The blog

MS AntiSpyware: First impressions

OK, I uninstalled my old evaluation copy of GIANT AntiSpyware and installed the new Microsoft version. As I suspected, it’s quite similar. Two noteworthy changes:

  • In the Advanced Tools section, the System Inoculation item is gone. This appears to be taken care of during initial setup and in the Real-Time Protection settings, so it doesn’t seem like a great loss. The File Shredder utility is also missing in this build.
  • The software doesn’t scan cookies or report “tracking cookies” as a spyware threat. The summary screen still shows Cookies as an item on the results list, but I can’t find an option anywhere that allows me to tell this program I want to scan cookies, and although there is a Cookies entry in the Help file, it points to a topic that doesn’t mention cookies at all. I believe that that text was removed from the Help entry but someone forgot to update the Help index.

Removing cookies from the list of things to be detected as spyware is a good move, in my opinion. As I’ve noted before (here and here and here), cookies are not spyware. This software appears to be aimed at removing browser hijackers, pop-up generators, adware, phony search tools, and other forms of deceptive software. Cookies don’t belong in that category. Kudos to Microsoft for making this fundamental change right away.

Update: Microsoft AntiSpyware runs only on Microsoft Windows 2000, Windows XP (including Tablet PC and Media Center Edition 2005), or Windows Server 2003. If you’re using Windows 98 or Windows Me, you’ll have to stick with third-party solutions.

Further update: Don’t install this beta if you are running Windows Media Center Edition 2005 and you have a Media Extender. The “Known Incompatibilities” include this one: “If you install Windows AntiSpyware (Beta) on a computer running Windows XP Media Center Edition 2005, Windows Media Center Extender will not be able to establish a remote connection.” Glad I read the documentation first!

Gates at CES: a wrap-up

I watched the Bill Gates keynote at the Consumer Electronics Show last night. Well, most of it, anyway. The high-speed feed had a little trouble keeping up with the demand, so I occasionally lost the picture. But I saw a few things I liked, and Conan O’Brien was a good foil for Gates, better than Jay Leno.

Joe Wilcox at Microsoft Monitor has the best high-level summary of what the various announcements all mean. Read Microsoft CES: Clarifying the Message for the details.

One quibble with Joe’s otherwise-excellent report. He writes, “Apple’s iTunes supports MP3 better than WMP 10, which requires third-party MP3 encoder support to rip to the format.”

This is not true. A basic installation of WMP 10 includes full support for the MP3 format at bit rates of up to 320K with no additional software required, either from Microsoft or third parties. The default format is WMA, but it takes one click in a dialog box to choose MP3 as the default format.

Update: I sent a note to Joe, and after we exchanged a few e-mails he edited his original report.

By the way, Microsoft announced that there have been 90 million downloads of Windows Media Player 10 in less than four months. That’s a staggering number. To put it into perspective: The folks at Mozilla.org are justifiably proud that they had 15 million downloads of Firefox in just under two months. And no one is questioning that Firefox is an enormous hit and a big story.

Seeing the spyware forest for the trees

Over at Broadband Reports, Eric L. Howes has some more details on the issue of “poisoned WMA files” that I’ve been writing about for the past few days. (See this entry and the follow-ups here and here.) His post, WMP Adware: A Case Study in Deception is enlightening for its depth, and it gives a real insight into how this sort of infection lands on a user’s machine. I agree with most of Eric’s conclusions, but I think he’s missing the forest for the trees in a few instances. Let’s start with this paragraph:

Contrary to Ed Bott’s assertion that this is not a “new and horrifying security risk” the installation practices that users are forced to deal with when attempting to play these rogue Windows Media Player files are so confusing, deceptive, and coercive that regular users are at high risk for unwittingly consenting to the installation of spyware and adware, with potentially dire consequences for their computers, to say nothing of their privacy and security.

My statement that this is not “new and horrifying” reflects the simple reality that these are the exact same techniques that purveyors of crapware have been using from Web sites for years. The ActiveX dialog boxes Eric posted are identical in every respect to those that users see when they visit Web pages that push the same software. This is merely a new variation on an old theme.

When I read the original PC World article, which was long on breathless assertions and short on detail, I was worried that this was a “zero-day exploit” that used a previously unknown vulnerability to install software on a user’s computer without any action required on their part. A reasonable person reading the original article might assume that their machine could get infected simply by playing a music or video file. Similar exploits have happened in the past, and it would be truly horrifying if this was new exploit that could sneak past even a sophisticated user. But that’s not the case. Everything in this exploit could just as easily be accomplished (and in fact is being done every day) by Web pages that open the exact same ActiveX dialog boxes. I hate the fact that these programs exist, and I’m certainly not defending them. But I don’t see much that’s new here.

Eric goes on to write:

The installation practices combine and exploit a dangerous combination of circumstances and qualities to bamboozle users into believing that they are consenting to the installation of software required to view media files. Among those circumstances and qualities are:

  • a legitimate, required Windows Media Player “Security Upgrade” that conditions users to expect the installation of required software;
  • ActiveX Security Warning boxes that users find inherently confusing because of the vague and inadequate information provided;
  • ActiveX installation prompts for software deliberately named to give the impression that it is yet another required Windows Media Player upgrade;
  • repeated, insistent pop-ups designed to coerce users into consenting to the installation of software;
  • murky, confusing End User License Agreements that fail to disclose the installation of third-party software as well as the functionality and privacy practices of that software.

With one exception, every item on that list describes exactly how spyware makers push software onto a naive user. The first item on the list is unique to Windows Media Player, but this is a dialog box that appears one time only. As Eric notes, the social engineering tactics that these folks are using are deliberately designed to fool users into thinking that the programs are required updates.

Eric continues:

What we need from Microsoft is a swift fix for the problems summarized here, not attempts to minimize and pooh-pooh the risk or to subtly suggest that users are the problem for not upgrading to XP SP2 and for clicking through installation prompts. As I stressed in an earlier post here at DSLR, it is absolutely inexcusable that media files should have ever become a vehicle for pushing spyware and adware on unsuspecting users. Media files should simply not be a vehicle for adware installations. Period. That there are preventative measures for this unwelcome behavior and functionality is no excuse for the problem itself. It should have never existed in the first place.

Just for the record, I am not trying to minimize this, nor am I blaming this on the user. In fact, I have specifically said the exact opposite. My original remarks were directed at people who regularly visit this site and who read the forums on Broadband Reports. Those people are most likely to be expert users who would be deeply suspicious of dialog boxes like these and who are likely to be running modern, fully patched operating systems. Sadly, they’re the minority in the larger computing world.

The reason that spyware and viruses are epidemic is that older versions of Windows make it easy for people to push this crap, and as Eric correctly notes, the confusing interfaces make it easy for naive users to be fooled by basic social engineering.

I think it’s important that we focus on the forest, not the trees. The biggest problem of all right now is finding a way to protect users of older Windows versions from agreeing to this stuff, regardless of where it comes from. If you fix the ActiveX problem in Internet Explorer, you fix it in Windows Media Player. As I noted, the security features in SP2 worked to prevent this exploit from confusing innocent users. There needs to be an equally effective way to make that protection work for users of older operating systems.

Eric says I’m “blaming the user” because I wrote this:

But really, isn’t that the real problem here? People running old operating systems, with only a dim awareness of the need to do updates and a willingness to install anything? … But how likely is it that the type of user Suzi is describing will download and install that patch?

I stand by that remark. Eric is demanding that Microsoft patch this vulnerability. I agree that that should be done. But the reason that viruses and spyware spread is because no matter how hard we try, many people simply don’t install patches after they’re released. I get virus-infected e-mail messages every day. In most cases the people who are infected with those viruses would have been protected if they had installed a patch that was released three or four years ago. If someone hasn’t installed that patch, why would they install a new one to fix this vulnerability?

As I’ve said since Day One, I believe that this is a security flaw and that Microsoft needs to issue a patch to Windows Media Player 9 and release it as a Critical Update. I would hardly call that an “attempt to minimize and pooh-pooh the risk.”

I have also reported this issue to security@microsoft.com. That’s an important first step in getting a patch written and released.

Firefox tweaks: one size doesn’t fit all

I’ve seen a bunch of links to various tweaks intended to make Firefox run faster. Boing Boing probably spread this go-faster tweak for Firefox farther than anyone. In addition, Brian Livingston published a lengthy Secrets of Firefox 1.0 article in his Windows Secrets newsletter last month.

I’ve been writing about various Windows speed-up tricks through the years, many of which are very popular and either misleading or flat-out wrong. Often, someone who follows all the advice in one of these articles winds up with a system that runs slower and is less stable than it was before.

That may well be the case with these Firefox tweaks as well. Brian is a reliable source of information, and I trust his advice. I also believe him when he writes:

The most sought-after performance improvements in any browser will always involve how quickly it downloads and renders Web pages. The good news is that Firefox (which is already pretty fast in its default configuration) includes numerous about:config settings that can improve the downloading and display of content. The bad news is that the optimum settings will differ from machine to machine, and there’s no consensus on what they should be.

After extensive research, I haven’t found a utility or even a well-tested explanation that can guarantee the optimum settings for any particular Windows scenario (Windows 2000 vs. XP, DSL vs. T1, etc.).

There are scores of Web sites that speculate on configuration settings that are said to speed up the browsing experience in Firefox. But these sites largely don’t show that they’ve done adequate testing of the alternatives, much less explain how such tests might have been conducted.

Asa Dotzler of Mozilla has written a cautionary note about some of the speed-up tips going around. He says something very similar:

Just note that what works for one person/system, may not work for another.

Yes, there are tuning change you can make (even at compile time, see Moox’ optimized builds) that will dramatically alter the performance characteristics of Firefox. Feel free to experiment, but remember that most of the defaults are defaults for a reason. If your browser starts misbehaving or web sites look broken, it might be worth going back to default settings.

That seems like a good opportunity to mention what I consider as one of Firefox’s greatest features: You can create and copy profiles anytime so you can test settings and extensions. If you’re trying out some odd tweak or extension, keep a copy of your old profile. If the tweak doesn’t work or the extension causes problems, you can quickly return to your old profile.

Windows XP users can open the Firefox Profiles folder by clicking Start, then Run. In the Open box, type %userprofile%\Application Data\Mozilla\Firefox\Profiles (include the percent signs, which automatically take you to your personal data folders). Make a copy of the profile folder you see there, which consists of a random eight-character string and the name of your default profile. You can then make changes to your current profile; you can undo those changes by closing Firefox and restoring the backed-up folder.

To create a new profile, use the well-hidden Profile Manager. Use the Run dialog box again and type firefox.exe -profilemanager as the command.

You can use the Profile Manager to switch between profiles. I actually keep several profiles – one for everyday use, one for some special-purpose tasks that require extensions I don’t normally use, and one that is completely clean, so I can test pages without fear that an extension is distorting my results.

Microsoft’s secret security plan?

Mary Jo Foley at Microsoft Watch has an interesting report on a rumored security subscription service from Microsoft, code-named “A1”:

Microsoft’s anti-virus/anti-spyware strategy is taking shape. Sources say Redmond’s prepping a fee-based bundle, which could go beta soon.

Publicly, Microsoft continues to be cagey about packaging and pricing plans for its anti-spyware and anti-virus solutions. But privately, Microsoft has begun informing partners of its plans for a security subscription service code-named “A1,” according to developers who requested anonymity.

Microsoft bought anti-virus vendor GeCAD in the summer of 2003, and anti-spyware maker Giant Company Software last month. As to how it plans to deliver these technologies, Microsoft has declined to give specifics. How/when/if it will repackage GeCAD’s technology remains uncertain. Ditto for Giant’s — although according to the Windows enthusiast site Neowin, Microsoft is expected to field its first anti-spyware beta based on Giant’s technology this week. Neowin said the anti-spyware beta is code-named “Atlanta.”

Microsoft officials have said the company is planning to make some form of its anti-spyware product available as a free tool. But that isn’t the ultimate plan, partner sources said.

Well, I’ve said it before and I’ll say it again: Microsoft should make this service as powerful as possible and not charge a dime for it to anyone. It’s part of the cost of doing business. Selling security software is ethically wrong for two reasons: 1) It involves making a conscious decision to expose some of your customers to greater risks than others, based on their ability to pay; 2) It encourages the security software vendor to overhype threats to encourage people so they’ll be stampeded into paying up.

I’m sure someone at Microsoft is saying something like, “Well, we’ll provide a free security offering that will provide basic protection to everyone, and we’ll just charge extra for bells and whistles.” That’s nonsense. Security should be considered a core feature, not an add-on.

Spread the word. Make some noise. Now is the right time to convince the folks who are making these decisions to do it the right way.

Windows Media Player secrets

Mike Williams explains the mysteries of Windows Media Player Artist fields:

WMP gives you three primary fields to work with for musical artists: Album Artist, Contributing Artist, and Composer. While functionally different, successive versions of WMP have hopelessly complicated how these are presented to the user. In v10, the Library has a tree associated with each, whereas v9 only exposed a [Contributing] Artist tree.

I had figured out some of this stuff during the writing of Windows XP Inside Out, Second Edition (when WMP10 was still in beta), but this post taught me several really interesting things I didn’t know. If you use WMP and you have a large media library, this is a must-read.

I discovered Mike’s blog thanks to Matt’s wiki. Isn’t the Web a wonderful thing?

File association fixes

You install a program. You decide you don’t like it. You uninstall it. But it changed your associations for a whole group of files, and now your original program doesn’t work. What do you do?

Visit Doug Knox’s site and pick one of these handy-dandy downloadable Windows XP File Assocation Fixes. He’s got 24 in all, from Batch Files to Zip Folders.

This also comes in handy if you inadvertently make a wrong choice when using the File Types tab on the Folder Options dialog box.

Comcast’s new HD-DVR

Just before the holidays, Matt Haughey had some first impressions of Motorola’s serious looking DVR, which is now rolling out to Comcast users. In a fresh post today, he has designer James Duncan Davidson’s first impressions of the unit and links to a screenshot of the unit in action.

Only 15 hours of HD recording? Only 60 hours total? That would be a deal-breaker for me, even if the interface looks way better than the horrible Scientific Atlanta software.

I’ve ordered a Fusion HDTV card for the Media Center PC and will be experimenting with over-the-air HDTV. (They say it supports MCE 2005.) If it works, the Cox/SA box is going back…