About Joe Wein

Software developer and anti-spam activist

Microsoft does listen to (some of) its users

Two weeks ago, Infoworld magazine launched a “Save Windows XP!” campaign. Within 5 days, over 164,000 people signed it, demanding that Microsoft do not end OEM and shrinkwrapped sales of Windows XP on 30 June 2008 as announced, but keep it on the market indefinitely. Microsoft did not seem impressed, as the following quote in PC World shows:

The spokeswoman said Microsoft is aware that some customers are pushing for an extension to the deadline — more than 160,000 people have signed a “Save XP” petition launched by Infoworld magazine, for example. But the company has also done its own research among partners and customers, and feels that “the dates are right,” she said, speaking on behalf of Microsoft.

“We feel we’ve made the right accommodations for customers in certain segments who may need more time to transition to Windows Vista,” she said. “But as [Microsoft CEO] Steve [Ballmer] noted, we maintain a constant stance of listening to our customers and our partners. That’s what is guiding our plan, and will continue to guide us going forward.”

I don’t know who Microsoft listens to, but personally I don’t know a single person who prefers Vista over XP. Some of the comments I hear are unprintable. Yesterday, a friend of mine allowed Windows Update to install some updates to his copy of Vista and since then he’s been unable to access the network. Many coroporates still maintain a blanket ban on it and stick with XP.

On the other hand, quite a number of Mac and Ubuntu fans are simply thrilled how much Vista has contributed to driving up interest in their platforms of choice.

Still, I suppose amongst hundreds of millions of Internet users there must be some who are genuine fans of Vista, despite its well documented shortcomings. When Microsoft claims that its death sentence for XP was based on user input, it may not exactly be lying: I suppose most Microsoft shareholder are Microsoft software users too.

Forcing people to buy a more expensive operating system may boost Microsoft’s revenue in the short term. In that sense, it may be in the interest of those users who also happen to be its shareholders. In the long term however it never pays to ignore your customers’ needs. About twenty years ago, IBM tried to force the PC market to switch to its proprietary Micro Channel Architecture (with IBM PS/2 range). The result was that IBM lost control of the PC market place to Compaq and other companies who took over. Microsoft is every bit as arrogant now as IBM was back then and it will suffer the consequences.

Ubuntu 8.04 LTS released

The latest version of Ubuntu, the most popular desktop version of Linux on the market, was released on Thursday, 24 April 2008.

New versions are released every six months and labelled after the release year and month, therefore the latest will be known as 8.04, replacing 7.10. The “LTS” suffix stands for “Long Term Support”, as this version will be supported for three years.

The new version, code named “Hardy Heron” bundles the new FireFox 3.0 web browser, updates to photo management and video and music-related features. It can also install on top of an existing copy of Windows without the need to repartition the hard disk. This lowers the barrier to entry for new users who, if they’re not happy with Ubuntu, can always remove it using the Windows Control Panel, just like any other Windows application.

If you have a bittorrent client such as uTorrent, you can download ISO images of install CDs and DVDs via this page:

http://torrent.ubuntu.com:6969/

Links:

Iraq, five years later

On occasion of some spring cleaning in my office I stumbled across an old copy of The Economist (April 5-11, 2003) published as the US forces were marching on Bagdad during the invasion that eventually swept Saddam Hussein from power.

I was opposed to that war at the time (it’s not hindsight, you can ask my wife!) and still am, but with the benefit of five years of experience of how things actually turned out it is interesting what the editors had to say then. I still respect the Economist as (overall) a relatively unbiased source of information though I’m no longer a subscriber.

The defect of these comparisons [with Vietnam and Palestine] is that Iraq is nothing like Vietnam, not much like Palestine or Afghanistan, and, on present evidence, no quagmire. (…) In Vietnam the Americans fought for ten years. The Soviet army spent ten years in Afghanistan. This war entered its third week with the Americans battering through Iraq’s Republican Guard divisions to the gates of Bagdad. At this rate, it will be a surprise if the Americans have to fight for ten weeks, let alone ten years. Israel’s occupation of the West Bank and Gaza has lasted for 36 years. If America has its way, its occupation of Iraq is more likely to last for fewer than 36 months. And there is no reason why America should not have its way: unlike Israel and the Palestinians, America and Iraq have no territorial quarrel. America’s stated aim is to remove the regime and its mass-killing weapons, allow the Iraqis to replace their dictatorship with a representative government, and then depart.

Well, those 36 months (3 years) already expired more than two years ago and no departure is in sight yet. Even someone who would (if elected to the highest office in the country) withdraw the troops after roughly twice that time has to face accusations of wanting to “cut and run”, while John McCain is talking about staying in Iraq for a hundred years.

Not only the time scales have shifted: Before President Bush decided to invade Iraq, his country was the only remaining superpower, having lost the Vietnam war but won the cold war. Following September 11 his people and country had an enormous amount of good will on its side from people and governments all over the world. Now the country is bleeding hundreds of billions of tax dollars and hundreds of lives every year in an undeclared war it can’t win. The Iraq war is deeply unpopular at home and abroad, not to speak of Iraq, where tens of thousands have died in the resulting civil war and “ethnic cleansing”.

The biggest winner of the US effort in Iraq so far has been the unfriendly regime in next door Iran, which saw one of its biggest enemies destroyed at the hands of the US, allowing its closest friends and allies to take over in Iraq.

I am looking forward to a new leadership in the White House that will have the courage to face reality: When you’ve taken a wrong turn you don’t then “stay the course”, especially when you’re heading into a dead end.

Recommended reading:

Yahoo! Mail “0000-00-00 and 9999-99-99” bug

You may have noticed emails from Yahoo accounts recently that include the string “between 0000-00-00 and 9999-99-99” at the bottom of the email. Apparently it gets added to outbound email only on new emails that were composed.

It’s a bug in Yahoo which crept in on April 15 during an upgrade. It’s an issue related to accessing the MySQL database and a date / time comparison. There is no way for Yahoo! Mail users to fix the problem, but it also doesn’t appear to cause any harm beyond thoroughly confusing everyone.

Yahoo is aware of the problem. Their current statement on it is:

“Please be assured that we are aware of this issue and have escalated this to our Engineering Department for further investigation. We hope to have it resolved as soon as possible”.

Toyota Prius hybrid versus BMW diesel

The Sunday Times did a road test, driving a BMW 520d SE and a Toyota Prius from London to Geneva. The BMW used 49.3 litres of diesel, versus 51.6 litres of petrol (gasoline) used by the Prius.

While the BMW’s results are clearly respectable, the figures quoted in the Sunday Times article do not tell the whole story.

For a start, about 40% of the trip were on motorways, another 40% on B-roads and the rest in urban areas. A driving mix that includes only a token 20% of urban driving is hardly typical for usage patterns of most motorists in our largely urban / suburban societies (for example, 79% of the US population lives in urban areas, with most European countries having similar rates). This unusual mix seems almost purposely designed to ensure that the advantage of the hybrid drive train of the Prius would lie mostly idle: Driving at constant speed on a flat road, you are not going to see any real benefits from a hybrid system, which really thrives in stop-and-go rush hour traffic with lots of traffic lights, as most of us experience on the way to work or home.

Secondly, even with these skewed parameters, the BMW lost out on greenhouse gas emissions. It burnt 10.84 Imperial gallons (13 US gallons) of diesel, while the Prius used 11.34 Imperial gallons (13.6 US gallons) of gasoline. Because of diesel fuel’s 15% higher carbon content by volume, the BMW added 131 kg of CO2 to the atmosphere versus 120 kg by the Prius.

Personally, I see no reason why in the long-term efficient diesel engines can not be mated to a hybrid system and have the best of both worlds. Sure, it may not yet be cost-effective at current fuel prices, but things may look very different 10, 20 or 30 years down the road.

Japanese petrol (gasoline) prices to fall 25c per litre

Following political gridlock in the Japanese parliament, a “temporary” tax on petrol (gasoline) that has been in force for three decades after being renewed every couple of years is set to expire on 01 April 2008 (to readers outside of Japan: No, this is not an April Fool’s joke). As a result prices of petrol are set to fall by 25 yen per litre (about US$0.95 per gallon, EUR 0.16 per litre).

I’m utterly unimpressed by how both major Japanese parties have handled this conflict.

Fuel taxes in Japan consist of the basic fuel tax and a “temporary” but de-facto permanent surcharge. The ruling conservative Liberal Democratic Party (LDP) wanted to hold on to the surcharge, as well as to a peculiar rule that fuel taxes must only be used for road construction and repair. This road-use-only restriction was defended by the so-called “road tribe”, an informal group of politicians with cozy ties to construction companies which in turn support their election campaigns.

The opposition Democratic Party, which controls the less powerful Upper House of parliament, called for dissolving the fuel – road construction link, as well as abolishing the surcharge altogether and only keeping the basic fuel tax, as it was until the 1970s.

The two did not compromise in time before the set expiration date and so prices will fall from tomorrow. Most likely the Lower House, which is controlled by the LDP-led coalition, will override the Upper House about one month later and reimpose the higher tax rate. Meanwhile Prime Minister Fukuda offered to remove the road construction link from April 2009 in order to get the opposition to agree to an extension of the surcharge.

While motorists will welcome cheaper fuel, petrol stations are likely to collectively lose about US$200 million over night, as they hold stocks of some 800 million litres of petrol in their underground tanks on which the tax has already been paid and which will not be refunded to them. Motorists are likely to give their business to whatever petrol station that starts selling at the new low prices first, making it near impossible for other stations to pass on to the consumer the taxes these stations have already paid on stocks delivered before April.

To me it makes no sense to maintain the outdated restriction on how fuel taxes can be used, which serves primarily the interests of construction companies, not the general public. Japan as an aging society with a declining population will need more and more cash for supporting elderly people and their health care, not more and more roads. Why can’t taxes be used where they are needed the most? This pork barrel restriction should have been abandoned a long time ago!

On the other hand it would be irresponsible to cut fuel taxes while the government is running a huge budget deficit. It would just mean more red ink, piling up higher debts to be repaid by our children and grandchildren. Also, cheaper fuel today will do little to encourage consumers to switch to more economical cars or public transport and to cut their output of greenhouse gases. Japan is already way behind on its efforts to meet its obligations under the Kyoto climate treaty.

It would make more sense to maintain and even raise fuel taxes and use the revenue to subsidise CO2 conservation measures, from better home insulation to solar collectors for warm water and subsidies for hybrid cars. Thirty years from now the world will live on maybe half the crude oil output per year as today, shared amongst more consumers. Whatever country comes up with intelligent solutions for living with scarce and expensive oil will do best in the 21st century. Trying to sneak back into a “golden age” of cheap fuel is not the way to succeed.

First impressions of Vista and Ubuntu

Last week I was on a business trip to the USA and decided it was finally time for me to buy a new notebook computer. Here in Japan it’s difficult to get machines with US keyboards.

My previous one was a 650 MHz Pentium III whose RAM was maxed out at 512 MB while my main desktops and servers have 2 GB or more. Lack of RAM slows down PCs much more than a slow clock speed does. People who buy entry level Vista machines equipped with only 512 MB would be better off with a sub-1 GHz CPU but a full 1 GB of RAM.

I picked a Gateway M-6750 with a 1.66 GHz Core 2 Duo CPU, a 250 GB 3.5″ hard disk and 3 GB of RAM. It comes with a built-in microphone and webcam, very handy for Skype-addicts like me.

Every single machine at Best Buy and Circuit City that I looked at came with some form of Vista preinstalled. Microsoft sure does not want to give customers any choice whether they stick with XP. Ideally, I would have wiped off Vista and installed Windows XP on it. Until now I had kept my office a Vista-free zone, but knowing that occasionally I will needed to test some software on it, I stuck with it for the new machine.

I spent some time reconfiguring the Vista desktop to be as Windows 2000 and XP-like as possible. The constant alerts to permit some actions I had requested soon became annoying. Often a single operation results in the user having to agree two or three times. Inevitably, agreeing to anything without giving it much thought soon becomes a habit. Does Microsoft seriously believe that training users to constantly click “Allow”, “OK”, “Yes” will lead to a noticeable gain in security?

So far I have seen little reason for anyone to upgrade from Windows XP or Windows 2000 (my favourite Windows version) to Vista. Sure, there is plenty of new eye candy, but who but the makers and vendors of graphics chipsets, CPUs and RAM benefits from that? Users spent countless hours relearning the user interface and getting old application working (or replacing them). Even for upgrades from Vista to Vista Service Pack 1 there were so many land mines that Microsoft decided to hold off general availability of SP1 via Windows Update for several more months.

One of the reasons I picked this model was its large hard disk, because I was planning to also run Ubuntu. I downloaded the ISO image and burnt it to DVD using the burner software included with Vista. Ubuntu initially boots off a live DVD that includes an installer. The installation was fairly straightforward. The installer shrank the Windows NTFS partition to make space for Ubuntu. After the main installation it downloaded close to 200 updated packages and fixes, then it was all done. The default configuration took up only 2.4 GB of disk space.

I was impressed that I can access shared folders and volumes on Windows machines from Ubuntu, as well as being able to read files in the NTFS (Windows Vista) partition on the drive.

There were two driver issues however, which I have yet to resolve [now partly resolved, see updates below!]:

  • The sound hardware is missing a driver. The loadspeaker symbol in the top right corner of the desktop is showing disabled and I can’t get sound output on the builtin speakers.
  • The builtin wireless card doesn’t appear to be suppported. I can only connect to the LAN and internet by using a wired connection.

In general, driver support in Ubuntu is good, but there are obviously still some rough edges. It would help if Gateway and other manufacturers were to offer pre-configured Ubuntu machines, as Dell already does.

Similar driver issues can occur on Vista. In fact, last week I was helping set up an AOpen MiniPC, which had been upgraded to Vista after a memory upgrade from 512 MB to 1 GB and it also had issues with its wireless, which wasn’t supported until a couple of Windows Update runs.

I think Linux and in particular Ubuntu will become an increasingly serious challenger to Microsoft’s de-facto monopoly on the desktop and not before time.

Update, 2008-03-14:
Ubuntu 7.10 (“Gutsy Gibbon”, released in October 2007) detects the sound hardware on this Intel chipset, but there doesn’t seem to be a driver for it yet. When I enter ” lspci -v” at the shell prompt, it lists this:

00:1b.0 Audio device: Intel Corporation 82801H (ICH8 Family) HD Audio Controller (rev 03)
Subsystem: Gateway 2000 Unknown device 0380
Flags: fast devsel, IRQ 22
Memory at fa500000 (64-bit, non-prefetchable) [size=16K]
Capabilities: [50] Power Management version 2
Capabilities: [60] Message Signalled Interrupts: Mask- 64bit+ Queue=0/0 Enable-
Capabilities: [70] Express Unknown type IRQ 0

I checked the sound drivers for Intel chips listed at http://www.alsa-project.org/main/index.php/Matrix:Vendor-Intel and it appears the ICH8 chipset is not supported yet.

Update, 2008-03-18:
The Marvell TOPDOG wireless adapter is now working with Ubuntu, by following the advice given by others and installing the Windows 2000/XP drivers for the hardware using ndiswrapper. I had first tried the Vista driver, but had no luck with that. The Ndiswrapper project page on SourceForge specifically recommended to avoid Vista drivers and use Windows 2000 or XP NDIS drivers. For PCI device ID 11AB:2A08 you need the NetMW14x.inf file which references the two driver files NetMW143.sys (for Windows 2000) and NetMW145.sys (for Windows XP).

The following threads and instructions proved very helpful, please read them both if you have the same problem as I did:

  1. https://help.ubuntu.com/community/WifiDocs/Driver/Ndiswrapper
  2. http://ubuntuforums.org/archive/index.php/t-575785.html

Here is what I did after installing the Ndiswrapper software and copying over the Windows drivers from a Windows machine where I had run the installer:

$ sudo ndiswrapper -i NetMW14x.inf
installing netmw14x …
$ sudo ndiswrapper -a 11ab:2a08 netmw14x
WARNING: Driver ‘netmw14x’ will be used for ’11AB:2A08′
This is safe _only_ if driver netmw14x is meant for chip in device 11AB:2A08
$ sudo ndiswrapper -l
netmw14x : driver installed
device (11AB:2A08) present

After that I followed the instructions for Configuring Wireless Network Settings. Voila! Wireless network connectivity under Ubuntu anywhere in the building!

Update, 2008-04-16:
Drew’s advice on how to get sound working did the trick for me too: I can now use the audio on my Gateway M-6750. I ran this as he suggested:

sudo apt-get install linux-backports-modules-generic

and restarted the machine. Thanks, Drew!

Microsoft subsidizes Nigerian scammers

A four-part series of blog postings at Artists against 419 discusses in detail the massive abuse of Microsoft’s OfficeLive (MSOL) webhosting service by Advance fee fraud scammers, which I mentioned in a previous blog post here. Currently I come across such MSOL domains at a rate of about two new ones per day.

As the Artists point out, one of the reasons for the large number of scam domains hosted at MSOL is that unlike other webhosting services where customers get their own domain, they are not charged any fees for registering and using a domain. Microsoft appears to be so desparate to find any business willing to host their website with them using the basic webhosting package that they fork out cash to VeriSign for the .com / .net domain registration fees. To secure against abuse, the user has to supply a gredit card when signing up, but no charge is ever made to that card. All that MSOL will do with it is get authorization from the card company to charge $1 to it (that means, the card company will verify that the card exists, has not been cancelled and that current accumulated charges since the last statement are at least $1 below its set spending limit). Those $1 authorizations will not show up on a monthly statement that the owner of a card whose data has been stolen could see. If the owner doesn’t see unauthorized charges he has no reason to cancel the card and the scammer could use the same card over and over to register hundreds of scam domains, while Microsoft pays hundreds of dollars in domain registration fees to VeriSign and scam victims lose thousands of dollars to the scammer.

The article series then discusses the problems with trying to get MSOL to take action against the criminal abuse of their system, which appears to be so broken that even a domain that has been disabled (no working website) can still be used for sending email, which is all that some 75% of scammers ever use it for anyway, according to the Artists.

Read the article series here:

Update on child porn hosted at Yahoo

Four weeks ago I reported that Yahoo seems to finally have got a handle on the problem of criminals abusing its webhosting service for posting child pornography. Alas, the porn spammer only seem to have taken a vaccation. After those 4 weeks of almost no new child porn sites, they returned. I counted 36 new domains used for hosting child porn between December 12 and January 5.

To their credit, Yahoo have responded promptly to every single report I sent them and have shut down the sites, but it would be far perferable if they took measures to ensure they catch fraudulent registrations before the scammers have a chance to send spam and collect credit card signups from people who respond.

Yahoo abuse handling improves, OfficeLive and Earthlink have their work cut out

Nine months ago I reported about a series of child porn sites that were being illegally hosted at Yahoo’s webhosting service. At the time I was seeing about half a dozen new sites pop up every day. I am glad to report that about 4 weeks ago Yahoo finally seems to have done something to stop this. After 18 months of a steady stream of new porn sites that I reported, things went quiet after two sites it suspended on November 5, 2007 that I had reported eralier that day. For the next two weeks I didn’t come across any new sites. Another 9 sites I came across on November 20, 21 and 22 were quickly terminated. Then again no new sites to report for three weeks. Thank you, Yahoo, for stopping these criminals! I don’t know what Yahoo did to prevent fraudulent signups (child porn webhosting signups usually involve stolen credit card data), but whatever it is seems to be working. Now if it could only stop the phishing scammers that still abuse their service.

Meanwhile, two other webhosts constantly keep popping up in connection with various Nigerian scams. For many months Microsoft’s OfficeLive has been the clear leader. I did some counts a few months ago and found that amongst domains connected to Advance fee scams that I was adding to the SURBL blacklist, more than half were hosted at OfficeLive, i.e. more than for all other webhosts combined!

Unlike most other webhosts, OfficeLive does not appear to maintain an abuse reporting email address to which to forward scam reports. All they have is a webform.

The runner up amonsgt Advance fee fraud domains has been Earthlink.net, where numbers seem to be increasing. If you try to report fraudulent domains that have appeared in contact addresses listed inside a scam email, such as a “claim agent” for an “email lottery” or an immigration lawyer for an international employment scam, do not waste your time contacting abuse@earthlink.com. All you would get back is a boilerplate message that the message you reported did not originate from an Earthlink account, which may well be true, but is besides the point. Here’s an example:

Hello,

Thank you for submitting a report to the EarthLink Network Abuse
Department. Unfortunately, we are unable to investigate the email you
forwarded because it does not appear to have originated from the
EarthLink network.

For instructions on determining the origin of an email, please visit:

http://support.earthlink.net/tutorial/mailbox/interpret_headers/

If, after reading the above article, you find that the email did NOT
originate from the EarthLink network, we encourage you to submit the
email to the appropriate network.

If you were trying to report fraud (“phishing”), please contact our
Fraud Department via our Fraud webform located at:

http://securitycenterkb.earthlink.net/fraudmi.asp?route=email

If you find that the email DID originate from the EarthLink network,
please reply directly to this email.

The EarthLink Appropriate Use Policy, Users Agreement, and Privacy
Policy are available at: http://earthlink.net/about/policies

We appreciate your assistance.

Sincerely,

EarthLink Network Abuse

The email I had been trying to report had been sent from a Gmail account, but it was telling people to contact an email address that used an Earthlink-hosted domain name.

I will give the Earthlink fraud report webform a try. Hopefully it works better. Webforms are poor substitute for reporting abuse via email. Much abuse will remain unreported if abuse reporting involves much more than hitting the forward button. Criminals will keep flocking to those providers who do not have effective abuse handling departments, such as OfficeLive and Earthlink.