Showing posts with label Takes. Show all posts
Showing posts with label Takes. Show all posts

Tuesday, November 27, 2012

Google Play Takes Away Reviewers' Mask of Anonymity

By Peter Suciu
TechNewsWorld

Google has begun to require that reviewers on Google Play be signed in through Google

View the Original article

Tuesday, November 20, 2012

Whither OpenSolaris? Illumos Takes Up the Mantle

By Jack M. Germain
LinuxInsider
Part of the ECT News Network
After Oracle bought Sun Microsystems, its lack of interest in maintaining OpenSolaris as an open source operating system drove a group of dedicated developers to pick up where Sun left off. The Illumos Foundation has created a new distro that builds off of OpenSolaris, but calling it a form might not exactly be accurate.For the installed user base of the former Sun Microsystems' OpenSolaris OS, questions about its continued support and development remain largely unanswered. When Oracle bought Sun Microsystems, it raised fees for its technical help and halted further development on OpenSolaris, replacing it with its own Oracle Solaris 11.
Enter the Illumos Foundation, which created a fork of the OS and is gearing up to continue its development. Illumos developers see strong interest in the project as it gains momentum.
An unexpected outcome of the Illumos Project could be the birth of a modified business model for open source. The Foundation is focusing on a collaboration of developers pursuing their own interests related to the Illumos OS platform.
"In essence, Illumos did more than create a fork of OpenSolaris. It took a sharp left turn. At issue is Illumos created its own version of OpenSolaris. That presented questions and concerns about its interoperability and compatibility with the existing user base," Laura DiDio, Principal at ITIC, told LinuxInsider.
Fork For the Taking
Oracle completed its acquisition of Sun Microsystems in January 2010. The general impression at that point was that OpenSolaris was dead, noted DiDio.
"Oracle inherited 40 percent of the user base of Sun's OpenSolaris customers. The new owner was logically looking for a 60 percent increase," she explained.
The clear mission plan for Oracle was to build the user base for its own Solaris derivative. If Oracle could have killed off OpenSolaris from the start in pursuit of its own closed OS version, it would have done so, surmised DiDio.
"The trend for Oracle with OpenSolaris has been downhill. User comments are very devastating," she added.
Fork in the Making
On Aug. 3, 2010, Garrett D'Amore announced the formation of the Illumos project. He is the head of Nexenta Systems, a major sponsor of the project.
His announcement called it a community effort by some core Solaris engineers to create an open source Solaris by swapping closed source bits of OpenSolaris with open implementations. At first, the project name took two parts.
"Illum" from the Latin word for "Light" and "OS" for "Operating System." Illum OS almost immediately morphed into a single word spelling Illumos.
Regardless of how the founders decided to spell their OS derivative, Illumos is not really a fork of OpenSolaris. According to Bill Roth, Vice President of Marketing at Nexenta Systems, it is more a continuation of OpenSolaris.
Solaris Namesake
In what may seem little more than a pea pod shuffle, the shakers behind Illumos, see their efforts as taking the OS in new direction. That direction is much more than a fork that parallels the main software roadway.
"We are a main line. We're continuing where OpenSolaris left off in the guise of Solaris," Roth told LinuxInsider.
Nor is the organizational structure a foundation, he noted. The founders are in the process of getting organized. The structure is essentially a 501c6 trade organization entity, he explained.
"We're just finishing our basic framework. We're putting together a board of directors," he said.
Code Colossus
At issue is the trail of builds that led to separating open source from not-so-open code in OpenSolaris. For example, In 2006, Sun open sourced the kernel of what it called OpenSolaris, but that did not include all of its code.
"The principal reasons for not releasing all of the code is that bits of it were owned by companies that went out of business. Solaris Nevada Build 27 was open sourced," Jason Hoffman, the founder and head coach at Joyent, told LinuxInsider.
When Oracle bought Sun, the buyer had no big interest in maintaining it as open source. So Joyent decided to pull out all proprietary drivers and code and replace them with open source to make a 100 percent open source version of what was OpenSolaris. That became Joyent's SmartOS, he explained.
Illumos as a kernel project has several very solid distros that serve different purposes built around it. For example, some distros are designed for desktops. Other distros are designed to run appliances or servers.
More of the Same
Several distro makers did the same thing in developing spin-offs of Sun's OpenSolaris. For example, Nexenta's distro is Illumos.
"The Illumos Project is where we aggregate all of our kernel changes. So we are a distro based on OpenSolaris 11 the same way other Linux distros build off an existing product such as Ubuntu," said Hoffman.
The way the definition of fork is applied is sensitive and matters greatly. Hoffman and Roth make that a clear distinction.
"It is a fork of the open sourced OpenSolaris 11. Saying it's a fork of OpenSolaris is like saying someone forked Ubuntu. At Sun some parts of the open sourced kernel still weren't open sourced," said Hoffman.
Open Source Anew
As the Illumos Project gears up to gain more traction, onlookers see a different perception. The Illumos community is not a peace, love and open source community. Rather, it follows a new model for open source, according to Roth.
"One thing we learned during the recession of 2008 is that open source can only continue when there is an underlying economic need for it to proceed -- for the simple reason that programmers need to eat and food costs money. So doing stuff for free doesn't necessarily keep one's children fed," he quipped.
The Illumos project now is a series of businesses all collaborating. Project participants are continuing the CDDL model with a unique difference compared to more traditional communities.
"We follow the mainline code and have to contribute it back. But we are adding our own intellectual property as a value add. We are firm believers in the open core model. At the core is Illumos. At the core is open source," he explained.
Going Great
Roth pegs the success of the Illumos Project's creation on several major strengths. Diversity, continuity and an economic base sustain the community.
"Our progress is going better than expected. We haven't experienced obstacles yet that are out of order. We are working with about 20 different vendors to develop the code. On the technical side things are working well," he said.
The community is succeeding around a set of economic entities that are working towards their own interests yet are collaborating. So far there is no overlap. All collaborate on what is core to the community, according to Roth.
To-Do List Done
The Illumos Community moved the development of the code much further than Oracle has done within Solaris 11, Hoffman said. For instance, there are more than 1,000 bug fixes in Illumos that will never be in OpenSolaris because of the closed code Oracle kept in there.
Now Illumos is a fully functional hypervisor to run as a virtual machine that competes with any product on the market. Joyent made that improvement to the OS and gave it back to the community, he added.
"One of the things we still have to work on is drivers for new products. This is a great example of our community working together to get what we all need," said Roth.
How Secure Is Obscure?
Whether Illumos is gaining traction is still up for debate, according to DiDio. Illumos became a haven for those who do not like Oracle and were much at odds with the company.
"Illumos can have a good following. It is small but very committed with very strong devotees who don't give up easily," DiDio said.
The continued success of Illumos could come down to a marketing battle, she believes. OpenSolaris users have a core product.
"There is an opportunity for Illumos. Will they have the budget for the kind of marketing needed to attract a user base?" she suggested. "The biggest problem Illumos faces is it needs to be more noticed. They have taken a big turn away from the accepted core or root of what OpenSolaris was. Have they gone too far afield?"
Brand Name vs. Niche
Part of a future success formula will be the ability to attract converts from Solaris. How many people looking for an alternative to OpenSolaris know about Illumos, DiDio wondered.
They also have to figure out how to reach out to traditional OpenSolaris users who will otherwise move to HP or IBM solutions. In short, OpenSolaris customers need to know how difficult it will be to switch and at what cost.

"This is a tremendous opportunity for Illumos. The community must capitalize on visibility through marketing. They need to illuminate on Illumos," DiDio said. "If the niche is too small and customers' needs are too great, then Illumos will fail."

View the Original article

Monday, November 19, 2012

Skype Takes Heat for Security - Both Too Little and Too Much

By John P. Mello Jr.
TechNewsWorld
Skype had an on-and-off kind of week, fixing an embarrassing flaw in its password reset system and then being called too secure for many corporate networks because its encryption could allow company secrets to escape undetected. Then, it had to deal with a report that it had given out information on one of its users to a private investigator who simply asked for it.Microsoft had to temporarily disable Skype's password reset feature last week after a Russian hacker revealed a simple way to lock users out of their accounts.
To hijack an account, all an attacker needed to know was an email address associated with that account. That address could be used to create a new account, which could then be used to reset the password of the original account and compromise it.
Ironically, Skype's robust security features are one reason some organizations bar it from their networks, said Tom Nichols, vice president for corporate marketing for Endace. "Skype is a risk because it's deeply encrypted and it can be used to transfer information out of an organization without anybody knowing what's going on," he told TechNewsWorld.
Skype is one of many applications running on corporate networks in defiance of company security policies, a study by Endace released last week revealed. Of the more than 100 senior network IT professionals from Fortune 500 companies, 53 percent confessed that their employees use applications that violate corporate policies, the study found.
After Skype fixed its password problem, it found itself in a bad light again when it was reported that the company had handed over the user information of a Dutch teenager and fan of WikiLeaks to a Texas cyber intelligence firm that just asked for it.
That appears to be a violation of Skype's privacy policy, which states it will not surrender user data "unless it is obliged to do so under applicable laws or by order of the competent authorities."
Workers Resent BYOD Logging
Workers like using their own devices to increase their productivity at the office, but they don't like the security measures that need to be imposed on those devices to keep their company's data safe.
That was the finding of a study released last week by Blue Coat, a provider of mobile device security services.
Fewer than a quarter -- 24 percent -- of the respondents were willing to have their companies log their access to corporate data through their personal device.
Even fewer wanted their bosses logging the Web content they accessed with their personal devices (19 percent) or restricting the types of sites and content they accessed (12 percent).
However, more than half the respondents were willing to have corporate-sponsored malware protection on their personal gadgets (55 percent) and comply with passcode requirements (58 percent).
"Users are knowledgeable enough now to want to have malware protection," Sasi Murthy, Blue Coat senior director of product marketing, told TechNewsWorld. "The contention shows up when we start talking about logging their personal data or personal access to the Web and also restricting personal access to things."
Malware's Future Is Mobile
As the end of the year approaches, it's customary to look forward and muse on what the next 12 months will bring. For malware researchers, those next 12 months will be mobile.
"You're going to see a continued shift into mobile vulnerability research," Brian Gorenc, manager of HP Enterprise Security's DVLabs, told TechNewsWorld. "There are conferences around the world now completely focused on mobile."
Malware will also become more of a team sport in the coming months, he added. "In the past, malware was done by one person," he observed. "Now you have things like Stuxnet and Flame with full-fledged development teams behind them."
"You're going to see stronger development efforts put behind this stuff in the future and an increase in those types of malware families," he predicted.
Data Breach Diary
Nov. 12: Blizzard, the creator of "World of Warcraft," is sued by two players who allege that the company has failed to take necessary measures to secure the private information of its customers. Blizzard counters that the lawsuit is without merit and contains patently false information.Nov. 13: The Chicago Board of Elections Commissioners acknowledges that a database containing the names, addresses, driver's license numbers and the last four digits of Social Security numbers of some 1,200 people who had applied to work at the city's polling places on election day was exposed online. Earlier in the day, a security firm, Forensicon, claimed the breach was much larger and that it affected 1.7 million registered voters.Nov. 13: A survey of UK companies by the Ponemon Institute and sponsored by Faronics revealed that 54 percent of the organizations polled had experienced at least one data breach in the last year and that 19 percent of them had experienced more than four break-ins during the period.Nov. 14: Adobe acknowledges that it is investigating a data breach on Nov. 13 by a hacker calling himself ViruS_HimA which may have exposed contact information for 150,000 employees and partners of the company.Nov. 14 South Carolina Gov. Nikki Haley announces she is ordering cabinet-wide cyber security measures to be put in place following a data breach in September in which hackers compromised 3.5 million Social Security numbers and information on 387,000 credit and debit card accounts. According to one estimate, the breach could cost South Carolina businesses as much as US$330 million.Nov. 15: NASA sends warning to all employees and contractors that their personal information may have been compromised when a laptop locked in an employee's car was stolen. The agency could not determine the magnitude of the breach at the time of the warning.
Upcoming Security Events
Nov. 28-29: Smart Strategies for Secure Identity. Washington convention Center, Washington, DC. Registration by Nov. 6: $1080. By Nov. 27: $1,200.
Nov. 28-29: Strategic Security Response Summit: The Detecting and Preventing Emerging Threats. Washington Convention Center, Washington, DC. Regular registration: $470. Government registration: $230.
Dec. 3-7: Annual Computer Security Applications Conference. Orlando, Fla. Registration is now open.
Dec. 3-6 Black Hat Abu Dhabi 2012. Emirates Palace, United Arab Emirates. Registration by Dec. 2: $1,895. On-site Registration: $2,595.
Jan. 7-9:Redmond Identity, Access & Directory Knowledge Summit 2013. Microsoft Conference Center, Redmond, Wash. sponsored by Oxford Computer Group. Early registration: $450. Registration after Nov. 21: $650.


View the Original article