The blog

Next week’s security updates

Yesterday, Microsoft published its advance notification of the security bulletins scheduled to be released next Tuesday. In all, the list contains 13 updates, some of which will be listed as Critical. If you’re set up to receive Automatic Updates, you’ll get them without any extra steps. (And if you’re not set up for Automatic Updates, change your settings!)

The most interesting item on the list, at least to me, was a single Critical Update that affects Windows Media Player and MSN Messenger. I’m hoping this update will fix the problem with “poisoned” Windows Media files (see the discussion here, here, here, and here), but we won’t know until the patch is officially released.

The national digital identity card

This ominous news comes from a new blog called The Identity Corner. The author is Stefan Brands, one of the top applied cryptographers in the world and author of Rethinking Public Key Infrastructures and Digital Certificates: Building in Privacy:

The Belgian State Secretary and Microsoft yesterday jointly announced an alliance to integrate Belgium’s national identity chipcard (the “eID card”) with MSN Messenger. Belgium is the first European country to have started distributing a national identity chipcard to all its citizens. The Belgian ID chipcards authenticate themselves on the basis of an X.509 digital identity certificate. This certificate is in effect a globally unique inescapable identifier that can be used to automatically trace and profile all citizen actions, possibly in real time. Perhaps even more dangerously, the current generation of national ID chipcards is based on the same kind of identity management architecture as that of enterprise employee chipcard systems for protecting access to physical areas and network use within the enterprise. Architectures for identity management that create all-powerful central parties may be perfectly suitable for enterprise needs, but for government the situation is (or at least should be …) drastically different. The central capability to lock misbehaving employees in real time out of internal corporate services is one thing, it is quite another for the government to be able to do so for citizens.


I shudder to think what the current government of the United States would do with similar technology. It’s one thing to have an immigration officer inspect your physical papers as you enter the country. It’s quite another to have a digital key that can be used to monitor and control access to the Internet, or to resources that are supposed to be public. Thankfully, the infrastructure isn’t available to support this sort of centralized on-line identity management. Yet.


Thanks to Prof. Froomkin for the pointer.

Why I prefer CDs to downloads

My buddy Michael called yesterday. He’s spent the better part of two days trying to clean up his 15–year-old niece’s spyware-infested computer. (Kazaa, of course. You had to ask?) He thought he finally had it cleaned up, only to discover that some of the crud had returned, and then the PC decided it didn’t even want to boot into Windows anymore. What should he do?

“Easy,” I say. “Reformat the sucker and start over. The kid’ll lose some data files, but nothing that she can’t re-create or replace.”

But it turns out to be more complicated than that. Seems that the niece had downloaded a large collection of iTunes tracks at 99 cents a pop, and Uncle Michael thought, rightly, that she might not want to lose several hundred dollars’ worth of music. No, she never backed them up. And no, she never burned them to CD. In other words, she’s just like a gazillion other people.

But can’t she download them again? I mean, she’s already paid for them, right? Imagine my surprise when I did a little research and discovered the sordid truth about music downloads.

The iTunes Music Store support site says if you lose it, you’re S.O.L.

When you buy a song or album from the iTunes Music Store, you are entitled to download it a single time. If you want to download it again, you must purchase it again.

Whoa. That sucks. Are all online music services like that? I decided to check.

The RealPlayer Music Store FAQ has an equally harsh answer to the What if I lose my music? question:

RealNetworks will not be responsible for refunding or replacing tracks or albums purchased through the RealPlayer Music Store if your system crashes or if you lose or delete your music files. Your downloaded music files are your responsibility. We recommend archiving your files to CD.

MSN Music says they might, might, help you out if you lose your music:

MSN is not responsible for lost downloads, and you should always ensure that you maintain a current backup of your music. MSN Support can replace lost downloads only under certain circumstances such as the crash of your computer’s hard disk drive. If you feel you have encountered circumstances that warrant a replacement of one or more of your purchased tracks please contact MSN Support for further assistance.

With Napster.com, on the other hand, you don’t need to beg. If your hard disk crashes, you can…

Sign into Napster on a secondary computer and use the Sync/Restore feature to download tracks you’ve already downloaded or purchased on another computer.

Too bad Napster tracks are only 128Kbps. Which, in a nutshell, is the problem with music downloads. At 128Kbps or 160Kpbs, the tracks you download contain only a fraction of the information originally recorded by the artist. Producers and engineers slaved to make those tracks sound great. If you sit down in a room with a decent (not great, just decent) audio system and do an A-B test with a CD and an MP3 download, you’ll hear the difference. Even in my car, where listening conditions are less than optimal, I can tell a real CD from an MP3 rip. You don’t need to be an audiophile snob, either; anyone who pays attention can tell that something’s missing from the MP3 or WMA copy. And yet the music services want you to pay at least $9.99 per album for this inferior product.

Well, I won’t do it. Not when I can buy the real deal for pretty close to the same price. The secret? Buy your CDs second-hand. Amazon.com has a thriving market in used CDs, and the prices in many cases are at least as good as downloading them. Today, for instance, I listened to three albums on Napster’s new Napster to Go service, which gives you unlimited access to an enormous library (they claim it’s a million tracks, and I believe it). The monthly fee is $15, and in the last month I’ve probably sampled 50 albums – something I could never have done with the 99–cents-a-song services. Today, I decided to buy a few of those CDs, so I went over to Amazon.com and found:

  • John Prine, Live on Tour – $9.88 used at Amazon.com
  • Roy Rogers and Norton Buffalo, R&B – 3 “like new” copies for $7.99 or less
  • Green Day, American Idiot – 80 used copies for sale, five of them for $9.00 or less

Amazon collects the payment and guarantees satisfaction. Shipping is a flat $2.49 per CD. Those three CDs, shipping included, cost me about $11.50 each, which is only a buck and a half more than I would have paid Apple or MSN or Real or Napster for a second-rate download. I can take the “real” CD and burn a CD-R copy to play in the car (no worries about the CD getting scratched or stolen). I can rip it to a high-bit-rate copy and play it through my Media Center PC anywhere in the house. At 192Kbps or 256Kbps, the quality of my digital copies is more than good enough, and way better than those downloads. And I don’t have to be paranoid about backing them up.

I don’t own a single DRM-restricted track, but I do download some digital music. The Live Music Archive has an incredible collection of free, legal music available in lossless format (SHN or FLAC). I can buy CDs, also in lossless format, from groups like Yonder Mountain String Band. All those downloads, when burned to CD, produce a copy that is indistinguishable from the original source. So tell me again why should I settle for an inferior digital copy that I can’t use or copy freely?

Thomas Hawk says he feels the same way:

Buying a track with DRM appeals even less to me than the screwed up music I get with Kaaza. This is why I still go out and buy my own CDs and rip them myself into crystal clear, properly meta marked, DRM free, high bit rate .mp3 files. In my opinion, this still is the best way to go for the serious music collector.

So does Microsoft’s Matt Goyer.

Update: Tristan Louis came to the same conclusion but for different reasons.

Another update: In the comments, Serge reminds me that I ignored two excellent music services that aren’t so restrictive: eMusic (192Kbps VBR MP3 downloads, with no copy restrictions and the right to re-download) and Disclogic, whose selection neatly mirrors my admittedly offbeat tastes. I’ll have more to say about both companies later. Thanks, Serge!

A bold suggestion to stop spyware and adware

Ben Edelman explains How VeriSign Could Stop Drive-By Downloads. VeriSign, in case you don’t recognize the name, is the company that controls 95% of the digital certificates used on the Internet today. These certificates are passed out like bubble gum cards to any company that has an address and a check (typically between $200 and $600) for the certificate registration fee. When you visit a Web site that wants to install an ActiveX control on your computer to extend the capabilities of Internet Explorer, VeriSign gets involved by displaying information contained in the official record for the company’s digital signature.

There are countless legitimate and ethical companies that use ActiveX technology for good purposes. Unfortunately, there’s also a disproportionately active community of scammers and charlatans intent on exploiting the trust that is implicit in a digital signature. An enormous amount of crapware has been dumped onto countless computers by this latter group, who use ActiveX permission dialog boxes to sucker unwitting users into “agreeing” to install software that they invariably regret later.

If VeriSign chose to enforce its license agreements, it could revoke the certificates of those companies that misuse the trust they inherit through a digital certificate. And without a certificate, virtually all versions of Windows will reject the proposed software cold, without subjecting the user to a misleading prompt. Ben explains:

Through existing software systems, already built into Internet Explorer and already implemented by VeriSign servers, VeriSign has the ability to revoke any certificate it has previously issued, disabling ActiveX installations that use that certificate. See VeriSign’s Certificate Revocation List server (crl.verisign.com) and Microsoft Certificates documentation of the revocation system.

I suggest that VeriSign can and should use its existing certificate revocation system to disable those certificates issued or used in violation of applicable VeriSign rules.

Ben documents three products that clearly violate the VeriSign contract. After presenting the proof, he writes:

Each of these misleading installations is contrary to VeriSign contract, contrary to VeriSign’s duty to its users, and contrary to VeriSign’s many promises of trustworthiness. In the first installer, VeriSign affirmatively certified the “click yes to continue” company name — although it seems that there exists no company by that name, and although that company name is facially misleading as to the purpose of the installation prompt. In the second and third examples, VeriSign certified companies that subsequently used VeriSign’s certification as a necessary step in deceiving users as to the function of and (alleged) need for their programs.

Given VeriSign’s claims (such as its old motto, “the value of trust”), VeriSign should want to put an end to these practices. When VeriSign certificates are issued wrongfully (as in the first example) or are used deceptively (as in the second and third), VeriSign should take action to protect users from being tricked. In particular, when an application offers a facially invalid and misleading company name, VeriSign should refuse to issue the requested certificate. When an applicant violates basic standards of truth-telling and fair dealing, VeriSign should revoke any certificates previously issued to that applicant.

Read Ben’s article. If you think VeriSign should follow through on its responsibility to you and me as users of their digital signature technology, why not give CEO Stratton Sclavos a call at 650-961-7500? If he’s not there, ask for Judy Lin, Executive Vice President, Security Services. (If anyone has a good e-mail address for either of these individuals, let me know and I’ll update this post.) Update: Send your e-mail to stratton@verisign.com.

And spread the link to this post and to Ben’s article. There’s nothing like a little publicity to help big companies like VeriSign understand their responsibilities to their ultimate customers – us.

Media Center wish lists

Sean Alexander notes that Windows Media Center Edition has a full-fledged software development kit and wonders: “What applications, games, and services would really make MCE shine?”

Thomas Hawk came up with a long list that boils down to one statement: “MCE should own the home.” I’m not sure I agree with that sweeping goal. There are some great items on his list, but the ten-foot interface isn’t right for everything. Not only that, but every extension comes with a cost in complexity and a risk of destabilizing the system. I want my Media Center to be solid and dependable, like an appliance. But that still leaves lots of room for add-ons. So, here’s my list:

  1. An alternate interface for home automation. But not the only one, please. I don’t want to have to turn on the entire home media system to turn off the lights. The home automation functions should be directly related to activities that I might want to control when using my Media Center: dimming lights so I can watch a movie and controlling the whole-house sound system, for instance.
  2. Integration with voice mail and Caller ID. Again, this should be an alternate interface, not the primary one. I don’t necessarily want to play back every incoming message in booming 5.1 digital stereo sound. Give me the option to see what messages are available, but assume that I’ll play back most of them through the telephone handset.
  3. A “build your own headline news” module. Make this a live, constantly updated list of available news segments from CNN, ABC, MSNBC, BBC, whoever. Make the list customizable so I can choose not to have Fox News on the list. When I’m ready to watch, I can use the remote to select the items I want to see and then MCE will build the “show” for me.
  4. Podcasting subscriptions. This one should be obvious. Queue up available podcasts for me and let me play them back through my home audio system or PC speakers. It would be really nice if clips could be indexed so I could skip to individual segments.
  5. A “home message” module. I’d like to type a note (better yet, be able to pick from ready-made templates and custom templates I create) and have it appear on the screen for other people in my household. “Went to the grocery store. Back by dinner time.” “Joanie called. Wants to go to the movies Wednesday.” That sort of thing. A screen saver could let me or my wife know there’s a message waiting.
  6. Photo Story for the Media Center. This one should be a slam-dunk.
  7. My Netflix. Ryan Hurst has written a superb extension for this now. It could be even better.
  8. Support for CD/DVD changers. I have a 300–CD Pioneer changer; unfortunately the only way to manage disks in this device is to input information manually. Ugh. I’d love to have that process automated and bypass the awful character limits on the Pioneer front panel.

Hmmm. As Thomas said, I could easily come up with 80 or 90 more. Good idea, Sean!

Indestructible notebooks

Scoble experiences what we all dread:

I pulled my backpack out of the car, flipped it over my shoulder (I hadn’t yet had my coffee) and I heard a sound that I had never heard before. Sounded like metal or glass sliding along concrete.

I knew without looking what it was. My Tablet PC was laying on the concrete. My heart sank. It had fallen from at least four feet onto concrete and I knew from the sound it made that it was not gonna be a good day.

Surprise! It still worked. Actually, maybe I’m not so surprised. Back in the dark ages, when I was a senior editor at the late, lamented PC Computing (later Smart Business), we used to do an annual “torture test” of notebook computers. The last one appeared in 2002, just before Ziff-Davis pulled the plug on the magazine. Marty Jerome and the PCC Labs crew devised a thorough set of tests that every unit had to go through: freezing cold (as if you had left it in the trunk overnight in Buffalo in mid-winter), extreme heat (same deal, only think Phoenix in the summer), a coffee spill on the keyboard, and of course the infamous drop test.

I remember Marty once telling me that the testers were always reluctant to push that first notebook off the drop table and watch it crash. The whole act flew against the spirit of everything they had ever learned about safeguarding a computer. But by the end of the test they were smiling and laughing, almost diabolically, as they went about their business of destroying really expensive brand-new computers.

Then, as now, the Toshibas were extremely well-engineered. I’ve got a two-year old Toshiba Tablet PC that’s still running strong. Never dropped it, though, and I hope I never do.

If you want to take a stroll down memory lane and see some of those old notebook torture test results, try this Google search. And if you want to protect your notebook, think about knitting your own laptop case.

Tell Microsoft Press how you use computer books

Juliana Aldous is a Product Planner for Microsoft Learning – the division that publishes books under the Microsoft Press imprint, including Windows XP Inside Out. She’s looking for a few good reviewers. If you use Office or Windows and you’re not an industry expert or another author, you can help. She promises that it’s just a “simple questionnaire.”  Visit her blog and click the e-mail link to add your name to the list.

Why I hate Kazaa (and why you should too)

Ooooooh, I love this! Australia’s apcmag.com has been diligently following Kazaagate, a civil trial now going on in Sydney’s Federal Court. Today, reporter Garth Montgomery reports on a whopper of a confidential document that Kazaa’s owners tried to suppress:

It’s a philosophical rant from [Sharman CTO Philip] Morle, which is printed and packaged to resemble a legitimate academic text, complete with footnotes and the longest title in the history of quasi-academia.

In it, Morle acknowledges what any PC support professional has known for years: Kazaa is riddled with adware and will turn your computer into a doorstop:

“We need to be careful with user resources. Most obvious is in the adware we add to their machine upon installation. This software slows down users’ machines and can affect other activity such as browsing the Internet (as we have seen with PerfectNav). It is reasonable that we show ads in order to create our free software, but I do not believe it is reasonable to place a user in a position where this free software will also make their machine sluggish. Consider how many people that work for Sharman Networks and its partners that hate installing Kazaa on their machines.”

Yep, the people who work for the company that makes Kazaa don’t want it on their computers because it’s such a viper’s nest. Lawsuits are an essential tool, sometimes the only way, to get confirmation of how a company really works as opposed to what it claims to be doing. That was true in the Microsoft antitrust trials and it’s certainly true here.

If you know someone who still uses Kazaa or Grokster, do them a favor and do whatever it takes to help them get rid of it. They’ll thank you.

The history of the Windows PowerToys

Raymond Chen wrote the original Tweak UI for Windows 95. In a post on his most excellent blog, The Old New Thing, he tells the history of the Windows PowerToys. It’s fun reading, especially given that this is the 10th anniversary of Windows 95. But I’m linking to it here because it also includes this most excellent list of all the other PowerToys that have since snuck out of other groups at Microsoft and are available for various Windows platforms:

(Plus, of course, the Windows XP PowerToys, which does come from the shell team. The Internet Explorer team originally called their stuff PowerToys, but they later changed the name to Web Accessories, perhaps to avoid the very confusion I’m discussing here.)

Until I read this post, I didn’t know that Raymond also wrote the original Kernel Toys for Windows 95. Nor did I know that Raymond wrote the whimsical blurb that introduced the original PowerToys. But I’m not surprised, given the cleaver, clear writing and insight that is the hallmark of Raymond’s blog.