Monday, October 16, 2006

Firefox 2 RC3 & Vista RC2 UAC - "launch Firefox when install finishes" runs in administrator's context

Small problem with Firefox vs. Vista's User Account Control. This is not really a bug but I still think Firefox could design around it. Firefox is probably not the only application that might have to worry about this.

So - you're running Vista as a regular, non-admin user.

You go to install Firefox. You're prompted to provide an administrator's credentials. You do.

Now the Firefox installation process is executing in the admin account's context. All good so far. Then the installation finishes, the dialog boxays "installation complete!" and presents a "Finish" button to click. But there's that little checkbox - launch Firefox. If that checkbox is checked, and you click Finish, Firefox will indeed launch and run just fine - as a process in the admin account's context. Which means that everything you do that gets stored in your Firefox user profile - or if you download files to the default location of the desktop - it is actually going into the admin account's profile, or the files are going onto the admin account's desktop - not your desktop!

So, just don't launch Firefox right away after installing it as an admin user. Just close out the installer, then launch Firefox the old-fashioned way: by clicking on its icon.

If I had the time, I'd make this a clearer explanation. If this doesn't make any sense to you, don't worry about it.

So - if Firefox wanted to design around it (really we're talking about modifying the installer, not the underlying app) maybe work out how to have the installer not launch the first run of Firefox using the admin account context but rather go back to the original user account.

Or - hey, wait, why does Firefox need admin rights to install in the first place? Shouldn't it just be able to install as a user-land app? (Or do I have Vista confused with *nix again?)

If I wasn't so lazy, I'd uninstall Firefox then try reinstalling it again without providing admin rights, just to see what would happen. Or I'd google for it.

But nah, I'm done now. Elbow and send....

Tuesday, September 05, 2006

Laszlo gets some

Some good news in Laszlo-land from CNET.
Laszlo lands $8 million to expand applications

Laszlo Systems on Wednesday is expected to announce that it has raised a series C round of $8 million, led by WI Harper. Altogether, it has raised over $26 million. The San Mateo, Calif.-based company, which makes tools for building interactive Web applications, said it intends to use the funding to invest in marketing, expand its partnership program, and develop Web applications.
Congrats!

Sunday, September 03, 2006

Testing before updating corporate client software

How many more times do we have to read one of these "virus definition update breaks things" stories without saying to ourselves "pshew, it wasn't [our brand of AV]."

I'm increasingly wary of simply trusting vendor QA to ensure that we won't have problems caused by automated AV definition updates. And as we have more components of the system (firewall, antispyware, who knows what's next) that follow similar auto-updating, that particular problem will only become worse.

(The same issue applies with system, application, and middleware patches and updates.)

Now, what we should NOT do is stop updating virus definitions (or stop patching & updating systems, applications, and middleware). That's foolhardy: the risk of remaining unpatched against known security exploits, or unable to detect the latest viruses, or living with bugs that have already been fixed is a known Very Bad Thing.

What we need to do is make it safe to update definitions (and patch, and update) frequently.

At a minimum, we should with every definition set install it and do a full scan of a baseline machine and verify that nothing was detected as a virus. The definitions do not go out until that test is passed. (This rule may be bypassed if there is a current SIRT event that the updated defs would mitigate.)

It should be achievable to have a test suite of basic functionality for the desktop image. We already have many of the necessary pieces throughout the broader ECC group, and elsewhere in IS. Assembling them into a manual test plan (v1) is quite achievable. Automating some parts of the test plan (v2) should also be achievable - especially if we assign the task of executing the manual test plan every time there is an environment change to someone with scripting skills (or teach someone who knows how to code in general how to use a scripting tool); you can bet they'll be scripting away by the 3rd runthrough of the manual test plan. However complete automation seems improbable for v2, focus on automating the most annoying parts to execute manually, and add in any easy timesaving automation too.

In a utopic world we would be able to install the defs onto a fleet of vm's, all loaded with those applications that have sufficient business criticality to justify packaging them and setting up an automated test script, run the vm's through the script, and again stop the updates from going out to production if we get failures.

(That utopic capability would of course be used EVERY time we had a baseline change, not just for virus definitions.)

Thursday, August 31, 2006

You preach it, brother Keith

Keith Olbermann speaks truth to power.


Saturday, August 19, 2006

Bruce Schneier Facts is an homage to both the original Chuck Norris Facts and my favorite thinker on security.

Sample Chuck Norris facts:
  • When the Boogeyman goes to sleep every night, he checks his closet for Chuck Norris.
  • Chuck Norris can lead a horse to water AND make it drink.
  • Outer space exists because it's afraid to be on the same planet with Chuck Norris.
  • When Chuck Norris does a pushup, he isn’t lifting himself up, he’s pushing the Earth down.
  • Chuck Norris' tears cure cancer. Too bad he has never cried.
Sample Bruce Schneier facts:
  • When God needs a new secure certificate, he uses Bruce Schneier as the signing authority.
  • Bruce Schneier once killed a man using only linear cryptanalysis.
  • There is no such thing as security by obscurity, but only because there is no such thing as obscurity. Bruce Schneier can always see you.
  • Bruce Schneier can decrypt your PKI message with the public key.
  • Bruce Schneier's tears can burn holes through an OpenBSD firewall. Lucky for us, Bruce Schneier never cries.

Friday, August 11, 2006

The only thing we have to fear...

The Cato Institute says something I actually completely agree with.

Anyway, I've got no argument with this: "Terrorists can be defeated simply by not becoming terrified."

Here's a link to the paper (pdf).

Excerpt:

Frantz Fanon, the 20th century revolutionary, contended that “the aim of terrorism is to terrify.” If that is so, terrorists can be defeated simply by not becoming terrified — that is, anything that enhances fear effectively gives in to them.
The shock and tragedy of September 11 does demand a focused and dedicated program to confront international terrorism and to attempt to prevent a repeat.

But it seems sensible to suggest that part of this reaction should include an effort by politicians, officials, and the media to inform the public reasonably and realistically about the terrorist context instead of playing into the hands of terrorists by frightening the public.


What is needed, as one statistician suggests, is some sort of convincing, coherent, informed, and nuanced answer to a central question: “How worried should I be?” Instead, the message the nation has received so far is, as a Homeland Security official put (or caricatured) it, “Be scared; be very, very scared — but go on with your lives.” Such messages have led many people to develop what Leif Wenar of the University of Sheffield has aptly labeled “a false sense of insecurity.”
Tip o' the hat to Bruce Schneier for pointing me to the paper.

PS on the Cato Institute - Normally I sympathize with the libertarian perspective, but Cato puts a bit more faith in the ability of the free market to optimize social outcomes than I can muster. And I don't think libertarian philosophy has a good answer to the tragedy of the commons problem, either.

Thursday, August 10, 2006

Why aren't businesses switching from Windows to Macs?

I posted this as a comment elsewhere, but then it seemed to disappear into the ether. Since I took 10 minutes writing it I figured I wasn't going to just let it disappear wihtout a fight - so here it is.

I’m another one of those IT guys. Want to know why my company is not switching from Windows to Mac (or Linux for that matter)?

It’s the applications.

Or as Steve Balmer says, “Developers, developers, developers, developers!”

We have over a thousand applications being used at my company.

If we wanted to switch to Mac OS X, we’d have to find Mac versions of those apps, or software with equivalent functionality, and buy the new versions, and get all our users to switch - when they were working well enough in the first place before IT came along to switch them.

We also have tons of web applications - some our own, some bought from vendors and hosted internally, and some bought/rented from vendors and hosted on their websites. Far too many of those require Active X or are otherwise coded specifically for Internet Explorer on Windows.

Saying “use Virtual PC/VMware/Parallels” doesn’t really work for us, because guess what? Then we still have a copy of Windows to pay for, patch, protect against viruses, and so on.

This isn’t because we don’t like Macs. In fact, I’m writing this on a Mac right now, and Macs have been my platform of choice since I bought a Mac SE and learned how to program on it in 1990.

This isn’t because we don’t understand Macs. In fact, for the first several years of my IT career, I had tons of extra opportunities because I am ‘cross-platform’ - I was an Apple-certified technician (and IBM, and HP, and Toshiba, and MCSE) who did hardware repair as well as Mac support & sysadmin work for various Mac-using businesses.

This isn’t because we don’t get that Macs are easier to manage than PC’s. I personally supported far more Macs & Mac users ’soup to nuts’ - from hardware, to software, to building and updating our “Mac image” - than was possible for one Windows tech to support - even with a bunch of specialized people taking care of the necessary infrastructure on the Windows side that I ran myself on the Mac side.

I’ve heard from colleagues at other companies who also found it much cheaper to support Macs and who know they can provide better support to more people with less $$ for tools and fewer technicians. That’s not really up for debate, in my opinion.

But with all our business apps on Windows, how can we switch? How does that help our company make more money?

It doesn’t. And that’s why businesses aren’t switching to Macs.

Could this change?

Sure.

Green-field companies can now choose to use only software that doesn’t lock them to one particular OS/browser platform; there are now choices out there that weren’t there when most of today’s businesses started making their software decisions.

Some forward-looking businesses are keeping this in mind when selecting new software, and thinking that maybe a decade from now all those “only runs on Windows/IE” apps will finally be retired. (This is why Microsoft is pushing developers so hard to write “Smart Clients” that require the Windows-only .NET Framework. “Developers, developers, developers!”)

And it’s not just me in my IS department who feels this way. TONS of IT people - some long time Mac users, but a surprising number of newcomers - are running Macs at home. And liking it! And I think most of them would agree with everything I’ve written here.

But we’ve got all these Win/IE applications that people at our business need to run….so on Windows we will stay.

Sigh.

Friday, July 28, 2006

TiVo Series 3: coming soon, really

Could it be? TiVo HD in reality? I'll be ordering one as soon as they ship, as long as my cable company will let me use it with a CableCARD.

From Ars Technica:
7/19/2006 3:16:43 PM, by Ken Fisher
The much-anticipated TiVo Series 3 is one step closer towards making it out before the close of this year, as an FCC filing (PDF) reveals that the unit is already being tested in select markets, and that the CableCARD certification process is complete. The company is aiming for a release later this year, but pricing has not yet been announced. Based on the cost of the DirecTV HD TiVo, we estimate a launch price of at least US$600.
[...]
The Series3 marks the first truly significant hardware release from TiVo in years, as it combines the convenience of dual tuners (in practice) with the capability of recording HD (previously, only DirecTV customers could use a dual-tuner HD TiVo). To do this, the unit uses not one but two CableCARDs, although it can be configured to use only one card (with diminished capabilities as a result).

Saturday, July 22, 2006

Izzy's first YouTube

Click to play....


Thursday, July 13, 2006

Sorry, It Is America's Birthday

Late the other night, Zeb was still awake in his bedroom. He started singing a song to himself. We recorded it over the monitor.

(We won't be hurt if you don't listen to the whole 5 minutes of it.)

Go here to download it.