Domain: computerworld.com
Stories and comments across the archive that link to computerworld.com.
Stories · 2,621
-
Google Patches 30 Chrome Bugs, Adds Instant Pages
JohnBert writes "Google patched 30 vulnerabilities in Chrome, paying out the third-highest bounty total ever for the bugs that outsiders filed with its security team. The company packaged the patches with an update to Chrome 13, adding Instant Pages to the 'stable' channel of the browser. The feature, which Google earlier tucked into Chrome 13 previews, proactively pre-loads some search results to speed up browsing. Google last upgraded Chrome's stable build in early June. Like Mozilla, which this year shifted to a rapid-release schedule, Google produces an update about every six-to-eight weeks. Fourteen of the 30 vulnerabilities patched were rated 'high,' the second-most-serious ranking in Google's four-step scoring system, while nine were pegged 'medium' and the remaining seven were labeled 'low.'" -
eBay Deploys 100TB of SSDs, Cuts Rackspace By Half
Lucas123 writes "eBay's QA division was facing mounting performance issues related to its exponential growth of virtual servers, so instead of purchasing more 15k rpm Fibre Channel drives, the company began migrating over to a pure SSD environment. eBay said half of its 4,000 VMs are now attached to SSDs. The changeout has improved the time it takes the online site to deploy a VM from 45 minutes to 5 minutes and had a tremendous impact on its rack space requirements. 'One rack [of SSD storage] is equal to eight or nine racks of something else,' said Michael Craft, eBay's manager of QA Systems Administration." -
eBay Deploys 100TB of SSDs, Cuts Rackspace By Half
Lucas123 writes "eBay's QA division was facing mounting performance issues related to its exponential growth of virtual servers, so instead of purchasing more 15k rpm Fibre Channel drives, the company began migrating over to a pure SSD environment. eBay said half of its 4,000 VMs are now attached to SSDs. The changeout has improved the time it takes the online site to deploy a VM from 45 minutes to 5 minutes and had a tremendous impact on its rack space requirements. 'One rack [of SSD storage] is equal to eight or nine racks of something else,' said Michael Craft, eBay's manager of QA Systems Administration." -
Windows XP PCs Breed Rootkit Infections
CWmike writes "Machines running the decade-old Windows XP make up a huge reservoir of infected PCs that can spread malware to other systems, a Czech antivirus company said. Windows XP computers are infected with rootkits out of proportion to the operating system's market share, according to data released Thursday by Avast Software, which surveyed more than 600,000 Windows PCs. While XP now accounts for about 58% of all Windows systems in use, 74% of the rootkit infections found by Avast were on XP machines. Avast attributed the infection disparity between XP and Windows 7 to a pair of factors: The widespread use of pirated copies of the former and the latter's better security. Vlcek assumed that many of the people running XP SP2, which Microsoft stopped supporting with security patches a year ago, have declined to update to the still-supported SP3 because they are running counterfeits." -
Windows XP PCs Breed Rootkit Infections
CWmike writes "Machines running the decade-old Windows XP make up a huge reservoir of infected PCs that can spread malware to other systems, a Czech antivirus company said. Windows XP computers are infected with rootkits out of proportion to the operating system's market share, according to data released Thursday by Avast Software, which surveyed more than 600,000 Windows PCs. While XP now accounts for about 58% of all Windows systems in use, 74% of the rootkit infections found by Avast were on XP machines. Avast attributed the infection disparity between XP and Windows 7 to a pair of factors: The widespread use of pirated copies of the former and the latter's better security. Vlcek assumed that many of the people running XP SP2, which Microsoft stopped supporting with security patches a year ago, have declined to update to the still-supported SP3 because they are running counterfeits." -
TN BlueCross Encrypts All Data After 57 Disks Stolen
Lucas123 writes "After dozens of hard disk drives were stolen from a leased facility in Chattanooga, potentially exposing the personal data of more than 1 million customers, BlueCross decided to go the safe route: they spent $6 million to encrypt all stored data across their enterprise. The health insurer spent the past year encrypting nearly a petabyte of data on 1,000 Windows, AIX, SQL, VMware and Xen server hard drives; 6,000 workstations and removable media drives; as well as 136,000 tape backup volumes." -
Sniffer Hijacks SSL Traffic From Unpatched IPhones
CWmike writes "Almost anyone can snoop the secure data traffic of unpatched iPhones and iPads using a recently-revised nine-year-old tool, a researcher said as he urged owners to apply Apple's latest iOS fix. If iOS devices aren't patched, attackers can easily intercept and decrypt secure traffic — the kind guarded by SSL, which is used by banks, e-tailers and other sites — at a public Wi-Fi hotspot, said Chet Wisniewski, a security researcher with Sophos. 'This is a nine-year-old bug that Moxie Marlinspike disclosed in 2002,' Wisniewski told Computerworld on Wednesday. On Monday, Marlinspike released an easier-to-use revision of his long-available 'sslsniff' traffic sniffing tool. 'My mother could actually use this,' he said." -
GE Bets On Holographic Optical Storage
Lucas123 writes "Years after announcing they had developed holographic optical disc technology that could store 500GB of data, GE this week said they're preparing to license the technology to manufacturing partners. At the same time, InPhase, which failed to actually get its holographic disc product out the door for years, says GE's product is nothing more than a 'science project,' and its own optical disc is almost ready to go to market — again. But, as one analyst quipped, the old joke about optical disc is that 'there's more written about optical disc than stored on it.'" -
Lawsuit Against Sony Highlights Cyber Insurance Shortcomings
CWmike writes "A brewing legal dispute between Sony and one of its insurers over data breach liability claims highlights the challenges that companies can sometimes face in getting insurance providers to cover expenses arising from cybersecurity incidents. Zurich American Insurance Co. asked the court last week to absolve it of any responsibility for defending or indemnifying Sony against claims arising from the recent data breaches at the company. The data breaches at Sony's PlayStation Network, Sony Entertainment Online and Sony Pictures resulted in account data on close to 100 million individuals becoming exposed and over 12 million credit and debit cards being compromised. The breaches have so far resulted in at least 55 putative class-action lawsuits being filed against Sony in the U.S and another three lawsuits filed against it in Canada. Sony expects to spend close to $180 million in the next year alone on breach-related costs. But analysts say insurance might not have even been worth it in Sony's case: 'There aren't many success stories where cyber insurance [has played] a significant role in reducing the cost of incidents,' said Gartner analyst John Pescatore. Um, better security as an insurance policy maybe?" -
Is Twitter Rendered Obsolete By Google+?
suraj.sun writes with a ComputerWorld piece predicting the end of Twitter, at least in its current form. From the article: "It's only a matter of time before Twitter becomes a ghost town. While Google+ will soon do all the things Twitter does, Twitter can't support a long list of the things Google+ supports. Also on Google+, you can post pictures and videos directly in posts, launch immediately into a video chat, send your posts to nonmembers and even present all your posts marked 'Public' as a blog available to anyone with an Internet." -
Amazon, Google Cave To Apple, Drop In-App Buttons
CWmike writes "Amazon bowed on Monday to Apple's newest App Store rules, and removed a link in its iPhone and iPad Kindle apps that took customers directly to its online store. The move was required to comply with new rules designed to block developers from evading the 30% cut that Apple takes from in-app purchases. In February, Apple CEO Steve Jobs laid down the law. 'Our philosophy is simple — when Apple brings a new subscriber to the app, Apple earns a 30% share,' said Jobs in a statement released Feb. 15. 'When the publisher brings an existing or new subscriber to the app, the publisher keeps 100% and Apple earns nothing.' Rhapsody updated its iPhone app last week to, among other things, remove the in-app subscribing link. Also on Monday, Google complied with Apple's new rules when it re-released Google Books — which had been yanked from the App Store — minus an in-app purchasing button." -
Amazon, Google Cave To Apple, Drop In-App Buttons
CWmike writes "Amazon bowed on Monday to Apple's newest App Store rules, and removed a link in its iPhone and iPad Kindle apps that took customers directly to its online store. The move was required to comply with new rules designed to block developers from evading the 30% cut that Apple takes from in-app purchases. In February, Apple CEO Steve Jobs laid down the law. 'Our philosophy is simple — when Apple brings a new subscriber to the app, Apple earns a 30% share,' said Jobs in a statement released Feb. 15. 'When the publisher brings an existing or new subscriber to the app, the publisher keeps 100% and Apple earns nothing.' Rhapsody updated its iPhone app last week to, among other things, remove the in-app subscribing link. Also on Monday, Google complied with Apple's new rules when it re-released Google Books — which had been yanked from the App Store — minus an in-app purchasing button." -
Oracle Ordered To Lower Damages Claim On Google
CWmike writes "Oracle has been ordered to lower its multibillion-dollar claim for damages in its patent infringement lawsuit against Google and its Android operating system, court papers show. Oracle's expert 'overreached' in concluding that Google owed up to $6.1 billion in damages for alleged infringement of Oracle's Java patents, U.S. District Court Judge William Alsup said Friday in a sternly written order. The 'starting point' for Oracle's damages claim should be $100 million, adjusted up and down for various factors, he said. At the same time, Google was wrong to assert that its advertising revenue is not related to the value of Android and should therefore not be a part of Oracle's damages, the judge wrote. He also warned Google, 'there is a substantial possibility that a permanent injunction will be granted' if it is found guilty of infringement." -
IBM Speeds Storage With Flash: 10B Files In 43 Min
CWmike writes "With an eye toward helping tomorrow's data-deluged organizations, IBM researchers have created a super-fast storage system capable of scanning in 10 billion files in 43 minutes. This system handily bested their previous system, demonstrated at Supercomputing 2007, which scanned 1 billion files in three hours. Key to the increased performance was the use of speedy flash memory to store the metadata that the storage system uses to locate requested information. Traditionally, metadata repositories reside on disk, access to which slows operations. (See IBM's whitepaper.)" -
Top General: Defense Department IT In "Stone Age"
CWmike writes "U.S. Marine Corps Gen. James 'Hoss' Cartwright, vice chairman of the Joint Chiefs of Staff, was sharply critical Tuesday of the Defense Department's IT systems and said he sees much room for improvement. the department is pretty much in the Stone Age as far as IT is concerned,' Cartwright said. He cited problems with proprietary systems that aren't connected to anything else and are unable to quickly adapt to changing needs. 'We have huge numbers of data links that move data between proprietary platforms — one point to another point,' he said. The most striking example of an IT failure came during the second Gulf War, where Marines and the Army were dispatched in southern Iraq, he said. 'It's crazy, we buy proprietary [and] we don't understand what it is we're buying into,' he said. 'It works great for an application, and then you come to conflict and you spend the rest of your time trying to modify it to actually do what it should do.'" -
NAND Flash Better Than DRAM For PC Performance
Lucas123 writes "Adding NAND flash memory to a PC does more for performance than DRAM and costs less, according to a new study. As the price difference between the two memory types widens, NAND flash will become the memory of choice in the PC. The effects of NAND flash adoption are already being felt in the DRAM market, as revenue in 2011 is expected to decline 11.8%." -
Apple Finally Approves Google+ App For iPhone
CWmike writes "Apple approved the Google+ app for the iPhone on Tuesday, and posted it to the App Store. It's unclear whether Google has created an iPad-specific app. Two weeks ago, a Google employee said that the company had submitted Google+ to the App Store ... on July 4. According to that timeline, Google's app took twice as long as the majority of submitted apps to win Apple's approval." -
Apple Finally Approves Google+ App For iPhone
CWmike writes "Apple approved the Google+ app for the iPhone on Tuesday, and posted it to the App Store. It's unclear whether Google has created an iPad-specific app. Two weeks ago, a Google employee said that the company had submitted Google+ to the App Store ... on July 4. According to that timeline, Google's app took twice as long as the majority of submitted apps to win Apple's approval." -
Outgoing Federal CIO Warns of 'IT Cartel' In DC
CWmike writes "In a wide-ranging discussion Friday with President Barack Obama's top science advisors, Federal CIO Vivek Kundra warned of the dangers of open data access and was sharply critical of government IT contracting, telling the committee: '...We almost have an IT cartel within federal IT' made up of very few companies that benefit from government spending 'because they understand the procurement process better than anyone else.' He added: 'It's not because they provide better technology.'" -
EU Considers Strict Data Breach Notification Rules
JohnBert writes "The European Commission is examining whether additional rules are needed on personal data breach notification in the European Union. Telecoms operators and Internet service providers hold a huge amount of data about their customers, including names, addresses and bank account details. The current ePrivacy Directive requires them to keep this data secure and notify individuals if such sensitive information is lost or stolen. Data breaches must also be reported to the relevant national authority. 'The duty to notify data breaches is an important part of the new E.U. telecoms rules,' said Commissioner Neelie Kroes. 'But we need consistency across the E.U. so businesses don't have to deal with a complicated range of different national schemes. I want to provide a level playing field, with certainty for consumers and practical solutions for businesses.'" -
HTC Infringed Apple Patents, Says ITC's Initial Determination
CWmike writes "A judge at the U.S. International Trade Commission has made an initial determination that HTC infringed two Apple patents, HTC said late Friday. If the judgment is made final, HTC could be banned from importing phones to the U.S. It's the latest blow to Google's Android operating system, which is being attacked by competitors including Apple, Microsoft and Oracle. The initial determination will now be reviewed by a larger panel of ITC judges, who can uphold or reject it. The two patents appear to be fundamental to Android, according to Florian Mueller, a patent expert. 'They are very likely to be infringed by code that is at the core of Android,' he wrote in a blog post. The same patents are also at the heart of a dispute between Apple and Motorola, he said." -
HTC Infringed Apple Patents, Says ITC's Initial Determination
CWmike writes "A judge at the U.S. International Trade Commission has made an initial determination that HTC infringed two Apple patents, HTC said late Friday. If the judgment is made final, HTC could be banned from importing phones to the U.S. It's the latest blow to Google's Android operating system, which is being attacked by competitors including Apple, Microsoft and Oracle. The initial determination will now be reviewed by a larger panel of ITC judges, who can uphold or reject it. The two patents appear to be fundamental to Android, according to Florian Mueller, a patent expert. 'They are very likely to be infringed by code that is at the core of Android,' he wrote in a blog post. The same patents are also at the heart of a dispute between Apple and Motorola, he said." -
Banks' Big Upgrade: Meet Real-Time Processing
CWmike writes "It has been years since the banking industry made any large investments in core IT systems, but some of the largest financial services firms in the U.S. are now in the midst of rolling out multi-million dollar projects, say industry experts. About a decade ago, they began replacing decades-old Cobol-based core systems, with open, Web-enabled apps. Now, they are spending more than $100,000,000 to replace aging systems, converting to real-time mobile applications for retail services such as savings and checking accounts and lending systems. The idea behind going real-time: Grab more business — and money — from customers. 'Five of the top 20 banks are engaged in some sort of core banking replacement and we expect to see another three or four in next 12 months,' said Fiaz Sindhu, who leads Accenture's North American core banking practice. 'They're looking at those upgrades as a path to growth.'" -
IBM Donates Symphony Code To Apache Software Foundation
CWmike writes "Hoping to further sharpen OpenOffice's competitive viability against Microsoft Office, IBM is donating the code of its Symphony open source office suite to the nonprofit Apache Software Foundation. Apache could fold this code into its own open source office suite OpenOffice, on which Symphony was based. In June, Oracle donated the OpenOffice suite to Apache. 'Prior to Apache's entry, there really hasn't been enough innovation in this area over the past 10 years,' said Kevin Cavanaugh, an IBM vice president. 'It's been constrained because we haven't had a true open source community with a mature governance model.'" -
IBM Donates Symphony Code To Apache Software Foundation
CWmike writes "Hoping to further sharpen OpenOffice's competitive viability against Microsoft Office, IBM is donating the code of its Symphony open source office suite to the nonprofit Apache Software Foundation. Apache could fold this code into its own open source office suite OpenOffice, on which Symphony was based. In June, Oracle donated the OpenOffice suite to Apache. 'Prior to Apache's entry, there really hasn't been enough innovation in this area over the past 10 years,' said Kevin Cavanaugh, an IBM vice president. 'It's been constrained because we haven't had a true open source community with a mature governance model.'" -
Google+: Tools, Names, and Facebook
Several readers submitted stories about Google+ today. CWMike writes in with an article about the lack of developer APIs from Computerworld "Currently, external developers don't have any Google+ APIs or tools to tinker with. A Google spokeswoman said, 'We definitely plan to involve developers and publishers in the Google+ project, but we don't have specific details to share just yet. Please stay tuned.' The spokeswoman declined to say specifically if Google+ will be compatible with the company's OpenSocial set of common APIs for social networking applications." Anita Khanna writes "Facebook is trying real hard to block users migrating to google+. Although the recently announced Google+ social platform is still in private beta, it has generated enough excitement to have Facebook making some preemptive measures. Shortly after the announcement, Facebook made a peculiar change to their TOS that resulted in the ban of popular Chrome extension Facebook Friend Exporter. Over the weekend, another personal data migration tool, Open-Xchange, has also been deactivated." Finally, an anonymous reader notes that Google is requiring real names for profiles, and may have already suspended some users for using aliases. -
Microsoft Yanks Security Site Poisoned With Porn
CWmike writes "Microsoft disabled the search tool on its Safety & Security Center on Saturday after attackers poisoned results with links to pornographic URLs. The company restored the website's search field early Monday afternoon ET. Alex Eckelberry, the general manager of GFI Software's security group and CEO of Sunbelt Software, said search poisoning is not unusual — but this is different. 'This is crafty,' Eckelberry said. 'This isn't normal search poisoning. It's poisoning the results with actual searches. Users were getting back a prior search as a search result.'" -
IT Crises vs. Vacation: Sometimes It Isn't Pretty
CWmike writes "It's true that IT systems have become essential to business operations, but the successful functioning of the IT department shouldn't rest on any one person's shoulders. All told, vacations serve as mini tests to prove if a department can function when key players are away. That's the theory, anyway. In reality, IT departments sometimes flunk. The results can either be comical or turn out to be a serious wake-up call to organizations that need a better Plan B. To prime your mental pump before your own vacation, Computerworld compiled anecdotes about good vacations gone bad." -
Microsoft: No Botnet Is Indestructible
CWmike writes "No botnet is invulnerable, a Microsoft lawyer involved with the Rustock take-down said Tuesday, countering claims that another botnet was 'practically indestructible.' Richard Boscovich, a senior attorney with Microsoft's Digital Crime Unit said, 'If someone says that a botnet is indestructible, they are not being very creative legally or technically. Nothing is impossible. That's a pretty high standard.' Instrumental in the effort that led to the seizure of Rustock's command-and-control servers in March, Boscovich said Microsoft's experience in take-downs of Waledac in early 2010 and of Coreflood and Rustock this year show that any botnet can be exterminated. 'To say that it can't be done underestimates the ability of the good guys,' Boscovich said. 'People seem to be saying that the bad guys are smarter, better. But the answer to that is 'no.''" -
Google Wrestles With Privacy Bugs In Google+
CWmike writes "Google's new social networking site, Google+ — built to beat Facebook primarily on privacy features — has several privacy bugs the company is working to fix. While some enthusiastic beta testers clamor for Google to open the social networking site to everybody now, it's clear Google needs to address these issues before launching Google+ more broadly. Stumbling right out of the gate over privacy problems would likely doom Google+'s chances of emerging as a viable, realistic rival to Facebook, which rules the social networking market with about 700 million account holders. So far, beta testers have been mostly positive about Google+, particularly over its design to make it easier for users to share posts and content with different sets of people, as opposed with their entire list of contacts. Many of the existing privacy bugs in Google+ revolve around the site's mechanism to block users, according to this published list." -
Google Wrestles With Privacy Bugs In Google+
CWmike writes "Google's new social networking site, Google+ — built to beat Facebook primarily on privacy features — has several privacy bugs the company is working to fix. While some enthusiastic beta testers clamor for Google to open the social networking site to everybody now, it's clear Google needs to address these issues before launching Google+ more broadly. Stumbling right out of the gate over privacy problems would likely doom Google+'s chances of emerging as a viable, realistic rival to Facebook, which rules the social networking market with about 700 million account holders. So far, beta testers have been mostly positive about Google+, particularly over its design to make it easier for users to share posts and content with different sets of people, as opposed with their entire list of contacts. Many of the existing privacy bugs in Google+ revolve around the site's mechanism to block users, according to this published list." -
@Whitehouse Hosting Twitter Town Hall On Wednesday
CWmike writes "In another milestone, the White House will hold its first Twitter town hall forum on Wednesday. President Barack Obama, known for using technology and Web 2.0 tools since his presidential campaign, will answer Twitter users' questions (submit them here) in a live webcast about the U.S. economy and jobs at 2 p.m. Eastern time on Wednesday. Twitter co-founder and Executive Chairman Jack Dorsey will moderate a conversation between Obama and Twitterers across the country. Twitter users can submit questions using the hashtag #AskObama. Some questions will be taken up in advance and others will be grabbed real-time during the event, Twitter said. In a blog post, Twitter executives said a conversation about the U.S. economy will fit right in with regular Twitter activity." -
@Whitehouse Hosting Twitter Town Hall On Wednesday
CWmike writes "In another milestone, the White House will hold its first Twitter town hall forum on Wednesday. President Barack Obama, known for using technology and Web 2.0 tools since his presidential campaign, will answer Twitter users' questions (submit them here) in a live webcast about the U.S. economy and jobs at 2 p.m. Eastern time on Wednesday. Twitter co-founder and Executive Chairman Jack Dorsey will moderate a conversation between Obama and Twitterers across the country. Twitter users can submit questions using the hashtag #AskObama. Some questions will be taken up in advance and others will be grabbed real-time during the event, Twitter said. In a blog post, Twitter executives said a conversation about the U.S. economy will fit right in with regular Twitter activity." -
Why Are There So Few Honeycomb Apps?
Fudge Factor 3000 writes "PC World's Brent Rose investigates the reason behind the dearth of Honeycomb apps even though the OS was released in February with the release of the Xoom. One would have expected an explosion of Android tablet apps like that seen with the iPad but the Honeycomb-optimized apps remain in the low hundreds. The answer, it turns out, is not that simple. The main contributing factors appear to be the low demand for Honeycomb tablets and the difficulty in discovering Honeycomb-optimized apps in the Market. Hopefully, this will be rectified in the near future." -
Microsoft Says Reinstall Overkill In Removing Rootkit
CWmike writes "Microsoft has clarified the advice it gave users whose Windows PCs are infected with a new, sophisticated rootkit dubbed Popereb that buries itself on the hard drive's boot sector, noting Wednesday that a complete OS reinstall is not necessary. 'If your system is infected with Trojan:Win32/Popureb.E, we advise fixing the MBR using the Windows Recovery Console to return the MBR to a clean state,' MMPC engineer Chun Feng wrote in an updated blog entry. Feng provided links to instructions on how to use the Recovery Console for Windows XP, Vista and Windows 7. Once the MBR has been scrubbed, users can run antivirus software to scan the PC for additional malware for removal, Feng added. Several security researchers agreed with Microsoft's revisions, but a noted botnet expert doubted that the advice guaranteed a clean PC. But an internationally-known botnet expert disagrees. Joe Stewart, director of malware research at Dell SecureWorks, said, 'Once you're infected, the best advice is to [reinstall] Windows and start over ... [MBR rootkits] download any number of other malware. How much of that are you going to catch? This puts the user in a tough position.' MBR rootkit malware is among the most advanced of all threats." -
IBM Creates Multi-Bit Phase Change Memory
Lucas123 writes "In what is likely to be a strong rival to NAND flash memory, IBM today announced it has been able to successfully store more than one bit of data per cell in a more stable non-volatile memory called phase-change memory (PCM). Unlike NAND, Previously, PCM couldn't contend with flash because of its low capacity points. PCM does not require that data be erased before new data is written to it, which reduces write amplification or wear out and it has 100 times the write performance of flash. IBM researchers say they plan to license the technology to memory manufacturers instead of producing it themselves." -
Massive Botnet "Indestructible," Say Researchers
CWmike writes "A new and improved botnet that has infected more than four million PCs is 'practically indestructible,' security researchers say. TDL-4, the name for both the bot Trojan that infects machines and the ensuing collection of compromised computers, is 'the most sophisticated threat today,' said Kaspersky Labs researcher Sergey Golovanov in a detailed analysis on Monday. Others agree. 'I wouldn't say it's perfectly indestructible, but it is pretty much indestructible,' Joe Stewart, director of malware research at Dell SecureWorks and an internationally-known botnet expert, told Computerworld on Wednesday. 'It does a very good job of maintaining itself.' Because TDL-4 installs its rootkit on the MBR, it is invisible to both the operating system and more, importantly, security software designed to sniff out malicious code. But that's not TDL-4's secret weapon. What makes the botnet indestructible is the combination of its advanced encryption and the use of a public peer-to-peer (P2P) network for the instructions issued to the malware by command-and-control (C&C) servers. 'The way peer-to-peer is used for TDL-4 will make it extremely hard to take down this botnet,' said Roel Schouwenberg, senior malware researcher at Kaspersky. 'The TDL guys are doing their utmost not to become the next gang to lose their botnet.'" -
Massive Botnet "Indestructible," Say Researchers
CWmike writes "A new and improved botnet that has infected more than four million PCs is 'practically indestructible,' security researchers say. TDL-4, the name for both the bot Trojan that infects machines and the ensuing collection of compromised computers, is 'the most sophisticated threat today,' said Kaspersky Labs researcher Sergey Golovanov in a detailed analysis on Monday. Others agree. 'I wouldn't say it's perfectly indestructible, but it is pretty much indestructible,' Joe Stewart, director of malware research at Dell SecureWorks and an internationally-known botnet expert, told Computerworld on Wednesday. 'It does a very good job of maintaining itself.' Because TDL-4 installs its rootkit on the MBR, it is invisible to both the operating system and more, importantly, security software designed to sniff out malicious code. But that's not TDL-4's secret weapon. What makes the botnet indestructible is the combination of its advanced encryption and the use of a public peer-to-peer (P2P) network for the instructions issued to the malware by command-and-control (C&C) servers. 'The way peer-to-peer is used for TDL-4 will make it extremely hard to take down this botnet,' said Roel Schouwenberg, senior malware researcher at Kaspersky. 'The TDL guys are doing their utmost not to become the next gang to lose their botnet.'" -
Supreme Court To Weigh In On Warrantless GPS Tracking
CWmike writes "In a move with far-reaching privacy implications, the U.S. Supreme Court has decided to hear a case involving the government's authority to conduct prolonged GPS tracking of suspects in criminal cases without first obtaining a court warrant. The government has argued that it has the authority to conduct such searches; privacy advocates have argued that such tracking violates Fourth Amendment protections against unreasonable search and seizure. The Supreme Court's decision in the case will be pivotal because lesser courts around the U.S. have appeared split on the issue in recent years, with some upholding warrantless GPS tracking and others rejecting it. Last August, the U.S. Court of Appeals for the District of Columbia circuit sided with the subject of the Supreme Court hearing, Antoine Jones, a Washington, D.C. man who was convicted in 2008 on charges of possessing and conspiring to distribute more than 50 kilograms of cocaine, and rejected claims by the government that federal agents have the right to conduct around-the-clock warrantless GPS tracking of suspects." -
Rootkit Infection Requires Windows Reinstall
CWmike writes "Microsoft is telling Windows users that they'll have to reinstall the OS if they get infected with a new rootkit. A new variant of a Trojan Microsoft calls Popureb digs so deeply into the system that the only way to eradicate it is to return Windows to its out-of-the-box configuration, Chun Feng, an engineer with the Microsoft Malware Protection Center (MMPC), said last week on the group's blog. 'If your system does get infected with Trojan:Win32/Popureb.E, we advise you to fix the MBR and then use a recovery CD to restore your system to a pre-infected state,' said Feng. A recovery disc returns Windows to its factory settings." -
Microsoft Exploits Firefox 4 Uproar, Beats IE Drum
CWmike writes "A Microsoft executive late Thursday used the furor over Mozilla's decision to curtail support for Firefox 4 to plead the case for Internet Explorer in the enterprise. 'I think I speak for everyone on the IE team when I say we'd like the opportunity to win back your business,' Ari Bixhorn, director of IE at Microsoft, said in a post on his personal blog. 'We've got a great solution for corporate customers with both IE8 and IE9, and believe we could help you address the challenges you're currently facing.' Bixhorn addressed his open letter to the manager of workplace and mobility in the office of IBM's CIO, John Walicki, who, along with others, had voiced their displeasure with Mozilla's decision to retire Firefox 4 from security support. In a comment appended to a blog maintained by Michael Kaply, a consultant who specializes in customizing Firefox, Walicki called Mozilla's decision to end security support for Firefox 4 a 'kick in the stomach.'" -
Microsoft Exploits Firefox 4 Uproar, Beats IE Drum
CWmike writes "A Microsoft executive late Thursday used the furor over Mozilla's decision to curtail support for Firefox 4 to plead the case for Internet Explorer in the enterprise. 'I think I speak for everyone on the IE team when I say we'd like the opportunity to win back your business,' Ari Bixhorn, director of IE at Microsoft, said in a post on his personal blog. 'We've got a great solution for corporate customers with both IE8 and IE9, and believe we could help you address the challenges you're currently facing.' Bixhorn addressed his open letter to the manager of workplace and mobility in the office of IBM's CIO, John Walicki, who, along with others, had voiced their displeasure with Mozilla's decision to retire Firefox 4 from security support. In a comment appended to a blog maintained by Michael Kaply, a consultant who specializes in customizing Firefox, Walicki called Mozilla's decision to end security support for Firefox 4 a 'kick in the stomach.'" -
Learning Programming In a Post-BASIC World
ErichTheRed writes "This Computerworld piece actually got me thinking — it basically says that there are few good 'starter languages' to get students interested in programming. I remember hacking away at BASIC incessantly when I was a kid, and it taught me a lot about logic and computers in general. Has the level of abstraction in computer systems reached a point where beginners can't just code something quick without a huge amount of back-story? I find this to be the case now; scripting languages are good, but limited in what you can do... and GUI creation requires students to be familiar with a lot of concepts (event handling, etc.) that aren't intuitive for beginners. What would you show a beginner first — JavaScript? Python? How do you get the instant gratification we oldies got when sitting down in front of the early-80s home computers?" -
Vint Cerf Says Fix the Net With More Pipe
CWmike writes "While ISPs may fret about Netflix, Hulu and other streaming media services saturating their bandwidth, Internet forefather Vint Cerf has a simple answer for this potential problem: Increase bandwidth exponentially. With sufficient bandwidth, streaming video services of prerecorded content wouldn't be necessary, said the now-technology evangelist at Google. With sufficient throughput, the entire file of a movie or television show could be downloaded in a fraction of the time that it would take to stream the content. Cerf, speaking at Juniper Network's Nextwork conference, spoke about the company's decision to outfit Kansas City with fiber-optic connections that Google claims will be 100 times faster than today's services. The purpose of the project was 'to demonstrate what happens when you have gigabit speeds available,' Cerf said. 'Some pretty dramatic applications are possible.' One obvious application is greater access to high-definition video, he explained. 'When you are watching video today, streaming is a very common practice. At gigabit speeds, a video file [can be transferred] faster than you can watch it,' he said. 'So rather than [receiving] the bits out in a synchronous way, instead you could download the hour's worth of video in 15 seconds and watch it at your leisure.' He adds: 'It actually puts less stress on the network to have the higher speed of operation.'" -
No Additional Firefox 4 Security Updates
CWmike writes "Unnoticed in the Tuesday release of Firefox 5 was Mozilla's decision to retire Firefox 4, shipped just three months ago. Mozilla spelled out vulnerabilities it had patched in that edition and in 2010's Firefox 3.6, but it made no mention of any bugs fixed in Firefox 4 on Tuesday, because Firefox 4 has reached what Mozilla calls EOL, for 'end of life,' for patches. Although the move may have caught users by surprise, the decision to stop supporting Firefox 4 has been discussed within Mozilla for weeks. In a mozilla.dev.planning mailing list thread, Christian Legnitto, the Firefox release manager, put it most succinctly on May 25: 'Firefox 5 will be the security update for Firefox 4.' Problem is, users are being prompted to upgrade now but are hesitant because the new rapid release of updates means many add-ons are not compatible. And without security updates in between, many could be left exposed with unpatched browsers." -
Mozilla Ships Firefox 5, Meets Rapid-Release Plan
CWmike writes "Mozilla delivered on Tuesday the final version of Firefox 5, the first edition under the new faster-release regime it kicked off earlier this year. The company also patched 10 bugs in Firefox 5, including one in the browser's handling of the WebGL 3-D rendering standard that rival Microsoft has called unsafe. Firefox 5 looks identical to its predecessor, Firefox 4, but Mozilla's made changes under the hood. Mozilla has denied copying Google Chrome's upbeat schedule but analysts have noted the similarities and pointed out the need of all browser makers to step up the pace. Because of the shorter development cycle, Mozilla called out relatively few new features in Firefox 5." -
Mozilla Ships Firefox 5, Meets Rapid-Release Plan
CWmike writes "Mozilla delivered on Tuesday the final version of Firefox 5, the first edition under the new faster-release regime it kicked off earlier this year. The company also patched 10 bugs in Firefox 5, including one in the browser's handling of the WebGL 3-D rendering standard that rival Microsoft has called unsafe. Firefox 5 looks identical to its predecessor, Firefox 4, but Mozilla's made changes under the hood. Mozilla has denied copying Google Chrome's upbeat schedule but analysts have noted the similarities and pointed out the need of all browser makers to step up the pace. Because of the shorter development cycle, Mozilla called out relatively few new features in Firefox 5." -
Sound-Based System Promises Chipless Phone Payment
CWmike writes "While near-field communication gradually emerges to turn mobile phones into payment devices, startup Naratte is introducing a system it claims can do roughly the same thing without adding a chip to the handset. On Monday, Naratte introduced Zoosh, a technology that lets phones exchange transaction information via inaudible sound waves. As with NFC, the phone user would just put the phone near to a point-of-sale terminal to redeem a coupon or make a purchase. NFC provides short-range radio communication between phones and point-of-sale devices so users can just tap or point their phones at the device to make a purchase. NFC uses specialized chips, which are already built into a few phones such as the Google Nexus S sold by Sprint Nextel, and are expected in more handsets in the future. Zoosh involves software that utilizes the speaker and microphone in a handset to send and receive audio signals with another device, similar to the way early modems exchange data by sending tones through the handsets of desk phones cradled in coupler devices. The company has posted a video that shows how it works. Between this and barcodes (which Starbucks says is working well already, thank you very much), is NFC already irrelevant?" -
Sound-Based System Promises Chipless Phone Payment
CWmike writes "While near-field communication gradually emerges to turn mobile phones into payment devices, startup Naratte is introducing a system it claims can do roughly the same thing without adding a chip to the handset. On Monday, Naratte introduced Zoosh, a technology that lets phones exchange transaction information via inaudible sound waves. As with NFC, the phone user would just put the phone near to a point-of-sale terminal to redeem a coupon or make a purchase. NFC provides short-range radio communication between phones and point-of-sale devices so users can just tap or point their phones at the device to make a purchase. NFC uses specialized chips, which are already built into a few phones such as the Google Nexus S sold by Sprint Nextel, and are expected in more handsets in the future. Zoosh involves software that utilizes the speaker and microphone in a handset to send and receive audio signals with another device, similar to the way early modems exchange data by sending tones through the handsets of desk phones cradled in coupler devices. The company has posted a video that shows how it works. Between this and barcodes (which Starbucks says is working well already, thank you very much), is NFC already irrelevant?" -
Vivek Kundra Quits As Federal CIO
CWmike writes "The first person ever appointed as the CIO of the federal government, Vivek Kundra, is resigning after two and a half years on the job, the White House said Thursday. There was no hint in the announcement made by Jack Lew, director of the Office of Management and Budget, that Kundra's exit was prompted by a shift in the White House's view on IT. Lew, who praised the CIO's work, said Kundra was leaving to take a fellowship at Harvard. Kundra was appointed CIO a few months after President Barack Obama took office. He immediately outlined an agenda that emphasized cloud adoption, use of consumer technologies, and making data available to the public on new sites, such as data.gov. He was critical of big IT contracts that moved too slowly and were at risk of failing."