Sunday, May 13, 2012

DNSChanger Virus & Trust on the Internet

I came across this forum in a CNET Newsletter which I subscribe to. The immediate issue on hand is the DNSChanger trojan. As discussed in this post, it is a nasty piece of malware that has infected not just PCs and Macs, but also routers and other network hardware. As mentioned on my post on the virus attacks on Macs, the culprits are not attention seeking hackers but an Estonian criminal gang that managed to steal $14 million from its victims. Although the FBI was able to catch the criminal gang and the rogue DNS server, they were unable to shut off the rogue servers immediately because this would result in the infected computers being suddenly cut off from the Internet. So instead the FBI "chose to keep the rogue DNS servers active and convert it to a legitimate DNS system for infected computers" and conduct an awareness campaign to alert users about this potential infection before shutting off the rogue DNS server. They plan to do this on July 9 2012.


For more information on how to address this issue, see:
The other aspect of this story relates to credibility on the Internet. "Barbara" submitted a classic "Dear Editor" letter to CNET which was the subject of the feed I received in my email. She did not know whether she should download the tools from DCWG.org and thought it could be a scam (see the first post at the top). Although she more than likely Googled (or Binged) the topic, she did not trust the results. Instead, she needed to turn to CNET as a "trusted intermediary" to verify that the tool the FBI was offering to clean the system was indeed legitimate. This illustrates a challenge for the new "here comes everybody" approach to the Internet enabled media: How do we verify claims on the Internet? Clay Shirky (who is the author of the book Here Come's Everybody) has analyzed how the Internet as a broadcast medium has made it possible to get one's news on events outside of the traditional mediums of print, television or radio, which were controlled by professional journalists. The implications of his analysis is that the previous monopoly that journalists had on broadcasting will be undermined by just regular people who can supplant such traditional media organizations through blogs, wikis and the like.  However, Barbara's concern about being duped by nefarious actors on the open Internet highlights how there continues to be a need for trusted institutions or individuals, such as CNET, to add credibility to news in order to effectively act on something such as the DNSChanger trojan.

This, however, does not mean that pre-existing business model of the media, which relied on its on monopoly on broadcast technology will continue to be viable. Changes will have to be made. For example, Encyclopedia Britannica was able to successfully shift from its previous model to of selling physical books to an online subscription model. In fact, 2012 will be the last year that they will be selling its iconic set of encyclopedias. More importantly, Encyclopedia's new approach is a good example of how people are willing to pay a premium for an "authenticated encyclopedia" instead of solely relying on the "free encyclopedia" Wikipedia. That being said, Encyclopedia Britannica's model may not work for traditional news outlet. As Jeff Jarvis,  professor in journalism at CUNY and author of "What would Google do?", points out on his post on the danger of pay walls, media organizations stand to lose audiences and therefore "Googlejuice" by adopting this approach. His post highlights the conundrum that media organizations find themselves in. Do they opt for the pay walls which are akin to the old way of doing things? Or do they embrace the "Googlejuice" and rely on online ads and greater user interaction? It will be interesting to see how this all gets sorted out.


Thursday, May 3, 2012

Mobile Access: Canada falling behind India and China

According to a survey from Randstad found that Canadian workers are less connected then counterparts in India and China. According to the article, 76% of Canadians were connected. Although this is the majority, it is materially lower than the level of "connectedness" with counterparts in India and China where 93% of workers were connected. The article lays blame on the exorbitant fees paid by Canadians for the Internet in contrast to other countries (e.g. see this post which compares to the US. Besides the stats, US providers give 2-year contracts instead of 3 year contracts) . One of the factors that contributed to the adoption of the internet was the availability of unlimited dial-up access: users did not have to worry about rates, so they were more willing to adopt the new technology (e.g. users had to pay $20/month for unlimited internet in 1997). So price does matter when increasing the adoption of technologies. With the growth of mobile commerce in places like the UK, Canada could fall behind not just in mobile commerce but the overall development of local apps and mobile services.  



Sunday, April 29, 2012

Cloud Computing and Unbilled Deferred Revenue: On the way to another bubble?

I was reading this report on the outlook cloud computing from GigaOm and came across an interesting accounting term:  "unbilled deferred revenue". When I googled the term, I came across the following explanation from Salesforce.com: "Unbilled deferred revenue, represent[s] business that is contracted but unbilled and off balance sheet". In other words, it is revenue that can't be recognized because it is not earned and it is off-balance sheet because it has been collected! Will such funky accounting terms be used to fuel a bubble vis-a-vis the cloud? It appears I am not the only one that saw the need to look into this a little deeper. This article actually analyzes the term and gives some rationalization to the concept: "[Subscription economy is] one way to make sense of cloud computing and the many new and very different ways of doing business on the Internet. We're most familiar with Software as a Service and how different it is from conventional licenses; so familiar, in fact, that I don't need to describe it for you here." 


One of the key factors in bubbles (based on a paper that Efrim and I wrote a few years ago) was "speculative valuation models".  So the next step is for some physicist to figure out how  "unbilled deferred revenue" can be put into a black-scholes type finance model -  and voila! -  we are are on our way to the next tech bubble. 


Of course there are other factors (see the paper for the list) that are necessary to inflate a bubble. The one to pay particular attention is to whether the credit is flowing freely. With the debts woes of Europe and people still stinging from the sub-prime crisis, this factor may inhibit the inflation of such a bubble. However, this assumes banks and traditional lenders will be the primary source of capital. The reality is that tech companies are awash in cash, and as evidenced by Facebook's acquisition of Instagram for a cool billion, they appear ready to step in and make the necessary deals to potentially fuel another tech bubble.  

Thursday, April 26, 2012

Google Drive: Cost, Security and Other Issues

Earlier this week, Google released its much anticipated release of Google Drive (even the official blog referred to it as the "Lochness monster"; due to the fact that Google was supposed to release this years ago). For those interested in how Google Drive stacks up against other cloud based storage services, see Dana Wollman's post on Engadget. Included in her post is a side-by-side comparison of Google's offering against  Dropbox, Microsoft SkyDrive and iCloud. In terms of security issues, this CIO article points out that it will be hard for system administrators to block Google Drive because it will be hard to distinguish from the other Google services (e.g. Gmail, youtube, etc), which many organizations allow users to access. 

As with any other cloud service, users need to be aware of the terms of service (ToS or "click wrap" agreement) which bind the users to all sorts of conditions (this ZDNet article gives a good analysis of how Google is imitating DropBox a little too much). This article claims that users concern that content shared would be owned by Google "are probably unfounded". Their evidence: Google's ToS are the same as Microsoft's ToS for their cloud drive offering. However, the following ZDNet article extracted the ownership clauses and it seems that Microsoft is much clearer in stating that the content belongs to the user and not Microsoft (but you can see it for yourself and decide). 


Although Google may capitulate to public pressure and alter the terms of service, the incident highlights one of the key trade offs with the cloud: convenience of the cloud comes at the cost of control. For example, most, if not all, cloud service providers (CSP) will hand over data to law enforcement - without the consent of the data owner. However, if the same law enforcement agencies wanted the data hosted at your business or house; they would have to obtain your consent first - because you are in control and not the CSP. 


Beyond the privacy issues, if CSPs are free to write their own terms of service customers, especially the small and medium sized businesses (SMBs), will be at the mercy of these large players who have an army of lawyers at their disposal to write the ToS in a way to protect the CSP - leaving the SMBs vulnerable. That's until there's some cataclysmic breakdown in the cloud forcing the regulators to act in a way to protect users from such agreements, similar to what we saw with SOX or even the birth of the SEC itself after the depression.

Sunday, April 22, 2012

Macs & Viruses: The End of Innocence


Macs & Viruses: The End of Innocence

With the Flashback botnet continuing to plague Mac users, it's good time to reflect on those Apple vs PC Ads. Oh you know the one where the slick Apple dude tells the PC guy that Mac's "don't get viruses".  And that probably was true when the ads ran in 2006: malicious code has been traditionally targeted towards Windows. For the cybercriminals behind these outbreaks it's just a game of numbers: more PCs users = more potential victims =more $$$. However, the picture has changed from 2006: Macs have risen from being 4% of the market to nearly 13% of the market in Q3 of 2011.  However, the numbers are just one part of the story. As illustrated Apple's smug ad, Apple users have been lulled into a false sense of security: "PCs not Macs" get viruses. This makes Mac users a juicy target for viruses, as they are likely not to have the proper security in place to prevent viruses.  Sorry Mac users, I know it's a sad day - but you have to defend yourself from viruses just like all the PC users out there. 

Monday, April 2, 2012

Security Rating in the Cloud

Security in the cloud is an issue of paramount importance to companies. Cloud computing is one of the biggest trends in eBusiness since the invention of the internet. But security has lagged behind the other aspects of cloud management.

In the attached (referenced) article published in ISACA Now, Antonio Ramos, CEO of Leet Security puts forward an argument for the implementation of security ratings for cloud service providers. Such ratings would be similar to credit ratings used in the financial world. He points out, correctly I think, that although credit ratings suffered credibility during the financial crisis, generally they have served the financial and investment world quite well. he argues that security ratings could serve a similar purpose for the cloud.

An idea worth thinking about. Check out his article here.

Wednesday, March 28, 2012

Black Holes a Major Security Concern

Scotiabank recently named black holes as its major security issue for 2011. They encountered a concerted effort by hackers to draw their people into them through setting a variety of traps (some 50 types of them they said). When users click on the URLs in the traps, they are drawn into a series of illicit domains that search their computers for vulnerabilities and then plant viruses that exploit these vulnerabilities. The viruses are shielded so that the anti-virus software can't recognize them. The most effective way to safeguard against these black hioles is to block the URLs that lead to them, but this is a big job and depends on having a knowledge of what those URLs are. Scotiabank managed some success in dealing with them, as explained in this article.