Wednesday, June 29, 2011

Trustworthy Internet

An interesting request, one that I second. A lot of work will be required, along with a lot of cooperation and a lot of time.

Amplify’d from www.winsupersite.com

It's Time for a Trustworthy Internet Initiative

Trustworthy Computing was a sea change for Microsoft. Remember that throughout the 1990s and early 2000s, Microsoft subscribed to the "more is always better" philosophy for software design. So when Windows 2000 popped up, the IIS web server wasn't just installed by default, it was also enabled by default, and it wasn't configured in a particularly safe way either. This was purposeful, as Microsoft wanted people to discover and use IIS.  But it was insecure.

Today, of course, Microsoft is a different company with a different outlook on security. And the hacking landscape has changed with it: As Microsoft's dominant OS has become more hardened over time, hackers have moved to lower-hanging fruit, first with Microsoft's popular Office applications and then with third-party applications, especially those from Adobe.

And that's the problem: Despite Microsoft's high-profile switch to a more secure development process, and despite documenting the changes it's made so that others could make similar changes, most software makers, virtually all of them in fact, haven't caught on. And as we move into a new generation of ever-connected systems and cloud services, our exposure to vulnerabilities—or what Microsoft calls the attack surface—has grown exponentially.

I'm thinking of course of the recent high profile Anonymous/Lulzsec hack attacks on AT&T, Fox, Sony, various US and international governmental organizations, the Arizona State Police, and others. Suddenly, the world is being held virtual hostage by what appears to be a loose knit (if not totally disconnected) group of disaffected teenager and young adult loners. One perhaps imagines them sitting in their parents' basements, peering at their monitors over giant cups of Mountain Dew or whatever. But you can forget these outdated stereotypes: Today's hackers have a much richer, more connected, and more damaging set of computing resources to attack. And they're doing so with gusto.

It's time to stop them. And what's required, I think, is an industry-wide agreement to do for Internet- and cloud-based computing what Microsoft's Trustworthy initiative did for the software giant. That is, we need a Trustworthy Internet initiative.

The first hopeful sign in a new version of the Domain Naming System (DNS) called Secure DNS, or DNSSEC. This scheme, which is being tested in Singapore, is perhaps the model for the future Internet. It's based on three secure data centers, in Singapore, San Jose, and Zurich, which are protected by five layers of physical, electronic, and cryptographic security. According to a report in the New York Times, four of the five layers are now in place, with the fifth, the physical security, now being built.

And if your understanding of Internet history is up to date, you'll appreciate the irony here: The Internet was of course designed to ensure communication in the event of a nuclear disaster, so it was designed without a center, or core, and is instead distributed with a means for messages to continue seeking alternate routes until delivered. But this resiliency is what now makes the Internet so insecure, since it provides the bad guys with many ways in which to hide their identity and pose as others.

However it happens, I think it's time for mankind to step it up collectively, work together, and fix what is very clearly a broken patchwork built on an insecure foundation. As with a growing body of other issues—global warming, the food and water supply, and global nuclear security—this is a problem that increasingly affects us all.

Read more at www.winsupersite.com
 

Friday, June 24, 2011

Protecting Private Information on Smart Phones

I find this development interesting. It goes direct to the heart of privacy concerns in the smartphone market. I have noticed many applications that ask for permissions that aren't needed or support functionality that I am not interested in. More granular, user-based control over application permissions would be welcome.



AppFence is not yet available (apparently), but there are other applications that provide similar protections, referenced in the comments to the original article.

Amplify’d from www.schneier.com

Protecting Private Information on Smart Phones

AppFence is a technology -- with a working prototype -- that protects personal information on smart phones. It does this by either substituting innocuous information in place of sensitive information or blocking attempts by the application to send the sensitive information over the network.

The significance of systems like AppFence is that they have the potential to change the balance of power in privacy between mobile application developers and users. Today, application developers get to choose what information an application will have access to, and the user faces a take-it-or-leave-it proposition: users must either grant all the permissions requested by the application developer or abandon installation. Take-it-or-leave it offers may make it easier for applications to obtain access to information that users don't want applications to have. Many applications take advantage of this to gain access to users' device identifiers and location for behavioral tracking and advertising. Systems like AppFence could make it harder for applications to access these types of information without more explicit consent and cooperation from users.

The problem is that the mobile OS providers might not like AppFence. Google probably doesn't care, but Apple is one of the biggest consumers of iPhone personal information. Right now, the prototype only works on Android, because it requires flashing the phone. In theory, the technology can be made to work on any mobile OS, but good luck getting Apple to agree to it.

Read more at www.schneier.com
 

If you use up your iCloud storage, you’ll stop getting email

This kind of thing makes iCloud less interesting for me. Google Docs, Music, and Gmail have their own individual quotas; same for Hotmail and Skydrive. 5 gigs is not a lot for today's phones, and not that much for email either.

Amplify’d from thenextweb.com

If you use up your iCloud storage, you’ll stop getting email

An email received by a Macrumors reader shows what happens when the iCloud space allotted to your iOS devices is used up. The email comes addressed from the ‘MobileMe Quota Service’ and specifies that your devices will no longer back up or save data to iCloud. It also lists the actions you can take once you’ve received the mail.

The interesting bit here is that iCloud storage is linked to your me.com email address as well. That means that if you use up your storage space with iPhone backups, you will stop receiving email to your me.com address. This seems like a poor way to handle email and having a shared storage space with backups, which can very quickly increase in size (my iPad backup is 3GB and I don’t even have all of my apps reinstalled after upgrading to iOS 5), seems like a quick way to annoy users of the new iCloud email service.

It’s unclear at this point whether the email that you get sent will just disappear, get bounced back to the recipient or be held in a queue until you upgrade your storage or delete backups. Apple has yet to announce pricing on additional iCloud storage.

See more at thenextweb.com
 

Tuesday, June 21, 2011

What Skype Really Means to Microsoft

An interesting viewpoint, now that the deal has received FTC approval. Microsoft, of course, could still horribly bungle the whole thing, but if it were to evolve as posited below, then it really could be that "this deal may represent yet another nail in the coffin of traditional land lines, another step down the path toward purely IP-based communications."

Amplify’d from www.windowsitpro.com

What Skype Really Means to Microsoft

But this deal is not just about adding Skype to Microsoft's secret sauce. For this to really make sense, Microsoft will need to deeply integrate these technologies across products. That is, if you're a Skype user and you're logged on to the service from any of these products or services, you should be able to reach any of your contacts, regardless of how they're connected, and vice versa. For example, there's no reason you couldn't get an IP-based call while playing games on the Xbox 360, while the person calling is utilizing a PC laptop and headset while on a Wi-Fi enabled flight. 

Perhaps this pervasiveness is the real secret behind Microsoft's desire for Skype. And while it may take a while for the software giant to integrate this technology into its various products, one might further conjecture that by providing both client/server and peer-to-peer alternatives for online communications, Microsoft will arrive at an overall infrastructure that is more reliable than anything the competition could muster. In fact, this deal may represent yet another nail in the coffin of traditional land lines, another step down the path toward purely IP-based communications.

And that's why I think Microsoft's deal for Skype, finally, does in fact make sense. When the company announced this deal, I didn't get it. But if you accept that the future of what we now think of phone calls—essentially audio communications, but also video and video conferencing—is going entirely IP, with the Skype deal, Microsoft is right in the center of things. And regardless of the details of how the company intends to implement this technology, that nicely positions Microsoft for the next big wave of technology adoption as we collectively, as a planet, move to mobile devices as our primary form of computing. And if successful, it will provide Microsoft with yet another chance to position itself in users' minds as the company that is making it all happen.

Read more at www.windowsitpro.com
 

Saturday, June 11, 2011

Apple sued by iCloud Communications over iCloud trademark

Why doesn't part of its vaunted "archetype branding" model contain the item "make sure you have freedom to use trademark?" Just asking.

Amplify’d from thenextweb.com

Apple sued by iCloud Communications over iCloud trademark

While I’m no legal expert, it does appear that Apple has some explaining to do. Specifically, iCloud Communications is claiming that Apple’s heavy promotion of the iCloud product is damaging to its business and has all but removed the branding of the name from itself and placed it onto Apple.

To make matters somewhat worse, there’s some accusation that Apple’s services are nearly identical to the ones being offered by iCloud Communciations:


The goods and services with which Apple intends to use the “iCloud” mark are identical to or closely related to the goods and services that have been offered by iCloud Communications under the iCloud Marks since its formation in 2005.  However, due to the worldwide media coverage given to and generated by Apple’s announcement of its “iCloud” services and the ensuing saturation advertising campaign pursued by Apple, the media and the general public have quickly come to associate the mark “iCloud” with Apple, rather than iCloud Communications.

There’s no specific amount of monetary relief set, but the suit does call for “all profits, gains and advantages” as well as “all monetary damages sustained”. Further, the suit asks for Apple to refrain from using the iCloud name and to “deliver for destruction all labels, signs, prints, insignia, letterhead, brochures, business cards, invoices and any other written or recorded material” with the iCloud name.

Read more at thenextweb.com
 

Integrity

Normally, I find this kind of thing amusing. As an OSU alum, I find it even more amusing. With all the football problems and Coach Tressel resigning ... karma?


Thursday, June 9, 2011

Senators seek crackdown on "Bitcoin" currency

Steve Gibson had an excellent technical discussion on Bitcoin here: http://www.grc.com/sn/sn-287.htm. From that I can say that the article is incorrect when it says the only way to get them is through the exchanges at $10 a bitcoin; however, it is much faster and more certain. I suppose that it is inevitable that something like Bitcoin would be used drug trafficing or the like, because of the untraceability and inability to control this kind of currency. There is probably an interesting analysis to be had here; an economy based on Bitcoin might be more brittle, since the system doesn't inherently allow for inflation or expansion of the money supply.

But back to the article: how much is concern over the drugs and how much is concern for the government not getting its cut? And at this point, is there anything the government can really do about it?

Amplify’d from www.reuters.com

Senators seek crackdown on "Bitcoin" currency

Democratic Senators Charles Schumer of New York and Joe Manchin of West Virginia wrote to Attorney General Eric Holder and Drug Enforcement Administration head Michele Leonhart in a letter that expressed concerns about the underground website "Silk Road" and the use of Bitcoins to make purchases there.
The letter prompted a discussion among Bitcoin enthusiasts about whether the government was capable of closing related bank accounts and thereby stifling the currency.

Silk Road buyers pay with Bitcoins and sellers mail the drugs, the Gawker blog reported. The transactions leave no traditional money trail for investigators to follow, and leave it hard to prove a package recipient knew in advance what was in a shipment.

"The only method of payment for these illegal purchases is an untraceable peer-to-peer currency known as Bitcoins. After purchasing Bitcoins through an exchange, a user can create an account on Silk Road and start purchasing illegal drugs from individuals around the world and have them delivered to their homes within days," the senators' letter states. "We urge you to take immediate action and shut down the Silk Road network."

The DEA is "absolutely" concerned about Bitcoins and other anonymous digital currencies, agency spokeswoman Dawn Dearden said when asked for a response to the senators' concerns.

Silk Road may be hard to close. It could easily move from server to server around the globe and change its Web address and name at will, while remaining accessible through Tor.

However, Bitcoins must be purchased with real money; of late, they have been selling for roughly $10 each.

One user described this process as simply "growing pains" and asserted that the government "can't stop a peer-to-peer service."

U.S. law enforcers might have difficulty stopping Bitcoins without help from their peers in other countries.

While little information about Bitcoin exchanges is publicly available, an item posted on a website called Bitcoin Watch states that Mt. Gox's bank account is in Japan, and anecdotal evidence suggests many other exchanges operate outside of the US.

Read more at www.reuters.com
 

"Multiliteracy"

This is a picture of my daughter's award from the Delaware DOE for "Multiliteracy". (Is "Multiliteracy" a word?)  ...