Menu
The Tech News Blog

July 21, 2014

XP Users Can Still Get Effective Antivirus Protection

XP Users Can Still Get Effective Antivirus ProtectionAs of April this year, Microsoft officially ended support for Windows XP. Those still using XP won't get any more security patches. Well, there was one in May for an egregious Internet Explorer bug, but that's not likely to happen again. An XP system without antivirus protection is a sitting duck, ripe for attack. On the plus side, the latest test results from AV-Test Institute show that many popular security products remain quite effective under XP.

Three-Part Test
AV-Test regularly releases lab test results organized into three categories: protection, performance, and usability. Products can earn up to six points in each category, in half-point increments, with a maximum possible score of 18 points. In order to receive certification, a product must achieve a total of ten points, with no category score below one point.

To measure protection, AV-Test researchers install each antivirus on a clean system and then expose that system to malware in a variety of ways. For testing, they use both very new zero-day malware and a collection of very widespread malware. Quite a few products managed 100 percent protection in both parts of this test. A few clunkers dragged down the overall average to 97 percent for zero-day samples and 98 percent for widespread samples. Microsoft Security Essentials (included as a baseline) and AhnLab both turned in scores below 80 percent protection.

Nobody wants antivirus protection at the expense of system performance. AV-Test's team measures how long it takes for a standard clean system to perform 13 actions reflective of real-world computer use, such as downloading files, running popular applications, and installing programs. They run these same tests after installing the antivirus and note any slowdown. About a third of the tested programs scored slightly worse on this test than on the previous test, which used Windows 7.

For a perfect usability score, an antivirus product must completely avoid identifying any valid website or file as malicious. At best, false positive warnings can confuse users and diminish their faith in an antivirus product's effectiveness. At worst, the antivirus might prevent installation of a legitimate application. All of the tested products scored 5.5 or 6.0 points in this test, with the exception of Comodo. Comodo's over-enthusiastic behavior-based blocking system knocked its score down to 4.0 points.

Three Champions
In all the time I've been tracking AV-Test, I've rarely seen a perfect score, and I don't think I've ever seen three at once. Yet that's exactly what happened in this test. Bitdefender, Kaspersky, and Panda all earned six points in each of the three categories. If you're stuck using XP, consider one of these three champions to protect your system.



July 17, 2014

Xbox Entertainment Studios to Shut Down

Xbox Entertainment Studios

As part of the massive Microsoft layoffs announced today, Redmond will also shutter Xbox Entertainment Studios.

As first reported by Re/Code, the shutdown will occur in the next few months, Xbox chief Phil Spencer wrote in a memo to staff.

Xbox Entertainment Studios was founded last year in order to produce original content for the Xbox platform. The L.A.-based, 125-person studio was led by former CBS television president Nancy Tellem, who remains "committed to new, original programming already in production," Spencer said today.

That includes the Signal to Noise documentary series announced in December, the first installment of which will tackle the rise and fall of Atari, and that recent Atari cartridge scavenger hunt in the New Mexico desert.

Also still on track is Halo: Nightfall, a live action series being produced by Ridley Scott, and the Halo TV series that is being developed in coordination with Steven Spielberg and is set to debut next year. Both "will continue as planned with 343 Industries," Spencer said today.

Interactive sports content like NFL on Xbox will also continue, but otherwise, Xbox users shouldn't expect too much more original content out of Redmond. Look to "our app partnerships with world-class content providers" for that, Spencer said.

Some of the original content Microsoft teased back in April included "an unscripted series about international street soccer, [and] an original drama about robotic servants in a dystopian world."

"Change is never easy, but I believe the changes announced today help us better align with our long-term goals," Spencer said today. "We have an incredible opportunity ahead of us to define what the next generation of gaming looks like for the growing Xbox community. I have a great deal of confidence in this team and know that with clarity of focus on our mission and our customers we can accomplish great things together. We already have."

Microsoft's layoffs, meanwhile, will affect 18,000 workers, about 12,500 of which will be from Nokia.



July 17, 2014

Microsoft to Lay Off 18,000 Employees in the Next Year

Satya Nadella Microsoft is eliminating 18,000 jobs over the next year as it works to integrate the Nokia handset business it acquired in April, CEO Satya Nadella announced on Thursday.

About 12,500 of the reductions are expected to come from Nokia, including professional and factory workers.

In a memo to employees, Nadella also said Microsoft will largely nix work on Android-based devices. "We plan to shift select Nokia X product designs to become Lumia products running Windows," he wrote. "This builds on our success in the affordable smartphone space and aligns with our focus on Windows Universal Apps."

In a separate email to employees, Microsoft exec - and former Nokia chief - Stephen Elop said "we expect to make this shift immediately while continuing to sell and support existing Nokia X products."

"Whereas the hardware business of phones within Nokia was an end unto itself, within Microsoft all our devices are intended to embody the finest of Microsoft's digital work and digital life experiences, while accruing value to Microsoft's overall strategy," Elop said. "Our device strategy must reflect Microsoft's strategy and must be accomplished within an appropriate financial envelope. Therefore, we plan to make some changes."



July 15, 2014

Report: Microsoft Layoffs Expected This Week

Microsoft CEO Satya Nadella

Microsoft is expected this week to announce its largest round of layoffs since 2009.

According to a report by Bloomberg, the tech giant plans to slim down its 127,104-person workforce—likely in those divisions that overlap with the newly acquired Nokia handset unit.

Final details are still being ironed out, though reports tip reductions in marketing departments for businesses like the global Xbox team and software testers.

Microsoft declined to comment on the reports.

The news comes days after new Microsoft CEO Satya Nadella (pictured) issued a lengthy memo to staffers, which suggested that layoffs might be on the horizon in the form of "engineering and organization changes" this month.

"Organizations will change. Mergers and acquisitions will occur. Job responsibilities will evolve. New partnerships will be formed. Tired traditions will be questioned," Nadella wrote.



July 9, 2014

Patch Tuesday Closes 29 Vulnerabilities in IE and Windows

Microsoft Patch TuesdayMicrosoft fixed 29 vulnerabilities in Internet Explorer and supported versions of Windows as part of July Patch Tuesday. The lion's share of the vulnerabilities fixed this round were in Internet Explorer.

Of the six security bulletins released, only two of them—for Internet Explorer and Windows Journal—are  rated as critical, according to Microsoft's Patch Tuesday advisory. Three are rated as important, and the final bulletin has only a moderate rating. Both the IE and Windows Journal bulletins address remote code execution flaws. The important bulletins fixed elevation of privilege flaws in the on-screen keyboard, ancillary function driver, and DirectShow, and the moderate bulletin fixed a denial-of-service bug in the Microsoft service bus.

Microsoft said it had not observed any attacks in the wild targeting any of these flaws.

IE Oh My
Microsoft fixed 24 flaws in Internet Explorer (MS14-037), one publicly disclosed bug and 23 privately reported ones. This is after Microsoft patched 59 vulnerabilities in Internet Explorer last month. The issues are critical for Internet Explorer 6 to Internet Explorer 11 on Windows machines, but just moderate on Windows servers.

Attackers can exploit the IE bugs by tricking users into visiting a specially crafted malicious site. Once the attack succeeds, the attacker would have the same user rights as the compromised user. Users with fewer rights—not logged in as Administrator, for example—would be less impacted.

"It remains to be seen if Microsoft has cleaned up the Internet Explorer vulnerability closet for the next few months or if this is the new normal," said Marc Maiffret, CTO of BeyondTrust.

Obscure Windows Software
The issue with Windows Journal (MS14-038) could allow attackers to remotely execute malicious code. Windows Journal is installed by default on all supported versions of Windows, from Vista to 8.1, but isn't commonly used. Windows Journal can be used on touch-enabled devices as well as non-touch Windows computers to capture handwritten notes. The vulnerability was in how Windows opened files saved in the Windows Journal (.jnt) format.

The Windows Journal bug is a "great example of how unused software can be abused by attackers," stated Craig Young, a security researcher at Tripwire.

Windows Journal is not installed on Windows Server versions.

Maiffret recommending treating the file extension as if it was an executable and block it on the Web and email gateways.

If there is a reason why the two critical patches can't be installed immediately, uninstalling Windows Journal and switching to a different Web browser are sufficient workarounds. "While a patch is always preferred, limiting the attack surface is a good backup," said Tyler Ranguly, manager of security research for Tripwire.

Remaining Patches
The bulletins rated important fixed bugs uncovered during the pwn2own contest back in March. The local elevation of privilege issues can be exploited to give unprivileged users greater access to the vulnerable system. They can be used in chained attacks to compromise the system, suggested Ross Barrett, senior manager of security engineering at Rapid7. "Given the nature of their disclosure, [they] must be known to have exploit code," Barrett warned.

The ancillary function driver bug can be paired with "something like the Internet Explorer vulnerabilities from this month to allow for drive-by web attacks that result in execution of code in the kernel," Maiffret said.



July 2, 2014

Microsoft Wants Office Beta Testers

Microsoft Office logo

Microsoft is seeking volunteers to test beta versions of its Office software, potentially hinting that a new version for Android tablets is on the way.

The company just posted a sign-up page where individuals and companies can register their interest in testing pre-release versions of Office.

"Your feedback in these programs will be instrumental in building the best productivity software and services available," Microsoft wrote on the sign-up page. "The programs will span across the full family of Microsoft Office client, server, and cloud services. The family of products include Word, Excel, PowerPoint, OneNote, Visio, Access, Publisher, and Outlook applications, as well as the Exchange, SharePoint, and Project server products and cloud services."

Microsoft last year launched its Office 365 suite for Android phones, and the company is now reportedly working on a version specifically for Android tablets. The Verge, citing unnamed sources familiar with Microsoft's plans, on Wednesday reported that Redmond is gearing up to launch a beta test of the new Office Android tablet version.

Meanwhile, Microsoft in March finally released the long-awaited Office for iPad suite, which allows full access for Office 365 members, and limited preview capabilities for non-subscribers. Office for Android will reportedly be optimized for touch, just like the iPad version.

Anyone with an iPad running iOS 7 and above can download the Office apps, but you'll need an Office 365 subscription to actually get any real work done. For more, see: Microsoft Office for iPad: How to Get It.

Microsoft also recently launched Office 365 Personal, which is designed for individuals, and allows one PC or Mac and one tablet to be connected to the service for $6.99 a month or $69.99 a year.



June 30, 2014

Leaked Doc Tips Folders for Windows Phone 8.1

Microsoft Windows Phone 8.1 (Developer Preview)

Microsoft's Windows Phone OS might soon be getting a new feature that should make organization aficionados happy — the ability to create folders for easier app management.

Redmond hasn't officially announced the feature, but the company accidentally posted (and quickly pulled down) a how-to page for creating folders on the Windows Phone Start screen.

"Folders help you keep your Start screen organized by letting you group Tiles the way you like," the now-cached page reads. "For example, you might have a folder with all your games or one with your favorite apps. It's completely up to you."

Folders are, of course, nothing new to iOS and Android users. Based on Microsoft's how-to page, it appears that the process of creating a folder on Windows Phone will be similar to that of iOS and Android.



June 25, 2014

Microsoft Restores Outlook Access After All-Day Outage

Outlook.com Logo

Microsoft has restored email service to users who found themselves twiddling their thumbs (and venting on Twitter) Tuesday during a system-wide outage.

First identified around 9 a.m. Eastern, the unidentified issue left Exchange Online customers without access to their email for almost nine hours. Redmond patched the problem just before 6 p.m.

"Investigation determined that a portion of the networking infrastructure entered into a degraded state," an official Microsoft update said. "Engineers made configuration changes on the affected capacity to remediate end-user impact."

The company offered multiple apologies for the inconvenience, though, judging by the Office 365 forum, that's not quite enough for many users.

"Not only did this outage cause our customers issues but ongoing problems that started before today [Tuesday] were blown off by MS partner support due to the outage," user CJB at Loffler wrote in a forum post. "What a huge waste of my support staff's time today."

User BradyBryan agreed, writing that "This is entirely unacceptable. … No coordination at MS? I've lost an entire day of productivity."

As per usual, many users took to Twitter to air their concerns.

Microsoft did not immediately respond to a request for comment.

Tuesday's Outlook outage struck only hours after Redmond's online communications service Lync suffered connection problems on Monday. The Lync downtime, according to a Microsoft statement published by ZDNet, was "due to network routing infrastructure issues."

The news comes shortly after Microsoft announced more than double the amount of OneDrive cloud storage space—15GB for free, up from 7GB.



June 23, 2014

Trade in MacBook Air, Get $650 for Surface Pro 3

Microsoft Surface Pro 3

Microsoft is offering up to $650 in store credit for those who trade in their MacBook Air and purchase a Surface Pro 3.

From now until July 31, MacBook Air users can bring their laptops to a Microsoft Store in the U.S. or Canada, and get a credit that they can use to purchase Redmond's latest Surface tablet.

To be eligible for a trade-in, a MacBook Air must power on, and not have any water damage or cracked screens.

When Microsoft introduced the Surface Pro 3, Panos Panay, head of Microsoft's Surface division, touted the device as "the tablet that can replace your laptop." Panay compared the Surface Pro 3 to the 13-inch MacBook Air, and said the Surface Pro 3 allows for 6 percent more content on the display than the Apple laptop, despite having a smaller 12-inch display.



June 23, 2014

Microsoft Matches Google With 15GB of Free OneDrive Storage

New Microsoft Logo With no shortage of competition in the cloud storage market, Microsoft is making it more attractive to use its OneDrive service.

The company on Monday announced it has more than doubled the amount of cloud storage space it offers to users for free. Now, OneDrive comes with 15GB of storage for free, up from 7GB.

"Our data tells us that 3 out of 4 people have less than 15GB of files stored on their PC," OneDrive Group Program Manager Omar Shahine, wrote in a blog post. "Factoring in what they may also have stored on other devices, we believe providing 15GB for free right out of the gate — with no hoops to jump through — will make it much easier for people to have their documents, videos, and photos available in one place."

Meanwhile, Microsoft is also hoping to get users to sign up for Office 365 with the promise of more OneDrive storage. From now on, all versions of Office 365 will come with 1TB of OneDrive storage, up from 20GB, Microsoft said.