Win 7 business sales weak, but uptick expected

Microsoft Thursday said 60 million Windows 7 licenses have been sold in the past six months, but most of those have been from the consumer side and business uptake has been flat. The shrink-wrap sales represent the fact that users are able to update existing machines with the new operating system, which shipped in October 2009. Klein said there has been "way more business activity" around Windows 7 than in previous releases of Windows operating systems. The news came as Microsoft reported record quarterly revenue of $19.02 billion and $6.6 billion in profits for the second quarter of fiscal 2010. Seven tips to migrate and manage Windows 7 On the company's quarterly earnings call, Peter Klein, Microsoft's new CFO, says the company posted $500 million in revenue from retail sales of shrink-wrapped Windows 7 software, but Klein did not give specific numbers for business sales.

But he again did not provide any specifics. During the call, Microsoft admitted that it has not seen a return of enterprise spending growth. He did say that users are not waiting for service pack 1, which Microsoft so far has refused to discuss. But Klein says the expectation is that it will begin to pick up later this year and continue for the next two to three years. The EAs include Microsoft's Software Assurance maintenance program.

In addition, the company said enterprise agreement renewals are taking longer to complete, but Klein said when they do get done, users are not dropping products "and in most cases we are actually adding products on the EAs." Enterprise agreements provide Microsoft customers from corporations to governments with a comprehensive volume licensing program that covers all their Microsoft software. In addition, Microsoft said sales of SharePoint Server, Office Communications Server and Dynamics continue to see double-digit growth. Follow John on Twitter: twitter.com/johnfontana Microsoft also reported that it eliminated 800 jobs during the quarter and paid out $59 million in severance.

One by one, carriers succumb to Google Voice

Ever since its launch this summer, Google Voice has presented carriers with some potentially thorny issues. Google Voice was designed in part to make it easier for users to change mobile carriers without sacrificing their phone numbers and also to give users several add-on features that are not offered by carriers. The biggest potential pitfall for carriers is that widespread adoption of Google Voice could render their networks "dumb pipes" that don't offer users any value-added services. For example, Google Voice can provide simultaneous ringing for both landline and wireless devices using the same phone number and it can serve as a hub for SMS as it lets users send text messages from any of their devices or even right over the Web on their computer.

However, America's top two wireless telcos this week indicated that they had no problem supporting Google Voice on their networks. Net neutrality proponents such as the media advocacy group Free Press have met Google Voice with enthusiasm, as they think it could give users the ability to seamlessly switch carriers if their current carrier is too restrictive of what they can and cannot use on their mobile devices. During a joint press conference with Google on Tuesday, Verizon CEO Lowell McAdam said that all Verizon phones based on the open-source Android platform would give users access to the Google Voice application. How Google Voice could change the wireless industry Although AT&T didn't mention Google Voice specifically as an application that it would allow onto its network, it's very likely that Google Voice will soon be available to iPhone users since it doesn't present the direct threat to cellular service revenues that other VoIP applications and services do. AT&T, meanwhile, said Tuesday that it was changing its tune and allowing iPhone users to utilize VoIP applications such as Skype on the AT&T 3G network. The reason for this is that when you make a call using Google Voice, it initially goes through the standard public switch telephone network to the Google cloud, where it is then sent out as a VoIP call.

But even if Google Voice won't harm carriers' ability to charge users for cell phone minutes, Gartner analyst Peggy Schoener does think it could harm carriers' profitability if users come to rely upon it for services. "It is a threat to their business model to some degree," she says. "But right now the demand for openness is trumping that. So while Google Voice will enable users to save money on typically expensive long-distance calls, it won't be an alternative to using up minutes from your standard wireless carrier in the way that Skype is. Carriers are looking at how the world is shaping up and they have to demonstrate openness and cooperation with industry newcomers." FCC action in the background While neither Verizon nor AT&T will say it out loud, one factor in their decision to allow Google Voice onto their networks could be the more active approach that the Federal Communications Commission has taken this year under new chairman Julius Genachowski. More recently, Genachowski has also proposed new network neutrality rules that would bar carriers from blocking or degrading lawful Web traffic and that would force carriers to be more open about their traffic management practices. For example, this summer the FCC asked Google, Apple and AT&T to explain why the Google Voice application was not yet been made available for the iPhone.

ABI Research analyst Jeff Orr thinks that the government's more aggressive stance toward regulating the wireless industry has been a key factor in the telcos' decision to allow Google Voice on their networks despite whatever misgivings about the application they may have. "I think that they're looking at the talk going around at the FCC looking for net neutrality, and they figure that they'll need to back off and pick the battles they want to fight," he says. "By allowing Google Voice and other VoIP applications onto their networks they say to the FCC that they can monitor their own practices and that there's not a need for legislation mandating net neutrality." Schoener agrees that FCC action is part of the reason why carriers are showing more openness on their networks right now, but she also thinks that carriers are being forced by market trends to embrace more openness as well. For instance, the past decade has seen large Internet companies such as Google and Skype become major market players with the clout to push for net neutrality regulations. "There's not a direct cause and effect between the FCC's actions and the carriers' decisions," she says. "But the FCC's stance is a part of the current trend that openness is better, and the telcos figure they can be better off in the long run if they embrace it rather than playing hardball."

Taiwan lawmakers reject funds for memory chip makers

A committee of Taiwanese lawmakers rejected requests for funding by Taiwanese memory chip companies on Wednesday and asked the executive branch to stop promoting the DRAM revitalization plan. That committee reviews applications before they are passed to the legislative body for a vote. The economics committee of the Taiwan legislature rejected requests by Powerchip Semiconductor and the government-led Taiwan Memory Company (TMC), a legislative aide confirmed.

Lawmakers in the group believe the worst of the global economic crisis has passed and that DRAM makers should be able to fend for themselves considering the rebound in DRAM prices this year, the aide said. The legislature usually follows committee recommendations when voting. The executive branch can work with lawmakers on a more palatable plan, but convincing the economics committee is vital. The rejection throws a wrench into the government's plan to restructure Taiwan's DRAM industry. The plan was the result of a crisis among DRAM makers caused by excessive debt and an inability to raise new funds amid the global recession.

In March, Taiwan's Ministry of Economic Affairs unveiled a plan to build TMC as a means for industry consolidation and DRAM technology development. Taiwanese DRAM makers built too many new factories during good times, leading to a glut of DRAM chips and a collapse in global DRAM prices. The Taiwan government first stepped in to ask banks on the island to give companies more time to repay loans and extensions were granted until Dec. 31. A government report argued the amount of money DRAM makers on the island owed Taiwanese banks could cause problems if not repaid. Most Taiwanese DRAM makers have not posted a net profit since the middle of 2007 due to the chip downturn.

Gartner: Server virtualization now at 18% of server workload

How fast is the shift to server virtualization happening? There are about 5.8 million virtual machines (VM) believed to be in use today, said Gartner analyst Thomas Bittman, speaking on the topic Monday at Gartner's Symposium ITExpo 2009 attended by thousands of high-tech managers from around the world. According to Gartner, 18% of server workloads this year run on virtualized servers; that share will grow to 28% next year and reach almost half by 2012. Large enterprises have driven server virtualization over the last four years or so, and VMware holds an 89% market share against a handful of competitors that include Microsoft, Citrix, Red Hat and others.

But growth is anticipated among the small-to-midsize businesses (SMB), and it's in this segment that Microsoft has a good chance to build a customer base. By that time, Gartner believes, Microsoft will hold 27% share, Citrix 6%, Red Hat 2% and others about 1%. Small enterprises will be "looking at a much more level playing field," Bittman said. By 2012, VMware's share is expected to shrink to 65% but the base of VMs will have grown to 58 million, a 10-fold leap. He said each of the VM software providers have ways to distinguish themselves in both features and prices, but for many the big question will likely be, "Should I choose VMware or Microsoft?" VMware, which can boast higher density and a mix of operating systems support and maturity in features, costs more than other offerings, such as Microsoft's HyperV. As it begins to release improved VM software, Microsoft seems poised to achieve growth in the SMB market, Gartner believes. The choices for an in-house virtualization platform that enterprises make now and in the near future are likely to influence their cloud-computing choices, too, Bittman pointed out. Bittman said the migration from physical servers to virtualized ones is also tied to the revolution in cloud computing, where enterprises will be considering various strategies from private clouds to public cloud services and a hybrid model.

Virtualization is "not a commodity," Bittman noted. But he noted virtualization provides dynamic provisioning, potential for disaster-recovery support, as well server consolidation, and "it's becoming the default" for the enterprise over the next few years. There's no commonality in the switching or management at this point, and mixing and matching among VM vendors is not a likely choice at this point.

Net neutrality could lead to inexpensive, high-quality broadband services for businesses

Federal Communication Commission net neutrality rules have the potential to save businesses money in ways that range from heading off potential new Internet access charges to opening up low-cost, high-bandwidth services distinguished by superior quality of service. FAQ: What's the FCC vote on network neutrality all about? While the FCC won't make final decisions until next spring at the earliest, its rule-making agenda that was approved Friday  prompts speculation on what the outcome might yield, and that includes the possibility of high-quality access at a low price.

The agenda includes examination of managed or specialized services such as IP TV that run over the same networks as general broadband Internet services. This was formerly the practice with information services, but the FCC changed its mind several years ago. If the FCC decides to formally classify these specialized services as information services, existing communications law would allow for a rule requiring providers to wholesale the component parts of the service to competitors, says Tom Nolle, president and CEO of tech consultancy CIMI Corp. But language in the proposed rule suggests the commission might revisit the old regulation. "It could be the start of a regulatory reversal," Nolle says, which might work this way: If a service provider sold IP TV for $60 per month to customers - made up of the TV content and the high-speed delivery network - it would have to sell just the network portion of the service for less, Nolle says. Even paying the full consumer price for the service would be a good deal. "I could save a ton of money on this if I'm a business," Nolle says.

That would drastically undercut the price of traditional network services with good enough QoS to support high-definition video, he says. That is an unlikely scenario based on a reading of the FCC proceeding, says Colleen Boothby, a partner at Washington, D.C.,  telecom law firm Levine, Blaszak, Block & Boothby. Rather, it seems more likely the commission will prevent service providers from discriminating about what services and content they will carry over their networks and under what circumstances, she says. The FCC would have to reverse an earlier decision, which is possible, but doesn't seem to be the main thrust of the FCC rule making. By banning such discrimination, the FCC could prevent a host of unnamed new charges against businesses depending on the type of content they move over their Internet access lines, she says. "All enterprise customers are content providers," Boothby says, so they stand to face new fees if providers are allowed to charge more for certain types. So the customer's ISP would charge the bank's ISP for allowing the account data to reach the customer.

Hypothetically, a bank could be charged for supplying account balance data to its customers who happen to access the bank's online services from a different ISP than the bank uses. There is no such proposal, but without a regulation this type of fee would not be prohibited, Boothby says. "It doesn't exist yet, but the models are there," she says. They both need to recover the enormous amounts they've spent on network fiber upgrades. This could help explain AT&T's and Verizon's lobbying efforts to prevent the rule making. So far they charge for Internet access, TV and phone services over them, but they are involved in price wars on all three fronts with cable operators.

And that could influence the costs of supporting corporate work-at-home programs. "Do not continue to assume that your employees will always have cheap access to high-speed residential services," Lazar says in his blog. "Develop contingency plans that include purchasing of business class services, use of optimization, and/or desktop virtualization to guarantee application performance." So in order to preserve application performance, it may become necessary to buy service-level agreements from providers or alter corporate infrastructure to squeeze better performance out of lower quality broadband services, he says. This predicament the providers find themselves in could result in higher general Internet access fees or a fee structure where customers pay by the byte, according to Irwin Lazar, an analyst for Nemertes Research. Likely additions to corporate networks are WAN optimization gear that reduces the volume of Internet traffic as well as gear that boosts the performance of Web applications, he says.

No app store for make-or-break ZuneHD

Microsoft's ZuneHD, set to go on sale Tuesday, will not feature an open application store like its competitor the iPod Touch. Those capabilities will determine whether the ZuneHD sells well - and whether Microsoft decides to keep selling its own music player, said Matt Rosoff, an analyst at Directions on Microsoft. It will come with some unique features, though, like an HD radio tuner, and with software that has been well-received by users.

After observers noticed a Marketplace folder during earlier demos of the ZuneHD, many had hoped the new device would feature an open application store like the one accessible from the iPhone and the iPod Touch. But the Zune Marketplace will be a closed store, meaning third-party developers won't be able to easily build applications for it. Marketplace is the name of the open app store that will be available on Windows Mobile 6.5 phones, to be released in early October. The new device will include the same casual games that came with earlier Zunes, plus a few other applications like an MSN weather application and a calculator, said Brian Seitz, group marketing manager for Zune. Zune customers will be able to download the applications they like for free. In November, Twitter and Facebook applications will become available, as well as a "Project Gotham" racing game, he added.

Seitz said the timing wasn't right to include the Windows Mobile Marketplace application, which isn't due out until next month, with the ZuneHD, but he also said it's not certain that a similar open Marketplace will come to the Zune in the future. "Down the line, if there's an opportunity for us to snap into what they're doing from a mobile application perspective, I'm sure it's something we'll look at," he said. He acknowledged that people are likely to criticize the decision. "I'm not saying we won't get dinged for that because I know we will," he said. However, Microsoft may decide it makes more sense to limit the applications in the Zune market and offer them all free, he said. That's for good reason, Rosoff said. "When you look at it as a head-to-head comparison with the iPod Touch, people will see it as a shortcoming," he said. It will feature the "smart DJ," which allows the user to pick an artist and then automatically creates a playlist of similar songs.

Microsoft will also debut new Zune software on Tuesday that customers use on their PCs to manage their music. Microsoft will also start offering people who subscribe to Zune Pass a way to access the Zune music collection from a browser. A Zune Pass subscription lets users stream any song from the entire Zune catalog and download 10 songs each month. That means subscribers will be able to listen to music from the entire catalog from any PC, including one at work, rather than only from a PC running the Zune software. Microsoft also revealed a few more details about a Zune feature that will start showing up in Xbox Live later this year.

That's part of a strategy to move the Zune software experience into other products from Microsoft, Seitz said. "Going forward, we hope more people think of a 'holistic Zune business,' as opposed to how many of these things we sell," he said, pointing to the Zune hardware. Xbox users will be able to buy or rent movies from a new Zune store that will be featured in Xbox Live. The most important upcoming product that will include Zune software will be Windows Mobile phones, Rosoff said. "The Zune interface will show up in Windows Mobile," he said. Rosoff suspects that Microsoft will eventually get out of the MP3 player market altogether. "We'll just see the Zune as a consumer component of Windows Mobile," he said. "This is sort of the last [Zune], if it doesn't sell." Even Zune hardware elements, like the touch screen and the form factor of the device, will likely make it into Windows Mobile phones, he said.

Lotus user wary of social networking tool rollout

As IBM moves to upgrade its cache of social networking tools, some users are taking a cautious approach to the technology while figuring out where it will apply and how to measure its effectiveness. The new 2.5 version software includes micro-blogging, file sharing and new mobile capabilities. Where IT pros do their social networking IBM Tuesday unveiled Lotus Connections 2.5, its upgraded lineup of social networking tools that are a major expansion to the company's suite of collaboration software. But some of the features are expanding faster than users' plans to utilize the software.

The company's manager of messaging and collaboration asked for anonymity because he was not authorized to speak on the record. One Connections 2.5 beta tester, a global consumer product corporation, is taking a deliberately slow approach to rolling out the social collaboration tools. The company started slow with a few hundred users who were only allowed to communicate with each other. At that point, the manager says, the number of users exploded by 650% to a few thousand. The group's size was eventually doubled and then the tools were opened up companywide. Despite the growth, the company is still "seeding the environment," said the manager, but a broader rollout is planned.

We will likely "wind up doing it anecdotally," said the manager. "The things we're struggling with there is that this doesn't match the ROI [metrics that executives] are used to looking at. The harder part to plan is the expected results because the company has yet to figure out how to measure its return on investment. How do you measure, 'we recruited this person because of the [collaboration tool]?'" While results are hard to gauge, the broader, anticipated benefits are being defined in the context of capturing and recording corporate knowledge. The worker could develop a how-to guide for use by others, he said. For example, a certain administrative assistant may routinely be tasked with booking a certain type of event, said the manager. The manager said it is a good time to ramp up internal communities and knowledge-sharing because as the economy and job markets rebound, workers who may have suffered pay or benefit cuts amid the recession will be looking to move on. "Now is the time to get people to put information in, so you're not losing it on the back of a Post-it note." Follow John on Twitter. -Kanaracus is with the IDG News Service Follow Chris on Twitter.

Macs retake reliability ranking top spot

Apple reclaimed the top spot in the computer-reliability ranking of Rescuecom, a Syracuse, N.Y.-based technical support franchise, as netbook maker Asus' rating plummeted, Rescuecom's CEO said Saturday. But Apple recaptured the top ranking for the third quarter with a reliability score of 374. Behind Apple were Lenovo and Asus with 320 and 166, respectively, followed by Toshiba and Hewlett-Packard in fourth and fifth place. Apple's Macs, which led all rivals in Rescuecom's rankings during 2007 and 2008, ceded first place to PCs sold by Asustek Computer (better known as Asus) in the first half of 2009, falling as low as third in the first quarter, behind both Asus and Lenovo. Rescuecom produces its scores by comparing the percentage of support calls represented by each vendor with each computer maker's U.S. market share.

For example, although Apple's U.S. market share was 9% - according to research firm IDC, whose data Rescuecom used to calculate its ratings - Macs accounted for just 2.4% of the calls to Rescuecom. The greater the difference between the two, the higher the score. According to Rescuecom's reasoning, the higher scores indicate more reliable hardware and better support from the computer makers. But Asus' decline was the big story. Apple's third-quarter rating was actually 5% lower than the 394 Rescuecom gave the company's computers for 2009's second quarter.

The Asian computer maker, which led Rescuecom's rankings for the first six months of the year, has seen its reliability rating plunge from a first-quarter high of 972 to 166 in the third quarter. That, in turn, meant that Asus machines had been in users' hands for just several months, which could translate into fewer support calls. "It will be interesting to see in the coming quarters if Asus will start coming down to the level of the other vendors, or can sustain it," Kaplan said at the time. Asus' nose-dive was hardly a surprise, said David Milman, Rescuecom's CEO. "This is what we were waiting for on Asus, whether or not their reliability score would be maintained," said Milman in an e-mail. "Now that many of the netbooks by Asus have been out for a while, there is obviously a higher need for service." Last March, when Asus first jumped to the top spot on Rescuecom's list, company president Josh Kaplan said Asus' ranking should be taken with a grain of salt, since it was based on a huge bump in sales during the last few months of 2008, when Asus' netbook sales took off. Apparently, it couldn't sustain its record rating, which in the first quarter Rescuecom measured as 972, nearly six times higher than its score in the third quarter. Toshiba's reliability score was 165 in the third quarter, down 24%, while HP's third-quarter score of 134 was off 6% from the previous quarter. Asus' second-quarter rating was 416. Toshiba's and HP's scores also fell from the second quarter, although less dramatically than Asus.

DOJ requires AT&T to sell some assets in acquisition

The U.S. Department of Justice will require telecom giant AT&T to sell off pieces of its mobile network in parts of Louisiana and Mississippi in order to continue with its US$944 million acquisition of Centennial Communications, the agency said Tuesday. The area covered includes parts of southwestern and central Louisiana and southwestern Mississippi. If AT&T did not divest its assets in the two states, the acquisition would "substantially lessen" competition for mobile telecom services and would likely result in higher prices, lower quality and reduced network investments, the DOJ said.

The DOJ's Antitrust Division, along with the attorney general of Louisiana, filed a civil lawsuit Tuesday in U.S. District Court for the District of Columbia to block the proposed acquisition of Centennial by AT&T. At the same time, the DOJ and the Louisiana attorney general filed a proposed settlement that, if approved by the court, would resolve the competitive concerns in the lawsuit. The complaint alleges that the proposed transaction would substantially reduce competition for mobile wireless telecommunications services in each of the areas. According to the complaint, AT&T and Centennial are each other's closest competitors for a significant number of customers in eight cellular marketing areas (CMAs), as defined by the U.S. Federal Communications Commission. AT&T is the second-largest mobile telecom provider in the U.S. by number of subscribers, serving nearly 80 million subscribers throughout all 50 states, the DOJ said. Centennial is the eighth-largest mobile telecom provider in the U.S., with about 1.1 million subscribers in six states, Puerto Rico and the U.S. Virgin Islands.

In 2008, AT&T earned mobile revenues of about $44 billion.

CA looks to ease encryption key management

CA today unveiled key-management software that helps automate the storage and distribution of encryption keys for multi-vendor tape encryption purposes. According to CA's director of storage product marketing Stefan Kochishan, CA intends to add support for other vendor tape-encryption methods in the future. "This product will manage the keys," Kochishan says. "If there's a call for centralization of management of either public or private keys, that can be done. Cool new products of the week CA Encryption Key Manager is z/OS-based software (it also runs on Linux, Unix, Windows and Solaris platforms) that can support the IBM TS1120 and TS 1130 tape encryption devices as well as the CA Tape Encryption subsystems from the same interface.

You can also set up key stores in various sites and those sites will be updated when there's a change. CA Encryption Manager allows tracking and monitoring of encryption keys and digital certificates as well as deletion once a key is no longer used, Kochishan notes. It's full life cycle key management." CA Encryption Key Manager will also interface with security systems that include IBM RACF, CA ACF2 for z/OS, and CA Top Secret for z/OS for public/private key and digital certificate storage. Changes are propagated via SSL-encrypted TCP/IP. The goal is to let IT managers more easily share encryption keys across business units or with outside business partners. Mark Depathy, senior infrastructure engineer there, indicated it has simplified key distribution for business-to-business tapes and other uses. "It's something that gives you real-time key distribution," Depathy says, adding it allows for a common database related to keys. Peoples United Bank in Bridgeport, Conn., has been beta-testing the CA Encryption Key Manager for the past month.

CA Encryption Key Manager, available now, starts at $16,000.

Windows 7 May Spur Virtual Desktops, On and Off the iPhone

Predictions from analysts and virtualization vendors that desktop virtualization will take off during 2010 may be off the mark. VMware, Citrix and a range of other companies are putting clients on smart phones, minimalist thin-client hardware and USB keys in an effort to find something about Virtual Desktop Infrastructures (VDI) that will hook a customer's imagination, says Andi Mann, head of systems and storage-management research at Enterprise Management Associates. "VMware and Citrix both announced support for the iPhone, which is sexier, even though Blackberries have a greater penetration in business," Mann says. "Virtualization on handhelds is a kind of halo project -like the Chevy Corvette that dazzles customers who come in and end up buying a Chevette." The Chevette, in this case, is the aging desktop PC or laptop used by any one of millions of corporate workers stuck with Windows XP and looking to upgrade to Windows 7 when it comes out later this year, says Chris Wolf, virtualization and infrastructure specialist at The Burton Group. "Windows 7 is going to drive a lot of the activity around desktop virtualization for companies that want or need to upgrade to Windows 7," Wolf says. Sales may take off, but the desktop PC may not have much to do with it.

Bulk migrations will take a long time, but many companies will at least begin moving users to the new OS within weeks or months, Wolf says, and will try to avoid spending the money it would take to upgrade every PC while they do it. [ For timely virtualization news and expert advice on strategy, see CIO.com's Virtualization Drilldown section. ] "Strategically, both Citrix and VMware have been planning that Windows 7 would be a major catalyst for desktop virtualization, and have been working toward it for a long time," Wolf says. Citrix Systems demonstrated its iPhone client in May. "Right now, it's a race to produce client-side hypervisors," according to Wes Wasson, chief marketing officer of Citrix Systems. "With that, [enterprise applications] are just a URL to the user. VMware announced more than a year ago that its VMware Infrastructure (VI) Client would run on the iPhone. You could be using a home-office PC or a Mac or a smartphone; as long as the client is there, you have secure access." Racing to an Anywhere Virtual Client Other software and hardware developers are also racing to build add-ons to make virtualization usable, and devices to make it easy to acquire. AppSense, whose code is part of both VMware and Citrix's VDI offerings, stores all that data and code on the server and reloads it all every time that user logs on, no matter through what device the access comes, according to Martin Ingraham, VP of strategy for the company. "We have to make it transparent across all the delivery technologies, so a user can set preferences on one, and go home and sign on using a different one, and have it exactly as they left it," he says.

The User Environment Manager from AppSense, for example, is designed to make a virtual desktop mimic the real thing by allowing end users to make changes, install software add photos, store cookies and do all the other things they'd do on an actual "personal" computer. Competitor Moka Five's desktop suite offers similar functionality adding the ability to personalize PCs and Macs without disturbing the "golden" PC image on which the company relies. It's just a hub to connect a keyboard, mouse, monitor and other peripherals to a Windows desktop image running in the data center. Thin-client manufacturer Pano Logic sells what it calls a "zero client" that has no CPU no operating system, drivers or moving parts. A starter kit of five, plus one remote USB key that can turn any computer into an authenticated thin client, starts at $1,989. LG Electronics is trying to streamline the hardware by building a thin client from NComputing a Pano Logic competitor directly into its SmartVine line of LCD monitors.

NComputing sells a range of mini- to micro thin computers. The 19-inch version retails for $199, can save 70 percent on maintenance, 60 percent on hardware and 90 percent on electricity compared to a PC, the company says. Big VDI Question: Management Tools "The hardware can really be anything, which is the great thing," according to Steve Bonney, vice president of business development at Bayscribe, a software developer that builds high-volume, server-based dictation systems for medical facilities. But questions about how to manage those assets, protect intellectual property, and even measure the amount of risk involved are holding many companies back. "The fundamental problem is not getting access to the application from a phone," Mann says. "We can do that with a Web application. Bonney is hoping VMware will push its client out on all the major phone operating systems to save his company development costs and show that even heavy duty applications work on very thin clients if the client is ubiquitous enough. "This will completely reshape the way enterprise IT is done," Wasson says of Citrix' client-side hypervisor. "It shifts the information flow model back to pull-so you're not pushing things at users they don't want, and it simplifies things for IT." Even without the fancy hardware, VDI can save a ton of money for IT in support, capital costs and licensing, Mann says. It's all about the manageability, without that, there's no question it's cool, but no one is really sure if it's practical." Follow everything from CIO.com on Twitter @CIOonline.

Akamai pitches Hollywood on its HD Network

Akamai Tuesday began pitching its new HD Network as the perfect solution for entertainment companies that want to deliver high-definition video streams over the Internet. During a live videoconference Tuesday, Akamai executives pitched the network to entertainment companies as a compliment for live TV and DVDs that would let content providers stream higher quality videos without the traditional problems of jitter and long buffer times that users regularly encounter. The CDN provider's new HD Network utilizes its HD EdgePlatform and combines it with digital video recorder technology and an adaptive bitrate streaming technology that adjusts users' delivery bitrates based on their network capacity. Separated at Birth: Tech Honchos and Their Famous Lookalikes "Our HD Network has been designed for large-scale broadcasters and studios," said Akamai CEO Paul Sagan. "Our goal is to meet and surpass the needs of the film and television industries… TV is now possible online at HD bitrates." Akamai cofounder and chief scientist Tom Leighton said that Akamai's HD Network had a unique advantage in delivering HD streams because it had roughly 1,000 servers located on networks' last miles in 750 cities around the world.

Users streaming content over the Akamai HD Network will be able to watch video using Flash, Silverlight and iPhone protocols. Leighton said that this access to the last mile has enabled Akamai to deliver content at a rate of 2Mbps or greater to two-thirds of users in the United States and at a rate of 5Mbps or greater to around a quarter of users in the United States. The network also features an HD content analytics that allow providers to monitor and understand who is accessing their content and an HD player based on the open source standard provider through the Open Video Player Framework.

Three-year-old Office patch stymies most attacks

Users running Microsoft Office can stump nearly three-fourths of all known attacks targeting the suite by applying just one three-year-old patch, according to recently published data. The flaw was fixed in the MS06-027 security update issued. Almost three-out-of four attacks - 71% of all those spotted in the first half of 2009 - exploited a vulnerability in Word that was patched in June 2006, Microsoft said in its bi-annual security intelligence report, released Monday.

The second-most popular exploit, with a 13% share, aimed at a bug that was quashed in March 2008, Microsoft said. The 2006 update patched Word 2000, Word 2002 and Word 2003, while the 2008 fix affected Excel 2000, Excel 2002, Excel 2003 and Excel 2007. Microsoft made the point that patching Office was as important as keeping Windows up-to-date with security fixes. "The majority of Office attacks observed in [the first half of 2009], 55.5%, affected Office program installations that had last been updated between July 2003 and June 2004," the company said in its report. "Most of these attacks affected Office 2003 users who had not applied a single service pack or other security update since the original release of Office 2003 in October 2003." Unfortunately, users are far less likely to update Office than they are to patch Windows. The flaw was one of seven patched by the MS08-014 update. According to Microsoft's data, the median amount of time since the last Office update was an amazing 5.6 years, compared to just 1.2 years since the last Windows update. "Users can keep Windows rigorously up to date and still face increased risk from exploits unless they also update their other programs regularly," Microsoft warned. They do what's required of them," he continued, hinting that they often do little more than that. "Windows' security has a high profile, and so they're patching Windows.

Wolfgang Kandek, the chief technology officer at security vendor Qualys, echoed Microsoft's take on Office patching patterns. "We see the same in our data," Kandek said. "People just don't patch Office, and when they do, they patch it much slower than Windows." That especially holds true in the enterprise. "This is a major security hole in the enterprise," Kandek said. "IT admins are not focusing on Office as they are on Windows. I don't think they're looking at Office, to tell you the truth." Qualys obtains its data from PCs that it manages for its clients, most of which are companies. Office 2007 SP2 hit the street in April 2009. Nine out of 10 Office exploits in the first half of 2009 involved a Trojan downloader, or backdoor malware. "These kinds of threats allow attackers to access compromised systems later to install more malware," Microsoft said. One way to stay up-to-date without patching every month is to apply the infrequent service packs that Microsoft issues for Office. "If the Office 2003 RTM users in the sample had installed SP3 [Service Pack 3] and no other security updates, they would have been protected against 98% of observed attacks," Microsoft said. "Likewise, Office 2007 RTM users would have been protected from 99% of attacks by installing SP2." Microsoft delivered Office 2003 SP3 in September 2007, fixing more than 450 bugs in the application suite, and adding other security measures, including file blocking of older formats, a move that confused users well into the following year. Microsoft urged Office customers to use the Microsoft Update service, a superset of the better-known Windows Update that pushes patches for Windows and Office.

Office was last patched Oct. 13 when Microsoft unveiled a record number of security updates and fixed flaws. Here, too, Kandek was stumped by Microsoft's practice of offering two separate update services. "I'm not sure why that's the way they do it," he said, speaking of Microsoft's providing Office updates to consumers and small businesses only through Microsoft Update. "I don't see why they simply can't replace Windows Update with Microsoft Update, and patch everything." Microsoft offers Office, as well as Windows patches, to businesses that use its Windows Server Update Services (WSUS) patch management system. The security intelligence report can be downloaded from Microsoft's site in PDF or XPS document formats.

AMD graphics chip shortage hitting PC vendors

An offshore Advanced Micro Devices Inc. foundry is having trouble ramping up on production of a new 40-nanometer graphics processing unit, forcing PC makers to delay shipments of desktop and laptop computers, AMD confirmed today. He added that the foundry is in full production but so far yields are below expectation. The Taiwan Semiconductor Manufacturing Company Ltd. (TSMC) is struggling to get up to speed manufacturing AMD's 5800 series, 40-nm GPUs (graphics processing units), according to Jim McGregor, an analyst at In-Stat.

Matt Davis, a spokesman for AMD, confirmed to Computerworld that TSMC is having issues in ramping up production of the chips. It's just a matter of trying to get TSMC to a point where they can yield. He added that it's not clear how far behind the foundry is on production expectations. "The design is sound. They're feeling the manufacturing crunch," said Davis. "We're a little bitter under yield but we're working back into a manufacturing schedule we want for these parts. They're getting a huge swing on this. TSMC can only kick them out so fast at this point." Davis said that PC vendors are being affected but declined to say how many vendors are feeling the pinch or which ones. "It's the end of the whip," he added. "[The vendors] are going to have a hard time." Davis also said AMD is working with TSMC on the issue and hopes to have production up to speed by year's end. "They haven't been producing these chips for long, so you'd expect some ramp issues," said McGregor. "AMD is being affected because these are great parts and they're getting a lot of demand.

When you have more demand for a product than expected and lower yields than expected, you get the perfect storm." McGregor said AMD has a little time to get manufacturing in line before PC vendors start looking for greener pastures and turn to a graphics chip from rival Nvidia . "It's not something you can move away from overnight," said McGregor. "They're set up for that GPU. They could switch over to Nvidia but it would take some effort. It will all depend on how bad the shortage gets." Dan Olds, principal analyst at Gabriel Consulting Group, said that if projections of slow tech sales, especially of high-end products, hold true, AMD should survive the production slowdown rather well. They could switch. If the economy was strong, and buyers were clamoring for desktops and laptops, a production slowdown would significantly hurt the struggling AMD . "If the problem goes on long enough, or gets worse, it may prompt system vendors to reexamine their decision or hedge with products using other suppliers," said Olds, who added that he expects AMD to rectify the problem soon. "It's not unusual to see low yields when a chip is shrunk to a smaller process. I would expect to see yields rise over time as the glitches get fixed, but that doesn't do AMD much good right now." But most of these problems are ironed out well before the product is introduced into the market, which ensures that there will be enough supply to handle demand.

NASA watching “perfect storm” of galactic cosmic rays

Astronauts and satellite integrated circuits are at most risk of an ongoing tempest of galactic cosmic rays that scientists say is at an all-time high. Cosmic rays cause showers of particles when they hit Earth's atmosphere but they pose their greatest health hazard, radiation, to astronauts in space. According to NASA's Goddard Space Flight Center, galactic cosmic rays come from outside the solar system and are made up of subatomic particles accelerated to almost light speed by distant supernova explosions.

They aren't too healthy for satellites either as a single cosmic ray can disable the unit if one hits an unlucky integrated circuit, NASA said. "In 2009, cosmic ray intensities have increased 19% beyond anything we've seen in the past 50 years," said Richard Mewaldt of Caltech in a release. "The increase is significant, and it could mean we need to re-think how much radiation shielding astronauts take with them on deep-space missions." Network World Extra:  Top 10 cool satellite projects 10 NASA space technologies that may never see the cosmos   NASA says the surge is being caused by what it calls a "solar minimum," a deep lull in solar activity that began around 2007 and continues today. Right now solar activity is as weak as it has been in modern times, setting the stage for what Mewaldt calls "a perfect storm of cosmic rays." Mewaldt also says the solar wind is flagging. "Measurements by the Ulysses spacecraft show that solar wind pressure is at a 50-year low, so the magnetic bubble that protects the solar system is not being inflated as much as usual." A smaller bubble gives cosmic rays a shorter-shot into the solar system. Researchers have long known that cosmic rays go up when solar activity goes down. Once a cosmic ray enters the solar system, it must "swim upstream" against the solar wind. Still the Earth is in no great danger from the cosmic bombardment. Solar wind speeds have dropped to very low levels in 2008 and 2009, making it easier than usual for a cosmic ray to proceed, he stated.

The planet's atmosphere and magnetic field combine to form a formidable shield against space radiation, NASA points out. The study, conducted by the National Academy of Sciences noted that besides emitting a continuous stream of plasma called the solar wind, the sun periodically releases billions of tons of matter called coronal mass ejections. Earlier this year a NASA-funded study looked to show some of the first clear economic data that quantifies the risk extreme weather conditions in space have on the Earth. These immense clouds of material, when directed toward Earth, can cause large magnetic storms in the magnetosphere and upper atmosphere, NASA said. One of the driving reasons for the study is that the sun, as we mentioned above, is currently near the minimum of its 11-year activity cycle but solar storms will increase in frequency and intensity toward the next solar maximum, expected to occur around 2012. Such space weather can impact the performance and reliability of space-borne and ground-based technological systems, NASA said.

Keep Your Passwords Private--and Handy--With LastPass

This fall, more than 20,000 stolen usernames and passwords for such Webmail providers as AOL, Gmail, Hotmail, and Yahoo appeared on Pastebin.com, a programmer's Website. Dixon removed the stolen info, which Microsoft and some security researchers theorize was gathered through phishing attacks. The Webmaster, Paul Dixon, wrote that "for reasons unknown," some "miscreants" posted the data on his site. A researcher at ScanSafe argues that the data may have come from password-stealing malware, not phishing.

They also want access to your Webmail. Either way, crooks clearly aren't after only bank accounts and other financial log-ins. But why? After her Hotmail account was hacked, every message she sent included an unwelcome advertisement. A friend of mine was recently hit by a scam, and her experience helps answer that question.

Crooks have also begun using stolen Webmail and Facebook accounts to send pleas supposedly from a victim to friends or contacts. Don't Pass the Password To guard against password thieves, I use LastPass. Some bogus messages claim the sender is stranded overseas and needs an urgent wire transfer of funds. The tool offers a free password-managing add-on for Firefox on Windows, Linux, or Mac OS X; Internet Explorer on Windows; and Safari on Mac OS X. An add-on for Google Chrome is under development. And because you don't type your password, keylogger malware can't capture your keystrokes and nab your password. LastPass fills in your username and password for verified sites that match a real URL; phishing scams that use similar but fake Web addresses won't deceive it.

Other apps, like Password Hash, offer similarly worth­while protection, but LastPass stores all of your data on its servers (using 256-bit AES encryption) as well as on your PC. Since the company never has the software decryption key or your password, nobody at LastPass can get to your info. Even without the add-on, you can log in to LastPass's site to get to your information. Because your data is stored centrally, you can use the add-on with any browser, log in with your LastPass master account info, and access all of your passwords. That means you should create a fairly complex master password for the LastPass site, but it also means you have a de facto backup if your PC goes kaput. For instance, it normally keeps you logged in to your LastPass account for two weeks, even if you close and re-open the browser; to prevent someone from sitting at your desk and accessing your accounts, click Preferences and check Automatically logoff after idle. Instant Entry The handy add-on can automatically log you in to sites and can fill in forms, but for better security you should change some of its default settings.

I set mine to log off my LastPass account after an hour. You can enable this when the add-on automatically asks if you want to save a newly entered password. It's also smart to require a password reprompt for sensitive accounts; the app will ask for your master password before filling in the username and password, even if you're already logged in. LastPass offers applications for the iPhone, BlackBerry and other mobile devices, too, but those will cost you $12 per year.

Check Point tackles Web 2.0 apps and social-site widget control

Soon businesses that run Check Point security tools will be able to understand how thousands of Web applications and Web 2.0 widgets are used, giving executives better control over what employees do with their computers at work. 12 tips for safe social networking The company is developing a software blade that customers can buy to address use of social Web sites and Web applications. With the blade, due out next year, businesses could see not only that employees use Facebook, but also whether they are participating in Facebook groups or playing games available through the site, for example. Check Point has licensed extensive libraries from FaceTime that identify 4,500 Web applications and more than 50,000 Web 2.0 widgets.

Or they could keep an eye on applications that do file transfers, Check Point says. Initially, Check Point plans to incorporate the libraries in a blade that is just a monitoring tool, but later it will incorporate them in a firewall to create an access-control blade that can enforce restrictions on the use of applications and widgets. Business use of Web 2.0 sites brings its own security concerns and can run afoul of regulations from governmental agencies and business consortiums. Later still, the company says it will incorporate the libraries into IPS and QoS blades. For instance, customers might buy firewall, intrusion-detection system and antispam software blades and run them on a single hardware chassis.

Under Check Point's software blade architecture announced earlier this year, customers can buy individual security tools to create packages of custom security features. Before, Check Point sold monolithic multi-function unified threat management platforms that might include more functions than customers wanted. The libraries support FaceTime's own Unified Security Gateway product.

Gmail, Yahoo Mail join Hotmail; passwords exposed

Google's Gmail and Yahoo's Mail were also targeted by a large-scale phishing attack, perhaps the same one that harvested at least 10,000 passwords from Microsoft's Windows Live Hotmail, according to a report by the BBC. Microsoft , for its part, said late yesterday that it had blocked all hijacked Hotmail accounts, and offered tools to help users who had lost control of their e-mail. The BBC also said it has seen a list of some 20,000 hijacked e-mail accounts; the list included accounts from Gmail, Yahoo Mail, AOL, Comcast and EarthLink. Gmail was the target of what Google called a large-scale phishing campaign, the company told the BBC . "We recently became aware of an industry-wide phishing scheme through which hackers gained user credentials for Web-based mail accounts including Gmail accounts," a Google spokesperson told the news network. The latter two are major U.S. Internet service providers. "As soon as we learned of the attack, we forced password resets on the affected accounts," the Google spokesperson also told the BBC. "We will continue to force password resets on additional accounts when we become aware of them." Neither Google's or Yahoo's U.S. representatives responded to e-mails from Computerworld seeking confirmation that their Gmail and Yahoo Mail services were targeted by phishers, or answers to questions about how many accounts had been compromised and what the firms are doing to help users.

Late Monday, Microsoft said it was blocking access to all the accounts whose details had been posted on the Web last week. "We are taking measures to block access to all of the accounts that were exposed and have resources in place to help those users reclaim their accounts," the company said on its Windows Live blog . Microsoft posted an online form where users who have been locked out of their accounts can verify their identity and reclaim control, and also pointed users to a support page from October 2008 that spells out steps users can take if they think their accounts have been hijacked. Neowin.net, the site that first reported the Hotmail account hijacking early Monday, today added that it had seen the same list of compromised accounts as the BBC. "Neowin can today reveal that more lists are circulating with genuine account information and that over 20,000 accounts have now been compromised," said the Windows enthusiast site . "[The] new list contains e-mail accounts for Gmail, Yahoo, Comcast, EarthLink and other third-party popular Web mail services." Microsoft has acknowledged that log-on credentials for "several thousand" Hotmail accounts had been obtained by criminals, probably through a phishing attack that had duped users into divulging their usernames and passwords. After a slump earlier this year, phishing attacks are on the upswing, according to the Anti-Phishing Working Group (APWG). Its most recent data - for the first half of 2009 ( download PDF ) - noted that the number of unique phishing-oriented Web sites had surged to nearly 50,000 in June, the largest number since April 2007 and the second-highest total since the industry association started keeping records. Yesterday, Dave Jevans, the chairman of APWG, called the Hotmail phishing attack one of the largest ever, but cautioned that the usernames and passwords may have been harvested over several months, and not by a single, defined attack.

Users nervous about Oracle's acquisition of MySQL

The European Union is not the only one antsy about Oracle taking possession of the open source MySQL database should the commercial database giant's merger with Sun Microsystems get final approval. On its Web site, Oracle merely notes that "MySQL will be an addition to Oracle's existing suite of database products." "I wish that Oracle would broadcast its intentions a little bit more" on the Sun acquisition, says Duane Kimble, a Linux technologist who works in the banking industry. So are MySQL users. (The E.U.'s executive arm has held up approval of the merger, fearing that Oracle's acquisition of MySQL could reduce competition in the database market, as well as harm the open source nature of MySQL. Sun's stockholders and the U.S. Justice Department have approved Oracle's $7.4 billion acquisition of Sun.) "We've got a fair number of databases and Web applications that use those databases in MySQL. If Oracle does something that sort of makes it look like MySQL's days are numbered or something is going to change that we don't like, we'll probably look at alternatives," says Ernest Joynt, a contractor for the National Oceanic and Atmospheric Administration. [ Relive Sun's storied history in InfoWorld's slideshow "The rise and fall of Sun Microsystems." | Learn why attendees at the JavaOne conference were skeptical of Oracle's buyout of Sun. ] Anand Babu Periasamy, CTO of clustered storage technology company Gluster, expresses doubts that Oracle would add enterprise capabilities to MySQL. "I hope that they will retain MySQL. [But] I am doubtful [that] they will ever improve MySQL to take it mid-enterprise level, but at least it will help them compete with Microsoft SQL Server on the low end," he says. (Gluster uses MySQL for its Web site operations.) Thus far, Oracle has said little about its intentions for MySQL and declined to discuss the issue with InfoWorld. For him, Oracle's ownership of MySQL is a specific cause for caution.

His firm has begun looking at other enterprise-scale open source databases such as EnterpriseDB's Postgres database in case it has to replace MySQL. Standing to reap a harvest from unease about the Oracle-MySQL pairing are open source database vendors EnterpriseDB and Ingres. MySQL users start looking at alternatives A key issue is that Oracle is a main competitor to MySQL, notes Timothy Dion, CTO of mobile and Web apps builder Sensei. "I'm very concerned about what that means," he says. EnterpriseDB, which builds its products on the PostgreSQL open source database, has been hearing from concerned MySQL users, says Larry Alston, EnterpriseDB's vice president of product management and marketing. "They're telling us that they're nervous" about the future of MySQL, he says. Doubts remain over the fate of other Sun technologies Users remain concerned over the fate of other Sun technologies such as Java and Solaris, not just of MySQL. "We are rethinking our Solaris deployments," says Linux technologist Kimble. "We are moving swiftly toward more of an AIX and Linux environment, depending on the size or the scale of the project." Although Kimble notes it is "too early to say whether we'll move off [Solaris] or not," he does say his employer is rethinking its Solaris commitment: "Certainly, we're not going full-bore with Solaris as we were before the merger." Kimble does see a positive side to the Sun acquisition: "I think it kind of simplifies the platform offering somewhat. Ingres also sees opportunities. "The phones ring a lot," says Ingres CEO Roger Burkhardt. Oracle is a strong company and if they keep Sun Java, which I'm sure is what they bought [Sun] for, I think it will make Java a better product." But Bryce Pier is not so sure.

Another large company buying another large company reduces competition," he says. The senior systems engineer at Target sees no benefits of the buyout - at least not yet. "I'm not really certain that it's going to be good for anybody. Pier expects the acquisition to cause Target to move away from Solaris to Red Hat's Linux over time. Oracle, said Craig Muzilla, Red Hat's vice president for middleware, was very active in the Java Community Process for updating Java and has strived for openness in Java. "We don't see anything from Oracle that [would indicate that] they would do anything" that would differ with the past, he said. One reason is the uncertainty: "We're just not sure what Oracle's commitment is going to be to the Java stack and to maintaining it as an open source project." Another is Oracle's reputation for extracting revenues from customers: "We certainly fear that all of the subscription fees are going to change for everything from Sun." At its recent conference, Red Hat sought to reassure customers about the continued openness of Java-based JBoss technology, which Red Hat owns, now that Oracle is buying Java founder Sun.

Microsoft Internet Explorer SSL security hole lingers

Microsoft still does not acknowledge a weakness in its Internet Explorer browser that was pointed out seven weeks ago and enables attackers to hijack what are supposed to be secure Web sessions. If Microsoft doesn't fix the problem, Apple can't fix it on its own, Apple says. The company says it is still evaluating whether the weakness exists, but Apple, which bases its Safari for Windows browser on Microsoft code, says Safari for Windows has the weakness and the Microsoft code is the reason.

Apple has fixed the problem for Safari for Macs. Once our investigation is complete, we will take appropriate action to help protect customers," a Microsoft spokesperson said via e-mail. "We will not have any more to share at this time." The weakness can be exploited by man-in-the-middle attackers who trick the browser into making SSL sessions with malicious servers rather than the legitimate servers users intend to connect to. Black Hat's most notorious incidents: a quiz "Microsoft is currently investigating a possible vulnerability in Microsoft Windows. Current versions of Safari for Mac, Firefox and Opera address the problem, which is linked to how browsers read the x.509 certificates that are used to authenticate machines involved in setting up SSL/TLS sessions. The attacks involve getting certificate authorities to sign certificates for domain names assigned to legitimate domain-name holders and making vulnerable browsers interpret the certificates as being authorized for different domain-name holders. In July two separate talks presented by researchers Dan Kaminski and Moxie Marlinspike at the Black Hat Conference warned about how the vulnerability could be exploited by using what they call null-prefix attacks.

For instance, someone might register www.hacker.com. In that case, the authority would sign a certificate for bestbank.hacker.com, ignoring the sub-domain bestbank and signing based on the root domain hacker.com, Marlinspike says. In many x.509 implementations the certificate authority will sign certificates for any request from the hacker.com root domain, regardless of any sub-domain prefixes that might be appended. At the same time, browsers with the flaw he describes read x.509 certificates until they reach a null character, such as 0. If such a browser reads bestbank.com\0hacker.com, it would stop reading at the 0 and interpret the certificate as authenticating the root domain bestbank.com, the researcher says. An attacker could exploit the weakness by setting up a man-in-the-middle attack and intercepting requests from vulnerable browsers to set up SSL connections.

Browsers without the flaw correctly identify the root domain and sign or don't sign based on it. If the attacking server picks off a request to bestbank.com, it could respond with an authenticated x.509 certificate from bestbank.com\0hacker.com. The user who has requested a session with bestbank would naturally assume the connection established was to bestbank. The vulnerable browser would interpret the certificate as being authorized for bestbank.com and set up a secure session with the attacking server. Once the link is made, the malicious server can ask for passwords and user identifications that the attackers can exploit to break into users' bestbank accounts and manipulate funds, for example, Marlinspike says. These certificates use an asterisk as the sub-domain followed by a null character followed by a registered root domain.

In some cases attackers can create what Marlinspike calls wildcard certificates that will authenticate any domain name. A vulnerable browser that initiated an SSL session with bestbank.com would interpret a certificate marked *\0hacker.com as coming from bestbank.com because it would automatically accept the * as legitimate for any root domain. Such a wildcard will match any domain, he says. This is due to "an idiosyncrasy in the way Network Security Services (NSS) matches wildcards," Marlinspike says in a paper detailing the attack. The differences between what users see on their screens when they hit the site they are aiming for and when they hit an attacker's mock site can be subtle.

A Microsoft spokesperson says Internet Explorer 8 highlights domains to make them more visually obvious, printed in black while the rest of the URL is gray. "Internet Explorer 8's improved address bar helps users more easily ensure that they provide personal information only to sites they trust," a Microsoft spokesperson said in an e-mail. The URLs in the browser would reveal that the wrong site has been reached, but many users don't check for that, Marlinspike says. Marlinspike says the null character vulnerability is not limited to browsers. "[P]lenty of non-Web browsers are also vulnerable. Outlook, for example, uses SSL to protect your login/password when communicating over SMTP and POP3/IMAP. There are probably countless other Windows-based SSL VPNs, chat clients, etc. that are all vulnerable as well" he said in an e-mail.