Thursday, March 31, 2011

Fast-Charging Batteries Face Long Road to Production

The research firm of IDC has predicted that Windows Phone 7 could beat the iPhone by 2015. I'm not sure if they predicted it to get a lot of attention for IDC or if they are serious.

The whole idea stems from the Nokia deal and patterns of buying behavior. There is not enough data—none, in fact—on the pick-up sales created by the Microsoft-Nokia deal, so this prediction is completely off-the-wall and seems based more on current Symbian numbers than actual sales. There is one conceivable underlying assertion, and that's that Phone 7 is better, by far, than Symbian, and if Symbian is still hanging in there (it is), then Phone 7 should do as well or better.



Best Cisco CCNA Training, Cisco CCNA Certification and more at certkingdom.com



So logically, this is not a real stretch.

The way IDC sees all this is as follows (all predicted for 2015): Android will be number one with 45.4 percent market share, next will be Windows Phone 7 and Windows Mobile with 20.9 percent, and will be followed by Apple's iPhone with 15.3 percent.. Taking up the rear will be BlackBerry with 13.7 percent, "Others" with 4.6 percent, and then Symbian with 0.2 percent.

This list assumes a lack of consolidation. Anyone who has read my thoughts on the issue knows that I expect the smartphone OSs to consolidate in much the same way that the PC OS business consolidated into two camps, PC and Mac. The smartphone market will logically consolidate into the same basic model. This time, the finally two will be Android and iOS.

This will happen largely for the same reason that the PC/Mac duopoly consolidated and that reason is developer support. People like to buy into a platform that has a lot of developer support, and developers only support what is popular, which is determined by developer support, and it goes round and round.

This crazy cycle cannot be easily broken by newcomers although it was done twice in recent memory in the gaming business by both Sony's PlayStation and Microsoft's Xbox. These two were not even in the game when Sega and Nintendo were battling it out, and everyone said no newcomers could emerge.

But the gaming business is different enough from the PC or smartphone businesses to reject the possibility that a newcomer—Phone 7—could enter the game and becoming successful. And I say this knowing full well that Microsoft invented the category. Okay, to put some historical gaming business spin on it: Atari invented the video game and where is it now?

To summarize: the IDC report is rank speculation.

The one long shot possibility, the way I see it, is that Windows Phone 7 phones could become the low-end smartphones that replace all the so-called feature phones. We have to face the fact that eventually all phones will have no buttons and be based on the smartphone virtual keyboard concept, because at some point they will be much cheaper to make. We can call them software phones, since their operation will be all software.

The problem with Microsoft trying to take over the lower-end segment of the market is that Android and Apple could both drop down and do the same thing. In fact, the Android OS has "Car Home," which presents the user with a simplified menu structure that is reminiscent of Phone 7 and can presumably be operated while driving.

But what is also overlooked in all this is that if all phones are going to become software-based, then there is zero reason not to push them to the max with more and more complex features. It's just software after all.

None of this bodes well, long-term, for Phone 7. It all seems like wishful thinking to me. But I wish them luck.

Saturday, March 12, 2011

Windows 7 Rogue WiFi Hack

Windows 7′s popularity has raised its market share at a sky-high pace. Within 3 months of its official launch, it has crossed the Mac OS to capture 8% of the OS market.

A while back, we discussed that Windows 7 features a half-baked “SoftAP” feature, also called “virtual Wi-Fi,” that allows a PC to function as a Wi-Fi client and also as an Access Point (AP) a.k.a wireless router.

The idea is not new but, pretty nifty for sharing data, music, files with others other peers in absence of an actual AP. But often good features come with a backdoor. But it makes executions of certain nightmares handy, e.g.Visitors and parking-lot hackers can piggyback onto the user’s laptop and “ghost ride” into the corporate network, unnoticed.

The problem was first demonstrated at BlackHat by AirTight networks, a wireless intrusion-prevention system (WIPS). They first executed Rogue APs to fetch user’s frequently-connected Wifi, followed by how to make a wishful hacking on the victim’s machine.



Best Cisco CCNA Training, Cisco CCNA Certification and more at certkingdom.com


Gopinath KN, director of engineering at AirTight Networks, says a Windows 7 device performs Port Address Translation (PAT), allowing a single public IP address to be used by many LAN devices (and exposing only certain Layer 4 port numbers). So devices that associate with the Windows 7′s virtual AP will be bridged into the wired network unseen because they will be hidden behind the “master” IP address.

The issue is more dangerous than Wi-Fi’s peer-to-peer(ad hoc) mode. In peer-to-peer mode, the only data exposed is the local files and applications on participating users’ laptops — not the whole corporate network.

Remedy

WIPS products such as AirTight’s and those from competitors such as AirMagnet and AirDefense scan the airwaves for unauthorized devices in the airspace — such as a Windows 7 SoftAP — and flag them as rogues that clients are not permitted to associate with.

So using WIPS is one protective option. Another is to provision the laptop with the SoftAP capability turned off and deprive Windows 7 user’s admin rights, so that they can’t turn it back on.

Another way out is to install mobile device management, security agent software on the laptop that enforces centralized policies such as disabling soft APs and ad-hoc Wi-Fi modes. And AirTight, in addition to offering WIPS, also has such a client agent it calls SpectraGuard SAFE.

Sunday, November 7, 2010

Microsoft Slams Google in EU Privacy Comments

Microsoft objects to Google's search-related business practices because Google locks in publishers and makes it hard for competing search engines to gain market share, not because of its popularity and competitive power, Microsoft said Friday.

Dave Heiner, vice president and deputy general counsel at Microsoft, released a blog post this afternoon in which he discussed the EU's decision to look into Google's search result rankings. He slammed Google for what he considered to be finger pointing at Microsoft over the investigation.




Best Cisco CCNA Training, Cisco CCNA Certification and more at certkingdom.com


"Google's public response to this growing regulatory concern has been to point elsewhere--at Microsoft," Heiner wrote. "Google is telling reporters that antitrust concerns about search are not real because some of the complaints come from one of its last remaining search competitors."

On Tuesday night, Google announced that European antitrust regulators are investigating whether Google intentionally buries search results that might promote its competitors. Three companies - Foundem, ejustice.fr, and Ciao from Bing - filed complaints with the EU over Google's rankings, said Julia Holtz, Google's senior competition counsel.

Foundem, which Google said is partly funded by Microsoft, and ejustice.fr are arguing that Google's algorithms demote their search results because they are a vertical search engine and, therefore, competitive with Google, Holtz said.

In regards to the third company, Ciao, Google suggested that the problems with them started after Microsoft acquired the company in 2008. Prior to that, Ciao was "a long-time AdSense partner of Google's, with whom we always had a good relationship," Holtz said. After Microsoft bought Ciao and re-branded it Ciao from Bing, Google "started receiving complaints about our standard terms and conditions."

In his blog post, Heiner did not address Microsoft's connection to the three companies, referring to them only as "upstart innovators."

UPDATE: A Microsoft spokesman e-mailed to say that the company does not directly fund Foundem. Microsoft partly funds the Initiative for a Competitive Online Marketplace (ICOMP), of which Foundem is a member, Microsoft said.

The real issue, Heiner said, is "whether Google's response really addresses the concerns that have been raised [because] complaints in competition law cases usually come from competitors."

Microsoft did not admit to being directly involved in filing the complaints against Google. Microsoft has heard complaints about Google over the years, Heiner said, and when those "antitrust concerns appear to be substantial, we suggest that firms talk to the competition law agencies."

Heiner acknowledged that Microsoft has talked with European investigators and the Department of Justice about Google, but only in the context of Microsoft's recently approved search deal with Yahoo.

"We told them what we know about how Google is doing business," Heiner wrote. "A lot of that entails explaining the search advertising business, which is complex. Some of that inevitably gets into Google practices that may be harming publishers, advertisers and competition in search and online advertising."

Specifically, Microsoft is concerned that "search and online advertising are increasingly controlled by a single firm, Google," Heiner said. "These and other network effects make it hard for competing search engines to catch up."

This is why Microsoft and Yahoo are combining their efforts, Heiner said. "And that is why we are concerned about Google business practices that tend to lock in publishers and advertisers and make it harder for Microsoft to gain search volume."

Heiner concluded by saying that "leading firms should not be punished for their success [or] because a particular business practice may harm a rival." They should face scrutiny, however, for practices that "exclude competitors, thereby undermining competition more broadly," he said.

Thursday, November 4, 2010

Cisco Netranger sensor

Cisco?s Netranger is one product that is only available as an appliance. For this test Cisco was only able to source an older PII-based hardware platform, although the sensor software was up to date. We were also provided with the latest signature library.

Deployment is a rapid affair thanks to Cisco?s Policy Manager software. This stores policy information on a local machine and distributes settings when changed. This means expansion of the network or hardware replacements are simple to manage.




Best Cisco CCNA Training, Cisco CCNA Certification and more at certkingdom.com




As this can be overkill in a smaller network Cisco has developed a web interface for three sensors or less.

Inside the policy manager are the sensor options. Each has settings that govern the way it works, including the networks it monitors and whether to reassemble IP fragments or not ? worth doing, as crackers often fragment attacks to avoid IDS.

Next, a signature library has to be associated. This library defines which attacks should be looked for and the action to take when they?re found. Each signature can be manually modified with options including resetting or blocking the attack, and changing the priority level.

Attack reporting can be seen in the Event Viewer application. For the most part, it only generated one message per attack and at no point were we flooded with hundreds of alerts.

This can be further fine-tuned with the help of signature debug mode. This mode reports the number of packets that caused the event to trigger. In a production environment false negatives can be tuned out by upping the set value. Signatures can also be altered to only fire once in a given time period. This prevents the console being flooded in the event of an attack.

You can even write your own pattern-matching signature files which helps if you want to block a new attack or virus before the appropriate signature is released.

Our testing showed the system to be fast and accurate in its detection. We noticed the engine is better working with generic network attacks, and tends to miss out on backdoor and Trojan detection.


Product Details


Installation: 4/5
Management: 5/5
Features: 4/5
Performance: 4/5
Value: 4/5
Overall: 4/5


Price From £5,000
Contact Cisco 020 8884 1000
www.cisco.com

Tuesday, October 19, 2010

Cisco Security Certificates Mechanism And Its Aspects

Security is always been the major concern for most of the people and there were numerous researches on improving the security. Cryptography has been a major area of research for most of the scientists. Network security is an indispensable part. Customers need to trust the network in order to use it. Thus the users of the network must be well guarded with privacy and security. Confidentiality and integrity must be maintained in order to make people use a network. Cisco security certificates mechanism and its aspects certificates deals with security aspects of a network. In order to authenticate network devices digital certificates are greatly used and they play a major role in authenticating users in a network and one can use it between the network nodes to negotiate IPSec sessions. There are three different ways in which a Cisco device recognizes itself in the network.



Best Cisco CCNA Training, Cisco CCNA Certification and more at certkingdom.com




The first one is the preshared keys, where two or more devices have same shared secret key and this is used by the peers for authentication. They compute a data and send it in order to authenticate themselves.

The receiver is expected to create the same hash and this does not depend on the preshared key. It is based on the concept of using the same secret in order to build trust. This method looks very similar to olden ways of communication and it is not very scalable.

The other popular method include self-signed certificate where a device is used for this purpose. It generates own certificate and takes ownership of it and signs it to be valid. One has to use this certificate in a limited manner. A very good example which illustrates the usage of this certificate is SSH. One can also find HTTPS access to be a good example and what it requires is all a username and a password. This is the primary requirement in order to establish a connection. One must be aware of the reloading of the persistent self-signed certificates which has the ability to survive reloads. It has the ability to be store in non-volatile RAM. This factor makes it to be persistent. SSl VPN is an excellent example for persistent SSI which has got a nonvolatile RAM. Another popular certificate is the certificate authority in which a third party is used for the validation process. He is used to authenticate the parties that are trying to communicate. Each party is given with a public and a private key.

The public key is employed for the encryption process and the private key is used with the decryption process. Since they are using the certificates, which were generated from the same source they are given assurance of the identities. In order to obtain the digital certificate one can use the ASA device. This is used to obtain the certificate from the third party.

One has to undergo an enrollment process and this can either be a manual or an automatic enrollment process. This method and the digital certificate is based on third party product and the certificate service is vendor based. One has to contact the vendor to obtain more information on this. One or more pre-shared keys are used with Cisco Adaptive security or third parties are involved in providing digital certificates which are used in the authentication of IPSec. Self-signed digital certificates can also be produced which are used with SSH, HTTPS.

The Cisco Adaptive Security Device Manager also uses this for its connections to the device. One can refer the document in order to understand the procedures for obtaining a digital certificate. This document does not include the procedure for the method of enrollment. One can find the use of ASDM and also the final command-line interface in the document.

One can refer various examples in order to get better enlightenment about the things in the Cisco IOS platform. A popular example includes the IOS certificate enrollment. One can also refer to related examples in order to understand about VPN 3000 series.

One must make sure the following rules are satisfied before proceeding to configuration.

Configure your window server.

Then make sure your server support Cisco axa pix version 7. 0

If required install extra dll files, in order to run the Cisco axa in window server.

Try to get the add-on dll as exe extension. These help you to add your Cisco application easily with the window server.

Make sure the date and time zone is configured properly in the window server.

Modules involved

Cisco asa with recent version should be used.

Cisco adaptive manager version should be minimum 5. 0

Window server should contain its certificate to ensure ability to run the program properly.

Added modules – This configuration also used in Cisco pix series also.

Step by step procedure to configure Asdm.

Click on Asdm application panel to choose configuration button.

Try to choose device manager from driver menu.

Enter the domain and the host name properly.

Then after configuration, click the save button.

Configure asa with proper time and date, and make sure the time setting is correct and matches with their time zones. To do the above configuration login in to ntp server.

Click the application panel, choose clock under device administration.

You can now able to see the calendar, choose the correct date and time in the calendar. Click the save button and close the window.

Now let us see how to configure the asa.

In the application panel, choose key pair under the certificate option.

Click add button, you get a pop up that asks you to fill the key name and size of key name.

Click generate key now and close the window.

Let us see the steps to add the network under trust worthy option in server.

Click on application panel and click add.

Here click the edit trustworthy configuration.

Fill the available key pair and give the related Microsoft URL address for the key used in server.

Let us see the steps to configure control retrieval methods.

Make sure you uncheck the directory access protocol.

Enable the simple http protocol by just putting check mark in check box.

Click save button and close it.

Friday, October 15, 2010

CompTIA IT Study Around The UK – News

In today’s high speed society, support workers who are able to solve problems with computers and networks, along with giving regular solutions to users, are essential in all areas of the business environment. Our country’s need for better qualified personnel is enhanced, as human beings become ever more dependent on computers in today’s environment.



Best Cisco CCNA Training, Cisco CCNA Certification and more at certkingdom.com



Watch out that all certifications you’re studying for are commercially relevant and are bang up to date. Training companies own certificates are not normally useful in gaining employment. If your certification doesn’t come from a company like Microsoft, CompTIA, Adobe or Cisco, then chances are it will have been a waste of time – as it’ll be an unknown commodity.

Review the points below and pay great regard to them if you believe that over-used sales technique about ‘guaranteeing’ exams sounds like a benefit to the student:

You’re paying for it somehow. You can be assured it’s not a freebie – they’ve simply charged more for the whole training package. If you want to qualify first ‘go’, then the most successful route is to avoid exam guarantees and pay when entering exams, give it the priority it deserves and apply yourself as required.

Isn’t it outrageous to have to pay the training college in advance for examinations? Go for the best offer at the time, instead of paying any mark-up – and take it closer to home – instead of miles away at the college’s beck and call. A lot of extra profit is made by many companies that incorporate exam fees into the cost of the course. For quite legitimate reasons, a number of students don’t get to do their exams but no refunds are given. Surprising as it sounds, there are training companies who actually bank on it – and that’s how they increase their profits. In addition to this, ‘Exam Guarantees’ often aren’t worth the paper they’re written on. Most companies won’t pay for you to re-take until you’ve completely satisfied them that you’re ready this time.

Spending hundreds or even thousands extra on an ‘Exam Guarantee’ is foolish – when study, commitment and preparing with good quality mock and practice exams is what will really see you through.

Commercially accredited qualifications are now, without a doubt, already replacing the more academic tracks into IT – so why is this? With 3 and 4 year academic degree costs becoming a tall order for many, and the industry’s increasing awareness that key company training is often far more commercially relevant, there has been a great increase in CISCO, Adobe, Microsoft and CompTIA accredited training programmes that create knowledgeable employees at a fraction of the cost and time involved. University courses, for example, clog up the training with vast amounts of background study – and a syllabus that’s too generalised. Students are then prevented from getting enough core and in-depth understanding on a specific area.

It’s a bit like the TV advert: ‘It does what it says on the tin’. All an employer has to do is know what they need doing, and then advertise for someone with the specific certification. Then they know that anyone who applies can do the necessary work.

Potential trainees looking to build an Information Technology career usually have no idea of what route is best, or even what market to achieve their certification in. Consequently, if you’ve got no background in the IT sector, how are you equipped to know what a particular IT employee actually does day-to-day? Let alone decide on what accreditation path is the most likely for ultimate success. To work through this, there should be a discussion of a number of definitive areas:

* Your personality type as well as your interests – what kind of working tasks you like and dislike.

* Is your focus to obtain training because of a specific motive – i.e. are you pushing to work based at home (being your own boss?)?

* Is the money you make further up on your priority-list than some other areas.

* Because there are so many ways to train in the IT industry – it’s wise to pick up some key facts on what differentiates them.

* Having a proper look at how much time and effort that you’re going to put into it.

At the end of the day, the most intelligent way of covering these is from a long chat with someone that understands the market well enough to give you the information required.

Thursday, September 2, 2010

Windows 8 is Enough? Microsoft OS Family Gets Confusing

Windows 8 is Enough? Microsoft OS Family Gets Confusing
Windows Phone 7: A major rebranding of the Microsoft phone operating system. Quite simply, the weight of Microsoft's mobile world is on Windows Phone 7, as Microsoft has fallen dangerously behind in the mobile race compared to Apple and RIM, with Android phones now also gaining steam. Windows Mobile 6.x phones will not be upgradeable to Windows Phone 7 because of hardware requirements. The OS is scheduled to ship for the 2010 holiday season.

Best Cisco CCNA Training, Cisco CCNA Certification and more at certkingdom.com


Windows Embedded Handheld: This is the newest member of Microsoft's mobile OS family and is built on Windows Mobile 6.5 technology (which was built on the Windows CE kernel, now known as Windows Embedded Compact. Confused yet?). This OS will be used on what Microsoft is calling "enterprise handheld mobile devices": durable smartphones and PDAs used by service technicians, field workers and healthcare reps who need custom line-of-business apps such as bar-code scanning and RFID reading. Windows Embedded Handheld will ship by the end of the year and then, in the second half of 2011, a new version based on the Windows Phone 7 kernel, aka Windows Embedded Compact 7, will be released.

Windows Embedded Standard 7: This is Microsoft's operating system for OEMs that want to include Windows 7 features like Aero, Windows Touch, Silverlight 2 and BitLocker in kiosks, point-of-sale terminals, televisions and set top boxes. It is shipping now.

Windows Embedded Compact 7: This is the next generation of Microsoft's Windows Embedded CE, the platform on which Microsoft builds its phone and mobile operating systems. The upcoming Windows Phone 7 is based on Windows Embedded Compact 7 core. On its own, Windows Embedded Compact 7 will be pitched to device makers whose products don't need or are not powerful enough for the full version of Windows 7, such as slates, portable media players and e-readers. OEMs can select from a menu of Windows Embedded Compact 7 features to get just what they need for their devices. The OS runs on either x86 or ARM-based chips and is scheduled to ship in the fourth quarter of this year.

Shane O'Neill is a senior writer at CIO.com. Follow him on Twitter at twitter.com/smoneill. Follow everything from CIO.com on Twitter at twitter.com/CIOonline.

Read more about operating systems in CIO's Operating Systems Drilldown.