Wednesday, 14 January 2015

Big names like Google dominate open-source funding

Companies can get plenty of bang for not many bucks via open-source sponsorship.

Network World’s analysis of publicly listed sponsors of 36 prominent open-source non-profits and foundations reveals that the lion’s share of financial support for open-source groups comes from a familiar set of names.

We found 673 companies on the donor rolls of our list of organizations – which was drawn heavily, though not entirely, from the Open Source Initiative’s list of affiliates.

Google was the biggest supporter of open-source organizations by our count, appearing on the sponsor lists of eight of the 36 groups we analyzed. Four companies – Canonical, SUSE, HP and VMware – supported five groups each, and seven others supported four. (Nokia, Oracle, Cisco, IBM, Dell, Intel and NEC.) For its part, Red Hat supports three groups – the Linux Foundation, Creative Commons and the Open Virtualization Alliance.

It’s tough to get more than a general sense of how much money gets contributed to which foundations by which companies – suffice it to say, however, that the numbers aren’t large by the standards of the big contributors. According to Pro Publica’s non-profit records, the average annual revenue for the open-source organizations considered in our analysis was $4.36 million, and that number was skewed by the $27 million taken in by the Wikimedia Foundation (whose interests range far beyond open-source software development) and the $17 million posted by the

Linux Foundation.

Split between, say, half a dozen companies, and even the Linux Foundation doesn’t look too hard to fund. What’s $2.83 million a year to Intel? The non-hypothetical, real-world price tag is actually lower, as it turns out – the foundation said that it charges $500,000 per year for platinum membership, $100,000 a year for gold, and anywhere from $5,000 to $50,000 for silver, depending on the size of the company.

It should be pointed out that this is still far from a complete picture – we used the most recent numbers available, but those were frequently from as long ago as 2011, and this doesn’t account for the many overseas groups and others not covered by the database – but it does suggest that, to a company like Google, even relatively major donations barely make a dent in the bottom line.

Another thing keeping the picture incomplete was a reluctance by some of the bigger companies to speak to us on the subject of their activities within the open-source community. We got only boilerplate responses back from two companies, and from list-topping Google, no response at all.
So what do they get out of it?

In the main, companies that support open-source nonprofits get brownie points – your developers can work on a project without the company joining an official foundation (and, importantly, vice versa), so the benefits of direct participation in a project aren’t necessarily related to the non-profit angle.

But those brownie points are far from valueless. All those services provided by non-profits are important to lots of people in the open-source community. Tejun Heo, a prominent kernel developer and Red Hat employee, gave the example of a hobbyist developer attending one of the many conferences on open-source held every year.

“A sponsoring company … would have a lot easier time getting acquainted with the person, and he or she would be a lot more likely to be familiar with and have a positive impression of the company,” he said.

A lot of that goodwill, Heo added, has to do with the job market – sponsorship can make companies more attractive to potentially valuable developers, while keeping them in the loop on individual projects.

“Even if it doesn’t directly result in hiring, the wider contact surface ensures that Red Hat at least can stay in contact with what’s going on in terms of both technical and human resources aspects of the project,” he said.

More even than that, companies like Red Hat employ a lot of people that are just big fans of open-source in the first place, according to Heo.

Of course, some see hints of whitewash in the movement of big tech companies toward the open-source world’s nonprofits. It’s important to note that support for those organizations doesn’t necessarily translate into actual code contributions to open-source projects.

A look at the most recent edition of the Linux Foundation’s “Who Writes Linux” publication, which covers 2013, found that Red Hat was the largest corporate contributor of code to the Linux kernel, at 10.2% of the total. Close behind is Intel, at 8.8%. So far, that tallies with the list of open-source organizations sponsored, but the similarities partially fall away from there – the two next-biggest code contributors were Texas Instruments and Linaro, both of which are supporters of just one organization, the Linux Foundation.

Obviously, this doesn’t prove much on its own – it’s tough to directly compare code contributions and sponsorship, and it doesn’t account for work done on any other projects besides the kernel. But the discrepancy is noteworthy in several cases. Google, for example, contributed less than a quarter of the kernel code that Red Hat did.

Jay Lyman, an analyst with 451 Research, highlighted both positive and negative attributes to corporate sponsorship in open source.

“[Participation] is good in the sense that organizations are focused on real benefits and results, but it could make it easier for those seeking to leverage open-source communities without participating or contributing,” he said.

What do foundations do?

So what do foundations do? In the case of major organizations like the Linux Foundation, it seems almost easier to ask what they don’t do.

The group has a legal defense fund, patent commons, trademark management program, workgroups for several technical focus areas like SDN and accessibility and lots more – not to mention the basic development and testing infrastructure that enables Linux development.

“And we’ll throw in a subscription to Outside Magazine, and a wind-up radio,” jokes Jim Zemlin, the group’s executive director.

Not every non-profit’s operations are so extensive, of course – many provide not much more than training, advocacy and/or a basic organization and collaboration framework for smaller projects, or for geographically clustered groups of open-source developers. But the principle is the same.

One other unique facet to the Linux Foundation’s activities is the group’s direct employment of Linus Torvalds – final arbiter over all things Linux kernel and probably the most powerful person in open-source – helps avoid allegations of bias over the direction of the project – which is an issue, though not as contentious as one might suppose, given the fact that many of the most active code contributors to Linux are employed by some of the same companies that underwrite the non-profit.

Tejun Heo said that there’s “no tension at all” between his employer and the broader kernel community.

“If I think something is a technically better direction, that’s the direction I follow. Even when that mismatches with what Red Hat internal engineering was expecting,” he said.

“Somebody once told me that [Red Hat] is a company where a bunch of open-source engineers hired management and marketing people to run the boring, money side of things so that they can continue to do whatever they like, and while it’s a bit of an exaggeration I think there’s a certain amount of truth to that,” he noted.


Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Monday, 5 January 2015

2015 11 predictions for security

It’s tough to know what the security landscape will look like in six months, never mind a year. But that doesn’t mean it’s not worth trying.

Predictions for 2015
In the world of business, correctly seeing the future even a few months out can provide a leg up on the competition or, in the case of cybersecurity, on ever-present attackers. A missed guess can leave one scrambling to catch up.

So, here are some predictions for 2015 on security from research firms Gartner and Forrester Research, and from Arthur W. Coviello Jr., executive chairman of RSA.

Nation states vs. private sector
(Coviello) Nation-state cyber-attacks will continue to evolve and accelerate but the damage will be increasingly borne by the private sector.

“With no one actively working on the development of acceptable norms of digital behavior … we can expect this covert digital warfare to continue,” Coviello said. And it will increasingly be private sector firms that will be, “the intended victim or the unwitting pawn in an attack on other companies.”

The rise of integrated threat intelligence
(Gartner) Internet of Things (IoT) device revenue growth of almost 30% will create new vulnerabilities and security demands relating to both physical and digital environments. The expected convergence of IoT security and information security technologies, along with increased regulatory activity directed at protecting critical infrastructure, will drive demand for integrated threat intelligence capabilities, including IoT-related threat data feeds.

More money, much more scrutiny
(Forrester) Security budgets will see double-digit growth in sectors outside of banking and the defense industrial base.

The downside to those increases will be an enormous amount of scrutiny and much higher expectations, not just from business leaders and counterparts in technology management, but also from customers, government agencies, and privacy watchdog groups.

The quest for a uniform threat language
(Gartner) The drive toward a common framework adopting a uniform language, such as Structured Threat Information Expression, will accelerate as a result of the complexity and challenges brought by the need to integrate IoT security data inputs for indicator of compromise (IOC) detection.

Pragmatic privacy
(Coviello) A maturing privacy debate will become more pragmatic and balanced. Prospects for responsible privacy policies and intelligence sharing legislation that would better protect our privacy may improve. One test of this prediction will be the outcome of the EU General Data Protection Regulation, which may reach a final form in 2015.

More billions of things, more billions of risks
(Gartner) 4.9 billion connected things will be in use in 2015, up 30% from 2014, creating disruption, continued opportunities and continued risk.

“Organizations must straddle the tension of all the information available from smart things by balancing their desire to collect and analyze it with the risk of its loss or misuse,” according to Steve Prentice, vice president and Gartner Fellow.

Find the breach, botch the response
(Forrester) With new investments in breach detection, a large majority of companies (60%) will discover a breach, or more likely be informed of it by a third party like a government agency, security blogger or a customer.

But they will likely botch the response, given that only 21% of enterprises report that improving incident response is a critical priority. That means more cases of customers’ trust undermined or corporate reputations dragged through the mud.

Unhealthy exposure
(Coviello) While retail will remain an ongoing target, well-organized cyber criminals will increasingly turn their attention to stealing PHI – personal health information. It is not as well secured, is very lucrative to monetize in the cybercrime economy, and is largely held by organizations without the means to defend against sophisticated attacks – healthcare providers.

Competing on privacy
(Forrester) Privacy will be a competitive differentiator, not just through lip service, but action – appropriate privacy policies, enforcement and building privacy considerations into business operations and the products or services offered to customers.

That will require the leadership of a privacy champion – a Chief Privacy Officer, Data Protection Officer, or privacy professional. Today, about a third of security decision-makers in North America and Europe view privacy as a competitive differentiator. That will increase to half by the end of 2015.

The essential, more secure, mobile payment option
(Gartner) A renewed interest in mobile payment will arise, together with a significant increase in mobile commerce, due in part to the increased security features of Apple Pay and similar near-field communication (NFC) efforts by competitors such as Google.

As device manufacturers and application developers improve usability and functionality and address users' security concerns, devices will become even more of an essential tool for customers, particularly the younger demographics.

Beware the Botnet of Things
(Coviello) The increase of machine-to-human and machine-to-machine interaction will only exacerbate the situation described in a tweet this past year as: “Who needs zero days when you’ve got stupid?” Get ready for the Botnet of Things. This trend along with the strong growth of IoT in the healthcare sector and the accompanying risks to PHI, has ominous implications.



Best Microsoft MCTS Training – Microsoft MCITP Training at Certkingdom.com

Tuesday, 23 December 2014

Cool Yule Tools: Best techie gifts for 2014

The National Santa Agency has a handle on what everyone wants.


Our motto: “He Sees You When You’re Sleeping, He Knows When You’re Awake…”
After months of investigations, cups of coffee and several arm-twisting interrogation tactics, the Cool Yule Tools staff of writers and editors has discovered a shocking truth. The government group that has allegedly been spying on us, known as the “NSA”, is actually a cover group for a little-known organization with headquarters near the North Pole. Yes, we are speaking of the National Santa Agency. (See full writeups on these products.)

Thanks to our "Special Agents" who contributed reviews: Keith Shaw, Craig Mathias, Neal Weinberg, Abigail Weinberg, Ken Mingis and Tom Lupien.

Phones, computers and other mobile goodies
A large majority of the subjects we were monitoring were VERY interested in acquiring a new mobile device, whether it was a new laptop, phone or tablet. But we think they'll be quite happy with these reviewed devices.

Apple iPhone 6 Plus
$299 for the 16GB model with 2-year contract; $749, contract-free

The iPhone 6 Plus represents the epitome of Apple's phone line, but if you're thinking of getting one as a gift, make sure your gift recipient can handle it. Literally. With a 5.5-in. "Retina HD" screen, this is one big phone -- the biggest Apple's ever made and its first foray into the phablet market.

As you'd expect from an Apple device, the design and engineering are top rate, and the screen is pixel packed, with 401 pixels per inch. That means everything is razor sharp, colorful and bright. It's easily the best iPhone display Apple has produced.

Kyocera Brigadier smartphone
Price: $49.99 with two-year agreement, plus data plan

The Brigadier by Kyocera runs on Verizon’s 4G LTE network, and can take any kind of abuse you can dish out. We dunked it in water, dropped it on a hardwood floor, scraped the screen with a sharp knife. And nothing, not even a scratch.

Lenovo Horizon 2 Tabletop PC
$1,500 (our test unit, available via Best Buy)
When you lay this giant 27-inch computer flat on a table, the first thing people may think is that you somehow got your hands on the iPhone 7 Plus (a really really really big phablet). But in reality, it’s still a Windows 8.1 PC, but one with a touchscreen that multiple people can interact with. The Aura interface that overlays the Windows PC to provide the tabletop mode lets multiple people pinch, expand, shrink and move objects around on the touchscreen. While you can collaborate with co-workers via this method (looking at photos, or watching videos, for example), the majority of your time spent with this machine will be spent playing games.

Logitech k480 Multi-Device Keyboard
$49.99
You’re most likely to need/want a Bluetooth external keyboard when you acquire a tablet, but plenty of other devices (such as your smartphone and notebook) have Bluetooth as well, so it’s nice to have a single keyboard that can connect to multiple devices.

Logitech achieves this with its k480, a small, portable keyboard that includes a dial that switches between up to three devices, across multiple operating systems. If you want to connect a Windows PC, Android smartphone and Apple iPad, just turn the dial associated with each of those devices (it’s up to you to remember which device goes with each setting on your dial). The keyboard quickly and easily makes the Bluetooth connection to those devices. (See full review here).

Lenovo Y50
Starts at $1,089
I’ve been in the Mac camp for about three years now, about the same amount of time that Windows 8 has been out. But if I were ever considering coming back to the world of Windows, it would definitely be with this machine – the Lenovo Y50. The latest systems include fourth-generation Intel Core processors, a brilliant 15.6-inch full HD displays (touch-enabled, too), JBL speakers and a very cool backlit keyboard. I’m even coming around on Windows 8.1, if only a little bit (the return of the Start menu and easier access to the desktop definitely helps). (See full review here).

Lenovo N20p Chromebook
$329.99 (as tested)
Chromebooks have been out for a few years now, so the rough edges from earlier models have smoothed out, and Google seems to be doing a pretty good job at filling in the blanks of things that were missing from the operating system (remember, Chromebooks don’t use a traditional operating system like Windows or MacOS). You have to be invested in the Google universe, which means email will be done through Gmail, your browser will be Google Chrome, your productivity applications will be done through Google Drive (Docs, spreadsheets, presentations, etc.), and your music will be located on Google Play Music, etc. In fact, you might want to ask your friend, family or co-worker how comfortable they are with all of these Google offerings - if so, then it’s a definite recommend. (See full review here.)

Macally Quick Switch Bluetooth Keyboard
$69.99
It may seem like overkill to think that you would need one keyboard that quickly switches for use with five different devices, but you could find yourself in a scenario with two computers, a phone, a tablet and then you’re already up to four right there. Even if you don’t need five devices, it’s still a very cool option to have this functionality. In fact, you can connect a sixth device via the included USB cable, which is like Spinal Tap going to 11.

The keyboard itself is a full-sized keyboard with a very light touch and feel - it’s so light that you could carry it with you if you had a big enough laptop bag (it’s the width, not the weight that would be limiting).

REPORT #2: Audio Entertainment (Headphones, Music, Speakers)
After mobile devices, the next most popular item on holiday wish lists focus around musical entertainment. Whether speakers or headphones, we think these items will look great under the tree (or on your head).

Blue Mo-Fi headphones
$350
At first glance, the Mo-Fi headphones from Blue appear to be so large you'd never want to be seen in public with them. The headphones are big – very big compared with other headphones we’ve seen. They’re heavier, too. But the reasons for that will likely cause you to veto any concerns you may have. The extra weight and design are due to a built in audiophile amplifier and “ultra-premium drivers”, which give high-fidelity sounds to multiple devices – whether you’re listening on your phone, tablet, computer or even higher end A/V systems. Sure, this adds some extra weight, and you might get some odd looks while wearing these on your flight. But deal with it, you’ll enjoy the awesome sound compared to your seatmates listening on other headphones.
(See a full writeup of this product.)

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Wednesday, 10 December 2014

11 Cyber Monday tech deals that truly save you serious money

Real deals, not cyber scams
If you want to see how morally bankrupt the post-Thanksgiving shopping season has become, just poke around online during “Cyber Monday.” You'll find many of our nation's major retailers marking up their list prices to advertise “savings” that don't actually exist, and pushing “limited-time” offers that are readily available elsewhere. But worry not; we've dug through these borderline scams to find 11 deals you should actually know about.

Motorola.com: Unlocked Moto X for $140 off
The 2014 Moto X is one of our favorite Android phones. You can customize it with different colors and textures (including real leather and wood), and it bucks the bloatware trend among Android handsets. Motorola's also good about updating its software—the Moto X is already running Android 5.0 Lollipop. The $140 discount starts Monday at 12 noon Eastern time.

Why it's a good deal: The discounted base price of $360 is killer for an unlocked “hero” phone, and AT&T or T-Mobile will give a discount on wireless service. [Link]

Best Buy: LG G3 for $1 on-contract
The LG G3 was this year's sleeper hit among Android phones, and unquestionably the one to get if you value camera quality above all else. With laser-assisted auto-focus, the G3 lines up shots quickly and excels in low light, so you rarely have to call for a do-over.

Why it's a good deal: Most carriers are still selling the G3 for its sticker price of $199 on contract. While that price will probably fall as the new year rolls around, it doesn't get any better than a buck right now. [Link]

Microsoft Store: Acer Aspire E15 for $399
The Aspire E15 is a run-of-the-mill budget notebook, with an Intel Core i5 processor, 4GB of RAM, a 500GB hard drive and a built-in DVD player. But because it comes from the Microsoft Store, it has none of the trialware and bloatware that comes standard on laptops from other major retailers. That alone makes it worth a look.

Why it's a good deal: This is one of the rare Cyber Monday laptop deals that packs Intel Core i5 power for $400. Just don't expect miracles from the display and build quality. [Link]

Newegg: Samsung 500GB SSD with Far Cry 4 for $180
With many new PC games gobbling gigabytes by the dozen, you're going to need a roomy solid state drive to run them at top speeds. Samsung's 840 EVO SSD has a whopping 500GB of storage and respectable read/write speeds of 540Mbps and 520Mbps, respectively. There's also a handy transfer tool for upgrading from a smaller drive.

Why it's a good deal: Newegg has a bunch of storage deals right now (including a $50, 128GB SSD from Sandisk) but $180 is darned cheap for a 500GB drive. The free copy of Far Cry 4 (normally $60) is the cherry on top for your new PC gaming rig. [Link]

Walmart: PlayStation 4 bundle for $449
Console bundles are everywhere this holiday season, but Walmart's $449 bundle will be hard to beat, especially for families. It includes the PlayStation 4 console, LittleBigPlanet 3, Lego Batman 3, your choice of another game, and a second controller.

Why it's a good deal : The PS4 normally costs $400, and most other holiday bundles are throwing in a game or two for free. This bundle has three games and an extra controller, so you're getting about $120 in value over other deals. [Link]

MacMall: 13-inch MacBook Pro with Retina Display for $1,030
Apple's current MacBook Pros are over a year old now, but they're still among the best professional-grade laptops you can buy. The discounted model has a dual-core Intel Core i5 processor, 4GB of RAM and 128GB of solid state storage, and it lasted nearly 11 hours in Macworld's battery test.

Why it's a good deal: You rarely see Apple products discounted by more than $100 on Black Friday or Cyber Monday, but MacMall's MacBook Pro deal manages to be $270 off the sticker price. [Link]

Google Play: LG G Watch for $99, $50 of Store credit
The LG G Watch, one of the first wave of Android Wear smartwatches, was quickly upstaged by classier-looking wearables such as the Moto 360 and LG's own G Watch R. Still, it does a decent job of showcasing how Android Wear works, and it's practically an impulse buy for the curious at $99.

Why it's a good deal : The $50 credit toward apps, videos and games from the Google Play Store effectively halves the G Watch's price if you were planning to buy some content anyway. You can still get the $50 credit when paying full price for a G Watch R, Asus Zenwatch, Samsung Gear Live, Sony SmartWatch 3 or Nexus 9 tablet. [Link]

B&H: iMac with Retina Display for $2,299
Apple's iMac with Retina Display is a fine piece of machinery, packing 14.7 million pixels into its 27-inch “5K” panel. B&H is knocking $200 off the base model, which includes a 3.5GHz quad-core Intel Core i5 processor, 8GB of RAM and 1TB of fusion drive storage.

Why it's a good deal: You don't often see big discounts on Apple products, especially brand-new ones. B&H's discount doesn't make the Retina display iMac cheap by any means—rather, a slightly easier splurge. [Link]

Microsoft Store: $100 to $150 off the Surface Pro 3
The Surface Pro 3 is a shining example of what a high-end Windows machine can be, weighing as little as an 11-inch MacBook Air but with a taller, higher-res touchscreen. Detach the keyboard cover, and you have a 1.7-pound tablet with a pen for sketching and a kickstand. Microsoft is knocking $100 off the price for Core i5 models, and $150 off for Core i7 models.

Why it's a good deal: The discount brings the base price to $1,030 with 128GB of storage and 4GB of RAM. That's just $30 more than a 13-inch MacBook Pro with similar specs. If you missed the same deal on Black Friday, now's the time to pull the trigger. [Link]

Staples: Acer Chromebook for $150
Like all other Chromebooks, this one can't run traditional Windows software such as Office and iTunes. But Acer's CB3-111-C670 Chromebook gets you online with a full mouse and keyboard at your disposal. It has an 11.6-inch, 1366x768 display, Celeron processor and 2GB of RAM, which should be all you need for basic browsing.

Why it's a good deal: Normally, Asus' competing 11-inch Chromebook is the slightly better buy, but these are two very similar machines. The $50 discount on the Acer is just enough to give it the edge. [Link]

Dell: 22-inch 1080p monitor for $99
The holiday shopping season can be a good time to upgrade aging computer monitors, and Dell's deal in particular is worth a look. The S2240L on sale for $99 has a 21.5-inch display, narrow bezels and a choice of VGA or HDMI input. The screen also tilts from 5 degrees down to 21 degrees up.

Why it's a good deal: You don't typically see 22-inch monitors of decent quality cracking the $100 barrier, so multi-monitor users may want to think about stocking up. You'll have to move quickly, though, as Dell says it will have limited quantities starting at 8 a.m. Eastern. [Link]

Thursday, 27 November 2014

Mozilla unveils search tool tweaks in next week's Firefox 34

New tools will accompany change from Google to Yahoo as default search engine for U.S. customers

Along with its impending switch to Yahoo as the default search engine for Firefox, Mozilla will also change how users conduct searches in the browser, the company said Tuesday.

Searches done in the next version of Firefox will display not only a list of suggested searches that narrow the results, but will show buttons for search engines other than the default, said Philipp Sackl, a lead designer of Firefox, in a blog post yesterday.

"These buttons allow you to find your search term directly on a specific site quickly and easily," Sackl wrote.

For example, a search for "US Grant" started in Firefox's default search engine can be switched to Wikipedia for results there by clicking a button.

Mozilla has implemented the changes in the beta of Firefox 34, which is scheduled for promotion to the finished, polished build next week. In the beta, Firefox 34 shows search-switch buttons for all available providers, including Bing, DuckDuckGo, Twitter and Wikipedia. Users can also add additional search engines.

Other browsers, such as Google's Chrome and Apple's Safari, lack similar tools, although Safari does offer a short list of suggested searches when a string is typed into its address bar.

Mozilla will introduce the search tweaks next week when it ships the production version of Firefox 34, currently slated for a Dec. 1 release. At the same time, Mozilla will also introduce Yahoo as the default search engine in the U.S.

"Under a new five-year strategic partnership ... Yahoo Search will become the default search experience for Firefox in the U.S.," Mozilla CEO Chris Beard said last week.

Beard's description implied that Mozilla will automatically change the default search engine within Firefox from the earlier Google to Yahoo for all U.S. customers. But in the beta of Firefox 34 the previous default -- Google -- remained in place.

Mozilla may face resistance from existing users if it changes the search engine to Yahoo without their permission when Firefox updates itself next week. Firefox users will be able to change the default to another provider, including back to Google, however.

Mozilla did not immediately reply to questions about how it will handle the change from Google to Yahoo within Firefox.

Firefox, unlike its browser rivals, will continue to use separate search and address bars rather than unify them into one field where users can type not only URLs but also search strings. Safari, Chrome and Microsoft's Internet Explorer (IE) all offer a unified address-search bar.

"That has been looked at several times, but there are difficult privacy problems to overcome if you also want to provide search suggestions," said Gervase Markham of Mozilla in an answer Wednesday to a user's comment appended to Sackl's post. "If someone is typing a URL, they don't necessarily want their default search engine to know where they are going. And yet, if you want to provide search suggestions well, you have to send every keystroke in a unified box to the search provider."


Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Tuesday, 11 November 2014

BYOD forces users' personal information on help desk

Help desk staffers can be caught in the middle when BYOD users get verrrry personal with their devices.

As the recent scandal over leaked celebrity photographs reminded us all, people use their electronic devices for very personal pursuits in the era of smartphone ubiquity. Depending on the age and inclination of its owner, a modern-day digital device might contain not just nude selfies like those that were shared online, but images from dating sites like Tinder and Grindr, creepshots, or other salacious or even illegal material downloaded from the backwaters of "the dark Web" via anonymizers like Tor.

As blogger Kashmir Hill summed up as the selfie scandal was unfolding, "Phones have become sex toys."

If that's true, then those toys are making their way into the workplace in record numbers, thanks to the ever-increasing number of organizations adopting bring-your-own-device (BYOD) policies.

In a perfect world, none of this should concern help desk employees -- with a well-executed mobile management program in place that incorporates containerization, a technician ought to be able to assist employees with corporate apps and data without encountering so much as a pixel of not-safe-for-work (NSFW) material.

But the world isn't always perfect, as IT support staffers know perhaps more than most. Which means they can find themselves looking not just at enterprise applications but at private images and texts they'd really rather not see. Or politely pointing out to an employee who's synced all her devices to the cloud that pictures from her honeymoon are currently being displayed on the conference room's smartboard. Or repeatedly removing viruses picked up by the same users visiting the same porn sites.

The scope of the problem

In a survey published last year by software vendor ThreatTrack Security, 40% of tech support employees said they'd been called in to remove malware from the computer or other device of a senior executive, specifically malware that came from infected porn sites. Thirty-three percent said they had to remove malware caused by a malicious app the executive installed. Computerworld checked with several security experts, none of whom was particularly surprised by that statistic.

The ThreatTrack survey didn't tease out how much of this was on BYODs. But in a February 2014 survey by consulting firm ITIC and security training company KnowBe4, 34% of survey participants said they either "have no way of knowing" or "do not require" end users to inform them when there is a security issue with employee-owned hardware. Some 50% of organizations surveyed acknowledged that their corporate and employee-owned BYOD and mobile devices could have been hacked without their knowledge in the last 12 months. "BYOD has become a big potential black hole for a lot of companies," says Laura DiDio, ITIC principal analyst.

One big concern: As McAfee Labs warns in its 2014 Threat Predictions report, "Attacks on mobile devices will also target enterprise infrastructure. These attacks will be enabled by the now ubiquitous bring-your-own-device phenomenon coupled with the relative immaturity of mobile security technology. Users who unwittingly download malware will in turn introduce malware inside the corporate perimeter that is designed to exfiltrate confidential data."

Today's malware from porn sites is usually not the kind of spyware that's dangerous to enterprises, says Carlos Castillo, mobile and malware researcher at McAfee Labs -- but that could change. "Perhaps in the future, because of the great adoption of BYOD and people using their devices on corporate networks, malware authors could . . . try to target corporate information," he says.

In fact, a proof-of-concept application was recently leaked that is designed to target corporate data from secure email clients, Castillo says. The software used an exploit to obtain root privileges on the device to steal emails from a popular corporate email client, alongside other spyware exploits like stealing SMS messages. "While we still have not seen malware from porn sites that is dangerous to enterprises," Castillo says, "this leaked application could motivate malware authors to use the same techniques using malicious applications potentially being distributed via these [porn] sites."

Beyond security, there could be legal liabilities in play as well, some analysts caution. For example, a corporation might be liable if an IT staffer saw evidence of child porn on a phone.

To be sure, porn sites cause only a small fraction of the problems that users introduce into the enterprise. According to Chester Wisniewski, senior security advisor at Sophos, some 82% of infected sites are not suspicious places like porn sites, but rather sites that appear benign. And for smartphones, the biggest malware danger is from unsanctioned apps, not NSFW sites, he says.

Roy Atkinson, a senior analyst at HDI, a professional association and certification body for the technical service and support industry, sees no evidence of a widespread problem. When he specifically asked a couple of IT professionals who are responsible for mobile management in their organization, "they told me either 'we don't see it' or 'we make believe we don't see it,'" says Atkinson. "People don't really want to think about this or talk about it much."

Escalate or let it go?

Whatever the frequency, when and if NSFW issues do arise, the IT department often winds up functioning as a "first responder" that has to decide whether to escalate the incident or let it go. "If somebody complains about [a co-worker] displaying pictures on their smartphone at a meeting . . . then the company's acceptable use policy will come into play," says Atkinson. Or if IT employees find malware that came from a porn site and could endanger the network, they may say something -- to the employee or to a manager. "But as we know, policies are enforced somewhat arbitrarily," Atkinson says.

Barry Thompson, network services manager at ENE Systems, a $37-million energy management and HVAC controls company in Canton, Mass., says he has seen problems increase because of what he calls "bring your own connection." People assume "that it's their personal phone so they can do as they like," he says. But they are using the office Wi-Fi network, which Thompson monitors. He can see every graphic that passes through the network. "If I notice pictures of naked people, I can click on it and find out who's looking at that," he says. When that happens, Thompson usually gives a warning on first offense. If it happens again, he brings in the employee's supervisor.

It's like the Wild West out there if it's the employee's own device. -- Dipto Chakravarty, ThreatTrack Security

"It's like the Wild West out there if it's the employee's own device," says Dipto Chakravarty, executive vice president of engineering and products at ThreatTrack Security. Companies have a hard time enforcing their policies on BYOD devices, because it is, after all, the employee's device.

Often, the "old boy network" kicks in. The user "is petrified that IT will see all these bad sites that the user has visited," says Chakravarty. Employees admit they made a mistake and ask IT to please ignore the material. "IT doesn't really want to see the dirty laundry, so they say, 'Hey, no problem. I'll just wipe it clean and you're good to go,'" he says. "That's the norm."

The tendency to "cover for your buddies -- guys have been doing that for time immemorial," says Robert Weiss, senior vice president of clinical development with Elements Behavioral Health and a sex addiction expert. But there are social and ethical concerns for both the employee and for IT, says Weiss, co-author of the 2014 book, Closer Together, Further Apart: The Effect of Digital Technology on Parenting, Work and Relationships.

What happens, asks Weiss, when IT sees photos of naked children on someone's phone, which could be child porn, or repeatedly removes malware from porn sites from the same user's device, which could indicate an addiction? IT staffers are typically not well equipped to address criminal or addictive behaviors.

Weiss thinks there should be clear policies that indicate when IT needs to report such information to human resources, similar to policies about repeated drinking or signs of other addictions, and let HR take it from there. "The IT person should not be involved," he says. "I would not want to put the IT person in the position of having to talk about sex with an employee that they don't particularly know well."
I would not want to put the IT person in the position of having to talk about sex with an employee that they don't know well. -- Robert Weiss, Elements Behavioral Health

At least one technical analyst, who has worked in IT support at a range of companies, thinks reporting such users to HR is taking it too far. Flagging child pornography is one thing, he says, but addiction? "I'm not going to HR about BYOD riddled with porn. It's their device. As much as I love helping people, their personal porn habits, even at an addiction level, are not my problem. Unless it's criminal, I don't care."

Protecting IT from users

The ideal fix is to create a corporate container to hold all business applications, including corporate email and Internet browsing.

And the best way to achieve that goal is with the emerging class of enterprise mobility management (EMM) technology, says Eric Ahlm, a research director at Gartner. "When properly configured, EMM solutions create a corporate container that provides OS-level security and isolates apps and data in the container from what's outside," explains Ahlm. The corporate container can encompass email applications, Web browsers, customer mobile applications and off-the-shelf mobile applications. Within that container, IT can create isolated data-sharing and -protection policies, or easily deploy more mobile apps, or remove them -- all without touching the personal information outside of the container, he explains. "It makes all those issues go away."

On the personnel management side of the equation, companies should be sure to update their acceptable use policies to include BYOD. ENE's Thompson found that his company's acceptable use policy did not mention personally owned devices. So last year, says Thompson, ENE amended the policy to specify that "any use of corporate resources or systems, regardless of ownership of the devices, obligates the user to comply with the corporate acceptable use policy."

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Monday, 27 October 2014

Microsoft's Surface turns first profit in 2 years

But gross margins -- between 9% and 13% -- aren't sufficient to sustain a profitable business

After two years and nearly $2 billion in losses, Microsoft's Surface turned a profit in the September quarter, the company said Thursday.

For the three months ending Sept. 30, Microsoft recorded $908 million in revenue for the Surface tablet line, an increase of 127% over the same quarter in 2013. The nearly one billion in revenue was a one-quarter record for the Surface, and beat the combined revenue of the previous two quarters.

Using information in Microsoft's filing with the U.S. Securities and Exchange Commission (SEC), as well as data from earlier quarters, Computerworld calculated the quarter's cost of that revenue at $786 million, leaving a gross margin of $122 million. Cost of revenue is the cost to make and sell a product, but excludes expenses such as advertising and R&D.

Microsoft said that the Surface line posted a positive gross margin -- implying that outside estimates of prior losses were correct -- but did not disclose a dollar figure.

According to Computerworld's estimate, the margin was small, about 13.4%. That's more than the average for a Windows personal computer, but less than half or a third of the margins on tablets like Apple's iPad.

It was even smaller by the figuring of Jan Dawson, principal analyst at Jackdaw Research, who has also used Microsoft's SEC filings to estimate the Surface's cost of revenue. He pegged the September quarter's cost of revenue at $825 million, the gross margin at $83 million, and the margin rate at just 9.1%.

"That's a gross margin ... which is not earth-shattering and in fact about half the gross margin of the phone business at Microsoft. But it's progress," Dawson wrote on his blog, where he published his analysis of Surface's financial performance.

Indeed.
Since its October 2012 introduction, Surface has been a money pit for Microsoft, in the hole to the tune of $1.73 billion through its first seven quarters. With the September quarter in the black, those overall losses have been reduced to about $1.6 billion.

Over the last four quarters, Surface also remained in the red, with losses of $325 million on revenue of $2.7 billion. Put another way, for each dollar Microsoft earned on Surface sales, it lost about 12 cents.

But were the brighter figures for the September quarter an accurate picture of what Microsoft really spent on the Surface? No, said Dawson and others.

"There's a long way to go to get to the kind of gross margins that would lead to true profitability once marketing and other costs are factored in," Dawson said.

Ben Thompson, the independent analyst behind Stratechery.com, agreed in his subscription-only Daily Update of Friday. "What is all but certain, though, is that this segment, once you include advertising and channel, was still quite unprofitable, and likely unprofitable by a lot," Thompson wrote of Microsoft's Computing and Gaming Hardware division, which generates the bulk of it revenue from Surface and Xbox sales.

Microsoft's advertising campaign for the Surface has been substantial, with widespread television spots, and its marketing spending has also been brisk, including a reported $400 million deal with the National Football League (NFL) that put Surface tablets on the sidelines.

Microsoft called out the Surface Pro 3, which went on sale in June -- making the September quarter the first complete quarter that booked Surface Pro 3 revenue -- in its earnings call with Wall Street for sparking the surge.

"Unit sales are pacing at twice the rate of what we saw with [Surface] Pro 2," said CFO Amy Hood, referring to the now-discontinued model launched in the fall of 2013.

"The release of Surface Pro 3 in June 2014 contributed to a 126% increase [in revenue], reflecting higher premium mix of devices sold," Microsoft said in the 10-Q filed with the SEC.

Thompson seized on the latter's "higher premium mix" to make the case for why Surface revenue jumped. He pointed out that the high prices of the Surface Pro 3 -- between $799 and $1,949 -- generated the increase, while the revenue in the comparative quarter of 2013 was fueled by large numbers of Surface RT tablets that Microsoft sold at fire sale prices to unload an overstock. Last year, Microsoft cut the price of the Surface RT to $349 for consumers and to as low as $199 for educational institutions, representing 30% and 60% discounts, respectively, from the original list price of $499.

Both Thompson and Dawson noted that Microsoft did not reveal Surface unit sales, making it impossible to determine which models have sold best or tell if volume was up, flat or down.

"We don't know the number of units sold or average selling price for the Surface, but considering that the Surface Pro 3 starts at more than double the price of last [year's third quarter] Surface RT, it's likely that Microsoft actually sold fewer Surfaces this quarter than they did a year ago," said Thompson.

"How many Surface devices did Microsoft sell in the quarter? Well, they won't say, but given the new version starts at $800, it's entirely possible that the company sold a million or fewer Surface tablets in total, and likely well under a million Surface Pro 3s in their first full quarter on sale," added Dawson.

As a comparison -- although Microsoft denies that the Surface Pro 3 is a tablet, preferring to dub it a notebook replacement instead -- Apple sold 12.3 million iPads in the same quarter, producing $5.3 billion in revenue.

Microsoft must do better if Surface is to be a viable business rather than a vanity project. "The gross margin has to keep moving up at this point," Dawson said in an email reply to questions. "It's at a point in its history when it has to get beyond the early losses to a sustainable business."

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com