Microsoft To Block SHA-1 Hashing
Software Giant Microsoft has joined Mozilla and will consider blocking the SHA-1 hashing algorithm on Windows to keep the US spooks from using it to spy on users computers.
Redmond had earlier said that Windows would block SHA-1 signed TLS (Transport Layer Security) certificates from January 1, 2017, but is now mulling moving up the date to June.
There have been concerns about the algorithm’s security as researchers have proven that a forged digital certificate that has the same SHA-1 hash as a legitimate one can be created. Users can then be tricked into interacting with a spoofed site in what is called a hash collision.
In October, a team of cryptoanalysts warned that the SHA-1 standard should be withdrawn as the cost of breaking the encryption had dropped faster than expected to US$75,000 to $120,000 in 2015 using freely available cloud computing.
Programme manager for Microsoft Edge Kyle Pflug wrote in his blog that Redmond will coordinate with other browser vendors to evaluate the impact of this timeline based on telemetry and current projections for feasibility of SHA-1 collisions.
Mozilla said in October that in view of recent attacks it was considering a cut-off of July 1, 2016 to start rejecting all SHA-1 SSL certificates, regardless of when they were issued, ahead of an earlier scheduled date of January 1, 2017.
Courtesy- http://www.thegurureview.net/computing-category/microsoft-to-block-sha-1-hashing.html
Sprint Confirms Jobs To Be Cut
November 17, 2015 by admin
Filed under Around The Net
Comments Off on Sprint Confirms Jobs To Be Cut
Sprint Chairman and SoftBank CEO Masayoshi Son has confirmed that job cuts at Sprint will be “in the thousands” as part of a restructuring plan.
His comments came as SoftBank, which owns more than 70% of Sprint, reported its quarterly earnings.
“Sprint is now in the position to increase the pace of user acquisition while cutting costs,” Son said, according to Bloomberg and other news sources. “We will also cut staff. The cuts will be in the thousands.”
Son’s comments are not out of line with things Sprint CEO Marcelo Claure has been telling Sprint workers for months.
On Tuesday, Sprint’s stock price sagged downward after an earnings report included a statement saying that the carrier plans to cut $2 billion or more in operating expenses for its 2016 fiscal year, which begins in April.
Son also said the $2 billion is a “minimum target” and should be the amount slashed annually, according to a report by The Wall Street Journal. The company now has more than $25 billion in annual costs.
Sprint has been investing in attracting new customers — an effort that has been costly but effective. On Tuesday, Sprint reported it gained 237,000 postpaid phone customers in its second fiscal quarter, which ended Sept. 30. It was the first time the company had showed gains on that measure in two years. It also reported its lowest customer cancellation rate in company history.
In November 2014, Sprint had said it would cut 2,000 jobs as part of $1.5 billion in cost reductions. That announcement came after Sprint had cut 5,000 jobs from January through September 2014. The company had 31,000 workers at the start of its current fiscal year on April 1.
Source- http://www.thegurureview.net/mobile-category/sprint-confirms-thousands-of-jobs-to-be-cut.html
Britain’s New Surveillance Plans Raises Privacy Concerns
November 16, 2015 by admin
Filed under Around The Net
Comments Off on Britain’s New Surveillance Plans Raises Privacy Concerns
Britain has announced plans for sweeping new surveillance powers, including the right to find out which websites people visit, measures ministers say are vital to keep the country safe but which critics denounce as an assault on freedoms.
Across the West, debate about how to protect privacy while helping agencies operate in the digital age has raged since former U.S. intelligence contractor Edward Snowden leaked details of mass surveillance by British and U.S. spies in 2013.
Experts say part of the new British bill goes beyond the powers available to security services in the United States.
The draft was watered down from an earlier version dubbed a “snoopers’ charter” by critics who prevented it reaching parliament. Home Secretary Theresa May told lawmakers the new document was unprecedented in detailing what spies could do and how they would be monitored.
“It will provide the strongest safeguards and world-leading oversight arrangements,” she said. “And it will give the men and women of our security and intelligence agencies and our law enforcement agencies … the powers they need to protect our country.”
They would be able to require communication service providers (CSPs) to hold their customers’ web browsing data for a year, which experts say is not available to their U.S. counterparts.
“What the British are attempting to do, and what the French have already done post Charlie Hebdo, would never have seen the light of day in the American political system,” Michael Hayden, former director of the U.S. National Security Agency and Central Intelligence Agency, told Reuters.
May said that many of the new bill’s measures merely updated existing powers or spelled them out.
Police and spies’ access to web use would be limited to “Internet connection records” – which websites people had visited but not the particular pages – and not their full browsing history, she said.
“An Internet connection record is a record of the communications service that a person has used – not a record of every web page they have accessed,” May said. “It is simply the modern equivalent of an itemised phone bill.”
Source-http://www.thegurureview.net/aroundnet-category/britains-new-surveillance-plans-raise-ire-of-privacy-advocates.html
Seagate Goes 8TB For Surveillance
Seagate has become the first hard drive company to create an 8TB unit aimed specifically at the surveillance market, targeting system integrators, end users and system installers.
The Seagate Surveillance HDD, as those wags in marketing have named it, is the highest capacity of any specialist drive for security camera set-ups, and Seagate cites its main selling points as maximizing uptime while removing the need for excess support.
“Seagate has worked closely with the top surveillance manufacturers to evolve the features of our Surveillance HDD products and deliver a customized solution that has precisely matched market needs in this evolving space for the last 10 years,” said Matt Rutledge, Seagate’s senior vice president for client storage.
“With HD recordings now standard for surveillance applications, Seagate’s Surveillance HDD product line has been designed to support these extreme workloads with ease and is capable of a 180TB/year workload, three times that of a standard desktop drive.
“It also includes surveillance-optimized firmware to support up to 64 cameras and is the only product in the industry that can support surveillance solutions, from single-bay DVRs to large multi-bay NVR systems.”
The 3.5in drive is designed to run 24/7 and is able to capture 800 hours of high-definition video from up to 64 cameras simultaneously, making it ideal for shopping centers, urban areas, industrial complexes and anywhere else you need to feel simultaneously safe and violated. Its capacity will allow 6PB in a 42U rack.
Included in the deal is the Seagate Rescue Service, capable of restoring lost data in two weeks if circumstances permit, and sold with end users in mind for whom an IT support infrastructure is either non-existent or off-site. The service has a 90 percent success rate and is available as part of the drive cost for the first three years.
Seagate demonstrated the drive today at the China Public Security Expo. Where better than the home of civil liberty infringement to show off the new drive?
Earlier this year, Seagate announced a new co-venture with SSD manufacturer Micron, which will come as a huge relief after the recent merger announcement between WD and SanDisk.
Courtesy-http://www.thegurureview.net/computing-category/seagate-goes-8tb-for-surveillance.html
Will UMC Chip Shipments Drop In The Fall?
Comments Off on Will UMC Chip Shipments Drop In The Fall?
Foundry UMC is expecting its shipments to fall by five percent in the fourth quarter of 2015, as a result of ongoing inventory adjustments within the industry supply chain.
Revenues for the last part of the year will be adversely affected by an about one per cent drop in wafer ASPs and capacity at its plants will slide to 81-83 per cent in the fourth quarter from 89% in the third.
UMC’s had already lowered capacity in the third quarter. At the beginning of the year it was running at 94 percent.
The company’s revenues decreased 7.1 per cent to $1.07 billion in the third quarter, with gross margin slipping below 20 per cent.
UMC net profits were down 62.9 per cent on quarter, as both operating and non-operating income eroded. This is bad news because in the first three quarters of 2015, UMC’s net profits increased 35.8 per cent from a year earlier.
However UMC is continuing to invest in new capital and will spend $1.8 billion.
CEO Po-Wen Yen said that the continuing IC inventory adjustment will dampen fourth quarter wafer shipments, but UMC continues on the path towards long-term growth.
“Throughout 2015, UMC engineers and Fab12A have worked tirelessly to bring several new 28nm product tape-outs into volume production. “UMC is working to bring a timely conversion of new 28nm requirements into production, which will strengthen our business.”
Courtesy-http://www.thegurureview.net/computing-category/will-umc-chip-shipments-drop-in-the-fall.html
Confusion Continues To Reign With U.S. Chip & PIN
November 11, 2015 by admin
Filed under Around The Net
Comments Off on Confusion Continues To Reign With U.S. Chip & PIN
Several large U.S. retailers are ramping up efforts to use personal identification numbers, or PINs, with new credit cards embedded with computer chips in a bid to prevent counterfeit card fraud.
But they are being resisted by the banking industry, which sees no need to invest further in PIN technology, already used with debit cards, resulting in halting adoption and widespread confusion.
A small band of retailers with the clout to call the shots on their branded credit cards is leading the charge. Target Corp is moving ahead with a chip-and-PIN rollout, and Wal-Mart Stores Inc plans to do the same.
But Wal-Mart said it faces obstacles because its credit card partner, Synchrony Financial, is not yet able to handle PINs on credit cards. Synchrony declined comment.
Broadly, U.S. banks are unprepared or resisting the change.
The impasse comes after many consumers got their hands on new credit cards embedded with so-called EMV chips in advance of an Oct. 1 deadline that required retailers to accept chip cards or be liable for fraud losses. EMV stands for EuroPay, MasterCard and Visa.
But only about a third of merchants are actually using the chip technology, according to analyst estimates. The number may not pick up until early next year, if at all, because the retail industry typically halts upgrades during the crucial holiday shopping season.
“PIN issuance will remain a niche,” said Julie Conroy, credit-card analyst with Aite Group.
Banks favor using chip cards verified by old-school signatures, even though chip-and-PIN usage has led to lower fraud over the decade they have been used in Europe and elsewhere.
“The PIN is definitely a must,” said Lance James, chief scientist with cyber intelligence firm Flashpoint. “It’s one extra step that provides true two-factor authentication.”
But bankers say PINs provide little benefit beyond the advantage of using chips in combating the estimated $7 billion-plus in annual U.S. card fraud.
EMV chips thwart criminals who use stolen data to create counterfeit cards, a category that Aite estimates accounts for 37 percent of that fraud. Banks say that PINs only provide additional fraud protection when criminals seek to use lost or stolen cards, a situation that Aite estimates accounts for only 14 percent of fraud.
Banking groups say there are better approaches than PINs for verifying customers and have asked retailers to embrace tokenization and encryption to prevent theft of credit card numbers.
“PIN is a static data element that would not have a meaningful impact on overall payments fraud,” said Electronic Payments Coalition spokesman Sam Fabens.
Courtesy-http://www.thegurureview.net/aroundnet-category/confusion-continues-to-reign-with-u-s-chip-pin.html
Oracle’s M7 Processor Has Security On Silicon
Comments Off on Oracle’s M7 Processor Has Security On Silicon
Oracle started shipping systems based on its latest Sparc M7 processor, which the firm said will go a long way to solving the world’s online security problems by building protection into the silicon.
The Sparc M7 chip was originally unveiled at last year’s Openworld show in San Francisco, and was touted at the time as a Heartbleed-prevention tool.
A year on, and Oracle announced the Oracle SuperCluster M7, along with Sparc T7 and M7 servers, at the show. The servers are all based on the 32-core, 256-thread M7 microprocessor, which offers Security in Silicon for better intrusion protection and encryption, and SQL in Silicon for improved database efficiency.
Along with built-in security, the SuperCluster M7 packs compute, networking and storage hardware with virtualisation, operating system and management software into one giant cloud infrastructure box.
Oracle CTO Larry Ellison was on hand at Openworld on Tuesday to explain why the notion of building security into the silicon is so important.
“We are not winning a lot of these cyber battles. We haven’t lost the war but we’re losing a lot of the battles. We have to rethink how we deliver technology especially as we deliver vast amounts of data to the cloud,” he told delegates.
Ellison said that Oracle’s approach to this cyber war is to take security as low down in the stack as possible.
“Database security is better than application security. You should always push security as low in the stack as possible. At the bottom of the stack is silicon. If all of your data in the database is encrypted, that’s better than having an application code that encrypts your data. If it’s in the database, every application that uses that database inherits that security,” he explained.
“Silicon security is better than OS security. Then every operating system that runs on that silicon inherits that security. And the last time I checked, even the best hackers have not figured out a way to download changes to your microprocessor. You can’t alter the silicon, that’s really tricky.”
Ellison’s big idea is to take software security features out of operating systems, VMs and even databases in some cases – because software can be changed – and instead push them into the silicon, which can’t be. He is also urging for security to be switched on as default, without an option to turn it back off again.
“The security features should always be on. We provide encryption in our databases but it can be switched off. That is a bad idea. There should be no way to turn off encryption. The idea of being able to turn on and off security features makes no sense,” he said.
Ellison referred back to a debate that took place at Oracle when it first came up with its backup system – should the firm have only encrypted backups. “We did a customer survey and customers said no, we don’t want to pay the performance penalty in some cases,” he recalled. “In that case customer choice is a bad idea. Maybe someone will forget to turn on encryption when it should have been turned on and you lose 10 million credit cards.”
The Sparc M7 is basically Oracle’s answer to this dire security situation. Ellison said that while the M7 has lots of software features built into the silicon, the most “charismatic” of these is Silicon Secured Memory, which is “deceptively simple” in how it works.
“Every time a computer program asks for memory, say you ask for 8MB of memory, we compute a key and assign this large number to that 8MB of memory,” he explained. “We take those bits and we lock that memory. We also assign that same number to the program. Every time the program accesses memory, we check that number to make sure it’s the memory you allocated earlier. That compare is done by the hardware.”
If a program tries to access memory belonging to another program, the hardware detects a mismatch and raises a signal, flagging up a possible breach or bug.
“We put always-on memory intrusion detection into the silicon. We’re always looking for Heartbleed and Venom-like violations. You cannot turn it off,” the CTO warned.
“We’ve also speeded up encryption and decompression, which is kind of related to encryption. It runs at memory speed there’s zero cost in doing that. We turn it on, you can’t turn it off, it’s on all the time. It’s all built into the M7.”
Ellison claimed that running M7-based systems will stop threats like Heartbleed and Venom in their tracks.
“The way Venom worked, the floppy disc driver concealed this code. It’s the worst kind of situation, you’re writing into memory you’re not supposed to. You’re writing computer instructions into the memory and you’ve just taken over the whole computer,” he explained. “You can steal and change data. M7 – the second we tried to write that code into memory that didn’t belong to that program, where the keys didn’t match, that would have been detected real-time and that access would have been foiled.
All well and good, except for the fact that nearly every current computer system doesn’t run off the M7 processor. Ellison claimed that even if only three or four percent of servers in the cloud an organisation is using have this feature, they will be protected as they’ll get the early warning to then deal with the issue across non-M7 systems.
“You don’t have to replace every micro processor, you just have to replace a few so you get the information real-time,” he added.
“You’ll see us making more chips based on security, to secure our cloud and to sell to people who want to secure their clouds or who want to have secure computers in their datacentre. Pushing security down into silicon is a very effective way to do that and get ahead of bad guys.”
SuperCluster M7 and Sparc M7 servers are available now. Pricing has not been disclosed but based on normal Oracle hardware costs, expect to dig deep to afford one.
Source-http://www.thegurureview.net/computing-category/oracles-new-m7-processor-has-security-on-silicon.html
Verizon Goes IoT
Verizon has rolled out ThingSpace, a development platform for companies of all sizes to create Internet of Things applications more efficiently and then later manage those apps.
The carrier also announced it is creating a new dedicated network core for IoT connections that can scale far beyond the ability of its existing networks with the intent to reach billions of sensors and devices.
“Continued innovation in smart cities, connected cars and wearables demonstrates that IoT is the future for how we will live and work,” said Mike Lanman, senior vice president of enterprise products at Verizon during an event held at Verizon’s San Francisco Innovation Center. He said Verizon is taking a “holistic approach” to help expand the IoT market from millions of connections to billions. The event was webcast.
Other major wireless carriers, including AT&T, are developing programs to offer a range of services to industries and cities for connecting IoT sensors to wireless networks and then to cloud services for data analysis.
At Verizon, Lanman said the company is working to lower the cost of connecting billions of existing devices that companies have used for years to Verizon’s network. Holding up a new computer chip made by Sequans Communications, an LTE chip maker, he said the chip will provide a “significant reduction in cost…that changes the game.” It will provide 4G LTE connectivity in modules connected to IoT devices to “make the wide-area network more accessible to developers.”
Also, next year Verizon will launch a new IoT core network within its LTE network to provide a “much lower cost” than with Verizon’s existing wired and wireless networks.
“The cost for an IoT module and the cost to connect will both drop dramatically,” Lanman added. “Whether you are connecting your dog or water meters and any other low-payload devices, we’ll handle it through a new IoT core.”
Source-http://www.thegurureview.net/consumer-category/verizon-launches-thingspace-for-iot-development.html
Is Intel Trying To Destroy Micron?
Wall Street analysts have downgraded Micron technology’s value after Intel’s announcement that it will expand investment in NAND.
Intel plans to invest up to $5.5 billion over the coming years to use its Dalan, China, facility to expand its NAND manufacturing capacity. Initial 3D NAND production is expected to commence in second-half 2016 in Dalan.
Barrons has said that with pricing pressure already present in DRAM, Intel’s move puts Micron in a state of uncertainty.
This is a little odd given that Intel and Micron are chums, but Barron’s Rajvindra Gill said that the move will reduce Chipzilla’s dependence on Micron.
More than half of output is expected to use 3D NAND in the next two to three years and Intel’s focus on the technology reduces its reliance on Micron as a supplier while transforming it into a competitor, Gill said.
Micron be the last one standing when the mergers and acquisitions the industry is seeing and be an industry also ran.
Intel’s focus on the non-volatile memory market could put the pricing and supply/demand environment under pressure.
Micron has already had difficulties setting up 3D NAND versus its peers and now has another significant challenger entering the market, Gill said.
Intel’s move to NAND places a major Micron customer at risk. While Intel noted that its relationship with Micron remains strong and that it will continue to focus on 3D Xpoint, we believe the IM Flash Agreement could be at risk.
With Intel producing more NAND on its own, it could look to lower its reliance on the joint venture.
Intel has a right to sell its portion of the joint venture to Micron. If Intel elects to do so, a closing date would be set within two years. Sales to IM Flash sales to Intel were $101 million in the third quarter, or 8 per cent of trade NAND revenue.
Courtesy-http://www.thegurureview.net/computing-category/is-intel-trying-to-destroy-micron.html
Sony To Acquire Toshiba’s Sensor Business
November 4, 2015 by admin
Filed under Consumer Electronics
Comments Off on Sony To Acquire Toshiba’s Sensor Business
Toshiba Corp is offload its image sensor business to Sony Corp for around 20 billion yen ($164.68 million) as part of a restructuring plan laid out earlier this year, sources with knowledge of the deal said on Saturday.
Toshiba, whose businesses range from laptops to nuclear power, is undergoing a restructuring after revelations this year that it overstated earnings by $1.3 billion going back to fiscal 2008/09.
Image sensors, which are used in digital cameras and smartphones, are part of Toshiba’s system LSI semiconductor business. Toshiba plans to sell its image sensor manufacturing plant in Oita, southern Japan, and pull out of the sensor business altogether, said the sources, who declined to be identified.
The sale is likely to be finalized soon, the sources said.
Toshiba is considering several options for its system LSI semiconductor business and its discrete semiconductor business and that debate is ongoing, a Toshiba official said when contacted.
An official from Sony declined to comment.
Masashi Muromachi, who became Toshiba’s CEO following the accounting scandal, has promised to restructure lower-margin businesses.
The deal for the image sensor business would be the beginning of the restructuring, Nikkei reported earlier on Saturday.
Sony is already a dominant player in the image sensor market, with its products used in phones made by China’s Xiaomi and India’s Micromax Informatix Ltd.
Courtesy-http://www.thegurureview.net/consumer-category/sony-to-acquire-toshibas-sensor-business.html