Editor : Martin Simamora, S.IP |Martin Simamora Press

Jumat, 19 Agustus 2011

IBM expands partner network in Azerbaijan


IBM is expanding a partner network in Azerbaijan, bringing to market a wide range of new products and services that are in demand in Azerbaijan, IBM Sales Director in the CIS Sergei Tabulin said in an interview with the Azerbaijani magazine InfoCity.

Tabulin said Azerbaijan is developing dynamically; that high-tech solutions are in demand throughout the country, as evidenced in the banking sector. Banks are now actively engaged in the creation of reserve data processing centers, their importance underscored by the travesty that occurred in Japan. A similar demand was observed in the oil and gas industry, where IBM is seen as the solution maker.

Active steps are being taken in Azerbaijan and in the construction of "E-government", which can only be welcomed, he said.


As for the latest projects undertaken by IBM in the Azerbaijani market, Tabulin noted the project implemented on the software-hardware platform of IBM for the "cloud computing" technology at the Information Technology Institute of the Azerbaijani National Academy of Sciences.


"A growing number of customers are installing the virtualization of computing resources, which serves as a preparatory stage for the subsequent transition to cloud computing", he added.


Tabulin said IBM wants to ensure its position in Azerbaijan not only as an equipment manufacturer. The company seeks to show that all services and products which are in demand and represented globally, are also presented in this country.


"CIS countries have a good chance of a technological breakthrough, as the cost of the technology is gradually lowering, whereas the existing data-processing infrastructure was built up over decades in other countries. So there is a real opportunity to create a fairly developed modern infrastructure using small investments", he said.

.trend.az

E-portal to the future

Universal online government services is the goal by 2015 through a planned all-purpose website.
Customers can check vessel or plane availability on the Customs Department site


In just a few short years, new small businesses will be able to apply for their permits and access other services electronically via a planned new government website that will automatically forward their information to the relevant state agencies.


The e-government portal will provide the public and local businesses with more convenient access to one-stop information and services.

Unlike the more conventional paper-based registration for new startups, the e-portal will encourage greater participation in democratic institutions and processes while improving the quality of state services.

"The goal is for Thailand to offer universal government services online by 2015, allowing public access via any device around the clock," said Sak Segknoonthod, director of the Information and Communications Technology Ministry's recently established Electronic Government Agency (EGA).
file taxes with the Revenue Department

The EGA is already playing an important role as technology adviser to state agencies while coordinating efforts among them.

A UN study on e-government readiness ranked Thailand 76th globally last year, slipping from 64th in 2009. The country also dropped from third place to fourth within Asean.

"Legal issues and broadband availability are major constraints impeding state agencies from offering full e- services," said Mr Sak.


The EGA will assess all e-government services this year while encouraging greater use of information technology and IT professionals in government agencies.

Early this year, it conducted a survey of 700 e-government services, with the results showing a distinct lack of interagency communication.

Of the total, only 5% were able to provide anything resembling full services with form submission and inquiries accepted, while 3% had some level of multimedia interaction.

The vast majority, 92%, offered only a basic service level such as posting information to be read on the website.

As a start, the EGA will introduce its first e-service this year, the "national single window", allowing citizens to access electronic data and share and integrate information among 35 state agencies and private organisations in the areas of import, export and logistics.

International cross-border data sharing is also in the pipeline.

Led by the Customs Department, the national single window will provide one-stop service for documentation procedures for exporters and importers.


check the breadth of services on the all-purpose e-government portal


The system will reduce many time-consuming manual processes and cut transport costs for the current 125,000 exporters and importers in Thailand by at least US$3.2 billion annually.

The shortened time frame will improve companies' competitiveness, especially for SMEs, in turn strengthening the country's overall competitiveness.

Mr Sak said the EGA will extend its reach to handset devices in order to accommodate the increasing numbers of mobile users.

Kiosks will be set up to help expand e-government service to remote rural areas.

"Thailand now has 20 million internet users, while the other 45 million have no access," said Mr Sak, adding that the EGA will work with Thailand Post branches nationwide.

To date, the EGA has provided 120,000 e-mail accounts for civil servants. Mr Sak said planned cloud services will allow officials to choose their storage, server, operating system and database software on a pay-per-use basis.

This will eliminate current IT constraints, particularly time-consuming procurement procedures.




In October, the EGA will test government cloud services on its existing internal data centre as a pilot project using Microsoft Office 360, the online version of Microsoft Office.

"then we'll evaluate the results and provide services in line with existing laws," said Mr Sak.

He said the EGA has asked cloud service providers in Thailand including TOT Plc and CAT Telecom to assist by using their networks. This will allow the agency to manage service quality while not having to invest on its own.

The infrastructure for the cloud services will be a collaborative effort including a government backup site and disaster recovery service paid monthly or per use without an upfront investment.

Mr Sak said adopting cloud technology will increase IT use among state agencies and ease the IT staff shortage.

"At the end of the day, cloud computing will an IT response to the changing needs of agencies. IT staff will switch from an operational role to systems analysis," Mr Sak added.

bangkokpost.com

Kamis, 18 Agustus 2011

Personal data law comes into full force, Medvedev signs more restrictive amendments

Last week, President Medvedev signed certain amendments to the Russian law on personal data, which hardened the legal obligations on all organizations – both corporate and state sector – which deal with personal data. Although the law was voted by the Russian parliament in 2006 – one year after Russia ratified the Council of Europe’s 1981 Strasbourg Convention on the Protection of Individuals with Regard to Automatic Processing of Personal Data – the application of many of its provisions had been postponed several times due to an absence of precise rules and principles of regulation.

The law, which came into full force on July 1, 2011, as well as the recent amendments, has raised serious concerns among some businesses due to the anticipated administrative burdens and high implementation costs.

Proving approval for data use

Personal data can be collected or used only upon approval of the concerned person or his/her representative – in which case the operator must check and be able to prove this approval.

An exception is for personal data collected and used exclusively for the purpose of implementing a contract – for instance, to provide a service or a good to an individual. No approval is required in this case, but the company cannot make any further marketing or commercial use of the data.

According to the law, approval must be voluntary. This means, in particular, that when ordering a service or good, a customer should not feel bound to accept further use of his personal data.

Approval can be received in any form that can be verified, according to the new amendments. Non-written forms of approval are thus implicitly allowed – an important issue when it comes to online commercial and marketing activities.

“While many transactions are made in an oral or electronic form, e-merchants will have to create and store supporting information that provides evidence of approval,” Otto Group Russia’s legal adviser Mikhail Chentsov said to East-West Digital News. “This may be difficult for many e-commerce players, especially the small ones.”

Heavy requirements for data protection

The law is particularly demanding when it comes to the protection of stored personal data. Only duly certified means of protection can be used. Moreover, a special license is required to handle the technical tasks related to storing personal data, unless these tasks are outsourced to licensed technical providers.

In this last case, the concerned person must approve the outsourcing, according to the new amendments.

In addition, organizations storing personal data are required to:
  • Assess the potential threats to data protection as well as the efficiency of the protection measures even before data starts being collected or used;
  • Establish precise rules for accessing the data and record any action related to the data;
  • Uncover any unauthorized access to data and bear responsibility, should data be altered or deleted following unauthorized access.

A flurry of criticism

Many provisions of the amended law – lobbied for by the Federal Security Service (FSB) and other state security bodies – have been severely criticized by the business and legal communities for containing excessively stringent requirements and involving considerable costs while lacking clear implementation mechanisms.
“Seven million organizations dealing with personal data must now abide by slightly adapted, 20 year-old state secret protection rules,” Russian business daily Vedomosti quoted a group of IT experts as saying. The rules will apply not only to banks, mobile operators, and government bodies dealing with passport information, but to any organization having employees and storing related personal information about those employees, according to Alexander Lukatsky, one of these experts.

In response to the new law, MTS, a leading mobile operator, expects to spend $40 million on additional equipment plus $2 to $5 million per year in operational expenses merely to serve the new equipment, Vedomosti quoted MTS Vice-president Ruslan Ibragimov as saying.

The legislation could be particularly difficult to implement for international companies and Internet players, since their information systems were designed to comply with the legislation of other countries, warned Dmitry Kuznetsov of IT security company Positive Technologies in an exchange with news agency RIA Novosti.

The new legislation applies equally to small businesses. “For them, the new rules may impose unbearable consulting or outsourcing costs,” Alexander Sanin of Russian information security agency LETA told RIA Novosti. “Less than 10% of businesses are fully ready to implement the law, and perhaps just 1% of small businesses are prepared.”
Alternatives to fully applying the law will still be available. “Since many requirements for certification are outdated or simply irrelevant, many organizations will build a double data protection system: an official one to show in case of inspections and a real one to ensure effective protection,” Alexander Kovalev of information security company SecurIT said to RIA Novosti.

As a less costly alternative, some businesses could opt to pay fines rather than implement certain rules. This is not to mention bribes, a very common way of avoiding administrative hassles in Russia.

ewdn.com

Rostelecom connects Siberian cities to e-government

National telecom operator Rostelecom and Irkutsk city authorities signed an agreement last week for the deployment of Rostelecom’s e-government solutions in the city, TASS-Telecom reported citing company sources.

Similar agreements have been signed earlier with municipal authorities in Siberian cities of Novosibirsk, Kemerovo, Krasnoyarsk and Omsk.
Rostelecom has given assurances on its web portal that these services will be developed in strict conformity with all requirements on information safety and personal data protection.

Rostelecom was appointed last March as an partner responsible for implementing important parts of the Federal Information Society 2011–2020 program, including e-government and e-signature platforms and cloud computing programs as well as a unified system of classifications and directories for Federal and local governments.

ewdn.com

Rabu, 17 Agustus 2011

10 Scariest Hacks

Hack week in Vegas


During the Black Hat and Defcon conferences in Las Vegas last week, researchers wheeled out their best new attacks on everything from browsers to automobiles, demonstrating ingenuity and diligence in circumventing security efforts or in some cases in exploiting systems that were built without security in mind. Here's a handful of the ones that deserve the most concern.


Siemens S7 hack


At Black Hat, NSS researcher Dillon Beresford demonstrated how to hack a Siemens S7 computer, gain read-and-write access to the memory, steal data, run commands and shut the computers off. All this is very bad when you consider these devices are used to control machines in factories, utility networks, power plants, chemical factories and the like -- a major security threat. His findings were so troublesome that he pulled out of an earlier conference where he'd been scheduled to present the information until Siemens could patch the vulnerabilities he exposed. And the Department of Homeland Security monitored his talk to make sure it didn't reveal too much.

VoIP botnet control


Botmasters can use VoIP conference calls to communicate with the zombie machines in their botnets, researchers Itzik Kotler and Iftach Ian Amit of security and risk-assessment firm Security Art demonstrated at Defcon. They released a tool called Moshi Moshi that converts touchtones into commands the bots can understand and turns text into speech to capture information on compromised corporate computers and read it into voicemail for the botmaster to pick up later. The techniques enable botmasters to control their hijacked machines from wireless phones and even payphones (if they can find one). The botmasters call in to the conference bridge, the zombies connect via the corporate network and data can flow, the researchers showed.

Powerline device takeover



Independent researchers Dave Kennedy and Rob Simon showed Defcon a device they customized that can tap into home powerlines to monitor and control home alarm and security camera systems. Using the device and broadband-over-powerline technology, burglars could plug the device into an electric outlet on the outside of a house and monitor devices inside the home. They could deduce, for example, that if the alarm system is turned on and security cameras activated then the residents are not at home. The device can send signals that jam signals from the security devices, leaving burglars free to break in without worry that alarms will be set off, the researchers say.

Hacker drone



A spy drone made from off-the-shelf electronics was demonstrated at both Black Hat and Defcon by its creators, Richard Perkins and Mike Tassey. The model plane -- Wireless Aerial Surveillance Platform (WASP) -- was tricked out with electronics that can crack codes and pick off cellphone calls, and an onboard computer that can execute a flight plan designed to have the plane circle above a target while it does its work. The researchers say that if they can build one, so can just about any country or corporate espionage group that puts its mind to it, so beware.

Car hijack via phone networks



A demo at Black Hat hacked a Subaru Outback car alarm, unlocked the doors and started the vehicle, all using text messages sent over phone links to wireless devices in the vehicle. The same type of exploit could just as easily knock out power grids and water supplies, says Don Bailey, a security consultant with iSec Partners, who presented the research. The common thread is that the car alarm and certain devices on critical infrastructure networks are all connected to public phone networks in ways that are fairly simple to compromise, and the prospect is threatening enough that the Department of Homeland Security wanted a briefing beforehand.

Hack faces to find Social Security numbers




A demo at Black Hat and Defcon showed it's possible to acquire a person's Social Security number using nothing more than a photo publicly available in online social-network databases, face-recognition software and an algorithm for deducing the numbers. The point is to show that a framework of digital surveillance that can go from a person's image to personal data exists today, says Alessandro Acquisti, a professor at Carnegie Mellon University, who presented the research. The results will only get better as technologies improve, making privacy more scarce and making surveillance readily available to the masses. "This, I believe and fear, is the future we are walking into," says Acquisti.

Remotely shut down insulin pumps


Insulin pumps that diabetics rely on to keep their blood sugar in balance can be shut off remotely, a researcher demonstrated at Black Hat. Jerome Radcliffe, a diabetic himself, showed how he could pick off wireless signals used to control the pump, corrupt the instructions and send the altered commands to the machine. He could force the wrong amount of insulin to be pumped or shut the device off altogether, either of which could be fatal in the wrong circumstances. The problem, he says, is that the devices weren't designed with security in mind.

Embedded Web server menace


There are embedded Web servers that come in photocopiers, printers and scanners meant to make administering the devices easier, but they lack security, leaving them open to being pilfered for documents recently scanned or copied, Michael Sutton, vice president of security research at Zscaler Labs, told Black Hat. He says he's able to find these Web servers through scripts he wrote to scan huge blocks of IP addresses and recognize telltale Web header fingerprints. "There's no breaking-in required," Sutton says.

Spreading false router tables



A researcher at Black Hat revealed a vulnerability in the router protocol Open Shortest Path First (OSPF) that lets attackers install false route tables on uncompromised routers in an OSPF-based network. That puts networks using the protocol at risk of attacks that compromise data streams, falsify network topography and create crippling router loops. The solution? Use another protocol such as RIP or IS-IS or changing OSPF to close the vulnerability, says Gabi Nakibly, a researcher at Israel's Electronic Warfare Research and Simulation Center, who discovered the problem.

SAP flaw


A flaw in SAP's NetWeaver software enables hackers to dodge authentication into the ERP system, says researcher Alexander Polyakov of security firm ERPScan, who presented his findings at Black Hat. The implications of this are that attackers could gain access to data and delete it, he says. He was able to Google hack servers that contained the flaw, he says, which was present on about half the servers he tested. SAP says it plans to issue a fix for the problem.

.networkworld.com


Government officials slow to develop, implement smart grid cyber security laws

forcechange.com
The rapid development of the smart grid over the past few years has resulted in the electric grid's increased effectiveness, among other benefits. Industry experts worry, however, that critical infrastructure protection (CIP) regulations are lacking, and according to a published report, lawmakers are to blame.
According to a report from Government Computer News, a number of government agencies are responsible for developing comprehensive cyber security protocols. Nonetheless, various groups are charged with protecting different sectors, and experts are concerned that those tasked with crafting and implementing smart grid cyber security measures are failing to deliver comprehensive guidelines.

Federal officials from the Department of Homeland Security, along with those from the Pentagon and other government agencies, met in Washington D.C. in July to discuss the vulnerability of computer networks to hackers, but little has been done since the meetings to improve smart grid cyber security protocols, analysts say.

In fact, though federal information security has been listed as a high-risk priority by the Government Accountability Office (GAO) since 1997, many industry experts contend that there has been very little accomplished in terms of improving cyber security standards.

The race to improve CIP regulations is of the utmost importance, government officials have said, but with so little accomplished over the past decade, many critics have charged the government with failing to deliver on its promises.
The Obama Administration unveiled in June a guideline of how it believes the smart grid should be developed over the coming years. While Obama Administration officials called for enhanced cyber security protocols, government officials are at odds over how exactly - and in what manner - such regulations should be developed, implemented and enforced.

"Despite the actions taken by several successive administrations and the executive branch agencies, significant challenges remain to enhancing the protection of cyber-reliant critical infrastructures," GAO director of information security issues Gregory Wilshusen told the House Energy and Commerce Committee's Oversight and Investigations Subcommittee in July.
"The threats to information systems are evolving and growing, and systems supporting our nation’s critical infrastructure are not sufficiently protected to consistently thwart the threats," he added.

With researchers discovering new vulnerabilities in computer defense systems nearly every day, the pressure is on government regulators to develop a comprehensive set of cyber security regulations. Critics, however, are afraid that officials will fail to unveil such rules in a timely manner.

subnet.com


Corruption Perceptions Index 2018

Why China is building islands in the South China Sea

INDONESIA NEW CAPITAL CITY

World Economic Forum : Smart Grids Explained

Berita Terbaru


Get Widget