Wednesday, April 15, 2009

Bottle Domains dumped by auDA over security breach


The Australian domain name administrator has ruled out a review of its registrar agreements in the wake of its decision to terminate Bottle Domains accreditation today over a security breach.

auDA took the action after it emerged Bottle may have hidden the hacking of its database for almost two years.

A spokesperson for Bottle was "not available" for comment.

The termination has left Bottle resellers such as Melbourne-based Cove "between a rock and a hard place" - with Cove, Bottle's largest reseller, now making a play to become a registrar in its own right.

Bottle, which counts some 11,000 registrants as customers, is the subject of an ongoing investigation by the Australian Federal Police after it was revealed in February that usernames and passwords had been compromised in a ‘security breach'.

It has now emerged, however, that the February ‘breach' may not have been the first.

In a statement today, auDA said it "has since discovered that Bottle Domains was the subject of an earlier security incident in April 2007, which auDA believes may have caused or contributed to the security incident in February 2009."

iTnews understands that the hack reported in February this year may actually have taken place back in April 2007 - some two years earlier than first thought.

This could mean data over the range of 2007 to 2009 may have been compromised, although the extent of the breach is still under police investigation.

auDA said in a statement that Bottle's failure to notify it at the time of the April 2007 security incident breached its obligations under the Registrar Agreement.

"Information recently provided to auDA by Bottle Domains about the April 2007 incident revealed that it did not reset customer passwords or alert its customers to the possibility that their account information had been accessed by third parties," auDA said.

"Bottle Domains also failed to conduct an independent security audit to verify that the security vulnerability had been fixed, and that there was no other unauthorised access to its systems."

aUDA chief Chris Disspain told iTnews that although the definitions for what does and doesn't constitute a security breach under current guidelines "is a matter for discussion", he expected all Australian registrars "to err on the side of caution".

He did not believe the Bottle case warranted a review or tightening of the agreement.

"You can argue that tighter rules are more dangerous because it's easier to argue a breach that doesn't fit into a tighter ‘box' of rules," Disspain said.

Disspain also said he had ‘absolutely no idea' whether Bottle would turn to legal action over the decision.

"They're entitled to take whatever action they deem appropriate," he said.

"We're very comfortable the action we've taken is appropriate. We believe we simply didn't have a choice."

Bottle resellers are now faced with a choice of forming a relationship with another registrar or - depending on their size and lobbying power - becoming a registrar in their own right.

Cove's national sales manager, Cheyne Jonstone, told iTnews that since news of the termination leaked out of auDA, Cove had been approached "by just about every [other] registrar in Australia".

But few offers had been able to offer flexibility in the API and pricing that Cove had received from Bottle.

"Our entire system has been built around Bottle's," Jonstone said.

"The problem for us is that no other registrar offers the comprehensiveness in their API as Bottle did."

Jonstone revealed that Cove is in the process of making an approach to auDA to reopen its registration process - which has been offline for approximately 18 months - to admit Cove as a registrar in its own right.

"We've been trying since March last year," he revealed.

"We have 3000 dot AU domains with Bottle now. We're large enough to be accredited anyway and for us that would be ideal because our system is already built to interact with auDA."

He said the phones "had been ringing off the hook" with domain owners seeking next steps. All customers had been notified of auDA's decision by email.

auDA has released its own set of guidelines [PDF] for both customers and resellers. While Disspain said there was no risk for either customers or resellers, he urged the latter to contact him directly to resolve any potential issues.

Skype to spin off in early 2010 IPO


Skype parent company eBay plans to spin off consumer voice-over-IP company Skype in an initial public offering in 2010.

Skype, which boasts over 400 million users, US$551 million in annual revenues and a claim to being the world's largest long distance communications carrier, has been an uneasy fit with parent company, auction house eBay.

eBay purchased Skype for close to US$4 billion in September 2005.

eBay representatives today said Skype will be spun off to standalone on the stockmarket at some stage in early 2010 - pending market conditions.

"Skype is a great stand-alone business with strong fundamentals and accelerating momentum," said eBay president and CEO, John Donahoe.

"But it's clear that Skype has limited synergies with eBay and PayPal. We believe operating Skype as a stand-alone publicly traded company is the best path for maximising its potential.

"This will give Skype the focus and resources required to continue its growth and effectively compete in online voice and video communications."

Donahue has been reviewing eBay's investment in Skype since his appointment as eBay CEO in April 2008.

Donahue installed a new management team at the VoIP company, led by CEO Josh Silverman - with whom the eBay CEO credits as the driver for much of Skype's growth.

Earlier this week it was revealed that Skype's founders were in discussions with private equity firms to make their own bid for the company.

eBay also revealed that two million people have downloaded the Skype for iPhone application within a week of it being made available -making it the number one free download for the iPhone in 40 (national) markets at the time.

The company claims this saw half a million new users register for the Skype service.

More giants buckle in CSIRO Wi-Fi patent case


Microsoft and Asus have settled with Australia's CSIRO over its claim to Wi-Fi patents, following similar moves by HP and Fujitsu to bail out of a continuing court battle contesting CSIRO's claims.

The Commonwealth Scientific and Industrial Research Organisation (CSIRO), currently fighting a patent case against over a dozen technology companies in the US District Court in Texas, is slowly managing to solicit royalties out of some of the world's biggest technology companies via out-of-court settlements.

CSIRO spokesperson Huw Morgan has confirmed CSIRO settled with software giant Microsoft and PC manufacturer Asus early this week, after settling with Fujitsu last week and HP the week prior.

CSIRO claims to have patented core elements of the technology used in 802.11a and 802.11g wireless devices.

Its US patent for Wireless LAN technology (US Patent 5487069) was granted in January 1996 and has since been appealed by several of the world's largest technology companies.

There are still nine technology companies battling CSIRO in the Texas court.

Morgan said CSIRO will not make any comment on the research organisation's prospects until the case concludes.

Monday, April 13, 2009

Business intelligence, business smart?


Pratima Harigunani of CyberMedia News checks it out with Dr. Mukund Deshpande, head - BI and Analytics Practice, Persistent Systems who has spent eight years of action in BI that also covers heuristic driven algorithms, classification and prediction algorithms after PhD in Computer Science from the University of Minnesota, Minneapolis, USA with a thesis on 'Data Mining Techniques for Sequences and Graphs'. He talks on a range of issues flanking BI today.

When it comes to day-to-day business, what role does or can BI play? How much information derived in BI is indeed actionable?

BI is important because the company wants to know about the customer, wants to analyse the competition, wants to study customer churn properly for corrective action, specially in context to today's scenario and the crowded marketplace wherein competition has become more fierce.

Churn identification, for instance, helps at the decision-making level directly for customer or campaign management. It's done by churning out reports, dashboards, predictive analysis etc from data warehouses.

How best can BI be applied to broader issues like national security?

Security is a hard management problem. It's all about how best to identify and focus on the priority areas. It's all about expanding relationships. Information in security incidents is mostly divided and scattered, but it's there. You have to find how best to link them.

The inference part is where the human comes in. But linking and tracing information is where technology can play a role. Today terror attacks are planned and managed often on Internet. What can be done better is that in reflection, one can connect the dots and we can have a frame of reference.

If we take a frank look at BI's evolution so far, how successfully has the reactive to proactive gap been covered?

Yes, EPA (Enterprise Performance Management) is where we are doing proactive work. Unlike the earlier report-generating work and focus on time-cutting, there is need for proactive work. A lot of BI is still reactive but EPM is a new breed. BI is trying to look at decisions the other way round with stuff like 'what-if' questions and scenario-based analysis.

What's the connection status, between BI and higher realms like human intelligence, artificial intelligence, robotics, cybernetics etc?

These are advanced analytics areas whereas BI is an analytics area focusing specifically on data and business problems. Its focus is mainly on decision-making.

With new scenarios like clouds and grids redefining computing and data, how does BI realign itself?

BI may go to cloud or Grid if privacy and security are taken care of. That's a challenge. But for that big leap in mindset is required. More so on areas like support and control. Guys like Google and Amazon can afford the infrastructure to do it.

What's your take on future trends and the status of BI in India?

As we move ahead, BI would graduate to real-time BI. The quicker, the better. DWA (Data Warehousing Applications) is another area that helps in how to deal in hardware to solve big data problems.

Apart from that, open source BI would be something to watch out for. The way open source has made inroads in areas of OS, Internet browser etc with Linux or Firefox, we have to see what happens in BI space.

Talking of India, the problem here is that unlike in the West, there is no unique identifier for data like the SSN in the US. I heard it's about to come in India too, and if that happens, it will take away the identification problem for BI. Not all data is captured here. Industry is still tactical in its approach towards BI.

What has been Persistent's ground of action so far in BI?

It's been traditionally an area of database. We have focused on building tools. Our work happens around BI tool vendors, and product development for some major DB and DWH vendors, which is the OPD flavour. We also build lots of applications and tools. The spectrum so far covers product engineering for leading ETL vendors where we have data cleaning, de-duping.

We also cover predictive analysis consulting area with churn analysis, targeted advertising, risk-modeling and cross-selling as some constituents. Apart from this, we have various domain-specific practices in industries like telecom, retail etc for reporting, dashboards.

Industry says cheers to Tech Mahindra, Satyam bid