Thursday, June 09, 2005

Spoofing flaw resurfaces in Mozilla browsers

By Joris Evers, CNET News.com

“A 7-year-old flaw that could let an attacker place malicious content on trusted Web sites has resurfaced in the most recent Firefox browser, Secunia has warned.

The flaw, which also affects some other Mozilla Foundation programs, lies in the way the software handles frames, which are a way of showing Web content in separate parts of the browser window. The applications don't check whether the frames displayed in a single window all originate from the same Web site, Secunia said in an advisory on Monday. Firefox 1.x, Mozilla 1.7.x and Camino 0.x versions are vulnerable to the flaw, the security monitoring company said.

As a result, an attacker could insert content into a frame on a trusted Web site, Secunia said. Account holders who believe they are interacting with a frame belonging to an online bank could be tricked into giving up personal information or downloading malicious code, for example. Secunia rated the issue "moderately critical."

The same "frame injection" vulnerability in Mozilla's browsers was detailed by Secunia in July of last year. At the time, it did not affect the most recent versions of the applications.

For a spoofing attempt to work, a surfer would need to have both the attacker's Web site and a trusted Web site open in different windows. A click on a link on the malicious site would then display the attacker's content in a frame on the trusted Web site, Secunia said. The company advised people not to visit trusted and untrusted Web sites at the same time.…”

The more things change… The more they brag about how secure they are.

CRN Breaking News Firefox Vulnerable To 7-Year-Old Bug

According to Danish security firm Secunia, Mozilla 1.7.x and Firefox 1.x are vulnerable to a frame injection flaw that first surfaced in 1998. Hackers could exploit the bug to insert their own content into the view of a legitimate site, to, for instance, pose as the log-in frame, then collect usernames and passwords to online bank accounts.

"The flaw means that if you are viewing a trusted site in one window (PayPal or your bank) and open a site belonging to a spoofer in another window, the spoofer can insert code in the window showing the trusted site," wrote a moderator on Mozilla's online forum Monday.

http://www.crn.com/nl/crnupdate/showArticle.jhtml?articleId=164300698

http://news.zdnet.com/2100-1009_22-5734121.html?tag=nl.e589

Saturday, June 04, 2005

Linux Distro Called 'Puppy'?

By Alexander Wolfe, TechWeb News

“A retired university lecturer in Australia has come up with the latest twist on Linux , fielding a distribution of the operating system that takes little memory and can boot directly off of a USB thumb drive.

Dubbed Puppy Linux, the OS is one of dozens of custom and guerilla variants on Linux circulating throughout the broader software community. (Many are tracked on the Distrowatch open-source Web site.) But Puppy appears to be catching on, attracting recent attention on Slashdot in the wake of the release in May of Puppy Linux version 1.0.2.

‘I think one of the key advantages of Puppy is the simplicity,’ said Barry Kauler, the developer of Puppy Linux, in an e-mail interview. ‘When other distributions start up, you see all these servers loading, but in Puppy it's really basic and bootup is remarkably fast. However, I still managed to stick to the requirement of it all loading into RAM and freeing up the CD drive, on a reference 128MB PC.’

That small-is-beautiful theme is Puppy's raison d'etre, according to Kauler. ‘If I were pressed to list why I think people use Puppy, it would be [that it's] very simple under-the-hood, very easy to use, very fast, highly portable, and easy to install.’ ”

http://www.crn.com/nl/crnupdate/showArticle.jhtml?articleId=163702896

Office Goes XML

From: Between the Lines

“The important revelation, which was expected, is that some Office 12 applications (Word, Excel and Powerpoint) will use Office Open XML as the default file format. Note: Excel and Word already have XML support and related schemas for saving documents with full fidelity as XML files. The formats are industry standard XML 1.0 and the schemas are available on a royalty-free basis. As a result, developers can query what's in a file and extract specific data or write their own compatible applications to view and manipulate the files. User can open the .XML files in any application that can read XML. "Our value is not tied to file format, but to the user experience and quality of the software." Capossela said. Now that's a refreshing point of view, given how in the past Microsoft has often made it difficult for others to parse the file formats.

What's new for Microsoft is compacting the often overweight XML text files using industry standard Zip compression technology to compress and decompress the data within a document–including comments, charts and document metadata–that is segmented and stored in different components. However, OLE objects and images are still stored as binaries.

Using Zip gets around the thorny issue of creating a binary XML to deal with file bloat.…

A preview of Office 12 (not an initial beta, which isn't due until the fall) will be available at www.microsoft.com/office/preview on Monday, June 6. I asked about XML file formats for Macintosh Office, but Capossela wasn' sure–Mac Office is done by a different business group at Microsoft. Nor is a Linux version of Office on the drawing board. We'll also have to wait to hear about other features that will make it into Office 12. The dribbling continues…”


http://blogs.zdnet.com/BTL/index.php?p=1459&tag=nl.e539

Friday, May 27, 2005

ZdNet Whiteboard Video: Beware of ungracious hosts

“Hackers can attack your host's file, rewriting the file to send you to a fraudulent site. Virus writers also use the host's file to block access to anti-virus companies. CNET’s Rob Vamosi says ‘beware.’ ”
Most home users don't even know there is a host file.

AOL and other net access programs tend to drop them in without so much as a mention. Virus scanners may not (usually do not look for changes other than a virus signature.

This short video tells you what you need to know, but assumes you'll know what to do.

http://news.zdnet.com/1607-2-5718931-2.asx?PSDir=ad_msnlivemeeting&videoName=5w0518ungracioushosts&NumClips=1

http://news.zdnet.com/2036-2_22-5718931.html

Thursday, May 26, 2005

Stealth virus warning

By Munir Kotadia, ZDNet Australia

Organized criminals are advertising networks of zombie computers for rent on underground newsgroups and Web pages. When they receive an order for a botnet of a certain size, they set about trying to infect computers using infected email attachments or socially-engineered spam with links to malicious Web pages. As soon as they infect enough computers to fulfill the order, they stop using that particular piece of malware.

“Virus authors are choosing not to create global epidemics--such as Melissa or Blaster--because that distracts them from their core business of creating and selling botnets, according to antivirus experts.

Botnets are groups of computers that have been infected by malware that allows the author to control the infected PCs, and then typically use them to send spam or launch DDoS attacks.

Speaking at the AusCERT conference on Australia's Gold Coast on Tuesday, Eugene Kaspersky, founder of Kaspersky Labs, said that the influence of organised crime on the malware industry has led to a change of tactics, echoing comments made in March of this year by Mikko Hyppönen of F-Secure. Instead of trying to create viruses and worms that infect as many computers as possible, malware authors are instead trying to infect 5,000 or 10,000 computers at a time to create personalized zombie armies.

"Do I need a million computers to send spam? No. To do a DDoS attack, 5,000 or 10,000 PCs is more than enough. That is why virus writers and hackers have changed their tactics of infection--they don't need a global epidemic," said Kaspersky.

http://news.zdnet.com/2100-1009_22-5719765.html?tag=nl.e589

Tuesday, May 24, 2005

Microsoft security guru: Jot down your passwords

By Munir Kotadia, ZDNet Australia

“Companies should not ban employees from writing down their passwords because such bans force people to use the same weak term on many systems, according to a Microsoft security guru.

Speaking on the opening day of a conference hosted by Australia's national Computer Emergency Response Team, or AusCERT, Microsoft's Jesper Johansson said that the security industry has been giving out the wrong advice to users by telling them not to write down their passwords. Johansson is senior program manager for security policy at Microsoft.

"How many have (a) password policy that says under penalty of death you shall not write down your password?" asked Johansson, to which the majority of attendees raised their hands in agreement. "I claim that is absolutely wrong. I claim that password policy should say you should write down your password. I have 68 different passwords. If I am not allowed to write any of them down, guess what I am going to do? I am going to use the same password on every one of them."

According to Johansson, use of the same password reduces overall security.

"Since not all systems allow good passwords, I am going to pick a really crappy one, use it everywhere and never change it," Johansson said. "If I write them down and then protect the piece of paper--or whatever it is I wrote them down on--there is nothing wrong with that. That allows us to remember more passwords and better passwords."

Johansson said the security industry had been giving out the wrong advice about passwords for 20 years.

Microsoft security guru wants you to jot down your passwords? by ZDNet's George Ou -- http://blogs.zdnet.com/Ou/wp-trackback.php?p=63

http://news.zdnet.com/2100-1009_22-5716590.html

Windows XP Video Decoder Checkup Utility

“The Windows XP Video Decoder Checkup Utility helps you determine if an MPEG-2 video decoder (also called a DVD decoder) is installed on your Windows XP computer and whether or not the decoder is compatible with Windows Media Player 10 and Windows XP Media Center Edition.

An MPEG-2 decoder is software that allows you to play DVDs and files that contain video content that was encoded in the MPEG-2 format (such as DVR-MS files, MPG files, and some AVI files).

If you encounter a problem while using Windows Media Player 10 to synchronize (copy) recorded TV shows to a Portable Media Center or other device, use this utility to verify that you have a compatible MPEG-2 decoder installed on your computer.

Note: This utility only indicates whether an MPEG-2 decoder is compatible with the synchronization feature of Windows Media Player 10 or whether an MPEG-2 decoder is compatible with the recorded TV playback feature of Windows XP Media Center Edition.

This utility:
• Lists all the MPEG-2 video decoders that appear in your Windows registry (a database that contains information about the hardware and software installed in your computer).
• Indicates whether each decoder listed in the registry is marked as compatible with Windows XP Media Center Edition and whether any decoder listed in the registry is marked as the preferred video decoder.
• Indicates whether each decoder listed in the registry is marked as compatible with the synchronization feature of Windows Media Player 10.
• Lets you designate which installed decoder that you want Windows Media Player 10 to use when synchronizing DVR-MS files to a portable device. This is known as the preferred video decoder.
• Lets you undo any changes the utility makes to your Windows registry.”

http://www.microsoft.com/downloads/details.aspx?FamilyID=de1491ac-0ab6-4990-943d-627e6ade9fcb&displaylang=en

Sunday, May 22, 2005

The Characteristics of Spam Email

By Bryan Costales, Marcia Flynt.
“The first step to fighting spam is knowing how to recognize it and, by extension, write code that recognizes it. Unfortunately, spammers realize this and work hard to circumvent detection. This chapter details the many ways that spam filters recognize spam, as well as the ways spammers have gotten around these filters.

It is easy for a person to look at a piece of email and say, "This isn't something I asked for. It looks like an advertisement, and I don't want it, so it must be spam." But although it is easy for humans to recognize spam, it is much harder for software to recognize it. And, after all, the point of spam-blocking software is to eliminate the need for humans to recognize spam.

  1. Connection Behavior
  2. Relaying through MX Servers
  3. Falsifying the Envelope Sender Address
  4. Disguising the Subject: Header
  5. Camouflaging the HTML Body
  6. Attempting to Fool Signature Detectors
  7. Unnecessary Encoding
  8. Grokking the Site
  9. Loose Ends
  10. Think Like a Spammer

http://www.informit.com/articles/article.asp?p=376874

Saturday, May 21, 2005

Apple Patches Widget Malware Hole in Tiger

By Ian Betteridge
“Apple Computer Inc. has quietly patched several security holes in Mac OS X 10.4, also known as "Tiger," including one that allows potentially malicious widgets to be downloaded and installed into Dashboard.

The security patches were released as part of an OS X 10.4.1 update earlier this week, but the company has only just released details of them. The update patches four security holes, the most well-known of which is the problem where widgets—small applications working in the software's Dashboard system—could be downloaded and installed without any specific user confirmation. Under 10.4.1, automatic installation of Widgets is blocked, and users must specifically approve the installation of each Widget.

Although several Web pages appeared that demonstrated how widgets could be installed without user intervention, there have been no reports of malicious widgets being found in the wild. However, because widgets can execute code—including shell scripts—outside the Dashboard environment, the ability for widgets to be downloaded and installed simply by clicking on a Web link looked like a potential route for malware on the platform.http://techrepublic.com.com/2100-10595_11-5700982.html
http://concat.blogspot.com/2005/05/mac-malware-door-creaks-open.html

http://www.eweek.com/article2/0,1759,1818272,00.asp

Tuesday, May 10, 2005

The missing glue in the fight against malware

by ZDNet's David Berlind --
“ …Three years from now, the spyware problem will be worse than it is today and I’ll be writing about one of the reasons that there has been no improvement: the failure of the industry to recognize where technological consensus is needed, and then to build solutions on top of that consensus technology.

So, in the case of spyware, what would that technology be? I’m directing that question rhetorically at the new executive team at Tenebril because it’s simply an extension of the same conversation that I was having with them about personal firewalls while they were at Zone Labs. Personal Firewalls and anti-spyware have quite a bit in common. In some ways, personal firewalls help to solve the spyware problem because they can block spyware from "phoning home" — what happens when malware reports back to its creators or distributors with its findings (eg: logged keystrokes).

But, one reason personal firewalls aren’t always successful in this endeavour is that they often require user inputs. When a personal firewall detects a first time attempt by some process to reach the outside world, it notifies the user that something new is trying to get out and it asks the user if the attempted communication should be permitted. But, as I’ve written before, this allow/disallow inquiry is all too often noticably deficient in the kind of information a user needs to make an informed decision. This is particularly troubling since, regardless of whether it’s trapping malware or legitimate software, the wrong answer might render your software inoperable. "LSASS.EXE is trying to reach 177.24.202.16. Allow Always? Allow this once? Deny?" it asks me. What the heck is LSASS.EXE? What or where is 177.24.202.16? And finally, why isn’t the software answering these questions for me?

The answer to that last question is easy. The software doesn’t know. Nor, considering the number of software components out there (legitimate and not), can it know. For a while, with many personal firewalls, this meant that answering the allow/deny question was guesswork (or, a lot of Googlework). Fortunately, guessing couldn’t get you into too much trouble. Sooner or later, every networked computer loses its connection to its network anyway. When, through a personal firewall, a user denies network access to a particular software component, the net result for that software component is pretty much the same as what happens when the system suddenly loses its network connection for some other reason (the cable get pulled out, the Wi-Fi signal disappears, etc.). If a user mistakenly denies network access to a legitimate software component that needs it, and the system or the software hangs, fixing the problem requires little more than a reboot and a correction to the firewall’s ruleset.

But that’s not how software should work. And when I started dinging Zone Labs and other firewall makers for having this problem, I also recognized that no single firewall developer — not even Symantec — was big enough to develop and maintain the database they’d need in order to provide users with the information required to make an informed decision. How do I know this? Some of them tried. But the information was invariably incomplete. To really do that database right would require the participation of all the software vendors, and for them to participate, it would have to be easy and it would have to be centralized. ”

http://blogs.zdnet.com/BTL/?p=1353

Mac malware door creaks open

"The average user, who can't find their Library folder with two mice and a spotlight, is stuck. It would take all of 30 seconds for me to pick out a nice porn image, make it the icon of a widget, drop it in your dashboard and you're stuck with it. It doesn't even need any Javascript," Stephan added.

by Jo Best ,
“Apple seems to have unwittingly opened a door in its Tiger OS--seen by some as a safer haven from viruses--to malware authors.

Apple has been encouraging developers to create new widgets for Tiger's Dashboard-—a semi-transparent layer of everyday, often-used applications such as a calculator or currency converter that appears over the user's desktop—-but within days of its public release, one developer claims to have already found a way to turn widgets into potential malware. Developer Stephan, who has posted the widgets to his blog, has created two mini-apps which he describes as "slightly evil."

One widget, he says, will automatically install itself on users' desktops when his "Zaptastic" Web site is visited using Apple's Safari browser. This, according to Stephan, is a golden opportunity for porn scammers, enabling them to auto-install widgets that can hijack browsers.

According to Stephan's blog: "I happen to like (auto-install). I think it's a great thing. But, as I have demonstrated here, it has the side effect of setting up a situation where a user can be given an application without their knowledge.

"That's not such a big deal; by default, widgets can't do much damage, and they can't run unless you drop them into your dashboard. The funny thing is that once that widget is there, according to Apple, you CANNOT remove it."

Widgets cannot be removed directly from the toolbar, but they can however be deleted from the Library folder.


http://techrepublic.com.com/2100-10595_11-5700982.html

Google Outage Dims OS X Tiger Debut

Before we get too excited, though, it's important to look at Dashboard's capabilities through the lens of the network's imperfections. When Sun trumpets its long use of the mantra, "The Network is the Computer," I bite back the temptation to retort that I'd never pay for a computer that behaves as badly as a network: one where any given memory address, for example, might or might not respond to a read or write operation at any given time, or where devices might come and go without warning.
By Peter Coffee

“You couldn't choreograph a more ironic pas de deux than the debut of Apple's OS X 10.4, with its Web-intensive Dashboard of data-tracking "widgets," followed just nine days later by a multihour outage of several Google services.

The first event illustrated, not just with a developer-conference demo but in an actual shipping product, the difference that results when always-on connections are designed in rather than added on to an end-user environment.

The second event was a rude reminder that "always-on connection" borders on an oxymoron, or at any rate tempts the Fates to rub our noses in technology's fallibility.

What makes Dashboard much more interesting than I expected is the combination of Web services on the back end, at least for the widgets that I find actually useful, and Web standards-based authoring on the front end. With a user interface defined by HTML and Cascading Style Sheets, and dynamic behavior defined in JavaScript, a widget is relatively straightforward to develop--and robust in operation thanks to the fact that it runs on a real Unixoid operating system. Very cool.

Before we get too excited, though, it's important to look at Dashboard's capabilities through the lens of the network's imperfections. When Sun trumpets its long use of the mantra, "The Network is the Computer," I bite back the temptation to retort that I'd never pay for a computer that behaves as badly as a network: one where any given memory address, for example, might or might not respond to a read or write operation at any given time, or where devices might come and go without warning.

My concerns about network inconsistency and volatility are substantial even in benign environments: Things get much worse when someone actually is out to get you with, for example, a man-in-the middle attack that obtains valuable information just from knowing what questions you're asking.

http://www.eweek.com/article2/0,1759,1813991,00.asp

Friday, May 06, 2005

Is search ruining the Web?

By Molly Wood
Search is the big dog; and it, more than standards, usability, or even aesthetics, drives the evolution of Web site design.

“It's easy to overinflate the importance of online search. Sometimes I can't help but wonder how it's even remotely possible that Google's stock is trading at more than $225 (at press time). But then I think of every new small business trying to make it on a shoestring marketing budget--actually every Web-based business, big and small, including CNET--and I realize that they're absolutely dead in the water unless they can somehow show up nice and high in search results. If Google tweaks its algorithms just a little bit, thousands of Web sites either have a very good or a very bad day. Search is the big dog; and it, more than standards, usability, or even aesthetics, drives the evolution of Web site design.

The cottage industry that's sprung up around improving a site's search results is called search engine optimization. At its best, SEO is a discipline that influences Web builders and designers to maximize their search engine results with some simple and uncontroversial changes. At its worst, though, the term includes a collection of questionable business practices, shady companies that promise clicks for cash and only sometimes deliver, and a tool that allows the proliferation of advertising-filled Web sites (free registration required) that do nothing but show up in search results and provide no information in exchange for ad impressions. It's also creating quite a heated debate about standards-based design and usability vs. search methodology. And as much as I'm a fan of standards and efficiency, I think the standards and usability are going to suffer the most.

http://www.cnet.com/4520-6033_1-6217815-1.html

Thursday, May 05, 2005

Fraud Goes With the Territory

eBay: Let's wait and see on tighter security
By Andrew Donoghue,
eBay and its customers must accept that fraud goes with the territory of online transactions, a top executive at the auction giant said.

Paul Kilmartin, director of performance engineering and availability at eBay, said the company could introduce security technology such as two-factor authentication, but the sure way to eradicate all fraud from its business would be to stop trading. "The one easy way to stop all the fraud would be to turn off the site tomorrow, and there would be no more illegal activity," he said.

Kilmartin, a 10-year eBay veteran, made the comments at Sun Microsystems' quarterly release event here on Tuesday following questions about whether eBay has any plans to introduce two-factor authentication technology to combat fraud among its users.

Two-factor authentication means requiring a second security device, such as a smart card or fingerprint, in addition to a password, to verify the identity of an IT user.

Kilmartin said that eBay has no plans to alter its authentication process for now. "We have no specific plans in this area yet, unless we start to see real demand for it," he said.

Kilmartin's remarks are at odds with comments made earlier this year by Howard Schmidt, the chief security officer for eBay and former White House cybersecurity advisor, who has called for greater use of two-factor authentication.

http://news.zdnet.com/2100-1009_22-5695440.html?tag=nl.e539

Wednesday, May 04, 2005

Patch Plugs 20 Mac OS X Holes

“Apple Computer late Tuesday released an update to fix a whopping 20 security flaws in its flagship Mac OS X and warned that the most serious bugs could lead to remote code execution attacks.

Apple Computer Inc.'s Security Update 2005-005 includes patches for Mac OS X v10.3.9 and Mac OS X Server v10.3.9. It covers a wide range of vulnerabilities that could be exploited by remote or local attackers to execute arbitrary commands, trigger a denial-of-service condition or obtain elevated privileges.

The mega update comes just two weeks after the Cupertino, Calif.-based computer maker shipped patches for a range of potentially serious kernel and browser flaws. Since April 18, Apple has posted fixes for 28 Mac OS X vulnerabilities.…”

http://www.eweek.com/article2/0,1759,1811817,00.asp?kc=ewnws050405dtx1k0000599

No Remedy for Spyware

By Matt Hines,
“Spyware is a general term used to describe software programs that are secretly deposited on computers to track Internet usage, launch advertising programs or steal users' personal information. Among the most popular of these programs are adware, keystroke loggers and so-called system monitors.

Despite reductions in the number of computers infected by spyware applications, the troublesome software has created a billion-dollar industry that continues to plague both consumers and businesses, researchers said on Tuesday.

In addition to remaining a major threat to personal and business security, Webroot said, spyware applications--specifically the types that generate pop-up advertisements, hijack home pages, redirect Web searches and use so-called DNS poisoning to steal Web traffic--generate an estimated $2 billion in revenue annually. Based on statistics published by the Internet Advertising Bureau, spyware could represent almost 25 percent of the entire online advertising industry.

The growing number of spyware attacks crafted expressly for making money, rather than for tracking Web use for marketing research or other purposes, is another emerging problem, Webroot said. The report contends that spyware exploits have "crippled" some businesses, particularly financial-services companies, in some cases by stealing customer data. Spyware infection also has slowed the growth of e-commerce by eroding consumer trust in online security.

"We can hope that the advertising industry will provide some help in trying to root out the truly malicious forms of spyware, but as long as there is an attractive return on investment on this activity for some people, this isn't going to stop anytime soon," Moll said.

Webroot said that adware continues to be the most pervasive form of spyware, with more than 50 percent of all business computers, and almost 60 percent of consumer machines, running some form of the programs. Of the devices already infected with the advertising applications, each machine averaged nearly seven different forms of the programs, according to the research.

Spying on the spyware makers
Ben Edelman may be spyware's most dangerous enemy.

The 25-year-old researcher has spent years analyzing how spyware and adware programs work and disclosing his findings publicly. That often results in red faces and, occasionally, lawsuit threats from companies like WhenU and Claria, formerly known as Gator.

When testing spyware and adware, Edelman isn't about to sacrifice his own Windows XP computer. So he uses the VMware utility to create a virtual Windows box.

"I infect the hell out of it," he says. "It destroys the infected machine." http://news.zdnet.com/2100-1009_22-5694727.html?tag=nl.e589

The security software maker worked previously with Internet service provider EarthLink to generate its spyware statistics, but Webroot representatives said that relationship has ended. No details were available on the reasons for ending the partnership.”

The remedy for spyware…not anytime soon Between the Lines ZDNet.com
Lydia Parnes, director of the Bureau of Consumer Protection at the Federal Trade Commission, kicked off the
CNET Antispyware Workshop saying that in defining spyware “it all depends.” And, a year after the FTC held a spyware workshop, the spyware and adware companies and their anti counterparts are still battling and consumers are caught in the middle. http://blogs.zdnet.com/BTL/?p=1340&tag=nl.e539
http://news.zdnet.com/2100-1009_22-5693730.html

Tuesday, May 03, 2005

Blogs, Board and Posts


Nathan Weinberg
“When users search for companies, 18% of the results are corporate info and 12% are media coverage, while consumer generated content makes up 26% of the results. Companies spend so much money making sure the media likes them, but it also needs to work to appeal to online pundits, from bloggers to consumer reviewers. One in four engage with "informal media". 34% chat, 23% post or read message boards, 16% read personal pages, 11% go to financial info sites, 8% go to their own created site, 6% read blogs, and 2% blog.

Apple is great at reaching brand advocates. We were shown an iPod ad that looked like one of the professional, broadcast quality, and (most importantly) fun ads Apple runs, and then Gary revealed it was made by a regular guy for his own site, not by Apple.

Final thought: Youth culture is adept at taking what's done by marketing and remixing it in their own way. Nothing makes that possible like the internet.”
http://google.blognewschannel.com/index.php/archives/2005/02/28/search-engine-strategies-blogs-board-and-posts/

Blogs, Boards, and Posts: Capturing Consumer Buzz Online, By Greg Jarboe
A new category of software tools has emerged that uses search engine technology to find and organize consumer-posted thoughts and opinions. These tools not only help marketers discover what is being said about their companies and brands, they also allow them to use that insight to drive new campaigns and even develop new products.

You can't use Google News or Yahoo News to find this content, typically posted to blogs, message boards or opinion sites. The major news search engines don't consider most of these types of sites to be news sources.

This was the main topic addressed by "Blogs, Boards, and Posts: Capturing Consumer Buzz Online" panel. The session featured five speakers: Two bloggers who talked about why monitoring consumer feedback sources such as blogs and message boards is becoming an important task for marketers, and three vendors who talked about how to use their tools to better integrate consumer opinions into marketing and advertising plans.

The two bloggers were JupiterResearch senior analyst Gary Stein, who also moderated the session, and Steve Rubel, Vice President of Client Services at CooperKatz and author of the Micro Persuasion blog. The three vendors were: Jonathon Carson, President and CEO of BuzzMetrics; Mark Fletcher, vice president and general manager of Bloglines at Ask Jeeves; and Mike Nazzaro, Chief Operating Officer at Intelliseek.

Stein opened the session by presenting research that found when users search for companies, 26% of the results are content generated by consumers, 22% by experts, 18% by corporate sources, 12% by media, and 22% by other sources. In other words, when prospects search for your company, the top 10 listings are likely to include:

  • 3 listings from consumer posts to blogs, message boards, and opinion sites
  • 2 listings from experts
  • 2 listings from your own corporate site
  • 1 listing from an online publication
  • 2 listings from other sources

While virtually all SEO's monitor the ranking of the two corporate listings and most PR departments monitor their press clippings, very few marketers monitor what is being said by consumers on blogs, message boards and opinion sites. What is needed, said Stein, is a Dynamic Attitude Analysis Tool, a way of making opinions measurable and actionable for marketing.

http://searchenginewatch.com/searchday/article.php/3495851

Is Bluetooth past its prime?

Posted by David Berlind

“For over five years, two of the supposedly killer wireless technologies — Bluetooth and Wi-Fi — have been marching to the beats of their own drummers. Whereas before, the two wireless technologies had almost nothing in common with each other and were designed to address distinctly different needs, now the two technologies are addressing some of the same applications (wireless printing for example). Is it time to reconsider whether the market is best served with two wireless technologies where there could be one?

When it comes to Bluetooth — a wireless technology that has the applications it supports practically baked into it (using something called profiles) — and other wireless technologies like Wi-Fi that are application-independent (it’s up to application developers to make sure devices can understand each other), Michael Foley and David Reed are two men who do not see eye-to-eye on the past, the present, or the future.

Should Wi-Fi and Bluetooth merge and, if so, what would the new radio be called? BlueFi? WiTooth? In this edition of ZDNet’s IT Matters podcast series, I moderate as Foley and Reed go head-to-head in a debate over the merits of Bluetooth. The interview is available as both an MP3 download and as a podcast that you can have downloaded to your system and/or MP3 player automatically (see ZDNet’s podcasts: How to tune in). ”

http://blogs.zdnet.com/BTL/?p=1327

Sunday, May 01, 2005

Experts Foresee End of e-mail viruses

By Will Sturgeon, Silicon.com
Published on ZDNet News: April 28, 2005

The end is coming for viruses sent by e-mail, security experts at a London conference predicted on Thursday, saying the problem has had its day.

The most severe issue Internet users now face is the growing problem of spyware, said some attendees at the Infosecurity Europe conference, noting that the malicious software is ready to fill the void.

Dan Hubbard, senior director of Websense Security Labs, told CNET News.com's sister site Silicon.com that the number of e-mail-borne viruses is falling and will continue to do so. David Perry, global director of education at antivirus software maker Trend Micro, said these things come in ages and the age of e-mail viruses has simply come to an end.

Larry Bridwell, content security programs manager at ICSA Labs, added, "If you look at virus history, I liken it to the ocean. You stand by the ocean in California and see these great big waves coming in, getting bigger and bigger before they hit the shore. People are always going to surf each of those waves as it comes in."

"There's only so much you can do with e-mail. The problem people face now in using that to carry out any criminal act is that we know how e-mail works and we know how to stop it," he said.

Bridwell warned the problem of malicious code in other forms won't go away. "These waves don't die, that water goes back out into the ocean, and people will surf in on the next big wave."

Many at this week's Infosecurity Europe said they believed that spyware is the next wave. Pete Simpson, ThreatLab manager at Clearswift, said, "Spyware definitely seems to be the theme of the show."

But Simpson is not convinced the end of the e-mail virus has come just yet. ‘It's difficult to say whether it's not just a lull,’ he said. ‘We've certainly seen a stop in the large numbers.’ ”

http://news.zdnet.com/2100-1009_22-5688726.html?tag=nl.e539

The State of New York vs. The Adware Mob

By Larry Seltzer
Opinion: It's about time someone called a fraud a fraud. Adware vendors who install programs on users' computers without their true permission are stealing from those users.

“The main job of all state Attorneys General is to grandstand as part of a campaign for the Governorship, and Elliot Spitzer of New York is the king of this technique.

There have been many cases where, IMHO, he has gone way overboard. But give credit where credit is due. It's about time someone with heavy-duty prosecutorial authority took on the lowlifes in the adware business.

Given the vigilance with which Spitzer has prosecuted legitimate businesses, one would hope that he will leave no stone unturned in the pursuit of spyware and adware, which he describes as equally objectionable.

http://www.eweek.com/article2/0,1759,1790956,00.asp?kc=EWRSS03129TX1K0000614