The blog

Stupid spammers

Earlier today I was sorting through the Junk Mail folder for a Hotmail alias I rarely use and ran across yet another variation on the Nigerian scam e-mail. This one was pretty sleazy — the sender claimed to be a Christian preacher in Sri Lanka who knew a wealthy man who was killed in the tsunami but had left $8 million in the bank and … well, you know how the rest of it goes.

My favorite part, though, was the free Webmail service that this scammer had chosen. Do you really think a preacher would have an account at gayfetishpool.de?

Misplaced criticism

Joe Wilcox at Microsoft Monitor is unhappy about Microsoft’s attempts to steer people to its paid services. They’re practically guilty of shipping spyware themselves, he concludes, based on this experience:

I started up the Averatec 6100H this morning and got a warning that http://www.averatec.com was trying to change the default home page from http://www.msn.com. Thing is, the default had been set to averatec.com by the PC manufacturer. The warning sure as hell baffled me. Either Microsoft’s software changed the setting to msn.com without asking or it was attempting to trick me into switching back to msn.com. Yes, trick. That’s absolutely my interpretation of the wording, regardless of Microsoft’s intentions.

Later on I checked the anti-spyware software log and learned that: “The user Joe Wilcox, has decided to allow the Internet Explorer Start Page URL change from its original URL of http://www.msn.com/ to http://www.averatec.com.” Of course, the original start page was averatec.com and not msn.com.

Sorry, but the wording is confusing and presumes that msn.com was the default home page, which it was not. A PC manufacturer choosing its own home page on it computers is a fairly common practice, I might add. I’m stunned, simply because the tactic of confusing the user into agreeing to a home page change (a.k.a. highjacking) is a common tactic used by spyware. And Microsoft calls its software anti-spyware?

Sounds horrible, doesn’t it? That evil Microsoft, trying to fool people into changing their home pages to MSN.com. Except that’s not what actually happens when you try to change your home page on a computer with Microsoft AntiSpyware installed and configured with its default settings.

First of all, the behavior Joe describes was coded by the original developers of this program, the GIANT Software Company. I know, because I checked it out this morning. Blaming this behavior on Microsoft’s motives is misguided.

Second, this is a beta. Feedback like this goes into the product design.

Third, I think Joe misread this dialog box. I have my Internet Explorer home page set to My Yahoo, and I have Microsoft AntiSpyware installed. Here’s the dialog box I saw when I tried to change my home page:

Change_home_page

The warning message accurately describes the current home page (http://my.yahoo.com) and the one I tried to change it to (http://www.bott.com/weblog). The reference to MSN.com appears afterwards and it is accurate, if you understand what the default home page is. On the Internet Options dialog box, there are three settings under the Home Page heading: Use Current, Use Default, or Use Blank. The default setting for all retail and OEM copies of Windows is MSN.com. In this case, it appears that the maker of Joe’s PC, Averatec, changed the Start Page value (which defines the current home page) but didn’t change the Default_Page_URL value. Both of these settings are found in the Registry as REG_SZ values at HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main.

Not only that, but notice that neither of the options in the dialog box above will allow me to change my home page to MSN.com. If I click Allow, my home page gets changed to the value I chose (or to the value that a script or spyware program is trying to force on me). If I choose Block, the setting for my Home Page stays exactly where it is!

I don’t know if it’s just sloppy note-taking or what, but this is at least the fifth time in the last four months that I’ve found an error at Microsoft Monitor. I’ve sent e-mail to Joe on each occasion, and he’s corrected most of the errors, although I’m disappointed that he’s never acknowledged the input publicly. And because Joe has decided not to allow comments, it’s impossible to carry on any kind of dialog except through e-mail or (as I’m doing here) by providing corrections on my own blog. (At least one other Jupiter Research analyst, Eric Peterson, does allow comments.) [Updated: The default template on Jupiter Research blogs includes a link that reads “I welcome your comments,” but it just pops up an e-mail window. It appears that no analyst at Jupiter Research actually allows comments that appear on the same page as a blog entry.]

It’s hard to continue reading or recommending a source that regularly gets the details wrong.

From PowerPoint to your TV screen

My sister-in-law Teri asked last week if I knew how to get a PowerPoint presentation onto DVD. She had a 180–slide PowerPoint presentation (made by someone else for a friend’s 50th wedding anniversary party), and they wanted to be able to pop a DVD into a player and watch the show on a big-screen TV.

I’ve written a few chapters on PowerPoint for various revisions of Special Edition Using Microsoft Office, but I’m far from an expert. I know that PowerPoint doesn’t natively support any video formats, and I found an interesting discussion of the topic here. But aside from those leads, I was stumped. So I was glad to get the follow-up today:

Got the 50th Anniversary project done via…

  1. PowerPoint PPT to PPS (less memory use during screen capture)
  2. Screen capture w/ CapturePad shareware 14-day non-crippled tryout (600×800 at 30 fps)
  3. NeroVision Express to burn DVD Video w/Menu (It failed twice trying to burn directly from NeroVision Express, so had to burn to the hard drive first then copy via Nero Recode to DVD)
  4. GoVideo VCR/DVD Player to copy from DVD to VHS tape

This would have been much easier if the author had created the original slide show in MS Movie Maker! PowerPoint is a bitch to match audio to video timing. I had a lot of cleaning up to do to get rid of awkward transitions and I had to shorten one of the WAV files with Creative Wave Studio–which is kinda like cutting sushi with a hatchet.

There were no fancy slide transitions or sound effects used in this 20-minute presentation–just an approximate 6-sec transition between still photo slides and background WAV music files. I don’t know how (or if) a fancy transition or effect would capture (or convert) to AVI–and I don’t have time to test it right now.

I screen-captured presentation with CapturePad to AVI with both video and audio UNCOMPRESSED. (The WAV files were already compressed.) I also noticed that there is a HUGE color loss going from the computer screen to NTSC. I think attention should be paid to colors used (as we do with web page art) and saturation of photos should be pumped up. I also set NeroVision to the highest quality video configuration and configured audio to Dolby 2.0. Make sure that any MICROPHONES (like soundcard headset or other inputs) are turned off (both in soundcard and CapturePad), or CapturePad will over-dubb the audio track with background noise (like me kindly yelling at the dog to get out of the office). The 22-minute, 186-slide presentation w/6 audio files ended up as only 858Mb on DVD.

I’m a happy camper.

I’ll have to try this one of these days!

Another Firefox security issue

As Firefox becomes more and more popular, it faces more and more attacks from bad guys. A new report this morning claims that phishers have found a hole in Firefox:

A security flaw in the increasingly popular Firefox browser is exposing millions of users to phishing scams, security experts have warned.

Jakob Balle, security specialist at Secunia Research, said that the vulnerability in Firefox and Mozilla allows malicious hackers to execute phishing scams by spoofing the source URL displayed in the browser’s Download Dialog box.

“The problem is that long sub-domains and paths are not displayed correctly, which can be exploited to obfuscate what is being displayed in the source field of the Download Dialog box,” he said.

A Secunia Research advisory stated that the “less critical” vulnerability has been confirmed in Mozilla 1.7.3 for Linux, Mozilla 1.7.5 for Windows, and Mozilla Firefox 1.0. It added that “other versions may also be affected”.

Reportedly a patch is under development but isn’t ready.

How often should you reinstall Windows?

John J. Fried is a syndicated columnist for Knight-Ridder. In his most recent column, he offers a piece of popular advice that I think is completely misguided. In response to a question from a read who complains that his computer is slow, he writes: 

Even if you treat your PC with kid gloves, delete temporary files of all sorts, defragment, uninstall programs rather than delete them, keep viruses and spyware off the system and update drivers and programs, it is still likely the PC will turn on you.

Endless wanderings on the Internet, the installation and uninstallation of programs and the addition and removal of devices, among many other things, take their toll on the Registry and other crucial files as unavoidable errors in them crop up and multiply.

 As much as you hate to hear it, what you should do every 12 to 18 months is wipe the record clean by reformatting the hard drive and reinstalling Windows and all your programs.

In fairness to Mr. Fried, he’s not the only one who believes this. For what it’s worth, I completely disagree.

If you’re experiencing a problem with Windows, there is likely a specific cause for it. Usually that cause is an unsigned driver or a program you installed. It might be an unrelated hardware problem. Whatever the cause, the best thing you can do is track down the actual cause of the problem so that you can fix it. If you simply blow everything away and start over, the most likely thing that will happen is that sooner or later (probably sooner), you’ll reinstall the driver or program that caused the original problem, and you’re right back where you started from.

The logical flaw in this advice is that installing and uninstalling software and devices causes “unavoidable errors” in Windows. No, it doesn’t. Installing a buggy driver (usually one that’s unsigned) can cause errors, as can poorly written programs and uninstallation routines that leave system files behind. But none of these errors are “unavoidable.”

Media Center 2005: Hit or miss?

Over at PaidContent.org, Jeremy Allaire sent in five predictions for 2005. This was the most interesting one, in my opinion:

— Microsoft Media Center 2005 Will Be a Hit. Third times a charm, and Microsoft now has a very strong product in the market. The PC industry is putting real weight behind it as it allows them to have a “whole product” sale with their emerging base of LCD and Plasma TV’s (higher margin), and lets them dabble in the content business (a breath of fresh air from the cut-throat PC world); the CE industry is shipping dozens of connectors, extenders, and portable devices that support it, and the base of content companies getting behind the platform is impressive. Best of all, the product is really great, and the tens of millions of consumers who go out ot buy new PCs will be tempted by the marginal incremental cost to get the promise of whole house convergnece on the cheap. Yes, there are problems and issues with the product, but the list is short and Microsoft will nail them down before the end of the year. This will not be a product that is “pushed”, but one that is pulled as consumer word-of-mouth helps fuel sales.

I think he’s right. I’ve read a lot about the cutthroat competition between TiVo, the cable companies, satellite providers, and Microsoft (not to mention Apple and Linux-based PC solutions). But the salient fact is that this market is going to grow explosively, which means that even a company that loses market share could still find itself growing.

Should be an interesting year.

Dolby goes overboard

Digital Media Thoughts has word on a new announcement from Dolby Laba at CES:

“Dolby Digital Plus builds on the original Dolby Digital specifications, allowing for higher bit rates and more channels. Dolby Digital Plus has a maximum bit rate of 6mbps, and support for 13.1 channels. In comparison, Dolby Digital caps out at 640kbps and 5.1 channels. So Dolby Digital Plus essentially provides 10 times the bandwidth of the original Dolby Digital. The new format also allows for extremely low bit rate multichannel sound for streaming on the Web or over the air. The benefits of the Dolby Digital Plus codec include transient prenoise processing, enhanced channel coupling, adaptive hybrid transform processing, and channel and program extensions.”

I live in a ritzy part of town, and I know a few folks who have big houses. But I can’t imagine any home theater that needs thirteen channels of sound. I’m not even sure my local multiplex has any theaters that need that many channels.

I can only imagine how deafened I would be if I were walking around the show floor at CES.

MCE Extenders reviewed

AP Technology Writer Matthew Fordahl has a thorough review of his experience with a Media Center Extender today.

He describes the benefits well and nails the one big drawback of these devices: They do not work well with wireless 802.11g network connections (although it’s possible that a dedicated 802.11a connection would suffice).

His other criticism, that the extender doesn’t play protected content from HBO and other sources, was true last month but has since been fixed with a downloadable software update. (Update: Ryan, in a comment, notes this isn’t true for Xbox extenders. He’s right. This support page has links to the updates for Linksys and HP extenders and promises that an Xbox update will be available this month.)

Good reading, if you’re thinking of getting one of these things.

Update: I missed the same writer’s longer, more detailed (and generally quite positive) review of HP’s Media Center PC. The good news is that both of these articles will probably appear in a lot of newspapers around the United States and encourage people to take a look at this technology.

MS antivirus tool on the way?

In the comments, Glenn points to a section of today’s press release that I just plain missed. Microsoft Announces Availability of New Solutions to Help Protect Customers Against Spyware and Viruses:

In January 2004 Microsoft released a series of removal tools, each of which targeted a single virus or worm and some of its variants. Collectively, these tools augmented existing antivirus protections by scanning more than 55 million PCs worldwide for viruses such as Blaster, MyDoom and Download.Ject. The new Microsoft Windows malicious software removal tool consolidates these existing removal tools into a single solution. The tool will be updated on the second Tuesday of each month as part of Microsoft’s monthly software security update process to respond to new viruses, worms and variants.
The Microsoft Windows malicious software removal tool will be offered in the following ways:

  • As a high-priority update through Windows Update and through Auto Update for the more than 112 million Windows XP-based PCs configured to receive priority updates automatically
  • Through a simple, online interface.
  • For larger corporate customers, a download through the Microsoft Download Center

Available at no charge, the Microsoft Windows malicious software removal tool is designed to augment traditional antivirus solutions to provide more complete protection against viruses, worms and variants. As with Microsoft’s earlier removal tools, the new solution incorporates the knowledge and technology gained through Microsoft’s acquisition of GeCAD Software in 2003.

Hard to tell what this really means. It isn’t exactly an antivirus program, but it sure sounds like the first step on the road to one.

Shouldn’t everyone be spyware-free?

Joe Wilcox is probably going to think I’m stalking him. I’m not, honest. It just so happens that his beat is identical to mine, so we cover a lot of the same topics. In a new post this afternoon, he reports on evidence that Microsoft may soon restrict access to its new AntiSpyware program to those with “genuine” copies of Windows. Joe writes:

Microsoft pushes product validation before users can get the software. In September, Microsoft started a trial for the Windows Genuine Advantage program, which seeks to curb piracy. The program, which is not yet officially launched, restricts some downloads to users with validated copies of Windows.

So far, at least, Microsoft isn’t restricting access to this beta to users with activated copies of Windows. Unfortunately, Microsoft is doing a lousy job of communicating their policy. When you go to the download page, you have only one choice. Read the wording carefully. Under the heading, “Validation Recommended,” it says “This download is available to customers running genuine Microsoft Windows.” The word only is not in there.

When you click the Continue button, you arrive at a page with TWO choices. You can choose to validate your copy of Windows (using an ActiveX control if you use IE, or by downloading and running a small executable program if you use another browser or prefer not to allow ActiveX downloads). If you don’t want to validate your copy of Windows, you can choose “No, do not validate Windows at this time but take me to the download.” Anyone can choose that option and get to the download page.

I agree with Joe on the main issue:

I fully support Microsoft’s right to protect its software from theft. But I don’t see how restricting a security software download is consistent with Microsoft’s often-stated goal of security being the company’s top priority. I would argue that Microsoft might even be doing itself more a disservice than its customers.

Security should not be an add-on feature. It should not be restricted to people who are willing to jump through a hoop to prove their copy of Windows is “genuine.” And it should not cost a dime. Making every Windows computer safer from spyware and viruses makes the entire Internet safer. Creating a link between new security programs and anti-piracy efforts is contrary to the goal of ensuring that all Internet users are secure. That is the ONLY way to look at this issue. Will whoever is working on this program at Microsoft please get that message?