Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Friday, June 25, 2010

Windows 7: Byte Me

I've had to play with Windows 7 in the workplace lately.

It's been...interesting?

First of all, Microsoft did improve heavily from Vista. Vista was frustration wrapped in a pretty eye candy shell, and no matter what you did to try and enjoy the candy the frustration was just itching to burst through and make you gag.

At least now it doesn't nag you quite as much.

That said, I've still had issues with Windows 7.

I hate not being able to easily run something as administrator. I find that I have to type "cmd" into the search bar and then right click on the result to "run as administrator."

We use a VNC server to remotely work on many of the desktops in our organization. Windows XP? It wasn't a problem. Under 7 (and Vista when we tested that abomination) we needed to run something like UltraVNC, because the version we were running isn't compatible with the security model used in newer versions of Windows.

I also was more than a little irritated when I could no longer run XLiveCD, a CD disc that has a standalone set of Cygwin tools and X Windows client for Windows. Pop in the CD, run it, and it allows me to secure shell into a Linux system at the office and run my mail client or other tools on my office system. Exit out, and there's no trace of anything on the client computer. Really handy for getting some work done in the field. Windows 7 won't allow me to run it, no matter what I've tried (compatibility settings, permissions, running as administrator...) How annoying!

Another item; I had to change some permissions on icons placed on the desktop of a system. They were icons for everyone, but because of the way my boss made a batch file the icons were placed in a directory for everyone to use under Users but the permissions were set to just the administrative user running the batch file. I went into Users (since documents and settings is no more) and went into all users (after I finally found the setting for showing hidden files and folders, since the file menu is gone now from Explorer windows.) I went into All Users, but even as an administrative user I couldn't get into the "desktop" folder.

I swore a few times and my supervisor came over. "Oh no, it's not there. Go up one and go into Shared." (It may have been Public, I'm recalling this from memory and am too lazy to look it up.) Sure enough, that folder had the Desktop folder for all users who log into the machine.

"That's stupid! The folder sounds like one used as a common sharing area for any user to share documents with each other..."

"I know. But that's what it is now."

Bloody @#$.

Then I had to reset the permissions by selecting the folder containing the desktop files and resetting the files from there, since I couldn't just select the files and tell it to change permissions to those inherited by the parent folder as I could under XP.

Then today I had an application that is niche, used by only a few of our users but "vital" (due to more mandates from outside our control) for their job function. The program looks for "Windows NT 4.0 SP 6 or higher", and installed .NET runtime 1.1, if that tells you anything about the age of the program. It looks like something shoveled together at the last minute and shoved out the door, then as long as the #@#% thing ran the company never bothered to improve it (hey, they have a contract to supply it and we're mandated to use it! So why should they improve it?!)

Can you guess where this is going?

I contacted the company, saying that we have this program that apparently has problems with Windows 7. Is there an update or patch?

"Nope. The workaround is to use a Windows XP SP 3 system until we get a chance to test it with Windows 7, maybe sometime next month."

Um...you're aware the Windows 7 has been released, right? And if you actually developed the product, you should have had a copy of the betas of Win7 to...I don't know...test with several months ago, yeah?

Great. Another company producing shovelware.

And I can't get the "compatibility" mode of anything to work with this piece of crud. Then I saw something that gave me hope! Windows 7 XP mode!

Basically, it's a virtual machine running Windows XP for backwards compatibility!

I downloaded the 500 meg installer from microsoft, installed the virtual machine software, then installed the update patch (MS actually had a convenient web page with a "install this, then install this, then install this...set of instructions and download buttons.) I was getting irritated that I had to run some "Authentic windows" verification program, several times for reasons unknown to me other than probably clicking the link too many times while it was pausing to think about whether it actually wanted to do what I told it to do, and finally everything installed!

Then I created a new virtual machine. Oddly enough it said for memory I could allocate 4 to 511 meg. I skimmed the wizard's instructions (don't most people) and just clicked "next"; it beeped at me with an error. Apparently the default memory size in the box was 512, despite the warning that it could only go up to 511. My supervisor wondered what was going on when I blurted out, "How fucking retarded is this thing?!"

He just shrugged and went back to what he was doing once I explained what Windows was doing again. Because really, how hard is it to check that error condition?

Fixed it, created the VM, and double clicked it, giddy with excitement that I may have found the solution to our problem. The computer hesitated, gave a busy pointer for a moment, then *blip*...blue screen of death.

The machine rebooted, and I tried again. *blam.* Blue screen of death.

Yes, I found a great Windows simulator here.

I slammed the desk with a fist and moved on to Googling the error. So far I found griping about problems with XP Mode on Windows 7, but no solutions. The last thing I did before leaving was upgrade the BIOS since it was an older computer, but haven't tested it again.

So what do I think of Windows 7? It has potential. It looks nice, it has great features, it's leaps ahead of Windows Vista, but it's still frustrating as hell half the time and the rest of the time it's mildly irritating. It's broken a lot of software, and if you're using software by developers that played loose and wild with best practices you'll be lucky if your software works properly.

There are those that would say it's just because I'm used to "bad habits" from Windows XP. Perhaps they are right to some degree. On the other hand, every irritation is one more reminder why I have come to prefer the Mac as my computing platform. It's not fanboy fanaticism or a need to feel superior to Windows users. It's because I find it far less frustrating to use and it doesn't get in my way even half as much as Windows.

Tuesday, April 27, 2010

Microsoft Licensing: The Pain It Keeps On Rolling

I continued to set up the Dell machine from the other day. I started out my day at the office where I updated my supervisor on the installation, saying that the laptop couldn't be joined to the Active Directory domain because it was running Windows 7 Home, and apparently that ability is disabled in the home edition. I wasn't sure if he'd care because I thought the user was going to be using it primarily at home anyway.

"Nah," he said. "We have Windows 7 Professional and the licenses, just install that on it."

I sighed, packed up my shiny Windows 7 DVD (64 bit, since for some reason the home version of Windows 7 was 64 bit on that laptop with less than 4 gig of usable RAM...) and headed out to the office where I could work on that system.

I vaguely recall that Windows since Vista has been coming in a form where every version, and there are lots of them, of Windows is included on the install DVD. The different versions that cost you hundreds and hundreds of dollars between the lowliest, crappiest version to the least crippled version are all one in the same; they simply have functionality that is disabled or enabled depending on the license key you feed it.

Neat, eh?

Don't get me wrong with what I'm about to say. I personally hate using software that is crippled artificially. It was one of the reasons I initially moved to Linux; my desktop computer could act as a capable server, while Windows, despite being able to handle a modest workload, was throttled back in what it could handle simply because of a registry setting. Even though I never to my recollection was even maxing out the throttled limits I hated the idea that my system was crippled simply because of me not having more money.

At the same time, I understand and support that it is Microsoft's right to impose limits on their users, as we have to agree to the license in the first place and that license places these (irritatingly arbitrary) limits on the end user. That's why I moved to Linux instead of pirating Windows. It's their product. They dictate what can and can't be done with it.

That said, why is it that Microsoft seems to go out of their way to make a task as simple as installing our volume-licensed, legal copy of Windows 7 Professional over the default Windows 7 Home preinstalled on a Dell laptop?

Here's the thing; for the most part, choice is bad for ease of use. You give users choices, you make them think, you give them the opportunity to screw up. That counts against you in the ease of use department. Weird, isn't it?

Microsoft has outdone itself, going out of their way to make something as simple as licensing into a pain in the arse.

The DVD we have actually has two licenses printed on it. One is KMS and the other is MAK. KMS is their Key Management Service key, and MAK is their Multiple Activation Key. Two really long string of numbers and letters that belong to our business. The difference? The KMS key allows us to have an "in-house" server to handle activations more or less automatically, while the MAK key allows us to input the MAK key individually into systems that then call Microsoft over the Internet to activate. Both the MAK and KMS keys are types of Volume Keys.

Making sense so far?

The Dell laptop with Windows 7 Home apparently has a self-activated key already installed. I popped in the DVD with Windows 7 and told it to run Setup. Setup started chugging along, asking a couple questions, then  it got to the point where it asked if I wanted to upgrade or clean install. I said, upgrade! I already installed an antivirus and our full version of Office (after deleting some crappy trial version of Office that was on the system when we received it for configuration. Setup started looking at the drive and said, "Nope! We can't do that with this version of Windows! You have to run the Windows Anytime Upgrade from the start menu!"

Ah-ha! It does have all the versions of Windows, I just need to plug my key there!

I do a search, since the menu system in today's incarnations of Windows makes it damn near impossible to actually find anything now, for the Windows Anytime Upgrade utility. Run it, it asks for the key. I put in our MAK. It rejects it.

Apparently you need a special Windows Anytime Upgrade key in order to activate that function.

So now I have a licensed, pre-activated Home key, a MAK key, and a KMS key, and none of them do me a damn bit of good because I need a WAU key.

I swear, several times actually, and re-run the setup utility, this time telling it to nuke the C: drive and start over.

This time it worked. I had to spend most of the day reinstalling Windows (Professional, this time), reinstalling Office, reinstalling antivirus, and all the miscellaneous utilities that I had installed but wiped out in the full reinstall.

This wouldn't piss me off so much if I hadn't seen the alternative way to handle licensing. In Linux, there are no real restrictions. You may get a flash of the GPL license, but no key to enter, no restrictions on how you use the operating system (other than what the GPL enforces, which for most users is of no consequence).

On OS X, there are licensing restrictions, but Apple largely takes you at the honor system. Their attitude seems to be, if you put the operating system on hardware that's not ours and it doesn't work, you're screwed, buddy. Apple is largely a hardware company. They make money from their hardware and services. While they have restrictions on what you can and can't do with their software they don't go out of their way to make customers bend backwards while gargling Yankee Doodle Dandy on a unicycle in order to install their software on their hardware.

In the end it feels as if you buy their operating system just by having purchased the Mac. It doesn't bug you for software keys or activation. It just installs. The closest I've had to being locked out from an installer was trying to use a MacBook installer CD to reinstall OS X on an older system whose hard disk had failed. The install CD was keyed to work only with MacBooks, even though it was the version I had on the PowerMac before it died. I think I was still able to reinstall on the new hard disk by booting the Mac to Target Disk Mode and installing from there, as I recall.

No pestering. No nagging. Definitely no typing thirty-digit codes by hand. Maybe Apple just thinks it's not worth pissing off or frustrating customers for the possibility that someone will pirate their software. I had to take my mother-in-law's old G4 notebook in to an Apple store after the operating system became corrupt, and in the end they did a restore from a clean image. The guy at the Genius bar asked what version of OS X was on it.

How would I remember? I haven't looked at that system in probably two years. I can't remember what I wore two days ago, let alone what my mother in law had on her notebook. I guessed 10.4 judging from what I probably had on it when it became her system.

The Genius didn't ask for proof. Didn't hassle us at all. I think he was prepared to install whatever version I said (except Snow Leopard, since that didn't work on G4 Macs). Oh dear, they might lose $30 if I stole a newer version of their operating system! Instead, they made happy customers a priority over losing a drop in the bucket in change.

On the other hand I ended up losing most of a day of work because I needed to install from scratch Windows because I didn't have a particular type of key. Because the keys we paid lots of money for, legitimate keys, wouldn't work to do an in-place upgrade that would have taken ten minutes.

Thanks, Microsoft. One of the largest companies on the planet and you manage to make something as simple as installing your operating system a major hassle for a legitimate customer. Let me wave my "you're number one" sign at you without using my pointer finger. With both hands.

Sunday, April 25, 2010

The Unpacking Experience: PC vs. Mac

I wrote that I recently purchased two 13-inch (mid-2010) MacBook Pros as gifts for myself and my wife. Late last week I also had to unbox and configure a Dell Inspiron 1750 (reviewed by PC Mag here and on Amazon here).

There is a significant difference in pricing between the two laptops and it wouldn't be fair to bitch about things that are primarily pricing differences. On the surface, there are several similarities that would make little difference to the end user; four gig of RAM on both, they both have webcams built in, they both have ports for external video (although the Mac isn't standard and requires a $30 adapter purchased separately), disc burners, etc. Most people, the vast majority, won't care about the manufacturer of the RAM, the brand of burner, or for the most part (unless it's really really bad) the resolution of the built-in camera.

The differences that really slapped me in the face were due to the differences between operating systems. This is something that is very much in the control of the manufacturers, regardless of the pricing of the laptops and the included hardware for the most part. Every time I cursed because I hit another roadblock to overcome was another "papercut" that makes me hate the hardware and software just a little more.

The Mac started up with a nice little flying welcome and music score before asking me some questions for basic setup. It took a few minutes before I was at the Finder desktop. Then I proceeded to run system updates; despite the system being introduced, literally, a week ago, it had two somewhat large updates (a little north of a hundred meg of downloads as I recall). Two reboots, done. My system had iWork already installed and I then proceeded to download some software that I planned to use (OpenOffice, FireFox, etc.) and all was well. I literally had a system ready for my personal use in about an hour or so, not counting the long process of copying my personal data from my old drives to the new laptop.

Not everything was gummy bears and rainbows. For my personal use, I wanted the laptop to run with encryption. The Mac uses FileVault for built-in encryption protection of your files, which is fine (aside from scary stories of the disk image now used for your home directory becoming corrupt; if it gets corrupted, you lose your whole home directory, not just a few files).

I also wanted backup protection. For the longest time I was very much a manual-protection person; I ran a script that synced my hand-created directory structure for personal data to external drives. I kept my photos in a folder structure I made to my own specifications, I kept my documents neatly organized, and if something happened I would just rebuild the computer from a clean install and copy the "files" folder from my external drive to the new computer. Fairly simple.

The Mac encourages...strongly...using a feature called Time Machine. It is really snazzy in that it creates hourly snapshots of your data to an external drive and has a neat almost Dr. Who-like flying-through-space interface for browsing your data as it changed over time. Just plug in an external drive and the Mac pops up asking if you'd like to use it as a Time Machine volume and from there handles the backup details in the background.

The problem? Use FileVault, and it will only back up your data at logoff for FileVaulted users. And you can't restore individual files from the Time Machine interface if you use FileVault, only the whole home directory. Ouch...

The process of enabling FileVault and Time Machine together on the Mac wasn't one hundred percent smooth either; the first time I enabled Time Machine, it said I was backing up about 150 gig of data (everything I read said this wasn't possible, as about 140 gig of it was my home directory and that wouldn't work until I logged off). Hmm...I think I'll log off to help it.

When you log off of a FileVaulted system the Mac will go through a process of recovering space on the disk; it's shrinking the disk image used in the background for storing your home directory data. Usually it doesn't take too long (unless you created and deleted a huge file during your session, I suppose.) Here, it did. It was going on ten or fifteen minutes before I made the decision to kill the machine from the power switch.

Reboot, came up, logged in without error (disk check revealed no problems). I did a reformat of the drive I was using for backup so I could start from scratch. Then I let Time Machine do its thing, this time staying logged in while it ran the first time. It told me it was backing up around 150 gig. Chugged along, and all of a sudden said it was done. Apparently it backed up the system and quit once it found the FileVault home directory image.

Logged out, and this time it recovered disk space in just a few seconds and the prompt changed to "backing up..." with a progress bar. Hours later (hey, it's USB...) it completed without issue. Definite user friendliness issues with how that was implemented, despite the somewhat scary warning that comes up when you turn on Time Machine with FileVault enabled.

Thinking back over the past week or two that's the only thing that really stood out as an operating system issue in migrating a brand new out-of-box system to my primary workhorse so far.

The work laptop running Windows 7 was in my experience far more frustrating.

Turned it on and the system asked me a few standard questions for configuration. Nod nod, yeah yeah, click click.

Next I was going to install our licensed copy of Microsoft Office. Usually it's pretty standard, but I had the slight irritation at having to remove the "trial copy" that was on the Windows 7 system first. I hate it when makers license "trials" of crap. It's a trap for users; they think they own the software or it came with the system, only to have it pop up errors a month down the road asking them to purchase it if they want to keep using it.

Then McAfee popped up with notices for updates and advertising. Another big peeve of mine related to what I just noted, because the user thinks they have antivirus protection when really it's a limited trial that will bug them to purchase further protection down the road. Users really don't think about these things and remain largely ignorant of the topic, right up until it stops protecting them. Errors pop up but the user just typically clicks through them until something goes really wrong, takes it to their resident geek, and he finds that the computer hasn't had updated virus definitions in six months and the user assumed it worked because they had McAfee (or another vendor's software) installed.

Uninstall uninstall uninstall.

Next I tried to put it on the domain. Guess what? Whoever purchased the laptop bought it with Windows 7 Home. Windows 7 Home won't connect to a domain. Another peeve of mine; artificially crippled software. I know it's a licensing issue and Microsoft has every right to do this with their software. It explained that this version of Windows is unable to join a domain. It's still a pain in the arse that I threw into my curse-pile after having to uninstall trialware crap.

I next had to uninstall a Dell wireless utility. On our network for reasons never fully explained the Dell utility for wireless interferes with the ability to connect to our Cisco wireless access points. Delete the utility, let Windows manage the connection, generally there's no problem after that (although now that it can't connect to the domain, I suppose the point is somewhat moot). I deleted the utility as we've done with countless Windows XP systems. Suddenly the system conveniently forgot it had a wireless card, period.

A big sigh and a dig through the box yielded a Dell Resource Disc with the drivers (ALREADY INSTALLED, it proclaimed). I inserted the disk and it prompted me to run a setup program first. Huh?

Okay...run install. Then it prompted me to remove the disc and reinsert it. Okay.

Then it popped up an error that I had the wrong volume in the drive.

Told it to continue twice and it suddenly decided it was okay. It ran a program that detected my hardware. Okay, I think, this is a turn for the better because now I don't need to guess the hardware!

It popped up with the Inspiron 1750 page and gave me an option of installing one of four or so drivers for the wireless card. Um...aren't you supposed to have detected it?!

I ran the first one. It told me that hardware wasn't installed.

Started running the installer to the second one. Suddenly Windows detected the wireless card, installed driver support (while the second installer hadn't run yet, it was just finished extracting files). So Windows now had the driver rediscovered and working, apparently, as it now had it in the device manager again.

That resource CD was a waste of time, and who knows what the installer littered on the drive?

The Mac doesn't have this issue because Apple hardware is tightly integrated with the operating system. If you buy OS X as an upgrade, it will have drivers to update all the hardware that it is known to support built right into the operating system.

What I don't understand is why Dell goes through the trouble of creating a separate utility that rides on top of or supersedes the Windows wireless utility. If it works fine for the purpose I'd far prefer having the built-in system over a third party utility. When I sit at the Mac, I know what to expect when I want to change settings, whether it's my system or a friend's system. On Windows, there's the Windows utility and there's a vendor utility or there's a manufacturer's utility (do I use the Dell configuration program? Windows? Intel?), and sometimes they work or they goof each other up.

Confusing, and definitely not user-friendly.

Not to mention that adding additional layers of software for redundant functions adds complexity, and with complexity comes more possibility for failure or bugs.

In the end I'd prefer that manufacturers stop adding trialware crap to entrap clueless users and stop adding software with redundant functionality. Unless you can genuinely add functionality to the system, I don't need a utility to join wireless networks when Windows has that function already built into Windows, and it's a real boon for the neighborhood geek when he doesn't need to know the ins and outs of each manufacturers crap utility just to join a laptop to a home router. Worse, I don't need to have two or more utilities that fight each other for access to the hardware and in the process can disable settings that were put into one program and now won't work when switching to the other program they ran intuitively (what do you mean I wasn't supposed to run the Windows network settings to join the network? Windows told me too, dammit!)

Overall these little papercuts in the process of configuring the system started having even minor things like the wallpaper, a series of upside-down boomboxes for reasons I haven't yet figured out, really grate on my nerves after the fourth reboot for updates and configuration settings.

I'm sure there are apologists that will point out that the circumstances were different between unboxing my system and unboxing the Dell. I'm aware of that. And I'm sure that there are good points that I'm overlooking. The point is that there was a lot more friction in just getting this Dell system configured for even basic use than I encountered on the Mac, and it was almost always due to problems and peeves that were under control of the manufacturer, right down to the gawdy and irritating upside down boombox wallpaper (c'mon...what the hell is that?? Look at the links at the beginning and see if you can see in the screenshot of the product for the reviews the wallpaper I'm referring to.)

There are people who will be anti-Apple no matter what. There is an "Apple tax" for their hardware; and it purchases less irritation for me. The hardware integration with the operating system simplifies things and standardizes the interface and removes the need for two different ways to turn on my wireless networking, and I don't have to go through and delete trialware from the computer to clean it up. It's not perfect by any means (why can't they use a networked Finder, like X? Or workspaces that allows me to rotate a cube or slide the screen for multiple desktops like I can with Ubuntu's desktop? Yes, I know it has Workspaces, but I always found the Ubuntu enhanced GUI features a little easier, if not glitchy at times, to work with, but maybe that's just habit speaking right now.)

What it boils down to is that I am an Apple fan because despite the money I have to spend on their hardware they generally treat the customers right. They remove friction, for the most part, in using the system. Their walled garden is expensive to get entrance into and has a few bees hovering around. It simply seems that the more I use Windows 7, OS X, and Ubuntu, the more I appreciate the differences and enhancements each offers.

To tell the truth though I'm still looking for the enhancements Windows 7 has over Ubuntu and OS X...anyone? Honestly?

Wednesday, November 18, 2009

I Hate VISTA!

There are many things that factor into user-friendliness and it absolutely floors me that something like Vista was released so many years after Apple's OS X, an operating system that has been hailed as a shining example of user friendliness. I can understand many of the shortcomings of Linux in this area...it's largely developed by geeks that like to do what they can to prevent the average user from entering the sacred halls of geekdom, and creating pain among users is a secret handshake in our meritocracy.

But when you're the dominant operating system vendor with millions of users and millions and millions of dollars in R&D, what excuse do you really have for releasing something that is actually several times more frustrating than anything a bunch of geeks have (laughingly) "designed"?

I had to work on a laptop (yes, that I previously had worked on with Vista Home Edition) that was reported as saying that it "needed to update the antivirus but need administrator to do it."

Okay, shouldn't be hard. The antivirus is one that I'm not too crazy over because it, too, has in my opinion design flaws that drive me freakin' batty as well...Central Command's Vexira. However, I take the laptop and start to work.

I ended up having the laptop brought home. I spend some time trying to get Vista to find my wireless network (usually with XP it's a simple matter of clicking the wireless icon in the tool bar and selecting from a list, but this Vista laptops wouldn't show that to me). I eventually found in the networking control panel a line in English, in tiny print, telling me I can "find a network." Fair enough.

It found my (unsecured) wireless network. Join it. Warning: EVERYONE WILL SEE WHAT YOU'RE DOING!" Then it gave a button that didn't look like a button to continue on anyway. I thought it was a label of some sort...nope, just an awkwardly labeled button in the interface. I twitched a little.

It joined my wireless network, telling me the signal strength was excellent. I then right clicked on the Vexira system tray icon and told it to update. And waited. After a few moments I noticed a blinking task bar icon; click that, it tells me that there's a system notice. Click that, and the screen does the obligatory blanking-switch-to-system-screen. Told it to update, and it belches an error with the connection.

Huh?

Told it to "return to my desktop", leading to the laptop blinking a few times.

I was disconnected from the wireless. No reason why, just not connected.

I sigh and go through all the steps to reconnect and once again bring up the update interface on the "special annoy the hell out of the user" desktop.

SAME @#% ERROR. I returned to the regular interface and check the network connection. Disconnected.

I tell the bloody thing to reconnect, and this time "remember the network" and "connect automatically".  This time the notebook connected and stayed connected.

That wasn't the end of the problems, but my gripe here is about Vista, not Vexira. I don't understand why the connection was:
A) so awkward to connect to in the first place.
B) kept disconnecting without notice.
C) had so many @#% clicks to find, establish, and re-establish.

This was on top of the issue with having to switch desktop modes a few times and having the display click and clack as it changed back and forth (resetting video modes? Redetecting the display? I don't know; from the user perspective, all I know is that it ticked me off having to repeatedly go through that annoyance).

I'm a big believer in preventing friction in a user experience. I do what I can to minimize this friction; one thing I do to make it as least annoying as possible is to secure my systems from intrusion and monitor my network usage while removing encryption from my wireless network to make it friendly to the myriad devices we use. This should have made connecting to my wireless network a simple matter of "show available networks, select, connect." So why wouldn't this @#$% notebook connect and stay connected?

Once I told it to "remember the network" and "connect automatically", it stayed connected long enough for me to get a dose of hate for Vexira. The wireless network worked without issues for my wife's Mac. My own Mac hasn't had issues. My iPod hasn't had issues. So unless something is flaky with that notebook's hardware...which hasn't been reported (although possible)...it tells me that my headaches were Vista-related.

It's almost like Vista was going out of it's way to make this three times more difficult than it needed to be! Another checkmark on why I hate Vista. Supposedly Windows 7 improves this dramatically. Me, I'm not so sure I care. There's an Apple ad that pokes fun of the "it has none of the problems Vista had...it has none of the problems XP had...it has none of the problems Windows 2000 had..." There comes a point where I just don't care anymore. When the track record goes this far down, when the experience just fails so hard and far, when I've switched to another platform altogether and found it to be a huge improvement to my ulcers...

I. Just. Don't. Care.

Pay me to try Windows 7, and I might try it. If not then I'll wait until I absolutely need to deal with a new set of headaches.

Tuesday, November 3, 2009

Security ID: NewSID is Retired?!

Mark Russinovich had this interesting blog article. He retired the NewSID utility.

If you didn't know, the NewSID utility was part of the Sysinternals suite of free Windows tools and was used to change the Security ID used on Windows NT based systems. The article explains more, but basically the SID identified certain accounts on the computer (the names associated with them are a friendly format for people to read, the SID was the machine version that actually mattered, similar to the userid in Unix systems mapping 0 to Root; anyone with userid 0 was considered Root).

Mark is a guru in the Windows world; he wrote NewSID, so when he posts his explanation that basically the SID is useless and doesn't need to be changed then questioning him is like questioning the Bible. It just isn't done.

The weird part is that I've had systems at work that acted very very strange on the Active Directory domain if it had a SID that matched another machine. Use NewSID, and suddenly issues went away. Coincidence?

Hmm...

Saturday, October 31, 2009

Conficker Hits the 7 Million Mark (and Computer Immune Systems)

Wow...Conficker has hit the 7 million infection mark. A year after being discovered a security firm now estimates that it has infected 7 million computers.

Most system administrators aren't too surprised at this. Anyone running a system connected to the Internet with just about any kind of server sees hits in their logs from systems that are infected with various worms, many of which are years old and patched back in the days of Windows 2000.

Conficker was a nasty but discoverable infection because in larger businesses and school there are often security measures in place to stop users from brute-forcing account passwords; this would mean that you would try to break into bob's account by using his username and guessing his password. Sit there long enough trying either random passwords (bobpassword, god, mypassword,...) or every iteration of the alphabet (a, aa, aaa,...abb, abc, abd,...) that eventually you get the password. Most corporations place a limit on the number of times you can screw up your password before the account is locked out and the user must call their IT department to reset it.

One method of spreading used by Conficker is to try random accounts and then fire away with a password brute-force attack, so then the school, business, or government agency suddenly finds most of their users locked out of their computer accounts. Of course this is a gross simplification; the Wikipedia article linked at the beginning of the post goes into detail on how this works and what variants used these methods.

So how is it that a worm, with known signatures, with known patches, with antivirus vendors and microsoft itself knowing how to remove it with its own malicious software removal tool, is still so virulent in the wild?

Several reasons are possible. One is that many of the infections are coming from pirated copies of Windows in use out there that are locked out of getting Windows Updates from Microsoft. Pirates don't tend to care about how their behavior affects other users out there, as long as they get their free fix of software to run their favorite software titles.

Another is that users are simply ignorant of keeping their systems updated. Despite the efforts to automate Windows Updates and make users pay attention to updating their systems, I still run into systems that are running old and outdated software, like the recent case where I had a system in our corporate lan configured by an outside agency that was running a "release candidate" (read: beta) of Service Pack 3, and after remedying that the PC was slammed with waiting post-SP3 updates. Home users are worse; they usually turn off their computers when not in use, so updates cannot be run overnight as they're usually automated to do (or run automated antivirus checks as many of those are defaulted to do), or dialup users turn off their connection to the Internet so updates can't be run.

Even when automated there are plenty of cases I run into where bugs and glitches with Microsoft's own updates end up breaking Windows Update, or installing update C means needing updates A and B installed first and often I've had Windows say it's done with Update A until it's rebooted...then it starts downloading update B, while the user thought he was completely up to speed with fixes.

In other words a home user needs to be diligent in keeping his system up to date and monitoring it for odd behavior. Most aren't. They expect their computer to be like a car or TV; an appliance that doesn't need any updating unless it directly affects them, such as not running the latest video game until they install a new driver. Since they're not interested in learning about how to be responsible with their computer in order to use it they write off such things as "I'm not a computer person" (which still doesn't stop them from using it).

Meanwhile these home users and ignorant corporate IT departments that don't maintain their systems are busy slamming other people on the Internet with their infected systems. It doesn't bother them that worms like Conficker are designed to take remote control of their computer for attacking other targets on the networks (such as launching a denial of service attack against a business) or stealing your personal banking information. As long as they can surf the web and read their email and play video games, they're happy.


Until computers gain some ability to use a self-protection system akin to an immune system, invisible to the user, and not requiring (or at least necessitating) online updates in order to heal, people will continue to blithely spread years-old worms and viruses. A sad state of affairs that is yet another reason I hesitate recommending any involvement in an IT-centered career at this point to new people (many of whom, I've found, also are spreading computer viruses through the same self-centered attitudes towards using their computers).

Wednesday, October 28, 2009

The Abomination that is Windows Vista

I recently had cause to work on a system that another department had ordered a few years ago with Windows Vista Home Basic on it.

It reminded me all over again of all the things I hate so passionately about Windows Vista.

I recently blogged about my trials and tribulations involving the fact that there's no default administrator account while I had to reset the password for the default administrative user on the system in question. It was irritating, but followed the trend of other operating systems; "hide the administrative user behind another layer so people who don't think before hitting Enter will have another hurdle to cross before destroying their system."

The more I worked with this computer, though, the more agitated I became. The computer wasn't really a slouch. It was a core 2 duo with a gig of RAM. Yet I booted it, it would pop up with a welcome screen. Log in. Goes black. Comes back up. Flickers back out. Comes back up. I think at a couple points in the troubleshooting I turned off the computer accidentally, thinking that it had crashed when it went black for more than ten seconds.

My first computer ran DOS and Windows 3.1 on a 486SX-25 processor and 4 meg of RAM. That system even ran a beta of Windows 95. 4 meg of RAM. The is like comparing an 86' Chevy to the starship Enterprise. And Vista was killing it.

I had to reboot it several times over the course of upgrades. The upgrade mechanism was infuriating. There was very little feedback; it would sit at the prompt that it was checking for upgrades at 0% for ten or fifteen minutes at a time. When I thought it had crashed, it suddenly jumped to 40% complete.

Other times it would come up and say I had 4 optional addons (after several rounds of updates completed). Done? Nope. I clicked "check for updates" (again) and it suddenly found another couple of updates waiting.

I was even more agitated earlier when it installed a whole group of updates...twenty or thirty...then I attempted to install Internet Explorer 8. It wouldn't. The install program would just "disappear", no warning, no nothing. I downloaded it four or five times.

I broke down and downloaded the standalone installer to another folder and ran it from there. It failed, this time leaving a link on the desktop with a potential fix. Between that and checking my trusty friend Google, I was told to check Windows Updates first. Then there was a little note saying that Vista with SP1 didn't need this, and IE8 would install fine with Service Pack 1 installed.

No...service...pack...one?

I went to Microsoft's site and downloaded a FOUR HUNDRED MEGABYTE service pack. And installed it.

Then installed IE 8.

You can rightly assume there were three or four reboots involved.

And I nearly screamed when it said there was another 200 megabytes of updates waiting for me after those were installed.

I had to attempt to install those updates about four times. Each time, some installed, others failed due to some vague error. A reboot and retry would yield a little more progress.

You can rightly assume that I was getting more and more agitated at this.

After all these updates, Windows Updates decided that there was a service pack 2 waiting for me.

If you didn't know, most service packs roll previous fixes right in. So if you install service pack 2, you already have all the fixes that came before it. That way you don't have to install service pack 1then 2. You install 2 and get all the fixes since the operating system was released up to that point.

I was incensed and furious. What kind of braindead monkey designed this update system?

All this time I was working on getting the antivirus working. In the corporation we use Vexira antivirus from Command Central. It's not my favorite.

Vista doesn't seem to love it either. I right click on the tray icon and tell it to update itself. The update console doesn't come up. Instead some "interactive service dialog" pops up. Click it, and it takes me to some kind of privileged desktop that hides the things I was actually working on so I can see the antivirus update console.

With a heavy sigh I told it to start updating. It dutifully began downloading a new version of the antivirus. The computer sat for about a minute.

And went dark.

Another "flicker out"? WTF?

I moved the mouse and the login screen pops up. It said my administrative user was "already logged in", but...huh?

I couldn't find any way to shut that off. Unless I keep moving the mouse while in that "interactive desktop", the @#% thing would drop me to the login prompt after a minute or two.

This didn't happen at the regular desktop. Couldn't find a setting to stop this from happening in power settings or desktop settings or the user account.

I would have checked the local user policies, but because of Microsoft's crappy ranking system of their operating systems they don't include the policy editor with their home edition of Vista. Same operating system as their "business" operating system, but artificially crippled by cutting out utilities that could actually help the users in need of troubleshooting...another reason I moved to Linux in the first place. If your system couldn't act as a server it's because the hardware or software couldn't handle it, not because of someone's idea of a fair market or sales policy found posted in their colon or some other artificial limitation in the software.

Supposedly Windows 7 fixes a lot of the usability snafus and glitches. I hear lots of praises for it. The problem is, I don't care. I've had enough frustrations with Windows. I've spent years finding workarounds to various glitches in Windows 2000, then XP, and now I'm expected to leap again with Windows 7.

I'll do it because eventually I'll have to. But I can't enjoy it anymore. I used to be enamored by technology; I loved jumping into the theory behind multitasking operating systems and handles and filesystems. I used to devour articles in Byte magazine that compared various operating systems and how they worked and compared to each other in architecture. I think I still have magazines in storage that had information on the great OS/2 vs. NT debates.

But today it's no longer a question that interests me. The arguments don't focus on usability or architecture so much as how much the OS can be dumbed down for users; the Vista control panel tries to communicate in plain English concepts that for tech people would be much better served with straightforward checkboxes and text boxes for values. I don't need handholding and friendly web-like links asking if I'd like to change my password, thank you.

There aren't any companies really trying to innovate in operating systems. There are three; Apple's OS X, Microsoft's Windows, and Linux. That's it.

There is a convergence in features and eye candy that suck up resources like crazy. I remember my old computer was perfectly adequate for my tasks. Today you couldn't even get a common OS distribution to boot on a system with those specs.

I've played with BeOS, AmigaOS, Linux, MacOS, OS X, DOS (MS, IBM, Novell), Windows from 3.0 to 98 (we don't speak of ME), NT from 3.1 to Vista, Netware, and several small and hobby OS's like QNX and ReactOS and others too small to name here. Today most of the projects are gone. Except, of course, for Windows, Linux, and OS X.

Vista was a reminder of what I hated about this trend. Technology is exciting today with new devices; the Kindle. The Nook. The iPod and iPhone. The web. Operating systems are so bland and commodity that they're not really even worth looking at anymore.

When operating systems frustrated me before it was because of my own limitations and lack of knowledge. I had to expand my understanding of how the system worked in order to bend it to my will. Today the frustration is being designed into the operating system. "Are you sure you want to run this?" "Do you really want this program to run?"

Or all the times I'm searching for a function that disappeared from the previous version of Windows. It's infuriating when I know what I'm looking to do and can't because I have to interpret the "natural language" version of the interface.

Or I have to click to open the C: drive, then confirm that yes I want to see this files, then click on Program Files, and again confirm that I wanted to see the contents of the folder.

At that point I really can't help but re-examine my job duties. It's one thing when I can't get something to work because I'm lacking information. Learn more about LDAP. Learn more about TCP/IP. Learn about priorities and file handles and applications to monitor I/O. Read read read. But to have an operating system act like it knows more than I do, and actively get into my way when I'm trying to configure it or set something up?

I'm tired of it.

And now Microsoft is promising, just as they did with Vista, that Windows 7 is better than anything they've released before.

Yeah, right. I'm going to go back to my corner and browse the web with my iPod.

Tuesday, October 27, 2009

Windows XP SP3 v. 3264 (Or, "The pre-release version of Remote Desktop Connection has expired...")

Here was an interesting problem today.

I was working on an "import" for a client. By import, I mean this computer technically belonged to another agency that is working within our network because of a leasing arrangement; we didn't set up the machine, but it was on our domain, authenticated to our domain servers, and ran some software we run because it's expected that we babysit the system and maintain it while on our property, but the computer itself isn't owned by us. Clear as mud?

The machine itself was somewhat decent. One of those budget E-Machines, 2.x Ghz with a gig of RAM. Decent enough for most users online chores, running Windows XP. I was annoyed at it since it won't run X on a RIP Linux CD (just keeps stuttering to the command prompt, and xsetup doesn't seem to like the video chipset).

The user ended up needing a home directory set up so they'd not be tranferring a 400 meg profile with them (who's the genius at MS that designed it so that "my documents" was part of the profile? If a home directory is defined, why not make it *automatically* point to that location instead of forcing admins to hack away at settings to redirect it? Stupid stupid stupid...)

No problem. Just open up the RDP client...start,...programs...accessories...click on the client. Voila! What the hell?

"The pre-release version of Remote Desktop Connection has expired. To download teh full version of Remote Desktop Connection, go to Windows Update or contact your system administrator."

Um...okay. Run Windows Update. Nope...no update available there.

Wait, did it say pre-release? I checked the version of Windows. It was Windows XP Pro SP3 v. 3264. I did a double take at that...what's the v. 3264?

Google. It's running a release candidate for service pack 3? Who's the chucklehead that did that? And inflicted it on a technology illiterate user? These are wedgie-deserving offences. Worse, if this draws into a problem where I'm going to go all Hulk on someone.

Google for a fix to the terminal issue. @#%...replace  a couple files under Windows' System32 directory. Didn't work. Replace two .mui files under en-us in the system32 directory. Still no joy.

Weird...

I pulled a copy of the ginormous service pack off our network share and run the setup. Goody. Takes forever, but it actually ran without complaint, and in the process fixed the RDP client. Know what else it fixed? A small flood of back hotfixes and security updates labelled for service-pack-3-no-freakin'-RC-version.

I don't know if the company behind those Walmart special E-machines installed a @#$% release candidate service pack or if their "tech person" did it, but anyone that installs a BETA of a SERVICE PACK on a user's system that is then turned out into the world to fend for themselves should be stabbed with shards from broken DVD's.

If you encounter that weirdo message about the RDP client expiring, try reinstalling SP3. The full version. Not some crippled beta.

Monday, October 26, 2009

Windows Vista and the Administrator

Well, I'm typing this on the eve of Windows 7's release and by the time you read it it will have been out for a month. Nearly.

It's being hailed as the next big thing, perhaps even big enough to erase that abomination that was Windows Vista.

I had occasion recently to have to work on a laptop running Vista Home. Most of the systems where I work are still running Windows XP for two reasons; it works (relatively) well on the cruddy hardware we have, and it is nowhere near as infuriating as Windows Vista.

My task was to clear a password for an administrative user on the laptop because the admin password had been lost.

Believe it or not, this is normally ridiculously simple. I boot with my trust RIP Linux CD, mount the hard disk, and then run chntpw to wipe the password. Reboot to Windows, log in. Done this hundreds of times with XP and have had no problems. Easy peasy.

Given that Vista is largely XP with more hassles layered on...well, okay, given that Vista is still the same basic code base as XP, it still uses the SAM portion of the registry to save password data. Shouldn't be any issue with wiping the password.

I booted, mounted the drive, checked for a /mnt/sda3/windows/system32/config/SAM file, and ran chntpw. Rebooted.

Um...where's the administrator?

Turns out...THERE ISN'T ONE! Surprise! On me!

By default the administrator account is turned off. Instead there's an administrative user account used by the system. Otherwise you have to go and enable it on Vista Home using a boot disk and command prompt. Check it out here.

So apparently I cleared a password for a user that doesn't work. @#$%

I was irritated. This was one of the few constants I have counted on in my administrative duties, having an administrator account available. Systems fall off the domain, systems have issues that necessitate a login to the local machine, now it doesn't work quite right.

I shouldn't be quite so irritated. Many Linux distros have started moving away from having the root user enabled, forcing you to instead use sudo to gain privileges. Ubuntu does it and OS X does it, both of which I use constantly.

I guess my main peeve is that those are systems I use. I know them. I generally can find my way around under the hood. When your job means having a system dumped on you with no back history available and the directive to get it working, though, this adds another layer of frustration since now I have to figure out another piece of the puzzle just to log into the damn thing.

It goes back to usability. One of the strengths of the Mac was that Apple was the most anal retentive companies about how their system appears and how your application looks and behaves. If you ask the user what word is in the upper left corner, it's going to be the active application. In Windows you have to guide the user ever so gently into figuring out which menu bar is highlighted to figure out the current window that is active. Menus may or may not follow the same order (you can imagine the calls and hair loss after Office 2007 was released with their wonderful redesigned ribbon bar for a menu...)

The ability to have a quick and easy way to log in was something I took for granted. No matter which head twitch configured the system or what knob had screwed it up, I could use administrator on the local machine to log in. No more.

I read that windows 7 continued the new tradition. Just another reason to want to cry some days in the tech pits, I suppose. It would be different if more people were knowledgeable about the tools they're misusing, but such is life.

In case you're curious, which you might not be, I did get into that system. I figured out which user from the menu was the admin user and then booted back to rip, and this time used chntpw with the -u parameter to specify the username whose password I wanted to erase. Voila. Worked.

*sigh*

Friday, September 11, 2009

What Is That Program Doing? Or, Why Is This System Using So Much Memory!?

First, let's get a quick concept out of the way. When dealing with computers, new sysadmins have to understand that when it comes to a system compromise (a computer gets hacked), the system cannot be trusted. It's like asking a person to objectively assess their mental state; when you ask a person's brain to evaluate itself, it's going to be biased and distorted. Similarly, when a person cracks a computer system, they can alter the programs and filesystem so that if you run utilities to show network connections, running programs, etc., the altered files will hide the unauthorized activity.

Pretty simple, yeah?

So how do you see unauthorized activity? If your computer was hacked and is now sending spam email...which is network activity...but if you run utilities everything is showing up as normal (because the altered files are hiding the unauthorized network activity), the computer can hide what's going on, but a second system on the network that is monitoring network activity will see all the activity. In other words, your hacked computer may have its fingers in its ears yelling, "LA LA LA LA LA" but a third party system will still see what that computer is doing.

You add a layer of abstraction to watch what's going on, and in the process you can learn a bit about what is actually going on with your computer.

Now...the topic of of the post.

I have been working with a technology called virtualization for some projects at work. It's really great stuff...it lets you create computers that exist only in software, letting you install and configure multiple computers that run on just one system. Schizophrenic, but very very handy for people like me that have to run print servers, web servers, and file sharing servers in an organization among other things because I can consolidate those systems onto one or two actual physical systems (with tons of RAM and disk space).

In the process of running tests to migrate some of our physical systems to virtual software systems we moved a printer server. This is a Windows computer whose entire job on our network is to spool print jobs and dole them out to our many many printers scattered around several buildings. Not uncommon in businesses to have printer servers configured in their network for easier management.

Normally we'd think that this isn't a huge task, either. Most of the time a server like this would sit largely unused; I mean, it just sits waiting for someone to send a print job, render it then send it to the appropriate printer. It's not crunching numbers to predict the weather.

"But Barry," you ask, "What does this have to do with hackers and second computers to watch what a system is doing?" Glad you asked. See, when you run a full-on virtual server system...in this case what's called a type 1 hypervisor...you get an abstracted view of a computer; memory use, disk use, network use...and so you can get a quick overview of what the computer is doing that ordinarily you wouldn't get to see with a physical computer.

What I saw was that out of (more than five, fewer than ten systems) on our virtualization server the printer server was taking up nearly 800 meg of memory and shooting between first and second place for CPU usage and network usage, depending on what the other systems virtualized on the testbed were doing at that point. What in blazes is it doing?

I logged into the machine and ran a wonderful tool from the sysinternals suite called Process Explorer (free download...I highly recommend the sysinternals suite of software to ANY system administrator or troubleshooter). From there I could monitor process (program) names, the command line from which they were running, memory and CPU usage, etc.

I found a couple things of note. First, the converter program I used to automagically convert the physical machine to a virtual machine runs a service that carries a large footprint of memory; now that the system was virtual, the converter program isn't needed. So I removed that program from add/remove programs and memory use for that virtual image dropped over 100 megabytes.

Second, the computer is running a database program as well as a Bash shell spawning Java. Huh?

In case you didn't know, Bash is a shell program that runs normally under a Unix system (like Linux), not Windows.

Process Explorer told me that both the database and the Bash shell (and in turn the Java system) was tied to a Dell utility tied to Openmanage. Many mental scars remind me that OpenManage is a set of utilities made by Dell for managing their servers...usually it has functions for things like monitoring fans and CPU temps, rebuilding RAID arrays, etc. etc...generally a headache to sort everything out and get working in the proper combination for your system. At least, that's my experience with it.

So I go into add/remove programs to remove the OpenManage software, since now that the system is virtual there really wasn't any Dell hardware for it to manage.

Surprise! I was wrong. Apparently at some point someone installed an OpenManage component for managing printers! It wasn't small either. In the add/remove programs there was a listing for "Dell Printer Software" and for "OpenManage Printer Manager", each of which was taking 1.6 gigabytes in storage space on the hard disk. Each. Not both together.

But since some departments wanted Dell multifunction printers on the network and I didn't install it I don't know if these software packages are something that are needed so I can't really just tear through and uninstall those programs without dealing with the possibility of Nasty Consequences(tm).

Apparently Dell tries to cut some corners to make their software more portable between Linux and Windows by using Java (I'm speculating since I'm not too thrilled with OpenManage software, so I don't install it on my Linux systems on Dell hardware). Part of their software workflow involves using a program called Cygwin to do something with logging or some management task; Cygwin is a port of Unix utilities to run on Windows (that's why I saw Bash running). You can run tools like Secure Shell or awk or sed or ls...many many many scripting and administration utilities...on Windows that normally you'd only see on Linux. Process Explorer popped up lines in the process list as some of these scheduled tasks were periodically popping up thn disappearing, no doubt adding to the memory and resource use of the virtual machine. To be clear, Cygwin has it's place and I think it's great when properly used. I've also seen it installed on systems that suddenly start spiking CPU usage because of one of the programs using Cygwin libraries (in that case, SSHD running on Windows as a service).

What lessons can we learn from this little educational field trip?
  • Generic is good. Addon software is bad. Backed up by anecdotes on the StackOverflow podcast, that CD that came with your camera/printer/device should not be installed unless you have no other choice but to use it to get the device to work. Many modern operating systems include drivers to work various media devices, or for devices like HP printers, you often can go right to the website and download just the driver, without all the addon crap that will bog down your computer with extra programs that you don't need (or know what they're really doing).
  • Virtualization can give you tools that will both teach you about using your system and open your eyes to some things your computer(s) may be doing in the background without your knowledge. There's no reason that a printer server should be sucking down resources like this one was except that it had some poorly optimized software installed that it probably doesn't need.
  • Third party utilities like the Sysinternals Suite can help you track down oddball activity on your system (or insights on how things work) for free. There are tools that tell you what's connected to the system over the network, which program is writing and reading the hard disk, which program is hitting what part of the registry, and many other useful tools. Try it out if you run Windows.
  • Audit your system once in awhile to see what's actually installed and what it's doing. If it's not needed, free up the drive space by uninstalling that program. Use Google to figure out what the programs are. Part of what contributes to your computer slowing down over time is having programs running in the background that take up space in memory and access the network and you probably don't need them. Become familiar with your system and it can help save you aggravation down the road...also it'll help you later on when you notice something that should not be in that process list running, so you can tell when something is out of the ordinary on your computer. Process Explorer even includes tools for you to Google process names from a menu, making it even easier to learn about what your system is doing!
Windows isn't the only platform to suffer from bloated, inefficient and/or poorly designed software, but since Windows has the majority of users who are non-technical in interest and nature it is the platform with developers who get away with creating shovelware much more often. Fight it by not using it. I'm not referring specifically to Windows, although I encourage not using that too...but rather don't use the bloated crap that comes as trinkets and addons that only serve to bog down your computer. Don't install software from CD's that came with your new tech toys unless you must; try plugging it into the computer first to see if Windows or Linux or the Mac recognizes the hardware and installs the necessary drivers for you first. Then you're using native tools and not someone else's idea of how you should use their tools (and sometimes screw up your system in the process). Check your computer and screen it for odd behavior and find out what those processes in the background of your system are doing so you can get rid of software that is slowing your computer without justified cause.

Anyone have any stories they'd like to share?

Friday, August 21, 2009

Windows 2008: I Hate You

I recently had the joy of installing Windows 2008 Server at work in preparation to migrate an older server application to it. I put off moving to or using the latest versions of Windows because I read of many of the headaches for sysadmins that lay in store (in case you want to relate a little, ever use Vista? Well, 2008 is Vista with server capabilities, and a few consumer interface items stripped out...but keeping most of the security problems).

In my two days using it, I ran into this short list of things that truly annoyed the bejebus out of me.

I ran a chkdsk (check disk) on the drives to repair any potential damage after a power outage that outlasted the UPS (I know, what were the odds?). Ordinarily, you run chkdsk at bootup, you can check the results by looking in the logs for messages from WinLogon. I searched for five minutes through the list without finding it...because now it was under something called WinInit. In a way this was funny, since I wondered "Wininit gonna work right for a change??"...say it out loud if you don't get it.
Almost every site, including Windows Updates, including innocuous sites that I've visited for years, including common sites for additional software...required me to add it to a "trusted sites" list. Sometimes it wouldn't even tell me it needed it, some redirect or addon simply wouldn't work. It's an additional step that I don't need when I'm under pressure to get the server working and get things configured.
VNC doesn't work. It's a neat program from www.realvnc.com (which has a free edition) that allows you to remotely view and control your desktop console. It's a convenient way to get to the console, whoever's logged in...we often use it for remote troubleshooting. It has its own password mechanism so it's not reliant on the password for a particular Windows user. "But Barry, why use that when you can use Remote Desktop? You get two client licenses included!"-easy. If Administrator is logged into the console downloading something, and then I RDP in and log in administrator, due to idiot licensing restrictions my login will kill the other session. So if something is being worked on at the same time...poof! Gone. VNC just brings up the remote console because it's remote control, not remote access. Anyway, VNC comes up with an error that Windows won't allow it to run because it's an interactive process. Nice. Really nice.
They changed the Management Console. I used to be able to right click on "my computer", go to manage, then from the top of the tree right click on the "local computer" and from there enter the address of another Windows system on our network so I could view services, system logs, etc...well, no more! Windows 2008 uses the "Server Management Console". And I can't connect to other systems from it! How handy is that?! Well, it's not. Thanks to some other people who were annoyed at this they already solved the problem...I just created a batch file on the desktop that contains the line, "start compmgmt.msc", launching the old fashioned management console from which I can actually manage other systems.
The system logs on the server like logging a message about licenses being validated by WinLogon. Um...who or what is it validating against? Why...? I'm always a bit skittish about software "phoning home". We are using a server, with potentially sensitive data on it. Maybe it's just validating against something on itself, maybe to one of our Active Directory servers, I don't know. But it's annoying me.
Creating a share seems to get more of a burden with each release of Windows. I had to use a wizard now to create a simple share; Wizards are supposed to be a good idea for helping new users with tasks that may be unfamiliar. But wow..."provision share"? I wasn't sure what it wanted me to do with that at first. The familiar route...right click the folder I want to share and select sharing...now takes you to a mini-wizard that would not let me change the name of the share, which I needed to do. I believe I ended up going through a submenu in the server manager to create the share I wanted...through a bigger wizard. All I would like is to right click the folder, have a list of tabbed options, and go from there. Why is that so !@#% difficult? This is Windows Server, sharing is a very basic and common task for server admins. Why must it be a topic for a wizard, without a choice to not suffer through a @#$$ wizard interface? Or worse, an inconsistent interface, since there is more than one wizard to go through for sharing?

Maybe these are just initial impressions and I have to adjust to it. But my first impression was that it was a pain in the arse. VNC didn't work on it. Security notifications keep popping up, even for Windows Update! And common tasks have to be relearned. This is progress? You must seriously have to love the Microsoft Kool-Aid to embrace newer versions of Windows. I find it to be an giant pain to deal with...

Anyone else have similar experiences? Or reasons I should love this version of Windows? Please?

Tuesday, August 18, 2009

Windows Security Identifiers

This is another edition of Fun With System Administration.

Of course, by "fun" I mean I want to choke myself with a SATA cable.

See, much of my day job involves interacting with Windows systems, and there is never any shortage of reasons for me to pull my hair out.

The latest issue involves the Security ID, or SID. See, Windows, unlike Linux, identifies users and machines with a really long string of numbers and letter called the SID. Even though you might have a friendly username (like, say, your name...) when you go to use the computer in the background Windows knows you by a really long string of numbers. Your human-readable name is an alias of sorts.

Remember, I said users and machines have a unique ID associated with them.

The problem is that we have situations where we have to clone machines to go out to different offices. We take a machine out of a batch of identical systems; we install Windows, configure special software options and printers and various drivers, then we create an image of that machine that we then can copy down to all the other machines in hopes of saving time not having to remember every Windows and Office update and special software package.

Part of that procedure involves running NewSID, a free utility that will change the name of the computer and the SID so the machine gets a unique ID associated with it.

In the Wikipedia article it said:
Now the truth is that when the computers are joined into a domain (Active Directory or NT domain for instance), each computer has a unique Domain SID which is recomputed each time a computer enters a domain. Thus there are usually no real problems with Duplicated SIDs when the computers are members of a domain, especially if local user accounts are not used. If local user accounts are used, there is a potential security issue that is the same as the one described above when the computers are members of a Workgroup but that affects only the files and resources protected by local users, not by domain users.

Now...our users are on a domain! Maybe we don't have to worry about it!

I made note of it and had cloned several machines before remembering to actually test it. The latest NewSID will tell you the current SID for the machine; I looked at two systems on the domain and they both matched. Joining the Active Directory domain doesn't alter the machine's identifier as I thought.

Apparently the Access Control List that controls file ownership and such is associated with the user's SID, and in theory there shouldn't be an issue with this. But on reflection I didn't want to risk it.

Nuts.

So it was my own fault for not testing more thoroughly but it is one more reason to hate Windows...Linux doesn't use machine-specific ID's on the network outside of their name. Windows lets you change names but hides the fact that the name is just a superficial shell over a long string of gibberish (okay, it actually means something as the article tells you, but still...) and it's that string of gibberish that is actually significant; plus you need a special tool to alter it.

Another annoyance with Windows...it doesn't include the tool to alter these sort of fundamental parts of the operating system that can cause problems. You can get NewSID for free but it was actually a third party tool written by Mark Russinovich, hired by Microsoft after he released a lot of useful tools for Windows.

The lessons to be learned?

  1. Don't assume. Test. Even if it takes more time which results in becoming less popular with your boss because you're taking that extra time...because it's going to save you the time it takes to fix your time-saving shortcut.
  2. With Windows, even though you'd think changing names and ID's and such would make the machine unique on the network, it might not. There are underlying functions that Microsoft actually had the brains to abstract away from the users since they didn't need to know about it...only they didn't put any obvious ways to check on or monitor those abstracted functions until it's too late and you have a new mess to try fixing.
  3. Don't assume that just because there's some fundamental part of Windows that needs administration you'll have the tools included to fix those fundamental parts. Find a tool and save it somewhere that you can access that tool later on.
  4. Windows is a major pain in the rear.
I think that pretty much covers it...

Sunday, June 21, 2009

Microsoft's PC Ads

I know this has been known for awhile in the blogosphere (or people with common sense) but I was thinking about it because I saw the ad campaign on TV again.

You may have seen it...some doofus off the street, a real Jane Average Consumer only this time she's named Lauren, is given a little over a thousand bucks and told that if she can find a system with a particular set of specs for that amount or less she can keep the computer. It's like winning the lotto!

Lauren goes to the Apple store and immediately heads back out to report to the camera that there's nothing within that price range that is near those specifications. "I guess I'm not cool enough to be a Mac person." Ooh, SLAM!

She ends up buying a wonderful WINDOWS computer from someplace...Best Buy, maybe? Woo hoo! Jackpot!

One problem. She never went into the Apple store. The proof is in the still shots captured from the advertisement.

C'mon. How can you screw up staging something so simple? Really. How dim do you have to be to screw up something like that?

Quick business tip. When you're dealing with the subject matter of technology, even if your target audience is meant to be the average computer-ignorant consumer, don't skimp on the details because geeks will call you out on it. Then they'll advertise it in the same Webbertubes that your average computer-ignorant consumer in the market for a computer may run across the information.

Know your audience as well as your potential audience.

And don't mess with geeks.

Thursday, June 11, 2009

Beware Internet Explorer 8

Any major update should be approached with trepidation...but according to this site, there are some issues that can render your system inoperable if you go through with the update to Internet Explorer 8 from Internet Explorer 7.

Have a backup handy first!

He has a link to a tool that his friend at the computer repair shop has used to revert back to IE7, but when I went to the site to grab a copy of the utility I got an error that the user had hit his download limit on that host...

The problem as his friend described it: users upgrade to IE 8 and on reboot you have nothing but wallpaper showing. No icons, nothing usable even in safe mode. He said that he had to use a bootable utility to revert to a restore point, at which point the machine would boot but have USB problems and no ability to connect to the Internet.

The utility rolled back the machine to IE6, and on two of the three machine upgrading again to IE7 worked as expected while that third machine still had USB problems so he had to roll it back down to IE6 until another fix can be found.

Ouch.

Just a bit of warning, that's all. Not too surprising since Internet Explorer has tentacles extending so far into the operating system that when it gets screwed up your whole system can be screwed up (or made vulnerable to malicious attacks)...another reason to use Firefox. Firefox is not tightly integrated with your system so if it gets screwed up then typically it's just your web browser, not your entire operating system, that gets hosed. For me it's nice that it's cross-platform, too. I use Windows, Linux, and OS X and Firefox is available on each of those platforms.

Wednesday, June 10, 2009

Antivirus Design and Usability

Developers of software tend to be surprisingly out of touch with users. Even technical ones like me get thrown for a loop sometimes.

Set aside the problems I have with antivirus in general...eat up resources, give users false sense of security, are a band-aid and not a fix (although users feel otherwise)...and there's still one area that some AV software falls short in but could fix. Just being "user friendly".

I just had a user contact us about a message of a virus on her computer. I checked on her system and sure enough, the software we're using for virus protection had a window popped up saying she had "JS.shellcode.AD" infecting her system.

The name tells me that it was most likely a browse-by attack of javascript downloaded to her cache. In other words, probably minor...antivirus software likes to make the littlest things appear on par with nuclear disaster, probably because it helps justify cost from their users in keeping a subscription renewed. But again that's part of another issue.

My problem was that this notification window told me, quote,
"Killing Method: Not Removed."

Huh? Is that like saying you killed a bug by letting it run away?

"File Access: denied."

Does that mean the antivirus was denied access, or the AV software is denying the user access to protect them?

"Proposed method: open file"

Are you suggesting it to me as an action to take? Or are you telling me what the user was trying to do? Because as a program continuously monitoring system activity, chances are pretty good you caught the problem because the system was trying to open a file that it didn't like. I assume when reading about an accident that a car struck another car because of something stemming from driving, not because the driver was flying around and landed on the other vehicle. So why are you reporting it to me unless this was actually trying to tell me something else?

The wording just plain sucks.

I then tried finding the file in question to see if I could delete it...after all, the AV is saying that it was "Not Removed". I couldn't find it.

I tried browsing from a remote computer into the root share. Windows nowadays likes to dynamically reformat the way it presents information to the user to "protect" them. While I understand the (simple) concept of a directory and file structure and have no problem navigating to folder X in Y inside Z to find file A, Windows will hide certain folders and combine them together in Explorer. For example, your Temporary Internet files are actually a series of subfolders with names like EROF43D. When you view your temporary files in Explorer on the local machine, you see a huge list of cookies and cached files in one big list. If you pull them up on a remote computer, you can actually navigate into individual cache directories with goofy names to find what the machine is actually seeing (or if you boot with a Linux boot disk you can actually navigate the folders the way they really are).

I hate Windows hiding this crap.

OS X's Finder does something similar to make the disk more "user friendly".

Anyway, browsed to that location. The file wasn't there.

Huh?

Is it quarantined? Sometimes AV software will take a file it can't "fix" and put it into a "protected" folder, so you don't access it again but can, theoretically, restore it if it was a false positive. But the error the AV popped up with and the log in the program didn't say anything about moving or quarantining the file.

ARGH!

In the course of repairing a second "virus infected" system here, I copied some tools from the Sysinternals Suite (free! Wonderful tools for sysadmins!) from a network share to the local system to help with some diagnosis. That same antivirus programmed deemed one of the applications to be a threat. And deleted it.

I tried copying remotely over to that system. The AV deleted it.

@#$#$!@# piece of @#!

This same system on which the AV protected me so vigilantly still has problems appearing...among them Virtumondo (remember the problem with them? Or at least the suspected problem? Yup, that same system...) and was confirmed with Spybot Search and Destroy. Undetected by the antivirus. Thank you so much! It had hit one small component while leaving other parts active from registry! Yay!

What's my point? My point in this particular post, aside from the side trips into Rantville, is that I wouldn't have been quite so frustrated had the messages been clear and the ability to work on the system isn't thwarted by the interface. The antivirus started it...but Windows also has some of this built in by trying to be user-friendly with barriers to actually getting to the problems to work on it. I have to find ways to work "around" the friendliness just to get the job done!

I mean, c'mon...who thought it would be a good idea to tell you the "kill method" on an infected file is "not removed"? That's not a method. That could be an action taken, but then why can't I find the #$$% file afterwards? You obviously did something to the file in question! WHERE IS IT!?

What happens when you throw these types of obstacles in front of the users? You're being counterproductive. Like I said above, I spend time finding ways to work around these issues when in reality the developers should just fix the problems. Read this blog entry from a developer back in '05...users will find ways to make it usable even if it means simply not using your product (and in the process screwing themselves over or breaking your viciously stupid policies). It also fosters the attitude of resenting your company, your product, or your department, depending on whether you're a vendor or an IT department in charge of helping the user.

You can't make all users happy and I won't pretend you can. My problem is that I am a technically inclined person and one of the people usually called on to help sort out the issues users have when they don't want to or cannot figure out why their computer isn't working...and you're making it hard for me to work with your products. That is crossing a usability line. Would you purchase another car from a company after finding that your mechanic can't work on it or that he can work on it, but because of the way the company designed the engine it takes your mechanic an extra three or four hours (with an hourly fee to go with it) to do the job that on another brand would have taken one-third the time?

Usability testing...look into it.

Tuesday, June 9, 2009

Virus Hunt: Trojan.downloader-54811

Windows...bleh.

I had a call about a system where the user had a notebook at home and said that something popped up with the word virus on it, and whenever she opened a web browser it would just close back out.

A little vague, but that's par for the course.

I had it brought into the work area and booted the laptop with the latest version of RIP Linux (I wanted to use the network to get tools and repair information, but you should NEVER plug a system...especially a Windows system...into the network if it's suspected of being infected with something. NEVER. Booting RIP from a CD bypasses whatever is on the hard disk, mitigating the risk).

RIP has two antivirus tools available if you're connected to the network...which you'd need to be anyway to get the latest definitions...xfprot (a front end to FProt) and ClamAV. I ran both and they both only buzzed an alarm on once file hidden in c:\windows\system32 called __c00BBCE1.dat, telling me it was infected with "trojan.downloader-54811."

Well, good that only one file was triggering an alarm. The fact that it was a downloader meant it was probably something from the web browser and was some kind of hidden component of malware meant to act as a "hook" to download more malicious crap in the background of the user's system. Marvelous.

Today viruses are meant to take over your computer. Whenever a vendor of an antivirus finds a signature to combat the specific "virus" the malware author changes a few small details and re-releases the malware into the wild until the vendor finds a sample and analyzes it and comes out with a new signature then the cycle repeats. Thus seeing another "trojan.downloader" is like seeing another piece of trash along the freeway. Not a big surprise.

A Google search turned up very little, probably because different vendors classify viruses under different names and because there's just so many of them that are ever-so-slightly changed that it's rediculous. Imagine taking a copy of Huckleberry Finn and changing three words in the fifteenth paragraph of chapter 4 and having a whole new book published because of it...that's the way it is with viruses.

Since I'm scanning under Linux I opened a terminal and navigated to the file and ran the "Strings" utility on it, which, oddly enough, looks for strings of words in a file. One stuck out: a call to find the DNS address of zappoworld.com. A google search for that name yielded a hit on a blog detailing one guy's efforts to get rid of some malware apparently called "Virtumondo". He actually had two posts: one here and one here chronicling the fun he was having.

While I can't verify that he and I were fighting the same fight the description was eerily similar in what little detail I bothered gathering to this point.

I agree with his assement...he'd most likely have to reformat and reinstall to be sure the "infection" is completely gone. Once a system is compromised you don't know what it could be hiding. Most users overlook this idea and figure that it can't be that bad for them; they just want it back in a "usable" state and are happy with that. If they don't mind the idea that something is recording their emails as they type them...their passwords...etc. and then sending them over the Internet to organized crime scum in other countries periodically then I suppose that's their choice.

So if you found this post from a Google of this particular trojan downloader's name you have two choices. The first, the one I recommend, is wipe your computer and reinstall from scratch and restore your personal data from a backup. Hopefully a backup from before the infection (this is why I don't normally do system-level backups on my personal computer...I copy my *data*, my personal files and folders, and want a clean set of system files from a fresh install in case a system is infected with something wonky or gets corrupted. I'd be restoring the same problems I'm trying to solve!). The second is to start downloading the latest antivirus definitions, maybe a bootable disc or two with AV tools like RIP Linux, along with Spybot Search-and-Destroy, Adaware from Lavasoft, etc., and prepare to spend a weekend and a half searching and scanning and rebooting and erasing and lather-rinse-repeat until your computer is supposedly "clean", keeping in mind that true stealth malware will have hooks into your operating system that will cloak the processes that may even simply reinfect your system the moment you reboot.

I strongly recommend the first method. It's right up there with using a Mac instead or Linux.

Friday, May 29, 2009

I Don't Do Financial Stuff On The Computer, So Why Care About Security?

On the topic of computer security, some people are lazy, some are ignorant, some just don't care because they say they don't do anything like buying things online or saving their credit information on the computer. They don't bother with updates or educating themselves about responsible computer use.

So what do they say if they're busted for child porn?

Yeah...that's one of many uses "zombied" computers...computers that are remotely exploited by system crackers...are put to work doing. Remote storage of warez, porn and possibly child porn.

Check this article which outlines more information in simple and easy to understand terms.

If you're not willing to take responsibility for your computer use you probably shouldn't be using the computer. Even if you don't do financially sensitive activities on the Internet your computer can be used against other people.

Uh Oh...When Computers Won't Boot

Another reason to love Linux.

I was working on a system in the lab today that was having some problems with a bit of software that was working fine, now wasn't.

I ran updates on it. Checked the hard disk. The usual.

discovered that the drive was seen in Windows XP as 20 gig, but the drive was actually 40 gig. Most likely this was an artifact from the system being imaged; the partition information given to Windows made it seem like a 20 gig drive so Windows wasn't properly seeing the entire disk.

So in the course of repair I took out my RIPLinux...Recovery Is Possible, although I thought it used to be called Rescue Is Possible... CD and booted to X Windows. The disc runs entirely in memory so you can use it for a variety of diagnostic and repair procedures on systems. A wonderful tool for any tech repairing computers.

Once in X I ran gparted from the partition tools menu. This gives a graphical menu of your disks and gives options for various alterations that can be made, among them resizing the partition. Because of a glitch in the way the partitioning was done gparted saw that the drive was already set as one partition taking up the entire 40 gig. I just told it to resize the disk to slightly less than 40 gig...better than the 20 it was already set to. Best of all is that this is a non-destructive resize (I'd still advise a backup, though)...resize the partition, and the data is still intact.

Clicked Apply and the changes went off without a hitch. Rebooted, Windows started...and rebooted itself. And rebooted itself. And rebooted itself. Uh-oh.

Information was still there because Windows started to boot. I stuck in the RIPLinux CD again and booted to X. This time I ran Testdisk. This is a utility that greatly helps in searching for lost data, partitions, errors, etc. and is a boon for recovering data from drives, but any tool for playing with partitions isn't child's play. One of the basic scans popped up telling me that the geometry on the drive was set to 16 heads but looked like it should be 255. I dropped through another couple menus to reset that information, told Testdisk to write the data to the disk, and rebooted.

Windows XP booted right up for me.

Yay, Linux!

This is by far not the first time I've fixed quirky and archaic and deep-level problems with Linux boot CD's and no doubt this won't be the last. Although this was the first time that resizing a partition triggered this kind of problem. I've seen this several times from cloning and duplication errors, especially switching drive brands and types...but never resizing on the same disk that I can recall. Goes to show that every task has its own challenges, I suppose.