|
|
|
Windows Secrets Newsletter • Issue 250 • 2010-07-01 • Circulation: over 400,000 |
|
AD
|
|
Table of contents INTRODUCTION: All subscribers get a free book excerpt TOP STORY: Office 2010's Web tools raise security questions LOUNGE LIFE: Unresponsive USB drivers stump Lounge member WACKY WEB WEEK: The sound of Tweeting takes to the streets LANGALIST PLUS: Graphics card stuck in nonworking mode INSIDER TRICKS: Good reasons not to install 64-bit Office 2010 WOODY'S WINDOWS: The ultimate software deal has strings attached |
|
ADS
|
|
INTRODUCTION All subscribers get a free book excerpt
By
Tracey Capen
We like to give loyal Windows Secrets subscribers a little something extra when we can. This month, every subscriber can download a two-chapter excerpt of the new book Hacking Exposed Wireless, Second Edition by Johnny Cache, Joshua Wright, and Vincent Liu. Hacking Exposed Wireless provides valuable updated information you need to keep your wireless networks safe from potential hackers.
New chapters in this second edition cover the latest strategies used by hackers to attack wireless Ethernet and Bluetooth networks. The new volume also gives detailed countermeasures you can use to secure your wireless systems.The book provides vital information on how to access your networks' security, plus techniques for developing your own custom wireless security tools. It also covers current laws and regulations affecting wireless networks. The printed volume isn't in stores yet, but all subscribers can receive our exclusive excerpt of two full chapters through August 4. Simply visit your preferences page, save any changes, and a download link will appear. Here's the preferences link: Set your preferences and download your bonus More info on the printed book: United States / Canada / Elsewhere Thanks for your continuing and valuable support! Tracey Capen is technical editor of WindowsSecrets.com. His technical journalism career spans more than two decades, including 10 years as executive editor of reviews at PC World and, prior to that, as managing editor of reviews at InfoWorld. |
|
TOP STORY Office 2010's Web tools raise security questions
By
Yardena Arar
Microsoft's newest Office adds some nifty Internet features, including easy access to shared documents via SkyDrive and PowerPoint Broadcast. But putting personal and business information into the cloud opens up potential security risks that all Office 2010 users should be aware of. Microsoft says it has done its best to balance conflicting demands of convenience and security. Still, security experts say Office 2010's Web-connectedness could present new opportunities for snoops and hackers. This concern isn't about some obscure Office capability — these potential threats touch on at least two of the suite's coolest new features: SkyDrive and PowerPoint Broadcast. The former lets you easily share documents with colleagues, either via Office desktop apps or the new Office Web Apps. And with a simple Web link, anyone with a free Windows Live account can now run a PowerPoint 2010 slideshow, viewable by any remote user with a desktop browser. At the very least, people who use these features should understand exactly what degree of security is and isn't provided. You get secure transit, but unencrypted storage As Michael Lasky reported in his June 24 Top Story, SkyDrive uses SSL encryption to protect data in transit from your PC to Microsoft's servers. But once a file arrives at its destination, security depends almost entirely on user authentication — password protection, to be more specific. "If anyone manages to compromise their credential system, you have a problem," says Nasuni CEO Andres Rodriguez. Nasuni sells businesses client-server technology that encrypts sensitive documents before they're stored online. SkyDrive's dependence on user authentication is no different from that of many other Web applications that manipulate stored data such as Web-based e-mail; none encrypt the data on their servers, Rodriguez says. "There's no encryption at rest. There can't be. The Microsoft servers have to be able to understand that data [the format] to represent it to you [via Office desktop or Web apps]," he explains. Thus, security measures must focus on controlling access to servers, whether by physical means or by hacking or bypassing the password system. In an e-mail, Microsoft spokesman Scott Massey described the measures in place to provide such protection. "Once your files are on our servers, we work to prevent hackers from accessing your data by employing sophisticated physical and electronic security measures. We also store multiple copies of your file on different servers and hard drives to help protect your data from hardware failure." Businesses face biggest cloud-computing threat For most consumers, Microsoft's cloud-security safeguards are most likely superior to their own, especially in terms of redundant data backups. But businesses may be uncomfortable with the many ways most Web services (not just SkyDrive) can be compromised — even when individual business users are careful. "The problem could be with the [business] owner setting the incorrect permissions, or a bug in the hosting provider's solution which could leak potentially damaging information," says Symantec Security Response researcher Vikram Thakur. Thakur points out that, since one reason for using SkyDrive is to easily share documents, permission settings are vitally important. "One minor setting ignored could potentially allow your files to be shared with everyone." "I'm not sure that an enterprise would be happy that it's that easy to put Office documents on SkyDrive," says Adi Ruppin of Confidela, whose WatchDox add-ons for Office encrypt documents before they are sent to others. Ruppin says Office 2010's Web features appear to be designed with sharing rather than security in mind. He adds, "Once you put stuff online and you share it, you lose control." Nasuni's Rodriguez concurs: "This model of running applications in the cloud may be appealing to consumers, but many businesses are going to have a problem with it." Businesses such as Nasuni and Confidela are, of course, depending on that perception. PowerPoint Broadcast opens up potential risks The new broadcasting feature in PowerPoint 2010 is impressive in action: click the broadcast button in the slideshow tab and sign in to your Windows Live account. Within a few seconds (while the presentation is uploaded to Microsoft's servers), a pop-up window presents you with a URL to distribute to your audience — usually via e-mail or instant message. (See Figure 1.) When they click on the link, they will see your slides in their browser — with you controlling the presentation. But the potential for security breaches may be greater here than with SkyDrive. The presentation is not sent using SSL encryption — it's a garden-variety http:// URL. The primary protection from hackers and snoopers is each presentation's unique and rather lengthy assigned ID, which is embedded in the URL. ![]() Figure 1. PowerPoint 2010 includes the ability to quickly broadcast live presentations through the use of a uniquely coded link. Microsoft spokesman Massey says the presentations are quickly deleted from Microsoft's servers once the broadcast ends. But Rodriguez says the threat here is not so much to document privacy as it is to PC security. "This is just an unsigned, unsecure connection to someone else." He adds that a hacker who hijacks the link could potentially use it to distribute malware. Business customers have security options not available to consumers using the free Web offerings. In his e-mail, Massey wrote, "For business use, access control is more important. When customers use the broadcast service paired with on-premise SharePoint servers or our upcoming cloud offerings, additional access controls become available due to the additional security layers those products will provide." Treat Office 2010 as you would any Web app While businesses can justify the expense of a SharePoint server or data protection services such as those offered by Confidela or Nasuni, they will still deploy Office 2010 on many thousands of business desktops. IT departments will have to plan for the potential security risks Office 2010 opens. The solution may lie with providing security training for Office users and possibly disabling some of Office's Web capabilities via the Group Policy options. Consumers have fewer options: you might not want to store sensitive documents on SkyDrive, which means forgoing the use of Microsoft's free Web apps. But remember, this potential privacy threat exists for just about all consumer Web services, not just SkyDrive. The difference is that using SkyDrive and the other Microsoft productivity apps could increase the likelihood that you'll store more of your confidential information online, where security is more difficult to manage. And what about protecting against a hijacked PowerPoint Broadcast link? Treat it as you would any link or file attachment that arrives in e-mail or instant message: check to make sure it comes from the person it purports to come from.
WS contributing editor Yardena Arar has written about technology for the New York Times, the Canadian Press, the Associated Press, and the Los Angeles Daily News. She was an editor of PC World magazine from 1996 to 2009. |
|
LOUNGE LIFE Unresponsive USB drivers stump Lounge member
By
Stephanie Small
Every PC user knows how useful USB flash drives are: from importing pictures from a camera to making portable backups, their uses are endless. When a flash drive suddenly stops working, the question arises: is it the drive or the PC that's failed? In his post, "USB drivers corrupt and unresponsive," Lounge member Peter Schulze detailed his frustrations with the nonfunctioning USB drives on his Win 7 OS. That generated a discussion about potential causes as well as a slew of well-articulated solutions to test. More» The following links are this week's most-interesting Lounge threads, including several new questions that you may be able to provide responses to: ☼ starred posts — particularly useful If you're not already a Lounge member, use the quick registration form to sign up for free. The ability to post comments and take advantage of other Lounge features is available only to registered members. If you're already registered, you can jump right in to today's discussions in the Lounge. The Lounge Life column is a digest of the best of the WS Lounge discussion board. Stephanie Small is the WindowsSecrets.com research director. |
|
WACKY WEB WEEK The sound of Tweeting takes to the streets
|
|
ADS
|
|
PERMALINKS Use these permalinks to share info with friends We love it when you include the links shown below in e-mails to your friends. This is better than forwarding your copy of our e-mail newsletter. (When our newsletter is forwarded, some recipients click "report as spam," and corporate filters start blocking our e-mails.) The following link includes all articles this week: http://WindowsSecrets.com/comp/100701 Free content posted on July 01, 2010:
You get all of the following in our paid content:
Thanks in advance for your support! |
|
YOUR SUBSCRIPTION The Windows Secrets Newsletter is published weekly on the 1st through 4th Thursdays of each month, plus occasional news updates. We skip an issue on the 5th Thursday of any month, the week of Thanksgiving, and the last two weeks of August and December. Windows Secrets is a continuation of four merged publications: Brian's Buzz on Windows and Woody's Windows Watch in 2004, the LangaList in 2006, and the Support Alert Newsletter in 2008. Publisher: WindowsSecrets.com LLC, Attn: #120 Editor, 1700 7th Ave., Suite 116, Seattle, WA 98101-1323 USA. Vendors, please send no unsolicited packages to this address (readers' letters are fine). Editorial director: Brian Livingston. Senior editors: Fred Langa, Woody Leonhard. Technical editor: Tracey Capen. Research director: Stephanie Small. Lounge administrator: Keely Dolan. Copyeditor: Roberta Scholz. Technology manager: Joe Kwon. Program director: Tony Johnston. Web developer: Damian Wadley. Contributing editors: Yardena Arar, Susan Bradley, Scott Dunn, Michael Lasky, Ryan Russell, Robert Vamosi, Becky Waring. Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, Support Alert, LangaList, LangaList Plus, WinFind, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of WindowsSecrets.com LLC. All other marks are the trademarks or service marks of their respective owners. HOW TO SUBSCRIBE: Anyone may subscribe to this newsletter by visiting our free signup page. WE GUARANTEE YOUR PRIVACY: 1. We will never sell, rent, or give away your address to any outside party, ever. 2. We will never send you any unrequested e-mail, besides newsletter updates. 3. All unsubscribe requests are honored immediately, period. Privacy policy HOW TO UNSUBSCRIBE: To unsubscribe from the Windows Secrets Newsletter,
|