Sunday, October 30, 2005
Common Sense for a Change
As rich and useful as Web 2.0 apps are, today we still need both local and remote applications on a daily basis.
Reports of Microsoft's End are Greatly Exaggerated, Way Premature, and Wishful Thinking
Something like this comes out every time Microsoft announces a ship date (and they should be called slipped dates) for a new product or service. It ignores the one important fact, which is that Microsoft's biggest competitive problem is other Microsoft products.
Isn't it funny how those new capabilities eventually become a competitive necessity? They aren't the Borg, but resistance is futile, we will be upgraded.
Sunday, September 25, 2005
Office 12 makeover takes on 'feature creep' | Tech News on ZDNet
“For years, Microsoft has been trying to add features to Office without them getting in the way of people who already know their way around the software.
Unfortunately, the company was a little too successful at making its innovations unobtrusive. In user testing, Microsoft found that nine out of every 10 features that customers wanted to see added to Office were already in the program.
'They simply don't know it's there,' Chris Capossela, a Microsoft vice president, told a developer crowd last week. 'It's just too hard to find it.'
Indeed, Office has become a case study for feature creep--the phenomenon in which a simple technology becomes complicated and unmanageable through the addition of new features. Office, which once had 100 commands neatly organized into menus, ballooned to contain some 1,500 commands located in scores of menus, toolbars and dialog boxes.
Having sensed that the software has reached the limits of functionality, Microsoft has been preparing its most radical overhaul ever for Word, Excel and friends. With Office 12, due next year, the company plans to do away with a system that depends on people remembering which series of menus lead to a particular command. Instead, users will see a 'ribbon' of different commands above their document, with the options changing depending on the task. Microsoft previewed the new look for Office at last week's Professional Developer Conference in Los Angeles.
The move could help Microsoft in its perennial quest to come up with enough reasons to prompt current Office users to upgrade, and might also stem some defections to rivals, such as OpenOffice. At the same time, it risks alienating some loyalists, as well as prompting some businesses to question the cost of retraining those accusaccustomed to the current Office.”
I don't see how a ‘ribbon’ is going to solve the problem. Features will still be hidden from users.
I don't believe the problem has ever been features people want to use all the time, but, features used rarely that usually come up when there's a deadline, leaving you barely enough time to do the task. Never enough time for the luxury of searching documentation online or off for the function you need.
Barring a breakthrough in A.I. combined with a telepathic program, I don't see how this is going to work. I think they're assuming a general familiarity with program features most users just don't have. Most people I deal with are only familiar with the specific features they use to accomplish their daily tasks.
Alfred Ingram
http://news.zdnet.com/2100-3513_22-5873597.html?tag=nl.e589
Friday, September 16, 2005
Court Unseals Files on Apple 'Asteroid' Probe
"A California appeals court has agreed with the Electronic Frontier Foundation's request to unseal documents relating to Apple Computer Inc.'s legal campaign to force reporters for three Web sites to reveal their sources for articles that disclosed details about Apple's 'Asteroid' audio product.
A redacted version of the documents, which the California 6th District Court of Appeals ordered unsealed last week, is available on the EFF Web page that covers the history of the case: O'Grady et al v. Superior Court, also known as 'Apple v. Does.'
Three sites—PowerPage.org, ThinkSecret.com and AppleInsider.com—posted articles outlining details about an Apple product code-named Asteroid, which is a FireWire-based audio interface unit that will work with GarageBand, Apple's music composition application.
The EFF said that the documents show that Apple did not exhaust other avenues of investigation, as required by law, before seeking subpoenas against the three sites, which published information about the product before it was released. The EFF is one of the organizations providing legal representation for AppleInsider.com and PowerPage.org.The documents are declarations from two of Apple's security personnel who described the measures they took in investigating the source of the leak of the Asteroid information. They described tracking who had access to the documents and who accessed files on a secure internal serrver. "At a minimum," Opsahl said, "[Apple] should have asked for depositions or
testimony under oath from employees under suspicion."While they're willing to seek subpoenas for people without associations with Apple, they failed to review laptops or e-mails," Opsahl said. He added that no investigations were made as to whether confidential information was sent via a Web-based e-mail client or copied to a physical medium.
Apple has claimed that publication of the Asteroid information, and complicity in the leaking of the information, constituted a violation of the Uniform Trade Secrets Act as defined in California Civil Code 3426.1. The act states that if a company takes reasonable measures to protect information and this information has value in being kept secret, California courts should rule that such information should be afforded protection as a trade secret.
When contacted for comment on the court's decision to unseal the documents, an Apple spokesperson simply restated the company's reasons for filing the complaint. "Apple has filed a civil complaint against unnamed individuals who we believe stole our trade secrets and posted detailed information about an unannounced Apple product on the Internet," the spokesperson said. "
http://www.eweek.com/article2/0,1895,1859271,00.asp?kc=ewnws091505dtx1k0000599
Sunday, August 28, 2005
Threats Spread Thick
Top 5 vulnerabilities as reported by ThreatFocus for Monday, August 22nd, 2005
| Date | Title | Severity |
| 8/19/2005 | Microsoft [Security Advisory: A COM Object (Msdds.dll) Could Cause Internet Explorer to Unexpectedly Exit] | High |
| 8/17/2005 | Adobe [Acrobat / Reader Plug-in Buffer Overflow Vulnerability] | High |
| 8/16/2005 | Apple [Security Update 2005-007] | High |
| 8/19/2005 | Red Hat [php security update] | High |
| 8/17/2005 | Debian [New Mozilla packages fix frame injection spoofing vulnerability] | High |
http://www.pcmag.com/article2/0,1895,1850852,00.asp
Worm Could Squirm on Windows XP
By Ryan Naraine"It is important to note that Simple File and Print Sharing is only available on Windows XP machines that are not part of a Windows Active Directory Domain. However, configuring a Windows XP SP1 host to share network resources prior to joining an Active Directory Domain will leave it in the vulnerable state even after the Domain is joined," the company warned.
“Microsoft late Tuesday warned that the Zotob worm could start squirming through certain configurations of Windows XP SP1 (Service Pack 1).
The worm, which squirms through a flaw in the Windows PnP (Plug and Play) service, has wreaked havoc on unpatched Windows 2000 machines, but new information suggests some Windows XP users could also be at risk.
Late Tuesday, Microsoft Corp. issued a new advisory that confirmed the expanded threat and recommended that users implement workarounds to thwart a new worm outbreak.
Users of Windows XP SP2 are not vulnerable to remote attacks.…”
http://www.eweek.com/article2/0,1895,1851908,00.asp?kc=ewnws082505dtx1k0000599
8 Out Of 10 Enterprise PCs Spyware Infected
By Gregg Keizer, TechWeb NewsThe number of malicious sites hosting spyware has quadrupled since the start of the year, said Richard Stiennon, Webroot's director of threat research, and now number over 300,000 URLs.
“On average, enterprise PCs have 27 pieces of spyware on their hard drives, a 19 percent increase in the last quarter alone, while a whopping 80 percent of corporate computers host at least one instance of unwanted software, whether that's adware, spyware, or a Trojan horse.
Worse, said Stiennon, evidence is accumulating that spyware is becoming more malicious than ever.
"The actual maliciousness of it is increasing," he noted. "There's simply more malicious activity per piece of spyware. They're not satisfied with making their seven cents a click by flooding systems with adware; now they're focusing on identity theft, sometimes from within an organization. Spyware's being used by insiders to, in essence, hack their employer or boss."
Instances of such activity during the second quarter included a scandal in Israel and a stymied multi-million dollar bank robbery in the U.K. that was based on spyware.
Part of the bump-up in spyware infection rates and most of the reason behind its increasing nastiness is due to pressure on spyware-as-a-business, Webroot claimed.
"There's an underlying principle that often gets overlooked: spyware's a business like any other," said C. David Moll, the chief executive of Boulder, Colo.-based Webroot. "Like any business, spyware developers are committed to increasing their profit margins by expanding their distribution channels, utilizing new products, and entering new markets.…" ”
http://www.crn.com/nl/crnupdate/showArticle.jhtml?articleId=169600391
Sunday, August 21, 2005
Zotob Proves Patching 'Window' Non-existent
“Although the initial attack on Windows 2000 PCs by bot worms exploiting a week-old vulnerability hasn't grabbed much traction, the way hackers jumped on the bug is proof that the patching "window" is virtually non-existent, said security experts Tuesday.
"The last week showed once more that there is no more patch window," wrote Johannes Ullrich, chief research officer at the SANS Internet Storm Center, in the group's daily alert. "Defense in depth is your only chance to survive the early release of malware."
Exploits were circulating within three days of Microsoft disclosing the Plug and Play vulnerability and offering up a patch, and within five days, several bot worms -- notably Zotob.a and Zotob.b -- were attacking systems.
"Microsoft must be fuming that virus writers are exploiting security holes in their software so quickly," said Graham Cluley, senior technology consultant for security vendor Sophos, in a statement. "It's not only embarrassing for the software giant, but a real headache for businesses who need to move quickly to roll out security patches."
The reason for the fast hacker turn-around, said Ullrich, is that attackers are sharing more and more information. "Malware can only develop as fast as it is developing in this case because of extensive code sharing in the underground," Ullrich said. "The only way we can keep up with this development is by sharing information as efficiently.
"We need to outshare the attackers.…" ”
http://www.crn.com/nl/security/showArticle.jhtml?articleId=168602090Thursday, August 11, 2005
Spyware Researchers Discover ID Theft Ring
During the research, Sunbelt researcher Patrick Jordan deliberately installed the "CoolWebSearch application on a machine and immediately noticed that the infected system became a spam zombie that was placing callbacks to a remote server.
When Jordan visited the remote server, he was shocked to find that it was being used to distribute sensitive personal information from millions of PC users infected by the spyware application.
"We found the keylogger transcript files that are being uploaded to the servers. We're talking real spyware stuff…chat sessions, usernames, passwords, bank account information, full names, addresses," said Sunbelt president Alex Eckelberry.
…Eckelberry said the sophistication of the operation suggests it's the work of a "massive identity theft ring" that used keystroke loggers to grab confidential information that could be used to create fake online identities.…"This is the most repulsive thing I've ever seen. It's very painful to see what's in these log files that are being uploaded in real time. We're seeing a lot of bank information and usernames and passwords to get in," Eckelberry said.
The log files included logins to one business bank account with more than $350,000 and another small company in California with over $11,000, readily accessible.
"There are lots of eBay account information and names and addresses of the people owning those accounts. Names, passwords, all matched up," Eckelberry added
He said the server, which is hosted out of a data center in Texas, was effectively a "massive repository of stolen data" that was being replenished in real time.
"As the [log] file gets to a certain size, it gets taken down and a new file starts generating. This goes on nonstop. We've been watching it for a few days while trying to get to the FBI, and it just keeps growing and growing."
While the site is being hosted in the United States, Eckelberry said the domain name is registered to an offshore company. The huge size of the log files is a clear indication that thousands of machines are pinging back daily.
Where users appeared to be at immediate risk of losing a considerable amount of money, Sunbelt has contacted the affected individuals.
Eckelberry said the "CoolWebSearch" payload included a typical adware download that immediately scanned the infected machine for e-mails to use for spam runs. It then sets up a "very intelligent keylogger" that looks for very specific information, noting that the keystroke logger was able to pick up identity-related data for delivery to the remote server.
Anti-virus vendor Trend Micro Inc. provides a free online scanning tool that detects and deletes the "CoolWebSearch" application. ”
http://www.eweek.com/article2/0,1895,1845248,00.asp?kc=ewnws080905dtx1k0000599
Effective professional blogging

“TechRepublic VP Bob Artner explains what it takes to be an effective professional blogger. He advises avoiding the mistakesof many personal blogs, which he says Bloviate and are Loud,Obnoxious and Gabby.”
http://ct.zdnet.com.com/clicks
Sunday, August 07, 2005
Spyware Costs
…applications that are downloaded and installed on end user PCs without IT sanction, are increasingly represented by instant messaging. "Within the next six months, virtually all end users will have deployed some type of greynet application," the report states. "Based on stated intentions, this number will rise to 93 percent in the next six months."
…Noting that in addition to instant messaging, greynet applications can include P2P file sharing, Web conferencing, Web mail, adware/spyware, and VoIP applications such as Skype, the study found that even among IT managers who have installed perimeter security measures, 77 percent of them had a spyware incident in the past six months. Most of the IT managers said spyware incidents are occurring at the same or greater frequency as six months ago.… ”
http://www.crn.com/nl/security/showArticle.jhtml?articleId=167100251Friday, August 05, 2005
Not Sure About that Phish? Throw It Back
Recommended Action: If you receive an e-mail from your bank asking you to sign in to verify or update your account then follow these steps:
- close the email
- open a new browser window
- go to the banks web site using your regular bookmark or by typing in the address
- log in there to see if there are any problems.
Thursday, August 04, 2005
Next Explorer to fail Acid test | Tech News on ZDNet
Standards advocates and Web developers have criticized Microsoft for letting Internet Explorer go without a significant upgrade for years. This spring it became clear that Microsoft would finally address long-standing standards-compliance issues in its planned version 7 upgrade.
Microsoft last week came out with a test, or 'beta' version, of its Windows Vista operating system and IE 7.
Wilson said the broad range of Acid2's demands made it more of a 'wish list' than a 'compliance test.'
'As a wish list, it is really important and useful to my team, but it isn't even intended, in my understanding, as our priority list for IE7,' Wilson wrote.
The Web Standards Project responded positively to the announcement, hailing Microsoft's standards to-do list and its openness in acknowledging the test."
http://news.zdnet.com/2100-9588_22-5813897.html?tag=nl.e539
Tuesday, July 26, 2005
Weekend Project: Get your hard drive back in the fast lane - CNET reviews
http://reviews.cnet.com/4520-10163_7-5555103-1.html?tag=nl.e501
Saturday, July 23, 2005
Is the XP SP2 firewall getting a raw deal?
A current report on a new denial of service vulnerability involving Windows RDP (Remote Desktop Protocol) blaming the Windows XP SP2 (Service Pack 2) firewall has touched off firestorm of inaccurate coverage fthat gets "blindly regurgitated in the forums." George Ou sets us straight.
“A recent report on a new denial of service vulnerability involving Windows RDP (Remote Desktop Protocol) blaming the Windows XP SP2 (Service Pack 2) firewall has touched off a rash of sensationalism from other media outlets that gets blindly regurgitated in the forums. This has caused some unwarranted confusion and fear in the IT industry. The original story incorrectly blamed the XP SP2 firewall for failing to protect against the RDP flaw. This was a false characterization of the XP SP2 firewall which has a history of being mischaracterized as something that breaks a lot of applications or is somehow unreliable. This has resulted in some harm to the general public because too many windows users are refusing to protect themselves with Windows XP SP2. Larry Seltzer did a wonderfully accurate and educational assessment on XP SP2 but is drowned out by all the doom and gloom sensationalism.
When Microsoft first came out with XP SP2 last year, its new firewall feature was incorrectly blamed for breaking hundreds of applications when in fact any personal firewall installed without the proper holes drilled would have caused the exact same issues. This latest story on the RDP vulnerability seems to be yet another slam on the SP2 firewall with the incorrect accusation that it fails to protect against this new RDP denial of service vulnerability. While it's technically true that a SP2 firewall with port TCP 3389 (used by RDP) opened to anyone will result in a successful denial of service attack to an unpatched windows machine, this is the normal behavior of any stateful packet inspection firewall.… ”
You can protect all the PCs in your office or home by simply implementing a router with a basic firewall or just NAT (Network Address Translation) capability. A router for the home with a built-in switch can be purchased for less than $40. Not only does the router protect you from a vast array of attacks, it also acts as an Internet sharing device. Another easy thing to do is to turn on the Windows XP SP2 firewall make sure that the RDP service is either entirely blocked or only permitted to enter from trusted network sources. You can find more in-depth information here to turn off the RDP service entirely or configure the XP SP2 firewall. One of the nicest features of the XP SP2 firewall besides the fact that it's free with Windows is that it can easily be managed from a central location. This can be done from a legacy Windows NT 4.0 domain environment using a script or better yet from a group policy in a Windows 2000/2003 Active Directory. This allows a Microsoft network administrator to quickly configure every single windows XP computer in the company with a single login script or a single group policy.http://blogs.zdnet.com/Ou/index.php?p=81&tag=nl.e539
Thursday, July 21, 2005
Domain Hijacking
“Domain-name hijacking occurs when someone fraudulently takes control of a domain name, often by masquerading as the legitimate administrative contact for a domain name.
The e-mail addresses of administrative contacts, widely available in the WHOIS database of domain registrations, are used to verify domain-name holders.
The domain-name hijacking report, available here as a PDF, came from ICANN's Security and Stability Advisory Committee.
The report, announced Wednesday during an international meeting of the ICANN (Internet Corporation for Assigned Names and Numbers) in Luxembourg, followed at least two high-profile incidents this year of what is known as domain-name hijacking—one hitting New York-based ISP Panix and another affecting e-mail provider Hushmail Communications Corp.
The committee advises the domain-name system overseer's board of directors and constituents such as the registrars that sell domain names to individuals and business and the registries that manage domains such as .com and .net.
While the Panix and Hushmail cases were widely reported, the ICANN committee report also cited a dozen other examples of stolen domain names. The hijacks hit such high-profile names as wifi.com, commericials.com, nike.com and ebay.de.
Committee members expressed optimism that the report will lead to swift action, but it was still unclear as of late Wednesday whether ICANN's board planned to address the report's findings and recommendations at its meeting later this week.”
http://www.eweek.com/article2/0,1895,1836820,00.asp?kc=ewnws071505dtx1k0000599Monday, July 18, 2005
Hollingsworth Rambles
Latlely I've been hearing a lot of chatter on the podoshpere ragging on conventional broadcasters who make their shows available as podcasts. The line of reasoning seems to be that when Mr. and Ms. Big Broadcaster post their conventional broadcasts on the Internet as downloadable mp3s, they're just posers jumping on the bandwagon.
Agreed, professional broadcasts lack the home-made charm of many current podcasts. That's probably more of a threat to the podcast producers than the podcast listeners.… ”
http://hollingsworthrambles.blogspot.com/2005/06/not-podcast.html
Sunday, July 17, 2005
Does OS matter anymore for security?
“…It's usually taken as gospel in many IT circles to assume that Windows Security is an oxymoron; anyone who dares to suggest using Microsoft IIS 6.0 for a public web server faces serious ridicule. To see if there was any truth to this presumption that Windows Server is fundamentally insecure, I looked up these hacking statistics from www.zone-h.org for 2003 to 2004. Not only did it not show that Windows was hacked more often, but just the opposite. The Linux servers were actually getting hacked and defaced far more often than the Windows server and Apache was also being hacked and defaced more than Microsoft IIS.
While most security research comparing various operating systems and applications focus on statistics for the number of vulnerabilities and their criticality, zone-h takes a completely different approach by looking at actual server compromises. Even more significant is that these are not theoretical hacks in the laboratory but actual website defacements that were confirmed by the public. Zone-h is essentially a centralized "score board" for hackers who want bragging rights for their handy work. While the source of the data is highly despicable, there is no denying the value of such data being collected regardless of the source because of its accuracy. When a website is hacked and defaced, there is little room for interpretation for what has transpired because the proof is in the humiliating public defacement. While these particular defacements are often the work of recreational hackers who hack for sport and not the work of a professional criminal who hacks for financial gain, the techniques uses to compromise the servers are usually identical.…
At the end of the zone-h report for 2003-2004, the author concludes (accurately, in my experience) that the argument about which OS is more secure is totally irrelevant since most modern exploits are against applications and not the operating system hosting them. This is true because servers are rarely deployed wide open on the Internet without a firewall. A properly configured firewall minimizes the vulnerability footprint to only permit the ports necessary for a specific application to work, which means the application is the only thing exposed to the hacker. The zone-h report doesn't actually prove which OS is more secure, only that the OS is mostly irrelevant and the Windows server security jokes are more myth than fact.”
http://blogs.zdnet.com/Ou/?p=77&part=rss&tag=feed&subj=zdblogSunday, July 10, 2005
PCs Have 50-50 Shot At Infection In Just 12 Minutes
6:04 PM EDT Wed. Jul. 06, 2005
Sophos estimated that a new PC stands a 50-50 chance of being infected by a worm within 12 minutes of being connected to the Internet. (Other analysts, such as the Internet Storm Center, put the current average survival time at around 34 minutes.)
“The number of new viruses, worms, and Trojans are up nearly 60 percent in the first half of 2005, a U.K.-based security company said Wednesday, while the length of time an unprotected PC survives on the Internet has shrunk to a measly dozen minutes.
Sophos reported that it had pinpointed 7,944 new pieces of malicious software in the first six months of the year, an increase of 59 percent compared to the first half of 2004.
The firm's researchers tracked an even larger spike in the number of keylogging Trojan horses. According to Sophos, that category has tripled in number.
"We are seeing a large amount of new Trojan horses on a daily basis, representing what may be the most significant development in malware writing," said Gregg Mastoras, a Sophos senior security analyst, in a statement.”
http://www.crn.com/nl/security/showArticle.jhtml?articleId=165700440
Thursday, June 30, 2005
Sell It on eBay: the Web Site Why not add a Buy It Now?
eBay Live is off and running and I just picked up a terrific tip in a session taught by Janelle Elms, eBay University instructor and author of eBay Your Business.
It is common knowledge the buyers are very put off by Reserve Price auctions. Buyers understand that sellers need to protect their bottom line, but the hide-and-seek of figuring out what someone's reserve price is can be awfully frustrating."
why not simply add the Buy It Now feature to any reserve price auction as well. If you set the Buy It Now amount to be the same as your reserve, potential buyers examining your auction can snap up your item immediately, at the price you want.
http://sellitonebay.blogspot.com/
