Showing posts with label Technology. Show all posts
Showing posts with label Technology. Show all posts

Monday, May 3, 2010

Buying A Used Computer? Then Learn to Evaluate it

Used computers are available plenty in number. But, the prime concern is that how it will satisfy the needs of the purchaser. The next one is about the functionality of the used computer and the longevity of the computer parts of the used computer. Many people decide to purchase used computers due to a tight budget, but they should not end up buying a showpiece rather than a working piece. This makes it very important to evaluate the used computer before buying it. Evaluation can be done by the purchaser himself provided he has some knowledge on computers and their parts. If not, he can get some help from their friends or relatives who are good in evaluating computers.

The used computer’s physical parts should be inspected thoroughly. First step is to look for any damages and then trying to turn on and off. It should be done by the buyer or by his friend rather than watching the computer sales person do it as it will alert for any glitches. Checking needs to be done to find out if the used computer has an original version of the operating software without which the computer is not worth buying. Manuals, licenses for software applications, discs and fonts should be got along with the computer.




The operating system of the used computer should be compatible enough to run the required applications of the buyer. Some times the seller may sell a used computer along with used disk drives, scanners and printers and include the cost of them too. It is not wise to buy used scanner, printers or disk drives as they have peripherals with moving parts which wear and tear with the passage of time and also the cost of them can be deducted making the price of the used computer even lesser.

The speed of the central processing unit needs to be checked. If it is not up to the expectation of the buyer, it needs to be found out if the used computer system can be upgraded for improving the speed and functionality. The entire hardware components should be checked including the keyboard, speakers, monitor, mouse and microphones. It should be if all the hardware components inside the computer like the CD-ROM drive, sound card, number of RAM sockets etc are if present or not and if present what are the components in use. Also it needs to be checked whether it has a provision for adding different type of cards etc.

If the purchaser has already got some computer components like the monitor, printer and so on, the used computer which is bought should be compatible with them. Nowadays used Pentium machines and power PCs are available at very low price. It is not advised to buy a used computer which is very old. Also it is good to find out if the used computer comes with a transferable warranty or service, if so it is worth buying.

The buyer should not end up overpaying as used computers depreciate at a lightning speed. There are many online auctions, which can give the idea of how much people are ready to pay for a used computer. Unfortunately, there is no reputed or unbiased source for knowing the prices for used computers.

Continue reading this article...

Feel free to share it!

Technorati Digg it Add to Del.icio.us Stumble It! Add to Google Bookmarks Twitthis Reddit Blinklist Furl Live Yahoo

Friday, January 29, 2010

Power Saver: How it works?

Can you really save 40% on your electricity bills by plugging a small box into your AC socket?

In the past six month a number of products have been advertised on TV and online which seem too good to be true. I’d like to explain the reality of these exciting claims and give you a layman’s understanding of how Power Savers work.

A Power Saver is a device which you plug in to your power socket. Apparently just by keeping the device connected it will immediately reduce your power consumption. Typical claims are savings between 25% and 40%.

The technology behind Power Saver units comes from German research coupled with Asian manufacturing and it is based on sound scientific principles.

Electricity is not stable. When electricity flows the voltage can rise and fall all the time. The rises in voltage are known as ‘spikes’ and they cannot be used by your appliances at all. All these spikes do is waste your electricity. These power spikes also convert electrical energy into heat energy which leaks power from your circuit. Not only that but the heat will also do long-term danage to your wiring and to your appliances.

There are a few Power Saver models on the market but they all work along the same principle. They store the electricity inside of it using a system of capacitors and they release it in a smoother way to normal without the spikes. The systems also automatically remove carbon from the circuit which also encourages a smoother electrical flow. This means that you will have less power spikes. More of the electricity flowing around your circuit can be used to power your appliances than before.

There are many factors which do affect the efficiency of your Power Saver. The device works immediately after plugging it in although it can take as long as 8 days before it has adjusted itself for peak performance. The rate of savings will depend on what kind of appliances you have connected. All appliances are different but expect savings of up to 25% on lights, 30% on air-conditioning units and up to 35% on other appliances.

The highest savings will be in areas where voltage supply is less stable. Locations close to shops, restaurants and light industries tend to gain additional savings from Power Saver devices.

So how can you be sure that your Power Saver is working correctly?

Most often Power Savers come fitted with a light to indicate that it is working. If you have access to an electricity meter then you should see it immediately slowing down. Assuming that the light is on and that you leave the device unattended you can expect savings immediately. Be aware that often electricity companies will not take meter readings each month. Often bills are calculated on monthly averages which self-correct over time so please be aware of that in using your bill as a guide.

Finally, it is highly recommended to order your Power Savers from companies offering 100% guarantees for longer than 30 days. Remember that 30 days may not be sufficient time to truly know if the device is working as effectively as you expect. Try to work with companies that extend their guarantee dates to at least 60 day which gives you a much longer period to assess the benefits.

Continue reading this article...

Feel free to share it!

Technorati Digg it Add to Del.icio.us Stumble It! Add to Google Bookmarks Twitthis Reddit Blinklist Furl Live Yahoo

Sunday, November 8, 2009

Useful Tips for Buying Used Computers

In this modern era, high tech devices that are very expensive like the computers can be replaced with cheaper ones. Such cheap computers mostly come in the form of used computers. Used computers can be found in abundance in the used computer warehouses in various places, even in the local area of the prospective buyer’s residence. However there is no guarantee of quality when buying a used computer.

The buyer has to take his own personal risk in doing so. But, if the buyer is ready to spend some money in upgrading the level of the used computer and also some time checking the quality of the used computer before purchase, it will save him from loss. Used computers can save a lot of money for the buyer when compared to buying a new computer. There are many who cannot afford to buy a new computer like the students who do not have any source of income but definitely require computers. For such people, used computers come as a boon.

Also, used computers need not always be second hand computers. They can also be recertified or refurbished computers. Refurbished or recertified computers are those, which are checked for any faults, if any corrected and sold with a warranty ensuring the working condition of the computer to be perfect. Hence, such computers are considered to be the safest form of buying a used computer. Refurbished computers can be bought from many of the online stores at very less prices. Quality computer manufacturers also sell such kind of recertified or refurbished computers. However, certain measures need to be taken while buying such kind of computers.

The prime aspect to be considered while purchasing a used or refurbished computer is to look for a good branded one. There are various companies who sell used computers or refurbished computers. The main reasons for opting for a branded one is that it comes with a warranty and also the buyer can be sure that the parts used are of good quality.

While buying used or refurbished computers related software documents, licenses and paperwork have to be got from the seller as this will avoid stolen computers being passed off as used computers to the buyer. If possible working for some time on the used computer will determine its efficiency. Most of the reputed dealers would allow the purchaser to use the computer for a shorter period to check the quality before purchase.

While checking for the efficiency of the used computer, it is good to check if the booting process is smooth, as most of the problems occur during booting and also to check all the sound drivers, video, graphics, monitor, mouse, keyboard etc. CD drives and hard disks also need to be checked. Another aspect is the support system offered for the used computer whether technical or non-technical, support staff capabilities and the number of support staff which determine the quality of service offered. If the purchaser is not satisfied, he can very well think of another choice.


Continue reading this article...

Feel free to share it!

Technorati Digg it Add to Del.icio.us Stumble It! Add to Google Bookmarks Twitthis Reddit Blinklist Furl Live Yahoo

Sunday, August 23, 2009

Jobs Hunting Through Social Networking Sites?

WASHINGTON (AFP) - – Nearly half of US employers research the online profiles of job candidates on social networks such as Facebook, MySpace or LinkedIn, according to a new survey.

Forty-five percent of the employers surveyed for CareerBuilder.com, the largest US online job site, said they use social networking sites to check on job candidates, up from just 22 percent in a survey conducted last year.

Another 11 percent said they plan to start using social networking sites for screening.

"As social networking grows increasingly pervasive, more employers are utilizing these sites to screen potential employees," CareerBuilder said in a statement.

It said job seekers should "be mindful of the information they post online."

CareerBuilder said that of those who conduct online searches as background checks on job candidates, 29 percent use Facebook, 26 percent use LinkedIn and 21 percent use MySpace.

Eleven percent search blogs while seven percent follow candidates on micro-blogging service Twitter.

Thirty-five percent of those surveyed said they have found content on a social network that caused them not to hire a candidate, CareerBuilder said.

Examples included "provocative or inappropriate photographs or information" or content about drinking or using drugs.

Other reasons cited were badmouthing a previous employer, co-workers or clients, poor communication skills, making discriminatory comments, lying about qualifications or sharing confidential information from a previous employer.

Information found on social networking profiles was not always a negative factor in finding a job.

Eighteen percent of employers said they have found content on social networking sites that caused them to hire the candidate, CareerBuilder said.

Some profiles "provided a good feel for the candidates personality" or supported their professional qualifications while others demonstrated creativity or solid communication skills.

Rosemary Haefner, vice president of human resources at CareerBuilder, recommended that candidates "clean up digital dirt" before beginning a job search by removing photos, content and links which could hurt their chances.

The survey of 2,667 hiring managers and human resource professionals was conducted by Harris Interactive between May 22 and June 10. It has a sampling error of plus or minus 1.9 percentage points.

Source: Yahoo News!


Continue reading this article...

Feel free to share it!

Technorati Digg it Add to Del.icio.us Stumble It! Add to Google Bookmarks Twitthis Reddit Blinklist Furl Live Yahoo

Sunday, August 9, 2009

Free e-books offerings

NEW YORK - James Patterson's latest best seller, "The Angel Experiment," is a little different from his usual hits. The novel isn't new; it came out four years ago. Readers aren't picking it up at bookstores, but mostly on the Kindle site at Amazon.com.

And the price is low even for an old release: $0.00.

"I like the notion of introducing people to one book, while promoting the sales of another," says the prolific and mega-selling author (and co-author) of numerous thrillers." His Kindle download is the first book of Patterson's "Maximum Ride" young adult series.

"We've given away thousands of free e-copies," Patterson said. "`Maximum Ride' is big already and we think it could be a lot bigger. That requires getting people to read it."

Patterson is among the biggest brands added to the growing list of free e-book offerings. Over the past few months, top sellers on the Kindle — with downloads in the tens of thousands, authors and publishers say — have included such public domain titles as "Pride and Prejudice" and "The Adventures of Sherlock Holmes," and novels by Jennifer Stevenson and Greg Keyes.

In recent days, the top three Kindle sellers have been free books: Patterson's, Joseph Finder's "Paranoia" and Keyes' "The Briar King."

"There's always going to be someone who wants free things. What we're trying to do is link free with paid," Maja Thomas, senior vice president of digital media at Patterson's publisher, the Hachette Book Group, said. "It's like priming the pump."

"What we like to do is make the first book in a series free, usually a series that has multiple books," said Scott Shannon, publisher of the Del Rey/Spectra imprint at Random House, Inc., which published Keyes' fantasy novel.

Shannon said Del Rey has had especially good luck with Naomi Novik's "Temeraire" fantasy series after offering the first book for free. He said sales for the other Temeraire novels increased by more than 1,000 percent. "It's been stunning," he said.

Publishers and authors have been nervous that the standard cost for electronic editions of new releases, just under $10, will take away sales from the more expensive hardcovers and set an unrealistically low price for the future. They are concerned, but open-minded, about free books, which present a chance and a challenge: Readers may buy other books, or, they may simply seek more free titles.

"It's a huge hot-button topic we've been discussing within our division and at the corporate level," Shannon said. "We have had phenomenal success with using free books to get people to buy others by an author. But in the long term, we have to guard the market. We have to make sure people understand that time and energy goes into writing a book."

"Consumers love free — free is a good price. But the opportunity they present to publishers is to experiment, and I stress experiment," Ellie Hirschhorn, Simon & Schuster's chief digital officer, said.

The dominant e-book seller Amazon.com has been aggressive about keeping prices low, and has given free e-books high visibility by including them on the Kindle best-seller list. A leading rival, Sony, does not include free works among its best sellers, although some free books have popular downloads.

"We do withhold them from the best-seller list, so that it's an accurate reflection of what people are actually buying," says Sony eBook store director Chris Smythe.

In an e-mail statement about free ebooks, Amazon.com spokeswoman Cinthia Portugal, said, "We work hard to provide customers with the best value possible and pass savings on to them whenever possible." Portugal added that Amazon includes free books among its top sellers because the list is "based on customer orders — customers are still ordering these books, they just have a price tag of $0.00."

David Bailey, 56, a systems analyst in Tacoma, Wash., is the kind of customer publishers and authors want to get. He has downloaded free texts by Kelly Link, Scott Sigler and others, but has then purchased other books by those authors, sometimes "just to support them."

One of Bailey's free downloads was Finder's "Paranoia," a thriller first published in 2004. Finder, whose "Vanished" comes out Aug. 18, said he initially saw the free offering as a "no lose" deal since "Paranoia" wasn't selling many copies anyway and sales for his other books, including "Power Play" and "Killer Instinct," have gone up. But, noticing all the free best sellers on the Kindle, he wondered if readers will get used to not paying.

"I get a lot of e-mails from people, saying, `I hadn't even heard of you until I read your free book.' So no question, it does bring in free riders," Finder said. "But I'm also increasingly concerned. There are so many free e-books that basically you could stuff your Kindle or Sony Reader with free books and never have to buy anything."


Continue reading this article...

Feel free to share it!

Technorati Digg it Add to Del.icio.us Stumble It! Add to Google Bookmarks Twitthis Reddit Blinklist Furl Live Yahoo

Saturday, July 4, 2009

Porn Continues to Plague iPhone Apps Store

Just one week after pulling an X-rated iPhone app offering photos of nude women, Apple has yet again found itself fighting off attempts to upload mobile porn.

An image of a teen girl, purported to be 15 years old who is topless and mostly bottomless appeared in the free app BeautyMeter, which lets users upload photos of themselves that are then rated by others, according to Wired magazine. The app is like an iPhone version of the rating site Hot or Not.

As of Wednesday afternoon, Wired said the app (including the same teen image) was still available in Apple's App store. But on Thursday, it appeared that Apple had removed it.

Funnymals, BeautyMeter's developer, and Apple did not immediately respond to requests for comment from ABCNews.com.

But in a note dated July 2 on Funnymals' Web site, the developer said that because of " inappropriate content upload we hardened our review process so the release time can be higher since now. As described in our terms and conditions, NO nude content is allowed (bikini content is allowed)."

Another note on the site says, "We don't review each uploaded photo exclusively but from time to time we will clean up."


Last week, after photos of nude women started appearing in the app Hottest Girls, the blogosphere lit up in disbelief.

The application previously displayed photos of women in lingerie and bikinis. But about a week after Apple unveiled a new operating system that includes parental controls that could filter out explicit content, the developers took off what was left of the clothes on the women, and turned up the heat on their product's content.

Read the rest of the story about Apple Porn Apps

Continue reading this article...

Feel free to share it!

Technorati Digg it Add to Del.icio.us Stumble It! Add to Google Bookmarks Twitthis Reddit Blinklist Furl Live Yahoo

Thursday, May 21, 2009

Aliens and UFO, are they really existing?

Many of us does not believe on these fictional endoparasitoid extraterrestrial species that is the primary antagonist of the Alien film series. Its existence remains hypothetical, because there is no credible evidence of extraterrestrial life which has been generally accepted by the mainstream scientific community. And yet, need to be proven by bare naked eye.

On the other hand, there's what we called UFO (unidentified flying object). UFO is the popular term for any aerial phenomenon whose cause cannot be easily or immediately determined which is more or like similar to Aliens. Both military and civilian research show that a significant majority of UFO sightings are identified after further investigation, either explicitly or indirectly through the presence of clear and simple explanatory factors, or the Occam's Razor.

The video compilation includes many of NASA UFO encounters/sightings that have been archived by Luna Cognita Productions over the years. All of these examples (with the exception of the second-to-last one) were captured on film by NASA astronauts or Russian Cosmonauts over the past half-century - showing many amazing examples from different eras - Gemini, Apollo, Apollo/Soyuz Test Project, Skylab, STS, the ISS, plus a couple Russian-source additions from their unmanned Zond and Mir Space Station programs as well thrown in to round things out.




Dr. Michio Kaku, a theoretical physicist specializing in string field theory, and a futurist, will help us to open our minds to our so called, science fictions.



Dr. Kaku appeared in the short documentary Obsessed & Scientific. The film is about the possibility of time travel and the people who dream about it. It has appeared at the Montreal World Film Festival and is in developmental talks about becoming a feature. He also appeared in the ABC documentary "UFOs: Seeing Is Believing," where he suggested that while he believes it is extremely unlikely that extraterrestrials have ever actually visited Earth, we must keep our minds open to the possible existence of civilizations a million years ahead of us in technology, where entirely new avenues of physics open up. He also discussed the future of interstellar exploration and alien life in the Discovery Channel special Alien Planet as one of the multiple speakers who co-hosted the show, and Einstein's Theory of Relativity on The History Channel.


Continue reading this article...

Feel free to share it!

Technorati Digg it Add to Del.icio.us Stumble It! Add to Google Bookmarks Twitthis Reddit Blinklist Furl Live Yahoo

Friday, May 8, 2009

Online Bash Shell For Beginners



If you want to learn Linux bash shell commands in a fun way this is the place for you.

This website provides Unix-like virtual online bash shell command line interface where you can try out bash commands easily online in a web browser without the fear of installing Linux.

Once you gets your hands over bash shell commands you can easily move on to Linux because the knowledge of bash shell commands are essential for operating any Linux distro to its full potential.

Online Bash Shell

Continue reading this article...

Feel free to share it!

Technorati Digg it Add to Del.icio.us Stumble It! Add to Google Bookmarks Twitthis Reddit Blinklist Furl Live Yahoo

Friday, March 27, 2009

CDR-King 12” Tablet Review by Nurses & Geeks

For some of you who doesn’t know about tablet, it is an input device used by artists which allows one to draw a picture onto a computer screen without having to utilize a mouse or keyboard.

A tablet consists of a flat tablet and some sort of drawing device, usually either a pen or stylus. It may also be referred to as a drawing tablet or drawing pad. While the graphics tablet is most suited for artists and those who want the natural feel of a pen-like object to manipulate the cursor on their screen, non-artists may find them useful as well.

The smooth flow of a graphics tablet can be refreshing for those who find the mouse to be a jerky input device, and repetitive stress injuries such as carpal tunnel syndrome are less likely when using a graphics tablet.

Wacom Bamboo on Dell Latitude D830

It’s a Wacom Bamboo on a Dell Latitude D830 from Ken Schaefer’s Wacom Review. The tablet is quite small (about 19cm on each edge), thin (<1cm) and weighs about 300 grams. It has four buttons at the top (illuminated in blue) which can be programmed, as well as a little touchpad which allows scrolling up/down in windows using a motion similar to the click wheel in an iPod. Price is over $100 or over 4000Php (Philippine Peso). On the other hand, if you’re looking for a starter, low price, and fully featured alternative tablet, I recommend, CDR-King 12.1″ Slim Tablet.




CDR-King 12


Read the rest of the Nurses & Geeks' CDR-King 12” Tablet Review

Continue reading this article...

Feel free to share it!

Technorati Digg it Add to Del.icio.us Stumble It! Add to Google Bookmarks Twitthis Reddit Blinklist Furl Live Yahoo

Wednesday, March 25, 2009

Assessing Internet Security Risk, Part One: What is Risk Assessment?

The Internet, like the Wild West of old, is an uncharted new world, full of fresh and exciting opportunities. However, like the Wild West, the Internet is also fraught with new threats and obstacles; dangers the average businessman and home user hasn't even begun to understand. But I don’t have to tell you this. You’ve heard that exact speech at just about every single security conference or seminar you’ve ever attended, usually accompanied by a veritable array of slides and graphs demonstrating exactly how serious the threat is and how many millions of dollars your company stands to loose. The “death toll” statistic are then almost always followed by a sales pitch for some or other product that’s supposed to make it all go away. Yeah right.

Am I saying the threat isn’t real? Am I saying the statistics aren’t true? No. What I’m saying is that many users fail to see what relevance any of this has to themselves and their company. Should the fact that e-Bay supposedly spent $120,000 dollars recovering from Mafia Boy's DDoS attack really have an impact on the reader's corporate IT policy? Perhaps not.

And yet, users can't afford to ignore these facts completely. That would be just plain dumb. What they need to do is to recognize that there are new threats and challenges and, like the other threats and challenges that businesses have always known, these need to be met and managed. No need to panic. No need to spend any money. Yet.

What users really need to do is to understand what the specific risks are that their company or home network faces from being connected to the Internet. In the same way that you don't borrow your business strategy from e-Bay, you probably shouldn't borrow your IT security strategy from them either. You need to develop an IT security strategy to meet your unique needs. You understand your company's own unique risk profile.

As with so many other things in life, the key to effective information security is to work smarter, not harder. And in this case, working smarter means investing your valuable time, money and human resources on addressing the specific problems that are the most likely to cause the most damage. The math is really quite simple. But before you can do the sums, you have to identify the variables. Here are some of the questions you'll have to ask yourself:

  • What are the resources - Information & Information Systems - I'm actually interested in protecting?
  • What is the value of those resources, monetary or otherwise?
  • What are the all the possible threats that that those resources face?
  • What is the likelihood of those threats being realized?
  • What would be the impact of those threats on my business or personal life, if they were realized?>

Having answered the five questions above, you can then investigate mechanisms (both technical and procedural) that might address those risks, and then weigh up the cost of each possible solution against the potential impact of the threat. Once again, the math is simple: if the cost of the solution is higher then the potential financial impact of the risk (or risks) being addressed, then one may need to investigate other solutions, consider accepting and living with a part of the risk, or accepting and living with the risk completely.

This article is the first of a series that is designed to help readers to answer questions three and four in the context of Internet-connected systems: What are the threats that my Internet-connected systems face and what are the chances of those threats being realized. Over the next few weeks we will explore the thinking around Internet Security Assessments, not only why they are done, but also how they are done. By the end of this series you should understand how performing an Internet security assessment can contribute to an effective information security strategy, what you should expect from such an assessment and even how you could go about performing such an assessment yourself.

The Reasoning Behind Security Assessments

Background

An Internet Security Assessment is about understanding the risks that your company faces from being connected to the Internet. As already discussed, we go through this exercise in order to effectively decide how to spend time, money and human resources on information security. In this way our security expenditure can be requirement driven, not technology driven. In other words, we implement controls because we know that they’re needed, not just because the technology is available. Some firms refer to security assessments as ethical hacking or penetration testing. Although I also use these terms, I see them as referring to something completely different than risk assessment and thus do not see their use as appropriate in this context.

Security Assessments vs Risk Analysis

Later in this article, I'll show you a diagram of what is know as the "security life cycle", a depiction of the concept that security is a continual cycle with a number of distinct phases being repeated on an ongoing basis. You'll notice that this cycle distinguishes between a risk analysis and a security assessment. You may even have come across both terms before and wondered at the distinction. It's not my intention to argue semantics here. Indeed, I'm not even convinced that there is universal consensus on the precise definition of each term. Here's how I see it, briefly: A risk analysis is typically performed early in the security cycle. It's a business-oriented process that views risk and threats from a financial perspective and helps you to determine the best security strategy. Security assessments are performed periodically throughout the cycle. They view risk from a technical perspective and help to measure the efficacy of your security strategy. The primary focus of this paper is on this kind of assessment.

Internal vs External Assessments

I have further limited this paper to a discussion of Internet Security Assessments. Let me point out right from the start that this is only a part of the picture. An Internet security assessment can consist of one or both of two things: an internal assessment and an external assessment. The company for which I work distinguishes between the two in the following way:

"An external assessment is also known as perimeter testing and can be loosely defined as testing that is launched from outside the perimeter of the private network. This kind of testing emulates the threat from hackers and other external parties and is often concerned with breaching firewalls and other forms of perimeter security.

On the other hand, in internal testing the analyst is located somewhere within the perimeter of the private network and emulates the threat experienced from internal staff, consultants, disgruntled employees, or, in the event of unauthorized physical access or a compromise of the perimeter security. These internal threats comprise more then 60% of the total threat portfolio."

Although an Internet assessment is attractive because it is finite and answers a direct question, the following should be noted at the outset:

  1. An Internet assessment will not identify all the risks to your information resources. Areas that are clearly not addressed include the following:
  2. Threats from within the trusted environment;
  3. Threats from RAS and other external connections; and,
  4. Threats from your extranet and connections to 3rd parties.
  5. There are other ways of assessing risk, without doing a technical assessment.

Although it's beyond the scope of this discussion, the scope of an Internet Assessment can easily be expanded to include areas like RAS and the Extranet (which is why we actually refer to the service as an external assessment). However, even with the limited scope, there are a number of strong reasons for performing an Internet Security Assessment.

But first, let's remind ourselves why we want to do an assessment in the first place.

Reasons for performing a Technical Security Assessment

I've often thought, at the end of a security assessment project, that I probably could have advised the customer without having to perform the entire analysis. Internet installations are generally fairly similar and one sees the same mistakes being made at different installations all over the world. And yet I haven't quite given up on the idea. There are a number or reasons for my continued faith in technical assessments.

Firstly, a technical assessment allows me to fully familiarize myself with the customer's architecture. By the time the assessment is finished, I usually understand the client's Internet architecture at least as well they do, often even better. This puts me in a unique position to offer then real and useful advice and ongoing technical support.

The technical familiarity I've acquired also very often buys me the respect of the customer's technical personnel. That, in turn, puts me in an even better position to advise them. Because our clients themselves are often non-technical people, such as risk managers and financial managers, it is essential that we also win the trust and respect of the technical team. Penetration testing, a later phase in the assessment methodology during which we actually attempt to breach security and compromise the customer's systems, is particularly effective in this regard. It's hard for someone to argue that their security is sufficient when you've already clearly demonstrated that it can be compromised. The fact that our findings are based on a formal assessment methodology lends weight to the recommendations we make.

Sometimes an organization needs an objective assessment from an independent third party is necessary to convince others that they are taking security seriously. This is becoming more of an issue in certain sectors, where government, shareholders and other regulatory authorities are expecting companies to provide proof of proper information security.

Moreover, the fact is that a properly executed assessment may very well identify problems that otherwise may have gone unnoticed. A single small finger-fault in your firewall configuration may be all that's needed by an attacker and a thorough technical assessment may be the only way of determining this.

But most importantly, an assessment introduces objectivity. With the overwhelming number of security products and vendors in the market, it's important that security-conscious organizations and individuals spend money for the right reasons. A good assessment should help you to understand and prioritize your security requirements, allowing you to invest resources effectively. Very often, the most serious requirements will not be addressed by the simple acquisition of more technology, and it's important for the customer to understand that.

Actually, this last point is nothing new and security assessments have been seen as an important phase in the security lifecycle for as long as there has been information security theory. One version of the lifecycle looks like this:

The Security Lifecycle


The Security Lifecycle

Notice how the assessment phases (threat/risk analysis and security assessment) are the first and last step in the process. The analysis is used to identify what needs to be done, and the assessment is used to measure how effective the other phases in the cycle have been. A number of companies are even starting to use the outcome of these repeated assessments to measure the performance of their technical personnel. Some companies even use security assessments as a key performance area for regular personnel. Now there's an interesting idea.

Reasons for performing an Internet Security Assessment

Hopefully I've convinced you now of the value of a technical security assessment. But I've also said that this paper is limited to a discussion of Internet security assessments only. Does it make sense to focus on one area of your system like that? Actually, no. But Rome wasn't built in a day, and a complete assessment of a large environment will typically need to be broken up into a number of distinct and manageable phases. The Internet is only one of a number of different areas we could examine. However, Internet-connected systems are the single area we assess more than any other. And, given limited time and resources, it is sometimes the only area we consider for clients. Here is a summary of the reasons that companies still perform Internet security assessments:

  1. Internet systems are an obvious part of the problem: Given the almost overwhelming size of the complete information security problem, it's often hard to know where to start. Internet systems are very often a clearly defined subset of the complete infrastructure and can be easily isolated, analyzed and secured. Although we realize that this only a small part piece in a much larger puzzle, it very certainly is a piece. If we can confirm that the Internet systems are secure many managers feel "Whew, at least that's out of my hair."

  2. The Internet is a unique network: The tools and methodologies that we apply in analyzing Internet security are different from those we use when looking at "internal" spaces like WANs, LANs and Extranets. For this reason we tend to see an Internet assessment as a separate body of work from the rest of the assessment and tackle it separately.

  3. Internet systems are an obvious target: Attack via the Internet is by no means the only threat your company faces, but it is a clear and obvious threat and one would be foolish to ignore it. And, just as you want to be sure you've locked your front door, you want to be sure you've secured your connections to the Internet. The threat of attack via the Internet is easily identified, tested and eliminated. We test our Internet security because then we can know that it has been done and move on.

  4. Internet systems are a high-profile target: It smarts to be hacked from the Internet. Even though the financial impact of such an attack is often smaller then other forms of attack, a defaced Web site and other forms of Internet attack can often do huge damage to your company's reputation. For this reason we want to know that our Internet security has been taken care of.

  5. Internet systems are often beyond our control: The Internet began its life a utopian exercise in community collaboration. Although this early utopianism has long since evaporated and the Internet has now developed in a battlefield for new-world commerce, there are still a rather scary number of uncontrolled inter-dependencies that make it possible for your company to operate on the Internet. The magical routing of IP packets from one network to the next is one example of this. The mapping of machine names to IP addresses via the Domain Name System is another. Yet we have no real control over these systems. They are critical to the safe operation of our Internet infrastructure and yet their security is beyond our control. Similarly, we have no control over when new vulnerabilities will be discovered in our Internet technologies. Quite simply, the only defense we have is to regularly assess this infrastructure for safe and secure operation. This is probably more true for the Internet then for other areas of your infrastructure.


Conclusion

In this section I've tried to convince you of the value of doing a technical risk assessment and to explain why we often consider the Internet systems separately from the rest of the infrastructure. In the next installment in this series, I'll give you an overview of the steps that we follow in performing this kind of assessment. The methodology is designed to ensure that our work is complete and consistent.


By: Charl van der Walt on Security Focus


Continue reading this article...

Feel free to share it!

Technorati Digg it Add to Del.icio.us Stumble It! Add to Google Bookmarks Twitthis Reddit Blinklist Furl Live Yahoo

Thursday, March 19, 2009

AMD lawyer: Intel would 'like us dead'

In the wake of the latest kerfuffle between Advanced Micro Devices and Intel, AMD's chief counsel seized the moment to sound off on a primal fear at his company: Intel is bent on its destruction. Intel, of course, doesn't quite see it that way.

After Intel accused AMD on Monday of breaching a 2001 patent cross-license agreement with Intel, AMD's top lawyer had some choice words for its bigger rival.

In a phone interview Tuesday, AMD general counsel Harry Wolin refuted Intel's claim that the AMD manufacturing spin-off Globalfoundries is not a subsidiary--and thus cannot legally use Intel intellectual property--and talked more broadly about Intel's tactics.

Intel's ultimate goal, Wolin believes, is to crush rivals into oblivion. "In their perfect world, we wouldn't exist. If they had to deal with the government every now and then, that's fine, and they're still extracting monopoly profits from the industry," he said.

Wolin doesn't buy into the oft-repeated theory that Intel needs AMD to keep the industry honest and to keep the U.S. government at bay. "I don't agree with the premise that they have to have us and they think they have to have us. I think they would absolutely like us dead," Wolin said.

The Dickensian depiction of AMD as the impoverished, distressed victim of Intel's bullying and manipulation is inaccurate and, more importantly, misses the relevant point, according to Intel spokesman Chuck Mulloy. "It's nice of them to try to speak for us. AMD has been a competitor for almost 40 years in one form or another. This is not about AMD going away," he said. "This is about our rights and AMD's rights under the patent cross-license agreement."

Ashok Kumar, an analyst at investment bank Collins Stewart, said the premise of a remorselessly predatory Intel set on killing off its rivals is attention-getting but not that realistic.

"Could Intel put them out of business? Probably. But is it a likely outcome? I don't think so," he said. "Because they'll get a lot of significant push back from the OEMs (PC makers). The OEMs will essentially be making a beeline to Washington, D.C."

Intel contends this is a very localized dispute about whether Globalfoundries is a subsidiary or not, and not a manufactured issue "to distract the world from the global antitrust scrutiny (Intel) faces," as AMD said in a statement Monday. "AMD cannot unilaterally extend Intel's licensing rights to a third party without Intel's consent," said Bruce Sewell, senior vice president and general counsel for Intel, in a statement on Monday. Intel maintains the issue is that Globalfoundries is 34.2 percent owned by AMD and 65.8 percent-plus owned by Advanced Technology Investment Co., an investment company. So, in effect, Globalfoundries is not an AMD subsidiary.

Wrong, AMD says. It is not about ownership. AMD has met the conditions that qualify it as a subsidiary. "It requires that AMD originally contributed at least 50 percent of the assets. If you look at the fact that we've thrown in the German factories, we've thrown in the people, we've thrown in the technology, we've thrown in the intellectual property. I don't think there's any credible argument that says we haven't thrown in more than 50 percent of this. It says nothing about owning. It says you have to originally contribute 50 percent of the assets," Wolin said.

And what happens from here?

"Let's say the parties end up in a lawsuit at the end of 60 days," Wolin said. (Intel says it will terminate AMD's rights and licenses under the cross license in 60 days if the alleged breach has not been corrected.) "Well, you know, that lawsuit doesn't come to court for years and wouldn't come to court until well after the antitrust suit would come to court, which is currently scheduled for February of next year," according to Wolin.

Intel says the next step is mediation, where Globalfoundries is brought to the table. If this doesn't resolve the issue, then they would both be off to the races and the lawsuits would begin.


Source: CNET News

Continue reading this article...

Feel free to share it!

Technorati Digg it Add to Del.icio.us Stumble It! Add to Google Bookmarks Twitthis Reddit Blinklist Furl Live Yahoo