Former Microsoft open-source chief joins cloud startup

Former Microsoft open-source chief Sam Ramji has joined cloud-computing startup Sonoa Systems, taking over product strategy and business development at the Santa Clara, California-based company. Last month he also took a position as interim president of the CodePlex Foundation, an open-source group formed out of his work at Microsoft. In his last job at Microsoft, Ramji was responsible for fostering more interoperability and collaboration with the open-source community as head of its Platform Strategy Group.

However, when the foundation and Ramji's role in it were unveiled, he said he was leaving Microsoft Sept. 25 to join a cloud-computing startup, though he did not specify which one. It also provides visibility, management and governance to make cloud services and the APIs (application programming interfaces) that connect to them as robust, policy-compliant and scalable as on-premise applications, according to the company's Web site. Sonoa offers technology called ServiceNet that helps companies manage their cloud-based services by setting policies for them, acting as a proxy server between service providers and the consumers of those services. In addition to ServiceNet, Sonoa also has released an analytics tool for API developers called Apigee as a free way to monitor and manage how their services are being accessed in the cloud. Sonoa's customers include MTV and Guardian Insurance. In an e-mail, a company spokesman compared the tool to Google Analytics.

Sonoa's CEO is a former BEA Systems executive, Chet Kapoor. The foundation also was formed by Microsoft to inspire other proprietary software companies to participate more in the open-source community, though eventually it is meant to be run as an independent group. Microsoft has not named anyone to take Ramji's role but said when the CodePlex Foundation was unveiled that the Platform Strategy Group will remain intact and will continue to promote collaboration with and participation in open-source projects.

Intel: Chips in brains will control computers by 2020

By the year 2020, you won't need a keyboard and mouse to control your computer, say Intel Corp. researchers. Scientists at Intel's research lab in Pittsburgh are working to find ways to read and harness human brain waves so they can be used to operate computers, television sets and cell phones. Instead, users will open documents and surf the Web using nothing more than their brain waves.

The brain waves would be harnessed with Intel-developed sensors implanted in people's brains. Researchers expect that consumers will want the freedom they will gain by using the implant. "I think human beings are remarkable adaptive," said Andrew Chien, vice president of research and director of future technologies research at Intel Labs. "If you told people 20 years ago that they would be carrying computers all the time, they would have said, 'I don't want that. The scientists say the plan is not a scene from a sci-fi movie - Big Brother won't be planting chips in your brain against your will. I don't need that.' Now you can't get them to stop [carrying devices]. There are a lot of things that have to be done first but I think [implanting chips into human brains] is well within the scope of possibility." Intel research scientist Dean Pomerleau told Computerworld that users will soon tire of depending on a computer interface, and having to fish a device out of their pocket or bag to access it. Instead, they'll simply manipulate their various devices with their brains. "We're trying to prove you can do interesting things with brain waves," said Pomerleau. "Eventually people may be willing to be more committed ... to brain implants.

He also predicted that users will tire of having to manipulate an interface with their fingers. Imagine being able to surf the Web with the power of your thoughts." To get to that point Pomerleau and his research teammates from Intel, Carnegie Mellon University and the University of Pittsburgh, are currently working on decoding human brain activity. People tend to show the same brain patterns for similar thoughts, he added. Pomerleau said the team has used Functional Magnetic Resonance Imaging (FMRI) machines to determine that blood flow changes in specific areas of the brain based on what word or image someone is thinking of. For instance, if two people think of the image of a bear or hear the word bear or even hear a bear growl, a neuroimage would show similar brain activity. Pomerleau said researchers are close to gaining the ability to build brain sensing technology into a head set that culd be used to manipulate a computer.

Basically, there are standard patterns that show up in the brain for different words or images. The next step is development of a tiny, far less cumbersome sensor that could be implanted inside the brain. Almost two years ago, scientists in the U.S. and Japan announced that a monkey's brain was used to to control a humanoid robot. Such brain research isn't limited to Intel and its university partners. Miguel Nicolelis, a professor of neurobiology at Duke University and lead researcher on the project, said that researchers were hoping its work would help paralyzed people walk again. Charles Higgins, an associate professor at the university, predicted that in 10 to 15 years people will be using "hybrid" computers running a combination of technology and living organic tissue.

And a month before that, a scientist at the University of Arizona reported that he had successfully built a robot that is guided by the brain and eyes of a moth. Today, Intel's Pomerleau said various research facilities are developing technologies to sense activity from inside the skull. "If we can get to the point where we can accurately detect specific words, you could mentally type," he added. "You could compose characters or words by thinking about letters flashing on the screen or typing whole words rather than their individual characters." Pomerleau also noted that the more scientists figure out about the brain, it will help them design better microprocessors. He said, "If we can see how the brain does it, then we could build smarter computers."

Challenges await head of new SAP user group

The Americas' SAP Users' Group announced its new CEO on Tuesday, nearly one year after parting ways with its previous chief. Chambers assumes the role previously held by Steve Strout, who was ousted by ASUG's board in November 2008 for undisclosed reasons. Interim CEO Bridgette Chambers will take leadership of ASUG, which represents about 70,000 individuals at 2,000 member companies.

Like Strout before her, a key issue before Chambers is SAP's controversial decision to move all customers to a fuller-featured but pricier Enterprise Support service. Following months of debate, SAP and the SAP User Group Executive Network (SUGEN), an organization made up of representatives from SAP user groups around the world, agreed to develop a set of KPIs (key performance indicators) meant to prove the value of Enterprise Support. While some European user groups were especially vocal about SAP's move, ASUG officials adopted a more moderate tone in public remarks. SAP has agreed to hold off on its incremental price increase schedule for Enterprise Support "until the targeted improvements measured by the SUGEN KPI Index are met." There will be an announcement regarding the KPIs later this year, said SAP spokesman Saswato Das. However, she added, "quite frankly, SAP can drop in every value-add they can, but at the end of the day the proof is in the KPIs. This adds value or it does not.

Some customers are more accepting than others of SAP's Enterprise Support decision, given that the company had held maintenance rates steady for many years, according to Chambers. If it does not, they need to understand the customer base is not open to this. Despite these ties, ASUG has retained its independence and objectivity, Chambers said. "I believe that is the clear differentiator for ASUG," she said. "Yes, we have close relationships with SAP. Yes, there is sharing of expenses for events ... [But] I don't really think you've got another organization that possesses the level of objectivity we do." Not all ASUG members are convinced, according to one observer. "The underlying concern that many ASUG members have expressed to us in the past has been that board members' organizations may have special relationships with SAP that could be jeopardized if they were to privately or publicly confront SAP on issues," said Ray Wang, a partner with the analyst firm Altimeter Group. "It would help usher in an era of transparency if members understood what those relationships are." Chambers declined to address the issues raised by Wang, saying it is not her position to speak for ASUG's board members. "I will say that I am pleased and proud to work for a board that is so interested in all the issues that impact the SAP ecosystem," she said. "I have watched board members work tirelessly to ensure that the mission of ASUG is supported." To that end, Chambers has a number of organizational goals and challenges on her plate, including plans to refocus ASUG around "education, influence and networking," she said. If it does, both SAP and customers win. ... We will help our customers make sure they get an answer." Even as it lobbies for members' interests, ASUG has had an intimate relationship with SAP, going as far as co-locating its annual user conference with the vendor's Sapphire show. Chambers has also been conducting a series of "town hall" meetings in recent weeks to gather feedback from ASUG members. You'll be able to verify the value is approximately 'X.' Right now, the answer [to that question] is softer."

In addition, by the end of 2010, ASUG members should be able to better determine how much return they've received on their investment in a membership, Chambers said. "What I will be able to do is make it measurable.

SMBs unprepared for disasters, Symantec finds

Small and midsize businesses are confident in their disaster recovery capabilities, but their actual performance preventing outages shows they are "remarkably unprepared," according to survey results released Monday by Symantec. But that confidence is unwarranted. Four out of five SMBs are satisfied with their disaste-recovery plans, and two-thirds believe their customers would be willing to "wait patiently until our systems were back in place" in the event of an outage, Symantec found.

Three out of four SMBs report that they are based in a region susceptible to natural disasters. The report is a follow-up to Symantec's annual Disaster Recovery Research Report released last summer,  which found that the average cost of executing and implementing a recovery plan amounted to $287,600 for each downtime incident. The average respondent suffered three outages in the past 12 months, either from natural disasters, power outages, or virus and hacker attacks. "With this kind of exposure, and with the confidence SMBs display about their disaster preparedness, one would think SMBs have solid disaster-recovery plans in place," Symantec writes in the SMB Disaster Preparedness report. "However this is not universally soothe case - almost half (47 percent) report they do not yet have a plan to deal with such disruptions." Survey respondents included 1,657 companies worldwide, including both SMBs (companies with 10 to 499 employees) and their customers. This week's SMB study found that in some areas, respondents showed "an alarming lack of readiness," according to Symantec. "First, the average SMB backs up only 60 percent of its company and customer data," Symantec writes. "Second, they do so infrequently. This inattention to data backup is echoed by the fact that more than half (55 percent) of the SMBs feel they would lose 40 percent of their company data if their computing systems were wiped out in a fire." This lack of preparedness puts SMBs at risk of losing customers.

Only one in five (23 percent) back up on a daily basis and 40 percent back up monthly or less. Two out of five SMB customers surveyed by Symantec have switched vendors because they decided their vendor's technology was unreliable. Forty-two percent of outages reported by SMB customers lasted eight hours or more, and 26% of customers reported losing data because of a vendor's outage. More than a quarter of customers had suffered outages, many of which were significant. Customers said the estimated cost of outages averaged $15,000 per day.

First SMBs should determine what critical information should be secured and protected, giving priority to customer, financial and business information, and trade secrets. Symantec offered several recommendations to SMBs looking to bolster their disaster-recovery preparedness. SMBs should also automate the backup process to minimize human error, and test systems annually to ensure that data can be recovered and downtime minimized during a disaster.

Personal Finance: Manage Your Money Better Online

Let's be honest. When times are good, we probably spend too much. Most of us could do a better job handling our money. When times are bad, too many of us stick our heads in the sand.

The Web has a wealth, indeed a surfeit, of tools and information to help you manage your personal finances. Both, of course, are bad ideas. To get an idea of just how much, simply take a look at Google's personal finance directory. So I've culled the list to find Web sites and tools that you'll find helpful and I find trustworthy. It's overwhelming.

This is by no means "a best of the Web" list. Swiss Army Knives of Personal FinanceKiplinger.com is a very deep site, ranging from short, newsy pieces like "A new ban on overdraft fees" to extensively reported features like this month's "Making the most of your benefits." The site tries hard to be helpful; for example a recent piece called "My Wallet was Stolen" gives bullet points about what to do right away and ends with the phone numbers of three major credit reporting agencies. It's too difficult to make that call, and I've avoided sites that have no free information. The Web site is free, but the eighty-year-old company offers a variety of newsletters and magazines at various prices. SmartMoney also has a well-deserved reputation for excellence and is notable for its wide-ranging information.

One big benefit as outlined on the site: "Kiplinger answers the queries of its readers as a regular feature of their subscriptions, filling requests for additional information on any subject its publications cover, by phone, mail or email. Clicking on "personal finance," for example, brings up sections devoted to 13 different topics, including bank notes, debt, elder care, marriage and divorce. College and Retirement Planning With the price of tuition at even public universities moving into the five-figure range, it's never been more important to develop a plan to afford a college education. SmartMoney also offers a wealth of investment tools, including real-time quotes, analysis and stock screening, but those features are behind a pay wall. Even if the heir apparent is very close to graduating high school there are steps you can take to mitigate the financial pain.

Indeed, the site has an entire section devoted to financial planning for college filled with actionable tips, newsy items and generally helpful stuff. SmartMoney, for example, has an informative story about early decision students and financial aid. Not to be outdone, Kiplinger has very meaty college-focused special report that includes pieces on comparing student loan packages and how best to use 529 (college savings) plans. By entering your personal information, you'll get back an estimate of your (teensy) monthly benefits at various retirement ages. It may be somewhat early for you to file for Social Security, but if nothing else, this government site provides a great reality check. The site has a good deal of related information, including application forms.

Best Rates on CDs Finding a financial advisor is not easy and is a decision that has real consequences. There is a also a wealth of information for people approaching retirement on the Web site of the AARP. One feature I really liked that has use for a consumer of any age was called "The All Cash Challenge." As you'd expect it underlines something we all know, but probably don't put to use often enough: People who pay with cash spend less than those who pay with credit cards, because pulling those greenbacks out of your wallet hurts. One place to start: The National Association of Personal Financial Advisors. NAPFA insists that its members be " fee only," which means the financial advisor is compensated "solely by the client with neither the advisor nor any related party receiving compensation that is contingent on the purchase or sale of a financial product." CDs don't pay much these days, but they are a secure place to park your money until better opportunities arise. Its Web site lets you search for advisors by area and by specialty.

If that works for you, bankrate.com is a good place to shop. A similar tool on the site allows you to check fixed and adjustable mortgage rates for different durations and localities. Its simple search tool includes clickable links, so if you see a deal you like, it's to take the next step. Any number of online sites help with basic financial chores, including budgets and expense tracking. After all, you'll be entrusting credit card numbers, bank account and maybe investment account information to a company you don't know much about. But I have to say that security is a real concern.

That's not to cast aspersions on anyone; I'm just careful, and I hope you are as well. Mint.com, which has garnered some good reviews, is now owned by Intuit, so the combined site is worth a look. Certainly Quicken Online, owned by Intuit, is long established, and its Web site is now free. Here's a final tip that I figured out after wasting too much money. When I had a misunderstanding with a credit card company, my account was temporarily suspended.

My online life includes many services and publications that renew automatically. Suddenly a number of those automatic renewals bounced and I was prompted to update. My credit account was quickly restored, and as a result of that little mishap I saved hundreds of dollars. (Thanks to Kathleen Pender, the long-time personal finance columnist for the San Francisco Chronicle, for her helpful suggestions.) San Francisco journalist Bill Snyder writes frequently about business and technology. I realized that I wasn't using some of those services and cancelled. He welcomes your comments and suggestions.

Follow everything from CIO.com on Twitter @CIOonline. Reach him at bill.snyder@sbcglobal.net.

Oracle: 11g Xpress Edition 'a year or two' away

It may be "a year or two" before Oracle releases a no-cost Express Edition (XE) of its 11g database, according to Andrew Mendelsohn, the company's senior vice president of database server technologies. Oracle took the same approach with the current 10g Express Edition, according to Mendelsohn, who oversees database development at the vendor. That's because Oracle is going to wait until after the first patch set ships for 11g Release 2, which was launched in July, Mendelsohn said in a brief interview following a speech at Oracle's OpenWorld conference in San Francisco on Monday.

Developers and ISVs (independent software vendors) prize XE because it includes many core features, and allows them to prototype, deploy and distribute applications without any licensing costs. Users with greater needs would need to upgrade to a paid database version such as Standard Edition. However, XE is limited to 4GB of user data, 1GB of memory and a single CPU, and is available on only 32-bit Windows or Linux systems. Some Oracle database administrators believe there is a deliberate reason for the protracted rollout. "It's an approach that ensures that adoption is nil," said Paul Vallée, founder of the Pythian Group, a database management outsourcing company in Ontario, Canada. "I don't think they're interested in adoption. ... I think they have to have it out there just for maybe a check box, just to maybe say they have a free edition." IBM and Microsoft also offer certain versions of databases at no cost. Oracle is attempting to buy Sun Microsystems for US$7.4 billion, but the deal is on hold while European officials conduct an antitrust review.

Oracle simply isn't "gunning for market share in the free database segment," Vallée added. "If they were, the strategy would be to release this exactly the way it is and then sell support and commit to patch sets for it." That is essentially the model Sun Microsystems has used for the open-source MySQL database. Instead, Oracle wants lower-end customers to use a paid version of the database, such as Standard Edition One, said Pythian Group CTO Alexander Gorbachev. It's unclear how the arrival of MySQL will affect XE, or any other aspect of Oracle's database strategy, Vallée said. A Standard Edition One processor license costs $5,800, according to Oracle's latest price list. Oracle plans to increase investment in MySQL, CEO Larry Ellison said during a keynote Sunday.

Gmail, Yahoo Mail join Hotmail; passwords exposed

Google's Gmail and Yahoo's Mail were also targeted by a large-scale phishing attack, perhaps the same one that harvested at least 10,000 passwords from Microsoft's Windows Live Hotmail, according to a report by the BBC. Microsoft , for its part, said late yesterday that it had blocked all hijacked Hotmail accounts, and offered tools to help users who had lost control of their e-mail. The BBC also said it has seen a list of some 20,000 hijacked e-mail accounts; the list included accounts from Gmail, Yahoo Mail, AOL, Comcast and EarthLink. Gmail was the target of what Google called a large-scale phishing campaign, the company told the BBC . "We recently became aware of an industry-wide phishing scheme through which hackers gained user credentials for Web-based mail accounts including Gmail accounts," a Google spokesperson told the news network. The latter two are major U.S. Internet service providers. "As soon as we learned of the attack, we forced password resets on the affected accounts," the Google spokesperson also told the BBC. "We will continue to force password resets on additional accounts when we become aware of them." Neither Google's or Yahoo's U.S. representatives responded to e-mails from Computerworld seeking confirmation that their Gmail and Yahoo Mail services were targeted by phishers, or answers to questions about how many accounts had been compromised and what the firms are doing to help users.

Late Monday, Microsoft said it was blocking access to all the accounts whose details had been posted on the Web last week. "We are taking measures to block access to all of the accounts that were exposed and have resources in place to help those users reclaim their accounts," the company said on its Windows Live blog . Microsoft posted an online form where users who have been locked out of their accounts can verify their identity and reclaim control, and also pointed users to a support page from October 2008 that spells out steps users can take if they think their accounts have been hijacked. Neowin.net, the site that first reported the Hotmail account hijacking early Monday, today added that it had seen the same list of compromised accounts as the BBC. "Neowin can today reveal that more lists are circulating with genuine account information and that over 20,000 accounts have now been compromised," said the Windows enthusiast site . "[The] new list contains e-mail accounts for Gmail, Yahoo, Comcast, EarthLink and other third-party popular Web mail services." Microsoft has acknowledged that log-on credentials for "several thousand" Hotmail accounts had been obtained by criminals, probably through a phishing attack that had duped users into divulging their usernames and passwords. After a slump earlier this year, phishing attacks are on the upswing, according to the Anti-Phishing Working Group (APWG). Its most recent data - for the first half of 2009 ( download PDF ) - noted that the number of unique phishing-oriented Web sites had surged to nearly 50,000 in June, the largest number since April 2007 and the second-highest total since the industry association started keeping records. Yesterday, Dave Jevans, the chairman of APWG, called the Hotmail phishing attack one of the largest ever, but cautioned that the usernames and passwords may have been harvested over several months, and not by a single, defined attack.

McCain Moves to Block FCC Net Neutrality

The FCC voted unanimously yesterday to move forward with the debate in an effort to formalize net neutrality guidelines. In the wake of FCC chairman Julius Genachowski's initial announcement of his intent to pursue formal net neutrality rules, a group of GOP lawmakers already initiated a similar attempt. Senator John McCain followed up by introducing a bill that would prohibit the FCC from governing communications. However, that amendment was retracted almost as quickly as it was filed.

Basically, those in power or those who pay more will have better access. McCain's bill, the Internet Freedom Act, seeks to do the opposite of what its name implies by ensuring that broadband and wireless providers can discriminate and throttle certain traffic while giving preferential treatment to other traffic. Apparently we have different definitions of 'freedom'. According to the text of the McCain bill, the FCC "shall not propose, promulgate, or issue any regulations regarding the Internet or IP-enabled services." Isn't that what the FCC does? Oddly, the bill also contains text stating that any regulations in effect on the day before the Internet Freedom Act is officially enacted are grandfathered in and exempt from the provisions of the Internet Freedom Act. Isn't that sort of like introducing a bill to prohibit the Treasury from printing money, or a bill to prohibit the IRS from collecting taxes? The implication seems to be that if the FCC can formalize net neutrality rules before McCain can get the Internet Freedom Act signed into law, the net neutrality rules would still apply.

However, Comcast tried to throttle peer-to-peer networking traffic and only changed policy after the threat of FCC net neutrality rules. Net neutrality opponents claim that the free market can police itself and that any net neutrality restrictions will stifle innovation and competition. AT&T sought to block customers from using VoIP services from its wireless network, but changed policy out of fear of the net neutrality rules. What the FCC voted on yesterday is simply to start the debate. The trend seems to be that these providers only do the 'right thing' when the net neutrality gun is pointing at their head. Its an open discussion, so what are net neutrality opponents afraid of?

If there are valid issues that need to be resolved, then go ahead and bring them to the table. They have 120 days to gather information and collect data and present their case. Don't initiate legislation that seeks to pretend the table doesn't exist. While Obama was attached surgically to his CrackBerry and his staff leveraged social media from their Macbooks, McCain admitted having little or no knowledge or interest in modern technologies like email or the Internet. During the Presidential election campaign last year the differences between the two candidates was stark.

It seems suspicious that the Internet is suddenly a major concern for him. Tony Bradley is an information security and unified communications expert with more than a decade of enterprise IT experience. Maybe he just missed seeing his name in the paper. He tweets as @PCSecurityNews and provides tips, advice and reviews on information security and unified communications technologies on his site at tonybradley.com.

GAO: Los Alamos National Lab's cybersecurity lacking

Cybersecurity efforts to protect a leading U.S. nuclear laboratory's classified computer network remain lacking even after a series of security lapses, according to a new report from the U.S. Government Accountability Office. The lab has vulnerabilities in several "critical" areas, including identifying and authenticating users, authorizing user access, encrypting classified information and maintaining secure software configurations, the GAO report said. "A key reason for the information security weaknesses GAO identified was that the laboratory had not fully implemented an information security program to ensure that controls were effectively established and maintained," the report said. The Los Alamos National Laboratory, which has suffered multiple security breaches in recent years, continues to have "significant weaknesses ... in protecting the confidentiality, integrity, and availability of information stored on and transmitted over its classified computer network," the GAO said in a report released Friday. The lab has not conducted comprehensive risk assessments to ensure against unauthorized use, has not marked the classification level of information stored on its classified network, and has inadequate training for users with security responsibilities, the GAO report said.

Later reports said as many as 67 computers were missing from the lab. In January, there were reports of the theft of three computers from a lab employee's home in Santa Fe, New Mexico. In July 2007, the U.S. Department of Energy moved to fine the lab for an October 2006 breach that exposed classified data. Also in mid-2007, U.S. lawmakers criticized the lab after reports that several officials there had used unprotected e-mail networks to share highly classified information. A contract worker illegally downloaded and removed hundreds of pages of data from the lab using USB thumb drives.

There were other security problems at the lab, including instances in 2003 and 2004 when the lab could not account for classified removable electronic media, such as compact discs and removable hard drives. The DOE's National Nuclear Security Administration (NNSA), while it said it generally agreed with the report, said the lab has made progress in its cybersecurity efforts. A lab spokesman did not immediately return an e-mail seeking comment on the GAO report. Many of the shortcomings have been addressed, said Michael Kane, associate administrator for the NNSA, in a letter to the GAO. In response to a DOE compliance order issued in 2007, "a number of key technical issues and policy implementation concerns have been or are currently being addressed," Kane said. The lab is jointly operated by several groups, including NNSA and the University of California.

The DOE oversees the lab, a multidisciplinary research institution working on strategic science on behalf of U.S. national security.

US relationship with ICANN may not end

A longtime agreement in which the U.S. Department of Commerce has oversight of the Internet Corporation for Assigned Names and Numbers (ICANN) is due to expire Wednesday, but that may not be the end of the relationship. This new type of agreement would allow ICANN to become more independent, while addressing concerns from several other countries that the U.S. has too much control over ICANN, said Michael Palage, a former ICANN board member. While ICANN isn't talking, some observers expect a new type of agreement to be announced as soon as Wednesday, with the U.S. government sharing oversight of the nonprofit organization that controls the Internet's domain name system with other countries. The new agreement would create several oversight boards, with international representation, Palage said.

What it's also doing is ... it's putting in some accountability mechanisms." Palage hasn't heard all the details about the new agreement, including how people will be appointed to the new oversight panels. The Economist reported last week that a new agreement, called an affirmation of commitments, will replace the existing pact between the U.S. government and ICANN. The Department of Commerce and ICANN have operated under a series of agreements laying out expectations for the nonprofit since November 1998. The new agreement "will tell them what it should do, but it can't legally bind them," much like past agreements, said Palage, now a senior fellow at the Progress and Freedom Foundation, a conservative think tank. "It gives the appearance in the global community that the U.S. government has recognized that ICANN has done what is was supposed to do. He's also concerned about whether private entities will have the same representation as governments. Many critics of ICANN have complained in recent years that the organization has moved forward with plans to expand services without widespread agreement. While not perfect, the new agreement being talked about would be an improvement over the existing agreement, he said. "Now while the devil will be in the detail, the only concern I have is that the private sector be on equal footing with the public sector in being able to hold ICANN accountable," he said. "If ICANN is to remain a public-private partnership that is founded on the principles of openness, transparency, inclusiveness, accountability and bottom-up coordination, then both the private and public sectors should have equal confidence in the accountability mechanism available to them." Under the latest agreement between the Department of Commerce and ICANN, the nonprofit reaffirmed its commitment to maintaining the security and stability of the domain name system, or DNS. ICANN also promised to stick to the principles of competition, bottom-up coordination and representation.

In particular, ICANN's board in June 2008 voted to allow an unlimited number of new generic top-level domains, such as .food or .basketball, but trademark owners have complained that new gTLDs would force them to register many new Web sites to protect their brands. Asked this week about what happens after the current agreement expires, an ICANN spokeswoman said the Department of Commerce has asked ICANN officials not to comment until Wednesday. Last week, several members of a U.S. Congress subcommittee urged ICANN to back off the gTLD plan until concerns could be resolved. A representative of Viviane Reding, the European commissioner in charge of the information society and the telecom industry, also declined to comment until "the situation in the U.S. has been officially confirmed." Reding has called for more international oversight of ICANN. But Steve DelBianco, executive director of NetChoice, an e-commerce trade group, said he expects a "new formal review process looking at security, consumer trust, and the interests of global Internet users." DelBianco expects that government and private stakeholders will be represented in the new review process, he said. "Prodded by public comments and encouragement from Congress, I'd expect to see a new arrangement that delivers what the global Internet community has wanted: an independent ICANN that preserves private-sector leadership with increased accountability to its core mission," he said. "The tricky part is how to give governments a well-defined role while preserving ICANN's private-sector orientation." An important part of the oversight going forward will likely be on cybersecurity, added DelBianco, a critic of ICANN's gTLD plan. "I'd expect to see explicit accountability for ICANN to make sure the DNS stays up 24-7 and around the world, even as we see increased cyber attacks and a significant expansion of top-level domains," he said. Heather Greenfield, a spokeswoman for the Computer and Communications Industry Association (CCIA), said the trade group expects the U.S. government to stay involved in ICANN. CCIA has also heard that oversight panels, involving the international community, will provide ICANN oversight going forward, she said. "We expect ICANN will retain some type of long-term relationship with the United States, while expanding the involvement of other countries," she added. "Ahead of this agreement ending, ICANN has been making a real effort to respond to past criticism about not being transparent enough."

Steganography meets VoIP in hacker world

Researchers and hackers are developing tools to execute a new data-leak threat: sneaking proprietary information out of networks by hiding it within VoIP traffic. (A brief history of steganography) Techniques that fall under the category of VoIP steganography have been discussed in academic circles for a few years, but now more chatter is coming from the hacker community about creating easy-to-use tools, says Chet Hosmer, co-founder and Chief Scientist at WetStone Technologies, which researches cybercrime technology and trains security professionals investigating cybercrimes. "There are no mass-market programs yet, but it's on our radar, and we are concerned about it given the ubiquitous nature of VoIP," he says. Steganography in general is hiding messages so no one even suspects they are there, and when done digitally, it calls for hiding messages within apparently legitimate traffic. VoIP steganography conceals secret messages within VoIP streams without severely degrading the quality of calls. For example, secret data can be transferred within .jpg files by using the least significant bits to carry it.

There are more than 1,000 steganographic programs available for download online that can place secret data within image, sound and text files, Hosmer says, and then extract it. Because only the least significant bits are used, the hidden messages have little impact on the appearance of the images the files contain. There are none for VoIP steganography yet, but in the labs, researchers have come up with three basic ways to carry it out. The second is hiding data inside each voice payload packet but not so much that it degrades the quality of the sound. The first calls for using unused bits within UDP or RTP protocols – both used for VoIP - for carrying the secret message. The third method calls for inserting extra and deliberately malformed packets within the VoIP flow.

A variation calls for dropping in packets that are so out of sequence that the receiving device drops them. They will be dropped by the receiving phone, but can be picked up by other devices on the network that have access to the entire VoIP stream. These techniques require compromised devices or conspirators on both ends of calls or a man-in-the-middle to inject extra packets. "It's much more difficult to do and much more difficult to detect," than hiding data within other files, Hosmer says. For example, x86 executables can carry secret messages, according to Christian Collberg, an associate professor of computer science at the University of Arizona and co-author of the book Surreptitious Software. The medium used to carry secret messages is called the carrier, and just about anything can be a carrier. By manipulating the compiler, it can be made to choose one addition operation over another, and that choice can represent a bit in the secret message, Collberg says. "There are lots of choices a compiler makes, and whenever you have a choice, that could represent a bit of information," he says.

One of the newest methods takes advantage of TCP retransmission – known as retransmission steganograpny (RSTEG) - in which sending machines resend packets for which they fail to receive acknowledgements. Even something as broadly used as TCP/IP can be host to steganographic messages. The sending and receiving machines must both be in on the steganography, according to a paper written by a group of Polish researchers headed up by Wojciech Mazurczynk at the Warsaw University of Technology. The resent packet is actually different from the initial packet and contains a steganographic message as the payload. At some point during the transmission of a file, the receiving machine fails to send an acknowledgement for a packet and it is resent.

The receiving machine can distinguish such resent packets and opens up the message, the researchers say. In general, defending against steganography is tough to do because traditional security devices such as firewalls and application firewalls don't detect this type of illicit transfer; a file containing a secret message looks just like a legitimate file. In his blog Crypto-Gram Newsletter, security expert Bruce Schneier dismisses the threat from RSTEG. "I don't think these sorts of things have any large-scale applications," he says, "but they are clever." Mazurczynk and his colleagues have spent a lot of time figuring out new carriers for secret messages, publishing research on embedding them in VoIP and wireless LAN traffic. The best way to combat suspected use of steganography to leak corporate data is to look for the telltale signs - known steganography programs on company computers, says Hosmer. When the steganography program is known, it can be applied to the carrier to reveal the secret message.

On systems where it is found, forensic analysis may reveal files that contained messages and an indication of what data might have been leaked. That message may be in code and have to be decrypted, he says. They can confront the person and take steps to prevent further leaks, Collberg says. In many cases, just knowing that steganography is going on and who is responsible is enough for a business. But businesses can take more active steps such as destroying the secret messages by altering the carrier file. Free programs such as Stirmark for scrambling files enough to destroy steganographic messages are available online.

For instance, if the carrier is an image file, setting all the least significant bits to zero would destroy any messages contained there without significantly changing the appearance of the image, he says. Keith Bertolino, founder of digital forensics start-up E.R. Forensics, based in West Nyack, N.Y., has developed double stegging – inserting stenographic messages within files with the intent of disrupting other stenographic messages that might also be in the files. According to Hosmer, a look at evidence in closed cases of electronic crime found that in 3% of those cases, criminals had steganographic programs installed on their computers. "The fact that these criminals were even aware [of steganography] was a startling surprise to law enforcement agencies," he says. He is waiting to find out if he gets a Small Business Innovation and research (SBIR) grant from the government to pursue turning his steganography jamming technology into a commercial product. Interest in steganography is growing, according to Wetstone Technology's monitoring of six popular steganography applications. That's not a dramatic increase given that the use of Internet-connected computes has gone up in the meantime, but it is still noteworthy, he says.

In 2008, the six combined logged 30,000 downloads per month, up from 8,000 to 10,000 per month about three years ago, Hosmer says. Steganography is not always bad. The watermark is a secret message embedded, for instance, in an image file so if the image is use online, a Web crawler can find it. Technically, steganography is just the same as digital watermarking, but with different intent, Collberg says. Then the creator of the image can check whether the site displaying the image has paid for it or is violating copyright, he says.

Exchange 2010 hits RTM

Microsoft Thursday concluded development on Exchange 2010 and said the new mail server would ship on Nov. 9 at the company's TechEd Conference in Berlin, Germany. In addition, the server is being touted as a hybrid - equally at home as the foundation for a hosted e-mail service or a corporate messaging infrastructure. Exchange alternatives Microsoft Exchange 2010 holds challenges, rewards for IT executives Exchange 2010, which is a 64-bit only server, includes new storage and deployment options, enhanced in-box management capabilities, built-in e-mail archiving, new database clustering, additional hardware options, and a revamped Outlook Web Access client.

The hosted version of Exchange 2010, however, is not expected to ship until May or June 2010. Microsoft already hosts more than 5 million users on Exchange 2010 as part of its Live@Edu program. The company said that the ability to use Exchange as a hosting platform is now built into the product. And end-users are already planning corporate rollouts, including Ford Motor Co. with plans to deploy 100,000 seats.  "Our senior leadership team has signed off on the final code, and it has been sent to our early adopters for one final look before its public release," read a blog post signed by "The Exchange Team". Microsoft has said previously that it has specially architected Exchange 2010 for high-availability and cross-domain integration using techniques such as pairing the server with Windows Server 2008 clustering technology and directory federation features. Lee Dumas, the director of architecture for Azaleos, a provider of remote management services for Exchange and SharePoint, says 2010 has challenges and rewards. "I'm not slamming Exchange, but to achieve the level of [service-level agreements], and dealing with large amounts of data, multiple copies of databases, server roles, and load balancing makes complexity inherent in getting the whole system in place," he says. Network World Lab Alliance member Joel Snyder said in his Exchange 2010 review that corporate users should carefully assess the implications of the new server. "The combination of clustering, replication and low-cost disk support means that reliability and scalability can be based on replicating small, inexpensive servers both within a data center and between data centers.

The rewards, however, will follow for those that heed due diligence, he says. E-mail managers thinking of deploying Exchange 2010 should step back and evaluate closely these new grid-style architectural approaches - and be sure that your Exchange team has adequate time to re-think and re-evaluate commonly held beliefs on how to build large Exchange networks." Exchange 2010 is the first in a wave of new Office products set to ship this year and next. Office 2010, SharePoint Server 2010, Office Communications Manager 2010, Visio 2010 and Project 2010 are slated to ship in the first half of 2010. Follow John on Twitter.

Detailing contingency planning

On Oct. 27, 2009, the National Institute of Standards and Technology (NIST) Information Technology Laboratory (ITL) Computer Security Division (CSD) published Special Publication (SP) 800-34 Revision (Rev) 1, "DRAFT Contingency Planning Guide for Federal Information Systems" and requested comments from readers by Jan. 6, 2010. The official announcement described the SP as follows: SP 800-34 Revision 1 is intended to help organizations by providing instructions, recommendations, and considerations for federal information system contingency planning. The guide defines a seven-step contingency planning process that an organization may apply to develop and maintain a viable contingency planning program for their information systems. Contingency planning refers to interim measures to recover information system services after a disruption. The guide also presents three sample formats for developing an information system contingency plan based on low, moderate, or high impact level, as defined by Federal Information Processing Standard (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems.

Authors Marianne Swanson, Pauline Bowen, Amy Wohl Phillips, Dean Gallup, and David Lynes include two of the six authors of the June 2002 original version of SP 800-34 (Swanson, Wohl, Lucinda Pope, Tim Grance, Joan Hash and Ray Thomas) and have, as usual for NIST ITL CSD, done a superb job of preparing a framework that lays out a sound basis for business continuity planning (BCP). The 150-page SP begins with an introduction presenting the purpose, scope and audience for 800-34 Rev 1. Page 13 of the PDF file describes the purpose as providing "guidelines to individuals responsible for preparing and maintaining information system contingency plans (ISCP). The document discusses essential contingency plan elements and processes, highlights specific considerations and concerns associated with contingency planning for various types of information system platforms, and provides examples to assist readers in developing their own ISCPs." This document explicitly excludes discussion of disaster recovery. Despite the inclusion of "for Federal Information Systems" in the title, SP 800-34 Rev 1 has a great deal of value for all information assurance and business continuity specialists. The scope is defined as "recommended guidelines for federal organizations"(p 14) and the audience is "managers within federal organizations and those individuals responsible for information systems or security at system and operational levels. Indeed, the authors write, "The concepts presented in this document are specific to government systems, but may be used by private and commercial organizations, including contractor systems." They then list a wide range of specific job titles of people likely to find the document useful, including IT managers, CIOs, systems engineers, and system architects. It is also written to assist emergency management personnel who coordinate facility-level contingencies with supporting information system contingency planning activities."(p 15) However, references to Federal Information Processing Standards (FIPS) in no way prevents the guidelines from serving organizations outside the U.S. federal government. The authors describe the structure of the document clearly as follows (p16): • Section 2, Background, provides background information about contingency planning, including the purpose of various security and emergency management-related plans, their relationships to ISCPs, and how the plans are integrated into an organization's overall resilience strategy by implementing the six steps of the Risk Management Framework (RMF)…. • Section 3, Information System Contingency Planning Process, details the fundamental planning principles necessary for developing an effective contingency capability.

This section presents contingency planning guidelines for all elements of the planning cycle, including business impact analysis, alternate site selection, and recovery strategies. The principles outlined in this section are applicable to all information systems. The section also discusses the development of contingency plan teams and the roles and responsibilities commonly assigned to personnel during plan activation. • Section 4, Information System Contingency Plan Development, breaks down the activities necessary to document the contingency strategy and develop the ISCP. Maintaining, testing, training, and exercising the contingency plan are also discussed in this section. • Section 5, Technical Contingency Planning Considerations, describes contingency planning concerns specific to the information systems listed in Section 1.3, Scope. The nine appendices provide practical templates and checklists of great utility in BCP. There is so much valuable information here that is offered in a structured, clear presentation that every IA professional concerned with BCP should read – and, I hope, comment on – this draft publication. This section helps contingency planners identify, select, and implement the appropriate technical contingency measures for their given systems.

Verizon updates Droid software; Users hope it fixes echo problem

An over-the-air software update to the Droid smartphone started yesterday, but it wasn't clear whether the 14 enhancements address a voice echo problem that hundreds of users complained about in online forums. The enhancements come from Verizon Wireless, Motorola and Google, which is behind the Android operating system that runs on the Motorola Droid. The much-anticipated update went to a "small percentage of handsets" yesterday and the update, identified as ESD56, will be phased in over the next week or so, a Verizon Wireless spokeswoman confirmed early today via e-mail. An update to the Droid Eris smartphone from HTC is "planned but a date has not yet been confirmed," the spokeswoman added.

However, it remains unclear whether the list of official fixes offers any relief to hundreds of customers who have complained of a voice echo heard by recipients of calls made from Droid phones. The Motorola Droid update is based on Google's release of a software developer kit for Android 2.0.2 on Dec. 6. The most noticeable modifications improve the Droid's camera autofocus capability and the phone's voice reception, the spokeswoman added. At least 300 comments at a Motorola online support forum refer to the subject, " Droid phone sound quality is not great ," and most comments refer to audio echo problems noticed by people whom Droid users are calling. Despite the many online complaints of a similar problem from Droid users, he couldn't get Verizon store officials to listen to him, he said. "Each time I returned to the store, now three times, I have been treated increasingly like an Android from out of space until [a recent] Friday when I threw a nutty in the store and screamed out for attention," he wrote. "The techs were clueless." Davis said his son, an engineer at Cisco Systems Inc., helped him decrease the echo somewhat by adjusting the phone's settings so that when the echo shows up, Davis must fidget with the speaker button to lessen the echo. One Motorola Droid user, John Davis, said he has enjoyed all aspects of his Droid except for the phone itself. "Almost from day one there has been an annoying echo primarily with the person on the receiving end," he wrote in an e-mail to Computerworld . Davis, a physician, bought his phone the first day it was available at a Verizon store near Boston.

But Davis was still awaiting the update, which was rumored to start on Dec. 11, but now appears to have started four days earlier. However, the official update documentation says only that one of the 14 improvements is listed as "audio for incoming calls is improved." A separate improvement says that Bluetooth functions are improved with "background echo ... eliminated" but only in reference to Bluetooth usage. Davis said his son believes the update is designed to address the issue, and so do many on an online forum. The full list also includes improvements to OS stability, battery life and camera auto focus. Ironically, many reviewers of the Motorola Droid found it has superlative sound quality , so the echo problem could be a function of networks as well as the Droid, many forum users have noted. Davis said he had no significant problems with his camera, but is still eager to have the update for the camera focus.

A Motorola support forums manager, identified online only as Matt, called attention to the update yesterday with a link to the separate Motorola forum on sound quality, implying that the improvements could help the echo problem. Verizon has noted that to get the free update, the Droid device needs to have 40% or more power available if it's not connected to an external power source and 20% power available to it if connected to a power source. The Verizon spokeswoman did not answer directly whether the updates fix the echo problem, saying only that descriptions of the audio problem on forums are "subjective," but she offered to provide a fuller explanation later.

Google Search Page Gets a New Look

Google has introduced a new version of the search engine's home page, which features a sleek fade-in effect that hides all the elements of the page except the logo, search bar, and the buttons. The rest of the elements of the page, such as links to Gmail, Documents, News, Maps, Shopping, etc., will be revealed with a fancy fade-in effect when you fist move the cursor on the screen. When accessing the main Google search page, you will only see the Google logo (or the doodle of the day) and the super-sized search bar (introduced a few months ago) with the search buttons underneath.

Google's new search homepage is now even less crowded, in comparison to Bing, the competing search engine from Microsoft, which overlays different images under the search bar daily and features search queries of interest. The search company says it tried about ten versions of the fading homepage and chose the current one based on "user happiness metrics". Some of the earlier versions of the fade-in Google homepage had an even more minimalistic approach, with the search buttons hidden at first. The fading Google homepage was first noticed a few months ago, when Google was experimenting with different designs. The final version of the fading homepage is now being introduced to Google home pages around the world. Google also introduced a better format for image search results earlier this week. Google explains in a blog post that it was concerned with the time to first action on the new homepage, which could confuse users initially. "We want users to notice this change... and it does take time to notice something (though in this case, only milliseconds!). "Our goal then became to understand whether or not over time the users began to use the homepage even more efficiently than the control group and, sure enough, that was the trend we observed," the Google team explained.

The new image search layout will show a larger image and additional smaller images alongside. In a previous update in November, Google also introduced Image Swirl, which bring layers of similar images into searches.

HP to focus on services with new print division

Hewlett-Packard on Monday formed a new print services division with a focus on managing print and imaging hardware and software in enterprises. The unit will also provide services and software that put scanned or printed documents in workflow systems to make document management easier. The division, called Managed Enterprise Solutions, aims to unify disparate hardware such as copiers, printers and scanners in order to cut hardware and printing costs, said Vyomesh Joshi, executive vice president of HP's imaging and printing group.

The company's attention has been geared toward hardware and supplies, but software and services surrounding printing and imaging are a growing opportunity, Joshi said. There is more to printing than just hitting the print button, said Roger Douglas, director of managed print services at HP. For example, software provided with the managed services could enable an invoice to be scanned, which can automatically be put into a company's payroll system. The company sees a US$121 billion annual opportunity in the printing market, of which $64 billion is for hardware and $57 billion for software and services. The automation reduces the number of steps and cost required to manage the document, Douglas said. The documents can also be secured through a service by establishing a status to ensure documents aren't appended, Douglas said.

It also reduces the chance for error through manual transcription. For example, if a marketing logo is finalized on a particular document, its status can be appended to ensure no one changes it. The company is also changing printer designs to build in more services-related functionality. This approach is particularly helpful when editing legal documents, he said. For example, a touch screen on multifunction printers can be used to input or check the job status of scanned documents like patient records. "A lot of times customers have treated imaging and printing like an afterthought," Douglas said. The company has also expanded the availability of a program that guarantees savings for customers who sign up for its print services outside the U.S. Under the plan, HP assesses a company's imaging and printing environment and calculates the possible savings a company can realize using HP's managed services.

Managed print is all about stepping back and taking a more strategic and methodical look at how those documents are managed, he said. If customers haven't realized the savings in a year, HP will make up the difference with a credit that can be used for their next printing services contract. The unit will be a part of the company's imaging and printing division, Joshi said. The company has already signed up 100 customers since it launched that program, Joshi said. The company has pulled some personnel from the existing services division and has seen its services customer base expand since acquiring EDS. HP has a strong presence in the printer market, and the expansion of services could help the company capture a larger share in the printer space, said Edward Crowley, CEO of Photizo Group, who was at HP's press briefing Monday.

The increased level of focus on services could also benefit HP's enterprise customers, he said.

States scramble to track federal stimulus bucks

There's no such thing as a free lunch, especially for IT. Go to the state of Iowa's Web site, and you can see that of the $2.5 billion in federal economic stimulus money earmarked for the state under the American Recovery and Reinvestment Act of 2009 (ARRA), $553 million has already been spent on health, education, infrastructure and other programs designed to create jobs and jump-start the local economy. Iowa CIO John Gillespie figures his IT organization has devoted about 800 man-hours so far to making that data available to the state's citizenry. "We actually had to build the application to give [different state agencies and programs] a way to submit data to us," he says. Drill a bit deeper into the data and you can pull up the exact amounts spent on weatherization training and technical programs, rental assistance programs and hundreds of other individual projects.

But the far bigger challenge, Gillespie says, has been building the business rules and defining internal processes to comply with federal reporting requirements, which have changed or been updated several times since the stimulus package was first announced in February. Just as the $787 billion ARRA is unprecedented, so are the reporting demands it's making on state CIOs and IT organizations, which are scrambling to whip up new processes and tools to accurately track and account for their states' shares of the stimulus pie. States are required to file quarterly reports that fully account for every tax dollar spent. The process has been complicated by a variety of factors, including exceedingly tight deadlines and complex and changing federal reporting guidelines. Like so many of the energy and construction projects launched with stimulus dollars, tracking and reporting systems remain works in progress.

The best state Web sites for ARRA tracking States with the best ARRA-tracking Web sites, as of July: 1. Maryland (see related story) 2. Colorado 3. Washington 4. West Virginia 5. New York 6. Pennsylvania - Mitch Betts Source: study by Good Jobs First (PDF), Washington, July 2009 Another big problem is the lack of a central accounting system in most states, which have had to first devise ways of extracting and aggregating data from multiple systems across hundreds of agencies before rolling it up to report it to the federal government. In Missouri, one of a handful of states to have a central accounting system used across all state agencies, funding and budgeting data is relatively easy to access. Two data points the feds want to track are job creation and retention under the economic stimulus program. "But the definition and requirements for how to count jobs is quite a challenge to understand," according to Marilyn Gerard-Hartman, director of enterprise applications for Missouri. What remains difficult to grasp, however, is precisely what the federal government wants to know, says CIO Bill Bryan. For example, if the state awards a highway infrastructure project to a contractor who in turn hires a subcontractor, who in turn hires other subcontractors, "how far down the chain is the state responsible for tracking? Meanwhile, fulfilling the requirements to the letter of the federal law is critical, Bryan notes. "If you don't comply, you could get thrown under the bus and not get any further funding." "One of the biggest challenges is just the speed at which we had to get things done," says Iowa's Gillespie. "The rules for the most part didn't get finalized literally until weeks - not months - ago.

And do you only count it as a job created if the job wouldn't have existed without the ARRA funding?" Generally, "it hasn't been clear what the requirements are until fairly late in the game," adds Bryan. Just keeping up has been the biggest challenge." Rather than licensing commercial stimulus-tracking tools, Gillespie's team internally developed a tracking and reporting system "using tools already familiar to financial folks who have all the data in Excel spreadsheets," he explains. First things first But before IT could build the tracking system, "we actually had to build a Web-based application to give people a way to submit data to us," Gillespie explains. The data is imported into a database, where it is aggregated, extracted and converted to an XML-formatted report and submitted online to the federal government. Stimulus reporting: The basics More than two-dozen federal agencies have been allocated a portion of the $787 billion in stimulus money.

The federal agencies are required to file weekly financial reports on how they're spending the money and their specific activities involving ARRA funds. Each federal agency develops specific plans for its share, then awards grants and contracts to state governments or, in some cases, directly to schools, hospitals, contractors or other organizations. Last month, states and other grant recipients for the first time filed the quarterly spending reports required under the law. As Nabors puts it: "Between OMB and the vice president's office and others in the White House and out in the agencies, we've done 169 different conference calls with recipients. The executive branch has worked hard to ensure a smooth reporting operation, according to Rob Nabors, director of the federal Office of Management and Budget.

There've been 170 events with state officials. There have been seven White House forums, and there've been 20 separate Recovery Act reporting training sessions. We've had 37 different events with local government officials. That by itself is an unprecedented effort by the federal government to make sure that we get it right, and this was something that started all the way back in February." - Julia King All of this was done in a matter of weeks by a small team comprising a designer-architect, a programmer and a project manager who is the chief liaison between IT and the state's stimulus office. But given the fierce push to quickly distribute ARRA funds and get new projects up and running, traditional IT project management practices, such as having a comprehensive set of user requirements, have in some cases gone out the window. The team already had some experience from working on the state's recovery Web site, which Gillespie says has "been kind of an iterative process that has been going on since the first recovery money came out." He chalks up the speedy rate of progress on both projects to what he describes as healthy competition among states to have good reporting and great Web sites. "We wanted to be better than everybody else," he says.

In Missouri, for example, a team was in the midst of implementing Microsoft Corp.'s Stimulus360 software for tracking funding and projects when the feds issued a change in data models for reporting. "We had to move forward with plans and put things in place even though you knew [more] changes were coming," says Gerard-Hartman. Tracking and reporting how many jobs are created with ARRA funds is a prime example. Like a start-up At the newly formed Massachusetts Recovery and Reinvestment Office, Deputy Director Ramesh Advani likens the fast pace and deadline-driven atmosphere and culture to the environment of a start-up company. "When you're doing something for the first time, you deal with systems issues, people issues, deadline issues, and you come across something new every day," he says. Meeting the first federal reporting deadline of Oct. 10 required some on-the-fly tactics. "For the first round of reporting, what we have done is develop some manual templates, which we issued out to state agencies. That data will then be gathered and uploaded into a recently launched central database, then uploaded through XML to the federal system," he explains.

Each agency must use the same template and also pass it on to subrecipients and vendors. But this is only for the first round of reporting, Advani emphasizes. We want to make sure we can use the same tools and reporting database beyond ARRA," Advani says. For the long term, the state is developing an automated data-gathering and -analysis system that includes Oracle Corp. business intelligence tools, data marts and data warehousing. "We're trying not to make this a short-term solution, because ultimately we want to upgrade how we do grants management and our budgets across the board. ARRA timeline: 2009 * Feb. 17: The American Recovery and Reinvestment Act is signed into law. For example, funding for ARRA transportation and highway projects had a 120-day "use it or lose it" deadline.

The federal government's Recovery.gov Web site goes live. * Feb. 19: Federal agencies begin announcing block grant awards. * May 17: Agency and program plans are posted on Recovery.gov. * May - October: ARRA stimulus money is distributed to states and other recipients. * May - August: Reporting requirements and updates are developed and distributed. * Sept. 28: Recovery.gov is relaunched with geographic mapping. * Oct. 10: The first quarterly deadline for recipient reporting is reached. * Oct. 30: Recipient grant and loan data is posted. - Julia King ARRA's tight timeline and strict reporting deadlines have already driven some key process improvements in the state. But it typically took the state between 100 and 300 days to advertise projects and solicit bids from contractors. "We ended up drilling down into the system to get it down to a 40-day process, which is something we're proud about," Advani says. Going forward, the office will oversee all activities involving grants reporting, monitoring and compliance. Another long-term improvement is the creation of the program office itself. The goal is to increase overall information transparency "beyond what's expected for federal reporting," says Advani.

Before ARRA, for example, the state didn't provide electronic versions of contracts on its Web site - which is a requirement under ARRA. "Now, we'll take that technology and process new contracts through the same system so we can provide broader information on all contracts that have been awarded," he says. Maine CIO Dick Thompson says he's already been directed by a legislative committee to ensure that IT work done to meet ARRA reporting requirements is also used to increase information transparency statewide. The result of ARRA reporting, CIOs agree, is a lot like the road signs popping up that say: "Temporary Inconvenience, Permanent Improvement."

Network-based e-mail – Ready for prime time?

In the prior newsletter, we raised the question of whether the time is here – or past due – for moving e-mail from local PCs back to the network. Security: Of course, this is always the first question for any public e-mail services (such as Amazon). Is your "private" e-mail really private? This time we want to continue the discussion by looking at some of the key questions that need to be addressed.

In truth, our answer is "probably not." However, anything that has ever transited the Internet is likewise probably not truly private. Data security: Yet another way of looking at "security." How difficult would it be for someone to hack into your public cloud-based e-mail? In reality, any illusion of true security is probably just that – an illusion. Given enough time and enough tries at a given account, the answer would be "not very." However, just to put this into perspective, what is the relative risk of someone hacking an online account vs. having a notebook computer (containing the same information) lost or stolen? For the SMB, the public services probably are quite appropriate.

Private or public cloud: This is a tough one, and a lot depends on scale. For larger shops, it's a more complex call. This alleviates the necessity of having local servers, maintaining these servers, backing up on a regular schedule… This is basically the same as any other cloud application. That said, we've seen numerous shops totally "outsourcing" e-mail to services like Google. Storage availability: One of the major reasons years ago for moving to a PC-based service was that network storage was limited and expensive. Now, however, even the free version of Gmail offers individuals over 7GB of storage (with a constantly incrementing counter.) And additional storage is available at an "almost free" price.

Now, however, that's no longer a stumbling block. Compliance: A great question. However, our initial take is that compliance with various regulations can be handled once by the cloud-based organization and then applied for multiple customers. And one that we'll be looking for your input on. More on this to come.

For now, the services are looking "good." And we're eagerly awaiting checking out "Google Wave" as a look at the next generation. Integrated interfaces and collaboration: Clearly, this is an area where we'll be seeing significant interest in the near future. Personalization: Right. No problem. You don't want to have your corporate image as [fill-in-the-blank]@gmail.com or [fill-in-the-blank]@yahoo.com. If it's a private cloud, then you still have your own servers.

And this is only a starting point for this issue. And even if it's a public cloud, it's trivial to personalize with your own domain name. For a continuation, we invite you to join our discussion on this topic at TECHNOtorials. Com.

Microsoft correctly predicts reliable exploits just 27% of the time

Microsoft's monthly predictions about whether hackers will create reliable exploit code for its bugs were right only about a quarter of the time in the first half of 2009, the company acknowledged Monday. "That's not as good as a coin toss," said Andrew Storms, director of security operations at nCircle Network Security. "So what's the point?" In October 2008, Microsoft added an "Exploitability Index" to the security bulletins it issues each month. The idea was to give customers more information to decide which vulnerabilities should be patched first. The index rates bugs on a scale from 1 to 3, with 1 indicating that consistently-successful exploit code was likely in the next 30 days, and 3 meaning that working exploit code was unlikely during that same period. Before the introduction of the index, Microsoft only offered impact ratings - "critical," "important," "moderate" and "low" - as an aid for users puzzled by which flaws should be fixed immediately and which could be set aside for the moment.

Microsoft also tallied its predictions by security bulletins - in many cases a single bulletin included patches for multiple vulnerabilities - to come up with a better batting average. "Sixteen bulletins received a severity rating of Critical," it said in its report. "Of these, 11 were assigned an Exploitability Index rating of 1. Five of these 11 bulletins addressed vulnerabilities that were publicly exploited within 30 days, for an aggregate false positive rate of 55%." The company defended its poor showing - even on a bulletin-by-bulletin level it accurately predicted exploitability only 45% of the time - by saying it was playing it safe. "The higher false positive rate for Critical security bulletins can be attributed to the conservative approach used during the assessment process to ensure the highest degree of customer protection for the most severe class of issues," said Microsoft. "There's some validity to that," agreed Storms. "They're going to err on the side of caution, if only to prevent people saying 'I told you so' if an exploit appears later." John Pescatore, Gartner's primary security analyst, agreed, but added, "If they want to stick with the index, they need to adjust the criteria so fewer vulnerabilities get a '1.'" With vulnerability-by-vulnerability predictions correct only a fourth of the time, Storms questioned the usefulness of the exploitability index. "What's the point of the index if they're always going to side on the more risky side, as opposed to what's most likely?" he asked. "In some ways, we're back to where we were before they introduced the exploitability index." From Storms' point of view, the exploitability index was meant to provide more granular information to customers who wondered what should be patched first. But in the first half of this year, Microsoft correctly predicted exploits just slightly more than one out of every four times. "Forty-one vulnerabilities were assigned an Exploitability Index rating of 1, meaning that they were considered the most likely to be exploited within 30 days of the associated security bulletin's release," Microsoft stated in its bi-annual security intelligence report , which it published Monday. "Of these, 11 were, in fact, exploited within 30 days." That means Microsoft got it right about 27% of the time. Presumably, a vulnerability marked critical with an index rating of "1" would take precedence over a critical vulnerability tagged as "2" or "3" on the exploitability index. "With these numbers of false positives, we are in no better place than we were prior to the index, in respect to granularity," he said. Instead, Pescatore again argued, as he did last year when Microsoft debuted the index, that the company would better serve customers by abandoning its own severity and exploitability rankings, and move to the standard CVSS [Common Vulnerability Scoring System] ratings. Pescatore also questioned the usefulness of the exploitability index. "I doubt anyone even looks at it," he said.

The CVSS system is used by, among other companies and organizations, Oracle, Cisco and US-CERT. "Because Microsoft does its own exploitability index, enterprises can't compare theirs with Adobe's or Oracle's. It's an apples and oranges thing then," said Pescatore. "It's not just Windows bugs that companies have to deal with anymore." He doubted Microsoft would take his advice. "They don't want to do that because then reporters and analysts can look and say, 'Microsoft has more higher-rated vulnerabilities than Oracle or Adobe,'" he said. "There's nothing in it for them to do that." Microsoft made the right call on all 46 vulnerabilities that were assigned an exploitability rating of "2" or "3," which indicate that an exploit would be unreliable or unlikely, respectively. "None were identified to have been publicly exploited within 30 days," Microsoft's report noted. Microsoft's security intelligence report, which covers the January-June 2009 period, was the first to spell out the accuracy of the exploitability index. If all its predictions in the first half of 2009 are considered, not just those marked as likely to be exploited, Microsoft got 57 out of a possible 87, or 66% of them, right. But Microsoft has touted its forecasting before. Microsoft's security intelligence report can be downloaded from its Web site in PDF or XPS document formats.

A year ago, for example, Microsoft said in a postmortem of its first-ever index that although it had accurately predicted exploits less than half the time, it considered the tool a success . "I think we did really well," said Mike Reavey, group manager at the Microsoft Security Research Center (MSRC), at the time.

Cloudera intros Hadoop management tools

Startup Cloudera is introducing a set of applications on Friday for working with Hadoop, the open-source framework for large-scale data processing and analysis. It allows an application workload to be spread over clusters of commodity hardware, and also includes a distributed file system. Cloudera, which provides Hadoop support to enterprises, developed the new browser-based application suite to simplify the process of using Hadoop, according to CEO Mike Olson. "It's an easy-to-use GUI suitable for people who don't have a lot of Hadoop expertise," Olson said. "The big Web properties with sophisticated and talented PhDs have been successful [with it], but ordinary IT shops ... have had a harder time." Hadoop is known for its behind-the-scenes role crunching oceans of information for Web operations like Facebook and Yahoo. But although the technology is "at its best" when data volumes get into multiple terabytes, Hadoop has relevance for a wide variety of companies, according to Olson. "It's increasingly easy to get your hands on that much data these days," especially from machine-generated information like Web logs, he said.

Cloudera and its partners are fine-tuning the suite, which is now in beta, before issuing a general release. The browser-based application set is supported on Windows, Mac and Linux, and includes four modules: a file browser; a tool for creating, executing and archiving jobs; a tool for monitoring the status of jobs; and a "cluster health dashboard" for keeping tabs on a cluster's performance. Hadoop needs many more tools like it, according to analyst Curt Monash of Monash Research. "If Hadoop is to consistently handle workloads as diverse and demanding as those of [massively parallel processing] relational DBMSes, it needs a lot of tools and infrastructure," Monash said via e-mail. "The three leaders in developing those are Yahoo, Cloudera, and Facebook. There's a long way to go."