Thoughts and links from the crew of the On Computers Radio Show as we wander the Web.
Tuesday, July 26, 2005
Tips: Keeping Your Computer Healthy
IBM's Z9 Mainframe Doubles Performance
IBM is suggesting to customers that the way to harness the increased power of the Z9 is to apply it to security; specifically, by encrypting data at all stages of storage and manipulation. While encryption, even with the Z9's hardware assists, is very compute-intensive, the benefits are legion against internal prying and theft. Various financial services and health care applications under strict privacy regulation in the U.S. and Europe, leaving data sitting around memory is increasing considered a poor plan prone to disaster and internal theft.
Worth noting, IBM is not alone in a strategy that uses some of the ever-increasing computer power to protect data security. I expect Intel will get to market next year with its Lagrande Technology. LT will do for PCs what IBM's Z9 is doing for mainframe data: encrypt data from keyboards and disks, and to monitors, while creating hardware-protected regions for processing "trusted" applications. Only the application will get to see the data in its actual form. The rest of the computer will just see a bunch of random, encrypted bits.
A tip of the hat to IBM and the Z9. But see how quickly the mass-market will catch up with this important security technology.
Russia's Biggest Spammer Brutally Murdered in Apartment - NEWS - MOSNEWS.COM
Monday, July 25, 2005
Secrets of good hard-drive hygiene
Jack
Driven to distraction by technology
Thank Goodness I have friends who are not offended if I say I can't talk because of needing to work. People in businesses often can't excercise that luxury and this article notes that they lose vast amounts of time because of it.
Jack
Sunday, July 24, 2005
OnComputers Podcast 07-24-05
The Geek Gazette - Home
This is one way to set up a BACK UP for your computers.
Joe
The Browser is the Problem
Now we have the Greasemonkey add-on to Firefox, which turns out to have a really huge significant security hole in it that can allow an attacker to list the contents of directories on the target machine and view files.
With the mind set of Firefox users, feeling so safe and all, we download add-ons to our browser with very little thought, if any. I know I did and I suspect most of us do. I never gave any thought that the add-ons I've downloaded might compromise the security of my machines. We ignored the truism that even adding a small snippet of code can open security vulnerabilities undreamed of and all out of proportion to the size of the change made to the system.
The problem isn't so much with Firefox, it's add-ons, Internet Explorer or any other browser. The problem is that we're spoiled; we expect our browser to do everything. Think about that for a minute. It's true. And adding those functions with ActiveX, Flash, javascript and all sorts of other technologies over the basic rendering functions of a browser has caused all sorts of security headaches. Functional and interoperability headaches, as well, but that's almost another story. We as consumers didn't demand all these functions. They were developed and released with good, or at least commercial intentions.. And once they were loose upon the world, we took them to our hearts and raised our expectations of what our browsers should do for us.
For a couple years now, you have heard me admit occasionally during the show that I still use text-only browsers, namely Links, which either comes with or can be installed on any Linux system. I do this because these browsers render pages much faster than full-functioned browsers do on our dialup connection, which is ideal when reading large amounts of text. While the interface is plain, for a lot of my browsing, Links is all I need. It can also download files and save pages. It works for me.
Links is also much safer. Containing less technological whizzbangs makes it that way. Not that it has received the amount of attention from malicious types that IE or Firefox has, so I can't say that for sure. But it stands to reason that less features equals less vulnerabilities and I have never heard of a successful malicious attack on it.
Perhaps we should carry this farther. Perhaps we, the public, should demand minimally functional browsers designed for security and to eliminate Po pups, adware, spyware, etc. I, for one, could do well over 90% of my browsing with such an application. For the remainder, I could either use a more fully featured application or (more likely) give it up.
Come to think of it; this same argument, that limited functionality could enhance our security, can be extended to make a good case for so-called "Internet appliances". Such machines, incapable of running any software but what they were built with, could enhance our browsing experience even as they protected us. providing only that and mail capabilities. Want to download files? Okay. We'll give you disk space for just that, but you will have to hand-carry the files to another machine to view or install them. We'll provide a USB slot for that and you can plug in your memory stick, if you insist.
If it's really well done, virii, spyware, adware and all sorts of annoyances could be a thing of the past for those who own them. The same could go for cookies and tracking users across the web. Maybe I need to take another look at Microsoft TV. Then again, I'd really like something not so heavily based on proprietary technology, though there's nothing beyond their history of corporate attitude and policy stopping MS from doing that right. Still, I think it's time for such appliances to make a comeback and so allow us to disconnect our precious data from the Internet. After all; if it's not hooked up, it can't be accessed by the bad guys. And we can access what we want on the Internet with our appliances, leaving the computer safely cut off from the outside world.
I'm not at all sure I like this idea. It's almost "over the top" and involves some inconvenience for us as users. But it would save us from the armies of zombie computers which attack us or spam us because our machines would be incapable of that sort of behavior. We could have more privacy, as well. And I wouldn't have to worry about my browser.
Jack
Friday, July 22, 2005
An Identity Theft Service: For Those Who Have Everything
Intelius, a Seattle-based background-check company, believes it has come up with a solution, called IDWatch, to help ID theft victims learn they're in trouble much, much sooner. The new service launches today and can be found at www.intelius.com.
Tips: 80 Security Tips You Can Use
Whether your PC is 3 years or 3 days old, it faces the same, sometimes scary security issues. Viruses want to attack your system the moment it goes online, spyware is piggybacking with your mail and trying to slide in along with online ads, Trojans lay in wait at every turn and Phish—perhaps the sneakiest attack of all—smile at you while trying to steal your identity.
There are ways out of this mess.
These tips can show you what to do, help you better understand the threats and be ready with a plan of counter attack.
Gamers Will Lag Then Lead Multi-Core Switchover
Most PC games today are not well suited for the dual-core processors that are now on the market -- and will next year become mainstream. There's a lot of history behind this fact. For the rest of this year, both Intel (Extreme Edition) and AMD (FX 57) are saying that best gaming performance will come from the company's fastest uniprocessors. Both companies plan follow-on uniprocessors into 2006, as well.
This uniprocessor-for-gaming argument suggests that a processor split is occuring, since the mainstream is going dual core by next year. I think the future will be the opposite.
By the end of next year's holiday season, game developers will have dozens of game titles out for the next-generation, multi-core consoles from Microsoft and Sony -- or they will be left behind in a dying legacy console market. These developers are now rewriting their game engines to support multiple processors. The smart ones are already planning for more than two processors (e.g., dual core PCs) since the xBox 360 and PSP 3 will have three processors. Moreover, the 2007-2008 products from AMD and Intel are likely to have four cores.
The multi-core games will first intro on the consoles because that is where the marketing dollars will be. But the standalone and online PC gaming markets are attractive enough that I expect many titles will be ported to dual-core PCs by the second half of 2006. This new content, in turn, will fuel dual-core purchases by PC gamers. Looking forward, more processors will allow more game threads to be running at the same time, allowing for real-time physics, motion, and rendering. All we need are the games to be multi-threaded to take advantage of multiple processors cores. And when the games are multi-threaded, even a much faster uniprocessor won't be able to keep up to a multi-processor.
That's the way I see the game ending.
Apple making big inroads in business with OS X
The report found that in businesses with 250 employees or more, 17 percent of the employees were running Mac OS X on their desktop computer at work. In Businesses that had 10,000 or more employees, 21 percent of employees used Mac OS X on their desktop work computer.
Mac OS X Server is also doing well with businesses. Nine percent of companies with 250 employees or more used Mac OS X Server, while 14 percent of companies with 10,000 employees or more used Apple’s Server software."
Please be advised that this is the dumbest, least believable piece of market research that I have seen in years, and I know market research. It should not have been published, and leads me to seriously question the lack of quality control at Jupiter Research.
My logic in debunking this garbage research is simple:
1. There are more business machines sold than consumer machines.
2. The industry counters say about 49 million machines shipped last quarter worldwide.
3. Apple shipped north of 1 million Macs last quarter, and OS X only runs on Macs (and a few Intel machines in the Apple R&D labs).
4. Apple's PC market share over the past year has grown from roughly 2.5% to 3.5%. Dell's market share is estimated at under 19%.
5. So how is it that 17-21% of medium and large business users are using Macs as Jupiter reports? There is not a single CIO in an F1000 company that will verify these munbers.
Now that my rant is over, I can agree that Apple is indeed modestly picking up market share in businesses, and the company's strong performance of late is likely to drive more demand over time. OS X is a viable competitor to Microsoft's Windows and Linux desktops. However, the Mac installed base is more like an order of magnitude smaller than Jupiter reports.
An audio file of the earthquake that caused the tsunami
"The T waves for the Sumatra earthquake were captured by underwater microphones located at Diego Garcia, more than 1,700 miles from the epicenter. These microphones are part of arrays known as hydroacoustic stations that are scattered throughout the world's oceans to listen for the telltale sound of an atomic blast."
I heard a brief clip and it really made my subwoofer work.
Amazing power!
--MissM
Medicare to "give" Doctors software
This could be great. This could be a nightmare. Medicare plans to give doctors free software for record keeping.
I do feel it's a step in the right direction. Long article. Check it out.
Microsoft secures FrontBridge acquisition
Jack
IBM Joins Project Harmony
IBM is almost certainly has as much Java knowledge and expertise as anyone, including Sun Microsystems, themselves. IBM has their own Java Virtual Machine, the development of which should convince any skeptics of IBM's prowess. It's possible IBM could donate their JVM to the Harmony Project, though there has been absolutely no word on this from IBM.
Surrounding all this is a tense atmosphere which has IBM and many others calling upon Sun Microsystems to fully open the Java source code. Sun resists, tenaciously. They maintain Java needs a corporate steward (themselves) to keep it pure and prevent unauthorized branching. I, personally, appreciate their point. Look at what happened with Microsoft, who developed an unauthorized and partially incompatible JVM, yet called it "Java". It took Sun years and millions of dollars in legal expenses to shut that down with legal actions.
I think Sun's action proves they are a willing and worthy steward for Java. I cannot embrace the notion that everything MUST be open-source. That level of philosophic extremity is beyond me. The defining factor in this case is how open Java actually is. Sun has responded to criticisms of the "Java Community Development Process" by making it easier to contribute code to and the decision making process about which code to include more open to outside input. The Java community is not closed, by any means. It is also not a common open development project and all I can say about this is "so what"?
It is not as if an open source community cannot protect their product. That is not my point nor Sun's. My point is that Sun has already proven themselves as a worthy steward and has all the necessary resources to continue as such. They are obviously willing to change to accomodate the needs of the Java user's community. It is possible branding pressures could keep Java pure, as the advocates of opening up the source code assert. But Sun already has the mechanisms in place to do this (along with enforcing developed and developing standards) and I see no compelling reason to change this. To me it is a case of leaving well enough alone and allowing Sun to modify the development process as they see fit in response to the developers who actually do the work.
Java has some problems. That is not surprising considering the size of the systems that comprise it. Succeeding versions do not have adequate compatibility with previous implementations. Efficiency of code execution needs improvement. Sun is attacking all the problems aggressively, in concert with the development community, though progress has not been as rapid as some would hope. I trust Sun in this, as do many of the Java developers I know.
The kids are all right. Leave them alone.
Jack
Thursday, July 21, 2005
Microsoft Revenue Up 9%, Operating Income Hurt by Legal Costs
Microsoft Corp. today announced revenue of $10.16 billion for the quarter ended June 30, 2005, a 9% increase over the results in the same period of the prior year. Operating income for the fourth quarter was $2.99 billion, compared to $3.13 billion in the prior year. Operating income for the fourth quarter includes $756 million related to legal charges for antitrust-related claims.
Net income and diluted earnings per share for the fourth quarter were $3.70 billion and $0.34 per share, which included $0.05 of legal charges and $0.09 of tax benefits. For the previous year, net income and diluted earnings per share for the fourth quarter were $2.69 billion and $0.25 per share, which included a $0.02 tax benefit.
The company also announced record revenue of $39.79 billion for the fiscal year ended June 30, 2005, an 8% increase over the $36.84 billion reported last year. Net income for fiscal year 2005 was $12.25 billion and diluted earnings per share were $1.12, which included legal charges of $0.13 and tax benefits of $0.09. For the previous fiscal year, net income and diluted earnings per share were $8.17 billion and $0.75, which included legal charges of $0.17 and a tax benefit of $0.02.
The earnings call slide show is here.
While client revenues were up 10%, OEM revenues were up 14% and units were up 18%. This suggests the PC industry grew at the high end of Gartner and IDC estimates. Like Intel, Microsoft did not anticipate the robust growth in PC units.
Tools and Servers were up 16%, helped by 20% growth in SQL Server -- an industry standard RDBMS at this point by anyone's view.
Apps were up 11% and information worker (Office) up 3%. MSN was up 1% but home & entertainment was up 22% to $610 million based on robust xBox ecosystem (up 46%). Mobile revenues were up 39% to $97M as smart phones (finally) begin to kick in nicely.
For fiscal 2006 ending June 30, Microsoft projects the following revenue growth by segment:
- Client up 5-6% in a 7-9% global PC growth environment. No Longhorn revenues anticipated until FY 07 -- the 1st beta this summer and GA in second half calendar 2006. The declining revenue per PC reflects, I think, the growth of low-cost versions in developing countries. I believe the decline will be multi-year into the Longhorn product cycle.
- Server & Tools up 11-13% with new Visual Studio, SQL Server, and Exchange versions
- Information Worker up 5-6% but no new Office until FY07
- Applications up 10-11% in a 6-7% overall market growth in apps
- MSN up 2-4% with ads up 20% offset by declining access revenues
- Mobile (garbled and I missed it)
- Home & Entertainment up >50% with the holiday launch of xBox 360 console, games and services -- first in US, Japan and Europe. Note the original xBox will still be sold once xBox 360 is released.
Tips: Hacking Windows XP
Good tips are in these articles.
EMC Continues High Growth
Systems revenue grew 15% in the second quarter, compared with the year-ago quarter, to $1.1 billion. EMC's software businesses grew software license and maintenance revenues 23% year on year to $878 million in the second quarter, representing 37% of total EMC revenues. Professional services, systems maintenance, and other services revenue grew 26% year on year to $389 million during the quarter.
High-end Symmetrix revenue only grew 4%. However, a much-anticipated new line of Symmetrix products is expected next Monday, which should spike demand in the second half. Mid-range Clariion storage grew and impressive 32%. EMC and partner Dell are clearly picking up market share. Note that software and services are growing much faster than hardware.
Amex and Visa Punt Online Processor Responsible for Data Leak
The penalty is death -- of the company responsible. Details of up to 40 million payments cards, including names, account numbers and expiration dates, are believed to have been taken out of a database system run by CardSystems—the biggest such privacy violation ever reported. In June, CardSystems Solutions, which processes credit cards for 115,000 U.S. merchants, revealed it had mishandled customer data by storing data on customers—in violation of Visa and MasterCard's security standards.
Both American Express and Visa are ceasing doing business with CardSystems by October. I suspect MasterCard will follow suit based on what their competitors are doing -- and MasterCard's suddenly increased liability. With nothing to interchange, I cannot see a way for CardSystems to stay in business.
Let that be an object lesson to the CEO's of companies with less than effective internal and external controls. These data privacy violations have got to be taken seriously.
Update: During congressional testimony Thursday, executives from bank and credit card companies involved in the largest credit card data loss ever pointed fingers at a new culprit for gaps in security: the auditors who had certified the credit card processing systems as being up to snuff. Now I've heard everything. Let's blame the auditors for our security problems...and the dog ate my homework.
Wednesday, July 20, 2005
Firefox - Rediscover the web
Jiminy, I just installed 1.05...
There are more browser updates, than antivirus ones anymore
"And my source for this up to date info?" you ask
Courtesy of Bill42 in the chat, filehippo,which has updates for more programs than I use, and just about all the other ones, too. Since I'm an RSS addict (loud and proud about it too lol) filehippo has an rss feed too
--MissM
Tuesday, July 19, 2005
HP takes hard line with partners
Consider this quote from HP Chief Executive Mark Hurd:
" 'We really like partners that are very focused on HP,' Hurd said during a conference call Tuesday. 'It doesn't mean that they are exclusively focused on HP, but when we go to market together, they are focused on what we call the attach rate and that we enlarge our content of product.' "
So if you go to buy HP products in the future expect to have other, perhaps unwanted, items pushed at you. I don't hear "great package deals" as part of this focus, but maybe they will be. I don't know at this point.
What I do know is that I'm personally turned off by such tactics. However, unless the implementation is so agressive as to be egregious, it can work. For various reasons, mostly having to do with software support for HP hardware, I'm not a big HP fan. So as I gently poo-poo Hurd's strategy, consider the source.
Microsoft to expand anti-spyware offering
Now that Microsoft's reliability and trustworthiness is in question because of their preferential treatment of Claria/Gator, it is ironic that they may soon be putting out the most capable application in the field, but hindering it's function to suit Microsoft's commercail interests.
Jack
PC Industry Up 15%, Intel Up 15%
Highlights:
- Intel had to cannibalize its motherboard sales to have chipsets to ship to OEM manufacturers. A chipset shortage may continue. Overall, inventories are lower than desirable. It looks like even Intel underestimated the strength of the global computer market.
- Microprocessor units were at a record, but xBox sales pulled average unit price down somewhat.
- Chipset units were higher.
- Motherboard units were lower.
- Flash memory units were higher and at record levels, with lower average selling prices.
- Wireless connectivity units set a record.
- Wired connectivity units were lower.
- The 65 nm process is proceeding better than expected. Samples of microprocessors code-named Yonah, Presler and Dempsey, the company's first 65nm dual-core microprocessors for notebook, desktop and server platforms, respectively, have shipped to OEMs.
- With five new Celeron D processors with 64-bit computing capability for the value PC segment, Intel now has 64-bit capability available throughout its desktop and server microprocessor product lines.
A "Priceless" Server Room - The Daily WTF
Enjoy!
OffTopic: I had to load this in IE to see the text correctly, there seems to be some issue with firefox and text wrapping.
--MissM
Thousands back petition to open source OS/2
IBM, for their part, would rather you migrate to Linux, and with good reason. As a matter of fact, it's the same reason they won't open the code. Linux is complete. OS/2 open-sourced would not be. Why? Remember who IBM partnered with to produce OS/2? Microsoft, that's who. And somehow I can't see MS going along with this one because some fundamental Windows stuff would be let into the wild.
I guess we'll have to go back to our Angelina Jolie daydreams. This one is full of holes.
Jack
Mozilla: IE 7 to boost Firefox growth
We alluded to this on last Sunday's show. Is Microsoft moving individuals and corporations towards upgrading to Windows XP, or will individuals and corporations move to Firefox and stick with Windows 2000?
I have no crystal ball, but considering that the conventional wisdom is that some who are sticking with Win2k already have licenses for WinXP, it could mean that short of equipment upgrades, Microsoft's decision not to support IE7 on Win2k will boost Firefox useage. If that becomes a reality, look for a version of IE7 that runs on Win2k to magically appear.
IBM Q2 Bounces Back
REVENUE - BRAND
Total Revenue in the second quarter was down 4 percent year-to-year as reported, but up 6 percent without PC’s. Without PC’s, revenue was up 4 percent at constant currency.
Global Services, which this quarter represented over 50 percent of IBM’s revenue, was up 6 percent year-to-year as reported, and up 4 percent at constant currency. An improvement in short term signings accelerated the growth rate of BCS. Our strategic outsourcing signings were up significantly year-to-year, which will provide a benefit over the longer term.
Hardware revenue was down 25 percent as reported. But, as we just discussed, this included one month of PC’s as compared to three months in second quarter of 2004. Without the PC business, hardware was up 5 percent, and up 4 percent at constant currency.
We had double-digit growth in pSeries, iSeries, xSeries, and storage.
This strong performance was offset by an expected decline in zSeries, as customers anticipated a new product announcement.
Software revenue grew 10 percent as reported, and 7 percent at constant currency.
You’ll recall that the second quarter of 2004 was a challenging environment for the software industry.
This year, we had especially strong performance in the Americas.
Global Financing revenue was down 4 percent as reported, or 7 percent at constant currency, driven by a continued decline in the asset base and yields.
From the press release
Hardware revenues decreased 25 percent (27 percent, adjusting for currency) to $5.6 billion in the second-quarter 2005 versus the year-ago period. Hardware revenues excluding the divested PC business were $5.0 billion, an increase of 5 percent (4 percent, adjusting for currency).
Hardware revenues for the Systems and Technology Group, which was newly realigned to include Retail Stores Solutions and Printing Systems, totaled $4.9 billion for the quarter, up 5 percent. Revenue growth from S&TG eServer products was driven by pSeries UNIX servers, which increased 36 percent, and xSeries servers and iSeries midrange servers, which increased 11 percent and 10 percent, respectively. Revenues from the zSeries mainframe product decreased 24 percent compared with the year-ago period. Total delivery of zSeries computing power, which is measured in MIPS (millions of instructions per second), decreased 19 percent. In addition to eServers, revenues from Storage Systems increased 19 percent and Microelectronics decreased 5 percent.
Revenues from Software were $3.8 billion, an increase of 10 percent (7 percent, adjusting for currency) compared with the second quarter of 2004. Revenues from IBM's middleware brands, which include WebSphere, DB2, Tivoli, Lotus and Rational products, were $3.0 billion, up 11 percent versus the second quarter of 2004. Operating systems revenues increased 3 percent to $592 million compared with the prior-year quarter.
Microsoft Begins Quantifying Longhorn Value
Longhorn will:
- launch applications 15 percent faster than Windows does
- boot PCs 50 percent faster than they boot currently and will allow PCs to resume from standby in two seconds
- allow users to patch systems with 50 percent fewer reboots required
reduce the number of system images required by 50 percent - enable companies to migrate users 75 percent faster than they can with existing versions of Windows.
Beta 1 is expected in three weeks. Beta 2 will stretch until mid-year 2006. We should have a lottery as to when the actual ship date will occur.
No One Expected PC Sales Up 15%
It was only three years ago that the industry hit 100 million units. It is the stealth, double-digit growth rate that should attract the reader's attention. The whole story is complex, but it is hard to see what going on from a U.S. vantage point. Much of the global growth is coming in developing countries. In mature markets, laptops have overtaken desktops for both consumer and business computing.
Again, I am flabbergasted at the size of the market growth. A 200 million PC market is a big, silent elephant in the corner of the global tech economy. That elephant carries bilions in software, peripheral, semiconductor, transportation and service revenues.
In the U.S., the top five manufacturers in order by market share are Dell, HP, Gateway, Apple (yes, Apple), and IBM/Lenovo.
HP Cuts Headcount 10%
The $1.9 billion in compensation and benefits savings will be plowed back into the business. My assumption is that future cuts and reorganizations will whack at least another $1.1 billion out of the cost structure.
Microsoft: DoS Bug Not Limited To Windows XP
Intel's Latest and Last Itanium Uniprocessor
Both of new Itanium 2 devices run at clock speeds of 1.66 GHz; one model comes with 6 MB of cache, the other with 9 MB. The former will sell for $2,194 in quantities of 1,000 or more, the latter for $4,655.
The next generation of Itaniums will feature dual processors early next year. HP is the largest OEM customer for Itaniums, basing its Integrity line on the chips. Hitachi plans to use the processors in its upcoming BladeSymphony servers, according to an Intel statement.
IBM's Power and Intel's Itanium are getting most of the R&D dollars for high-end microprocessors these days.
Anti-Spam!
I guess there are issues, to consider, because there is server bandwidth, so feel free to delete this.
--MissM
Workarounds Released for XP SP2 Flaw
Just in case this isn't in today's updates, or is that in August.. ?
Monday, July 18, 2005
Anti-Spyware Coalition
Public comments on the draft definitions document are welcome here:
Anti-Spyware Coalition - Comments
The deadline for submitting comments is August 12, 2005.
Why Microsoft AntiSpyware Is Untrustworthy
The good news is that Microsoft AntiSpyware is in beta. By that very designation, that means that no one should be relying on it. It is also free. Since that is the case, I can still say, no foul on Microsoft's part. If anyone is relying on this beta to keep their computer clean, it's their bad, not Microsoft's. Yet.
The bigger question will come when people actually start paying for it. Will Microsoft still give a "pass" to Claria and others?
Until these problems are cleared up, Microsoft AntiSpyware is on my not-recommended list.
Coding misstep forces new Firefox release
The Mozilla Foundation is taking a lot of heat over this from non-English speaking Firefox users.
Corrupted PCs find new home in the Dumpster
Well, ahem, not really that rational. It is however an understandable response.
A rational response is wiping the hard drive and starting over. I contend that it will take longer to purchase a new machine than the 40 or so minutes it takes to do a clean install of Windows XP. That doesn't even account for the wasted resources.
If it must be disposed of, take that infested machine to someone who restores them and donates them to those in need. Now that's a rational response.
Dell Laser Jet Limbos Too
HP and Dell Do the Desktop Limbo
Holes in Kerberos Authentication Threaten Mission-Critical Unix Enterprise Systems
Kerberos, the popular authentication protocol developed by the Massachusetts Institute of Technology, is vulnerable to three serious flaws that could allow an attacker to gain access to protected corporate networks, MIT researchers disclosed late on Tuesday. Unix variants such as Solaris and Apple Computer Inc.'s Mac OS X, and Linux distributions such as Red Hat and Gentoo all contain the affected code. Windows also uses a version of Kerberos, but it doesn't contain the flaw.
The big-iron Unix boxes from HP, IBM, and Sun -- plus everybody's X86 servers running Red Hat Linux AS -- are particularly vulnerable to the Kerberos security flaws because Kerberos is often at the heart of authenticating user log-ins. Thus, enterprise IT professionals would be well advised to install the Kerberos patches to Unix when they become available. The reason for alacrity is that the bad-guy hackers, now alerted to the vulnerabilities, will concentrate on this new avenue into the computer systems of global enterprises, governments, and educational institutions.
The workload for the fixes includes patching hundreds of thousands of Unix servers, which will undoubtedly have to be taken out of 24 x 7 service to reboot the changes.
Tip: Keeping Your Computer Cool
Patch Tuesday Goes Industry-Wide
This is good news for the industry because it creates a cadence for the compauter industry, including; it is bad news because IT professionals can plan on being inundated every patch Tuesday with the patches, which they then have to test and integrate with other (patched) software and the enterprise's applications.
Oracle Compromises on Multi-Core Processor License Fees
Licensing terms for the Oracle Store Web site now state that, for the purposes of counting how many processors need to be licensed, a multicore chip with "n" cores will be multiplied by 0.75. Oracle will then round up fractions to the next whole number.
For example, if you have a multicore chip with 11 cores, multiply 11 by 0.75, which equals 8.25. Round that up to nine processors, and that's what you'll be paying for.
Notwithstanding the three-quarters rule, Oracle will count only one processor when licensing Oracle Standard Edition One or Standard Edition programs on servers with a maximum of one processor with one or two cores.
For more background and a chart of Oracle's pricing moves, see this IT Jungle article.
Domain Hijacking Hits Big Companies
The report, announced Wednesday during an international meeting of the ICANN (Internet Corporation for Assigned Names and Numbers) in Luxembourg, followed at least two high-profile incidents this year of what is known as domain-name hijacking—one hitting New York-based ISP Panix and another affecting e-mail provider Hushmail Communications Corp.
Light up your boring life with LED screws
Jack
Google Maps Transparencies
Sunday, July 17, 2005
OnComputers Podcast 07-17-05
Joe
IBM's OS/2 Sees End of Life
OS/2 was a very strong 16-bit graphical operating system back when Microsoft was clueless. But the vaunted Redmond marketing engine pushed Windows past IBM and Apple in short order. The rest is history -- except for the OS/2 installed base.
OS/2 was a good product which I will remember fondly.
AMD Cracks Corporate Laptop Market
Note the increasing revenue per processor that AMD reported in the latest quarter. Laptop Turion chips will help keep the gross margins up.
E-Mail Crime Pays
In this case, a Nigerian woman was sentenced to 2-1/2 years in prison for e-mail fraud. You probably got the letter, and I certainly hope you did not respond. She has to return $85 million, but the take from the scam was -- please sit down now -- $242,000,000.
Makes you stop and consider going over to the dark side...
Saturday, July 16, 2005
Podcast Now Supports iTunes
PCWorld Firefox Continues to Spread
As Firefox approaches the 10 percent market share milestone, it is expected to gain "significant traction" once its acceptance grows among corporations, according to NetApplications.com.
I'm a diehard Internet Explorer person and I have to admit, at least half the time now I use Firefox instead of IE.
Friday, July 15, 2005
Worm spells double trouble for PCs
United Nations calls for US net pull out
IBM officially kills OS/2, suggests switch to Linux
The Clicker: Microsoft’s OPM for the masses
Am I the only one who sees a problem with this business model? Just as Podcasts fill the free and legal audio void, free and legal video will also fill that void, thereby enabling those who don't want to be bound by DRM and such to stay entertained.
Except for the PATRIOT Act, the public library is looking more and more entertaining. In other words, there is one way not to be held captive by the content providers with their onorous DRM -- don't buy their content. Just like digital TV, they may be selling but the masses may not be buying.
SCO e-mail: No 'smoking gun' in Linux code
Thursday, July 14, 2005
Speed of Apple Intel dev systems impress developers
They further report that "Rosetta", the virtual machine that allows native PPC Mac OS X applications to run on the Intel hardware is "seamless" and fast.
Those of you who worried about the new Mac's performance might rest a little easier after reading this.
Jack
Microsoft's antitrust concessions are 'pointless'
Read it and judge for yourselves.
Jack
Optimus keyboard
O'Reilly: Seven Steps to Noise-Free Digital Audio
For your continued enlightenment...
MissM at home, finally.
Cybercrooks lure citizens into international crime
Wednesday, July 13, 2005
AMD Turns a Profit
- Microprocessor sales were up 38% year-over-year.
- Opteron server microprocessor sales were up 89% as enterprises feel more comfortable with AMD at the heart of corporate systems.
- Mobile microprocessor sales were at record levels. There are 60 design wins for the Turion mobile chip.
- Microprocessor selling prices were up 6% in the quarter, which certainly helped gross margins.
- Memory sales were down 31%, a sign of the brutal competitive market for semi-conductor memory.
AMD was forecast by analysts to show a loss for the quarter, so being profitable is a positive sign.
Apple's Success is No One Hit Wonder
Apple shipped 1,182,000 Macintosh® units and 6,155,000 iPods during the quarter (up over a million units sequentially from the previous quarter), representing 35 percent growth in Macs and 616 percent growth in iPods over the year-ago quarter.
- iTunes Store now represents about 5% of the U.S. music market. Almost 500 million songs sold.
- Over a million podcast subscriptions in first two days
- Apple store retail sales are up 56% with 12.2 million visitors last quarter
- Education market is up 16% to the highest level in 9 years
- Gross profit and net profit are at the highest levels in years.
First, we can discount the rumors of a couple of weeks ago that iPod sales are off. Au contraire. Inventories are within the planned 4-6 weeks of stock. The "better value" iPods launched two weeks ago -- lower price with color LCD and photo capability -- should continue to drive consumers to Apple.
The overall iPod ecosystem has no close competitors, period, as there are over 1,000 iPod-related products available. Apple in just a couple of years has become a force to be reckoned with in the entire music industry, as any artist with a chance at an iTunes Store song pane will tell you. This opens up opportunities for further differentiation.
The significant uptick in Mac sales is also fortuitous. But its not just the iPod halo effect: iPod has no impact on the K-12 education market, for instance.
With an entrenched position in music that is still expanding, a strong professional graphics and video market position, and renewed respect for the value and quality of the Mac line -- and that certainly includes OS X 10.4, Apple is on a roll.
The current quarter should be the strongest of the fiscal year, as Apple and the rest of the industry are in high gear chasing back-to-school sales.
All in all, an excellent quarter that shows Apple is back.
Patch Tuesday: Microsoft and Firefox Fixes Posted
McAfee Virtual Cybercrime Report Paints Grim Picture
Some of the report's most compelling highlights include:
- The FBI estimates that cybercrime cost about $400 billion in 2004.
- In an investigation, codenamed "Operation Firewall," U.S. and Canadian authorities announced the arrest of 28 people from six countries involved in a global organized cybercrime ring. They operated Websites to buy and sell credit card information and false identities. They bought and sold almost 1.7 million stolen credit card numbers. Of these stolen credit cards, financial institutions have estimated their losses to be $4.3 million.
- The use of pseudonyms or online identities provides an anonymity that is attractive to criminals. Sources estimate that perhaps only 5% of cybercriminals are ever caught or convicted.
EC Jumps in on AMD Suit
Spyware, Adware and Security, Among Other Things
The general population of Internet users may not know exactly what it is, but they know they don't like it. Their machines slow to a crawl, they are forced to click through ads to do their work or pursue their pleasures, sometimes seemingly endlessly. They worry about trojan horse programs stealing their personal data and making theft of their identity possible.
Businesses of every size now see spyware and adware, no matter the definitions, as a major problem. And trojan horses have been discovered in Isreal custom designed to facilitate industrial espionage. It must be pointed out that this incident did not involve files obtained from the Internet. Instead, they were spread on physical media using some fairly simple social engineering. But the lesson is clear: The machines we use in so much of our life threaten to do us harm at the hands of others.
Recently, I read where an officer of a company which distributes adware said consumers have to be educated on the difference between adware and spyware and other malicious programs. What I took from that told me he thought that if consumers were so educated, they would tolerate adware much more readily.
I have news for him; Computer use is often an intensely personal experience and the majority of people resent ANY intrusion into it. Don't believe me? Look at the proliferation of ad and popup blockers. Only the most technically inept are not aware of their availability and, in my personal experience (which may or may not be typical) adding them to the machine is THE most often requested software upgrade.
We don't just dislike popup ads. We resent them deeply. Hate is probably not too strong a term for the way we feel. The same goes for those animated Flash presentations you insist on putting in the middle of texts we want to read. I will read and occasionally react to a tastefully placed advertisement. It's not as if I think advertising is bad. I do not. I just don't wish to be forced to deal with it, have it detract from my surfing experience or leave anything on my machine, no matter what it is. I have yet to find anyone who disagrees with me on this, though I admit I haven't asked anyone I know in the online advertising trade.
There are issues of who gets to control whose computer, as well. But the vast majority of users aren't really aware of these. They just want to be able to view the content they choose without wading through layers of ads.
CNet's News.com is reporting adware companies are trying to clean up their act and image. The driving force in this is the specter of federal legislation and nothing I've found signals anything like a moral re-awakening on the part of the adware folks. They're just afraid of possible legal consequences. In cases where companies have actually posted accurate details in licenses and made uninstallation of the adware easy, their penetration (in number of installations) has gone 'way down. There is a lesson in this, but no one I know expects these companies to hear it.
Jack
Questions About Intel's Fortran Compiler
It seems Intel's compiler for Fortran 77 and Fortran 90 produces code that looks for the Intel trademark and if it doesn't find it, refuses to enable several optimizations, regardless of whether or not the chip it does find is capable of using them or not. Note that this is NOT the usual cpuid routine, but something hidden. The code so produced runs much more slowly or segfaults on AMD processors.
The "bug" has been fixed, but the compiler still does not use cpuid for identifying the processor. Intel claims it was a mistake. Various observers label it a dirty trick. Read it and make up your own mind.
Jack
Tuesday, July 12, 2005
A quickie RE: Spyware
InternetWeek | Firefox Users Sound Off: Fix Those Bugs!
Not to mention I think its useful for all firefox users...
MissM in Louisiana
Monday, July 11, 2005
Good News for NCR: Dell Loses CIO to HP
So expect that HP will (quietly) become a major Teradata customer. In my opinion, there is no better technology for creating the complex, near real-time transaction systems that drive supplier-facing and customer-facing operational excellence. Part of that opinion rests on the deep and strategic use of Teradata by industry-leading companies who are betting their business on NCR Teradata. (For the record, I have no financial relationship with NCR).
-- Peter S. Kastner
Cybercrooks lure citizens into international crime
One of the big tricks is to go online with stolen ID and change the notification address, then ask for a higher credit limit. You can imagine what happens next. How large banks miss an obvious check is beyond me. Bank stockholders, who are paying billions in fraudulent charge reimbursements, ought to be asking why banks do not send an address change notification to the old address. That way the people whose ID is stolen have a clue when their bank statement is changed to Pocohontas, Iowa. The banks are acting like fools or knaves.
Lenovo links with blade desktop maker
Companies are hot on the idea because the rack concept saves precious office and/or cubicle space. OEMs are in favor of it because, just like in servers, they tend to lock-in customers to a brand because the blades are not interchangeable between various makers. You need a rack from the company who makes your blades and this makes switching brands much more expensive. Given a well thought-out setup, blades are also easier to service because you just jerk out the offending unit, plug in the replacement and restore from the storage appliances. There's no need to disrupt someone's office.
Since they took over IBM's PC division, Lenovo seems intent on offering a truly complete line of computers and this is proof. It's entirely possible the broad spectrum of their offerings will quickly overcome any hesitancy about the brand being under new ownership. In short; it looks as if they have all the smart moves on tap.
Jack
A MOST Alarming Privacy Threat
The Electronic Privacy Information Center (EPIC) has filed a complaint with the Federal Trade Commission (FTC) in which they point out that many web sites are selling information protected by law, such as drivers license information, postal box information, cell and long-distance phone records.
This kind of information has been used in the past by stalkers to find victims they subsequently murdered, which is why it is protected by law.
The link above is to a short article in The Inquirer and there is a link to the actual complaint on EPIC's web site. I urge you to read both. This one is not rampant paranoia. This is a real threat, by any standard.
Jack
Zlib Security Bug is Being Addressed
Most Linux and BSD distributions, some Microsoft products and many applications from all over use this set of functions. Gentoo, Debian, Mandriva and others have already issued patches. I urge anyone using Linux, BSD or any application which uses PNG (Portable Network Graphics) format images to check for updates pretty much continuously until they get one for this problem.
It is a hard vulnerability to exploit, but with the increasing sophistication of attackers, it WILL be exploited. Get your patches as fast as you possibly can.
Also, some older Microsoft products use this library of functions and are vulnerable. Watch for updates to them, as well.
Jack
OnComputers Podcast 07-10-05
Sunday, July 10, 2005
Your Firewall Won't Get You Into Heaven Anymore!
There are other things that are equally important and perhaps chief among them is user education and enforcement of policies, both security and otherwise, that foster a safe environment. Smaller businesses are particularly prone to this problem; once they've invested in an expensive firewall, they assume their security quotient has risen significantly, when in fact it may not have advanced the cause at all.
This is worth a read. It applies to the home network and small business as well as larger entities. Security is a state of mind as well as a state of being.
Jack
Saturday, July 09, 2005
Trojan horses gallop into networks | Tech News on ZDNet
Make sure your Anti-Virus is up to date and if you're running NAV you might want to think about replacing it with one that works!
Joe@GeekMeet 2005
Friday, July 08, 2005
Patch Tuesday: 3 Critical Bugs to Fix
What time is it anyway?
Are We Headed for an Internet Winter?
Here is some ammunition for our live discussion on the OnComputers radio show, July 10th, 2005. The question before the house is: will the growing threats on the Internet dramatically change corporate and consumer behavior, leading to a major decrease in Internet activity -- an Internet winter.
- 59 million Americans have dealt with spyware. They are changing how they approach the Internet based on bad experiences with viruses, spyware, and identity theft.
- IBM says the number of phishing attacks is at an all-time high, up 225% in May.
- INternet hacking is no longer the province of teenagers; professional criminals are behind much of today's Internet crime. These criminals are acting in concert.
- With 246,000 complaints to the Federal Trade Commission on identity theft, independent estimates put the number of victims of identity theft in the past five years at a staggering 1 in 5 Americans. NBC News reports that the identities of 50 million Amercians have been stolen or compromised in the past six months. The Internet is one of the key vehicles for identity theft.
- On the technology front, viruses and trojans are merging and becoming polymorphic. This smart malware is flying under the radar of anti-virus products, the first line of defense for many consumers and enterprises.
- There is a 50 percent chance your unprotected Windows PC will be compromised within 12 minutes of going online, says security vendor Sophos. That means your machine may be hijacked before you can install anti-virus, firewall, and adware software on a clean install of any version of Windows prior to SP2. Do not plug in your network cable until all of your safety/security software is installed. Unfortunately, older versions of Windows do not install network drivers and protocols unless a network connection is available. Catch 22.
- Life is not much safer inside the business world's firewall, as evidence of the recent Veritas Backup flaw reveals. Aberdeen Group reported this week that only a small fraction of enterprises have best-in-class policies and practices in place to deal with security on networks and infrastructure, information access, and governance.
- Businesses face a number of threats to hard-one consumer business on the Internet, as the pharmacist CVS found recently in a compromised consumer-facing application.
- The biggest threat to enterprises comes from the inside, security experts tell me. It can be a trivial exercise to get the keys to corporate jewels.
- It's getting hard to know what and who to trust on the Internet. The latest attack used a Microsoft security bulletin lookalike to spoof users. If users stop paying attention to Microsoft security bulletins, their machines will become a lot more vulnerable over time.
- The complexity of the multiple technologies (e.g., TCP/IP, routing, switching, Microsoft Windows internals, HTTP(S), Javascript, and all of the options these have) is absolutely beyond the capacity or ken of all but a handful of geek consumers. It requires multiple specialists in the enterprise world too. In short, computer users are unfit (but not necessarily incapable) of protecting themeselves.
- User education alone is not the answer, says Jakob Neilsen.
- Strike-back systems are not the answer, says Larry Seltzer.
Predictions of the demise of the Internet go back a decade -- before the general public really knew about the Internet! Are we headed for Internet winter, or will Darwinian selection win out with (massive) adaptations to thwart the black hats? We'll discuss this on Sunday.
-- Peter S. Kastner
Internet Users Adjust to Unfriendly Internet
Spyware and the threat of unwanted programs being secretly loaded onto computers are becoming serious threats online. Nine out of ten internet users say they have adjusted their online behavior out of fear of falling victim to software intrusions. Unfortunately, many internet users’ fears are grounded in experience - 43% of internet users, or about 59 million American adults, say they have had spyware or adware on their home computer. Although most do not know the source of their woes, 68% of home internet users, or about 93 million American adults, have experienced at least one computer problem in the past year that are consistent with problems caused by spyware or viruses.
FAQ: Wi-Fi mooching and the law
Geek Meet 05! What we're talking about....
MissM/Jane
Surfers get smart on spyware - vnunet.com
Rumored Microsoft Adware Deal Raises Red Flags
Google to release Firefox toolbar | CNET News.com
and as I was scanning tech news, looking for links, I ran across this too Techworld.com - Three critical Microsoft patches this month
Microsoft Downgrades Claria Adware Detections
courtesy of locolobo
Wednesday, July 06, 2005
Blake Ross on Firefox and Beyond � The new Firefox tag line
MissM
Microsoft Employee Volunteers For Computer Hardwiring
"One of the guys that works at Microsoft ... always says to me 'I'm ready, plug me in,"' Gates said at a Microsoft seminar in Singapore. "I don't feel quite the same way. I'm happy to have the computer over there and I'm over here."
He must be worried that the computer is running Windows...
Tuesday, July 05, 2005
Pigs Will Fly When Sun Offers Windows OS
Don't we watch a wonderful industry? That Sun, once Microsoft's most vocal critic, no enemy, would sell Micsorodt Windows Server should customers want it is a true sign of how hard it is to make a buck in the high tech industry. Combined with Michael Dell's throwaway comment a couple of weeks ago that Dell would sell Apple's OS X -- if customers wanted it.
Makes me think I woke up in the twilight zone this morning. Must have been the dream about pigs flying. Hey, more unusual things have happened. I worked for a company, Arthur D. Little Inc., that once made a sow's ear into a silk purse.
Anyway, Dell and Sunn will sell the competitor's products because customer satisfaction -- the real thing, not the platitudes -- is what can make or break direct-selling tech companies today.
Monday, July 04, 2005
KVM-Mac update
Gail, the new look is fine by me :-).
Sunday, July 03, 2005
OnComputers Podcast
Swiping Back At Credit-Card Fraud
Microsoft about to buy into a BIG mistake
And I agree with the headline. But as one commenter posted, what better way to report to MS what software you have on your computer, as an anti-piracy measure, of course.
*Tongue firmly in cheek*
Perhaps another blogger has a better perspective on any positive business angle for Microsoft.
Any thoughts????
UPDATE:As I read through the article, there was a link to a previous show guest Ben Edelmen,
and his concerns with it, even more info at that link.
P.S. Well I tried to find the link to the show, and couldn't quickly, but I'm sure you heard it :)
U.S. to Retain Oversight of Web Traffic
"A unilateral decision by the United States to indefinitely retain oversight of the Internet's main traffic-directing computers prompted concerns Friday that the global telecommunications network could eventually splinter."
Fasten your seatbelts and hang on tight!