|
|
|
Windows Secrets Newsletter • Issue 210 • 2009-08-13 • Circulation: over 400,000 |
|
AD
|
|
Table of contents TOP STORY: Sun, Apple, Microsoft install chaff with patches KNOWN ISSUES: Gmail activity log helps you detect hijacking WACKY WEB WEEK: Water fights that will make you cry uncle LANGALIST PLUS: Free utilities make Windows smaller, faster IN THE WILD: Laptop rootkit is widespread but likely harmless PATCH WATCH: Heavy patch week to block Web-based attacks |
|
ADS
|
|
TOP STORY Sun, Apple, Microsoft install chaff with patches
By
Susan Bradley
When you apply a security update for one of the programs on your PC, beware of uninvited software that wants to come along for the ride. Vendors are more and more often going over the line, piggy-backing unsolicited commercial products and services onto crucial security patches. If you're like many people, you were tricked into installing Apple's Safari browser as part of an iTunes or QuickTime update — a marketing tactic the company has been employing for more than a year. (I reported in my March 27, 2008, Patch Watch column that Apple had quietly started installing its browser using a little-noticed check box.) You may also have succumbed to Microsoft's incessant offer of Silverlight and Office Live as part of the Microsoft Update service. And you may have tired of saying "no!" to downloading Internet Explorer 8. (I don't feel IE 8 is a necessary upgrade, due to IE 7's relative security and IE 8's incompatibility with some sites, as I describe below.) Now, the latest Sun Java update shows how cavalier some vendors have become in taking advantage of software updates, including vital security patches. The latest Sun Java SE Update 16 (6u16), released on Aug. 11, includes seven security updates and fixes a few bugs. What the release notes don't document, however, is that this update comes with a surprise. The download process starts out normally enough, with the usual coffee-cup update icon in the notification area of Windows' taskbar. (See Figure 1.) Figure 1. Sun's Java icon — the coffee cup at the far left — indicates the availability of an update. However, after you begin the update, a confusing offer to download and install a 30-day trial of Carbonite Inc.'s commercial backup software appears. A small check box is preselected for download and installation. (See Figure 2.) ![]() Figure 2. The option to install a trial version of Sun's Carbonite backup software is prechecked in the Java updater. Some Java patchers are not offered Carbonite but instead get Microsoft's Bing search toolbar, which is preselected on many systems. (See Figure 2.) ![]() Figure 3. Sun's Java updater preselects the option to install Microsoft's Bing search toolbar for IE along with the Java update. That's right, ladies and gentlemen. Not only may we have to uninstall random toolbars if we're not careful with our Java updates, now we have to remove trial versions of commercial software that vendors quietly attached to a security update. Microsoft pushes IE 8 as 'critical' to your PC Microsoft is one of the biggest offenders in promoting nonsecurity updates via its security mechanism. First in 2006, and again in 2007, the Redmond company installed its intrusive Windows Genuine Advantage app as though it were a "critical security upgrade," as I described in a June 14, 2007, column. In the latest such case, you'll find that Microsoft has prechecked Internet Explorer 8 when you use Automatic Updates and choose the option to view available updates. The company argues that IE 8 is a critical update to your operating system. In reality, the program may conflict with other software on your PC. I'm postponing deployment of IE 8 on my computers, because I continue to encounter compatibility problems in my testing. The glitches are slowly being resolved, but I'm still not ready to give a blanket recommendation to upgrade to IE 8, nor am I comfortable applying it to the production systems I manage. (I described the problems and some solutions in a column on May 28.) As the person in charge of managing PCs in my company, I need to test the program before it's installed on production systems. By preselecting the IE 8 installation, Microsoft eliminates my ability to conduct responsible testing. Even while claiming that IE 8 is a critical update, Microsoft continues to support the hopeless old version 6 of IE, as stated on the company's IEBlog. IE 6 long ago stopped being a defensible browser and cannot now be considered secure by any stretch of the imagination. If you're still running IE 6, you should upgrade to IE 7 immediately. If your company uses a line-of-business app that requires IE 6, isolate that machine from the Internet and use it only until that app is upgraded. Installing IE 8, however, should be considered optional and should not be associated with security patches. (In an unrelated move, IE 8 will no longer silently make itself a PC's default browser when users select the Express installation option. The change was revealed in a U.S. Department of Justice antitrust compliance report, as reporter Grant Gross explains in an IDG News Service article.) Let's put a halt to any marketing in updates I understand that the publishers of "free" software sometimes need to push other programs that generate revenue. Whenever a vendor is offering useful software at no cost, I'm willing to consider some software bundles at the time of original download. To avoid tricky bundles, you should consult sites offering advice about specific problems. One of the best is the Calendar of Updates' Installers Hall of Shame, which lists uninvited programs that ride along with various apps. It's a completely different matter to use security updates to sneak software onto our PCs — there's simply no other term for it. Corrupting a vendor's security channel to promote a marketing opportunity violates our fundamental right to control the programs installed on our systems. When it comes to bug fixes and security patches, I need to be able to trust that the changes vendors are making to my system are intended only to protect me. I strongly object to attempts to install any nonessential software as part of the update process. To me, the marketing tie-ins described above step way over the line. I hope you'll join me in urging software vendors to limit security updates to nothing but security updates. Susan Bradley recently received an MVP (Most Valuable Professional) award from Microsoft for her knowledge in the areas of Small Business Server and network security. She's also a partner in a California CPA firm. |
|
ADS
|
|
KNOWN ISSUES Gmail activity log helps you detect hijacking
By
Dennis O'Reilly
A line at the bottom of the Gmail window indicates when your account was last used and also links to more-complete usage info. You can use this activity log to determine whether someone has guessed your password and taken over your account. In the Aug. 6 Top Story, "Gmail flaw shows value of strong passwords," WS contributing editor Becky Waring explained how to create strong passwords that are easy to remember. Her story was inspired by the disclosure of a Gmail weakness that allows hackers to test thousands of passwords per day and take over poorly defended accounts. A reader named James points out that the Gmail activity log can alert you to unauthorized use of your account:
![]() Figure 1. View recent activity on your Gmail account to determine whether someone other than you has signed in. (All IP addresses are obscured in this image.) If you find unfamiliar IP addresses or activity recorded when you weren't using the account, reset your password immediately and notify Google of the breach. Microsoft's ambiguous advice on strong passwords When it comes to crafting strong passwords, it can be difficult to know whom to believe, especially when the same source offers conflicting advice. A reader who goes by the name of RockDoc was befuddled by contradictory information on Microsoft's site:
If anyone has evidence that Microsoft transmits across the Internet the passwords entered into this browser app, let us know immediately using the Windows Secrets contact page. Bill McGarry reports that Microsoft's app rates an entered password as "strong" if it is merely eight or more characters in length and has two out of three of the following: both uppercase and lowercase letters, one or more numerals, and some punctuation mark. To be sure, those are good rules of thumb, but Password1 (one of the first strings an attacker would try) would receive a "strong" rating. Several people told us about other password-strength checkers. One that goes to greater lengths than Microsoft in explaining what constitutes a weak or strong password is Password Meter. It's available as an online password checker and also as a downloadable freeware program. You can find both at the Password Meter site. No matter how strong a password you select, it won't remain secret if you enter it on a machine that's infected with a keylogger. For this reason, you shouldn't sign in to online banking sites at random Internet cafés or any place without good antivirus protection. Ensure passwords remain useful to your heirs Becky's article recommends that you avoid writing your passwords on sticky notes or saving them in an unencrypted text file on your PC. However, there's one instance when this otherwise-sound advice doesn't apply, as Allan Treadwell explains:
For the ultimate — and I do mean ultimate — in online security, check out a service such as Legacy Locker, which promises to "grant access to online assets for friends and loved ones in the event of loss, death, or disability." A free trial account lets you protect three assets, assign one beneficiary, and create one "legacy letter." For U.S. $30 a year or a one-time fee of $300, you can protect an unlimited number of assets, assign any number of beneficiaries, create as many legacy letters as you wish, back up important documents, and even upload a "good-bye" video. Can I leave my folder full of corrupted Office files to Steve Ballmer?
The Known Issues column brings you readers' comments on our recent articles. Dennis O'Reilly is technical editor of WindowsSecrets.com. |
|
ADS
|
|
WACKY WEB WEEK Water fights that will make you cry uncle
|
|
BONUS DOWNLOAD
|
|
PERMALINKS Use these permalinks to share info with friends We love it when you include the links shown below in e-mails to your friends. This is better than forwarding your copy of our e-mail newsletter. (When our newsletter is forwarded, some recipients click "report as spam," and corporate filters start blocking our e-mails.) The following link includes all articles this week: http://WindowsSecrets.com/comp/090813 Free content posted on Aug. 13, 2009:
You get all of the following in our paid content:
Thanks in advance for your support! |
|
YOUR SUBSCRIPTION The Windows Secrets Newsletter is published weekly on the 1st through 4th Thursdays of each month, plus occasional news updates. We skip an issue on the 5th Thursday of any month, the week of Thanksgiving, and the last two weeks of August and December. Windows Secrets is a continuation of four merged publications: Brian's Buzz on Windows and Woody's Windows Watch in 2004, the LangaList in 2006, and the Support Alert Newsletter in 2008. Publisher: WindowsSecrets.com LLC, Attn: #120 Editor, 1700 7th Ave., Suite 116, Seattle, WA 98101-1323 USA. Vendors, please send no unsolicited packages to this address (readers' letters are fine). Editorial Director: Brian Livingston. Senior Editor: Ian Richards. Editor-at-Large: Fred Langa. Technical Editor: Dennis O'Reilly. Program Director: Tony Johnston. Web Developers: Dan Engler, Damian Wadley. Research Director: Stephanie Small. Research Analyst: Allison Espiritu. Copyeditor: Roberta Scholz. Contributing Editors: Susan Bradley, Scott Dunn, Michael Lasky, Woody Leonhard, Ryan Russell, Robert Vamosi, Becky Waring. Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, Support Alert, LangaList, LangaList Plus, WinFind, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of WindowsSecrets.com LLC. All other marks are the trademarks or service marks of their respective owners. HOW TO SUBSCRIBE: Anyone may subscribe to this newsletter by visiting our free signup page. WE GUARANTEE YOUR PRIVACY: 1. We will never sell, rent, or give away your address to any outside party, ever. 2. We will never send you any unrequested e-mail, besides newsletter updates. 3. All unsubscribe requests are honored immediately, period. Privacy policy HOW TO UNSUBSCRIBE: To unsubscribe from the Windows Secrets Newsletter,
|