PowerShell development environment

I haven’t had a chance to try it yet, but this integrated development environment (IDE) for PowerShell looks extremely cool. Having a debugger, syntax highlighting, and Intellisense for PowerShell would be really handy for building, say, a PowerShell version of the cookbook…

Comments Off on PowerShell development environment

Filed under General Tech Stuff

Hardware failures galore

It’s been a tough two or three weeks here, at least for computer hardware.

First, I flattened my trusty ThinkPad. Ryan Femling, my coworker, says you can easily go two or more years without performance problems on a stable Windows install. He’s right; I got just over three years out of the install, but for some reason, the machine had decided that it would permanently disable both its wireless card and its onboard Ethernet port. That made it, if not useless, much less useful. There wasn’t anything wrong with the hardware; some combination of Windows patches and software installs/removals apparently whacked the driver. A clean install using IBM’s recovery partition certainly fixed things up.

The next weekend, I came back from Michigan to find my only x64 machine (an Athlon 3800+ in an ASUS A8N) was beeping every two or three seconds. All the fans spin up normally, but the machine just sits there and won’t POST. I haven’t started diagnosing it yet.

Two nights ago, our electrician was here doing some work. He had to take down house power, so I cleanly shut down all my servers. When the power came back on, my primary file server wouldn’t boot. After a little troubleshooting, I found that the video card was at fault; after I removed, cleaned, and reseated it, I was back in business. Coincidentally, Windows maven Ed Bott had the same problem two weeks ago, and his post is what reminded me to check the video card first, so I’m passing the tip on.

And another thing, which I originally forgot: I lost a 16-port network switch early Wednesday morning. It was making a cool frying-bacon sound when I came downstairs; this is annoying since it’s the link to the ground floor of the house. Until I replace it, no Internet in Arlene’s workroom.

Comments Off on Hardware failures galore

Filed under General Stuff

Walter Glenn has a blog

Thanks to Technorati, I just found that Walter Glenn has a blog; with characteristic modesty, he hasn’t been plugging it anywhere, so I found it through searching for links to my own blog! Walter and I first worked together on an MCSE guide for Exchange 5.5 back in 1998 or so. He’s a great guy and knows a ton about Windows and Exchange. His blog is focused on simple tips for making Windows easier to use– check it out.

Comments Off on Walter Glenn has a blog

Filed under General Stuff

TechNet Radio interview

I just got off the phone with Chris Avis of Microsoft’s TechNet Radio podcast series; we chatted about Exchange 2007, PowerShell, unified messaging, and my lame Xbox 360 skills. The podcast will go live next Tuesday; I’ll post a link to it when it’s up.

Comments Off on TechNet Radio interview

Filed under UC&C

How’d we pick the products for the anti-phishing test?

I’ve gotten several inquiries about how we selected the products we tested in the anti-phishing technology evaluation. That’s a fair question; some companies are unhappy that they were included, and some that they weren’t.

When we defined the parameters for the testing, we selected the vendors that had either browser-based toolbar add-ons or built-in anti-phishing technology in the browser as of May 2006 and that (in our opinion or by market data) had a significant usage presence. There are dozens of products that meet the first test, but not that many that meet the second. We picked the top 8 based on our understanding of actual usage and deployment. I didn’t want to include payware products because the original objective was for us to help Microsoft understand how well IE 7 worked compared to its biggest competitors– and in this market segment, payware products are at a disadvantage.

Would we have preferred to test all the products? Sure. The team at Carnegie Mellon that did a similar study (with a smaller list of products and a smaller set of URLs) said the same thing. However, we had to draw the line somewhere. When we redo the tests, we’ll probably change the product mix around; I’d expect to see Firefox 2.0 included, and maybe some of the commercial products.

To address Symantec’s complaint, I’d make two points. First, Norton Confidential wasn’t announced until June, so how could we have included it? You’re making the Firefox argument. We only tested products that were publicly available at the start of our time period; we excluded Norton Internet Security 2006 because it was commercial (and I suspect that if we’d tested the 2006 version, we’d be hearing that we should’ve tested the 2007 version instead. Sic transit gloria annual releases…)

Second, it’s pretty worthless to have a blog but not allow comments or trackbacks. That’s not a blog, it’s a monologue. Whatever you think of the quality of Microsoft’s products (including IE), you have to admit that they have aggressively embraced blogging as a way to communicate directly with customers– something I’d like to see more security companies emulate.

Update: fixed the link to McAfee’s SiteAdvisor blog.

Technorati Tags: ,

Comments Off on How’d we pick the products for the anti-phishing test?

Filed under Security

More on e-mail-enabling SharePoint

As a follow-up to last week’s post on public folders and SharePoint, Liam Cleary has a pretty good walkthrough that covers the process of setting up SharePoint document libraries and records archives so that they can directly accept items mailed to them. I haven’t had a chance to play with this yet, but it’s an important part of Microsoft’s arguments around migrating to SharePoint from Exchange public folders, so it’s definitely on my radar.

Comments Off on More on e-mail-enabling SharePoint

Filed under UC&C

McAfee SiteAdvisor sure looks like an anti-phishing tool

Oh, bother.

I got a testy e-mail from Shane Keats of McAfee asking us to remove SiteAdvisor from the study, based on his claim that SiteAdvisor isn’t an anti-phishing toolbar. I wrote a detailed response, in private e-mail, and was prepared to leave it at that.

However, Mr. Keats cried “foul” to InfoWorld and on the IE blog, saying that including SiteAdvisor is “silly and wrong. We don’t claim, anywhere, to offer phishing protection. In fact, we’re pretty explicit that we don’t.”

I’ll admit to sometimes being silly, and I’ve certainly been wrong before, but I think in this case it’s fair to include SiteAdvisor. Here’s why:

  • The SiteAdvisor.com home page contains this text: “McAfee SiteAdvisor also complements and enhances your existing security software by detecting threats which traditional security products often miss, including spyware attacks, online scams, and sites that spam you”. I think a reasonable person would likely interpret the reference to “online scams” as including phish.
  • Question 2 of the SiteAdvisor FAQ page says “SiteAdvisor is a consumer software company dedicated to protecting Internet users from all kinds of Web-based security threats and annoyances including spyware, adware, unwanted software, spam, phishing, pop-ups, online fraud, and identity theft.” This definitely seems to represent SiteAdvisor as an anti-phishing tool.
  • Mr. Keats included a partial quote from this support article: “SiteAdvisor’s software does not currently provide automated or real-time phishing detection”. However, the full text of this article explicitly says that user reports of phish sites are reported by SiteAdvisor. In our report, we didn’t distinguish between tools that use automated reporting and those, like SiteAdvisor, that can incorporate user-generated reports.
  • On August 3rd, I spoke via phone with both Craig Kenwec of McAfee and Scott Van Sickle of Global Fluency, a PR agency that handles client-security PR for McAfee. Both of them told me that SiteAdvisor incorporates anti-phishing functionality.

Technorati Tags: ,

Comments Off on McAfee SiteAdvisor sure looks like an anti-phishing tool

Filed under General Stuff, Security, UC&C

Phishing data sources and transparency

Microsoft pointed to our study from the IE blog, where there are already several comments, including this one from “Sheep and Duck”:

3Sharp was founded in 2002 by three friends: Paul Robichaux, Peter Kelly, and John Peltonen, all experts in their respective fields. Their goal was to establish a company that could demonstrate the robustness, flexibility, and sheer native capabilities of the Microsoft communication and collaboration technologies. By working closely with Microsoft’s Information Worker Group, 3Sharp has always been able to stay on the cutting-edge of the Office System technologies.
http://www.3sharp.com/about_us.htm
Somehow I don’t trust this “study”.

To which I say:

Sheep and Duck, I understand why you’re skeptical. No matter who commissioned the study, *someone* would distrust the results on that basis alone. However, I think if you read the report, you’ll see that we have been transparent about our test methods and the data we used for the test. If you read the report and still have questions, feel free to contact me via e-mail (paulr@3sharp.com) or my blog (www.robichaux.net/blog) and I’ll do my best to address them.

The report even says that the actual scores of which product blocked or warned on which URLs is available from us on request. It’s hard to be much more transparent than that!

The folks over at mozilla links also asked a good question that I should have addressed in the FAQ: because some of the URLs came from a feed generated by opt-in Hotmail users, does IE have an unfair advantage? The answer is “no”, because the feed we used wasn’t incorporated in the data feeds that Microsoft uses for the Phishing Filter.

Technorati Tags: ,

Comments Off on Phishing data sources and transparency

Filed under Security, UC&C

09-28-06: 3Sharp releases “Gone Phishing”: study of anti-phishing technologies

Big day for 3Sharp— we just released “Gone Phishing“, the first public study to compare the effectiveness of anti-phishing technologies for Windows. I alluded to it in an earlier post. The study is the topic of today’s podcast installment. As a bonus, this episode features music and even embedded URLs (at least for the iPod-compatible AAC version).

MP3 version | AAC version

Comments Off on 09-28-06: 3Sharp releases “Gone Phishing”: study of anti-phishing technologies

Filed under Security

Frequently asked questions about 3Sharp’s anti-phishing report

When we started working on “Gone Phishing“, I anticipated that I’d get some questions, so I’ve been keeping a running list of things that I expect to be FAQs.

Q: What’s unique about your study?

A: As far as we know, no one’s done a public study that directly compares multiple products against a meaningful number of URLs. Most of the evaluations that have been put out there are anecdotal and only used a few URLs.



Q: What did you test?

A: We took 8 anti-phishing products (including the Netcraft toolbar, IE 7’s Phishing Filter, Google’s Safe Browsing for Firefox, Netscape 8.1, GeoTrust TrustWatch, McAfee SiteAdvisor, the eBay toolbar, and EarthLink’s ScamBlocker) and ran two sets of tests: one to determine how good each technology was at catching known phish, and one to see how many mistakes each made on known-good URLs.

Q: Who won?

A: IE 7 came out best overall, with a score of 172 of a possible 200. Netcraft was a very close second, scoring 168/200. For the rest of the scoring, see the report.

Q: Microsoft commissioned the study. Isn’t it biased?

A: No. 3Sharp, not Microsoft, designed the methodology, picked the URLs, and ran the tests. The report includes a complete discussion of how we did this, and even lists of the URLs we tested. We believe our methodology is sound and we’re being 100% transparent about how we got the results we did so that others can duplicate the results if they like.

Q: How’d you decide who won?

A: We calculated a composite accuracy score for each technology. This score combined the product’s performance at blocking or warning phish with its accuracy in not blocking or warning on legitimate URLs. Each technology earned points for correct blocks/warns and lost points for bogus blocks/warns. (See p10 of the report for the full scoring formula). A product that blocked all 100 phish and none of the 500 good URLs would score a perfect 200; a product that didn’t block anything (e.g. IE 6, Safari, Firefox 1.5, Opera, etc.) would score 0.



Q: 200? I thought there were only 100 phish.

A: We used 100 live phish and 500 known good URLs for the test. However, our scoring formula counts 2 points for a block and 1 point for a warning– so if product X blocked all 100 phish, it would score 200.

Q: Why’d you decide that a block should score twice as much as a warn?

A: Users have increasingly become conditioned to ignoring security warnings. In our view, stopping someone from going to a potentially dangerous site is better than suggesting that they not do it.

Q: What URLs did you use?

A: We gathered 100 phish for the tests; we did this by using several data feeds, scanning them using regular expressions, and then manually culling out the real phish. We tested each phish by hand to make sure that it was still live before running our tests, then we manually tested each phish in each technology and scored the results. Each phish was tested within 48 hours of its arrival to make sure it was fresh (or is that “phresh”?) See appendices A and B of the report for a complete list. For the known-good URLs, we took a set of 500 randomly selected URLs from our data feeds, then manually checked them to make sure they weren’t 404.

Q: Why didn’t you test <my favorite product>?

A:
We had to take a snapshot of available products at a point in time. We couldn’t test all of the products, and we couldn’t go back and re-do the tests every time one of the technologies got updated. For example, EarthLink released an update to ScamBlocker during our test period, Mozilla released Firefox 2.0 (which includes anti-phishing features) recently, and Microsoft has updated IE 7 twice since the tests. Because phish have such a short lifetime, we couldn’t go back and re-run the tests.

Technorati Tags: ,

Comments Off on Frequently asked questions about 3Sharp’s anti-phishing report

Filed under Security, UC&C

Windows PowerShell RC2 available

w00t! Microsoft just released PowerShell release candidate 2. That’s good news for almost everyone– I say “almost” because I’m working on a PowerShell poster for Windows IT Pro and now I have to go back and study the changes with a fine-tooth comb to see which ones I need to incorporate. (Remember, the current Exchange 2007 beta build requires PowerShell RC0; I’m not sure what will happen if you install RC2 on top of a working Exchange 2007 install, but I’m not gonna try it.)

Comments Off on Windows PowerShell RC2 available

Filed under General Tech Stuff

Improving the value proposition of Notes e-mail?

Over on Ed’s blog, he’s been talking about how the battle between IBM Lotus and Microsoft isn’t about e-mail. In the comments, I pointed out that both sides want the battle to be about their broader platform… but many customers still think it’s about messaging and calendaring, and they see the debate in those terms. That may be because they’re more familiar with messaging and calendaring tools, or it may be because (despite protestations to the contrary) many Notes shops aren’t using all the collaboration functionality that they paid for (and have to manage).

Continue reading →

Comments Off on Improving the value proposition of Notes e-mail?

Filed under UC&C

Free Key Bank iPod Nano: way better than expected

Arlene and I got our free iPod nano units from KeyBank’s promotion today. I was expecting a 1GB unit because that’s what the ad promised. Instead, though, they shipped me one of the brand new (as in, introduced two weeks ago) aluminum 2GB models. I’m delighted! That’s way nicer than I expected. Now, if I can just get Key to send me that debit card I asked for…

Comments Off on Free Key Bank iPod Nano: way better than expected

Filed under General Stuff

UM trial kit: $1000

Want to try Exchange 2007 Unified Messaging? Microsoft is working with a set of select partners to sell a “trial kit” with the hardware you’ll need. Rather, they’re selling some of the hardware you’ll need: an AudioCodes gateway that will link up to 4 analog phone lines with your Exchange UM server via Voice-over-IP. That gives you Outlook Voice Access, play-on-phone, and the Exchange automated attendant. You also get two hours of phone support, which you’ll probably need to set up the gateway.

Continue reading →

Comments Off on UM trial kit: $1000

Filed under UC&C

Timely story on phishing impact

Reuters has an interesting story today on how phishers are cranking up their attempts to steal your money– and your identity. Symantec released a study today claiming an 81% increase in the number of unique phishing message sent out in the first half of 2006 vs the second half of 2005– not a huge surprise to anyone who has an e-mail account.The story is particularly timely, though, given that 3Sharp will be making a phishing-related announcement later this week; I’ll have more to say later in the week.

Comments Off on Timely story on phishing impact

Filed under Security