Contact Me By Email

Showing posts with label PC World (magazine). Show all posts
Showing posts with label PC World (magazine). Show all posts

Friday, March 25, 2011

Google Patches 6 Serious Chrome Bugs - PCWorld

Google Chrome IconImage via WikipediaGoogle Patches 6 Serious Chrome Bugs - PCWorld

Google on Thursday patched six vulnerabilities in Chrome, and as usual, silently updated users' copies of the browser.

The update to Chrome 10.0.648.204 also included two more blacklisted SSL certificates that may be related to last week's theft of nine digital certificates from a Comodo reseller.

All six bugs were rated "high," Google's second-most-serious ranking in its threat scoring system. Of the half-dozen bugs, two were "use after free" flaws -- a type of memory management bug that can be exploited to inject attack code -- while a second pair were pegged by Google as "stale pointer" vulnerabilities, another kind of memory allocation flaw.

As is Google's practice, the company locked down its bug-tracking database, blocking access to the technical details of the patched vulnerabilities. Google usually unlocks the bug entries several weeks, sometimes months later, to give users time to update before the information goes public.

Google paid out $8,500 in bounties to three different researchers for finding and reporting the six vulnerabilities. So far this year, Google has cut bounty checks totaling $58,145.

Frequent-contributor Sergey Glazunov took home $7,000 for reporting four of the bugs patched Thursday, bringing his 2011 bounty total to $20,634. Glazunov has become the most prolific of the independent researchers who specialize in rooting out Chrome flaws, reporting 14 of the 54 bugs attributed to outsiders.

Yesterday was the sixth time Google patched security vulnerabilities in its browser this year.

Google said the update also added support for the browser's password manager on Linux, and included performance and stability fixes. According to the Chrome change list, it also blacklisted two additional SSL (secure socket layer) certificates , the digital certificates that encrypt traffic between users and sites.

The additions to the SSL blacklist may be connected to last week's theft of several certificates from a Comodo reseller, an event that prompted Comodo to revoke the stolen certificates. Since then, Google, Mozilla and Microsoft have each issued updates -- Google was the first off the mark -- to block the certificates and warn users if they tried to connect to fake sites.

Comodo has cited circumstantial evidence that points to Iran , perhaps the Iranian government, being involved in the certificate theft.

Google did not immediately reply to questions Friday about whether the newest additions to Chrome's blacklist were related to the Comodo theft.

Chrome 10 can be downloaded for Windows, Mac OS X and Linux from Google's Web site. Users already running the browser will be updated automatically.

Saturday, March 05, 2011

iPad 2.0 will Help Apple Rule for Years, Analyst Says - PCWorld

iPad, iPhone, MacBook ProImage via WikipediaiPad 2.0 will Help Apple Rule for Years, Analyst Says - PCWorld

By Ross O. Storey, MIS-Asia Mar 5, 2011 8:40 am

With Apple's launch of the second version of its iPad, research house Ovum predicts that it will take until 2015 for devices running Google's Android platform to catch up.

Ovum principal analyst Adam Leach said that in such a fast-moving market, Apple was forced to release a new version of its iPad hardware to stay ahead.

"Apple clearly had first mover advantage. However, its competitors have been hot on its heals with a slew of tablet devices from big brand vendors such as Samsung, Motorola, HP, HTC and RIM, all of which have announced tablet devices which aim to replicate the Apple experience, which is notoriously difficult to match," Leach said.

"Much of the early growth of the tablet market can be attributable to the Apple iPad, a device whose sales constituted 90 per cent of the total market opportunity in 2010. The remaining 10 per cent of shipments in 2010 was made up of devices running variants of Google's Android OS".

Honeycomb Popular
Leach said most device vendors are looking to exploit Google's latest version of the Android operating system, honeycomb, to deliver a user experience that can compete with Apple's own iOS.

"However, some vendors, notably HP and RIM, are choosing to invest in their own software platforms," he said.

"Ovum's belief is that the platform dominance of Apple and Google will continue through 2011 and beyond, albeit with devices based on Google's software platform commanding an increasing proportion of the total market opportunity".

"However, devices based on Google's platforms will only overtake those based on Apple's platform by 2015, when we forecast 36 per cent and 35 per cent market shares respectively, of a total market with shipments of about 150 million units in 2015," Leach said.

This compares with Ovum's estimate of 10 per cent for Google and 90 per cent for Apple at the end of 2010.

Saturday, February 26, 2011

Study: Apple's Mobile Browser is Fastest - PCWorld

Image representing Apple as depicted in CrunchBaseImage via CrunchBaseStudy: Apple's Mobile Browser is Fastest - PCWorld

By Nick Mediati, PCWorld Feb 25, 2011 8:50 PM

Sick of waiting for pages to load on your mobile device? Get an iPad or iPhone. That’s the upshot of a mobile browser speed study done by a company called Gomez. They found that Apple’s mobile version of Safari was fastest and BlackBerry’s browser the slowest.

According to Gomez, the iPad fully loads pages in 8.4 seconds on average. The iPhone comes in second at 19.7 seconds, followed by Android at 36.5 seconds, and Blackberry at 61 seconds.


Gomez also analyzed perceived page loading times--that is, how long it took each browser to load the items visible "above the fold" on screen (i.e. the elements visible to you when you first visit the page without scrolling down). Perceived load times are shorter because … In this, the iPad again came out on top, with a perceived load time of roughly 6.6 seconds. The iPhone clocked in at about 15.7 seconds, followed by Android at 28.2 second, and BlackBerry at around 43.8 seconds.

Some have tested mobile browsers on a particular OS--such as our Android browser comparison from September--or have compared browsing on one phone to browsing on another, but as far as we're aware, nobody else has released this sort of mobile browser speed comparison before.

Browser Testing: No Clear Winners

These are by no means end-all, be-all numbers. Browser speed testing can be a bit of a thorny issue. There are many variables involved, depending on your hardware, your network connection, your operating system, the Web site itself, and so forth. For example, Gomez's numbers don't match up exactly with the testing we've previously done.

In the case of Gomez, the company, which helps companies improve the performance of their Websites and applications, decided to take what it considers to be a "real-world" approach to measuring browser performance. Its data is based on over 282 million Webpages served across over 200 popular sites. Gomez used data collected from business customers that use its performance monitoring services. It only takes into account Webpages visited using the browser included with the operating system, so browsers like Opera Mini were not included.

Also, since the data is in aggregate, it includes data from both Wi-Fi and cellular network users, and users from different cellular networks. It also includes data from all sorts of different phones and tablets with different hardware configurations. Still the information they provided to us is interesting, and gives us at least an idea of what the general experience of using each browser is like.

And as we've said in the past, other factors beside speed should dictate your choice in browsers--and now, smartphone OSes. Go with whatever works best for you.

How about you? Do Gomez's numbers reflect what you've experienced? Let us know what you think by leaving a comment below.

Friday, February 25, 2011

Chrome Browser Acts More Like an OS, But Security Is Unclear - PCWorld

Google Chrome IconImage via WikipediaChrome Browser Acts More Like an OS, But Security Is Unclear - PCWorld

With the capability to run apps in the background, Google’s making its Chrome browser even more like an operating system and is attempting to change the way we work forever.

By Keir Thomas
Feb 25, 2011 12:42 PM

Google has announced that forthcoming releases of its Chrome browser will be able to run apps in the background. Essentially, the feature moves Chrome one step closer to becoming a true application platform--and with continuing efforts to develop HTML5, in a few years time it's very likely the Chrome browser will have more in common with an operating system than a humble Web browser.
Google says the new feature will see use "checking for server-side changes and pre-emptively loading content into local storage," and it's not hard to imagine how apps could use the feature. A chat application could listen for messages, for example, and then pop up a new window should somebody want to message you. A cloud office suite could watch for changes made to your online docs and download them locally, ready for you to work on them instantly when you choose.

The background processes keep running for as long as Chrome is running, even if no browser windows are open. Right-clicking the taskbar icon will allow users to see what background apps are running.
One of the central definitions of a contemporary operating system is the capability to run tasks in the background. MS-DOS did it with infamous terminate-and-stay-resident programs, while Windows does it with Services. Linux and Unix use daemons.
As with those operating systems, significant security issues come up with the capability to run background apps. Running code in the background without the user's knowledge is the modus operandi of viruses, for example.
It's not clear how Chrome is going to be able to tell apart good and bad background processes, or whether Google intends to rely on third-party applications like antivirus suites to do so.
Google says "backgrounding" will be allowed only for apps and extensions, and not Web pages, which will avoid drive-by infections from nefarious Websites. Chrome users already have to confirm installation of apps and extensions, giving security warnings at the time. If the app or extension isn't offered via Google's official distribution channels, it's usually blocked from installation unless the user makes a configuration change allowing it.
However, as anybody who's used the Android Marketplace will know, Google takes a laissez-faire attitude towards monitoring apps. Last year the company pulled around 50 third-party and unauthorized Android banking apps from the Marketplace after suggestions came up that they could easily be used to harvest account details.
To ensure user safety, the bar for app and extension quality is going to have to be set high, and there's no indication in this announcement that that's going to happen.
However, security issues aside, Google's efforts will bring a smile to cloud computing advocates. By blurring the distinction between browser and operating system, Google's making it far more intuitive for us both to work and store our data online. Of course, data is what Google is interested in, and it seems Google won't be satisfied until it has control of all the data in the world.

It's not hard to imagine a future scenario whereby we first boot our computer and then "boot the Internet" by double-clicking a browser like Chrome. Upon starting, Chrome will automatically log into all our favorite Web applications, and start any necessary background services. The new tab screen within Chrome, which shows installed apps, could easily evolve into a desktop-like experience in the future, wherein users are able to start and stop apps, and manage any data stored online.
A lot has been written about whether the Chrome browser or OS will ultimately succeed, but it's not an either-or situation. It's better to view the projects as two heads of the same animal. If you buy a new computer, then Google can provide an operating system, but if you prefer to stick with what you know--such as Windows, Mac OS X, or Linux--then Google will offer you the same functionality via a program you can download.
Essentially, Chrome browser and Chrome OS are heading in the same direction, which is to turn the Internet into an platform where we all can work. If we're ready to abandon our desktops, however, is yet to be seen.
Keir Thomas has been making known his opinion about computing matters since the last century, and more recently has written several best-selling books. You can learn more about him at http://keirthomas.com. His Twitter feed is @keirthomas.

Thursday, December 30, 2010

Will 2011 Signal a Mac Virus Onslaught? Not So Fast - PCWorld

Will 2011 Signal a Mac Virus Onslaught? Not So Fast - PCWorld

s it really true that it's only a matter of time before Macintosh users are under siege by a flood of viruses and malware? McAfee announced recently that 2011 would be a bad year for people using Apple computers, as hackers will be increasingly attracted by growing Mac market share. It's not at all hard to find experts who agree.

The thing is, they also agreed back on July 18, 2010, June 17, 2010, April 9, 2008, and October 20, 2006, among many other dates in the past which I didn't bother excavating from Google. Remember that horrible Christmas of 2006, when all of your Macs broke simultaneously?

Me neither.

How malware hackers eat

It's worth noting how computer malware comes into being. Unlike biological viruses, such as H1N1, malware doesn't spontaneously create new offspring. New viruses require the effort of "black hat" hackers, who try to create code that is easy to replicate, hard to remove, and does something to benefit of its creator.

That last bit is a crucial part of the malware environment. A few malware hackers write software attacks purely out of malice, but mostly it's done for profit. In theory, the more Mac users there are in the world, the more appealing they become as a target for hackers. This theory is pretty much the sum total of the analysis you'll see about Mac security on many general news sites.

In practice, though, there are three major components that play into the creation of viral attacks:.

Motivation: Hackers will attack where they have reason to do so. Consider the Stuxnet worm that attacked sensitive computers in Iran. If anyone knows for certain who wrote this, or how it was introduced into Iranian nuclear plants, they're not talking to Macworld. But these attacks weren't motivated by the sudden increase of people walking around carrying programmable industrial logic controllers in their pockets.

Opportunity: When there's vulnerability in software-from Apple or or any other vendor-the malware hacker community is almost always the first to know. After all, this is their bread and butter-give them a chance to make money, and they'll race to exploit the vulnerability before it's found and fixed. Serious computer security experts (who are, alas, less frequently quoted in the general media than software vendors and supposed experts who give good sound bites) classify these opportunities into vulnerabilities (theoretical avenues for attacks) and exploits (actual attacks taking place in the real world).

For example, if you go away for the weekend and forget to lock your door, but you come home to an intact house, that's a vulnerability. But if you came back to find that some scoundrel has made off with your worldly possessions, thanks to your forgetfulness, that's an exploit. Most computer security issues you read about-and especially the ones you see on cable TV news-are vulnerabilities. But we're vulnerable to thousands of things a day, including death rays from outer space which do everything from cause cancer to crash your MacBook. Unless you've already lined both your hat and your laptop bag with tinfoil, you're clearly not too worried about this. (Nor should you be-the odds of this occurring are extremely low. And the tinfoil is unlikely to help.)

Herd immunity: Herd immunity is a concept from biological infection that also applies to computers. Disease relies on a certain critical mass to spread: if your population is dominated by those who are immune to infection, it helps curtail the communication of the disease. In terms of computers, it means that so long as the vast majority of machines that your computer interacts with aren't subject to the same malware-i.e. when your Mac talks to Windows PCs-you're less likely to get infected. When your machine talks mostly to computers that are susceptible, herd immunity is lost.

So, the assumption that is made by almost all of the doomsaying articles linked above-and thousands I didn't link to-is incorrect. There is no magic number of Macs, above which they suddenly become less secure. There is instead a theoretical protection that is offered by Macintosh market share. The actual point at which a larger market share becomes dangerous depends entirely on the nature of the threat.

As Macs are built on many of the same technologies as the iPad and iPhone, it is possible that the rapid rise of iOS devices exposes Macs to new vulnerabilities. But until an actual exploit is in circulation, this is simply a conjecture that falls somewhere between "aliens are killing cows in Montana" and "global warming will submerge Manhattan in 2050." It's my opinion that beachfront property in Pittsburgh might be a good buy-and-hold strategy, but there's still considerable debate about how the proven vulnerability of ocean surface rise will play out in human-impact exploits.

How Mac users think

There's a second flaw in the Macs-are-vulnerable argument: the oft-repeated notion that Mac users believe their Macs are immune to attack. This is mentioned in both the McAfee report as well as the Computerworld coverage.

I beg to differ, on the basis of overwhelming-and purely anecdotal-evidence. As a Mac consultant, writer, and generic "known expert" to a bunch of folks in my community, I regularly field questions about Mac security issues. This demonstrates a general understanding that A) security issues exist on the Mac and B) people are curious enough to ask questions. No one has ever asked me whether a cosmic ray can crash their computer-although it can-or if their MacBook can come to life overnight and raid their fridge. Mac users do seem to assume they're safe from death rays and late night Mac snack raids, otherwise, I'd be asked about those threats. If people ask me about malware-and they do-I take that as proof that they don't assume they're immune.

As for what you should be doing about these attacks, that has been covered by experts numerous times in greater detail than I can address here. Given that you're reading this article, you're already doing the most important thing you can: Staying informed. When a new Mac vulnerability breaks, you'll read about it on Macworld and other Macintosh-specific news sites. When this escalates to the level of a circulating exploit, you'll see even more coverage. If and when an exploit becomes common-which has not occurred since the primary method of moving Mac files around was an 800K floppy disk-then you won't be able to avoid hearing about it if you're keeping up on Mac-specific news.

Conversely, you should take any information you get about the Mac from a general news site with a grain of salt. Unfortunately, many tech and computer news websites can fall into the "general" category here more often than they probably should. If you hear about a threat, but it doesn't seem to concern editors at Macworld and other reputable Mac sites, then those general sites are likely missing something. When something is genuinely dangerous, you'll hear about it here from Mac-specific writers and editors. You'll also be told how to protect yourself, if such a method exists.

Critics often accuse Apple of touting the imperviousness of its systems, but it's worth noting that the company acknowledges its imperfections. For example, it still recommends that Mac users scan downloads from untrusted sources with antivirus software. (Users looking for an antivirus package have a number of options to choose from.) Apple itself builds a wide range of security measures into the Mac OS, including-in OS X's most recent incarnation-a limited malware-detection system. Security requires a proactive approach, but Apple helps users out by enabling most of those measures by default.

In the meantime, despite the many varied technical debates to the contrary, you can generally rest easy-unless you enjoy getting lost in the weeds where Mac experts and geeks like to hang out. You'll find many debates among Mac experts about theoretical dangers, and these can sometimes make it into the general media. But that doesn't mean you need to take action every time the hint of a threat pops up in your RSS reader. The vaunted grain of salt and information from reliable sources should see you right.

Sunday, December 26, 2010

Google Turns Borg: Time to Rein in the Search Giant - PCWorld

Google Turns Borg: Time to Rein in the Search Giant - PCWorld

By Bill Snyder
Dec 26, 2010 10:23 AM
Remember when Microsoft was the company feared for trying to dominate the computing world? That risk has passed, but a new one -- with Google in the role of the bad Borg -- is taking its place.

Microsoft's "ownership" of the desktop operating system and its attempt to own the Internet via Internet Explorer was a terrible detriment to innovation and competition in the tech marketplace -- so it was struck down, first by the U.S. Justice Department's antitrust actions and more recently by users as they adopt alternative technologies in the cloud and in mobile devices. It's hard to argue that an unfettered Microsoft, free to strangle the Internet in its cradle by jamming Internet Explorer down everyone's throat, would have been a good thing.

Today, the desktop operating system as we knew it is no longer the centerpiece of computing. That's not to say it isn't important, but technology has moved on. At the moment, nothing has really taken its place; the tech world is multipolar, with products from Apple, Microsoft, Facebook, and -- perhaps most important -- Google determining how billions of people related to the digital world.

If anything sets the tone for both desktop and mobile computing today, it's search, and there of course is where Google has no real rival. (Sorry Bing, you've yet to move to the major leagues.) The combination of search and advertising is the Windows of today. Search dominates our experience of the Web, while advertising dominates the business model of the Web. That's not a new thought, of course, but Google's planned foray into the online travel business, not a sector I'd normally care about, brings new concerns about the search giant's effect on competition to the fore. Coincidentally, the E.U. shares that concern and is already investigating.

In July, Google reached an agreement to buy ITA Software, a maker of air-travel information applications, but the $700 million deal is awaiting U.S. federal regulatory approval. The acquisition was the subject of a rather critical editorial in the New York Times, a piece that provoked conversation around the Web, some of it pretty interesting.

Greg Sterling over at Search Engine Land critiqued the Times for not just coming out and saying what he thinks the paper really means: block the deal. So I'll say it: Block the deal, and take a hard look at Google's effect on competition.

When Microsoft ruled the earth

In case you weren't around in the 1980s, let me remind you of how Microsoft used to act.

Every now and then, Bill Gates would look around and notice a technology, generally one owned by a small company, and decide it should be part of DOS -- and later, Windows. Microsoft would then add a feature like disk compression or file management to the operating system and give it away. That spelled the end of lots of small competitors and a certain amount of innovation.

Gates later realized that the Internet was the next big thing, so Microsoft bundled Internet Explorer with Windows. That, of course, is what prompted the Department of Justice to sue the company and eventually force it to unbundle IE. It's worth remembering that Microsoft swore up and down that pulling IE from Windows wasn't possible without wrecking the OS. Monopolists always come up with self-serving rationales to convince the world that what they're up to is the way things have to be. Usually they'll tell you that their domination of the marketplace is good for everyone.

Google should be stopped before it gets too strong

Just as Microsoft's power wasn't good for us, neither is Google's growing stature, and Google would do just fine if it were reined in. Indeed, a bit more focus might be helpful. Witness the Nexus One fiasco. Google had no clue how to operate in the mobile market, and it flat out embarrassed itself, probably wasting a good deal of money and time with a poorly thought-out initiative. The Nexus One was hardly an isolated incident. Google TV and Google Wave are similar fiascos by a company trying to do everything but not very well. In fact, the company tripped all over itself for much of 2010.

We're lucky that Google has been so inept, as that has kept it from dominating even more businesses -- so far. At some point, Google could succeed in its new endeavors. Allowing Google to play Microsoft and gradually dominate an expanding ring of related businesses would be bad for Internet users everywhere.

Like it or not, advertising is the lifeblood of the Web. If Google owns ITA, whose software is used by many large travel sites, I'd expect search rankings for competitors such as Kayak and Orbitz to suffer. That means less consumer choice in the short run and the greater loss of innovation due to the much higher bar it would set for any new company to enter the market.

As the Times pointed out, look at what happened to MapQuest when Google entered that business: It tanked, in part because Google started putting its own maps on top in response to queries about locations.

The same logic applies to other markets, including those we may care about more than online travel. Wireless location services, when teamed with search and advertising, are opening the door to innovative new business models. If Google makes another more successful run at the wireless market, what happens to competition in that arena?

Google, like Microsoft before it, needs to be reined in. It will still be a great company, and it will be free to innovate and beat the heck out of its competition -- but that beating will take place on the proverbial level playing field.

This is my last post of the year. Thanks to all of you for reading and taking the trouble to set me straight with your comments and emails when I needed it. See you in 2011. Happy New Year!

I welcome your comments, tips, and suggestions. Post them here so that all our readers can share them, or reach me at bill.snyder@sbcglobal.net. Follow me on Twitter at BSnyderSF.

This article, "It's time to rein in Google -- before it assimilates all Web business," was originally published by InfoWorld.com. Read more of Bill Snyder's Tech's Bottom Line blog and follow the latest technology business developments at InfoWorld.com.

Sunday, December 12, 2010

Google, Twitter Tools Helped Protests - PCWorld

Image representing Twitter as depicted in Crun...Image via CrunchBaseGoogle, Twitter Tools Helped Protests - PCWorld

British students coordinated their recent mass demonstrations using social media sites, including Twitter and Facebook.
By Leo King

Dec 12, 2010 10:17 am

Student protesters last week turned to social media sites, including Twitter and Facebook, to co-ordinate their mass demonstration in Westminster, U.K. and other areas.
Google Maps was also used extensively as protesters pinpointed what was happening and where.

The sites were used equally by the police, who watched for information on the protesters' plans. Police officers were present in large numbers around the planned route and at changed locations.
The demonstration, which in places turned violent and led to police cordoning off parts of central London, was held in protest at the near trebling of university fees to £9,000 a year. The change was narrowly passed in a controversial vote in the House of Commons the same day.
The extensive use of social networking sites to co-ordinate and track demonstrations comes in a week when Twitter and the blogosphere were alive with comments on US ambassadors' cables leaked by Wikileaks. Blogs and forums are also being extensively used to co-ordinate hacking attacks on businesses unwilling to work with the whistleblower website.
Students have claimed they were making easy use of social media and Google to co-ordinate their actions.
"A few days ago I suggested the protesting students could do with some kind of "anti-kettling app," to outwit the efforts of the police to stop them protesting," said Ben Goldacre on his blog.
"It turns out I was over engineering things in my head. The students on the anti-fees protests in London are now using this simple Google map: http://j.mp/dayx3"
Meanwhile, as the protests started, blogger Laurie Penny wrote on Twitter: "And they're off. The noise is incredible. Taking over the whole road." Others updated on Twitter under the hashtag #fees.

Saturday, December 11, 2010

Microsoft Readies Record Patch Tuesday - PCWorld

The current logo of Microsoft Windows, the com...Image via WikipediaMicrosoft Readies Record Patch Tuesday - PCWorld

Microsoft says it will deliver a record 17 security updates next week to patch 40 vulnerabilities in Windows, Internet Explorer (IE), Office, SharePoint and Exchange.

Among the 40 patches will be two that address a pair of bugs that hackers have already exploited.
"I really was not expecting 17," said Andrew Storms, director of security operations at nCircle Security. "I expected 10 at the most."
The 17 updates -- Microsoft calls them "bulletins" -- are a record, beating the count from October 2010 by one. The bulletins that will ship next Tuesday will include 40 patches, Microsoft said, nine fewer than the record set last October, but six more than the next-largest months of October 2009 and June and August of this year.
The total bulletin count for the year -- 106 -- was also a record, as was the number of vulnerabilities patched in those updates: 266.
Microsoft defended the blistering bug patching pace of 2010.
"This is partly due to vulnerability reports in Microsoft products increasing slightly ... [and to the fact that] Microsoft supports products for up to ten years," said Mike Reavey, the director of the Microsoft Security Response Center (MSRC), in a post to the team's blog today. "Older products meeting newer attack methods, coupled with overall growth in the vulnerability marketplace, result in more vulnerability reports."
But it was December's big number that caught Storms' eye.
"The sheer number is quite surprising for December," said Storms. In the past three years, Microsoft has issued no more than nine updates in December, he said. "And while Microsoft doesn't necessarily take its cues from the rest of the world, the fact is many organizations won't patch a lot of these until after the first of the year," Storms continued.

Not only will enterprise IT staffs be short-handed this month -- what with holidays and vacation time -- but they will be unlikely to risk problems that could crop up in patching during such an important time of the year for their business.
"In this case, there might be less risk involved by doing nothing," said Storms. "That's especially true of companies, like those in the financial sector, that have locked down their networks since early November."
Many firms forbid patching the last two months of the year to insure that their hardware continues to operate, said Storms.
Two of the 17 updates were tagged with Microsoft's "critical" label, the highest threat ranking in its four-step scoring system. Another 14 were marked "important," the second-highest rating, while the remaining update was labeled "moderate."
Ten of the updates could be exploited by attackers to remotely inject malicious code into vulnerable PCs, Microsoft said in its usual bare-bones advance notification . Microsoft often labels remote code executable bugs -- the most dangerous -- as important when the vulnerable components are not switched on by default or when other mitigating factors, such as defensive measures like ASLR and DEP, may protect some users.
Among the fixes slated for next week will be one that addresses an already-disclosed vulnerability in all supported versions of IE, said Reavey.
In early November, Microsoft disclosed the zero-day IE bug and confirmed that attacks were already circulating . It was unable to craft and test a patch in time to make it into that month's security update, which appeared six days later.

Next week's IE update is one of the two marked critical, and will affect all versions of the browser with the possible exception of IE9, which is still in preview mode.
Microsoft also intends to patch the last of four Windows vulnerabilities that were used by the notorious Stuxnet worm to infiltrate industrial control systems, said Reavey. As far as Microsoft knows, the bug, which lets attackers elevate access privileges on a compromised PC, has not been exploited by malware other than Stuxnet.
Exploit code for that vulnerability, however, has been available on the Internet for several weeks.
Of the 17 updates, 13 will affect one or more versions of Windows, two will patch Office and Microsoft Works on Windows, and one each will address bugs in the Exchange and SharePoint server software.

Storms was concerned about the Exchange update.
"Anytime it has to do with e-mail, it's concerning," he said, adding that because the server must face the outside world, there may be easily-exploited attack vectors. "SharePoint, on the other hand, is usually very well protected inside the network," he said.
Also of interest, Storms said, was what Microsoft today identified only as "Bulletin 2," an update that affects all versions of Windows, but was tagged as critical for newer editions, including Windows Vista, Windows 7 and Server 2008. The same bulletin was marked as important for the older Windows XP and Server 2003 operating systems.
The Microsoft patch burden this month will be especially tough for administrators to deal with, because of other events, notably the WikiLeaks release of confidential U.S. diplomatic messages, and the resulting retaliatory distributed denial-of-service (DDoS) attacks against firms like Amazon, MasterCard and PayPal.
"It is enough that IT administrators are addressing the current DDoS service attacks surrounding WikiLeaks where anyone could very quickly become a target, but now organizations also have to address this disruptive Patch Tuesday from Microsoft with 17 bulletins," said Paul Henry, a security analyst at Lumension, in an e-mail Thursday.
"There's more than enough to handle at the moment without this Patch Tuesday," added Storms. "There's the ongoing WikiLeaks attacks and then there are always zero-days released around Christmas."

Storms was confident that Microsoft would include workarounds for the most egregious of next week's bugs that will help organizations and users protect themselves if they were unable to apply the security updates.
"That's something that Microsoft is actually been very good at lately," said Storms. "I expect that they'll deliver a decent set of mitigations."
Microsoft will release the 17 updates at approximately 1 p.m. ET on Dec. 14.
__________________________________
There is an easy solution. Buy a Mac.

John H. Armwood

WikiLeaks Attacks Illegal Says Internet Society - PCWorld

WikiLeaks Attacks Illegal Says Internet Society - PCWorld


Takedown attempts against WikiLeaks undermine what the Internet stands for, says the nonprofit group dedicated to open use of the Internet.

Dec 11, 2010 9:11 am
Takedown attempts against WikiLeaks undermine what the Internet stands for, and those responsible should be tracked down and prosecuted, says the Internet Society, a nonprofit group dedicated to the open use of the Internet.
Could Wikileaks spawn troubles for the IT industry?

In its December newsletter, ISOC says it recognizes that WikiLeaks' posting of diplomatic cables is a worry to some, but knocking the site offline is illegal.
"Unless and until appropriate laws are brought to bear to take the wikileaks.org domain down legally, technical solutions should be sought to reestablish its proper presence," ISOC says, "and appropriate actions taken to pursue and prosecute entities (if any) that acted maliciously to take it off the air."
Wikileaks has suffered distributed DoS attacks and in response supporters of WikiLeaks have launched DDoS attacks of their own against Visa, Mastercard, and Amazon.com.
"The Internet Society is founded upon key principles of free expression and non discrimination that are essential to preserve the openness and utility of the Internet," ISOC writes. "We believe that this incident dramatically illustrates that those principles are currently at risk.
"Free expression should not be restricted by governmental or private controls over computer hardware or software, telecommunications infrastructure, or other essential components of the Internet."
WikiLeaks has managed to continue posting the leaked documents and fresh ones with help from mirror sites around the world.
ISOC notes that due to the very resilient design of the Internet, the attempts to keep WikiLeaks offline have failed, but they have had a negative effect on the Internet in general.
The cooperation among several organizations has ensured that the impact on the Wikileaks organizational website has not prevented all access to Wikileaks material," ISOC says. "This further underscores that the removal of a domain is an ineffective tool to suppress communication, merely serving to undermine the integrity of the global Internet and its operation."

Wednesday, December 01, 2010

Google Targeted by EU Antitrust Probe - PCWorld

Google Logo bg:Картинка:Google.pngImage via WikipediaGoogle Targeted by EU Antitrust Probe - PCWorld

The European Commission is investigating allegations that Google has abused its dominant position in online search to promote its other services, such as price...
Nov 30, 2010 8:04 am

The investigation will also look into alleged abuse of exclusivity clauses that discourage sites carrying advertisements served by Google from also carrying advertisements served by its rivals.
PC manufacturers and software developers will also be questioned to see whether they were pressured by Google to make its search service the default in their products, the Commission said.
Complaints from other search service providers sparked the investigation, it said.
The companies told the Commission that Google treated their services unfavorably in its unpaid and sponsored search results. They also alleged that Google gave its own services preferential placement, the Commission said.
The Commission is particularly concerned that Google may have lowered the ranking in its search results of rival providers of services such as price comparators, in order to promote similar services of its own.
Last week, a U.S. researcher published details of his investigation into Google's treatment of its own supplementary search services compared to those of its rivals.
The Commission stressed that opening the investigation does not imply that it already has proof of any infringements: merely that it is looking for it. Google has been notified of the investigation, the length of which will depend to some extent on the company's cooperation, the Commission said.
Google said it would work with the Commission to deal with its concerns.
Peter Sayer covers open source software, European intellectual property legislation and general technology breaking news for IDG News Service. Send comments and news tips to Peter at peter_sayer@idg.com.
Enhanced by Zemanta

Saturday, November 20, 2010

LibreOffice Is Taking Shape With Third Beta - PCWorld Business Center

OpenOffice.org_logoImage via WikipediaLibreOffice Is Taking Shape With Third Beta - PCWorld Business Center
It's been less than two months since the Document Foundation announced that it was launching its own "fork" of the OpenOffice.org productivity software suite, but already its new LibreOffice alternative is beginning to take shape.
On Thursday the third beta version of LibreOffice 3.3 was released, and it's available for download for Linux, Mac OS X, and Windows. While not intended for production use, the current version of the free, fully open source software gives an early glimpse at LibreOffice's reinterpretation of office productivity, and it's an exciting one.
‘Our Code Base Is Getting Old'
LibreOffice 3.3 is based on OpenOffice.org 3.3, but it adds numerous code optimizations and new features that offer a first preview of new development directions for 2011 and beyond.
First, developers are now working full steam at improving the overall quality of the OpenOffice.org code, with a focus on easy testability and quality assurance. New developers and code hackers are handling the bulk of this activity, the group said.
"Our code base is getting old," explained Charles Schulz, a member of the Document Foundation's steering committee, in a recent blog post. "Worse, the whole frigging software looks and feels like we're stuck in the Bush area. Many things were not fixed, some others need a complete rewrite."

Monday, November 15, 2010

Mobile Broadband at 115MHz of Spectrum Gets Fast-Tracked - PCWorld

Mobile Broadband at 115MHz of Spectrum Gets Fast-Tracked - PCWorld
The National Telecommunications and Information Administration has identified 115MHz of spectrum that can be made available for commercial mobile broadband services within the next five years.
Obama's broadband stimulus: Will wireless fit the bill?
In a report issued Monday, the NTIA said that it had identified portions of two spectrum bands that could be opened up quickly for commercial use, as well as another band that could be opened up in the near future pending further evaluations.
Artwork: Chip TaylorThe first band identified by the NTIA, ranging from 1695 to1710MHz, is currently used by radio transmitters on weather balloons, as well as for weather satellites. NTIA says that the band could be used for commercial broadband services as long as the government sets exclusion zones that prevent commercial services from interfering with government agencies that receive data over the spectrum.
The second major band identified by the NITA is in the range from 3550 to 3650MHz and is used mostly by the Department of Defense for a wide variety of high-power radars. NTIA says that this spectrum can be safely licensed for broadband "outside certain coastal areas and test and training areas" without interfering with Defense Department operations.
The NTIA also examined spectrum in the 4200 to 4220MHZ and 4380 to 440MHz bands but concluded that they couldn't be opened up from commercial use before the year 2016. The administration also says that it could open up spectrum on the 1755 to1780MHz band but it would need more time to evaluate the spectrum since it is used by multiple government agencies throughout the country.
The federal government has made opening up new spectrum for commercial wireless data use one of its major goals in furthering the spread of mobile broadband. The Federal Communications Commission recently projected that growth in wireless data demand will lead to a "spectrum deficit" of 275MHz if no new spectrum is released by 2014.

Tuesday, November 09, 2010

Office 2011 Update Boosts Security, Stability - PCWorld

Office 2011 Update Boosts Security, Stability - PCWorld
Two weeks after launching Office 2011, Microsoft has rolled out an update that aims to improve the security and stability of the latest version of its office productivity suite.
Release notes for the Microsoft Office for Mac 2011 14.0.1 Update say that the release fixes "critical issues" in the latest version of Office that could cause components of the suite to stop responding or quit unexpectedly. Microsoft says the update also fixes a security vulnerability that could allow an attack to overwrite the contents of a computer's memory with malicious code.
As for performance and stability improvements in the 14.0.1 update, the company says that the update includes form-based authentication for connecting to Microsoft Office SharePoint Servers, allowing user credentials to be transmitted through HTML forms that users complete. The update also allows images copied from an Office for Mac application to be edited when copied back to ChemDraw; previously, images were locked when copied to the molecule editor.
Excel for Mac 2011 gets fixes that stop the spreadsheet program from crashing when a macro is enabled and allow cells to update when revisions are made to related data. The update also improves reliability when the FORMAT macro command is used. The update improves the stability of Word 2011 when users build equations, while bolstering stability of PowerPoint 2011 slideshows. Microsoft also improved compatibility with the Windows versions of its presentation software that now allows numbered lists to be displayed correctly in PowerPoint 2011.
Outlook 2011 gets a number of improvements in this update, including better reliability for deleting messages from multiple IMAP accounts, a Sync Services fix, and improved reliability for importing Office 2008 identities into the new version of the suite. The update also allows Outlook to retain e-mail passwords in the keychain after users import new accounts into the mail client.

Sunday, November 07, 2010

Google Squashes 12 Chrome Bugs, Fixes Flash - PCWorld

Image representing Google as depicted in Crunc...Image via CrunchBaseGoogle Squashes 12 Chrome Bugs, Fixes Flash - PCWorld
Google last week patched 12 vulnerabilities in its Chrome browser, all of them rated as high-level threats by the company's security team.
The patched version of Chrome also included an update to Adobe's Flash Player, giving Google users an early fix for a critical flaw that hackers have been exploiting with rigged PDF documents. Adobe planned to release that Flash patch to users of other browsers later in the week.
The dozen flaws fixed in Chrome 7.0.517.44 include a pair related to SVG (Scalable Vector Graphics), a collection of XML specifications for describing two-dimensional vector graphics; one in Chrome's V8 JavaScript engine; and three involving aspects of the browser's text handling.
Google paid $7,500 in bounties to eight researchers who reported 11 of the 12 bugs, the most it's awarded since mid-August when the company handed out $8,674.
As usual, Google locked down its bug tracking database to bar outsiders from picking up technical details of the vulnerabilities. The company usually unlocks access to a flaw several weeks after a patch ships, to give users time to update before the information goes public.
Other browser makers, including Mozilla, do the same.
The update to the "stable" build -- Google maintains three separate "channels" for Chrome, ranging from stable to "beta" to "dev" -- included a revamped version of Flash Player, the popular media playing plug-in.
Seven months ago, Google and Adobe struck a deal that lets the former bundle Flash Player with Chrome and upgrade the plug-in using the browser's own silent updater, This is the second time in six weeks that Chrome users received a patched Flash Player before people running rival browsers, such as Microsoft's Internet Explorer or Mozilla's Firefox.
Last week, Adobe confirmed that Flash contained a critical bug that attackers were exploiting in the wild, and promised to fix the flaw by Nov. 9. Earlier this week, however, Adobe bumped up the release of the Flash update to, saying that it had wrapped up work faster than anticipated.
Although the bug is in Flash, hackers are actually using malicious PDF documents; Adobe's Reader includes code to render Flash from within a PDF, and that code is also flawed. Adobe is planning to issue a fix for Reader and the Acrobat PDF-creation software the week of Nov. 15.
Thursday's update was the second round of Chrome security fixes since the browser jumped to version 7 late last month.
According to Web metrics company Net Applications, Google's hands-off update technology -- which automatically applies not only patches, but also new features -- shifted the bulk of Chrome 6 users to the new Chrome 7 within days.
A week after the Oct. 21 launch of Chrome 7, that version outnumbered its predecessor in usage share by more than 7-to-1.

Wednesday, November 03, 2010

Violent Video Game Ban Could Set Dangerous Precedent - PCWorld

Violent Video Game Ban Could Set Dangerous Precedent - PCWorld From P.C. World
Thank God Steve Jobs isn't on the Supreme Court.
Our nation's highest justices, you see, are in the midst of debating a case about violent video games. They're trying to determine whether the government has the right to decide which video games minors should and shouldn't be allowed to buy. In other words, they're trying to determine whether centuries-old guidelines about free speech still apply to modern forms of media like Playstations and Xboxes.
Their decision, needless to say, could have serious implications on the future of First Amendment rights. And I think we can all imagine how Steve Jobs would vote.
The Supreme Court Violent Video Game Case
The Supreme Court case revolves around a California law passed in 2005. The law makes it illegal for anyone to sell a video game deemed as "violent" to a minor. Breaking it would result in a fine of a thousand dollars per violation.
Thanks to legal challenges, the law has never actually gone into effect. And now, its fate rests in the hands of the high court justices.
We can only hope that the U.S. Supreme Court agrees with the federal courts that have struck down this law in the past. It isn't even limited to California; similar laws have been enacted in eight states overall, according to NPR, and have been deemed unconstitutional by federal judges in each instance. It's no small coincidence.
Let me be clear about one thing: I rarely play video games -- and I'm certainly not a minor -- but I have every reason to be concerned about this decision. And so do you.
Violent Video Game Ban: Questions and Concerns
Ultimately, the Supreme Court case comes down to the divisive question of how much the government should "protect" us from "offensive" materials.
Consider this: The video game industry has already established a ratings system similar to what we see with movies. If anything, it may be even more effective than its film-based cousin: A 2009 Federal Trade Commission report [PDF] found only 20 percent of minors were able to purchase "mature"-rated video games, compared to 28 percent that were able to buy tickets to R-rated movies. Does the government really need to intervene and get involved? Isn't this system -- not to mention that silly ol' thing called parental supervision -- sufficient enough?
Principles aside, the violent video game law poses plenty of practical challenges. According to the law's wording, a violent video game would be defined as one "in which the range of options available to a player includes killing, maiming, dismembering, or sexually assaulting an image of a human being" in a manner that's "patently offensive," appeals to a person's "deviant or morbid interests," and lacks "serious literary, artistic, political, or scientific value."
So who's going to make the call as to which video games are "patently offensive" and which aren't? Or, as Justice Antonin Scalia asked during the arguments, "What's a 'deviant' violent video game? As opposed to what -- a 'normal' violent video game?"
Like with Apple's arbitrary App Store approval system, we're looking at a purely subjective judgment. Unlike Apple's little world, however, this is the real government we're dealing with here -- and granting this type of power is a dangerous precedent to set.
"If you are supposing a category of violent materials dangerous to children, then how do you cut it off at video games? What about films? What about comic books?" asked U.S. Supreme Court Justice Ruth Bader Ginsburg.
Supporters of the California video game law counter that argument with the notion that this scenario is different; because players are actively involved, they say, the violent acts are more damaging to their minds than the graphic violence in movies and on TV. They've even dug up some studies that suggest playing violent video games "increases aggressive thought and behavior" and "engenders poor school performance" in minors. Those studies, of course, conveniently make the mistake of assuming causation from correlation -- just because some kids who play video games also have behavioral problems doesn't mean that the video games caused those problems -- but hey, it's far easier to jump to that conclusion than to search for a real explanation.
Violent Video Game Ban: Broader Implications
Here's the kicker: Even if you accept the "video games are different" argument, opening the door to government-controlled content regulation is asking for trouble. Do we want to make the First Amendment a medium-specific form of protection? If evil, mind-warping video games warrant special consideration, what other modern media will need supervision next? Surely our smartphone app markets should be regulated too, right? There's an awful lot of interactive material there that we need to be protected from -- just ask you-know-who. If this law is green-lighted, we'd better brace ourselves for an awful lot of asterisks under America's "free speech" header.
Finally, with government-enforced fines on selling violent video games, how long will it be until the gaming industry itself starts to change? Forbes.com blogger Paul Tassi raises an interesting point:
"If video games are equated with pornography and it becomes a crime to sell them to minors, 'family-friendly' retailers might change their store policies and someone like Wal-Mart might ban all these games from their shelves entirely. This would in turn cause developers to tone down the violence in their titles to make sure that every outlet will sell them."
All factors considered, the outcome of this case is extremely consequential. When real world policies start to resemble those of Steve Jobs' world, there is definite cause for concern.
Contributing Editor JR Raphael writes plenty of things the state of California would find patently offensive. You can find him on Facebook, on Twitter, or at eSarcasm, his highly uncensored geek-humor getaway.

Monday, November 01, 2010

Adium 1.4 Arrives With Twitter, IRC, More - PCWorld

Adium 1.4 Arrives With Twitter, IRC, More - PCWorld
After debuting as a beta over a year and a half ago, Adium 1.4 has now been officially released, adding support for two new services and a ton of other new features and fixes.
The new Adium adds support for something old and something new-IRC and Twitter, to be exact. You can add multiple Twitter accounts and enjoy many of the basic features of the social networking service. IRC is also well supported, with a number of new preferences to help bend Adium to your chat room whims.
The Adium development team says this release is "jam-packed with hundreds of other new features and bug fixes." Stand-outs from Adium's lengthy list of release notes include: the contact list can display contacts in multiple groups; instant searching now works in any window configuration (select the list and start typing a name; super handy); a revamp of the built-in message styles; faster launch time; the ability to specify a different style for group chats (including IRC); and much more.

Wednesday, October 27, 2010

Is the MacBook Air a Peek Into the Future of Laptops? - PCWorld

MacBook AirImage via WikipediaIs the MacBook Air a Peek Into the Future of Laptops? - PCWorld
"We think all notebooks will look like these one day." Those were Steve Jobs's words when he took the stage on October 20th to introduce a refreshed version of the MacBook Air, making it clear that Apple's newest computers were a harbinger of things to come.
Many people insist on calling the Air an overpriced netbook despite the fact that every single one of its specifications would easily blow any other computer in that category out of the water. But much of the analysis on this new product has been on its immediate usefulness as a mobile computing platform, rather than on its significance for the long-term evolution of the notebook computer.
A triumph of integration
There are a number of major changes in the Air that clearly tag it as a forward-looking system; it seems clear that Apple has gone out of its way to redefine the very concept of portable computers.
Those old enough to remember a time when laptops were still a niche area of computing will also remember how alien they looked inside. While the desktop industry was already well on its way to standardizing component sizes, specifications, and arrangements, laptop manufacturers were faced with the unenviable task of fitting a whole computer into some sort of portable format--and that was before loading it up with heavy, bulky batteries.
The early attempts at this process resulted in some rather bizarre contraptions that were called "portable" simply because they happened to be fitted with a handle: case in point, the 16-pound "luggable" Macintosh Portable. It wasn't until the industry started rethinking the components themselves that the form factor of laptops started to evolve into what we're used to today. The need for retooling and rethinking made laptops expensive for many years until, eventually, the entire market once again standardized on the components that make today's laptops possible: 2.5-inch hard disks, ultra-slim optical drives, smaller and less power-hungry processors, more efficient batteries, and so on.
If Apple wants to push laptop design to a new level, the newest Air clearly indicates that the roadmap it has chosen points in one direction: integration. A picture of the Air's underbelly clearly shows that no effort has been spared to squeeze every last cubic inch of space from the device's interior. This has meant letting go of the traditional 2.5-inch casing that solid-state drives have adopted in favor of a set of a chips on a circuit board (which is really all an SSD is, of course), shedding the optical drive, and tightly integrating every chip into a custom design that minimizes clutter and leave as much room as possible for those still bulky batteries.
From this perspective, then, the Air is much more than a thin laptop: it is a proof of concept that a powerful computer doesn't need to come into a big package. If Apple can squeeze a machine like the Air into a container that others have only been able to use for underpowered devices--such as the many netbooks currently on the market--imagine what it can do with a system like the MacBook Pro.