Showing posts with label Businesses. Show all posts
Showing posts with label Businesses. Show all posts

Wednesday, 4 September 2013

Will Nokia help Microsoft regain relevance with businesses?

Microsoft rocked the tech world today with the announcement that it is spending about $7 billion to acquire Nokia. The move has a variety of potential benefits and ramifications, and many of those could have an impact on how your business relates to Microsoft in the years to come.

For many small and medium businesses, the chaos that seems to surround Microsoft may seem like cause for concern. Businesses don’t like change and uncertainty, but the tech landscape has shifted and Microsoft needs to adapt or die. Whichever direction Microsoft goes, it will mean change for the businesses that rely on Microsoft products and services.

Purchasing Nokia puts Microsoft in direct control of its own mobile future.

Who knows what the true motive for buying Nokia is or Microsoft’s ultimate goal?. Microsoft has already gotten into the device market with the Surface tablet line, and it recently restructured its business units to focus more on devices, so acquiring Nokia to get directly involved in manufacturing smartphones makes some sense. That’s more or less the pitch Microsoft made to investors as its rationale for buying Nokia.

Perhaps it has something to do with the impending change in Microsoft leadership. Steve Ballmer recently announced his imminent departure, and Nokia’s CEO—Stephen Elop—is an ex-Microsoft executive considered by many to be a frontrunner for the role.

Rob Enderle, principal analyst with the Enderle Group, thinks the move may have been necessary for the fate of both Nokia itself and the Windows Phone mobile platform. “Given Nokia was really the last company providing a Windows Phone line—but still in trouble—it makes sense that the two firms tie more tightly together," he says. "Starting over from scratchshould Nokia fail would have been excessively expensive, and they are gaining share.”

Enderle also concurs that buying Nokia might be a move to acquire Elop and smooth the transition of leadership. “This should give them Elop as a viable replacement for Ballmer," he says. "The board appears focused on mobile as the way to expand, and Elop knows Microsoft and its problems. He could more effectively hit the ground running.”

Microsoft has been between a rock and a hard place for a few years now, and it’s probably going to get tougher before it gets easier—if it ever gets easier. As the world has migrated away from traditional PCs to mobile platforms, Microsoft has been faced with a seemingly impossible dilemma: plow ahead with the status quo to keep its core customers happy and die a slow death or evolve to remain competitive in an increasingly mobile tech world and risk losing major sources of revenue.

Microsoft has been slow to recognize challenges to its dominance and even slower to adapt and try to address those challenges head on. Its efforts so far—Windows Phone, and the Surface tablets—are well-engineered and have received a fair share of praise from analysts, media, and consumers. Yet the reality remains that they’ve failed so far to shift Microsoft’s waning relevance.

The silver lining for Microsoft is that as hard as it is for the tech juggernaut to shift direction, it’s almost as difficult for Microsoft customers to shift gears. In spite of Microsoft’s lethargy, no rival has stepped in to seize the opportunity. There are alternatives out there, and some businesses have abandoned Windows, or Microsoft Office, or other Microsoft products and services, but the competition is generally lacking and doesn’t offer a clear, compelling reason to change.

Can Microsoft rise from the ashes and retain its dominant role for small and medium businesses, or is it just too little, too late? Check back in a year or two and we’ll see how it’s going.

Updated at 2:20 p.m. PT with a video report from IDG News Service.

Tony is principal analyst with the Bradley Strategy Group, providing analysis and insight on tech trends. He is a prolific writer on a range of technology topics, has authored a number of books, and is a frequent speaker at industry events.
More by Tony Bradley


View the original article here

Friday, 30 August 2013

Feds developing guidelines to help businesses to better secure their IT systems

Following through on an order earlier this year from U.S. President Barack Obama, the National Institute of Standards and Technology (NIST) is rapidly developing a set of guidelines and best practices to help organizations better secure their IT systems.

The agency has released a draft of its preliminary cybersecurity framework and is seeking feedback from industry.

The agency is scheduled to release a full preliminary draft in October, for public review. It will then issue the final 1.0 version of the framework in February 2014 and continue to update the framework thereafter.

When finished, the framework will provide guidance for organizations on how to manage cybersecurity risk, “in a manner similar to financial, safety, and operational risk,” the document states.

In February the White House issued an executive order tasking NIST to develop a cybersecurity framework, one based on existing standards, practices and procedures that have proven to be effective.

In July, NIST issued an outline of the framework and held a workshop in San Diego to fill in some details. This draft incorporates some of that work, and was released to gather more feedback ahead of the next workshop, to be held in Dallas starting on Sept. 11.

“The Framework complements, and does not replace, an organization’s existing business or cybersecurity risk management process and cybersecurity program. Rather, the organization can use its current processes and leverage the framework to identify opportunities to improve an organization’s cybersecurity risk management,” the draft read.

When finished, the framework will consist of three parts. One component, called the core functions, will be a compilation of commonly practiced activities and references. The second component, the implementation tiers, provides guidance on how to manage cybersecurity risks. The third component, the framework profile, provides guidance on how to integrate the core functions within a cybersecurity risk strategy, or plan.

On Twitter, framework ideas are being submitted and discussed with the hashtag #NISTCSF.

Joab Jackson covers enterprise software and general technology breaking news for the IDG News Service.
More by Joab Jackson


View the original article here

Thursday, 29 August 2013

Hack of New York Times holds a lesson for all businesses

The New York Times, Twitter, and other major sites were knocked offline yesterday in an attack by the Syrian Electronic Army (SEA). While there is certainly a political motivation to the hacks, there is an underlying lesson that all businesses should learn.

Apparently, the latest attack was the result of sites being redirected at the DNS server level. AlienVault Labs has posted a comprehensive list of domains pointing to the Syrian Electronic Army server as of last night. The WhoIs data for the New York Times domain showed the SEA listed as the admin for the domain, and the name server entries were modified to redirect to the SEA.

The Syrian Electronic Army took down the New York Times and other high-profile sites.

The Syrian Electronic Army was also reportedly behind recent attacks on The Washington Post. The recent attacks by the SEA have a common thread, and recognizing it is the first step to defending against future attacks.

Darien Kindlund, FireEye's manager of threat intelligence, says the attacks aren’t coming through the front door and attacking the sites directly. Instead, they’re going after the low-hanging fruit—exploiting weaknesses in third-party affiliates. “With the Washington Post, a third-party advertiser platform was hacked," he says. "With the New York Times, the SEA went after the hosting provider.”

Kindlund has some stern advice for the affected organizations. “Targeted media companies need to start to look at their entire infrastructure not as a contained system, but rather, how does their infrastructure integrate with their external partners, as they conduct business online," he says. "The SEA has found the weak link in these giants—it’s not a direct attack; it's an attack against their partners (aka "supply chain")."

He has a good point, but we can extend that a step farther to encompass other businesses as well. The task of defending your network and protecting your PCs doesn’t end at securing your own business. You have to take a broader approach and consider all of the networks and services your business uses, as well as the partner or supplier networks that are connected with yours.

Before you sign up for a service, or allow a partner or supplier to connect to your network, you need to do your due diligence. Make sure the companies you work with and grant access to your network have adequate security measures in place. Ideally, their security measures should be as good or better than yours. At the very least, though, you need to know what security controls are in place so you are at least aware of where the weak links in the chain are so you can be more vigilant about monitoring them.

Your network is only as secure as the weakest point that has access to it. For the Washington Post it was a third-party advertising platform. For the New York Times it was a weakness at the Web hosting provider. Where is your weak link?

Tony is principal analyst with the Bradley Strategy Group, providing analysis and insight on tech trends. He is a prolific writer on a range of technology topics, has authored a number of books, and is a frequent speaker at industry events.
More by Tony Bradley


View the original article here

Thursday, 22 August 2013

Box rolls out new cloud storage plans catering to small and medium businesses

Box has big news today for small companies and individuals. It is launching new, more affordable pricing plans to attract small and medium businesses to its cloud data storage and file sharing service, and it is doubling the amount of storage it provides for free personal accounts.

Cloud data storage today is like instant-messaging services used to be. Everyone has a favorite, but they also have an account set up with virtually every service available to allow them to share files with co-workers, customers, or friends and family who prefer a different service. Because the services offer free storage plans, many people have a Box, Dropbox, SugarSync, Google Drive, Microsoft SkyDrive, and other accounts.

Box has doubled space for the free Personal account, and added a new Starter tier for SMBs.

For those people, Box is increasing the amount of storage available with the free Personal plan from 5GB to 10GB. Box also frequently runs promotions that add storage for customers, such as the campaign earlier this year that rewarded Dell customers with 50GB of free storage for life. It might still be beneficial to maintain accounts on other services in certain scenarios, but for general personal use it would be much better to have data consolidated in one place than trying to juggle four or five different services.

The increased storage is great for individuals, but a business can’t—or at least shouldn’t—have employees running around sharing business data across their own personal cloud storage services. From a number of perspectives—protecting intellectual property, securing data from unauthorized exposure, and regulatory compliance to name a few—it’s just a bad idea. The company has no ability to limit or control access to the data once it leaves the internal network, and there is no way for the company to know which data is being stored where, or who it’s being shared with.

This makes the new Box plans particularly attractive for SMBs. The Starter plan offers customers 100GB of pooled storage for teams up to 10 users for $5 per user per month. As a business grows and its needs exceed what the Starter plan has to offer, they can step up to the Business plan which provides 1TB of pooled storage for more users and enterprise application integration (such as Active Directory or Salesforce.com), along with more robust administrative tools for $15 per user per month.

In a blog post about the changes, Box CEO Aaron Levie, says “Whether you’re a boutique financial services firm, a construction company, a small medical practice, or a startup working with manufacturers in China, Box can make your business more competitive. We want to help big businesses be as nimble as small ones, and small businesses be as scalable and global as giants.”

Box isn’t cheap, but the old adage “you get what you pay for” applies. Box offers better administrative controls and business tools and works with a variety of developers and services to provide a complete ecosystem that integrates seamlessly with the data stored in Box.

The new Starter plan lets small and medium businesses step up from using rogue personal storage services and manage and protect cloud data the way a business should. Box now gives SMBs a way to affordably dip a toe in the water, and a path to evolve and scale up as needs change.

Tony is principal analyst with the Bradley Strategy Group, providing analysis and insight on tech trends. He is a prolific writer on a range of technology topics, has authored a number of books, and is a frequent speaker at industry events.
More by Tony Bradley


View the original article here

Tuesday, 20 August 2013

GoDaddy to acquire Locu to boost offerings to small businesses

GoDaddy has agreed to acquire Locu, a startup in San Francisco that helps local merchants get discovered online by their customers.

The financial terms of the transaction were not disclosed. The acquisition is in line with the strategy of GoDaddy, a Web hosting provider and domain name registrar, to broaden its offerings to small businesses.

The acquisition advances GoDaddy's strategy to deliver digital identities that help small businesses get more customers, the company said in a statement Monday.

Started in 2011, Locu is said to be used by more than 30,000 businesses, including restaurants, spas, salons, accountants, photographers and home-remodeling companies, to promote their services across Locu's partner network which includes ties with Yelp, YP.com, Foursquare, TripAdvisor and Facebook.

Locu will continue to operate out of its San Francisco and Cambridge, Massachusetts offices, and all its employees will join GoDaddy. The two companies have been working closely together since May when GoDaddy integrated Locu into its Website Builder service for small businesses.

Current Locu customers will not be impacted by the acquisition, Locu said in a post on its site.

GoDaddy in Scottsdale, Arizona, acquired M.dot, the developer of a mobile app for website creation and management by small businesses, in February. The company said in December it planned to take advantage of its scale, technology and brand to expand through partnerships and acquisitions aimed at helping small businesses succeed online.

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service.
More by John Ribeiro, IDG News Service


View the original article here

Businesses shouldn't let Google and Microsoft outages shake their confidence in the cloud

The recent outages of Google and Microsoft’s Outlook.com reinforce concerns many businesses have about relying on cloud services and may cause organizations that have already moved or are considering moving to the cloud to reconsider. When you look at the big picture, though, you can still trust the cloud.

It’s no secret at this point that there are a number of benefits to using cloud services. Cloud providers are generally able to take advantage of economies of scale that let them offer servers, storage, and services cheaper on a per user basis than what businesses can accomplish on its own—particularly small and medium businesses that have fewer employees to average the investment across.

Saturday, 17 August 2013

Facebook mobile payments a boon for businesses

Practical IT insight from Tony Bradley

Facebook is reportedly looking to get into the mobile payments game. If it does it right, businesses will reap the benefit of monetizing their Facebook presence and be able to simplify the process of turning Facebook followers into revenue.

Rivals should be worried any time an 800-pound gorilla like Facebook enters a market. Facebook is the online destination where users spend the most time each month, and with a billion-ish users it represents a dominating force in whatever market it chooses to compete.

Your customers already like and use Facebook--making it an ideal e-commerce platform.

Mobile payments is a logical culmination of the framework Facebook has put in place for businesses. Businesses have been encouraged to develop a Facebook presence and build a following of loyal customers to "Like" and share information about the company with their extended social networks. Brick-and mortar-businesses encourage customers to check-in so the they can increase visiblity among the customers's Facebook friends. All of that effort also ties in to the Facebook Graph Search functionality to enable Facebook users to identify the music, restaurants, movies, and other things their extended social network likes.

With Facebook mobile payments, businesses can streamline the process of turning that social relationship with customters into a revenue stream. The idea has always been to promote the business and hopefully generate revenue, but if those billion potential customers can use the tool they’re already logged into to do business with the companies they already Like and follow, it will make it that much easier.

The problem for other mobile payment providers like PayPal or an Internet currency like Bitcoin is that they’re not used uniformly by the masses. They’re all proprietary payment frameworks to an extent—including whatever Facebook does—but Facebook is able to capitalize on a massive active user base, and businesses and consumers can just click an extra button to complete a transaction rather than having to install and consciously choose to use some different payment provider.

There is one major hurdle Facebook has to deal with before a Facebook mobile payments system can really turn into an e-commerce goldmine. Security.

Most consumers are leery of the concept of mobile wallets to begin with. A Bloomberg BusinessWeek report from June claims that nearly seven out of 10 adults don’t want to use a mobile wallet. Combine that with a general distrust of security and privacy on social networks, and you can see what a serious obstacle this could be for Facebook.

If history is any indication, though, consumers will choose convenience over security almost every time. That bodes well for Faceook in general, and means that a Facebook mobile payments system will be a jackpot for businesses with an established presence on the social network.

Tony is principal analyst with the Bradley Strategy Group, providing analysis and insight on tech trends. He is a prolific writer on a range of technology topics, has authored a number of books, and is a frequent speaker at industry events.
More by Tony Bradley

Close

Aug 5, 2013 11:17 AM

Alex Wawro goes deep inside the design lab at Razer to check out the company's prototyping process.

READ THE RELATED ARTICLE:<

Behind the scenes at Razer


View the original article here

Monday, 5 August 2013

Android one-click Google authentication method puts users, businesses at risk

A feature that allows Android users to authenticate themselves on Google websites without having to enter their account password can be abused by rogue apps to give attackers access to Google accounts, a security researcher showed Saturday at the Defcon security conference in Las Vegas.

The feature is called "weblogin" and works by generating a unique token that can be used to directly authenticate users on Google websites using the accounts they have already configured on their devices.

Weblogin provides a better user experience but can potentially compromise the privacy and security of personal Google accounts, as well as Google Apps accounts used by businesses, Craig Young, a researcher at security firm Tripwire, said during his talk.

Young created a proof-of-concept rogue app that can steal weblogin tokens and send them back to an attacker who can then use them in a Web browser to impersonate a victim on Google Apps, Gmail, Drive, Calendar, Voice and other Google services.

The app was designed to masquerade as a stock viewing app for Google Finance and was published on Google Play, with a description that clearly indicated it was malicious and shouldn't be installed by users.

During installation, the app asks for permission to find accounts on a device, use the accounts on a device and access the network. When run, it then displays another prompt asking for permission to access a URL that starts with "weblogin" and includes finance.google.com.

This secondary prompt is uninformative and most users are likely to accept the request, Young said.

If they do, a weblogin token is generated and the users are automatically signed in to the Google Finance website. However, at the same time, the token is siphoned off through an encrypted connection to a server controlled by the attacker.

The issue is that this weblogin token does not only work for Google Finance, but for all Google services, Young said.

For example, it can provide access to the victim's documents in Google Drive, emails in Gmail, calendar entries in Google Calendar, Google Web search history or potentially sensitive company data stored in Google Apps, the researcher said.

It can also be used to access a user's Google Play account and remotely install apps on his device or to access his accounts on third-party websites that support Google Federated Login.

If the user is an administrator for a company's Google Apps domain, the attack could compromise the company's entire Google Apps operation. The attacker would gain the ability to reset the passwords for other users on that Google Apps domain, create and modify privileges and roles, create and modify mailing lists, and even add new users with administrative privileges, the researcher said.

The issue was reported to Google in February and the company started blocking some of the things an attacker could do, Young said.

For example, an attacker authenticated via a weblogin token can no longer use the Google Takeout service to get a data dump for an entire Google Account and can no longer add new Google Apps users, although there is a workaround that still makes the latter action possible, Young said.

Young's app displays the weblogin permission prompt because it uses the standard Android API (application programming interface) to get the token. However, if the app used an exploit to get root privileges on the device, it would be able to grab the token without requiring user confirmation, he said.

The app stayed in Google Play for around a month until someone probably reported it as malicious, and during this time there was no indication it had been scanned by Bouncer, a Google Play service that searches for malicious apps in the marketplace, the researcher said. If it was scanned, then it wasn't flagged as malicious, which raises questions about Bouncer's effectiveness, he said.

After it was reported as malicious, the app was removed from Google Play, and Android's local app verification feature now blocks it as spyware when trying to install it.

Google did not respond to a request for comment sent Thursday.

Most Android antivirus products from well known vendors didn't detect the app as malware either, but one privacy advisor application did list the rogue app as having account access, Young said.

"Today's presentation showed that with enough ingenuity and effort you can easily bypass apparently well protected systems," said Alexandru Catalin Cosoi, the chief security strategist at antivirus vendor Bitdefender, who attended Young's talk.

The only way to prevent these things from happening is to raise the cost of attacks, so that by the time one lock is bypassed, there is a new lock in place that needs to be breached, Cosoi said. Vulnerabilities can be found on a regular basis, so continuous research definitely helps in improving systems like Google Bouncer, making attacks more costly for hackers to pull off, he said.

Businesses shouldn't allow their IT administrators to use Google accounts on their Android devices that are also Google Apps domain administrators, Young said.

Users should be wary of apps that request access to accounts added on the device and should answer "no" to permission prompts containing the words "weblogin" or "ID," he said.

Google should create an option to allow Google Apps domain owners to block Google Apps access via weblogin and should make the weblogin prompts more informative so that users understand what they do, the researcher said.


View the original article here

Saturday, 3 August 2013

Why Small Businesses Need to Spring for Business-Class Internet Access

Google is being accused of violating the FCCs Open Internet Order as a result of its policy toward servers. Essentially, if you run a server from a Google Fiber Internet connection, you’re technically violating the terms of service, and you could find your Internet access shut down. Google stands by that policy, but the reality is that this is only one of many reasons that small businesses should not run a server from a consumer-grade Internet connection.

The issue with Google Fiber stems from a clause in the terms of service that reads, “Unless you have a written agreement with Google Fiber permitting you to do so, you should not host any type of server using your Google Fiber connection.”

Google has been a proponent of net neutrality, but some were quick to note that Google seems to have changed teams now that it’s also in the Internet provider business. Google’s response to the FCC includes this explanation: “The server policy has been established to account for the congestion management and network security needs of Google Fiber’s network architecture, particularly given that Google Fiber does not impose data caps on its users.”

Bottom line: Google believes it has a right to ban someone from hosting a server on it’s Google Fiber network because of the potential impact it could have on the bandwidth for all of the rest of the customers. That seems reasonable.

You don’t really want to host your business server on a consumer Internet service anyway. Granted, Google Fiber delivers a 1Gbps connection for a very low cost compared to any other consumer or business service. However, Google Fiber is only available in a few select cities, and there are other reasons to choose a business-class Internet provider.

First, Google states explicitly that it doesn’t impose a bandwidth cap, but many consumer Internet services do. Comcast used to have a 250GB per month cap, but switched to a tiered-pricing plan last year for heavy users. The cap is now 300GB, after which Comcast charges $10 extra per month for each additional 50GB.

Another benefit of business-class Internet service is that you generally have a dedicated, static IP address, which makes it much easier to host and manage a server. Consumer Internet services use DHCP to randomly assign IP addresses, so your website or FTP server might be on one address today, and a different one tomorrow.

Most consumer Internet services block various TCP ports—for example port 25. It’s blocked as a measure to guard against or limit spam, based on the assumption that no consumer customer is hosting an email server (because it would violate the TOS). You want to have full access to all of the ports for your Internet access—including TCP port 25, so business-class Internet is the way to go.

Tech support is also different. Calling the consumer tech support line when you’re having an issue is typically an exercise in futility and frustration. If your business depends on the Internet connection, it can be that much more stressful. The technical support for a business-class account is generally more knowledgeable and more expedient, so you can minimize down time and keep your business online.

The operative word in the term “small and medium business” is “business”. In other words, regardless of whether your company has one employee, one hundred, or one thousand, it’s still a business, and it still needs to act like one. That is particularly true when it comes to choosing an Internet provider.


View the original article here

Tuesday, 30 July 2013

Will New 300GB Optical Discs Be Good For Businesses?

Two of the leading names in DVD and Blu-ray technology announced a joint effort to develop a next-generation standard for optical discs. Sony and Panasonic will collaborate on a new standard, and plan to produce new super discs that can hold up to 300GB of data on a single disc by 2015.

The first question to ask is whether or not such technology will even be relevant in 2015. Is it even relevant today? Or, more importantly, what value or impact will it have for your business?

Not too long ago, recordable optical discs were a primary means of storing and archiving data. Blank disc media is cheap, and burning data to disc is a relatively simple process that small and medium businesses can easily manage. Current Blu-ray discs can hold 25GB of data—or 50GB on a dual-layer disc. But, removable media often has trouble keeping up with the skyrocketing storage demands of newer technology.

There was 1.8 trillion gigabytes of data generated in 2011 alone. According to a study conducted by IDC, the explosion of mobile devices, embedded technologies, wearable computers, and sensors in clothing, medical devices, and building will result in the overall amount of data expanding by 50 times by 2020.

25GB ain’t what it used to be. Documents, spreadsheets, presentation, photos, videos, and more all take up a lot of space. It’s not unusual for a business—or even a consumer—to have a terabyte or more of data. Even at 50GB per dual-layer Blu-ray disc, it would take 20 discs to back up 1TB of data, so optical discs have been superseded by hard drives or cloud-based storage options.

A small business can store and manage terabytes of data from a single server, and easily back it up to an external drive, or to a cloud-based storage service.  You can purchase a 3TB drive for a little over $100, or a compact, portable 1TB drive for well under $100. Archiving terabytes—or even hundreds of gigabytes—of data on discs is tedious compared with other available options.

Optical discs still have a few advantages as well, though. Blank disc media is generally relatively cheap. It’s also light and thin, which makes it more suitable and cost-effective for shipping, either to an offsite storage facility, or to send data to a partner, customer, or remote employee.

Optical discs are also a good medium for distributing applications or information to users, or sharing data with others. They provide a disposable, one-time option for sharing data, making it so that you don't have to let go of your hard drive in the process. Of course, USB thumb drives are smaller, often easier to transfer data to, and hold as much or more information as an optical disc on a device that isn’t susceptible to damage or corruption from scratches.

One possible motivation for Sony and Panasonic to squeeze more data onto an optical disc is the advent of 4K video technology. While a standard feature-length HD movie fits comfortably on a DVD or Blu-ray disc, the same movie in a 4K format would take up a couple hundred gigabytes at least.

It’s unlikely that 300GB optical discs will have a major impact for businesses. If the price is right—both for the hardware and the blank media—it could prove useful in certain scenarios. It’s hard to say what technology will be leading the way for business data archiving in 2015, but it seems safe to say it won’t be optical discs.


View the original article here