May 4, 2011

New Wi-Fi gear aims to wipe out Ethernet edge switches

A third new service is a patent-pending technology called Orthogonal Array Beam Forming (OABF). WLAN vendors over the past two years have been adding support for various optional parts of the 11n standard, (see from May 2010, "Major Wi-Fi changes ahead") including transmit beam forming (sometimes "beamforming"). The same waveform is sent over 11n's multiple antennas, with the magnitude and phase adjusted at each transmitter to focus the beam direction toward a particular receiver. This increases the signal's gain so it's more stable, and can be "steered around" interferers so it's more reliable.






Best Microsoft MCTS Training – Microsoft MCITP Training at Certkingdom.com




[Ruckus Wireless in 2009 was the first to introduce beam forming for 11n products, exploiting its unique multi-component antenna design. Wireless blogger Craig Mathias used that introduction to explore the topic.]

Meru has created what it says is a more fine-grained alternative. Each Wi-Fi signal is made up of about 60 sub-carriers over a wide swath of spectrum, says Graham Melville, Meru's director of product management. Meru's code can optimize each of the sub-carriers and the result, he says, is an improvement in gain, or sensitivity, on the order of 8-10 dB.

The result of the improved gain is a higher signal quality and higher data rates: where Meru saw 36Mbps before applying its beamforming technology, it saw 54Mbps after, for example. "It stays at the high data rates because the signal is stronger, and better quality," Melville says.

The new access points also can use the optional Meru Proactive Spectrum Analysis as part of another service, called Air Traffic Services. One of the AP400 radios can be assigned the job of continually monitoring the Wi-Fi radio frequencies for unauthorized radios, analyzing the spectrum usage and interference, and running Meru's integrated wireless intrusion prevention system.

Another network service is called Mobile Application Segregation: administrators can create a dedicated channel for individual applications or groups of them, high definition video, or wireless VoIP.

John Cox covers wireless networking and mobile computing for "Network World."

May 3, 2011

New features of Microsoft Dynamics AX 2012 revealed

Microsoft on Monday offered new information about the next version of its enterprise resource planning software, Microsoft Dynamics AX 2012, and revealed that beta testing for the suite is expected to begin this month. Microsoft Dynamics AX 2012

Here's a point by point list of the improvements that Microsoft announced today:






Best Microsoft MCTS Training – Microsoft MCITP Training at Certkingdom.com



* Dynamics AX 2012 comes with five high-level "industry templates," for instant optimization for specific usage scenarios: manufacturing, distribution, public sector, professional services and retail. Within these, Dynamics AX 2012 has customizable sets of Unified Natural Models that cover real-world situations that each of these businesses face.

* Microsoft Dynamics AX 2012 uses Microsoft SQL Server as the default data management system, for more uniform embedded business intelligence functionality.

* Bi-directional integration with Microsoft Office 2010, and Enterprise Search functionality through connection with Microsoft SharePoint 2010 Business Connectivity Services.

* Integration with Microsoft Lync 2010 collaboration and communication services.

* Overall design streamlining, including the simplification of processes, and access to RoleTailored business intelligence data.

* Support for currencies, time zones, languages, and regional banking, reporting and legislative compliance for business systems in 38 countries worldwide.

Microsoft Dynamics AX 2012 logo

The beta of Microsoft Dynamics AX 2012 will be released this month, but Microsoft did not yet specify a date. The final release is expected to be available some time in August. Subsequent versions of Microsoft's ERP software will be available on the Azure cloud platform, Microsoft revealed on Monday. Their design will be similar to Microsoft's CRM products which are available both as on-premises software and as cloud-based SaaS.

May 2, 2011

Security researcher: 'Trivially easy' to buy SSL certificate for domain you don't own

Last week, Betanews reported on the discovery by two university researchers, made at a recent security conference, that security companies often deal with governments that can compel certificate authorities to produce SSL security keys for them. Those keys can then be used to sign certificates as any other Web site, enabling a law enforcement authority -- hypothetically speaking, of course -- to spoof virtually any other site.




Best Microsoft MCTS Training – Microsoft MCITP Training at Certkingdom.com

Today, Betanews heard from world-renowned security expert Kurt Seifried, author of numerous books on Linux system administration, network security, and cryptography. In the May 2010 issue of Linux Magazine, Seifried reports on his own discovery, which goes one very critical step further: You don't need to be a government, he found, to compel a certificate authority (CA) to issue an SSL certificate for a major Web mail service of your choice. You just need a valid credit card.

"Brief summary: One way to get certificates for domains you don't own: 1) Find a free Web mail provider. 2) Register an account such as ssladmin. 3) Go to RapidSSL.com and buy a certificate. When given the choice of what e-mail address to use, simply select ssladmin. 4) Go through certificate registration process (this takes about 20 minutes). 5) You will now have a secure Web certificate for that Web mail provider," Seifried told Betanews this afternoon.

In his Linux Magazine article, Seifried lists several other permutations of generic-sounding e-mail account names that may be given to the guy in charge of administration, including the obvious postmaster, administrator, and root. In his own tests, Seifried says, it usually took only a half-hour to acquire a perfectly valid certificate for a major Web mail service.

"The industry-accepted standard for confirming someone is who they say they are and that they control a domain is that 'the CA takes reasonable measures to verify,' which is very ambiguous at best and meaningless at worst," reads Seifried's article. "One CA proposed that customers could fax a signed letter on company letterhead as proof that they controlled a domain (Have they not heard of word processors and image editing programs? Or online fax services?). CAs want to sell as many certificates for as little money as they can; if this puts users at risk but doesn't cost the CA anything, then there is no incentive to fix things."

We asked Seifried, what can the general user do to protect himself against a possible authoritative spoof using a false certificate? We didn't like the sound of his answer: "Nothing. User education hasn't worked and won't work...The only reason I know the difference is I investigated this a while back; I've been writing about how broken SSL is off and on for a decade now."

Seifried credits Mozilla Firefox for at least giving the user good visual clues as to the validity of a signed certificate -- for instance, using the color-coded bars next to the HTTPS: address in the upper bar. But ask everyday folks what those colors mean, he said, and they wouldn't be able to tell you. Are there further steps Mozilla, or any other browser maker, could take to make "Trust" more meaningful to the user, and less likely to be something else for him to ignore? "Well there would be one possibility, but it'll never happen, and that would be to boot out all the CAs that don't do a good job verifying domains/etc. and only have root CAs that do a good job," Seifried responded.

"Basically right now, when a CA checks 'ownership' of a domain, it checks one e-mail address, which is trivial to bypass especially with, say, a free Web mail provider," he continued. "If it were to add more checks -- i.e., the CA generates a random string (say an MD5 sum) and requires you to place 8987a978d987e987c978.html or whatever in your webroot at www.yourdomain.com to prove you have control over the Web server as well; and maybe a DNS check, like requiring you to create a DNS record of iugasdcviuoba.yourdomain.com to prove that you have control over the DNS -- that would greatly help, because in that case, you either are a legit domain owner, or the attacker has such a degree of control over your domain that any checks won't matter. The funny thing is, Google used to do this for some of its services like Google Analytics. Also making the e-mail check more stringent -- i.e., only e-mail_address@the domain listed in WHOIS, or well-known and typically controlled e-mail address such as postmaster@, would also help greatly.

"But then buying a certificate would take time and the verification process would fail more often (waiting for DNS propagation/etc.), so it's very unlikely to happen. Once you get a certificate in the root CA store, you basically have a license to print money."
Bookmark and Share