Monday, September 12, 2011

Bad spelling opens security hole

A missing dot in an email address might mean messages end up in the hands of cyber thieves, researchers have found.

By creating web domains that contained commonly mistyped names, the investigators received emails that would otherwise not be delivered.

Over six months they grabbed 20GB of data made up of 120,000 wrongly sent messages.

Some of the intercepted correspondence contained user names, passwords, and details of corporate networks.

About 30% of the top 500 companies in the US were vulnerable to this security shortcoming according to researchers Peter Kim and Garret Gee of the Godai Group.

The problem arises because of the way organisations set up their email systems. While most have a single domain for their website, many use sub-domains for individual business units, regional offices or foreign subsidiaries.

Dots or full stops are used to separate the words in that sub domain.

For example a large American financial group may take bank.com as its corporate home but internally use us.bank.com for staff email.

Usually, if an address is typed with one of the dots missing, ie usbank.com, then the message is returned to its sender.

But by setting up similar doppelganger domains, the researchers were able to receive messages that would otherwise be bounced back.

"Start Quote

It's striking that the researchers managed to capture so much information by focusing on just one common mistake"

End Quote Mark Stockley Sophos

"Doppelganger domains have a potent impact via email as attackers could gather information such as trade secrets, user names and passwords, and other employee information," wrote the researchers in a paper detailing their work.

Only one of the companies being impersonated noticed that spoofing was taking place and tracked down the researchers.

Man in the middle

A clever attacker could cover their tracks by passing on the message to its correct recipient and relaying back any reply.

By acting as a middleman the likelihood of more messages being mis-sent using the "reply" function increases.

Follow-up work by the researchers revealed that some cyber criminals may already be exploiting keyboard errors.

A search uncovered many addresses resembling corporate sub-domains which were owned by individuals in China or linked to sites associated with malware or phishing.

Writing on the blog of security firm Sophos, Mark Stockley said: "It's striking that the researchers managed to capture so much information by focusing on just one common mistake.

"A determined attacker with a modest budget could easily afford to buy domains covering a vast range of organisations and typos," he said.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Friday, September 9, 2011

Supercomputer predicts revolution

Feeding a supercomputer with news stories could help predict major world events, according to US research.

A study, based on millions of articles, charted deteriorating national sentiment ahead of the recent revolutions in Libya and Egypt.

While the analysis was carried out retrospectively, scientists say the same processes could be used to anticipate upcoming conflict.

The system also picked up early clues about Osama Bin Laden's location.

Kalev Leetaru, from the University of Illinois' Institute for Computing in the Humanities, Arts and Social Science, presented his findings in the journal First Monday.

Mood and location

The study's information was taken from a range of sources including the US government-run Open Source Centre, and the Summary of World Broadcasts (now known as BBC Monitoring), both of which monitor local media output around the world.

News outlets which published online versions were also analysed, as was the New York Times' archive, going back to 1945.

In total, Mr Leetaru gathered more than 100 million articles.

Reports were analysed for two main types of information: mood - whether the article represented good news or bad news, and location - where events were happening and the location of other participants in the story.

Mood detection, or "automated sentiment mining" searched for words such as "terrible", "horrific" or "nice".

Location, or "geocoding" took mentions of specific places, such as "Cairo" and converted them in to coordinates that could be plotted on a map.

Analysis of story elements was used to create an interconnected web of 100 trillion relationships.

Predicting trouble

Data was fed into an SGI Altix supercomputer, known as Nautilus, based at the University of Tennessee.

The machine's 1024 Intel Nehalem cores have a total processing power of 8.2 teraflops (trillion floating point operations per second).

Based on specific queries, Nautilus generated graphs for different countries which experienced the "Arab Spring".

In each case, the aggregated results of thousands of news stories showed a notable dip in sentiment ahead of time - both inside the country, and as reported from outside.

For Egypt, the tone of media coverage in the month before President Hosni Mubarak's resignation had fallen to a low only seen twice before in the preceding 30 years.

Previous dips coincided with the 1991 US aerial bombardment of Iraqi troops in Kuwait and the 2003 US invasion of Iraq.

Mr Leetaru said that his system appeared to generate better intelligence than the US government was working with at the time.

"Start Quote

If you look at this tonal curve it would tell you the world is darkening so fast and so strongly against him that it doesn't seem possible he could survive."

End Quote Kalev Leetaru University of Illinois

"The mere fact that the US President stood in support of Mubarak suggests very strongly that that even the highest level analysis suggested that Mubarak was going to stay there," he told BBC News.

"That is likely because you have these area experts who have been studying Egypt for 30 years, and in 30 years nothing has happened to Mubarak.

The Egypt graph, said Mr Leetaru, suggested that something unprecedented was happening this time.

"If you look at this tonal curve it would tell you the world is darkening so fast and so strongly against him that it doesn't seem possible he could survive."

Similar drops were seen ahead of the revolution in Libya and the Balkans conflicts of the 1990s.

Saudi Arabia, which has thus far resisted a popular uprising, had experienced fluctuations, but not to the same extent as some other states where leaders were eventually overthrown.

Mapping Bin Laden

In his report, Mr Leetaru suggests that analysis of global media reports about Osama Bin Laden would have yielded important clues about his location.

While many believed the Al Qaeda leader to be hiding in Afghanistan, geographic information extracted from media reports consistently identified him with Northern Pakistan.

Only one report mentioned the town of Abbottabad prior to Bin Laden's capture in April 2011.

However, the geo-analysis narrowed him down to within 200km, said Mr Leetaru.

Real time analysis

The computer event analysis model appears to give forewarning of major events, based on deteriorating sentiment.

However, in the case of this study, its analysis is applied to things that have already happened.

According to Kalev Leetaru, such a system could easily be adapted to work in real time, giving an element of foresight.

"That's the next stage," said Mr Leetaru, who is already working on developing the technology.

"It looks like a stock ticker in many regards and you know what direction it has been heading the last few minutes and you want to know where it is heading in the next few.

"It is very similar to what economic forecasting algorithms do."

Mr Leetaru said he also hoped to improve the resolution of analysis, especially in relation to geographic location.

"The next iteration is going to city level and beyond and looking at individual groups and how they interact.

"I liken it to weather forecasting. It's never perfect, but we do better than random guessing."



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

German court upholds Samsung ban

A German court has upheld a ban on the sale of Samsung's Galaxy Tab, saying it did infringe Apple patents.

It was asked to reconsider a previous ruling that elements of the tablet's design were copied from the iPad.

That decision led to a Europe-wide ban, which was later lifted amid concerns about the court's power to impose such a broad embargo.

The latest hearing went in Apple's favour and means the Galaxy Tab 10.1 is again banned from sale across Germany.

Dusseldorf regional court judge Johanna Brueckner-Hoffmann said that the "minimalist, modern form" of the two products gave a "clear impression of similarity".

In the early stages of the dispute, Apple had won the right for the ban to be imposed continent-wide. However, that was lifted following a challenge by Samsung.

Its re-imposition, albeit only within one country, marks yet another round in the ongoing patent battle between Apple and Samsung.

The two electronics giants currently face each other in courtrooms in Australia, North America and Asia.

Apple has also been successful in winning a sales ban of several Samsung phones across Europe following court action in the Netherlands.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Mozilla calls for security checks

Web certificate authorities have been told to audit their security or risk being dumped from Firefox by the browser's developer Mozilla.

The demand follows a breach at Dutch certificate issuer DigiNotar which lead to scores of bogus authentications being created.

Belgian security firm GlobalSign also stopped issuing new certificates amid fears it too may have been compromised.

Mozilla wants proof that other companies have protected their systems.

Attack pattern

Security certificate issuers have been given until 16 September to demonstrate to Mozilla that their internal networks have not been compromised.

It also wants to know what steps the issuers take when certificates are issued to make sure fakes are not being generated.

The security certificates issued by DigiNotar and many others act as an identity guarantee so people can be sure that the site or service they are connecting to is what it claims to be.

Typically users will notice that a certificate is being used by the appearance of a padlock icon, or the https prefix.

By penetrating DigiNotar's network and issuing fake certificates, hackers could pose as anyone they want and get at confidential messages or steal saleable data.

The attack on DigiNotar seems to have originated in Iran and put at risk about 300,000 people who use Gmail in that country, according to an interim report into the breach.

The hacker who carried out the DigiNotar attack, plus one on another security certificate firm, Comodo, earlier in 2011, bragged that he had access to four other CAs. This led to security checks at GlobalSign, one firm mentioned in the message.

In issuing its demand for audits, Mozilla said it reserved the right to revoke certificates recognised by Firefox.

Kathleen Wilson, head of Mozilla's security certificate group, said that working with Firefox was at its "sole discretion".

"We will take whatever steps are necessary to keep our users safe," wrote Ms Wilson.

If a certificate issuer is boycotted it could mean many users see pop-up warnings when trying to securely buy goods online or send messages.

Mozilla has already issued updates for Firefox to revoke DigiNotar certificates. Microsoft and Google have taken similar action with Chrome. Apple has yet to issue an update for Safari.

Google has also moved to contact those who may have had their email communications spied upon as a result of the DigiNotar hack.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Microsoft services hit by outage

Millions of Microsoft users were left unable to access some online services overnight because of a major service outage.

Hotmail, Office 365 and Skydrive were among the services affected.

Microsoft was still analysing the cause of the problem on Friday morning, but said it appeared to be related to the internet's DNS address system.

Such a major failure is likely to raise questions about the reliability of cloud computing versus local storage.

Especially embarrassing is the temporary loss of Office 365, the company's alternative to Google's suite of online apps.

The service also went offline briefly in mid-August, less than two months after it launched.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Waterstone's to launch e-reader

Waterstone's is to launch a digital e-reader to rival Amazon's Kindle next year.

The company's managing director, James Daunt, told the BBC he had been inspired by Barnes & Noble's successful Nook device.

The US bookseller is one of the few high street retailers to have challenged Amazon's growing dominance in both physical and electronic sales.

Amazon customers now buy more Kindle titles than paper versions.

Waterstone's is currently in the midst of a shake-up after being bought from HMV Group by Russian businessman Alexander Mamut.

James Daunt was brought in by the new owner in an attempt to reverse its declining sales.

Entering the hardware market would be an ambitious move for Waterstone's and likely involve it partnering with a major electronics company.

Barnes & Noble teamed-up with Taiwanese manufacturer Foxconn - best known for making the iPhone - in 2009 to create the Nook.

The American retailer predicted last month that it would sell around $1.8bn (�1.1bn) in Nook e-books by the end of the financial year.

Amazon does not provide a detailed breakdown of e-book sales and has never revealed the number of Kindle devices sold, other than to say it is in the millions.

<!-- Embedding the audio player --> <!-- This is the embedded player component -->
<!-- embedding script -->
<!-- end of the embedded player component --> <!-- Player embedded -->

However, Mr Daunt believes that Barnes and Noble has managed to claw back market share from its online rival by linking the electronic product with its high street stores.

Nook owners are allowed to read for free in Barnes and Noble stores for up to one hour each day.

"We in Waterstone's need to offer you a digital reader which is at least as good, and preferably substantially better, than that of our internet rival, and you will have a much better buying experience purchasing your books through us," Mr Daunt told BBC Radio 4's You and Yours programme.

Waterstone's e-reader project was "well down the planning line", according to Mr Daunt, and would launch in Spring 2012.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Thursday, September 8, 2011

HTC sues Apple after Google sale

Taiwanese smartphone firm HTC has fired a fresh salvo in its continuing war with Apple over patent infringement.

HTC has used patents it bought from Google last week to lodge a fresh complaint against Apple with the US International Trade Commission (ITC).

It has alleged that Apple's computers and mobile devices infringe patents involving wi-fi capability and processor communication technology.

This is the third complaint that HTC has filed against Apple.

"We are taking this action against Apple to protect our intellectual property, our industry partners, and most importantly our customers that use HTC phones," said Grace Lei, general counsel of HTC.

Apple v Android?

HTC is not the only smartphone maker involved in a legal tussle with Apple.

Samsung Electronics, which makes the Galaxy series of smartphones and tablet PCs, has also been fighting a legal battle against Apple.

"Start Quote

It is becoming an Apple versus Android war. Google is trying to fight a proxy war with Apple through its licensees such as HTC"

End Quote Tim Charlton Charlton Media Group

Apple has filed complaints against the South Korean manufacturer, accusing it of infringing its patents. It said that Samsung had copied the design and look of Apple's iPhone and iPad devices.

Samsung has counter-sued Apple, saying it infringed Samsung's wireless patents.

Both HTC and Samsung use Google's Android operating system in most of their smartphones.

Analysts said that HTC's latest legal action, which uses patents it acquired from Google, indicates that the tussle is becoming a much bigger issue than just a simple fight between two manufacturers.

"It is becoming an Apple versus Android war," Tim Charlton of Charlton Media Group told the BBC.

"Google is trying to fight a proxy war with Apple through its licensees such as HTC." he said.

Andrew Milroy of Frost & Sullivan added that tighter co-operation between HTC, Samsung and Google would create a strong rival to Apple.

"I see them being in a very strong position if they get together to take on Apple," he said. "Google plus Samsung plus HTC is a very big force to fight against."

Many fronts

The companies have been stepping up their legal action against each other this year.

And in the early salvos, Apple seems to have got the upper hand.

"We think competition is healthy, but competitors should create their own original technology, not steal ours," Carolyn Wu, a spokeswoman for Apple, told the BBC.

Last month, a court in the Netherlands banned Samsung from selling three models of its Galaxy smartphones in a number of European countries after Apple filed a claim for patent infringement.

Earlier this week, Samsung pulled out its new Galaxy Tab 7.7 from the IFA electronics fair in Berlin, one the world's largest electronics shows, after a court blocked sales of the product in Germany.

"Right now Apple is winning the patent war," Mr Charlton said.

'Weapon to compete'

Analysts said the regularity with which these companies have been taking legal action against each other was also an indicator they may be using it as a competition tool.

"It seems it is being used as a weapon to compete, to slow down rival products from coming out in the market," Frost & Sullivan's Mr Milroy said.

Mr Milroy explained that the rapid growth in the smartphone and tablet PC sector had turned the segments from being a niche market to a mainstream one.

That, he said, had resulted in an increased push from various players for a bigger market share.

"I guess it will go on as long as the market is growing at this phenomenal rate," he said.

"Once the market slows down, we will see a return to conventional competitive techniques."



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Google mulls Android favourites

Court papers have thrown light on how Google gives some firms early access to Android technology.

The documents detail an internal Google discussion about how to make the most of the mobile operating system.

They explain the quasi-open nature of Android and reveal why it lets firms that keep to Google's specifications put products on sale first.

The policy assumes new significance given Google's bid to buy Motorola's mobile unit, say analysts.

Cashing in

Excerpts from the court papers were posted to the blog of patent expert Florian Mueller. The documents were filed to a US court as part of Google's defence in its legal wrangle with Oracle over some of the code in Android.

One page highlighted by Mr Mueller and labelled "Confidential and Proprietary" lists some of the ways Google profits despite Android being freely distributed.

It discusses the value of granting "early access" to partners who build and market devices to Google's standards and specifications.

The document cites the example of Motorola and US network Verizon.

This, argues Google, allows the companies to sell products that make use of new features and gives them a "time to market" advantage.

The page also mentions the idea of a "lead device" that would launch with a new version of the code already installed.

It also states baldly that to profit, Google should "not develop in the open". As has been seen with Android, Google prefers to get the code working internally before it is released more widely for others to tinker with.

What is not yet clear is when the papers were drawn up, whether it was during the early days of Android or more recently.

Mr Mueller said the mention of "early access" should worry firms making handsets that run Android. It suggests, he said, that Google has a "stated commitment to a non-level playing field".

A Google spokesperson said: "We have had a "lead device" strategy publicly for years with a variety of manufacturers including HTC and Samsung".

The spokesperson cited the example of Samsung's Nexus S - the lead device for the Gingerbread release of Android co-developed by Google and Samsung.

Pete Cunningham, principal analyst at market research firm Canalys, said the, "lead device" policy had operated since the earliest days of Android.

"Every time there's been a major launch of Android, there's been a 'hero' product that comes out with it," he said.

Before now that had not meant Google playing favourites even though being a lead device usually meant greater publicity and higher sales, said Mr Cunningham.

If Google gets permission to buy Motorola's mobile unit that might mean the end of the policy of giving different manufacturers lead device status, he said.

"If Motorola get that advantage consistently then alarm bells may start ringing at those other handset makers," he said.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Wednesday, September 7, 2011

Web authentication breach spreads

Belgian security firm GlobalSign has temporarily stopped issuing authentication certificates for secure websites.

It comes after an anonymous hacker claimed to have gained access to the company's servers.

If confirmed, it would be the second security breach at a European certificate authority in two months.

Hundreds of bogus DigiNotar authentications were issued following an intrusion into its systems.

Certificate authorities (CAs) are companies or public bodies whose job is to confirm that secure websites are genuine.

When computers connect to a site with TLS or SSL authentication, a certificate is issued which verifies the site's identity to the web browser.

Fake certificates could allow someone to spy on a user's activity.

Multiple targets

GlobalSign took action as the result of a posting which appeared on the online notice board Pastebin.

The author, who identified themselves only as "ComodoHacker", claimed to have gained access to four certificate authorities, in addition to DigiNotar.

Only GlobalSign is named, although the message points out that an attack on StartCom was foiled by its boss Eddy Nigg.

ComodoHacker also refers to an attack on US certificate authority Comodo, which was targeted in March.

As a precaution, GlobalSign said it was temporarily ceasing the issuance of all certificates while it investigated the claims.

The hacker also played down suggestions that the attacks were the work of Iranian authorities.

"I'm single person, do not AGAIN try to make an ARMY out of me in Iran. If someone in Iran used certs I have generated, I'm not one who should explain," said the posting.

It had been suggested that, because many of the bogus DigiNotar certificates were issued to users in Iran, that authorities in there may have initiated the CA hack as a tool for spying on dissidents.

A report on the DigiNotar attack said that up to 300,000 Iranians may have had their Gmail accounts monitored as a result of a fake Google certificate being created.

Hacktivist

While the anonymous posting contains no information about the identity of the CA hacker, it does detail a political agenda.

The message states: "Dutch government is paying what they did 16 years ago about Srebrenica, you don't have any more e-Government huh?"

It appears to reference the apparent non-intervention of Dutch peacekeeping forces during the notorious 1995 Srebrenica massacre, where Serbian forces killed more than 8,000 Bosnian Muslims.

DigiNotar certificates are used to authenticate many online services offered by the Dutch government, although the company has said that these use a separate system which was not compromised during the attack.

State prosecutors in the Netherlands are investigating the incident.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials

Online firm Yahoo fires CEO Bartz

Yahoo's chief executive Carol Bartz has been fired by the internet company after two-and-a-half years in the top job.

The company said in a statement that Ms Bartz was removed by the board of directors, effective immediately.

Tim Morse, Yahoo's chief financial officer, will take over from Ms Bartz.

Yahoo has been struggling to increase its market share as it faces increased competition from rivals such as Google and Facebook.

Yahoo shares jumped more than 6% in after-hours trading after news of the firing broke, indicating they would trade higher when Wall Street opens for business on Wednesday. Yahoo's stock price was up at $13.72, an increase of 81 cents.

Mr Morse will serve as interim chief executive and the board of directors will look for a new CEO, the company said.

No turnaround

Ms Bartz was hired to run Yahoo in early 2009, taking over from co-founder Jerry Yang.

She made significant changes to the management team and cut jobs to save on costs. She also shifted the focus of the traditionally search-oriented firm towards more personalized content.

"Start Quote

I am very sad to tell you that I've just been fired over the phone by Yahoo's chairman of the board"

End Quote Carol Bartz Former CEO, Yahoo

However, Larry Magid, a technology analyst at C-net, said the company has not seen enough of a turn-around under Ms Bartz's leadership.

"She hasn't done anything to change the company's fortunes, and they are still anxious to find a leader who can move them up," he said.

Critics also claim that Yahoo has failed to make significant strides in two of the most lucrative segments of the market; search and social networking.

"Facebook is way ahead, and now even Google is way ahead of Yahoo in social networking," C-net's Mr Magid added.

"In terms of the potential for long-term revenue it's just not there. They've got some great sites, great information resources, news, stocks, sports, but that's not what bringing in the money."

Phone firing

The news first broke on the Wall Street Journal's All Things D website, which quoted an email from Ms Bartz to Yahoo staff. The email has since been reported by other news agencies including Bloomberg and Reuters.

"I am very sad to tell you that I've just been fired over the phone by Yahoo's chairman of the board," Ms Bartz said in the email to staff.

"It has been my pleasure to work with all of you and I wish you only the best going forward."

As news of the sacking spread across the internet, Yahoo released its own press statement in which it confirmed it was undergoing a "leadership reorganisation" and that Ms Bartz would be leaving the company.

Roy Bostock, chairman of Yahoo's board, said in the statement: "On behalf of the entire board, I want to thank Carol for her service to Yahoo during a critical time of transition in the company's history, and against a very challenging macro-economic backdrop."

He added that he saw "enormous growth opportunities" for the firm.



Powered By WizardRSS.com | Full Text RSS Feed | Amazon Plugin | Settlement Statement | WordPress Tutorials