Microsoft greasing Windows 7 skids with early release of desktop tools

With the hope of sparking Windows 7 upgrades, Microsoft is planning an early release of its suite of desktop deployment tools.  The tools were originally slated to ship in early 2010, but Microsoft hopes to give customers the software in late October for use in rollouts of Windows 7 across corporate desktops. The news of the early release was announced by Ran Oelgiesser, senior product manager for MED-V, on the MDOP blog. The catch is that the Microsoft Desktop Optimization Pack (MDOP) R2 2009 is only available to volume licensing customers with Software Assurance contracts.

Slideshow: Snow Leopard vs. All the tools in MDOP R2 2009 will include support for Windows 7 except MED-V. Support for the new OS in MED-V 1.0 SP1 will come early in 2010, wrote Oelgiesser. Windows 7 Windows 7 is slated to ship to commercial customers on Oct. 22, but corporate users with volume licensing contracts have had access to Windows 7 since last month. MED-V runs multiple versions of Windows or applications concurrently without having to open multiple virtual machine sessions. The suite is a major part of Microsoft 's Optimized Desktop strategy, which addresses centralized management and deployment of physical and virtual resources. The software complements another MDOP tool called App-V, which is used for managing and deploying virtual PCs. The MDOP lineup also includes Asset Inventory Service; System Center Desktop Error Monitoring; Advanced Group Policy Management (AGPM) for change management via group policy objects; and the Diagnostics and Recovery Toolset, which helps in recovering a crashed PC. MDOP is composed of software from Microsoft's purchases of Softricity, Kidaro, AssetMetrix, Winternals Software and DesktopStandard.

According to Oelgiesser, App-V 4.5 SP1 will have various integration points with 32-bit versions of Windows 7, including with the AppLocker, Branch Cache and BitLocker ToGo features. The 64-bit version, App-V 4.6 will be available in the first half of 2010. Advanced Group Policy Management 4.0 features two new capabilities targeted at Windows 7. One allows users to manage group policies across different domains, and the other provides new search and filtering to ease tracking of group policy objects. In addition, the software will support 32-bit version of XP, Vista and Windows Server. Follow John Fontana on Twitter 

US company burned by China Web filter plans rival product

A U.S. company whose software code was allegedly stolen in China by a controversial, government-backed Internet filtering program will hit back by launching a rival product for a low price in China, the company said late Sunday. The Solid Oak program, called CyberSitter and targeted at parents, will be offered in languages including Chinese in a version due out next month. Solid Oak Software, which has said its code was copied in a program that China ordered be bundled with all new PCs, is exploring ways to offer its own Web filter for free or at a very low price in China, company President Brian Milburn, said in an e-mail.

A Chinese version of the product would compete with Green Dam Youth Escort, the program that Solid Oak says copied its code and that China originally ordered PC makers to include with all new computers sold in the country from July this year. But under heavy pressure from foreign PC makers and the U.S. government, China indefinitely postponed the mandate just hours before it was set to take effect. The Chinese government had paid the program's developers to allow all PC buyers to use the software for free for one year. Major PC makers including Lenovo and Acer began bundling Green Dam with new PCs until this month. The program also used blacklists apparently lifted from Solid Oak's software, according to the company and a group of U.S. researchers.

The program, which China said was meant to protect children from online pornography, was also found to block politically sensitive material such as negative references to a former Chinese president. One file found in the Chinese program contained an encrypted version of a years-old Solid Oak news bulletin, according to the researchers. Green Dam came under fire for concerns about system stability in addition to user privacy and freedom of speech. Solid Oak, which is based in Santa Barbara, California, is preparing legal action against PC makers that shipped Green Dam, though an update to the program in June removed some of the allegedly infringing elements. One Beijing high school recently removed the program from its computers after finding that it conflicted with software used for grading and attendance tracking.

Bryan Zhang, general manager of Jinhui Computer System Engineering, one of the designers of the Chinese software, declined to comment on the allegations of code theft. Green Dam "is a conglomeration of whatever components [the developers] managed to steal ... or otherwise appropriate from various sources, and duct tape together in the form of an alleged piece of software," Milburn wrote in his e-mail. "They should be utterly humiliated, not just because they stole much of the core functionality, but even more so because they intentionally inflicted such a miserable product on a population of innocent computer users," Milburn wrote. The new Solid Oak product will have a Chinese user interface available and a filtering function that the company reworked after much of its old proprietary code appeared online. That is the ultimate goal," company spokeswoman Jenna DiPasquale said in an e-mail. The filtering will be entirely URL-based, avoiding the need to translate keywords into Chinese. "We are working on a way to release it for free.

Perot wins key health-care IT outsourcing deal in India

Perot Systems has bagged a 10-year IT outsourcing contract in India, its first outside the U.S. The win reflects Perot's bid to grow its health-care business in markets other than the U.S., as well as in emerging markets like India, China, Brazil, and Mexico, company executives said on Friday. But only 4.1 percent of the company's revenue from the health-care industry was from outside the U.S., up from 2.5 percent two years ago, said Kevin Fickenscher, executive vice president for International Healthcare at Perot, in a telephone interview. In the second quarter, 48 percent of Perot's revenue came from the health-care industry.

Expansion outside the U.S. is a key focus area for Perot, said Raj Asava, Perot's chief strategy officer. The maturing health-care industry in these emerging markets has a big appetite and also funds to invest in technologies such as electronic health records and clinical information systems, Asava said. For its health-care business, the company is targeting emerging markets in the Middle East, China, India, and Latin America, besides more mature markets such as the U.K. and Germany. The contract with Max Healthcare, a large hospital chain in India, has an initial value of US$18 million, but could go up in value as more applications and services are added, Perot said. The deployment will be around the open source VistA (Veterans Health Information Systems and Technology Architecture) electronic health record and health information system, he added.

Besides running the applications already installed at Max, Perot will also deploy an electronic health records system and other IT infrastructure, Fickenscher said. Perot already has a services subsidiary in India with about 9,000 staff that offer outsourcing services to customers in the U.S., Europe, and other parts of the world. Multinational and Indian service providers are targeting India's growing services market, including in the telecommunications sector where a number of mobile service providers are outsourcing their IT infrastructure. About 60 percent of these staff do work for the health-care industry. The immediate opportunity for vendors of IT targeting the health-care industry is from private sector providers, but government run hospitals will soon follow, Fickenscher said.

Fugitive hacker headed back to U.S. for arraignment

A Miami man who for three years had evaded prosecution in connection with the theft and reselling of VoIP services is being extradited to Newark from Mexico today and is set to be arraigned in a New jersey federal courthouse on Friday. He had been free on $100,000 bail. Edwin Pena, 26, had been arrested in June, 2006, on multiple computer and wire fraud charges, and then allegedly fled the country about two months later.

Pena was apprehended in Mexico in February and federal prosecutors have been working to get him extradited back to the U.S. since then, according to Assistant U.S. Attorney Erez Liebermann . "He's been a fugitive for over three years," said Liebermann, who is prosecuting the case. "We're looking forward to proceeding with the prosecution." Pena faces 20 charges that include conspiracy to commit computer intrusion and conspiracy to commit wire fraud charge. According to a criminal complaint filed in U.S. District Court in New Jersey, Pena and co-conspirator Robert Moore of Spokane, Wash., sold more than 10 million minutes of VoIP service that had been stolen from 15 telecommunications providers. The U.S. alleges that from November 2004 to May 2006 Pena and a cohort hacked into the computer networks of VoIP service providers and routed calls made by customers of Pena's VoIP service through them. Prosecutors have contended that the lost minutes were valed at $1.4 million to the providers victimized in the alleged scam. In the fall of 2007, Moore pleaded guilty to conspiracy to commit computer fraud and began a two-year prison sentence. Federal investigators contend that Pena was the mastermind behind the scheme and Moore hacked the systems.

Voice-over-IP systems route telephone calls over the Internet or other IP-based networks. The complaint alleges that once Moore found unsecured networks, he would then e-mail Pena the key information needed to access vulnerable networks. Moore scanned telecommunications company networks around the world, searching for unsecured ports - the criminal complaint said that between June 2005 and October 2005, Moore ran more than 6 million scans of network ports within the AT&T network alone. Once the networks were accessed, prosecutors allege that Pena ran brute force attacks to find the proprietary codes needed to identify and accept authorized calls coming into the networks. According to court documents, Pena gained more than $1 million from the scheme. He allegedly would used the codes to surreptitiously route his clients' calls through the systems.

Some was spent to buy real estate in Miami, a 40-foot boat and luxury cars, including a BMW M3 and a Cadillac Escalade.

Meet Nook, Barnes & Noble's e-book reader

On Tuesday, Barnes & Noble announced that the Nook, the company's e-book reader that aims to compete with Amazon's Kindle, is available for pre-order. That ancillary screen is used to navigate books via a Cover Flow-like interface, display an on-screen keyboard, and generally operate the device. It's a very interesting device: the first dedicated e-book reader that is powered by Google's Android operating system (it runs Android 1.5). The Nook should ship at the end of November and it'll cost you $259. That's the same price as the Kindle 2, though an international Kindle 2 that allows wireless access outside of the U.S. costs $279. (The nook doesn't include an International option at the moment.) Barnes & Noble's reader has a 6-inch diagonal E Ink display, just like the Kindle 2, but the clever folks at B&N have also added a 3.5-inch color LCD screen below the E Ink screen. The Nook comes with 2GB of internal memory, which Barnes & Noble says will hold about 1500 e-books, though that can be expanded by using the included Micro SD slot.

And should you wish, you can remove the Nook's battery, for fun and profit-and B&N will sell you an extra battery if the 10-day charge without using wireless isn't enough for you. You can even listen to MP3s on the nook, either through the built-in mono speaker or by plugging in headphones. The Nook, again much like the Kindle, comes bundles with wireless 3G access-via AT&T, while the Kindle uses Sprint's network-so you can download content wirelessly. Free samples of all titles will be available and users will be able to access special content when using their nook at a Barnes & Noble store. The Nook ups the wireless ante by also including Wi-Fi connectivity (802.11 b/g) and access to free Wi-Fi in all of Barnes & Noble's stores (which is a very good idea, though it doesn't appear that the Nook has a Web browser, as the Kindle does). An e-reader isn't of much interest without something to read on it, and Barnes & Noble boasts more than a million titles, though many of those are through a partnership with Google to distribute public domain titles; there are newspapers and magazines available as well. You can also read your own PDFs on the Nook, something you can't do with a Kindle 2 without converting the PDF first.

They will be able to read it on their Nook, or using the Barnes & Noble e-reader available for PCs, Macs, the iPhone, some Motorola smartphones, and the BlackBerry. One of the biggest differences between the Nook and Amazon's Kindle is that you can let your friends borrow a Nook book for up to 14 days. You can also start reading a book on your Nook, and then keep reading where you left off on your Mac or PC thanks to Barnes & Noble's Reading Now technology, which sounds very much like Amazon's WhisperSync feature. If you want to play around with a Nook in person, you'll be able to do so at any of Barnes & Noble's physical stores, thanks to special Nook displays that should be popping up in the coming weeks.

The other iPhone lie: VPN policy support

It turns out that Apple's iPhone 3.1 OS fix of a serious security issue - falsely reporting to Exchange servers that pre-3G S iPhones and iPod Touches had on-device encryption - wasn't the first such policy falsehood that Apple has quietly fixed in an OS upgrade. Before that update, the iPhone falsely reported its adherence to VPN policies, specifically those that confirm the device is not saving the VPN password (so users are forced to enter it manually). Until the iPhone 3.0 OS update, users could save VPN passwords on their Apple devices, yet the iPhone OS would report to the VPN server that the passwords were not being saved. It fixed a similar lie in its June iPhone OS 3.0 update.

The fact of the iPhones' false reporting of their adherence to Exchange and VPN policies has caused some organizations to revoke or suspend plans for iPhone support, several readers who did not want their names or agencies identified told InfoWorld. Worse, it revealed that Apple's iconic devices have been unknowingly violating such policies for more than a year. "My guess is the original decision to emulate hardware encryption was made at a level where there wasn't much awareness of enterprise IT standards. One reader at a large government agency describes the IT leader there as "being bitten by the change," after taking a risk to support the popular devices. "I guess we will all have to start distrusting Apple," said another reader at a different agency. [ Apple's snafu on the iPhone OS's policy adherence could kill the iPhone's chances of ever being trusted again by IT, argues InfoWorld's Galen Gruman. ] Last week's iPhone OS 3.1 update began correctly reporting the on-device encryption and VPN password-saving status when queried by Exchange and VPN policy servers, which made thousands of iPhones noncompliant with those policies and thus blocked from their networks. (Only the new iPhone 3G S has on-device encryption.) Apple's document on the iPhone OS 3.1 update's security changes neglected to mention this fix, catching users and IT administrators off-guard. After all, this is a foreign language for Apple," says Ezra Gottheil, an analyst at Technology Business Research. "However, once the company realized the problem, it made a spectacularly dumb choice. Instead, it allowed itself to be seen in the worst possible light.

The change was necessary and inevitable, but Apple could have earned some points by coming clean at the earliest opportunity. This is the result of a colossal clash of cultures. Even when it is trying, Apple cannot force itself to think like an enterprise vendor." Apple's advice to users on addressing the Exchange encryption policy issue is to either remove that policy requirement for iPhone users or replace users' devices with the iPhone 3G S. IT organizations can also consider using third-party mobile management tools that enforce security and compliance policies; several now support the iPhone to varying degrees, including those from Good Technology, MobileIron, and Zenprise.

CIA endorses cloud computing, but only internally

WASHINGTON - One of the U.S. government's strongest advocates of cloud computing is also one of its most secretive operations: the Central Intelligence Agency. Jill Tummler Singer, the CIA's deputy CIO, says that she sees enormous benefits to a cloud approach. But the CIA has adopted cloud computing in a big way, and the agency believes that the cloud approach makes IT environments more flexible and secure.

And while the CIA has been moving steadily to build a cloud-friendly infrastructure - it has adopted virtualization, among other things - cloud computing is still a relatively new idea among federal agencies. "Cloud computing as a term really didn't hit our vocabulary until a year ago," said Singer. For example, a cloud approach could bolster security , in part, because it entails the use of a standards-based environment that reduces complexity and allows faster deployment of patches. "By keeping the cloud inside your firewalls, you can focus your strongest intrusion-detection and -prevention sensors on your perimeter, thus gaining significant advantage over the most common attack vector, the Internet," said Singer. But now that the CIA is building an internal cloud, Singer sees numerous benefits. Moreover, everything in a cloud environment is built on common approaches. But there are limits.

That includes security, meaning there's a "consistent approach to assuring the identity, the access and the audit of individuals and systems," said Singer. The agency isn't using a Google model and "striking" data across all its servers; instead, data is kept in private enclaves protected by encryption, security and audits. And it has virtualized storage, protecting itself "against a physical intruder that might be intent on taking your server or your equipment out of the data center," said Singer. The CIA uses mostly Web-based applications and thin clients , reducing the need to administer and secure individual workstations. Speaking at Sys-Con Media's GovIT Expo conference today, Singer not only provided a rare glimpse into the IT approaches used by the agency, but also talked about one of its greatest challenges: the cultural change cloud environments bring to IT. A move to cloud environments "does engender and produce very real human fear that 'I'm going to lose my job,'" she said.

Barry Lynn, the chairman and CEO of cloud computing provider 3tera Inc. in Aliso Viejo, Calif., said a typical environment may have one systems administrator for every 75 physical servers. In practice, highly virtualized environments reduce the need for hardware administration and, consequently, for system administrators. In contrast, a cloud-based environment may have just one administrator for every 500 servers or more. Federal CIO Vivek Kundra is encouraging agencies to adopt cloud computing, and he recently opened an online apps store that enables federal agencies to buy cloud-based services from Google, Salesforce.com and other vendors. The CIA has "seen a significant amount of pushback, slow-rolling [and] big-process engineering efforts to try to build another human-intensive process on top of enterprise cloud computing," said Singer. "It will take us a good long while to break that." One thing the agency will do to address resistance will be to base contract competitions on performance, not head count, "where it's to [a service provider's] benefit to do the work with fewer bodies and make more profit for their company," said Singer.

That's something the CIA will not do; its data will remain within the agency's firewalls, said Singer. Obstacles to the adoption of cloud computing, including concerns about security and loss of data control, may slow momentum, but "I think we'll see broader adoption and higher spending after the administration makes progress in some of the pilot programs it has planned," said Peterson. Government market research firm Input has revised its forecast for federal cloud-related spending upward; it now expects the government's cloud expenditures to grow from $363 million this year to $1.2 billion by 2014. "I think this is probably a conservative estimate, considering the push from the administration," said Deniece Peterson, an analyst at Reston, Va.-based Input. Singer said the CIA's IT department was moving in the direction of cloud computing, even if it wasn't using that term, when it widely deployed virtualization technology. Abstracting the operating system and software from the hardware "is the foundation of the cloud," Singer said. "We were headed to an enterprise cloud all along."