Diberdayakan oleh Blogger.

Popular Posts Today

Ubuntu Tweak: After three days 'dead,' user outcry brings it back to life

Written By Unknown on Selasa, 23 Oktober 2012 | 16.00

There's nothing like absence to make the heart grow fonder, as the old saying goes, and that's apparently just as true for software projects as it is for people.

Case in point: Ubuntu Tweak.

Fans of Canonical's popular Ubuntu Linux distribution are probably already familiar with Ubuntu Tweak, which lets users modify not just the OS in general but the controversial new Unity desktop in particular, adding extra flexibility beyond what is offered in Ubuntu itself.

I've written about Ubuntu Tweak on a few occasions--most recently when the "Precise Tweak" version was launched back in April for Ubuntu Linux 12.04 "Precise Pangolin"--but last week, news about the software took a darker turn.

Specifically, rather than releasing a "Quantal Tweak" edition following Thursday's release of Ubuntu 12.10 "Quantal Quetzal," the Ubuntu Tweak project announced that it was shutting down.

'Not free any more'

"When you see this article, the development of Ubuntu Tweak is stopped," wrote developer Tualatrix Chou in a blog post on Friday.

"You may ask why I made this decision to stop the development of Ubuntu Tweak," Chou added. "I may write 10,000 words to describe how I start this project, how I feel happy from this project, how I feel bad from this project…But I just want to say: If making free software is not free any more, why still doing this?"

Chou's announcement inspired more than 275 comments, most of them lamenting the end of the project.

Ubuntu Tweak has been downloaded more than 3 million times since the launch of version 0.4.999 back in 2009, according to its Launchpad page.

'I don't really want to give up'

Monday, however, brought good news for Ubuntu Tweak fans.

The QuickLists Editor in Ubuntu Tweak 0.8.1 now works under Ubuntu 12.10 'Quantal Quetzal' (Click image to enlarge.)

"I would like to thank you all, who left your message here," Chou wrote in a new blog post  today. "I was really moved! You made me know that Ubuntu Tweak is still valuable, and as the first software project I made 5 years ago, it is just like my baby, I don't really want to give up the development."

Escalating development and maintenance demands had made the project come to feel overwhelming, Chou explained, particularly given that he also has another job. Canonical did not play any role in the decision, he added.

A new version debuts

Looking ahead, the pace of development on the software will slow down, Chou noted, but he wasted no time in introducing Ubuntu Tweak 0.8.1, which "works better on Ubuntu 12.10," he said.

Bottom line? Ubuntu fans looking for a degree of customizability not present in Ubuntu itself now get to keep this popular tool after all. To try out the latest version, you can download it for free from the Ubuntu Tweak site.


16.00 | 0 komentar | Read More

FTC: Companies should limit facial recognition in some cases

Web companies using facial recognition technology should avoid identifying anonymous images of consumers to someone who could not otherwise identify them, unless the companies have the consumers' consent, a U.S. Federal Trade Commission report said.

Companies using facial recognition software should also obtain consumer consent before using images or any biometric data in a different way than they originally represented when they collected the data, the FTC said in guidelines for the use of facial recognition software released Monday.

Users of the emerging technology should also develop reasonable security protections for the information they collect and sound methods for determining when to keep and when to dispose of information, the FTC report said.

"Fortunately, the commercial use of facial recognition technologies is still young," the FTC report said. "This creates a unique opportunity to ensure that as this industry grows, it does so in a way that respects the privacy interests of consumers while preserving the beneficial uses the technology has to offer."

Facebook, when rolling out its facial recognition feature in mid-2011, said it would help users tag photos of friends and family members. Privacy groups complained that the company was collecting new personal data without asking users for permission.

The use of facial recognition by Web companies, including Facebook, and government agencies, including the U.S. Federal Bureau of Investigation, has raised concerns from privacy advocates and some lawmakers. In July, U.S. Senator Al Franken, a Minnesota Democrat, said that legislation may be needed to limit the way government agencies and private companies use the technology.

In September, Facebook turned off its facial recognition feature for users in the European Union after privacy regulators there raised concerns.

A Facebook spokesman said the company was examining the FTC report, but didn't have an immediate comment.

The report recommends best practices for companies using or planning to use facial recognition software, the FTC report said. The best practices, where they go beyond existing legal requirements, are not intended to "serve as a template" for future FTC enforcement actions, the report said.

"If companies consider the issues of privacy by design, meaningful choice, and transparency at this early stage, it will help ensure that this industry develops in a way that encourages companies to offer innovative new benefits to consumers and respect their privacy interests," the report said.

The commission voted 4-1 to release the report, with Republican Commissioner Thomas Rosch dissenting. The report "goes too far, too soon," he wrote.

The report suggests companies should first get permission from consumers to use facial recognition software in a "broad swath of contexts," when opt-in permission may not be necessary, he added.

"I disagree with the adoption of 'best practices' on the ground that facial recognition may be misused," Rosch wrote. "There is nothing to establish that this misconduct has occurred or even that it is likely to occur in the near future."


16.00 | 0 komentar | Read More

Amazon Web Services outage takes out popular websites again

Just five months after storms took down Amazon-powered sites such as Instagram, Pinterest and Netflix, issues at Amazon's Northern Virginia datacenter gave Amazon Web Services customers fits on Monday.

The outage started around 2:11pm Eastern Time, and affects "a small number" of instances in Amazon Web Services's US-EAST-1 Region.

According to AWS' Service Help Dashboard, the Northern Virginia data center is experiencing "Degraded EBS performance in a single Availability Zone" that appeared to take down or severely degrade performance of sites including Reddit, Flipboard, Airbnb, and Github.

To be fair, Monday's downtime appears to be from actual issues with the servers themselves. June's disruption and an August 2011 incident at the same datacenter were due to power outages.

As of Monday night, Amazon said it restored normal performance to about half of the instances affected, although it did not say how long it would be before service was fully restored.

These downtime periods aren't just frustrating for companies providing the affected Web-based services; increasingly, it's becoming an issue for Internet users. A third of us now access a site that uses Amazon Web Services as its backend at least once a day, according to a recent DeepField Networks survey.


16.00 | 0 komentar | Read More

Wall Street Roundup: Mixed earnings prove tough quarter

Written By Unknown on Senin, 22 Oktober 2012 | 16.01

Some of the biggest names in tech reported quarterly earnings last week, and the resulting picture is not pretty. The main culprit for the weak earnings reported this week is a slump in the PC market, but uncertainty about the global economy is weighing down almost all sectors of IT.

Disappointing, or at best mixed, quarterly results were turned in this week by Microsoft, Google, Advanced Micro Devices, Intel, and IBM. Share prices of every one of those vendors declined Friday. The financial results, coupled with the uncertainty about the economy, has shaken confidence in tech. Even shares of the mighty Apple declined Friday by US$22.80 to $609.84.

The Nasdaq Computer Index dropped 41.16 points to 1569.96 Friday afternoon, a day after Google, AMD and Microsoft issued their earnings. While Nasdaq tech stocks are still up about 15 percent for the year, they were up 26 percent for the year a month ago.

Toward the end of the third quarter, moves by the U.S. Federal Reserve and the European Central Bank to prop up economic growth instilled confidence in market watchers. The Fed announced it would launch the so-called "QE3," a third round of "quantitative easing," buying mortgage bonds and possibly other assets until the unemployment picture looks better. For its part, the European Central Bank revealed details of a plan to use a stability fund to buy up short-term European debt. But since then, the reality of weak earnings reports has put a damper on the enthusiasm generated by the banks' actions.

Earnings reports

Microsoft's general manager for investor relations, Bill Keofoed, summed up some of the main issues confronting vendors on the company's earnings conference call Thursday: "We saw the overall PC market decline this quarter in advance to the launch of Windows 8 and in part due to competitive pressures and the challenging macroeconomic climate."

In other words, facing economic uncertainty as well as an upcoming flood of new PCs and tablets based on the new Windows OS, users put off purchases. For the quarter ending Sept. 30, Microsoft reported a 22 percent year-over-year decline in profit, to $4.47 billion, and an 8 percent drop in revenue to $16.01 billion. Part of the decline was due to Microsoft's move to defer the reporting of revenue for pre-orders of Windows 8. But there is no doubt that consumers themselves are deferring purchases. For the quarter, the Windows division reported sales of $3.24 billion, a whopping 33 percent drop from the same period in 2011.

However, sales of larger hardware systems by other vendors have also slumped this quarter, signaling hesitation on the part of large companies to make big purchases in the current economic climate. For example, revenue in IBM's systems and technology unit, which includes its hardware business, decreased by 13 percent year over year for the quarter ending Sept. 30. IBM, reporting Tuesday, said it generated $24.7 billion in revenue for the quarter, down 5 percent from the year-earlier period. Profit was flat at $3.8 billion. Sales slumped in the last month of the quarter, noted IBM Chief Financial Officer Mark Loughridge on the company's earnings call. While software did not suffer as much as hardware, there was not much to cheer about. Software revenue was $5.8 billion, down 1 percent year over year, while sales of middleware such as WebSphere, Tivoli and Lotus also dropped 1 percent, to $3.6 billion.

Chip vendors reports

The general decline in hardware sales has affected chip vendors. As expected, AMD Thursday reported that revenue declined due to both weak demand and lower selling prices -- a result of competitive pressure in a tough market. AMD earlier in the week put out preliminary results and Thursday's report confirmed the earlier figures. AMD total sales were $1.27 billion for the third quarter, dropping from $1.69 billion a year earlier, while the company reported a loss of $157 million. That compares with a profit of $97 million a year earlier. The company said it would lay off about 15 percent of its 11,813-employee workforce to cut costs and get back to profitability.

Intel, the world's biggest chip maker, said Tuesday that for the quarter ending in September, revenue dropped to $13.5 billion from $14.2 billion a year earlier. Profit also declined, to $2.97 billion from $3.47 billion.

"Our third-quarter results reflected a continuing tough economic environment," according to a succinct statement from CEO Paul Otellini. He did hold out some hope that ultrabooks, phones and tablets would help revive sales in the next few quarters.

Internet stocks stumble

It was also a tough quarter outside of the operating system, PC, and chip markets, however.

Google, facing its own set of business issues, said Thursday that net income for the third quarter was $2.18 billion, down from $2.73 billion a year earlier. Revenue was up 45 percent year over year, at $14.10 billion. But subtracting commissions and other fees paid to advertising partners, revenue was $11.33 billion, below the consensus expectation of $11.86 billion from financial analysts polled by Thomson Reuters.

Google faces rising costs as it bulks up its workforce, ramps up R&D and absorbs Motorola Mobility. At the same time, the price of paid clicks—the money Google charges advertisers when someone clicks on a search ad—fell 15 percent during the last quarter. Several analysts appear to be willing to give Google more time to absorb Motorola and make the transition to the mobile world.

 "While the mobile transition is taking longer than anticipated, we believe the long-term opportunity is intact," said Canaccord Genuity Internet analyst Michael Graham in a research note.

Earnings season is not yet over. Next week, for example, Apple and Facebook are due to report, and market watchers will be keen to see positive signs.


16.01 | 0 komentar | Read More

Tweets from the spies: Tool checks for data use and leaks

From Google Maps, the U.S. National Security Agency's parking lot has a larger footprint than the building itself. And for the high secrecy surrounding what goes on inside, there is plenty of information flowing just outside.

In a demonstration last week at the Breakpoint security conference, Roelof Temmingh, who founded the company Paterva in South Africa, showed how his company's application, called Maltego, can scoop up scattered online clues, quickly providing an insightful picture of individuals or organizations.

What Maltego does is quickly and succinctly draws on public data sources to put together a graphical digital footprint. Temmingh and four people developed Maltego, a made-up name with no special meaning, from a converted 105-year-old barn in South Africa.

Before his demonstration, Temmingh stressed that all of the information collected by Maltego is from public sources.

"No controls were broken to get to the information that we got," he said. "This is the information that's out there on the net. We just kind of put it together in a nice way."

Assembles disparate data

Maltego is highly efficient at quickly assembling digital crumbs and linking those pieces together, which would be tedious work otherwise. Temmingh used Maltego to search Twitter with coordinates for the vicinity of the NSA's parking lot. Twitter is capable of labeling messages with geo-location data, which then can be searched, although Twitter's geo-location API (application programming interface) isn't that accurate.

Roelof TemminghRoelof Temmingh

Temmingh pulled up a web of scattered tweets in Maltego. He picked out one person. First, he said it is prudent to check if the Twitter messages from a particular person actually fit in context of them being in certain place. For the person he chose, it appeared the person lived or worked in the area.

Then Maltego combed social networking sites, checking sources such as Facebook, MySpace, and LinkedIn. An identical photo linked the person's Facebook and MySpace page. From there, Maltego spotted more information. After a day of searching, Maltego discovered the person's email address, date of birth, travel history, employment, and education history.

"This is about a day's worth of digging around," Temmingh said. "It's not weeks and weeks."

Other interesting information can come from EXIF (exchangeable image file) data, which is information often embedded in a photograph that can include timestamps and the make and model of the camera or mobile device used to take a photo. The photos can be pulled from social networking sites.

With all of that information, it would be easy for an attacker to target the person with a convincing email, asking the person to click on a link causing malicious software to be downloaded to their computer.

Tech footprints

When used to analyze large organizations, Maltego makes it much easier to create detailed graphics of, for example, how a company's network is structured, the addresses of mail servers, IP address blocks and what providers support their internet connectivity. It shines a light on an organization's "attack surface," a term used describe the potential weaknesses in a network.

Interestingly, Temmingh has also pointed Maltego at North Korea. The country, which heavily restricts Internet access, has almost no Internet presence. Its attack surface is really small, resembling that of just one company.

The graphic of the country's networks in Maltego "fits on one page," Temmingh said. "There's nothing there to attack."

MaltegoThe open-source intelligence platform Maltego Radium gathers and maps data usage. (click to enlarge)

But the lesson isn't to withdraw from the Internet, which could invite other problems, such as impersonators. "You should choose what you expose really carefully. But you can't put nothing up there," Temmingh said.

Paterva is releasing a new version of its application, dubbed Maltego Radium, which allows people to run automated queries in a sequence. Maltego can perform some 150 kinds of queries, and the automation improves the speed at which information can be obtained and makes the application easier to use.

"We find that a lot of people find the entry point to Maltego really steep," he said.

Maltego's community edition is free to use. Paterva also has a commercial edition, which gets the latest updates immediately. The community edition gets the latest features about three months or so after they've gone in the commercial product.

The commercial edition costs $650 the first year, then $320 per year in subsequent years.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


16.00 | 0 komentar | Read More

Pacemaker hack can kill via laptop

Pacemakers from several manufacturers can be commanded to deliver a deadly, 830-volt shock from someone on a laptop up to 50 feet away, the result of poor software programming by medical device companies.

The new research comes from Barnaby Jack of security vendor IOActive, known for his analysis of other medical equipment such as insulin-delivering devices.

Jack, who spoke at the Breakpoint security conference in Melbourne on Wednesday, said the flaw lies with the programming of the wireless transmitters used to give instructions to pacemakers and implantable cardioverter-defibrillators (ICDs), which detect irregular heart contractions and deliver an electric shock to avert a heart attack.

A successful attack using the flaw "could definitely result in fatalities," said Jack, who has notified the manufacturers of the problem but did not publicly identify the companies.

In a video demonstration, Jack showed how he could remotely cause a pacemaker to suddenly deliver an 830-volt shock, which could be heard with a crisp audible pop.

Wireless risk

As many as 4.6 million pacemakers and ICDs were sold between 2006 and 2011 in the U.S. alone, Jack said. In the past, pacemakers and ICDs were reprogrammed by medical staff using a wand that had to pass within a couple of meters of a patient who has one of the devices installed. The wand flips a software switch that would allow it to accept new instructions.

Barnaby JackBarnaby Jack

But the trend is now to go wireless. Several medical manufacturers are now selling bedside transmitters that replace the wand and have a wireless range of up to 30 to 50 feet. In 2006, the U.S. Food and Drug Administration approved full radio-frequency based implantable devices operating in the 400MHz range, Jack said.

With that wide transmitting range, remote attacks against the software become more feasible, Jack said. Upon studying the transmitters, Jack found the devices would give up their serial number and model number after he wirelessly contacted one with a special command.

With the serial and model numbers, Jack could then reprogram the firmware of a transmitter, which would allow reprogramming of a pacemaker or ICD in a person's body.

"It's not hard to see why this is a deadly feature," Jack said.

His research is just beginning. The FDA, he said, just looks at the medical effectiveness of devices and does not do an audit of a device's code.

"My aim is to raise awareness of these potential malicious attacks and encourage manufacturers to act to review the security of their code and not just the traditional safety mechanisms of these devices," Jack said.

Data vulnerable, too

He also found other problems with the devices, such as the fact they often contain personal data about patients, such as their name and their doctor. Other tell-tale signs of sloppy code were also found, such as potential access to remote servers used to develop the software.

"The new implementation is flawed in so many ways," Jack said. "It really needs to be reworked."

Jack is developing "Electric Feel," an application with a graphical user interface that would allow a user to scan for a medical device in range. A list will appear, and a user can select a device, such as a pacemaker, which can then be shut off or configured to deliver a shock.

pacemakerA standard Pacemaker

As if this wasn't bad enough, Jack said it is possible to upload specially-crafted firmware to a company's servers that would infect multiple pacemakers and ICDs, spreading through their systems like a real virus.

"We are potentially looking at a worm with the ability to commit mass murder," Jack said. "It's kind of scary."

Ironically, both the implants and the wireless transmitters are capable of using AES (Advance Encryption Standard) encryption, but it is not enabled, Jack said. The devices also have "backdoors," or ways that programmers can get access to them without the standard authentication using a serial and model number.

There a legitimate medical need since without backdoors, you might have to "cut someone open," Jack said. "But if they're going to have a backdoor, at least have it embedded deep inside the ICD core. These are expensive devices."

Jack's presentation was beautifully illustrated in a comic-book like fashion. At one point, a slide showed a man who looked quite similar to former U.S. vice president Dick Cheney, who has long suffered from heart problems. The flaws in the device, Jack said, could mean an attacker could perform "a fairly anonymous assassination" from 50 feet away.

"To me, a laptop doesn't look like a device that is capable of killing someone," Jack said.

Or as an audience member added: "There's no muzzle flash with a laptop."

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


16.00 | 0 komentar | Read More

Office 365's college edition will be subscription-only

Written By Unknown on Minggu, 21 Oktober 2012 | 16.00

Microsoft has announced a version of its new Office suite for university students, and one of the most interesting aspects is that it will be sold only through a subscription license.

microsoft office 365

In other words, it won't be possible to buy Office 365 University by paying a flat, one-time fee for a perpetual license.

Instead, Office 365 University, scheduled for release in the first quarter, will be available for US$79.99 for a four-year subscription, and will give users the right to install the software to up to two Windows or MacOS computers. Whether they buy it in a store or online, users in the U.S. will download the product from Microsoft data centers and receive rolling, automatic software updates in the same manner.

The release underscores Microsoft's belief that the subscription model represents the future not only for businesses but also for its consumer products. While Microsoft has a longer track record of using this model in the enterprise, it is now starting to push it among consumers.

It remains to be seen whether consumers—in this case, university students, faculty and staff—will embrace this model, in which users pay for the right to use the software for a specific time period, usually a year, with the option to renew the license subsequently.

Change of Strategy

When it announced the new Office in July, Microsoft said that in addition to selling the suite via an upfront, perpetual license—the product branded Office 2013—it would also let people buy the suite as a subscription service, and gave this option the Office 365 brand.

When asked why buyers of Office 365 University are only getting the subscription option, a spokeswoman for Microsoft said via email that students—the target audience—are younger and thus more familiar with that model.

Office 365 University will include the new versions of Word, PowerPoint, Excel, OneNote, Outlook, Publisher, and Access.

By comparison, Office University 2010 comes with the current versions of those applications and costs $99.99 for a perpetual license.

Like the other versions of Office that have been announced, including Office 365 Home Premium and Office 365 Small Business Premium, Office 365 University is tightly integrated with Microsoft's SkyDrive storage service. A default setting to save files to SkyDrive is intended to make it easy for users to store documents online and then access them from other computers. The license includes 27GB of SkyDrive storage, and 60 Skype minutes per month.

University version specs

Office 365 University can save settings and preferences to the cloud and synchronize them across a user's different computers. A feature called Office on Demand will let users stream a full version of Office to PCs they don't own for use during one-time sessions.

Under an offer launched Friday, students who buy Office University 2010 or Office University for Mac 2011 will get Office 365 University free when it becomes available.

Office 365 University is not to be confused with Office 365 for Education, a suite of cloud-hosted collaboration server software that includes Exchange Online, SharePoint Online, Lync Online and Office Web Apps. It is hosted by Microsoft and sold to educational institutions, which then make it available to their users.

Juan Carlos Perez covers enterprise communication/collaboration suites, operating systems, browsers and general technology breaking news for The IDG News Service. Follow Juan on Twitter at @JuanCPerezIDG.


16.00 | 0 komentar | Read More

5 Silicon Valley tech companies we all want to work for

If only we could all live and work in Silicon Valley.  The New York Times reports that Evernote—the company behind the same-named app as well as others including Skitch and Penultimate—is giving its employees a fantastic perk: Housekeeping twice a month for everyone from receptionists to executives.

evernote

Anyone with a full-time job knows pulling off work-life balance isn't easy. "The workplace was built on the assumption that there was somebody at home dealing with the home front," Anne Weisberg, a longtime human resources executive and author on the subject, told The Times.

No kidding, but employee benefits can really help. Want more examples to covet? Here are four other Bay Area Internet companies that offer amazing perks we all wish we had.

Google

google logo

The search and advertising giant is widely known to offer some of the best employee benefits on the planet, including free gourmet meals, haircuts, legal advice, travel assistance, and much more.

And get this: If a U.S. Googler dies while working for the company, his or her surviving spouse or domestic partner gets a check for 50 percent of the person's salary every year for ten years. Google doesn't even impose a tenure requirement.

Facebook

facebook

In addition to free food prepared by professional chefs, Facebook employees get free laundry service, haircuts, photo processing, and dry cleaning, not to mention reimbursement for day care and fully-paid-for medical, dental, and vision coverage.

Not only that, the company gives four months of paid maternity leave plus forks over $4000 in "baby cash" to new parents to cover day care and adoption fees.

Airbnb

airbnb

It makes sense that the company that lets anybody rent out their couch for a night would encourage its employees to travel. Every employee gets $2000 a year to go anywhere on Earth—presumably staying with Airbnb hosts, you'd think.

They also can bring pets to work, enjoy organic lunches and yoga classes as well as play around with "Mustache Monday," or oddly, dress up for "Formal Friday."

Zynga

The gaming company's logo smacks of play and features the silhouette of a dog, and not just any dog. Zynga is actually named after the late bulldog of CEO Mark Pincus.

It follows, then, that the place would be canine-friendly, and that's an understatement if one has ever been made. The company encourages employees to bring their dogs to work, offers on-site grooming and even is building a dog park on the roof of its new headquarters, which, by the way, is dubbed "The Dog House."

In addition to hang-time with furry friends, Zynga also gives employees free massages, acupuncture and hair cuts as well as stock, cash bonuses and trips. Oh, and everybody can take as much vacation time as they want.


16.00 | 0 komentar | Read More

Team up to fight cyberattacks, US government official urges

Groups of companies in the same industry could pool infrastructure resources to help each other mitigate the effects of cyberattacks and work together on security issues, a senior official in the U.S. Department of Homeland Security suggested on Friday.

The comments by Mark Weatherford, deputy undersecretary for cybersecurity, come as a handful of American banks are dealing with a fourth week of DDoS (distributed denial-of-service) attacks on their websites.

Mark WeatherfordIDGNSMark Weatherford at the Bay Area Council

DDoS attacks are one of the simplest forms of cyberattack and seek to push websites offline by overloading them with junk traffic so they cannot handle legitimate requests from users.

The attacks have hit banks including Wells Fargo, U.S. Bancorp, PNC Financial Services Group, Citigroup, Bank of America, and JPMorgan Chase, and have been claimed by hackers in Iran.

"This has been an eye-opening experience for a lot of very, very large organizations," Weatherford said. "It's got a lot of people's attention. Not just the banks, but the ISPs and some of the other third-party providers as well."

Weatherford was speaking at a cybersecurity awareness conference in Santa Clara, California, that was organized by the Bay Area Council, a public policy advocacy group made up of local companies.

"How about developing a co-op kind of a model for these Web content delivery providers, like an Akamai or Prolexic or some of those folks, where you buy a bunch of servers, more than any one company might need at one time, but you co-op that for like-minded organizations and when someone needs that kind of service you point it at them and they have it available to them," he said.

"I can tell you, because these big banks have just gone through it, they did not have enough capacity, or they barely had enough capacity [because] no one was hurt too bad over the last couple of weeks, but we need to think about different ways of sharing resources among like-minded organizations," said Weatherford.

Weatherford said he made the suggestion at a cybersecurity forum held by the National Cyber Security Alliance in New York on Monday that included representatives of some U.S. banks in the audience.

He preceded his remarks on Friday by noting, "I have no idea if this is legal or conceptually even possible, but it's something to think about."

Martyn Williams covers mobile telecoms, Silicon Valley and general technology breaking news for The IDG News Service. Follow Martyn on Twitter at @martyn_williams. Martyn's e-mail address is martyn_williams@idg.com


16.00 | 0 komentar | Read More

Researchers say some Android apps have serious SSL vulnerabilities

Written By Unknown on Sabtu, 20 Oktober 2012 | 16.01

A team of researchers from two German universities has released a study asserting that many of the most popular free apps available through the Google Play store may be vulnerable to man-in-the-middle attacks -- seriously threatening user privacy.

RELATED: The 10 most common mobile security problems and how you can fight them

The researchers, from the Universities of Hannover and Marburg, studied the 13,500 most popular free apps on the Play store for SSL and TLS vulnerabilities. They found that 1,074 of the applications "contain SSL specific code that either accepts all certificates or all hostnames for a certificate and thus are potentially vulnerable to MITM attacks," according to a summary posted online.

Additionally, the scientists performed a manual audit of 100 apps for a more definitive look at potential security issues, finding that 41 were open to man-in-the-middle attacks because of SSL vulnerabilities. They said that the vulnerable apps could be exploited, allowing an attacker to steal highly sensitive usernames and passwords for Facebook, WordPress, Twitter, Google, Yahoo and even online banking accounts, among others.

Similar vulnerabilities, the team added, could be used to manipulate antivirus software on the phone, changing definitions to include benign apps or ensure that malicious ones are ignored.

"The cumulative install base of the apps with confirmed vulnerabilities against MITM attacks lies between 39.5 million and 185 million users, according to Google's Play Market. Actually Google's Play Market does not give a precise number of installs, instead giving a range. The actual number is likely to be larger, since alternative app markets for Android also contribute to the install base," the researchers wrote.

According to the H-Online, the team plans to make the code analysis tool it developed for the research public "in the near future."

Email Jon Gold at jgold@nww.com and follow him on Twitter at @NWWJonGold.

Read more about security in Network World's Security section.


16.01 | 0 komentar | Read More
techieblogger.com Techie Blogger Techie Blogger