The blog

Busting a virus writer

Larry Seltzer at eWeek has an interesting new article called Who Wrote Sobig?

Follow the links to read a series of reports that purport to identify the specific individual who wrote this worm and why he did it. Interesting stuff.

As I learned in Journalism school from studying Woodward and Bernstein, just follow the money. I wonder if the Russians would be interested in extraditing this guy…

More on cookies and spyware

Adam Gaffin at Network World Fusion gets comments from people demanding to know why his Web site is trying to install spyware on their computer. His reply:

Well, good for you dear sir or madam for running anti-spyware software on your PC. It’s a good idea, and I do it myself. Unfortunately, your software is equating a bit of text with a malicious application.

What we do is use “tracking” cookies from DoubleClick so we can track aggregate site numbers (how many people visit page X, how many articles about topic Y are viewed, etc.)

These are NOT spyware applications. These are simple text files. Text files cannot take over your browser. They can’t screw around with your Windows Registry. They don’t keep you from uninstalling them.

Like I said: Cookies are not spyware.

Which Windows utilities should you run?

In the comments on another post, longtime reader Ken asks a great question:

…I would love to get your thoughts on so-called “performance software” generally, such as utility suites (e.g. Systemworks, SystemSuite, System Mechanic, and the like), defraggers (such as Diskeeper and PerfectDisk), memory managers (e.g. Memokit, Cacheman), etc. — especially on Windows XP SP2. Ditto for “Internet Security” suites” and third party firewalls. My opinion on all of this is that with the possible exception of defraggers and a good stand-alone anti-virus program, less is more and native Windows XP (especially after SP2) is more than good enough for most users (even better for experienced users who know what not to download from the Internet). Do you agree?

Great question. I’m a minimalist when it comes to utilities. (If it ain’t broke, don’t fix it.) So here’s a quick summary of each category in Ken’s list:

  • Utility suites. I don’t typically use them. I used to be a big fan of Norton Utilities, but I can’t think of the last time I needed to perform some maintenance task that couldn’t be done with a single-purpose tool. I especially distrust those that run at startup.
  • Defraggers. I use and recommend Diskeeper and have heard good things about Perfect Disk. I don’t obsess about fragmentation, though.
  • Memory managers. Snake oil, especially on Windows XP.
  • Internet security suites and third-party firewalls. I use Trend Micro’s PC-cillin Internet Security 2005 and have installed it on several clients’ systems with excellent results. In my opinion a knowledgeable user can get by with just antivirus software and the Windows Firewall added by Windows XP SP2. For unsophisticated users, a firewall or anti-spyware monitor that is too aggressive can cause as many problems as it solves.

When you add it all up, I think your summary closely matches my preferences. Less is more, indeed!

If you want to see a list of all the software I currently have installed on my everyday computer, see this page.

Why should I trust Yahoo?

While doing research for the forthcoming update to Windows Security Inside Out, I stumbled across Jeremy Zawodny’s blog. From a post dated last May, I learned that the Yahoo! Toolbar has anti-spyware features. The fact that Jeremy works for Yahoo makes the following bit of bragging just a little unseemly:

The previously mentioned secret alpha test was for the just announced upgrade to the Yahoo! Toolbar which now contains anti-spyware code.

I have to say, this one of those ideas that was immediately obvious
upon hearing it. “Of *course* we should use the Toolbar as a way to
help poor Windows users get all that crap off their machines.” But at
the same time it’s amazing how many folks never came up with it on
their own, me included.

This is followed by a bit of obligatory Microsoft-bashing, which I guess I should expect. But I have a couple problems with the details in this post. I was able to Google around (oops!) and find a bit of information about the Yahoo Toolbar, starting with this page.

Here’s the problem, though. Yahoo wants me to download the toolbar and install it on Internet Explorer. (Sorry, doesn’t work with Firefox.) But try as I might, I can’t find any details on how this software works, what it does and doesn’t do, who developed it, and what it will do for me. I can take a little Flash tour and see a Fisher-Price version of how the toolbar works. But no technical details. Zero.

So, I’m just supposed to trust Yahoo? No, thank you very much. In fact, the most insulting thing about the whole package is the search box at the very top of Yahoo’s Anti-Spyware Community page. Yahoo has generously provided links to top searches, using phrases like anti spyware, spyware doctor, free spyware, spyware removal, and adware spyware. When I followed the links, I found some good search results, mixed in with an appalling number of phony anti-spyware products. And of course, every search result page starts with three “sponsored results” at the top of the page and a sidebar filled with more ads along the right side of the page. When I viewed the search page at 1024 X 768, I saw 7 links that were paid for and only three that were supplied by Yahoo’s search engine.

I did a little more searching to see if Yahoo had buried the technical details of its spyware toolbar somewhere. Nothing on Yahoo’s site. I found lots of stories in the computer press, most of them slightly rewritten versions of Yahoo press releases. Ironically, the top search result that wasn’t from Yahoo was a negative review from Adware Report. A slightly more complimentary story from eWeek contained the details that the spyware scanner in the Yahoo Toolbar is based on technology from PestPatrol Inc. But the rest of the story is just marketing.

So, if anyone from Yahoo is reading this, tell me please: Why should I trust Yahoo? Why doesn’t Yahoo trust me with the details of this software? And why do I feel like this is really just a way to get me to spend more time on Yahoo’s search pages?

(Full disclosure: I make a few pennies a day from the Google ads served on this site. So I suppose you could say I’m in competition with Yahoo. Still, I do something that Yahoo doesn’t, which is to block ads from companies that I’ve decided are selling fake anti-spyware software. I don’t want their money, but I see those ads on the Yahoo search pages. If Yahoo is really serious about “helping poor Windows users,” they should just say no to those ads.)

AOL says: We suck

Have you seen the new, exceedingly annoying commercials for AOL? Mike at Techdirt has, and he pens this comment about one of them:

It shows every AOL customer showing up at the headquarters to give suggestions. The message is supposed to be “AOL listens to its customers,” but what I (and apparently Seth) got was “every one of AOL’s customers has problems with the service and wants to complain.” Not exactly a strong selling point.

Heh. And if every one of those customers showed up at AOL headquarters with all the CDs that have arrived in the mail this year, they could probably make a stack that reaches about halfway to the moon.

“Cookies are not spyware”

An excellent post from Jason Dunn at Digital Media Thoughts today:

I’ve had two emails in the past week from Pocket PC Thoughts asking why we’re distributing “spyware” onto their computers. We’re not – it’s that simple. What people are seeing is over-protective anti-spyware software treating normal cookies like spyware….

In this case, Avenue A (one of the third-party advertisers that serves up banners when we don’t have our own paying ad) is doing nothing more than dropping a cookie on your machine. The cookie is like every other advertising cookie from DoubleClick and other large advertising agencies: it tracks what ads you’ve seen so it doesn’t show you the same ad more than “X” times.

It’s grossly irresponsible for these anti-spyware companies to treat cookies like spyware. REAL spyware is malicious, machine-hijacking junk that throw pop-ups on your computer, resets your start page, and all sorts of other ugly tricks. A cookie is a text file that has some non-personal information what banner ads have shown on certain sites. That’s it.

Go ahead and open the cookie on your computer and you’ll see it’s harmless. Cookies are not spyware, no matter how hard these anti-spyware companies try to make them out to be. You have to realize that these guys are trying to sell their software too, and if they start blocking cookies as well, they give the perception that they’re “protecting” you even more often. They have an agenda too – think about it.

Yes, indeed. Makers of security software have a vested interest in making sure you are afraid, very afraid. They want you to believe that the online world is dangerous and that without their software you are in danger of being mugged (virtually, anyway) every time you open your browser.

This idea is, to put it bluntly, just so much crap. I spend a frightful amount of time online. I look at all sorts of sites, some of them quite disreputable, when I’m researching security-related topics. And yet I’ve never had one of these evildoers plant a piece of so-called spyware on my computer. Why? Because:

  • I am conscientious about installing security patches. Any exploit that relies on OS and browser vulnerabilities is unlikely to affect you if you do likewise.
  • I do not install untrusted software, including ActiveX controls and browser add-ins, and I do a lot of due diligence before I decide to install a program even when it comes from a trusted source.
  • I am alert to the danger signs of possible problems with rogue software – sudden, unexplained deterioration in performance, mysterious pop-ups, crashes – and I work on solving those problems the instant they appear.

Did you notice that I didn’t mention cookies at all? I don’t spend a lot of time worrying about them. Yes, I block third-party cookies, and yes, I have my browsers set to alert me when a site wants to install a new cookie. But most of the time I say yes. Because cookies are not a serious problem. If anyone would care to point to evidence where someone has had their privacy or security attacked in a serious way as the result of a cookie, I’m interested in hearing about it. I watch this stuff for a living, and I’ve never seen anything that fits in that category.

I wish that the makers of anti-spyware programs would stop obsessing about cookies. All they’re doing is distracting us from the real threats.

Reality Check: Windows Update and SP2

I spend a lot of time reading what other people have to say about Windows. Through the years, I’ve found that a lot of the most common advice from so-called Windows experts is misleading or flat-out wrong. In Windows XP Inside Out, Second Edition, Carl, Craig, and I directly addressed many of these myths in sections entitled “Reality Check.” (You might be surprised by the number of myths we shatter in this book!)

One of the most common rants I’ve read lately is from experts advising experienced Windows XP users to turn off Automatic Updates and handle the job of patching Windows by downloading updates directly. This is a Very Bad idea. Here’s why.

After my recent post on overcoming SP2 problems, I received an e-mail message from an old friend who works on the Windows team. He makes a good case for why every Windows user should have Automatic Updates turned on.

By way of background, the two most common killer problems that afflict SP2 are caused by (1) a piece of rogue software called TVMedia, which causes a blue-screen (STOP) error when you restart your computer after installing SP2l; and (2) an outdated BIOS on a computer running a Pentium 4 chip based on Prescott C-0 processor stepping, which causes your computer to hang when you restart after installing SP2.

It’s important to note in both cases that the problem is external. The real solution is updating your BIOS or getting rid of the spyware, but that’s cold comfort when your computer has stopped working and trying to install SP2 was the last thing you did.

OK, Microsoft identified these problems within a very short time after releasing SP2 to the world and came up with fixes to prevent the blue-screen errors and hangs. I’ll let my friend at Microsoft explain what happened:

Windows Update (WU) and Automatic Update (AU) can detect a machine’s configuration (regkeys and files installed) which is how we know when to offer specific security updates, when they have been installed, etc. (privacy note: WU downloads a blob of data that describes the fixes available and their respective requirements and the local machine actually scans itself, it’s not scanned by the server.) As soon as we became aware of these two issues in August, we immediately put “safety blocks” on WU and AU so that SP2 would not be offered to anyone with either of the two conditions you note, and documented it in a KB article.

Then, as we developed, tested and signed off on the specific fixes later, we then posted those fixes on WU/AU, and modified the detection logic. Thus, if a customer has tvmedia or the problematic Pentium chips, the updates are offered up front, instead of SP2. Once they are installed where needed, SP2 shows up via WU or AU. So a simple test is to go to Windows Update – if you see SP2, then you don’t have an issue. If you don’t see SP2, but see one of these two packages, install it and then go back to WU. For the AU customer, this will happen automatically – on the first day, the updates are installed, and on the next day, SP2 starts downloading.

Each of these updates is only offered to machines that needs them, not to the general population. This is one of the reasons we encourage average users to install SP2 via WU/AU, in addition to the download size savings.

Ironically, the people who have Windows Update and Automatic Update disabled are MOST likely to be bit by this issue. The nightmare scenario, in fact, is for an expert user to try to outsmart the system by downloading SP2 directly and then installing it manually. If you try to do this on a system that is afflicted with either of these problems, and you didn’t install one of the two patches designed to prevent the problem, the results will be ugly.

For those who prefer to be conservative about patches, it is easy to configure Automatic Update so that it downloads any necessary patches but doesn’t automatically install them. Instead, you get a notification in the taskbar alerting you that new patches are available. Click the icon to see the full list, read all the details, and decide for yourself whether you want to install them.

Linux security

A little article at Windows IT Pro claims to have the results of a new study that proves Linux is the least secure OS:

According to a study the British security firm mi2g, Linux is the world’s “most breached” OS and is exploited more frequently than Windows. The company recently analyzed more than 235,000 successful attacks against computers that were permanently connected to the Internet during the past year and concluded that Linux was responsible for most of the successful exploits.

“For how long can the truth remain hidden, that the great emperors of the software industry are wearing no clothes fit for the fluid environment in which computing takes place, where new threats manifest every hour of every day?” DK Matai, mi2g’s executive chairman, said in a statement. “Busy professionals … don’t have the time to cope with umpteen flavors of Linux or to wait for Microsoft’s Longhorn when Windows XP has proved to be a stumbling block in some well-chronicled instances.”

To which I say, puh-leeze. I’m a Windows guy, but I’m not a hack, and this “study” just smells to the high heavens of hackery.

I’d love to check out the details so I could decide for myself, but the good folks at Windows IT Pro apparently decided that it wasn’t important to provide a link to the original study or to any information about the consulting firm behind the report. In fact, there are no links in this story at all except for the fake links inserted by the execrable Vibrant Media, which lead directly to ads, not real content.

Lame, lame, lame.

A quick Google search leads to a wealth of information about mi2g, much of it unflattering. Like this little blurb from Attrition.org.

You can find the mi2g press release on which the Windows IT Pro article was based here.

For the record, I think security problems in Windows are consistently overstated, especially for server versions, and security problems in Linux are probably understated on average. But articles like this one don’t add to the debate; they just give the /. crowd a big, fat, legitimate target.

Office 12 in 2006?

Mary Jo Foley has some very (very!) early Office 12 details:

According to partner sources who requested anonymity, Microsoft has established an internal Office 12 ship calendar that pegs Office Beta 1 availability for August 29, 2005. Beta 2 is slated for December 5, 2005. The internal release-to-manufacturing target is May 22, 2006. And the target for “street” availability for the Office 12 System is July 17, 2006, the sources said.

Hmmm. It might be a while before my next Office book.

Do you love espresso?

I used to spend a small fortune at Starbucks and Seattle’s Best Coffee and Peets. Not any more. About six months ago, I bought my own home espresso maker, and I’m pleased to say it works great.

The model I purchased is now on sale at Amazon.com. If you’re a fellow coffee lover, check out the Cappresso C1000. The $599 price tag may seem high, but trust me, this is a screaming deal. (Update: As of January 2005, the price tag is back up to $799. See what a deal it was?) I read lots of reviews at CoffeeGeek.com before settling on this machine. No regrets. At $3 per latte it will pay for itself in just a few months.