The blog

Sure. Macs are easier. Uh-huh…

As long as I’m sticking my toe into the Mac waters… I ran across this post from Jeffrey Zeldman today, which explains how users of Mac OS X can safely update to the latest version of their OS. (In other words, install the latest Mac service pack.)

Apple’s 10.3.6 update to OS X Panther worked wonderfully well for many users. But it created problems for many others, including slow startups, bizarre internet connection delays, and the sudden failure of networked drives.

Apple has just solved that problem by introducing version 10.3.7, which unfortunately creates problems for some users including slow startups, bizarre internet connection delays, and the sudden failure of networked drives. Oops.

The recommended procedure for installing this service pack … er, update involves the following steps:

  • Use a third-party tool to delete all cached fonts
  • Use another third-party tool to “repair permissions, run cron scripts, prebind the system, and clean system, user, and internet caches”
  • Run a full backup
  • Turn off all third-party startup items and
  • Remove all external hard drives from the desktop

At that point, you’re ready to perform the update. Apparently you need to hold your breath and face Cupertino while you do this, because after the update is complete you have to delete the font caches again, use that third-party tool to do all those bizarre techie tasks, slowly bring back the third-party startup items, and then…

After working with the Mac for a while without experiencing problems, run another full backup.

OK, can anyone explain how this is less complex for the average person than installing Service Pack 2 for Windows XP?

As long as we’re covering flame wars

You want to read a rant? A really great rant? Steve Gilliard is your man. Compared to Steve, Lewis Black is Mr. Rogers.

Steve is angry at Mac fanatics who insist that replacing your Windows PC with a Mac will solve all your problems. I’ve put the excerpt from Steve’s rant in the extended portion of this post, which means you’ll have to click once if you want to read his words and the rest of my remarks. If you’re offended by earthy language, don’t click. Me, I use some of those words on a daily basis, and they seem particularly appropriate here. (This isn’t basic cable, folks.)

Continue reading “As long as we’re covering flame wars” →

The Firefox flame war is on

I predicted Peter Torr would start a flame war with his Firefox post, and sure enough… To his credit, he’s addressed most of the criticisms directly in this follow-up post, entitled, I love Slashdot. My favorite part:

You’re spreading FUD

Well, yes, I suppose I am.

  • People should fear code they cannot easily verify
  • People should feel uncertainty about downloading and executing code that they cannot easily verify
  • People should doubt the integrity of code they cannot easily verify

And, to re-iterate what I said earlier, manually checking MD5s or compiling the source does not qualify for 99% of users.

This debate is very, very healthy. If Microsoft pays attention to the success of Firefox and improves IE to remain competitive, we all benefit.

How can you trust Firefox?

Microsoft’s Peter Torr invites a flame war with his essay, How can I trust Firefox? He walks through the installation and configuration process with Firefox and determines that it reinforces some particularly bad habits for users. He concludes:

I actually think Firefox is a nice browser. It seems to render HTML without any problems, and the tabs are nice for browsing Slashdot. But just because it doesn’t currently have any unpatched security vulnerabilities talked about in the press doesn’t mean they don’t exist (Secunia currently lists three unpatched vulnerabilities, for example).

Mozilla has had its share of security vulnerabilities in the past (just as IE has), and — despite what the open source folk might say — Mozilla keeps their security bugs hidden from the public (just like Microsoft does) in order to protect their customers from coming under attack by malicious users. Note that this is not a bad thing; all vendors should treat security bugs responsibly to ensure customers are not put at undue risk. It’s just something you should be aware of. Just because you don’t see any unpatched security bugs in Bugzilla doesn’t mean they don’t exist, either.

But the thing that makes me really not trust the browser is that it doesn’t matter how secure the original code is if the typical usage pattern of the browser requires users to perform insecure actions.

  • Installing Firefox requires downloading an unsigned binary from a random web server
  • Installing unsigned extensions is the default action in the Extensions dialog
  • There is no way to check the signature on downloaded program files
  • There is no obvious way to turn off plug-ins once they are installed
  • There is an easy way to bypass the “This might be a virus” dialog

This is definitely food for thought. My take? I use Firefox. It’s a nice piece of software, and in terms of usability I believe it is a better choice for folks who want a powerful Web browsing tool. But contrary to what some ill-informed folks in the media are saying, it is not a cure-all for security problems.

Google desktop security…again

An article in today’s New York Times reports that some university researchers have found a Flaw in Google’s New Desktop Search Program. This does seem like a legitimate concern, but here’s the part that troubles me:

An attack would require a user to visit the attacker’s Web site first, and any type of Web browser could make a user vulnerable. Google said there was no evidence that any such attacks had occurred.

The Rice group was able to create a Java program that makes network connections back to the computer from where it was downloaded and then make it appear as if it were asking for a search at Google.com. That was enough to fool the Google desktop software into providing the user’s search information. The program was able to do anything with the results, including transmitting them back to the attacking site.

OK, so in order to take advantage of this security exploit, you, dear Google user, have to visit a Web site run by some nasties, where you have to download a Java program and allow it to be installed on your computer. Presumably, the nasties would disguise this Java program as a game or screen saver or something equally shiny and appealing.

Which is the entire point. I’ll say it again: If a bad guy can convince you to install a program on your computer, it’s game over. Don’t install software from untrusted sources on your computer. And assume that any source is untrusted until you are certain that the opposite is true.

By the way, as the story makes clear, this exploit would work with any browser on any operating system.

Hotmail dumps McAfee, chooses Trend Micro

FirstAdopter.com points to a CNET News story today:

Starting today Microsoft is going to use Trend Micro instead of McAfee for anti-virus on Hotmail. The reason for the change is unclear although an Austrialian Microsoft executive said Trend Micro’s products offer “deeper virus protection.”

Excellent move. I don’t recommend McAfee software at all, and I am an enthusiastic supporter of Trend Micro. I use Pc-cillin Internet Security 2005 myself. I’ve installed this package on several clients’ machines in the past year and have heard nothing but positive reports. If you follow the link (I have no relationship with Trend Micro and get nothing for the referral), note that you can save some money by choosing the Upgrade option ( you qualify if you have any AV software at all). If you have multiple computers, check out the Home Security Pack, which is an excellent deal.

Windows Media Player performance

Thomas Hawk has a great Christmas wish list, with a lot of overlap to the things I’d like to see (I don’t need a Pogo stick with training wheels, though).

But in this post, once again, Thomas takes a shot at what he considers the miserable performance of Windows Media Player. I first read this complaint in a post by Thomas from last September, when he wrote an otherwise glowing review of Windows Media Player 10:

The single largest problem with Microsoft Media Player 10 remains the poor performance you have with large digital libraries. If you have 5,000 mp3s or less, this is not an issue. On the other hand if you are a hardcore, diehard, digital music enthusiast like I am then this simply will not cut it. I did notice a speed improvement between the WMP 9, WMP 10 Technical Beta and the final release of WMP 10 but it still can take about 1 minute and 30 seconds to move between playlists, libraries, etc. for my collection. Microsoft needs to continue to work on indexing and possibly allowing users to run the application in RAM to improve performance.

My digital music collection currently consists of 1,280 files in MP3 format and 10,488 files in WMA format, for a total of 11,768 tunes, which is well over the 5000-song limit where Thomas says he sees performance problems. In Windows Media Library and in Windows Media Center Edition, performance is essentially instantaneous for everything. When I click an album, a playlist, or an artist in the Media Player tree list, its contents appear without any hesitation. In Windows Media Center Edition, I notice a delay of approximately five seconds when I first view the list of albums, but after that, performance is lightning-fast.

The biggest difference between Thomas’s setup and mine is one he calls out explicitly: He’s a diehard supporter of the MP3 format, whereas nearly 90% of my collection is in WMA format. Every device I use supports WMA format (no iPod here), so this is simply not an issue for me. Anyone else see this issue?

Two smart things you can do for your data

I just got a call from a friend who had a hard drive crash. It appears his video card is toast, too, and this was the latest in a string of several hardware failures. He blames it on Mercury being in retrograde. I think there’s a more rational explanation: bad power.

Look, hardware can fail at any time. Circuit boards and chips are really sensitive to surges and spikes in your power supply. A simple power strip does nothing to protect you, even if it claims to be a surge protector. Most of those devices are just junk. What you really need is a universal an uninterruptible power supply (UPS), which is basically a big battery in a case that plugs into the wall and to which you can in turn plug your PC, monitor, and other sensitive devices. (But not your printer, which draws too much power).

You can find sales on decent UPS products regularly. I’ve got a couple of Belkin models here that work very well and cost around $30 when I bought them. I’ve also used APC products and wouldn’t hesitate to recommend them. When you get a power surge or spike, the device kicks in and filters the current. If you have a momentary power failure, the UPS keeps you running so you don’t lose anything. And if your power goes out for long enough, you can shut down gracefully and save what you’re working on.

The other thing everyone should have is an external hard drive for backing up important files. You can find DIY USB 2.0 drive enclosures just about anywhere, for around $20-30. Get yourself a cheap 80-120GB hard drive and put the pieces together. Voila! Instant backup device.

Update: Thanks to Ryan Walters for the correction on what UPS really means.

When we assume…

Joe Wilcox at Microsoft Monitor had a little problem accessing a Microsoft Web site today and decided to jump to some conclusions:

I found that I could easily get to the Website using Internet Explorer on Windows. This morning, I tried to access the Website using Mozilla’z Firefox and ended up at the same error page. Apparently, Microsoft’s Small Business Center Website is for people using its software, and I think that’s a mistake.

[…]

This wouldn’t be the first time a Microsoft Website locked out other Web browsers. And I can understand why Microsoft wants to hook SMBs as tightly as possible into its technologies.

[…]

The news media loves to rap Microsoft whenever it pulls these kind of proprietary stunts, particularly around Internet Explorer. I know plenty of editors who were reporters during the browser wars or Microsoft’s U.S. antitrust trial; they love to rehash that chapter of Microsoft history. I think Microsoft would serve itself better by making sure its Websites conform to World Wide Web consortium standards rather than assuming everyone uses Internet Explorer. I don’t really believe Microsoft Website developers are trying to lock out other Web browsers, so much as they don’t take them seriously. That’s a mistake.

OK, I use Firefox 1.0 here. I just tried to visit the Web site Joe wrote about. And guess what? It opened right up. So whatever the problem was, it didn’t seem to have anything to do with Microsoft trying to “lock out” other browsers.

Last August, Ed Foster was griping about Microsoft locking out other browsers from its online Knowledge Base. Guess what? That turned out to be a temporary issue also. I checked at the time and had no problem accessing the Knowledge Base search page with Firefox. Almost certainly unrelated to any deliberate decision to lock anyone out.

But it’s much more fun to write stories that say how evil Microsoft is. Even when they’re not true.

Fighting comment spam

I allow comments on this Web site. In fact, I encourage them. In the past, I’ve had to shut down comments for fairly long periods of time because of “comment spam,” automated attacks that fill the comments section with plugs for whatever sleazy product you can imagine.

The comments are open again because I upgraded to the latest version of Movable Type and installed the latest version of MT-Blacklist, an awesome program created by Jay Allen. If you leave a comment here, it may get held for my approval. That’s a small price to pay, considering that MT-Blacklist has blocked more than a thousand pieces of comment spam since I installed it two months ago.

Via this thread at Brad DeLong’s Weblog, I learn that Jay is now working for Six Apart, the developers of Movable Type. Congratulations, Jay!

If you have a blog, the combination of Movable Type and MT-Blacklist is absolutely awesome. So here’s a public thanks to all the folks who made this software possible.