Your Ad Here
Showing posts with label News. Show all posts
Showing posts with label News. Show all posts

The Bluetooth 3.0 buzz is building. The short-range wireless standard Bluetooth 3.0 will get its official launch on April 21. The developers of the standard, the Bluetooth Special Interest Group, have confirmed multiple reports forecasting the release of Bluetooth 3.0 specs. According to the Bluetooth SIG on April 21 it will announce the groups latest Bluetooth standard. At that time the Bluetooth 3.0 specifications will be unveiled.

Here's What We Know About Bluetooth 3.0

The Bluetooth 3.0 standard is expected to deliver even faster short-range wireless speeds (up to 480 Mbit/s), improvements to reduce chances of device disconnections when syncing, and the addition of Generic Alternate MAC/PHY (AMP) technology that will reportedly allow Bluetooth 3.0 devices to transfer data at speed on par with Wi-Fi. Another advancement will allow the Bluetooth wireless frequency to piggyback on the Wi-Fi 802.11 protocol - in affect allowing Bluetooth over Wi-Fi. We'll have to wait until April 21 to find out more.

What's unique about Bluetooth is its low cost and low power consumption, allowing it to be used in devices such as cell phones where cost and power consumption are huge concerns for developers. However, Bluetooth technology has struggled in its efforts to be adopted widely.

What the blogs are saying

The Bluetooth SIG claims Bluetooth 3.0 can wirelessly transfer an entire music library, a complete DVD [or] a vacation's worth of photos, all within seconds, according to the blog the Bluetooth SIG. In addition to pumped-up speed, Bluetooth 3.0 could also feature "Enhanced Power Control," which reduces those annoying headset disconnects caused by putting your phone in your pocket or purse.

There are no details at the moment about Bluetooth 3.0-ready devices, but most Bluetooth watchers expect the Bluetooth SIG to release a list of manufacturers that have products ready to go at the Bluetooth 3.0 launch on April 21.

Bluetooth in the smart phone age

The new Bluetooth standard comes as smart phones are growing way beyond e-mail and voice calling into full-fledged mini-computers. For some time now, cell phone users have turned to Bluetooth for wireless headsets and to sync calendar and contact information. Now that many people are listening to music and watching movies on their mobile devices, Bluetooth needed to get faster to remain an effective solution for wireless syncing.

In the meantime, Bluetooth technology will have to compete with the Wireless USB standard that is going in popularity and influence.

A 10-month cyberespionage investigation has found that 1295 computers in 103 countries and belonging to international institutions have been spied on, with some circumstantial evidence suggesting China may be to blame.

The 53-page report, released on Sunday, provides some of the most compelling evidence and detail of the efforts of politically-motivated hackers while raising questions about their ties with government-sanctioned cyberspying operations.

It describes a network which researchers have called GhostNet, which primarily uses a malicious software program called gh0st RAT (Remote Access Tool) to steal sensitive documents, control Web cams and completely control infected computers.


"GhostNet represents a network of compromised computers resident in high-value political, economic and media locations spread across numerous countries worldwide," said the report, written by analysts with the Information Warfare Monitor, a research project of the SecDev Group, a think tank, and the Munk Center for International Studies at the University of Toronto. "At the time of writing, these organizations are almost certainly oblivious to the compromised situation in which they find themselves."

The analysts did say, however, they have no confirmation if the information obtained has ended up being valuable to the hackers or whether it has been commercially sold or passed on as intelligence.
Spying Since 2004

The operation probably started around 2004, the time security researchers noticed that many of these institutions were being sent bogus e-mail messages with executable files attached to them, according to Mikko Hypponen, director of antivirus research at F-Secure. Hypponen, who has been tracking the attacks for years, says that GhostNet's tactics have evolved considerably from those early days. "For the past three-and-a-half years or so it's been fairly advanced and fairly technical."

"It's really good to see a spotlight on this while thing right now, because it's been going on for so long and nobody's been paying attention," he added.

Although evidence shows that servers in China were collecting some of the sensitive data, the analysts were cautious about linking the spying to the Chinese government. Rather, China has a fifth of the world's Internet users, which may include hackers that have goals aligning with official Chinese political positions.

"Attributing all Chinese malware to deliberate or targeted intelligence gathering operations by the Chinese state is wrong and misleading," the report said.

However, China has made a concerted effort since the 1990s to use cyberspace for military advantage "The Chinese focus on cyber capabilities as part of its strategy of national asymmetric warfare involves deliberately developing capabilities that circumvent U.S. superiority in command-and-control warfare," it said.
Tibet's Computers Breached

A second report, written by University of Cambridge researchers and published in conjunction with the University of Toronto paper, was less circumspect, saying that the attacks against the Office of His Holiness the Dalai Lama (OHHDL) were launched by "agents of the Chinese government." The Cambridge team titled their report, "The Snooping Dragon."

The analysts' research started after they were granted access to computers belonging to Tibet's government in exile, Tibetan nongovernmental organizations and the private office of the Dalai Lama, which was concerned about the leak of confidential information, according to the report.

They found computers infected with malicious software that allowed remote hackers to steal information. The computers became infected after users opened malicious attachments or clicked on linked leading to harmful Web sites.

The Web sites or malicious attachments would then try to exploit software vulnerabilities in order to take control of the machine. In one example, a malicious e-mail was sent to a Tibet-affiliated organization with a return address of "campaign@freetibet.org" with an infected Microsoft Word attachment.

As the analysts probed the network, they found that the servers collecting the data were not secured. They gained access to control panels used to monitor the hacked computers on four servers.

Those control panels revealed lists of infected computers, which went far beyond the Tibet government and NGOs. Three of the four control servers were located in China, including Hainan, Guangdong and Sichuan. One was in the U.S., the report said. Five of the six command servers were in China, with the remaining one in Hong Kong.

The University of Toronto report classified close to 30 percent of the infected computers as being "high-value" targets. Those machines belong to the ministry of foreign affairs of Bangladesh, Barbados, Bhutan, Brunei, Indonesia, Iran, Latvia and the Philippines. Also infected were computers belonging to the embassies of Cyprus, Germany, India, Indonesia, Malta, Pakistan, Portugal, Romania, South Korea, Taiwan and Thailand.

International groups infected included the ASEAN (Association of Southeast Asian Nations) secretariat, SAARC (South Asian Association for Regional Cooperation) and the Asian Development Bank; some news organizations such as the U.K. affiliate of the Associated Press; and an unclassified NATO computer.
Spotlight on Security Needs

GhostNet's existence highlights a need for urgent attention to information security, the analysts wrote. "We can safely hypothesize that it [GhostNet] is neither the first nor the only one of its kind."

The Cambridge researchers predict that these highly targeted attacks bundled with sophisticated malware -- they call them "social malware" -- will become more prevalent in the future. "Social malware is unlikely to remain a tool of governments," they write. "What Chinese spooks did in 2008, Russian crooks will do in 2010."

While F-Secure has seen only a few thousand of these attacks so far, they are already a problem for corporate users in the defense sector, Hypponen said. "We're only seeing this right now on a minuscule scale," he said. "If you could take techniques like this and do it on a massive scale, of course that would change the game."

source: PCWORLD

f Microsoft had invented the iPod, it would have been called the Microsoft I-pod Pro 2005 Human Ear Professional Edition. The cult-hit video that makes that assertion may have been a joke, but it rings true. And when word emerged that the video was a self-parody produced within Microsoft, the point was even clearer: The world's largest software developer just isn't very good at naming stuff.

Some Microsoft names sound clunky; some are confusing; some are undignified or overambitious. More than any other company in technology, the Redmond powerhouse loves to change product names--often replacing one lackluster label with an equally uninspired one. Microsoft has also been known to mess up some names that are actually perfectly good, such as Windows and Word, by needlessly tampering with them.

Herewith, in chronological order, are ten Microsoft names that could have been a lot better, together with some semiconstructive advice on monikers that would have more euphonious and/or more accurate. I also selected six not-quite-as-bad runners-up.

1993: Word 6.0 for Windows: When Microsoft upgraded 1991's popular Word 2.0 for Windows, it replaced it with...no, not something logical like Word 3.0. Rather, it blithely hopscotched over three version numbers and landed at Word 6.0. The official explanation for the skippage was that it brought the Windows edition's version number into line with that of the older DOS incarnation of Word. But conspiracy theorists noted that it also allowed Word to catch up with archrival WordPerfect, which also released a version 6.0 in 1993.

Whatever the rationale, the move rendered the practical purpose of version numbers meaningless, thereby setting a bad example for other companies such as Netscape, which later went straight from Netscape Navigator 4.0 to version 6.0.

What it should have been called:
Word 3.0 for Windows. Simple and accurate.

1995: Microsoft Bob. When I asked my Twitter and Facebook pals to nominate bad Microsoft names, this legendarily lousy Windows front-end hosted by animated characters came up far more often than any other product. It's possible that the badness of the product has tarnished its title. But as several people pointed out, "Microsoft Bob" is both cutesy-cute and uninformative--it doesn't give you an inkling as to what the product is all about. (The box featured a smiley face wearing Bill Gates-like nerdy glasses, but the main character in the interface was a dog named Rover, who was later revived for Windows XP's misbegotten search feature.)

What it should have been called: Well, Microsoft Rover would have been at least slightly more descriptive--especially since the product itself was such a dog.

1996-present: Every name ever associated with handheld devices running Microsoft software. At first, they were called Handheld PCs, and ran an OS known as Windows CE. Then they morphed into Palm PCs--until the PalmPilot people complained, whereupon they became Palm-Size PCs. But only briefly: Soon, Microsoft wanted us to call them Pocket PCs, and the software they ran was renamed Windows Mobile.

That name stuck around when the OS migrated from PDAs to phones, although it bifurcated into two editions: Windows Mobile Pocket PC and Windows Mobile Smartphone. Then Microsoft declared that there were three Windows Mobile variants--Windows Mobile Classic, Windows Mobile Professional, and Windows Mobile Standard. As for the devices themselves, Steve Ballmer declared in February of this year that they'd be known henceforth as Windows Phones--scratch the "Mobile." Except for the fact that the OS is still Windows Mobile. Got that?

What they should have been called: Melvin. Or just about anything else, really, as long as it didn't keep changing.

2000: .NET. In the mid-1990s, critics accused Microsoft was accused by many of being slow to jump on the Internet bandwagon. By the dawn of the new millennium, however, it was firmly on board--and in June 2000, it unveiled a vision for online services it called .NET. As originally articulated, .NET addressed consumers, businesses, and developers, and it involved everything from programming languages to an online version of Microsoft Office to calendaring and communications services to a small-business portal to stuff for PDAs, cell phones, and gaming consoles. It was so wildly ambitious, so all-encompassing, and so buzzword-laden that it pretty much defied comprehension, at least if you weren't a professional geek. Which the company seemed to realize--it quickly stopped pushing the concept to consumers, instead restricting it to programming tools.

What it should have been called: How about "Virtually Everything Microsoft Does Involving the Internet From This Day Forward," or VEMDIFTDF for short? Or taking a different tack, what if Microsoft had simply declared that it was now Web-centric, period--no new branding required?

2000: Windows Millennium Edition. Microsoft couldn't call this successor to Windows 98 "Windows 2000" because it had already assigned that name to Windows NT's replacement. So the company saddled the OS with a name that was both pretentious and goofy, and gave it the overly adorable (and badly capitalized) nickname "Windows Me." It was probably bad juju: The product itself went on to be widely reviled as slow, glitchy, and insubstantial; and to this day its name rivals that of Microsoft Bob as shorthand for "crummy software."

What it should have been called: Windows 2001, especially if Microsoft marketing had assembled an ad campaign involving HAL 9000 and/or apes hurling things at an obelisk. Bonus virtue: That name would have given Microsoft an excuse to delay the OS for six months to fix bugs.

2001: HailStorm. Hail isn't exactly a form of weather resplendent with positive associations: It kills crops, damages cars, blinds drivers, and is downright painful--and occasionally deadly--to people unfortunate enough to get pelted by it. Yet that's the codename that Microsoft chose to associate with the plans it unveiled in 2001 to deliver an array of Web services and to store consumers' personal information for use with Microsoft and third-party offerings.

The notion of Microsoft controlling so much private data proved instantly controversial; the company changed HailStorm's name to .NET My Services, and then put the whole idea on hold And yet HailStorm wasn't so different from services that Microsoft, Google, Facebook, and others offer today. I can't help wondering whether it would have fared better if it hadn't had a name that suggested a violent weather disturbance descending from the heavens to afflict us mere mortals.

What it should have been called: Microsoft Passport--a name Microsoft gave its online ID service even before it announced HailStorm--wouldn't have been bad. Today, however, Microsoft Passports are known as Windows Live IDs (presumably to distinguish them from all those Windows IDs that have died).

2004: Windows Genuine Advantage. Understandably, Microsoft hates it when people pirate Windows. So it added multiple copy-protection measures such as activation and validation to Windows XP and Windows Vista. Collectively, they're known as Windows Genuine Advantage, which the company touts as a benefit to properly licensed users. But WGA asks paying Microsoft customers to jump through piracy-detecting hoops. Worse, it's been known to accuse them of stealing Windows and shut off functionality.

What it should have been called: Snarky answer: Windows Genuine Disadvantage. Serious one: Windows Anti-Piracy Technology.

2004: PlaysForSure. This logo program for services and devices that used Windows Media DRM may have been the single most inaccurately named item in the history of personal technology. The name exuded hubris, but PlaysForSure tracks often FailedToPlay on PlaysForSure-enabled devices--and, of course, they didn't play at all on the world's most popular MP3 player, arch-rival Apple's iPod. For Pete's sake, they didn't even play on Microsoft's own music player when it appeared. By the time Microsoft shut down the PlaysForSure-powered MSN Music service, it had already rolled PlaysForSure into the blandly named Certified for Windows Vista program, which doesn't promise much of anything.

What it should have been called: MusicCripplingWindowsMediaDRM. Or just plain Windows Media, which is what PlaysForSure was beneath the patina of marketing hype.

2006: 2007 Microsoft Office System. When Microsoft announced Microsoft Office 2007 in February 2006, it started calling the overall Office platform the "2007 Microsoft Office System," even though individual versions, such as the alarmingly wordy Microsoft Office Professional Plus 2007, kept the year at the end of the name. At the time, a Microsoft representative explained the distinction to me, but I barely comprehended it even then--it was as if the company wanted Windows 95 to be called 95 Windows in certain instances. Then there was the superfluous "system" on the end, which reminds me of how the Disney company insists on calling Disneyland the "Disneyland Resort."

What it should have been called: Microsoft Office 2007. Actually, that's what everybody outside the city limits of Redmond does call it.

2008: Windows Live Essentials: In September 2008, Microsoft announced that it was stripping three of Windows Vista's applets--Windows Mail, Windows Photo Gallery, and Windows Movie Maker--out of Windows 7. They would live on, but as free downloads, known collectively (along with other apps such as Windows Live Writer) as Windows Live Essentials. But doesn't the fact that Microsoft unbundled these tools from Windows prove that they're not essential? Bonus annoyance: Microsoft's decision to identify these downloadable freebies' under the Windows Live rubric (which usually applies to Web services) makes it even harder to define just what Windows Live means.

What it should have been called: I'm not sure that anyone gains anything by giving these applets a collective name. But something along the lines of Windows Bonus Material or Windows Extras would work.

Runners Up: Six More Unfortunate Microsoft Names

Chkdsk. Even in the DOS era, it was unclear why the name of this venerable disk-checking utility skipped all its vowels; even with the eight-character filename limit it could have at least been Checkdsk or Chekdisk. Today, there's no excuse for not calling it CheckDisk.

All Microsoft products called Messenger. Not that it's inherently bad name. But there's Windows XP's Windows Messenger; there's the unrelated command-line utility called Windows Messenger Service, famous mostly for being a security leak; and there's the old MSN Messenger, which was renamed Windows Live Messenger in 2005. That's at least two Messengers too many. To its credit, though, Microsoft didn't change "Messenger" to "Message Explorer."

Microsoft Office Word. And Microsoft Office Excel, Microsoft Office PowerPoint, and Microsoft Office Access. With Office 2007, Microsoft stuck in a superfluous "Office" in the middle of some of the best-known names in the history of software. Nobody noticed. Basic rule of thumb: If your customers don't realize that you've changed your product's name, you've failed.

OneNote. Merriam-Webster reports that "one-note" means "monotonous." Microsoft's handy note-taking application deserves better.

The Road Ahead. Published in 1995, Bill Gates's best-selling book famously didn't predict the rise of the Internet, thereby utterly failing to live up to the visionary promise of its title.

Windows 95: Yes, seriously: By the time it finally shipped, 1995 was two-thirds of the way over, leaving the blockbuster new version of Windows sounding slightly stale from the get-go. And it ushered in the era of consistently inconsistent Windows names, from additional year-based ones (Windows 98, 2000), to inappropriately highfalutin' modifiers (Windows Millennium Edition, Windows Vista) to mysterious acronyms (Windows XP).

Are there other tech-product names you find annoying and/or inaccurate--from Microsoft or from other companies? Or maybe even names you think are really good? Sound off in the comments.

5 Great Technology Bargains

Posted by Unknown | 5:37 PM | | 0 comments »

When you're strapped for cash for a can't-avoid-it purchase, sometimes it's worth sacrificing a few frills. We zeroed in on a desktop, a laptop, a color laser printer, a camera, and an HDTV. Each represents a great value in its category.

1. Desktop PC: Dell Inspiron 518 ($654)

Need solid performance for everyday tasks in a budget PC? Dell's Inspiron 518 sports a 2.4-GHz Intel Core 2 Quad Q6600 CPU, 3GB of PC6400 DDR2 memory, and a 320GB Western Digital Caviar SE16 hard drive (7200 rpm, 16MB cache). The Inspiron 518 turned in a respectable score of 108 on our WorldBench 6 tests, and while hard-core gamers might hold out for more graphics oomph than the unit's ATI Radeon HD3450 provides, the system sports some nice design touches such as a recessed storage tray on top of the system with two easily accessible USB ports (in addition to two on the face of the unit). We also liked the bundled 20-inch wide-screen LCD monitor with a built-in Webcam. For under $700 (in early February), this sounds like a good value to us.

2.Netbook: Acer Aspire One ($350)

Looking for a budget netbook? The Acer Aspire One could fit the bill. It's not perfect--you might consider splurging for the six-cell battery, since the included three-cell battery will barely last 2 hours, and the 8.9-inch screen is undeniably tiny. But it's got a great usable keyboard and a reasonably roomy 120GB hard disk drive, and the $350 base price makes it a solid candidate to tide you over until a future crop of this fast-evolving class of portables comes along later this year.

3.Multifunction Ink Jet Printer: Canon Pixma MP620 ($150)

You'll be hard-pressed to find a multifunction color inkjet that strikes as good a balance between cost (about $150, list, in February) and quality as the Canon Pixma MP620. With support for USB, ethernet, and Wi-Fi connections; media slots for most common storage cards; and two 150-sheet input trays, it's ready to meet the needs of most small offices and homes. Image, scan, and copy quality is generally solid, and the cost of consumables (4.6 cents for a page of plain black text and 12.4 cents for a full-color page) is about or slightly better than average.

4.Camera: Pentax Optio A40 (under $200)

With all the new camera announcements at the recent Consumer Electronics Show--as well as all the ones coming up at the PMA imaging show in March--it's a great time to buy one of last year's top-of-the-line point-and-shoots at bargain-bin prices. We like the Pentax Optio A40, a 12-megapixel pocket camera that delivers very good image quality (according to our tests) and has optical image stabilization and a DivX movie mode. The Optio A40 cost about $250 when it was released last year, but by this February it was selling for as little as $120.

5.HDTV: Vizio SV420XVT 42-Inch LCD TV ($999)

With good overall image quality and a 120-Hz refresh rate for smoother motion, the Vizio SV420XVT also has a fair price for a 42-inch LCD-TV: under $1000 as of early February. It isn't the easiest TV to set up, but if you're looking for a great HDTV picture at a good price, this Vizio has the goods.

Perhaps Microsoft was right all along. In the 1990s, it saw the new kid on the block, Netscape, as a threat, and did what it could to destroy the upstart. With Google, the 'Softies won't be so lucky.

Most of you have heard the story about Netscape Communications, but let me summarize for the newcomers: Netscape was the first serious improvement to the Internet browser, and it grew like crazy, pretty much dominating the scene overnight. Then out of the blue, Marc Andreessen (the man credited with developing the product) decided to blow smoke about how this would eventually lead to the end of Microsoft. He was vague as to how it would lead there, but Microsoft determined that it had something to do with thin-client, browser-based computing somehow taking over everything.

Microsoft went into high gear, bought up a slew of little Internet companies and a minor browser company, and rolled out Internet Explorer as a freebie. This was important. The business plan for Netscape was based on selling the browser, but Microsoft was going to give away Explorer forever and bundle it with every new system. That was pretty much the end of Netscape, which eventually morphed into Mozilla's Firefox, a nonprofit browser that makes its money off its little Google search box.

The destruction of Netscape was awesome, Microsoft's "peak oil," as it were. The company was under the gun after that from various antitrust initiatives, and has never really been the same since. Now it is indeed vulnerable despite its overwhelming market share.

The new kid on the block today is Google, and everyone knows it. But Google didn't make Netscape's mistakes. The company has never claimed to be targeting Microsoft. Google mostly says it is interested in search and whatever else its minions create. Its approach is far different from that of any company Microsoft has ever encountered.

First, Google has remained warm and fuzzy, with its cute name, cute logo, and cute gimmicks. Microsoft has never owned a fleet of jets featuring a 767. But to remain warm and cuddly, the 767 is called the Google party plane. Yay, a party!

The company also took a lesson from the early days of Yahoo, when keeping it simple was the key to success. Google just does search better than anyone else, and that's it for now. Of course, there are Google Docs, Gmail, and other "cloud computing" initiatives that Microsoft is watching warily. Just as Microsoft throws its weight behind the notion of the cloud, Google says it will build a client-side version of Gmail—so people can go through their mail the way an Outlook customer can. Before that it rolls out the beta of an entirely new smartphone. It's one little thing after another. Nothing quite consolidated, just little experiments.

All along I keep hearing talk about a Google OS, probably based on Linux. Yet there's no real evidence that the company would do such a thing. Still, it is on the phone; what would it take to port Android to a netbook?

Well that's what a lot of people are beginning to ask. Linux suffers from a flavor-of-the-month complex, where the best Linux distro comes and goes. For years, the Linux community has resigned itself to not competing with Windows and the Mac OS—this despite the fact that the Mac OS is, like Linux, Unix-based. What if Google tried to be that competition? With its resources, could Google take over the OS business and push Microsoft up into the miserable enterprise computing scene, where it could take the place of the old dinosaurs while Google and Apple get to do all the fun stuff?

And how would Google make money from this effort? Linux is open-source, after all, and selling copies or even licensing Linux is problematic. Well, how about a Google-branded computer?

I've always wondered why Microsoft, the dominant software company, could never manage a branding program for its OS that was more than a crummy sticker stuck on a machine as an afterthought. Where is the "Microsoft Windows Computer by HP," for example?

Had Microsoft followed a branding strategy with a reference design computer (in collaboration with Intel or AMD) that could be licensed, the company wouldn't have gotten into trouble for bundling Internet Explorer, for example. That approach would have changed the way the game was played.

But Microsoft long since missed that boat. Google can still release an Android Desktop or Android Netbook, or whatever. I'd like to see it. The topper would be offering Microsoft an opportunity to do MS Office for Android. That would be rich.

This possibility all stems from the fact that Microsoft seems to have lost its way, coasting on its main cash cows and unable to do anything else confidently. To end on a positive note for Microsoft, I've believed for years that the company can effectively counter all this momentum by itself embracing Linux and doing a fully supported MS-Linux as a kind of competitive jujitsu. It's the only long-term solution to this slow death we seem to be observing.

source : pcmag.com

The Web is teeming with venomous exploits. And an ever-increasing quantity of that malware sneaks onto hard drives via the browser.

Which begs the question: Does your choice of browser affect your chances of being infected? Conventional wisdom says to avoid Internet Explorer, simply because it's the target of a magnitude more malware than any other browser.


That reasoning makes sense, but we couldn't settle for the easy answer. That's why we drilled deep into the security workings of the five most popular browsers: Internet Explorer, Firefox, Opera, Safari, and Chrome. Every control, checkbox, and slider was poked and prodded, as we browsed the most infected sites on the Web. In the end, we concluded that sensible user behavior and a commitment to install the latest patches had a vastly greater impact on security than which browser you choose.
Rogue Programs: Click Me!

Most malicious exploits require an accomplice: you. By now, you'd think people would know that if they're visiting a site they're unfamiliar with, and they're asked whether they want to download something, the correct answer is "No." But naiveté apparently knows no bounds. Ironically, the great majority of exploits occur when an end user falls for a bait and switch such as the fake anti-virus scam ("you've been infected; download this anti-virus program"). No browser can protect against such folly.

The good news is that smart users who don't make those mistakes and keep up with patches have little to fear, even from the worst neighborhoods on the Web. In our tests, which included exposure to more than one hundred known-malicious public Web sites, none of the fully patched browsers let through stealth infections or exploits, though browser lockups were frequent and complete system reboots sometimes necessary.

Just keep in mind that the browser is not alone in the battle. Through the browser, Web-based malware can exploit vulnerabilities in the operating system and in browser plug-ins such as Flash, Java, and QuickTime. In addition to the browser itself, these too should be kept fully patched. The good news is, the Web also mends. For most popular software these days -- including the five browsers we tested -- automated updates are available.

Browsers have many security features that help the end user avoid being bitten by malware, as well as some privacy protections.

All five browsers have pop-up blockers, anti-phishing filters, and password protection. Except for Opera, they allow for private session browsing where the browser saves nothing from the session that can be used to track your online movements -- no browsing history, no cookies, no temporary Internet files, and so on.

But only two, Internet Explorer and Firefox, have the coolest browser security feature of all: configurable security zones, which let end users set up different levels of security for Web sites based on their trustworthiness.

For instance, an end user can set up a "zone" where obscure, shady-looking Web sites must face the browser's most stringent security measures, such as disabled JavaScript, which often plays a role in malicious exploits. Firefox and Internet Explorer also let end users turn off add-ons, whereas Safari, Opera and Chrome do not.

These browser security features play an important role in keeping the end user safe. They also vary from browser to browser: some browsers have certain features, others do not. And some browsers are simply better at security than others. Here's a quick look at each of the five browsers.

Microsoft Internet Explorer 8 beta 2

Pros: Internet Explorer is the powerhouse browser, boasting more than 1,300 security controls, whereas the second closest browser (Firefox) has 150. Internet Explorer has five security zones that are easily configurable, and allows you to turn off JavaScript and add-ons. It's the only browser with parental controls.

Cons: Explorer's popularity makes it the primary target of hackers. Its unique support of ActiveX (another way malicious exploits get into a computer) poses an additional security threat that other browsers don't have.

Takeaway: Internet Explorer's superior security controls should be weighed against the fact that it's the most frequently attacked browser in the world.

Mozilla Firefox 3.12

Pros: This battle-tested veteran has security zones and a built-in add-on manager that allows you to easily turn off add-ons and JavaScript.

Cons: Setting up security zones isn't easy.

Takeaway: Firefox makes a good browser choice for PC users. In terms of security granularity and choices of controls, it's second only to Internet Explorer.

Apple Safari 3.2.1

Pros: Safari boasts the most accurate anti-phishing filter and always prompts users before downloading files. Safari (like Chrome) does a good job at blocking unwanted cookies.

Cons: Lacks security zones and the ability to turn off add-ons.

Takeaway: While Safari is a great looking browser, it's a mixed bag with respect to security. Still, Safari -- if fully patched and running on a fully patched system -- can be a secure environment.

Opera 9.63

Pros: Opera has extensive security controls and good protections against "denial-of-service" attacks.

Cons: Lacks security zones, the ability to turn off add-ons, and private-session browsing. Its lack of support for key Windows security features may put it at higher risk of buffer overflow attacks.

Takeaway: Opera is a great browser but hasn't been exposed to the crucible of constant attacks. Support for Windows' Data Execution Prevention and Address Layout Space Randomization features is needed before its use can be more highly recommended.

Google Chrome 1.0

Pros: JavaScript runs inside a virtual machine, thus providing some containment. Chrome (like Safari) does a good job at blocking unwanted cookies.

Cons: Chrome can't disable JavaScript -- a big problem considering JavaScript is involved in some of the most malicious Web exploits. Chrome allows passwords to be displayed in plain text, potentially exposing them to passersby, and has been plagued by relatively simple buffer overflow problems.

Takeaway: The security model Chrome follows is excellent, but the security choices Google has made for its browser are often abysmal. More troubling, the vulnerabilities that have been found in Chrome are simple and common ones that Google easily should have avoided.

source : PCWORLD

Facebook may have done an about-face with its policies on using user data, but the social network's struggle to balance business with privacy is far from over.

Facebook CEO Mark Zuckerberg announced the company would revert to its old terms of use in a blog posting late Tuesday night. The decision followed wide-reaching outrage over the service's updated policies on user-generated content. The changes essentially gave Facebook a "perpetual" license to use any uploaded materials within advertising or any number of other venues--even if the user had long since deleted the content, or even deleted the account.

Advocates in Action

Facebook's backtracking announcement came just hours after word broke that the Electronic Privacy Information Center (EPIC), an advocacy group based in Washington, D.C., intended to file a formal complaint with the Federal Trade Commission over the altered licenses.

"What we sensed was taking place was that Facebook was asserting a greater legal authority over the user-generated content," says EPIC Executive Director Marc Rotenberg. "It represented a fundamental shift in terms of how the company saw its ability to exercise control over what its users were posting, and that really concerned us."

Shortly after Rotenberg shared those concerns and his complaint-filing intentions with PC World, he received a phone call.

"We got a call late last night from Facebook and they said that they were thinking of going back to their original terms of service," he says. "We said that if they would agree to do that, we wouldn't see the need to file the complaint."

The complaint--which ran 25 pages and had support from about a dozen other consumer and civil liberty groups--essentially asked the FTC to require Facebook to readopt its previous policies. The fact that Facebook ended up doing so on its own was a pleasant, though perhaps unexpected, surprise.

"We've been in this situation before with other companies that have really dug in their heels and tried to fight it out in the courts and the media. I think Facebook did the right thing," Rotenberg says.

The Power of Protest

Rotenberg gives much of the credit to Julius Harper Jr., a 25-year-old who formed the now-88,000-member-strong "People Against the New Terms of Service" Facebook group. Harper's efforts began as a simple protest, but they quickly became much more. He and other members, for example, formulated a list of "three big questions for Facebook" and submitted it to the service's legal team.

The list asked why the terms of service seemed to give Facebook the right to use user photos if the company didn't intend to exercise that option. "Will I wind up seeing pictures of my niece staring at me from a bus stop at some point and be told I shoulda read the fine print?" one user asked.

The note also raised the issue of what would happen if Facebook were to be bought out by another corporation at some point in the future, and the new owner were to hold less honorable intentions than Zuckerberg and his team may now. The updated terms of service, the document suggested, would give that owner powerful rights over user-generated content being created today.

"As we all know, corporate strategies adjust, CEOs change, boards of directors shuffle and companies get bought out. We're just looking for some legal assurances in writing that if and when that happens, we won't be left in the cold," the group stated.

Harper and his supporters received a response from a Facebook spokesperson Tuesday night. It said that executives realized "the new version of the terms might technically permit some of the hypothetical situations" the group had raised. It went on to assure that those weren't situations Facebook "had in mind" when updating its terms. Those kinds of consequences, however--even if unintended--were exactly what had troubled Harper.

"The legal language is very overarching and very scary if you really take a minute to think about what the implications are," Harper says. "[It] was basically saying, 'We own you.' And so that’s where the issue came from."

Now, Harper and his followers are claiming a victory--but the biggest work, staying involved in Facebook's efforts to reformulate its terms, is still ahead of them.

"What this issue is that I hope Facebook will stick with is that they should set a precedent by rewriting their terms of service in English," Harper says. "I'm hoping this will affect other companies in the industry as well, because Facebook is just one of many, many services that people like me use."

An Ongoing Effort

For privacy advocate group EPIC, a victory isn't yet so clear.

"It's great that Facebook has responded, and I think that’s a step in the right direction--but these issues don’t go away, and it's going to be an ongoing concern for users of new network-based services until we get comprehensive privacy laws in place," Rotenberg says.

In the immediate future, EPIC plans to keep a close eye on Facebook's progress and the rights of its users. Rotenberg promises he and his colleagues will step in if the need arises--and won't hesitate to appeal to the FTC if it becomes necessary, either.

"People shouldn’t have to run around trying to think about which stuff they're going to delete," Rotenberg says. "People shouldn’t be in that position. They should be able to sign up for a service with the confidence that their rights will be respected."

One new concern already on the horizon comes with Facebook's updated advertising models. The site is now utilizing APIs to pull user data off of status updates, Rotenberg says, then use it within ads placed on the page.

"People ... who care about privacy on Facebook typically don’t install applications, because they know that applications are pulling down a lot of their data. But if you're not installing applications and you learn that the information that you're putting in your status updates is being provided for advertising, you might be a little upset," Rotenberg says.

Luckily, organizations like EPIC are on the watch. And so, too, are thousands of regular users--people just like Julius Harper Jr.

"The fact that [the protest group] blew up so huge has to do more with how people on the service felt way more than it had to do with me," Harper says. "Had I not done it, it would have happened some other way. But I'm grateful that I got to be part of the process and make a real difference on something that affects millions of people."

source : PCWORLD

Microsoft plans to open its own retail stores to "transform the PC and Microsoft buying experience," the company said Wednesday as it hired an executive to run the retail operation.

The stores will help Microsoft engage more deeply with consumers and learn firsthand about what they want to buy and how, according to a Microsoft press release. Deciding where the stores will be located and what they'll look like will be the first order of business for David Porter, who will report to work on Monday as corporate vice president of Retail Stores.

Microsoft has long been perceived as lagging behind rival Apple in appealing directly to consumers, and Apple has a head start of several years in running a chain of stores. While Microsoft makes its own Xbox game terminals, Zune media players and some other devices, it doesn't have a branded PC product of its own like Apple's Macintosh.

In December, Apple neared 10 percent of personal computer sales while Windows lost a full percentage point of share for the second month in a row.

With the retail strategy, Microsoft said it hopes to articulate and demonstrate its innovation and value proposition. It will pass on lessons it learns from the stores to its retail and OEM (original equipment maker) partners.

The move comes as the company gears up for the release of the Windows 7 PC operating system as well as new releases of Windows Mobile and of the Windows Live online portal. It follows changes Microsoft has made to its marketing efforts as the Windows Vista operating system took on a negative image.

Porter has been head of worldwide product distribution for Dreamworks Animation SKG since 2007, but before that, he spent 25 years at Wal-Mart Stores. His last position there was vice president and general merchandise manager of entertainment.

Microsoft has already had at least one retail store. In 1999, it opened a large store on the second floor of Sony's Metreon entertainment and shopping complex in downtown San Francisco. Among other things, visitors to the store could try out Windows CE-based handhelds and buy Microsoft apparel, souvenirs and shrink-wrapped software. The shop closed several years later, as did most of the other non-Sony-related businesses in the complex.

Conficker Worm Draws a Counter-Attack

Posted by Unknown | 1:48 AM | | 0 comments »

n response to the Conficker worm's massive infection of millions of PCs worldwide, industry heavyweights including Microsoft, Symantec and others Thursday announced they're forming a new team to fight back against the worm.

In addition to the team's mission to grab domain names Conficker (aka Downadup) might try to use, Microsoft is offering a fat $250,000 reward for information that leads to the arrest and conviction of those responsible for the worm. The reward is available to residents of any country, Microsoft says.

Conficker's Achilles heel is its need to receive orders from a server on the Internet. The worm checks a list of up to 250 different domain names each day for instructions.Normally, cycling through 250 different names would likely be enough to ensure that the good guys would be unable to keep up, as Conficker's controllers would theoretically only have to register one of those domains per day to control their massive herd of malware. But Conficker's notoriety has prompted the companies to coordinate their efforts and try to nab all the potential domain registrations before the bad guys can.

Doing so would restrict the worm to receiving updates or instructions only through its secondary peer-to-peer capability, according to Symantec. From the description, that secondary ability would likely limit the worm to making a peer-to-peer connection only with infected PCs on the same local network.

According to Symantec's announcement, the team includes "Microsoft, ICANN, Neustar, Verisign, CNNIC, Afilias, Public Internet Registry, Global Domains International Inc., M1D Global, AOL, F-Secure, ISC, researchers from Georgia Tech, The Shadowserver Foundation, Arbor Networks, and Support Intelligence."

If anyone does manage to register one of the domains before the team does, the team will investigate its owner.

This is a good step, and one I'd sure like to see taken further. This team should stick around after Conficker and continue to work to deny the bad guy's use of domain names, hosting providers and other infrastructure required by the malware black market.

I do wonder, though, why Microsoft didn't set up a phone number or other central point of contact for collecting information about Conficker. The company says that "individuals with information about the Conficker worm should contact their international law enforcement agencies."

source : www.networkworld.com

Google's PowerMeter

Posted by Unknown | 7:15 PM | | 0 comments »


Google is testing software that will let consumers get detailed information on how much electricity they're using, which could help households reduce consumption by as much as 15 percent, the company said Monday.

The software, Google PowerMeter, integrates into the company's iGoogle platform, where users create a customized page with lightweight Web-based applications. The PowerMeter is designed to show a granular, real-time view of electricity-consuming devices.

Although just a prototype now, consumers will eventually be able to opt in to use it, and no personal information will be shared between Google and utilities, the company said. The electricity data will be stored securely, and users will be able to tell their utility to stop sending data to the PowerMeter, Google said.

Most consumers don't have much data or context regarding their electricity consumption, according to Ed Lu of Google's engineering team.

Google's PowerMeter takes data from so-called "smart meters," or advanced electricity meters and other electricity management devices. About 40 million smart meters are in use worldwide, with that number expected to rise to 100 million in the next few years, Lu said.

U.S. President Barack Obama's economy stimulus plan includes investments to put up to 40 million smart meters in U.S. homes.

Google takes data from a home's smart meter and displays it in a graph. It can show the current day's electricity consumption compared to the day before, but the graph can be expanded to get a historical view of peaks and troughs in electricity usage, Google said.

Google also plans to release APIs (application programming interfaces) for PowerMeter that would let other software developers build applications around it.

Google is making a strong push for agreements with utilities on how to standardize the data that's available from smart meters. In a position paper dated Monday sent to California's Public Utility Commission, Google said that "the data from the smart meter needs to be available to the consumer in real-time and in a non-proprietary format."

California has been pushing ahead with Advanced Metering Infrastructure (AMI) plans, which call for new meters that show real-time data well as pricing information to consumers.

So far, Google is letting its own employees test PowerMeter. The insights gained include at least two revelations about the electricity used to make toast and the inefficiency of 20-year-old refrigerators.

"One morning I noticed that my energy consumption was higher than normal," wrote Kirsten, a Google program manager, who didn't give her last name. "I went into the kitchen and found that the dial on our toaster oven was stuck and had been on all night.

"It was already burning and the once white exterior was now brown. If I hadn't seen my energy consumption and known where to look, my apartment could have been toast," she wrote.

source : Technology

Conficker Worm Draws a Counter-Attack

Posted by Unknown | 6:32 PM | | 0 comments »

In response to the Conficker worm's massive infection of millions of PCs worldwide, industry heavyweights including Microsoft, Symantec and others today announced they're forming a new team to fight back against the worm.

In addition to the team's mission to grab domain names Conficker (aka Downadup) might try to use, Microsoft is offering a fat $250,000 reward for information that leads to the arrest and conviction of those responsible for the worm. The reward is available to residents of any country, Microsoft says.




Conficker's Achilles heel is its need to receive orders from a server on the Internet. The worm checks a list of up to 250 different domain names each day for instructions.

Normally, cycling through 250 different names would likely be enough to ensure that the good guys would be unable to keep up, as Conficker's controllers would theoretically only have to register one of those domains per day to control their massive herd of malware. But Conficker's notoriety has prompted the companies to coordinate their efforts and try to nab all the potential domain registrations before the bad guys can.

Doing so would restrict the worm to receiving updates or instructions only through its secondary peer-to-peer capability, according to Symantec. From the description, that secondary ability would likely limit the worm to making a peer-to-peer connection only with infected PCs on the same local network.

According to Symantec's announcement, the team includes "Microsoft, ICANN, Neustar, Verisign, CNNIC, Afilias, Public Internet Registry, Global Domains International Inc., M1D Global, AOL, F-Secure, ISC, researchers from Georgia Tech, The Shadowserver Foundation, Arbor Networks, and Support Intelligence."

If anyone does manage to register one of the domains before the team does, the team will investigate its owner.

This is a good step, and one I'd sure like to see taken further. This team should stick around after Conficker and continue to work to deny the bad guy's use of domain names, hosting providers and other infrastructure required by the malware black market.

I do wonder, though, why Microsoft didn't set up a phone number or other central point of contact for collecting information about Conficker. The company says that "individuals with information about the Conficker worm should contact their international law enforcement agencies."

resource : PCWORLD