Computers blogs
flyg till köpenhamn

MCC 2011 Awardee

MCC 2011 Awardee
MCC 2011 Awardee

Recommended Books and Devices

Saturday, January 1, 2011

Microsoft's travails in 2010

One company i'm very passionate about when it comes to releasing products that the computer users and tech savvy consumers need is Microsoft.
Quoting Sharon Chan  of newsfactor;  "As Microsoft looks back on 2010, one thing is clear: The company has more product in it than Justin Bieber's hair."


Through the year 2010, the software company reeled out a stream of new offerings, from the early success of Kinect to the flaming failure of Kin.
It however aches my heart to say that despite all the effort, Microsoft's stock hasn't done as well as i would have envisaged. Microsoft started the year at $30.48 a share but closed at $28.01 Tuesday -- down 8.1 percent.

The company also lost leaders and brains of the software business: Chief Software Architect Ray Ozzie, Entertainment and Devices division President Robbie Bach and Business division President Stephen Elop.

Below is an enumeration of the products that kept Microsoft on the lips of every tech savvy consumer,on the display screens of every information technology and communications forum, and on the products-to-purchase list of every enterprise seeking to maximise their profit by using cost-effective,service delivering, software and hardware.

WINDOWS AZURE: Microsoft began the year with the launch of Azure, its platform for cloud computing.

As Chief Executive Steve Ballmer first said at a University of Washington speech in March, "We're all in" the cloud, a platform where software and data are stored in remote Microsoft data centers instead of corporate servers and are accessed with Internet-connected devices, such as laptops, mobile phones, tablets and televisions. Cloud computing is a bet-the-company move for Microsoft. In the next 10 years, the company believes delivering software via the cloud could make up half of the company's revenue.

The progress has been slow, however. Success of Azure depends on how many developers build software for it. It now has 20,000 customers. The company, meanwhile, continues to release new features and products for the cloud. In July, Microsoft announced plans to sell an Azure appliance that would reside on a corporate campus rather than in a data center run by Microsoft. The product is aimed at companies that don't trust their business data to an outside company.


Windows 7
: To me, he best Client operating system to be released by Microsoft in terms of and bringing  together ease of use and ease of deployment ,the latest version of Microsoft's operating system Windows 7 launched last year, it continued to see strong sales in 2010, selling 240 million copies since it hit the market in October 2009.

Kin: Microsoft launched the Kin mobile phone in April, calling it the phone for the socially networked generation. The phone's software was designed for life-casters who want to update their status and upload photos to Facebook. It began selling in May with Verizon Wireless, and by the end of June, Microsoft had pulled it from the market. Sales were reportedly disappointing. CEO Ballmer said the Kin distracted attention from Windows Phone 7, which started selling in the fall.


Office 2010: This ultimate product for the workplace makes $18.6 billion a year in revenue for Microsoft, came out with its latest version in May. For the first time, Microsoft also made a free lightweight Web-based version, called Office Web Apps, to compete with Google Docs. Microsoft reports Office 2010 has sold 6 million copies.In October, in the quest for further pushing its software-as-a-service campaign, the company also launched Office 365, Office software offered as an online service hosted by Microsoft in the cloud.

SharePoint 2010: Microsoft's collaboration software, which unifies into a single box, file sharing, Web site design and internal corporate searching(both document and people search). The latest version that came out in May added social-media features for businesses.

Bing: While Microsoft launched Bing in 2009, the search-engine development team has since continually rolled out new features. Microsoft also sewed up its massive partnership with Yahoo in October. Bing now runs all of Yahoo's searches and Microsoft's AdCenter now serves as the advertising platform for both sites. With the addition of Yahoo's search traffic, Bing now conducts 28 percent of all searches online in the U.S., according to November numbers from comScore. Google's dominant position remains strong at 66 percent.

Internet Explorer 9: In September, Microsoft released the beta version of its new Web browser, which has since been downloaded 15 million times. The software promises a new generation of richer, more animated and more application-like Web sites. The new browser supports the HTML5 Web standard, the foundation of new Web design. Unfortunately, Internet Explorer 9 works only on Windows 7 and Vista, which will limit how quickly it will be downloaded and how many developers will build HTML5 sites.

Windows Phone 7: Two years after Apple launched the iPhone, Microsoft introduced its redesigned mobile-phone operating system, dubbed Windows Phone 7, in October. The company says it will spend $100 million to market the phones, which are designed to make it faster to get contact updates and other information from your phone.In the absence of Microsoft's figure of how many phones customers have bought,phone-makers have sold 1.5 million to wireless carriers.

Kinect for Xbox 360: The motion sensor for Microsoft's video-game system allows people to play games without using a handheld controller. While the sensor has only a limited array of Xbox games that take advantage of the technology, it has sold 2.5 million units since launching in November. Microsoft sees potential in motion sensors beyond riding imaginary river rafts. The company believes that voice and gesture, not the mouse and keyboard, will define the desktop and office of the future.

Microsoft store in Bellevue: While it was not a global product that will sell in 40 countries, the Microsoft store that opened at Bellevue Square in November, the first retail store Microsoft opened in its home base. Ballmer himself showed up for the ribbon cutting.

Lync: This unified communications system simply named Lync, released in November, totally outshined Microsoft's other unified communications softwares such as Office communicator,... Lync can replace a traditional office phone system, and it brings together phone calling, instant messaging, video conferencing and presence, software that senses whether you're at your desk, on the phone or in a meeting.


As we begin 2011, i'm excited just thinking about what Microsoft has in store for us.Certainly the cloud computing technology named windows Azure is expected to be made less Microsoft hosted, i'm also thinking virtualization technology will not end with Virtual pc, what with VMware conquering the virtualization market in 2010.Also, i dont think Microsoft is done unleaashing the Office software tricks on us. Lets wait and see ...

Saturday, December 25, 2010

THE TWELVE DAYS OF CHRISTMAS



on the first day of christmas,computing gave to me, a root node in a B-Tree

On the second day of christmas, computing gave to me,
2 SATA drives
and a root node in a B-tree.

On the third day of christmas, computing gave to me,
3 French programmers
2 SATA drives
and a root node in a B-tree

On the forth day of christmas, computing gave to me,
4 primary keys
3 French programmers
2 SATA drives
and a root node in a B-tree

On the fifth day of christmas, computing gave to me,
5 constructors
4 primary keys
3 French programmers
2 SATA drives
and a root node in a B-tree

On the sixth day of christmas, computing gave to me,
6 codes compiling
5 constructors
4 primary keys
3 French programmers
2 SATA drives
and a root node in a B-tree


On the seventh day of christmas, computing gave to me,
7 hackers attacking
6 codes compiling
5 constructors
4 primary keys
3 French programmers
2 SATA drives
and a root node in a B-tree

On the eighth day of christmas, computing gave to me,
8 drives formatting
7 hackers attacking
6 codes compiling
5 constructors
4 primary keys
3 French programmers
2 SATA drives
and a root node in a B-tree

On the ninth day of christmas, computing gave to me,
9 backups restoring
8 drives formatting
7 hackers attacking
6 codes compiling
5 constructors
4 primary keys
3 French programmers
2 SATA drives
and a root node in a B-tree

On the tenth day of christmas, computing gave to me,
10 files uploading
9 backups restoring
8 drives formatting
7 hackers attacking
6 codes compiling
5 constructors
4 primary keys
3 French programmers
2 SATA drives
and a root node in a B-tree



On the eleventh day of christmas, computing gave to me,
11 crackers cracking
10 files uploading
9 backups restoring
8 drives formatting
7 hackers attacking
6 codes compiling
5 constructors
4 primary keys
3 French programmers
2 SATA drives
and a root node in a B-tree

On the twelfth day of christmas, computing gave to me,
12 calling functions
11 crackers cracking
10 files uploading
9 backups restoring
8 drives formatting
7 hackers attacking
6 codes compiling
5 constructors
4 primary keys
3 French programmers
2 SATA drives
and a root node in a B-tree


Sunday, November 28, 2010

CHINA'S 18 MIN INTERNET "HIJACK";HOW?,WHY? WHAT DOES IT MEAN

Recent proofs have been uncovered that shows that Sometime in April, a government owned telecoms company(China Telecoms)  for 18 minutes successfully routed 15% of the world's internet traffic via their routers and servers. These included communications to and from Government agencies(especially U.S), internet shopping traffic,  ...
The alleged "theft" of internet traffic was discovered by a communications company outside Washington, D.C. where computer network engineers monitor Internet traffic.

HOW DID IT HAPPEN
The internet operates on a trust-based system both in infrastuctural architechture and in terms of usage.Electronic routers direct the traffic flow, insuring the shortest path between any two computers anywhere in the world that hope to exchange information.
A little illustration here;lets say i have 3 uncles in the federal  ministry and i want to send a letter directly to the President of Nigeria.i would mentally calculate which of my 3 uncles is closest to the President by the number of people between them and the President,then i "forward" my letter to that uncle.That uncle in turn also calculates his distance to the president by the ranks of those he knows and forwards my letter to the next person he thinks is closer to the president....this continues until my letter is safely in the hands of the president.
Thats how routers "forward" information on the internet, only this happens in microseconds.

so essentially, the 18MIN hijack happened when computer routers in China belonging to China Telecom began signaling to other computer routers on the Internet that they could provide the quickest path between different computers. 
For 18 minutes, the traffic on 35,000 to 50,000 computer networks elsewhere in the world began flowing toward China, before getting routed to their final destinations. China Telecom had created a massive detour.

 Rodney Joffe, Senior Vice-president and Senior technologist at Neustar Inc said "They, all of a sudden, began announcing the fact that they were an optimal path to about 15 percent of the destinations on the Internet, that, in fact, they were a way to get to a large number of destinations on the Internet, when, in fact, they were not. We have never seen that before on this scale ever."

WHY DID IT HAPPEN
 The mere fact that the incident didn't severe all communications during the time it lasted suggests a calculated attempt to intercept, capure and later examine/inspect information.

Security expert Dmitri Alperovitch—VP of threat research at McAfee—says that this happens "accidentally" a few times a year, but this time it was different: The China Telecom network absorbed all the data and returned it without any significant delay. Before, this kind of accident would have resulted in communication problems, which lead experts to believe this wasn't an accident but a deliberated attempt to capture as much data as possible.

WHAT DOES THIS SAY 

A lot can be captured in 18 minutes. When all the communications from tens of thousand of computer networks was routed to China, that included all the Web traffic, e-mail, and instant messages to and from dot.mil -- that's the Department of Defense -- and dot.gov -- those are U.S. governments departments. The U.S. Senate and NASA also had all their traffic diverted.

Companies like Dell, Yahoo!, Microsoft and IBM had their data diverted by China Telecom, too. On that day in April, officers logging into a Pentagon Web site ended up looking at an image that came to their screen via China.


Information could have been gathered, which after much examination could be used to craft a virus to be released in such huge networks.The fact that traffic could be intentionally diverted to where it is "MALICIOUSLY WANTED" opens the eyes to possibilities such as the data actually being altered(man-in-the-middle attack) before being forwarded to its destination,fabricated rogue mails could be concocted to seem as being  sent from someone/somewhere....usernames could be masqueraded... the possibilities are just limitless!!

WHAT CAN BE DONE

Private networks and networks that provide essential services ;from life- essential services such as power grids,water, traffic, product mixing networks.. to those trusted services  such as internal government mail,military, Organizational services should be hosted on servers distant from the internet.worst case scenario;if these servers have to have a connection to the internet whatsoever, DMZ's (De-militarized zones) should be used as a sort of buffer.

Network administrators and security experts have to harden their organizations' networks.
 Wider proliferation of use of network security software, such as Microsoft's Forefront Threat management gateway 

The most efficient solution i see is for stakeholders and computer professionals around the world to;
 Greater Policize the internet trust system or all-together just fashion another network of networks that is just not as trust-based as the present standards.It might be  a longtime coming, but maybe we just go back to the base,how it all began, a revolution might just be underway.   


 

Tuesday, November 9, 2010

Choosing a Datacenter compute model

Compute models refer to infrastructures with which the IT department or datacenter chooses to render ,deliver, or deploy a particular service.
 Certain services/applications may be right candidates for central management or central distribution while others are just better managed locally,also existent in modern computing  is a hybrid of the two. Needless to say the various subtypes of these models.

MODERN COMPUTE MODELS

1.TERMINAL SERVERS
In this model,the client is merely a display and input device. All computation is
done centrally on the server, and all data is stored in a data center.
Nothing is executed or persistent on the client. Usually, Remote
Display Protocol (RDP) or Independent Computing Architecture*
(ICA*) is used to push an image of the server-based application
to a terminal viewer on the client.

2.VIRTUAL DESKTOP INFRASTRUCTURE
As with Terminal Services, all computation and storage are centralized,
with application images pushed over the network to the client
via Remote Display Protocol (RDP) or other display protocols. The
major difference is that VDI can offer each user their own complete
virtual machine and customized desktop, including the OS, applications,
and settings.

3.BLADE PCs
Much like server  blades,Blade PCs repartition the PC, leaving basic display, keyboard, and
mouse functions on the client, and putting the processor, chipset,
and graphics silicon on a small card (blade) mounted in a rack on a
central unit. OS, application, and data storage are centralized in a
storage array.
Unlike server blades, PC blades are built from standard desktop or
mobile processors and chipsets. The central unit, which supports many
individual blades, is secured in a data center or other IT-controlled
space. In some cases, remote display and I/O is handled by dedicated,
proprietary connections rather than using RDP over the data network.



4.OS Image Streaming or Remote OS Boot
At startup, the client is essentially “bare metal,” with no OS Image
installed locally. The OS Image is streamed to the client over the
network, where it executes locally using the client’s own CPU and
graphics. Application data is stored in a data center. The client is
usually a PC with no hard drive, which uses RAM exclusively

 5.APPLICATION VIRTUALIZATION
The client OS is locally installed, but applications are streamed
on demand from the server to the client, where they are
executed locally.
Although the terms “streaming” and “application virtualization” are
often used interchangeably, they are not the same thing. Streaming
refers to the delivery model of sending the software over the
network for execution on the client. Streamed software can be
installed in the client OS locally or, in most cases, it is virtualized.

FACTORS TO CONSIDER IN SELECTING THE RIGHT MODEL
 The factors listed below should be quantified per model, making trade-offs where necessary and contrasted to determine the optimal model for every unique service need.

Performance
Security
Manageability
Mobility
Disaster recovery
Infrastructure cost
User customization
Remote network access
Remote access

Reference: Principled technologies white paper titled "Understanding alternative compute models" 

Saturday, October 9, 2010

Time for a NAP

As a kid, i used to be cajoled to take naps(or Siesta,as my mum called it) in the afternoons.Now as a System engineer/administrator i still need NAP, for my networks and the computers in my networks to meet certain compliance requirements for a healthy network.Did i hear u ask how?


 NAP, as i know it now, stands for Network Access Protection.NAP is a new set of operating system components in Windows Server 2008, Windows Vista, and Windows XP Service Pack 3 that provides a platform for system health validated access to private networks. The NAP platform provides an integrated way of validating the health state of a network client that is attempting to connect to or communicate on a network and limiting the access of the network client until the health policy requirements have been met. 

To control access to network resources,based on requesting computers health status,the following functionalities need to be put in place:

·         Health state validation  Determines whether the computers are compliant with health policy requirements.
·         Network access limitation  Limits access for noncompliant computers.
·         Automatic remediation  Provides necessary updates to allow a noncompliant computer to become compliant without user intervention.
·         Ongoing compliance  Automatically updates compliant computers so that they adhere to ongoing changes in health policy requirements.
Windows Server 2008, Windows Vista, and Windows XP Service Pack 3 provide the following NAP enforcement methods:
·         Internet Protocol security (IPsec) enforcement for IPsec-protected communications
·         802.1X enforcement for IEEE 802.1X-authenticated connections
·         Virtual Private Network (VPN) enforcement for remote access VPN connections
·         Dynamic Host Configuration Protocol (DHCP) enforcement for DHCP-based address configuration
·         Terminal Server (TS) Gateway connections.

NAP COMPONENTS 
Network access protection client-server architecture is depicted in the image below:
   
 
·         NAP clients  Computers that support the NAP platform for system health-validated network access or communication.
·         NAP enforcement points(VPN servers,DHCP servers,Network access devices)  Computers or network access devices that provide access to a resource and that use NAP or can be used with NAP to require the evaluation of a NAP client’s health state and provide restricted network access or communication. NAP enforcement points use a Network Policy Server (NPS) that is acting as a NAP health policy server to evaluate the health state of NAP clients, whether network access or communication is allowed, and the set of remediation actions that a noncompliant NAP client must perform. Examples of NAP enforcement points are the following:
·         Health Registration Authority (HRA)  A computer running Windows Server 2008 and Internet Information Services (IIS) that obtains health certificates from a certification authority (CA) for compliant computers.

·         NAP health policy servers  Computers running Windows Server 2008 and the NPS service that store health requirement policies and provide health state validation for NAP. NPS is the replacement for the Internet Authentication Service (IAS), the Remote Authentication Dial-In User Service (RADIUS) server and proxy provided with Windows Server 2003. NPS can also act as an authentication, authorization, and accounting (AAA) server for network access. When acting as a AAA server or NAP health policy server, NPS is typically run on a separate server for centralized configuration of network access and health requirement policies, as Figure 1 shows. The NPS service is also run on Windows Server 2008-based NAP enforcement points that do not have a built-in RADIUS client, such as an HRA or DHCP server. However, in these configurations, the NPS service is acting as a RADIUS proxy to exchange RADIUS messages with a NAP health policy server.
·         Health requirement servers  Computers that provide current system health state for NAP health policy servers. For example, a health requirement server for an antivirus program tracks the latest version of the antivirus signature file.
·         Active Directory® Domain Service  The Windows directory service that stores account credentials and properties and Group Policy settings. Although not required for health state validation, Active Directory is required for IPsec-protected communications, 802.1X-authenticated connections, and remote access VPN connections.
·         Restricted network (some people may choose to call this a DMZ network(Demilitarized zone) A separate logical or physical network that contains:
·         Remediation servers  Computers that contain health update resources that NAP clients can access to remediate their noncompliant state. Examples include antivirus signature distribution servers and software update servers.
·         NAP clients with limited access  Computers that are placed on the restricted network when they do not comply with health requirement policies.


HOW IT WORKS 

The NAP client uses the appropriate security or authentication protocol (SSL(Secure socket layer),PEAP(Protected extensible authentication protocol),(Extensible authentication protocol)EAP,(Point-to-point) protocol )PPP...) depending on the resource the client is trying to access to craete protected session to send its current system health state to the HRA and request a health certificate. The HRA also uses the appropriate protocol  to send remediation instructions (if the NAP client is noncompliant) or a health certificate to the NAP client(if compliant).

While the NAP client has unlimited access to the intranet, it accesses the remediation server to ensure that it remains compliant. For example, the NAP client periodically checks an antivirus server to ensure that it has the latest antivirus signature file or a software update server, such as Windows Update Services, to ensure that it has the latest operating system updates.
If the NAP client has limited access, it can communicate with the remediation server to become compliant, based on instructions from the NAP health policy server. For example, if during the health validation process the NAP health policy server determined that the NAP client does not have the most current antivirus signature file, the NAP health policy server instructs the NAP client to update its local signature file with the latest file that is stored on a specified antivirus server.
The HRA sends RADIUS(Remote authentication dial-in user service) messages to the NAP health policy server that contain the NAP client's system health state. 
The NAP health policy server sends RADIUS messages to:
·         Indicate that the NAP client has unlimited access because it is compliant. Based on this response, the HRA obtains a health certificate and sends it to the NAP client.
·         Indicate that the NAP client has limited access until it performs a set of remediation functions. Based on this response, the HRA does not issue a health certificate to the NAP client.
Because the HRA in Windows Server 2008 does not have a built-in RADIUS client, it uses the NPS service as a RADIUS proxy to exchange RADIUS messages with the NAP health policy server.

When performing network access validation for a NAP client, the NAP health policy server might have to contact a health requirement server to obtain information about the current requirements for system health. For example, the NAP health policy server might have to contact an antivirus server to check for the version of the latest signature file or to contact a software update server to obtain the date of the last set of operating system updates.

So whether you'r instructing your kids or doing your million Naira/dollar job of instructing your network,taking a NAP really does pay-off.