April 30, 2013

Hackers target shared Web hosting servers for mass phishing attacks
In this type of attack, once phishers break into a shared Web hosting server, they update its configuration so that phishing pages are displayed from a particular subdirectory of every website hosted on the server, APWG said. A single shared hosting server can host dozens, hundreds or even thousands of websites at a time, the organization said.


How Big Data Is Playing Recruiter for Specialized Workers
Companies use Gild to mine for new candidates and to assess candidates they are already considering. Gild itself uses the technology, which was how the company, desperate for programming talent and unable to match the salaries offered by bigger tech concerns, found this guy named Jade outside of Los Angeles. Its algorithm had determined that he had the highest programming score in Southern California, a total that almost no one achieves.


Servant leadership: A path to high performance
These leaders were servants in the best sense of the word. They were people-centric, valued service to others and believed they had a duty of stewardship. Nearly all were humble and passionate operators who were deeply involved in the details of the business. Most had long tenures in their organizations. They had not forgotten what it was like to be a line employee.


Three Gaps in Employee Productivity and What They Mean for IT
Fewer than 40% of employees are truly effective in the competencies shown to have the greatest impact on enterprise performance – right at the point where executives and managers consistently express the belief that they need at least 20% higher performance from employees to meet business goals. Where is employee productivity falling short, and what can IT and Infrastructure teams do to counter these figures?


The IT Conversation We Should Be Having
A simple summary of the work suggests that CEOs believe that CIOs are not in sync with the new issues CEOs are facing, CIOs do not understand where the business needs to go, and CIOs do not have a strategy, in terms of opportunities to be pursued or challenges to be addressed in support of the business.


IT Manager: An IT dashboard for the iPad
IT Manager is an app that offers IT managers another option for using an iPad as an administration tool for local network or web services. It’s a subscription-based app with a wide selection of network and web services admin tools. The growth of tablets and mobile apps in IT management means 24/7 operations go on, regardless of whether staff are working in a data center cage, a user’s desk, or responding to an outage after hours.


Infosec 2013: managing risk in the supply chain
For IT departments, securing information in the supply chain is one of the biggest challenges they face today. This is because supply chains are composed of various companies, all of which have their own set of security standards, and organisations struggle to communicate their requirements to all of these different parties. One way to approach the problem is to assess the “risk appetite” of your organisation, according to Mark Pearce, Head of Information Security at the Post Office.


How UpStream uses R for Attribution Analysis
Major retailers like Williams Sonoma use UpStream Software for marketing analytics, including revenue attribution, targeting, and optimization. In this video Tess Nesbitt (senior statistician at UpStream) describes how she uses Revolution R Enterprise and Hadoop to figure out the impact on various marketing channels (for example direct mail, email offers, and catalogs) on consumer retail sales.


A Note for the Boss Who Talks Too Much
Play leadership anthropologist in your own organization and chances are you’ll find a good number of these en-titled characters who are compelled to consume every possible molecule of oxygen and every moment of air-time to share their self-defined pearls of wisdom and precious nuggets of managerial and inspirational gold.


Microsoft Updates Cloud Agreement For HIPAA Rules
Cloud service providers are starting to take notice of the new HIPAA security regulations that define them as "business associates" of HIPAA-covered entities such as healthcare providers and health plans. Microsoft has just announced a revised business associate agreement (BAA) for its cloud services that reflects the new HIPAA Omnibus Rule governing data security.



Quote for the day:

"Experience is a hard teacher because she gives the test first, the lesson afterwards" -- Vernon Sanders Law

April 29, 2013

When It Comes To Big Data Is Less More?
“I think there is a fear and paranoia among companies that … if they don’t keep every little piece of information on a customer, they can’t function,” said Bradlow. “Companies continue to squirrel away data for a rainy day. We’re not saying throw data away meaninglessly, but use what you need for forecasting and get rid of the rest.”


Prepare for Oz privacy reforms now: Attorney-general, privacy commissioner
"If there continues to be under-reporting of data breaches, or we continue to find out about them only through media reports, some would argue that there is strong case to move to a mandatory scheme," Dreyfus said. "Large-scale data breaches continue to occur, and every incident that is reported in the media continues to raise community concerns about the need for a mandatory scheme."


U.S. Lawmakers Plan Sweeping Review of Copyright
"It is my belief that a wide review of our nation's copyright laws and related enforcement mechanisms is timely," said Goodlatte. "I am announcing today that the House Judiciary Committee will hold a comprehensive series of hearings on U.S. copyright law in the months ahead. The goal of these hearings will be to determine whether the laws are still working in the digital age."


IBM's emerging open cloud architecture
IBM has announced that all of its cloud services and software will be based on an open cloud architecture. This will ensure that innovation in cloud computing is not hampered by locking businesses into proprietary islands of questionable and difficult-to-manage offerings. In fact, customers who choose open standards-based cloud computing are on the right course to take advantage of new opportunities. Specifically, they will be able to harness their interconnected data with high-value business analytics across traditional and mobile devices.


Hacking suspect arrested for 'biggest cyberattack in history'
The alleged hacker is accused of launching an attack against anti-spam watchdog group Spamhaus. A 300Gbps distributed denial-of-service sent the non-profit into disarray, taking down the agency's website and forcing Spamhaus to turn to Cloudflare for assistance. According to the cloud services provider, the majority of the attack was traffic sent using a technique called DNS (domain name system) reflection.


Twitter Speaks, Markets Listen, and Fears Rise
Even though Syrian hackers remain the prime suspects, the trading commission is now investigating 28 different futures contracts and specifically examining the five-minute period before and after The A.P.’s Twitter account was hacked. It is looking to see if there were anomalous trades, and investors who benefited from them.


Searching for Smart Data: All-In-One, Automated Big Data Applications
Once software firms like MicroStrategy, BusinessObjects and others allowed business users to generate ad hoc reports that provided insights about sales, operations and more, data warehouse technology was off and running. Second, while software giant SAP may not be the most elegant technology architecture, SAP beat out the competition in the ERP arena because their ERP applications actually solved business problems.


New Version of Software Deployment Tool Adds Self-Service Cloud Pack
The new Deployit Cloud Pack for EC2, vSphere and other clouds, is an add-on that provides a self-service portal for Developers, Testers and QA teams to easily spin up and tear down the on-demand environments they need. Deployit 3.9 then automatically deploys your applications to new environments, accelerating development and testing.


Could You Survive a Cyberattack?
One way companies can prepare is by buying cyberrisk insurance. Though it has been around since the mid-'90s, cyberinsurance has only recently started to work its way into the mainstream and is now offered by companies such as the Hartford Financial Services Group and Travelers.


7 Tips to Speed Time to Innovation
Leveraging a PPM solution and its attendant processes can help product teams get innovative products to market faster by streamlining and automating development, eliminating wishful thinking and brute force in favor of discipline and strategy. So how can Product Development leverage portfolio management as a foundation for innovation and to support time to market requirements?



Quote for the day:

"Leadership involves finding a parade and getting in front of it." -- John Naisbitt

April 28, 2013

SaaS Business Model Competitive Advantage Revisited
Network automation enables the SaaS vendor to service not just one customer, but many customers from a single infrastructure. With each new customer added, the average cost of operating that infrastructure is reduced for all. When you ask “What is SaaS?”, it is easy to get hung up on things like multi-tenancy, virtualization, and so forth. When you ask “Why is SaaS?”, there are no such concerns. What matters is uniform, automated infrastructure and scale.


Enterprise Data Platform Reference Architecture
This article proposes reference architecture for creating a new generation platform for delivering enterprise Data Information to knowledge workers to help improve their productivity and accuracy. It also articulates some high-level design options for implementing the platform.


Risk Enchantment, The Holy Grail of Risk
“I define risk enchantment as the process of delighting people with risk management. The outcome of risk enchantment is voluntary and long-lasting support that is mutually beneficial.”. How powerful a statement is that? And now imagine working for an organisation where the CEO talks about risk management like this! Here are top 10 quotes that resonated with the Enchantment from a risk management perspective.


Pivotal Launched From VMware, EMC Technologies
Pivotal's new services and newly retailored software packages will allow enterprises the ability to replicate the IT operations used by today's "Internet Giants" such as Google, Facebook, and Amazon Web Services, said Paul Maritz, who is the Pivotal CEO and was the CEO of VMware from 2008 until 2012. Maritz spoke in a webcast Wednesday launching the new company.


Big Data vs. Business Intelligence vs. Customer Intelligence
In this video from McKinsey and Company, Shashi Upadhyay explains how Big Data can provide forward-looking insights for businesses, whereas customer intelligence and business intelligence have traditionally focused on past data. By starting with the problem your company is trying to solve (e.g. improve conversion rates, improve cross-sell rates, attract more prospects, etc.), your company will not need to focus on a large BI project. Instead, consider using a Big Data approach and analyzing internal and external data sets.


Three Essential Steps to Big Data Success
If you’re going to start a Big Data project, there are a few foundational steps to success you should know. While there’s a lot of advice about starting or succeeding with Big Data, much of it is actually about data management in general. That’s fine — you’ll need those skills, but since they apply to any data project, they can’t really be called the essential — or, if you prefer, the quintessential — steps specific to Big Data.


Free Response-Time Database Monitoring Tool
IgniteFree takes the real time features of the award winning Confio Ignite 8 software and makes them free for all to use. Why? Confio believes that when more DBAs see how effective they can be with Response Time analysis, it will drive interest in the full enterprise features of Ignite 8.


Enterprise Architecture
An EA model is an aid to avoiding the waste associated with building the wrong systems; or building the right systems in the wrong business environment. It is also an aid to breaking down silos and fostering true collaboration between the business, IT and other stakeholders ... EA is about providing the correct information to strategic planners to allow them to be more effective in what they do.


Meet DSSD, Andy Bechtolsheim’s secret chip startup for big data
The DSSD system sounds like it treats files not as a series of bits but as an object that gets a name. That name is the file’s address and it stays the same for the life of the file. The result is there’s no central index that stands between sending the data to storage and storing it, and people can write to it in parallel and not worry abut overwrites. It is both faster and can scale out.


Develop Financial Applications with F# and QuantLib
QuantLib is an open source library for modeling, trading and risk management of quantitative finance that can be used with F# lanugage. In order to access QuantLib, you have to make use of NQuantLib.dll, which is a .NET component and NQuantLibc.dll, which is a native component.



Quote for the day:

"It is impossible to win the race unless you venture to run, impossible to win the victory unless you dare to battle. " -- Richard M. DeVos

April 27, 2013

APK Clues: Better Gaming Services Coming to Android?
The games service probably has nothing to do with Google Glass; Glass can't run complex apps. The Glass team accidentally shipped the full suite of Google Play Services with their new app, which is not normal. This included a never-before-seen backend for an extensive multiplayer gaming service, with just about every gaming feature you could possibly imagine.


Authentication with iOS and Windows Azure Mobile Services
This article will cover how to connect the Mobile Service we set up there with an iOS client using the Mobile Services SDK for iOS. All of the source code for this iOS app is available here in GitHub. I’m going to cover a few different areas in the app in this post: giving users the choice of how to login, creating and logging in with custom accounts, logging users out and returning to the root view controller, caching user tokens so we won’t have to login each time, and dealing with expired tokens now that we’re caching them.


What do people mean when they say "the PC is dying"?
What is meant by "the death of the PC" is that the relevance of the PC within people's lives is being diluted by compute devices that are not PCs and the ability to use them for activities that are rewarding yet do not require PCs. This has in fact been going on a long time (e.g. SMS), it's just that we've reached a tipping point over the past few years where the whole world seems to be full of smartphones and tablets and everyone is now talking about it.


Islamic group expands targets in bank DDoS attacks
With each new wave of attacks the group has shifted to other targets. The first wave, which lasted about six weeks from mid-September to mid-October, targeted mostly major financial institutions. Targets included Wells Fargo, U.S. Bank, Bank of America, JPMorgan Chase & Co. and PNC Bank. In the second phase, which went for seven weeks from December to late January, the attackers expanded to mid-tier banks and credit unions.


U.S. council warns of threat of cyber attacks, market runs
"Technological failures, natural disasters, and cyberattacks can emanate from anywhere, at any time," the report said. "Preparation and planning to address these potential situations are essential to maintain the strength and resilience of our financial system." The FSOC, a powerful body chaired by Treasury Secretary Jack Lew, voted on Thursday to adopt its annual report, which includes a set of recommendations to other regulatory agencies. The heads of those agencies are members of the council.


Two-factor or not two-factor? That is the security question
As if to underscore the point that mere passwords are passé, the Twitter hack coincided with the release of Verizon's 2013 data breach report, which pointed the finger at single-factor authentication as a primary culprit in security spills. According to the report, 76 percent of network intrusions in 2012 exploited weak or stolen credentials. The case for two-factor authentication would appear to be a slam dunk. But not all security experts praise the solution as a remedy for all security ills.

Is it time to create your own succession plan?
If you’re in a senior leadership role in a large organization, there’s a good chance there is a succession plan for your position in case you get promoted, win the lottery, get hit by a bus, leave for another company or need to be replaced for poor performance. In smart companies, an orderly replacement of high-level, critical positions is considered to be strategically important to the continued success of the company. A failure to proactively plan for succession is the same as failing to safeguard the financial assets of an organization.


The Internet of Things gets a protocol -- it's called MQTT
"One of the big challenges for right now is that there is not a clear open standard" for message communication with embedded systems, said Mike Riegel, an IBM vice president of mobile and application integration middleware. "We know historically that unless you get to an open standard like this, it is not possible to drive the breakthroughs that are needed."


Moves, mistakes prove Steve Jobs era at Apple over, say analysts
"I just don't think Apple is running quite as well as in Jobs' days," said Ezra Gottheil, analyst with Technology Business Research. "Mistakes have been made, like the poor performance of newer OSes on older hardware, Maps, the miss on the iMac, the neglect of the professional market." Cook, in fact, rued the decision to launch the iMac, the firm's hallmark all-in-one desktop, last October even though Apple had no hardware to ship.


Java Security Questions Answered
Most of the products tested (except Windows Server 2012), use Oracle's Java in one form or another, at least for client access and also in some cases within the management interface. With numerous vulnerabilities recently discovered in Java, leading to guidance from Department of Homeland Security and others to disable it entirely, this raised some questions about usability and possibly even security of the devices tested.



Quote for the day:

"Winning becomes easier over time as the cornerstones of confidence become habits" -- Rosabeth Moss Kanter

April 26, 2013

Why You Need an In-Memory Action Plan
You need to change the way you look at IT infrastructure, applications, and the infrastructure that’s running those applications. Truly, with some of these new technologies like in-memory technology, there are no barriers, things that you can’t do. Words like “no, we can’t do it” start to go away. I’m not going to tell you it’s going to be cheap, I’m not going to tell you there’s not going to be bumps in the road as you’re doing it, but things that you really thought were not possible are possible now. Period.


Inside Windows Phone – code samples
What Windows Phone code samples are available to you, and how do you get them? We publish a large number of code samples that cover a solid range of Windows Phone developer scenarios. In this video, we touch on some of the code samples we’ve created to help you design and develop great Windows Phone apps, and where to find them.


Data Breaches: When the Lawyers Get Involved
Data breaches have become big business for many law firms. ... But it's not just a cash-grab by the lawyers — an interesting example was described where companies are starting to loop their attorneys in at the first hint of a data breach. This way, the attorney-client privileges kick in immediately, they can pre-empt a potential influx of lawsuits by just taking a few simple steps


Senate committee limits government electronic surveillance
"Americans are very concerned about unwarranted intrusions into our private lives in cyberspace," said Senator Patrick Leahy, a Vermont Democrat and main sponsor of the bill. "There's no question that if [police] want to go into your house and go through your files and drawers, they're going to need a search warrant. If you've got the same files in the cloud, you ought to have the same sense of privacy."


How Apple's iWatch Will Push Big Data Analytics
These intelligent wrist watches will permit monitoring of an individual's heart rate, calorie intake, activity levels, quality of sleep and more. Now imagine collecting that data on a much bigger scale. Potentially, governments, medical agencies, etc. will be able to use such collective data to gain a better insight into a nation's physical output, eating habits, risk indicators, and worrying trends. The buzz word surrounding this type of data analysis is 'big data' and I predict that it will have a huge impact in the business world.


Storage Where You Need It, When You Need It
As most CIOs understand, the business value of the IT department is only loosely correlated to the infrastructure they manage. The real value is the information contained in the datacenter. And that data is not worth much if the data is not safe and accessible. Therefore the datacenter needs to be architected in a way that stored information is highly available and applications consuming it have efficient and reliable access. How do you do that?


The fight for HTML5: 'Keep DRM out' lobby steps up standards battle
... the specification would encourage the proliferation of closed-source DRM plug-ins that would be required to view media and that each DRM plug-in could impose arbitrary restrictions on the type of hardware and software that could play media. The BBC raised the possibility of a content decryption module working with EME blocking the ability of an OS to forward an online video stream to a third party device in its submission supporting encrypted media extensions earlier this year.


Five Ways to Use ARA to Ease Agile Development Challenges
The challenges created by agile can limit the development method's value, making agile-specific support strategies key in many organizations. Fostering agile development in the enterprise can be much easier when application deployment processes are simplified. Application release automation can make this simplification possible. There are a few key ways that ARA enables better operations, these include:


Lessen Core Banking Risks, use IT controls
It is a pre-requisite for IT managers to possess good banking domain knowledge and be conversant with the features available on the CBS. He should have knowledge of IT audits with Risk assessment techniques to determine whether the information systems are properly protected and controlled and provide value to the organisation. Likewise, an IT manager should also have an understanding of the organisation and its environment, and of factors which can affect the entity, both external and internal.


No more fake names: German court sides with Facebook over pseudonym lawsuit
"The court allowed that the applicability of the strict German data protection law is undermined by clever internal organisation in an IT company... For both users and German companies which have to comply with the German data protection standards, it is difficult to understand why an offer for the German market may ignore these standards," Thilo Weichert, the head of the ULD, said in a statement.



Quote for the day:

"My responsibility is leadership, and the minute I get negative, that is going to have an influence on my team." -- Don Shula