Crypto dream team Diffie & Hellman wins $1M “Nobel Prize of Computing”

Whitfield Diffie and Martin Hellman, whose names have been linked since their seminal paper introduced the concepts of public key encryption and digital signatures some 40 years ago, have been named winners of the 2015 ACM A.M. Turing Award (a.k.a., the "Nobel Prize of Computing").The work of MIT grad Diffie, formerly chief security officer of Sun Microsystems, and Hellman, professor emeritus of electrical engineering at Stanford University, has had a huge impact on the secure exchange of information across the Internet, the cloud and email. ACM Whitfield Diffie and Martin Hellman The annual Association for Computing Machinery prize carries a $1 million prize, with financial support from Google. Past winners have included the likes of Internet pioneer Vinton Cerf, database visionary Michael Stonebraker and recently deceased AI innovator Marvin Minsky.To read this article in full or to leave a comment, please click here

IDG Contributor Network: Cyberattacks beginning to affect mobile service too, study says

Distributed Denial of Service (DDoS) attacks are beginning to show up as a cause of mobile phone outages, according to respondents of a survey.The Spirient-commissioned report surveyed 54 global Mobile Network Operators (MNO), polling them on their experiences with outages and service degradations. It found that DDoS attacks showed up for the first time in this year’s report. For comparison, cyberattacks didn’t surface at all the last time researcher Heavy Reading conducted the survey for Spirient in 2013.Spirient is a test and service management firm for MNOs.To read this article in full or to leave a comment, please click here

Security ‘net: Internet of Things and iPhones edition

One of my college professors has suggested that the question of whether or not Apple should help the FBI break the encryption on the iPhone used by a terrorist is an ideal diagnostic question for your view of all things privacy. There are, of course, gray area answers, like “Apple should help the FBI break the encryption in this case, but not others.” The problem is, of course, that this isn’t the simple answer it might seem. First, there are motives behind the apparent motives. Many people see Apple as just “doing what’s right to save the world.” I don’t see it that way at all. Given I’m a bit cynical (who would have guessed), I see two motives from Apple’s point of view.

First, Apple is trying to protect a marketing stance. They’ve as much as admitted this in court documents and the implied threat of suing the U.S. Government for loss of revenue if they’re forced to build a version of their O/S that will allow the FBI to break the encryption. Just Security notes—

There are other interests at stake here too. Apple has a liberty interest in not being dragooned into writing forensic Continue reading

FTC: Imposter scams, identity theft, and debt collection top consumer grumbles

The Federal Trade Commission found few surprises in its annual summary of consumer complaints – offensive debt collection activities, identity theft, and imposter scams were the main offenders in 2015. Imposter scams have been in the news of late because the Internal Revenue Service issued a report in January that said that aggressive and threatening phone calls by criminals impersonating IRS agents continues to plague taxpayers. The Treasury Inspector General for Tax Administration in January said it has received reports of roughly 896,000 contacts since October 2013 and have become aware of over 5,000 victims who have collectively paid over $26.5 million as a result of the scam. The IRS also noted recently that there has been a 400% surge in phishing and malware incidents in this tax season alone.To read this article in full or to leave a comment, please click here

Cisco enters storage, hyperconvergence market with data center splash

SAN DIEGO – Cisco this week is throwing its hat into the hyperconvergence and software-defined storage ring with a system co-developed with software company SpringPath. Cisco is also rolling out at its Cisco Partner Summit here a new generation of Nexus 9000 data center switches featuring 25G/50G Ethernet based on custom ASICs. The new products dovetail with Cisco’s acquisition today of CliQr, a maker of “application-defined” hybrid cloud orchestration software for deploying and managing applications across bare metal, virtualized and container environments.To read this article in full or to leave a comment, please click here

Sponsored Post: zanox Group, Varnish, LaunchDarkly, Swrve, Netflix, Aerospike, TrueSight Pulse, Redis Labs, InMemory.Net, VividCortex, MemSQL, Scalyr, AiScaler, AppDynamics, ManageEngine, Site24x7

Who's Hiring?

  • The zanox Group are looking for a Senior Architect. We're looking for someone smart and pragmatic to help our engineering teams build fast, scalable and reliable solutions for our industry leading affiliate marketing platform. The role will involve a healthy mixture of strategic thinking and hands-on work - there are no ivory towers here! Our stack is diverse and interesting. You can apply for the role in either London or Berlin.

  • Swrve -- In November we closed a $30m funding round, and we’re now expanding our engineering team based in Dublin (Ireland). Our mobile marketing platform is powered by 8bn+ events a day, processed in real time. We’re hiring intermediate and senior backend software developers to join the existing team of thirty engineers. Sound like fun? Come join us.

  • Senior Service Reliability Engineer (SRE): Drive improvements to help reduce both time-to-detect and time-to-resolve while concurrently improving availability through service team engagement.  Ability to analyze and triage production issues on a web-scale system a plus. Find details on the position here: https://jobs.netflix.com/jobs/434

  • Manager - Performance Engineering: Lead the world-class performance team in charge of both optimizing the Netflix cloud stack and developing the performance observability capabilities Continue reading

Slacking Off

A Candlestick Phone (image courtesy of WIkipedia)

A Candlestick Phone (image courtesy of WIkipedia)

There’s a great piece today on how Slack is causing disruption in people’s work habits. Slack is a program that has dedicated itself to getting rid of email, yet we now find ourselves mired in Slack team after Slack team. I believe the real issue isn’t with Slack but instead with the way that our brains are wired to handle communication.

Interrupt Driven

People get interrupted all the time. It’s a fact of life if you work in business, not just IT. Even if you have your head down typing away at a keyboard and you’ve closed out all other forms of distraction, a pop up from an email or a ringing or vibrating phone will jar your concentration out of the groove and force your brain to deal with this new intruder into your solitude.

That’s evolution working against you. When we were hunters and gatherers our brain had to learn how to deal with external threats when we were focused on a task like stalking a mammoth or looking for sprouts on the forest floor. Our eyes are even developed to take advantage of this. Your peripheral vision will pick up Continue reading

Cisco flexes some data center muscle at Partner Summit 2016

Cisco’s reseller event, Partner Summit, kicked off this week in San Diego. The event is normally a big one for Cisco as thousands of its resellers gather to be updated on the latest, greatest plans for Cisco. All eyes are on Chuck Robbins as this is the first Partner Summit held under his watch as the company’s CEO. The event kicks off today and has already seen Cisco make a couple of significant announcements in the data center.This morning Cisco announced its intention to acquired Silicon Valley based, CliQr Technologies for $260 million. The 105-person company provides application centric cloud orchestration that enables customers to model, deploy and manage across bare metal, virtual and container environments regardless of whether the infrastructure is on premise or in a private or public cloud. The technology will be used to help Cisco customers move to a seamless hybrid cloud model where the information can be moved between clouds, and resources can be provisioned across clouds. CliQr’s technology is already tightly integrated into a number of Cisco data center products including ACI (Application Centric Infrastructure) and Unified Computing System (UCS).  To read this article in full or to leave a comment, please Continue reading

Cisco flexes some data center muscle at Partner Summit 2016

Cisco’s reseller event, Partner Summit, kicked off this week in San Diego. The event is normally a big one for Cisco as thousands of its resellers gather to be updated on the latest, greatest plans for Cisco. All eyes are on Chuck Robbins as this is the first Partner Summit held under his watch as the company’s CEO. The event kicks off today and has already seen Cisco make a couple of significant announcements in the data center.This morning Cisco announced its intention to acquired Silicon Valley based, CliQr Technologies for $260 million. The 105-person company provides application centric cloud orchestration that enables customers to model, deploy and manage across bare metal, virtual and container environments regardless of whether the infrastructure is on premise or in a private or public cloud. The technology will be used to help Cisco customers move to a seamless hybrid cloud model where the information can be moved between clouds, and resources can be provisioned across clouds. CliQr’s technology is already tightly integrated into a number of Cisco data center products including ACI (Application Centric Infrastructure) and Unified Computing System (UCS).  To read this article in full or to leave a comment, please Continue reading

Don’t let DROWN get you down

drown-blogpost.jpg

If you’re maintaining services on the internet, you know about the importance of keeping up to date with security patches as they come available. Today is no exception with the release of  CVE-2016-0800, describing the ‘DROWN’ vulnerability in OpenSSL.

The key points of DROWN are that it can allow for passive decryption of encrypted traffic, via vulnerabilities in the obsolete SSLv2 protocol. Merely using SSLv2 for one service could cause the compromise the traffic of other services, even if they aren’t using SSLv2. More information can be found at http://www.drownattack.com/.

The Red Hat specific announcement can be found in the  Red Hat Knowledgebase.

Obviously, this is a big deal, but patching your systems for DROWN doesn’t have to be a big deal, thanks to Ansible.

Here’s a sample playbook for Red Hat/Fedora/CentOS and Debian/Ubuntu systems (link to source):

- hosts: all
  gather_facts: true
  sudo: true
  tasks:
	- name: update openssl from apt if available
  	  apt: name=openssl state=latest update_cache=yes
  	  when: ansible_os_family == 'Debian'
  	  notify: restart_system
  
	- name: update openssl from yum if available
  	  yum: name=openssl state=latest update_cache=yes
  	  when: ansible_os_family == 'RedHat'
  	  notify: restart_system

   Continue reading

Fibre Channel is still alive and kicking

In 1897 the great American author, Mark Twain was rumored to have stated, “the reports of my death are greatly exaggerated”. In the tech industry, Fibre Channel could make the same statement. It seems that for years, the death of Fibre Channel has been speculated, as Fibre Channel over Ethernet (FCoE) or even IP networks would be the death knell for the more traditional storage protocol.However, Fibre Channel is still alive and kicking. It’s certainly not the high growth market it once was but the market has maintained about a $2 billion run rate over the past few years. The big driver for the continued investment has been the rise of flash-based storage. The value proposition of flash is speed so it makes sense to deploy a storage network that is as fast as possible.To read this article in full or to leave a comment, please click here

Announcing Docker Cloud

Today we are proud to announce the immediate general availability of Docker Cloud. And we are excited to invite and welcome everyone of you to try it out. Docker Cloud is the name of the new cloud service by Docker … Continued

Staying afloat: the DROWN Attack and CloudFlare

CloudFlare customers are automatically protected against the recently disclosed DROWN Attack. We do not have SSLv2 enabled on our servers.

We publish our SSL configuration here so that others can use it. We currently accept TLS 1.0, 1.1 and 1.2.

We are proactively testing our customers' origin web servers to detect vulnerable servers and will be reaching out to any that have a server that is vulnerable to DROWN.

In the interim, ensure that SSLv2 is fully disabled and/or that private keys are not shared with servers that still need to have SSLv2.