Sunday, 1 February 2015

7 Reasons Not to Use Open Source Software

7 Reasons Not to Use Open Source Software

Businesses of all sizes embrace open source software and the benefits it can bring. Sometimes, though, choosing proprietary software makes better business sense. Here are seven scenarios when it pays to pay for your software.

Talk to an open source evangelist and chances are he or she will tell you that software developed using the open source model is the only way to go.
The benefits of open source software are many, varied and, by now, well-known. It's free to use. You can customize it as much as you want. Having many sets of eyes on the source code means security problems can be spotted quickly. Anyone can fix bugs; you're not reliant on a vendor. You're not locked in to proprietary standards. Finally, you're not left with an orphaned product if the vendor goes out of business or simply decides that the product is no longer profitable.


However, the open-source evangelist probably won't tell you that, despite all these very real benefits, there are times when using closed-sourced, proprietary software actually makes far more business sense.
Here are some of the circumstances when old-fashioned proprietary products are a better business choice than open source software.

1. When It's Easier for Unskilled Users
Linux has made a huge impact on the server market, but the same can't be said for the desktop market - and for good reason. Despite making strides in the last several years, it's still tricky for the uninitiated to use, and the user interfaces of the various distributions remain far inferior to those of Windows or Mac OS X.
While Linux very well may be technically superior to these proprietary operating systems, its weaknesses mean that most users will find it more difficult and less appealing to work with. That means lower productivity, which will likely cost far more than purchasing a proprietary operating system with which your staff is familiar.

2. When It's the De Facto Standard
Most knowledge workers are familiar with, and use, Microsoft Word and Excel. Even though there are some excellent open source alternatives to Office, such as LibreOffice and Apache OpenOffice, they aren't identical in terms of functionality or user interface, performance, plugins and APIs for integration with third-party products. They are probably close enough as much as 90 percent of the time, but on rare occasions there's a risk that these differences will cause problems - especially when exchanging documents with suppliers or customers.


It also makes sense to use proprietary software in specialist fields where vendors are likely to have gone into universities and trained students on their software. "The software may not necessarily be better, but it may be selected by a university before an open source solution gets a big enough community around it," says Chris Mattman, an Apache Software Foundation member and a senior computer scientist at the NASA Jet Propulsion Laboratory.
"When that happens, the students will then know the software better and be more productive with it," Mattman says. When the students then move into a business environment, it makes sense for them to continue with the software they are used to.

3. When Proprietary Software Offers Better Support
Business-class support is sometimes available for open source software, either from the company leading the project or a separate third-party. This isn't the case often, though - and that can be a problem, according to Tony Wasserman, professor of software management practice at Carnegie Mellon University.

"Some customers prefer to have someone outside the company to call for product support on a 24/7 basis and are willing to pay for a service level agreement that will provide a timely response," he says. "People often respond very quickly to queries posted on the forum pages of widely-used open source projects, but that's not the same thing as a guaranteed vendor response in response to a toll-free telephone call."

4. When You Want Software as a Service
Cloud software is slightly different than conventional software. As a general rule, you don't get access to the source code, even if the hosted software is built entirely on open source software. That may not make the software proprietary, strictly speaking, but it doesn't give you all the benefits of open source. In that sense, the benefits of using the "pay for what you use" software as a service model may outweigh the disadvantage of not having access to the source code.

5. When Proprietary Software Works Better With Your Hardware
Many types of proprietary hardware require specialized drivers; these are often closed source and available only from the equipment manufacturer. Even when an open source driver exists, it may not be the best choice. "Open source developers may not be able to 'see' the hardware, so the proprietary driver may well work better," Mattman says.

6. When Warranties and Liability Indemnity Matter
Some open source software companies, such as Red Hat, are structured to look like proprietary software vendors. They accordingly offer warranties and liability indemnity for their products, just like proprietary vendors do. "These companies are exactly the same as proprietary software companies, except that they won't take you out to play golf," Wasserman says.
For every Red Hat, though, there are many open source projects that aren't backed by a commercial organization. While you may get warranties and liability from a third-party, in many cases you won't. If that doesn't suit you or your company's software procurement policies, then you're advised to find a proprietary vendor.

7. When You Need a Vendor That Will Stick Around
Yes, there's no guarantee that a commercial software vendor will stick with a product if demand drops to such an extent that it's no longer profitable to develop it. The company itself may even go out of business. But if an open source project is small, there's also a danger that the person behind it may lose interest. If that happens, it may not be easy to find another open source developer to step in.

(This may be more of an argument against small open source projects than an argument for proprietary software - but at least you can look into the books of large software companies and make an informed decision as to whether they're likely to be around in a few years to honor any commitments they give you.)

Don't Be Too Dogmatic About Open Source Software
The lesson here: While open source software may often - and even usually - be a better choice than functionally similar proprietary offerings, it doesn't make sense to be too dogmatic about it.
"As a practical matter, I think that many people would prefer to have everything open, especially in light of the recent revelation about the NSA spying on machines through USB chips," Wasserman says. At the same time, though, many of those who prefer open source will make exceptions when there are no practical alternatives - not to mention their use of Mac and iOS devices ... "

How to Test the Security Savvy of Your Staff

How to Test the Security Savvy of Your Staff

How do you know your employees retain what you teach them in company-required security awareness training? You don't -- unless you regularly test their security savvy and effectively address their mistakes during post-test follow-up sessions.

How to Test the Security Savvy of Your Staff
Security can be an acute pain point for CIOs. There might be nothing that causes more sleepless nights than ensuring the security of an organization's data and systems. Specialists fortify the network perimeter with firewalls and IDPSs, segment the network and perform regular audits and rigorous assessments. They also classify data and isolate critical files, and follow best practices regarding least privilege and security policies.
Unfortunately, these efforts are vulnerable to the actions of undereducated or malicious users. In its 2013 global, the Ponemon Institute estimates that the average total cost of a data breach in the United States is just over $5.4 million. Roughly 67 percent of the incidents resulted from a malicious or criminal attack or a system glitch, but 33 percent are attributed to the human factor, such as a negligent employee or contractor. It can all start with a single click on the wrong link in an email or trusting an imposter.

[ Study: Most Data Breaches Caused by Human Error, System Glitches ][ How-to: Address the Human Element of Data Security ]

User training is an essential part of any security program. Most employees aren't IT or security experts. Nor should you expect them to be. The purpose of security training and awareness is to provide all employees with basic security knowledge, as well as appropriate actions to take when presented with a possible security situation.

Technology must be accompanied by awareness training to protect against social engineering and phishing, two common causes of data leakage and breaches. However, once you've spent time and budget delivering a terrific training program, how do you know your employees have retained the information they learned and are putting it to good use?

4 Security Testing Approaches That Surprise Employees
Testing your employee's security savviness helps you detect who is or might be prone to giving away sensitive organization or customer information. Approaches to testing include the following:

Administer quizzes. The folks who host security awareness training should administer multiple-choice quizzes during training and a few times each year at random. Post a Web-based quiz and vary the questions so employees don't get used to a pattern or share answers in order to get it over with as quickly as possible.

Perform random work area checks. Employees can become desensitized or complacent to the information around them. Check employee desk security for documents and sticky notes that contain confidential information. Are they out in the open so anyone walking by can view or take them? See if filing cabinets are locked and if document storage boxes are left in unlocked work areas. Also check whether employees' computers are still logged on, without password protection, when they're away from their desk.

Become a white hat social engineer. Appoint a staff member who isn't well known in the organization (or hire a consultant) to call employees or stop by their desks, requesting confidential information such as logon credentials or information in a non-public document. The social engineer should have a "pertinent" story ready as to why he or she needs the information.
[ Feature: 6 Ways Employees Put Company Data at Risk ][ Tips: How to Prevent Thumb Drive Security Disasters ]

Simulate phishing email attacks. A phishing email contains links to malicious websites or payload-filled attachments. The email is designed to look legitimate, which throws off the typical user. One of the best ways to find out if employees are mindful of phishing emails is to send some to their inboxes. Your test emails should contain some clues that they are not from the purported sender (for post-testing educational purposes) and contain links that go to a safe website. The site could simply be a page that says, "Security awareness training - phishing test in progress." Security technicians can gather IP addresses of visitors to the page to monitor which employees visited the site and therefore clicked the link.
If your staff is short on time, consider hiring a third party to help you perform simulated phishing attacks. Companies such as KnowBe4 and OneLogin either perform the tests on your employees or provide you with a portal that requires you to enter employee email addresses. You'll get reports detailing the results of the tests to use for additional training.

Follow Up on Security Tests
Talk to employees who click on a phishing link or fall for social engineering tricks as soon as possible. Explain that, although this was only a test, the next incident could be real and result in the theft of important organization or customer data. Your goal isn't to embarrass or belittle your staff but, rather, to further educate them and deepen your organization's security posture.
Organizations that must adhere to government regulations should stress the consequences of a security breach on their compliance status. Failing to maintain effective security, even as a result of user error, can result in an organization being out of compliance and might lead to criminal, legal or financial penalties.
[ Related: How to Prevent Healthcare Data Breaches - and What to Do If You're a Victim ][ Also: Wall Street Sets Example for Testing Security Defenses ]

IT should consider performing a second test on this subset of employees within a few weeks to gauge workers progress. Some employees might need additional tests and reminders before they internalize the gravity of potential security breaches.
In discussions with employees after phishing tests, point out elements of the phishing email that should raise red flags. For example, an email that contains spelling and grammatical errors, or threatening language, is most likely bogus. The sender's URL can offer clues as well, especially if it contains an IP address or originates from a domain other than the alleged company's domain.
When it comes to social engineering, many employees feel that security is someone else's problem, from security guards to management; others are simply reluctant to get involved. Make them feel empowered to stop and ask an unknown person why they're in the building and coach them on how to ask for credentials in a professional manner. Regardless of the type of test, emphasize the appropriate steps the employees should have taken, such as contacting a supervisor or the security department immediately.
It's not just general employees who are prone to security gaffes - senior managers struggle with security policies and guidelines, too.

After a round of testing and follow-ups, create a list of lessons learned to improve your program. Remember: A good security awareness program should be ongoing, interactive, include different learning formats and have repetition built in. Post security awareness signs around the workplace, schedule short workshops and seminars and be sure to recognize employees who have demonstrated that they take security as seriously as you do.

 

 

In 2015, expect to see the cloud mature as a platform for hybrid operations, with cloud data centers achieving new efficiencies through containers

Read more at: http://www.informationweek.in/informationweek/news-analysis/299061/cloud-trends-2015?utm_source=referrence_article
In 2015, expect to see the cloud mature as a platform for hybrid operations, with cloud data centers achieving new efficiencies through containers

Read more at: http://www.informationweek.in/informationweek/news-analysis/299061/cloud-trends-2015?utm_source=referrence_article
 
In 2015, expect to see the cloud mature as a platform for hybrid operations, with cloud data centers achieving new efficiencies through containers

Read more at: http://www.informationweek.in/informationweek/news-analysis/299061/cloud-trends-2015?utm_source=referrence_article

PHP vs. Node.js: An Epic Battle for Developer Mind share

PHP vs. Node.js: An Epic Battle for Developer Mind share


Here's how the old guard and upstart darling of the server-side Web stack up against each other

PHP vs. Node.js: An Epic Battle for Developer Mind share
It's a classic Hollywood plot: the battle between two old friends who went separate ways. Often the friction begins when one pal sparks an interest in what had always been the other pal's unspoken domain. In the programming language version of this movie, it's the introduction of Node.js that turns the buddy flick into a grudge match: PHP and JavaScript, two partners who once ruled the Internet together but now duke it out for the mind share of developers.
In the old days, the partnership was simple. JavaScript handled little details on the browser, while PHP managed all the server-side tasks that existed between port 80 and MySQL. It was a happy union that continues to support many of the crucial parts of the Internet. Between WordPress, Drupal, and Facebook, people can hardly go a minute on the Web without running into PHP.
But then some clever kid discovered he could get JavaScript running on the server. Suddenly, there was no need to use PHP to build the next generation of server stacks. One language was all it took to build Node.js and the frameworks running on the client. "JavaScript everywhere" became the mantra for some.
Of course, the ending isn't written yet. For every coder crowing about the purity of Node.js and the simplicity of JavaScript everywhere, there's another who's happy with the deep code base and long-understood stability of PHP. Will the old codger beat back the server-side upstart? Will JavaScript topple its old friend to achieve world domination? Put another batch of popcorn in the microwave and sit back.

Where PHP wins: Mixing code with content
You're typing along, pouring thoughts into text for your website, and you want to add a branch to the process, a little if-then statement to make it look pretty, say, depending on some parameter in the URL. Or maybe you want to mix in text or data from a database. With PHP, you open up the magic PHP tags and start writing code within seconds. No need for templates -- everything is a template! No need for extra files or elaborate architectures, just programmable logistical power at your fingertips.

Where Node wins: Separating concerns
Mixing code with content is a crutch that can end up crippling you. Sure, it's fun to mix code in with HTML the first two or three times you do it. But soon your code base becomes a tangled mess of logic. Real programmers add structure and separate the cosmetic layer from the logical layer. It's cleaner for new programmers to understand and easier to maintain. The frameworks running on Node.js are built by programmers who know that life is better when the model, view, and controller are separate.

Where PHP wins: Deep code base
The Web is filled with PHP code. The most popular platforms for building websites (WordPress, Drupal, Joomla) are written in PHP. Not only are the platforms open source, but so are most of their plug-ins. There's PHP code everywhere, and it's waiting for you to download it, modify it, and use it for your needs.

Where Node wins: Newer code means more modern features
Sure, there are thousands of great open source PHP files, but some are 8-year-old WordPress plug-ins hoping and praying that someone will download them. Who wants to spend hours, days, or weeks monkeying with code that hasn't been updated in years? Node.js plug-ins are not only newer; they were built with full knowledge of the latest architectural approaches. They were built by programmers who understand that modern Web apps should push most of the intelligence to the client.

Where PHP wins: Simplicity (sort of)
There's not much to PHP: a few variables and basic functions for juggling strings and numbers. It's a thin layer that doesn't do much except move the data from port 80 to the database and back. That's what it's supposed to do. A modern database is a magical tool, and it makes sense to leave the heavy lifting to it. PHP is the right amount of complexity for a job that's not supposed to be complex.

Where Node wins: Complexity of closures and more
JavaScript may have many little idiosyncrasies that drive some mad, but for the most part it is a modern language that sports a modern syntax and a few useful features like closures. You can reconfigure and extend it easily, making powerful libraries like jQuery possible. You can pass functions around like objects. Why limit yourself?

Where PHP wins: No client app needed
All of the talk about using the same language in the browser and on the server is nice, but what if you don't need to use any language on the browser? What if you ship the data in HTML form? The browser pops it up, and there are no headaches or glitches caused by misfiring JavaScript threads that try to create a page on the browser from two dozen Web service calls. Pure HTML works more often than anything else, and PHP is optimized to create that. Why bother with JavaScript on the browser? Build up everything on the server and avoid overloading that little browser on the little phone.

Where Node wins: Service calls are thinner than HTML-fat PHP calls
While AJAX-crazy HTML5 Web apps can have too many moving parts, they are cool -- and very efficient. Once the JavaScript code is in the browser cache, the only thing that moves along the wires is the new data. There's not a ton of HTML markup, and there are no repeated trips to download the entire page. Only the data has changed. If you're willing to put in the time to create a slick browser-side Web app, there's a big payoff. Node.js is optimized to deliver the data and only the data through Web services. If your app is complex and data-rich, it's a good foundation for efficient delivery.

Where PHP wins: SQL
PHP was built to co-exist with MySQL and its many variants, like MariaDB. If MySQL isn't exactly right, there are other great SQL databases from Oracle and Microsoft. Your code can switch with a few changes to your queries. The vast SQL world doesn't end at its borders. Some of the most stable, well-developed code will interface with an SQL database, meaning all that power can also be easily integrated into a PHP project. It may not be one perfect, happy family, but it's a big one.

Where Node.js wins: JSON
If you must have access to SQL, Node.js has libraries to do that. But Node.js also speaks JSON, the lingua franca for interacting with many of the latest NoSQL databases. That's not to say you can't get JSON libraries for your PHP stack, but there's something fluid about the simplicity of working with JSON when using JavaScript. It's one syntax from browser to Web server to database. The colons and the curly brackets work the same way everywhere. That alone will save you from hours of frustration.

Where PHP wins: Speed of coding
For most developers, writing PHP for Web apps feels faster: no compilers, no deployment, no JAR files or preprocessors -- just your favorite editor and some PHP files in a directory. Your mileage will vary, but when it comes to banging a project together quickly, PHP is a good tool to use.

Where Node.js wins: Raw speed
Writing JavaScript code is a bit harder when you're counting curly brackets and parentheses, but when it's done, your Node.js code can fly. The callback mechanism is brilliant because it saves you from juggling the threads. The core is well-built and designed to do all that for you. Isn't that what everyone wants?

Saturday, 17 January 2015

6 IT Workforce Predictions for 2015

6 IT Workforce Predictions for 2015

Every new year brings a unique set of challenges and opportunities for IT workers as existing technologies evolve and new technologies emerge. The first half of 2015 looks promising based on these six predictions from career experts.

Year 2015 promises to be a banner year for IT workers as the unemployment rate continues to plummet, salaries increase and organizations double down on retention and engagement strategies. CIO.com asked experts to predict the biggest trends, technology and strategies that will make an impact on hiring and recruiting in 2015.

 2015 it recruiting hiring trends

Prediction 1: Expect Hiring Explosion in Q1 and Q2

The forecast for the first half of 2015 looks bright for IT workers. Eighty-seven percent of 2,400 CIOs surveyed by Robert Half Technology say they will add more staff, whether to fill vacant roles or new positions.
With that expected hiring boom, its likely salaries will increase for existing workers, or they'll receive a bevy of new benefits, according to Jason Berkowitz, vice president of client services, Seven Step RPO."We are seeing a noticeable increase in IT hiring and we expect this to continue. Because of increasing competition, we also are seeing pressure to raise salaries and other benefits," says Berkowitz. "In some cases, competition is so tough that companies are looking outside of their geographic areas and considering relocating candidates from areas where talent is more available."

Prediction 2: Companies Will Leverage Mobile and Social Networks to Recruit Passive Talent
"Social recruiting is yesterday's news -- all serious recruiters are already deeply networked through social channels. If Facebook unveils rumored job search function -- the so-called 'Linked-in killer' -- this could change, but for now even new anonymous job search tools aren't likely to change the landscape in favor of one network or another," says Berkowitz. The new paradigm for 2015 is using social networks and mobile tech to increase connections with passive candidates, which will also serve to drive up salaries.
"Good candidates already get multiple outreach requests per week through LinkedIn, so finding candidates isn't the issue. It's convincing them to make a move. Candidates are understandably taking advantage of this candidate's market by making increasing demands and driving up salaries across the board," Berkowitz says. 

Prediction 3: Increased Focus on Employee Engagement and Retention
The upward pressure on salaries and benefits will make it necessary for companies to employ better engagement and retention strategies, at least if they want to hold onto elite talent already in their ranks. "[Rising salaries and benefits] will likely lead to a lot of 'job hopping,' and, as we've seen before, to avoid this, companies are going to start emphasizing retention as well as placing a premium on potential employees who display loyalty and longevity," says.
"Smart employers are definitely increasing their investment in keeping the people they have -- not just through bonuses and perks, but by really focusing on keeping their people engaged. We've seen everything from corporate-sponsored hackathons and other team-building activities to group volunteering activities -- anything to provide more collaboration and meaning to peoples' jobs. Smart employers understand that there is always a higher paying job out there, but people will stick around for jobs that have true meaning for them," says Emily He, CMO at Saba Software.

Prediction 4: Emphasis on Education and Training
Education and training will be a major focus for 2015, says Cristin Sturchio, global head of talent at Cognolink -- especially for millennials. "When you invest in training your people, you're providing them with skills and tools they can not only use today, but also continue to draw upon throughout their career," says Sturchio.
Top of Form
Bottom of Form
Top of Form
Bottom of Form
"We're also confident this approach significantly enhances their loyalty to our company. For example, initiatives like Corporate Universities, which are multi-year programs built with learning and development in mind, aren't just for large, Fortune 500 companies. When it comes to developing your people, size doesn't matter; the results do. Employees are engaged as teachers and facilitators, and they are invested in teaching others," says Sturchio.
For the newer generation entering the workforce, engagement isn't just about having a ping-pong table in your office or hosting happy hours after work. "It's about knowing that as the company grows, so will they. It's about creating an environment that encourages active participation and engagement. [It] makes them feel like a valued part of the company from day 1. It's about providing rewarding opportunities like being selected to serve as campus ambassadors to represent the company at their alma maters and teaching training courses that give back to the employee community," says Sturchio.

Prediction 5: Employees Shift Focus from Full-time Work to Contracting/Freelancing
"During the last hot employment market, we saw an increase in IT contracting and we expect that trend to return," says Seven Step RPO's Berkowitz.
"A strong IT professional can do very well contracting -- making a higher hourly rate than they would make as a full-time employee -- and they can move from project to project every few months and take time off in between. It's a very attractive model for some employees. Employers would be smart to consider laying in some contract staff in addition to their full-time employees, especially for very hard-to-find or niche requirements," says Berkowitz.
"The global economy in general is moving to a contract or freelance workforce. It's now a $1 billion worldwide market, and projected to be $5 billion in the next five years," says Xenios Thrasyvoulou, founder and CEO of PeoplePerHour and SuperTasker.
"The flexibility benefits for both employees and employers are hard to beat; the ability to find exactly the talent you need for exactly the job you need them for is one of the drivers, as well as the desire for specialization without having to pay a premium long-term for a full-time employee," says Thrasyvoulou.

Prediction 6: HR Department Turn to Big Data
Big data will play a big role in the employment landscape in 2015, says Saba Software's He, as HR departments try to leverage data and translate it in ways that are meaningful to employees.
"We call it 'Intelligent Talent Management,' taking advantage of all that data around employee behavior, productivity, skills, system usage and workflow to grow workers skillsets and continue engagement and productivity. Using Big Data from employees can be helpful in determining who they should be connecting with on their career path, what skills and education might be valuable to them, what information they need and how better to improve their performance," says He.
"Looking ahead to 2015, we will see the emergence of the Chief Data Officer. This person will advance from the organization's Data Scientist role, and will possess strong left-brain and right-brain competencies. They will excel in the areas of math and science, but will also be extremely curious, collaborative, and communicative, and will work hand-in-hand with other key business leaders such as the Chief Digital Officer and the CIO," says Piyush Pant, vice president of strategic markets, MetricStream.

Thursday, 15 January 2015

Google’s Project Ara update: New partners, inductive data transfer, and cutting-edge battery tech

Google’s Project Ara update: New partners, inductive data transfer, and cutting-edge battery tech



AraComponents


Ever since Google’s Project Ara debuted, consumers have been interested in the possibility of a customized smartphone with hot-swappable modules and varying functionality that can be changed on the fly depending on the user’s needs. Today, Google gave a major update on where the program is and where it’s headed through 2015.
Right now, Google is focused on building what it calls the Spiral 2 device, a new version of the hardware that will include multiple modules, greater flexibility, the option to swap out the battery while the device is in low power mode, and the opportunity to use multiple antennas for better signal sourcing and multiple carrier support. Spiral 2 also shifts from FPGA’s (Field Programmable Gate Arrays) to ASICs — specialized application-specific integrated circuits with superior performance and generally lower power consumption compared to FPGAs.

Project-Ara
Spiral 2 still has some problems with signal degradation over the long term and an issue with the framework used to attach the various modules. Google is reportedly working on induction signaling, with a 150-micron gap between components that will prevent the wear and tear that comes with repetitive switching back and forth. These improvements will come with Spiral 3, which adds additional RF field improvements as well (as shown below).

Project Ara Spiral 3

Project Ara’s roadmap

Google also laid out the Project Ara longer-term roadmap through 2015, including plans for an eventual market test in Puerto Rico by the end of the year.

Project Ara roadmap

Spiral 3 will add the Rockchip reference design, an LTE 4G modem, an Android release, packaging and decorating improvements, and an updated framework for software development that’s meant to make it easier for both software and hardware developers to build their projects. Google also talked up the concept of giving new and unusual battery designs a forum to experiment with Project Ara — there are battery technologies that offer substantial improvements over conventional lithium polymer architectures, but either cost too much for typical inclusion into smartphones or have other, specialized requirements. Some of these could be met within the Project Ara modular concept, and Google wants to see the platform used for prototyping and market testing.

Longer term, the goal is to create an initial pool of some 20-30 modules, including some of the options shown above. Google didn’t go into detail on what a “pollution sensor” might be, but it’s possible to include a carbon monoxide, carbon dioxide, and other types of smoke detector modules in a smartphone platform. A Project Ara device could conceivably include multiple modules to scan for various types of atmospheric contaminants, along with an LTE modem to report their prevalence at specific locations.

Google has stressed the goal of creating an entire ecosystem around this concept rather than simply throwing it to the consumer-wolves, which implies that the device could at least find targeted applications in specific markets or spaces where its customizability are a selling point. It’s not clear if the wider consumer space will take to the device (this will likely be cost-dependent) but the modular nature could prove popular with enthusiasts and hobbyists who want the ability to customize a phone for particularly long battery life or with specialized sensors. The ability to use multiple antennas could also prove useful for globetrotters, if the phone can be equipped with a sufficiently flexible LTE radio to allow for a truly global device.

If the Puerto Rico tests go well, Google intends to move forwards with market availability in the 2016 timeframe.

Google throws nearly a billion Android users under the bus, refuses to patch OS vulnerability

Google throws nearly a billion Android users under the bus, refuses to patch OS vulnerability



Android mascot broken
Google Android Logo







When it comes to providing security updates for previous products, various manufacturers have pursued different strategies. Some, like Microsoft, tend to provide security updates long after they’ve stopped selling an operating system (Microsoft only stopped providing Windows XP support last year). Others, like Google and Apple, have pursued tighter timelines for security updates. Google is now doubling down on that schedule, refusing to patch bugs in Android 4.3 or prior, even when those bugs could expose critical vulnerabilities on nearly a billion devices.

The flaws in this case affect Android 4.1 to 4.3, aka Jelly Bean, which began shipping in mid-2012 and was the primary version of Android through late 2013, or roughly 14 months ago. Up until quite recently, Google has aggressively patched problems in Android’s WebView rendering engine. Before KitKat (Android 4.4), all versions of Android used the version of WebView found within the Android Browser for rendering HTML webpages. With KitKat and Lollipop, Google updated the operating system to use a WebView plugin derived from its Chromium project.

When Security firm Rapid7 discovered a new exploit in the Android Browser version of WebView, it contacted Google to inform the company that Android 4.3 and below were vulnerable. Google’s response and policy change are raising major eyebrows. Specifically, the company states that:

If the affected version [of WebView] is before 4.4, we generally do not develop the patches ourselves, but welcome patches with the report for consideration. Other than notifying OEMs, we will not be able to take action on any report that is affecting versions before 4.4 that are not accompanied with a patch.

KitKat-Webview

This isn’t a minor issue. 60% of Android users are on pre-KitKit versions. No one uses Lollipop yet.
In other words, security staff are now expected to submit a patch to fix an issue when they report it. If they do, Google will “consider” the patch to see if it resolves the problem. If they don’t, Google now says the only thing it can do is inform various OEMs of the problem.

What Google is doing, in essence, is telling its user community “Sorry, you have to tell Samsung, LG, and Motorola to provide you with an updated version of our operating system.” This is hilariously impossible. It would never fly in the PC world — imagine Microsoft telling customers “Sorry, you have to make HP, Dell, and Lenovo provide you with a free update for our operating system.” The disparity is even larger if you consider that, in most cases, a computer running a previous version of Windows can be upgraded by the end user to run the next version. That upgrade may be a headache, but system requirements on Windows haven’t budged in nine years.

The average phone or tablet buyer has no way to upgrade their operating system unless the carrier provides an OTA update, and two-year upgrade cycles means that plenty of people are going to be stuck on broken devices with known exploits that Google isn’t going to fix. Granted, the fact that Google fixes an exploit doesn’t mean that carriers will deploy it, and fragmentation has been a major problem in Android’s ecosystem over the years — but there’s a difference between acknowledging the difficulty of maintaining security updates for the entirety of one’s user base and flatly refusing to do them.

Pushing OEMs off open-source Android

One obvious reason for Google to stop fixing Android Browser problems is that the company is aggressively moving to get OEMs to stop using Android’s open-source features and to replace them with features licensed directly from Google. Ars Technica has done an extensive write-up on this trend here, and getting rid of the Android Browser is a key facet of moving away from an Android that’s actually maintained and useful.
No, Google isn’t killing Android — it’s just ensuring that the only parts of the program that get feature updates, capability improvements, and performance enhancements are the parts that require licensing agreements and promises not to develop competing products. The reason Amazon’s Kindle Fire has its own app store, and Samsung’s continued interest in Tizen are both the result of Google’s push to embed itself into the center of mobile business while paying lip service to the idea of open source.

By throwing all of the responsibility for security updates back on carriers and security researchers, Google is telling OEMs that they can either agree to its licensing terms and fall in line, or take on the responsibility of performing security updates that they’re typically not qualified or funded to do. It’s a trick worthy of Microsoft in the Bad Old Days, and it’s particularly funny to see the company doing this, given that it threw Microsoft under the bus in December when it published the full details of a security flaw two days before Redmond patched it, on the grounds that the desktop and laptop OS company wasn’t moving fast enough.

Saturday, 10 January 2015

Windows 10: 12 things you need to know



Windows 10: 12 things you need to know

Microsoft gave the first look at its Windows 10 operating system on Tuesday, a major release that will span all hardware from PCs to phones and try to address the ills that have dogged Windows 8.

The event in San Francisco was aimed mostly at enterprise customers, and Microsoft promised an OS that will be more intuitive for the millions of workers still on Windows 7 and older OSes. Here’s a rundown of some of the key points we learned Tuesday about Windows 10.

Why Windows 10?

The natural name would have been Windows 9, but Microsoft is eager to suggest a break with the past. “We’re not building an incremental product,” said Terry Myerson, head of Microsoft’s Operating Systems Group.
Microsoft considered the name “Windows One,” he said, to match products like OneNote and OneDrive and its “One Microsoft” business strategy. But he noted the name was snagged a long time ago, by a young Bill Gates.
Perhaps Microsoft didn’t like the idea of being numerically one step behind Apple’s OS X. (A reporter asked jokingly if subsequent versions will be named after big cats.)
Whatever the reason, Windows 10 it will be.
“When you see the product in its fullness, I think you’ll agree it’s an appropriate name for the breadth of the product family that’s coming,” Myerson said.

What car does it resemble?

Yup, Microsoft came up with a car analogy. It wants you to think of Windows 10 as a Tesla.
“Yesterday, they were driving a first-gen Prius, and when they got Windows 10 they didn’t have to learn to drive something new, but it was as if we got them a Tesla,” Myerson said.

What devices will it run on?

All of them. Microsoft demonstrated only the desktop version Tuesday, but Windows 10 will be for tablets, smartphones and embedded products, too.
windows10 windows product family 9 30 eventIMAGE: MICROSOFT
“It will run on the broadest types of devices ever, from the smallest ‘Internet of things’ device to enterprise data centers worldwide,” Myerson said. “Some of these devices have 4-inch screens, and some will have 80-inch screens. And some don’t have any screen at all.”

Is there a start menu?

There is, and it tries to combine the familiarity of Windows 7 with the modern interface of Windows 8. That means the menu is split: On the left, apps are displayed in the familiar Windows 7 style, while on the right are more colorful “live tiles” that open the modern, Windows 8-style apps. The start menu is customizable, so you can resize the tiles and move them around, and make the start menu tall and thin or long and flat.
windows10 start menu on screenJAMES NICCOLAI

Will I still toggle between two distinct app environments?

Apparently not. In Windows 8, when you launch a modern-style app, it takes you into that modern UI, and when you launch a Win32-style app, it launches to the traditional desktop environment.
In Windows 10, “we don’t want that duality,” said Joe Belfiore, a corporate vice president with the OS group. “We want users on PCs with mice and keyboards to have their familiar desktop UI—a task bar and a start menu. And regardless of how an app was written or distributed to your machine, it works the way you expect.”

So how does it look now?

If you launched one of the new-style apps in Windows 8, it filled the whole screen and there weren’t many options to resize it. With Windows 10, the familiar “windows” metaphor is back; you’ll be able to resize the new-style apps and drag them around the screen like an old Win32 app. Conversely, if you’re using an older Win32-style app, it will be able to “snap into place” and fill all the available screen space just like the modern apps.

What else is new?

Some users have been confused by the Windows 8 interface and can’t figure out what’s open on their screen or how to get back to an app. Windows 10 has a feature like OS X’s Mission Control that lets you zoom out and see everything that’s open on a PC, then select any app to enter it.
windows10 win tabSIMON BISSON
You can also have multiple desktop configurations open and switch between them. So if you have two apps on the screen for a particular task, sized just how you want them, and then you change to some other apps, you’ll be able to get back to those first apps easily without having to resize them again. You can navigate through several of these desktop displays at the bottom of the screen.

What’s in it for business customers?

Today’s event was focused primarily on business users; Microsoft will talk about the consumer aspects of Windows 10 early next year. There weren’t a lot of specifics but here are a few points:
— Microsoft promises that Windows 10 will be more intuitive than Windows 8. “Windows 10 will be familiar to end users whether they’re coming from Windows 7 or Windows 8. The workers will be immediately productive,” Belfiore said.
— It will be compatible with “all traditional management systems in use today.” Customers are increasingly using “mobile device management” tools to manage phones and tablets. “Windows phones and tablets support MDM today, but with Windows 10, customers will be able to use MDM to manage all their Windows devices” including PCs, laptops and even Internet of things devices.
— Developers will get “one application platform,” Belfiore promised. “Whether it’s building a game or a line-of-business application, there will be one way to write a universal application that targets the entire product family,” he said.

Will it still be touch-enabled?

Yes. “We’re not giving up on touch,” Belfiore said. That means you’ll still be able to use touch to do things like scroll and pinch-to-zoom on laptops and desktops.
There’s also a new feature, tentatively called “continuum,” for people using two-in-one PCs. When you detach the keyboard from a Windows 10 hybrid, it will ask if you want to go into tablet mode. If you say yes, the UI changes to better match a tablet. The app expands to full screen, for instance, and the start menu switches into a larger-icon mode.

Is there a Command Prompt?

You’re kidding, right? Well, actually there is. Microsoft showed how it now supports shortcuts like CTRL+C and CTRL+V so you can paste in a directory listing from another app, for instance. Belfiore called it a “niche, geeky feature” but said he wanted to show the diverse range of users the OS is trying to support.

When will it be released?

The OS will launch around the middle of next year, after Microsoft’s Build conference. Before that, a select group of “Windows insiders” will receive a “technical preview build” for laptops and desktops on Wednesday this week, followed “soon after” by a preview for servers. Previews of other device categories will follow later.

Excel Formula's (Regular & Job-Oriented)

 Excel Formula's  1) SUM Task: Sum of numbers Formula: =SUM(A1:A10) Example: Sum of all numbers in A1–A10 2) AVERAGE Task: Average Formu...