Scrolling box

computer hardware

Breaking News

Social Icons

Recent Comments

Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Thursday, April 3, 2014

As Windows XP retirement nears, businesses weigh upgrade risks

Microsoft will end support for the aging operating system after April 8, leaving unprepared financial institutions vulnerable to hacking.
FORTUNE -- After April 8th, 2014, Microsoft (MSFT) will end support, including automatic security patches, for its 13-year-old Windows XP operating system. This may sound like an inconvenience primarily for government agencies and aging uncles, but another major set of Windows XP users are the automated teller machines and credit card sales systems that handle billions of dollars of transactions daily.
While major retailers and banks are likely to be well-prepared for the end of XP, financial systems based on the software are also in the hands of a far-reaching hodgepodge of independent ATM operators and small businesses. Despite ample warning, industry analysts and insiders agree that high cost and inconvenience will keep plenty of these smaller players running outdated software for many months to come -- with serious implications for the security of their systems.

Jerry Nevins, co-owner of the Kansas City cocktail bar Snow & Co., is close to the dilemma. Snow & Co. bought a point of sale system less than a year ago from the payments servicer Micros -- only to be told within a few months of the need for an upgrade to Windows 7, at a cost of $1,700 for the single-store system. Luckily, Snow & Co. was still under a service agreement, so its upgrade was free. But as Nevins puts it, "If you're a small business, an unexpected $1,700 might be like, eh, I'll go ahead and take my chances." Moreover, Nevins describes a "huge line" of Micros customers waiting for an upgrade. He's crossing his fingers that Snow & Co. will be upgraded before the April 8 deadline.
Costs to retail credit card processors will vary widely, says John Berkeley of Mercury Payment Systems. "If you have the right hardware you can just upgrade the OS, but for some merchants upgrading from XP to Windows 7 can mean all new hardware," likely costing much more than that $1,700.
The challenges of upgrading become even bigger in the case of ATMs. ATM manufacturers are offering software upgrades for machines still based on XP -- though some of those have been available for less than a month. But the cost to upgrade can be staggering.
According to Jay Weber, vice president in charge of North American debit and ATM systems for FIS Global, "An ATM machine purchased in the last five years ... would only need a software upgrade of $4,000 to 5,000 per machine." That software cost is so high in part because much specialized software written for Windows XP can't be easily ported to a new operating system. But ATMs 10 years old or more would need to be completely replaced, and Weber says that new high-end ATMs can cost at least $50,000 to $60,000 per device.
ATM operators and business owners are largely being left to decide on their own whether to upgrade or not, says Weber. "Organizations are trying to look at the investment of the upgrade and weight it against their perceived risk" -- and many seem to be ready to take their chances. "[April 9th] is going to come and go, and there are going to be some merchants who haven't done it yet," says Berkeley. Weber speculates that "it's going to be a trickle approach, a slower ramp-up," with many systems going without an upgrade -- and remaining officially insecure -- through the end of 2014.
This hesitancy may be worsened because operators are getting mixed messages about their risk. The Payments Card Industry Security Standards Council has issued public warnings about the need for retailers to upgrade their point of sale systems, but their current set of standards, which are used to determine eligibility to operate on credit card networks, do not require it. And Weber himself seems sanguine: "The risk is hard to quantify. There's a lot of technology in place in the marketplace to help mitigate the risk," such as the "fairly closed telecom environment" that most payment systems operate on.
But Bogdan Botezatu, senior e-threat analyst for the anti-malware software company Bitdefender, couldn't disagree more. He talks about the issue with the barely suppressed terror of a father watching his teenage son drive solo for the first time. "They're not panicky," he says, "and actually that makes me panicky."
Botezatu, who haunts underground hacking forums to keep an eye on looming security threats, claims that hackers are gearing up to raid suddenly insecure XP machines the minute Microsoft support ends. "When an operating system is announced as reaching its end of life, [hackers] are frantically looking for exploits, because then they can use it indefinitely," he says. "It's the holy grail of malware."
To take fullest advantage of the situation, black-market vendors selling new XP exploits have been stockpiling them, waiting to release them until after Microsoft is no longer monitoring and repairing security flaws. Though third-party security firms will continue to update anti-malware programs for XP, users not running or updating such software could be permanently vulnerable to an ever-growing set of exploits. Mercury Payment Systems' John Berkeley confirms that "If a hacker discovers [a vulnerability] a month or two after the end of [XP support], they have more time to exploit that."
These exploits could range from stealing credit card information from small vendors to even more dramatic forms of theft, many of them easily circumventing external security measures such as the semi-closed payments network. Botezatu says there have been reports of an ATM exploit through a mobile phone connected through an ATM's card reader. He also cites a legendary stunt by the security expert Barnaby Jack at the Black Hat security conference in 2010, where he demonstrated a "Jackpotting" hack that easily emptied an XP-based ATM machine. According to Botezatu, Jack, who died in 2013, never revealed the nature of this exploit, meaning that it could remain an unpatched vulnerability in XP-based machines.
Most troubling of all, Botezatu predicts that unsecured XP machines of all kinds will be compromised by hackers to form new botnets. This kind of system, in which hacked systems' processors are put to new tasks unbeknownst to their owners, can be used for everything from massive Denial of Service attacks to mining cryptocurrency, and would add substantially to the insecurity of the Internet as a whole. "I see a lot of trouble," Botezatu warns.
Whether April 9th brings a plague of cash-spewing ATMs, zombie PCs, and thieving credit-card readers remains to be seen. But Botezatu sounds exasperated that he even has to consider these scenarios. "It's an operating system that was released 13 years ago. Everyone should have started migrating two or three years ago" to avoid the mad rush and risks that come with the end of support. He hopes, at least, that this episode will motivate today's users to think about the future.

"This is going to happen soon with other operating systems," Botezatu says. "You should start upgrading from Windows 7 now."
Read more ...

Thursday, March 20, 2014

Microsoft defends opening Hotmail account of blogger in espionage case

Company says it cracked open the Hotmail account of an unnamed blogger involved in a Windows 8 espionage case in part because he was selling Windows Server activation keys.
Microsoft's Panos Panay proudly shows off the then-new Surface hardware at the company's unveiling event at Chelsea Piers in New York, October 2012.
Microsoft defended what it called the "exceptional" step of a "limited review" of a blogger's Hotmail account as part of a larger Windows espionage case, saying it had caught the blogger selling Microsoft's intellectual property without permission.

A court filing alleges that the unnamed blogger had been provided prerelease Windows 8 RT source code by then-Microsoft employee Alex Kibkalo. Kibkalo is being charged with stealing trade secrets.
The filing says that Microsoft triggered an internal investigation into the blogger's actions when the blogger sent the source code to an unnamed person, hoping for verification of its origins. Instead, that person tipped off then-Windows chief Steven Sinofsky, who forwarded the details to Microsoft's Trustworthy Computing Investigations department, which investigates external threats and internal information leaks.
The March 17 filing (PDF) alleges that the unnamed blogger confessed to selling Microsoft's intellectual property.
 During his interview, the blogger admitted to posting information on Twitter and his Web sites, knowingly obtaining confidential and proprietary Microsoft IP from Kibkalo, and selling Windows Server activation keys on eBay.
Microsoft provided CNET with a statement defending its actions:
During an investigation of an employee, we discovered evidence that the employee was providing stolen [intellectual property], including code relating to our activation process, to a third party. In order to protect our customers and the security and integrity of our products, we conducted an investigation over many months with law enforcement agencies in multiple countries. This included the issuance of a court order for the search of a home relating to evidence of the criminal acts involved. The investigation repeatedly identified clear evidence that the third party involved intended to sell Microsoft IP and had done so in the past.

As part of the investigation, we took the step of a limited review of this third party's Microsoft operated accounts. While Microsoft's terms of service make clear our permission for this type of review, this happens only in the most exceptional circumstances. We apply a rigorous process before reviewing such content. In this case, there was a thorough review by a legal team separate from the investigating team and strong evidence of a criminal act that met a standard comparable to that required to obtain a legal order to search other sites. In fact, as noted above, such a court order was issued in other aspects of the investigation.
Read more ...

Tuesday, March 11, 2014

Microsoft, Google to sue over FISA gag order

Google and Microsoft plan to sue the government, demanding the right to publicly discuss any surveillance requests served up by the FISA court.
Microsoft general counsel Brad Smith.

Stonewalling by the Department of Justice has led Google and Microsoft to decide to file a lawsuit so that they can publicly discuss Foreign Intelligence Surveillance Court-approved surveillance orders.
Microsoft general counsel Brad Smith announced Friday that the company, in collaboration with Google, would sue the government despite its statement on Thursday that it would  publish some surveillance request information  annually.
Google and Microsoft are requesting the ability to publish "aggregate information" about FISA court orders directed at the companies in the hopes of being more transparent to their customers, the companies have said.
Google originally filed the motion to claim a First Amendment right to publish information such as how many requests it has received from under the Foreign Intelligence Surveillance Act. Section 702 of the act was amended in 2008 to allow the government to declare even the number of requests issued under the act subject to gag orders.
Before the National Security Agency document leaks from Edward Snowden, the FISA orders had been declared so secret that Google, Microsoft, and other companies served with them were barred from acknowledging in public that they had received the requests.
As part of the procedure for the lawsuit to proceed, Google and Microsoft will be amending their petitions filed with the Foreign Intelligence Surveillance Court, a source close to the matter told CNET. The companies received a 10-day extension, so the government isn't expected to respond by Friday's deadline.
The government's response to the original filing's deadline was delayed six times by the Department of Justice, leading to frustration on the part of the tech companies, which has culminated in the announcement of the lawsuit.
The source, who requested anonymity because the person lacked authorization to speak on the record, said that Google and Microsoft will be amending their petitions to more closely reflect the details of an open letter signed by most major tech companies (PDF) and sent after the initial FISA court filing from the Center for Democracy and Transparency to the heads of the US government and intelligence agencies.
It is likely that the government will consolidate the various petitions into the Microsoft lawsuit to avoid potentially having disparate decisions for different companies.
Read more ...

Justice Dept. weighs Google's request to lift NSA gag order

Microsoft, Google, and Facebook are asking the Obama administration for permission to clear their names by disclosing surveillance details. The Justice Department has not yet responded.
Attorney General Eric Holder, who has not lifted a gag order on Internet companies

The U.S. Department of Justice confirmed Tuesday that it is considering requests from Google, Facebook, and Microsoft that would let them clear their names after allegations they opened their networks to government spies, although U.S. Attorney General Eric Holder has not yet issued a decision on the matter.
In response to queries from CNET, the Justice Department said late this afternoon: "The department has received the letter from the chief legal officer at Google. We are in the process of reviewing their request."
David Drummond, Google's chief legal officer,  sent an open letter  to Holder and FBI Director Robert Mueller today asking them to lift a gag order so they could clear up misconceptions about National Security Agency eavesdropping. The ongoing gag order fuels incorrect "speculation," Drummond said.
Microsoft followed shortly afterward with a statement saying "government should take action to allow companies to provide additional transparency." And Facebook's general counsel, Ted Ullyot, called on the feds to allow "companies to include information about the size and scope of national security requests we receive, and look forward to publishing a report that includes that information."
The three requests from some of the United States' largest tech companies increases pressure on the Obama administration to permit more disclosure of what's happening in terms of national security-related surveillance. So does a parallel move today by Democratic senators to support legislation that would partially lift the veil on the secret Foreign Intelligence Surveillance Court.
Google, Apple, Yahoo, Microsoft, Facebook, and other Internet companies were left reeling after a pair of articles on Thursday alleged that they provided the National Security Agency with "direct access" to their servers. By late Friday, however, CNET reported that was not true, and the Washington Post backtracked from its original story on PRISM. In an editorial Tuesday, the paper said the process met legal "standards" and was subject to "judicial review."
Also today, Google told Wired that: "When required to comply with these requests, we deliver that information to the U.S. government -- generally through secure FTP transfers and in person. The U.S. government does not have the ability to pull that data directly from our servers or network."
Google already releases many statistics about government surveillance as part of itstransparency report, including, as of March, information on secret National Security Letters sent by the FBI. But a source familiar with the situation said the company has not secured permission to disclose information about secret court orders.
James Clapper, the head of national intelligence, confirmed last week that the Internet companies were receiving legal orders sent to them "pursuant to Section 702 of the Foreign Intelligence Surveillance Act."
After the Foreign Intelligence Surveillance Court limited a Bush-era warrantless surveillance program's scope, Congress enacted the FISA Amendments Act, which established a new procedure for foreign surveillance.
That Section 702 procedure works like this: The Justice Department must demonstrate that its surveillance will not intentionally target anyone present in the United States or any American who's overseas. And the surveillance process must comply with the Fourth Amendment.
Section 702 also requires that the government obtain the secret Foreign Intelligence Surveillance Court's approval of "targeting" and "minimization" procedures, and that the court review the agencies' certification describing how proposed surveillance techniques will comply with the law. Judges must consider whether the targeting procedures are "reasonably designed" to exclude Americans and purely domestic surveillance.
A former government official who is intimately familiar with this process of data acquisition and spoke on condition of anonymity told CNET last week that the government delivers an order to obtain account details about someone who's specifically identified as a non-U.S. individual, with a specific finding that they're involved in an activity related to international terrorism. Both the contents of communications and metadata, such as information about who's talking to whom, can be requested.
Amnesty International and journalists launched a legal challenge to Section 702 (which is sometimes called 1881a, for its location in the law books). They argued their confidential communications with foreign correspondents would be intercepted under Section 702 in violation of the Fourth Amendment. But in February 2013, the U.S. Supreme Court rejected their challenge by a 5-4 vote, with Justice Samuel Alito writing that their allegations were too "speculative" and the Section 702 process is subject to ongoing "oversight" and "review."
Here are the full statements from Microsoft and Facebook:
 "As Mark said last week, we strongly encourage all governments to be much more transparent about all programs aimed at keeping the public safe. In the past, we have questioned the value of releasing a transparency report that, because of exactly these types of government restrictions on disclosure, is necessarily incomplete and therefore potentially misleading to users. We would welcome the opportunity to provide a transparency report that allows us to share with those who use Facebook around the world a complete picture of the government requests we receive, and how we respond. We urge the United States government to help make that possible by allowing companies to include information about the size and scope of national security requests we receive, and look forward to publishing a report that includes that information." -- Ted Ullyot, general counsel, Facebook
 "Permitting greater transparency on the aggregate volume and scope of national security requests, including FISA orders, would help the community understand and debate these important issues. Our recent Report went as far as we legally could and the government should take action to allow companies to provide additional transparency." -- Microsoft
Also today, Sen. Al Franken, a Minnesota Democrat and head of a Senate privacy panel,downplayed concerns about NSA surveillance, saying: "I availed myself of [briefings by executive branch officials] so nothing surprised me and the architecture of these programs I was very well aware of."

Last updated at 6:50 p.m. PT
Read more ...

Microsoft's Kurt DelBene to lead HealthCare.gov revamp

Retiring Microsoft Office Vice President Kurt DelBene is going to be heading up the revamp of the troubled HealthCare.gov site.
Kurt DelBene

Politico reported the news on Tuesday. The US Department of Health and Human Services confirmed it shortly thereafter. 
Microsoft announced in July 2013 that DelBene, a 20-year Microsoft veteran, would be retiring as Microsoft reorganized itself along more device/services-focused lines. DelBene's last day at Microsoft was Monday, a Microsoft spokesperson confirmed.
Kathleen Sebelius, US Secretary of Health and Human Services, announced DelBene's appointment in a press release today. From that release:
"Today, I am pleased to announce Kurt DelBene as my senior advisor and successor to Jeff Zients. Jeff did an outstanding job working with our team to provide management advice and counsel on the HealthCare.gov project. Today, the site is night and day from what it was when it launched on October 1. I am very grateful for his service and leadership. His role leading the management of the site proved critical and today we are announcing his successor: Kurt DelBene. Kurt, who most recently served as president of the Microsoft Office Division, will lead and manage HealthCare.gov starting this Wednesday."
Back in 2011, Ballmer appointed DelBene as president of the Office division in a move some saw as signifying CEO Steve Ballmer's decision to bring more engineering-savvy talent into Microsoft's senior leadership circles."
Related posts

HealthCare.gov site can't fix its own mistakes -- report
HealthCare.gov security -- 'a breach waiting to happen'
'Pardon Snowden,' one tech exec tells Obama, report says

The Obama administration's Healthcare.gov initiative has been plagued with problems since it launched in October 2013. While some front-facing parts are now in better shape than they were in the first few months of its operation, the back-end is still a mess, according to some accounts.
According to Sebelius' announcement, DelBene has agreed to oversee the Healthcare.gov project for "at least the first half of next year." He will be providing management expertise, operations oversight, advice on additional enrollment channels, field operations, marketing and communications. He will work alongside CMS Administrator Marilyn Tavenner and in partnership with general contractor on the project, QSSI.
As Politico noted, DelBene's wife is freshman Rep. Suzan DelBene (D-Wash.), who also formerly served as a vice president in Microsoft's mobile communications business.

Update: DelBene isn't the first Microsoft exec to move into a high-profile government job, post-Microsoft. Former Windows Server Director Steven Van Roekel was appointed the US Chief of Information Technology in 2011.
Read more ...
THam khảo: Đầu thu DVB T2 | giàn phơi, lắp đặt giàn phơi quần áo hay giá giàn phơi thông minh tốt nhất cả nước