Translate

Showing posts with label Technology. Show all posts
Showing posts with label Technology. Show all posts

Thursday, June 19, 2014

Are Employees Putting Organizations at Risk?


According to a recent report released by Forrester Research, the global public cloud market is expected to hit $191 billion by 2020, based on Forrester's last forecast (published in 2011), this represents a 20% increase over the same time period. It also represents a significant increase from where the market is currently, Forrester estimates that the market was public cloud market was $58 billion at the end of 2013.

However, the challenge facing enterprises with cloud adoption is quite concerning. According a recent article published by Computerworld, "There's a tug-of-war tension in the enterprise right now," said Gartner analyst Lydia Leong. "IT administrators very rarely voluntarily want to go with the public cloud. I call this the 'turkeys don't vote for thanksgiving' theory. The people who are pushing for these services are not IT operations people but business people."

There is no doubt that the business owner is making this selection to drive their business and sees little to no risk with their decision. However, IT security and the lack of oversight, digital loss prevention techniques and audit requirements can leave a company in precarious situation.

The question is, how does IT and the business user coexist as a partners and not as roadblocks to business growth? The key is a common product and sales technique. Understanding the business requirements is critical to forming the right partnership. IT needs to focus on delivering products that help the business become more efficient and meet their needs to facilitate business. The business needs to be the buyer, but IT needs to be there to make sure the corporation remains well protected.

One of the very real risks that corporations are facing today is cloud based file sharing, the reality is that these applications can be acquired very easily by the business, unfortunately, there is no way to control what is actually being store outside the firewall or if the service provider even meets corporate standards. Many companies have blocked the most popular URLs to prevent internal use, but Gartner lists over 100+ competitors, many approaching file sharing from a different industry focus, so it is unrealistic to expect an IT department to be able to prevent all files sharing solutions.

This is just one example of the risk that the business faces when they acquire technology without going through the correct process. But IT must also understand, they are not the business, nor must they decided what is best for the business, rather they must learn to deliver the business requirements, while ensuring that the product or service meets with the Corporate Security Standards. Only then wll the risk of Rouge IT applications subside!

Monday, June 16, 2014

Why International Organizations don’t want to do business with US Cloud providers


While you would need to have been vacationing in the Rockies for the last year or so to have missed the stories outlining the US Government’s legal right to obtain data, most people have just come to accept that we have no choice in the matter. Court papers released on Monday show that Microsoft is fighting a US warrant for customer data stored overseas.

The US is pursuing criminal matters against an individual and has requested emails stored in Dublin Ireland. Microsoft’s theme for their objection to the US warrant is that allowing the obtuse nature of the warrant would "violate international laws and treaties, and reduce the privacy protection of everyone on the planet," as well as "have a significant negative impact on Microsoft's business, and the competitiveness of US cloud providers in general".

In support of this, both Apple and Cisco have filed a friend-of-the-court brief backing Microsoft's position, this is in addition to ones submitted earlier in the week by Verizon and AT&T. Many international organizations recognize the fact that the US government has the right to ask and obtain data from a US company or subsidiary customer data no matter where it resides in the world. The problem is that many International companies feel this is a serious risk to doing business with US companies, I guess only in America do we teach of a global economy. Yes it is true that the law exists, and it is true that companies may not do business with a US company because of it, however, if you build a product that they want, they will use it.

Let’s face facts, data in the cloud is subject to risk (so by the way is data behind the firewall, just ask Target), if it were not, you would see considerably more data stored in the cloud. Having worked both cloud solutions and enterprise software, it is very easy to see the distinction; however it is far more complex when trying to run a business.

We often talk about Salesforce.com (SFDC), as being a major cloud platform that companies heavily rely on. I mean after all, if your entire customer database is on SFDC, you would really need to trust the cloud, right? Well truth be told, the average sales person will probably do more damage leaving an organization with his contact list than losing data from the use of SFDC.

As companies consume homogenized data, it becomes a commodity; you purchase the integration value, not the protection of the data. Don’t misunderstand, the data must be protected, however, no one believes that a cloud provider could deliver better protection than keeping the data encrypted behind their own firewall. Organizations traditionally move data that would not jeopardize the organization to the cloud. This may also include data that extends beyond the firewall.

The debate will rage on for several more years, our society is very fickle, when bad things happen, we want the government to do their job, when things are okay, we want the government to stay away. But how do you balance this? At some level we must realize that the ability to communicate across thousands of miles in milliseconds puts us all at risk, where do we draw the line? I am not advocating government censorship and I am a firm believer that power corrupts, but is profiling patterns, which is typically what happens with most of our data, the worse thing to give up for our protection?

Do we really believe that the US government is doing anything more than other governments, just because their Snowden hasn't gone public? I remember as a child my father saying to me after I got caught doing something I shouldn't have been doing, “The difference between you and me, is that I did not get caught”, I was about to challenge him on that statement, but having thought about this for a brief second, I realized, to defend myself, would mean I would have to tell him about the other 100 times I got away with it. Do we really believe that spying is a US government anomaly?


Thursday, June 5, 2014

Is Big Data secure enough?


Most people have heard the concept of Big Data, but few understand how it impacts our lives on a daily basis. The news outlets will sensationalize the government (particularly the NSA) for using Big Data techniques on public data in order to spy on people. For example, selfies are now used by the NSA for facial recognition, but should any of this surprise people? The data we put on the web is viewable by almost anyone and you must realize that companies like Facebook, twitter, LinkedIn are in the business to make money. So let’s face it their data is priceless to the right audience, this includes governments, and don’t think for a second that the US is the only government doing this, however we are the only ones where it makes an interesting news story.To level set, here are some interesting data points from Wikipedia

Government
  • In 2012, the Obama administration announced the Big Data Research and Development Initiative, which explored how big data could be used to address important problems faced by the government. The initiative was composed of 84 different big data programs spread across six departments.
  • Big data analysis played a large role in Barack Obama's successful 2012 re-election campaign.
  • The United States Federal Government owns six of the ten most powerful supercomputers in the world.
  • The Utah Data Center is a data center currently being constructed by the United States National Security Agency. When finished, the facility will be able to handle a large amount of information collected by the NSA over the Internet. The exact amount of storage space is unknown, but more recent sources claim it will be on the order of a few Exabytes.
Private sector
  • eBay.com uses two data warehouses at 7.5 petabytes and 40PB as well as a 40PB Hadoop cluster for search, consumer recommendations, and merchandising. Inside eBay’s 90PB data warehouse
  • Amazon.com handles millions of back-end operations every day, as well as queries from more than half a million third-party sellers. The core technology that keeps Amazon running is Linux-based and as of 2005 they had the world’s three largest Linux databases, with capacities of 7.8 TB, 18.5 TB, and 24.7 TB.
  • Walmart handles more than 1 million customer transactions every hour, which are imported into databases estimated to contain more than 2.5 petabytes (2560 terabytes) of data – the equivalent of 167 times the information contained in all the books in the US Library of Congress.
  • Facebook handles 50 billion photos from its user base.[36]
  • FICO Falcon Credit Card Fraud Detection System protects 2.1 billion active accounts world-wide.
  • The volume of business data worldwide, across all companies, doubles every 1.2 years, according to estimates.
  • Windermere Real Estate uses anonymous GPS signals from nearly 100 million drivers to help new home buyers determine their typical drive times to and from work throughout various times of the day.
The amount of data we create daily is mind boggling and the amount of data we put on the web unsecured should be of great concern, but we often do not think twice of posting photos of our children on Facebook to share with friends, or writing on our timeline that we are on vacation (this is invaluable information if you are a thief), then we get upset because the NSA is collecting and using this information to “spy” on American citizens.

The truth of the matter is that the US Government is not spying on anyone; they, like all private sector companies, use the data to form patterns and then target high profile individuals. Is the US Government really doing anything different than Google? Google looks at your browsing history to serve up targeted ads that you are more likely to click on to generate revenue. Amazon serves up potential items for you to impulse purchase based on your previous buying history and items you have looked at, all of this is an invasion of privacy, but some we accept as helpful, even cool, and others we deem as violations of our civil rights. Let’s face it, if you don’t want someone spying on you, don’t put it out on public display!

Big Data security is finally becoming an important topic, many companies are bringing in large amounts of data purchased from Twitter, Facebook and other public sites to develop buying profiles to increase the target rates of their marketing spend, however at what point does a bunch of public data start to become private information. For example, let’s say on Facebook, you always put down that you are at the local Starbucks getting coffee, you go to work and then Tweet about your favorite sports team acquiring a new star player, after work you use Google maps to find a restaurant and you run into an old friend and post a selfie on SnapChat. You go home and then browse a few of your favorite sites. By themselves they mean very little, but combined a company now has a very strong profile of your behavior, what you like, what you may buy, political views, how to increase the chance you will buy from them and so on.
So what happens when these profiles are hacked and the wrong person acquires a bunch of data that seems worthless until it is combined with all the other data they have collected? Is this any better than Target losing 40 Million credit card numbers?

Interestingly both Hortonworks and Cloudera (both Big Data software companies) acquired security companies to enhance their offerings. From my perspective, it is about time. But protecting the data in storage is not the only risk, if you are going to move large subsets of data that do not have strong relevancy on its own, but when combined build very sensitive profiles, then you must secure the transport of the data at all times. Many companies feel that public data does not need to be moved securely since it is already public, but the real risk is the selection of data these companies are collecting and how they eventually assemble the profiles, both components must be secured.

Big Data is a part of our lives now and will not go away, it will evolve and become even more invasive, it is time that companies collecting data secure all transmissions, even public information!

Tuesday, June 3, 2014

Hey MAC - It’s time to grow up



Ever notice how most Mac users are skinny? It's because of all the calories they burn because they can't stop talking about how great their Macs are. OK that is probably not accurate but I did find it comical when I read it. But you know the people I am referring to, the really smart guys that cannot get enough MAC speak, My favorite line that they often throw out is that Mac’s just work, well in reality, one would beg to differ, otherwise why would you have macfixitforums.com (on the net for over 10 years and is now part of CNET).

OK enough picking on the guys who are going to take over the world, we will need them someday soon the way things are going. But I digress; my real topic today is that it is high time that Apple grow up. If you look back at the old days, Apple created a unique buzz about being your own person, that their technology, although ubiquitous, could be used by the buyer to be as individualistic as they were. One of my favorite commercial sequences was the ongoing debate between the corporate pitchman from Microsoft and the really hip Apple pitchman. These commercials tried to show how Apple was the hip up and coming product offering that would create disruption in the business world and Microsoft was the old stagnant way to do business, just throw money at it and raise prices. I am sure plenty will debate that Apple did in fact accomplish a disruption in the market place, especially if you ask your company IT administrator.

In fact the debate continues to this very day. Tim Cook pointed out at the Worldwide Developers Conference this week that OS X Mavericks, which he said accounted for 51% of all Macs in use "Is the fastest adoption ever of any PC operating system in history. Now, you may wonder how that compares to Windows. I knew somebody was going to ask, so I made a chart."

According to Computerworld  the pie chart showed that Windows 8, which Microsoft launched in October 2012, owned a small sliver of Windows overall. "It's at 14%. Need I say more?" Cook continued, to applause and laughter from the very pro-Apple crowd.

Needless to say, it was not mentioned that the overall numbers of Mac users still dwarf PC users and the fact that OS X Mavericks was free, unlike Windows 8. However Windows 8.1 release which also was provided at no charge was trending the same as OS X Mavericks.

In the end though does any of this really matter? People should be tired of the gimmicks, Microsoft and Apple should be focusing on building technology that improves the life of its users and integrates with different technologies. One should not have to be forced to use a PC or Mac to gain ubiquitous access to the overall suite of services. What made these companies great is that they changed the way we viewed how technology could improve our lives, it seems that it has moved towards who can drive the bigger profit and maintain the greatest market share through marketing and empty promises. It is time that both Apple and Microsoft get back to the basics and improve their software and delvier the next breakthrough in computer performance.

Monday, June 2, 2014

Do File Sharing Sites Provide Enough Security?


Whether you are a consumer or a business you must carefully consider what you are willing to put out in the public arena. Even if you believe your data is encrypted or protected by the provider, once it leaves your control, you have to accept the fact that you are relying on someone else to deliver the same level of care to your documents. On May 6th this year, ARS Technica published the following article, “Dropbox disables old shared links after tax returns end up on Google, Vulnerability that may also affect Box sent shared documents to Google AdWords.”

For most consumers, these file sharing sites are an easy way to share pictures with friends and families, but, more and more users are using these sites to store personal data. In fact, file sharing sites are expected to host more than 36% of personal data by 2016. While Dropbox did resolve the aforementioned issue, the question is not whether it is good enough, but rather when will the next vulnerability occur?

As more and more businesses move to increase collaborative efforts between their employees and trading partners and utilize public File Sharing Sites, the Security Team has to be concerned with what data is leaving the firewall. Even with encryption at rest and encryption during transit, vulnerabilities will always be identified. Sometimes they are even trivialized until it becomes wide spread. Box.com, one of the larger file sharing sites for businesses posted the following on their Box.Com blog“Once someone has access to the user's auth-token they are able use that for browser login. This is a known issue and was a product decision to leave in for Box Sync.”

Is it fair to ask a company to protect data the same way for all customers? Does a large Enterprise require more security than a Small Enterprise and does a consumer need the same level of security? More security means more complexity and greater overhead for systems and bandwidth transfers. In reality each person and business needs to decide what data is relevant for file sharing services versus on premise solutions. If you are not comfortable with the data being exposed then you must look long and hard with keeping your sensitive data on someone else’s “secure” environment.

Tuesday, October 16, 2012

Are You Maximizing Facebook for Your Business?


Many businesses understand that they must have a social media strategy, but many companies do not fully understand how to accomplish this. In order to be successful, let’s first understand the demographics of Facebook. According to a recent report on Pingdom the average age for a Facebook user is 40.5 years old. Here are some additional stats that may alter your way of thinking about Facebook, 65% of Facebook users are 35 or older and Facebook and Twitter have the same gender distribution: 40% male, 60% female.

Here is what is truly interesting about the age trend for Facebook and Twitter. Compared to a previous survey Pingdom did 2.5 years ago, the age of the average Facebook user has gone up two years, while the age of the average Twitter user has gone down two years. In other words, Twitter’s user base is getting younger, while Facebook’s is getting older.

So now that you understand who is using Facebook, let’s start to figure out how you maximize your exposure. The first thing you need to consider is how to build a strong fan base. Your Facebook page can drive traffic to your website, increase sales and build customer loyalty, but like anything else you have to carefully create your presence. Make sure your page is using your company name and any specialized keywords that your business is typically found under.

You want your page to stand out from competitors, to do this, you need to engage your fan base, for example, you can customize the tabs of your page to highlight your business, including photos, videos, hot items and genera discussions. You also need to keep the content fresh, there is nothing like going back to a website several times to see no updates, so while it may take you some time each day, make sure you stay current with your content, otherwise your fan base will go elsewhere. If you want to grow your fan base quickly, Host contests or giveaways, according to Facebook, research by Forrester shows that contests, giveaways and promotions are the fastest ways to build fans to your page.

Another great way to increase your exposure is to collaborate and connect with Facebook Applications, they are a great way to network and do business through your Page. Facebook has over 50,000 applications on its platform. There are Facebook apps available for everything, including Twitter, Wordpress, Google Reader, and many others. To get your business moving start with the following, and build from there, Add the RSS Feed application to incorporate your blog , add the LinkedIn Profile application to promote your LinkedIn account by posting a badge on your Page, add the Twitter application to incorporate your Tweets.

Once you have built your page you need to gain exposure by getting everyone involved, don’t just put up a Business Page and forget about it. Monitor the feeds, make updates and discuss industry trends, product reviews and relevant events. Encourage employees to be active and participate on your Page. The more people involved on Facebook, the more exposure your company will receive With fresh content and lots of activity, your Page will build in strength and become successful — no one will follow a stagnate page. You should also join other Facebook groups and become fans of other Business Pages to build a network of conversations

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

.

Monday, October 15, 2012

Can we protect against nation-state espionage?


Researchers at Kaspersky Lab have uncovered new nation-state espionage malware that has links to two previous identified espionage tools known as Flame and Gauss, and it appears to be a “high-precision, surgical attack tool” targeting victims in Lebanon, Iran and elsewhere.

The new malware has been coined miniFlame, although the attackers who designed it called it by two other names – “SPE” and “John.” MiniFlame appears to be used to gain control of and obtain increased spying capability over select computers originally infected by the Flame and Gauss spyware.

According to Wired, “It is the fourth piece of nation-state malware discovered in the last year that appears to have been created by the same group behind Stuxnet, the groundbreaking cyberweapon that sabotaged Iran’s nuclear program and is believed to have been created by the U.S. and Israeli governments. The others – all designed for espionage rather than destruction – are DuQu, Flame, and Gauss.”

“With Flame, Gauss and miniFlame, we have probably only scratched [the] surface of the massive cyber-spy operations ongoing in the Middle East,” the Kaspersky researchers write in a report released Monday. “Their true, full purpose remains obscure and the identity of the victims and attackers remain unknown.”

The report was released as the U.S. continues to make claims against China for its involvement in nation-state cyberespionage. Most notably are the alleged hacks against Google to obtain intelligence about political dissidents and against defense contractors to obtain military secrets.

The risk with miniFlame/SPE malware is that it can be used on its own as a small, standalone data collection tool, or it can be inserted into Flame or Gauss. Until recently, it was assumed that Flame and Gauss were independent nation-state projects that had no connection; but the discovery of miniFlame is the first solid clue that the two projects came out of the same “cyberweapon factory” and were part of the same larger operation.

While the targets appear to be focused on the Middle East, the question must still be answered as to how far this has spread and what information are these countries trying to obtain. While many of us feel that our data is protected and even if it is not, what is the real harm in being compromised, the bigger risk is what happens when the financial institutions are attacked – replacing a credit card is an inconvenient, not being able to use credit cards could impact a nation.

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

Friday, October 12, 2012

Now it is Microsoft versus Google in German patent lawsuit

Yesterday Microsoft informed the judge that it will amend their patent infringement lawsuit against Motorola Mobility to include Google as a defendant. Microsoft is suing over European patent EP0845124, which covers a “computer system for identifying local resources and method therefore. The same technology is addressed in U.S. Patent no 6,240,360.

The German lawsuit, filed in April, goes after Android’s Google Map app, which Motorola spent a good amount of time yesterday denying Microsoft’s infringement accusations without ever getting into actual server process discussions. Microsoft has aggressively going after Android handset makers to agree to license agreements, including LG, Samsung and HTC. All have signed on to avoid the legal battle, which can put up to $15 per handset they sell.

Motorola has held out and had hoped that it’s acquisition by parent company Google would prevent Microsoft from taking them on – a strategy that has ultimately failed. Motorola has been forced to pull virtually all of their smartphones from retailers in Germany due to previous patent litigation with Apple and Microsoft. The move today is believed to show that the Android OS is not free and that the Windows Phone system would be a worthy alternative.

Once again Patents will force manufacturer behavior, which will end up providing the consumer with little choice in which phone they can purchase. It would be interesting if these companies would put more of the legal costs into R&D and develop the next generation phone rather than continually fight each other for positioning. The concept of the strong will survive, now appears to mean that the one with the best lawyers will survive – not the best product!

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

Wednesday, October 10, 2012

Walmart versus Amazon



The lines between on-line retailers and brick and mortar have become blurred even further today as Walmart announces same day delivery in several launch cities. In competing with Amazon (AMZN) and their push to deliver products the same day to meet consumer’s requirement for instant gratification, Walmart has conveniently launched their same day delivery service jut in time for Christmas.

For a flat $10.00 you can have all of your items delivered the same day, Walmart intends to utilize their large quantity of store locations to act as warehouses versus Amazon’s methodology of using strategically place warehouses to support the same day shipping. In reality Walmart has the distinct advantage since you can find them virtually everywhere – this expands their product availability and allows them far more flexibility in the shipping process.

Just like all things, the old become new – if you remember it was predicted that on-line retailers would make the old brick and mortar stores obsolete, and to a large degree we saw many icons collapse as on-line retailers were able to offer lower cost for the same products (does anyone remember Circuit City or Comp USA?). But in the end we have seen a integration of on-line and brick and mortar, in rare instances the exclusive on-line or brick and mortar store has been able to thrive, but the most successful ones had to become more than just a one trick pony.

\It will be interesting to see who ends up winning the holiday season, Walmart or Amazon.  What I can predict is that one of them will see their stock price soar while the other will see it decline dramatically. Investors will be watching this battle closely to see which power house retailer comes out on top.

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

Friday, September 7, 2012

Can The Internet Be Silenced?

Worldwide, suppression of free speech is growing and nowhere is that trend more evident than on the World Wide Web. The man who created the Web, Tim Berners-Lee, felt compelled to mention this trend while unveiling the newest report on how governments manage the online lives of their constituents. The bottom line, Berners-Lee said, is that there is no kill switch for Internet freedom.

There is no off switch for the Internet, Sir Tim Berners-Lee, who's widely acknowledged as the father of the Web, said in London when launching the World Wide Web Index report for 2012.

Growing suppression of free speech, both online and offline, is the major challenge to the Web's future, Berners-Lee stated. Countries in the Middle East as well as China, have continually attempted to suppress free speech, but information seems to find ways to get in and out of these countries.

Even the United States has attempted to insert an Internet kill switch, but this was dropped after strong opposition from a wide spectrum of society here, including consumer advocates and privacy groups. Sen. Joseph Lieberman, who pushed for the kill switch provision to be included in the Protecting Cybersecurity as a National Asset Act, said in a TV interview that the US government should follow the lead of China in this area.

Several Western democracies that scored high on the Web Index either monitor citizens' access to the Internet or restrict it in some way. They include the UK and Australia, which scored 93.83 and 88.44 on the index, respectively. The US scored 97. The Index assesses the use, utility and impact of the Web around the world. It looked at 61 countries With Sweden ranking number one followed by the US and the UK. respectively.

Ultimately, the web provides access to content and information that just cannot be stopped, as long as there are social sites, information will continue to permeate throughout the world. In the end we as the people control the flow of content, there has been a substantial shift in the power of information as the web has been adopted by more countries and despite certain governments best efforts, there is just no way to silence our voices.

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

Thursday, September 6, 2012

Java 7 Patch Contains Critical Vulnerability

According to security researchers from Security Explorations, the Java 7 security update released Thursday contains a vulnerability that can be exploited to escape the Java sandbox and execute arbitrary code on the underlying system.

Security Explorations sent a report about the vulnerability to Oracle on Friday together with a proof-of-concept exploit, Adam Gowdiak, the security company's founder and CEO said Friday via email. The company doesn't plan to release any technical details about the vulnerability publicly until Oracle addresses it, Gowdiak said.

According to Gowdiak, Security Explorations privately reported 29 vulnerabilities in Java 7 to Oracle back in April, including the two that are now actively exploited by attackers.  The new vulnerability discovered by Security Explorations in Java 7 Update 7 can be combined with some of the vulnerabilities left unpatched by Oracle to achieve a full JVM sandbox bypass again.

"Once we found that our complete Java sandbox bypass codes stopped working after the update was applied, we looked again at POC codes and started to think about the possible ways of how to fully break the latest Java update again," Gowdiak said. "A new idea came, it was verified and it turned out that this was it."

Based on the experience of Security Explorations researchers with hunting for Java vulnerabilities so far, Java 6 has better security than Java 7. "Java 7 was surprisingly much easier for us to break," Gowdiak said. "For Java 6, we didn't manage to achieve a full sandbox compromise, except for the issue discovered in Apple Quicktime for Java software."

The most recent security problems with Java are far from unique. Security firm Sophos, for example, blames underlying Java vulnerability for attacks by the Flashback malware last April that infected one out of five Macs.

The risks do not outweigh the rewards, security expert Dominique Karg, the founder and chief hacking officer of AlienVault, a security software company said. “I'd say 90 percent of users don't need Java anymore, I consider myself a ‘power user’ and the last and only time I realized I had Java installed on my Mac was when I had to update it.”

Most security researchers have said it before: If you don't need Java, uninstall it from your system. 

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

Wednesday, September 5, 2012

Was The FBI Hacked?


The Federal Bureau of Investigation is claiming that a statement made by members of AntiSec this weekend that they hacked the laptop of an FBI special agent and acquired a file containing 12 million Apple device IDs and associated personal information is completely false. The FBI also claims that is does not or ever did possess a file containing the data the hackers claim they stole.

In a statement released on Tuesday September 4th, the FBI said, “The FBI is aware of published reports alleging that an FBI laptop was compromised and private data regarding Apple UDIDs was exposed. At this time there is no evidence indicating that an FBI laptop was compromised or that the FBI either sought or obtained this data.”

However, this weekend, the hacker group AntiSec released an encrypted file that contained 1 million of the 12 million Apple device IDs and device names that the group said was obtained from an FBI computer they hacked. The hackers claim the original file contained 12 million IDs, including personal information, but they chose to releas only 1 million (minus the personal data) in an encrypted file and published it on torrent sites.

The hackers state in their post that they released the Apple UDIDs so that people would know that the FBI may be tracking their devices and also because, “we think it’s the right moment to release this knowing that Apple is looking for alternatives for those UDID currently … but well, in this case it’s too late for those concerned owners on the list.” Apple has been called out numerous times for hard-coding the IDs in devices, since they can be misused by application developers and others to identify a user, when combined with other personal information, and track them. Last April, Apple began rejecting applications that track their UDIDs.

In case you are concerned that your UDID has been leaked, the Next Web has developed a tool for users to check if their Apple UDID is among those that the hackers released over the weekend. For years I have had to listen to MAC users tell me how they do not get viruses and that the PC is a bad knock off of Apple's design, and I am not totally in disagreement here, but all technology has design flaws and given time and desire, someone will find a way to exploit it. This once again comes down to how the company will react and modify their behavior to protect consumes and enterprises.

While we may see this issue as being exclusively related to the consumer who buys the Apple product, more and more enterprises are permitting employees to their bring your own devices to use at the company, this equipment will find its way on to the enterprise network and can potentially compromise corporate data.

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

Tuesday, September 4, 2012

Malware Attacks Explode In 2012


According to The third edition of the FireEye Advanced Threat Report, “Compared to the second half of 2011, the number of infections per company rose by 225% in the first half of 2012. If you compare the first six months of 2011 with the first six months of 2012, the increase seen is even larger at 392%.”


The following is a summary of the key findings that the report found:

• Organizations are seeing a massive increase in advanced malware that is bypassing their traditional security defenses.

• The patterns of attack volumes vary substantially among different industries, with organizations in healthcare and energy/utilities seeing particularly high growth rates.

• The dangers posed by email-based attacks are growing ever more severe, with both link- and attachment-based malware presenting significant risks.

• In their efforts to evade traditional security defenses, cybercriminals are increasingly employing limited-use domains in their spear phishing emails.

• The variety of malicious email attachments is growing more diverse, with an increasing range of files evading traditional security defenses.

The reality is that hackers are becoming more innovative than the intrusion software consumers and enterprises run to protect themselves. To make matters worse the anti-virus software has become almost as intrusive as the viruses. I have one Laptop that is less than two years old running Windows 8 (with no issues) and Norton Anti-Virus provided by Comcast. I had to shut off the E-mail Anti-Virus module because it was literally bringing the machine to a crawl.

If the protection software becomes too over bearing, it will kill productivity, so ideally the threat protection should occur prior to the mail infrastructure, but this will mean new appliances and new methods to detect an ever changing hacking model.

The report found that hackers have increased the number of "throwaway" domains used in phishing E-mails in order to evade technologies that rely on domain reputation analysis and URL blacklists. The number of domains used fewer than ten times rose 45 percent from the second half of 2011. "The domains are so infrequently used that they fly under the radar of URL blacklists and reputation analysis and remain largely ignored and unknown," the report says. For those readers looking for more information on phishing attacks, check out PCWorld’s article 4 Security Tips Spurred by Recent Phishing Attacks on Gmail, Hotmail, and Yahoo.

The bottom line is that phishing attacks have become part of the Internet culture, playing it safe is and questioning anything that seems too good to be true or does not make sense is a great way to stay ahead of the hackers.

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

Friday, August 31, 2012

#help! Japan is Considering Using Twitter and Social Networks for Emergency Notifications

On Wednesday the Japanese government hosted a panel discussion in Tokyo to discuss placing emergency calls through social networks during natural disasters, as reported by PCWorld. This was the first event of a three part program that will run through March of next year to discuss how to use social media during large disasters. The panel included the head of Twitter Japan as well as Yahoo Japan officials.

The thought is that when traditional voice-based infrastructure is impacted the social network might be a better alternative to process emergency requests. During Japan’s Earthquake that impacted several nuclear power plants, many of the Japanese citizens were only able to get updated information via the social network. The culture is quite fanatic about using cell phones and social media, so the government see this as a natural evolution for their emergency communication strategy.

On the surface this sounds like a practical and plausible solution to a difficult situation, however having managed a notifications platform, there is a lot of concern from a product perspective. Posting content and accessing the social media is only viable if the people have access to the service, cell phone service is not designed for the level of usage that occurs during a disaster. Alert notifications are a great tool, but you must have reserved capacity and if you are only using the service on rare occasion, your cost for reserving the bandwidth could become quite expensive over time.

But let’s assume the government can solve the bandwidth issue, now the question comes around geo-presence, how do you know where the person is if they are using it to tweet in an emergency? Yes the phone probably has a GPS chip and the location can be triangulated to near proximity of the cell tower, but how do you control this, how do you use it only in an emergency? You could probably build an app for this, but that would mean that now everyone has to install the application to tweet in an emergency and how do you train the masses on how to use the social network?

Finally, and this is my biggest concern, how do you prevent hacking, both on the notification and 911 inbound tweets. None of the social media sites that I have used provide any moderator level controls, which means if the government Twitter account gets hacked and someone send out an emergency alert, there would be wide spread panic.

Don’t get me wrong, these are the right discussion to be having, we need to find new ways to communicate to large groups of people, especially in a disaster, but if we are going to enlist the use of social media then these service providers have to find a way to manage security beyond their current methods.

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

Thursday, August 30, 2012

AMD’s New Buzz Word “Surround Computing”

Mark Papermaster, the IBM executive who was named AMD’s chief technology officer last year, prompted discussion on Tuesday at the Hot Chips conference in Silicon Valley to promote “surround computing” a concept that will usher in an era where the intelligence delivered through microprocessors becomes a built-in functionality that integrates into all devices around us.

Papermaster described a world in which natural user interfaces such as gestures, fingerprints and facial recognition replace keyboards, touchscreens and mice for interactive experiences on tablets and other devices. That integration can help users connect in a more natural way with their hardware but ultimately would require more power for servers to keep up with the increased flow of information being processed.

While everyone is always intrigued with the hologram keyboard that is often used in movies or the slick hand movements that pull up video and content, like in the minority report, the reality is that we are a few years away from that and probably a decade away before it becomes something you would see in a home.

I enjoy the competition that AMD and Intel have built over the last decade, and chip performance has certainly improved over that time, but the amount of data and processing needed to deliver these types of enhancements may make the financial cost somewhat impractical, not to mention the peripheral devices needed to interact with the user and the machine. Speech recognition programs have been around for years and despite the best technical minds and improved processing speed, they still do not function at the level that we have come to accept in our movies.

Perhaps the most comical example come from Star Trek IV: The Voyage Home, when Scotty is trying to build the glass needed to contain the water to transport the whale and he starts off by saying, “computer”, and the owner looks at him and points to the mouse and he picks it up and says “computer”. The irony is that we have envisioned computer interactive designs for over 50 years, so I guess another decade is probably to be expected, at least the chip manufactures are thinking along the next generation of productivity.

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

Wednesday, August 29, 2012

VMware’s New vCloud 5.1 Makes Data Centers Virtual

According to VMware, VMware vCloud® Director™ (vCloud Director) orchestrates the provisioning of software-defined datacenter services, to deliver complete virtual datacenters for easy consumption in minutes. Software-defined datacenter services and virtual datacenters fundamentally simplify infrastructure provisioning and enable IT to move at the speed of business.

So what are you really getting? Conceptually this is a very neat package of utilizing data center services (compute, storage, networking, security and availability) into a software on-demand construct.. The vCloud Suite 5.1 is built on an updated version of VMware vSphere 5.1 and includes over 100 enhancements.

What appears promising about this design is the ability to manage flow resources across systems and workloads, along with privatizing the cloud infrastructure and securing the network. However there are skeptics. In an interview with TechNewsWorld, John Vincenzo, vice president of marketing at Embrane stated that this is "basically a small evolution of the classical virtual appliance approach, there's no scale-out architecture, with no elasticity."

The next round of designs will need to incorporate the ability to increase demand as needed (including interoperability with different hardware architecture), reduce demand as needed and park applications when necessary. The software appears to be headed in the right direction and should foster some strong innovation on the data center management front.

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

Tuesday, August 28, 2012

zEnterprise EC12 - IBM’s Mainframe Built For The Cloud


IBM announced today that they are releasing zEnterprise EC12, a Highly Secure System for Cloud Computing and Enterprise Data. According to their press release the new mainframe will provide:

· New, cutting-edge System z® capabilities for security and analytics dramatically boost cloud performance with help from IBM Research innovations.

· zEC12 offers 25% more performance per core, over 100 configurable cores and 50% more total capacity than its predecessor.

· Over $1 billion in IBM R&D investment and collaborative client input on today's enterprise system challenges

In addition, zEC12 includes a state-of-the-art, tamper-resistant cryptographic co-processor called Crypto Express4S that provides privacy for transactions and sensitive data. Crypto Express4S includes new hardware and software developed with IBM Research to help meet stringent security requirements for various industries and geographies. According to IBM, it can be configured to provide support for high quality digital signatures used with applications for Smart passports, national ID cards and online legal proceedings, replacing handwritten signatures as directed by the EU and the public sector.

Traditionally mainframes have been used in the financial sector where millions of transactions are processed and have a high need for security, but I would expect adoption in the healthcare area as well, especially since the US has mandated that patient records move to an electronic status by 2014 with penalties starting in 2015.

Due to the cost (between 1 million and 10 million dollars), I do not expe small organizations to move quickly, but I would expect the larger organizations to adopt the technology and implement IBM;s solution. Being the only commercial server to achieve Common Criteria Evaluation Assurance Level 5+ security classification I think IBM has found a way to increase Mainframe adoption.

I would not be surprised to see the reduction of paper processes in a more expedited time frame. The good news is that this could very well spark new jobs and new technologies that have been unobtainable in the past.

IBM’s Mainframe sales account for only 4% of their overall sales, but peripheral sales for the Mainframe account for 25% of their total sales and deliver substantial margin to the bottom line, estimated to be. more than 40 percent of its profits, according to A. M. Sacconaghi, an analyst at Sanford C. Bernstein.

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

Monday, August 27, 2012

The Patent Verdict Is In - $1 Billion for Apple



After just three days of deliberation, the nine jurors assigned to the Apple/Samsung Patent infringement case answered all 700 questions and returned with a verdict in favor of Apple, and awarding them more than $1 billion dollars in damages. For the most part the financial impact to Samsung, one of the world’s largest electronics manufactures is minimal, but the impact to how smartphones are built in the future could be dramatic.

In what was covered with much less detail, a similar suit was being argued in South Korea, In that case, the court ruled that Apple and Samsung both infringed on each other’s patents and awarded damages to both parties, $22,000 to Apple and $35,000 to Samsung, far less than the 1 billion awarded to Apple in the US.

There is clearly a lot to be said for home court advantage, while South Korea recognized both companies were in violation of patents, the advantage went to Samsung, in the US however, Samsung was the clear loser, not only did the jury find in favor of Apple, but the did not feel that Apple in any way violated Samsung’s patents.

It is interesting how two cases being argued with virtually the same data have two entirely different outcomes. Currently phones and tablets that are on the market have not been pulled off shelves and no injunction has been granted, although experts are predicting that Apple will ask for an injunction on all devices that currently violate the patents, this could have a major impact for Samsung and for consumers, especially since three smartphones are sold to every iPhone. Samsung is expected to ask to have the verdict overturned and if that fails appeal the verdict to a higher court.

There are a few things that will be interesting to see as this dilemma unfolds. There are those that believe that patents, like the ones Apple has, stifles innovation, meaning that the organization will rely on what it has already built and continue to offer that to the marketplace. In this way, the organization remains status quo. Others will argue that it will force Samsung and others to become more innovative and find ways around the patents which will ultimately lead to innovation. Of course, if Samsung licenses the technology from Apple, than we probably will not see that new innovation.

Even if Samsung takes the innovative path to compete with Apple, the reality is that it will take time, time to develop, review, test and ultimately distribute the product, in the meantime the consumer receives less choices, demand goes up while supply goes down, a great mix for increased prices.

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

Friday, August 24, 2012

Tim Cook Apple’s Savior or downfall?


Tim Cool assumed Apple’s top position a year ago and based on that news the stock price dropped, as of today it is not up more than 44 percent from where it was. On the surface this look great and Apple appears to be driving towards long term success. However (and there is always a however), product development takes more than a year at most companies and Apple is no exception. The products that are driving Apple are still the brain child of Steve Jobs. The real question is where will Apple be next year.

Back in April, Forrester CEO George Colony, wrote in his blog post that Apple will decline in the post Steve Jobs era. Colony also believes that Apple lost quite a bit when Steve Jobs left, “When Steve Jobs departed, he took three things with him: 1) singular charismatic leadership that bound the company together and elicited extraordinary performance from its people; 2) the ability to take big risks, and 3) an unparalleled ability to envision and design products.”

There is also heavy criticism regarding the advertising efforts that Apple is moving forward with, the addition of celebrities versus the traditional imagery that Apple products used to invoke seems to have hit a discord with potential buyers. While not scientific, the belief is that Apple is now becoming just one of the products versus a way to express your own identity and all of their advertising is beginning to lean towards that shift.
In addition, Apple and Samsung are embattled in a patent case around Samsung’s HTC smartphone. The outcome will have a substantial impact on both companies and depending on the verdict may highlight Cook’s legacy one way or the other.

Finally, Apple is also dealing with several issues around their retail stores. First reported by Gizmodo, Apple’s Dallas flagship store has been doing some pretty horrible things to customers including erasing data and breaking components that worked when they were brought in. The story was also further confirmed by 9TO5Mac.

Where will Apple be in 12 months from now? Well if I knew that I would play the stock market, but what I can say is that without continual innovation and strong leadership, Apple will not be the same company it was two years ago.

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.

Thursday, August 23, 2012

FCC Report Finds 19 Million Americans Do Not Have High-Speed Internet Access

According to the Federal Communications Commission's Eighth Broadband Progress Report  there are still 19 million Americans (6% of the US population) who lack access to high-speed Internet. Congress in Section 706 the Telecommunications Act of 1996 requires the FCC to report annually on whether broadband “is being deployed to all Americans in a reasonable and timely fashion.”

The FCC believes that we are in an era when broadband is essential to innovation, jobs, and global competitiveness, the Report concludes that the FCC – and the nation – must continue to address obstacles impeding universal broadband deployment and availability. In addition, the report states that billions have been invested by the communications industry in broadband deployment, including next-generation wired and wireless services, including:

• Expansion of networks technically capable of 100 megabit-plus speeds to over 80 percent of the population through cable’s DOCSIS 3.0 rollout

• World-leading LTE deployment by mobile operators

• Sweeping reforms by the FCC to its universal service programs, including the new Connect America Fund for broadband deployment, Mobility Fund, and the Lifeline program for low-income Americans

• Action under the FCC’s Broadband Acceleration Initiative to reduce the cost and time required for deployment

• Numerous steps to expand availability of wireless spectrum for broadband 

With this said, many rural and tribal areas still lack access to high speed service. The report also indicated that the US is behind many other industrial countries in the speed and coverage of high speed Internet service. With that said, I will admit I would never go back to dial up - I can even remember when I was overly excited to get the USR upgrade patch to bring my 28.8k modem up to 33.6k, but on the flip side the communications act has a cost.

My cable bill has steadily increased, I now pay more for cable than I ever imagined, yes I love my high speed service, but at what cost is it being delivered? In NJ we spent billions laying fiber optic cabling over a decade ago, someone had to pay for it, nothing in this world is free. So while the report provides great insight to our current state, my experience has been that the last part of a project of this magnitude is typically the most expensive and difficult.

In my days of Six Sigma, getting to 99.9% was much easier and less costly than moving to 99.99%. This is a pure statistical metric, in order to move to the next 9, you have to endure considerable effort and this effort has a substantial cost, so while we are making progress, I would expect the cost to complete the additional 6% to be a heavy burden.

Frank Toscano is a 15+ year specialist in cloud based services focusing on Product Management, Marketing and Security within the Cloud. He has worked for EasyLink Services and Premiere Global Services in a global role providing hosted services to Fortune 1000 clients. He is currently seeking employment with a cloud based provider in a senior level Product/Marketing role.