The blog

RSS demystified

Wondering about RSS? Here’s an excellent introduction that explains all about feeds and aggregators.

If you’re visiting this Web site and others at irregular intervals in your Web browser, I strongly encourage you to learn about RSS. By using an RSS aggregator, you can skip the tedium of checking all your favorite Web sites and trying to figure out if anything’s changed. Your RSS aggregator does the checking for you, and whenever something new appears, you’ll be the first to know about it.

If you’re just getting started out, consider using Bloglines. You sign up for a free account, and then start adding sites to your list. From that point on, you can go to Bloglines and see all your subscriptions in one place. (Hint: Do a search on Bloglines for my name and you’ll have a chance to preview what the service looks like as well as to subscribe to my RSS feed by just clicking on a link.)

New RSS feeds

I’ve redone the templates for the RSS feeds generated by this site. It took a little prodding from Robert Scoble, who said he was going to drop any feed that didn’t publish full text. So OK, I now publish full text. No more wimpy excerpts. Robert, are you happy now?

You can take your choice of RSS 2.0 or RSS 1.0, both with full feeds. Icons are at the bottom of the right column on the main page.

Should pirates get SP2?

I bookmarked this column by Bruce Schneier some time ago but am just getting around to discussing it here. It’s titled, Microsoft’s actions speak louder than words:

Initial news stories reported that Microsoft would make this upgrade available to all XP users, both licensed and unlicensed. To me, this was a smart move on Microsoft’s part. Think about all the ways the company would benefit. Licensed users would be more secure and happier. Worms that attack Microsoft products would be less virulent, so Microsoft wouldn’t look as bad in the press. Microsoft would win, its customers would win and the Internet would win. It’s the kind of marketing move about which best-selling books are written.

Then Microsoft said the initial comments were wrong; SP2 would not run on pirated copies of XP. Only legal copies of the software could be secured. This is the wrong decision, for all the same reasons that the initial decision was the correct one.

[…]

This decision, more than anything else Microsoft has said or done in the past few years, proves to me that security is not the company’s first priority. Here was a chance for Microsoft to do the right thing: to put security ahead of profits. Here was a chance to look good in the press and improve security for all its users worldwide. Microsoft says that improving security is the most important thing, but its actions prove otherwise.

Well, I agree, mostly. It would be nice if SP2 was available for everyone, in the interests of making the Internet at large a safer place.

But I think this may be a bit of a red herring, too. This block occurs for what I suspect is a very small group of people who are running truly pirated copies of Windows XP. These copies are downloaded from warez sites and use product keys that were originally intended for use on volume licensed copies. It does not include those that were sold through gray-market channels, or those where someone has activated an extra copy or two. Technically, those are pirated copies as well, but they will have no trouble upgrading to SP2.

Schneier hints at the reality underlying all this: Anyone running one of these specific pirated versions of Windows XP knows full well their copy is illegal. They get reminded of it every time they try to download an update. And I suspect that the overwhelming majority of people who run one of these pirated copies will be able to find a “cracked” version of SP2 at the same place they got their original CD.

I would be curious to see whether one of these volume-licensed copies of Windows XP will be upgradable to SP2 using a CD or a separate download. I don’t have a pirated copy of Windows XP to test with, however.

Using the RunAs command

Aaron Margosis’s WebLog has some excellent observations on what should be an obvious security precaution for Windows XP users. In a perfect world, you would run as a Limited user, logging in as Administrator only when you need to perform an administrative task. Windows even has a RunAs command you can use to do this on the fly without the tedium of logging in and logging out.

The problem is that running as a Limited user is difficult. Too many programs just assume that you’re running as Administrator and refuse to run properly for a Limited user.

Anyway, props to Aaron for some excellent information on this site. If you’re security-conscious and want to give it a try, go for it!

Be someone’s computer hero

Scott Hanselman has a great suggestion. This holiday weekend (assuming you’re in the U.S., that is), take a few minutes to clean up PCs that belong to your friends and relatives. (With their permission, of course!) His checklist is a good start:

This holiday weekend, when you (computer person) visit your cousin/dad/aunt/grandma, give them a gift:

  • install anti-spyware software and configure it to run automatically on startup. I use SpyBot Search and Destroy.
  • enable their existing Windows Xp firewall, just turn it on
  • give them anti-Virus software (or install the free version of AVG)
  • run diskcleanup and defrag
  • lower the size of the IE cache
  • turn the security in IE up (for ActiveX controls) or install FireFox.

Great idea! I would add:

  • Get the latest patches from Windows Update and turn on Automatic Updates.

The whole process shouldn’t take more than 30 minutes, especially if you download Service Packs and anti-virus/spyware tools to your computer first and burn them to a CD.

Download.ject update available

Microsoft is releasing an update that addresses the most recent security vulnerability. Details in What You Should Know About Download.Ject.

On Friday, July 2, 2004, Microsoft is releasing a configuration change for Windows XP, Windows 2000, and Windows Server 2003, to address recent malicious attacks against Internet Explorer, also know as Download.Ject.

Windows customers are encouraged to apply this configuration change immediately to help be protected from current Internet Explorer exploits.

The update is currently available on the Download Center and will be made available later today on Windows Update.

Customers who have enabled automatic updates will receive the configuration change automatically. We recommend that customers immediately install this configuration change as soon as it is downloaded by automatic updates or by visiting the Windows Update site later today.

If you use an older version of Windows, you’ll need to make some manual changes using the procedures outlined in Knowledge Base article 870669 – How to disable the ADODB.Stream object from Internet Explorer.

If you’re using Service Pack 2 for Windows XP, you’ve been protected all along.

Misinformation on AutoRun

Phillip Torrone of Engadget gets two things wrong in a post this morning, and because Boing Boing picked up his post, the misinformation is going to get amplified mightily. How-To Tuesday: Disable AutoRun on Windows! He says:

Yes, this is a bit of a report from our post Monday, but we feel disabling Autorun is extremely important. By default Windows will automatically look for a file called Autorun.inf on any CD you pop in to your system, we’ve always known this is a big security issue as there are a lot of spyware and viruses distributed on CDs, you read about this every week. In fact, Microsoft is even disabling this in their next security focused service pack.

This is then followed by detailed instructions on how to edit the Registry to disable AutoRun.

Where to begin…?

First, name a single virus in the past five years that has been distributed via CD. I vaguely recall some Microsoft CDs issued to the press in 1997-98 that contained Word documents that had been infected with Melissa or some such. Nothing at all since that time, and I pay close attention to that stuff. So the idea that we should all be petrified over the prospect of a CD transmitting a virus is … let’s call it silly. And as for spyware — typically it gets installed when you visit a Web site or when you install a program. If you voluntarily install a program that you receive on CD, it could install spyware. Disabling AutoRun won’t stop that in any way.

Second, AutoRun on CD hasn’t been disabled in the latest security pack. You do get a security dialog box, but that’s it.

Ah, if you read further into the article you see what this is about. Not viruses or Trojan horses, but copy protection. Seems that a new RCA CD is using a copy-protection scheme called MediaMax, which relies on Windows AutoRun. As Phillip points out in his story, however, you can disable AutoRun on any CD, any time you want, by just holding down the Shift key as you insert it.

Finally, he says, “Please, tell everyone to disable autorun, use our email option, IM your pals, whatever it takes.”

Please don’t.

Bye-bye, fair use?

The Electronic Frontier Foundation explains why Sen. Orrin Hatch’s Induce Act is terrible, terrible law.

Under the Supreme Court’s ruling in Sony v. Universal (the Betamax VCR case), devices like the iPod and CD burners are legal as long as they have legal uses—what the Court called “substantial non-infringing uses.” This has been the rule in the technology sector for the last 20 years. Billions of dollars and thousands of jobs have depended on it. Industries have blossomed under it. And any case brought against Apple or HP or Dell would be immediately dismissed because of it.

Now Senator Hatch and his allies want to tear down that rule and substitute a new one with the Induce Act. With it, the fact that a device or product has legal uses, even lots of them, is irrelevant. Filing a lawsuit under the Induce Act is like dropping a litigation bomb on any company that gives users products that have even the slightest potential to assist in copyright infringement. Technology companies will avoid being innovative, and investors will avoid supporting new technologies for fear of being sued out of existence based on the possible conduct of their customers. If this bill had been law in 1984, there would be no VCR. If this bill had been law in 1995, there would be no CD burners. If this bill had been law in 2000, there would be no iPod. If this bill becomes law in 2004, we may lose those devices and many more that we haven’t even begun to imagine.

Orrin Hatch has probably introduced more bad legislation than any sitting Senator, but this one takes the cake. Read the EFF’s write-up. Then write your Senator and your Congressman.

This is alarming

A very popular blog I read regularly reports that it has come under sustained attack this week by comment spammers. Nothing unusual there — I delete a dozen or more comments every week, and many, many more get shunted away by a spam-blocking program that runs on my Web server.

What’s alarming about this report, though, is the detail that the attacks have been launched from computers in the .mil domain. For those who aren’t up on their Internet architecture, those are PCs that belong to the United States Army, Navy, Air Force, and Marines, not to mention the Army Corps of Engineers and special offices in the Pentagon. Comments (of the non-spam variety) in the thread that first reported this suggest that this problem is happening to other people as well.

So, if these reports are to be believed, we have two possibilities:

  1. A group of computers in the United States military have been compromised by viruses, Trojan horses, and/or hackers. What other types of damage could a compromised machine inside a .mil network do?
  2. An arm of the United States military is actively targeting specific Web sites with attacks. I don’t have nearly enough tinfoil to make the hat I’d need to wear to believe this one.

But if the first case is true, it sounds like someone in the Government needs to get serious about security. Soon.

Security hysteria

The mainstream media is going nuts over a new security warning. Probably the worst reaction came from Dan Gillmor of the San Jose Mercury-News, who is one of the most reasonable people in the world until he hears the word “Microsoft.” In Yet More Microsoft Insecurity Outrages, he quotes a BBC News story that claims: “Users are being told to avoid using Internet Explorer until Microsoft patches a serious security hole in it.”

Then he adds:

How many billions of dollars of damage is Microsoft’s inadequately secure software causing every year? Why is the company not liable for any of its nonfeasance?

Where are the trial lawyers on this one? I don’t get it.

Oh yeah. That’s what we need. More lawyers. Sheesh.

Read Microsoft’s official warning on this issue. If you use Windows XP, consider installing Windows XP Service Pack 2, which is available as a very stable Release Candidate beta. I can confirm from personal testing that it blocks this type of exploit effectively.

Update your antivirus software. Trend Micro’s PC-Cillin (my favorite) protects against this exploit. So does Norton AntiVirus. So, I presume, does just about every other maker of antivirus software. If your virus definitions are up to date, you’re protected. If they’re not, well, you’re vulnerable to this and many other attacks.

If you run a Web server using Windows 2000 and IIS, install the latest patches. This exploit depends on Web servers that are running without the proper attention to security.

If you don’t think Microsoft can handle security, you have lots of alternatives, starting with Mozilla and ending with Linux. But please, don’t start talking about lawsuits and lawyers. Class action suits make lawyers richer. They won’t make you safer. Not one bit.