Accessible Web Typography - an introduction for web designers:
"A book by Jim Byrne
The author is available for accessible web design development and consultancy work: jim@scotconnect.com
The HTML version of the book is free:"
http://www.scotconnect.com/webtypography/
Friday, February 13, 2004
The Windows Patch—What You Need to Know :
"On Tuesday February 10th, Microsoft released three new security updates to patch new vulnerabilities, one of which is catching a lot of attention. Security Update MS04-007 is rated as critical because it has the potential to leave a user of Windows NT, 2000, XP or 2003 Server open to an attack that could result in remote code execution. The vulnerability has no workarounds, and is being very strongly recommended by Microsoft and security organizations. However, at this time, Microsoft says there are no reported incidents using the vulnerability, but is recommending the patch as a preemptive strike against attack.…"
http://www.pcmag.com/article2/0,4149,1525075,00.asp
"On Tuesday February 10th, Microsoft released three new security updates to patch new vulnerabilities, one of which is catching a lot of attention. Security Update MS04-007 is rated as critical because it has the potential to leave a user of Windows NT, 2000, XP or 2003 Server open to an attack that could result in remote code execution. The vulnerability has no workarounds, and is being very strongly recommended by Microsoft and security organizations. However, at this time, Microsoft says there are no reported incidents using the vulnerability, but is recommending the patch as a preemptive strike against attack.…"
http://www.pcmag.com/article2/0,4149,1525075,00.asp
Microsoft TechNet:
"Microsoft Security Bulletin MS04-007
ASN.1 Vulnerability Could Allow Code Execution (828028)"
Impact of vulnerability: Remote Code Execution
Maximum Severity Rating: Critical
Security Update Replacement: None
Caveats: Windows NT 4.0 (Workstation, Server, and Terminal Server Edition) does not install the affected file by default. This file is installed as part of the MS03-041 Windows NT 4.0 security update and other possible non-security-related hotfixes. If the Windows NT 4.0 security update for MS03-041 is not installed, this may not be a required update. To verify if the affected file is installed, search for the file named Msasn1.dll. If this file is present, this security update is required. Windows Update, Software Update Services, and the Microsoft Security Baseline Analyzer will also correctly detect if this update is required.…
http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS04-007.asp
"Microsoft Security Bulletin MS04-007
ASN.1 Vulnerability Could Allow Code Execution (828028)"
Impact of vulnerability: Remote Code Execution
Maximum Severity Rating: Critical
Security Update Replacement: None
Caveats: Windows NT 4.0 (Workstation, Server, and Terminal Server Edition) does not install the affected file by default. This file is installed as part of the MS03-041 Windows NT 4.0 security update and other possible non-security-related hotfixes. If the Windows NT 4.0 security update for MS03-041 is not installed, this may not be a required update. To verify if the affected file is installed, search for the file named Msasn1.dll. If this file is present, this security update is required. Windows Update, Software Update Services, and the Microsoft Security Baseline Analyzer will also correctly detect if this update is required.…
http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS04-007.asp
MyDoom author may be covering tracks - News - ZDNet:
"A worm that started spreading on Sunday places the source code for the original MyDoom virus on victims' hard drives, an action equivalent to planting evidence, antivirus experts said Tuesday.
The worm, Doomjuice, spreads to computers that have already been infected by either the original MyDoom virus or the MyDoom.B variant, and among other actions, places several copies of the source code for MyDoom.A on a victim's computer.
The author may be using the tactic to create a crowd of PC users in which to hide, or the author could be spreading the code in hopes that other virus writers will create variations on MyDoom, said Graham Cluley, senior technology consultant for antivirus company Sophos. "
Doomjuice is one of two opportunistic programs--the other dubbed Deadhat--that started spreading this week. Both viruses infect computers that have already succumbed to either of the two MyDoom viruses. Doomjuice also attempts to direct any re-infected PCs to attack Microsoft's Web site.
Doomjuice's possession of the source code for the original MyDoom virus suggests that the creator of the worm is also the writer of the original virus. A word in both MyDoom viruses--the name "andy"--has already suggested to some researchers that the original MyDoom and the MyDoom.B variant were created by the same person or group.
Other antivirus researchers agree that the latest hostile program could be intended to confuse investigations into who created the viruses.…
http://zdnet.com.com/2100-1104_2-5156836.html
"A worm that started spreading on Sunday places the source code for the original MyDoom virus on victims' hard drives, an action equivalent to planting evidence, antivirus experts said Tuesday.
The worm, Doomjuice, spreads to computers that have already been infected by either the original MyDoom virus or the MyDoom.B variant, and among other actions, places several copies of the source code for MyDoom.A on a victim's computer.
The author may be using the tactic to create a crowd of PC users in which to hide, or the author could be spreading the code in hopes that other virus writers will create variations on MyDoom, said Graham Cluley, senior technology consultant for antivirus company Sophos. "
Doomjuice is one of two opportunistic programs--the other dubbed Deadhat--that started spreading this week. Both viruses infect computers that have already succumbed to either of the two MyDoom viruses. Doomjuice also attempts to direct any re-infected PCs to attack Microsoft's Web site.
Doomjuice's possession of the source code for the original MyDoom virus suggests that the creator of the worm is also the writer of the original virus. A word in both MyDoom viruses--the name "andy"--has already suggested to some researchers that the original MyDoom and the MyDoom.B variant were created by the same person or group.
Other antivirus researchers agree that the latest hostile program could be intended to confuse investigations into who created the viruses.…
http://zdnet.com.com/2100-1104_2-5156836.html
Study: Spammers turning blind eye to the law - News - ZDNet:
"Only 3 percent of bulk commercial e-mail includes a valid U.S. postal mail address and a valid link to opt out of future messages, according to data released on Tuesday by MX Logic, a maker of mail-filtering software. Those requirements are part of the Can-Spam Act, short for Controlling the Assault of Non-Solicited Pornography and Marketing, the nation's first federal spam law.
What's more, the amount of spam has continued to grow since the law went into effect at the beginning of the year. As much as 60 percent of the e-mail sent in January was spam, up from 58 percent in December, according to San Francisco-based Brightmail, one of the largest spam-filtering companies.…"
http://zdnet.com.com/2100-1104_2-5156629.html?tag=adnews
"Only 3 percent of bulk commercial e-mail includes a valid U.S. postal mail address and a valid link to opt out of future messages, according to data released on Tuesday by MX Logic, a maker of mail-filtering software. Those requirements are part of the Can-Spam Act, short for Controlling the Assault of Non-Solicited Pornography and Marketing, the nation's first federal spam law.
What's more, the amount of spam has continued to grow since the law went into effect at the beginning of the year. As much as 60 percent of the e-mail sent in January was spam, up from 58 percent in December, according to San Francisco-based Brightmail, one of the largest spam-filtering companies.…"
http://zdnet.com.com/2100-1104_2-5156629.html?tag=adnews
Microsoft Warns Software Users of 'Critical' Flaw:
"The company called the software flaw a "critical" vulnerability, its highest rating. It is the second major security flaw announced this month by Microsoft, which recently began issuing regularly scheduled security patches for its software. "We urge all of our customers to apply this update," said Stephen Toulouse, a security program manager with Microsoft's security response center.
The flaw, one of three announced yesterday by Microsoft, affects a fundamental building block of network operating systems known as Abstract Syntax Notation One, and helps govern how machines communicate with one another and how they establish secure communications. Microsoft's version of that protocol is flawed, and could be used to gain control of the target machine. The company said there was no evidence that any attacks based on the flaw had occurred.… "
For now, Mr. Cooper said, computer users are probably safe because the flaw "is not exactly a simple one" to take advantage of, and no attack that would exploit the flaw had appeared on the hacker sites where such code is freely circulated. But once such an attack method is created, he said he expected to see a malicious program that could circulate via e-mail messaging and which would have as profound an effect on computer networks as the widespread "Blaster" worm of last year.…
http://www.nytimes.com/2004/02/11/technology/11worm.html
"The company called the software flaw a "critical" vulnerability, its highest rating. It is the second major security flaw announced this month by Microsoft, which recently began issuing regularly scheduled security patches for its software. "We urge all of our customers to apply this update," said Stephen Toulouse, a security program manager with Microsoft's security response center.
The flaw, one of three announced yesterday by Microsoft, affects a fundamental building block of network operating systems known as Abstract Syntax Notation One, and helps govern how machines communicate with one another and how they establish secure communications. Microsoft's version of that protocol is flawed, and could be used to gain control of the target machine. The company said there was no evidence that any attacks based on the flaw had occurred.… "
For now, Mr. Cooper said, computer users are probably safe because the flaw "is not exactly a simple one" to take advantage of, and no attack that would exploit the flaw had appeared on the hacker sites where such code is freely circulated. But once such an attack method is created, he said he expected to see a malicious program that could circulate via e-mail messaging and which would have as profound an effect on computer networks as the widespread "Blaster" worm of last year.…
http://www.nytimes.com/2004/02/11/technology/11worm.html
Wednesday, February 11, 2004
MyDoom.C Slams Into Microsoft.com:
"UPDATED: A stripped-down version of the MyDoom worm, a k a Doomjuice, on Monday spread through network backdoor and attacked Microsoft's Web site.
A new version of the MyDoom worm appears to be circulating on the Internet and may be responsible for some disruptions to Microsoft Corp.'s Web site Sunday night and Monday morning, researchers said.
When it's executed, the new variant, called MyDoom.C, or Doomjuice, begins scanning for machines listening on TCP port 3127. When it finds available PCs, it copies itself to the new machine's Windows directory under the file name 'intrenat.exe' and also creates a file named 'sync-src-1.00.tbz' in several locations. "
But unlike the two previous versions of MyDoom, this third variant does not spread via e-mail, nor does it install a backdoor on infected machines or have a kill date, according to an analysis done by Ken Dunham, malicious code manager for iDefense Inc., based in Reston, Va. The worm's code is not encrypted, but it contains all of the source code for MyDoom.A.
The new worm's infection procedure may limit its spread, experts said. MyDoom.C spreads by scanning for machines that are already infected with one of the other variants of the worm. So the possibility of spreading widely in the enterprise is mitigated by the fact that most companies affected by one of the other worms likely already has cleaned up those PCs. Also, administrators can trump the new variant by blocking Port 3127 at the firewall.
"The risk presented by Mydoom.C needs to be tempered with the fact it is easily foiled by protection available from as early as two weeks ago. The fact the worm preys on existing Mydoom infected computers is much like a flock of vultures circling around an unfortunate soul about to succumb to the elements in that it is picking through scraps," said Ian Hameroff, eTrust security strategist at Computer Associates International Inc. of Islandia, N.Y.…
MyDoom.C does have the ability to launch a denial-of-service attack against Microsoft's main Web site, which experienced some severe performance problems overnight Sunday and again Monday morning, according to data compiled by Netcraft Ltd. If the worm is started between Feb. 8 and Feb. 12, it starts a thread that sleeps for a random amount of time and then spawns 80 threads that begin requesting pages from Microsoft.com at once. MyDoom.C does not try to attack The SCO Group's Web site, however, as the two previous versions did.…
http://www.eweek.com/article2/0,4149,1522236,00.asp
"UPDATED: A stripped-down version of the MyDoom worm, a k a Doomjuice, on Monday spread through network backdoor and attacked Microsoft's Web site.
A new version of the MyDoom worm appears to be circulating on the Internet and may be responsible for some disruptions to Microsoft Corp.'s Web site Sunday night and Monday morning, researchers said.
When it's executed, the new variant, called MyDoom.C, or Doomjuice, begins scanning for machines listening on TCP port 3127. When it finds available PCs, it copies itself to the new machine's Windows directory under the file name 'intrenat.exe' and also creates a file named 'sync-src-1.00.tbz' in several locations. "
But unlike the two previous versions of MyDoom, this third variant does not spread via e-mail, nor does it install a backdoor on infected machines or have a kill date, according to an analysis done by Ken Dunham, malicious code manager for iDefense Inc., based in Reston, Va. The worm's code is not encrypted, but it contains all of the source code for MyDoom.A.
The new worm's infection procedure may limit its spread, experts said. MyDoom.C spreads by scanning for machines that are already infected with one of the other variants of the worm. So the possibility of spreading widely in the enterprise is mitigated by the fact that most companies affected by one of the other worms likely already has cleaned up those PCs. Also, administrators can trump the new variant by blocking Port 3127 at the firewall.
"The risk presented by Mydoom.C needs to be tempered with the fact it is easily foiled by protection available from as early as two weeks ago. The fact the worm preys on existing Mydoom infected computers is much like a flock of vultures circling around an unfortunate soul about to succumb to the elements in that it is picking through scraps," said Ian Hameroff, eTrust security strategist at Computer Associates International Inc. of Islandia, N.Y.…
MyDoom.C does have the ability to launch a denial-of-service attack against Microsoft's main Web site, which experienced some severe performance problems overnight Sunday and again Monday morning, according to data compiled by Netcraft Ltd. If the worm is started between Feb. 8 and Feb. 12, it starts a thread that sleeps for a random amount of time and then spawns 80 threads that begin requesting pages from Microsoft.com at once. MyDoom.C does not try to attack The SCO Group's Web site, however, as the two previous versions did.…
http://www.eweek.com/article2/0,4149,1522236,00.asp
Tuesday, February 10, 2004
Chicago Tribune | 'Mydoom' Creators Start Up 'Doomjuice':
"Finnish computer security experts warned Tuesday of a new worm, known as 'Doomjuice,' that is expected to attack computers infected by 'Mydoom,' despite the fact it's programmed to stop spreading later this week.
The virus, first detected by F-Secure on Monday night, has so far infected at least 30,000 computers worldwide since it was activated Sunday, said the company's director of antivirus research, Mikko Hypponen. "
Like Mydoom.A and Mydoom.B, the new worm is designed to strike Microsoft Corp.'s Windows operating systems and is programmed to launch a worldwide attack on the web site of SCO, one of the largest UNIX vendors in the world.
"Unlike Mydoom, it does not spread via e-mail. It comes through a backdoor left open by Mydoom," Hypponen told The Associated Press. "People won't even realize their computers are being attacked, and then they'll have both Mydoom and Doomjuice in their computers."
Doomjuice drops the original source code of the Mydoom.A worm in an archive to folders on infected computers.
"This proves to us that Doomjuice and Mydoom.A are written by the same people," Hypponen said. "The source code of Mydoom.A has not been seen circulating in the underground before."
Doomjuice's ability to spread is limited because it will only attack computers infected by Mydoom, Hypponen said. "And lots of them are being cleaned up already at a quick rate."
But, he warned, unlike Mydoom which is programmed to stop spreading on Feb. 12, Doomjuice could run forever. "At least until all computers everywhere infected by both worms have been cleaned up, and that could be years," Hypponen said.
F-Secure said it is difficult to fully assess how destructive Doomjuice has been so far, but that one sensor monitoring a fifth of the world's Internet traffic Monday found 30,000 hits.
So far, www.microsoft.com, one of the largest web sites in the world, appears to be operational, but F-Secure had noticed a disruption in service on Monday.
F-Secure: http://F-Secure.com/
http://www.chicagotribune.com/technology/sns-ap-finland-doomjuice-worm.story
"Finnish computer security experts warned Tuesday of a new worm, known as 'Doomjuice,' that is expected to attack computers infected by 'Mydoom,' despite the fact it's programmed to stop spreading later this week.
The virus, first detected by F-Secure on Monday night, has so far infected at least 30,000 computers worldwide since it was activated Sunday, said the company's director of antivirus research, Mikko Hypponen. "
Like Mydoom.A and Mydoom.B, the new worm is designed to strike Microsoft Corp.'s Windows operating systems and is programmed to launch a worldwide attack on the web site of SCO, one of the largest UNIX vendors in the world.
"Unlike Mydoom, it does not spread via e-mail. It comes through a backdoor left open by Mydoom," Hypponen told The Associated Press. "People won't even realize their computers are being attacked, and then they'll have both Mydoom and Doomjuice in their computers."
Doomjuice drops the original source code of the Mydoom.A worm in an archive to folders on infected computers.
"This proves to us that Doomjuice and Mydoom.A are written by the same people," Hypponen said. "The source code of Mydoom.A has not been seen circulating in the underground before."
Doomjuice's ability to spread is limited because it will only attack computers infected by Mydoom, Hypponen said. "And lots of them are being cleaned up already at a quick rate."
But, he warned, unlike Mydoom which is programmed to stop spreading on Feb. 12, Doomjuice could run forever. "At least until all computers everywhere infected by both worms have been cleaned up, and that could be years," Hypponen said.
F-Secure said it is difficult to fully assess how destructive Doomjuice has been so far, but that one sensor monitoring a fifth of the world's Internet traffic Monday found 30,000 hits.
So far, www.microsoft.com, one of the largest web sites in the world, appears to be operational, but F-Secure had noticed a disruption in service on Monday.
F-Secure: http://F-Secure.com/
http://www.chicagotribune.com/technology/sns-ap-finland-doomjuice-worm.story
Monday, February 09, 2004
MyDoom sparks talks of security's future - News - ZDNet:
"Despite a deep understanding of how such viruses spread, security experts seem to be at a loss at how to stop them. Popular antivirus technology is generally ineffectual against many of the attacks until an update is downloaded by the user. Moreover, even though antivirus software is the most popular security technology in use--about 99 percent of corporations use it, according to the Computer Security Institute--many home users still don't use the software.
'Many people don't even have the software,' said Bruce Schneier, chief technology officer for Counterpane Internet Security. 'And for those that do, the first few hours of an epidemic is a race against time.' "
MyDoom spread through e-mail a week ago, infecting a new computer every time an unwary user opened the attached filed containing the program. As many as 2 million computers may have been infected. The original virus was programmed to attack The SCO Group's Web site last Sunday, while a variant is scheduled to target Microsoft on Tuesday.
E-mail service provider MessageLabs has quarantined more than 17 million e-mail messages in a week, said Alex Shipp, senior antivirus technologist for the company. From data captured early in the epidemic, MessageLabs says that for every Internet address with an infected PC behind it, eight e-mails are sent, on average, to one of the company's customers.
However, even though companies are still seeing massive quantities of e-mail messages bearing the MyDoom virus, the spread has slowed, stressed Shipp.…
http://zdnet.com.com/2100-1105_2-5152165.html?tag=zdaresources
"Despite a deep understanding of how such viruses spread, security experts seem to be at a loss at how to stop them. Popular antivirus technology is generally ineffectual against many of the attacks until an update is downloaded by the user. Moreover, even though antivirus software is the most popular security technology in use--about 99 percent of corporations use it, according to the Computer Security Institute--many home users still don't use the software.
'Many people don't even have the software,' said Bruce Schneier, chief technology officer for Counterpane Internet Security. 'And for those that do, the first few hours of an epidemic is a race against time.' "
MyDoom spread through e-mail a week ago, infecting a new computer every time an unwary user opened the attached filed containing the program. As many as 2 million computers may have been infected. The original virus was programmed to attack The SCO Group's Web site last Sunday, while a variant is scheduled to target Microsoft on Tuesday.
E-mail service provider MessageLabs has quarantined more than 17 million e-mail messages in a week, said Alex Shipp, senior antivirus technologist for the company. From data captured early in the epidemic, MessageLabs says that for every Internet address with an infected PC behind it, eight e-mails are sent, on average, to one of the company's customers.
However, even though companies are still seeing massive quantities of e-mail messages bearing the MyDoom virus, the spread has slowed, stressed Shipp.…
http://zdnet.com.com/2100-1105_2-5152165.html?tag=zdaresources
Friday, February 06, 2004
IE security patch nixes some apps - News - ZDNet:
"Some Web developers are complaining that an Internet Explorer patch that's meant to foil Net scams is disabling some applications that didn't put a premium on security.
Microsoft last week announced that a modification to its IE browser would stop the insecure practice of including sensitive information in links. The update, which was released Monday, had some Web site programmers up in arms Wednesday due to complaints from Web users that they could no longer log in to sites that secure entry through credentials included in the URL.
'Microsoft may have legitimate reasons for addressing the issue, but the way they addressed it--an across-the-board kill of an industry standard--is troublesome,' said James Rosko, a software engineer for a data-processing service on the Web. He and other programmers spent Tuesday night making changes to the programs that process login requests for his company's Web site, which he requested not be named."
The incident could be the first known case of Microsoft getting attention for putting security before a feature used by some of its customers. Microsoft promised to put security first when it launched its Trustworthy Computing Initiative more than two years ago. But some critics have claimed that they haven't seen many results.…
The problem occurs when programmers design a Web site to enable a Web user to log in by typing credentials into the URL. In such cases, the Web address might look like this: http://username:password@www.somecompany.com/program.ext. The link gives the person access to a company's Web site when the authentication program verifies the username and password.
Because the username and password are part of the Web address and are not encrypted, embedding the credential in the URL is considered a security risk, said William Kennedy, chief technology officer at ActivMedia Robotics and the co-author of "HTML & XHTML: The Definitive Guide."
"It was a dumb idea to include such functionality in the first place," Kennedy said. "There are millions of other ways of logging in to a site."
However, that sentiment was not what made Microsoft disable the feature. The software giant made the change to stop scam artists from constructing URLs that appeared to link to a legitimate Web site but actually directed people to a fraudulent site. For instance, a URL that appears to go to eBay could actually send the person to a fraudulent site such as: http://www.ebay.com@fraudsite.com.
The fake site will typically ask for a person's username and password and then use that information to complete a scam. Major banks and other financial Web sites, such as PayPal, are popular targets of such fraud, often called "phishing." The Federal Deposit Insurance Corp., the government organization that underwrites U.S. citizens' banks accounts, recently warned of a similar scam.…
http://zdnet.com.com/2100-1105_2-5153534.html
"Some Web developers are complaining that an Internet Explorer patch that's meant to foil Net scams is disabling some applications that didn't put a premium on security.
Microsoft last week announced that a modification to its IE browser would stop the insecure practice of including sensitive information in links. The update, which was released Monday, had some Web site programmers up in arms Wednesday due to complaints from Web users that they could no longer log in to sites that secure entry through credentials included in the URL.
'Microsoft may have legitimate reasons for addressing the issue, but the way they addressed it--an across-the-board kill of an industry standard--is troublesome,' said James Rosko, a software engineer for a data-processing service on the Web. He and other programmers spent Tuesday night making changes to the programs that process login requests for his company's Web site, which he requested not be named."
The incident could be the first known case of Microsoft getting attention for putting security before a feature used by some of its customers. Microsoft promised to put security first when it launched its Trustworthy Computing Initiative more than two years ago. But some critics have claimed that they haven't seen many results.…
The problem occurs when programmers design a Web site to enable a Web user to log in by typing credentials into the URL. In such cases, the Web address might look like this: http://username:password@www.somecompany.com/program.ext. The link gives the person access to a company's Web site when the authentication program verifies the username and password.
Because the username and password are part of the Web address and are not encrypted, embedding the credential in the URL is considered a security risk, said William Kennedy, chief technology officer at ActivMedia Robotics and the co-author of "HTML & XHTML: The Definitive Guide."
"It was a dumb idea to include such functionality in the first place," Kennedy said. "There are millions of other ways of logging in to a site."
However, that sentiment was not what made Microsoft disable the feature. The software giant made the change to stop scam artists from constructing URLs that appeared to link to a legitimate Web site but actually directed people to a fraudulent site. For instance, a URL that appears to go to eBay could actually send the person to a fraudulent site such as: http://www.ebay.com@fraudsite.com.
The fake site will typically ask for a person's username and password and then use that information to complete a scam. Major banks and other financial Web sites, such as PayPal, are popular targets of such fraud, often called "phishing." The Federal Deposit Insurance Corp., the government organization that underwrites U.S. citizens' banks accounts, recently warned of a similar scam.…
http://zdnet.com.com/2100-1105_2-5153534.html
Geeks Put the Unsavvy on Alert: Learn or Log Off:
"The tension over the MyDoom virus underscores a growing friction between technophiles and what they see as a breed of technophobes who want to enjoy the benefits of digital technology without making the effort to use it responsibly.
The virus spreads when Internet users ignore a basic rule of Internet life: never click on an unknown e-mail attachment. Once someone does, MyDoom begins to send itself to the names in that person's e-mail address book. If no one opened the attachment, the virus's destructive power would never be unleashed."
"It takes affirmative action on the part of the clueless user to become infected," wrote Scott Bowling, president of the World Wide Web Artists Consortium, expressing frustration on the group's discussion forum. "How to beat this into these people's heads?"
Many of the million or so people who have so far infected their computers with MyDoom say it is not their fault. The virus often comes in a message that appears to be from someone they know, with an innocuous subject line like "test" or "error." It is human nature, they say, to open the mail and attachments.
But computer sophisticates say it reflects a willful ignorance of basic computer skills that goes well beyond virus etiquette. At a time when more than two-thirds of American adults use the Internet, they say, such carelessness is no longer excusable, particularly when it messes things up for everyone else.…
http://www.nytimes.com/2004/02/05/technology/05VIRU.html?pagewanted=all&position=
"The tension over the MyDoom virus underscores a growing friction between technophiles and what they see as a breed of technophobes who want to enjoy the benefits of digital technology without making the effort to use it responsibly.
The virus spreads when Internet users ignore a basic rule of Internet life: never click on an unknown e-mail attachment. Once someone does, MyDoom begins to send itself to the names in that person's e-mail address book. If no one opened the attachment, the virus's destructive power would never be unleashed."
"It takes affirmative action on the part of the clueless user to become infected," wrote Scott Bowling, president of the World Wide Web Artists Consortium, expressing frustration on the group's discussion forum. "How to beat this into these people's heads?"
Many of the million or so people who have so far infected their computers with MyDoom say it is not their fault. The virus often comes in a message that appears to be from someone they know, with an innocuous subject line like "test" or "error." It is human nature, they say, to open the mail and attachments.
But computer sophisticates say it reflects a willful ignorance of basic computer skills that goes well beyond virus etiquette. At a time when more than two-thirds of American adults use the Internet, they say, such carelessness is no longer excusable, particularly when it messes things up for everyone else.…
http://www.nytimes.com/2004/02/05/technology/05VIRU.html?pagewanted=all&position=
Thursday, February 05, 2004
Do Web search engines suppress controversy?:
"Do Web search engines suppress controversy? by Susan L. Gerhart
Web behavior depends upon three interlocking communities: (1) authors whose Web pages link to other pages; (2) search engines indexing and ranking those pages; and (3) information seekers whose queries and surfing reward authors and support search engines. Systematic suppression of controversial topics would indicate a flaw in the Web’s ideology of openness and informativeness. This paper explores search engines’ bias by asking: Is a specific well–known controversy revealed in a simple search? Experimental topics include: distance learning, Albert Einstein, St. John’s Wort, female astronauts, and Belize. The experiments suggest simple queries tend to overly present the "sunny side" of these topics, with minimal controversy. A more "Objective Web" is analyzed where: (a) Web page authors adopt research citation practices; (b) search engines balance organizational and analytic content; and, (c) searchers practice more wary multi–searching.…"
http://www.firstmonday.dk/issues/issue9_1/gerhart/
"Do Web search engines suppress controversy? by Susan L. Gerhart
Web behavior depends upon three interlocking communities: (1) authors whose Web pages link to other pages; (2) search engines indexing and ranking those pages; and (3) information seekers whose queries and surfing reward authors and support search engines. Systematic suppression of controversial topics would indicate a flaw in the Web’s ideology of openness and informativeness. This paper explores search engines’ bias by asking: Is a specific well–known controversy revealed in a simple search? Experimental topics include: distance learning, Albert Einstein, St. John’s Wort, female astronauts, and Belize. The experiments suggest simple queries tend to overly present the "sunny side" of these topics, with minimal controversy. A more "Objective Web" is analyzed where: (a) Web page authors adopt research citation practices; (b) search engines balance organizational and analytic content; and, (c) searchers practice more wary multi–searching.…"
http://www.firstmonday.dk/issues/issue9_1/gerhart/
Wednesday, February 04, 2004
Microsoft shrugs off MyDoom attack - News - ZDNet:
"Microsoft has created an alternate Web site for people whose PCs are infected with MyDoom.B and who want to get security information but cannot contact the main site because of a mechanism in the virus that blocks some 65 Web sites, including Microsoft's home page. The alternate site, which starts with 'information' rather than 'www,' lets people see the regular home page content."
http://information.microsoft.com/
http://zdnet.com.com/2100-1105_2-5152702.html
"Microsoft has created an alternate Web site for people whose PCs are infected with MyDoom.B and who want to get security information but cannot contact the main site because of a mechanism in the virus that blocks some 65 Web sites, including Microsoft's home page. The alternate site, which starts with 'information' rather than 'www,' lets people see the regular home page content."
http://information.microsoft.com/
http://zdnet.com.com/2100-1105_2-5152702.html
Halting MyDoom Is a Free Download Away:
"MyDoom.A has 'DoS-ed' SCO.com out of commission, forcing the company to establish thescogroup.com in order to maintain its presence on the Internet. Microsoft, thus far, has fared better as MyDoom.B has yet to cripple the software giant's considerable defenses.
But where are individual PC users supposed to turn for relief?… "
http://www.enterpriseitplanet.com/security/news/article.php/3307751
"MyDoom.A has 'DoS-ed' SCO.com out of commission, forcing the company to establish thescogroup.com in order to maintain its presence on the Internet. Microsoft, thus far, has fared better as MyDoom.B has yet to cripple the software giant's considerable defenses.
But where are individual PC users supposed to turn for relief?… "
http://www.enterpriseitplanet.com/security/news/article.php/3307751
Google Ultimate Interface - Fagan Finder
If you want all of Google's tools and options conveniently displayed on a single screen, try FaganFinder.…It even has handy links for typing non-English letters.
http://www.faganfinder.com/google.html
If you want all of Google's tools and options conveniently displayed on a single screen, try FaganFinder.…It even has handy links for typing non-English letters.
http://www.faganfinder.com/google.html
Hidden Google Tools:
"Even if you consider yourself a Google expert, these 'hidden' tools and resources let you push the search engine's capabilities to the max.… "
http://searchenginewatch.com/searchday/article.php/3304771
"Even if you consider yourself a Google expert, these 'hidden' tools and resources let you push the search engine's capabilities to the max.… "
http://searchenginewatch.com/searchday/article.php/3304771
Microsoft Patches Serious IE Flaw:
"Microsoft Corp. on Monday finally released a patch for a dangerous vulnerability that lets attackers trick Internet users into visiting malicious sites. The flaw has been public knowledge for some time, but Microsoft failed to include a fix for it with January's scheduled patch releases.…"
http://www.eweek.com/article2/0,4149,1485698,00.asp
"Microsoft Corp. on Monday finally released a patch for a dangerous vulnerability that lets attackers trick Internet users into visiting malicious sites. The flaw has been public knowledge for some time, but Microsoft failed to include a fix for it with January's scheduled patch releases.…"
http://www.eweek.com/article2/0,4149,1485698,00.asp
IT Losing Ground in Virus Battle:
"After years of success deploying more effective and smarter defenses, anti-virus researchers contacted last week in the wake of the MyDoom outbreak acknowledged for one of the first times that the battle may be getting away from them.
The MyDoom virus, which hit Jan. 26 and infected several-hundred-thousand machines, is the fastest-spreading virus in the history of the Internet, experts said. At its peak late last week, MyDoom had infected one in every 12 pieces of e-mail, according to MessageLabs Inc., a New York-based e-mail security company. MyDoom also is the latest in a line of recent viruses that, while not particularly innovative, have been maddeningly effective.…"
http://www.eweek.com/print_article/0,3048,a=117996,00.asp
"After years of success deploying more effective and smarter defenses, anti-virus researchers contacted last week in the wake of the MyDoom outbreak acknowledged for one of the first times that the battle may be getting away from them.
The MyDoom virus, which hit Jan. 26 and infected several-hundred-thousand machines, is the fastest-spreading virus in the history of the Internet, experts said. At its peak late last week, MyDoom had infected one in every 12 pieces of e-mail, according to MessageLabs Inc., a New York-based e-mail security company. MyDoom also is the latest in a line of recent viruses that, while not particularly innovative, have been maddeningly effective.…"
http://www.eweek.com/print_article/0,3048,a=117996,00.asp
Subscribe to:
Posts (Atom)
