Posted by: kurtsh | January 4, 2006

RELEASE: Add your Gamer tag to your Blog!

XBox.com released Gamertag graphics that can be added to your blog or your web site that will dynamically change as you play more games and grow in Gamer points.
 
Wow.  Hook this cordless phone to your PC’s USB port or to a standard POTS phone line.  The phone can be used to make calls over the Internet to land lines and receive them.
Posted by: kurtsh | January 4, 2006

NEWS: 2006… the big year for Microsoft?

Windows Vista
Office 2006
Sharepoint Portal Server 2006
Infopath Server
Excel Server
XBox360
Internet Explorer 7.0
Office Live & Windows Live Services
Microsoft Antivirus, Anti-Spyware
OneCare
Windows Mobile 5.0
…
Interesting article about the dozen or so projected product and services releases coming from Microsoft this upcoming calendar year.
Posted by: kurtsh | January 4, 2006

UPDATE: Official WMF Vulnerability patch coming Jan 10th

The official Security Advisory for the WMF vulnerability is located here:
 
There are several options available on the advisory page but apparently a patch is slated for release next week.  It’s currently built and being tested internally and with certain test customers.
"Microsoft recommends that customers download and deploy the security update for the WMF vulnerability that we are targeting for release on Jan. 10, 2006"
 
 
Posted by: kurtsh | January 3, 2006

TOOL: Converting to WMA

Check this out.  A free tool to convert your media collection to Windows Media Audio.
I think I’ve mentioned this before to various people that have told me, "I use Firefox because you guys are lazy and refuse to update Internet Explorer!"
…as you can see, even our internal employees, who frankly don’t often know the whole story behind how things go at Microsoft, complain bitterly about this stuff.
 
The bottom line is that WE (as in myself and my constituents) want Internet Explorer evolved as well.  WE would like to see various changes and features implemented.  WE would love nothing more than to have IE kick ass over our competition.  But let’s be clear one important thing:  Microsoft has to deal with something regarding product development that doesn’t really hinder our competitors to the same degree… LAWSUITS.
 
Every time you think to yourself, "DAMMIT – why hasn’t Microsofti implemented feature X?  They’re just sitting on their money pile doin’ nuthin… damned monopoly!"  try remembering the following.  In order for an improvement to be made, the feature must be:
 
1) SPEED OR STABILITY RELATED
No one can accuse us to doing something bad to the market if we simply improve a product’s speed or it’s stability.  This is the reason that improvements between point-releases are so ‘speed’ and ‘stability’ related. 
 
2) SECURITY/PRIVACY RELATED
Anything that protects the public or serves the public’s best interests really can’t be argued against.  We we able to incorporate cookie blocking into Internet Explorer because even though there were a variety of cookie-blocking add-ons available for IE and Windows, the improvement was made in the best interests of our customers security and we would have a strong base to stand on against any developer of a ‘cookie-blocking’ tool that claimed, "Microsoft is killing my business by incorporating a cookie blocker!"  We couldn’t do the same thing for Pop-up Blocking for the longest time (until IE 6.02) because pop-ups aren’t security related but rather just an annoyance.
 
3) ALREADY INCORPORATED INTO A COMPETITIVE SOLUTION
If a competitor has incorporated a feature into their product, we can do the same under the auspices of "being competitive".  This means that for ticky-tack features, we’re likely always going to be behind.  For example, tabbed browsing… we had to wait until someone incorporated it into their product.  Another example:  When Pop-up Blocking became a stock feature of Firefox and Opera, we were able to incorporate it into IE 6.02.
 
So wait:  Why is it that Internet Explorer 7.0 is taking so long?  Why hasn’t Microsoft cranked out improvements to it’s browser now that Firefox, Opera, and Netscape have released richer solutions?
 
Here’s a few of the many reasons:
1) NEW DEVELOPMENT PROCESS
The much-publicized new development process that Microsoft follows ensures that products are developed without the infamous security holes and buffer overflows that have plagued Microsoft in the past.  Internet Explorer 7.0 is no exception.  What makes this product release so special however is that it’s being developed from the ground up with this process, and while IE 6.0 code is being used, it’s being processed through the same filters that new code is using.  (Part of the process is a newly created computer-driven analysis filter that examines all submitted code and virtually eliminates the possibility of traditional buffer overflows.
 
2) API DOCUMENTATION & COMPLIANCE
All code has to be throughly documented.  Gone are the days of undocumented features like "easter eggs" and other fun stuff.  Microsoft is from what I understand tasked to ensure that every interface is documented and every feature is explained to comply to various regulations that I frankly don’t know much about.  All I know is that stuff exists that make documentation very important.
 
3) LOCALIZATION
This one is huge:  All products have to be ported to 26 different languages and more importantly, modularly switchable between 26 different languages for all aspects of the product – including the menus and the help system.  People literally have to be able to change the interfaces for the product from English to Japanese on the fly.   In the case, of Internet Explorer, we also have to support various language character sets in the content of the browser which is big fun.
 
4) MANAGEABLE
The product has to be managable centrally for corporate customers.  This means being able to set mandatory settings from a single point on a network and force them onto every PC within a company – for example, the ability to lockdown the home page of the browser to always go to a corporate portal.
 
There’s even more than this but I hope it’s clear that the burden that we have to meet in order to ‘build a better browser’ is a lot larger than what our competitors have to meet.  Does this mean we’re always going to be behind?  Perhaps.  Ultimately however, we believe that we’ll be able to develop products that adhere to the letter of the law, while also addressing the needs of our customers in a deliberate and exacting fashion.
Posted by: kurtsh | January 3, 2006

RELEASE: USB-based Beverage Cooler

This is so insignificant it’s pathetic but I’m going to post it because I know at least 3 people reading this will immediately go out and order it.
USB-based Beverage Cooler:
Posted by: kurtsh | January 2, 2006

RELEASE: WMF vulnerability 3rd party patch released

(Note:  Microsoft doesn’t recommend that people use this patch)

Ilfak Guilfanov who is being billed as one of the foremost experts in Windows low level technology has released a temporary/interim patch for Windows that’s NOT from Microsoft.

EXE file:  http://castlecops.com/article-6436-nested-0-0.html
(MSI file located here:  http://handlers.sans.org/tliston/WindowsMetafileFix.html)

 

Technical details:

"This is a DLL which gets injected to all processes loading user32.dll. It patches the Escape() function in gdi32.dll. The result of the patch is that the SETABORT escape sequence is not accepted anymore."

Once Microsoft releases an official patch, or if the above doesn’t work, you can uninstall it from your Add/Remove Programs menu. It’ll be listed as "Windows WMF Metafile Vulnerability HotFix".

 

The Internet Storm Center gives this patch its stamp of approval:

——————————————————————————–
We have very carefully scrutinized this patch. It does only what is advertised, it is reversible, and, in our opinion, it is both safe and effective.

The word from Redmond isn’t encouraging. We’ve heard nothing to indicate that we’re going to see anything from Microsoft before January 9th.

The upshot is this: You cannot wait for the official MS patch, you cannot block this one at the border, and you cannot leave your systems unprotected.

I nearly kneeled over laughing reading this.
 
The full text explanation of the rationale around the comic is here.
 
Apparently the folks at Penny Arcade discovered that wikipedia is almost entirely subjective.  Objectivity is not a requirement for anyone publishing to a given publicly accessible wiki.
 
At Microsoft, we have a wiki and it works wonderfully.  It’s called a Support database.  When you call into Microsoft with a problem, all the research and solution information is cataloged for anyone else to reference.  Granted the content is rather "pell mell’ in the sense that every email, every comment, every dialogue is recorded for everyone to read – this includes every customer swear word, every bit of customer-identifiable information, every Microsoft reference to current issues and secret projects being worked on.  (These are the reasons, y’all, the reading public aren’t permitted to see it.)
 
But the difference between OUR Support database, and public wikis is that:
1) ACCOUNTABILITY
Everyone is held accountable to their entries and there are consequences to ‘screwing around’ with the Support database… being fired is one of those consequences.  Not to mention that everything in the database is backed up regularly.
2) COMMON PURPOSE
People using the database are in there to track their own customer’s product support issues.  It’s their JOB to create good content and get resolutions by recording nothing but fact… conjecture is identified readily, and dismissed if it is found to be incorrect, however both the hypothesis and the conclusion are recorded permanently for posterity.  Putting inaccurate information only hurts the employee, not to mention other employees.
3) UNIFYING GOAL
The Support organization has a unifying goal of helping to make Microsoft a better company through the creation of a better customer experience.  This is the foundation upon which the Support database exists, thus, everything that is entered into it is done with "the company’s best interests in mind".
 
Public wiki has NONE of this which is why most wiki content is an endless charade of subjective opinions masquerading as expert fact.
Posted by: kurtsh | December 31, 2005

RELEASE: A commentary on the WMF Vulnerability

The sad ridiculous media hype over this vulnerability truly highlights how warped the priorities are of many journalists – particularly those on the Internet.  The common journalistic claim to "inform the public" and "defend their right to know" sometimes seems like a giant front for a real agenda to "create panic and hysteria"… because as we all know, negativity always generates an audience in the same way that highway accidents attract rubberneckers. 
 
To be clear, I have no problem with people that want to bring attention to this vulnerability.  That’s important.  What’s not cool is that most of these same people absolve all responsibility for informing people about what to do about it.
 
Net Net:  If there’s a problem, why not link to the "official description" of the problem instead of some 1 man consulting firm hack that wants to get his name in the press… and God forbid,  why not link to some"potential solutions"?  Why write about the supposed cataclysmic disaster impending and not tell people how to avoid it?
 
THE PROBLEM:
The official Microsoft advisory on this issue is located here: 
Microsoft Security Advisory (912840):  Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution. http://www.microsoft.com/technet/security/advisory/912840.mspx
 
THE SOLUTION:
There are a number of solutions available. 
  1. SOFTWARE DATA EXECUTION PROTECTION:
    There’s a real simple solution – Enable software DEP, a feature of Windows XP Service Pack 2.  Here’s a quote from the advisory that no one seems to be reading.
    "I have software DEP enabled on my system, does this help mitigate the vulnerability?
    Yes. Windows XP Service Pack 2 also includes software-enforced DEP that is designed to reduce exploits of exception handling mechanisms in Windows. By default software-enforced DEP applies to core operating system components and services. This vulnerability can be mitigated by enabling DEP for all programs on your computer.
    For additional information about how to “Enable DEP for all programs on your computer”, see the product documentation."

    To enable or mess around with the DEP settings:
    – Go to START->CONTROL PANEL->SYSTEM
    – Click ADVANCED tab & press Performance SETTINGS button
    – Click DATA EXECUTION PROTECTION tab
    Make sure that the "Turn on DEP for essential Windows programs and services only" radio button is clicked.

  2. HARDWARE DATA EXECUTION PROTECTION:
    This is an even easier solution.  Enable hardware DEP support  (also called NX support) on your PC if you have a recent Pentium 4 from Feb 2005 on, or an AMD Athlon chip. 
    (BTW If you have no idea what this is, check out http://www.updatexp.com/data-execution-prevention.html for a 3rd party explanation of what software and hardware DEP is.)
  3. DISABLE OR UNREGISTER "SHIMGVW.DLL"
    A couple of security firms, including Verisign’s iDefense, have published workarounds that appear to mitigate the threat. According to iDefense, Windows users can disable the rendering of WMF files using the following hack:

    1. Click on the Start button on the taskbar.
    2. Click on Run…
    3. Type "regsvr32 /u shimgvw.dll" to disable.
    4. Click ok when the change dialog appears.

    iDefense notes that this workaround may interfere with certain thumbnail images loading correctly, though I have used the hack on my machine and haven’t had any problems yet. The company notes that once Microsoft issues a patch, the WMF feature may be enabled again by entering the command "regsvr32 shimgvw.dll" in step three above.

There’s even more than this, but I’ll leave 3 as a starter.  This hopefully will tell you, dear reader, how easy it is to protect yourself – in fact, many of you probably already are by virtue of WinXPSP2’s software DEP feature that you installed and didn’t even know was operational.
 
…but oooohh watch out.  The press says that "THERE IS NO KNOWN PATCH AVAILABLE FROM MICROSOFT!"  Aigh!  What are we going to do?!?  There’ll be panic in the streets!  Mayhem and chaos across the Internet!  Dogs and cats living with each other!  (With apologies to Bill Murray)  We’rrrrrre allllll gonnnnnnna diiiiiiiiiiiie!
 
Or maybe not.  Film at 11.
 
 
 

« Newer Posts - Older Posts »

Categories