Wednesday, April 18, 2012

Apple Fights Mac Targeted Virus Aftermath

Story first appeared in PCWorld.com

It was a busy week for Apple malware hunters fighting the Flashback Trojan horse, which has infected between 270,000 and 600,000 Macs. A bevy of tools to find and remove the malware debuted this week, including several long term security solutions. And two days after promising to release a detection and removal tool, Apple finally offered its own fix.

Now, as the dust settles on what is considered to be the largest Mac malware threat to date, experts have started pointing fingers at Apple as being partially to blame for the scope of the Flashback malware infection. They argue that if Apple were more transparent about security issues--and if it had promptly released a Flashback fix--the extent of the damage could have been smaller. Also contributing to the magnitude of the infections is a boost in the number of Mac OS users, they say.

When the installed base [of an OS] is 10 percent or less, the bad guys don't care. The bigger the user base, the more attractive the target. Web analytics firm NetMarketShare.com estimates that the Mac installed base has jumped to 13 percent in the United States, and research firm Gartner says that Apple has become the fastest-growing U.S. computer maker--overtaking Acer and Toshiba--over the past year.

Apple's Image of Invulnerability--Gone

Perhaps surprisingly, security experts say that Apple needs to look to Microsoft when it comes to handling OS security breaches. For years Apple has mocked Microsoft for its track record in dealing with Windows malware, viruses, and weekly patches. Now the tables have turned.

The Flashback Trojan horse is the final nail in the coffin for Apple's stellar security image. He says that although Microsoft juggles a much larger number of threats, it does a better job of warning customers and delivering fixes.

We have heard dire "Macpocalypse" warnings before. Last year Apple's sterling security image was tarnished with the advent of the Mac Defender malware program. Before that, in 2006, the focus was on the Leap. A virus, the first ever virus for Mac OS X. (For a great short history of Apple Mac malware, check out NakedSecurity.com's timeline from 1982 to 2010.) But this time, security experts insist, Apple's security bragging rights are gone for good.

Mac Security Experts: Full Disclosure

It's worth noting that Mac security software sales jumped as Flashback infections began to dominate tech headlines. That fact has prompted many vocal critics to point out that it's in the self-interest of Mac antivirus companies to be critical of Apple's security measures.

But a brief timeline of Flashback, security experts say, illustrates their point. The underlying Java vulnerability that Flashback exploited was publicly known, and patched by Oracle, in February. On April 3, Apple released a Java security bulletin pointing to the Oracle patch, and declined to disclose, discuss, or confirm the infections. On Tuesday, Apple acknowledged the existence of Flashback and said that it was developing software to detect and remove the malware. On Thursday, it released the Flashback malware removal tool.

What Apple Can Learn From Microsoft Security

First off, there is no disputing that Microsoft, having the dominant OS, faces far more security threats than Apple does. You can argue all day about how secure Apple's flavor of BSD Unix is versus Microsoft's Windows, but the difference is Microsoft's transparency. As PCWorld's sibling publication Macworld puts it: Apple has a good security record, but it still has some work to do in terms of its reputation for security.

Mac OS users unfamiliar with Windows may be surprised to learn that Microsoft regularly schedules the rollout of security fixes on Patch Tuesday, the second Tuesday of each month. But for IT managers and consumers, knowing what's at risk and when a fix will be available is vital for minimizing exposure to threats. Microsoft also issues critical patches as they become available for exploits.

The system is not perfect; coupled with Windows Update, however, it offers a first line of defense against malware, exploits, and viruses.

Mac OS also automatically checks for software updates every week, and you can change that setting for more-frequent updates. But it's Apple's legendary wall of silence and foot-dragging on deploying fixes that have placed it in security experts' crosshairs.

When problems and vulnerabilities exist, Microsoft provides information quickly. Microsoft has been good at communicating, sometimes to the point of being annoying. Apple hasn’t done as much to communicate with its users.

Apple's iron grip on information and the release of fixes has been a nagging issue for years. In 2008, for example, Apple took over four months to patch a DNS vulnerability.

Why Apple did not deploy these fixes before Mac users were victimized by criminals is unclear.

Expect an evolution of threats against Mac users that will largely mirror those that Windows users face: that is, via the exploitation of vulnerable browser plug-ins, such as Adobe Reader, Flash, and most definitely Java.

Apple's Flashback fix, deployed Thursday, mitigates Java flaws. As a security hardening measure, the Java browser plug-in and Java Web Start are deactivated if they are unused for 35 days.

Ignorance Is Not Bliss


The bigger problem, say some observers, is correcting the perception that the Mac platform is invulnerable. That notion has fostered a laissez-faire attitude toward security among Apple customers.

For years Apple has promoted the idea that Macs are far less vulnerable to malware and viruses than PCs are.

Mac users are faced with new threats that require new security precautions.

A system administrator says that many of the student Mac users for whom he provides help-desk services live in denial. An IT manager for several state universities at the Tennessee Technology Center in Shelbyville, Tennessee, says students come to his staff with Mac problems and don't believe that their computers have been infected until shown the evidence.

Over the past few years, Mallard says, he has seen the percentage of infected Macs brought in by students jump from 1 to 15 percent.

Even though the Mac OS is more secure, its users don’t have the awareness. Educating users to the risks that they face is one of the most important things Apple can do, the same way you teach your kid to cross at the green light.

Bendable Displays In The Near Future?

Story first appeared in USA Today.

In the film The Graduate, cynical young protagonist Benjamin Braddock is pulled aside by an elder with sage advice: "Just one word. … Plastics," he whispers. "There's a great future in plastics."

The line became part of Hollywood lore, underpinning the yawning gulf between the counterculture and the status quo.

But 45 years after it entered the American zeitgeist, the punch line is serious stuff for tech companies such as Samsung and Hewlett-Packard. Flexible-display technology, the pliable plastic casings that many predict will be the next iteration of laptops and tablets, is morphing into all sorts of cool gadgets of the near future.

In a few years, bendable displays will be everywhere, adorning coffee mugs, newspapers, car dashboards and sunroofs, white boards, backpacks, refrigerators — you name it.  Within five years, every surface becomes a display.

The question, though, is when? And to what extent?

Flexible displays — computing screens that can be rolled, folded or flexed — can take the form of personal devices, such as an eReader, or larger surface displays, such as furniture or wallpaper.

Yet the flexible narrative has experienced fits and starts for years, and it still isn't likely to take hold until 2015.

The field is littered with noble failures and unfulfilled promises.

Philips Electronics spinoff Polymer Vision promoted its flexible eReader for years but declared bankruptcy before bringing the device to market. Hewlett-Packard has been developing printable Mylar displays that it imagines could be used for candy wrappers, armband computers for the military or living-room wallpaper, but the displays are still several years from commercialization.

The most likely scenario is that wildly popular tablets will be the first iteration of flexible technology.

Other emerging technology, such as wearables, embedded devices and mini-projectors, might catch on sooner when new manufacturing processes ramp up.  Consumers would love to bend or fold devices.  Rather than carry a phone and a tablet, you could unfold a large screen from your phone.

Any surface will do …

The promise of unbreakable, lightweight, non-glass displays has researchers and engineers at HP, Samsung and elsewhere toiling away in hopes of tapping into a potential gold mine.

Despite ups and downs, sales for flexible displays are expected to zoom to $8.2 billion in 2018 from $85 million in 2008.

Foldable technology is expected to take form in:

•Wristbands. HP is developing prototypes with the U.S. Army of a wristband for foot soldiers that is something out of the old Dick Tracy comic strip. HP also is huddling with the NFL about the possibility of an electronic wristband for quarterbacks to view and call plays.
Soldiers would be fitted with a bendable wristband that could also be sewn into their uniform's cuff. The small display could function as a combination Global Positioning System, shortwave radio and field manual for vehicle repairs. Such a device would significantly reduce the estimated 70 pounds of equipment typically lugged by soldiers, without sacrificing ruggedness.

A solar-powered wrist unit is set to undergo field testing by the military later this year.

The NFL could replace the balky helmet microphone now used with a plastic band for quarterbacks and defensive players to relay and view formations. The NFL had no comment.

Another possible use is digital bracelets for hospital patients, says Carl Taussig, director of HP Labs' Advanced Display Research.

•Kitchen counters. Microsoft's home of the future — think Ozzie and Harriet meets Futurama— is chock-full of digital displays, none more eye-catching than its kitchen counter.

The marble surface doubles as a display capable of input for ingredients and recipes. The graphics are beamed from an overhead projector, which could become a staple of homes within five years.

•Cars. Toyota showed a model at the Tokyo auto show late last year and the Detroit auto show this year that it described as a "smartphone on four wheels." In Tokyo, Toyota CEO Akio Toyoda unfurled the Fun-Vii (vehicle interactive Internet), which lets drivers change the car's color — both exterior and interior. Flexible screens embedded in the car's body allow the Fun-Vii to display multiple colors.

•Buildings. Remember the dystopian city in Ridley Scott's Blade Runner with screens that show advertisements built into buildings?

NanoLumens designs and engineers large, energy-efficient LED displays for commercial use. Its flagship product is the world's first flexible LED screen that is 112 inches diagonal, an inch thick and only 80 pounds.

The NanoFlex product is used to show video on a curved wall at the NASCAR Museum in Charlotte. A NanoSlim product is installed at the Mac Cosmetics store in New York's SoHo neighborhood

The thin but durable screens are being tested for advertising use at trade shows and in subways and airports. You can pressure wash it and bounce a beer bottle off of it.

China, home to some of the world's largest buildings, is a prime candidate for even larger displays.

What are consequences, if any?

So what's wrong with this picture of a seemingly boundless market for flexible displays?

The immense promise is undercut by nagging issues, such as the difficulty in properly bending silicon-containing electronic components.

Costly, time-consuming manufacturing processes also remain a steep hurdle. There are plenty of obstacles, none more so than glass-based displays.

The ticklish task of laying electronic components on glass, stainless steel or plastic is a tricky, multiple-step process that can be pricey.

The industry will only achieve mass production at affordable prices when it makes the inevitable, and necessary, shift to roll-to-roll manufacturing — as is customary in the newspaper industry. And that's a few years away.

Germany-based PolyIC is making flexible touch-screens. Corning has shown flexible glass that can be used in roll-to-roll manufacturing, and a low-end display from Samsung is a prime candidate for such a process. E Ink, Plastic Logic, Infinite Power Solutions and Universal Display all are doing interesting things in the field, but it is a work in progress.

Bendable displays can be made, but mass manufacturing is the obstacle.

There have been advances — LG just announced it started mass production of its electronic paper display product, with a planned launch in Europe next month — but few.

Until then, flexible displays will be visible in smaller, more modest designs such as smart security tags, shelf and food labels and loyalty cards with memory.

PARC, the storied research center that inspired many of the features in the original Macintosh computer, is tinkering with plastic memory, chips on consumer goods packaging, sensors on helmets, and more.

One project is a wearable patch with sensors to monitor a patient's heart rate, temperature and blood pressure. PARC is also looking at the concept of a flexible battery to save energy and space.

It all makes for an intriguing game of promise vs. patience.

Not every surface will be a display, but it could be. There are no barriers.

For more national and worldwide related business news, visit the Peak News Room blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For technology and electronics related news, visit the Electronics America blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.


Oakley Developing Tech Glasses Too

Story first appeared in the Bloomberg Business Week

Oakley Inc. is developing technology that can project information directly onto lenses, putting the sunglass maker into potential competition with Google Inc.

The technology would let Oakley, a division of Italy’s Luxottica Group, make hardware that’s comparable with Google’s Project Glass, an experimental effort to build smartphone features into eyewear.

Companies are stepping up efforts to build a wider range of electronics -- including articles of clothing -- that can connect wirelessly to the Internet. The market for so-called connected devices, a broad category that includes smartphones, tablets and PCs, may surge to 1.84 billion units in 2016, more than double the figure for last year, according to research firm IDC in Framingham, Massachusetts.

Oakley has been working on such technology since 1997. Ultimately, everything happens through your eyes, and the closer it can be brought to your eyes, the quicker the consumer is going to adopt the platform.

Oakley would initially target athletes with products based on the so-called heads-up technology. Oakley could develop a similar product for the U.S. military through Eye Safety Systems, a subsidiary that specializes in eyewear for military and government agencies.

Obviously, you can think of many applications in the competitive field of sports. That’s the halo point of where we would begin, but certainly you can transcend that into a variety of other applications.

‘Barrier to Success’

Early versions of the product would not be cheap. The product should be able to function on its own, while also working with a smartphone wirelessly using Bluetooth. The device might be controlled with voice commands, similar to Apple Inc.’s Siri software.

There’s a lot of interesting optical issues that come up when you’re trying to create a positive experience when interacting with these devices. So the technology barrier to success is significant.

Oakley released sunglasses in 2004 that featured an MP3 music player built in. While the Thump product line was not a big hit, it is profitable. The latest version, the Thump Pro, costs $129 for a half-gigabyte of storage. That means it holds one-fourth the songs as the smallest iPod, yet costs more than twice as much.

Oakley has been working on technology related to heads-up displays for about 15 years, and has 600 patents, many of which apply to optical specifications. The company would consider licensing the patents.

The CEO declined to comment on whether Oakley would release its own so-called smart glasses, but he said the market for such a device is ripe. He said Oakley would have an edge over more tech-savvy competitors because the company is able to create stylish accessories.


For more technology and electronics related news, visit the Electronics America blog.
For national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.

Wireless Market Headed for a Wall

Story first appeared on Bloomberg Business Week

The U.S. wireless market, long the fastest-growing sector in the telecommunications industry, looks like it’s headed for a wall.

Sales of wireless contracts, the most lucrative segment of the business because it locks in monthly payments over long periods, may have shrunk for the first time ever in the first quarter. One big reason for the sharp reversal: Soaring iPhone sales in late 2011 may have satiated consumers’ appetites for wireless plans.

A decline would mark a turning point for the previously rapid-growth business, leaving carriers such as AT&T Inc., Verizon Wireless and Sprint Nextel Corp. fighting over a shrinking pool of customers. A slowdown also forces device manufacturers such as Apple Inc. and Samsung Electronics Co. to battle more intensely for customers.

The huge fourth quarter fueled by the iPhone took all the air out of the first quarter. It’s now a saturated market.

U.S. wireless carriers shed a combined 20,000 contract customers in the first quarter.

The decline forces carriers to seek revenue gains at the expense of weaker players. That may mean increasing promotional activity by carriers who already are selling smartphones at a loss to lure users into two-year contracts, a practice that has reduced profit margins.

To offer the iPhone, for instance, carriers already pay Apple about $600 per phone and then collect $199 from retail customers, subsidizing the difference with revenue from monthly service charges.

These subsidies have narrowed wireless operating income margins at AT&T to 15.2 percent in the fourth quarter, down from 30 percent in the first quarter of 2010.

‘Milestone’

What you’ll see in a saturated market are the forces of consolidation and price pressure. Margins in the U.S. have already been shrinking at a faster rate than any other time in the wireless industry. The possibility that the contract-user number dropped in the first quarter could also be factored in.

The industry is maturing. Given that the pie isn’t growing rapidly any longer, it’s now a game of share-shifting.

IPhone Surge

Within the industry, AT&T and Verizon Wireless probably kept winning users from smaller rivals T-Mobile USA and Sprint Nextel Corp. T-Mobile probably lost 600,000 contract customers and Sprint 125,000 last quarter. Verizon Wireless added 500,000 contract users and AT&T gained 225,000 such customers.

The potential first-quarter drop follows exceptionally strong gains in the previous period, when holiday sales of Apple Inc.’s new iPhone 4S boosted subscriber numbers. The first quarter also is traditionally the slowest sales period for the industry, and contract-subscriber growth may resume after that.

Some analysts say the market may have avoided a contraction in the first quarter. The big four carriers -- Verizon Wireless, AT&T, Sprint and T-Mobile USA -- added 380,000 contract customers collectively.

Sprint, based in Overland Park, Kansas, rose 4 percent to $2.61 yesterday, and AT&T added 0.9 percent to $30.89. Verizon Communications Inc., which owns Verizon Wireless with Vodafone Group Plc, advanced 0.8 percent to $37.74. T-Mobile is a unit of Deutsche Telekom AG. 

Market Penetration

Gains in the prepaid market -- a smaller, faster-growing part of the mobile-phone business -- means the wireless industry as a whole kept adding users in the first quarter. Still, in that market, which includes carriers MetroPCS Communications Inc. and Leap Wireless International Inc., the growth also is slowing.

The number of new prepaid customers added by the industry in the first quarter was an estimated 2.5 million, an 18 percent decline from the year-earlier growth rate.

If you take out every kid under 10 and every adult over 80, you have a market with 125 percent penetration. It’s no surprise the industry is maturing.



For more technology and electronics related news, visit the Electronics America blog.
For national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.


Tuesday, April 17, 2012

Supercookies Stealing Personal Information

Story first appeared in the Wall Street Journal.

Major websites such as MSN.com and Hulu.com have been tracking people's online activities using powerful new methods that are almost impossible for computer users to detect, new research shows. Unfortunately, security solutions may not be effective against these so called "supercookies".

What 'History Stealing' Is

The new techniques, which are legal, reach beyond the traditional "cookie," a small file that websites routinely install on users' computers to help track their activities online. Hulu and MSN were installing files known as "supercookies," which are capable of re-creating users' profiles after people deleted regular cookies, according to researchers at Stanford University and University of California at Berkeley.

Websites and advertisers have faced strong criticism for collecting and selling personal data about computer users without their knowledge, and a half-dozen privacy bills have been introduced on Capitol Hill this year.

Many of the companies found to be using the new techniques say the tracking was inadvertent and they stopped it after being contacted by the researchers.

The associate general counsel at MSN parent company Microsoft Corp., said that when the supercookie was brought to their attention, and they were alarmed by it. It was inconsistent with their intent and their policy. He said the company removed the computer code, which had been created by Microsoft.

WSJ reports so-called 'supercookies' reside in web sites that are tracking web users' activities and can continue to track users after they click a box to remove cookies from their computer.

Hulu posted a statement online saying it acted immediately to investigate and address the issues identified by researchers. It declined to comment further.

The spread of advanced tracking techniques shows how quickly data-tracking companies are adapting their techniques. When The Wall Street Journal examined tracking tools on major websites last year, most of these more aggressive techniques were not in wide use.

But as consumers become savvier about protecting their privacy online, the new techniques appear to be gaining ground.

A Stanford researcher identified what is known as a "history stealing" tracking service on Flixster.com, a social-networking service for movie fans recently acquired by Time Warner Inc., and on Charter Communications Inc.'s Charter.net.

Such tracking peers into people's Web-browsing histories to see if they previously had visited any of more than 1,500 websites, including ones dealing with fertility problems, menopause and credit repair, the researchers said. History stealing has been identified on other sites in recent years, but rarely at that scale.

The researchers determined that the history stealing on those two sites was being done by Epic Media Group, a New York digital-marketing company. Charter and Flixster said they didn't have a direct relationship with Epic, but as is common in online advertising, Epic's tracking service was installed by advertisers.

The chief executive of Epic, says his company was inadvertently using the technology and no longer uses it. He said the information was used only to verify the accuracy of data that it had bought from other vendors.

Both Flixster and Charter say they were unaware of Epic's activities and have since removed all Epic technology from their sites. Charter did the same last year with a different vendor doing history stealing on a smaller scale.

Gathering information about Web-browsing history can offer valuable clues about people's interests, concerns or household finances. Someone researching a disease online, for example, might be thought to have the illness, or at least to be worried about it.

The potential for privacy legislation in Washington has driven the online-ad industry to establish its own rules, which it says are designed to alert computer users of tracking and offer them ways to limit the use of such data by advertisers.

Under the self-imposed guidelines, collecting health and financial data about individuals is permissible as long as the data don't contain financial-account numbers, Social Security numbers, pharmaceutical prescriptions or medical records. But using techniques such as history stealing and supercookies "to negate consumer choices" about privacy violates the guidelines.

Until now, the council has been trying to push companies into the program, not kick them out.

Last year, the online-ad industry launched a program to label ads that are sent to computer users based on tracking data. The goal is to provide users a place to click in the ad itself that would let them opt out of receiving such targeted ads. (It doesn't turn off tracking altogether.) The program has been slow to catch on, new findings indicate.

The industry has estimated that nearly 80% of online display ads are based on tracking data. Only 9% of the ads they examined on the 500 most popular websites—62 out of 627 ads—contained the label. They looked at standard-size display ads placed by third parties between Aug. 4 and 11.

The industry says self-regulation is working. The labeling program has made tremendous progress.

Several Microsoft-owned websites, including MSN.com and Microsoft.com, were using supercookies.

Supercookies are stored in different places than regular cookies, such as within the Web browser's "cache" of previously visited websites, which is where the Microsoft ones were located. Privacy-conscious users who know how to find and delete regular cookies might have trouble locating supercookies.

Supercookies have also been found on Microsoft's advertising network, which places ads for other companies across the Internet. As a result, people could have had the supercookie installed on their machines without visiting Microsoft websites directly. Even if they deleted regular cookies, information about their Web-browsing could have been retained by Microsoft.

Microsoft's representative said that the company removed the code after being contacted, and that Microsoft is still trying to figure out why the code was created. A spokeswoman said the data gathered by the supercookie were used only by Microsoft and weren't shared with outside companies.

Separately last month, researchers at the University of California at Berkeley, found supercookie techniques used by dozens of sites. One of them, Hulu, was storing tracking coding in files related to Adobe Systems Inc.'s widely used Flash software, which enables many of the videos found online, the researchers said in a report. Hulu is owned by NBC Universal, Walt Disney Co. and News Corp., owner of The Wall Street Journal.

Hulu was one of several companies that entered into a $2.4 million class-action settlement last year related to the use of Flash cookies to circumvent users who tried to delete their regular cookies.

The Berkeley researchers also found that Hulu's website contained code from Kissmetrics, a company that analyzes website-traffic data. Kissmetrics was inserting supercookies into users' browser caches and into files associated with the latest version of the standard programming language used to build Web pages, known as HTML5.

In a blog post after the report was released, Kissmetrics said it would use only regular cookies for future tracking. The company didn't return calls seeking comment.

For technology and electronics related news, visit the Electronics America blog.
For national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.

IT Security Breaches a Major Concern

Story first appeared in the Wall Street Journal

A recent wave of information-security breaches at high-profile companies has many executives on heightened alert. They're trying to figure out everything they can do to prevent breaches, limit the damage if one occurs, and be prepared to rebound quickly from whatever harm is done.

As they consider their options, two questions loom large: How much should they spend to protect their companies' information? And how can they get the most for their money?

Our research suggests they should spend substantially less than the expected loss from a breach, and perhaps spend it differently than many might think.  Investing in a managed IT service is a good way to go, as they typically offer security solutions, backup solutions, and disaster recovery solutions in the case of a breach.

The One-Third Mark

We developed a model to help executives determine the optimal level of investment to protect a given set of information—whether it's customers' personal information, company financial data, strategic-planning documents or something else. The model weighs the potential loss from a security breach, the probability that a loss will occur, and the effectiveness of additional investments in security.

One key finding from the model: The amount a firm should spend to protect information is generally no more than one-third or so of the projected loss from a breach. Above that level, in most cases, each dollar spent will reduce the anticipated loss by less than a dollar.

A second key finding: It doesn't always pay to spend the biggest share of the security budget to protect the information that is most vulnerable to attack, as many companies do. For some highly vulnerable information, reducing the likelihood of breaches by even a modest amount is just too costly. In that case, companies may well get more bang for their buck by focusing their spending on protection for information that is less vulnerable.

Working It Out
The following four-step approach has proved useful in helping executives sort all this out:

Step 1. Estimate the potential loss from a security breach for each of the company's various sets of information. For starters, it's useful to simply categorize information sets as having either Low Value, Medium Value or High Value.

Step 2. For each set of information, estimate the likelihood that it will be stolen, by examining the probability of an attempt to steal the information and the vulnerability of the information to attack. Again, broad categories are useful: Designate each set of information as either Low Threat/Vulnerability, Medium Threat/Vulnerability or High Threat/Vulnerability.

To combine the two factors, assign each a numerical rating—say, on a scale from 1 to 10—and multiply the two numbers by each other.

Using that scale, you might consider any combined ranking below 30 to be Low Threat/Vulnerability, and any ranking above 70 to be High Threat/Vulnerability; different people will draw those lines in different places.

A key point: Information that is highly vulnerable to attack but unlikely to interest a hacker (think of a banged-up old subcompact parked with the keys in the ignition, in a high-crime neighborhood), or that is very attractive to a thief but is very well protected (a brand-new luxury car on the White House grounds), would fall into the Low Threat/Vulnerability category.

Step 3. Create a grid with all the possible combinations of the first two steps, from Low Value, Low Threat/Vulnerability up to High Value, High Threat/Vulnerability. Then plot each set of information on the grid. This gives a clear view of where the greatest potential losses lie—not just in terms of the cost of a breach, but also in terms of its likelihood.

Step 4. Focus spending where it can reap the largest net benefits—where a given amount of money will produce the biggest reduction in potential loss.

Security investments should continue to be made as long as the incremental benefits are greater than the incremental costs—which usually stops being the case where the costs are roughly one-third of the total expected loss from a security breach.

Security breaches can have a substantial negative effect on corporations. However, contrary to conventional wisdom, the overwhelming majority of security breaches have little economic impact on corporations—all the more reason to use this kind of cost-benefit analysis to allocate finite information-security resources.

However, this approach is best thought of as a framework, not a panacea, for making sound information-security investments. It is not a magical formula that can be used to churn out exact answers. Rather, it should be used as a complement to, and not as a substitute for, sound business judgment.


For more technology and electronics related news, visit the Electronics America blog.
For national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.

Monday, April 16, 2012

Physical Books Not Outdated Yet

Story first appeared in the Los Angeles Times.

Reading habits may be fundamentally changing, but a new survey shows that the printed word remains fundamental.

Although many Californians who own Kindles, Nooks and other e-readers love their gadgets, they still prefer books the old-fashioned way — on paper — according to a poll by USC Dornsife and the Los Angeles Times.

Even with sales of e-readers surging, only 10% of respondents who have one said they had abandoned traditional books. More than half said most or all of the books they read are in printed form.

The pleasure of reading endures in the digital age, even with its nearly boundless options for entertainment, according to data collected from 1,500 registered state voters. Six in 10 people said they like to read "a lot," and more than 20% reported reading books for more than 10 hours a week.

Young adults — often assumed to be uninterested — read about as much as many of their elders. An overwhelming portion (84%) of those ages 18 to 29 said they like to read some or a lot; that's only a percentage point less than for respondents 50 and older. Sixty-five percent of the younger group said they read books for pleasure three or more hours a week; 69% of those 50 to 64 said the same.

And age is clearly no barrier to new habits. Folks over 50 are embracing some new reading technology at about the same rate as younger people. Twenty-two percent of those ages 18 to 49 own e-readers; 20% of people 50 and older have them.


How much education people have helps determine how much — and how — they read, the poll shows. More than 7 in 10 college-educated respondents said they read "a lot," while only half of those with no college said they did. Those who went to college are also more likely to use an e-reader.

Owners of e-readers are more likely to read books, read more books and spend more hours each week reading. About 4 in 10 said they devoured four or more books a month.

Technology has turned some people away from the printed book however.  When you travel for work alot, carrying books is awkward and bulky.

But the sensation of hefting a physical book, opening its thick cover and turning its delicate pages is hard-wired in some people. Words illuminated on screens are a cold substitute.


The poll was conducted for USC's Dornsife College of Letters, Arts and Sciences and the Los Angeles Times by two companies: Greenberg Quinlan Rosner Research and American Viewpoint. The survey took place March 14-19. The margin of error is 2.9%.


For more technology and electronics related news, visit the Electronics America blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.