Search Logger
Archives for January, 2010.

Archive for January, 2010

IE Cumulative Security Update Now Available

1:52 pm - January 21, 2010 in IEBlog

Today we released a Cumulative Security Update for Internet Explorer.  We’ve released this Cumulative Security Update earlier than originally scheduled based on malicious activities reported on the web. The update is available via Windows Update and Microsoft Update. Most users configure their machines to update automatically; you can find more information on that here.

This update actually includes 236 separate packages for all the different languages and versions of Windows and IE that customers run and Microsoft supports worldwide. We release these packages simultaneously for all supported products and languages as part of this update. The complete matrix of browsers, operating systems, and languages is available in the security bulletin. At a high level, these packages cover:

  • Seven operating system versions: Windows 2000, Windows XP, Windows Server 2003, 2008, and 2008 R2, Windows Vista and Windows 7. Customers run 32-bit, 64-bit, as well as Itanium versions of some of these operating systems, as well as a variety of different service packs.
  • Four different versions of IE: 5.01, 6, 7, and 8.
  • All supported languages. Older versions of Windows require separate language-specific packages, typically between 18 and 25. Windows Vista and later operating systems have a single language-neutral binary to update IE.

We test each security fix thoroughly with different variants of the security issue. We also test the entire package extensively for compatibility and reliability, as well as any setup, deployment, and manageability issues. Also, security updates are cumulative and contain all previously released updates for each version of Internet Explorer, to make securing any system (one updated a month ago or never updated at all) easy.

This update addresses several vulnerabilities including the one described here. Other blog posts describe specifics. Some of these vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer.  Note that IE8 users on Windows 7 have extensive defense in depth protections with DEP, ASLR, and protected mode that make remote code execution from a malicious site extremely difficult.  Microsoft therefore strongly recommends customers upgrade to IE8 to benefit from these extensive defense in depth protections.

For detailed information on the contents of this update, please see the following documentation:

We encourage everyone to set their operating system to automatically update with the latest security updates for all their software.  You can find more information here.

 

Dean Hachamovitch

IE General Manager

 

Haiti’s sorrow, My Yahoo! and you

6:04 pm - January 20, 2010 in My Yahoo! Blog

 Wednesday’s 6.1 magnitude aftershock in Haiti is a jolting reminder of a tragedy whose scale we struggle to comprehend. The world has responded with resources and compassion, but a disaster of this size will be with us for years and years. 

The Internet can help us zero in on the specifics of a challenge and empower us to help in more direct and potentially more effective ways than ever before. My Yahoo! can simplify and expand the information at your disposal.

 

  •  The Haiti Sun – Produced by the Haitian community abroad and at home, provides a unique perspective on the tragedy.
  • The New York Times – Some of the most moving international coverage has come from the New York Times, providing an extraordinary mix of personal stories, breaking news and analysis.
  • The Red Cross – Just one organization providing relief to Haiti but it is a great way to keep track of the progress being made to help the millions of earthquake victims.
  • United Geological Survey’s shaker maps and alerts - If you want an up-to-the-minute alert about temblors and where they occur.

 A sign of hope coming out of Haiti’s calamity is the way technology has hastened the exchange of information and stirred people to action. May these resources help you feel connected to the plight of Haiti’s people and their path to recovery.

Apps showcased in this post:

 Jay
- My Yahoo! Editorial

 

Blogger Status 2010-01-20 01:50:00

1:50 am - January 20, 2010 in Blogger Status
Users are experiencing problems playing videos in Blogger blogs. We are investigating and will send an update when fixed.

Update 1/22: This is now fixed. Thanks for your patience.
 

New Parameter for Server Side API Calls

4:10 pm - January 19, 2010 in Google AJAX Search API Blog
Over the last several years, you've helped make Google's AJAX APIs incredibly successful. Not surprisingly, however, there are some people who try to take advantage of these free APIs by using them in ways that they were not designed for, abuse which is prohibited by the Terms of Use. Specifically, some servers are making countless requests - requests not made on the behalf of an end-user - in an attempt to scrape data from the APIs.

To help us discourage this behavior without affecting legitimate developers, we're adding a new parameter to the RESTful interface, userip. With this parameter, developers have the option of supplying the IP address of the end-user on whose behalf they are making the API request. Doing so will help us distinguish this legitimate server-side traffic from the more abusive scraping in which there are no end-users.

Use of this new parameter is *not* required. However, if it is not included with server-side requests, those requests are more likely to be interpreted and automatically blocked as abuse, especially in situations where a server is sending a high volume of traffic to the API. Additional safeguards you can take include setting setting a valid HTTP referer (as required by our Terms of Use) and using an API key. These additional measures will help us contact you in case there are problems with your website or application (sometimes a programming error results in massive traffic, forcing us to block your access if we are unable to contact you). In choosing to utilize this parameter, please be sure that you're in compliance with any local laws, including any laws relating to disclosure of personal information being sent.

Check the documentation for usage of the new parameter. We'd love to hear any comments, questions or problems you're having in the support forum.
 

In the Wild for January 19, 2010

10:32 am - January 19, 2010 in Yahoo! User Interface Blog

News and notes follow from the past week in the YUI community. As always, please let us know via the comments or @yuilibrary if we missed something good.

 

Playoffs, Football & Fans

7:24 pm - January 15, 2010 in My Yahoo! Blog

2009 + 1 = a whole new year. We’re starting it off running working on a new set of features to enhance My Yahoo!.  I’ll start off by letting you know that we have a series of fan apps for all your favorite NFL football teams. With the playoffs here, you may want to add a few of these to your page:

In addition, we upgraded our Horoscope feed so that should be working for you again. We also fixed the bug where sometimes the Fantasy Sports app’s layout didn’t display correctly.

Apps showcased in this post:

Michael
- My Yahoo! Team Lead

 

Add-on Guidelines in Action – Crawler Toolbar

4:52 pm - January 14, 2010 in IEBlog

A new version of the Crawler Toolbar has recently been released and comes with many improvements to the user experience similar to the changes we described in a previous post about the AVG Security Toolbar. It’s another great example of the Guidelines for add-on developers in action. Here are some high-level examples of the changes they’ve made:

  • The close button is visible so that users can manage it like other toolbars. Additionally, the toolbar is positioned in a supported location which improves stability and performance.
  • It no longer modifies the new tab page to maintain a predictable new tab experience for users.

Many thanks to the Crawler Toolbar team for the work they’ve done to provide a more predictable and reliable experience, keeping users in control of the browser.

-Paul Cutsinger and Herman Ng

Before: Previous version of Crawler Toolbar

new tab page with the old Crawler toolbar which modifies the new tab page.

After: Newest version (5.1.0.177) of the Crawler Toolbar provides a more predictable experience and lets users stay in control of their browser

new tab page with the new Crawler toolbar which does not modify the new tab page.
 

Support Haiti Disaster Relief

9:17 pm - January 13, 2010 in Blogger Buzz
Like many of you, we watched in horror as news emerged from Haiti about yesterday's disastrous earthquake. For those of you who publish your blog with Blogger, we built a couple of widgets that make it easy to invite your readers to contribute money to the Red Cross's international disaster relief effort. Pick a size that best fits your sidebar:


After clicking the appropriate button, select which of your blogs you want to add the widget to, then click "Add widget". The Red Cross assures us that 100% of the money raised is going to disaster relief efforts in Haiti — we and they thank you for your support!

Not on Blogger? Be sure to visit the Red Cross's Haiti banners page with banners that you can add manually, or visit Google's page containing information about relief organizations, news and contact info relating to the earthquake.
 

GWT Developers: Hope to see you at Google I/O

9:23 am - January 13, 2010 in Google Web Toolkit Blog
As you may have heard from our announcement this morning, registration for Google I/O is now open. In addition to publishing access to registration, we've also included event details on the I/O website.

We already have quite a few Google Web Toolkit I/O sessions and Developer Sandbox demos lined up, and we expect this number to grow over the coming months. Here's a partial list of the GWT sessions that are already listed on the I/O website:

Over the next couple of months, we'll be adding new GWT sessions and more GWT Developer Sandbox participants to the I/O website. For updates on when new content is added, follow @googleio on Twitter.

Registration for Google I/O (at the early bird rate of $400) is open as of today. We hope you'll be as excited about this year's I/O as we are, and we look forward to seeing everyone in May.

Google I/O
May 19-20, 2010
Moscone West, San Francisco
http://code.google.com/io

 
 
 
 
 
 
It's All About Search | © clsc.net |
2012.02.0420:31
Tech used here: Valid HTML - Valid CSS - Valid RSS - JavaScript - PHP - Smarty - MySQL - and a partridge in a pear tree.