Going thin and bling, HP tries to strike Envy with latest laptops

Hewlett-Packard Co. introduced a half-dozen new notebook PCs today, including a luxury line that bears a striking resemblance to Apple Inc.'s laptops. Overall, two things unify the new models introduced by the world's largest notebook vendor: a skinny, sub-inch profile, and an overt emphasis on design, including metallic shells and imprinted or etched designs on the cases. HP also introduced a thin-and-light Pavilion consumer notebook with an aluminum shell starting at $549, and a new Mini netbook powered by Nvidia Inc.'s ION graphics.

Take the two new high-end notebooks HP is calling its Envy line. The result, as the picture below and PC World's reviewer both confirm, is a machine very similar to Apple's unibody aluminum-encased MacBook Pros. The Envys come encased in sleek gunmetal gray aluminum-magnesium alloy shells, use a low-profile, chiclet-style, backlit keyboard, sport a long-running but nonremoveable lithium-polymer battery, and a bright (410 nits) widescreen. The Envy 13, with a 13-in. screen, is 0.8-inches thick and weighs 3.74 pounds. He likens the strategy to the car industry. "The Envy is like a Lexus, a luxury car that is still affordable to the upper-middle-classes," Kay said.

It starts at $1,699. The Envy 15 starts at $1,799. Fully loaded models of either will cost more than $2,000. Roger Kay, an analyst with EndPoint Technology Associates Inc., is not bothered by HP's strategy of aping Apple's design or its prices. "More than any other vendor, HP has narrowed that gap" with Apple, he said. Dell Inc.'s forthcoming ultra-thin (0.4-inches) Adamo, by contrast, is likely to be priced more "like a Ferrari - only a few people are going to be able to buy them." Besides the Envys, HP rolled out the Pavilion DM3 consumer notebook. It also rolled out a new business notebook, the ProBook 5310M, which starts at $649. HP also introduced a special edition of its HP Mini 110 netbook imprinted with a picture created by a noted European design firm. Tipping in at 1-in. thick and 4.2 pounds, the aluminum-clad Pavilion starts at $549 when equipped with an AMD processor. The HP Mini 110 by Studio Tord Boontje will start at $399. HP also introduced the new HP Mini 311. It comes with a larger-than-average 11.6-inch screen powered by Nvidia's ION multimedia platform. Shim hailed HP's ongoing prowess at taking high-end trends and translating them into products that work at different price points.

The Mini 311 also starts at $399. That pricing appears to be lower than other ION-equipped netbooks, notes Richard Shim, an analyst with IDC Corp. HP has been "pretty successful" going "after a wide audience, from entry-level to high end," he said. "Apple, I would argue, is still just high-end." Most of the notebooks will become available on Oct. 22 the day that Windows 7 launches, though buyers can reserve them immediately via HP's Web site.

Intel's Otellini says it's time to take the lid off IT budgets

Intel President and CEO Paul Otellini said the economy has already hit rock bottom and now that it's emerging from the recessionary mire, companies are about to take the lid off of IT budgets. We're likely to see PC unit volume this year above 2008, which you wouldn't have thought even three months ago." And the head of Intel said since companies have been making due with aging laptops the last few years, it's time for CIOs to do a little high-tech shopping. "Corporate budgets were just clamped down. Otellini talked about the economy , PC sales, the advance of silicon and the metamorphosis of netbooks at a morning session of the Web 2.0 Summit in San Francisco today. "We found bottom," he said. "Actually, I think we found bottom much earlier than everyone thought we would. CIOs and CFOs kept the lid on budgets last year and I expect that to change.

They have to be replaced. We expect that to open up in 2010," he added. "The average desktop is five years old, a laptop is four years old. They're out of warranty. And CIOs are buying that argument." Otellini has good reason to be optimistic. It's more expensive to keep the old ones than to buy new ones.

Just last week, Intel reported strong third-quarter earnings that beat analyst expectations. Revenue was even up by $1.4 billion compared to this fiscal year's second quarter. The chip maker reported third-quarter revenue of $9.39 billion for the quarter that ended Sept. 26, beating the $9.04 billion estimations. Over the next few years, Otellini said, much of what will drive Intel's business is the increasing focus on mobile computing. We've been able to shrink the micro processor down to a very tiny part of the chip, so we can use the other transistors available to put more function on the chip.... And engineers at the chip maker are focusing on how to feed that growing market. "Moore's Law gives you a template to build things at much higher performance, much lower cost, much lower power," he said. "We're aiming at a whole family of products of a system on a chip.

The things we do that go in your pocket are focused on the lowest power and all-day battery life, which is the minimum you need on these things, and very high performance graphics and video with a minimal cost, while keeping the form factor very, very thin." Otellini also said that the time is running out on using silicon to build chips. Scientists and engineers have been working with the material and even adding other materials to try to change its properties so the chip can do more than before. Silicon is the basic building block of the microchip. Today, Otellini said he thinks chip makers will come out with three more generations of processors using silicon and then will be looking at a different base material. Trust me," he said. He wouldn't say what that material might be. "It's cool.

And responding to a question about the choice between smartphones and netbooks , Otellini said he sees big changes coming for the netbook. "I think the [netbook's] screen size and having a different keyboard is a different use model than smart phones," he said. "Not any better and not any worse. They'll have both. In places like San Francisco, people will have a laptop and a smart phone. In other places, most people will have to choose. They'll get smaller.

We'll put more capabilities into netbooks that will make them better. They'll have GPS. They'll just get better."

Google commands more than half of iPhone’s Web traffic

A new report from Chitika Research shows that Google has even more significant presence on the iPhone than you might have thought. Chitika's findings show that across the Internet as a whole-not just iPhone or mobile Internet-Google search accounts for about 31 percent of Web traffic. According to Chitika, Google searches alone account for more than 50 percent of all Internet traffic from mobile device running the iPhone OS.That means Google outstrips all other traffic, including other search sites and all visits to Websites in the phone's browser.

Google has doubtlessly attained an even more commanding position on the iPhone because it's the default search provider in the iPhone's Safari browser. There has been no shortage of ink spilled about the growing rivalry between Apple and Google. Some iPhone users tend to search for sites via Google rather than type in full URLs.  But what happens if Google loses its prime location on the iPhone and iPod touch, as a recent BusinessWeek report suggests? And the Mountain View search behemoth has just released its Google Voice Web app, entirely bypassing Apple's App Store. The mobile Web market is changing rapidly, though, and Google's own Android OS is capturing a bigger piece of the pie. If a tit-for-tat ensues, we could very well see Google search get demoted on the iPhone, and with that could come a sudden change in fortunes for Google's mobile advertising.

The iPhone now accounts for 54 percent of total smartphone traffic. All of this should make the coming year unpredictable and pretty interesting. Android has snagged 27 percent. One final word about the data: Chitika is a search-based online advertising network, and the company derived its numbers from a sample of traffic through that network. With 700 million impressions to analyze, one can assume that Chitika has used a fairly representative sample, but the report doesn't include a detailed methodology.

ITU Telecom World expo shifts in response to economic crisis

The ITU Telecom World exhibition has returned to Geneva after a visit to Hong Kong in 2006 - and has brought many Asian exhibitors back with it. The booths of China Mobile, ZTE and Datang Telecom Group loom over the entrance to the main hall, alongside those of NTT DoCoMo and Fujitsu, while upstairs Huawei Technologies and Samsung Electronics booths dwarf that of Cisco Systems, which has more meeting rooms than products on display. "Ten months ago, people were urging us to cancel the event," said Hamadoun Touré, secretary-general of the International Telecommunication Union, which organizes the exhibition and the policy forum that runs alongside it. There are also signs that the way some companies are using the show is shifting. The pessimists feared that the show would attract neither exhibitors nor visitors, as companies slashed marketing budgets and cut back on business travel in the midst of the economic downturn.

The ITU still expects 40,000 visitors at this year's show; 82,000 turned up at the last Geneva event, in 2003. This year, around half the show is occupied by national pavilions: Saudi Arabia has the biggest, followed by those of Spain and Russia. While the show is noticeably smaller than previous editions - it only occupies Halls 2, 4 and 5 of the sprawling seven-hall Palexpo exhibition center, with some yawning gaps between stands, Touré is satisfied. "It's a good show, despite the crisis," he said. Other European nations, including Belgium, France and the U.K., also have pavilions, but by far the most numerous are those of the African nations: Burundi, Egypt, Ghana, Kenya, Malawi, Nigeria, Rwanda, Tanzania and Uganda. The biggest company stands are those of the Asian network operators and equipment manufacturers, with the U.S. and Western European countries keeping a low profile. Microsoft and IBM have booths, but you'd barely notice. This domination of the show floor is not down to size alone: It's also about tactics.

There were actually only three of them, but their effect was magnified by loud music and the multiple video walls on the booth. Russia deployed what looked like an army of violinists dressed mostly in sequins on its stand on Monday. China Mobile has taken a similar route, with the logo of its 3G mobile brand, Wo, swirling and pulsing hypnotically across the walls and even the ceiling of its booth. Similar exhibits fill the stands at NTT DoCoMo and Samsung. ZTE has taken a more traditional route, with glass cases full of mobile phones, modems and cellular base stations.

On the Cisco booth, there are almost no products to be seen - unless you count the looming bulk of one of its TelePresence systems, linking the booth in high resolution to similar systems around the world. This shows images of the products that can be rotated on screen to examine them from different angles - and even measured or dismantled so that prospective buyers can figure out whether they would fit in their data center. Other elements of the Cisco product range are present virtually thanks to another screen, supplied by Massachusetts-based Kaon Interactive. Like Secretary-General Touré, Cisco faced a crucial decision last year about whether to maintain a show presence in Geneva. "One year ago, it wasn't clear how many customers were going to make this trip," said Suraj Shetty, the company's vice president of worldwide service provider marketing. That's why the rest of the stand is given over to meeting rooms. "Our focus is on customer intimacy," Shetty said.

However, the company realized that "this could be used as an opportunity to shift how we get contact with customers," he said. Carrier Ethernet specialist Ciena has taken a similar approach. Like Cisco, it prefers to show products virtually, rather than physically. "Computer graphics and touch screens are more effective in these cases. Its stand, close to Cisco's and even more discreet, consists entirely of meeting rooms. That's the trend," said Ciena CTO Stephen Alexander.

If you're buying bulky network or data center infrastructure, then don't expect to kick the tires at a trade show next year - although you might be able to click on them, on the booth's screen or your own.

Former Seagate engineer says company destroyed evidence

A former employee of Seagate Technology claims that the company destroyed evidence that could have affected a long-standing patent infringement lawsuit filed against it by engineering company Convolve Inc. and the Massachusetts Institute of Technology (MIT). In a court document obtained by the New York Times that was filed late last month, the former employee, Paul A. Galloway, claimed in an affidavit that Seagate deliberately destroyed the source code pertaining to a disk driving using Convolve's intellectual property and "failed to preserve" Galloway's PC containing all of his work during development of the drive. Seagate officials were not immediately available for comment. Galloway, who worked for Seagate until July as an engineer, also claimed that Seagate "withheld, if not destroyed, minutes of a server engineering group meetings used as a forum for disseminating Convolve's technology.

Convolve spokesman Mark Tanquary said his company had no official comment on Galloway's affidavit, but said, "I think a lot of people were happy to see that." The nine-year-old patent infringement case alleges that Seagate misappropriated Convolve's Quick and Quiet technology, incorporating it as its own Sound Barrier Technology . Sound Barrier was originally used in Cheetah X15 hard drives in Compaq computers to make them run more smoothly and quietly. In July 2000, Convolve and MIT sued Seagate and Compaq Computer seeking $800 million in damages over its Quick and Quiet technology. The software was developed using patented intellectual property under license by Convolve from MIT. The Quick and Quiet motion-dampening technology was originally created in 1989 by three MIT professors, one of whom founded Convolve. The lawsuit also sought a permanent injunction barring Seagate or Compaq from selling products using the Sound Barrier technology. Galloway claims in his affidavit that Convolve's technology was disseminated freely throughout his servo engineering group, but that those working on the drive technology were never told it was covered by a non-disclosure agreement (NDA). Additionally, Galloway said in his affidavit that he would not have used the intellectual property had he known it was protected under an NDA. A court conference is scheduled to take place regarding the case on Jan. 20. Lucas Mearian covers storage; disaster recovery and business continuity; financial services infrastructure; health care IT for Computerworld . Follow Lucas on Twitter @lucasmearian , send e-mail at lmearian@computerworld.com or subscribe to Lucas's RSS feed .

In January 2008, the court ordered Seagate to provide all documents relevant to the case by February of that year.

Study: 54% of companies ban Facebook, Twitter at work

Planning on firing off a short missive on Twitter or posting an update to your friends on Facebook from the office? According to a study commissioned by Robert Half Technology, an IT staffing company, 54% of U.S. companies say they've banned workers from using social networking sites like Twitter, Facebook, LinkedIn and MySpace, while on the job. Better check the rules of your workplace first. The study, released today, also found that 19% of companies allow social networking use only for business purposes, while 16% allow limited personal use.

Nucleus Research, an IT research company, reported in July that companies that allow employee productivity drops 1.5% in companies that allow full access Facebook in the workplace. Only 10% of the 1,400 CIOs interviewed said that their companies allow employees full access to social networks during work hours. "Using social networking sites may divert employees' attention away from more pressing priorities, so it's understandable that some companies limit access," said Dave Willmer, executive director of Robert Half Technology, in a statement. "For some professions, however, these sites can be leveraged as effective business tools, which may be why about one in five companies allows their use for work-related purposes." A study released last summer concluded that social networking use can hurt the bottom line. That survey of 237 corporate employees also showed that 77% of workers who have a Facebook account use it during work hours. It did not say how many workers fit into that category, but did note that one in 33 workers surveyed use Facebook only while at work. Nucleus said the survey found that "some" employees use the social networking site as much as two hours a day at work.

And of those using Facebook at work, 87% said they had no clear business reason for accessing the network. And in August, the U.S. Marine Corps reaffirmed its ban on the use of social networks by its soldiers.

iTunes gains Automatically Add to iTunes feature

One of the often requested features for iTunes has been the ability to set a folder for it to watch, automatically adding any items you drop in that folder to its library. In typical Apple fashion, it's not exactly what people were asking for, but Apple's interpretation of what they want. In iTunes 9, Apple has quietly added this feature, although I wouldn't blame you for not having noticed its existence. When you install iTunes 9, it automatically creates an Automatically Add to iTunes folder in your ~/Music/iTunes/iTunes Music folder (or under ~/Music/iTunes/iTunes Media if you created a new library after installing iTunes 9). When you put an iTunes-compatible media file in this folder, it will, as the name suggests, be added to iTunes automatically.

Whenever you drop any file into that folder, it's instantly added to iTunes if the application is running. In my limited testing, I've found that it pretty much works as advertised. If not, it gets added the next time iTunes is launched. And if you ever delete or rename the Automatically Add to iTunes folder, iTunes simply creates a new one for you the next time it is launched. It even looks for files in subfolders you create and adds them to the library as well.

However, it does have a lot of caveats. You can be pretty assured that if the video was downloaded from the Internet, it will not be supported by iTunes. For one thing, iTunes's list of supported formats, especially in the video department, is comically short. In such a case, iTunes will move it to a Not Added subfolder within the Automatically Add to iTunes folder. Still, there are other problems. But that's to be expected because iTunes has never exactly supported a host of media formats.

When users asked for an option to direct iTunes to a folder, they really wanted an option to direct iTunes to any folder. So if you have a huge collection of media in your Movies folder or on an external hard disk drive containing files that you'd like to automatically add to iTunes, you'll still have to move them to that particular folder. What Apple has done, on the other hand, is created a pre-designated folder for the task and not given an option to change it to any other location. What's the point, then? Well, you say, we can just use the Automatically Add to iTunes folder as our primary movies folder, then-maybe even move it to a location of our choosing, and leave behind an alias to take its place.

You can just drag and drop them onto the iTunes icon in the Dock and be done with it. Wouldn't that work? Not only does iTunes not accept anything added to that folder if you move it, but the presence of the alias prevents iTunes from creating a new version of the folder either. Not so much. And when iTunes does add media files from the Automatically Add to iTunes folder, it moves them into its media folder and organizes them as it normally would, even if you have the option to do so disabled under iTunes's advanced preferences.

The only possible use I can see if for you to set it as the default download location for media files you purchase/download off the Internet, so that they can automatically be added to iTunes without your having to do so (and even there, Apple has recommended you don't use it for incomplete files). I hope Apple rethinks this and gives users the freedom to use any folder they want and makes iTunes stop moving the media files around if the user doesn't want it to. It also deletes any subfolders you create within that folder (although that's a logical conclusion, given that they're useless if the media files you put in them never stay there). In short, I don't think the feature is very useful in the form Apple chose to implement it. It's still a (very small) step in the right direction though.

Oracle/Sun: Why European Union jurisdiction matters

A mild war of words is breaking out between American and European regulators on the proposed merger between Oracle and Sun. But American officials are not contesting Europe's jurisdiction over the matter and previous cases show that European regulators have broad powers over American companies that do business in Europe. Slideshow: Hottest Tech M&A deals U.S. government officials have expressed displeasure with the European Commission's objection to Oracle's planned acquisition of Sun.

The European Commission issued a fine of more than $1 billion to Intel this year after finding the company guilty of antitrust violations. In 2001, for example, Europe prevented a merger between General Electric and Honeywell even after American regulators had given the deal a green light. "If the annual turnover of the combined businesses exceeds specified thresholds in terms of global and European sales, the proposed merger must be notified to the European Commission, which must examine it," European officials explain on their official competition Web site. "These rules apply to all mergers no matter where in the world the merging companies have their registered office, headquarters, activities or production facilities. In rare cases, Europe has also blocked mergers between American companies. This is so because even mergers between companies based outside the European Union may affect markets in the EU if the companies do business in the EU." In its merger regulation, the EU stipulates that it has control over mergers in which the combined worldwide revenue of the companies involved exceeds $7.5 billion, and more than $374 million within Europe. Sun earned $11.4 billion in worldwide revenue in fiscal 2009, and $3.8 billion in Europe. In fiscal 2009, Oracle alone pulled in more than $23 billion in worldwide revenue and nearly $8 billion in the Europe, Middle East & Africa (EMEA) region.

When Oracle first announced its deal to purchase Sun in April, the merger was valued at $7.4 billion. European officials objected to "the combination of Sun's open source MySQL database product with Oracle's enterprise database products and its potential negative effects on competition in the market for database products," Sun said in a filing with the U.S. Securities and Exchange Commission. Although U.S. officials gave Oracle and Sun the green light, the European Commission issued a formal statement of objections this week, a decision that could scuttle the acquisition. U.S. officials issued a mild criticism of their European counterparts. "Several factors led the [U.S. Antitrust] Division to conclude that the proposed transaction is unlikely to be anticompetitive," Deputy Assistant Attorney General Molly Boast of the Department of Justice's Antitrust Division said in a written statement. "There are many open-source and proprietary database competitors. The Department also concluded that there is a large community of developers and users of Sun's open source database with significant expertise in maintaining and improving the software, and who could support a derivative version of it." The U.S. comments were described as "unusual" by a European official. The Division concluded, based on the specific facts at issue in the transaction, that consumer harm is unlikely because customers would continue to have choices from a variety of well established and widely accepted database products.

According to the Reuters wire service, a European Commission spokesman named Jonathan Todd said "That's unusual. We apply European merger control rules, they apply U.S. merger control rules," Todd said. I cannot recall any instance where the European Commission has ever issued a statement concerning ongoing investigations in another jurisdiction." Todd further noted that the United States and Europe have different methods of judging whether a deal is anticompetitive."We have our methods, they have theirs. The GE/Honeywell failure was the last time U.S. and European authorities have issued different decisions on a merger, according to the Reuters article. The Antitrust Division will continue to work constructively with the EC and competition authorities in other jurisdictions to preserve sound antitrust enforcement policies that benefit consumers around the world." Follow Jon Brodkin on Twitter. In her statement, Boast said the United States will continue to work with Europe on competition policy. "The Department and the European Commission have a strong and positive relationship on competition policy matters," Boast said. "The two competition authorities have enjoyed close and cooperative relations.

Apple Changes App Store Review Process

Apple may be feeling the Android heat. Many see the move as yet another step by Apple to keep app store developers from defecting to competing mobile platforms - namely Android. The company has changed the way it deals with iPhone app developers letting them now keep closer tabs on how their software is proceeding through Apple's strict App Store review process.

As first reported in Wired this week, a software developer can now see precisely when an app is "Ready for Review," "In Review," and "Ready for Sale." Before that, developers only got vague status bulletins from Apple giving the "average wait time" around finding out whether or not Apple has okayed an app. Meanwhile, many mobile developers have started to expand their mobile platform horizons by creating apps not just for iPhones but myriad other phone environments, including Android, RIM, Palm's Pre, and Microsoft's Windows Mobile. Software developers began complaining loudly about Apple's review policies late last year, after Apple offered a hodgepodge of reasons for banning apps ranging from the Murderdrome comic book to the "Pull My Finger" fart joke app and Alex Sokirynsky's "Podcaster" app. To help pacify developers, Apple recently added a new in-app feature that lets users of free iPhone apps upgrade to expanded capabilities from directly inside the apps, so that a visit to the App Store is no longer needed At the same time, fewer complaints have been emerging lately about applications getting arbitrarily rejected from the App Store. The iPhone still has a lot more applications for its users than any other mobile platform, with more than 100,000 applications available in Apple's App Store in comparison to "10,000-plus" on Google's Android Market, for instance.

But Apple's tops-down App Store policies again spurred confusion in late October, when Apple suddenly restored a 3G TV app formerly banned from its online store. Apple's move to improve communications should go a long way toward keeping developers in the iPhone fold, even though developers really still have no way of knowing in advance whether or not their software will make it into the App Store.

MySpace adds music features in bid to reinvent itself

As part of its attempt to reinvent itself, MySpace unveiled a slew of new music products, including a massive collection of music videos, at the Web 2.0 Summit in San Francisco. But Van Natta strove to keep the packed session on the topic of new music services being dished up on the site. MySpace CEO Owen Van Natta took the main stage Wednesday to talk about the lagging social network's business strategy and its position behind rival Facebook.

Separately, reports circulated Wednesday that Google was also planning a music service . The company announced MySpace Music Videos, which is set up to be one of the most biggest collections of online videos. And to give users better access to the video library, MySpace also unveiled a new Video Search Tab. Van Natta explained that they worked with the company's music label partners to gather fully licensed music videos. The tab is designed to help users search for videos, songs and artist profiles. The dashboard is designed to give bands and singers with MySpace profile analytics on who is listening to their music and how they're interacting with it. "We think MySpace has the opportunity to be the next generation digital distributor of content," said Van Natta, who was an early executive at Facebook before leaving to join MySpace. "MySpace is positioned uniquely to be the place where the socialization of content occurs." MySpace has been slipping in popularity as rival Facebook moved to the top of the social networking pile.

MySpace's roster of new music products also includes an Artist Dashboard. Last December, Facebook drew almost twice as many worldwide visitors as MySpace. At the beginning of Van Natta's presentation, the moderator polled the audience about what social networking site they used. In June, Facebook surpassed MySpace in the U.S. , which had been MySpace's stronghold. A smattering of hands went up to show people who used MySpace. Later in his presentation, the MySpace CEO said he's optimistic about the company's ability to get back on its feet. "We believe that we have all of the building blocks and we need to focus on execution," he said. "If we do a great job at executing and building a great user experience... then we will realize this vision to be the place where you discover a huge amount of content through other people.

When asked who used Facebook, a sea of hands shot up, along with a ripple of laughter from the audience. "Thanks for framing that up for me," Van Natta said. If that is happening in music or other areas, like games, TV and films, it'll be easy to recognize success because you'll just know this is where a huge amount of that socialization is happening."

New Banking Trojan Horses Gain Polish

Criminals today can hijack active online banking sessions, and new Trojan horses can fake the account balance to prevent victims from seeing that they're being defrauded. To stop those attacks, financial services developed authentication methods such as device ID, geolocation, and challenging questions. Traditionally, such malware stole usernames and passwords for specific banks; but the criminal had to access the compromised account manually to withdraw funds.

Unfortunately, criminals facing those obstacles have gotten smarter, too. Greater Sophistication Banking attacks today are much stealthier and occur in real time. One Trojan horse, URLzone, is so advanced that security vendor Finjan sees it as a next-generation program. Unlike keyloggers, which merely re­­cord your keystrokes, URLzone lets crooks log in, supply the required authentication, and hijack the session by spoofing the bank pages. According to Finjan, a so­­phisticated URLzone process lets criminals preset the percentage to take from a victim's bank account; that way, the ac­­tivity won't trip a financial institution's built-in fraud alerts. The assaults are known as man-in-the-middle attacks because the victim and the attacker access the account at the same time, and a victim may not even notice anything out of the ordinary with their account.

Last August, Finjan documented a URLzone-based theft of $17,500 per day over 22 days from several German bank ac­­count holders, many of whom had no idea it was happening. Criminals using bank Trojan horses typically grab the money and transfer it from a victim's account to various "mules"-people who take a cut for themselves and transfer the rest of the money overseas, often in the form of goods shipped to foreign addresses. But URLzone goes a step further than most bank botnets or Trojan horses, the RSA antifraud team says. URLzone also seems to detect when it is being watched: When the researchers at RSA tried to document how URLzone works, the malware transferred money to fake mules (often legitimate parties), thus thwarting the investigation. When victims visited the crooks' fake banking site, Silentbanker in­­stalled malware on their PCs without triggering any alarm. Silentbanker and Zeus Silentbanker, which appeared three years ago, was one of the first malware programs to em­­ploy a phishing site.

Silentbanker also took screenshots of bank accounts, redirected users from legitimate sites, and altered HTML pages. According to security vendor SecureWorks, Zeus often focuses on a specific bank. Zeus (also known as Prg Banking Trojan and Zbot) is a banking botnet that targets commercial banking accounts. It was one of the first banking Trojan horses to defeat authentication processes by waiting until after a victim had logged in to an account successfully. Zeus uses traditional e-mail phishing methods to infect PCs whether or not the person enters banking credentials. It then impersonates the bank and unobtrusively injects a request for a Social Security number or other personal information.

One recent Zeus-related attack posed as e-mail from the IRS. Unlike previous banking Trojan horses, however, the Zeus infection is very hard to detect because each victim receives a slightly different version of it. According to Joe Stewart, director of malware research for SecureWorks, Clampi captures username and password information for about 4500 financial sites. Clampi Clampi, a bank botnet similar to Zeus, lay dormant for years but recently became quite active. It relays this information to its command and control servers; criminals can use the data immediately to steal funds or purchase goods, or save it for later use. Clampi defeats user authentication by waiting for the victim to log in to a bank account.

The Washington Post has collected stories from several victims of the Clampi botnet. It then displays a screen stating that the bank server is temporarily down for maintenance. Defending Your Data Since most of these malware infections occur when victims respond to a phishing e-mail or surf to a compromised site, SecureWorks' Stewart recommends confining your banking activities to one dedicated machine that you use only to check your balances or pay bills. When the victim moves on, the crooks surreptitiously hijack the still-active bank session and transfer money out of the account. Alternatively, you can use a free OS, such as Ubuntu Linux, that boots from a CD or a thumbdrive.

Most banking Trojan horses run on Windows, so temporarily using a non-Windows OS defeats them, as does banking via mobile phone. Before doing any online banking, boot Ubuntu and use the included Firefox browser to ac­­cess your bank site. The key step, however, is to keep your antivirus software current; most security programs will detect the new banking Trojan horses. Older antivirus signature files can be slow to defend PCs against the latest attacks, but the 2010 editions have cloud-based signature protection to nullify threats instantly.

Seagate Goes Solid State with Pulsar Drive

Seagate tosses its hat into the solid state drive (SSD) market today with the unveiling of its Pulsar drive, a unit aimed at enterprise-level blade and server applications. With the Pulsar drive, Seagate lays claim to being "the first enterprise HDD vendor to deliver an enterprise-class SSD solution." The Pulsar drive is built with single-layer-cell (SLC) technology, which Seagate says enhances the reliability and durability of the SSD. Solid state drives offer much faster data access speeds than the rotating media in conventional hard disk drives (HDDs) since there are no moving parts. The new drive stores up to 200GB of data in a 2.5-inch form factor with a SATA interface. According to Seagate, the Pulsar drive achieves a peak performance of 30,000 read IOPS (input/output operations per second) and 25,000 write IOPS, which is a measure of how a drive processes small, random blocks of information.

The drive comes with a five-year warranty and has an annualized failure rate (AFR) of 0.44 percent, according to Seagate. "Seagate is optimistic about the enterprise SSD opportunity and views the product category as enabling expansion of the overall storage market for both SSDs and HDDs," said Dave Mosley, Seagate's executive vice president for sales, marketing, and product line management in a press release. The drive is rated at up to 240 megabytes per second for sequential reads and 200 mbps for sequential writes; a measure of how it accesses large chunks of contiguous data. Solid state drives built with single layer cell technology can offer faster read/write speeds than those built with multiple layer cell technology (MLC), but MLC drives can offer more storage. The Pulsar drive, which was made available to select OEM (original equipment manufacturer) customers in September, is now available to all OEMs.

IPv6: Not a Security Panacea

With only 10% of reserved IPv4 blocks remaining, the time to migrate to IPv6 will soon be upon us, yet the majority of stakeholders have yet to grasp the true security implications of this next generation protocol. While IPv6 provides enhancements like encryption, it was never designed to natively replace security at the IP layer. Many simply have deemed it an IP security savior without due consideration for its shortcomings. The old notion that anything encrypted is secure doesn't stand much ground in today's Internet, considering the pace and sophistication in which encryptions are cracked.

Unfortunately, IPsec, the IPv6 encryption standard, is viewed as the answer for all things encryption. For example, at the last Black Hat conference hacker Moxie Marlinspike revealed vulnerabilities that breaks SSL encryption and allows one to intercept traffic with a null-termination certificate. But it should be noted that:  IPsec "support" is mandatory in IPv6; usage is optional (reference RFC4301). There is a tremendous lack of IPsec traffic in the current IPv4 space due to scalability, interoperability, and transport issues. Many organizations believe that not deploying IPv6 shields them from IPv6 security vulnerabilities. This will carry into the IPv6 space and the adoption of IPsec will be minimal. IPsec's ability to support multiple encryption algorithms greatly enhances the complexity of deploying it; a fact that is often overlooked.

This is far from the truth and a major misconception. For starters, most new operating systems are being shipped with IPv6 enabled by default (a simple TCP/IP configuration check should reveal this). IPv4 based security appliances and network monitoring tools are not able to inspect nor block IPv6 based traffic. The likelihood that rogue IPv6 traffic is running on your network (from the desktop to the core) is increasingly high. The ability to tunnel IPv6 traffic over an IPv4 network using brokers without natively migrating to IPv6 is a great feature. Which begs the question, why are so many users routing data across unknown and non-trusted IPv6 tunnel brokers?

However, this same feature allows hackers to setup rogue IPv6 tunnels on non-IPv6 aware networks and carry malicious attacks at will. IPv6 tunneling should never be used for any sensitive traffic. By enabling the tunneling feature on the client (e.g. 6to4 on MAC, Teredo on Windows), you are exposing your network to open, non-authenticated, unencrypted, non-registered and remote worldwide IPv6 gateways. Whether it's patient data that transverses a healthcare WAN or Government connectivity to an IPv6 internet, tunneling should be avoided at all costs. The rate at which users are experimenting with this feature and consequently exposing their networks to malicious gateways is alarming.

The advanced network discovery feature of IPv6 allows Network Administrators to select the paths they can use to route packets. Is your security conscious head spinning yet? In theory, this is a great enhancement, however, from a Security perspective it becomes a problem. So where are the vendors that are supposed to protect us against these types of security flaws? In the event that a local IPv6 Network is compromised, this feature will allow the attacker to trace and reach remote networks with little to no effort. The answer is, not very far along.

Since there are no urgent mandates to migrate to IPv6, most are developing interoperability and compliance at the industry's pace. Like most of the industry, the vendors are still playing catch-up. So the question becomes: will the delay in IPv6 adoption give the hacker community a major advantage over industry? As we gradually migrate to IPv6, the lack of interoperability and support at the application and appliance levels will expose loopholes. Absolutely! This will create a chaotic and reactive circle of patching, on-the-go updates and application revamp to combat attacks.

There is more to IPv6 than just larger IP blocks. Regardless of your expertise in IPv4, treat your migration to IPv6 with the utmost sensitivity. The learning curve for IPv6 is extensive. Many of the fundamental network principles like routing, DNS, QoS, Multicast and IP addressing will have to be revisited. People can't be patched as easily as Windows applications, thus staff training should start very early.

Reliance on given IPv4 security features like spam control and DOS (denial of service) protection will be minimal in the IPv6 space as the Internet 'learns' and 'adjusts' to the newly allocated IP structure. Jaghori is the Chief Network & Security Architect at L-3 Communications EITS. He is a Cisco Internetwork Expert, Adjunct Professor and industry SME in IPv6, Ethical Hacking, Cloud Security and Linux. It's essential that your network security posture is of the utmost priority in the migration to IPv6. Stakeholders should take into account the many security challenges associated with IPv6 before deeming it a cure-all security solution. Jaghori is presently authoring an IPv6 textbook and actively involved with next generation initiatives at the IEEE, IETF, and NIST. Contact him at ciscoworkz@gmail.com.

New gadgets, prototypes to debut next week in Japan

Japan's biggest electronics and gadgets show, Ceatec, runs all of next week and many new technologies and prototype gadgets are expected to be on show. Originally developed by Toshiba, IBM and Sony for use in the PlayStation 3 games console, the Cell is expected to bring functions like real-time upscaling and processing of recorded videos. The first big news is expected on Monday afternoon when Toshiba unveils its first commercial LCD TV that includes the Cell multimedia processor, after showing a prototype of the television last year.

Panasonic will also focus on TV technology and showing a 50-inch plasma TV that can display images 3D. At the IFA electronics show in September the company said it planned to launch such a set next year, so Ceatec will provide more insight into what consumers can expect. The camera is aimed at content producers, not consumers, but the technology could eventually scale down into more compact cameras. Sony is also pushing 3D and will use Ceatec to show a new video camera that can record 3D images through a single lens. In the cell phone arena, NTT DoCoMo is planning to show a cell phone with a wooden rather than plastic case. The phone uses surplus cypress wood from trees culled during thinning operations to maintain healthy forests.

The prototype phone was made in conjunction with Olympus, which has developed a method for wooden casing, and Sharp. DoCoMo and its partners are also expected to show their progress in developing a cell-phone platform for future LTE (Long Term Evolution) wireless services. Meanwhile Fujitsu will show a new cell phone with a built-in golf-swing analyzer. The company is working with Panasonic, NEC and Fujitsu on development of a phone that can download data at up to 100M bps and upload at half that speed. The phone's sensors feed motion data to a 3D sensing program that analyzes the swing and then provides advice.

One of the hits from last year's Ceatec, Murata's unicycling robot, is due to make an appearance and show off a new trick. Each swing can also be compared against past swings. The latest version of the robot is capable of cycling at about 3 times the speed of last year's model. Specifically, the company plans to show off a technology that allows several cars to automatically follow a lead car. Nissan will also be at Ceatec showing off some of its latest research into advanced automotive IT systems.

The futuristic system, which will be demonstrated in robot cars, could one day be used to allow cars to automatically move along roads in "trains" of vehicles with little input from the driver. The exhibition, which is now in its tenth year, attracted just under 200,000 visitors last year. Ceatec runs at Makuhari Messe in Chiba, just outside of Tokyo, from Tuesday until Saturday.

iSuppli now ranks Acer ahead of Dell in PC market

Lifted by fast-growing notebook shipments, Taiwan's Acer Inc. grabbed the No. 2 spot in the global PC market for the first time over Dell Inc., according to iSuppli Corp. That helped it leap ahead of Dell. The market researcher also confirmed that the PC market is starting to rebound, and now expects this year's sales to be almost flat compared to the prior year's. Boosted by a 17% year-over-year growth in notebook (including netbook) shipments, Acer had 13.4% of the 79.9 million PCs shipped globally in the third quarter, said iSuppli. Hurt by sluggish corporate IT spending, Dell's sales fell 5.9% and it recorded a 12.9% share.

On the rebound, Lenovo's shipments growing 17.2% year-over-year, giving it fourth place. "Acer's rise to the No. 2 rank in the global PC business reflects not only its strong performance in the notebook segment, but also the historic rise of Asia as a primary force in the computer industry," said iSuppli analyst Matthew Wilkins in a statement. Another Asian manufacturer, Lenovo Corp., also had a standout quarter. Acer and Lenovo were ranked just No. 6 and No. 8, respectively, in 2003, Wilkins said. "The Asian manufacturers are a growing force in the global PC business due to their aggressive pricing along with their ability to quickly react and embrace new developments, such as the netbook PC," Wilkins said. Both IDC Corp. and Gartner Inc. had already ranked Acer ahead of Dell. iSuppli is the third market tracker to note Acer's rise to number two. HP remained atop the heap for the 13th straight quarter, with 19.9% of the market.

iSuppli also said that Q3 shipments overall grew year-over-year (1.1%) for the first time in a year, while growing 19% from the second quarter. "The sequential and year-over-year shipment increases show that the PC industry emerged from the downturn and began to grow again in the third quarter," Wilkins said. Toshiba is No. 5 globally, with a 5.0% share, iSuppli said. Notebook shipments were "critical in driving growth," as they never wavered into the negative even during the worst quarters, he added. As a result, the PC market is now expected to decline just 0.9%, rather than iSuppli's earlier prediction of a 4% decline. Christmas and Windows 7 will conspire to "bring more good news for PC makers," said Wilkins.

Remaking the data center

A major transformation is sweeping over data center switching. Ethernet switch vendors propose data center collapse Three factors are driving the transformation: server virtualization, direct connection of Fibre Channel storage to the IP switching and enterprise cloud computing. Over the next few years the old switching equipment needs to be replaced with faster and more flexible switches. They all need speed and higher throughput to succeed but unlike the past it will take more than just a faster interface.

Without these changes, the dream of a more flexible and lower cost data center will remain just a dream. This time speed needs to be coupled with lower latency, abandoning spanning tree and supporting new storage protocols. Networking in the data center must evolve to a unified switching fabric. The answer is yes. Times are hard, money is tight; can a new unified-fabric really be justified? The cost savings from supporting server virtualization along with merging the separate IP and storage networks is just too great.

The good news is that the switching transformation will take years, not months, so there is still time to plan for the change. Supporting these changes is impossible without the next evolution in switching. The Drivers The story of how server virtualization can save money is well known. Virtualization allows multiple applications to run on the server within their own image, allowing utilization to climb into the 70% to 90% range. Running a single application on a server commonly results in utilization in the 10% to 30% range. This cuts the number of physical servers required; saves on power and cooling and increases operational flexibility.

Storage has been moving to IP for years, with a significant amount of storage already attached via NAS or iSCSI devices. The storage story is not as well known, but the savings are as compelling as the virtualization story. The cost saving and flexibility gain is well known. Moving Fibre Channel to the IP infrastructure is a cost saver. The move now is to directly connect Fibre Channel storage to the IP switches, eliminating the separate Fibre Channel storage-area network. The primary way is by reducing the number of adapters on a server.

Guaranteeing high availability means that each adapters needs to be duplicated resulting in four adapters per server. Currently servers need an Ethernet adapter for IP traffic and a separate storage adapter for the Fibre Channel traffic. A unified fabric reduces the number to two since the IP and Fibre Channel or iSCSI traffic share the same adapter. It also reduces operational costs since there is only one network to maintain. The savings grow since halving the number of adapters reduces the number of switch ports and the amount of cabling.

The third reason is internal or enterprise cloud computing. Over the years, this way of design and implementing applications has changed. In the past when a request reached an application, the work stayed within the server/application. Increasingly when a request arrives at the server, the application may only do a small part of the work; it distributes the work to other applications in the data center, making the data center one big internal cloud. It becomes critical that the cloud provide very low latency with no dropped packets.

Attaching storage directly to this IP cloud only increases the number of critical flows that pass over the switching cloud. A simple example shows why low latency is a must. With most of the switches installed in enterprises the get can take 50 to 100 microseconds to cross the cloud, which depending on the number of calls adds significant delays to processing. If the action took place within the server, then each storage get would only take a few microseconds to a nanosecond to perform. If a switch discards the packet, the response can be even longer.

What is the problem for the network? The only way internal cloud computing works is with a very low latency and non-discarding cloud. Why change the switches? Compared with the rest of the network the current data center switches provide very low latency, discard very few packets and support 10 Gigabit Ethernet interconnects. Why can't the current switching infrastructure handle virtualization, storage and cloud computing? The problem is that these new challenges need even lower latency, better reliability, higher throughput and support for Fibre Channel over Ethernet (FCoE) protocol.

The problem with the current switches is that they are based on a store-and-forward architecture. The first challenge is latency. Store-and-forward is generally associated with applications such as e-mail where the mail server receives the mail, stores it on a disk and then later forwards it to where it needs to go. How are layer 2 switches, which are very fast, store-and-forward devices? Store-and-forward is considered very slow. Switches have large queues.

Putting the packet in a queue is a form of store-and-forward. When a switch receives a packet, it puts it in a queue, and when the message reaches the front of the queue, it is sent. A large queue has been sold as an advantage since it means the switch can handle large bursts of data without discards. The math works as follows. The result of all the queues is that it can take 80 microseconds or more for a large packet to cross a three-tier data center.

It can take 10 microseconds to go from the server to the switch. For example, assume two servers are at the "far" end of the data center. Each switch to switch hop adds 15 microseconds and can add as much as 40 microseconds. A packet leaving the requesting server travels to the top of rack switch, then the end-of-row switch and onward to the core switch. That is four switch-to-switch hops for a minimum of 60 microseconds. The hops are then repeated to the destination server.

Add in the 10 microseconds to reach each server and the total is 80 microseconds. Latency of 80 microseconds each way was acceptable in the past when response time was measured in seconds, but with the goal to provide sub-second response time, the microseconds add up. The delay can increase to well over 100 microseconds and becomes a disaster if a switch has to discard the packet, requiring the TCP stack on the sending server to time out and retransmit the packet. An application that requires a large chunk of data can take a long time to get it when each get can only retrieve 1,564 byes at a time. The impact is not only on response time.

A few hundred round trips add up. The application has to wait for the data resulting in an increase in the elapsed time it takes to process the transaction. The new generation of switches overcomes the large latency of the past by eliminating or significantly reducing queues and speeding up their own processing. That means that while a server is doing the same amount of work, there is an increase in the number of concurrent tasks, lowering the server overall throughput. The words used to describe it are: lossless transport; non-blocking; low latency; guaranteed delivery; multipath and congestion management. Non-blocking means they either don't queue the packet or have a queue length of one or two.

Lossless transport and guaranteed delivery mean they don't discard packets. The first big change in the switches is the design of the way the switch forwards packets. A cut-through design can reduce switch time from 15 to 50 microseconds to 2 to 4 microseconds. Instead of a store-and-forward design, a cut-through design is generally used, which significantly reduces or eliminates queuing inside the switch. Cut-through is not new, but it has always been more complex and expensive to implement. The second big change is abandoning spanning tree within the data center switching fabric.

It is only now with the very low latency requirement that switch manufacturers can justify spending the money to implement it. The new generation of switches use multiple paths through the switching fabric to the destination. Currently all layer 2 switches determine the "best" path from one end-point to another one using the spanning tree algorithm. They are constantly monitoring potential congestion points, or queuing points, and pick the fastest and best path at the time the packet is being sent. Only one path is active, the other paths through the fabric to the destination are only used if the "best" path fails. A current problem with the multi-path approach is that there is no standard on how they do it.

Spanning tree has worked well since the beginning of layer 2 networking but the "only one path" is not good enough in a non-queuing and non-discarding world. Work is underway within standard groups to correct this problem but for the early versions each vendor has their own solution. Even when DCB and other standards are finished there will be many interoperability problems to work out, thus a single vendor solution may be the best strategy. A significant amount of the work falls under a standard referred to as Data Center Bridging (DCB). The reality is that for the immediate future mixing and matching different vendor's switches within the data center is not possible. Speed is still part of the solution.

The result of all these changes reduces the trip time mentioned from 80 microseconds to less than 10 microseconds, providing the needed latency and throughput to make fiber channel and cloud computing practical. The new switches are built for very dense deployment of 10 Gigabit and prepared for 40/100 Gigabit. Virtualization curve ball Server virtualization creates additional problems for the current data center switching environment. This causes operational complications and is a real problem if two virtual servers communicate with each other. The first problem is each physical server has multiple virtual images, each with their own media access control (MAC) address. The easiest answer is to put a soft-switch in the VM, which all the VM vendors provide.

There are several problems with this approach. This allows the server to present a single MAC address to the network switch and perform the functions of a switch for the VMs in the server. The soft switch needs to enforce policy and access control list (ACL); make sure VLANs are followed and implement security. If they were on different physical servers the network would make sure policy and security procedures were followed. For example, if one image is compromised, it should not be able to freely communicate with the other images on the server, if policy says they should not be talking to each other. The simple answer is that the group that maintains the server and the soft switch needs to make sure all the network controls are followed and in place.

Having the network group maintain the soft switch in the server creates the same set of problems. The practical problem with this approach is the coordination required between the two groups and the level of knowledge of the networking required by the server group. Today, the answer is to learn to deal with confusion and develop procedures to make the best of the situation and hope for the best. The idea is that coordination will be easier since the switch vendor built it and has hopefully made the coordination easier. A variation on this is to use a soft switch from the same vendor as the switches in the network. Cisco is offering this approach with VMware.

This would simplify the switch in the VM since it would not have to enforce policy, tag packets or worry about security. The third solution is to have all the communications from the virtual server sent to the network switch. The network switch would perform all these functions as if the virtual servers were directly connected to the servers and this was the first hop into the network. The problem is spanning tree does not allow a port to receive a packet and send it back on the same port. This approach has appeal since it keeps all the well developed processes in place and restores clear accountability on who does what.

The answer is to eliminate the spanning tree restriction of not allowing a message to be sent back over the port it came from. As the number of processors on the physical server keep increasing, the number of images increase, with the result that increasingly large amounts of data need to be moved in and out of the server. Spanning Tree and virtualization The second curve ball from virtualization is ensuring that there is enough throughput to and from the server and that the packet takes the best path through the data center. The first answer is to use 10 Gigabit and eventually 40 or 100 Gigabit. Using both adapters attached to different switches allows multiple paths along the entire route, helping to ensure low latency. This is a good answer but may not be enough since the data center needs to create a very low latency, non-blocking fabric with multiple paths.

Once again spanning tree is the problem. The reality is the new generation layer 2 switches in the data center will act more like routers, implementing their own version of OSPF at layer 2. Storage The last reason new switches are needed is Fibre Channel storage. The solution is to eliminate spanning tree, allowing both adapters to be used. Switches need to support the ability to run storage traffic over Ethernet/IP such as NAS, ISCSI or FCoE. Besides adding support for the FCoE protocol they will also be required to abandon spanning tree and enable greater cross sectional bandwidth. Currently the FCoE protocol is not finished and vendors are implementing a draft version.

For example Fibre Channel requires that both adapters to the server are active and carrying traffic, something the switch's spanning tree algorithm doesn't support. The good news is that it is getting close to finalization. The first step is to determine how much of your traffic needs very low latency right now. Current state of the market How should the coming changes in the data center affect your plan? If cloud computing, migrating critical storage or a new low latency application such as algorithmic stock trading is on the drawing broad, then it is best to start the move now to the new architecture.

The transformation can also be taken in steps. Most enterprises don't fall in that group yet but they will in 2010 or 2011 and thus have time to plan an orderly transformation. For example, one first step would be to migrate Fibre Channel storage onto the IP fabric and immediately reduce the number of adapters on each server. The storage traffic flows over the server's IP adapters and to the top of the rack switch which send the Fibre Channel traffic directly to the SAN. The core and end of rack switch do not have to be replaced. This can be accomplished by replacing just the top of the rack switch.

The top of the rack switch supports having both IP adapters active for storage traffic only with spanning tree's requirement of only one active adapter applying to just the data traffic. If low latency is needed, then all the data center switches need to be replaced. Brocade and Cisco currently offer this option. Most vendors have not yet implemented the full range features needed to support the switching environment described here. The first part is whether the switch can provide very low latency.

To understand where a vendor is; it is best to break it down into two parts. Many vendors such as Arista Networks, Brocade, Cisco, Extreme, Force 10 and Voltaire have switches that can. As is normally the case vendors are split on whether to wait until standards are finished before providing a solution or provide an implementation based on their best guess of what the standards will look like. The second part is whether the vendor can overcome the spanning tree problem along with support for dual adapters and multiple pathing with congestion monitoring. Cisco and Arista Networks have jumped in early and provide the most complete solutions. Other vendors are waiting for the standards to be completed in the next year before releasing products.

Wipro sets up global services delivery from China

Indian outsourcer Wipro has set up a global services delivery center in Chengdu in southwest China, targeting customers in the U.S., Europe, and other markets outside the country. The center, set up in 2004, is focused on local customers and on Chinese operations of multinational companies, Suchira Iyer, general manager at Wipro Chengdu, said Thursday. The company already runs a services center in Shanghai with about 300 to 400 staff.

The move by Wipro to open a global services facility in Chengdu reflects a growing trend for Indian outsourcers to set up global delivery facilities outside India. "The center is part of our strategy to have development centers worldwide, and to use local talent that is available across the world," Iyer said. Setting up operations outside India also helps outsourcers offer their customers assurances about business continuity and disaster recovery, analysts said. Indian outsourcing companies have to become global with the flexibility to offer services from a large number of countries, said Siddharth Pai, a partner at outsourcing consultancy Technology Partners International (TPI) in Houston. The center at Chengdu has 100 staff with plans to increase the number to about 1,000 in a few years, Iyer said. The Chengdu center, though predominantly focused on foreign customers, will also address the local market, Iyer said. Chengdu offers skilled staff at costs similar to those in India, she added.

Chengdu has a large number of universities, and there is large pool of skilled staff that Wipro hopes to hire, she said. The Chengdu center will provide IT and business process outsourcing (BPO) services, Wipro said. The local government in Chengdu is also actively promoting outsourcing, she added. The center will have an initial focus on testing and enterprise application services for the manufacturing, banking, financial services, and insurance industries. It will provide multilingual services in English, Chinese and Japanese, Wipro added.

Mac News Briefs

Apple has released Logic Pro 9.0.2, a minor update to its professional music recording, editing, and mixing software. According to the release notes, the 9.0.2 update allows Flex Markers to align and snap to MIDI notes, makes performing a punch-in recording with Replace Mode behave correctly, adds an option for latency measurement to the I/O plug-in, and causes TDM plug-ins to behave as expected (only an issue previously for users with Pro Tools HD audio hardware.) The update is available via Software Update or from Apple's support Web site. Logic Pro 9 is part of the Logic Studio suite of music applications. Apple had yet to update its Logic Pro 9: Release Notes Web page with additional details when this story was posted.-Jonathan Seff Prosoft updates Data Rescue recovery utility Prosoft Engineering updated Data Rescue, introducing a new interface and a number of speed and performance improvements to its data-recovery utility.

Prosoft also added more than 100 new Reconstructed file types for Deleted and Deep scans. Data Rescue 3 features animated visual effects in its redesigned interface to help guide users through recovering files from corrupted hard drives or accidental deletions. The new FileIQ features lets the software learn about new file types from user-supplied samples, extending the number of potential Reconstructed file types supported by Data Rescue. Prosoft improved support for scanning Apple software RAID drives and 1TB or greater drives as well as support for recovering large sparse disk image files, pkzip files, and hard linked files. Other enhancements include the ability to suspend and resume scans and manage the results from multiple scans. Data Rescue 3 runs on OSX 10.4.11 or later, including Snow Leopard.

In addition, File Stitcher 2.1 features a pre-stitch validation check list, expanded bitrate support, and Snow Leopard compatibility. The software costs $99 for a personal use license; licenses for IT pros cost $249.-Philip Michaels File Stitcher 2.1 features redesigned merging engine File Stitcher, the MP3 merging tool from Pariahware, has been updated to version 2.1. The latest update features redesigns to both File Stitcher's interface and merging engine. Version 2.1 is a free upgrade to all File Stitcher 2.0 license holders. Available for $15, the program also offers a demo where you're limited to stitching two files together at a time.-PM

Juniper’s enterprise business hums in Q3

Juniper Networks (JNPR) can thank its enterprise business for third-quarter results that exceeded expectations. Profits came in at $122.5 million, or 23 cents per diluted share, an increase of 21% quarter-over-quarter but a decrease of 28% from the third quarter of 2008. Still, the results were better than the $800 million in revenue and 21 cents per share earnings Wall Street was expecting. For the period ended Sept. 30, Juniper recorded revenue of $823.9 million, an increase of 5% sequentially but a decrease of 13% from the same period a year ago.

And that's due to a 10% sequential growth in Juniper's enterprise business, which was "better than expected," according to Juniper CFO Robyn Denholm. Johnson added that the IBM-branded Juniper products offered under a recent OEM arrangement are now available. Juniper's answer to Cisco in the data center: Stratus Project CEO Kevin Johnson said those results for the enterprise business represent "a starting point for a level of momentum" Juniper believes it can achieve in that market. "Our vision of the data center architecture of the future is resonating," Johnson said in a conference call with analysts. Juniper's EX LAN switching line, which debuted in the first half of last year, accounted for $50 million in sales in the quarter and is on a $200 million annual run rate. The MX debuted in 2006. The SRX firewall, which was unveiled a year ago, is on a $100 million annual run rate.

The MX series Ethernet router, deployed mostly in carrier networks but also in some enterprise data centers, is on a $400 million annual run rate. Together, the EX, MX and SRX product lines accounted for $180 million of Juniper's $634 million in product revenue in the quarter. "We are executing better, and that's coming mainly from the US," Johnson said of the enterprise results in the quarter. We're share takers in the enterprise market, we've got a lot of upside. Sales were particularly strong in the US federal government marketplace. "We will continue to throttle up execution globally. As the economy improves, enterprise investments will improve, but at a slower rate than service providers. "The level of buzz with customers in the enterprise continues to grow," Johnson added. "It's indicative of our opportunity. SLT revenue was a record for the quarter at $229 million, Denholm said, an increase of $11 million from 2008's Q3. In general, Juniper sees the economy and its business improving. "Our visibility has improved in key areas of our business," Johnson said. "We're in an economic recovery.

But we've got to execute and engage with customers." Juniper experienced increased sales of its Service Layer Technology products – traditionally enterprise security and WAN acceleration gear – to service providers in Q3 as well. The pace varies across geographies" with improvements domestically, stabilization in Asia and a slower uptick in Europe. For the fourth quarter, Juniper expects revenue of $860 million to $895 million, and earnings per share in the 23 cents to 26 cents range.

Google, Facebook to offer music sales

Facebook plans to let users buy music and other virtual products on its Web site, the company said Wednesday, expanding its sources of revenue as the company seeks to turn its huge popularity into fiscal profit. The move comes as Google looks to hold its dominance against Bing, which has stolen around 9 percent of the U.S. online search market since its launch earlier this year, according to Internet monitoring companies. Separately, Google will let users sample and buy songs directly from its search results page with a service it plans to announce next week, according to reports.

Songs and official sports icons are among the new virtual gifts Facebook will add to its store, the company said on its blog. The service, powered by music streaming site Lala.com, will be available by the end of this week, a Lala representative said in an e-mail. Users in the U.S. will be able to pay US$0.10 to send friends a song that can only be listened to online, or $0.90 to send a copy that can be downloaded and transferred, the company said. Google will let users stream songs from Lala and iLike.com, which is owned by MySpace, according to a report in the The Wall Street Journal. Google already has an ad-supported music search service, offered only in China, that lets users stream and download songs for free.

A Lala link will let users stream a full song once for free and pay about $1 to download a copy, the report said. A Google executive earlier this year said the company had started work on applying the model in other countries. Lala declined to comment on any deal with Google. Google did not immediately reply to a request for comment. Google's rivalry with Bing was visible as both countries announced search deals with Twitter on Wednesday.

Google said it would launch a search service for Twitter messages just hours after Microsoft announced a similar deal for Bing.