Thursday, 16 May 2013

VMware launches dual persona feature for Verizon smart phones

The feature is currently available on the LG Intuition and Motorola RAZR M smartphones

VMware today announced that its dual persona mobile device software is now available on some Android OS-based mobile devices sold by Verizon.

Dual persona technology creates two OS instances, one for business use and the other for personal use.

VMware's dual persona application, called VMware Horizon Mobile, is available now for the LG Intuition and Motorola RAZR M smartphones. Workers who already own the phones can download the application from VMware's website.

VMware said additional device support is expected throughout the year.

"There's no special hardware requirement to run this. All you need is a single core processor and 1GB of RAM," said Srinivas Krishnamurti, senior director of Mobile Solutions for End-User Computing at VMware. "Our expectation is that by end of year there will be tens of millions of VMware ready devices."

VMware and Red Bend separately announced plans to offer dual persona smartphone technology last year. Red Bend offers the ability to host both a business and personal OS instance on hardware. VMware and other companies offer it through software.

Red Bend's Type 1 hypervisor runs on a new generation of mobile processors, such as the ARM Cortex-A15.

VMware uses a Type 2 hypervisor product that embeds on a smartphone and awaits activation by a corporate IT department.

A Horizon Mobile Manager server on the backend recognizes when an authorized users logs-in, and a pre-configured an Android OS instance (with all the work apps) is pushed to the smartphone. If an employee tries to transfer data or apps between the corporate instance and the private instance, the transfer is automatically blocked.

At the beginning of the year, BlackBerry announced its Balance software, which creates dual personas in the BlackBerry 10 OS that runs the Z10 smartphone.

In March, BlackBerry announced a dual persona technology called Secure Work Space for iOS and Android, which runs as an update to BlackBerry Enterprise Server 10. A closed beta test recently began with enterprise and government customers; the software will be generally available by June 30, BlackBerry said. Pricing has not been announced.

Like other dual persona mobile applications, VMware's new Horizon Mobile creates a separate container for corporate content and helps prevent data leakage and preserve the privacy of any personal information on the same device. IT manages only what it needs to manage, bringing security and compliance to personally owned devices.

Security for Android devices is enforced by isolating personal and corporate assets and encrypting all corporate assets that reside on the device.

Horizon Mobile leverages existing enterprise infrastructure including virtual private network, authentication solutions and full integration with standard enterprise directory services so enterprises can extend their current trusted and compliant security services to smartphones.

VMware Horizon Mobile is available immediately with perpetual licensing starting at $125 per user. The server software can be purchased through local VMware and Verizon Wireless resellers.


Best CCNA Training and CCNA Certification and more Cisco exams log in to examkingdom.com

Monday, 13 May 2013

Microsoft says Yammer sales are booming

The enterprise social networking's product revenue grew 259 percent year on year in the quarter ended in March

With the backing of its new parent company, Yammer more than tripled its revenue year on year in the quarter that ended in March.

Sales of Yammer's cloud-based enterprise social networking (ESN) software shot up 259 percent in Microsoft's third fiscal quarter, compared with the same quarter in 2012, when Yammer was still an independent company, Microsoft said on Thursday.

Microsoft isn't disclosing Yammer's revenue in dollar figures, but the growth and momentum -- Yammer added 312 new customers in the quarter -- is a validation of the US$1.2 billion it paid for Yammer last July, a Microsoft executive said in an interview.

"We're really pleased with the acquisition, with the process of the teams coming together and with the continued customer acceptance and demand," said Jared Spataro, senior director of the Microsoft Office Division.

"There are always questions after an acquisition, like, 'How is it going?' There's a worry about cultures clashing, and about products and strategies coming together," Spataro said. "When we did the acquisition, we talked a lot about how it would accelerate Yammer's momentum. So this is a great data point to demonstrate how well things are going in general."

Spataro specified that to calculate the revenue spike, Microsoft considered only sales of standalone Yammer licenses, and left out revenue coming in from Enterprise Agreement volume licensing deals involving the ESN product.

It should also be noted that after the acquisition, Microsoft eliminated Yammer's Business edition and slashed the price of the more sophisticated Enterprise edition from $15 to $3 per user per month, so in this year's quarter Microsoft generated significantly less revenue per license than Yammer did in the prior year's quarter.

Microsoft expects Yammer sales to get another boost this summer when the Yammer sales team is merged with Microsoft's global salesforce, boosting the number of reps pushing Yammer from about 100 today to thousands worldwide.

As a frame of comparison, worldwide revenue for enterprise social collaboration software grew about 25 percent in 2012 compared with 2011, according to Michael Fauscette, an IDC analyst.

Another market benchmark is Jive Software, a publicly traded ESN vendor, whose revenue grew 34 percent to almost $34 million in the quarter that closed at the end of March.

"Clearly with this announcement Microsoft is trying to put a certain amount of validation out there that says they made a good acquisition, because some people thought they had overpaid for Yammer," Fauscette said.

Looking back, it's clear to Fauscette that Microsoft picked the best ESN product available at the time, and that so far the acquisition appears to be working well for both parties.

Microsoft bought Yammer primarily to boost the ESN features in its all-purpose and ubiquitous SharePoint enterprise collaboration server, which has an on-premises version and a cloud-based version called SharePoint Online that is part of the broader cloud email and collaboration suite Office 365. The newest on-premises version is called SharePoint 2013.

Integration of Yammer and SharePoint is grinding along and will take probably two years to complete. In March, Microsoft offered an integration road map that calls for Office 365 customers to get the option this summer to replace SharePoint Online's activity-stream component with Yammer's, a modest, basic first integration point.

Also by this summer, Microsoft will deliver a Yammer application that will let users embed a Yammer group feed into a SharePoint site. This Yammer application, which will be available in the SharePoint app store, will work both with SharePoint Online and with SharePoint 2013 servers installed on a customer's premises. Microsoft will also make it possible for customers to replace the newsfeed in SharePoint 2013 servers installed on premise.

Later in the year, the integration will deepen with a single sign-on and the inclusion of Yammer in the Office 365 interface. Yammer will also gain integration with Office Web Apps, the browser-based version of the Office productivity suite, before the end of the year.

Next year, Office 365 customers can expect integration between Yammer and other Office 365 components beyond SharePoint, such as Lync and Exchange. Yammer is already being integrated with Microsoft Dynamics enterprise software.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Tuesday, 7 May 2013

Microsoft's Windows Blue to be available later this year

The update to Windows 8 will be delivered across a variety of form factors and display sizes

Microsoft's update of its Windows 8 operating system, code-named Windows Blue, will be available later this year, supporting a variety of form factors and display sizes, and providing more options for both businesses and consumers.

"The Windows Blue update is also an opportunity for us to respond to the customer feedback that we've been closely listening to since the launch of Windows 8 and Windows RT," said Tami Reller, Microsoft's chief marketing officer and chief financial officer in a post on Tuesday on the progress of Windows 8.

Microsoft shipped Windows RT for ARM-based devices and Windows 8 for devices based on Intel processors in October last year. The update to Windows 8 comes in the wake of sometimes adverse user feedback about the operating system, which is said to have failed to boost flagging PC sales.

First-quarter PC shipments, for example, totaled 76.3 million units, down 13.9% compared to the same quarter last year, in part because Windows 8 failed to boost sales, and also because of the popularity of alternative computing devices like tablets, research firm IDC said in April.

Reller did not provide details on the features of the upcoming version of Windows 8.

Microsoft has recently crossed the 100 million licenses sold mark for Windows 8, about six months after its general availability, which includes Windows licenses that ship on a new tablet or PC, as well as upgrades to Windows 8. "This is up from the 60 million license number we provided in January," Reller said.

The company has also seen the number of certified devices for Windows 8 and Windows RT grow to 2,400 and is seeing more and more touch devices in the mix, she added.

"While we realize that change takes time, we feel good about the progress since launch, including what we've been able to accomplish with the ecosystem and customer reaction to the new PCs and tablets that are available now or will soon come to market," Reller said.

The decline in the PC market in the first quarter was worse than the 7.7% drop previously forecast, and the market could be headed into further contraction, IDC said in April. Reller, however, continues to be optimistic about the PC business.

"The PC is very much alive and increasingly mobile," she said. The PC part of the market is evolving fast to include "new convertible devices and amazing new touch laptops, and all-in-ones," she added. Some of these PCs are coming into the market now, and they are more affordable than ever, Reller said. The Microsoft executive said Windows 8 was also built to address a broader market consisting of devices like tablets.

Microsoft has also seen the number of apps in its Windows Store grow six-fold since launch. Over 250 million apps were downloaded from the store in the first six months, with almost 90 percent of its app catalog downloaded every month.

The company claims to be doing well in some of its other services too. It announced Monday that over 250 million people are now using its SkyDrive online file hosting service. Microsoft now has 400 million active accounts for its Outlook.com webmail, after completing the transition of Hotmail users to the new service. The company plans to add more features to Outlook.com, which started with the integration of Skype, which is being phased in throughout the world. It now has over 700 million active Microsoft accounts using its services, Reller said.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

FAQ: What you need to know about cloud computing's hidden tax hit

KPMG LLP tax expert Reid Okimoto speaks to state tax burden of cloud computing and questions you should ask before buying

Cloud computing services, both software as a service (SaaS) and infrastructure as a service (IaaS), are subject to taxes, whether your cloud provider tells you or not when you purchase them. Reid Okimoto, senior manager in the state and local tax practice at KPMG, shares tips to help you understand the real cost of cloud computing.

Q: What questions should companies buying cloud services be asking about state and local taxes?
Reid Okimoto
Reid Okimoto, senior manager, state and local tax practice, KPMG

A: One major question is, "Is it subject to sales tax?" If sales tax isn't clearly charged by the cloud provider, the customer may still be subject to 'use tax.' IT-focused professionals and their enterprises are consuming and purchasing cloud services and they're normally dealing with sellers and vendors of cloud services, not necessarily those familiar with the "taxability of services." Questions to ask the seller of the cloud services: "Are you charging sales tax or not?" If the answer is no, the next question is, "Why not?" It could be either that the provider does not have nexus or that the service is not taxable. This answer makes a difference to the consumer.

Q: So what happens with taxation and "nexus," which means a connection or link?
A: The concept of "nexus" determines who has the obligation of collecting and remitting a sales tax. Nexus is not synonymous with taxability. If the vendor has nexus in the state and the cloud service is taxable in the state, it should collect the sales tax. If not, the consumer will be responsible for self-accruing and remitting.

Q: State taxes vary, with some at 8% or even more. You note that state policies regarding taxation of cloud services also vary. Would you give us some examples?
A: New York imposes sales tax on many cloud services. California, in the majority of cases, does not tax cloud services. By contrast, a state like Washington shifts the burden of self-accruing and remitting the use tax from the cloud service provider to the consumer. States that offer multiple points of use exemptions for multi-state users of cloud services are preferred to those that impose sales tax of 100% of the purchase price based on the billing address. Imposing sales tax on 100% of the purchase price based on a billing address makes it likely that more than 100% will be taxed or nothing will be taxed. Taxpayers are always concerned about getting "whipsawed" by two competing states' taxing policies.

Q: If you don't go into this fully understanding the tax situation with cloud services, what might come back to haunt you later?
A: A state auditor does periodic audits of companies and they will require you to prove that sales tax was charged and paid appropriately. You may need to prove this by showing them your invoices. Also, your financial statement auditors may inquire about contingent sales or use tax liabilities on the sale or purchase of cloud services. This could result in a contingent liability being placed on the balance sheet. Another reason to keep straight on the cloud-tax issue is that when companies are sold or recapitalized, they typically go through a "due diligence" process with the buyer to "scrub" companies for all liabilities, including tax liability. If there's a lot of liability, there will be a "failed process" question.

Q: What more do business professionals need to think about here?
A: Clear guidance on taxability and sourcing of cloud services creates predictability from a business investment standpoint. States that do not provide clear guidance put cloud service providers in an awkward position, stuck between a possible state tax audit or False Claims Act allegation for under-collecting and a possible class action lawsuit for over-collecting.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Saturday, 4 May 2013

Microsoft promises more Windows Embedded Compact 7 updates

Microsoft promises more Windows Embedded Compact 7 updates

Microsoft has revealed several Windows Embedded Compact 7 updates, one planned for the fourth quarter of this year and one for the second half of 2012. Next year's version will get an updated kernel, faster file system, and broader hardware support, according to an EE Times report.
A 9:30 a.m. keynote was delivered Oct. 26 at the ARM TechCon show in Santa Clara, Calif. by Microsoft's Dan Javnozon, group product manager for the Windows Embedded marketing group. At the time, we were up north in our Palo Alto batcave getting other news stories out, so we're grateful to EE Times for reporting on what transpired.

According to writer Rick Merritt, Javnozon spilled the beans regarding two pending updates to Windows Embedded Compact 7. Building on an "Windows Embedded Compact 7 Update 3" version that was released last month -- see later -- the revisions suggest that the Windows CE-based operating system won't be left forgotten in the wake of an ARM-powered Windows 8.

Microsoft's Dan Javnozon announcing Windows Embedded Compact 7 updates

Source: EE Times
Javnozon, pictured above, is said to have promised a Compact 7 update for the fourth quarter of this year, though apparently no details were provided. In addition, Merritt writes, he promised "Compact v.Next" for the second half of 2012 -- with an updated kernel, faster file system, and "broader hardware support."

Compact v.Next will also get boosted real-time capabilities, EE Times reports. But in a brief post-keynote interview, Javnozon declined to provide further specifics, the story added.

Microsoft's most recent revision to Windows Embedded Compact 7 operating system was announced on Oct. 17. "Windows Embedded Compact 7 Update 3" includes approximately 125 code defect fixes, several new tools for automating testing, and available Silverlight source code for the operating system's media player, according to the company.

Windows Embedded Compact 7 was first announced in June 2010 as a significant upgrade to the previous Windows Embedded CE 6.0 R3. New features included multicore support, an upgraded Internet Explorer web browser, Adobe Flash support, user interface (UI) development via Silverlight, and the ability to share and manage content across DLNA (digital living network alliance) devices.

The operating system runs not only on x86 processors like its big brother Windows 7, but also on other architectures such as ARM -- including the multicore Cortex-A9 -- and MIPS. (However, Microsoft notes, Hitachi's SH4 is no longer supported by this particular Windows CE variant, and ARMv5 is the earliest supported ARM architecture.)

According to an Oct. 17 blog entry by Olivier Bloch, chief software architect for Windows Embedded, Windows Embedded Compact 7 Update 3 is now freely downloadable. He wrote that the new release contains "approximately 125 code defect fixes" for the Compact 7 operating system, Platform Builder tools, and the Compact Test Kit (CTK).


The installer for Microsoft's Windows Embedded Compact 7
The CTK has two new tools, Bloch adds: The Compact Automation Tool Solution (CATS) for automating test scenarios, and The Compact Stress Tool for automating stress tests. Also now included is new Silverlight for Windows Embedded (SWE) sample code for the Compact 7 Media Player, which was previously provided only in binary format. A previous dependency on the compositor in the sample code has been removed, so Media Player performance should be improved across all hardware configurations, according to Microsoft.

Microsoft originally promoted Windows Embedded Compact 7 as "bringing the power of Windows 7 across ... specialized devices such as slates, portable media players, and others." Indeed, the operating system was shown off last year on an early version of the Asus Eee Pad EP101TC (below), a tablet that was later revamped to run Android instead.


The Asus Eee Pad EP101TC originally ran Windows Embedded Compact 7
Since then, both the progress of Android devices and the announcement of a pending, ARM-based version of Windows 8 has caused Redmond to lower its sights -- or so it would appear. Thanks to its low cost, simpler hardware requirements, modularity, and real-time characteristics, however, Windows Embedded Compact 7 will continue to find customers, or so its supporters argue.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Why you should take hacked sites’ password assurances with a grain of salt

Beware of e-mails that play down the ease of cracking your leaked passcode.

Reputation.com, a service that helps people and companies manage negative search results, has suffered a security breach that has exposed user names, e-mail and physical addresses, and in some cases, password data.

In an e-mail sent to users on Tuesday, officials with the Redwood City, California-based company said the passwords were "highly encrypted ('salted' and 'hashed')," a highly vague description that can mean different things to different people. "Although it was highly unlikely that these passwords could ever be decrypted, we immediately changed the password of every user to prevent any possible unauthorized account access," the e-mail added unconvincingly.

It's unfortunate that companies make such assurances, because they may give users a false sense of security. As Ars has been reporting for nine months, gains in cracking techniques means the average password has never been weaker, allowing attackers to decipher even long passwords with numbers, letters, and symbols in them. Even Ars' own Nate Anderson—a self-described newbie to password cracking—was able to crack more than 45 percent of a 17,000-hash list using software and dictionaries he downloaded online.

Jeremi Gosney, a password cracking expert with Stricture Consulting Group recently explained in an Ars forum post that it's highly unusual for a leaked password list to go uncracked, as suggested by the Reputation.com e-mail.

"It definitely depends on the specific leak we're talking about, but generally speaking, your average security expert/penetration tester/casual password cracker is probably only going to be able to recover at most 50-60% of passwords in any given leak," he wrote. "Seasoned password crackers will likely recover 70-75%; and truly exceptional password crackers will recover 80% or more."

Adding cryptographic salt to passwords is crucial to the safe storage of passwords because it forces password cracking programs to guess the plaintext for each individual hash, rather than guessing passwords for thousands or millions of hashes all at once. (Yes, it also thwarts rainbow-table attacks, but no one uses this method anymore.) But it's easy to overstate the benefits of salting. It in no way slows down the cracking of a single hash, so if an attacker locates the hash belonging to a particular high-value Reputation.com user, the measure does nothing to thwart the cracking of that hash. The security value of salting alone only slows down cracking of large lists by a multiple of the number of unique salts, so that value decreases with each hash that is decoded.

A far more meaningful security measure is the type of algorithm that's used to convert plaintext passwords into cryptographic hashes. If the company used SHA1, SHA3, MD5, or any number of other "fast" hashes, it's extremely likely that at least some of the leaked password data has already been cracked. If, on the other hand, the company used bcrypt, scrypt, PBKDF2 or another "slow" algorithm specifically designed to hash passwords, the chances are significantly lower. Reputation.com makes no mention of the algorithm it used, so users should presume the worst. Anyone who used their Reputation.com password to protect one or more accounts on other sites should change those passcodes immediately. Passwords should be randomly generated by a password-manager, contain a minimum length of 11 characters, and include numbers, letters, and symbols. They should also be unique to each site.

For a deeper dive into the benefits of salting and hashing, see last Saturday's story about the password breach that hit LivingSocial.com. Some of the user comments are especially illuminating.


Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Thursday, 2 May 2013

Companies explore self-detonating data as security control

Self-detonating data would put expiration dates on sensitive documents

The popular Snapchat photo-messaging app used mainly by Android and iOS mobile device owners to share images that then self-destruct after 10 seconds is the sort of security idea that businesses say can help them secure online transactions with business partners.

“It puts controls on what people see, and I can put expiration dates on sensitive documents,” says Marc McDonald, owner of Chicago-based Midland Metal Products that a few months ago started using the software-as-a-service called VIA from Intralinks Holdings that now lets the maker of store fixtures share computer-aided design files for custom manufacturing with business partners. Midland Metal Products restricts download of sensitive information and also sets a time for the files to self-destruct. McDonald says the password-controlled VIA option is simpler and has more security controls than the Dropbox option he’d previously used.

While Intralinks sometimes casually refers to the collaboration service, which is priced at $25 per user per month as a “Snapchat for the enterprise,” it’s not related to the real Snapchat, which was launched in September 2011 by Stanford students Evan Spiegel and Bobby Murphy as a way to share “impermanent photos” taken on mobile devices through their Snapchat app.
We've been getting a lot of inquires about Snapchat apps."
— Jason Novak, assistant director of digital forensics, Stroz Friedberg

After a short period of time, each Snapchat image is said to be deleted from the devices and the Snapchat servers. The still-evolving Snapchat service, which has started to receive venture-capital funding, is proving popular with teens and young adults that now send millions of Snapchat photos and videos each day. Snapchat is also starting to be noticed in business circles in connection with questions about whether unauthorized photos and images of sensitive business information are being sent via mobile devices.

“We’ve been getting a lot of inquires about Snapchat apps,” says Jason Novak, assistant director of digital forensics at Stroz Friedberg, the New York-based firm which focuses on cybercrime issues and providing digital evidence that will stand up in court, if need be.
One big question is whether Snapchat does leave any trail of evidence of use on a mobile device. Stroz Friedberg says its forensics analysis can detect a trail of use of Snapchat for the Apple iPhone, though not evidence of specifically what photos or videos were sent. It hasn’t yet completed forensics for Snapchat on an Android device.

In its digital forensics tests it did with Snapchat for the iPhone, Stroz Friedberg found Snapchat maintains what’s called the user.plist file which is not encrypted. The file is a way to identify, preserve and analyze that the user of the iPhone did send something to a recipient via Snapchat. Novak says it’s possible to clear the Snapchat plist file on the device if the user knows how.

He points out that other Snapchat-like services oriented toward mobile have sprung up -- such as Facebook’s Poke, as well as Wickr and Silent Circle which take advantage of encryption as well. These type of services are presenting digital forensics with new challenges, Novak notes. Mobile devices such as smartphones and tablets that use these type of services remains a new and evolving field beyond traditional computer-based forensics which is now more automated.

Best CCNA Training and CCNA Certification and more Cisco exams log in to examkingdom.com