Friday, February 25, 2011

Verizon iPhone suffers 'death grip,' says Consumer Reports

Lab, real-world tests show results similar to AT&T's model; solved with case
Consumer Reports today said that its lab tests show the Verizon iPhone 4 suffers from a "death grip" problem similar to last summer's revelations about AT&T's model.
Holding the Verizon model in certain ways can "cause the phone to drop calls, or be unable to place calls, in weak signal conditions," the magazine said Friday.
Similar problems with AT&T's iPhone last summer raised a ruckus that Apple first dismissed, then dealt with by offering free cases to all owners. Apple discontinued the offer last September.
As it did last year with the AT&T version of the iPhone 4, Consumer Reports today declined to put Verizon's on its "recommended" list because of the dropped call problem, even though the device is among its highest-rated smartphones.
"[Dropped calls] can occur when you hold either version of the iPhone in a specific but quite natural way in which a gap in the phone's external casing is covered," said Paul Reynolds, the magazine's electronics editor, in a blog post.
Covering the gap at the lower left of the steel band encircling the Verizon iPhone 4 resulted in dropped calls and an inability to place calls when the cellular signal was at a low strength -- at the level of one bar in the iPhone's indicator -- said Reynolds.
"Reception typically dropped notably within 15 seconds or so of the gap being bridged," Reynolds reported.
Experts, including antenna engineer Spencer Webb, president of AntennaSys, a mobile device antenna design and consulting firm, explained last year that placing part of one's hand over a gap in the band degraded performance by bridging separate antennas, changing the length of the cellular antenna and thus its ability to receive and transmit.
The Verizon iPhone has four such gaps, one more than AT&T's version.
Consumer Reports tested the Verizon iPhone in an isolation chamber at its Yonkers, N.Y. labs, using the same equipment and methodology it used last year to confirm the quickly-dubbed "death grip" issue with AT&T's iPhone. It replicated the tests, and came up with the same results -- dropped calls, inability to place calls -- using a live network connection as well.
The solution for the Verizon iPhone's death grip problem, said Reynolds, is the same as for AT&T's smartphone: Get a case.
"When we placed the Verizon iPhone 4 into the Apple iPhone 4 Bumper, a $29 frame-like cover sold by the company, the problem was essentially eliminated," Reynolds said. "Based on past tests of the AT&T iPhone with cases of other designs, we also expect other cases sold for the Verizon iPhone 4 will alleviate the problem."
After Apple stopped giving cases to every iPhone 4 owner last September, Consumer Reports blasted the company for the move, calling the decision "not acceptable" because it put the burden on customers.
At the time it ended the case giveaway, Apple said customers had to contact product support to request a free bumper. Apple did not immediately reply today to questions about whether that offer was still valid, or to a request for comment on Consumer Reports' findings.
The publication also ran five other highly-rated smartphones through the same tests, including HTC's Droid Incredible, LG's Ally, Motorola's Droid 2 Global and Droid X, and Samsung's Fascinate. All those smartphones run Google's Android mobile operating system.
None of five Android smartphones exhibited the death grip problem.
Reynolds noted that, unlike last summer, few complaints about dropped calls have surfaced from Verizon subscribers. In an interview Friday, Reynolds declined to speculate on why consumers haven't voiced concerns about the Verizon iPhone's reception. "I will note, though, that Verizon is above average in our satisfaction surveys," he said.
The bottom line for Consumer Reports? It's not recommending the Verizon iPhone, even though it gave the device a score of 75 out of a possible 100, just one point off the top ranking of 76, which the AT&T iPhone 4, T-Mobile's myTouch 4G and Samsung's Vibrant all received.
"We're not recommending [the Verizon iPhone 4] because it has the potential to drop calls or make it unable to place them if used in a normal way," said Reynolds. "You shouldn't need to a case to use a phone."

Apple invites bug researchers to scrutinize Lion OS

Apple invites bug researchers to scrutinize Lion OS
But security experts who accept must keep findings secret
Apple is offering security experts a copy of the developer preview of Mac OS X 10.7, aka Lion, and asking them for feedback.
Several prominent Mac security researchers have reported that they received invitations to try out the Lion preview, which Apple issued Thursday.
"Apple has invited me to look at the Lion developer preview," said Dino Dai Zovi in a tweet yesterday. "I won't be able to comment on it until its release, but hooray for free access!"
Charlie Miller, an analyst with Baltimore-based consulting firm Independent Security Evaluators (ISE) and Dai Zovi's co-author, confirmed today that he had also received an invitation to try out Lion.
The preview comes with a non-disclosure agreement (NDA) that prevents Zovi, Miller and others from commenting publicly about what they find. But Apple has asked for feedback and provided researchers an e-mail address to report vulnerabilities or other issues, said Miller.
"They've never done this before," noted Miller in an interview today. "That they're thinking of reaching out [to researchers] is a good positive step, but whether it makes a difference, I'll believe it when I see it."
Miller has been critical of Apple's security practices in the past, saying in 2008 that Mac OS X was an easier target at the time than either Windows or Linux.
Miller has proven his point at the last three Pwn2Own hacking contests by walking away with cash prizes and laptops for exploiting vulnerabilities in Mac OS X and Safari, Apple's browser. Miller is slated to tackle Safari and Apple's iPhone on March 9 at this year's Pwn2Own.
Other researchers have heard the news, if not received an invitation to the preview, and given their two cents on expectation for security improvements.
"I doubt we'll see any real security innovation in Lion," opined Alexander Sotirov on Twitter. And in a later tweet aimed at Miller, Sotirov said, "I'm sure we'll see improvements in Lion, perhaps even full ASLR. But that doesn't count as 'innovation' in 2011."
Sotirov is an independent security researcher, who with Miller and Dai Zovi, launched a 2010 effort they dubbed "No Free Bugs" that proposed researchers should be paid for their work because vulnerabilities have value.
ASLR, or "address space layout randomization," is an anti-exploit technology that randomly assigns data to memory to make it tougher for attackers to determine the location of critical operating system functions, and thus make it harder for them to craft reliable exploits.
Windows, for example, leans on ASLR, but Apple's current operating system -- 2009's Snow Leopard -- relies on partial ASLR that doesn't randomize important components of the OS. Microsoft has included ASLR in Windows since Vista's late 2007 debut.
After Snow Leopard's August 2009 launch, Miller said Apple missed the security boat by not fully implementing ASLR.
Apple has not disclosed a ship date for Lion -- saying only that it will be available "this summer" -- or its price. Historically, the company has priced its operating system upgrades at $129 for a single license, $149 for a five-license package, although it departed from that practice with Snow Leopard when it priced Mac OS X 10.6 at $29 and $49, respectively.

Thursday, February 24, 2011

Large Hadron Collider powers up to unravel mysteries of nature

Physicists at CERN rob hydrogen atoms of their protons, compact them into bunches and inject them into the series of four accelerator rings. Each ring in the sequence amplifies the energy of the protons and guides the subatomic particles with powerful magnets. Finally, two proton beams are flung in opposite directions at nearly the speed of light and smashed together at one of four detectors. Then the sparks fly. Credit: Justin Eure/MEDILL
Outside the small village of Meyrin, Switzerland, horses graze quietly in fields lined by the Jura mountains. You'd never know it by the idyllic landscape, but 300 feet below the Swiss-French border, the Large Hadron Collider is searching for the secrets of the universe. A 17-mile circular tunnel houses the world’s largest atom smasher that is once again firing high-energy proton beams.
On Monday, the CERN Control Center turned on the LHC beams to begin the next two-year run of the particle collider. CERN directors decided to extend the run through the end of 2012, instead of shutting down in 2011 for repairs as previously planned, and spirits are running high among scientists working in the field of new physics.
Researchers from across the world engineer detectors and seek to solve the mysteries of matter in an international collaboration that reaches from Chicago to Mumbai.
“Recently there was a convention in Chamonix,” said Georgios Choudalakis, a Greek physicist on the ATLAS experiment at the LHC. “The heads of the experiments and the director of the laboratory decided that we will take data for 2 years. And the decisive criterion for this was the sensitivity to the Higgs, so we’re optimistic.”
The search is on for the Higgs! The international team of scientists at CERN recalls the bumpy history of the Large Hadron Collider, from disastrous delays to recent results that are exceeding expectations. The physicists anticipate breakthroughs in the next two years that will change our fundamental understanding of the universe. Video credit: Chelsea Whyte and Justin Eure/MEDILL.
This comes on the heels of the news that 2011 will be the end of the run for the Tevatron, the second most powerful particle collider in the world located at the Fermi National Laboratory in Batavia. After setbacks and shutdowns, the LHC had collisions in 2010 that went even better than expected. “We made it clear even to ourselves that the page has turned,” said Choudalakis. “The energy frontier is not at the Tevatron anymore. We are cutting more ice here.”
Now, the hunt for the Higgs is on at CERN, the Conseil Européen pour la Recherche Nucléaire.
The elusive Higgs particle is, according to the theory, a fundamental building block of matter and the reason everything has mass.
“Nobody can explain where mass comes from, but we know it’s there,” said Pauline Gagnon, a French physicist at the ATLAS experiment. This conundrum is the most important question physicists have to answer, she said.
“If you think of a one pound bag of salt and you add up the weights of each grain of salt, they will logically equal one pound,” said Gagnon. But, when physicists break down atoms in this way and try to determine the weight of the pieces inside, the calculations of the weight of atomic building blocks such as quarks and electrons don’t add up, she said. Here’s where the Higgs comes in.

Google turns up the enterprise collab heat on Microsoft

Google will intensify its attack on Microsoft's enterprise collaboration business with the release on Thursday of the Cloud Connect plug-in for Microsoft Office and with the launch of a trial program for the collaboration components of Google Apps.
In limited release since November, Cloud Connect is now available to all Microsoft Office 2003, 2007 and 2010 users who also have an individual Google account or a Google Apps account.
Based on technology from DocVerse, a company that Google acquired about a year ago, the Cloud Connect plug-in lets Office users share and collaboratively edit their documents by storing them on Google's cloud infrastructure but without leaving the Office interface.
Once stored on Google servers, Office documents receive a unique URL and pop into their author's Google Docs file list. Cloud Connect tracks changes and edits made to documents and lets users revert to previous versions.
Because users work at all times with the Microsoft software, documents don't need to be converted to Google Docs, avoiding formatting problems.
Docs, a hosted office productivity suite freely available with an individual Google account, competes with the Office desktop suite and with its online companion Office Web Apps, which does allow for cloud-based collaboration.
Docs is also part of Google Apps, a free, hosted collaboration and communication suite that competes with Microsoft Exchange through its Gmail component. Apps is free, except its Business edition, which costs $50 per user per year.
Apps also competes against Microsoft's BPOS (Business Productivity Online Suite), a hosted suite that includes online versions of Exchange 2007, SharePoint 2007 and Office Communications Online but not Office Web Apps.
Microsoft plans to ship this year a BPOS upgrade called Office 365 with online versions of Exchange 2010, SharePoint 2010 and Office Communications Server 2010 (renamed Lync). It also comes with Office Web Apps, and in some configurations includes the full-featured Office 2010 offered on a hosted, subscription basis.
Clearly, in Google's ideal world there would be no need for Cloud Connect because everyone would use Apps instead of Office, Exchange and SharePoint.
To that end, Google is also launching on Thursday a 90-day trial program called Appsperience for organizations to test drive the collaboration components in Apps, such as Docs and the Sites website builder.
The program doesn't include Gmail, but organizations that sign up for Apps at the end of the trial period do get the full suite, including Gmail.
The program costs $7,000 for organizations with 500 users or less, and $15,000 for those with more than 500 users. Google and its reseller partners will actively help participating organizations get set up and trained on using the Apps collaboration components.
The program includes access to a new usage analytics dashboard that Google is also rolling out to all Apps for Business and Apps for Education customers.
The dashboard provides granular stats on Apps usage patterns within an organization, so that administrators in the trial program can eventually decide how many Apps licenses they truly need.
At first, organizations were drawn to Apps mostly by Gmail, but in the past two years, Google has seen a spike in interest and usage of Docs and Sites, said Jeremy Milo, Google Apps product marketing manager.
"That's what sparked the idea for this program," Milo said.
The general availability of Cloud Connect is expected to boost this trend even further, he said.
Industry analyst Rebecca Wettemann from Nucleus Research sees the two-punch announcement as a serious escalation of the collaboration wars between Google and Microsoft.
"This highlights the diminishing benefit of Office upgrades and it's likely to make companies reconsider their Office strategy. If everyone needs collaboration, and only power users need all the capabilities of Office, why buy both Google and Office for everyone?," she said via e-mail.
"We see the enterprise search space in three tiers: Web, desktop, and enterprise application. Google already owns the Web, this gives them more opportunity on the desktop," Wettemann added.

Hacker claims credit for knocking church's site offline

Twitter post suggests 'The Jester' may have been responsible for knocking controversial church offline
A Twitter message from Monday suggests that a seld-proclaimed "hacktivist" using the handle The Jester may have been responsible for knocking the controversial Westboro Baptist Church offline.
In the message, the hacker claimed to have temporarily taken down the public website of the church "for celebrating the death of U.S. troops."
The message, however, made no direct mention if The Jester (@th3j35t3r on Twitter) was also responsible for the unavailability today of several other websites affiliated to the WBC.
Members of the WBC church, based in Topeka, Kan., are known for their strident anti-gay views and for protests at funerals of slain military personnel and others.
Last week, someone purporting to be from the hacking collective known as Anonymous, posted a letter on an Anonymous site, warning WBC members of attacks against their church public websites if they did not stop their protests.
The letter lamented the "inimitable bigotry and intolerant fanaticism" of the protesters and warned of online attacks that the church would not be able to withstand or recover from.
That letter was later dismissed as a hoax by Anonymous, which has been involved in several high-profile attacks recently, including one against the security firm HBGary.
Shirley Phelps-Roper of the Westboro Church today said such attacks are not unusual for the church.
"Every time we look up somebody is doing something to us," she said claiming that in the past the church's website has been attacked by hackers not just from the U.S. but also from other countries such as the Netherlands and New Zealand. "All such attacks do is to cause somebody to look at us," she said.
She attributed the latest attack on the military but offered no explanation for her claim.
This morning, all of the church's sites were unavailable. It is not immediately clear how long the sites have been down and what role, if any, The Jester or Anonymous may have played. There has been no response yet from Anonymous members.
The Jester, previously claimed responsibility for launching distributed denial of service attacks against WikiLeaks last year in response to what it claimed was WikiLeaks' role in endangering the lives of U.S. troops.

Update: Firefox update will patch CSRF bug, Mozilla says

Delayed Firefox 3.6.14, 3.5.17 to ship March 1, fix cross-site request forgery bug that can be exploited via Flash
Mozilla said late Wednesday that it will ship security updates to Firefox 3.5 and Firefox 3.6 next week that will include a patch for a bug that can be exploited using a malicious Adobe Flash file.
(Editor's note: An earlier version of this story, published before Mozilla responded to a request for comment, said company meeting notes suggested that the Firefox security updates would not include the patch.)
Firefox 3.5.17 and Firefox 3.6.14 will now appear Tuesday, March 1, Mozilla disclosed in meeting notes published today.
Originally slated for release Feb. 14, the security updates were held while Mozilla developers investigated a bug that affected some, though not all, users of the betas. According to Mozilla, the bug caused some copies of the updates to repeatedly crash. Mozilla then backed out a recent fix to retest the betas.
Around the same time, another problem -- a separate cross-site request forgery (CSRF) vulnerability -- surfaced that Mozilla needed to patch. "Adobe is pressing for a release due to a public CSRF issue," Mozilla said last week.
The vulnerability is in Firefox, but Adobe's involved because the vulnerability can be exploited using a malformed Flash file.
According to patch information posted Feb. 8 by the open-source Ruby on Rails Web development framework, and a follow-up message two days later on a security mailing list, the CSRF bug can be exploited by "Certain combinations of browser plug-ins and HTTP redirects."
An attacker could exploit the vulnerability to bypass the built-in CSRF protections of Ruby on Rails -- and that of Django, another Web development platform, which also patched its products earlier this month -- and successfully attack a Web application built with those tools.
The security mailing list message posted Feb. 10 spelled out several affected browsers, including Firefox -- including an earlier beta of Firefox 4 -- as well as Google's Chrome and Apple's Safari on both Windows and Mac OS.
That same message also said that a Google security researcher had first reported the CSRF vulnerability.
Last week, an Adobe spokeswoman said she knew nothing about a potential zero-day that would impact its software and/or Firefox.
Mozilla will patch the CSRF flaw in both Firefox 2.5.17 and Firefox 3.6.14 when they ship next week, a spokeswoman for that company confirmed late Wednesday.
The timing of the update may help Firefox survive the Pwn2Own, the hacking contest that kicks off March 9 at the CanSecWest security conference in Vancouver, British Columbia.
Firefox will be one of four browsers -- the others are Chrome, Safari and Microsoft's Internet Explorer -- that will be targeted by attackers hoping to walk off with $15,000 or $20,000 in cash. Pwn2Own's rules state that the targeted browsers will be "the latest release candidate at the time of the contest," meaning that researchers will have to tackle Firefox 3.6.14.
Last year, Mozilla confirmed a critical vulnerability in Firefox less than a week before 2010's Pwn2Own, but said it wouldn't fix the flaw until after the contest. Pwn2Own organizers then ruled that hackers would not be allowed to use the vulnerability to exploit Firefox.