Sunday, July 20, 2008

Microsoft's $60B Year-End Earnings Dogged by Search Costs

Microsoft's fiscal fourth-quarter and 2008 year-end financial results were announced in a Webcast on Thursday. The results fell just under some analysts' predictions, but questions tended to center on the performance of its Online Services Division, which showed high operating expenses.

Those expenses -- operating losses of $488 million for the fourth quarter and $1.23 billion for the year -- represent Microsoft's ongoing efforts to chase after the online advertising space. The company currently trails badly behind Google and Yahoo in search market share and search ad revenue.

Revenues Show Increase
Still, the company seems to have oodles of money to spare. Microsoft's fiscal 4Q revenue result was $15.84 billion, which is up 18 percent when compared with the same quarter's revenue last year. The year-end revenue figure, at $60.42 billion, represents a similar 18 percent increase.


Microsoft pegged its diluted earnings per share for the quarter at $0.46, up 48 percent compared with 4Q 2007. The year-end diluted earnings per share figure was $1.87, up 32 percent from the previous year.

The Yahoo Deal
The Yahoo question was something everyone had ears for, and Chris Liddell, Microsoft's senior vice president and chief financial officer, didn't disappoint. Microsoft is currently pursuing an unsolicited bid to buy Yahoo's search business.

Liddell assured that Microsoft planned "no changes to Yahoo's governance" under the proposed deal -- something that no doubt had spooked Yahoo's management earlier under bungled negotiations with corporate raider Carl Icahn. Yahoo will face a proxy board fight on August 1 from Icahn, and that fact can't have helped the negotiations.

Liddell gave grueling specifics on Microsoft's current bid for Yahoo's search business, although Yahoo apparently spurned such a deal earlier this week.

"Firstly, we are providing significant revenue guarantees," Liddell said of the proposed Yahoo search acquisition. "Microsoft proposed a 10-year minimum revenue guarantee totaling between $19.5 and $26.5 billion dollars. For the first five years, the guarantee is $2.3 billion per year. There afterwards, both Yahoo and Microsoft have the option to extend the agreement for an additional five-year period. If Yahoo unilaterally chooses to extend the agreement, the guarantee would be for $1.6 billion dollars per year after the extension. Conversely, if Microsoft unilaterally chooses to extend the agreement, the guarantee to Yahoo would be $3 billion dollars per year after the extension. These guarantees are not conditional on Yahoo's search queries. Rather, the guarantees are tied to Yahoo's home page performance."

If that wasn't clear enough, Liddell expounded on the proposal.

"Microsoft would pay Yahoo $1 billion for its search assets, provide $2.8 billion dollars of senior debt to Yahoo on favorable terms, and make a significant equity investment in Yahoo through the purchase of $3.9 billion dollars of Yahoo stock at $19.50 per share, reflecting our view of the value of the company as a result of our proposed transaction and the distribution of cash, and the Yahoo Asian investments by Yahoo to its stockholders," Liddell said.

Liddell had also discussed how Yahoo's rejection of Microsoft's various offers over the last six month or so had caused Microsoft to accelerate its "online services organic growth strategy," with investments in search and ad platform technologies.

"We believe that the additional investments -- several hundreds of millions of dollars -- is worth the short-term costs given the opportunity to participate in a market where the opportunity is measured in the tens of billions of dollars," he said.

Quarterly Highlights
Supplementing the hard numbers were a few nuggets of company information delivered by Colleen Healy, Microsoft's general manager for investor relations. She described this fourth-quarter performance as Microsoft's "fastest growing fourth quarter since 1999."

Healy gave an estimated arrival time for SQL Server 2008, which she said is targeted for release on or during the first quarter of fiscal-year 2009.

She also disclosed a figure for Windows Vista licensing, saying that "during the quarter, we surpassed the 180 million mark for Windows Vista licenses sold today."

Healy noted that SharePoint revenue was "up over 30 percent" and that "Dynamics grew 22 percent" during the quarter. Highlights for the Microsoft Business Division included the launch of both Microsoft Dynamics AX 2009 and Dynamics CRM Online products, she said.

For a link to the report showing Microsoft's fiscal fourth-quarter and 2008 financial results, go here.


Google search share climbs
Details Emerge in New Microsoft/Yahoo!

Saturday, July 19, 2008

Live Mesh Preview: It's Wait-List Only

Microsoft quietly opened its Live Mesh preview to more testers on July 15, but by today (July 17), the offer had been narrowed to just waiting-list only.

Live Mesh is Microsoft's new open platform for enabling the broader connectivity of applications across different platforms. Applications can connect to data wherever located via the Internet, across multiple devices. Live Mesh also includes a synchronization capability that will enable users to keep working when offline, and then it will automatically refresh the data when the user comes back online.

The Live Mesh platform, which features pub/sub, collaboration and data storage features, got its big debut before developers in April.


The Live Mesh preview originally was available by invitation only. However, a July 15 Microsoft Forum post said that the preview is now open to anyone with a Windows Live ID.

The offer is for U.S.-based testers of Live Mesh, but there's a workaround for those located outside the United States. The Forum post suggested interested parties change their Windows region and language preference settings to "US-EN" to sign up for the preview.

Microsoft's Chief Architect Ray Ozzie has been shepherding Live Mesh as part of Microsoft's broader "software plus services" vision in which companies will use a combination of both installed solutions and cloud computing.

Microsoft has already entered the cloud-based world by rolling out some of its hosted applications, including Microsoft CRM Online, Exchange Online and SharePoint Online.

At its Worldwide Partner Conference, Microsoft executives told its partner community -- the traditional providers of Microsoft installed solutions -- that Microsoft will deliver its hosted applications directly to businesses in some cases using its own server farms, which Microsoft has been growing in recent months.


Ubuntu 8.04 LTS vs. Windows XP SP3: Application Performance Benchmark
Microsoft Eyes Consumer Subscription Market With Equipt
Vista SP1 ‘Update’ Released for OS Reliability
Valve Announces Steam Cloud

Research in Motion Issues Fix for Blackberry PDF Bug

Research in Motion Ltd., maker of the popular BlackBerry handset, on Friday issued a patch to plug a vulnerability in its BlackBerry Enterprise Server (BES) solution. The vulnerability could allow hackers to enter into a network via a maliciously crafted PDF file.

The hotfix was distributed via a cluster of updates to BES systems. It's designed to remedy a bug in the PDF distiller function of BlackBerry's attachment mechanism, which enables users to open up documents from the mobile device.

The exploit enabled a remote code execution attack if the user opened up corrupt Adobe or other PDF-type files.


Research in Motion's advisory proposes that network administrators working within a Windows enterprise environment update to BES Version 4.1, Service Pack 6 for Microsoft's Exchange Server.

Using the new patch is much safer than relying on workarounds, according to one network security expert reacting to the news. For instance, relying on updating the BlackBerry Unite software -- an application that can be loaded onto the handset to detect and clean potentially infected files -- isn't the most optimal solution.

"It looks like they [Research in Motion] may have solved the problem for now by what they did [on Friday] because it's very tricky to sanitize these files on the client side," said Kevin Gillis, vice president of product management for IPswitch, a network monitoring, file transfer and messaging software firm in Lexington, Mass. "It's much better to do it on the server side so that the carrier-class scanner is more effective in this case."

Gillis added that the bigger issue now for companies will be reacting to the downtime that may have been caused by putting a temporary moratorium on sending PDFs via the handset, as some enterprises may have done while awaiting the patch.

"You have people sending presentations, graphs and charts all the time over these phones and while the problem is serious enough to wipe out the devices' whole memory storage, I think this is a reminder of why disaster recovery solutions and best practices are important too," he said.


‘Important’ Fixes To Come in July Patch Cycle
Most Network Data Sits Untouched
Call of Duty 4 Patch v1.6 Released

Citrix To Enhance Virtualization Interop

Citrix has released details of a new tool that will speed virtual machine interoperability between hypervisors from Microsoft, VMware and its own offering.

"Project Kensho" is the name for a toolset that packages virtual appliances into the Open Virtual Machine Format (OVF), making them easily transportable between Hyper-V from Microsoft, ESX from VMware, and XenServer from Citrix. Citrix said in the press release that a technical preview of the tools will be available in September.

The main benefit of OVF is that it allows virtual appliances -- applications and operating systems together in one package -- to move from one platform to another, helping to avoid vendor lock-in. Citrix, along with VMware, originally developed the OVF specification, with input from a number of industry heavyweights, including Microsoft, IBM, Dell and HP. OVF uses a standards-based XML wrapper containing configuration and installation data for the appliance, allowing any platform using OVF using the standard to run the virtual machine [VM] containing the appliance.


Chris Wolf, a Virtualization Review magazine columnist and Burton Group analyst specializing in virtualization, says Project Kensho is "a good start. The big thing with Kensho is that Citrix and Microsoft ... can package apps with OVF and share [VMs] from one to another. You don't need any additional device driver installation."

The press release highlighted the close relationship between the two companies, and took an oblique shot at VMware, the market leader:

"In addition, because of the open-standard format and special licensing features in OVF, customers can seamlessly move their current virtualized workloads to either XenServer or Hyper-V, enabling them to distribute virtual workloads to the platform of choice while simultaneously ensuring compliance with the underlying licensing requirements for each virtual appliance."

Since VMware has such a large share of the market space, "current virtualized workloads" likely means VMware-created VMs. Citrix and Microsoft go to great lengths to emphasize the interoperability of their virtualization products, and have banded together for some time in an effort to cut into VMware's substantial lead.

Wolf said that Kensho may have an effect down the road, since hypervisors are starting to become commoditized. From an IT administrator's view, he said, "If I change hypervisors, I don't have to change out management tools. I just need something that supports OVF."


Virtual Users And Domains With Postfix, Courier, MySQL And SquirrelMail (Ubuntu)
Greene Out at VMware
Hyper-V Made Available

Friday, July 18, 2008

Cloud Computing To Bring Security App Shift, Report Says

Microsoft's Chief Architect Ray Ozzie dubbed it a "Web-catalyzed services transformation," and some say the sky will be the limit for cloud computing in the enterprise. However, there still will be a strong need for information security -- even in the clouds. A new Gartner Inc. research report, released on Tuesday, predicts growth in the online security application industry segment as companies gravitate toward using hosted applications.

Revenues for hosted security apps are expected to triple over the next five years, from 20 percent of the revenue in 2008 to 60 percent in 2013, according to the report, "Cloud-Based Computing Will Enable New Security Services and Endanger Old Ones."

As companies adopt cloud computing, the security space will be reshaped, according to the research think tank. Gartner defines cloud computing as a system where "massively scalable IT-related capabilities are provided 'as a service' using Internet technologies to multiple external customers."


The "messaging security controls software" segment currently represents the big seller among security software vendors, according to Gartner. These vendors focus on malware and spam detection, e-mail filters and instant messaging code cleaners.

The upcoming shift in the security application segment was not unexpected. IT prognosticators have known for a while that the boxed software model had only so much time. The shift will be good for start-ups and existing security app vendor heavyweights who want to team up with the Microsofts and VMwares of the world.

However, IT pros will face the challenge of maintaining browser-based security under the new cloud computing model.

Gartner and groups such as the Center for Internet Security warned last year that the increased use of cloud-based or virtual distribution services -- i.e., such as Salesforce.com or Google Apps -- will create avenues for attack. Critical business data might be accessed remotely without touching the corporate network or even having to log-in.

Security controls will have to be placed between mobile users and cloud-based services. Moreover, virtualization won't make things easier. Gartner claimed that by early 2009, 60 percent of virtual machines, which include the apps sitting on them, will be less secure than their physical counterparts.

"What virtualization does is it complicates and compounds the threats," said Nancee Melby, a senior product manager in virtualization for Shavlik Technologies. "It may be easier to install a virtual program but it's also easier to roll out a new virtual guest system than it is to go into a room and push a physical server out. There will be a substantial increase in the number of logical operating systems and applications sitting on virtual servers and it's exciting but there is work to do."


IE Is Least-Patched Browser, Report Says
Apple ships massive Mac OS X 10.4 security upgrade

Government, Health Care Web Sites Attacked

A scan of Web servers by Internet security company Finjan Inc. has found more than 1,000 legitimate Web sites that had been compromised by a new wave of attacks in recent weeks.

High percentages of the compromised sites, which serve up malicious code to unsuspecting visitors, belonged to government at 13 percent, and to health care organizations at 12 percent, said Finjan Chief Technology Officer Yuval Ben-Itzhak.

"We started to see it at the end of last month," Ben-Itzhak said. "But most of [the compromised] domains we found in the last two weeks." The compromises were found using Finjan's SecureBrowsing security tool.


The attack toolkit being used is named Asprox, and has been in use for several years, having gained popularity with cybercriminals during 2007.

"This is not groundbreaking," Ben-Itzhak said. The tool uses a well-established SQL-injection attack to compromise the sites. But the sites being targeted appear to indicate a shift in the underground economy that has grown up harvesting sensitive information from online activities.

"For government, we still don't have the reason," Ben-Itzhak said. "We believe the criminals are targeting health care [data] because they can sell it for a higher price."

The black market price for stolen credit card information has declined sharply in the last year, from around $100 per account to $15 or $20 each, he said. "It's supply and demand." Credit-card information can be easy to steal and has been targeted by many criminals. "It explains why they're looking for new types of information that they can sell for a higher [profit] margin."

The Asprox toolkit searches Google for Web pages with an ".asp" file extension. These pages use the Microsoft Active Server Pages server-side scripting environment for creating and serving dynamic Web pages. It was widely used from around 1998 to 2003, when it was largely replaced with Web development tools that provide more security. But there still are many Web sites using it.

"It is not a vulnerability in the Microsoft tool," Ben-Itzhak said. "It is because of the way the pages were designed and not because of the technology."

To protect themselves from the attack, he recommended that enterprises use application firewalls in front of their servers to block the attacks, and that consumers use real-time content inspection tools to protect their browsers. "They cannot assume that legitimate Web sites will remain safe all the time," he added.

Finjan offers a free browser plug-in for content inspection, but Ben-Itzhak said that user uptake for the technology still is slow -- only about 25 percent compared with more than 90 percent for traditional signature-based anti-virus tools.


PC Tools launch iAntiVirus beta
Security Certification Rules Could Shake Up IT Management
Microsoft Advisory Targets SQL Injection Attacks

Embarcadero Releases SQL Optimizer

In its first product release since acquiring Borland's CodeGear business, Embarcadero Technologies Inc. this week released a new tool set designed to help developers optimize SQL code in databases.

The new tool set, called DB Optimizer, represents a new area of focus for San Francisco-based Embarcadero, which believes database administrators are under more pressure by consolidated IT organization to shoulder the responsibilities of database and application development. "We see a lot of our customers are splitting the roles of their database administrators and developers," said Greg Nerpouni, a senior product manager at Embarcadero. "Service level requirements mean databases always have to be up and running and running as fast as they can, so in production if there is a slowdown or spike of some sort, they can react by profiling that database."

On the development side, Nerpouni says a growing number of DBAs are being assigned or associated with application development teams. "As they're developing out their applications, they are responsible for making sure the applications that they are releasing into production are running effectively and are fully optimized," he said.


Nerpouni said the tool helps stop the proliferation of poor performing SQL in the development lifecycle. Teams can react quickly to unexpected database performance issues, using DB Optimizer to hone in on the offensive SQL. Development teams are presented detailed information to help fix the problematic SQL, according to Nerpouni. From the desktop the software will allow a DBA to perform a wait time analysis of SQL statements within a database without any agents being installed in that database.

In addition to wait times, the IDE examines CPU and I/O performance and can optimize SQL problem statements. "Whatever it might be, in real time we will draw a graph that shows the peaks and valleys, where you will be able to see quickly where the most activity is happening," Nerpouni said.

CodeGear Synergy
DB Optimizer is the first product released since Embarcadero acquired development tools vendor CodeGear in May. While the product was under development before the acquisition, IDC Analyst Al Hilwa says CodeGear offers a marketing and distribution boost to the DB Optimizer line.

"One of the things CodeGear has going for it is its channel," Hilwa said. Embarcadero sells direct, primarily in North America, so bringing the international channel reach of Borland and CodeGear promises to expand Embarcadero's overall market presence, he said.

"The question for me is how are these companies going to cross leverage their skills and create synergy. The database and code developers are not exactly the same people, but it's always a plus for them to have similar and congruent tools and integrated tools," Hilwa said. "Now the combined company will try to address that combined need but it's a question of whether they can take the CodeGear brand and extend it to the DBA and take the Embarcadero brand and extend it to developers. It's going to be a TBD, but there is a tremendous value proposition."

The DB Optimizer tool runs against Oracle, IBM DB2, Microsoft SQL Server and Sybase databases, according to the company. It costs $1,500 per seat per database platform.


Sentrigo Offers Help for Database Patching Woes
Apple ships iPhone SDK beta 8