Data breach hits payroll firm PayChoice

PayChoice of Moorestown, N.J., suffered an online breach that has apparently compromised its payroll-processing operations. 10 of the worst moments in network security history "PayChoice discovered a security breach in its online system on Wednesday, September 23, 2009," PayChoice CEO Robert Digby confirmed in a statement. "We are handling this incident with the highest level of attention as well as concern for our clients, software customers and the employees they serve." PayChoice today indicated it is working to provide additional information about the breach. Post writer Brian Krebs reports that the phishing attack was apparently aimed at getting into payroll and account data. According to the Washington Post, a number of PayChoice customers were subjected to an apparent phishing scam when they received an e-mail instructing them to download a Web browser plug-in in order to maintain access to PayChoice's online payroll service, onlineemployer.com.

PayChoice is said to license its online employee payroll management product to more than 240 other payroll processing firms to serve 125,000 organizations. He said licensees and payroll clients will be apprised on a daily basis, and he added they should taking "appropriate protective measures, including changing passwords and user id information." In his statement, Digby said that on Sept. 23rd, "we immediately shut down the online system and instituted fresh security measures to protect client information before starting it up again." The payroll-processing company has also engaged forensics experts to help determine the scope of the intrusion and notified federal law enforcement, according to Digby.

Microsoft's CodePlex Foundation leader soaks in stinging critique

After a stinging critique from a noted expert in establishing consortia, the leader of Microsoft's new CodePlex Foundation says such frank evaluation is welcome because the open source group's structure is a work in progress. The CodePlex Foundation's aim is to get open source and proprietary software companies working together. Sam Ramji, who is interim president of the CodePlex Foundation, was responding to last week's blog by Andy Updegrove, who said the group has a poorly crafted governance structure and looks like a sort of "alternative universe" of open source development. Updegrove, a lawyer, noted expert on standards, and founder of ConsortiumInfo.org, laid out in a blog post five things Microsoft must change if it wants CodePlex to succeed: create a board with no fewer than 11 members; allow companies to have no more than one representative on the Board of Directors or Board of Advisors; organize board seats by category; establish membership classes with rights to nominate and elect directors; and commit to an open membership policy.

He added, however, "There are some best practices [for running the boards of non-profits] that we are not as familiar with as we would want to be." Slideshow: Top 10 open source apps for Windows  Stephanie Davies Boesch, the foundation's secretary and treasurer, is the only board member with experience sitting on a non-profit's board. Despite the stinging tone in Updegrove's assessment, Ramji says he is thankful for the feedback. "Andy's been incredibly generous with his expertise and recommendations," Ramji says. "It is the kind of input and participation we were hoping to get by doing what is probably non-traditional for Microsoft but not necessarily non-traditional for non-profit foundations, which is to basically launch as a beta." For instance, Ramji says that the decision to go with only five people on the board came from Microsoft's experience that larger groups often have difficulty with decision making. Ramji says Updegrove's suggestion to have academic representation on the board was "outstanding. And basically it is re-writable. We did not think of that." And to Updegrove's point on becoming an open membership organization, Ramji says, "our goal is to become a membership organization and Andy has some excellent recommendations for that."He says the fact that Updegrove took the time to respond "in the format that he did is more proof that there is something worth doing here." Ramji, compares the Foundation's formation to the early days of a software development project. "We have said in these first 100 days we are looking at everything as a beta. Obviously, there are some areas like contributions and licensing agreements we put a lot of time into but even those can be modified." Microsoft announced the foundation Sept. 10 with a stated goal "to enable the exchange of code and understanding among software companies and open source communities." The company seeded the group with $1 million and Microsoft employees dominated the interim board of directors and board of advisors.

One is a call for a broad independent organization that can bridge cultural and licensing gaps in order to help commercial developers participate in open source. Ramji says the foundation has spent the past couple of weeks listening to feedback in "Twitter messages, email, and phone calls in order to understand what people hope this can be." Within that feedback two patterns have emerged, Ramji says. The other focuses on creating a place where open source .Net developers can gain strong backing. "Look at projects related to Mono, you also can look at NUnit, NHibernate, we really feel optimistic that the Foundation could help them gain a higher level of credibility in the open source community. Miguel de Icaza, the founder of the Mono project and the creator of the Gnome desktop, is a member of the Foundation's interim board of directors. They feel they have been lacking that strong moral support," Ramji says. From a high level, Ramji says the Foundation stands as a sort of enabler that helps independent developers, companies and developers working for those companies navigate the nuances and practices of open source development so they can either contribute source code to projects or open source their own technologies. "One suggestion has been that the Foundation should house all the best practices we have seen software companies and open source communities use," said Ramji. "We want to have a place where everyone interested in how to participate can come and read and if they choose they can use our license agreements or can use the legal structure of the Foundation to grant patent licenses and copyrights for developers and derivative works." Those licensing agreements have a distinct focus, Ramji said, on the rights that are related to code that is being contributed and on how to contribute the patent rights on that code.

Ramji says the goal is to service multiple projects, multiple technologies and multiple platforms rather than having one specific technology base, which is how most current open source foundations are structured. "It's early days and we have received a lot of good ideas from experts in a variety of fields from law to code to policy that is what we had hoped for," says Ramji. "Someone wrote it is nice to see Microsoft engaging early on without all the answers and to have the community solve what they would like to see. Once those issues are settled, code would be submitted using existing open source licenses. That is satisfying for me and refreshing to others. This is the right way to proceed." Follow John on Twitter

The other iPhone lie: VPN policy support

It turns out that Apple's iPhone 3.1 OS fix of a serious security issue - falsely reporting to Exchange servers that pre-3G S iPhones and iPod Touches had on-device encryption - wasn't the first such policy falsehood that Apple has quietly fixed in an OS upgrade. Before that update, the iPhone falsely reported its adherence to VPN policies, specifically those that confirm the device is not saving the VPN password (so users are forced to enter it manually). Until the iPhone 3.0 OS update, users could save VPN passwords on their Apple devices, yet the iPhone OS would report to the VPN server that the passwords were not being saved. It fixed a similar lie in its June iPhone OS 3.0 update. The fact of the iPhones' false reporting of their adherence to Exchange and VPN policies has caused some organizations to revoke or suspend plans for iPhone support, several readers who did not want their names or agencies identified told InfoWorld.

Worse, it revealed that Apple's iconic devices have been unknowingly violating such policies for more than a year. "My guess is the original decision to emulate hardware encryption was made at a level where there wasn't much awareness of enterprise IT standards. One reader at a large government agency describes the IT leader there as "being bitten by the change," after taking a risk to support the popular devices. "I guess we will all have to start distrusting Apple," said another reader at a different agency. [ Apple's snafu on the iPhone OS's policy adherence could kill the iPhone's chances of ever being trusted again by IT, argues InfoWorld's Galen Gruman. ] Last week's iPhone OS 3.1 update began correctly reporting the on-device encryption and VPN password-saving status when queried by Exchange and VPN policy servers, which made thousands of iPhones noncompliant with those policies and thus blocked from their networks. (Only the new iPhone 3G S has on-device encryption.) Apple's document on the iPhone OS 3.1 update's security changes neglected to mention this fix, catching users and IT administrators off-guard. After all, this is a foreign language for Apple," says Ezra Gottheil, an analyst at Technology Business Research. "However, once the company realized the problem, it made a spectacularly dumb choice. Instead, it allowed itself to be seen in the worst possible light. The change was necessary and inevitable, but Apple could have earned some points by coming clean at the earliest opportunity.

This is the result of a colossal clash of cultures. Even when it is trying, Apple cannot force itself to think like an enterprise vendor." Apple's advice to users on addressing the Exchange encryption policy issue is to either remove that policy requirement for iPhone users or replace users' devices with the iPhone 3G S. IT organizations can also consider using third-party mobile management tools that enforce security and compliance policies; several now support the iPhone to varying degrees, including those from Good Technology, MobileIron, and Zenprise.

Web server attacks, poor app patching make for lethal mix

A dangerous combination of a massive increase in Web server attacks and poor patching practices is a major cause of concern for experts, according to a report issued today by several security organizations. Hackers are after a foothold in the corporate network, to conduct client-side attacks against visitors of the site, but also once they have that foothold, to gain much higher privileges and use those to also steal data." Dhamankar pointed to the recent spread of malware from the New York Times Web site as a perfect example of the alarming increase in server attacks. In a groundbreaking study that matched attack trends with patching cycle data, some conclusions came as a shock, said Rohit Dhamankar, the director of security research at 3Com TippingPoint, which contributed real-world attack information - acquired from its intrusion detection systems - to the report. "The sheer number of attacks against Web servers was surprising," said Dhamankar. "In terms of attack volume, they were almost 60% of all so far this year. Over the weekend, hackers duped the newspaper into using a malicious ad, which in turn tricked users into downloading and installing fake antivirus software . "The New York Times is a respected brand, and so it's a perfect avenue to infect lots and lots of users," he noted.

The report - which can be read on the SANS Institute's Web site - correlated the high number of Web server attacks with another trend: poor patching practices by the Web's highest-profile third-party applications. "Applications that are widely installed are not being patched at the same speed as the operating system," said Wolfgang Kandek, the chief technology officer of Qualys, which contributed its patching data to the study. "For Adobe Reader, Adobe Flash, Sun Java, Microsoft Office, Apple QuickTime, the patch cycles are much much slower than for operating system," he added. Some servers, once compromised, are even attacking other servers to pillage back-end information and to host malware fed to unsuspecting users, said Dhamankar. That's a major problem. "From our point of view, this is a big deal, said Kandek, speaking for security professionals in general. "There are real-life examples, where you can see attackers attacking corporate Web servers, then from there infecting client machines, until eventually a client machine is compromised that has full access to the network. The combination of hacked servers and unpatched client applications is critical. "The lack of patching opens up a huge window of vulnerabilities," Kandek acknowledged. "It shows that patching is crucial." Adding salt to the wound, said Dhamankar and Kandek, is that while users are patching, they're patching the wrong software. Then [attackers] are stealing that corporation's data." "Attackers have realized that patching of these third-party apps is complex," added Dhamankar. "They know that a lot of people are focused on patching operating systems rather than patching applications like Flash or Reader." And thus they dig into the most widely-installed applications, looking for flaws.

While operating systems, particularly Windows, are patched by users and organizations at a relatively rapid - and complete - clip, the number of attacks exploiting OSes has dropped precipitously. "Enterprises are focused on OS patching rather than on application patching," said Dhamankar. "They don't have their resources allocated properly." Putting a stop to the threat trend won't be easy, but it is possible, argued Kandek. "Some enterprises have patching policies in place for third-party applications, and there are industry-standard tools to do this," he said. "The technical solutions are out there. [Third-party] patching could be much better, and I see vendors being pressured to do more to integrate their patching into these tools. "But we've done this before," Kandek continued, referring to the security situation several years ago, when Windows was the main target of attackers. Microsoft beefed up its then-OS, Windows XP, dedicated itself to writing more secure code and pushed customers to update religiously. "That means we can do something about this, too," Kandek concluded.

Oracle breaks silence on Sun plans in ad

Oracle Corp. ended it silence Thursday on its post-merger plans for Sun Microsystems Inc.'s Unix systems in an advertisement aimed at Sun customers to keep them from leaving the Sparc and Solaris platforms. Ever since Oracle announced in April its plans to acquire Sun, its competitors - notably IBM and Hewlett-Packard Co. - have been relentlessly pursuing Sun's core customer base, its Sparc and Solaris users. Oracle's ad to "Sun customers," makes a number of promises that includes spending more "than Sun does now," on developing Sparc and Solaris, as well as boosting service and support by having "more than twice as many hardware specialists than Sun does now." Analysts see Oracle's ad as a defensive move that doesn't answer some of the big questions ahead of the $7.4 billion merger with Sun . In fact, there may be a lot of room for skepticism and parsing of Oracle's claims, despite their apparent black and white assertions.

Among the top hardware makers, Sun registered the biggest decline in server revenue in the second quarter, offering evidence that this protracted merger may be eroding Sun's value. Europe is allowing until mid-January to sort this out, which keeps the merger in limbo for another quarter. Oracle wanted the acquisition completed by now but the European Commission this month said it would delay its antitrust review because of "serious concerns" about its impact on the database market. Analysts point out that Oracle's plans to spend more "than Sun does now," may be a little hallow because Sun's spending on developing Sparc and Solaris is probably at a low. "The ad sounds convincing - but perhaps being a word nitpicker, the Sun does now' might not mean much if Sun has drastically cut back due to plummeting sales," Rich Partridge, an analyst at Ideas International Ltd., said in an e-mail. "I think someone at Oracle suddenly realized that Sun was bleeding so badly that what would be left when Oracle finally got control would be worth a small fraction of what they paid and no one would buy the hardware unit," Rob Enderle, an independent analyst, said in an e-mail. But Enderle said the ad's claims do not preclude Oracle from selling its hardware division, and says the company "will have to support the unit for a short time after taking control; during that short time they can easily outspend Sun's nearly non-existent budgets." Gordon Haff, an analyst at Illuminata Inc., said if it was Oracle's plan to start on day one of the merger to shop the Sparc processor around, "would they have put this ad out? Taken at face value, the ad seems to indicate that Oracle will keep Sun's hardware and microprocessor capability and not spin it off, as some analysts believe possible.

Probably not," he said. "Does it preclude Oracle from changing their mind? Indeed, Oracle's major competitive concern was indicated in the ad in a quote by Oracle CEO Larry Ellison: "IBM, we're looking forward to competing with you in the hardware business." No. Companies change their mind all the time." An erosion of Sun's customer also hurts Oracle, because a lot of Sun customers are also Oracle customers, and Oracle doesn't want its existing customer to go to IBM and move away from Oracle's platform, Haff said.

Microsoft Issues Emergency Patches for IE

Microsoft today took the unusual step of releasing out-of-band patches for severe security flaws in all versions of Internet Explorer, along with related holes in the Microsoft Active Template Library included with Visual Studio.

Microsoft generally only releases patches outside of its normal monthly cycle for the most dangerous security flaws. The IE risks involve "components and controls that have been developed using vulnerable versions of the Microsoft Active Template Library," according to Microsoft, and could allow an attacker to run commands or download malware on a vulnerable PC if you simply view a malicious Web page. Such drive-by-download attacks are a favorite among Internet attackers.

According to Microsoft, this MS09-034 patch "is rated Critical for Internet Explorer 5.01 and Internet Explorer 6 Service Pack 1, running on supported editions of Microsoft Windows 2000; Critical for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 running on supported editions of Windows XP; Critical for Internet Explorer 7 and Internet Explorer 8 running on supported editions of Windows Vista; Moderate for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 running on supported editions of Windows Server 2003; and Moderate for Internet Explorer 7 and Internet Explorer 8 running on supported editions of Windows Server 2008."

Translation: if you use any version of IE on Windows 2000, XP or Vista, get the fix asap by running Windows Update. IT folks who maintain Windows Server 2003 and 2008 boxes don't have to rush quite as quickly but will still want the fix.

The companion patch fixes holes in the Microsoft Active Template Library, part of Visual Basic, which can be used to create the vulnerable ActiveX controls that trigger the IE flaws fixed in the MS09-034 patch. According to Symantec, the ATL patch won't fix vulnerable controls that have already been created, but will avoid creating new vulnerable controls. For more information see the MS09-035 bulletin.

EMC distances rival NetApp

EMC  has scored another victory over storage rival NetApp by purchasing Data Domain, a merger which widens the technological gap between the companies in the fast-growing data de-duplication market.

NetApp desperately wanted Data Domain to bolster its largely unsuccessful de-duplication business, as evidenced by its $1.9 billion bid to purchase the company. But EMC proved too rich, and on Wednesday signed a definitive agreement to buy Data Domain for $2.1 billion. 

"This is a move that strengthens EMC and doesn't put them in any financial or competitive bind," notes Pund-IT analyst Charles King. "From a competitive standpoint, I think EMC won the day here."

De-duplication is expected to play a major role in the storage market because it lets companies reduce the amount of disk space they need in their data centers. With data volumes growing quickly, technologies that make storage more efficient will be of huge importance over the next few years, says Forrester analyst Andrew Reichman.

But Reichman believes EMC paid too much for Data Domain. De-duplication is important because it automates the process of reducing storage requirements, but it isn't the only technology that can make storage more efficient, he says. Thin provisioning, snapshots and clones, and denser drives can all help enterprises use disk space more efficiently, he says.

The $2.1 billion price tag for Data Domain could be "mitigated by significant market growth" in de-duplication, Reichman says. "But I think in a number of years we might look back on this deal and say the winner lost and the loser won," he says. "You could say NetApp is a loser in this buy they didn't spend that huge amount of money. That gives them flexibility.

NetApp actually comes out of the negotiations $57 million richer, courtesy of a merger agreement termination fee Data Domain was obligated to pay. NetApp CEO Dan Warmenhoven said the company could not justify "engaging in an increasingly expensive and dilutive bidding war," and that NetApp remains confident in its "already compelling strategic plan, market opportunities, and competitive strengths."

NetApp was smart to walk away from the bidding war, but may still attempt to acquire another de-dupe vendor, says Deni Connor, principal analyst with Storage Strategies Now.

"I think it was a wise decision for NetApp to step away from it," Connor says. "Re-bidding for Data Domain would have really hurt their cash flow. It'll be interesting to see, though, what both companies do, how EMC integrates the Data Domain products and also what NetApp does in order to get some extra de-duplication capability."

Even if NetApp's decision was the right one, the bidding war forced the company to expose its financial limitations relative to EMC.

"This puts NetApp in a curious position," King says. "I've seen some analysts say that the company with the deeper pockets won and that's true enough. But the bidding war has also exposed the amount of money that it took to make NetApp blink, in essence. From a strategic standpoint, that's not a great place for a vendor to be in. … They've laid their cards on the table and moving forward I think that would put them at a disadvantage."

EMC reportedly has more than $7 billion in cash reserves, compared to $2.7 billion for NetApp. EMC also has a sizable sales lead, with $871 million in external disk storage systems factory revenue in Q1 2009, compared to $373 million for NetApp, according to a June report by IDC. NetApp isn't even EMC's biggest rival in terms of storage revenue, as HP, IBM, Dell and Hitachi all earn more NetApp.

To one observer, the Data Domain bidding war made little sense for either potential buyer. Data Domain's de-duplication technology is robust, but not the only game in town, notes analyst Arun Taneja of the Taneja Group. Data Domain's technology is single-node, meaning it can only de-dupe one node at a time, whereas rivals such as FalconStor, Sepaton and Permabit offer the more expansive global de-duplication, Taneja says.

"I think there are way less expensive ways of getting really good technology," Taneja said earlier this week, when the outcome of the bidding war was not yet clear. "The price is excessive right now. I'm always in favor of a company getting fair value. This is beyond fair, this has gone into a degree of madness. And I don't understand that because there are other technologies that are extremely viable."

NetApp does offer de-duplication today, but Taneja says the offerings haven't caught on with customers. "Unquestionably, NetApp needs a data de-duplication product. They don't have [a successful] one of their own," he says.

NetApp has offered de-dupe with its VTL product, but "it has no visibility, it has no traction," Taneja said.

NetApp last year  boasted that it can de-dupe primary storage from third-party vendors such as EMC, Hitachi and HP, as part of its V-Series line of storage virtualization products. NetApp has de-dupe built into its Data Ontap operating system, but clearly wanted to adopt an appliance-based approach by purchasing Data Domain, Connor says.

Connor expects further consolidation in the data de-duplication market. In addition to NetApp, HP and Dell might be interested in picking up one of the various de-dupe vendors, such as FalconStor, Sepaton, CommVault or Quantum, she says.

"I think it will be interesting to watch what else happens in the de-duplication wars. I don't think it's over yet," Connor says.King believes the pickings are slim now that Data Domain is off the market. Despite the limitation noted by Taneja, King said Data Domain succeeded in building a product with great efficiency and price-performance. "There are some other good companies out there, but I don't believe there are any with the same stature as Data Domain," King says.

One more question is how EMC will integrate Data Domain into its own line of products. The acquisition could potentially be bad for customers, who would have preferred de-duplication offered by an independent vendor, suggests Juergen Urbanski, managing director with industry analyst firm TechAlpha.

"Storage efficiency (notably de-duplication) is the enemy of a business model predicated on pushing more disk capacity out the door year after year, which is why customers we spoke to would have preferred to see such a disruptive technology remain in the hands of an independent vendor," Urbanski writes in a blog. "By acquiring Data Domain, EMC controls the pace of innovation, possibly pushing out the time when Data Domain's technology becomes applicable to ever broader classes of workloads."

EMC has sometimes maintained acquired companies as separate product lines or business units, for example VMware, Reichman notes. It's too early to tell how far EMC will go in integrating Data Domain into its own product line, he says.

"That's the question," he says. "Do they leave it alone? Or will they take the software technology and merge it into their core offerings? Initially they will definitely want to leave it separate. You could argue they will get more benefit if it's more tightly integrated into their own products."