Thursday, 31 October 2013

Mavericks rushes onto Macs as uptake easily beats predecessor to 10% mark

Computerworld - Five days after its release, Apple's new OS X Mavericks had accumulated more usage share than the predecessor Mountain Lion did in five weeks, an ad network claimed today.

Chitika said 11.8% of all Macs accessing clients' ads from the U.S. and Canada were running Mavericks five days after its launch.

In 2012, OS X Mountain Lion needed five weeks to collect a 10.3% share of all North American Macs.

Other Web measurement firms have not corroborated Chitika's data. U.S.-based Net Applications, which breaks out desktop operating systems by versions, publicly discloses only monthly statistics, not daily numbers. Net Applications will issue its October data on Friday.

But last year, just days after Chitika portrayed Mountain Lion's share at 10%, Net Applications said its data put the OS at 20%, hinting that Chitika's recent figure may be underestimating Mavericks' uptake as well.

Unlike previous OS X upgrades, Mavericks is free to all eligible Mac owners, which included those running Mountain Lion, 2011's Lion and 2009's Snow Leopard on machines up to seven years old.

Yesterday, Apple's chief financial officer, Peter Oppenheimer, confirmed that Mavericks will be the first in a line of free operating system upgrades for the Mac. "We're ... making Mavericks and future OS X upgrades ... free to our Mac customers," Oppenheimer said, putting an end to speculation that the Mavericks deal was a one-off (emphasis added).

By freeing Mavericks from a sticker price, Apple hopes that a larger percentage of its customer base will upgrade, reducing OS fragmentation. As in iOS, whose users typically make the newest the default within weeks, the strategy will give OS X developers a bigger target: They can assume most Macs will soon be running Mavericks, and write for that edition to take advantage of its unique features and new APIs (application programming interfaces).

Apple likes to boast about the percentage of iOS users who have upgraded to the newest edition, and did so again last week at the unveiling of new iPad tablets when CEO Tim Cook said that 64% of all iOS devices were already on iOS 7. Cook dubbed it the "biggest, fastest software upgrade ever."

"It blows away the other guys," Cook then added, not speaking the word "Android" but clearly referring to Google's mobile operating system. "It gives our users the latest software so they can enjoy the greatest features and the best-possible experience."

That makes the silence from Apple about the number of Mavericks downloads especially odd. Last year, it trumpeted the sale of 3 million copies of Mountain Lion -- at $19.99 each -- in four days.

Mac owners with suitable systems can download OS X Mavericks from the Mac App Store.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at Twitter @gkeizer, on Google+ or subscribe to Gregg's RSS feed Keizer RSS. His email address is gkeizer@computerworld.com.

See more by Gregg Keizer on Computerworld.com.

Read more about Mac OS X in Computerworld's Mac OS X Topic Center.

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

MongoDB support firm says intruders may have accessed databases

IDG News Service - MongoHQ, which provides hosting and support for the open-source Mongo database, said attackers may have accessed several of its customers' databases earlier this week.

On Monday, someone accessed an internal support application using a password that had been used for a compromised personal account, wrote Jason McCay, MongoHQ's founder.

The support application contains connection information for customer MongoDB instances, along with lists of databases, email addresses and user credentials hashed with bcrypt, a file encryption tool, McCay wrote. An audit showed that several databases may have been accessed via that support application.

"We believe we have exhausted the scope of this compromise and are directly contacting all affected customers," McCay wrote. "We are continuing to evaluate our audit logs and conducting further investigations with the help of third-party experts."

The company invalidated credentials such as IAM (Identity and Access Management) keys it stored for customers using Amazon Web Services (AWS) for backups. MongoHQ has notified AWS of the accounts that may have been affected, and AWS is offering Premium Support for organizations that need new credentials, McCay wrote.

MongoHQ, which has offices in California and Alabama, provides services to let developers create and manage NoSQL Mongo databases for their applications.

Since the breach, MongoHQ said it has reset the login credentials for its employee accounts, including email, network devices and internal applications. Employee-facing support applications have been disabled until two-factor authentication is enabled, VPN connections to those applications are enforced and employee access permissions are reviewed, McCay wrote.

In the meantime, McCay said MongoHQ is modifying its system to encrypt and decrypt data at the application level, which will mitigate possible damage from the same type of intrusion. It has also hired a security consulting firm to do a penetration test of its application stack, McCay wrote.

"Based on their recommendations, we will be hardening our applications to provide more layers of security," he wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Mozilla releases 10 patches, five critical, for Firefox

IDG News Service - Mozilla released 10 patches for three versions of its Firefox browser on Tuesday, five of which are considered critical and could be used to remotely install malicious code.

The U.S. Computer Emergency Readiness Team warned that the problems "could allow a remote attacker to execute arbitrary code, bypass intended access restrictions, cause a denial-of-service condition or obtain sensitive information."

The Mozilla products affected are Firefox 25, Firefox ESR 24.1, Firefox Extended Support Release (ESR) 17.0.10, Thunderbird 24.1, Thunderbird ESR 17.0.10, and Seamonkey 2.22.

Among the flaws fixed were several memory safety bugs in the browser engine, which is also in Mozilla's Thunderbird email client and Seamonkey, a suite of applications and web development tools.

Those bugs, tagged as update MFSA 2013-93, "showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code," according to Mozilla's advisory.

The other four critical vulnerabilities could cause potentially exploitable crashes, Mozilla said.

One of the vulnerabilities given a "high" risk rating, MFSA 2013-99, could divulge information on a computer's local system. A security researcher, Cody Crews, discovered "a method to append an iframe into an embedded PDF object rendered with the chrome privileged PDF.js."

"This can used to bypass security restrictions to load local or chrome privileged files and objects within the embedded PDF object," Mozilla wrote.

In August, the TOR project warned that a vulnerability in Firefox ESR may have been used to collect information on computers visiting websites configured as TOR hidden services.

TOR, short for The Onion Router, is a system that allows for more anonymous browsing by routing encrypted requests for websites through servers worldwide. The TOR Project distributes a Browser Bundle, which includes Firefox for browsing with TOR.

The vulnerability could have facilitated the execution of remote code, but instead may have been used to collect the hostname and MAC address of Windows computers, it said. The TOR Project typically updates its browser bundle package quickly after Mozilla releases new patches.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Report: NSA breaks into Yahoo, Google data center links

IDG News Service - The U.S. National Security Agency has penetrated the main communication links that connect Yahoo and Google data centers around the world, giving it access to the accounts of hundreds of millions of people including U.S. residents, The Washington Post reported Wednesday.

By tapping the links, the agency is able to collect at will a wide range of content such as metadata -- indicating the recipients of emails and when the messages were sent -- as well as actual content like text, audio and video, according to the report.

The NSA does not store all of the content permanently, but it keeps a lot, the newspaper reported, based on documents provided by former NSA contractor Edward Snowden as well as interviews with what the Post called "knowledgeable" officials.

Through the program, millions of records are sent every day from Yahoo and Google's internal networks to data warehouses at the NSA's headquarters in Fort Meade, Maryland, the report said. In the past 30 days alone, more than 181 million records containing various data had been processed by field collectors, according to the report.

The data links are exploited using a tool called MUSCULAR, which is operated in partnership with the NSA's British counterpart, GCHQ, the Post reported. Together, the NSA and GCHQ can copy entire data flows across fiber-optic cables carrying information between Yahoo and Google data centers, the report said.

The interception points were not disclosed.

In a statement, Google Chief Legal Officer David Drummond said the company does not give any government access to its systems. However, the company has been concerned about the possibility of this kind of snooping and has encrypted more of Google's services and links as a result, he said.

"We are outraged at the lengths to which the government seems to have gone to intercept data from our private fiber networks, and it underscores the need for urgent reform," he said.

The revelation constitutes the latest in a series of high-profile leaks of information about U.S. surveillance programs since the Post and the Guardian newspaper first reported the existence of a program known as Prism in June. That program allows the NSA to access data stored within the servers at major Internet companies like Yahoo, Google, Facebook, Microsoft and others.

Zach Miners covers social networking, search and general technology news for IDG News Service. Follow Zach on Twitter at @zachminers. Zach's e-mail address is zach_miners@idg.com

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Review: Mobile Web dev frameworks face off

Infoworld - The programming world is made up of virtual city-states that tend to keep to themselves. The device driver authors rarely share much code or ideas with the server app creators. The Windows hackers don't talk with the Mac programmers. It's as if some emperor decreed that Java City will always be at war with C-ville.

That reality is changing rapidly as one language, JavaScript, breaks out of its once simple life of popping up alert boxes to tell people that they needed to fill out every form field marked with a red asterisk. This is most apparent in the mobile world where more and more developers are building mobile apps with JavaScript, CSS, and HTML, then bundling them with a thin, native wrapper. Sure, the JavaScript code isn't always as responsive as the pure native code, but it runs on all of the major mobile platforms -- and in your desktop browser. It's the fastest way to create cross-platform apps.

[ The InfoWorld Test Center review: 3 PhoneGap toolkits tame mobile app development | How are your HTML and JavaScript skills? Find out in InfoWorld's JavaScript IQ test and HTML5 IQ test. | Keep up with the latest developer news with InfoWorld's Developer World newsletter. ]

JavaScript is making these inroads because tablets and phones are growing incredibly powerful, at least compared to their anemic predecessors. The fifth generation of the iPad may actually be 70 times faster than the first generation at some tasks. The new tablets and phones have so much horsepower that they don't always need the speed and simplicity of native code. If the workload isn't too heavy, they can do a good job with HTML5. Why not get all of the cross-platform simplicity if it works well enough? (For more information on what happens afterward, see our review of PhoneGap and related tools.)

But smartphone programmers aren't the only ones interested. For many people, the smartphone is their main way for accessing the Internet. A larger and larger percentage of the mail I get comes with a little disclaimer at the bottom asking me to disregard any typos because it was written on an iPhone or an Android phone. (The BlackBerry keyboards never seemed to need this, for some reason.) If regular websites want to follow the crowd, they need to generate pages that look good on the tiny screen. They can't assume that everyone is reading the information on a desktop box. That means the Web designers are interested in many of the same techniques as the mobile app designers.

Reprinted with permission from InfoWorld. Story copyright 2012 InfoWorld Media Group, Inc. All rights reserved.

View the original article here

Samsung takes baby steps in touting Tizen OS to developers

Computerworld - SAN FRANCISCO -- The open source Tizen mobile operating system is one of the most visible examples that Samsung isn't completely dependent on the Android mobile OS.

At the Samsung Developer Conference here this week, Samsung held a single breakout session on developing apps using Tizen. The session was led by two engineers from Intel, which is working jointly with Samsung to create code to enable Tizen to run across multiple hardware platforms, including tablets, smartphones, cars and smart TVs.

Most of Samsung's smartphones and tablets run Android or the company's own Bada OS. In fact, Samsung is by far the largest Android smartphone maker globally, as well as the largest maker of smartphones overall, according to IDC and others.

The company makes Windows Phone smartphones as well, though a Windows Phone session wasn't among the 50 scheduled at the developer conference. Nearly all of the sessions focused on applications or services that work on Android.

Tizen has a modern Internet interface for use on devices, supporting HTML 5 and other Web technologies, so developers can theoretically write applications once to work on many devices. A Samsung roadmap for Tizen rollouts hasn't been announced.

At the Tizen session on Tuesday, two developers in the audience said they had different experiences with their early Tizen development efforts.

Developers at MightyMeeting, a maker of business collaboration applications, have been using Tizen with promising results because of its use of HTML 5 across platforms, said Mighty Meeting CEO Dmitri Tcherevik.

On the other hand, Shivakumar Mathapathi, chief operating officer at Dew Mobility, said his company tried Tizen with Windows Phone devices and found it wasn't very stable on the Microsoft mobile OS. He didn't provide any details.

Tcherevik said that Samsung's interest in Tizen demonstrates that it's "willing to try many different things" even as a large company.

Some attendees at Samsung's first developer conference said they were glad to see Samsung show off its distinctive features with Android at an event other than the Google I/O conference. Here, Samsung could separate itself from other Android smartphone and tablet makers.

A few analysts have said Samsung is going a step further in offering its own developer conference, using it as preludes into Tizen and its own Samsung app store. Further, those analysts say Samsung is clearly trying to show off its own brand of products and software and emphasize that it is not entirely dependent or aligned with Android and Google.

In an interview, Curtis Sasaki, vice president of Samsung's Media Solution Center in the U.S., said that Samsung's separate app store, its developer efforts, its interest in Tizen and other moves are "not about forking Android or any of that stuff ... Android is big enough and continuing to grow. If we can continue to grow that ecosystem, then that's good for everybody."

"Google is a great partner of ours. Our job as a platform provider is to really help developers take advantage of core applications," Sasaki added.

Abe Elias, chief technical officer at Sencha, a Web application developer, praised Samsung for supporting Tizen and HTML 5.

Sencha uses HTML 5 to provide cross-platform applications to many large companies. There are 2 million registered developers using Sencha's tools.

"We're a huge fan of Tizen, and HTML is native in Tizen," Elias said in an interview. One reason application developers should support HTML 5 for making Web apps is to avoid the 30% fee charged by app stores to host a native app, he said.

Elias agreed that Samsung isn't trying to fork Android, but noted that the company has been separating itself from Google with a number of forked apps that ride atop of Android. For example, Google uses the Chrome browser with Android, while Samsung's browser is simply called Internet. Also, while Google has Hangouts, Samsung has Chat-On.

"Samsung's forking apps, not Android," he said.

Matt Hamblen covers mobile and wireless, smartphones and other handhelds, and wireless networking for Computerworld. Follow Matt on Twitter at Twitter@matthamblen, or subscribe to Matt's RSS feed Hamblen RSS. His email address is mhamblen@computerworld.com.

Read more about Operating Systems in Computerworld's Operating Systems Topic Center.

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

Security concerns prompt subpoena for Healthcare.gov data

Computerworld - A U.S. House committee chairman, citing security concerns, today ordered a Healthcare.gov contractor to provide detailed information about its work on the project.

Rep. Darrell Issa, (R-Calif.), chairman of the Committee on Oversight and Government Reform chairman, Tuesday issued a subpoena for Quality Software Services Inc.'s contract with the U.S. Dept. of Health and Human Services (HHS) to work on the Affordable Care Act's (ACA) website.

The subpoena also orders QSSI to disclose how much it has been paid so far for its work on the project for the project, along with details about all Healthcare.gov-related internal communications and that between the company and workers at HHS and the White House.

Issa said he issued the subpoena after QSSI failed to voluntarily hand the information after it was asked for it by the committee last week.

QSSI did not respond to a request for comment on the subpoena.

"It is crucial that you provide information quickly because of the serious concerns about data security related to the lack of testing," Issa said in a letter sent to QSSI and 10 other Healthcare.gov contractors on October 23. "This lack of testing is concerning due to the amount of sensitive consumer information flowing through the data hub and exchanges."

QSSI is responsible for building Healthcare.gov's core Data Hub, which is designed to support ACA health exchanges. The hub is operated by the U.S. Centers for Medicare and Medicaid Services (CMS) and is designed to let healthcare marketplaces quickly verify the eligibility of individuals seeking insurance coverage.

Healthcare.gov's Data Hub doesn't store data, it's designed to connect insurance exchanges with federal databases at various government agencies, including the Social Security Administration, the Internal Revenue Service, the Dept. of Homeland Security and the Dept. of Veterans Affairs.

QSSI also oversees the testing of software code developed by other Healthcare.gov contractors and last week signed a contract to be the general contractor in charge of fixing glitches that have plagued the site since it went live on Oct. 1.

Issa said that QSSI's first-hand knowledge of the design and implementation of the Data Hub could help committee members better understand the decisions that went into building the website.

The subpoena is the latest sign of a growing unease over the security controls in Healthcare.gov. Though the site does not store much personal data, critics fear that it could nonetheless expose users to identity theft and other types of fraud.

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at Twitter@jaivijayan, or subscribe to Jaikumar's RSS feed Vijayan RSS. His email address is jvijayan@computerworld.com.

Read more about Gov't Legislation/Regulation in Computerworld's Gov't Legislation/Regulation Topic Center.

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here