Apple's HTML5 bet against Android extermination

Open ... and Shut Harvard professor Clayton Christensen has more than 500 billion reasons to think he's wrong to suggest Apple is in for rough sailing, but he's not backing down. The father of disruption theory - a theory that Apple's former chief executive Steve Jobs claimed had a huge impact on his thinking - believes that Apple's end-to-end, integrated approach to innovation is susceptible to disruption from a more modular, open approach like that of Google's Android.

He could be right. But then, we've heard this before. (Proving that I can be consistently inconsistent, I've argued both for and against Apple's strategy.)

It takes a bold person to predict Apple's downfall even as it continues to grow from strength to strength, but Christensen is comforted by having the weight of history on his side:

The transition from proprietary architecture to open, modular architecture just happens over and over again. It happened in the personal computer, and although it didn't kill Apple's computer business, it relegated them to a minor player.

As much as Apple looks indomitable right now, there are signs that Christensen's theory will prove correct again. While Apple is crushing competitors in the relatively new tablet market, it has already lost its pole position to Android in smartphones. If the Android crowd can get its act together in tablets, this seems likely to play out in the tablet market as well. Indeed, despite a Q1 drop in market share, Amazon's Android-based Kindle Fire seems like it could be the first Android tablet to give Apple a serious run for its money.

It's possible that part of the delay in Apple's "inevitable" decline has come from the two sides – Apple (closed) and Google (open) – stealing ideas from each other's playbooks. Apple has continued its high-margin business model, but it has also consistently lowered prices to compete on price with alternatives from Samsung and others. (Whether it can cut prices enough to be competitive in emerging markets is another question, however.)

Apple, for its part, has married these price cuts with significant investments in open technologies like HTML5 support in its devices. Contrarily, Google's Android hasn't been a truly open alternative to Apple's integrated approach, dulling its effect as the knight in open armor.

Roger McNamee, managing director of Elevation Partners, channels Christensen, arguing that Apple has won precisely by betting against the openness of the web with a closed ecosystem. But this is only momentarily true, as McNamee holds that Apple's closed app ecosystem model will give way to an infinitely more open web app future built on HTML5. There are plenty of reasons for this, but at least one is the hit-or-miss success of app developers, in part due to the difficulty of getting noticed in an overburdened App Store.

But this is where Apple may have learned from Christensen's "Innovator's Dilemma". As noted above, Apple has actually surpassed Google's Android in terms of HTML5 support. Apple not only has the best closed app model, but it also has the best open HTML5-based web app model.

Perhaps. But as legendary investor Warren Buffett notes, even an investor as savvy as he did not predict Apple's last 10 years, and so he and other big brains can't reliably predict its next 10 years.

Still, one thing is a pretty safe bet: over the long haul, openness generally wins. When that openness is backed by Google's willingness to lose money on Android for years in order to seed the market, Apple has a strong competitor. The question is whether Apple, through HTML5 and other means, has been open enough to keep winning the mobile game. As Buffett goes on to say, you might not want to bet on Apple to win, but you wouldn't be wise to short it, either. ®

Matt Asay is senior vice president of business development at Nodeable, offering systems management for managing and analysing cloud-based data. He was formerly SVP of biz dev at HTML5 start-up Strobe and chief operating officer of Ubuntu commercial operation Canonical. With more than a decade spent in open source, Asay served as Alfresco's general manager for the Americas and vice president of business development, and he helped put Novell on its open source track. Asay is an emeritus board member of the Open Source Initiative (OSI). His column, Open...and Shut, appears three times a week on The Register.

Adobe sucks on Oracle brain drain for HTML5 game gain

Adobe seems to be juicing its software gaming credentials against HTML5 by grabbing some hard-core Sun Microsystems talent as they slip out Oracle's back door.

Four senior and respected members of the old Sun Hotspot Java Virtual Machine team jumped clear of Oracle during March and April, and all four have landed at Adobe.

The four are Paul Hohensee, who has been named principal computer scientist at Adobe, John Pampuch, who grabbed a spot as director of Flash VM, and Igor Veresov and Tony Printezis, who were both appointed as senior computer scientists at the software-maker.

A further two Sun VM brains – Charlie Hunt, a former performance lead engineer, and YS Ramakrishna – have also left Oracle, for Salesforce.com and a small private software firm respectively.

Until their exit, they'd occupied similar posts inside Oracle as technical staff directing HotSpot or working on engineering performance. Hohensee joined Sun in 1999 and Ramakrishna in 2002 while Veresov, Pampuch and Printezis joined in 2005.

The group's members all boast deep experience in garbage collection, memory management, compilers, HotSpot development and in languages – prized among anybody interested in squeezing out micro sub seconds of performance from their software.

According to his LinkedIn profile, Hohensee is working with Adobe managers and engineers on technical direction and delivery of a "high performance and extremely reliable product" and to "contribute to overall Flash technical direction".

Oracle inherited the team along with HotSpot when it acquired Sun in 2010. Adobe, meanwhile, has them working on its ECMAScript-based ActionScript language and associated VM, which is part of Flash Player.

In November 2011, Adobe shook up its Flash roadmap in the face of competition from HTML5 and growing resistance to Flash on devices, thanks to Apple's deceased co-founder and chief exec Steve Jobs. Adobe has recast Flash as the platform for something very specific, gaming, instead of being a generic media player for broad use everywhere.

The ActionSctipt VM had been part of Flash but with Flash being sidelined either the ActionScript VM must perform better minus Flash, or ActionScript must work better on other VMs: chiefly, HotSpot.

To help, Adobe is revisiting ActionScript, which has gone virtually unchanged since its introduction in 2006. "Adobe believes it is time to revise the language to carefully steer its further evolution towards greater expressiveness as well as productivity and performance gains," the firm said.

The idea is to make ActionScript better suited to the high-performance and hardware utilisation requirements of gaming, and to improve developer productivity. The wording of the roadmap plays right into the skills of the ex-Oracle team – a complete embrace of static typing and hardware-oriented numerics.

This is big: having killed Flash for mobile, Adobe is now focusing on the browser and device hardware. ActionScript is up against its ECMAScript cousin, HTML5, which everyone from browser-makers to tablet-lovers wants to get with. The planned changes are so extreme that Adobe has warned that existing apps might not work with the new ActionScript.

While Adobe will have recognised the value of the quartet it has hired, there was no word on their LinkedIn profiles on why they've all jumped clear of Oracle all at the same time. Oracle has certainly seen a number of former Sun brains leave, the biggest being Java daddy James Gosling.

It is not unusual for employees acquired by a new owner to leave and it's possible this group have left in the wake of the vesting of any share options they might have received from Oracle. Shares in such acquisitions are allocated in chunks over a given time period to help retain the talent. Vesting periods are typically six months, a year, two years and four years. ®

Oracle claims $777m in new trial over SAP infringement

TomorrowNow business balls-up haunts SAP

By Iain Thomson in San Francisco • Get more from this author

Posted in Business, 3rd May 2012 19:41 GMT

WIN - A free one year, 25 user licence of Microsoft Office 365!

Oracle is going back to court with a claim of $776.7m against SAP over the software-stealing antics of subsidiary TomorrowNow.

Larry Ellison's crew got an award of $1.3bn in 2010 after TomorrowNow admitted filching Oracle's intellectual property and taking it to SAP when the German software house bought the company out. Co-CEO Bill McDermott was forced to make a humbling apology to Oracle on stand and now the two companies are fighting over the damages.

TomorrowNow pleaded guilty to the code copying charges and paid a paltry $20m for its crimes, but the battle over the amount of damages oracle wants has been going through the courts for two years now, and will probably not be sorted by the end of the year.

SAP's initial $1.3bn charge was potentially increased by $211m after Oracle demanded interest payments as well, but the award was deemed too high by the appeals judge and reduced to $272m. Oracle said that wasn't good enough and appealed, initially for the full $1.3bn but it has since reduced its offer.

“We think Oracle’s damage estimate is overstated,” Jim Dever, a spokesman for SAP, told Bloomberg. ®

WIN - A free one year, 25 user licence of Microsoft Office 365!

Google unleashes Chrome 19, flattens 20 bugs

Google released a major update to its Chrome browser on Tuesday that tackles 20 security vulnerabilities, eight of which are classified as high-risk bugs.

Chrome 19 – a cross-platform update for Windows, Mac, Linux and Chrome Frame – also includes a number of improved features such as tab sync. Google paid security researchers more than $7,500 under its bugs bounty programme for identifying the various vulnerabilities squashed by Chrome 19.

Most of the high risk flaws patched by the new version of Chrome tackle either "out-of-bounds write" or "use-after-free" memory vulnerabilities.

The full list of vulnerabilities addressed in Chrome 19 is detailed in Google's advisory here.

In other patching news, Apple released a critical update addressing 17 security flaws in its QuickTime Media Player software. Several of the fixed vulnerabilities might lend themselves to attacks that plant malware onto the systems of users running pre-update versions of Apple's media player software. QuickTime 7.7.2 addresses a total of 17 security bugs, as explained in Apple's advisory here.

Rodrigo Branco, director of vulnerability and malware research at Qualys, discovered one of the critical bugs during fuzzing, a process that involves supplying a range of malformed data inputs to the application and checking for problems. ®

IBM smashes Flash out of Wimbledon, serves up HTML5 app

Next month’s Wimbledon tennis championship in London will serve up more player data than ever before and, for the first time, deliver live video to game fans over the web.

SPSS software from IBM will be deployed at all 19 courts and to capture information, draw up competitors’ stats and evaluate their performance.

The kit is increasingly used in other sports to analyse players and predict injuries; the Leicester Tigers rugby club uses Big Blue's analytics for risk assessment, for example. It has also been used to study play on Wimbledon’s outer courts, but 2012 will be the first tournament with SPSS covering every court, including centre court and court number one.

IBM’s software will crunch minutiae game data - such as how fast a player runs, the distance covered and speed of turn - that’s fed in manually and electronically to build up a stats-based picture on aspects of the game, such as returns and consistency of servers.

SPSS runs as part of the Wimbledon Information System (WIS) installed at the venue in southwest London and that uses DB2 on System x and Linux.

The output will be chewed over by pundits, pros and the public from online scoreboards that have been redesigned from Flash to HTML5 to help Wimbledon capitalised on growth in mobile traffic, specifically iPhones and Android. The expansion in the SPSS will mean more data served up to the web using HTML5 by the Wimbledon tournament than ever before.

The Wimbledon website got 450 million hits during the tournament’s two weeks last year, and 7.6 per cent of that traffic came from mobile. Between 10 and 20 per cent of that came from an iPhone app that IBM had launched in 2010 – the Android build arrived last year. IBM, meanwhile, is relying on HTML5 for the iPad instead of building a dedicated app at this stage.

“Traditionally our on-demand scoreboards have been built in Flash, and Flash let us be very visual in the way the information could be presented,” IBM's Wimbledon client and programme executive Alan Flack told The Reg. “But tablets don’t support Flash and we are seeing an increasing number of these.”

Andy Burns, IBM lead consultant, added that the tennis-watching mobile public wants more data and less graphics – the latter being something Flash basks in.

“We may have sacrificed some of the visual eye candy, but our site is not about that – it’s about providing the rich and accurate stats. Our fans want to see stats rather than fancy transitions. We don’t need the power of Flash. We are quite OK using the power of HTML5,” Burns said.

Scoring might be stripped down but video is on the rise and this year’s tournament will see live match play broadcast online for the first time from Wimbledon.com – a move OK’d by the Lawn Tennis Association.

Video will be encoded using H.264 and played using the Daily Motion player. There won’t be geographic restrictions on the live feeds, meaning it can be viewed anywhere.

Flack added: “Hits to the web site grow every year – whether that’s through mobile or traditional laptops or computers. Mobile is driving a lot of additional traffic. It’s probably bringing sport to a wider audience.” ®

Microsoft to devs: Don't ruin Win 8 launch with crap code

Microsoft has urged developers to only use approved Windows 8 software interfaces to avoid spoiling the launch of its new operating system with dodgy code.

In a stark warning this week, the company said third-party programmers should “resist the temptation” of invoking APIs that aren’t included in the official Software Development Kit (SDK) for the new Metro user interface.

Developers who flout this rule are in “violation of customer expectations and [Windows] Store policy”, the software giant said in a blog post titled “delivering reliable and trustworthy Metro-style apps”.

Using unofficial APIs, Microsoft said, is likely to “ultimately undermine the expectations that customers have for your app” if it crashes or plays up as a result.

John Hazen, a programme manager for the Windows 8 developer experience team, blogged here:

APIs that are outside the SDK are not guaranteed to work with Metro style apps either in this release or in future releases, so you may find that your app doesn’t function properly for all customers.

These APIs may also not function properly in the async environment that is foundational to Metro style app design. Finally these APIs may undermine customer confidence by accessing resources or data that Metro style apps would not normally interact with.

The advisory is a standard one from any operating system developer; technophobic punters often blame the OS maker when a program crashes because some smart arse cut corners, used unofficial APIs or tried an unapproved technique.

However the warning comes hot on the heels of Redmond locking down Windows 8 on ARM (Windows RT) to ensure handheld devices can't be jail broken to run homebrew and unapproved software. The company is keeping the mobile platform so closed, it’s denying access to rival Mozilla which had been porting Firefox to Windows 8.

Microsoft has created plenty of confusion between Windows 8 for ARM and Windows 8 for everything else; its Metro interface for phone and PC use completely different runtimes and frameworks, and they have different online software shops - Windows Store for Windows 8 and Windows Marketplace for the phone.

It would seem Microsoft is trying to keep these two worlds separate, and prevent an app built for the phone finding its way on to the PC, encountering not just technical problems but also ruining some careful market segmentation by Microsoft based on device type and software.

Reg contributor Tim Anderson pointed out that the greater danger Microsoft faces is the likelihood that coders will try to play fast and loose on Windows 8 for PCs rather than Windows RT.

It comes back to what we've said before on Windows 8: just like the first Windows Phone, Microsoft is keeping the ARM platform closed to third parties, whose apps could cause application crashes and ruin the consumer launch. ®

Google Street View Wi-Fi data slurper named

The 'Engineer Doe', who designed Google's Street View Wi-Fi software to collect personal data, has been named by an American newspaper.

The engineer is reportedly Marius Milner, developer of the popular NetStumbler wardriving programme for Windows. Milner describes his occupation as a "hacker" on his LinkedIn page.

Google initially denied collecting personal information using its street-mapping camera-car fleet, then admitted it had captured unsecured Wi-Fi traffic but blamed a lone gunman slurper: a so-called "rogue engineer" who wrote the software in his "20 per cent time permitted for self-directed projects".

An investigation by the Federal Communications Commission demolished this theory, however. The FCC found Google guilty of obstructing its investigation but concluded that collecting personal data from unsecured wireless networks did not breach the US Wiretap Act.

Privacy group EPIC says the FCC report "undercuts the company's prior statements that a rogue engineer was responsible for the payload data collection".

"Instead," the organisation added, "it indicates that Google intentionally intercepted payload data for business purposes and that many supervisors and engineers within the company reviewed the code and the design documents associated with the project."

Google itself released the FCC's report into its Street View data collection activities on Saturday, with most of the details readable - some portions remain redacted. Groups including EPIC and Consumer Watchdog have filed Freedom of Information requests to access all of the documents in the case.

An independent source code analysis of the engineer's work, commissioned by Google, is now available [PDF, 486KB].

A little business context, missing from most press reports on this story, is useful to remember here. It concerns a firm called SkyHook.

SkyHook is a Boston-based company that had already compiled a nationwide database of Wi-Fi access points. The biz merely collected SSID and signal strength - not personal data. SkyHook's database was used by licensees of Google's Android operating system for locations services. Eighteen months ago, SkyHook filed a suit claiming that Google had strong-armed Android licensees to use Google's location database instead of SkyHook's.

Far from being the work of a "lone slurper" tinkering in his own time, the software could be seen as creating an essential component of the Street View software stack. Google's Wi-Fi access point database was considered to be of enormous strategic significance.

Google's strategy after the data-slurp is proving to be much more interesting than the actual packet sniff. ®

Facebook launches App <strike>Store</strike> Center

It's just a gallery of mobile applications ... for now

Facebook is launching an App Center to recommend mobile applications based on demographic preferences as well as user ratings, just as long as they're tied into users' Facebook credentials – with a view to monetising the process eventually, of course.

The App Center won't just recommend mobile apps, it will also showcase web-based applications embedded in Facebook and even other websites, as long as they are based around the Facebook logon. Listing will be free, and users will receive recommendations based on their demographic and history rather than blanket star ratings, so the Center will look different to every customer who enters.

Facebook won't sell mobile applications – Apple would never permit such a thing – so users are directed to the appropriate app store (iTunes/Google Play, there's no mention of BlackBerry World) but Facebook is the company telling them what to buy and is now open for submissions.

But Zuckerberg's empire has commercial aspirations for its service, promising "a simple-to-implement payment feature that lets people pay a flat fee to use an app on Facebook.com", which is taking applications for beta testing now. For mobile apps that will have to jump though the app-store hoops, this would probably involve a cut going to Google/Apple, but for applications within the Facebook site it could be a useful source of revenue.

Facebook would love to make some money on mobile applications, it would be delighted to make some money on mobile anything – having identified that mobile users are growing in number but are almost entirely unexploited as far as generating revenue is concerned. Even if the App Center can't make money selling mobile app subscriptions, Facebook might be able to sell premium advertising on it, and should be able to filter out a lot of the kipple which blights the main app stores.

Targeting content based on social demographics, recommending things on the basis that one's Facebook friends liked it, has a bit of a chequered past. Google's social search has attracted more than its share of criticism, while Facebook's Beacon was treated with the derision it deserved, but app recommendations based on demographic as well as social factors and may be an acceptable thin edge of the wedge for consumers looking for the next Bubble Witch Saga with which to fill their time. ®

Apple blocking Dropbox SDK over in-app buying

Developers using the latest Dropbox cloud storage SDK have been having applications rejected from Apple after Cupertino apparently decided that its terms and conditions have been breached.

"We have found your app provides access to external mechanisms for purchases or subscriptions to be used in the app, which is not in compliance with the App Store Review Guidelines. Specifically, this app contains a link that takes the user to Dropbox via Safari," numerous developers reported, with one posting his correspondence online.

According to the correspondence, Apple is taking umbrage at having a link to the Dropbox website where users can sign up for an account. The basic Dropbox service is free, although there are paid options available for higher amounts of storage, and it's these that appear to be causing the problems.

"Apple is rejecting apps that use the Dropbox SDK because we allow users to create accounts. We're working with Apple to come up with a solution that still provides an elegant user experience," the company told The Register in a statement.

Forum posts suggest that older versions of the Dropbox SDK may be good to go as far as Apple's concerned. Dropbox employee Brian S. has posted a workaround.

"You need to use this version of the SDK that removes the create account option," he posted. "We're working on a better solution and will have more to share about that next week."

The fuss is certainly not what Dropbox needs right now. The company is under pressure from similar cloud offerings and needs all the application support it can get. ®

Apache releases new OpenOffice build, promises faster upgrades

The Apache Software Foundation (ASF) has released an updated version of the OpenOffice free software suite, with enhanced graphics and better encryption support.

Version 3.4 of the office suite has had major changes in the graphics capability of the package. OLEObject handling has been improved, thanks in part to volunteer coder Armin LeGrand, as well as support for scalable vector graphics and better chart rendering. Line cap graphics have also received an improvement that should improve the look and feel of the code.

Other new features include a speeding up of the boot process and better support for ODF, notably ODF 1.2 encryption, as well as multiple images within the format. The entire software suite is now also under the Apache License 2 regime.

This is the first major revision to the OpenOffice code since Oracle handed OpenOffice over to the ASF, and will go some way towards regaining ground on its rival LibreOffice. OpenOffice Podling Project Management Committee member Donald Harbison told The Register that more revisions were coming soon and the team is already considering additions to the version four release.

"We wanted to make sure we had a really clean and stable built for version 3.4," he said. "Within six to eight weeks we should be in a position to get to version 3.4.1 out and then we'll be working on version four with the help of code from IBM."

IBM is due to hand over a chunk of its Symphony code for the OpenOffice project, which had been on hold until version 3.4 was released, and other companies are adding features. SugarCRM is working on integrating sections of its code base and SourceForge has been helping with extensions, although these are outside the Apache license, as well as adding a new distribution channel.

The releases will go some way to making OpenOffice more relevant for users, after much of its support has moved to LibreOffice, a similar suite set up by defectors from OpenOffice who left when Oracle started sticking its oar into the project. LibreOffice is now on version 3.5 and is included in most of the major Linux distributions, as OpenOffice used to be, and is gaining both developers and customers in government and enterprise.

It's not all cut and thrust in the open source office suite world however. Plenty of developers code for both packages – indeed the new work on line caps was done by a female German academic who has a foot in both OpenOffice and Libreoffice.

Harbison said that so far demand for the new build of OpenOffice was strong, with a significant spike in downloads so far, and Apache would be bringing in new features like a British English dictionary and application control features, with future releases. ®

RIM shares take a bath after uninspiring BlackBerry 10 unwrap

Investors were less than impressed with Research in Motion's demo of its new BlackBerry 10 operating system and the developer tools to go with it, sending shares sliding by 5.76 per cent.

New CEO Thorsten Heins pulled out the new gear at his first BlackBerry World keynote speech yesterday, giving folks a look at what the OS should be able to do. The start of the conference also marked the release of the developer kit for the system so app-makers can start have some snazzy stuff ready by the time the first handsets come out at the end of the year.

BlackBerry 10 is widely seen as the last chance saloon for the troubled Canadian phone-maker, which has struggled to look like it's keeping up with the likes of Apple and Android. And RIM needs developers to make a ton of apps for the new OS if it has any chance of taking off.

However, investor confidence in the firm seems to have evaporated. The stock has plummeted 72 per cent in the last year, helped by a 5.76 per cent fall yesterday from the previous day's close, leaving the shares trading at $13.48 on the NASDAQ.

One problem may be that RIM still hasn't given out many clues about what the hardware to go with the new system might be like. At BlackBerry World, it handed out a prototype device to developers, the Dev Alpha, although the company said the actual mobiles won't look anything like it.

In general, RIM has not done a good job of reassuring investors that it can recover from the market share shrinkage caused by Apple and Android phone-makers like Samsung.

Aside from failing to come up with a smartphone that can claw back some BlackBerry popularity, the firm also suffered after a three day outage towards the end of last year that was handled horribly, and from low sales of its unloved fondleslab the PlayBook. ®

Apple OS X update puts elderly Flash out of its misery

Apple has pushed out a slew of security updates for Macs running Snow Leopard (OS X 10.6) and Lion (OS X 10.7).

The operating system upgrades tackle various bugs that leak sensitive information, elevate a user's privileges and, most seriously, allow malicious code to be injected remotely and executed.

The 10.7.4 update grapples with a flaw in FileVault which causes users file encryption passwords to be stored in a log file in plain text. Apple's Remote Desktop client is also updated in 10.7.4 but isn't included in the update pack for Snow Leopard.

Mac OS X 10.7.4 fixes more than 30 vulnerabilities in the core OS, including Apple applications such as Quicktime, and some bundled software packages such as Samba, Ruby and PHP. A similar update for Snow Leopard 10.6.8 is available as Security Update 2012-0002.

Apple's explanation of the security components on both its Mac OS X updates can be found here. Each update requires a system restart to take effect, as is the norm.

The updates also bring in a new build of the Safari web browser. The latest version, 5.1.7, includes a feature that automatically disables the Adobe Flash browser plugin when it gets out of date and prompts users to install the latest version. This is to stop outbreaks of viruses that exploit security holes in old Adobe software.

Apple recently automatically switched off elderly Java installations in an OS update after hundreds of thousands of Macs were infected by the Flashback Trojan.

The update was broadly welcomed by security experts including Wolfgang Kandek, CTO at Qualys here, and Paul Ducklin of Sophos here.

The desktop update follows hot on the heels of Apple's update for smartphones and tablets – iOS 5.1.1 – which was released earlier this week; that update addressed three vulnerabilities with updates to Safari and WebKit. ®

RIM takes BlackBerry 10 out for a spin, forgets to bring phone

Video RIM's latest CEO has been showing off what its next OS, BlackBerry 10, will do, although without any hardware it's hard to be impressed by a touchscreen keyboard.

The trinkets came out during the Thorsten Heins' first BlackBerry World keynote, where attendees were given glances of a multitasking interface that involves swiping away foreground apps, and a soft keyboard with predictions above keys instead of the whole board.

But what they didn't get to see was a BlackBerry 10 device and without that it's little more than slideware.

That's a little unfair: developers will get to play with a "BlackBerry 10 Dev Alpha" device upon which they can prep their applications in anticipation of the launch of proper hardware later in the year, but that's small consolation for those who were hoping to see some real hardware at the event.

Thorsten Heins has only been RIM's CEO for three months, so it's not his fault there was only a video to show. The presentation does look like a step up from iOS and Android, though, if only because it departs slightly from the touch vocabulary that has become established on the leading platforms.

"We're taking our time to make sure we get this right," he told the audience, which is probably a good thing - patience with RIM is already running out and the company can't afford another PlayBook.

RIM probably has one roll of the dice left to avoid becoming an acquisition, holding the bones a little longer is therefore the right thing to do even if it disappoints those waiting to see how they fall. ®

Java jury finds Google guilty of infringement: Now what?

Analysis No judge has tried harder than Judge Alsup, presiding over the Oracle-versus-Google case, to persuade two warring parties not to go to court. But he hadn't counted for the egos of the two billionaire Larrys.

The jury seems to affirm Alsup's instincts were correct. At the weekend, after five days of deliberating, the panel turned in its verdict on the first phase of the trial, covering copyright issues. The jury found Google to be unequivocally guilty of copyright infringement on the major charge, copying the "overall structure, sequence and organization" of Java for its mobile operating system Android. Google isn't guilty of infringing the Java documentation, the jury decided.

However, the jury was unable to reach a verdict on whether Google's use of the code was permitted under "fair use" - a US legal concept covering exemptions for special purposes such as literary criticism, accessibility for blind users, and so on.

Fair use has expanded to include very limited clean-room copying for compatibility purposes, and Google tried to use this to justify the use of Java APIs in Android. However, Alsup didn't like this argument, and so when some jury members wanted more time for their deliberations, the judge allowed them to leave the question blank.

Oracle, which had sought $1bn in damages, welcomed the interim verdict: "Google knew it needed a licence and … its unauthorised fork of Java in Android shattered Java's write-once-run-anywhere principle." Google wants a retrial. "The core issue is whether the APIs are copyrightable, and that's for the court to decide," the company said.

It's not as clear cut as either side would have you believe.

Google only appeared to realise late in the day that there could be collateral damage - giving it a small patch of moral high ground to claim. Defeat could potentially allow an extension of copyright into previously undisputed areas, such as programming languages and APIs.

For two years, much of the tech press has reported the skirmish as a patent dispute, perhaps not surprisingly as the initial fusillade from Oracle alleged infringement of seven patents. But as we noted at the time, "this is no simple dispute over the violation of patents, though". Oracle alleged code was copied, and what could be copied became fairly central to Oracle's case.

For its part, Oracle has presented damning and unequivocal evidence that Google knew it needed a licence if it was to build Android on Java, but it didn't negotiate one figuring it would face the consequences if and when they came.

But Sun's management during the 2005-2009 period, embodied in the catastrophic appearance of former Sun CEO Jonathan Schwartz at the trial, gave Google every comfort that the judgement day would never come. Schwartz, who had authorised millions of dollars to be spent on a happy-clappy "participation economy" ad campaign, welcomed on his blog Google's copying and fragmentation; hostile litigation didn't start until long after Oracle had acquired Sun and bundled Schwartz out of the door. That may have been enough to temper the damage Oracle wanted to prove.

Ultimately, it's Judge Alsup who will decide on whether he considers APIs to be copyrightable in this instance - and on whether Google's copying can be covered by fair use. The case is unusual, and troublesome for the entire software industry, because Java itself is quite unusual. It's a hairball (as former CEO Scott McNealy might put it) of many things: a runtime, a language, frameworks using that language, compatibility tests, and documentation. A precedent appropriate to Java may be used inappropriately elsewhere.

Potentially, the effects could be severely disruptive. Could IBM reclaim ownership of SQL, and for that matter, markup languages such as HTML - which are all descended from work originating at Big Blue? Or is Java such a singular case, that only extensively derivative copies, such as Android's implementation, could be contested? If those IBM examples sound absurd, then remember that absurdity is no obstacle to a determined litigant. Demanding royalties from ISPs for the use of HTML hyperlinks was pretty absurd, too.

Contrary to some reports, the situation remains ambiguous. Europe effectively threw the issue back to national courts to apply some common sense to the issue. "It is only through the choice, sequence and combination of those words, figures or mathematical concepts that the author expresses his creativity in an original manner," the European Court of Justice affirmed. Nobody wants to set a precedent.

The copyrighting APIs and languages is a Pandora's Box - and the trouble with a Pandora's Box is that nobody knows what's inside. ®

Atlassian warns of critical security flaw

Confluence customers urged to upgrade

By Simon Sharwood, APAC Editor • Get more from this author

Posted in Security, 18th May 2012 06:50 GMT

WIN - A free one year, 25 user licence of Microsoft Office 365!

Atlassian has warned of a critical security flaw in its Confluence product.

All versions of Confluence up to and including 4.1.9 are at risk, the company says, thanks to what it calls an “XML parsing vulnerability” that could lead to “denial of service attacks against the Confluence server” or allow intruders to “read all local files readable to the system user under which Confluence runs.”

Atlassian has provided fixes for all major versions of Confluence that are supported – 3.5.x, 4.0.x and 4.1.x. Hence, customers do not have to upgrade to 4.2 to fix the vulnerability.

Atlassian has posted a mitigation procedure, but warns the actions it recommends “will only limit the impact of the vulnerability … not mitigate it completely.” ®

WIN - A free one year, 25 user licence of Microsoft Office 365!

Microsoft ejects DVD playback from Windows 8

Digital media playback in Windows 8 has fallen casualty to the savage economics of the PC industry and changing tastes in consumer viewing.

We knew Windows Media Center would be sold at extra cost in Windows 8, but Microsoft now says you won’t be able to play DVDs on Windows Media Player in Windows 8.

If you do want DVD playback, then it’ll be a case of shopping judiciously and picking a PC whose manufacturer has licensed the codecs from a third party.

The twist? Windows 8 customers will end up paying more than others, as PC makers will likely be compelled to license the required codecs themselves to enable DVD playback.

In the latest Windows 8 blog, Microsoft said:

Windows Media Player will continue to be available in all editions, but without DVD playback support. For optical discs playback on new Windows 8 devices, we are going to rely on the many quality solutions on the market, which provide great experiences for both DVD and Blu-ray.

The development came as Microsoft separately announced a deal to use audio playback technology from Dolby in Windows 8. Microsoft will include Dolby Digital Plus 5.1 channel decoding and two-channel encoding in Windows 8.

To use this technology in their machines, PC makers will have to pay Dolby licensing and royalties.

What’s going on is an attempt to pare the costs of PCs and keep down the price and maximise the margins. In its blog post Microsoft didn’t say why it’s killing the Windows Media’s ability to play DVDs, but overall the blog talks about the broader decision to make Media Player available as a separate addition at extra cost.

Price is one factor: vendors will be looking to avoid the need to license codec decoders on all machines. The idea is only a small market would want DVD-ready PCs. The irony is Microsoft is one of the planet's biggest licensees of media codecs, with Apple and others behind H.264 for video compression licensed through MPEG-LA. H.264 is used in Windows Media Player.

There was a time when such licensing costs could have been lost in the cracks, but that time has passed. One factor is that the internet is killing DVD: “The vast majority” of video consumption on the PC and other mobile devices is coming from online sources such as YouTube, Hulu and Netflix, Microsoft says.

Another factor is margin: on the reseller front, companies could make 30 per cent on a PC at the dawn of the PC revolution in the mid-1980s by convincing happy shoppers to spring for peripherals and consumables (printer and ink cartridges) with their new machines. However, margins today hover between 3 and 5 per cent. ®

Skype slurping software threatens IP exposure

Code posted online that can skim the last known IP address of users is being checked out by Skype as a possible security flaw.

The software, posted on Pastebin, works on a patched version of Skype 5.5 and involves adding a few registry keys that allow the attacker to check the IP address of users currently online without calling them. Services like Whois will then give some other details on the city, country, internet provider and/or the internal IP-address of the target.

"I've tested this and it does what it says on the tin," blogged Nick Furneaux, MD of security researchers CSITech. "I was able to extract the external and internal IP's of a friend in the US to within a few miles of his house, a buddy in Asia to within a few streets and my own to just a few miles down the road. More concerningly the internal IP combined with the internet facing address provides the basis for a direct probe and then attack of any individual on Skype's global address book."

He said a website had been set up to provide an easier way to exploit the IP tracking but that it hadn't yet been checked out for malware. The site is down at present.

Before everyone panics, it is not clear if the problem affects the current corporate build of Skype or just the deobfuscated build mentioned in the posting. Skype, and presumably Microsoft given the amount of integration Redmond is planning with its code base, are no doubt hoping it's the latter situation. In any case, simply turning off the software when you're not using it minimizes any threat window.

"We are investigating reports of a new tool that captures a Skype user’s last known IP address," Adrian Asher, director of product security at Skype told El Reg in an emailed statement. "This is an ongoing, industry-wide issue faced by all peer-to-peer software companies. We are committed to the safety and security of our customers and we are taking measures to help protect them." ®

Chrome beats IE for a weekend

Google creeps up on leisure time browsing crown

By Simon Sharwood, APAC Editor • Get more from this author

Posted in Software, 8th May 2012 05:56 GMT

WIN - A free one year, 25 user licence of Microsoft Office 365!

Fresh from knocking off Microsoft's Internet Explorer as the web's most-used browser for a single day in March, Google's Chrome browser has now claimed more users than Redmond's HTML-cruncher for a whole weekend.

Data gathered by StatCounter shows Chrome has enjoyed a day of dominance on most weekends since its March ascendancy. On May 5th and 6th, however, it opened a gap over IE. Sunday the 6th even saw Chrome take a lead of nearly three percent.

Chrome beats IE for a whole weekend

IE still rules on weekdays, when use of the browser surges, presumably thanks to corporate drones diligent workers returning to the locked-down world of enterprise IT. But IE's days as the market leader may even be numbered in those environments, as Microsoft has recently announced SharePoint and Microsoft CRM will support other browsers. That move will mean workplaces have fewer reasons to insist on IE as the corporate standard. ®

WIN - A free one year, 25 user licence of Microsoft Office 365!

Mozilla and Google blast IE-only Windows on ARM

Mozilla and Google are crying foul over Microsoft restrictions blocking rivals from Windows 8 on ARM, due later this year.

Firefox-shop Mozilla has branded Microsoft's restrictions a return to the digital dark ages "where users and developers didn't have browser choices".

Harvey Anderson, Mozilla general counsel, accused Microsoft of restricting user choice, reducing competition and chilling innovation by only allowing Internet Explorer to run on Windows RT – unveiled last month by Microsoft as the new name for Windows on ARM (WOA). He said:

Only Internet Explorer will be able to perform many of the advanced computing functions vital to modern browsers in terms of speed, stability, and security to which users have grown accustomed. Given that IE can run in Windows on ARM, there is no technical reason to conclude other browsers can't do the same.

Mozilla Firefox director Asa Dotzler has weighed in with the technical argument:

On ARM chips, Microsoft gives IE access special APIs absolutely necessary for building a modern browser that it won't give to other browsers so there's no way another browser can possibly compete with IE in terms of features or performance.

Anderson and Dotzler said this violated a 2006 statement of principles (PDF) by Microsoft on choice, opportunity and interoperability, and are calling on Microsoft to live up to these principles.

Chrome-maker Google has thrown its weight behind Mozilla. In a statement to The Reg, a spokesperson said the search giant shared Mozilla's concerns about Windows 8's restrictions of user choice and competition.

Google's spokesperson said:

We've always welcomed innovation in the browser space across all platforms and strongly believe that having great competitors makes us all work harder. In the end, consumers and developers benefit the most from robust competition.

Microsoft's decision to lock down Win RT is not news: introduced as WOA in February, Windows chief Steven Sinofsky said WOA would only support a small number of existing Microsoft apps – Word, Excel, PowerPoint and OneNote with Internet Explorer 10. x86 apps would not run on WOA. WOA would be populated with apps via the Windows Store.

The reason for this was simple and came down to chipset and interface: ARM doesn't support native x86 apps while Windows 8 introduces the tiled and touch-based Metro UI.

For this reason, Microsoft has three development scenarios for Windows 8: Classic - Windows 7-style 32-bit APIs that won't work with Metro; Metro that lives in a sandboxed environment; and "Metro-style enabled" desktop apps that straddle Classic and Metro and call both sets of APIs.

Back in March, Mozilla said it would build a version of Firefox in this third category, with the same system-level parity as IE10, built using traditional Win32 calls and the Windows Runtime WinRT framework that Microsoft has devised for building Windows 8 Metro apps.

At the time Dotzler said: "We should be able to build a single product, that when installed into the Classic environment via traditional means – a download from www.mozilla.org – will be able to become both the default browser in the Classic environment and in the new Metro environment."

At the same time we at The Reg said while this sounded fine in theory, the two big questions would be whether Microsoft would actually permit rivals' browsers to install as the default on Windows 8 and whether Mozilla's work could be transferred to ARM.

Between then and now an answer has been delivered, and it seems this was the catalyst for Mozilla's outburst. In a report here, Anderson says senior Microsoft lawyer David Heiner told him other browsers would not be allowed on ARM. Whether this is a technical or political choice is unclear, although Anderson's implication is there are no technical hurdles.

Dotzler, who had been upbeat in March, now says:

Microsoft has made it clear that the third category won't exist on Windows for ARM (unless you're Microsoft) and that neither will the first category (unless you're Microsoft.) That means that IE on ARM has access to win32 APIs – even when it's running in Metro mode, but no other Metro browser has that same access. Without that access, no other browser has a prayer of being competitive with IE.

Microsoft supporters may dismiss Mozilla and Google, and feel that Redmond is being given a hard time over openness and freedom to install software while others, mainly Apple, enjoy a free pass; Apple also only allows one native browser on its platform for tablets and phones: its own, Safari.

Mozilla, however, feels frustrated because it sees a potential market slipping away by not getting Firefox on Windows RT. ARM dominates smartphones and while it's tiny in tablets today, it has big growth plans. This is the market Mozilla fears losing out on should it expand.

That said, Windows RT is unproven and little known commodity, so there's no telling how successful it will actually be beyond Microsoft's own infectious predictions – that Windows on ARM is its riskiest bet and biggest change in 30 years. We don't know what devices will run Windows RT – although we imagine it will be ereaders; how many types of device there will be; or how they will stand up to the competition from Apple or Amazon.

Microsoft was unable to comment at the time of going to press.®

Google Knowledge Graph straddles semantic web and <i>Star Trek</i>

Google’s battle to retain search supremacy is seeing it roll something it claims will take us closer to the "computers of Star Trek".

Google has unveiled The Knowledge Graph, which it claims will give you the answers you really want, we presume instead of a bunch of useless blogs, blue links or message fragments from Wikipedia.

Rollout of the Knowledge Graph has started for US English users and will be tailored to work and display on the limited screen space of smartphones and tablets.

This is more than the standard moving about of the bits around the screen or feeding in of crowd-surfed results from Twitter or Facebook, as Google and Microsoft (with its Bing search engine), have been doing in their attempts to outdo each other in recent years.

Amit Singhal, senior vice president of engineering, reckoned Google has studied in aggregate what users have been asking Google about, to gain a better understanding of what questions are asked and the way they are being phrased.

This might mean answers can be returned even when the question is typed or phrased incorrectly and that Google will present the returns cleanly. Web-watchers already have a name for this - they call it the “the semantic web” – which drills into unstructured data to make it categorisable and searchable.

Also, Singhal said, Google has worked on its algorithms so that they can determine the relationship between “things” – again ensuring relevant data is pulled back.

On this latter point, the social graph has its roots in that other great graph of Web 2.0 – the social graph used by social networks such as Facebook and LinkedIn.

These sift personal data and posts to link you to other people that you know and build up a comprehensive map of people. The CIA does a similar type of online digital matching to find terrorists and their unknown associates.

Singhal said: ”We’ve always believed that the perfect search engine should understand exactly what you mean and give you back exactly what you want.”

He closed: “We hope this added intelligence will give you a more complete picture of your interest, provide smarter search results, and pique your curiosity on new topics. We’re proud of our first baby step — the Knowledge Graph — which will enable us to make search more intelligent, moving us closer to the ‘Star Trek computer’ that I've always dreamt of building.“

It’s a grand claim and something that will get consumer tech titles and news organisations very excited, which is probably just what Google wants.

The search giant's forays outside its core market haven’t gone so well – Google Wave and Google+ being good examples – and Google killed off its Labs projects. It now sounds like the company is trying to recapture the intellectual high ground in an area where it remains strong by doing something it has already tried: improving the basic search and return process to see off Bing.

Only now it has a piece of marketing shorthand to bandy about Silicon Valley while it does this. ®

Now India snaps on gloves, bends Google over for antitrust probe

Google is undergoing an antitrust investigation in India, the Competition Commission (CCI) in that country confirmed on Monday.

The Economic Times, citing sources, reported over the weekend that the CCI was readying a competition inquiry into the search giant's "alleged discriminatory practices" relating to its AdWords business.

According to that news story, an investigation was ordered following the discovery of "prima facie evidence" that allegedly showed Google had abused its dominant market position by selling advertising keywords related to dating website Bharatmatrimony.com to the site's rivals.

"We have asked the Director General (Investigations) to complete the probe and give a report on it within 60 days. Prima facie, we found evidence that suggests that Google did abuse its dominant market position," a senior official at CCI reportedly said.

A complaint was filed with the commission by the India-based match-making website in February this year.

The AFP reported yesterday that CCI's secretary S.L. Bunker had said that the investigation would last "at least a couple of months". He added that the commission was probing the claims to see if they could be substantiated.

A separate probe into Google's business practices is already underway in the country. That inquiry is looking at claims that Mountain View may have breached domestic foreign exchange transactions regulations.

Google gave The Register this statement:

Though competition is always a click away, we understand that with success comes scrutiny. We have not received any communication from the CCI, but we're always happy to answer questions about our business, and we're confident that our products are compliant with competition law in India.

Google is getting use to regulatory scrutiny around the world as more and more companies gripe about the world's largest ad broker's business practices.

In June last year the US Federal Trade Commission formally began probing allegations that Google favours its own search products over those of its rivals. A similar but separate investigation into Google's actions has been ongoing in Brussels since November 2010, but, as we reported late last month, regulators in Europe are yet to conclude on their findings.

The European Commission confirmed to El Reg that it had once again delayed its response to just before the EU's summer break. Regulatory pressure is piling up for Google, but responses from individual watchdogs remain months away. ®

Apple updates iOS, mum on Wi-Fi, battery fixes

Apple has released an update to its iOS mobile operating system, version 5.1.1, which it claims remove some bugs and improves reliability of some options, but which does not address the wireless connectivity problems – well, at least not overtly – that have had some fanbois fuming.

The update, released Monday, is for the iPhone 3GS and later, the third and fourth-generation iPod touch, and the iPad and iPad 2 – presumably by "iPad", Apple means both the original iPad and the third-generation iPad, aka "The new iPad".

According to Apple's release notes, the update includes the following:

iOS 5.1.1 update information

There may be other fixes in iOS 5.1.1, but these are the ones that Apple wants to tell you about

Not included among the listed fixes, you'll notice, are any references to battery-life or Wi-Fi connectivity upgrades – two items that have caused consternation among purchasers of the third-generation iPad.

One bit of advice: if you should choose to upgrade your iDevice to iOS 5.1.1, don't do it through iTunes, but instead download it from your device itself at Settings > General > Software Update. The 5.1.1 update's iTunes-download file size for our first-generation iPad was 726.1MB; downloading it using the iPad's Software Update function was a svelte 42.3MB.

Three cheers for incremental upgrades, new in iOS 5 – though clearly not yet available through iTunes. ®

Nvidia launches Nsight CUDA dev tools into Eclipse

GTC 2012 Nvidia kicked off its GPU Technical Conference today by launching an updated version of its Nsight development platform that wraps around the CUDA compiler set and now interfaces with Eclipse-based integrated development environments.

Nvidia also unwrapped updated versions of the Nsight tools that plug into Microsoft's Visual Studio IDE, at the shindig in San Jose, California.

Nvidia obviously wants for graphics and HPC application developers to have an easier time coding on its GPUs and GPU coprocessors. Back in July 2010 the company rolled up a bunch of tools for GPU computing and graphics processing that were available individually and made a plug-in to hook them into the Visual Studio 2008 IDE to make it a snap for programmers working from the Windows environment to dispatch work to GPUs.

Parallel Nsight Standard Edition 1.0, as the original stack was called, included a graphics debugger and a graphics inspector. The graphics debugger could debug Microsoft's HLSL graphics shading language right on the GPU as it is running, and could also examine how shaders were executing in parallel on the GPU. The graphics inspector did real-time examination of DirectX calls and monitored the the GPU pipeline state as applications step through their code. It also had a pixel history function to show how each operation in the application affects any pixel on the screen.

With the Professional Edition, Nvidia tossed in a parallel debugger for compute - you can debug right on the GPUs and look at thousands of threads executing in parallel at the same time and use conditional breakpoints to fix their bugs. A system analyzer was also in this edition of the Nsight tool, which showed what instructions are executing in both the CPUs and GPUs on a timeline as applications run. Professional Edition cost $349 per seat while Standard Edition was free. Both ran on Windows XP, Vista, and 7 desktops, now support Visual Studio 2008 and 2010, and hook into GeForce and Quadro discrete graphics cards and Tesla GPU coprocessors.

Now, with the 2.2 release announced today, Nvidia has thrown all of the Parallel Nsight features into one pot (no more editions) and has made plug-ins available for both Visual Studio and Eclipse IDEs while at the same time branding the toolkit just Nsight. There are two editions: one for Visual Studio and one for Eclipse.

The Eclipse edition lets coders working from Linux and MacOS environments integrate with these debuggers and analyzers and hook into the CUDA compiler stack for GPU applications.

With the updated release, Nvidia is adding automatic code refactoring, which converts sequential CPU loops automatically into GPU kernels where they can execute in parallel on the GPUs. Nvidia is also adding in syntax highlighting and autocompletion for both CPU and GPU code (pity it can't just write all the code, eh?) and an expert code analysis system that can help programmers deal with bottlenecks in their hybrid CPU-GPU applications. The Eclipse edition makes use of the CUDA 5 toolkit, which is still in preview and which includes Nvidia's own C and C++ compilers.

With Nsight Visual Studio Edition, Nvidia is now allowing you to debug code on a single GPU. Before, you needed to have one GPU to run the code and one GPU to run the debugger and analysis tools. Now, if you have the CUDA 1.1 or higher compiler stack, you can get by with one GPU, which saves you dough and hassle.

Nvidia is also boosting the performance for the frame profiler and debugger, and supporting DirectX 9 frame debugging, frame profiling, and analysis. The Visual Studio Edition 2.2 also supports the CUDA 4.2 compiler stack and the new "Kepler" GPUs, too, which began their rollout in the GeForce graphics chips in March.

Nvidia is giving freebie versions of the Nsight tools away to coders that become registered developers; it was not clear at press time if Nvidia is charging coders that don't register if they want to use the tools with their Eclipse or Visual Studio IDEs. But Nvidia confirmed from the floor of the GPU Tech Conference that the tools are now free and that it has created only one edition of the Eclipse and Visual Studio tool stacks. You can download the Visual Studio Edition here and the Eclipse edition there. ®

Solving traffic jams with maths

A Swiss traffic management and transport economics expert believes a combination of queue management and computing can help solve the gridlock that plagues the modern city.

Dr Dirk Helbing of ETH Zurich, a professor of sociology specializing in modeling and simulation, says “self organizing” traffic control systems, using massively parallel, decentralized control, are needed to avoid gridlocks. The problem, he told Tages Anzeiger (in German) is the inflexibility of current traffic control systems.

Today’s designs over-generalize: traffic lights are phased for typical behavior for a particular time of day (and day of week), and cope badly with anything unexpected. As a result, traffic lights have no response to an accident at an intersection; the previous set of lights will continue allowing traffic into an already-congested section of road, and eventually, the congestion feeds back into the rest of the road network.

Instead of typical queues, Dr Helbing says, the system is suddenly asked to cope with “extremely varied” queues.

Using sensors to measure variables like the amount of traffic already in a road section, how quickly it is moving, and how long to the next change of lights, Dr Helbing’s approach is designed to respond to unexpected events.

For example, the system would detect that traffic on one section of road is slowing down or has stopped, and divert it to alternate routes to prevent the backfill causing gridlock.

Dr Helbing told Tages Anzeiger that the mathematical modeling needed to represent such complex systems was “my most difficult trial”.

While lobbying Zurich to trial the system, Dr Helbing says the city of Dresden in Germany has already taken the plunge, and is about to launch a trial. ®

Microsoft makes good with a 23-fix Patch Tuesday

Busy Wednesday for BOFH

By Iain Thomson in San Francisco • Get more from this author

Posted in Security, 9th May 2012 00:48 GMT

WIN - A free one year, 25 user licence of Microsoft Office 365!

It'll be all hands to the pumps in IT departments around the globe as Microsoft has issued this month's round of patches. There are 23 flaws to be fixed.

The seven patches include three critical issues, affecting Microsoft Windows, Office, Silverlight, and the .NET Framework. One patch, MS12-034, sorts ten flaws, some of which are publicly disclosed.

“Duqu was only designed to exploit specific instances of CVE-2011-3402 that were addressed last year. We have not received any information to indicate that the attack vectors addressed in bulletin MS12-034 have been publicly used to attack customers,” said Yunsun Wee, director of Trustworthy Computing at Microsoft.

Microsoft's second highest priority if a critical flaw in Word that allows remote code execution from malware accessed via email and websites. One exploit is in the wild but doesn't give admin access, and Office 2010 users don't need to fix this. ®

WIN - A free one year, 25 user licence of Microsoft Office 365!

BlackBerry 10 developer kit aims to unleash application tsunami

RIM has marked the start of its BlackBerry World conference by announcing the release of the developer kit for the much-delayed BlackBerry 10 operating system and handing out crippled prototype handsets that should go on sale by the end of the year.

"We’re extremely excited to release the BlackBerry 10 developer beta tools for general use,” said Christopher Smith, VP of handheld application platform and tools at RIM. “Developers can use this first beta of the tools to get started building apps for BlackBerry 10 and as the tools evolve over the coming months, developers will have access to a rich API set that will allow them to build even more integrated apps."

The download includes BlackBerry 10 Native SDK with Cascades that can handle C++ or QML code. A WebWorks SDK is included for HTML 5 and CSS development, with JavaScript bindings built in, and there's a beta version of a plug-in to allow limited Visual Studio development. The initial API bundle includes push management controls, payment systems, LED and battery control, and some gaming features.

The point of all this is to get a whole host of applications ready to go when the final hardware carrying the new operating system is released, hopefully by the end of the year for the crucial fourth quarter sales peak. RIM seems to have recognized that the lack of apps is a major turnoff for customers and is hoping the 2,000 developers attending the conference in Orlando can rectify that.

Attendees also were also given a BlackBerry 10 Dev Alpha handset to play with, although it's not capable of voice calls as yet (Wi-Fi and Bluetooth only) and uses a stripped down PlayBook GUI that should be changed before the final release. The handset comes with a 4.2-inch screen (larger than the iPhone 4S's 3.5 inches) capable of 1280×768 resolution, along with 1GB of RAM and 16GB of storage.

The hardware keyboard, a feature much beloved by many existing BlackBerry users, has been replaced with a software version and a new style of typing that uses predictive text and swiping motions to speed up wordage, as shown in the traditional promo video.

These devices are very much prototype designs, and look more like a PlayBook that has shrunk in the wash rather than a final product. But RIM is hoping there's enough there to get developers started, and hinted that the final screen resolution may stand, which visually would make the devices stand out. Whether they are desirable enough to tempt people for their Jesusphones is another thing entirely.

The company is also eyeing the Asian market, with a coding initiative designed to get Chinese university students writing applications for the platform. It will be distributing code and handsets to several universities and looking to find the best applications for the automotive and "mobility lifestyle" markets. ®

Google's latest webspam crusade 'breaks' search results

Google's latest search engine algorithm update – dubbed Penguin – is proving to be something of a dud, according to website owners not happy with the latest tweak.

The Chocolate Factory debuted its latest search engine optimisation (SEO) change last week, at which point its engineer Matt Cutts penned a blog post explaining the latest update.

He said Google, this time, was targeting webspam. The update is the latest tweak to Panda - the company's controversial search results ranking algorithm that the ad giant claimed had been designed to bury "low-quality sites" on its search engine.

Google's Panda and Penguin love. Pic credit: Matt Cutts

"I've been in SEO for 10 years and this is the worst update in Google's history. I've been tracking results in the 'vision improvement' niche for many years," said one narked-off website owner using the handle MarkMark5 on the TrafficPlanet.com forum.

He went on to use the example of the search query "repair vision" on Google, which returned completely irrelevant results including an outdated article and another page that displayed no content whatsoever.

An online petition has already been created by webmasters who are unhappy with the Penguin update.

It reads:

With the recent Google Penguin update, it has become nearly impossible for small content based websites to stay competitive with large publishers like eHow, WikiHow, Yahoo Answers and Amazon.

Countless webmasters have seen their livelihoods vanish overnight. In a recent interview, Sergey Brin came out against 'Walled Gardens' of the likes of Facebook... Ironically, the Penguin update has created a similar garden that only admits multimillion dollar publishing platforms.

On [a] personal level, this update has ruined small online businesses, passive incomes and families' livelihoods worldwide.

The petition has so far garnered 285 signatures.

Following the webspam update from Google, Cutts has told web owners via his Twitter account to "report post-Penguin spam" by filling out an online form.

The Register has asked Google to explain what it is doing about the gripes expressed by some webmasters in response to the Penguin update. The company hadn't got back to us at time of writing, however.

The Choc Factory claimed at the launch of Penguin that only 3 per cent of search queries would be affected by the webspam update. ®

Adobe backs down, patches critical Photoshop CS5 hole

Adobe backed down on Friday and promised to release a fix for earlier versions of its Photoshop software after previously insisting users who wanted to safeguard themselves from a critical security vulnerability had to pay for an upgrade.

A security flaw in Adobe Photoshop version CS5 and earlier means users could be exposed to malware providing they were tricked into opening a boobytrapped .TIF file. Adobe's initial response to the discovery of the flaw was an issue an advisory pointing out that users of the latest Adobe Photoshop version CS6 were immune to the cross-platform flaw. The software giant initially declined the issue a security patch for earlier versions of the software on the dubious grounds that because Photoshop "has historically not been a target for attackers", the risk level was supposedly low.

This view was mistaken for several reasons, including the plausibility of possible exploits and the fact that Adobe applications, in general, have become a prime target for hackers over the last two or three years.

Instead of offering a security patch, Adobe initially advised users of earlier versions of Photoshop to "exercise caution" over what files they open with their applications. If that wasn't good enough then an upgrade to Adobe Photoshop CS6 would do the trick, at a cost of $199 (£124) or more. Adobe Photoshop CS6 was only released in early May 2012, just days before the security issue with earlier versions of the product became public knowledge.

Photoshop version CS5.5, released last year, doesn't need to be patched.

Adobe Photoshop version CS5 is around two years old and certainly not a discontinued product. The widely used application remains on sale through various channels.

Adobe Illustrator CS5.5 and earlier, and Adobe Flash Professional CS5.5 (11.5.1.349) and earlier are also vulnerable to the same vulnerability. In each case users were initially advised to upgrade to the CS6 versions of the expensive design product if they wanted security software.

Security watchers wasted little time on heaping scorn on Adobe's stance, arguing that the vendor was abusing its monopoly position and pushing its customers towards choosing between paying for a security upgrade or leaving themselves at greater risk of hacking attacks. They said Adobe was effectively charging paying customers for security fixes.

"Adobe has abdicated this responsibility," Graham Cluley, senior technology consultant at security vendor Sophos argued. "It has found a critical vulnerability — a security flaw in Photoshop CS5 — that puts its users at risk, and instead of fixing it, the company is advertising the fact that there is a problem where the solution is that you pay for an upgrade to Photoshop CS6."

Photoshop users also vented their frustrations on social networking websites.

As late as Friday afternoon, in response to questions from El Reg, Adobe continued to defend its controversial no-patch-for-CS5 stance.

While Adobe did resolve the vulnerabilities addressed in the security bulletin you are referencing below (APSB12-11) in the Adobe Photoshop CS6 major release, no dot release was scheduled or released for Adobe Photoshop CS5.

In looking at all aspects, including the vulnerabilities themselves and the threat landscape, the team did not believe the real-world risk to customers warranted an out-of-band release for the CS5 version to resolve these issues.

The security bulletin for Photoshop is rated as a Priority 3 update, indicating that it is a product that has historically not been a target for attackers, and in this case we are not aware of any exploits targeting any of the issues fixed. Installation of the upgrade is therefore at the user's/administrator's discretion.

Hours later, Adobe performed an abrupt U-turn and promised to issue a fix for Adobe Photoshop version CS5, something it should have done in the first place. Arguments advanced by Adobe last week – that the vulnerability was "theoretical" or that hackers weren't after its software – were shown to be weak and just plain wrong more than 10 years ago, as Microsoft would be able to testify.

Adobe has modified its original 8 May advisory to say it is developing patches for the critical holes in the CS5.x versions of Adobe Photoshop, Adobe Illustrator CS5.x and Adobe Flash Professional CS5.x. It's unclear when these patches will become available.

"Adobe has released Adobe Photoshop CS6 (paid upgrade), which addresses these vulnerabilities," the revised version of the advisory continues to say. "We are in the process of resolving these vulnerabilities in Adobe Photoshop CS5.x, and will update this Security Bulletin once the patch is available." ®

Amazon Cloud Drive updates for Windows and Apple desktop

After a wave of cloud storage announcements, Amazon has updated its Cloud Drive system with a desktop access application for Windows and Apple systems.

Amazon launched its Cloud Drive service a year ago, and it gives users a basic 5GB of storage for music in MP3 or AAC formats, as well as photos, documents, and videos that can be accessed via a web browser. Amazon has now got around to releasing a desktop application for Windows 7 and Vista, with Mac OS 10.6 and above, but it’s a fairly basic affair.

There's nothing in the way of automatic synchronization with local folders, for example, and you can't share files, either. Users can pay extra to bump up their storage allowance, starting at 20GB for $20 a year, with music you buy from Amazon not counting towards your storage allowance.

When put against Google Drive (when it works) or Microsoft and Dropbox's offering it's clear Amazon has some way to go on this one. As El Reg pointed out at Cloud Drive's launch, Amazon doesn't seem quite clear on what it's doing with the product, other than playing catch-up with the companion.

With Apple, Microsoft, and Google all staking out their turf on the cloud storage front, Amazon needs to stay relevant if it's to get the kind of user base it needs to make Cloud Drive an effective driver of business. Based on this code, it needs a lot more development work. ®

How to simulate a light armoured vehicle

The Australian Light Armoured Vehicle (ASLAV) is an eight-wheeled, 13,450-kilogram monster, which bristles with a grenade launcher, a pair of machine guns and a 25 millimetre M242 “Bushmaster” chain gun.

The ASLAV can carry six troops in addition to its three crew. Two of the latter ride inside the vehicle's turret, where the Gunner must be able to aim the Bushmaster in accordance with the instructions of fellow turret-dweller, the Crew Commander.

Australia has a large fleet of ASLAVs – more than 250 are in service – with many currently deployed in places like Afghanistan.

The vehicles get a lot of use, so it makes sense to use simulators for training. Thales Australia built the first nine such machines and has recently been engaged to build another set. When we heard that news, we decided to ask them how they'll do it.

The answers, provided by Tony Landers, Thales Australia’s Director of Business Development - Maritime & Aerospace, are revealing. But not too revealing – in order to write this story we had to agree to vetting by the Australian Department of Defence.

So what did we learn? Well … we expected the simulator would re-create the interior of the ASLAV, which indeed features a mock ammo belt for the Bushmaster and other similarly high-verisimilitude accoutrements.

What we didn't expect was Landers' insight that manufacturers of the various internal fittings of vehicles like the ASLAV now have half an eye on simulation market. Some items in the mocked-up interiors of the simulators are therefore identical to those found in actual vehicles, save for their simulator-ready USB interfaces.

The new simulators will also be joined, for the first time, by a desktop tool that runs on touch screens instead of a mock vehicle.

The Australian Light Armored Vehicle (ASLAV)

An Australian Light Armoured Vehicle

Which is not to say that assembling a simulator is as simple as daisy-chaining a stack of USB hubs: there's still plenty of bespoke electronics work to be done, which Landers explains in the context of the ASLAV's periscope. “We designed optical paths to LCD screens sitting at the end of tube that simulates a periscope,” he explains. “We built all the I/O and control it from the application software on the servers.” A team of nearly 30 spent three years building that kind of thing for the first nine simulators.

That team was helped by a Thales product called SETHI product that simulates a battlefield environment, animating enemies with artificial intelligence while creating a realistic 3D world.

The tricky part of building simulators, Landers says, is not necessarily the hardware or software. Instead, he says “the devil is in the detail, especially understanding the level of fidelity you need to teach the student the task. You could spend a large fortune simulating every element of a device to 100% accuracy, but that might not be required for training. You need to understand training design to understand what to build.”

For the ASLAV simulator, that means a “motion platform” that simulates working in a moving vehicle is not necessary. Students do get haptic feedback from the Bushmaster, but it is not felt that making the simulator rock and roll has a training benefit.

The new generation of simulators will refine the work from the first nine units. An important refinement will only be visible in the server rack that powers the sim. SETHI runs across almost two dozen servers which live in the same shipping container that houses the simulators. Landers said the servers run a mix of Windows and Linux, pack the most powerful graphics cards available at the time of building and house a number of virtual machines. The next-generation design requires just over a dozen servers, a number that has come down thanks to virtualisation.

Next page: The fine art of 'knobology'

Plumbers of the interwebs vow to kill IP hijacking

The Internet Engineering Task Force (IETF) aims to strengthen the basic protocols of the internet, with a way to stop route, or IP, hijacking. IETF experts say the proposed fix is simpler to implement than previous suggestions.

IP hijacking exploits a fundamental weakness of the internet, Data and messages sent across the internet are transmitted via routers, and those routers are blindly trusted. No measures are in place to verify if they have been tampered with to re-direct or intercept traffic.

In 2008, Pakistan Telecom took advantage of this blind trust to send YouTube briefly into a global blackhole. CNET's Declan McCullagh wrote at the time:

By accident or design, the company broadcast instructions worldwide claiming to be the legitimate destination for anyone trying to reach YouTube's range of Internet addresses.

The security weakness lies in why those false instructions, which took YouTube offline for two hours on Sunday, were believed by routers around the globe. That's because Hong Kong-based PCCW, which provides the Internet link to Pakistan Telecom, did not stop the misleading broadcast - which is what most large providers in the United States and Europe do.

The same fundamental weakness in BGP (Border Gateway Protocol), a core routing protocol that maps preferred paths for traffic to flow over the internet, was used to hijack the network at the Defcon hacker conference in Las Vegas in 2008. Everything looked the same to delegates after the hijack, but all unencrypted traffic sent over the network was open to wiretapping.

In 2010, China Telecom rerouted up to 15 per cent of the world's internet destinations on two brief occasions, using false BGP route information to direct traffic through its own networks.

The hijackings sparked a security scare in the US. Even without the China dimension, America's dismay is understandable:

The [April 8] hijacking, which lasted 18 minutes, affected email and web traffic traveling to and from .gov and .mil domains, including those for the US Senate, four branches of the military, the office of the secretary of defense, and NASA, among other US governmental agencies, according to the report. It also affected traffic for large businesses, including Dell, IBM, Microsoft and Yahoo.

Similar tricks might be used to steal corporate communications, without leaving a trace or even, at least theoretically, making entire countries unreachable via IP communications. BGP has no built-in security. Routers might accept bogus routes from peers, internet exchanges or transit suppliers. Dodgy routers, however accepted, can have local, regional or global effects.

"Someone can advertise your address space and a route to get there and routers don't know any better," explained Joe Gersch of Secure64, a Domain Name System vendor. "They are just looking for the shortest path."

"It doesn't necessarily have to be malicious for something to go wrong. It could be accidental. Admins could type something wrong into router and this information would still propagate."

The issue has been known for about 10 years but previous attempts to find a fix floundered because proposed solutions were too complex or too expensive, Gersch says. More recently, governments have taken greater interest in the issue, increasing the pressure to find a fix.

At an IETF meeting in Paris last month, a working group proposed a solution that seeks to safeguard the integrity of networking kit.

The proposal involves publishing preferred routes to sites in DNS records before applying a second step, using utilities to verify that the instructions are trustworthy.

This latter step would use DNSSEC, or DNS Security Extensions, a separate security mechanism which is gradually rolling out as a defence against cache-poisoning attacks.

The whole scheme is called ROVER, or BGP Route Origin Verification (via DNS).

Rover calls for the use of reverse DNS records to periodically publish route announcements, a process that would be done by sites themselves, before carrying out real-time verifications of BGP route announcements.

Rover uses "best effort" data retrieval with worldwide data distribution, redundancy and local caching. If the data is unreachable, the default is that routing would proceed as normal but without any checks.

Gersch said the working group (the Secure Inter-domain Routing Group, of which he is a member) believes the proposed approach has the potential to succeed because of its simplicity, in contrast with other ideas such as BGPSec or RPKI.

"Rover is a simpler method to publish your authoritative data," Gersch explained. "I own it, and you can look it up. The process can be automated."

Gersch described Rover as an "enabling technology". Preliminary discussions have already been held with members of Cisco's secure networking group on how to interface the technology with routers.

Several early adopter telcos and ISPs are in the process of publishing route origins in their reverse DNS and signing with DNSSEC. In addition, Secure64 has established a Rover Testbed available at "rover.secure64.com" (registration required).

Deployment of Rover is simple, as no changes need be made to existing routers, IOS or policies, according to backers of the technology. The system builds on DNSSEC, which firms ought to be deploying anyway – although in practice roll-out have been slow.

The Secure Inter-domain Routing Group at the IETF has worked on alternatives to Rover such as BGPSec and RPKI for at least six years.

"Rover uses something that's already there, DNSSEC crypto keys, rather than having to build out a new system," Gersch explained.

"All the ideas for preventing IP hijacking are proceeding forward. The systems can co-exist but I still expect there will be a fierce debate over which is best," he added. ®

Security bug stalls new dot-word TLD land grab AGAIN

Domain name overlord ICANN has been forced to delay its new top-level domain (TLD) expansion by another week as its techies attempt to analyse the fallout of an embarrassing security vulnerability.

Its TLD Application System (TAS), which companies worldwide have been using since January to confidentially apply for gTLDs such as .gay, .london and .blog, has now been down for 10 days due to a bug that enabled some applicants to see information belonging to others.

While ICANN maintains that it has fixed the problem, it now says that it needs at least another week to sift through its mountains of TAS logs, in order to figure out which applicants' data was visible to which other applicants.

ICANN had been receiving reports about the bug since at least 19 March, but only pulled the plug on 12 April, just 12 hours before the final application submission deadline, when it realised how serious the problem could be.

It initially hoped to get the system back up and running by 17 April, but when that deadline passed it then promised to give users an update on the timing by Friday 20 April.

However, that update, which arrived over the weekend, merely promised to provide yet another update before the end of Friday 27 April.

"No later than 27 April 2012 we will provide an update on the reopening of the system and the publication of the applied-for new domain names," chief operating officer Akram Atallah said.

While ICANN is declining interview requests from the media, it did publish a video interview between its head of media relations and chief security officer Jeff "The Dark Tangent" Moss on Friday, which explained some of the technical details of the vulnerability.

"Under certain circumstances that were hard to replicate users that had previously deleted files could end up seeing file names of users that had uploaded a file," Moss said. "Certain data was being revealed to users that were not seeking data, it was just showing up on their screen."

Moss confirmed that no outside attackers had access to data, and that the contents of the compromised files were not accessible by anyone but the applicant to which they belonged.

Nevertheless, the file names themselves could have proven valuable. Most gTLD applications have been filed secretly, without public announcement, in order to reduce the risk of competing applications being filed for the same strings.

Due to the way ICANN's new gTLD programme is structured, a "contention set" of two or more conflicting applications could wind up in an auction. This has pressed the need for confidentiality on most applicants.

Because many companies uploaded files to TAS named after the gTLD string being applied for, confidential information may therefore have been compromised.

While no claims of foul play have yet been made, ICANN is promising to fully disclose – at least to the applicants themselves – whose data was viewable by whom.

"We’re putting everyone on notice: we know what file names and user names were displayed to what people who were logged in and when," Moss said. "We want to do this very publicly because we want to prevent any monkey business. We are able to reconstruct what file names and user names were displayed."

The delay in reopening TAS has not been well-received by some applicants.

"My advice to ICANN now: get your skates on!" said Stephane Van Gelder, general manager of the domain name registrar Indom, in an editorial on CircleID.

"Stop faffing about trying to verify every single bit of applicant data that may have been impacted by the glitch," Van Gelder, who is also chair of ICANN's influential GNSO Council policy body, added. "ICANN's next update... should be: 'in the interest of getting the new gTLD program back on track, we've decided to restart TAS now.'"

The organisation currently plans to reopen TAS for five business days before the final filing deadline, which now appears to mean 4 May at the earliest – 20 days late. As a consequence, its planned 30 April Reveal Day, when it publishes the applications for public comment, has been postponed. ®

Ofcom probes Sky News over Canoe man email hacks

Broadcaster Sky News is being investigated by Ofcom over its admission that it hacked into emails for a story in 2008.

"Ofcom is investigating the fairness and privacy issues raised by Sky News' statement that it had accessed without prior authorisation private email accounts during the course of its news investigations," the regulator said in an emailed statement.

"We will make the outcome known in due course."

Following a Guardian newspaper article, Sky News released a statement at the start of this month acknowledging the computer invasion, but claiming that the intrusion had been justified as it was "in the public interest" and that the hacking had led to criminal charges being brought.

The emails in question were those of "canoe man" John Darwin, who disappeared in a canoe on the North Sea in 2002. Darwin faked his own death so that his wife could claim his life insurance money and pensions, staying hidden until he turned up five years later pretending he'd had amnesia.

"The police described material supplied by Sky News as pivotal to the case," the broadcaster said in its statement. "Mrs Darwin received a jail sentence of six-and-a-half years. More than £500,000 of assets have since been recovered and funds returned to the insurance companies and pension funds which were victims of the fraud."

The Guardian article also mentioned a second case of computer hacking, this time while investigating a man and woman suspected of paedophilia. There wasn't any story published after that investigation and Sky News didn't mention that hack in its statement.

Today, Sky News reiterated its stance on the hacking.

“As the head of Sky News, John Ryley, said earlier this month, we stand by these actions as editorially justified," a spokesperson said in an emailed statement.

"The Crown Prosecution Service acknowledges that there are rare occasions where it is justified for a journalist to commit an offence in the public interest.

"The Director of Public Prosecutions Kier Starmer told the Leveson inquiry that 'considerable public interest weight' is given to journalistic conduct which discloses that a criminal offence has been committed and/or concealed.”

The question for Ofcom will be its interpretation of Rule 8.1, which states that "any infringement of privacy in programmes... must be warranted".

The courts usually allow for invasions of privacy by journalists where the information sought is "in the public interest", which was often interpreted as anything anyone might be interested in, although the widespread phone-hacking scandal has seen a lot of criticism for legal leniency with the media.

However, written into that rule as an example of the public interest is "revealing or detecting a crime", which is exactly what Sky News claims it was doing.

It's still bad timing for parent BSkyB however, as the media giant is currently being assessed as to whether its owners and directors are fit to own a broadcast licence. BSkyB is of course 39 per cent owned by Rupert Murdoch, whose newspaper empire is at the centre of the phone-hacking scandal. ®

UK biz pays heavy price for skimping on security - PwC

Infosec 2012 Hacking attacks against Blighty's top firms hit a record high according to figures for 2011.

On average, each large organisation suffered 54 significant digital assaults in that 12-month period, twice the level in 2010, while 15 per cent – one in seven – had their networks successfully penetrated by unauthorised parties.

The average cost of a major security breach at a big biz last year was £110k to £250k ($177k to $403k), a figure that drops to £15k to £30k ($24k to $48k) for small businesses. SMEs were less frequently targeted with an average of one assault a month.

Chris Potter, information security partner at PricewaterhouseCoopers, said: "Large organisations are more visible to attackers, which increases the likelihood of an attack on their IT systems. They also have more staff and more staff-related breaches which may explain why small businesses report fewer breaches than larger ones.

"However, it is also true that small businesses tend to have less mature controls, and so may not detect the more sophisticated attacks."

The figures come from the 2012 Information Security Breaches Survey of 447 UK businesses by management consultants PwC and Infosecurity Europe. The poll, published every two years, is supported by UK.gov's Department for Business, Innovation and Skills. One-fifth of those surveyed are public sector organisations.

Apart from hacking, the figures show that companies are experiencing many data-protection breaches. The vast majority of firms polled (93 per cent of large organisations and 76 per cent of small businesses) experienced a security breach in the last 12 months: the most serious breaches generally resulted from failings in a combination of people, process and technology.

The survey also found customer impersonation attempts were up threefold since 2008, with financial services organisations and government bodies affected most.

Despite the prolonged economic slowdown, most organisations are spending more on security. On average, companies spent eight per cent of their IT budget on infosec, and those that suffered a very serious breach spent on average 6.5 per cent of their IT budget on security.

By contrast, 12 per cent of bosses gave a low priority to security, with one in five spending less than 1 per cent of their IT budget on information security – possibly as a result of not being able to quantify and measure the business benefits from spending cash on defences.

Potter said: "Organisations that suffered a very serious breach during the year spent slightly below the overall average on security. The key challenge is to evaluate and communicate the business benefits from investing in security controls. Otherwise, organisations end up paying more overall.

"The cost of dealing with breaches and the knee-jerk responses afterwards usually outweigh the cost of prevention."

Universities and science minister David Willetts, whose responsibilities include cyber-security issues, commented: "The survey demonstrates why the government is right to be investing £650m to improve cyber-security and make the UK one of the safest places to do business in cyberspace. We will use the findings to help design a new annual survey of cyber-security breaches beginning next year." ®

Brit upstart flogs cloudy SaaS to clipboard-waving bods

Infosec 2012 UK-based startup SureCloud is flogging a cloud-based auditing and compliance platform at mid-market businesses with high info-security standards.

SureCloud’s Unified Compliance Platform pulls together component elements such as vulnerability scanning, SIEM (security information & event management), wireless intrusion detection (IDS) and configuration auditing into a single platform.

Richard Hibbert, SureCloud chief exec, said that the firm's "security as a service" approach allows it to target SME and local government customers to meet compliance standards on a lower budget and without buying a variety of point products and services from the likes of Cisco, HP and Qualys.

The SaaS-based auditing and compliance automation service is designed to help mid-market organisations in regulated industries to simplify and reduce the cost of fulfilling their security management and information compliance obligations – making it easier for them to comply with the credit-card industry's PCI-DSS regime, for example.

SureCloud’s hybrid offering ties together products from multiple third-party vendors, but the firm doesn't disclose whose technology it is using.

The platform is designed to simplify the whole compliance process from data discovery through to providing actionable intelligence about vulnerabilities, via a single dashboard the provides data on threats and network activity. Customers gain the opportunity to significantly reduce their risk from data breaches as well as ability to manage their compliance commitments using fewer staff and without buying complex kit from multiple suppliers, says the firm.

"Customers can do more with less budget," Hibbert said. "Our platform helps customers to minimise security monitoring and remediation costs," he added.

Established in 2006, SureCloud is based in Reading and says it has more than 200 customers throughout the UK, which include a large number of local authorities and other customers in retail, financial services and gambling. The firm has aspirations to expand overseas, initially to English-speaking countries. ®

Bit9 wants to bin 'broken' antivirus, install whitelisting tech

Infosec 2012 Bit9 is using the Infosec show as a launchpad for its move into Europe as part of its wider ambitions to displace traditional antivirus technologies from corporate desktops and data centres.

The firm is marketing its brand of trust-based application control and whitelisting as a better way of tackling the growing malware menace posed by targeted attacks on security suites from the likes of Symantec and McAfee. However, if one traditional antivirus firm we spoke to is any guide then traditional players are not going to go down without a fight.

Bit9's Parity Suite uses the firm's Global Software Registry – a repository of five billion records of software – and "qualified" trust in updated applications from the likes of Adobe and Microsoft, to restrict the types of software allowed to run on Windows PCs and servers. Bit9's so-called "Advanced Threat Protection" platform also allows IT staff to set policies to block illegal and unauthorised software. Other components in its portfolio offer forensics capabilities.

The firm has set up operations in central London and in Munich in Germany to kickstart a channel programme it hopes will allow it to triple its sales in EMEA year-on-year. The firm already supplies its technology to customers ranging from various NHS trusts to Middle East Airlines.

Bit9’s chief executive Patrick Morley argues that the traditional antivirus model is broken and that businesses can benefit from moving to a trust-based model – enabled by Bit9's technology, of course – which he compared to the Apple App store. Bit9's Parity Suite is based on intelligent whitelisting and trust in the Microsoft update process, for example, rather than the detection of "something bad" from an analysis of the behaviour of software on PCs.

Whitelisting technology traditionally had a problem with false positives, falsely stopping legitimate business-critical applications from running. Morley conceded false positives with whitelisting technology were "bad in the early days" but said that by incorporating a "broad trust policy" for installers, intelligent whitelisting and cloud-based software reputation services, Bit9's technology had long since overcome these types of teething problems. He added that although Bit's technology offers a recording device on host end-points, it would be also be inaccurate to classify it as host-based intrusion prevention.

Bit9 is one of a number of firms talking up the benefits of smart application whitelisting at Infosec. Avecto and Faronics are also discussing the approach.

Morley said that although Bit9's technology can be run on top of an antivirus, the aim is to eventually displace it. He added that this displacement has already happened on retail tills and data centres, where the software can be used to protect file servers and domain controllers (Active Directory servers) in the data centre.

"Antivirus doesn't work and it's only the addition of anti-spam, firewall, data loss prevention and other technologies that have kept customers buying it," Morley told El Reg. "The model is broken and has been for a long time. It's only in the last two years that people have realised this," he added.

Morley justified buzzword-friendly claims that Bit9's technology supplied superior protection against Advanced Persistent Threats (industry slang for targeted malware driven industrial-espionage attacks) by saying that its software blocked the malware that featured in the infamous RSA attack last year dead in its tracks. This assault featured an Excel spreadsheet containing a Flash file that Bit9's software automatically deemed untrustworthy, Morley explained.

Eddy Willems, a security evangelist at anti-virus firm G Data, argued that whitelisting technologies are not without their shortcomings either, and ought to exist as a component of anti-malware suites, and not the replacement that Morley would like to see.

Willems, who as a consultant has installed whitelisting software, described it as "hard to tune and not easy to install".

He also listed other problems such as "legitimate samples which turn into malware examples afterwards" and a failure to combat in-memory malware or certain strains of rootkit as other shortcomings of the technology.

"It's a prevention method with no real removal capabilities, which is needed for several [strains of] malware," Willems said, adding: "It's part of the AV solution and not a solution on its own, we use it to prevent false positives so that it doesn’t remove important system files." ®