It has been said that there is nothing new under the sun and that every generation forgets or never learned the hard-earned lessons from the spilled blood of the previous generation.
Reviewing the security and compliance issues of a new mobile medical device recently, I was struck by how familiar many of the themes are.
What makes mobile devices special? Actually nothing.
Deploying line of business or life science applications on mobile Android tablets or an iPad has a different set of security requirements than backing up your address book. It requires thinking about the software security and privacy vulnerabilities in a systematic way.
However, a software security assessment of a life science software application deployed on a mobile device needs to look beyond the malware and spyware and data breach attacks on the device. Mobile Android tablets or iPads running electronic medical records applications are usually deployed in uncontrolled, complex and highly vulnerable environments such as enterprise IT networks in hospitals. The software security issues are much more severe than those of a single tablet: a combination of network vulnerabilities, application software vulnerabilities, malicious attackers superimposed on the large, complex threat surface of an enterprise IT network.
The mobile medical device is now an attack vector into the hospital network, a far more valuable asset than the mobile device itself.
It seems that there are 5 key areas of vulnerability for mobile devices, but not surprising, they all coincide with the classic IT network vulnerabilities:
Protocol coverage is lacking: Mobile devices often rely on built-in firewalls or enterprise network isolation. The protection that firewalls provide is only as good as the policy they are configured to implement and there are a whole slew of issues related to remote security policy management of untethered devices. I expect that analysis of network exploits on mobile devices with internal firewalls, will match analysis of real-world configuration data from corporate firewalls that shows rule sets that frequently violate well-established security guidelines (for example zone-spanning objects and lack of stealth rules). In addition, a stateful inspection firewall on a mobile device doesn’t perform deep content inspection on complete sessions and is therefore blind to data theft attacks – for example piggy-back attacks on text messaging in order to steal sensitive data.
Proxy-based access to control a device is convenient but may enable attackers to compromise a device and steal data – proxies end-point devices to obtain direct access to the Internet – research with clients show us that as much as 20 percent of all endpoints already bypass content filtering proxies on the enterprise IT network.
Visibility of network transactions is usually missing making incident response very difficult: Firewall and proxy logs are generally never analyzed, and often lag hours behind an event. An IPS often relies on anomaly detection. Anomaly detection relies on network flow data, which is often reported at intervals of 15 to 45 minutes. With that kind of lag, an entire network can be brought down. Because anomaly detection is looking for an anomalous event rather than an attack, it is frequently plagued by time-consuming false positives. A proxy on the other hand relies on URL filtering and simple keyword matching that analyzes the HTTP header and URL string. By looking at content and ignoring the network; a proxy can suffer from high rates of false negatives, missing attacks.
Multiple security and application layers increases cost of implementation and maintenance. Installation of multiple, disparate, proxy-based security products complicate network and end-point maintenance. Proxies require changes to the network infrastructure and in large networks may be impossible to install. Updating mobile device application software to latest patch levels can be challenging to enforce and control and may result in injecting new software vulnerabilities into the device as there is probably not central IT administrator in charge of updating the mobile electronic medical records application running on 300 Android tablets in the hospital.
Redundant, multiple network security elements increase risk in the overall solution: This is additional risk that manifests itself as a result of the interaction between mobile devices accessing cloud services via a complex system of cache servers, SSL accelerators, Load balancers, Reverse proxy servers, transparent proxies, IDS/IPS and Web Application Firewalls. Consider that endpoints can bypass SSL proxies by specifying a gateway IP address and transparent proxies on a Windows network are no assurance for unauthenticated user agents bypassing the entire proxy infrastructure. HTTP-Aware firewalls such as Web application firewalls can be completely or partially bypassed in some cases. Transparent proxies can be compromised by techniques of HTTP response splitting since they rely on fine-grained mechanisms of matching strings in HTTP headers. This is why Mozilla is delaying their implementation of Web sockets which may not matter if you’re running Chrome OS.
It’s a new dawn but with old rules.
Wednesday, February 23, 2011
Mobile device security challenges | #Israeli Software #infosec
Elyssa Durant's photos - @firetown beam me up @SpottyX | Plixi #disinfo
Q&A - Asperger's syndrome - ABC News (Australian Broadcasting Corporation)
Asperger's syndrome
By Tim Leslie
Updated Fri Feb 18, 2011 1:07pm AEDT
Asperger's syndrome is a neuro-developmental disorder, one of the suite of conditions making up the autism spectrum.
While people with Asperger's have an intellectual capacity within the normal range, they experience problems with social interaction, and difficulties understanding the nuances of emotion, as well as intense preoccupation with a particular subject or interest.
These difficulties are often offset by exceptional abilities, brought about by the intense focus that forms part of the disorder.
For International Asperger's Day, ABC News Online spoke to expert Tony Atwood, a psychologist who specialises in treating children with the disorder, and has authored several books on the subject.
What is Asperger's syndrome?
Asperger's syndrome describes someone who is different, and one way I describe it, is that the person has found something more interesting in life than socialising.
And that means that the person with Asperger's syndrome finds people a real challenge in reading body language, making friends and really understanding social situations.
But there are other dimensions too, a different form of learning, of perceiving the world, becoming very sensitive to certain sensory experiences, and sometimes being a bit sort of anxious. But someone with Asperger's syndrome may have particular talent in areas like engineering or the arts.
How does it occur?
What has happened is that the brain didn't develop as we anticipate. Now that may be because of inheritance; in other words it's a family characteristic that with this particular child is greater, or something has disrupted brain development from conception, right through to early infancy.
Is there a genetic component to the condition?
There is a genetic component in the sense for half the children we see, this seems to be a characteristic within families, and also from our clinical experience one in five of the families we see have more than one child with the characteristics.
Asperger's syndrome and autism are often linked together, can you explain the difference between the two?
It's part of what we call the autism spectrum, and it's a bit like visual impairment. You can have someone who is blind, ie you can have someone who's severely autistic - completely blind to the social world.
Asperger's syndrome is like someone who needs glasses, who can read the big print, for example that somebody is crying, so they're sad, but may not read the fine print in facial expressions, say embarrassment or jealousy.
How common is Asperger's?
Asperger's is about one in 250 people, and the ratio is about three to one; so three males to one female.
What do you think of public perceptions of Asperger's syndrome?
I think the general public is very positive. I think people are very curious, it's a name that they're starting to get to know.
What we're trying to get across is that the child has difficulties, but also talents, and I think if there's going to be a change, it's in terms of seeing their qualities as children eg for Lego, their ability to play music, their ability to draw in photographic realism.
So we're looking at their strengths to build up their self esteem and also their careers.
Do you think there needs to be more support for those who have Asperger's?
If it's one in 250 people everyone will know someone either at school or a neighbour or somebody in their past with those characteristics.
So what we're trying to do is to get people to recognise such individuals, and instead of laughing at them, or feeling annoyed by them, to show some degree of compassion and support.
What is the one thing you would like the public to keep in mind in regard to Asperger's syndrome?
Celebrate difference and not necessarily see it as defect.
Tags: health, diseases-and-disorders, autism-spectrum-disorder, australia
First posted Fri Feb 18, 2011 10:22am AEDT
Conversation aka TROLL TRAIN
2011-02-23 12:51 @ElyssaD looking for an art site. http://tinyurl.com/4vuarbj/?=ndcx&=mtkx #inventosdeldiablo |
2011-02-23 12:50 @musicbaebe @mario49k and you can bet your last dollar that it is a Very serious crime. likely to be take. More seriously due 2 COINTELPRO |
2011-02-23 06:02 Are you suggesting @ElyssaD that @Mario49k participates in gang stalking? Extremely serious organised crime. Perps cd face life in prison. |
2011-02-22 03:19 @Mario49k see that happens to be illegal - not only did you participate in gang stalking & harassment, but u invited your friends. #shame |
2011-02-21 23:31 Google Street View raises Israeli security fears http://bit.ly/ijvQLa @cinnamon_carter @GovernAmerica |
No mention @leahita @CelticFire69 and @elyssad
| Elyssa Durant (@ElyssaD) 2010-12-30 18:07 FUCKING DING-- |
| Ernie Hopkins (@CelticFire69) 2010-12-30 18:06 U R aware that rockingjude on facebook and twitter lists name as jude vaxen? Her/It behavior odd she follow/unfollowed me several times. |
| Elyssa Durant (@ElyssaD) 2010-12-30 17:27 Vaxen sent a dm saying that he no longer follows Jude. |
| Elyssa Durant (@ElyssaD) 2010-12-30 17:25 Rockingjude is the bitch who hacked my account. Longhawl is another account she had access to and they gang stalked me and harassed online |
| Ernie Hopkins (@CelticFire69) 2010-12-30 17:18 No one should attack a baby cat. BTW my son thinks U must b super cool because of your cat. Back 2 mtr, who is rockingjude, who is longhaul? |
| Elyssa Durant (@ElyssaD) 2010-12-30 16:47 Vaxen is male I think he is okay. Longhawl is an alias she uses and they attack @spottyx which is my poor baby cat I use when I'm in twitmo |
| Ernie Hopkins (@CelticFire69) 2010-12-30 13:49 OK jude vaxen=rockingjude. Chats portray female, 26 Dec DM indicates male. Which is it? Is it safe to be following it? More flares unfollow? |
Sent with Twitter for iPhone
@badjerry L88K-- GRANT FOR HACKTIVISTS $11,000 - $17,000 i can do that!
Y Combinator Funding Application s2011 | news | logout How It Works
- Please put your email address in the email field of your profile. This is the address we'll use to reply to you. (It's not visible to anyone else.)
- Please create YC accounts for any of your cofounders who don't already have one.
- Edit your application online.
- The update button on the application form saves your changes, but doesn't submit the application to us.
- When you're ready for us to see your application, click on the submit button that will appear here
- Edit and resubmit as much as you want, but be sure to submit at least once before the deadline (March 20 at 8 pm PST), because you haven't applied till you do.
- Early submissions have a significant advantage because we have more time to look at them and engage with the founders.
- We may have questions about your application. If there is a question waiting from us, you'll see a link to it on this page and at the top of Hacker News (when you're logged in). So check HN regularly after submitting.
- If you want a copy of your application, please save one locally, because we turn off this url after the application deadline.
- We'll review applications and get back to you at the end of the day on April 9.
Thanks, ElyssaD!
Iranian cyber army strikes again hitting Voice of America || #iDEFENSE #ISRAEL
Iranian cyber army strikes again -- hitting Voice of America
A Network Solutions account was compromised by the same group that changed DNS settings for Twitter and Baidu a year ago
- Robert McMillan (IDG News Service)
- 23 February, 2011 09:00
- Comments
The pro-Iran hacktivist group that defaced the Baidu and Twitter Web sites a year ago has hit another target: the U.S. Government's Voice of America news site.
Voice of America was knocked offline temporarily Monday after hackers were able to change the organization's DNS (Domain Name System) settings, redirecting Web traffic hitting Voice of America sites to another site controlled by the hackers.
"On Monday, February 21, VOANews.com's primary domain, along with numerous related domains registered with Network Solutions, were hacked by an unknown party. This enabled the hacker to redirect VOA URLs to a site claiming to be run by a group called the 'Iranian Cyber Army,'' Voice of America said Tuesday in a statement posted to its Facebook page.
Visitors to the Web page saw a statement addressed to U.S. Secretary of State Hillary Clinton, telling the U.S. to "stop Interfering in Islamic countries."
Breaking into domain name registration accounts and redirecting Web sites is a favorite tactic of the Cyber Army, and it has pulled off this attack numerous times in recent years. The group posted similar messages in the Twitter and Baidu incidents.
After it was hacked, China's top search engine company, Baidu, sued its domain name registrar, Register.com, claiming that hackers got into the account by pretending to be Baidu representatives in an online chat with the registrar's tech support staff. That lawsuit was quietly settled at the end of November.
The Web site Shortwavepirate.info has compiled a list of Web sites hit by the Cyber Army.
Most of the Voice of America sites have now been restored, and no data was lost due to the incident, said Network Solutions Director of Social Media Shashi Bellamkonda, in an interview Tuesday. He wouldn't say exactly how the hackers were able to change the DNS. "It isn't a hack or a breach of Network Solutions services," he said. "The DNS was changed and we helped the customer reset it."
Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com
http://www.techworld.com.au/article/377622/iranian_cyber_army_strikes_again_-...
HACKED UNITED STATES IP: What it something I said? IP 175.0.0.0). Details
| Access Type [ ? ] (Browser, mobile, POP3, etc.) | Location (IP address) [ ? ] | Date/Time (Displayed in your time zone) |
| Browser | * United States (CA) (66.87.0.114) | 5:49 am (0 minutes ago) |
| IMAP | 208.87.200.155 | 4:57 am (51 minutes ago) |
| IMAP | 208.87.200.154 | 4:42 am (1 hour ago) |
| IMAP | United States (CA) (66.87.0.114) | 3:45 am (2 hours ago) |
| Browser | * United States (CA) (66.87.8.189) | 2:45 am (3 hours ago) |
| IMAP | United States (CA) (66.87.6.145) | 12:48 am (5 hours ago) |
| IMAP | United States (CA) (66.87.8.73) | 10:24 pm (7 hours ago) |
| IMAP | 208.87.200.154 | 9:30 pm (8 hours ago) |
| IMAP | 208.87.200.155 | 9:30 pm (8 hours ago) |
| IMAP | United States (OR) (66.87.7.97) | 8:42 pm (9 hours ago) |
Security - Whitepapers - ZDNet Asia
Security
Latest whitepapers Sort by Popularity
DownloadSelecting a Networking Product Platform
This paper is written for OEMs that market networking, telecom, and network security solutions to Information Technology (IT) departments in companies of all sizes and industries. For the purposes here, OEMs are organizations that combine hardware computing platforms and software applications into solution-level products. WIN Enterprises networking platforms are typically used to support networking, network security functions, and converged applications. As network platforms they may be deployed as switches, load balancers, routers, etc. As network security platforms they support Deep Packet Inspection (DPI), Unified Threat Management (UTM), firewalls, anti-SPAM, anti-Virus, VPN security, etc.
7 days ago by WIN EnterprisesDownloadCIO Strategies for Consumerization: The Future of Enterprise Mobile Computing
It's been a generation since the first workers to grow up with personal computers at home entered the workforce. Twenty years ago, this new generation of workers helped fuel the massive expansion of business computer use and the productivity gains that ensued. In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the blurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
13 days ago by DellDownloadUpgrading MIIS and ILM: Best Practices in Extending Identity Management to the Entire Business
Upgrade to Microsoft Forefront Identity Manager 2010! One has been using Microsoft Identity Integration Server or Microsoft Identity Lifecycle Manager for years and loves it. One has wanted to move to Forefront Identity Manager 2010 and take advantage of all the new features plus the 64-bit platform. But, one didn't want to create downtime or a possible outage. The presenter of this podcast discusses the best way to upgrade.
20 days ago by MicrosoftDownloadProtecting Your Network from Rogue Security Software
In this webinar, Chris Boyd, GFI Software's Senior Threat Researcher will provide an in-depth look into rogue antivirus. He will detail the damage it can cause, including an exclusive look behind the scenes of what the customer interfaces of rogue antivirus products look like, and how they have been tailored to look like legitimate products and what businesses can do to better protect their network and end users.
23 days ago by GFi SoftwareDownloadAdvances in Fingerprint Scanning Technologies
Fingerprint scanner is a device which reads the finger surface and converts the analogue reading in digital form through an Analog to Digital convertor, and it has an interface module responsible for communicating with the external devices. Sensor is an internal component of scanner that reads the finger surface. The paper discusses about the developments in fingerprint scanning technologies like Multispectral fingerprint imaging and touchless finger print sensing technology and draws a comparison between both on the basis of the products by the vendors. The paper also throws light on the pros and cons of other existing fingerprint technologies.
23 days ago by PEC University of TechnologyDownloadWhy Customers Love VIPRE Business
Selecting an antivirus solution for your organization is an important decision. Read the results of a survey focused on enterprise antivirus users and discover why customers love VIPRE Antivirus Business
27 days ago by GFi SoftwareDownloadPCI-DSS Compliance and GFI Software Products
This document outlines what GFI can do to assist in your achieving PCI DSS compliance. The intent of this document is to provide you with GFI's understanding of the requirements, and how the GFI Software product line can assist you to meet PCI compliance as outlined in the PCI DSS Requirements
27 days ago by GFi SoftwareDownloadSecurity Talk: Fending Off Attacks by Reducing an Application's Attack Surface
The attack surface of an application is the set of ways in which an adversary can enter the software and potentially cause damage. The larger the attack surface, the more insecure the software. Reducing the attack surface is a key security practice required in the design phase of Microsoft Security Development Lifecycle (SDL) process. Attack surface reduction reduces the inherent risk the software application carries. The presenter of this podcast explains best practices for minimizing code exposed to untrusted users and protecting against vulnerabilities and threats that one don't know about.
27 days ago by MicrosoftDownloadEfficient Small Template Iris Recognition System Using Wavelet Transform
Iris recognition is known as an inherently reliable biometric technique for human identification. Feature extraction is a crucial step in iris recognition, and the trend nowadays is to reduce the size of the extracted features. Special efforts have been applied in order to obtain low templates size and fast verification algorithms. These efforts are intended to enable a human authentication in small embedded systems, such as an Integrated Circuit smart card. In this paper, an effective eyelids removing method, based on masking the iris, has been applied. Moreover, an efficient iris recognition encoding algorithm has been employed.
27 days ago by University of LiverpoolDownloadForefront Endpoint Protection 2010: Technical Overview
Microsoft Forefront Endpoint Protection 2010 (The next generation of Microsoft Forefront Client Security) is built on Microsoft System Center Configuration Manager to deliver high levels of protection and productivity. This podcast provides technical overview and live demonstrations of the new features in Endpoint Protection 2010 that help reduce complexity and lower infrastructure costs, including advanced threat detection and malware protection, centralized control of desktop security and management, and easy deployment using existing client management
http://www.zdnetasia.com/whitepaper/security_cat-39001066.htm
Next iPhone to enable remote computing?
Could the NFC chips rumored to be inside a future iPhone be used for more than just mobile payments?
That's what a source tells Apple blog Cult of Mac. The unnamed source asserts that Apple is researching ways to use near-field communication (NFC) for enabling remote computing.
According to Cult of Mac, here's how it would work:
If users wave a NFC-equipped iPhone at a NFC Mac (they need to be in close proximity to interact), the Mac will load all their applications, settings and data. It will be as though they are sitting at their own machine at home or work. When the user leaves, and the NFC-equipped iPhone is out of range, the host machine returns to its previous state.Essentially, the Mac would use NFC to authenticate with the phone. A user's bookmarks, address book, passwords, preferences, and settings would be stored on the phone so that when they sat down to any Mac it functioned as if they were using their home computer. As soon as the connection was lost between the Mac and the iPhone--as in, by moving the devices farther than half a foot away from each other--the Mac's original settings would be restored.
Cult of Mac's source cautions that this is still very much in the research phase. But it does line up with previous rumors and an actual Apple hire this summer.
In August it was first rumored that Apple had placed a large order for NFC chips from NXP Semiconductor. Those chips allow data to be sent wirelessly over very short distances, around 4 inches. It sends data from a chip inside a device like an iPhone, to a payment terminal, or another device.
Apple's subsequent hire of an expert in mobile payments led to assumptions that it was that use the company had in mind. But while mobile payments is an obvious application of NFC, it's not the only one. It could also be used to transfer data between devices very near each other, say an iPhone and an NFC-equipped Mac.
This article was first posted as a blog post on CNET News.
Apple overhauling iPhone notification system?
To cap off last week's chock-full of Apple-related rumors, we now have this: is Apple about to acquire a company in the process of giving its iOS notifications system a major makeover?
Apple blog Cult of Mac says it's hearing exactly that from a source, who is not named. The company Apple is allegedly buying isn't confirmed in the report, but is said to be "small" and currently has an application available for sale in the iOS App Store.
Now that would describe about a thousand companies. But there aren't that many that do slick notification apps. Cult of Mac has zeroed in on App Remix, the company that makes the app called Boxcar.
Boxcar pools all of your social media feeds and delivers your notifications from each into one app. App Remix's CEO apparently had "no comment" on Cult of Mac's query as to whether Apple plans on making the company an offer.
Apple's own notification system isn't regarded as the most stellar implementation. The original iPhone actually shipped without any real push notification system for third-party apps. It took Apple three iterations of the iPhone's software before it found a system it liked.
But the system employed in Palm's original Pre smartphone featuring WebOS is still roundly praised as the best in the business. Hewlett-Packard (HP), of course, owns WebOS now and recently introduced the software on several new phones and a tablet.
The man who invented the WebOS notification system, Rich Dellinger, actually quit Palm just after the HP acquisition last year to return to his former employer, Apple. The rumor mill heated up then that iOS' notifications were in for a big change, but nothing more has come of that--at least not yet.
Apple updates its iOS software on a yearly basis, usually in June, and there's a preview event usually around March to see what will be in the next version, in this case iOS 5. It's possible we could see a new push notification process included in the next big software update for the iPhone, iPod Touch, and iPad.
The unvarnished truth about unsecured Wi-Fi - Security - News
Chances are you don't leave your front door unlocked. And you shouldn't leave your Wi-Fi network unsecured either.
Many of you may have heard this before, but many still seem to not be doing anything about it. You should. Here's why. With a US$50 wireless antenna and the right software a criminal hacker located outside your building as far as a mile away can capture passwords, e-mail messages, and any other data being transmitted over your network, and even decrypt data that is supposedly protected.
Someone could also join the network and launch attacks on your computer and any other devices using the network at that time. If file sharing has been left on or the personal firewall is misconfigured it's relatively easy to access the computer via an open Wi-Fi network. Someone could upload an executable program to a file on your hard drive that steals data or just leaves a back door for future access. And if you are using the network to connect to a corporate network through a VPN (virtual private network) an attacker can get into the corporate system too.
"The most dangerous thing is a direct attack," Don Bailey, a security consultant at iSec Partners who is also an expert on telecommunications snooping, told CNET. "The threat is not only that your traffic can be sniffed, but that an attacker can get access to all your data and connections on your computer, even those supposedly secured by SSL (Secure Sockets Layer) and TLS (Transport Layer Security) encryption."
Unsecured Wi-Fi networks can be attractive for scammers to launch spam and virus attacks because the attack would be tracked back to the Wi-Fi network but not to the computer of the criminal who exploited the open network.
"Someone could be using your wireless network, whether it's a neighbor or a customer, and you are taking on the liability of that person's action," Bailey said. "If they do something illegal, like break into computers, those actions are going to come back to your hot spot and the federal authorities are going to hassle you."
Even though many Wi-Fi routers come with WPA (Wi-Fi Protected Access) enabled by default, a lot of people don't want to be bothered with setting up a password, despite the fact that you don't have to type it in every time you log on. The Wigle.net (Wireless Geographic Logging Engine) site shows that of 26.8 million Wi-Fi networks logged by volunteers who were "war driving"--driving around in cars and using laptops or PDAs to find wireless networks--49 percent were listed as secured with encryption and nearly 28 percent were shown to be not using encryption. (On the remaining 23 percent the security level was unknown.)
There is also an interactive map on Wigle.net where you can zoom in to see individual Wi-Fi networks and even the SSID (Service Set Identifier) numbers associated with individual wireless local area networks.
Not only should you not host an unsecured wireless network, but you should definitely be extra careful when using other people's open networks.
There is no good way to tell whether a hot spot is legitimate, like a Starbucks Wi-Fi network, or if it was set up by someone for malicious purposes. Even if you are on what appears to be a Starbucks network, there could be someone on the network who is spying on other users.
There are also instances of inadvertent fake hot spots. Some older Windows machines running XP create ad hoc networks called "Free Public WiFi," which do not connect you to the Internet but to the computer broadcasting that service. The hole that enables this has been patched, but affected computers that haven't had an operating system update are still vulnerable.
Whether you choose to trust hot spots, configure your device--laptop and smartphone--to connect to open Wi-Fi networks only with your approval and not automatically. Wi-Fi-enabled devices may automatically open themselves to sharing and connecting with other devices, so be sure to turn file sharing off when using Wi-Fi.
"The best thing to do is to stay off hot spots all together," Bailey said. "If you are going to use them, make sure you have a firewall and VPN technology."
This article was first posted as a blog post on CNET News.
Mobile broadband is killing free Wi-Fi - Communications - News
Mobile broadband is killing free Wi-Fi
By Josh Taylor, ZDNet Australia on January 31, 2011
Summary
commentary Two weeks in Japan has made this author realize that mobile Internet may be killing free Wi-Fi there, as most facilities offer chargeable connection.
Topics
japan, australia, wireless technology, science and technology, technology, wireless and mobile networking, wimax, tokyo, starbucks corporation, mcdonald's corporation
Events
CIO Day 2011
18 Mar 2011JW Marriott Hotel, Hong Kong
Annual Banking and Finance Technology Forum Asia 2011
9 Mar 2011
Singapore11 Mar 2011
Hong KongThe Internet Show 2011
13 - 15 Apr 2011Suntec, Singapore
commentary After spending two weeks in Japan scrounging for free Wi-Fi, I've come to the conclusion that mobile broadband is killing free Wi-Fi.
In seeking to avoid monster costs for global roaming while I was abroad, I disabled that feature on my phone before I left, meaning I was entirely reliant on Wi-Fi to get in contact with friends and family back home.
In Australia, free Wi-Fi is generally available at stores like McDonald's and Starbucks, as well as the ever-reliable Apple. Apart from using my iPad (which is the Wi-Fi model), I have little use for free Wi-Fi within this country because my 3G download quota with Optus for my iPhone is generally sufficient for all my internet needs, so I had not paid too much attention to what was available.
But prior to departing for my trip earlier this month, I thought I should research what Internet facilities were available. It was a bleak view to say the least, but I was optimistic because my accommodation provided free Internet and the Apple stores were a last resort, so it would all be good.
When I landed in Japan, I found that McDonald's and Starbucks generally didn't have any free Wi-Fi and the stores that did offer Wi-Fi often opted for paid services. The most common I found was BB Mobilepoint, a consortium of telcos that offers connections through hotspots mostly at train stations around Tokyo.
Handy for locals, sure, but not so much for tourists. In Australia, Telstra has a similar program in place with its hotspots.
When I was visiting the sights in Akihabara, the "electric town" in Tokyo that boasts dozens of stores with all the computer and high-tech gear you could ask for, I discovered that most of these stores sold WiMax broadband dongles and it was clear looking at the signs around town that most internet access would be through those.
When I did find places with Wi-Fi (the Wired cafes in Ueno and Shibuya, for example), I would often spend at least an hour or so there, and have a full meal at the same time, so I agree with Darren Greenwood that it is a smart business decision for stores to make the investment in free Wi-Fi.
I could only come to the conclusion that because most of the locals in Japan had existing mobile Internet accounts, free Wi-Fi was less of a pressing issue for them, so it wasn't as worthwhile for more businesses to offer free Wi-Fi to its customers. 3G killed the free Wi-Fi star.
After my experience in Japan, I could only think of how it would affect tourists visiting Australia, and I think it would be great to see our telcos team up to offer Wi-Fi services in areas where their 3G networks are lagging, and also invest in offering a free (or cheap) alternative for tourists who lack the ability to access it.
Or the telcos could look at reducing the incredibly outrageous global roaming costs, so we wouldn't need to scrounge for free Wi-Fi. But somehow, I still think that's a long way off.
This article was first published at ZDNet Australia.
Legitimate Web links haven for cybercrime - Security - News
BALI--Malware threats are getting more sophisticated, with 90 percent of them embedded in legitimate sites that Web users visit every day last year, according to a study by Blue Coat Systems.
In a report released Wednesday, the security vendor revealed that such attacks are increasingly migrating from free domains to known sites with trusted reputations and acceptable use category ratings.
"Cyber criminals want to be where the eyes are," said Jonathan Andresen, director of product and solution marketing Asia-Pacific, Blue Coat.
Speaking to ZDNet Asia at the sidelines of its regional partner conference here, Andresen explained that it is no longer adequate to educate users to look out for dodgy Web sites.
"Hackers are changing their attack methods, moving toward compromising the trust model for users so they are masquerading as your friends, selling things that you think are safe, sending you e-mail with your name on it," he said.
The less assuming users will then be "led down the path" to download malware from the Web, mostly via URL links rather than the traditional e-mail.
An analysis of Web requests from Blue Coat's cloud-based Webpulse service, which processes 3 billion requests weekly, also revealed that social networking sites have become a malware vector where phishing and click-jacking attacks were the two most common types of attacks on these platforms last year.
Obtaining user credentials that give access to banking, financial and other online accounts that use shared passwords, was the main reason for the shift in phishing attacks to social networks.
Online storage and the "open/mix" category of content sites including those that require users to upload data, such as Flickr, have also become malware "carriers".
According to report, the number of new online storage sites with malware increased 13 percent last year compared to the year before, while new "open/mix" content sites that hosted malware upped 29 percent.
"These two types of content sites had the highest increase in amount of malware over the last 12 months," Andresen added.
The security report also surveyed Internet usage trends which revealed that social networking activities last year took over as the new communication medium.
Based on Web requests from its 73 million-strong user base, among the subcategories of social networking activities, content servers came up tops. Personal pages and blogs ranked in second, followed by chat and instant messaging.
Web-based mail was the 17th most requested service last year, falling from 9th position in 2009 and 5th in 2008.
"This ongoing decline in popularity in driven by an overwhelming shift to social networking as the communication platform of choice for Internet users," the report said.
Another finding pointed a shift in Web behavior from personal lust to more business focused demands. Requests for content from dating and personals sites, pornography and adult content saw a "significant decline" in 2010, compared to their previous ranks at fourth, fifth and eighth, respectively,
Taking over top 10 these spots last year were requests for audio and video clips, new media and reference Web content.
Reputation-less
According to Blue Coat, reputation and signature-based protection systems have proven effective in combating Web security threats but it is no longer sufficient to rely on both mechanisms in today's fast-moving malware threat landscape.Because hackers are now targeting sites with good reputation, Web users will be caught off guard if no additional layer of protection is employed, Andresen noted. "For example, if abc.com is a reputable site, you don't scan it [for potential malware] but that's where the hackers will put their injection. It [instills] a false sense of security," he warned.
Tyler Thia of ZDNet Asia reported from Blue Coat's annual Asia-Pacific partner conference in Bali, Indonesia.
App-Rising: Who Will Fix America's Broken Broadband Policies?
Who Will Fix America's Broken Broadband Policies?
There can be no argument against the current deficiencies of America's broadband policies.
A third of Americans don't subscribe to broadband, and the rate of adoption is slowing.
Upwards of ten percent of American's can't subscribe, and there's no clear plan in place yet to provide them access to fix that.
Many Americans only have access to broadband that's too slow, too expensive, and not reliable enough.
Most of America is not yet realizing even a fraction of the potential that broadband has to offer.
And we ignore at our peril the reality that "broadband" in America means less bandwidth for more money than countries like South Korea, Sweden, and soon Australia.
Yet despite these undeniable truths about our shortcomings as a nation, our policymakers in DC continue to focus almost all attention on the issues of net neutrality and reclassification.
It was just two years ago that the Obama administration swept in a Democratic Congress with a wave of promising appointees that filled us with hope that a new day had dawned for broadband policy making. These were people who were supposed to get it. Who weren't afraid to take on big challenges.
Now two years later little progress has been made on directly addressing the issues listed above. At best the government's thrown $7 billion at the problem and made some tweaks around the edges of a system that's failing to deliver equal access to all Americans and to maximize the potential of this 21st century infrastructure.
Today we have a White House that says very little of substance about broadband. An FCC that's somehow lost the authority to regulate broadband and has been overly enamored with solving the relatively easy problem of freeing up more spectrum. And a Congress that's so polarized it can't move on anything, let alone something as potentially politically charged as making the many tough choices that need to be made in building a better framework for broadband policymaking.
And with a newly Republican House what's so so scary is that the odds of any progress being made on issues like net neutrality are nil, especially with each side of the issue ready to scream bloody murder if they have to give up an inch.
So what this all leads me to is, who's going to step up and lay out a path of sound policies to build a better broadband future for America?
The facts can't be ignored that we're not where we should be, so how do we get from here to there? Who's willing to recognize that to achieve long-term gains there may have to be some short-term losses and that we can't put aside entirely the possibility of making additional funding a national priority?
Now, I'm not totally without hope. NTIA is an agency in the White House that fancies itself an Internet policy shop. While it may not be diving in to try and solve all these broadband-related issues, they could play a helpful leadership role if they wanted to to at least get us pointed in the right direction.
I haven't given up on the FCC yet as the reality is that Genachowski still has three votes and the support of the White House, so if he wants to he could start taking up the charge and putting the pressure on Congress to act. But I'm not holding my breath that the FCC is capable of getting us going in the right direction as their actions have mostly been anything but visionary over the last two years.
And there's always the chance that President Obama wakes up to the significance of these issues relative to his desire to grow the economy as he leads this country deeper into the 21st century.
But where I'm most hopeful for the potential for change is in local, state, and maybe even some day Congressional leaders stepping up and realizing that they need to make broadband a priority, not just because it's what the country needs but also because it's what will help them get reelected.
What I'm saying is I think the only way to truly change the system is by engaging the people of this great nation, finding ways to bring those who are already interested in broadband together to learn from each other and to find ways to leverage that energy to teach those who are not yet connected. By empowering more users we create more educated voters who'll demand more from their leaders.
We also need to be supporting our digital innovators to help them find new solutions to old problems through the use of broadband-powered apps, services, and technologies. Because these are the future captains of industry who policymakers will ultimately need to be supporting the growth of to enable them to continue creating more jobs.
By doing these things those of us who are out there building networks of fiber, computers, and communities can overcome the follies of our "representatives" and their appointees in DC set this nation back on track to stay a global leader.
I didn't start this post intending for it to become a rallying cry for those who believe as I do in the power of fiber to positively impact every aspect of our lives and communities, but it's the only place I could find with certainty the kind of energy that's needed to fix what's wrong with our country.
Who will fix America's broken broadband policies? We will.
It won't be fast, and it won't be easy, but we will endure, innovate, and prosper in our broadband-powered future, and in so doing shape policies from the bottom up.
Posted by Geoff Daily on November 8, 2010 11:54 AM | Permalink | Comments (0) | TrackBacks (0)
More posts about policy
App-Rising: Why Broadband Utilization Matters More Than Deployment
Why Broadband Utilization Matters More Than Deployment/Adoption
In recent conversations I've been having with Michael Curri, head of Strategic Networks Group, it's become crystal clear to me that as a nation we're not focused enough on what really matters as it relates to broadband.
Most of the attention to date has gone to broadband deployment, figuring out how to get every last home online and how to encourage more deployment of faster networks. Increasingly the conversation also now turns to issues of broadband adoption, or how do you get everyone online.
What I've come to believe is that what's too often missing in this equation are questions surrounding broadband utilization, or how people and organizations are actually using broadband to improve their lives and how can we encourage more of that use.
The reason this is so important is simple: why are we building broadband networks? Is the end game to have viable, self-sustaining infrastructure? Is it to make sure that everyone's connected to that infrastructure? Or is what really matters what we do with that infrastructure once we've got it?
To some this may seem like an obvious line of thinking. We didn't deploy electricity in the 20th century for the sake of deploying electricity, and we didn't encourage adoption for the sake of being able to use electricity, it's what individuals and institutions did with electricity that led America to be the economic superpower of the 20th century.
I bring this up because I think we've been focusing too much energy on issues of deployment and adoption to the detriment of those surrounding utilization.
Is focusing on deployment important? Absolutely! Without broadband available none of the rest of this is important. But we can't lose sight of the fact that having viable networks is only part of the equation.
Is focusing on adoption important? Without a doubt! We need an environment whereby everyone understands the value of broadband and has the financial ability to get connected. But if we only focus on the basics of getting people online we'll never realize the full potential of what broadband has to offer.
A way to think about this is Maslow's hierarchy of needs. The bottom tiers of Physiological and Safety relate to the availability of broadband. The middle tier of Love-Belonging relates generally to the adoption of broadband. The top tiers of Esteem and Self-Actualization, then, relate to the utilization of broadband.
It's important to note that it's in this top tier where we find things like creativity, problem solving, confidence, and achievement.
What this says to me is that despite the fact that the bottom tiers of deployment and adoption are vitally important, if we focus all of our attention on them we're missing out on encouraging greater realization of the true benefits of broadband, which can only be found in the utilization of the many apps, services, and technologies that broadband makes possible.
So let's not limit our focus to deployment and adoption. Instead let's realize that, in the end, what really matters most is what we do with broadband once we've got it. And that if we want our communities to realize the full potential of what broadband makes possible, we can't stop at deployment and adoption when it's the utilization of broadband that drives economic development and improves quality of life.
Posted by Geoff Daily on November 10, 2010 10:06 AM | Permalink | Comments (0) | TrackBacks (0)
More posts about adoption broadband deployment policy utilization
App-Rising: Maslow's Hierarchy of Broadband Needs
« Solving Net Neutrality By Splitting The Baby (In A Good Way!) | Main | The Unspoken Tension Between Public and Private Broadband »
November 22, 2010 9:34 AM
Maslow's Hierarchy of Broadband Needs
In a recent post arguing for a great focus on broadband utilization rather than just broadband availability and adoption, I used the analogy of Maslow's hierarchy of needs. Today I want to explore that idea further in order to establish a Maslow's hierarchy of broadband needs.
To start with we must review the five levels of Maslow's hierarchy of needs, starting at the bottom:
- Physiological
- Safety
- Love/belonging
- Esteem
- Self-actualizationPhysiological needs relate directly to the physical needs of broadband. Without your physiological needs of food and water being met, you can't move up the hierarchy. To be able to use broadband, you need to first have it be available to you. Pretty simple.
Safety needs is where it gets a bit more interesting. I see at least two parallels in this analogy. The first is that broadband must be stable and reliable for users to feel secure using it. The second is that users must know enough about how to use the Internet that they feel safe navigating it. This last point in particular can be a major barrier to driving broadband adoption and utilization. If users don't feel comfortable online then that's a major disincentive to continued use.
The need for love and a sense of belonging has some profound ramifications when thought of related to broadband. Other than providing access to the world's information and entertainment, the biggest reason people use the Internet is to connect with others individually and as a community. The Internet has in fact redefined our sense of what "community" even means. This sense of belonging is what drives many people to spend hours online. Yet the flip side to this is that if you don't feel like there's a community online for you, or you don't know how to find or join the ones that do exist, that's going to be another major disincentive to use broadband.
With broadband available, and users feeling secure and part of a community, we now reach the tier of esteem, which is where users should start to get a sense of accomplishment and validation. This can come from others, like well wishes from friends when you first join and start using Facebook. It can also come from inside a user's self, as they accomplish something using broadband that has a direct impact on their lives. This level is so key as it's what gives users the confidence to believe they can do more, which is what will fuel their curiosity to find new ways broadband can benefit their lives.
We've now arrived at the top level of self-actualization, which is where users are able to continue reaching to achieve their full potential. Like in the traditional hierarchy of needs, you can see how this tier is only possible if the four tiers below it are addressed. Users need broadband to first be available, they then need to feel secure using it, they also need to feel a sense of community, and ultimately they need to feel a level of esteem to expand upon their utilization.
What's most important to keep in mind about this is that if users aren't able to reach the top of this hierarchy, then they'll never have the opportunity to benefit from the full scope of what broadband makes possible. It's only in this tier of self actualization that creativity's able to flourish, that users are able to consider changing their behaviors now that the rest of their needs are met, and that the real benefits of broadband are realized.
Now, I'm not sure if the broadband version of Maslow's hierarchy of needs should end here as there's still adjustments that could be made.
For example, for most users, issues of security are more about perception than reality. It's not that we necessarily have to do that much to make users more secure, we just need them to feel reasonably safe.
I also don't know if security, belonging, and esteem should be reordered as if a user has an experience that builds their esteem that can be the catalyst to get them more involved with the online communities that will lead to them feeling a sense of belonging.
There may also need to be additional tiers included so that we're not missing any of the major factors that drive users to want to use broadband more.
But I think this is a good start to helping better define how we should be thinking as we go about trying to get everyone online and benefitting from broadband. What this shows is that just making broadband available isn't enough. That in order to achieve universal broadband adoption and significantly greater broadband utilization we need to be cognizant of the many needs that drive the decision-making of users.
Posted by Geoff Daily on November 22, 2010 9:34 AM | Permalink | Comments (0) | TrackBacks (0)
More posts about adoption utilization
App-Rising: Google Goes To Bat For Fiber In A Big Way
February 10, 2010 1:46 PM
Google Goes To Bat For Fiber In A Big Way
Wow! Wow, wow, wow!!! That's all I've been thinking ever since reading the hot-off-the-presses announcement that Google's going to invest in building out open fiber networks to serve at least 50,000 and up to 500,000 households.
Their intent is threefold:
- To spur the development of the next generation of fiber-powered apps
- To experiment with and share the results of different models for deployment
- To prove that the open access model can work for broadband networksThe significance of each one of these can not be understated.
To have Google embrace the notion that fiber can enable a new era of high performance applications is huge. It means they're preparing to devote some of their own resources to the creation of new networked experiences, and in so doing they're going to raise the profile about the potential of fiber to a much larger audience of developers.
To have Google support fiber not just in words but in action by putting up capital to spur deployment shows a tremendous commitment to their country's future. And the fact that they're specifically looking to experiment with new models and to share the results with the public could have a profound impact on the future of fiber.
And to have Google put its money where its mouth in terms of proving the viability of open networks could ultimately shift the dynamic of how we perceive networks vs. services and applications.
These developments would be extremely important in a vacuum, but their impact is even more significant given where we stand with the broadband stimulus and national broadband plan.
To date the stimulus has been slow to get moving and limited in its imagination. To now have a new source of funds that presumably will be more open to exploring new ideas could mean that the good projects that slip through the stimulus cracks can still have a chance at making their projects a reality.
To date the national broadband plan has been on a lower-than-hoped-for trajectory with the FCC seemingly unwilling to set America on a more aspirational path. To now have a major Internet player coming out hard in support of the need for a more connected future will move this issue to the forefront and potentially force the government to step beyond their good-enough mindset and instead strive to be great. In fact, Google specifically cites the FCC's perceived lack of ambition as a driving force behind this initiative.
Not to put too much pressure on Google, but if they do this right, this initiative could be the most significant thing to ever happen to America's broadband ecosystem. It could set America on a path that the government seems unwilling and/or unable to lead us down.
So needless to say, today is a good day for Google, for fiber, and for our great nation.
Posted by Geoff Daily on February 10, 2010 1:46 PM | Permalink | Comments (0) | TrackBacks (0)
More posts about fiber google
API of the Week: Convert HTML to PDF with Joliprint's API
Wi-Fi Alliance: What is an "Evil Twin?"
What is an “Evil Twin”?
An Evil Twin, sometimes referred to as Wiphishing, is a potential security threat to users
of Wi-Fi, predominantly in public hotspots. A hacker sets up what is called a "rogue
access point" which mimics the characteristics of the network to which users expect to
connect. Users unknowingly connect to the rogue access point and the hacker's
network instead of the intended network.The Evil Twin hijacks data, such as passwords, account information, credit card
information, etc., and then connects the user to the Internet as intended. A sophisticated
evil twin can even control what Web site appears when the Internet is accessed, often
mimicking the intended starting Web site, for the purposes of capturing the user's private
information.To date, there have been no reported large-scale incidences of Evil Twin attacks, but
most network administrators have been aware of this theoretical threat for some years.
Recent media coverage of Evil Twin threats has directed consumer attention to the
matter, making users concerned about the problem and how they can protect
themselves.The Wi-Fi Alliance recommends that users of wireless networks exercise the same level
of caution they've learned to use to avoid scams in the wired world. End users should
change their passwords regularly, not respond to questionable e-mails, and look for
secure connections. As Wi-Fi continues to grow in reach and popularity, consumers
need to make some new simple security precautions a habit, like connecting through a
provider that uses encryption with a list of trusted hotspots, using a VPN, and always
enabling security within a home network. Also, users should make it a point to look for
products that are Wi-Fi CERTIFIED for or WPA2 security.