Wednesday, 28 January 2015

IT Technology: Google Taps WePay to Put Wallet Support in 200K More Online Stores


Google Wallet just struck up a partnership with payment processor WePay to put its Instant Buy API in 200,000 e-commerce shops.

WePay is a payment processor that powers invoicing applications, marketplaces, and donation platforms like GoFundMe. Through its relationship with InvoiceASAP, it also provides payment processing for some 200,000 small and medium online businesses.

“This integration with WePay will now expand its reach and allow us to support small business owners through WePay’s hosted payment offering, making it easier for them to accept payments online and on mobile devices,” says Steve Klebe, Business Development, Payments for Google.

The integration will allow consumers to pay with their Google Wallet with a couple of taps both online and on mobile. It will also make Google Wallet more visible.

Right now the most visible wallet service on the web is PayPal. On many e-commerce sites PayPal appears alongside Visa and MasterCard. Google launched Google Wallet Instant Buy API in 2013, so that people would have more of an opportunity to use its wallet. Two years down the road it doesn’t have the pervasiveness that PayPal has.

With the launch of Apple Pay, digital payments have been jettisoned into the spotlight. In order to capitalize on that Google needs to make a case for its own payment solution — and fast.

Many merchants are not partial to a payment method. They’re happy to accept whatever consumers want to use — so long as it doesn’t cost them too much.

WePay CEO Bill Clerico is also agnostic. He says WePay is in the process of incorporating Apple Pay.

IT Technology: SAN versus NAS versus DAS


NAS stands for Network Attached Storage. It differs from traditional, directly attached storage in that, in NAS, the operating system and other software on the NAS product are dedicated solely to data storage.

SAN stands for Storage Area Network. A SAN is a network designed to attach storage hardware and software to servers. SANs generally come in two forms: as a network primarily dedicated to transferring data between computer systems and storage systems, or as a complete system that includes all of the storage elements and computer systems within the same network.

DAS stands for Directly Attached Storage. DAS is generally used to differentiate between storage systems directly attached to a server or workstation and NAS and SAN setups.

IT Security: Malware Makers Cash In With Fake YouTube Views


Programmers of malware software have found a new way of making their exploits pay: A newly-discovered scam downloads malware to unsuspecting users’ computers and then makes those machines watch YouTube videos to cash in on the video service’s partner program. The malware, dubbed Trojan.Tubrosa, was able to generate more than two million views for videos uploaded by the malware makers, according to security researchers at Symantec.

YouTube has a few safeguards in place to prevent users from gaming the system. Not only does the video service monitor the types of content uploaded to YouTube to make sure that users aren’t infringing any rights, it also monitors for fraudulent clicks, much in the same way Google monitors its ads for irregular activities.

The developers of Trojan.Tubrosa tried to circumvent these safeguards by dynamically changing referrers in an attempt to trick YouTube’s servers into thinking that each view came from just a single user. In reality, affected machines were generating lots of views. From Symantec’s blog:
“In order to keep its malicious activities secret, the malware will lower the volume of the compromised computer’s speakers to zero. The malware will even update or install Flash on the user’s computer to allow it to view these videos. The user may not realize that anything is amiss until their computer’s resources are fully used up and they experience significant performance degradation.”

Symantec’s researchers expect that the developers of this particular malware made “several thousand dollars.” Google apparently caught on to it eventually, telling Symantec that it was “aware of this malware.”

And of course, YouTube isn’t alone in being targeted by fraudulent views. Ad fraud is a huge problem that the industry doesn’t like to talk about, and estimates vary widely. Some think that around 36 percent of all ad impressions are fraudulent, while others believe the number could be even higher. Kraft went public last year saying that it rejects up to 85 percent of digital ad impressions because of possible fraud and other quality concerns.

Friday, 23 January 2015

IT Technology: WhatsApp Web


You will now have the ability to use WhatsApp on your web browser. The web client is simply an extension of your phone: the web browser mirrors conversations and messages from your mobile device -- this means all of your messages still live on your phone.

To connect your web browser to your WhatsApp client, simply open https://web.whatsapp.com in your Google Chrome browser. You will see a QR code --- scan the code inside of WhatsApp, and you’re ready to go. You have now paired WhatsApp on your phone with the WhatsApp web client. Your phone needs to stay connected to the internet for our web client to work, and please make sure to install the latest version of WhatsApp on your phone. Unfortunately for now, we will not be able to provide web client to our iOS users due to Apple platform limitations.


Reference:
WhatsApp Web
https://blog.whatsapp.com/614/WhatsApp-Web

Thursday, 22 January 2015

Microsoft: Microsoft Windows 10 for FREE!


Microsoft's Windows 10 event is just getting started, and it sounds like the company is eager to make it as easy and cheap as possible for those running older versions of Windows to upgrade. Terry Myerson just announced on stage that, for the first year after Windows 10 launches, any device running Windows 7, Windows 8.1, or Windows Phone 8.1 will be able to upgrade to the latest version of MIcrosoft's OS — for free. How exactly this program will work isn't clear just yet — it'll certainly be subject to some hardware requirements, particularly for older machines running Windows 7. But a simplified upgrade path will likely do a lot to help Windows 10 adoption — rather than dealing with a number of different versions of Windows and different upgrade costs, most consumers will simply take this free update and enjoy running Microsoft's latest.

Beyond this, Myerson shared Microsoft's vision for Windows as a service, not just an operating system. A big part of that is Microsoft's new commitment to keep devices consistently updated throughout the "supported lifetime for the device." It sounds like that means those upgrading from Microsoft's older versions of Windows will consistently receive updates to keep it as up-to-date as possible. Myerson noted that this will let developer "target every single Windows device" when they build apps — anything that makes it easier for developers to reach more users will certainly be appreciated by both the developer community as well as end users.


Reference:
Windows 10 will be a free upgrade for Windows 7 and 8.1 users
http://www.theverge.com/2015/1/21/7866679/windows-10-will-be-a-free-upgrade-for-windows-7-and-8-1-users

Monday, 19 January 2015

Cisco: Cisco Identity Services Engine ( ISE )

Get a security policy management platform that automates and enforces secure access to network resources. Cisco Identity Services Engine (ISE) delivers superior user and device visibility to support enterprise mobility experiences. It shares contextual data with integrated partner solutions to accelerate their capabilities to identify, mitigate, and remediate threats. Cisco Identity Services Engine (ISE) is a network administration product that enables the creation and enforcement of security and access policies for endpoint devices connected to the company’s routers and switches.

Cisco ISE helps IT professionals conquer enterprise mobility challenges and secure the evolving network across the attack continuum. ISE provides you with several capabilities, some of which are listed below.

1.  Centralize and unify network access policy management to provide consistent, secure access to end users, whether they connect to your network over a wired, wireless, or VPN connection.

2.  Gain greater visibility and more accurate device identification. ISE's superior device profiling and zero-day device profile feed service provides updated profiles for the latest devices. Combined, these two features help reduce the number of unknown endpoints (and potential threats) on your network.

3.  Implement logical network segmentation based on business rules by taking full advantage of Cisco TrustSec technology. Use it to create role-based access policy to dynamically segment access without the complexity of multiple VLANs, replicating complicated access control lists across your network, or completely changing network architecture.

4.  Simplify guest experiences for easier guest onboarding and administration. Use ISE’s easily-customizable, branded mobile and desktop guest portals to create access in just minutes. ISE’s dynamic visual workflows let you fully manage every aspect of guest access.

5.  Streamline BYOD and enterprise mobility with easy, out-of-the-box setup for self-service device onboarding and management. ISE includes an internal certificate authority, multi-forest Active Directory support, and integrated enterprise mobility management (EMM) partner software.

With support for 250,000 active, concurrent endpoints (and up to 1,000,000 registered devices), ISE allows enterprises to accelerate mobility projects across the extended network.

6.  Share deep contextual data with third-party ecosystem partner solutions through Cisco Platform Exchange Grid (pxGrid), included within ISE. Contextual data improve the efficacy of partner solutions and accelerate their abilities to identify, mitigate, and remediate network threats.

For example, with ISE, integrated partner solutions can more rapidly remediate threats and streamline network forensics and endpoint vulnerability remediation. They can also provide adaptive single sign-on to identity-federated devices, and even extend secure access to SCADA/control networks - all based on context and identity received from Cisco ISE.


Reference:
Cisco Identity Services Engine
http://www.cisco.com/c/en/us/products/security/identity-services-engine/index.html

Friday, 16 January 2015

IT Technology: DNS Amplification DDoS Attack

DNS Amplification Attacks are a way for an attacker to magnify the amount of bandwidth they can target at a potential victim. Imagine you are an attacker and you control a botnet capable of sending out 100Mbps of traffic. While that may be sufficient to knock some sites offline, it is a relatively trivial amount of traffic in the world of DDoS. In order to increase your attack's volume, you could try and add more compromised machines to your botnet. That is becoming increasingly difficult. Alternatively, you could find a way to amplify your 100Mbps into something much bigger.
The original amplification attack was known as a SMURF attack. A SMURF attack involves an attacker sending ICMP requests (i.e., ping requests) to the network's broadcast address (i.e., X.X.X.255) of a router configured to relay ICMP to all devices behind the router. The attacker spoofs the source of the ICMP request to be the IP address of the intended victim. Since ICMP does not include a handshake, the destination has no way of verifying if the source IP is legitimate. The router receives the request and passes it on to all the devices that sit behind it. All those devices then respond back to the ping. The attacker is able to amplify the attack by a multiple of how ever many devices are behind the router (i.e., if you have 5 devices behind the router then the attacker is able to amplify the attack 5x, see the diagram above).

SMURF attacks are largely a thing of the past. For the most part, network operators have configured their routers to not relay ICMP requests sent to a network's broadcast address. However, even as that amplification attack vector has closed, others remain wide open.


Reference:
Deep Inside a DNS Amplification DDoS Attack
https://blog.cloudflare.com/deep-inside-a-dns-amplification-ddos-attack/