Diberdayakan oleh Blogger.

Popular Posts Today

Review: Brother's HL-3170CDW color laser-class printer is inexpensive, but graphics are mediocre

Written By Unknown on Senin, 22 Juli 2013 | 16.00

You want a color laser printer, but you don't have a lot of cash. How does $280 sound? That's the price of the Brother HL-3170CDW, and in exchange it delivers reasonably good prints. Not pristine, evocative color graphics—move on to another printer for that. But good text and decent spot color, it can do, and the toner costs are tolerable as well.

Here's the real decision: Do you pick this all-around-average machine, or do you pick this other, like-priced color laser, the Dell C1760nw, which has much better color quality—but also much more expensive toner? Or do you think a bit outside of the box and consider a business inkjet, such as the Epson WorkForce WP-4020, which competes head-to-head with both of these lasers on speed, print quality, and features, and whomps them both on cost of consumables? By our reckoning the latter is the best deal, but some people just can't get laser out of their heads, and they will have to think harder about the tradeoffs.

Bulky profile, basic features, and duplexing

Measuring 16.1 inches wide by 18.3 inches deep by 9.4 inches wide and weighing 39 pounds, the HL-3170CDW is fairly large and beefy for an entry-level, laser-class printer (it uses LED technology to produce basically identical results). The height is due more to the stacked toner/drum system than the bottom-mounted, 250-sheet paper cassette. There's also a 100-sheet output tray integrated into the top of the unit, and a single-sheet manual feed for envelopes and glossy photo paper. The unit prints automatically in duplex.

When some color printers run low on one color, they will complain, but keep printing. Not so with the HL-3170CDW: It will not print when you run out of any of the four colors. This can be a problem if you really, really need to print something and haven't any spare toner. Better a warning and a less-than-optimal printout, than no printout at all. Brother needs to rethink this.

There's no reason to make a big deal about control panels on single-function printers, as most people rarely use them after setup is over. (Multifunctions are another story.) But the HL-3170CDW's control panel could definitely use a dedicated menu button. Employing the OK button for this purpose is unintuitive and awkward, an unnecessary corner cut. Otherwise, the single-line monochrome LCD display and controls are easy enough. The HL-3170CDW's setup was a breeze. The unit sports USB, ethernet, and Wi-Fi connectivity. There's a full array of wireless and email printing features, including AirPrint, and both the PC and Mac driver dialogs offer a bevy of options.

Reasonably priced toner

After enjoying its initial purchase price, your ongoing costs for the HL-3170CDW will be, if not actually cheap, at least better than expected. Most low-cost color lasers hit you with high toner costs down the road. The HL-3170CDW's prices hover comfortably around the average—and are better than those of many of its competitors, though not as good as the above-mentioned Epson WorkForce WF-4020, whose inks are amazingly cheap. The unit ships with starter cartridges rated for a scant 1000 pages. Brother's price for the standard-size, 2500-page black is $85, or a midrange 3.4 cents per page (cpp). We found it online for closer to $70, or 2.8 cpp.

The standard-size, 1400-page cyan, magenta, and yellow supplies cost about $70 apiece per Brother—a middling 5 cents per color, per page. Our shopping found prices closer to $57 apiece, or just over 4 cents per color, per page. A page with all four colors (using the lower prices) would cost about 15 cents. Higher-capacity, 2200-page color cartridges are available, but they offer just a small savings in cost per page over their standard-size cousins.

Good speed for the price

Speed is good compared to other entry-level color lasers and business inkjets. The Brother HL-3170CDW spits out text and mixed monochrome pages at a lively 12.2 ppm on the PC and 11.2 ppm on the Mac. Snapshot-sized (4-inch by 6-inch) color photos printed onto letter-size paper at a brisk pace of 2.9 ppm, and full-page photos arrive at a spirited 1.4 ppm.

Fast means nothing if quality is inferior, and unfortunately, that describes the HL-3170CDW's graphics. Both monochrome and color artwork exhibited mild horizontal striations and vertical banding that were visible under light scrutiny. Worse, the color palette is overly light, and human faces look jaundiced. For a dab of color, a small picture, or the occasional, simple graphic, the HL-3170CDW's color quality will suffice, but not for much else. On the other hand, text is top-notch, and that's generally the larger part of the equation for the small or home offices that would consider this model.

A good choice for basic color printing

To its credit, Brother offers a little more than most competitors do. The warranty lasts only one year, but there's free phone support for as long as you own the product. Speed is excellent, and for text and spot color the HL-3170CDW's print quality is fine. Toner costs are around average. At this price point, it offers a decent color-laser experience without gouging you later. But if you want the best possible deal in this price range, a business inkjet delivers far more.


16.00 | 0 komentar | Read More

Researcher: SIM cards vulnerable to hacking

Millions of mobile phones may be vulnerable to spying due to the use of outdated, 1970s-era cryptography, according to new research due to be presented at the Black Hat security conference.

Karsten Nohl, an expert cryptographer with Security Research Labs, has found a way to trick mobile phones into granting access to the device's location, SMS functions and allow changes to a person's voicemail number.

Nohl's research looked at a mobile phones' SIM (Subscriber Identification Module), the small card inserted into a device that ties it to a phone number and authenticates software updates and commands sent over-the-air from an operator.

More than 7 billion SIM cards are in use worldwide. To ensure privacy and security, SIM cards use encryption when communicating with an operator, but the encryption standards use vary widely.

Nohl's research found that many SIMs use a weak encryption standard dating from the 1970s called DES (Data Encryption Standard), according to a preview posted on his company's blog.

DES has long been considered a weak form of encryption, and many mobile operators have upgraded now to more secure forms. It is relatively easy to discover the private key used to sign content encrypted with DES.

In its experiment, Security Research Labs sent a binary code over SMS to a device using a SIM with DES. Since the binary code wasn't properly cryptographically signed, it would not run on the device.

But while rejecting the code, the phone's SIM makes a crucial mistake: it sends back over SMS an error code that carries its own encrypted 56-bit private key, according to the company. Because DES is considered a very weak form of encryption, it's possible to decrypt the private key using known cracking techniques.

Security Research Labs did it in about two minutes on a regular computer with the help of a rainbow table, a mathematical chart that helps convert an encrypted private key or password hash into its original form faster.

With the private DES key in hand, it is then possible to "sign" malicious software updates with the key, and send those updates to the device. The device believes the software comes from a legitimate source and then grants access to sensitive data.

The company outlined an attack scenario against SIM cards that run some form of Java virtual machine, a software framework for Java applications.

Using the SIM's private key, an attacker could force the SIM to download Java applets, which are essentially very small programs that perform some function. Those applets would be "allowed to send SMS, change voicemail numbers, and query the phone location, among many other predefined functions."

"These capabilities alone provide plenty of potential for abuse," the company wrote.

Possible remedies to the problem including ensuring SIM cards use state-of-the-art cryptography and also using Java virtual machines that restrict applets' access to certain information.

Nohl's presentation, "Rooting SIM cards," will take place at the Black Hat security conference in Las Vegas on July 31.


16.00 | 0 komentar | Read More

US court renews permission to NSA to collect phone metadata

The Foreign Intelligence Surveillance Court has renewed permission to the U.S. government for a controversial program to collect telephone metadata in bulk.

The office of the Director of National Intelligence said the government filed an application with the FISC seeking renewal of the authority to collect telephony metadata in bulk, and the court renewed that authority, which expired on Friday.

The information was being disclosed "in light of the significant and continuing public interest in the telephony metadata collection program," and an earlier decision by DNI James R. Clapper to declassify certain information relating to the program, it said.

The secret court has been set up under the Foreign Intelligence Surveillance Act (FISA) which requires the government to obtain a judicial warrant for certain kinds of intelligence gathering operations. (

The Guardian newspaper published in June a copy of a secret April 25 order from FISC in Washington, D.C., which required Verizon to produce call records or telephony metadata on an ongoing daily basis until expiry of the authorization on July 19.

The requirement to turn in metadata applied to calls within the U.S., and calls between the U.S. and abroad, and did not cover communications wholly originating or terminating outside the U.S. Metadata was defined to include communications routing information such as session-identifying information, trunk identifier, telephone calling card numbers, and time and duration of calls.

The program does not allow the government to listen in on anyone's phone calls, and the information acquired does not include the content of any communications or the identity of any subscriber, Clapper said in a statement in June, which also confirmed the authenticity of the order published by the British newspaper.

The authorization required the production of telephony metadata under the "business records" provision of the FISA Act.

In response to the disclosure about the collection of phone data of Verizon customers, American Civil Liberties Union filed a lawsuit in June in U.S. District Court for the Southern District of New York, claiming that the "mass call tracking" by the U.S. National Security Agency was in violation of the U.S. Constitution's First Amendment, giving U.S. residents the rights of free speech and association, and the Fourth Amendment that protects against unreasonable searches and seizures. It asked the court to order an end to the tracking of phone records under the Verizon order or any successor order.

In a letter last week to Rep. Jim Sensenbrenner, the U.S. Department of Justice said intelligence tools that NSA uses to identify the existence of potential terrorist communications within the data "require collecting and storing large volumes of the metadata to enable later analysis." If the data is not collected and held by the NSA, the metadata may not continue to be available for the period that it "has deemed necessary for national security purposes" as it need not be retained by telecommunications service providers.

Internet companies like Google, Microsoft and Yahoo have been demanding for greater transparency in the orders of the FISC, after Edward Snowden, the former NSA contractor behind the leak of the Verizon order, also disclosed documents that suggested that the NSA has access in real-time to content on their servers. The companies have denied the claims, and want FISC to remove restrictions that prevent them from disclosing requests for customer data under FISA. Yahoo appears to have persuaded FISC to release its secret order and parties' briefs in a 2008 case. The court ordered the government recently to declassify the documents, as it prepares to publish the court's opinion in a redacted form.


16.00 | 0 komentar | Read More

US leads 'dirty dozen' of spam traffickers, Sophos study says

Written By Unknown on Minggu, 21 Juli 2013 | 16.00

Sophos has selected its "dirty dozen" of countries that relay spam for the second quarter of 2013, and the U.S. has taken the top spot.

With a population of more than 300 million people that makes up a large portion of the world's online traffic, Sophos security evangelist, Paul Ducklin, said it is no surprise that the U.S. is the leader.

"Remember that the Dirty Dozen doesn't tell us from where the spam originates," he said. "It tells us how spam gets relayed from the crooks to their potential victims."

Belarus has risen up to take the second spot, with Ukraine, Kazakhstan, and Argentina and making their debut as France, Peru, and South Korea drop from the list.

Ducklin warns that a law-abiding citizen in a law-abiding country may be contributing to the country's inclusion into the dirty dozen if the right security precautions are not undertaken on PCs. "It may sound corny, but security really does begin at home," he said.

As for what precautions people can take, Ducklin said it includes patching security loopholes, having an up-to-date antivirus solution, and being skeptical about unwanted attachments and suspicious offers.

spam

"By taking these steps, you'll not only protect yourself, but also help to protect everyone else at the same time," he said.

Although the dirty dozen lists ranks countries based on the amount of computers used for delivering spam, Ducklin admits that the location of spammers themselves could be entirely different.

"That's because most spam is sent indirectly these days, especially if it is overtly malevolent, such as phishing emails, malware links, malware deliveries, identity theft, investment scams, and advance fee fraud," he said.

Emerging tech markets such as China and India as rose up the dirty dozen list, with Ducklin attributing this to the large populations of the two nations and a growing demand for Internet access.


16.00 | 0 komentar | Read More

ICANN leader shares vision for growth and a global Internet

In his first year heading the Internet Corporation for Assigned Names and Numbers, Fadi Chehade has tried to establish a more international ICANN by opening hubs in Turkey, Singapore, Beijing, and Geneva.

Governments, meanwhile, have found a new role within ICANN, mainly in respect to the new generic Top Level Domains, while the traditional tussle between ICANN and the International Telecommunications Union (ITU) over who should govern and manage the global Internet seems to have lost some momentum.

Chehade replaced Rod Beckstrom as president and CEO of the international nongovernmental organization that oversees Internet standards. He sat down with the IDG News Service at the ICANN 47 meeting in Durban to answer questions about his first year in office. The following is an edited transcript of the interview.

IDGNS: How has ICANN improved in the last year?

Chehade: In the last year, we have done three main things; one, we have successfully changed the posture of ICANN, from an organization that was very centric towards Europe and U.S.A. (to an) organization that is embracing the rest of the world. We are moving a lot of our staff and resources from California to the new offices opening in Turkey, Singapore, Beijing, and Geneva.

The second thing we did is we grew ICANN staff; it's double compared to when I started in terms of resources and these resources will grow.

The third thing is that we have fundamentally changed our relationship with world organizations where we had contentious relationships. We cannot sit and shoot at each other, we have to come to mutual recognition that we cannot erase each other; we have distinct complementary roles.

IDGNS: The Internationalization of ICANN has been a thorny issue for ITU how is this changing?

icann logo

Chehade: In his opening ceremony speech at this meeting in Durban, Hamadoun Toure, ITU Secretary General, said that ICANN is becoming more international, and it was great to hear him say that. There are many international organizations we need to work with and this is a journey that starts with a posture change. Mahatma Gandhi said "our actions express our priority" and we should respect other organizations including ITU.

We are not a U.N. organization or a government organization and we must constantly find our legitimacy in a different way. And where does a transnational organization find its legitimacy? When it starts looking as if people are having a hard time participating in our meetings, then we are losing our legitimacy. I am focusing my efforts in the weakest points of our community.

When I started, I had three people who focused on global engagement and by next year June we will have 40; I tell them go spend time to meet government, academics, and businesses among other ICANN constituencies.

IDGNS: How has the role of governments evolved?

Chehade: The Government Advisory Council (GAC) is growing. We now have participation from 130 countries including countries like Iran. The technical community has not always viewed the role of government as constructive but the GAC advice is now well managed. We have to realize that governments have a role and if we don't recognize them we are breaking the multistakeholder model.

In cases where GAC shares advice that we feel will not work, we share our views and tell them why we think certain advice might not work. That is why GAC is growing in substance and number within ICANN.

IDGNS: The Registrar Accreditation Agreement has now been signed, what compromises were made?

Chehade: Some of the complaints were not substantive but were very important to me. For instance, I wanted a simple document that explained the rights and responsibilities of an end user. We managed to do this and it is now available as one page document on the website. The best part is that we had the interests of end users. It wasn't about ICANN regulating registrars; we made it clear that we had common goals and had to make compromises for the benefit of end users. In the end the process went faster.

IDGNS: The format of ICANN seems to have changed its format to include more young people.

Chehade: For years, ICANN meetings used to be about getting our work done but that has changed. We need to engage with different regions in work meetings and across cultures. We need more young people from Africa to speak and we need more African sessions. How can I go to a local university and meet with students? When we hold meetings in Latin America, Asia, Europe, and North America, we will try to make the meetings address the unique challenges in the region and this is how our public will find more value.


16.00 | 0 komentar | Read More

Does your IP address betray you to data-harvesters?

In today's world of hackers, stalkers, and cybercriminals, not to mention government spy programs and commercial sites that collect information about you for advertising purposes, is there a way to surf the Web and keep your privacy intact? Or does that mere fact that you have an IP address mean that your identity is out there for the taking?

Turns out, there's no easy answer to this question. (Watch the slideshow version.)

Legally, an IP address does not constitute personal identifiable information, according to two recent court cases.

In July 2009, in a case involving Microsoft, the U.S. District Court for the Western District of Washington ruled that IP addresses do not constitute personal identifiable information (PII). And in a separate case in 2011, the Illinois Central District Court also ruled that an IP address does not -- by itself -- qualify as personal information that can accurately identify a specific Internet user.

Shutterstock

Alan Webber, a research analyst at the Altimeter Group, agrees that "with the exception of law enforcement personnel who have other tools and methods to match IP addresses to a variety of sources (which provide additional information); at this time, an IP address, alone, cannot identify a specific person."

He adds, "However, when combined with other information, such as a user name, then yes, the IP address can reveal your identity."

Scott Crawford, managing research director at Enterprise Management Associates, explains that an IP address identifies a host on a specific network or subnet. That subnet may identify a set of logical addresses that can, in some cases, be associated with a physical location. For example, there could be an address range associated with ISP subscribers in a certain area.

Crawford emphasizes that when correlated to more specific information (such as address, browsing activity, or other data collected), during the course of online transactions; for example, the IP address can be associated with that activity or with a specific location. Although ISPs often assign addresses dynamically through protocols such as DHCP, it's not uncommon for a single, physical location (such as a home) to retain the same IP address for a long period of time. "Once the specific personal data is linked to the IP address, the activity associated with that address can be correlated accordingly," Crawford adds. (See also "The 5 biggest online privacy threats of 2013.")

Path to protection

Andrew Lee, CEO of London Trust Media, Inc./PrivateInternetAccess.com (a VPN service that protects users' privacy and identity), says linking users to their IP address is not simple, but it can be done. Many email providers, some IRC networks, extreme tracking sites, poorly configured forums, and design flaws in applications such as Skype and AOL (among others) have disclosed users' identities along with their IP addresses.

He adds that email providers have been known to leak IP addresses to advertisers, market researchers, and other such agencies and some emails (like those from mailing lists) are indexed by Google. "Thus, the IP becomes searchable," Lee says. "Programs such as skypegrab.info (now inactive), which reveals users' personal data are developed every day by programmers across the globe. Extreme tracking sites link IPs to Google searches and make them public. And business websites including, but not limited to, Facebook, Twitter, Google, and others—in addition to ad targeting companies—already have your personal info linked to your IP address in their databases. Anyone with access to those databases, including those with legitimate or illegitimate access (such as hackers), can obtain any and all of that information."

David Gorodyansky, CEO of AnchorFree's HotspotShield (an Internet security solution that includes anonymous browsing) agrees the IP address can be linked to a specific individual's name, address, and other personally identifiable information. According to Gorodyansky, hackers and malware programs attempt to compromise user identities by gaining access to their IP address and then tracking them on the web.  

"An IP is like your digital address," Gorodyansky says. "It provides intel on the city and state of the ISP location, which can be linked back to a residential address if accessing a Wi-Fi hotspot from home. Based on the IP address, companies and hackers collect information about individuals without knowing specific details such as their name. Third party websites and hackers can collect this data and, for example, use it to identify your name and steal or resell your identity and/or track your web browsing habits."

Surfers, beware

John Kindervag, a security and risk analyst at Forrester, says that the IP address can be tracked, but with some limitations. The IP header should not have any personal information in it. The mapping of the IP address is performed at the ISP level and, since there is no real user information in the headers, the assumption is that since person A lives at the location where the IP address is assigned, then person A created the traffic.

"This is a flawed assumption," Kindervag says. "Person A's network could be compromised, especially if it's wireless, to hide the identity of an attacker. Attackers always spoof their IP address, sometimes by using someone else's network and sometimes by going through a proxy server located in some other country. The attacker could live next door, but make his/her traffic look like it came from Eastern Europe."

According to Andrew Lewman, executive director at the Tor Project (a free anonymity online service), lots of companies use GeoIP databases to determine where a potential or actual customer is located in the world and then directs the marketing pitches appropriately. "Criminals also use GeoIP databases to target geographic areas for various malware attacks (English vs. French vs. Spanish languages, donation scams based on localized events). Child molesters and kidnappers can also use the IP address to track where a potential victim is located and further convince the victim that they are local and friendly," Lewman says.

"The greatest danger here, in my opinion, is from malware such as toolbars and other downloaded utilities that can secretly and systematically collect information and interfere with communications," cautions Andrew Frank, research vice president at Gartner. "IT professionals should prioritize malware prevention and home users should enforce basic rules about not opening unknown email attachments, how to identify suspicious sites, and regular use of a virus protection service. IT professionals concerned about this should talk to their ISP about proxy services and other privacy protection methods that may be available. And last, concerned citizens should support common-sense privacy options that give them choice and control over tracking and targeting, but should recognize that illegal tracking is unlikely to be curtailed by any new privacy laws."

How to mask your IP address

In addition to caution regarding how much personal information you disclose on the Internet, you can further protect your privacy by hiding or masking your IP address. The easiest and most effective solutions are anonymous proxy servers or VPN software and services. An anonymous proxy server functions as a liaison between your home network or computer and the Internet. It requests information, on your behalf, using its own IP address instead of yours, so only the proxy's IP address is revealed instead of your home IP address.

Lichtmeister/Shutterstock

VPN protection generally requires that you download a software product that works with the company's VPN services, which bounce your connections around the globe through various distributed networks. These virtual tunnels burrow through the Internet landscape creating a random path, which thwarts traffic analysis.

If you search for proxy servers,' VPN services,' or hide my IP address,' note that dozens of products are available; some free and some with fees. The Tor Project is a free "onion routing project" that was originally designed for the U.S. Naval Research Laboratory, which provides multiple privacy services including IP protection. Fee-based VPN products include Private Internet Access, Hotspot Shield, Banana VPN, Black Logic, and Unblock Us. Free proxy services include Hide My Ass and Mega Proxy, and fee-based services include Proxy Solutions and AllAnonymity.


16.00 | 0 komentar | Read More

The new Chrome App Launcher: Google's backdoor into the offline world

Written By Unknown on Sabtu, 20 Juli 2013 | 16.00

On Friday, Google gave Windows users something that they've been pining for: A Start button. And even better than that, Google's version keeps you on the desktop and actually opens a pop-up menu full of programs, unlike the nerfed Start button that's slated to appear in the Windows 8.1 update.

No, Larry Page hasn't decided to jump into the crowded Windows Start button replacement arena. Instead, Google's engineers quietly dragged Chrome OS's App Launcher—the Googlefied equivalent of a Start button—over to Chrome for Windows today. The seemingly simple addition is a major step in Google's push to bring Web standards to walled gardens.

Big things in little packages

The Chrome App Launcher is exactly what you'd expect: A taskbar icon that lets you quick-launch Chrome browser apps, such as Gmail, the Play Store, Angry Birds, and yep, even Chrome itself. Simple, right? But the little launcher is a Trojan horse for much bigger ambitions—especially when paired with packaged Chrome apps.

Packaged apps are available now, but since Google has yet to highlight them in the Chrome Web Store, you might not be familiar with them. Packaged apps are programs built on the bones of the Chrome browser. They use traditional Web languages such as HTML5 and CSS, but they run as separate, standalone software that can also be used offline, unlike traditional browsers.

You could consider packaged apps to basically be desktop Web apps, as odd as that sounds.

"For quite some time, we've had a dichotomy between Web apps and native apps, and one of the things that sets them apart is the ability [for native apps] to be launched from the desktop and have a degree of persistence and independence from the browser," says Ross Rubin, principal analyst at Reticle Research. "The availability of the Chrome App Launcher for Windows helps to further blur the line."

Hey, who put Chrome OS's Start button where my Windows Start button used to be? The apps without tiny arrows in their lower-left corner are all packaged apps.

With the arrival of packaged apps and the Chrome App Launcher, no longer will you need to connect to the Internet, open the Chrome browser, and launch the Web app you want to use. Now, there's a Web-app Start button right on your taskbar, and the packaged apps don't even require an Internet connection.

"Clearly, one of the missions of the whole Chrome initiative is to serve as an incentive for people to adopt HTML5 and create cross-platform or Web applications," says Rubin. "People want to interact with their Web apps as easily as they do with their desktop apps. Having the [Chrome App Launcher] available helps to ease the transition."

Each packaged app runs as its own instance, not as part of the main Chrome browser, as this look at several packaged apps in the Windows fast-switch interface shows. (Click to enlarge.)

It's made even easier by the App Launcher's Chrome tie-in. All your Chrome apps seamlessly travel with you to any Windows PC on which you've installed the Chrome App Launcher, even the locally stored package apps (though those take a few moments to download to new installations). Download a Chrome app once, and it's available anywhere.

What's more, the Chrome App Launcher lets you pin shortcuts for specific apps to the Windows taskbar or the desktop—mimicking native software functionality even further. It doesn't matter whether the app is packaged or a Web native, either. Blurring the lines, indeed.

Google gains

As a Web-focused company, Google gains whenever more people start using the Web more often. But beyond generally coaxing the world to Web services, Google has a direct interest in getting people in front of Google's Web services. That's the reason the Chrome App Launcher comes chock full of links to YouTube, Chrome, Gmail, Google Drive, Google Search, and the Chrome Web Store (whose third-party apps often include Google Ads).

"It looks like Google is defining the Chrome platform as what I'd call 'Web Platform Plus,'" says IDC's Hilwa.

More notably, though they may appear as standalone offline programs, packaged apps can work only if you have Chrome installed. Not only are they built on top of the browser, but some of the advanced features being packed into packaged apps—such as in-app payment support or the ability to play nice with Fitbits and iTunes libraries—come courtesy of proprietary Google APIs, not open Web standards.

That's a price you have to pay for running those apps closer to the metal, so to speak.

"[Packaged apps] provide APIs for accessing device capabilities, which is something that's been lacking in Web applications for browsers," IDC analyst Al Hilwa told TechHive earlier this year. "This brings web-app capabilities closer to the level of what some native platforms offer."

It also means that while the Chrome App Launcher is indeed a force to spur general Web adoption to traditionally offline platforms, packaged apps in particular are inextricably tied to Chrome—which, in turn, makes Google's browser-centric Chrome OS more appealing, too.

Creating Web app shortcuts with Chrome App Launcher. Hey, you're not supposed to be able to do that! (Click to enlarge.)

"It looks like Google is defining the Chrome platform as what I'd call 'Web Platform Plus,' and intends for Chrome OS and the Chrome browser to be a 'platform on a platform' on any device it is permitted to run on," Hilwa told PCWorld in a separate interview.

Yes, folks, between the App Launcher and packaged apps, soon every notebook can be a Chromebook, even if it's not a Chromebook. (The Chrome App Launcher was recently added to the OS X version of Chromium, the open-source version of the browser.)

Rubin sings a similar tune.

"The adoption of HTML5 and Web standards is the larger mission," he says. "But of course, Google wants Chrome and the implementations of Web technologies that it has bet on to be the means of access. By making available the Chrome rendering engine, Google can integrate the technologies it's endorsing or helping to develop, like the new Blink browser engine—particularly on Windows or OS X, where it helps further the implementation of those technologies where [Google] can't control the default browser."

In other words, the Chrome App Launcher is a way for Google to have its cake and eat it too. Google wants as many people as possible to embrace open Web standards, no doubt at least partially motivated by the desire to bring its services (read: ads) to as many eyeballs as possible. Open standards tend to be used by everyone, after all. But packaged apps bind their users to Chrome specifically, though Chrome is available far and wide and across multiple platforms.

That seems slightly ominous in the wake of Google's transition from the open Google Talk to the proprietary Hangouts protocol.

Bringing the Web to the desktop

But fear not: Chrome isn't going to devour the desktop and the Web overnight. Google hasn't even publicly published the Chrome for Windows App Launcher in the Chrome Web Store, and packaged apps are similarly obscured for everyone but developers. You need to have a direct link to find anything. Talk about obscure.

If you're interested in seeing what the low-key yet portentous hubbub is about, you can download the Chrome App Launcher here. Once that's done, head to Pocketables for a long list of direct links to Chrome packaged apps. Give some a whirl; it's so seamless, you'd never even know that you were helping to tear down the wall between the online and the offline.


16.00 | 0 komentar | Read More

Wall Street Beat: Software a bright spot as tech results bring gloom

Though software sales provided a ray of light in otherwise mixed results this week, gloom settled over the tech sector Friday in the wake of bellwether IT quarterly earnings reports.

The broad Standard & Poor's 500 Index managed to close Friday at a record high of 1,692.09, but the tech-heavy Nasdaq dropped 23.66 points to 3,587.61, and the Dow Jones industrial average declined 4.65 points to 15,543.89. Of the five tech stocks on the Dow, only Intel traded up slightly, while Microsoft, IBM, Cisco Systems and Hewlett-Packard were down.

"Overall I'd say the earnings confirmed some common themes—software is going to do better than hardware and services," said Forrester chief economist Andrew Bartels.

In Forrester's latest forecast for the global tech market, issued last week, Bartels lowered expectations for spending on IT goods and services to 2.3 percent growth measured in U.S. dollars, from the January estimate of 3.3 percent. Calculated in local currencies, the forecast looks better, at a 4.6 percent increase, but recession in Europe and slower growth in China is putting a damper on tech purchases by any measure.

IBM's earnings report on Wednesday was a good window into business tech spending and largely conformed to the big themes of the year, Bartels noted. IBM is considered a bellwether for the tech industry due to its geographic reach and giant portfolio of software, hardware and services. It is also the most heavily weighted stock on the Dow.

The company said second-quarter net income declined 17 percent from the year earlier to $3.2 billion, while revenue dropped 3 percent to $24.9 billion. Though services and overall hardware sales declined during the second quarter, company officials stressed strength in software and big systems.

Software sales totaled $6.4 billion, an increase of 4 percent year over year. Middleware, including WebSphere, information management, Tivoli and Social Workforce Solutions (formerly Lotus), generated $4.3 billion in revenue, up 9 percent.

The company's Global Technology Services segment, however, suffered a 5 percent decline in revenue to $9.5 billion. Revenue for the Systems and Technology unit, which includes hardware products, was $3.8 billion, down 12 percent.

The big disappointment of the week was Microsoft, which Thursday said it took a whopping $900 million charge in the quarter to reflect unsold inventory of its Surface RT tablets. As the sagging PC market curbs sales of Windows, Microsoft is having trouble making headway in the booming markets for tablets and smartphones.

Overall revenue for the company was $19.9 billion, up 10 percent year over year. Net income was $4.97 billion, or $0.59 per share, compared with a net loss last year of $492 million, or a loss per share of $0.06.

In keeping with the global trend for a strong software market this year, Microsoft's application sales were strong. The Microsoft Business Division, which includes Office, had a revenue increase of 14 percent year over year, while sales for the Server & Tools unit increased 9 percent, boosted by demand for SQL Server and System Center.

In a departure from the good news for software, however, SAP reported some sales weakness. The business applications giant said Thursday that quarterly revenue increased 4 percent to €4 billion (US$5.3 billion) year over year, while profit rose 10 percent to €724 million. But while software and software-related service revenue rose 6 percent year on year to €3.3 billion overall, revenue from software alone dropped 7 percent to €982 million.

One problem for SAP is that while it is pushing its HANA in-memory database platform as a market leader for new types of analytics and data-processing, some customers may not be ready to embrace it yet, noted Forrester's Bartels.

On the components front, Intel reported a decline in earnings and revenue as the slumping PC market continued to hurt sales. Intel net earnings for the quarter plunged 29 percent from last year to $2 billion, while revenue fell 5 percent to $12.8 billion.

The chip maker lowered its expectations for the year, forecasting sales to be flat, compared to its prior guidance for single-digit percentage growth.

Other tech giants reporting results this week included:

  • Google, which said second-quarter net revenue, excluding payments to ad partners, was $11.1 billion, up year over year from $9.2 billion, while net income rose about 16 percent to $3.23 billion, or $9.56 a share. The results missed analyst expectations of $11.33 billion in revenue and $10.78 earnings per share. While the company is working mobile ads into its offerings, growth in its desktop advertising business is slowing.
  • Yahoo, which reported a 46 percent increase in profit to $331 million. Revenue, however, was $1.14 billion, a 7 percent decline from last year. Though under CEO Marissa Mayer the company has tried to reinvent itself through acquisitions and has made efforts to control costs, it ultimately needs to boost sales to achieve real growth.
  • Nokia, which despite reporting strong sales of its Lumia smartphones, suffered a 24 percent decline in revenue to €5.70 billion (US$7.48 billion). The company's net loss, however, was €278 million, smaller than the year-earlier loss of €1.53 billion.

16.00 | 0 komentar | Read More

Internet traffic jams, meet your robot nemesis

On an 80-core computer at the Massachusetts Institute of Technology, scientists have built a tool that might make networks significantly faster just by coming up with better algorithms.

The system, called Remy, generates its own algorithms for implementing TCP (Transmission Control Protocol), the framework used to prevent congestion on most networks. The algorithms are different from anything human developers have written, and so far they seem to work much better, according to the researchers. On one simulated network, they doubled the throughput.

Remy is not designed to run on individual PCs and servers, but someday it may be used to develop better algorithms to run on those systems, said Hari Balakrishnan, the Fujitsu professor in Electrical Engineering and Computer Science at MIT. For now, it's churning out millions of possible algorithms and testing them against simulated networks to find the best possible one for a given objective.

IP (Internet Protocol) networks don't dictate how fast each attached computer sends out packets or whether they keep transmitting after the network has become congested. Instead, each system makes its own decisions using some implementation of the TCP framework. Each version of TCP uses its own algorithm to determine how best to act in different conditions.

These implementations of TCP have been refined many times over the past 30 years and sometimes fine-tuned for particular networks and applications. For example, a Web browser may put a priority on moving bits across the network quickly, while a VoIP application may call for less delay. Today, there are 30 to 50 "plausibly good" TCP schemes and five to eight that are commonly used, Balakrishnan said.

But up to now, those algorithms have all been developed by human engineers, he said. Remy could change that.

"The problem, on the face of it, is actually intractably hard for computers," Balakrishnan said. Because there are so many variables involved and network conditions constantly change, coming up with the most efficient algorithm requires more than "naive" brute-force computing, he said.

Figuring out how to share a network requires strategic choices not unlike those that cyclists have to make in bike races, such as whether to race ahead and take the lead or cooperate with another racer, said Balakrishnan's colleague, graduate student Keith Winstein.

"There's a lot of different computers, and they all want to let their users browse the Web, and yet they have to cooperate to share the network," Winstein said.

However, Remy can do things that human algorithm developers haven't been able to achieve, Balakrishnan said. For one thing, current TCP algorithms use only a handful of rules for how a computer should respond to performance issues. Those might include things like slowing the transmission rate when the percentage of dropped packets passes some threshold. Remy can create algorithms with more than 150 rules, according to the researchers.

To create a new algorithm using Remy, Balakrishnan and Winstein put in a set of requirements and then let Remy create candidates and try them against software that simulates a wide range of network conditions. The system uses elements of machine learning to determine which potential algorithm best does the job. As it tests the algorithms, Remy focuses on situations where a small change in network conditions can lead to a big change in performance, rather than on situations where the network is more predictable.

After about four to 12 hours, Remy delivers the best algorithm it's found. The results have been impressive, according to the researchers. In a test that simulated a fast wired network with consistent transmission rates across physical links, Remy's algorithms produced about twice the throughput of the most commonly used versions of TCP and cut delay by two-thirds, they said. On a simulation of Verizon's mobile data network, Remy's algorithms gave 20 percent to 30 percent better throughput and 25 percent to 40 percent lower delay.

But don't expect blazing page loads just yet. Balakrishnan and Winstein cautioned that Remy is still an academic research project.

For one thing, it hasn't yet been tested on the actual Internet. Though Remy's algorithms would probably work fairly well out there, it's hard to be sure because they were developed in simulations that didn't include all of the Internet's unknown variables, according to Balakrishnan. For example, it may be hard to tell how many people are active on a particular part of the Internet, he said.

If machine-developed TCP algorithms do end up going live, it will probably happen first on private networks. For example, companies such as Google already fine-tune TCP for the requirements of their own data centers, Balakrishnan said. Those kinds of companies might turn to a system like Remy to develop better ones.

But even if Remy never makes it into the real world, it may have a lot to teach the engineers who write TCP algorithms, Balakrishnan said. For example, Remy uses a different way of thinking about whether there is congestion than TCP does today, he said.

Though the researchers understand certain tools that Remy uses, they still want to figure out how that combination of tools can create such good algorithms.

"Empirically, they work very well," Winstein said. "We get higher throughput, lower delay and more fairness than in all the human designs to date. But we cannot explain why they work."

"At this point, our real aspiration is that other researchers and engineers pick it up and start using it as a tool," Balakrishnan said. "Even if the ultimate impact of our work is ... more about changing the way people think about the problem, for us, that is a huge win."


16.00 | 0 komentar | Read More

Symantec: Google Glass still vulnerable to Wi-Fi attack

Written By Unknown on Jumat, 19 Juli 2013 | 16.01

Google fixed one Wi-Fi security problem with its wearable computer Glass, but Symantec says there's another problem, which has been a long-known weakness in wireless networking.

The security vendor has been analyzing Google Glass in its labs and found a second issue that is just as harmful as the now-patched QR-code vulnerability found by Lookout Mobile Security, which was made public earlier this week.

Many Wi-Fi devices regularly look for networks that they have been connected to before, wrote Candid Wueest, a threat researcher for Symantec. The behavior is convenient for users, since they don't have to manually connect to a known network, he wrote.

But for as little as $100, a hacker can buy a device that impersonates the known Wi-Fi network by borrowing the network's name, known as its SSID (Service Set Identifier).

If a mobile device such as Google Glass looks for a known network with the SSID of "myPrivateWiFi," a device called the Wi-Fi Pineapple can respond, pretending it is the network.

Wi-Fi Pineapple is intended as a tool for security researchers. It sits between a targeted device and the Internet. Once it has tricked a Wi-Fi device into thinking it is the legitimate network, it can then spy on the data traffic.

If the traffic between a pair of Google Glasses and a remote server is unencrypted, an attacker using Wi-Fi Pineapple can view it, a major privacy and security problem known as a man-in-the-middle attack (MITM).

The issue isn't exclusive to Google Glass and could affect any device used, for example, by someone in a coffee shop. Savvy laptop and mobile phone users may be able to take steps to prevent data from leaking by using a VPN (Virtual Private Network). But the keyboard-less interface of Google Glass could make thwarting this style of attack more complicated.

In early June, Google fixed the vulnerability found by Lookout, which found that Glass would scan a QR Code instructing it to connect to a malicious Wi-Fi access point. Lookout, which told Google of the problem in May, then directed Glass to a malicious website that ran a known Android 4.04 vulnerability, which gave the security vendor complete control over the glasses.

Google issued several fixes, including one that required users to approve instructions contained in QR codes.

The fundamental problem of Wi-Fi devices looking for known networks isn't an easy one to solve, Wueest wrote. Devices could check a hardware identifier, called the MAC (Media Access Control) address, of a Wi-Fi router and match it with the SSID. But MAC addresses are easily faked, he wrote.

"The more practicable solution is to treat every network as hostile and ensure that all the applications use encrypted communications like SSL [Secure Sockets Layers] or tunnel through a VPN," Wueest wrote.

Google couldn't immediately be reached for comment.


16.01 | 0 komentar | Read More
techieblogger.com Techie Blogger Techie Blogger