Twitter’s Authentication Has Vulnerabilities
June 6, 2013 by admin
Filed under Around The Net
Comments Off on Twitter’s Authentication Has Vulnerabilities
Twitter’s SMS-based, two-factor authentication feature could be abused to lock users who have not enabled it for their accounts if attackers gain access to their log-in credentials, according to researchers from Finnish antivirus vendor F-Secure.
Twitter introduced two-factor authentication last week as an optional security feature in order to make it harder for attackers to hijack users’ accounts even if they manage to steal their usernames and passwords. If enabled, the feature introduces a second authentication factor in the form of secret codes sent via SMS.
According to Sean Sullivan, a security advisor at F-Secure, attackers could actually abuse this feature in order to prolong their unauthorized access to those accounts that don’t have two-factor authentication enabled. The researcher first described the issue Friday in a blog post.
An attacker who steals someone’s log-in credentials, via phishing or some other method, could associate a prepaid phone number with that person’s account and then turn on two-factor authentication, Sullivan said Monday. If that happens, the real owner won’t be able to recover the account by simply performing a password reset, and will have to contact Twitter support, he said.
This is possible because Twitter doesn’t use any additional method to verify that whoever has access to an account via Twitter’s website is also authorized to enable two-factor authentication.
When the two-factor authentication option called “Account Security” is first enabled on the account settings page, the site asks users if they successfully received a test message sent to their phone. Users can simply click “yes,” even if they didn’t receive the message, Sullivan said.
Instead, Twitter should send a confirmation link to the email address associated with the account for the account owner to click in order to confirm that two-factor authentication should be enabled, Sullivan said.
As it is, the researcher is concerned that this feature could be abused by determined attackers like the Syrian Electronic Army, a hacker group that recently hijacked the Twitter accounts of several news organizations, in order to prolong their unauthorized access to compromised accounts.
Some security researchers already expressed their belief that Twitter’s two-factor authentication feature in its current implementation is impractical for news organizations and companies with geographically dispersed social media teams, where different employees have access to the same Twitter account and cannot share a single phone number for authentication.
Twitter did not immediately respond to a request for comment regarding the issue described by Sullivan.
Is This A Mobile First World?
June 3, 2013 by admin
Filed under Smartphones
Comments Off on Is This A Mobile First World?
Judging from the number of people engrossed in activities with their smartphones on the sidewalk, in their cars and in public places, mobile seems to have stolen our attention away from the wired Internet and traditional TV.
However, there is a ways to go before mobile platforms become the primary place where consumers turn for entertainment and getting things done, players at CTIA Wireless trade show said.
Nokia Siemens Networks announced new capabilities in its network software to make video streams run more smoothly over mobile networks. Among other things, the enhancements can reduce video stalling by 90 percent, according to the company. But even Sandro Tavares, head of marketing for NSN’s Mobile Core business, sees “mobile-first” viewing habits as part of the future.
“Now that the networks are providing a better capacity, a better experience with mobile broadband, mobile-first will come,” Tavares said. “Because the experiences they have with the devices are so good, these devices … start to be their preferred screen, their first screen.
“This is a trend, and this is something that will not change,” Tavares said. But he thinks it’s too early to build networks assuming consumers will turn to tablets and phones as their primary sources of entertainment. “Do you have to be prepared for mobile-first now? Probably not. You have to be able to keep the pace.”
For AT&T, mobile-first is a top priority for its own internal apps, ensuring employees can do their jobs wherever they are, said Kris Rinne, the carrier’s senior vice president of network technologies. But to make it possible over the network, a range of new technologies and relationships may have to come together, she said.
For example, giving the best possible performance for streaming video and other uses of mobile may require steering traffic to the right network if both cellular and Wi-Fi are available. AT&T is developing an “intelligent network selection” capability to do this, Rinne said. When AT&T starts to deliver voice over LTE, it will stay on the cellular network — at least in the early days — because the carrier has more control over quality of service on that system, she said.
Other issues raised by mobile-first include security of packets going over the air and rights for content that subscribers are consuming primarily on mobile devices instead of through TV and other traditional channels, Rinne said.
Lenovo Soars
PC sales in China and high growth in smartphones sales helped boost Lenovo’s net profit for its fiscal fourth quarter by 90% year-over-year.
For the quarter ended March 31, Lenovo’s net profit was $127 million, the company said on Thursday. Revenue shattered records and was at $7.8 billion, growing 4% from the same period last year.
In Lenovo’s home market of China, the company had an operating margin of 4.9%, an increase of 8% year-over-year. The company also saw continued profitability in its mobile devices business, which makes up 9% of its overall sales. At the end of the quarter, Lenovo’s smartphone shipments were up 206% year-over-year.
Globally, PC shipments were down 13.9% year-over-year in the quarter, the market’s steepest decline since research firm IDC began tracking the market in 1994. Lenovo itself posted flat year-over-year PC shipment growth in the period.
Smartphone and tablet popularity have hurt PC sales, according to analysts. Computers running Microsoft’s Windows 8 have also failed to drum up consumer interest in the previous two quarters.
Lenovo, however, has managed to weather the slowdown by taking advantage of the Chinese PC market, where it has an over 30% market share. Close to half of the company’s revenue comes from the country, now the world’s largest PC market.
The company is now close to surpassing leading PC vendor HP for the top spot. The company had a 15.3% share of the market in this year’s first quarter, while HP had a 15.7% share.
But the Chinese PC maker also plans to focus more of its investment on tablets, smartphones and enterprise hardware, the company’s CEO Yang Yuanqing said in a statement. Earlier this year, Lenovo also reorganized its operations to sharpen the company’s branding and compete better in high-end products.
For the current fiscal year, Lenovo aims to ship 50 million smartphones, up from 30 million last year, Yang said Thursday in an earnings call. It aims to ship 10 million tablets, a five-fold increase from the previous fiscal year.
Most of Lenovo’s smartphone sales come from China, but the company has also begun selling handsets in the emerging markets of Russia, India, Indonesia, the Philippines and Vietnam. In addition, Lenovo is preparing to bring its smartphones to the U.S. and European markets, Yang said, without saying when.
Qualcomm surpasses AMD
May 30, 2013 by admin
Filed under Uncategorized
Comments Off on Qualcomm surpasses AMD
It’s no secret that the mobile boom is taking a toll on makers of PC components and AMD is one of them. According to data from IC Insights, Qualcomm and Samsung have managed to pass AMD in microprocessor sales last year.
Intel still dominates the market, with $36.9 billion sales and a 65.3 percent market share. However, Qualcomm has managed to squeeze into second spot, with $5.3 billion in sales and a 9.4 percent share. Samsung ranked third, with $4.66 in sales and an 8.2 percent market share. Qualcomm and Samsung also recorded plenty of growth, 28 and 78 percent respectively.
However, AMD slumped 21 percent to take 6.4 percent of the market, with $3.6 billion in sales. It was still ahead of Freescale and Nvidia, as well as Texas Instruments and ST Ericsson.
It should be noted that about 83 percent of Samsung’s revenue came from chips churned out for Apple. In other words, had Apple built the chips on its own, it would have tied with AMD for the third spot.
nVidia Explains Tegra 4 Delays
nVidia’s CEO Jen-Hsun Huang mentioned a concrete reason of Tegra 4 delays during the company’s latest earnings call.
The chip was announced back in January, but Jensen told the investors that Tegra 4 was delayed because of Nvidia’s decision to pull in Grey aka Tegra 4i in for six months. Pulling Tegra 4i in and having it scheduled for Q4 2013 was, claims Jensen, the reason for the three-month delay in Tegra 4 production. On the other hand, we heard that early versions of Tegra 4 were simply getting too hot and frankly we don’t see why Nvidia would delay its flagship SoC for tactical reasons.
Engaging the LTE market as soon as possible has been the main reason for pulling Tegra 4i, claims Jensen. It looks to us that Tegra 4 will be more than three months delayed but we have been promised to see Tegra 4 based devices in Q2 2013, or by the end of June 2013.
Nvidia claims Tegra 4i has many design wins and it should be a very popular chip. Nvidia expects to have partners announcing their devices based on this new LTE based chip in early 2014. Some of them might showcase some devices as early as January, but we would be surprised if we don’t see Tegra 4i devices at the Mobile World Congress next year, that kicks off on February 24th 2014.
Jensen described Tegra 4i as an incredibly well positioned product, saying that “it brings a level of capabilities and features of performance that that segment has just never seen”. The latter half of 2013 will definitely be interesting for Nvidia’s Tegra division and we are looking forward to see the first designs based on this new chip.
SOA’s New API Goes To The Cloud
SOA Software has launched an application programming interface (API) gateway today that allows businesses to expose their API’s with a built-in cloud based developer community, helping to grow their services and make it quicker for them to get up and running.
The firm’s CTO Alistair Farquharson said the API Gateway is unique due to it being a new concept in API and SOA management, aiming to “deliver new advantages in the application-level security space”.
“The new API Gateway provides monitory, security, and more uniquely, a developer community as well, so kind of a turnkey approach to an API gateway where a customer can buy that product, get it up and running, expose their API and expose the developer community to the outside world,” Farquharson said.
“[It will] support and manage the porting of mobile applications or web apps or B2B partnerships.”
Farquharson explained that there are three main components within the Gateway, which SOA Software has termed a “unified services gateway”, including a runtime component, a policy manager, and a developer community.
The runtime component handles the message traffic, whereas the policy manager component is capable of managing a range of different policies, such as threat protection, authentication, authorisation, anti-virus, monitorin, auditing, logging, for example.
“The whole objective here is to get a customer up and running with API’s as quickly as possible to meet some kind of a business need that they have, whether that’s mobile an application initiative or a web application, integration or syndication,” Farquharson added.
The third component is the API’s cloud-based “developer community”, which exposes an organisation to the outside world so developers can come take a look at its API, read its documentation, and see what APIs it has to figure out how to interact with them.
It’s this component that sets SOA Software’s Gateway apart form other firms doing similar appliances on the market, claims Farquharson.
“It essentially becomes the developer site for your organisation, with it all running on a single appliance which is rather unique,” he added.
“The interesting thing about the gateway is that it does API’s as well as services [that are] needed for mobile devices so you have old and the new encapsulated in the single appliance, which is very important to our customers.”
The developer community is offered through the API as a service, “like the Salesforce of APIs”, Farquharson said.
“Developers can go there and build their community and it provides them with high level service and availability and saglobla infrastructure and leverage the strength of their community to get themselves going.”
Did Apple Trick Sharp?
Sharp is really regretting its dependence on Apple as its main customer.
While it made sense at the time to be extremely pleased when Apple sucked up most of its capacity with screens for its iPhone and iPad, now the tide has turned the outfit is reporting a bigger than forecast loss. Sharp is now suffering from low output at its factories and forced to write off excess capacity.
The company had a $5.1 billion net loss for the year which is much worse than it predicted. At the start of the year, Sharp was forced to curtail production of 9.7-inch screens for Apple’s iPad. That has stepped up the urgency for Sharp to find new customers and uses for its leading-technology displays and may make it harder for the company to convince investors and lenders it remains a viable company.
Sharp will officially announce its results for latest business year on May 14. To make matters worse the company is also taking a charge to put aside cash for possible fines from a display price-fixing investigation in Europe, the sources said. Sharp in October received a $4.4 billion bailout from banks including Mizuho Financial Group and Mitsubishi Financial Group in return for mortgaging nearly all its factories and offices in Japan and pledging to cut 10,000 jobs.
Qualcomm Sticks With Windows RT
Tim McDonough, Vice President, Marketing at Qualcomm, was Qualcomm´s commitment to Windows RT. Ever since Microsoft announced Windows RT, ARM supporters had high hopes and Windows RT has yet to live up to some.
Tim confirmed Qualcomm´s commitment to Windows RT and future releases, saying “we are here for the long run”. He describes the partnership as the beginning of a long journey and of course Qualcomm is going to continue rolling out chips that will run great with Windows RT.
Qualcomm mentioned that Samsung ATIV and Dell XPS 10, both of which use Qualcomm’s S4 dual-core APQ8060A chips, run really nice. Tim told us that he is a real fan of both devices and that he is currently using one of them.
We also learned that Snapdragon 600, the one used in the HTC One and some versions of Samsung’s Galaxy S4, is 40 per cent faster than the S4 Pro, adding that Adreno 320 graphics core is significantly faster than the Adreno 225 used in the S4 APQ8060A chip. Another number we got is that the Adreno 330 is up to four times faster than the 225, which is a huge leap forward. Let’s not forget that Snapdragon 800, which is up to 75 per cent faster than Snapdragon S4 Pro, is also coming in mid-year, second half of 2013. The 800 will be Qualcomm’s first chip with Adreno 330 graphics.
One can easily conclude that there should be some Snapdragon 600 and 800 Windows RT convertible tablets at some point in the future. To stay on the safe side, Qualcomm just confirmed that new and exciting things are coming in the next months and quarter and they are Windows based.
We have to notice that most people in the tablet world get really excited talking about convertible tablets in all shapes and sizes, as the physical keyboard is definitely an accessory you want to have.
nVidia Wins With Tegra 4
Nvidia’s first Tegra 4 design win is here, apparently, and it doesn’t appear very impressive at all. Tegra 4 is late to the party, so it is a bit short on design wins, to put it mildly.
Now a new ZTE smartphone has been spotted by Chinese bloggers and it seems to be based on Nvidia’s first A15 chip. The ZTE 988 is a phablet, with a 5.7-inch 720p screen. It has 2GB of RAM, a 13-megapixel camera and a 6.9mm thin body. It weighs just 110g, which is pretty surprising. The spec is rather underwhelming, especially in the display department.
However, a grain of salt is advised. It is still unclear whether the phone features a Tegra 4 or a Qualcomm chipset. Also, it is rather baffling to see a 720p screen on a Tegra 4 phablet, it just seems like overkill.
Citrix Goes To The Cloud
Citrix System’s GoToWebcast has become generally available in North America and Europe, offering users a cloud-based webcasting tool for up to 5,000 participants.
The subscription-based GoToWebcast allows users to broadcast unlimited audio and video presentations to live and on-demand audiences that can access them using mobile devices such as Apple’s iPhones and iPads, or Android-based smartphones and tablets.
To simplify administration, GoToWebcast has a five-step wizard that walks users through setting up their event. Users are first asked to schedule the event, including deciding audience size and if the web cast should be available on-demand or live with an archive. Users are then asked to select registration alternatives, multimedia options, choose what content to upload and finally decide on security and email settings.
In addition to audio and video, users can upload presentation documents, chat with attendees, conduct polls and link to social media channels. Citrix didn’t announce any pricing for the new service, only saying that users pay a fixed monthly fee.
The company also released a beta version of GoToWebinar with HDFaces for the 500- and 1,000-attendee plans. HDFaces is a video conferencing technology that lets up to six presenters lead interactive Q&A sessions, host panel discussions, or do demonstrations in high-definition.
The announcement comes after the recently announced availability of HDFaces for up to 100 participants in GoToWebinar and GoToTraining sessions, as Citrix adds high-definition video across its GoTo portfolio.