<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AllThingsD &#187; security</title>
	<atom:link href="http://allthingsd.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://allthingsd.com</link>
	<description></description>
	<lastBuildDate>Fri, 10 Feb 2012 14:09:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><image>
		  <url>http://allthingsd.com/theme/images/logo-rss.jpg</url>
		  <title>All Things Digital</title>
		  <link>http://allthingsd.com/</link>
		  <width>144</width>
		  <height>22</height>
	</image>		<item>
		<title>Google's "Bouncer" Has Been Quietly Scanning Android Apps for Malware</title>
		<link>http://allthingsd.com/20120202/googles-bouncer-has-been-quietly-scanning-android-apps-for-malware/</link>
		<comments>http://allthingsd.com/20120202/googles-bouncer-has-been-quietly-scanning-android-apps-for-malware/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 20:30:59 +0000</pubDate>
		<dc:creator>Ina Fried</dc:creator>
				<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Android Market]]></category>
		<category><![CDATA[Bouncer]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Hiroshi Lockheimer]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=170672</guid>
		<description><![CDATA[The Android maker says its technology looks for the presence of known malicious apps as well as for red flags that might indicate an app is up to no good.]]></description>
			<content:encoded><![CDATA[<p>Google is publicly confirming on Thursday the existence of &#8220;Bouncer&#8221; &#8212; a technology that it has been using for months now to scan Android market applications for malware.</p>
<p><a href="http://allthingsd.com/files/2012/02/android-bouncer-adventure.png"><img src="http://allthingsd.com/files/2012/02/android-bouncer-adventure-380x285.png" alt="" title="android-bouncer-adventure" width="380" height="285" class="alignright size-Medium380 wp-image-170689" /></a></p>
<p>While Google doesn&#8217;t require the kinds of approvals needed from Apple or Microsoft before an app goes live, the company has been taking some actions to try to keep malicious code out of its virtual storefront.</p>
<p>Bouncer not only looks for known malware and spyware, it also tries to detect behavior that might offer a red flag that a product is malicious. In addition, the company runs every submitted app on its own cloud infrastructure to simulate how the program would run on an Android device. Finally, when the company learns of a new type of exploit, it goes back and rescans all of the apps in the market.</p>
<p>&#8220;We have been working on this for a while,&#8221; Android Engineering VP Hiroshi Lockheimer said in an interview. &#8220;It&#8217;s always been a goal of ours to have a secure market.&#8221;</p>
<p>Lockheimer said that avoiding a manual approval process is very important to Google, but he said that shouldn&#8217;t have to mean giving up security. Bouncer, he said, is Google&#8217;s attempt to avoid that trade-off.</p>
<p>&#8220;It is the Google way to use technology and automation,&#8221; he said.</p>
<p>And, Lockheimer said, it is paying off. While lots of outsiders have said Android malware is on the rise, Google says it has seen a decline in malicious apps in the official Android market. The number of such programs was down 40 percent from the first half of 2011 to the second half of the year, Lockheimer said.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120202/googles-bouncer-has-been-quietly-scanning-android-apps-for-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Email Giants Move to Slash "Phishing"</title>
		<link>http://allthingsd.com/20120130/email-giants-move-to-slash-phishing/</link>
		<comments>http://allthingsd.com/20120130/email-giants-move-to-slash-phishing/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 12:30:30 +0000</pubDate>
		<dc:creator>Ben Worthen</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Voices]]></category>
		<category><![CDATA[Bank of America]]></category>
		<category><![CDATA[Ben Worthen]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[Fidelity Investments]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[PayPal]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[The Wall Street Journal]]></category>
		<category><![CDATA[Yahoo]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=168619</guid>
		<description><![CDATA[Email-service providers Google Inc., Yahoo Inc., Microsoft Corp. and AOL Inc. are backing a new effort intended to dramatically reduce "phishing" emails -- which attempt to trick recipients into thinking they come from a legitimate source.]]></description>
			<content:encoded><![CDATA[<p>Email-service providers Google Inc., Yahoo Inc., Microsoft Corp. and AOL Inc. are backing a new effort intended to dramatically reduce &#8220;phishing&#8221; emails &#8212; which attempt to trick recipients into thinking they come from a legitimate source.</p>
<p>The companies &#8212; along with others such as financial-service companies Bank of America Corp., FMR LLC&#8217;s Fidelity Investments and eBay Inc.&#8217;s PayPal &#8212; are hoping to create an environment that allows the recipient of an email from, say, a bank, to feel secure that it isn&#8217;t a trick.</p>
<p><a href="http://online.wsj.com/article/SB10001424052970204652904577191360158848618.html">Read the rest of this post on the original site »</a></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120130/email-giants-move-to-slash-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>An App for Monitoring Mobile Malware Around the Globe</title>
		<link>http://allthingsd.com/20120124/an-app-for-monitoring-mobile-malware-around-the-globe/</link>
		<comments>http://allthingsd.com/20120124/an-app-for-monitoring-mobile-malware-around-the-globe/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 17:02:05 +0000</pubDate>
		<dc:creator>Lauren Goode</dc:creator>
				<category><![CDATA[Commerce]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[apps]]></category>
		<category><![CDATA[harmful]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Lookout Labs]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[tracker]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=166918</guid>
		<description><![CDATA[Lookout's hackers-turned-start-up-guys have launched an Android app for real-time spying on mobile malware and spyware.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20101222/lookout-mobile-security-picks-up-funding-steam/">Lookout Mobile Security</a>, the start-up behind wireless security software and a <a href="http://allthingsd.com/20110302/lookouts-new-plan-b-app-allows-users-to-find-an-already-lost-phone/">&#8220;Plan B&#8221;</a> app for finding lost phones, has launched a new app for keeping an eye on malware hotspots around the world. </p>
<p>The <a href="https://market.android.com/details?id=com.lookout.threattracker">Mobile Threat Tracker app</a> consolidates the most recent two weeks&#8217; worth of Lookout&#8217;s security data into a kind of mobile heat map. The user sees dots flying around the globe as a real-time visualization of where threats are happening. </p>
<p><a href="http://allthingsd.com/files/2012/01/Mobile_Threat_Tracker-atd1.png"><img src="http://allthingsd.com/files/2012/01/Mobile_Threat_Tracker-atd1-352x285.png" alt="" title="Mobile_Threat_Tracker atd" width="352" height="285" class="alignright size-medium wp-image-167040" /></a></p>
<p>When users scroll over the globe, a timeline appears, showing how much of the threat is malware and how much is spyware; the top three threats are listed along with plain-English descriptions, and why Lookout has identified them as malicious.</p>
<p>Kevin Mahaffey, Lookout&#8217;s co-founder and CTO, said the app isn&#8217;t necessarily about offering immediate solutions, but more about making people aware of when they might be particularly vulnerable on mobile. &#8220;People shouldn&#8217;t have to be security experts to stay safe. We want to remind them to download apps from reputable app stores, to not go to shady download sites; to look at the developer name behind an app, and make sure it&#8217;s legitimate.&#8221;</p>
<p>The Mobile Threat Tracker is only available on devices running an Android OS to start, and Mahaffey says it&#8217;s unclear whether there will be a version for iOS devices. &#8220;Right now, it makes less sense, because there isn&#8217;t any real malware on the iPhone,&#8221; Mahaffey said, &#8220;though at some point there might be a need for it.&#8221; </p>
<p>Lookout Mobile Security launched in 2007, and now claims more than 15 million users worldwide. The company says it takes an educational approach to informing people about products for malware and spyware, rather than using fear-mongering in its marketing; it offers most of its apps for free, with additional features available at a premium. </p>
<p>While threats on mobile devices still aren&#8217;t as high-scale as malware and spyware on PCs, Lookout&#8217;s <a href="http://blog.mylookout.com/blog/2011/12/13/2012-mobile-threat-predictions/">internal research</a> shows that the amount of malware on mobile has increased.</p>
<p>Lookout said the likelihood of an Android user encountering malware increased from 1 percent to 4 percent over the course of 2011. The company has identified more than a thousand instances of infected applications, double the number it saw in July 2011. </p>
<p>The Lookout report notes that Web-based threats like phishing can carry over easily from PCs, making the likelihood of clicking on a bad link higher than that of acquiring malware through mobile apps. The global yearly likelihood of an Android user clicking on an unsafe link is 36 percent &#8212; up 6 percent from just six months ago &#8212; while in the U.S., the likelihood is higher than the global average, at 40 percent.</p>
<p>(Photo courtesy of <a href="http://www.flickr.com/photos/thetechblock/6682888581/">TheTechBlock</a>/Flickr)</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120124/an-app-for-monitoring-mobile-malware-around-the-globe/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Anonymous Fails, Once Again, to Make Its Point</title>
		<link>http://allthingsd.com/20120120/anonymous-fails-once-again-to-make-its-point/</link>
		<comments>http://allthingsd.com/20120120/anonymous-fails-once-again-to-make-its-point/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 21:58:58 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Ann Coulter]]></category>
		<category><![CDATA[anonymous]]></category>
		<category><![CDATA[AntiSec]]></category>
		<category><![CDATA[Bill O'Reilly]]></category>
		<category><![CDATA[chat rooms]]></category>
		<category><![CDATA[Church of Scientology]]></category>
		<category><![CDATA[computer crime]]></category>
		<category><![CDATA[distributed denial of service attacks]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[jail]]></category>
		<category><![CDATA[LulzSec]]></category>
		<category><![CDATA[Megaupload]]></category>
		<category><![CDATA[Megaupload.com]]></category>
		<category><![CDATA[MPAA]]></category>
		<category><![CDATA[New Jersey]]></category>
		<category><![CDATA[Ohio]]></category>
		<category><![CDATA[PIPA]]></category>
		<category><![CDATA[prison]]></category>
		<category><![CDATA[PROTECT IP Act]]></category>
		<category><![CDATA[RIAA]]></category>
		<category><![CDATA[Rudolph Giuliani]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SOPA]]></category>
		<category><![CDATA[Stop Online Piracy Act]]></category>
		<category><![CDATA[Sweden]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[U. S. House of Representatives]]></category>
		<category><![CDATA[U.S. Department of Justice]]></category>
		<category><![CDATA[U.S. Senate]]></category>
		<category><![CDATA[United Kingdom]]></category>
		<category><![CDATA[Universal Music Group]]></category>
		<category><![CDATA[US Federal LAw]]></category>
		<category><![CDATA[Washington D.C.]]></category>
		<category><![CDATA[Wikileaks]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=165909</guid>
		<description><![CDATA[Big as they were, the attacks carried out in revenge for the Megaupload arrests accomplished nothing significant.]]></description>
			<content:encoded><![CDATA[<p><div id="attachment_166097" class="wp-caption alignright" style="width: 390px"><img src="http://allthingsd.com/files/2012/01/anonymous_cleanup.png" alt="" title="anonymous_cleanup" width="380" height="284" class="size-full wp-image-166097" /><span class="media-attribution">AllThingsD.com</span><p class="wp-caption-text"> </p></div>The world seemed awfully impressed yesterday with the size and oomph of the revenge attacks carried out online in reaction to the arrests of four people associated with the file-sharing site Megaupload.com. </p>
<p>Yet now that the attacks have subsided, it&#8217;s time to see them for what they are: Nothing more than a blunt instrument that accomplishes nothing constructive.</p>
<p>As of today, only one of the Web sites attacked by the hacker troupe Anonymous is still apparently affected, and that belongs to the <a href="http://www.universalmusic.com/">Universal Music Group</a> recording label. It currently displays only a message saying &#8220;The Site is under maintenance. Please expect it to be back shortly.&#8221; Others that had been attacked yesterday, including the sites of the <a href="http://www.justice.gov/">U.S. Department of Justice</a>, the <a href="http://riaa.org/">Recording Industry Association of America</a> and the <a href="http://mpaa.org/">Motion Picture Association of America</a> all seemed to be operating normally.</p>
<p>Thursday&#8217;s attacks, which have been described as the biggest action yet organized by Anonymous, were launched in apparent revenge for the FBI&#8217;s arrest of several people associated with the file-sharing site <a href="http://allthingsd.com/20120119/fbi-charges-seven-with-online-piracy/">Megaupload.com</a> over suspicions of online piracy. Taking place against the backdrop of <a href="http://allthingsd.com/20120118/sound-bites-from-the-sopa-strike/">a wider, more civil protest</a> against anti-piracy legislation currently before the U.S. Congress, the atmosphere around the attacks has been politically charged.</p>
<p>As <a href="http://news.cnet.com/8301-31322_3-57362437-256/anonymous-goes-nuclear-everybody-loses/">Molly Wood of CNET put it</a>, the #OpMegaUpload attacks &#8212; coming as they did on the heels of Wednesday&#8217;s peaceful anti-SOPA protest &#8212; seem like an &#8220;unsettling wave of car-burning hooligans that sweep in and incite the riot portion of the play,&#8221; spurring equally unsettling reactions from the powers that be.</p>
<p>Many outlets have portrayed the attacks as &#8220;hacks,&#8221; implying that someone had picked a lock in order to commit some kind of sabotage. But the tactic used &#8212; a distributed denial-of-service (DDoS) attack &#8212; is more aptly compared to a blunt instrument, requiring neither skill nor knowledge, only large numbers of willing participants who team up to swarm a site with more requests than it can accommodate and thus overwhelm its ability to function normally.</p>
<p>The adjective &#8220;willing&#8221; is debatable, and perhaps inaccurate. Anonymous was able to generate such impressive numbers with the operation &#8212; it claimed more than 5,000 participants &#8212; by spamming a link in chat rooms and via Twitter that, when clicked, triggered a tool used to launch the attack. People tricked into following the link are given no context or information, and so may or may not have any idea that they&#8217;re participating in the execution of a crime.</p>
<p>For the record, it is illegal in the U.S., the U.K., Sweden and other countries to launch and participate in a DDoS attack like the one Anonymous organized. As anyone who has observed the evolution of Anonymous (and its various affiliates using the names LulzSec and AntiSec) should know, the <a href="http://allthingsd.com/20110719/16-arrested-in-nationwide-hacker-crackdown/">FBI arrested 16 people last July</a>, many of them charged with participating in a DDoS attack against PayPal in protest of its <a href="http://allthingsd.com/20101204/paypal-to-wikileaks-youre-cut-off/">shutting down an account used by WikiLeaks</a>. </p>
<p>In 2009, a New Jersey man was sentenced to a <a href="http://nakedsecurity.sophos.com/2009/11/20/scientology-website-attacker-jail/">year and a day in prison</a> for launching a DDoS attack against the Church of Scientology. And in 2010, a 23-year-old Ohio man was sentenced to 30 months in prison for launching DDoS attacks against several prominent U.S. conservatives, including the author Ann Coulter, former New York City mayor Rudolph Giuliani and Fox News commentator Bill O&#8217;Reilly.</p>
<p>Records like that suggest to me that DDoS attacks never accomplish anything that the people who organize and carry them out attempt to do. At most, they inconvenience the people who visit and operate the targeted sites for a few hours, until the attention spans of the attackers shift elsewhere. They also generate headlines that are forgotten by nearly everyone except the targets, and sometimes law enforcement. </p>
<p>And so it will be this time. Mark your calendars, because the Megaupload revenge attacks will spur a series of arrests later this year. Some of those arrested will be people who didn&#8217;t know they were committing a crime. And that certainly won&#8217;t help Anonymous&#8217; image. Nor will it further a single bit of what passes for the Anonymous agenda.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120120/anonymous-fails-once-again-to-make-its-point/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Going Back to Internet Explorer</title>
		<link>http://allthingsd.com/20120111/going-back-to-internet-explorer/</link>
		<comments>http://allthingsd.com/20120111/going-back-to-internet-explorer/#comments</comments>
		<pubDate>Wed, 11 Jan 2012 23:59:04 +0000</pubDate>
		<dc:creator>Walt Mossberg</dc:creator>
				<category><![CDATA[Mossberg's Mailbox]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Reviews]]></category>
		<category><![CDATA[Walt Mossberg]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[IE9]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Mozilla]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Web browser]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=162978</guid>
		<description><![CDATA[Walt answers a reader's question about security holes in Web browsers.]]></description>
			<content:encoded><![CDATA[<p class="mailbox-q">Q:</p>
<p class="mailbox-question"><em> A few years ago we moved our company completely off of Internet Explorer to Firefox because you wrote in your column that IE had security holes and lacked speed. Our IT Services provider has told us that IE9 has solved all the pitfalls of previous versions, it&#8217;s the safest yet, and there are many business-oriented sites that are much friendlier to IE. So is it OK to go back? </em></p>
<p class="mailbox-a">A:</p>
<p>I haven&#8217;t done a comparative browser review in a while, but I do agree that Internet Explorer has improved tremendously in speed, security and features. I think IE9 is a good browser and a reasonable choice, assuming you are a 100% Windows shop. IE is the only major browser that lacks a Mac version.</p>
<p>Some caveats: Each of the major browsers has improved, and, by some measures, some competitors beat IE in speed.  A new, fast-rising contender since I wrote that old column  is Google&#8217;s Chrome, which I find to be fast and reliable.  IE&#8217;s market share, while still the highest, has shrunk dramatically and the browser market is more balanced. Finally, the number of business-oriented sites that require or do better in IE has been greatly reduced from, say, five years ago.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120111/going-back-to-internet-explorer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Scary Was the Internet in 2011?</title>
		<link>http://allthingsd.com/20120101/how-scary-was-the-internet-in-2011/</link>
		<comments>http://allthingsd.com/20120101/how-scary-was-the-internet-in-2011/#comments</comments>
		<pubDate>Sun, 01 Jan 2012 23:22:39 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[anonymous]]></category>
		<category><![CDATA[AntiSec]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[Duqu]]></category>
		<category><![CDATA[espionage]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Intel]]></category>
		<category><![CDATA[Kaspersky Labs]]></category>
		<category><![CDATA[LulzSec]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[PLC]]></category>
		<category><![CDATA[sabotage]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Sony]]></category>
		<category><![CDATA[Stuxnet]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=158718</guid>
		<description><![CDATA[How scary was the Internet in 2011? It depends on what you consider scary. News of attacks, some silly, some downright chilling, created uneasiness all year.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20120101/how-scary-was-the-internet-in-2011/hackingexposed-242x300-2/" rel="attachment wp-att-158729"><img src="http://allthingsd.com/files/2012/01/hackingexposed-242x3001-242x285.png" alt="" title="hackingexposed-242x300" width="242" height="285" class="alignright size-Featured wp-image-158729" /></a>With 2011 in the books, I thought it would be interesting to revisit some predictions I made last year on the subject of computer security. In &#8220;<a href="http://allthingsd.com/20101230/2010-was-the-year-the-internet-got-scary-get-used-to-it/">2010 Was the Year the Internet Got Scary. Get Used to It.</a>&#8221; I looked at a string of events on the computer security landscape during the prior year and thought about what they meant for the year ahead.</p>
<p>I wrote then: </p>
<blockquote class="memo"><p>
&#8220;The unvarnished fact is that the networked society to which we’ve become accustomed in the last several years has a soft, vulnerable underbelly. </p>
<p>And the more we rely upon it, the more people with a combination of advanced technical skills and repugnant motivations are going to look for ways to turn it against us.</p>
<p>Some will do so as a means of making a personal profit. Others may see it as a way of advancing a political or ideological agenda.</p>
<p>But others will want to use theirs skills to do serious harm to innocent people on a large scale.&#8221;</p></blockquote>
<p>Part of these predictions or ruminations or whatever you care to call them makes me think of the hijinks of the group that started out in the spring variously known as LulzSec, Anonymous and later adopted the moniker AntiSec. This loosely affiliated group emerged from the wake of the various attacks against Sony, and seemed to have nothing to prove but that it could make mincemeat out of whatever security measures had been put in place <a href="http://allthingsd.com/20110604/sony-hacked-for-what-seems-to-be-the-umpteenth-time/">by Sony </a>or whatever <a href="http://allthingsd.com/20110605/lulzsec-strikes-again-claims-attack-on-nintendo-server/">video game outfit</a> it had targeted on a given day.</p>
<p>Sony&#8217;s Playstation Network was a favorite target, and its service was <a href="http://allthingsd.com/20110705/sony-to-finally-complete-restoration-of-playstation-services-after-attacks/">at least partially offline</a> during two months ended in July. </p>
<p>Then, as summer dawned, the group&#8217;s members became aware of global politics and <a href="http://allthingsd.com/20110620/lulzsec-and-anonymous-team-up-to-hack-governments-and-banks/">teamed up with Anonymous</a>, the Wikileaks-allied band of hackers known for their campaigns of digital civil disobedience. Together they declared &#8220;immediate and unremitting war&#8221; on governments and corporations, and said their top priority would be to steal and leak any classified government information, including but not limited to email and documentation. They <a href="http://allthingsd.com/20110623/lulzsec-goes-all-wikileaks-on-arizona-state-cops/">attacked an Arizona police agency</a> as a way of making a statement against anti-immigrant laws in that state, and <a href="http://allthingsd.com/20110624/arizona-confirms-lulzsec-docs-are-authentic-worries-about-officer-safety/">published the names and home addresses</a> of several officers.</p>
<p>Later they sought to earn some street cred by stealing &#8220;secret&#8221; documents from NATO, only to learn after the fact that the documents they released had not only been released before, but <a href="http://allthingsd.com/20110721/anonymous-hacks-nato-steals-lame-documents/">weren&#8217;t even really all that secret</a> to begin with. It wasn&#8217;t long before alleged members of the group started showing up <a href="http://allthingsd.com/20110801/uk-police-say-this-is-the-face-of-lulzsec-hacker-known-as-topiary/">in handcuffs</a>, which seemed not to faze them. The prospect of body bags and real-world violence during a <a href="http://allthingsd.com/20111102/facing-real-world-violence-anonymous-backs-down-against-drug-cartel/">confrontation with Mexican drug cartels</a>, however, did.</p>
<p>Yet for all the headlines they garnered and the headaches they caused, the LulzSec/Anonymous/AntiSec gang wasn&#8217;t anywhere near the scariest thing to appear on the computer security landscape in 2011. To my mind, one of the top three scariest things was the disclosure of Operation Shady RAT, which Intel-unit McAfee said appeared to be the <a href="http://allthingsd.com/20110803/operation-shady-rat-the-biggest-hacking-attack-ever/">biggest large-scale compromise ever</a>, affecting 72 organizations and governments around the world, including the U.S., Taiwan, Vietnam, South Korea, Canada and India — some of them dating back as far as 2006. McAfee said the attacker was a &#8220;state actor,&#8221; though it declined to name it. The candidate highest on the short list was, naturally, China.</p>
<p>The second truly scary incident was the attack carried out <a href="http://allthingsd.com/20110317/rsa-under-extremely-sophisticated-attack-yes-the-tokens-are-involved/">against RSA Security</a>, a unit of the IT company EMC, the maker of the popular SecurID tokens that so many people have on their keychains and use to create an added layer of security that goes beyond the password. Months later, the U.S. defense contractor Lockheed Martin was <a href="http://allthingsd.com/20110528/lockheed-martin-confirms-it-came-under-attack/">attacked with duplicate SecurID</a> tokens.</p>
<p>Finally, the Stuxnet Trojan (used by parties officially unknown, but probably Israel with a little help from the U.S.) continued to fascinate and confound security researchers in 2011. Having caused nuclear centrifuges in Iran to explode in an attempt to set back that country&#8217;s nuclear weapons research program, Stuxnet was found to have a sibling called Duqu. Unlike Stuxnet, which messed with industrial control computers and made them do things they wouldn&#8217;t normally do, Duqu&#8217;s mission was much simpler: <a href="http://www.kaspersky.com/about/press/duqu.aspx">Steal everything in sight</a>.</p>
<p>And after that, it was discovered by researchers at Kaspersky labs that Stuxnet and Duqu are part of an even bigger family, with at least three more siblings still undetected by researchers, and that all five were created by the <a href="http://www.reuters.com/article/2011/12/28/us-cybersecurity-stuxnet-idUSTRE7BR1EV20111228">same people and with the same tools</a>.  Chances are we&#8217;ll see at least a few of those final three in 2012, particularly as <a href="http://online.wsj.com/article/SB10001424052970204720204577132923798499772.html">tension with Iran heats up</a>.</p>
<p>So while there was much to consider scary happening on the Internet in 2011, I&#8217;m grateful for being wrong on one key prediction: That we didn&#8217;t see a significant computer attack used to physically harm innocent people on a large scale. That&#8217;s one prediction I hope to miss for years to come.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20120101/how-scary-was-the-internet-in-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stratfor Hack Damage Report: 50,000 Credit Cards, 44,000 Passwords</title>
		<link>http://allthingsd.com/20111227/stratfor-hack-damage-report-50000-credit-cards-44000-passwords/</link>
		<comments>http://allthingsd.com/20111227/stratfor-hack-damage-report-50000-credit-cards-44000-passwords/#comments</comments>
		<pubDate>Tue, 27 Dec 2011 22:10:00 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[anonymous]]></category>
		<category><![CDATA[AntiSec]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[LulzSec]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Stratfor]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=157427</guid>
		<description><![CDATA[Number of Lulz: Incalculable.]]></description>
			<content:encoded><![CDATA[<p><img src="http://allthingsd.com/files/2011/07/anonymous_at_scientology_in_los_angeles-380x285.png" alt="" title="anonymous_at_scientology_in_los_angeles" width="380" height="285" class="alignright size-Featured wp-image-99962" />A few days after the private security think tank Stratfor disclosed that it had been the <a href="http://allthingsd.com/20111226/anonymous-plays-robin-hood-with-stolen-credit-cards/">victim of a hacking attack</a>, apparently carried out by the loosely affiliated group Anonymous, the extent of the damage is becoming clear.</p>
<p>Identity Finder, a New York-based identity theft protection firm, has analyzed the information breached and summarized what the attackers appear to have made off with.</p>
<blockquote class="memo">
<ul>
<li>50,277 unique credit card numbers, of which 9,651 are <em>not</em> expired<br />
<LI>86,594 email addresses, of which 47,680 are unique<br />
<LI>27,537 phone numbers, of which 25,680 are unique</p>
<li>44,188 encrypted passwords, of which roughly 50 percent could be easily cracked
<li>73.7 percent of decrypted passwords were weak
<li>21.7 percent of decrypted passwords were medium strength
<li>4.6 percent of decrypted passwords were strong
<li>Average decrypted password length: 7.1 characters
<li>10 percent of decrypted passwords were less than 5 characters long
<li>Only 4.8 percent of decrypted passwords were 10+ characters long
<li>Presumably the remaining non-decrypted passwords were stronger than the decrypted subset
<li>13,973 of the addresses belonged to United States victims; the remainder belonged to individuals from around the world</ul>
</blockquote>
<p>There are also an additional 2.7 million email messages that the attackers claim to have taken, but that have not yet been released.</p>
<p>Stratfor has promised to inform the customers whose information was taken no later than Dec. 28, which is tomorrow. Anonymous, ever seeking to justify its actions in the name of some higher moral purpose, said in a tweet that Stratfor, which sells subscriptions to its intelligence analysis reports to government, law enforcement agencies and businesses, isn&#8217;t &#8220;the harmless company it tries to paint itself as,&#8221; and that the emails will show that.</p>
<p><!-- tweet id : 151731063918563329 --><br />
<style type="text/css">#bbpBox_151731063918563329 a { text-decoration:none; color:#99001a; }#bbpBox_151731063918563329 a:hover { text-decoration:underline; }</style>
<div id="bbpBox_151731063918563329" class="bbpBox" style="padding:20px; margin:5px 0; background-color:#131516; background-image:url(http://a1.twimg.com/images/themes/theme14/bg.gif);">
<div style="background:#fff; padding:10px; margin:0; min-height:48px; color:#333333; -moz-border-radius:5px; -webkit-border-radius:5px;"><span style="width:100%; font-size:18px; line-height:22px;">@<a href="http://twitter.com/intent/user?screen_name=techwriterjim" class="twitter-action">techwriterjim</a> It was conducted by <a href="http://twitter.com/search?q=%23Antisec" title="#Antisec">#Antisec</a>. Stratfor is not the &#8220;harmless company&#8221; it tries to paint itself as. You&#8217;ll see in those emails.</span>
<div class="bbp-actions" style="font-size:12px; width:100%; padding:5px 0; margin:0 0 10px 0; border-bottom:1px solid #e6e6e6;"><img align="middle" src="http://allthingsd.com/wp-content/plugins/twitter-blackbird-pie//images/bird.png" /><a title="tweeted on December 27, 2011 10:27 am" href="http://twitter.com/#!/AnonymousIRC/status/151731063918563329" target="_blank">December 27, 2011 10:27 am</a> via <a href="http://code.google.com/p/qwit/" rel="nofollow" target="blank">Qwit</a><a href="https://twitter.com/intent/tweet?in_reply_to=151731063918563329" class="bbp-action bbp-reply-action" title="Reply"><span><em style="margin-left: 1em;"></em><strong>Reply</strong></span></a><a href="https://twitter.com/intent/retweet?tweet_id=151731063918563329" class="bbp-action bbp-retweet-action" title="Retweet"><span><em style="margin-left: 1em;"></em><strong>Retweet</strong></span></a><a href="https://twitter.com/intent/favorite?tweet_id=151731063918563329" class="bbp-action bbp-favorite-action" title="Favorite"><span><em style="margin-left: 1em;"></em><strong>Favorite</strong></span></a></div>
<div style="float:left; padding:0; margin:0"><a href="http://twitter.com/intent/user?screen_name=AnonymousIRC"><img style="width:48px; height:48px; padding-right:7px; border:none; background:none; margin:0" src="http://a1.twimg.com/profile_images/1554234337/anontopenyan_normal.png" /></a></div>
<div style="float:left; padding:0; margin:0"><a style="font-weight:bold" href="http://twitter.com/intent/user?screen_name=AnonymousIRC">@AnonymousIRC</a>
<div style="margin:0; padding-top:2px">AnonymousIRC</div>
</div>
<div style="clear:both"></div>
</div>
</div>
<p><!-- end of tweet --></p>
<p>Whatever. Wired reported that someone who participated in the attack said that a total of four servers were breached, <a href="http://www.wired.com/threatlevel/2011/12/antisec-hits-private-intel-firm-million-of-docs-allegedly-lifted/">and the data on them wiped</a>. The question that then logically arises is this: What was a firm that&#8217;s ostensibly in the business of advising business and government clients on security doing about its own?</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111227/stratfor-hack-damage-report-50000-credit-cards-44000-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anonymous Plays Robin Hood With Stolen Credit Cards</title>
		<link>http://allthingsd.com/20111226/anonymous-plays-robin-hood-with-stolen-credit-cards/</link>
		<comments>http://allthingsd.com/20111226/anonymous-plays-robin-hood-with-stolen-credit-cards/#comments</comments>
		<pubDate>Mon, 26 Dec 2011 15:34:58 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[anonymous]]></category>
		<category><![CDATA[care]]></category>
		<category><![CDATA[F-Secure]]></category>
		<category><![CDATA[George Friedman]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[LulzSec]]></category>
		<category><![CDATA[Mikko Hypponen]]></category>
		<category><![CDATA[Red Cross]]></category>
		<category><![CDATA[Robin Hood]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Stratfor]]></category>
		<category><![CDATA[think tank]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=156899</guid>
		<description><![CDATA[The hackers of Anonymous are at it again, attacking the servers of intelligence think tank Stratfor, and then using the pilfered credit cards to give money to charities.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20110528/lockheed-martin-confirms-it-came-under-attack/hackers_ver1-2/" rel="attachment wp-att-79611"><img src="http://allthingsd.com/files/2011/05/hackers_ver1-375x285.jpg" alt="" title="hackers_ver1" width="375" height="285" class="alignright size-Featured wp-image-79611" /></a>The hacking collective that goes by the name Anonymous appears to have had a busy Christmas weekend. First came word that that its members had attacked and compromised the servers of the global intelligence think tank <a href="http://www.stratfor.com/">Stratfor</a>. (The Stratfor site is currently down for maintenance.) Then Anonymous claimed to have used the stolen credit cards to make charitable donations to aid organizations like CARE and the Red Cross.</p>
<p>Some people claiming to represent Anonymous &#8212; the lines and affiliations are always difficult to discern &#8212; said that the information taken in the attack included user names and passwords of some Stratfor subscribers, plus another 200 gigabytes worth of other data.</p>
<p>Stratfor founder George Friedman confirmed the attack in an email to subscribers; I received it because I&#8217;ve been an intermittent Stratfor subscriber over the years. Here&#8217;s Friedman&#8217;s email:</p>
<blockquote class="memo"><p>Dear Stratfor Member,</p>
<p>We have learned that Stratfor&#8217;s web site was hacked by an unauthorized party. As a result of this incident the operation of Stratfor&#8217;s servers and email have been suspended.</p>
<p>We have reason to believe that the names of our corporate subscribers have been posted on other web sites. We are diligently investigating the extent to which subscriber information may have been obtained.</p>
<p>Stratfor and I take this incident very seriously. Stratfor&#8217;s relationship with its members and, in particular, the confidentiality of their subscriber information, are very important to Stratfor and me. We are working closely with law enforcement in their investigation and will assist them with the identification of the individual(s) who are responsible.</p>
<p>Although we are still learning more and the law enforcement investigation is active and ongoing, we wanted to provide you with notice of this incident as quickly as possible. We will keep you updated regarding these matters.</p>
<p>Sincerely,<br />
George Friedman </p></blockquote>
<p>And here&#8217;s an update to Stratfor subscribers, from Dec. 25:</p>
<blockquote class="memo"><p>Dear Stratfor Member,</p>
<p>On December 24th an unauthorized party disclosed personally identifiable information and related credit card data of some of our members. We have reason to believe that your personal and credit card data could have been included in the information that was illegally obtained and disclosed.</p>
<p>Also publicly released was a list of our members which the unauthorized party claimed to be Stratfor&#8217;s &#8220;private clients.&#8221; Contrary to this assertion the disclosure was merely a list of some of the members that have purchased our publications and does not comprise a list of individuals or entities that have a relationship with Stratfor beyond their purchase of our subscription-based publications.</p>
<p>We have also retained the services of a leading identity theft protection and monitoring service on behalf of the Stratfor members that have been impacted by these events. Details regarding the services to be provided will be forwarded in a subsequent email that is to be delivered to the impacted members no later than Wednesday, December 28th.</p>
<p>In the interim, precautions that can be taken by you to minimize and prevent the misuse of information which may have been disclosed include the following:</p>
<p>- contact your financial institution and inform them of this incident;<br />
- if you see any unauthorized activity on your accounts promptly notify your financial institution;<br />
- submit a complaint with the Federal Trade Commission (&#8220;FTC&#8221;) by calling 1-877-ID-THEFT (1-877- 438-4338) or online at https://www.ftccomplaintassistant.gov/; and<br />
- contact the three U.S. credit reporting agencies: Equifax (http://www.equifax.com/ or (800) 685-1111), Experian (http://www.experian.com/ or (888) 397-3742), and TransUnion (http://www.transunion.com/ or (800) 888-4213), to obtain a free credit report from each.</p>
<p>Even if you do not find any suspicious activity on your initial credit reports, the FTC recommends that you check your credit reports periodically. Checking your credit reports can help you spot problems and address them quickly.</p>
<p>To ease any concerns you may have about your personal information going forward, we have also retained an experienced outside consultant that specializes in such security matters to bolster our existing efforts on these issues as we work to better serve you. We are on top of the situation and will continue to be vigilant in our implementation of the latest, and most comprehensive, data security measures.</p>
<p>We are also working to restore access to our website and continuing to work closely with law enforcement regarding these matters. We will continue to update you regarding the status of these matters.</p>
<p>Again, my sincerest apologies for this unfortunate incident.</p>
<p>Sincerely,<br />
George Friedman</p></blockquote>
<p>Then came reports that whoever had taken the information &#8212; which included credit card numbers &#8212; had used the numbers to make donations in the name of the hacking victims. Here&#8217;s a link to what is said to be a screen grab following <a href="http://imagebin.org/190299">just such a donation</a> to CARE by an employee of the Defense Intelligence Agency.</p>
<p>While some might applaud the apparent cleverness of Anonymous&#8217;s &#8220;steal from the rich, give to the poor&#8221; attitude, it&#8217;s unlikely that the charities in question will ever see a dime of the money that&#8217;s been &#8220;donated&#8221; to them. As Mikko Hypponen of F-Secure <a href="http://www.f-secure.com/weblog/archives/00002288.html">pointed out here</a>, once the credit cards in question are reported stolen, the charges will  be reversed and the charities will more than likely be on the hook for any fees or penalties that result.</p>
<p>As is often the case with a headline-making attack carried out in the name of Anonymous, there followed a series of claims and counterclaims as to whether or not this was an &#8220;official&#8221; Anonymous attack, or just the work of someone falsely claiming the Anonymous cloak. There was, for instance, this &#8220;emergency press release,&#8221; claiming that the attack on Stratfor was &#8220;most definitely not the work of Anonymous&#8221;:</p>
<p><iframe src="http://pastebin.com/embed_iframe.php?i=8yrwyNkt" style="border:none;width:100%"></iframe></p>
<p>Following that, Anonymous tweeted, via its semi-official Twitter account @AnonymousIRC, that it &#8220;laughed so hard&#8221; in response to that message &#8212; essentially saying it&#8217;s a fake. The group has hinted that it is going to be busy over the next several days.</p>
<p><!-- tweet id : 151293774415400960 --><br />
<style type="text/css">#bbpBox_151293774415400960 a { text-decoration:none; color:#99001a; }#bbpBox_151293774415400960 a:hover { text-decoration:underline; }</style>
<div id="bbpBox_151293774415400960" class="bbpBox" style="padding:20px; margin:5px 0; background-color:#131516; background-image:url(http://a1.twimg.com/images/themes/theme14/bg.gif);">
<div style="background:#fff; padding:10px; margin:0; min-height:48px; color:#333333; -moz-border-radius:5px; -webkit-border-radius:5px;"><span style="width:100%; font-size:18px; line-height:22px;">RT @<a href="http://twitter.com/intent/user?screen_name=FiloSottile" class="twitter-action">FiloSottile</a>: &#8220;Anonymous denies involvement in <a href="http://twitter.com/search?q=%23STRATFOR" title="#STRATFOR">#STRATFOR</a> hack. <a href="http://t.co/cQ1INYlh&#038;#8221" rel="nofollow">http://t.co/cQ1INYlh&#038;#8221</a>; | We laughed so hard at this!</span>
<div class="bbp-actions" style="font-size:12px; width:100%; padding:5px 0; margin:0 0 10px 0; border-bottom:1px solid #e6e6e6;"><img align="middle" src="http://allthingsd.com/wp-content/plugins/twitter-blackbird-pie//images/bird.png" /><a title="tweeted on December 26, 2011 5:30 am" href="http://twitter.com/#!/AnonymousIRC/status/151293774415400960" target="_blank">December 26, 2011 5:30 am</a> via <a href="http://code.google.com/p/qwit/" rel="nofollow" target="blank">Qwit</a><a href="https://twitter.com/intent/tweet?in_reply_to=151293774415400960" class="bbp-action bbp-reply-action" title="Reply"><span><em style="margin-left: 1em;"></em><strong>Reply</strong></span></a><a href="https://twitter.com/intent/retweet?tweet_id=151293774415400960" class="bbp-action bbp-retweet-action" title="Retweet"><span><em style="margin-left: 1em;"></em><strong>Retweet</strong></span></a><a href="https://twitter.com/intent/favorite?tweet_id=151293774415400960" class="bbp-action bbp-favorite-action" title="Favorite"><span><em style="margin-left: 1em;"></em><strong>Favorite</strong></span></a></div>
<div style="float:left; padding:0; margin:0"><a href="http://twitter.com/intent/user?screen_name=AnonymousIRC"><img style="width:48px; height:48px; padding-right:7px; border:none; background:none; margin:0" src="http://a1.twimg.com/profile_images/1554234337/anontopenyan_normal.png" /></a></div>
<div style="float:left; padding:0; margin:0"><a style="font-weight:bold" href="http://twitter.com/intent/user?screen_name=AnonymousIRC">@AnonymousIRC</a>
<div style="margin:0; padding-top:2px">AnonymousIRC</div>
</div>
<div style="clear:both"></div>
</div>
</div>
<p><!-- end of tweet --></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111226/anonymous-plays-robin-hood-with-stolen-credit-cards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>eBay Acquires Invoicing Company in Germany</title>
		<link>http://allthingsd.com/20111222/ebay-acquires-invoicing-company-in-germany/</link>
		<comments>http://allthingsd.com/20111222/ebay-acquires-invoicing-company-in-germany/#comments</comments>
		<pubDate>Thu, 22 Dec 2011 16:34:35 +0000</pubDate>
		<dc:creator>Tricia Duryee</dc:creator>
				<category><![CDATA[Commerce]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Austria]]></category>
		<category><![CDATA[BillSafe]]></category>
		<category><![CDATA[eBay]]></category>
		<category><![CDATA[Germany]]></category>
		<category><![CDATA[invoice]]></category>
		<category><![CDATA[M&A]]></category>
		<category><![CDATA[Netherlands]]></category>
		<category><![CDATA[PayPal]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Switzerland]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=156249</guid>
		<description><![CDATA[EBay has acquired BillSAFE, which serves 15 million accounts in Germany, after buying a minority stake in the company last year. Terms were not disclosed. With BillSAFE, PayPal customers will now be able to receive an invoice for an order, after items have been shipped and received. Because of its security benefits, purchasing by invoice is used heavily in Germany, Austria, Switzerland and the Netherlands, eBay says.]]></description>
			<content:encoded><![CDATA[<p>EBay <a href="http://www.ebayinc.com/content/press_release/20111222005130">has acquired BillSAFE</a>, which serves 15 million accounts in Germany, after buying a minority stake in the company last year. Terms were not disclosed. With BillSAFE, PayPal customers will now be able to receive an invoice for an order, after items have been shipped and received. Because of its security benefits, purchasing by invoice is used heavily in Germany, Austria, Switzerland and the Netherlands, eBay says.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111222/ebay-acquires-invoicing-company-in-germany/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IBM Predicts Home Electricity From Your Bike, Mind-Reading Computers</title>
		<link>http://allthingsd.com/20111219/ibm-predicts-home-electricity-from-your-bike-mind-reading-computers/</link>
		<comments>http://allthingsd.com/20111219/ibm-predicts-home-electricity-from-your-bike-mind-reading-computers/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 20:29:37 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[battery]]></category>
		<category><![CDATA[Big Blue]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[Digital Divide]]></category>
		<category><![CDATA[electricity]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Five in Five]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[IBM Research]]></category>
		<category><![CDATA[innovations]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[mind-reading]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[PC]]></category>
		<category><![CDATA[power]]></category>
		<category><![CDATA[predictions]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[smart phones]]></category>
		<category><![CDATA[tablets]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=155065</guid>
		<description><![CDATA[Big Blue marks the end of the year by rolling out its crystal ball.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20111219/ibm-predicts-home-electricity-from-your-bike-mind-reading-computers/ibm-think-to-call-feature/" rel="attachment wp-att-155077"><img src="http://allthingsd.com/files/2011/12/IBM-think-to-call-feature-380x285.png" alt="" title="IBM-think-to-call-feature" width="380" height="285" class="alignright size-Featured wp-image-155077" /></a>There&#8217;s something about the reflective, year-end state of mind that causes tech companies and institutions (and pundits) to make predictions about what they think is plausibly in our near future.</p>
<p>One example is <a href="http://allthingsd.com/20111208/2012-siri-is-a-stunner-amazon-is-amazin-and-security-gets-spendy/">the annual tech prediction by analyst Mark Anderson</a>, which I wrote about last week. Another is IBM&#8217;s recurring &#8220;Five in Five&#8221; series, wherein Big Blue looks at the unfolding technology landscape and predicts what innovations are still just this side of &#8220;gee whiz&#8221; today, but will be commonplace within five years.</p>
<p>Think back to what we were doing in 2006, and how far things have come in that short period of time in terms of consumer and enterprise technology. The iPhone existed only as an Apple prototype. Facebook had just opened itself up to the population at large, beyond just college and university students. Twitter was just getting started. And a tablet was a <a href="http://en.wikipedia.org/wiki/Microsoft_Tablet_PC">not-terribly-popular PC design</a>.</p>
<p>As you&#8217;ll see, some of these five predictions aren&#8217;t exactly mind-blowing, especially if you pay attention to general technology trends. Over the past decade, you&#8217;ve probably already heard predictions saying that computer passwords will go away and be replaced by biometrics of some kind, whether in the form of fingerprints or voice authorization or some part of your eyeball. Also: Junk mail I actually want? That one I&#8217;ll believe when I see it. However, I really like the &#8220;think to call&#8221; idea, which sounds like a super speed-dial. </p>
<p>Anyhow, here are IBM&#8217;s predictions for stuff we&#8217;ll see by 2016, and a video explaining them in a little more detail:</p>
<blockquote class="memo"><p><strong>You will make your own energy:</strong> Anything that moves has the potential to create energy. Your running shoes, your bicycle and even the water flowing through your pipes can create energy. Advances in renewable energy technology will allow individuals and scientists to collect this energy and use it to help power our homes, offices and cities.</p>
<p><strong>You will not need a password:</strong> Your biological makeup is the key to your individual identity, and soon, it will become the key to safeguarding it. Each person&#8217;s unique biometric data such as facial definitions, retinol scans and voice files will be composited through software to build your DNA-unique online password. You will be able to log into your mobile phone or have access to an ATM machine by simply speaking your name or looking into a camera.</p>
<p><strong>Mind reading is no longer science fiction:</strong> Scientists are researching how to link your brain to your devices, such as a computer or a smartphone, so you just need to think about calling someone and it happens. Scientists have designed headsets with advanced sensors to read electrical brain activity that can recognize facial expressions, excitement and concentration levels, and thoughts of a person without them physically doing anything.</p>
<p><strong>The digital divide will cease to exist:</strong> In five years, the gap between information haves and have-nots will narrow considerably due to advances in mobile technology. Growing communities will be able to use mobile technology to provide access to essential information and better serve people with new solutions such as mobile commerce and remote healthcare.</p>
<p><strong>Junk mail will become priority mail:</strong> Think about how often we&#8217;re flooded with advertisements we consider to be irrelevant or unwanted &#8212; it doesn’t have to be that way anymore. In five years, unsolicited advertisements may feel so personalized and relevant it may seem spam is dead. Systems will be able to filter and find only the data that’s important and relevant to you and will bring you the information without you having to ask for it.</p></blockquote>
<p><iframe width="560" height="315" src="http://www.youtube.com/embed/tuisda1q6ns" frameborder="0" allowfullscreen></iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111219/ibm-predicts-home-electricity-from-your-bike-mind-reading-computers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Could Security Be HP's Unexpected Strength?</title>
		<link>http://allthingsd.com/20111219/could-security-be-hps-unexpected-strength/</link>
		<comments>http://allthingsd.com/20111219/could-security-be-hps-unexpected-strength/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 14:44:27 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[3Com]]></category>
		<category><![CDATA[ArcSight]]></category>
		<category><![CDATA[Brian Marshall]]></category>
		<category><![CDATA[earnings]]></category>
		<category><![CDATA[financial analysts]]></category>
		<category><![CDATA[Hewlett-Packard]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[ISI]]></category>
		<category><![CDATA[Meg Whitman]]></category>
		<category><![CDATA[Mercurity Interactive]]></category>
		<category><![CDATA[Opsware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TippingPoint]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=154967</guid>
		<description><![CDATA[Could security be the business that helps turn HP around? One analyst thinks so.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20111219/could-security-be-hps-unexpected-strength/hp-padlock/" rel="attachment wp-att-154979"><img src="http://allthingsd.com/files/2011/12/hp-padlock-380x285.png" alt="" title="hp-padlock" width="380" height="285" class="alignright size-Featured wp-image-154979" /></a>Hewlett-Packard is, after much mishegas in its C-Suite, on the mend. CEO Meg Whitman has set the expectation that 2012 is going to be a year devoted to getting the company back on track and, among other things, rebuilding its balance sheet after a year and change of painful twists and turns that have shaken the confidence of investors and analysts in the venerable tech giant, once considered a relative safe bet among tech stocks.</p>
<p>With its shares trading down 39 percent since the end of 2010, there&#8217;s clearly still a lot of work to be done. But analysts are taking notice and expressing new confidence. In a note to clients this morning, ISI analyst Brian Marshall says HP is looking better for a variety of reasons &#8212; one of them is its little-noticed IT security business.</p>
<p>If you break down HP&#8217;s various lines of business, you&#8217;ll find, Marshall argues, that its security assets are surprisingly strong. In 2009 and 2010, HP made two key acquisitions in the area of security: It <a href="http://allthingsd.com/20100913/hp-to-buy-arcsight-for-1-5-billion/">spent $1.5 billion for ArcSight</a>, a security software player; before that, it <a href="http://allthingsd.com/20091111/hp-to-acquire-3com/">nabbed the networking concern 3Com</a> for $2.7 billion. A key asset in that deal was TippingPoint, a network intrusion prevention product.</p>
<p>Marshall writes that HP&#8217;s security assets bring in about $1.5 billion in sales and are growing at about 30 percent year, with gross profit margins in the neighborhood of 80 percent. This compares favorably with security outfit Check Point, which trades at a multiple of about 10 times sales, Marshall says.</p>
<p>Security is going to matter a lot more to HP&#8217;s corporate customers, as they start sweating over intrusions by hackers and nation-states poking holes in the infrastructure and looking for valuable information to steal, he says.</p>
<p>If you conservatively assume that HP&#8217;s security assets are worth half as much as Check Point, or only five times sales, and then assume that they report a reasonable $2 billion in revenue in calendar 2012, (nearly 2 percent of HP&#8217;s expected total sales), you wind up with a business unit that&#8217;s worth about $10 billion, or one-fifth of HP&#8217;s market cap. Suddenly, the security push that <a href="http://allthingsd.com/20110912/hp-makes-enterprise-security-push/">HP announced in September</a> makes a lot more sense. </p>
<p>Security, Marshall says, is just one leg of a four-legged stool that HP has in its favor. The other three legs are its enterprise storage, networking and server businesses, and the &#8220;seat&#8221; of the stool which tie them all together are the software and IT services businesses. The one weakness, he concedes, is its software portfolio, which has historically been small and limited, and accounts for about 2 percent of sales despite such big acquisitions as Mercury Interactive and Opsware.</p>
<p>Even so, Marshall sees a 30 percent upside to HP&#8217;s valuation, and has pegged it with a $34 price target and Buy rating. </p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111219/could-security-be-hps-unexpected-strength/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MyForce Pushes a Panic-Button App for the Campus</title>
		<link>http://allthingsd.com/20111208/myforce-pushes-a-panic-button-app-for-the-campus/</link>
		<comments>http://allthingsd.com/20111208/myforce-pushes-a-panic-button-app-for-the-campus/#comments</comments>
		<pubDate>Thu, 08 Dec 2011 23:20:17 +0000</pubDate>
		<dc:creator>Lauren Goode</dc:creator>
				<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[app]]></category>
		<category><![CDATA[Blackberry]]></category>
		<category><![CDATA[campus]]></category>
		<category><![CDATA[college]]></category>
		<category><![CDATA[emergency]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[response]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[shootings]]></category>
		<category><![CDATA[Virginia Tech]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=152081</guid>
		<description><![CDATA[A Colorado-based security company is looking to bring a one-touch mobile app to school campuses for emergencies.]]></description>
			<content:encoded><![CDATA[<p>Today’s shootings at <a href="http://online.wsj.com/article/SB10001424052970203413304577086471652837662.html">Virginia Tech</a> are another reminder that, despite a relatively new mandate for universities to provide student communities with timely warnings in the event of danger, danger could still occur, leaving those involved feeling helpless.</p>
<p>One security company has been looking to the device many students have in their hands at all times &#8212; their smartphone &#8212; to see if a one-touch security app could mean even faster response times. <img src="http://allthingsd.com/files/2011/12/myforce_security.png" alt="" title="myforce_security" width="380" height="285" class="alignright size-full wp-image-152141" /> </p>
<p>Colorado-based MyForce has developed the MyForce Campus System, with a compatible mobile app, for university safety officials to receive alerts placed within campus borders. It provides access to such details as a student’s location, health conditions and emergency contacts. The app works on iPhone, BlackBerry and Android smartphones.</p>
<p>The app overrides the phone’s lock feature so &#8212; as long as the user has the MyForce app open &#8212; the interface will always be accessible, though the screen may dim a bit. If a user is in imminent danger, he or she can press the large button featured on the app that sends an immediate notification to MyForce and to campus security officials (provided they are equipped to use the MyForce monitoring software). MyForce also begins to pinpoint the user’s GPS location and record streaming audio from the phone. (MyForce says this information remains private in the company’s database, aside from sharing it with law enforcement officials at the time of the emergency. It can also be submitted later on as evidence of a crime.) </p>
<p>When the user sends an alert, the phone vibrates and also prompts the user to enter a PIN code &#8212; so if it’s a misfire that the user didn’t mean to send, he or she can disarm the app by entering in the PIN. At that point, MyForce says it then stops tracking the user.</p>
<p>“The one thing students always have in their hands these days is a smartphone,” said Brad Zotti, MyForce’s co-founder. The idea for the app occurred to him when he was visiting a college campus and thought about integrating the “blue light” emergency phone stands into a mobile phone. “Even if you call 911, it might take some time for your location to be recognized,&#8221; he said. &#8220;And other security apps promise to send texts or emails to your closest contacts, but who knows if or when they’ll be able to respond?” </p>
<p>MyForce is currently being used at the University of Colorado Anschutz Medical Campus and the University of Colorado at Colorado Springs. The privately owned company just signed a deal with e2Campus, another school security solutions company, to potentially bring the mobile-app version of the “blue light” system to e2Campus’ client base of around 800 schools in the U.S.   </p>
<p>Part of MyForce’s challenge will be convincing more schools to use the app. There may be some resistance on the part of school law enforcement bodies to adopt a third-party security monitoring system, and there could also be varying layers of approval needed at the administrative level.  </p>
<p>Even if administrators don’t officially opt in to the MyForce monitoring system, students and parents can still purchase the app themselves, though it may offer a less immediate response action. In that case, MyForce still offers to work with school officials to create a virtual “geo-fence” around a college campus that establishes which areas should be monitored. If a student is in danger and presses the button within that geo-fence, the alert goes to MyForce’s dashboard, and MyForce can then call campus security directly.</p>
<p>It won’t cost anything to download the mobile app, but subscriptions to MyForce cost $11.99 per month or $119 annually.</p>
<p>Since the Virginia Tech massacre in 2007, many schools have put more sophisticated emergency alert systems in place. Universities are required under the Clery Act to provide campus crime reports and timely warnings in potentially dangerous situations. </p>
<p>As we’re reminded today, there are instances in which no amount of campus security, call boxes or instantaneous mobile applications can prevent danger. And apps like MyForce rely on working wireless and data networks in order to send emergency notifications. </p>
<p>Hopefully, as the technology improves, more solutions will emerge to bring help to users in desperate situations and speed up response times even more. </p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111208/myforce-pushes-a-panic-button-app-for-the-campus/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Why Today Is a Very Good Day to Update Java on Your Computer</title>
		<link>http://allthingsd.com/20111202/why-today-is-a-very-good-day-to-update-java-on-your-computer/</link>
		<comments>http://allthingsd.com/20111202/why-today-is-a-very-good-day-to-update-java-on-your-computer/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 13:45:03 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Bain Capital Ventures]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[HD Moore]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Rapid7]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Sun]]></category>
		<category><![CDATA[Technology Crossover Ventures]]></category>
		<category><![CDATA[Tim McAdam]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=149758</guid>
		<description><![CDATA[A nasty security vulnerability in Java is likely to cause headaches at large companies with lots of PCs, because installing a fix takes a lot of time.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20111202/why-today-is-a-very-good-day-to-update-java-on-your-computer/javacrosshairs/" rel="attachment wp-att-149768"><img src="http://allthingsd.com/files/2011/12/javacrosshairs-348x285.png" alt="" title="javacrosshairs" width="348" height="285" class="alignright size-Featured wp-image-149768" /></a>Consider yourself warned: Today is a very good day to update the version of Java running on your computer. This applies to you whether you run Windows, Mac OS X or Linux. If you&#8217;ve noticed your machine suggesting that you update Java, do it right away.</p>
<p>The reason? A scary vulnerability in Java that was detected over the summer, and which Oracle has subsequently fixed, is being exploited by people who create the malware and crimeware that causes so many headaches for home users and corporate IT departments.</p>
<p>The risk is especially acute at large companies with big fleets of desktops and notebooks to manage. If you&#8217;re a home user, the patch is easy to install. But most employees don&#8217;t have administrative privileges on their work desktops or notebooks, so someone from the IT department has to come and install the patch for them. </p>
<p>That&#8217;s a big, time-consuming process, says HD Moore, chief security officer at Rapid7, a Cambridge, Mass-based company that specializes in helping companies stay ahead of new computer security vulnerabilities. He&#8217;s also the chief architect of <a href="http://metasploit.com/">Metasploit</a>, which Rapid7 owns. </p>
<p>One of the reasons this particular vulnerability is so bad is that even after it was detected and fixed, it wasn&#8217;t fully understood how dangerous it is, Moore says. Crimeware creators somehow figured it out ahead of most security researchers, and started adding code to Web sites designed to take advantage of it. And that&#8217;s especially dangerous at this time of the year, when people are shopping online both at home and the office. &#8220;It&#8217;s kind of like a perfect storm,&#8221; Moore told me yesterday. Add to that the fact that many companies have IT staff taking vacation during the holiday season, and the timing couldn&#8217;t be worse.</p>
<p>Enterprise is historically bad at patching Java vulnerabilities anyway, because it doesn&#8217;t have the same automatic update tools that Windows or Adobe Flash does. &#8220;The tools for patching Java aren&#8217;t that great,&#8221; Moore told me. &#8220;A Java update just isn&#8217;t treated with the same fervor as a Windows update.&#8221;</p>
<p>So how bad is this one? The National Vulnerability Database <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3544">rates it a 10</a> out of 10 on the severity scale, and also rates it as &#8220;low&#8221; on the access complexity scale &#8212; meaning it&#8217;s really easy for the bad guys to carry out an attack using it.</p>
<p>Security blogger Brian Krebs discovered the vulnerability <a href="http://krebsonsecurity.com/2011/11/new-java-attack-rolled-into-exploit-kits/">being &#8220;weaponized,&#8221;</a> that is, built into the software that computer criminals buy on the black market. For instance, those who have bought something called the Blackhole Exploit Kit, a $4,000 software toolkit used to target Windows machines, are getting automatic updates that include tools to take advantage of the Java vulnerability.</p>
<p>What to do until you can get all your machines updated with the latest version of Java? Simple, really: Disable it and block it at the firewall, until all the machines on the network that need the update have it, Moore says. </p>
<p>Rapid7, incidentally, is a security company on the rise. Just last month it raised a <a href="http://www.rapid7.com/news-events/press-releases/2011/2011-tcv-funding.jsp">$50 million series C round</a> of funding, led by Technology Crossover Ventures and joined by previous investors Bain Capital Ventures; Tim McAdam, a TCV partner, joined Rapid7&#8242;s board.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111202/why-today-is-a-very-good-day-to-update-java-on-your-computer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Carrier IQ: How to Hack Back Your Phone</title>
		<link>http://allthingsd.com/20111202/carrier-iq-how-to-hack-back-your-phone/</link>
		<comments>http://allthingsd.com/20111202/carrier-iq-how-to-hack-back-your-phone/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 13:30:29 +0000</pubDate>
		<dc:creator>Lauren Goode</dc:creator>
				<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Al Franken]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Blackberry]]></category>
		<category><![CDATA[Carrier IQ]]></category>
		<category><![CDATA[carriers]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[HTC]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iOS 5]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Research In Motion]]></category>
		<category><![CDATA[RIM]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[smartphones]]></category>
		<category><![CDATA[Sprint]]></category>
		<category><![CDATA[Trevor Eckhart]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=149602</guid>
		<description><![CDATA[Worried about smartphone software that tracks your keystrokes? Here's what to do.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20111202/carrier-iq-how-to-hack-back-your-phone/youve_been_hacked1/" rel="attachment wp-att-149710"><img src="http://allthingsd.com/files/2011/12/Youve_Been_Hacked1-380x215.png" alt="" title="Youve_Been_Hacked1" width="380" height="215" class="alignright size-medium wp-image-149710" /></a></p>
<p>The findings of a Connecticut-based systems administrator have sparked <a href="http://allthingsd.com/20111201/carrier-iq-improves-my-wireless-service-by-logging-my-keystrokes-please-explain/">alarm</a> in millions of smartphone users, after security researcher Trevor Eckhart published a video showing how a cellphone software company has the ability to log users&#8217; Web searches and keystrokes.</p>
<p>The technology, made by Carrier IQ, is currently deployed on more than 150 million devices worldwide.  </p>
<p>Research In Motion and HTC &#8212; the maker of the phone targeted in the security demo &#8212; have issued <a href="http://allthingsd.com/20111201/rim-htc-on-carrier-iq-blame-the-carriers/">statements</a> denying that Carrier IQ is preinstalled on their devices. Meanwhile, U.S. Sen. Al Franken (D-Minn.) has sent a letter to Carrier IQ seeking more information on what the software does.</p>
<p>Carrier IQ has <a href="http://allthingsd.com/20111201/carrier-iq-speaks-our-software-monitors-service-messages-ignores-other-data/">told </a><strong>AllThingsD</strong> that while its software has the ability to receive a tremendous amount of information, some of which could be relayed to a carrier for diagnostics purposes, the company doesn&#8217;t log keystrokes and the software is not being used to gather intelligence about the phone&#8217;s user. </p>
<p>But while we wait for more answers, what&#8217;s a smartphone user to do? </p>
<p><strong>Google Android Phones</strong>: If you&#8217;re wondering whether your Google Android phone might have Carrier IQ installed on it, Eckhart, the researcher behind all of this, points people to a Logging Test <a href="https://market.android.com/details?id=com.treve.loggingkey#?t=W251bGwsMSwxLDIxMiwiY29tLnRyZXZlLmxvZ2dpbmdrZXkiXQ">app</a> that he claims can be used to verify &#8220;what logging is being done on your phone and where the data is going to.&#8221; If successfully installed &#8212; which we hear may take some finagling, including emailing the app link to yourself to access it, and &#8220;rooting&#8221; your phone first &#8212; the $1 app is meant to detect Carrier IQ and remove it.  </p>
<p>According to his <a href="http://forum.xda-developers.com/showpost.php?p=17612559&#038;postcount=110">blog</a> post, Eckhart has tested this app on the HTC Evo 3D phone; he believes it works on the Sprint Evo 4G and HTC Thunderbolt, as well.  </p>
<p>But since the Google Android operating system runs on devices from multiple manufacturers, it is not known at this point which models could be running Carrier IQ and which ones are not.  </p>
<p>It should be noted that some manufacturers have denied responsibility for the app; HTC, for example, has put the blame on wireless carriers, and basically advises HTC phone owners to contact their carriers. The company did add it was looking into an option for allowing its customers to opt out of the Carrier IQ application, but no further details were given beyond that.  </p>
<p>Sprint has not yet responded to my inquiry as to whether the wireless company was actively involved in the installation of Carrier IQ, or how users might disable such applications on Sprint. AT&#038;T said it uses Carrier IQ solely to improve its network performance; Verizon claims not to use it at all, although my colleague John Paczkowski reports that may not be the case.</p>
<p><strong>RIM BlackBerrys</strong>: While RIM hasn&#8217;t explicitly pointed to wireless carriers as HTC did, the BlackBerry maker also denies any involvement with Carrier IQ, stating &#8220;RIM does not pre-install the CarrierIQ app on BlackBerry smartphones or authorize its carrier partners to install the CarrierIQ app before sales or distribution.&#8221;</p>
<p>However, the next part of RIM&#8217;s <a href="http://supportforums.blackberry.com/t5/Java-Development/Does-CarrierIQ-run-on-BlackBerry-devices/m-p/1439275#M183840">statement</a> on the BlackBerry developers forum indicates that it’s possible Carrier IQ could live on a BlackBerry device.</p>
<p>According to BlackBerry Development Advisor Mark Sohm: &#8220;If the Carrier IQ application is present on a BlackBerry smartphone, it does not mean that the Carrier IQ application has &#8216;hacked&#8217; the BlackBerry platform. It means that either the BlackBerry smartphone user or the user&#8217;s BlackBerry Enterprise Server admin explicitly installed the application and authorized it to run.&#8221;</p>
<p>In other words, if it&#8217;s on your phone, you may have granted it access in some way, shape, form or click of your Qwerty keypad. </p>
<p><strong>Apple iPhones</strong>: Apple has issued a <a href="http://allthingsd.com/20111201/apple-we-stopped-supporting-carrieriq-with-ios-5/">statement </a>to <strong>AllThingsD</strong> declaring that the company stopped supporting Carrier IQ with iOS 5, its latest version of mobile software, and plans to remove it from future mobile software updates, too.</p>
<p>But what if you&#8217;re running an earlier version of iOS on your iPhone and are worried about where your data is going? Apparently, you can opt out of having your usage data submitted for diagnostics. To do that, go to to Settings → General → About → Diagnostics &#038; Usage. Select &#8220;Don&#8217;t Send.&#8221;</p>
<p>More info to come as I get it.</p>
<p><blockquote class="memo" style="background:#faf5e5;font-style:normal;"><p>
<strong>Related Posts on Carrier IQ:</strong></p>
<ul>
<li><a href="http://allthingsd.com/20111213/carrier-iq-gets-transparent-about-its-mobile-monitoring/">Exclusive Interview: Carrier IQ Gets Transparent About Its Mobile Monitoring</a></li>
<li><a href="http://allthingsd.com/20111202/carrier-iq-how-to-hack-back-your-phone/?mod=snippet">Carrier IQ: How to Hack Back Your Phone<br />
</a></li>
<li><a href="http://allthingsd.com/20111201/carrier-iq-speaks-our-software-monitors-service-messages-ignores-other-data/?mod=snippet">Carrier IQ Speaks: Our Software Monitors Service Messages, Ignores Other Data</a></li>
<li><a href="http://allthingsd.com/20111201/apple-we-stopped-supporting-carrieriq-with-ios-5/?mod=snippet">Apple: We Stopped Supporting Carrier IQ With iOS 5</a></li>
<li><a href="http://allthingsd.com/20111201/rim-htc-on-carrier-iq-blame-the-carriers/?mod=snippet"> RIM, HTC, Google on Carrier IQ: Blame the Carriers</a></li>
<li><a href="http://allthingsd.com/20111201/carrier-iq-improves-my-wireless-service-by-logging-my-keystrokes-please-explain/?mod=snippet"> Carrier IQ Improves My Wireless Service by Logging My Keystrokes? Please Explain.</a></li>
</ul>
<p style="text-align:center; margin: 15px 0 15px 0;"><a href="http://allthingsd.com/tag/carrier-iq/?mod=snippet" class="btn-link">Full Carrier IQ Coverage &raquo;</a></p>
</blockquote>
</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111202/carrier-iq-how-to-hack-back-your-phone/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>HP Memo Spanks Columbia Researchers Over Flaming Printers Flap</title>
		<link>http://allthingsd.com/20111130/hp-memo-spanks-columbia-researchers-over-flaming-printers-flap/</link>
		<comments>http://allthingsd.com/20111130/hp-memo-spanks-columbia-researchers-over-flaming-printers-flap/#comments</comments>
		<pubDate>Wed, 30 Nov 2011 19:45:26 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Columbia University]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Hewlett-Packard]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[imaging and printing]]></category>
		<category><![CDATA[printers]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[VJ Joshi]]></category>
		<category><![CDATA[Vyomesh (VJ) Joshi]]></category>
		<category><![CDATA[Vyomesh Joshi]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=148698</guid>
		<description><![CDATA[No, a hacked HP printer can't burn down your house or office, but HP has a fix in the works anyway.]]></description>
			<content:encoded><![CDATA[<p><img src="http://allthingsd.com/files/2011/11/springsteen-fire-feature-380x285.png" alt="" title="springsteen-fire-feature" width="380" height="285" class="alignright size-Featured wp-image-148769" />Hewlett-Packard is still doing a little damage control from an <a href="http://redtape.msnbc.msn.com/_news/2011/11/29/9076395-exclusive-millions-of-printers-open-to-devastating-hack-attack-researchers-say">MSNBC story</a> that emerged yesterday citing researchers at Columbia University saying essentially that HP printers could be hacked in such a way as to make them burst into flames. HP has denied most of the claims.</p>
<p>Printers are Internet-connected devices just like computers. They have their own operating systems and software, and so, in theory, are vulnerable to attacks by hackers just as computers are. There was an old urban myth that in the run-up to the first Iraq War in 1991, hacked HP printers shipped to Iraq were instrumental in shutting down Iraqi radar systems. It wasn&#8217;t true &#8212; it was published on April 1 of that year by the trade magazine InfoWorld &#8212; but the idea stuck, and at least one group of security researchers <a href="http://www.infoworld.com/t/intrusion-detection-and-prevention/attack-the-trojan-printers-331">has been studying the use</a> of Trojans installed into printers.</p>
<p>The Columbia researchers had claimed that a part inside a printer called a fuser, used to dry the ink, could be remotely instructed to overheat, eventually causing paper inside the printer to turn brown and start to smoke. </p>
<p>Conceptually it&#8217;s not that different from the Stuxnet attack against the Iranian nuclear research program. The attackers in that case, thought to be Israel with a little help from the U.S., attacked industrial control computers known as SCADA systems that serve as the bridge between typical Windows-based machines and industrial equipment that the SCADA systems control. In the case of Stuxnet, the SCADA systems were controlled &#8212; often they have only default passwords or no passwords at all &#8212; and the machines they were connected to could be instructed to literally destroy themselves. </p>
<p>Some researchers at the U.S. Department of Energy&#8217;s Idaho National Lab did just that in the video below, showing in a controlled environment that a generator could be hijacked over the Internet and <a href="http://www.youtube.com/watch?v=fJyWngDco3g">made to destroy itself.</a></p>
<p>But could you do the same thing with a printer? Theoretically, I&#8217;d say it&#8217;s possible. But in this case, HP says not where its printers are concerned.  </p>
<p>Below is an internal HP memo from Vyomesh &#8220;VJ&#8221; Joshi, the head of HP&#8217;s Imaging and Printing Group, that was circulated to employees today.</p>
<p>First off, he says, the fire issue is not true. As noted in the public statement, HP&#8217;s printers have a component called a thermal breaker that prevents the fuser from overheating, and it can&#8217;t be overcome by a firmware upgrade.</p>
<p>But Joshi also spanks the Columbia researchers for turning to the media and not calling HP first, which is the way security researchers usually operate when they identify a serious vulnerability. There is, he concedes, a vulnerability to malicious firmware modifications, especially on printers that are left unprotected on a network without a firewall running. HP aims to fix that. But usually in these situations, the media doesn&#8217;t get called until a fix is ready. &#8220;Unfortunately in this situation, a Columbia representative took it upon himself to contact the media and reports were published prior to a solution being available,&#8221; he writes.</p>
<p>Joshi&#8217;s full memo is below.</p>
<blockquote class="memo"><p><strong>From: IPG, Vyomesh Joshi<br />
Sent: Tuesday, November 29, 2011 4:40 PM<br />
Subject: Inaccurate Printer Security Press Coverage</strong></p>
<p>Dear IPG Employees,</p>
<p>As many of you have read today there has been sensational and inaccurate press coverage regarding potential security risks with some HP LaserJet printers.  I wanted to make sure you had the most current information and context for this situation.  No customer has reported unauthorized access. We have also seen speculation in the media regarding the potential for devices to catch fire due to a firmware change.  This claim is inaccurate.  We have issued a <a href="http://www.hp.com/hpinfo/newsroom/press/2011/111129b.html">public statement</a> communicating to customers and partners and refuting inaccurate information.</p>
<p>This information first came to us late last week from a research lab based at Columbia University.  As a result, we have identified a specific vulnerability exists for some HP LaserJet devices if placed on a public internet without a firewall or if a malicious effort is made to modify the firmware of the device by a trusted party on the network. Our security team is taking immediate measures to build a firmware upgrade to resolve any potential risk and will be communicating this proactively to customers and partners who may be impacted.</p>
<p>Typically when a security issue is identified, responsible disclosure is followed so that vulnerabilities are not made public until a solution is available.  Unfortunately in this situation, a Columbia representative took it upon himself to contact the media and reports were published prior to a solution being available.</p>
<p>We have always taken security very seriously. In fact, HP’s reputation for security continues to be among the highest in the industry. I want to assure you that our security experts are working around the clock to mitigate any potential risk.</p>
<p>We will make every effort to communicate new information as it becomes available.</p>
<p>Regards,</p>
<p>VJ</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111130/hp-memo-spanks-columbia-researchers-over-flaming-printers-flap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter Buys Security Hacker's Android Start-Up</title>
		<link>http://allthingsd.com/20111128/twitter-buys-security-hackers-android-start-up/</link>
		<comments>http://allthingsd.com/20111128/twitter-buys-security-hackers-android-start-up/#comments</comments>
		<pubDate>Mon, 28 Nov 2011 19:42:46 +0000</pubDate>
		<dc:creator>Liz Gannes</dc:creator>
				<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Social]]></category>
		<category><![CDATA[acquisition]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Moxie Marlinspike]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Start-up]]></category>
		<category><![CDATA[Stuart Anderson]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Whisper Systems]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=147721</guid>
		<description><![CDATA[Twitter has acquired Whisper Systems, a small mobile security start-up founded last year by security hacker Moxie Marlinspike.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-147733" title="MoxieMarlinspike" src="http://allthingsd.com/files/2011/11/MoxieMarlinspike.png" alt="" width="157" height="169" />Twitter has acquired <a href="http://www.whispersys.com/">Whisper Systems</a>, a small mobile security start-up, for its &#8220;technology and expertise,&#8221; according to <a href="http://www.whispersys.com/updates.html">the Whisper Systems blog</a> (via <a href="http://thenextweb.com/twitter/2011/11/28/twitter-acquires-mobile-data-security-gurus-whisper-systems/">The Next Web</a>).</p>
<p>The company was founded last year by security hacker <a href="http://en.wikipedia.org/wiki/Moxie_Marlinspike">Moxie Marlinspike</a> (pictured) and robotics researcher Stuart Anderson. It offered software for Android phones that secured user data, created firewalls and encrypted calls and texts.</p>
<p>Whisper said its products would &#8220;live on&#8221; post-acquisition but would be taken offline for the moment.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111128/twitter-buys-security-hackers-android-start-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IBM Launches Service to Secure Smart Phones at the Office</title>
		<link>http://allthingsd.com/20111111/ibm-launches-service-to-secure-smart-phones-at-the-office/</link>
		<comments>http://allthingsd.com/20111111/ibm-launches-service-to-secure-smart-phones-at-the-office/#comments</comments>
		<pubDate>Fri, 11 Nov 2011 13:46:50 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Blackberry]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Research In Motion]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[smart phones]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=143152</guid>
		<description><![CDATA[You know that smartphone you just got that you use to check your office email? The one the guy in the IT department grumbled about? IBM wants to give that guy one less thing to complain about.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20111111/ibm-launches-service-to-secure-smart-phones-at-the-office/smartphoneswpedia/" rel="attachment wp-att-143154"><img src="http://allthingsd.com/files/2011/11/smartphoneswpedia-380x285.png" alt="" title="smartphoneswpedia" width="380" height="285" class="alignright size-Featured wp-image-143154" /></a>It&#8217;s not exactly a news flash that IT administrators are struggling with one big new demand from their bosses and employees right now. It&#8217;s often referred to as the &#8220;consumerization of IT,&#8221; a phrase I generally dislike. But in practice it means that corporate IT departments are being pushed and pressured to support pretty much any mobile device that an employee wants to use.</p>
<p>Gone are the days when you&#8217;d get a company-issued BlackBerry and laptop locked down and secured to within an inch of its life. Now, everyone &#8212; from the CEO and the board of directors on down to interns &#8212; expect to get their corporate email, access to internal corporate networks and documents on their personal iPads, iPhones and Android devices.</p>
<p>IBM today announced a new service aimed at helping IT admins get control of the devices they&#8217;re being asked to support. Big Blue calls it IBM Hosted Mobile Device Security, and its capabilities include making sure personal devices comply with corporate security policies, protecting them against malware, tracking user activity and making sure network connections are secured. It&#8217;s working with Juniper Networks on the service. And it covers pretty much every smartphone platform you can think of: Apple&#8217;s iOS, Android, BlackBerry, Nokia&#8217;s Symbian, and Microsoft&#8217;s Windows Mobile.</p>
<p>The BYOD &#8212; or &#8220;bring your own device&#8221; &#8212; trend is the sort of thing that gives IT administrators night sweats. A <a href="http://www.kace.com/about/releases/09_13_11.php">Dell Kace survey</a> of 750 IT managers found that 87 percent of companies have employees using some kind  of personal device accessing a corporate network. The same survey found that 62 percent of IT admins feel they don&#8217;t have the tools to properly manage them all.</p>
<p>Phones get lost, for one thing. A lost phone that can still access confidential information is a liability. And worse, because of the value of information they can store and access, hackers are paying more attention to mobile devices than ever before. A study by IBM projects that the number of software weaknesses that can give a criminal access to data stored on or accessed by a phone or tablet will double this year over 2010. More or less nonexistent as recently as 2006, IBM&#8217;s X-Force security unit tracked 15 exploits last year and expects to see more than 30 this year. And malware on the Android platform is also <a href="http://allthingsd.com/20110802/android-malware-on-the-rise/">on the rise</a>.</p>
<p>If it sounds like a business opportunity, you&#8217;re right. Mobile security companies have been springing up. <a href="http://allthingsd.com/20111018/mobile-security-firm-lookout-expands-to-the-iphone/">Lookout Security</a> is one that comes to mind. As mobile devices multiply, especially with <a href="http://allthingsd.com/20111103/if-you-are-under-45-chances-are-you-have-a-smartphone/">younger people just entering the workforce</a>, you can expect to see a lot more activity from companies large and small around making sure they&#8217;re secure. As is often the case with IT security, some of that will be wasted effort, because too often security is something you consider only after something bad has happened, not before. But not always.</p>
<p><em>(Image from <a href="http://en.wikipedia.org/wiki/Smartphone">Wikipedia</a>.)  </em></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111111/ibm-launches-service-to-secure-smart-phones-at-the-office/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Admits It Is Saying Buh-Bye to Flash for Mobile Devices</title>
		<link>http://allthingsd.com/20111109/adobe-admits-its-saying-buh-bye-to-flash-for-mobile-devices/</link>
		<comments>http://allthingsd.com/20111109/adobe-admits-its-saying-buh-bye-to-flash-for-mobile-devices/#comments</comments>
		<pubDate>Wed, 09 Nov 2011 18:15:30 +0000</pubDate>
		<dc:creator>Kara Swisher</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Air]]></category>
		<category><![CDATA[Amazon Appstore]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Android Market]]></category>
		<category><![CDATA[app]]></category>
		<category><![CDATA[App Store]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Blackberry]]></category>
		<category><![CDATA[BlackBerry App World]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[browsing]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[chipset]]></category>
		<category><![CDATA[compatibility]]></category>
		<category><![CDATA[competitive]]></category>
		<category><![CDATA[content]]></category>
		<category><![CDATA[CSS Shaders]]></category>
		<category><![CDATA[development]]></category>
		<category><![CDATA[device]]></category>
		<category><![CDATA[entertainment]]></category>
		<category><![CDATA[featured post]]></category>
		<category><![CDATA[flagship]]></category>
		<category><![CDATA[Flash]]></category>
		<category><![CDATA[Flash Player 11]]></category>
		<category><![CDATA[Flash Player 12]]></category>
		<category><![CDATA[gaming]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[HTML5]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iTunes]]></category>
		<category><![CDATA[maker]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[native]]></category>
		<category><![CDATA[PC]]></category>
		<category><![CDATA[platform]]></category>
		<category><![CDATA[PlayBook]]></category>
		<category><![CDATA[plug-in]]></category>
		<category><![CDATA[post]]></category>
		<category><![CDATA[premium]]></category>
		<category><![CDATA[product]]></category>
		<category><![CDATA[Research In Motion]]></category>
		<category><![CDATA[RIM]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[source code]]></category>
		<category><![CDATA[Steve Jobs]]></category>
		<category><![CDATA[Store]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[version]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=142353</guid>
		<description><![CDATA[Looks like Apple's Steve Jobs was right (as usual).]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20111109/adobe-admits-its-saying-buh-bye-to-flash-for-mobile-devices/buh-bye/" rel="attachment wp-att-142354"><img src="http://allthingsd.com/files/2011/11/buh-bye.png" alt="" title="buh-bye" width="480" height="480" class="alignright size-full wp-image-142354" /></a></p>
<p>In a <a href="http://blogs.adobe.com/conversations/2011/11/flash-focus.html">blog post by one of its execs</a>, titled &#8220;Flash to Focus on PC Browsing and Mobile Apps; Adobe to More Aggressively Contribute to HTML5,&#8221; Adobe said what had already been reported: That it would no longer be developing its well-known Flash for mobile devices.</p>
<p>Here&#8217;s the key graph:</p>
<p>&#8220;Our future work with Flash on mobile devices will be focused on enabling Flash developers to package native apps with Adobe AIR for all the major app stores. We will no longer continue to develop Flash Player in the browser to work with new mobile device configurations (chipset, browser, OS version, etc.) following the upcoming release of Flash Player 11.1 for Android and BlackBerry PlayBook. We will of course continue to provide critical bug fixes and security updates for existing device configurations. We will also allow our source code licensees to continue working on and release their own implementations.&#8221;</p>
<p>Last night, <a href="http://allthingsd.com/20111108/gone-in-a-flash-adobe-said-halting-development-on-mobile-version-of-its-plug-in/">reports surfaced</a> that the high-profile software company &#8212; whose Flash technology has been a flagship product &#8212; was halting development on the mobile version of its browser plug-in.</p>
<p>Now, Adobe will focus its PC Web browser business on tools that allow Flash developers to create mobile apps by packaging their code to run on Adobe&#8217;s AIR platform.</p>
<p>The move has big implications for Adobe going forward and also for mobile device makers, such as Google and Research In Motion. But <a href="http://allthingsd.com/20111109/horse-flash-apples-steve-jobs-on-adobe-vendetta-in-2010-at-d8-video/">not Apple</a>.</p>
<p>As Ina Fried wrote: </p>
<p>&#8220;The move, if true, would be a major blow to Android device makers, who have long touted Flash compatibility as a key competitive advantage over Apple&#8217;s iPhone and iPad.</p>
<p>It would also mark a posthumous vindication for former Apple CEO Steve Jobs, who took a controversial stand by not supporting Flash on Apple&#8217;s mobile products.&#8221;</p>
<p>Turns out Jobs was prescient, as usual.</p>
<p>Here is the full version of the Adobe blog:</p>
<blockquote class="memo"><p><strong>Flash to Focus on PC Browsing and Mobile Apps; Adobe to More Aggressively Contribute to HTML5</strong></p>
<p>POSTED BY DANNY WINOKUR, VICE PRESIDENT &#038; GENERAL MANAGER, INTERACTIVE DEVELOPMENT AT ADOBE ON NOVEMBER 9, 2011 5:59 AM IN BUSINESS PROFESSIONALS, CREATIVE PROFESSIONALS, DEVELOPERS, VIDEO</p>
<p>Adobe is all about enabling designers and developers to create the most expressive content possible, regardless of platform or technology. For more than a decade, Flash has enabled the richest content to be created and deployed on the web by reaching beyond what browsers could do. It has repeatedly served as a blueprint for standardizing new technologies in HTML. Over the past two years, we&#8217;ve delivered Flash Player for mobile browsers and brought the full expressiveness of the web to many mobile devices.</p>
<p>However, HTML5 is now universally supported on major mobile devices, in some cases exclusively. This makes HTML5 the best solution for creating and deploying content in the browser across mobile platforms. We are excited about this, and will continue our work with key players in the HTML community, including Google, Apple, Microsoft and RIM, to drive HTML5 innovation they can use to advance their mobile browsers.</p>
<p>Our future work with Flash on mobile devices will be focused on enabling Flash developers to package native apps with Adobe AIR for all the major app stores. We will no longer continue to develop Flash Player in the browser to work with new mobile device configurations (chipset, browser, OS version, etc.) following the upcoming release of Flash Player 11.1 for Android and BlackBerry PlayBook. We will of course continue to provide critical bug fixes and security updates for existing device configurations. We will also allow our source code licensees to continue working on and release their own implementations.</p>
<p>These changes will allow us to increase investment in HTML5 and innovate with Flash where it can have most impact for the industry, including advanced gaming and premium video. Flash Player 11 for PC browsers just introduced dozens of new features, including hardware accelerated 3D graphics for console-quality gaming and premium HD video with content protection. Flash developers can take advantage of these features, and all that our Flash tooling has to offer, to reach more than a billion PCs through their browsers and to package native apps with AIR that run on hundreds of millions of mobile devices through all the popular app stores, including the iTunes App Store, Android Market, Amazon Appstore for Android and BlackBerry App World.</p>
<p>We are already working on Flash Player 12 and a new round of exciting features which we expect to again advance what is possible for delivering high definition entertainment experiences.  We will continue to leverage our experience with Flash to accelerate our work with the W3C and WebKit to bring similar capabilities to HTML5 as quickly as possible, just as we have done with CSS Shaders.  And, we will design new features in Flash for a smooth transition to HTML5 as the standards evolve so developers can confidently invest knowing their skills will continue to be leveraged.</p>
<p>We are super excited about the next generations of HTML5 and Flash.  Together they offer developers and content publishers great options for delivering compelling web and application experiences across PCs and devices. There is already amazing work being done that is pushing the newest boundaries, and we can&#8217;t wait to see what is still yet to come!</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111109/adobe-admits-its-saying-buh-bye-to-flash-for-mobile-devices/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facing Real-World Violence, Anonymous Backs Down From Drug Cartel</title>
		<link>http://allthingsd.com/20111102/facing-real-world-violence-anonymous-backs-down-against-drug-cartel/</link>
		<comments>http://allthingsd.com/20111102/facing-real-world-violence-anonymous-backs-down-against-drug-cartel/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 13:09:25 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[anonymous]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[luzsec]]></category>
		<category><![CDATA[Mexico]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Zetas]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=139333</guid>
		<description><![CDATA[A planned campaign by the hacking troupe Anonymous against a Mexican drug cartel is called off. The threat of getting arrested is one thing. The all-too-real threat of getting killed is quite another.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20110719/fbi-moves-on-anonymous-in-new-york-and-california/anonymous_at_scientology_in_los_angeles/" rel="attachment wp-att-99962"><img src="http://allthingsd.com/files/2011/07/anonymous_at_scientology_in_los_angeles-380x285.png" alt="" title="anonymous_at_scientology_in_los_angeles" width="380" height="285" class="alignright size-Featured wp-image-99962" /></a>The hacking troupe Anonymous has apparently decided to call off a planned campaign to out associates of the Mexican drug cartel Los Zetas. The campaign had been set to begin on Nov. 5.</p>
<p>In a weird sort of mash-up of villains, one decidedly more evil than the other, a Mexican affiliate of Anonymous Veracruz announced that it was going to start publishing the names and addresses of the cartel&#8217;s business associates in response to the kidnapping of an Anonymous member. Anonymous had accused taxi drivers, police officers and journalists of being Zeta &#8220;servants.&#8221;</p>
<p>Of course, the publication of that information would give an advantage to rival cartels, who would probably have them whacked. According to a report on <a href="http://www.stratfor.com/analysis/20111101-dispatch-implications-online-tactics-against-mexican-cartels">Stratfor</a>, the Zetas had taken the threat seriously enough that the cartel dispatched its own computer experts to track down the people behind various anti-cartel blogs. A few people have been killed.</p>
<p>Having hassled <a href="http://allthingsd.com/20110604/sony-hacked-for-what-seems-to-be-the-umpteenth-time/">Sony over the summer</a>, attacked targets as varied as <a href="http://allthingsd.com/20110721/anonymous-hacks-nato-steals-lame-documents/">NATO </a>and the <a href="http://allthingsd.com/20110613/lulzsec-strikes-again-hits-bethesda-softworks-and-u-s-senate/">U.S. Senate</a>, and posted the addresses of <a href="http://allthingsd.com/20110624/arizona-confirms-lulzsec-docs-are-authentic-worries-about-officer-safety/">state cops in Arizona</a>, all Anonymous seems to have accomplished is getting some of its <a href="http://allthingsd.com/20110801/uk-police-say-this-is-the-face-of-lulzsec-hacker-known-as-topiary/">lesser members arrested</a>.</p>
<p><a href="http://idealab.talkingpointsmemo.com/2011/11/report-anonymous-cancels-operation-cartel.php">TalkingPointsMemo</a> has a pretty good rundown. Basically, it comes down to this: Anonymous didn&#8217;t have the stomach for real-world violence.</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111102/facing-real-world-violence-anonymous-backs-down-against-drug-cartel/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers Press the "Schmooze" Button</title>
		<link>http://allthingsd.com/20111031/hackers-press-the-schmooze-button/</link>
		<comments>http://allthingsd.com/20111031/hackers-press-the-schmooze-button/#comments</comments>
		<pubDate>Mon, 31 Oct 2011 12:00:44 +0000</pubDate>
		<dc:creator>Suzanne Kapner</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Voices]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Suzanne Kapner]]></category>
		<category><![CDATA[The Wall Street Journal]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=138128</guid>
		<description><![CDATA[Chris Patten called a large investment-management firm to report that he was going through a divorce and was worried that his wife had set up an account under a false name.]]></description>
			<content:encoded><![CDATA[<p>Chris Patten called a large investment-management firm to report that he was going through a divorce and was worried that his wife had set up an account under a false name.</p>
<p>And with that story &#8212; entirely plausible but in this case a lie &#8212; a customer-service representative turned over customer account numbers and other details with a readiness that makes banks and other companies cringe.</p>
<p>Mr. Patten, a 35-year-old cybersecurity expert who was with the U.S. Air Force before he started working for a consulting firm in Kansas City, Mo., didn&#8217;t actually use or sell the data, which he gathered in running a test for the investment firm of its security arrangements. But the ease with which the employee was persuaded to divulge the information points to a troubling trend, security experts and law enforcement officials say.</p>
<p><a href="http://online.wsj.com/article/SB10001424052970203911804576653393584528906.html?mod=WSJ_Tech_LEFTTopNews">Read the rest of this post on the original site &#187;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111031/hackers-press-the-schmooze-button/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google's High-Profile Los Angeles Deal Faces Criticism</title>
		<link>http://allthingsd.com/20111020/googles-high-profile-los-angeles-deal-faces-criticism/</link>
		<comments>http://allthingsd.com/20111020/googles-high-profile-los-angeles-deal-faces-criticism/#comments</comments>
		<pubDate>Thu, 20 Oct 2011 22:18:36 +0000</pubDate>
		<dc:creator>John Letzing</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Voices]]></category>
		<category><![CDATA[Computer Sciences Corp.]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Apps]]></category>
		<category><![CDATA[John Letzing]]></category>
		<category><![CDATA[Los Angeles]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[The Wall Street Journal]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=135143</guid>
		<description><![CDATA[Google Inc. has been unable to provide more than a third of Los Angeles city employees with its Apps software because of security concerns, highlighting difficulties the search giant faces as it tries to create revenue streams outside of its core business.]]></description>
			<content:encoded><![CDATA[<p>Google Inc. has been unable to provide more than a third of Los Angeles city employees with its Apps software because of security concerns, highlighting difficulties the search giant faces as it tries to create revenue streams outside of its core business.</p>
<p>On Wednesday, Los Angeles City Council member Dennis Zine filed a motion requesting a status report on Google&#8217;s contract with the city. Google and Computer Sciences Corp., its partner implementing Apps, have been unable to meet the security requirements of the city&#8217;s police department, Mr. Zine wrote in the motion.</p>
<p><a href="http://online.wsj.com/article/SB10001424052970204485304576643303722921250.html">Read the rest of this post on the original site »</a></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111020/googles-high-profile-los-angeles-deal-faces-criticism/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mobile Security Firm Lookout Expands to the iPhone</title>
		<link>http://allthingsd.com/20111018/mobile-security-firm-lookout-expands-to-the-iphone/</link>
		<comments>http://allthingsd.com/20111018/mobile-security-firm-lookout-expands-to-the-iphone/#comments</comments>
		<pubDate>Tue, 18 Oct 2011 14:20:11 +0000</pubDate>
		<dc:creator>Ina Fried</dc:creator>
				<category><![CDATA[Mobile]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[John Hering]]></category>
		<category><![CDATA[Lookout]]></category>
		<category><![CDATA[Lookout Mobile Security]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[smartphones]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=133386</guid>
		<description><![CDATA[After spending the last many months working to secure Android, Lookout Mobile Security is expanding onto the iPhone.]]></description>
			<content:encoded><![CDATA[<p>After spending the last many months working to secure Android, Lookout Mobile Security is expanding onto the iPhone.</p>
<p><img src="http://allthingsd.com/files/2011/10/Screen-Shot-2011-10-18-at-7.18.11-AM-380x274.png" alt="" title="Screen Shot 2011-10-18 at 7.18.11 AM" width="380" height="274" class="alignright size-Medium380 wp-image-133395" /></p>
<p>The company announced a new free app aimed at delivering protection for iPhone users, including help finding lost devices and protecting against attacks on iPhones that are still safe in their users&#8217; hands. While the iPhone app is similar to what the company has offered for Android, there are some key differences.</p>
<p>&#8220;It’s not something where we have just taken the Android product and plopped it on the iPhone,&#8221; Lookout CEO John Hering said in an interview. One feature the company is not able to offer for the iPhone is its <a href="http://allthingsd.com/20110302/lookouts-new-plan-b-app-allows-users-to-find-an-already-lost-phone/">Plan B software</a>, which allows a user to track down a lost Android phone even if they hadn&#8217;t planned ahead.</p>
<p>&#8220;I will be very excited if we figure out how to do that,&#8221; Hering said.</p>
<p>The software focuses on other areas, such as warning those who have a jailbroken iPhone about some of the added risks associated with that, as well as warning users when they are using an unsecured Wi-Fi network. The app also explains the concept of location-based services and offers details on which apps are making use of such services.</p>
<p>Over time, Hering said, the company hopes to establish for the iPhone a model similar to the one it has on Android &#8212; that is, offering a base set of services for free and then charging for more advanced features on a subscription basis.</p>
<p>&#8220;You should expect you will see a very similar path,&#8221; Hering said.</p>
<p>Hering declines to say whether Lookout is profitable, but he did say that the company is more focused on growth than it is on making a profit. The company has been racking up the funding, including a <a href="http://allthingsd.com/20110921/mobile-security-specialist-lookout-secures-another-40-million-in-funding/">$40 million round announced last month</a>.</p>
<p>The company currently has about 10 million users. Moving to the iPhone is key to its longer-term goal of reaching 100 million or more.</p>
<p>&#8220;The iPhone is going to be a huge step forward in that path,&#8221; Hering said. </p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111018/mobile-security-firm-lookout-expands-to-the-iphone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Talking Science Fiction and Fact With Intel Futurist Brian David Johnson (Video)</title>
		<link>http://allthingsd.com/20111014/talking-science-fiction-and-fact-with-intel-futurist-brian-david-johnson-video/</link>
		<comments>http://allthingsd.com/20111014/talking-science-fiction-and-fact-with-intel-futurist-brian-david-johnson-video/#comments</comments>
		<pubDate>Fri, 14 Oct 2011 22:51:58 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Brian David Johnson]]></category>
		<category><![CDATA[communicator]]></category>
		<category><![CDATA[computing]]></category>
		<category><![CDATA[Cory Doctorow]]></category>
		<category><![CDATA[futurist]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Intel]]></category>
		<category><![CDATA[mobile computing]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[science-fiction]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Star Trek]]></category>
		<category><![CDATA[the future.]]></category>
		<category><![CDATA[tricorder]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=132599</guid>
		<description><![CDATA[Science fiction makes it possible to have a conversation about the future, Johnson says, by giving us the metaphors we need to figure out what we want and don't want to happen.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20111014/talking-science-fiction-and-fact-with-intel-futurist-brian-david-johnson-video/future-is-now/" rel="attachment wp-att-132616"><img src="http://allthingsd.com/files/2011/10/future-is-now-380x285.png" alt="" title="future-is-now" width="380" height="285" class="alignright size-Featured wp-image-132616" /></a><em>We are living in the future<br />
I&#8217;ll tell you how I know<br />
I read it in the paper<br />
Fifteen years ago*<br />
</em><br />
<object width="235" height="40"><param name="movie" value="http://grooveshark.com/songWidget.swf" /><param name="wmode" value="window" /><param name="allowScriptAccess" value="always" /><param name="flashvars" value="hostname=cowbell.grooveshark.com&#038;songIDs=25858106&#038;style=metal&#038;p=0" /><embed src="http://grooveshark.com/songWidget.swf" type="application/x-shockwave-flash" width="235" height="40" flashvars="hostname=cowbell.grooveshark.com&#038;songIDs=25858106&#038;style=metal&#038;p=0" allowScriptAccess="always" wmode="window" /></object></p>
<p>It&#8217;s been more than 30 years since my favorite American bard, John Prine, sang that lyric, and it came to mind as I sat down today to meet with Brian David Johnson, who is, to my recollection, the first person I&#8217;ve ever known to carry the job title &#8220;futurist.&#8221; And yes, it sounds a little specious, until you find out he works as a futurist for the chipmaker Intel, which certainly has a long-term strategic interest in anticipating the demands of the future well before they happen.</p>
<p>Johnson was a guest today on The Wall Street Journal&#8217;s &#8220;Digits&#8221; program, which I co-hosted with the Journal&#8217;s affable <a href="http://twitter.com/#!/simonconstable">Simon Constable</a>. Johnson is in New York to speak at Comic Con about Intel&#8217;s <a href="http://techresearch.intel.com/tomorrowproject.aspx">Tomorrow Project</a>, which aims to ask honestly what computing may be like 15 or 20 years from now &#8212; and the implications for our daily lives.</p>
<p>Think back to 1996 and you probably had some idea of what 2011 would be like. But did you really? You may have had a cellphone, but would you have imagined how much of your daily life would be punctuated by its use, beyond making phone calls? If you were to zap back in time and have a conversation with the 1996 you about life in 2011, you&#8217;d probably have to rely on science fiction to get the point across. &#8220;You know the <a href="http://en.wikipedia.org/wiki/Communicator_%28Star_Trek%29">communicator</a> and <a href="http://f4.aaa.livedoor.jp/~data/tng-MedicalTricorder.htm">tricorder</a> from &#8216;Star Trek&#8217;? Yeah, we basically have those. We call them smartphones, and they&#8217;re <a href="http://allthingsd.com/20111014/sprint-launch-of-iphone-4s-led-to-best-retail-day-ever/">kind of a big deal</a>,&#8221; the 2011 you might say. &#8220;And they&#8217;re also the <a href="http://allthingsd.com/20111011/the-iphone-finds-its-voice/">talking computers</a> from &#8216;Star Trek.&#8217; And you won&#8217;t believe <a href="http://allthingsd.com/20111005/smartphone-snapshot-still-a-two-horse-race/">who makes them</a>.&#8221;</p>
<p>Science fiction makes it possible, Johnson says, to have a conversation about the future, by giving us the metaphors we need to figure out what we want and don&#8217;t want to happen. Hence &#8220;The Tomorrow Project Anthology,&#8221; a collection of short stories set in the future, imagining plausible situations emerging from science fact of today. One volume of the anthology was published <a href="http://techresearch.intel.com/newsdetail.aspx?Id=30">earlier this year</a>, and a new one is out now. </p>
<p>What happens, on some hypothetical day in the future, when passwords are easily and readily hackable and all our personal information is more or less available for all the world to see and take and use? That&#8217;s what the writer Cory Doctorow asks in his story, &#8220;The Knights of the Rainbow Table,&#8221; which appears in the new volume.</p>
<p>So these are some of the things that Simon and I talked about with Johnson in today&#8217;s closing segment on &#8220;Digits,&#8221; which you can  see below. Enjoy.</p>
<p><object id="wsj_fp" width="512" height="363"><param name="movie" value="http://s.wsj.net/media/swf/VideoPlayerMain.swf"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><param name="flashvars" value="videoGUID={D53A19FC-3901-4CB6-971C-868BA813C284}&#038;playerid=1000&#038;plyMediaEnabled=1&#038;configURL=http://wsj.vo.llnwd.net/o28/players/&#038;autoStart=false" base="http://s.wsj.net/media/swf/"name="flashPlayer"></param><embed src="http://s.wsj.net/media/swf/VideoPlayerMain.swf" bgcolor="#FFFFFF"flashVars="videoGUID={D53A19FC-3901-4CB6-971C-868BA813C284}&#038;playerid=1000&#038;plyMediaEnabled=1&#038;configURL=http://wsj.vo.llnwd.net/o28/players/&#038;autoStart=false" base="http://s.wsj.net/media/swf/" name="flashPlayer" width="512" height="363" seamlesstabbing="false" type="application/x-shockwave-flash" swLiveConnect="true" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></embed></object></p>
<p>*Lyrics from &#8220;Living in the Future,&#8221; by John Prine, from the 1980 album &#8220;Storm Windows.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111014/talking-science-fiction-and-fact-with-intel-futurist-brian-david-johnson-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sony Finds Unauthorized Sign-In Attempts on PlayStation Network</title>
		<link>http://allthingsd.com/20111012/sony-finds-unauthorized-sign-in-attempts-on-playstation-network/</link>
		<comments>http://allthingsd.com/20111012/sony-finds-unauthorized-sign-in-attempts-on-playstation-network/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 14:44:10 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[gaming]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[PlayStation Network]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Sony]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=131493</guid>
		<description><![CDATA[In a setback to its efforts to reestablish a reputation for online security, Sony said Wednesday it has found a "large amount" of unauthorized sign-in attempts on its PlayStation Network and other online entertainment services, forcing the temporary suspension of about 93,000 user accounts. The Japanese electronics and entertainment giant said in a statement that credit card details for those user accounts are "not at risk."]]></description>
			<content:encoded><![CDATA[<p>In a setback to its efforts to reestablish a reputation for online security, Sony said Wednesday it has found a &#8220;large amount&#8221; of unauthorized <a href="http://online.wsj.com/article/SB10001424052970203633104576625971976475508.html">sign-in attempts</a> on its PlayStation Network and other online entertainment services, forcing the temporary suspension of about 93,000 user accounts. The Japanese electronics and entertainment giant said in a statement that credit card details for those user accounts are &#8220;not at risk.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111012/sony-finds-unauthorized-sign-in-attempts-on-playstation-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>"Perplexed" by U.S. Ownership Rules, Alibaba's Ma Yellow Lights Yahoo Buying Parade</title>
		<link>http://allthingsd.com/20111004/perplexed-by-u-s-ownership-rules-alibabas-ma-yellow-lights-yahoo-buying-parade/</link>
		<comments>http://allthingsd.com/20111004/perplexed-by-u-s-ownership-rules-alibabas-ma-yellow-lights-yahoo-buying-parade/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 21:28:09 +0000</pubDate>
		<dc:creator>Kara Swisher</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[agreement]]></category>
		<category><![CDATA[Alibaba Group]]></category>
		<category><![CDATA[board]]></category>
		<category><![CDATA[cash]]></category>
		<category><![CDATA[CFIUS]]></category>
		<category><![CDATA[change of control]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[Chinese]]></category>
		<category><![CDATA[Committee on Foreign Investment in the United States]]></category>
		<category><![CDATA[consumer]]></category>
		<category><![CDATA[deal]]></category>
		<category><![CDATA[DST Global]]></category>
		<category><![CDATA[entrepreneur]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[federal]]></category>
		<category><![CDATA[foreign]]></category>
		<category><![CDATA[interagency]]></category>
		<category><![CDATA[investment]]></category>
		<category><![CDATA[Jack Ma]]></category>
		<category><![CDATA[Jerry Yang]]></category>
		<category><![CDATA[member]]></category>
		<category><![CDATA[national]]></category>
		<category><![CDATA[ownership]]></category>
		<category><![CDATA[perplexed]]></category>
		<category><![CDATA[politics]]></category>
		<category><![CDATA[process]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[rule]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Silicon Valley]]></category>
		<category><![CDATA[Sliver Lake]]></category>
		<category><![CDATA[speech]]></category>
		<category><![CDATA[stake]]></category>
		<category><![CDATA[Stanford University]]></category>
		<category><![CDATA[strategic]]></category>
		<category><![CDATA[Yahoo]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=127909</guid>
		<description><![CDATA[From "very, very interested" to a case of wanna-be-buyer's remorse?]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20111004/perplexed-by-u-s-ownership-rules-alibabas-ma-yellow-lights-yahoo-buying-parade/disappointmentequation/" rel="attachment wp-att-128095"><img src="http://allthingsd.com/files/2011/10/disappointmentequation-380x246.png" alt="" title="disappointmentequation" width="380" height="246" class="alignright size-medium wp-image-128095" /></a></p>
<p>After his unusually enthusiastic declaration at a Silicon Valley event last week that <a href="http://allthingsd.com/20110930/jack-ma-at-stanford-we-are-very-interested-in-buying-yahoo/">&#8220;we are very, very interested&#8221;</a> in buying the &#8220;whole&#8221; of Yahoo, you might imagine Alibaba Group co-founder and CEO Jack Ma running out of the speech looking for a giant pile of cash to pay for it immediately.</p>
<p>Instead, according to sources close to the situation, what the Chinese entrepreneur got was a cold dose of CFIUS &#8212; or Committee on Foreign Investment in the United States, the federal interagency review process for foreign investment deals.</p>
<p>Translation: If you are from China and want to buy our U.S. companies, we are going to have to give you a major look-see and it is not going to be pretty.</p>
<p>Perhaps that&#8217;s fair, but the prospect that even a purchase such as Yahoo, a consumer business that seems to have little in the way of national security concerns, might enter the buzzsaw of U.S. politics apparently surprised Ma.</p>
<p>Thus, sources said, that while it remains very interested, Alibaba is now at least a little concerned about the feasibility of the deal and that Ma is &#8220;perplexed&#8221; about why the U.S. has such restrictive rules against foreign ownership of a consumer business.</p>
<p>That said, he has been in touch with Yahoo co-founder and board member Jerry Yang and is likely to make a more official visit soon with others involved in Yahoo&#8217;s strategic review.</p>
<p>In addition, sources said, rumors of an imminent Yahoo bid hook-up with DST Global and Silver Lake &#8212; which recently <a href="http://allthingsd.com/20110922/exclusive-dst-silver-lake-and-yunfeng-to-lead-1-6b-tender-offer-aimed-at-alibaba-employees-and-others/">invested in Alibaba</a> &#8212; are overblown. While Ma did say last week at his much-noticed speech at Stanford University that he was talking to a lot of buyers, Alibaba is not closely aligned with anyone as yet.</p>
<p>Of course, given that Yahoo owns a 40 percent stake in Alibaba, Ma will be a big player in any deal done.</p>
<p>That&#8217;s because of a 2005 agreement that stipulates that if there is a change of control, Yahoo must give Alibaba a 15-day chance to buy back its stake. </p>
<p>Still, after his effusive I-want-Yahoo-<em>now</em> speech that caught the Internet giant and its bidders off guard, dialing back the rhetoric a bit is probably no surprise given the delicate dancing now going on. </p>
<p>In other words, a case of wanna-be-buyer&#8217;s remorse. </p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111004/perplexed-by-u-s-ownership-rules-alibabas-ma-yellow-lights-yahoo-buying-parade/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
