Skip to navigation
   
Simon Bisson & Mary Branscombe's Blog

Office 2010 protects you – from your own documents

By Simon Bisson & Mary Branscombe in Editorial

Posted in Beta, Android, Applications, Office, Security, Networking, Microsoft on August 18, 2009 at 8:36 pm

Permalink | Author Profile

Remember macro viruses? Trojans and bots have taken over from them in the virus top ten, but there could easily still be binary Office documents lurking in your business’s fileservers with unwanted code in them. The XML file formats introduced with Office 2007 mean you know when a document has a macro by the file extension (an XLSX file can’t have code in, an XLSM can) but even though XML files are smaller as well as more secure, not everyone wants to spend the time to convert a backlog of many years. So to protect you from anything worrying, Office 2010 introduces a Protected View that locks documents when you open them, and runs in an isolated, low-integrity  process with a restricted token (rather like combining the protected mode that IE 8 runs in with the secure desktop you see with UAC elevation prompts - Protected View uses the same User Interface Privilege Isolation).

As the Office engineering blog post puts it, “For a malware to actually be able to run in Protected View it will first need to find a way around DEP, ASLR, GS and our new 2010 Office File validation checks.  After all that, the malware would need to find a way to break out of the sandbox.”

The Office team is confident enough in Protected View that opening and previewing attachments from Outlook will get less annoying; you won’t have to say yes, you trust every different type of document to open and preview individually the first time you come across it. It seems like a welcome security measure that will make life easier too. Sadly, as implemented it’s currently a productivity blocker that will be turned off or loathed by every user that comes across it.

On my system at least, every single document I open in Office 2010, binary or XML, from the office network is opened in Protected Mode and tagged as coming from ‘an unsafe location’. That’s supposed to be for documents downloaded from the Internet (”When a file is downloaded from the Internet the Windows Attachment Execution Service places a marker in the file’s alternate data stream to indicate it came from the Internet zone,” says the Office Engineering blog) and I’m kind of offended that Microsoft is telling me that our network isn’t secure - it is Windows Server 2008 we’re running. I’m also losing time on every document, having to click through before I can start editing.

I tried turning Protected View off; you can’t. You can go into the Trust center, ignoring the sign that tells you not to go in there and not to change anything, and tell Office to trust network documents (again, ignoring the warning that a network is a scary place and you shouldn’t be trusting it) but that didn’t fix it. I had to manually add the file shares on the server, mount point by mount point. You can’t just give office the name of your file server and trust the whole thing; Office refuses to mark the root of the server as safe.

This isn’t supposed to happen, says Microsoft. In some cases, the proxy settings are to blame (check out The LIZ and Proxies: the surprising connection for an explanation by Eric Lawrence of the IE team of why proxies are involved in the intranet at all. We don’t use a proxy. Maybe the Local intranet setting in Internet Options isn’t set to ‘Automatically detect’? It is, as it happen. 

Ah, says the Office team; it’s a bug, and they’re working on it. That’s good news; if I only have to put up with this until the beta of Office 2010 this autumn, that’s fair enough - you expect problems when you use a ‘technical preview’ (or alpha code as we used to call it).

But the fact that Office 2010 is relying on Internet Explorer options that may or may not apply if you don’t have Internet Explorer on your system is a little worrying (Firefox doesn’t use security zones, for example). And Simon, who is joined to the domain doesn’t see Protected View on network documents. So the underpinnings of Protected view seem to be a tangle of Internet Explorer, Active Directory and Microsoft network settings; that’s fine for an all-Microsoft business - like Microsoft. It’s less useful for the rest of the world where heterogeneous networks are the norm and security is important - but will always get demoted if it gets in the way of getting your job done. Let’s hope the bug fix does more than just tweak things; Protected View uses a spiffy new architecture inside Windows and it needs to take a clear and manageable approach to defining what a ’safe’ or ‘unsafe’ location actually is, or it’s going to be unpopular and insecure (cue everyone copying documents onto their laptop to edit them without the nagging and leaving them in the pub car park).
-Mary
 

12345
Not yet rated
Loading ... Loading ...

 

Don’t like the ribbon? You will

By Simon Bisson & Mary Branscombe in Editorial

Posted in Applications, Office, Microsoft on July 13, 2009 at 3:24 pm

Permalink | Author Profile

You have to get used to the Office 2010 ribbon - and now it’s a lot easier to get used to.

The statistics from Office 2007 users show that the ribbon does what it was designed to do in terms of exposing more of the features that are in the application (because 80% of new feature requests were for features that are already in Office, just not where people were finding them). More people use more of the features in Office 2007 than ever before, says Chris Bryant from the Office team.

Not everyone likes the ribbon and for some people, Microsoft learned the lesson of how multiple interface options increase support costs rather too well with Office 2007 and Windows 7. Having gone to the effort of developing a logical user interface that’s more productive than the old muddle, Microsoft didn’t allow users to stay with old and inferior if they wanted the features that went with the new and improved interface. Quite where users who want new versions of Office without the ribbon think the new features would go is a mystery - and personally speaking, I embraced the ribbon, even though not all of the commands were quite where I thought they should be, on the grounds that I’d been nagging Microsoft for years to tidy up the old Office interface and find logical places for the extra commands and features they’d been cramming in to the old dialogs like pushing socks into a drawer you haven’t been able to close for months.

I know where every feature in the old Office interface was and sometimes I have to look in two tabs to find a specific command so you might expect me to complain about it - but I don’t (much). In Office 2003 the ribbon isn’t perfect but it is still a huge improvement and if a feature is in the wrong place on the ribbon I put it on the quick access toolbar.

And Office 2010 addresses almost every complaint about the ribbon (although if you’re one of the people who hate the ribbon because you have laboriously learned the obscure location of commands that are now clearly and logically arranged in the tabs, then your issue is more about forgiving Microsoft for past sins, abandoning the time you invested and stepping out of your comfort zone - and Microsoft can’t do much about that). If you don’t like features you never use taking up screen space, you can remove commands from tabs - or entire tabs. If your issue was that, say, proofing tools don’t belong under Review with the tools for working with comments on someone else’s document, then you can either move them to the tab where you think they fit better or create a whole new tab and put those commands in what you think is a logical group. And if you dislike the ribbon because you have to switch between tabs (which is no more work that opening menus and dialog boxes, but may feel like more work because you’re comparing it to clicking buttons that are right there in front of you on the ribbon), you can make your own ‘home’ tab for each application that has the tools you use at the full size of the ribbon rather than crammed onto the quick access toolbar. You can completely customise the ribbon and make something that increases productivity generally increase your own productivity too.

Mary

12345
Not yet rated
Loading ... Loading ...

 

   
Tag cloud

virus mapping iPhone Previous Versions service oriented enterprise tele atlas EEE SP1 WEI T-Mobile MING exabytes Jeff Hawkins evernote information rights management mobility Java RSS search database WinHEC SBS lockdown ProCurve mobile network ruggedized Numenta private cloud vulnerabilities lost server benchmark server processors education IBM Linux Nokia OFCOM twitter security mainframe demo Vodafone Internet Explorer 8 web 2.0 expo anti-virus Loki flash drive netbook Istanbul TSA timezones business bug system center co-processor virtual desktop old software MacBook Air netbooks yahoo beta trends annotation Opteron data centre virtualisation DOS ATI migration Visual Studio Girl Geek Dinners Internet Explorer isp legacy Gears server sprawl hierarchical temporal memory information bandwidth ucsd green printing utilities HSPA MIX Google IO outlook BlackBerry colossus performance innovation rtm traffic Firefox hard drive lawsuit HTML 5 Google teched machine learning venture capital politics Windows 7 vs Windows Vista O2 microsoft research Active Directory Seagate accelerator DSL IO wes malware RIM licensing MWC enterprise architecture gameboard Itanium media video Apple Sony augmented reality mobile ofcom network ubuntu monitor gabriola october IT value Mozilla Lenovo Opera bbc iplayer legislation BT flash SMB 2 claims safend cables Secunia web2expo RIA battery life toshiba Express Gate RBL images citrix high performance computing UMPC HSDPA NexT AMD android nvision08 windows 7 multiple monitors futura Protected View xT9 ontier Magny-Cours terabytes international roaming data loss prevention MRDA Dopplr Google Spreadsheets troubleshooting browser installer OEM insert SIM voice ultraportable BitLocker offload numbers privacy Acrobat Pro navteq pre-boot wireless USB RSA 2008 Beacon logitech no signal wildfire T9 exchange future in review CardSpace user interface training navigation CPU regulation Netscape target Trampoline GPL microsoft security essentials Crossfader Frauenhofer Mini-Note DisplayLink national museum of computing HP BBC catalyst Wyse rich client quiz security paradox downturn CERN Asus user experience Delphi 965 AIR whitelist mscape gamer ADFS 2.0 mobile Linux identitity NVIDIA screen Wimbledon how do I get the back off? deperimeterization ikea laptop camera geotagging flex fingerprint Google Sets Trend Micro cracking biometrics Tombstone Objects software 3G NGSCB emulator Web 2.0 office politics CIO todo list oracle mobile data tariffs pen computing Windows Server electricity price g-2 desktop. PC amherst cosmic rays networks power cuts wave moscow development GPS HTC Quest active digitiser deborah adler business technology automation Reqall 2.0 business intelligence routing mms 2009 green IT fault uninstall open open source cisco html cam conferences IT transformation MIX08 Hugh Thompson FUD hardware social networking iPass Ruby g-1 apps remove back encryption accessories spam merger web advertising adfs mobile working project Windows Live developer media center Adobe meaning control panel radeon distributed computing parallel computing Gartner IDF netiquette email windows switch Dell Motorola MacWorld 2008 .NET instant messaging Location SSD fonts designer ballmerbot IM patch Tuesday Ruby On Rails codec usb Microsoft Volume Shadow Copy telecoms market share robot mythbusters Windows Mobile maps macro transcoding hyper-v Facebook LiveID EMC AuthenTec BES anti-trust Chrome cloud service google online applications infrastructure collaboration bolt geneva information cards Qualcomm Verbatim 2009 case Mercury analytics Eee PC thermo regulations fingerprint scanner cold fusion icons disaster recovery identity theft connectivity IIW2008b isps ribbon pgp setup streaming media backhaul eu spam fighting HMT data wifi Salesforce ipsec verdana M&A office Silverlight competition DOSBox bugs storage SapphireSteel identity metasystem upgrade patent dual boot demo09 security theatre Trolltech gaming london Ray Ozzie Corsair screencam Greasemoneky Tim Berners-Lee aws mysql Windows Server 2008 mobile broadband business continuity Large Hadron Collider Tripit anti-patterns Xen power business technology optimisation installation congestion charge disk space Toshiba Portege R500 support Embarcadero social engineering Mono Hp 2710p Bill Gates appzero moblin dvi mobile tablet VSSAdmin secure relocation tennis Skyfire Tom Hogan bletchley park winhec2008 task bar semiotics i-mate productivity Nuance TouchSmart Pal keyboard credit crunch drivers calit2 Bill Cheswick disk network Treo Pro magic thin client Barracuda police hold music wubi QWERTY geek tourism data centre transformation ClipMate direct access Xobni interoperability acquisitions Netscan Enterprise 2.0 beta test IT policy fire cellcrypt Fire Eagle CTO business model clean install history OQO consolidation d2c optical interconnects firewall ANR 64-bit cloud cloud computing smartphone RAZR WPF bombe search goview Moonlight etech culture fibre applications Tablet Kiosk NAS voice recognition system management hdmi display hibernation mash-up data tariff Intel Clear RX management it pro enterprise pixetell Palladium turing vmware utility city SKU design Mark Hurd Internet hacking CES Vista docking station Tablet PC forensics Bing Palm Smartbook p2v Credentica dual display power supply atom visualisation workflow TechEd 2008 MAX appstore phone management data loss webkit sun windows server 2008 r2 griffin amazon Ask.com DLP context application compatibility GPU Safari power saving phone settings greenplum public cloud office 2010 IT automation conference LHC ipv6 O'Reilly people OpenID WWW natural interface macbook bea community CUDA AskEraser Jeff Jones ec2 Opsware Live Mesh hp microsoft research geocaching ports christmas rc
Advertisement
Advertisement