<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tech Prognosis</title>
	<atom:link href="http://blog.techprognosis.com/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.techprognosis.com</link>
	<description>Allowing You to Focus on Work</description>
	<lastBuildDate>Tue, 13 Dec 2011 16:52:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Drive-by Trojan Download: CNET Embraces the Dark Side</title>
		<link>http://blog.techprognosis.com/2011/12/13/drive-by-trojan-download-cnet-embraces-the-dark-side.html</link>
		<comments>http://blog.techprognosis.com/2011/12/13/drive-by-trojan-download-cnet-embraces-the-dark-side.html#comments</comments>
		<pubDate>Tue, 13 Dec 2011 16:12:35 +0000</pubDate>
		<dc:creator>Daniel Ihonvbere</dc:creator>
				<category><![CDATA[Ethics]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Privacy Matters]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Technology]]></category>
		<category><![CDATA[CNET]]></category>
		<category><![CDATA[download.com]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[trojan horse]]></category>

		<guid isPermaLink="false">http://blog.techprognosis.com/?p=2020</guid>
		<description><![CDATA[It appears that the draw of the almighty dollar has pulled CNET to the dark side. CNET is a popular technology news site with a download portal called Download.com where many users go to download software that are free, shareware and open source. The site built a reputation a while back as a dependable location [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1027" style="margin-left: 8px; margin-right: 8px;" title="onlinespyingimage" src="http://blog.techprognosis.com/wp-content/uploads/2010/08/onlinespyingimage.jpg" alt="" width="183" height="130" />It appears that the draw of the almighty dollar has pulled CNET to the dark side. CNET is a popular technology news site with a download portal called Download.com where many users go to download software that are free, shareware and open source. The site built a reputation a while back as a dependable location for hosting software that was devoid of malicious content &#8211; trojan horses, adware, virus etc.<span id="more-2020"></span></p>
<p>Apparently, that was then. Fyodor, the creator of nmap recently wrote a <a title="CNET and Drive-By  Trojan Downloads" href="http://insecure.org/news/download-com-fiasco.html">scathing article</a> about how CNET has now become the very essence of a drive-by download &#8211; where you get a little more than you bargained for when you download software from a website. CNET has taken the concept to another level by actually reverse-engineering submitted software and injecting malicious content before presenting them to trusting users.</p>
<p>The article is a serious indictment on CNET for abusing the trust placed on them by millions of users and the software developers who are kind enough to create a program and give it to users for free. By monetizing the hard work of these developers without their knowledge (unless they are willing to pay a &#8220;premium fee), it is not far-fetched to accuse CNET of &#8220;stealing&#8221;. It is just now, after they were outed that there is talk of &#8221; giving the developers a cut&#8221; of the money they&#8217;ve been raking in from dropping trojans and adware on the computers of millions of unsuspecting users, including kids, for crying out loud.</p>
<p>Why is this a problem? We know that most users click through installation prompts without bothering to read, and this is exactly what CNET was taking advantage of, until they messed with Wireshark and NMap.</p>
<p>The unethical nature of it is that while CNET was raking in millions of dollars, the creators of the software they were reverse-engineering were catching grief for infecting users&#8217; computers with bogus web browser toolbars, home pages and adware that could very well have leaked private information.</p>
<p>As <a title="Download Wrappers Explained" href="http://www.networkworld.com/community/node/79382">Alan Shimel</a> of networkworld explains it, here&#8217;s how these &#8220;wrappers&#8221; work:<br />
&#8220;[W]hen you click to download software from their site (which is software developed by others), they are &#8220;wrapping&#8221; it in their own installers.  This C/Net installer will either ask you (if they are polite) or in some cases not so obviously install other 3rd party software on your computer.  Things like web toolbars, alternate search engines and other programs that usually pay money for every copy that gets installed.&#8221;</p>
<p>Is this practice limited to just CNET? Not by a long shot, but most do it on the website &#8211; like when you are presented with the download button for something different than what you originally wanted to download. The argument is always that &#8221; this is to help us pay the bills&#8221;. No one is arguing with the need to generate revenue. It is the deceptive way in which that goal is being achieved that is drawing some angst. There is a difference between giving the user an option to install a toolbar and respecting the choice when the user selects &#8220;No&#8221;, and installing a toolbar, changing the home page and dropping adware on a user&#8217;s computer through a deceptive &#8220;accept&#8221; button.</p>
<p>Then there is the other part of the equation &#8211; the enablers of CNET&#8217;s unethical behavior. The parties who were encouraging CNET to bundle toolbars, browsers, search engines etc. in the software they were hosting should also be ashamed of their dirty tricks.</p>
<p>It is important to remind users to take the time to read the dialog boxes that pop up when trying to install an application:</p>
<ul>
<li>If available, always choose the &#8220;Custom&#8221; option so you can at least see what other crap is going to be dumped on your computer by the installer. In most cases, you can decline or uncheck the box for items you do not want.</li>
<li>After the installation, go through the &#8220;add/remove&#8221; (Windows XP) or &#8220;program features&#8221; (Windows Vista/7) section in control panel to see if some strange software was installed without your knowledge and promptly remove them.</li>
<li>Run &#8220;msconfig&#8221; and look through the &#8220;startup&#8221; tab to see if some strange application has inserted itself to automatically start with Windows and disable them.</li>
</ul>
<p>It is only going to get worse, unfortunately.</p>
<p>&nbsp;</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Drive-by+Trojan+Download%3A+CNET+Embraces+the+Dark+Side+http%3A%2F%2Fblog.techprognosis.com%2F%3Fp%3D2020" title="Post to Twitter"><img class="nothumb" src="http://blog.techprognosis.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter4.png" alt="Post to Twitter" /></a> <a class="tt" href="http://twitter.com/intent/tweet?text=Drive-by+Trojan+Download%3A+CNET+Embraces+the+Dark+Side+http%3A%2F%2Fblog.techprognosis.com%2F%3Fp%3D2020" title="Post to Twitter">Tweet This Post</a></p></div>]]></content:encoded>
			<wfw:commentRss>http://blog.techprognosis.com/2011/12/13/drive-by-trojan-download-cnet-embraces-the-dark-side.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To Fix QuickBooks Error 3371 statuscode-11118</title>
		<link>http://blog.techprognosis.com/2011/09/23/how-to-fix-quickbooks-error-3371-statuscode-11118.html</link>
		<comments>http://blog.techprognosis.com/2011/09/23/how-to-fix-quickbooks-error-3371-statuscode-11118.html#comments</comments>
		<pubDate>Fri, 23 Sep 2011 18:19:27 +0000</pubDate>
		<dc:creator>Daniel Ihonvbere</dc:creator>
				<category><![CDATA[Enterprise Computing]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Small Business]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[error code 3371]]></category>
		<category><![CDATA[QuickBooks error 3371 statuscode-11118]]></category>
		<category><![CDATA[statuscode-11118 in quickbooks]]></category>

		<guid isPermaLink="false">http://blog.techprognosis.com/?p=2009</guid>
		<description><![CDATA[If you recently ran into a strange Quick Books error, specifically Error Code 3371 &#8220;Quickbooks could not load license data. This may be caused by a missing or damaged file.&#8221;,  with a status code of 11118, you are not alone. And it looks like this headache has been plaguing the users of the accounting software [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1812" title="quickbooks2" src="http://blog.techprognosis.com/wp-content/uploads/2011/06/quickbooks2.jpg" alt="" width="148" height="114" />If you recently ran into a strange Quick Books error, specifically <strong>Error Code 3371 &#8220;Quickbooks could not load license data. This may be caused by a missing or damaged file.&#8221;</strong>,  with a<strong> status code of 11118</strong>, you are not alone. And it looks like this headache has been plaguing the users of the accounting software for several years.</p>
<p>The symptoms are usually that you are unable to open your company file in Quick Books and resolution attempts like repairing the installation fail, and you get prompts for a mysterious html file.<span id="more-2009"></span></p>
<p>From most indications, this usually happens if you do a system restore, or move your operating system files to a new hard drive or new computer. It leads one to believe that there is some kind of hash or signature on the specific file causing the frustration and that file is the aptly named &#8220;Entitlement&#8221; file which manages the phone-home registration process of Quick Books. The file in question is the &#8220;Entitlement DataStore.ecml&#8221; file.</p>
<p>To fix error 3371, rename the offending file and you should be able to start living again. Obviously, you will have to re-register with Intuit.</p>
<p><strong>If you are still using Windows XP</strong>, you need to do this:</p>
<p>For those who like to type:</p>
<ul>
<li>Click Start and choose Run.</li>
<li>Type the following command into the Open field:<br />
C:Documents and Settings\All Users\Application Data\Intuit\Entitlement Client\v2 (Note: you may have multiple &#8220;v&#8221; folders, so look for the current or latest one)</li>
<li>Click OK</li>
<li>Delete (or preferably, rename) the &#8220;Entitlement DataStore.ecml&#8221; file.</li>
</ul>
<p>For the clickers, you can just &#8220;Explore&#8221; your way to the &#8220;C:Documents and Settings\All Users\Application Data\Intuit\Entitlement Client\ v*&#8221; folder and rename or delete the stupid file.</p>
<p><strong>For the Windows 7 users</strong>, go here: C:\ProgramData\Intuit\Entitlement Client\v* (where &#8216;*&#8217; is a number). Rename the errant file. Quick Books will create a new one when you start the application.</p>
<p>[Note that the "ProgramData" folder may be hidden in which case you can unhide it like this:</p>
<ul>
<li>Open "Computer", Click on "Organize | Folder and search options | View,  and select "Show hidden files, folders..."]</li>
</ul>
<p>Start Quick Books and you should be good to go. Remember, you most likely, will get a reminder to register Quick Books within 30 days.</p>
<p>Disclaimer: Backup your stuff before you start messing with files. If you hose your application, do not come crying to me. If you are not sure, consult a professional. &#8216;Nuff said.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=How+To+Fix+QuickBooks+Error+3371+statuscode-11118+http%3A%2F%2Fblog.techprognosis.com%2F%3Fp%3D2009" title="Post to Twitter"><img class="nothumb" src="http://blog.techprognosis.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter4.png" alt="Post to Twitter" /></a> <a class="tt" href="http://twitter.com/intent/tweet?text=How+To+Fix+QuickBooks+Error+3371+statuscode-11118+http%3A%2F%2Fblog.techprognosis.com%2F%3Fp%3D2009" title="Post to Twitter">Tweet This Post</a></p></div>]]></content:encoded>
			<wfw:commentRss>http://blog.techprognosis.com/2011/09/23/how-to-fix-quickbooks-error-3371-statuscode-11118.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>The DigiNotar Breach: Another Exposure of Negligence</title>
		<link>http://blog.techprognosis.com/2011/09/06/the-diginotar-breach-another-exposure-of-negligence.html</link>
		<comments>http://blog.techprognosis.com/2011/09/06/the-diginotar-breach-another-exposure-of-negligence.html#comments</comments>
		<pubDate>Tue, 06 Sep 2011 23:39:04 +0000</pubDate>
		<dc:creator>Daniel Ihonvbere</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Regulations]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Software Patches]]></category>
		<category><![CDATA[Web Technology]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[certificate authority]]></category>
		<category><![CDATA[diginotar]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[security management]]></category>

		<guid isPermaLink="false">http://blog.techprognosis.com/?p=1990</guid>
		<description><![CDATA[In case you have not heard, another SSL Certificate provider, Dutch certificate authority DigiNotar, a subsidiary of Vasco Data Security, was breached recently and from the preliminary report coming from the company that did an audit, it looks pretty bad. Some of the names in the list of bogus certificates generated by the attackers include [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1992" style="margin-left: 8px; margin-right: 8px;" title="Matrix Mania 1.0" src="http://blog.techprognosis.com/wp-content/uploads/2011/09/TP_Matrix.jpg" alt="" width="106" height="79" />In case you have not heard, another SSL Certificate provider, Dutch certificate authority <a title="DigiNotar Breach" href="http://www.vasco.com/company/press_room/news_archive/2011/news_diginotar_reports_security_incident.aspx">DigiNotar, a subsidiary of Vasco Data Security, was breached</a> recently and from the preliminary report coming from the company that did an audit, it looks pretty bad.</p>
<p>Some of the names in the list of bogus certificates generated by the attackers include Comodo, Google, Thawte, Microsoft, Mozilla, WindoswUpdate, WordPress&#8217; MI6, the CIA, Facebook and Twitter.<span id="more-1990"></span></p>
<p>For three whole months ( June to August), the attacker camped out on DigiNotar&#8217;s servers and did his/her work and cleaned up.  S/He was even kind enough to leave a message in a script file that was used to generate the rogue certificates.</p>
<p>The question now is, how much trust should we place on these providers of digital certificates? A few months ago (March 2011), a subsidiary of Comodo was hacked apparently by the same person. Here&#8217;s why I am concerned, and I&#8217;ll quote from page 9 of the <a title="Initial Audit Report by Fox IT on DigiNotar Breach" href="http://www.rijksoverheid.nl/documenten-en-publicaties/rapporten/2011/09/05/diginotar-public-report-version-1.html">report</a>:</p>
<blockquote>
<ul>
<li>The successful hack implies that the current network setup and/or procedures at DigiNotar are not sufficiently secure to prevent this kind of attack.</li>
<li>The most critical servers contain malicious software that can normally be detected by anti-virus software</li>
<li>The separation of critical components was not functioning or was not in place</li>
<li>The CA (Certificate Authority) servers were accessible over the network from the management LAN</li>
<li>All CA servers were members of the same Windows domain (and they all apparently used the same user/password combination)</li>
<li>The password was not very strong and could easily be brute-forced</li>
<li>The software installed on the public web servers was outdated and not patched</li>
<li>No antivirus protection was present on the investigated servers</li>
<li>No secure central network logging was in place</li>
</ul>
</blockquote>
<p>The breach has led to the revocation of a lot of digital certificates &#8211; over 500 so far and the breach prompted Mozilla to take measures so &#8220;that all DigiNotar certificates will be untrusted by Mozilla products,&#8221; which includes the Firefox browser. Google&#8217;s Chrome browser also placed DigiNotar certificates on a permanent block list.</p>
<p>It is inexplicable that after the attention that the Comodo breach garnered and the recent spate of hacks against RSA, Barracuda, Citigroup and a host of other high profile targets, that the management at DigiNotar did not deem it wise to do due diligence and execute some element of due care.</p>
<p>This is even more depressing because from this <a title="F-Secure Blog on DigiNotar Hack" href="http://www.f-secure.com/weblog/archives/00002228.html">F-Secure blog</a>, the company has been hacked before, back in May of 2009.</p>
<p>Look at the bullet points above again and tell me if those are not things that could have been fixed. And beyond that, what role has their auditor play in this mess? It will be ridiculous to assume that they were not paying an external party to audit their environment. Why did an auditing firm not raise a red flag over these lapses? Is this another case of check box auditing that has come to bite DigiNotar in the ass?</p>
<p>The larger concern is how can we continue to trust DigiNotar and other certificate authorities to help ensure that there is no eavesdropping on secure communications between users and the sites they visit? After all, anyone armed with a rogue certificate for a web firm or service can impersonate that organization and get at communications that would otherwise be impossible to read because they are encrypted.</p>
<p><strong>Update:</strong></p>
<p>As <a href="http://rbellew.wordpress.com/2011/09/23/diginotar-files-for-bankruptcy/">Russ Bellew posted</a>, DigiNotar filed for bankruptcy and their fate should be a wake-up call to other Certificate Authorities and indeed all companies with an internet presence. After all, the DigiNotar hacker did say that four other major CA&#8217;s were on the chopping block.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=The+DigiNotar+Breach%3A+Another+Exposure+of+Negligence+http%3A%2F%2Fblog.techprognosis.com%2F%3Fp%3D1990" title="Post to Twitter"><img class="nothumb" src="http://blog.techprognosis.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter4.png" alt="Post to Twitter" /></a> <a class="tt" href="http://twitter.com/intent/tweet?text=The+DigiNotar+Breach%3A+Another+Exposure+of+Negligence+http%3A%2F%2Fblog.techprognosis.com%2F%3Fp%3D1990" title="Post to Twitter">Tweet This Post</a></p></div>]]></content:encoded>
			<wfw:commentRss>http://blog.techprognosis.com/2011/09/06/the-diginotar-breach-another-exposure-of-negligence.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How To Fix Windows Update Error 0&#215;80070424</title>
		<link>http://blog.techprognosis.com/2011/07/11/how-to-fix-windows-update-error-0x80070424.html</link>
		<comments>http://blog.techprognosis.com/2011/07/11/how-to-fix-windows-update-error-0x80070424.html#comments</comments>
		<pubDate>Mon, 11 Jul 2011 10:53:53 +0000</pubDate>
		<dc:creator>Daniel Ihonvbere</dc:creator>
				<category><![CDATA[Enterprise Computing]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Software Patches]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Error 80070424]]></category>
		<category><![CDATA[Windows Update Error 0x80070424]]></category>
		<category><![CDATA[WindowsUpdate_80070424]]></category>

		<guid isPermaLink="false">http://blog.techprognosis.com/?p=1875</guid>
		<description><![CDATA[When you run the Windows Update service, you may sometimes discover that you are not able to install any windows updates or even use the windows update website. Instead, you get a message like: The website has encountered a problem and cannot display the page you are trying to view. The options provided below might [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-full wp-image-816 alignleft" style="margin-left: 8px; margin-right: 8px;" title="windows-logo" src="http://blog.techprognosis.com/wp-content/uploads/2009/07/windows-logo.jpg" alt="" width="97" height="85" />When you run the Windows Update service, you may sometimes discover that you are not able to install any windows updates or even use the windows update website. Instead, you get a message like:</p>
<blockquote><p>The website has encountered a problem and cannot display the page you are trying to view. The options provided below might help you solve the problem</p></blockquote>
<p>Then there is an <strong>error code 0&#215;80070424</strong>. It could also show up as error 80070424.</p>
<p>This could be a symptom of one or more of the following problems:<span id="more-1875"></span></p>
<ul>
<li><strong>The Automatic Updates feature is turned off</strong> in Security Center and you cannot turn this feature on.</li>
<li><strong>The Automatic Updates service is missing from the Services snap-in.</strong></li>
<li><strong>The registry is missing one or both of the following registry subkeys:</strong><br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WUAUSERV</li>
</ul>
<p>What this simply means is that<strong> Windows thinks the update service does not exist on your computer</strong> either because it was accidentally de-registered or was not installed properly. So you get error 0&#215;80070424.</p>
<p>The fastest way to fix Windows Update Error 0&#215;80070424 is to re-register the Windows Update and Automatic Update services by running the following commands either using command prompt or the &#8220;Run&#8221; option.</p>
<p><strong>Option 1:</strong></p>
<ul>
<li>Go to Start&gt;Run</li>
<li>Type<strong> regsvr32 wuaueng.dll</strong></li>
<li>Click on OK wait a few seconds, then click on OK in the RegSvr32 dialog box.</li>
<li>Click on Start&gt;Run key in regedit then click on OK<br />
Navigate to:<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv<br />
Look for a <strong>DeleteFlag</strong> value and, if it exists, right-click on it and select<br />
Delete.</li>
</ul>
<p><strong>Option 2:</strong></p>
<p>Open the command prompt, or the &#8220;<strong>Run</strong>&#8221; box and type, or cut and paste the following:</p>
<p><strong>%systemroot%\system32\regsvr32.exe %systemroot%\system32\wuaneng.dll</strong></p>
<p>This will register the Windows Update service and a dialog box should display to say the commands were executed successfully. You can then retry the Windows Update service again.</p>
<p>It may also help to make sure that required Windows Update services like the Background Intelligent Transfer Service, Windows Update and Workstation services are running. If they are not, start those services.</p>
<p><strong>To check and start required Windows Update services:</strong></p>
<ul>
<li>Click on Start, select &#8220;Run&#8221; and type in &#8220;<strong>Services.msc</strong>&#8220;. You may be prompted for an administrator password or confirmation.</li>
<li>In the Services dialog box, click Background Intelligent Transfer Service</li>
<li>Note the status of the selection. If it shows Stopped, right-click the service and click &#8220;Start&#8221;.</li>
</ul>
<p>Do the same for Windows Update and the Workstation services.</p>
<p>In some weird instances, when you look in the &#8220;Services&#8221; section under Administrative tools, the Windows Update service may not appear at all. If that is the case, see this <a href="http://go.microsoft.com/fwlink/?LinkId=153562">article</a> about installing the Windows Update agent.</p>
<p>Additionally, Microsoft has also made version 7.4.7600.226 of the Windows Update Agent available and you can get the files <a href="http://support.microsoft.com/kb/949104">here</a>.</p>
<p><strong>You must know which kind of processor platform</strong> (x86-based, x64-based, or Itanium-based) that you have. Most users have x86-based processors [http://support.microsoft.com/kb/949104]</p>
<p><strong>To learn which version of Windows that you are running</strong>, or to learn whether it is a 32-bit version or 64-bit version, open System Information (Msinfo32.exe). Then, review the value that is listed for System Type. To do this, follow these steps:</p>
<p><strong>Step 1:</strong><br />
Click Start, and then click Run, or click Start Search.<br />
Type msinfo32.exe, and then press ENTER.<br />
In System Information, review the value for System Type.<br />
For 32-bit editions of Windows, the System Type value is x86-based PC.<br />
For 64-bit editions of Windows, the System Type value is x64-based PC.</p>
<p><strong>Step 2:</strong><br />
Download Windows Update Agent for Windows Vista, Windows Server 2008, Windows XP, Windows Server 2003, and Windows 2000 Service Pack 4</p>
<p>To automatically obtain the latest Windows Update Agent,  we recommend that you visit the Windows Update Web site. When you visit this Web site, the latest version of the Windows Update Agent will automatically be installed. For Windows 7 and Vista, Windows Update is integrated with the Operating System and can be accessed through the Control Panel.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=How+To+Fix+Windows+Update+Error+0%C3%9780070424+http%3A%2F%2Fblog.techprognosis.com%2F%3Fp%3D1875" title="Post to Twitter"><img class="nothumb" src="http://blog.techprognosis.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter4.png" alt="Post to Twitter" /></a> <a class="tt" href="http://twitter.com/intent/tweet?text=How+To+Fix+Windows+Update+Error+0%C3%9780070424+http%3A%2F%2Fblog.techprognosis.com%2F%3Fp%3D1875" title="Post to Twitter">Tweet This Post</a></p></div>]]></content:encoded>
			<wfw:commentRss>http://blog.techprognosis.com/2011/07/11/how-to-fix-windows-update-error-0x80070424.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privacy: How To Lock Down Google&#8217;s Chrome Browser</title>
		<link>http://blog.techprognosis.com/2011/07/08/privacy-how-to-lock-down-googles-chrome-browser.html</link>
		<comments>http://blog.techprognosis.com/2011/07/08/privacy-how-to-lock-down-googles-chrome-browser.html#comments</comments>
		<pubDate>Fri, 08 Jul 2011 21:20:24 +0000</pubDate>
		<dc:creator>Daniel Ihonvbere</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Ethics]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Privacy Matters]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Web Technology]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[data leak]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[tracking]]></category>

		<guid isPermaLink="false">http://blog.techprognosis.com/?p=1851</guid>
		<description><![CDATA[Google&#8217;s Chrome browser is quickly becoming a favorite of users in the ever competitive Internet browser market mostly because of its perceived speed and clean interface. A lot of the accolades are warranted, but my focus in this write-up is on the area of user data privacy and how the Chrome browser seems to have [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1853" style="margin-left: 8px; margin-right: 8px;" title="chrome-205_noshadow" src="http://blog.techprognosis.com/wp-content/uploads/2011/07/chrome-205_noshadow.png" alt="" width="110" height="110" />Google&#8217;s Chrome browser is quickly becoming a favorite of users in the ever competitive Internet browser market mostly because of its perceived speed and clean interface.</p>
<p>A lot of the accolades are warranted, but my focus in this write-up is on the area of user data privacy and how the Chrome browser seems to have built-in tools that are a reg-flag for privacy violations in spite of Google&#8217;s <a href="http://www.google.com/chrome/intl/en/privacy.html">Privacy Policy</a>.</p>
<p>Our position is that the Chrome browser is &#8220;chatty&#8221;,  and acts as a keystroke logger in the area of search. In fact, the folks at <a href="http://www.scroogle.org">Scroogle</a> characterized Google Chrome as a browser that tends to &#8220;phone home a lot&#8221;.  And here&#8217;s why:<img title="More..." src="http://blog.techprognosis.com/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" alt="" /><span id="more-1851"></span></p>
<ul>
<li>It is common knowledge now that when a user conducts a search using a search engine, Google stores three main types of information in a log file: the user&#8217;s IP address (a unique network address given by an Internet service provider), the words the user searched for, and a cookie identifier (unique value given to every Web-browser that visits a web page). See <a href="http://news.cnet.com/8301-13739_3-10038963-46.html?tag=mncol;title">here</a> for more details.</li>
</ul>
<ul>
<li>According to Google, the Omnibox (which combines search with the address bar) is supposed to automatically suggest websites as you type and you &#8220;can disable Omnibox suggestions by unchecking the box in the &#8220;Privacy&#8221; section of Goggle Chrome&#8217;s options. As it turns out, you can disable Omnibox suggestions, but the browser conveniently ignores your choice and uses auto-suggest anyway.</li>
</ul>
<ul>
<li>The Chrome browser uses a client_id variable which is unique for every Chrome user, and which can be used to create exact user profiles of a user&#8217;s actions while using Google Chrome. According to Google&#8217;s Privacy Policy:<br />
&#8220;The client ID is used for the user metrics service. This is an opt-in service that lets users send usage statistics to Google so that we can learn how Google Chrome is being used for the sake of making improvements. It helps us answer questions like, &#8220;Are people using the back button?&#8221; and &#8220;How common is it that people click the back button repeatedly?&#8221; Users can always update their preference about sending usage statistics.&#8221;<img class="aligncenter size-full wp-image-1859" title="chrome_unique_id" src="http://blog.techprognosis.com/wp-content/uploads/2011/07/chrome_unique_id.png" alt="" width="265" height="100" /></li>
</ul>
<ul>
<li>Apparently, there is no option to prevent Chrome from recording History and downloads, options which  are available in Firefox, Opera and Internet Explorer 9. I found it really annoying that Google deliberately removed the option to disable history, especially since it was tied to the search engine a user may be using at any point.<br />
For example, here&#8217;s how Firefox does it:<br />
<img class="aligncenter size-full wp-image-1861" title="techprognosis_ffprivacy" src="http://blog.techprognosis.com/wp-content/uploads/2011/07/techprognosis_ffprivacy.png" alt="" width="334" height="326" /></li>
</ul>
<p>Auto-complete and &#8220;predictive&#8221; search may have their uses, but the fact that a user&#8217;s keystrokes are sent to a search engine in real-time and are tied to the user&#8217;s IP address does not look like protecting privacy. This is doubly worrisome since we learned a long time ago that Google was uploading the history data in Chrome offsite &#8211; to its data centers.</p>
<ul>
<li>Google Update does more than update your Chrome browser to the latest version. It &#8220;periodically sends information to Google about how you obtained the browser, how often you use the Chrome browser, and specifically, &#8220;whether you used Google Chrome in the last day, the number of days since the last time you used it, and the total number of days that Google Chrome has been installed&#8221;</li>
</ul>
<p><strong>Here&#8217;s how to lock down Google&#8217;s Chrome browser:</strong></p>
<p>There are some tools available that you can install to help you remove the client_id that Google tags you with in order to track your usage of the browser. See <a href="http://www.abelssoft.net/unchrome.php">Unchrome</a>,  <a href="[http://www.aqlsoft.com/chrome-privacy-protector">Chrome Privacy Protector</a>  and <a href="http://blog.gjl-network.net/archives/166-google-chrome-chrome-privacy-guard-cpg.html">Chrome Privacy Guard</a>. Ultimately, I prefer not having to deal with yet another software for a feature Google should have made available or not included in the first place. So we will fix this at the source.</p>
<ul>
<li>First thing is to resolve the privacy issue by making Chrome open up in private browsing or incognito mode permanently. To do this, right-click on a Chrome shortcut, select properties. The &#8220;Shortcut&#8221; tab will open up. On the &#8220;Target&#8221; address, add &#8211;incognito at the end so it will look like this:<br />
\google\Chrome\Application\chrome.exe &#8212; incognito</li>
</ul>
<p><img class="aligncenter size-full wp-image-1860" title="incognito" src="http://blog.techprognosis.com/wp-content/uploads/2011/07/incognito.png" alt="" width="341" height="69" /><br />
To address the history palava, make the relevant files in the default folder read-only. These files are &#8220;Archived History&#8221;, &#8220;History&#8221; and &#8220;Visited Links&#8221; and can be found in the &#8220;Users\&lt;profile&gt;\AppData\Local\Google\Chrome\User Data\Default&#8221; folder in Windows Vista and 7.  XP users can find the folder here: &#8230;\Local Settings\Application Data\Google\Chrome\User Data</p>
<ol>
<li>Create a blank home page by going to options and setting the home page to about:blank</li>
<li>Close the Chrome browser and navigate to &#8220;Users\&lt;profile&gt;\AppData\Local\Google\Chrome\User Data\Default&#8221;. Delete the files called &#8220;Archived History&#8221;, &#8220;History&#8221; and &#8220;Visited Links&#8221;. Do not close the folder.</li>
<li>Open Chrome, but do not visit any site. This will allow the browser to recreate the files you just deleted. The big difference now is that those files are empty and you want to keep them that way by doing the next step.</li>
<li>Locate the new archived history, history and visited links files and make them read-only by right-clicking, selecting properties and checking the &#8220;Read-only&#8221; box.</li>
<li>Open Chrome and enjoy</li>
</ol>
<p>The next hurdle is the search engine spying that is built into the Chrome browser. While this knowledge is not new, it is still disturbing that the browser tracks every keystroke you type while using the location bar. A quick check with Wireshark will educate you on this.</p>
<p>The ability of browsers to tie your search to your IP address is troubling. To prevent this, create your own &#8220;search engine&#8221; by doing this:</p>
<ul>
<li>On the &#8220;Basics&#8221; section of the Options page, select &#8220;Manage search engines&#8221;.<br />
In the &#8220;Other search engines&#8221; section, click on the &#8220;Add a new search engine&#8221; box and type in a name. Call it anything you want, like &#8220;Private&#8221;.<br />
Enter a keyword in the Keyword box and http://%s in the URL box. This prevents Chrome from piping every URL you type in the location bar to a search engine. Unfortunately, this also messes up searching.<br />
If you must set up a default search engine, I recommend Scroogle at www.scroogle.org and you can use this on the URL box &#8211; https://ssl.scroogle.org/cgi-bin/nbbwssl.cgi?Gw=%s</li>
</ul>
<p>A little paranoid? I don&#8217;t think so. It&#8217;s all about choices. There are things we must do online and it is inevitable that some of our private information will be exchanged. But users need to know that they have the option of turning something off, if they do not need it. If a &#8220;malicious&#8221; software installed a keylogger on a user&#8217;s computer, we would cry blue murder. How is the keystroke tracking behavior by search engines different?</p>
<p><strong>Next we need to disable the automatic opening of files.</strong></p>
<p>You cannot control the setting to automatically open certain downloaded files in the browser &#8211; a practice you should stay away from as much as possible. It is preferable to download and scan before opening a file. Drive-by downloads use this vector to drop stuff on your computer.<br />
<img class="aligncenter size-full wp-image-1864" title="techprognosis_download_option" src="http://blog.techprognosis.com/wp-content/uploads/2011/07/techprognosis_download_option.png" alt="" width="625" height="162" />The option to manage this feature tends to be grayed-out on first use, unless you allow Chrome to open a file &#8211; see the complaints <a href="http://www.google.com/support/forum/p/Chrome/thread?tid=4d67be07c18033d8&amp;hl=en">here</a>. Thankfully, exe files are not allowed.</p>
<p>Again, in contrast, here&#8217;s how applications are managed in Firefox:<br />
<img class="aligncenter size-full wp-image-1863" title="techprognosis_apps_options" src="http://blog.techprognosis.com/wp-content/uploads/2011/07/techprognosis_apps_options.png" alt="" width="512" height="288" /></p>
<p>Notice the options to &#8220;Always ask&#8221;, &#8220;Save File&#8221; etc.</p>
<p>To fix this annoyance, open a blank tab and type in chrome://plugins/ or about:plugins to pull up the settings for the plug-ins installed with Chrome and turn off what you do not want.</p>
<p><img class="aligncenter size-full wp-image-1865" title="techprognosis_plugins" src="http://blog.techprognosis.com/wp-content/uploads/2011/07/techprognosis_plugins.png" alt="" width="409" height="264" /></p>
<p>For those not afraid of looking under the hood:<br />
Close Chrome. Browse to: Users\&lt;profile&gt;\AppData\Local\Google\Chrome\User Data\Defaul (Windows Vista/7) or In Linux it is usually $HOME/.config/google-chrome/Default/Preferences.</p>
<p>Open the Preferences file in a text editor. Look for these lines:</p>
<p>&#8220;download&#8221;: {<br />
&#8220;directory_upgrade&#8221;: true,<br />
&#8220;extensions_to_open&#8221;: &#8220;flv&#8221;,   [ change this to ]    &#8220;extensions_to_open&#8221;: &#8220;&#8221;,<br />
&#8220;prompt_for_download&#8221;: false<br />
}</p>
<p>For those who are interested, here&#8217;s a link on <a href="http://www.googlechromebrowser.com/customizing-google-chrome-settings/">customizing chrome</a>.</p>
<p>Final thoughts are that Google&#8217;s Chrome browser may be a good fit for many users, but given the subtle and sometimes aggressive data gathering tools built into the browser, there is a lot to be worried about in the area of user data privacy. While data breach and hacking seem to be a daily occurrence these days, it won&#8217;t hurt a user to take some precautions in limiting the amount of information unwittingly sent to vendors just because you installed their software on your computer.</p>
<p>Here are some other things you could do:</p>
<p>Set the browser to automatically delete cookies every time you close it.</p>
<p>Whenever possible, use the private browsing feature built into most modern browsers.</p>
<p>Use specific browsers for specific purposes &#8211; general browsing, search, online banking etc. and customize each browser accordingly.</p>
<p>You can also get an alternative Chrome-like browser called <a href="http://www.srware.net/en/software_srware_iron.php">Iron</a> that is based on the free Source code &#8220;Chromium&#8221; &#8211; without the problems of privacy and security baggage of Google Chrome.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Privacy%3A+How+To+Lock+Down+Google%E2%80%99s+Chrome+Browser+http%3A%2F%2Fblog.techprognosis.com%2F%3Fp%3D1851" title="Post to Twitter"><img class="nothumb" src="http://blog.techprognosis.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter4.png" alt="Post to Twitter" /></a> <a class="tt" href="http://twitter.com/intent/tweet?text=Privacy%3A+How+To+Lock+Down+Google%E2%80%99s+Chrome+Browser+http%3A%2F%2Fblog.techprognosis.com%2F%3Fp%3D1851" title="Post to Twitter">Tweet This Post</a></p></div>]]></content:encoded>
			<wfw:commentRss>http://blog.techprognosis.com/2011/07/08/privacy-how-to-lock-down-googles-chrome-browser.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

