Qualcomm's FLO puts a TV in your hand

MediaFLO, the Qualcomm subsidiary that broadcasts digital TV to mobile phones, introduced its first device on Wednesday by taking the phone out of the TV. The FLO TV Personal Television has a 3.5-inch (8.9 centimeter) diagonal LCD screen and a touchscreen interface that lets viewers change the channel just by swiping a finger across it. MediaFLO can broadcast as many as 20 channels of live and prerecorded TV on a dedicated network that complements mobile operators' infrastructure rather than consuming more of their mobile data capacity. The TV is set to go on sale during the year-end holiday season in retail stores at a suggested retail price of US$249.99. Service will be priced as low as $8.99 per month. Verizon Wireless launched MediaFLO on select handsets in 2007, and AT&T followed in 2008. The U.S. network operates on MediaFLO's own frequencies, former analog TV channels.

The handheld TV is one part of MediaFLO's expansion beyond selling TV on phones. MediaFLO has also tested the service in other countries, including Japan and the U.K. By promoting its FLO (Forward Link Only) technology, Qualcomm has set itself up against the widely espoused DVB-H (Digital Video Broadcast-Handheld) standard, a familiar role for the pioneer of CDMA (Code-Division Multiple Access) cellular technology. Last month, the company announced a partnership with automotive electronics manufacturer Audiovox to offer live in-car TV. That service will be sold through auto dealers as an added feature on new cars, typically with prepaid pricing for a year or more of initial service. Up until now, through the mobile operators, the service has been charged on a monthly basis on phone bills. The company did not detail monthly pricing for service on the Personal Television, but the $8.99 per month rate will come with a three-year prepaid subscription.

For example, Verizon sells a service with 10 channels for $15 per month. The Personal Television weighs just over 5 ounces (142 grams) and measures 4.4 inches by 3 inches by 0.5 inch. Consumers won't have to sign up for a contract to buy the Personal TV, but it can't be used for anything but watching MediaFLO's broadcasts. MediaFLO estimates its battery life at five hours of TV watching or 300 hours of standby. It has a software feature for users to set reminders of shows they want to watch, according to MediaFLO. Like other outlets for FLO TV, the Personal Television will get a unique set of channels, but the major brands MediaFLO offers will be represented, according to a company representative.

The device includes built-in stereo speakers and a stand to prop up the screen. ESPN, Fox, MTV, CNBC and MSNBC are represented among channels offered on FLO TV now.

HHS guts health-care breach notification law, groups warn

Privacy and civil rights advocates accused the U.S. Department of Health and Human Services of trying to neuter a landmark data breach notification law for health care organizations that is scheduled to go into effect next week. Companies that used encryption and data destruction methodologies to render sensitive health information unusable and unreadable to unauthorized individuals were exempt from the breach notification requirement. The law would require any organization covered under the Health Insurance Portability and Accountability Act (HIPAA) to notify patients of a data breach involving their personal health information. However, in an interim final rule published late last month, the HHS introduced a new "harm threshold" for breach notification which critics say completely guts the original intent of the bill.

The change allows health-care companies to do a self-assessment of the potential privacy and fraud risks stemming from a data breach and leaves it up to them to decide if a notification is justified. Under the change, health-care entities will be required to publicly disclose breaches involving health-care data only if they think the breach will cause financial or reputational harm to those whose data was compromised. If a breached company decides there is no harm, it will have no obligation to disclose the breach to anyone - even if it had taken no measures previously to protect the data. "The harm standard completely undermines the purpose of mandatory notification, which is that covered entities protect their patient data with strong safeguards," said Harley Geigel, legal counsel at the Center for Democracy and Technology (CDT), a Washington-based think tank. "Now an entity can avoid both encryption and notification because they can decide that any information that was released poses no risk," he said. The health-care breach notification law is part of the $20 billion Health Information Technology for Economic and Clinical Health Act (HITECH) that was passed by Congress earlier this year as part of President Obama's economic stimulus plan. The HHS did not respond immediately to a request for comment. The act requires HHS to develop rules for breach notification in the health-care industry.

In justifying the change, the HHS said a harm threshold was necessary to prevent needless breach notifications. The interim final rule, which contains the harm standard, was released late last month. It argued that the impact of notifications would be diminished if individuals got "flooded" with notices of breaches that posed no risk to their protected health information. But the comments are unlikely to be acted upon until the first HHS update to the rule in April 2010, according to the CDT. Meanwhile, the statute is scheduled to go into effect next week. The public has about 40 days to comment on the interim final rule before it becomes final.

Deborah Peel, founder and chairwoman of Patient Privacy Rights, a watchdog group in Austin, Texas, blasted the HHS' proposed harm threshold. It eliminates the consumer protection that Congress intended to be built into it," Peel said. The decision to include a harm threshold suggests that the HHS might have succumbed to pressure from the health-care industry, which has vehemently opposed a notification requirement, she said. "This harm requirement actually violates Congress' intent in the stimulus bill," she said. "This is essentially an industry rewrite of the law." Given the way the law is worded, health-care organizations will have little incentive to own up to a breach involving protected health care data, she said. "This is totally for the protection of the industry. She added that her organization will be part of a "giant response" to the proposed change by national consumer protection and privacy organizations. When making its original Request for Information on the notification rule, the HHS gave no indication that it planned on having a harm threshold, Geiger said. Given the manner in which the harm threshold requirement was introduced in the notification bill, it appears unlikely that the HHS will budge easily on the issue, Geiger said.

As a result, organizations such as the CDT and others had no chance to formally oppose or to have a public debate on the issue with the HHS, he said. "The way we read the statute, a harm standard should never have figured in the equation to begin with," Geiger said. Originally for notification purposes, a breach was simply defined as a compromise in which protected health information was exposed or accessed in an unauthorized fashion, he said. "How the HHS made the leap from the language in Congress to the interim final rule we don't know," he said.

Nobel Physics Winners Changed Our Lives

Like the Internet? If so, please take a moment to thank today's three Nobel prizewinners for their discoveries. Own a digital camera?

The three American scientists, honored today with the 2009 Physics prize, helped give us modern telecommunications-including the Internet-and digital photography. Sad it took 40 years to honor these great men-their work was done during the 1960's-but good health has smiled upon all three, now in their 70's and 80's. (Nobels are not awarded posthumously). Charles Kao, who also holds British citizenship, is being honored for his work helping to develop fiber optics, the oh-so-slender glass pipelines than carry digital data-converted into pulses of colored light-around the world. Fiber optic cable makes the high-speed communications possible, while charge-coupled devices (CCDs) are the cornerstone of digital photography. Born in 1933, Kao was in England when he invented a method to dramatically improve the purity of the glass used to construct the fibers. Dr. Boyle also holds Canadian citizenship. The other half of the $1.4 million prize was won by Willard Boyle, 85, and George Smith, 79, for their invention of the CCD, made at AT&T Bell Laboratories in 1969. CCDs are based on the photoelectric effect, which itself won a Nobel for Albert Einstein.

Read about the science being honored in this New York Times story. In honoring these three today, perhaps we can also honor all those who make our technology-based lives possible. Many other people played a part in making these Nobel-winning discoveries a part of daily life. Better, we can recommit ourselves to supporting basic science and research-hard thinking-that is so out-of-fashion in much of society today. You and I are direct beneficiaries of the work the Nobel committee has chosen to honor today. (The ceremony will be held Dec. 10 in Stockholm). Let's honor these scientists by supporting math and science education and, perhaps, in another 40 years we'll be honoring a new generation of American scientists for their life-changing achievements. At a time when we need more answers than ever before, we should be concerned about how many people are capable of asking the questions and putting what they discover to use for the good of everyone.

David Coursey tweets as @techinciter and can be contacted via his Web page.

Review: Kingston's new USB drive offers public and encrypted partitions

USB sticks have offered pretty much the same functionality over the past year or so. Kingston's new thumb drive offers the somewhat stand-out capability of allowing a user to set up an encrypted partition to safeguard some of that data, while allowing the remaining drive space to remain open and accessible by anyone. So when Kingston announced a new DataTraveler Locker USB Flash Drive that offered partitioning capability, I took notice.

I find this useful because I'm often lending my USB drive to friends who want a simple way to transfer files or temporarily save some data. However, it's possible that solution could render your drive unusable. You can trick a Windows system into creating partitions on a USB stick by flipping Removable Media Bit, making it appear as a permanent or fixed drive. So I liked the idea that I could quickly set up a partition on my USB stick to protect sensitive data while still being able to lend the drive to someone. Kingston makes two versions of its encryptable DataTraveler, dubbed the Locker and the Locker+. The Locker+ automatically encrypts everything stored on the drive using 256-bit hardware-based AES encryption. Or I could simply plug it into another computer without having to log in.

The Locker allows a user to partition space. You type in a password and reminder; your name and company; and then select "OK". That's it. Like most other USB sticks with encryption features, the DataTraveler Locker+ drive set up is as simple as one, two, three. Everything you save to the drive is now automatically encrypted. Once plugging it into your USB port, it will show up as a drive and you double click on "DTencryptor". Setting up the partition is intuitive and fast.

Kingston's DataTraveler Locker (sans +) setup isn't much more difficult. Pop up boxes guide you along asking to first pick a language, then to pick whether or not you want a "privary zone" - as it calls the encrypted partition. The slide scale on my 16GB capacity drive allowed me to partition up to 13.7GB of secure space. The software asks you to choose a password for the encrypted partition and then allows you to choose the size of the partition with an easy-to-use sliding scale. The DataTraveler Locker+ comes in capacities of up to 32GB, and the Locker comes with capacities of up to 16GB. The drive's size is pretty standard: 2.58-in x 0.71-in x 0.41-in. The DataTraveler Locker+ drive locks down and reformats after 10 incorrect password attempts, deleting all your data and protecting it from prying eyes.

One of the features I liked right off the bat is the ability of the two drives to protect themselves against brute-force attacks, or from someone attempting to guess the password. While other drives have this feature, they often tend to be the higher end, pricey models. Instead of a cap that can be lost, the drive swings out on a hinge - a relatively common form factor today, but still one of the best designs out there. Another attribute is the DataTraveler's cover. I'm a big fan of non-removable caps for obvious reasons.

The drive showed an average read speed of 28.3MB/sec and an impressive random access time of 1.7 milliseconds, but CPU utilization was a disappointing 24%. When you're running more than one application on your computer, that can definitely impact performance. I tested the DataTraveler Locker+ drive's I/O speed with Simpli Software's HD Tach 3.0 benchmarking softare. For my next performance test, I transferred a 2GB size document containing 544 files made up of photos, video and text documents to the encrypted partition, which took 5 minutes, 37 seconds. A 4GB model of the DataTraveler Locker+ retails for $36.00, an 8GB $50.00, a 16GB $100.00, and a 32GB DataTraveler Locker+ retails for $200.00. A 4GB model of the DataTraveler Locker retails for $30; an 8GB for $44; and a 16GB for $93. For comparison, you can purchase a 32GB SanDisk Extreme Contour USB Flash Drive with 256-bit AES encryption for $166.99 retail or a 16GB model of the same for $108.99. The DataTraveler drives are compatable with Windows 7, Vista, XP, 2000 and Mac OS X v.10.4 - v.10.6. While this drive is a little more affordable than others with similar encryption features, it mainly stands out for one thing: its partitioning capability. Not bad at all. Lucas Mearian covers storage, disaster recovery and business continuity, financial services infrastructure and health care IT for Computerworld . Follow Lucas on Twitter at @lucasmearian , send e-mail to lmearian@computerworld.com or subscribe to Lucas's RSS feed .

The Richest CIOs: Our Annual List of Top Earners

Which CIOs are earning the most? The below chart details 2008 earnings for the top money-makers at public companies. What does a top CIO's total compensation look like? Methodology note: This list is based on publicly-filed SEC documents.

The total compensation figure combines value of stock and options awards, incentive payouts, perks, pension contributions and other compensation. It represents only CIOs from public companies among the Fortune 1000, where the CIO is one of the company's 5 highest-paid officers. For more background on CIO salaries, see our related story, "Richest CIOs: What's Behind Smaller Bonuses." CIO Earnings Top Technology Executive Title Company Total 2008 Compensation Salary Randall Mott EVP, CIO Hewlett-Packard $28,293,134 $690,000 Larry Kittelberger SVP Technology and Operations Honeywell International $8,030,866 $712,788 Sam Leno EVP Finance and Information Systems, CFO Boston Scientific $6,321,255 $621,721 Steve Squeri EVP Corporate Development and CIO American Express $6,252,701 $600,000 Bill Chenevich Vice Chairman, Technology and Operations Services US Bancorp $5,384,509 $537,521 Franck Moison President Global Marketing, Supply Chain and Technology Colgate-Palmolive $5,058,159 $641,667 Bob DeRodes former EVP, CIO Home Depot $4,836,618 $462,769 Tim Shack former EVP, CIO PNC Financial Services Group $4,577,332 $510,000 Glen Salow EVP Service Delivery and Technology Ameriprise Financial $4,071,987 $475,000 Randy Darcy* EVP Worldwide Technology and Operations General Mills $3,476,976 $489,895 Robert Willett* CIO Best Buy; CEO Best Buy International Best Buy $3,468,486 $821,157 Anil Kottoor SVP, CIO WellCare Health Plans $3,079,961 $305,000 Anna Ewing EVP, Global Software Development and CIO NASDAQ OMG Group $2,791,709 $400,000 Patrick McNamee EVP Operations and Technology Express Scripts $2,769,387 $464,981 Deborah Butler EVP Planning and CIO Norfolk Southern $2,723,561 $435,000 Michael Maslowski SVP, CIO CenturyTel $2,672,770 $353,712 Greg Framke EVP, Chief Information and Operations Officer Etrade Financial $2,059,718 $421,731 Kenneth Tye Sr. Exec. CIO magazine assistant editor Simone Levien contributed research support to this project. VP, CIO Total System Services $2,047,126 $440,013 David Johns SVP, Supply Chain and IT Officer Owens Corning $1,816,368 $367,500 David Kelley EVP, CIO TD Ameritrade $1,792,653 $300,000 Thomas Frank EVP, CIO Interactive Brokers Group $1,778,179 $312,000 Jenny Bolt EVP Operations and Technology Franklin Resources $1,768,722 $506,250 Michael Cheles VP IT MEMC Electronic Materials $1,745,238 $237,000 Rob Autor former EVP, CIO SLM $1,741,720 $350,000 Tim Sullivan Corporate EVP, CIO SunTrust Banks $1,698,634 $484,067 Bruce Goodman SVP, Chief Service and Information Officer Humana $1,588,048 $489,385 Lisa Bachmann SVP Merchandise Planning/Allocation and CIO Big Lots $1,572,566 $436,222 John Alexander Du Plessis Currie EVP, CIO Brightpoint $1,400,797 $475,000 Richard Flaks SVP, Planning, Allocation and IT The Children's Place $1,382,189 $494,497 Mahvash Yazdi SVP, CIO Edison International $1,228,790 $394,947 Calvin Sihilling EVP, CIO Nash-Finch $1,189,392 $378,866 Jeanne Moreno VP, CIO Snap-On $1,177,949 $319,340 Raymond Voelker CIO Progressive $1,170,457 $377,307 Scott Arvidson EVP, CIO Kansas City Southern $1,141,863 $336,386 Joseph Osbourn* EVP, CIO Tech Data $1,127,556 $498,001 Pierre Samec CTO Expedia $1,070,060 $350,000 Keith Morrow SVP, CIO Blockbuster $1,054,104 $350,000 Michael Relich SVP, CIO Guess? $977,590 $386,154 Gregory Tranter SVP, CIO The Hanover Insurance Group $948,736 $369,231 Richard White Former SVP, CIO MPS Group $916,176 $250,000 Richard Smith* SVP, CIO CarMax $864,800 $338,308 Lawrence DelGatto EVP, CIO Radian Group $845,018 $300,000 Kenneth Smith SVP, CIO and Human Resources Officer PolyOne $840,753 $333,308 Jon Kerner SVP, CIO MPS Group $837,517 $250,000 Larry Thomas VP, CIO Landstar Systems $808,482 $206,000 Dudley Sondeno SVP, Chief Knowledge and Technology Officer Southwest Gas $792,009 $272,377 Paul G.P. Hoogenboom* SVP, Manufacturing and Operations, CIO RPM International $727,055 $346,000 Bruce Marcus EVP, CIO McGraw-Hill $651,861 $420,000 Allan Lubitz SVP, CIO Mercury General $604,708 $325,000 Laurie Douglas SVP, CIO Publix Super Markets $540,093 $505,600 Richard George VP, Controller and CIO The Andersons $504,100 $210,885 Kenneth DeWitt VP, CIO United Rentals $459,486 $205,077 Source: SEC documents. *2009 figures were used when 2008 figures were not available. Follow senior editor Kim S. Nash on Twitter @knash99. Follow everything from CIO.com on Twitter @CIOonline.

Satyam faces claims of about US$267 million

Indian outsourcer Satyam Computer Services has received legal notices from 37 companies, demanding the return of 12.3 billion Indian rupees (US$267 million) they claim were paid to the company as temporary advances, Satyam said in a filing on Tuesday to the Bombay Stock Exchange. Satyam first mentioned these claims in June, but said that the matter was still under investigation by various authorities. The demand comes as Satyam, now managed by Indian outsourcer Tech Mahindra, has been trying to turn the corner after the company was plunged into a financial crisis in January. In January company founder B. Ramalinga Raju said that Satyam had inflated revenue and profit figures for several years.

Satyam informed the stock exchange that the companies want the money back to repay their creditors. His confession letter also referred to the advances arranged by Satyam from the 37 companies, Satyam said in the filing to the stock exchange. Among the creditors are Maytas Properties and Maytas Infra, both construction companies promoted by Raju's family. Tech Mahindra was selected in the bid, and acquired a dominant stake of 43 percent in the company. The Indian government, after taking over the board and management of Satyam in January, decided to invite bids to select a strategic investor in the company. The move by Tech Mahindra and its investment subsidiary Venturbay Consultants was seen as risky, as the results of Satyam had been ordered to be restated by the government.

Satyam said that it had replied to the legal notices from the 37 companies, describing their claims as "legally untenable." The financial scandal at Satyam is still under investigation by the Central Bureau of Investigation, a federal agency, and the Serious Fraud Investigation Office of the country's corporate affairs ministry. The accounts have as yet to be restated. Raju and others accused in the case are in custody, but have not been tried or sentenced.

Cloud computing inevitable? Not so fast, educator says

DENVER - Is cloud computing inevitable? FAQ: Cloud computing demystified Michael Dieckmann, CIO at the University of West Florida, thinks otherwise and the two spent Wednesday at the annual Educause conference debating the hype vs. the hope around commercial cloud computing that promises to cut IT costs and provide efficiencies. Maybe, but IT still has a lot of questions to ask before floating away on its promises, according to Melissa Woo, director of cyberinfrastructure and network and operations services at the University of Wisconsin-Milwaukee.

Woo's contention isn't so much that the cloud won't emerge as an option, but that IT still has a lot of questions to ask before floating away on its promises. "Why is the conversation always when, why are we not asking why," she said to a packed Educause session that with a raising of hands showed the audience of higher-ed IT pros are on the fence over cloud computing. "Gartner has cloud computing at the peak of inflated expectations on its hype cycle," she said. This week, cloud provider Rackspace reported its third outage since June. Woo noted recent reports of outages by large providers should grab attention. Last month, Microsoft reported it lost the data stored by users of T-Mobile's Sidekick service before eventually recovering most of the data. Where is that data being stored?

And Google, which provides e-mail services for students, faculty and staff on Dieckmann's campus, has had numerous outages that have frustrated users so much that Google developed a Google Apps Status Dashboard and pumps updates to users via RSS. "And what about the privacy risks, security risks? Where is research data being stored? Dieckmann countered that the cloud question is most relevant for commodity services, but the tricky part is that the definition of commodity services is constantly changing. "To many people e-mail is e-mail," he said. "Storage is becoming more of a commodity. How do you handle identity and access management, what happens if the cloud service falls out from under you?" Woo said. When that service can come externally just are reliably and with the same service levels we can provide why do we need to spend significant resources to run it in-house?" But on the cost issue, Woo's contention is that most universities don't have a true handle on costs and therefore can't determine if the cloud is saving money. "Another thing to think about is are we just cost shifting. But Dieckmann compared the cloud with what has been happening internally in IT over the past few years in terms of centralizing servers into data centers and adding virtualization for added efficiencies and benefits.

Are we throwing things over the wall for others to worry about," said Woo, who wonders about the burden put on legal and purchasing departments. "We are not just looking at saving IT costs but costs across the institution." Dieckmann, in part, conceded Woo's point, saying he spends more time now with UWF's general counsel than he did before venturing out into the cloud. He said many of the same arguments IT made for centralization are now being turned against them via the cloud debate. "Part of what is uncomfortable here is that it is our apple cart that is now being upset," he said. "But we need not approach this as a poison pill. What if the cloud provider breaks the SLA, do we know how to measure harm if our storage disappears," she said. "We need to come to grips with the inevitability of the cloud," Dieckmann says. There are many advantages and we should be leading here rather than following." Woo contends the transfer to centralized IT has been based on trust, but questioned whether that same trust exists in the cloud. "Can we negotiate good service-level agreements (SLA). We don't have the maturity to negotiate those. The massive economy of scale involved in cloud computing can make it the most cost effective way to provide services for higher education, he contends. "Cost is not a minor concern today." When evaluating cloud services, he says users must focus on how the cloud alters the parameters on the old notion of outsourcing, an idea that was hot nearly a decade years ago but lost its sizzle for technological and other reasons.

He concedes the debate has many layers, but he points out that end-users have their own cloud choices now and that could eventually mean less IT control. "Our clients are voting with their feet," he said, in reference to students and faculty who go out on their own to online services. "Our challenge will be to combat the choices users make and to keep coherent IT enforcement," he said. "The next evolution of this is academic departments deciding to using the cloud and they are not doing that with IT or general counsel input. The cloud has benefits that can't be ignored, Dieckmann says, such as delivering infrastructure as a service, support for massive sharing, flexibility and a pay-as-you-go model. In some cases we have no control. We need to show some leadership." Follow John on Twitter.

NASA: With Atlantis docked, work begins today

With the NASA space shuttle Atlantis successfully docked at the International Space Station this afternoon, hatches have been opened and work has begun 210 miles above the Earth. Atlantis is carrying some 27,250 pounds of spare parts. The shuttle, which lifted off from the Kennedy Space Center on Monday afternoon, arrived and docked at the space station at 11:51 a.m. EST this morning.

The load is more than any other current space vehicle could handle. The shuttle brought up two equipment-carrying platforms. The Atlantis crew is now ready to work with the robotic arms onboard both the shuttle and the station to begin unloading some of that gear, according to NASA. The robotic arm on the shuttle will reach into its own payload bay and lift out one of the equipment carriers and hand it off to the robotic arm on the space station. Both will be attached on either side of the station's truss or backbone during the 11-day mission. The astronauts running the inspection used a suite of cameras and lasers designed to give them 3-D views of the shuttle's heat shield. On Tuesday, the Atlantis crew spent about five hours using the shuttle's 50-foot-long robotic arm, along with its 50-foot-long orbiter boom sensor system, to take pictures of the shuttle craft's wings and nosecap, to inspect for damage that might have occurred during takeoff.

This morning, as the shuttle approached the space station, Atlantis Commander Charlie Hobaugh rotated the vehicle backwards so astronauts on the space station could take pictures of the shuttle heat shield with 800 millimeter and 400 millimeter lenses. The equipment being delivered during this mission is considered critical to the operation of the space station, according to NASA. At this point, there are only six flights left for the space shuttle fleet before it's scheduled to be retired. All of the images will be sent back to ground control, where engineers will inspect them for any problems with the shuttle's thermal protection system, which will be needed to protect the craft during the blazing temperatures it will encounter during re-entry into the Earth's atmosphere. The equipment that needs to go up is being delivered in order of highest priority. The astronauts are expected to make three space walks to unload the parts from the shuttle and connect them to the sides of the station's truss .

Since this is the first mission to deliver what scientists hope will turn into a trove of spare parts, they're taking up the most important pieces.

Apple Plans for 'World-Mode iPhone' Bad News for AT&T

The Apple rumor mill claims that work is underway todevelop a 'world-mode' iPhone capable of operating on both CDMA and GSM/UMTS networks. Rumors also persist that Verizon will begin to carry the iPhone in 2010. All of these rumors suggest that the AT&T honeymoon with the iPhone is nearing an end. World mode.

A 'wordl-mode' iPhone could signal the end of exclusivity and be bad news for AT&TThese are just rumors at this point, but when a rumor is both pervasive and tenacious there is usually a reason. Without iPhone exclusivity, what does AT&T bring to the table that would entice customers to switch to, or stick with the wireless provider? That gives AT&T some reason to be concerned. AT&T has found itself under both customer and regulatory scrutiny for a variety of issues from inadequate service to questionable business practices. The move to a 'world-mode' version of the iPhone would be good news for Apple.

Users havecomplained about network speed, the lack of MMS messaging (which AT&T eventually added), the lack of data tethering for the iPhone (although the device itself is technically capable). AT&T has also drawn the attention of the FTC and the FCC regarding device exclusivity and other exclusionary practices. Analysts have already suggested that Apple could double iPhone sales by dropping the exclusivity with AT&T, and the world-mode device could also enable Apple to save manufacturing costs by allowing it to manufacture just one version that serves all markets. The news is also potentially great news for rival wireless provider Verizon. Of course, the recent iPhone launch in China has been a bit tepid so there are no guarantees. Verizon has been aggressively attacking the iPhone with recent marketing campaigns for the new Motorola Droid, but it has also been very clear that it is still open to welcoming the iPhone to its portfolio of devices. iPhone battle becomes a win-win for Verizon because whichever you choose you could get it from Verizon.

With an iPhone available from Verizon the whole Droid vs. AT&T does have devices that aren't iPhones. I know. No, really. I am an AT&T customer and I gave up my iPhone for alternate hardware.

There are rumors of AT&T also embracing the Google Android platform in the near future, and AT&T has generally offered the most compelling Windows Mobile devices like the HTC Tilt and the HTC Pure. AT&T was a tough competitor before the iPhone and it seems fair to assume the company won't just fold its tent and fade away when it loses iPhone exclusivity. I don't know if coming late to the Android party, or even adding a device as exciting as the upcoming HTC HD2 (which may or may not even come to AT&T) can replace iPhone exclusivity though. But, rollover minutes lose relevance when all major carriers now offering some form of unlimited minutes to a select calling circle, and some form of unlimited minutes between mobile devices, and the rising popularity of calling plans with unlimited minutes to begin with. Without the iPhone exclusivity, AT&T's only real strategic advantage right now is rollover minutes.

Verizon and Sprint are working on implementing 4G networks, and AT&T is filing lawsuits because it doesn't want to look bad for having such sparse 3G coverage. Hopefully its been enough of a warning that AT&T is working on a Plan B that involves more than adding an Android device and trying to get injunctions against clever marketing campaigns. Rumors of iPhone exclusivity ending have circulated for awhile. Tony Bradley is an information security and unified communications expert with more than a decade of enterprise IT experience. He tweets as @PCSecurityNews and provides tips, advice and reviews on information security and unified communications technologies on his site at tonybradley.com

Apple marginally improves App Store approval process

The App Store approval process appears to be improving in fits and starts. Wired was among the first to note that the Apple Dev Center site now features a table that displays whether a submitted application is "Waiting for Review," "In Review," or "Ready for Sale," along with a timestamp for each entry. Developer who submit their programs into Apple's black box can now get limited status updates on the state of the process.

But we've confirmed the update, which has also been mentioned by some iPhone developers on Twitter. Previously, the site gave only extremely impersonal statistical information about the overall approval rate, along the lines of Apple's claims last March that it approved 98 percent of applications within a week of submission. Of course, that's about the bare minimum information that the company should provide, and the system appears to be new enough that we don't yet know how it will handle the bizarre rejections that have plagued the approval process like crows stalking Tippi Hedren. This move is a step in the right direction, but it's also a little ridiculous given that the App Store has been open for well over a year-this is the kind of basic feedback that should have been in place from day one. The real problem here is that it seems that Apple doesn't treat developers-outside of the inner circle it parades around at events-with the same basic courtesy that it accords its customers. Meanwhile, prestigious developers continue to walk away from the platform, the latest being Facebook iPhone app developer Joe Hewitt, who has not shied away from expressing his disappointment with the App Store review process.

This, despite the fact that not only are pretty much all iPhone developers also Apple customers, but they pay to develop apps for the platform (and many have told me in the past that they'd gladly pay more if it were accompanied for a higher level of service). Imagine you, as a customer, bought a computer from Apple's online store. Should your order suddenly be canceled, wouldn't you want an explanation? Would you expect the ability to know the status of your order? And should you not be satisfied with that explanation, wouldn't you want some form of recourse, whether it be simply talking to a manager? And consider that not only are developers paying money directly to Apple, but they're investing in Apple, in the success of its platform-they're tying their own livelihood to Apple's product. These are all things we take for granted as part of the consumer experience, but they're elements woefully lacking from most developers' interactions with Apple.

They have a stake in Apple's prosperity so, despite being labelled as whiners and complainers, they want Apple to succeed. Sure, for every developer that decides to stop working on the iPhone there are a thousand that stay. You'd think that it would entitle them to a little respect. But you can bet Apple looks at data to figure out why people decide not to buy its products-I only hope it's being as vigilant about the developer side of the equation.

VMware ties disaster recovery to vSphere, lifting obstacle to adoption

VMware's Site Recovery Manager is now supporting vSphere, eliminating one of the obstacles preventing customers from upgrading to the latest version of VMware's virtualization platform. VMware on Monday released SRM version 4, with support for vSphere and other upgrades including a "many-to-one failover [that] protects multiple production sites with automated failover into a single, shared recovery site." Because Site Recovery Manager did not immediately support vSphere, numerous customers have delayed upgrades from 3.5, acknowledges Jon Bock, product marketing manager for VMware's server business unit. vSphere 4, the successor to ESX Server 3.5, was unveiled in April but until now did not work with Site Recovery Manager, VMware's software for recovering virtual machines in case of disaster.

Now that SRM supports vSphere, adoption should accelerate, he said. "vSphere was a significant change that we had to update the add-on products for. But the months-long delay is similar to delays often seen between the release of a new operating system and add-on products, he said. "A customer who has important production applications on ESX 3.5 is probably not going to upgrade to vSphere 4 the day after it's released," Bock said. In a perfect world, we'd love to have all the new releases of products released on the same day as the platform," Bock said. vSphere is still not supported by VMware View, the vendor's desktop virtualization software. Lifecycle Manager just gained compatibility with vSphere in a new release a few weeks ago. VMware View will be compatible with vSphere in its next release, expected in 2010, according to a VMware spokeswoman.

In addition to support for vSphere, Site Recovery Manager now supports NFS storage, along with Fibre Channel and iSCSI, which were already supported. "We have a lot of interest in NFS from customers looking at using that in important applications," Bock says. VMware provides an integration module to partners, and most of the major storage companies have made their products compatible with Site Recovery Manager. SRM works by integrating tightly with storage array-based replication. Shared recovery sites, the other new feature, could be useful for companies with multiple branch offices, Bock said. The new version of SRM is available now and costs $1,750 per processor.

Overall, the new release is "focused on expanding the use cases for Site Recovery Manager," he said. SRM was first released in June 2008 and has been purchased by more than 2,000 customers, Bock says. Virtualization offers inherent advantages when it comes to disaster recovery, since it eliminates the need to recover the actual physical server an application was running on, Bock notes. That's still a small portion of VMware's 150,000 customers overall. Some customers have been using SRM not for disaster recovery but to move applications from one site to another when they are switching data centers, he said.

SRM support for vSphere was a highly anticipated feature, says ITIC analyst Laura DiDio. "Disaster recovery and backup are in every customer's top five checklist of things you must have," she says. Still, disaster recovery is the main purpose for the software. Follow Jon Brodkin on Twitter

ITU Telecom World expo shifts in response to economic crisis

The ITU Telecom World exhibition has returned to Geneva after a visit to Hong Kong in 2006 - and has brought many Asian exhibitors back with it. The booths of China Mobile, ZTE and Datang Telecom Group loom over the entrance to the main hall, alongside those of NTT DoCoMo and Fujitsu, while upstairs Huawei Technologies and Samsung Electronics booths dwarf that of Cisco Systems, which has more meeting rooms than products on display. "Ten months ago, people were urging us to cancel the event," said Hamadoun Touré, secretary-general of the International Telecommunication Union, which organizes the exhibition and the policy forum that runs alongside it. There are also signs that the way some companies are using the show is shifting. The pessimists feared that the show would attract neither exhibitors nor visitors, as companies slashed marketing budgets and cut back on business travel in the midst of the economic downturn.

The ITU still expects 40,000 visitors at this year's show; 82,000 turned up at the last Geneva event, in 2003. This year, around half the show is occupied by national pavilions: Saudi Arabia has the biggest, followed by those of Spain and Russia. While the show is noticeably smaller than previous editions - it only occupies Halls 2, 4 and 5 of the sprawling seven-hall Palexpo exhibition center, with some yawning gaps between stands, Touré is satisfied. "It's a good show, despite the crisis," he said. Other European nations, including Belgium, France and the U.K., also have pavilions, but by far the most numerous are those of the African nations: Burundi, Egypt, Ghana, Kenya, Malawi, Nigeria, Rwanda, Tanzania and Uganda. The biggest company stands are those of the Asian network operators and equipment manufacturers, with the U.S. and Western European countries keeping a low profile. Microsoft and IBM have booths, but you'd barely notice. This domination of the show floor is not down to size alone: It's also about tactics.

There were actually only three of them, but their effect was magnified by loud music and the multiple video walls on the booth. Russia deployed what looked like an army of violinists dressed mostly in sequins on its stand on Monday. China Mobile has taken a similar route, with the logo of its 3G mobile brand, Wo, swirling and pulsing hypnotically across the walls and even the ceiling of its booth. Similar exhibits fill the stands at NTT DoCoMo and Samsung. ZTE has taken a more traditional route, with glass cases full of mobile phones, modems and cellular base stations. On the Cisco booth, there are almost no products to be seen - unless you count the looming bulk of one of its TelePresence systems, linking the booth in high resolution to similar systems around the world.

This shows images of the products that can be rotated on screen to examine them from different angles - and even measured or dismantled so that prospective buyers can figure out whether they would fit in their data center. Other elements of the Cisco product range are present virtually thanks to another screen, supplied by Massachusetts-based Kaon Interactive. Like Secretary-General Touré, Cisco faced a crucial decision last year about whether to maintain a show presence in Geneva. "One year ago, it wasn't clear how many customers were going to make this trip," said Suraj Shetty, the company's vice president of worldwide service provider marketing. That's why the rest of the stand is given over to meeting rooms. "Our focus is on customer intimacy," Shetty said. However, the company realized that "this could be used as an opportunity to shift how we get contact with customers," he said. Carrier Ethernet specialist Ciena has taken a similar approach.

Like Cisco, it prefers to show products virtually, rather than physically. "Computer graphics and touch screens are more effective in these cases. Its stand, close to Cisco's and even more discreet, consists entirely of meeting rooms. That's the trend," said Ciena CTO Stephen Alexander. If you're buying bulky network or data center infrastructure, then don't expect to kick the tires at a trade show next year - although you might be able to click on them, on the booth's screen or your own.

Intel/AMD deal could help solve virtualization compatibility problems

The $1.25 billion Intel/AMD settlement announced Thursday could improve competition in the server hardware market and solve some lingering problems related to server virtualization, analysts say. 50 greatest arguments in networking: AMD vs. But a new five-year cross-license agreement between the companies raises the possibility that Intel and AMD will share information on their instruction sets and enable live migration across servers with different processors, he says. Intel Today, a virtualization technology known as live migration lets customers move workloads from one physical server to another, but only if both servers contain processors from the same chip maker, according to Forrester analyst James Staten. "If you look at the virtualization instruction sets that have been implemented by AMD and Intel, they are incompatible with each other," Staten says. "If you build a virtualization pool and do live migration from one system to another, it has to be all Intel, or it has to be all AMD." The Intel/AMD settlement, which ends various antitrust and patent cross-license disputes, doesn't explicitly talk about virtualization, Staten notes.

Gartner analyst Martin Reynolds agrees the Intel/AMD settlement could be good news for virtualization customers. "If they were to integrate virtualization more deeply into the processors as a single standard that companies use, it's possible virtualization could become less expensive," Reynolds says. In the wake of the settlement, there are several other potential areas for new levels of compatibility between Intel and AMD processors, Staten says, including memory and power management, and security. The virtualization incompatibility has mainly harmed AMD, because the issue forces customers to standardize on one type of server and Intel has a dominant market share, according to Staten. Broad collaborations between the rivals should not be expected, though. "These are two fighters who just took a lot of bruises over the last two years," Staten says. "They're not about to run to the center of the ring and shake hands." In lawsuits filed against Intel, AMD claimed that Intel illegally forces customers into exclusive deals with cash payments, discriminatory pricing, marketing subsidies and other practices. I think that's beneficial for all." AMD benefits from the settlement more than Intel does, because it eliminates many concerns customers have about purchasing AMD-based servers, according to Staten.

The settlement prohibits Intel from "offering inducements to customers in exchange for their agreement to buy all of their microprocessor needs from Intel," and other anticompetitive practices such as inducing customers to limit or delay sales of AMD products. "Intel agreed to a set of rules of the road for how they will conduct business going forward," says AMD spokesman Drew Prairie. "It should help create a fair and open competitive environment where products compete on their merits, and where innovation is rewarded by the marketplace. Even if customers like AMD technology, they might have chosen Intel-based servers instead because of concerns about AMD's viability. The time and money allocated to fighting Intel in court may also have distracted AMD from product development. "Having those hindrances gone will definitely help AMD because their CPUs are quire competitive at this point," Staten says. Moreover, if AMD's allegations were correct, that means Intel's business practices were preventing OEM vendors from embracing AMD processors to the extent they would have liked. The settlement also makes AMD more attractive to outside investors, Reynolds says.

While both companies are embracing multi-core processors, Intel is taking a homogenous approach in which every core is the same and AMD is using different types of cores in the same CPU for different workloads, according to Staten. AMD is taking a different approach than Intel to the server market. AMD is also trying to go down the multi-core path faster than Intel, with attempts to get 16- and 24-core processors on the market before its rival. Generally, AMD is about a year behind Intel's technology, but turns a profit by making products that are cheaper and cost less to build, Reynolds said. "Generally the server vendors use the product that most meets their needs," he says. "They know their customers are smart and will buy the product that delivers the best value." Follow Jon Brodkin on Twitter. Reynolds said he doesn't expect the settlement to cause any major shifts in how OEM vendors approach Intel and AMD, however.

Expert provides more proof hackers hijacked Hotmail accounts

It's almost certain that hackers obtained the Hotmail passwords that leaked to the Internet through a botnet-based attack, a researcher said today as she provided more proof that Microsoft's explanation was probably off-base. "When I look at the infamous list of 10,000 Hotmail accounts, it just does not appear to be cataloged in the way you would normally expect from a phishing attack," said Mary Landesman, a senior security researcher at San Francisco-based ScanSafe. Microsoft acknowledged that "several thousand" Windows Live Hotmail usernames and passwords had been acquired by criminals, and that it believed the list was the result of a massive phishing attack. Landesman based her opinion on further analysis of the list that was posted to the Web two weeks ago. Google later said the same thing after another list surfaced with Gmail account details . "There are just too many inconsistencies in the list," Landesman said, ticking off several characteristics of the Hotmail list that didn't fit with phishing results researchers have uncovered in the past, ranging from relatively strong passwords to typos. "There were many misspellings of 'hotmail,' and other typos that you wouldn't expect people to make when they were logging in live to their accounts," Landesman said, noting that those kinds of errors are inconsistent with phishing attack lists.

Some researchers who analyzed the leaked list said that it was dominated by weak passwords , with the simple "123456" and "123456789" as the most popular. She also disputed the notion that a large number of the accounts used very weak passwords, another clue that the users were unsophisticated and thus more likely to fall for a phishing scam. While true, that doesn't tell the whole story, Landesman countered. "123456 was the most frequently used password, but it appeared only 63 times out of the +10,000 records," she said. Landesman first refuted Microsoft's contention that the Hotmail passwords had been obtained by phishers last week. That would represent just over 6/10ths of 1%. "I'd call most of the passwords certainly strong, respectable passwords, and not the type of passwords from someone naive," Landesman said. "That doesn't fit the profile of people who you might think would be susceptible to phishing scams." In fact, the treasure trove of Windows Live ID usernames and passwords that Landesman uncovered in August, which she believes is related to the leaked Hotmail list, contained a large number of accounts owned by corporate and government users, who typically relied on what she called "very strong" passwords. "A [malware-based] keylogger attack turns all the advice about strong passwords on its side," Landesman said, speculating that users with stronger passwords were less likely to succumb to the deceit of a phishing attack. "In cases where you see very strong passwords, it's almost certain that data theft was involved," she added. She added more to her list of proof points last Wednesday in a follow-up entry to the ScanSafe threat alert team's blog.

Native iPhone support ready for Lotus Domino

IBM/Lotus said next week it will ship the long-anticipated real-time access support for the iPhone on its Domino messaging platform. In January, IBM announced that it would add support for ActiveSync to its Lotus Notes Traveler, a server add-on that provides real-time replication between mobile devices and Notes. Lotus Domino support for the iPhone uses the Apple device's mail, calendar and contact application and synchronizes data between the two platforms in real time using Microsoft's ActiveSync protocol. It is the updated Traveler software in Domino 8.5.1, which was released Tuesday, that provides the iPhone support.

Updates to Traveler in Domino 8.1.5 add remote wipe, device lock, password management, and external calendar integration to the Symbian platform. Traveler already works with devices based on Windows Mobile and Symbian. Lotus is playing a bit of catch-up as Microsoft and other vendors such as Kerio who offer push e-mail for the iPhone. Also from Network World: Lotus goes after Microsoft's 'ridiculous and fabricated' figures The only thing iPhone users have to add to their device is a configuration file that tells the iPhone how to find the user's mailbox on the Domino server. Motorola, Nokia, Palm, Sony Ericsson, Symbian also support ActiveSync on their mobile devices.

For initial set-up, the iPhone's Safari browser is used to access the Domino server and download the configuration file. Those credentials are stored on the device so the iPhone and Domino can trade data without further user intervention. When the user signs onto Domino to get the configuration file, the user's sign-on credentials are captured by the iPhone. Lotus Notes users have had to suffer with e-mail access via the iPhone's Safari browser and the Notes Web Access client. We want to support all the devices out there and this is the next one we have added." The Domino iPhone support also features limited management capabilities, including the ability to remotely wipe data if the device is lost or stolen.  Follow John on Twitter

With that configuration, users have to manually connect to the Domino server and go through each individual e-mail via the browser. "It has rich email, attachment support and calendaring capability and is the same user experience a user would get using the iPhone against Exchange or Google," said Ed Brill, director of product management for Lotus Software. "Clearly the iPhone is increasingly a component of an enterprise strategy.

Google Apps scores in LA, with assist from Microsoft

Los Angeles City Council approved a US$7.25 million five-year deal Tuesday in which the city will adopt Gmail and other Google Apps. According to Los Angeles City Council minutes, just over $1.5 million for the project will come from the payout of a 2006 class action lawsuit between the City and Microsoft. Google is touting the deal as a major endorsement of its cloud-based approach to computing, but it turns out that some of the funding is indirectly coming from an unlikely source: Microsoft. Microsoft paid $70 million three years ago to settle the suit, brought on behalf of six California counties and cities who alleged that Microsoft used its monopoly position to overcharge for software.

Los Angeles City Council approved the deal unanimously on Tuesday, according to Google Spokesman Andrew Kovacs. Microsoft has paid out more than $1 billion in other class-action settlements based on similar claims. The migration from the city's Novell GroupWise e-mail servers will be handled by contractor Computer Sciences Corp. The five-year contract will cost Los Angeles about $1.5 million more than simply sticking with Novell. Other applications such as calendaring, document sharing and chat will be handled by Google Apps too. But because the city will get extra storage capacity from Google, while at the same time being able to run other software on the Novell servers, it's worth the cost, according to an Oct. 7 city finance committee memo written by City Administrative Officer Miguel Santana.

The Los Angeles deal may hint at how this product will work. Google has pushed Google Apps as an option for government agencies, promising to ship a product called Government Cloud, which will be certified under the Federal Information Security Management Act (FISMA), sometime next year. According to a Sept. 15 memo from the Los Angeles Information Technology Agency, Google will "provide a new separate data environment called 'GovCloud.' The GovCloud will store both applications and data in a completely segregated environment that will only be used by public agencies." This GovCloud would be encrypted and "physically and logically segregated" from Google's standard applications. Because data would be encrypted and then stored on many different servers, Google's administrators wouldn't typically be able to access the information, although there would be so-called "Super Administrators" who would be able to recompile the data and read it. The data would be stored only in the U.S. and only accessible to U.S citizens who have undergone security clearance.

The city would own the data and would be notified of "any request of data or security breach," the memo states. They convinced Los Angeles council members to tack on a "liquidated damages" clause to the contract that would award the city a payout in the event of a data breach. Critics are still worried about security and privacy, though. Kovacs of Google downplayed privacy and security concerns over the project. "One thing that was very clear in council today," he said. "They believe that Google Apps will make the city more secure than their current solution."

Microsoft shows off Bing tool for measuring ad effectiveness

Microsoft on Monday demonstrated a new tool for its Bing search engine that will allow advertisers to measure the effectiveness of their ads with online users. Mehdi pointed out that statistics show that 39 percent of Web users do 65 percent of the online searches, so it would be beneficial for advertisers to see which of those "heavy users" are targeting certain ads, versus which ads are favored by "light users." The tool Microsoft created shows where the interest in a marketing or advertising campaign is specifically coming from, he said. Speaking at the IAB MIXX Conference and Expo 2009 in New York on Monday, Yusuf Mehdi, senior vice president of Microsoft's Online Audience Business group, showed off what he called a "user-level targeting" tool that allows Microsoft to see which search-based ads that appear in the Bing search engine are getting the most traffic and from where. "What we're doing with Bing for vigorous measurement is we're matching the exact ad online with the exact user," he said.

This measuring ability for Bing was demonstrated as part of Mehdi's presentation, in which he discussed how Microsoft is applying lessons it's learned from studying advertising campaigns and creating technology to reflect that learning. You have to pick and focus." Microsoft revamped and rebranded its Live Search engine "Bing" in June, and making it more effective for search advertising is something the company continues to work on, Mehdi said. One of those lessons was what he characterized as "relentless measurement and optimization" to find out what ads are most effective so they can be better targeted to their proper audience. "One of the big things is trying to build a loyal fan base for the product," he said. "You can't just go out and put your message everywhere. It was unclear from Mehdi's presentation whether this technology is available for advertisers using Bing today or whether it's just something Microsoft is using internally. This kind of ability to measure what kinds of online advertising is working with users is becoming essential as more and more business is being done on the Web.

A representative from Microsoft's public relations firm, Waggener Edstrom, declined to answer follow-up questions about the technology or his presentation. In fact, Microsoft competitor Adobe Systems - an executive from which spoke before Mehdi on Monday - last week said it was purchasing Web analytics company Omniture to build measuring technology directly into Adobe's tools for creating online media.

Is the Cisco MARS mission going into abort on non-Cisco security devices?

Is Cisco freezing support for any new non-Cisco security devices in the Cisco Security Monitoring, Analysis and Response System (MARS) appliance? Since the SIEM market consists of equipment aimed at consolidating and correlating event information from multiple vendor equipment, several of Cisco's rivals, including NitroSecurity and Q1 Labs, contend Cisco MARS will lose its relevance if Cisco freezes support for non-Cisco appliances. "As of a certain timeframe, they'll support what they support, and that's it," claims Jerry Skrula, vice president of marketing at SIEM vendor NitroSecurity. Cisco isn't confirming it or denying it, but Cisco rivals claim they're hearing from Cisco customers that Cisco won't add support for additional non-Cisco security devices to MARS, a security information and event monitoring (SIEM) appliance used by about 4,000 Cisco customers.

The SIEM vendor claims to be hearing this from Cisco customers and others in industry. NitroSecurity states "industry sources have confirmed that Cisco has begun informing its customers of a freeze on MARS support for most non-Cisco event sources and is encouraging customers to find an alternative for log collection and event analysis for non-Cisco event sources," though NitroSecurity declined to reveal these sources specifically, merely noting they were Cisco customers and others in industry. Skrula admits he doesn't know the specific timeframe but NitroSecurity yesterday kicked off a so-called "MARS Migration Program" targeting Cisco SIEM customers. As part of its push to get MARS users, NitroSecurity is offering its own NitroView product, promising Cisco MARS customers "custom-tailored financial incentives" to switch. As for Cisco itself, spokesman David Oro, said "We are not going to address competitive rumors, but what I can tell you is that any decisions about MARS are future roadmap discussions that are internal and subject to change depending on market conditions and customer needs." He notes that Cisco continues to release "new versions of MARS that include support for new device features (like Botnet Traffic Filter and Global Correlation reporting in 6.04), new MARS application features (numerous improvements for operational features in the past couple of releases), and signature updates for Cisco and non-Cisco devices. At Q1 Labs, another Cisco SIEM rival, Brendan Hannigan, president and COO, and John Burnham, vice president of corporate marketing there, also say they believe Cisco won't be supporting new non-Cisco devices in MARS. And evidence this week of glee in that prospect is abounding, with rival ArcSight sponsoring a Google link that turns up "Worried about Cisco MARS?" when a search is done for "Cisco MARS" and another competitor, CorreLog, sponsoring "Cisco MARS Alternatives." But is it all just fear-mongering?

There is no internal or external end-of-service plan at this time, and MARS is available from Cisco and our partners." MARS 6.0.4 currently supports several non-Cisco security products, including McAfee IntruShield and Entercept, the NetScreen IDP, Symantec, NIDS, Enterasys Dragon, Qualys Guard and eEye Retina products for scanning and vulnerability assessment.

Microsoft confirms phishers stole 'several thousand' Hotmail passwords

Microsoft today confirmed that thousands of Windows Live Hotmail account usernames and passwords had leaked to the Internet, but said the credentials were "likely" stolen in a phishing attack. Earlier today, Neowin.net reported that more than 10,000 accounts had been compromised and speculated that Hotmail had either suffered a breach or an aggressive phishing campaign had collected the usernames and passwords by duping people into divulging the information. "We determined that this was not a breach of internal Microsoft data and initiated our standard process of working to help customers regain control of their accounts," a Microsoft spokeswoman said in an e-mail to questions posed earlier today by Computerworld . Microsoft did acknowledge that Hotmail accounts had been compromised. "Over the weekend Microsoft learned that several thousand Windows Live Hotmail customers' credentials were exposed on a third-party site due to a likely phishing scheme," the same spokeswoman added. "That's a big result for a phishing campaign," said Dave Jevans, the chairman of the Anti-Phishing Working Group (APWG), an industry association dedicated to fighting online identity theft. "But it's not outside the realm of possibility. The company denied that its Web-based e-mail service had been hacked and the account log-in information stolen because of some lapse on its part. We've seen 50,000 to 75,000 [compromised] accounts when phishers target an ISP with millions of users." Hotmail has about 400 million registered users, according to Microsoft, although the company declined to spell out how many are active users of the service. "A .05% rate, which is what 100,000 users would represent, isn't unreasonable for 10 to 20 million users," Jevans said. "They wouldn't have to spam every [Hotmail] user to get that." According to Neowin.net, which first reported the Hotmail incident, more than 10,000 accounts had been compromised.

If the 10,000 accounts for A-B are extrapolated to the full alphabet, it's possible that over 100,000 accounts were compromised. "If that's the case, this would definitely be one of the biggest single phishing events," said Jevans. "But it could be the result of a long period of time, months and months of harvesting." Although the number of phishing attacks declined earlier this year, they have recent stormed back, said Jevans. "They're close to, or at, an all-time peak," he said. However, Neowin said it had seen only a partial list - accounts with usernames starting with "A" or "B" - and suspected that the total could be much larger. Both Microsoft and Jevans recommended that all Hotmail users change their passwords, just in case. "Change it, ASAP," urged Jevans.

Computer programmers set for smash-mouth brain battle

A smart people smack-down is set to start next week where thousands of university computer researchers will pit their brains and machines in a grueling battle of logic, strategy, and mental endurance. Layer 8 Extra: 15 genius algorithms that aren't boring During the competition, ten to twelve problems are attempted in a five hour period. The 34th annual IBM-sponsored Association for Computer Machinery (ACM) International Collegiate Contest (ICPC) pits teams of three university students against eight or more complex, real-world problems, with a nerve-wracking five-hour deadline. The problems are of varying difficulty and flavor.

The goal is that every team solve two problems, that every problem is solved, and that no team solve them all, according to ACM. Contests in the past have included problems that searched for a missing boat at sea, triangulated the location of a faulty transmitter, computed golf handicaps, stacked pipe of varying diameters in a fixed width bin, coded or decoded messages, printed braille, sought an exit to a maze, processed satellite images and solved a math problem. ACM says it wants two problems that could be solved in an hour by a first or second year student, two that could be solved in an hour by a third year student, and two that will likely determine the winners. Problems are presented with no more than a page of text, a helpful illustration, a sample input set with and accepted output set, ACM states. And judging is relentlessly strict, IBM says. Teammates collaborate to rank the difficulty of the problems, deduce the requirements, design test beds, and build smart software systems that solve the problems under the intense scrutiny of expert judges. The students are given a problem statement, not a requirements document.

Each incorrect solution submitted is assessed a time penalty. They are given an example of test data, but they do not have access to the judges' test data and acceptance criteria. The team that solves the most problems in the fewest attempts in the least cumulative time is declared the winner. Some problems require a knowledge and understanding of advanced algorithms. For a well-versed computer science student, some of the problems require precision only.

Still others are simply too hard to solve - except for the world's brightest problem-solvers, according to IBM. The Battle of the Brains is the largest and most prestigious computing competition in the world, with more than tens of thousands of students from universities in approximately 90 countries on six continents participating. Previously, the 2009 ACM-ICPC World Finals took place in Stockholm, Sweden, where a team from St. Petersburg University of Information Technology, Mechanics and Optics in Russia emerged as the world champion for the second year in a row. Since IBM began sponsoring the contest in 1997, participation has grown from 1,100 to more than 7,100 teams. Regional bouts will begin in the United States on October 18 and continue through December, sweeping from continent to continent. Only 100 three-person teams will advance to the World Finals on February 5, 2010 hosted by Harbin Engineering University in Harbin, China. "The ACM-ICPC affords students the opportunity to showcase their talents and gain exposure among top recruiters," said Dr. Bill Poucher, ICPC Executive Director and Baylor University Professor. "The contest is also a forum for advancing technology in an effort to better accommodate the growing needs of the future."