Thursday, August 7, 2008

What's in a Name?

Imagine for a moment that you know nothing about Apple's notebook lineup.
Perhaps you suffered a concussion when your previous notebook fell on your head, or--more likely--you're a fed-up-with-Windows would-be switcher. Whatever the reason, you know so little about Apple's notebook lineup that you don't even know they're all called MacBooks.
What's remarkable is that you could still walk into an Apple store--or dial up Apple's online store in your browser--and with no outside research whatsoever buy the right Mac laptop to meet your needs. Your commonsense hunch after reading nothing more than the names of products would be spot-on correct.
The same self-evident naming scheme applies to Apple's desktops (Mac mini, iMac, and Mac Pro) and iPods (shuffle, nano, classic, and touch). The names alone tell you what the products are and how they relate to each other; they make it easy to buy.
Simplicity everywhere
As the sort of person who does know something about the Mac lineup, you might think everything I've said so far is incredibly obvious. But here's the thing: such easily understood product branding is almost nonexistent among Apple's competitors.
Dell offers at least five different notebook lines: Inspiron, XPS, Precision, Latitude, and Vostro. Sony offers six different lines of Vaio notebooks: TZ, SZ, CR, FZ, NR, and AR. The names tell you nothing about the laptops; they sound more like abbreviations for obscure states from the former Soviet Union.
The experience of buying a laptop from Apple, on the other hand, is every bit as well designed as the laptops themselves. The same adjectives that apply to Apple's products--simple, obvious, elegant, thoughtful--apply to Apple's branding.
It wasn't always like this at Apple. Just ask any longtime Mac user about the Performa era. But ever since the iBook and PowerBook lineups, followed by the MacBook and MacBook Pro models, Apple has been making it easier for its customers to understand its Mac offerings.
Apple doesn't force you to figure out the difference between, say, a Vaio SZ660N and a Vaio SZ440N66. Products within a given Mac product line are simply differentiated by their specs--CPU speed, color, screen size, and storage capacity.
Fewer names, fewer products
The trade-off, though--and there's always a trade-off--is that Apple's product lineups are deliberately sparse. The company's goal is to satisfy as many customers as possible with the fewest number of products. It's a lot less likely that Apple makes a Mac that's perfect for you. Take, for example, the gap that exists between the Mac mini and the Mac Pro: many Mac buyers would like to see something with the specs of the iMac but without the built-in display.
Until recently, the other big gap was at the small end of the MacBook line. Rumors of a new ultraportable MacBook began back in 2006, when Apple dropped the 12-inch PowerBook G4. But ultraportable meant different things to different people. Some wanted lighter, some wanted thinner, some wanted a smaller footprint (and thus a smaller screen). Some wanted cheaper (like the 12-inch iBook) and some wanted as much performance as could fit inside (like the 12-inch PowerBook). What we got with the MacBook Air is something else: lighter, thinner, and more elegantly designed, with compromises in performance and expandability.
It won't hurt Apple that some Mac users are disappointed in the MacBook Air. If you're going to buy a Mac no matter what, Apple doesn't need to make one that's exactly what you want. You'll just buy the one the company does offer that comes closest. Apple doesn't have to mimic PC makers, who are driven to offer complex product arrays out of fear that gaps in their lineups will drive customers to competitors.
What Apple has needed is a notebook that appeals to customers who might not have otherwise bought a Mac portable at all. The MacBook Air is that machine. It's far better than the MacBook or MacBook Pro as secondary machine for users who already have a nice Mac desktop. It may sacrifice expandability, but it offers simplicity and elegance--two factors at the core of Apple's appeal to Windows users. For fence-sitting switchers who are thinking, "Man, things do look easier and simpler on the Mac," the MacBook Air is just what they were waiting for.

ID Theft Ring Attacked Retailers on Multiple Levels

A ring of identity thieves that targeted U.S. retailers used sophisticated and multifaceted attacks to steal more than 40 million credit and debit card numbers from TJX, OfficeMax, Barnes & Noble and other companies, according to court documents.
The attacks cost retailers and credit card companies tens of millions of dollars.
Members of the ID theft conspiracy used so-called wardriving techniques to find holes in wireless networks operated by retail stores. Once inside the networks, the thieves located and stole credit card transaction information stored on the retailers' networks, according to court documents.
The thieves also installed so-called sniffer software to capture password and account data on the stores' networks, and they used Internet-based attacks, including SQL injection attacks, to gain access to credit card databases.
The ID theft group stored the captured credit card numbers on compromised servers in the U.S., Latvia and the Ukraine, according to court documents. The thieves then encrypted the credit card numbers on those servers, according to the indictment document of Albert Gonzalez, the alleged ringleader of the ID theft scheme.
Gonzalez, of Miami, was indicted Tuesday in U.S. District Court for the District of Massachusetts on charges of computer fraud, wire fraud, access device fraud, aggravated identity theft and conspiracy. Ten other defendants have been indicted or charged with crimes in what's believed to be the largest ID theft and computer hacking investigation in the history of the U.S. Department of Justice, the DOJ announced Tuesday.
The indictment document for Gonzalez, who was working as an informant for the U.S. Secret Service while allegedly engaged in the scheme, sheds some light on the ID theft operation. The thieves were able to encode credit card information on blank cards that were used to obtain tens of thousands of dollars from cash machines in single visits, the court document says.
Among the attacks detailed in the court document:
-- In about 2003, Gonzalez and others found an unencrypted wireless access point at a BJ's Wholesale Club store. BJ's reported a breach of its computer networks in early 2004.
-- In 2004, other members of the ID theft ring compromised an OfficeMax wireless access point in Miami, and they were able to steal credit card data. After law enforcement officials in 2006 identified OfficeMax as the victim of a data breach, the company said it hired an outside auditor to conduct an investigation and found no evidence of a security breach. An OfficeMax spokesman didn't immediately return a message seeking comment.
-- In July, September and November of 2005, alleged ID theft ring member Christopher Scott compromised two wireless access points operated by TJX at Marshalls department stories in Miami. Scott used his access to repeatedly transmit computer commands to TJX's servers storing credit card information in Framingham, Massachusetts. TJX, which also owns TJ Maxx, HomeGoods and other retail outlets, reported data breaches in January 2007.
Cybersecurity experts said companies worried about being victims can learn from the attacks. Companies storing personal information need to take a comprehensive approach to data security, including encryption of credit card databases, notifications of suspicious behavior inside their networks and limitations on who can access the data, security experts said.
Companies should also install software patches quickly and make sure they know were sensitive data is located on their networks, added Ted Julian, vice president of strategy and marketing for computer security vendor Application Security. Many companies do not know where all their sensitive data is stored, due to IT worker turnover and other factors, he said.
Companies also need to analyze their risks and take a targeted approach to fixing problems, said Sam Curry, vice president of product management at cybersecurity vendor RSA.
Attacks have changed in recent years, with more organized, targeted campaigns, Julian said. "The hackers are much more focused, and they'll try 38 doors, they'll try 100 doors," he said. "As soon as they find the one that's unlocked, they're on their way to the database. I don't know that a lot of [IT] people are getting $10 million in their budget to roll out a bunch of new security measures."
Companies should also examine whether the data they store is needed and how long they keep data, said Graham Cluley, senior technology consultant at Sophos, another cybersecurity vendor.
Companies have too long focused on perimeter defenses and not on protecting data inside their networks, Curry said. Retailers and other companies need to "wake up and take these threats seriously," Curry said. "Make the cost to the bad guys too high for them to do it."
The indictments announced Tuesday could raise awareness about cybersecurity, Curry added. And some high-profile convictions could serve as a deterrent to criminals.
But Curry and Cluley declined to point fingers at the retailers whose systems were compromised. While customers of the companies need to put pressure on them to improve security practices, the companies are victims, too, Cluley said.
"It'd be wrong to beat up the companies too much," Cluley said. "Competing companies shouldn't be feeling too smug, because how many of them can put their hands on their hearts and say, 'this could never happen inside our organization?'"
The U.S. Federal Trade Commission, however, filed complaints against TJX, BJ's Wholesale and DSW, a shoe retail chain targeted by the ID theft ring that reported a data breach in March 2005. DSW reported that more than 1.4 million credit card numbers were compromised, and losses ranged from US$6.5 million to $9.5 million.
As of mid-2005, BJ's reported outstanding claims of $13 million related to the data breach. About 455,000 credit card numbers were taken in the TJX breaches, according to the FTC.
The FTC alleged that the three retailers did not take appropriate security measures to protect against the attacks.
The FTC announced a settlement with BJ's in June 2005 requiring the company to implement a comprehensive information-security program and obtain audits by an independent third-party security professional every other year for 20 years. The agency announced a similar settlements with DSW in December 2005 and TJX in March of this year.
The FTC has not filed complaints against six other companies identified as data breach victims by the DOJ. Those companies are Dave and Buster's, OfficeMax, Barnes & Noble, Boston Market, Sports Authority and Forever 21. An FTC official said she could not comment on possible complaints against those companies because the FTC does not comment on ongoing investigations.

Tuesday, August 5, 2008

Nissan Goes High-tech to Stop Accidents, Inefficient Driving

Nissan has developed two new systems that communicate safety and fuel-efficiency information to car drivers through force feedback of the pedals and steering wheel.
The first, called side collision prevention, uses a millimeter-wave radar to monitor the blind-spot -- the area just to the rear of a car where other vehicles and objects can't be easily seen in the car's mirrors -- and indicate the presence of an object with a small light positioned near the wing mirror. It works with other systems in the car to sense when a dangerous maneuver is being attempted.
"All sorts of technologies are combined," said Yasuhisa Hayakawa, an engineer at the advanced engineering group of Nissan's technology development department. "Apart from the millimeter system it also uses a camera and measures the relationship between the lanes so all this sensor information is combined to detect that a vehicle is approaching from behind and also that the driver is trying to do a lane change."
When the driver attempts a lane change with a car in the blind-spot, an audible warning sounds and the steering wheel gently resists the turn.
In a test drive of the system, it was remarkably effective and letting me know that I really shouldn't be attempting to change lanes. It would have been fairly easy to push through the resistance if I really needed to change lanes but in normal use it should prove enough of a warning to avoid a collision with a vehicle moving up from the rear.
The side collision prevention system is one of Nissan's "Safety Shield" family of four technologies intended to make driving safer. Two of the technologies are already available in some Nissan cars: distance control assist gently eases back the accelerator and applies the brake if you get too close to a vehicle in front while lane departure control monitors the road markings and provides a warning if you begin straying out of your lane.
The fourth technology, back-up collision prevention, watches for objects coming into the car's path when its reversing. Nissan will demonstrate this technology at the ITS World Congress that is due to take place in New York in November this year.
Nissan is also applying some of the same basic technology to make driving more environmentally friendly. The actuator pedal used in the distance control assist to add resistance to the accelerator is being employed to indicate when a car is being driven efficiently.
Dubbed "eco-pedal," the system is tied into a computer that monitors the car's current fuel consumption and transmission efficiency during acceleration and cruising to determine the optimal acceleration for best fuel efficiency.
Within this "eco-driving" range, a lamp in the dashboard illuminates. It begins to flash when the car starts moving out of the optimum zone and turns orange when the car is being driven inefficiently. At the same time the actuator in the accelerator pedal gently pushes back the pedal to indicate to the driver that they should ease back a little to increase efficiency.
If the driver is intent on accelerating, the resistance can be pushed through without too much effort or the entire system can be switched off depending on the driver's preference but Nissan says fuel efficiency can be improved by between 5 percent and 10 percent using the eco-pedal system.
Driving a car with the system installed it was immediately obvious when I was driving inefficiently. The slight resistance on the pedal also made it easy to hold the accelerator at the optimal position and drive using the least amount of fuel. It also made me realize that I'm probably wasting fuel in the way I drive my current car.
The eco-pedal scheduled to begin appearing in some Nissan cars next year.

Cucku Backup Invites You to Partner Up

Just as it's a good idea to store important documents in a safe deposit box to protect against fire, storing a copy of your data offsite is a smart move for any business. But for many individuals and small businesses, regular backups are enough of a chore, let alone regularly moving those backed-up files to offsite storage. It's easy to fall out of the habit.
A new startup called Cucku thinks the answer is something it calls "social backup software." Cucku Backup makes regular backups of your important files to a local hard disk and then automatically sends a copy of the latest changes to an offsite "backup partner" -- whether it's a dedicated server or just a friend with a PC. You don't need any special hardware to make it happen. So how does it work? I'll give you a hint: Your backup partner can't be more than a phone call away (but Cucku doesn't use a modem).
Give up? The answer is that Cucku is a novel use of the Skype voice-over-IP network. Both you and your backup partner need to have the Skype client installed in addition to the Cucku Backup software. But rather than placing voice calls, Cucku uses Skype to locate your partner on the Internet and initiate file transfers. It just sends backup data instead of voice data. The big advantage of this method is that, thanks to the Skype engineers' know-how, it makes it easy for less technically inclined users to connect to each other, without worrying about the vagaries of routers, firewalls, or IP networking.
Cucku Backup runs on Windows XP and Vista. The current software is free, but Cucku says it's planning a "Pro" version, to be released later this year, that will be available "for a small fee."
In case you were wondering, naming a backup partner doesn't mean turning over your confidential data to that person. Your partner can't make copies of your files, or open them, or even see the filenames. All of the backup data is encrypted before it is transmitted or stored, using virtually unbreakable 256-bit AES encryption.
The immediate downside, of course, is that when you agree to become someone's backup partner you give up some portion of your own hard drive in order to store their backups. Cucku doesn't set any limits to how much data your partner can backup over the service, either (though it currently can't backup individual files that are bigger than 4GB), but you do get to say just how much drive space you're willing to give up. In these modern times, when a terabyte of hard drive space can be had for just a couple hundred bucks, couldn't we all spare a few megabytes for a friend?

Sun Calls for SSD Companies to Unite on Standards

Players in the solid-state drive industry need to unite and establish an umbrella organization that establishes standards that define the technology, like its performance, a Sun Microsystems executive said on Monday.
The SSD industry, while in its infancy, has organizations establishing separate standards around SSD metrics, and there is not enough work being done to standardize them, said Michael Cornwell, lead technologist for flash memory at Sun.
"We don't see a focus among suppliers and vendors like ourselves because everyone looks at their implementation [individually] rather than as an industry implementation," Cornwell said.
A standards organization could help users measure SSDs and their applications, like the performance of SSDs in comparison to hard drives, Cornwell said. SSDs have attracted criticism for being expensive while providing less storage compared to hard drives.
Price-per-gigabyte could continue to be a relative issue when comparing SSDs to hard drives, but SSDs are more about performance than price, Cornwell said. SSDs don't have the capacity of hard-disk drives, but they perform better in certain environments. SSDs could be more relevant for data centers, for example, where it is comparatively faster and more power efficient than hard drives.
"The traditional storage market is completely focused on 'well, what's the cost-per gigabyte?' We look at 'what's the cost for meeting your performance metric' and design systems around that architecture rather than capacity," Cornwell said.
The SSD industry could use an organization like IDEMA (International Disk Drive Equipment and Materials Association), an organization that sets standards and guidelines for disk development, Cornwell said. IDEMA establishes industry standards and provides guidance on technology to vendors including heads and media in disk drives.
Without mentioning names, Cornwell said Sun is talking to other companies about the development of standards. Last month, Sun worked with Samsung to bump up the durability of SSDs, announcing the development of single-level cell flash chips capable of lasting 500,000 read/write cycles, higher than the 100,000 read-and-write cycles of earlier SLC-based flash memory.
A number of organizations developing SSD standards independently include T13, a committee for the International Committee on Information Technology Standards (INCITS), which defined standards for ATA (Advanced Technology Attachment) storage interface. Through standards organization JEDEC (Joint Electron Device Engineering Council), Seagate and Micron are trying to establish some SSD standards, including the definition of form factors.
SSD adoption will be driven by Web 2.0 applications, Cornwell said. Web 2.0 applications mainly reside in data centers, and distributed applications on SSDs in different nodes could deliver "phenomenal" performance, Cornwell said. For example, delivering cached photo content from an SSD may be quicker than getting it from a disk drive.
Sun has said it will include SSDs in storage products later this year.

Security Oversight May Have Enabled Countrywide Breach

The man accused of stealing customer data from home mortgage lender Countrywide probably was able to download and save the data to an external drive due to an oversight by the company's IT department.
On Friday, Rene Rebollo, a former senior financial analyst at Countrywide, was arrested for his alleged role in stealing customer data and selling it.
U.S. Federal Bureau of Investigation affidavits show that Rebollo told special agents that he knew most computers in the office had a security feature that disabled the use of a thumb drive. However, he discovered that one computer didn't have this feature.
On a weekly basis, often on Sundays, Rebollo would collect customer names per request by his buyers and download them onto his personal thumb drive using that one computer in the office, according to the documents. Rebollo might specifically collect names of people who recently declined an offer of a loan by Countrywide, for example.
Over a two-year period, Rebollo estimated he downloaded approximately 20,000 customer profiles each week and sold files with that many names for US$500, according to the affidavit. The profiles included Social Security numbers and other contact details about the people. He typically would e-mail the data in Excel spreadsheets to his buyers, often using computers at Kinko's copying and business center stores.
Countrywide's owner, Bank of America, has not responded to a request for information about the type of security it employs to prevent this type of theft. According to a statement from the FBI last week, Countrywide said it is analyzing the stolen data to determine whether any customer identities have been compromised. If they have, the company said it will notify the customers, according to the FBI statement.
While it's not clear what type of security Countrywide employs that disables the use of thumb drives, it may use software that includes an agent on all computers that IT administrators can set to control how each port on the computer can be used. Such products can allow administrators to set rules that allow certain employees to access certain ports, or set rules that define what types of files can be copied to certain ports, said Pat Clawson, chairman and CEO of Lumension Security, a company that sells such software. If this is the method Countrywide uses, its administrators may have accidentally failed to install the agent on the computer that Rebollo discovered.
But that type of vulnerability can be avoided, Clawson said. Companies should have policies that require any device that touches the network to be checked. "No matter if that device is a laptop or a handheld, it has to go through some sort of scanning process to find if they have all the requisite materials before you allow them to access the network. It's clear that didn't happen here," he said.
Many companies that handle sensitive data also have systems that enforce encryption rules and prevent most workers from copying sensitive data, Clawson noted.
Some organizations have resorted to far more "draconian" methods to try to prevent this type of theft, Clawson said. For a time, many U.S. government agencies filled USB ports with hot glue and drove plastic screws into microphones in an effort to prevent access to them, he said.
The FBI collected some of the customer data allegedly stolen by Rebollo by working with confidential witnesses who agreed to buy the data from one of Rebollo's customers, Wahid Siddiqi, who was also arrested last week. The witnesses then turned the data over to the FBI agents. Countrywide matched those numbers provided by the FBI with its own internal spreadsheets, confirming that the names were from its customers and were paired with accurate Social Security numbers.
In two years, Rebollo estimated he earned $50,000 to $70,000 on the activity. His Countrywide salary was $65,000 per year, according to the documents.
Rebollo initially cooperated with FBI agents, describing his actions to them and willingly giving them one of his home computers and a thumb drive, according to the affidavit. But he later seemed to have changed his mind. A few days after his meeting with the agents, Rebollo's lawyer told the FBI that he had decided to revoke his consent to search the drive and the computer.
Rebollo, who faces as much as five years in federal prison if convicted, was released on an $80,000 bond last week even though he doesn't appear ready to give up his activities, at least according to the affidavits. FBI agents said that six days after they spoke with Rebollo, when he described how he stole and sold the data, he called a witness offering to sell him more Countrywide customer names.

Friday, August 1, 2008

Microsoft's Open Source Guru Faces Uphill Battle

Microsoft's Sam Ramji is like a turkey knocking on Thanksgiving's door. Ramji has the unenviable task of stretching his neck out into the open source world as Microsoft's representative. And on top of it, his employer has preheated the oven with years of hubris, sleights of hand and broken promises.
Ramji's Sisyphean task was evident last week in Portland at the Open Source Conference (OSCon) and will likely be fuel for chatter at next week's LinuxWorld gathering in San Francisco. (Disclosure: Network World's parent company IDG sponsors LinuxWorld.)
In Portland, Ramji, who runs the Open Source Software Lab for Microsoft and is the company's director of open source technology strategy, gave a 15-minute presentation highlighting Microsoft's work with open source, the company's first code submission ever to the PHP community and a $100,000 investment to become one of only three Platinum sponsors of the Apache Foundation (Yahoo and Google are the others).
Then it turned ugly.
The first questioner from the audience wanted to know what it would take for Microsoft not to claim patent infringement violations in open source code.
His inquiry was followed by whoops, whistles and thunderous applause.
The next question was about trust, as in why should we trust you this time? And the next referenced what the questioner called the "Office Open XML debacle" and accused Microsoft of using its power to buy international standards.
Ramji, dressed in a Firefox T-shirt like it was a virtual bullet proof vest, is use to the machine gun fire and didn't shy away. He mentions cultural change that he has to facilitate within proprietary-minded Microsoft, trust built within an 18-month working relationship with Samba creator Jeremy Allison and others, and the need to provide more clarity around patents and the company's work to address shortfalls in U.S. patent law.
As he left the stage, he invited people to the back of the room for more questions, which becomes a six-deep ring of fire that lasted nearly 30 minutes.
"People stopped and wanted to ask more questions," he said later during an interview. "They thanked me for being here, appreciated the change agency work that my team has the privilege of doing outside the company."
Listening Is Key
Ramji, who took on the open source post in 2006, says listening is the start. "It lets us start to look at what divides us and what we can do to come closer together. What I said today may not be the be-all and end-all, but we have more than started the conversation, we are opening the next chapter."
That next chapter, he says, includes speaking and actions.
And if Portland is any indication, the speaking part is actually working.
"At its heart there is a lot of bad blood, but I'm proud to see Microsoft stepping up to the plate," says Ben Hengst, a Linux developer for Powell's Books. Hengst says he feels Microsoft is willing to change but that the open source community has ideas about how it should change. In essence, they are tired of being talked at and want a part in defining change.
"Animosity? Yes. But we want to get them going down the right path," Hengst says. "The biggest piece of change I saw was Sam on stage with a Firefox T-shirt and without fear of getting fired."
Ramji, a veteran of five start-ups who has a bachelor's degree in cognitive science and interests that range from history to physics, says he has a long leash. "What helps is that I have business responsibility. It is not strictly advocacy. I can tie what we are doing to good outcomes for the company."
In Portland, he announced Microsoft was contributing a patch to ADOdb, a data access layer for PHP. The code contribution to the PHP community was a first for Microsoft, and Ramji had to work with Microsoft's legal team to fit the work around the Free Software Foundation's GNU Lesser General Public License (LGPL). Last year, the LGPL was a dead end for Microsoft.
But it wasn't all altruism, Ramji says the code makes it easier for PHP developers who routinely develop on Windows to actually deploy their applications on the platform.
"Those kinds of innovation are what lead companies like IBM to contribute to open source," he says. "You have to find an operational business framework -- legal, financial, development -- that lets you move forward methodically. You can't be a corporate-level contributor and have everything be ad hoc."
As part of the plan, Microsoft earlier this year published 30,000 pages documenting APIs and communications protocols that its products use to connect to Windows Server 2008 and Windows Vista (including the .Net Framework). Last week, Ramji announced 100 protocols from its Communications Protocol Program would move under Microsoft's Open Specification Promise to ensure they could be used without fear of patent infringement.
The business side of the relationship is a reality many understand Ramji brings to his change efforts.
"We feel that if we fight Sam we weaken him," said Russell Nelson, the licensing approval chairman at the Open Source Initiative. "But it is going to take Microsoft time to figure out what they can execute. The biggest problem is that open source people feel under attack, under siege."
Ramji says he battles on two fronts, those within Microsoft that see open source as a threat and the open source side which sees Microsoft as a villain.
When asked which faction is softening faster he is careful not to speak for the other side.
"I have gotten to the point where I'm backed by great organizational management," he says. He points to new chief software architect Ray Ozzie, who talks about the importance of open source, and Ozzie predecessor Bill Gates, who Ramji says is fully connected with where Ozzie is driving Microsoft.
"Guys like Bill Hilf (GM of platform strategies) and Bob Muglia (senior vice president, server and tools division) have a vision and there is other executive sponsorship from places like the legal team and the sales team. People who see this is going to help our business," he says.
Ramji has delivered keynote addresses at more than a dozen open source events. "People are passionate. They ask questions and I am willing to take them. They say they appreciate the work that I do and they say they are seeing some changes in Microsoft."
Whether they see that change as positive or not will be the difference between Ramji being at open source's Thanksgiving table or on it.