Online libel case stirs up free speech debate

An Illinois politician's attempt to unmask the identity of an e-mail poster who allegedly made disparaging remarks about her teenage son in an online forum is stirring a debate about free speech rights on the Internet. The paper had run a story describing a bitterly contested local election that Stone was running in. The case involves Lisa Stone, Trustee of the Village of Buffalo Grove, Il. According to a story in the Chicago Tribune , someone anonymously posted "deeply disturbing" comments about Stone's 15-year old son earlier this year in a local newspaper.

In response to that story an individual using the name Hipcheck15 posted comments that were critical of Stone. Those comments, in turn, evoked allegedly defamatory statements directed against Stone's son by Hipcheck15, the Tribune story said. The comments apparently prompted Stone's son to go online and post comments in defense of his mother. The paper did not say what exactly Hipcheck15 wrote, but it quoted Stone as describing the comments as being "vile" and "shocking." Stone did not immediately respond to an e-mailed request from Computerworld seeking comment for this story. In response to an order from the court, the paper turned in the IP address for Hipcheck15. Stone then obtained a similar order from the circuit court judge that asked Hipcheck15's Internet service provider, or ISP, to reveal the true identity of the person to whom the IP address was assigned to. As part of an effort to file a defamation lawsuit against Hipcheck15, Stone approached the Cook County Circuit Court and asked it to order the newspaper to turn in the true identity of the poster, the Tribune said.

According to the Tribune, the ISP late turned in the identity of Hipcheck15 to the court last month. Stone apparently has insisted that all she is trying to do is protect her son and other children from being similarly attacked online. A hearing is now scheduled for November 7 to decide whether the judge should provide Stone with Hipcheck15's true identity. She is hoping the case will serve as a deterrent against similar attacks. Individuals who libel or defame others online, anonymously or otherwise, are just as exposed to lawsuits as they are in the physical world and cannot expect First Amendment rights to automatically protect them. "Saying you're a lousy professor is one thing.

Eugene Volokh, professor of law at the University of California at Los Angeles' School of Law, said the case serves as another reminder that online anonymity does not automatically provide immunity against libel charges. But saying you molest 13-year olds is completely different," he said. Judges in other cases have shown a willingness to do just that if, in their opinion, the complaints had merit. Though one might use a pseudonym to conceal their true identity a court can force an ISP to unmask them in such cases, Volokh said. In a similar case earlier this year, a Texas circuit court judge ordered an online news aggregation site to turn over identifying information on 178 people who had anonymously posted allegedly defamatory comments about two individuals involved in a sexual assault case.

William Pieratt Demond, a partner at Connor & Demond PLLC, a law firm in Austin that is representing the couple, today said that the online site has since turned over information that has so far led to three people being identified as tied to the comments. The two individuals, who were acquitted of all charges, had claimed they had been subjected to intense and inarguably defamatory comments in the online forum. Libel lawsuits have been filed against all three, Demond told Computerworld today. Judges have to make the decision whether an online comment reflects just a personal opinion which is protected, or if it crosses the line and becomes defamatory. "Courts have said that because revealing a speaker's identity could end up deterring people from speaking up, we are going to require some showing whether there is a cause," he said. In the Stone case, it is hard to know how much merit her complaint has, Volokh said. Ed Yohnka, spokesman for the American Civil Liberties Union of Illinois, said the case was troubling. "We think anonymous speech on the Internet is really critical and needs to be protected," Yohnka said.

Yohnka warned against a growing tendency by corporations and individuals to use defamation claims as a way to get the courts to force ISPs to unmask anonymous online commentators. "Saying something is defamatory shouldn't be the trigger" for deciding when someone should be unmasked he said. It has traditionally been one way in which people have chosen to express themselves on political and social issues, he said. Corporations and public figures in particular need to show they have a prima facie case before they are allowed to seek the identity of an anonymous poster, Yohnka said.

Windows 7 steals biggest chunk of share from XP

Microsoft's Windows ran to stay in place last month as Window 7's market share gains made up for the largest-ever declines in Windows XP and Vista, data released today by Web metrics firm Net Applications showed. But it was Microsoft's ability to retain its share in the face of record slumps in its older editions that was the news from Net Applications. By Net Applications' numbers, Windows 7's gains were primarily at the expense of Windows XP. For each copy of Vista replaced by Windows 7 during November, more than six copies of XP were swapped for the new OS. Meanwhile, Apple's Mac OS X lost share during November.

Even though Windows XP lost 1.45 percentage points to end November with a 69% share, and Vista fell 0.2 percentage points to 18.6%, Windows kept its total operating system share at 92.5%, the same as in October. For Vista, November marked the second time in three months that the often-maligned operating system lost share. The declines in XP and Vista were both records in Net Applications' tallies, which because of a change in methodology instituted last July go back only two years. That trend, if accurate, means that the 2007 operating system has peaked, and will now, like XP before it, begin a slow, inexorable decline as it is replaced by Windows 7. Give Windows 7 all the credit for holding Microsoft's line. Windows 7 has been on a share roll since it debuted, according to Net Applications.

In the first full month after its Oct. 22 public launch, Microsoft's newest operating system increased its share by 1.8 percentage points, ending November with 4%, more than enough to make up for the losses by XP and Vista. Less than three weeks after its release, Windows 7 had acquired a slice of the OS pie that it took Vista five months to reach. Currently, about three of every four Windows PCs runs XP, while one-in-five runs Vista. Neither XP nor Vista will vanish overnight if Net Applications' data is any indicator. Only about one in every 23 Windows systems is powered by Windows 7. Almost as unusual as Windows remaining in place was the Mac OS X's dip. Most months, Mac OS X gains ground on Microsoft, albeit by small margins: Over the last 12 months, Apple's OS has increased its share by an average of less than 0.1 percentage points.

By Net Applications' estimate, Apple's operating system finished November with 5.1%, a decline of 0.16 percentage points, the largest since February 2009 and only the third negative number this year. Linux, on the other hand, came up a winner last month, returning to the 1% share mark for the first time since July. It then weights share by the estimated size of each country's Internet population. Linux's all-time high in Net Applications' rankings was May 2009, when it nearly reached 1.2%. Net Applications measures operating system usage by tracking the machines that surf to the 40,000 sites it monitors for clients, which results in a pool of about 160 million unique visitors each month. November's operating system data can be found on Net Applications' site.

Verizon updates Droid software; Users hope it fixes echo problem

An over-the-air software update to the Droid smartphone started yesterday, but it wasn't clear whether the 14 enhancements address a voice echo problem that hundreds of users complained about in online forums. The enhancements come from Verizon Wireless, Motorola and Google, which is behind the Android operating system that runs on the Motorola Droid. The much-anticipated update went to a "small percentage of handsets" yesterday and the update, identified as ESD56, will be phased in over the next week or so, a Verizon Wireless spokeswoman confirmed early today via e-mail.

An update to the Droid Eris smartphone from HTC is "planned but a date has not yet been confirmed," the spokeswoman added. However, it remains unclear whether the list of official fixes offers any relief to hundreds of customers who have complained of a voice echo heard by recipients of calls made from Droid phones. The Motorola Droid update is based on Google's release of a software developer kit for Android 2.0.2 on Dec. 6. The most noticeable modifications improve the Droid's camera autofocus capability and the phone's voice reception, the spokeswoman added. At least 300 comments at a Motorola online support forum refer to the subject, " Droid phone sound quality is not great ," and most comments refer to audio echo problems noticed by people whom Droid users are calling. Despite the many online complaints of a similar problem from Droid users, he couldn't get Verizon store officials to listen to him, he said. "Each time I returned to the store, now three times, I have been treated increasingly like an Android from out of space until [a recent] Friday when I threw a nutty in the store and screamed out for attention," he wrote. "The techs were clueless." Davis said his son, an engineer at Cisco Systems Inc., helped him decrease the echo somewhat by adjusting the phone's settings so that when the echo shows up, Davis must fidget with the speaker button to lessen the echo.

One Motorola Droid user, John Davis, said he has enjoyed all aspects of his Droid except for the phone itself. "Almost from day one there has been an annoying echo primarily with the person on the receiving end," he wrote in an e-mail to Computerworld . Davis, a physician, bought his phone the first day it was available at a Verizon store near Boston. But Davis was still awaiting the update, which was rumored to start on Dec. 11, but now appears to have started four days earlier. However, the official update documentation says only that one of the 14 improvements is listed as "audio for incoming calls is improved." A separate improvement says that Bluetooth functions are improved with "background echo ... eliminated" but only in reference to Bluetooth usage. Davis said his son believes the update is designed to address the issue, and so do many on an online forum. The full list also includes improvements to OS stability, battery life and camera auto focus.

Ironically, many reviewers of the Motorola Droid found it has superlative sound quality , so the echo problem could be a function of networks as well as the Droid, many forum users have noted. Davis said he had no significant problems with his camera, but is still eager to have the update for the camera focus. A Motorola support forums manager, identified online only as Matt, called attention to the update yesterday with a link to the separate Motorola forum on sound quality, implying that the improvements could help the echo problem. Verizon has noted that to get the free update, the Droid device needs to have 40% or more power available if it's not connected to an external power source and 20% power available to it if connected to a power source. The Verizon spokeswoman did not answer directly whether the updates fix the echo problem, saying only that descriptions of the audio problem on forums are "subjective," but she offered to provide a fuller explanation later.

Microsoft shows off Bing tool for measuring ad effectiveness

Microsoft on Monday demonstrated a new tool for its Bing search engine that will allow advertisers to measure the effectiveness of their ads with online users. Mehdi pointed out that statistics show that 39 percent of Web users do 65 percent of the online searches, so it would be beneficial for advertisers to see which of those "heavy users" are targeting certain ads, versus which ads are favored by "light users." The tool Microsoft created shows where the interest in a marketing or advertising campaign is specifically coming from, he said. Speaking at the IAB MIXX Conference and Expo 2009 in New York on Monday, Yusuf Mehdi, senior vice president of Microsoft's Online Audience Business group, showed off what he called a "user-level targeting" tool that allows Microsoft to see which search-based ads that appear in the Bing search engine are getting the most traffic and from where. "What we're doing with Bing for vigorous measurement is we're matching the exact ad online with the exact user," he said.

This measuring ability for Bing was demonstrated as part of Mehdi's presentation, in which he discussed how Microsoft is applying lessons it's learned from studying advertising campaigns and creating technology to reflect that learning. You have to pick and focus." Microsoft revamped and rebranded its Live Search engine "Bing" in June, and making it more effective for search advertising is something the company continues to work on, Mehdi said. One of those lessons was what he characterized as "relentless measurement and optimization" to find out what ads are most effective so they can be better targeted to their proper audience. "One of the big things is trying to build a loyal fan base for the product," he said. "You can't just go out and put your message everywhere. It was unclear from Mehdi's presentation whether this technology is available for advertisers using Bing today or whether it's just something Microsoft is using internally. This kind of ability to measure what kinds of online advertising is working with users is becoming essential as more and more business is being done on the Web. A representative from Microsoft's public relations firm, Waggener Edstrom, declined to answer follow-up questions about the technology or his presentation.

In fact, Microsoft competitor Adobe Systems - an executive from which spoke before Mehdi on Monday - last week said it was purchasing Web analytics company Omniture to build measuring technology directly into Adobe's tools for creating online media.

Western Digital launches WD TV Live

Western Digital announced Tuesday the launch of its new WD TV Live HD Media Player. Available now for $149.99, the WD TV Live hopes to transform your television into a home media hub. The WD TV Live is an upgrade over the previous WD TV model, now adding Ethernet connectivity and digital theater sound to its extensive features.

The concept remains the same: you plug the WD TV into a television set and any external hard drive. Western Digital says it designs products with users in mind and has paid particular attention to how user friendly the UI is. The WD TV is designed to take your media files from your external hard drive and play them on your TV. The device supports many different types of audio and video files, such as H.264, MKV, VIDEO_TS folders, and FLAC audio, and can play back HD video in full 1080p resolution. While providing high definition capabilities, it's designed to be easily navigable for the average user. First, it adds Digital Theater Sound (DTS) support (it previously supported Dolby Digital) for surround sound capabilities. Since the introduction of the original WD TV, the Western Digital team has sought consumer input, said Seema Lindskog, a director of marketing for WD. In addition to offering an improved UI with a movie preview screen feature, the WD TV Live has two major advantages over its predecessor.

With the addition of an Ethernet port, the WD TV Live can access popular Web services such as YouTube, Pandora, and Flickr with the click of a button. While some people may see this an oversight, Western Digital seems to be targeting this product for users with large media libraries who would quickly fill up a built-in hard drive. It can also stream content from an external hard drive, a Mac, or a Windows PC. The Ethernet capabilities of the WD TV Live make it easy to centralize your media, though the WD TV Live itself does not have any storage capacity. Also, not including storage in the unit allows the company to keep the price down.

Benioff plays nice to Oracle at OpenWorld

Attendees packed into a presentation by Salesforce.com Chairman and CEO Marc Benioff at Oracle's OpenWorld conference Tuesday, but those hoping the executive would deliver some of his trademark trash talk toward Oracle left the room disappointed. But Benioff made no response to Ellison's jibes on Tuesday, instead referring to the companies' "fantastic relationship" and thanking Oracle for being "magnanimous" enough to let Salesforce.com appear at OpenWorld. Some sort of throwdown seemed possible, even likely, given that during a shareholder meeting last week, Oracle CEO Larry Ellison mocked Salesforce.com's offering as a "little itty-bitty application" that is dependent on Oracle's own technology. Salesforce.com is a sponsor of the show.

Since then, the two executives have repeatedly slammed each other's business model, with Benioff declaring on-premise software a dying model and Ellison famously mocking cloud computing on a number of occasions, even as his own company tests those waters. Ellison was an early investor in Salesforce.com, but left the vendor's board after he and Benioff had a falling out. Their history caused surprise and curiosity among some observers, who questioned why Oracle would allow such a direct rival to tout its products at OpenWorld. And during the shareholder meeting, Ellison said he could provide a long list of customers who once used Salesforce.com but "chucked it out" in favor of Oracle's own on-demand CRM (customer relationship management) software. Indeed, beyond slamming Salesforce.com's technological achievements, Ellison has made it a point during recent earnings conference calls to cite deals it won against the on-demand vendor.

But in the end, Benioff seemed more intent Tuesday on building bridges than burning them. The two companies announced a partnership on Monday for selling Salesforce.com CRM and related services to small and medium-sized businesses. At one point, he was joined onstage by Dell CEO Michael Dell. Salesforce.com and Dell already had close ties, having used each other's products for some time. Dell said its experience running Salesforce.com will give it an edge when working with new customers.

Former DHS cybersecurity chief points finger at Congress

Part of the blame for continued cybersecurity problems in the U.S. government and beyond lies with Congress and its "scattershot" approach to dealing with the issue, a former assistant secretary for cybersecurity at the U.S. Department of Homeland Security said Thursday. Some committees are pushing for more cybersecurity responsibility outside of DHS, while other committees are resisting changes, he said during a press briefing. Congress has often provided aggressive oversight of cybersecurity efforts at DHS and elsewhere, but there are continued turf battles between various congressional committees, and lawmakers introduce multiple pieces of legislation that sometimes conflict with each other, said Gregory Garcia, who served as assistant secretary for cybersecurity and communications at DHS from late 2006 to late 2008. Garcia mentioned eight congressional committees that have responsibility for a portion of cybersecurity policy, and he called on congressional leadership to coordinate cybersecurity efforts. Congressional leaders "need to bring their committees together, sit them around the table ... and make sure everybody understands what is their jurisdiction, what's their responsibility, and what are the policy gaps," Garcia said. "Have a coordinated, leadership-driven process, rather than letting all these committees go off freelancing with their next great idea." If one committee is pressing for the U.S. Department of Justice to have more authority and a second is pressing for DHS to have more authority, "we're not making progress, we're going off scattershot," Garcia added.

There were also significant management problems at DHS, partly because the agency is only six years old, Garcia said, but a large problem was that agency leaders were sensitive about criticism from Congress, and wouldn't let lower level staffers make the decisions they had expertise to make. "Decisions were made at the political level, not at the civil servant level," he said. Garcia's time at DHS was marked by hypercriticism from a Democrat-controlled Congress of the agency, with its leadership appointed by former Republican President George Bush, he said. Some of the congressional criticism of DHS seemed "cynical," added Garcia, now president of Garcia Strategies, a consulting group. The House committee has hosted several hearings focused on cybersecurity in recent years. Representatives of the U.S. House of Representatives Homeland Security Committee didn't immediately respond to a request for a reaction to Garcia's comments.

Garcia's criticism of the cybersecurity policy process came two days after the U.S. Government Accountability Office (GAO) issued a report saying that federal IT systems remain vulnerable to a variety of cyberattacks. Agencies did not consistently authenticate users to prevent unauthorized access to systems; did not encrypt sensitive data; and did not log and monitor security-relevant events, the GAO said. Security audits have "identified significant weaknesses in the security controls on federal information systems, resulting in pervasive vulnerabilities," the GAO report said. "GAO has identified weaknesses in all major categories of information security controls at federal agencies." During 2008, audits found weaknesses at information security controls at 23 of 24 major U.S. agencies, the GAO said. Agencies have failed to fully implement information security programs, the report said. Many large companies should have enough incentives to protect their data, Kessler said. "I'm not sure regulations or fine are necessarily going to compel boards of directors or senior IT executives," he said. "They can lose everything with one vulnerability." However, Congress may be able to create some incentives for medium-sized businesses that don't have the resources to properly address cybersecurity, Kessler added. Asked what Congress can do to help private companies better protect themselves, Garcia and Alan Kessler, president of intrusion protection vendor TippingPoint, questioned whether new regulations would be productive.

Garcia also questioned whether new regulations would be effective, but he warned that they may be coming. Some U.S. industries still don't take cybersecurity seriously enough, he said. "There may be a time when the Congress gets fed up ... and will declare market failure and regulate," he said.

NASA offers $400,000 prize for super space glove

If you can build a high-tech glove that can move easily and operate effectively in the vacuum of space, NASA may have $400,000 for your effort. NetworkWorld Extra: 12 mad science projects that could shake the world NASA said the competition will test gloves from at least two contestants that will measure the gloves' dexterity and strength during operation in a glove box that simulates the vacuum of space. That's the amount of money up for grabs in the 2009 Astronaut Glove Challenge set for Nov. 19 at the Astronaut Hall of Fame in Titusville, Fla.

According to the competition Web site, the challenge will be conducted by Volanz Aerospace in a format that brings all competitors to a single location for a "head to head" competition to determine the winning Team(s). Each team will be required pass a series of minimum performance requirements having to do with the glove's interface with the interface to the test box, flexibility, dexterity and pressurization. The team(s) that earns the highest score will be the winner. Other requirements include: the weight of the outer or thermal micrometeoroid garment (TMG) layer of the glove must not exceed 200 grams; and the TMG must be able to withstand a temperature range from -120 degrees Celsius (-185 F) to +113 degrees Celsius (235 F). Performance tests include range-of-motion and the ability of the operator to push and pull items as well as manipulate them. From the Web site: For this test, conducted in the glove box, the Competitor will insert the full Glove, consisting of the TMG layer, outer glove unpressurized layer, and the unpowered, bladder and bladder-restraint portion of the Glove into the Glove Box. The glove challenge is but one of NASA's Centennial Challenges that offers top dollar rewards for a variety of innovative technologies.

The Competitor will perform 30 minutes of hand exercises (e.g., pinching and gripping), and other manipulation dexterity tests and tasks that will be scored based on performance. For example, NASA recently awarded $1.65 million in prize money to a pair of aerospace companies that successfully simulated landing a spacecraft on the moon and lifting off again. NASA recently held and awarded a $900,000 prize in its Power Beaming and Tether Challenge to develop future solar power satellites and a futuristic project known as the Space Elevator. NASA gave a $1 million first prize to Masten Space Systems and a $500,000 second prize to Armadillo Aerospace for successfully completing the Northrop Grumman Lunar Lander Challenge. Space elevators are in a nutshell stationary tethers rotating with the Earth, held up by a weight at its end, and serving as a track on which electric vehicles called "climbers" can travel up and down carrying about 10 tons of payload, according to The Spaceward Foundation which is working with NASA on these challenges.

Microsoft Windows chief decries standards grandstanding

Los Angeles – Microsoft will be compliant with industry standards in Internet Explorer 9 such as HTML 5, but Steven Sinofsky, president of the Windows and Windows Live division, decried the habit of vendors getting ahead of the process. There is a little bit of a time warp going on." Sinofsky was making reference to Mozilla who is pushing heavily on HTML 5 in development of its Firefox browser. Browser that launched an industry turns 15 "We are not trying to market things that are not there for developers to use yet," said Sinofsky during an interview with Network World. "Whether they are in IE or not, saying you are standards based but then saying you are the most HTML 5 compliant browser does not make sense because the standard is not [complete] yet.

The browser issue is a hot topic given that Microsoft has lost over the past year about 7% market share, according the thecounter.com, as users gave up on IE 7 to go to alternatives such as Firefox and Safari. Sinofsky characterized his stand as responsible engineering. "We understand people's desire for interoperability so HTML 5 is a thing that people talk about a lot but it is not even at the standard recommendation phase yet." Microsoft supports some aspects of the standard that are complete now such as storage and cross-site navigation. Microsoft is hoping IE 8 can attack that trend and have IE 9 squash it. Microsoft, however, is working toward full support on the HTML 5 specification, which was one of three advancements Sinofsky highlighted when he talked about IE 9 during his Wednesday keynote address. But he would not provide any delivery dates for the software.

The other two were improvements on the Acid 3 test of standards compatibility, where Microsoft now scores 32 out of 100 with its latest prototype browser, and GPU-based rendering, which takes advantage of hardware for tasks such as animation or rendering type. "These three things will be in IE 9," he said. In terms of Acid 3, a test from the Web Standards Project that checks how well a browser follows certain parts of Web standards, Sinofsky admitted there is work to do and said that Microsoft is doing it. "We are behind in it and I want to make sure people understand that we get it, we are working and we are showing progress," he said. Microsoft released a set of videos it produced that highlight its standards work. Sinofsky also acknowledged that the SunSpider Java benchmark shows IE performance lacking against the competition and said that disparity would be corrected. Sinofsky said the third important area for IE 9 will be performance, especially as it relates to taking advantage of modern PC hardware.

In terms of animation in a browser, Sinofsky said it can't be done effectively without hardware. "The difference between a PC game today and a PC game from 10 years ago is that the game 10 years ago looked like an animated cartoon, it is like comparing a Pixar film to a Disney film. During his Wednesday demo, Sinofsky showed text rendering being done by a graphics chip using DirectX's Direct2D, and he showed a map animation using GPU-based rendering that improved the frame per second rate from 14 to 60. "The device [the browser] is on matters; hardware acceleration is just one example" he said. "The readability you gain by using a hardware chip rendering text is very significant." Sinofsky said corporate end-users reading lots of text each day from a browser can reduce eye strain and improve their performance just by having improved text rendering. That is all hardware; and having all that show through the browser while still working on standards is incredibly important." Follow John on Twitter.

NASA ready for Mars rocket test flight Tuesday

NASA is set to launch a test flight of its new Ares I-X rocket that is designed to replace the aging space shuttle fleet and eventually spirit humans to Mars . NASA announced today that the test vehicle is slated to take off some time between 8 a.m. and noon tomorrow from Kennedy Space Center's Launch Pad 39B. The space agency noted that Ares I-X rocket is the first non-space shuttle craft to be launched from the Pad 39B since the Apollo program's Saturn rockets were retired more than 25 years ago. "For those of us who've lived with the shuttle and grew up looking at Saturn Vs, it's obviously a little different than what we're used to seeing," said Jon Cowart, one NASA's two Ares I-X deputy mission managers, in a statement. If the 1.8-million-pound, 327-foot-tall rocket doesn't launch on Tuesday, the take-off will be rescheduled for Wednesday, according to NASA. The space agency noted on its Web site that it's looking for tomorrow's flight to gauge the dependability and characteristics of the rocket's hardware, facilities and ground operations. Bad weather could stand in the way of the big test launch, though, as meterologists say that there's only a 40% change of good weather in the four-hour window. With more than 700 sensors on board, Ares I-X is wired to relay ascent data back to engineers on the ground.

NASA reported that the rocket's four first-stage, solid-fuel booster segments come from the space shuttle program. The Ares I-X combines technology from several different operations. A booster segment contains Atlas-V-based avionics, and the rocket's roll control system comes from the Peacekeeper missile. NASA's Ares rockets are expected to return humans to the moon and later take them to Mars. However, the launch abort system, simulated crew and service modules, upper stage, and various connecting structures are original. NASA has been planning on a move to the moon and then on to Mars for several years now.

With budgetary concerns in the forefront, the review is looking at possible alternatives to programs already in the pipeline. The space agency has been working toward setting up a lunar outpost by 2020. However, the schedule, if not the mission itself, has come into some question as President Barack Obama's administration oversees an independent review of NASA 's human space flight activities.

Momentum builds for open content management standard

A proposed standard meant to help content management systems communicate with each other has steady momentum, and an initial version could be finalized early next year. Organizations face difficulties when integrating information from various content repositories, because specialized connectors typically have been required for each system. Content Management Interoperability Services (CMIS) was first announced in September 2008. It outlines a standardized Web services interface for sharing content across multiple CMS (content management system) platforms.

Both customers and vendors stand to gain from CMIS. It should cut the amount of one-off integrations and custom development work end-users currently must do, and in addition, software vendors won't have to build and support a wide range of connectors, said 451 Group analyst Kathleen Reidy via e-mail. The company said Monday it has included support in the 3.2 version of its platform for CMIS 1.0, which is now in a public review period scheduled to end Dec. 22. CMIS' inclusion in Alfresco 3.2 will enable users to get a hands-on look during the review period, the company said. The specification, which is being developed under the auspices of standards body OASIS (Organization for the Advancement of Structured Information Standards), is supported by the content management industry's biggest players, including EMC, Adobe, Microsoft, Open Text, IBM and SAP. Open-source CMS vendor Alfresco is also a backer. CMIS 1.0 is on track to be finalized within the first few months of 2010, according to a recent blog post by Ethan Gur-esh, a Microsoft program manager. But even that percentage is "remarkably high" given that CMIS isn't even a standard yet, CMS Watch analyst Alan-Pelz Sharpe said in a blog post at the time. "CMIS has good momentum and has the right set of vendors backing it," the 451 Group's Reidy said. "It will take a while for the standard, once ratified, to show up in actual, commercially supported, shipping versions of most ECM products though, just due to the release cycles of these products. Despite the high-profile vendors involved, it's not clear how many end-users are aware of CMIS. A study released recently by research firm AIIM said it had "gained traction" among 15 percent of the organizations surveyed.

But it does look like it will happen, as most have stated support and have support for the current spec in developer-only downloads and so forth."

E-voting system lets voters verify their ballots are counted

A new electronic voting system being used today for the first time in a government election in the U.S. will allow voters and elections auditors in Takoma Park, Md. to go online and verify whether votes have been correctly recorded. It uses cryptographic techniques to let both voters and election auditors check whether votes have been cast and counted accurately. The voting system is called Scantegrity and was developed by independent cryptographer David Chaum, along with researchers from the University of Maryland-Baltimore, the George Washington University, MIT, the University of Ottawa and the University of Waterloo.

The Scantegrity technology is being used to augment regular optical-scan voting systems in Takoma Park's city council election. When the bubble is filled, it reveals a three-digit confirmation number already printed on the ballot using an invisible marker. To cast a vote, an individual takes a paper ballot and fills in the optical-scan oval next to the name of the selected candidate using a pen with a special type of ink. That three-digit code is a sort of randomly generated cryptographic marker that's used to associate the voter's choice with the appropriate candidate. If the code is present on the Web site, it means the ballot was counted correctly, he said.

The codes are separately randomized for each oval and for each ballot, ensuring that the codes don't reveal who an individual voted for, Chaum said in an interview with Computerworld . Voters can use that confirmation code to later log into the city's election Web site to confirm that their votes were recorded accurately. Scantegrity also lets election auditors - and even third-party observers - check whether the results were accurately tabulated without revealing how each individual vote was cast, Chaum said. Scantegrity uses cryptographic techniques to first map each code to the associated candidate and then completely conceals the link. Though it is not possible to link an individual ballot to a specific candidate, auditors can verify that the codes do lead to the recorded votes. It then uses a concept known as "zero-knowledge proof" to show auditors that the codes do in fact correspond to the right candidates, said Aleks Essex, a PhD. student in computer science at the University of Ottawa who was involved in the Scantegrity effort.

For example, an individual could use a piece of paper with a hole cut in it to prove to a child that he knows the location of Waldo in a "Where's Waldo" puzzle, Essex said. Zero-knowledge proof is a way to demonstrate the authenticity of a statement without revealing any other details about the statement, said Essex. By placing the hole over Waldo, he shows he knows Waldo's location in the puzzle, but doesn't reveal the exact location to child. The results of today's elections in Takoma Park are being audited by two officials one of whom is from Harvard University. "It is a really powerful thing to have public transparency of the tabulation process and yet preserve ballot secrecy," Chaum said. Scantegrity enables auditors to get the same sort of proof to show that confirmation codes in an election map to the right candidates, without revealing an individual voter's choice, he said.

Because Scantegrity is built on open-source software, it can be used elsewhere to run similar audits against election results using custom tools, he said. But to a large extent, optical-scan voting machines already offer a relatively high degree of verification support. Pamela Smith, President of the Verified Voting Foundation, said that technologies such as Scantegrity do add an additional layer of integrity to the election process. Because such machines save a record of the voter's intent, auditors can go back and verify results if necessary, she said. Maryland is one of the few states that rely on touch-screen voting systems, which are costlier to operate and maintain than optical scan systems, she said. The bigger issue in Maryland is that the state needs to adopt optical-scan systems on a larger scale, she said.

UC Berkeley tightens personal data security with data-masking tool

To better safeguard the personal data of its students, the University of California at Berkeley (UC Berkeley) has adopted a specialized data-masking technique in its application development work that effectively can hide data in plain sight by mixing it up. 10 of the Worst Moments in Network Security History Data such as students' first and last names can be switched around to camouflage the real names, and sensitive information such as student identification numbers also undergoes a gentle jumbling so what appears to the eye is not the true number. Steve McCabe, associate director of information in UC Berkeley's residential and student services program, says the advantage in using the dataguise tool is it significantly reduces security risks around personal, sensitive data. "Student IDs paired with names becomes restricted data here," says McCabe, describing some of the data-privacy rules that the university must follow. It's done with a tool called datamasker from dataguise.

But the challenge has been how to enforce restrictions in a software-development environment where constant work by several developers is ongoing to support UC Berkeley's home-grown Web-based applications for SQL Server, such as the housing and assignment system. Though the actual production database has to be protected through other means, the risks associated with data exposed to developers and testers in the course of their work has been vastly reduced since UC Berkeley started using the tool about half a year ago. McCabe says the data-masking approach, in which the dataguise tool mixes up names, sensitive numbers and other data prior to developers seeing it (dataguise calls it "de-identification"), has worked out well because the data columns maintain the necessary structure but the content is effectively concealed to the naked eye. "We do a lot of application development and handling large volumes of student information, and we wanted a way to restrict that data," McCabe says. "So we randomize the IDs, and first name, last name, date of birth, and so forth." While one main copy of a production database is preserved, with the genuine student information, developers can freely work on copies that have undergone the dataguise data-masking treatment in what McCabe calls a "sanitized version" without concern of a potential data breach. "It maintains the relationship and updates with scrambled data," McCabe says. UC Berkeley, like many universities, has suffered consequential data breaches. In May of this year, UC Berkeley acknowledged a data breach in which it said hackers broke into its health-services databases, compromising health-related information on about 160,000 individuals.

Cloud security service looks for malware

Webroot Tuesday announced it has extended its cloud-based Web security service, adding a way to filter outbound as well as inbound Web traffic, monitoring for threats in order to detect and block malware such as botnets that have infected computers. If the cloud-based Webroot service detects malware such as botnet code calling out to get instructions or otherwise perform an activity, it will block that request, though not all traffic on the user's machine. Five questions to ask before trusting your data to Amazon or other storage cloud provider  "We already have inbound filtering and now we're adding outbound," says Brian Czarny, vice president of solutions marketing at Webroot about the Web Security Service that can now monitor for signs of malware-infected corporate computers trying to "call home" for more instructions, a common practice among criminally run botnets.

The Webroot service would then notify the systems administrator of the security event via e-mail and the Web-based administrative console where reports can be obtained. The service works by having the corporation proxy its Web traffic through Webroot's data centers where a variety of security methods can clean malware and ward off phishing attacks. Czarny says there is no additional charge for the outbound monitoring now available through the Webroot Web Security Service, which also includes some basic URL filtering for productivity purposes. Webroot is also announcing on Tuesday an in-the-cloud e-mail archiving service that lets customers store e-mail to be searched and retrieved whether from on-site corporate mail servers or Google Apps. The pricing for the e-mail archiving is $6 per month per user for unlimited storage and retention; the Web Security Serivce costs $5 per user per month, with discounts based on volume.

Unpatched SMB bug crashes Windows 7, researcher says

A day after Microsoft plugged more than a dozen holes in its software, a security researcher unveiled a new unpatched bug in Windows 7 and Server 2008 R2 that, when exploited, locks up the system, requiring a total shutdown to regain control. Laurent Gaffie posted details of the vulnerabilities, along with proof-of-concept exploit code, to the Full Disclosure security mailing list today, as well as to his personal blog. Microsoft acknowledged that it's investigating the flaw.

The attack code, said Gaffie, crashes the kernel in Windows 7 and its server sibling, Windows Server 2008 R2, triggering an infinite loop. "No BSOD [Blue Screen of Death], you gotta pull the plug," Gaffie said in notes inserted into the exploit code . Gaffie claimed that the exploit, powered by a vulnerability in the new operating systems' implementation of SMB (Server Message Block), could be successfully launched from within a network from an already compromised computer, or used to attack Windows 7 machines via Internet Explorer (IE) by transmitting a rogue SMB packet to the PC. Unlike more serious flaws, the Windows 7 SMB bug cannot be used by attackers to hijack a PC, Gaffie confirmed. "No code execution, but a remote kernel crash," he said in an e-mail today. None of the 15 affected the final version of Windows 7, which was released to retail Oct. 22, or affected Windows Server 2008 R2. Gaffie also said that Microsoft's security team has acknowledged the vulnerability, which he first reported to them last weekend, but was told by the company that it wasn't planning to fix the flaw with a security update, instead perhaps correcting it in the first service packs for Windows 7 and Server 2008 R2. A Microsoft spokesman confirmed that the company is looking into Gaffie's claims. "Microsoft is investigating new public claims of a possible denial-of-service vulnerability in Windows Server Message Block," said the spokesman in an e-mail reply to questions. "Once we re done investigating, we will take appropriate action & [which] may include providing a security update through the monthly release process, an out-of-cycle update or additional guidance to help customers protect themselves." Gaffie's disclosure came just a day after Microsoft issued November's security updates , which patched 15 vulnerabilities in Windows, Windows Server and Office.

Microsoft pushes switchover deal for CRM Online

Microsoft is trying to steal away Salesforce.com and Oracle CRM on Demand customers with a new offer that will provide them with six months' access to its own CRM Online application at no charge if they sign a 12-month contract. That compares to $65 per month per user for Salesforce.com Professional. Microsoft charges US$44 per month per user for CRM Online Professional edition. Oracle CRM on Demand pricing starts at $70 per month per user.

Microsoft will consider expanding access to customers of other CRM products once it sees how well the program is received, Wilson said. Meanwhile, Microsoft's application is comparable from a feature standpoint and "already about 35 percent cheaper" than the competition, said Brad Wilson, general manager of Dynamics CRM. The six-month offer is valid through the end of this year. Six months is about how long it takes a customer to know for sure whether an application is right for their business, said Ray Wang, partner with the analyst firm Altimeter Group. For one thing, a customer and Oracle or Salesforce.com may have a year-to-year deal, which might still be in effect when the six-month trial period expires, Wang said. But potential hurdles lie in the way of a smooth transition over to CRM Online, he added. While contract terms may allow the customer to cancel, they may not get a refund on the year's remaining fees, according to Wang. "Hopefully you'd be [signed up] month-to-month.

Microsoft on Monday also announced price cuts for its Business Productivity Online Suite. It's good to check and see where you are in that process." Overall, however, "users win" in price wars like this, Wang said. Other SaaS (software as a service) vendors, such as NetSuite, have made a steady stream of financial enticements in recent months too, as sales slowed during the global recession. It is also planning to roll out the software worldwide in the second half of 2010, he said. Salesforce.com has also quietly lowered monthly per-user fees for its two lowest-end editions, Contact Manager and Group Edition, to $5 and $25 respectively, down from $9 and $35. Meanwhile, Microsoft is announcing the CRM switch-over deal in conjunction with an update to CRM Online, Wilson said. The service is now available in North America.

No credit card information is required to sign up, although users need to provide an e-mail address. In the new release, Microsoft made signing up for CRM Online "super-simple," he said. They can then start a free trial with either Microsoft's Outlook client or a browser-based interface, Wilson said. A series of help tools provide information on setup and maintenance. Thirty-day trials include sample data so users can begin experimenting with the system. Microsoft has also developed an improved data import wizard.

In addition, mobile access is available at no additional charge for any phone with a HTML 4.0-compliant Web browser. "We specifically tried to engineer [the application] to make it really easy for people who don't have CRM systems," Wilson said.

MySpace replaces all server hard disks with flash drives

Social networking site MySpace.com announced today that it has switched from using hard disk drives in its servers to using PCI Express (PCIe) cards loaded with solid state chips as primary storage for their data center operations. MySpace said the solid state storage uses less than 1% of the power and cooling costs that their previous hard drive-based server infrastructure had and that they were able to remove all of their server racks because the ioDrives are embedded directly into even its smallest servers. "We looked at a number of solid state solutions, using many different kinds of RAID configurations, but we felt that Fusion-io's solution was exactly what we needed to accomplish our goals," Buckingham stated. The PCIe cards, from Fusion-io Inc., have allowed MySpace to replace multiple server farms made up of 2U (3.5-in high) servers that had used 10 to 12 15,000 RPM Fibre Channel drives each with 1U (1.75-in high) servers using a single ioDrive . "In the last 20 years, disk storage hasn't kept pace with other innovations in IT, and right now we're on the cusp of a dramatic change with flash technologies," said Richard Buckingham, vice president of technical operations for MySpace, in a statement.

MySpace's new servers also have replaced its high-performance hosts that held data in large RAM cache modules, a costly method MySpace had been using in order to achieve the necessary throughput to serve its relational databases. Salt Lake City-based Fusion-io claims the ioDrive Duo offers users unprecedented single server performance levels with 1.5GB/sec. throughput and almost 200,000 IOPS. The system can reach such performance levels because four ioDrive Duos in a single server can scale linearly, which provides up to 6GB/sec. of read bandwidth and more than 500,000 read IOPS. The cards come in 160GB, 320GB and 640GB capacities. MySpace said its new servers using the NAND flash memory modules give it the same performance as its older RAM servers. A 1.28TB card is expected in the second half of this year. "Social networking sites and other Web 2.0 applications are very database dependent. Ethernet pipe," David Flynn, CTO of Fusion-io, said in an interview. Our 320GB ioDrive can fill a 10Gbit/sec.

IA job prospects bright

No one reading this column needs general references to news about the economic difficulties we are living through in the United States and elsewhere. He's looking for a permanent job. Just the other day, I spoke with a long-time friend and colleagues from the information security field who used to earn a decent living as a much sought-after consultant; last week he canceled his business telephone line to save money.

High-tech talent set to take off Another colleague of ours hasn't had a consulting contract in months – despite having had trouble in the past keeping up with demand for his services. The situation makes me think more positively about having moved from the business world to academic in 2001 – despite dropping my nominal salaried income by 57.5% at that time and now earning about one-third of what I'd be making as a senior IA executive in industry today. I think that security consultants may be suffering from a side-effect of the economic downturn: clients who don't already have or want permanent information assurance (IA) personnel may simply have decided to continue taking risks and hoping that nothing bad will happen to them. At least I have tenure, which means that I'm not going to be fired unless I appear in class out of uniform (Vermont Militia = US Army Class A greens), show up drunk (I never drink alcohol), treat a student rudely (no way) or recite Monty Python skits in class… uh wait a minute, I do recite Monty Python skits in class – but very briefly. Only little bits of them.

Really. Honest. Perhaps organizations who have enough savvy to employ permanent IA staff also understand the value of hiring good people for these critically important functions. But more seriously, there is good news for IA students and professionals: according to an extensive survey published by Foote Partners, LLC in Florida, job prospects are good for information assurance (IA) specialists. Upasana Gupta of BankInfoSecurity reviews the "2009 IT Skills Trends Report Update" which is available free in return for buying any other report from Foote or simply for registering with them. Interestingly, the skills most frequently sought-after by employers include (quoting Gupta directly): • Forensic Analysis• Incident Handling & Analysis• Security Architecture• Ethical Hacking• Network Security• Security Management Professor Gene Spafford said in his acceptance address for the National Computer System Security Award in 2000 that we were "eating our seed corn" by paying IA professors less than our IA graduates earn on their first job.

Gupta quotes the company as describing a number of factors (described in more detail in her excellent article) increasing demand for IA professionals: • IA is increasing recognized as strategically significant to all aspects of business.• Customers are demanding better security to protect their own information.• Laws and regulations are pressuring organizations into compliance with better security.• Liability costs for non-compliance are rising.• Virtualization is increasingly making technologists aware of security issues. The Foote report shows average salaries for various IA positions ranging from $70,000 to $170,000. How we are to attract professionals and recent graduates to our field of teaching and research in universities is a mystery to me. Universities will usually be willing to provide publicity for donors, so it's not a one-way donation devoid of short-term value for the donors, either. Some years ago I begged industry to think ahead and start funding supplements to professors' salaries so university IA departments can compete with industry in attracting field-experienced, professionally certified experts with advanced degrees to our faculty. Anyone interested in raising my salary – oops, our salaries – at Norwich University is welcome to contact me directly and I'll put you in touch with our Chair of Computing to make the arrangements. We even teach courses for free and do work on courses during the summers, when we are not paid for our time!

In the long run, without support from industry to raise salaries, the only people who are going to be willing to work long hours in universities for pathetic salaries are nut-cases like my colleagues and me who work on courses and research because we are addicted to teaching. WE ARE ADDICTS. But I can stop any time. Really.

Acorn 2.1 gains AppleScript, more

It seems like only last month that Flying Meat released Acorn 2, its exceptional "image editor for humans," with a massive array of new features like mutli-layer screenshots, RAW support, and two heaping handfuls of other new tools. After a couple of minor touch-ups and fixes in recent weeks, the purveyor of virtual airborne nourishment is back with Acorn 2.1, a major update that adds another laundry list of new features and fixes. Oh wait, it was only last month. Acorn 2.1's most significant new feature is definitely "scripting for humans" in the form of AppleScript, complete with a series of example scripts to get users started.

Adding AppleScript support to an application can be hard, which inspired Flying Meat to integrate the JSTalk scripting language for Acorn 2.0's launch. AppleScript is a fairly simple scripting language that is accessible to mere mortals (read: non-developers) like you and me, but there has been some understandable debate recently about its future. JSTalk is based on Javascript-it arguably jives better with developers' style and can be easier to add to Mac OS X apps. Other new features include a Hex color picker in the color palette (great for Web design), various improvements to managing layers, automatic image scaling when printing, and the adoption of a smart new Mac trend wherein Acorn will ask if you want to move it to the Applications folder if you run it from any other location. Nevertheless, the community asked for AppleScript, and it's great to see Flying Meat swoop in to the rescue.

I wasn't kidding about there being a laundry list of improvements and fixes in Acorn 2.1, so take a look at the rest for yourself, or fire up Acorn to take the update out for a spin. But before you resort to drastic measures, you could just download a demo for free. If, for some strange reason, you still have not tried or bought a copy of Acorn yet, you may need to consult your physician. Acorn 2 requires 10.6 Snow Leopard and a license costs $50.

Patch Tuesday: What the experts say

Microsoft Tuesday released six patches that address 15 vulnerabilities. Windows exploit code coming "There are three vulnerabilities this month that target a listening service. Here's a look at what security experts are saying about the vulnerabilities, patches and what should concern users.

While none of them are likely to considered great candidates for exploit, they are worth noting as they all primarily affect the enterprise. While Web Services on Devices affects Vista and Server 2008, the attack vector requires that you be on the local subnet, meaning the home user is unlikely to see any real risk."- Tyler Reguly, senior security engineer for nCircle "MS09-066 affects corporate networks as it addresses a vulnerability in Active Directory. It is unlikely that the home user will be running a license logging server or have Active Directory up and running. A successful exploit can result in denial-of-service on the system. All operating systems other than Windows 2000 require valid credentials to send a specially crafted packet.

This vulnerability will be difficult to exploit though. If an attacker already had valid credentials, they would do more damage than a denial-of-service attack on a server. A specially crafted packet sent to a Windows 2000 machine can result in an unresponsive machine that requires an unscheduled reboot."- Jason Miller, data and security team leader for Shavlik Technologies "The Embedded OpenType font kernel vulnerability [MS09-065] is the most serious in our opinion. For Windows 2000 servers, like MS09-064, these machines should be patched immediately. Not only is proof-of-concept exploit code publicly available, but all that's required of a user to become infected by it is simply viewing a compromised Web page. Symantec isn't seeing any active exploits of this in the wild yet, but we think attackers will be paying a lot of attention to it in the future."- Ben Greenbaum, senior research manager at Symantec Security Response. "One of the nice things that you will see today is that Windows 7 and Windows Server 2008 are not affected by any of these patches."- Richie Lai, director of vulnerability research for Qualys Follow John on Twitter: http://twitter.com/johnfontana