Commentary

Fritz Nelson
 

The Fritz & David Show: TPM Danger, Google's Mobile Mgt Play & Mudslingers

No high-flying Apple iPad type news, but the implications of some of this week's news could weigh heavily (good and bad) on enterprise IT managers. On today's Fritz & David Show Podcast, my colleague David Berlind and I discuss news of a successful Trusted Platform Module hack, as well as a Black Hat researcher's prediction of the end of anti-virus as an effective tool. We also discussed some significant news coming from Google, and we ranted about some of the recent mudslinging between Apple and Adobe.

No high-flying Apple iPad type news, but the implications of some of this week's news could weigh heavily (good and bad) on enterprise IT managers. On today's Fritz & David Show Podcast, my colleague David Berlind and I discuss news of a successful Trusted Platform Module hack, as well as a Black Hat researcher's prediction of the end of anti-virus as an effective tool. We also discussed some significant news coming from Google, and we ranted about some of the recent mudslinging between Apple and Adobe.You can download the audio of the latest Fritz & David Show or click the little play button in this sentence. The podcast player should appear as a pull-out tab near the lower left hand side of your browser's window as well.

First, David is doing some significant digging into Flylogic founder and researcher Christopher Tarnovsky's revelatory hack of Infineon's TPM implementation. You can read more about it in Dark Reading's piece here. Some tried to downplay its significance, since it requires an attacker to actually have his hands on device with Infineon's chip, but we read often about lost or stolen systems; and besides, Tarnovsky has said that he isn't stopping with the Infineon implementation.


More Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

But Infineon has a major problem on its hands, especially given that it received certification not only by the Trusted Computing Group, but also from the UK government, which certified the chip for classified information. Prior to news of Tarnovsky's successful hack, The Trusted Computing Group made a pretty big deal about this certificationon its web site. Meanwhile, TCG has issued a response downplaying the significance of what Tarvnovsky has accomplished on the basis of the rarity and cost of the required skills and gear.

Some may remember Tarnovsky from a five-year legal battle with Dish Network over allegedly stolen satellite signals. The case finally concluded, with Dish awarded $1500. David Berlind will continue his investigation into the issue and will publish his findings on InformationWeek.

David also sat in on a session from Andy Fried, the senior special agent with the Treasury Inspector General for Tax Administration's System Intrusion and Network Attach Response Team. In this session Fried claimed that Anti-Virus technology was, for all intents and purposes, dead; that botnets have been deployed to install such sophisticated malware, that the anti-virus tools simply can't keep up. Much of this malware is coming out of Russia, and is being used to capture banking information. This malware, Fried said, is morphing so frequently that anti-virus solutions can't possibly keep up.

In other significant news, Google announced the ability to now manage mobile device features on iPhones, Windows Mobile and Nokia smart phones -- essentially anything that runs Microsoft's Exchange ActiveSync. You can read David's excellent blog on this here This is important because it removes a major barrier to running Google Apps in the enterprise. It also makes Microsoft an unwitting co-conspirator in making Google Apps that much more competitive with Microsoft's technologies. Research In Motion should also take note: Its expensive, but popular Blackberry Enterprise Server (BES) is now, officially, threatened. We hope to hear more from RIM at Mobile World Congress coming up in just two weeks.

Finally, a bit of a rant, not against mudslinging, but for it. This week the buzz has been all about an alleged internal Apple meeting at which Jobs derided Adobe's Flash technology for its instability. Adobe fired back, claiming that Apple has refused to work with the company on its pervasive technology so that it will alleviate any concerns Apple has about it (note that Apple isn't the only smart phone platform that doesn't deploy Flash). When combined with Oracle's Larry Ellison calling out IBM as its single target, the industry noise level has started to rise, and more importantly, become interesting again. It reminds David and me of the days when Scott McNealy and Philippe Kahn and others would regularly take shots at their competitors. Let us know what mudslinging you remember from the past.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links