Showing posts with label Defect. Show all posts
Showing posts with label Defect. Show all posts

Sunday, March 2, 2008

Some of Microsoft's dealings with Intel and HP revealed

It is not often that the internal dealings of a company such as Microsoft are released to the public for analysis, especially when it deals with the interaction of the company with other major chip and computer manufacturers such as HP and Intel. But, a federal class-action lawsuit provides access to internal emails that are worrisome to customers who have bought machines labeled Vista capable; they can no longer be sure that the certification provided by Microsoft to such machines is genuine. Read this article and these excerpts to understand more:


But documents show that in early 2006, a full year before Vista's release, there was intense discord within Microsoft over its dealings with Intel, HP and others in preparing to roll out the new system. The documents suggest Microsoft bowed to Intel's pressure in certifying certain chips as capable of running the new operating system to enhance sales. Intel declined to comment on assertions that it had pressured Microsoft. "It's private litigation between plaintiffs and Microsoft, and we're not a party to it," Intel spokesman Chuck Mulloy said.
At issue is whether Microsoft misled customers by labeling PCs carrying the Intel 915 chipset as "Vista Capable" when they were put on sale in spring 2006, ahead of the much-anticipated launch of the Vista operating system. Only computers labeled "Premium Ready" carried the more advanced Intel 945 chip and could operate Vista's touted features, such as Aero graphics.


If all this is true, it is tantamount to deceiving computers. Customers buying computers do not have the technical competency to evaluate whether a particular chip and computer were capable of running Vista; if the certification says that the chip is capable, the customer would believe so.

Sunday, September 2, 2007

Microsoft starts planning for the release of Vista SP1

It's the inevitable. After the release of a new application or Operating system by Microsoft, come the regular questions about the Service Pack. There are a number of people who actually believe that the software becomes stable only when the first Service Pack is released; so it is important for Microsoft to release information about the Service Pack. One can be sure that information will be released in bits and pieces, but it seems clear that the Service Pack will be available for restricted beta testing in September (this month) and then finally out sometime early 2008. Given the complexity of this new system, Microsoft will need a lot of time to make sure that the Service Pack can get as wide a testing as possible; after all, nothing hurts the company as much as the news about bad service packs. For example, when I installed Service Pack2 for Win XP, one of my hard disks became unusable and had to re-formatted losing all the data on the system. This may be an isolated case, but if it happens enough times, it makes for a lot of noise on tech forums and among Microsoft baiters.


After lots of whispers, rumours from beta testers and confusing messages from Microsoft executives, Microsoft has finally revealed the full details about Windows Vista's first service pack. The company confirmed a three-month launch window, with a beta testers getting their hands on the update during September.
Microsoft is saying only "a few weeks" and "September", which are, after all, one and the same, for the beta. As for the final release, the software maker finally acknowledged rumours circulating June that the service pack be fully available until the first quarter of 2008.


As time goes by, doubtless we will hear more about this service pack.

Sunday, August 5, 2007

Hacking the iPhone and ease of hacking the Mac

For a long time, Apple and Mac users have disdained the PC and Windows as very bad in security, and instead tom-tommed the relative lower number of hacks on the Mac. Microsoft has always been on the defensive in terms of security, and the large number of cracks and holes available on the OS and apps have always led them to be worried. There have been people who have been saying that Mac has not shown so many cracks just because it has a 5% market share, and people have not found it worth their while to try and break through the Mac OS security:


Though there has yet to be any documented criminal hijacking of the iPhone outside of a lab, Miller says his research shows the relative ease of hacking smart phones, as well as Macs in general. He spoke with Forbes.com about the iPhone's vulnerabilities, Apple's short-lived patch and the company's undeserved reputation for building secure computers.
There are two issues with the iPhone. First, the specific weakness that we found in its Web browser. But there's a more fundamental problem. The iPhone runs everything as "root." In other words, there are no privileges for different users. They should have built layers of security. Instead, if you can find a single crack, any user has the entire phone at their disposal. Last week they basically patched a hole in the wall. But inside, it's still pudding.
Bad guys aren't yet targeting Macs because they want to maximize their time. That means writing viruses that target 95% of computers rather than 5%. Apple currently has around 3.5% of the market, but its market share is growing by around 35% a year. As Mac's numbers creep up to 30% or 40%, cyber-criminals will start asking whether it's better to spend two weeks writing a bug for Windows or just a couple days to write one for Macs.


Almost nothing in this interview is complementary to Mac, but one tends to agree with what he says. Windows is the dominant OS, and most hackers are anyhow biased against Microsoft, in addition people are ready to believe that Windows is inherently insecure, and hence most hackers target Microsoft. Now that the iPhone is a well advertised target, one can expect many more Black Hat hackers to target the iPhone for benefit, and for Apple to be on the backfoot.

Thursday, August 2, 2007

An apple patch that you might want to take

Apple has recently released a patch, 2007-007 update for MacOS X, 10.3 and 10.4. This is a mega patch, fixing over 45 defects, out of which 17 are serious security issues where hackers could compromise systems and are classified as equivalent to 'critical'. Since Apple also uses a number of open-source projects, approx 75% of the patches were in the open-source software that Apple blends in with its own code.
These open-source bug fixed include fixes in the following apps: Kerberos, PHP, Samba, SquirrelMail and Tomcat. Components of MacOS X patched as part of this release were CFNetwork, the Mac OS X library of network protocols; CoreAudio, the API (application programming interface) that handles sound on Macs; the zgrep file compression utility; iChat; and WebCore, the part of the WebKit application framework that handles HTML rendering. Fixes also included fixes in Safari (including a fix for a problem on Safari on iPhone)
One normally hears primarily of Microsoft releasing patches at regular intervals to fix security holes and other bugs, so it would be interesting to evaluate whether this gets an negative publicity for Apple. Microsoft would like to advertise this as claiming that OS X has also a number of flaws, and equally, open source technology has a number of security holes for which there are no clear owners, and the total cost of ownership of open source systems is high, as per the Microsoft argument.

Wednesday, July 18, 2007

iPhone causing denial of service attacks

Could it be too good to be true ? The iPhone is one of the tech marvels that happens once in a few years, and it has shown itself to be a revolution in the designing of phones, although the restriction on carriers and the relatively slow network are acting as hobble-stones.
Well, in the latest news on this area, the iPhones have been caught to be behaving very strangely on the Duke University campus, with around 150 iPhones (a fraction of what would be available once the students come back from holiday) bring several wireless access points to a halt, in an imitation of a Denial of Service attack, probably the last thing that Apple wants to hear at this point:


The iPhone is flooding wireless access points at the US Duke University with MAC address requests, resulting in a denial of service-like attack that is taking out 20 to 30 access points for 10 to 15 minutes at a time – weird! The iPhones are asking for an address that isn’t on Duke University’s network, and when the iPhones don’t get a response, they keep on sending out requests, flooding the available bandwidth.
Help has been sought from Cisco, the maker of the school’s networking equipment, and technical support has been sought from Apple, although there is only speculation online as to precisely what might have caused the problem – Apple isn’t saying anything yet as it no doubt investigates the problem. When the fix inevitably comes, either the iPhone, Cisco’s equipment, or both, will simply be patched with a software update to resolve the problem.


So even though it will probably be a short-lived problem, the fact that such a problem occurred reflects badly on Apple's quality regime. And it is good that it happened at a time when the university was thinly populated, otherwise at peak times and if happening in a number of places at the same time, the problem would have been magnified many times and probably resulted in a loss of face for Apple.

Saturday, July 7, 2007

Selling security exploits

The biggest fear of software makers, application system makers and the like (Microsoft, Adobe, Apple, and numerous other big entities) is coming true. Ever since software holes and bugs started to come into existence, there was always the pressure between the software company trying to release a patch, and hackers trying to exploit this defect. In the past, software makers would try to apply pressure on the defect finders to keep it quiet till the patch is released. If the patch was found by a big company, they would normally respond to pressure from the likes of Microsoft and not release into the public domain.
However, this was not happening more and more, with the security companies releasing their findings independently of the software makers. Some of them would even sell these to people who would exploit them for nefarious purposes. As an example, review the number of botnets that exist in the internet today, with millions of computers being hacked into and controlled. The situation was literally demanding a market-place for such bugs:


An eBay-like auction site that sells vulnerabilities will improve security by ensuring researchers get a fair price for their work, its founders say. "The existing business model to reward researchers is a failure," said Herman Zampariolo, chief executive of WSLabi, and the man behind the WabiSabiLabi auction site. A tiny minority of vulnerabilities currently get patched, he said, because IT experts aren't paid for their work in uncovering them.
"As long as vulnerabilities are bought and sold privately, the value can't be the right one," Zampariolo said. "Our intention is that the marketplace facility on WSLabi will enable security researchers to get a fair price for their findings and ensure that they will no longer be forced to give them away for free or sell them to cybercriminals," he added.
So far, no bids have been posted, possibly because of delays in identifying the buyers, each of whom must use snail mail or fax to deliver proof of their identity and their bank account--electronic currencies are not accepted on the site. Around 20 buyers have been registered so far, as well as 30 sellers, who have provided another batch of flaws that should be on the site next week.


In this case, the intention may be genuine; however, where is the control mechanism to ensure that these sales are happening to the right people. If we are just dependent on the operators of the exchange, then there is no guarantee. Later, if the number of such buyers increases, it would be very easy for the cyber-criminals to pretend to be a genuine buyer and get access to top-notch holes on a very quick basis.

Monday, July 2, 2007

The time involved in getting the iPhone to actually start working

In all the launch buzz of the iPhone, there has been an incredibly successful publicity campaign that has been run, and market watchers have been waiting to see whether Apple will do anything to trip up on this success story. Well, there is some news, just not enough to trip up the iPhone story, but enough to give a serious headaches to the thousands of people affected.
Normally, the process of wireless activation involves the sales person in the shop handling the activation process, something that would take rougly an hour. However, to make things easier for the large crowds expected, Apple changed the activation process to something that can be done via the user's own computer, through their version of iTunes. However, in the end, this caused problems for a number of buyers, with no clarity regarding contact numbers, and in many cases, with buyers having to spend more than 10 hours waiting for activation to happen.
This can actually be the most frustating thing in the world as of that point, if you imagine spending some time in queue to buy a new phone for around $600-700, and then having to wait while customer service tells you that you need to wait. Obviously, these are teething problems, and Apple should be happy that otherwise people are happy with the phone, otherwise this issue would have escalated into a disaster.


Apple and AT&T unveiled an innovative activation scheme with the iPhone launch. Usually, activating a new cell phone means spending almost an hour or so in a wireless store as the sales representative lights up the phone. But with the long lines expected last Friday, Apple came up with a way to use iTunes to connect to AT&T's activation process so iPhone customers could set up the device at home.
Activation was supposed to be a snap: hook up the iPhone to a Mac or PC with the latest version of iTunes installed, and the software would automatically walk you through the process. After entering a credit card number and selecting a rate plan, the system was supposed to send an e-mail confirming the iPhone had been activated. But waiting for that e-mail turned into a frustrating experience for some iPhone customers.
Other iPhone owners on Apple's Web site reported problems with the SIM (subscriber identity module) cards inside their iPhones. SIM cards hold information unique to a mobile phone account and allow users to easily switch between phones while keeping their numbers and contacts--except on the iPhone, which uses a SIM card that works only with the iPhone. It seemed that the activation system was unable to recognize the SIM cards in some iPhones, which led it to bypass the activation screen and move straight into syncing music, movies and contacts. One user reported that his local AT&T store switched the SIM card that originally came with his iPhone for a new one, fixing the problem. Others said they had done the same thing.


Of course, Apple made a feature that caused a lot of worry to those users who were not activated. Unless the phone was activated, users could not even access other features on the phone; this was something that Apple should have thought through much more clearly, and from the perspective of phone users, not from the perspective of AT&T.

Friday, June 15, 2007

Safari on Windows already with 1 million downloads

When Steve Jobs released the beta of its web browser, Safari on Windows at a worldwide developer's conference, he may not have expected this kind of response. This release was also broadcast as the release of the fastest surfing software for Windows.
Even though the browser got hit by security problems and Apple has already released 3 patches to fix major security issues (and Steve Jobs would certainly not have been happy at such adverse publicity about such major problems), it was successful in another front. Within 48 hours of release, Safari got more than 1 million downloads.
Whether this spurt will continue or not is unknown, although Apple would be hoping that it become as popular in the browser application area as iTunes is in the cross-platform music buying and playing software. Safari is currently trailing IE and Firefox in the browser wars, with only 5% (native Mac users) as opposed to IE's 80% and Firefox's 15% market share. If Apple wants to come out with some strength in the browser wars, it will need to push the browser much more.
It will have to come out with more plugin support, not be too different in terms of interface from IE and Firefox, and be very easy to use.

Thursday, June 14, 2007

Anti-botnet campaign by FBI

Botnets are a major nuisance on the internet. These are a large number of computers having inadequate protection, that have been compromised and are under the control of people wanting to use these large number of computers (in many cases, in the thousands) for a number of activities such as launching distributed denial of service attacks where these computers together attach a web site or network, used as relays for mass distribution of spam and malware, used for phishing, click fraud, and a variety of other attacks.
How does a computer get compromised? The computer may be running a version of Windows that has a hole, and this hole has been exploited to gain control of the computer. In addition, the computer may not be having an active firewall and virus protection. Botnets are increasingly being found on the internet and cause a high degree of costs by causing down-time, by actual losses due to phishing and click fraud, etc. And the biggest problem is that users do not even know that their computer has been compromised; they find that their computer has gone slower, or becomes active suddenly, but there are no easy ways of knowing that their computer has been used by a crime or is compromised. Typically, when a computer has been infected and is a part of a botnet, it can be used to attack hundreds of other computers.
Given this situation, and the dangers posed by the menace of botnets, the FBI has been investigating and found more than 1 million botnet victims so far. Along with the Justice Department, the FBI has been running a program called Operation Bot Roast to disrupt botnets. They have caught people; however, as long as security patches determine the safety of a computer, there will be infected and compromised computers in the wild. Refer this article:


The FBI is working with industry partners, including the Computer Emergency Response Team Coordination Center at Carnegie Mellon University, to notify the victim owners of the computers. Microsoft and the Botnet Task Force have also helped out the FBI. Through this process the FBI may uncover additional incidents in which botnets have been used to facilitate other criminal activity, the FBI said in a statement.
Bots are widely recognized as one of the top scourges of the industry. Gartner predicts that by year-end 75 percent of enterprises "will be infected with undetected, financially motivated, targeted malware that evaded traditional perimeter and host defenses," and early reports from beta customers of a yet to be released product from Mi5 show how nefarious these infections can be. Mi5 says it installed a Web security beta product at an organization with 12,000 nodes and in one month detected 22 active bots, 123 inactive bots and was watching another 313 suspected bots. That may not sound like a lot, but those bots were responsible for 136 million bot-related incidents, such as scanning for other hosts inside the firewall.


It can get pretty hairy for people. Suppose the computer of a unsuspecting user is used to break into a protected military installation or a bank, or used to break down a major network, the first path for investigators will be to find the computers that were used, and in the case of a compromised computer, the owner will have no idea.
This will also start to increase pressure on software companies to make their software more secure from the ground up, such that they do not land in the situation where the security of the system is dependent on patches.

Wednesday, June 13, 2007

Problems in using Safari on Windows

Apple is on a high nowadays. It is seen as the leader in computing design, has the by-far-largest selling product in the personal media player market, has ownership of the iPhone (probably the most hotly awaited product for some time), and seems to have played a master stroke by moving its Mac onto an Intel machine, this allowing people the option to install windows on their Mac machines and pushing up the sales of Macs. However, there comes a time when a company gets too arrogant, and then realizes that arrogance is not a virtue (especially when the arrogance is revealed to be based on false premises). Microsoft has faced this repeatedly in the past, especially in the area of security (both for operating systems and applications); claiming that their apps are secure, and then facing a number of holes pointed out by hackers and security specialists. Well, the high and mighty Apple faces the same situation today with Safari.
Safari, the default browser on the Mac, is now available on Windows as a Beta, and I read reports where Apple claimed that this browser is secure. Well, no longer. Security experts, no doubt encouraged by Apple's claims, found numerous security holes in this Beta of Safari such as Denial of Service support, remote execution bugs, memory corruption, etc, As time goes by, more such errors will be found. This article claims that the Beta of Safari should not be used for actual web use because of its bugs.


Although all browsers have security issues uncovered on a relatively regular basis, most of which are rapidly patched up with updates and fixes, the latest beta version of Safari has been put to the test by a number of security researchers, as reported by PC Magazine and others, and is so far failing a lot of security tests.
Problems with Safari uncovered so far include DoS and remote execution bugs, memory corruption that could be exploited, command execution vulnerabilities simply by visiting a web site – and that’s just in the last couple of days. Security researchers are bound to find more bugs in the system, or more ghosts in the machine for Apple to eliminate.
So, should you use Safari on Windows? After all, plenty of Windows users will have downloaded Safari since its release on Monday, and will no doubt have had a surf around to see what it’s like. It looks and feels just like Safari on the Mac, it’s certainly fun to use. For now, it’s also the latest novelty must-have experience from Apple that Windows users can enjoy. Apple’s download servers must be running hot!


Safari is indeed hot, after all, it is the browser on the iPhone, which itself lends to a lot of pull for the browser. However, Firefox is a pretty strong competitor on a number of platforms, so it is not sure as to how much Safari can take away from established browsers.

Saturday, May 26, 2007

Microsoft delaying release of Halo 2 due to nudity scenes

Halo was one of the top selling games on the original Xbox, and helped increase the popularity of the Xbox. The next version of the game is eagerly awaited, but now Microsoft has released a statement that the release of Halo 2 for Windows Vista has been delayed by around a month due to 'content' issues. And what are these content issues ? Well, Microsoft discovered that due to an error in Halo 2's map editor, there are scenes of partial nudity, and hence unless these are repaired, the game cannot be released. Refer to this article:


Halo 2 for Windows Vista is now expected to hit the stores sometime in the first week of June, approximately two weeks behind the revised May 22 schedule. The game was originally scheduled for release on May 8, but was delayed due to some technical problems, Microsoft said at the time.
The software giant attributes the most recent delay to an "obscure content error" found in the initial production of Halo 2's map editor. That error was partial nudity.
The company has no plans to change the rating of its game, given it affects only the initial run of games and not subsequent shipments. Warning labels will be placed on packaging for the affected games, and Microsoft has developed a patch that can be downloaded to remove the content in question.

However, after the furore over similar scenes discovered in Grand Theft Auto and the political questions over it, it was impossible for Microsoft to discover that something like this occurs in the game, but is not yet fixed. They would rather bite the schedule and take a fix.

Thursday, May 10, 2007

Data breach at University of Missouri Computer Database

A hacker managed to access and download information from a computer database (owned by the University) that contained information on names and social security numbers of around 22,000 current and former employees and students. In a sign that officials realized that keeping this information was not safe, there was a project to removed social security numbers from unnecessary computer systems, but the project was not complete. Refer this report at DailyTech:


More than 22,000 current and former University of Missouri employees and students are at risk of identity theft after a hacker reportedly accessed a computer database containing names and Social Security numbers.
Campus IT people discovered the intrusion on Friday morning -- the hacker exploited a hole in a campus web site that is used "to make queries about the status of trouble reports to the university's computer help desk."
The school suffered a similar intrusion in January. In that incident, a hacker was able to secure more than 1,000 Social Security numbers and the passwords of around 2,500 users of an online grant application program.

The shocking thing is that this has happened before in January, and yet this happened again. Now, it is true that computer systems security is an evolving field with constant battles between security folks and hackers, but the fact remains that one would have expected a greater show of urgency towards making systems safe.
Now, the university is faced with the prospect of sending out letters to everybody who could be affected, including former employees and students. And stealing of social security numbers is very different from stealing of credit card information because a database of stolen social security numbers can cause immense identity theft cases.

Friday, May 4, 2007

Busy week for Microsoft patching

Next week promises to be a busy week for systems administrators of companies where there are a number of Microsoft systems. These would consist of security updates for Windows, Office, Exchange and Biztalk. Microsoft normally does not disclose details of the updates, but this article provides some details of what the expected updates would be.
These are one of the issues with using Microsoft updates, in terms of the number of updates that need to be installed on a regular basis. And many of these updates require reboots, causing downtime on systems that are in regular use. Doing downtime on a production system requires some amount of coordination and making sure that users are aware of this downtime. Refer this article:


Two of the seven bulletins slated for the May 8 release involve Windows, three affect Microsoft Office, and one each impact Microsoft Exchange and the cryptography API within BizTalk Server. At least five of the seven updates will be pegged critical, Microsoft's highest threat score in its four-level system, according to the advance notification posted today.
As usual, Microsoft did not disclose details of the updates, but intelligent guesses are not difficult. One of the Windows updates, for example, will likely be a fix for the DNS (Domain Name System) zero-day bug found in all editions of Microsoft's server line, including the current beta of Windows Longhorn Server. While researchers predicted last month that Microsoft would issue an out-of-cycle fix for the DNS server service flaw, the company's security team instead has repeatedly blogged that it would probably wait until the regularly scheduled patch day.
If Microsoft issues the seven updates, users will have seen 29 bulletins in the first four months of the year, and at least 49 patches; more than half of those will have been marked critical. During the first five months of 2006, Microsoft issued 20 updates with 36 patches.

These are a significant number of updates. The biggest problem is that in the time that Microsoft releases a patch, the information about the bug is already being exploited by hackers. Microsoft normally releases a patch with some delay after reporting, while trying to make sure that information about the defect is not available publicly. However, with a reported market in defects, it would seem to be losing this battle.

Sunday, April 15, 2007

Programming error lead to loss of Mars Global Surveyor

Programming errors are something that are inevitable when any computing system is involved. In a normal application development, these are known as bugs that get fixed. But errors in any kind of programming can happen anytime and any place, including at locations millions of kilometers from the earth. Earlier, there was the time when a craft sent to the moon had crashed due to incorrect conversion between different units of measurement.
The Mars Global Surveyor was an accomplished success for NASA. It was originally supposed to have a life of 2 years, but given how it was working, this life period was extended 4 times, and it gave a good new perspective of Mars, including the latest presentation of a couple of months back that water still flowed on the Martian surface from small springs.
So what went wrong ? In June last year, a command that oriented the spacecraft was sent to the wrong address. This caused the solar power panels to get wrongly positioned. A couple of months later, when the spacecraft detected the positioning error, it tried to go into safe mode, which unfortunately caused one of the batteries to get exposed to direct sunlight, in turn causing over-heating. Sensors shut down the charging system, and this eventually drained the batteries, and communications were lost with earth. Refer this article.