Follow us on RSS or Twitter for the latest updates.

January 8, 2013

Hack Windows RT to Run any Desktop App


microsoft-surface
The security mechanism preventing unauthorised software running on ARM-powered Windows RT tablets - such as Microsoft's Surface slabtops - can be easily defeated.

The Redmond giant wanted only cryptographically signed executables, ideally those obtained from the official Windows application store, to run on its hardware. But, we're told, by twiddling a byte of memory in the Windows kernel, it is possible to disable the protection system and allow any code to run on the system.

Taking full control of the device, effectively jail-breaking the computer to run any desktop or touch-driven ARM-compatible software, is an exercise left to the user.

A security researcher calling him or herself C. L. Rokr claims to have found an oversight in the Windows kernel to allow this to happen. According to Rokr, all you have to do is fire up the Windows Debugger software with Administrator-level permissions, connect it to the tablet and manipulate the device's kernel memory.

Specifically, one needs to inject a blob of ARM code into a safe spot of RAM and have the Windows RT kernel divert the processor momentarily to run these instructions. This code locates and alters a moderately hidden variable in the kernel to disable the executable signature check. On PCs the variable contains '0' allowing any program to run, whereas it is '8' on Windows RT devices to enforce the signature check.

Trivially overwriting this byte can therefore change the level of protection on the system and circumvent Microsoft's cryptographic keys.

You can read more about the hack along with a how-to guide here.

Windows RT, which is a straight-up ARM port of Windows 8 for portable computers, was built to only run apps that are signed using a Microsoft-issued certificate.

The hack is unlikely to be something most non-techie users could pull off as it requires knowledge of WinDbg. And modifying the operating system could fall foul of the device's secure boot protection, which refuses to start the OS if it has been altered.

It's also not clear which apps can be run, although as pointed out in this programming forum the software must be compiled for, or otherwise be compatible with, ARM-powered systems. Programs already built for Intel and AMD processors need not apply, therefore.

Windows RT can be found on Microsoft's Surface tablet and fondleslabs from companies including Asus and Samsung. So far it appears sales of Windows RT devices are low and below Microsoft's expectations. Redmond has quickly turned from only selling Surface itself online and in its stores to recruiting retail partners.

One reason for the lack of interest could be lack of apps. Windows RT has been deliberately locked down because, we're told, Microsoft wants to maintain a standard of performance and security, and to ensure apps conform to the design of the interface and input via touch. This means the number of Windows RT apps is far behind the number of apps that exists for Intel machines running the exact same operating system.

Devices using Windows RT come with some built-in apps including Office Home and Student 2013 RT Preview Edition and Mail, Messaging and SkyDrive, but the official way to obtain more is via Microsoft's Windows Store, which supplies suitably signed executables.

Author: dfgdfg,

December 5, 2012

Microsoft Releases So.cl Network to the Public


so.cl-microsoft.PNG
Microsoft’s "experiment in open search", so.cl, is now open to anyone.

Launched back in May amidst very little fanfare, so.cl (pronounced "social") was initially offered only to students and billed as an experiment in learning.

Redmond has recanted those restrictions, today telling world+dog they’re free to pile in and enjoy the fun, as so.cl is now "a service where people connect over shared interests."

So.cl is rather unlike other social networks inasmuch as a post starts with a search. The results of that search can then be assembled into a post that brings together the user’s desired elements.

Many users post just a single image. Others take a more curatorial approach, collecting several images related to the same topic in a fashion not entirely unlike creating a Pinterest collection.

Redmond’s not building a walled garden, as Facebook is a permitted login mechanism and so.cl’s About page states it is not in competition with other social networks.

Socl — pronounced social — allows you to express and share your ideas through rich post collages comprised of images, links, captions and videos.
"Socl is a research project from Microsoft Research FUSE Labs and began as an experiment in social search targeted at students for the purpose of learning. Following the lead of the Socl community, Socl has since evolved to be a service where people connect over shared interests expressed through beautiful posts that take only seconds to create", says Microsoft.
Whether Redmond will be still be saying that if, or when, it embeds a so.cl tile in the default Windows 8 start screen remains to be seen.

Author: dfgdfg,

Categories: , ,

October 16, 2012

Microsoft Surface Priced: 32GB For $499 Without Touch Cover, $599 With; 64GB For $699


Microsoft's Surface tablet pricing has been outed by the software giant.

Earlier today, Surface pricing was posted on the Microsoft Store online site. Not long after, the page was taken down, seemingly because the pricing information was put up on the site before it was supposed to go live.


Based on that screenshot, it appears Microsoft will sell its Surface with Windows RT for a starting price of $499 with 32GB of storage and a Touch Cover. Those who want a Touch Cover included in the order will need to set aside $599 for the device. Adding an additional 32GB of storage will push the Surface's price up to $699.

Microsoft unveiled its Surface tablet earlier this year. The RT version comes with a 10.6-inch screen and a 1,280 x 720 resolution. The device is expected to be Wi-Fi-only, and its Touch Cover add-on works as a screen protector, stand, and keyboard. Surface for Windows 8 Pro is expected to launch after the Windows RT version, and will come with a "full HD" 1080p screen resolution. That device will likely be more expensive than the Windows RT model.

Windows 8 is scheduled to launch on October 26. Windows RT, which will be running on the Surfaces leaked on the store site, will run on ARM processors. Microsoft will also sell Windows 8, Windows 8 Pro, and Windows 8 Enterprise versions. Those models are not compatible with ARM-based chips.

Author: dfgdfg,

Categories: , , ,

September 19, 2012

German Goverment Urges Everyone to Stop Using Internet Explorer


Following the recent bug  that was discovered in Internet Explorer 6, Internet Explorer 7, Internet Explorer 8 and Internet Explorer 9 which makes PC's vulnerable to attack by hackers, the German government advised the public on Tuesday to stop using the browser temporarily.


The security flaw, which affects hundreds of millions of Internet Explorer browser users around the globe, publicly surfaced over the weekend.

Microsoft had said on Monday that attackers can exploit the bug to infect the PC of somebody who visits a malicious website and then take control of the victim's computer.

The German government's Federal Office for Information Security, or BSI, said that it was aware was aware of targeted attacks and that all that was needed was to lure web surfers to a website where hackers had planted malicious software that exploited the bug in Internet Explorer to infect their PCs.

"A fast spreading of the code has to be feared," the German government said in its statement.

BSI advised all users of Internet Explorer to use an alternative browser until the manufacturer has released a security update.

Officials with Microsoft did not respond to a request for comment on the move by the German government.

The company late on Monday urged customers to install a piece of security software as an interim measure, buying it time to fix the bug and release a new, more secure version of Internet Explorer.

Microsoft did not say how long that will take, but several security researchers said they expect the update within a week.

The free security tool, which is known as the Enhanced Mitigation Experience Toolkit, or EMET, is available through an advisory on Microsoft's website: blogs.technet.com/b/msrc/

The EMET software must be downloaded, installed and then manually configured to protect computers from the newly discovered threat, according to the posting from Microsoft. The company also advised customers to adjust several Windows security settings to thwart potential attackers, but cautioned that doing so might impact the PC's usability.

Some security experts had said it would be too cumbersome for many PC users to implement the measures suggested by Microsoft. Instead they advised Windows users to temporarily switch from Internet Explorer to rival browsers such as Google Inc's Chrome, Mozilla's Firefox or Opera Software ASA's Opera.

Internet Explorer was the world's second-most widely used browser last month, with about 33 percent market share, according to StatCounter. It was close behind Chrome, which had 34 percent of the market.

Author: dfgdfg,

September 21, 2011

Microsoft Secure Boot Firmware may Block Linux Booting


Windows-8-Linux
Computer scientists warn that proposed changes in firmware specifications may make it impossible to run “unauthorised” operating systems such as Linux and FreeBSD on PCs.

Proposed changes to the Unified Extensible Firmware Interface (UEFI) firmware specifications would mean PCs would only boot from a digitally signed image derived from a keychain rooted in keys built into the PC. Microsoft is pushing to make this mandatory in a move that could not be overridden by users and would effectively exclude alternative operating systems, according to Professor Ross Anderson of Cambridge University and other observers.

UEFI is a successor to the BIOS ROM firmware designed to shorten boot times and improve security. The framework, a key part of Windows 8, is designed to work on a variety of CPU architectures.

If the draft for UEFI is adopted without modification, then any system that ships with only OEM and Microsoft keys will not boot a generic copy of Linux. A signed version of Linux would work, but this poses problems, as tech blogger Matthew Garrett explains.

Garrett writes:

Firstly, we'd need a non-GPL bootloader. Grub 2 is released under the GPLv3, which explicitly requires that we provide the signing keys. Grub is under GPLv2 which lacks the explicit requirement for keys, but it could be argued that the requirement for the scripts used to control compilation includes that. It's a grey area, and exploiting it would be a pretty good show of bad faith.

Secondly, in the near future the design of the kernel will mean that the kernel itself is part of the bootloader. This means that kernels will also have to be signed. Making it impossible for users or developers to build their own kernels is not practical. Finally, if we self-sign, it's still necessary to get our keys included by ever OEM.

There's no indication that Microsoft will prevent vendors from providing firmware support for disabling this feature and running unsigned code. However, experience indicates that many firmware vendors and OEMs are interested in providing only the minimum of firmware functionality required for their market.

Garrett concluded that there is no need to panic just yet.

The upshot of the changes is that considerable roadblocks might be placed in the way of running alternative operating systems on PCs. Anderson describes this as a return to the rejected Trusted Computing architecture – which at that point involved force-feeding DRM copy-protection restrictions – which may be far worse than its predecessor.

The professor said:

These issues last arose in 2003, when we fought back with the Trusted Computing FAQ and economic analysis. That initiative petered out after widespread opposition. This time round the effects could be even worse, as 'unauthorised' operating systems like Linux and FreeBSD just won’t run at all. On an old-fashioned Trusted Computing platform you could at least run Linux – it just couldn’t get at the keys for Windows Media Player.

The extension of Microsoft’s OS monopoly to hardware would be a disaster, with increased lock-in, decreased consumer choice and lack of space to innovate.

Anderson concludes that the technology might violate EU competition law in a rallying call on Cambridge University's Light Blue Touchpaper blog here.

Author: dfgdfg,

September 15, 2011

Windows 8 to come with built-in Malware Protection


windows-8
Microsoft's next version of Windows will ship with "tons of security features," including one that automatically scans boot drives for malware and a revamped version of the Windows Defender antivirus program, company executives said.

At the company's BUILD conference in Anaheim, California on Tuesday, Corporate Vice President of Windows Planning and Ecosystem Michael Angiulo demonstrated an early version of Windows 8 that automatically scanned an infected USB drive used to boot the next generation operating system. Before the OS was able to load, the computer stopped the process and displayed a warning that the boot volume contained an "invalid signature" indicating it had been compromised.

He was able to get the valid version of Windows to load by turning off the system and turning it back on. The presentation starts around the 1:08 mark in the following video:



The technology making this possible is known as UEFI, short for Unified Extensible Firmware Interface. A successor to the BIOS ROM firmware that Microsoft operating systems have relied on since their beginning, UEFI was designed to shorten the time it takes a PC to start up. It was built by Intel, but is designed to work with a variety of CPU architectures.

"It's not just about speed and having a boot that looks better," Angiulo said during Tuesday's keynote, referring to UEFI. "It's about security, too."
Steven Sinofsky, president of Microsoft's Windows and Windows Live division, went on to say that Windows 8 developers "have taken Defender and we've actually built a whole new range of protection, all the way up though antimalware, antivirus." Users are free to run Defender or security software supplied by another company. In all, the new OS will offer "tons of security features," he added.

The company issued a statement Wednesday saying Windows 8 would include "low-level security features such as Secured Boot to help defeat classes of threats, and user facing features including Windows Defender and SmartScreen" spam-filtering. The statement didn't elaborate.

Windows 8 will also offer a new way to log on to PCs equipped with a touchscreen. Sam Bowne, a security instructor at San Francisco City College, provided a screenshot here that describes the feature this way: "You choose the picture – and the gestures you use with it – to create a password that's uniquely yours."

Bowne and his students have been testing the security features in the new Windows beta, according to a source.

"There is built in antivirus, and it works!" he wrote "It stopped not only thr EICAR test file, but more than a dozen malware items in Metasploit. So it might be time to sell your Symantec stock."

Author: dfgdfg,

Windows 8 Developer Preview


win8-start-screen
Those of you interested in taking the current flavor of Windows 8 for a spin can now download and install the Developer Preview edition.

Being demoed at Microsoft's Build conference, the Developer Preview is a prebeta version showing off the operating system at its current stage. Though technically designed for developers, no registration is required, so anyone can download and install it.

The Windows 8 Preview is being offered in three different packages--a 64-bit version with various developer tools, a 64-bit version of just the operating system, and a 32-bit version of the OS.

All three come as ISO files--image files of the contents of a CD or DVD. Since each of the packages is several gigabytes in size, you'll need a DVD if you want to burn the files to a disc.

In Windows 7, you can burn the ISO file to a DVD by double-clicking it to open the Windows Disc Image Burner. For older operating systems, you can use a tool such as ISO Recorder to burn the file. Alternatively, you can use such utilities as Virtual CloneDrive or Daemon Tools to "mount" the ISO file as a drive, eliminating the need to burn it onto a disc.

Since this is a prebeta version, you'll want to install the OS on a spare PC or in a virtual environment so that it doesn't interfere with your production or work machine.

Those of you who want to know what you're getting into before you attempt to install the Developer Preview can check out a hands-on early look at Windows 8.

What's next after the Developer Preview?

Speaking at the Build conference yesterday, Steven Sinofsky, senior vice president of Microsoft's Windows division, said that Windows 8 will next segue into one beta version, followed by one Release Candidate. Assuming all goes well, we can then expect the final RTM (release to manufacturing) edition sometime after that.

Sinofsky didn't reveal a specific timeframe for the beta or Release Candidate. However, the company has been expected to launch the beta at the 2012 Consumer Electronics Show in January, according to WinRumors.

Author: dfgdfg,

September 9, 2011

Microsoft promises faster startup for Windows 8, Boots in 8 seconds


window8-interface
Are you the sort of person who prefers to shut your PC down at the end of the day rather than hibernate it or put it to sleep, but do you still want to the system to start up fast? Windows 8 has a new feature that will be of great interest to you.

The feature is called ‘fast startup mode’ and it is a hybrid between a standard cold boot and restoring your PC from a hibernated state. How does it work? Gabe Aul, director of program management in Windows, explains over on the Building Windows 8 blog:

The key thing to remember though is that in a traditional shutdown, we close all of the user sessions, and in the kernel session we close services and devices to prepare for a complete shutdown.

Now here’s the key difference for Windows 8: as in Windows 7, we close the user sessions, but instead of closing the kernel session, we hibernate it. Compared to a full hibernate, which includes a lot of memory pages in use by apps, session 0 hibernation data is much smaller, which takes substantially less time to write to disk. If you’re not familiar with hibernation, we’re effectively saving the system state and memory contents to a file on disk (hiberfil.sys) and then reading that back in on resume and restoring contents back to memory. Using this technique with boot gives us a significant advantage for boot times, since reading the hiberfile in and reinitializing drivers is much faster on most systems (30-70% faster on most systems we’ve tested).

How much faster is this than a standard cold boot? Take a look at this:


Here’s how fast startup is different to a traditional cold boot:


The speed of the handoff between POST and Windows depends on whether the system has a traditional BIOS or the newer Unified Extensible Firmware Interface (UEFI) … so watch out for the sales pitch for new systems:

One thing you’ll notice in the video was how fast the POST handoff to Windows occurred. Systems that are built using Unified Extensible Firmware Interface (UEFI) are more likely to achieve very fast pre-boot times when compared to those with traditional BIOS. This isn’t because UEFI is inherently faster, but because UEFI writers starting from scratch are more able to optimize their implementation rather than building upon a BIOS implementation that may be many years old. The good news is that most system and motherboard manufacturers have begun to implement UEFI, so these kinds of fast startup times will be more prevalent for new systems.

And here it is in action:



The notebook used in that video is an EliteBook 8640p (Intel Core i7-2620M, 8GB, 160GB SSD).

Author: dfgdfg,

Categories: , ,

August 11, 2011

PC Revolution from the Beginning (Photos)


The original IBM 5150, the personal computer that helped launch an industry, made its debut at a press conference at the Waldorf Astoria Hotel in New York on August 12, 1981.

Photo by IBM


A marketing photo of the IBM 5150 illustrated how the company wanted to push the new personal computer into the workplace.

Photo by IBM

Don Estridge, later called "the father of the PC," led the team at IBM that developed the 5150, the personal computer that sparked the PC revolution.

Photo by IBM

An advertisement for the IBM 5150 noted: "IBM believes that the age of the personal computer has arrived."

Photo by Computer History Museum

IBM sped up development of the 5150 personal computer, worried about the encroachment of the popular Apple II into homes and businesses.

Photo by Computer History Museum

IBM turned to a young company, Microsoft, and its co-founders Paul Allen and Bill Gates, for the operating system for the 5150. This photo was shot shortly after Microsoft signed the contract with IBM. The image was featured in the Seattle Business Journal's October 19, 1981 article, "Building on success, Microsoft owners shoot for $100 million target."

Photo by Microsoft

An advertisement for MS-DOS 1.0, the operating system that got its start on the IBM 5150 and was used on the so-called clone PCs.

Photo by Microsoft

Author: dfgdfg,

August 10, 2011

IE, Windows server bugs is likely to be exploited soon


microsoft-logo
Microsoft has released 13 updates that patch security holes in a wide range of its software offerings, including vulnerabilities rated critical in its Internet Explorer browser and Windows server operating systems.

The bugs in IE make it possible for attackers to remotely execute malicious code when an end user does nothing more than visit a booby-trapped website. Although there's no evidence the vulnerabilities are being exploited in the wild now, members of Microsoft's security team said there was a high likelihood reliable exploit code would be developed by real-world attackers in the next 30 days.

The vulnerabilities affect all supported versions of the Microsoft browser, including versions 8 and 9, which were rebuilt from scratch to minimize the damage that can be done when hackers identify vulnerabilities.

The second critical update covers all versions of Windows Server 2003 and Windows Server 2008, including the most recent R2 iteration, which is regarded as one of Microsoft's most secure server operations systems ever. By setting up a malicious DNS server and getting a vulnerable system to query it from inside the victim's network, an attacker can take complete control of the underlying machine.

According to Microsoft's exploitability index for August, attackers aren't likely to exploit the DNS flaw in the next month.

The remaining 11 patches carry the lower-level ratings of important and moderate and affected products including Windows, Office, .Net, and Visual Studio. Vulnerable components include the Remote Desktop Web Access Login, Microsoft Chart Web Control, and the Report Viewer Web control. The vulnerabilities enable attacks involving information theft and and denial of service outages.

Roundups of this month's Patch Tuesday offerings from Microsoft and SANS are here and here. Commentary from Kaspersky Lab and Qualys is here and here.

Author: dfgdfg,

July 13, 2011

Window Server 8: Preview by Microsoft


microsoft
Microsoft has given a peek into Windows 8 Server, the successor to Windows Server 2008 R2 and companion to the tablet-tastic Windows 8 client.

The company is reported Tuesday to have boasted Windows 8 Server will pack more than 100 new features.

Speaking at its Worldwide Partner Conference (WPC), however, Microsoft seems to have zeroed in on just one: the new Hyper-V it's positioning as an enabler of cloud computing when used to virtualize server

operating systems and applications in your data center.

Microsoft's teaser came in the shadow of virtualization giant VMware's vSphere 5 launch in San Francisco, California, on the same day.

There, VMware chief executive Paul Maritz – a former Microsoft exec with 14 years at the company – boasted that according to various industry analysts VMware virtual machines are about six months away from running 50 per cent of the world's server workloads.

Microsoft is coming from behind in virtualization, and claimed at WPC in Los Angeles, California, that HyperV is the fastest growing virtualization stack.

Cutting to the features at WPC, Microsoft unveiled Hyper-V Replica that will let you replicate virtual machines either immediately or according to a schedule. This will, Mary-Jo Foley reports, let you do something like replicate a mission-critical database to an offsite data vendor.

Microsoft claimed it will be vendor-agnostic and support different storage, data center and software and service providers. In keeping with Microsoft's goal of getting customers to put more of their data in its cloud by not charging for imports, Microsoft will also give Windows Server 8 users unlimited replication without an additional fee per virtual machine.

Hyper-V, meanwhile, will also support more than 16 virtual processors per machine.

Microsoft called Windows 8 Server "the next step in private cloud computing".

Microsoft backed the cloud play by talking planned software that'll unify management of apps running on virtualized Windows servers and on Microsoft's Windows Azure cloud.

It announced Systems Center 2012, which will feature an account controller that gives single sign-in to all your apps on different servers, and that provides a tiled view of apps. You will be able to deploy apps using a set of best practices. Systems Center 2012 is due to ship this year.

On the apps front, Microsoft dressed an announcement about a third test build for the next version of SQL Server, codenamed Denali, with a demo of the ability to suck in data from the Windows Azure Data Market to the new database. It did this while showing off what it called "PowerPoint for data" that lets you customize and re-size data fields and turn them into charts and graphs by simply clicking and tugging at them using your mouse.

The Data Market is an online data store with pre-built integration for SQL Server, Office and Bing.

Microsoft, meanwhile, said that finished applications are now available for sale on the Windows Azure Marketplace - there are 578 offerings. Announced in November, the Marketplace, which includes the data Market, was originally a place for sharing data.

Source: The Register

Author: dfgdfg,

June 30, 2011

Internet Explorer 10: Microsofts Unveils Preview of It's New Features


Microsoft has released another preview version of Internet Explorer 10, and it has used the occasion to once again explain how it loves the enterprise more than Firefox.

On Wednesday, the company released the second platform preview of IE 10 featuring what it called the "HTML5 engine" behind recent demos of the browser on Windows 8.

According to Microsoft's corporate vice president in charge of IE, Dean Hachamovitch said, the IE10 platform preview means that developers can start working with several "site-ready" HTML5 technologies. Like so many others, Microsoft uses HTML5 as an umbrella term that applies not-only to the still gestating HTML5 standard but also other standards such as JavaScript and CSS.

The IE10 platform preview offers support for CSS3 Positioned Floats, HTML5 Drag-drop, File Reader API, and Media Query Listeners and initial support for HTML5 Forms. Microsoft has also added support for an HTML5 sandbox for iframe isolation.

Much of this is designed to work with the tiled and touch-friendly interface that arrives with the version of Windows 8 for tablets. CSS3 Positioned Floats lets text flow around figures on a page, and it builds on the support for CSS3 grid, multi-column, and flexbox in the first platform preview in April. It's the kind of thing you'd want on any touchy tablet.

Then Hachamovitch alluded to last week's Firefox controversy.

Last week, Mozilla handed Microsoft an easy avenue of attack when it killed support for Firefox 4 following the release of Firefox 5. This is typically the way it works, except that Firefox 5 is the first Mozilla browser delivered on the outfit's new rapid release cycle. It arrived just months after the release of Firefox 4. When one enterprise user piped up to say how this made life very hard for his kind, Mozilla man Asa Dotzler, told him to get over it, saying Mozilla has never, and should never, care about the needs of the enterprise.

Announcing the IE10 preview, Hachamovitch played up Microsoft's long-term support for IE, coupling IE10 with the lifecycle of the forthcoming Windows 8. "Because of this approach to productizing Web technologies, Microsoft will support IE10 for 10 years after its release, honoring the same product lifecycle commitments as Windows itself," Hachamovitch said.

Microsoft has traditionally supported each version of IE for as long as it supports the version of Windows it was built for. With IE9 on Windows 7, support for the browser is due to run until 2020 according to Microsoft. If Windows 8 and IE10 are delivered next year, as is expected, then you can expect Microsoft's IE10 support to run until roughly 2022.

Author: dfgdfg,

June 28, 2011

Office 365: Microsoft finally Releases Office 365


office365
Today, at media events around the world, Microsoft Corp. announced the availability of Microsoft Office 365, the company’s newest cloud service. Office 365 is now available in 40 markets, and it brings together Microsoft Office, Microsoft SharePoint Online, Microsoft Exchange Online and Microsoft Lync Online in an always-up-to-date cloud service, at a predictable monthly subscription.

The service was introduced in beta last year with enthusiastic response and, in a few months, more than 200,000 organizations signed up and began testing it. Businesses using Office 365 are already reporting impressive results and reducing IT costs by up to an estimated 50 percent while boosting productivity.

Today, more than 20 service providers around the globe also shared plans to bring Office 365 to their customers this year. Bell Canada, Intuit Inc., NTT Communications Corp., Telefonica S.A., Telstra Corp. and Vodafone Group Plc, among others, will package and sell Office 365 with their own services for small and midsize businesses.

“Great collaboration is critical to business growth, and because it’s so important, we believe the best collaboration technology should be available to everyone,” said Microsoft CEO Steve Ballmer. “With a few clicks, Office 365 levels the playing field, giving small and midsize businesses powerful collaboration tools that have given big businesses an edge for years.”

A Game Changer for Businesses of All Sizes

Office 365 is available in a wide range of service plans designed to meet the needs of businesses of all sizes, ranging from the largest to the smallest.

With Office 365, people can stay on the “same page” using instant messaging and virtual meetings with people who are just down the hall or across the world. They can work on files and documents at the same time and share ideas as easily as they can share calendars. Office 365 gives people new ways to work together with ease, on virtually any device.

Microsoft Office applications are at the heart of Office 365. Microsoft Word, PowerPoint, Excel, OneNote, Outlook and other Office applications connect to Microsoft Exchange, SharePoint and Lync to deliver a world-class solution for communication and collaboration.

“When I saw Office 365, I knew this was the way businesses would work in the future,” said Elia Wallen, owner of fast-growing temporary housing provider Travelers Haven. “With Office 365, I’m going to save $100,000 a year and cut 30 hours of work a day across my 35 employees, but most importantly, my team is going to be able to work together better — no matter where they are.”

More stories from businesses that have tried Office 365 are available at http://www.microsoft.com/casestudies.

Office 365 Partners

Microsoft is building a massive partner ecosystem around Office 365, including systems integrators, software vendors, resellers and other partners. Today, that ecosystem is expanding as the company partners in new ways with market-leading service providers. These companies will package Office 365 with their own services — from Web hosting and broadband to finance solutions and mobile services — and bring those new offerings to millions of small and midsize businesses globally.

“Our partners represent some of the best-known, most-trusted brands in their local markets,” said Kurt DelBene, president, Microsoft Office Division. “Our customers will be able to rest easy knowing their cloud services are backed by Microsoft and some of the greatest service providers in the world.”

A list of Office 365 service provider partners is available here.

About Office 365

Office 365 offers a range of service plans for a predictable monthly price from $2 to $27 per user per month. With Office 365 for small businesses, customers can be up and running with Office Web Apps, Microsoft Exchange Online, Microsoft SharePoint Online, Microsoft Lync Online and an external website in minutes, for $6 (U.S.) per user, per month. These tools put enterprise-grade email, shared documents, instant messaging, video and Web conferencing, portals, and more at everyone’s fingertips.

Office 365 for enterprises has an array of choices, from simple email to comprehensive suites to meet the needs of midsize and large businesses, as well as government organizations. Customers can now get Microsoft Office Professional Plus on a pay-as-you-go basis with cloud-based versions of the industry’s leading business communications and collaboration services. Each of these plans comes with the advanced IT controls, innovative security technologies, 24/7 IT support and reliability customers expect from Microsoft.

Availability

Office 365 for small businesses and Office 365 for enterprises are available now. Businesses can try Office 365 for free for 30 days by signing up at http://www.office365.com or from their local Microsoft partner. Follow Office 365 on Twitter (@Office365), Facebook (http://www.facebook.com/office365) and the Office 365 blog at http://community.office365.com for the latest information.

Author: dfgdfg,

June 24, 2011

Microsoft Hotmail Personalization and Keyboard Shortcut


msn-hotmail
One of the biggest changes in this new version of Hotmail are additional mouse and keyboard shortcuts. A new menu has been created that appears when a user right-clicks on a message in the inbox. The menu offers a direct link to reply, reply all or forward the selected message. This is in addition to previously supported right-click actions such as delete, move or mark as junk.

Users who like to use keyboard shortcuts whenever possible have now access to a whole new set of shortcuts, taken directly from Microsoft’s desktop messaging client Outlook, as well as the online email services Gmail and Yahoo Mail.

Users of Outlook, and those who switched from Gmail or Yahoo Mail to Hotmail can now use keyboard shortcuts that they are already familiar with. Popular ones include:

Outlook 
  • To do thisPress this
  • Delete a message – Delete
  • Create a new message – Ctrl+N
  • Send a message – Ctrl+Enter
  • Open a message – Ctrl+Shift+O
  • Print a message – Ctrl+Shift+P
  • Reply to a message – Ctrl+R
  • Reply all to a message – Ctrl+Shift+R
  • Forward a message – Ctrl+Shift+F
  • Save a draft message – Ctrl+S
  • lag a message for follow up – L
  • ark a message as junk – Ctrl+Shift+J
  • # Mark a message as read – Ctrl+Q
  • Mark a message as unread – Ctrl+U
  • Move to a folder – Ctrl+Shift+V
  • Open the next message – Ctrl+.
  • Open the previous message – Ctrl+,
  • Close a message – Esc
  • Search your email messages – /
  • Check spelling – F7
  • Select all – S then A
  • Deselect all – S then N
  • Go to the inbox – F then I
  • Go to your Drafts folder – F then D
  • Go to your Sent folder – F then S
Gmail, Yahoo Mail
  • To do this – Press this for Gmail shortcut – Press this for Yahoo! shortcut
  • Delete a message – # – Delete
  • Create a new message – C – N
  • Send a message – None – Alt+S
  • Open a message – O – None
  • Print a message – None – P
  • Reply to a message – R – R
  • Reply all to a message – A – A
  • Forward a message – F – F
  • Save a draft message – Ctrl+S – Ctrl+S
  • Mark a message as junk – ! – None
  • Mark a message as read – Shift+I – K
  • Mark a message as unread – Shift+U – Shift+K
  • Move to a folder – None – D
  • Open the next message – J – Ctrl+.
  • Open the previous message – K – Ctrl+,
  • Close a message – U – Esc
  • Search your email messages – / – S
  • Select all – * then A
  • Deselect all – * then N
  • Go to the inbox – G then I – M
  • Go to your Drafts folder – G then D
  • Go to your Sent folder – G then T
All keyboard shortcuts work at the same time, which means that you can either press the delete key or # to delete a message, or Ctrl-n, c or n to create a new message.

You find all supported keyboard shortcuts here.

What’s your take on the new Hotmail features? I really like the new keyboard shortcuts as they tend to speed things up considerably, tell your experience with it.

Author: dfgdfg,

June 17, 2011

How To Fix Microsoft Outlook Can’t Create File Errors


Microsoft Outlook users who receive many file attachments of the same name will run into a can’t create file error message eventually. This can happen for instance if voicemail or faxes are routed to email. The core problem is this. Outlook creates a temporary copy of each attachment in a directory, and appends a number behind the file name if the names are otherwise identical. The error message is displayed once that count reaches 100. If that is the case, users will get the following error message in Outlook for the next files with that filename.

Can’t Create file: [filename]. Right-Click the folder you want to create the file in, and then click properties on the shortcut menu to check your permissions for the folder

The only option? To clear the temporary storage space to make room for new attachments. Clearing the cache does not negatively affect the attachments in Outlook, it simply means that Outlook won’t be able to access them from hard drive cache but instead from MIME format directly which might take longer to process.

Outlook Cleanup Tool is a free program for Outlook that can clear the cache automatically or semi-automatically so that the can’t create file error does not pop up anymore in the email client.



Run the program after download to resolve the error. It displays a list of cached files. The information are taken from the Registry. A click on Clean Up clears the temporary cache which in turn resolves the error message.

It needs to be noted that the cache will be filled again by Outlook, and that it may be necessary to run the tool regularly to avoid the can’t create file error message.

The program can be run from the command line. It has a /silent switch which will clean up the cache automatically without user interaction. Handy to use the command in a batch file at log on for instance or log off.

Besides solving the can’t create file errors, it resolves a privacy issue as well, if other users have access to the computer system. Caching attachments as temporary files might give other users access to them in the temp folder, even if the original attachment has been deleted or detached from the email message. Cleaning the temporary data folder removes that possibility.

You can naturally locate and delete the temp folder manually. For that, you need to open the Windows Registry and search for the key OutlookSecureTempFolder.

It should be under HKEY_CURRENT_USER\Software\Microsoft\Office\x.x\Outlook\Security where x.x is the internal version of Outlook.

You can download the portable Outlook Cleanup Tool from the developer website over at Intelliadmin. The program is compatible with all versions of Windows from Windows 2000 on, and all versions of Microsoft Outlook from Outlook XP to the very latest Outlook 2010.

Author: dfgdfg,

Microsoft gets antitrust approval to buy Skype


microsoft-skype

Microsoft has won U.S. antitrust approval to buy the Internet phone service Skype, the Federal Trade Commission said in a website posting on Friday.

Microsoft announced in May it was buying Skype for $8.5 billion, its biggest-ever acquisition, placing a rich bet on mobile and the Internet to try and best rivals such as Google Inc.

The approval was announced in a listing of deal approvals that comes out several times a week.

Microsoft's interest in the money-losing, but popular service highlights a need to gain new customers for its Windows and Office software. Skype has 145 million users on average each month and has gained favor among small businesses.

Author: dfgdfg,

June 16, 2011

Microsoft Warns the Public on Support Tech Scams


A survey from Microsoft reveals just how widespread the fake tech support call scam is becoming.

The crooks cold-call people at home and claim to be calling from Microsoft or a well-known security firm and offering "free security checks".

The software giant surveyed 7,000 computer users in the UK, Ireland, US and Canada and found an average of 16 per cent of people had received such calls. In Ireland this rose to a staggering 26 per cent.

More than a fifth of those who received such a call, or 3 per cent of the total surveyed, were tricked into following the crooks instructions which ranged from allowing remote access of their machines, downloading dodgy code or in some cases giving credit card information in order to make purchases.

Microsoft said if someone claiming to be from Windows or Microsoft Tech Support calls you: "Do not purchase any software or services. Ask if there is a fee or subscription associated with the 'service'. If there is, hang up."

Redmond said 79 per cent of those tricked suffered financial loss – the average loss was $875 (£542). Losses ranged from just $82 (£51) in Ireland to a whopping $1,560 (£967) in Canada.

Microsoft warned that while the gangs were currently targeting English-speaking countries it was just a matter of time before they go after other countries.

The company advised anyone who had already fallen for such a scam to change their passwords, scan their machines for malware and contact their bank and credit card providers.

Author: dfgdfg,

Categories: , ,

June 13, 2011

Why Microsoft Has Made Developers Horrified of Coding for Windows 8


window 8
By Peter Bright, Ars Technica

When Microsoft gave the first public demonstration of Windows 8 a week ago, the reaction from most circles was positive. The new Windows 8 user interface looks clean, attractive and thoughtful. And, in a first for a Microsoft desktop operating system, it’s finger-friendly. But one aspect of the demonstration has the legions of Windows developers deeply concerned, and with good reason: They were told that all their experience, all their knowledge and every program they have written in the past would be useless on Windows 8.

Key to the new Windows 8 look and feel, and instrumental to Microsoft’s bid to make Windows a viable tablet operating system, are new-style full-screen “immersive” applications. Windows 8 will include new APIs for developing these applications, and here is where the problem lies. Having new APIs isn’t itself a concern — there’s simply never been anything like this on Windows before, so obviously the existing Windows APIs won’t do the job — but what troubles many developers is the way that Microsoft has said these APIs will be used. Three minutes and 45 seconds into a demo video, Microsoft Vice President Julie Larson-Green, in charge of the Windows Experience, briefly describes a new immersive weather application and says, specifically, that the application uses “our new developer platform, which is, uhh, it’s based on HTML5 and JavaScript.”

Cue much wailing and gnashing of teeth.

Windows developers have invested a lot of time, effort and money into the platform. Over the years, they’ve learned Win32, COM, MFC, ATL, Visual Basic 6, .NET, WinForms, Silverlight and WPF. All of these technologies were, at one time or another, instrumental in creating desktop applications on Windows. With the exception of Visual Basic 6, all of them are still more or less supported on Windows today, and none of them can do it all; all except Visual Basic 6 and WinForms have a role to play in modern Windows development.

Hearing that Windows 8 would use HTML5 and JavaScript for its new immersive applications was, therefore, more than a little disturbing to Windows developers. Such a switch means discarding two decades of knowledge and expertise in Windows development and countless hours spent learning Microsoft’s latest-and-greatest technology. Perhaps just as importantly, it means discarding rich, capable frameworks and the powerful, enormously popular Visual Studio development environment, in favor of a far more primitive, rudimentary system with substantially inferior tools.

A Justified Reaction

The idea of Microsoft discarding all of that expertise seems crazy, and one might think that the developer response is an overreaction — but it’s seen as confirmation of the direction Microsoft already appears to be heading down: moving HTML5 to the foreground, in spite of its inferiority to other technology. The Windows 8 comment made by Larson-Green was shocking, yes, but seemed to be confirmation of what developers already suspected. Developers aren’t willing to assume that the company is going to do right by them, because the messages from the company have given them every reason to believe that the Larson-Green really meant what she said: If you want to use the new development platform, you’re going to have to use HTML5 and JavaScript.

The company has never exactly been good at picking a direction for its development strategy and sticking with it. There’s been too much infighting, too many leaps aboard new technology bandwagons, and too much software that fails to adopt new paradigms. But until about a year and a half ago, it looked like things were beginning to settle down, with the combination of .NET, Windows Presentation Foundation (WPF), and WPF’s Flash-like sibling, Silverlight. WPF and .NET provide a flexible, high-level and structured approach for writing GUI applications, and Silverlight is a cut-down version of WPF that can be used as a browser plugin on both Windows and Mac OS X.

Neither of these technologies was perfect — WPF has never been as fast as it should be, and Silverlight is not as cross-platform as it ought to be — but the set of products did at least represent some kind of a coherent vision for software development. WPF and .NET for big applications, Silverlight for portable ones.

Hopes Dashed

But then Internet Explorer 9 happened. Microsoft jumped on the HTML5 bandwagon, and that’s when things all got rather muddy. Prior to Internet Explorer 9, Silverlight had been the company’s preferred solution for developing rich cross-platform applications. The lack of broad platform support meant that Silverlight could never quite rival Flash on this front, but it was there, and it worked well on those platforms that were supported. With Internet Explorer 9, however, Silverlight took a back seat. HTML5 became the way forward. If Silverlight was to be used at all, it should only be used for those things that HTML5 couldn’t do very well, such as streaming video. For anything else, the message was that developers should use HTML5.

Microsoft did have a point. If you’re really wanting to target people on any platform, HTML5 is the way to go. For Web-facing applications that don’t have any special needs such as DRM video, HTML5 is the long-term bet. But third-party developers were deeply unhappy when this repositioning was made explicit, and they had a point too. For a developer writing an internal-use line-of-business application, one for whom depending on a browser plug-in is not a problem, Silverlight had, and still has, a lot of points in its favor.

HTML5 remains true to its text mark-up heritage. Its structure and semantics are still geared towards creating structured text documents, not application user interfaces. Where Silverlight programs can deal with buttons, icons, list boxes, tree views and other interface controls, HTML5 applications must generally deal with boxes of text, with no higher-level concepts to work with. There are JavaScript libraries that attempt to bridge this gap, but they lack the capabilities and control that Silverlight offers. Ultimately, if one were to design a framework for creating user interfaces, it would look a lot more like Silverlight than it does HTML5.

Another weak area for HTML5 is tooling. Design and development tools that work with HTML5 are not as developed or as robust as those that exist for Silverlight, making HTML5 development more complicated, especially as application complexity increases. Thus far, though the company has continued to promote it as the first choice for browser-deployed applications, Microsoft has done little to address these issues with HTML5.

Redmond has, however, done something with HTML5 that it has never bothered to do for either Silverlight or WPF, and that’s make it fast. Internet Explorer 9 builds on top of an API called Direct2D. This is a 2-D graphics library that uses Direct3D 10 for acceleration. The Direct2D API is even lower-level than HTML5; while HTML5 pages are basically built up of text boxes, these boxes do have some “intelligence” of their own; they have layout rules, borders, backgrounds, and more. Direct2D in contrast can handle little more than curved lines — or groups of curved lines — with every aspect of layout left to the developer. And unlike the inefficient way in which WPF uses Direct3D, Internet Explorer 9 and Direct2D have been optimized and are far more efficient.

With Internet Explorer 9, Microsoft was therefore telling its developer community two things: HTML5 is the preferred technology, regardless of its suitability or desirability. If you want high performance you can either use the low-level Direct2D from C++ directly — an unpalatable option — or the mid-level HTML5. If you want a high-level, purpose-built API with high performance — a version of WPF built on top of Direct2D, for example — it isn’t going to happen.

The Windows 8 comment thus seems to be the culmination of Microsoft’s policy of the last few years. HTML5 was already the blessed development platform in spite of its many failings, and with Windows 8 developers are going to be faced with little alternative but to embrace these inadequate technologies if they want to produce new-style immersive applications. As crazy and destructive as this policy appears, it has the feeling of consistency. Internet Explorer 9 and the downplaying of Silverlight were the first step down this path; immersive applications requiring use of HTML5 are the next.

Author: dfgdfg,

Categories: , ,

May 28, 2011

Microsoft downplays IE 'cookiejacking' bug



Microsoft today downplayed the threat posed by an unpatched vulnerability in all versions of Internet Explorer (IE) that an Italian researchers has shown can be exploited to hijack people's online identities.

The bug, which has been only discussed and not disclosed in detail, was part of an attack technique described by Rosario Valotta, who dubbed the tactic "cookiejacking," a play on "clickjacking," an exploit method first revealed in 2008.

Valotta combined an unpatched bug, or "zero-day," in IE with a twist on the well-known clickjacking tactic to demonstrate how attackers can steal any cookie for any site from users duped into dragging and dropping an object on a malicious Web page.

He had demonstrated the attack at a pair of security conferences in Amsterdam and Zurich earlier this month, then published more information on his blog Monday.

By hijacking site cookies from IE7, IE8 and even IE9, attackers would be able to access victims' Web email, Facebook and Twitter accounts; or impersonate them on critical sites that encrypt traffic, like online banks and retail outlets.

Jeremiah Grossman, co-founder and CTO of WhiteHat Security, called Valotta's attack "clever" and said he could see hackers taking to it as a fallback to clickjacking, which he and Robert Hansen uncovered and publicized nearly two years ago. "In the event they can't find a cross-site scripting or clickjacking vulnerability, this would be a nice fallback plan for [attackers]," Grossman said.

But Microsoft didn't think cookiejacking was much to worry about.

"Given the level of required user interaction, this issue is not one we consider high risk in the way a remote code execution would possibly be to users," said Jerry Bryant, group manager with the Microsoft Security Response Center (MSRC). "In order to possibly be impacted, a user must visit a malicious Web site and be convinced to click and drag items around the page in order for the attacker to target a specific cookie from a Web site that the user was previously logged into."

Grossman strongly disagreed.

"I think they're wrong," he said. "Like many esoteric attack techniques, until they've seen it used in the wild, they'll downplay it. It's actually a very simple attack, but it's not technically difficult, so their take is 'Nothing new to see here.'"

Valotta's proof-of-concept attack was relatively simple: He built a Facebook game that baited users with a simple puzzle of an attractive woman, and with it was able to collect dozens of cookies from unsuspecting Facebook users.

"I published this game online on Facebook and in less than three days, more than 80 cookies were sent to my server," Valotta told the Reuters news service this week.

The puzzle required users to drag and drop pieces on the Web page; unbeknownst to the victims, when they did so they actually dragged cookies to a specific spot on the screen where a clickjacking attack captured the data before sending it Valotta.

Valotta said that all versions of IE, including the just-released IE9, on all supported editions of Windows, including XP, Vista and Windows 7, were vulnerable to cookiejacking attacks.

Bryant added that the IE vulnerability was not serious enough to trigger an emergency, or "out-of-band" security update. "We are also not aware of it being used in any active way outside of the demo at [the Amsterdam] Hack in the Box [conference], he said.

Author: dfgdfg,

May 11, 2011

Microsoft Acquires Skype for $8.5 Billion


After rumors that first Facebook and then Microsoft were in talks to acquire Skype, the latter announced that it has acquired the VoIP giant for $8.5 billion in cash.

Skype will be integrated into Microsoft devices and systems such as Xbox and Kinect, Xbox Live, the Windows Phone, Lync and Outlook, Microsoft said in a statement. The company has pledged to continue supporting and developing Skype clients on non-Microsoft platforms as well.

The deal, which was spearheaded by Microsoft CEO Steve Ballmer with assistance from Charles Songhurst, the company’s head of corporate strategy, was completed Monday evening, AllThingsD reported earlier.

The acquisition is an expensive one for Microsoft. Not only is it the largest price Microsoft has paid for a company in decades, Skype is not yet profitable. Despite revenues totaling $860 million last year and operating profits of $264 million, the company lost $6.9 million overall, according to documents filed with the SEC. And the company carries $686 million in debt.

Much of the company’s appeal rests in its largest user base of 663 million, 145 million of which use Skype monthly (Update: Microsoft says Skype has 170 million regular users), and 8.8 million of which are paying customers.

There is one clear set of winners here: Skype’s investors. A group including Silver Lake, Index Ventures, Andreessen Horowitz and the Canada Pension Plan (CPP) Investment Board purchased the company from eBay for $2.75 billion in September 2009.

In August, Skype filed for an IPO but put plans on hold after Tony Bates joined the company as CEO in October. Bates will take on the title of president of the Microsoft Skype Division and report directly to Ballmer.

Author: dfgdfg,

Categories: , ,