With the EliteBook Folio 9470m, due to ship in October. HP hopes the Ultrabook laptop will appeal to corporate IT departments and consumers. The device supports legacy connectivity such as a VGA video port and USB connections. HP says it offers nine hours of battery life, but this can be upped to 20 hours using an extended battery.
I can't be the only person to have suffered a catastrophic loss of Wi-Fi at this year's Infosecurity Europe conference at Earls Court. The network, provided by Ruckus Wireless, was free but required users to accept terms & conditions. The problem I found was that the authentication kept timing out, and even once I had gained access as a legitimate user, it was far too slow to enable me to connect to my corporate network via f5 FirePass. How rubbish is that? One exhibitor actually told a colleague of mine that he didn't expect any better from exhhbtions or conferences.
The organiser roughly knows how many delegates will attend; it knows how many exhibitors will be there. It surely cannot be rocket science to create a temporary WiFi LAN that can scale to this many concurrent users, given the majority of people attending, work in the IT sector and therefore are heavy users of mobile internet.
It goes to show just how ill-prepared the UK is. We have nothing to fear about green furry monsters. But when the world and his dog descends on London for the Olympics, I wonder how the cellular, data and WiFi networks will cope?
Greg Hadfield, a former Fleet Street journalist and internet entrepreneur, is organising the United Kingdom's first Open-data Cities Conference. In this guest blog post, Hadfield discusses the opportunities of open data.Imagine a city where your car tells you the location of the nearest vacant parking space. Or a city where you are notified as soon as a neighbour submits a planning application. Where up-to-the-minute listings of every cultural event and venue are available - all the time, wherever you happen to be. Imagine if you could discover the asking price of the cheapest two-bedroom home that has just gone on sale, in the catchment area that will guarantee your child a place at the best-performing school.
This is the thinking that led to the United Kingdom's first Open-data Cities Conference, which will be held at Brighton Dome Corn Exchange on Friday, April 20.
It's not technology that is holding us up. Although the rate of change will be greater as we progress towards ubiquitous, free, high-speed internet access available to everybody via a myriad devices.
For open-data cities to become reality, we don't have to wait until connectivity - and the "connectedness" it engenders - is the air we breathe.
Nor do we have to wait for the "internet of things", of which all kinds of objects - not just computers, tablets and phones - will be a part.
Emerging technologies associated with a semantic web of data are already sufficient to power innovative applications, services, and enterprises that will compete and combine to meet the needs of communities in the 21st century.
It is lack of data that will limit our ambitions. It is a dearth of data that risks keeping our cities in the slow lane to the future.
In a post-digital era - when the differentiation between analogue and digital, between "real" and "virtual", will finally be blurred beyond relevance - we will live in the age of data.
Even now, data is everywhere, all the time. It defines, describes and determines the world we live in.
The more data that is released - without strings attached, in machine-readable and non-proprietary "open" formats - the more likely it is that businesses and developers will use it to build the applications and services that world-class cities need.
Of course, I'm not urging the release of personal data relating to identifiable individuals.
The civic data I'm talking about is data about schools, catchment areas, and property prices; about bus times and bus-stops, taxi ranks, car parks, and traffic congestion; about energy use, CO2 emissions, and carbon footprints.
The crucibles for global change will be "open-data" cities - cities which self-consciously and collectively decide to make available unimaginable quantities of data, openly and freely.
CIOs are already well versed on virtualisation, with many
having already invested into virtualisation within their data centres and
server estates. For those CIOs that have, this usually prompts the question of:
where next? Given that they are using their underlying hardware more
productively, some CIOs assume that investment should start shifting to other
IT initiatives. But this would be a mistake. A major opportunity to better
utilise the enterprise's IT assets, while radically speeding up time to market,
can be captured through the orchestration and provisioning of IT via a service
catalogue.
Getting there requires the completion of virtualisation the IT environment, while also moving to greater level of standardisation. This virtualisation goes beyond the servers, where much attention has so far been placed, as far more can reliably be virtualised. For example, while network virtualisation is now mainstream within many organisations, relatively little has been done on application and storage virtualisation. CIOs that start to virtualise these areas are finding that they can far more flexibly allocate available resources against towards true application requirements. Overall, the goal here is the complete virtualisation of the server, storage and network environment, to provide a commoditised pool of IT capability that can be easily provisioned and orchestrated as needed.
The implementation of a service catalogue for IT assets is an important aspect of a parallel part of the journey. This essentially provides a single view for users that defines what services are available, and at what level. Putting this in place is a major step for CIOs, and should be used to lead the drive towards implementing the automated provisioning of IT assets. Orchestration then adds the necessary intelligence so that IT can dynamically match user demand against availability of the underlying infrastructure.
Achieving this gives CIOs various new options that can help drive out inefficiencies and radically speed up time to market. To give one example, specific operating areas, such as an organisation's test and development setup, can be transformed in how they are set up and run. Rather than taking days or weeks to build and deploy dedicated test and development machines for a new project, hundreds of virtualised test environments, simulating specific conditions or setups, can be created in hours and used for only as long as they're needed. This also ensures far more efficient setups, by only providing the specific test environments needed, for as long as they're needed, before the capacity is switched over to other tasks. One bank cut its test environment from 900 constant images to just 300, simply by restructuring the way it provisioned the workload in a 'just in time' basis.
A further example of how the IT environment can be more flexibly provisioned might be a rethink of how an enterprise ERP system is implemented. Such deployments typically provision sufficient capacity to ensure that any potential spikes in demand can be catered for, even though these peaks are rare. As a result, potential computing resource lies wasted for the majority of the time. In a more flexible IT environment with orchestration and provisioning, CIOs can cater for the typical operating load of the application, while "borrowing" capacity from other lesser-used systems, such as disaster recovery or training, to cater for the occasional surges in demand as they happen.
Of course, making a successful transition to an IT environment that can flexibly provisioned and orchestrated through a service catalogue is not without its challenges. The initial software investment can be high, and there are several prerequisites: standardisation of the underlying IT assets; complete, or very nearly complete, virtualisation; the ability to share a common IT resource pool; and a service-oriented approach to IT that focuses on application service delivery.
The good news is these goals are also prerequisites for any CIO thinking about a future move into a cloud environment. And more fundamentally, this forms part of the evolution of the role of the CIO: away from being a manager of IT infrastructure, and towards that of being an orchestrator of services.
Thorsten Heins RIM CEO confirmed on the call:So basically, RIM wants to concentrate on the enterprise, and, at the same time, allow staff, to bring in their own devices to work - presumably to connect via the Blackberry Enterprise Server.
- Whilst we announced we would refocus on the enterprise business, we also stated part of competing in the 'bring your own device' segment is to create a compelling consumer offering.
- Ahead of the BlackBerry 10 launch and throughout the remainder of our FY13, it is critical that we drive BlackBerry 7 sales to sustain the subscriber base. To do this we plan to aggressively incentivize sales of BlackBerry 7 smartphones to both drive upgrades from older BlackBerry products to BlackBerry 7 and to attract feature phone customers to BlackBerry 7 for their first smartphone experience.
- We have new BlackBerry 7 devices scheduled to come out in the next few months to reinvigorate our position in the key entry level smartphone segment, to support our efforts to continue growing our subscriber base by upgrading feature phone customers to smartphones.
- We will seek partnerships to deliver those consumer features and content that are not central to the BlackBerry value proposition, for example media consumption applications.
Again, it wants to partner with companies to deliver features that are "not central" to the Blackberry value proposition. Does that mean not central to "Enterprise IT"??
Point three is a bit of a contradiction, as RIM also wants to deliver an entry level smartphone.
What does it ll mean. Who knows - it seems even RIM doesn't!
Hello xxxx,I'm sorry to hear that your Kindle was lost. I've deregistered this Kindle from your account and noted this in our systems so that it can't be registered by another person.Your Kindle's Serial Number is: xxxxxxxxxx. If you find your Kindle, please contact us again and we can reinstate your registration.

US Xpress has implemented a single data analytics user interface that pools in information from multiple sources. The logistics firm collects 900 data elements from tens of thousands of trucking systems - sensor data for tyre and petrol usage, engine operation, geospatial data for fleet tracking, as well as driver feedback from social media sites.
All of this data is stream both in real time and collected for historical analysis. Information fed to appropriate online transaction processing systems, Hadoop and data warehouses,
In this podcast, Tim Leonard, CTO and vice president at US Xpress, explains how the company processes and analyses Big Data to optimise fleet usage, reduce idle time and fuel consumption and save millions a year as a result.
Application Compatibility Update
with Quest ChangeBASE
Executive Summary
With this March
Microsoft Patch Tuesday update, we see a set of 6 updates; 1 with the rating of
Critical, 4 with the rating of Important and 1 with that of Moderate. This is a
relatively small update from Microsoft, and the potential compatibility impact
for these updates is likely to be low.
Notably, the
Patch Tuesday Security Update analysis performed by the ChangeBASE team has not
identified any compatibility issues across the thousands of applications
included in testing for this release. This makes us confident that this set of
patches may be deployed with low risk of issue across the entire application portfolio.
Given the
nature of the changes and updates included in each of these patches, most
systems will require a reboot to successfully implement any and all of the
patches and updates released in this March Patch Tuesday release cycle.
Sample Results
Here is a sample Summary report for a sample database
where the Quest ChangeBASE Patch Impact team has run the latest Microsoft
Updates against a test application portfolio. As you can see, no issues have
been detected:

Testing Summary
|
MS12-017 |
Vulnerability in DNS Server Could Allow
Denial of Service (2647170) |
|
MS12-018 |
Vulnerability in Windows Kernel-Mode
Drivers Could Allow Elevation of Privilege (2641653) |
|
MS12-019 |
Vulnerability in in DirectWrite Could
Allow Denial of Service |
|
MS12-020 |
Vulnerabilities in Remote Desktop Could
Allow Remote Code Execution (2671387) |
|
MS12-021 |
Vulnerability in Visual Studio Could
Allow Elevation of Privilege (2651019) |
|
MS12-022 |
Vulnerability in Expression Design Could
Allow Remote Code Execution (2651018) |
|
|
|
Quest ChangeBASE RAG Report Summary
Security Update Detailed Summary
|
MS12-017 |
Vulnerability
in DNS Server Could Allow Denial of Service (2647170) |
|
Description |
This security update resolves a privately
reported vulnerability in Microsoft Windows. The vulnerability could allow
denial of service if a remote unauthenticated attacker sends a specially
crafted DNS query to the target DNS server. |
|
Payload |
Afd.sys, Dns.exe, Dnsperf.dll, Dnsperf.h,
Dnsperf.ini, Mswsock.dll, Tcpip.sys, Tcpip6.sys, W03a3409.dll, Wdnsperf.dll,
Wmswsock.dll, Ww03a3409.dll |
|
Impact |
Important - Denial of Service |
|
MS12-018 |
Vulnerability
in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2641653) |
|
Description |
This security update resolves a privately
reported vulnerability in Microsoft Windows. The vulnerability could allow
elevation of privilege if an attacker logs on to a system and runs a
specially crafted application. An attacker must have valid logon credentials
and be able to log on locally to exploit this vulnerability. |
|
Payload |
Win32k.sys |
|
Impact |
Important - Elevation of Privilege |
|
MS12-019 |
Vulnerability
in DirectWrite Could Allow Denial of Service |
|
Description |
Could Allow Denial of Service (2665364) |
|
Payload |
D2d1.dll, Dwrite.dll, D3d10_1.dll, D3d10_1core.dll,
D3d10warp.dll |
|
Impact |
Moderate - Denial of Service |
|
MS12-020 |
Vulnerabilities
in Remote Desktop Could Allow Remote Code Execution (2671387) |
|
Description |
This security update resolves two
privately reported vulnerabilities in the Remote Desktop Protocol. The more
severe of these vulnerabilities could allow remote code execution if an
attacker sends a sequence of specially crafted RDP packets to an affected
system. By default, the Remote Desktop Protocol (RDP) is not enabled on any
Windows operating system. Systems that do not have RDP enabled are not at
risk. |
|
Payload |
Rdpwd.sys |
|
Impact |
Critical - Remote Code Execution |
|
MS12-021 |
Vulnerability
in Visual Studio Could Allow Elevation of Privilege (2651019) |
|
Description |
This security update resolves one
privately reported vulnerability in Visual Studio. The vulnerability could
allow elevation of privilege if an attacker places a specially crafted add-in
in the path used by Visual Studio and convinces a user with higher privileges
to start Visual Studio. An attacker must have valid logon credentials and be
able to log on locally to exploit this vulnerability. The vulnerability could
not be exploited remotely or by anonymous users. |
|
Payload |
Vsaenv.exe, BaseConfig.pkgdef, BaseConfig.pkgdef.version |
|
Impact |
Important - Elevation of Privilege |
|
MS12-022 |
Vulnerability
in Expression Design Could Allow Remote Code Execution (2651018) |
|
Description |
This security update resolves one
privately reported vulnerability in Microsoft Expression Design. The vulnerability
could allow remote code execution if a user opens a legitimate file (such as
an .xpr or .DESIGN file) that is located in the same network directory as a
specially crafted dynamic link library (DLL) file. Then, while opening the
legitimate file, Microsoft Expression Design could attempt to load the DLL
file and execute any code it contained. For an attack to be successful, a
user must visit an untrusted remote file system location or WebDAV share and
open a legitimate file (such as an .xpr or .DESIGN file) from this location
that is then loaded by a vulnerable application. |
|
Payload |
No specific file payload |
|
Impact |
Important - Remote Code Execution |
Security Update Detailed Summary
|
MS12-017 |
Vulnerability
in DNS Server Could Allow Denial of Service (2647170) |
|
Description |
This security update resolves a privately
reported vulnerability in Microsoft Windows. The vulnerability could allow
denial of service if a remote unauthenticated attacker sends a specially
crafted DNS query to the target DNS server. |
|
Payload |
Afd.sys, Dns.exe, Dnsperf.dll, Dnsperf.h,
Dnsperf.ini, Mswsock.dll, Tcpip.sys, Tcpip6.sys, W03a3409.dll, Wdnsperf.dll,
Wmswsock.dll, Ww03a3409.dll |
|
Impact |
Important - Denial of Service |
|
MS12-018 |
Vulnerability
in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2641653) |
|
Description |
This security update resolves a privately
reported vulnerability in Microsoft Windows. The vulnerability could allow
elevation of privilege if an attacker logs on to a system and runs a
specially crafted application. An attacker must have valid logon credentials
and be able to log on locally to exploit this vulnerability. |
|
Payload |
Win32k.sys |
|
Impact |
Important - Elevation of Privilege |
|
MS12-019 |
Vulnerability
in DirectWrite Could Allow Denial of Service |
|
Description |
Could Allow Denial of Service (2665364) |
|
Payload |
D2d1.dll, Dwrite.dll, D3d10_1.dll, D3d10_1core.dll,
D3d10warp.dll |
|
Impact |
Moderate - Denial of Service |
|
MS12-020 |
Vulnerabilities
in Remote Desktop Could Allow Remote Code Execution (2671387) |
|
Description |
This security update resolves two
privately reported vulnerabilities in the Remote Desktop Protocol. The more
severe of these vulnerabilities could allow remote code execution if an
attacker sends a sequence of specially crafted RDP packets to an affected
system. By default, the Remote Desktop Protocol (RDP) is not enabled on any
Windows operating system. Systems that do not have RDP enabled are not at
risk. |
|
Payload |
Rdpwd.sys |
|
Impact |
Critical - Remote Code Execution |
|
MS12-021 |
Vulnerability
in Visual Studio Could Allow Elevation of Privilege (2651019) |
|
Description |
This security update resolves one
privately reported vulnerability in Visual Studio. The vulnerability could
allow elevation of privilege if an attacker places a specially crafted add-in
in the path used by Visual Studio and convinces a user with higher privileges
to start Visual Studio. An attacker must have valid logon credentials and be
able to log on locally to exploit this vulnerability. The vulnerability could
not be exploited remotely or by anonymous users. |
|
Payload |
Vsaenv.exe, BaseConfig.pkgdef, BaseConfig.pkgdef.version |
|
Impact |
Important - Elevation of Privilege |
|
MS12-022 |
Vulnerability
in Expression Design Could Allow Remote Code Execution (2651018) |
|
Description |
This security update resolves one
privately reported vulnerability in Microsoft Expression Design. The vulnerability
could allow remote code execution if a user opens a legitimate file (such as
an .xpr or .DESIGN file) that is located in the same network directory as a
specially crafted dynamic link library (DLL) file. Then, while opening the
legitimate file, Microsoft Expression Design could attempt to load the DLL
file and execute any code it contained. For an attack to be successful, a
user must visit an untrusted remote file system location or WebDAV share and
open a legitimate file (such as an .xpr or .DESIGN file) from this location
that is then loaded by a vulnerable application. |
|
Payload |
No specific file payload |
|
Impact |
Important - Remote Code Execution |
*All results are based on a ChangeBASE Application Compatibility Lab's test portfolio of over 1,000 applications.
For more information, please visit www.changebase.com
Amazon is offering its DynamoDB NoSQL database service, in Europe to provide businesses with a scalable database system in the cloud.
Amazon says DynamoDB in the EU-West region, complies with European data regulations since data remains the European Union. The database stores data on Solid State Drives (SSDs) and replicates it synchronously across multiple AWS Availability Zones within the EU-West region to provide built-in high availability and data durability.
It's been a few weeks since my last post. I've been busy attending conferences - Cloud Expo at Olympia and the Intellect Regent Annual Summit. Cloud computing is all the rage with the suppliers, but a survey from TechTarget, the parent company of Computer Weekly, shows that IT directors and senior IT decision makers are not buying the hype. It really is time for the industry to take a step back and try a little harder to appreciate the challenges IT departments are facing during these tough economic conditions.
The tough economic climate was the backdrop to the Intellect event in London last week. Antony Miller from analyst TechMarketView presented a compelling argument as to why the economics of cloud do not work. In most instances flexibility comes at a price, but the cloud providers want everyone to believe they can offer the ultimate flexibility, cheaper than on-premise software. He pointed out that most of the Saas companies are losing money, some have already been acquired by traditional suppliers. So maybe Saas providers will need to increase their prices to remain in business.

Image via CrunchBase
Prior to Patch Tuesday, software companies were very secretive about security vulnerabilities. While it may have generated negative headlines about the risks and vulnerabilities in Microsoft software, Patch Tuesday has become an essential part of IT administration, allowing IT departments to plan and test updates to their Microsoft software.
Speaking to Computer Weekly, Steve Lipner, partner director of program management, TwC group at Microsoft, said "We have made progress and learned a lot of lessons, but we know we are not done. Computing is part of the fabric of society and trustworthy computing is still something we have to focus on."
What TwC has achieved is raise the bar on software quality, and, at the same time, it has made the general public more aware of keeping their computers "up-to-date." In this age of greater and greater connectivity, such awareness will go some way to protect people from hacking and phishing.
Image via Wikipedia
Executive Summary
With this January Microsoft Patch Tuesday update, we see a set of 7 updates; 1 with the rating of Critical and 6 with the rating of Important. This is a moderately sized update from Microsoft and the potential impact for the updates is likely to be low.
As part of the Patch Tuesday Security Update analysis performed by the ChangeBASE team, we have seen a small number of potential compatibility issues, including some which were caused by the fifth update in this release, MS12-005, where vulnerabilities in Microsoft Windows could allow Remote Code Execution.
Given the nature of the changes and updates included in each of these patches, most systems will require a reboot to successfully implement any and all of the patches and updates released in this January Patch Tuesday release cycle.
Sample Results
Here is a sample of the results for two applications tested for compatibility with these updates:
MS12-005: Vulnerabilities in Microsoft Windows Could Allow Remote Code Execution.
MS12-006: Vulnerabilities in SSL/TLS Could Allow Information Disclosure.

And here is a sample ChangeBASE Summary report for a sample database where the ChangeBASE Patch Impact team has run the latest Microsoft Updates against a small application portfolio:

Testing Summary
|
MS12-001 |
Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615) |
|
MS12-002 |
Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381) |
|
MS12-003 |
Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524) |
|
MS12-004 |
Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391) |
|
MS12-005 |
Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146) |
|
MS12-006 |
Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584) |
|
MS12-007 |
Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664) |
Security Update Detailed Summary
|
MS12-001 |
Vulnerability in Windows Kernel Could Allow Security Feature Bypass (2644615) |
|
Description |
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow an attacker to bypass the SafeSEH security feature in a software application. An attacker could then use other vulnerabilities to leverage the structured exception handler to run arbitrary code. Only software applications that were compiled using Microsoft Visual C++ .NET 2003 can be used to exploit this vulnerability. |
|
Payload |
Ntdll.dll, Wntdll.dll, Updspapi.dll |
|
Impact |
Important - Security Feature Bypass |
|
MS12-002 |
Vulnerability in Windows Object Packager Could Allow Remote Code Execution (2603381) |
|
Description |
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate file with an embedded packaged object that is located in the same network directory as a specially crafted executable file. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. |
|
Payload |
No specific files affected |
|
Impact |
Important - Remote Code Execution |
|
MS12-003 |
Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (2646524) |
|
Description |
The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application. The attacker could then take complete control of the affected system and install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability can only be exploited on systems configured with a Chinese, Japanese, or Korean system locale. |
|
Payload |
Winsrv.dll, Updspapi.dll |
|
Impact |
Important - Elevation of Privilege |
|
MS12-004 |
Vulnerabilities in Windows Media Could Allow Remote Code Execution (2636391) |
|
Description |
This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow remote code execution if a user opens a specially crafted media file. An attacker who successfully exploited the vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. |
|
Payload |
Mciseq.dll, Winmm.dll, Updspapi.dll |
|
Impact |
Critical - Remote Code Execution |
|
MS12-005 |
Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146) |
|
Description |
This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file containing a malicious embedded ClickOnce application. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. |
|
Payload |
Packager.exe, Updspapi.dll |
|
Impact |
Important - Remote Code Execution |
|
MS12-006 |
Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584) |
|
Description |
This security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0. This vulnerability affects the protocol itself and is not specific to the Windows operating system. The vulnerability could allow information disclosure if an attacker intercepts encrypted web traffic served from an affected system. TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are not affected. |
|
Payload |
Schannel.dll, Winhttp.dll, Updspapi.dll |
|
Impact |
Important - Information Disclosure |
|
MS12-007 |
Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664) |
|
Description |
This security update resolves one privately reported vulnerability in the Microsoft Anti-Cross Site Scripting (AntiXSS) Library. The vulnerability could allow information disclosure if a an attacker passes a malicious script to a website using the sanitization function of the AntiXSS Library. The consequences of the disclosure of that information depend on the nature of the information itself. Note that this vulnerability would not allow an attacker to execute code or to elevate the attacker's user rights directly, but it could be used to produce information that could be used to try to further compromise the affected system. Only sites that use the sanitization module of the AntiXSS Library are affected by this vulnerability. |
|
Payload |
No specific files affected |
|
Impact |
Important - Information Disclosure |
*All results are based on a ChangeBASE Application Compatibility Lab's test portfolio of over 1,000 applications.
He says, "Organisations do not insist an application is secure - they should push this responsibility down to their suppliers"
Companies are poor at measuring quality. "How do you know you are getting better over time."
Six months ago I wrote about a weekend project to install the SqueezeServer Squeezebox media server on an aging PC (a Hush PC based on a
1.2 GHz Via system with 40GB hard disk and 1 GB of memory) running Ubuntu 10.04 LTS.




CIOs have a tough challenge ahead of them in 2012. While cost-cutting will inevitably be on their agenda, businesses will still look to them to deliver on innovation, helping firms operate smarter, faster and leaner, to gain a much-needed competitive edge. But in trying to deliver on that, they face another issue, which is that the availability of skilled technology professionals is running low. Unemployment may be high on the news agenda right now, but the war for tech talent is getting steadily more intense. There are two broad reasons for this impending shortage. The first is well known. Quite simply, the overall supply of skilled technology workers is steadily reducing. At one end, the sector's grizzled veterans are about to start retiring in record numbers: 2011 marks the year that the first of the baby boomer generation starts to turn 65 and retire. At some major US firms, as much as half of their total engineering workforce will become eligible for retirement in the coming five years. At the other end of the labour pipeline, the intake of new graduates has been steadily declining. In the UK, since 2002, there has been a 33% decrease in the number of people applying for computer science-related courses, according to e-skills UK.
But there is also a second and less well understood reason for the CIO's looming talent troubles. Quite simply, the particular tech roles that will help firms gain a competitive advantage are now far more specific, and therefore far scarcer. Three roles stand out in particular. Welcome the data scientist, the data architect, and the user experience designer. Collectively, they are becoming IT's differentiators-in-chief.
These roles reflect that changing nature of technology, with varying drivers coming into play here. One is big data--large sets of both structured and unstructured data, from emails, blogs and tweets to videos, transaction records, and sensors, to name just a few sources--which is increasingly becoming a key factor in corporate innovation and productivity. To tame this, firms will increasingly rely on the data scientist: a multi-skilled role that combines technical acumen with mathematical abilities to tease out commercial insights from growing volumes and combinations of information.
The pharmaceutical sector gives just one example here. As the ability to sequence an individual's genome becomes increasingly cheap, there will be a growing emphasis on personalised medicine. To deliver on this, firms here will rely more on new kinds of data scientists to mine huge data sets and assess which compounds might be most effective in a particular circumstance. In other industries, data scientists will help their firms understand anything from high-level market trends to what retail store configuration will sell the most Christmas gifts.
But before the data scientist can do her job, the systems enterprise architect needs to do his. There's no point in building a better data analytics tool if there isn't a fundamentally sound foundation in place: a proper data architecture, with governance rules, master data management and a scalable storage architecture. Without this critical base, higher order analytics simply aren't possible. Unfortunately, this is typically one of the areas where firms are worst prepared, with data silos and platforms that aren't able to communicate with each other. Data architects will become increasingly crucial as firms become more reliant on data to compete.
The third critical role is the user experience designer. Such specialists are finding newfound importance, picking up from where business analysts typically held most sway before. This is directly due to the incredible success of mobile apps, with a corresponding rise in user expectations about design and user interfaces. Consumers expect that the websites or apps they use - whether for booking travel, buying groceries, or making an appointment - are simple to use, and visually appealing.
In turn, this makes user interfaces a means of standing out from the crowd. Take Square, for example, a start-up that offers a device to allow companies to accept credit card payments via a smart phone or tablet. Hardware aside, the firm stands out from its rivals by using interface design to turn one of the most routine and commoditised transactions of any business - people's card payments - into a chance to surprise and delight customers. This is the competitive advantage that the user experience designer can bring to a business.
Not all of these roles will matter to all firms, and other skills will matter more to some companies, but for those CIOs wanting to put technology at the heart of their company's innovation, these roles will matter more than before in 2012. The challenge, however, will be in finding and recruiting such skills.
Gavin Michael is Chief Technology Innovation Officer at Accenture. Follow Gavin on Twitter @gavinmichael.
Gavin started working for Accenture in 2010. He previously worked at Lloyds Banking Group as the Retail Technology Director. At Lloyds he was also a member of the Retail Bank Board. Prior to this role, he served as CIO of Lloyds TSB - UK Retail Banking & General Insurance. In this capacity, Gavin set the information technology strategy and direction for growing the UK Retail Banking Division and drove strong collaboration and alignment of technology with the business.

Image by Daves Portfolio via Flickr
-- Advertisement --
-- Advertisement --












Recent Entries