Showing posts with label Lessons. Show all posts
Showing posts with label Lessons. Show all posts

Wednesday, 18 September 2013

The 7 key lessons of IDF

Let's face it: Intel's track record of anticipating trends in computing is, in a word, lousy.

Intel didn't truly embrace low-power computing until Transmeta forced its hand. The company has repeatedly squandered opportunities in the phone by fumbling its StrongARM processor, and Intel's internal graphics program has struggled to keep its head above water until recently.

[ Also on InfoWorld: Google, Intel cement ties on Chrome OS, could weaken Wintel. | Keep up on the day's tech news headlines with InfoWorld's Today's Headlines: Wrap Up newsletter. ]

Recent trends imply nothing has changed: One could argue that former chief executive Paul Otellini was shown the door because of an inability to, once again, capitalize on mobile -- specifically, the tsunami of tablets toting ARM silicon inside.

But, as analyst Jon Peddie noted, Intel does one thing right: It sees mistakes, and it fixes them, dragging its customer industries along with them. In May, Intel shifted its corporate motto to "Look Inside," implying that Intel technology might be found unexpectedly in products beyond the PC. Now, Intel is busy driving the PC forward, but also hedging its bets with any number of non-traditional devices. The common thread? Those devices must compute, communicate, and consume less power than before.

So what does that imply? Seven trends that are changing the computing industry: the lessons of this week's Intel's Developer Forum.

1. Desktops are dinosaurs
It's a bit premature to declare the desktop dead. But the roaring minitowers of years past have been pushed upward into the rarefied air of the gaming PC. Instead, the desktop has evolved into one of two things: a docking station for a notebook, or an ultra-small-form-factor "desktop" device that's actually portable.

Scattered throughout Intel's technology showcase were what Intel rather awkwardly calls NUC's, or New Units of Computing. Just 4 inches by 4 inches by 1.5 inches high, the latest version of these tiny boxes can actually house Intel's latest "Haswell" processor  -- which in turn has enough graphics horsepower inside its "Iris" graphics accelerator to run some pretty sophisticated modern games. While it seems silly to consider anything but a notebook for a low-cost PC these days, the NUC certainly looks like a strong candidate for the last gasp of the mainstream desktop.

Intel's 14-nm "Broadwell" Core chip, due at the end of the year (and in PCs in 2014) should enable truly fanless designs, Intel executives said. That has implications for the NUC, as well as the...

2. Two-in-ones: the new Ultrabook
In years past, Intel and Microsoft both pitched new ideas and new directions for the industry to adopt. Several, to their credit, were merely ahead of the curve, such as the SPOT watch and the original Tablet PC. One of the ideas that truly failed was 2008's Mobile Internet Device (MID), an ugly combination of a small touchscreen, Linux, and an SSD.

But Intel's ideas to combine touchscreens and portability helped pave the way for the Ultrabook, the 2011 Intel concept that has evolved into the "Harris Beach" design that now straddles dozens of Ultrabook designs using Intel's latest "Haswell" Core processor.


View the original article here

Monday, 9 September 2013

Decline of Digital Equipment offers lessons for Microsoft

Computerworld - Microsoft has piled up so many stresses on its corporate body in the last 10 months that it must beat almost insurmountable odds to remain healthy and viable, a business strategist said today.

"There's something endemic in technology companies that they are not built to last," said Peter DeLisi, founder and president of Organizational Synergies, a Fremont, Calif. strategy consulting firm. "The larger and larger they become, the more they spin out of control. In a highly empowered culture like Microsoft or DEC, the pieces are loosely held together. And in a crisis, down they go."

DeLisi was not predicting the collapse of Microsoft -- the Redmond, Wash. firm is a member of the Fortune 50, with revenues in its latest fiscal year of $78 billion -- but current and former Microsoft employees have been struck by the parallels between the company's current situation and that of DEC, or Digital Equipment Corporation, which in the late 1980s was the world's second largest computer company. By 1996, DEC had disappeared, sold at a fire sale price of $9.6 billion to Compaq.

And DeLisi knows DEC -- specifically its downfall. A 16-year-veteran of the Maynard, Mass. company, half of those as a strategy, IT and organizational culture consultant to DEC's largest enterprise customers, DeLisi wrote a seminal paper on the company's decline, "A Modern-Day Tragedy: The Digital Equipment Story," in 1998. Five year later he co-authored the book, "DEC is Dead, Long Live DEC" with Ed Schein, a former professor at the MIT Sloan School of Management and one of the world's foremost authorities in organizational behavior.

Computerworld spoke with DeLisi after seeing his paper mentioned numerous times in a semi-underground blog, "Mini-Microsoft," purportedly written by a current Microsoft employee, when the blog's author posted his or her take on Ballmer's retirement. Among the several hundred comments left by others -- most anonymously -- were dozens referencing DeLisi's description of DEC's downfall.

Those with time at Redmond saw similarities between the tale of DEC and today's Microsoft:

"I spent 12 years at Microsoft after leaving DEC in 1994," stated one anonymous commenter. "The time between DEC's first [layoffs] and its closing shop was brief. DEC in its heyday had 140K employees, large cash reserves (no debt) and was the 2nd largest computer company in the world (behind IBM).

"DEC missed early entry into the PC market and was not able to catch up; similar to Microsoft missing on mobile. Missing the market, sound familiar? [emphasis in original].

"DEC's beloved CEO and visionary, Ken Olsen, left in 1992 and was replaced by Bob Palmer who had been internally lobbying for the job for years ("managing up"). Palmer I believe is still on the board at debt-laden AMD. [Editor's note: Palmer left AMD's board this year.] CEO change, sound familiar?

"If employees think it cannot happen at Microsoft because of its large cash reserves, they are wrong."

While DeLisi was hesitant to cast Microsoft as a DEC doppelganger because he was not inside Microsoft -- as he had been at DEC two decades before -- he was confident that Microsoft had, purposefully or not, stacked the deck against itself.

Microsoft's strategy turn-about and the resulting July top-to-bottom reorganization, then the announcement six weeks later that Ballmer would depart and a new CEO found, and then 10 days after that, the acquisition of Nokia -- a move that will boost the company's head count by a third -- are an incredible number of corporate strains in quick succession. "Any one of those are by themselves major efforts to assimilate," DeLisi said. "Sometimes companies can weather some of those changes, but when they must deal with more than one major change, most cannot."

Just absorbing Nokia and its estimated 32,000 employees will be a chore that could disrupt Microsoft or otherwise end badly, said DeLisi. "The integration of Nokia is not a slam dunk," he said. "Half of all mergers and acquisitions fail outright, and in two-thirds of the cases, the companies would have been better off investing in Treasury notes. That by itself is going to be difficult to pull off."

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

Sunday, 18 August 2013

Blaster worm: Lessons learned a decade later

CSO - 10 years ago, I had a life-altering work experience. I was on the team at Microsoft that was trying to solve 2 huge problems:

2 Billion computers had been infected with a self-replicating virus (AKA 'worm') now known as Blaster.

The NE Power Outage was, for a period of time and by some people, attributed to Blaster.

There are many of my former colleagues who spent literally a year of their lives working with me to fix the aftermath of these problems. There are more friends with whom I later worked with at the Idaho National Lab (INL) that helped me understand the breadth of the problem that was uncovered by Blaster, specifically the reliance of critical infrastructure upon consumer-grade technologies.

[Slideshow: 20 notorious worms, botnets and viruses]

Much of my success in my career is due to the people I met (working tremendously long hours) and the lessons I learned (the VERY hard way) from those weeks of toiling to try to understand the scope of the problem and then the months we spent attempting to fix it some way for the following year. It was one of the most-expensive projects I've ever worked on.

Millions upon millions of dollars were spent by Microsoft to improve internal processes and technologies to prevent a similar outcome in the future.

Millions upon millions more were spent by Microsoft to help customers improve their technology infrastructures, and then those customers spent millions upon millions more so that they would be more resilient to future cybersecurity events

But, by far the greatest cost of Blaster was personal toll it took on all of us involved in the response. Work/life balance has always been a problem for me, and when a problem of this magnitude arose, I automatically threw myself into the thick of trying to solve it. Late-night conference calls, sleeping on the floor of computer labs, eating rushed meals of take-out food in conference rooms and many more hours spent at work than I had spent at a job which was demanding a tremendous amount of my team even before Blaster, resulted in tension in my marriage. Fortunately, my dear wife Holli (with whom I am celebrating 18 years of marriage this month) brought me to my senses in a very-direct conversation in November of 2003 that most definitely prevented a divorce and established a path upon which she and I are still reaping personal, career and economic benefits built upon the foundation of experiences like those of 2003.

The only reason why I was able to re-balance my life was through the hard work and dedication of others. The early days of security efforts were more like a volunteer fire department than a top-down effort. I was on the Microsoft Services team during the Blaster incident. We were responsible for all customer interactions, both measuring the impact of Blaster on our customers and communicating any solutions to them. The Microsoft business model relied on very few Microsoft employees and an army of partners (re-sellers, service providers, etc.). This meant that while we had direct contact with thousands of Microsoft customers (most of them threatening to sue Microsoft for damages in those first few days), we had to rely on thousands more individuals to scale the response to the millions of customers impacted by the event. The training efforts that we coordinated to help those partners get ready to effectively solve the Blaster problem were enormous efforts in and of themselves.

Fortunately for Microsoft and its customers, many thousands of people made incredible personal sacrifices to help organizations of all sizes recover from the effects of Blaster. For all of you, both internal Microsoft staff as well as external partner employees and even those super-smart Microsoft customers, who worked with me during that horrible year of 2003, thanks for sharing your expertise. Thanks for making sacrifices yourselves to help Microsoft and its customers try and make sense of the madness that was August 2003. I know many of you paid high personal prices for your efforts. There are many of us who quite literally lost a year of our lives because of the underlying flaws in technologies and miscreants' exploitation of those flaws for their own purposes.

There are many reasons in my humble opinion why we haven't seen another Blaster-level cyber event. Most definitely the Microsoft team learned their lesson and spent incredible amounts of time to improve the way that technology is developed and deployed. But, not all companies have the luxury of funding multi-million-dollar security mobilization efforts. Based upon some of the research that I have done over the last decade, I have also seen that the adversaries (the miscreants as we called them then) have fundamentally changed the way that they operate. On one occasion, while working at INL, I was working with a team of international researchers and we saw the attackers self-policing when it came to deploying worm-like attacks. One individual on an IRC channel bragged that he could deploy a worm that day on an un-patched vulnerability. The other people on that channel immediately threatened the braggart with bodily harm should he proceed with his plan.

It makes sense when you think about it. Massive worms cause huge denial of service problems, thereby blinding the attackers and preventing them from exploiting the systems that they already control. Also, worms drive a news cycle which results in organizations improving their infrastructures and applications, thereby reducing the attack surface. Worms like Blaster are bad for their business, and I think thats why we havent seen similarly-sized incidents since. The underlying technology problems have not been solved. The root cause of Blaster was a vulnerability in Microsofts operating systems. But the contributing factor which exponentially increased the impact of the worm was the fact that Microsoft's customers were not properly managing their technology infrastructures.

When I go to conferences and speak on the topic of mobile security today, this is one of the key points I focus on: Configuration Management is getting WORSE, not better. A few years ago, I started playing a game which I called Smartphone Bingo. It required everyone sitting in the room to take out their smartphone or tablet, open up the settings of the device and then find the version of the operating system. I then start a sort of reverse auction, calling out version numbers to see who had the oldest, un-patched version. Sometimes we would limit the devices in our Bingo game to just corporate-issued devices. It is shocking to me that even the most-mature organizations are completely ignoring the very-hard-learned lessons about configuration management on the ever-increasing numbers of mobile devices. Within one organization that I spoke with last year, they had 60,000+ smartphones and they estimated that they had 20,000+ different configurations/versions of those smartphones deployed. Over the last few years, we've seen more and more evidence of how attackers are targeting mobile technology for either direct financial gain or to steal intellectual property for longer-term advantages. The lack of effective configuration management on enterprise-connected mobile devices makes their jobs incredibly easy.

Imagine I had a time machine and I went back to August of 2004. On that imaginary trip, I sit down with the CIOs/CISOs of the Microsoft customers I had just spent the last year helping to recover from Blaster and tell them that in 2013 they are relying on the good-will of mall kiosk employees to keep their enterprise mobile technology configured in a way to prevent a system compromise. I'm sure they would laugh in our imaginary conversation. How would it ever be possible to believe that we as technology and information security professionals would ever set ourselves up to fail like we did in 2003?

Unfortunately, the reality is that we ARE setting ourselves up to fail. Every un-patched Android or iOS device that you let have full access to Exchange Activesync is an invitation to the miscreants to steal your company's email, attachments and contact lists. Every time I bring this up at a conference, there are always people who respond, "I'm just a little company in an obscure industry! Surely the attackers are going after bigger fish than me!"

The reality is that attackers are going after targets of opportunity just as often as they are dedicating their efforts to attack a specific organization. If you are not enforcing strict mobile technology configuration management policies, you are getting on a risk management treadmill that will grind you down, chew you up and leave you worn out. While I do not believe we will ever see another Blaster-level event which impacts billions of systems, I am certain that configuration management failures are being exploited every day both opportunistically as well as during targeted attacks. We've seen some very interesting non-persistent exploits run against iOS and Android devices that leave very few forensic traces as weve helped our consulting customers.

Proper mobile technology configuration management can be difficult because of the relatively limited technologies available to scalably manage the situation. But, just because it's difficult doesnt give us as technologists the excuse to ignore the problem. Discipline, innovation and hard work will be required until we see mobile technology management platforms catch up with their server/desktop/laptop counterparts.

I find it hard to believe that it has already been a decade since Blaster. I'm saddened by the fact that it sometimes appears to me that we've forgotten many of the hard lessons we learned in the Fall of 2003. I'm very grateful that we haven't had a similar-magnitude event since. Here's hoping that we avoid one for a long, long time to come and that we can keep applying those hard-learned lessons to new technologies as they are integrated into our enterprises and that we can keep up the good fight against those who wish to steal and misuse our information.

Security veteran Aaron Turner, a former strategist in the security division of Microsoft, is the founder and president of IntegriCell.

This story is reprinted from CSO Online.com, an online resource for information executives. Story Copyright CXO Media Inc., 2006. All rights reserved.

View the original article here