Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Sunday, February 04, 2007

Endless Vistas... of confusion

Having been at this tech thing for a goodly amount of time, I've had this policy (and learned survival skill) for almost as long: Never Buy The 1.0 Version Of Anything.

So it's been with a complete lack of surprise that I've been watching the news of Microsoft's introduction of Windows 05 (which drifted to 06... no, make that '07). IDG's Computerworld, which has been around since only the giant Mainframus Rex roamed the earth, put it succinctly (Jan. 25):
"Wait! Don't buy Windows Vista! Microsoft's new OS is the best Windows ever. But don't buy it!"

They've updated that story since (Feb. 2, by Mike Elgan,) with the amusing headline, "Windows Vista: The 'Huh?' starts now; Microsoft is confusing everyone with its new OS..." The story explains that no one knows for sure what you'll have to do to upgrade from XP: "Microsoft created this confusion by failing to tell anyone what the proof requirement would be for using an Upgrade version of Vista. Meanwhile, the Upgrade versions are poison."

Then there's the fact that MS has introduced Vista in "10 -- count 'em, 10 -- versions. Instead of giving us a simple new upgrade path to the future, they instead gave us a homework assignment."

But wait, there's more! The first "service pack" from Microsoft -- aka, bug fixes -- won't be available until late in the year. Major peripheral vendors aren't ready yet for the new operating system. (Also, attention iPod Nation, Apple is warning everyone not to upgrade to Vista yet if you want your iTunes to work, at least until the next version of iTunes "in the next few weeks.")

The Why's and How's
It's like this: software companies only make real money when they ship a major new version. It's sad but true, but most often software that's shipped (by just about everybody, and I'd love to know who this isn't true of,) is still in the beta stage, and the companies depend on the unpaid labor of all the eager-beaver early adopters, and innocent newbies, to debug their software for them.

Generally, by the time the second update is available, that application is ready for primetime. But not before.

Vista has been delayed over a year (and retailers were dismayed, to put it mildly, when it wasn't ready as promised for their biggest season, the holidays), so just as with the famous release of Windows 95 so many years ago, with 3000 known bugs, MS pushed this release out the door before they had to start to consider closing theirs.

Related, on Rosswriting.com:Scouting the Techno-Frontier
(An editorial for the AltaVista MarketSpace webzine, 1997-98)

Saturday, August 19, 2006

Getting Closer to Microsoft (for purely defensive purposes)

“Deluge of flaws” being found in Office

You are not going to see much in here that’s all warm and fuzzy on the subject of Microsoft, or even particularly friendly. But let’s be practical, everybody uses their stuff. And it’s because of that fact that this is bulletin is important, nay, crucial.

Ziff-Davis’s E-Week reports that:

"What started as an amusing eBay listing of an Excel vulnerability for sale has developed into an all-out hacker assault on Microsoft Office applications.

"Security researchers and malicious hackers have zeroed in on the desktop productivity suite, using specialized 'fuzzing' tools to find a wide range of critical vulnerabilities in Word, Excel and PowerPoint file formats."
("Fuzzing tools”? You mean, marketing? No, eWeek explains,)
"Fuzzing, or fuzz testing, is an automated technique used by researchers to find software bugs."
The article points out that as Microsoft (belatedly) got serious about security vulnerabilities in Windows, hackers and hence security researchers have moved up the software ecosystem to go after “the low-hanging fruit” in applications. Well, there ain’t any bigger trees in the orchard than Word, Excel and Powerpoint, which were originally put together with the same oblivious attitude to security as the OS.

In short, what this means is that in order to keep our lives simple, we’d all better keep in touch with all the bug fixes, "service packs," etc., for Office from the E-Empire. (That “E-“ is for “electronic” – no, honest! ; - )


(…half an hour later:) Oooh, boy, is my head spinning. Well, try this, bravely found by starting at microsoft.com, Gawd help us:
Security and Office: Find out how to help protect your data

This page was obtained by clicking Office under Product Families in the navigation column at left, then typing “security” into the search box. (I’m specifying all this as a disclaimer, since there’s an awful lot of stuff there, and who knows what’s the most recent and comprehensive.) There are, naturally, thousands of rabbit holes there you could disappear down, so if you’re a masochist with a week or two to spare, have at it!

Here's a case where you really might be better off hiring a professional to at least get you set up with this. (No, we don't do that; this is not a subtle sales pitch.) It'll cost you, true, but it beats the hell out of having your computer taken over by zombies, spending long hours trying to get it exorcised, and losing all your data (because few are those who back theirs up).

Just a sec -- here we need to say, BACK UP YOUR COMPUTER! This weekend! At least just copy all your own files onto CDs, preferably rewritable CD-RWs. (There, now you can't say nobody warned you, okay? And we've done our duty as digital citizens.)

How much do I hear for a hole in Excel?

That Excel vulnerability for sale on eBay was indeed pretty funny. eWeek's story on that explains,

The seller openly taunts the software giant, poking fun at the company's delays in providing fixes for known security bugs. "It can be assumed that no patch addressing this vulnerability will be available within the next few months. So, since I was unable to find any use for this by-product of Microsoft developers, it is now available for you at the low starting price of $0.01 (a fair value estimation for any Microsoft product)," the listing read.

"Microsoft representatives get 10 percent off the final price. To qualify, you MUST provide @microsoft.com e-mail address and MUST mention discount code LINUXRULZ during checkout," it added.