Skip to navigation
   
Simon Bisson & Mary Branscombe's Blog

Office 2010 protects you – from your own documents

By Simon Bisson & Mary Branscombe in Editorial

Posted in Beta, Android, Applications, Office, Security, Networking, Microsoft on August 18, 2009 at 8:36 pm

Permalink | Author Profile

Remember macro viruses? Trojans and bots have taken over from them in the virus top ten, but there could easily still be binary Office documents lurking in your business’s fileservers with unwanted code in them. The XML file formats introduced with Office 2007 mean you know when a document has a macro by the file extension (an XLSX file can’t have code in, an XLSM can) but even though XML files are smaller as well as more secure, not everyone wants to spend the time to convert a backlog of many years. So to protect you from anything worrying, Office 2010 introduces a Protected View that locks documents when you open them, and runs in an isolated, low-integrity  process with a restricted token (rather like combining the protected mode that IE 8 runs in with the secure desktop you see with UAC elevation prompts - Protected View uses the same User Interface Privilege Isolation).

As the Office engineering blog post puts it, “For a malware to actually be able to run in Protected View it will first need to find a way around DEP, ASLR, GS and our new 2010 Office File validation checks.  After all that, the malware would need to find a way to break out of the sandbox.”

The Office team is confident enough in Protected View that opening and previewing attachments from Outlook will get less annoying; you won’t have to say yes, you trust every different type of document to open and preview individually the first time you come across it. It seems like a welcome security measure that will make life easier too. Sadly, as implemented it’s currently a productivity blocker that will be turned off or loathed by every user that comes across it.

On my system at least, every single document I open in Office 2010, binary or XML, from the office network is opened in Protected Mode and tagged as coming from ‘an unsafe location’. That’s supposed to be for documents downloaded from the Internet (”When a file is downloaded from the Internet the Windows Attachment Execution Service places a marker in the file’s alternate data stream to indicate it came from the Internet zone,” says the Office Engineering blog) and I’m kind of offended that Microsoft is telling me that our network isn’t secure - it is Windows Server 2008 we’re running. I’m also losing time on every document, having to click through before I can start editing.

I tried turning Protected View off; you can’t. You can go into the Trust center, ignoring the sign that tells you not to go in there and not to change anything, and tell Office to trust network documents (again, ignoring the warning that a network is a scary place and you shouldn’t be trusting it) but that didn’t fix it. I had to manually add the file shares on the server, mount point by mount point. You can’t just give office the name of your file server and trust the whole thing; Office refuses to mark the root of the server as safe.

This isn’t supposed to happen, says Microsoft. In some cases, the proxy settings are to blame (check out The LIZ and Proxies: the surprising connection for an explanation by Eric Lawrence of the IE team of why proxies are involved in the intranet at all. We don’t use a proxy. Maybe the Local intranet setting in Internet Options isn’t set to ‘Automatically detect’? It is, as it happen. 

Ah, says the Office team; it’s a bug, and they’re working on it. That’s good news; if I only have to put up with this until the beta of Office 2010 this autumn, that’s fair enough - you expect problems when you use a ‘technical preview’ (or alpha code as we used to call it).

But the fact that Office 2010 is relying on Internet Explorer options that may or may not apply if you don’t have Internet Explorer on your system is a little worrying (Firefox doesn’t use security zones, for example). And Simon, who is joined to the domain doesn’t see Protected View on network documents. So the underpinnings of Protected view seem to be a tangle of Internet Explorer, Active Directory and Microsoft network settings; that’s fine for an all-Microsoft business - like Microsoft. It’s less useful for the rest of the world where heterogeneous networks are the norm and security is important - but will always get demoted if it gets in the way of getting your job done. Let’s hope the bug fix does more than just tweak things; Protected View uses a spiffy new architecture inside Windows and it needs to take a clear and manageable approach to defining what a ’safe’ or ‘unsafe’ location actually is, or it’s going to be unpopular and insecure (cue everyone copying documents onto their laptop to edit them without the nagging and leaving them in the pub car park).
-Mary
 

12345
Not yet rated
Loading ... Loading ...

 

Don’t like the ribbon? You will

By Simon Bisson & Mary Branscombe in Editorial

Posted in Applications, Office, Microsoft on July 13, 2009 at 3:24 pm

Permalink | Author Profile

You have to get used to the Office 2010 ribbon - and now it’s a lot easier to get used to.

The statistics from Office 2007 users show that the ribbon does what it was designed to do in terms of exposing more of the features that are in the application (because 80% of new feature requests were for features that are already in Office, just not where people were finding them). More people use more of the features in Office 2007 than ever before, says Chris Bryant from the Office team.

Not everyone likes the ribbon and for some people, Microsoft learned the lesson of how multiple interface options increase support costs rather too well with Office 2007 and Windows 7. Having gone to the effort of developing a logical user interface that’s more productive than the old muddle, Microsoft didn’t allow users to stay with old and inferior if they wanted the features that went with the new and improved interface. Quite where users who want new versions of Office without the ribbon think the new features would go is a mystery - and personally speaking, I embraced the ribbon, even though not all of the commands were quite where I thought they should be, on the grounds that I’d been nagging Microsoft for years to tidy up the old Office interface and find logical places for the extra commands and features they’d been cramming in to the old dialogs like pushing socks into a drawer you haven’t been able to close for months.

I know where every feature in the old Office interface was and sometimes I have to look in two tabs to find a specific command so you might expect me to complain about it - but I don’t (much). In Office 2003 the ribbon isn’t perfect but it is still a huge improvement and if a feature is in the wrong place on the ribbon I put it on the quick access toolbar.

And Office 2010 addresses almost every complaint about the ribbon (although if you’re one of the people who hate the ribbon because you have laboriously learned the obscure location of commands that are now clearly and logically arranged in the tabs, then your issue is more about forgiving Microsoft for past sins, abandoning the time you invested and stepping out of your comfort zone - and Microsoft can’t do much about that). If you don’t like features you never use taking up screen space, you can remove commands from tabs - or entire tabs. If your issue was that, say, proofing tools don’t belong under Review with the tools for working with comments on someone else’s document, then you can either move them to the tab where you think they fit better or create a whole new tab and put those commands in what you think is a logical group. And if you dislike the ribbon because you have to switch between tabs (which is no more work that opening menus and dialog boxes, but may feel like more work because you’re comparing it to clicking buttons that are right there in front of you on the ribbon), you can make your own ‘home’ tab for each application that has the tools you use at the full size of the ribbon rather than crammed onto the quick access toolbar. You can completely customise the ribbon and make something that increases productivity generally increase your own productivity too.

Mary

12345
Not yet rated
Loading ... Loading ...

 

   
Tag cloud

robot upgrade macro Netscan thermo power saving applications licensing open source media center dual boot ec2 atom email Active Directory screencam tele atlas Previous Versions regulations bug patent disk space RIA AuthenTec T9 Netscape Palladium MING collaboration Istanbul UMPC RIM tennis Gartner MRDA geek tourism RSS search power Secunia bletchley park demo09 data centre citrix Lenovo Hp 2710p Delphi AskEraser identitity flash drive apps tablet software enterprise IBM mythbusters SMB 2 Dell IO performance media identity theft mms 2009 cloud computing remove back Seagate wireless USB data loss prevention bbc iplayer distributed computing 2.0 TouchSmart amherst video Vista web 2.0 expo conferences data loss eu windows 7 Location Google IO windows server 2008 r2 Acrobat Pro smartphone safend Motorola Tablet Kiosk Palm training Bill Gates patch Tuesday Asus bandwidth phone management server sprawl insert SIM TechEd 2008 xT9 anti-patterns cold fusion search MWC WPF business intelligence encryption natural interface O2 Moonlight BBC backhaul griffin 2009 community SBS Crossfader Fire Eagle webkit switch codec WWW hp microsoft research ATI phone settings GPU international roaming CardSpace oracle developer culture future in review education BlackBerry images voice london iPhone moscow IIW2008b OFCOM benchmark utilities Silverlight goview Girl Geek Dinners screen aws bolt telecoms legacy MIX Trampoline Corsair Jeff Hawkins uninstall AIR catalyst malware clean install ultraportable server business model Opera calit2 turing toshiba ipv6 lockdown adfs Clear RX maps productivity Ruby virus todo list ANR IT policy semiotics network anti-virus mainframe Tripit fingerprint scanner christmas user interface Tablet PC monitor yahoo Opsware accelerator d2c Smartbook trends flash FUD annotation Tombstone Objects Hugh Thompson IM Xobni Ask.com MacWorld 2008 HP web2expo database ucsd lost server NVIDIA Opteron 965 business technology automation BT Google cloud macbook Windows Live DOSBox transcoding biometrics GPS gamer Windows 7 vs Windows Vista Windows Mobile old software Linux wubi Mozilla Live Mesh AMD Xen Facebook ubuntu management BitLocker development target LiveID web gabriola CERN pre-boot Mini-Note Google Spreadsheets Firefox high performance computing MAX Toshiba Portege R500 control panel geneva city windows acquisitions national museum of computing Safari Express Gate task bar DOS isps HSDPA Nuance Google Sets mysql display amazon evernote system management logitech cellcrypt ontier QWERTY Qualcomm Intel Wyse virtual desktop police radeon spam fighting project security service oriented enterprise public cloud Internet Explorer 8 green IT CUDA direct access Itanium utility power supply bugs migration sun teched conference mobile ofcom network WEI co-processor information rights management machine learning Pal mobile network verdana Trolltech navigation cosmic rays LHC Magny-Cours credit crunch VSSAdmin mapping Jeff Jones business continuity moblin fire Windows Server 2008 Credentica mobile broadband Large Hadron Collider voice recognition quiz winhec2008 usb active digitiser Beacon ballmerbot connectivity accessories p2v Salesforce Ray Ozzie designer RBL Enterprise 2.0 pen computing merger ClipMate Adobe hard drive laptop mscape no signal DSL streaming media IDF hdmi fingerprint gameboard Microsoft system center geotagging security theatre secure beta test Internet Explorer politics IT automation gaming microsoft research wifi demo OEM isp Volume Shadow Copy flex outlook hacking HMT processors html MacBook Air beta identity metasystem futura NGSCB timezones IT value wildfire Nokia TSA office 2010 T-Mobile ADFS 2.0 rich client Treo Pro Mercury business technology optimisation RSA 2008 i-mate congestion charge social engineering fonts Tim Berners-Lee application compatibility traffic MIX08 SapphireSteel ipsec people infrastructure etech case SKU netbook camera NexT hyper-v hibernation spam appstore security paradox wes consolidation social networking cloud service google online applications SSD hold music DLP ports docking station Wimbledon cisco deperimeterization information fault EEE history routing bea ikea EMC .NET Frauenhofer regulation multiple monitors g-1 netiquette android innovation Bing Sony venture capital hierarchical temporal memory Apple numbers Mark Hurd electricity price parallel computing icons design colossus cam cracking 3G desktop. PC RAZR business ruggedized it pro Web 2.0 networks emulator meaning ribbon Tom Hogan legislation interoperability analytics Eee PC CTO twitter disaster recovery exchange Visual Studio support bombe power cuts context Protected View CES dvi Vodafone cables troubleshooting CPU data relocation open IT transformation OQO october rtm browser market share battery life navteq augmented reality Verbatim setup claims geocaching g-2 information cards installation netbooks HSPA mobile lawsuit greenplum offload Gears downturn workflow Trend Micro fibre thin client WinHEC Java data tariff NAS exabytes drivers competition green printing vulnerabilities enterprise architecture Bill Cheswick Skyfire HTC rc user experience Quest office mobile Linux iPass GPL keyboard Embarcadero mobility Barracuda terabytes 64-bit OpenID installer advertising CIO HTML 5 privacy Reqall appzero anti-trust virtualisation data centre transformation mobile working Greasemoneky whitelist Loki dual display Windows Server forensics SP1 magic ProCurve firewall M&A BES private cloud nvision08 vmware Mono DisplayLink office politics wave storage Chrome pixetell microsoft security essentials deborah adler hardware disk mobile data tariffs O'Reilly Internet Numenta visualisation how do I get the back off? Dopplr pgp optical interconnects mash-up Ruby On Rails instant messaging
Advertisement
Advertisement