Monday, 5 March 2012

REVIEW: Hackers are winning security battle

REVIEW: Hackers are winning security battle
Hackers
Technology security professionals seeking wisdom from industry leaders in San Francisco this week saw more of the dark side than they had expected: a procession of CEO speakers whose companies have been hacked.


“It’s pretty discouraging,” said Gregory Roll, who came for advice and to consider buying security software for his employer, a large bank which he declined to name because he was not authorized to speak on its behalf. “It’s a constant battle, and we’re losing.”

The annual RSA Conference, which draws to a close on Friday, brought a record crowd of more than 20,000 as Congress weighs new legislation aimed at better protecting U.S. companies from cyber attacks by spies, criminals and activists.

If the bills suggest that hackers are so far having their way with all manner of companies, the procession of speakers brought it home in a personal way.

The opening presentation by Art Coviello, executive chairman of conference sponsor and recent hacking victim RSA, set the tone with the Rolling Stones song “You Can’t Always Get What You Want.”

RSA, owned by data storage maker EMC Corp, is the largest provider of password-generating tokens used by government agencies, banks and others to authenticate employees or customers who log on away from the office. Not long after last year’s RSA conference, the company said an email with a poisoned attachment had been opened by an employee.

That gave hackers access to the corporate network and they emerged with information about how RSA calculates the numbers displayed on SecurID tokens, which was in turn used in an attack on Lockheed Martin that the defence contractor said it foiled.

Coviello said he hoped his company’s misfortune would help foster a sense of urgency in the face of formidable opponents, especially foreign governments, who are being aided by the blurring of personal and professional online activities. Some 70 percent of employees in one survey he cited admitted to subverting corporate rules in order to use social networks or smartphones or get access to other resources, making security that much harder.

“Our networks will be penetrated. People will still make mistakes,” Coviello said. He argued that with better monitoring and analysis of traffic inside company networks, “we can manage risk to acceptable levels.”

If that didn’t inspire enough enthusiasm after the worst year for corporate security in history – including the rise of activist hacks by Anonymous, numerous breaches at Sony Corp, and attacks on Nasdaq software used by corporate boards – there was more to come.

Next onstage was James Bidzos, CEO of core Internet infrastructure company VeriSign, which disclosed in an October securities filing that it had lost unknown data to hackers in 2010. He was followed by Enrique Salem, CEO of the largest security company, Symantec, which recently admitted that source code from 2006 version of its program for gaining remote access to desktop computers had been stolen and published.

FBI Director Robert Mueller spoke on Thursday, warning that he expected cyber threats to pass terrorism as the country’s top threat.

Though all sounded an upbeat call to arms, some watching grumbled that vendors with little credibility were trying to use their own shortcomings to peddle more expensive and unproven technology.

“There’s some panic” among the buyers, said a security official with ING Groep NV who asked not to be named because he was not authorized to speak to the press. Banks are very sensitive to questions about security breaches and often deny they have any significant problems in this area.

That panic contributed to vigorous panel discussions and hallway debates about who should be in charge of safeguarding defense companies, banks and utilities – private industry itself, the U.S. Department of Homeland Security or the National Security Agency, which has the greatest capability but a legacy of civil liberties issues.

A pending bill backed by Senate Majority Leader Harry Reid would put DHS in the lead, with assistance from NSA. Former NSA chief Michael Hayden said in an interview at the conference that should suffice.

“The Net is inherently insecure,” Hayden said. “We need to quit admiring the problem and move out. No position could be worse than the one we’re in now.”

Coviello said one of the few pieces of good news was that the country as a whole is now realizing the gravity of the loss of its trade and government secrets, along with the difficulty of reversing the trend.

“People have definitely talked more seriously after our breach,” he said in an interview. “Maybe a sense of realism has settled in.”

Spain: Google should respect "right to be forgotten"

Spain: Google should respect "right to be forgotten"

GOOGLE

Spain's highest court wants the top court in Europe to decide if requests by Spanish citizens to have data deleted from Google's search engine are lawful, in a case that could put more pressure on it to review its privacy policies.


The court, the Audiencia Nacional, said it had asked the European Court of Justice (ECJ) to clarify whether Google should remove data from its search engine's index and news aggregator even when it is not responsible for producing the content in its search results.

Madrid's data protection authority has received over 100 requests from Spanish citizens to have their data removed from Google's search results.

Among the cases is one of a Spanish man who complained to the national regulator about a notice of his home's repossession for non-payment of social security, which kept appearing in a national newspaper in the Google News aggregator. In another case, a plastic surgeon wants to get rid of archived references to a botched operation.

The Spanish judges also asked the ECJ whether the complainants must take their grievances to California, where Google is based and said it wanted the matters heard.

The referral of the case to the ECJ marks the first formal inquiry into when people can demand that their data be deleted.

Such a "right to be forgotten" is included in updated data protection rules proposed by Viviane Reding, the European commissioner for justice and fundamental rights, and is being considered by the European Parliament.

The Spanish judges' request also fuels the ongoing debate over when the web giant should delete content from its massive news index.

Google has maintained that it cannot lawfully remove any content for which it is merely the host and not the producer, a principle enshrined in EU law on eCommerce since 2000.

The U.S.-based web search company told the Spanish prosecutor it needed more legal justification for removing references to events in an individual's history, the court said in a statement on its website.

Google was upbeat about the referral to the European court - in a case likely to be watched closely by many web firms which would welcome more clarity on usage of right to be forgotten.

"We support the right to be forgotten, and we think there are ways to apply it to intermediaries like search engines in a way that protects both the right to privacy and the right to free expression," a Google spokesman told Reuters.

In one of the highest profile cases over the right to be forgotten, Google told the Leveson inquiry into the British press on January 26 that it had removed hundreds of web pages that contained information about former motor-racing boss Max Mosley and his sex life.

The Spanish referral comes two days after the French Data Protection Authority said it wanted Google to delay implementing a new privacy policy which allows all of its services such as Gmail, YouTube and Google+ to share users' information. Google introduced the new policy on March 1.

Facebook eyes at mobile ad market

Facebook eyes at mobile ad market
Facebook 



For Facebook it must look like a no-brainer - exploit its huge consumer loyalty and half a billion mobile phone users as a way of opening up the mobile market to blue chip advertisers.

Trouble is, there are reasons for the limited success so far of mobile advertising and none of them have completely gone away. Even if Facebook succeeds, others eyeing this potentially massive market may still struggle to cash in.

Earlier this week, Facebook announced new ways for businesses to advertise to its users, including on mobile for the first time, by having marketing messages appear in its members' news feeds -- partly an effort to establish regular revenue streams as it gears up for an initial public offering.

The move could help give advertisers access to the mobile phone market, long seen as underexploited, but is unlikely to open up the market more generally.

Despite pent-up demand from advertisers -- and a vast discrepancy between the amount of time consumers spend on their mobile devices and the advertising dollars spent there -- there are still big barriers to mobile phone ads.

Mobile has proved almost impenetrable to advertisers except through Google Inc searches for a host of reasons, including the small screen, a lack of good mobile websites and resistance to the invasion of a space seen as more private than a computer.

Much experimentation is underway at telecom operators, ad agencies and software firms to find ways to deliver tailored ads to people based on their location and capitalise on a boom in smartphone sales, without driving away customers.

In Britain, for example, the three biggest mobile operators including Vodafone Plc are creating a joint venture that they say will allow advertisers to create a one-stop shop for advertisers to book campaigns that reach a national audience, as well create coupons and loyalty schemes for stores.

Together, they have 70 million subscribers -- more than the entire UK population as many Britons have more than one device -- but such numbers are dwarfed by Facebook's 425 million who regularly access the site from a mobile phone.

Facebook could succeed where others have failed because the messages will appear as a news item where a user has "liked" a brand or bought a product via Facebook, meaning they should feel more like a personal recommendation than an ad.

"You cannot have a brand coming along and just flaunting itself," says Marco Veremis, president of digital marketing firm Upstream, which has run mobile campaigns for brands including Coca-Cola Co , Nestle SA and Royal Dutch Shell Plc .

"I would say they are going about it very carefully."

IRRITATING ADS
Of the time spent consuming media, more than a quarter is on a mobile device, surpassing television at 22 percent, according to a study released this week at the Mobile World Congress in Barcelona by InMobi, the world's biggest independent mobile advertising network.

Yet mobile accounts for only around 2 percent of the near half a trillion dollars spent globally on advertising each year, while television attracts about 40 percent.

Even powerful companies like Apple Inc are struggling to make an impact.

Advertising agencies and mobile operators are hopeful that the rapid spread of smartphones and tablets, with their Internet capabilities, bigger screens and greater processing power, will create new opportunities for mobile advertising.

Ad agencies can be more inventive than ever before, for example creating layers of video or interactive screens that open up when a user clicks on a banner ad, offering a more interesting experience and new ways of measuring engagement.

Mobile ad technology firm Celtra recently created a campaign for Starbucks Corp in which users could click on an ad to be taken to a screen where they could design their own cup, with the best ones featured in an online gallery.

"Because it's such a personal device, we'll see higher levels of engagement, and that should encourage higher levels of responsiveness," says David Gosen, European managing director of the telecoms unit of research firm Nielsen.

But the personal nature of the phone is a two-edged sword.

According to a survey released by Upstream last week, the vast majority of adults in the United States and Britain find banner adverts on mobile devices irritating, and fewer than one in six who surf the Web on a mobile have ever clicked on one.

THREE FORCES
For those who do get it right, the rewards can be enormous.

Google, which leads the market for online paid search advertising, said in October its annual run rate for mobile revenue had more than doubled to $2.5 billion in a year.

Search results are not generally perceived by consumers as advertising, while the fact that many users choose to share their location on a mobile device to use services like Google Maps helps to deliver more targeted results.

Twitter also expanded its mobile advertising offering this week, and may succeed for the same reason, because its sponsored tweets are seen by many as news.

Facebook is now planning to use its knowledge of its members, gathered through their voluntary sharing of status reports, personal details and likes, to build an offering to rival Google's.

"Facebook is becoming the biggest collection of preferences in the universe," says Karl-Heinz Land, head of social internet commerce at business intelligence firm MicroStrategy, which analyses Facebook data for corporate clients.

"Social, mobile, local -- these are the three forces which are creating the perfect wave. Facebook now makes it very easy."

Privacy concerns, however, are a key risk for any company seeking to commercially exploit its users' data, especially one that has such highly personal information as Facebook does.

Google is already facing a backlash against its new policy of pooling all the data it collects from its search, gmail, YouTube and Google+ social network -- which has been seen as a move to help it compete better against Facebook.

Facebook users may not necessarily understand when they are volunteering to have their purchase of an item broadcast on their news feed, and could be embarrassed at the consequences.

Users may also perceive advertising that is too personalised as creepier on such a personal device as a phone in their pocket that knows where they are than on a desktop.

"People don't like to have too targeted advertising because it can feel a little spooky," says Paul Lee, head of technology, media and telecoms research at consultancy Deloitte, saying campaigns sometimes deliberately blend in less relevant ads.

EXPLOITING CUSTOMERS
Some mobile operators, who have enormous amounts of data about their customers but have largely failed to or decided not to exploit that information, argue they are best placed to work with advertisers and are also the best guardians of customer information.

"Our economic model simply doesn't require us to monetise the hell out of every piece of data we ever get. Our approach is that if I make the service better for my customer, and he gets more out of it, then it's a legitimate conversation," says Ronan Dunne, head of Telefonica SA's O2 UK.

Some operators are already offering services where customers explicitly opt in for advertising messages in exchange for free minutes or other benefits.

Mobile media company Blyk has teamed up with operators Orange , T-Mobile and Aircel to deliver between one and four marketing messages per day to customers who have chosen to take part in return for minutes or discounts.

It quadrupled its mainly young audience to 4 million last year and has helped its operator partners reduce the proportion of subscribers switching away to other services.

In Turkey, about 8 million Turkcell customers have downloaded commercial jingles that play while a caller is waiting in exchange for free minutes. One-third of Turkcell's mobile internet revenue now comes from mobile marketing.

But in general, the revenues that mobile operators have made from marketing have been negligible, while Web giants have exploited their networks to push their own services and earn ad revenue in the process.

So far, Facebook seems to be getting the right balance between privacy and money-making, although the path is fraught with danger, especially as the company opens up to private investors impatient for profits, says Upstream's Veremis.

"They recognise that over mobile you've got to advertise less and your advertising shouldn't look like advertising," he says. "But there is absolutely no way to sidestep the fact that if you ask users they'd definitely prefer that this never happened."

REVIEW: NASA website hacked 13 times last year

REVIEW: NASA website hacked 13 times last year
NASA



NASA said hackers stole employee credentials and gained access to mission-critical projects last year in 13 major network breaches that could compromise U.S. national security.

National Aeronautics and Space Administration Inspector General Paul Martin testified before Congress this week on the breaches, which appear to be among the more significant in a string of security problems for federal agencies.

The space agency discovered in November that hackers working through an Internet Protocol address in China broke into the -network of NASA's Jet Propulsion Laboratory, Martin said in testimony released on Wednesday. One of NASA's key labs, JPL manages 23 spacecraft conducting active space missions, including missions to Jupiter, Mars and Saturn.

He said the hackers gained full system access, which allowed them to modify, copy, or delete sensitive files, create new user accounts and upload hacking tools to steal user credentials and compromise other NASA systems. They were also able to modify system logs to conceal their actions.

"Our review disclosed that the intruders had compromised the accounts of the most privileged JPL users, giving the intruders access to most of JPL's networks," he said.

In another attack last year, intruders stole credentials for accessing NASA systems from more than 150 employees. Martin said the his office identified thousands of computer security lapses at the agency in 2010 and 2011.

He also said NASA has moved too slowly to encrypt or scramble the data on its laptop computers to protect information from falling into the wrong hands.

Unencrypted notebook computers that have been lost or stolen include ones containing codes for controlling the International Space Station, as well as sensitive data on NASA's Constellation and Orion programs, Martin said.

A NASA spokesman told Reuters on Friday the agency was implementing recommendations made by the Inspector General's Office.

"NASA takes the issue of IT security very seriously, and at no point in time have operations of the International Space Station been in jeopardy due to a data breach," said NASA spokesman Michael Cabbagehe.

AIR FORCE SCRAPS IPAD PURCHASE
In a separate development, the U.S. Air Force said on Friday it had scrapped a plan to outfit thousands of personnel with second-generation iPad tablet computers from Apple Inc , but denied the reversal was because some of the software it wanted on the devices had been written in Russia.

Two days ago, news website Nextgov raised questions about a requirement that the 2,861 iPad2s come equipped with GoodReader, an electronic document display program written by an independent Russian developer.

The devices were to be used to store and update flight information, regulations and orders, according to procurement documents.

"The cancellation was not the result of any concern about GoodReader," said Matt Durham, a spokesman at the Air Force Special Operations Command.

He said the cancellation of the six-week-old order followed a decision that the procurement should not have been reserved for small businesses.

The military and other branches of government have been putting an increased emphasis on "supply-chain security" as they try to make sure that hardware, software and other components have not been tampered with by other nations.

This has proved challenging because so many parts come from overseas. Even American companies often contract for programming work abroad.

Mike Jacobs, who headed the National Security Agency's program for defending U.S. equipment, said in an interview he had killed a major procurement of encryption software within seconds after learning that a U.S. supplier had included a small amount of Russian-made code.

REVIEW: Startup sued for putting local TV on the iPhone

REVIEW: Startup sued for putting local TV on the iPhone
Startup sued for putting local TV on the iPhone

NEW YORK -- Broadcasters have sued a startup backed by media billionaire Barry Diller that sends live local TV feeds to iPhones and iPads in the New York area.
Two groups of broadcasters, including ABC, CBS, NBC, Fox and the local PBS station, filed suits Thursday in federal court, saying Aereo Inc.'s service uses their content without permission.

Aereo launched two weeks ago, but it's available by invitation only. Subscribers pay $12 per month for access to 27 locally broadcast TV channels through the Web browsers on their Apple devices. It's set to open up to more subscribers on March 14. The company hopes to expand service to other cities.

Aereo says the suits are groundless and it looks forward to "a full and fair airing of the issues."

Aereo has more than $25 million in venture capital backing, with more than $20 million of it coming from a funding round led by InterActiveCorp, which owns Match.com, Ask.com and other websites. Diller is the chairman of InterActiveCorp and the former CEO of Fox.

The startup exploits what it believes is a loophole in the laws governing retransmission of local broadcasts. It doesn't use one big antenna to pick up the local broadcasts and relay them to the Internet. Instead, it uses one tiny antenna for each subscriber that's watching.

People are entitled to watch local broadcast TV when they use their own antennas, and Aereo believes that what it's doing, legally speaking, is acting as a remote antenna for each subscriber, rather than taking broadcasts and retransmitting them.

Broadcasters aren't buying that argument.

"Aereo's service to the end user is similar to and competes with cable or satellite operators and telephone companies that also retransmit broadcast programming to their subscribers, except that Aereo's service is unlawful," said the suit filed by ABC, CBS, NBC and others.

Mobile apps grows for Indian appetite

Mobile apps grows for Indian appetite 
Mobile apps grows for Indian appetite 



Be it playing Angry Birds or watching movies on the go, a rise in the number of low-cost smartphones has enabled young Indians to access mobile applications like never before.

According to search engine giant Google, around 40 million Indians access the Internet through their mobile phones and there are 30 million apps downloads in one week. A combined survey by global market research firm IPSOS and Google found the 18-29 age-group using smartphones the most.

"Availability of smart and feature-rich phones at low cost, low telecom tariffs and flexibility of accessing the services on the go have made mobile apps all the more popular in a price sensitive country like India," Amit Sachdeva, partner, business advisory firm Ernst & Young (E&Y), told IANS.

Low-cost smartphones in the Indian market are available at a price as low as Rs.5,000.

"Launch of 3G services has become an added advantage. The sector will witness a boom once 4G and LTE (long term evolution) services are launched as well," he added.

According to Sachdeva, the most popular apps in India are the entertainment apps such as games, music and Bollywood followed by social networking and utility services that include paying off electricity bills and job search.

The e-commerce segment is fast gaining popularity with services. Deals and discounts are being accepted across the country. And mobile banking, which has a long way to go owing to security concerns, would soon draw customers in large numbers, he said.

Data collated by IT research firm CyberMedia showed the smartphone sales in India surged 87 percent at 11.2 million units in 2011 over the previous year as almost 150 models were launched by more than 30 vendors.

Unlike earlier days when pre-loaded apps like social media and music applications were mostly used, people are now buying games, said Virat Khutal, chief operating officer, mobile apps development firm Twist Mobile.

Instead of spending Rs.150 or more in buying tickets for a movie which would end in three hours, youngsters these days think why not buy an app which would be available with you all the time even while you are on the move, said Khutal.

According to Ditto TV, a Zee Group company which earlier this week launched its services in India, there has been a paradigm shift in the way Indians consume information.

"The need to be mobile has become an indispensable one and the role of internet-enabled devices paramount," said Vishal Malhotra, business head, New Media, Zee Business Enterprises.

"We are seeing a substantial response to mobile devices that allow users to have access anywhere, anytime. This has spurred the growth of applications which has developed into a full-fledged market," he told IANS.

The firm is bullish about the Indian apps market and is planning to tap an audience ready for entertainment on the go.

"We are looking at a subscriber base of one million users by the end of our first year," Malhotra said.

Ditto TV provides live channel-agnostic TV content and would soon incorporate features such as catch-up TV by which users will be able to share information related to shows, content that they like.

Russia Fake US envoy's tweets spark ire

Russia Fake US envoy's tweets spark ire
Twitter



Some mischievous fakery on Twitter has briefly caused a flare-up in already strained U.S.-Russian relations.

An Internet user mimicking U.S. Ambassador Michael McFaul's account tweeted that evidence of mass violations would undermine the legitimacy of Russia's presidential election Sunday. Prime Minister Vladimir Putin is expected to win handily.That tweet sparked indignant responses from, among others, Russian presidential aide Arkady Dvorkovich.The real McFaul hastily issued messages distancing himself from his disguised online doppelganger.Dvorkovich tweeted his relief, but likely not before the damage was done.Putin supporters have routinely accused the U.S. - and McFaul personally - of being behind the unprecedented protests against his rule.