Showing posts with label problems. Show all posts
Showing posts with label problems. Show all posts

Wednesday, 18 September 2013

New Java feature aims to manage multiple version problems

Hoary versions of Oracle's programming language Java can be a security nightmare for organizations and a fever dream for hackers because those older releases often contain flaws -- patched in later editions -- that remain susceptible to exploitation by bad actors now.

The problem with running a new version of Java is that some apps important to a business's operation may not work with it. Oracle made an effort to address that problem with a new version of Java 7 made available this week.

[ Think you know Java? Test your programming smarts in InfoWorld's Java IQ test. | Master the latest in Java development with our JavaWorld Enterprise Java newsletter. ]

The new release, Java Update 40, implements changes announced by Oracle earlier this year. They include allowing network administrators to create a DRS (Deployment Rule Set) that defines which version of Java an app should use. Such definitions could allow critical internal apps to use older versions of Java, while forcing external apps -- those more likely to carry infections that exploit flaws in older editions -- to use the latest version.

In a company blog, Java Platform Group Product Manager Erik Costlow explained that the new release of Java is aimed at desktop administrators who manage a number of users and need to control version compatibility and default dialogs to specific company applets. It's also designed for Java and Web Start app developers, who should be aware of the role deployment rule sets play on users' desktops.

[See also: Java security woes to stay with businesses for a long time]

While Oracle's intentions with DRS are laudable, the implementation may be wanting. "It's not going to be an easy fix for anybody," Ross Barrett, senior manager of security engineering at Rapid7, said in an interview. "It's better than nothing. We had nothing before and now we have something very complicated and hard to manage.

"It's a first step," he added. "Hopefully they'll refine it."

Oracle did not respond to a request for comment.

What DRS attempts to do is give organizations control over employees' desktop apps. That can be a dubious goal. "It's noble and a good idea, but it's high in administration costs," NSS Research Director Chris Morales said in an interview.

He explained that for DRS to work an organization will need to know about all of the applications on employee desktops and the versions of Java required by those apps. Then, each desktop has to be configured with that information and maintained.

"Those are all problems with application control in general that makes it not work well in a dynamic environment," Morales said.

Although DRS has security ramifications, it's more of a deployment tool than a security tool. "If you look at the configuration necessary to deploy this, it's really targeting large organizations that need to maintain a very consistent application environment across their infrastructure," Alex Watson, director of security research at Websense, said in an interview.


View the original article here

Saturday, 24 August 2013

Connectivity issue caused trading problems, Nasdaq says

Nasdaq blamed the unprecedented trading halt Thursday on a "connectivity issue" between an exchange participant and its core Securities Industry Processor (SIP) system, used to consolidate and disseminate quote and trade information on Nasdaq-listed securities.

The connectivity problems degraded the ability of the SIP to disseminate consolidated quotes and trades, Nasdaq said in a statement. It added that the cause of the problem has been identified and addressed.

[ For quick, smart takes on the news you'll be talking about, check out InfoWorld TechBrief -- subscribe today. | Find out what topics and issues affect tech's biggest names and news makers in the IDGE Insider CEO interview series. | Read Bill Snyder's Tech's Bottom Line blog for what the key business trends mean to you. ]

The Nasdaq OMX Group today halted trading on all Nasdaq-listed securities at 12:14 p.m. because of the glitch. Trading did not resume until after 3:10 ET.

The outage affected more than 2,000 companies, including Google, Amazon, Microsoft, and Cisco. The Wall Street Journal's Market Watch described the trading freeze as affecting companies with a combined worth of about $5.7 trillion.

The SIP is part of system that enables other exchanges such as the New York Stock Exchange, Chicago Stock Exchange, and BATS Global Markets to trade in Nasdaq-listed securities. It is the single source of consolidated market data for Nasdaq-listed securities and provides continuous quotes and last sale information from all markets trading in Nasdaq-listed securities.

When Nasdaq ran into the connectivity problem Thursday afternoon it immediately issued a regulatory halt on all trading in Nasdaq-listed securities in order to protect the integrity of the markets, the statement noted.

It went on to add that the technical issues with SIP were identified and resolved within 30 minutes. "For the remaining period of time, Nasdaq OMX, other exchanges, regulators and market participants coordinated with each other to ensure an orderly re-opening of trading in Nasdaq-listed securities," the statement noted.

Trading resumed and finished in normal course at the end of the trading day, Nasdaq said. "Nasdaq OMX will work with other exchanges that are members of the SIP to investigate the issues of today, and we will support any necessary steps to enhance the platform," it said.

This is not the first time that Nasdaq has run into problems with the SIP. In January, the exchange briefly shut down trading while it investigated the cause for stale data on the system. The problem resulted in Nasdaq-listed trades not being recorded in real time.

The latest glitch comes even as the system is being modified to accommodate two new data sets, which are scheduled to go live in October.

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan or subscribe to Jaikumar's RSS feed. His e-mail address is jvijayan@computerworld.com.

See more by Jaikumar Vijayan on Computerworld.com.

Read more about networking in Computerworld's Networking Topic Center.


View the original article here