>

Buy Microsoft Office Ultimate 2007!

February 16, 2009

Woman Sues Microsoft Over XP Downgrade Charge

PC World has published an article about a woman in Washington that has decided to sue Microsoft for charging users who purchase computers with Windows Vista a downgrade charge if they want XP installed.

Her argument is that Microsoft is being unfair because they are forcing people to buy Vista if they want XP, because XP is being discontinued. Because of this, she things they should give her XP for free since she is buying vista.

Lets remove Microsoft from he equation, and pretend its another piece of software. Lets say Adobe release Version CS4 of Photoshop, with CS4 do you get CS3? CS2? no, absolutely not, you get CS4. If there was something you wanted in CS3 that's not in CS4, you pay the money for the older version (and they don't give a discount)

Microsoft is charging just under $60 dollars as a downgrade fee. They do this because now they not only have to give you a copy of XP, they have to continue to manage the licensing for it and provide support for it. I think this is very reasonable.

Also, the women fails to realize that a product manufacturer is allowed to discontinue any product they want, regardless of level of demand, so saying but people hate vista, and want XP" is not a legal argument for them to allow people to just buy XP.

As an IT company, we buy these downgrade rights all the time for clients. Many don't want to move to Vista on new computers because they want to keep all of their systems running the same OS and they don't want to pay to upgrade 40-100 machines to Vista since they have no reason to. This makes sense to me. Smaller companies who are just getting started and are buying new company computers buy all Vista machines, because Vista IS a good operating system despite what all the people who have never given it a shot have to say.

The bottom line is, if you want a piece of software, you are paying for it. If the only way to get it is packaged with something else, that's a manufactures decision, not yours. What's next. Apple getting sued because I need to use iTunes if I want to upgrade the software on my iPod?

Read the full PC World Article Here

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

February 14, 2009

How do Spam Filters Work?

Over 95 percent of all email sent today is spam. That means if you have nothing filtering the email you read, only 5 of the 100 emails you look at will be legitimate. Within those 95 pieces of junk mail, several will contain tempting attachments that are really viruses, even more will contain letters of sorry trying to get you to send money, and even more will contain advertisements for fly by night pharmaceutical companies trying to sell you miracle drugs. How has time to deal with all of them? No one, and that is why Spam filters are becoming more and more important.

But how do spam filters know which emails are real and which are spam? Well, like any good security system, they run each message through several layers of tests and checks to ensure the email you get is not dangerous.

  1. Black Lists: The first layer of protection that a spam filter offers utilizes a black list. A black list is a list of IP address and domain names that in the past have sent out spam. It is similar to the black list used by clubs and casinos to keep out trouble makers. Where at a club, every person has their ID checked, spam filters do the same thing and look at where the email is coming from. If the sender's domain or mail servers IP address is on a black list, the message is refused. Some of the most popular blacklists that people use are Spam Cop, Barracuda Central and The Spamhaus Project, although there are hundreds of others, many of which use each other to increase their effectiveness.
  2. Key Word Searches: Spammers know what attracts peoples attention, they know that people love money, people love good looking men and women, people like exciting news, and because of this, they use the same type of word combinations to get people attention. This makes them predicable, and because of that, spam filters can look for key words and phrases and if present, block a message. For instance, if a message says something like "FREE VICODIN!!!!" its probably not legitimate, so the spam filter will mark it as spam. Some of the most common words used in spam are "millionaire" and "sex"
  3. Mail Formatting: Spam filters can also look at the design of an email. Is it all text? is it one big image? are their tons of links to other things. is any of the text hidden? By using characteristics like this, the spam filter can make an educated guess as to what is real and what isn't.
  4. Attachment Scanning: Spam filters will not only scan the email it self, but good ones will scan the attachment as well. This allows the filter to catch viruses and Spyware before they get to your computer.

When using any of the methods above on their own there is a good chance that you will both miss a lot, and let a lot through, so many spam filters use a point system to rate emails. For instance, a key word search might find a few things that look like spam, but could also be real, so it will give it 2 points, the formatting also looks bad, so it gives it another 2 points. The message comes from an IP that is not black listed, so no points given, and there are no attachments, so no points there wither. this is 4 points. So if the spam filter is only configured to block things that get 5 points or more, then the mail would go through, if it is configured to only allow 3s and below, it would be blocked.

Of course, no scan is ever going to be perfect. because of this good spam filters will have a way for the email recipients to see all mail that was filtered so they mark it as not spam so the spam filter doesn't make the mistake again, and also have an option to mark things it did let past as spam so the filter can better recognize the spam in the future.

          Bookmark this post:
          StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

          February 13, 2009

          Why Do I get Spam?

          SPAM has got to be one of the most annoying things about the Internet.  Not only does it take up space in you mailbox, but it also wastes you time because it forces you to wade through it to get to your real email. In addition to being a waste of time and money, it can be dangerous.

          Every day people fall for scams like the well known Nigerian 419 Scam, and it costs them time and usually money. SPAM can also contain viruses and malware in attachments that are sent and look like something important, maybe pictures from a friend, or an urgent message from your bank. So how do you avoid getting all of this trash?

          As always, Prevention is key. Spammers collect email addresses in a number of ways, here are a few of the more popular methods and ways to prevent them.

          Method 1:  Buy them from shady companies who collect them by tricking people into signing up for things like surveys, mailing lists, and free things.

          Prevention: The best way to prevent this is to be careful who you give your information to. Always read the terms and conditions of service when you sign up for something, and make sure it mentions not sharing or selling your info. If you must sign up for something like this, use an email designated just for signing up for things. I have several email accounts. 1 for this blog, 1 for friends, family, and lists I actually care about, 1 for junk mail, and 1 for various other things. All of them are free GMAIL accounts.

          Method 2:Spammers with scrape web sites for information. This is when they use a piece of software and scan hundreds of web sites for email addresses. Sites like Craig's List are very popular, because while the real email address usually isn't listed, people their are categorized by what they are interested in (that is where they posted) so they make good targets, and will end up replying with their real email address. Businesses are highly vulnerable to this because they need to list contact info on their web site, which exposes them a lot.

          Prevention: Never post your email address in a forum, on a web site, or anywhere that someone can see it easily. For businesses, using "Contact Me" links like the one I use are very helpful. People can contact you, but not know your email address.

          Method 3: They guess. People tend to use common formats for email addresses, and will usually include their first initial and last name, or first name and last name, so they really can guess.

          Prevention: The only way to stop getting emails like this is to have a good spam filter in place. Most services like GMAIL, Yahoo! Mail, and Hotmail use a spam filter, but if you are a business and host your own email, you need to get one.

          Bookmark this post:
          StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

          67 Computers Missing from Los Almos Nuclear Weapons Lab

          POGO reported today that 67 computers have gone missing from Los Almos Nuclear Weapons Lab, 13 of which were in the last year. While the number of machines missing is a bit alarming, Los Almost says that none of them contained confidential data. I did however find one part of the report concerning;

          "Thirteen of the missing computers were lost or stolen in the past 12 months, including three computers that were taken from a scientist's home in Santa Fe, N.M., on Jan. 16, and a BlackBerry belonging to another employee was lost "in a sensitive foreign country," according to the memo and an e-mail from a senior lab manager...Only one of the three computers stolen from the employee's home was authorized for home use, which raised concerns "as to whether we were fully complying with our own policies for offsite computer usage," he said."

          While I am ok with people taking their work home (believe me, I know how necessary it is sometimes) I also understand that if you are taking a piece of equipment home, there are some special security concerns that need to be addressed. It is concerning that in a place that is supposed to be so heavily secured someone was able to walk out with 3 computers.

          Read the complete article.

          Bookmark this post:
          StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

          February 12, 2009

          People are the weak link in security

          Errata Security recently released their finding after analyzing 28,000 User passwords that had been stolen.

          From the AFP Article:

          "It found that 16 percent took a first name as a password, often their own or one of their children, according to the study published by Information Week.

          Another 14 percent relied on the easiest keyboard combinations to remember such as "1234" or "12345678." For those using English keyboards, "QWERTY", was popular. Likewise, "AZERTY" scored with people with European keyboards.

          Five percent of the stolen passwords were names of television shows or stars popular with young people like "hannah," inspired by singer Hannah Montana. "Pokemon," "Matrix," and "Ironman" were others.

          The word "password," or easy to guess variations like "password1," accounted for four percent."

          While I don't find the results all that difficult to believe, I am still amazed by how little people seem to care. Your username and password are the key to who you are online or on a computer network. If someone steals them, they are you for that moment. In the case of these passwords, I partly blame the administrator of the network that allowed such weak passwords to be used. While we can't expect everyone to understand what makes a password strong, I can expect those tasked with the security of a website to know.

          The Do's and Don'ts of strong passwords:

          Do:

          • Use a minimum of 8 characters
          • Include both upper and lower case letters
          • Include at least one number
          • Include at least one special character

          Do not:

          • Use your name, your kids names, spouses name
          • Use your birthday, anniversary, kids birthday, etc
          • Use simple words like love, hate, dog

          Things like names and dates are easy to find out and are the first things tried. Simple words are easy to guess, and password cracking software will try common words before trying random characters.

          Your password does NOT have to look like this: Yffg87^7!!4f (Although I do know several administrators who do use passwords like that) That type of password is unnecessary for most things. Sure, it wouldn't be cracked very quickly (it would take days to crack if on a Windows network), but it is also very hard to remember, which usually means it will be written down and kept somewhere, which means someone can steal it.

          Instead, use something you can remember, a word with special meaning,  a phrase, or a song title like H0telCalifornia! This provides almost the same level of security, and also has the benefit of being remembered.

          Remember, strong passwords need to meet the balance of security and usability. If you cant remember it, it is useless, but if its easy to crack, its a security risk, so find a happy medium.

          Bookmark this post:
          StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google