Thursday, January 19, 2012

Top 10 Wireless Industry Predictions for 2012

Top 10 Wireless Industry Predictions for 2012

NEWS ANALYSIS: Once again, Wayne Rash fearlessly predicts what will happen in the mobile and wireless industry in 2012, or in some cases, what won't happen, which might be more...

Published: December 30

http://j.mp/rQ1TXv

This article was sent from the eWEEK App.

NEWS ANALYSIS: Once again, Wayne Rash fearlessly predicts what will happen in the mobile and wireless industry in 2012, or in some cases, what won't happen, which might be more interesting.


For those of us who write about the wireless industry, 2011 was a busy, and sometimes annoying, year. We got to read hundreds of pages of court documents and FCC pleadings for the AT&T acquisition of T-Mobile, which fortunately never happened.

We got to see 4G LTE finally get rolling, at least with Verizon Wireless. And of course we got to see LightSquared claim, with an apparently straight face, that it's perfectly OK for them to destroy the entire GPS industry just so they could sell LTE to carriers. But will 2012 be any better? Of course not.

1. AT& T will deploy 4G LTE country wide

AT&T will field 4G LTE on a national basis, proving that it was lying about needing T-Mobile all along. In fact, AT&T has already started lighting up a few cities with LTE, and now that it's closed the spectrum deal with Qualcomm, the pace should increase. The truth is that T-Mobile had nothing to offer AT&T's LTE plans. The whole thing was a sham so they could take out their low-price competition.

2. T-Mobile will find new partners to expand business

T-Mobile USA will find a new partner to help it grow its business. While it will get some spectrum that it badly needs from AT&T's break-up deal with Deutsche Telekom, it probably won't see any of the breakup fees DT expects to get from AT&T. DT has so many intractable legal problems that it needs all of the money it can get its hands on. Will DT sell T-Mobile USA? Probably not, unless some buyer with tons of money and no potential antitrust conflicts comes along. After all, T-Mobile USA is DT's most profitable foreign operation. Who will that new partner be? Maybe Dish Network and maybe there will be a marketing arrangement with AT&T.

3. No roaming on competing carriers' LTE networks

LTE will remain proprietary, despite the lack of any technical justification. The carriers currently fielding LTE could give their devices the ability to roam on each other's network, but they won't. It's all about marketing and who can claim the best 4G service, despite the fact that they're all basically the same.

4. LightSquared wireless data service is doomed

LightSquared will not be allowed to launch its GPS killing data service. Opposition from the military will ensure it won't happen and the suggestions from LightSquared that the Pentagon could keep GPS interference to a minimum with just a simple upgrade will fall on deaf ears in a time of Pentagon budget cutbacks. Besides, this would mean having to retrofit every one of those GPS-guided smart bombs, cruise missiles, drones and other devices. Unless the military weapons people can be absolutely certain that GPS interference won't cause a drone to launch a Hellfire missile into school instead of a group of terrorists, it's not going to happen. Furthermore the civilian GPS industry will lobby relentlessly against the LightSquared plan, which will encourage Congress to keep a close eye on the issue.

5. Nokia Windows Phone 7 handsets will catch on–overseas

Nokia and Windows Phone 7 will start to blossom, but in Africa, South Asia and the Middle East where people need smartphones; where Nokia has a huge installed base; and where nobody can afford an iPhone. Sales will pick up in the U.S., too, but not like sales overseas. Around the end of 2012, Microsoft will start throwing serious marketing money at WP7 wherever there are signs of sales momentum. Despite rumors, Microsoft will not buy Nokia.

6. Look for a 7-inch Apple tablet early in the year

Apple will release a 7-inch (or thereabouts) version of the iPad. Now that Amazon is selling a million 7-inch tablets a week, it's clear that the market exists. While Steve Jobs ridiculed 7-inch tablets before he died, he's not around anymore and Apple executives are smart enough to know a hot market when they see one. Besides, a 7-inch tablet is the perfect size for a lot of tasks where an iPad is just too big. The announcement will be early in the year when the iPad 3 is announced, and the new 7-inch version might not be called an iPad.

7. Amazon will add 3G or 4G connectivity to Kindle Fire

Amazon will introduce 3G (or maybe 4G) capabilities for the Kindle Fire once it starts to look like the market for WiFi-only devices is becoming saturated. However, it won't be an all-you-can-eat plan like the one that the original Kindles came with. The Kindle Fire is far too capable of running data-intensive applications, such as movie watching, for an unlimited data plan to work. So guess what? It'll be the same type of plans that the iPad has and probably with the same carriers.

 

8. Prices for 7-inch tablets will hover around $225

Competition from the Kindle Fire and the Barnes and Noble Nook as well as the hefty 2011 sales of the HP TouchPad and the BlackBerry PlayBook once their prices were slashed will make $225 the market sweet spot for 7-inch tablets. While Samsung and others will try to keep high-end 7-inch tablet prices close to where they are now, their days are numbered. In fact, Apple's new 7-inch tablet will sell for less than the current iPad because of the competitive price pressure.

9. Using a smartphone will get more costly

As the popularity of 4G wireless grows, the price will go up, data caps will get lower and using a smart phone will get more expensive. WiFi calling, pioneered by T-Mobile, may start to show up with other carriers, most likely Sprint where it would help keep backhaul costs under control.

10. Guerilla WiFi phone access to fight rising 4G costs

The "Occupy" movement will inspire an "Occupy Wireless" concept in which people will take it on themselves to help fight the growing prices of 4G access by opening up their WiFi access points using unregulated guest access, thus offering free wireless service to anyone within range. Some will do this just by changing the settings on their routers, while others will find ways to install rooftop antennas that support 802.11n over a wide area. ISPs will try to fight it, but their efforts will fail. The big wireless companies will ignore this until it becomes clear that a lot of people are using this free WiFi instead of 4G. T-Mobile may see growth in their WiFi-calling equipped phones in areas where this practice is common.




Smartphones, Tablets, Android Are Why Malware Is Going Mobile in 2012

Smartphones, Tablets, Android Are Why Malware Is Going Mobile in 2012

NEWS ANALYSIS: As 2012 gets going, it's time to accept that malware and cyber-attacks will increasingly target mobile users and Internet applications. For years, computer users' biggest security threats were...

Published: Yesterday

http://j.mp/wOBJxd

This article was sent from the eWEEK App.

NEWS ANALYSIS: As 2012 gets going, it's time to accept that malware and cyber-attacks will increasingly target mobile users and Internet applications.



For years, computer users' biggest security threats were attacks against their desktop computers and applications. But cyber-criminals increasingly have been turning their sights toward mobile devices and Web applications, as they are fertile new ground for lucrative cyber-attacks.

It won't happen overnight, of course, and there will still be more than enough security flaws impacting Windows and other desktop platforms to keep companies like Symantec and McAfee in business for years to come. But for mobile device users, security applications are as much a requirement for them as they are for desktop computer users.

Cyber-criminals have spent the past several years developing new attack strategies for mobile applications and devices. And this year, they're going to try to break in every chance they get.

Read on to find out why security threats are increasingly going mobile this year.

1. Windows 8′s security

According to Microsoft and the security researchers who have tried out Windows 8, the operating system will be the best yet at protecting users. In fact, some say that all users will need is Microsoft's own security suite to safeguard their computers. That's a major development in the Windows ecosystem. If Microsoft can actually deliver on those lofty promises, cyber-criminals may shift their attention from the desktop to online targets. But a really secure Windows 8 could go a long way toward showing the industry at large how to build security into mobile and Web applications as well as desktop applications.

2. Cloud services are a cash cow

Cloud services are a potential cash cow for cyber-criminals. In enterprise-focused applications, they can include bank information and Social Security numbers to just about anything else. What's worse, enterprises and consumers accessing cloud applications are placing all their hope in the service provider to protect their data when there is a serious risk that cloud services can be penetrated by cyber-criminals, who could reap boatloads of cash from stolen information.

3. Social networks are too

As the Koobface worm has proved, there's an inordinate amount of money in targeting social networking users. A new report from the New York Times claims the people allegedly behind Koobface generated millions of dollars just by taking aim at social network users. Security experts say the cyber-criminals behind Koobface are still active and it's likely that they or copycat hackers will launch new Koobface variants or Koobface-like attacks this year.

4. Android use is exploding

Unfortunately, Android has quickly become an easy target for malicious hackers around the world. The operating system is the most popular mobile OS for cyber-criminals, and most security researchers believe that trend will only continue in 2012. So, why is that happening? For one thing, the operating system doesn't have all the safeguards found in, say, BlackBerry OS. What's more, a tremendous number of people are adopting the software each day. That presents an ever larger and highly lucrative target for cyber-criminals. Keep that in mind.

5. Apps are easy entryways

After Apple launched the App Store and other companies followed suit, smartphone owners around the world assumed they could download any program to their mobile devices with complete confidence and safety. But as last year's Android Market infiltrations showed, that's not the case. Even so, users don't realize the threats associated with apps, and how easily they can be used against them. Even text-messaging applications can deliver malicious payloads. Apps are a unique and hugely profitable opportunity for cyber-criminals, and this year they're not going to let that slip by.

6. Where are all the security apps?

Interestingly, security companies have been somewhat slow to deliver mobile anti-malware applications to safeguard mobile devices. The big firms, like McAfee, offer some apps, of course, but as with early Windows software, they don't appear to be keeping up as well as they could with all the threats out there. Even cloud security solutions are subpar. It's about time the security community gets far more serious about protecting people both online and on the Web.

7. User ignorance is a factor

It's no secret that one of the main reasons Windows became such a security hole was that its users let it happen. Too often, PC owners don't update security software, go to malicious sites and trust sources that they shouldn't. In the mobile and online world, things are even worse. Unfortunately, people have been conditioned to believe that the real threats are on Windows, when in reality, they're also present on the Web and in mobile operating systems. Study after study has shown that people are especially lax about security when using a smartphone. This year, cyber-criminals will capitalize on that in a big way—and we'll all rue the day we failed to acknowledge the importance of security no matter where we are.

8. The enterprise is moving there

If history is to be our guide, it will show that whenever the enterprise goes to a new technology or service, cyber-criminals will follow. Now, the enterprise is shifting to mobile products, like the iPhone and iPad, and cloud services. Seeing a potential cash windfall, cyber-criminals are pouncing. Make no mistake, the enterprise's shift to the Web and mobile is a big reason cyber-criminals are doing the same.

9. Solutions are few and far between

Just about everywhere one turns, they'll find a security company or analyst talking about the increased threats we'll be facing in the coming months. But at what point do all those analysts and researchers deliver a solution to safeguard users? Sure, there's security software and other online safeguard mechanisms, but it's not enough. Solutions are needed to identify cyber-criminals, anticipate their actions and respond with a way to stop them.

10. The opportunities are endless

The move to mobile and cloud computing has brought about an endless universe of inviting targets. No computing device connected to the Internet is immune. New opportunities for cyber-criminals to target users are nearly endless. Should they go after us via email, hacked Websites, SMS messaging or malware-tainted apps? How about social networks? Mobile devices and the Web provide an endless array of opportunities for cyber-criminals to hit us. The challenge is for the technology industry to find innovative and broad solutions to the ever-expanding array of cyber-threats.




Sunday, December 18, 2011

Cyber-Attackers Successfully Exploiting Java Flaw in Outdated Software

Cyber-Attackers Successfully Exploiting Java Flaw in Outdated Software

SUMMARY: Here's more proof that people aren't regularly patching software: Most of the attacks in the first half of 2011 exploited Java bugs that Oracle had patched over a year...

Published: November 30

http://j.mp/tBuUwv

This article was sent from the eWEEK App.

SUMMARY: Here's more proof that people aren't regularly patching software: Most of the attacks in the first half of 2011 exploited Java bugs that Oracle had patched over a year ago.



Cyber-attackers continue to target vulnerabilities in Java, even the ones that Oracle has already patched, because end-user systems aren't being properly updated, Microsoft warned.

"Between one-third and one-half" of all attacks detected and blocked by Microsoft's security software from the beginning of July 2010 to the end of June 2011 were Java-based, Tim Rains, a director of Microsoft's Trustworthy Computing group, wrote Nov. 28 on the Microsoft Security blog. Microsoft's anti-malware technologies blocked more than 27.5 million Java exploits over a 12-month period, many of which had been patched at least a year ago, Rains said.

Microsoft researchers have noted in previous Security Intelligence Reports that attacks targeting Java exploits have been increasing, and they surpassed Adobe-related attacks in volume last year. The latest volume of the Microsoft Security Intelligence Report, volume 11, found that the most commonly observed type of exploits in the first half of 2011 targeted Oracle's Java Runtime Environment (JRE), Java Virtual Machine (JVM) and Java SE in the Java Development Kit (JDK).

"Attackers have been aggressively targeting vulnerabilities in Java because it is so ubiquitous," Rains said, noting that Oracle claims over 3 billion devices run Java.

The most commonly blocked attack in the first half of 2011 exploited a JRE bug discovered and patched in March 2010. The exploits first appeared during the fourth quarter of 2010, at least six months after the patch was released, and increased "tenfold" in the first quarter of 2011, according to Rains. The second most commonly blocked exploit relied on a JVM flaw that allowed an unsigned Java applet to gain elevated privileges outside the Java sandbox and exists in JVM 5 up to update 22 and in JVM 6 up to update 10. It was patched in December 2008. Others on the list included a JVM bug patched by Sun Microsystems in November 2009 and a different JRE flaw patched by Oracle in March 2010.

"Once attackers develop or buy the capability to exploit a vulnerability, they continue to use the exploit for years, presumably because they continue to get a positive return on investment," Rains said, noting that this tactic is not unique to Java flaws, but in "all prevalent software."

System administrators and users should regularly update Java and keep up with the updates, Rains said. Some environments may have systems running different versions of Java, as well.

Some security experts recommend not installing Java by default and limiting the installation to only those systems that actually require it. "Most people aren't using Java these days, and it reduces the attack surface for exploits delivered over the Internet," said Chester Wisniewski, a senior security adviser at Sophos. "Less software plugged" into the browser means less chances for an attack to succeed, he said.

Security analyst and writer Brian Krebs recently uncovered an instance of malware exploiting an already patched Java flaw, with the resulting exploit being bundled with a crimeware kit available for sale on criminal underground forums.

The new Java exploit is being distributed as a free add-on to existing owners of the BlackHole crimeware kit, or priced at $4,000 for new owners. A three-month license for the crimeware kit itself costs $700, and hosted servers running the malware toolkit are also available, according to the post on Krebs on Security.

Java exploits are "notoriously successful" when bundled with commercial exploit packs, according to Krebs. Cyber-attackers can use the BlackHole kit, which extensively uses Java flaws, to launch malicious Websites that can download malware on unsuspecting site visitors running an outdated version of Java, he said. Even though it is a relatively new malware toolkit, BlackHole has become one of the more popular exploit kits this year, according to security experts.

This particular vulnerability exists in the Java Runtime Environment Component in older versions of Oracle Java, namely Oracle Java SE JDK and JRE 7 and Java 6 Update 27 and earlier. Users with the latest version of Java, such as Java 6 Update 29 or Java 7 Update 1, are not affected. Oracle patched this flaw in mid-October with 19 other script engine bugs.




Five Key Enterprise Development Trends

Five Key Enterprise Development Trends

SUMMRY: eWEEK identifies major areas on which developers should concentrate. As we head into 2012, enterprise developers will need to focus on some major themes, including the emergence of HTML5,...

Published: December 5

http://j.mp/vUf9ZA

This article was sent from the eWEEK App.

SUMMRY: eWEEK identifies major areas on which developers should concentrate.


As we head into 2012, enterprise developers will need to focus on some major themes, including the emergence of HTML5, "big data" and analytics, and Agile Application Lifecycle Management (ALM). They should also continue to concentrate on Web, mobile and cloud development, and take advantage of advances in languages and integrated development environments (IDEs).

HTML5 is going like gangbusters. Microsoft has adopted HTML5 for Windows 8, Internet Explorer 9 and upcoming versions of the browser and other products. And there are indications that Microsoft may shelve future development of Silverlight, a development framework for building Web and mobile applications, after Silverlight 5 or a subsequent point release.

The onset of HTML5 also drove Adobe to halt its development of its Flash technology for mobile browsers.

"HTML5 is coming on strong as a standard, accelerated by the speed of change of hardware devices," said Al Hilwa, an analyst with IDC. "By 2013, we will reach a point where 90 percent of smartphones and tablets will sport HTML5-capable browsers."

However, Hilwa notes that it is important to remember that the need for a Flash browser plug-in continues on the desktop. "We don't expect 90 percent of desktop browsers to be capable of HTML5 until 2015," he said. "So the differentiation that Flash provides in high-end graphics and video protection continues, and Adobe will continue to invest in it."

Web-based development environments, such as the Eclipse Orion, Cloud9 IDE, eXo Cloud IDE and others, are becoming more and more popular. "Web-based tools will become more important as development moves into the cloud," said Mike Milinkovich, executive director of the Eclipse Foundation. "However, we should expect a new way of thinking about Web-based IDEs. Trying to fit something like Eclipse into a Web browser just won't scale. The nice thing about Orion is, it attempts to make the browser your IDE."

The big data and analytics craze will continue to grow due to the explosion of data coming from intelligent devices, social media and other sources. According to IDC, the market for intelligent systems will grow substantially in the next few years, from 800 million units today to more than 2.3 billion by 2015. Shipments of embedded devices already exceed those of cell phones and PCs, and IDC predicts the market for intelligent systems will soon represent a $520 billion industry.

"Data has become the new currency," said Kevin Dallas, Microsoft's Windows Embedded general manager. As proof of how hot big data has become, venture capital firm Accel Partners launched a $100 million big data fund at the recent Hadoop World 2011 conference.

Meanwhile, "One of the most important trends in 2012 will be the maturation of Java PaaS [platform as a service]," said Mik Kersten, CEO of Tasktop Technologies. "While the transition will be a long one, Oracle's Java Cloud culminates key announcements around PaaS offerings in 2011, and sends a signal that Java developers [should] start considering PaaS solutions as the deployment destination of new applications."

The Eclipse Foundation's Milinkovich said he believes the concept of Agile Application Lifecycle Management is becoming a reality. Developers are integrating new tools chains to support Agile development and a faster release process, he said.

"On the ALM side, a key trend to watch [in] 2012 is the open-source-powered tidal wave changing how developers work and collaborate," Tasktop's Kersten added.




Monday, November 14, 2011

Legal Issues with Cloud in UK.


Cloud computing did not exist when data protection regulations came in. John Roberts of Redstone explains how to keep within the law
The UK Data Protection Act (DPA) is often regarded as the world's leading law on protecting personal data. But many UK companies now adopting cloud services are not only putting data at risk, but also themselves, by breaching data protection laws. How do you comply with the DPA, whilst maintaining a cloud presence? When the UK government passed the DPA in 1998 it was heralded as the definitive way to guarantee personal data was protected. Over the following decade, refinements to the act ensured that personal data was not just secure, but more specifically, it was secure online. This worked well when data was held on-premise, within a company's own data centre, but the advent of cloud technology has changed all that.

What do we mean by cloud?

Just to be clear, in this context we're referring to 'cloud' as infrastructure as a service. Ask many cloud service providers (CSPs) where a specific piece of data is held, and it would take them a while to answer. In most instances the cloud does not recognise national boundaries. CSPs simply move data across their often globally dispersed infrastructure at will in the most efficient way for them. This means that the IT director no longer knows where his or her data is, nor are they able to comply with the DPA. With data being streamed and stored across national territories, it also runs the risk of falling foul of other countries' legislation. When George W Bush signed the US Patriot Act into law in 2001 following 9/11, no one could have predicted the data protection conflict that would occur between the UK and US as a result. The two acts lie in direct opposition of each other. The UK DPA prohibits organisations passing personal data on to another party, yet, the US Patriot Act expressly permits the US government to access and examine any data – personal or otherwise – that's held by a US company. Security has long been a real concern for IT directors considering cloud infrastructures but previous anxieties have focused on data loss rather than location – a legal requirement enforceable under the DPA. Location of data has to become a priority, considering the words of Microsoft UK MD Gordon Frazer this summer who admitted that the US Patriot Act took precedence over the DPA. Not only does this mean trouble for UK companies using cloud services where data is stored in the US, it also means that the data of US companies operating outside of its borders are also subject to this priority, affecting some of the world's largest CSPs – from Microsoft and Salesforce, to Google and Amazon. The EU, UK and other nations are debating the issue. The EU has negotiated a safe harbour agreement with the US to protect data. However, since most CSPs are unable to assure customers where data is located, the bigger question has to be: just whose responsibility is data storage when operating in the cloud? The Information Commissioner's Office (ICO) is responsible for enforcing the DPA, and its latest annual tracking survey found that one in four companies are still unaware of the need to comply with the DPA. While many companies may plead ignorance, we've found a more concerning trend. When it comes to the cloud many data owners believe data protection responsibility lies with the CSP, or more worryingly, are simply using the cloud as a way to abdicate responsibility for storing and protecting their data. This company apathy to data protection is widespread. We know this from experience. Rarely are we asked by prospective customers to ensure that data held within our cloud service is stored in the UK – compliance is simply not considered an issue when buying cloud services.

With power comes responsibility

Many cloud services are problematic because they provide a generic, one-size fits all solution. Yet as cloud services have evolved, alongside customer needs, more tailored solutions have appeared, including UK-specific, DPA (and PCI) compliant services. With these services 'control', a concern cited by many IT directors when considering cloud services initially, has been given back to the IT department. With that control, however comes the responsibility for data protection. The other failure occurs with the law itself. While the DPA provides stipulated requirements for the protection of data, it is enforced retrospectively not proactively. That means that companies are only prosecuted once a breach has occurred. The ICO has no power to audit private sector companies' compliance to ensure that a data breach doesn't occur in the first place. Having no audit control over the private sector makes it impossible to proactively regulate and enforce the DPA. It's generally accepted that the private sector generates the most data protection complaints. As a result, the information commissioner Christopher Graham, recently called for compulsory audit powers for the private sector. Data audits need to become a requirement within the financial and legal audit processes if companies are to be held accountable for data protection. We think that the solution may be simpler. What the industry (and companies operating in the cloud) needs to assist in compliance is a series of DPA standards. Comparable to ISO 9000, a simple checklist of standards would provide companies with a way to effectively measure themselves as part of any risk assessment or business continuity plan. We've seen how well they work for quality management, so now it's time to apply the same theory to the question of data protection. 
Source : eweek


Code Search for Open Source Holes

Tools such as Google Code Search can provide hackers with a wealth of information hidden in open source code, writes Eric Doyle

The downside of open source is its very openness. Hackers are using Open Source Intelligence (OSint) to find personal information and even passwords and usernames to plan their exploits.

Organisations like Anonymous and LulzSec have been using Google Code Search - a public beta in which Google let users search for open source code on the Internet - according to Stach & Lui, a penetration testing firm.  In Code Search, they can unearth information to assist them in their exploits, for instance finding passwords for cloud services which have been embedded in code, or configuration data for virtual private networks, or just vulnerabilities that lay the system open to other hacking ploys, such as SQL injection.

Google Hacking

The Google service is due to be switched off next year as part of the company's rationalisation of its research efforts with the closure of Google Labs but that does not mean that exposed code on the Internet will be safer. There are several sites which provide similar services.

 Google's BigTable is the repository of most things the company gleans from its searches, and searching it for nefarious purposes is known as Google Hacking.

A-Team, a white-hat hacking group which appears to have the sole purpose of exposing Anonymous and its various subgroups, wrote a highly critical, sneering condemnation of Google Hacking.

"LulzSec and Anonymous [are] believed to use Google Hacking as a primary means of identifying vulnerable targets," the group blogged in June this year. "Their releases[revelations] have nothing to do with their goals or their lulz [fun]. It's purely based on whatever they find with their 'google hacking' queries and then release it."

Mark Stockley, an independent Web consultant, wrote on the Naked Security blog, "While the findings provide a much-needed wake-up call to online businesses, admins and developers, they also offer a fascinating insight into the motivation of hacking collectives such as Anonymous and LulzSec...

"Rather than being motivated by politics or injustice, hacking groups may simply be targeting organisations because Google Code search has turned up a vulnerability too tempting to ignore, making them less political action groups, more malicious 21st century Wombles," he said.

The best protection is to ensure that nothing is included in code that is useful to a hacker. If it is unavoidable then the information should be stored separately and encrypted.

Colin Tankard, managing director of encryption and security specialist Digital Pathways, advised, "Obviously if the data is encrypted it protects that data wherever it goes as long as the key is never stored with the data. This adds extra control of who or what application is allowed access to the data. By applying encryption with access control organisations can define who or what is allowed access to data."

Source: eWeek