Announcement

Collapse
No announcement yet.

Pc News

Collapse
This is a sticky topic.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Gates, Ellison Tout Security At RSA Event

    The annual RSA Conference, expected to draw 15,000 security professionals and more than 325 vendors from around the world to San Francisco's Moscone Center exhibit hall, kicks off this week with keynotes from industry luminaries Bill Gates and Larry Ellison.

    Microsoft Chairman Bill Gates, accompanied by Craig Mundie, chief research and strategy officer, is expected to tout the security of Microsoft's new Vista operating system, plus how e-commerce can improve if Web sites make use of the industry's new Extended Validation Secure Sockets Layer (EV SSL) certificate for authentication.

    The EV SSL certificate causes the visited Web site's URL address to glow green in the Microsoft Internet Explorer 7.0 browser to indicate the Web site is legitimate, not a phishing site. VeriSign and Entrust are the first public certificate issuers to make it available.

    So far, few sites other than PayPal are known to be making use of the EV SSL certificates, which require the certificate issuer to go to some effort to verify the identity and business affiliation of an individual requesting one.

    "We confirm every piece of information independently," says Tim Callan, director of product marketing at VeriSign, which in December began selling the high-assurance EV SSL certificates for US$995.

    VeriSign's more "general-purpose certificates," which don't display the green URL bar with the IE 7.0 browser and don't require the same investigative checking, cost $400. The drawback of conventional certificates is that they don't provide users with any effective warning and sometimes are issued without enough information about the certificate buyer's identity.

    Callan says that while Microsoft has the first browser to support EV SSL, the Mozilla Firefox and Opera browsers are expected to support EV SSL green-light authentication.

    Entrust this week plans to announce that it is selling EV SSL certificates for $495, in comparison with $159 for its standard SSL server certificate.

    While certificate-issuing organizations anticipate quick adoption of the more expensive EV SSL server certificates with their antiphishing "green-light-go" feature, some e-commerce companies say they're not in a hurry to use them.

    "We'll be evaluating the EV SSL certificate this year, but, no, we don't plan to use it right now," says John Millican, chief information security officer at online travel firm Expedia.

    Ellison's turn

    When Oracle CEO Ellison takes the stage at the RSA Conference for his keynote, his topic is expected to be identity management and Oracle's approach to providing customers with application and system-management administration, configuration, provisioning and monitoring.

    In addition, Oracle plans to announce this week Oracle Management Pack for Identity Management, server-based software used for network discovery, monitoring, service-level management and configuration of Oracle and non-Oracle products, including directories, authentication servers and provisioning software.

    The executive keynotes don't stop with Gates and Ellison. Conference attendees will also hear from Art Coviello, formerly CEO at RSA Security who became executive vice president at EMC and president of EMC's security division RSA after EMC acquired RSA last year; John Thompson, Symantec's chair and CEO; John Swainson, CA's CEO; Gene Hodges, CEO of Websense; and Stratton Sclavos, chair, president and CEO of VeriSign. In addition, RSA at the last minute has decided to add one more keynote speaker: Gen. Colin Powell.

    Beyond the RSA keynotes, the action at the conference will take place in the 220 conference sessions, which range from network-access control to mobile-phone malware to VoIP and encryption. There, corporate CSOs, vendors and independent experts can be expected to weigh in on what they think works, and what doesn't.

    Product launch pad

    The RSA Conference has become a launch pad for security products. Check Point is expected to have in the exhibit hall its line of UTM-1 appliances released this week, which integrate firewall, VPN and intrusion-protection systems. The Network World Lab Alliance, which took a look at the UTM-1 450 model designed to support 250 simultaneous users, provides a review.

    Also at the conference, network access control will make a splash with Tipping Point and NeoAccel both announcing their first NAC products and with NAC vendors Vernier and Mirage announcing compatibility with security products from Microsoft and IBM, respectively.

    TippingPoint is announcing a NAC Policy Server and Policy Enforcer elements that combines with its intrusion-prevention gear to continuously monitor traffic flows on the network and weed out those that are unauthorized. Pricing for the NAC gear has not been set.

    NeoAccel is introducing an appliance that can allow a device onto a network but then block if from running unauthorized applications.

    Comment


    • گزارش CNN در مورد يك ويروس جديد خطرناك
      ويروس جديدي كه* ازطريق پست الكترونيكي و در قالب يك دعوتنامه *ارسال مي*شود، كاربران اينترنت را تهديد مي*كند.


      به*گزارش ايرنا به نقل از CNN‬ اين ويروس جديد همراه با يك فايل ضميمه *تحت عنوان دعوت (Invantion) ‬در حال انتشار در شبكه اينترنت است.

      بر اساس اين گزارش، اين ويروس يكي از بدترين ويروس*هاي شناخته شده است كه در صورت باز كردن آن، هاردديسك رايانه مي*سوزد و اطلاعات حياتي و مهم آن از بين مي*رود.

      ويروس ياد شده *توسط كمپاني امنيتي مك*آفي شناسايي شده* و شركت مايكروسافت آن را به عنوان يكي از مخرب*ترين ويروس*ها رده*بندي كرده است.

      هنوز هيچ راه*حل و اصلاحيه*اي براي جلوگيري از فعاليت اين ويروس ارايه نشده است. اگركاربران اينترنت چنين پيامي از طرف دوستان خود دريافت كردند بلافاصله آن را بسته و سيستم رايانه خود را خاموش كنند.

      Comment


      • Teacher Faces Prison for Pop-Up Infested PC

        Have you ever faced a pop-up that wouldn't go away? You try clicking it closed and another pops up in less than a nanosecond. You reboot the system, annoyed that your anti-spyware program let something slip through.

        That's a hassle, sure--but chances are, your experience won't land you in jail.

        A Teacher's Worst Nightmare
        Julie Amero, a substitute teacher in Norwich, Connecticut, has been convicted of impairing the morals of a child and risking injury to a minor by exposing as many as ten seventh-grade students to porn sites.

        It's a short story: On October, 19, 2004, Amero was a substitute teacher for a seventh-grade language class at Kelly Middle School. A few students were crowded around a PC; some were giggling. She investigated and saw the kids looking at a barrage of graphic, hard-core pornographic pop-ups.

        The prosecution contended that she had used the computer to visit porn sites.

        The defense said that wasn't true and argued that the machine was infested with spyware and malware, and that opening the browser caused the computer to go into an endless loop of pop-ups leading to porn sites.

        Amero maintains her innocence. She refused offers of a plea bargain and now faces an astounding 40 years in prison (her sentencing is on March 2).

        Just the Facts
        I'll admit all my don't haves right away: I don't have access to court records; I don't have first-hand evidence of what occurred; and I haven't examined the computer's hard drive myself.

        What I do have is a working knowledge of spyware and plenty of experience cleaning infected PCs.

        I also have a copy of the report written by computer forensic specialist W. Herbert Horner, the expert witness who testified in Amero's defense. You can read it, too; it's on the NetQos site.

        Proof, Speculation, and a Not-Very-Good Defense
        Horner made an image of the computer's hard drive. He saw that there was no firewall and that the antivirus program was outdated. He also found 42 active "spyware/adware tracking cookie/programs." Most important, Horner said that 27 of the spyware apps were accessed before Amero had access to the computer.

        To me, the implication is clear that Amero hadn't used the PC for browse for porn, as the prosecution claimed.

        The defense wanted Horner to have Internet access at the trial in order to re-create what happened to Amero in the classroom. The prosecution objected, claiming they hadn't had ?full disclosure? of Horner's examination.

        In my opinion, had the defense attorney been on his toes, and had the jury seen the demonstration, Amero would have been found innocent.

        Guilty: The School or the Teacher?
        The question is, Who should be held responsible? After reading articles in the Norwich Bulletin, the area's local newspaper, and a chat with someone familiar with the case, I've come to some conclusions. (And if you've ever helped a computer novice deal with a PC loaded with spyware, I think you know who I'm siding with.)

        First, it would be a good idea to take a look at newspaper articles covering the trial. Read the January 5, 2007 article, the next on January 7, and the January 11 editorial supporting the conviction.

        Now, back to our story. To begin with, the prosecutor pointed his finger at Amero because she didn't turn off the computer right away.

        If I faced the same situation, I'd probably panic, just as Amero did--shield the kids from seeing the monitor and move them away from the computer. Then I'd reach over to an unfamiliar system, fumble around looking for the Off switch, and turn off the monitor, or computer, or both.

        I imagine Amero was also flustered because she was told by the class's regular teacher, quite adamantly, not to turn off the computer. That's a lame excuse, I agree, because questioning authority is sometimes the right thing to do.

        But I've learned from my source that Amero is a rank novice. About the most she can do is check e-mail on AOL using her husband's home computer. That says lots, no?

        For instance, when faced with the classroom PC's pop-ups, her reaction was to click the red "x" in the corner of each box--which, as anyone who's faced spyware knows, often results in another pop-up.

        More important, though, if the school had done its part in protecting its students, it would have up-to-date anti-spyware and antivirus programs installed on every PC.

        On January 24 the Norwich Bulletin reported that the school district's technology administrator, Information Services Director Bob Hartz, said, "from August to October 2004, the district's filtering system didn't regularly add newly discovered pornographic sites to its restricted Web sites database." Oddly enough, they upgraded the software just after Amero's incident.

        In my opinion, Amero is the victim here.

        The blogsphere has been following the story carefully, though the mainstream media hasn't picked it up yet. My guess is when it does, the bits will hit the fan.

        Malware: How It Happens
        Have you ever clicked on a browser message that looks legit and offers to, say, block spam or remove spyware? According to Sunbelt Software's spyware expert Alex Eckelberry, if you click on an innocent looking dialog, you could inadvertently install malware on your machine and end up with a PC that's infested with annoying pop-up ads that appear whenever you open your browser. Watch this YouTube video to see exactly how it happens.

        Comment


        • Google CEO: Internet's Role in Freedom Still Expanding

          The Internet has an ever-growing role to play in allowing free expression across the globe, but only if attempts to reign it in are unsuccessful, Google Inc. Chairman and CEO Eric Schmidt, said Tuesday.

          Schmidt, speaking in Washington, D.C., warned his audience that the Internet will continue to create public policy challenges as it's second billion users move online in the coming years. One reaction to a perceived loss of privacy and to new Internet users questioning repressive governments will be to clamp down on information, he said.

          "[That approach] appeals to people who prize order over everything else," said Schmidt, speaking at the Carnegie Endowment for International Peace's launch of a global think tank. "Those people exist everywhere."

          Schmidt acknowledged that a completely free flow of information over the Internet can be messy, but an unfettered Internet gives people the best information, he said. "The Internet has empowered people in a way we've never seen before," Schmidt said. "What we say at Google is, 'don't bet against the Internet'."

          In the coming years, governments will have to deal with a series of questions as more people come online, he said.

          The second billion Internet users will often compare the way their countries govern with other governments, he predicted. "They're going to see their government has been treating them badly," he said. "They're going to be annoyed."

          Some governments will struggle with how much free expression is too much, he said. Even in Western democracies such as France and Germany, posting information about the Nazi Party is prohibited, Schmidt said, and other governments will struggle with what expression to allow.

          Schmidt said he hopes governments will err on the side of freedom, but free expression will continue to be a hot debate in coming years. "Have we gained more freedom than we want?" he said. "Freedom of choice may be more choice than people want."

          And with computers able to store more and more information, governments will struggle with the idea of privacy, he added. Many people will eventually regret rants or photos put online 20 or 30 years earlier.

          "What happens to personal privacy when everything that's created exists forever?" Schmidt said. "My daughter calls this, 'too much sharing in your early life'."

          The Internet creates paradoxes, he said. It creates a global marketplace, but it also allows people to segment themselves into tribes, he said. It allows the truth to emerge faster than with other mediums, but it also allows users to spread false information. "If you don't like a piece of information, spread some information," he said of the attitude of many Internet users. "People here wouldn't do that."

          When he heard groans from the Washington crowd, Schmidt amended his statement. "I should say, people in this room wouldn't do that," he said.

          Despite the policy questions, Schmidt encouraged the audience to work for ways to open information up to more people across the globe. "Globalization is fundamentally about universal access to information," he said. "This information revolution that's coming can be shaped."

          Comment


          • Sony Ericsson Launches New Walkman Phones

            Responding to demand for ultra-thin designs, Sony Ericsson Mobile Communications AB has announced a new Walkman music phone -- its slimmest handset yet. The product is one of several announced Tuesday ahead of the 3GSM World Congress in Barcelona next week.

            The W880 packs music features into its 9.4 millimeter-thin mobile phone design: the handset comes preloaded with Walkman Player 2.0, Disc2Phone music management and TrackID music recognition applications. A 1G-byte Memory Stick Micro (M2) card, capable of storing up to 900 tunes, is included in the box.

            The handset also features a 1.8-inch QVGA, 262k TFT (thin-film transistors) display, a 2 megapixel camera and the Bluetooth Music Receiver MBR-100 system. This discreet accessory uses short-range wireless technology to stream music from the user's phone directly to a home or car stereo, using the phone as a remote control to alter the volume or skip through tracks.

            In addition, the phone provides a flight mode for use on airplanes and is equipped with a battery capable of playing music up to 20 hours or offering 6.5 hours of talk time.

            The W880 music phone is based on the GSM (Global System for Mobile Communications) standard and supports both the GPRS (General Packet Radio Service) and 3G (third-generation) technologies. It offers a range of communication services, such as a push e-mail, Web surfing and video streaming.

            Sony Ericsson will also provide a GSM variant of the Walkman music phone, the W88, without video telephony capability, for the Chinese market.

            A slightly larger Walkman phone, minus a few features, is the W610.

            The W880 music phone will be available in selected markets in the first quarter, with the W610 to follow in the second quarter. Prices were not available.

            Among the other new products is a series of low-end, easy-to-use handsets, which Sony Ericsson calls "candy bar" phones.

            The K200 phone has a camera and a central navigation key to give one-click access to key features. The K220, another camera phone, has an integrated FM radio, which can store up to 10 stations.

            The J110 and J120 phones, which lack a camera, offer large legible keys and easy navigation.

            Comment


            • Microsoft to Put Office in Windows Mobile 6

              For business users who want Microsoft Office on their cell phones, Windows Mobile 6, the upcoming version of Redmond's mobile operating system to be unveiled next week, will be a must-have upgrade.

              Mobile 6 comes with mobile versions of Outlook, Word, Excel and PowerPoint.

              With the continuing increase in sales of smartphones at the expense of handheld devices, Office makes a lot of sense, especially for synchronizing with desktop files, according to Rob Enderle, principal at the Enderle Group.

              Carriers and handset manufacturers who believe they can put the limited memory and storage to better use, however, are out of luck. Microsoft Office still comes with Mobile 6.

              According to John Starkwether, a product manager in the Mobile and Embedded Devices Division at Microsoft, Office is part of the package. Starkwether conjectured that if a vendor really wants to exclude Office from the operating system, an accommodation might be possible.

              Additional upgrades to the mobile OS include Microsoft's Direct Push Technology with automatic synchronization of Outlook calendars, tasks, and contacts using Exchange Server.

              For security and management, Mobile 6 will also give mobile network managers the capability of remotely wiping out all data from a device should it be lost or stolen. Other security features include certificate options and storage card encryption.

              Business users will also be pleased with the inclusion of mobile versions of the .Net Compact Framework and SQL Server in order to access a company's standard line of business applications remotely.

              The Office applications are the most robust to date for the limited capacities of a cell phone. Spell checking in Word, though, is not included.

              E-mail viewing will be easier on the eye with formatting, tables, and pictures viewable as originally generated.

              One-click options for e-mail, such as "reply all", moving a message to a subfolder and "delete" have been added to accommodate the restricted functionality of a small device.

              Windows Vista users on the desktop will be able to swap music, pictures, movies and Outlook information between the Vista PC and the mobile device.

              Windows Live will integrate mail, messenger, search, contacts, and spaces.

              Call history is now placed inside the individual contact card.

              Enderle said that although there was "a lot of great stuff" in Mobile 6 Microsoft still has to focus on ease of use.

              "Compared to the Apple iPhone with its simplified interface, Mobile 6 is still complex to use," Enderle said.

              Devices with Windows Mobile 6 will ship worldwide in the second quarter.

              Comment


              • Massachusetts Leads Retail Security Breach Probe

                Massachusetts Attorney General Martha Coakley will lead a civil investigation by dozens of states into the security breach disclosed last month by The TJX Companies Inc., the owner of T.J. Maxx and Marshalls retailers.

                The state's consumer protection division is looking into the data breach, "particularly what security measures the company took to protect consumer information," Coakley's office said in a statement yesterday. A Coakley spokeswoman, Emily LaGrassa, added that more than 30 states have asked for details on the TJX investigation or expressed interest in joining the probe.

                "It's pretty fluid at the moment," LaGrassa said today. "We don't have a time frame for concluding any investigation."

                TJX on Jan. 17 disclosed the security breach, in which one or more hackers penetrated the company's computer network and made off with a still-unspecified number of customer records, including credit card numbers. More than three dozen banks in Massachusetts, the home state of the Framingham-based company, have reported that cards they've issued have been compromised.

                Coakley characterized TJX as "very cooperative" in the investigation -- phrasing that her spokeswoman repeated. "They've been cooperative, and we continue to work with them," LaGrassa said.

                A TJX spokeswoman did not immediately return a phone call requesting comment on the investigation.

                "The recent TJX data breach demonstrates that Massachusetts citizens do not have all the necessary tools to protect themselves against identity theft or credit card fraud," Coakley said in her statement.

                Although the attack began in May 2006, the breach was not discovered by TJX until mid-December. The company said it delayed disclosing the intrusion until January so it could contain the problem and meet confidentiality obligations to law enforcement agencies.

                Fraudulent charges on stolen accounts have been reported in such far-flung places as Hong Kong and Sweden; TJX, however, has yet to confirm any direct impact. "TJX cannot address everything that others are reporting regarding the breach of our systems," the company said in an online FAQ on the break-in.

                Coakley, who took office last month as Massachusetts' first female attorney general, added that her office would work with the state legislature on efforts to mitigate any repeat of the TJX breach. "There are several proposals pending, including those that would require notification of consumers when their data was stolen or released, or that would give consumers the right to place a security freeze on their credit reports," said Coakley.

                Comment


                • Emergency Responders Ask Lawmakers for More Spectrum

                  Police and fire organizations called on the U.S. Congress to give them more radio spectrum for communications interoperability than the 24MHz they're due to get in early 2009.

                  Representatives of the International Association of Fire Chiefs and the International Association of Chiefs of Police on Thursday told a U.S. Senate committee that they need an additional 30MHz of spectrum. The government is scheduled to auction spectrum to commercial users as U.S. television stations abandon the upper 700MHz spectrum band in February 2009, under a law passed last year.

                  The additional spectrum would help public safety agencies deploy broadband communications systems that would fix the radio interoperability problems that plagued emergency workers following the Sept. 11, 2001, terrorist attacks, said Charles Werner, fire chief for Charlottsville, Virginia. Congress must act before the spectrum is auctioned to private companies in the next year, he said.

                  "I encourage Congress to take advantage of this very limited, one-time opportunity," Werner said. "We cannot suggest too strongly the urgent and identified need for broadband capability that public safety can use with assurance that it will work when needed, be available when needed, and is affordable."

                  But some members of the Senate Commerce, Science and Transportation Committee questioned the plan to put the additional 30MHz of spectrum into a public safety broadband trust.

                  The new spectrum plan, first advanced by Cyren Call Communications Corp. last April, could potentially cost the government billions of dollars in lost auction revenue, said Senator Ted Stevens, an Alaska Republican. The committee, in its DTV (digital television) transition bill, budgeted at least US$10 billion to be raised by the spectrum auctions, with $1 billion going to fund emergency communications interoperability efforts.

                  The Cyren Call plan is "impossible for us to do fiscally," Stevens said.

                  Stevens' criticism echoed the High Tech DTV Coalition, a group of technology vendors, which on Tuesday called on the Senate to stick to the original spectrum plan.

                  Cyren Call Chairman Morgan O'Brien said the company's plan calls for the broadband trust to raise $5 billion from private investors to pay for the 30MHz of spectrum. Private investors would pay for expensive public safety broadband networks, instead of Congress or local governments, he said.

                  Nearly all public safety organizations support the broadband trust concept, O'Brien added. "This is a crying out for help," he said. "We're sending men and women into dangerous situations every day, knowing their devices are inferior."

                  But the spectrum auctions could raise billions of dollars more than what the Cyren Call plan offers to pay, Stevens said. And Steve Largent president and CEO of CTIA, a trade group representing wireless carriers, questioned whether the broadband trust would find enough investors to fund a broadband wireless rollout for public safety, especially in rural areas.

                  Other senators suggested alternative approaches to the Cyren Call plan. Senator John Sununu, a New Hampshire Republican, suggested that public safety agencies could better use the 25MHz of spectrum they already have. Senator Maria Cantwell, a Washington state Democrat, said public safety agencies in her state and elsewhere are finding success using existing spectrum with radio over IP (Internet Protocol) devices.

                  This "boot-strap" approach using open standards and radio over IP could cost as little as $300 million across the U.S., as opposed to an average of about $1 billion per state using other equipment, said David Billstrom, chairman and CEO of public safety consulting group National Interop Inc. and a volunteer firefighter.

                  Comment


                  • House Gets New Pretexting Bill

                    Two U.S. representatives have introduced a law that would give the U.S. Federal Trade Commission the authority to investigate and prosecute imposters who gain access to other people's private telephone records.

                    The bill, introduced Wednesday by Representatives Jay Inslee, a Washington state Democrat, and Marsha Blackburn, a Tennessee Republican, comes in addition to a bill signed into law by President George Bush in January criminalizing the phone records scheme known as pretexting.

                    The new pretexting bill is important because the FTC has more expertise and interest in prosecuting identity theft cases than many local prosecutors, a spokeswoman for Inslee said.

                    Ken Springer, the founder and president of Corporate Resolutions Inc., a private investigations firm, applauded the pretexting legislation. State prosecutors have been targeting similar tactics to get personal bank records for about 10 years, and reputable private investigations firms haven't used pretexting for many years, he said.

                    "You've got to play by the rules," said Springer, a former special agent with the Federal Bureau of Investigation. "It's not a grey area. You can't use it."

                    Although corporate customers may demand that private investigators use all means necessary, Springer tells clients they should consider that the details of their investigations could wind up in the media. "The risk-reward [balance] is something they should consider," he said.

                    After a pretexting scandal at Hewlett-Packard Co. in late 2006, "corporate America got the message," he said. Still, the new pretexting bill can give customers faith that their records are protected, he said.

                    Inslee and Blackburn introduced a similar bill in January 2006, but it didn't come up for a vote on the floor of the House of Representatives. Their Consumer Telephone Records Protection Act would make it illegal for anyone to knowingly obtain confidential phone records by making false or fraudulent statements to a telephone company, or to knowingly sell or receive confidential phone records knowing such information was obtained fraudulently.

                    The bill would also require telephone companies to notify customers when their phone records fall into the wrong hands.

                    In January, Bush signed a law making pretexting illegal, punishable with up to 10 years in prison and fines. Fines and prison sentences would increase if the violations involve more than 50 telephone customers.

                    Congress began investigating pretexting in early 2006, after media reports and a complaint from privacy advocacy group the Electronic Privacy Information Center showed that several companies were selling private phone records online for less than US$100.

                    Then in September, HP revealed that investigators it hired had used pretexting to try to discover the source of board leaks. California prosecutors charged former HP board Chairwoman Patricia Dunn, former HP legal counsel Kevin Hunsaker, and three investigators with felonies late last year.

                    Comment


                    • Comment


                      • Study Provides Insight Into Hacks

                        A new study by the University of Maryland's A. James Clark School of Engineering shows the Internet wilds are still teeming with hordes of good old-fashioned brute-force attacks and quantifies how frequently machines are attacked and the methods used.

                        Michel Cukier, Clark School assistant professor of mechanical engineering and an affiliate of the Clark School's Center for Risk and Reliability and Institute for Systems Research, deployed four Linux systems with "weak security " on the Internet and sat back to watch.

                        Not surprisingly, the attacks came fast and furiously - averaging one every 39 seconds, or 2,244 attacks per day.

                        "The majority of attacks came from relatively unsophisticated hackers using dictionary scripts" ... running through "lists of common usernames and passwords," the school reported. Analyzing the attacks showed which usernames and passwords were tried most often and provided insight into what hackers tried once they gained entry.

                        "'Root' was the top user name guess by dictionary scripts - attempted 12 times as often than the second-place 'admin,'" the school reported. "Successful 'root' access would open the entire computer to the hacker, while 'admin' would grant access to somewhat lesser administrative privileges. Other top usernames in the hackers' scripts were test, guest, info, adm, mysql, user, administrator and oracle."

                        The research showed the most common password-guessing ploy involved playing off usernames. "Some 43% of all password-guessing attempts simply reentered the username," the school reported. "The username followed by 123 was the second most-tried choice. Other common passwords attempted were 123456, password, 1234, 12345, passwd, 123, test, and 1."

                        Once inside, the hackers did what hackers do, in this sequence: try to access the systems' software configuration, change passwords, check the software and hardware configuration again, download a file, install the downloaded program, and then run it.

                        The scripts returned a list of other systems the hackers might be able to access, and the hackers then busied themselves with that task, often installing backdoors so the compromised machines could be used in botnets.

                        The study concluded with the obvious, but it is always worth repeating: "Computer users should avoid all of the usernames and passwords identified in the research and choose longer, more difficult and less obvious passwords with combinations of upper and lowercase letters and numbers that are not open to brute-force dictionary attacks."

                        Security is a people, process and technology problem and the weakest link in the chain are the people. Putting in place stronger password requirements could save some agony.

                        Comment


                        • Xerox Works Deal to Rival Google

                          Xerox Corp. research subsidiary the Palo Alto Research Center has struck a licensing deal with a high-profile startup in the hopes of building a search engine that could one day rival Google Inc.

                          Powerset Inc. in San Francisco is developing a search engine based on natural language processing with the help of PARC, which has been working on technology in this area for 30 years, said Powerset founder and CEO Barney Pell. The search engine is expected to go live by the end of the year.

                          Powerset, which has raised US$12.5 million in funding from various venture capital firms and angel investors, has been negotiating with PARC to use the technology the research firm developed since September 2005, a mere month after Powerset was launched and a month before the company was incorporated in October, Pell said.

                          The startup even managed to win over top talent from PARC to join its team. Ron Kaplan, who led the PARC team that developed the natural language processing technology Powerset is licensing, is joining the company as its chief technology and scientific officer.

                          In addition to the licenses, Powerset also holds the patents to the technology, Pell said. In return, PARC receives equity in Powerset and royalties on company revenue. Powerset also is funding the natural language processing research team's efforts at PARC.

                          Pell described the difference between how a search engine powered by natural language processing technology and search engines available from Google Inc., Yahoo Inc. and others that depend on keywords work. He said the way many of the top search engines today index Web content is in keywords, but they don't have any idea what those words mean or how they relate to each other.

                          A search engine based on natural language, however, can accept queries written as people normally speak -- such as, "What company did IBM acquire in 1996?" Pell said. The results of the search should directly answer that question without giving a Web user every reference to the words "acquire," "IBM" and "1996" that have been indexed.

                          It's true the major Web search engines such as Google do question-and-answer type searches today, Pell said, but they are still mainly based on keywords.

                          Of course, researchers have been working for three decades to come up with successful natural language processing technology, and it has been no easy task, something that Pell himself acknowledges.

                          "Enabling computers to extract meaning and relationships in text ... is an incredibly hard problem," he said.

                          That said, to assume Powerset's search engine will work without a hitch is not necessarily a safe bet. However, Pell said that there have been recent breakthroughs at PARC in this area, and the software that Powerset has licensed should provide some of the highest-quality natural language processing-based search available.

                          Powerset is not the only company attempting to perfect natural language processing-based Web search. Hakia Inc. also is developing a search engine based on natural language processing. A beta of that engine can be found here. The Brainboost search engine, which is now a part of Answers.com, also is based on natural language processing.

                          Comment


                          • IPhone Likely Uses Arm Processors, Analysts Say

                            The guessing game continues over which processors Apple Inc.'s iPhone will use, with Arm Holdings PLC's top executive hinting the device will contain his company's intellectual property.

                            Warren East, Arm's president and CEO, was reported as saying the iPhone will have "at least three" Arm processor cores, according to the EE Times on Wednesday. Arm, based in Cambridge, England, licenses a variety of processor designs to other companies and manufacturers.

                            A spokesman with Arm's public relations agency in London said the report wasn't quite accurate but not inaccurate, either. The report was "based on speculation," and Arm was considering issuing a clarifying statement regarding the story, he said.

                            Apple's public relations agency said the few details about the iPhone were revealed by Apple CEO Steve Jobs in his MacWorld keynote speech on Jan. 9.

                            "We don't know anything," the Apple representative said on Friday.

                            When unveiling the phone, Apple's boss Steve Jobs said it will run OS X with special iPhone applications. Apple hopes to sell 10 million devices, which will retail for US$499 for a 4-G-byte model or $599 for an 8G-byte one.

                            Analyst firms including investment bank Friedman, Billings, Ramsey Group Inc. (FBR) have compiled lists of which manufacturers are likely contributing to the iPhone.

                            A day after Jobs' announcement, FBR said Samsung Electronics Co. Ltd. would likely provide an applications/video processor. Samsung licenses a range of processor technology from Arm.

                            Didier Scemama, a semiconductor analyst with ABN AMRO Bank NV in London, figures Arm cores going into three processors: the Samsung processor, a Wi-Fi chip from Marvel Technology Group Ltd. and GPRS/EDGE baseband chip from Infineon Technologies AG. Scemama wouldn't say how he came to his conclusions.

                            The use of three cores won't mean much for Arm, whose technology already goes in other mobile devices made by companies such as Nokia Corp., Scemama said. Other analysts agreed with Scemama's assessment.

                            "If Arm cores are common in phones and other small devices, why wouldn't they be found in the iPhone?," said Roger Kay president of Endpoint Technologies Associates Inc., an analyst company.

                            So why do people care so much about the slivers of silicon? For enthusiasts, it fuels speculation over the iPhone's performance before it hits U.S. shelves in June.

                            An Arm-based processor would mean OS X would have to be ported to a new platform. The OS already runs on Intel Corp.'s x86 and IBM Corp.'s PowerPC processors.

                            For others, it means the satisfaction of cracking the wall of secrecy Apple builds around it products months before the first device is cracked open with a putty knife.

                            "The only thing that makes it news is that Apple is so tight-lipped about its products, every little snippet of information is thought to be significant," Kay said.

                            Suppliers aren't supposed to reveal that their components are used in Apple products, Kay said. But as Apple has diversified its product line, its number of suppliers has increased, making leaks more prevalent and the monitoring of the suppliers harder, he said.

                            Comment


                            • Warner Chief Calls Jobs' DRM Fight 'Without Logic'

                              Warner Music CEO Edgar Bronfman Thursday rejected in no uncertain terms Apple Inc. CEO Steve Jobs' suggestion earlier this week that the major music label companies should abandon digital tunes copy protection.

                              Jobs' proposal, which the Apple executive floated on Tuesday in an open letter that called on the label companies to let users download tracks sans digital rights management (DRM) antipiracy protection, is "completely without merit," said Bronfman. His comments came in a Q&A portion of an earnings conference call Thursday.

                              "We advocate the continued use of DRM," said Bronfman. "The notion that music does not deserve the same protection as software, film, video games or other intellectual property, simply because there is an unprotected legacy product in the physical world, is completely without logic or merit."

                              Jobs said that Apple would drop its FairPlay DRM "in a heartbeat" if the major record labels would license their music without requiring copy protection schemes. In his letter, Jobs criticized the labels -- Warner, EMI, Sony and Universal -- for demanding DRM on music sold online at the same time that they sell billions of CDs containing unprotected tracks.

                              "So if the music companies are selling over 90% of their music DRM-free, what benefits do they get from selling the remaining small percentage of their music encumbered with a DRM system?" Jobs asked. "There appear to be none."

                              Bronfman was the first executive of a major recording company to publicly take on Jobs' idea. He urged Apple and the music industry to continue working together. "Frankly, manifestos in advance of those discussions is counter-productive," said Bronfman.

                              Comment


                              • Hidden Costs of a Windows Vista Upgrade

                                The shiny, new Windows Vista beckons, and an upgrade is mighty tempting. But before you take the plunge, be aware that you may end up forking out a lot more money than just the cost of an operating system upgrade. Here are 15 reasons to upgrade and here are 6 on why you should wait on Vista.

                                A lot more than just cash is on the line as well, because you may also spend plenty of time upgrading your hardware to make sure it's Vista-ready. Read on before you upgrade; being forewarned is being forearmed.

                                The High Cost of Hardware
                                If you're upgrading to Windows Vista, the first cash outlay you likely face is buying more RAM for your PC. Microsoft says that you can run Windows Vista with 512 megabytes of RAM, but don't believe it. It's simply not worth running Windows Vista on a machine with less than 1 gigabyte of RAM. In fact, you'd be a lot happier with 2GB.

                                How much will that much RAM cost you? Figure that you can get 1GB of RAM for as low as a little over $100, while 2GB will run you $180 and up.

                                Even if you have enough RAM, your existing graphics card may not be up to snuff, because Vista is graphics-hungry. If you want to run its Aero environment, you'll need a good graphics card.

                                There are two levels of Vista hardware compatibility: "Vista Capable," and "Vista Premium Ready." Forget Vista Capable; it won't run Aero, and if you can't run Aero, you shouldn't bother upgrading to Windows Vista.

                                So you need a graphics card that is Vista Premium Ready. To be Premium Ready, a PC needs a graphics card with support for DirectX 9 graphics with a WDDM driver, a minimum of 128MB of graphics memory, and what's called Pixel Shader 2.0 and 32 bits per pixel. There's no room in this story to delve into each of these specs, but the key is the support for DirectX 9 graphics with a WDDM driver, and a minimum of 128MB of graphics memory. Before buying a card, check the box or the manufacturer's site, and make that it matches these specs.

                                How much will such a card cost? It depends on how much graphics oomph you want. You can get a graphics card that meets these specs for as low as about $60. If you want better performance, of course, you can pay more, in the $100 to $150 range. But with graphics cards, the sky is the limit, and you can spend just about as much as you want until your pocketbook screams. As a practical matter, though, only gamers need the more expensive graphics cards; you don't need them merely to run Vista.

                                If you don't have a DVD drive, you'll need one, because Vista installs only via DVD. These days DVD drives are cheap; you can get a reasonable one for as low as about $30 to $40.

                                How about your hard disk? You should have a hard drive with a least a 40GB capacity, with 15GB of free disk space. But you'll certainly want a much bigger drive than that, to leave plenty of room for files and media. So you might need to add a new hard drive. Hard drives are cheap these days; for as low as $70 or $80, you can get one with a 250GB capacity.

                                How much will all of this cost you? Depending on what you need to install, you can get by with as little as spending only about $60 for a new graphics card, or up to $400 or more if you need to upgrade your RAM, graphics card, and hard disk, and also have to buy a DVD drive.

                                What's Your Time Worth?
                                You'll be spending more than just money if you upgrade to Windows Vista, of course--you may spend plenty of time as well. If you need to upgrade your hardware, count in the time it takes to do the upgrade. If you only need to upgrade your RAM, and all goes well during installation, you should need to spend only about 15 minutes. On the other hand, graphics card upgrades can sometimes be tricky, as can hard disk and DVD installations. If things go badly, you can spend hours troubleshooting and listening to bad music while you're on hold on tech support lines.

                                Finally, consider the time you'll spend upgrading to Windows Vista itself. Microsoft has done an excellent job with the Windows Vista installation process, and it's far easier and faster than previous Windows installs. So if you're going to merely upgrade over your existing version of Windows XP, it may take as little as 40 minutes with very little intervention on your part.

                                You may, though, opt instead for a clean install, which means that you'll wipe your hard disk clean, and then install Windows Vista. If you do that, you'll have to copy your data somewhere, and then after Vista installs, copy it back to your PC. And you'll also have to reinstall all your applications. This can take multiple hours if your PC has an extensive set of software.

                                The Bottom Line
                                So what's the bottom line for hidden upgrade costs? If you've got a relatively new system and opt to upgrade Vista over XP instead of doing a clean install, you may get away with not having to upgrade any hardware, or just need to add some RAM or a new graphics card. That won't put much bite on your pocketbook, and you won't lose your weekends, either.

                                On the other hand, if you need to do heavy-duty installation work and opt for a clean install, make sure you've got plenty of time--and cash as well.

                                Comment

                                Working...
                                X