The blog

Still more on WMA and spyware

Andrew Clover adds a comment to my original post with some interesting observations. Worth reading.

One correction to Andrew’s note. He writes:

I did get one ActiveX download box from MS for the DRM stuff immediately prior to the two bogus downloaders, which looked almost identical.

That’s not an ActiveX download. That’s an automatic update from Windows Media Player. It’s not served up as HTML, and it looks completely different. Yes, a user (even a sophisticated one like Andrew) may be confused into thinking this is the same thing. But ultimately, IMO, this is the saving grace for Microsoft.

Because Windows Media Player has an auto-update feature, Microsoft should release a WMP patch that disables all ActiveX functionality in the instance of Internet Explorer that is hosted by the License Acquisition dialog box. They should then push this patch out as a required update via Critical Updates and through the auto-update feature in Windows Media Player. That step would go a long way toward solving this problem.

Update: In a comment, Andrew insists that the DRM update looks exactly like the spyware installers. I went back and snapped some screens so you can compare. I’ve got the details in the extended portion of this post.

Continue reading “Still more on WMA and spyware” →

More on “poisoned” media files

In a comment posted to my earlier post on “poisoned” Windows Media files, Ben Edelman offers the sort of excellent counterpoint you’d expect from someone who is not only attending Harvard Law School but also studying for a PhD in economics at Harvard:

I don’t think it’s right to say the license agreement is “quite clear on what [users] would get.” Certainly the license never says anything like “this program will install 30+ other programs from third parties, and clog your registry with tens of thousands of new entries.”

Fair enough. My comments were not in any way meant to let the scummy purveyors of this crapware off the hook. My intent was to indicate that a security-conscious individual who follows the links in the installation dialog boxes will see plenty of stuff to raise red flags.

Update: I went back and read the terms of service for iSearch and iLookup, which was the second module installed using this file. The terms of service specifically say: “…you understand and agree that the Software may, without any further prior notice to you … automatically update the Software and install added features or functionality or additional software, including search clients and toolbars, conveniently without your input or interaction.” (This doesn’t excuse the actions of the purveyors of this crapware, but any aware user will know exactly what he or she is getting.)

Ben’s absolutely right that the people who are behind these add-ins are preying on ordinary users with a wide range of tricks. Sadly, I’ve seen all these tricks used before, but that doesn’t make them any more acceptable here. I agree completely with Ben when he writes:

I think Ed gives too little weight to the especially deceptive circumstances of a software installation prompt shown when users try to watch a video. For one, legitimate media players actually do use these prompts to install necessary updates (i.e. the latest version of Macromedia Flash). In addition, the unusually misleading (purported) product name and company name make it particularly easy to be led astray here. Users deserve better.

I can end this post on a positive note, by the way. After I read the most recent update to Ben’s test report (including a link to this post and a discussion of my findings), I decided to carry the test one step further. I took a deep breath and did what a naive, foolish user would do: I clicked Install when presented with the first deceptive spyware prompt. And then for good measure I clicked Install when prompted to install the second spyware program as well.

How bad was it? Surprise! My test PC is running GIANT AntiSpyware, which promptly blocked the nasty program from installing with a stern warning.

giant_anti_spyware.JPG

I clicked Remove, and a subsequent scan showed that no spyware — zero — was installed on this computer. I had no unexplained pop-ups, my searches went to the place they were supposed to go, my home page was unchanged, and a scan of the firewall logs showed no suspicious activity. (Curiously, the SpiderSearch program was apparently not installed at all, and the iLookup module was blocked. I don’t know if this is the one that so throughly polluted Ben’s test computer.)

Last month, Microsoft purchased the company that makes GIANT AntiSpyware and announced plans to release a free public beta of the Microsoft-branded version of this program later this month. They also announced a new set of strategic initiatives to reduce the spyware threat. Based on my experience, they’re going in the right direction.

Update: Suzi at Spyware Warrior has some comments on her blog as well. Some interesting food for thought, but this line struck me more than anything:

I installed the same WMA file on an old Win ME box with no protection except AVG free and the free version of Zone Alarm.

She goes on to describe the disaster that befell that computer. But really, isn’t that the real problem here? People running old operating systems, with only a dim awareness of the need to do updates and a willingness to install anything? Spyware is an epidemic now precisely because it is trivially easy to install it on that type of computer.

Don’t misunderstand what I’m saying. Microsoft can and should patch Windows Media Player (9 and 10) so that it rejects all ActiveX controls. Period. It should push that patch out as a Critical Update. But how likely is it that the type of user Suzi is describing will download and install that patch?

“Poisoned” Windows Media files: more details

In an earlier post, I pointed to the fast-spreading but suspicious story alleging that a flaw in WMA files can plant spyware on your computer. This is a follow-up.

In the extended portion of this post, I provide details and screen grabs. I’m indebted to Eric L. Howes for his assistance. Thanks to Ben Edelman for posting a detailed report on his experiences with earlier operating systems and to Andrew Clover who provided a sample file that ultimately made its way to me.

Here’s a quick summary of what you need to know:

  • The PC World story contained several errors and some misleading statements.
  • I have not identified any circumstance in which this exploit can install software on a computer that has a properly patched version of Internet Explorer. The victim must specifically click a button to install the spyware.
  • The programs in question are digitally signed and are from known companies. The terms of service make it clear what you’re getting. It takes one click and 10 seconds of reading to realize that the correct answer is no.
  • The installation mechanism uses social engineering tricks that could fool a naive user. These are the same tricks that are used on Web pages (especially porn sites) to install spyware.
  • You are most likely to acquire one of these “poisoned” WMA files from a peer-to-peer file-sharing network. The risk that you will get a file like this from a reputable music seller that uses digital rights management is as close to zero as it is possible to get.
  • If you use Windows XP with Service Pack 2 and Windows Media Player 10, you are completely protected.
  • If you have restricted ActiveX programs from being installed on your computer, you are completely protected. If you have assigned a program other than Windows Media Player to play back Windows Media content, you should be protected as well, although I didn’t test this scenario.
  • Clearing the option to acquire software licenses automatically seems to have no effect on this exploit. [Update: A later update to WMP 10 changed this setting so that it now provides an extra warning before displaying the license acquisition dialog box.]

Continue reading ““Poisoned” Windows Media files: more details” →

MCE plug-ins

If you have a Media Center PC (or if you’re thinking about getting one), bookmark mcesoft.nl:

Media Center Plug-ins are little programs that give new possibilities or expand existing functionality to your Windows XP Media Center Edition. Many programmers have made and are still making these Media Center plug-ins to make features available which aren’t there when you have a Media Center “out of the box” This goes from features like a system for categorising your DVD’s and Movies complete with descriptions, actors and director info to features like having your local current Weather situation and forecast available, but it also includes the possibility to listen to or watch online media or the possibility to edit or compress recorded television and make a DVD of it. This site is dedicated to those plug-ins and we will try to give you as much info as possible about them.

I just installed the latest version of MCEWeather. Excellent, and it works with my Media Center Extender as well.

Please help

Update: I’ve changed the date and time on this post so it will stay at the top of my blog through December 31. As of 12:00 noon PST on Wed 29-Dec, more than $2.25 million has been donated to the relief fund through Amazon.com alone. That is an amazing thing. Thanks to everyone who has done so.

Further update: As of noon on Thursday 30-Dec, more than $4.25 million has been donated through the Amazon.com link alone.

I can’t even begin to fathom the scope of the tragedy in South Asia. I do know that we can all help by sending some money to the relief effort. I got a few checks for Christmas that I was thinking of spending on some new toys. The toys can wait.

One very easy way to donate is via Amazon.com. The link below allows you to make a direct donation to the American Red Cross. Amazon takes absolutely nothing, and I get no compensation either.

[Update: Amazon link removed as it’s no longer live.]

If you’d prefer to donate directly, I’ve posted a list of reputable organizations in the extended portion of this post.

Look, we Americans are the richest nation on earth. The CEOs of Goldman Sachs and Merrill Lynch this week received year-end bonuses that add up to more than this country has so far pledged to the relief effort in South Asia. If by any chance those two gentlemen are reading this blog, it would be nice for them to kick in a few millions. If you were lucky enough to get a year-end bonus, this would be a great place to share it. Meanwhile, I’ll do what I can with what I have, and I ask you to join me.
Continue reading “Please help” →

Firefox is not a security cure-all

I have lost count of the number of times I have read reviewers telling people that they should switch to Firefox because it is secure, unlike Internet Explorer. This is simply untrue. Mozilla-based browsers are somewhat more secure than IE, for two main reasons: one, they don’t support ActiveX controls (although with Service Pack 2, the likelihood of being attacked by an ActiveX control has dropped dramatically); and two, because most virus/spyware writers have historically targeted the IE platform. But the more successful Mozilla/Firefox becomes, the more likely it is that bad guys will start targeting it too. Over time you will see more alerts like this one:

SecurityTracker.com Archives – Mozilla Buffer Overflow in Processing NNTP URLs Lets Remote Users Execute Arbitrary Code

(This vulnerability is fixed in the version of Mozilla that forms the core of Firefox 1.0, so don’t worry if you’re running the released version of Firefox.)

Virtually every virus and spyware attack in recent memory has taken advantage of a vulnerability for which there was a patch. Windows users who conscientiously apply patches and security updates (a painless process using Automatic Updates) don’t get hit. Those who ignore updates become victims.

Firefox does script. It uses buffers. Most viruses and many spyware programs use buffer overflows and hostile scripts to force unwanted software onto users’ machines. If you install a copy of Firefox and then don’t update it when a security patch comes out, you are vulnerable to these exploits.

The programmers who put together Firefox have done a remarkable job. But I guarantee you they are on the lookout for reports like this one. When (not if) someone discovers a critical flaw in Firefox, they’ll write a patch. Will all 14 million people who have downloaded Firefox 1.0 also install each new patch? We’ll see.

Update: For news of a later and apparently more ominous security hole that affects Firefox but not Internet Explorer, see “Oops! This Firefox security exploit is a doozy.”

Terminating spyware with extreme prejudice

This first-person account of a reporter’s struggle with spyware is amusing and surprisingly accurate:

I can trace the decline of my computer’s performance to an ill-advised download over the summer. In a pop-music-induced frenzy, I am embarrassed to admit, I went to http://www.kazaa.com, downloaded and installed the free file-sharing service, then proceeded to download (a k a steal) Britney Spears’s and Madonna’s collaborative effort, “Me Against the Music.”

I was about to get my karmic retribution.

In downloading Kazaa, I had inadvertently opened the floodgates to all manner of spyware. By the end of the summer, even after I had deleted Kazaa and installed Norton AntiVirus 2004 – which took care of the virus-related part of the problem – I was unable to open Internet Explorer without being deluged with pop-ups enticing me to buy everything from herbal weight-loss pills to obscure business publications.

My home page would mysteriously try to redirect itself to a site called badgurl.grandstreetinteractive.com. Little gray dialog boxes would pop up in the center of my screen to inform me, shockingly, that my computer might be infected with spyware. Then it would crash.

I really couldn’t relate to the melodramatic descriptions of how intimidating the process of wiping and restoring a hard drive is, however. But I guess for people who don’t do this for a living, that’s a big deal.

Digital rights (and wrongs)

In a previous post, I included a snippet that linked to Chris Anderson’s blog The Long Tail. (Chris is editor of Wired magazine.) After I posted that, I read a little more. I’ve been meaning to write about digital rights lately but haven’t found the time to set out a coherent thought on what can be a very controversial topic. So I was pleased to find this statement, which pretty much matches my thoughts:

Like Larry Lessig and his Creative Commons project, we believe in the value of protecting intellectual property rights, but we’re opposed to overzealous extensions and implementations of those protections. Copyright good; infinite copyright bad. Piracy bad; treating everyone like a pirate worse.

But equally, we believe in putting the consumer first. Consumers want more content, easier-to-use technology, and cheaper prices. If some form of DRM encourages publishers, consumer electronics makers and retailers to release more, better and cheaper digital media and devices, that’s not necessarily a bad thing. This is just being realistic: much as we might want it to be otherwise, content owners still call most of the shots. If a little protection allows them to throw their weight behind a lot of progress towards realizing the potential of digital media, consumers will see a net benefit.

The real question is this: how much DRM is too much? Clearly the marketplace thinks that the protections in the iPod and iTunes are acceptable, since they’re selling like mad. Likewise, the marketplace thought that the protections in Sony’s digital music players (until recently, they didn’t support MP3s natively) were excessive and they rejected them. Indeed, we were one of the first to criticize Sony in a big way for getting that balance wrong.

Let me put my biases right out front. I spent 20 years working for print magazines, and I’ve been writing books for more than a decade. In a sense, I am in the same business as musicians and movie makers, with a crucial difference: Anyone with the right software can make a perfect digital copy of a CS or DVD, cheaply and at essentially zero cost. You can’t make a perfect copy of a book or magazine unless you own your own printing press, and the cost is more than most people can bear. For now at least, it’s easier to buy a book than to print your own copy. And even though all the books I’ve written in recent years have also been available in electronic versions, I guess people still like to turn pages and scribble notes in the margins, which you can’t easily do with an e-book.

When perfect copies are easy and free, the temptation to make copies and pass them around is overwhelming, even for people who are basically honest. So, like Chris, I understand the need for protecting digital media. But as soon as any company decides to use DRM to protect their rights, they have a responsibility to make it not only possible but effortless for me to exercise the rights I buy from them. I should be able to make archival copies. I should be able to play music on a portable player and a car stereo and my home music system without paying for it three times, and the TV shows I record for personal convenience shouldn’t expire unwatched just because I’m on a vacation that lasts more than two weeks.

I think the Electronic Frontier Foundation is doing excellent work, but I don’t agree that all media should be free to copy by anyone, anywhere, at any time. Reasonable restrictions are just fine with me. It’s too bad the entertainment industry (movies and music) is run by people who don’t seem willing to be reasonable about much of anything. That’s one reason I listen to a lot of music by artists on independent labels. I’d love to see an equally healthy independent movie and video industry that could tell the big studios to shove it.

Spyware in WMA files? Color me skeptical…

The normally reliable Techdirt admits that the following story raises many more questions than it answers:

Is The Recording Industry Hiding spyware In Windows Media Files?

When the recording industry first tried to get politicians to shut down file sharing networks, they went with the “it’s stealing music” line, which generated some interest, but most people didn’t seem to pay attention. Then, the industry suddenly became oh-so-concerned about the fact that child porn was on these systems, and tried to convince politicians they needed to stop file sharing for the “sake of the children.” Lately, it seems the industry will do whatever it takes to make file sharing systems look bad. With that in mind, it makes you wonder if they’d go so far as to specifically hide spyware on file sharing networks just to upset users. It’s not entirely clear if that’s what happened, but it seems like the most obvious explanation for the following story, which was found on Broadband Reports.

Overpeer, a subsidiary of Loudeye, has been caught hiding adware and spyware within Windows Media files. Overpeer is the same company that the recording industry has hired in the past to dump fake versions of songs on file sharing networks. What the article doesn’t answer is whether or not the industry hired Overpeer to dump spyware on the network as well, but it’s likely they’re pleased either way. Overpeer defends their actions by saying that anyone obviously deserves what they get because, obviously, they were looking for unauthorized files. It’s not clear that everyone would agree. Sneaking malicious files onto someone’s computer because “they deserved it!” doesn’t seem like a very good justification.

What may be even more important to this story, however, is the revelation of just how easy it is, thanks to a huge loophole in Microsoft’s copy protection technology, to include a malicious file with an audio or video file. Basically, because Windows DRM needs to look for a license, all anyone needs to do is point that license to a website that loads malicious content and off you go. Thank you Microsoft, for creating a huge loophole that will probably make sure millions of new computers are loaded with spamming, DDOSing trojans shortly. Thank goodness for that Microsoft DRM, huh? Not only does it not protect any actual property while making things more expensive, it opens up plenty more people to malicious attacks.

OK, first of all, folks have been making similar allegations about Overpeer since 2002, as a quick search will reveal. I don’t know if it’s true, but if so then they should be prosecuted. Period.

However, I am always very suspicious of stories like this, where the underlying facts are impossible to replicate. I know enough about the way SP2 works to know that what is being described here shouldn’t happen on a system with SP2 installed, and I’ve read enough bad journalism from PC World and similar mainstream sites to be suspicious of the underlying facts. In particular, there is no way that Windows Media Player should be able to load an ActiveX control, because of the security zone it runs in. So color me skeptical…

And no, I do not agree that if you use Kazaa you deserve whatever you get. But if you use Kazaa or any underground file-sharing system to randomly troll for files from a worldwide network of untrusted services, you should expect to be attacked often, by the state of the art in malware. Likewise, if you spend enough time trolling in the porn underground you should expect to fight off a steady stream of pop-ups and attempts to load spyware. Is it right? No. Is it real? Absolutely. This is why I refuse to provide support for any friend or family member who uses Kazaa unless they agree to remove it from their system and keep it off. And you know what? It works.

Update: I see this story has now been picked up by Boing Boing, which means it will get a lot of publicity. That’s unfortunate, because the original story is just so murky.

Further update: I’ve received a sample file and have done some tests. Read the results here.