Showing posts with label Their. Show all posts
Showing posts with label Their. Show all posts

Wednesday, 11 September 2013

iPhone jailbreakers begin cracking their knuckles over iOS 7

Apple's latest operating system iOS 7, due to be released Sept. 18, is already under the microscope of independent security researchers looking for a new jailbreak.

The team, which goes by the Twitter handle "@evad3rs," hunts for software vulnerabilities that allow users to customize their iPhones and install applications not vetted by Apple, which the company discourages.

[ Also on InfoWorld: All you need to know about the new iPhone. | Also: Apple sneaks in changes to AppleCare+ | Get the latest insight on the tech news that matters from InfoWorld's Tech Watch blog. ]

Apple's iPhone security has become tighter with every version of its mobile operating system. The jailbreak team often has to find a series of vulnerabilities for a working exploit that can grant unfettered access, which can be a difficult, painstaking process.

David Wang, who works with @evad3rs, wrote on Twitter on Tuesday that "We are currently in a reconnaissance phase where we are identifying which exploits we have still work."

Apple has been releasing beta versions of the iOS 7 software since its World Wide Developers conference in June, but has released its Gold Master version of the software that will ship next week.

In the past, the jailbreak team has withheld using some vulnerabilities they've found in the hope that those flaws will become useful for future exploits. When a jailbreak is released, Apple typically moves quickly to release a patched version of iOS to eliminate the software flaws.

Apple released two phones on Tuesday, the iPhone 5S, its premium model with fingerprint authentication and an upgraded processor, and the 5C, a lower-end model with the same processor as the fifth-generation model.

The new A7 processor in the 5S is the first 64-bit processor to be used in a smartphone. The chip can process larger amounts of memory than 32-bit chips, although applications need to be written to use those capabilities.

Apple has modified the iOS kernel, libraries and drivers for the A7, which the company said means faster CPU processing and graphics performances for applications and games.

Another member of the @evad3rs team, who goes by "@pod2g" on Twitter noted that the 64-bit processor will "probably kill some exploits."

On Reddit, Wang wrote that the 64-bit processor itself "will make little or no difference in terms of security, vulnerabilities and exploitation. All the difficult parts about jailbreaking will remain as difficult but not more so than before."

Jailbreaking is legal in the U.S. due to an exemption under the Digital Millennium Copyright Act, which forbids circumventing protections in place to prevent modification of devices. The most popular source for unauthorized applications is Cydia.

iOS 7 will be a free update for the iPhone 4 and later versions, iPad 2 and newer models and the fifth-generation models of the iPad mini and iPod touch.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk.


View the original article here

Sunday, 8 September 2013

Salesforce realizes nobody wants to store their files in Salesforce

Salesforce realizes nobody wants to store their files in Salesforce

A year ago at the TechCrunch Disrupt conference, Salesforce CEO Marc Benioff dropped some big news: Salesforce was getting into file sharing, taking on competitors like Box with a new product called Chatterbox.

Turned out that wasn't really true. Chatterbox was an add-on feature to Chatter, Salesforce's news feed (think of it like Facebook for salespeople). It allowed users to place files from their local hard drives into the Chatter news stream so that other Salesforce users could read them on any device. But in conjunction with an earlier product called Chatter Files, which let Chatter users upload files for collaboration, it seemed like Salesforce was trying to get people to use Chatter to store and work on files, rather than relying on third-party repositories like Box.

Never mind.

[ Also on CITEworld: How Google Apps helped this company double in size overnight ]

Today, Salesforce is killing the Chatterbox name and instead subsuming its functionality into a new feature called Salesforce Files. It's different from previous Salesforce file-sharing efforts in several critical ways:

It works with third-party file repositories, both on-premises (like SharePoint or Documentum) and cloud-based (like Dropbox or Box). To achieve this, Salesforce used technology it gained in the February 2013 acquisition of EntropySoft, which had built direct connectors to these repositories using their APIs. For repositories without direct APIs, Salesforce is relying on the CMIS standard.Files don't have to be stored in Salesforce. Instead, Salesforce will contain read-only links or pointers to files in other repositories. Access will be read-only -- a user will be able to see a PowerPoint presentation stored in SharePoint that her business partner has shared via Salesforce, but she won't be able to edit it unless she downloads it to her device and opens it in a third-party app (likeQuickOfficeon the iPhone, for instance).It doesn't require Chatter, but it will be available from within other Salesforce products.It will also be available to third-party applications built on the Salesforce Force platform.

The product enters beta today and will supposedly be out in February 2014, so there are still some areas that seem like they need a lot more fleshing out. In particular, Salesforce said Files would rely on permissions inherited from the other repositories -- for example, users who have permission to access a particular SharePoint folder will have permission to access that folder in Salesforce Files, too. But this seems to require Active Directory Federation Services, which is not trivial to set up; support for third-party identity brokers like Ping and Okta will come later on.

Salesforce Chatter executive vide president Nasi Jazayeri also told reporters that Files will eventually offer read-write access to files, but it wasn't clear which repositories would support this or what the timeline would be for this feature.

At any rate, the takeaway is that Salesforce no longer expects to be an alternate repository for files. Instead, it's going to work with the repositories you already have.

Benioff speaks at TechCrunch Disrupt again next week. We can't wait to see what he says this time.

Matt Rosoff is the editorial director of CITEworld. Read Matt's bio

This story was originally published at CITEworld.


View the original article here

Sunday, 25 August 2013

Twitterers have their say on Steve Ballmer, Microsoft ... and Batman?

Computerworld - As reports on Steve Ballmer's plan to retire from his Microsoft CEO post raced across the Internet this morning, Twitter lit up with tweets poking some fun and hand wringing about the fate of Microsoft.

Microsoft Friday disclosed Ballmer's plan to retire from the company at some point in the next 12 months. Ballmer joined Microsoft in 1980 and has been CEO since 2000.

The announcement comes just weeks after Ballmer unveiled a "far-reaching realignment" of the company to hasten its move to become a devices and services business.

"We need a CEO who will be here longer term for this new direction," Ballmer wrote in an email to employees today.

The surprise announcement brought a burst of activity to Twitter -- Steve Ballmer and related hashtags have been trending high for hours. Many of the tweets gave Ballmer a verbal punch before he heads out the door.

"Was Ballmer the Vista of CEO's?" asked @jeffsussna. "Why is he leaving now? There's still something of the company left yet to ruin," added @linuxuser3. And @zoltandulac tweeted, "Steve Ballmer is actually now doing the best thing he can do for Microsoft - leaving!"

Others noted that the surge in Microsoft's share price following the announcement added some $560 million in value to Ballmer's 333.3 million shares of Microsoft stock as of early this afternoon.

"Looks like Ballmer finally figured out how to make Microsoft stock go up," tweeted @spolsky. Twitterer @ggoodale tweeted, "I can only hope my retirement announcement will be as profitable for me as Steve Ballmer's was."

Another tweet, this one from "Sorta like cheering when the long talker leaves the dinner party. Steve Ballmer will retire; stock rises," @profitandlaws noted.

Others took note that the announcement comes at the same time actor Ben Affleck was cast to play Batman in the Man of Steel sequel. "Why cant Ben Affleck replace Steve Ballmer instead?" tweeted @firasatdurrani.

Some twitterers also lauded Ballmer's work at Microsoft. "And you forget that Steve Ballmer was the sales guy that helped make Windows what it is in the first damn place," tweeted @robertmclaws.

Sharon Gaudin covers the Internet and Web 2.0, emerging technologies, and desktop and laptop chips for Computerworld. Follow Sharon on Twitter at Twitter@sgaudin, or subscribe to Sharon's RSS feed Gaudin RSS. Her email address is sgaudin@computerworld.com.

Read more about IT Leadership in Computerworld's IT Leadership Topic Center.

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

Wednesday, 21 August 2013

In their own words: Unix pioneers remember the good times

We caught up with the pioneers who brought us the Unix operating system and asked them to share some memories of the early days of Unix development.

Unix co-developer Ken Thompson worked at Bell Labs from 1966 until he retired in December 2000. He recalls this prank:

[ InfoWorld's Paul Venezia reveals the 9 traits of the veteran Unix admin. | Track the latest trends in open source with InfoWorld's Open Sources blog and Technology: Open Source newsletter. ]

"The Unix room was on the sixth floor at one end of Bell Labs. The cafeteria was on the ground floor about a quarter of a mile away. There were dozens of ways to walk to lunch. You could pick one of four or five staircases and any segment of the six floors. One day, we were walking through the fourth floor, which was being renovated. It looked like a bombed-out city. The walls and ceilings were open with pipes and wires hanging everywhere. I noticed that there were, what looked like, speakers throughout the ceiling. I had always wanted to tap into the Bell Labs PA system and thought this was a perfect chance.

[ALSO: The last days of Unix]

"At night, I examined the speakers more closely and discovered that they were not really speakers, but white noise transducers. I chased the wires back to a panel that contained the generator and amplifier. Without anything specific on my mind, I borrowed the keys to the panel, duplicated them and put them back. Months later, after the construction was all done, I discovered the keys in my desk and decided to investigate. The generator was active and the amplifier volume was set to 1. In the office area, I could hear the noise, but only because I knew it was there.

"OK, I started turning the volume up by one notch every week. I would walk through the office area at least once a week on the way to the cafeteria. By the time that the volume was up to 8, still no one had noticed it but, to me, it sounded like Niagara. Everyone in the offices was screaming at each other. At that point, I couldn't help but laugh. On questioning, I told my lunch buddies what was going on. The word spread like a virus and, the very next day, the panel was open and the amplifier was removed. I still have a mental image of two people sitting across a table from each other yelling at each other in a normal conversation."

Doug McIlroy remembers Unix co-developer Dennis Ritchie, who died in 2011:


View the original article here

Monday, 19 August 2013

Cyber criminals add new exploit for recently patched Java vulnerability to their arsenal

Cyber criminals were quick to integrate a newly released exploit for a Java vulnerability patched in June into a tool used to launch mass attacks against users, an independent malware researcher warned.

The exploit targets a critical vulnerability identified as CVE-2013-2465 that affects all Java versions older than Java 7 Update 25 and can enable remote code execution. The vulnerability was patched by Oracle in its June Critical Patch Update for Java.

[ InfoWorld's expert contributors show you how to secure your Web browsers in a free PDF guide. Download it today! | Learn how to protect your systems with Roger Grimes' Security Adviser blog and Security Central newsletter, both from InfoWorld. ]

The exploit was released Monday by security research group Packet Storm Security, which originally acquired it through its bug bounty program as a zero-day exploit -- an exploit for an unpatched vulnerability -- from a researcher whose name was not disclosed. Packet Storm publishes the exploits it acquires 60 days after it receives them, with permission from their authors, so other security professionals can use them to perform penetration tests and security risk assessments.

Two days after its release, the CVE-2013-2465 exploit was already integrated into so-called exploit kits, attack tools that infect computers with malware by exploiting vulnerabilities in outdated software when users visit compromised websites.

An independent malware researcher who uses the online alias Kafeine found a live installation of the Styx exploit kit, previously known as Kein, that is using the exploit.

From an attacker's perspective the exploit for CVE-2013-2465 is better than the exploit for CVE-2013-2460, another Java vulnerability also patched in June, that was recently integrated into a different attack toolkit called the Private Exploit Pack, Kafeine said Thursday in a blog post. That's because CVE-2013-2465 affects both Java 7 and Java 6 installations, while CVE-2013-2460 only affects Java 7, he said.

Oracle ended its public support for Java 6 in April and will no longer release security updates for it to all users. Despite this, Java 6 is still widely used, especially in enterprise environments.

A recent study by security firm Bit9 showed that more than 80 percent of Java-enabled enterprise computers have Java 6 installed on them. The most widely deployed Java version on those systems was Java 6 Update 20.

The latest publicly available version of Java 6 is Java 6 Update 45, which is also affected by CVE-2013-2465. The vulnerability was patched in Java 6 Update 51, but this version is only available to users who have extended support contracts with Oracle.

The fact that an exploit for CVE-2013-2465 is publicly available and has already been integrated in mass attack toolkits suggests that this vulnerability will soon see widespread exploitation. Users who have yet to upgrade to Java 7 Update 25 might want to do so as soon as possible.


View the original article here

Wednesday, 7 August 2013

One Direction Play With Their Dolls, Harry Styles Posts Video of Him and His Mini-Me

One Direction Rich Polk/WireImage

One Direction had a ball with their dolls!

At a private concert for their fans at the W Hotel in Westwood, Calif., Harry Styles, Zayn Malik, Liam Payne, Louis Tomlinson and Niall Horan came face-to-face with the 12-inch likenesses of themselves created by Hasbro.

And who can blame them for proudly posing for pics with them at Tuesday's event?  They're actually pretty good representations of the fab five.

PHOTO: Harry Styles wears a grill, American flag bandana and gold chains

Styles, in particular, seemed to be exceptionally fond of his miniature doppelgänger.

The guy did create a Vine video of his doll, after all.

And while we're not quite sure what to make of the rotating head in the clip, we're sure fans will nevertheless be pleased to see that he chose to make the plastic figure topless.

Sure, it's a doll, but it's still Styles, right?

PHOTOS: See more pics of the 1D boys


View the original article here