Archive

Category Archives for "Networking"

Securing BGP: A Case Study (7)

In the last post on this series on securing BGP, I considered a couple of extra questions around business problems that relate to BGP. This time, I want to consider the problem of convergence speed in light of any sort of BGP security system. The next post (to provide something of a road map) should pull all the requirements side together into a single post, so we can begin working through some of the solutions available. Ultimately, as this is a case study, we’re after a set of tradeoffs for each solution, rather than a final decision about which solution to use.

The question we need to consider here is: should the information used to provide validation for BGP be somewhat centralized, or fully distributed? The CAP theorem tells us that there are a range of choices here, with the two extreme cases being—

  • A single copy of the database we’re using to provide validation information which is always consistent
  • Multiple disconnected copies of the database we’re using to provide validation which is only intermittently consistent

Between these two extremes there are a range of choices (reducing all possibilities to these two extremes is, in fact, a misuse of the Continue reading

Google’s biggest, craziest ‘moonshot’ yet

Google is nothing if not ambitious. It’s famed “moonshot” projects have taken on notoriously large projects, from extending human lifespans to drones that can stay aloft for years at a time. But this one takes the cake.According to the subscription tech news site The Information, Alphabet, Google’s holding company, is trying to get CEO Larry Page to sign off on “Project Sidewalk.” The Information describes the effort as an attempt “to create an area in the U.S. that serves as a test bed for new technologies from superfast internet to autonomous cars. … An area that could accommodate hundreds of thousands of people has been contemplated.”To read this article in full or to leave a comment, please click here

IT employees at EmblemHealth fight to save jobs

IT employees at EmblemHealth are organizing to stop the New York-based employer from outsourcing their jobs to offshore provider Cognizant.Employees say the insurer is on the verge of signing a contract with Cognizant, an IT services firm and one of the largest users of H-1B workers. They say the contract may be signed as early as this week.They fear what a contract with at IT services offshore firm may mean: Humiliation as part of the "knowledge transfer" process, loss of their jobs or a "rebadging" to Cognizant, which they see as little more than temporary employment. Many of the workers, about 200 they estimate, are older, with 15-plus-year tenures. This means a hard job search for them.To read this article in full or to leave a comment, please click here

Introducing the new Citrix

Kirill Tatarinov took over as CEO of Citrix in January, a key piece of a company reorganization demanded by activist investor Elliott Management, which had acquired a 7.5% stake in Citrix.  Tatarinov, a 13 year veteran of Microsoft, where he was most recently Executive Vice President of the Microsoft Business Solutions Division, is putting the finishing touches on the company’s new plan, which will be introduced at the company’s large user conference in May, but he shared a preliminary glimpse with Network World Editor in Chief John Dix. Citrix CEO Kirill Tatarinov  To read this article in full or to leave a comment, please click here

Network visibility can reverse the security asymmetry challenge

Securing a business network has never been easy, but the task is becoming increasingly more difficult.Years ago, there was a single ingress/egress point to get into the network. The delineation between what was public and what was private was obvious.Today, that’s all changed. The rise of mobile devices, Wi-Fi access points, cloud applications and software-defined everything has increased the number of entry points into a company from one to tens, hundreds or even thousands for large organizations. For example, it’s common for a worker to connect to some kind of “free” Wi-Fi network when travelling without having any idea who might own that network, browse the web and infect their mobile device.To read this article in full or to leave a comment, please click here

The nightmare of rogue USB-C cables and adapters will end soon

The wave of rogue USB-C products that poses risks to PCs and mobile devices hasn't gone unnoticed, and the USB Implementers Forum has taken steps to eradicate the issue once and for all.A new specification announced by the USB 3.0 Promoters Group, which is part of USB-IF, aims to eliminate rogue cables, ports and chargers. The USB Type-C Authentication protocol will verify and ensure a USB-C connection won't fry a port or damage a device.A host device like a smartphone or PC will first verify the authenticity of the cable, charger or power source before any data is transferred. If everything checks out, a connection will be established.So if a smartphone or PC won't charge from a USB port in a public place, it's perhaps because there's a non-compliant component.To read this article in full or to leave a comment, please click here

Cybersecurity Salary Inflation – A Red Flag

If you follow my blog at all you know that I am quite passionate about the cybersecurity skills shortage and its ramifications.  Just to put this issue in perspective, ESG research indicates that 46% of organizations claim they have a “problematic shortage” of cybersecurity skills in 2016 as compared to 28% in 2015 (note: I am an ESG employee). Yup, the ESG research seems to indicate that things are getting worse on an annual basis, and ESG isn’t alone in this belief.  For example: According to Peninsula Press (a project of the Stanford University Journalism Program), more than 209,000 US-based cybersecurity jobs remained unfilled and postings are up 74% over the past 5 years. Analysis of the US Bureau of Labor Statistics indicates that the demand for cybersecurity professionals is expected to grow 53% by 2018. Adding to this trend, Computerworld research indicates that more than half of security managers expect their organizations to increase cybersecurity headcount this year adding more pressure to the pot. To read this article in full or to leave a comment, please click here

Facebook tells B2C businesses: I feel your mobile pain

Facebook’s Messenger chat-bots and an update to the React Native cross-platform mobile development framework—both announced last week week—could relieve the pain felt by businesses trying to shift customer interaction from the web to mobile.It might seem there is an app for everything, but not every business has one. Building a token app that lives a lonely existence on the app store doesn’t help keep customers buying as they shift from the web to mobile. And meaningful mobile relationships and revenue-generating campaigns still elude most businesses because of the high cost of having Android and iOS development teams and the challenges of recruiting developers.To read this article in full or to leave a comment, please click here

Hacker: This is how I broke into Hacking Team

Almost a year after Italian surveillance software maker Hacking Team had its internal emails and files leaked online, the hacker responsible for the breach published a full account of how he infiltrated the company's network.The document published Saturday by the hacker known online as Phineas Fisher is intended as a guide for other hacktivists, but also shines a light on how hard it is for any company to defend itself against a determined and skillful attacker.The hacker linked to Spanish and English versions of his write-up from a parody Twitter account called @GammaGroupPR that he set up in 2014 to promote his breach of Gamma International, another surveillance software vendor. He used the same account to promote the Hacking Team attack in July 2015.To read this article in full or to leave a comment, please click here

Hacker: This is how I broke into Hacking Team

Almost a year after Italian surveillance software maker Hacking Team had its internal emails and files leaked online, the hacker responsible for the breach published a full account of how he infiltrated the company's network.The document published Saturday by the hacker known online as Phineas Fisher is intended as a guide for other hacktivists, but also shines a light on how hard it is for any company to defend itself against a determined and skillful attacker.The hacker linked to Spanish and English versions of his write-up from a parody Twitter account called @GammaGroupPR that he set up in 2014 to promote his breach of Gamma International, another surveillance software vendor. He used the same account to promote the Hacking Team attack in July 2015.To read this article in full or to leave a comment, please click here

Thrilled that AI is no longer a dirty word

Cognitive computing, artificial intelligence and machine learning are here to stay and promise to benefit both consumers and the organizations that exploit these advanced technologies.That was the sentiment from “Dawn of the Cognitive Era” panelists representing mostly startups (startup wannabe IBM being the exception) at the annual TiE StartupCon event in Boston this past week.MORE: 10 Internet of Things Companies to WatchWhereas it wasn’t long ago that the public’s view of AI was influenced disproportionately by books and movies, an increasing number of real-life cognitive computing applications such as those enabled by IBM Watson have begun to seep into the public’s consciousness. In fact, many people are taking advantage of cognitive computing, whether or not they realize it, when they use tools such as Apple’s Siri or various bots, said panel moderator and DataXylo CEO Abhi Yadav. Such applications, enabled in large part through the access to relatively cheap computing power via the cloud, have resulted in the technology finally living up to the hype -- and dissuading fears it will lord over us.To read this article in full or to leave a comment, please click here

Homeland Security issues warning about QuickTime for Windows

Because Apple no longer supports QuickTime for Windows, users are being encouraged to uninstall the program immediately. The warning from the U.S. Department of Homeland Security (DHS) comes on the heels of a warning from antivirus vendor Trend Micro that the video playback software is vulnerable to a pair of zero-day exploits.Apple has not updated the Windows version of QuickTime 7 since January and it would seem does not plan to release any more security patches to fix the exploits. Trend Micro notes that even Apple recommends Windows users uninstall the player. QuickTime for Mac is unaffected and remains supported by Apple.To read this article in full or to leave a comment, please click here

Up to 64% Off Belkin Surge Protectors Today Only – Deal Alert

For today only, Amazon is featuring deals on highly rated surge protectors from Belkin that will save you up to 64%. Use the links below to see which model is right for your application: Belkin 12 Outlet Home/Office Surge Protector with 10-Foot cord and Phone/Ethernet/Coaxial Protection plus Extended Cord. Price: $49.99  $17.98 (save 64%) Belkin 3-Outlet SurgePlus Mini Travel Swivel Charger Surge Protector with Dual USB Ports (2.1 AMP / 10 Watt)Price: $29.99  $13.99 (save 53%) Belkin SurgePlus 6-Outlet Wall Mount Surge Protector with Dual USB Ports (2.1 AMP / 10 Watt)Price: $24.99  $13.99 (save 44%) Belkin 6-Outlet Home/Office Surge Protector with 2.5-Foot Cord & Straight PlugPrice: $12.99  $5.49 (save 58%) To read this article in full or to leave a comment, please click here

Up to 64% Off Belkin Surge Protectors Today Only – Deal Alert

For today only, Amazon is featuring deals on highly rated surge protectors from Belkin that will save you up to 64%. Use the links below to see which model is right for your application: Belkin 12 Outlet Home/Office Surge Protector with 10-Foot cord and Phone/Ethernet/Coaxial Protection plus Extended Cord. Price: $49.99  $17.98 (save 64%) Belkin 3-Outlet SurgePlus Mini Travel Swivel Charger Surge Protector with Dual USB Ports (2.1 AMP / 10 Watt)Price: $29.99  $13.99 (save 53%) Belkin SurgePlus 6-Outlet Wall Mount Surge Protector with Dual USB Ports (2.1 AMP / 10 Watt)Price: $24.99  $13.99 (save 44%) Belkin 6-Outlet Home/Office Surge Protector with 2.5-Foot Cord & Straight PlugPrice: $12.99  $5.49 (save 58%) To read this article in full or to leave a comment, please click here

Up to 48% Off Belkin Surge Protectors Via Amazon – Deal Alert

Amazon is currently featuring deals on highly rated surge protectors from Belkin that will save you up to 48%. Use the links below to see which model is right for your application: Belkin 12 Outlet Home/Office Surge Protector with 10-Foot cord and Phone/Ethernet/Coaxial Protection plus Extended Cord. Price: $49.99  $25.88 (save 48%) Belkin 3-Outlet SurgePlus Mini Travel Swivel Charger Surge Protector with Dual USB Ports (2.1 AMP / 10 Watt)Price: $29.99  $18.00 (save 40%) Belkin SurgePlus 6-Outlet Wall Mount Surge Protector with Dual USB Ports (2.1 AMP / 10 Watt)Price: $24.99  $20.99 (save 16%) Belkin 6-Outlet Home/Office Surge Protector with 2.5-Foot Cord & Straight PlugPrice: $12.99  $7.99 (save 38%) To read this article in full or to leave a comment, please click here