Monday, October 3, 2011

Oracle President Attacks Microsoft, HP, IBM and SAP

Oracle President and CFO Safra Catz today said Hewlett-Packard may be a “former” partner, claimed Microsoft is distracted by 16-year-old consumers, and said IBMers should hide under their desks in Armonk, N.Y., as Oracle’s Exadata business marches forward. Catz’s comments, some tongue-in-cheek, surfaced at Oracle OpenWorld today in San Francisco. Here’s the blow by blow.

Catz and Oracle (ORCL) Channel Chief Judson Althoff shared the stage during Oracle PartnerForum, part of the broader Oracle OpenWorld gathering today. Amid an audience of roughly 4,500 Oracle partners, Catz took aim at Oracle’s four fiercest rivals. Her comments were captured in this FastChat Video:

Thursday, July 21, 2011

Three free tips to better protect your iPhone

Smartphone security expert Graham Lee offers some simple advice on how better to protect your iPhone or iPad.

The iPhone - along with the rest of Apple's iOS product family - seems to me to be the TARDIS of the computing world.

There's a full-featured UNIX computer with almost permanent network access, and it fits in my pocket: surely it must be bigger on the inside. Apparently you can even use them to make phone calls, too.

It certainly puts my first portable to shame.

Of course, such a powerful computer must be protected, particularly when you use it for sensitive tasks like email and editing work documents on the move. So here's a short list of iOS tips to help you stay secure using your iPhones and iPads.

1. Set the passcode

Passcode screenAll of Apple's products that run iOS allow the user to configure a passcode. The passcode controls access to the apps and data installed on the device. No passcode, no data - and there's no way to get around that, because content including saved passwords and mail attachments is encrypted so that without the passcode, iOS can't read the content at all.

To enable the passcode, first launch the Settings app. In the "General" section, look for the "Passcode Lock" setting. Tap that, and you'll see a screen that allows you to turn the passcode on, and to define when it's required and whether to use a "simple passcode" (a four-digit PIN) or a longer password.

Even though iOS is designed to slow down "brute force" attacks (where the attacker enters multiple guesses at the passcode until he finds the correct value), guessing one of the 10,000 simple combinations is very quick.

Particularly if you use one of the most common PINs.

It's best to turn simple passcode off and use a stronger password, following Graham Cluley's advice.
2. Don't jailbreak

JailbreakMeBy default, Apple limit the software that will run on your iPhone or iPad to their own apps, and anything that you download through their app store. They do this to restrict the chance that malware gets onto the devices, and so far it seems to work: iOS has not seen the same malware problems that have plagued Android.

Google are more permissive about the software allowed in their marketplace, and allow installation of non-marketplace apps: both good avenues for getting malware onto a mobile phone or tablet.

Of course, some people (including regular Naked Security contributor Duck, who discussed the issue in a recent Chet Chat podcast) see this as an unwelcome limitation on what they can do with the phones that they paid for.

Such people may turn to jailbreaking to remove Apple's limitations, so that they can install unapproved software or reconfigure the operating system.

Down that path lies iPhone malware and an easy route for attackers to install remote access tools, keyloggers (well, taploggers I suppose...) and other nasty things.

"Grange Hill" stalwart Zammo would probably agree with me here: when it comes to jailbreaking, just say no.
3. Be careful of where you surf

Phishing, and other scams like the recent iTunes giftcard ruse, do not depend on your technology choices: they're designed to fool you, not your computer.

Mobile SafariWith that said, it's perhaps easier to be taken in when surfing with Mobile Safari: user interface hints including the location bar and the SSL padlock are smaller, and in scrolling to read a page's content you'll push them off the top of the page and perhaps forget to check that you're on the correct site.

Especially if you've just snuck your phone out during that boring meeting, and are still half-listening to the Q3 sales projections.

Personally, I reserve sensitive tasks including online shopping and banking for either native apps released by the banks and stores, or for the desktop browser where it's easier to see whether I'm on the right website.

I hope you found those tips useful. For more chat about mobile security and privacy, please follow me on Twitter.

Thursday, June 30, 2011

Robert Morris, Pioneer in Computer Security, Dies at 78

Robert Morris, a cryptographer who helped developed the Unix computer operating system, which controls an increasing number of the world’s computers and touches almost every aspect of modern life, died on Sunday in Lebanon, N.H. He was 78.

The cause was complications of dementia, his wife, Anne Farlow Morris, said.

Known as an original thinker in the computer science world, Mr. Morris also played an important clandestine role in planning what was probably the nation’s first cyberwar: the electronic attacks on Saddam Hussein’s government in the months leading up to the Persian Gulf war of 1991.

Although details are still classified, the attacks, along with laser-guided bombs, are believed to have largely destroyed Iraq’s military command and control capability before the war began.

Begun as a research effort at AT&T’s Bell Laboratories in the 1960s, Unix became one of the world’s leading operating systems, along with Microsoft’s Windows. Variations of the original Unix software, for example, now provide the foundation for Apple’s iPhone iOS and Macintosh OSX as well as Google’s Android operating systems.

As chief scientist of the National Security Agency’s National Computer Security Center, Mr. Morris gained unwanted national attention in 1988 after his son, Robert Tappan Morris, a graduate student in computer science at Cornell University, wrote a computer worm — a software program — that was able to propel itself through the Internet, then a brand-new entity.

Although it was intended to hide in the network as a bit of Kilroy-was-here digital graffiti, the program, because of a design error, spread wildly out of control, jamming more than 10 percent of the roughly 50,000 computers that made up the network at the time.

After realizing his error, the younger Mr. Morris fled to his parents’ home in Arnold, Md., before turning himself in to the Federal Bureau of Investigation. He was convicted under an early federal computer crime law, sentenced to probation and ordered to pay a $10,000 fine and perform community service. He later received a computer science doctorate at Harvard University and is now a member of the Massachusetts Institute of Technology computer science faculty.

Robert Morris was born in Boston on July 25, 1932, the son of Walter W. Morris, a salesman, and Helen Kelly Morris. He earned a bachelor’s degree in mathematics and a master’s in applied mathematics from Harvard.

At Bell Laboratories he initially worked on the design of specialized software tools known as compilers, which convert programmers’ instructions into machine-readable language that can be directly executed by computers.

Beginning in 1970, he worked with the Unix research group at Bell Laboratories, where he was a major contributor in both the numerical functions of the operating system and its security capabilities, including the password system and encryption functions.

His interest in computer security deepened in the late 1970s as he continued to explore cryptography, the study and practice of protecting information by converting it into code. With another researcher, he began working on an academic paper that unraveled an early German encryption device.

Before the paper could be published, however, he received an unexpected call from the National Security Agency. The agency invited him to visit, and when he met with officials, they asked him not to publish the paper because of what it might reveal about the vulnerabilities of modern cryptographic systems.

He complied, and in 1986 went to work for the agency in protecting government computers and in projects involving electronic surveillance and online warfare. Although little is known about his classified work for the government, Mr. Morris told a reporter that on occasion he would help the F.B.I. by decoding encrypted evidence.

In 1994, he retired to Etna, N.H., where he was living at his death.

In addition to his wife and his son Robert, of Cambridge, Mass., Mr. Morris is survived by a daughter, Meredith Morris, of Washington; another son, Benjamin, of Chester, N.J.; and two grandchildren.

Wednesday, June 15, 2011

Introducing the Linux Oracle Enterprise Manager Manual

Welcome to the first edition of the Linux Oracle Enterprise Manager Manual. Oracle Enterprise Manager is supported on multiple Unix, Linux and Windows operating systems on a wide variety of hardware and virtualization platforms. Oracle has consolidated all of the Oracle Enterprise Manager Unix, Linux and Windows operating system documentation within a large documentation library with hundreds of external links to My Oracle Support notes and addendum's. The Oracle Enterprise Manager installation documentation is presented in a consolidated format with the Unix, Linux and Windows operating system installation steps merged into the same sentences and paragraphs. For example, there is not a dedicated chapter or section about the installation of Oracle Enterprise Manager for Oracle Linux. The Linux installation steps are merged together with Unix and Windows. The consolidated format along with the external links to My Oracle Support make the Oracle Enterprise Manager 11g documentation challenging to use for any single operating system.

Tuesday, May 31, 2011

Will Linux Kernel 3.0 be a ground-breaking achievement?

Linux Kernel, an operating system used by the Linux family of Unix-like operating systems, is all set to launch its newest version Kernel 2.8.0 or to be named Kernel 3.0, a report on the ThinkDigit website said.

The Linux kernel 2.x.x series has been in the market for nearly 15 years. The recent Linux versions that have been released are 2.6.37, 2.6.38 and most recently 2.6.39. There have been issues and criticisms about the security and the complex structure of these versions, mainly originating from the complicated numbering system of the versions and their updates, which the company hopes will be fixed in the new 2.8.0 or the 3.0 version.

The new version aims at stabilizing the system for future projects like Linux 3.1 or 3.2, and the security updates will now be coming as 3.1.1 or 3.2.4.

With the kind of success Linux 2.6.x.x has experienced in the last 15 years, it will be a target for the developers to deliver ground-breaking features in Linux 3.0, rather than being just another Linux release.

Tuesday, May 3, 2011

Can Unity create first consumer-class Linux distro?

Linux, from the start, was never about being a consumer desktop.

It was an UNIX-based server operating system that could run on some college kid's PC. Which later could then run a graphical environment. And sound (sort of).

That did not stop people from trying to get it to become a consumer desktop. Caldera OpenLinux--my very first distro--was an early attempt to present ease-of-use to those users who were "less than power." Corel Linux was a better attempt, in that it brought WordPerfect and the rest of Corel Office to the table.

There were others, of course, as Linux got more mature, hardware issues settled down, and apps were created. But nothing seemed to take hold of the desktop market and be more than an IT lover's novelty OS. This was certainly not the case on the server side, which sees stunning success stories every day. But you should see that kind of server success, because that's where Linux excels.

Then there was Ubuntu.

Ubuntu, the Debian GNU/Linux-based distro that eschewed "Linux" from the start, set out to be the world's first commercially successful Linux desktop. That has been the goal of its commercial vendor, Canonical Ltd., from the beginning.

To reach that goal, Canonical has made some decisions that have led us to where we are today: Ubuntu 11.04, also known as Natty Narwhal. Also known as the 1.0 launch of the Unity desktop interface, a new GNOME-based shell that maximizes the amount of content viewing space by shoving toolbars and launch menus out of the way. With an eggplant color scheme.

Yesterday, I read Steven J. Vaughan-Nichols' discussion with Canonical founder Mark Shuttleworth on the merits of Unity, and saw an interesting point that Vaughan-Nichols raised, but did not follow as far as I would have gone. Citing another blog lamenting GNOME 3.0, the "official" new GNOME shell that's out and about, as "Defective by Design," Vaughan-Nichols states:

"GNOME 3.0, like too many Linux/Unix interfaces, was designed by software developers for software developers.."

Unity, on the other hand, was built with Canonical's usability testing and performance goals in mind. Which is why, we have heard Canonical reps explain ad nauseum, Canonical chose to take a different path with Unity rather than stick with a pure GNOME 3.0 environment for Ubuntu.

Yes, the irony in that last sentence is not too subtle.

It is not clear if Vaughan-Nichols' next passage is paraphrasing something Shuttleworth actually said, or if Shuttleworth just built his statement off of a point Vaughan-Nichols made in their conversation:

"Is Unity too simple for power users? Yes, it is. But, as Shuttleworth tells us that's by design. If you don't like simple, consumer-oriented desktops, you'll want to look at another Linux distribution because that's exactly where Ubuntu is now and will continue to go."

And that point got my attention. Do we really want power users to go off and find another distro? Again, it's not clear who actually came up with that notion in the Vaughan-Nichols article, which is why the headline for this article isn't "Shuttleworth tells power users to step off Ubuntu." But no matter where the idea came from, I can't say it's something with which I agree.

Linux has never had a clear separation between "regular" users and "developer" users. The line has always been a bit blurry, which has had the effect of sharpening the learning curve for incoming Linux users. Because Linux was designed by developers for their own use, new Linux users always had to put a little more effort into learning how to use the operating system. And, because Linux was sometimes built without the goals of independent software vendors in mind, it made Linux a challenge for ISVs to jump into as well.

This situation would tend to make one think that having a "pure" consumer distro, then, would be a good thing. After all, lower the barriers of entry and more consumers will come. More consumers, and ISVs will start to want to get their apps in front of new Linux users. More apps, and more consumers--well, you get the idea.

But, despite the success and good works of commercial Linux vendors like Canonical, Red Hat, and Novell/Attachmate, Linux has never been a vendor-only system. The communities around every part of Linux are those power users and developers who like to spend their time ripping the guts out of their systems and tweaking code for the pure pleasure of it. There are such users of Windows and OS X, too--but the difference is Microsoft and Apple don't need them.

Linux distros need their power user/developer set.

In some ways, I think the Linux design decisions made in the past catered too much to this power class of user, which did hold back the success of the Linux desktop.

But Linux vendors like Canonical cannot move too far in the opposite direction just to make only consumers happy. To do so would cut out a significant resource for future development. That balance is the price to pay for being an open source project.

Let's see if Unity can live up to its name for all levels of users.

Tuesday, April 19, 2011

In the beginning: Linux circa 1991

In 2011, you may not “see” Linux, but it’s everywhere. Do you use Google, Facebook or Twitter? If so, you’re using Linux. That Android phone in your pocket? Linux. DVRs? Your network attached storage (NAS) device? Your stock-exchange? Linux, Linux, Linux.

And, to think it all started with an e-mail from a smart graduate student, Linus Torvalds, to the comp.os.minix Usenet newsgroup:

Who knew what it would turn into? No one did. I certainly didn’t. I came to Linux later, although I was already using Minix and a host of other Unix systems including AIX, SCO Unix System V/386, Solaris, and BSD Unix. These Unix operating system variants continue to live on in one form or another, but Linux outshines them all.

The only real challenger in popularity to Linux from the Unix family already existed in 1991 as well, but I’ll bet most of you won’t be able to guess what it was.

Remember this now folks, I may use it another Linux quiz down the road. The answer is NeXTStep. You should know it as the direct ancestor of the Mac OS X family.

The real question isn’t how Linux got its start. That’s easy enough to find out. The real question has always been why did Linux flourish so, while all the others moved into niches?

It’s not, despite what former Sun CEO Scott McNealy has said, that Solaris ever had a realistic chance of making sure that “Linux never would have happened.” Dream on, dream on.

Linux overcame Solaris, AIX, HP-UX, and the rest of the non-Intel Unix systems because it was far less expensive to run Linux on Commercial Off-The-Shelf (COTS) x86 hardware then it was to run them on POWER, SPARC or other specialized hardware. Yes, Sun played with putting Solaris on Intel, three times, but only as a price-teaser to try to sell customers Solaris on SPARC.

In addition, historically Unix’s Achilles heel has been its incompatibility between platforms. Unlike Linux, where any program will run on any version of Linux, a program that will run on say SCO OpenServer won’t run on Solaris and a Solaris program won’t run on AIX and so on. That always hurt Unix, and it was one of the wedges that Linux used to force the various Unix operating systems into permanent niches.

There were other x86 Unix distributions–Interactive Unix, Dell SVR4 Unix (Yes, Dell), and SCO OpenServer-but none of them were able to keep up with Linux. That’s why SCO briefly turned into a Linux company with its purchase of Caldera, before killing itself in an insane legal fire against Linux that was doomed to fail from the start .

It was also to Linux’s advantage that its license, the Gnu General Public License version 2 (GPLv2) made it possible both to share the efforts of many programmers without letting their work disappear into proprietary projects. That, as I see it, was one of the problems with the BSD Unix family–FreeBSD, NetBSD, OpenBSD, etc.–and its BSD License.

Another plus in Linux’s favor was that as it turned out, Linux Torvalds wasn’t just a great programmer; he was a great project manager. Oh, Torvalds can be grumpy, very grumpy, but at the end of the day, after almost twenty-years in charge, he still manages to get thousands of developers to work together on an outstanding operating system. Not bad for an obscure graduate student out of Finland eh?