Archive for the ‘Telecom and Networking’ Category

Tell your IT problems in time

Monday, January 30th, 2012

Our society relies increasingly on information technology (IT). In such a society, it is important that we, as citizens, trust and are satisfied with services utilizing IT. Unfortunately, IT problems in the use of services are part of our daily lives and. And they are frequently reported by the mass media.

Usually most of the IT problems visible to society are the same ones that system and service providers perceive to be the most problematic. Compensation alone will not satisfy users when the incident creates unpredictability and uncertainty for them. After service degradation, users are eager to use the service again if they receive relevant information. Information and knowledge thus play a significant role in incidents. Users will continue to IT after the failure, using a service, most likely, when they get the problem situation in a sufficient factual information.

This is stated in a recent Finnish study, doctoral thesis Information technology incidents in the present information society : Viewpoints of service providers, users, and the mass media, which examined the users’ thinking and intentions of the services provided at the time of their IT-related problems after the failures.

itservice

Clear information can bring significant competitive advantages over other service providers.

Computer technologies for 2012

Wednesday, January 25th, 2012

ARM processor becomes more and more popular during year 2012. Power and Integration—ARM Making More Inroads into More Designs. It’s about power—low power; almost no power. A huge and burgeoning market is opening for devices that are handheld and mobile, have rich graphics, deliver 32-bit multicore compute power, include Wi-Fi, web and often 4G connectivity, and that can last up to ten hours on a battery charge.The most obvious among these are smartphones and tablets, but there is also an increasing number of industrial and military devices that fall into this category.

The rivalry between ARM and Intel in this arena is predictably intense because try as it will, Intel has not been able to bring the power consumption of its Atom CPUs down to the level of ARM-based designs (Atom typically in 1-4 watt range and a single ARM Cortex-A9 core in the 250 mW range). ARM’s East unimpressed with Medfield, design wins article tells that Warren East, CEO of processor technology licensor ARM Holdings plc (Cambridge, England), is unimpressed by the announcements made by chip giant Intel about the low-power Medfield system-chip and its design wins. On the other hand Android will run better on our chips, says Intel. Look out what happens in this competition.

Windows-on-ARM Spells End of Wintel article tells that Brokerage house Nomura Equity Research forecasts that the emerging partnership between Microsoft and ARM will likely end the Windows-Intel duopoly. The long-term consequences for the world’s largest chip maker will likely be an exit from the tablet market as ARM makes inroads in notebook computers. As ARM is surely going to keep pointing out to everyone, they don’t have to beat Intel’s raw performance to make a big splash in this market, because for these kinds of devices, speed isn’t everything, and their promised power consumption advantage will surely be a major selling point.

crystalball

Windows 8 Release Expected in 2012 article says that Windows 8 will be with us in 2012, according to Microsoft roadmaps. Microsoft still hinting at October Windows 8 release date. It will be seen what are the ramifications of Windows 8, which is supposed to run on either the x86 or ARM architectures. Windows on ARM will not be terribly successful says analyst but it is left to be seen is he right. ARM-based chip vendors that Microsoft is working with (TI, Nvidia, Qualcomm) are now focused on mobile devices (smartphones, tablets, etc.) because this is where the biggest perceived advantages of ARM-based chips lie, and do not seem to be actively working on PC designs.

Engineering Windows 8 for mobile networks is going on. Windows 8 Mobile Broadband Enhancements Detailed article tells that using mobile broadband in Windows 8 will no longer require specific drivers and third-party software. This is thanks to the new Mobile Broadband Interface Model (MBIM) standard, which hardware makers are reportedly already beginning to adopt, and a generic driver in Windows 8 that can interface with any chip supporting that standard. Windows will automatically detect which carrier it’s associated with and download any available mobile broadband app from the Windows store. MBIM 1.0 is a USB-based protocol for host and device connectivity for desktops, laptops, tablets and mobile devices. The specification supports multiple generations of GSM and CDMA-based 3G and 4G packet data services including the recent LTE technology.

crystalball

Consumerization of IT is a hot trend that continues at year 2012. Uh-oh, PC: Half of computing device sales are mobile. Mobile App Usage Further Dominates Web, Spurred by Facebook article tells that the era of mobile computing, catalyzed by Apple and Google, is driving among the largest shifts in consumer behavior over the last forty years. Impressively, its rate of adoption is outpacing both the PC revolution of the 1980s and the Internet Boom of the 1990s. By the end of 2012, Flurry estimates that the cumulative number of iOS and Android devices activated will surge past 1 billion, making the rate of iOS and Android smart device adoption more than four times faster than that of personal computers (over 800 million PCs were sold between 1981 and 2000). Smartphones and tablets come with broadband connectivity out-of-the-box. Bring-your-own-device becoming accepted business practice.

Mobile UIs: It’s developers vs. users article tells that increased emphasis on distinctive smartphone UIs means even more headaches for cross-platform mobile developers. Whose UI will be a winner? Native apps trump the mobile Web.The increased emphasis on specialized mobile user interface guidelines casts new light on the debate over Web apps versus native development, too.

crystalball

The Cloud is Not Just for Techies Anymore tells that cloud computing achieves mainstream status. So we demand more from it. That’s because our needs and expectations for a mainstream technology and an experimental technology differ. Once we depend on a technology to run our businesses, we demand minute-by-minute reliability and performance.

Cloud security is no oxymoron article is estimated that in 2013 over $148 billion will be spent on cloud computing. Companies large and small are using the cloud to conduct business and store critical information. The cloud is now mainstream. The paradigm of cloud computing requires cloud consumers to extend their trust boundaries outside their current network and infrastructure to encompass a cloud provider. There are three primary areas of cloud security that relate to almost any cloud implementation: authentication, encryption, and network access control. If you are dealing with those issues and software design, read Rugged Software Manifesto and Rugged Software Development presentation.

Enterprise IT’s power shift threatens server-huggers article tells that as more developers take on the task of building, deploying, and running applications on infrastructure outsourced to Amazon and others, traditional roles of system administration and IT operations will morph considerably or evaporate.

Explosion in “Big Data” Causing Data Center Crunch article tells that global business has been caught off-guard by the recent explosion in data volumes and is trying to cope with short-term fixes such as buying in data centre capacity. Oracle also found that the number of businesses looking to build new data centres within the next two years has risen. Data centre capacity and data volumes should be expected to go up – this drives data centre capacity building. Data centre capacity and data volumes should be expected to go up – this drives data centre capacity building. Most players active on “Big Data” field seems to plan to use Apache Hadoop framework for the distributed processing of large data sets across clusters of computers. At least EMC, Microsoft, IBM, Oracle, Informatica, HP, Dell and Cloudera are using Hadoop.

Cloud storage has been very popular topic lately to handle large amount of data storage. The benefits have been told very much, but now we can also see risks of that to realize. Did the Feds Just Kill the Cloud Storage Model? article claims that Megaupload Type Shutdowns and Patriot Act are killing interest to Cloud Storage. Many innocent Megaupload users have had their data taken away from them. The MegaUpload seizure shows how personal files hosted on remote servers operated by a third party can easily be caught up in a government raid targeted at digital pirates. In the wake of Megaupload crackdown, fear forces similar sites to shutter sharing services?. If you use any of these cloud storage sites to store or distribute your own non-infringing files, you are wise to have backups elsewhere, because they may be next on the DOJ’s copyright hit list.

Did the Feds Just Kill the Cloud Storage Model? article tells that worries have been steadily growing among European IT leaders that the USA Patriot Act would give the U.S. government unfettered access to their data if stored on the cloud servers of American providers. Escaping the grasp of the Patriot Act may be more difficult than the marketing suggests. “You have to fence yourself off and make sure that neither you or your cloud service provider has any operations in the United States”, “otherwise you’re vulnerable to U.S. jurisdiction.” And the cloud computing model is built on the argument data can and should reside anywhere around the world, freely passing between borders.

crystalball

Data centers to cut LAN cord? article mentions that 60GHz wireless links are tested in data centers to ease east-west traffic jams. According to a recent article in The New York Times, data center and networking techies are playing around with 60GHz wireless networking for short-haul links to give rack-to-rack communications some extra bandwidth for when the east-west traffic goes a bit wild. The University of Washington and Microsoft Research published a paper at the Association of Computing Machinery’s SIGCOMM 2011 conference late last year about their tests of 60GHz wireless links in the data center. Their research used prototype links that bear some resemblance to the point-to-point, high bandwidth technology known as WiGig (Wireless Gigabit), which among other things is being proposed as a means to support wireless links between Blu-ray DVD players and TVs, replacing HDMI cables (Wilocity Demonstrates 60 GHz WiGig (Draft 802.11ad) Chipset at CES). 60 GHz band is suitable for indoor, high-bandwidth use in information technology.. There are still many places for physical wires. The wired connections used in a data center are highly reliable, so “why introduce variability in a mission-critical situation?”

tcpdump

Monday, January 23rd, 2012

Packet capture is one of the most fundamental and powerful ways to do network analysis.

If you think that tcpdump has been made obsolete by GUI tools like Wireshark, think again. Wireshark is a great application; it’s just not the right tool for the job in every situation.

tcpdump uses a “one-off-command” approach that lends itself to quick, on-the-spot answers. You can run it through an SSH session, doesn’t need X and is more likely to be there when you need it. And, because tcpdump uses standard command-line conventions (such as writing to STDOUT, which can be redirected), tcpdump can be used in all sorts of creative, interesting and extremely useful ways.

logo

You can even use tcpdump and Wireshark together by capturing the network data with tcpdump for viewing with Wireshark. To ensure that you capture complete packets, use the following command:

tcpdump -i <interface> -s 65535 -w <some-file>

tcpdump fu article introduces some of the basics of packet capture and provide a breakdown of tcpdump syntax and usage. Manual page of tcpdump lists you all the command line options you can use.

If you are embedded Linux system developer, remember that you can easily fit the tcpdump program inside a small embedded Linux system without too much problem (which is not the case with Wireshark, because it is a huge program that needs GUI and has many dependencies).

WANem network emulator

Thursday, January 12th, 2012

There are many cases when need to emulate various networking conditions and scenarios. Usually the most practical way to test the application on different networking conditions is to use some kind of WAN emulator that lets you control the various networking characteristics. WANem is a free WAN emulator suitable for this task. WANem allows the application development team to setup a transparent application gateway which can be used to simulate WAN characteristics like Network delay, Packet loss, Packet corruption, Disconnections, Packet re-ordering, Jitter, etc.

WANem is a Wide Area Network Emulator that is designed to provide a real experience of a WAN/Internet during application development and testing. WANem works over an Ethernet LAN environment. WANem is available in bootable CD and VMware virtual appliance versions at an affordable cost (for FREE!). Award winning (FOSS INDIA AWARDS 2008) WANem is built on top of Linux and many open source component. From a functionality perspective WANem hooks into the Linux kernel towards provisioning the network emulation characteristics and extends the functionality with additional modules.

Setup is pretty straight forward. WANem is normally launched through a LiveCD, which is based on a re-mastered Knoppix. Another option is to use VMware virtual appliance. I have used both versions. Both versions allow a quick and easy setup in any development environment with an intuitive web interface for purposes of configuration. You don’t need to be a network and Linux guru to use WANem because the provided easy and very quick. There are many example configurations you can easily select and you can modify them as needed.

wanem_basic_mode_small

In advanced mode you have option to set all necessary network performance parameters you can think of. If you are a networking expert and know what are the right setting for different parameters, this is the way to go. You can see the supported settings (in advanced mode) on the picture below.

wanem-adv

WANem has even tool (WANalyzer is distributed along with WANem) that allow you to measure the performance of an existing real network, and then it can simulate how that network performed.

WANem has to be located between two hosts, between each we want to simulate a network link. The routing parameters which need to be configured on the clients and/or on the WANem machine. The preferred and most straightforward configuration uses a PC with two Ethernet cards and connect that between the two hosts.

wanem

It is possible to work also with only one Ethernet card (with some limitations), but for this to work you need special configuration on the end hosts to make sure all traffic they send gets sent to the WANem machine that forwards the traffic to other host. I have personally used this approach only when I have wanted to use the virtual machine version of WANem.

Installing and Configuring WANem Virtual Appliance and Using the WANem WAN Emulator Virtual Appliance articles tells that setup is pretty straight forward. After the WANem Virtual Appliance has been started and setup in your network environment, all you have to do is to route your traffic through it.

WANem is an excellent tool.

Security trends for 2012

Tuesday, January 10th, 2012

Here is my collection of security trends for 2012 from different sources:

Windows XP will be the biggest security threat in 2012 according to Sean Sullivan, security advisor at F-Secure: “People seem to be adding new systems without necessarily abandoning their old XP machines, which is great news for online criminals, as XP continues to be their favourite target.”

F-Secure also says also that it might not be long before the cyber criminals turn their attentions to tablet devices. Attacks against mobile devices have become more common and I expect this to continue this year as well.

Americans more susceptible to online scams than believed, study finds. A recent survey from The Ponemon Institute and PC Tools dives into this question and reveals a real gap between how aware Americans think they are of scams and how likely they actually are to fall for them.

Fake antivirus scams that have plagued Windows and Mac OSX during the last couple of years and now it seems that such fake antivirus scams have spread to Android. Nearly all new mobile malware in Q3 2011 was targeted at Android.. When antivirus software becomes a universally accepted requirement (the way it is on Windows is the day), has the platform has failed and missed the whole point of being mobile operating system?

crystalball

Cyber ​​criminals are developing more sophisticated attacks and the police will counterattack.

Mobile phone surveillance will increase and more details of it will surface. Last year’s findings have included Location data collecting smart-phones, Carrier IQ phone spying busted and Police Surveillance system to monitor mobile phones. In USA the Patriot Act lets them investigate anything, anywhere, without a warrant. Now they are on your devices and can monitor everything. Leaked Memo Says Apple Provides Backdoor To Governments: “in exchange for the Indian market presence” mobile device manufacturers, including RIM, Nokia, and Apple (collectively defined in the document as “RINOA”) have agreed to provide backdoor access on their devices.

Geo-location tagging in smartphones to potentially cause major security risks article says that geo-location tagging security issues are likely to be a major issue in 2012—and that many users of smartphones are unaware of the potentially serious security consequences of their use of the technology. When smartphones images to the Internet (to portals such Facebook or Flickr) there’s a strong chance they will also upload the GPS lcoation data as well. This information could be subsequently misused by third parties.

You need to find your balance between freedom and security (
Vapauden ja turvallisuuden tasapaino). Usernames poured out for all to see, passwords and personal identification numbers are published. A knowledge of access management is even more important: who has the right to know when and where the role of functioning? Access, identity and role management are essential for the protection of the whole system. Implementation of such systems is still far from complete.

When designing networked services, the development of safety should taken into account in the planning stage, rather than at the end of execution. Even a secure network and information system can not act as operating a vacuum.

crystalball

Reliability of the server certificates will face more and more problems. We can see more certificate authority bankruptcies due cyber attacks to them. Certificate attacks that have focused on the PC Web browsers, are now proven to be effective against mobile browsers.

Stonesoft says that advanced evasion techniques (AET) will be a major threat. Stonesoft discovered that with certain evasion techniques (particularly when combined in particular combinations) they could sneak common exploits past many IDS/IPS systems (including their own, at the time last summer). Using the right tool set (including a custom TCP/IP stack) attackers could sneak past our best defenses. This is real and they foresee a not too distant future where things like botnet kits will have this as a checkbox feature.

Rise of Printer Malware is real. Printer malware: print a malicious document, expose your whole LAN says that sending a document to a printer that contained a malicious version of the OS can send your sensitive document anywhere in Internet. Researchers at Columbia University have discovered a new class of security flaws that could allow hackers to remotely control printers over the Internet. Potential scenario: send a resume to HR, wait for them to print it, take over the network and pwn the company. HP does have firmware update software for their printers and HP Refutes Inaccurate Claims; Clarifies on Printer Security. I wonder how many more years until that old chain letter, where some new insidious virus infects everything from your graphics card to your monitor cable, becomes true.

Unauthorized changes in the BIOS could allow or be part of a sophisticated, targeted attack on an organization, allowing an attacker to infiltrate an organization’s systems or disrupt their operations. How Do You Protect PCs from BIOS Attacks? The U.S. National Institute of Standards and Technology (NIST) has drafted a new computer-security publication that provides guidance for computer manufacturers, suppliers, and security professionals who must protect personal computers as they start up “out of the box”: “BIOS Integrity Measurement Guidelines,” NIST Special Publication 800-155.

According to Stonesoft security problems threaten the lives and the year 2012 may be the first time when we lose lives because of security offenses. According to the company does this happen remains to be seen, but the risk is due to industrial SCADA systems attacks against targets such as hospitals or automated drug delivery systems. I already posted around month ago about SCADA systems security issues.

Telecom trends for 2012

Wednesday, January 4th, 2012

What can we expect for the fast-moving telecommunications market this year?

There are many predictions. I started looking for information from Twelve 2012 Predictions For The Telecom Industry and Top 12 Hot Design Technologies for 2012 articles. Then I did some more research on what is happening on the field and decided to make my own list of what is expected this year. You can go to the original information sources by clicking the links to see where all this information comes from.

crystalball

The global telecommunications services market will grow at a 4% rate in 2012 (was 7% in 2011).

Mobile growth does not stop. The number of global mobile subscriptions will pass the 6 billion mark in February. India will pass China to become the world’s largest mobile market in terms of subscriptions.

The mobile handset market will surpass the $200 billion mark. Smartphones are most heavily used by people under 45, and that age group increasingly sees the smartphone or tablet as a portal to Facebook and Twitter, among other social networks. The demand for the chips that generate and process that data in smartphones is increasing (sales of smartphone applications processors surged to $2.2 billion in the third quarter of 2011). Six Companies Want Supremacy On The Smartphones Chip Market! Qualcomm Look Out!

There is lots of competition on mobile OS marker, but I expect that thing continue pretty much as 2011 ended: Android continues to boom, RIM and Microsoft decline. Symbian’s future is uncertain although Symbian started and finished 2011 as the undisputed king of mobile OSs (33.59%). Windows Phone will try to get to market and Leaked Windows Phone Roadmap gives us a peek into the future. Java Micro Edition making a comeback according to the NetApplications report because large number of low-cost feature phones. The real mobile application battle lines of 2012 will be drawn across the landscape of HTML5.Tizen open source project tries to push to mobile Linux market (first version Q1 2012) with ideas from Meego, LiMo and WebOS. Cars and smartphones start to communicate using MirrorLink technology to allow new features.

Mobile campaigns to be hot in 2012 presidential race article tells that though mobile advertising not seen much on the campaign trail, mobile strategy is expected to be important for attracting younger voters. Social networks played an important role in the last U.S. presidential election, but the explosive growth in smartphone usage and the introduction of tablets could make or break the candidates for president in 2012. Expect to see specialized apps to help campaign groupies follow the candidates.

Text messaging has been very profitable business for mobile phone operators and making them lots of money. Text Messaging Is in Decline in Some Countries tell that all signs point to text messaging’s continuing its decline. There has been already decline in Finland, Hong Kong and Australia. The number of text messages sent by cellphone customers in USA is still growing, but that growth is gradually slowing, “SMS erosion” is expected to hit AT&T and Verizon in this year or next years. The fading allure of text messaging is most likely tied to the rise of alternative services, which allow customers to send messages free using a cellphone’s Internet connection.

EU politicians want to ban roaming charges according to Computer Sweden magazine article. If the proposal becomes law in the EU, it takes away slippery roaming charges for mobile data (could happen earliest at summer 2012, but I expect that it will take much more time). Roaming robbery to end – 2015 article tells that the goal is that the mobile roaming fees should be completely abolished the 2015th.

Near Field Communication (NFC) is becoming available in many mobile phones and new flexibility via organic materials can help in implementing NFC. NFC-enabled SIM cards are expected to become a worldwide standard. Electronic wallet in smartphones probably takes a step forward with this. Google, opened the game with Google Wallet service. According to research firm ABI Research estimates that in 2012 NFC phones is growing 24 million to 80 million units. There is still years to wait until mass market on NFC wallets starts. ABI Research estimates that there is 552 million NFC enabled devices at year 2016.

The 4G technology WiMax will see the beginning of its end in Asia. Like operators in other regions, Asian operators will opt for the rival 4G technology LTE instead.

crystalball

The number of active (installed) PCs worldwide will pass the 2 billion mark. Broadband penetration continues to increase. Broadband penetration of the world’s population will pass the 10% mark globally. IPTV (Internet Protocol TV) penetration of the world’s population will pass the 1% mark. Broadband technologies are fundamentally transforming the way we live. UN wants two-thirds of the world online by 2015.

Today’s Cable Guy, Upgraded and Better-Dressed article tells that the cable guy is becoming sleeker and more sophisticated, just like the televisions and computers he installs. The nearly saturated marketplace means growth for cable companies must come from all the extras like high-speed Internet service, home security, digital recording devices and other high-tech upgrades.

Ethernet displaces proprietary field buses. As Ethernet displaces proprietary field buses to facilitate the operation of the digital factory. Ethernet switches are the ubiquitous building block of any intelligent network. Ethernet has also become the de facto networking technology in industrial automation even in mission-critical local networks. Modern Ethernet switches have added significant new functionality to Ethernet while decreasing port prices. Ethernet for Vehicles also becomes reality largely to serve the expected boom of camera-based applications in cars.

Operators’ growth will increasingly depend on their having a cloud computing strategy, an approach for the high-growth IT service market and a clear value proposition for the enterprise market. Data center technologies will be hot topic. 10GBase-T Technology will become technically and economically feasible interface option on data center servers. 10GBase-T Technology allows you to use RJ45 connectors and unshielded twisted pair cabling to provide 10Mbps, 100Mbps, 1Gbps, and 10Gbps data transmission, while being backward-compatible with prior generations.

40/100 Gbit/s Ethernet will be a hot topic. Carriers and datacenters have been clamoring for the technology to expand their core backbone networks. 2012–A Return to Normalcy and Pragmatic, Power Conscious 100G article mentions that in 2010 and 2011, the industry saw the first real roll-outs of 100G transport solutions based on Coherent Detection and FPGA-based Framers. In 2012 we’ll start to see 100G taking a bigger place in the build out of new and existing networks around the world. The initial deployments of 100G are clearly too costly and too power hungry to be widely deployed as the primary transport technology, so optical transport marketplace will move to much lower power and lower cost Direct Detection optical transport solutions. The average WDM link for 10G is dissipating about 3.5W per optical module, the average WDM link per 100G is dissipating about about 100W.

crystalball

5 Major Changes Facing the Internet in 2012 article tells that 2012 is poised to go down in Internet history as one of the most significant 12-month periods from both a technical and policy perspective since the late 1990s. This year the Internet will face or can face several milestones: root servers may have a new operator, new company could operate the .com registry, up to 1000 new top-level domains will start being introduced, additional 10,000 Web sites will support IPv6 and Europe will run out of IPv4 addresses.

No IPv6 Doomsday In 2012. Yes, IPv4 addresses are running out, but a Y2K-style disaster/frenzy won’t be coming in 2012. Of course there’s a chance that panic will ensue when Europe’s RIPE hands out its last IPv4 addresses this summer, but ‘most understand that they can live without having to make any major investments immediately. Despite running out of IPv4 addresses we will be able to continue to use IPv4 techniques (Asia depleted all of its IPv4 address space already April 2011). ISP’s and hosting companies will not run out of IPs. This only means that the price per IP will start to slowly grow. Forward thinking enterprises can spend the year preparing for the new IPv6 protocol (USA is expected run out of addresses next year). Comcast has said it will offer production-quality IPv6 services across its nationwide network in 2012.

Operators start to pay more attention to the business opportunity of “M2M” (machine-to-machine connections). Investment and innovation in M2M (think smart energy meters and fleet trackers for logistics) will follow.

Smart Grid technologies include smart power management and architecture system components are already hot. Smart meter deployment on the rise globally. The global power utilities are the next mega-market moving from analog, standalone systems to digital networked technology. The opportunities are huge in everything from wireless components in smart meters to giant power electronics. First cut of some very basic framework standards have been drafted and lots of works needs to be done (ensure safety!). Forward-looking utilities and such vendors have now put business units and plans in place. IPv6 is seen as a needed technology in implementing Smart Grid communications. IPV6 has become a buzz word for smart grid firms.

You Will See A Ton Of Hype Around “The Internet Of Things” article tells that “The Internet Of Things” is a catchy term revolving around the idea that most everyday objects around us will be equipped with internet-collected electronics, and this will open up new applications. You Will See A Ton Of Hype Around “The Internet Of Things”, and it is hard to say if The Internet Of Things will be a huge business or a passing fad. NXP Semiconductor’s vision of Internet of Things starts with lightbulbs. Wireless sensor networks will get attention. EE Times article Top ten Embedded Internet articles for 2011 gives you links to articles that help you to catch on those topics.

Security issues were talked about lot on 2011 and I expect the discussion will continue actively during year 2012. There are still many existing security issues to fix and new issues will come up all the time.

Hot trends for 2012

Sunday, January 1st, 2012

Generally, at the end of the year, predictions stream forth as to how this or that new technology will transform the world in the next 12 months. This article is a link collection to articles that try to do that.

2012 and the Technology Blahs article mentions few predictions: We will continue to see innovation around cost savings and information flow. There’s no stopping the momentum of consumerization of technology in 2012. Smartphone owners are increasingly paying a high price for free mobile applications, with 2012 set to be a disruptive year of widespread mobile hacking.

TechCrunch has an interesting predictions on how HTML5 and 2012 will change the web in The Definitive Guide To HTML5: 14 Predictions For 2012 article. Apart from making the whole web more interconnected between different websites, web browsers starting to look and behave more like iPad, complete with push notifications and geolocation, and HTML5 ads replacing majority of flash based ads, the article also predicts that browser makers will start to introduce App Stores within their browsers. In fact, Chrome already has one and Facebook will also get a lot more seamlessly integrated with your desktop. Marketing speak decoded:
“Push notifications” -> ads rammed up your ass
“Apps” for browsers -> pay per view content
“HTML5 ads” -> ads take over the whole screen.
“Facebook will be seamlessly integrated into the desktop” -> all your info belongs to us

If there is a way to exploit the consumer with technology, companies have ALWAYS done so. Everything you do, everything you see, everything you eat, every breath you take, every move you make… it’s worth something to someone and they will always do everything they can get away with to capitalize on it. The only areas which aren’t being exploited are either prohibited by law or new enough that they haven’t yet figured out how to best exploit.

crystalball

Late-Stage Web Companies Took In The Largest Tech Investments Of 2011. Facebook Poised to Lead Biggest U.S. Internet IPO Year Since 1999 Bubble article says that Facebook Inc. and Yelp Inc. are set to lead the biggest year for U.S. initial public offerings by Internet companies since 1999. That would be the most since $18.5 billion of IPOs in 1999, just before the dot-com bubble burst. There are companies that would like to go public, but are waiting for the right market environment to do so. The IPO market in Europe is six months behind USA.

6 Game-Changing Digital Journalism Events of 2011 article tells that after an incredible year of news events and milestones, online journalism in 2012 has a tough act to follow. We can certainly expect more successes and more failures when it comes to business models and mobile strategies. News organizations will clamor to be the first on new social networks. 2012 is a year of very new games.

SOPA opponents may go nuclear and other 2012 predictions article tells to expect an article page blackout as a way to put “maximum pressure on the U.S. government” in response to SOPA. Technically speaking, it wouldn’t be difficult to pull off. Antitrust on the rise because it tends to be far cheaper to pay lobbyists to cripple your rival than compete in the marketplace. If 2011 was the Year of the Hackers, 2012 may be the Year the Hackers Upset the Political Establishment, especially ones supporting SOPA and similar legistlation. Computer hackers plan to take the internet beyond the reach of censors by putting their own communication satellites into orbit.

Click here to find out more! Study Predicts Growing Use Of Social Media In Healthcare article tells that men are more likely than women to turn to Facebook and other social networks for healthcare purposes. Facebook was the most popular site for people searching for healthcare information, followed by YouTube. Another study says that Facebook a Factor in a Third of UK Divorces. When they say cited, they mean just that: That something from Facebook was brought up in the courtroom.

The 5 Hardest Jobs to Fill in 2012 article tells that finding a talent is in short supply, especially in these five areas: Software Engineers and Web Developers, Creative Design and User Experience, Product Management, Marketing, Analytics.

Five Things You Should Stop Doing in 2012: Responding Like a Trained Monkey, Mindless Traditions, Reading Annoying Things, Work That’s Not Worth It and Making Things More Complicated Than They Should Be. Eliminating these five activities is likely to save hundreds of hours next year. What are you going to stop doing and how are you going to leverage all that extra time?

Ethernet for Vehicles

Monday, December 19th, 2011

Ethernet for Vehicles Advances article tells that Ethernet technology in the car (a concept that was once unthinkable for the automotive industry) has been gaining momentum lately. The irony of this sudden trend is that a few years ago, Ethernet wasn’t seen as a solution to any applications in the car (one exception for this rule is that BMW cars supporting Ethernet have been on the market since 2008).

There are many existing in-vehicle technologies such as CAN, LIN, LVDS and FlexRay. Just few years ago MOST (Media Oriented Systems Transport) was seen as the de-facto standard for multimedia and infotainment networking in the automotive industry, but is has has now fallen out of favor. So now it seem to be right time for Ethernet.

ds4

A coalition of automakers and automotive suppliers said recently that they are forming a special interest group (SIG) aimed at driving broad-scale adoption of Ethernet in vehicles, largely to serve the expected boom of camera-based applications in cars. NXP and Broadcom are playing a big role in the launch of the new special interest group, known as the OPEN (One-Pair-Ether-Net) SIG. This SIG is focused on the idea of creating a single physical layer that would enable easy use of Ethernet with vehicle cameras. OPEN Alliance is designed to encourage wide scale adoption of Ethernet-based, single pair unshielded cable networks as the standard in automotive applications.

NXP said it would be the first supplier to license Broadcom’s BroadR-Reach ethernet technology (technology originally designed to extends the range of twisted pair connections from 100 meters to up to 500 meters) for in-vehicle networking. Broadcom has also introduced their Automotive Ethernet Product Portfolio. BroadR-Reach allows full-duplex operation over a single twisted pair at 100 Mbps (same type of cabling 80-110 ohms unshielded or shielded twisted pair cabling as used in FlexRay works).

connectedcar_diagram1_black

Interest in one pair Ethernet technology has grown dramatically as the automotive industry accelerates its adoption of Ethernet based networks. BMW and Hyundai have teamed up with Broadcom, NXP Semiconductors, Freescale and Harman to make ethernet the computer networking technology of choice inside the car. Infotainment systems maker Harman said that higher-bandwidth connectivity will address customers’ growing demand for seamlessly integrated information, entertainment and safety features in the car.

I have been for long time wondering why the automotive makers have been very hesitant to spec Ethernet in the past since it’s such a well-proven technology? Ethernet has gained momentum in many sectors, because it’s a fast, mature technology with high production volumes in the computer industry. Now it is the time for the auto industry is to leverage the computer industry’s enormous Ethernet know-how.

SCADA systems security issues

Wednesday, December 14th, 2011

SCADA systems are used to monitor and control critical installations in oil and gas refineries, water and power distribution plants, manufacturing plants and other industrial facilities. There has been a lot of discussion about malware and security in industrial automation systems after Stuxnet. Widely viewed as the most complex piece of computer malware ever created, Stuxnet is believed to have been designed to sabotage uranium enrichment centrifuges at the Iran’s Natanz nuclear plant. If nasty malware can do that, other similar malware can do something else nasty as well.

Attacks against SCADA systems can have potentially very serious consequences. I think that we have been quite lucky that we have not seen any big disasters yet. Even though the attacks are rare at the moment, security researchers are confident that their number will increase, especially since the Stuxnet industrial sabotage worm set a successful precedent. And now there are many news on Dugu worm.

News around one month ago told that SCADA hack shut down a US water plant at 8 November 2011. This hacking attack at a US water plant has been credited to an unknown attacker (handle “pr0f” took credit) who according to hacker sources managed to access a SCADA controller and take over systems. Once again caused security experts to question the security of SCADA systems. Hacker Says Texas Town Used Three Character Password To Secure Internet Facing SCADA System. “This was barely a hack. A child who knows how the HMI that comes with Simatic works could have accomplished this,” he wrote. “You know. Insanely stupid. I dislike, immensely, how the DHS tend to downplay how absolutely (expletive) the state of national infrastructure is. I’ve also seen various people doubt the possibility an attack like this could be done,” he wrote in a note on the file sharing Web site pastebin.com. On the other hand Federal officials said there’s no evidence to support a report that hackers destroyed a pump used by an Illinois-based water utility after gaining unauthorized access to the computer system it used to operate its machinery. What is the truth in this case it is hard to say.

What is known that many industrial systems are vulnerable. Siemens Simatic is a common SCADA product and has been the subject of other warnings from security researchers according to Siemens industrial control systems are vulnerable to attack that can cause serious problems. The US Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) warned earlier that Siemens’ SIMATIC S7-1200 programmable logic controllers (PLCs) are vulnerable to so-called replay attacks that can interfere with the normal operations. An attacker with access to the PLC or the automation network could intercept the PLC password and make unauthorized changes to the PLC operation. ISO-TSAP protocol is functioning to specifications; however, authentication is not performed nor are payloads encrypted or obfuscated.

White Paper On Industrial Automation Security In Fieldbus And Field Device Level is an interesting white paper (from Vacon, Nixu and F-secure) that focuses on presenting a generic overview about security in industrial automation. Security aspects of traditional fieldbuses, Ethernet-based networks and wireless communication technologies are presented. Challenges regarding data security in the field of industrial automation are discussed. The properties of industrial automation devices are described with a focus on security, tampering possibilities, and risk mitigation methods.

Many protocols used in industrial control systems were intentionally designed to be open and without security features. As long the the networks that run those protocols are kept physically separate from public network you are quite safe. For the most part SCADA systems are not necessarily designed to be connected to the internet, but engineers can put in workarounds for remote access. Anytime you do this you put in a pathway where someone can get in. And there are often case where remote devices are accessed using those non-secure protocols though unsafe networks (public telephone network, cellular network, radio waves, even Internet).

There has been long time the belief that SCADA systems have the benefit of security through the use of specialized protocols and proprietary interfaces (security through obscurity), networks are physically secured and disconnected from the Internet. Today those beliefs all do not hold anymore. There are nowadays you can find many tools on Internet to work with standard SCADA protocols (for example Wireshark can be used to decode several commonly used SCADA protocols).

The move from proprietary technologies to more standardized and open solutions together with the increased number of connections between SCADA systems and office networks and the Internet has made them more vulnerable to attacks. Modern SCADA systems should be designed so that they can be withstand the situation they are accidentally connected to Internet (it will happen sooner or later). In addition to making SCADA system itself secure, you should separate it from Internet (no connection at all or very strictly configured series of firewalls). FACT CHECK: SCADA Systems Are Online Now article tells at nearly everything is connected now. Nearly all SCADA systems are online. The addition of a simple NAT device is far from bulletproof security access control.

Most of SCADA systems in use are are old computer systems. They are usually horribly patched (”if it ain’t broken, don’t fix it”) and often run very old operating system version. Windows is very commonly used operating systems on SCADA applications, because only few SCADA-packages support other than Windows operational systems. It seems that there are many people who are not happy with the security stance being taken within their organizations around SCADA hosts. Even if you have patches up to date and current anti-malware on a host, all you have done is eliminated some of the risk (and maybe created new risks caused by fact that anti-malware software can sometimes disturb normal system operation). Add a firewall and you have reduced some of the risk. Pile on as much security as you want and people are going to find ways to disable it and make themselves vulnerable.

I wish no one had to worry about hackers in any application, but we do. Unfortunately, data security is never a non-issue.

FACT CHECK: SCADA Systems Are Online Now article mentions an interesting story on Boeing 747 (For those who do not know, modern 747’s are big flying Unix hosts with lots of Ethernet). They had added a new video system that ran over IP. They segregated this from the control systems using layer 2 – VLANs. The security researchers managed to break the VLANs and access other systems (including Engine management systems). The issue here is that all that separated the engine control systems and the open network was VLAN and NAT based filters.

How Much Does The Internet Weigh

Tuesday, November 29th, 2011

How heavy is the internet? Information on the internet such as e-mails, documents, video clips, Web pages, are represented in binary digits, 1s and 0s. How Much Does The Internet Weigh video gives you some idea of the wight of the information on the Internet.


hd film izle korku filmleri film izle hd film izle