Here’s an interesting tidbit: Scalix announced today that they’re going to ship a wireless solution for their messaging product, based on Notify‘s product. Pricing and availability weren’t announced; from a functionality standpoint, Notify has a pretty nice solution in terms of the range of devices and OTA methods they support. However, this may add significantly to Scalix’ “flyaway” cost, making them potentially less attractive compared to Exchange 2003. No word yet either on whether Scalix will require device or mobile CALs in addition to mailbox CALs. Developing…
RPC-over-HTTP considered harmful, if you don’t understand what it’s for
Bruce Schneier is a smart guy, but he also has a strong anti-Microsoft bias. That’s why it’s no surprise to see this article, in which he lambasts Microsoft for “building in security bypasses”. What’s he talking about? A quote from Microsoft’s Martin Taylor:
For example, this new feature tool we have would allow me to tunnel directly using HTTP into my corporate Exchange server without having to go through the whole VPN (virtual private network) process, bypassing the need to use a smart card. It’s such a huge time-saver, for me at least, compared to how long it takes me now.
Of course, that’s our friend RPC-over-HTTPS. I think Schneier missed the point because he misunderstands the intent of the feature, which is to allow mail-only access from remote systems. It’s true that VPNs allow for secure remote access to many different types of resource, often using multi-factor authentication. It’s also true that many VPN systems (particularly the clients) are unstable and difficult to use, particularly from locations like hotels and airports where the network provider may not be clueful. The RPC tunneling feature allows secure access to email only without a VPN. This is actually a security benefit.
Why? Think of what happens when you connect a remote computer via VPN: you’re allowing it unrestricted access to your entire corporate network. That means that when Joe Executive‘s home machine connects via VPN it has free roam of the network. That places a mighty high premium on ensuring that the remote machine is uncompromised, hence the interest in network access protection (but that’s a solution for another day). As an admin, if I have users who only need email, I’m perfectly happy for them to use RPC-over-HTTPS instead of VPN because then I know that their machines are very unlikely to be able to cause damage to other machines on my intranet, no matter how crap-infested they may be. Couple RPC tunneling with an application-layer RPC scanner (like the one in ISA Server 2004) and you’re better off than you would be with a pure VPN solution.
Some of the comments on Schneier’s post make good points about the tradeoff between usability and security, including one guy who asks why VPNs are so hard to use. That’s for another post, unfortunately.
Filed under General Stuff, Musings
Oracle: if you can’t say something nice…
Boy, this is worth a read: Oracle’s chief security officer, Mary Ann Davidson, has an op-ed piece on CNet in which she attempts to blast some security researchers (in particular, she links to this story on Alexander Kornbrust, so I assume he’s target #1). I don’t think I would have taken her approach, for two reasons. One is that it’s going to inflame the BlackHat crowd, and will undoubtedly result in Oracle’s vulns getting much more press than they would otherwise– remember, the tech press loves controversy.
The other reason is that, given Oracle’s recent security troubles, she would have been better off to talk about how Oracle is addressing the legitimate concerns its customers have. She’s right that fixes to even simple vulns still have to go through a full test and release cycle, but she’s being disingenouous in claiming that Oracle has been responding in a timely manner to the notifications they’ve received. They haven’t (and this is not new behavior).
Fearless prediction: Oracle will get publicly spanked by Kornbrust, Litchfield, and probably some others during BlackHat. Davidson will be unrepentant.
Filed under Smackdown!
Escape from Yesterworld
The MS SQL Server 2005 and Visual Studio 2005 teams have a hysterical site called “Escape from Yesterworld” that casts IT development as something out of Flash Gordon. The overall site design is brilliant, and there are some extremely amusing video clips there, including:
- Evil Wears a Cape
- I.T. From Ages Past
- Repetitive Tasks of Doom
- Change Orders of Death
- Terror on Two Wings
Well worth a look– I give it two thumbs up.
Filed under General Stuff, Musings
Enabling and disabling MAPI access
Yesterday I wrote about Simon Butler’s quest to prevent individual users from sending messages via MAPI. In related news, the Exchange team blog has a great post today explaining how Exchange 2003 SP2 gives us the ability to block individual users from using MAPI. The good news: because the MAPI blocking is added to the existing ProtocolSettings mechanism for blocking other protocols, you can use the same script to block or allow multiple protocols at once. The bad news: as with Simon’s original question, this method doesn’t stop existing connections; it only blocks new ones. Still, this is a valuable new capability to have.
Filed under General Stuff, Musings
Killing Rain (Eisler)
So, the obvious first: no, John Rain doesn’t get killed in this book, but not for lack of opportunities. As the book opens, Rain’s in Manila to kill a bomb-maker at the behest of Israeli intelligence. With him is Dox, Rain’s new partner. The hit misfires when Rain makes a spur-of-the-moment decision not to kill the target after seeing him with his family– the target has a son about the same age that Rain was when his own father was killed. That brief moment of hesitation buys him a butt-load of trouble; while exfiltrating, Rain and Dox kill two people who are believed to be CIA agents. The Israelis are worried that Rain’s attempt will be tracked back to them, so they put the word out: John Rain must die.
Trust is one of the central themes of this book. Rain somewhat reluctantly comes to trust Dox after the shootout that ends Rain Storm— but as that trust blossoms, Rain comes to realize how much he’s missed being able to trust people. This is certainly a common problem among contract assassins, but us ordinary Joes can get the idea. As Rain attempts to figure out whether the two dead agents were really CIA or not, and thus dissuade the Mossad from killing him, he’s forced to make some hard decisions about who to trust, and how much.
Another key theme is redemption, for want of a better word. Rain begins to wonder if he’s done any good by his long string of killings, and if perhaps his energies might be redirected to killing evil people instead of whomever he’s paid to kill. Illustrating this, he considers the difference between the Japanese words roughly translating to “sword of justice” and “sword of oppression”. Some reviewers on Amazon have dismissed this introspection as sap or fluff, but I think it adds a great deal of depth to Eisler’s portrayal of Rain. Who among us has not looked back to consider whether his life has been well spent, and whether the remainder could be better spent?
As with preceding books, Eisler moves the action along at a racetrack pace. His descriptions of place are crisp and evocative (I particularly liked his description of Rain’s trips to the rural Philippines), and there is less emphasis on the minutae of Rain’s hand-to-hand fights with his opponents (more knife- and gunplay, though). Because I’m not a judoka, this made the book way more readable for me.
I can’t say much about the denouement of the book except that it sets out very clearly what’s going to happen in the next book, and that it contains a plot twist that I certainly didn’t anticipate that sets things up neatly. I’m eagerly looking forward to the next book, but I only have to say one thing until then: jazz goes with New Orleans. Highly recommended.
Update: I found this essay by Eisler that describes the backstory behind Killing Rain. It’s pretty darn interesting.
Filed under Reviews
Unbelievable: Kärcher USA
Update 4/30/08: the gentleman whose name appeared here as the CEO of Kärcher USA is no longer with the company. At his request, I removed his name from the post.
I own a Kärcher electric pressure washer. I bought it because it was reputed to be from a solid company. Over the five or so years that I’ve had it, it’s worked well enough, but it failed, so I wanted to get it repaired. Here’s the deal:
- if you have a gas pressure washer, you can take it to one of Karcher’s service centers.
- If you have an electric pressure washer, and it’s under warranty, Karcher will exchange it for a refurbished unit under their “rapid exchange” program.
- If you have an electric pressure washer, and it’s out of warranty, too bad. Karcher won’t fix it. I spoke to Shane, at their customer service [sic] center. He said, “Oh, if you want to fix it, you can order the parts from us.”
So, I fired up Word and made ready to send them a letter asking how I could get the unit fixed. Surely what Shane told me can’t be right. However, here’s what I learned:
- The Karcher USA web site doesn’t list an address or telephone number for their US office.
- The customer support number on their website goes to what’s obviously an outsourced firm; they’ll only give out the company address, not the phone number. That’s because (drum roll) they don’t have it
- If you use an online directory to find their phone number, the listed telephone number for their Atlanta office rings incessantly; no one ever answers
- Their press releases don’t include any contact information
- The press release site for the parent company requires a user name and password to log on
After a whole bunch more web searching, I found their correct address (2825 Breckinridge Blvd, Suite 120; Duluth, GA 30096) and phone number (678-935-4545). No one answers that number, either, but I plan to keep trying until I get a human. In the meantime, I’d certainly advise against buying anything from these folks, given their unusual mastery of customer-avoidance techniques.
Update: I found this page, which lists XXX as the CEO and 678-935-4550 as the fax number. Score!
Update: I faxed them a letter. It’s in the “more” section.
Update: I got a call on Friday, July 29, from a customer service rep who offered me a discount on a remanufactured unit. He was supposed to send me some email explaining which units I could choose from– but lo and behold, 10 days later, no email. Hmmm. (And yes, I checked the spam filter logs; no such email ever arrived here)
Filed under Smackdown!
Bluetooth needs a bluedentist
Wow, this article made my head hurt. David Berlind of ZDNet documented all the stuff he had to do to get his XV6600 to work via Bluetooth as a modem for his laptop. I admit that I never bothered to try this while I had a loaner XV6600, fearing that it would be too hard to be worthwhile. Here’s Berlind’s conclusion:
OK, now that we’re done, and some of you now have the best step by step you’ll ever find for getting a DUN connection working with Bluetooth, what does it tell you that takes nearly 40 distinctly separate screen shots or photos to document something that should be a lot simpler?
It tells me that I’m sticking with my aircard, thankyouverymuch.
Filed under General Stuff, Musings
Stop me before I mail again
Exchange MVP Simon Butler posed what seems like a simple question: how do you stop a user from sending mail? The answer is deceptively complex; we’ve been debating this on an MVP list for a few days now.
Say you have a MAPI user. You disable the associated Active Directory account, either by disabling the account or by changing the password. In either case, the user can still submit mail to the information store! In the case of a password change, the user will be asked to authenticate again, but if she cancels the password dialog, she can still send– she just can’t receive new mail! That might be a problem in case of an employee who’s leaving (voluntarily or not), although a measure of physical access control will help.
You can kill the MAPI session, but that doesn’t do anything to stop the user from reconnecting from the client side, at which point you’re back to square 1: the user can still send mail. (This doesn’t seem to be true if the user quits and relaunches the client after you kill their session, though).
For other protocols, it’s easy to prevent users from connecting and sending mail. For example, for IMAP, POP, or HTTP connections, you can just remove the user’s ability to use those protocols by using the Exchange Features tab in AD Users and Computers.
If you want to block all users, you can do that too; KB 288894 describes how to limit MAPI connections to a particular version of Outlook (so just set the regkey to deny from the current version (which I think is 11.0.6352.0) backwards. For HTTP, you can either set an IP address restriction on the Exchange vdir (thanks, KC!) or stop the w3svc, although this will have other effects. For that matter, if you want to prevent all client access, stopping store.exe will do the trick nicely at the cost of a service interruption.
Perhaps MS will fix this in Exchange 12.
Filed under General Stuff, Musings
Getting ready for Sturgis
Mom and Arlene are planning the menus and packing. The boys are asking “Can we buy a pop gun?” and saying things like “I’m so ‘cited about seeing Mount Rushmore” at random intervals. I’m looking for wireless access and squaring away my radio gear, and Dad and Tim are getting their bikes ready. It’s almost time!
Comments Off on Getting ready for Sturgis
Filed under Travel
Finding connectivity in South Dakota
I leveraged McDonald’s wireless service when I was in rural Louisiana, but it looks like I’ll have a tougher time getting connected while I’m at Sturgis. The nearest McD locations to Hill City, where we’re staying, are in Rapid City, and none have Wi-Fi. Verizon’s coverage map shows no coverage for Hill City, although the surrounding areas have digital service– hopefully I’ll be able to use my aircard. There’s a local ISP, RapidNet, that may be able to help, too.
Filed under General Stuff, Musings
Turning DDoS attacks around
Interesting press release this morning from Blue Security, touting their new “Do Not Intrude Registry”. The basic concept is simple: you sign up for their service and install an agent on your local computer. Blue creates honeypot mailboxes, which it then monitors. If spammers spam those mailboxes with messages that don’t comply with the CAN-SPAM law, Blue asks the spammers to stop. If they don’t, the Blue agent (which they call a Blue Frog, after the blue poison arrow frog) starts spamming the spammers by posting junk data to their order form. This is no big deal if only one agent does it– but the agents are cooperative, so if the spammer sends out 10,000 messages, they get 10,000 junk order submissions.
The PR calls this “ethical and effective”. I disagree on both counts; it’s nothing more than a botnet in disguise. If it’s wrong for J. Random Attacker to mount a DDoS against a website they don’t like, it’s wrong for Blue to mount DDoSes against spammers. Despite the fancy language deployed by Blue’s CEO in this InformationWeek article, it’s pretty clear that this is a clear-cut DDoS approach– Blue is trying to hit the spammers where it hurts by degrading their operational capacity to take orders.
I don’t condone spammers, but descending to their level isn’t an ethical approach. In a remarkable coincidence, most of the sentiment on /. seems to agree that this is a bad idea.
Update: but don’t take my word for it; legendary guru John Levine has weighed in with his thoughts (including the interesting fact that Blue tried to get sponsorship from a number of anti-spam orgs, all of whom rejected the idea).
Filed under General Stuff, Musings
Comment test
Betty’s told me several times that she can’t leave comments here, so I’m trying to get to the bottom of the problem. Please leave a comment on this post so I can wring the bugs out of my commenting code. Thanks!
Filed under General Tech Stuff
Skating
Last week, I got a call from my friend Scott. He teaches our adult Sunday School class, and his wife was scheduled to have a baby on Friday; he wanted to know if I could teach class for him. “Sure,” I said, and I dutifully prepared lesson 28 from this year’s manual. It was a fascinating lesson on God’s purposes in allowing adversity– something that the early Saints certainly learned a lot about as they moved from Ohio westward to the Salt Lake Valley. Anyway, when we got to church this morning, there was a strong stench of polyurethane from the newly refinished floor in the “cultural hall” (which most of the world would call the gym). Arlene was asked to pinch-hit and teach a lesson on temple marriage to the 16-to-18-year-olds; the original teacher was out sick, and the substitute was feeling ill too. Then we found out that the three kids who were supposed to give talks in Primary weren’t there, so our boys were on tap. Arlene spent much of the first hour cramming with her lesson manual while I tried to alternate between listening to the speaker (we had three excellent talks today) and quelling rebellion in the ranks. We got a last-minute reprieve, though; the fumes were so bad that Brother Czarny cancelled our meetings once Sacrament Meeting was over, so none of the five of us had to teach or talk today. Woo hoo! (I’m sure there will be paybacks next week, though!)
Thought for the day: we’re asked to be willing to serve the Lord. That doesn’t mean that we’ll have to, only that we should be willing to.
Comments Off on Skating
Filed under Spiritual Nourishment
Ashdown vs Urquhart for Utah Senate seat
So, now there are two challengers for Orrin Hatch’s seat in the US Senate. Despite the fact that Hatch is nominally from Utah, he’s getting a lot of attention in the upcoming race because of his persistent anti-technology stand (here’s just one example). Now there are two challengers. Yesterday, Doc Searls mentioned Steve Urquhart, the Republican majority whip in the Utah House; he’s going to challenge Hatch in the Republican primary. Boing Boing mentioned Democratic challenger Pete Ashdown yesterday, too (although so far they haven’t responded to my email pointing out Urquhart’s candidacy).
Interestingly, both candidates blog. However, on Urquhart’s blog, he links to news stories at the original source. On Ashdown’s site, he’s copied most of the articles to his own server and modified them by removing ads. I asked Ashdown about that, and he said that he had permission from the reporters, but he hasn’t answered my follow-up question about whether he has permission from the rights holders- a critical distinction.
Neither candidate has defined his platform in much detail; Ashdown seems to be saying (in this article) that he’ll position himself as “not-Hatch” and choose whatever platform seems to resonate with potential voters. Urquhart has a slightly better defined platform, going after Hatch’s anti-tech attitude and his support for stem-cell research, among other things. It’ll be fascinating to see how these two tech-savvy candidates use the Internet to mobilize support both inside and outside Utah. After all, since both are gunning for Hatch based in part on his support of DMCA and copyright extensions, it seems to me that both will be fighting over the same support dollars from organizations like the EFF and Downhill Battle. We’ll have to wait and see…
