Operation Global Blackout

Operation Global Blackout, planned for March 31, is apparently a protest against “SOPA, Wallstreet, our irresponsible leaders and the beloved bankers who are starving the world for their own selfish needs”.

So how serious are these threats?


Well, for a start, it’s worth pointing out that the date of the take-down could be an indication of an April Fools joke – albeit one day early. And then there are the suggestions that whoever published the announcement does not really represent Anonymous. Instead, they appear just to be using Anonymous' name and reputation to give their anti-SOPA campaign some publicity.

But even if the plans of “Anonymous” don’t come to fruition, would their take-down methods actually work? Is it possible to shut down the internet?

At the top of the hierarchy are the 13 root servers that Anonymous is apparently going to target. The idea is that if you take down all 13 root DNS servers, domain name resolution for the internet would eventually fail.Of course, we shouldn’t discount Anonymous' ability to marshall many botnets to an attack, but for this particular attack to succeed, an enormous number of bots would be needed.

Finally, even if the root servers could be brought down, most ISPs cache queries from these root servers for substantial amounts of time. For Anonymous to “take down” the internet, they would need to maintain a sustained attack. Only after the cached entries have timed out would the attack start to be noticed by users. This would likely take several hours; much longer than the minutes claimed by Anonymous.

So, all things considered, it’s very unlikely a DDoS attack on the internet’s root DNS servers would succeed. But that’s not to say there aren’t other weaknesses that could be exploited to shut the internet down.

Regardless, if the internet is ever brought down, I suspect it will be through something more sophisticated and more arcane than a DDoS of the net’s DNS root servers.

Microsoft's L33t and Lame Moves in 2011

Microsoft has always created a buzz in the entire technology world. Some of its decisions regarded the best while the rest invited a wide range of criticism from the tech savvy. Listed below are some of the good and bad moves made by Microsoft in 2011.

L33t moves:

 
Breaking the tradition with Windows8


The compatibility of old software’s to new OS has always been a big advantage and disadvantage of windows. The need to support these vast software’s continued to be an obstacle for Windows in refining itself. But With windows8, Microsoft is going radical with a whole new set of applications and software’s created for the new UI. The new apps promise to be less expensive. With its new OS built focusing more on tablets than the PC’s Microsoft is moving closely to the future ‘cloud computing’.

Vast market with the Skype acquisition

With $8.5 billion, Microsoft not only bought Skype, but also its broad base of customers eager to chat and video conference across the PC’s and Smartphones. Microsoft also gained 50 patents with Skype which will help in its battle with the Android market. Microsoft promised to continue support of Skype on all devices. Before closing its deal with Microsoft, Skype cleared its biggest complaint by adding video support to a wide range of android devices.

Acknowledging the HTML5

2011 witnessed the changing face of Microsoft towards HTML5. It started supporting HTML5 in Windows8 and IE 10, making the developers more than happy. Microsoft also released an HTML5 app for Bing which extends its search functions to android and iphone. The Microsoft’s old Silverlight is now relabeled as a tool for enterprise web development.

Spam Control

Microsoft went a step further in fighting the spam by petitioning the US courts to order Verisign to shut down 21 internet domains associated with Botnets. Microsoft was successful in its previous attempts on controlling Rustock and Kelihos Botnets.

Popularizing Kinect

Microsoft encouraged Kinect applications in 2011 by releasing an SDK for non commercial uses and also designed a program to help 10 developers or startups launch businesses around products for Kinect, the controller that senses motion and voice. Kinect has gained Microsoft a whole new generation of Gamers.


Lame Moves :

Android war

Microsoft’s secret plans on collecting the all available android patents and thereby forcing the android device makers to pay large fees are exposed with the legal battle with Barnes & Noble. At least some of Microsoft's patent licenses involving Android were broad cross-patent license agreements with hardware partners (like Samsung). B&N really blows the lid off of what Microsoft is doing and how they are forcing money from Android.

Windows Clouds

Microsoft’s cloud applications which are promised to run smoothly on any device and any OS is continuously failing to do so. Be the new browser or the OS, Microsoft is taking a long time in recognizing the non windows platforms. For example Intune, Microsoft’s managed software distribution and security monitoring service is said to enable the users work on every platform. But it currently only supports Windows platform and not even Windows phone 7.

Anticipated Tablets

Microsoft is waiting for the launch of Windows8 to widen its works on tablets. But the world is not waiting till the launch as it shows an aggressive increase in the tablet market. Even though the Microsoft introduced touch support in Windows7, it is still nowhere in the tablet market. Forrester, an analytics firm already predicted that by the time Windows8 arrives, Microsoft will have surrendered the market to others in terms of feature, price and performance specifications.

Control Open Source Programming with Windows 8

Microsoft had created a controversy when it demanded the hardware developers to implement the next generation boot specification in its secure mode, which is known as Unified Extensible Firmware Interface. This prevents users from loading operating systems and drivers onto a device when it is in secure mode. It usually comes with an off button but Microsoft wanted the hardware makers to remove the button which prevents the open source developers from installing other OS like Linux.

Problems with Office 365

Microsoft has launched its upgraded version of Business Productivity Online Standard Suite (BPOS), Office 365 in 2011 in order to compete with wide adoption of the Google apps. But the product lacked certain features as it rolled out without a perfect feature set. The testers always complain about the limitations in importing the contacts. Also office 365 doesn’t match some of the main features of its rivals like simultaneous co editing in word processing documents.

Sony, Are You Listening?

14-Year-Old Hacker Scoops Job At Microsoft After Being Caught Phishing Via Call of Duty Server.

An interesting little tidbit coming out of Microsoft today, with news that the Redmond outfit has offered a job to a young Irish boy who came to their attention though a Call of Duty: Modern Warfare 2 phishing scam.

The 14 year old who’s not been named has been given the opportunity by Microsoft to turn his back on more nefarious uses for his talent.


Microsoft is reported to be working with the 14-year-old Irish hacker who managed to stir up a little trouble with his Call of Duty: Modern Warfare 2 phishing scam alert. According to the managing director of Microsoft of Ireland, the company is helping the hacker “develop his talent for legitimate purposes.”

This move has obviously caused many to wonder why Sony didn’t take a similar stance over the infamous George Hotz affair.This is exactly what Sony should have done with George Hotz – given him a job as a security specialist, instead of suing him in court and getting its PlayStation Network and other Sony websites hacked day in and out.

For those not up to speed on the matter, Hotz was taken to court by Sony over his PlayStation 3 hacking exploits. After much media speculation and legal wrangling, the pair finally settled out of court, but could it all have been avoided? Even at the time many suggested Sony should have taken George Hotz onboard to use his undoubted talent instead of taking him to task. Perhaps they could have avoided the PSN hacking debacle?

Congrats to that young hacker, whose name was not disclosed. While the new prospect for the Dublin kid is not meant to be an example for other hackers to follow, companies do have to realize that there are many talented people among hackers. Why make an enemy when you can have them on your side?

Red Dragon's Cyberarmy

Chinese government officials have acknowledged the existence of a military unit dedicated to cyber warfare activity, according to intelligence sources. Chinese Defense Ministry spokesman Geng Yansheng said that the unit, called the "cyber blue team", is designed to "better safeguard the internet security of the armed forces".


Geng stated that the unit was organized in response to international threats to Internet security, and that China is still relatively weak in regards to cyber security and its ability to defend against cyberterrorism. Intelligence analyst Glenmore Trenear-Harvey says many in the intelligence field believe China has had a cyber offensive unit active for at least the last five years.


"They [China] may have acknowledged that they have set up this unit but they have been doing it for a long time, and they have been enormously successful in their attacks," Trenear-Harvey said.


China has recruited thousands of hackers for a cyber force tasked with infiltrating a multitude of computers to establish a large botnet which can be utilized to conduct denial of service (DoS) campaigns to disrupt targeted websites as well as conducting cyber espionage activity to pilfer sensitive information. "It is one of the greatest threats we have... But do remember that - the US and UK - are doing this in reverse and are very successful. It's an incredibly potent weapon which will certainly be utilized," Trenear-Harvey said.


According to a recent article by Joshua Philipp and Matthew Robertson, the Chinese have long seen a tactical cyber offensive capability as being a potentially powerful equalizer in their quest to attain superpower status and undermine the effectiveness of international political rivals.


The Chinese strategy extends well beyond potential military targets, posing a significant threat to the core industries and critical infrastructure systems a nation relies upon to sustain a healthy military presence. Attacks on private sector assets are seen as a central aspect of a successful Chinese cyber aggression strategy by eroding the industrial and technological superiority of an adversary over time.


Chinese hackers are not merely tasked with infiltrating established western economies, they are also conducting extensive operations in emerging economies (India, Brazil..etc) and extending their presence in regions fraught by political conflict and economic turmoil.


While numerous nations are involved in varying levels of cyber aggression, what makes the Chinese threat so much more palpable is the systemic nature and comparatively large scale of the state-sponsored cyber-offensive operations, as evidenced by attacks like Operation Aurora, Ghostnet, and most recently Night Dragon.

WebApp $ecurity expenditure.

Companies Spend More on Coffee Than Web App Security
A recent report by the Ponemon Institute, Cenzic and Barracuda Networks has produced a startling statistic: eight-eight percent of companies surveyed indicate they spend more on coffee than they do on securing Web applications.

In spite of this staggering revelation, seventy-four percent of the organizations surveyed still ranked Web application security as being equal to or more important than other security priorities. Clearly, organizations are struggling with Web application security issues.

"While it is encouraging to see that Web application security is on the minds of most organizations, there still seems to be a real disconnect between the desire and implementation of security countermeasures required for Web application security.

Other findings from the survey include:
  • 66 percent test less than 25 percent of these applications for vulnerabilities
  • 62 percent cited data protection as impetus for Web app security
  • 51 percent cited compliance as the top reason for securing Web apps
  • 51 percent listing compliance as a key driver for Web application security
  • 41 percent reported having over 100 Web applications or more
"The fact that 69 percent of respondents are relying upon network firewalls to secure Web applications is like relying upon a cardboard shield for protection in a sword fight – eventually your shield will prove that it's insufficient and an attack will reach you that can fly past a network firewall," Judge stated. With cloud becoming popular everyday WebApp security is going to be a big challenge for service providers.

Referencenet-security

Office 365

"BPOS seems history, welcome Office 365"

Recent hype about Office 365 drawn my attention a lot. So i thought of digging some information about the service. In first place one must ask "what is Office 365" ?

Well the answer is pretty straight forward and simple. It is a subscription service that combines the familiar Microsoft Office Web Apps with a set of web-enabled tools that are easy to learn and use, that work with your existing hardware, and that come backed by the robust security, reliability, and control you need to run your business.

Why Office 365 ?

Because of the Unique Selling Proposition of Office 365
.
Powered by Microsoft Exchange Online

Office 365 gives you access to email, calendar, and contacts from virtually anywhere, at any time, on desktops, laptops, and mobile devices*—while it helps to protect against viruses and spam.

Work from virtually anywhere
Work from almost anywhere and get automatically updated email,calendar, and contacts on the devices you use most, including PCs, Macintosh computers, iPhone, Android phones, Blackberry smartphones**, Windows Mobile, and Windows Phones*.




Easy-to-manage email

Get professional, easy-to-manage email. Office 365 provides each user with a 25-gigabyte (GB) mailbox and lets them send email messages up to 25 megabytes (MB). Connect with Microsoft Outlook 2010 or Outlook 2007 and use all of the rich Outlook functionality you already know and use, whether you are connected to the Internet at home or in the office or you are working offline.


Simplify scheduling
Easily schedule meetings by sharing calendars and viewing them side by side, so user can see their colleagues’ availability and suggested meeting times from user's calendar. Access users email, calendar, and contacts from nearly any web browser while keeping the rich, familiar Outlook experience with Microsoft Outlook Web Application.



Business-class security

Help protect your organization from spam and viruses with Microsoft Forefront Online Protection for Exchange, which includes multiple filters and virus-scanning engines.








Highly competitive pricing structure
Microsoft plans to offer Office 365 to businesses with less than 25 employees for $6 per user per month; larger companies will pay between $2 and $27 per user a month. Remember money always matters.

Earlier Microsoft launched SharePoint, Exchange and Lync as online services in 2009, calling it the Business Productivity Online Suite, or BPOS. Customers are currently sending and receiving 167 billion messages every day from its cloud services (Ref:- Kurt DelBene, president of Microsoft's Office Division)

Now with Office 365 a new cloud-based version of a suite of productivity tools that combines SharePoint, Exchange, Lync (formerly Communications Server), and both the Office Web applications and the Office Pro Plus desktop client. Dubbed Office 365, the suite goes into beta today (sign up here).
BPOS seems history, welcome Office 365.
Chris Capossela, senior vice president of Microsoft's Office Division said Microsoft has created what it feels is a highly competitive pricing structure, because it really wants to capture the small business market. Microsoft is including single sign-on access all of these services, Capossela said. Enterprises also have the option to get Microsoft Office Professional Plus desktop software on a pay-as-you-go basis. Microsoft is opening a limited Office 365 beta program in seven languages and thirteen countries around the world.
Hope Office 365 retain the familiar client experience that everyone knows and loves with a rich back-end.

Tech's not originate in Redmond

These technologies may not have been Microsoft originals, but today they bear the Redmond stamp :)

Microsoft, unfairly or not, has a reputation for taking over others innovations . But i still love the fact of what Microsoft did with these technologies and pushed the envelope to take these technologies to a whole new level which others cannot match. Below are the few examples:


Windows Azure
First, let's be clear. We're hearing good things about Windows Azure from third parties who have their choice of cloud providers. But let's face it -- Google and Amazon.com have been in this space so long it makes the entire cloud concept seem old.


Bing
Search has been around for years. Before Yahoo! and Google took over, there was Alta Vista and others. Once Google turned simple search into a massively intertwined business, Microsoft wanted in -- badly. And thus was born a Microsoft ad network, enterprise search and now Bing, a fresh stab at the problem. Many people might not aware of this but internet community conclude BING=Bing Is Not Google.


Windows GUI
This one is almost too obvious. Bill Gates, looking for the next innovation in OS, used Mac fundamentals as the basis of Windows 1.0. On the flip side, Gates had multitasking long before Steve Jobs!


Internet Explorer
Netscape wowed the world with its browser, then branched out into other areas such as mail and collaboration. Microsoft feared the browser was to some extent a platform, and that it could disrupt the Windows franchise. Microsoft bought a browser, tweaked and bundled it with Windows 95. Despite anti-trust losses, Microsoft still won this game.


SQL Server
Sybase in the late '80s was a rising database star, and Sybase SQL Server ran on larger systems. Microsoft wanted to bring this kind of solid relational product to a PC-based platform, so Microsoft, Sybase and Ashton-Tate formed an alliance. The code would be ported to PC servers, and Ashton-Tate would rejigger dBase to front-end SQL Server. But dBase was so fundamentally different it couldn't work with SQL, leaving only Sybase and Microsoft. When Windows NT arrived, Microsoft split from Sybase, but kept components that remain the basis of SQL Server today.


Stacker
Stac Electronics built a utility that doubled the capacity of your hard drive through compression. Microsoft tried to strike a deal to embed a version of Stacker within Windows, but Stac said no, so Microsoft went ahead and wrote its own data-compression tool called DoubleSpace. Unfortunately, the Microsoft version violated Stac's patents. Can you say lawsuit? Microsoft lost, but instead of just paying Stac off the $120 million it was ordered to pay, Redmond invested in the company and paid royalties to Stac, which ultimately folded.


Virtualization
Virtualization is the hottest thing to happen to computing since Dell laptop batteries started catching fire. Microsoft was late to the market with Hyper-V and crafted a strategy eerily similar to VMware, with PC- and server-virtualization tools. However, through its partnership with Citrix, and Microsoft's own Windows Server Terminal Services, Redmond is also arguably a virtualization pioneer.


Windows Sever
Novell became a powerhouse through network OSes that mostly supported print and file services. Microsoft saw this huge market and made a move with Windows NT. IT pros loved NetWare, but Microsoft had advantages: deep relationships with CEOs and CTOs, and the fact that NT was a true partner of the Windows client, sharing an interface and many core functions.


Microsoft Word
The WordPerfect word processor came out around 1980, and as the decade progressed it became as dominant as Lotus 1-2-3 and Ashton-Tate dBase were back in their day. Microsoft wanted an application and OS, and WordPerfect was an obvious target. Microsoft Word came in 1983, and subsequent versions promoted compatibility -- even keystroke compatibility -- with WordPerfect. We all know who ultimately won this war.


Xbox
The Xbox may be the hippest console out there, but Microsoft was way late to the video game business.