Microsoft Downgrades Claria Adware Detections
Microsoft's Windows AntiSpyware application is no longer flagging adware products from Claria Corp. as a threat to PC users.
Less than a week after published reports of acquisition talks between Microsoft Corp. and the Redwood City, Calif.-based distributor of the controversial Gator ad-serving software, security researchers have discovered that Microsoft has quietly downgraded its Claria detections.
According to the results published by Howes, four different builds of the Windows AntiSpyware beta detected the Claria products, but the default recommendation was "ignore."
MS partner finds MS software cheaper than Linux
Microsoft has bankrolled another "independent" study that happened to turn up some interesting results. Namely that Microsoft's software is less expensive to patch than open source products.
What Wipro's study doesn't show is that in November of last year, Microsoft CEO Steve Ballmer revealed multi-million dollar deals with both Wipro and Infosys - another large Indian software maker and services firm. Earlier that year, a watchdog claimed that Wipro was one of two Indian companies said to be working on parts of Microsoft's upcoming version of Windows code-named Longhorn. Microsoft denied that Indian staff were handling the core of the OS.
For the curious, Wipro found that Windows desktops cost 14 per cent less to patch than Linux desktops, that Windows servers cost 13 per cent less to patch than Linux servers and that Windows database servers cost 33 per cent less to patch than Linux database servers. The Meta Group audited the survey methodology.
"Risk is defined as the number of days between when a vulnerability was identified and when a patch was made available, combined with the amount of time it took organizations to deploy the patch. The study concludes that even when a greater number of patches are deployed for Windows, the costs are lower because it takes about half as much effort per patch to complete the task," Microsoft said.
Indian cracks Microsoft's anti-piracy program
An Indian researcher has breached the much-touted "impenetrable" Windows Genuine Advantage of Microsoft.
Bangalore-based Debasis Mohanty has cracked WGA through an "easy-to-exploit" weakness in the software for generating illegal copies of the Windows XP programme.
Microsoft confirmed the claims of Mohanty, but sought to downplay it saying, "It represents very little threat." A company spokesperson said they did expect counterfeiters to try a number of different methods to circumvent safeguards provided by WGA.
The Insecurity of Security Software
BusinessWeek is reporting that, despite a number of software products meant to safeguard Windows PCs from harm, a rising number of them endanger their hosts because of poor design and flaws. From the article: 'A new Yankee Group report, to be released June 20, shows the number of vulnerabilities found in security products increasing sharply for the third straight year -- and for the first time surpassing those found in all Microsoft products.'
Enter Avalanche: P2P filesharing from Microsoft
Researchers at Microsoft's computer science lab in Cambridge have developed a peer-to-peer filesharing system that they say overcomes the scheduling problems associated with existing distribution protocols such as Bit Torrent.
The researchers claim download times are between 20-30 per cent faster, using their network coding approach, than on systems that only code at the server, and between 200 and 300 per cent faster than distributing un-encoded information.
Naturally, Microsoft is very keen to stress that this technology should be used for distributing legitimate content. It even put that in italics in the press material.
The basic principle of the system, dubbed Avalanche, is pretty much the same as BitTorrent. Certainly the problem it solves is: a large file needs to be distributed to many people. One server does not have the bandwidth to deal with all that traffic, so you need to find another way of getting the file to everyone who needs it.
IE 7 for Windows 2000 not likely
Software giant Microsoft has confirmed that its coming version of IE 7 will not work with Windows 2000.
Although there are still a fair number of people using Windows 2000, Vole has been gradually pulling the plug on supporting the aged operating system. However there were some who hoped that Microsoft would make IE7, which is supposed to be a lot more secure, backwardly compatible to cut down on the number of security attacks on Win2000 machines.
However according to Microsoft IE programme manager, Chris Wilson, wrote on the Internet Explorer Weblog here, IE 7 will need Windows XP Service Pack 2 (SP2) when it releases in beta. He said that some of the security work in IE7 relies XPSP2 and it is too much like hard work to port back to Windows 2000.
Microsoft Demands Removal Of Longhorn Images
After the previously reported release of the Longhorn beta at this year's WinHEC, Neowin and other Windows sites are reporting that Microsoft is going around sending legal letters demanding removal of Longhorn Build 5048 screenshots. Paul Thurrott discusses it on his site, stating that Microsoft never told anyone beforehand not to post screenshots of the publicly available beta, and links to the new galleries he has up now. 'Enjoy it while it lasts.'
Fake Windows update fools
The software giant Microsoft is warning about an email scam which encourages users to download a Trojan horse in the mistaken belief that they are updating their computers with a security patch.
Spinsters, from the Vole Hill in Redmond, said that the 'update' appears as a spam email. It points people to a bogus website that claims to host critical security updates. Of course anyone downloading from the site gets infected with the DSNX-05 trojan.
According to the BBC, media friendly anti-virus firm Sophos spotted the e-mail which uses subject lines saying "Urgent Windows Update" or "Important Windows Update".
Security software insecure
Online security firm Symantec said some of it anti-virus software has holes in it.
The company admitted its Norton Antivirus, Norton Internet Security and Norton System Works, 2004 and 2005 editions, were so flawed hackers could quite easily sneak in and knobble computers running the software.
Japan's Information-Technology Promotion Agency told Symantec about one situation with both Windows versions of Norton AntiVirus 2004 and 2005, where a real-time scan of a specific file type can cause the Blue Screen of Death to appear.
The programs' Auto-Protect and SmartScan features were found to be faulty and susceptible to Denial of Service attacks.
Microsoft Silently Backs Favorable Presentation
Two researchers, from the Florida Institute of Technology and Boston-based Security Innovation Inc., 'surprised the audience at a computer-security convention last month with their finding that a version of Microsoft Windows was more secure than a competing Linux operating system' according to the Seattle Post-Intelligencer. 'This week, the researchers released their finished report, and it included another surprise: Microsoft was funding the project all along.' When will they ever learn?