Thomas Lee's collection of random interesting items, views on things, mainly IT related, as well as the occasional rant
Sunday, October 26, 2003
Saturday, October 25, 2003
Packing for PDC
MVPs get source code access.
MVPs get source code access
The word is finally out. This is a fantastic idea - giving some of the folks that support the OS access to the code. There is some good news and bad news of course.First, there is a very tight NDA in place. Even so, I can only imagine how hard the MVP team at MS must have argued with the lawyers to let individuals, vs companies, to have access to the source. When MS provides source accesss to companies, the normal license calls for an unlimited liability. With individuals, e.g. MVPs, this simply would not work for obvious reasons. It will be interesting to see what happens on this front.
Thus far there have only been a handful of MVPs who have it. Only MVPs who are "up to date and ho are in a few restricted groups will get it. So it's not all of the 2000 or so MVPs who will get it, and it's not a gift for life!
And not all the code is there. Most of the 3rd party drivers are missing, as are some large chunks of the security code, and some stuff that MS feels is IPR-intensive. That makes sense, although it does restrict MVPs from looking at some of the more interesting areas of the source tree! The access license is also pretty restricted. The licenseee can't compile or build anything, you can't use it to create a derivitive product, and you can't talk much about what you actually see.
And did I mention that even though there's stuff missing, the source tree is big. Very, very big. Humooungouse in fact. When I was working on the resource kit team, I had source code access which I put to good use. The source tree is huge, complex and confusing to the new user. You could tell that the source code tree grew, versus having been designed as it currently exists. New (to the team) developers quickly find their way around (as developers tend to do). But for the casual lay user, it is tough to get into it.
As an MVP, I can see that the access could be interesting and fun. I've got enough background to at least look up the DNS stuff (I think). Whether I can really read the code to the level I'd like is a much different story.
This is cool.
Hey Little Chef/Travel Lodge - Get with the Program
This leads me to think that the telcos don't quite get wireless yet - at least they don't provide me with what I need. What I need is simple. I want one type 2 PC card that I can pop into my laptop that gives me internet connectivity (wirelessly) pretty much everywhere I go (and could possibly use wireless client). I'd like this for a reasonable flat rate/month, for world-wide access. In Sept/Oct, I've been to Boston, London, Chicago, Redmond, New Orleans and Los ANgeles, plus stays at those airports plus visits to DFW, MIA and ORD. I would have liked just one plan. Is this an unrealistic requirement?
Monday, October 20, 2003
Intuit users force rethink on Product Activation
My first taste of product activation came with Novell, many,many years ago when they were the market leader in PC Lans. I had to install several servers, in an office late at night. With two of the four kits, there were problems with the serial number disk. One had been seemingly dropped in something, and the label was only partly legible, and the other floppy was destroyed. We never did figure out how either happened - but knowing the shipping guys I can guess. But I managed to get the servers up and running, and am forever grateful to some great help I got from Compuserve (and not from Novell). I'm sure I aged greatly that night.
By comparison, Windows NT 3.1 was a dream. I remember so vividly the openness MS UK presented with this release. They were talking to ME - the IT Pro - and made it easy. Well easier - don't forget that NT 3.1 was released at a time when CD Roms were very much the upcoming things. After doing ONE installation of 3.1 Advanced server by floppy, a 2xCD was heaven! By way of diversion, the CD along was �400 ($US600) and the whole system nearly �4000 ($6k). Just imagine what you could get for that today. Oh never mind - I just did :-). Opps, I did it again. But I digress.
In summary: I just don't WPA.
I've listened long and hard to most of the arguments for, and against it. It's certainly been a hotly debated topic. I'd like to think I've helped argue MS to be a little more lenient in their application of WPA. WPA has been good for Microsoft too but when I see the WPA stuff, I just see an attitude of "we don't trust you" that's very much in my face.It's much the same resentment I feel towards the 'security' at US airports these days. Traveling in/through several of the bigger US airports (Chicago, Miami, Seattle, Dallas, Lax, and Boston) in the past few weeks, well all I can say is it sucks. There are all these folks just there hassling a population that is overwhelmingly honest. This is another manifestation of the "I don't trust you so you really have to prove yourself" attitude. I find it bordering on degrading to have to nearly strip off (having to remove my shoes and walk across a pretty filthy "carpet" and removing my belt and having to hold trousers up with my hand) as well as having to unpack my bags (I managed 4 trays on the last trip to the US) then repack them (much to the annoyance to the people behind and to the TSA bods who seem to have partly lost the will to live and seem just a bit highly strung. I put up with it because I have to, but that does not stop me for wanting to get rid of it (and the associated costs). At the end of the day, I'd like it to be a lot simpler - and I'd love to get rid of all forms of product activation. It's nice to see I'm not totally alone in disliking "we assume you are dishonest" type product activation schemes. Intuit users didn't either - and they let Intuit know. It's really nice to see that Intuit listened to their customers and removed product activation. See the PC World article where Intuit Apologizes for Product Activation.
Well done Intuit.
Saturday, October 18, 2003
Windows Rights Management Services for Windows Server 2003 Pricing and Licensing Overview
RMS is close
MS is building up it's support for the launch of the Rights Management Server software later this year. RMS is a very interesting product - which solves some important security issues for many customers. The problem is how to protect information that is inside the firewall.I remember many years ago reading an internal memo from a member of the Windows 2000 development team to the team. It was addressed as 'Dear Mary Jo' - since he knew that, within hours of being sent Mary Jo Foley would have a copy and would be putting spin on it in her column. At that time both she and Paul Thurrot sort of made a habit of posting internal information - stuff marked MS Confidential DO NOT COPY. I can feelfor Iain - it's tough to be honest in email where you need to discuss and evalute tough issues and come up with a good resolution, when you know your every word will be sent to people with very different motives (by people with very different motives!).
RMS enables you to create documents whose usage you can determine. You can, for example, make a document no print, no forward. The receipient can read the mail, but can't send it on (e.g. to Mary Jo), or print/fax it. Of course this won't stop analog attacks (taking a digital photograph of the screen, or simply re-typing all the text), but it will cut down on a heck of a lot of more casual abuse.
Right now there are only really two products that make use of RMS: Office 2003 and IE. With Office 2003, you'll need to have the Professional edition in order to create rights managed documents - you can view RM'd docs using Office 2003 Standard. But this will certainly change. I'd expect every native app that ships with Longhorn, for example, to be RMS capable. I look forward to seeing what innovations the ISV community has here! IE integration will provide security on documents provided via an Intranet solution. The IE stuff will ship separately. RMS, however, is not free. Take a look at the Windows Rights Management Services for Windows Server 2003 Pricing and Licensing Overview for the full license detail.
In summary, each RMS user (document creator and document reader) must have an RMS Cal (US$37.00 each). If you want external users to be able to access RMS software, an external Connector license is required: $18,066. So a 500 seat company will need to stump up in the region of US$50,000 for the CALs, the External Connector, and the RMS server - presumably this would be a new system requiring harware/software/services/backup/etc. Given the instant document security this gives you, the cost seems pretty reasonable, especially when seen in the light of of the cost of accidental disclosure.
Oh, and to get much use out of it just now, you'll need to upgrade to Office 2003. Maybe RMS is the killer reason for upgrading to Office 2003. I can see a huge number of firms who will love this and will rush to buy it. The IE component will be useful too, especially for firms with large intranet applications.
Tuesday, October 14, 2003
Momentum
Back from Momentum
I'm just back from MS's partner conference, Momentum. Held in New Orleans, it was the first time that the traditional MS partner channel (Partner Classic) and the MBS partners (who look after the Great Plains etc product lines) all met at a single partner event. We got to hear Microsoft's plans for providing a single partner channel - with room for both sets of partners. The plans for combining the channels made sense to me, but one felt that the MBS partners were less than happy.One interesting aspect of the new programme is how performance is to be recognised. Partners will earn "points" that are the basis for future status and benfits incoming years. These points are awarded based on Skills, Customer Satisfaction, Influence, Sales (for MS), and Certifications.� These Partner points will be for example, 50 says you are a Certified Partner, 120 says you are Gold.�That will make it a bit easier for the larger CTECs, for example, to differentiate themselves.
vnunet.com Samba 3 extends lead over Win 2003
Samba beats Windows Server 2003
Or does it?
I've been reading in IT Week that Samba 3 extends is lead over Windows Server 2003. But before getting too excited, I felt it worthwhile to read the details carefully.Two comments stood out for me: First: "We selected a low-specification but otherwise modern server for our tests. We used an HP ProLiant BL10 eClass Server fitted with a 900MHz Pentium III chip, a single 40GB ATA hard disk and 512MB of RAM. We did not tune any of the software to improve performance." And later: "Each NetBench client makes a constant stream of file requests to the server under test, whereas in real-world environments many users would remain idle for long periods. Consequently our test environment simulates the workload of some 500 client PCs in a typical production environment." So out of the box, on a low end server, a Linux/Samba box performed better than Win2k3 out of the box and untuned. I guess the first question I have on this is to ask why you'd seriously consider putting an important mission critical file server, serving a large community, on a single ATA disk, using a small, underpowered blade computer with limited memory. The test is meant to simulate 500 users, that equates to around 80mb per user - this is 1/3 the size of the memory card for my digital camera.
Their comment about not tuning the system also does not ring totally true. In my experience, installing Linux is an exercise in tuning at least to a degree. If they chose a very thin Linux kernel, possibly one compiled only for only the PIII chip, and loaded only Samba, then they are doing tuning. One thing that could make a huge difference to Windows is how the file and print service is setup.
What I'd really liked to have seen where the bottle neck was while this test was underway and to have seen what effect adding a decent amount of RAM would have had. I suspect the system was kind of busy paging. I've not studied the NetBench benchmark well enough to know how it works when running in this configuration.
So, I'm not really sure if this test if all that valid. Of course, it looks good but what I'd like to see is this test repeated on a properly specified/configured system.
Friday, October 10, 2003
Microsoft launches Desktop Support Technician Cert
Today in New Orleans, Microsoft have announced a new entry level certification: Microsoft Certified Desktop Support Technician (MCDST). There are two exams (70-271, and 70-272), and two courses. Course 2261 (3 days) covers Supporting users on XP and and Course 2262 (2 days) which covers supporting users running applications. The MCDST is aimed at an entry level technical support person - and comes in 'below' the MCSA. This looks like a great certification!Sadly, the certification does not cover any soft skills - this is a shame.
Monday, October 06, 2003
Landover Baptist Community Message Boards
Serious or not?
I can't decide if the Landover Baptist Community Message Board is a serious site or not. It is rather amusing in any event.VeriSign calls halt to .com detours | CNET News.com
Versign calls halt to .com detours
I must have missed this over the weekeend, but it seems that VeriSign has shut down "Site Finder". While I and many more complained to Verisign, the company refused, as I commened in an earlier blog entry. However, it looks like the recent ICANN letter to Verisign has had the desired effect.For a good overview to the issue, and reaction, read the Washington Post's analysis. Horray.
C# Tutorials
Learning C#
I'm trying to learn C#: here's some C# Tutorials that I've found useful.I'm preparing for a talk at IT Forurm, and I've put up a new page on Reskit.net to hold background stuff, links, etc. See http://www.reskit.net/dotnetmcse/index.htm as a starting point.
Sunday, October 05, 2003
Keeping up to date - redux
More on Keeping Up To Date on MSDN
MS now publish updates to MSDN using RSS. The RSS feed itself is at http://msdn.microsoft.com/rss.xml.Use a RSS client like FeedDemon and you're all set.
For tonight,use google to search for the urls for the above. I'll update this entry later.
British Airways - Online Press Office - News Releases
Concorde - The End of an Era
British Airways is ceasing the operation of Concorde in just a few weeks. This sad day was announced in a British Airways Press Release, issued in April, but the final day looms.The last flight you can buy tickets for will be BA001, LHR-JFK Thursday 23 October, although BA are running further private flights for friends, staff, VVIPs, etc. The fares, for travel between London and New York, cost from the standard �£4,350 for one way Concorde returning in World Traveller, and up to �8292 for a return trip both ways on Concorde. Yes, it's steep, but it is truly a once in a lifetime opportunity.
If you can't afford the ticket price, then there's a web site selling Concorde memorabiliaia
I've been lucky enough to fly in Concorde a few times. I surprised my wife on the occasion of her 40th birthday by flying her to New York (she thought she was going to Malta). She was surprised, to say the least. It was cool for me too - I got to sit in the cockpit for takeoff! I've also had the chance to pilot the Concorde Simulator in Bristol, which was a real thrill.
Concorde is a noisy, fuel guzzling technologically outdated aeroplane - but she's a fantastic site. I love watcning her take off, land, or just fly by. And inside, it's a nice 3 hour lunch, while you also cross the Atlantic.
I shall miss her.
Saturday, October 04, 2003
Utilizing the Windows 2000 Authorization Data in Kerberos Tickets for Access Control to Resources
Details of MS Use of Kerberos
In a document on the MSDN site, entitled Utilizing the Windows 2000 Authorization Data in Kerberos Tickets for Access Control to Resources, Microsft set out the contents of the Authorisation Data section of the Kerberos ticket. The article is dated February 2002, although the MSDN RSS feed has just pushed this out as being just published.Speeding up time
In a recent blog entry, I mentioned that I liked Media Player 9 bacause it allowed me to listen to stuff speeded up. Turns out The New York Times has an article about how this technology is being used in a more general way.Wednesday, October 01, 2003
NTBugtraq - NTBugtraq Archives
Another security vulnerabilty?
Could this post on NTBugtraq be another problem? Russ confirms it to be a problem at a number of sites in a later bugtraq post. Oh Joy.Online Network Diagnostic Tools
The Online Toolbox looked good - but none of the tools work. :-(
Now all I need to do is to work out how to fix the router!
Update on Identity Theft
Update on IP Theft
In a recent blog entry I pointed out a guy called Brent Larsson had stolen some of my pages for his site. I was not annoyed that he'd nicked the pages, but he hadn't even changed half the URLs - so many of them pointed to content on MY site (actually some outdated material long since gone!). I discovered this when I got some junk mail from one of those spammers (you know the ones: "We noted your link is not in the search engines, we can help"). Helpfully, the spammer included the link to Larsson's page. Anyway, the ISP has taken the page down. Thanks to http://www.passagen.se/!Mitch Tulloch's net Book
IIS6 Administration - A New Book
I've just picked up Mitch Tulloch's latest (or perhaps nearly latest) book, IIS 6 Administration published by McGraw Hill/Osborne. My summary is that this is a good book on the subject of IIS6 administration. Mitch covers the basic ground of what IIS is (and some history), it's architecture and how to deploy and manage it. He also covers some more advanced topics, such as setting up mail and news, working with the metabase, administering IIS 6 from the command line.A particularly nice feature of this book are the 'blueprint' pages in the centre of the book. These give some nice views of the Architecture, and a nice map of the IIS6 site property sheets (very helpful for navigating around a fairly rich dialog box). I give it 4.5 stars. It's a good solid reference manual on administering IIS.
I'm glad to see that one of my favorite typos (typing SMPT instead of SMTP) has taken root in this book in a couple of places.