Friday, February 10, 2006

Don’t use Google toolbar, says EFF

The link above is to a synopsis in The Inquirer. The Electronic Frontier Foundation warning is here.

The problem is, to put it very succinctly, that in order to index your computer for search, Google has to have copies of the docs indexed. These are open to subpoena from the government and subsequent data-mining. This whole deal must have federal security people salivating like a dog does over a steak.

Jack

Thursday, February 09, 2006

For All Geek Kittys

Catproof your computer. Got this from an email to Fred Langa's newsletter, as the correspondent says: "I thought it was a joke at first, but its real"

The real question as Fred puts it is, "Will my own typing activate it?"
Joe, hally??? ;)


PawSense helps you catproof your computer.

--MissM

Microsoft Security Response Center Blog! : Two new security advisories posted

Two new security advisories posted

Hi folks, Mike Reavey here. Just wanted to point out two new security advisories that we posted late last night.

The first is related to a WMF vulnerability in older versions of Internet Explorer. This is different from the issue addressed by MS06-001 and only impacts older versions of Internet Explorer – if you’re using IE6SP1 or later, you’re protected from this issue. The second is related to a research paper regarding default services behavior that has already been addressed in Windows XP SP2 and Windows Server 2003 SP1. For more information, check out the advisories located here:

http://www.microsoft.com/technet/security/advisory/913333.mspx

http://www.microsoft.com/technet/security/advisory/914457.mspx

-Mike

*This posting is provided "AS IS" with no warranties, and confers no rights.*

Published Wednesday, February 08, 2006 5:42 PM by stepto

Microsoft Security Response Center Blog! : Two new security advisories posted

--MissM

Monday, February 06, 2006

Why I Do Not and Will Not Use GMail

The link is to an article in MIT's Technology Review. In it, the author details just how much of a leap of faith users must make to use GMail. Google has far and away the most comprehensive privacy policy in the business, but it does not go nearly far enough. The repositories of email on Google's servers are a tempting target for everyone from law enforcement to divorce lawyers trawling for evidence. Users have so little control over deletion of email that unwanted copies can (and probably do) lay about for months after the deletion command is given.

So, even though I have nothing to hide (except an ugly mole here or there, which is another story entirely) I refuse to use GMail. I simply do not trust the system or the owners of it enough to allow my personal business to be deposited there.

You might want to read this article, just so you are making an informed decision on whether or not to use GMail.

Jack

How Much RAM Do You Need?

It seems as if every computer user, plus their dogs, has an opinion on this. The show cast is pretty well in agreement on the subject, but so many variables apply that our opinions can hardly be said to apply globally.

In an article at XBit Labs.com, Ilya Gavrichenkov reveals some testing designed to measure up against the the common wisdom. While not conclusive at all, it certainly is food for thought and on that basis I recommend reading it.

Jack

Sunday, February 05, 2006

OnComputers Radio show Podcast 02-05-06

This is the On Computers Radio show podcast for 02-05-06. If you prefer, you can download the same file here via ftp.

Thursday, February 02, 2006

NOD32 The Anti-Virus that WORKS!

By now I'm sure you've heard about the Kama Sutra worm (also known as Blackmal and VB.NEI) scheduled to activate on February 3, 2006.


Rest assured that you and your NOD32 customers are proactively protected. However, your non-NOD32 users may have problems and need help. Be prepared to let them know that NOD32 can protect them from current and evolving threats before they occur.

Remember you can buy NOD32 from AlaskaJoe to help support the radio show.

New worm relies on old trick

February 3, 2006

"That's when the Kama Sutra computer worm will begin destroying critical files on infected computers. And hundreds of thousands of machines may have the worm lurking within their Windows operating system, ready to be unleashed on February 3 and the third of every month thereafter."

This is a very destructive, but very preventible. Take the common sense precautions outlined in the article and you should be okay.

Wireless Networking in the Developing World

It's an eBook, available at no charge under a Creative Commons license.

I got the link from Waleed al-Shobbaky, a journalist friend from Egypt. I have read a decent part of it now and think some of you might find it food for thought. Because I have spent long periods in parts of our own nation without even telephone service and am intimately involved with charities attempting to change things like that, I feel a kinship with those in under-developed and/or developing nations.

There is no doubt that wireless technology in the form of cell phones. Now other types of wireless services are starting to make their mark. Large areas, even entire nations, will see their access to information open up to a flood. How they will use this is open to question, of course, but the one thing that cannot be argued is that the status quo will change.

Jack

Gates Speaks Out Against Net Censorship - Yahoo! News

"'The ability to really withhold information no longer exists,' Gates told a government forum on the Internet."

Wednesday, February 01, 2006

Make Your Windows Machine Look and Behave More Like a Mac

I found this from a link at Wired News.

What it does is make your Windows XP machine look and behave more like a Mac. Lots of Mac users have told me that they can function better in the Mac environment because it suits how they work better. If you think you might be one of those or are just curious, download the free trial of TopDesk and give it a whirl. Should you decide to keep it, the price is only $10 (USD). It's definitely worth a whirl. I rather liked the trial.

Jack

Are You Ready for Goobuntu?

Google working on a operating system for real. It's not just a rumor. Whether or not this really means anything is unclear and will be until Google clears it up.

So why are they doing this? Mostly because they can and, in my opinion, they'd be negligent if they didn't check out the possibilities. Checking something out, even by developing it to a state of usability, is a long ways from actually letting the beast out into the wild.

Will Google take Microsoft on in their core business, operating systems? I have no idea and I'm betting no decision has been made. They could do it, but be aware that they most likely won't do it, simply because that would be an outright war with MS. I could be wrong. I am not privy to the market data Google has and that is what they will judge whether or not to dive in by.

Stay tuned.

Jack

Politicians deface Wikipedia

You gotta love this one!

It seems Wikipedia's problems with rogue edits are being taken advantage of by pols. The kids just won't play fair.

Jack

Sunday, January 29, 2006

OnComputers Radio show Podcast 01-29-06

This is the On Computers Radio show podcast for 01-29-06. If you prefer, you can download the same file here via ftp.

Saturday, January 28, 2006

HEY JOE! A message for you

Hey guys, it appears your link to the podcast is:

http://update.microsoft.com/windowsupdate/v6/default.aspx?ln=en-us

Can you fix that so my itunes can pick it up?

Thanks,
ksn


TEST? TEST?
note to ksn: I did forward your comment to Joe in email, and that didn't work, so I'm trying a different option.
We want to make sure nobody misses a single episode of On Computers.


--MissM

Thursday, January 26, 2006

Chip maker is setting up an innovation center in India

From Infoworld. For some reason this caught my eye.

Taiwanese chip maker Via Technologies announced Monday that it is setting up an innovation center in Mumbai, India, that is focused on developing computing and communications appliances designed for rural markets in India and other countries

Wednesday, January 25, 2006

Sunbelt BLOG: Google helps to fund an antispyware site

Alex Eckelberry says the following:
According to an article by Ryan Naraine in eWeek, “Web search powerhouse Google has joined with Sun Microsystems to fund a new anti-spyware coalition that is on tap to launch on Jan. 24…”. It will be operated by the Berkman Center at Harvard and the Oxford Internet Institute at Oxford University.

Apparently, the site is going to be an information clearinghouse and help center for consumers. In an article in the Christian Science Monitor, the group’s co-director was quoted as saying “the coalition will act like a "neighborhood watch" for the Internet, relying on citizens to report problems.”

The new site, “StopBadware.org” will be up tomorrow. The domain is owned by Google.

He has links to all the articles, so go check it out. It will be interesting to see how this all pans out in practice, my first impressions are good, but I'm posting this before reading all the links, myself [full disclosure, eh? ;) ]

--MissM
[for RSS readers]Sunbelt BLOG: Google helps to fund an antispyware site

Tuesday, January 24, 2006

EFF: DeepLinks

You say you want the power to time-shift and space-shift TV and radio? You say you want tomorrow's innovators to invent new TV and radio gizmos you haven't thought of yet, the same way the pioneers behind the VCR, TiVo, and the iPod did?

Well, that's not what the entertainment industry has in mind. According to them, here's all tomorrow's innovators should be allowed to offer you:

"customary historic use of broadcast content by consumers to the extent such use is consistent with applicable law."


PDF of the Draft Legislation

--MissM
Thanks Joanne for the link to Big Content would like to outlaw things no one has even thought of yet
EFF: DeepLinks

Monday, January 23, 2006

Supreme Court rejects BlackBerry patent appeal

The high court’s refusal to hear Canada-based Research In Motion Ltd.’s appeal means that a trial judge in Richmond, Va., could impose an injunction against the company and block BlackBerry use among many of its owners in the United States.

Technorati link, cause I know there will be a great deal of discussion about this, since so many in government rely on this.

--MissM

Supreme Court rejects BlackBerry patent appeal

The Coming Tug of War Over the Internet

If you don't have a log on for wapo use bugmenot because this article is a must read, for anybody on the internet. Which includes you! :)

ISPs are trying to get content providers to subsidize the bandwidth, and Congress is considering overhauling the Telecommunications act of 1996. An example is a nickel PER iTunes download from Apple. Another potential example, yahoo pays the pipe owner, to "optimize" the connection from the ISP customers, and then google loads slowly. This is something that definitely needs to be kept an eye on.

Just looking at who's on which side, leads me to believe this is a classic David and Goliath (except we have google, and Apple maybe? on David's side). The ONLY way I'd consider this, is if it reduced my cable bill, SERIOUSLY. But, I have to wonder how bittorrents would be affected. By the way, I was getting over 800KB downloaded with 2 twit video feeds!!! Nice!

--MissM
article link here (for RSS ;) )

Update: I was reminded of Doc Searle's essay about keeping the internet pipes consumer friendly and the perils of not, its long, but important. Saving the Net: How to Keep the Carriers from Flushing the Net Down the Tubes | Linux Journal

Sunday, January 22, 2006

OnComputers Radio show Podcast 01-22-06

This is the On Computers Radio show podcast for 01-22-06. If you prefer, you can download the same file here via ftp.



-- Edited on 1/28/06 by Aaron to correct link.

Confirmed: Gmail dot bug sends your email to other users!

Gmail doesn't recognize dots in usernames, so to Gmail, digg.user@gmail.com and digguser@gmail.com are the same. So while you can create a Gmail username with a dot, if an identical name exists without the dot, he'll get your email! Users have reported this weirdness for many months already, now it's confirmed by Google, albeit, not yet fixed.


I've run into this myself. I got user.name@gmail.com when I've registered username@gmail.com

Have you?

--MissM


read more | digg story

A 3fer day for google. Feel the luv????!?!?!!?!!?!? ;)

Google Word Verification Accessibility Petition

To: Google Inc.

We, the undersigned, ask Google Inc. to "do no evil" and follow their mission statement to "organize the world's information and make it universally accessible and useful" by promptly adding accessibility to their visual word verification scheme so that the blind and visually impaired are allowed to fully participate in all products and services offered by the company on terms of equality with our sighted peers.

Sincerely,

The Undersigned

Go, sign it! And don't forget to hit approve at the end, or your signature won't count. As I mentioned here, paypal.com does have a system that works for visually impaired.

--MissM
kudos go to Mike @ MikeTechShow for making me aware of the petition.
Experiment: I'm trying to make this rss friendly by including a direct link to the petition, hopefully, it'll be clickable in my reader.
Google Word Verification Accessibility Petition

Feds want Google search records

The Bush administration on Wednesday asked a federal judge to order Google Inc. to turn over a broad range of material from its closely guarded databases...Nicole Wong, an associate general counsel for Google, said the company will fight the government's effort "vigorously.''

Gonzales v. Google, Inc. The U.S. Department of Justice filed a motion in federal court seeking a court order that would compel search engine company Google, Inc. to turn over “a multi-stage random sample of one million URL’s” from Google’s database, and a computer file with “the text of each search string entered onto Google’s search engine over a one-week period (absent any information identifying the person who entered such query.”

If that paragraph above does not raise the hairs on your neck, I suggest you re-read the first amendment to the Constitution. What are they thinking? This is no way to survey porn use.[Peter S. Kastner]

Go Google Go!
But, this is one of the reasons I don't have google desktop installed, if its not available, there's nothing to search....

--MissM

Update: Yahoo caved in to the record request.
America, United States, Sunday Times Yahoo has admitted that it granted the US Government access to its search engine's databases this summer, as a battle develops over the right to privacy in cyberspace.
Update2: The reason for the request was :
The lawsuit is the government's attempt to revive the 1998 Child Online Protection Act (COPA) which was struck down by the U.S. Supreme Court on grounds it violated the First Amendment. COPA was enacted by Congress with the aim of protecting minors from potentially harmful effects of sexually explicit material on the Internet. (Courtesy of CNN.com

It occurs to me (and I apologize if its not techie enough for you) that they aren't even trying to prosecute anybody, just eliminate the First Amendment of the United States Constitution.

Saturday, January 21, 2006

FBI: Most Companies Get Hacked

If this one doesn't give you pause about the businesses you deal with, nothing will.

Some security researchers take issue with the study, saying the numbers are simply wrong. No one disagrees with the basic conclusion, though. Major security incidents are the norm, not the exception.

The survey really is a little goofy. It equates spyware infections with genuine intrusions and several other assumptions are equally strange. I suspect this was done to simplify the form in order to not burden those responding unduly.

The point is that there is a lot more of this sort of thing going on than was generally acknowledged.

Jack

Friday, January 20, 2006

Update: Inside the WMF Backdoor [Mark's Systinternals Blog]

Some of the latest info:

Mark received several requests to look into the WMF vulnerability and he believes it is merely bad design, not a deliberate backdoor. Steve Gibson has released another security now podcast which apparently "close[s] the backdoor" on the WMF vulnerability, but I haven't listened yet, so go check it out, there are a variety of ways to access the podcast listed, from audio to text to PDF.


--MissM

Thursday, January 19, 2006

Gonzales v Google: the study methodology is flawed

The text below was sent to Joel McElvain at the Department of Justice:

Sir,
I have read and considered your motion to force Google to comply. May I humbly suggest that you may win the battle and lose the war. I have no stake in this dispute, but I do know a few things about computer technology. Yes, you will find me with a Google search.

Assuming you get the data requested from Google and its competitors, what kind of picture can you paint with the data obtained for the Supreme Court? The answer is not enough that is useful in setting United States law and policy. Internet search providers such as Google have search servers spread throughout the world, largely to handle queries in local geographies. The search engines must comply with local laws such as Arabic bans on indecency, China's ban on "democracy" and France's ban on Nazi memorabilia auctions.

For various reasons, Internet data that is searchable and available in one part of the world may not be available in or accessible from the United States, and vice versa. Therefore, it appears to me that a random set of data from Google's query servers around the world cannot say whether the query made in, say, China can also return the same results if made from the United States -- and therefore be controlled by U.S. law. Your subpoena will drag in worldwide data without identifying the query limits of the source data server.

As a citizen, I am interested in seeing that the Supreme Court's remand re COPA is met with a study that is accurate and defensible as it relates to U.S. law and citizens. I fail to see how the methodology implied in the Google motion is going to achieve a "national" set of data when a "world" net is being cast.

Regards,
Peter S. Kastner

Wednesday, January 18, 2006

New Linux license takes aim at DRM and Hollywood | CNET News.com

"At a two-day event here to launch the General Public License version 3, which governs use of countless free and open-source programs, Moglen said the license includes anti-DRM provisions that could put it in conflict with movie studios and even digital video recorder maker TiVo"

Next XP Service Pack is Far in the Future

Apparently Microsoft has much less interest in service packs for XP than they do in releasing Vista. While that is understandable, it seems to indicate they are not terribly concerned with problems that exist in XP now.

Here is Microsoft's roadmap for service packs.

I frequently get the idea that Microsoft simply does not have enough people to deal with all the updates and upgrades they need to be putting out. With all their billions, one would think they could and would hire enough good people to do what they and their customers need done.

Jack

Tuesday, January 17, 2006

Researcher: Sony BMG "rootkit" still widespread

As we have hinted during the show; the damage and flap over Sony/BMG's behavior is far from over. This Security Focus article makes that perfectly clear.

Be afraid;

Jack

Sunday, January 15, 2006

OnComputers Radio show Podcast 01-15-06

This is the On Computers Radio show podcast for 01-15-06. If you prefer, you can download the same file here via ftp.

Saturday, January 14, 2006

Speaking of Trustworthy computing....

The link in the title goes to the latest Security Now podcast with Leo Laporte and Steve Gibson. Steve releases his current information about the WMF Vulnerability. He says that the WMF exploit was a deliberate backdoor, by somebody at Microsoft, and there's no way that it was unknown. One does have to go to a website that could take advantage of the exploit though.

He came to this conclusion while trying to determine if 95, 98 and WinME were vulnerable or not to the wmf exploit, and had to come up with a file that would test the exploit in the earlier Operating Systems. Steve gets into a bit of an arcane discussion re: bits of data in wmf files, when all of a sudden he says it had to be deliberate. That woke me up! It'll be very interesting to see what happens on this issue, in the next week or so.

--MissM
P.S. At first, I assumed that the MS patch had been forced on his machine, since this was so public (referring to Jack's post below).
P.P.S. I assume the fix, fixed the exploit, er backdoor?

UPDATE: 'Windows backdoor' theory causes kerfuffle |CNET News.com

Further UPDATE: Microsoft Security Response Center Blog! : Looking at the WMF issue, how did it get there?

PCWorld.com - Symantec, Kaspersky Criticized for Cloaking Software

More companies are using Root-Kits now!Mark Russinovich, chief software architect with systems software company Winternals Software, says that the techniques used by Symantec's Norton SystemWorks and Kaspersky's Anti-Virus products are rootkits, a term usually reserved for the techniques that malicious software uses to avoid detection on an infected PC.

Friday, January 13, 2006

Anti-Spyware Coalition Risk Model Description

The link above is not to the Anti Spyware Coalition's home page, but to their definition of "risk modelling" in relation to these programs.

I have no idea whether the ASC can actually make a difference and to be perfectly honest, I have my doubts. No matter that; they're trying to do well by users and that must be applauded.

Check it out. Send them feedback if you think you can be of help. Anything is worth a shot to make this plague upon users better.

JacK

A Time to Patch

The link is to an article on The Washington Post's web site. In it, Brian Krebs examines the timeliness of Microsoft' patching of security vulnerabilities. According to Krebs, it is not a pretty picture.

It seems MS assigns priority to patches based on how much the public knows of them. Those that have gotten publicity get higher priority in Redmond than those that don't. And regardless of publicity, Kreb's analysis shows MS is actually slowing down in it's responses to vulnerabilities.

Isn't Trustworthy Computing grand?

Jack

Microsoft patches without permission

I had no idea this was the case and have heard no reports of it until this blurb made it to my attention.

Apparently; even as MS played down the severity of the WMF vulnerability to us, they were taking it so seriously that they chose to over-ride the patch installation settings on machine to install this patch the instant it was received, rather than waiting for the administrator to do the deal. The subsequent reboot must have thrown a wrench into at least some operations.

So; we see Microsoft saying one thing about a security problem and acting in such a way as to convince me they knew differently all the while. So much for Trustworthy Computing".

Jack

A Reasonable Discussion of Digital Rights Management

Victor Yodaiken has written an article posted at Groklaw about problems associated with widespread DRM. I recommend this highly, though the author does have a viewpoint of his own, he tries really hard to express only technical problems and not get into philosophy or law.

Yodaiken accepts that pervasive DRM is coming and concentrates on which problems have to be solved before DRM becomes a danger to users or their data.

The same author has written "DRM Out of Control" at Linuxdevices.com.

Jack

Microsoft Support Lifecycle

Updated today, according to ISC. Online support for XP Pro [my flavor of XP] until 2011, a full list of links by product, handy resource.

--MissM

F-Secure : News from the Lab

To add to Jack's post about Symantec's RootKitAccording to F-Secure Norton's Rootkit was part of a well documented feature, its related to recovering deleted files. Evil program writers could have hidden there, but apparently none had done it yet, as I read it, and now it can't be exploited, according to Mikko at F-Secure.

--MissM

Thursday, January 12, 2006

Linux is Not Windows

A VERY good opinion article on why Windows users find using most Linux distros does not mimic the Windows experience. If you've ever had any interest in trying Linux, or of converting your operations to it, this will clarify both the issues and what you are getting yourself into.

Jack

Mark's Sysinternals Blog

Mark Russinovich is the person who discovered Sony's XCP rootkit. His current blog entry is an almost sickening account of misleading spyware/adware popups that sell dodgy anti-spyware apps. Ben Edelman has other documentation of the same sort of thing.

If you need a refresher course in what we are up against in terms of spyware/adware, this is it.

Jack

More RootKit Madness

This time it's Symantic. One would think a vendor of security products would know not to do stuff like this, but evidently they included a rootkit function in Norton SystemWorks.

This is downright disgusting.

Jack

Wednesday, January 11, 2006

New Wi-Fi standard back on track

The link is to a story on CNet's News.com.

Peter and I alluded to the fact that some hardware for 802.11n is already on the market, such as AirLink's "MIMO" parts. These are built to the company's best guess as to what the "n" standard will be, not to the standard itself. This has the potential of causing interoperability problems to kit made to the actual standard.

This new spirit of cooperation is essential to speeding codification and adoption of the standard. When that is done, all products will (in theory) interoperate smoothly as we can spend our money on kit with confidence it will work in all or most situations.

Jack

Should Apple Open Up?

The link above will take you to a current article in Business Week's web site. I got the link from my friend, Waleed al-Shobakky, who is attending university in Qatar.

Though Apple is almost completely without a commercail presence anywhere except the US and western Europe, the company garners a lot of attention in the rest of the world. Almost an amazing amount of attention.

I don't think Apple should open up any part of their digital entertainment operations. However; I do think they are missing a lot of income by not selling OS X for x86 as a standalone product. Actually, I would see that as a grand move to drive their digital entertainment market forward, besides generating a boatload of profits.

Doing so could conceiveably drive Apple's market share of operating systems above 10% and 20% is not beyond possiblity. Rather than the iPod generating operating system and hardware sales, I could see operating system sales generating a much more widespread presence in digital entertainment, which is where the real money is.

Apple does not have to attempt supporting the vast majority of hardware, as Windows does. They only have to support a small subset of x86 stuff. They can line up strategic partners for this and support no other products. That's doable without great development costs to drain their profits.

If they don't do this, and relatively soon, I think they'll be missing a chance to really grab the maket and lead it, despite their minority share.

Jack

Skype - the bandwidth hog

From Om Malik's blog... some interesting observations, comments and links about Skype. Several of us here use Skype and have had pretty good results. Apparently though, there are some bandwidth and security issues. For some of us, these aren't serious enough issues to stop using Skype, for some others they are. Interesting food for thought, though.

NOD32 now detects rootkits

NOD32 scores again! "Today, Eset’s ThreatSense technology represents the only integrated solution able to protect from even unknown rootkits proactively. According to Eset’s chief software architect Richard Marko, the technology is very effective with detection rate in company’s internal tests on the level up to 90%..." This seems a significant development because of the incredible stealth of rootkits. Check out the article. Folks, I'm not just praising NOD32 because of OnComputers (although I'm always glad to support O.C. when possible) but I've been using NOD32 for several months on every computer system that I own or support and the results have been as near perfect as you could get; it hasn't missed a single threat or potential threat. Joe's not kidding when he says it's the best A/V available today. And recently, Jack brought to my attention that NOD32 is one of, if not the the least resource-intensive A/V available. There are certainly other good ones (and some not so good) but IMO, it's the best, and definitely worth the money. Here's to "safe computing"...

Tuesday, January 10, 2006

Feds Give MySQL Thumbs Up

In granting a GSA contract to sell MySQL relational database software into the federal government for the next four years, the Feds have blessed another component of open source software. Bad news for Microsoft, Oracle and IBM. The maturity of MySQL was a factor in the decision.

The U.S. federal government also met in November to flesh out a process of building an open-source software stack that will be used across agencies to develop, deploy and maintain applications across their life cycle. That stack will include such open-source components as the JBoss application server and the Eclipse application development environment. I find such a federal software stack very interesting, primarily because it will likely create a parallel non-government use of the open source stack by enterprise and commercial software developers.

Microsoft to hunt 'new species' of bugs

Yet another take on Microsoft's WMF vulnerability and the patching thereof.

Remember what this article makes clear. What turned out to be a vulnerablity was intended originally as a feature. We can extend that to include other parts of Microsoft's various code bases and realize what security researchers have known for a very long time (this includes both the good guys and the bad guys); A large fraction of MS' code base in both operating systems and applications is quite old and from a kinder, gentler time when organized crime wasn't keen to exploit any vulnerability. Therein lies a large part of the problem. It's not that Microsoft can't write secure code. It's that they really didn't need to when a large part of their code was written.

Not all legacies are good.

Jack

Apple's Jobs Wows the Crowd at Macworld

Apple Computer introduced new Intel-powered desktop and notebook computers, said its wildly popular iPods helped drive a 63 percent jump in holiday quarter sales, and indicated it sold 1.25 million Macintosh computers during the holiday quarter when sales at its own retail stores were about $1 billion.

Apple sold 14 million iPods music and video players during the holiday quarter and 42 million to date. Jobs said that iPods were supply-limited. Speaking at the company's annual Macworld conference in San Francisco, CEO Steve Jobs claimed the iTunes store has so far sold 850 million songs.

The strong demand for iPods and Macs fueled a 63 percent jump in revenue to a record $5.7 billion compared with a year earlier, beating Wall Street concensus.

The company introduced new computers based on Intel Corp. chips. The company's new line of iMac computers would come in the same shape and sizes as the existing G5 line of iMacs, with starting prices at $1,299 and with twice the G5 performance. It also introduced a new high-end laptop called the MacBook Pro that will replace its PowerBook series, starting in February at prices beginning at $1,999. Some eyebrows were raised as Apple will be shipping the new Intel-based products six months before it said it would. The early shipments are likely to fuel a greater whole-year market share gain by Apple.

iLife photo and media software is updated in a new version of its suite of digital media editing tools for use in organizing and editing music, photos and movies and Web sites. ILife, which costs $79, also includes the ability to edit high-definition videos.

With its own stores generating over $22 million in annual sales each -- Best Buys stores do about $30M -- the company is clearly profiting by its own channel. Recall how Gateway tried the same strategy and failed.

Wall Street was ecstatic.

Paul Allen's Hobby Web Site

It seems like everyone my age (except me) started computing on Digital Equipment Corporation's PDP series of computers. Indeed, they are still mentioned fondly and a few are still in use. Certainly the successor to the PDP series, the VAX is still going strong in many businesses.

DEC is no more, but their influence is still strong in the history of computing. Microsoft co-founder Paul Allen has an old computer museum and a web site about them. It really is a work in progress, but there is enough there to satisfy a lot of your curiosity and whet your appetite for more.

Jack

Wow, Microsoft Sure Patched That One Quickly!

This is Larry Seltzer's look back at the WMF vulnerability in Windows and the surrounding flap. It's worth a look and pointing you toward that will keep me from having to write it up.

The article points out that it is hard for Microsoft to be believeable when they say that security is their highest priority when they have vulnerabilites of which they have been aware going unpatched for over half a year! The tired old excuse of having to test every patch and release it in multiple languages simultaneously doesn't hold water. Why can't they devote a very small part of their billions in yearly profits to expanding the security team to the point where they can make timely improvements when flaws are found?

Microsoft has indeed made great progress in security. I don't understand why they cannot go farther faster.

Jack

Strip Out The Fans, Add 8 Gallons of Cooking Oil

Save this url for when you need a bit of comic relief.

It's a real experiment and had a good result, but filling a sealed PC case with pure cooking oil as a coolant is a bit much and makes me think the folks at Tom's Hardware have a bit too much time on their hands and money for their own good.

What they ended up with is a high-performance PC that operates totally silently. No fans to disturb the user at all!

If you do this with Intel Xeons, you can make french fries.

Jack

Mercury ships PS3 - kind of

I've been watching the emergence of the Cell microprocessor in areas other than the PlayStation 3 and thought to point this one out to you.

The article grudgingly makes the point that gaming is related to other fields where data visualization is used. We're not talking about simple graphs, here. But visualization of seismic or medical data. There are actually a large number of fields where this is very important. Intense calculation is required and the Cell does it all in this area.

Expect to see a lot of this sort of Cell implementations. It's a marvelously well suited device for this. IBM and their partners have what looks like a killer design win here.

I want one. Jane? You missed my birthday. Better late than never.

Jack

Engadget says " Samsung combo HD DVD/Blue-ray a no go"

It looks like licensing issues will keep a combo player from getting to market in the near, if foreseeable future. That stinks, and is NOT consumer friendly. I just hope that it gets straightened out soon, or we are gonna be caught in a Beta/VHS war (if I'm not dating myself). :)
Have you decided on a format or approach to this conflict?

--MissM

I read somewhere this morning that XP Pro isn't gonna be supported after 2006. Doesn't that mean Vista HAS to be out in 2006? ;)

Buy a Local PC, Get a Vacation for Two

From one of the ads served up on this blog, I find a fascinating deal: buy a PC from a local builder with genuine Windows XP, and get lots of prizes worth up to $615. But wait, the average PC costs about $615, so that means you get a vacation and a free PC.

Served up at Microsoft Windows Marketplace, this appears to be a real marketing campaign -- as opposed to "click here and win a free iPod" scams. But I'll be damned if I can make out the economics.

So, hey, support your local PC builder!

[Full Disclosure: several of the hosts of the On Computers Radio Show are PC builders]

Microsoft's Vista for Consumers at Home

With all the smoke, mirrors, and speculation about Vista, it has been hard to keep track of the goals for Vista. Here's what Microsoft says about Vista directly from the mouth of eHome division executive Joe Belfiori:

Executive Q&A: Joe Belfiore
Corporate VP, Microsoft Windows eHome Division

This year at the 2006 International Consumer Electronics Show (CES) in Las Vegas, Microsoft Corp. Chairman and Chief Software Architect Bill Gates revealed powerful new innovations for Windows® users that will be launched with the company’s next-generation operating system, Windows Vista™. The following brief Q&A with Joe Belfiore, corporate vice president of the Microsoft Windows eHome Division, will provide a sense for what the upcoming changes to Windows will mean.

How does Windows Vista improve consumers’ experiences?
Microsoft® Windows Vista offers four clear categories of benefits, the first being that it makes it safer and easier to accomplish everyday tasks. Windows Vista features safer browsing, greater control for parents over what their children view, and enhanced protection from threats such as viruses, worms, and other attacks. Second, the operating system features enhancements to help users instantly find what they want. These include integrated search capability throughout the operating system and a fresh, new interface that will help people find and organize information in a fast, personalized way. Third, Windows Vista enables people to be connected at home or on the go with fast off (previously called instant on/off) capabilities, a new mobility center that enables people to access and change mobile computer settings easily from one place, and new features that allow quicker and easier connecting and syncing while on the go. And fourth, Windows Vista will allow people to enjoy the latest in entertainment through new photo and video capabilities, an updated Windows Media® Player and Games Explorer, and an enhanced Windows Media Center experience.

How will Windows Vista change the way consumers use their PCs?
Perhaps the most dramatic change in how people will use their computers lies in the ability of Windows Vista to provide easier and wider access to an integrated yet seamless menu of entertainment functions. Beyond enhancing the users’ ability to work with their music and pictures, Windows Vista will allow them to watch live TV, record TV shows, and access the many Web services that provide “TV-like” content — and they’ll be able to do so using a remote control. The Media Center experience will feature a revamped user interface optimized for high-definition (HD) widescreen displays and large media libraries and will also deliver new HD content through a number of means, particularly by the inclusion of CableCARD support for U.S. cable companies, which will allow for the consumption of cable HD broadcasts. Through these scenarios, Windows Vista marries the worlds of computing and entertainment in a way that’s never been possible before, and we think this is something that consumers are really going to be excited about.

How is Microsoft working to bring this digital entertainment vision to fruition with Windows Vista?
This is a process that actually began with Windows XP Media Center Edition. Because Media Center has become so popular — with sales now surpassing 6.5 million units in just three years — a host of media and entertainment partners have now seen the potential of bringing digital media to the PC in new ways and have begun to build hardware and software that unite the best of the digital entertainment world with the world of computing. As a result, you’re seeing us work with a range of partners and service providers that you wouldn’t have necessarily associated with Microsoft just a few years ago. Today we’re working with companies such as MTV Networks and Showtime Networks Inc. to bring new content to our customers in new and exciting ways.


How does Microsoft envision Windows Vista changing the industry?
Windows Vista has created a buzz among Microsoft’s software, hardware, and services partners because it enables them to build new devices and programs on the platform in a way that wasn’t as easy or wasn’t even possible before. Windows 95 changed the industry dramatically, and we think that Windows Vista will provide a similar, almost revolutionary, raising of the bar for our developer ecosystem and the industry at large. For consumers, Windows Vista will simply provide clarity so they can safely and easily enjoy everything on their PCs, at home or on the go.

Two new WMF bugs found

Strangely enough, these two flaws are not the ones I spoke of during Sunday's show. They are closely related, though. It turns out that the two I spoke of have been deprecated to the level of bugs and are not vulnerabilities.

Before you get too wound up over these, note that they are not rated as nearly as severe as last week's flaw. And as the article says; this is a consequence of the inherent complexity of image handling. While we as users tend to think of images as a simple display task, that is not true. There is a whole lot more to it and that complexity is the reason vulnerabilities are continually found.

Jack

Monday, January 09, 2006

OnComputers Radio show Podcast 01-08-06

This is the On Computers Radio show podcast for 01-08-06. If you prefer, you can download the same file here via ftp.

Sunday, January 08, 2006

Now Here's a Password!

This nifty site generates several unique, long and hard to crack passwords -- just for you! Each visitor gets a different password set from the server.

Intel's Tune: Take Viiv

Viiv (pronounced "five") is a new home-entertainment platform. After ignoring what I thought was fairly obvious for the past five years, the company is finally realizing that its star is attached to microprocessor-based media hubs in the living room.

By using the Napa platform, a new dual-core laptop chip and chipset that's part of the latest Centrino technology, PC form factors can shrink to attractive sizes and shapes that fit better in the living room or TV den. Napa generates much less heat than a Pentium 4, so the Viiv PCs can be quieter and smaller. But Pentium 4's can be used in Viiv's too. The past and next generation of chipsets -- 945, 955 and now 975 provide the I/O. That means high-definition audio is standard. More than 110 PC companies will introduce Viiv PCs in the first quarter of 2006.

Microsoft is a key technology partner because Windows XP Media Center Edition (MCE) 2005 is the preferred operating system. But Intel has also created digital rights management glue software that allows content providers and OEMs to avoid Microsoft's proprietary DRM.

If you have been one of the 6.5 million owners of a PC with MCE 2005, Viiv is a ho-hum product brand launch. But the impact on the industry will be great, nonetheless. The reason is that Intel and Microsoft have cajoled Hollywood into allowing much more content to move into and about our homes on networks. As a result, TV and movie video whizzing over the 'Net and around our homes will be routine in five years.

And lest you think I have missed the 800-pound content gorilla in the corner, fear not. The first Apple products based on Intel processors will be announced at Macworld this week. To Intel's bottom line, it doesn't matter whether they carry the Intel Viiv logo or not -- and I am betting they do not. Apple will be one of Intel's allies in opening up the digital living room.

Saturday, January 07, 2006

Interview: Ilfak Guilfanov

Here's an interesting interview with the developer of the "hexblog" WMF vunerability patch. You know, the patch before the official patch. If you wondered what it was and how it worked, here ya go.

Want To Try An Honest-to-Goodness Web App?

Writely is a web-based word processor and collaboration application. I"ve been using it all day with another author to collaborate on a magazine piece. It works excellently in Firefox on Windows and with just a bit of clunkiness in either FF or Konqueror on Linux, though it is certainly usable on the alternative platform.

If the pundits are to be believed, and I don't see why they shouldn't be, web-based apps are the shape of things to come. Here's a chance to dip your toe into the water, albeit in a small way.

I am not yet ready to give up my Open Office installations. OO 2.0 is my preferred office suite now and I have not yet missed MS Office.

On a related note, there is a portable version of Open Office that can be carried around on a USB pen drive. You can see it here.

Jack

Google Pack

In blog synergy , I have a post to Google's latest software offering, to complement Jack's and Peter's post on Google hardware,

Very interesting, here's a link to the beta (of course) Google Pack.
CES: Google Pack: Live Now [by rafat] : The Google keynote is in 15 minutes, but the Google software package bundle called Google Pack is live now, for dowloading here. More info on Google Pack here on About page...
The package has:
Google Earth; Google Toolbar for IE; Ad-Aware SE Personal; Google Desktop; Google Pack Screensaver; Norton AntiVirus 2005 SE; Picasa; Mozilla Firefox with Google Toolbar; Adobe Reader 7; Google Video Player ; GalleryPlayer HD Images; RealPlayer; and Trillian. hat tip to paidcontent.org


--MissM

Oh Yeah, I'd also like to wish the blog HAPPY 2nd BIRTHDAY! Gail and Jack are right on the bleeding edge of tech, and got us (and I use that term liberally ;) ) a weblog 2 years ago, which in internet time is, decades? Well Done Y'all!

Friday, January 06, 2006

Google Selling PCs is a Bad Idea

The idea that Google would start selling PCs is a non-starter for this analyst. The margins on PCs are too low (ask HP). The business is constantly changing (ask Dell). And even the once-great manufacturing company, IBM, sold off its PC division to Levovo last year.

Google software on Google hardware is not synergy. It is less than the sum of the parts.

Could I be wrong? Of course, as I am not privy to GOOG insider strategy secrets. But is it happens, Ill be one of the first ones yelling "short".

Will Your PC Run Windows Vista Graphics?

Yes, your PC will run Vista graphics. However, there are four levels of Vista graphics capability that demand increasing -- maybe even cutting edge -- graphics cards. What you want may not be a level that your PC can deliver.

The attached article on WindowsBlinds 5 suggests the opportunity to try out this windowing-intensive graphics shell for Windows XP. If your PC does not choke, I suspect it will do adequately or better with the Avalon wizz-bang GUI in Vista.

And as a side benefit, WindowsBlinds 5 will make your PC look as close to a Mac running OS X as it is ever likely to get. Enjoy.

xBox 360 Watch

On eBay, xBox 360 Premium today is going for about $520 + shipping for the $399 MSRP product.

There has been no significant downturn in auction pricing after Christmas as crudely measured by me. (Hey, there's no pay in this job so quality is what it is!)

Supply is expected to improve later in January, so local merchants say. I would not bet on that.

Dell shows 20 inch notebook at CES

Dell is showing a "concept" notebook with a 20.1 inch display at The Consumer Electronics Show. It is armed with very good speakers and microphones and seems aimed at multimedia applications, including teleconferencing. No plans for shipping were given, though a representative did say "soon".

There is a reason no other member of the cast disagreed with my prediction that by the end of this new year notebooks (of all sizes and including tablets) would account for 62 to 65% of all PC sales. As this develops, two trends are evident. One is to smaller, lighter, thinner notebooks and the other toward what can only be described as true desktop replacement machines. While these are portable, they are heavy and large. The extremes in size form the two poles in terms of sales. Notebooks in between the poles, while selling well, are unlikely to have the appeal and sales of the largest or smallest units.

I'm sure this Dell is but one of a new wave of true desktop replacement notebooks. It sure looks attractive.

Jack

Phone Companies Set Off Battle Over Internet Fees

Large phone companies, setting the stage for a big battle ahead, hope to start charging Google Inc., Vonage Holdings Corp. and other Internet content providers for high-quality delivery of music, movies and the like over their telecommunications networks.

Historically, network providers have agreed to deliver Internet traffic on a "best efforts" basis without guaranteeing various levels of quality of service. That hasn't been a problem for the most popular Internet services, like email and Web surfing, because they aren't dependent on uninterrupted streams of data. Real-time videogames, phone service and video, however, demand more reliable quality, and network operators are trying to prioritize Internet traffic to meet increasing demand for those services.

Under a two-tier Internet system, the phone companies would be under pressure to provide an even higher-quality of service because paying for premium access would demand more than a "best efforts" guarantee. Cable and phone companies have already started offering multitiered pricing of broadband for consumers. And some cable companies have looked into ways of curtailing individual broadband customers from using too much bandwidth.

What surprises me is the immediate and loud complaints about the telco ISPs "locking out" small or new Internet services. Not so. Internet 1 -- the 'Net since inception to date -- has absolutley no quality of service built in. That's one reason why Internet realtime video, even with broadband, has been problematic -- the packets don't flow one after the other like data does on a dedicated phone line. Internet 2, as implemented in IP SEC v2, supports the ability of network providers to offer quality of service that will quickly drive video, teleconferencing, and other realtime demands over the 'Net.

You'll pay for that superior service if you want it. Hey, standard FedEx is two days. You pay extra to have it there tomorrow before 10am. Right? Why shouldn't the ISPs get paid for providing higher service levels at the buyer's option? Akamai, for instance, has built an entire business around this premise. If you don't want the better services, you don;t have to pay for it -- although the "free" Internet is apt to get slower and more choked over time.

So, I take the griping from those who want something for nothing with a grain of salt. If you want a better, high-bandwidth Internet experience, let me be the first to say "it's gonna cost you."

Microsoft Security Bulletin MS06-001: Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution (912919)

Here is a web site from Microsoft with all of the downloads for the WMF fixes. This web site had a fix for each OS.
Joe

Gadgets � Network your electric wires

This is our first CES report!! So.... here's a compendium of links about CES, to make up for the shortage ;)
The link in the title goes to a "Panasonic BL-PA100 HD-PLC Ethernet you can instantly create a high bandwidth network in your home. The adapter simply uses your existing electric wires to transfer data at up to 190MBps."
Technorati tag: CES
Techmemorandum: Google link to tech.memeorandum, cause google's blog search AT tech.memeorandum doesn't show any results....( As usual)
IceRocket: Today's Links for CES. Past week result didn't show anything, on Thursday
Engadget is doing a wonderful job, too!
Gizmodo has lots of pictures!
Digg.com links here [Digg spy is cool,too, it scrolls everything as its entered, and can be filtered by comments or front page]

ENJOY!

--MissM
P.S. As I was editing the posts, I went to the web pages, but, as I scroll through my voluminous RSS list, the content seems enhanced, pictures in engadgets feed, to be specific. I say BRAVO to this!! Any website that addresses those of us, who use RSS 75% of the time to read websites, gets my subscription ;) And if the content is better, woohoooooo! A necessary requirement, of course, is that the title goes to the home page of the feed (which may be wrong in almost 25% of my feeds)!!

Thursday, January 05, 2006

WMF Official Microsoft Patch

It arrived via automatic download sometime this afternoon. I was away from my computer and when I returned there was the little yellow shield icon in my system tray telling me that an update from Microsoft had arrived. The information I have says that it was released at 2 pm EST. It looks like I got it automatically about three hours after that -- about 2 pm PST. If you haven't yet, uninstall the hexblog WMF vunerability patch if you installed it. Everyone needs to install the official patch from Microsoft. I just did that and it went smoothly.

Microsoft's WMF Patch Leaks Out

Things just keep getting flakier and flakier with the WMF vulnerability.

The reason for posting this one is not that the patch leaked out, but that it confirms the patch as it exists now works seamlessly with the unofficial patch.

Jack

Wednesday, January 04, 2006

Got one of these for Christmas

It's a USB powered "Lava" lamp. Thought it was to say the least interesting. LOL

Tuesday, January 03, 2006

Click Here to Save on Dell

This nice site tracks Dell's everchanging list of deals, and gives you the super-secret coupon codes that save you big dollars at checkout.

If you are buying a Dell, I would certainly check out the site.

Apocalypse Near: U.S. Outsources Pleasure

Hey, we can have a long discussion on the relevant merits or demerits of outsourcing manufacturing to China. But what caught my eye is this International Herald Tribune article. Seems U.S. gamers are outsourcing pleasure. Call it gamers skipping the foreplay, if you will.

By allowing Chinese gamers to play endless hours at lower game levels, rich, time-challenged players can buy with real cash the accumulated wealth and power of the Chinese-made game avatars.

The obvious outcome in this capitalistic world is simple to deduce: game companies will split their products into multiple skill levels, at dramatically increasing prices. That locks out the Chinese-slave game labor and moves the profits to the IP producers. Want to jump in at level 50? That will be $500 plus the $50 normal game price.

The obvious question is whatever happened to hard work and perseverance?

Sony coughs up for rootkit disaster

The title is misleading, to say the least.

Sony is getting off here without any real compensation to those who have had to scrape and reinstall machines ro rid themselves of this scourge!

Businesses I know of who were infected were left with no choice but the "nuclear option" in order to make sure their customer's, client's or patient's information was safe. They could not wait for patche. They certainly will not be compensated by $7.50 payments and freebie downloads.

I'll wager the lawyers got their fees while selling us out.

Jack

NOD32 Stops WMF Malware

AV-Test, which tests anti-malware products, has been tracking the situation closely and has, so far, analyzed 73 variants of malicious WMF files. NOD32, the anti-virus software recommended by and sold by the OnComputers.info team that produces this blog, passes the WMF tests for all 73 variants, and is one of several AV products that you can trust with the WMF problem.

'Nuf said.

Sunbelt BLOG: Workarounds for the WMF exploit

I received this link from the president of SunBelt software Alex Eckelberry. Alex points out that the temporary fix does NOT work on Windows 9X, their only workaround is probably to unregister shimgvw.dll, it's in their blog.
This is very important so please if you are the family geek, tell your family to do this workaround until Microsoft comes out with a patch.
Remember this fix must be uninstalled before you apply the Microsoft patch.

Comments, Please

I really don't know how to take Microsoft's response(s) to the recent .WMF vulnerability flap. I'm soliciting comments from everyone on this.

While Microsoft readily acknowledged the existence of the vulnerability, they steadfastly clung to the position that user interaction was necessary to exploit them long after it was known that is not true.

Today, 3 January, they announced they have a patch completed, but will not release it until 10 January, which is their regularly scheduled "patch day". While I realize that they have to test any patch thoroughly, it seems to me they should be expediting this at any and all costs and release it sooner, if humanly possible.

After all; millions upon millions of PCs are at risk, here. The distribution of the exploits related to this vulnerability are widely spread. It's not just dodgy web sites. They're arriving in emails and have been slipped onto more reputable sites that have been compromised. In my opinion, Microsoft simply cannot continue to treat this casually and act as if users will be at fault because of their surfing habits.

What do you think?
Jack

Microsoft to Release Patch for .WMF Vulnerabilities 10 January

You'll have to decide whether or not you want to wait for the official patch or install the unofficial one. Personally, I've gone with the unofficial one on all the machines I can reach, at the same time disabling automatic updates until the official patch is available. That way, I can uninstall the unofficial one before it has a chance to conflict with the official one.

Jack

The Google PC?

Okay. I haven't yet found anything even resembling confirmation for this. However, if it is true, battle is joined for real between Google and Microsoft.

Jack

Microsoft's Advisory on the .WMF Vulnerability

I thought you might want to see this. It's MS' take on the WMF vulnerability.

Either this was published before the full extent of the problem was known or Microsoft is intent on minimizing the impression of danger. (The former is more likely than the latter.) They are insistent that user interaction is a requirement for an exploit to be successful. This is now known to be untrue. An indexing program, such as a desktop search utility (ala Google's) can trigger the exploit. In my own tests, here, I triggered two of the known exploits by using a third-party thumnail generator, as well.

The Internet Storm Center at SANS has an FAQ on the problem. Note that IE users are at more risk than FireFox users, but only just. Almost everyone is vulnerable.

All we can do is to install the unofficial patch and wait for Microsoft to act decisively.

Jack

Monday, January 02, 2006

Stores hope tech advice will mean fewer returns - The Boston Globe

This seems like a great idea.

I'd be more concerned that if someone needs training on how to use a mp3 player, maybe thats the wrong gift to get?

Sunday, January 01, 2006

New Year's Superstitions

Here is a little fun from Snopes.com. It is my favorite site where myst is de-mystified and bunk is debunked. Happy New Year everyone!

OnComputers Radio show Podcast 01-01-06

This is the On Computers Radio show podcast for 01-01-06. If you prefer, you can download the same file here via ftp.

An E-mail to send your friends today about the WMF 0 Day Exploit

You can cut-n-paste this and send it to your friends and relatives that may need your help.

***

Dear Friends,

You know that I don't often send warnings like this, but there is a serious problem on the Internet that impacts versions of Windows -- everything 98 and newer including a fully updated Windows XP with Service Pack 2. Your computer can get infected with this bad stuff just by looking at a picture on the Internet or in e-mail. I know this almost sounds like so many hoaxes in the past, but I can assure you it is not.

This was fully discussed in the first hour of the January 1, 2006, On Computers show which is podcast on http://oncomputerstips.blogspot.com

You can also download the show at http://www.oncomputers.info/archivehome.shtml

Please download and run this patch from Sans (a very reputable Internet site):

http://handlers.sans.org/tliston/wmffix_hexblog13.exe

It installs like a normal Windows program. You will need to restart your computer after you install it.

When the official Microsoft fix arrives you can uninstall this patch as a normal program and install the official Microsoft patch.

If you need more help, please contact me. I'm here if you need additional help.

Your Friend,

P.S. If you are up to some techincal reading, here is a complete FAQ. at the Sans Internet storm center

http://isc.sans.org/diary.php?storyid=994

Right now, I consider isc.sans.org to be the best source of information on this exploit.

(this story was edited and updated at 22:26 UTC)

I'm curious about this....







If you can post to the blog, do you actually READ it?
Yes
No
Read, what's that???
I promise to check it before I post.


  

Free polls from Pollhost.com

SANS- 2nd generation WMF 0day exploit Spammed

As the WMF saga continues, SANS is really on top of it, they worked with a programmer to come up with a patch to protect you from the WMF exploit. In addition to the info in Joe's post below, they recommend you install the (a direct link to the exe file that contains the patch AND unregister the dll. There is also a discussion about how to protect your company from the WMF exploits, from most extreme (not use windows!?!?!?! to Disallow email, or strip all attachments from the more secure email server they get access to.)

Is this a precursor of Security threats in 2006????
Be Safe!

--MissM

Happy New Year!!

Happy New Year! Oh yeah, if you are a bit hungover this morning, you might wanna make sure your volume is down, before you countdown ;)

May 2006 be a WONDERFUL year for everybody!!
(Link taken from Ponzi's blog (She's engaged to Chris Pirillo of Lockergnome.com fame, amother others)

--MissM

Saturday, December 31, 2005

Lavalys - Comprehensive IT Security and Management

What a bummer they quit Everest home version! :(

Blogger: Browser Cookies Disabled

Blogger: Browser Cookies Disabled
Why do I get this error when I try to log into blogspot.com but can get in if I use the Blogger button on the Google toolbar?

ANY ATTEMPT TO DISPLAY A MALICIOUS IMAGE IN WINDOWS

Security Now! Notes for Episode #20: "regsvr32 -u shimgvw.dll" This is from Steve Gibson from www.GRC.com
This fix is temporary, until Microsoft comes out with a patch Steve has an undo for it if it breaks anything.
To immediately disable the vulnerable Windows component:

Logon as a user with full administrative rights.

Click the Windows "Start" button and select "Run..."

Enter the following string into the "Open" field:



regsvr32 -u shimgvw.dll

(You can copy/paste from this page using Ctrl-C/Ctrl-V)

Click "OK" to unregister the vulnerable DLL.

If all goes well, you will receive a confirmation prompt, and your system is now safe. No need to reboot, but you might want to just to be sure that any possible currently loaded instance is flushed out.

Friday, December 30, 2005

'Intel Inside' sent to the place where brands go to die

So how does "Leap Ahead" grab you?

I knew that it would, lol.

As an AMD only household here I won't have to change my case badges ;-)

Wednesday, December 28, 2005

Windows zero day nightmare exploited

Image handling flaws can infect Windows machines, including XP SP2, when visiting maliciously constructed web sites. This does not just affect Internet Explorer users. Firefox users are apparently vulnerable as well.

More information is available at F-Secure here. This one will garner a LOT of attention in nearly every corner of the web.

Watch Microsoft closely for a patch.

Jack

Tuesday, December 27, 2005

Schneier on Security: Internet Explorer Sucks

"This study is from August, but I missed it. The researchers tracked three browsers (MSIE, Firefox, Opera) in 2004 and counted which days they were 'known unsafe.' Their definition of 'known unsafe': a remotely exploitable security vulnerability had been publicly announced and no patch was yet available.

MSIE was 98% unsafe. There were only 7 days in 2004 without an unpatched publicly disclosed security hole.

Firefox was 15% unsafe. There were 56 days with an unpatched publicly disclosed security hole. 30 of those days were a Mac hole that only affected Mac users. Windows Firefox was 7% unsafe."
Mr. Schneier continues....
"This underestimates the risk, because it doesn't count vulnerabilities known to the bad guys but not publicly disclosed (and it's foolish to think that such things don't exist). So the "98% unsafe" figure for MSIE is generous, and the situation might be even worse.

Wow."

Why is ANYbody using IE still? Get Firefox!

--MissM

Monday, December 26, 2005

Open Source and Your Legal Rights

A court fight in Florida over the software used in the instruments that detect alcohol in breath could threaten the ability of states and localities to prosecute drunk drivers.

The battle is over the source code of breath analyzers made by CMI Group, a closely held maker of breath-alcohol instruments. Defense lawyers have challenged the use of the device and asked to see the original source code that serves as its computer brain, saying their clients have the right to examine the machine that brings evidence against them.
Last February, a state appeals court in Daytona Beach ruled that Florida had to produce "full information" about the test that establishes the blood-alcohol level of people accused of driving under the influence, or DUI. Otherwise, the court said, the evidence is inadmissible.
"It seems to us that one should not have privileges and freedom jeopardized by the results of a mystical machine that is immune from discovery," the state's Fifth District Court of Appeal wrote.


A court in Seminole County later interpreted the ruling to apply to CMI's source code. As a result, at least 1,000 breath tests have been thrown out of court in the county this year. Last month, a court in Sarasota County said the breath tests used in 156 DUI cases will have to be thrown out if CMI continues to refuse to hand over the source code.
CMI, which is based in Owensboro, Ky., has refused to turn over the code for its Intoxilyzer 5000, saying it is proprietary. "It's a trade secret, and like any company they don't just turn over information for the asking," says Allen Holbrooke, outside attorney for CMI. [WSJ 12-16-2005]


As I see it, this is a huge, broad issue that has been creeping inexorably onto the radar screen: since the constitution grants defendants the right to challenge the evidence against them, it should come as no surprise that DUI defendants -- or rather, the defendant's lawyer -- are going after the technology that nailed them. Since most test and measurement equipment (TME) today has a programmed computer in its bowels, the defendants want to double-check the code of the all-too-human programmer. "Opening the source", as it were.

Now, those country-boy lawyers are no dumbies. They realize that any self-respecting TME manufacturer would want to protect its source code -- especially as open-source Linux replaces proprietary TME operating systems and programming languages. It has become too easy to lift source code from online court documents right into a compiler. So, the lawyers are trying to bluff an acquittal by asserting TME source code evidence as critical to their cases. "Uh, my client is innocent by reason of programming error." In the past, the TME device was treated as a "black box"; it could be externally tested but its entrails could not be dissected. To test a radar gun, for instance, you drive a car with a calibrated speedometer at the radar gun and then trigger a speed measurement. How the gun got the measurement internally is less relevant when the external results match the experimental. Apparently, the law is heading down a different track with programmable TME.

So, besides DUI, look for more creative legal tactics regarding voting machines, ATM fraud, automobile insurance cases -- did you know automobiles now tell police and insurance investigators how fast you were going when the car went off the road? -- medical devices and many other instances. Thousands of legal hours worth. It will be interesting to see how defendants rights are (re)balanced against property rights.

Sunday, December 25, 2005

OnComputers Radio show Podcast 12-25-05

This is the On Computers Radio show podcast for 12-25-2005. If you prefer, you can download the same file here via ftp.

Alex Bosworth's Weblog: Dynamics of Digg

I found this article interesting. I believe that it is a glimpse inside what I believe Web 2.0 really is, and that is "Attention," although there are many terms for this now. Everybody is trying to monetize the eyes that are drawn to a site. And I believe that most diggers are what could be considered "early adopters," those who use RSS, podcasts without Itunes, fill in your own "geeky edge" :).

» Digging into the Digg System | Web 2.0 Explorer: "Digging into the Digg System
Posted by Richard MacManus @ 6:43 pm

Alex Bosworth has a great post investigating the dynamics of the digg.com system. He discovered that the system is 'very simple' and made up of five groups of people:

1. Readers: Alex guesstimates that 'ten to twenty percent of those ever click 'digg''. I'd love to know the actual figure though.

2. Diggers: 10-20% says Alex. He also says these are the least important members of the system, because 'once a link is on the front page, it makes marginal difference the number of votes next to the link.'

3. Hardcore Diggers: 'people who sit in the queue of submitted stories and watch for breaking news that should make its way up to the front page, or report stories as being spam or irrelevant.'

4. Submitters: people who submit stories. It's highly competitive and difficult to be the first to post a successful story (one that makes the front page).

5. Publishers: 'often bloggers who want to get readership for their content.'"

--MissM
P.S. in order to give attribution to the source of the link, I used a new extension I found for Firefox 1.5, its called How'd I get here? and once put on your toolbar, it will trace back the path to the original site to the page one is looking at.
Clicking back one more time, the original link came from digg.com ;)

Xbox 360: Back to the Drawing Board

Though this FiringSquad.com article really takes the XBox 360 team to task, it is still constructive criticism. I have disagreements with a few small details, but only a few. It's worth a read.

XBos 360 is a perfect example of how a company gets painted into a corner by a release date and doesn't have time to work everything out well enough. It's a common problem, and not just at Microsoft. Still, I like the product, which surprises me greatly. I expected it to be just another console, which it definitely is not.

Jack

Migration Software

This looks good. Whether or not it is will take some time and a long look at a bulk licensing agreement.

It's softare to automate the transition from various Microsoft products to Linux. Handles the desktop, Exchange to Linux based apps and a whole lot more.

I've sometimes wondered why this hasn't been done before. A series of products like this could ease the transition to Linux to the point where the expense becomes acceptable. Yes, you save money using Linux. Everyone knows that. But the costs of conversion could easily double one's IT budget for the year, which is a powerful deterrent. It will take a good while to amortize the expense of conversion and begin realizing the savings. If this software can cut the price and problems of conversion to a significant degree, it could sell a lot of enterprises on the conversion.

Jack