Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Microsoft criticizes its competition OpenOffice.org on YouTube

by Michael Smith (Veshengro)

Epsom, UK, 10/15/2010: Some days ago Microsoft's Office Division made public on YouTube a video in which they list one supposed disadvantage of OpenOffice.org after the other.

They claim that Oracle's free office product, OpenOffice.org, is incompatible, insecure and slow and that it would be no alternative for firms and other businesses to the Microsoft Office-Suite.

In this video Microsoft's Office Division claims the free office OpenOffice.org to be entirely incompatible, insecure and way too slow. For the professional use in businesses they claim that the free Open-Source solution is entirely useless, as, because of the lack of support and the unreliability high additional costs would arise.

In the three-minute long film selected representatives of a variety of companies are cited who, so it is claimed, after the installation of OpenOffice were forced, because of disappointment, to switch over to the to be paid for Microsoft Office software.

Mostly mention is made of so supposed additional costs which are supposedly caused by the implementation of Open Source software solutions.

“First we used Open Office, based upon Linux systems, in order to save money. We found soon, however, that the exorbitant costs and the extremely limited available support, left us worse off than before,” claims, for example, James Fleminf, of the American company “Speedy Hire”.

An estimated 25% extra time would be needed in order to install and maintain Open Office based systems, claimed David Sterling, IT manager of Central Scotland Police. Even a teacher is quoted as saying that pupils who handed in a document converted with OpenOffice.org for grading and who, as a result, and how could it be different, received worse grades. With use of Microsoft Word or Excel this could and would not have happened, they claim.

After the video had been put up on YouTube and the first critics had countered the claims made as not being objective enough it was removed from YouTube. In the meantime, however, Microsoft has put it back up, in, so I understand, the same way as it was before.

Having been using OpenOffice.org for years now I can but say that I find it easier to use than MS Word (and other MS Office products) and there is absolutely no compatibility issue. In fact all documents convert to OpenOffice.org without any problems whatsoever, whether MS Word, Excel, or PowerPoint. Just a shame that MS often does not allow for proper back-conversion.

It is also a shame that the likes of Avery and others still only make their templates available for MS Word and not OpenOffice.org though many Microsoft templates do, in fact, convert.

I must say that I have serious misgivings as to the reliability of the quotes in the video as, for instance, many local governments and police authorities on mainland Europe work in OpenOffice.org on Windows and on Linux-based Operating Systems.

The claim about security issues with OpenOffice.org and its files is absolutely laughable. Microsoft would do well to clean up in front of their own door before talking about other people's products.

Then again, those tactics and antics of the Redmond-based company do not surprise me at all. It is the same story when it comes to talking about Open-Source Operating Systems as when it comes to OpenOffice and, indeed, other Open-Source software.

Microsoft is running scared that it could be losing customers, especially in the still ongoing Great Recession.

While it is true that not all the keyboard shortcuts on OpenOffice are the same as on MS Word, for instance, it does not take much to get used to them and the interface is not much different to MS Office, even Office 2007.

Folks, don't allow yourselves to be scared off by the bullies out of Redmond. Rather give the a good run for their money while not wasting yours.

OpenOffice.org is compatible and secure and fast and I use it every day.

© 2010

Microsoft MEA Director's comments on security shows the need for branch office protection says Finjan

Farnborough, United Kingdom, 1st April 2009 - Comments on the need to stay protected by Microsoft's Commercial Market Strategy Director in the Middle East and Africa highlight the need not to overlook the security requirements of branch offices, says Yuval Ben-Itzhak, Finjan's Chief Technology Officer.

"The comments of Microsoft's Mark Chaban, which came after Chinese cyber spies had been found to have infiltrated into the online networks of companies around the world are very relevant to the needs of branch offices," he said.

"When news reports like this there is a tendency to overlook the fact that we live and work in a global village, and that many companies have branch offices in the Middle East or, of course, that Middle Eastern firms have operations elsewhere in the world," he added.
According to Ben-Itzhak, Chaban's revelations that Microsoft's security software detected malware and similarly unwanted applications on 42.6 per cent more PCs in the Gulf States last year than in 2007 makes for very interesting reading.

Whilst many major companies install unified Web security on their head office systems, he says, the security needs of branch offices and operations are often overlooked, with the result that these branch IT systems are usually the weakest link in the IT security defence chain.
Hackers, he explained, are now sufficiently criminally-driven (and minded) to research their victim companies and, as a result, target branch offices, knowing full well that this is their best chance of gaining unauthorised access to the organisation concerned.

Ben-Itzhak went on to say that, in its latest quarterly cybercrime report (http://preview.tinyurl.com/cajblt), Finjan identified that criminal hackers are injecting search engine optimisation targeted pages to include repetitive popular search keywords with minor typos.

By targeting regional pages of major companies, which have lesser page visitors, but whose page accesses are still measured in the tens of thousands, he says, it is far easier to get these injected pages to the top of the search engine lists.

"This means that, when someone searches for XYZ Corporation Middle East, they have a greater chance of ending up on the compromised pages of XYZ Corp's pages than if they searched for the company name alone," he said.

"And this is where weaker defences on branch office IT systems really come into play, as their weaknesses can be exploited by hackers wanting to route innocent Internet users over to their compromised sites," he added.

It's against this backdrop that Ben-Itzhak is urging IT managers to spend just as much time and resources on securing their branch offices as their head office.

"Only by doing this can they hope to equally protect all aspects of their organisation's IT operations against criminals," he said.

Finjan MCRC specializes in the detection, analysis and research of web threats, including Crimeware, Web 2.0 attacks, Trojans and other forms of malware. Our goal is to be steps ahead of hackers and cybercriminals, who are attempting to exploit flaws in computer platforms and applications for their profit. In order to protect our customers from the next Crimeware wave and emerging malware and attack vectors, Finjan MCRC is a driving force behind the development of Finjan's next generation of security technologies used in our unified Secure Web Gateway solutions. For more information please also visit our info center and blog.

Secure Gateway provides organizations with a unified web security solution combining productivity, liability and bandwidth control via URL categorization, content caching and applications control technologies. Crimeware, malware and data leakage are proactively prevented via patented active real-time content inspection technologies and optional anti-virus modules. Powerful central management enables intuitive task-based policy management, excellent drill-down reporting capabilities and easy directory integration for all network implementation options. By integrating several security engines in a single dedicated appliance, Finjan’s comprehensive and integrated web security solution enables quick deployment, simplified management and reduction of costs. Business benefits include real-time web security (no patches or updates needed), lower total cost of ownership (TCO), cost savings in administration efforts, lower maintenance costs, and reduction in loss of productivity. Finjan's security solutions have received industry awards and recognition from leading analyst houses and publications, including Gartner, IDC, Butler Group, SC Magazine, eWEEK, CRN, ITPro, PCPro, ITWeek, Network Computing, and Information Security. With Finjan’s award-winning and widely used solutions, businesses can focus on implementing web strategies to realize their full organizational and commercial potential. For more information about Finjan, please visit: www.finjan.com.

For more on Mark Chaban's comments: http://preview.tinyurl.com/dan3xd

Neil Stinchcombe, Eskenzi PR
<>

Zero day flaw in WORD allows exploits by Trojan

by Michael Smith (Veshengro)

Microsoft warned on July 10, 2008, that an unpatched security vulnerability in WORD has become the subject of targeted attacks.

Yet another security flaw in Microsoft products? You don't say... The more I see of Microsoft the more I wonder what kind of incompetence reigns there at Redmond.

The flaw – which, supposedly, is restricted, so they claim, to Microsoft Office WORD 2002 Service Pack 3 (one may wonder when they notice that it not just affects that one) – creates a mechanism for hackers to inject hostile code onto vulnerable systems. Redmond has published workarounds as a stop-gap measure while its researchers investigate the flaw in greater depth.

In the meantime, Microsoft is keen to downplay alarm. "At this time, we are aware of limited, targeted attacks attempting to use the reported vulnerability, but we will continue to track this issue," a post on its security response blog explains.

The vulnerability has appeared in a number of samples on malware. A widening number of anti-virus firms have issued signature updates to defend against the threat.

Symantec, acting on samples sent to it by handlers at the SANS Institute's Internet Storm Centre, was the first to publish an advisory.

Maybe a firewall would be advisable here as well that can prevent the injection of hostile code such as the recently tested – by me, due to my favorite Zonealarm having been disabled by the nice guys from Redmond with Microsoft Security Update for Windows KB951748 – PC Tools' free Firewall. It has an advanced facility that can prevent the injection of code. It can be annoying though when this is set as it will have the little window pop up every time that you launch a program, until it has learned which programs are allowed to do this and that.

The timing of the arrival of the exploit meant Microsoft had not enough time to respond before its regular “Patch Tuesday” update, This factor is probably no coincidence. So far the direct details of the flaw are still under investigation and it can be safely assumed that they will probably be withheld from the public and industry even until a fix is unavailable. It is also not at all clear as to who the attack is targeting and aimed at. However, historically unpatched WORD exploits are a particular favorite of Chinese hackers.

Seeing how clever Redmond was recently with Microsoft Security Update for Windows KB951748, which disabled most if not indeed all Zonealarm applications and so far we have no response from them as to that foul up, why should we trust them when they are so silent.

Many people seem to believe that the disabling of Zonealarm in the above mentioned patch was no coincidence but was in fact one of the aims.

Yet again, I cannot and will not comment further to such claims as they cannot, so far, be substantiated and proven. Let the reader, however, beware.

The best advice, I am sure, can only be here, yet again, to go Open Source, and to use and alternative to Microsoft Office. There are a number of them available and most are as good, at least, as MS Office.

As I, personally, am moving – work wise – between Linux and Windows all the time, I am using only, nowadays, Open Office 2.0 for all the work that generally would have been the domain of MS Office. This is with the exceptions as and when WORD needs to be used to work with some templates, for instance, such as Avery Dennison's ones, as they still do not have created an Open Office interoperability.

I am not saying that there may not be vulnerabilities in Open Office or the other Open Source products. The fact remains, though, that most hackers do not seem to even attempt to target such open source software and also operating systems. Or, more precisely, in the case of the operating systems, such as Linux Ubuntu, they try to get somewhere but do not succeed.

© M Smith (Veshengro), July 2008

To patch or not to patch – that is the question

by Michael Smith (Veshengro)

After the recent episode of problems with a “security” update by Microsoft for Windows XP that disabled not only the Zone Alarm firewall on my system but, basically, all Zone Alarm firewalls left, right and center, that is to say the firewalls of thousands of other users worldwide, I am beginning to wonder, yet again as to the question of patch or no patch.

The question is as to whether downloading patches, and other such so highly tauted important updates and patches, from Microsoft for Windows is such a great idea. I have had problems in that department before but we shall touch on the advice given to me by computer personnel later in this article.

Obviously, initially, and I assume I was not alone there, I thought that the Zone Alarm program had gone bonkers for some reason or other and I uninstalled the older version, that is to say 6.5, downloaded the latest version, installed same but, guess what? Well, you guessed it... zilch. The problem persisted. No access to anything on the Web, neither my emails via the email client nor web pages. Nothing was loading.

As I wanted and need Internet access, which I just could not get, I disabled Zone Alarm, accessed the Web and downloaded PC Tools' Firewall which though nice and rather powerful if just not Zone Alarm (sorry PC Tools... nothing wrong with the program... just me having used Zone Alarm now for so many years and that...). I am sure you all know what it is like when you have gotten used to and used to trusting something for many years.

Had it, however, not for the fact that I got PC Tools' firewall I would not have been able to get online and finally find out that I was not the only one affected and that Zone Alarm was advising that there is a problem for all Zone Alarm users with the Microsoft Security Update for Windows KB951748. Cheers Microsoft! I followed the instructions provided by Zone Alarm's website and uninstalled that patch and put Zone Alarm back on and all is well.

But back to the question of “to patch or not to patch”...

Years ago some geeks told me not ever to install any patched and so-called “security updates” from Microsoft as some of them were doing more harm than good and I must say I have had a couple of occasions in those days when that did happen and when, according those that then sorted out the PC for me (before I learned a lot of how to deal with them things), the reason for the malfunctions were those “security updates” from Microsoft.

I may just about go back to those days after the above events when I no longer installed any “security updates” and “patches” from Microsoft and do as I did then, while ensuring, obviously, that all possible security software is in place and continually updated.

I must say that, after some bad experiences with patches, such as disabled Open Source software on my PC and disabled add-ons to Firefox I am beginning to think and to believe that there is something in what some of the geeks used to say and still say about Microsoft's patches and such; namely that some of those pieces of software are there to check on one's system and disable software in use that Microsoft does not agree with or approve of. I have no proof for that and therefore make no claims as to whether or not what others have said and claimed is the truth or not.

All I am beginning to wonder is as to whether “to patch or not to patch?”

Who would have believed that an update patch, in this case Microsoft's Security Update for Windows KB951748, direct from a supposedly reputable source would disable a firewall on PCs and only, so it would appear, the firewalls of one particular company.

Let me hear your thoughts, theories and even conspiracies on this.

And, the question remains, “to patch or not to patch?”

As I have indicated already, I am of a mind right now to turn off, as I had done with previous Windows operating systems, automatic updates, and leave the operating system as it is and just just run the best third-party protection software and keep said programs updated, obviously, ate a more-or-less daily basis.

The “game” with Microsoft updates “killing” off Zone Alarm cost me hours of productive work and while I managed to get back online, protected, with PC Tools' firewall, which, as said, is quite neat and has lots of features, I was missing my Zone Alarm that I was familiar with and with which I have good experiences. This was time that I could have use much better in researching and writing articles or doing other productive work and things. Messing around with a computer when you are not really certain as to what has happened in the first place does not rather as very good entertainment in by book.

I would love to hear Microsoft's response and excuse with regards to this as to how and why and wherefore this happened and what guarantees they are proposing to give and what safeguards they are putting in place that this is not going to happen again with other patches. Mind you, I doubt that we will get a real response from Microsoft at all. Corporations such as that one and especially that one think that they are different and do not have to do things like that.

So, “to patch or not to patch?”

I think my answer – for the time being at least – you all can guess. What say the rest of you?

© M Smith (Veshengro), July 2008

Windows' Genuine Disadvantage

Recently it emerged that Microsoft is removing the "kill switch" from Vista.

When you install Vista, Microsoft claims that you consent to being spied upon, through the "Windows Genuine Advantage" system. This system tries to identify instances of copying that Microsoft thinks are illegitimate. This system includes a "kill switch" which allows Microsoft to remotely deactivate your copy of Vista. This deactivation, whether deliberate or by accident -- as has been the case in some 500,000 cases already according to a study last year -- locks you out of your computer, and forces you to contact Microsoft to get access to your files.

While they may have now ostensibly removed the kill switch from Vista, they have not updated the hostile license they say you must agree to in order to use Vista. Vista still restricts your freedom, because freedom at the whim of someone else is not freedom.

Read on...

'Kill switch' dropped from Vista

Microsoft is to withdraw an anti-piracy tool from Windows Vista, which disables the operating system when invoked, following customer complaints.

The so-called "kill switch" is designed to prevent users with illegal copies of Vista from using certain features.

But the tool has suffered from glitches since it was introduced with many Windows users claiming that legal copies of Vista had been disabled.

Microsoft says its efforts have seen a drop in piracy of its software.

In a statement released by the company, Microsoft corporate vice president Mike Sievert, said: "Users whose systems are identified as counterfeit will be presented with clear and recurring notices about the status of their system and how to get genuine copies."

'Take action'

"They won't lose access to functionality or features, but it will be very clear to them that their copy of Window Vista is not genuine and they need to take action."

Microsoft has described the new approach as a "change of tactics". It said efforts to tackle piracy had seen numbers of fake copies of Vista at half the level of XP, the previous Windows operating system.

The change will take effect with the release of Service Pack 1, a major update to Windows Vista.

Customers who buy a copy of Windows Vista or have the operating system (OS) installed when they buy a new PC are required to validate the OS with Microsoft.

An online tool, called Windows Genuine Advantage, checks the authenticity of the OS to determine if it was legally acquired.

The tool can "lock" Vista from further use if it believes it is an unauthorised copy. But many users have complained that the system is not working because legally bought copies result in error messages.

It was introduced in 2006 as a voluntary option, but became mandatory with the release of Vista, and had problems from the day it was introduced. Mr Sievert added: "It's worth re-emphasising that our fundamental strategy has not changed.

"All copies of Windows Vista still require activation and the system will continue to validate from time to time to verify that systems are activated properly."

Microsoft said it had pursued legal action against more than 1,000 dealers of counterfeit Microsoft products in the last year and taken down more than 50,000 "illegal and improper" online software auctions.

Story from BBC NEWS:

Comment:

Well, still best to go for and Open Source OS, whether Linux or BDS (though I have no experience of the latter). Ed.