english | deutsch | RSS 2.0 | Atom 1.0

Contact me: Send mail to the author(s) E-mail

My favorite Blogs

My favorite Board Games

Ultimate Boot CD

Categories on this blog

On this page

'Unhackable' Android can be hacked, Black Hat researchers say
Microsoft, Yahoo Test Search Pact
The Enemy Within
Apple vs. Adobe: Is Flash dying?
Windows Home Server “Vail” Overview and Review
Adobe Gives Up on iPhone App Development After CS5
1.5 Million Stolen Facebook IDs up for Sale
Internet 2009 in numbers
Why Apple Won't Allow Adobe Flash on iPhone

Archive

Total Posts: 312
This Year: 8
This Month: 2
This Week: 1
Comments: 1

Disclaimer
The opinions expressed herein are my own personal opinions and do not represent my employer's view in any way.

 Thursday, July 29, 2010
Thursday, July 29, 2010 10:39:48 PM UTC ( EN | mobile | security | tech )

Network World - LAS VEGAS -- Once thought to be unhackable, the Android phone is anything but, according to researchers presenting at Black Hat 2010.

FBI details worst social networking cyber crime problemsNot only has malicious software cloaked in a wallpaper application stolen personal information from infected phones and sent it to a Web site in China, but researchers from Lookout Mobile Security have found a way to take the phones over completely - including top-of-the-line models hawked by major wireless carriers.

In one presentation, Lookout's CEO John Herring said the Jackeey Wallpaper app, which has been downloaded millions of times, can gather passwords, browser history, the subscriber ID and SIM card numbers and text messages.

In a separate presentation, researchers said top-of-the-line Android phones used by Sprint and Verizon can be taken over completely by attacking known flaws in the Linux operating system that underpins Android, researchers reported at Black Hat 2010. "It gives you root control, and you can do anything you want to do" with the phone, says Anthony Lineberry, a researcher for Lookout Mobile Security.

The company says Android's reputation for security may be exaggerated. "It survived the recent pwn2own slay fest unscathed, but this does not mean it is safe by any means," the company said in describing Lineberry's talk.

The best way to distribute malware that could exploit the flaw - known as CVE-2009 1185 - is via Android applications that customers might acquire free or buy from the Android Market. Installing the booby-trapped application would give root control of the device, Lineberry says. "Root is kind of God mode in the context of Linux. Once you have that, you have pretty much any system privilege."

CVE-2009 1185 has been known for more than a year and can be patched, but so far the carriers have not issued patches, Lineberry says. The root-control exploit has been successfully carried out in Lookout labs on EVO 4G (Sprint), Droid X (Verizon), and Droid Incredible (Verizon) as well as older models G1 and Hero, he says.

But root control is unnecessary in order to carry out the type of attack executed by Jackeey Wallpaper, according to another Lookout researcher, Tim Wyatt. Applications require permissions in order to access features of the phone, and these permissions can be exploited. So, for instance, an application that tells the customer the nearest Chinese restaurant would need access to the phones GPS capabilities.

When selling applications, developers must list all the permissions the application requires to work, and the customer must sign off on allowing those permissions. An application that sorts SMS messages but requires Internet access may seem suspicious, and customers might bail out of buying the application.

But some permissions sound innocuous, Wyatt says. Customers might not know what the permission "Import Android log" means, but approve an application that requires it because the name of the permission doesn't sound threatening. But the logs can reveal browsing histories, passwords, phone numbers and a wealth of other data, he says.

Malicious applications with Internet permissions can be crafted to send the data in the background or display innocuous Web sites to mask where the data is being sent, Wyatt says.

The best course for users is to beware the applications they buy and if they are suspicious, not to download the apps, Lineberry says.

Lookout has carried out a study it calls the App Genome project that examined Android and iPhone applications for what permissions they have and what malicious activity they might carry out with the set of permissions they have. An application might use the permissions legitimately, but in the hands of a hacker could cause mischief, the company says.

Part of the permission system in Android allows applications to tap each other's resources, so an application without permission to access the Internet might have access to an application that does and so use the Internet anyway, the researchers say.

Source: www.computerworld.com

| Trackback | # 
 Thursday, July 22, 2010
Thursday, July 22, 2010 11:32:50 PM UTC ( EN | internet | markets | microsoft | Yahoo )

Yahoo Inc. engineers began testing keywords in Microsoft Corp.'s search advertising system for the first time last week, a key step toward implementing a comprehensive search agreement the two companies hope will reshape the industry.

The so-called "shadow tests" replicate how keywords will perform when Yahoo's advertisers are plugged into Microsoft's adCenter system, which will soon power the paid search businesses of both companies. The test results will help determine whether Yahoo and Microsoft can flip the switch on their unusual partnership this fall, as they hope.

"The next couple of weeks are going to be critical," said David Karnstedt, who runs search engine marketer Efficient Frontier.

The tests, which come almost one year after the alliance was announced, are part of a meticulously planned blueprint that Yahoo and Microsoft hope will position them as an effective counterweight to industry leader Google Inc.

Though the partners will have less than a third of the $12.4 billion U.S. search market, they want to achieve enough scale to generate better returns for advertising clients, more revenue for themselves and greater profits for investors.

Microsoft hopes the 10-year revenue-sharing pact will help turn its ailing online services division into a profitable business. Yahoo says the agreement will enable it to cut costs, focus on display advertising and deliver search results in more innovative ways.

Microsoft's Bing search engine will power searches on Yahoo Web sites. The two companies' small and midsize advertisers will use Microsoft's adCenter paid search platform to buy keywords and put ads on Web pages. Yahoo's sales staff will handle the largest advertising accounts for both companies.

While Yahoo is free to choose any partner for mobile search and search advertising, the company said it will rely on Microsoft in the U.S., Canada, the U.K. and France. Yahoo said the shift in each market is expected to coincide with the desktop migration schedule and it may soon add other markets.

For the past two months, Yahoo and Microsoft have been shadow-testing the algorithmic search technologies that generate the non-paid search results on their Web pages, according to Mark Morrissey, who runs Yahoo's integration team.

The project remains on schedule as engineers eliminate bugs in the system, he said. They aim to gradually increase the volume of Yahoo traffic that passes through Bing, eventually fabricating imaginary queries so they can stress-test the system beyond full capacity.

"The most challenging time is when we get to 100%-130% (of full capacity) because it tests not only the functionality, but the limits of the infrastructure," Mr. Morrissey said.

Shifting Yahoo's advertisers to Microsoft's adCenter will be far more complicated. Microsoft must beef up adCenter to process four times the traffic it currently handles. Engineers also have been adding features from Yahoo's Panama search advertising system that weren't in adCenter, such as giving advertisers more control over where their ads appear.

Key questions remain. The most critical is whether the alliance will generate better returns for advertisers, as well as more revenue per search for the companies.

Second-quarter data from Efficient Frontier shows Microsoft's advertisers get an average return on investment that is 21% higher than Google--the industry standard--while Yahoo returns 25% less than Google. Advertisers focus on ROI because it enables them to measure the performance of search ads against the overall cost of such campaigns.

Chris Lien, who runs search marketer Marin Software Inc., said Yahoo's relatively low ROI might simply cancel out Microsoft's, reducing the combined platform's appeal to advertisers.

Still, Yahoo and Microsoft aim to make the transition in the U.S. and Canada by Oct. 15, giving advertisers, ad agencies and search-engine marketers enough time to switch over before the crucial holiday shopping season. Mr. Morrissey said the two companies have hit every major milestone on schedule. But they won't flip the switch until they are comfortable the combined market place can deliver adequate ROI for advertisers.

Source: http://online.wsj.com

| Trackback | # 
 Wednesday, May 19, 2010
Wednesday, May 19, 2010 8:03:57 PM UTC ( EN | internet | security | tech )

When the Conficker computer “worm” was unleashed on the world in November 2008, cyber-security experts didn’t know what to make of it. It infiltrated millions of computers around the globe. It constantly checks in with its unknown creators. It uses an encryption code so sophisticated that only a very few people could have deployed it. For the first time ever, the cyber-security elites of the world have joined forces in a high-tech game of cops and robbers, trying to find Conficker’s creators and defeat them. The cops are failing. And now the worm lies there, waiting …

By Mark Bowden


Image credit: Alex Ostroy

The first surprising thing about the worm that landed in Philip Porras’s digital petri dish 18 months ago was how fast it grew.

He first spotted it on Thursday, November 20, 2008. Computer-security experts around the world who didn’t take notice of it that first day soon did. Porras is part of a loose community of high-level geeks who guard computer systems and monitor the health of the Internet by maintaining “honeypots,” unprotected computers irresistible to “malware,” or malicious software. A honeypot is either a real computer or a virtual one within a larger computer designed to snare malware. There are also “honeynets,” which are networks of honeypots. A worm is a cunningly efficient little packet of data in computer code, designed to slip inside a computer and set up shop without attracting attention, and to do what this one was so good at: replicate itself.

Most of what honeypots snare is routine, the viral annoyances that have bedeviled computer-users everywhere for the past 15 years or so, illustrating the principle that any new tool, no matter how useful to humankind, will eventually be used for harm. Viruses are responsible for such things as the spamming of your inbox with penis-enlargement come-ons or million-dollar investment opportunities in Nigeria. Some malware is designed to damage or destroy your computer, so once you get the infection, you quickly know it. More-sophisticated computer viruses, like the most successful biological viruses, and like this new worm, are designed for stealth. Only the most technically capable and vigilant computer-operators would ever notice that one had checked in.

Porras, who operates a large honeynet for SRI International in Menlo Park, California, noted the initial infection, and then an immediate reinfection. Then another and another and another. The worm, once nestled inside a computer, began automatically scanning for new computers to invade, so it spread exponentially. It exploited a flaw in Microsoft Windows, particularly Windows 2000, Windows XP, and Windows Server 2003—some of the most common operating systems in the world—so it readily found new hosts. As the volume increased, the rate of repeat infections in Porras’s honeynet accelerated. Within hours, duplicates of the worm were crowding in so rapidly that they began to push all the other malware, the ordinary daily fare, out of the way. If the typical inflow is like a stream from a faucet, this new strain seemed shot out of a fire hose. It came from computer addresses all over the world. Soon Porras began to hear from others in his field who were seeing the same thing. Given the instant and omnidirectional nature of the Internet, no one could tell where the worm had originated. Overnight, it was everywhere. And on closer inspection, it became clear that voracity was just the first of its remarkable traits.

Various labs assigned names to the worm. It was dubbed “Downadup” and “Kido,” but the name that stuck was “Conficker,” which it was given after it tried to contact a fake security Web site, trafficconverter.biz. Microsoft security programmers shuffled the letters and came up with Conficker, which stuck partly because ficker is German slang for “motherfucker,” and the worm was certainly that. At the same time that Conficker was spewing into honeypots, it was quietly slipping into personal computers worldwide—an estimated 500,000 in the first month.

Why? What was its purpose? What was it telling all those computers to do?

Imagine your computer to be a big spaceship, like the starship Enterprise on Star Trek. The ship is so complex and sophisticated that even an experienced commander like Captain James T. Kirk has only a general sense of how every facet of it works. From his wide swivel chair on the bridge, he can order it to fly, maneuver, and fight, but he cannot fully comprehend all its inner workings. The ship contains many complex, interrelated systems, each with its own function and history—systems for, say, guidance, maneuvers, power, air and water, communications, temperature control, weapons, defensive measures, etc. Each system has its own operator, performing routine maintenance, exchanging information, making fine adjustments, keeping it running or ready. When idling or cruising, the ship essentially runs itself without a word from Captain Kirk. It obeys when he issues a command, and then returns to its latent mode, busily doing its own thing until the next time it is needed.

Now imagine a clever invader, an enemy infiltrator, who does understand the inner workings of the ship. He knows it well enough to find a portal with a broken lock overlooked by the ship’s otherwise vigilant defenses—like, say, a flaw in Microsoft’s operating platform. So no one notices when he slips in. He trips no alarm, and then, to prevent another clever invader from exploiting the same weakness, he repairs the broken lock and seals the portal shut behind him. He improves the ship’s defenses. Ensconced securely inside, he silently sets himself up as the ship’s alternate commander. He enlists the various operating functions of the ship to do his bidding, careful to avoid tripping any alarms. Captain Kirk is still up on the bridge in his swivel chair with the magnificent instrument arrays, unaware that he now has a rival in the depths of his ship. The Enterprise continues to perform as it always has. Meanwhile, the invader begins surreptitiously communicating with his own distant commander, letting him know that he is in position and ready, waiting for instructions.

And now imagine a vast fleet, in which the Enterprise is only one ship among millions, all of them infiltrated in exactly the same way, each ship with its hidden pilot, ever alert to an outside command. In the real world, this infiltrated fleet is called a “botnet,” a network of infected, “robot” computers. The first job of a worm like Conficker is to infect and link together as many computers as possible—the phenomenon witnessed by Porras and other security geeks in their honeypots. Thousands of botnets exist, most of them relatively small—a few thousand or a few tens of thousands of infected computers. More than a billion computers are in use around the world, and by some estimates, a fourth of them have been surreptitiously linked to a botnet. But few botnets approach the size and menace of the one created by Conficker, which has stealthily linked between 6 million and 7 million computers.

Once created, botnets are valuable tools for criminal enterprise. Among other things, they can be used to efficiently distribute malware, to steal private information from otherwise secure Web sites or computers, to assist in fraudulent schemes, or to launch denial-of-service attacks—overwhelming a target computer with a flood of requests for response. The creator of an effective botnet, one with a wide range and the staying power to defeat security measures, can use it himself for one of the above scams, or he can sell or lease it to people who specialize in exploiting botnets. (Botnets can be bought or leased in underground markets online.)

Beyond criminal enterprise, botnets are also potentially dangerous weapons. If the right order were given, and all these computers worked together in one concerted effort, a botnet with that much computing power could crack many codes, break into and plunder just about any protected database in the world, and potentially hobble or even destroy almost any computer network, including those that make up a country’s vital modern infrastructure: systems that control banking, telephones, energy flow, air traffic, health-care information—even the Internet itself.

The key word there is could, because so far Conficker has done none of those things. It has been activated only once, to perform a relatively mundane spamming operation—enough to demonstrate that it is not benign. No one knows who created it. No one yet fully understands how it works. No one knows how to stop it or kill it. And no one even knows for sure why it exists.

If yours is one of the infected machines, you are like Captain Kirk, seemingly in full command of your ship, unaware that you have a hidden rival, or that you are part of this vast robot fleet. The worm inside your machine is not idle. It is stealthily running, issuing small maintenance commands, working to protect itself from being discovered and removed, biding its time, and periodically checking in with its command-and-control center. Conficker has taken over a large part of our digital world, and so far most people haven’t even noticed.

The struggle against this remarkable worm is a sort of chess match unfolding in the esoteric world of computer security. It pits the cleverest attackers in the world, the bad guys, against the cleverest defenders in the world, the good guys (who have been dubbed the “Conficker Cabal”). It has prompted the first truly concerted global effort to kill a computer virus, extraordinary feats of international cooperation, and the deployment of state-of-the-art decryption techniques—moves and countermoves at the highest level of programming. The good guys have gone to unprecedented lengths, and have had successes beyond anything they would have thought possible when they started. But a year and a half into the battle, here’s the bottom line:

The worm is winning.

A Digital Sam Spade

Twenty years ago, computers were bedeviled by hackers. These were savvy outlaws who used their deep knowledge of operating systems to invade, steal, and destroy, or sometimes just to tap into secure facilities and show off their skills. Hackers became heroes to a generation of teenagers, and had all sorts of motives, but their most distinctive trait was a tendency to show off.

Some had truly malicious intent. In his 1989 best seller, The Cuckoo’s Egg, Cliff Stoll told the story of his stubborn, virtually single-handed hunt for an elusive hacker in Germany who was using Stoll’s computer system at the Lawrence Berkeley National Laboratory as a portal to Defense Department computers. For many people, Stoll’s book was the introduction to the netherworld of rarefied gamesmanship that defines computer security. Stoll’s hacker never penetrated the most secret corners of the national-security net, and even relatively serious breaches like the one Stoll described were more nuisance than threat. But the individual hacker working as a spy or vandal has evolved into something more organized and menacing.

Andre’ M. DiMino, a computer sleuth who is part of the Conficker Cabal, is considered one of the world’s foremost authorities on botnets. He stumbled into his avocation on a Monday morning a decade ago, when he discovered that over the weekend, someone had broken into the computer system he was administering for a small company in New Jersey. DiMino has an undergraduate degree in electrical engineering with an emphasis in computer science, but he has mostly taught himself up to his present level of expertise, which is extreme. At 45, he is a slender, affable idealist who keeps a small array of computers in an upstairs bedroom. When I stopped by to talk to him, he baked me pizza. His day job is doing computer forensics for law enforcement in Bergen County, New Jersey, but he has a kind of alter ego as what he calls a “botnet hunter.”

Back when he discovered the weekend break-in, DiMino assumed at first that it was the work of a hacker, a vandal, or possibly a former employee, only to discover, based on an analysis of the IP (Internet Protocol) addresses of the incoming data, that his little computer network had been invaded by someone from Turkey or Ukraine. What would someone halfway around the planet want with the computer system of a small business-management firm in a New Jersey office park? Apparently, judging by what he found, his invader was in the business of selling pirated software, movies, and music. Needing large amounts of digital storage space to hide stolen inventory, the culprit seemed to have conducted an automated search over the Internet, looking worldwide for vulnerable systems with large amounts of unused disc space—DiMino equates it to walking around rattling doorknobs, looking for one door left unlocked. DiMino’s system fit the bill, so the crooks had dumped a huge bloc of data onto his discs. He erased the stash and locked the door that had allowed the pirates in. As far as the company was concerned, that solved the problem. No harm done. No need to call the police or investigate further.

But DiMino was intrigued. He reviewed the server logs for previous weeks and saw that this successful invasion was one of many such efforts. Other attackers had been rattling the doors of his network, looking for vulnerabilities. If there were bad guys actively exploiting other people’s computers all over the world, designing sophisticated programs to exploit weaknesses … how cool was that? And who was trying to stop them?

DiMino set about educating himself on the fine points of this obscure battle of wits. He eventually co-founded the Shadowserver Foundation, a nonprofit partnership of defense-minded geeks at war with malware, effectively transforming himself into a digital Sam Spade—indeed, the graphic atop Shadowserver’s home page features a Dashiell Hammett–style detective emerging from shadow.

Both sides in this cyberwar have become astonishingly sophisticated, operating at the cutting edge of programming theory and cryptography. Both understand the limits of security methodology, the one side working to broaden its reach, the other working to surpass it. Because malware has been automated, the good guys usually can only guess at who they are up against.

Trojans, Viruses, and Worms

Rodney Joffe heads the cabal that has been battling Conficker. He is a burly, garrulous South African–born American who serves as senior vice president and chief technologist for Neustar, a company that provides trunk-line service for competing cell-phone companies around the world. Joffe’s interest in stopping the worm did not stem just from his outrage and sense of justice. His concern for Neustar’s operation is professional, and illustrative.

The company runs a huge local-number-portability database. Almost every phone call in North America, before it’s completed, must ask Neustar where to go. Back in the old days, when the phone company was a monopoly, telecommunications were relatively simple. You could figure out where a phone call was going, right down to the building where the target phone would ring, just by looking at the number. Today we have competing telephone companies, and cell phones, and a person’s telephone number is no longer necessarily tied to a geographic location. In this more complex world, someone needs to keep track of every single phone number, and know where to route calls so they end up in the right place. Neustar performs this service for telephone calls, and is one of many registries that oversee high-level Internet domains. It is, in Joffe’s words, “the map.”

“If I disappear, there’s no map,” he says. “So if you take us down, whole countries can actually disappear from the grid. They’re connected, but no one can find their way there, because the map’s disappeared.”

A botnet like Conficker could theoretically be used to shut down Neustar’s system. So Joffe helped form the Conficker Cabal. He scoffed when he read in late 2009 that the Obama administration’s Department of Homeland Security planned to hire “a thousand” computer-security experts over the next three years. “There aren’t more than a few hundred people in the world who understand this stuff.”

Most of us use the word virus to describe all malware, but in geekspeak, it means something more specific. There are three types of the stuff: Trojans, viruses, and worms. A Trojan is a piece of software that works like a Trojan horse, masquerading as one thing to get inside a computer, and then attacking. A virus attacks the host computer after slipping in through a hole in its operating system. It depends on the computer-operator—you—doing something stupid to activate it, like opening an attachment to an e-mail that appears innocuous, or clicking on an enticing link. A worm works like a virus, exploiting flaws in operating systems, but it doesn’t attack once it breaks in. It generally doesn’t have a malicious payload. Exactly like the most-sophisticated viruses in the biological world, it does not cripple or kill its host. It is primarily designed to spread. The instructions that will put a worm like Conficker to work are not embedded in its code; they will be delivered later, from a remote command center.

In the old days, when your computer got infected, it slowed down because your commands had to compete for processing with viral invaders. You knew something was wrong because the machine took 10 times longer to boot up, or there was a delay between command and response. You began to get annoying pop-ups on your screen directing you to download supposedly remedial software. Programs would freeze. In this sense, the old malware was like the Ebola virus, a very scary strain that messily kills nearly everyone it infects—which is another way of saying that it is grossly ineffective, because it burns out the very host organisms it needs to survive. The miscreants who created computer viruses years ago learned that malware that announces itself in these ways doesn’t last.

So today’s malware produces no pop-ups, no slowdowns. A worm is especially quiet, since all it does, at least initially, is spread. Conficker stealthily sets up shop without making a ripple, and—other than calling home periodically for instructions—just waits. Its regular messages to its command center amount to only a couple hundred bytes of data, which is not enough to even light up the little bulb that flashes when a computer hard drive is at work.

After Phil Porras and others began snaring Conficker in increasing numbers, they began dissecting it. The worm itself was exquisite. It consisted of only a few hundred lines of code, no more than 35 kilobytes—slightly smaller than a 2,000-word document. In comparison, the average home computer today has anywhere from 40 to 200 gigabytes of storage. Unless you were looking for it, unless you knew how to look for it, you would never see it. Conficker drifts in like a mote.

It exploited a specific hole, Port 445, in the Microsoft operating systems, a vulnerability that the manufacturer had tried to repair just weeks earlier. Ports are designated “listening” points in a system, designed to transmit and receive particular kinds of data. There are many of them, more than 65,000, because an operating system consists of layer upon layer of functions. A firewall is a security program that guards these ports, controlling the flow of data in and out. Some ports, like the one that handles e-mail, are heavily trafficked. Most are not; they listen for updates and instructions that deal with a narrow and specific function, usually routine procedures that never rise to the notice of computer-users. Only certain very specific kinds of data can flow through ports, and then only with the appropriate codes. Windows opens Port 445 by default to perform tasks like issuing instructions for print-sharing or file-sharing. Late in the summer of 2008, Microsoft learned that even a system protected by a firewall was vulnerable at Port 445 if print-sharing and file-sharing were enabled (which they were on many computers). In other words, even a well-protected computer had a hole. On October 23, 2008, the company issued a rare “critical security bulletin” (MS08-067) with a patch to repair that hole. A specially crafted “remote procedure call” could allow the port to be used by a remote operator, the security bulletin warned, and “an attacker could exploit this vulnerability without authentication to run arbitrary code.” The patch Microsoft offered theoretically slammed the door on a worm like Conficker almost a month before it appeared.

Theoretically.

In fact, the bulletin itself may have inspired the creation of Conficker. Many, many computer-operators worldwide—you know who you are—fail to diligently heed security updates. And the patches are issued only to computers with validated software installations; millions of computers run on bootlegged operating systems, which have never been validated. Microsoft issues its updates on the second Tuesday of every month. Every geek in the world knows this; it’s called “Patch Tuesday.” The company employs some of the best programmers in the world to stay one step ahead of the bad guys. If everyone applied the new patches promptly, Windows would be nigh impregnable. But because so many people fail to apply the patches promptly, and because so many machines run on illegitimate Windows systems, Patch Tuesday has become part of Microsoft’s problem. The company points out its own vulnerabilities, which is like a general responsible for defending a fort making a public announcement—“The back door to the supply shed in the southeast corner of the garrison has a broken lock; here’s how to fix it.” When there is only one fort, and it is well policed, the lock is fixed and the vulnerability disappears. But when you are defending millions of forts, and a goodly number of the people responsible for their security snooze right through Patch Tuesday, the security bulletin doesn’t just invite attack, it provides a map! Twenty-eight days after the MS08-067 security bulletin appeared, Conficker started worming its way into unpatched computers.

The Cabal’s Sandboxes

Conficker’s rate of replication got everyone’s attention, so a loose-knit gaggle of geeky “good guys,” including Porras, Joffe, and DiMino, began picking the worm apart. The online-security community consists of software manufacturers like Microsoft, companies like Symantec that sell security packages to computer owners, large telecommunication registries like Neustar and VeriSign, nonprofit research centers like SRI International, and botnet hunters like Shadowserver. In addition to maintaining honeypots, these security experts operate “sandboxes”—isolated computers (or, again, virtual computers inside larger ones) where they can place a piece of malware, turn it on, and watch it run. In other words, where they can play with it.

They all started playing with Conficker, comparing notes on what they found, and brainstorming ways to defeat it. That’s when someone dubbed the group the “Conficker Cabal,” and the name stuck, despite discomfort with the darker implications of the word. Here are some of the things the cabal discovered about the worm in those first few weeks:

• It patched the hole it came through at Port 445, making sure it would not have to compete with other worms. This was smart, because surely other hackers had seen security bulletin MS08-067.
•It tried to prevent communication with security providers (many computer-users subscribe to commercial services that regularly update antivirus software).
•When it started, if the IP address of the infected computer was Ukrainian, the worm self-destructed. When in attack mode, searching for other computers to infect, it skipped any with a Ukrainian IP address.
•It disabled the Windows “system restore” points, a useful tool that allows users with little expertise to simply reset an infected machine to a date prior to its infection. (System restore is one of the easiest ways to debug a machine.)

All of these things were clever. They indicated that Conficker’s creator was up on all the latest tricks. But the main feature that intrigued the cabal was the way the worm called home. This is, of course, what worms designed to create botnets do. They settle in and periodically contact a command center to receive instructions. Botnet hunters like DiMino regularly wipe out whole malicious networks by deciphering the domain name of the command center and then getting it blocked. In the old days, this was easier because malware pointed to only a few IP addresses, which could be blocked by hosting providers and Internet service providers. The newer worms like Conficker bumped the game up to a higher level, generating domain names that involve many providers and a wide range of IP addresses, and that security experts can block only by contacting Internet registries—organizations that manage the domain registrations for their realm. But Conficker did not call home to a fixed address.

Shortly after it was discovered, the worm began performing a new operation: generating a list of domain names seemingly at random, 250 a day across five top-level domains (top-level domains are defined by the final letters in a Web address, such as .com or .edu or .uk). The worm would then go down the list until it hit upon the one connected to its remote controller’s server. All Conficker’s controller had to do was register one of the addresses, which can be done for a fee of about $10, and await the worm’s regular calls. If he wished, he could issue instructions. It was as if the boss of a crime family told his henchmen to check in daily by turning to the bottom of a certain page in each day’s Racing Form, where there would be a list of potential numbers. They would then call each number until the boss picked up. So it was not apparent from day to day where the worm would call home.

With the Racing Form trick, if you were a cop and were tipped off where to look, you might arrange with the paper’s publisher to see the page before it was printed, and thus be one step ahead of the henchmen and their boss. To defeat Conficker, the geeks would have to figure out in advance what the numbers (or, in this case, domain names) would be, and then hustle to either buy up or contact every one, block it, or cajole whoever owned it to cooperate before the worm “made the call.”

Michael Ligh, a young Brooklyn researcher employed by the computer-security company iDefense, is one of several people who went to work unraveling Conficker’s methods. Ligh and others had seen algorithms for random-domain-name generation before, and most were keyed to the infected computer’s clock. If new places to call home must be generated every day, or every few hours, then the worm needs to know when to perform the procedure. So the malware simply checks the time on its host computer. This provided the good guys with a tool to defeat it. They turned the clock forward on their sandbox computer, forcing their captured strain of the worm to spit out all the domain names it would generate for as long into the future as they cared to look. It was like stealing the teacher’s edition of a classroom textbook, the one with all the answers to the quizzes and tests printed in the back. Once you knew all the places the malware would be calling, you could cordon off those sites in advance, effectively stranding the worm.

Conficker had an answer for that. Instead of using the infected computer’s clock, the worm set its schedule by the time on popular corporate home pages, like Yahoo, Google, or Microsoft’s own msn.com.

That was interesting,” Ligh said. “There was no way we could turn the clock forward on Google’s home page.”

So there was no easy way to predict the list of domain names in advance. But there was a way. The first step was to set up a proxy server to, in effect, intercept the time update from the big corporate Web site before it got back to the worm, alter the information, and then send it on. You could then tell the worm it was a date sometime in the future, and the worm would spit out the domain names for that date. This was a tedious way to proceed, since you could generate only one set of new domain names at a time. So Ligh and other researchers reverse-engineered the worm’s algorithm, extracted the time-update function, and wedded it to a piece of code they could control. They instructed their copy to generate the future lists in advance. They could then buy up or block all the sites, and direct all the worm’s communications into a “sinkhole,” a dead-end location where calls go unanswered. Conficker’s creators had deliberately made the task so onerous and expensive that no one would go to the trouble of blocking all possible command centers.

Or so they thought. The cabal, through a determined and unprecedented effort, did manage to cordon off the worm. By the end of 2008, Conficker had infected an estimated 1.5 million machines worldwide, but it was on its way to full containment. In the great chess match, the good guys had called “Check!”

Then the worm turned.

MD-6

On December 29, 2008, a new version of Conficker showed up, and if the geeks had been intrigued with the original version, they now experienced something more akin to respect … mingled with fear.

One of the early theories about the worm was that it had slipped out of a computer-science lab, the product of some fooling-around by a sophisticated graduate student or group of students. They had loosed it on the world inadvertently, or maybe on purpose as a prank or experiment without realizing how effective it would be. This hypothesis appealed to optimists.

The new version of the worm, Conficker B, exploded the benevolent-accident theory. It was clear that the worm’s creator had been watching every move the good guys made, and was adjusting accordingly. He didn’t care that the good guys could predict its upcoming lists of domain names. He just rejiggered the worm to spread the new lists out over eight top-level domains instead of five, making the job of blocking them far more difficult. The worm had no trouble contacting all of these locations. If it received no command from one, it simply tried the next one on its list. Conficker B could go on like this for months, even years. It had to find its controller only once to receive instructions.

“That’s a high number,” Rodney Joffe, of Neustar, told me. “The cops will get sick and tired of knocking on 250 doors a day and finding there’s no one there. And if I’m the chief bad guy, all I have to do is be behind one of those doors on one of those days.”

There were other improvements to Conficker. Among them: besides shutting down whatever security system was installed on the computer it invaded, and preventing it from communicating with computer-security Web sites, it stopped the computer from connecting with Microsoft to perform Windows updates. So even though Microsoft was providing patches, the infected machines could not get to them. In addition, it modified the computer’s bandwidth settings to increase speed and propagate itself faster; and it began to spread itself in different ways, including via USB drives. This last innovation meant that even “closed” computer networks, those with no connection to the Internet, were vulnerable, since users who cannot readily transmit files from point to point via the Web often store and transport them on small USB drives. If one of those USB drives, or a CD, was plugged into an infected computer, it could deliver the worm to an entire closed network.

All of this was impressive—but something else stopped researchers cold. Analysts with Conficker B isolated in their sandboxes could watch it regularly call home and receive a return message. The exchange was in code, and not just any code.

Breaking codes used to be the province of clever puzzle masters, who during World War II devised encryption and code-breaking methods so difficult that operators needed machines to do the work. Computers today can perform so many calculations so fast that, theoretically at least, no cipher is too difficult to crack. One simply applies what computer scientists call “brute force”: trying every possible combination systematically until the secret is revealed. The game is to make a cipher so difficult that the amount of computing power needed to break it renders the effort pointless—the “thief” would have to spend more to obtain the prize than the prize is worth. In his 1999 history of code-making and -breaking, The Code Book, Simon Singh wrote: “It is now routine to encrypt a message [so securely] that all the computers on the planet would need longer than the age of the universe to break the cipher.”

The basis for the highest-level modern ciphers is a public-key encryption method invented in 1977 by three researchers at MIT: Ron Rivest (the primary author), Adi Shamir, and Leonard Adleman. In the more than 30 years since it was devised, the method has been improved several times. The National Institute of Standards and Technology sets the Federal Information Processing Standard, which defines the cryptography algorithms that government agencies must use to protect communications. Because it is the most sophisticated oversight effort of its kind, the standard is determined by an international competition among the world’s top cryptologists, with the winning entry becoming by default the worldwide standard. The current highest-level standard is labeled SHA-2 (Secure Hash Algorithm–2). Both this and the first SHA standard are versions of Rivest’s method. The international competition to upgrade SHA-2 has been under way for several years and is tentatively scheduled to conclude in 2013, at which point the new standard will become SHA-3.

Rivest’s proposal for the new standard, MD-6 (Message Digest–6), was submitted in the fall of 2008, about a month before Conficker first appeared, and began undergoing rigorous peer review—the very small community of high-level cryptographers worldwide began testing it for flaws.

Needless to say, this is a very arcane game. The entries are comprehensible to very few people. According to Rodney Joffe, “Unless you’re a subject-matter expert actively involved in crypto-algorithms, you didn’t even know that MD-6 existed. It wasn’t like it was put in The New York Times.”

So when the new version of Conficker appeared, and its new method of encrypting its communication employed MD-6, Rivest’s proposal for SHA-3, the cabal’s collective mind was blown.

“It was clear that these guys were not your average high-school kids or hackers or predominantly lazy,” Joffe told me. “They were making use of some very, very sophisticated techniques.

“Not only are we not dealing with amateurs, we are possibly dealing with people who are superior to all of our skills in crypto,” he said. “If there’s a surgeon out there who’s the world’s foremost expert on treating retinitis pigmentosa, he doesn’t do bunions. The guy who is the world expert on bunions—and, let’s say, bunions on the third digit of Anglo-American males between the ages of 35 and 40, that are different than anything else—he doesn’t do surgery for retinitis pigmentosa. The knowledge it took to employ Rivest’s proposal for SHA-3 demonstrated a similarly high level of specialization. We found an equivalent of three or four of those in the code—different parts of it.

“Take Windows,” he explained. “The understanding of Windows’ operating system, and how it worked in the kernel, needed that kind of a domain expert, and they had that kind of ability there. And we realized as a community that we were not dealing with something normal. We’re dealing with one of two things: either we’re dealing with incredibly sophisticated cyber criminals, or we’re dealing with a group that was funded by a nation-state. Because this wasn’t the kind of team that you could just assemble by getting your five buddies who play Xbox 360 and saying, ‘Let’s all work together and see what we can do.’”

The plot thickened—it turned out that Rivest’s proposal, MD-6, had a flaw. Cryptologists in the competition had duly gone to work trying to crack the code, and one had succeeded. In early 2009, Rivest quietly withdrew his proposal, corrected it, and resubmitted it. This gave the cabal an opening. If the original Rivest proposal was flawed, then so was the encryption method for Conficker B. If they were able to eavesdrop on communications between Conficker and its mysterious controller, they might be able to figure out who he was, or who they were. How likely was it that the creator of Conficker would know about the flaw discovered in MD-6?

Once again, the good guys had the bad guys in check.

About six weeks later, another new version of the worm appeared.

It employed Rivest’s revised MD-6 proposal.

Game on.

“Our Finest Hour”

By early 2009, Conficker B had infected millions of machines. It had invaded the United Kingdom’s Defense Ministry. As CBS prepared a 60 Minutes segment on the worm, its computers were struck. In both instances, security experts scrambled to uproot the invader, badly disrupting normal functioning of the system. Conficker now had the world’s attention. In February 2009, the cabal became more formal. Headed initially by a Microsoft program manager, and eventually by Joffe, it became the Conficker Working Group. Microsoft offered a $250,000 bounty for the arrest and conviction of the worm’s creators.

The newly named team went to work trying to corral Conficker B. Getting rid of it was out of the question. Even though they could scrub it from an infected computer, there was no way they could scrub it from all infected computers. The millions of machines in the botnet were spread all over the world, and most users of infected ones didn’t even know it. It was theoretically feasible to unleash a counter-worm, something to surreptitiously enter computers and take out Conficker, but in free countries, privacy laws frown on invading people’s home computers. Even if all the governments got together to allow a massive attack on Conficker—an unlikely event—the new version of the worm had new ways of evading the threat.

Conficker C appeared in March 2009, and in addition to being impressed by its very snazzy crypto, the Conficker Working Group noticed that the new worm’s code threatened to up the number of domain names generated every day to 50,000. The new version would begin generating that many domain names daily on April 1. At the same time, all computers infected with the old variants of Conficker that could be reached would be updated with this new strain. The move suggested that the bad guys behind Conficker understood not just cryptology, but also the mostly volunteer nature of the cabal.

“You know you’re dealing with someone who not only knows how botnets work, but who understands how the security community works,” Andre’ DiMino told me. “This is not just a bunch of organized criminals that, say, commission someone to write a botnet for them. They know the challenges that the security community faces internally, politically, and economically, and are exploiting them as well.”

The bad guys knew, for instance, that preregistering even 250 domain names a day at $10 a pop was doable for the good guys. As long as the number remained relatively small, the cabal could stay ahead of them. But how could the good guys cope with a daily flood of 50,000? It would require an unprecedented degree of cooperation among competing security firms, software manufacturers, nonprofit organizations like Shadowserver, academics, and law enforcement.

“You can’t just register all 50,000—you’ve got to go one by one and make sure the domain name doesn’t already exist,” Joffe says. “And if it exists, you’ve got to make sure that it belongs to a good guy, not a bad guy. You’ve got to make a damn phone call for any of the new ones, and have to send someone out there to do it—and these are spread all over the world, including some very remote places, Third World countries. Now the bar had been raised to a level that was almost insurmountable.”

The worm was already running rings around the good guys, and then, just for good measure, it planted a pie in their faces on, of all days, April 1. By playing with the new variant in their sandboxes, the cabal knew that the enhanced domain-name-generating algorithm would click in on that day. If the update succeeded, it would be a game-changer. It was the most dramatic moment since Conficker had surfaced the previous November. Apparently, at long last, this extraordinary tool was going to be put to use. But for what? The potential was scary. Few people outside the upper echelon of computer security even understood what Conficker was, much less what was at stake on April 1, but word of a vague impending digital doomsday spread. The popular press got hold of it. There were headlines and the usual spate of ill-informed reports on cable TV and the Internet. When the day arrived, those who had been warning about the dangers of this new worm were sure to see their fears vindicated.

The cabal mounted a heroic effort to shut down the worm’s potential command centers in advance of the update, coordinating directly with the Internet Corporation for Assigned Names and Numbers, the organization that supervises registries worldwide. “It was our finest hour,” Joffe says.

“I don’t think that the bad guys could have expected the research community to come together as it did, because it was pretty unprecedented,” Ramses Martinez, director of information security for VeriSign, told me. “That was a new thing that happened. I mean, if you would have told me everybody’s going to come together—by everybody, I mean all these guys in this computer-security world that know each other—and they’re going to do this thing, I would have said, ‘You’re crazy.’ I don’t think the bad guys could have expected that.”

Much of the computer world was watching, in considerable suspense, to see what would happen on April 1. It was like the moment in a movie when the bad guy at last has cornered the hero. He pulls out an enormous gun and aims it at the hero’s head, pulls the trigger … and out pops a little flag with the word BANG!

Conficker found one or two domain names that Joffe’s group had missed, which was all it needed. The cabal’s efforts had succeeded in vastly reducing the number of machines that got the update, but the ones that did went to work distributing a very conventional, well-known malware called Waledac, which sends out e-mail spam selling a fake anti-spyware program. The worm was used to distribute Waledac for two weeks, and then stopped.

But something much more important had happened. The updated worm didn’t just up the ante by generating 50,000 domain names daily; it effectively moved the game out of the cabal’s reach.

“April 1 came and went, and in the middle of that night the systems switched over to the new algorithm,” Conficker C, Joffe told me. “That’s all that was supposed to happen, and it happened. But the Internet didn’t get infected; it was just an algorithm change in the software. So of course the press said, ‘Conficker is a bust.’”

Public concern over the worm fizzled, just as the problem grew worse: the new version of Conficker introduced peer-to-peer communications, which was disheartening to the good guys, to say the least. Peer-to-peer operations meant the worm no longer had to sneak in through Windows Port 445 or a USB drive; an infected computer spread the worm directly to every machine it interacted with. It also meant that Conficker no longer needed to call out to a command center for instructions; they could be distributed directly, computer to computer. And since the worm no longer needed to call home, there was no longer any way to tell how many computers were infected.

In the great chess match, the worm had just pronounced “Checkmate.”

Watching and Waiting

As of this writing, 17 months after it appeared and about a year after the April 1 update, Conficker has created a stable botnet. It consists of anywhere from hundreds of thousands of computers to 12 million. No one knows for sure anymore, because with peer-to-peer communications, the worm no longer needs to check in with an outside command center, which is how the good guys kept count. Joffe estimates that with the four distinct strains (yet another one appeared on April 8, 2009), 6.5 million computers are probably infected.

The investigators see no immediate chance or even any effective way to kill it.

“There are a bunch of infected machines that are out there, and they can be taken over, given the right circumstances, by the bad guys,” VeriSign’s Martinez says. “Will they do that? I don’t know. So it’s a potential threat. It’s something that’s out there, sitting there, and it needs to be addressed, but I don’t think, honestly, that we know how. How do we address this? If it was sitting in the U.S., it would be a fairly easy thing to do. The fact is that it’s spread out all around the world.”

Ever since the paltry Waledac scam, the worm has been biding its time.

“They are watching us watch them,” says Andre’ DiMino, the botnet hunter. “I think it’s really either that or somebody let this thing get bigger, and it’s advanced bigger and further than they ever dreamed possible. A lot of people think that. But in looking at the sophistication of this thing and looking at the evolution of this thing, I think they knew exactly what they were doing. I think they were trying something, and I think that they’re too smart to do what everybody figured they were going to do. You have to remember, the world was watching this thing and waiting for the world to end from Conficker on April 1, 2009. The last thing you’d want to do if you’re the bad guy is make something happen on April 1. You’re never going to do that, because everybody’s watching it. You’re going to do something when you’re least suspected. So these guys are sophisticated. They have good code. And just even seeing the evolution from Conficker A to B to C, where there’s the peer-to-peer component, which … strikes fear into the heart of botnet hunters because it’s just so damn difficult to track—these guys know exactly what they’re doing.”

So who are they?

One of the things Martinez’s team does, patrolling the perimeter at VeriSign looking for threats, is dip into the obscure digital forums where cyber criminals converse. Those who are engaged in writing sophisticated malware boast and threaten and compare notes. The good guys venture in to collect intelligence, or just out of curiosity, or for fun. They sometimes pretend to be malware creators themselves, sometimes not. Sometimes they engage in a little cyber trash talk.

“In the past you were just sort of making sure they didn’t steal your proprietary information,” Martinez says. “Now we go in to engage them. You talk to them and you exchange information. You have a guy in Russia selling malware, working with a guy in Mexico doing phishing attacks, who’s talking to a kid in Brazil, who’s doing credit-card fraud, and they’re introducing each other to some guy in China doing something else.”

Martinez said he recently eavesdropped on a dialogue between a security researcher and a man he suspects was at least partly responsible for Conficker. He wouldn’t say how he drew that connection, only that he had good reasons for believing it to be true. The suspect in the conversation was eastern European. The standard image of a malware creator is the Hollywood one: a brilliant 20-something with long hair and a bad attitude, in need of a bath. This is not how Martinez sees his nemesis—or nemeses.

“I see him, or them, as a really well-educated, smart businessman,” he said. “He may be 50 years old. These guys are not chumps. They’re not just out to make a buck.”

The eastern European, backpedaling from further dialogue with the security geek, wrote, “You’re the good guys; we’re the bad guys. Bacillus can’t live with antibodies.”

“Now, I didn’t grow up in a bad neighborhood or anything,” said Martinez, “but the few thugs that I saw would never use a word like bacillus or make an analogy like that.”

One of the early clues in the hunt was the peculiarity in the Conficker code that made computers with active Ukrainian keyboards immune. Much of the world’s aggressive malware comes from eastern Europe, where there are high levels of education and technical expertise, and also thriving organized criminal gangs. Martinez believes Conficker was written by a group of highly skilled programmers. Like Joffe, he sees it as a group of creators, because designing the worm required expertise in so many different disciplines. He suspects that these skilled programmers and technicians either were hired by a criminal gang, or created the worm as their own illicit business venture. If that’s true, then the Waledac maneuver was like flexing Conficker’s pinkie—just a demonstration, a way of showing that despite the best and most concerted effort of the world’s computer-security establishment, the worm was fully operational and under their control.

Will they be caught?

“I have no idea,” Martinez says. “I would say probably not. I’ll be shocked if they’re ever arrested. And arrest them for what? Is breaking into people’s computers even illegal where they’re from? Because in a lot of countries, it isn’t. As a matter of fact, in some countries, unless you’re touching a computer in their jurisdiction, their country, that’s not illegal. So who’s going to arrest them, even if we know who they are?”

Ridding computers of the worm poses another kind of overwhelming problem.

“There are controls, or checks and balances, in place to limit what police can do, because we have civil liberties to protect,” he says. “If you do away with these checks and balances, where the government can come in and reimage your computer overnight, now you’re infringing on people’s civil liberties. So, I mean, we can talk about this all day, but I’ll tell you, it’s going to be a long time, in my opinion, before we really see the government being able to effectively deal with cyber crime, because I think we’re still learning as a culture, as a nation, and as a world how to deal with this stuff. It’s too new.”

Imagining Conficker’s creators as a skilled group of illicit cyber entrepreneurs remains the prevailing theory. Some of the good guys feel that the worm will never be used again. They argue that it has become too notorious, too visible, to be useful. Its creators have learned how to whip computer-security systems worldwide, and will now use that knowledge to craft an even stealthier worm, and perhaps sell it to the highest bidder. Few believe Conficker itself is the work of any one nation, because other than the initial quirk of the Ukrainian-keyboard exemption, it spreads indiscriminately. China is the nation most often suspected in cyber attacks, but there may be more Conficker-infected computers in China than anywhere else. Besides, a nation seeking to create a botnet weapon is unlikely to create one as brazen as Conficker, which from the start has exhibited a thumb-in-your-eye, catch-me-if-you-can personality. It is hard to imagine Conficker’s creators not enjoying the high level of cyber gamesmanship. The good guys certainly have.

“It’s cops and robbers, so to speak, and that was a really interesting aspect of the work for me,” says Martinez. “It’s guys trying to outwit each other and exploit vulnerabilities in this vast network. “

In chess, when your opponent checkmates you, you have no recourse. You concede and shake the victor’s hand. In the real-world chess match over Conficker, the good guys have another recourse. They can, in effect, upend the board and go after the bad guys physically. Which is where things stand. The hunt for the mastermind (or masterminds) behind the worm is ongoing.

“It’s an active investigation,” Joffe says. “That’s all I can say. Law enforcement is fully engaged. We have some leads. This story is not over.”

This article available online at: http://www.theatlantic.com/magazine/archive/2010/06/the-enemy-within/8098/

| Trackback | # 
 Sunday, May 02, 2010
Sunday, May 02, 2010 8:38:26 PM UTC ( Apple | EN | markets | multimedia | tech )

The stats seem to support Steve Jobs' contention that Adobe's video format is fading fast

In the Thoughts on Flash essay that Steve Jobs posted last week, Apple's CEO took on Adobe's oft-repeated contention that Apple's (AAPL) mobile products — the iPhone, iPad and iPod touch — don't offer access to the "full Web" because they don't support Adobe's Flash format. 75% of the video on the Web, Adobe's supporters point out, is encoded in Flash.

"What they don't say," Jobs wrote, "is that almost all this video is also available in a more modern format, H.264" — which iPads and iPhones do support.

"Almost all" may be an exaggeration, but the chart above, posted Saturday by TechCrunch's Erick Schonfeld, suggests that the trends are headed Apple's way.


Source: Encoding.com via TechCrunch

The chart was produced by Encoding.com, which does on-demand Web video encoding for a variety of clients, from MySpace to MTV Network. It encoded some 5 million videos last year, so it has a pretty good handle on which formats are up and which are down. Schonfeld explains:

As the chart shows, in the past four quarters, the H.264 format went from 31 percent of all videos to 66 percent, and is now the largest format by far. Meanwhile, Flash is represented by Flash VP6 and FLV, which combined represent only 26 percent of all videos. That is down from a combined total of 69 percent four quarters ago. So the native Flash codecs and H.264 have completely flipped in terms of market share (Flash also supports H.264, however, but you don’t need a Flash player to watch H.264 videos).

Once again, Apple may be skating not to where the puck is, but where it's going to be.

See also:

[via tech.fortune.cnn.com]
| Trackback | # 
 Wednesday, April 28, 2010
Wednesday, April 28, 2010 6:27:04 AM UTC ( EN | microsoft | tech )

Now that Microsoft has announced the availability of the public beta of Windows Home Server Codename Vail, I wanted to share an overview to benefit both those of you that will be installing the Beta as well as those that don’t plan to install the Beta but are curious about what Vail delivers.

Remember that this is a beta product with no announced final release date, so what we are seeing today may not be what the final product looks like. Also remember that if you choose to run the Vail beta, you should only do so on a test system and definitely do not store your production data on it.

Initial Thoughts
At first glance, Vail has a very similar feature set to Windows Home Server v1. The Home Server will back up your client PCs, you can easily add and remove hard drives to expand your storage, you can remotely access your files and computers from outside the home, and you can install Add-Ins to increase the functionality of your Home Server. While the basic features look and even feel similar to it’s predecessor, Vail has been polished, refined and improved in many ways, and delivers a few key new features that should provide a better experience for Windows Home Server users.

If you like the way Windows Home Server currently functions, I think you’ll be mostly pleased with the changes in Vail. However if you were hoping to see significant new features such as Media Center integration or the ability for Windows Home Server to be the only box that is always running on your home network, you’ll likely be disappointed. There are also a few key changes to Windows Home Server Vail that I think may be show-stopping issues for some of you. Please read on for all the details.

As a further reminder that this is a Beta release, Microsoft has an extensive list of Known Issues that I recommend you review before installing Vail.

Supported Client Operating Systems

The following home computer operating systems are supported by Windows Home Server Vail.

The Windows 7 Operating System

  • Windows 7 Home Basic (x86 and x64)
  • Windows 7 Home Premium (x86 and x64)
  • Windows 7 Professional (x86 and x64)
  • Windows 7 Ultimate (x86 and x64)
  • Windows 7 Enterprise (x86 and x64)
  • Windows 7 Starter (x86)

The Windows Vista Operating System

  • Windows Vista Home Basic with Service Pack 2 (SP2) (x86 and x64)
  • Windows Vista Home Premium with SP2 (x86 and x64)
  • Windows Vista Business with SP2 (x86 and x64)
  • Windows Vista Ultimate with SP2 (x86 and x64)
  • Windows Vista Enterprise with SP2 (x86 and x64)
  • Windows Vista Starter with SP2 (x86)

The Windows XP Operating System

  • Windows XP Home with Service Pack 3 (SP3)
  • Windows XP Professional with SP3
  • Windows XP Media Center Edition 2005 with SP3

New and Improved Features
There are number of new and improved features in Windows Home Server Vail that I believe will make a large number of you happy. Here’s a summary of some of these changes, I talk about some of them more later in the article, you can read more in the Getting Started guide, and of course explore Vail after you’ve installed it.

First, the client PC backup feature has been made more robust and so we should see less errors and erratic failures that we are used to in Windows Home Server v1. They have also added a computer backup archive feature, so that you can save off the backup of a PC that you wish to retire and not have it count as one of the 10 connected PCs. Vail also borrows a cue from the popularity of my BDBB Add-In and has a “Backup the Backups” feature, just like you can back up the shared folders. This is a welcome change, but means I’ll have to find a new Add-In to work on for Vail. :)

The shared folder backups can now be scheduled, and also include the ability to back up and restore the entire Vail operating system, which was one of the most requested features.

Drive Extender has been extensively worked on and claims to have increased robustness and control. One of the issues we saw with v1 was that failed or failing hard drives could cause significant issues with Windows Home Server, often leaving the user with no idea of how to repair their server. Here are the listed changes from the Getting Started guide, I believe they are important enough to call out specifically here.

  • Allows you to remove the system drive from the storage pool to help increase the speed of the OS
  • Automatically detects and corrects many silent hard drive data errors
  • Allows you to remove a drive without server down time
  • Offers improved drive health monitoring and alerting
  • Makes data for duplicated folders available when a drive is missing without requiring you to remove the missing drive first
  • Supports 60GB hard drives or larger, and up to 10 drives can be a part of the server storage pool

I imagine that last bullet point has several of you with your jaws hanging open. This is the first I’ve heard of a 10 drive limit in Vail, and if it is true I believe this is a bad idea and will be feeding that back to Microsoft.

One other concern point I have is that while drives can be viewed and added to other Vail servers, due to the technical changes in Drive Extender there is currently no way to access your data on your server hard drives should you need to. The drives are no longer formatted with NTFS and so your data is “hidden” behind the abstraction of Drive Extender. I’m hopeful that Microsoft will be able to create a utility or driver that provides access to your files for when you need access without building a new server.

Another positive Drive Extender feature is that Previous Versions can be enabled in Vail, which is a nice improvement over v1. This allows you to keep historical versions of changed files on the server, in case of accidental or unintended changes. You will need to manually turn this feature on to use it, however, as it is disabled out of the box.

Finally, DLNA Streaming and “PlayTo” are now supported by Windows Home Server Vail which delivers an improved media streaming experience to the Xbox 360 and other media streaming devices in the home. Vail also provides HomeGroup support which is included in Windows 7 and simplifies the process of sharing files and printers on a home network.

Now we’ll take a look at what the new user interface looks like, and examine the Remote Access and streaming features of Windows Home Server Vail.

Client Installation and Setup
We have full guides on how to either manually or automatically install Vail onto your MediaSmart Server as well as your own server so be sure to check those articles to see what the installation process looks like.

After the installation completes you are ready to join your client PCs to your Vail server. This process is now completely web based instead of requiring a Client Install CD, which means you perform the installation and configuration simply by pointing your browser to http://servername/connect. This will download a small file to run on your computer that joins your PC with your Vail server.

In my case, I still had the Connector software from my Windows Home Server v1 installed on my client PC, which Vail detected and required me to uninstall. After uninstalling v1 I restarted the client install and proceeded through the steps.

Having the ability the add a description for your PC is a nice touch for identifying each PC that you join with your Home Server. As you can see I’ve stressed the importance of this particular PC. :)

The rest of the installation should be familiar to current Windows Home Server users. You can choose to wake the computer for backups, participate in the Microsoft feedback program, and then the actual join with the Home Server occurs.

At the end you are left with three shortcuts on your desktop and a system tray application giving you access to the Launchpad, Dashboard, and server notifications.

Client Launchpad
In addition to the system tray icon and Shared Folders desktop shortcut that was included in v1, Vail now includes a client Launchpad application. The Launchpad gives you access to the Home Server features running on the client PC, such as the ability to see Recent Backup status, Backup Now, and the Server Health Notifications. An interesting new item is the “Remote Access” item that launches a browser to your servers Remote Access URL, and will be handy running on your laptop when away from home.

Add-In developers are also able to add their own items to the Launchpad to extend the functionality of Windows Home Server.

Server Dashboard
The Server Console has been renamed in Vail to the Server Dashboard but should be familiar in layout to users of Windows Home Server v1. The Home tab has basic instructional information.

The Users tab allows you to add, edit, and view the users configured with your Vail server. The Add User feature allows for a little more fine-grained control of user permissions.

The Computers and Backup tab gives you access to the joined client PCs as well as the exciting new Server Backup features that allow you to backup up the Operating System of the server to protect against system drive failure, schedule automated server backups, and even backup the Client PC Backups (I guess they took a hint from the popularity of my WHS BDBB Add-In :) ). In the below screenshots I’ve attached a 1.5TB USB drive and designated it as a Server Backup drive, and am now configuring the server to back itself up.

The Storage tab allows you to add and remove drives as either Storage or Backup, as well as configure the shared folders. One noteworthy item is that the individual Users shares are no longer created by default. If these were valuable to you then you’ll have to manually create them yourself. In the first two shots you can see that Duplication is unavailable because I only have a single drive in the server.

A nice feature is the ability to name or add a label to your drive when you install it. You’ll likely want to use a more descriptive name than I did.

Another nice feature is that Vail now automatically enables duplication on your shared folders after additional drives are added.

The Add-Ins tab will give you access to any installed Add-Ins. We’ll see how long it takes for the community add-ins to begin showing up.

The Settings tab is simplified and my understanding is that Add-In developers will no longer be able to add their own settings tab. One area I’d like to see improved is the configuration for Media Streaming. Currently in Vail, streaming provides access to all media types in each share. This means that my music album art appears in the Photos stream, which is incredibly annoying. I mention this more in the Remote Access section later.

The Remote Access configuration has been improved so that you can choose to manually configure your Remote Access. This is useful if your router doesn’t support UPnP, or if you prefer to manually forward ports. You can also add your own custom images and links to the Remote Access pages.

Finally, the Alerts tab allows you to view the health status of your home server.

Remote Access Features
The Remote Access features have been significantly updated in Vail, and Microsoft has now built-in many of the features that differentiated the HP MediaSmart Server from other Home Server offerings. Your Media is now completely accessible from anywhere on the internet, thanks to the new Remote Media Streaming features.

The initial login is familiar with Windows Home Server v1, and provides access to the Server Console as well as Remote Desktop sessions to any PC that supports RDP and has it enabled. Unfortunately the ActiveX control that provides RDP access was out of date and required me to download a new version (and then reboot my PC) before I could utilize this feature. There is also access to upload and download files from the shared folders.

The music streaming is one of my favorite features, as I like to listen to music on my headphones while at work. The interface is very attractive, and usable even with relatively large libraries. I have over 7,000 tracks in more than 500 albums, and the browser was able to load the album art fairly quickly. Music streams started within a couple of seconds and there is little to no delay between track changes.

The user interface is very similar to the Windows 7 Media Center experience, with scrolling album covers in the background.

The Music Streaming experience is more attractive than the current offering from HP, however the “beta” state of Vail has shown itself and I am experiencing issues with playback where tracks randomly stop playing and skip to the next. I’ve not yet determined if specific files cause this or if it is a more common issue.

Video streaming is also included and features on-the-fly transcoding of files on the server. This means that when you start to stream a video over the web interface, your server will automatically convert it to a resolution and format that streams well. This does require some decent horsepower from your server’s CPU so if you plan on using this feature you may want to take that into consideration when deciding what hardware to use.

Streaming videos from my home has never been very important to me, I just don’t seem to have the interest or need to watch the videos stored on my home server while away from home. I did perform some testing, and unfortunately this feature also has some issues. My Recorded TV shows wouldn’t play (apparently unsupported file formats but they appear in the Remote Media display) and more importantly my home video 720p AVCHD files in MP4 container from my digital video camera wouldn’t play their normal widescreen aspect ratio and are instead squished which ruins the experience of watching the video. Interestingly enough the thumbnail image that is generated shows the correct widescreen aspect ratio. I also found that my test .mts files, which are another common digital video camera format, weren’t able to be played by the streamer even though the Getting Started guide claims to support them. The mkv files that are so popular for storing ripped movies are also not supported. Of course WMV files all worked great, including a sample 1080p version of Terminator 2 that have for testing.

In all cases the playback began quickly and the transcoding seems to work well. I did experience many lockups of Internet Explorer during my testing, while Chrome and Firefox seemed more robust.

One of the biggest frustrations for me is that all my media is mixed up (combined) when displayed by the Vail media streamer, meaning that my Album Art from my Music share is showing up in the Pictures stream. I find this to be quite annoying and it makes the Photo streaming feature pretty much useless. I’ll be advocating very strongly for more configuration options for media management in the shipping version of Vail.

The photo slideshow feature is pretty much what you’d expect and worked fine in my light testing. I’m not sure how useful this will be given that a Remote Access user account is required to access the photos.

Summary
There is a lot of excitement about what Windows Home Server Vail will deliver as a second generation operating system. Even though Windows Home Server v1 had it’s warts and issues, it is a popular product that serves us very well at protecting our data and making it accessible wherever we are. Vail improves on these features in many ways, however I have some significant concerns that I’m hoping our feedback as beta testers will convince Microsoft to make some changes.

Here is what I want to see changed in Vail as it exists today:

  • Don’t restrict us to 10 hard drives. There’s no good reason to do this, especially on a “Premium” labeled SKU and when v1 supported 32 drives.
  • Make Vail storage disks readable on non-Vail computers, just like they are in v1. This has been a much needed feature in the current version, people’s systems do fail and they need to feel confident that their data is safe
  • Make the Media Streaming more configurable, I really hate having my album art mixed in with my photos.
  • Keep improving the Remote Streaming experience. It’s fairly buggy right now, and I’d like to see improved media support for Recorded TV and other video containers such as the extremely popular MKV. There is also the need for real widescreen aspect ratio support as currently that doesn’t seem to work well for many files.

Finally, be sure to submit bugs on Connect, and make sure Microsoft hears what you think of Vail and how it is working for you. Post in the comments or the forums to share what you think about the new and changed features in Vail, as well as your experience when you run the Beta.

[via www.mediasmartserver.net]

| Trackback | # 
 Monday, April 26, 2010
Monday, April 26, 2010 1:38:51 AM UTC ( Apple | EN | mobile )

The saga of Adobe and Apple or, more precisely, Flash app development for the iPhone, is drawing to its inevitable conclusion.

It all started with Apple’s change to its iPhone Developer Program License Agreement – the notorious article 3.3.1 – which banned the use of the Flash-to-iPhone converter. In the simplest of terms, the article makes it meaningless for developers to create Flash apps that target the iPhone because Apple can ban them at any time.

Now Mike Chambers, the principal product manager for developer relations for the Flash platform at Adobe, has put a full stop to the story from Adobe’s side. In a lengthy blog post, he calls for developers of Flash apps for smartphones to focus on Android and stop developing apps for the iPhone. He also announces Adobe’s intention to stop working on the Flash-to-iPhone converter.

“We will still be shipping the ability to target the iPhone and iPad in Flash CS5. However, we are not currently planning any additional investments in that feature,” Mike says. In the post, he also criticizes Apple’s treatment of developers. “If you want to develop for the iPhone you have to be prepared for Apple to reject or restrict your development at anytime, and for seemingly any reason,” he says.

So, that’s it for Flash apps on the iPhone. Apple may have won this round, but the wall around its garden just got a little bit taller.

[via mashable.com]

| Trackback | # 
Monday, April 26, 2010 1:35:25 AM UTC ( DE | EN | internet | security | social )

A hacker named Kirllos has a rare deal for anyone who wants to spam, steal or scam on Facebook: an unprecedented number of user accounts offered at rock-bottom prices.

Researchers at VeriSign's iDefense group recently spotted Kirllos selling Facebook user names and passwords in an underground hacker forum, but what really caught their attention was the volume of credentials he had for sale: 1.5 million accounts.

IDefense doesn't know if Kirllos' accounts are legitimate, and Facebook didn't respond to messages Thursday seeking comment. If they are legitimate, he has the account information of about one in every 300 Facebook users. His asking price varies from US$25 to $45 per 1,000 accounts, depending on the number of contacts each user has.

To date, Kirllos seems to have sold close to 700,000 accounts, according to VeriSign Director of Cyber Intelligence Rick Howard.

Hackers have been selling stolen social-networking credentials for a while -- VeriSign has seen a brisk trade in names and passwords for Russia's VKontakte, for example. But now the trend is to go after global targets such as Facebook, Howard said.

Facebook has more than 400 million users worldwide, many of whom fall victim to scams each day. In one such scam, criminals send out messages from a compromised account, telling friends that the account's owner is trapped in a foreign country and needs money to get home.

In another, they send Web links that lead to malicious software, telling friends that it's a hilarious or sensationalistic video.

"People will follow it because they believe it was a friend that told them to go to this link," said Randy Abrams, director of technical education with security vendor Eset. Once the malware gets installed, criminals can steal more passwords, break into bank accounts, or simply use the computers to send spam or launch distributed denial of service attacks. "There's just a plethora of things that people can do if they can trick people into installing their software," he said.

Kirllos' Facebook prices are extremely cheap compared to what others are charging. In its most recent Internet Security Threat Report, Symantec found that e-mail usernames and passwords typically went for between $1 to $20 per account -- Kirllos wants as little as $0.025 per Facebook account. More coveted credit card or bank account details can go for much more, ranging between $0.85 to $30 for credit card numbers to $15 to $850 for top-quality online bank accounts.

[via www.pcworld.com]


Hacker bietet 1,5 Millionen Facebook-Konten zum Verkauf

"Kirllos" bietet rund 1,5 Millionen Facebook-Zugangsdaten im Netz zum Verkauf an. Dabei sind die Preise überraschend billig: Für 1000 Konten fordert er zwischen 25 und 45 Dollar. 700.000 Accounts soll Kirllos bereits verscherbelt haben. Ein Ende ist nicht in Sicht.

Schon lange ist es kein Geheimnis mehr, dass soziale Netzwerke wie Facebook und StudiVZ Datenschützern und Verbraucherschützern ein Dorn im Auge sind. Die Skepsis ist nicht unbegründet, denn immer wieder kommt es zu überraschenden Datenlecks, die auf unklare Datenschutzbestimmungen und ein unverantwortliches Verhalten seitens der Nutzer zurückzuführen sind. Auch der neueste Fall lässt zahlreiche Netzaktivisten aufschrecken. Einem Bericht von "PC World" zufolge bietet der russischstämmige Hacker "Kirllos" rund 1,5 Millionen Zugangsdaten des sozialen Netzwerks Facebook zum Verkauf an. Mit Schleuderpreisen versucht der Hacker die Kunden auf seine Seite zu gewinnen. Für Datensätze von 1000 Konten verlangt er nur 25 bis 45 US-Dollar. 700.000 Accounts konnte "Kirllos" auf diese Weise bereits zu Geld machen.

Auf das Angebot des Hackers sei man erstmals in einem bekannten Hacker-Forum aufmerksam geworden. Schnell habe sich die Offerte von "Kirllos" in Kennerkreisen herumgesprochen, da die Preise ungewöhnlich niedrig waren. Während man in der Regel ein bis 20 US-Dollar pro Account einfordere, biete der russischstämmige Hacker die Accounts zu Schnäppchenpreisen an, heißt es. Mit durchschnittlich nicht einmal zwei Cent pro Account sei der Preis in diesem Fall überraschend günstig. Je nachdem, wie viele Freunde die jeweiligen Konten aufzuweisen haben, variiere der Preis der Datensätze. Für die Preisgestaltung sei auch die Aktivität des Nutzers von großer Bedeutung.
Welche Nutzer es getroffen hat, ist noch nicht bekannt. In Anbetracht der Tatsache, dass Facebook derzeit mehr als 400 Millionen Benutzer zählt und der Hacker "Kirllos" im Besitz von 1,5 Millionen Accounts ist, scheint das Ausmaß jedoch überwältigend. Sollten die Angaben stimmen, hätte der Hacker Zugang auf ungefähr jedes 267ste Konto.

[via www.gulli.com]

| Trackback | # 
 Saturday, January 30, 2010
Saturday, January 30, 2010 9:07:42 PM UTC ( EN | internet | markets )
Email
  • 90 trillion – The number of emails sent on the Internet in 2009.
  • 247 billion – Average number of email messages per day.
  • 1.4 billion – The number of email users worldwide.
  • 100 million – New email users since the year before.
  • 81% – The percentage of emails that were spam.
  • 92% – Peak spam levels late in the year.
  • 24% – Increase in spam since last year.
  • 200 billion – The number of spam emails per day (assuming 81% are spam).
Websites
  • 234 million – The number of websites as of December 2009.
  • 47 million – Added websites in 2009.
Web servers
  • 13.9% – The growth of Apache websites in 2009.
  • -22.1% – The growth of IIS websites in 2009.
  • 35.0% – The growth of Google GFE websites in 2009.
  • 384.4% – The growth of Nginx websites in 2009.
  • -72.4% – The growth of Lighttpd websites in 2009.

Web server market share

Domain names
  • 81.8 million – .COM domain names at the end of 2009.
  • 12.3 million – .NET domain names at the end of 2009.
  • 7.8 million – .ORG domain names at the end of 2009.
  • 76.3 million – The number of country code top-level domains (e.g. .CN, .UK, .DE, etc.).
  • 187 million – The number of domain names across all top-level domains (October 2009).
  • 8% – The increase in domain names since the year before.
Internet users
  • 1.73 billion – Internet users worldwide (September 2009).
  • 18% – Increase in Internet users since the previous year.
  • 738,257,230 – Internet users in Asia.
  • 418,029,796 – Internet users in Europe.
  • 252,908,000 – Internet users in North America.
  • 179,031,479 – Internet users in Latin America / Caribbean.
  • 67,371,700 – Internet users in Africa.
  • 57,425,046 – Internet users in the Middle East.
  • 20,970,490 – Internet users in Oceania / Australia.

Internet users by region

Social media
  • 126 million – The number of blogs on the Internet (as tracked by BlogPulse).
  • 84% – Percent of social network sites with more women than men.
  • 27.3 million – Number of tweets on Twitter per day (November, 2009)
  • 57% – Percentage of Twitter’s user base located in the United States.
  • 4.25 million – People following @aplusk (Ashton Kutcher, Twitter’s most followed user).
  • 350 million – People on Facebook.
  • 50% – Percentage of Facebook users that log in every day.
  • 500,000 – The number of active Facebook applications.
Images
  • 4 billion – Photos hosted by Flickr (October 2009).
  • 2.5 billion – Photos uploaded each month to Facebook.
  • 30 billion – At the current rate, the number of photos uploaded to Facebook per year.
Videos
  • 1 billion – The total number of videos YouTube serves in one day.
  • 12.2 billion – Videos viewed per month on YouTube in the US (November 2009).
  • 924 million – Videos viewed per month on Hulu in the US (November 2009).
  • 182 – The number of online videos the average Internet user watches in a month (USA).
  • 82% – Percentage of Internet users that view videos online (USA).
  • 39.4% – YouTube online video market share (USA).
  • 81.9% – Percentage of embedded videos on blogs that are YouTube videos.
Web browsers

Web browser market share

Malicious software
  • 148,000 – New zombie computers created per day (used in botnets for sending spam, etc.)
  • 2.6 million – Amount of malicious code threats at the start of 2009 (viruses, trojans, etc.)
  • 921,143 – The number of new malicious code signatures added by Symantec in Q4 2009.

Data sources: Website and web server stats from Netcraft. Domain name stats from Verisign and Webhosting.info. Internet user stats from Internet World Stats. Web browser stats from Net Applications. Email stats from Radicati Group. Spam stats from McAfee. Malware stats from Symantec (and here) and McAfee. Online video stats from Comscore, Sysomos and YouTube. Photo stats from Flickr and Facebook. Social media stats from BlogPulse, Pingdom (here and here), Twittercounter, Facebook and GigaOm.

| Trackback | # 
 Saturday, November 28, 2009
Saturday, November 28, 2009 10:09:58 PM UTC ( Apple | EN | internet | multimedia | tech )

Don’t hold your breath waiting for the iPhone to support Adobe’s Flash software: Apple’s terms-of-service agreement prohibits it.

Hulu_2

Although Adobe says it is working on a version of its popular Flash player for the iPhone, Apple is unlikely ever to permit it to appear in the handset’s App Store, no matter how much customers want it.

“I’m pretty skeptical that Flash could be implemented in a way that doesn’t violate the Terms of Service of the developer’s agreement,” said Bart Decrem, CEO of Tapulous, developer of the popular Tap Tap Revenge iPhone game.

Flash is Adobe’s highly popular platform for displaying interactive graphics, animations and multimedia within a browser. According to Adobe, 98 percent of desktop computers currently support Flash, which has led to its widespread use by web developers. Adobe’s recent announcement that it is working on a version of Flash for Windows Mobile has prompted speculation that an iPhone version might be coming soon. But the speculators may be waiting in vain, based on Apple’s TOS and the company’s history of tightly controlling applications for its smartphone platform.

Allowing Flash — which is a development platform of its own — would just be too dangerous for Apple, a company that enjoys exerting total dominance over its hardware and the software that runs on it. Flash has evolved from being a mere animation player into a multimedia platform capable of running applications of its own. That means Flash would open a new door for application developers to get their software onto the iPhone: Just code them in Flash and put them on a web page. In so doing, Flash would divert business from the App Store, as well as enable publishers to distribute music, videos and movies that could compete with the iTunes Store.

Apple’s well aware of these problems, which is why the company wrote a clause in its iPhone developers’ Terms of Service agreement (.pdf) that prohibits Flash from appearing on the iPhone:

“An Application may not itself install or launch other executable code by any means, including without limitation through the use of a plug-in architecture, calling other frameworks, other APIs or otherwise,” reads clause 3.3.2 of the iPhone SDK agreement, which was recently published on WikiLeaks. “No interpreted code may be downloaded and used in an Application except for code that is interpreted and run by Apple’s Published APIs and built-in interpreter(s).”

This could come as major disappointment to iPhone owners, as the lack of Flash support has been a paramount complaint about the handset since its release. No Flash means that the iPhone browser is incapable of displaying a large portion of the internet. For example, free Flash games aren’t supported, videos can’t be streamed from the vastly popular television and movie site Hulu, and websites that use Flash to render content or navigation won’t work on the iPhone.

It’s no wonder Adobe is expressing reluctance about the prospects of Flash for iPhone. The company on Monday demonstrated a version of Flash for Windows
Mobile handsets. And all that product manager Michele Turner could say about iPhone was, “We are working on Flash on the iPhone, but it is really up to Apple.”

Adam Dann, CEO of Nullriver, agrees that Flash would take away some of Apple’s control. Apple eventually banned Nullriver’s application NetShare because it violated AT&T Terms of Service agreement by turning the iPhone into a wireless modem for tethering. If Apple introduced Flash to iPhone, it’s possible Nullriver could code a Flash version of NetShare, repeating that violation, Dann said.

Dann added that the only way Flash could ever appear on the iPhone is if Adobe offered an extremely stripped-down version of the software. But even if there is a “Flash Lite” for iPhone, that just reinforces the point that the handset’s owners still will not have a true Flash experience.

And aside from taking software control away from Apple, Flash would introduce a slew of other potential headaches as well. Flash apps could hurt battery life, suck up the graphics-processing unit’s power, use an inordinate amount of memory, or potentially introduce security risks. Apple has plenty of customer complaints to address about the iPhone; the last thing it needs is to add Adobe and Flash to the pile.

In August, Britain’s Advertising Standards Authority pulled an iPhone advertisement because the commercial said, “All the parts of the internet are on the iPhone.” The lack of Flash and Java support on iPhone were enough for the ad to be deemed misleading. And it’s looking like Apple won’t be able to air that ad again.

Apple did not return phone calls for comment.

[via wired], [Download Apple iPhone SDK Agreement via wikileaks]

| Trackback | #