Showing posts with label 1. Show all posts
Showing posts with label 1. Show all posts

Wednesday, 14 August 2013

MySQL face-off: MySQL or MariaDB?

You may have heard about the upstart MySQL database MariaDB, a branch of MySQL created in the wake of Oracle's purchase of Sun Microsystems. You'll find many great reasons to consider MariaDB, not least that MariaDB is led by the original author of MySQL, Monty Widenius. But there are reasons to stick with MySQL too.

It's best to think about this decision in terms of the community you'll be turning to for support and bug resolution. For example, if you want to purchase a support contract and feel that Oracle support is your best avenue for problem resolution, you should surely go with MySQL. Also, if you're considering an upgrade to MySQL Cluster CGE (Carrier Grade Edition) down the road, you'll want to start with Oracle's community edition.

The choice will probably depend a lot on your team and their familiarity with the open source culture. If they're more comfortable having a support contract and official answers from Oracle's call center, go with MySQL.

Feels like MySQL

For MySQL users who are considering a move away from Oracle's version, compatibility is the foremost concern. That's why knowing that MariaDB is a complete drop-in replacement is key. What does it mean?

Although the package names differ, when you check them out of the repository, most everything else remains the same. Binary names of command-line tools, such as mysqladmin, mysqldump, mysql shell, and the daemon all retain the same names. What's more, the data files are completely compatible. MariaDB will work "out of the box" with the data files and table definitions of your existing MySQL instance.

Day-to-day advantages

What's great about a drop-in replacement is that your application doesn't need to change one bit. In the case of replacing MySQL with MariaDB, you'll immediately enjoy performance advantages. Community improvements from Facebook, Twitter, Google, and Percona all roll into MariaDB sooner than they appear in MySQL.

MariaDB also provides user statistics and better instrumentation through the data dictionary information schema, including microsecond support. If you're using TIME or DATETIME data types, you can specify precision, such as TIME(4), where the number represents the number of digits after the decimal place. MariaDB supports up to six digits -- for example, 0.000001 second or one microsecond. No more wondering how fast is fast. For those cases where precision is not specified, MariaDB defaults to 0 for easy backward compatibility -- nice!

Have you ever waited in frustration while executing a long-running ALTER TABLE in MySQL? MariaDB gives you a command-line progress indicator of such operations so that you can plan ahead. Welcome changes indeed!

Query execution is typically a big challenge for Web-facing applications. The brains behind query execution in MySQL is the query optimizer, and here too MariaDB offers serious improvements, including better subquery optimization, as well as faster, more efficient, and more consistent joins, derived tables, and views. In addition, MariaDB gives you additional control over how the optimizer makes decisions, exposing more internal instrumentation and configuration as server variables you can set.

MariaDB has also incorporated a kernel enhancement that removes mutexes that were terrible for performance. A mutex is a type of lock that serializes access to resources in the kernel. If the resource is currently held, a process must wait until it is available. An existing mutex built into the MySQL kernel slowed things down dramatically on modern hardware. Removing it helps MariaDB scale on the large SMP boxes that are becoming increasingly common these days.

Lastly, if you've wanted to move to row-based replication but been held back by the omission of SQL statements in row-based replication logs, MariaDB has addressed this too.

Row-based replication isn't generally readable because you're sending the raw data block, the before and after "image" of that data, not the SQL statement that was executed. The data block is delivered to the slave database and written directly to the file, no reexecution of SQL. For this reason, the SQL statement was left out of logging in MySQL.

In MariaDB, the SQL statements are logged to the binary logs for row-based replication just as they are for statement-based replication. Having that SQL statement can be very helpful for troubleshooting and in cases where you want to do point-in-time recovery. It's a much-needed addition.

Pushing the envelope

For those who want to push the envelope further, MariaDB has features that take you beyond the stock MySQL functionality.

For starters, you have two new high-performance storage engines to choose from: Aria and XtraDB. Although these are not drop-in compatible with existing MySQL deployments, you can rebuild a table to or from these engines with a simple ALTER command.

Next up you get access to a whole new clustering technology called Galera. This is completely different from NDB Cluster and its many known problems. Galera allows active-active multimaster updating, which does not work well with NDB Cluster because of the limitations on JOINs. Here you can really start to scale writes on cloud servers. What's more, you get access to parallel and synchronous replication features.

Want to get NoSQL speed? Consider the HandlerSocket plug-in, which enables direct access to storage engines without going through the optimizer, boosting velocity by 10 times or more. You can also now get a row of data returned in JSON format using dynamic columns in MariaDB -- not so in MySQL.

MariaDB includes yet another new storage engine, Cassandra SE, that allows you to read or write data into a Cassandra data store. Finally, integration between SQL and NoSQL made easy!

Want to consolidate data from multiple master databases? Multisource replication is exactly what you're looking for. Assuming your source data is stored in multiple schemas, they can all be brought together on one instance downstream -- again, not possible in MySQL.

As if all of these reasons aren't enough, MariaDB is a fully GPL-licensed version of MySQL. None of the plug-ins or other components are closed source. This brings all of the advantages of open source, from security and transparency to identifying bugs. MySQL is available under the GPL or a commercial license provided by Oracle. As a result, some components are open source, but others are not.

Comparing apples and oranges

If you're evaluating the various alternative distributions of MySQL, you'll need to weigh the pros and cons.

Percona, for example, offers another alternative to Oracle's MySQL Community Edition. Percona tends to take a more conservative approach to rolling in new features. This likely amounts to a small plus for stability but a minus point for not having the very latest and greatest features. Percona is still a big step ahead of MySQL, but perhaps not as close to the bleeding edge of what's happening across the MySQL world as MariaDB.

Drizzle is yet another fork of MySQL. In this case, though, it's a complete rewrite aimed at cloud deployments. Open source yes, but it's not a drop-in replacement for MySQL. You'll have to dump and reload your data, perhaps tweak your application as well, to get everything to work perfectly.

Although MariaDB may lag Percona a bit in terms of adoption, its popularity is growing quickly. For instance, Red Hat is replacing MySQL with MariaDB in its enterprise distribution, and Google recently devoted an engineer to the MariaDB project. As a serious alternative to MySQL, the case for MariaDB seems only to get stronger.

Google boosts flaw bounties to $5,000 on Chromium program


Google is upping the rewards it offers to bug hunters on its Chromium Vulnerability Rewards (VRP) program to $5,000 (£3,250) for those previously rated at $1,000, the firm has announced.

Nearly three years after it started handing out money to researchers on this program, Google has gradually increased the sums it offers for those wanting to make it  on to its 'Hall of Fame' list.

Judging from the list, a small elite of researchers is already making a tidy living from the rewards.


As for the higher sums, “In many cases, this will be a 5x increase in reward level! We’ll issue higher rewards for bugs we believe present a more significant threat to user safety, and when the researcher provides an accurate analysis of exploitability and severity,” said Google’s Chris Evans.

Google currently has three types of bug rewards; the Chromium VRP, the highly-rewarded and more critical Web VRP, and the sums it hands out at the public CanSecWest Pwnium contest.

In total, Google had handed out over $2 million across these schemes, split evenly between the Chromium/Pwnium track and the Web VRP, it said.

It’s the second increase in as many months with Google in June boosting the money on offer for critical cross-site scripting (XSS) flaws and those affecting its own programs by about the same factor.

Despite the optimistic enthusiasm of the latest announcement, the higher rewards are probably linked to lower submission rates. Last August, the firm raised bounties generally, saying it planned to offer much larger sums to specific types of serious flaw.

It remains true that bug hunters can get larger rewards by offering significant flaws to other vendors.

Earlier this year Google paid out a record $31,000 bug bounty to a University of Luxembourg researcher for spotting flaws in the O3D JavaScript API.

More Android malware distributed through mobile ad networks

Mobile ad networks can provide a loophole to serve malware to Android devices, according to researchers from security firm Palo Alto Networks who have found new Android threats being distributed in this manner.

Most mobile developers embed advertising frameworks into their applications in order to generate revenue. Unlike ads displayed inside Web browsers, ads displayed within mobile apps are served by code that's actually part of those applications.

The embedding of code for the advertising network into a mobile application itself ensures that ads get tracked and the developers get paid, but at the same time this third-party code represents a backdoor into the device, said Wade Williamson, senior security analyst at Palo Alto Networks, in a Monday blog post.

"If the mobile ad network turns malicious, then a completely benign application could begin bringing down malicious content to the device," Williamson said. "What you have at that point is a ready-made botnet."

There are precedents for this type of attack. In April, mobile security firm Lookout identified 32 apps hosted on Google Play that were using a rogue ad network later dubbed BadNews. The apps were benign, but the malicious ad network was designed to push toll fraud malware targeting Russian-speaking users through those apps. The malware masqueraded as updates for other popular applications.

According to Williamson, researchers from Palo Alto Networks recently came across a similar attack in Asia that involved using a rogue ad network to push malicious code through other apps without being detected by mobile antivirus vendors.

The malicious payload pushed by the ad network runs quietly in the device memory and waits for users to initiate the installation of any other application, Williamson said. At that point, it prompts users to also install and grant permissions to the malware, appearing as if it's part of the new application's installation process, he said.

"This is a very elegant approach that doesn't really require the end-user to do anything 'wrong'," the researcher said.

Once installed, the malware has the ability to intercept and hide received text messages, as well as to send text messages in order to sign up users for premium-rate mobile services, Palo Alto Networks said in a description of the attack sent via email.

Such attacks are probably specific to certain geographic regions, said Bogdan Botezatu, a senior e-threat analyst at antivirus vendor Bitdefender, Tuesday via email.

Botezatu expects the distribution of malware through mobile ad networks to become more common, especially in countries where mobile devices can't access the official Google Play store or where users have difficulties in purchasing applications in a legitimate manner, causing most Android devices to be configured to accept APKs (Android application packages) from unknown sources.

That doesn't mean that apps that deliver malware through ad networks can't make it into Google Play, as the BadNews incident has shown.

Google Play checks APKs for malware before approving them, so getting an infected APK uploaded there can be very hard, Botezatu said. However, a malicious ad server could lay dormant until after the application is approved and then start delivering malware, he said.

Botezatu believes that users are more likely to fall victim to "malvertising" -- malicious advertising -- attacks launched through mobile apps than Web browsers. That's because there have been many incidents of ad-based malware infections on computers and users are probably more careful about what they click on inside their browsers, he said.

Android users should make sure that their devices are not configured to allow the installation of apps from unknown sources and should run a mobile antivirus product, which might be able to detect malicious apps delivered through ad networks, he said.

Google at fault for adware in Play store apps, suggests Zscaler


Adware is now so deeply buried in Google’s Play store that one in five of the most popular apps are rated a privacy risk by mobile security programs, an analysis by Zscaler has found.

The firm ran the top 300 apps in each of the Play store’s main categories through a wide range of security products, finding that 1,845 were considered ‘adware’ by one or more programs, equivalent to 22 percent of the total.

All of these were marked out for bundling ads inside legitimate apps, sometimes deceptively, with a few even altering device and browser settings. Others captured personal data such as email addresses and device IDs without notifying users in a clear way and went on to push ads.

Concern about the volume of Play adware is not new but Zscaler’s analysis makes some new and interesting points as to why it might be happening, starting with the popularity of a single API, Airpush, used at the core of many apps by developers.

But there is another and more unsettling reason why adware has turned into such an issue – Google’s business model for the Play store is built on it.

“It is in the best interests of Google to appease advertising companies,” said Zscaler researcher, Viral Gandhi. “Google wants to encourage developers to expand offerings in their app store and developers often profit from free apps through advertising. Paid apps may also include advertising, in which case, Google takes a direct cut from the app proceeds.”

In a sense, the rise of adware underlines a conflict of interest. The Android platform needed as many apps as possible to attract users. Once there, these users had to be ‘monetised’.

“Google has plenty of incentive to allow apps with aggressive advertising practices,” Gandhi concluded.

Meanwhile, security vendors were under an equal pressure to spot behaviour that could be construed as being against the interest of users.

“There is a big gap between Google and AV vendors when it comes to adware. Ultimately, end users are stuck in the middle as they are left to decide if they will keep or delete the apps being flagged.”

The two biggest categories for suspect apps were games and personalisation, for instance wallpapers and themes.

Zscaler’s analysis of Google’s motives seems harsh. Ultimately, if users feel they are being fed aggressive adware by too many popular apps, even free ones, they will be put off Android to Google’s detriment. Google might also point out that users are now sophisticated enough to grasp that free apps have to be paid for somehow.

But what is acceptable and what isn’t?

In June, mobile security specialist Lookout publically blacklisted a class of free apps after finding that 6.5 percent of them met its definition of adware.  This is lower than that discovered by Zscaler but looked at a far larger number of apps.

In Lookout’s view the real problem is the popularity of a clutch of ad networks embedded in the apps to generate revenue. Some follow best practice but a hardcore don’t. Until Google makes a public stand on what is acceptable for apps the controversy looks likely to continue.

Foxconn's Hon Hai net profit up 41 percent in Q2

Foxconn's Hon Hai Precision Industry reported a strong gain in net profit during the second quarter, but revenue growth for the Apple supplier continued to remain weak.

Hon Hai's net profit in the quarter reached NT$16.9 billion (US$564 million), up 40.8 percent from NT$12 billion in the same period a year ago, the company reported on Tuesday.

Revenue, however, increased year-over-year by only 0.4 percent, putting it at NT$895.6 billion.

Hon Hai is the main manufacturing arm for Taiwan-based Foxconn Technology Group and builds products for major tech vendors including Amazon, Microsoft and Nintendo. Apple, however, is the company's most important customer and makes up about 40 percent of Hon Hai's revenue, according to analysts.

In this year's first quarter, Hon Hai posted a 19.2 percent year-over-year decrease in revenue. Some analysts have attributed the decline to weak demand for Apple's iPhone 5 product.

Hon Hai's reported financials on Tuesday did not go into detail about the business conditions behind its results. But in June, Foxconn CEO Terry Gou apologized to company shareholders for Hon Hai's falling stock price. At the time, news reports had emerged that Hon Hai had also lost manufacturing orders for Apple's rumored budget iPhone to rival Taiwan-based Pegatron. Gou declined to name Pegatron, but said his company's competitors were using low prices on manufacturing to grab orders.

A budget Apple iPhone is rumored to go on sale later this year, alongside with the new iPhone 5S.

Despite its declining revenue, Foxconn is working to expand its manufacturing and research. Last month, Gou made a high-profile visit to the Chinese city of Guiyang, where his company plans to establish a new manufacturing facility that could build products for the nation's electronics market. Foxconn already has over 1.2 million workers in China.

The company is also investing in researching robotics to better automate its factory assembly lines. In addition, Foxconn wants to hire 3,000 software engineers in Taiwan to help the company make Mozilla's Firefox OS a viable mobile OS competitor.

BlackBerry turns to 7 OS with social networking features for new 9720 smartphone


BlackBerry has launched the 9720 smartphone running the 7 OS in a bid to stay relevant in the growing low end of the smartphone market.

The launch of the new device comes as BlackBerry on Monday formed a committee to explore strategic alternatives for its future that could include joint ventures or a sale of the company.

As its new BlackBerry 10 operating system struggles to get off the ground, the company is still depending on the old version 7. During its last fiscal quarter BlackBerry shipped 6.8 million smartphones, but only 2.7 million phones running the new OS.

The launch of the BlackBerry 9720, which runs a refreshed version of the BlackBerry 7 OS, may play to the company's dwindling strength. The smartphone has a re-engineered physical QWERTY keyboard with a dedicated BBM key, a trackpad and a a 2.8-inch touchscreen with 480 x 360 pixel resolution.


The smartphone also has a 5-megapixel camera and an FM radio. Connectivity options include HSPA, 802.11n and A-GPS.

On the software side, BlackBerry has focused on social networking features. Users can write a message once and post it simultaneously to their friends on BBM, Twitter and Facebook, for example.

The updated interface also lets users swipe to unlock the phone or access the camera from the lock screen, among other enhancements.

The company didn't provide pricing, but beginning in the coming weeks, the BlackBerry 9720 smartphone will be available in select markets from retailers and carriers in Asia, Europe, Africa, the Middle East and Latin America. BlackBerry didn't disclose plans for U.S. availability.

Paypal founder Elon Musk unveils 760mph transport concept


Elon Musk has unveiled a near-supersonic transport concept to link Los Angeles and San Francisco, cutting the 380-mile journey to less than half an hour.

The blueprints reveal how the US-based billionaire wants to use magnets and fans to fire passenger-carrying capsules floating on a cushion of air through pressurised tubes. The plans were released as part a 57-page document outlining the project.

"Short of figuring out real teleportation, which would of course be awesome ... the only option for super-fast travel is to build a tube over or under the ground that contains a special environment," he wrote.

The SpaceX, Tesla and Paypal founder said the capsules would travel at speeds of up to 760mph or nearly the speed of sound. Musk claimed the solar-powered shuttle would be a quicker, safer, cheaper, and more efficient mode of transport between Los Angeles and San Francisco than the high-speed train line that is currently being built.

The pods could arrive every 30 seconds and even accommodate cars onboard.

Last week Musk described the concept as a cross between a "Concorde, a railgun, and an air hockey table".

He said on a conference call that passengers in the cabins would experience a little bit more than the force of gravity and compared the experience to being on an aeroplane as opposed to a rollercoaster.

He said the concept would work best between destinations less than 1,000km, adding that anything beyond that would be more suited to supersonic air travel.

In order to avoid minimal disputes over land, Musk envisions building the project on an elevated platform alongside an existing Californian motorway. He said the structure holding it up would be designed to withstand earthquakes.

Musk estimated that linking the two Californian cities in this way would cost $6bn (£3.9bn) and said fares could be in the region of about $20 (£13) for a one-way ticket.

Musk has said he is currently too busy to develop the project himself and is therefore making it “open source” so that anyone can improve it, or try to create it.
VRacer Car Racing Banner

Amazon improves performance of CloudFormation management platform


Amazon Web Services (AWS) has added new features to the company's management platform CloudFormation that aim to improve performance and simplify updates.

As companies get more used to running applications in the cloud, they are putting together more complex systems. That in turn puts higher demands on management platforms, which have to allow users to take better advantage of the programmability and scalability of the cloud.

CloudFormation aims to give developers and systems administrators a way to create and manage a collection of related resources, provisioning and updating them in an orderly and predictable fashion.

The latest additions to the platform are parallel stack processing and nested stack updates.

The first feature allows CloudFormation to create, update, and delete resources in parallel in order to improve the performance of these operations. For example, provisioning a RAID 0 setup, which involves the creation of multiple Elastic Block Store volumes, is now faster because CloudFormation can provision the volumes in parallel, Amazon said in a blog post.

The platform automatically determines which resources in a template can be created in parallel. Templates are used as a blue print when running CloudFormation to describe the stack of applications and resources needed.

The second new feature, called nested stack updates, deals with how resources are updated. Using CloudFormation, a three-tier application consisting of, for example, a web tier, app tier, and database tier can be created together and in the correct order. With the introduction of nested stack updates, users can also update all the parts in one swoop, instead of having to update each part individually.

IBM develops wind and solar forecasting system

IBM has developed power and weather modelling software that could help utilities increase the reliability of renewable energy resources.

IBM says the technology combines weather prediction and analytics to forecast the availability of wind power and solar energy.

The American firm claims this will allow utilities to integrate more renewable energy into the power grid, helping to reduce carbon emissions while improving clean energy output for consumers and businesses.

The solution, named Hybrid Renewable Energy Forecasting (HyRef), uses weather modelling capabilities, advanced cloud imaging technology and sky-facing cameras to track cloud movements, while sensors on the turbines monitor wind speed, temperature and direction.

When combined with analytics technology, the data-assimilation based solution can produce local weather forecasts within a wind farm as far as one month in advance, or in 15-minute increments.

By utilising local weather forecasts, IBM claims HyRef can predict the performance of each individual wind turbine and estimate the amount of generated renewable energy.

According to IBM, this level of insight can help utilities to better manage the variable nature of wind and solar, and more accurately forecast the amount of power that can be redirected into the power grid or stored. It could also allow energy organisations to integrate other conventional sources such as coal and natural gas.

"Utilities around the world are employing a host of strategies to integrate new renewable energy resources into their operating systems in order to reach a baseline goal of a 25 percent renewable energy mix globally by 2025," said vice admiral Dennis McGinn, CEO of the American Council On Renewable Energy (ACORE). "The weather modelling and forecasting data generated from HyRef will significantly improve this process and in turn, put us one step closer to maximising the full potential of renewable resources."

State Grid Jibei Electricity Power Company Limited (SG-JBEPC), a subsidiary company of the State Grid Corporation of China (SGCC), is using HyRef to integrate renewable energy into the grid. This initiative led by SG-JBEPC is phase one of the Zhangbei 670MW demonstration project, the world's largest renewable energy initiative that combines wind and solar power, energy storage and transmission. This project contributes to China's five-year plan to reduce its reliance on fossil fuels.

By using the IBM wind forecasting technology, phase one of the Zhangbei project aims to increase the integration of renewable power generation by 10 percent. This amount of additional energy can power roughly more than 14,000 homes.

Brad Gammons, general manager of IBM's global energy and utilities industry, said applying analytics and harnessing big data will allow utilities to tackle the intermittent nature of renewable energy and forecast power production from solar and wind, in a way that has never been done before.

BlackBerry's bleak options: will suitors really pay for a wedding?

As BlackBerry's board of directors formally begin exploring "strategic alternatives," they'll find their options limited, according to two IT sectoranalysts. All the likely alternatives call for a much diminished company, or broken up into some software assets and a brand value that's declining every day.

The board announced Monday the creation of a special committee to explore options to "inhance value and increase scale in order to accelerate" deployment of its BlackBerry 10 mobile operating system and server applications. In theory, everything is on the table, according to the company's statement, including "possible joint ventures, strategic partnerships or alliances, a sale of the Company or other possible transactions."

But potential partners, and buyers, are unlikely to see the same opportunities as BlackBerry's board, given that it's new generation of smartphones, running the innovative BlackBerry 10 operating system, have failed to ignite consumer interest since being released earlier this year.

BlackBerry's stock surged to $10.91 on Monday, from its Friday close of $9.76 per share, before finally closing at $10.78. It's past 52-week range is $6.22  to $18.32. Its market capitalization on Monday was $5.38 billion.

"BlackBerry is really three companies," says Jack Gold, principal for J. Gold Associates, an IT research and strategy consultancy. "There's BlackBerry the Device, BlackBerry the Services and BlackBerry the Community. Each has differing value."

The new BlackBerry 10 phones have received mixed reviews. Many reviewers game BlackBerry an "A" for effort but said the first phones suffer by comparison to the high-end iPhone and Android rivals like Samsung Galaxy S III.

Services assets include the BlackBerry Enterprise Services 10 server, for securing and managing multiple mobile operating systems, secure messaging, and the well-regarded BlackBerry Messenger for text and now video chat and collaboration. "It includes all themobile device management [MDM]  stuff," says Gold. "A cloud-based, cross-platform solution [from BlackBerry] for MDM, mobile application management and security is the same market that companies like AirWatch and MobileIron have been going after. That could be an attractive stand alone [business], or an acquisition by one of the other  layers in that space."

The community includes 60 million Messenger users, according to Gold and a total of global base of roughly 90 million.  That base could possibly interest emerging smartphone makers in China and other parts of Asia, companies such as Huawei, ZTE and Tata, if they see those millions as evidence of still-existing brand value. Despite its massive decline in the U.S., "it's still a recognized brand," according to Gold.

"Could one of them buy instant brand recognition and leverage the market?" Gold asks. "They could under the right circumstances."

But the best outcome for BlackBerry is a leverage buyout that takes the company private, according to Gold. "Once that's done, you're a private business without stockholders or government overseers," he says.

But another analyst thinks there's less to BlackBerry's value than meets the eye.

"BlackBerry Messenger is the only viable, attractive asset for a prospective buyer," says Jack Narcotta, analyst with Technology Business Research. "The likelihood of BlackBerry existing as an independent software-only company is slim as its cash reserves. The other assets and [the] subscriber base simply lack the scale needed to support transforming [the current company] into that business model."

There's little that can be done to change that.

"[T]e fuel on the fire for BlackBerry as it exists today isn't so much that its software is lacking," Narcotta says. "It's that BlackBerry is being overwhelmed by the flood of Android and iOS devices coming over the walls into the enterprise."

If there is a buyer, the most likely candidate is Samsung, he says.  The Korean smartphone maker has launched over the past year two programs to improve Android mobile security and management. Samsung for Enterprise or SAFE improves security for Samsung phones and tablets targeted at enterprise users; and Knox provides security enhancements to the underlying Android operating system.

"Samsung emerges as the most likely vendor to scoop up BlackBerry Messenger and BlackBerry Enterprise Services [BES] and integrate them into Android," Narcotta says. "BBM dovetails with Samsung's Knox and SAFE security initiatives nicely. Most BB10 apps are ported versions of Android apps, somewhat streamlining the process for BBM's core kernels and software development kits to be 'Android-ized.'

Neither analyst expects large-scale disruptions for enterprise BlackBerry and BES users, in part because so many have been already embracing iOS and Android. Narcotta says BlackBerry's future as an acquisition isn't "ideal" for customers but he's confident there will be a path to new vendors and services over time.

"BlackBerry is not likely to simply cease to exist, and if you find benefit in BES, as many shops do, its not likely you will simply be orphaned any time soon," says Gold. "Contingency plans are good, but no need to panic."

Intelligence chief Clapper to set up US surveillance review group


The administration of U.S. President Barack Obama on Monday launched a review of whether the country uses optimally advancements in technology to protect its national security while preventing unauthorized disclosure and maintaining public trust.

Surveillance by the U.S. National Security Agency has been at the center of a privacy controversy after its former contractor, Edward Snowden, released in June certain documents that suggested large scale collection of phone metadata and information from the Internet by the agency.

Director of National Intelligence James R. Clapper has been directed to form the new Review Group on Intelligence and Communications Technologies, which is to brief Obama on its interim findings within 60 days of the establishment of the group. A final report and recommendations are to be submitted through Clapper to the president no later than Dec. 15.

The constitution of the body including the number of members it will have was not disclosed.

The review group "will assess whether, in light of advancements in communications technologies, the United States employs its technical collection capabilities in a manner that optimally protects our national security and advances our foreign policy while appropriately accounting for other policy considerations, such as the risk of unauthorized disclosure and our need to maintain the public trust," according to a memorandum on the White House website.

Obama said Friday that his administration will appoint an independent board to review the country's surveillance programs, and also add a privacy advocate to defend privacy in the Foreign Intelligence Surveillance Court when agencies ask the court for new surveillance orders. Obama also said he will work with the U.S. Congress to limit data collection by the NSA under the Patriot Act.

The U.S. National Security Agency "touches" about 1.6 percent of daily Internet traffic, of which only 0.025 percent is selected for review, the agency said in its defense in a brief on Friday.

Citing figures from an unnamed tech provider, the NSA said the Internet carries 1,826 petabytes of information per day, of which the agency's analysts in effect look at 0.00004 percent or "less than one part in a million." The agency said its total collection added up to an area smaller than a dime in the standard basketball court of global communications.

U.S. telecommunications providers are compelled by court order to provide NSA with metadata about telephone calls to, from or within the country, NSA said in the brief. The purpose of the collection, under the NSA's Business Records FISA program, is to identify the "U.S. nexus of a foreign terrorist threat to the homeland." But the government "cannot conduct substantive queries of the bulk records for any purpose other than counterterrorism," it added.

NSA said it is authorized under section 702 of the Foreign Intelligence Surveillance Act to target non-U.S. persons who are reasonably believed to be located outside the U.S. The controversial part, criticized by many rights groups, is that the communications of U.S. persons are sometimes incidentally acquired in targeting the foreign entities.

In those cases, approved minimization procedures, which control the acquisition, retention, and dissemination of any information of a U.S. person, are used to protect the privacy of that person, NSA said.

"We do not need to sacrifice civil liberties for the sake of national security; both are integral to who we are as Americans," the unsigned document stated.

Verify people online. Backgroud checks, Criminal Histories, Marriage Records plus more. One Billion Records. Click Here

Monday, 12 August 2013

Bitcoins at risk of theft on Android

 Bitcoin is the best-known virtual currency A weakness in the Android mobile operating system has left users of the virtual currency Bitcoin vulnerable to theft, the Bitcoin Foundation has said.

The issue affects some Android "wallet" apps, the organisation said, including Bitcoin Wallet and BitcoinSpinner.

To protect an Android wallet, the developers said users must update their apps once a new version was available.

The news came as a US banking regulator ordered companies to co-operate with a probe into the way Bitcoin is used.

Continue reading the main story
Bitcoin is often referred to as a new kind of currency.

But it may be better to think of its units as being virtual tokens that have value because enough people believe they do and there is a finite number of them.

Each of the 11 million Bitcoins currently in existence is represented by a unique online registration number.

These numbers are created through a process called "mining", which involves a computer solving a difficult mathematical problem with a 64-digit solution.

Each time a problem is solved the computer's owner is rewarded with 25 Bitcoins.

To compensate for the growing power of computer chips, the difficulty of the puzzles is adjusted to ensure a steady stream of about 3,600 new Bitcoins a day.

To receive a Bitcoin, a user must also have a Bitcoin address - a randomly generated string of 27 to 34 letters and numbers - which acts as a kind of virtual postbox to and from which the Bitcoins are sent.

Since there is no registry of these addresses, people can use them to protect their anonymity when making a transaction.

These addresses are in turn stored in Bitcoin wallets, which are used to manage savings. They operate like privately run bank accounts - with the proviso that if the data is lost, so are the Bitcoins contained.

Bitcoin said the wallet problem had to do with Android's ability to generate sequences of secure random numbers needed to keep the wallets safe.

Analysts say Android's SecureRandom Java program sometimes repeats the number sequences, which must be unique in order to keep each Bitcoin secure.

Members of a Bitcoin forum have suggested that the equivalent of thousands of US dollars may have already been stolen.

Number sequences
"Because the problem lies with Android itself, this problem will affect you if you have a wallet generated by any Android app," the Bitcoin statement said on Sunday.

The issue affects only programs where the number sequences - or private keys - are controlled on the user's device.

For wallet apps that were vulnerable, Bitcoin said it would be necessary to change keys.

This involves "generating a new address with a repaired random number generator and then sending all the money in your wallet back to yourself", according to the Bitcoin statement.

Some of the affected apps were in the process of updating their wallet apps to fix the problem, including Bitcoin Wallet, BitcoinSpinner, Mycelium Wallet and blockchain.info, Bitcoin said.

But experts say virtual currencies could face ongoing problems of a similar nature because of the way they have been designed.

Dr Joss Wright, a research fellow at the Oxford Internet Institute, said that cryptographers relied heavily on a computer's ability to generate random numbers in order to keep information secure. But, he added, that computers did not always do this reliably.

"Choosing good random numbers is the key issue," Dr Wright said. "If the random numbers can be predicted by somebody else, this could lead to all sorts of security problems."

Meanwhile, The New York Department of Financial Services has told about two dozen firms associated with Bitcoin it wants information on anti-money-laundering programmes, consumer protection measures and investment strategies, .

The newspaper said there were concerns that virtual currency companies did not comply with money transfer rules and the state of New York was considering legislation aimed specifically at virtual currencies.

Bitcoin is the most well-known of a handful of virtual currencies. The currencies are developed through a computer process called "mining" and can be traded on exchanges or privately between users.

Blackberry shares jump on deal talk

Blackberry launched the Z10 this year Shares in smartphone maker Blackberry jumped more than 5% in New York following a report that the company is considering a major shift in strategy.

According to a Reuters report, Blackberry's management is considering taking the company private, which means buying out existing shareholders.

Going private would allow the company to reorganise its business without the pressure of shareholder scrutiny.

Blackberry has been losing money after failing to keep up with its rivals.

Last month the company's chief executive said that Blackberry was on the right and track, but needed more time to fix its problems.

Continue reading the main story If Blackberry decided to go private it would have to find partners who could raise the billions of dollars need to buy out existing shareholders.

That could prove difficult as the company has been struggling.

In its most recent quarter, Blackberry lost $84m (£54m) and expects to lose more money in the three months to the end of September.

Blackberry launched two all-new smartphones this year, the touchscreen Z10 device, followed by the Q10, with a mini keyboard favoured by many Blackberry users.

But some analysts have been disappointed by the sales of Blackberry's new phones.

Blackberry's managers will have noted the experience of computer maker Dell.

Founder Michael Dell is trying to buy out shareholders to help reorganise the firm.

But the plan resulted in a painful struggle with some shareholders accusing him and his partners of undervaluing their shares.