Thursday, September 8, 2011

Google mulls Android favourites

Court papers have thrown light on how Google gives some firms early access to Android technology.

The documents detail an internal Google discussion about how to make the most of the mobile operating system.

They explain the quasi-open nature of Android and reveal why it lets firms that keep to Google's specifications put products on sale first.

The policy assumes new significance given Google's bid to buy Motorola's mobile unit, say analysts.

Cashing in

Excerpts from the court papers were posted to the blog of patent expert Florian Mueller. The documents were filed to a US court as part of Google's defence in its legal wrangle with Oracle over some of the code in Android.

One page highlighted by Mr Mueller and labelled "Confidential and Proprietary" lists some of the ways Google profits despite Android being freely distributed.

It discusses the value of granting "early access" to partners who build and market devices to Google's standards and specifications.

The document cites the example of Motorola and US network Verizon.

This, argues Google, allows the companies to sell products that make use of new features and gives them a "time to market" advantage.

The page also mentions the idea of a "lead device" that would launch with a new version of the code already installed.

It also states baldly that to profit, Google should "not develop in the open". As has been seen with Android, Google prefers to get the code working internally before it is released more widely for others to tinker with.

What is not yet clear is when the papers were drawn up, whether it was during the early days of Android or more recently.

Mr Mueller said the mention of "early access" should worry firms making handsets that run Android. It suggests, he said, that Google has a "stated commitment to a non-level playing field".

A Google spokesperson said: "We have had a "lead device" strategy publicly for years with a variety of manufacturers including HTC and Samsung".

The spokesperson cited the example of Samsung's Nexus S - the lead device for the Gingerbread release of Android co-developed by Google and Samsung.

Pete Cunningham, principal analyst at market research firm Canalys, said the, "lead device" policy had operated since the earliest days of Android.

"Every time there's been a major launch of Android, there's been a 'hero' product that comes out with it," he said.

Before now that had not meant Google playing favourites even though being a lead device usually meant greater publicity and higher sales, said Mr Cunningham.

If Google gets permission to buy Motorola's mobile unit that might mean the end of the policy of giving different manufacturers lead device status, he said.

"If Motorola get that advantage consistently then alarm bells may start ringing at those other handset makers," he said.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Wednesday, September 7, 2011

Web authentication breach spreads

Belgian security firm GlobalSign has temporarily stopped issuing authentication certificates for secure websites.

It comes after an anonymous hacker claimed to have gained access to the company's servers.

If confirmed, it would be the second security breach at a European certificate authority in two months.

Hundreds of bogus DigiNotar authentications were issued following an intrusion into its systems.

Certificate authorities (CAs) are companies or public bodies whose job is to confirm that secure websites are genuine.

When computers connect to a site with TLS or SSL authentication, a certificate is issued which verifies the site's identity to the web browser.

Fake certificates could allow someone to spy on a user's activity.

Multiple targets

GlobalSign took action as the result of a posting which appeared on the online notice board Pastebin.

The author, who identified themselves only as "ComodoHacker", claimed to have gained access to four certificate authorities, in addition to DigiNotar.

Only GlobalSign is named, although the message points out that an attack on StartCom was foiled by its boss Eddy Nigg.

ComodoHacker also refers to an attack on US certificate authority Comodo, which was targeted in March.

As a precaution, GlobalSign said it was temporarily ceasing the issuance of all certificates while it investigated the claims.

The hacker also played down suggestions that the attacks were the work of Iranian authorities.

"I'm single person, do not AGAIN try to make an ARMY out of me in Iran. If someone in Iran used certs I have generated, I'm not one who should explain," said the posting.

It had been suggested that, because many of the bogus DigiNotar certificates were issued to users in Iran, that authorities in there may have initiated the CA hack as a tool for spying on dissidents.

A report on the DigiNotar attack said that up to 300,000 Iranians may have had their Gmail accounts monitored as a result of a fake Google certificate being created.

Hacktivist

While the anonymous posting contains no information about the identity of the CA hacker, it does detail a political agenda.

The message states: "Dutch government is paying what they did 16 years ago about Srebrenica, you don't have any more e-Government huh?"

It appears to reference the apparent non-intervention of Dutch peacekeeping forces during the notorious 1995 Srebrenica massacre, where Serbian forces killed more than 8,000 Bosnian Muslims.

DigiNotar certificates are used to authenticate many online services offered by the Dutch government, although the company has said that these use a separate system which was not compromised during the attack.

State prosecutors in the Netherlands are investigating the incident.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Online firm Yahoo fires CEO Bartz

Yahoo's chief executive Carol Bartz has been fired by the internet company after two-and-a-half years in the top job.

The company said in a statement that Ms Bartz was removed by the board of directors, effective immediately.

Tim Morse, Yahoo's chief financial officer, will take over from Ms Bartz.

Yahoo has been struggling to increase its market share as it faces increased competition from rivals such as Google and Facebook.

Yahoo shares jumped more than 6% in after-hours trading after news of the firing broke, indicating they would trade higher when Wall Street opens for business on Wednesday. Yahoo's stock price was up at $13.72, an increase of 81 cents.

Mr Morse will serve as interim chief executive and the board of directors will look for a new CEO, the company said.

No turnaround

Ms Bartz was hired to run Yahoo in early 2009, taking over from co-founder Jerry Yang.

She made significant changes to the management team and cut jobs to save on costs. She also shifted the focus of the traditionally search-oriented firm towards more personalized content.

"Start Quote

I am very sad to tell you that I've just been fired over the phone by Yahoo's chairman of the board"

End Quote Carol Bartz Former CEO, Yahoo

However, Larry Magid, a technology analyst at C-net, said the company has not seen enough of a turn-around under Ms Bartz's leadership.

"She hasn't done anything to change the company's fortunes, and they are still anxious to find a leader who can move them up," he said.

Critics also claim that Yahoo has failed to make significant strides in two of the most lucrative segments of the market; search and social networking.

"Facebook is way ahead, and now even Google is way ahead of Yahoo in social networking," C-net's Mr Magid added.

"In terms of the potential for long-term revenue it's just not there. They've got some great sites, great information resources, news, stocks, sports, but that's not what bringing in the money."

Phone firing

The news first broke on the Wall Street Journal's All Things D website, which quoted an email from Ms Bartz to Yahoo staff. The email has since been reported by other news agencies including Bloomberg and Reuters.

"I am very sad to tell you that I've just been fired over the phone by Yahoo's chairman of the board," Ms Bartz said in the email to staff.

"It has been my pleasure to work with all of you and I wish you only the best going forward."

As news of the sacking spread across the internet, Yahoo released its own press statement in which it confirmed it was undergoing a "leadership reorganisation" and that Ms Bartz would be leaving the company.

Roy Bostock, chairman of Yahoo's board, said in the statement: "On behalf of the entire board, I want to thank Carol for her service to Yahoo during a critical time of transition in the company's history, and against a very challenging macro-economic backdrop."

He added that he saw "enormous growth opportunities" for the firm.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Tuesday, September 6, 2011

Iranians hit in email hack attack

Up to 300,000 Iranians may have had their Google email monitored using security certificates stolen from Dutch firm DigiNotar.

The figure came from a report into the breach at DigiNotar which let attackers generate hundreds of fake certificates.

The report suggests the certificates were used in Iran to eavesdrop on email accounts.

The list has been passed to Google so it can tell victims they may have come under government scrutiny.

On 30 August, security firm Fox-IT was called in to analyse the sequence of events at DigiNotar that led to the security breach. It published its interim report late on 5 September.

DigiNotar is one of many firms which help to ensure that no-one is eavesdropping on secure communications between users and the sites they visit.

It does this via security certificates which act as a guarantee of identity so people can be sure they are connecting to the site they think they are.

Anyone armed with a rogue certificate for a web firm or service can impersonate that organisation and get at communications that would otherwise be impossible to read because they are encrypted.

"Start Quote

The network has been severely breached"

End Quote Fox-IT

DigiNotar first took action to revoke fake security certificates on 19 July when it found that hackers had got access to its internal network.

The Fox-IT report suggests that the hackers were able to access those internal systems for a month before DigiNotar took action.

The first exploration by the hackers took place on 6 June, suggests the report, and the first rogue certificates were issued on 10 July.

"The network has been severely breached," said the report. It said security procedures at DigiNotar were clearly lacking because the tools the hackers used and installed on network computers can be detected by standard anti-virus software.

All evidence gathered by Fox-IT suggests that the attacks were carried out to help surveillance of Iranian net users. More than 99% of the 300,000 IP addresses known to have connected to Google's email service with the help of a fake security certificate are in Iran.

Fox-IT noted that the use of the fake certificates would also have given attackers access to small text files known as cookies that Google and many others use to recognise regular visitors.

As a result, Fox-IT said: "It would be wise for all users in Iran to at least logout and login but even better change passwords."

DigiNotar has called on the Dutch government to help it recover following the attack. In its wake Google and many others have issued updates to ensure that the fake certificates are no longer recognised.

DigiNotar is the second security certificate firm to suffer at the hands of hackers. In March 2011, Comodo revealed that it had been hit and pointed the finger at Iran.

Now evidence is emerging that the same hackers were behind both attacks according to a message posted to the pastebin website. In the message, the hacker or hackers claim to have access to four other security certificate firms.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Dell in tie-up with China's Baidu

Dell has confirmed it is one of a number of companies partnering with Baidu, China's top search engine, on mobile devices.

A Dell spokesperson said the company was developing smartphones that would run Baidu's new software platform for the Chinese market.

Baidu announced the platform, Baidu Yi, on Friday.

Many Chinese internet companies are trying to increase their presence in the mobile market.

"The partnership is to provide users with an out-of-box experience, so Baidu Yi will be installed," said Dell spokesperson Adeline Lee.

Baidu Yi is Android-based, but Ms Lee did not say with operating systems would be installed on the Dell smartphones.

Baidu executives have not ruled out the possibility of releasing their own operating system at a later date.

Baidu's announcement also said that it was working with a number of developers and handset makers as part of an alliance to support the Baidu Yi platform.

Ms Lee would not give a date for the release of the Dell smartphones.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Monday, September 5, 2011

Fake certificate risk to Iranians

Fresh evidence has emerged that stolen web security certificates may have been used to spy on people in Iran.

Analysis by Trend Micro suggests a spike in the number of compromised DigiNotar certificates being issued to the Islamic Republic.

It is believed the digital IDs were being used to trick computers into thinking they were directly accessing sites such as Google.

In reality, someone else may have been monitoring the communications.

Hundreds of bogus certificates are thought to have been generated following a hack on Netherlands-based DigiNotar.

The company is owned by US firm Vasco Data Security.

Web passport

Authentication certificates are used by many websites to give their users secure access.

Typically these take the form of a TLS or SSL connection - which can be identified by the appearance of a padlock logo and "https" prefix.

Together, they are supposed to guarantee that the site is what it appears to be, and that the user's session is not being monitored.

Hundreds of bodies - known as certificate authorities (CAs) - are allowed to provide such authentication.

Web browsers, such as Safari, Chrome, Firefox and Internet Explorer have a built-in list of which CAs they can trust.

However, if a third-party was able to steal certificate details or generate their own, they may be able to launch a "man-in-the-middle" attack, similar to tapping a phone line.

The presence of an apparently genuine certificate means browser security would be unlikely to detect the surveillance.

Issued and revoked

On 19 July, Dutch CA DigiNotar detected an unauthorised intrusion into its systems.

The company immediately revoked a number of bogus certificates that had been created as a result.

It emerged later that some were missed, and other new ones generated, after the initial attack.

Unconfirmed information published online suggested that more than 500 false DigiNotar certificates exist.

Among the domains listed are Google, Facebook, Twitter and Skype.

At the same time, it was noticed that a sizeable portion of the Dutch company's certificates were mysteriously going to users in Iran.

By August, 76.5% of DigiNotar validations were in the Netherlands. 18.7% were in Iran and 4.8% elsewhere in the world, according to security firm Trend Micro.

Iranian activity dropped off after the certificates were revoked.

DigiNotar eventually went public about the intrusion on 30 August, at which time most web browsers stopped recognising DigiNotar certificates altogether.

Soft target

There are many reasons why Iran may have been targeted using the bogus certificates, according to security experts.

The republic's tight controls on dissent mean that monitoring web traffic could yield useful information.

Iran's internet setup also makes some types of interception easier, according to Rik Ferguson, Trend Micro's director of security research and communications.

"All the internet traffic has to go through an Iranian government proxy before it goes out to the final destination.

"If you want to spy on normal HTTP traffic, that is not a problem - you get to see all the outbound requests and all the inbound responses," he explained.

For secure websites, attempts to intercept would ring alarm bells with the web browser and therefore the user.

One option is to make the Iranian national proxy server look like it is the target website - using a fake DigiNotar certificate.

The proxy then relays information to and from the real website, e.g. Google.com, but there is no indication that the secure chain has been broken.

Government involvement?

While much online debate has centred around the role of the Iranian authorities, there is no firm evidence to support such a theory.

However, a spokesman for the Dutch Interior Ministry, Vincent van Steen told the Netherland's-based ANP news agency that the cabinet was looking into claims of Iranian government involvement.

Iran has previously been on the receiving end of cyber attacks, including the elaborate Stuxnet conspiracy which enabled a computer worm to take control of machinery in a uranium enrichment plant.

The DigiNotar incident has also raised broader concerns about the security of the global certificate authorisation system.

"The more there are, the more opportunities there are to attack the system," said Paul Mutton, a security analyst from Netcraft.

"Whenever there is a certificate authority that is trusted by all the mainstream web browsers, if someone was to compromise them it is just as bad as compromising the largest CA."

Alternatives to the current system have been suggested, including one by former hacker Moxie Marlinspike, known as Convergence, which verifies site authenticity by checking with multiple online "notaries".



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Hackers carry out website hijacks

Visitors to the websites of Vodafone, the Daily Telegraph, UPS and four others were re-directed to a site set up by Turkish hackers on Sunday night.

The divert was the result of the group's attack on computers that hold web address information.

Real URL names were deliberately mistranslated into the IP address of the hackers' site.

No data from the seven victims was lost or compromised as a result of the attack.

The hacking group, called Turkguvenligi, targeted the net's Domain Name System (DNS).

This acts as an address book for the web and turns the names that people use (e.g. bbc.co.uk) into IP address numbers that computers understand (e.g. 212.58.246.90).

DNS is consulted by a person's web browser when they want to visit a particular site.

In its attack, the Turkguvenligi group changed the records relating to seven sites in DNS databases run by NetNames and Ascio - two subsidiaries of domain name management firm Group NBT.

In an interview with The Guardian, Turkguvenligi revealed that it got access to the files using a well-established attack method known as SQL injection.

It said it had targeted the sites and found that attacking their DNS records was the easiest way to achieve their ends.

"The hardest one is reaching the domain company but if you can succeed there will be a treasure for you," Turkguvenligi told The Guardian.

According to Zone-H, which logs website defacements and hack attacks, Turkguvenligi has carried out 186 defacements since late 2008.

In a DNS attack, the sites targeted are not affected at all. The only impact is for visitors who will be re-directed to a site they were not expecting.

A statement by The Register about the attack suggests the re-direct was active for about three hours.

Writing on the blog of security company Sophos, Graham Cluley said: "We have to be grateful that the message displayed appears to be graffiti, rather than an attempt to phish information from users or install malware."

When contacted by the BBC, a spokesperson for Group NBT said it would release an official statement soon.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Samsung's Galaxy pulled from show

Samsung Electronics will not promote its new tablet computer at one of the world's largest electronics shows after sales of the product were blocked in Germany.

The new Galaxy Tab 7.7 was pulled out of the IFA electronics fair in Berlin.

On Friday a Dusseldorf court granted a request from Apple to ban Samsung from selling the product in Germany.

The two rivals are locked in a global patent war over their smartphone and tablet products.

The new court injunction comes after a temporary ban on sales in Germany of another Samsung product - the Galaxy Tab 10.1 - by the court in August.

Ongoing battle

Apple claims that South Korea's Samsung has infringed on its patents with the Galaxy line of smartphones and tablet computers.

It argues Samsung copied the design, look and feel of Apple's popular iPhone and iPad devices.

Samsung has counter-sued Apple, saying it infringed on Samsung's wireless patents.

The two companies have been fighting legal battles in the US, Europe, South Korea and Australia since April.

In Australia, Samsung has already been forced to delay the introduction of the Galaxy Tab 10.1 twice.

Galaxy Tab

Samsung was planning on displaying its Galaxy Tab 7.7, as well as other new devices, at this year's IFA.

The electronics fair is one of the most important showcases for companies looking to attract European consumers.

However, the injunction means it will miss out on the opportunity.

"The product is not on sale yet, but we've decided to respect the court order," said Samsung spokesman James Chung.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Friday, September 2, 2011

Suspected hackers arrested in UK

Four men have been arrested in separate parts of the UK by police investigating the hacker groups Anonymous and LulzSec.

The suspects - from Doncaster, Warminster, Northampton and London - are being questioned by Scotland Yard's e-Crime unit.

Their arrests are part of a wider operation involving UK law enforcement and the FBI.

At the same time, 14 suspected members of Anonymous appeared in a US court.

Authorities around the world have been rounding up suspects following a wave of attacks by both groups on major corporations and government institutions.

Amazon, PayPal, the CIA, US Senate and the UK's Serious Organised Crime Agency have all suffered either intrusions or denial of service attacks, designed to take their websites offline.

Mass arrests

In the latest round of British arrests, police detained 20-year-old Christopher Weatherhead from Northampton and 26-year-old Ashley Rhodes from Kennington, near London.

The pair are due to appear at Westminster Magistrates Court on 7 September.

Detectives also arrested a 24-year-old man from Doncaster, and a 20-year-old from Wiltshire for conspiring to commit offences under the Computer Misuse Act 1990.

In the United States, a mass court appearance saw 14 suspected Anonymous members appear before a judge in San Jose, California.

All of them denied being involved in a denial of service attack on PayPal's website in December 2010.

Anonymous had publicly declared its intent to target both PayPal and Amazon for, what the group perceived as, their complicity in isolating whistle blowing website Wikileaks.

Following the leaking of confidential US State Department memos, PayPal stopped processing donations to Wikileaks, while Amazon kicked the site off its web hosting service.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Video games get classical concert

Final Fantasy, Angry Birds and Enemy Zero <!-- Empty - Wide embedded hyper -->

Music featured in video games ranging from Angry Birds to Mario Bros is set to feature in a classical concert.

The London Philharmonic Orchestra (LPO) is playing more than 20 songs as part of a music festival in the city.

Two of this year's most hotly-anticipated games series, Battlefield and Call of Duty, will also be among the play list.

By going as far back as titles like Tetris the concert is tracing the history of music in gaming.

The festival's director Andrew Missingham says music plays an essential role in the gaming experience.

He said: "Video games from Heavenly Sword to Little Big Planet are taken to the next level by music."

Having recorded music in the past for blockbuster films like The Lord of the Rings trilogy the orchestra might be more suited to Final Fantasy and Legend of Zelda.

Tongue-in-cheek

Andrew Skeet was asked to compose the concert for the LPO.

"I was recording, by coincidence, a score for a film based on a video game called Ghost Recon when I got a call from the London Philharmonic," he revealed.

"I thought, 'We've got to go a little bit on the nostalgia front but also find the best bits of music.'

"The slightly darker ones like Advent Rising, it's quite romantic but dark romantic, so I like that.

"I love the ones to work on that are a bit different to the originals because they're a bit more fun.

"But then I loved doing Tetris and Angry Birds because they're completely new versions and a little bit tongue-in-cheek."

The full list of video games included in the concert is:

  • Advent Rising
  • Elder Scrolls
  • CoD Main Menu Theme
  • CoD Modern War 2: Theme
  • Legend of Zelda
  • Mario Bros Theme
  • Little Big Planet
  • Splinter Cell
  • Battlefield 3
  • Final Fantasy
  • Metal Gear Solid
  • Dead Space
  • Uncharted: Drake's Fortune
  • World of Warcraft
  • Halo 3
  • Blood Stone 007
  • Grand Theft Auto
  • Bioshock
  • Mass Effect
  • Fallout 3
  • Tetris
  • Super Mario
  • Angry Birds
  • Enemy Zero

Follow our technology reporter Dan Whitworth on Twitter



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials