显示标签为“service”的博文。显示所有博文
显示标签为“service”的博文。显示所有博文

2011年5月6日星期五

Bits: Password Service Warns of Possible Hacking Attack

 

5:28 p.m. | Updated Adding more background and information from interview with the company’s chief executive.


LastPass, a service for managing passwords, said late Wednesday that out of concern about a possible hacking attack, it would force its more than 1 million users to change their master passwords, which they use to retrieve passwords for other sites across the Web.


The news comes in the wake of several recent high-profile hacks of computer-security companies, including another maker of technology designed to make access to Web sites more secure, RSA Security.


In a blog post, LastPass, which offers free and paid products, said that last Tuesday it had detected two “traffic anomalies,” including one leaving the company’s database, and could not explain the causes. That sparked fears that intruders may have made off with user information.


“We’re going to be paranoid and assume the worst,” LastPass said. It said its analysis so far suggests hackers could have acquired users’ e-mail addresses and might be able to decipher their master passwords using “brute force” methods, if those passwords are simple enough.


In addition to requiring its users to set new master passwords, LastPass said it would confirm that users of its system are legitimate by matching the numerical Internet Protocol addresses tied to their computers with IP addresses used by them in the past, or by validating them through e-mail.


The password information stored by LastPass clearly makes it a tempting target for hackers.


“The data that they store, it’s the keys to the kingdom” for many consumers and company employees using LastPass to store passwords for bank accounts and sensitive corporate systems, said Jeremy Conway, a senior threat researcher at NitroSecurity, who was formerly part of the team defending NASA’s network. “It’s a high-value target.”


But security professionals praised LastPass’s swift disclosure and action to protect users as a model of how to handle a security problem. Security experts have been relentless in their criticism of other companies that have suffered hacks recently and were slow to report them or provided few details.


Two security firms, RSA, whose SecurID technology was raided by hackers, and Comodo, whose system for certifying Web site authenticity was hit, have come under particular criticism for security fumbles and slow or incomplete disclosure.


However, some, including Mr. Conway, questioned the adequacy of LastPass’s internal security, noting that the company’s description of the incident suggested it was not using available technology that would provide more visibility into activities on its network and are necessary to understanding the true extent of a data breach.


“They don’t know what data was accessed. Why not?” Mr. Conway said. “It shows that they are immature in their security practices. They have issues they need to address.”


Joe Siegrist, LastPass’s chief executive, said that the growing popularity of the company’s service has made it more attractive to attackers, and that it would look for ways to make itself harder to hit. For one, he said he would hire a security firm to audit its systems.


LastPass’s rapid action also sparked problems for some users. The company was triggering password resets by asking users to enter the e-mail address associated with their account when they entered in their master password, and then sending an e-mail with a link to a site where they would enter a new master password. In a Catch-22, many users found they were unable to get the e-mail because, without a working master password, they were locked out of their e-mail accounts. Others ran into different roadblocks trying to reset their master passwords.


“Was this mandatory panic thoroughly thought about before being initiated?” asked one anonymous “paying customer” who commented on LastPass’s blog post. “It will take a lot for Lastpass to restore trust in the system, because I am out as soon as this fiasco is over.”


LastPass conceded that its systems were overwhelmed by the task of resetting so many passwords and responding to customers running into difficulties. In response, it slowed things down by forcing immediate resets only on users visiting its service from unfamiliar IP addresses. And it encouraged other users to wait to reset their master passwords until LastPass prompted them to do so.


With the extent of the potential breach unknown, experts said extra-cautious users may also want to change their passwords, especially for sensitive accounts, stored with LastPass.


View the original article here

Bits: Password Service Warns of Possible Hacking Attack

 

5:28 p.m. | Updated Adding more background and information from interview with the company’s chief executive.


LastPass, a service for managing passwords, said late Wednesday that out of concern about a possible hacking attack, it would force its more than 1 million users to change their master passwords, which they use to retrieve passwords for other sites across the Web.


The news comes in the wake of several recent high-profile hacks of computer-security companies, including another maker of technology designed to make access to Web sites more secure, RSA Security.


In a blog post, LastPass, which offers free and paid products, said that last Tuesday it had detected two “traffic anomalies,” including one leaving the company’s database, and could not explain the causes. That sparked fears that intruders may have made off with user information.


“We’re going to be paranoid and assume the worst,” LastPass said. It said its analysis so far suggests hackers could have acquired users’ e-mail addresses and might be able to decipher their master passwords using “brute force” methods, if those passwords are simple enough.


In addition to requiring its users to set new master passwords, LastPass said it would confirm that users of its system are legitimate by matching the numerical Internet Protocol addresses tied to their computers with IP addresses used by them in the past, or by validating them through e-mail.


The password information stored by LastPass clearly makes it a tempting target for hackers.


“The data that they store, it’s the keys to the kingdom” for many consumers and company employees using LastPass to store passwords for bank accounts and sensitive corporate systems, said Jeremy Conway, a senior threat researcher at NitroSecurity, who was formerly part of the team defending NASA’s network. “It’s a high-value target.”


But security professionals praised LastPass’s swift disclosure and action to protect users as a model of how to handle a security problem. Security experts have been relentless in their criticism of other companies that have suffered hacks recently and were slow to report them or provided few details.


Two security firms, RSA, whose SecurID technology was raided by hackers, and Comodo, whose system for certifying Web site authenticity was hit, have come under particular criticism for security fumbles and slow or incomplete disclosure.


However, some, including Mr. Conway, questioned the adequacy of LastPass’s internal security, noting that the company’s description of the incident suggested it was not using available technology that would provide more visibility into activities on its network and are necessary to understanding the true extent of a data breach.


“They don’t know what data was accessed. Why not?” Mr. Conway said. “It shows that they are immature in their security practices. They have issues they need to address.”


Joe Siegrist, LastPass’s chief executive, said that the growing popularity of the company’s service has made it more attractive to attackers, and that it would look for ways to make itself harder to hit. For one, he said he would hire a security firm to audit its systems.


LastPass’s rapid action also sparked problems for some users. The company was triggering password resets by asking users to enter the e-mail address associated with their account when they entered in their master password, and then sending an e-mail with a link to a site where they would enter a new master password. In a Catch-22, many users found they were unable to get the e-mail because, without a working master password, they were locked out of their e-mail accounts. Others ran into different roadblocks trying to reset their master passwords.


“Was this mandatory panic thoroughly thought about before being initiated?” asked one anonymous “paying customer” who commented on LastPass’s blog post. “It will take a lot for Lastpass to restore trust in the system, because I am out as soon as this fiasco is over.”


LastPass conceded that its systems were overwhelmed by the task of resetting so many passwords and responding to customers running into difficulties. In response, it slowed things down by forcing immediate resets only on users visiting its service from unfamiliar IP addresses. And it encouraged other users to wait to reset their master passwords until LastPass prompted them to do so.


With the extent of the potential breach unknown, experts said extra-cautious users may also want to change their passwords, especially for sensitive accounts, stored with LastPass.


View the original article here

2011年5月5日星期四

Pandora Internet Radio Service to Offer Large Archive of Comedy Clips

On Wednesday Pandora will add 10,000 clips by more than 700 comedians to its archive, and allow users to sort through them in the same way they do the site’s music: by picking a starting place — a comedian, type of comedy or even a specific joke — and then letting Pandora send a stream of similar material chosen by analyzing his or her taste.


“This is a logical step under the umbrella of personalized radio,” said Tim Westergren, the founder and chief strategy officer of Pandora Media, the company behind the service.


The comedy offerings stretch back to the days of Will Rogers and W. C. Fields, and include most of the greats, past and present: Bill Cosby, George Carlin, Bob Newhart, Jerry Seinfeld, Richard Pryor, Eddie Murphy, Joan Rivers, and Cheech & Chong. For more specialized tastes, there are routines by Triumph the Insult Comic Dog, Minnie Pearl and Yakov Smirnoff.


As with music, Pandora has developed a system to predict what its listeners will like. With the help of professional comedians, the company identified more than 100 traits common in jokes, from basic themes (ethnicity, family) and styles of delivery (dry, self-deprecating) to broader categorizations of how comedians toy with logic and language (spoonerisms, juxtaposition, misdirection).


Put together, these traits make a “genomic” composite of a joke or routine, and can be strung together to follow unexpected themes. For example, a listener who begins with Chris Rock may end up listening to Bill Hicks because of his similar “male perspectives, subject explorations, sarcastic delivery and slow delivery,” as the service explains.


For Pandora, comedy is one piece in a broad expansion that has made the company one of the biggest players in digital music. For most of its history it struggled to stay alive and raise money, but now, largely thanks to its popularity on smartphones, it has 82 million registered users and is preparing to raise $100 million in an initial public offering.


The company is still reporting losses, but they are getting smaller. According to Securities and Exchange Commission filings, Pandora Media lost $1.7 million for the year that ended Jan. 31, compared with $16.8 million the year before; advertising revenue, its main source of income, was $119.3 million in fiscal 2011, compared with $50.1 million in 2010.


Comedians and their record companies are hoping that Pandora will be a boon. Comedy videos may be hugely popular online, but aside from the occasional hit — like Dane Cook’s “Retaliation,” for example, which has sold 1.4 million copies, according to Nielsen SoundScan — most comedy albums have minuscule sales. The most popular current comedy album is Mike Birbiglia’s “Sleepwalk With Me Live,” whose 3,400 sales were not enough for it to make Billboard’s standard Top 200 album chart.


“One of our biggest challenges is that of discovery,” said Jack Vaughn, vice president of Mr. Birbiglia’s label, Comedy Central Records. “How do we get people who like a certain comic to find out about another comic they might like? This seems like the next phase of what the Internet can do for comedy.”


Each comedy track on Pandora is about three to six minutes, with some made up of multiple bits by the same artist. As with music, the comedy service is offered in a free version supported by advertising, and paid, ad-free version. For its introduction, the free comedy streams will be supported by two Unilever brands with a penchant for comedic advertising: Klondike bars and Axe male grooming products.


Axe favors a bawdy, locker-room style of humor, said Rob Candelino, the brand’s marketing director. Since Pandora’s user registration includes demographic information like age and sex, Axe will show its 15-second ad spots only to men aged 18 to 24.


“We thought it was a sensational opportunity to reach our guy,” Mr. Candelino said.


Since it entered the market in 2005, Pandora has collected a mountain of data to help it parse what music people like and why. But some of the people involved in the comedy service are just waiting to see exactly how Pandora’s comedic algorithms will work.


“It’ll be interesting when I find out who I’m paired up with,” said the comedian Adam Carolla, whose material will be included in the service. “I’m sure at some point someone will be insulted. There may be a lot of unintended comedy.”


 

2011年5月2日星期一

Eyeing the White House After Service in China

Blindsided, Pentagon officials considered whether the best response would be to pack up and leave before the mission had even begun. The American ambassador, Jon M. Huntsman Jr., advised forcefully against it. Too much was at stake, he said. Better to make clear Mr. Gates’s displeasure, then move on to more serious business.


Which is what Mr. Gates did, raising the issue with President Hu Jintao and relaying Mr. Hu’s embarrassed response to reporters shortly afterward.


“Jon came in and gave sensible advice,” said a person who was privy to the discussion and spoke on the condition of anonymity because the debate had been both private and official. “It was classic and proper handling of a difficult situation with the Chinese.”


It was also classic Huntsman. The ambassador, who was to leave his post on Saturday, has proved deft with the carrot and stick, mixing measured criticism of China’s government with a relentless effort to cement its fractious relations with the United States. It has not always worked: in recent months, as China’s growing crackdown on domestic dissidents drew Mr. Huntsman’s pointed objections, the efforts of the ambassador and other American diplomats have been angrily rejected by Beijing.


When President Obama selected Mr. Huntsman, then the popular Republican governor of Utah, as ambassador in 2009, pundits speculated that the president was working to edge him out of the race for the 2012 Republican nomination. Mr. Huntsman has implied otherwise in speeches, expressing respect for Mr. Obama’s skills and saying that they share a common cause in improving relations.


Now that Mr. Huntsman is publicly pondering a run for the nomination anyway — an unstated but clear reason behind his departure — the question may not be whether his China stint hurt his chances, but whether it improved them. Clearly, he did not achieve the goals he set. In a valedictory speech last month in Shanghai, he put his frustrations with China’s prickly and suspicious diplomacy on full display.


“Turning the relationship on and off in reaction to unwelcome events is inconsistent with the objective of a positive, cooperative and comprehensive relationship that our leaders have set out to achieve,” Mr. Huntsman said. “Canceling meetings as a sign of displeasure will not encourage greater respect for each other’s views.”


“We cannot move forward if, when differences emerge, only one of us is fully committed and fully engaged,” he said.


Getting China fully engaged — and persuading it to temper the suspicion and resentment that has marked even warm periods in its relationship with the United States — is the Obama administration’s strategic goal and, by all accounts, Mr. Huntsman’s passion. If that goal is, by many assessments, only slightly less distant than it was two years ago by, his pursuit of it wins wide praise.


“The course of a major relationship such as that between the United States and China is not going to be guided solely by the skill or lack thereof of an ambassador, but what an ambassador can do is make a meaningful difference,” J. Stapleton Roy, a China-born diplomat who served President Ronald Reagan and the first President George Bush and was President Bill Clinton’s first ambassador to China, said. “If Washington has confidence in the ambassador and the ambassador has access, then a lot of business will get done.” Mr. Huntsman, he said, “has what it takes. He’s done a superb job.”


Current and former diplomats and White House officials said he skillfully managed preparations for the two signal occasions of his tenure, the state visits of both nations’ leaders to the other’s capital. Workers at the United States Embassy in Beijing give him high marks for his management of the United States’ second-largest diplomatic outpost.


Officially, the Chinese government bade him a fond farewell. Vice President Xi Jinping, the heir apparent to President Hu, called him “an old friend of China” in a meeting last month, adding, “We will never forget what you have done.”


Polished by years in American politics and fluent in Mandarin, Mr. Huntsman was nothing if not charming in his courtship of the Chinese. He regularly reminded Chinese audiences of his adopted Chinese daughter and his years in Asia as a youth. He flummoxed Chinese security guards — but perhaps left a distinctively American impression on Chinese diplomats — by forgoing the requisite limousine and suit and instead bicycling in casual clothes to several meetings at the Chinese Foreign Ministry.


He nevertheless spent much of his two years in the diplomatic doghouse. Mr. Huntsman did win the rare permission to visit Tibet, but he was denied an official visit to the restive western region of Xinjiang. (He went anyway, as a private citizen.) The cold shoulder included efforts to limit his official dealings to lower-level Chinese diplomats, as is standard for ambassadors who are out of favor. Most of those moves were a consequence of the deep chill that settled over relations in 2010, when the Chinese crimped Google’s Chinese search-engine business and the White House entertained the Dalai Lama and approved the sale of weapons to Taiwan. That was dispelled only after the successful visit to Washington by Mr. Hu last winter.


Perhaps Mr. Huntsman’s greatest misstep, which he has insisted was just a coincidence, was to wander into the tense scene of a pro-democracy protest in February while on a stroll through central Beijing with his family. The protest, the first of several Internet-based calls for a “Jasmine Revolution,” drew a horde of security agents who regarded Mr. Huntsman as a potential provocateur.


Mr. Huntsman later publicly condemned the beating and detention of foreign journalists at the scene. The Chinese, who appear to believe he deliberately attended the event, placed him back in the doghouse. But last week, at a farewell reception at the United States Embassy, Foreign Minister Yang Jiechi shared a toast with Mr. Huntsman and his wife. He appears to leave China in good standing — much as a future president, Mr. Bush, did when he left the chief diplomatic post in 1975.


 

2011年5月1日星期日

Eyeing the White House After Service in China

Blindsided, Pentagon officials considered whether the best response would be to pack up and leave before the mission had even begun. The American ambassador, Jon M. Huntsman Jr., advised forcefully against it. Too much was at stake, he said. Better to make clear Mr. Gates’s displeasure, then move on to more serious business.


Which is what Mr. Gates did, raising the issue with President Hu Jintao and relaying Mr. Hu’s embarrassed response to reporters shortly afterward.


“Jon came in and gave sensible advice,” said a person who was privy to the discussion and spoke on the condition of anonymity because the debate had been both private and official. “It was classic and proper handling of a difficult situation with the Chinese.”


It was also classic Huntsman. The ambassador, who was to leave his post on Saturday, has proved deft with the carrot and stick, mixing measured criticism of China’s government with a relentless effort to cement its fractious relations with the United States. It has not always worked: in recent months, as China’s growing crackdown on domestic dissidents drew Mr. Huntsman’s pointed objections, the efforts of the ambassador and other American diplomats have been angrily rejected by Beijing.


When President Obama selected Mr. Huntsman, then the popular Republican governor of Utah, as ambassador in 2009, pundits speculated that the president was working to edge him out of the race for the 2012 Republican nomination. Mr. Huntsman has implied otherwise in speeches, expressing respect for Mr. Obama’s skills and saying that they share a common cause in improving relations.


Now that Mr. Huntsman is publicly pondering a run for the nomination anyway — an unstated but clear reason behind his departure — the question may not be whether his China stint hurt his chances, but whether it improved them. Clearly, he did not achieve the goals he set. In a valedictory speech last month in Shanghai, he put his frustrations with China’s prickly and suspicious diplomacy on full display.


“Turning the relationship on and off in reaction to unwelcome events is inconsistent with the objective of a positive, cooperative and comprehensive relationship that our leaders have set out to achieve,” Mr. Huntsman said. “Canceling meetings as a sign of displeasure will not encourage greater respect for each other’s views.”


“We cannot move forward if, when differences emerge, only one of us is fully committed and fully engaged,” he said.


Getting China fully engaged — and persuading it to temper the suspicion and resentment that has marked even warm periods in its relationship with the United States — is the Obama administration’s strategic goal and, by all accounts, Mr. Huntsman’s passion. If that goal is, by many assessments, only slightly less distant than it was two years ago by, his pursuit of it wins wide praise.


“The course of a major relationship such as that between the United States and China is not going to be guided solely by the skill or lack thereof of an ambassador, but what an ambassador can do is make a meaningful difference,” J. Stapleton Roy, a China-born diplomat who served President Ronald Reagan and the first President George Bush and was President Bill Clinton’s first ambassador to China, said. “If Washington has confidence in the ambassador and the ambassador has access, then a lot of business will get done.” Mr. Huntsman, he said, “has what it takes. He’s done a superb job.”


Current and former diplomats and White House officials said he skillfully managed preparations for the two signal occasions of his tenure, the state visits of both nations’ leaders to the other’s capital. Workers at the United States Embassy in Beijing give him high marks for his management of the United States’ second-largest diplomatic outpost.


Officially, the Chinese government bade him a fond farewell. Vice President Xi Jinping, the heir apparent to President Hu, called him “an old friend of China” in a meeting last month, adding, “We will never forget what you have done.”


Polished by years in American politics and fluent in Mandarin, Mr. Huntsman was nothing if not charming in his courtship of the Chinese. He regularly reminded Chinese audiences of his adopted Chinese daughter and his years in Asia as a youth. He flummoxed Chinese security guards — but perhaps left a distinctively American impression on Chinese diplomats — by forgoing the requisite limousine and suit and instead bicycling in casual clothes to several meetings at the Chinese Foreign Ministry.


He nevertheless spent much of his two years in the diplomatic doghouse. Mr. Huntsman did win the rare permission to visit Tibet, but he was denied an official visit to the restive western region of Xinjiang. (He went anyway, as a private citizen.) The cold shoulder included efforts to limit his official dealings to lower-level Chinese diplomats, as is standard for ambassadors who are out of favor. Most of those moves were a consequence of the deep chill that settled over relations in 2010, when the Chinese crimped Google’s Chinese search-engine business and the White House entertained the Dalai Lama and approved the sale of weapons to Taiwan. That was dispelled only after the successful visit to Washington by Mr. Hu last winter.


Perhaps Mr. Huntsman’s greatest misstep, which he has insisted was just a coincidence, was to wander into the tense scene of a pro-democracy protest in February while on a stroll through central Beijing with his family. The protest, the first of several Internet-based calls for a “Jasmine Revolution,” drew a horde of security agents who regarded Mr. Huntsman as a potential provocateur.


Mr. Huntsman later publicly condemned the beating and detention of foreign journalists at the scene. The Chinese, who appear to believe he deliberately attended the event, placed him back in the doghouse. But last week, at a farewell reception at the United States Embassy, Foreign Minister Yang Jiechi shared a toast with Mr. Huntsman and his wife. He appears to leave China in good standing — much as a future president, Mr. Bush, did when he left the chief diplomatic post in 1975.


 

2011年4月15日星期五

Spotify announces new limits for free service, hopes you'll consider its premium options

 By Donald Melanson posted Apr 14th 2011 3:11PM No, it's still not saying anything about the eventual US launch, but Spotify is now causing a minor ruckus across the pond, where it's just announced some changes to the free version of the music streaming service. The timeline for the changes varies depending on when you signed up, but the short of it is that users will have six months of access to the free service as it is now, after which they'll face some stricter limits on how much they can listen to. That includes a total of just ten hours of listening time each month, and the ability to listen to individual songs no more than five times. Of course, the obvious goal there is to get more folks to sign up for its Premium or Unlimited services, which the company notes remain unchanged.

[Thanks to everyone who sent this in]