Pages

Saturday, March 19, 2011

New connection bar in Gmail for iPhone

Using Gmail in Safari on your iPhone gives you access to fast search, conversation view, stars, labels, and more. But it’s sometimes frustrating not knowing whether your email has been sent or whether your phone has a functioning internet connection at all. To address this, we recently introduced the “connection bar.” The connection bar appears at the bottom of the screen when needed to give you the info you want— and then gets out of the way.

The connection bar appears when the app launches and is checking for new mail:


It also appears when your phone is offline, back online and sending, and then again when it finishes sending all messages:


You can see this improvement by visiting gmail.com from your iPhone or iPod Touch’s browser (iOS4 only). Don’t see the new changes yet? Try clearing your cache and refreshing the page. And if you like using Gmail in mobile Safari, get to it faster by tapping the “+” at the bottom of the screen and then “Add to Home Screen.”

Security firm RSA gets hacked, ID token data stolencccccccccccc

IMG_0104b.jpg(Image: New Scientist)
Hackers mounting an "extremely sophisticated cyber attack" have broken in to the servers of security firm RSA and stolen information linked to the company's SecurID tokens, which are widely used to grant secure access to corporate networks and online bank accounts.
In an open letter on the RSA website, executive chairman Arthur Coviello said the security leak does not pose a direct risk to SecurID users, but the stolen information could be used as part of a "broader attack". It's not clear exactly what that means, but Rich Mogull of information security research firm Securosis suggests that the attackers may have gained the ability to generate valid token values in some cases.
SecurID tokens work by generating an authentication code that users enter in to their computer to gain access to their network or bank account. The token system generates a new code every 30 or 60 seconds, and is normally combined with a separate password. Mogull suggests that if attackers already know a user's password they could potentially generate a valid token and access the system.
This hypothesis seems to agree with recommendations made by RSA's parent company EMC in a filing with the US Securities and Exchange Commission. One document urges RSA customers to ensure their employees use strong passwords and avoid suspicious emails requesting usernames or other credentials. EMC also states that the matter won't "have a material impact on its financial results".
If you personally use a SecurID token, there's probably very little you can do right now to increase your security, but there's also little you actually need to do. Coviello says that RSA is "very actively communicating" with its customers about the steps needed to ensure security, so your employer or bank should soon be in touch with more information.

Global IT Security Wonks Get Wake-up Call

A panel discussion on global IT security at the ITSEF conference Wednesday involved much talk of private and public sector cooperation and trust. Such conversations, however, can only go so far, as audience member Jody Westby reminded the panelists. "The issue is a legal one," Westby remarked.

The audience at a panel discussing challenges and opportunities from a global IT security perspective Wednesday at the IT Security Entrepreneurs' Forum was nodding off until question time, when Jody Westby blasted the panelists.
She accused them of not sticking to the topic and suggested they focus more on the issues.
"The issue is a legal one," Westby said. "We need to stop talking at the 10,000-foot level about private/public partnerships or you gentlemen will be up there [on the stage] for the next few years."
The panel, moderated by CSO Magazine publisher Bob Bragdon, was held at Stanford University.
Panel members were Sumit Agarwal from the United States Department of Defense (DoD); Adam Hatfield from Canada's National Cybersecurity Directorate, and Kjetil Nilsen of Norway's National Security Authority.

The Security Waffle Factor

The 50 or so members of the audience seemed unimpressed as the panelists droned on, mainly about private/public sector cooperation.
The DoD's Agarwal essentially said nothing in a lot of words. One example is his answer when moderator Bragdon asked whether the level of cooperation that's needed between the two sectors can be achieved.
"There are things on which there's a large amount of consensus; there are things on which they're not all aligned," Agarwal replied. "The biggest challenge, I think, is in getting comfortable with the inevitable failure, the inevitable breach; understanding that the value of that sharing outweighs the risk of a breach, as long as that benefit we accrue by sharing is larger than the risk we incur by sharing."
It would probably be fair to say that those involved in IT security in both the private and public sectors would have spent considerable time mulling over this point.
In response to a question from Bragdon about what other policies nations need, Norway's Nilsen talked about the need for inclusion and trust.
"I think it's important to make the private sector feel included," Nilsen said. "To do that we need to establish mutual trust. There must be some incentives for private business to cooperate with government."
Canada's Hatfield provided more of the same in his response.
"From a philosophical perspective, the government must be willing to do things together with the private sector, be willing to offer more transparency, but not pull out the heavy hammers of regulation."
The same philosophy was espoused back in 2008 when the Center for Strategic and International Studies, a bipartisan think tank, called on the then-incoming Obama administration to work closely with the private sector in securing cyberspace. Nothing new here, move on.

Cybercrime and Punishment

Here's Canada's Hatfield in response to a question by Bragdon about the definition of cybercrime: "Crime means something specific to government. It means you send someone to arrest someone for doing something."
Cybersecurity, on the other hand, requires a lot of cooperation between governments as to what to do and governments need to be "extremely clear" as to what they are trying to do when they cooperate, Hatfield added.
After waffling about cooperation being the sharing of information and best practices in response to the question about defining cybercrime, Nilsen said all cooperation requires trust. "The matter of trust is very, very important," he stated. "I think this may be our largest challenge in the upcoming years," he added.
"There is no entity anymore that is only an adversary or only an ally," the DoD's Agarwal remarked. "There is no clear demarcation on who's an adversary on the international level in the standards area."
Yes, that certainly defines cybercrime clearly.

Round and Round We Go

Why the need to define cybercrime at all?
"People have been talking about what cybercrime is for the past 10 years," Global Cyber RiskCEO Westby huffed. "I tell everybody not to spend 10 years arguing about a definition of cybercrime."
Several bodies have been set up to facilitate international cooperation for crackdowns on cybercrime, she told TechNewsWorld.
One such body is the Council of Europe Convention on Cybercrime, set up in 2001. This body has 46 signatories, but only 30 have ratified the convention, Westby remarked.
Another body is the G8 High-Tech Crime 24-Hour Point-of-Contact Network, set up in 1997, Westby said. This organization has 50 member states.
The real difficulty in fighting cybercrime across national borders hinges on the law.
For one thing, different countries have different laws, so what may constitute a cybercrime in one nation may be perfectly legal in another, Westby said.
Also, different countries have different interpretations of laws, she added.
Further, not all countries are tackling the cybercrime issue.
"There are many countries that don't even have cybercrime laws," Westby stated.
That makes it difficult to pursue criminals across national borders in those countries because "law enforcement agencies can't even talk to each other," Westby remarked.

iPad 2 Is Everywhere and Nowhere

Apple is currently selling the iPad 2, but for all practical purposes that really means it's accepting payment and promising delivery in over a month. Buyers quickly exhausted supplies at launch, but that appears to be par for the course for new iThings. Is its supply chain stretched to the limit or is it shortage by design? Meanwhile, Netflix pulls an HBO, AT&T pushes data caps and HP reaches for the cloud.

The new iPad 2 has arrived, sort of. It made a brief appearance last Friday in Apple (Nasdaq: AAPL) stores and a few other retailers. But by Saturday the only place you could find one was either chained to an Apple store table as a demo model or clutched in the hands of a neighbor who decided that getting up in the wee hours to stand in line on Day One was a sensible thing to do.
Ordering online didn't necessarily mean instant gratification either. Some extremely early orders have come in, but by the second day, delivery times had stretched to three weeks. Now it's more like five.
So yeah, it's once again a hard life for desperate Apple fanboys and fangirls. But they've been here before. Every time Apple puts out a new iObject there are lines, shortages, riots. The company never seems to have enough on opening day, and that might be strategy, it might be accident, or it might be one big mistake.
Obviously, if you leave customers waiting long enough, they'll just go somewhere else. With the original iPad, there was really nowhere else to go for a tablet, but now several other choices with certain degrees of similarity to the iPad are out there, ready to go, and others are just around the corner. The Xoom is one big rival, and by the end of this month, Motorola(NYSE: MOT) says it'll start selling a WiFi-only model that will be competitive with iPad 2 on price.
Or are shortages all part of Apple's master plan? Make it harder to get, make people line up for it, make 'em beg for it, and suddenly it's more desirable than if you could just pick one up at a Fry's any time you please.
Perhaps a shortage tends to have that effect on some people's perception of the product, but I don't know that Apple's intentionally choking its own supply pipeline. The things are built in a factory by incredibly hard workers, but Apple has to play the calendar just as hard as everyone else. It needed to get it out there fast in order to claim new buyers and get them hooked on a brand in a market where most loyalties haven't been established yet. Some analysts estimate that more than two-thirds of iPad 2 buyers do not own an original iPad.
Also, there's a gaping maw of demand that just isn't evident for a lot of other products. Did you see lines for the Xoom or the Galaxy Tab? On the other hand, maybe lines just form because people think there will be a shortage. Kind of a chicken-and-egg thing, I guess.

Microsoft is more ethical than Google, Apple, Facebook

Ethisphere Institute has released its list of the 2011 World’s Most Ethical Companies. There is no set number of companies that make the list. Almost 3,000 companies were nominated – or nominated themselves – to be considered this year, but only 110 were honored, the largest number since the award's inception in 2007.
In the computer software category, five companies were named: Adobe Systems, Microsoft, Salesforce.com, Symantec Corporation, and Teradata Corporation. Only Hitachi Data Systems was present in the Computer Hardware section. In Telecom Hardware, three were listed: Avaya Inc., Cisco Systems, and Juniper Networks. Under Electronics and Semiconductors, the three picked were Freescale Semiconductor, Premier Farnell, and Texas Instruments.
Apple, Facebook, Twitter, and Google did not make the list. Neither did Intel, AMD, or Nvidia. Frankly, more tech companies that we know did not make the list than companies that did.
"At the heart of the evaluation and selection process for Ethisphere's World's Most Ethical Companies is Ethisphere's proprietary rating system, the Ethics Quotient (EQ)," the Ethisphere Institute explains. "The framework of EQ is comprised of a series of multiple choice questions that capture a company's performance in an objective, consistent and standardized way. The information collected is not intended to cover all aspects of corporate governance, risk, sustainability, compliance or ethics, but rather it is a comprehensive sampling of definitive criteria of core competencies. The EQ framework and methodology was determined, vetted and refined by the expert advice and insights gleaned from Ethisphere's network of thought leaders and from the World's Most Ethical Companies Methodology Advisory Panel."

IE9 users get a free month of Hulu Plus, more

Microsoft has teamed up with several online services to promote the arrival of Internet Explorer 9. Folks running the latest iteration of IE will be able to take advantage of deals from Hulu, Groupon, eBay, Slacker and Gilt Groupe. In addition to attracting new users, Microsoft says the partnerships will show other sites how they can customize their web experience to take advantage of IE9's new features. 

Some of the deals are available immediately while others will go live over the coming months. All of them require Windows 7's new taskbar, so it seems Vista and XP users are out of luck. Starting March 28, IE9 users will receive a free month ofHulu Plus by pinning and accessing the promotion through the Jump List. Hulu Plus usually costs $7.99 a month and includes higher quality videos and more content. 


You can earn $5 in Groupon Bucks by pinning Groupon to your taskbar and clicking on a deal. We don't see a specific date when this offer will be active, so we assume it's available now. Likewise, from March 28-30 (or while supplies last) you'll be awarded a free Xbox 360, Xbox 360 Kinect bundle or a Samsung Focus WP7 handset by pinning Gilt to your taskbar and making a purchase of $250 or higher. 

Internet radio service Slacker has a deal "coming soon" that will give IE9 users a free month of premium radio (a $4.99 value, removes ads on top of other features). Two deals are planned for eBay. In April you'll be able to earn 8% extra eBay bucks when you make purchases by clicking through the Jump List, and in May you'll get a $5 discount on the first thing you buy when coming from the Jump List.

Ubisoft caught selling 'pirated' Assassin's Creed soundtrack?

Ubisoft has been accused of selling a torrented soundtrack of Assassin's Creed: Brotherhood. Customers who preordered the "digital deluxe" edition of the title received various extras including the game's soundtrack. According to one customer, the music files that Ubisoft included with his game came from the popular BitTorrent tracker Demonoid. 

The AC: Brotherhood soundtrack was uploaded to Demonoid more than four months ago by a member named "arsa13". The same user is credited for encoding the official soundtrack's MP3s (see the screenshots below). "Apple Chamber" is the only song that doesn't mention arsa13, but that track was also excluded from the original torrent file. 




This, of course, is ironic given the developer's stance against piracy and torrent sites. Last year the company introduced anew DRM scheme in the name of piracy that requires users to remain online while playing. To the dismay of fans, the mechanism has been used in Assassin's Creed II, The Settlers VII, Splinter Cell: Conviction and other titles. 

This is the second time Ubisoft has been caught using torrented content. In 2008, customers who bought a digital copy of Rainbow Six: Vegas 2 couldn't launch the game after installing an official update. Ubisoft resolved the issue with a second patch, which was eventually discovered to be a torrented No-CD crack from warez group RELOADED. 

We should note that this story first surfaced on Wednesday and Ubisoft hasn't released a public statement besides tellingEurogamer that it's investigating the matter. It shouldn't take more than 48 hours to determine if Brotherhood's retail soundtrack is from a legitimate internal source, so we're not sure what to make of the company's silence.