Citrix Updates Xen Server
Citrix has released its open source Xen Server 6.2 to go up against VMware’s closed source free Vsphere hypervisor.
Citrix for years has maintained a free, open source version of its Xen hypervisor but it has been losing ground to KVM and in particular VMware’s free Vsphere hypervisor. Now the firm has released Xen Server 6.2 and a community website that the firm hopes will help increase support for its open source hypervisor.
According to Citrix, Xen Server 6.2 supports Cloud Stack, Open Stack and Citrix’s own Cloud Platform. The firm touted support for the latest guest operating systems including Microsoft’s Windows 8 and Windows Server 2012.
Sameer Dholakia, group VP and GM of Citrix’s Cloud Platforms Group said, “The cloud era has brought a lot of exciting opportunities for data center infrastructure, but the reality is that one size doesn’t fit all when it comes to virtualization.
“By empowering our users and partners with a committed open source strategy and community for XenServer – which already powers some of the largest clouds in the world – we are moving the needle in innovation to help customers of all sizes, and at all stages of their cloud strategies, to maximize the benefits they gain from vitualization and the cloud.”
Citrix said its Xen Server 6.2 supports its Xen Desktop software, including Intellicache and Dynamic Memory Control. The firm said it has added Desktop Director alerts so that administrators can be notified of low resources to try to prevent virtual machines from becoming unusuable.
Citrix will be hoping that as firms get used to the free version of Xen Server they will shell out for the full versions that cost up to $3,250. However, Citrix’s continued support of its free, open source Xen Serven means that VMware will have to continue offering a free version of Vsphere if it doesn’t want to leave a gap in the market.
Are CCTV Cameras Hackable?
June 28, 2013 by admin
Filed under Around The Net
Comments Off on Are CCTV Cameras Hackable?
When the nosy British bought CCTV cameras, worried citizens were told that they could not be hacked.
Now a US security expert says he has identified ways to remotely attack high-end surveillance cameras used by industrial plants, prisons, banks and the military. Craig Heffner, said he discovered the previously unreported bugs in digital video surveillance equipment from firms including Cisco, D-Link and TRENDnet.
They could use it as a pivot point, an initial foothold, to get into the network and start attacking internal systems. Heffner said that it was a significant threat as somebody could potentially access a camera and view it. Or they could also use it as a pivot point, an initial foothold, to get into the network and start attacking internal systems.
He will show how to exploit these bugs at the Black Hat hacking conference, which starts on July 31 in Las Vegas. Heffner said he has discovered hundreds of thousands of surveillance cameras that can be accessed via the public internet.
Office 365 Goes Yammer
June 21, 2013 by admin
Filed under Around The Net
Comments Off on Office 365 Goes Yammer
Microsoft has taken the first step in its integration roadmap for SharePoint and Yammer, allowing Office 365 customers to swap SharePoint Online’s activity stream with Yammer’s.
This first, modest integration point will let SharePoint Online users click on the Yammer link and launch a separate browser window where they’re asked to sign in.
Later this year, Microsoft will deepen the integration with a single sign-on and the addition of Yammer to the main Office 365 interface, which will begin to merge the two products’ user experience.
Next month, Microsoft will release a Yammer application for SharePoint that will let users embed a Yammer group feed into a SharePoint site. The application will work both with SharePoint Online and with the on-premises version of the server SharePoint 2013.
Also in July, Microsoft will provide instructions for replacing the SharePoint 2013 newsfeed with Yammer’s.
For now, the first integration step in optional, but Microsoft is strongly suggesting that Office 365 customers make the activity stream switch to Yammer.
“Our recommendation is to use Yammer, since it’s our big bet for enterprise social, and we’re committed to making it the underlying social layer for all our products,” wrote Christophe Fiessinger, a Microsoft Office Division product marketing manager, in a blog post.
Customers should also accompany the technical change with an outreach effort to promote the benefits of using the enterprise social networking features of Yammer, according to Fiessinger.
“To drive adoption and really get the value out of Yammer, you need a strategy, advocates, and openness to the way it will transform the way people in your organization work and communicate,” he wrote.
Microsoft bought Yammer for $1.2 billion in mid-2012 in order to boost the development and availability of enterprise social collaboration features in SharePoint and in other Office and Microsoft business software like the Dynamics applications.
Microsoft makes a convincing case for the benefits of integrating Yammer with SharePoint and its other software to provide a common social collaboration layer, but the process is clearly complicated and will take years.
IBM Buys SoftLayer
IBM has signed an agreement to purchase SoftLayer Technologies, as it looks to accelerate the build-out of its public cloud infrastructure. The company is also forming a services division to back up the push.
The financial details of the deal were not announced, but SoftLayer is the world’s largest privately held cloud computing infrastructure provider, according to IBM.
IBM already has an offering that includes private, public and hybrid cloud platforms. The acquisition of SoftLayer will give it a more complete in-house offering, as enterprises look to keep some applications in the data center, while others are moved to public clouds.
SoftLayer has about 21,000 customers and an infrastructure that includes 13 data centers in the U.S., Asia and Europe, according to IBM. SoftLayer allows enterprises to buy compute power on either dedicated or shared servers.
Following the close of the acquisition of SoftLayer, which is expected in the third quarter, a new division will combine its services with IBM’s SmartCloud. IBM expects to reach $7 billion annually in cloud revenue by the end of 2015, it said.
Success is far from certain: The public cloud market is becoming increasingly competitive as dedicated cloud providers, telecom operators and IT vendors such as Microsoft and Hewlett-Packard all want a piece. The growing competition should be a good thing for customers if it drives down prices. For example, Microsoft has already committed to matching Amazon Web Services prices for commodity services such as computing, storage and bandwidth.
Not all hardware vendors feel it’s necessary to have their own public cloud. Last month, Dell changed strategy and said it would work with partners including Joyent, instead of having its own cloud.
McAffee See Sure In Spam
The first three months of 2013 have seen a surge in spam volume, as well as a growing number of samples of the Koobface social networking worm and master boot record (MBR) infecting malware, according to antivirus vendor McAfee.
After remaining relatively stable throughout 2012, spam levels rose during the first quarter of 2013, reaching the highest volume seen in the past two years, McAfee said in a report released Monday.
The amount of spam originating from some countries rose dramatically, McAfee said. Spam from Belarus increased by 540% while spam originating in Kazakhstan grew 150%.
Cutwail, also known as Pushdo, was the most prevalent spam-sending botnet during the first quarter, McAfee said.
The increased Pushdo activity has recently been observed by other security companies as well. Last month, researchers from security firm Damballa found a new variant of the Pushdo malware that’s more resilient to coordinated takedown efforts.
On the malware front, McAfee has also seen a surge in the number of Koobface samples, which reached previously unseen levels during the first quarter of 2013. First discovered in 2008, Koobface is a worm that spreads via social networking sites, especially through Facebook, by hijacking user accounts.
The number of malware samples designed to infect a computer’s master boot record (MBR) also reached a record high during the first three months of 2013, after increasing during the last quarter of 2012 as well, McAfee said.
The MBR is a special section on a hard disk drive that contains information about its partitions and is used during the system startup operation. “Compromising the MBR offers an attacker a wide variety of control, persistence, and deep penetration,” the McAfee researchers said in the report.
The MBR attacks seen during the first quarter involved malware like StealthMBR, also known as Mebroot; Tidserv, also known as Alureon, TDSS and TDL; Cidox and Shamoon, they said.
Will Qualcomm Be First?
We could not get the right timeframe for the launch of Qualcomm’s successor to the high-end Snapdragon 800, but there is no doubt that Qualcomm, Samsung, Nvidia and other ARM supporters are thinking about 20nm products where some of them will be based on Cortex A57.
Qualcomm has its own Krait core that can be adapted to 20nm and follow up the success of Snapdragon 600 and the soon to come Snapdragon 800. It turns out that it traditionally takes 18 to 24 months for the mobile industry to shift from one process to another and Qualcomm had its first 28nm part in April 2012, with the Snapdragon S4, used in the HTC One S. The first ever 28nm part from Qualcomm was the Snapdragon S4 MSM8260A that is now more than a year old and a relatively obsolete product.
Less than a year after the first 28nm product Qualcomm followed up with the Snapdragon 600 that is shipping in millions of high end devices right now. In a month or two it plans to release Snapdragon 800 based on new Krait 400 core and add a new core and get even better performance.
The next step is the 20nm core that should start shipping before the end of 1H 2014. We would not be surprised to see 20nm Krait demoed at CES 2014 already in January, see more of it at the Mobile World Congress in February and the volume shipment to follow in early Q2 2014. This is the expected schedule and not something we got from Qualcomm.
The only official world we got is that the new generation traditionally comes 18 to 24 months after the first iteration of a current one. This can give you an idea that Tegra 5, codenamed Logan, should show up at a similar time, along with Samsung’s 20nm Exynos.
Apple Raising Prices In Japan
June 10, 2013 by admin
Filed under Uncategorized
Comments Off on Apple Raising Prices In Japan
Apple Inc increased prices of iPads and iPods in Japan on Friday, becoming the highest-profile brand to join a growing list of foreign companies asking Japanese consumers to pay more as a weakening yen squeezes profit.
Some U.S. companies have inoculated themselves at least temporarily against the yen’s fall through financial hedging instruments, while others are charging customers more.
The yen has fallen more than 20 percent against the U.S. dollar since mid-November when then-opposition leader Shinzo Abe, who is now prime minister, prescribed a dose of radical monetary easing to reverse years of sliding consumer prices as part of a deflation-fighting policy, dubbed “Abenomics.”
The Bank of Japan, under a new Abe-backed governor, in April promised to inject $1.4 trillion into the economy in less than two years to achieve 2 percent inflation in roughly two years.
Price rises are rare in Japan, which has suffered 15 years of low-grade deflation. A few other foreign brands have also raised prices on products, providing an early sign of inflation for Abe and an indication that these companies feel consumer demand is strong enough to withstand the increases.
Still, price rises would have to spread much more widely, especially to lower-end discretionary goods, to show that Abe’s aggressive policies are helping reinvigorate the economy.
Apple, one of the most visible foreign companies in Japan, raised the price of iPads by up to 13,000 yen ($130) at its local stores. The 64-gigabyte iPad will now cost 69,800 yen, up from 58,800 yen a day ago, an Apple store employee said. The 128-gigabyte model will cost 79,800 yen compared with 66,800 yen.
Apple also upped prices of its iPod music players by as much as 6,000 yen and its iPad Mini by 8,000 yen.
Will Arm/Atom CPUs Replace Xeon/Opteron?
Comments Off on Will Arm/Atom CPUs Replace Xeon/Opteron?
Analyst are saying that smartphone chips could one day replace the Xeon and Opteron processors used in most of the world’s top supercomputers. In a paper in a paper titled “Are mobile processors ready for HPC?” researchers at the Barcelona Supercomputing Center wrote that less expensive chips bumping out faster but higher-priced processors in high-performance systems.
In 1993, the list of the world’s fastest supercomputers, known as the Top500, was dominated by systems based on vector processors. They were nudged out by less expensive RISC processors. RISC chips were eventually replaced by cheaper commodity processors like Intel’s Xeon and AMD Opteron and now mobile chips are likely to take over.
The transitions had a common thread, the researchers wrote: Microprocessors killed the vector supercomputers because they were “significantly cheaper and greener,” the report said. At the moment low-power chips based on designs ARM fit the bill, but Intel is likely to catch up so it is not likely to mean the death of x86.
The report compared Samsung’s 1.7GHz dual-core Exynos 5250, Nvidia’s 1.3GHz quad-core Tegra 3 and Intel’s 2.4GHz quad-core Core i7-2760QM – which is a desktop chip, rather than a server chip. The researchers said they found that ARM processors were more power-efficient on single-core performance than the Intel processor, and that ARM chips can scale effectively in HPC environments. On a multi-core basis, the ARM chips were as efficient as Intel x86 chips at the same clock frequency, but Intel was more efficient at the highest performance level, the researchers said.
Twitter’s Authentication Has Vulnerabilities
June 6, 2013 by admin
Filed under Around The Net
Comments Off on Twitter’s Authentication Has Vulnerabilities
Twitter’s SMS-based, two-factor authentication feature could be abused to lock users who have not enabled it for their accounts if attackers gain access to their log-in credentials, according to researchers from Finnish antivirus vendor F-Secure.
Twitter introduced two-factor authentication last week as an optional security feature in order to make it harder for attackers to hijack users’ accounts even if they manage to steal their usernames and passwords. If enabled, the feature introduces a second authentication factor in the form of secret codes sent via SMS.
According to Sean Sullivan, a security advisor at F-Secure, attackers could actually abuse this feature in order to prolong their unauthorized access to those accounts that don’t have two-factor authentication enabled. The researcher first described the issue Friday in a blog post.
An attacker who steals someone’s log-in credentials, via phishing or some other method, could associate a prepaid phone number with that person’s account and then turn on two-factor authentication, Sullivan said Monday. If that happens, the real owner won’t be able to recover the account by simply performing a password reset, and will have to contact Twitter support, he said.
This is possible because Twitter doesn’t use any additional method to verify that whoever has access to an account via Twitter’s website is also authorized to enable two-factor authentication.
When the two-factor authentication option called “Account Security” is first enabled on the account settings page, the site asks users if they successfully received a test message sent to their phone. Users can simply click “yes,” even if they didn’t receive the message, Sullivan said.
Instead, Twitter should send a confirmation link to the email address associated with the account for the account owner to click in order to confirm that two-factor authentication should be enabled, Sullivan said.
As it is, the researcher is concerned that this feature could be abused by determined attackers like the Syrian Electronic Army, a hacker group that recently hijacked the Twitter accounts of several news organizations, in order to prolong their unauthorized access to compromised accounts.
Some security researchers already expressed their belief that Twitter’s two-factor authentication feature in its current implementation is impractical for news organizations and companies with geographically dispersed social media teams, where different employees have access to the same Twitter account and cannot share a single phone number for authentication.
Twitter did not immediately respond to a request for comment regarding the issue described by Sullivan.
Google Updates It’s SSL Certificate
Google has announced plans to upgrade its Secure Sockets Layer (SSL) certificates to 2048-bit keys by the end of 2013 to strengthen its SSL implementation.
Announcing the news on a blog post today, Google’s director of information security engineering Stephen McHenry said it will begin switching to the new 2048-bit certificates on 1 August to ensure adequate time for a careful rollout before the end of the year.
“We’re also going to change the root certificate that signs all of our SSL certificates because it has a 1024-bit key,” McHenry said.
“Most client software won’t have any problems with either of these changes, but we know that some configurations will require some extra steps to avoid complications. This is more often true of client software embedded in devices such as certain types of phones, printers, set-top boxes, gaming consoles, and cameras.”
McHenry advised that for a smooth upgrade, client software that makes SSL connections to Google, for example, HTTPS must: “perform normal validation of the certificate chain; include a properly extensive set of root certificates contained […]; and support Subject Alternative Names (SANs)”.
He also recommended that clients support the Server Name Indication (SNI) extension because they might need to make an extra API call to set the hostname on an SSL connection.
He pointed out some of the problems that the change might trigger, and pointed to a FAQ addressing certificate changes, as well as instructions for developers on how to adapt to certificate changes.
F-secure’s security researcher Sean Sullivan advised, “By updating its SSL standards, Google will make it easier to spot forged certificates.
“Certificate authorities have been abused and/or hacked in the past. I imagine it will be more difficult to forge one of these upgraded certs. Therefore, users can have more confidence.”








Sign up for our Technology Newsletter