Showing posts with label their. Show all posts
Showing posts with label their. Show all posts

Thursday, 5 September 2013

Phone makers roll their own operating systems as Google and Microsoft close ranks

Sometimes, you can’t help but pay attention to what the man behind the curtain is doing. Earlier this week, Microsoft announced plans to acquire Nokia’s device and services business for more than $7 billion, effectively seizing control of the entire Windows Phone experience, from software to hardware to services.

Just like that, the companies behind every major smartphone operating system now compete directly with their manufacturing partners. And while Google erected a "firewall" between Android and Motorola when it bought the handset maker in 2012, Microsoft has no plans to separate Nokia from the core Windows Phone business. It’s full steam ahead for Microsoft-made smartphones as Redmond tries to single-handedly turn Windows Phone from an also-ran into a contender.

Monday, 2 September 2013

Sharks go wireless as scientists tag them to track their travels

Meet Mary Lee, a great white shark that's the same weight and nearly the same length as a Buick. And, by the way, you may have been swimming within a few feet of her this past year and not known it.

Since last September, when she received an array of radio, acoustic, and satellite tags, Mary Lee has travelled from Massachusetts to Florida, often hugging the coastline so closely that scientists tracking her called beach authorities in Florida to warn them about her. The 16-foot, 3456-pound shark also headed into open ocean, taking a February vacation off the beaches of Bermuda.

"She was undoubtedly not the only one there. Sharks have probably been doing it for millions of years," said Nick Whitney, a marine biologist with the Mote Marine Laboratories in Sarasota, Florida. "We're learning things that ten years ago we would have never dreamed we could have learned about these species."

OCEARCHMary Lee, a 16-foot 3456-pound great white shark, traversed the East Coast over the past year, at times hugging the shoreline so close as to prompt a warning call from researchers.

Whitney, who spoke from a research vessel off of Cape Cod, Massachusetts, is part of a team that runs OCEARCH, a nonprofit global shark-tracking project that uses four different tagging technologies to create a three-dimensional image of a shark's activities. OCEARCH is hoping to develop successful conservation and management strategies by studying shark habits in more granular detail.

While traditional research has focused on small-scale movements, the data being gathered by OCEARCH offers surprising new information about where sharks go and what they do. That's where the tracking technology is crucial.

A dorsal fin tag attached by OCEARCH uses a satellite to track a shark's position each time it breaks the surface. Other tags include an RFID implant whose ping is picked up whenever the shark passes a special, underwater buoy; an accelerometer, similar to the technology used in an iPhone or Nintendo Wii, that detects up or down movement; and a Pop-off Satellite Archive Tag (PSAT), which acts as a general archive, recording average water depth, temperature and light levels.

"On average, we're collecting 100 data points every second—8.5 million data points per day. It's just phenomenal," Whitney said. "Second by second, we can pick up every tail beat and change in posture."

One of the surprises the tracking data revealed is that white sharks don't always stick to cold water, as previously thought. Some even venture into the Gulf of Mexico during the summer.

In addition to in-depth data, what sets OCEARCH apart from past shark-tracking projects is that anyone—from a child in grade school to a television arm-chair warrior—can see the tracking data at the same time as researchers on the OCEARCH web site.

Each shark's location is represented by an icon on a Google Maps-based TruEarth Viewer. By clicking on the icon, a user can get detailed information such as the species, gender, size, weight, length, as well as where and when the shark was tagged. A user also gets images of the shark as it was being tagged.

By drilling down further, and clicking on the "Where Have I Been" icon, a user can also see a track of where the shark has been since being tagged, in some cases see a detailed trail over the course of a year or more.

OCEARCH expedition leader Chris Fischer calls the methodology "open source" research, since all scientists see the data at the same time; nothing's proprietary. Within a week, OCEARCH also plans to launch a "digital hub" shark tracker platform with a real-time social media interface that allows researchers to post FAQs and videos to the most popular social networks: Facebook, YouTube, Instagram or Twitter, according to OCEARCH spokesman Chris Berger.

OCEARCH will also be launching a Science, Technology, Engineering, and Mathematics (STEM) Education-based curriculum for K-12 students. "We currently have 30 lesson plans for sixth through eighth graders, and will have more for K-12—eventually, even pre-K," Berger said.

Currently, OCEARCH is tracking 47 sharks, some of them bull and mako but mostly great whites off the U.S. East Coast and in the waters off South Africa.

Many of the sharks are given endearing names, such as Princess Fi, Genie, Opera, and Sabrina. Others have handles more befitting ships, such as Poseidon, Redemption, Perseverance, and Courage.

Mary Lee, who was tagged off of Cape Cod, is named after Fischer's mother. "My parents have done so much. I was waiting and waiting for a special shark to name after her and this is truly the most historic and legendary fish I have ever been a part of and it set the tone for Cape Cod," Fischer wrote in an online description of Mary Lee.

Co-Captain Jody Whitworth and master of the Martha's Vinyard OCEARCH team Brett McBride prepare to stabilize a great white shark named Amy. Before taking measurements, blood and securing real-time technology tags, a device is inserted into the shark's mouth to irrigate its gills. (Image: OCEARCH).

To tag the sharks, the OCEARCH team first goes fishing with a hand-held line tipped with special barbless hook, engineered so it won't injure the animal. The team then brings the shark alongside their 126-foot boat, which has an underwater hydraulic lift that can hoist up to 75,000 pounds. That capacity is needed since the team is not only lifting what could be a one- to two-ton shark but also the water around it.

Once the shark is above the water line, from three to eight scientists get to work on it like a NASCAR pit crew, first placing a wet towel across its eyes to calm it and an irrigator in its mouth so it can breath. The crew then rolls the shark on its side to surgically implant the first tracking tag in its belly.

That device, known as an acoustic tag, is about the size of a Sharpie pen. It can remain in the shark for as long as ten years and can be "heard" whenever the animal swims to within a quarter to a half mile of underwater buoys that can pick up a radio frequency specific to marine tagging operations. Throughout the world, marine biologists have anchored such buoys, which can record an acoustic tag's unique ID as well as the day and time.

OCEARCHThe OCEARCH team tags a great white shark off of Cape Cod, Massachusetts.

Once the acoustic tag is in place, the OCEARCH crew rolls the shark back onto its belly and attaches a Smart Position Or Temperature Transmitting (SPOT) device. The SPOT tag is placed high on the shark's dorsal fin because its radio ping can only be received when the shark breaks the surface of the water and a satellite is in position to receive the signal. The longer the fin is out of the water, the more accurate the data. There are six ARGOS global positioning satellites orbiting the earth that can pick up a SPOT tag's ping at any time.

"The ARGOS satellite is only around about every two hours. Then the fin has to stay out of water for minute or two to get a good fix," Whitney said. "It's ridiculous that this works. It's pretty amazing when you look at the map and understand how many fixes we get on these sharks."

The third tag is an accelerometer package, which tracks fine-scale data on the shark's body movement and behavior along with water depth and temperature information. That tag, which is designed to release from the shark after just two days, records more than eight million data points each day, with the information stored to memory. The tag is embedded in a float package that contains a satellite transmitter and a VHF radio tag, which transmits a ping that can be heard over a ten-mile range with a VHF receiver and antenna.

"In this case, the VHF tag allows us to find the needle in the haystack, once the satellite tag tells us where the haystack is," Whitney said.

Although OCEARCH has been using two-day accelerometer tags, the team off Cape Cod is now going for the longest accelerometer track of a shark ever: two weeks of second-by-second behavioral information.

Finally, OCEARCH researchers attach a PSAT archival satellite tag, which records depth, temperature, and light levels (used for geolocation) and stores the data to memory. The tag is programmed to release from the fin anywhere from six months to a year after being attached. It then floats to the surface and processes and summarizes the data for transmission back to researchers via satellite.

"It'd be great if there was one tag to get all the information, but there's not," Berger said.

The researchers have gotten the tagging procedure down to, well, a science. They've perfected the process by performing it on more than 100 sharks—67 of them great whites.

To date, the largest great white the team has captured and tagged is an 18-foot, 5000-pound animal named Apache. Apache currently holds the world record as the largest fish ever caught and released by anyone, Berger said.

For their massive size and ferocious reputation, white sharks actually represent a small minority of shark attacks throughout the world, including the shark attack capital, Florida.

"Florida has more shark incidents than any place in the world, but virtually all of those bites form small sharks—black tips and spinner sharks. In fact, I'm not sure of any confirmed white shark attacks there," Whitney said.

Follow TechHive on Tumblr today.


View the original article here

Friday, 30 August 2013

Intel wants to help gamers, others overclock their SSDs

Computerworld - Without saying exactly what it will be, Intel plans to make a "big splash" near the end of the year or the beginning of next with a product that can "overclock" solid-state drives (SSDs).

"This is a product we're looking into but we have not released yet. So I'm not able to go into great detail about a future product ... as far as specs and such," said Alan Frost, marketing and communications manager for Intel.

What Frost could say is that the SSD product will allow users to tweak the percentage of the drive that's used for data compression.

Overclocking typically refers to pushing past the recommended processor clockspeed, thereby increasing performance over what is specified by a manufacturer. In the case of SSDs, Intel is using the term "overclocking" to define modifying its specified SSD parameters.

At its Intel Developers Forum next month in San Francisco, Intel has scheduled an information session on overclocking SSDs. Frost said the session will remain at a high level, and it will not reveal specifics about the product.

The conference session, titled "Overclocking Unlocked Intel Core Processors for High Performance Gaming and Content Creation," is aimed at system manufacturers and developers as well as do-it-yourself enthusiasts, such as gamers.

"Anyone interested in the performance tuning and overclocking experience on desktop and mobile platforms," the session description states.

Frost stressed that Intel executives are still talking in back rooms about what markets might benefit from creating an SSD with flexible provisioning properties.

"We've debated how people would use it. I think the cool factor is somewhat high on this, but we don't see it changing the macro-level environment. But, as far as being a trendsetter, it has potential," Frost said.

Michael Yang, a principal analyst with IHS Research, said the product Intel plans to release could be the next evolution of SandForce controller, "user definable and [with the] ability to allocate specified size on the SSD."

"Interesting, but we will have to see how much performance and capacity [it has] over existing solutions," Yang said in an email reply to Computerworld.

Late last year, Intel began using the third-party SandForce (now owned by LSI) controller for the first time in its SSD 520 flash drive.

"The premise of SandForce SSD controllers is compression. By compressing data, less time is required to transfer data from and to the SSD," Yang wrote. "Is Intel talking about its own controller? Or are they simply 'glamorizing' something they already have?"

Data compression would first and foremost increase the capacity of a drive, but it could also lead to greater performance. Frost cautioned that allocating a percentage of an SSD's capacity for compression would come at a cost. That cost could be shorter endurance, according to analysts.

"If you overclock and get faster performance and capacity and sacrifice endurance by doing so, well, then you could still enjoy the benefits if you are in a mostly read-intensive environment," said Joseph Unsworth, Gartner's NAND flash and SSD research vice president. "I suspect DataCenter server IT admins would also be savvy enough (especially at hyperscale level) to exploit this advantage."

Frost made it clear that the SSD overclocking product won't be for the average consumer, whom he still thinks is learning what the term "solid-state drive" means.

"SSD penetration is getting better, but still small overall," Frost said. "The market for this is not big."

This article, Intel wants to help gamers, others overlock their SSDs, was originally published at Computerworld.com.

Lucas Mearian covers storage, disaster recovery and business continuity, financial services infrastructure and health care IT for Computerworld. Follow Lucas on Twitter at Twitter @lucasmearian or subscribe to Lucas's RSS feed Mearian RSS. His e-mail address is lmearian@computerworld.com.

See more by Lucas Mearian on Computerworld.com.

Read more about SSD in Computerworld's SSD Topic Center.

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

Feds developing guidelines to help businesses to better secure their IT systems

Following through on an order earlier this year from U.S. President Barack Obama, the National Institute of Standards and Technology (NIST) is rapidly developing a set of guidelines and best practices to help organizations better secure their IT systems.

The agency has released a draft of its preliminary cybersecurity framework and is seeking feedback from industry.

The agency is scheduled to release a full preliminary draft in October, for public review. It will then issue the final 1.0 version of the framework in February 2014 and continue to update the framework thereafter.

When finished, the framework will provide guidance for organizations on how to manage cybersecurity risk, “in a manner similar to financial, safety, and operational risk,” the document states.

In February the White House issued an executive order tasking NIST to develop a cybersecurity framework, one based on existing standards, practices and procedures that have proven to be effective.

In July, NIST issued an outline of the framework and held a workshop in San Diego to fill in some details. This draft incorporates some of that work, and was released to gather more feedback ahead of the next workshop, to be held in Dallas starting on Sept. 11.

“The Framework complements, and does not replace, an organization’s existing business or cybersecurity risk management process and cybersecurity program. Rather, the organization can use its current processes and leverage the framework to identify opportunities to improve an organization’s cybersecurity risk management,” the draft read.

When finished, the framework will consist of three parts. One component, called the core functions, will be a compilation of commonly practiced activities and references. The second component, the implementation tiers, provides guidance on how to manage cybersecurity risks. The third component, the framework profile, provides guidance on how to integrate the core functions within a cybersecurity risk strategy, or plan.

On Twitter, framework ideas are being submitted and discussed with the hashtag #NISTCSF.

Joab Jackson covers enterprise software and general technology breaking news for the IDG News Service.
More by Joab Jackson


View the original article here

Tuesday, 20 August 2013

Businesses shouldn't let Google and Microsoft outages shake their confidence in the cloud

The recent outages of Google and Microsoft’s Outlook.com reinforce concerns many businesses have about relying on cloud services and may cause organizations that have already moved or are considering moving to the cloud to reconsider. When you look at the big picture, though, you can still trust the cloud.

It’s no secret at this point that there are a number of benefits to using cloud services. Cloud providers are generally able to take advantage of economies of scale that let them offer servers, storage, and services cheaper on a per user basis than what businesses can accomplish on its own—particularly small and medium businesses that have fewer employees to average the investment across.

Don't start selling until you see the whites of their eyes: Google patents "pay-per-gaze" ads

Although we are constantly surrounded by advertisements both online and offline, companies have no way to know whether we’ve actually seen what they’re selling. That could change in the future, with the help of Google Glass.

A newly-discovered Google patent for “pay-per-gaze” ads would use eye tracking to determine what the user is looking at. Google’s patent says it would then be able to charge companies when users look at advertisements, including online banner ads and offline billboards.

These pay-per-gaze ads could go even further, the patent says, by determining how long users have looked directly on an ad, and even measure emotional response.

“For example, if the advertiser desires to generate a shocking advertisement to get noticed or a thought provoking advertisement, then the inferred emotional state information and/or the gazing duration may be valuable metrics to determine the success of the campaign with real-world consumers,” the patent says.

Google’s patent also mentions the ability to provide automatic, augmented reality search results based on eye-tracking. Dubbed “latent pre-searching,” the system would begin its search queries for objects in the user’s peripheral vision, so they’re ready to display by the time they come into focus.

Eye tracking is not a feature that Google Glass currently offers, but the code in Glass’ companion app has hinted at support for “eye gestures” such as winks. Another Google patent has called for even more precise eye tracking, including a way to unlock Glass by tracing a lock pattern with your eyes.

Because these are just patents, there’s no guarantee Google will implement them in Glass or other products. And even if Google did offer eye tracking, it would have to convince people that the benefits outweigh the creepiness of letting the company see what you see. “Latent pre-searching” doesn’t seem like enough of a hook.

Technical hurdles come to mind as well. The current version of Google Glass already suffers from poor battery life, and the power it would take to constantly scan and interpret visual data would likely be immense. It doesn’t seem practical without major breakthroughs in battery efficiency.

Still, recent reports have claimed that the final version of Google Glass may not cost a lot, and the idea of an inexpensive product supplemented by ads definitely fits with Google’s business model. Even if pay-per-gaze isn’t coming soon, it seems like something Google will inevitably try to pull off.


View the original article here

Saturday, 17 August 2013

Cybercriminals add new exploit for recently patched Java vulnerability to their arsenal

Cybercriminals were quick to integrate a newly released exploit for a Java vulnerability patched in June into a tool used to launch mass attacks against users, an independent malware researcher warned.

The exploit targets a critical vulnerability identified as CVE-2013-2465 that affects all Java versions older than Java 7 Update 25 and can enable remote code execution. The vulnerability was patched by Oracle in its June Critical Patch Update for Java.

The exploit was released Monday by security research group Packet Storm Security, which originally acquired it through its bug bounty program as a zero-day exploit—an exploit for an unpatched vulnerability—from a researcher whose name was not disclosed. Packet Storm publishes the exploits it acquires 60 days after it receives them, with permission from their authors, so other security professionals can use them to perform penetration tests and security risk assessments.

Two days after its release, the CVE-2013-2465 exploit was already integrated into so-called exploit kits, attack tools that infect computers with malware by exploiting vulnerabilities in outdated software when users visit compromised websites.

An independent malware researcher who uses the online alias Kafeine found a live installation of the Styx exploit kit, previously known as Kein, that is using the exploit.

From an attacker’s perspective the exploit for CVE-2013-2465 is better than the exploit for CVE-2013-2460, another Java vulnerability also patched in June, that was recently integrated into a different attack toolkit called the Private Exploit Pack, Kafeine said Thursday in a blog post. That’s because CVE-2013-2465 affects both Java 7 and Java 6 installations, while CVE-2013-2460 only affects Java 7, he said.

Oracle ended its public support for Java 6 in April and will no longer release security updates for it to all users. Despite this, Java 6 is still widely used, especially in enterprise environments.

A recent study by security firm Bit9 showed that more than 80 percent of Java-enabled enterprise computers have Java 6 installed on them. The most widely deployed Java version on those systems was Java 6 Update 20.

The latest publicly available version of Java 6 is Java 6 Update 45, which is also affected by CVE-2013-2465. The vulnerability was patched in Java 6 Update 51, but this version is only available to users who have extended support contracts with Oracle.

The fact that an exploit for CVE-2013-2465 is publicly available and has already been integrated in mass attack toolkits suggests that this vulnerability will soon see widespread exploitation. Users who have yet to upgrade to Java 7 Update 25 might want to do so as soon as possible.


View the original article here

Tuesday, 30 July 2013

Tech firms squirm over their role in Prism surveillance

The disclosures about the National Security Agency's massive global surveillance by Edward Snowden, the former information-technology contractor who's now wanted by the U.S. government for treason, is hitting the U.S. high-tech industry hard as it tries to explain its involvement in the NSA data-collection program.

Last week, a gaggle of 22 large U.S. high-tech firms—including Apple, Facebook, Google, Microsoft, and Yahoo which have acknowledged they participate in NSA data-gathering efforts in some form, if not exactly as Snowden and some press reports have described it—begged to be freed from the secrecy about it in their pleading, public letter to President Obama, NSA director Keith Alexander, and a dozen members of Congress.

nsa

The July 18 A letter from America's high-tech powerhouses, which was also signed by almost three dozen nonprofit and trade organizations as well as six venture-capital firms, begged for "greater transparency around national security-related requests by the US government to Internet, telephone, and web-based service providers" in terms of how much information the government demands on high-tech customers and subscriber accounts and how.

The letter begged for the U.S. government to make the amount of requests the government makes related to national security for individual customer information public.

"This information about how and how often the government is using these legal authorities is important to the American people, who are entitled to have an informed public debate about the appropriateness of those authorities and their use, and to international users of US-based service providers who are concerned about the privacy and security of their communications.," the letter to President Obama, Congress, the NSA director and Director of National Intelligence, stated yesterday.

The revelations last month from Snowden about NSA's extensive involvement in U.S. high-tech firms for purposes of information collection has suddenly put the U.S. high-tech industry on the defensive as they struggle to offer an explanation about all this to their global users while still bound by secrecy under the U.S. Patriot Act. There's no indication yet from the White House or others in government that any change in the NSA spying program, which relies on the participation of U.S.-based firms, will change.

"This should be debated in a public setting," said John Dickson, principal at security firm Denim Group and a former U.S. Air Force officer, about the situation in which NSA's global surveillance is tied so clearly to U.S.-based companies. He noted the U.S. government has actually said little but the media much.

spyware privacy

This is all putting tremendous pressure on the U.S. high-tech industry, especially abroad in Europe where privacy questions may be making U.S. industry seem less competitive. This week Brad Smith, Microsoft general counsel and executive vice president, legal and corporate affairs at Microsoft, A issued a public statement that sought to clarify Microsoft's participation in the U.S. government's content gathering methods.

""Recent leaked documents have focused on the addition of HTTPS encryption to Outlook.com instant messaging, which is designed to make this content more secure as it travels across the Internet," Microsoft counsel Smith wrote. "To be clear, we do not provide any government with the ability to break the encryption, nor do we provide the government with the encryption keys. When we are legally obligated to comply with demands, we pull the specified content from our servers where it sits in an unencrypted state, and then we provide it to the government agency."

Microsoft's SkyDrive and Skype A is handled somewhat similarly in terms of government requests, Smith said. As far as enterprise and document storage for business customers, "we take steps to redirect the government to the customer directly, and we notify the customer unless we are legally prohibited from doing so," Smith stated in his July 16 post. "We have never provided any government with customer data from any of our business or government customers for national security purposes."

Smith added Microsoft got four requests related to law enforcement in 2012. "We do not provide any government with the ability to break the encryption used between our business customers and their data in the cloud, nor do we provide the government with the encryption keys."

In the meantime, it's safe to assume in this NSA leaks debacle that "the bad guys have switched tactics" and probably wouldn't use U.S.-based high-tech services, Dickson points out. And in this atmosphere of rising cyber-nationalism, the possible role of China's government and its own high-tech industry have to be asked, too, he noted.

Former head of the U.S. Central Intelligence Agency and the NSA, Gen. Michael Hayden, recently charged forward on that topic in an interview with The Australian Financial Review.

Hayden said he believes that China-based network vendor Huawei conducted clandestine activities and shared with the Chinese state "intimate and sensitive knowledge of the foreign telecommunications systems it is involved with." According to the published report, Gen. Hayden said the Huawei is a significant security threat to Australia and the U.S., has spied for the Chinese government, and intelligence agencies have evidence of this.

A Huawei spokesman, John Suffolk, Huawei's global cyber security officer, is quoted by the Australian publication yesterday as calling Hayden's remarks "unsubstantiated and defamatory" and that any critics of the company should present any evidence publicly.In an opinion piece on CNN.com today, Gen. Hayden railed openly against Edward Snowden as a national security threat, saying he "fled to China with several computers' worth of data from NSANET, one of the most highly classified and sensitive networks in American intelligence."

Hayden acknowledged that one aspect of the fallout from Snowden's leaks is that "the undeniable economic punishment that will be inflicted on American businesses for simply complying with American law."

Hayden's remarks on CNN also seem to sarcastically criticize the Europeans now complaining about the NSA activities and how they may violate European data-privacy laws. "Others, most notably in Europe, will rend their garments in faux shock and outrage that these firms have done this, all the while ignoring that these very same companies, along with their European counterparts, behave the same way when confronted with the lawful demands of the European states."

Hayden continued: "The real purpose of those complaints is competitive economic advantage, putting added burdens on or even disqualifying American firms competing in Europe for the big data and cloud services that are at the cutting edge of the global IT industry."

As if all this weren't enough, former President Jimmy Carter also spoke out yesterday on NSA global surveillance, suggesting the NSA data collection practices were harming democracy. Former president Carter also said Edward Snowden's revelations didn't really harm national security and and was actually "beneficial" because "they inform the public."

Ellen Messmer is a senior editor at Network World. She covers news and technology trends related to information security.
More by Ellen Messmer


View the original article here