Thursday, April 7, 2011

Google boosts Android security with encrypted tablets, remote PIN reset

Google is trying to make Android more appealing to businesses by adding IT administration tools to Google Apps that can encrypt Android tablets or remotely locate a lost Android phone and reset the PIN.

In a new blog post, Google product manager Mayur Kamat announced that "With the new version of the Google Apps Device Policy app, employees can quickly secure a lost or stolen Android 2.2+ device by locating it on a map, ringing the device, and resetting the device PIN or password remotely via the new My Devices website."



Best online Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com


MOBILE SECURITY: Android improves, but trails iPhone and BlackBerry

Android 2.2 and up is used on mobile phones, while Android 3.0 is for tablets, such as the Motorola Xoom. To make Android tablets more business friendly, Google Apps customers will now be able to require encrypted storage on tablets running Android 3.0.

The tablet encryption requirement is achieved through an API that lets administrators enforce policies such as encryption and the aforementioned PIN reset. As with Android phones, it appears that Android tablets will support software-level encryption but not the more robust hardware-level encryption.

The PIN reset and encryption features, as well as a new tool for looking up corporate contacts, will be rolled out to Google Apps business and education customers. Google Apps for Business costs $50 per user per year for Gmail, Google Docs, Calendar and several other applications. (See also: Google Apps basics.)

It only makes sense for Google to bring IT administration tools for Android right into Google Apps.

"With more than 300,000 devices activated per day globally, Android is seeing rapid adoption in the post-PC era," Kamat said. "Android works quite well with Google Apps, but we're working to make it an excellent choice for both end users and IT at businesses and schools."

This week's Google announcement doesn't say anything about the ability to remotely wipe all the data off an Android device, a key requirement for many IT organizations. However, Google already announced remote wipes and other features last October when it first released the Google Apps Device Policy application, which can be downloaded on the Android Market.

The application, in combination with a Google Apps subscription, lets IT "remotely wipe all data from lost or stolen mobile devices; lock idle devices after a period of inactivity; require a device password on each phone; set minimum lengths for more secure passwords; [and] require passwords to include letters and numbers," according to Google.

Google Apps for Mobile also includes administration tools for rivals iPhone, BlackBerry, Windows Mobile and Symbian. Managing multiple types of devices will be key for any mobile management platform because the smartphone market is not dominated by any one single vendor.

Microsoft just recently, for example, expanded its System Center management capabilities to iPhones, iPads, Android and Symbian. (See also "iPhone, Android, Windows and Linux: Microsoft now manages them all.)

Wednesday, April 6, 2011

Windows Live Family Safety 2011

Parental control of a sort is built right into Windows 7 and Windows Vista. For each child you can set a weekly computer use schedule, control which games are permitted, and block specific programs. Windows Live Family Safety 2011 (free, direct) extends these features and adds the remaining components you'd expect in a full-scale parental control system. Note, though, that if you got yourself a new computer and gave the kids the old XP box, you can't use this edition of Family Safety, and the older XP-compatible edition lacks many significant features.




Best online Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com



Family Safety is a component of Windows Live Essentials but it can be used independently if you don't want the whole package. As in Norton Online Family Premier ($49.99 direct, 4 stars) and Bsecure CloudCare 6.0 ($49.95 direct, 3 stars) all Family Safety configuration occurs online—from any Web browser—with a small client program that enforces rules on the computers the kids use.

As another full-scale free parental control product, Norton Online Family (Free, 4 stars) is the closest competitor to Family Safety. In this article, unless otherwise stated, I'll refer to features from the free edition of Norton Online Family, not the Premier edition.

Rocky Start
Installing just the Family Safety and Messenger modules from Windows Live Essentials was easy enough. However, on trying to launch Family Safety I got the error message "Access is denied: Error 80070005." According to Microsoft's help website this is caused by attempting to run the program under an account without Administrator privilege. I verified that was not the case; I was definitely using an Administrator account. Luckily the product ran correctly after a reboot.
Specifications

Type
Personal
Free
Yes
OS Compatibility
Windows Vista, Windows XP, Windows 7
Tech Support
FAQs and forum.

More

On another computer I logged into the Family Safety website and defined a child account. As part of this process, I had to create a Windows Live ID for my imaginary child. I'm not entirely sure I approve of that requirement—does a toddler really need a Windows Live ID?

On the flip side, if a child under 13 attempts to create that Windows Live ID directly then the Children's Online Privacy Protection Act (COPPA) requires parental permission. Microsoft verifies parental permission using a small charge (50 cents) on the parent's credit card.

Back on the test system, I created a user account for my child. The product strongly recommends using Standard/Limited accounts for children. That's a reasonable requirement. The problems that caused many parents to just give the kids Administrator accounts under XP are effectively solved in Window 7 and Vista.

At first log-in, my brand-new user account didn't work correctly at all. The Start menu would only stay open for a few seconds, so launching any program was tough. Family Safety's program control correctly blocked Firefox, as I had configured it to do, but also blocked many other programs. It even blocked the program that provides its own visible user interface. Another reboot cured the problem, but it was definitely a rocky start.

A little experimentation showed that changes made online don't take effect right away. Family Safety checks the configuration once per hour or at login. Most products that offer remote configuration receive changes almost immediately—a much better result. Some, like Norton Online Family, also include an option to check for new settings on demand.

Content Filtering
Keeping the kids from accidentally or deliberately visiting inappropriate websites is a primary feature of most parental control systems. Net Nanny 6.5 ($39.99 direct, 4.5 stars) (PCMag's Editors' Choice), Norton, and most others let parents pick and choose from specific categories to block. Many automatically pre-configure categories based on the child's age.

In Family Safety parents choose a filtering level rather than picking from dozens of specific categories. The toughest level prevents access to all sites except those explicitly added by parents. At the Child-friendly level kids can also visit sites that have been categorized and vetted as fine for kids. The General Interest level allows wider access to web sites "of general interest," and the Online Communication level also permits social networking, chat, and webmail.

For the oldest kids, the Warn on Adult level doesn't block anything but does give a warning before allowing access to adult sites. I used the Online Communications level for my testing.

When Family Safety blocks a site, it gives the child an option to request access by e-mail or by asking a nearby parent. The online management console includes a page for pending requests which lets the parent allow or block the site for this user or for all users. Parents can also transfer existing lists of blocked and allowed sites between users at any time.

As always I tried to find sites with offensive content that slipped past the filter. I was able to reach a few iffy ones, but nothing undeniably "adult" in nature. I verified that Family Safety forces Safe Search in Bing and Yahoo, but when I tried to visit Google I found it blocked by Family Safety. They're pulling for Bing, maybe? Microsoft said Google should not be blocked, but the only way I could use it was to define an exception for the site. K9 Web Protection 4.0 (Free, 3 stars) and Net Nanny take Safe Search protection to the next level by blocking access to search sites for which forced Safe Search isn't possible.

A child with a Standard account can't run the network command that disables some parental control systems. In any case, Family Safety is immune to this attack. A secure anonymizing proxy will still give the kids unlimited access. However, I had quite a hard time finding a secure anonymizing proxy site that wasn't itself blocked by Family Safety. The one I did locate gave me unfiltered access but went from unblocked to blocked overnight.

Both Norton Online Family and Family Safety allowed to me view some videos that I'd definitely consider inappropriate. That's not uncommon. Net Nanny's real time content analysis can filter out videos based on keywords, and Safe Eyes specifically includes filtering for videos but few other parental control systems have the ability to allow a site like YouTube while blocking specific videos. The Premier edition of Norton Online Family tracks videos watched on popular sites, which at least gives parents an eyeful of what the kids are watching.

Tuesday, April 5, 2011

The real security issue behind the Comodo hack I

News of an Iranian hacker duping certification authority Comodo into issuing digital certificates to one or more unauthorized parties has caused an uproar in the IT community, moving some critics to call for Microsoft and Mozilla to remove Comodo as a trusted root certification authority from the systems under their control. Though the hacker managed his feat by first compromising a site containing a hard-coded logon name and password, then generating certificates for several well-known sites, including Google, Live.com, Skype, and Yahoo, I'm not bothered by the technical issue. Instead, my main concern over Public Key Infrastructure (PKI) and digital certification is that users don't understand it.


Best online Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com

For the most part, people don't care about digital certificates and the security they could provide. I have a hard time getting worked up about a system error that 99 percent of users simply ignore.

[ Master your security with InfoWorld's interactive Security iGuide. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. | Get a dose of daily computer security news by following Roger Grimes on Twitter. ]

PKI is not the culprit
First, I should point out that the PKI system didn't fail, at least after the compromise. The designers of PKI realized from the very beginning that fraudulently issued certificates were a fact of life. They invented revocation for it. When the fraudulent activity was noticed, the major involved vendors revoked the certificates and issued security updates inform of the revocation. Security advisories were sent out and the worldwide news picked it up.

In short, the Comodo hacker did something that has been carried off and in all likelihood will happen again. He didn't accomplish anything significant such as invalidating the math or crypto algorithms relied upon by the world's PKI subsystems. The latter issue would be far more unsettling.

Blissful ignorance
I'd be more concerned about this incident if people actually paid attention to digital certificate errors. However, study after study shows that most people simply ignore such warnings and move around them. I remember a study a few years ago that showed that the more one knows about digital certificates, the more likely one is to ignore certificate errors.

Monday, April 4, 2011

Lessons from the Samsung rootkit that never existed

A lot of malicious software originates in the former Eastern Bloc and other once-communist nations. Theories of why that is vary: Perhaps unemployed workers in those countries are highly educated in technology disciplines and remain steeped in a culture of underground capitalism from the communist era. Or, more simply, it could be the a lack of a legal framework to prosecute cybercrime.





Best online Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com


Security software firm GFI Software went unintentionally overboard protecting against Balkan malware, classifying the entire Slovenian language as malicious. Under certain settings, GFI's Vipre malware scanning engine labeled the Windows/SL directory found on some Samsung computers as malicious, mistaking it for the StarLogger rootkit. Rootkits hide themselevs on a victim's system to escape detection; in reality, the directory contains localization files for the south-central European nation of Slovenia.

The false positive came to light when a blogger for Network World (a sister publication to InfoWorld) posted that he had discovered rootkit software on a new Samsung laptop Wednesday using the Vipre malware scanner. Within 24 hours, both Samsung and GFI Software confirmed that the software was not detecting a true rootkit. GFI apologized for the mistake on Thursday, calling it a false positive.

"A Slovenian language directory for Windows Live is causing us considerable headaches this morning, and we have no one to blame but ourselves," Alex Eckelberry, general manager of GFI Security, wrote in the post.

The problem, according to a post on the GFI Labs blog, is that its software can use directory paths as a detection method if the scanning software is set to a very aggressive mode of detection.

"The detection was based off of a rarely-used and aggressive Vipre detection method, using folder paths as a heuristic," Eckelberry says. "I want to emphasize 'rarely,' as these types of detections are seldom used, and when they are, they are subject to an extensive peer review and QA process."

Eckelberry apologized to Samsung and blogger Mohamed Hassan for the mistake.

Security experts started twittering their criticism of the mistake in short order, with at least one antivirus rival blaming Vipre, despite the fact that GFI noted that only running Vipre in a non-standard mode will generate the false positive.

Hassan has become the focus of the most vociferous criticism. To some extent, that criticism is justified: If the IT consultant and blogger had sought out and waited for positive confirmation of the rootkit, the article would have been stopped before it became widely published.

However, if it's true that a support person at Samsung actually told Hassan that "we just put it (the rootkit) there to find out how the computer is being used," then the technology company has to share a part of the blame as well.

Finally, others blame journalists who telegraphed Hossan's story without adequate confirmation. Ultimately, the speed at which the story propagated itself is a testament to the nature of news coverage in the digital age. Information is a virus -- even if it's not written in Slovenian.

Sunday, April 3, 2011

“Across the world, thousands of people are giving birth to what I call an ‘Empire of One’”

Thomas Frey’s revolutionary vision has inspired people in the higher levels of government as well as the top executives in Fortune 100 companies, including NASA, IBM, AT&T, Hewlett-Packard, Lucent Technologies, Boeing, Bell Canada, Visa, Ford Motor Company and many more.


What technologies do you think would be with us in the future?

1. Binary power is the concept where two otherwise harmless beams of energy will intersect at some point in space, creating a source of power.
To better explain binary power, think in terms of two invisible beams intersecting in a room and the point at which they intersect as a glowing point of light. Binary power will eventually replace all light bulbs. And lest you think it can only be used for intense forms of power, it will also be used to create ‘points’ of sound, eliminating the need for speakers and headphones.






Best online Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com



2. Proof has to be demonstrated on two very fundamental levels before there is reason to think that time travel is truly possible. The first is to be able to communicate across time, and the second is to be able to view things across time. If we cannot first communicate across time, or view real life images of another time, how can we possibly imagine sending people across time?

So the ‘viewing things across time’ technology that I think most promising is—viewing the past. Think in terms of setting up sensors around a room and being able to replay images of past events, as much as 20, 50 or 100 years ago.

3. Disassembling matter. Imagine a technology capable of breaking all of the molecular bonds in any given material. As an example, place a rock on a table, focus a beam on the rock and visualise all the molecules in the rock separating and falling in a pile onto the table.
Now imagine being able to selectively disassemble the rock. All of the molecules separate except for a piece in the middle that looks like a rocking chair. Suddenly we would have the ability to sculpt solid-rock rocking chairs whenever we wanted to.

This is probably a poor example but I think you get the idea.
Thomas_Frey1
"Inventions will happen so quickly that few people will understand the line between what is real and what is still only imagined."

What are today’s most prominent technologies that you believe will have no takers in the future?

Some of today’s technologies that are on their way out include fax machines, the checking industry, traditional television, invasive surgery and regular AM-FM radio.
Also, RFID technology will quickly come and go as we develop search technology for the physical world that works without the chips. You can understand this better only through a detailed example, and this example is necessary because RFID is considered by many as a promising technology.

Many years ago, the famed father of fractal geometry, the gifted mathematician Benoit Mandelbrot, was presented with the question: “What is the distance around a lake?” His response was: “It depends on your perspective.”

If you look at a lake on a map from an altitude of 100,000 feet or 30,000 metres, it is very easy to draw a line around the lake and measure the distance. As you move down through the different altitudes, more and more details become visible and the distance continues to increase, as suddenly the line is being drawn around clumps of dirt, and later grains of sand, and eventually individual molecules. The distance around a lake approaches infinity.

The Mandelbrot distance-around-a-lake perspective has far reaching implications. As we develop the technology to see tinier and tinier particles, we will also be able to define physical objects in unique and different ways. And one way will be to define every object as digital information—digital information that will be searchable, traceable, and yes, even ‘spyable’.

So is the case when you look at a departmental store from a distance--it is just a building, but as you come closer, the components with RFID tags become clearer.

While the argument will arise that RFID chips have the ability to emit signals that make them uniquely and unreasonably intrusive, the reality is that all objects emit reflected light and this too will some day be the source of uniquely and unreasonably intrusive information.
This type of technology is inevitable and will likely be developed sometime within the next 10-15 years.

Considering your view that some of the promising technologies will vanish, how different would the entertainment of the future be?

I am going to answer this in a rather unusual way and talk about how libraries will become a very entertaining place to go to.

John Naisbitt tells us, “In the experience economy, services are linked together to form memorable events that personally engage the customer.”

As an example, coffee can be bought on a commodity level at any grocery store. On a product level it can be bought in any restaurant. But if you want the real coffee experience, you have to go to Starbucks. If you pay close attention, Starbucks is not in the business of selling coffee. Rather, their primary product is the Starbucks experience. So, if we transition that concept into the information world, how do we go about creating the ultimate information experience? How do we take words on a page, books on a shelf, or digitised bits on a memory stick and create information that has an impact? Another way of asking this is, how do we create informational experiences that are entertaining, timely, pertinent and fun, while at the same time are meaningful and relevant to our lives?

Libraries are a perfect example of an industry struggling to make this transformation. Long regarded as a ‘centre of information’, libraries find themselves competing with Barnes & Noble and their warm, inviting atmosphere, soft comfortable chairs and in-store coffee shops. Future libraries have an opportunity to reinvent the information experience.

Here are some examples of featured experiences that could be added to a library:

• Treadmills and exercise bicycles—People can read a book or listen to an audio book while they are working out. In fact, with added blood flow to the brain, this type of exercise-learning can actually improve retention.
• Mini-theatres—The world is rapidly shifting to video for their information, best exemplified by YouTube’s million-plus downloads each day. Watching video on a computer screen is just scratching the surface of what the true experience could be. Mini-theatres will be designed to offer a fuller sensory experience without all the distractions.
• Podcasting studios—Podcasting is quickly catching on, but few people understand how to use the equipment and post their podcasts online.
• Vidcasting studios (the video version of Podcasting)— These studios will quickly develop their own centre of gravity, attracting a wide spectrum of creative people who want to make their ideas come to life.
• Band practice rooms—MySpace currently has 2.2 million bands in their social network, and virtually all of them are searching for good places to practice. Sound-proof rooms with viewing windows and listening phones will create an entirely new experience for libraries.

These are just a few of the possibilities for creating the next-generation super-entertaining library.

Technology is going to play a major role in driving us towards the future—what would be the structure of enterprises or businesses going ahead?

Running a solo (one person) business in the past meant that you had a one-person practice, most often offering a professional service, well suited for lawyers, accountants and doctors. However, a new breed of solo business has emerged that allows people to leverage the power of the Internet and control a vast empire from their home office or wherever they happen to be. Across the world, thousands of people are giving birth to what I call an ‘Empire of One’.
Most ‘Empire of One’ (an Empire of One business is a one-person (sometimes married couple) business with far-reaching spheres of influence) businesses require an affinity for working in the online world. The Internet is an unparalleled communications tool, growing organically in ways few could have imagined, and in ways that are difficult to manage. Unlike putting a product on a store shelf and counting the number of sales, feedback loops for gauging influence and making good decisions online are not always intuitive. Quite often, the mention of a product online today will yield results several months from now, and the establishment of an online brand is far different than traditional corporate branding.

Few people can run their ‘Empire’ business without good relationship-building skills. While it is commonly thought that online businesses isolate people, and owners end up being quite insulated from their customers and vendors, successful businesses are far more sustainable if they are built on a foundation of good will and solid relationships. Relationships can be as weak as an e-mail exchange or a voice at the end of the telephone, or as strong as lengthy face-to-face meetings. But, a person’s ability to build endearing forms of communications between affected parties, has a direct correlation to the likelihood of success.

Typically, the business outsources everything—information products marketed and sold online, or products manufactured in Asia, sent to a distribution centre in Europe, with customers in the US, UK and Brazil. Manufacturing, marketing, book-keeping, accounting, legal and other operations are all out-sourced to other businesses around the world.

Yes, much of this has been done before, but a person’s ability to leverage people and products across country lines in a below-the-radar fashion, and still maintain control of a vast and virtual empire, is refreshingly new.

Virtual Citizens are already out there—what do you think about a ‘real’ virtual world in the future? How would people interact or commute, transfer money or buy things in that age?

The world presently being created on Second Life already has much of what you are talking about. I see Second Life as the next generation of social networking, but so much more.
It has its own currency, land to buy and sell, and free enterprise systems that allow entrepreneurial-minded people the ability to build new countries and new kinds of business.

What is the future of laboratories or inventions?

In the past, computer programming has been focused around architecting the flow of electrons. In the future, nanotechnology will be focused around architecting the flow of matter.
Laboratories in the future will be akin to thought factories where the outputs will be visualisations with several million permutations. Inventions will happen so quickly that few people will understand the line between what is real and what is still only imagined.

Saturday, April 2, 2011

Microsoft Offers Students Windows 7 Upgrade for $29.99

For a limited time, college students can upgrade from Windows Vista to Windows 7 Professional for just $29.99, Microsoft said Friday.

Students need to be currently enrolled at a university, with a current student ID and a valid email address. If they meet those criteria, then students simply need to visit this Microsoft site and register, where they will purchase a digital license key. The software will be delivered electronically via Digital River, Microsoft said, with an option for backup media.



Best online Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com



Normally, students pay $64.95 to upgrade, Microsoft said. Microsoft did not specify whether the software was designed for 32-bit or 64-bit systems.

Students can also purchase Microsoft Office Professional Academic for $79.95, and the Microsoft Office Language Pack for $9.95, Microsoft said.

Ever since it launched Windows 7 with some amazing discounts, Microsoft hasn't shied away from occasionally offering discounts to users to persuade them to move away from Windows XP and Windows Vista to its latest OS.

The student discount easily trounces even the discounted OEM version of Windows 7 Home Premium, available for $99.99. A version of Windows 7 Professional costs $139.99 from Newegg.

Last year, Microsoft re-instituted the Family Pack for Windows 7. For $149.99, the bundle provides upgrade licenses to Windows 7 Home Premium for up to three devices.

At the full list price, buying the Family Pack will cost users about $180 less than it would to buy separate licenses for three computers. It's available in the Microsoft online store and at participating retailers. Amazon.com sells the bundle for a little bit cheaper than most at $139.99. Microsoft didn't indicate a specific end date for the sale of the pack and just said it was available "while supplies last."

Friday, April 1, 2011

Facebook Launches One Mobile Site to Rule Them All

Facebook launched a new mobile site on Thursday, one geared as much to feature phones as the most expensive mobile handsets.

The site name is the same: m.Facebook.com, which will replace Facebook's previous sites at touch.facebook.com and m.facebook.com. The former site was geared towards high-end touchscreens, and the latter was a slimmed-down, simplified interface that was designed for feature phones. The ultra-stripped down site, 0.facebook.com, will also be folded into m.facebook.com, Lee Byron, a Facebook product designer, said in a blog post.



Best online Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com



"We think it's important to provide an excellent mobile Web experience," Byron wrote. "Now, whenever we launch new features on the mobile site, they'll be available on any mobile browser, presented in the best possible experience."

The new versions of the sites will be rolled out to users over the next few weeks, Byron wrote.

The key to all this? WURFL, an open-source device description repository, or an "'ambitious' configuration file that contains info about all known wireless devices on earth," according to Luca Passani, who authored a background info page at SourceForge, where the WURFL code is hosted.

Previously, Facebook tried to write individual pages for as many devices as possible. This didn't work, and in the mishmash of Javascript and CSS, features were left out and the user experience was degraded, Byron wrote.

By referring back to the WURFL database, Byron noted, one command can be written and then interpreted for a specific device, thus optimizing the experience.

"For other devices we can target specific issues," Byron said. "For example, some devices don't have keyboards, or have limited means of navigating a page, tiny screens, or crippling browser bugs. We can customize our site in each case to deal with these issues and provide the best possible experience to everyone.

"This mobile UI framework allows engineers to focus on building their product and not on supporting device edge cases," Byron added. "Rather than directly writing HTML, CSS, and JavaScript, our product engineers write XHP and use these mobile components to build new features."

MCITP Training - MCITP Certificaion - MCTS Exams Training - CCNA Exams - and more at CertKingdom.com