3G means more porn, China laments amid cleanup

China called for a cleanup of mobile porn Web sites on Wednesday, blaming their rise on high-speed mobile data services, deployment of which has otherwise been a point of pride for the country. This year the country has also closed thousands of Web sites and arrested dozens in a campaign against online pornography that is increasingly shifting focus to mobile Web sites. "Lawless people have begun using the full commercial deployment of 3G and its faster download speeds for pictures and videos... to spread obscene and pornographic content," Su Jinsheng, an engineer in China's IT ministry, said in a speech, according to a transcript on the ministry Web site. China issued 3G (third generation) mobile network licenses to its three mobile carriers early this year, and the number of 3G users in China has slowly climbed since then.

A cleanup is needed to "protect the healthy growth of the next generation and purify the social environment," he said. But owners of mobile porn Web sites have been able to evade authorities through technical tactics such as frequently switching domain names and IP (Internet Protocol) addresses, Su said. China sees its long-delayed rollout of 3G services as a step toward its goal of becoming a global technology power. Counter-tactics being used by authorities include a blacklist to prevent pornographic Web sites from reappearing online and the design of content-filtering technology to help network operators themselves block obscene content, he said, giving a rare official glimpse into how Chinese regulators control information on the Internet. Earlier this year Google had a row with Chinese authorities over pornographic search results that ultimately led to Google.com and other Google services being briefly blocked in the country.

Pornography is illegal in China and authorities have long seen it as a scourge on the country's culture.

World of Warcraft players targeted by 'free mounts' phishing scheme

The popular online game World of Warcraft (WoW) is being hit with a new phishing scheme that lets attackers steal players' accumulated "gold" and other treasure by luring players with offers of free "mounts" used in the online game, say security researchers at F-Secure. The link takes the player to a site that looks exactly like World of Warcraft and offers them free "mounts," the fantasy horses that humans would ride or trusted wolf mounts that the Orcs prefer, which have powers like helping move the player more quickly through the game or defend them against monsters. It's an attack that exploits the WoW-based in-game chat to lure a player into clicking on a link. If the victim falls for the "free mounts" phishing fraud and enters his online credentials, the attacker can take over his account and steal all the "gold" or other treasures the player accumulated in the game's progress. "This is like physical property, it can be traded," said Sean Sullivan, security researcher at F-Secure about the value of the online game's items like "gold" and "mounts," which can bring money in auctions in sites in China, for example.

Sullivan added that over two years ago, eBay declared a ban on auctioning WoW items like fantasy "gold," apparently because of the fraud level. The latest phishing scam to hit WoW, which F-Secure describes here, is a new twist on some of the older attacks that made use of malicious banner ads on WoW to try and install trojans on victim's desktops. The current "mounts" phishing scam allows the successful attacker to steal whatever treasures the victim has associated with the WoW account, and then to go after other victims. F-Secure's Internet Security 2010 product recognizes this type of phishing scam and blocks against it, the vendor says.

Microsoft: No TCP/IP patches for you, XP

Microsoft late last week said it won't patch Windows XP for a pair of bugs it quashed Sept. 8 in Vista, Windows Server 2003 and Windows Server 2008. The news adds Windows XP Service Pack 2 (SP2) and SP3 to the no-patch list that previously included only Windows 2000 Server SP4. "We're talking about code that is 12 to 15 years old in its origin, so backporting that level of code is essentially not feasible," said security program manager Adrian Stone during Microsoft's monthly post-patch Webcast , referring to Windows 2000 and XP. "An update for Windows XP will not be made available," Stone and fellow program manager Jerry Bryant said during the Q&A portion of the Webcast ( transcript here ). Last Tuesday, Microsoft said that it wasn't patching Windows 2000 because creating a fix was "infeasible." The bugs in question are in Windows' implementation of TCP/IP, the Web's default suite of connection protocols. In the revised advisory, Microsoft explained why it won't patch Windows XP, the world's most popular operating system . "By default, Windows XP SP2, Windows XP SP3 and Windows XP Professional x64 Edition SP2 do not have a listening service configured in the client firewall and are therefore not affected by this vulnerability," the company said. "Windows XP SP2 and later operating systems include a stateful host firewall that provides protection for computers against incoming traffic from the Internet or from neighboring network devices on a private network." Although the two bugs can be exploited on Windows 2000 and XP, Microsoft downplayed their impact. "A system would become unresponsive due to memory consumption ... [but] a successful attack requires a sustained flood of specially crafted TCP packets, and the system will recover once the flood ceases." Microsoft rated the vulnerabilities on Windows 2000 and XP as "important" on Windows 2000, and as "low" on XP. The company uses a four-step scoring system, where "low" is the least-dangerous threat, followed in ascending order by "moderate," "important" and "critical." The same two bugs were ranked "moderate" for Vista and Server 2008, while a third - which doesn't affect the older operating systems - was rated "critical." During the Q&A, however, Windows users repeatedly asked Microsoft's security team to explain why it wasn't patching XP, or if, in certain scenarios, their machines might be at risk. "We still use Windows XP and we do not use Windows Firewall," read one of the user questions. "We use a third-party vendor firewall product. All three of the vulnerabilities highlighted in the MS09-048 update were patched in Vista and Server 2008. Only two of the trio affect Windows Server 2000 and Windows XP, Microsoft said in the accompanying advisory, which was refreshed on Thursday.

Even assuming that we use the Windows Firewall, if there are services listening, such as remote desktop, wouldn't then Windows XP be vulnerable to this?" "Servers are a more likely target for this attack, and your firewall should provide additional protections against external exploits," replied Stone and Bryant. Windows Server 2000 SP4, for example, is to receive security updates until July 2010; Windows XP's support doesn't expire until April 2014. Stone's and Bryant's answer: "We will continue to provide updates for Windows 2000 while it is in support unless it is not technically feasible to do so." Skipping patches is very unusual for Microsoft. Another user asked them to spell out the conditions under which Microsoft won't offer up patches for still-supported operating systems. According to a Stone and Bryant, the last time it declined to patch a vulnerability in a support edition of Windows was in March 2003 , when it said it wouldn't fix a bug in Windows NT 4.0. Then, it explained the omission with language very similar to what it used when it said it wouldn't update Windows 2000. "Due to these fundamental differences between Windows NT 4.0 and Windows 2000 and its successors, it is infeasible to rebuild the software for Windows NT 4.0 to eliminate the vulnerability," Microsoft said at the time.

IBM offers cheaper Linux mainframe bundles

IBM is introducing new Linux-focused mainframe bundles that it says will provide discounts of up to 80% over previous offerings. But Linux has been a bright spot, with 70% of IBM's top 100 mainframe customers running Linux, according to Gartner. How to really bury a mainframe IBM's mainframe business has struggled in 2009, with year-over-year revenue declines of 26% in the third quarter and 39% in the second quarter. In an attempt to boost falling sales, IBM has taken several steps to lure new customers and capitalize on interest in consolidating Linux workloads on mainframes using IBM's virtualization technology.

IBM also cut prices nearly in half for some specialty Linux processors known as Integrated Facility for Linux (IFL). In IBM's latest move, announced Tuesday, the company is releasing a new mainframe bundle called the Enterprise Linux Server, which starts at a little more than $200,000. The least expensive version includes two IFL processors, plus memory, I/O connectivity, licenses for the z/VM mainframe virtualization software, and three years worth of maintenance. In August IBM released seven hardware, software and services packages which are known as the "Solution Edition Series" and are aimed at specific application workloads like data warehousing and SAP software. The business class version can scale up to 10 IFLs, while the enterprise class machine can scale up to 64. Savings per processor improve the more a customer buys, and can cost as much as 80% less than previous mainframe offerings, according to IBM. The basic $200,000 machine with two IFL processors can run about 50 Linux-based virtual machines, says Reed Mullen, IBM's System z virtualization strategy manager. IBM hopes to lure customers away from competing platforms such as Itanium and Sun's Solaris, he says. IBM partners Novell and Red Hat are offering discounted Linux licenses when purchased with the Enterprise Linux Server.

IBM has been successful in selling more capacity to existing Linux-on-mainframe customers, but has had trouble convincing new organizations of the economic benefits of putting Linux on System z, Mullen says. "We want to target not just existing mainframe clients with this solution, we also want to target non-mainframe clients who are waking up to some of the realities of large-scale server consolidation," he says. "We believe those who have yet to embrace Linux on the mainframe are ready to do so more aggressively." In addition to the Enterprise Linux Server, IBM is releasing two new Solution Edition bundles, one for Linux and one for Chordiant CRM software. Because IBM mainframe's division is struggling, now is a good time for customers to negotiate with Big Blue, Gartner analyst Mike Chuba recently said. While the Enterprise Linux Server is a stand-alone mainframe for new deployments, the Solution Edition bundles add capacity to existing machines, according to Mullen. The Solution Edition bundles represent some of the best deals IBM has offered to date. "If you're going to go into a negotiation with IBM right now and want to get the best price, the first two words out of your mouth should be 'solution edition,'" Chuba said. Follow Jon Brodkin on Twitter.

Data Robotics ships Drobo iSCSI SAN

Data Robotics today released its first iSCSI SAN storage array that, like its other low-end arrays, manages itself and allows any capacity or brand of disk drive to be mixed, matched and exchanged without any downtime. The new system extends the number of Smart Volumes - Data Robotics' thin provisioning that pools capacity from all eight drives - so users can now create as many as 255 virtual storage volumes, up from 16 volumes in the current Drobo model. Data Robotics' DroboElite offers automated capacity expansion and one-click single- or dual-drive (RAID 5 or 6) redundancy for Windows, Mac and Linux machines.

The latest addition to the Drobo family of arrays is aimed at the small to mid-size business market and resellers selling into the virtual server space, according to Jim Sherhart, senior director of marketing for Data Robotics. "Virtual servers tend to use a lot of small LUNs (logical unit numbers)," said Jim Sherhart, senior director of marketing for Data Robotics. For example, if a user were to initially set up DroboElite for dual drive failure, he could switch to single-drive failure with one mouse click. The DroboElite is also able to drop from higher to lower levels of RAID with no manual intervention. Users can also change out drives, adding higher-capacity models, in 10 seconds - with no formatting required, according to Sherhart. Tarun Chachra, chief technology officer at marketing company KSL Media , has owned two Drobo USB arrays for about a year and a half.

DroboElite can support VMware environments and advanced functionality including VMotion, Storage VMotion, snapshots, and high availability. He purchased four DroboPro arrays in June for use in two offices for Microsoft Exchange replication and backups for about 16 servers. Chachra said he was impressed that he could simply go out and buy a 1TB, 7,200 RPM SATA drive for $69 and stick it in the DroboElite, saving him money on total cost of ownership on pricier SAS drives. He's also beta testing the DroboElite, which he plans to purchase for backing up his VMware servers because of its higher throughput with dual Gigabit Ethernet ports and greater number of creatable volumes. Chachra has been comparing his existing DroboPros, which can be configured with up to eight 2TB drives, to what he'd previously been using for backups: a Hewlett-Packard AiO400R array with four 500GB drives. The HP array runs the same iSCSI stack as the DroboPro, but it uses Windows 2003 Storage Server as a backup and replication application.

Chachra said the DroboPro cost about $3,500 compared with the AiO400, which cost $5,219. The HP array was set up for RAID 5 right out of the box and couldn't be changed; the DroboPro offers both RAID 5 and 6 interchangeably. The HP has forced Chachra to reboot his backup server every three days or so because it would hang up and couldn't handle bandwidth, he said. "We don't have huge IT teams looking at servers, so it's better for us to have something that can tolerate a higher driver failure rates," he said. "We also don't stock a lot of hard drives. The DroboElite also offers a non-automated thin provisioning feature called Smart Volumes that allows users to create new volumes in seconds and manage them over time by pulling storage from a common pool rather than a specific physical drive allocation. The main thing, though, is redundancy and having Exchange available all the time." "I don't know that an enterprise is going to run out and deploy this for 2,000 or 3,000 [users], but for small or mid-size shops, this is cost effective and it works as well as it should," Chachra added. Smart Volumes are also file system aware, which allows deleted data blocks to be immediately returned to the pool for future use.

Geoff Barrall, CEO and founder of Data Robotics, said the DroboElite can deliver cost savings of up to 90% compared to other iSCSI SANs "by combining cost-effective hardware with robust iSCSI features." The DroboElite is currently available starting at a price of $3,499, with multiple configurations selling for up to $5,899 for a 16TB configuration (using eight 2TB drives).

Cloud Engines updates Pogoplug media sharing device

On Friday, Cloud Engines introduced the second generation of its Pogoplug multimedia sharing device. The new version adds several new features. The Pogoplug is designed to plug into your home or small office network and let you access and share content of USB hard drives over the Internet using a standard Web browser.

First off, it now has four USB 2.0 ports instead of one so you can connect multiple USB hard drives or flash drives without the need for a USB hub. It works with H.264 video, as well as common photo types, but doesn't support DRM media. Along with that, there's now support for global search across multiple drives. (It still connects to your router using gigabit Ethernet.) Also new are improved transcoding and wider support for streaming movies on the Web or to an iPhone app; the ability to automatically sync photos, music, videos, and other content from apps such as iTunes and iPhoto; tighter integration with Facebook, Twitter, and MySpace; automatic organization of your music, photos, and videos; and an address book that remembers the e-mail addresses with which you've shared content for future sharing. (Many of the enhancements will be available to current Pogoplug owners as well.) Pogoplug supports OS X 10.4 and higher as well as Windows XP and Vista, and Linux; Safari, Firefox 3, IE 7, IE 8, and Chrome Web browsers; and hard drives formatted as NTFS, FAT32, Max OS Extended Journaled and non-Journaled (HFS+), and EXT-2/EXT-3. Although there are no specific bandwidth requirements listed, the company says that a typical DSL connection (with 512 Kbps upload speed) works fine. Cloud Engines expects to ship the new Pogoplug before the end of the year for $129, and is currently taking pre-orders.

Ciena to buy Nortel unit for $521 million

Ciena has agreed to acquire Nortel's Metro Ethernet Networks business for approximately $521 million in cash and stock. The two companies earlier this week confirmed they were in an advanced stage of negotiations for the sale.  Ciena will pay $390 million in cash and 10 million shares of Ciena stock for Nortel's MEN business. Hottest tech M&A deals of 2009 The MEN business includes Nortel's optical networking and Carrier Ethernet assets.

Ciena's stock closed yesterday at $13.05. The product and technology assets to be acquired include Nortel's long-haul optical transport portfolio, including the 40G/100Gbps systems; metro optical Ethernet switching and transport solutions; Ethernet transport, aggregation and switching technology; multiservice SONET/SDH product families; and network management software products. The assets to be acquired generated approximately $1.36 billion in revenue for Nortel in 2008 and $556 million in the first six months of 2009. Nortel says it has deployed 430,000 optical nodes to more than 1,000 customers in 65 countries, making Nortel – along with Ciena – one of the leading optical transport and switching vendors worldwide. "We believe this transaction will position us for faster growth by giving us greater geographic reach, broader customer relationships and a deeper portfolio of solutions," said Gary Smith, Ciena's CEO and president, in a statement. "We believe we are best positioned to leverage these assets, thereby creating a significant challenger to traditional network vendors." Ciena says it expects to offer employment to at least 2,000 Nortel employees, which represents more than 85% of Nortel's optical networking and Carrier Ethernet workforce. The agreement also includes all patents and intellectual property that are predominantly used in the businesses, and provides for the transition of substantially all of Nortel's Optical Networking and Carrier Ethernet customer contracts. As of July 31, Ciena employed 2,110. Nortel's bankruptcy: A long time coming "Today's announcement is a positive step forward for the future of Nortel's Optical Networking and Carrier Ethernet customers and employees," said Philippe Morin, Nortel MEN president, in a statement. "The sale of these businesses to a strong and stable buyer enables the innovation of one of the foremost leaders in the optical industry to continue to thrive." The transaction is subject to a "stalking horse" competitive bidding process and requires the approval of the United States Bankruptcy Court for the District of Delaware and the Ontario Superior Court of Justice Ciena expects hearings before those courts to approve bidding procedures, break-up fee and expense reimbursement will be held within the next several weeks, followed by a bid period and a potential auction, with final sale hearings to be held thereafter. Nortel is liquidating assets after having failed to restructure the company under Chapter 11 bankruptcy as a viable telecom competitor.

The transaction is also subject to customary closing conditions, including receipt of necessary regulatory approvals. To date, Nortel has sold its CDMA and LTE wireless assets to Ericsson for just more than $1 billion and its Enterprise Solutions business to Avaya for just less than $1 billion. It's also looking to sell its GSM wireless business. 

NEC upgrades to HYDRAstor grid storage system

NEC Corp. today unveiled several upgrades to its flagship HYDRAstor grid-storage system , adding write-once, read many (WORM) capabilities and the ability to encrypt data in transit. NEC officials said that the upgraded software will increase performance by 67%, while boosting security by improving HYDRAstor's ability to archive mission-critical data. "Over 70% of even high I/O data from source applications such as databases have not been touched after 6 months. The upgraded system also provides deduplication capabilities for more third party backup applications.

A lot can be off loaded onto more efficient platforms," said Gideon Senderov, director of product management for NEC's IT Products Group. The new RepliGrid in-flight data encryption capability protects data as it's being transmitted between HYDRAstor grids and data centers, he added. The new HYDRAlock WORM capability allows administrators to lock out any changes to documents or other records, maintaining a chain of custody for regulatory purposes, Senderov said. NEC also announced that it will allow users to license additional physical capacity that can be activated without adding additional components. A new quota management system allows administrators to set limits to the maximum effective capacity allocated for each file system and its associated application. For example, can now license as little as 12TB of capacity in a 24TB configuration and then pay a fee to activate additional capacity as needed.

The quota management system also offers threshold notifications as well as the ability to set aside a capacity reserve for other applications, such as critical archive data. The upgraded system can deliver up to 1.8TB per hour per accelerator node and up to 90TB per hour for the largest supported configuration of 55 accelerator nodes and 110 storage nodes, according to the company. Previously, the HYDRAstors grid architecture had a default capacity of 256 petabytes for all applications. "We are really looking forward to taking advantage of the new in-flight encryption and quota management functions," said Scott Ashton, a LAN/WAN specialist at TLC Engineering for Architecture Inc., an Orlando, Fla.-based engineering firm. "We've really seen the return on our initial investment as we've been able to take advantage of each new upgrade with HYDRAstor since our early adopter installation in 2007." NEC said that the performance boost comes from software enhancements and more efficient inter-node data transfer and communication protocols. Accelerator nodes are the controller blades with the CPU processing power and storage nodes are the system blades with disk storage capacity. NEC today also introduced lower-capacity, or "entry-level" models of HYDRAstor offering raw storage capacities of 12TB (or over 150 TB effective capacity); 24TB (or over 300 TB effective capacity) and 36 TB (or over 450 TB effective capacity). "A highly resilient storage solution primed for archiving, that self-evolves with the ability to intermix several generations of technology, offers global deduplication, great scalability, and automates provisioning, migration, workload balancing and system management will be the key features of a storage solution that the market will demand," said Dave Russell, a vice president at researcher Gartner Inc. The new application-aware deduplication feature allows newly-supported third-party backup applications such as IBM's Tivoli Storage Manager and EMC's NetWorker, as well as previously previously supported Simpana from CommVault and NetBackup from Symantec, to take advantage of the data reducing feature.

With the exception of WORM capability, the customers can install the latest HYDRAstor upgrades for free. The WORM upgrade costs $14,000 per accelerator node.

Mobile WAN operators raise 'openness' bar

It was a productive week for mobile WANs, with AT&T, Verizon Wireless, T-Mobile and Sprint all making announcements that broke new ground for the licensed operators. One reason for the demand is that, theoretically, you could bypass paying for a separate voice plan for using AT&T's legacy circuit-switched GSM network. Especially noteworthy: * AT&T caved to pressure to allow VoIP traffic on its 3G data network from the iPhone, something customers have been demanding. Note, though, that VoIP traffic over the 3G data network will consume kilobytes on your data plan if you don't have an unlimited domestic plan.

Top 10 must-have iPhone business apps * Verizon Wireless said it has partnered with former nemesis Google to develop two open source Android devices this year and associated applications. And if you're traveling out of the country, usage rates can be astronomical, so you're better off using VoIP over Wi-Fi (already supported) in those locations anyway. Note that the devices will support the Google Voice application that AT&T recently shunned for its iPhone amid much public fanfare. T-Mobile and Sprint also each announced intentions to launch Android phones made by Samsung, leaving AT&T as the only carrier without publicly announced plans to offer an Android device. * T-Mobile introduced an enterprise version of its UMA-based service, which allows Wi-Fi calling over its GSM network. Even Google CEO Eric Schmidt expressed surprise "that Verizon Wireless would emerge as the 'open' leader" among the mobile operators, though he said the two companies have been in cahoots on the Android project for 18 months. The Research in Motion BlackBerry-centric service is integrated with your corporate PBX features and dial plan, so users can pick up or make a call from either their desk phones or their BlackBerries.

Verizon Wireless offers such a managed service, too, says Rob Arnold, senior analyst at Current Analysis, but without the Wi-Fi calling capabilities. T-Mobile's Wi-Fi Calling with MobileOffice involves T-Mobile installing and managing a BlackBerry Mobile Voice System (MVS) server on your premises. Note that you could also buy, install and manage an MVS server yourself. The difference is that the service offers unlimited Wi-Fi calling over T-Mobile's GSM core network for free to enterprise customers with 100+ T-Mobile lines or for $9.99 per month per line for companies with fewer than 100 lines.

Three indicted for Comcast hack last year

Three hackers have been indicted for redirecting the Comcast.net Web site to a page of their own making in 2008. When Comcast customers visited the Comcast.net site during the attack on May 28, 2008, they were redirected to a Web site that displayed a message attributing the attack to members of the Kryogeniks hacker gang. At that time, about 5 million people connected to the Web site each day, the U.S. Department of Justice said in a statement. Because the site redirected to that page, customers were unable to access their Comcast e-mail accounts through the Comcast.net site.

Instead of the Comcast page, customers saw the message: "KRYOGENIKS Defiant and EBB RoXed COMCAST sHouTz to VIRUS Warlock elul21 coll1er seven." Immediately after Comcast was able to address the hack, the ISP (Internet service provider) and Network Solutions, the registrar, said they didn't know how the hackers managed to get the passwords necessary to switch the DNS servers and redirect the site. The suit said that one of the defendants, Christopher Allen Lewis, made two phone calls through which he got the information that he and his friends used to access Comcast's DNS information. The indictment sheds only a bit of light on how they did it. Another of the defendants, Michael Paul Nebel, allegedly logged onto a specific Comcast e-mail account that allowed him to communicate with Comcast's DNS registrar. During the attack, one of the defendants, Lewis, called a Comcast employee at his home and asked if the company's domains were working properly, the indictment alleges. Lewis was then able to sign onto Comcast's account at the registrar and point the Comcast.net Web site to the page he and the others made, according to the filing.

Comcast claims that it lost US$128,578 due to the attacks. The men are charged with one count each of conspiracy to intentionally damage a protected computer system. James Robert Black Jr. is the third defendant named in the indictment. The charges were filed in the U.S. District Court for the Eastern District of Pennsylvania on Thursday. If convicted they each face a five-year prison sentence and a $250,000 fine.

Google Voice Frees Your Voicemail, and Your Number

Until yesterday, signing up for a Google Voice account required you to pick a new phone number - not a pleasant option for those who have kept the same digits for years. When you sign up for Google Voice - which is still not widely available to the public (you need to get an invite or request one) - you can either choose Google one-stop phone number or keep your own for a more pared-down experience. Now Google has enabled users to keep their existing phone numbers and get (most of) the features Google Voice offers, including Google's excellent voicemail service. Keeping your old digits gives you: Online, searchable voicemail Free automated voicemail transcription Custom voicemail greetings for different callers Email and SMS notifications Low-priced international calling Going for the full-throttle Google experience gives you all of the above plus: One number that reaches you on all your phones SMS via email Call screening Listen In Call recording Conference calling Call blocking If you already have a Google Voice number, you can add the voicemail option to any mobile phone associated with the account.

Happily, Google circumvented this problem earlier this month. Some of the awesome benefits are explained in Google's YouTube explanation: Since voicemails are transcribed and placed online, even made publicly available for sharing purposes, there has been some danger of said voicemails appearing in search results. These new features are both freeing and limiting: you can keep your number but sacrifice some of the goodies that make Google Voice a powerful contender in the telephony business. Follow Brennon on Twitter: @neonmadman Full number portability is likely coming in the future, after, of course, Google deals with AT&T, Apple, and the FCC. But some have high hopes that eventually the opposition will grow to accept and embrace Google Voice.

Beware BlackBerry Browser Bug Until Carriers Offer Updates

BlackBerry smartphone users who frequently surf the Web via handheld will want to keep checking with their wireless carriers for BlackBerry Handheld Software updates in the coming weeks. The BlackBerry Browser dialog box informs the BlackBerry device user when there is a mismatch between the site domain name and the domain name indicated in the associated certificate, but does not properly illustrate that the mismatch is due to the presence of some hidden characters (for example, null characters) in the site domain name." The flaw relates to the BlackBerry software's certificate-handling functionality. That's because a new bug found in most current versions of Research In Motion's (RIM) device software, which makes it easier for malicious parties to execute "phishing" attacks on unsuspecting smartphone users, has been addressed via handheld software updates from RIM. From RIM's online security advisory: "This advisory relates to a BlackBerry Browser dialog box that provides information about web site domain names and their associated certificates.

A hacker could potentially recreate, or "spoof," a site commonly visited by BlackBerry users, such as RIM's BlackBerry.com, by purposely adding "null characters" to the site certificate's Common Name (CN) field. CVSS is a vendor agnostic, open standard for the security industry meant to depict the seriousness of vulnerabilities, according to RIM. The BlackBerry-maker recommends that all BlackBerry users running handheld OS 4.5 or higher check in with their wireless carriers to see if device software updates are available. The recently discovered flaw keeps the BlackBerry Browser from correctly identifying mismatched site certificates due to an inability to render said null characters. (See screenshot below for an example of how the BlackBerry Browser box should look when it encounters site certificate issues due to the presence of null characters in site CN fields.) The flaw was rated 6.8 (Medium Risk) on a Common Vulnerability Scoring System (CVSS) scale of one to ten, with one representing little or no risk and ten representing very serious risk. The problem: I just did a quick search of both AT&T and Verizon's BlackBerry download pages, but in a number of cases I could only locate earlier software versions than those recommended by RIM. Here's a list that specifies which software should be updated and to which new versions. If you encounter a BlackBerry Browser dialogue box like the ones shown in this post, you should choose to close the connection rather than subject yourself to potential phishing-related risk, according to RIM. More information on BlackBerry security can be located on the company's website. Current Software Version * BlackBerry Device Software v4.5.0.x to v4.5.0.173 or later * BlackBerry Device Software v4.6.0.x to v4.6.0.303 or later * BlackBerry Device Software v4.6.1.x to v4.6.1.309 or later * BlackBerry Device Software v4.7.0.x to v4.7.0.179 or later * BlackBerry Device Software v4.7.1.x to v4.7.1.57 or later Until you're able to sit down and update your device-or while you wait for your carrier to issue an update-RIM says to use caution when clicking unknown links in SMS text or e-mail messages, even if they're from what appears to be a trusted source.

Defunct airport fast-pass program may be revived

Tens of thousands of subscribers to a registered air traveler program, who were left feeling scammed when the company offering the service abruptly went out of business, may soon get a break. Subscribers to the Clear service, some of whom had signed up for two years or more of service just before VIP went out of business, will be offered a chance to continue their subscriptions after the deal goes through. A new investment group based in California has signed a letter of intent with Morgan Stanley, the defunct company's largest debt holder, according to the New York Times . Under a proposed plan, the investment firm will be allowed to buy the assets of Verified Identity Pass Inc. (VIP) and restart the Clear fast-lane security service, the Times reported, quoting the owner of the Emeryville, Calif.-based investment banking firm, Henry Inc. If an individual chooses not to, any personal data on that individual that had been collected by VIP for Clear, will be permanently destroyed, the Times said quoting the investment banker.

VIP was one of seven companies approved by the Transportation Security Administration (TSA) to operate a registered traveler program, which lets air travelers get through airport security checks faster. The news is likely to provide some comfort to thousands of customers of VIP who were left in the lurch when the company in June abruptly announced it could no longer offer the Clear service because it had run out of cash. It offered the service at 21 major airports, including New York's John F. Kennedy International Airport, La Guardia, Boston's Logan International and Atlanta's Hartsfield-Jackson airports. To sign up for VIP's Clear service, customers had to submit to background checks and provide identifying information, including Social Security and credit card numbers, home address, date and place of birth, phone numbers and driver's license number. More than 200,000 customers had signed up for the service when the company went out of business.

They also had to provide fingerprints, iris scans and digital images of their faces. The company made matters worse by hinting that it would sell the data it had collected to fulfill its debt obligations. VIP's decsion to shut the service raised concerns about the fate of the data that had been collected by the company. Many participants were left feeling scammed when VIP announced that it couldn't refund their subscriptions because it had run out of money. The motion was in response to a lawsuit brought by concerned customers.

Days after the company's closure, the chairman of the House Committee on Homeland Security asked the TSA to ensure that all information collected by VIP was properly protected and destroyed . In August, a federal judge in New York issued an injunction prohibiting VIP from selling, transferring or disclosing to any third-party the data it collected while operating the Clear service. The injunction, however, was later lifted on a technicality. For the moment, the purchase does little to alleviate the major complaint in the lawsuit, which is that VIP's customers didn't get a refund from their subscriptions. "That is something that they are entitled to regardless of whether or not other companies" purchase VIP, he said. Todd Schneider, an attorney with Schneider, Wallace, Cottrell, Brayton, Konecky LLP, a San Francisco law firm representing one of the parties in the lawsuit, today said he was unclear on the ramifications of the reported purchase of VIPs assets by the investment banking firm. A hearing in the case has been scheduled for Oct. 16, where Schneider plans to again ask the judge to bar VIP from selling its data assets to any third party.

News of the proposed purchase comes as the House Committee on Homeland Security is scheduled to hold a hearing today on the future of the registered air traveler program.

Sybase smooths enterprise path for iPhones

Sybase is extending its Afaria mobile-device management platform and database software to the Apple iPhone, taking advantage of new enterprise features in Version 3.1 of the iPhone's software to give IT departments more control and capabilities on the popular handset. Going on sale in the middle of this month, Sybase's Afaria 6.5 will finally give administrators the kinds of controls they have had previously for mobile platforms such as Symbian, Microsoft Windows Mobile 6.1, Research In Motion BlackBerry and PalmOS. Apple's recent iPhone 3.1 release added the capability to lock down certain settings on a device so the user can't change them using the phone's configuration utility, said Mark Jordan, senior product manager for Afaria. Though many enterprise employees bring iPhones into the office and rely on them for personal communications, the device originally caught on as a consumer gadget for music, Web browsing and entertainment applications, and has only gradually made inroads as a workplace tool. That allowed Sybase to give enterprise IT departments the power to do things such as block applications, define the required password strength and lock down Wi-Fi and VPN (virtual private network) settings.

With the new Afaria, enterprises can make and change settings on employees' iPhones over the air based on overall policies for certain departments, job descriptions and other criteria. Administrators can now establish a trusted relationship between Afaria and the employee's phone using a certificate, he said. Among other capabilities, they can also require device authentication for access to a corporate directory and set up compliance reporting on the employee's use of the phone. Also on Tuesday, it announced tools for the Sybase SQL Anywhere database to be used for synchronization of data between an iPhone application and a back-end database. Sybase announced Afaria's iPhone capabilities on Tuesday at the iPhone Developer Summit in Santa Clara, California.

Using SQL Anywhere, internal developers and software vendors can build in bi-directional synchronization between an on-device app and relational databases including Sybase, Oracle, SQL Server, DB2 and MySQL. This frees employees from having to depend on the cellular data connection to get work done while on the road, Jordan said. Also on Tuesday, the company's Sybase 365 subsidiary introduced a turnkey system for mobile banking on the iPhone. There is a beta test program now open for SQL Anywhere for iPhone. With it, banks can allow their customers to check balances, transfer funds among accounts, securely communicate with bank representatives, find branches and automatically dial the bank, Jordan said. The Sybase mBanking 365 iPhone platform is available now and is already deployed by BBVA Compass as the BBVA Compass Mobile application.

Cisco results top estimates

Cisco Systems on Wednesday posted first-quarter results that far exceeded Wall Street's expectations, though revenue and profits were down from a year earlier. Likewise, earnings per share for the quarter came in $0.05 better than expected, at $0.36. The non-GAAP figure excludes expenses, charges and other one-time items. Revenue for the quarter ended Oct. 24, the first of Cisco's fiscal year, was US$9.0 billion, compared to the $8.74 billion expected by financial analysts, according to a poll by Thomson Reuters.

Sales in the quarter were down 12.7 percent from a year earlier. On a sequential basis, revenue was up 6 percent from the fourth quarter, while earnings per share were up 16 percent. "Our Q1 results continued to reflect strong sequential growth trends that meet or exceed expectations during normal economic times," Cisco CEO John Chambers said in a statement. "We view the improving economic outlook, combined with solid execution on our growth strategy, as creating unparalleled opportunity to drive more value into the core of the network. The non-GAAP earnings per share were also down, by 14.3 percent. Simply said, we believe that key market transitions across collaboration, virtualization and video will drive productivity and growth in network loads for the next decade, and are evolving even faster than expected. "A new model of productivity based on collaboration is clearly emerging, and we believe this may be the most profound opportunity for businesses in our 25 years as a company," Chambers added. Cisco's board had previously authorized up to $62 billion in stock repurchases.

Cisco also said its board of directors authorized up to $10 billion in additional repurchases of its common stock. There is no fixed termination date for the repurchase program. The remaining authorized amount for stock repurchases under this program, including the additional authorization, is approximately $13.1 billion.

Benioff trumpets Force.com platform's success

Salesforce.com CEO Marc Benioff on Thursday attempted to cement an image of the vendor as a full-blown application development platform provider, not merely a purveyor of SaaS (software-as-a-service) applications. More than 135,000 custom applications have been built with Force.com and more than 200,000 programmers now belong to the company's developer network, the company said. The colorful CEO pulled a familiar arrow from his rhetorical quiver during a keynote address at the Dreamforce conference in San Francisco, decrying the annual software maintenance fees vendors like Oracle charge, and imploring customers of those companies to align themselves with Salesforce.com and its Force.com development platform. "They think it's their purpose in life to collect those taxes on software development [technologies] that were developed a decade ago," he bellowed. "When are you going to ask for innovation instead of paying maintenance?" But according to Salesforce.com, many already have. Salesforce.com claims its system, available by subscription starting at US$25 per user per month, allows companies to develop applications much more quickly and less expensively than with traditional development stacks.

Also, since companies are using Salesforce.com's own cloud infrastructure, there is no need to invest in hardware. Part of the reason for this is that developers do not need to test their applications against multiple combinations of databases, application servers and other components. But Force.com development also presents a trade-off, since it could difficult to port an application built there elsewhere. CA on Thursday announced plans to release CA Agile Planner, a Force.com-built system for managing agile software development projects. Still, Salesforce.com is beginning to attract ample interest from some of the industry's largest software vendors.

Agile development lets teams create many incremental iterations of an application, allowing for continual feedback from end-users and managers along the way. Both companies described how they built ERP (enterprise resource planning) applications on Force.com. BMC executives also took the stage to showcase the company's own Force.com project, a service-desk application that will be released in 2010. The keynote also showcased how Force.com is being used by businesses as well as ISVs. Benioff introduced officials from a variety of companies, including countertop maker Vetrazzo and the Japanese convenience-store chain Lawson. Force.com may indeed be a more convenient method of developing applications, especially if a company isn't dealing with a wealth of legacy systems, said Michael Coté, an analyst with Redmonk. "Just having a Web site to log into, that's a better way of getting IT in general," he said. IT shops will have plenty of cloud development platforms to choose from in the months and years ahead, including Microsoft's Azure, Coté said.

However, "not everyone is lucky enough that they can start from a clean slate," he added. Therefore, the best approach may be to initially experiment with small projects, especially because doing so will help companies determine "how this new way of delivering software affects the business," he said.

FCC identifies roadblocks to broadband adoption

Several factors, including a lack of a broadband subsidy program at the U.S. Federal Communications Commission, have contributed to gaps in broadband adoption in the U.S., a new report from an FCC task force said. The task force suggested that broadband deployment and adoption programs should be included in the FCC's Universal Service Fund (USF) program, which now subsidizes primarily telephone service for rural areas and low-income U.S. residents. Several "critical gaps" in the nation's broadband efforts must be filled before all U.S. residents can get broadband, said the task force, working on a national broadband plan for the FCC. The task force report identified several often-mentioned factors for a lack of broadband adoption, including the cost of the service and a lack of deployment in some areas, but it also focused on some less obvious issues.

Part of the fund, with an annual budget of about US$7 billion, should be shifted to broadband, the task force said. Freeing up new spectrum can take several years, and a handful of studies have predicted a spectrum shortage by the mid-2010s due to growth in subscribers and use of bandwidth-heavy applications, said Ruth Milkman, chief of the FCC's Wireless Telecommunications Bureau. "We know there's a spectrum gap, and we know we need to act in the near term," she said. In addition, the task force recommended that the FCC begin looking for additional wireless spectrum for mobile broadband. The task force report also suggested that video and a convergence between television sets and computers will drive the demand for broadband. There may be ways for the FCC to encourage a retail set-top box market, the task force said. But the TV set-top-box market has seen relatively few innovations in recent years, with most cable subscribers leasing their set-top boxes from their providers, commission staff said.

Another roadblock to broadband adoption is a lack of information about broadband services, the task force said. There is "no shortage of issues" that the FCC should address in its national broadband plan, due Feb. 17, said Eric Carr, general manager of the FCC's Omnibus Broadband Initiative. It can be difficult for consumers to compare the performance of their broadband service to advertised speeds or compare the performance of different broadband providers, the report said. FCC members generally praised the task force's report, but Commissioner Michael Copps said he wanted to see a greater emphasis on civic engagement as a driver for broadband adoption. I want to see a little more heightened emphasis on the point of civic engagement ... and on the point of how this encourages interactivity among the citizens of this great country of ours." Task force members talked about the need for a "fact-based" look at broadband needs, but there are bigger issues as well, Copps said. "This is an exercise that goes beyond metrics and beyond tangibles," Copps said. "I would urge you to look at the intangibles that are involved here.

India schedules 3G license auction for December

India's auction of 3G and WiMax licenses is now scheduled to be held in December, according to a notice on the Web site of the country's Department of Telecommunications. Bidding for 3G licenses will start Dec 7, with the WiMax auction scheduled to start two days after the 3G auction is complete, according to the notice. The auction was originally scheduled for January of this year, but was postponed after disagreement within the government on the minimum cost of the licenses.

Both Indian and foreign companies are allowed to bid for the licenses, but foreign companies will have to set up joint ventures with Indian investors to run services in the country. The Ministry of Communications will license four slots for 3G in each of India's 22 service areas, with a fifth slot reserved for two government-run telecommunications companies. A group of ministers, set up to resolve the dispute over pricing the licenses, has named Indian rupees 250 billion (US$5 billion) as the minimum revenue from the auction of the 3G and WiMax licenses in the country, India's Minister of Communications, A. Raja said last month. A telecommunications company bidding for 3G licenses in all 22 circles will have to pay at least Indian rupees 35 billion, according to the new minimum pricing proposed by the Indian government. Two companies, Bharat Sanchar Nigam Ltd. and Mahanagar Telephone Nigam Ltd., were allotted 3G spectrum ahead of the auction, and have started offering services. By the pricing announced last year, they would have to pay about rupees 20 billion.

The government said last year that these companies would have to pay license fees equal to the highest bid in each service area. The final date for applications from bidders is Nov 13.

Mozilla unblocks one sneaky Microsoft add-in

Mozilla has unblocked one of the two Microsoft-made add-ons that put Firefox users at risk from attack and will probably unblock the second in the next 48 hours, the company's head of engineering said today. "We've unblocked the .NET Framework Assistant," said Mike Shaver, Mozilla's vice president of engineering, on Monday morning. Late on Friday, Mozilla added .Net Framework Assistant and the accompanying Windows Presentation Foundation plug-in to its rarely-used blocking list , which then threw up a warning to users notifying them that the pair was being barred from Firefox. Shaver was referring to one of the two Microsoft components that Mozilla automatically disabled late Friday after deciding it needed to protect Firefox users from a critical vulnerability Microsoft disclosed, and patched, last week. "We got confirmation from Microsoft over the weekend that the add-on wasn't a[n attack] vector for the vulnerability in question," said Shaver.

Mozilla has also pushed out a change that will let users running Firefox 3.5 override the block, added Shaver. The block of Windows Presentation Foundation will likely be lifted in the next two days. "Microsoft is watching the patch deployment numbers, and sharing them with us," said Shaver. "At some point, we'll take the [Windows Presentation Foundation] plug-in off the blocker. That change came out of discussions with enterprise Firefox users who said that they needed the two components to run their .NET-based software within the browser. I expect that to happen in the next 48 hours." Last week, Microsoft's security team acknowledged that its software - which had been silently installed in Firefox as far back as February 2009 - contained a critical vulnerability that could be used by hackers to hijack Windows PCs through Firefox . The vulnerability also affected all versions of Internet Explorer (IE), including IE8. However, the MS09-054 bulletin, which provided details on the vulnerability, said nothing about Firefox. Friday, Shaver cited the severity of the vulnerability and the difficulty some users have had in removing Microsoft's software as Mozilla's reasons for engaging the blocking list.

Later last Tuesday, Microsoft expanded on MS09-054 in a blog post, and confirmed that Firefox users were in danger . Microsoft maintained that Firefox users who applied the patches would be safe from attack, but Mozilla felt that was not enough. Removing the Microsoft add-on and plug-in have been a contentious issue since Microsoft first slipped them into Firefox without users' permission last February as part of the .NET Framework 3.5 Service Pack 1 (SP1) update, which was delivered via Windows Update. Later, Microsoft issued a follow-on update that made it possible to uninstall the components without a registry edit. Users were also furious that the software was impossible to uninstall without editing the Windows registry. Shaver denied that there was miscommunication between Microsoft and Mozilla, and instead characterized it as a "lack of clarity." "We're going to be in better communication," he promised, "especially about things like the version number of the [affected] plug-in." One of the problems Mozilla had last week was determining what - .NET Framework Assistant or Windows Presentation Foundation, or both - was vulnerable, and specifically what versions were at risk to attack. "This was an unusual case of using the blocker," Shaver said. "Version information was not available to us at first, and since [the software] was installed by many users, many of them were unaware they even had it, and the add-on and plug-in were difficult to uninstall, we thought it best to block them, at least for a time.

We do that with add-ons in Firefox now, which checks for those added since the last time you ran the browser. Microsoft agreed." Mozilla has used its add-on/plug-in blocking tool only nine times, including last week's incident, since it first deployed it in 2007. In the future, Firefox will include built-in tools that check whether components have been added by third-party software, then disable the add-on or plug-in by default and notify the user and allow him or her to enable the component(s). That kind of check, if it had existed earlier this year, would have kept the Microsoft software from being installed without Firefox users noticing. "We're big believers in informed user choice," said Shaver. "So we're going to improve notifications to users when plug-ins are installed. We will do the same thing for plug-ins, likely in Firefox 3.7." That version of Firefox, the second of two minor upgrades scheduled for the next six months, is currently slated to ship in March 2010. Since Version 3.0, Firefox has notified users when any new add-ons, called "extensions" by Mozilla, have been installed since the last time the browser was launched. The plan now is to make those notifications clearer, and also to warn about system-installed items before they're running, Shaver said. "We're also building our plug-in check into the product for Firefox 3.6," added Shaver, referring to the outdated plug-in campaign that Mozilla kicked off last month, and bolstered last week when it launched a plug-in checking service . Firefox 3.6 will warn users of outdated third-party plug-ins, like Adobe's Flash or Apple 's QuickTime, when the browser reaches a site that calls upon such software. "We've learned a lot from this," concluded Shaver. "We're not trying to get into an adversarial model, but this was more visible than most [blocks in the past] because of the size of the company involved and the history of the plug-in. "I would call the communication between us and Microsoft 'greatly clarified' as of now," Shaver said. That notification, however, is "poor," acknowledged Shaver, since it simply highlights the new add-ons in a window and most importantly, does so after the add-on has already been installed.

Making Sense of Rapid7's Metasploit Acquisition

News of Rapid7's Metasploit acquisition hit some in the information security community like a clap of thunder. But in the hours after Wednesday morning's announcement, cautious optimism began to take hold. The Metasploit Project has a deep, loyal user base, and it's always unsettling to those who rely on open-source tools when those tools are snatched up by a commercial vendor. Some IT security practitioners started to see the potential benefits of a Rapid7-Metasploit union - providing the vendor handles its new property and user base with great care. "They certainly have acquired an exceptional back-end research capability," said Pete Hillier, CISO at CMA Holdings in Ottawa. "The question is if they can ensure the continuity once the acquisition is complete?" Some are skeptical of that, including Richmond, Va.-based IT security practitioner Rick Lawhorn, who quipped in an e-mail: "The road to hell is paved with good intentions.

It also promised to "sponsor dedicated resources and contributions to the standalone, community-driven Metasploit Project to further its growth and success." "Metasploit and Rapid7 NeXpose are uniquely positioned to improve upon the industry-leading capabilities of both products and to raise the bar on the industry at large," Mike Tuchen, president and CEO of Rapid7, said in a press release. "With our broader solution portfolio, we are the first security provider to meet the demand of enterprises and government agencies in enabling them to identify and mitigate exploitable threats in their IT environment based on their security risk profile." The vendor said Metasploit Project founder HD Moore will become Rapid7's chief security officer and will remain Metasploit`s chief architect. Unfortunately, the ones who will be happy are the bad guys; with a potentially-reduced focus on making things secure and greater focus on profitability." Rapid7, a vendor of unified vulnerability management, compliance and penetration testing tools, said it will use Metasploit to enhance its NeXpose product. For his part, Moore predicts big dividends for his user base. "This acquisition provides dedicated resources to the project, accelerating our growth and allowing us to provide even better solutions to the community," he said in the Rapid7 press release. "Rapid7 recognizes the value of the community and is passionate about the success of the project." Nick Selby, a faculty member of the Institute for Applied Network Security (IANS) and managing director of Trident Risk Management, is among those expressing optimism. "The best thing about the acquisition is that enterprise customers now have three legitimate, sue-able and responsible organizations proffering tools for penetration testing," he wrote Wednesday in the IANS blog. "Quality will likely rise, average price will likely fall, and functionality will likely increase. The Rapid7-Metasploit union will likely shake up that dynamic, to the benefit of buyers and end users, he added. This is a good time to be in the market for pen-test software." See also: Why Pen Testing is Central to Pennsylvania's App Security Selby wrote that the dynamics of the pen-testing market have been that Core Security sat atop the marketplace in terms of price, scale and enterprise usability while Immunity Security "cleaned up at the lower end of the enterprise market" and dominated for vendors and professional services types who also used Metasploit as a free tool.

Boston-based IT security practitioner Zach Lanier said the acquisition is "phenomenal" news for Moore, Egypt (a Metasploit developer, now joining the project/Rapid7 full time), and Rapid7 as a whole. "Naturally, this acquisition will give Metasploit access to more resources, including more full-time team members; Rapid7's knowledge base; and technology and tools," he said. "This will also bring more visibility to Rapid7's vulnerability scanner, NeXpose, given the complementary nature of the Metasploit Framework." Though he's reluctant to simply accept that there will be little-to-no change in the Metasploit Framework's licensing and open source nature, Lanier said he's "pretty confident" Moore and others "will adamantly defend such important principles." Gadi Evron, a security strategist based in Israel, said the acquisition at least goes to show that not-for-profit work can exist in today's market and be competitive enough to draw commercial interest. Asked if he believes Rapid 7 will handle its new acquisition in a way that will benefit users or, at the least, do no harm, Evron said, "One would hope they would, just as one would hope HD made sure they would."