2011/06/20

Adobe To Patch Flash Player on PCs and Android Devices (NewsFactor)

Adobe Systems issued a security bulletin Tuesday concerning the discovery of a critical vulnerability in Flash Player 10.3 and earlier versions. This memory-corruption flaw may cause computing devices to crash and potentially allow an attacker to take control of the operating system. "There are reports that this vulnerability is being exploited in the wild in targeted attacks via malicious web pages," the software maker said.

Adobe expects to release a Flash Player update later this week for computers running the Windows, Mac, Linux and Solaris operating systems. It noted that Chrome browser users will automatically receive the new update since Google's browser includes Flash Player as a built-in feature.

Adobe's advisory was unusual in that it also covers smartphones, tablets and other mobile devices running Google's Android OS. Still, vulnerability patching is "a fact of life for any software that runs on connected machines today," noted Al Hilwa, director of applications software development at IDC.

A Mobile Exploit

Heavily used online software like Flash and web browsers get more than their fair share of issues in this space, Hilwa observed. Moreover, exploits are "often platform-specific and with most attacks targeted at desktop platforms, which have the greatest deployments and surface area," he said.

By contrast, mobile devices are more locked down and susceptible to different forms of malware, data corruption, and theft, Hilwa noted. "Having said that, Android -- which is the only mobile platform cited in this vulnerability -- has a variety of issues today."

As Sprint's new deal with Lookout Mobile Security demonstrates, U.S. wireless carriers are paying attention to the security issues that their mobile subscribers may face. However, Hilwa doesn't see Adobe's forthcoming critical patch for Android mobile devices having any effect on how the carriers and mobile-device makers perceive Flash.

"I think carriers and OEMs understand the risks of the general maturity of mobile-device software and the trade-offs they present," Hilwa said. "I don't think this affects Flash in a unique way."

New AIR Tool

Adobe also issued a separate security bulletin Tuesday covering a number of critical vulnerabilities in Adobe Reader X for machines running Windows and Apple's Mac OS X. Users are advised to update to the latest available version of Adobe Reader now available on the software maker's web site. "These vulnerabilities could cause the application to crash and potentially allow an attacker to take control of the affected system," Adobe noted.

Meanwhile, Adobe has just released optimized versions of its AIR runtime -- a multi-platform development tool available for desktops, most new tablets, and both Apple's iOS and Google's Android mobile operating systems. Though Flash doesn't run on iOS, Flash developers have actually been catering to iOS for some time through the AIR runtime, Hilwa observed.

The Adobe folks are truly persistent in continuing to improve Flash and AIR for mobile platforms, Hilwa observed. "Even in a world of quickly multiplying platforms and form factors, they appear to be broadening their reach to as many platforms as makes sense, thereby slowly but surely carving Adobe a place as a leading multi-platform mobile development environment," he explained.


View the original article here

Ericsson to buy Telcordia for $1.15 bln (AP)

STOCKHOLM – LM Ericsson AB has signed a deal to buy U.S.-based software development firm Telcordia for $1.15 billion, the Swedish wireless equipment company said Tuesday.

Ericsson said it will buy 100 percent of the shares in Telcordia from private equity firms Providence Equity Partners LLC and Warburg Pincus and expects to complete the acquisition in the fourth quarter 2011.

Telcordia, based in Piscataway, New Jersey, develops mobile, broadband and enterprise communications software and services. It reported revenues of $739 million during the fiscal year, ending January 31 and employs 2,600 people who will now be transferred to Ericsson.

The Swedish company said Telcordia has a leading market position within the operations and business support system field — producing computer systems that are used by telecommunications operators to handle the growth in mobile and fixed broadband traffic.

"The importance of operations and business support systems will continue to grow as more and more devices are connected, services become mobile and new business models for mobile broadband are introduced," Ericsson CEO Hans Vestberg said.

The acquisition is subject to regulatory approvals.

Shares in Ericsson rose by 1.8 percent to 88.80 Swedish kronor ($13.99) in Stockholm.


View the original article here

More About Android Application Development

With the recent introduction of android application development, companies offering software consulting services have shifted gears to support this latest technology that is the first of its kind as a open source mobile platform. Android is defined as a software stack for mobile devices that includes an operating system, middleware and key applications. The Android SDK provides the tools and application programming interfaces that are necessary to begin developing applications on the Android platform using the Java programming language. In android application development developers are free to take advantage of the device hardware, access location information, and run background services. This is the biggest advantage of using open source software.

The android application development market is the fastest growing market in mobile technology with majority of its developers being young people under the age of 34. This growth is attributed to the fact that android phones are available in any cell phone network and which makes them accessible to many subscribers. Android applications can be distributed for a fee, free of charge, or monetized with advertising. They are usually based on GPS and Wifi, SMS and Email, usage of Google maps, browser and contacts, and multimedia.

Software consulting firms are now providing support for the android platform so as to stay up to date with the latest technologies. These consulting firms have observed that the increase in android application development is considered to be directly proportional to the increase in user population since the more the number of users the more the demand for android applications. Software firms have thus invested in acquiring skilled developers who are proficient in mobile applications.

The android market has the highest percentage of applications from third-party developers. However these apps have to ask for permission before accessing certain features such as reading and writing to users' memory cards and accessing users' address books.

Mobile application developers use the android software development kit and the android native development kit for android application development. Most of the android developers have good experience in mobile applications and this has greatly contributed to their success. Software consulting firms are committed to testing and learning new technologies and teaming up with interested clients to develop their applications. These firms will as a norm carry out a feasibility study before any project is initiated, and followed by project management which is carried out in phases. When implementation is completed and the client is satisfied the project is then terminated. Consultations on hardware and software can also be done separately.


View the original article here

Simplify Remote Desktop Printing With Universal Print Drivers

When working via remote desktop, printing to a local printer connected to a windows machine can be accomplished, according to Microsoft, by the following simple procedure:

To make a local printer available in a Remote Desktop session:

1. Click Start, point to All Programs, point to Accessories, point to Communications, and then click Remote Desktop Connection.

2. Click Options in the Remote Desktop Connection dialog box.

3. Click the Local Resources tab.

4. Click Printers in the Local Devices box.

5. Click Connect.

After you establish the remote connection and log on to the remote computer, the local printer that is connected to the client becomes the default printer for any programs that are running on the remote desktop. If the client has more than one printer attached to it, the default printer for the computer becomes the default printer on the remote desktop; however, all local printers are available.

Sounds easy enough, but is it? Users working from home will rarely have the 'Business Class' printer found at the office. While the Universal Print Driver (UDP) that windows utilizes claims to handle a wide variety of hardware, it is almost certain that users will a printer on sale at the local shop and drive IT staff to distraction with incompatibility problems. Also, UDP may not include all of the advanced features that a native print driver might hold. UDP has weak support for compression, and could cause delays where bandwidth is constrained. Questions also arise if operating systems other than Windows are being run on the local host. And what about thin clients that are locked down and don't allow users full control of the OS to add or install printers or drivers?

In these situations, third party print driver solutions can solve the problem. For bandwidth control, look for a vendor solution that offers configurable compression of print jobs. Some convert all jobs to PDF before transmission and others have support for features like font embedding and image de-duplication to reduce the overall size of each job sent. Options should be available that will set an upper-bound on the total amount of bandwidth that can be used to transmit print jobs, reserving the remaining for other data traffic. In some cases, the third party software can be configured to send the print data directly from the terminal server to the print server, bypassing the client side entirely, which will reduce print delay and minimize possible driver issues.

Advanced capability printers rely on the manufacturers drivers to provide their full range of services to the end-user. A third party service will allow these to run, with little chance of system crash. Printer naming conventions can cause issues across different operating systems, and features allowing granular control over printer names can solve these. Users at remote sites that are running thin clients may not be able to install a printer on the embedded OS (Linux or CE), and a third party solution can be configured to assign local network printers by policy.

Third party print drivers for Remote Desktop are not necessarily needed to facilitate printing in a distributed environment. Depending on the size and variety of the user and printer pool, built in solutions may foot the bill. However, if complete granular control over all aspects of printing is required, then a third party print driver solution will provide better management of the organization's print resources. Where the scope of enterprise operations exceeds the functionality of the built in solution, third party solutions exist to solve the problem, and can help keep printing from consuming IT support cycles.

To learn more about Lisa Gecko or how to print from a local printer during a remote desktop session, call Infinitely Virtual at (866) 257-8455 or visit: Virtual Server, Virtual Server Hosting.


View the original article here

Exclusive: China software bug makes infrastructure vulnerable (Reuters)

NEW YORK (Reuters) – Software widely used in China to help run weapons systems, utilities and chemical plants has bugs that hackers could exploit to damage public infrastructure, according to the Department of Homeland Security.

The department issued an advisory on Thursday warning of vulnerabilities in software applications from Beijing-based Sunway ForceControl Technology Co that hackers could exploit to launch attacks on critical infrastructure.

Sunway's products, widely used in China, are also deployed to a lesser extent in other countries including the United States, DHS's Industrial Control Systems Cyber Emergency Response Team said in its advisory.

"These are vulnerabilities that hackers could leverage to cause destruction," said Dillon Beresford, a researcher with private security firm NSS Labs, who discovered the bugs.

The DHS advisory comes amid a wave of high-profile cyberattacks on institutions ranging from the International Monetary Fund to Citigroup Inc and Sony Corp. The attacks focused primarily on stealing data; only in a few instances has critical infrastructure been attacked.

Last year the Stuxnet computer worm surfaced, targeting industrial control systems manufactured by Siemens. Security experts widely believe that the worm was built as part of a state-backed attack on Iran's nuclear program.

Iran said the worm was used to attack computers at its Bushehr nuclear reactor. There has been widespread speculation that Stuxnet actually damaged the plant, something Iran denies.

FIXING BUGS

Beresford has worked with Sunway, Chinese authorities and the DHS to fix the bugs he found. Sunway has developed software patches to plug the holes, but it could take customers months to install those patches, Beresford said.

That gives hackers a window of time in which to exploit those vulnerabilities.

"Customers need to be notified and given proper time to patch," said Beresford, who also discovered security bugs in industrial control management systems from Siemens. The German company addressed those vulnerabilities in an advisory it released last week.

Representatives for Sunway could not immediately be reached for comment.

The Sunway software flaws highlight growing concerns about the safety of supervisory control and data acquisition (SCADA) computer systems that are used to monitor and control processes in a wide variety of facilities, including nuclear power plants, chemical factories, water distribution networks and pharmaceutical plants.

SCADA systems -- designed before Internet use became widespread -- were not built to withstand Web-based attacks.

Security systems to deal with Web threats have been bolted on rather than incorporated into SCADA systems, leaving holes that hackers can penetrate.

Beresford said that there are other vulnerabilities in SCADA systems that have yet to be documented by security experts and plugged by the manufacturers.

"The point of my putting this information out and getting it into the public domain is so that we can pressure the vendors to actually patch the vulnerabilities instead of sitting on them because these systems are inherently flawed by design," he said.

(Reporting by Jim Finkle; Editing by Tiffany Wu, Phil Berlowitz)


View the original article here

2011/06/19

Protect Your Data With Email Encryption

According to the Pew Internet and American Life Project survey from May 2010, email remains the most popular activity online and 94% of U.S. Internet users have gone online and sent or read email. Although email is an easy and efficient way to communicate with others, many people do not realize that standard email messages are often transmitted in plain text over the internet without any form of encryption and is an inherently an insecure medium. As a result, anyone can intercept the emails and easily access its contents, including any attachments.

Perhaps even more alarming is copies of your messages are typically stored unencrypted on your computer, your company's or host's mail server, each recipient's mail server, and each recipient's computer. While transmitting your message normally takes a fraction of a second, once your message is stored it normally sticks around for years. This provides multiple opportunities for unauthorized access to your email messages and raises legitimate privacy concerns. With the data security risks and potential costs of data attacks, it makes sense for small businesses and individuals to protect sensitive data when sending emails.

Email security has been a hot topic in recent months, especially with reports of well-known companies accidentally exposing private information of their customers in unencrypted e-mails. Since the bulk of business transactions and communications is performed via e-mail, many of the high-cost security incidents occur when insiders send confidential data outside the company without properly securing the data. This includes emails containing personal data, financial information, legal information, trade secrets, or personally identifiable information such as health information, social security numbers, and other sensitive material. Many large corporations use expensive, complex, management intensive solutions such as public key cryptography to secure their sensitive emails.

For small businesses and individuals, e-mail encryption is the most practical and affordable. A good email encryption solution will use powerful cryptography techniques to ensure your messages are both stored and transmitted securely, and that only you and your recipients have the capability to decrypt your message data. Remember, email is typically stored and transmitted in plain-text. Moreover, anytime you click the send button copies of your message are generally stored on your computer, your mail server, each of your recipients' mail servers, and each of your recipients' computers. That gives unauthorized users a lot of opportunities to access your data. Therefore, making sure a message that contains sensitive information can only be accessed by your recipients is the only smart way to go and email encryption is the way to go.

Than Nguyen is an Internet consultant specializing in Internet Technology and helping businesses implement strategies and tools to increase productivity and profitability. Send Secure emails for free at https://www.sendinc.com/


View the original article here

Role of Business Intelligence in Software Engineering

A major problem with outsourcing software development is how to analyze the project. Analysis of metrics is an area that is often underutilized in software engineering because of lack of expertise and tools. However, in the business world, data is modelled and analyzed along different dimensions helping in making critical business decisions that can determine profits or loss. These techniques fall under the umbrella of "business intelligence".

Having better predictability in the software engineering process would lead to improvements in many areas, including:

‧ Higher accuracy in cost and time estimates.
‧ Better utilization, and wiser allocation, of project resources.
‧ Clear understanding of business processes and organizations.

The major role of business intelligence in software engineering, when applying the analytical strategies is as follows:

Measuring performance: It is easy to measure the sales person performance in numbers but difficult to measure the performance of a programmer. To measure individual performance becomes a difficult task and resulted in increasing competition and discouraging teamwork. This situation becomes worse in a team dependent organization, such as engineering group. This gives rise to business intelligence techniques for performance analysis for a project or team as a whole rather than on a per-person basis.

Resources: Whenever a new project comes it becomes essential for an organization to identify what resource requirements will be needed in the future to achieve specific goals. This could involve training and hiring. This is broken down by functional departments in order to assess budgetary requirements.

Eliminate guesswork: Managers in IT are greatly benefited from business intelligence. Often, their data lacks any structure to allow them to make truly informed choices. Business intelligence provides more accurate historical data, real-time updates, synthesis between departmental data stores, forecasting and trending, and even predictive 'what if?' analysis," eliminating the need to guess.

Get insight of the customer behavior: The most important benefit of business intelligence is that it allows companies to gain visibility into what customers exactly want, giving them the ability to use this solution in retaining the valuable customers and getting additional profit.

Get key business metrics reports when and where you need them: Business intelligence helps the software vendors to access key business metrics, reports and dashboards related to their project on mobiles devices like their iPhone, iPad, Droid or BlackBerry, giving sales and marketing people access to critical business information on the fly.

Many mobile software development companies offer product services and outsourced the product development in business intelligence software. These companies provide customized, secure, reliable, and easy-to-use software. The business intelligence software is developed exactly to meet the organization and business needs. Software is strongly encrypted to prevent both inside and outside information theft. The data is stored and processed reliably, and backup mechanism to make sure that there is no lose of information due to hardware failures. The interface of the software developed is made user-friendly and presentation of data in simple and clear form.

Christa Joe is the author of this article. She has been demonstrating her writing skills by writing the articles for outsourcing software development companies like Q3 technologies from last two years. She also has a keen interest in writing stuff for warehousing management related firms. For more details, feel free to visit http://www.q3tech.com/


View the original article here