Monday, 30 September 2013
Friday, 20 September 2013
Hackers exploit critical IE bug; Microsoft promises patch
Microsoft today said that hackers are exploiting a critical, but unpatched, vulnerability in Internet Explorer 8 (IE8) and Internet Explorer 9 (IE9), and that its engineers are working on an update to plug the hole.
As it often does, the company downplayed the threat.
[ Windows 8 left you blue? Then check out Windows Red, InfoWorld's plan to fix Microsoft's contested OS. | Microsoft's new direction, the touch interface for tablet and desktop apps, the transition from Windows 7 -- InfoWorld covers all this and more in the Windows 8 Deep Dive PDF special report. | Stay atop key Microsoft technologies in our Technology: Microsoft newsletter. ]
"There are only reports of a limited number of targeted attacks specifically directed at Internet Explorer 8 and 9, although the issue could potentially affect all supported versions," Dustin Childs, a manager in the Trustworthy Computing group and its usual spokesman, said in a blog post Tuesday morning.
"We are actively working to develop a security update to address this issue," Childs added.
According to Childs and the security advisory Microsoft also published today, the vulnerability affects all supported versions of IE, from the 12-year-old IE6 to the not-yet-officially-released IE11, the browser that will accompany Windows 8.1 when it ships Oct. 18.
"There is no escaping this one," said Andrew Storms, director of DevOps at cloud security vendor CloudPassage, referring to the bug affecting all versions of Microsoft's browser. "IE zero-days are never a good thing, especially when they affect every version," Storms added.
Although Microsoft's advisory did not put it in these terms, the vulnerability can be exploited using classic "drive-by" attack tactics. That means hackers need only lure victims running IE to malicious sites -- or legitimate websites that have previously been compromised and loaded with attack code -- to hijack their browser and plant malware on their Windows PCs.
Until Microsoft produces a patch, the company offered customers several options to protect themselves, including advice on configuring EMET 4.0 and running one of its "Fixit" automated tools to "shim" the DLL that contains the IE rendering engine.
EMET (Enhanced Mitigation Experience Toolkit) is a tool designed for advanced users, primarily enterprise IT professionals, that manually enables anti-exploit technologies such as ASLR (address space layout randomization) and DEP (data execution prevention) for specific applications.
But the Fixit route will be easiest for individual users: Microsoft's posted a link to the Fixit tool on its support site, and customers need only click the icon marked "Enable." Microsoft has used the shim approach before when faced with unexpected attacks against IE.
Wednesday, 31 July 2013
Sprint promises wide rollout and device support for ex-Clearwire spectrum
Sprint says it will have live LTE sites using former Clearwire spectrum across the U.S. next year and expects all its new mobile devices in 2014 to be equipped for those frequencies -- though not necessarily iPhones.
The company gave an update on progress in its Network Vision upgrade project during a conference call on Tuesday to discuss second-quarter financial results, according to a transcript provided by Seeking Alpha. Earlier this month, the fourth-largest U.S. mobile operator got a shot in the arm with its US$21.6 billion acquisition by SoftBank and also bought out former partner Clearwire.
With the Clearwire acquisition, Sprint got access to an emerging Clearwire LTE network that it plans to use for extra mobile data capacity in densely populated areas. Though it uses a slightly different form of LTE than Sprint's and operates in a relatively short-range spectrum band, around 2.5GHz, the former Clearwire network could give the carrier a large amount of capacity to bolster services in cities.
The network had been intended for Sprint's use through the longstanding partnership between the two companies, but Sprint's takeover of Clearwire gave that plan a more solid foundation.
There were already about 2,000 Clearwire LTE sites completed when the buyout was completed earlier this month, said Steve Elfman, president of network operations and wholesale, on the conference call. He expects several thousand 2.5GHz LTE base stations on the air this year, with sites across the country next year, though not the full deployment of sites that will use the spectrum. The 2.5GHz radios don't have as long a range as Sprint's other gear, so they'll be deployed in a larger number of sites, he said.
Sprint plans eventually to operate LTE in three spectrum bands: Its own 1.9GHz band, the 800MHz frequencies from its defunct Nextel network, and the 2.5GHz spectrum. Earlier this month it introduced the first mobile device that will be able to use all those bands.
The carrier expects to have a few handsets with 2.5GHz capability in the fourth quarter, and starting in 2014, all its new devices will be able to use that spectrum, Elfman said. But asked later on the call whether that would include the Apple iPhone, Elfman clarified that Sprint couldn't say whether Apple would adopt 2.5GHz for that device.
"We can't confirm anything on the iPhone at this time or anytime," Elfman said.
Stephen Lawson covers mobile, storage and networking technologies for The IDG News Service. Follow Stephen on Twitter at @sdlawsonmedia. Stephen's e-mail address is stephen_lawson@idg.com
Tuesday, 30 July 2013
Flash breakthrough promises faster storage, terabytes of memory
In the ongoing quest for faster access to data, Diablo Technologies has taken what could be a significant next step.
Diablo's Memory Channel Storage (MCS) architecture, expected to show up in servers shipping later this year, allows flash storage components to plug into the super-fast channel now used to connect CPUs with memory. That will slash data-access delays even more than current flash caching products that use the PCI Express bus, according to Kevin Wagner, Diablo's vice president of marketing.
The speed gains could be dramatic, according to Diablo, helping to give applications such as databases, big data analytics and virtual desktops much faster access to the data they need most. Diablo estimates that MCS can reduce latencies by more than 85 percent compared with PCI Express SSDs (solid-state disks). Alternatively, the flash components could be used as memory, making it affordable to equip servers terabytes of memory, Wagner said.
Other than on-chip cache, the memory channel is the fastest route to a CPU, Wagner said. Not only do bits fly faster over this link, there are also no bottlenecks under heavy use. The connection is designed to be used by many DIMMs (dual in-line memory modules) in parallel, so each component doesn't have to relinquish the bus for another one to use it. That saves time, as well as CPU cycles that would otherwise be used managing the bus, Wagner said.
The parallel design of the memory bus also lets system makers scale up the amount of flash in a server without worrying about diminishing returns, he said. A second MCS flash card will truly double performance, where an added PCIe SSD could not, Wagner said.
Diablo, which has been selling memory controllers for about 10 years, has figured out a way to use the standard DDR-3 interface and protocols to connect flash instead of RAM to a server's CPU. Flash is far less expensive than RAM, but also more compact. The MCS components, which come in 200GB and 400GB sizes, will fit into standard DIMM slots that typically accommodate just 32GB or so of memory. The only adaptation manufacturers will need to make is adding a few lines of code to the BIOS, Wagner said.
Enterprises are more likely to use MCS as high-capacity memory than as low-latency storage, said analyst Jim Handy of Objective Analysis.
"Having more RAM is something that a lot of people are going to get very excited about," Handy said. His user surveys show most IT departments automatically get as much RAM as they can for their servers, because memory is where they can get the fastest access to data, Handy said.
"Basically, you'd like everything to be in the RAM," Handy said. Virtualized data centers, where many servers need to share a large set of data, need a shared store of data. But in other applications, especially with databases and online transaction processing, storage is just a cheaper and more plentiful -- but slower -- alternative to memory. "Everything that's on the storage is there just because it can't fit on the RAM," he said.
To implement the MCS architecture, Diablo developed software and a custom ASIC (application-specific integrated circuit), which it will sell to component vendors and makers of servers and storage platforms. Flash vendor Smart Storage Systems, which earlier this month agreed to be acquired by SanDisk, will be among the companies using the MCS technology, Wagner said. In addition, a tier-one server vendor is preparing about a dozen server models with the technology and will probably ship the first of them this year, Walker said.
For the most part, Diablo doesn't expect consumers or small enterprises to install MCS flash on their own computers. However, Diablo may work directly with enterprises that have very large data centers they want to accelerate, he said.
Using MCS flash to supplement DRAM would dramatically reduce the per-gigabyte cost of memory but also would allow for further consolidation of the servers in a data center, Wagner said. A large social networking company with 25,000 servers analyzed the MCS technology and said it would make it possible to do the same amount of work with just 5,000 servers.
That's because the current DRAM-only servers can be equipped with just 144GB of memory, but MCS would allow each server to have 16GB of DRAM and 800GB of flash. With that much memory, each server can do more work so fewer are needed, Wagner said. Fewer servers would mean savings of space and energy, which would translate into lower costs, he said.
Stephen Lawson covers mobile, storage and networking technologies for The IDG News Service. Follow Stephen on Twitter at @sdlawsonmedia. Stephen's e-mail address is stephen_lawson@idg.com