Microsoft Surrenders IM War, Claims Security Risk 123
calibanDNS writes "The BBC is running an article about Microsoft surrendering in its instant messaging war with AOL. According to the article, the latest version of AOL's instant messaging software 'blocks interoperability by exposing a very serious security bug in its software.'"
MS would prefer it not be called a surrender, of course; see also the
Nando Times article
which hints at running arbitrary code on the client. Is this FUD, or will we carry a story next week about a new AOL IM exploit?
Re:IM standards (Score:2)
So the one time that they talk relatively sanely, do you expect me to just go "oh, okay"... No. Once there's a standard in place, that's when Microsoft will subvert it.
Serious security flaw in Windoze (Score:1)
Since most uSoft software has serious security flaws that are caused by applying power to the system, maybe there's a single point at which these problems could be fixed....
Re:WE need a single IM system (Score:2)
don't cry over spilt beer. (Score:1)
Microsoft software broken by someone else, how can it be? I thought it was supposed to be one network, one computer, one program. Boo Hoo Hoo!
Re:Here's the buffer overflow details (Score:2)
It makes one wonder why they did *this* hacky thing, instead of a Netrek-style method. For those that never played (bronco) Netrek, the "official" clients were compiled with blessed RSA keys. The servers sent (sometimes periodic) challenges to the clients; the clients had to respond in such a way that the server could tell whether it was a valid client, and which it was. If a key was cracked, it could be invalidated at the server side.
It's not fool-proof, but it doesn't open the user up to remote exploits...
Re:WE need a single IM system...NOT (Score:2)
Re:Is the risk real? Yes it is! (Score:2)
As you say, there is a world of difference between being crappy in recognising existing errors, and actually deliberately introducing new errors...
Re:The exploit is there! (Score:2)
Re:Try Everybuddy (Score:2)
Re:How many different OS's do we need anyway? (Score:1)
This wasn't that. This was MS basically writing software that cracked into AOL's proprietary database system and then used their network to provide a MS service. This was no more a test of open standards than if I went to a local ISP with a PPP client and *demanded* that they give me access through their network.
--John
Re:How many different OS's do we need anyway? (Score:1)
Astounding to see this here.
How many different operating systems do we need anyways? Surely Windows is good enough for everyone. Hmm, perhaps not?
Oh, and for the record, allowing them to communicate with each other is exactly what the fight is about. That's what MS did and AOL does want to permit. This is one time where MS was actually on the side of open standards.
Here's where we see where people really stand, in favor of open standards or just in favor of bashing MS.
-Blake (rolling his eyes)
This wouldn't be happening if we where more open. (Score:2)
This is one of the things that started development of the Jabber project [jabber.org]. We're designing a non centralized system, where users belong to themselves. Servers are not set in stone, but instead behave simularly to email servers. Anyone can bring their IM to any server. Any ISP can setup their own IM server, and provide their users with what they want, without 'ownership' of the user. The user can just as easily setup his/her account on a different server.
But we've taken it a step further. Any of these servers can then talk to AIM, MSIM, etc on the server level. We let you choose.
No one owns us, and we shouldn't tolerate NOT having a choice of what we want to do with IM'ing, no more so then we are limited to what we do with email.
The corperate 'wars' over user ownsership are silly, and bad buisness for them. Hopefully, for their sake, they'll wake up and smell the coffee before IM is a commodity, and their users flood to other providers.
Re:IM standards (Score:1)
This line shows your complete lack of understanding of this issue. Microsoft is the one who came in with their different client in a market which still has no need for it. ICQ is the IM standard. I am aware of no problems with it requiring "innovation" from monoposoft. They totally missed the parade on yet another emerging market and then bribed and extorted their way into it.
Personally I would not deign to converse with anyone so misinformed about so many things that they would use a redundant piece of crap like monoposoft's IM.
---CONFLICT!!---
Open Stanards. (Score:2)
If you read the source from licq (and other ICQ-compatible *nix clients), you'll find that ICQ 99a and 99b don't really adhere to their protocol v5. ICQ 99b, for example, seems to want its bytes swapped around (endianness bug, or purposefull?).
What would be really good are:
1) Standard communication (clients can talk to clients), with standard back-end communication (I can make up my own ICQ server, and this can go and connect with the ICQ network).
^ This is a general thing to benefit everyone
2) A migration program for the different client databases. I'd love it if there was something like alien (package format converter) that I could use to let licq and ICQ 98 (99 is a bloated P-O-S) share the same history database.
^ This is more specific, and would mainly be a benefit for people migrating from Windows to Linux (a good browser, like Opera, would also be a must).
The standards aren't going to come about unless we can come up with a good protocol, have GPLed source (no AOL "bait and switch" tactics are possible then), and get a fair number of people using it. A good internal client with plugins for different OS specific display (like licq) would be great for this. Why would I want to use ICQ98 if I can use Licq-Win32, contact friends on the new Open network, as well as keep in touch with the older ICQ people? Not to mention the fact that this would remove the main barrier (data in one OS, but not the other) that people have to switching from one to another.
---
Re:Yeah, but this is the client (Score:1)
Re:IM standards (Score:1)
Oh so if i want to send mail to one of my friends on one of those server I can't... oh wait, your just stupid.
No, he's not stupid. He was saying that your ISP (hopefully) has their mail server configured so that someone who is not a subscriber can not send mail out through their SMTP server. If they didn't, they would be an open relay. Many admins block incoming mail from known open relays (I do for instance) because much of the spam coming into their network comes from open relays.
For example, if your ISP did not block non-subscribers from sending messages out through their SMTP server, you could not send email to me.
1 centralized network of IM clients is a bad thing (Score:2)
A distributed IM protocol, with individual ISPs running messaging servers for their customers, or even the irc protocol is a much better thing for the network as a whole.
So what is Microsoft's trap? (Score:2)
I bet you are right. I'm just curious to hear people's theories about what kind of trap Microsoft has set. Microsoft is a very deliberate company. Their retreat is probably a pseudo-defeat to look weak for the DOJ trial. Plus, Microsoft recognizes the Internet train is leaving without BillG. They want to own the Internet, or at least its users, at any cost. Linux and Apache are far more popular on the Internet than Windows NT and IIS. I've read some recent articles pointing out how Microsoft is retargeting at corporate intranets with Windows 2000 and the ActiveDirectory, trying to win the Internet war from the "inside out". Maybe Microsoft is working on an IM strategy or product that involves intranet or business features. B2B is a bigger, richer market than B2C (or C2C?).
Re:Heh (Score:1)
-----------------
Your attention please everyone, if I could just say a few words... I would be a better public speaker.
Re:IM standards (Score:1)
Instant messaging [as it stands] is unlike many other server propositions, because whereas it makes sense for ISPs to prevent you using their mail server, proxy server, news server etc if you are not a subscriber to that ISP, with messaging it is almost certain that one or more party is not a subscriber. This is not a problem if the ISP can get some other benefit out of use of their server e.g. use of their client and the possibility of being exposed to their adverts.
Any common messaging protocol will have to address these issues. It should be possible to write a protocol that is hosted by ISPs in a similar manner to mail i.e. so both ISPs involved have to supply a messaging server.
Microsoft's two faces (Score:1)
Re:[OT] MS age is over (Was: Re:Antitrust ploy?) (Score:1)
"Gates said, Intel could not count on Microsoft to support Intel's next generation of microprocessors as long as Intel was developing platform-level software that competed with windows."
AND
"Microsoft expends a significant portion of its monopoly power, which could otherwise be spent maximizing price, on imposing burdensome restrictions on its customers -- and in inducing them to behave in ways -- that augment and prolong that monopoly power."
- Thomas Penfield Jackson, US District Judge
Read the FoF!
Re:WE need a single IM system (Score:1)
Re:IM standards (Score:1)
You are sending it to the POP server, not the SMTP server. You are not using his outgoing-only server to send him mail.
Re:don't cry over spilt beer. (Score:1)
Closed source software sucks now, huh? If they break it, you're screwed. It's funny to watch MicroShit cry foul. They've done their best to break everything else from everyone else.
Re:1 big network of IM clients is a good thing. (Score:2)
Re:Yeah, but this is the client (Score:1)
AOL assuredly modified their binary protocol, and clients using that protocol (the offical Win/Mac ones) are the only ones vulnerable.
I think this is all correct. But don't trust me - research it on your own.
Re: Open Standards (Score:1)
Not entirely. It's also true to say that M$ was just looking for a free ride on AOL's database server. Keeping track of who & where has a price tag. An open IM standard would be nice, but who foots the bill?
Re:Yeah, but this is the client (Score:1)
Re:IM standards (Score:1)
Re:IM is redundant (Score:1)
Not depend on a singular server connection between servers. (This is called 'netsplit'
Scale well.
Not require ALL SERVERS know about the exitence of ALL USERS.
There are many, MANY more..
Re:MS should circumvent this in next win service p (Score:1)
wait. let me think about this one again.
ahhahahahahahahaha
Re:How many different messengers do we need anyway (Score:1)
First: "Microsoft could keep their hands out of this."
Then: "Ok, if multiple vendors wish to put out various chat software, at least allow them to communicate with each other."
Microsoft's actions will hopefully force AOL to submit to an open standard. They have actually HELPED by having their hands in this. get it?
4? Insightful?
new .sig (Score:1)
Re:IM standards (Score:1)
It's true that good ISPs only allow their customers to use their SMTP/POP servers. (Ignore free e-mail services for now.) However, that doesn't stop anyone from sending an e-mail to someone at another ISP - Bob's ISP's SMTP server accepts his message and sends it to Jane's ISP's POP server, from which she picks it up. It also doesn't matter if one is using MS Outlook and the other is using elm.
With IM clients in their current state, it's different. To communicate, users have to be both on the same server and using the same client. Which is, of course, a problem. ICQ, by far the most popular IM client, is in its official incarnation an ugly-slow-huge-cumbersome-bloated program (the MS one is comparatively very nice. of course, just about anything would be comparatively very nice.)
There should also be no need for MS to negotiate a contract with AOL. if I want to send e-mail to slashdot, my ISP doesn't have to have a contract with andover.net. Shouldn't be any different for IM. Course, getting a current monopoly (AOL, with both AIM and ICQ) to form a pact in the best interests of the consumer is difficult. Especially if the pact is mainly with MS, a wannabe monopoly in this area.
WE need a single IM system (Score:2)
Let AOL and ICQ and MSN and PDQ and ABC all come up with there own IM products. As long as they all can talk to each other. I for one am tired of hainvg three different IM products running.
-- Patrick Aland
-- http://www.stetson.edu/~paland
80 MILLION USERS? (Score:1)
IM standards (Score:3)
MS has some points, but it's blowing smoke on one issue. A single IM standard will not allow MS clients to communicate with AOL clients. The reason is simple: to communicate with AOL clients you need to use AOL servers. AOL has the right to prevent non-AOL subscribers from using it's servers. And if you think that's wrong, think about other servers. Your ISP has it's mail servers configured to prevent anyone but it's subscribers from using them to send mail. ISPs that don't end up on the RBL. They probably also have them configured to not handle mail from certain domains, typically to block incoming spam. They probably have their news servers configured similarly, so that only their subscribers can read news off of them. Why should IM servers be different?
A single standard would be neccesary, but if MS wants their subscribers to be able to talk to AOL's subscribers, they need to negotiate a contract with AOL to have AOL's servers carry MS's traffic. Which, to date, MS has shown no apparent interest in doing.
Is the risk real? (Score:2)
The exploit is there! (Score:5)
The AOL IM actually has a buffer overflow exploit present. Basically whenever an AOL client connected to the server, the server smashed the stack and executed a piece of code that would send a packet back to the server. This let AOL change the authentication on the fly without updating the client. Of course, it also opened up some security holes. This [securityfocus.com] was discussed on bugtraq in August.
How many different messengers do we need anyway? (Score:3)
Microsoft could keep their hands out of this.
My friends and I all have AIM.
Ok, if multiple vendors wish to put out various chat software, at least allow them to communicate with each other.
"Hey Bob, I thought you said you would be on AIM last night. I had to talk to you."
"Well, I tried the new Yahoo chat. It's cool. Only thing is, my wife Brenda likes eShare chat she just found."
WTF?
It's all about the protocols, yeah (Score:1)
Of course, that'll happen about the same time windows is voluntarily open-sourced.
--
Matt Singerman
Heh (Score:1)
I do find it quite funny about how AOL is putting an end to this silly war though. MS kept exploiting AOL stuff - now AOL exploits a hole in Windows. Someone has egg on their face and I don't think it is Steve Case....
Jabber is shaping up (Score:2)
It still not user-ready, but it's getting there quickly.
I'm not surprised, but. . . . (Score:1)
History has shown that most MS and AOL have a generally sloppy attitude towards security.
However, history has also shown that MS is willing to say pretty much anything about competitors, backed up only by anecdote or flawed studies, in order to put the desired spin on any business decision they make.
So what's the truth? Honestly, I don't even care. I don't think that AIM or MMS is the answer. If any of you open-sourcers are devoting any resources to AIM-based or MMS-based stuff, I would encourage you to donate a little time to the Jabber project (http://www.jabber.org), a messaging system with an open protocol and (IMHO, of course) a better design than either of the commercial competitors. The product has been languishing a bit in the last several months, and it would be nice to see a surge of interest in it. If you like, check out the most recent release (as of 1999/11/09), 0.7pre4 (which can be found at http://download.jabber.org/0.7pre4.html).
TOC (Score:1)
Re:WE need a single IM system (Score:1)
Re:Is the risk real? Yes it is! (Score:1)
overflow (Score:3)
My concern is that AOL did not release a patch after this became public knowledge. Everybody knows there's a bug in that client. Sending executable code over the wire is never a good idea on something as woefully under-authenticated as tcp/ip. I have nothing but contempt for AOL - and I'm extremelly worried that they might do something equally stupid with other products - such as the AOL v5 client now shipping. How many buffer overflows does *that* thing depend on, or what is being sent over the wire that their customers are blithingly unaware of?
There are more serious questions to answer than the "buffer overflow" in the client. Where is the outrage over this? This should be prime time news!
--
MS and security! (Score:1)
1 big network of IM clients is a good thing. (Score:3)
Jakob Nielsen's article on Metcalfe's Law [useit.com] offers good insight on why the segregation of different AIM clients is a bad thing, and reduces the potential value of the network.
Metcalfe's Law states that "the value of a network grows by the square of the size of the network".
Reversing this law provides:
Note to Rob: We need SUB and SUP tags allowed in /.
Here's the buffer overflow details (Score:3)
Describes the buffer overflow AOL is using in some pretty good detail. Here's the basic idea:
When AIM connects to the AOL server, the AOL server sends back a message containing x86 executable code. This overflows a buffer in the AIM client, and the code gets run. This code creates a packet to send back to the AOL server. If the AOL server doesn't see the packet, then it assumes you're not using AIM, and boots you.
What MS's client did was see the packet containing the code, and generate the reply message WITHOUT overflowing a buffer or executing that code. But, AOL can just tweak that code on the server a bit and have a different reply get generated, while MS's client has to get updated to use that new code.
Nevertheless, this is pretty damn reprehensible on the part of AOL. If they don't want MS customers using their servers, sue the shit outta M$, don't exploit holes in your own code to do it. You fix bugs, not exploit them.
---
Antitrust ploy? (Score:2)
Showing that the Big Bad Microsoft can be defeated on something like this proves that they have competition. If they can prove that they have competition they can try and appeal any anti-trust decision against them.
Look for microsoft to "lose" a few more battles in the next couple of months, eg conceding to Apache etc.
It's not like Microsoft to give up so easily on something.
Then again they could just be scared.
Re:IM standards (Score:1)
moderation at slashdot is done by the masses. My personal solution is to just not give a shit, and set my threshold low.
It's not that the moderation system is inherently stupid. I think it's a great idea and pretty well thought out. In the end though, working pretty good most of the time isn't good enough for me to trust the moderation system.
Re:1 centralized network of IM clients is a bad th (Score:1)
This sounds like it would be a Good Thing for instant messaging.
On another note I basically agree that AOL servers should only be able to be accessed by AOL's members, but essentially wasn't this what Microsoft was trying to do? AOL's beef is that they want their software used, not microsoft's. That is perfectly reasonable for AOL to want that, but as a consumer I don't really want that.
What about TiK and TOC? (Score:1)
I know AOL didn't exactly make too many friends when they took down their Tik and TOC pages, but TiK and other clients like GAIM still work. Blocking all Unix based clients probably would generate bad press and make AOL look worse than they already do. But that is not to say I don't believe they wouldn't make such a stupid move.
Microsoft and Yahoo do want to use the extra feature of OSCAR but if it a choice between interoperating with AOL users with limited features or not working at all I would think they would choose the limited route. Of course since Tik and TOC are covered by the GPL Microsoft and Yahoo would have to release their source which may be the other problem. But again it would be better than nothing, right?
Re:TOC (Score:2)
AIM uses a protocol called Oscar. When people started clamoring for non-Windows clients, AOL engineered a compatible, but less feature-rich protocol called TOC. After its release, a plethora of non-Windows, AIM-compatible clients were developed.
Then Microsoft came along, reverse-engineered Oscar (ignoring the sanctioned interoperable protocol of TOC), and started getting a free ride for their client on AOL's servers. AOL claimed that because Microsoft was using *their* servers for MS' services with authorization, they had basically hacked into AOL's networks and proceeded to (apparently) use a buffer overflow exploit to detect AIM clients.
Re:IM standards (Score:1)
Your missing the point, i CAN send mail to that server, and people on that server can send mail back to me. The other server doesn't say, well that mail is coming from a netcom address so i'm not going to let him mail my people, that is stupid.
Actually, you're wrong on both points. I'm an XMission subscriber. You are not. If you attempt to connect to XMission's mail server and use it to send mail, it will refuse to let you connect to it because you are not a subscriber. And if you are on an ISP listed in the RBL, you will not be able to send mail to me because XMission's mail servers will not accept incoming mail from your ISP. XMission also blocks incoming mail from some other domains that they've had problems with, and if you're on one of those domains you won't be able to send mail to me.
Summed up: they're XMission's servers, XMission can and does decide who can send mail out and in through them. IM servers are the same.
Beat to the punch (Score:1)
80 mil users of AIM possible... (Score:1)
Re:IM standards (Score:2)
2 - The enemy of my enemy is still my enemy.
Server connections to AIM/ICQ (Score:2)
Re:Server connections to AIM/ICQ (Score:1)
If I'm an ICQ (or AIM in the Microsoft case) user, I'm going to be using the AOL server regardless of which client I use. This isn't about the AOL server - it's about the client and controlling the user base. Why do you think AOL bought Mirabilis? They're not going to give up control just because you say "please"!
Re:IM standards (Score:2)
Microsoft instead tried to hijack the AOL IM servers with a client not authorized to access the AOL servers. This wasn't an "open standards" attempt -- it was an attempt to use the AOL systems for free, without permission, and without even a token nod to providing reciprocal access (like publishing the specs that would allow AOL to enable its clients to access the Micrsoft messaging system).
Microsfot, in short, was cracking the AOL systems and using stolen access for its own benefit. While that may be understandable behavior in a teenager, a multibillion-dollar corporation should be slammed hard for it.
That isn't the only one... (Score:1)
<BINARY>
<DATA SIZE=12345(everything after five overflows...)>
</DATA>
</BINARY>
AIM users couldn't crash each other because AIM
would interpret the tags before they were sent, thus crashing the potential attacker. I'm sure a sophisticated user (e.g. someone not on AOL) could have smashed the stack and done some interesting things. I discovered and reported the bug and AOL actually fixed (although they never returned any email, news.com ran a story and got AOL to admit to it.)it quite fast. yay for me.
steveh@globaltelinc.net
AOL is exploiting their own buffer overflow. (Score:1)
The grammar of this sentence is confusing. Microsoft was using AOLs servers for Microsoft's instant-messanger product because it uses AOL's protocol to talk to other AIM users. AOL has tweaked their protocol a dozen times to prevent this, and each time, Microsoft tweaks their client to match. Finally, AOL decided to exploit a buffer overflow in their own client in order to prevent MS from being able to further tweak to be compatible.
I'm sorry, but I'd have to agree with MS on this one: AOL should open up their protocol and secure your clients. I'm not holding my breath though. It's pretty clear that AOL is only interested in security to the extent it affects their bottom line. Unless people just decide to give up on AIM and AOL and take their dollars elsewhere, this isn't going to hit their pocketbook, which is why AOL still hasn't fixed it. After all, consider the average AOL user. (Yes, there are a few intelligent people who use AOL. It's a little like saying "Yeah, there are a few intelligent people on Earth." Most people are idiots.)
--Joe--
Re:The exploit is there! (Score:2)
However, the Linux clients TiK and gAIM speak to TOC, which is an ASCII-based gateway to OSCAR. What prevents MSNM from talking to TOC?
Re:WE need a single IM system (WIM?) (Score:1)
IM really necessary? (Score:1)
I personally don't understand the need for IM software... email and IRC have done me well for the last few years and apart from a nice user interface, I see no advantage to IM apps...
am i missing something?
M@T
Re:WE need a single IM system...NOT (Score:1)
Let me clear up some things (Score:1)
AIM runs on AOL's servers. AOL's physical hardware. Microsoft is using *their* software (MSN Messenger) to send messages via AOL's hardware. That is, pretty much, hacking.
Look at it in another way. It's akin to using software to send email over your servers without your permission. It's an abuse of your system, it's an unauthorized use, and you'd do your best to track me down or stop me. Hence, AOL's actions against Microsoft.
While AOL has no excuse to exploit a buffer overflow in their clients, I feel they're certainly entitled to keeping the protocol secret and to prevent Microsoft from using AOL's hardware without permission.
Crazy Microsoft.. (Score:1)
Pretty good at blocking interoperability.
Has serious security bugs in software.
Microsoft Windows
Pretty good at blocking interoperability.
Has serious security bugs in software.
Yeah, Microsoft is one to talk.
--
No winners (Score:3)
-Yusuf Mehdi, director of marketing for Microsoft's Consumer and Commerce Group
I just love it when Microsoft talks about open standards. It just gives me that warm, embraced, cuddly, mushy, smothered feeling.
_______________________________
Re:IM standards (Score:2)
Imagine what the hub-bub would be if instead of AOL, MSN was the dominant ISP. Then this little company comes along and says "Hey we want open standards. AND we want to use your servers until those standards appear". How long do you think they would be in existance after that? MSFT would break them, buy them, or bankrupt them.
But this time, since they happen to be the underdog, they whine whine whine, and say they're the white knights riding in to save us from horrible AOL. Like I said earlier, if it were anyone but Microsoft, I might just believe them.
Re:IM standards (Score:1)
Hmm, is it even possible for a "universal" IM service to exist?? Given that it's not only a matter of what protocol you use, but also whether the *servers* allow you to connect, it seems that the most we can do is to achieve something similar to the current situation of IRC: same protocol, but different server networks.
But perhaps this isn't such a bad thing? Say, AOL's servers communicates with MS's servers, and both also communicate with ICQ servers, etc.. That way, although you're running off different servers, your messages can be transported across services. As long as the service providers can work out a common protocol amongst themselves, we don't even need a universal IM protocol for the clients -- the servers would be handling the inter-service communication.
I suppose there are technical difficulties in transporting messages across different IM protocols, but it seems to me at a first glance that this is no different from the Internet itself -- different network protocols for LANs, but each connected via WANs, routers, etc.. Wouldn't something analogous be possible for the existing IM services? eg. messages from one IM protocol gets translated to another IM protocol at a "bridge" (analogous to network bridges translating packets from one protocol to another). The analogy is rather compelling, don't you think? :-)
Re:Is the risk real? (Score:2)
This is a classic military-style manoever. Retreat, get the enemy to charge in, so you can encircle them. Much as I dislike them, it's sheer brilliance on Microsoft's part to use a manoever like that to destroy AOL.
Here's the scenario, as I perceve it:
Mind you, I might just have played too many wargames and seen Hannibal's utter destruction of the Roman legions too many times. :)
Re:It's all about the protocols, yeah (Score:2)
The IETF is already doing this. They have an "Instant Messaging and Presence Protocol" Working group. Check it out. [ietf.org]
Of course, they take a long time to get anything together, but standards engineering needs to be good.
-Ted
Re:WE need a single IM system (Score:1)
They're developing an OSS platform independent and decentralized server I.M. platform. With module interfaces to other I.M. systems it will also transparently work with ICQ, AIM etc, all from one client.
[OT] MS age is over (Was: Re:Antitrust ploy?) (Score:1)
I have mixed feelings about the antitrust case... OT1H it's good that clueless people (excuse the label) out there now understands that MS is not the ultimate when it comes to computers. OTOH what does the whole antitrust suit accomplish?!?! Breaking MS doesn't really do much, imposing fines doesn't reform their behaviour/practices. Besides, the MS age is over. With cases like this, where MS concedes defeat, and with the rise of Linux, the advent of Open Source, etc., all these seem to me like signs that the MS age is over (or at least, going to be over soon). Perhaps we'd all be better off if we'd just let MS be defeated "naturally" (ie. by competitors) rather than spend all that money on the anti-trust lawsuit, which probably won't accomplish that much anyway.
Re:IM standards (Score:1)
Jabber (Score:1)
Re:IM standards (Score:1)
I suggest you read http://maps.vix.com/tsi/ar-what.html [vix.com] before you make more of an ass of yourself.
Re:How many different messengers do we need anyway (Score:2)
Re:Is the risk real? (Score:2)
If MS can get rile enough people with a remote exploit of AIM, then perhaps these folks (angry users? Or if they managed to convince sysadmins that the risks were high enough to merit banning AIM from their networks...) will go in and finish the job.
By claiming that the reason they're backing off is to avoid replicating the security hole, they may be seemingly on the high ground, and diverting attention from the fact that it's AOL's servers that are involved, and AOL can arguably ban arbitrary networks from their servers at will.
Re:Jabber is shaping up (Score:3)
It's also the only system currently that will be able to support the IETF standard for an open namespace 'out of the box', simply becouse of it's design..
Re:1 centralized network of IM clients is a bad th (Score:2)
Re:1 centralized network of IM clients is a bad th (Score:2)
Re:It's all about the protocols, yeah (Score:1)
Try Everybuddy (Score:2)
----
Re:Try Everybuddy (Score:1)
Hmm, this raises an interesting thought... would it be possible that a universal IM protocol will be achieved ultimately by having clients like Everybuddy -- ie., a client that supports as many (if not all) IM protocols out there as possible? Then, when users realize this client would be compatible with whatever IM service they're already using, and also provides interoperability with other services, they would switch over. (Especially if it's an opensource client that can be obtained at minimal cost). Eventually, when most people are using this client, it could start to have its own protocol that encompasses all the functionality of the other protocols.
(Of course, this is a little like M$'s strategy of embrace - extend - exterminate, but if the client were opensource, it might be embrace - extend - celebrate (because everyone will be happy to finally have a single, universal IM protocol). :-> )
Re:TOC (Score:1)
I believe they do. That's half their arguement... after AOL made it public, MS and others started using it. I believe Yahoo tried the same, as did some company or client called something like "Tribal" (??)
If all they want to do is send messages to AIM users, TOC would work fine. The protocol was released by AOL, so they cant yell about MS using it.
Now AOL "claims" is was released so the Unix-based clients could be built using it.
American Online has worked hard (Score:1)