10:2

delong% uptime
22:14 up 4 days, 8:54

Fourteen days? Four days? That’s the best you’ve got. Sheesh. I’m typing this note on a PC running Windows XP. I use it daily, it runs 24/7, and its current uptime is 25 days, 18 hours, 51 minutes. The last time I rebooted it was because I installed a third-party service that asked me to do so. I cannot remember the last time this system crashed.

I have a Tablet PC. I use it for an hour or two a day and hibernate it when I’m done so I can return to the same spot the next night. It hasn’t been restarted in over a month.

My office is built around a server running Windows 2003. Current uptime: 21 days, 18 hours, 4 minutes. I rebooted it when I replaced a hard drive a few weeks ago.

And Professor, here’s a lesson you might want to teach your students: Always go to the original source material. Here’s Scoble’s original quote, in context, from his blog:

I shut down my Tablet PC most evenings and start it up from a fresh boot. Why do I do that? Because I’ve been using computers for 20 years and have learned that’s the best way to work.

This was a behavior I learned on System 7.0 back in 1992 when I was a page designer at San Jose State. It takes an extra minute in the morning to boot up, but that’s why I never hit this bug.

System 7.0? Wasn’t that a Macintosh operating system? Yep. Scoble learned not to trust operating systems to be reliable because he used to use a Mac.

Look, this OS triumphalism is truly pointless. Windows XP and Mac OS X are both extremely reliable operating systems. Both of them are also quite secure, especially if you understand the kinds of precautions to take. (Hint to Mac users: you might want to be careful where you browse with Safari and install the latest security updates.)

Longhorn beta will arrive by June

ZDNet has the first official confirmation that a Longhorn beta will be out in the first half of this year:

Microsoft is on track to release the first full test version of the next major Windows release by the end of June, a Microsoft executive told CNET News.com on Monday.

The company has said publicly that Beta 1 of Longhorn would arrive by the end of 2005, though internally, the company has been aiming for a release by midyear. The final version of Longhorn is slated for the second half of next year.

“There will be a beta 1 of Longhorn…happening in the first half of this year,” John Montgomery, a director in Microsoft’s developer division, said during an interview at VSLive, a conference devoted to the company’s Visual Studio .Net toolkit. The release will be primarily aimed at developers, Montgomery said. “I do, however, expect that you will find IT departments starting to look at it, kick the tires, figure out what’s in it and what’s not in it.”

If history is any guide, a public beta will appear before the end of this year. This should be very, very interesting.