Showing posts with label industry. Show all posts
Showing posts with label industry. Show all posts

Saturday, 31 October 2015

2015 technology industry graveyard

2015 technology industry graveyard
Cisco, Microsoft, Google and others bury outdated technologies to move ahead with new ones.

Ba-bye
The Technology Industry Graveyard is pretty darn full in 2015, and we’re not even including the near-dead such as RadioShack and Microsoft’s IE browser. Pay your respects here…

GrooveShark
The self-described “World’s Music Library” is no more after shutting down in April in the wake of serious legal pressure by music companies whose songs GrooveShark allowed to be shared but had never licensed. Apple and Google had each kicked GrooveShark out of their app stores years ago due to complaints from music labels. Much more sadly than the 9-year-old company’s demise, however, was the death of co-founder Josh Greenberg in July at the age of just 28.

Typo iPhone keyboard
Not even the glamor of being co-founded by American Idol host Ryan Seacrest could help Typo Innovations save its iPhone keyboard, which BlackBerry said infringed on its patents. So instead, Typo bailed on the iPhone model and settled for selling ones for devices with screens 7.9-inches or larger (like iPads).

Amazon Fire Phone
With a product name like Fire, you’re just asking for colorful headlines if it bombs. And indeed, Amazon has stopped making its Fire Phone about a year after introducing it and media outlets were quick to highlight the company “extinguishing” it or remarking on the phone being “burnt out.” Amazon has had some success on the hardware front, namely with its Kindle line, but the Fire just didn’t distinguish itself and was going for free with a carrier contract by the end.

Interop New York
Interop Las Vegas carries on as one of the network industry’s top trade shows next May, but little sibling Interop New York is no more this year. The Fall show, traditionally held at the Javits Center since 2005, was always smaller and was discontinued for 2015 despite lively marketing material last year touting “More Than 30 Interop New York Exhibitors and Sponsors to Make Announcements in Anticipation of the Event.”

GTalk
Google ditched so many things in 2015 that we devoted an entire slideshow to Google’s Graveyard. So to choose just one representative item here, we remember Google Talk, which had a good run, starting up in 2005. But it’s never good when Google pulls out the term “deprecated” as it did in February in reference to this chat service’s Windows App. Google said it was pulling the plug on GTalk in part to focus on Google Hangouts in a world where people have plenty of other ways to chat online. However, Google Talk does live on via third-party apps.

Cisco Invicta storage products
Cisco has a good touch when it comes to acquisitions, but its $415 mlllion WHIPTAIL buyout from 2013 didn’t work out. The company in July revealed it had pulled the plug on its Invicta flash storage appliances acquired via that deal. It’s not unthinkable though that Cisco could go after another storage company, especially in light of the Dell-EMC union.

RapidShare
The once-popular file hosting system, begun in 2002, couldn’t withstand the onslaught of competition from all sides, including Google and Dropbox. Back in 2009, the Switzerland-based operation ran one of the Internet’s 20 most visited websites, according to Wikipedia. It shut down on March 31, and users’ leftover files went away with it.

Windows RT devices
This locked-down Microsoft OS for tablets and convertible laptops fared about as well as Windows 8, after being introduced as a prototype in 2011 at the big CES event in Las Vegas. Microsoft’s software for the 32-bit ARM architecture was intended to enable devices to exploit that architecture’s power efficiency, but overall, the offering proved to be a funky fit with existing Windows software. Production of RT devices stopped earlier in 2015 as Microsoft focuses on Win10 and more professional-focused Surface devices.

OpenStack vendor Nebula
As Network World’s Brandon Butler wrote in April, Nebula became one of the first casualties of the open source OpenStack cloud computing movement when it shuttered its doors. The company, whose founder was CIO for IT at NASA before starting Nebula in 2011, suggested in its farewell letter that it was a bit ahead of its time, unable to convert its $38 million in funding and hardware/software appliances into a sustainable business.

FriendFeed
Facebook bought this social news and information feed aggregator in 2009, two years after the smaller business started, and then killed it off in April. People have moved on to other means of gathering and discovering info online, so FriendFeed died from lack of use. It did inspire the very singular website, Is FriendFeed Dead Yet, however, so its legacy lives on.

Apple Aperture
Apple put the final nails in its Aperture photo editing app in 2015, ending the professional-quality post-production app’s 10-year run at Version 3.6. In its place, Apple introduced its Photos app for users of both its OS X Mac and iOS devices.

Secret
One of the co-founders of anonymous sharing app shared this in April: The company was shutting down and returning whatever part of its $35 million in funding was left. The company’s reality was just not going to meet up with his vision for it, said co-founder David Byttow. The company faced criticism that it, like other anonymous apps such as Yik Yak, allowed for cyberbullying.

Amazon Wallet
Amazon started the year by announcing its Wallet app, the company’s 6-month-old attempt to get into mobile payments, was a bust. The app, which had been in beta, allowed users to store their gift/loyalty/rewards cards, but not debit or credit cards as they can with Apple and Google mobile payment services.

Circa News app
Expired apps could easily fill an entire tech graveyard, so we won’t document all of their deaths here. But among them not making it through 2015 was Circa, which reportedly garnered some $4 million in venture funding since starting in 2012 but didn’t get enough takers for its app-y brand of journalism.


Wednesday, 29 April 2015

Cyber extortion: A growth industry

The traditional philosophy of never negotiating with extortionists has had to adapt to the realities of cybercrime – if you don’t pay, your data may be lost forever

The prevailing wisdom in law enforcement has been that it is a bad idea to negotiate with extortionists. Cave to their demands and all you’re doing is encouraging more extortion. And you don’t even have a guarantee that paying a ransom will produce the return of your loved one unharmed, or your stolen assets.

Better to refuse the demands, find the criminals and punish them in a way that will discourage them and others from doing the same thing.

But, in the digital world, where criminals encrypt data and then demand a ransom to provide the key, that prevailing wisdom is getting a forcible adjustment.

The first reality is that, much of the time, cyber extortionists are far beyond the reach of domestic law enforcement. Second, most of them actually make good on unlocking the data once the ransom has been paid, because they want future victims to pay up as well.

In some cases, it is law enforcement itself that is paying the ransoms. The Boston Globe reported recently that the police department in Tewksbury, a Boston suburb, had paid a $500 ransom to criminals who had encrypted data including arrest and incident records.

“(S)pecialists from federal and state law enforcement agencies – plus two private Internet security firms – could not unscramble the corrupted files,” the paper reported.

There have been similar stories in police departments near Chicago, in Tennessee, New Hampshire and Alabama.
MORE ON NETWORK WORLD: 26 crazy and scary things the TSA has found on travelers

In short, this is a growth industry. Most thieves have learned that if they keep the ransom relatively low – a few hundred dollars – and get a reputation for providing the encryption key once the ransom has been paid, those few hundred dollars per victim can add up to thousands per month.

Val Saengphaibul, security response manager at Symantec, said his firm knows of one cyber gang that makes, “at least $35,000 a month. Other cyber-gangs have taken note and there are quite a few of them running this scam,” he said, noting that, “payment is not easily traced or stopped, and targeting specific data files that are valuable to people and organizations increases the likelihood of payment.”

Indeed, a recent survey by ThreatTrack Security found that 30% of the security professionals who responded said they would negotiate with the extortionists. And that percentage rose to 55% among organizations that have already fallen victim to cyber-extortionists.

Some of that was conditional. When asked if organizations should set aside funds for paying ransoms to recover their data, 45% gave a conditional “yes,” but nearly half of them said it would “depend on the data.” The most important, in their view, were employee Social Security numbers, addresses and salaries.”
"Cybercriminals’ No. 1 priority is making money, not keeping their word."

Stuart Itkin, senior vice president, ThreatTrack

Stuart Itkin, ThreatTrack’s senior vice president, said there is obviously no guarantee that criminals will unlock the encrypted data, but that it is in their, “best interest to keep their word so victims succumb and they continue making money by infecting more people.”

He said ransomware developers have even, “created safeguards to ensure their malware doesn’t infect the same victims again after they’ve paid a ransom.”

Jody Westby, CEO of Global Cyber Risk, also said in her experience, cyber extortionists have kept their side of the deal. She said for most of her clients, it comes down to a business decision.

“I have seen IT guys say, ‘No way, we aren't negotiating or paying a dime,’” she said. “But then the CFO or another C-suite executive gets involved, evaluates the amount of money requested, and says it is a no-brainer: They are going to pay and keep the business running. It would cost more to have the system down.”

Of course, not all extortionists are so “honorable”. According to Saengphaibul, “if you look hard enough, you’ll find numerous victims experiences showing hackers not upholding their end of the deal by not unlocking computers after ransom is paid.”

Saengphaibul said Symantec sticks with the more traditional law enforcement philosophy – don’t pay up.

“Paying the ransom just further promotes this illegal activity,” he said. “It’s unlikely that victims will get their files back anyway, so don’t put money in the criminals’ pockets. If we deny the criminals profit, then there is no point in running the scam. They move on.”

He said if extortion targets have regularly backed up their files, they can’t be victimized in the first place. “When there is no demand on the underground economy for ransomware attack services, hackers will ultimately be out of business,” he said.

But, particularly for businesses, it is not always as simple as having backup files.

“Everyone should have backups,” Westby said. “But that is not the issue. The issue is having the data disclosed. They pay to get it back so it won't be disclosed.”

She said if a company refuses to pay the demanded ransom, extortionists can start making it public. “They can start disclosing data in pieces, or send some of the most damaging to the press, they can sell the data on the black market or to a competitor company,” she said.

“The damage is to reputation, loss of market share, loss of customer and pricing data or other strategic business data that could have a real impact on the bottom line.”

Itkin agrees. “Data breach headlines, lawsuits, eroded customer trust and other collateral damage a breach can cause gives (extortionists) tremendous leverage,” he said.
MORE ON CSO: What is wrong with this picture? The NEW clean desk test

“All you have to do is look at the fallout from the Sony breach. First, the extortionists succeeded in manipulating Sony’s release of a major motion picture, which had financial consequences for not just Sony, but the theaters that planned to screen it, among others. Second, their data was perfect for wide-spread media appeal – dripping with Hollywood gossip.”
"I have seen IT guys say, ‘No way, we aren't negotiating or paying a dime. But then the CFO or another C-suite executive gets involved, evaluates the amount of money requested, and says it is a no-brainer: They are going to pay and keep the business running."
jody westby

Jody Westby, CEO, Global Cyber Risk

That means, while data backups ought to be regular and automatic, they are not enough. Rigorous, end-to-end encryption ought to be mandatory as well, since it can make most stolen data useless to extortionists.

With stolen encrypted data, “criminals don't even know what they have to ask ransom for it,” Westby said, adding that, “cyber extortion insurance also is good, because we are in a new era of cybercrime.”

But beyond backups and encryption, experts including Saengphaibul say that, “security is multilayered and requires an encompassing approach – endpoint security, employee training, system updates, etc.”

Security, he said, should include not just traditional anti-virus, but also, “download protection, browser protection, heuristic technologies, firewall and a community sourced file reputation scoring system.”

And when it comes to negotiation, Itkin said security pros should, “always be aware that cybercriminals’ No. 1 priority is making money, not keeping their word.”

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com