Windows Secrets

 

 

   
       
   
Windows Secrets Newsletter • Issue 209 • 2009-08-06 • Circulation: over 400,000

   
   
AD

Make your PC run like new

   Make your PC run like new
Tired of your unstable and crashing PC? Looking for a permanent solution for your dysfunctional XP? Don't compromise — get our new, state-of-the-art technology. Reimage requires no setup and causes no loss of data or applications. This is the ultimate professional repair tool, which works like "magic," according to eWeek. Get a free Reimage PC booster with every scan. Try it now!
Reimage


   
   
Table of contents
TOP STORY: Gmail flaw shows value of strong passwords
KNOWN ISSUES: Navigating the maze of Microsoft patches
WACKY WEB WEEK: Go really green with Taco Bell's artificial food
LANGALIST PLUS: Diagnose and repair network-connection glitches
BEST SOFTWARE: Give Vista the best features of Windows 7
WOODY'S WINDOWS: Time to dump Outlook Express and Windows Mail

   
       
   
ADS

Free PC performance scan   Free PC performance scan
"I repair computers for a living and was looking for a utility that would simply do what usually took me hours. PC Pitstop's Optimize did all of it and more. I am very satisfied with the product and have recommended it to numerous clients." Larry, CA ... Run a free PC Optimize scan now!
PC Pitstop

Computer parts, accessories, and security   Computer parts, accessories, and security
Supplier of low-cost computer parts and accessories. Quantity discounts on all items. Computer cables, adapters, and converters | power strips and cords | network/telephone cables and parts | internal PC cables | tool kits | fiber optics | security | TV mounts.
Computer Parts Plus

Move software and files to a new PC easily   Move software and files to a new PC easily
Easy, virus-free transfers of files and applications between computers. SoftRescue saves you time and money by moving applications, files, settings, and e-mail automatically. No CDs or keys needed for most applications. The only utility that leaves your new computer free from viruses, spyware, and malware! Multiple transfers with one license. Now only $39.95 for box or download.
SoftRescue

See your ad here

   
   
TOP STORY

Gmail flaw shows value of strong passwords

Becky Waring By Becky Waring

The disclosure of a back door allowing bad guys to repeatedly guess Gmail passwords should remind us all to protect our accounts with long and strong character strings.

There's a straightforward way to protect your online accounts — use signin phrases that are easy for you to remember but hard for others to guess.

The latest vulnerability affecting Gmail accounts was recently revealed by security researcher Vicente Aguilera Díaz in a posting on the Full Disclosure security list. (Aguilera previously revealed a Gmail flaw known as session-riding, which Google subsequently fixed, as reported by WS contributing editor Scott Spanbauer on April 23 and May 7.)

According to Aguilera's new security alert, Google allows anyone with a Gmail account to guess another Gmail user's password 100 times every two hours, or 1,200 times per day. No "captcha" keeps hacker bots from guessing passwords in this way. Worst of all: If a hacker controls, say, 100 Gmail accounts, 120,000 guesses can be made per day. Because Gmail accounts are free, many hackers control far more than 100 accounts, of course.

To its credit, Gmail requires fairly long passwords of 8 characters or more. However, as Aguilera points out, Gmail allows users to create extremely weak passwords such as aaaaaaaa.

A quick survey of my friends and relatives revealed that not one of them uses strong passwords. Most people have no idea how to create them. Yet everyone I asked expressed guilt at using easy-to-crack passwords: pet names, birthdays, and common dictionary words.

Most people's passwords could be guessed in far fewer than 10,000 attempts. And, despite using weak passwords, the people I interviewed say they rarely change their signin strings. (One-third of the people surveyed use the same password for every Web site they sign in to, and the infamous Conficker worm needed to try only 200 common passwords to break into many systems, according to an analysis by the Sophos security firm.)

Here's the topper: many respondents to my informal survey admitted to keeping an unencrypted file on their systems that lists every password they use!

You may not think the password to your webmail account is valuable. But anyone with access to your account can use it to send spam and ruin your online reputation. More seriously, you may have entered the same password at an online banking site, such as PayPal, or a site where your credit-card number is stored for easy ordering, such as Amazon.

Use tough passwords but make them easy to recall

You can see whether your current passwords — you do use more than one, right? — are rated "strong" by using Microsoft's online Password Checker. I bet you'll be unpleasantly surprised by the results.

Microsoft's Password Checker
Figure 1. Test the strength of your passwords by entering them in Microsoft's Password Checker.

The three keys to strong passwords are length, randomness, and use of different types of characters. Each additional character multiplies the potential combinations a brute-force attack must try.

Random passwords use upper- and lower-case letters, numbers, and symbols. When at least three of these four categories are used, an eight-character password should suffice in most instances. According to the FrontLine security site, such a password would take a century or more to crack by a hacker using a single PC. The eight-character standard is also the minimum the Microsoft Password Checker deems "strong." Of course, the more characters in your password, the safer you'll be.

If you wish to create your own password, use a sentence or phrase you can recall easily and then tweak it for each account.

For example, start with the phrase "all good things come to those who wait." Then take the second letter of each word — or the only letter in the case of single-character words — to yield lohoohha. Then use upper case for every other consonant and substitute numerals or punctuation for certain vowels: loHooHh@.

(Never use any password-creation system you've read in a book or on the Web, including the example in the preceding paragraph. The password crackers read these articles, too.)

You can be as creative as you want with your rules. The goal is to produce a random-seeming combination of letters, numbers, and special characters — one generated by a set of rules you can remember and recreate.

Next, add a few characters denoting the site or the account for which the password is required. For example, you could add the first three letters of the site URL to the beginning, middle, or end of your base password, but five letters later in the alphabet, so "ama" for Amazon.com becomes frf.

By this time, you'll likely have a password that's at least 8 to 16 characters long and fairly random-looking — strong by any measure. When you need to change a password, keep the same rules and change just the base phrase.

Dos and don'ts to keep your passwords safe

Now that you know how to create strong passwords, follow these ten tips for using and protecting them.

  • DO use a password manager such as those reviewed by Scott Dunn in his Sept. 18, 2008, Insider Tips column. Although Scott focused on free programs, I really like CallPod's Keeper, a $15 utility that comes in Windows, Mac, and iPhone versions and allows you to keep all your passwords in sync. Find more information about the program and a download link for the 15-day free-trial version on the vendor's site.

    Callpod Keeper password manager
    Figure 2. Callpod's Keeper password-management utility lets you sync passwords between Windows and Mac PCs and iPhones.

  • DO change passwords frequently. I change mine every six months or whenever I sign in to a site I haven't visited in long time. Don't reuse old passwords. Password managers can assign expiration dates to your passwords and remind you when the passwords are about to expire.

  • DO keep your passwords secret. Putting them into a file on your computer, e-mailing them to others, or writing them on a piece of paper in your desk is tantamount to giving them away. If you must allow someone else access to an account, create a temporary password just for them and then change it back immediately afterward.

    No matter how much you may trust your friends or colleagues, you can't trust their computers. If they need ongoing access, consider creating a separate account with limited privileges for them to use.

  • DON'T use passwords comprised of dictionary words, birthdays, family and pet names, addresses, or any other personal information. Don't use repeat characters such as 111 or sequences like abc, qwerty, or 123 in any part of your password.

  • DON'T use the same password for different sites. Otherwise, someone who culls your Facebook or Twitter password in a phishing exploit could, for example, access your bank account.

  • DON'T allow your computer to automatically sign in on boot-up and thus use any automatic e-mail, chat, or browser signins. Avoid using the same Windows signin password on two different computers.

  • DON'T use the "remember me" or automatic signin option available on many Web sites. Keep signins under the control of your password manager instead.

  • DON'T enter passwords on a computer you don't control — such as a friend's computer — because you don't know what spyware or keyloggers might be on that machine.

  • DON'T access password-protected accounts over open Wi-Fi networks — or any other network you don't trust — unless the site is secured via https. Use a VPN if you travel a lot. (See Ian "Gizmo" Richards' Dec. 11, 2008, Best Software column, "Connect safely over open Wi-Fi networks," for Wi-Fi security tips.)

  • DON'T enter a password or even your account name in any Web page you access via an e-mail link. These are most likely phishing scams. Instead, enter the normal URL for that site directly into your browser, and proceed to the page in question from there.
Following these tips will help you keep your personal data safe online.

WS contributing editor Becky Waring has worked as a writer and editor for CNET, ZDNet, Technology Review, Upside Magazine, and many other news sources.

Table of contents

   
   
ADS

Scan, repair, and optimize your system   Scan, repair, and optimize your system
RegistryWizard's free scan automatically identifies Registry problems and provides a complete Registry report detailing harmful system conflicts and errors. RegistryWizard cleans your Registry, safely fixes PC errors, and optimizes your system for peak performance. Give us just 2 minutes and we guarantee that your PC will run better, faster, and error-free!
RegistryWizard

"Who wants a faster computer?"   "Who wants a faster computer?"
Now, at last, an easy, proven PC optimization formula that works in speeding up your PC without spending a penny on expensive hardware or complicated software — guaranteed!
PC Secret Formula

Get Windows news and tech tips daily   Get Windows news and tech tips daily
Replenish your mind with tech excellence! Visit the Infopackets site right now and get your daily fix of Windows news, reviews, tech tips, plus freeware goodies daily. Bonus: join our mailing list today and you'll also receive our highly coveted Top 10 Tech Reports, including PC Security Essentials, Windows Optimization Secrets, Top Freeware Antivirus Reviewed, MS Office Alternatives, and more.
Infopackets Windows Newsletter

See your ad here

   
   
KNOWN ISSUES

Navigating the maze of Microsoft patches

Dennis O'Reilly By Dennis O'Reilly

The numbering system Microsoft uses to identify its various Windows updates and the security bulletins referencing them often leaves us scratching our heads.

Just determining whether your PC has all the patches it needs can be like deciphering a secret code.

In describing last week's out-of-cycle Windows patches, Susan Bradley's July 30 Top Story linked to Microsoft security bulletins MS09-034 and MS09-035. Unfortunately, this information left Jim Long perplexed:
  • "I just read 'Install MS's out-of-cycle patches for IE, apps' by Susan Bradley in Issue 208, 2009-07-30. It was clearly written, and I understand the need for the patches.

    "Maybe I'm uneducated or alone in this, but I cannot seem to get the hang of this patching stuff. I went to the security bulletin as recommended, but it doesn't seem to contain the information needed to download the recommended patches. Then I ran Windows Update, as recommended by the security bulletin. It found no unapplied, high-importance patches.

    "So then I went to Control Panel, with 'Show updates' turned on. For some reason, it shows patches according to Knowledge Base article number. I have no idea what the Knowledge Base numbers are for MS09-034 or MS09-035. As a result, I have no idea whether the patch suggested is on my system or not."
Windows Secrets columns place the patch number corresponding to a security bulletin in text directly above each section's headline. For example, in Susan's July 30 Top Story, security bulletin MS09-034 corresponds to patch number 972260 and was shown at the top of the discussion like this:

MS09-034 (972260)
Apply this Internet Explorer patch today

Microsoft security bulletins include links to the patch download pages in the "Affected Software" section at the top of each bulletin. Finding the correct update that applies to your particular system, however, can be a challenge. A different patch is listed for every version of the operating system and every affected application.

The simplest way to download patches is to visit the Microsoft Update site and install the needed files using the Custom option. To verify in Microsoft Update whether a particular patch has been installed, click Review your update history in XP or View update history in Vista.

Another option is to open the Add or Remove Programs applet in the Control Panel of XP. (In Vista, the applet is called Programs and Features.) Make sure Show updates is checked in XP, or click View installed updates in Vista. Look for the updates by installation date and/or their patch number.

We'll be providing much more detail on managing the software-update process in a Windows Secrets Newsletter coming soon to an inbox near you.

Reader Jim Long will receive a gift certificate for a book, CD, or DVD of his choice for sending a comment we printed. Send us your tips via the Windows Secrets contact page.

The Known Issues column brings you readers' comments on our recent articles. Dennis O'Reilly is technical editor of WindowsSecrets.com.

Table of contents

   
   
ADS

Save up to 76% on quality inkjet ink   Save up to 76% on quality inkjet ink
We offer the sharpest prices on the Web for quality ink and laser toner. Bonus: save an extra 10% by using coupon code DPL7349X. Free shipping to contiguous U.S. locations for all orders over $50. Offer expires 9/30/2009 and excludes OEM items.
4InkJets

Your old drivers are slowing down your PC   Your old drivers are slowing down your PC
Driver Detective provides the most up-to-date drivers specific to your computer, including all major-brand OEMs (Dell, HP, Compaq, Toshiba, etc.) and generic brands. We access a database of over 9.2 million device-associated drivers — the largest driver update database on the Internet. Driver Detective saves you endless hours of work and aggravation normally associated with updating drivers.
Driver Detective

Get your message seen by 400,000 readers   Get your message seen by 400,000 readers
Does your company offer a product or service? Now you can place an ad in the Windows Secrets Newsletter and be seen by more than 400,000 active buyers of PC hardware and software. Bid as much or as little as you like to get the ideal ad placement. Take advantage of our all-new design interface, allowing larger images and longer text, and get updated stats in real time!
Windows Secrets Newsletter

See your ad here

   
   
WACKY WEB WEEK

Go really green with Taco Bell's artificial food

Taco Bell green menu By Stephanie Small

Think you know what it's like to be green? Perhaps you recycle compulsively, use earth-friendly cleaning products, drive a hybrid, and wear only organic clothing. Or maybe you believe simply eating organic food is enough to reduce your carbon footprint.

Taco Bell has come up with what is truly the greenest thing you could do. For a limited time only, all items on the menu will be environmentally sound, taking none of their ingredients from nature. Beef, lettuce, and practically everything else will be replaced with artificial alternatives — which may not be much different than what the company's been selling for years. So grab a chalupa or burrito and taste the future! Play the video

Table of contents

   
   
BONUS DOWNLOAD

Windows 7 All-in-One for Dummies download
Everything Windows 7 available at your fingertips
This month's free bonus download for all our subscribers is Windows 7 All-in-One for Dummies by our very own contributing editor Woody Leonhard. The book provides valuable information about making the transition to Windows 7 for the novice to the expert computer user. The printed volume isn't in stores yet, but all subscribers can receive our exclusive excerpt of two full chapters now through September 9. Simply visit your preferences page, save any changes, and a download link will appear. Thanks! —Brian Livingston, editorial director

All subscribers: Set your preferences and download your bonus
Info on the printed book: United States / Canada / Elsewhere

   
   
PERMALINKS

Use these permalinks to share info with friends

We love it when you include the links shown below in e-mails to your friends. This is better than forwarding your copy of our e-mail newsletter. (When our newsletter is forwarded, some recipients click "report as spam," and corporate filters start blocking our e-mails.)

The following link includes all articles this week: http://WindowsSecrets.com/comp/090806

Free content posted on August 6, 2009:

 
You get all of the following in our paid content:

Get our paid content by making any contribution

12 months of paid content

There's no fixed fee! Contribute whatever it's worth to you
Readers who make a financial contribution of any amount by August 12, 2009, will immediately receive the latest issue of our full, paid newsletter and 12 months of new paid content. Pay as much or as little as you like — we want as many people as possible to have this information.
 
Maria in Ecuador

A portion of your support helps children in developing countries
Each month, we send a full year of sponsorship to a different child. Your contributions in August are helping us to sponsor Maria, a 3-year-old girl from Ecuador. Children International channels development aid from donors to Maria and her community. We also sponsor kids through Plan USA and other respected agencies. More info

Use the link below to learn more about the benefits of becoming a paid subscriber!

More info on how to upgrade

Thanks in advance for your support!

   
   

Table of contents

   
   
YOUR SUBSCRIPTION

The Windows Secrets Newsletter is published weekly on the 1st through 4th Thursdays of each month, plus occasional news updates. We skip an issue on the 5th Thursday of any month, the week of Thanksgiving, and the last two weeks of August and December. Windows Secrets resulted from the merger of several publications: Brian's Buzz on Windows and Woody's Windows Watch in 2004, the LangaList in 2006, and the Support Alert Newsletter in 2008.

Publisher: WindowsSecrets.com LLC, Attn: #120 Editor, 1700 7th Ave., Suite 116, Seattle, WA 98101-1323 USA. Vendors, please send no unsolicited packages to this address (readers' letters are fine).

Editorial Director: Brian Livingston. Senior Editor: Ian Richards. Editor-at-Large: Fred Langa. Technical Editor: Dennis O'Reilly. Program Director: Tony Johnston. Web Developer: Damian Wadley. Research Director: Stephanie Small. Research Analyst: Allison Espiritu. Copyeditor: Roberta Scholz. Contributing Editors: Susan Bradley, Scott Dunn, Michael Lasky, Woody Leonhard, Ryan Russell, Scott Spanbauer, and Becky Waring.

Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, Support Alert, LangaList, LangaList Plus, WinFind, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of WindowsSecrets.com LLC. All other marks are the trademarks or service marks of their respective owners.

HOW TO SUBSCRIBE: Anyone may subscribe to this newsletter by visiting our free signup page.

WE GUARANTEE YOUR PRIVACY:

1. We will never sell, rent, or give away your address to any outside party, ever.
2. We will never send you any unrequested e-mail, besides newsletter updates.
3. All unsubscribe requests are honored immediately, period.  Privacy policy

HOW TO UNSUBSCRIBE: To unsubscribe from the Windows Secrets Newsletter,
Copyright © 2009 by WindowsSecrets.com LLC. All rights reserved.

Table of contents