Tuesday, 20 May 2014

Software from the Shadows

If I were to ask you what software was installed on your computer would you be able to tell me?

It’s a simple enough question to answer you’d think – you’ve got your browser or two, probably a version of Office, some antivirus software, and maybe an account package or some games. If you install your software using standard install packages then you will find them listed in the control panel under Programs and Features. It’s always interesting to see what’s listed, and what you can identify, because when I examine a customer’s computer I’ll invariably find several programs they had no knowledge of installing and one or two really obscure ones that I have to Google for (almost always before I remove them). When I write up the job I describe this part of it as ‘removed unwanted programs’.

The question we are always asked is “how did this software get there”. And the answer is of course that you installed it. This certainly wasn't something you did intentionally but the sad fact is that a lot of the free software that we regularly install will come with a hidden payload that you will only see if you look carefully while you are installing it.

We are talking here about the fringes of the dark Internet; that borderland where what is going on certainly isn't good, but falls short of the activities of the criminal dark side. It's a confusing world where a button on a webpage may not do what you think it's going to do; where you need to be on your toes to make sure you don't click the big green ‘Start Download’ button because the one you really want is a little one above it, and it’s the sort of place that would confuse the hell out of your parents. Welcome to the world of foist-ware

At one end of the scale you've got Adobe who I seem to mention far too frequently - their default download of Adobe reader tries to foist a copy of McAfee Security Scan, which is top of our list for instant removal. Two respectable companies there, both of which should know better.

Next let's take the example of another respected name; Java. As you'll know Java will regularly prompt you for an upgrade. If you look carefully at the install screen it will have a pre-ticked box that will install the Ask toolbar and make Ask your default search provider. Apart from the fact that the Ask search engine is absolutely terrible, this resetting of your search engine without your actual permission is exactly the sort of thing that malware will do. Evil is as evil does.


Another piece of software that we regularly see installed is uTorrent, which has gone from being a well-respected bit torrent client to a bit of a whore when it comes to foist-ware. Their recent partnerships have included the Ask toolbar, another piece of borderline malware called Search Protect, and at one stage even the Bing toolbar. I mean which self-respecting user would ever knowingly install any of that tat?

There is of course a reason for all this and it comes down to the commission that is paid for deploying these nasty bits of software, but the ends shouldn’t justify the means. It reminds me a little bit of the old days of trying to book a flight with budget airline, where just as you were about to check out you noticed that the price has mysteriously changed, and on closer examination you'd spot that travel insurance had been added to your purchase.

In the name of consumer protection this sort of practice has since been stopped, but for some reason the low-life that pedal a lot of the software that we customarily remove from computers seem to think that the same rules shouldn't apply to them. Given that generally users don't want their software, didn't ask for it, and suffer in performance terms as a result of it running, I have no hesitation in calling them out as peddlers of malware.

They may claim legitimacy and threatened to sue those who attack their business model, but it seems to me that a simple code of conduct that states that software may only be installed on a computer when explicitly requested by a user, rather than by means of a pre-ticked box, would see these companies put out of business overnight. This simple change would at least allow some separation between the bad guys and the rest of us, and I've no doubt that products like Search Protect will find no place to hide if they are forced to come out of the shadows.

Thursday, 6 March 2014

How Computers are Creating a Lost Generation


This post has been a while in the making – it’s a subject I first thought about covering when Fred, one of our long standing and well liked customers started passing beyond the point of understandable confusion with the ever-changing digital world, and regressed in a few months into crippling and overwhelming dementia.

It’s a tragic thing to watch; Fred enjoyed a successful career and headed up a French property group before retiring. He had much in common with the  large number of seniors amongst our clients, many of whom came to computing late in life, but still managed to embrace it with enthusiasm. We are terribly proud of them, and I’m happy to say that usually the sequence of events isn’t as dramatic as Fred’s but I’m sure we see a side of computing that those who write code are rarely exposed to – after all that’s a young man’s world, and the last thing they are concerned about is anything that interferes with the pace of progress. I should know - I was once one of them.

These days I realise that I am now no longer part of that generation because I’ve failed the PSU test – it’s a simple metric – I can officially no longer read the power rating  labels on laptop power supplies without reading glasses, and the same goes for most of the serial codes and the badly etched lettering you find on motherboards.

Fortunately I’m still able to use my screen at native resolution, but I know from my clients that eventually I’ll be forced to step it down to be able to read it – and that’s where another set of problems start. A few weeks ago I dropped in on another of our senior clients who was unable to print PDF files. I assumed this was a user problem, but as it turned out it was actually an Adobe problem – their custom print dialog was so large that on a 640x480 screen that the bottom of the form wasn’t visible, and as this was where the OK button was the only way to print was by using the TAB button to get down to it; easy enough if you know this trick, but I’m still going to name and shame Adobe for failing to take into account the needs of poorly sighted users.


Developers love updating their software, and one the things that I’m sure contributed to Fred’s decline was when Yahoo Mail rolled out their major revamp of the widely used webmail service. Developers probably don’t give a thought about moving buttons around on a page, but they should be aware that something as simple as a relocated print button can throw older users into total confusion – they lack the good eyesight that allows them to spot the newly located button in the first place, and they don’t have the same cognitive abilities as younger users that allow them to remember where it now is even if they do find it.

In a month Microsoft’s support for XP will officially end. It’s had a good run since it’s release in 2001 (and we conveniently forget just how bad it was in the early days), but things move on. Since XP we’ve had Vista, Win7 and now Win8, so it’s a long way behind the curve. I fear, however, that this will orphan two important groups – those who cannot afford to replace their computers with newer ones, and those who are unable to adapt to a new operating system. Stop there and imagine these two groups on an intersecting Venn diagram. Do you see the huge intersection, and can you guess the demographic?

I’m not sure that the end of support means the end of XP – after such a long run I suspect that most of the vulnerabilities have been discovered and patched, so hopefully any new vulnerabilities will be minor ones. I also suspect that the technical community will step up to the mark and introduce patches if they are required, and I think this is going to be important, as I see XP being used by a select group of older users for some time to come.

I’m not the only one who hopes I’ve got it right. Susan has suffered through a series of neurological problems and suffers from frontal lobe epilepsy; her ability to cope with even the smallest change on her computer is severely reduced by the cognitive impairment caused by her injuries, and worse still, the stress of trying to cope with something as simple as a revamped web page layout can cause her to have a seizure. As her laptop is approaching the end of its life, our solution is to take a new laptop and recreate her old working environment as closely as we can. With a bit of luck she should be using XP and Office 2002 until well into the 2020’s.

It’s time that we all woke up to the dangers leaving our parents and grandparents behind – there are lots of simple things that can be done, such as extending the legacy layouts of webpages like Yahoo mail, and simple things like testing page layouts and minimum resolutions, but it’s got to start with developers, so spread the word, because if we’re lucky, one day we’ll be old too...

Wednesday, 22 January 2014

It's All Change for Remote Desktops


If you’ve been using LogMein Free you will by now have received notification that the Free part of the name is being retired at the end of this month.

It’s a sad day for many of us; I’ve been using the service to access my own PCs for years, and as a result of this experience we adopted the professional version, LogMeIn Rescue as our platform for remote support here at Computer Angels. Many of you reading this will have the tell-tale icon of a white cross on a blue background that is the Computer Angels Remote Support tool, or as we call it, the panic button.

I’m not sure how many people will opt to pay for the product now that it’s no longer free, but for those using the product for non-commercial use there are still several options out there.

My first thought was to switch to TeamViewer which is marketed as a business tool for virtual meetings and online presentations, but it also works as a remote access service. In works well on both Windows, OS X and Linux, and includes file transfer and remote printing functions. Remember however that if you’re using this for commercial use then you are breaking the licensing conditions, and the paid-for version is a whopping £439. Most of my access falls under non-commercial use, but there’s a definite grey area there, and when I started to look for alternatives I found a familiar name with a new product which I just had to check out.

Google’s Chrome Remote Desktop requires a Google account, but is totally free, including for commercial use. Installing it is straightforward, and if you have a small stable of computers that you want to access remotely then this could be the perfect solution.


First impressions are that it’s not perfect – I’ve had a few freezes and disconnects which may be to do with my using nested Virtual Machines which I’m also trying to control with the tool, but the screen clarity and resolution handling is great, and hopefully as more people move to this new service, which I'm sure will see a surge in download in the next week, then I've no doubt the Google will pile on the developer resources and fix the inevitable niggles.  I’ll let you  know how I get on with it.

Tuesday, 10 December 2013

All I Want for Christmas is to Close Skype

This morning I began writing about a subject that has been on my hit list for some time now. I’m referring to those in-your-face applications that are commonly used but have chosen to disregard the common courtesies users should expect.

The two worst offenders these days are Adobe, who have for years been obtrusively nagging us about updates, yet show no hesitation when it comes to trying to sneak Chrome and the Google toolbar onto our systems as part of the update by pre-selecting a tick box that is all too easy to miss as you work your way through the installation.

The other miscreant is Skype which seems to combine universal popularity with universal dislike with its constant version changes (each with a new layout for us to learn), and which this morning was once again asking to be upgraded.

Skype tries to sneak in Bing as my search engine and MSN my home page, which is to my mind a bit like asking me if I really want to set my system clock back to 1993.The MSN homepage is famous for its popularity, but that’s because it has for years been the default home page for Internet Explorer. In all my years of configuring computers for people I’ve never once been asked to set a homepage to MSN, and you can be sure that I unchecked that option as I upgraded Skype.

Just about then Chrome, my browser of choice, crashed and I was forced to kill it through task manager, and when I restarted it I was furious to find that my homepage was now MSN, with Bing as my default search engine. This only takes me a few seconds to change, but then I’m hardly an average user, and I know from experience that fixing this sort of minor change is beyond many of our customers’ abilities, which is when they call us.

Call me cynical but I wonder if this is Microsoft, who own Skype, trying to sabotage my installation  of Chrome, which is owned by Google? Considering that Skype is owned by the same people who wrote Windows, you would also expect Skype to play according to the rules when it comes to usability, yet it absolutely fails to do so unless you open up the bonnet and start tweaking settings to remove it from you task bar when you aren’t using it. You know it’s irritating people when it’s the subject of a Dilbert cartoon.


Another program which users complain about constantly is the McAfee Security Scan which I’m constantly having to remove from PCs – thanks again Adobe, but these days everybody already has antivirus software in place. Running two antivirus scans simultaneously will at best cripple the performance of your computer, and at worst damage system files and render your computer unbootable.

Software vendors need to show a little more respect for their users. Adobe has already created enough enemies with its punitive pricing policies which see UK users paying far more than their American cousins for the same software. Once you lose the respect of the market you become increasingly vulnerable to a challenge by competing products, and there are few people I know who would miss Adobe if this came to pass.

So here’s my Christmas request for the giants of the software industry: It’s time to start showing your customers more respect, so stop trying to trick them into installing software they haven’t asked for as part of an update, and start treating them like people who use your software because they want to, not because they have to.

A very merry Christmas to you all!

Saturday, 23 November 2013

Hammersmith and Fulham Brilliant Business Awards 2013

This month we are all sporting smart new email signatures bearing a blue and green rosette. So a huge thanks to all our customers who voted for us as H&F Brilliant Business Awards. Last year, when we won a runners-up award, I was determined to launch a well-organised campaign to ensure victory this year, but as ever events overtook us as we were at full stretch trying to get our Surbiton branch up and running, so this never happened.

I was therefore both extremely surprised and hugely proud of the efforts of my team when we were voted as the winners of the Hammersmith and Fulham Brilliant Business Awards Best Business Supporter of the Community. A big thanks to Nicki Burgess at London Borough of H&F Economic Development Learning & Skills for organising such a popular event.!

It’s hard to believe it’s taken 9 months from first finding the new  premises, but taking a business from one branch to two requires a huge amount of extra work to ensure that the infrastructure works.

Our old phone system used 3CX, which is a software based PBX, but while this would have been scalable in theory, we simply don’t have the in-house expertise to deploy and support it across two sites. I should stress that this isn’t a shortcoming on our part – our philosophy is ‘Choose what you do, and do it well’. When it comes to phones, rather than dabble ourselves we would rather work with experts who we know and trust in the form of Spitfire. Our recommended solution for small businesses is hosted PBX, so it made sense to migrate our own phone system to this platform so that we can provide fist line support to our customers based on our experience with working with it ourselves, as well as knowing what the system is capable of, which in turn means we can better advise our customers on which configurations would best meet their requirements.

Now that everything is up and running we’re all delighted; each site has its own geographical number, but shares the 0800, number which rings four times in Fulham before spilling over to Surbiton in case Fulham is busy. For internal calls we have extensions beginning with 20xx for Fulham, and 21xx for Surbiton, as well as caller display so we know who is calling. We are using dedicated SIP trunks to carry the traffic, as well VDSL (the acronym for fibre) for our data which is welcome improvement of our ADSL speeds. For any business out there that isn’t using IP telephony this is your wakeup call – ISDN is looking decidedly dated.

It’s great that we can configure pretty much anything to work the way we want it to, but the main consideration is that it no longer depends on our own server. That’s not to say our server is unreliable; although we have had our fair share of hardware issues the redundancy features mean that or downtime has been minimal, but we have to face the fact that these huge, power hungry behemoths (there are two of them, of course) are now getting old in server terms, and as we grow we are working to eliminate single points of failure – outsourcing your telephone network to a highly resilient service provider is a sensible step along this path.

We have until recently also used our servers for file and email services, as well as hosting our database, so it made sense to move our Exchange email service to the cloud at the same time – we’ve now competed our migration to the Microsoft Office 365 platform, with our next steps being to more our data to SharePoint and our database to SQL Server on Azure.

At this point we will be using our servers for storing client backups, and domain security, and that’s about all. I have to say that as the person who carries ultimate responsibility for everything working properly, this brings a certain peace of mind.

Because we work with smaller businesses we’ve always recommended avoiding the expense of running a server if you can, but the viability of Microsoft’s hosted services is such that even larger businesses can start thinking about outsourcing their email and data to the cloud to reduce their reliance on the on-site server, and we’ve seen this part of our business grow in leaps and bounds – we are just about to print up another batch of mouse mats, and for the first time in years you’ll notice that we’ve changed our list to services to include hosted services. A sign of the times.

Monday, 12 August 2013

Find me in Paradise

After a bit of a hiatus I’m back – the break was enforced by an increased workload due to both the demands of getting the new service centre open, and of getting married. Of the two the wedding was probably the least stressful as I’m now getting pretty used to planning complex operations and then having to trouble shoot on my feet.

Flying out to my honeymoon on a new Emirates Airbus A380-800 was a delight – the economy cabin is more comfortable than some business classes, but the in-flight entertainment system blew me away.  The sheer range of entertainment options meant that I had trouble sleeping despite the great seats, and the console included power outlets for laptops as well as allowing me to plug my iPhone into a USB socket (with a little bit of trepidation, as I really didn’t want to have to take over flying the plane) for a quick charge. It’s refreshing that the decrepit entertainment systems that most planes still carry are being replaced at last – the last generation are getting on for ten years old, so it’s a bit like moving from a very sluggish installation of Windows XP straight to the slick interface of Windows 8. You may laugh, but I’ve always wanted to see my house from the plane, but as I live directly under the flight path the only way to do this would be from the cockpit; on my return flight I got to use the downwards facing camera, one of three external cameras, to zero in on my very own roof as we passed overhead.

Before setting off I did a little research and downloaded a few apps to help us explore Dubai (18 hour stopover) as well as a few offline maps of the Seychelles using the excellent MapsWithMe App. This free App is simply brilliant as you can select countries and download detailed maps before you leave, and then use it without relying on a data connection. This is something you can also do with Google Maps, but in practice it’s means zooming in to the required levels of detail and then copying dozens of map tiles to cover an area, and to describe it as clunky would be to flatter it greatly.

MapsWithMe worked superbly once we arrived in the Seychelles on our island hopping holiday, but I did discover something about my Wi-Fi-only iPad which surprised me. While it worked well while I was connected to Wi-Fi, as soon as I left my hotel it would be unable to locate me on the map. While connected I did some research and found out that the iPad’s GPS module is part of the 3G board, so the Wi-Fi only iPads use Wi-Fi to locate themselves. In a city where there are plenty of Wi-Fi signals to browse this means that the device can easily position itself accurately, but out in the islands signals are few and far between, and it gets lost pretty easily.

By chance during my stay at this particular hotel the wireless router failed, and I lent a hand in diagnosing the problem. When the hotel replaced the router for a new one I was surprised that despite it using the out-of-the-box identifier of ‘Linksys’ my iPad still knew exactly where it was. This got me thinking. A router, like all network devices, has something called a MAC address which is in theory unique. So how did my iPad know that the new MAC address was located exactly at our hotel in Praslin Island? Router’s don’t have GPS receivers, and the ISP couldn't as far as I could see work out exactly where the router was either even if it were using postcode look-ups. It seemed to me that the only way it could know my position so accurately is if another device connected to the same router was telling it. This seemed a little unlikely, but it also seemed to be the only logical answer to this mystery, so now I’m back I decided to see if I was right, and after a little digging it turns out that I had hit the nail on the head. 

Simply put, as soon as an apple device with GPS identifies a wireless signal it transmits its position and the unique MAC address back to Apple who store this information in a database. So even if I want to keep my router’s location a secret and turn off Apple’s location services on my own devices, Apple can still locate the router as soon as the first iPhone without location services disabled sees my wireless signal, and to clarify, it doesn't need to connect to my router, it only needs to be able to see the station identifier.

In itself this still isn't really that sinister as lots of people know where my router is; my ISP, my neighbours, Apple… but now imagine a government wants to combine this location database with something really useful, such as a router firmware enhancement which logs and transmits all MAC codes that connect to a router to, say, the NSA, and you start asking yourself if something that useful to the NSA won’t already be out there. And if Prism has taught us anything, the answer is probably yes.

Friday, 12 April 2013

Why trusting your IT company just became a whole lot more important

When we book a computer into  our workshop we use a paper form which includes a box for the password for the computer we are going to work on. Often we may also need the password for the customer’s email account – and we’ll either hack that using a tool called Mail PassView or ask the customer for it if we need to.

I’ve never really thought about the security implications of this process as I trust my staff implicitly, however we do intentionally keep the password off the database system as it’s pretty hard to hack a piece of paper, and once we are done with the worksheet this can be either filed under lock and key, or shredded and pulped.

If the customer is concerned about their security they have the option of changing the password afterwards, but in practice I’m sure very few bother as it’s not always easy to manage, particularly now you have to change it on all your mobile devices too.

One of the big changes in Windows 8 is the reliance on a Windows Live ID, which is often associated with the customer’s main email account. The implication is that we now need the email password to do pretty much anything on the computer, including tasks such as installing Office 2013 which must be linked to a Live ID account.

Whereas before a single password would give limited access to a system, with cloud services and Windows Live ID integrating with everything, it’s a case of one password to rule them all. In many ways this is great as Microsoft have long been the champions of a single authentication for everything, but as soon as you need to give your password to a third party for essential work to be carried out this model presents a huge security risk.

What does this mean for the average Windows 8 user? Well for starters you need to be able to trust your technical support as never before, as now they get access to everything. Suddenly that shady PC repair shop on the corner with the second hand laptops and the phone unlocking sign in the window isn’t looking so attractive is it?

One of the problems with our industry is that there’s very little regulation – the organisations that claim to act as trade associations are mostly just glorified social clubs who would much rather organise another members’ golf day than actually get involved in policing their members. It’s left to organisations such as the council run Trading Standards Officers to weed out the bad boys

In some ways this is good news for us as we work to defined procedures which include DBS (previously CRB) checking our employees. We also have excellent relations with our local Trading Standards team and have assisted them in bringing some of the less reputable operations in our borough to account.

However I do sometimes feel that companies like ours are in the minority – I can count on the fingers of one hand the other companies in our sector that I’d confidently recommend. When it comes to handing over your entire on-line identity what is really needed is something like a valet key, which are commonly employed in the US where valet parking is everywhere. This is a clever little key that allows the valet to drive the car and lock the door, but not to open the boot, for example, and some even turn off the engine if  the car travels more than a short distance.

If Microsoft allowed a temporary service account password to be created that worked alongside the main Live ID this would provide an elegant solution to the problem. It could be configured to automatically expire after a set number of days, and could include features such as allowing the ‘valet’ to see email headers, but not open them to read the full content. So there in a nutshell is both the problem and a solution. Over to you Microsoft.