Monday, August 8, 2011

French Security Firm Hacks Chrome

News

French Security Firm Hacks Chrome

Google Chrome has survived hacker contests for more than two years. Now a security firm claims it's found a zero-day exploit of Chrome running on Windows.


Google offered $20,000 to any programmer, who could find a vulnerability in its Chrome Web browser in February. Chrome survived that contest without being hacked.

After two years of escaping hackers' exploits, Chrome's luck may be running out. This week French security firm Vupen claimed that it discovered a zero-day exploit of Chrome running on Windows.

Vupen used its "most sophisticated codes" yet to successfully hack Google Chrome, as described in a video posted to YouTube today. The exploit enables a user to bypass all security features, including ASLR, DEP and the sandbox, in all Windows versions.


The attack on Google Chrome "is silent (no crash after executing the payload)," according to the security company. Furthermore, the zero-day exploit is tapped using "undisclosed vulnerabilities discovered by Vupen and it works on all Windows systems (32-bit and x64)."

More bad news for Google Chrome (along with Mozilla Firefox and Apple Safari) comes from Context Information Security. The security firm found a handful of issues associated with WebGL, a new Web standard for displaying 3D graphics. All three browsers use the WebGL standard, which can permit malware to be loaded in a browser.

"These issues can allow an attacker to provide malicious code via a web browser which allows attacks on the GPU and graphics drivers," according to the company's findings described on its Web site. "These attacks on the GPU via WebGL can render the entire machine unusable."

WebGL has this vulnerability because it uniquely communicates directly with system display drivers. The problem is that "the current hardware and graphics pipeline implementations are not designed to be pre-emptable or maintain security boundaries," according to Context.

Google Chrome notably has avoided hacker exploits up to this point. Google even offered $20,000 to those who could find a vulnerability within its browser during the February Pwn2Own hacker contest. Chrome escaped without being hacked at that time, as with the previous two years.

Due to the damage both these exploits can cause, the security firms responsible for the discoveries will not publicly disclose how to take advantage of them.

Sunday, August 7, 2011

Microsoft Drops Fees for Data Transfers to the Cloud

News

Microsoft Drops Fees for Data Transfers to the Cloud
Starting July 1, Microsoft will offer free inbound data transfers to its Windows Azure cloud computing platform.

The cut in pricing,announced this week, is available to all Windows Azure customers, according to the company.


Users of Windows Azure still get charged for outbound data transfers, which are region specific. Outbound data transfers are priced at $0.15 per GB in North America and Europe, as well as $0.20 per GB in the Asia Pacific region.

The pricing structure for Windows Azure remains rather complex ever since its introduction in July 2009. Essentially, organizations using Windows Azure pay for the compute time, data storage and data access, plus the bandwidth of the data transferred in and out of the cloud. The various cloud computing phases get priced at specific rates, usually per GB. There's also a monthly fee rolled into the overall cost if an organization uses SQL Azure.

Microsoft offers different monthly plans and discounts, as well as pay-as-you-go plans. To get an idea of the pricing complexity, see Microsoft's "Windows Azure Platform Offer Comparison Table" here.

Microsoft has attempted to make the process of calculating Windows Azure costs a little easier by introducing a Windows Azure Pricing Calculator, which apparently was first released in May. Users of the calculator will get a warning before using it that the calculator's results don't imply "a commitment on the part of Microsoft." Rob Sanfilippo, an analyst with the Directions on Microsoft consultancy, described the calculator as "a starting point."

"The estimation tools are getting better, but organizations should be wary of usage when first deploying cloud-based applications to determine whether there are unexpected resources required," Sanfilippo stated via e-mail. "Variables such as the number of users, types of usage, length of deployment, and development architecture can affect costs in unexpected ways if they are not carefully considered and tested."

Microsoft offers a free 90-day "extra small" trial of Windows Azure, which is available until Sept. 30, 2011.

In other Windows Azure news, Microsoft this week announced the release of the June Community Technology Preview (CTP) of Windows Azure AppFabric. AppFabric is a middleware platform used to develop, deploy and manage Windows Azure cloud-based applications, according to Microsoft's description. The new CTP contains developer tools for Visual Studio, an application manager program and .NET Framework extensions, among other enhancements.

Microsoft provides a demo of some of the new CTP's features in a Channel 9 video here.

Saturday, August 6, 2011

Microsoft's May Security Patch Is Light After Massive Load in April

News

Microsoft's May Security Patch Is Light After Massive Load in April
Microsoft's security update, which is expected on Tuesday, May 10, is relatively light compared to last month's massive patch load.

The one "critical" item will address remote code execution vulnerabilities in Windows Server 2003 and 2008. The important item will be designed to plug an RCE security concern with PowerPoint in Microsoft Office. Office XP, Office 2003 and 2007, and Office 2004 and 2008 are among the affected versions.

"While the light patch load for May will be disruptive, it isn't out of the ordinary. What we do need to worry about is that in light of recent mega-breaches, we are obviously not getting it right when it comes to protecting ourselves," said Paul Henry, security and forensic analyst at Lumension. "People need to reevaluate their security infrastructure and perhaps even their priorities."


IT pros could take advantage of the light load this month by checking out this Microsoft Knowledge Base article. It describes nonsecurity patching being delivered through Microsoft's client update services and Windows Server Update Services.

Friday, August 5, 2011

Microsoft's Nadella Talks about Azure, Office 365

News

Microsoft's Nadella Talks about Azure, Office 365
The new head of the Microsoft Server and Tools Business, Satya Nadella, took the stage today at the GigaOM Structure event to talk about Windows Azure and cloud computing adoption. Nadella talked publicly about the company's strategy for the first time since replacing longtime Microsoft executive Bob Muglia in February.

The live Q&A, which lasted about 15 minutes, focused on Microsoft's business model for Azure and software as a service for products such as Office 365 (now in beta) that will get a "preview" rollout on Thursday. General availability of Office 365 is planned for June 28.

Nadella noted generally that the IT industry is in the midst of a "sea change" from the client-server world to a connected world of mobile devices and connected services. It's early in the process, but the operating system on the back end now no longer focuses on a single machine. Instead, the focus is on a datacenter with 250,000 machines and a million cores. Mean time to failure is no longer the approach to build for since the guiding principle has shifted to building for mean time to recovery. The OS has to be resilient, he added.


Nadella was asked about any stumbling blocks that might exist in businesses moving to widespread cloud adoption. He cited reliability/availability, security and compliance as the top three concerns, but those concerns aren't universal since organizations use mixed environments, such as public clouds, private clouds and a hybrid approach. Next, Nadella was asked pointedly whether security might be the largest concern for organizations considering cloud services.

"It's really the soft core vs. the hard shell [traditional approach to security], which is as much of an issue wherever you are -- it can be in the enterprise, it can be in the hybrid, or it can be in the public cloud," Nadella said. "So I would claim that it all comes down to having a lot of compliance that enterprises are putting in place or the public cloud folks are putting in place. And then having great encryption technology for anything that's moving over the wire. The extreme management is a big issue because that's sort of the thing that can easily be compromised. So I think security will remain a big topic for the industry at large, but it's not just primarily a cloud issue. It's an issue today for anyone with any kind of network."

The cloud is being used in a hybrid manner by businesses to support Web site transactions, while still calling back home for things like identity, data and synchronization, Nadella said. He cited the example of Ticketmaster in New Zealand, which used Windows Azure to spin up databases for some of the more popular ticketed events.

In terms of Microsoft's SaaS offerings (both its Business Productivity Online Services and Office 365), Nadella said that "over 50 percent of the Fortune 500 businesses that have used us, are now using our online offerings." He added that "tens of thousands of customers are playing with [Windows] Azure."

Nadella was asked whether the cloud represents an opportunity for Microsoft, or is it more of a threat. He said that Microsoft has always sought out the low-price, high-volume market, so that the cloud is structurally beneficial for the company and not a threat. He saw some overlap with the various cloud providers, as with Amazon Web Services, which is a Microsoft partner. To the extent that people might use multiple clouds, that would be the kind of case where Microsoft's approach would be to form partnerships, he explained.

The commoditization that may occur with cloud computing, with its value proposition of reducing costs for enterprises, will not necessarily lower Microsoft's revenues, Nadella contended. He expects cloud computing to increase the appetite of organizations for the consumption of data.

Nadella's talk was just a small part of the GigaOM Structure event. A live stream of the event can be accessed here.

Thursday, August 4, 2011

Microsoft Acquires ERM Partner Prodiance

News

Microsoft Acquires ERM Partner Prodiance

On Monday Microsoft announced it had acquired Prodiance Corp., a Microsoft Certified Partner that specializes in enterprise risk management software, which integrates with Office and SharePoint.


On Monday Microsoft announced it had acquired Prodiance Corp., a Microsoft Certified Partner that specializes in enterprise risk management software, which integrates with Office and SharePoint.

The company's Enterprise Risk Manager product line works with Excel. The ERM solutions are designed to help organizations with compliance issues, inventory, discovery, risk analysis, management and remediation.

Under the terms of the deal, Prodiance remains in Pleasanton, Calif. and becomes a wholly owned subsidiary of Microsoft. Microsoft is currently working with Prodiance management "to bring a number of Prodiance employees to Microsoft," according to Microsoft's FAQ. The companies aren't disclosing the financial details.


Microsoft intends to integrate some of Prodiance's technologies into future Microsoft Office and SharePoint versions, according to Microsoft's announcement. The integration" will add "increased security and control over critical business information in spreadsheets." It will enable auditing and policy enforcement via "continuous monitoring of documents." It's also expected to enable "automated risk assessment."

Microsoft plans to disclose further details about its product integration at a future date. Existing Prodiance customers, as of June 6, can buy more Prodiance licenses. In addition, Prodiance support policies for current customers will continue through their expiration periods. Customers wanting to purchase Prodiance solutions today should wait for Microsoft to disclose pricing and licensing details to be offered with the Office product line at a later unspecified date, according to the FAQ.

A "Microsoft Pathways" page here lists additional transition details associated with the acquisition.

Microsoft's 'License Mobility' Extends to Amazon Cloud

News

Microsoft's 'License Mobility' Extends to Amazon Cloud

Microsoft launched its License Mobility with Software Assurance program this month, enabling companies to move on-premise application servers to public cloud hosting services, such as Amazon Web Services, without incurring additional software licensing costs.


Microsoft's License Mobility with Software Assurance (SA) program, which started on July 1, can be used to move on-premise Microsoft application servers to Amazon Web Services, according to Amazon.

License Mobility enables organizations with volume licensing and SA agreements, flexibility on how to use Microsoft application servers without incurring additional licensing fees. Microsoft announced the License Mobility with SA program in March.

In many cases, organizations can transfer application server licenses into a hosting company's public cloud, including leveraging Amazon's infrastructure-as-a-service offerings to run applications as services, without incurring additional licensing costs.


Microsoft's license mobility with SA program applies to select application servers. It doesn't include Windows licensing. Organizations paying to use a public cloud, such as Amazon Web Services, typically get access to Windows Server through the Service Provider Licensing Agreement (SPLA) that the service provider signed with Microsoft. In addition, Windows is licensed per device, which is another reason why an organization's on-premises Windows licenses aren't transferrable to public cloud infrastructures.

Licenses for the following Microsoft application server products are eligible for Microsoft's mobility program, provided that they are covered by Microsoft's SA licensing option: Microsoft Exchange Server, Microsoft Dynamics CRM, Microsoft Lync Server, Microsoft SharePoint Server, Microsoft SQL Server (Standard and Enterprise Editions) and Microsoft System Center.

Amazon claimed in its announcement that companies with volume licensing and SA agreements in place have been upgrading to the cloud using Microsoft's mobility licensing option. For instance, they may move from using SharePoint 2007 on premises to using SharePoint 2010 on the AWS cloud.

Amazon lays out the eligibility requirements to use Microsoft's mobility licensing option on this page. The license mobility program is described by Microsoft here.

An important caveat is that SA agreements also have to be in place with Microsoft for the Client Access Licenses, or CALs, used to access the application servers.

Microsoft had announced back in March that the licensing mobility program would apply to service providers with SPLA agreements. Consequently, the program is opened up to AWS or any other authorized public cloud hosting company or value-added reseller that may want to participate.

U.S. Regulators Approve Microsoft Skype Acquisition

News

U.S. Regulators Approve Microsoft Skype Acquisition
The Federal Trade Commission indicated on Friday that the U.S. Department of Justice has cleared Microsoft's bid to buy Skype in a deal estimated at $8.5 billion.

Luxembourg-based Skype provides IP-based voice and video communications services over the Internet. In order to proceed, the acquisition still requires international regulatory approvals.

Under the terms of the deal announced on May 10, Microsoft plans to run Skype as a division of Microsoft, headed by current Skype CEO Tony Bates. Skype's technologies may be rolled into certain Microsoft products, such as Outlook, Xbox, Kinect, Messenger, Hotmail and Lync, according to comments made last month by Microsoft CEO Steve Ballmer.


Skype has claimed it had "an average of 145 million connected users per month" in the fourth quarter of last year. Skype's ownership is led by Menlo Park, Calif.-based Silver Lake investment partners. Other owners include eBay Inc., Joltid Ltd. and Skype's founders, Niklas Zennström and Janus Friis, the Canada Pension Plan Investment Board and Andreessen Horowitz, according to Skype's description.

Skype's management terminated the employment of about eight executives before the merger, as noted by the independent Skype Journal blog here. The reasons for the job cuts aren't clear, but the Journal speculated that Tony Bates wants to hand pick the team or that Microsoft has its own team in place.

A Bloomberg article posits another possibility for the executive dismissals, with a source speculating that the cuts will lower Skype's stock option price should someone want to buy them. Silver Lake floated a list of executives to cut, according to the Bloomberg article. The investment company may hold about 70 percent of Skype, which is what it purchased from EBay in 2009.

One of the terminated Skype execs was David Gurle, who formerly served as vice president of the company. Previous to joining Skype, Gurle had founded Microsoft's Real Time Communications business group, according to a Skype bio.