<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Nigel Gibbons ~ Welcomes you</title>
	<atom:link href="http://nrgfxit.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://nrgfxit.net</link>
	<description>“Cutting through unnecessary complications with clear, direct and flexible thinking, looking beyond the obvious, moving freely from established ways of thinking, reappraising old assumptions, finding new answers.&#34;</description>
	<lastBuildDate>Fri, 10 May 2013 13:07:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='nrgfxit.net' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/1f6a6db9070b748100093f5092f7651b?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Nigel Gibbons ~ Welcomes you</title>
		<link>http://nrgfxit.net</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://nrgfxit.net/osd.xml" title="Nigel Gibbons ~ Welcomes you" />
	<atom:link rel='hub' href='http://nrgfxit.net/?pushpress=hub'/>
		<item>
		<title>The Writing is on ‘The Wall’</title>
		<link>http://nrgfxit.net/2013/04/26/the-writing-is-on-the-wall/</link>
		<comments>http://nrgfxit.net/2013/04/26/the-writing-is-on-the-wall/#comments</comments>
		<pubDate>Fri, 26 Apr 2013 17:45:55 +0000</pubDate>
		<dc:creator>NRG</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Computers and Internet]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.nigelgibbons.com/?p=736</guid>
		<description><![CDATA[As I wrote back in 2011 &#8216;A fickle prospect – &#8216;Business dependent on the Social Flocking collective&#8217; and then again in July 2012 &#8216;Facebook and the &#8216;The Emperor&#8217;s New Clothes&#8217;  it looks like Facebook is nothing unique and is reproducing a user analysis declining trend of past failed social media sites. The article in the Business Insider &#8216;Why Mobile-First [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=736&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>As I wrote back in 2011 &#8216;A fickle prospect – <a href="http://nrgfxit.net/2011/04/27/the-fickle-prospects-business-dependent-on-the-social-flocking-collective/" target="_blank">&#8216;<em>Business dependent on the Social Flocking collective&#8217;</em> </a>and then again in July 2012 <em><a href="//nrgfxit.net/2012/07/30/facebook-and-the-the-emperors-new-clothes/" target="_blank">&#8216;Facebook and the &#8216;The Emperor&#8217;s New </a>Clothes&#8217; </em> it looks like Facebook is nothing unique and is reproducing a user analysis declining trend of past failed social media sites.</p>
<p>The article in the Business Insider <a href="http://www.businessinsider.com/infographic-how-mobile-first-teens-could-unravel-facebook-2013-4#ixzz2SKT31Pt1" target="_blank">&#8216;<em>Why Mobile-First Teens Are A Big Threat To Facebook&#8217;</em> </a>highlights the weakness of the Facebook business model and this in turn points to the complete lack of ANY structured alternative on the Facebook strategic roadmap. This is not however the first time this decline has been reported, <a href="http://www.guardian.co.uk/technology/2011/jun/13/has-facebook-peaked-drop-uk-users" target="_blank">&#8216;<em>New drop in number of UK users&#8217;</em></a> user fickle attitudes go back to this report in June 2011.</p>
<p>As I have stated before with its hyped IPO Facebook achieved a valuation that allows it to effectively buy a business model. The recent Facebook Home on Android attempt at re-inventing itself as a Mobile device &#8216;Skin&#8217; seems to have flopped <a href="http://www.fudzilla.com/home/item/31071-facebook-home-flops-gets-terrible-reviews" target="_blank">&#8216;<em>Facebook Home flops, gets terrible reviews&#8217;</em> </a>so where will they throw their next wad of shareholder cash?</p>
<p>However the latest reports do have greater substance, and the failing of the Facebook Home initiative supports this. The analysis reflects maturing use patterns on the internet and the simple nature that Information and collaborative resources are becoming very fragmented in the nature of how users consume them. No single resource satisfies, with the resource platforms recognising this and the need to interact through cross-posting and <a href="http://en.wikipedia.org/wiki/Mashup_(web_application_hybrid)" target="_blank">&#8216;mash-ups&#8217;</a>. This is after all the strength of Cloud Computing and the new <a href="http://en.wikipedia.org/wiki/Application_Programming_Interface" target="_blank">Application Programming Interface (API)</a> orientated service environment that is being built out. All of which waters down the traction any single site or vendor is able to have on their audience, placing greater emphasis on DEPTH versus BREADTH of service delivery capability. It is the vendors demonstrating greater domain expertise in DEPTH that are the ones that will retain their niche user base, and those vendors that provide flexible well documented and user friendly API&#8217;s to allow third parties to integrate their unique offering instead of trying to compete.</p>
<p>If Facebook had any imagination, instead of copying other ideas and or closing its environment to cross-posting by trying to be all things to all users, it should open up to the new API world. BUT this is where its poor privacy record and attitude to data makes it a dinosaur, and one that will constrain how any API data sharing will benefit the platform. So until Facebook matures its data usage, retention and privacy attitude it is likely to continue to miss out on the next wave of Internet innovation.</p>
<p>That having been said for better or worse the Internet has not heard the last of this Data Privacy predator.</p>
<br />  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=736&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://nrgfxit.net/2013/04/26/the-writing-is-on-the-wall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/140aeed54fbeba9806e7ee00708e98c0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">nrgfx</media:title>
		</media:content>
	</item>
		<item>
		<title>Security 365 – Toilet Paper &amp; Tea bags!</title>
		<link>http://nrgfxit.net/2013/04/19/security-365-toilet-paper-tea-bags/</link>
		<comments>http://nrgfxit.net/2013/04/19/security-365-toilet-paper-tea-bags/#comments</comments>
		<pubDate>Fri, 19 Apr 2013 12:39:08 +0000</pubDate>
		<dc:creator>NRG</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Computers and Internet]]></category>
		<category><![CDATA[Home Computing]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Office 365 and Azure]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.nigelgibbons.com/?p=731</guid>
		<description><![CDATA[OK the title got you this far, so what has Toilet Paper and Tea bags got to do with Security? There is a genuine point to it, please read on ….. Following a recent Cloud Computing event I found myself increasingly alarmed by the prevalence of red herrings being thrown around by vendors with respect [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=731&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>OK the title got you this far, so what has Toilet Paper and Tea bags got to do with Security? There is a genuine point to it, please read on …..</p>
<p>Following a recent Cloud Computing event I found myself increasingly alarmed by the prevalence of red herrings being thrown around by vendors with respect to how their solutions and or products solved Cloud security issues when in fact they did little more than <span style="color:black;">try to address them individually at best.</span></p>
<p>The reality is that DATA must be exposed to the software we use to orchestrate it, be that photo&#8217;s in Photoshop, a Document in Microsoft Office Word or a record in a database or a record spread across multiple databases. That is where the issue lies in the exposure of Data. The challenge is <span style="color:black;">how we protect that which is of true value. No longer the network boundary, but protecting the DATA, wherever it goes, however it is being accessed, regardless of its form factor. Not how a software solution can provide a secure environment in which to process data, albeit an important factor, it is not a solution in itself.</span></p>
<p>Bring on the day when data in its raw form is encrypted and the owner can manage that encryption with convenience and ease whilst ensuring complete control over whom they elect to share any part of that data set with. Imagine being able to share data and attach an expiry date, or revoke data usage at will (regulatory retention aside) instead of having to go through lengthy protracted third party information disclosure requests, which even then are often questionable in their accuracy.</p>
<p>What is appealing about this concept is the reality that it places the control of data back into the hands of the individual. The individual or corporation can then dictate whom, when and for how long they share their data. It opens up possibilities like levying a micro payment charge in cases where that data sharing has a commercial value transfer to any benefiting third party. Assuming a trusted platform that can orchestrate this according to a set of user defined sharing rules (policies), such micro payments would soon add up to reasonable sums of money when considering the current spread of personal data. Sadly we are currently a long way from that Holy Grail. It would certainly sober up the Internet Corporatocracy (Facebook, Twitter, Google and their ilk) of this world who have been building personal value by gorging themselves dining at the Internet table of free data. Their addiction to the concept of free data will I suspect see little support from that quarter for such a solution.</p>
<p>Data security software solutions and products largely address a single issue and do not materially protect the critical payload in transit, rest and during its consumption. The payload being none other than data and the information that is &#8216;data&#8217;.</p>
<p>Erosion of privacy through data seepage into the public domain out with owner&#8217;s control or intent is an issue of paramount importance and at a corporate and enterprise scale the exposure and risk grows exponentially. On a private individual level that is often of singular concern, attitudes towards privacy of data influenced largely through the Social Media behavioural contagion, massaged by the Internet&#8217;s Corporatocracy, who work hard at breaking down the principles of privacy for self-interest. At some point the Social Media lemmings of the world will wake up to find themselves victims of <em>&#8216;The <a title="The Emperor New Clothes" href="http://en.wikipedia.org/wiki/The_Emperor%27s_New_Clothes" target="_blank">Emperor&#8217;s New Clothes&#8217;</a></em>, loss of privacy and control of one&#8217;s personal data is a sorrowful state of affairs many will have to come to terms with. Reminds me of the immortal words &#8216;<em>For fools rush in where angels fear to tread&#8217; </em>from the poem &#8216;An essay on criticism&#8217; by Alexander Pope, or for the more contemporary and more poignantly named song <a title="Bib Dylan - Jokerman" href="http://www.songlyrics.com/bob-dylan/jokerman-lyrics" target="_blank"><em>&#8216;Jokerman&#8217;</em> by Bob Dylan</a>.</p>
<p>I digress, Social Media aside, the simple acts of transmitting and collaborating on information present the largest risk surface area(s) for data compromise. Surfaces that are being built out faster than ever before with the boom in personal / portable compute devices (PCD&#8217;s) be that a smartphone, tablet, laptop or the next gadget that gets christened off a keyboard with a stuck &#8216;i&#8217; key!</p>
<p>For every collaborative event requires a transmission of data, and such events are infrequently constrained within Local Area Network (LAN) but at some point transit a public fixed or wireless network (Internet) exposing or depositing data en-route as well as compute devices out with any structured realm of control. Increasingly the securing of the communication conduit is addressed using <em><a title="HTTP Secure" href="http://en.wikipedia.org/wiki/HTTP_Secure" target="_blank">HTTPS (Hypertext Transfer Protocol Secure</a>)</em>, an encrypted transmission that secures data in transit. But that is only part of the exchange process, and one that has had its security reliability tested and questioned, with early iterations of its underlying protocol having been hacked, ref; <a title="HTTPS Hacked" href="http://www.infoworld.com/t/security/red-alert-https-has-been-hacked-174025" target="_blank">Infoworld Article &#8216;<em>HTTPS has been hacked&#8217;</em></a>. So far we have secured the trickiest part of the information exchange to compromise, the transmission, leaving the easiest, the PC and or Server, available and ready to be compromise. An email attachment click away and data on any unsuspecting PCD regularly falls victim to malware.</p>
<p>This gives a false impression of security, rarely are the end points to a data exchange, the PC, Servers or PCD&#8217;s similarly encrypted. But it is not JUST end points is it. Every device en-route between exchanging parties holds the data be it for milliseconds or in some cases longer. A veritable pass the parcel where, Data is cached and stored in a myriad of places, where the parcel is little more than a colander raining data and the information life blood of companies and individuals into the public domain.</p>
<p>A recent study released by <a title="Team Cymru" href="https://www.team-cymru.org" target="_blank"><em>Team Cymru</em></a> reveals that hackers misappropriate more than 1TB of data daily from corporate networks alone. If they can do that from corporate systems what hope is there for the Silver Surfers (60+ generation), one of the fastest growing use bases on the internet today. This is not an isolated issue either. With a global population of <a title="Zombie Computers" href="http://en.wikipedia.org/wiki/Zombie_computer" target="_blank"><em>Zombie computer</em>s </a>in the millions the bad guys capacity to leverage compute power with malicious intent outnumbers the good guys. Moving briefly off theme a bit, the escalation of this power was clearly demonstrated recently with the 300GB <a title="Denial-of-service attack" href="http://en.wikipedia.org/wiki/Denial-of-service_attack" target="_blank">Distributed Denial of Service (DoS)</a> attack on Spamhaus &#8216;<a title="When Spammers go to war behind the Spamhaus DDOS Attack" href="http://arstechnica.com/security/2013/03/when-spammers-go-to-war-behind-the-spamhaus-ddos/" target="_blank"><em>When spammers go to war: Behind the Spamhaus DDoS&#8217;</em></a>. This was a x6 increase on the previously largest recorded DoS attack of 50GB. At this scale of escalation attacks are having a collateral impact affect beyond the targeted systems. Subject for a future article I would hazard.</p>
<p>Back on theme, we have all heard of &#8216;Data Security&#8217;, but as a term its use is more often not a full truth. As with the data in transit example above, data security is subjective when it needs to be objective. The security that vendors address today is addressing an environmental state that the data is not persisting in, or not persistent in for long. Securing the protocol&#8217;s that we communicate data through, or the servers, datacentres, PCD&#8217;s that we store data on or the software applications with which we orchestrate our data, is not true &#8216;DATA&#8217; security. Access to any of these environments, whether authorised or not, means data can readily be harvested, and believe me it is and most of you will not even know it is happening off your own computers.</p>
<p>I feel like shouting in frustration sometimes &#8211; it&#8217;s in the name &#8216;DATA&#8217; security, so secure the DATA itself, as I have blogged before &#8216;<a title="Data Security – It’s in the Name!" href="http://nrgfxit.net/2012/12/20/data-security-its-in-the-name/" target="_blank">Data <em>Security – It’s in the Name!</em></a>&#8216; OK good that you secure the other servers, datacentres, PCD&#8217;s or software application assets but what about the DATA! I am not proposing we stop securing servers, datacentres, PCD&#8217;s and software application, but their security is addressing THEIR security profile and the DATA security is largely by association only. As we currently deal with security at the server, datacentre, PCD and software application level we create security silo&#8217;s that require gatekeeping. Thus the cracks start to appear and data fall&#8217;s through or the hacker sneaks in, every other which way the data is exposed to higher risk and the prospect if not likelihood of compromise.</p>
<p>Now throw into the mix the structural nature of Cloud Computing architectures and its fastest growing method of interfacing systems with the use of Web/Cloud services. A Web or Cloud service being little more than a traditional <a title="Application Programming Interface" href="http://en.wikipedia.org/wiki/Api" target="_blank"><em>API (Application Programming Interface) </em></a>exposed to a public network. Designed to link disparate systems to deliver richer and often more real time functionality at scale and with collaborative resources unattainable until now to single organisations. Web/Cloud Services live for data exchange and data retention follows hard on the heals of those exchanges between API exposed entities. API&#8217;s = more joins and cracks, not to mention interactions to be audited and jurisdictions that will be challenging to reach into to audit and truly validate Service Level and or compliance. This is no scare tactic, I work with programmers every day, and these are some of the smartest guys around, but they are human, and <em>&#8216;humanum est errare&#8217;</em> (it is human to err).</p>
<p>With an Industry average of <em>&#8220;about 15 &#8211; 50 errors per 1,000 lines of delivered code&#8221; Quote</em> Steve McDonnell from his book <a title="Code Complete" href="http://www.amazon.co.uk/s/ref=nb_sb_noss_1?url=search-alias%3Daps&amp;field-keywords=Code%20Complete" target="_blank"><em>&#8216;Code Complete&#8217;</em> (2nd Edition. Redmond, Microsoft Press, 2004. 960 pages. ISBN</a>), there is an inevitable high risk in API&#8217;s, they are just code after all. Yes errors can be ironed out, but the effort is often not commercially viable. For example only after using extensive format development methods, peer reviews, and statistical testing did the space-shuttle project achieved a level of 0 defects in a random sample of 500,000 lines of code. The <a title="Cleanroom development Engineering" href="http://en.wikipedia.org/wiki/Cleanroom_software_engineering" target="_blank">&#8216;Cleanroom Development&#8217; </a>technique pioneered by Harlan Miles achieves consistent rates as low as 3 errors per 1,000 lines of code (Cobb and Mills 1990), so there are no easy options. All said and done commercial realities turn this into a real concern, the cost of this diligence means API&#8217;s will not all be tested to such robustly high quality levels as the space shuttle which means there are errors, and where there are errors there will be means to an end for hackers:</p>
<ul>
<li><a href="http://www.darkreading.com/cloud-security/167901092/security/application-" target="_blank">Insecure API Implementations Threaten Cloud</a></li>
<li><a href="http://www.darkreading.com/authentication/167901072/security/news/232602844/web-services-single-sign-on-contain-big-flaws.html" target="_blank">Web Services Single Sign-On Contains Big Flaws</a></li>
<li>Microsoft Research <a href="http://research.microsoft.com/pubs/160659/websso-final.pdf" target="_blank">&#8220;<em>All these flaws allow the attacker to sign in as the victim to her accounts on the websites using SSO services even without knowing the victim&#8217;s password,&#8221;</em></a></li>
</ul>
<p>But what if the data itself was of no use once the hackers got hold of it? Do you think they would bother spending long ours gaining access to it if they found it worthless?</p>
<p>What I am getting at is the act of encrypting the DATA itself, the raw data packets, only then are we starting to address the nub of the issue &#8211; making the data secure. Encryption (to encipher) and Cryptography (hidden, secret) is a powerful resource. I like the core message in these terms because they point to the essence of what we must achieve with our data to make it truly secure to turn it into something of <em>&#8216;no value or importance to anyone else&#8217;</em> = cipher to encipher / encrypt our data. Whilst that may sound simple I and the rest of the security community are under no pretence of the challenge this would represent to manage.</p>
<p>Encryption is no small undertaking, by its nature it is very unforgiving to the forgetful or unstructured amongst us which is why all but the very large Enterprises can afford data encryption systems. It is no wonder Enterprise Digital Rights Management (E-DRM) has become a familiar term transposed onto the more generic <em><a title="Information Rights Management" href="http://en.wikipedia.org/wiki/Information_Rights_Management." target="_blank">Information Rights Management (IRM</a>).</em> At a private level it is almost non-existent, for even if you understand the principles of <em><a title="Public Key Infrastructure" href="http://en.wikipedia.org/wiki/Public_Key_Infrastructure" target="_blank">Public Key Infrastructure (PKI</a>)</em> and can wield the tools of<em><a title="Pretty Good Privacy" href="http://en.wikipedia.org/wiki/Pretty_Good_Privacy" target="_blank"> Pretty Good Privacy (PGP</a>)</em> to manage you data in an encrypted way you will find yourself limited in terms of who you can interact with as this is far from user-friendly or mainstream.</p>
<p>Do not be misled, poor adoption of PKI, PGP and their ilk are not an early adopter issue, it is a fundamental structure issue. These mechanism are complex to get to work optimally, and in a sub-optimum deployment they are compromised so its worth is questionable and in a corporate world &#8216;it works some of the time&#8217; does not win much in budget debates. At an individual level it is simply the complexity of management and exchange of encryption keys and their associated Certificates validating key ownership that renders it unusable.</p>
<p>The best we have at present for securing our data files is through forms of IRM / E-DRM, but this has until recently been out of reach of not just the Small and Medium Size Business (SMB / SME&#8217;s) but even large Corporates. OK there are proprietary application level encryption and password locking features, but they lack the truly &#8216;in-line&#8217; capacity as a real time solution and after all the internet is full of solutions that can break these within seconds just head over to the likes of:</p>
<ul>
<li><a title="Passware" href="http://www.lostpassword.com/kit-enterprise.htm" target="_blank">Passware</a></li>
<li><a title="Elcomsoft" href="http://elcomsoft.com" target="_blank">Elcomsoft</a></li>
</ul>
<p>Not all is lost though. Most of us have come up against the power of IRM in the form of <em><a title="Digital Rights Management" href="http://en.wikipedia.org/wiki/Digital_Rights_Management" target="_blank">Digital Rights Management (DRM</a>)</em> with online music purchase, finding that if we try to share a music file bought through one of the online stores we cannot. Why? Because the data is secured and has been locked for use to a single user account. Reflect, the data itself is secured this is the DATA protected, OK the software you use to play the media has to know how to read the data. The data compliance with a standard supported by the software that allows the software to interpret how to authorise the user to use the data, but again I point out this is the DATA that is secured, secured by encryption that refers a user (be it individual or software) to comply with a policy set by the data owner.</p>
<p>Welcome to the future of corporate and personal data, where software (any software) conforms to a standard whereby data is encrypted and software has to comply with that standard to use that data. Just as your Windows Media Player or iTunes software does today through their respective online stores which act as a validation and authorisation proxy for the music industry who are the ultimate rights owners of the tunes you play. In such a new world of data, you could perceivably leave you data anywhere and it would be secure. Why? Because it is encrypted, available to those authorised by the data owner. In such a utopia hackers would gain little from stealing data, and Google would not be able to scan your documents and emails so readily!</p>
<p>IRM as stated above has been the exclusive realm of large Enterprises with the deep pockets to invest in the necessary infrastructure and process discipline mandatory to ensure such an environment works seamlessly and critically data encryption keys are not lost! Until now….</p>
<p>May I introduce or re-introduce you to <em><a title="Microsoft Office365" href="http://office.microsoft.com/en-gb/business/compare-office-365-for-business-plans-FX102918419.aspx" target="_blank">Microsoft Office 365</a>,</em> Microsoft&#8217;s Software as a Service platform for business of all sizes, affordable even for individuals. Microsoft Office 365, delivers Enterprise grade email, collaboration, conferencing and productivity software amongst other benefits. It reset&#8217;s the bar in terms of empowering organisations and even individuals and most poignantly stands alone in its security capabilities with its Information Protection and Control (IPC) in the form of <a title="Windows Azure Rights Management Services" href="http://www.microsoft.com/en-us/download/details.aspx?id=30139" target="_blank">Windows Azure Rights Management Service</a>:</p>
<ul>
<li><a href="http://www.microsoft.com/en-us/download/details.aspx?id=34768&amp;amp" target="_blank">Windows Azure AD Rights Management whitepaper</a></li>
<li><a href="http://www.microsoft.com/en-us/download/details.aspx?id=30139" target="_blank">Microsoft Exchange Online with AD RMS whitepaper</a></li>
<li><a href="http://technet.microsoft.com/en-us/office365/hh699847" target="_blank">Office 365 Virtual Labs for IT Pros</a></li>
<li><a href="http://www.microsoft.com/en-us/download/details.aspx?id=30339" target="_blank">Windows Azure AD Rights Management Administration Tools and Utilities</a></li>
</ul>
<p>Microsoft Office 365 forges a Grand Canyon of a chasm between it and the following herd of online Saas business productivity service vendors when it comes to its compliance credentials and security capabilities, and at a price point that is challenging for any serious functionality and data conscious business executive to not consider very, very seriously. Microsoft Office 365 scales from 1 to 50,000 user environments OUT OF THE BOX! Now NO organisation has an excuse for inappropriate document or email disclosure. It allows ANY organisation to Rights Manage their documents and emails, applying Enterprise class encryption helping to ensure they are only visible to those that have been given explicit rights. This protects organisations in the following common risk scenarios:</p>
<ul>
<li>Laptop theft.</li>
<li>Portable media loss.</li>
<li>Dismissed employee data retention.</li>
<li>Inadvertent CC&#8217;ing of emails or sending to the wrong recipient</li>
<li>Email interception.</li>
<li>Internet vendor document/data scanning.</li>
<li>&#8230;.. amongst others</li>
</ul>
<p>Not 100% full proof by any means but 100% better than about 95% of the &#8216;Data&#8217; security being implemented by organisations today. Be assured that just because you believe you have not been compromised does not mean you have not. In fact I would challenge an organisation, <span style="color:black;">IF you have any Intellectual Property worthy of being stolen KNOW that you are either compromised and you don&#8217;t know it or adversaries are going after it, if you don&#8217;t believe me I fear your falling foul of the </span>old &#8216;<em>Struthio camelus&#8217; </em>syndrome of head in the sand!</p>
<p>The elephant in the room then becomes how to validate the identity of those access in the data, how do you prove that you are who you are and not an impersonator or a middle man &#8216;borrowing&#8217; someone access code(s). Single factor Username + Password authentication mechanism are too weak for true identity security, <a title="2 Factor Authentication" href="http://en.wikipedia.org/wiki/Two-factor_authentication" target="_blank">multi-factor authentication</a> (<em>something you know and something you have</em>) is a step in the right direction but many multi-factor authentication approaches remain vulnerable, and thus the goalposts move …. that&#8217;s a subject for another day.</p>
<p><span style="text-decoration:underline;"><strong>Conclusion<br />
</strong></span>So whether you believed me at the start of this article or not here it is, for little more than the cost each year most organisations spend on toilet paper and tea bags (Ok and coffee) per employee they can enjoy Enterprise grade document and email security amongst a bucket load of other powerful features with Microsoft Office 365, no excuses.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p><span style="text-decoration:underline;"><em><strong>Toilet Paper &amp; Tea Bags Analysis</strong> </em></span></p>
<p><em>Thanks to Discovery Channel and MySupermarket.com:</em></p>
<ul>
<li><em>Average usage per employee/yr = 30,000 sheets/year or 134 rolls/year (@ 150 sheets per roll).</em></li>
<li><em>Average price of 50p/roll</em></li>
</ul>
<p><em>Total £67/year per individual on toilet rolls + Tea breaks at £300 per employee per year &#8211; Epiphany research 2012 quoted on &#8216;The <a href="http://www.wsandb.co.uk/wsb/news/2192130/tea-breaks-cost-employers-gbp300-per-employee-per-year" target="_blank">Workplace Savings and benefits&#8217; website</a>.<br />
</em></p>
<br />  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=731&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://nrgfxit.net/2013/04/19/security-365-toilet-paper-tea-bags/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/140aeed54fbeba9806e7ee00708e98c0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">nrgfx</media:title>
		</media:content>
	</item>
		<item>
		<title>The ‘Freemium’ cost to ISV’s</title>
		<link>http://nrgfxit.net/2013/03/18/the-freemium-cost-to-isvs/</link>
		<comments>http://nrgfxit.net/2013/03/18/the-freemium-cost-to-isvs/#comments</comments>
		<pubDate>Mon, 18 Mar 2013 13:44:02 +0000</pubDate>
		<dc:creator>NRG</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Computers and Internet]]></category>
		<category><![CDATA[Small Medium Enterprise (SME)]]></category>

		<guid isPermaLink="false">http://blog.nigelgibbons.com/?p=740</guid>
		<description><![CDATA[Most of you reading this will no doubt at some point have tried a &#8216;Free&#8217; service or online product offering from a vendor website. Free in most cases means &#8216;Freemium&#8216; = a limited service offering designed as a &#8216;Hook&#8217; to get users to consume a service or product. The &#8216;Free&#8217; service or product offering just enough [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=740&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Most of you reading this will no doubt at some point have tried a &#8216;Free&#8217; service or online product offering from a vendor website.</p>
<p>Free in most cases means &#8216;<a title="Freemium" href="http://en.wikipedia.org/wiki/Freemium" target="_blank">Freemium</a>&#8216; = a limited service offering designed as a &#8216;Hook&#8217; to get users to consume a service or product. The &#8216;Free&#8217; service or product offering just enough features and or resources to make it useful for users. The ultimate goal of course being to get subscribers to the &#8216;Free&#8217; versions to upgrade to a premium or professional paid-for version of the product or service that gives more functionality and or resources.</p>
<p>For new Cloud Start-ups and ISV&#8217;s looking to create market this sounds like a great way of attracting a user base and the techie business start-ups flock to this model with little real awareness of the poor returns this can offer. The challenge lies in the conversion rate of subscribers from &#8216;Freemium&#8217; to &#8216;Premium&#8217; paid-for usage. The conversion rate is not encouraging. Compare high user volume applications with low and you get to see the hard facts:</p>
<ul>
<li>560 million user base &#8211; Skype = 8%</li>
<li>300 thousand user base – Ning 5%</li>
<li>Pandora, Dropbox and Evernote conversion rates are in the range 0.5% to 4%.</li>
</ul>
<p>What is clear is there is these are not impressive and no &#8216;Average&#8217; can be used as a rule of thumb, it largely relates to the value proposition for the users and that is the quandary for ISV&#8217;s looking at this model.</p>
<p>A full understanding of the Freemium dilemma for ISV&#8217;s going online is well laid out in the article by Kim Joar Bekkelund <a href="https://github.com/kjbekkelund/kimjoar.net/blob/master/posts/understanding-user-acquisition-in-freemium.markdown" target="_blank"><em>&#8216;Understanding User Acquisition in Freemium&#8217;</em></a> Kim interviewed 10 companies that use Freemium and provides an insightful analysis of the success of this model.</p>
<p>To achieve even the &#8216;Freemium&#8217; subscription rate from which you hope to convert users there are some clear rules that are appearing to maximise this potential. Some top tips that are not rocket science but aim to lower the bar of entry to get users to sign-up and convert:</p>
<ol>
<li>
<div>Remove as much &#8216;Threat&#8217; and friction as possible:</div>
<ol>
<li>DO NOT demand a Credit Card or other payment method upfront for a Freemium or Trial. This will immediately reduce your sign-up rate to a trickle. Handing over payment details is the biggest decision for the users, so make sure you get them right to the wire first.</li>
<li>Do use a third party authentication channel such as Microsoft Account (Former Live ID) or LinkedIn, Twitter etc This reduces time to sign-up and through association makes the process less threatening. Great for doing user marketing research as you will get more perspective from these login resources which often expose more information about users across other systems helping you to build up your customer knowledge.</li>
<li>Automatically sign-users up to receipt of customer support and training as part of the quid pro quo for the &#8216;Freemium&#8217; offering.</li>
<li>Have a clear Privacy Policy statement that make sit clear what you do with users supplied data.</li>
<li>IF you solution stores data in The Cloud, state clearly where and the nature of the security of that storage. Is it encrypted <em>(ideally).</em></li>
<li>
<div>If your service application stores data, have a European data location option. This is not expensive in the new Cloud world and will be a green light for offerings into a Professional user base who will be more data compliance aware.</div>
</li>
<li>Provide a Contact form on the website for users. You don&#8217;t have to respond, its good to, but it is critical you provide a means of connection.</li>
</ol>
</li>
<li>
<div>Conversion MUST DO&#8217;s:</div>
<ol>
<li>Get to know your market so you can communicate to users and gain mindshare.</li>
<li>Follow-up by reaching out to your new subscribers within a week of sign-up. If users do not engage the resource in this timescale they are unlikely to, so stimulate action.</li>
<li>Use training tips and videos to encourage user adoption of the &#8216;Freemium&#8217;, a great method of increasing the traction of your offering and to dangle Premium features.</li>
<li>Use your &#8216;Freemium&#8217; audience as voluntary testers of BETA &#8216;Premium&#8217; features. Remember Google apps etc for years had BETA stamped all over them.</li>
<li>Use support as a channel into &#8216;Premium&#8217; if you have a business audience. According to <a href="http://www.forentrepreneurs.com" target="_blank">David Skok</a>, business users want professional customer support and are willing to pay for it, consumer users are less likely to pay for support.</li>
<li>
<div>Make it easy and simple for users to get to &#8216;Premium&#8217;, some tricks include:</div>
<ol>
<li>In app free 30 days activation of premium features. Can be re-activated again IF user signs up to BETA test for example.</li>
<li>Delay payment prompts till the last moment. I repeat, handing over payment details is the biggest decision for the users, so make sure you get them right to the wire first.</li>
<li>Provide 7 days free email support. Be proactive if they call on it, you can charge for this afterwards so make it appealing. As existing Freemium users they are unlikely to need it but it&#8217;s a comfort factor that plays to the Professionals more than consumers.</li>
</ol>
</li>
</ol>
</li>
<li>
<div>Evolve and adapt:</div>
<ol>
<li>LISTEN to your users, let them show you the way forward and drive features. Just because you think you know what they want does not mean it&#8217;s right!</li>
<li>Use surveys to reach out to users. Many users like to provide feedback and feel they can influence a toolset they are adopting.</li>
<li>Adapt your Freemium offering to maximise adoption. Existing users will see this as a bonus (they either retain functionality or gain), new users may need this to get them on the Freemium conveyor belt and or into Premium.</li>
<li>Do be a good data citizen. Secure your user data online PROPERLY, and don&#8217;t sell contact details. If you get compromised or found out you have just killed your credibility.</li>
<li>PARTNER – The new world of Cloud Computing allows you to extend functionality quickly and cost effectively. API&#8217;s (<a href="http://en.wikipedia.org/wiki/Application_programming_interface" target="_blank"><em>Application Programming Interfaces</em></a>) allow you to tie in niche features from third parties quickly and in so doing add value and give yourself a Premium revenue option. Yes you will have to share revenue with the partner but then you do not have the development costs but hopefully will get the marriage value incremental gain with your offering.</li>
</ol>
</li>
</ol>
<p>This is by no means exhaustive in detail or exclusive. Make sure you manage a detailed conversion pipeline, a finger on the pulse of your cost of conversion will save you from any unpleasant surprises and keep you firmly rooted in the realms of reality.</p>
<p><em>Good luck!</em></p>
<br />  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=740&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://nrgfxit.net/2013/03/18/the-freemium-cost-to-isvs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/140aeed54fbeba9806e7ee00708e98c0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">nrgfx</media:title>
		</media:content>
	</item>
		<item>
		<title>Nokia Loses The Plot</title>
		<link>http://nrgfxit.net/2013/02/26/nokia-loses-the-plot/</link>
		<comments>http://nrgfxit.net/2013/02/26/nokia-loses-the-plot/#comments</comments>
		<pubDate>Tue, 26 Feb 2013 02:02:06 +0000</pubDate>
		<dc:creator>NRG</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Computers and Internet]]></category>
		<category><![CDATA[Mobile]]></category>

		<guid isPermaLink="false">http://blog.nigelgibbons.com/?p=681</guid>
		<description><![CDATA[This week Nokia pushed out an update to its &#8216;Nokia Drive&#8216; Windows Phone application. The pre-eminent satellite navigation application of the Nokia Windows Phone platform partnership. Wonderful, reminds me of the great new real time service world we are now living in where updates come automatically and services are iteratively improved. So goes the story. [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=681&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>This week Nokia pushed out an update to its <a title="Nokia Drive BETA on Windows Phone Store" href="http://www.windowsphone.com/en-us/store/app/here-drive-beta/9a0f7585-9f16-47d5-8041-28018fcea606" target="_blank">&#8216;Nokia Drive</a>&#8216; Windows Phone application. The pre-eminent satellite navigation application of the Nokia Windows Phone platform partnership.</p>
<p>Wonderful, reminds me of the great new real time service world we are now living in where updates come automatically and services are iteratively improved. So goes the story. But for the fact that the Nokia update this week forgot the rules and left me amongst many other Nokia an HTC users stranded and frustrated.</p>
<p>What appears to have happened is Nokia has &#8216;flipped a bit&#8217; in their software that now restricts the application to providing directional guidance to users default region ONLY. The UK in my case. Somewhat useless as I am sitting in the US. The worst of it was at the weekend the application got me up to Stevens Pass, WA, for some wonderful skiing, only for the update at lunch to then deny me directional guidance to get home! Not that I would mind being stranded on the hill, there was some great snow to carve up, but I was due to be in Seattle the next day for meetings with none other than their Phone buddy Microsoft. If this was a conscious feature addition or rectification of a bug that should have had this locked down in the first place is largely irrelevant. Nokia were aware of what they were doing and the impact was crystal clear to even the most closeted of product development managers.</p>
<p>This would not have been so bad IF they had declared this in the update log, but they did not, I tend to check the update logs before hitting update as some app vendors have done manipulative things in the past. Nokia did not provide any notice, furthermore they provide NO means for me to purchase or extend my applications regional support, or any guidance as to how I could remedy the situation. Just a cold and hostile message that left me stranded.</p>
<p>This has without doubt been poorly implemented and I fear Nokia will hide behind the line that the software is technically classed as BETA = user beware. The lesson for Nokia is in this day and age a company of its calibre should be aware of the new attitude that BETA or not users should be respected and such dramatic feature changes communicated or fear the worst, brand trust and confidence damage, so easily incurred, so hard to regain. It is a very delicate balance dealing with real time, something I would not have expected Nokia to have got wrong having had more time in this type of service game than many. But a lesson none the less to ALL companies, that if Nokia can get it so wrong we all need to tread carefully.</p>
<p>The outcome is, I have now been driven (excuse the pun) by Nokia&#8217;s poor handling of this functionality injection into finding a replacement and at a commercial cost (£79 in my case) that will not see me reverting back to the Nokia application. Cost was never the issue, as such they have not only lost a user they have lost a customer and revenue to boot. Furthermore it has breached a delicate trust that means I am no longer have confidence this Nokia service has my best interests in mind and will not be venturing into the Nokia service or device ownership space in a hurry again.</p>
<p>Nokia has some damage limitation and trust re-building to do. At the moment I see little to suggest they even care. We can but hope.</p>
<br />  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=681&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://nrgfxit.net/2013/02/26/nokia-loses-the-plot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/140aeed54fbeba9806e7ee00708e98c0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">nrgfx</media:title>
		</media:content>
	</item>
		<item>
		<title>EU Cyber Strategy – A Risk of Overkill!</title>
		<link>http://nrgfxit.net/2013/02/11/eu-cyber-strategy-a-risk-of-overkill/</link>
		<comments>http://nrgfxit.net/2013/02/11/eu-cyber-strategy-a-risk-of-overkill/#comments</comments>
		<pubDate>Mon, 11 Feb 2013 15:08:59 +0000</pubDate>
		<dc:creator>NRG</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Computers and Internet]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Small Medium Enterprise (SME)]]></category>

		<guid isPermaLink="false">http://blog.nigelgibbons.com/?p=692</guid>
		<description><![CDATA[Last Thursday the European Commission of the European Union (EU) released their much leaked and awaited Cybersecurity plan to protect open internet and online freedom and opportunity – &#8216;Cyber Security strategy and Proposal for a Directive&#8217; The challenge that faces all Nations and individuals alike is the increased impact of Cyber Thread. This is fundamentally [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=692&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Last Thursday the European Commission of the European Union (EU) released their much leaked and awaited Cybersecurity plan to protect open internet and online freedom and opportunity – <a title="EU Cyber Security Strategy" href="http://ec.europa.eu/digital-agenda/en/news/eu-cybersecurity-plan-protect-open-internet-and-online-freedom-and-opportunity-cyber-security" target="_blank">&#8216;Cyber Security strategy and Proposal for a Directive&#8217; </a></p>
<p>The challenge that faces all Nations and individuals alike is the increased impact of Cyber Thread. This is fundamentally what the European Commission is attempting to address for the whole of the European Union (EU) by encompassing an eye watering range of disciplines and jurisdictions from law enforcement, defence, the digital agenda, security, and foreign policy. On the face of it the format fits the EU objectives of greater integration and harmony, but under the surface it has all the hall marks of an exercise in herding cats. The rubber will not really hit the road till we see the action plans, and the monitoring process to qualify results, that are going to be fundamental to exercising and delivering on this ambitious strategy. This latter point being the Achilles heal of the exercise in tight economic times when the EU budget has to reflect the austerity measures of its members with NO exceptions.</p>
<p>Most worryingly cost of delivery is in the timescales this whole process is going to take to implement. In the meantime Cyber Crime becomes more creative maturing as fast as, if not faster, than the creative innovation engine that drives the digital landscape, itself moving at a faster and faster rate of evolution.</p>
<p>In summary the politicians and unelected cohorts of bureaucrats will forever be playing catch up. The fear is that in their haste they will be riding rough shod over some of our core democratic rights. As the Dutch Member of the European Parliament, Sophie in &#8216;t Veld was quoted saying &#8220;<em>The lines are being blurred and we need to safeguard the fundamental rights we expect in a democracy and not cede disproportionate powers to law enforcement&#8221;</em>.</p>
<p>The rolling up of all these powers does have a very dark side. One that is open to abuse. The danger here is that once in place the temptation / convenience can become too compelling for any elected governing entity to leverage, and the European Commission has inadequately addressed historical challenges to its own Trust and Credibility record across too many areas to be endowed with this level of centralised power.</p>
<p>This exercise the EU is going through is communicating a need for a new approach. Instead of a Big Brother flavour about it, an approach that can reflect the nature of the changing environs that are being addressed. The problem is it is easier said than done to teach an old dog new tricks, especially when we are talking about what goes on largely behind the closed doors from behind which unelected bureaucrats influence our elected politicians and launch sallies of conditions on our lives.</p>
<p>Actions speak louder than words and one thing the new digital economy is good at is making things happen, and happen FAST.</p>
<p>Estonia and their implementation of <a title="X-Road" href="http://e-estonia.com/components/x-road" target="_blank">X-Road</a> and individual digital certificate usage demonstrates where there is a will there is a way, and leveraging the technology (not having to reinvent anything) can be an effective remedy. It is encouraging to see that Thomas Hendrik Ilves, the President of Estonia, has been elected as Chairman for the European Cloud Partnership governance Steering Board. But more needs to be done faster.</p>
<p>As I wrote just before Christmas <a title="Data Secuity - Its in the Name!" href="http://nrgfxit.net/2012/12/20/data-security-its-in-the-name/" target="_blank">&#8216;Data Security – It&#8217;s in the Name</a>!&#8217; We should perhaps be taking a fresh perspective on the problem. Protecting the DATA itself and less worrying about the actual environments that data exists in (networks/cables, computers/serves/PC&#8217;s, smart devices, datacenters/offices etc). Why? It&#8217;s actually about managing the risk of the loss of DATA availability, and this is an EDUCATIONAL issue more than a regulatory and legislative requirement. Risk management is an acceptance that there will be failures, and that is REAL WORLD.</p>
<p>Take for example:</p>
<ol>
<li>The internet – It was designed to withstand nuclear impact! It is largely self-healing and can route around network failures or even whole geographical regional blackouts. If so much of the Internet goes down that it ceases to function then no EU strategy is going to help. Furthermore Cyber Terrorists are unlikely to see much gain in the digital equivalent of triggering an extinction event by killing the Internet!</li>
<li>Datacentres – Deigned for failure, or perhaps you should be re-evaluating your datacentre provider <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </li>
<li>Computers &#8211; These are commodities today and with the exception of a few specialist systems, disposable with affordable options for data resilience through external backup storage media or cloud computing empowering even the most economically distressed with scalable backup. Or for the more paranoid both!</li>
<li>Smart Devices – It&#8217;s in the name. If they are doing their job they should be replicating core data and configuration settings to resilient external storage options which will allow a new device to be provisioned conveniently.</li>
<li>Data – Use of Information Rights management (similar or that used by the music Industry) encrypts data objects such as a digital document (Microsoft Office files) so they can only be read by those the creator has intended the document to be shared with. Theft of these files then becomes futile, remove the attraction, the threat is expunged. The same principles apply to an automated function of databases and exported record sets.</li>
<li>Digital Certificates – A means for individuals to identify themselves consistently so that access to Data can be reliably managed and TRUSTED.</li>
</ol>
<p>The demands of society are actually on mandatory digital education and should be taught like learning how to tie up your shoe laces. To cover the following areas amongst others:</p>
<ul>
<li>Backup (and restore).</li>
<li>Encryption.</li>
<li>Digital Certificates.</li>
</ul>
<p>At the moment society is learning by osmosis and Urban Myth. Times have changed, so must needs, and the EU Cybersecurity plan may have a place at a National response level but quite possibly there are more practical and immediate means of addressing needs further down the social hierarchy that will not have the cost burden on Small Medium Enterprises (SME&#8217;s) that the current strategy would impose.</p>
<p>Remove the ease with which data can be breached and the requirement for security and data breach notification regimes start to look somewhat dated controls.</p>
<br />  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=692&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://nrgfxit.net/2013/02/11/eu-cyber-strategy-a-risk-of-overkill/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/140aeed54fbeba9806e7ee00708e98c0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">nrgfx</media:title>
		</media:content>
	</item>
		<item>
		<title>Free Windows RT – A Future or not?</title>
		<link>http://nrgfxit.net/2013/01/28/free-windows-rt-a-future-or-not/</link>
		<comments>http://nrgfxit.net/2013/01/28/free-windows-rt-a-future-or-not/#comments</comments>
		<pubDate>Mon, 28 Jan 2013 09:28:03 +0000</pubDate>
		<dc:creator>NRG</dc:creator>
				<category><![CDATA[Computers and Internet]]></category>
		<category><![CDATA[Home Computing]]></category>
		<category><![CDATA[Microsoft Partners]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Small Medium Enterprise (SME)]]></category>
		<category><![CDATA[Windows 8]]></category>

		<guid isPermaLink="false">http://blog.nigelgibbons.com/?p=683</guid>
		<description><![CDATA[Windows RT officially launched alongside Windows 8 on October 26, 2012 with the Microsoft Surface device leading the pack of several Windows RT-powered devices from OEM partners. Despite the lack of clarity around the Windows RT v. Windows 8 versions, Windows RT has established a solid user base. It delivers to the mobile demands of [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=683&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Windows RT officially launched alongside Windows 8 on October 26, 2012 with the Microsoft Surface device leading the pack of several Windows RT-powered devices from OEM partners.</p>
<p>Despite the lack of clarity around the Windows RT v. Windows 8 versions, Windows RT has established a solid user base. It delivers to the mobile demands of users in key areas of a stylish aesthetic design and critically excellent battery life. More on that discussion in my earlier blogs:</p>
<ul>
<li><a title="Windows RT - iPad Killer?" href="http://nrgfxit.net/2012/10/29/windows-8-rt-ipad-killer/" target="_blank">Windows 8 RT – iPad Killer?</a></li>
<li><a title="Windows RT - The New Windows OS" href="http://nrgfxit.net/2012/06/14/windows-rt-the-new-windows-os/" target="_blank">Windows RT – The new Windows OS</a></li>
</ul>
<p>Microsoft&#8217;s decision to release an OS build for the ARM CPU was largely driven by the capability this architecture gave the design teams to forge a svelte cutting edge design. Systems on a Chip reduced the bulk and cooling demands as well as increased the battery efficiency allowing for thin devices.</p>
<p>With the announcements by both Intel and AMD that they have their own x86 &#8216;Systems on a Chip&#8217; CPU&#8217;s in the pipeline raises the question that has started entering debate as to the future of Windows RT. Couple this with the new Atom class CPU&#8217;s that are now driving fully fledged Windows 8 OS&#8217;s and narrowing the gap in critical areas of compactness and battery life.</p>
<p>If the hardware continuous evolve allowing a fully-fledged Windows 8 OS to be delivered on tablet devices without compromising battery and design then what does the future hold for Windows RT? The reality is very little. After all who would invest in a Windows RT device over a fully-fledged Windows 8 device? It is an election into a closed ecosystem with a derisory ecosystem of desktop applications and despite a 4 fold increase in Windows New UI applications they represent a poor compete against Android and iOS libraries of apps.</p>
<p>The decision maker in this saga is the application ecosystem and third party product and vendor attachment. iPad has enjoyed a momentum that appears to demonstrate that OS grade functionality is not a critical factor in the Tablet class as long as app and vendor add on product are compelling. That was in an environment that lacked such fully-fledged OS power, Android being no better than iOS. With Windows RT the started to change, but for the lack of application ecosystem. Now with Windows 8 appearing on iPad tablet design class devices there is going to be some interesting times ahead as the full momentum of the Windows application ecosystem and Partner 650,000+ commercial developer organisations get up to speed. Throw in the next generation of Office 365 due out soon and things get even more interesting.</p>
<p>Back to the debate on Windows RT&#8217;s future, there are many permutations but to consolidate these under a few common headline options we are left with:</p>
<ol>
<li><strong>Status-Quo</strong></li>
</ol>
<p>No change, however it lacks real viable evidence that it is not going to just wither on the vine. OEM&#8217;s have not only cancelled RT initiatives they are largely cold on the whole project and driving their hardware architectures to a full Windows 8 which is clearly their agenda further eroding the current device class RT is pitched at fast. There is a price and battery advantage that RT offers as a differentiator but that is modest, and for everyone I have spoken to Windows RT is not worth it.</p>
<ol>
<li><strong>Trim</strong></li>
</ol>
<p>Reduce the OS to the Windows New UI side of its personality, allowing it to live on lighter and cheaper hardware. As Windows 8 drives a new fully featured OS class of tablet, it will not supplant the cheaper, more compact, lighter and battery efficient Android and iOS class of device which we have become used to as consumption devices. RT has a future in the iOS and Android &#8216;Consumption device&#8217; class. To do so it needs to drop its split personality (desktop side) and deliver just the new Widows UI. This would allow RT to be stripped back as an OS which could allow it to be delivered on reduced capacity device design&#8217;s that would slash cost and battery usage. This still does not identify what will stimulate the redressing of the small application ecosystem, as this is just another low end user volume platform competing against two well established platforms in iOS and Android.</p>
<ol>
<li><strong>Kill</strong></li>
</ol>
<p>Discontinue the ARM experiment in light of the point made above over hardware evolution supporting full Windows 8. This is the current consolidated view IF it continues in its current form and lacklustre redressing of blatant short fallings such as no offline SkyDrive storage which makes a mockery of the device as a mobile platform when you think you need to be always network attached!</p>
<ol>
<li><strong>Free</strong></li>
</ol>
<p>One thing is clear something has to happen to allow RT to compete in a class of devices that will not see it being thumped by its big brother Windows 8 as Atom Tablet architectures are already seeing happen. This will probably come over as a heretical idea and likely to be more than out of bounds for Microsoft culture to adapt to BUT there is a real and viable case for releasing Windows RT as an Open Source community effort.</p>
<p>Amongst many viable reasons:</p>
<ul>
<li>Removes license costs from production placing it toe to toe with Android and giving OEM&#8217;s a choice they currently do not have. It&#8217;s Android or nothing in that class of device.</li>
<li>Make a friend with the OEM&#8217;s.</li>
<li>Opening up the closed RT architecture would immediately get the attention of the largest programmer audience in the world.</li>
<li>Put a cat amongst the pigeons with the regulators who have always enjoyed having a snipe at Microsoft.</li>
<li>Microsoft has an established Trusting audience and loyal user base.</li>
<li>Windows 8 UI familiarity on the Desktop will drive adoption.</li>
<li>Free platform does not mean NO revenue. This has the potential of driving explosive growth in applications that will stimulate significant reviews through the Microsoft store.</li>
<li>Community goodwill.</li>
<li>Takes the fight to Google on territory it arrogantly believes it owns.</li>
</ul>
<p>There would be significant challenges, headline ones including:</p>
<ul>
<li>Microsoft cultural readiness.</li>
<li>It is unclear how much opening up the RT code would reveal cross platform x86 insights that Microsoft would rather were not.</li>
<li>It will eat away at the bottom end of the Windows 8 market, BUT this is just the user tier that is adopting Android and iOS devices accepting the restrictions as they do not need power features and functions.</li>
</ul>
<p>Most of the challenges could be dealt with either in the Open License Agreement and or limitations placed on opening up certain parts of the OS code, whilst providing them &#8216;black boxed&#8217;.</p>
<p>Looking at the bigger picture, services and application store revenues are increasingly becoming the new revenue generators. Would &#8216;giving away&#8217; a lightweight OS iteration on a constrained hardware architecture really impact bottom line? I challenge that the ecosystem revenues would out weight that furthermore the momentum it would build behind the new generation of Windows OS&#8217;s in this class would be an accelerator into taking chunks out of the competitions market share for Microsoft.</p>
<p>It is just this type of bold and decisive action that would shake up this class of devices and place Microsoft very much into the tier of innovators again.</p>
<p>Casual discussions with some of Microsoft OEM hardware partners has seen this received with significant interest. Maybe a lunch with them all in the same room could forge a friendly meeting with the power that be at Microsoft?</p>
<br />  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=683&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://nrgfxit.net/2013/01/28/free-windows-rt-a-future-or-not/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/140aeed54fbeba9806e7ee00708e98c0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">nrgfx</media:title>
		</media:content>
	</item>
		<item>
		<title>Oracle puts JAVA users at risk</title>
		<link>http://nrgfxit.net/2013/01/14/oracle-puts-java-users-at-risk/</link>
		<comments>http://nrgfxit.net/2013/01/14/oracle-puts-java-users-at-risk/#comments</comments>
		<pubDate>Mon, 14 Jan 2013 09:53:00 +0000</pubDate>
		<dc:creator>NRG</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Computers and Internet]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Small Medium Enterprise (SME)]]></category>

		<guid isPermaLink="false">http://blog.nigelgibbons.com/?p=645</guid>
		<description><![CDATA[Recently there have been multiple very severe security problems found in Oracle Java. For additional background there are a range of posts online addressing specific details of the exploits and vulnerabilities: US Government Recommends users Disable JAVA What you need to know about the JAVA Exploits Despite Oracle patches JAVA still compromised JAVA fails to [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=645&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Recently there have been multiple very severe security problems found in Oracle Java.</p>
<p>For additional background there are a range of posts online addressing specific details of the exploits and vulnerabilities:</p>
<ul>
<li><a href="http://bits.blogs.nytimes.com/2013/01/14/department-of-homeland-security-disable-java-unless-it-is-absolutely-necessary/" target="_blank">US Government Recommends users Disable JAVA</a></li>
<li><a href="https://krebsonsecurity.com/2013/01/what-you-need-to-know-about-the-java-exploit/" target="_blank">What you need to know about the JAVA Exploits</a></li>
<li><a href="http://www.reuters.com/article/2013/01/13/us-java-oracle-security-idUSBRE90C0JB20130113" target="_blank">Despite Oracle patches JAVA still compromised</a></li>
<li><a href="http://www.kb.cert.org/vuls/id/625617" target="_blank">JAVA fails to restrict access to privileged code</a></li>
</ul>
<p>This is not just another extremely dextrous hacker trick that would be limited in its impact. It is a fundamental failure by Oracle the new owners of JAVA to address fundamental security flaws in JAVA that have led to widespread exploitation.</p>
<p>The worst part of this is Oracle have failed the JAVA community by skirting around the reality of the situation, Quote Java security expert Adam Gowdiak, <em>&#8216;the update from Oracle leaves unfixed several critical security flaws&#8217;</em>.</p>
<p>Because of the severity of this issue and the poor job Oracle has done, it is critical awareness amongst users is proactively promoted with the recommendation that appropriate action is taken to protect themselves and their companies.</p>
<p>The advice is to Uninstall JAVA if you don&#8217;t have a need for JAVA, and if you are unsure that you need it uninstall it to be safe. If in the future users find it is needed, then at least the latest version can be downloaded and easily installed and hopefully by then the problems resolved so the version of JAVA will be secure.</p>
<p>You can uninstall JAVA from the Windows Control Panel &#8216;Programs and Features&#8217; (Vista, Windows 7 and 8) or the &#8216;Add / Remove Programs&#8217; in Windows XP.</p>
<p>If JAVA is perceived to be needed for some reason, firstly check if there is an alternative method of accessing the content. If not and JAVA has to be installed then the advice is to make sure you are running the latest version which can be easily downloaded from <a href="http://www.java.com" target="_blank">JAVA.com</a> this does not guarantee security, in fact the current version <strong><span style="color:#ff0000;">IS NOT SECURE</span></strong>.</p>
<p>The understanding is therefore even after updating to the latest version, you and your company are still exposed. To mitigate this disable JAVA web browser support when it is not explicitly required, only enabling it for sites you explicitly trust, then immediately disable Java support again once you are finished. To disable web browser support for Java on a Windows PC do this:</p>
<ol>
<li>Start &#8211; Control Panel &#8211; Open the Java icon</li>
<li>Click on the security panel and uncheck the box for &#8220;enable Java content in the browser.&#8221;</li>
<li>This will disable Java in your web browsers. You can manually re-enable it if you need it on a specific site.</li>
</ol>
<p>Once Oracle addresses the current security holes in JAVA, it should be safe to re-enable Java support IF you require JAVA. That having been said it would be advisable for organisations to consider alternative technologies to JAVA that are better supported and in today&#8217;s modern multi-device world offer greater flexibility.</p>
<p>Perhaps this will see some sanity come back into decisions by the likes of HP, Dell and Cisco to continue building client management interfaces in JAVA.</p>
<br />  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=645&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://nrgfxit.net/2013/01/14/oracle-puts-java-users-at-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/140aeed54fbeba9806e7ee00708e98c0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">nrgfx</media:title>
		</media:content>
	</item>
		<item>
		<title>Data Security – It’s in the Name!</title>
		<link>http://nrgfxit.net/2012/12/20/data-security-its-in-the-name/</link>
		<comments>http://nrgfxit.net/2012/12/20/data-security-its-in-the-name/#comments</comments>
		<pubDate>Thu, 20 Dec 2012 12:28:42 +0000</pubDate>
		<dc:creator>NRG</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Computers and Internet]]></category>
		<category><![CDATA[Home Computing]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Office 365 and Azure]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Small Medium Enterprise (SME)]]></category>

		<guid isPermaLink="false">http://blog.nigelgibbons.com/?p=688</guid>
		<description><![CDATA[I have just come out of my last meeting before Christmas in which security has been forefront (again) on both business and IT principles minds, and tongues… The bizarre thing is that despite the obvious, the prevalence of IT security systems protect the &#8216;Environment Boundary&#8217; in which data resides or is transmitted, whilst understandable form [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=688&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I have just come out of my last meeting before Christmas in which security has been forefront (again) on both business and IT principles minds, and tongues…</p>
<p>The bizarre thing is that despite the obvious, the prevalence of IT security systems protect the &#8216;Environment Boundary&#8217; in which data resides or is transmitted, whilst understandable form a certain perspective, it is somewhat medieval in its approach to the core &#8216;Data Security&#8217; problems facing organisations and individuals today.</p>
<p>It is all good and well using <a title="Secure Socket Layer" href="http://en.wikipedia.org/wiki/Secure_Sockets_Layer" target="_blank">SSL (Secure Socket Layers )</a> to ensure your communications (data exchanges in transit) are secure. BUT a waste of time if the communicating entities do not apply similar levels of security when the data is stored (data at rest). Even the most inept hacker knows that the easiest point to attack in any data exchange is the client (workstation, notebook, mobile device). The server end of the chain is likely to be more secure environment (not necessarily) than the end users. Hence the prevalence of end user vectored attacks, email being the weakest and most convenient conduit to perpetrate a hack. Once a Hacker can get some malware on a user&#8217;s PC they can just about do what they want with it, and that includes all the data unless the documents and or data is encrypted.</p>
<p>Thus we get to the headline of the article. DATA SECURITY. If all data adopted the same protective measures as the entertainment industry tries to do with their music and movies then less of our private lives would become public, and organised crime feeding off corporate systems selling inside secrets or blackmail would be poorer overnight. Organisations should be securing their CONTENT as well as their IT environments. Currently most organisations actually do &#8216;<em>Environment Security</em>&#8216; NOT &#8216;<em>Data Security&#8217;</em>.</p>
<p><a title="Information Rights Management" href="http://en.wikipedia.org/wiki/Information_Rights_Management" target="_blank">Information Rights Management (IRM)</a> has been around for decades in various guises.. ISV&#8217;s (Independent Software Vendors) are largely ignoring a HUGE market opportunity to tap this capability. Some understand it and build their business on this core feature, but most ignore it and defer security to the IT department&#8217;s ability to secure a whole environment. IRM has never been easier today to implement, without even needing to deploy a service it is possible to tap Wi<a title="Windows Azure AD Rights Management" href="http://technet.microsoft.com/en-us/library/jj585024.aspx" target="_blank">ndows Azure AD Rights Management </a>and have this capability on tap. For organisations using the <a title="Microsoft Office 365" href="http://office.microsoft.com" target="_blank">Microsoft Office 365</a> Online <a title="Software as a Service" href="http://en.wikipedia.org/wiki/Software_as_a_Service" target="_blank">Software as a Service (SaaS)</a> suite it is possible to enable this with ease:</p>
<ul>
<li><a title="Set-up IRM for SharePoint Online" href="http://office.microsoft.com/en-us/office365-sharepoint-online-enterprise-help/set-up-information-rights-management-irm-insharepoint-online-HA102895193.aspx" target="_blank">Set up Information Rights Management (IRM) in SharePoint</a></li>
<li><a title="Set-up IRM for Exchange Online" href="http://technet.microsoft.com/en-us/library/jj585001.aspx" target="_blank">Enabling IRM Services with Exchange Online</a></li>
</ul>
<p>Microsoft Office 365 with Windows Azure AD Rights Management enabled represents one of the most secure and feature complete collaboration environments available on the market today. I would challenge some enterprises to prove a more secure data environment, and this is available to the smallest of organisations for less than £15/mth per user. This default functionality in Microsoft Office 365 is just a baseline, for the more security conscious this can be enhanced exponentially with third party products.</p>
<p>IRM is not full proof, nothing can stop someone re-typing a document or photographing a screen. BUT it represents a significant convenience barrier to those perpetrating corporate espionage and removes any &#8216;accidental&#8217; disclosures.</p>
<p>I suspect though there will be a few more fruitful Christmas seasons for the corporate espionage crime syndicates to roam deserted corporate systems before the penny drops.</p>
<br />  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=688&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://nrgfxit.net/2012/12/20/data-security-its-in-the-name/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/140aeed54fbeba9806e7ee00708e98c0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">nrgfx</media:title>
		</media:content>
	</item>
		<item>
		<title>Still paying for eMail &amp; Website Hosting? Think again…</title>
		<link>http://nrgfxit.net/2012/12/01/still-paying-for-email-website-hosting-think-again/</link>
		<comments>http://nrgfxit.net/2012/12/01/still-paying-for-email-website-hosting-think-again/#comments</comments>
		<pubDate>Sat, 01 Dec 2012 17:26:43 +0000</pubDate>
		<dc:creator>NRG</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Computers and Internet]]></category>
		<category><![CDATA[Home Computing]]></category>
		<category><![CDATA[Small Medium Enterprise (SME)]]></category>

		<guid isPermaLink="false">http://blog.nigelgibbons.com/?p=675</guid>
		<description><![CDATA[If you are a sole operator and still paying for email and website hosting then you are throwing money away. It may not be a lot, but then I guarantee there are richer featured options that you can benefit from. Read on. For many the reasoning is practical. You have your own Domain and you [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=675&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>If you are a sole operator and still paying for email and website hosting then you are throwing money away. It may not be a lot, but then I guarantee there are richer featured options that you can benefit from. Read on.</p>
<p>For many the reasoning is practical. You have your own Domain and you believe this requires you to pay for an email service that supports this. For others it is simply evolutionary, you have had an email and website packaged service many years with Vendor &#8216;X&#8217; and have never evaluated your options so you are still paying for something you don&#8217;t need to.</p>
<p>For many of you in this scenario you may also find the interfaces for mobile connectivity and browser access are retro, as for website management solution (if at all), some websites are still limited to FTP (File Transfer Protocol) management access to a bare directory on the vendors servers, forcing you into the hands of a commercial agency to get any half decent site built and maintained at more cost.</p>
<p>The solution is simple:</p>
<ol>
<li>For eMail = <a href="http://windows.microsoft.com/en-HK/windows/outlook-inbox" target="_blank">Outlook.com</a></li>
<li>For WebSite = <a href="http://www.windowsazure.com/en-us/home/scenarios/web-sites/" target="_blank">Windows Azure Websites</a> (<em>See a follow-on blog for details on this</em>)</li>
</ol>
<p>If you want to see why and fancy a punt at other options such as &#8216;Google&#8217; apart for the privacy issues that you may not be aware of with Google&#8217;s terms and Conditions, have a look at a straight <a href="//windows.microsoft.com/en-HK/windows/outlook-compare" target="_blank">Outlook.com v. GMail Feature Comparison </a>which tells you why Outlook.com is the</p>
<p>If you are still not convince, just one feature should make it for you in this new mobile world we live in and that is <a href="http://technet.microsoft.com/en-us/exchange/bb288524" target="_blank"><strong>Exchange ActiveSync (EAS) </strong></a></p>
<p>For those who like a 3<sup>rd</sup> party opinion then head over to:</p>
<ul>
<li><a href="http://www.vexite.com/2012/gmail-vs-outlook-com/" target="_blank"><em>&#8216;<strong>10 Outlook.com Features That Makes It A Gmail Killer&#8217;</strong></em></a></li>
<li><a href="http://www.thewindowsclub.com/outlookcom-adds-features-transition-gmail-easier" target="_blank"><strong>&#8216;<em>Outlook.com adds new features; some of which make transition from Gmail easier!&#8217;</em></strong></a></li>
</ul>
<p>The following is a summary guide as to how to set-up your eMail and domain on Outlook.com, a separate Blog will cover the Free Website feature in Windows Azure and the rich content management options this can include.</p>
<p>A PDF version of this Guide is available for download &#8211; <a href="http://nigelgibbons.files.wordpress.com/2013/01/outlook-com-admin-configuration-guide.pdf"><em>&#8216;Outlook.com Admin Configuration Guide</em></a>&#8216; (PDF 428kb):</p>
<p><span style="color:#0070c0;font-size:14pt;"><strong>Outlook.com Configuration &amp; Admin Overview Guide<br />
</strong></span></p>
<p><strong>Step 1.<br />
</strong></p>
<p>First off you need a <a href="https://account.live.com" target="_blank">&#8216;Microsoft Account&#8217;</a>, formerly known as Live ID/Hotmail ID/ Passport amongst others. If you already have one then that&#8217;s easy, just jump straight to the <a href="http://mail.live.com" target="_blank">Outlook.com Webmail Login</a>  and voila, you are now running &#8216;Outlook.com&#8217;. If as an existing Microsoft Account holder you get the old Hotmail interface, it is simple to click on the <em>&#8216;Options&#8217;</em> then &#8216;<em>Upgrade to Outlook.com&#8217;</em> link and that is you upgraded, per the image below:</p>
<p><img alt="" src="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying1.jpg?w=630" /></p>
<p>That&#8217;s you set-up with free Outlook.com email on your Microsoft Account. This is not yet active on your own domain or domains. To get your email on your own domains working you need to continue to Step 2.</p>
<p><span style="color:red;"><strong>It is advisable to be ready to move ALL our email accounts to Outlook.com BEFORE you commence Step 2</strong></span>. This should include being clear who controls your domain(s) DNS settings. If in doubt contact your hosting provider AFTER reading through the rest of this guide so you are clear on what is involved.</p>
<p><strong>Step2.<br />
</strong></p>
<p>Configure your domain and get access to Multiple User accounts on your own domain FOR FREE.</p>
<ol>
<li>Head over to the &#8216;<em>Windows Live Admin Center</em>&#8216; at <a href="http://domains.live.com">http://domains.live.com</a></li>
<li>
<div>Click on the &#8216;<strong><em>Get Started&#8217;</em></strong> link&#8217; Assuming you&#8217;re already logged in!</div>
<p><img alt="" src="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying2.jpg?w=630" /></li>
<li>
<div>Enter your domain name. Don&#8217;t get confused by the &#8216;www&#8217; prefix, it is perhaps not the most intuitive way of simply requesting a domain name! Then Click &#8216;<strong><em>Continue</em></strong>&#8216; <img alt="" src="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying3.jpg?w=630" /></div>
</li>
<li>
<div>Next you will have to go through a formality, check the setting s are correct and assuming your OK with the Terms &amp; Conditions click <strong><em>&#8216; I Accept&#8217;</em></strong></div>
<p><img alt="" src="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying4.jpg?w=630" /></li>
<li>
<div>The next screen is a little overwhelming for the non-techies. If you have access to your domain&#8217;s DNS or DNS management page then I assume you know what yru doing, if not you will be emailing a copy of this page to your Domains Registrar or Hosting provider who controls your domains DNS.</div>
<p>In summary this page update your DNS records so that email etc will start getting pointed to your new Outlook.com profile.</p>
<p><strong><span style="color:red;">DO NOT initiate this till you&#8217;re ready for email to STOP arriving at your old email service, and you are ready to set-up all your email accounts on Outlook.com.</span><br />
</strong></p>
<p>You can pre-configure this and leave it as is, note the &#8216;<em>Prove Ownership&#8217;</em> box highlighted in <span style="color:#4472c4;">Blue</span>. Until you have either made the changes or instructed someone else to and this box is replaced with a &#8216;<em>Your Service is Active&#8217;</em> statement your email routing is unaltered.</p>
<p><img alt="" src="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying5.jpg?w=630" /></li>
<li>Assuming were good to go with Outlook.com and you have made the changes noted above in DNS instead of the yellow &#8216;<em>Prove Ownership&#8217;</em> box, you should now see an &#8216;<em>Your Service is Active&#8217;</em> message box as illustrated below:</li>
</ol>
<p><img alt="" src="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying6.jpg?w=630" /></p>
<p>Now you can configure a variety of features from the left hand Admin menu:</p>
<p><strong>Custom Addresses</strong> &#8211; This allows you to create additional Domain URL prefix&#8217;s for your mail domain ie:&#8217;mail.<em>yourdomain.com</em>&#8216; :</p>
<p><img alt="" src="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying7.jpg?w=630" /></p>
<p><strong>User / Members Accounts</strong> – user mailbox&#8217;s (Up to 500!!)</p>
<p><img alt="" src="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying8.jpg?w=630" /></p>
<p><strong>Open Membership</strong> – Great commercial angle to allow you to share your Domain with subscribers to a service or your website:</p>
<p><img alt="" src="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying9.jpg?w=630" /></p>
<p><strong>Co-Branding</strong> – Allow you to brand your email experience, ideal if you are using Open membership features:</p>
<p><img alt="" src="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying10.jpg?w=630" /></p>
<p><strong> Domain Reports</strong> – All important management tool to monitor activity on your email usage, a summary list of available reports below:</p>
<p style="margin-left:18pt;"><img alt="" src="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying11.jpg?w=630" /></p>
<p>You should not be set-up with your Outlook.com service. You can add additional domains to this all managed by your principle Microsoft Account, or any other Microsoft Account you may wish to designate.</p>
<p>Other features you may wish to explore will include the Microsoft Live SkyDrive and Office Web application linkage that you get for collaboration with Outlook.com, you can access this from the Outlook.com mail interface at <a href="http://mail.live.com">http://mail.live.com</a>, top left click the down arrow next to the Outlook banner, see image below:</p>
<p><img alt="" src="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying12.jpg?w=630" /></p>
<p>This will open up a link menu to other rich interface features and SkyDrive for document sharing and Office Web Apps integration:</p>
<p><img alt="" src="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying13.jpg?w=630" /></p>
<br />  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=675&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://nrgfxit.net/2012/12/01/still-paying-for-email-website-hosting-think-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/140aeed54fbeba9806e7ee00708e98c0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">nrgfx</media:title>
		</media:content>

		<media:content url="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying1.jpg" medium="image" />

		<media:content url="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying2.jpg" medium="image" />

		<media:content url="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying3.jpg" medium="image" />

		<media:content url="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying4.jpg" medium="image" />

		<media:content url="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying5.jpg" medium="image" />

		<media:content url="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying6.jpg" medium="image" />

		<media:content url="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying7.jpg" medium="image" />

		<media:content url="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying8.jpg" medium="image" />

		<media:content url="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying9.jpg" medium="image" />

		<media:content url="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying10.jpg" medium="image" />

		<media:content url="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying11.jpg" medium="image" />

		<media:content url="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying12.jpg" medium="image" />

		<media:content url="http://nigelgibbons.files.wordpress.com/2013/01/012113_1725_stillpaying13.jpg" medium="image" />
	</item>
		<item>
		<title>Windows 8 To Go Workspace Creation Guide</title>
		<link>http://nrgfxit.net/2012/11/24/windows-8-to-go/</link>
		<comments>http://nrgfxit.net/2012/11/24/windows-8-to-go/#comments</comments>
		<pubDate>Sat, 24 Nov 2012 15:00:00 +0000</pubDate>
		<dc:creator>NRG</dc:creator>
				<category><![CDATA[Computers and Internet]]></category>
		<category><![CDATA[Home Computing]]></category>
		<category><![CDATA[Small Medium Enterprise (SME)]]></category>
		<category><![CDATA[Windows 8]]></category>

		<guid isPermaLink="false">http://blog.nigelgibbons.com/?p=621</guid>
		<description><![CDATA[The following guide will allow you to configure a USB device that is Windows 8 To Go &#8216;Ready&#8217;. This guide is designed for users who are not yet running Windows 8, and whilst it can be followed if you are running Windows 8 IF you have Windows 8 Enterprise then a much simpler option is [&#8230;]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=621&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>The following guide will allow you to configure a USB device that is Windows 8 To Go &#8216;Ready&#8217;.</p>
<p>This guide is designed for users who are not yet running Windows 8, and whilst it can be followed if you are running Windows 8 IF you have Windows 8 Enterprise then a much simpler option is to use the &#8216;Windows To Go Creator Wizard&#8217; (<i>accessible from the Windows 8 Enterprise Control Panel or search</i>) which automates:</p>
<ul>
<li>USB Device provisioning process,</li>
<li>Windows 8 Instalment (<em>you still need to have the Windows 8 Enterprise install media for this)</em></li>
<li>Bitlocker enablement options that can activate Bitlocker automatically during the Windows To Go creation process.</li>
</ul>
<p>As you are creating a portable instance of your Windows 8 Operating System which is likely to contain private data we strongly recommend you activate the built in bitlocker drive encryption technology.</p>
<p>The process below does not allow you to enable Bitlocker during creation, it requires you to enabled bitlocker drive encryption AFTER creating your ‘Windows To Go Drive’ from within the Windows To Go workspace.</p>
<p>You can download a PDF version of this guide for ease of reference from here: <a href="http://nigelgibbons.files.wordpress.com/2012/11/windows-to-go-creation-guide1.pdf">Windows To Go Creation Guide</a><em> (220 KB PDF)</em></p>
<p><span style="color:#ff0000;"><em>This process requires Windows 8 <strong>Enterprise</strong> install media and does not work with other versions</em></span>.</p>
<p>For a <a title="Windows To Go: Feature Overview" href="http://technet.microsoft.com/en-us/library/hh831833.aspx" target="_blank">Windows To Go Feature Overview</a> and more information please visit the Microsoft TechNet site.</p>
<p><span style="font-size:12pt;text-decoration:underline;"><strong>Preparation Phase:<br />
</strong></span></p>
<p><strong>Step 1. Get the imagex.exe from the Windows Automated Installation Kit (AIK</strong>):</p>
<ol>
<li>Download the Windows Automated Installation Kit (AIK) for Windows 7 (1.7GB) <a href="http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;id=5753">http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;id=5753</a></li>
<li>Download WinRAR, then uncompress the AIK ISO file that you downloaded, browse and extract the Neutral.cab file.</li>
<li>Uncompressed the Neutral.cab with WinRAR, and extract the file name <strong>F1_imagex</strong>.</li>
<li>Rename the file <strong>F1_imagex</strong> to <strong>imagex.exe</strong>.</li>
</ol>
<p><strong>Step 2. Get the install.wim Windows 8 Enterprise Install File:<br />
</strong></p>
<ol>
<li>Download or get your copy of Windows 8 Enterprise</li>
<li>If you have this is ISO format (if you downloaded from MSDN for example) use WinRAR to uncompress the Windows 8 Enterprise ISO file.</li>
<li>Browse the uncompressed Windows 8 Enterprise files going to the <strong>\sources\</strong> folder, extract the <strong>install.wim</strong> file that it should be in there.</li>
</ol>
<p>Copy both the <strong>imagex.exe</strong> and the <strong>install.wim </strong>files to a separate directory.</p>
<p><span style="font-size:12pt;text-decoration:underline;"><strong>USB To Go Creation Phase:<br />
</strong></span></p>
<p><strong>Step 1. Configure your USB drive:<br />
</strong></p>
<ol>
<li>Open a Command Prompt<em> (in Administrator Mode) </em></li>
<li>
<div>Run the following Commands allow each to finish before proceeding to the next:</div>
<ol>
<li><span style="color:#2f3335;font-family:Verdana;font-size:10pt;"><strong>DISKPART</strong></span></li>
<li>
<div><span style="color:#2f3335;font-family:Verdana;font-size:10pt;"><strong>LIST DISK </strong><em>(Note down the Disk number of your USB Device, ie: Disk 1 in my example below)</em></span><em><br />
</em></div>
<p><img alt="" src="http://nigelgibbons.files.wordpress.com/2012/11/112812_1459_windows8tog1.jpg?w=630" /><em><br />
</em></li>
<li><span style="color:#2f3335;font-family:Verdana;font-size:10pt;"><strong>SELECT DISK 1 </strong><em>(Replace 1 with the number of your USB Device from the step before)</em></span><em><br />
</em></li>
<li><span style="color:#2f3335;font-family:Verdana;font-size:10pt;"><strong>CLEAN</strong></span><em><br />
</em></li>
<li><span style="color:#2f3335;font-family:Verdana;font-size:10pt;"><strong>CREATE PARTITION PRIMARY</strong></span><em><br />
</em></li>
<li><span style="color:#2f3335;font-family:Verdana;font-size:10pt;"><strong>SELECT PARTITION 1</strong></span><em><br />
</em></li>
<li><span style="color:#2f3335;font-family:Verdana;font-size:10pt;"><strong>ACTIVE</strong></span><em><br />
</em></li>
<li><span style="color:#2f3335;font-family:Verdana;font-size:10pt;"><strong>FORMAT FS=NTFS QUICK </strong><em>(Format process may take few seconds, longer if you opt to do a full format by leaving off the &#8216;QUICK&#8217; option)</em></span><em><br />
</em></li>
<li><span style="color:#2f3335;font-family:Verdana;font-size:10pt;"><strong>ASSIGN</strong></span><em><br />
</em></li>
<li><span style="color:#2f3335;font-family:Verdana;font-size:10pt;"><strong>EXIT</strong></span><em><br />
</em></li>
</ol>
</li>
</ol>
<p><strong>Step 2. Install Windows 8 Enterprise onto the USB:<br />
</strong></p>
<ol>
<li>Open a Command Prompt<em> (in Administrator Mode) </em></li>
<li>Browse to the folder that has the <strong>Imagex.exe</strong> and now the <strong>install.wim</strong></li>
<li>Run the following command: <strong>imagex.exe /apply install.wim 1 D:\<em><br />
</em></strong><em>(Replace D with your USB drive letter)</em></li>
<li>This write process will take a bit of time, progress is displayed.</li>
<li>Once the write process has completed configure the boot record in the Windows To Go USB drive. Type the following command: <strong>bcdboot.exe D:\windows /s D: /f ALL</strong><br />
<em>(Replace D with your USB drive letter)</em></li>
</ol>
<p>Volia!</p>
<p>Now you should be able to boot to your external Windows 8 Enterprise USB To Go device and complete your installation. Some helpful hints on how to configure the traditional desktop Start Button etc available at <a title="Windows 8 Desktop Prioritisation Guide" href="http://nrgfxit.net/2012/11/20/windows-8-desktop-prioritisation-guide/">Windows 8 Desktop Prioritisation Guide</a></p>
<p><span style="color:#333333;font-family:Georgia;font-size:10pt;"><br />
</span></p>
<br />  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nrgfxit.net&#038;blog=16269867&#038;post=621&#038;subd=nigelgibbons&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://nrgfxit.net/2012/11/24/windows-8-to-go/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/140aeed54fbeba9806e7ee00708e98c0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">nrgfx</media:title>
		</media:content>

		<media:content url="http://nigelgibbons.files.wordpress.com/2012/11/112812_1459_windows8tog1.jpg" medium="image" />
	</item>
	</channel>
</rss>
