Tuesday, September 24, 2013

Google fixes lengthy, widespread Gmail malfunction

A Gmail glitch that took about 10 hours to fix and hit close to 50 percent of the webmail service's users has been fixed, ending one of the longest, most widespread Gmail disruptions in years.

Affected users endured email delivery delays and difficulties downloading attachments due to a still unexplained bug first acknowledged by Google at around 10:30 a.m. U.S. Eastern Time Monday. The company declared it patched at 10 p.m.

On its Google Apps Status site, the company pegged the start of the problem at close to 9 a.m. and its resolution at 6:30 p.m.

The issue affected individuals who use the free version of Gmail as well as businesses, schools and government agencies that pay for it as part of the Google Apps cloud collaboration and email suite.

In the U.S., the disruption covered most of the workday on both coasts, which heightened the impact of the bug for millions.

People who depend on Gmail for critical tasks took to Twitter, discussion groups and other online forums to express their frustration.

The last time Google gave an official figure for active Gmail users was more than a year ago, when it said there were more than 425 million.

Assuming conservatively that the service now has about 450 million active users, Monday's disruption likely affected more than 200 million users, plus senders on other email platforms whose messages weren't received in a timely fashion.

Google said that the severity and length of the impact varied among users. About 29 percent of messages received were delayed by an average of 2.6 seconds, but some mail was "severely delayed."

"We apologize for the duration of today's event; we're aware that prompt email delivery is an important part of the Gmail experience, and today's experience fell far short of our standards," the company wrote on the status site.

The incident is a big deal for both Google and those affected, but it shouldn't on its own dissuade CIOs from using the suite, said Forrester Research analyst TJ Keitt.

"Data centers hosting multi-tenant collaboration services aren't immune to disruptions. So, when they happen, the way to judge the vendor is on how well they identify and resolve the problem, and then inform the public to how they resolved the issue," Keitt said.

Using that criteria, Google's updates throughout the duration of the incident could have been more transparent and detailed regarding the nature of the problem and the strength of the fix that was put in place, he said via email.

"They have clearly not communicated this publicly, so I hope they've been forthcoming with this information with their clients," Keitt said.

Meanwhile, Matthew Cain, a Gartner analyst, said the incident raises fundamental questions about what is considered downtime, especially as it relates to service-level agreements from cloud application vendors.

"If message delivery is delayed 15 minutes, is that considered downtime? What about 2 hours?," he said via email. "The move to cloud email puts a spotlight on these essential questions about how to meter and compensate for subpar messaging performance that is not traditionally classified as 'downtime.'"

Juan Carlos Perez covers enterprise communication/collaboration suites, operating systems, browsers and general technology breaking news for The IDG News Service. Follow Juan on Twitter at @JuanCPerezIDG.

Chrome will block NPAPI plug-ins over stability, security concerns

Plug-ins based on the NPAPI architecture will be blocked by default in Chrome starting early next year as Google moves toward completely removing support for them in the browser.

"NPAPI's 90s-era architecture has become a leading cause of hangs, crashes, security incidents, and code complexity," Justin Schuh, a Google Chrome security engineer, said Monday in a blog post. "Because of this, Chrome will be phasing out NPAPI support over the coming year."

First developed for Netscape, NPAPI (Netscape Plug-in Application Programming Interface) has long been the most popular plug-in architecture, supported by browsers like Mozilla Firefox, Google Chrome, Apple Safari, Opera and Konqueror.

However, NPAPI's security shortcomings, like the fact that it spawns processes with privileged access to the underlying operating system, have in recent years led to a surge in attacks that exploit vulnerabilities in browser plug-ins to silently install malware on computers when users visit compromised or malicious websites. Google, Mozilla and Opera responded to this threat by implementing click-to-play, an optional feature that prompts users for confirmation before executing plug-in based content.

Google went even further and in 2010, the company started developing a new plug-in architecture called PPAPI (Pepper Plugin API) or simply Pepper, that forces plug-in code to run securely inside a sandbox and makes it less susceptible to crashes.

In August 2012, following two years of collaborative work with Adobe, Google switched the Flash Player plug-in bundled with Chrome for Windows from NPAPI to PPAPI. One month later it did the same for Chrome on Mac OS X.

While click-to-play has been available in Chrome for several years, the feature has not been enabled by default, except for a number of plug-ins that Google considered to present a higher security risk, like Java, RealPlayer, QuickTime, Shockwave, Windows Media Player and Adobe Reader prior to Adobe Reader X. That policy will soon change.

"Starting in January 2014, Chrome will block webpage-instantiated NPAPI plug-ins by default on the Stable channel," Schuh said. A temporary exception will be made for the most popular NPAPI plug-ins that are not already being blocked for security reasons in order to avoid disruption to users, he said.

The plug-ins that will be temporarily whitelisted will be Silverlight, Unity, Google Earth, Google Talk and Facebook Video, as they were used by more than 5 percent of users during the past month. Java was used by almost 9 percent of users, but it's already on the list of blocked plug-ins.

"In the short term, end users and enterprise administrators will be able to whitelist specific plug-ins," Schuh said. "Eventually, however, NPAPI support will be completely removed from Chrome."

That is expected to happen before the end of 2014, but the process of phasing out NPAPI support has already begun. Starting Monday, no new NPAPI-based apps or extensions will be accepted into the Chrome Web Store, the central repository for Chrome apps and extensions.

"Developers will be able to update their existing NPAPI-based Apps and Extensions until May 2014, when they will be removed from the Web Store home page, search results, and category pages," Schuh said. "In September 2014, all existing NPAPI-based Apps and Extensions will be unpublished. Existing installations will continue to work until Chrome fully removes support for NPAPI."

Schuh also noted that Mozilla plans to start blocking NPAPI plug-ins by default in December 2013 with the release of Firefox 26.

Mozilla already blocks some outdated plug-ins that pose security risks and in January announced plans to block all plug-ins except for the most recent version of Flash Player once its work on the click-to-play user interface is complete. The Firefox click-to-play feature is still in beta testing stages and can only be enabled at this time by accessing the browser's advanced about:config options.

It's not clear if Mozilla also plans to completely remove support for NPAPI plug-ins from Firefox in the future. A representative was not able to immediately clarify the situation.

Cancel data sharing deal with US, EU politicians urge

European politicians on Tuesday demanded that a broad data-sharing agreement between the U.S. and the European Union be suspended, following allegations that the U.S. National Security Agency illegally tapped banking data.

The Terrorist Finance Tracking Program (TFTP) allows the U.S. Treasury to access some data stored in Europe by Swift, the international banking transfer company. But allegations that the NSA accessed this data without going through legal channels has led some members of the European Parliament (MEPs) to declare the agreement defunct.

None of those present at the Civil Liberties Committee's Tuesday hearing on U.S. and E.U. countries' surveillance plans had evidence that the NSA has actually breached Swift. The latest allegations are based on documents leaked by whistleblower Edward Snowden that indicate the NSA spied on Swift. According to the documents, Swift is included in an NSA training manual for new agents on how to target private computer networks.

Dutch MEP Sophie in't Veld told the hearing that she considered the agreement "effectively dead."

"We have no evidence that they have actually been doing this, but they don't deny it either. So in a way it is irrelevant whether they have used the opportunity so far, because they will continue to reserve that right in the future," she said, calling for the accord to be terminated.

Fellow MEPs Claude Moraes and Alexander Alvaro also called for suspension as a "minimum option."

Home Affairs Commissioner Cecilia Malmström said that she had requested formal consultations with the U.S. under Article 19 of the TFTP agreement -- a first step toward suspension of the deal.

She said she had written to U.S. Treasury Under-Secretary David Cohen on Sept. 12 to ask for the "how, what and when" on the spying allegations, but that she was not satisfied with the responses.

"The TFTP agreement with the U.S. was negotiated precisely to avoid that personal data of EU citizens are exposed without legal guarantees or safeguards," Malmström pointed out. "We have made that very clear, that if those allegations are true, they constitute a breach of the agreement and the breach of the agreement can certainly lead to a suspension."

There were however some voices of dissent. "At this point we cannot simply withdraw from the deal," said German MEP Axel Voss.

"We have no information that would indicate that the NSA has additional direct access to the data operated by Swift," said Rob Wainwright, director of the E.U.'s police agency, Europol. However, he added that "because of the nature of the way in which we work, it's unlikely that Europol would have this information anyhow."

Likewise, Swift's general counsel Blanche Petre said there was no evidence to suggest that there has been any unauthorized access to the data, but added she would be "extremely concerned" if this proved to be the case. "Whenever we believe there is any risk to security of our services we will investigate and take whatever actions we think appropriate to mitigate the risk," she added.

A third annual review of the TFTP program took place last month, and results have not yet been published. However the second review sparked anger among MEPs last year when it revealed that U.S. requests for European banking data were too vague to assess whether they meet E.U. data standards. But Europol still approved them.

The TFTP agreement was controversial from the start with Parliament only reluctantly agreeing to it in 2010. The European Parliament inquiry is due to present its report on surveillance by the end of this year

Follow Jennifer on Twitter at @BrusselsGeek or email tips and comments to jennifer_baker@idg.com.

Red Hat serves middleware to cloud developers

In a move to jump ahead of other PaaS (platform as a service) providers in the enterprise space, Red Hat will augment its OpenShift offering with a suite of middleware to ease the process of deploying cloud-based applications.

"The needs of a traditional enterprise developer go beyond what a person writing a simple Web app needs," said Jim Whitehurst, CEO of Red Hat. "They need orchestration, mediation, messaging, integration. No PaaS offers all those services today. We have those technologies in our JBoss portfolio."

Over the course of the next year, Red Hat will introduce new services into OpenShift for messaging, for running server-based applications, for business process modeling and for communicating with mobile clients. The technology will be used in Red Hat's JBoss suite of middleware software.

Such services, which Red Hat calls xPaaS, will be available to use as cartridges alongside OpenShift's selection of languages, databases and frameworks, which include JavaScript, PHP, Python, Java, MySQL, PostgreSQL and node.js.

While competitors such as Heroku, Google App Engine, and Cloud Foundry have been adding to their arsenals of supported languages and developer tools, Red Hat's introduction of enterprise middleware services is relatively novel for the PaaS space. Though it is not unprecedented: On Monday, Java PaaS provider CloudBees launched a set of tools that would allow enterprises to link on-premise applications with their CloudBees deployments, through the use of VPN (virtual private networking), authentication mechanisms and publish-and-subscribe tools.

The core JBoss application server will be the first cartridge made available on OpenShift. It can cover traditional EAP (enterprise application platform) duties such as handling transactions and persistence.

The messaging cartridge will be based on Red Hat's Fuse enterprise service bus (ESB), which was built from the Apache Camel open source project.

A BPM (Business Process Management) cartridge will be based on technology Red Hat acquired in its 2012 purchase of Polymita. It will provide a way to perform business activity monitoring, process simulation, dynamic workflow configuration and other functionality for understanding how applications operate.

Red Hat will also build new software for OpenShift to help applications communicate with mobile devices. It will offer push notifications, which have been a burdensome feature for developers to write from scratch.

Fellow Linux distributor SUSE also has been updating its cloud stack, refreshing its SUSE Cloud OpenStack package. SUSE Cloud now runs the latest version of OpenStack, named Grizzly, which includes the newly added block storage and networking modules. SUSE Cloud can now also work with Microsoft Hyper-V, making it the first OpenStack distribution to work with the Microsoft hypervisor.

Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is Joab_Jackson@idg.com

Microsoft eyes China's gaming market with new joint venture

Microsoft is entering China's gaming market with a new joint venture, the latest sign that its Xbox console soon arrive in the country.

Microsoft established the joint venture with BesTV, a local provider of Internet television services, according to a stock exchange filing the Chinese company made on Tuesday. The venture's core business will focus on "a new generation of family gaming entertainment technology, devices, content, and services."

No mention of the Xbox name was made in the stock exchange filing. But the venture's business scope also includes game development and operating third-party games and entertainment software. In addition, the venture will push a "one cloud multiple screens" technology.

BesTV, a subsidiary of Shanghai Media Group, will have a controlling stake in the venture at 51 percent, while Microsoft holds the remainder. The total investment will reach US$237 million.

Microsoft declined to say what role, if any, its Xbox product would have in the joint venture. But in an email, the company said the deal was made "to explore new opportunities in Shanghai and China."

"We believe there is great market potential and partnership opportunities here and look forward to sharing more details soon," the company said. "This is the first step of many to come for Microsoft and BesTV."

Earlier this year, Microsoft unveiled its upcoming Xbox One console, a product meant to be both a gaming and home entertainment device. It will launch in the U.S. in November.

Many gaming consoles, however, have long been banned in China, as part of government regulations meant to protect children. But despite the official ban, the products have still thrived in the country's gray market, where local merchants often import Xbox 360s and Sony PlayStation 3s bought in Japan.

Microsoft has spent years trying to gain China's permission to sell its gaming console directly in the country, a task that has involved getting approval from various regulators.

The company's joint venture, however, is being established in a new free trade zone located in Shanghai that is meant to attract more foreign investment. Exact regulations of the zone are still unclear, but it could offer more open policies on trade.

The free trade zone will launch on Sept. 29, according to the Chinese state press.

Demand for cyber security advice helps fuel Ernst & Young hiring spree

Companies increasingly seeking advice on issues such as cyber security has led to professional services firm Ernst & Young's (EY) latest recruitment drive.

In the UK, EY is looking to hire 2,400 experienced people in the next 12 months, to meet growing demand from its clients for advisory services. It will also hire 700 graduates, 500 undergraduates and 150 school leavers.

"Demand is being driven by companies seeking advice on a whole range of issues, from managing the growing threat of cyber security - one of the hottest issues for UK plc this year - to working with fast-growth markets and adapting to on-going regulatory changes as a result of the financial crisis," an EY spokesperson said.

Related Articles on Techworld

She added: "There is also a high demand for advisory services to the financial services industry."

Banks such as Barclays and Santander have recently hit the headlines for being attacked by cyber criminals attempting to steal money using remote computer devices.

EY started its recruitment process on 1 July 2013, the start of its financial year. It is also increasing its workforce in line with ambitious growth plans set out in its global strategy.

Cisco to launch new Catalyst access switch

Cisco is set to unveil a new Catalyst access switch designed to converge wired and wireless networking.

The Catalyst 3650 features line rate 24 and 48 Gigabit Ethernet ports and an integrated wireless controller. It can be stacked in groups of nine switches for support of up to 25 access points and 1,000 clients at 40Gbps.

Stacking bandwidth is 160Gbps.

Related Articles on Techworld

Uplinks on the switch include 4 x1G, 2 x 10G or 4 x 10G fixed ports. It features native support for NetFlow analytics on all ports, and full Layer 3 routing capabilities, as well as eight queues per port for priority and quality-of-service.

The 3650 includes Cisco's new Universal Access Data Plane (UADP) ASIC that debuted with the Catalyst 3850 early this year. It runs the company's IOS XE operating system.

The switch also features PoE+ for powering external voice, video and wireless gear, and a multicore CPU for hosted services. It also supports Cisco's TrustSec role-base security architecture and SmartOperations for network planning, deployment, monitoring and troubleshooting.

The 3650 also supports Cisco's Application Visibility and Control deep packet inspection technology, and are MACSec "ready," meaning they will eventually support the IEEE 802.1ae "MACSec" data encryption standard.

The Catalyst 3650 will be available in October at the same price points as Cisco's 3560-X switch -- $3,400 -- which the company will continue to offer.

The 3650 will compete with other 24/48-port stackable Gigabit Ethernet PoE+ switches from HP, Dell, Extreme/Enterasys, Juniper and Brocade.