AWS launches Amazon Honeycode for code-free app building


Bobby Hellard

25 Jun, 2020

Amazon Web Services (AWS) has announced a fully managed service for customers to build apps quickly without having to worry about any coding

Amazon Honeycode is a visual application builder that can be used to create interactive web and mobile applications backed by an AWS database. 

Users can create mobile and web-based apps that range in complexity from a task-tracking application for a small team to a project management system that controls complex workflows for multiple departments. 

The service is aimed at those that need innovative online capabilities, but can’t necessarily hire experienced software engineers. Instead, Honeycode can help companies to build applications to track and manage things like process approvals, event scheduling, customer relationship management, user surveys, to-do lists, and content and inventory tracking.  

«Customers have told us that the need for custom applications far outstrips the capacity of developers to create them,» said Larry Augustin, vice president, AWS. «Now with Amazon Honeycode, almost anyone can create powerful custom mobile and web applications without the need to write code.»

Honeycode customers can select pre-built templates, with data models and pre-defined business applications all ready to go. Alternatively, users can import data into a blank workbook and use a spreadsheet interface to define the data model and design the on-screen applications themselves. Once fully formed, the application can easily be shared with the rest of your organisation.
 
The idea is to enable more and more businesses to build and access cloud-based services to help navigate a more digital future. It follows yesterday’s Amazon announcement to support 200,000 UK startups with digital training and expertise. The Amazon Small Business Accelerator will help startups navigate the ‘new normal’ and along with Honeycode, will aim to further expand the global footprint of the world’s biggest provider of cloud computing. 

Slack attempts to replace email with Slack Connect tool


Bobby Hellard

25 Jun, 2020

Slack has made its pitch for organisations to finally ditch email with the launch of Slack Connect. 

From today, up to 20 organisations can be added to a single Slack channel, enabling businesses to bring more of their external ecosystems, such as an entire supply chain or third-party marketing, into Slack. 

Previously two companies could connect this way via ‘shared channels’, but through trials, Slack has expanded that capability with the aim to add more in the coming years. The communications platform suggests this is a more secure way of communicating with other partners. 

The company also said it would add efficiencies to workflows, taking conversations out of «siloed email inboxes» and into the right channels with the right people. This way, organisations can come together to work and make decisions more quickly with customers, vendors and partners, according to Slack.

«My vision, as the CISO at Slack, is to make Slack the most secure collaboration environment for businesses,» Said Larkin Ryder, CISO of Slack.

«When you think about the things you have to do as a CISO to make your email environment secure, you have layers and layers of products that you’re adding on to address things like spam and phishing on an ongoing basis. 

«Email is an open front door to security threats to an organisation – $12 billion in losses are caused by business email scams, and 90% of data breaches are from phishing. If you want a more secure collaboration solution for your organisation, the first thing you can do is take your employees out of email and into Slack.»

Slack suggests that its enterprise-grade security features and compliance standards can help prevent data loss. Its recently announced partnership with AWS has also helped to shore up the service with Enterprise Key Management, giving organisations increased control over their data and who can see it.

Apple’s ARM-based Macs won’t support Windows virtualisation


Carly Page

25 Jun, 2020

Users will no longer be able to run Windows virtualisation software once they switch to Apple’s upcoming ARM-based Macs, it has emerged.

In new developer support documents published by Apple, the company confirmed that the switch from Intel to ARM-based processors will prevent users from running Windows on the Mac.

In the document, Apple confirmed that Rosetta 2 – an emulation layer that will enable users to run old apps on new Mac devices – won’t be able to translate x86_64 virtualization apps, which could prevent the virtualisation of Windows environments using apps such as Parallels and VMWare Fusion.

«Rosetta can translate most Intel-based apps, including apps that contain just-in-time (JIT) compilers,» the document reads. «However, Rosetta doesn’t translate the following executables: kernel extensions, Virtual Machine apps that virtualize x86_64 computer platforms.»

In addition to these restrictions, Boot Camp, a popular tool that allows MacBook users to switch between Windows and macOS, will no longer be available for use on devices powered by Apple Silicon.

Although the tool will remain in macOS Big Sur, it will be an Intel-only feature. Non-Intel Macs will not be able to access the tool and the company has not yet announced a replacement.

In a statement, Microsoft confirmed that there’s no official way to install the operating system, telling The Verge that it «only licences Windows on ARM to OEMs». When asked whether it plans to change this policy to allow Boot Camp on ARM-based Macs, and the company said “we have nothing further to share at this time».

It remains unclear whether virtualisation companies are working on a solution for ARM-based Macs, though VMWare on Tuesday announced that Big Sur-compatible «tech preview» of Fusion will arrive in July.

What’s more, Apple showed off a Mac with an ARM-based A12Z Bionic SoC running a Linux distribution in Parallels during its WWDC keynote this week, suggesting that the company is working to support virtualisation software.

HPE continues cloud push with new GreenLake services


Jane McCallion

24 Jun, 2020

HPE’s edge-to-cloud mantra continues to permeate its products, with the company announcing new cloud offerings available through its GreenLake «as a service» platform at its HPE Discover 2020 virtual event.

Machine learning, operations, containers, virtual machines (VMs), storage, compute, data protection, and networking are now all available through the GreenLake Central self-service console

This, the company says, allows users to choose a configuration that suits them, and manage it, scaling up or down, as they need.

With these new GreenLake services, however, the company is offering customers a choice of 17 pre-defined configurations, delivered in three sizes – described by HPE as small, medium and large «t-shirt sizes» – rather than full customisability. This mode of delivery speeds up the order-to-run process to as little as 14 days, the company claims.

“[This is] a new generation of cloud services from GreenLake, bringing a new level of speed and agility to the on-prem cloud services market,” said Keith White, SVP and GM of HPE GreenLake Cloud Services, during a press and analyst briefing.

White said the use of pre-configuration as a way to bring «a whole new level of automation and simplicity» to HPE’s customers.

«I think the easiest way to think about these building blocks is kind of like Lego bricks,» he explained. «With Legos, you can build almost anything with a few standard blocks. 

«These can look and feel like custom offerings, but as we do it through these standard blocks and ‘t-shirt sizes’, this really accelerates time to customer, accelerates time to market for the customer’s solution and more importantly accelerates time to value for the customer.»

The service is then installed and connected by the company’s Pointnext services division, as well as through channel partners.

“Think of it as leveraging our whole HPE portfolio – hardware, software, Pointnext Services and the power of HPE FS. With third parties, we can provide complete secure and integrated services for our customers,” White added

GreenLake cloud services for VMs, compute, storage, data protection, and intelligent edge are available immediately worldwide. GreenLake cloud services for the newly announced HPE Ezmeral software portfolio, consisting of ML Ops and Containers, is currently in beta, with general availability expected for the company’s fiscal fourth quarter of the year, which ends on 31 October.

HPE launches Ezmeral software portfolio – but is it just SBS in disguise?


Jane McCallion

24 Jun, 2020

Not three years since it spun out its Software Business Segment to Micro Focus in an $8.8 billion deal, HPE has launched a new overarching software portfolio called HPE Ezmeral.

The name is inspired by the Spanish word for emerald – esmeralda – giving it a touch of the green-coloured branding that permeates the company now, from its logo to GreenLake «as a service» platform.

Ezmeral is, according to the company, a brand new software portfolio designed to help organisations make the most of their computing with an edge-to-cloud strategy. It includes two products, currently: Ezmeral ML Ops and Ezmeral Container Platform.

Ezmeral Container Platform, as the name suggests, allows organisations to deploy and manage containerised applications, be they cloud-native or cloud non-native, at scale on any infrastructure, be that in the cloud, a colocation facility, on-premises data centre or at the edge.

Ezmeral ML Ops, meanwhile, is focused on machine learning. It uses containerisation to manage the machine learning lifecycle in its entirety across edge, cloud, and on-premises infrastructure, allowing users to standardise workflows and, the company claims, reduce the time taken for AI deployments from months to days.

But is Ezmeral just SBS by another name? When asked by IT Pro, HPE CEO Antonio Neri said this was not the case.

“We made the decision to spin the software business [in 2016] because we felt there was not a cohesive strategy to begin [with]. You know, it was a very good portfolio of assets, in the wrong domains but not architected for the cloud reality [in which] we all live – and AI reality,” Neri said

“So not only did we do the right thing by spinning them and combining with a company which was way more focused on that space, but it also freed us up to really pivot harder to this new way to deploy software. And obviously it’s taken us a little bit of time, but I’m super excited about what we’re doing with HPE Ezmeral, with our Container Platform, with the integration of the acquisitions we’ve done, with the utilisation of AI in the form of HPE Infosight, and also the security aspect.”

It also, he said, allows the company to make the best use of assets from recent acquisitions including MapR and BlueData

Both of the current elements of Container Platform and ML Ops will be available on a consumption-based pricing model via the company’s GreenLake «as a service» platform, and as traditional software, too. It’s open in beta currently and HPE is taking applications to join the beta platform, with general availability expected in Q4 this year.

HPE announces new services from Pointnext to help businesses get back to work


Jane McCallion

23 Jun, 2020

As it gears up for its first virtual Discover conference, HPE has announced five new offerings to help businesses in their efforts to recover from the COVID-19 crisis.

Delivered through the company’s Pointnext Technology Services division, the “return-to-work as a Service solutions” use HPE Proliant Servers, EdgeLine Converged Edge Systems and Aruba AI-powered network infrastructure, as well as technology from partners like Kognition and Venzo Secure, to enable organisations to safely bring workers back into the office as they reopen.

This includes a fever detection system, touchless entry, social distancing enforcement and tracking, augmented reality for more effective communication with remote workers – of which there will likely be many even once offices reopen – and workplace alerts.

For contactless building entry, the system uses biometrics – facial recognition in particular – multi-factor access control, and identity verification. This will reduce or eliminate the amount that workers are touching shared access points like doors, ensuring a more hygienic workplace, the company said.

The fever detection system, meanwhile, uses thermal cameras, machine learning and video analytics to pick out and alert anyone with a high temperature in the office, and the social distancing pillar uses Bluetooth technology to alert workers if they’re getting too close to each other, track the location of specific employees and facilitate contact tracing.

While the technical element of the AR/VR system is relatively well defined – an AR system provided in partnership with PTC and HPE’s Visual Remote Guidance (VRG) product – the use case is a little fuzzier, although the company says it can provide better learning and collaborative experiences, as well as allowing users to be guided through a complex procedure like replacing a gas valve remotely.

Finally, there’s the workplace alert system. This is already part of the company’s Intelligent Workplace offering, which the company said this initiative builds on, and allows organisations to push notifications to workers using dashboards and apps. This could be particularly useful to notify those in a particular building if someone there had tested positive for COVID-19 and that they should begin isolation, rather than sending a company-wide message incorporating people working at sites that are unaffected, for example.

Saadat Malik, vice president of IoT and Intelligent Edge Services, at HPE, said: “Since the COVID-19 outbreak, our customers have turned to HPE to help them adapt to unique challenges presented by the pandemic to maintain business continuity. 

«We have been there for them throughout these difficult times, on everything from supporting a transition to a remote workforce with our comprehensive virtual desktop interface (VDI) solutions, to now helping them return back to work and to a new normal.

“As businesses are reopening and returning employees onsite, our new robust solutions, featuring a range of HPE technologies and partner capabilities, are helping them make this transition safely while building on a highly differentiated, long term workplace digitization strategy.»

All five services are available worldwide from HPE’s Pointnext professional services business and use Greenlake’s as a service subscription consumption model starting today.

Safe Documents sandbox tool released for Microsoft 365


Keumars Afifi-Sabet

23 Jun, 2020

Microsoft has rolled out its Safe Documents feature for all Microsoft 365 customers in a bid to boost enterprise security by verifying untrusted files when they’re opened by a user.

When enabled by an administrator, the feature will automatically scan documents for any threats after opening the file in Protected View. This is an additional step which involves uploading and scanning by Microsoft Defender ATP.

Safe Documents essentially brings the power of the firm’s enterprise security platform Intelligent Security Graph to the desktop, with access to a live dataset of billions of data points, combing to form massive security-centric datasets.

The feature has been rolled out to rectify the limitations of Protected View, which is currently in play for all Microsoft 365 users. When opening documents received from external sources, the company suggested, people often exit the Protected View sandbox without considering whether the document is safe.

It was initially previewed in February 2020, when it was touted as a means to automate a crucial phase in the security of opening documents, which may often be overlooked if this decision is in the hands of the individual user.

«While a scan is in progress, Safe Documents will prevent users from exiting the Protected View container,» Microsoft’s security employee Kenny Shi said. «Users are still able to access and read the document during this process but will be unable to make any edits until the scan has completed.

«Once the file has been successfully scanned, users will be able to leave the Protected View container with confidence that their file is safe.»

If the file being scanned is identified as being malicious, users will be prevented from leaving Protected View entirely, with administrators able to decide whether users can bypass and ‘enable editing’ for malicious files using the Admin portal.

In addition to the added security features, IT admins will be given access to an Advanced Hunting feature to get additional analytical information on users.

Safe Documents is turned off by default, with security administrators able to activate the feature by navigating to the Security and Compliance centre within Microsoft 365. Organisations will need a Microsoft 365 E5 Security license in order to use the feature.

Employees are overlooked in digital transformation processes, study claims


Sabina Weston

22 Jun, 2020

Just 5% of IT managers consider employees as their top priority when making technology investments, which stifles productivity and causes staff to become overwhelmed.

That’s according to a new study from Lenovo, which surveyed 1,000 IT managers from the UK, Netherlands, France, and Germany. 

The research that employees are often overlooked in the process of digital transformation, with the majority (62%) of respondents reporting that their investment decisions are entirely business-centric.

This leads to new technology slowing down processes instead of improving them, according to a fifth of employees. Lenovo suggests that, in order to experience the full potential of the newly-implemented technology, businesses should ask people-centric questions during the adoption process.

The study also found that flexible working policies introduced during the coronavirus pandemic provided employees with a greater level of support, signalling the emergence of a more people-centric approach. In fact, 70% of respondents have observed more emphasis within their organisation on responsible business.

President of Lenovo’s Data Center Group for EMEA Giovanni Di Filippo said that, although “organisations place greater emphasis on the wellbeing of their employees, (…) the study shows that this is only the beginning”.

“If there is a change of heart and mind within the industry, taking a people-first approach to IT adoption, we will see positive change for both organisations and wider society. Happier employees, greater productivity and a faster pace of innovation – these are the benefits of placing people at the centre of IT decisions,” he said.

However, for the time being, many employees still feel overwhelmed by the complexity and pace of digital transformation– almost one in two (47%) IT managers reported that users struggle to embrace new software.

According to Di Filippo, “data and technology cannot be transformative without humans bringing it to life and giving it purpose”.

“We want businesses to think human by investing in ‘Smarter Technology for All’. As for vendors – it’s time to think beyond what they make and consider who they make it for. If people are put first, we know the benefits and desired company outcomes will be great.”

The challenges presented by the coronavirus pandemic and resulting lockdown can also be credited with accelerating transformation plans, with digital technology enabling the overwhelmed NHS to keep providing vital services to millions of patients.

Microsoft acquires data model provider ADRM


Keumars Afifi-Sabet

19 Jun, 2020

Microsoft has snapped up enterprise data modelling company ADRM Software with a view to combining the firm’s “information blueprints” with Azure storage and compute to create sophisticated data lakes.

ADRM, which providers large-scale sector-specific industrial data models to large enterprises, has built and refined its services over decades for business-critical analytics. These models allow organisations to more completely capture and define their business processes and build interoperability across IT infrastructures.

Microsoft is hoping to combine these comprehensive industrial models with the limitless storage and computing power of Azure to create intelligent data lakes where data from several lines of businesses can be combined more efficiently.

“Data and AI are the foundation of modern technological innovation, yet businesses today struggle to unlock the full value data has to offer as fragmented data estates hinder digital transformation,” said Microsoft’s CVP for Azure Global Industry Ravi Krishnaswamy said.

“Without a comprehensive and integrated view of their data, companies are at a competitive disadvantage, which hinders digital adoption and data-driven innovation.

Combining ADRM Software’s services with Azure, these capabilities can be offered to enterprises at scale, and allow customers to embark on digital projects quicker and with less risk, Microsoft explained.

Although data and AI are considered key to modern innovation, many businesses struggle to fully extract value from datasets due to fragmentation. Without a comprehensive and integrated view of their data, companies may find their digital transformation plans disrupted. This is the issue that Microsoft is hoping to resolve by feeding ADRM’s data models into its cloud computing platform.

“As we worked closely with the Azure global engineering team during the past year, we became very enthusiastic about the tremendous additional value and acceleration we believe can be unlocked for large enterprises across many industries,” said ADRM Software in an announcement.

The post added that the data lakes that can be created as a result of the acquisition aren’t “just vast reservoirs” but are also metadata-rich foundations that can supercharge data warehouses, analytics, AI and machine learning.

‘Severe’ Cisco WebEx flaw grants hackers access to meeting data


Keumars Afifi-Sabet

19 Jun, 2020

Cisco has patched a dangerous flaw that allows a hacker to access victims’ accounts from another machine in order to see all meetings, individuals invited, meeting passwords and past meeting records.

The shared memory information leakage vulnerability, found in the Cisco WebEx Meetings desktop app for Windows, allows an authenticated attacker to gain access to sensitive information either locally, or by running a malicious programme.

Assigned CVE-2020-3347, the exploitation is based on the unsafe usage of shared memory used by the video conferencing platform’s desktop client, according to Trustwave researchers, who discovered the flaw.

Once the WebEx Meetings application is installed, it adds an application to the tray that starts up automatically once the user logs on. If the user has configured the client to log on automatically too, which by default it does, several memory-mapping files open, with some unprotected from opening for reading and writing.

An attacker with permissions to view system memory could exploit this vulnerability by running an application that’s designed to read shared memory. The hacker can loop over sessions and try to open, read and save content for future examination.

Successful exploitation could give the hacker the power to retrieve sensitive information through this mechanism, including usernames, meeting information, as well as authentication tokens that can be used in future attacks.

“Due to the global pandemic of COVID-19, there’s been an explosion of video conferencing and messaging software usage to help people transition their work-life to a work from home environment,” said Trustwave security research manager Martin Rakhmanov.

“Vulnerabilities in this type of software now present an even greater risk to its users. Cisco WebEx is one of the most popular video conferencing solutions available, so I decided to turn my research skills to see how secure the platform is.

“In an attack scenario, any malicious local user or malicious process running on a computer where WebEx Client for Windows is installed can monitor the memory-mapped file for a login token. Once found the token, like any leaked credentials, can be transmitted somewhere so that it can be used to login to the WebEx account in question, download Recordings, view/edit Meetings, etc.”

Cisco has released a software update addressing this vulnerability, urging users to update their Cisco Webex Meetings software to version 40.6.0 and higher. The “relatively severe” flaw affected versions of the platform released earlier than this, with Rakhmanov testing the exploitation on version 40.4.12.8.