Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Thursday, March 19, 2009

IE Eight Released Today

Microsoft Explorer 8 was released today. Are you going to use it? Let me know. I don't think I'm going to use it, I gave up on Microsoft products awhile ago,Firefox and Safari do everything I want them to do without any of the hassles.


Digg!

Tuesday, May 20, 2008

Microsoft, HP ready XP SP3 endless-reboot patches Help is ON the way for The Endless Reboot Monster

Well it looks like help might be on the way for those of us that got hit by The Endless Reboot Monster that owners of HP Computers with AMD chipsets were having.

Help is on its way for users affected by the Windows XP Service Pack (SP) 3 endless-reboot problem that has plagued some users for the past week-plus.

Both Microsoft and Hewlett-Packard are readying patches that should remedy the glitch, which seems to affect primarily users of AMD-based systems.

Microsoft blamed OEMs who improperly placed a Windows XP image created for Intel-based machine on non-Intel-based systems.

HP is advising users running XP on AMD-based systems to delay deploying SP3 until the company releases a patch, which sounds like it is due out this week or next at the latest. From a May 15 report in Computerworld:

“HP is working diligently with Microsoft on a software update and will be proactively distributing a patch this week through HP Update that will prevent this error from occurring….The patch will be posted to this page of HP’s support site when it’s available.

“Microsoft is also developing a prerequisite fix that must be downloaded before SP3 will automatically install prior to its proactive distribution of SP3,” HP statement added.”

Digg!

Monday, May 19, 2008

MICROSOFT Blames Users For security Holes

MICROSOFT Blames Users For security Holes

Well well well, This goes down as one of the cutest excuses of the year award. Microsoft says "The number of virus infections found by a virus vendor does not necessarily equal poor security," wrote Kleef in a blog post. "In many cases it equals poor user behavior. If I, despite all prompting and consent behavior, choose to go to a (probably dodgy) website, accept the ActiveX control prompts to download (probably dodgy) code and I actually choose to execute that code then I'm hosed."

Well is that not convenient as the church lady would say from Saturday night live, Hmmm Maybe Satan made you you do it? When I write I try and think of things from the point of view of the average user, as thats what I am. I'm not a techy, and I'm most definitely not a computer software developer, but this sure as hell sounds to me like the hopelessly useless account user interface on Vista is being used as a way to blame user's for Window's flawed code.

I would like to ask Microsoft how many user's can tell what is a good active X control and what is dodgy? I know I can't, but I do know many websites have them and I can tell you when I say yes using Microsoft's account control it give's me no useful information whatsoever to tell me if it's dodgy or not, it just let's me know something is going on, but I have no idea if thats a normal process or not. Microsoft stop blaming the customer. I want to know what do you think? Is Microsoft right is the User to Blame?

Microsoft has claimed user "complacency" is to blame for malware infections, and denied that its Vista operating system is less secure than Windows 2000.

The claim that Vista is less secure than Windows 2000 was made last week by security vendor PC Tools, which said that over the past six months Vista had suffered 639 unique threats, whereas Windows 2000 has suffered 586. PC Tools's research was conducted by collecting data from customers using its ThreatFire behavioral detection software.


"Ironically, the new operating system has been hailed by Microsoft as the most secure version of Windows to date," said Simon Clausen, the chief executive of PC Tools last week.


"However, recent research conducted with statistics from over 1.4 million computers within the ThreatFire community has shown that Windows Vista is more susceptible to malware than the eight-year-old Windows 2000 operating system, and only 37 percent more secure than Windows XP," Clausen said.


However, Microsoft strongly hit back at the claims, blaming users for executing malicious code on their machines. On Tuesday, Technet blogger and Microsoft evangelist Michael Kleef said the number of infections found by PC Tools was an indication of poor user behavior.


"The number of virus infections found by a virus vendor does not necessarily equal poor security," wrote Kleef in a blog post. "In many cases it equals poor user behavior. If I, despite all prompting and consent behavior, choose to go to a (probably dodgy) website, accept the ActiveX control prompts to download (probably dodgy) code and I actually choose to execute that code then I'm hosed."


Kleef claimed the number of infections was not purely the operating system's fault, but said that "in some cases it's the user and their lack of knowledge and their implicit 'it-won't-happen-to-me' complacency" that causes them to get infected.


Kleef's comments followed on from a blog post on Friday by Austin Wilson, the director of Windows Client Security Product Management, which also denied that Vista was less secure than Windows 2000. Wilson said results collected from over 450 million uses of Microsoft's Malicious Software Removal Tool (MSRT) and published in Microsoft's most recent Security Intelligence Report show Vista is more secure than Windows 2000.


"Our results published in the April 2008 version of the Security Intelligence Report show that Windows Vista is significantly less susceptible to malware than older operating systems," wrote Wilson in the blog post. "Using proportionate numbers, MSRT found and cleaned malware from 44 percent fewer Windows Vista-based computers than Windows 2000 SP4 computers and 77 percent fewer than from computers running Windows 2000 SP3."


Digg!

Friday, May 16, 2008

Microsoft XP SP 3 The Reboot Monster

I'm not a High tech person, I'm pretty simple really and not very demanding all I want is for something to work properly. I tried installing SP 3 on My AMD machine. I read all the paperwork on known issues and thought I was safe, needless to say I was not.

I ended up getting the endless reboot monster. I was lucky though I was able to get into a safe mode where I could do a restore some people are not even able to do that! Now I'm spending hours fixing everything reinstalling security fixes and that does not even cover my losses.

I'm sick and tired of Microsoft putting out things that break your computer at what point should they be held financially liable? My thoughts are the only time we are going to see them take responsibility is when it Hurts their pocket book.

I'm going to take a wait and see approach though, as I know Microsoft is Blaming HP for using an alleged disk image that was only to be used for Intel machines, but I think Hp is saying Microsoft put in an unnecessary driver that is causing the crashes either way I'm one ticked off customer. I also don't think this is an isolated event please take the time to report your problems with Microsofts XP SP 3 here. You will also find some links below to some helpful info.

Jespers Blog

Steps to take before you install Windows XP Service Pack 3

Digg!

Sunday, March 09, 2008

Is your Xbox 360 still working? You must be one of the lucky ones.

Is your Xbox 360 still working? You must be one of the lucky ones. This is a very interesting article about the Xbox 360 failure rate it makes for an interesting read. Let Me know what you think.

Over 18 million Xbox 360s have sold through since the console's launch in November 2005, but just how many of those are still working? Squaretrade, a company that specializes in providing warranty support to purchasers of electronic goods from various manufacturers, claims 16% of Xbox 360s experience a hardware failure within six to ten months after a warranty purchase. Three out of every five failures were for the infamous "Red Ring of Death" general hardware failure error, a problem often linked to overheating.

The Xbox's figures compare poorly to competing consoles, which have a failure rate of around 3% -- and if anything, the Squaretrade figure underestimates the scale of the Xbox 360's reliability issues. It's a good bet that some buyers of Squaretrade warranties went straight to Microsoft after experiencing hardware issues and don't factor into the 16% number. On its company blog, Squaretrade pointed out that failure rates are "certain to go up" as the machines in their study group grow older.

Microsoft is cagey about coughing up official failure rate figures, which has lead some commentators to speculate about the actual severity of the problem. Luke Plunkett, a blogger on respected games news site Kotaku, said in a recent post that if the real failure rate wasn't in the 30-40% range, he'd "wolf down humble pie until his sides split."
Plunkett's sides are likely safe. Stories of 360 owners making their way through eight or nine consoles aren't hard to find, but to its credit, Microsoft has been working with the affected individual in at least one of those cases to lessen the impact of the constant failures.

16 Percent of Xbox 360s Are Likely to Break, Report Claims Even so, there's a surprise lurking for consumers who return their 360s for repair. When you purchase content -- arcade games, extra tracks, etc. -- over Xbox Live, it's playable by any user on the console you used to make the transaction. If you go to a different console and sign in with your gamertag, you can download the content and play it only for as long as you're signed in. Once you move back to your main machine, it will no longer be playable. Sounds like a handy system to let you take the content you own from place to place, right? But the trick with this system is that once a broken machine returns from its little vacation, it generally has sufficient internal changes to make it look, to Xbox Live, like a different console. So all your downloaded content -- which, if you're a heavy user, could amount to hundreds of dollars worth of purchases -- are only accessible to one gamertag, and only when the console has a live internet connection.

Getting this situation resolved can be difficult. Affected users have reported having to make repeated calls to the Xbox support line, often to no avail. Some fortunate individuals were able to eventually convince the MS reps to refund all the points they'd spent so they could repurchase all the affected content, although they had to do it using a different gamertag.

How to Avoid Hardware Problems

Air it out. Many failures are attributed to the inadequate cooling system of early-model 360s, so anything you can do to give it an easier time will pay off. Make sure you put the console in a place with cool, steady airflow.
Move it and lose it. Don't change the orientation of the console when it's running. The DVD drive's running gear isn't as well secured as it could be, so knocking over a vertically-standing console can cause the machinery to collide with the disc surface. Characteristic circular scratches are the result and are generally fatal for the game.

Think new. Thanks to a well-publicized cooling system redesign, newer machines are less likely to suffer problems. Any console bought in the last six months or so should have much better chances of surviving.

Red Ring of Death: What to do

Is it a "real" red ring of death? Somewhat confusingly, the true red ring error only has three of the four quarters of the ring illuminated. If all four are lit up, you have a much simpler problem: your A/V cable is loose!
Enterprising 360 owners have discovered a homebrewed way to fix the problem, although it only works for a short period of time. It involves turning on your console, wrapping it tightly in a towel, and leaving it on for 20-25 minutes. This might void your warranty from Microsoft, so consider yourself warned.

If all else fails, hit up the Xbox web site to request a warranty repair. They'll send you a cardboard "coffin" for you to return your console and send back a fixed machine in a few weeks. The official warranty was extended to three years for this specific problem, so even launch-day 360s are technically still covered.


Digg!

Sunday, February 24, 2008

Microsoft pulls plug on HD DVD players

Well it looks like Sony won, HD DVD seems to be dead.

Microsoft Corp. said it will stop making HD DVD players for its Xbox 360 video game system after Toshiba Corp. ceded the high-definition video format battle to Sony Corp.'s Blu-ray.

Microsoft said Saturday it would continue to provide standard warranty support for its HD DVD players. Toshiba President Atsutoshi Nishida last week estimated about 300,000 people own the Microsoft video player, sold as a separate $130 add-on for the Xbox 360.

"HD DVD is one of the several ways we offer a high definition experience to consumers and we will continue to give consumers the choice to enjoy digital distribution of high definition movies and TV shows directly to their living room, along with playback of the DVD movies they already own," Blair Westlake, a corporate vice president of Microsoft's media and entertainment group, said in a written statement.

Microsoft was one of HD DVD's main backers, along with Intel Corp. and Japanese electronics maker NEC Corp., and its support for the format was seen as a big win for Toshiba's format.

But support for the HD DVD waned as major movie studios — Sony Pictures, Walt Disney Co., News Corp.'s Twentieth Century Fox and Warner Bros. Entertainment — picked Blu-ray to distribute high-def DVDs. Wal-Mart Stores Inc. struck what seemed to be the final blow just over a week ago when it said it would only sell Blu-ray players and discs.

Microsoft said it is looking at how the HD DVD technology it has developed, such as HDi, which adds interactive features to HD DVDs, and its VC-1 video encoding technology, can be applied to other platforms.

The Redmond-based software maker said the decision to stop selling HD DVD players won't have a material impact on its video game business.

Digg!

Thursday, October 25, 2007

Microsoft addresses new reports of forced Windows updates and reboots

This seems to be an ongoing story that keeps changing as Microsoft seems to be trying to spin it it, maybe I'm just dense, but what part of no does Microsoft not understand? To make it plain and simple no means no and whatever way Microsoft wants to spin it people still have the right to choose what they want updated or not updated. Microsoft can spin it any way they want, either way they have broken peoples trust, and I think most people will see that. Microsoft spin away, how stupid do you really think people are?

Microsoft has posted a long and complex explanation to its Windows Software Update Services (WSUS) blog, explaining the latest case of why software updates are being pushed to users who believe they've turned automatic updating off. Here's the abridged version of what the Redmondians said.

read more | digg story

Saturday, May 12, 2007

Vista Day One

I thought it might be interesting to give some updates about the trials and tribulations of using Vista.

This is day one, so far I have spent way too much time removing crapware on top of that you have the constant barrage of yes or no's being asked to run or not run a program.

This in my opinion is a crock of you no what, so that Microsoft can claim they are concerned about security, as these messages do not give you any useful information and for the lay person creates a condition of a person just saying yes without really knowing what they are saying yes to just to get the system to work.

It also creates for Microsoft Vista a tech support excuse of Hey you caused the problem not us, you clicked yes! as opposed to saying hey we created a system that has legacy code and still has poor security, using Vista feels all most like it's running on top of XP so far it just does not feel right.

Also Vista is a RAM Hog Computers are being shipped with the bare minimum needed to run each flavour of Vista, I'm running the premium flavour with one gig of Ram, it's not enough in my opinion you need at least Two gigs and for things to get back to a XP like speed you need Three GiGs and a good graphics card if you want anything near average performace in the real world.

Needless to say I'm not impressed, maybe in time I will change my mind, but so far Vista is all flash and hype with no substance stay away from it at all costs. That's my opinion, let me know what you think? Do you Like Vista or do you hate it?

Wednesday, March 28, 2007

Microsoft unveils enhanced Xbox 360 Elite

Well this is a very interesting article, it could really give Sony some Trouble with market share, and I really like this idea Internet Protocol-based TV (IPTV), as it could open the doors for a lot of media gaining access to people.

One Thing I know for sure it will be fun to watch what happens, it looks like Microsoft and Sony are heading towards a good fight, and the consumer I think is going to be the winner.

Let me know what you think, will it be Sony or Microsoft that wins the console battle?


Microsoft Corp. on Wednesday took the wraps off of the Xbox 360 Elite, confirming weeks of intense speculation that it would release a new version of its flagship video game console.

The upgraded machine is to launch April 29 in the United States, sporting features not found on the two existing versions of the console, including a 120 gigabyte hard drive, high-definition media interface (HDMI) port and cable, and a black finish instead of the white one on current versions, Microsoft said. It will not include a high-definition HD-DVD hard drive.

The package will also come with a black wireless controller and headset, and sell for about $480 US.

Canada will be included in the initial launch period according to a report in the San Jose Mercury News, but specific dates and pricing were not immediately available.

"Today's games and entertainment enthusiast has an insatiable appetite for digital high-definition content," Peter Moore, corporate vice president for Microsoft's interactive entertainment division said in a written statement. "Xbox 360 Elite's larger hard drive and premium accessories will allow our community to enjoy all that the next generation of entertainment has to offer."

Speculation rampant for weeks
Rumours and photos of the new model have been spurring heavy speculation on internet video game and gadget discussion forums for weeks but Microsoft would not offer direct comment.

"It is our standard policy to not comment on speculation," Jeremy Bartram, a spokesman with Microsoft's public relations agency in Seattle, told CBC News Online when asked for official comment on the rumours. "Microsoft has not announced anything regarding a new Xbox 360."

Microsoft's Canadian spokespeople made a similar statement in response to CBC's inquiries.

Photos of the console and advertising for its 120 GB hard drive had surfaced on the internet in recent days. One set of images on a Chinese-language website depicted units of the new console coming off an assembly line in a Chinese factory. An image published on the Xbox 360 Fanboy website on Monday is apparently a shot of a poster promoting the new hard drive.

Microsoft targeting Sony: experts
The refreshed console is a significant improvement on the existing versions, and surpasses rival Sony Computer Entertainment Inc.'s PlayStation 3 console on some features, according to observers who spoke to CBC News Online.

The current Xbox 360, moulded in white plastic, comes in two versions. The Premium version includes a 20 GB hard drive but no HDMI connector and retails in Canada for about $500. A lower-priced Core version sells without the hard drive and several accessories for about $400.

Sony sells two versions of its PlayStation 3 console, both of which include a high-definition Blu-Ray DVD drive built-in. The premium version of the console, which has a 60 GB hard drive, sells for about $660 in Canada, while a version with a 20 GB hard drive is priced at about $550. Neither includes an HDMI connector cable.

"A 120 [GB] hard drive versus 60 [GB] on the PS3 sounds like penis envy on the part of Microsoft," Michael Pachter, director of research at Wedbush Morgan Securities in Los Angeles, Calif., said ahead of Wednesday's announcement.

Analysts divided
Ruminations about whether the new Xbox unit would come with a HDMI connector cable were clarified by the announcement.

"One thing I'm pretty confident is wrong [about the reports] is that it includes a HDMI cable," he said, explaining he had recently bought one for $300 US. "It's frickin' expensive, which is why the PS3 doesn't come with one, and Microsoft doesn't have the buying power to make it cheap."

Eddie Chan, an analyst with market research firm IDC Canada, disagreed.

"The HDMI cable is a non-issue in my books," he said, explaining that bridging the gap between an analog signal and a superior digital signal is a logical step.

The price is just a function of how "clean" a signal you want, and most people are not going to shell out for a top-quality cable that has low electrical resistance (and therefore a better signal) for what they may see as a marginal improvement on picture quality, he explained.

"Sure, you can pay $300 for a Monster [brand cable] and lower-priced cables have more resistance, but you can get one for cheap — $10 or $20," Chan said.

Device sets stage for IPTV
"It would not surprise me to see a new console come to fruition," he added, noting that Microsoft has been talking about Internet Protocol-based TV (IPTV), which would use internet technology to stream a video signal across a data network such as Microsoft's Xbox Live. "It's probably a good segue in preparation for those rollouts."

In a keynote address at the Consumer Electronics Show in Las Vegas in January, Microsoft founder Bill Gates and Robbie Bach, president of the entertainment and devices division, made remarks that some say hinted at the new console.

"I can play the best next-generation games, download movies and TV shows, connect to my Windows PC, and access my music and my photos, watch HD-DVDs, and now experience next-generation TV programs with IPTV," or Internet Protocol TV, Bach said. "This is everything I want, it's all in one box, it's all on Xbox 360."

"It's pretty self-evident what the strategy is," Sam Punnett, president of Toronto-based FAD Research Inc., said about Microsoft's approach. "It's reminiscent of the walled garden idea — they have a sufficient claim to a captive audience that they can create an environment to sell content."

Punnett, who has been a consultant to federal and provincial governments on developing strategies that would foster new media and video game industries in Canada, noted that Microsoft has a unique advantage over competitors.

"They have that channel into the living room that no one else has," he said. "They can take that captive audience and branch it off … and expand into music services, streaming video. It's one of those [Holy] Grail dreams of the games industry."

Thursday, March 22, 2007

The Gozi Strikes Back ( Russian Gozi Trojan powering massive ID-theft ring)

I have just taken two points from the article below "Users state-of-the-art, modularized Trojan code" " Launch attacks through Internet Explorer browser exploits"

Now if you read The article it's rather scary, that all that information was being gathered and put up for sale and even might still be up. When is Microsoft going to take security seriously?

Even with Vista that was delayed a year, has bugs up the gazooo, one reason why a lot of Business are reluctant to jump on board.

My advice stay with XP and try and make sure you can be as secure as you can be. Remember though, even then you could still be prone to attacks as long as Windows chooses to make security a lower priority. Let me know what you think? Are you tired of this? What Should Microsoft Do?


Russian (Gozi) Trojan powering massive ID-theft ring by ZDNet's Ryan Naraine -- Researchers at SecureWorks have stumbled upon what appears to be a massive identity theft ring using state-of-the-art Trojan code to steal confidential data from thousands of infected machines in the U.S. The Trojan, which connects to a server in Russia, has so far pilfered information from more than 5,200 home computers with 10,000 account records. The [...]

Monday, January 29, 2007

Bill Gates: Microsoft vs. Google Checkout, eBay PayPal

This could get interesting hopfully it will make things better for the end users of these sevices. I'm also wondering though, at what point would these services be cosidered a Monoply? All Comments welcome.


Bill Gates has done a lot of thinking about the online payments market.

At Microsoft’s “Think Week,” a development plan was set for an online payment system “that will be cheaper than credit card transactions, making it possible for companies to charge small fees for Web-based content and services they now offer for free,” according to Dow Jones reports.
Speaking at the Davos World Economic Forum, Gates said:
If you want to charge somebody $0.10 or $1 a month, that will just be a click…you won't have to manage some funny thing or pay some big credit charge, where half of it goes to the clearing.
By undercutting credit card fees, the Microsoft offering would enable an online newspaper to profitably charge small fees for individual articles, Gates put forth as an example.


A new universal Microsoft online micro payments system could attract the legions of independent Web publishers, blogs and small ecommerce plays, with the potential to be a significant rival to eBay’s PayPal.

Google Checkout is not a competitor to PayPal; Google invests in the Google-centric formula as part of a strategy to continually increase monetization of AdWords. Google positions Google Checkout as undercutting credit card transaction fees but in reality it pays for them on behalf of merchants. It also subsidizes the consumer transaction.

As Google is losing money on its Checkout offering, it is not sustainable as a stand alone micro payments service, or for mass distribution on the Google publisher network. Google Checkout currently has no raison d'etre without its AdWords tie-in.
Google's AdSense business could potentially be disrupted by a well thought out Microsoft micro payments offering. In lieu of monetization by content "enhanced" by Google's "Sponsored Links," Websites could monetize their own content directly.

Direct monetization would enable Web publishers to keep users at their sites, without revenue sharing with Google and without need for the ubiqutous "Ads by Goooooogle."
Microsoft vs. Google in Website monetization options could test Google's assertion that Google ads enhance third-party Website content, rather than detract from it

Friday, October 20, 2006

McAfee, Symantec and vested interests

I found this to be an interesting article, as I do find it strange they want to hide the kernel so to speak and I'm really not sure why this guy supports that. It's my opinion that having something open makes it more secure, because more people get a chance to attack it and find ways to fix it.

Is it just me or does anyone see the irony in that Microsoft has had years of lax security that helped create the industry's that help protect those breaches, now late into the game Microsoft comes out with it's Onecare product line. So you have a company that is selling something that is flawed, and now are selling you the product to fix those flaws, anyone see a conflict of interest there?

http://blogs.zdnet.com/carroll/?p=1611&tag=nl.e622

McAfee, Symantec and vested interests Posted by John Carroll @ 9:25 am
Digg This!

Vested interests often force governments to continue with policies that are counter-productive, if not downright negative. Examples aren't hard to find. Even if congress had the will to confront the vested interests that protect all the various deductions in the US tax code and create something that is clean and simple, truckloads of lobbying dollars would be spent by tax preparation companies to block the changes. Mandatory minimum sentencing laws are strongly supported by the private companies that build and maintain many of America's prisons, even as those laws swell America's prison population to levels not typically found in nominally "free" nations. Likewise, the DEA and companies that support them can be expected to fight against any attempts to stop America's futile war on drugs, a war that sends Bolivian leaders into the arms of Hugo Chavez, funds both sides in Colombia's civil war (think Al Capone times 1 million) and provides a steady stream of cash to Afghani insurgents through sale of poppies - the raw material used in heroin.

Though Symantec and McAfee lobbying the EC on behalf of their ability to hook the Windows kernel doesn't wreak as much havoc as these other vested interests, as an instance of business interests using government to warp policy in selfish directions, it falls into the same category. This smells of companies trying to preserve the flaws in a product upon which they have built their businesses. Really, does anyone in these forums WANT third parties to have access to the Windows kernel? The fact that no one does is why McAfee/Symantec aren't trying to defend the inherent value of such access and opt instead for the "futility" argument. The core of the argument is that PatchGuard won't work and that hackers will find workarounds that McAfee will have to ride in and fix for Microsoft. Essentially, there's no point in Microsoft trying to protect the kernel because they will never make it bulletproof, anyway. Following that reasoning to its logical conclusion, Microsoft shouldn't bother to alter its software development processes so as to emphasize secure coding techniques, given that perfection is impossible, and from a business standpoint, deprives Symantec and McAfee of the opportunity to protect consumers from the consequences of those flaws. As noted, I'm not seeing many in ZDNet Talkbacks rushing to defend McAfee and Symantec in their quest, probably because they DON'T WANT Symantec and McAfee to have that kind of access.

If McAfee and Symantec want to do something useful, they should build products that help to to enforce the kernel protections represented by PatchGuard. What they should NOT be doing is trying to prevent Microsoft from locking down the kernel in the first place. People really should read this blog post by Stephen Toulouse, a program manager in Microsoft's Security Technology unit, as it clarifies considerably the situation as it pertains to kernel hooking past, present and future. http://www.stepto.com/default/log/displaylog1.aspx?ID=258

Some useful excerpts…

Regarding Microsoft's past encouragement of kernel hooks: Wrong. For the implementation of the 32 bit kernel of Windows, there existed undocumented and unsupported system hooks into the kernel. Their use was frowned upon, even inside Microsoft. It's simply not a safe practice to utilize these interfaces into the kernel. Regarding the termination of support for kernel hooks being something that is "new:" Wrong.

Kernel Patch Protection was implemented almost 2 years ago in Windows XP x64 edition and Windows Server 2003 x64 edition. Regarding supposed "insecurity" resulting from a ban on kernel hooks: What security vendors are misrepresenting, is that only through unrestricted access to modify the kernel at the highest level of privilege can they protect you.Of course, the referenced blog predates Microsoft's decision to enable in some as of yet undetermined fashion a means by which to enable kernel hooking "in a secure fashion."

On that note, consider the perils of such an approach as explained at the end of Mr. Toulouse's blog. First, you grant one, pretty soon you have to grant thousands. That's how many people are out there using these undocumented, unsupported interfaces into the kernel.

Second, the more exceptions you grant, the more you dilute the protection. Attackers will simply morph their attacks to try and mimic the "safelist" to get an exception – this may be as simple as malicious software “bundling” third party software in order to disable the protection.

Third, because the OS was still designed to be run with the unmodified kernel, you still have the problem of code running at highest possible privilege crashing the system or causing performance problems.

Fourth, by granting an exception list you introduce a huge performance problem into the kernel, as you force it to check a safelist with every single operation.

Fifth, how would the logistics for adding and removing exceptions work? Would it only be done in software updates? Service Packs? Would someone sue because we weren't fast enough implementing them into a safelist?

That last issue is particularly worrisome for Microsoft, and constitutes the problem with selectively allowing people to have access to the kernel. If McAfee and Symantec get access, you can expect most security companies to want comparable access, and once that happens, the question becomes: how big do you have to be to have access? Pandora's box, truly.

Like prison construction companies encouraging policies that lock up as many people as possible (let's not call them prisoners; let's call them "customers"), McAfee and Symantec are trying to encourage an architecture that "needs" the fixes of a McAfee and Symantec. In so doing, they show how self-interest and government controls over software design collide to create "solutions" that have little to do with benefitting consumers.

Thursday, October 12, 2006

Zero Day

Here is an article about even more security flaws in XP. I really don't understand how Microsoft can come out with operating systems that are so prone to problems like this.

Microsoft releases 6 patches for flaws

October 12, 2006 - 12:16PM

Microsoft has released six patches to fix software flaws that carry its highest threat rating, including three for defects that attackers were already trying to exploit.
The company said all six of the critical flaws could allow an attacker to obtain some access to other people's computers.

The software maker also released four other patches to fix vulnerabilities that the company deemed less severe.
Customers can download all the patches for free on Microsoft's security website and also can sign up to have them automatically delivered to their computers. The automatic update system went down for several hours on Tuesday, but the problem was later resolved.
Microsoft said last month that it knew attackers were already trying to take advantage of defects in its Windows operating system, Microsoft Word software and PowerPoint presentation program.

Christopher Budd, a program manager with the Microsoft Security Resource Centre, said that the company had seen limited attacks exploiting the flaws, but were nevertheless recommending that users apply those and other patches immediately.
Such vulnerabilities are rare. In most cases, security experts quietly provide Microsoft evidence of a security flaw, allowing the company to fix the problem in secret and release a patch before attackers can take advantage of it.
But recently, the company has been hit with a number of so-called "zero-day" attacks, in which flaws are targeted before Microsoft is aware of them or can release patches.
Such attacks have prompted some security researchers to release their own interim fixes. Microsoft also has occasionally taken the unusual step of releasing patches outside of its normal monthly fix schedule, so users can be safeguarded more quickly.

Budd said Microsoft isn't seeing any specific pattern to the burst of zero-day attacks. But he said the company is seeing more focus on attackers trying to infiltrate computers through applications - such as Word or PowerPoint - rather than the Windows operating system.
Microsoft software is a constant target of internet attackers, in part because the company's products are so widely used.
Microsoft has yet to release a patch for one other publicly known flaw - one affecting the Internet Explorer browser that is part of its Windows operating system. Budd said the company was seeing very few attacks as a result of the flaw.

AP

Wednesday, September 13, 2006

MicroSoft We Share Your Pain

It's a bit old but still funny, if only they really did feel our pain.




WSYP Project:
"We Share Your Pain"




Now I am all for increasing the connection
between Microsoft's customers and the software product
teams...especially, the individual developer.




So, if you've ever wondered what happens when
you press the Send Error Report button after an application failure,
you need to watch the four minute video!






We Feel Your Pain












FlashVars="fileNumber=0&startStreaming=true&moviePath=http://www.marclirontraining.com/vids/feelpain.flv&movieLength=230&finalRedirectURL=&redirNewWindow=_self&autoplay=1" quality="high" bgcolor="#ffffff" width="330" height="290" name="movieplayer320" align="middle" allowScriptAccess="sameDomain" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" />