Cloud security: Try these techniques now

For Logiq³ Inc., the decision to go with a cloud-based provider of IT infrastructure as a service (IaaS) was a matter of cost and flexibility. So Logiq³ instead chose cloud computing and managed IT services provider BlueLock LLC to handle its data needs in the cloud. A start-up that began operations in 2006, the Toronto-based life reinsurance management firm could not afford to build and staff a data center from scratch, according to David Westgate, Logiq³'s vice president of technology.

BlueLock's virtualized environment allowed data and volumes to move between systems in a dynamic, low-cost way that would be impossible with a traditional, hosted environment, Westgate says. The life reinsurance company handles death records, which include personal information like social security numbers, as well as financial data and information about major assets that its large financial customers have on their books. There were, however, security concerns to be addressed before Logiq³ would entrust its critical systems to BlueLock's cloud. Although Logiq³ isn't regulated by the U.S. government's Sarbanes-Oxley Act, its customers in the financial sector are, "so they'll be auditing us," says Westgate. Logiq³ is far from alone. As a result, Logiq³ needed potential cloud vendors to demonstrate that they were in compliance with applicable regulations and could provide high levels of security.

While security and compliance issues crop up in any Web-based outsourcing arrangement, businesses are justifiably concerned about putting everything in a virtualized cloud. If you are going with an infrastructure-as-a-service provider, ask what tools it can provide you to protect your virtual environment. * Encrypt data at rest and in transit; otherwise, don't put sensitive information in the cloud. * Divvy up responsibilities between your administrators and the service provider's administrators, so no one has free access across all security layers. * Check whether a vendor has been accredited as meeting SAS 70 Type 2 and ISO 27001 security standards. It's a comparatively new service area where risks are unknown - "which in itself is a risk," says Jay Heiser, an analyst at Gartner Inc. "If I can't figure out how risky something is, I have to assume it isn't secure." 5 tips for effective cloud security * Find out as much as you can about a software-as-a-service provider's security measures and infrastructure. If you are an international company, check for European Safe Harbor accreditation as well. * Go with a high-end service provider with an established security record. "You get what you pay for," says Gartner analyst Jay Heiser. So far, there have been few instances of a successful, large-scale data breach on a public cloud.

The extent to which hackers can take advantage of unique cloud vulnerabilities is being hotly debated at Web sites like Linkedin.com's Cloud Computing Alliance. Just recently, however, someone managed to set up the Zeus password-stealing botnet inside Amazon.com Inc.'s EC2 cloud computing infrastructure by first hacking into a Web site that was hosted on Amazon servers. Cloud vendors are, in some instances, playing catch-up on the security front, and IT managers are trying to figure out just exactly what the risks are and how to counter them. It is, in other words, early days yet in the cloud computing industry. Divvy up responsibility A crucial first step is for cloud-based service providers and their potential clients to sit down and determine who has responsibility for securing and protecting what components of the IT infrastructure, which often spans both companies' systems. For example, at Logiq³, Westgate decided to let BlueLock handle patching and configuration management because he was familiar with the software BlueLock was using, a tool from Shavlik Technologies LLC. The division of labor between Logiq³ and BlueLock actually strengthened security, because "no one person, or company, has all the keys to the kingdom." says Westgate.

Sometimes, particularly with an IaaS provider, the division of labor is negotiable. Because BlueLock manages the firewall, for example, "none of my admins can go in and decide to sell or move the data," he notes. "And BlueLock admins can't do it either, because they don't control the systems." How much responsibility lies with the cloud-based service provider largely depends on the type of service. The terms of service for Amazon's IaaS offering, for example, state that the customer is responsible for protecting the data it puts into the public cloud, he adds. With an IaaS setup, for example, the customer is usually responsible for protecting everything above the middleware and APIs, including the applications and operating system, says Todd Thiemann, senior director of security vendor Trend Micro Inc.'s Data Protection group. In contrast to IaaS arrangements, a software-as-a-service provider is usually responsible for protecting whatever customer applications and data reside on its cloud.

IBM's LotusLive SaaS offering, for example, which was launched January 2009, utilizes "the same standards, security, compliance and governance we use to run major business systems for some very large and important companies," says Sean Poulley, IBM's vice president of online collaboration services. That setup often works well for budget-challenged businesses, because it gives them access to advanced security technologies and resources that they might not be able to afford in-house. For example, LotusLive data centers are protected by environmental and biometric controls, including closed-circuit TV. Access control is handled by IBM's enterprise-scale Tivoli software. This means companies have to take the vendor's word that its systems are indeed secure and compliant. "Vendors have done little to accommodate security risk evaluation," says Gartner's Heiser. "They may have incredibly secure and robust systems, but there's no sensible way to ensure this." Security accreditation standards such as ISO 27001 and SAS 70 Type 2 provide some assurance, he adds, noting that "27001 is more relevant to cloud security issues, but weak when applied to new forms of technology." Playing nicely with the cloud Many SaaS vendors are understandably reluctant to have a customer insert third-party security products into their proprietary platforms, even if it's just an agent that would permit a customer's security system to interact with theirs. However, many cloud-based service providers - and SaaS providers in particular - feel that their security practices and technologies give them a competitive advantage, so they don't like to reveal details about how they approach security. For example, Pfizer Inc. had outsourced some security services to D3 Security Management Systems Inc. and was interested in using Oracle Corp.'s Access Manager in D3's incident management applications.

Anderson solved the problem by using Symplified Inc.'s SinglePoint Cloud Access Manager, which does not use an agent, but rather interacts with D3's published APIs, he says. But D3 expressed concerns about installing Oracle agents on its systems, says Kurt Anderson, the pharmaceutical company's manager of global operations business technology. Since IaaS customers technically own their virtualized slice of a vendor's infrastructure, they can install security software and controls. One such product is Trend Micro's Deep Security 7. Once its agent is installed in a private or public cloud infrastructure, it can perform deep packet inspection, monitor event logs and monitor system activity such as file changes for unauthorized activities, Thiemann says. However, only a few vendors provide products that can protect both private and public cloud-based environments. Shavlik, a cloud-based vendor that provides systems management for private cloud installations, tackles public cloud security from a different angle.

For Logiq³'s Westgate, BlueLock's use of Shavlik's software was a definite selling point. "I am very familiar with Shavlik: I've been using it for patch and configuration management for years," he says. It licenses its patch and configuration management and compliance-monitoring software to cloud-based service providers - including its own IaaS provider, says Mark Shavlik, the company's CEO. Cloud-based service providers are catching on to the fact that using an established commercial security product can attract customers. Access control in the cloud The dynamic, flexible resource provisioning that makes virtualization and cloud services so attractive to cost-challenged IT executives also makes it difficult to track where data is located at any given time, and who is accessing it. Pfizer uses Symplified's Single Point Cloud Access Manager to provide single sign-on (SSO) functionality across different SaaS providers and applications. This is true in private clouds, and even more so in public cloud-based systems, where access control has to be correlated between the customer and the service provider - and often several service providers.

When the end user moves between an Oracle- and a Symplified-managed domain, for example, he still has to log on again but he can use the same set of credentials, Anderson says. However, Anderson feels that it's up to the SaaS vendors to adopt a more holistic and standardized form of access management, so the customer would no longer have to bear that burden. Symplified and Ping Identity Corp. are two vendors that currently provide SSO systems for both internal and SaaS cloud-based applications, using federated identity technology that coordinates user identity and access management across multiple systems. Another access management concern when dealing with a cloud-based service - or any outsourced service for that matter - is how to ensure that the service provider's system administrators don't abuse their access privileges. IaaS providers, in contrast, will often allow a customer to install event log monitoring software on their virtualized portion of the infrastructure.

Again, SaaS customers don't have a lot of control or oversight of how the service provider addresses that issue. Logiq³, for instance, uses Sentry Metrics Inc.'s security event management service, which monitors event logs, does trend analysis and reports on anomalies. Checking bona fides Customer control and monitoring of a carrier's cloud can only go so far, however, no matter what the type of service. So the Sentry Metrics system could, for example, alert Logiq³ when a BlueLock administrator logs on without being given a specific job to do, Westgate says. So how do you ensure that sensitive data is adequately secured and protected? Therefore, due diligence is critical, Anderson says.

Service level agreements with monetary penalties don't cut it, says Pfizer's Anderson, especially for a Fortune 50 company, since "the small amount they get back is a pittance" compared to the cost of a major security breach. Pfizer uses SAS 70 Type 2 certification, in which an independent third party audits the service provider's internal and data security controls. Another standard by which to evaluate a service provider is ISO 27001, which defines best practices for designing and implementing secure and compliant IT systems. Anderson also verifies the vendor's level of Safe Harbor compliance and checks Dun & Bradstreet research to make sure it's legitimate, he adds. While such standards provide a useful starting point, their criteria tend to be generic, says Gartner's Heiser.

For example, after checking out BlueLock's SAS 70 Type 2 accreditation, Logiq³'s IT staff did a further evaluation to "make sure the controls we require are supported by the controls they have in place," Westgate says. Companies still need to match a service provider's specific controls to their specific requirements, he adds. His team then followed up on discrepancies, identifying missing controls and working with the vendor on solutions. Cautioning users doesn't work Many companies that want the cost benefits of cloud-based services but still have security concerns tell their end users not to put sensitive data on the cloud. The company plans to repeat the process at least once a year, he says. But this is generally an exercise in futility, according to Heiser. "The problem is that users often don't know what's sensitive, and probably won't follow the rules anyway," he says. "You can assume that any application or data service end users can pump with data will get sensitive data eventually." Pfizer is in the process of establishing a SaaS center of excellence to educate users about the correct way to deal with SaaS activities, Anderson says.

Among other things, those best practices forbid applications that involve competitive or personally identifiable information from being included in a SaaS setup. In addition, his group is establishing best practices for procurement of SaaS services. Basic security tasks such as access control and rights management become even more complicated when, as often happens, a SaaS provider outsources its infrastructure or development platform to another cloud-based service provider - adding yet another party to the equation. The company entrusted its infrastructure to Amazon because it's the most proven service provider, according to founder Robbie Forkish. Take the case of Cloud Compliance Inc., which provides access-control monitoring services for private cloud environments.

However, he acknowledges that the arrangement introduces potential security problems. "There are certain areas where we, as a consumer of their services, need to fill in security capabilities they lack" in order to meet Cloud Compliance's internal security requirements and to reassure its customers. The latter option involves a performance hit, since customers have to re-upload data into the cloud every time an application is run, but some customers accept that trade-off in return for a higher level of security, Forkish notes. For example, Cloud Compliance encrypts data in transit and gives customers the option of either encrypting data at rest - on Cloud Compliance's Amazon-hosted servers - or not putting any data in the cloud. Cloud Compliance's external customers do ask about Amazon's security, Forkish says. Cloud Computing will either address their concerns or, if it can't, pass them on to Amazon. "In some cases, we don't get a response, and we figure this is a real issue, but they're working on it," Forkish says. The concerns they raise change from month to month, depending on what vulnerabilities the press has been writing about, he adds.

But the recent Zeus botnet incident on Amazon, he says, "as far as we can tell, was not a threat over and above what we would expect for an Internet service, cloud-based or not." Compliance in the cloud

IBM adding data centers, cloud computing lab in Asia

IBM opened a new data center in South Korea on Thursday and said it is building another one in Auckland, New Zealand, to address a surge in demand for cloud computing and IT services in the Asia-Pacific region. The total investment by IBM in these three facilities is about US$100 million, said James M. Larkin, a spokesman for IBM Global Services. The company also announced the opening of a cloud computing lab in Hong Kong.

The company, which already has over 400 data centers worldwide, will continue to invest in new data centers that offer cloud computing capabilities, while upgrading existing data centers to support cloud computing, Larkin said. The data center at Auckland will be in operation by 2010 with IBM investing about US$57 million in that center over the next ten years. IBM is planning to announce by February next year a new data center in Raleigh, North Carolina, he added. IBM will locate the data center at Highbrook Business Park in East Tamaki. The company can add more stages to expand the data center as demand rises, it added. The 56,000 square-foot facility will include a 16,000 square-foot data center, IBM said.

The center will support IBM's clients in New Zealand and neighboring countries in the Asia-Pacific region, Larkin said. The center was built using green technology, according to the company. The data center in Seoul will provide IT services including strategic outsourcing, e-business hosting and disaster recovery to more than 20 clients which have entered into outsourcing agreements with the company, IBM said. The Cloud Computing Laboratory in Hong Kong is a development and services center, focusing on LotusLive messaging development, testing, technical support and services delivery, IBM said. The lab, which is IBM's tenth cloud computing lab worldwide, builds on the email technology and expertise of Outblaze, a company in Hong Kong, whose messaging assets were acquired by IBM earlier this year and included in the Lotus brand of collaboration services. LotusLive is IBM's collection of integrated, online collaboration solutions and social networking services for businesses.

The lab is part of the IBM China Development Laboratory which has over 5,000 developers.

Profile of an IT forensics professional

A snapshot look at the IT forensics profession from the perspective of Rob Lee, an IT forensics expert at Mandiant. He is a graduate of the U.S. Air Force Academy and a founding member of the USAF's Information Warfare Squadron, the first U.S. military operational unit focused on information operations. Name: Rob Lee Title: Director and IT forensics expert at Mandiant, a Washington-based information security software and services firm Related work: Curriculum lead for digital forensics training at the SANS Institute. 30-second résumé: Before joining Mandiant, Lee served as the technical lead for a vulnerability discovery and exploit development team that worked for a variety of law enforcement, government and intelligence agencies. Skills boost: To stay current, Lee does hands-on work in the field and is an avid reader of and contributor to information security journals and blogs.

He also recommends specializing in a particular area of computer forensics. "If you're choosing forensics, be a specialist in firewalls or hacking or mobile devices," Lee says. "Mobile devices alone are extremely complex and constantly changing. "If you're just beginning, classes are the way to go," he advises. "After that, you can continue to learn online. A passion to learn and to continue learning - rather than a formal computer science degree or security certification - is the top requirement for an IT forensics expert, says Lee, who also teaches SANS certification classes. The best thing you can do once you attain a certain level [of expertise] is give of yourself back to the community. Always do research and publish it." Next: Opinion: Web 2.0 security depends on users Choose something you don't think anyone else has [expertise in] and research that.

Wall St.: HP-3Com union a real Cisco threat

Financial analysts see HP's pending purchase of 3Com as a threat to Cisco because it means 3Com Ethernet switches that are inexpensive and very popular in China will have better access to U.S. businesses via well-established HP sales channels. "We see HP's acquisition as primarily a response to Cisco's converged network/CPU strategy," writes Catharine Trebnick, an analyst with Avian Securities. "With Cisco owning the bulk of the enterprise Ethernet market, they have the most to lose if HP is successful in integrating the 3Com portfolio." Trebnick says HP's 3Com acquisition is filling a gap in its high-end networking to better compete with Cisco, and that 3Com's success in China will be a boon to HP. "Our conversations indicate that HP is well on its way to successfully maintaining [3Com's] China presence," she writes in a memo reacting to news of the deal. Trebnick is also optimistic that HP can use its established sales channels to expand 3Com's market share in North America where "success has been limited." "This acquisition has negative implications for every other provider of networking equipment," Trebnick says, spelling out some specifics, with Cisco being the main target with the most to lose by the new HP. She says it seems logical that if HP wants to compete with Cisco on all fronts, it needs to make more purchases, possibly Avaya for unified communications and Polycom for telepresence and videoconferencing gear. A Brief History of 3Com  Nikos Theodosopoulos and Jack Monti of UBS Warburg write that Cisco faces a long-term threat from the beefed-up HP because it could come at Cisco with aggressive pricing. 3Com's plan has been to sell its low-cost H-3C gear that is popular in China in countries around the world, they say.

The deal is bad news for Brocade, she says, because HP sells Brocade storage gear under the name StorageWorks and might have hoped to make inroads with its Ethernet gear as well. Ittai Kidron and Joseph Park of Oppenheimer write that it is now unlikely that HP will try to buy Brocade, and also calls into doubt possible OEM relationships with Brocade and Juniper for data center switching and fibre channel over Ethernet products, because HP will probably try to develop this equipment in-house. But she writes that 3Com has been doing R&D on fibre channel over Ethernet, "raising the possibility that HP may build that functionality organically." Juniper is not affected as directly, she says, but if HP becomes stronger with corporate customers, it could blunt Juniper's momentum in enterprise sales. Near-term, though, the deal could be good for Cisco as well as Juniper and Brocade because integrating 3Com into HP will be disruptive, Kidron and Park write. Still, if HP wants to offer a complete array of network offerings it will have to make other purchases, strike OEM deals or develop its own technology, Theodosopoulos and Monti write in their bulletin about the deal. Analysts were impressed with 3Com's success in China, with Trebnick noting the Chinese government and corporate customers represent 30% of 3Com revenue, and Theodosopoulos and Monti noting its claim to 300 of the top 500 enterprises in China and a low-cost R&D center in that country.

In general, the purchase reduces the probability of other large networking mergers and acquisitions in the near term, they write, and that is likely to put pressure on the price of stocks of other companies they think might be acquisition targets, naming Brocade and F5. They also think that IBM is unlikely to buy networking vendors in the near term because it has OEM deals in the works with Juniper and Brocade that aren't fully up and running yet.

Analysis: Real ID program on life support

A decision by lawmakers to slash funding for the unpopular Real ID national driver's license program has put an already struggling program on life support. But continuing hesitation by Congress to kill the program entirely highlights the somewhat touchy political nature of the program, he said. "A straightforward repeal of Real ID is too much for our Congress to handle at this point," Harper said. "There isn't any love for Real ID in Capitol Hill. Earlier this week, the U.S. Senate approved a $43 billion budget for the U.S. Department of Homeland Security (DHS) for fiscal year 2010, which began Oct. 1. The measure included substantial increases in DHS spending in several key technology areas, but slashed Real ID funding by 40%, from $100 million to $60 million in 2010. That reduction all but ensures that Real ID is going nowhere, said Jim Harper, director of information policy studies at the Cato Institute.

Most in the Senate and the House don't want it." At the same time, many lawmakers are reluctant to openly reject it for fear of being seen as being too soft on national security issues, he said. The law requires states to follow a single national standard for identifying and authenticating people who apply for a driver's license. The Real ID Act was approved by Congress and signed into law by President Bush in 2005 as part of the government's effort to combat terrorism. It spells out specific technical and process requirements, including the use of biometric identifiers, for issuing licenses. Several have expressed particular concern over a Real ID requirement that all state driver's license databases be linked via a central hub for easier information sharing.

But the law has evoked widespread criticism from privacy advocates and civil rights groups who say it would create a de facto national identity card system that would be hard to manage and even harder to secure. Even the DHS itself, which is responsible for implementing the Act, has expressed reservations about Real ID security, privacy and logistics. Many see it as an attempt by the federal government to force costly and unwanted ID standards on them. States, too, have railed against Real ID, largely because it requires them to pay for the program themselves. A majority of states have formally expressed their refusal to participate in the program, including Arkansas, Idaho, Maine, Montana, New Hampshire, Washington and South Carolina. In a bid to make the idea of a national identity standard more palatable to states, several U.S. senators earlier this year introduced a bill proposing some revisions to Real ID . That "Providing for Additional Security in States' Identification" Act of 2009," or Pass ID Act, has the same goal as Real ID, minus some of its more controversial provisions.

DHS Secretary Janet Napolitano, in fact, was one of the first to reject Real ID when she was the governor of Arizona - a fact that many have said makes it especially hard for her to now try and push it on other states. The DHS has also pushed back implementation schedules on numerous occasions in what is seen by some as an attempt to push the issue down the road until someone kills it. But it isn't dead, yet." Pam Dixon, executive director of the World Privacy Forum, said that the proposed budget cuts make it impossible for Real ID to move forward in its present incarnation. "Congress is looking at this realistically and saying that states simply do not have the money to implement Real ID," she said. "For all intents and purposes, real ID has been put on the back-burner.

Rogue Amoeba quits iPhone development

Stories about App Store submission woes have become standard fare in the tech media of late, which has understandably led to some readers groaning "not another App Store sob story" whenever they come across one. Adding its name to a rapidly growing list of disgruntled iPhone developers is Rogue Amoeba, makers of fine audio utilities for the Mac, such as Airfoil, Audio Hijack Pro, and Fission. But, as Dan Moren so ably put it, iPhone developers are entitled "to a little respect," and constantly being on Apple's case with regard to the App Store approval process is the only way to get them to do something substantial about it. The company has also entered the iPhone app market with Radioshift Touch and Airfoil Speakers Touch.

Having submitted the updated version in July, they'd expected the app to be available on the store within a week or two, given that it was almost identical to the version already in the store, with merely minor bug fixes. Having shipped version 1.0.0 of Airfoil for the iPhone earlier this year, the folks at Rogue Amoeba quickly went to work on a 1.0.1 update to fix some bugs relating to audio sync when outputting to multiple sources. If you've read this far, you already know what's coming next: after being rejected three times, Airfoil Speakers Touch 1.0.1 was made available on the App Store on Friday, after floating in App Store submission limbo for three-and-a-half months. This, despite the fact that the first version of Airfoil for the iPhone, which was approved by Apple, had the exact same feature and that the feature uses Mac OS X code provided by Apple expressly for this purpose. I recommend checking out this post on the Rogue Amoeba Website by CEO Paul Kafasis to read about the events in detail, but here's the gist: Apple rejected the update on grounds of trademark infringement because the application displayed a picture of the Mac streaming the audio and an icon of the application whose audio is being streamed. As Kafasis notes in his missive, it's no worse than Apple displaying third-party app icons in the Dock and Finder.

Instead, there's a graphic that you can tap on to visit a Web page about why the icons are missing. That page also suggests that you consider donating to the Electronic Frontier Foundation (EFF), an organization that lobbies for Internet freedom. After having unsuccessfully re-submitted an unchanged binary to Apple for reconsideration, they took the only available recourse and removed the feature from the app, in accordance with Apple's demands. Perhaps the most important part of Kafasis's post comes at the end, where he states that Rogue Amoeba will be scrapping any plans to develop new iPhone applications for the foreseeable future and that updates to existing applications will also be few and far between. It's been more than a year since the App Store opened its doors; there are currently more than 100,000 applications that have cumulatively been downloaded more than two billion times. And, just like that, yet another passionate Mac developer walks out of the App Store, frustrated by its inane and inconsistent policies and their heavy-handed implementation. The argument that Apple is still new to this just doesn't fly anymore.

It's hard to believe that the company that produced the Mac, Mac OS X, the iPod, iPhone, Apple Online Store, and the iTunes Store is incapable of making the App Store work the way it should. Apple's attempts to fix the App Store in the past year have been lukewarm at best.

2009 geek gift guide: Toys and books for techies

Finding the perfect gift for techies is no easy matter. To help you find the perfect gift for the techie in your life - or to steer a loved one toward something you'd really like - InfoWorld.com has looked beyond the obvious to uncover 10 seriously cool new gadgets and 24 must-read tech books that will appeal to the geek in all of us. After all, by definition, geeks are steeped in the latest and greatest of tech gadgets, and it's just as difficult to find a tech-based subject they don't already think they know everything about.

You won't find the iPhone or Droid here, nor will you light upon the latest external network drive; more likely than not, your geek already has those. Sometimes that means toying around with a somewhat esoteric gadget. Instead, you'll find items aimed at satisfying every geek's innermost desire: to explore. [ Discover the 10 best gifts for techies in the InfoWorld.com's "2009 geek gadget gift guide" slideshow. | Discover the 24 best new books for techies in the InfoWorld.com's "2009 geek book gift guide" slideshow. ] Because if there's one thing we geeks all love to do, no matter what type of science, engineering, or tech discipline floats our boat, it's to play with technology that is both cool and useful. Other times that means soaking up new tech know-how we can apply at home or at work. This year's geek book gift guide has recommendations in seven categories: "something different" explorations, personal tech guides, hands-on deep technology how-tos, cloud and architecture expositions, business management primers for IT people, IT management how-tos, and tech best-practices "rethink" books.

This year's geek gadget gift guide includes the 55-cent Animal Clips for budding young geeks to the seriously useful and cool personal Pogoplug cloud storage device to a touch-based laptop that could show the way for real tablet computing. This article, "2009 geek gift guide: The best toys and books for techies," was originally published at InfoWorld.com.

Apple patent filing reignites tablet device rumors

A just-published Apple patent application for hand-writing recognition on pen-based computers has re-ignited speculation the company will soon unveil a tablet device. Technically, the Apple patent application - filed in July but published this week by the U.S. Trademark & Patent Office - is for "acquiring and organizing ink information in pen-aware computer systems." That's a type of device that Apple doesn't currently offer, though hand-writing recognition, dubbed Rosetta, was part of the Newton handheld device and operating system, released in 1993. And, according to Wikipedia, some of that code, renamed Inkwell, was introduced into Mac OS X, for use by peripherals graphics tablets. But if that's Apple's plan, the company may be in a furious race with Microsoft, which is leaking and hinting at details of an innovative small tablet device, Courier, now in development.

One of the developers of Inkwell, Larry Yaeger, is named in the newest patent application along with Richard Fabrick II, and Giulia Pagallo. The Apple filing describes a tablet "input device" that "may be a thin layer of sensing circuitry present either beneath the visible screen/tablet surface…or as part of a thin, clear membrane (not shown) overlying the screen…that is sensitive to the position of the pen on its surface. The worst Apple products of all time One of the first sites to pick up on the filing was Seth Weintraub's daily Apple news site, 9to5Mac.com.  Earlier this month, Craig Mundie, chief research and strategy officer, declined to comment on the Courier device but made it clear that Microsoft not only hasn't given up on tablets, but thinks the pieces are in place for a breakthrough product. "Today, several factors are coming together that will probably make the concept more resurgent or at least become more mainstream," he said. "It's a confluence of small, light devices with the hybrid touch and writing screen technology that will finally probably result in a tablet-type computer going mainstream." One key question is what operating system Courier might be using: a slimmed down version of the recently released Windows 7, or an early version of Windows Mobile 7, expected next year, with dramatically improved touch support on Windows handhelds. But the Inkwell heritage raises the question of just what kind of "tablet" Apple may have in mind. Engadget's Tom Ricker uses the pen-oriented patent filing to mock Apple CEO Steve Jobs, who famously called the finger the "best pointing device in the world" compared to the stylus, which has been a staple for Windows Mobile devices for years. Most of the speculation for much of this past year has been around a portable device with a notebook-sized screen and, in keeping with the success of the iPhone and iPod touch, a multi-touch user interface.

But Apple's patent filing specifically mentions that "A suitable tablet…for use with the present invention includes the Wacom graphics tablets from Wacom Technology Company of Vancouver, Wash." Wacom's products are advanced USB peripherals that plug into a Mac or Windows computers to enable pen or gesture input. The Intuoas4, introduced in March, can capture subtle differences in pressure, for example. The Bamboo products are pads only, using the host computer's screen; the Intuoas and Cintiq products incorporate their own displays as well. Tablets have been about to "happen" for the last 20 years. Yet today, tablets are relegated to small niches and vertical applications, such as healthcare. Microsoft has tried at least twice, most recently in 2001, to promote them as the next big thing in personal computing, investing time and treasure in creating intuitive digital ink technology, to make using the screen as easy as using a piece of real paper.

But the success of the big-screened, Web-browser-equipped iPhone, and the explosion of the netbook, or shrunken notebook, market seems to be reviving interest in finding the Next Big Small Form Factor device. The video, which seems more like an animation than a recorded live demonstration, shows a device that opens flat like a small book, with each "page" being a screen, each roughly 5x7 inches. Gizmodo in September released a Microsoft-created video that apparently shows a new, small tablet-like device from Microsoft, the Courier. The interface combines a pen and gestures to take notes and work with a variety of what seem to be PIM and Web applications. "[T]he biggest question that popped up for me is whether the pen interface (digital ink) is the right choice for the job," writes Network World blogger, Mitchell Ashley. "Is the pen interface something that belongs in the Tablet PC era, but not in new touch interface devices?... I personally would rather type, even with a simulated digital keyboard, than write with a pen stylus"

Maybe the touch keyboard, like [that] used with the iPhone, is the way to go.

Global Dispatches: Ex-Google exec helps Chinese startups

Fund Formed for Chinese Start-ups BEIJING - Kai-Fu Lee, who resigned as president of Google Inc.'s China operation earlier this month, has founded an angel investment fund and plans to help out three to five new Chinese high-tech companies annually. Steve Chen, a co-founder of YouTube Inc., is also an investor in Innovation Works. The fund, dubbed Innovation Works, launched with some $115 million (U.S.) provided by several IT vendors, including Taipei-based Foxconn Electronics Inc. and Lenovo Group Ltd.

The new company said the funds will be used to train young entrepreneurs and help them build Internet, mobile Internet and cloud computing companies. - Owen Fletcher, IDG News Service Telecom Firms Plan Joint Venture LONDON - Deutsche Telekom AG and France Telecom SA plan to form a joint venture that would oversee their respective U.K. mobile communications networks - T-Mobile U.K. and Orange U.K. The combined company would have about 28.4 million customers, or 37% of U.K. mobile subscribers, leapfrogging current market leader O2 U.K. Ltd., which reported 20.7 million customers at the end of June, the companies said. Ombudsman P. Nikiforos Diamandouros said he will rule on the complaint later this month. - Agam Shah, IDG News Service The venture is expected to realize overall savings of more than £3.5 billion ($5.7 billion U.S.) by, among other things, closing some stores and "optimizing" the companies' customer service staffs. - Peter Sayer, IDG News Service Briefly Noted The European Union has confirmed that its ombudsman received a complaint from Intel Corp. in July alleging that "procedural errors" were made by the European Commission during an antitrust investigation that led to a record fine of €1.06 billion ($1.44 billion U.S.) against the chip maker.

With Perot, Dell can get a chunk of IT's hottest market -- health care

There are a lot of reasons why Dell Inc. agreed to buy Perot Systems Corp. for $3.9 billion, but Congress' vote earlier this year to appropriate billions of dollars to spread the use of electronic medical records may be a key one. Even before today's announcment that Dell plans to buy Perot, the PC maker and IT services firm had agreements in place develop platforms dedicated to electronic health care applications. Perot, which says that about half of its $2.8 billion in annual revenue is derived from health care projects, is in a good position to gain a significant chunk of the $36 billion the federal government is poised to spend on IT related health care projects. During a conference call with reporters today, Michael Dell, CEO and chairman of Dell, called the move "the right acquisition" for his company, and that the two Texas-based firms share several similar characteristics. "Our products, services and structures are overwhelmingly complementary," Dell said.

EDS was spun off in 1996 as an independent firm and remained that way until it was acquired last year by Hewlett-Packard Co. for $13,9 billion . Ross Perot founded Perot Systems in 1988. Harry Greenspun, chief medical officer for Perot Systems' health care group, told investors garthered at an industry conference this month that there's tremendous opportunity for companies like Perot in the health care market. "Most hospitals, most physicians' offices are very immature in their adoption in their technology," he said, according to an archived recording on Perot's web site. Ross Perot, the chairman emeritus of Perot, added, "We saw this as a cultural match, and we saw what we could do together, and I think that made it a lot easier to jump on Michael's vision to build Dell," Perot founded Electronic Data Systems (EDS) in 1962 and sold it to General Motors Corp. in 1984 for $2.5 billion. Dell hopes to complete the deal by year's end, just after the federal fiscal year starts on Oct. 1, which is when federal spending on electronic records is set to begin in earnest. Dell and Perot are already jointly offering what Greenspan called a "dumb box" without ports of disk drives. The demand for help in implementing new health care IT projects should come quickly - Under the law, health care providers have to start upgrading e-health systems by 2015 or face federal penalties.

The Software-as-a-Service system delivers electronic records to virtual desktops that charge customers on a subscription basis. "This is a different way of delivering this service," said Greenspun. Bendor-Samuel said improved revenue from health care projects should be a strong side effect of the merger, but contended that Dell's primary interest is gaining access to a broader base of enterprise customers. "It's great to be a dominant player in the fastest growing segment of the economy, but I view that as a nice thing to have," he said. The purchase of Perot Systems will also give Dell some credibility among large users as a service provider, said Peter Bendor-Samuel, CEO of Everest Group, an Dallas-based outsourcing consultancy. "It both significantly improves their delivery capability and tremendously improves their credibility," he said. Dane Anderson, an analyst at Gartner Inc., believes that the deal shows only that Dell is finally embarking on a services strategy. It has not offered the broader consulting and integration services provided by IT services firms like Perot Systems, he added.. "Really, where the opportunity is in the nearest term is to bring more capabilities to the table for that Dell installed based of clients, he said. Dell's support operation has traditionally focused on providing services to meet the needs of existing users.

Anderson said that he doesn't expect Dell to quickly gain new services contracts due to the acquisition of Perot. Enterprise aren't likely to exit existing contracts with other services providers.

Verizon dances on grave of AT&T lawsuit

Verizon wasted no time gleefully mocking AT&T after the rival carrier dropped its lawsuit challenging the legitimacy of Verizon's "There's a Map for That" ads. The 25 funniest vintage tech ads In the day since AT&T announced it was dropping the suit, Verizon spokesman Jeffrey Nelson has updated his Twitter account 15 times to reference the failed suit. Priceless!

Typically, Nelson would retweet a comment from another tweeter making fun of AT&T. Prominent examples include "There's An Apology For That: AT&T Dismisses Its Pointless Lawsuit Against Verizon," "Now AT&T can focus on improving their 3G network," and "AT&T to Verizon: We give up, you win the ad war." Additionally, Nelson linked to an speech delivered by Verizon Chief Marketing Officer John Stratton detailing the company's plan to continue ridiculing AT&T throughout the holiday season. The ads then display maps that show the total geographical reach of 3G coverage for each carrier, with Verizon's map showing a far larger area of the country covered by its 3G service. Furthermore, Stratton said that Verizon has scrapped its original holiday ad campaign in favor of producing more ads attacking AT&T. "We tried to do some research to find out where our competitors' 3G coverage actually was, but we couldn't find it, they didn't provide it," he said. "So we went with an industry source, a third-party source who maps roaming for the industry and asked them to map our 3G coverage and map our competitors' 3G coverage… Now, we had already completed our fourth-quarter holiday work at considerable expense, but we have that stuff now sitting on a shelf." Verizon's "There's a Map for That" ads typically show AT&T users struggling to use applications on their mobile devices while Verizon customers happily watch live streaming videos. In its lawsuit, AT&T did not dispute that the maps used by Verizon in its ads were accurate. However, in Verizon's ads the company clearly marks the maps as "AT&T 3G Coverage" and "Verizon Wireless 3G Coverage."

Rather, it accused Verizon of misleading consumers by implying that AT&T has no wireless coverage in large parts of the country, when in reality parts not covered by AT&T's 3G HSPA network are still covered by its 2G EDGE network.

Intel/AMD deal could help solve virtualization compatibility problems

The $1.25 billion Intel/AMD settlement announced Thursday could improve competition in the server hardware market and solve some lingering problems related to server virtualization, analysts say. 50 greatest arguments in networking: AMD vs. But a new five-year cross-license agreement between the companies raises the possibility that Intel and AMD will share information on their instruction sets and enable live migration across servers with different processors, he says. Intel Today, a virtualization technology known as live migration lets customers move workloads from one physical server to another, but only if both servers contain processors from the same chip maker, according to Forrester analyst James Staten. "If you look at the virtualization instruction sets that have been implemented by AMD and Intel, they are incompatible with each other," Staten says. "If you build a virtualization pool and do live migration from one system to another, it has to be all Intel, or it has to be all AMD." The Intel/AMD settlement, which ends various antitrust and patent cross-license disputes, doesn't explicitly talk about virtualization, Staten notes. Gartner analyst Martin Reynolds agrees the Intel/AMD settlement could be good news for virtualization customers. "If they were to integrate virtualization more deeply into the processors as a single standard that companies use, it's possible virtualization could become less expensive," Reynolds says.

In the wake of the settlement, there are several other potential areas for new levels of compatibility between Intel and AMD processors, Staten says, including memory and power management, and security. The virtualization incompatibility has mainly harmed AMD, because the issue forces customers to standardize on one type of server and Intel has a dominant market share, according to Staten. Broad collaborations between the rivals should not be expected, though. "These are two fighters who just took a lot of bruises over the last two years," Staten says. "They're not about to run to the center of the ring and shake hands." In lawsuits filed against Intel, AMD claimed that Intel illegally forces customers into exclusive deals with cash payments, discriminatory pricing, marketing subsidies and other practices. I think that's beneficial for all." AMD benefits from the settlement more than Intel does, because it eliminates many concerns customers have about purchasing AMD-based servers, according to Staten. The settlement prohibits Intel from "offering inducements to customers in exchange for their agreement to buy all of their microprocessor needs from Intel," and other anticompetitive practices such as inducing customers to limit or delay sales of AMD products. "Intel agreed to a set of rules of the road for how they will conduct business going forward," says AMD spokesman Drew Prairie. "It should help create a fair and open competitive environment where products compete on their merits, and where innovation is rewarded by the marketplace. Even if customers like AMD technology, they might have chosen Intel-based servers instead because of concerns about AMD's viability.

The time and money allocated to fighting Intel in court may also have distracted AMD from product development. "Having those hindrances gone will definitely help AMD because their CPUs are quire competitive at this point," Staten says. Moreover, if AMD's allegations were correct, that means Intel's business practices were preventing OEM vendors from embracing AMD processors to the extent they would have liked. The settlement also makes AMD more attractive to outside investors, Reynolds says. While both companies are embracing multi-core processors, Intel is taking a homogenous approach in which every core is the same and AMD is using different types of cores in the same CPU for different workloads, according to Staten. AMD is taking a different approach than Intel to the server market. AMD is also trying to go down the multi-core path faster than Intel, with attempts to get 16- and 24-core processors on the market before its rival.

Generally, AMD is about a year behind Intel's technology, but turns a profit by making products that are cheaper and cost less to build, Reynolds said. "Generally the server vendors use the product that most meets their needs," he says. "They know their customers are smart and will buy the product that delivers the best value." Follow Jon Brodkin on Twitter. Reynolds said he doesn't expect the settlement to cause any major shifts in how OEM vendors approach Intel and AMD, however.

High-tech hardware spending returns, no help for IT jobs

IT decision makers will be investing in hardware in the coming six months, according to recent research, but high-tech executives say staffing will remain flat as companies not only slow the pace of jobs cuts but also hold off on new hires. The latest release of the CDW IT monitor reveals that more than two-thirds of some 1,043 IT decision makers in corporate and government sectors plan to make IT hardware purchases in the next six months. Podcast: Have IT budgets hit bottom yet? More than 80% of large businesses and 84% of federal government high-tech executives polled expect to invest in hardware, with a majority pointing to operational efficiency gains as motivation. "Hardware refresh cycles have been pushed to limits we've rarely seen, and anticipated investment in this area is encouraging as companies prepare for a larger economic recovery," said Mark Gambill, CDW vice president, in a statement.

Nearly 50% of both corporate and federal IT decision makers expect budgets to stay the same, with just more than 30% expecting slight budget increases. The survey, conducted over two weeks in September, also showed that more than 50% of federal government IT workers anticipate increased budgets in the next six months. Twenty-seven percent of those polled expect to also invest in software across a significant part of their organization, while 45% anticipate software purchases for a smaller portion of their companies. Eighty percent of IT decision makers do not anticipate adding staff and plan to keep their personnel counts at current levels. While spending is set to increase in various sectors in big and small ways, depending on the organization, questions regarding IT staff seemed to garner the same response across the board. Twelve percent do plan to hire additional IT workers in the next six months, and 8% continue to consider cutting staff, the research found. "The confidence we began to see emerge in April with decreases in planned job cuts has now evolved into planned capital investments in IT infrastructure to increase efficiency and productivity," Gambill stated. "The down side is that the percentage of organizations planning investments in IT staffing has held steady and in some cases declined." Do you Tweet?

Follow Denise Dubie on Twitter

Security service protects PCs from attack

Start-up InZero Systems Tuesday makes its debut with a security service that promises to protect PCs from possible malware, intrusions and other types of attacks. The device protects the PC from Internet threats without relying on the more traditional antivirus scanning model. The InZero Secure PC service features what the company calls a "little black box" that, when plugged into a PC and attached to Ethernet cable, offers a "hardware sandbox" with its own CPU, read-only memory and stateful inspection firewall and encryption engine. There's also a version of the hardware that would fit inside a PC. The InZero Secure PC device, which externally measures about 3" x 4" x 1", also acts as a gateway that can prevent malicious code from being sent out as well through what he calls a filtering and conversion-engine mechanism. 11 security companies to watch "This completely isolated area is dealing with anything from the outside," says co-founder Louis Hughes, chair and CEO of the start-up, which was founded in 2005 with undisclosed investment from financial partners and now has 60 employees.

The InZero Secure PC service also includes an encryption capability for protecting applications that might be stored on the user's own PC, says another co-founder, Alexander Pyntikov, president and COO. "We believe hardware is the key to this," he notes, since using just software wouldn't provide the level of protection the company is striving to achieve. InZero Secure PC is intended for use by either business or consumer, and as a service, it is managed through a data center in the Washington, D.C., area. The hardware-based service also includes a way to use a VPN to encrypt traffic. Wesley Clark, chair of the InZero Systems advisory board, is expected to make an appearance as well touting the InZero Secure PC service and product. In a press conference in Washington, D.C., Tuesday, Phil Zimmermann, creator of PGP, is expected to speak on the topic of evaluating the encryption in the product, and Gen. InZero Systems says it has about 37 businesses trying out the security service, which is being offered free for one month, with pricing around $70 per month, and lower based on volume discounts.

Google Voice Frees Your Voicemail, and Your Number

Until yesterday, signing up for a Google Voice account required you to pick a new phone number - not a pleasant option for those who have kept the same digits for years. When you sign up for Google Voice - which is still not widely available to the public (you need to get an invite or request one) - you can either choose Google one-stop phone number or keep your own for a more pared-down experience. Now Google has enabled users to keep their existing phone numbers and get (most of) the features Google Voice offers, including Google's excellent voicemail service. Keeping your old digits gives you: Online, searchable voicemail Free automated voicemail transcription Custom voicemail greetings for different callers Email and SMS notifications Low-priced international calling Going for the full-throttle Google experience gives you all of the above plus: One number that reaches you on all your phones SMS via email Call screening Listen In Call recording Conference calling Call blocking If you already have a Google Voice number, you can add the voicemail option to any mobile phone associated with the account.

Happily, Google circumvented this problem earlier this month. Some of the awesome benefits are explained in Google's YouTube explanation: Since voicemails are transcribed and placed online, even made publicly available for sharing purposes, there has been some danger of said voicemails appearing in search results. These new features are both freeing and limiting: you can keep your number but sacrifice some of the goodies that make Google Voice a powerful contender in the telephony business. Follow Brennon on Twitter: @neonmadman Full number portability is likely coming in the future, after, of course, Google deals with AT&T, Apple, and the FCC. But some have high hopes that eventually the opposition will grow to accept and embrace Google Voice.

Microsoft plans six patches next week, ties November record

Microsoft today said it will deliver six security updates Tuesday, less than half the number it issued last month, to fix flaws in Windows and Office. The six slated for next week, however, tie the record for the most issued in November, traditionally a light month for Microsoft updates. The updates will patch a total of 15 separate vulnerabilities , Microsoft said in a follow-up entry to its security response center's blog. "Six is the lucky number this month," said Andrew Storms, director of security operations at nCircle Network Security. "Really, anything less than 13 is a lucky number." Last month, Microsoft released 13 updates that patched 34 vulnerabilities, both records since the company started shipping monthly updates more than six years ago.

In November 2006, the company also delivered a half-dozen security updates. Four of the six affect one or more editions of Windows or Windows Server; the other two will patch Office, specifically Word and Excel. In 2007 and 2008, however, it shipped just two each year in November, while it released only one in 2005. Of the half-dozen updates, Microsoft tagged three as "critical," the highest severity rating in its four-step scoring system, while the remaining trio were labeled "important," the next-lowest ranking. Because there are no outstanding Microsoft-generated security advisories, Storms was at a loss about what next week's updates might fix. "But Bulletin 1 looks interesting," he said, noting that the critical update would patch only Vista and Server 2008. "Historically, you would expect a Vista patch to also affect XP, and maybe even Windows 7," Storms explained. Last month, Microsoft released the first patches for Windows 7's final code. "There aren't any Windows 7 patches at all," Storms said. "So, so far so good." Windows 7 will be worth watching, however. "It will be more interesting down the road to see if Microsoft disclosed bugs they found in Windows 7, and fixed during development, but are just now going back and fixing in the older OSes." Another update to watch carefully next week is the one Microsoft named "Bulletin 3" in its advance notification , the monthly forewarning that includes only the barest of details. None of Tuesday's updates will affect Windows 7, Microsoft's just-released operating system, or the also-new Windows Server 2008 R2, the companion server software.

That update, also rated critical, affects everything version from the aged Windows 2000 to Vista and Server 2008. "I think No. 3 is the big one to watch next week," said Storms. The first update will impact Word 2002 and Word 2003 on Windows, and Word 2004 and Word 2008 on the Mac. Another researcher agreed. "Our sources unanimously suggest that Bulletin 3 will be the issue that needs to be addressed first this month," echoed Sheldon Malm, senior director of security strategy at Rapid7, in an e-mail. "[Users] should take inventory of where Windows versions are within their environments so they can plan testing and roll-out of the patch for Bulletin 3 as quickly as possible." The two Office updates, both important, will address issues in Word and Excel. The Excel update, on the other hand, will patch one or more problems in Excel 2002, Excel 2003 and Excel 2007 on the PC, Excel 2004 and Excel 2008 on the Mac. "The Office updates are interesting, but from what Microsoft gave us today, I think they'll be the kind of file format parsing bugs we've all come to know and love," Storms said today. Earlier this week, Microsoft acknowledged that the bulk of all attacks targeting Office in the first half of 2009 were leveraging a single vulnerability, which Microsoft patched in June 2006. This is the second month in a row that Microsoft has disclosed not only the number of updates it will ship next week, but also the number of flaws those patches will fix. Vulnerabilities in Office file formats have been a treasure trove for hackers, who have successfully exploited them for years.

And that's a good thing, said Storms. "That's great," he said. "It aids the planning process, because six bulletins could be six vulnerabilities or 20." Microsoft will release the six updates at approximately 1 p.m. ET on Nov. 11.

Hijacked Web sites attack visitors

Here's the scenario: Attackers compromise a major brand's Web site. The issue goes unnoticed until it's exposed publicly. But instead of stealing customer records, the attacker installs malware that infects the computers of thousands of visitors to the site. Such attacks are a common occurrence, but most fly under the radar because the users never know that a trusted Web site infected them, says Brian Dye, senior director of product management at Symantec Corp.

But word can get out, leaving the Web site's customers feeling betrayed, and seriously damaging a brand's reputation. When his company tracks down the source of such infections, it often quietly notifies the Web site owner. Attackers, often organized crime rings, gain entry using techniques such as cross-site scripting, SQL injection and remote file-inclusion attacks, then install malicious code on the Web server that lets them get access to the end users doing business with the site. "They're co-opting machines that can be part of botnets that send phishing e-mail, that are landing sites for traffic diversion and that host malware," says Frederick Felman, chief marketing officer at MarkMonitor. That possibility is one of Lynn Goodendorf's biggest worries as global head of data privacy at InterContinental Hotels Group. "I worry about attacks that use a combination of malware and botnets," she says, adding that she has watched this type of activity increase steadily over the past two years. "That's very scary," says Goodendorf. But because the business's Web site isn't directly affected, the administrators of most infected Web sites don't even know it's happening.

Most victims haven't associated such attacks with the Web sites that inadvertently infected them. The latest versions of Microsoft's Internet Explorer browser and Google's search engine detect sites infected with malware, issue a warning and block access to the site. "To me, this is serious online brand damage," says Garter analyst John Pescatore, and it can be disastrous for small and midsize businesses that totally depend on search engine traffic. But that may be changing. The next frontier, says Dye, may be attackers who use these types of exploits against the Web sites of high-profile brands and then publicize - or threaten to publicize - what happened. But Pescatore sees a more fundamental problem: rushing through Web site updates and ignoring development best practices designed promote security.

Preventing attacks like SQL injections requires using enterprise-class security tools, such as intrusion-prevention and -detection systems, with a focus on behavioral analysis to spot attacks, Dye says. Most organizations follow formal processes for major upgrades, but not for the constant "tinkering" that takes place. The result: Vulnerabilities creep into the code. "Security groups often are forced to put Web application firewalls in front of Web servers to shield [these] vulnerabilities from attack," says Pescatore.

Using the Internet makes people smarter, study finds

Could it be that the Internet actually - gasp! - makes you smarter? The researchers said they found that surfing the Web seemed to stimulate neural activity and possibly enhance cognitive functioning in the mature group of Internet users . Just a week online increased brain activity twofold in the oldest Internet users studied, noted the scientists. "The results suggest that searching online may be a simple form of brain exercise that might be employed to enhance cognition in older adults," said Teena D. Moody, a UCLA senior research associate, in a statement. That's the word from a team of scientists at the University of California, Los Angeles , who reported this week that new Internet users between age 55 and 78 improved their scores on decision-making and complex reasoning tests after just seven days online. The researchers reported that using the Internet triggers key centers in the brain that usually atrophy with age and lack of use.

The UCLA team studied 24 adults - half of whom used the Internet daily, and half with very little online experience. However, when people begin using the Internet, it positively affects cognitive functions and alters the way the brain encodes new information. "We found that for older people with minimal experience, performing Internet searches for even a relatively short period of time can change brain activity patterns and enhance function," said Gary Small, a professor of psychiatry at UCLA and the study's author, in a statement. At the start of the program, the volunteers did online searches for information while undergoing MRI scans that recorded brain circuitry changes. After the two week period, the participants underwent a second brain scan. The they each went home and conducted Internet searches for an hour a day for seven days over a two-week period.

According to the researcher, the volunteers that had little Internet experience showed a marked improvement in areas of the brain that control memory and decision making. The UCLA team now plans to investigate the affects of online search on younger adults.

UMC posts best Q3 in years on stronger chip sales

United Microelectronics (UMC), the world's second-largest contract chip maker, reported its best quarterly net profit in two years on Wednesday due to strong chip sales. It is optimistic about the fourth quarter, as it expects average selling prices to rise due to an improved product mix. The company's positive momentum in the second quarter carried over into the third quarter, it said.

The global chip industry has continued to rebound after bottoming in the first quarter of this year as the global recession gripped financial markets. The last time UMC posted a better net profit was in the third quarter of 2007, when it reported net profit NT$9.23 billion. Stronger chip shipments sent UMC's sales for the third quarter up 11 percent year on year to NT$27.41 billion (US$843.9 million) as it turned to a net profit of NT$6.1 billion from a loss of NT$1.4 billion in the same quarter last year. The chip maker warned that the appreciation of the Taiwan dollar and some seasonal factors may hurt its shipments in the fourth quarter. UMC expects its chip shipments to remain flat or drop as much as 3 percent in the fourth quarter compared to the third, but average selling prices could rise as much as 3 percent. Chip sales normally peak in the third quarter because gadget makers need to install them inside devices ahead of the gift buying season for end-of-the-year holidays.

Demand for chips in consumer electronics is expected to grow, while the computer segment might show some weakness, UMC said. UMC also on Wednesday announced it plans to buy all stock in UMC Japan Challenges in Japan's chip industry could cause a surge in outsourcing to contract chip makers such as UMC, the company said, but UMC Japan is losing money and could continue to lose money and be unable to capture new business without help from the parent company in Taiwan. The company will spend US$500 million on new factory equipment this year, and plans to substantially increase capital spending on cutting edge chip production gear next year. UMC will offer nearly NT$2.44 billion for outstanding shares of UMC Japan.

SAP, Salesforce.com make apps with Google Wave

Google's Wave communication and collaboration platform is getting early interest from enterprise application vendors like Salesforce.com and SAP. Both companies have built prototype applications using Wave, which was released in preview mode for about 100,000 users on Wednesday after being available only to developers. SAP Research and the vendor's NetWeaver development team created an application called Gravity using Wave. Wave combines a range of technologies such as document sharing and instant messaging into a system for real-time collaboration.

In a demonstration video, Gravity is used to develop process models for a hypothetical merger between an insurance company and a bank. Meanwhile, Salesforce.com created an extension that employs Wave for customer service. Once completed, the process models are exported into SAP's BPM (business process modeling) software for further refinement. A demonstration video shows how a customer in need of support can use Wave to start a dialogue with an automated support robot. If the robot can't answer the user's questions, the user can request a live representative, who joins the conversation.

The system also creates a case record in Salesforce.com. Google is mulling the prospect of a "monetizable wave extension store," according to an official blog post, through which these applications and others could conceivably be sold. But while Wave is an intriguing technology, at this point it doesn't quite meet the needs of enterprises, according to Redmonk analyst Stephen O'Grady. "For both ISVs and enterprises, the usability will have to be improved," he said. "It's still an intimidatingly new technology for less technical users, so Google would do well to work with potential partners to abstract needless complexity and exposing only the business functionality required." Google acknowledged that Wave remains a work in progress in an official blog post this week, saying it "isn't quite ready for prime time" and noting that key features, such as a draft mode, remain to be implemented.