NewsScan Daily, 2 October 2003 ("Above The Fold")

"NewsScan" <[email protected]> Thu, 02 Oct 2003 09:28:34 -0700
Newsgroups gmane.culture.it.newsscan
Message-ID <[email protected]>
NewsScan Daily, 2 October 2003 ("Above The Fold")
***********************************************************
NewsScan Daily is underwritten by RLG, a world-class organization
making significant and sustained contributions to the effective
management and appropriate use of information technology. NSD is
written by John Gehl and Suzanne Douglas, [email protected].
***********************************************************

"ABOVE THE FOLD"
        Microsoft $10.5 Million Consumer Settlement
        Genes on a Chip
        Idealab Not Out of Ideas and Not Out of Hope
        New Viruses Use 'Blended Threats' to Wreak Damage
        Overlooked Security Risk: The Telephone
        RIAA Calls on P2P to Police Networks

FEATURES
        Flash Card
        Honorary Subscriber: Charles William Eliot
        Safe & Sound in the Cyber Age

MICROSOFT $10.5 MILLION CONSUMER SETTLEMENT
Microsoft has agreed to pay $10.5 million to consumers who complained in a 
class-action lawsuit that they were overcharged when they bought software 
directly from the company. About 550,000 licenses are represented in the 
class. Rob Helm, an industry analyst and Microsoft-watcher, says: "It's 
certainly not going to put a dent in Microsoft's pockets. This is clearly a 
victory, in the sense that Microsoft wants to settle these cases. From a 
Microsoft perspective, the bad PR outweighs any benefit it would gain by 
fighting this to the bitter end." (AP/2 Oct 2003)
http://www.siliconvalley.com/mld/siliconvalley/6901041.htm

GENES ON A CHIP
Affymetrix, Agilent, Applied Biosystems, and NimbleGen are some of the 
companies that have begun selling postage-size gene-chips, or 
"microarrays," of all known human genes (of which there are about 30,000), 
thereby lowering the cost and increase the speed of a test that has 
transformed biomedical research in recent years. The chief executive of 
Affymetrix boasts: "It's sort of a milestone event, very similar to 
generating an integrated circuit of the genome." Gene chips detect genes 
that are actively being used to make a protein, and scientists try to 
understand the genetic mechanisms of disease by seeing which genes are 
turned on. Researchers have found that tumors that look the same under the 
microscope can differ in terms of which genes are active, and that by 
studying gene patterns it may be possible to discriminate between deadly 
and harmless tumors -- or to predict the effectiveness of a particular drug 
on a particular patient. (New York Times
2 Oct 2003)
http://partners.nytimes.com/2003/10/02/technology/02GENE.html

IDEALAB NOT OUT OF IDEAS AND NOT OUT OF HOPE
Idealab, founded in 1996 as an Internet technology incubator by high-tech 
visionary Bill Gross is now being sued by key investors who claim they have 
not received any of the company's profits. The plaintiffs include Dell's 
venture capital arm and mutual fund company T. Rowe Price. Gross says the 
allegations in the case are completely untrue, and that company is busy 
developing new ideas. But the analysts such as venture capitalist Howard 
Anderson of YankeeTech think the incubator business is a thing of the past: 
"It's not surprising Gross hit the wall. Idealab was an idea that was right 
in 1999, but time has passed it by." Still, in spite of the lawsuit and in 
spite of the general decline of the incubator business, the optimistic Bill 
Gross continues to talk the talk: "We want to build companies that change 
the world. We know to build that kind of company, and we're doing it 
again." (USA Today 2 Oct 2003)
http://www.usatoday.com/tech/techinvestor/2003-10-01-idealab_x.htm

NEW VIRUSES USE 'BLENDED THREATS' TO WREAK DAMAGE
Computer viruses are increasing in frequency, speed and sophistication, 
according to the latest Internet Security Threat Report from Symantec, 
adding that hackers are using "blended threats" that combine various types 
of viruses to carry out their attacks. Not surprisingly, the target of most 
of these attacks is Microsoft software, says Tony Vincent, Symantec's lead 
global security architect. "There's a continued focus by the bad guys on 
vulnerabilities based on Microsoft's Web server product and Internet 
Explorer." The report also cites a narrowing gap between the discovery of a 
potential vulnerability and the launch of a virus designed to exploit it. 
"The speed of propagation of blended threats is also increasing. Symantec 
expects to see greater worm propagation resulting in overloads to network 
hardware, crippling network traffic, and seriously preventing both 
individuals and businesses from using the Internet." (Reuters 1 Oct 2003)
http://story.news.yahoo.com/news?tmpl=story&cid=581&ncid=581&e=6&u=/nm/20031001/tc_nm/tech_symantec_report_dc

OVERLOOKED SECURITY RISK: THE TELEPHONE
As corporate phone systems become increasingly complex and computerized, 
criminals are finding new ways to infiltrate company networks, and the 
problem becomes magnified as businesses turn to IP-based phone systems. 
"This is the first time that a computer virus can stop your telephones from 
working," says PricewaterhouseCoopers senior manager Mark Lobel. "There is 
a whole new class of attacks that can occur. The essence of the problem is 
that everyone is looking at this as a new technology for voice -- the way 
we're sending voice communications is absolutely new. But the data is still 
riding on the same infrastructure that was pounded by recent problems like 
SoBig." To counteract the threats, phone system administrators need to be 
much more vigilant about password management and may even consider locking 
out certain country codes. "In fact, you should probably consider the risk 
associated with VoIP systems to be as high as the threats to your 
organization's most sensitive data. If someone in your IT department gets 
paged when your firewall goes down, they should also be paged when 40 new 
voicemail boxes mysteriously appear on your IP system," says Lobel. 
(E-Commerce Times 2 Oct 2003)
http://www.ecommercetimes.com/perl/story/31731.html

RIAA CALLS ON P2P TO POLICE NETWORKS
Recording Industry Association of America (RIAA) chairman and CEO Mitch 
Bainwol suggested at a Senate hearing on Tuesday that Kazaa and other 
peer-to-peer file-sharing software vendors could institute three reforms 
that would discourage users from illegal activities: change the default 
settings so users aren't unwittingly sharing private documents; incorporate 
"meaningful" warnings about trading copyrighted content; and filter 
unauthorized copyrighted works off the P2P networks. "The file-sharing 
business must become responsible corporate citizensÂ… moving beyond excuses. 
If the Kazaas of the world can institute three common-sense reforms, 
lawsuits can be avoided, the record industry will be healthier, there will 
be more jobs, consumers will get the music they want." Kazaa responded that 
it's already instituted the first two recommendations but that the third 
would be technically impossible. "If you're going to block the titles of 
every song, every word in every copyright song, every copyright movie, and 
every copyright book, you might as well input the whole dictionary," said 
Philip Corwin, attorney for Kazaa parent Sharman Networks. Meanwhile, 
rapper LL Cool J said though royalties generated through legitimate online 
music downloads were small, they were better than nothing. "Some of the 
artists may only get a nickel out of the 99 cents [charged per song]. Can 
we at least get that? Is it alright for us to make a living as Americans?" 
(IDG News Service/InfoWorld 1 Oct 2003)
http://www.infoworld.com/article/03/10/01/HNriaafilter_1.html

*****

FLASH CARD
      "We haven't failed. We now know a thousand things that won't work, so 
we are much closer to finding what will." (Thomas Edison)

HONORARY SUBSCRIBER: CHARLES WILLIAM ELIOT
      Today's Honorary Subscriber is the long-serving president of Harvard 
University, Charles William Eliot, who was named president in 1869 and held 
office for the next 40 years until his retirement in 1909. He was an 
educational innovator who instituted major changes at Harvard, elevating 
the university into an institution of world renown.
      Eliot was himself an 1853 Harvard graduate who had joined the 
university's faculty in 1858, working in the department of mathematics and 
chemistry. In 1869, when the university trustees were searching for a new 
president, his name came to their attention as the author of an Atlantic 
Monthly article reporting Eliot's first-hand observations of European 
educational systems, based on information he had gathered personally during 
an overseas trip the previous 18 months.
      Eliot was born in Boston, Massachusetts, the son of Samuel Atkins 
Eliot who in his lifetime was Boston's mayor, a U. S. congressman, and 
Harvard's treasurer. Besides his relative youthfulness, Eliot's election as 
Harvard's president was remarkable because he was not a clergyman and was a 
scientist, not a humanities major. As a reformer, Eliot began almost 
immediately to restore electives to a curriculum that had become rigid with 
prescribed courses. He also insisted on a place for the sciences alongside 
the humanities to broaden and invigorate Harvard's liberal arts program. 
His influence reached into secondary education when Harvard raised its 
entrance requirements, and other major colleges followed suit. He also 
influenced secondary schools to introduce foreign languages and mathematics 
into their programs.
      As editor of the Harvard Classics, famous as the "five-foot shelf of 
books," he helped elevate the literary sophistication of the nation at 
large. During his presidency Harvard developed from a small college with 
attached professional schools into a great modern university. Faculty size 
was increased and the student body grew. Professional schools were added, 
as well as Radcliffe College for women, and the standards in the law and 
medical schools were improved.
      After Eliot's resignation in 1909 he turned to public affairs. He had 
been a strong advocate of civil service reform for many years and was a 
member of the General Education Board and a trustee of the Carnegie 
Foundation for the Advancement of Teaching. Among his published works are 
"The Durable Satisfactions of Life" (1910), which presents his religious 
and ethical views, and "The Conflict between Individualism and Collectivism 
in a Democracy" (1910). In 1901 he wrote a biography of his son Charles 
Eliot (1859-97), a landscape architect, who designed the Greater Boston 
park system.

See 
http://www.amazon.com/exec/obidos/tg/detail/-/0404035450/newsscancom/ref=nosim 
for a biography of Eliot -- or look for it in your favorite library. (We 
donate all revenue from our book recommendations to adult literacy programs.)

SAFE & SOUND IN THE CYBER AGE
      In their computer security column for this issue of NewsScan Daily, 
Stephen Cobb and Chey Cobb write about: "As The Potato Turns":
      When a report highlighting the security problems created by 
over-reliance on a single source for software was published last week, it 
came as no surprise to regular NewsScan readers, who were, once again, 
ahead of the curve. That's because the very same problem was highlighted in 
NewsScan back in August. Back then we wrote, in a column titled "Of 
Potatoes and Worms," the following:
      "Reliance by an information system on one application or operating 
system, to the exclusion of others, reduces the ability of that system to 
survive a vulnerability in that operating system or application."
      This is the problem of monoculture, which can threaten different 
types of systems, not just information systems. The potatoes in our title 
were an allusion to potato famine in Ireland in the nineteenth century, 
when over-reliance on a single strain of potato had devastating 
consequences. The worms in the title alluded to the outbreak of worms such 
as Blaster, Welchia, SoBig. The security firm Symantec estimates that this 
summer's crop of worms may have caused up to $2 billion in damages over 
just eight days in August. The London-based computer security company, mi2g 
Ltd., projects global economic damages from malicious software to be in 
excess of $100 billion this year (the company estimates the total due to 
SoBig alone to be nearly $30 billion).
      The monoculture problem exists at different levels. In our column we 
contrasted an organization using nothing but Microsoft products with one 
that uses applications and operating systems from a mix of vendors. We 
pointed out that the Microsoft-only shop is more likely to have experienced 
widespread negative effects due to Blaster and SoBig. The emphasis in last 
week's CyberInsecurity Report was on the risks that monoculture poses to 
the global information infrastructure. The subtitle spelled out where the 
authors see the current monoculture threat: "The Cost of Monopoly: How the 
Dominance of Microsoft's Products Poses a Risk to Security."
      Reports written by security professionals rarely make the news, but 
this one did. Unfortunately, the media attention was prompted less by what 
the report said than by the fact that one of its authors, Dan Geer, was 
summarily dismissed by his employer, AtStake, within moments of the report 
being published. Seldom has an event rocked the staid world of us security 
geeks like this one. Not only was the person fired a widely respected 
security veteran, the company that fired him had -- and the past tense may 
now be doubly apt -- a reputation for iconoclasm. Here's what Network World 
said about AtStake, back in February, 2000:
      "Security start-up @Stake has caused quite a sensation since its 
recent launch as a professional services firm employing members of the 
hacker nether world as hired guns sent out to test corporate networks for 
vulnerabilities... These employees include Mudge -- the leader of the 
underground group L0pht -- and even more amazingly, Dildog, top dog in the 
notorious Cult of the Dead Cow (CDC)."
      You may recall that the CDC created BackOrifice, a piece of software 
widely used to gain unauthorized access to computers running Microsoft 
Windows. While some of those associated with BackOrifice claimed it was not 
a hacking tool, that was hardly the impression you got from its highly 
theatrical launch to a packed house at the DefCon hackers convention in the 
summer of 1998.
      We don't mean to impugn the character of anyone who works for 
AtStake, or anyone associated with the L0pht or CDC, both of which have 
provided the world with some very useful code. The point is that AtStake 
was, for a lot of security folks, the last place from which you'd expect 
someone to get fired for criticizing Microsoft. Besides, the monoculture 
problem is not specific to Microsoft. As Geer has stated, a networked world 
dominated by Linux would also be bad. After all, and this is what makes 
Geer's firing so hard to fathom, this is well-established security theory. 
Stephen referred to Microsoft in the context of monoculture in the second 
edition of his PC & LAN security book:
      "The spread of dominant, cross-platform software, such as Microsoft 
Word, creates fertile territory for new viruses strains, much as 
over-reliance on one species led to the Irish potato famine."
      That was in the summer of 1995, when the first Word macro virus 
appeared. Yet, as we noted in our column in August, the federal 
government's increasing reliance on Adobe Acrobat today could just as 
easily become problematic. Perhaps it was unfortunate that the 
CyberInsecurity Report was published by an organization funded by companies 
that have lost market share to Microsoft. But the risks that the authors 
highlight, those inherent in a monoculture, won't just go away. They need 
to be addressed and the sooner the better. We hate to think it took the 
trauma of one person's unexpected unemployment to alert the world to this 
issue. On the other hand, it is hard to imagine someone of Dan's caliber 
being between jobs for very long.
      [Chey Cobb, CISSP, the author of Network Security for Dummies, is an 
independent consultant(www.cheycobb.com) and a former senior technical 
security advisor to the NRO. She can be emailed as chey at patriot dot net. 
Stephen Cobb, CISSP, developed his first computer auditing program over 
twenty years ago. He can be emailed as scobb at eprivacygroup dot com.]

SUBSCRIPTION INFO FOR NEWSSCAN DAILY:
      To subscribe or unsubscribe to the text, html, or handheld versions 
of NewsScan Daily, send the appropriate subscribe or unsubscribe messages 
(i.e., with the word 'subscribe' or 'unsubscribe' in the subject line) to 
the addresses shown below:
      Text version: Send message to [email protected]
      HTML version: Send mail to [email protected]
      NewsScan-To-Go: http://www.newsscan.com/handheld/current.html

TELL YOUR FRIENDS ABOUT NEWSSCAN DAILY! Send them our little frog: 
http://www.newsscan.com/newsscan/newscup.html

***********************************************************
Please visit the site of RLG, the great organization that makes NewsScan 
Daily possible. (RLG has no influence over, nor any responsibility for, our 
editorial content.) Created in 1974 as the Research Libraries Group, RLG is 
a not-for-profit membership corporation of more than 160 universities, 
national libraries, archives, museums -- and other institutions with 
remarkable collections for research and learning. Its major initiatives are 
long-term retention of digital materials, resource sharing among member 
institutions, and improvement of researcher access to primary source 
material. RLG supplies online research resources worldwide. Visit RLG at 
http://www.rlg.org.

*********

To subscribe or unsubscribe to the TEXT version of NewsScan Daily, send an 
e-mail message to [email protected] with 'subscribe' or 'unsubscribe' 
in the subject line. To subscribe to our HTML version of NewsScan Daily, 
send mail to [email protected], with the word 'subscribe' as the 
subject. (Subscribing to the HTML version won't automatically unsubscribe 
you from the text version; please unsubscribe yourself as explained above.) 
Please note: To unsubscribe from an account to which you no longer have 
access, send mail to at [email protected].

*********

We call our news section "Above The Fold" to honor the tradition of the 
great "broadsheet" newspapers in which editors must decide which news 
stories are of such importance that they should be placed "above the fold" 
on the front page. The NewsScan Credo: Be informative, have fun, and get to 
the point! See http://www.newsscan.com/, and send us mail: John Gehl 
<[email protected]> and Suzanne Douglas <[email protected]>, or call 
770-704-7517.

*********

Get a free 6-week trial subscription to Innovation Weekly, an executive 
summary of trends, strategies and innovations in business and technology. 
Send mail to [email protected] with the word 'subscribe' in the 
subject line.

What customized news and information services do you need for your company? 
Get in touch with us at [email protected] or call 770-704-7517 to talk 
over the possibilities.

Copyright 2003. NewsScan Daily (R) is a publication of NewsScan Inc.
***********************************************************