The blog

Longhorn to ship in May 2006?

Neowin has details on the current Microsoft internal schedule for Longhorn, the next major release of Windows. Their report says the first beta release is due on May 25, with a second beta on October 12. The internal schedules say the product will release to manufacturing on May 24, 2006, almost exactly one year after the first beta.

Take all the dates with a shovel full of salt, of course. But regardless, I know what I’ll be doing for about a year when I get back from vacation on May 23!

Update: Steven Bink has a slightly different set of dates.

How to completely eliminate tracking cookies

Some people seem really concerned about cookies. The worst offenders, they argue, are so-called “tracking cookies,” which supposedly allow companies like Doubleclick to track your movements on the Internet.

If you think this is a big deal, fine. You don’t need anti-spyware software to get rid of these cookies. Instead, take the following two steps:

  1. Delete all currently saved cookies from your computer. In Internet Explorer, click Tools, Internet Options and then click the Delete Cookies button on the General tab. In Firefox 1.0, click Tools, Options. Click the Privacy icon in the sidebar and then click the Clear button to the right of the Cookies heading.
  2. Specify that you want to block all third-party cookies. In Internet Explorer, click Tools, Internet Options. On the Privacy tab, click Advanced. Click to select the Override automatic cookie handling check box, and then click Block under the Third-party Cookies heading. In Firefox 1.0, click Tools, Options. Click the Privacy icon in the sidebar and then click the plus sign to the left of the Cookies heading to expand your list of options. Click to select both options: Allow sites to set cookies and for the originating web site only.

There. You’re done. You’re completely protected from “tracking cookies.”

But (I can hear you asking) what about first-party cookies? Well, if you’re visiting a Web site, they already have your IP address, and they have a record of every page you visit on their site and everything you type into a form. If you’re really that concerned about a Web site, you might want to avoid visiting it. But if you’re really worried about first-party cookies, open Internet Explorer’s Advanced Privacy Settings page and then click the Prompt option under the First-party Cookies heading. With Firefox, you can use an extension or set the ask me every time option. After you save these settings, you’re in complete control.

Here’s what your IE options should look like:

Ie_cookies

And here’s what Firefox options look like:

Ff_cookies

Now can we agree that there’s no need for an anti-spyware program to do something so simple?

Mossberg reviews Microsoft AntiSpyware

Walt Mossberg at the Wall Street Journal reviews the new Microsoft AntiSpyware program today. I disagree with several of his conclusions. Let’s start with one complaint where I think he’s absolutely right:

I found the program easy to use, though downloading it was a bit of a hassle because Microsoft tries to get you to verify that your copy of Windows isn’t pirated, which can force you to dig up your Windows serial number. You can avoid this step and still download the program, but you have to pay careful attention to the download options.

I agree. The whole Genuine Windows program should be reserved for add-ons and fun stuff. Security updates should be available to anyone with as little hassle as possible.

The software offers two kinds of scans: a quick, five-minute version, and a longer version that took about half an hour on my test machine. But the scans missed some spyware found by [Webroot’s] Spy Sweeper. In particular, Microsoft missed “tracking cookies,” small files deposited by Web companies, often without your knowledge or permission, that track your online activities. The Microsoft program deliberately doesn’t look for these. Microsoft officials say they are concerned that some legitimate cookies, such as those that store Web-site login information, could be unfairly labeled as spyware. They promise to add tracking-cookie detection in the future.

That’s just wrong. As I’ve said before, cookies are not spyware, and I think Microsoft is making the right decision here. Ben Edelman, in a comment on the same post, agreed:

Absolutely agreed that cookies aren’t spyware and shouldn’t be detected or removed as such.

It’s quite striking how badly other companies (even companies I generally admire, i.e. Webroot) have done with this issue. It seems like they’ve been stuck in competition with each other — who can detect more stuff as “spyware” and make the issue sound bigger, perhaps for PR purposes. Certainly the Webroot surveys for Earthlink had this ring to them — reporting millions of tracking cookies as if this told the world something about the spyware problem.

Major kudos to Microsoft for getting this right the first time, and for being an industry leader in doing so. Here’s hoping the reviews praise this improvement.

The security companies have trained reviewers to think “more is better,” and this may take some time to overcome. I hope that Microsoft doesn’t cave on this issue just to avoid some unwarranted criticism.

Even worse is the way the program handles another spyware problem, the hijacking of Web-browser home pages and search pages. This is a spyware technique in which the home and search pages in a Web browser are replaced by pages selected by a spyware company, and it’s nearly impossible for a user to restore his or her own selections.

The usual way of handling this, with programs like Spy Sweeper, is to detect the page changes and to restore the user’s original choices. But the Microsoft program tries to replace the spyware pages with home and search pages from MSN, Microsoft’s own online service. This smacks of the same kind of coercion the spyware authors are using.

Microsoft insists it isn’t trying to drive people to MSN…

I discussed this problem in an earlier post. The code that Walt is complaining about is exactly what was in the original Giant AntiSpyware, and there’s a logical technical reason for it. (Remember, the Microsoft beta was released less than three weeks after the program was purchased, and there were two holidays in there.) So insinuating that this is devious behavior from Microsoft is unwarranted. Nonetheless, I expect that this feature will be changed in the final release. I would recommend that the program ask the user during setup to confirm that that the current home page is their preferred entry. Clicking Yes would write the value of the current home page to the Default_Page_URL value in the Registry

Not only that, but Microsoft AntiSpyware does nothing at all to protect users of the rival Firefox Web browser from home- and search-page hijacking. It detects and corrects such hijacking only in its own Internet Explorer Web browser. The company says it is trying to focus on things that affect “the largest number of customers,” and it notes that the vast majority of users rely on IE. But this, too, smacks of favoritism toward Microsoft products.

Well, again, this is the original code from Giant Software, so it seems a trifle unfair to blame Microsoft. But tell me, has anyone seen a home page hijacker that works on Firefox? Is Walt asking for a solution to a problem that doesn’t exist?

Walt recommends Spy Sweeper. Sadly, I think the main reason is because its scan detects hundreds of tracking cookies and thus appears to be more aggressive. In my review of that program last year, I found that it actually tried to remove or disable completely innocent programs that I use regularly. A reader reported similar experiences; in fact, Webroot’s program actually disabled all access to the Internet for her. More (and more aggressive) is not necessarily better.

I’ll have more to say about cookies in a follow-up post.

Malicious Software Removal Tool

I’ve been getting a lot of search requests today for the new Microsoft Malicious Software Removal Tool. So here it is.

The Microsoft Windows Malicious Software Removal Tool checks Windows XP, Windows 2000, and Windows Server 2003 computers for and helps remove infections by specific, prevalent malicious software—including Blaster, Sasser, and Mydoom. When the detection and removal process is complete, the tool displays a report describing the outcome, including which, if any, malicious software was detected and removed.

Microsoft will release an updated version of this tool on the second Tuesday of each month. New versions will be made available through this Web page, Windows Update, and the Microsoft Download Center.

You can do a quick online scan at this page. You’ll need to download an ActiveX control or a stand-alone executable file to complete the operation.

Update for Outlook 2003 Junk Email Filter

Yesterday was Patch Tuesday, and of course you have Automatic Updates set to download Critical Updates for you. Right?

But if you use Outlook 2003 you might have missed this one, which isn’t delivered via Windows Update:

Update for Outlook 2003 Junk Email Filter (KB890854)

It’s a shame that Microsoft doesn’t provide any documentation of how these filters work. They do, however, seem to be updating more frequently now. Earlier updates were irregular (December 2003, March 2004). But the most recent two have appeared on Patch Tuesday: September 14, 2004, and November 9, 2004. This update is cumulative. If you skipped the previous updates, this one gets you completely up to date.

I’m unsubscribing from this feed, too…

I’ve decided to take all the Windows IT Pro feeds out of my newsreader. Why? Because they use the hideous  IntelliTXT sponsored-link technology provided by Vibrant Media. Take a look at this post for an example. The green underlined words, which are designed to look almost exactly like hyperlinks, are actually ads. Hover your mouse over the link, even accidentally, and a pop-up box appears. Click one, and you visit an advertiser’s page in a new browser window.

Ugh. It’s deceptive and obnoxious. I’m not going to support publishers who use this technology.

Update: ActiveWin.com uses the same annoying ads.

Cable HDTV in Windows Media Center?

This little paragraph was dropped in casually in the middle of a write-up on the new Shuttle Media Center XPC at AnandTech:

The XPC is obviously designed for a more set-top applications and thus will also feature a cable card reader as well as HDTV output. The next version of Microsoft’s Windows XP Media Center Edition due out in Q3 will support cable card and content protected HDTV content over digital cable services, making this device actually useful from a HDTV standpoint.

Kudos to Jason Dunn at Digital Media Thoughts for catching this one. Is it true? Ah, that’s another story, isn’t it?