4 Tips for Writing a Great Social Media Security Policy

Facebook now claims 300 million active users. Naturally, social media growth has also been seen in the workplace, both with regard to employee use as well as functioning as a communication and/or marketing tool for some companies. And Twitter, the micro-blogging site that was almost unheard of at the beginning of 2008, is now one of the internet's 50 most popular sites, according to Alexa Internet Inc.'s web traffic statistics.

And according to a survey recently conducted by IANS, a Boston-based research company that focuses on information security, regulatory compliance and IT risk management, the number of enterprises with a social media policy in place has jumped dramatically, too, in just twelve months. The take away, according to Phillips, is that social media is front and center now in organizations and the discussion is taking place not only among the security team, but within marketing, sales, human resources and even executives. Also see The Seven Deadly Sins of Social Networking Security Jack Phillips, IANS co-founder and CEO, said when IANS conducted the same survey in 2008, the majority of respondents did not have a social media policy. "They really hadn't done the hard thinking," said Phillips. "But then jumping forward to 2009 we saw about a third of the audience now has something in place and another large percentage is considering these kinds of policies." Specifically, just under ten percent of respondent enterprises said their social media policy was fully implemented and communicated in 2008. That jumped to 34 percent in 2009, with another third responding that they had either created or implemented a policy for social media use. Phillips believes this is an opportunity for security folks to raise their profile and take part in an important issue from its inception. Instead, said Phillips, use this as an opportunity to draw attention to existing policies. "Most purists will say: This stuff isn't really new.

He shared with CSO four things he thinks organizations should consider when putting together policies and practices for use of Facebook, Twitter, Linked In and other social media within an organization. 1. Don't start from scratch The media landscape is so dynamic that if you create policy for today's hot technology, tomorrow it will be obscure. It should be part of our HR and acceptable use policies," said Phillips. "The same sort of norms apply to this new world that has applied to the world before today." (See How to Write an Information Security Policy for more on the basics of effective policy.) Phillips noted most of the organizations IANS polled with a social media policy already in place said they had not named specific medias because of changing pace of new media. "It's Twitter today, but it may be something else tomorrow," he said. 2. Use social media policies to raise security awareness "This issue is an opportunity for info sec leaders to refocus attention on information security and risk management, said Phillips. For instance, when compliance regulations came into play, savvy security teams were able to create new policies to comply, while also letting employees know why they were important. IANS is dispelling what Phillips says is age-old advice for enterprises when it comes to adapting to change. Same holds true this time around, said Phillips. "We are finding some innovative awareness tactics that focus on these technologies because they are front and center.

The percentages are so low in terms of success of awareness campaigns, this is an opportunity to jump in." 3. Use social media access to raise security's positive profile within the organization While the initial security reaction to new media is often to block, Phillips said most organization now need to consider that not only may allowing access be necessary, but also useful from an info sec perspective. A Twitter campaign, or a Facebook campaign, a Linked In campaign, can all have real impact in terms of receptivity. Also see Security Awareness Programs: Now Hear This! "The advice we have given is, instead of just knee-jerk blocking everything, we find that this as an opportunity to record usage and activity among the employee base," said Phillips. "When the original data-loss-protection technologies were introduced, they were not in blocking mode, but in monitoring mode." Phillips believes the new technology of social media gives information security what he calls "an interesting opportunity" to see how critical these technologies are to the enterprise. "That kind of information is quite useful to other functions of the enterprise," he said "Sales, marketing, HR are all going to be interested and that raises information security's profile among management." 4. Be prepared for the next phase As social media platforms come and go, some will ultimately become commonplace and integral to an enterprise. As it stands now, he said, he finds his clients are more comfortable with some mediums and with others; not so much. While creating entire new policies around social media doesn't make sense right now, at some point, said Phillips, it will become necessary for policies to be more specific.

Most organizations find Linked In to be the most controllable and with the least potential for damage. Particularly, said Phillips, because many employees are not respecting that line between personal and enterprise. "Because these technologies are so different, it is at some point we expect policies are going to have to get granular," he said. "Our sense is high-performing teams will have to create unique Facebook, Twitter, Linked In and Google Docs policies. But Facebook, with its security vulnerabilities, and the nature of its content, still makes many uncomfortable. And they are going to have to get that granular about what is appropriate and inappropriate with each tool. "We will end up with an open environment, but we will end up with some asterisks that say, it's open, but not 100 percent open. For example, some might say: 'It is not appropriate to use the company's name on your Facebook profile.'

Acadia, Cisco, EMC, VMware data center cloud unveiled

Cisco, EMC and VMware last week unveiled the much rumored joint venture to sell their products to companies wanting to build internal clouds. Vblocks will be sold by Cisco, EMC and VMware to their largest enterprise customers and through the channel by systems integrators, service providers and solution providers. Called Acadia (for who knows what reason), the joint venture is a collaboration between the three companies that will launch in 2010 and sell what they call Vblocks, preconfigured packages of Cisco UCS blade servers, EMC storage gear, VMware virtualization software and EMC Ionix management software.

Already the coalition of Cisco, EMC and VMware has inked deals with six integrators, six service providers and nine solution providers. The company Acadia, which is being formed as we speak, will hire its own CEO and is hiring sales representatives. At the moment, Vblocks are pr-built, pretested and preconfigured packages that include Cisco's recently announced UCS blade servers, the company's networking switches, EMC Symmetrix V-Max or Clariion arrays and VMware's vSphere virtualization software. No one yet knows (or they aren't talking about it) where the company will be based. Vblock's consists of three configurations: * Vblock 2 is a high-end configuration supporting up to 3,000-6,000 virtual machines that is targeted at large enterprises and service providers. Acadia has investments from Cisco, VMware and EMC and minority investments from Intel.

It uses Cisco's Unified Computing System (UCS), Nexus 1000v and Multilayer Directional Switches (MDS), EMC's Symmetrix V-Max storage and the VMware vSphere platform.* Vblock 1 is a midsized configuration supporting 800 up to 3,000 virtual machines that uses Cisco's UCS, Nexus 1000v and MDS, EMC's CLARiiON storage and the VMware vSphere platform.* Vblock 0 will be an entry-level configuration available in 2010, supporting 300 up to 800 virtual machines that uses Cisco's UCS and Nexus 1000v, EMC's Unified Storage and the VMware vSphere platform.

Facebook groups disrupted but not hijacked, Facebook says

A group calling itself "Control Your Info" appears to have taken control of several dozen Facebook groups, inserting its own logo and stating "Hello, we hereby announce that we have officially hijacked your Facebook group." 12 tips for safe social networkingWith a link back to a site, the apparent members - using the names "Bella Roregit," "Burstin Woltan" and "Janis Roukkos" - began leaving their mark on various Facebook groups intended for topics that include entertainment, business and sports. If we wanted, we could make you appear in a bad way which could damage you severely." According to the Control Your Info Web site, the group's mission is to bring attention to security weaknesses in social media. "Social media has become a natural part of most people's daily lives. The Control Your Info statements declared: "This means we control a certain part of the information about you in Facebook.

Unfortunately, the security aspects of social media have been more or less neglected." Control Your Info did not immediately respond to a request for comment about its activities. The groups in question have been abandoned by their previous owners, which means any group member has the option to make themselves an administrator in order to continue communication to the group. Facebook, however, has issued a statement about the incident that says, "There has been no hijacking and there is no confidential information at risk. Group administrators have no access to private user information and group members can leave a group at any time. The names of large groups cannot be changed nor can anyone message all members.

For small groups, administrators can simply edit a group name or info, moderate discussion and message group members. In the rare instances when we find a group has been changed inappropriately, we will disable the group, which is the action we plan for these groups." Some users in the groups affected by the Control Your Info takeover were obviously displeased about the turn of events and scornful of Control Your info's explanation about how it's making a point about security by taking control. "I have an idea, why don't I teach you about traffic safety by running you over with my car? wrote one irate Facebook user in a group that had been commandeered by Control Your Info. "Is that how it works? That's because the person who creates a group of this sort on Facebook is by default the administrator, and when this individual decides to abandon that by de-listing as the admin, anyone else in the group can step in to promote themselves be the administrator. Michael Sutton, vice president of security research at zScaler, said he doesn't think the Control Your Info takeovers constitute a major security concern. That's the way Facebook designed this type of group and is clear about it, though other types of Facebook groups, such as closed ones, have different security procedures.

In that case, the Control Your Info people simply did a search to discover the type of Facebook groups that had the administrator position abandoned, and stepped in with their dramatic hijacking routine. "This is really making a mountain out of a molehill," he said.

As driving summit opens, AT&T launches anti-texting campaign

AT&T Inc. announced a campaign today to warn cell-phone users, especially teens, about the dangers of texting while driving in advance of a federal Distracted Driving Summit that kicks off in Washington on Wednesday. AT&T will also revise its policies to expressly prohibit texting while driving for its employees who drive as part of their job. The carrier said it will put warnings about texting on phones it sells before the holiday season and on signs in its stores.

AT&T is one of the country's largest employers, with 290,000 workers. Information about the dangers of texting while driving is being included in defensive driving classes. U.S. Transportation Secretary Ray LaHood is expected to attend the two-day meeting as well as federal highway safety officials and researchers on cell phone use while driving. Public service announcements are also planned to bring home the message to the public. All the major wireless carriers have campaigns opposing texting while driving, although the companies vary on their views about laws banning the practice.

The campaign will be announced today by AT&T CEO Randall Stephenson at the Detroit Economic Club, AT&T said. "Our goal is to send a simple, yet vital, message to all wireless users: Don't text and drive," Stephenson said in a statement. AT&T and others carriers want to take advantage of the timing before the summit, which AT&T will attend and support. Pending in the U.S. Senate is a bill to require states to ban texting while driving or face the partial loss of federal highway funds. "We think the decision as to whether there is specific legislation required is up to the public and to their legislators," the spokesman said in an e-mail today. But an AT&T spokesman said the carrier has decided to let the public decide its position on proposed legislation. The bill, called the ALERT Driving Act , was introduced in July and would require states to ban drivers from sending text or e-mail messages or risk losing 25% of their federal highway funds each year they fail to comply. Verizon Wireless supports the legislation, while Sprint Nextel said it hadn't taken a position, but has long argued for better driver education to urge drivers not to text and drive.

AT&T said in July, before it had reviewed the ALERT legislation, that it was generally supportive of legislation prohibiting texting while driving, but did not explain its apparent shift today. The financial sanctions in the bill caused the Governors Highway Safety Association to oppose the measure. One recent study found that the risk of getting into an accident is 23 times higher when texting while driving. Currently, 14 states have various laws that ban texting while driving, which some research studies have found greatly impairs a driver's ability to drive safely. Some groups argue that more laws won't help.

Vlingo's view is that laws are hard to enforce, making hands-free technology all that more important. Vlingo Corp., which makes a mobile voice application, today released data from a survey of 4,800 people that showed little or no impact from state bans on driver behavior.

Google Street View Battle Highlights Privacy Challenge

Google is being sued by a Swiss watchdog agency for allegedly failing to take adequate measures to protect privacy. The debate in Switzerland is over Google's Street View image indexing. The legal battle in Switzerland is just the latest in a long line of privacy issues with Google and illustrates the challenge of providing as much information as possible without violating privacy concerns.

Hanspeter Thuer, the Swiss Federal Data Protection and Information Commissioner (FDPIC) made recommendations to Google to address concerns with Street View images displaying car license plates and people's faces. This isn't the first time Street View has gotten into trouble over privacy. Google claims it has taken strides to comply with those recommendations, but the FDPIC doesn't feel Google has done enough. Google has also faced backlash over Street View in the United Kingdom, Canada, Greece, and Japan. Greece is distressed by how long Google plans to maintain the Street View images in its database.

One concern in Japan, which has been echoed in Switzerland, is that the height of the car-mounted Street View cameras is capable of seeing over fences and into homes. Google's privacy issues are not restricted to the Street View images, though. Google recently launched a new feature allowing you to set up alerts that can notify you when a friend is nearby. Google Latitude, a GPS mapping and tracking service, keeps track of your location in real-time and maintains a mapped database of previous locations. The cool factor is tempered with a creepy Big Brother vibe. There are privacy issues related to Google Social Search, Google recently modified indexing of Gmail messages to address concerns over transcribed Google Voice emails showing up in the search engine, and even the embryonic Chrome OS has raised privacy concerns.

The list goes on and on. Google recently unveiled the Google Dashboard to address privacy concerns. But, the Google Dashboard itself also has privacy and security implications as well. The Google Dashboard displays all of the information associated with your Google profile, providing you with an at-a-glance resource to see just how much Google knows about you. It is a difficult balance for Google to manage.

Technology has brought us to the point where, unless you live in an unmarked cabin in the Rockies and live off the land, data about you is being indexed virtually everywhere. If you read books like Database Nation by Simson Garfinkel, or The Soft Cage by Christian Parenti, you come to the realization that privacy is largely an illusion at this point. Privacy is a myth. On the contrary, perhaps it suggests we need to be more vigilant about protecting what little privacy we might have left. That doesn't mean we should all just give up and accept that we have no privacy. Google has to struggle with the conflict of interest between indexing all of the data in the world, and protecting privacy.

My fellow PC World writer David Coursey has pointed out that Google has not yet done anything to lead us to believe it has evil intentions for our data, but the data is still there on the Google Servers. Not only that, but Google must also to tailor its indexing and business practices on a country by country basis to comply with local data protection and privacy regulations. Coursey ponders what might happen following another 9/11-caliber terrorist attack "Would Google provide information it has about suspects? If it did, how long would it be before we knew? Use its data and profiling capability to find more suspects?

And where, exactly, is the line between patriotism and invasion of privacy?" That is a valid question. Tony Bradley tweets as @PCSecurityNews, and can be contacted at his Facebook page . Google has to continue strike a balance between information and privacy, and users need to grasp that the convenience provided by Google's products and services comes at a cost.

Do collaboration tools enable collaboration?

At the recent IT Roadmap conference in Washington D.C. there was a panel discussion about how the younger generation uses tools such as texting to stay in touch with friends. Another implication was that as the younger generation enters the workforce, they will bring their collaborative approach with them to the workforce and this will drive the existing workforce to be more collaborative. One of the implications of the discussion was that the younger generation is more facile with collaboration than is the current workforce. We want to use this newsletter to express an alternative opinion.

However, most people that we know that are currently in the workforce also text – perhaps not as much as the younger generation, but they do. Ford driving Exchange 2010 into collaboration plans There is no doubt that the younger generation, the kids that are currently in grammar school and high school, are very facile with collaboration tools such as texting. Hence, we do not see that age is a barrier that keeps the current generation of workers from texting. In fact, in some cases, they seem to prefer to send texts back and forth vs. having a conversation. One concern that we have is that young people often use texting as an alternative to face-to-face communications.

Is this really collaboration or is it running away form collaboration? That is a form of collaboration – but a very low level form. Collaboration tools such as texting, instant messaging, and twitter are well suited to support a simplex or at best half duplex conversation, such as sending a text to inform someone that you will be late for a meeting. Let's set up a hypothetical situation. The company pulls together a project team comprised of people in different organizations, including someone from the WAN organization, from the software development group, security and compliance, and one or more business units. A company is considering using a software-as-a-service provider for some new application.

The various members of the team have different, and in some cases, conflicting goals.  For example, the people who represent the business units want to get the solution running as soon as possible; the security and compliance people are worried that they will not be able to pass an audit if the solution is deployed; the person from the software organization feels their organization is being bypassed, and the person from the WAN organization is concerned about how much extra traffic will now transit the WAN. The disparate goals of the project team members will not be resolved by sending text messages, IMs, or tweets. One IT professional we talked with told us that his organization had used traditional videoconferencing for years. That is not to say that there are not collaboration tools that can help. He added that he believes that telepresence is more powerful than traditional videoconference in part because the picture quality allows you to see body language and facial expressions as well as you could in person. It does, however, have a better chance of succeeding than a text that reads: OMG, c u @ 10:15.

Of course, telepresence does place a tremendous burden on the WAN. Just seeing body language and facial expression may not resolve the fact that the project team members have disparate goals.

Vendor group forms cloud storage initiative

The Storage Networking Industry Association (SNIA) announced today the formation of the Cloud Storage Initiative (CSI) in order to establish a lexicon of cloud-computing terminology, publish use cases, white papers and technical specifications, and to create reference implementation models for grid-storage architectures. The organization also plans to perform market outreach highlighting the virtues of cloud storage. The CSI will coordinate and deliver educational materials for cloud storage vendors and user communities. The group is developing a single specification as part of its efforts.

The SNIA made the announcement at the Storage Networking World conference, which is co-sponsored by Computerworld . "Part of the challenge with cloud is where does the data live? The Cloud Data Management Interface (CDMI) will be an application programming interface to which vendors can write management software that will allow interoperability between heterogeneous cloud storage offerings, according to Wayne Adams, SNIA's chairman emeritus. And how are you able to manage it once it's in the cloud, and can you get it back in the same format that you now have," said Mark Carlson, a SNIA Technical Council member said. "There's this idea of how portable is my data that once I get it out there can I get it back in a format that can be ingested by another vendor?" Carlson said the CSI will focus on disseminating information about technology to build both public cloud service, such as Amazon's S3 service, and private cloud architectures in data centers. The CSI will complement the technical innovation and de velopment from the SNIA Cloud Storage Technical Working Group , which has more than 140 members representing over 50 commercial vendors, service providers and educational institutions. CSI published cloud storage cases and requirements for cloud storage in June.

The CSI will aid the Technical Working Group in bringing specifications and technical developments to international standards development organizations. It is also releasing a joint white paper with the Open Grid Forum (OGF) focused on cloud storage for cloud computing all developed by the working group. "It's both encouraging and timely to see this new initiative from SNIA," said Simon Robinson, research director of storage for research firm The 451 Group. "It's gratifying to see this co-operative effort around standards and education, since those are two of the current impediments to fast adoption as technologies mature and become integrated into more vendor offerings." For example, the CSI will promote and deliver a new cloud storage tutorial to be unveiled at Storage Networking World this week.

Restaurants sue vendors after point-of-sale hack

When Keith Bond bought a computerized cash register system for his Broussard, Louisiana, restaurant, he thought he was modernizing his restaurant. His story reads like a warning for small businesses, who in connecting their businesses to the Internet, have also become prey for sophisticated cyber-criminals. Today, he believes he was unwittingly opening a back door for Romanian hackers who have now cost him more than US$50,000. Bond's is one of more than a half-dozen Louisiana restaurants that have sued the makers of their point-of-sale system, alleging that the companies that made and resold the systems are the ones who should be responsible for fines levied by payment processors following the hack.

Bond says that systems at his Mel's Diner, Part II, were hacked, along with several other restaurants in the region, sometime around March 2008. Investigators told him that the systems were compromised by Romanian hackers who used the devices' remote access software to steal credit card numbers from the systems. The criminals took those credit card numbers and then used them to make fraudulent purchases throughout the U.S., he said. This software let Bond's reseller, Computer World, provide remote support to the systems. In the class-action lawsuit, Bond and the other plaintiffs allege that their point-of-sale systems were out of compliance with the Payment Card Industry Data Security Standard (PCI DSS), which defines how secure the big credit card companies expect their merchants' computers to be. He was then assessed tens of thousands of dollars in fines and chargeback fees generated by the 699 credit card numbers that were stolen from his three point-of-sale devices. "Our clients are restaurants," said Bond's lawyer, Charles Hoff, in a statement. "They are food experts, not technologists.

Bond and others blame the maker of his Aloha point-of-sale system, Radiant Systems, and its Louisiana reseller, Computer World (Computer World is not related to IDG's ComputerWorld magazine). After the hack, Bond had to spend close to $20,000 to audit his systems. When major players in the hospitality industry such as Radiant Systems and its distributors say their software and business practices are PCI-DSS compliant, our clients trust them." The class-action lawsuit was filed in October but was not widely known until the privacy blog DataBreaches.net disclosed it last week. Citing company policy, a Radiant spokeswoman declined to comment on the lawsuits, but in an e-mailed statement, she said that the company believes that the allegations are without merit. "These customers were victims of criminal acts almost two years ago. Another similar lawsuit was filed against Radiant and Computer World in April by plaintiffs in Georgia. Unfortunately, in today's world criminal acts like these are not uncommon in the restaurant industry," the statement read.

There's no level of responsibility with the processor, the reseller or with Visa Mastercard. Bond doesn't buy that. "You're buying an expensive point-of-sale system," he said. "But when you're compromised, Visa and Mastercard come after the merchant. So the merchant is the person who is suffering." The lawsuit claims that Visa warned Radiant and Computer World that they were not PCI compliant the year before the hack, but that merchants were never notified of these problems, even though they were the ones who ultimately had to pay big fines. The alert warned Aloha users to disable a Remote Desktop feature on their equipment if it's not being used to provide remote support to the point-of-sale system. That's a real problem, said Avivah Litan, an analyst with the Gartner research firm. "Merchants should be notified directly when Visa or MasterCard issue alerts about non-compliant software," she said in an e-mail interview. "Restaurants are in the business of selling food; they should not be expected to be experts in the intricacies of credit card processing certification processes, especially when they are not even privy to most of the communications surrounding them." Radiant warned about the problem, according to a security alert posted by a San Francisco Bay Area Radiant reseller.

The plaintiffs in Bond's lawsuit say they received no such alert. According to Bond, Computer World used this Remote Desktop feature to access his systems. Computer World did not respond to a request for comment on this article. To make matters worse, Computer World had set up his and other restaurants with the same default password: "Computer," Bond said.

Lawsuit claims HP PCs suffer constant lockups, crashes

A Colorado man has sued Hewlett-Packard, saying that its Pavilion Elite desktop computers are "inherently defective," and constantly lock up within 10-20 minutes of use. Pegatron Technology is a subsidiary of Taiwan-based Asustek Computer, which is best known for its ASUS line of netbooks. "After operating the [Pavilion Elite] e9150t for approximately two weeks, Plaintiff's computer began experiencing repeated disruptive failures including lock-ups, freezes, and blue screen errors, requiring him to reboot the computer," read the suit, which was filed on behalf of Michael Kent of Arvada, Colo. The lawsuit, which was filed with a California federal court last Thursday, seeks class-action status that, if granted, would open the case to all HP customers who have purchased one of the allegedly defective PCs. According to the lawsuit, HP's Pavilion Elite e9150t, e9180f, e9180t, m9600t and m9650f, when equipped with the "Truckee" motherboard from Pegatron Technology and Intel's i7 quad-core processor, crash or lock up soon after they're powered on.

Kent purchased the Pavilion Elite e9150t in late July 2009. "Since that time, Plaintiff experiences the aforementioned errors on an almost daily basis. Kent's lawyers cited 20 messages posted on an HP support forum as proof that others have complained of the same problem. These errors occur most frequently within 10 to 20 minutes after a 'cold boot,'" the lawsuit continued. The lawsuit also included a link to a support thread that as of Monday ran 288 pages, and boasted nearly 2,900 messages submitted by customers. Others on the thread said that although HP had replaced either the CPU or the entire computer, they were still seeing frequent crashes or lock-ups of the Pavilion. "Even though HP is replacing the e9150t models with the upgraded e9180 models and including faster, more costly processors, the computers still exhibit the same defects," Kent's lawsuit read. The thread is the most-heavily-trafficked of all those on the HP support forum dedicated to lockups and freezes . On the Pavilion Elite e9150t lock-up thread, users said that they had tried several different HP-suggested remedies, including installing a BIOS update, a tack Kent claimed he also tried to no avail.

Users continued to post messages on the support forum today. "I hereby give up with HP 'support,'" said a user identified as "GaryJ51," in a message added to the thread Monday morning. "After dozens of calls to HP, and many broken promises, I eventually wrote to the CEO as suggested by someone on this site. My unreliable PC is still ... here, waiting for a returns box. Nothing. It's many weeks now since I began this effort to fix the thing. I don't know what else to do." "I just received a call from a Case Manager Supervisor," added "Hanspuppa" in a message posted shortly after GaryJ51's. "I explained all my issues with the two systems I purchased, and requested the defective systems be replaced with new systems, and she denied my request. $3,500.00 down the drain." Kent's lawsuit charged HP with deceptive advertising, fraud and breach of warranty, and asked the federal judge to grant the case class-action status, as well as to force HP to pay compensatory and statutory damages.

I give up. HP did not respond to a request for comment.

Microsoft's CodePlex Foundation leader soaks in stinging critique

After a stinging critique from a noted expert in establishing consortia, the leader of Microsoft's new CodePlex Foundation says such frank evaluation is welcome because the open source group's structure is a work in progress. The CodePlex Foundation's aim is to get open source and proprietary software companies working together. Sam Ramji, who is interim president of the CodePlex Foundation, was responding to last week's blog by Andy Updegrove, who said the group has a poorly crafted governance structure and looks like a sort of "alternative universe" of open source development.

Updegrove, a lawyer, noted expert on standards, and founder of ConsortiumInfo.org, laid out in a blog post five things Microsoft must change if it wants CodePlex to succeed: create a board with no fewer than 11 members; allow companies to have no more than one representative on the Board of Directors or Board of Advisors; organize board seats by category; establish membership classes with rights to nominate and elect directors; and commit to an open membership policy. He added, however, "There are some best practices [for running the boards of non-profits] that we are not as familiar with as we would want to be." Slideshow: Top 10 open source apps for Windows  Stephanie Davies Boesch, the foundation's secretary and treasurer, is the only board member with experience sitting on a non-profit's board. Despite the stinging tone in Updegrove's assessment, Ramji says he is thankful for the feedback. "Andy's been incredibly generous with his expertise and recommendations," Ramji says. "It is the kind of input and participation we were hoping to get by doing what is probably non-traditional for Microsoft but not necessarily non-traditional for non-profit foundations, which is to basically launch as a beta." For instance, Ramji says that the decision to go with only five people on the board came from Microsoft's experience that larger groups often have difficulty with decision making. Ramji says Updegrove's suggestion to have academic representation on the board was "outstanding. And basically it is re-writable.

We did not think of that." And to Updegrove's point on becoming an open membership organization, Ramji says, "our goal is to become a membership organization and Andy has some excellent recommendations for that."He says the fact that Updegrove took the time to respond "in the format that he did is more proof that there is something worth doing here." Ramji, compares the Foundation's formation to the early days of a software development project. "We have said in these first 100 days we are looking at everything as a beta. Obviously, there are some areas like contributions and licensing agreements we put a lot of time into but even those can be modified." Microsoft announced the foundation Sept. 10 with a stated goal "to enable the exchange of code and understanding among software companies and open source communities." The company seeded the group with $1 million and Microsoft employees dominated the interim board of directors and board of advisors. One is a call for a broad independent organization that can bridge cultural and licensing gaps in order to help commercial developers participate in open source. Ramji says the foundation has spent the past couple of weeks listening to feedback in "Twitter messages, email, and phone calls in order to understand what people hope this can be." Within that feedback two patterns have emerged, Ramji says. The other focuses on creating a place where open source .Net developers can gain strong backing. "Look at projects related to Mono, you also can look at NUnit, NHibernate, we really feel optimistic that the Foundation could help them gain a higher level of credibility in the open source community. Miguel de Icaza, the founder of the Mono project and the creator of the Gnome desktop, is a member of the Foundation's interim board of directors.

They feel they have been lacking that strong moral support," Ramji says. From a high level, Ramji says the Foundation stands as a sort of enabler that helps independent developers, companies and developers working for those companies navigate the nuances and practices of open source development so they can either contribute source code to projects or open source their own technologies. "One suggestion has been that the Foundation should house all the best practices we have seen software companies and open source communities use," said Ramji. "We want to have a place where everyone interested in how to participate can come and read and if they choose they can use our license agreements or can use the legal structure of the Foundation to grant patent licenses and copyrights for developers and derivative works." Those licensing agreements have a distinct focus, Ramji said, on the rights that are related to code that is being contributed and on how to contribute the patent rights on that code. Ramji says the goal is to service multiple projects, multiple technologies and multiple platforms rather than having one specific technology base, which is how most current open source foundations are structured. "It's early days and we have received a lot of good ideas from experts in a variety of fields from law to code to policy that is what we had hoped for," says Ramji. "Someone wrote it is nice to see Microsoft engaging early on without all the answers and to have the community solve what they would like to see. Once those issues are settled, code would be submitted using existing open source licenses. That is satisfying for me and refreshing to others.

This is the right way to proceed." Follow John on Twitter

The six greatest threats to US cybersecurity

It's not a very good day when a security report concludes: Disruptive cyber activities expected to become the norm in future political and military conflicts. From the GAO: "The growing connectivity between information systems, the Internet, and other infrastructures creates opportunities for attackers to disrupt telecommunications, electrical power, and other critical services. But such was the case today as the Government Accountability Office today took yet another critical look at the US federal security systems and found most of them lacking.

As government, private sector, and personal activities continue to move to networked operations, as digital systems add ever more capabilities, as wireless systems become more ubiquitous, and as the design, manufacture, and service of information technology have moved overseas, the threat will continue to grow. " Within today's report, the GAO broadly outline the groups and types of individuals considered to be what it called key sources of cyber threats to our nation's information systems and cyber infrastructures. According to the Director of National Intelligence, a growing array of state and nonstate adversaries are increasingly targeting—for exploitation and potential disruption or destruction—information infrastructure, including the Internet, telecommunications networks, computer systems, and embedded processors and controllers in critical industries. From the GAO: Foreign nations: Foreign intelligence services use cyber tools as part of their information gathering and espionage activities. Criminal groups: There is an increased use of cyber intrusions by criminal groups that attack systems for monetary gain. While remote cracking once required a fair amount of skill or computer knowledge, hackers can now download attack scripts and protocols from the Internet and launch them against victim sites.

Hackers: Hackers sometimes crack into networks for the thrill of the challenge or for bragging rights in the hacker community. Thus, attack tools have become more sophisticated and easier to use. These groups and individuals overload e-mail servers and hack into Web sites to send a political message. Hacktivists: Hacktivism refers to politically motivated attacks on publicly accessible Web pages or e-mail servers. Disgruntled insiders:The disgruntled insider, working from within an organization, is a principal source of computer crimes.

The insider threat also includes contractor personnel. Insiders may not need a great deal of knowledge about computer intrusions because their knowledge of a victim system often allows them to gain unrestricted access to cause damage to the system or to steal system data. Terrorists: Terrorists seek to destroy, incapacitate, or exploit critical infrastructures to threaten national security, cause mass casualties, weaken the U.S. economy, and damage public morale and confidence. The Central Intelligence Agency believes terrorists will stay focused on traditional attack methods, but it anticipates growing cyber threats as a more technically competent generation enters the ranks. However, traditional terrorist adversaries of the United States have been less developed in their computer network capabilities than other adversaries. Testifying before the Senate Judiciary Committee, Subcommittee on Terrorism and Homeland Security today, FBI Deputy Assistant Director, Cyber Division said that while the FBI has not yet seen a high level of end-to-end cyber sophistication within terrorist organizations, it is aware of and investigating individuals who are affiliated with or sympathetic to al Qaeda who have recognized and discussed the vulnerabilities of the U.S. infrastructure to cyber attack; who have demonstrated an interest in elevating their computer hacking skills; and who are seeking more sophisticated capabilities from outside of their close-knit circles. "In addition, it is always worth remaining mindful that terrorists do not require long term, persistent network access to accomplish some or all of their goals.

The likelihood that such an opportunity will present itself to terrorists is increased by the fact that we, as a nation, continue to deploy new technologies without having in place sufficient hardware or software assurance schemes, or sufficient security processes that extend through the entire lifecycle of our networks," Chabinsky said. Rather, a compelling act of terror in cyberspace could take advantage of a limited window of opportunity to access and then destroy portions of our networked infrastructure.

Cyberattacks on U.S. military jump sharply in 2009

Cyberattacks on the U.S. Department of Defense - many of them coming from China - have jumped sharply in 2009, a U.S. congressional committee reported Thursday. That's a big jump. Citing data provided by the U.S. Strategic Command, the U.S.-China Economic and Security Review Commission said that there were 43,785 malicious cyber incidents targeting Defense systems in the first half of the year.

In all of 2008, there were 54,640 such incidents. The committee is looking into the security implications of the U.S.' trade relationship with China. If cyber attacks maintain this pace, they will jump 60 percent this year. It released its annual report to Congress Thursday, concluding that a "large body of both circumstantial and forensic evidence strongly indicates Chinese state involvement in such activities." "The quantity of malicious computer activities against he United states increased in 2008 and is rising sharply in 2009," the report states. "Much of this activity appears to originate in China." "The cost of such attacks is significant," the report notes. Attacks on department systems have been rising steadily for years.

Citing data from the Joint Task Force-Global Network Operations, the report says that the military spent $100 million to fend off these attacks between September 2008 and March 2009. A Defense Department spokesman did not have any immediate comment on the report's numbers Thursday. In 2000, for example, only 1,415 incidents were reported. The department figures are "probably more accurate now," than they were nine years ago, he said. The increase is in part due to the fact that the U.S. military is simply better at identifying cyberthreats than it used to be, said Chris Poulin, the chief security officer of Q1 Labs, and formerly a manager of intelligence networks within the U.S. Air Force. Security experts have long known that many computer attacks originate from Chinese IP (Internet Protocol) addresses, but due to the decentralized nature of the Internet, it is very difficult to tell when an attack is actually generated in China, instead of simply using Chinese servers as a steppingstone. Who knows.

Q1's Poulin says that his company's corporate clients in the U.S. are seeing attacks that come from China, North Korea, and the Middle East. "We do definitely see patterns coming from specific nation states." He said that because China's government has taken steps to control Internet usage in the country, it could probably throttle attacks if it wanted to. "China's defiantly initiating attacks," he said. "State-sponsored? But they're certainly not state-choked."

HP's history of billion-dollar technology buys

HP's news that it would lay down $2.7 billion to acquire network switch maker 3Com not only causes industry watchers to look ahead at what could come of such a deal, but also reminds many of the IT vendor's long history of billion-dollar acquisitions. This way HP will also be able to run its next-generation data centers on 3Com networking equipment. Hottest tech M&A deals of 2009 3Com HP announced on Nov. 11 it would pay big bucks to add 3Com's Ethernet network switches, routers and security products to its ProCurve business. The deal also strengthens HP's converged data center product portfolio vs. that of Cisco and its partners. "It gives HP a core switch - a brand-new core switch," said Steve Schuchart of Current Analysis of 3Com's H3C 12500, which the company is pitting against Cisco's Nexus 7000. "It gives them a real platform to move forward with," Schuchart said in an interview with Network World Senior Editor Jim Duffy, adding that the HP ProCurve 8212 and 5400 series switches didn't really cut the mustard for core applications. "This is newer, bigger and a much more purpose built switch." EDS About 18 months ago in spring 2008, HP announced it would invest $13.9 billion in exponentially expanding its global IT services business via the acquisition of EDS. Aiming squarely at IBM, HP's EDS buy pushed the IT vendor quickly up the list of services providers to land behind IBM as the second largest global outsourcing company worldwide.

He explained that if IBM Global Technology Services is working with a client at the services level, there is more of a chance the customer will buy IBM technology. At the time, industry watchers speculated that HP not only wanted to enhance its services business but also potentially sell more data center equipment via outsourcing deals. "IT services are a big and strategic part of the marketplace and they influence technology purchases downstream," said Ben Pring, research vice president at Gartner, at the time of the deal. If HP can get its foot in the door with more services customers, hardware and software sales could follow. "If HP had a bigger professional services umbrella and footprint, they would get greater access to a very strategic marketplace," Pring said. HP's net gain included automation technology that could be applied to configuring and provisioning physical and virtual components across network, system, storage and application components in a data center. Opsware In 2007, HP paid what some industry watchers said was too much money for data center automation darling - and Marc Andreessen offspring - Opsware.

The acquisition was one of the first significant moves by one of the four market leading management software makers to incorporate broad automation technologies across their product portfolios. "The next big step for the big four management vendors [BMC, CA, HP and IBM] is a move into automation in the areas of active configuration management and dynamic resource allocation. BMC and CA will have to almost spring into the market with a fully shaped technology through acquisition." In fact, HP spending $1.6 billion for the automation software company had the indirect effect of upping the price for Opsware competitor BladeLogic,which BMC later acquired for $800 million. It will be a big disruptive play and a defining technology when they move into automation technologies," said Will Cappelli, a research vice president at Gartner, in an interview with Network World at the time of the deal. "It will be more of a challenge for BMC and CA than for HP and IBM because the latter have server and storage technologies from which they can incrementally grow. Mercury Interactive One of HP's initial moves to broaden its niche network management software, known as OpenView at the time, into a larger IT management software suite involved paying $4.5 billion to buy application management vendor Mercury Interactive. The technology Mercury offered addressed applications from development to quality testing to performance on production networks and would boost HP's management play beyond its OpenView Network Node Manager and Operations products. "None of those deals have been large enough to significantly impact HP's software revenue. HP had been on a buying binge of sorts snapping up smaller management software makers such as Peregrine Systems, Novadigm and Consera Software, but those vendors didn't promise the revenue increase that Mercury could offer, analysts said at the time.

The Mercury acquisition really bumps up HP's software business to where a significant portion of their revenue will now come from software," said Rich Ptak, co-founder and principal analyst at Ptak, Noel & Associates at the time the acquisition was made public. The Mercury buy was expected to increase that to more than $2 billion annually, according to HP. In 2008, HP's software revenue  had reached more than $3 billion. In 2005, HP reported net revenue of $1 billion from its software business. Compaq HP's bid to acquire Compaq in 2002 garnered much industry speculation and concern from customers, but ultimately the two companies came together with their separate computer, printer and server businesses for about $25 billion. At the time, Gartner suggested HP faced many challenges in terms of the respective companies' business and how they might be spun out or eliminated to ensure success going forward. "Both HP and Compaq depend on tactical partnerships with outside vendors to meet their customers' software infrastructure requirements," Gartner concluded. With regulatory approval concerns, product support worries and what was tagged a "sour PC market" at the time, HP received much negative press surrounding its bid for Compaq.

Gartner also said at the time that HP and Compaq didn't have a strong track record in the software infrastructure arena, contrary to CEO Carly Fiorina's assertion that the new HP will set the standard for innovation; and that HP will have to spin off its software businesses to take any kind of lead in the software arena. The deal soon soured for HP, which reported less than five years later losing $48 million in its VeriFone software business. VeriFone In 1997, HP paid about $1.2 billion to acquire e-commerce and smart-card technology maker VeriFone to help customers in the financial services and other industries advance Internet-based business. In 2001, HP sold its VeriFone assets to Gores Technology Group. Follow Denise Dubie on Twitter here.   Do you Tweet?

Pantone releases iPhone App

If you're a designer whose inspiration strikes while you're on the go, Pantone has a new iPhone app for you: myPantone. The app provides the sRGB, HTML, and LAB values on each color swatch, and its cross referencing system lets users identify colors across color libraries. The app gives graphic, multimedia, fashion, interior, and industrial designers the tools to capture, create, and share Pantone color palettes while they're riding the bus to work, waiting on line at the supermarket checkout, or anywhere they happen to be. "MyPantone gives designers the freedom to access Pantone colors anywhere, without the need to be in their office or carry around cumbersome guides," said Andy Hatkoff, vice president of technology licensing for Pantone. "Now with myPantone's Portable Color Memory in their pocket, designers no longer need to agonize trying to recall an exact color." MyPantone gives designers access to all the Pantone color libraries, including the Pantone Matching System for coated, uncoated, and matte stock; the Pantone Goe System for coated and uncoated stock; Pantone Pastels for coated and uncoated stock; and the Pantone Fashion + Home Smart Color system. In addition, myPantone facilitates creation of harmonious color palettes by finding complementary, analogous, and triadic combinations for selected colors.

Once you create a color palette, you can view or share it with others. And, the app can extract colors from any image stored in your iPhone's camera roll or let you choose individual colors from an iPhone photo and match them to specific Pantone colors. For viewing color chips, you can use Pantone's slate of built-in backgrounds or you can use one of your own photos as a background. You can attach text notes or voice annotations, as well. Sharing options include sending color palettes via e-mail, sending palettes to other iPhone users, and sharing via Facebook or Twitter.

You can e-mail palettes as color patches, or as application swatch files for use in Adobe Creative Suite, CorelDraw, and QuarkXPress. MyPantone is available for $10 at the iPhone App Store. Designers can also share their color palettes with other designers by sending them to Pantone's hosted Web site. It is compatible with iPhone OS 3.0 or higher and can also be used with the iPod Touch.

SANS official talks security

This is the second of two parts of an interview of Stephen Northcutt by technologist David Greer. How do you see the evolution of the problem space of information security? Everything that follows is by Messrs Greer and Northcutt with minor edits. (See part 1.) * * * DG: It seems like many of the current security issues are problems that we have been dealing with for decades.

SN: Twelve years ago, we were standing up for a cyber capability for the United States. We do make progress; for instance we now have the Cyber Guardian program and have already graduated the first class. All the things we are saying today and the stuff we are doing to our cyber capability I heard 12 years ago. The attack surface just continues to get larger and larger and larger. We are more connected, so there's a lot more vulnerability points because we are increasingly connected and more code is exposed to potential attacks. So we're dealing with more lines and more kinds of codes.

We are not dealing with that many fundamental problems. There is an ever-greater need for security people who can integrate with the business. The specifics are changing, but the classes of the problems haven't changed very much. I was just trying to explain to someone that the No. 1 thing a manager wants out of a security person is communication skills. Our challenge is to develop people's communications skills. We've done survey after survey after survey.

You can't do business without communication. If we don't put a tremendous amount of attention and simplify, simplify, simplify, we end up with things we cannot manage. I would also say that my personal observation is that people often think complexity is its own reward. This is true on the security level, technology level and organization-process level. SN: A couple of years back I spent some time with the trade organization that represents the 100 largest banks in the U.S. We were trying to do some work around information security risk. DG: How do you see evaluating and managing risk in the security environment today?

More than once I heard the finance guys say "You information security folks have no idea what you're doing in terms of risk management. In finance we know for any set of financial transactions within a few dollars of what our risk is." One of those quants was in the risk management department at Bear Stearns which is gone now. You are using qualitative methods when you need quantitative. The finance folks have an advanced terminology and methodology. We need to make sure in information security we are never arrogant and that we make every effort to present risk to senior management in such a way that they can govern wisely.

I am sure senior management were briefed on the risks, but because house prices and stock prices kept going up they thought this incredible risk of bubble deflation was an acceptable risk and they found out they were wrong. I think there are three parts to that. 1. Start using metrics to measure and quantify risk. Instead of just saying "We might get hacked," we should explain the financial cost of a data breach or the destruction or manipulation of our data.3. Finally, we need to present the information well and at the management level. There are several books such as Andrew Jaquith's "Security Metrics: Replacing Fear, Uncertainty, and Doubt" and W. Krag Brotby's "Information Security Management Metrics: A Definitive Guide to Effective Security Monitoring and Measurement"; tools such as security information and event management (SIEM) and vulnerability management products that are internally consistent provide a quantitative score.2. We need to describe risk in terms of the business objectives. I know that is a strength of the MSIA program at Norwich.

DG: As we move toward cloud computing do you see these risks increasing? I think every security person needs to read "The Exceptional Presenter: A Proven Formula to Open Up and Own the Room" by Timothy J. Koegel and "The Cognitive Style of PowerPoint: Pitching Out Corrupts Within" by Edward R. Tufte once every 18 months or so and struggle to apply that information to our lives.

MS won't punish users for switching to hosted software

Microsoft's licensing of internal versions of software vs. their online counterparts won't penalize users for buying on-premises licenses and then switching to online hosted software, according to CEO Steve Ballmer. Ballmer, in a meeting with Network World at the annual SharePoint Conference, said moving between enterprise applications like SharePoint and Exchange deployed internally to versions of that software operated in the cloud by Microsoft will be "seamless." "Customers are saying give me some credit here, this is more like an upgrade than it is like a new buy, give us a little credit,"he said. Ballmer says Sidekick episode 'not good,' but Microsoft ensuring that its online services won't make the same error. Users have been questioning whether they can move licenses online without having to take a credit and renegotiate with Microsoft on licensing terms. "I know it will take them time to get it straight; it is really complicated," said Guy Creese, an analyst with the Burton Group. "They claim software plus services as a mantra and if that is true they need to make it so these two environments [cloud and on-premises] are seamless [from a licensing perspective]." Ballmer said users need to break it down by separating Internet and intranet deployments from cloud and on-premises. "Internet stuff we do is all priced basically per application or per server and it will be priced that way whether it is offered in the cloud, as a service or on-premises," he said. "I think that is pretty clean and I think that is the way that people would like to see things licensed." He said intranet applications are essentially priced by the number of users and that fact is true whether it is in the cloud or on-premises. "So one is user-based and one is application based." But Ballmer said Microsoft will be flexible in the way the company prices cloud versus on-premises.

For example, if a user has a client access license for SharePoint running internally but decides he wants Microsoft to run SharePoint in the cloud, the customer only pays to have Microsoft operate the SharePoint service. "You don't need to convert [the license], you can use your on-premise license and just buy the service capability; that you can do." If you want to transition you can do that too but most of our customers say just let me use the license that I already bought and have you operate this thing for me." Follow John on Twitter: twitter.com/johnfontana He said users that want to come to the cloud can buy the service and use the license they own or they can start in the cloud and buy an integrated license that pays for both the service Microsoft operates and the license. "We designed it to be seamless, in a sense it looks more complicated now because you have two choices." "We have a big enough install base of people that bought licenses that say, 'Hey, when we buy your service we don't want to be re-buying what we have already paid you for in terms of software.' We have to recognize that our customers expect a transition step where we give them credit for the software that they already own," he said.

Apple leaves Chamber of Commerce, citing green policies

Don't look for any Apple executives at the next U.S. Chamber of Commerce mixer wearing any of those "Hello, My Name is..." stickers. The trade group has been a very vocal opponent of current legislative efforts to reduce greenhouse gasses Apple's resignation comes in the wake of comments last week from Chamber of Commerce president Thomas J. Donohue who said that his group supported federal legislation to reduce carbon emissions but criticized a bill passed by the House of Representatives this summer "because it is neither comprehensive nor international, and it falls short on moving renewable and alternative technologies into the marketplace and enabling our transition to a lower carbon future." That was apparently the final straw for Apple, which has made a strong push to reduce the environmental impact of its products in recent years. The computer maker has resigned its membership in the business trade organization, citing opposition to the U.S. Chamber of Commerce's stance on greenhouse gasses. In a letter to Donohue, Catherine A. Novelli, the company's vice president of worldwide government affairs wrote: As a company we are working hard to reduce our own greenhouse gas emissions by relying on renewable energy at our facilities and designing more energy-efficient products for our customers. ... For those companies who cannot or will not do the same, Apple supports regulating greenhouse gas emissions, and it is frustrating to find the Chamber at odds with us in this effort.

The Washington Post reports that three other companies have pulled out of the group because of its climate policy-Pacific Gas and Electric, PNM Resources, and Exelon. Apple's not the only company to part ways with the U.S. Chamber of Commerce over this issue. A fourth company, Nike, resigned from the Chamber of Commerce board, but remains a member. [Hat Tip: SFGate.com's Bottom Line blog]

TwitterPeek: The World's First Twitter-only Device

Mobile e-mail device maker Peek has partnered with Twitter to bring you the world's first dedicated Twitter device: TwitterPeek. TwitterPeek features a 2.7-inch by 4-inch color screen, a full QWERTY keyboard, and no-contract nationwide unlimited wireless coverage. The new handset lets you send and receive tweets and direct messages, follow new users, and view images sent via Twitpic. Available now from Amazon or TwitterPeek.com, this Twitter-only handset sells for $100. That price includes six months of free wireless service; monthly access will set you back $7.95 per month after that.

What TwitterPeek doesn't have From the sounds of it TwitterPeek leaves a lot to be desired. Big spenders, though, can pay $200 up front for TwitterPeek and get lifetime wireless coverage. TwitterPeek allows you to send and receive tweets, but lacks a search function. TwitterPeek is also lacking a Web browser, which means you'll be left out of any conversations happening around a particular blog post or news item. So if plan on using this device to track tweets about your business, you will miss out on any conversations using hashtags-a user-created system of cataloging tweets by subject-or other conversations that don't include an @reply to your company's Twitter account. So a tweet like, "Dog Lovers - you'll Dig this! bit.ly/4prwrb" will be useless on TwitterPeek.

Better Alternatives With so many other Twitter-capable devices out there, I have to wonder about TwitterPeek's appeal. Plans are in the works to allow you to preview Web pages within TwitterPeek, but that will still leave the device crippled if you won't be able to get a complete view of what others are looking at. You can already get Twitter on any smartphone or feature phone with Internet access, and you can also send and receive tweets using SMS. If you don't want to be stuck with high data fees typical of most smartphone plans, there are cheaper alternatives from Peek such as the Pronto for $60. This email-centric device will also let you send text messages, and access Twitter via Ping.fm. So what do you say? It's still a stripped-down device, but at least you can use it for three different functions, all with a cheaper price tag.

Has TwitterPeek got you excited? If I had to guess, I'd say not that many. How many of you out there plan on grabbing one of these devices?

Google Books Won't Hit Digital Shelves Anytime Soon

Google is reportedly working to make its settlement with book publishers more palatable to the court, but even if the deal goes through, consumers are likely a long way from getting out-of-print "orphaned" books onto their e-readers. The government and other parties have raised privacy concerns, worrying about Google's observation of what people read. (And not all authors and publishers are satisfied, although their associations signed on to the deal.) But what really has Amazon, Microsoft and other competitors in a tizzy is the part of the settlement that lets Google sell online access and subscriptions to orphaned books. The settlement, in its current state, would allow Google to make large passages of these books, which are in copyright but whose authors can't be found, searchable on the Web. As the e-reader market heats up, Amazon argues, the Google book settlement would create "a cartel of authors and publishers" who could set pricing and availability without restrictions.

On Friday, the U.S. Department of Justice dealt a blow to Google, the Authors Guild, and the Association of American Publishers, saying the settlement between the three parties violates antitrust and copyright laws. These opponents would have a harder time setting up their own market of orphaned materials because they'd have to create an agreement with publishers and authors from scratch, instead of making a settlement in court. The DOJ advised a U.S. District Court not to approve the settlement unless it is modified. Google and its settlement partners are motivated to quickly address the DOJ's concerns, but delays are inevitable. Though the government seems to want the settlement to go through in the end, the slow pace of government and courts means we could be waiting a long time. It seems unlikely that the deal will be approved on October 7, when the United States District Court for the Southern District of New York has scheduled a hearing on the matter.

All this could take awhile. All parties must agree to any settlement, and even then, the opponents could still make legal challenges. Maybe it's not all bad. With any luck, Google will start selling the orphaned books just as the e-reader glut hits full swing.

Microsoft delivers massive Patch Tuesday, fixes 34 flaws

Microsoft today delivered a record 13 security updates that patched 34 vulnerabilities in every version of Windows, including the not-yet-for-sale Windows 7, as well as in Internet Explorer (IE), Office, SQL Server and other parts of its software portfolio. The closest competitor was December 2008, when the company quashed 28 bugs . "To anyone following Apple, this isn't a big surprise," said Andrew Storms, director of security operations at nCircle Network Security, referring to Microsoft's operating system rival, which typically issues security updates that include scores of fixes. "But this is certainly an unprecedented month for Microsoft." Microsoft ranked 8 of the 13 updates and 21 of the 34 vulnerabilities as "critical," the top rating in its four-step scoring system. The 34 flaws were also a record number for Microsoft, the most holes patched in one sitting since Microsoft switched to a regular monthly update schedule six years ago.

The remainder of the bulletins were judged "important," the next threat level down, while nine of the flaws were also pegged important, and the final 4 were tagged as "moderate." Among today's patches were several for zero-day vulnerabilities - bugs for which exploit code had already gone public. Microsoft patched three vulnerabilities in SMB (Server Message Block) 2, a Microsoft-made network file- and print-sharing protocol that ships with Windows; two bugs in the FTP server that's included with older editions of its Internet Information Services (IIS) Web server; and two in the Windows Media Runtime. One of the zero-day vulnerabilities was undisclosed until today. The flaws in SMB 2 and IIS had been public knowledge since early September, but the Windows Media vulnerabilities included one that Microsoft said was already in the wild, but had not leaked to the usual public sources, such as security mailing lists. More important, it can be exploited in drive-by attack situations, just be getting people to go to a [malicious] Web site." Early last month, Microsoft revealed the SMB 2 vulnerability , but although attack code went public, security researchers have not seen any actual attacks. For that reason, Storms urged everyone to deploy the MS09-051 update, which patches the Windows Media bugs, as soon as possible. "At first glance, [MS09-]051 should be patched immediately," he said. "What's interesting today is that we're learning it's in the wild.

The flaw affects Windows Vista, Windows Server 2008 and preview releases of Windows 7, but not the final edition slated for retail release next week. Microsoft also fixed a slew of flaws today that go back to a programming error in one of its code "libraries," Active Template Library (ATL). The company had acknowledged the error last summer. The FTP flaw , on the other hand, was disclosed by Microsoft Sept. 1, when the company confirmed that its security team was investigating attack code that hit the street on the last day of August. Today's patches quashed three ATL-related bugs in Office and set "kill bits" to disable four or more Microsoft-made ActiveX controls for Windows Live Mail, the MSN Photo upload tool, and various Office document viewers used by Internet Explorer (IE) to display spreadsheets, charts and databases on the Web. "And we have the token IE patches today, too," noted Storms, talking about MS09-054, which plugs four holes, all critical, in Microsoft's browser. As part of today's record update, Microsoft also patched eight vulnerabilities in GDI+, (Graphics Device Interface), a component that debuted in Windows XP and is a core part of Windows Vista and Windows 7, as well as the server-side operating systems, Windows Server 2003 and Windows Server 2008. Hackers could exploit the GDI+ bugs by sending specially-crafted image files in a variety of formats - including BMP, PNG, TIFF and WMF - to a user via e-mail, or by convincing users to visit sites that contain malicious image files.

Included in the four, said Storms, was one apparently accidently disclosed at the Black Hat security conference several months ago. By triggering the vulnerabilities, attackers could then follow up with additional malware to hijack a system or steal data. The audio codec bugs [in MS09-051] will be so much easier to exploit," he reasoned. "I would put the two items in the public domain, MS09-050 [the SMB 2 flaws] and MS09-053 [the FTP bug in IIS] at the top of the list," said Storms. "And then MS09-051 and the IE updates, the latter because those kind of client-side bugs get a lot of attention from attackers." This month's security updates can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services. Storms, however, discounted exploits of the GDI+ vulnerabilities.