The blog

The itsy-bitsy Windows XP boot drive

Over at eHomeUpgrade, Will Wagner indulges in a little science project: How-To: Boot Windows XP Off a Compact Flash Card.

This article describes how I was able to get BeyondTV Link, a .Net application, running Windows XP Home using an inexpensive compact flash card. As a disclaimer, please note that your mileage may vary when doing this procedure so please don’t blame me if things go badly, your spouse leaves you, and/or your dog bites you as a result of this article.

He started out trying to boot from a USB flash drive and decided it couldn’t be done. Sounds like a challenge. Anyone want to try?

Really lame security advice

CNET News tries to spread some panic about desktop search technologies and misses the point completely:

Security experts are warning that virus writers could use new desktop search tools to make their malicious software more efficient.

Foad Fadaghi, senior industry analyst at Frost & Sullivan Australia, said that most viruses are designed to harvest e-mail addresses and other personal information from an infected system. He warned that because desktop search tools such as those recently announced by Google, Microsoft and Yahoo can index and categorize that information, virus writers are likely to start exploiting the technology.

“Desktop search products are very efficient at harvesting data, so it wouldn’t be surprising if exploits are sought by malicious coders. Any software that can index and capture data on a user’s PC will be subject to virus and Trojan exploits. It is just a matter of time,” Fadaghi said.

And how exactly would they do this? If you install an untrusted piece of software, someone else owns your PC. They can do anything they want, with or without the help of an indexing engine. (Oh, and by the way, Windows XP already has an indexing engine, and has since Day 1.)

The implication of this story is that you are somehow safer if you allow a virus or worm to be installed on your computer but don’t have desktop search software running.

Do you believe that? I didn’t think so.

Ultimate password protection

Carl Siechert and I are currently updating Windows Security Inside Out for a second edition due early next year. One promising new development that can really help you keep your online identity secure is to use a fingerprint reader manage your logons. Amazon has the Microsoft Optical Desktop with Fingerprint Reader on sale right now. I’ve been told that it does a great job of logging you on automatically to your computer, remembering all your saved passwords, and entering them automatically when you browse to associated Web sites.

The best part of a system like this is that you can safely use strong, unique, truly random passwords for every site you visit. In fact, I generate a separate random password for every site and store them in Roboform. I keep the encrypted master list of passwords stored in an online drive and on a second system. That’s a big improvement over what most people do, which is to use one easy-to-remember password for every Web site. The trouble with that strategy, of course, is that if someone gets hold of your Amazon password, they can get into your Ebay account, and your PayPal account, and so on and so on.

Anyone tried this device yet?

The unfriendly skies

This just sucks. According to The New York Times:

Federal regulators plan next week to begin considering rules that would end the official ban on cellphone use on commercial flights. Technical challenges and safety questions remain. But if the ban is lifted, one of the last cocoons of relative social silence would disappear, forcing strangers to work out the rough etiquette of involuntary eavesdropping in a confined space.

Imagine a five-hour cross-country flight, on a full plane, with you seated next to a hyperaggressive lawyer playing hardball with some insurance company. In front of a real estate agent returning 20 calls from clients. Behind a guy bragging to his buddy about how wasted he got last night.

Can you imagine anything more annoying? With the possible exception of a Harley-Davidson brand leaf blower, I can’t.

Dear FCC: I don’t care about Janet Jackson showing her boobie for three-tenths pf a second at the Super Bowl. I do care about an airplane full of people chatting on their cellphones. Please get your priorities straight.

A geek’s-eye view of security

BigUnix has a fascinating article on computer security. Well, I found it fascinating. If you read it all the way through, then you may be a geek, too:

If a system has bugs, sometimes those bugs can be exploited in order to inject new code for the processor to execute. This can be a hardware, Operating System, or application bug. Almost always, the bugs tend to be a software bug. Those software bugs are usually the result of an unchecked boundary for some input data. When that boundary is passed, or overflowed, some of that input data mingles with execution code. This problem is a very old one. The naive solution, which has been tried for years, is to just fix all the broken code. The OS vendors may be realizing that this is too hard. Is there another solution?

If we look at the most common platform on the net for common users, it is the Windows Platform. According to the Google zeitgeist for May, this is probably at least 50% of the internet. This platform has also been the most popular for viruses as well. Recently, Microsoft has stated that security is an important focus for them, and they have been taking great strides to redeem themselves from a long history of security issues.

Here are some of their solutions to code injection:

# They are pushing .NET CLR which will dramatically reduce the possibility of an exploit

# They are turning on the firewall on as the default and re-securing all of their network exposed systems (code reviews)

# They are implementing new stack checking systems into Visual C and other compilers for future programs

# They are utilizing the No-Execute (NX) feature from the AMD64 architecture to provide memory protections in a finer granularity within a Win32 process

Of all of these, the No-Execute feature is by far the most interesting. It is a simple hardware enhancement to the x86 architecture that arrived with the introduction of the AMD64 system. It is interesting to note that it has been present in other non-x86 CPU architectures (like MIPS) for years. Microsoft is going to give users the ability to use the NX feature under the name Data Execution Prevention (DEP) via XP Service Pack 2. So, what is it, and why did it take so long to get here?

The bad news is you’ll probably need all-new hardware to take advantage of this. But it’s coming.

Firefox stops blocking popups

A VC writes:

One of the main attractions of Firefox is the lack of spyware and associated stuff like popups that you get when you switch.

Well at least for me, that’s over.I got about four or five Firefox popups last week. The one shown above was courtesy of Panasonic.

I’d be curious to find out if this is happening to others.

Yes, it’s happening here. The makers of some types of popups have figured out how to work around Firefox’s popup blocker. Not only that, but apparently the Movable Type (blog software) Quick Post shortcut actually turns off the Firefox popup blocker!

This, by the way, is yet another piece of evidence that Firefox (although it is a wonderful bit of software) is not a magic bullet of security. As it gets more popular, it will get attention from the people who make popups, spyware, and other annoyances. Anyone want to bet on how long it takes before the first piece of spyware gets installed through Firefox?

Update: I created a clean Firefox profile and the browser is correctly blocking popups again. This suggests that an extension (probably related to tabbed browsing) is to blame. Is the incredible popularity and utility of Firefox extensions a double-edged sword?

MCE 2005 FAQ

The AVS Forum is filled with really smart people who know a lot about all sorts of digital home entertainment topics. I stumbled across their Mce 2005 Faq today. Wow! What a great resource. They’ve even managed to get Jay P. Kapur, Lead Program Manager of the Windows Media Center TV Team, to post.

If you use MCE 2005, bookmark this thread. (And set aside an hour or more to read it. This thread’s currently at 15 pages and growing…)

MyPVRSucks.com

I’m a member of a Yahoo group devoted to the Scientific Atlanta Explorer 8300 personal video recorder. It’s been enlightening, to say the least, to read about the experiences of others who are stuck with this woeful piece of consumer electronics gear. Now, a software engineer who is also a part of that group has started MyPVRSucks.com:

When I upgraded my TV to an HD compatible set, I decided to get a Rogers Cablevision HD set-top box – and decided to get the PVR model at the same time. I envisioned a beautiful utopia where I could simply click the “Record” button while viewing the guide, and all my shows would be recorded in HD digital splendor, for my viewing enjoyment.

I picked the PVR up at my local Rogers store. Easy. As the transaction completed, the sales lady told me “Remember to power it off every night. You have to turn it off.” This is slightly alarming, but, what the heck… and I head for home with my nice new PVR.

Unfortunately, everything was not quite as smooth as I had hoped.

Because…

The Scientific Atlanta Explorer 8000 HD sucks!

The Scientific Atlanta Explorer 8300 HD sucks too!

And here’s why…

After having used a TiVo for nearly five years and spending the last month with Microsoft’s new Windows XP Media Center Edition 2005, I have to agree. I use the SA box because it is the only way I can record HDTV. But the software is dreadful. For instance, if you sit down to watch a show that is currently being recorded, you have to manually (and slowly) reverse your way through the current recording to get to the beginning. If you’re 20 minutes into a show, that can take two minutes. There is no way to start at the beginning. As you’re watching, the progress bar (which appears when you hit the Play button) doesn’t show you any indication of how much time has elapsed or how much remains. It’s a graphical display only.

Oh, and here’s my favorite: When the currently recording program reaches the end, the recorder automatically dumps you out of the program you’re watching and to whatever happens to be on live TV at that moment. To get back to where you were, you have to visit the list of recorded programs again, start at the beginning, and then fast-forward through the program. How lame is that?

Let’s not discuss the video artifacts, the sound that drops out mysteriously, or the dancing green bars that took over the screen for about five minutes during last night’s episode of Lost.

Judy and I have learned to resist the urge to watch a program on the Cox/SA box until it’s done recording. We’re also using the Media Center PC to record as much as possible, reserving the Cox box strictly for HD programming and for times when the single tuner in the MCE machine is otherwise busy.

Thanks to the mysterious software engineer who started MyPVRSucks.com, at least I know I’m not alone.

Update: For a more detailed look at the 8300HD and its alternatives, see TiVo versus MCE versus my cable company.

Spreading misinformation

Dan Gillmor is an excellent journalist and a ferocious critic of Microsoft. His blog is widely read and respected – in fact, it’s on my must-read list daily. That’s why I was distressed to see that a recent blog entry from Dan contained a startling bit of misinformation. As part of a discussion of Google News, Dan quotes Andrew Orlowski of the Register as having written:

…at one point in an Antitrust deposition Bill Gates claimed that “the computer wrote” one particular incriminating email. It’s the “cat ate my homework” excuse of the 21st Century.

The Washington Post has transcripts of the infamous Gates depositions from the August September 1998 depositions. I read through them, and I can’t find anything remotely resembling what Orlowski wrote and Gillmor quoted without fact-checking.

I’m not going to give Orlowski the benefit of the doubt and say that he was just paraphrasing something else. If you look back, you’ll see that he has spread this story before. In this story about Google, for example, published earlier this year, Orlowski directly quotes BillG:

At an awkward point in his testimony to during the Antitrust trial, Chairman Bill was asked to confirm that he’d written an incriminating email that had come from the account billg@microsoft.com. ‘The computer wrote it,’ said Bill.

I copied the full text of the Gates depositions here and allowed Copernic Desktop Search to index them. I did a dozen searches on a wide variety of words and phrases and can’t find anything remotely like this exchange.

It’s unfortunate when a writer for a Web site that is known for its snarky but entertaining takes on technical news makes up a quote. I don’t believe very many people believe the Register follows the same standards as real journalists. But Dan Gillmor is a real journalist, and he shouldn’t be spreading this sort of misinformation so casually.

Update: I found the passage in question, and I was right. Orlowski is grossly exaggerating, to put it mildly. This is from the Deposition of Bill Gates, September 2, 1998 (follow the link above if you want to read for yourself):

Q. BY MR. BOIES: And you type in here “Importance: High.”

A. No.

Q. No?

A. No, I didn’t type that.

Q. Who typed in “High”?

A. A computer.

Q. A computer. Why did the computer type in “High”?

A. It’s an attribute of the e-mail.

Q. And who set the attribute of the e-mail?

A. Usually the sender sends that attribute.

Q. Who is the sender here, Mr. Gates?

A. In this case it appears I’m the sender.

Q. Yes. And so you’re the one who set the high designation of importance, right, sir?

A. It appears I did that. I don’t remember doing that specifically.

Q. Right. Now, did you send this message on or about August 15, 1997?

A. I don’t remember doing so.

One of the first things a lawyer tells you when you are about to be questioned for a legal proceeding is to answer the question exactly as asked. Don’t volunteer information. Don’t explain. In this case, Boies asked Bill Gates whether he typed a particular phrase at the top of the printed e-mail. Gates answers, truthfully, that he didn’t type that. As any Outlook user knows, that information was inserted by Outlook when the message was printed, based on the Importance attribute. Gates correctly made Boies work to get that information.

Now, you can argue, and I won’t disagree, that Bill Gates made some serious mistakes during this deposition, not the least of which was coming across as hostile and uncooperative. But that’s a question of public relations, not law.

Anyway, Orlowski’s repeated assertion that Bill Gates said “The computer wrote” that e-mail isn’t true. It makes a great urban legend, but it isn’t based on the facts. Unfortunately, when a savvy reporter like Dan Gillmor prints a story like this one without comment or fact-checking, it becomes another hit in the Google cache, and pretty soon this “fact” becomes common knowledge.

I know Dan has been busy lately with his new venture into “emerging grassroots journalism.” This is very exciting stuff. I wish him the best of luck and can’t wait to see and maybe even participate in it.