|
|
|
Windows Secrets Newsletter • Issue 200 • 2009-06-04 • Circulation: over 400,000 |
|
BONUS DOWNLOAD
|
|
Table of contents INTRODUCTION: I can't believe we've put out 200 newsletters TOP STORY: Windows 7 Starter Edition limits netbook designs KNOWN ISSUES: Problems confirmed with Vista Service Pack 2 WACKY WEB WEEK: Here's looking at you, Steven Seagal LANGALIST PLUS: Yes or no to firewall request to act as server? BEST SOFTWARE: Why you need to validate your downloads INSIDER TRICKS: Stop your ISP from tracking your Net usage |
|
ADS
|
|
INTRODUCTION I can't believe we've put out 200 newsletters
By
Brian Livingston
Numerous Windows geeks and I have brought you a lot of secrets since I first started publishing an e-mail newsletter called "Brian's Buzz on Windows" back in February 2003. After switching to, ahem, a better name (Windows Secrets) — and merging the old newsletter with Woody Leonhard's in 2004, Fred Langa's in 2006, and Gizmo Richards's in 2008 — we've put out 200 newsletters, and now we're celebrating by giving away for free my $9.95 antispam e-book, newly revised.
Actually, "revised" is stretching it. Spam-Proof Your E-Mail Address, 3rd Edition (photo, left) has been tweaked to bring some references up-to-date and add a new color cover. But there's just a single important change to the book's recommendations: one very useful free service bounced around among Web sites, and the service's new name and URL needed to be edited in throughout.As most Windows Secrets readers know by now, spammers use "harvester bots" to scrape e-mail addresses from Web sites. My e-book, based on studies by nonprofit research organizations, shows you how easy it is to protect your e-mail address inside images and encoded scripts whenever you really need to post your contact information. The most useful free service I know of for encoding e-mail addresses into Web-friendly (but not harvester-friendly) scripts is Hivelogic's Enkoder Form. I want all readers to have Enkoder's new URL: http://hivelogic.com/enkoder/form From now through July 1, every Windows Secrets subscriber can download my revised e-book for free. To get yours, simply use the following link to visit your preferences page, make sure the information there is up-to-date, and a download link will subsequently appear: All subscribers: Set your preferences and download your bonus Thanks for your support — we promise to keep digging up more secrets for you in the years to come. MS uses patch channel to install Firefox add-on It's been widely blogged that Microsoft can silently add an extension to Firefox when users install .NET Framework 3.5 Service Pack 1 and certain other updates. Readers asked us about this last week because of a May 29 article by Brian Krebs of the Washington Post. I enjoy Krebs's writing, but in this case he was apologizing for telling his readers earlier this year to install the .NET service pack. He didn't realize until later that Microsoft's Assistant 1.0 extension exposes Firefox to any .NET security holes that may be discovered. Even worse, Microsoft wrote the add-in in such a way that its Uninstall button was grayed out and unusable in Firefox. WS contributing editor Susan Bradley warned our paying subscribers on Feb. 5 and Feb. 12 not to install .NET 3.5 SP1 (and explained, if need be, how to uninstall it). I tip my hat to her excellent advice. No holes currently affect the latest .NET software, according to Secunia.com's .NET Framework 3.x advisory and Assistant 1.x advisory. But the security firm published in 2006, 2007, and 2008 four security warnings about flaws in the earlier .NET Framework 2.x. The most severe hole was rated "highly critical." A weakness that's currently undiscovered in .NET Framework 3.x might be exploited in the future. The extension that MS adds to Firefox implements a technology called ClickOnce. It allows .NET apps to be downloaded and executed within browsers other than Internet Explorer. Unfortunately, this technology can also allow hacked Web sites to infect PCs. Many Windows Secrets readers use Firefox because it suffers from fewer security holes than IE — and most people don't need .NET features — so I'm publishing in my free column today the following steps to remove Assistant 1.0 from Firefox: Step 1. Check whether the .NET Framework Assistant is installed. You may or may not have Assistant 1.0, even if you installed .NET Framework 3.5 SP1, so check this first. In Firefox, pull down the Tools menu and select Add-ons. In the Add-ons dialog box that appears (as shown in Figure 1), if you don't see .NET Framework Assistant, the add-on is not installed. In that case, you don't need to do anything further (except close the dialog box). ![]() Figure 1. The Uninstall button is grayed out and unusable due to the way Microsoft implemented the original version of Assistant 1.0. Step 2. Remove or disable the add-on. If you do find the extension, I recommend that you remove it to reduce your vulnerability to possible security flaws. Choose one of the options shown below. • Best option: Install the Microsoft fix. On May 6, with little publicity, Microsoft posted an update for .NET Framework 3.5 SP1. Installing this update enables Firefox's Uninstall button for the add-on. To install the official update, visit Microsoft's download page. • Another option: Temporarily disable the extension. Using the Add-ons dialog box to disable the extension prevents it from running and protects Firefox from potential security flaws. You might disable the extension instead of uninstalling it if your company insists that you use Firefox to run a .NET app, but you don't wish to be vulnerable when visiting random Web sites. To disable Assistant 1.0 (or any Firefox extension), pull down Firefox's Tools menu and select Add-ons. In the Add-ons dialog box that appears, select the unwanted extension and click the Disable button. Close the dialog box. • Not recommended: Edit the Registry. Before Microsoft's official patch was released, several sites published a procedure to manually delete entries from the Windows Registry to disable the Firefox extension. I don't recommend this, because it's easier and safer to use the options shown above. But if you need the full details, .NET Framework product unit manager Brad Abrams posted the Registry procedure in an MSDN blog entry. Step 3. Install the third-party extension FFClickOnce, but only if necessary. If you really need ClickOnce functionality in Firefox, consider installing FFClickOnce, a Mozilla-approved extension developed by James Dobson. This third-party extension poses some of the same risks as Microsoft's add-on. But at least Dobson's extension prevents downloaded apps from running without first making the user click OK twice. For more info, see Dobson's SoftwarePunk site and the extension's Mozilla Add-ons page. That's it. More information on .NET problems — and what to install and not install — will appear in future columns by Susan and our other contributors. Write 50 words and enter to win 1,000 pages From April 16 to May 6, Windows Secrets offered subscribers an exclusive bonus: a free download of "The Final Chapter," the thrilling conclusion to Stealing the Network, a book that hadn't yet shipped. The new hardcover volume is a collection of four previous books describing fictional high-tech security capers.
Now its publisher, Syngress (an imprint of Elsevier), is promising to send copies of the 1,000-page book — complete with a DVD of author interviews — free to 10 lucky Windows Secrets readers.If you were one of the thousands who downloaded "The Final Chapter" and you'd like the whole book for free, e-mail a 50-word review of the chapter to info (at) syngress.com. The publisher will display some of the reviews on its site and select 10 winners at random to receive the hardcover collector's edition. (By entering the contest, you agree to allow Syngress to e-mail you.) If you'd simply like to buy the collection, Syngress is also offering Windows Secrets readers a 20% discount — a U.S. $18 savings off the $90 list price. Enter the promotional code secrets at ElsevierDirect.com. (At the site, you may select one of nine fulfillment centers around the world.) Or use the company's special Stealing the Network link, and the promotional code will be entered for you. Offer expires July 15, 2009. Here's an even-better price break: anyone can get approximately 37% off the list price — a $33 savings — at Amazon.com. More info: United States / Canada / Elsewhere. Brian Livingston is editorial director of WindowsSecrets.com and co-author of Windows Vista Secrets and 10 other books. |
|
ADS
|
|
TOP STORY Windows 7 Starter Edition limits netbook designs
By
Woody Leonhard
Last week, Microsoft dropped its plan to enforce a three-concurrent-app limit on Windows 7 Starter Edition — the version of the new OS that will be preinstalled only on small PCs, such as netbooks. Microsoft is still expected, however, to restrict netbook hardware configurations that are eligible for Starter Edition pricing, which means your choices for cheap netbooks may be hobbled — at least in the near term. When Microsoft first unveiled the various versions of Windows 7 in February, the Windows Team blog explained the editions as follows:
Heaven knows why, but Starter Edition users can't even change the desktop background (wallpaper). In addition — as promised on the Windows Team blog — the Release Candidate Starter Edition was going to limit you to a maximum of three applications running simultaneously. That three-app restriction went over like a lead-filled balloon in a microburst. Windows 7 Starter Edition's planned three-concurrent-app limit drew brickbats from many corners. In practice, the three-app restriction didn't really mean much. Many programs didn't count toward the limit of three. Some apps — such as installers — counted against the limit but really shouldn't have. Microsoft never did articulate in simple, declarative sentences precisely which programs were included in the three-application limit. Ed Bott has a thorough accounting of the vagaries of the three-app rule on his ZDNet blog. In the end, common sense ruled, and Microsoft dropped the three-simultaneous-app limit, as the Windows Team blog described on May 29. Hooray for this ounce of sanity! SE is ultra-cheap, but netbooks don't need it Windows 7 embodies Microsoft's Great Hope to lock up the netbook software market. With Linux nipping at its heels, Microsoft desperately needs a cheap, hobbled version of Windows 7 to nail down the lowest-end PC models. From a marketing point of view, Microsoft is caught between a rock and a hard place. The 'Softies have to endow Starter Edition with enough glitz to get you to buy it preinstalled on netbooks, but at the same time the company wants to leave a bunch of feature carrots dangling on a software stick to get you to pay more for Windows 7 Home Premium, Business, or Ultimate. Don't be fooled: Windows 7 Home Premium works very well on most netbooks — the machines don't need Starter Edition. I've been running Windows 7 Ultimate on an Asus Eee PC 1000H since the earliest days of the beta, and Win7 works great. Despite what you may have read, Microsoft didn't devise Starter Edition to run on smaller, less-well-endowed computers. Rather, the company needed something cheaper than Home Premium to sell to the ultra-low-cost crowd. Keep that fact in mind while you sift through the marketing hype. Win7 Starter Edition's hardware restrictions Microsoft offers PC manufacturers a price break on copies of Windows XP that are preinstalled on netbooks. The company doesn't offer any breaks at all on copies of Windows XP that are sold on more-powerful laptops — in fact, those larger notebook PCs always include a license for Windows Vista, even if they ship with Windows XP. Although the details are highly confidential, it appears that Microsoft will enforce a similar restriction on sales of Windows 7 Starter Edition. According to the TechARP site, Microsoft will sell copies of Starter Edition to PC manufacturers only for installation on netbooks with limited processing ability. That's defined as those using a single-core processor, running slower than 2GHz, consuming fewer than 15 watts, having less than 1GB of system memory, and using screens 10.2 inches or smaller. If you work for a hardware manufacturer that's gearing up to produce large numbers of netbooks with 11-inch screens for sale during the 2009 holiday season, your summer vacation plans may have just gone out the window. An April 20 Wall Street Journal article (paid sub required) states: "People familiar with the matter say Microsoft takes in less than $15 per netbook for Windows XP once marketing rebates are taken into account — far less than the estimated $50 to $60 the company receives for PCs running Windows Vista." If that same differential of $35 to $45 holds true for Windows 7 Starter and Home Premium, you can bet netbook manufacturers are going to keep their low-cost offerings within Microsoft's limits. Microsoft's Win7 Starter Edition requirements may change at any point. But as long as they're in effect, Microsoft has forced hardware manufacturers to tone down their products running the low-cost version of the OS. That doesn't prevent netbook manufacturers from making bigger screens, using faster chips, or offering more system memory. However, those who offer better netbook configurations won't be able to include Starter Edition as part of the package. Instead, they'll have to ship their netbooks with Linux or a different — considerably more-expensive — edition of Windows 7. Controversies swirl around Win7 Starter Edition Some people see conspiracies behind every Microsoft move, and the Starter Edition hardware throttling is no exception. Certainly, by restricting Starter Edition to netbooks with screens smaller than 10.2 inches, companies planning to build netbooks with larger screens will face higher prices and, probably, lower margins. As explained in a DigiTimes article (paid sub required), some people see the netbook hardware upgrades as a competitive advantage for Intel over up-and-coming chip makers such as Via. You can insert your favorite Intel-Microsoft conspiracy theory here. In his InformationWeek blog, Dave Methvin — who's been covering Windows as long as I have, meaning since the last Ice Age — has this to say about Microsoft's Starter Edition hardware limitations:
One thing's for sure: we're in for an interesting ride with Starter Edition. Stay tuned! Woody Leonhard's latest books — Windows Vista All-In-One Desk Reference For Dummies and Windows Vista Timesaving Techniques For Dummies — explore what you need to know about Vista in a way that won't put you to sleep. He and Ed Bott also wrote the encyclopedic Special Edition Using Office 2007. |
|
KNOWN ISSUES Problems confirmed with Vista Service Pack 2
By
Dennis O'Reilly
Some early adopters have encountered installation glitches and software conflicts when attempting to apply Service Pack 2 for Windows Vista. As with nearly all service packs, there's no rush to install Vista SP2 — and when you do apply it, be ready with a full system backup, just in case. In the May 28 Patch Watch column (paid content), Susan Bradley recommended that you hold off on installing Vista SP2. Microsoft hasn't yet begun to push out the service pack via its Automatic Updates service, but some people who chose to apply SP2 now wish they'd waited. Among them is Ted Myers:
IE 8 causes Microsoft Money print failure Susan's column also described some of the glitches occurring with Internet Explorer 8, including conflicts with third-party firewalls and an inability to print information from Web pages. Brad Clarkson discovered a different IE 8 glitch when he attempted to use another Microsoft application:
Reader sends kudos for informative newsletter When the PC industry was young, dozens of print magazines sprang up to help us make sense of these convoluted machines. The medium may have changed, but the goal remains the same, as a reader named Bud points out:
The Known Issues column brings you readers' comments on our recent articles. Dennis O'Reilly is technical editor of WindowsSecrets.com. |
|
WACKY WEB WEEK Here's looking at you, Steven Seagal
|
|
ADS
|
|
PERMALINKS Use these permalinks to share info with friends We love it when you include the links shown below in e-mails to your friends. This is better than forwarding your copy of our e-mail newsletter. (When our newsletter is forwarded, some recipients click "report as spam," and corporate filters start blocking our e-mails.) The following link includes all articles this week: http://WindowsSecrets.com/comp/090604 Free content posted on June 4, 2009:
You get all of the following in our paid content:
Thanks in advance for your support! |
|
YOUR SUBSCRIPTION The Windows Secrets Newsletter is published weekly on the 1st through 4th Thursdays of each month, plus occasional news updates. We skip an issue on the 5th Thursday of any month, the week of Thanksgiving, and the last two weeks of August and December. Windows Secrets resulted from the merger of several publications: Brian's Buzz on Windows and Woody's Windows Watch in 2004, the LangaList in 2006, and the Support Alert Newsletter in 2008. Publisher: WindowsSecrets.com LLC, Attn: #120 Editor, 1700 7th Ave., Suite 116, Seattle, WA 98101-1323 USA. Vendors, please send no unsolicited packages to this address (readers' letters are fine). Editorial Director: Brian Livingston. Senior Editor: Ian Richards. Editor-at-Large: Fred Langa. Technical Editor: Dennis O'Reilly. Program Director: Tony Johnston. Program Manager: Ryan Biesemeyer. Web Developer: Damian Wadley. Research Director: Katy Abby. Copyeditor: Roberta Scholz. Contributing Editors: Susan Bradley, Scott Dunn, Mark Joseph Edwards, Michael Lasky, Woody Leonhard, Ryan Russell, Becky Waring. Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, Support Alert, LangaList, LangaList Plus, WinFind, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of WindowsSecrets.com LLC. All other marks are the trademarks or service marks of their respective owners. HOW TO SUBSCRIBE: Anyone may subscribe to this newsletter by visiting our free signup page. WE GUARANTEE YOUR PRIVACY: 1. We will never sell, rent, or give away your address to any outside party, ever. 2. We will never send you any unrequested e-mail, besides newsletter updates. 3. All unsubscribe requests are honored immediately, period. Privacy policy HOW TO UNSUBSCRIBE: To unsubscribe from the Windows Secrets Newsletter,
|