Microsoft Azure flaw exposed ‘thousands’ of customer databases


Bobby Hellard

27 Aug, 2021

Microsoft has warned thousands of its Azure cloud customers that their main databases have been compromised.

The impacted customers included some of the world’s largest companies, according to cyber security researcher Wiz. 

The vulnerability is in Microsoft’s Azure Cosmos database and allows intruders to read, change and even delete customer information, according to Wiz. The researchers were able to find keys that control access to databases held by «thousands» of companies.

The chief technology officer of Wiz, Ami Luttwak, is former CTO of Microsoft’s Cloud Security Group. Her team found the exploit, dubbed ‘ChaosDB’, on 9 August and notified Microsoft on 12 August. 

«This is the worst cloud vulnerability you can imagine. It is a long-lasting secret,» Luttwak told Reuters. «This is the central database of Azure, and we were able to get access to any customer database that we wanted.»

IT Pro has approached Microsoft for comment, but it seems that it cannot change the access keys by itself, according to emails sent by the company to Wiz. The tech giant has reportedly agreed to pay the security researchers $40,000 for finding the flaw and reporting it.

In the email to customers, Microsoft said it has fixed the vulnerability, adding that there was no evidence the flaw had been exploited: «We have no indication that external entities outside the researcher (Wiz) had access to the primary read-write key,» it said. 

This latest disclosure comes just a few months after the SolarWinds hack, where actors suspected to be working for the Russian government stole Microsoft’s source code and caused breaches and issues around the world.

Exchange email flaws were still cropping up last week, with the US government sending out a warning that customers needed to instal patches that were issued months ago because ransomware gangs were now exploiting them. 

IBM launches SASE services


Danny Bradbury

26 Aug, 2021

IBM has unveiled a set of secure access service edge (SASE) solutions to help customers secure complex distributed work environments. ​

SASE is a concept first articulated by Gartner in a 2019 white paper. It combines security and SD-WAN in a cloud-based approach designed to embed security directly into the network. This enables companies to apply security policies in the cloud that govern users no matter where they are. 

Because the network and security are software-defined, administrators can manage them programmatically, making it easier to update these policies across the organisation. 

IBM Security Services for SASE is an end-to-end offering covering strategic consulting, design and integration, and application onboarding. It also encompasses a set of managed security services in the cloud to protect user sessions and data, such as secure web gateways, cloud-based firewalls, cloud access security broker services and data loss prevention. 

Zero-trust security is another big component of SASE. This part of the solution removes implicit trust for people that access the network and verifies their identity when accessing resources inside the company’s infrastructure. Zscaler, with which IBM partnered in May, will provide the zero-trust functionality for IBM’s SASE portfolio. 

IBM sees potential for its SASE services in areas such as hybrid workforce access, contractor and third-party access, and edge computing scenarios. It can also help to secure businesses undergoing mergers and acquisitions, the company said. 

IBM commissioned a study from Forrester to support its SASE roll-out, and it found 60% of companies lacked a clear security strategy spanning their entire cloud deployment.

Most companies (70%) found it challenging to implement centralised security controls across multi-cloud environments, while almost two-thirds found it difficult to secure their remote and in-office employees across multiple devices and locations. 

Microsoft hires AWS veteran Charlie Bell for VP role


Bobby Hellard

26 Aug, 2021

Microsoft has reportedly hired former Amazon Web Services (AWS) executive Charlie Bell for an undisclosed position.

Bell, who left AWS earlier in August, has been listed as a ‘corporate vice president’ but assigned to the department led by Kathleen Hogan, Microsoft’s chief human resources officer, according to CNBC sources.

It’s unlikely that Bell will stay within the human resources team at Microsoft, given his 23-year career at AWS was largely spent developing services such as EC2 and S3 computing and storage. He was also reportedly a candidate to succeed Andy Jassy as the cloud giant’s CEO.

The secrecy around his role is thought to be due to a ‘non-compete clause’ he may have signed with AWS. The Information reports that «people familiar with the matter» said Bell is going to take «a few weeks off» while Microsoft and AWS work out what Bell can do in his new role without violating the non-compete agreement.

AWS is well known for using the practice of non-compete agreements, which prevents one party from participating in activities that would directly compete with the other party, and has taken legal action against a number of former employees for breaking these agreements.

In 2019, ex-global director of financial services, Philip Moyer was taken to court after leaving AWS for a similar role at Google. Brian Hall, a former VP of product marketing at AWS, was also hit with legal action after leaving for Google Cloud. In both cases, AWS alleged that it was the terms of the new role that violated the non-compete agreement.

Whatever role Bell eventually takes, he brings extensive leadership experience to Microsoft, having held management roles at Oracle and an engineering position at Boeing in the early 1980s. He also ran his own business, Server Technologies Group, which was acquired by Amazon in 1998, kicking off his career with AWS.

Managed edge services market primed for growth


Danny Bradbury

24 Aug, 2021

IDC has predicted a bright future for the managed edge computing services market as multiple drivers compel businesses to rethink their computing architectures. 

The market research company forecasts worldwide revenues of $445.3 million for the managed edge services market this year, up 43.5% compared to 2020. This positive trend will continue until at least 2025, with a compound annual growth rate of 55.1% during that period. 

Managed edge services are low-latency services that process data near the edge of a network, closer to where it is consumed and produced. Services in this emerging market range from content distribution through to edge application hosting and real-time data analytics. 

IDC has identified three types of managed edge services environments. On-premises or private deployments located at the customer’s facilities, such as production plants or health care facilities, will be the fastest-growing use case with a five-year CAGR of 74.5%. An example might be augmented reality services or industrial automation.

Service provider deployments in a public cloud service or telco’s premises will enjoy the second-fastest growth. IDC added that this use case will involve fixed and mobile deployments and would be significant for sector-specific applications. It expects a CAGR of 59.2%, making it the largest market segment by next year. 

Finally, IDC singled out content distribution network (CDN) services as a specific use case. CDNs will continue to refine their services with new edge technologies. IDC expects more personalized and interactive media experiences from the CDN managed edge services segment, enjoying a 41.9% CAGR over five years. 

A key driver for the deployment of managed edge services is the need for process efficiencies. Analysts also pointed to new consumer applications, such as augmented and virtual reality. 

Data sovereignty and security measures will also be big drivers as companies strive to maintain regulatory compliance while pursuing better customer experiences. 

5G will also play a big part in managed edge services, the company said. Cloud service providers will partner with 5G infrastructure companies — typically telcos. Data center operators will also be eager to participate, as will network equipment vendors and software companies. ​

Zoom charts course for ‘hybrid’ office return


Keumars Afifi-Sabet

25 Aug, 2021

Zoom is preparing its employees for a return to the workplace on a hybrid basis blending in-person office-based work with remote working.

The company has rejected any notion of returning to the office on a full-time basis, with flexibility a key priority in the formulation of these plans. It’s pertinent given just 1% of staff want a full-time return, with a quarter warning to work from home permanently, and more than half requesting a blend of the two.

Zoom also suggests it won’t rush office reopenings, and won’t do so until any given office space is fitted with personal protective equipment (PPE) and social distancing policies. The company had reopened its office in Sydney this summer but closed it shortly after due to a re-emergence of COVID-19 in the local area.

“There isn’t a one-size-fits-all approach to returning to the office, and we’re listening to our employees to understand their concerns and help guide our plans,” said Zoom CFO, Kelly Steckelberg.

“Any decision we make at Zoom ladders into one goal: maintaining a mutual sense of trust between leadership and employees, as higher trust leads to a happier, more productive workforce. We’re carefully listening and learning, but ultimately, our office reopenings will be one component of a flexible, hybrid approach.”

During COVID-19, Zoom became the poster child for remote working and mid-pandemic communication, with businesses and consumers in equal measure resorting to the video conferencing service to stay in touch.

As the company swelled in reputation and revenue, it began investing in developing its core platform, addressing major security concerns, and building alternative technologies. Recently, for example, the firm announced new hardware that promises more office-style experiences for remote workers, including hosting video conferencing services on a TV.

The company is promoting its own technology and features as allowing it to take this hybrid approach, including the Zoom Rooms Smart Gallery, that’s designed to create an inclusive experience for in-person and remote workers. 

Zoom is the latest tech company to outline its return to work plans, after Google, for example, approved the majority of requests from its staff to work remotely or relocate. LinkedIn, too, has allowed remote working after initially being hesitant. 

Apple, by contrast, has held a hard stance on hybrid working, requiring its employees to return to the office at least three days per week. Its plans to reopen offices, however, have been delayed due to a spike in COVID-19 cases, with October set as the next date by which the firm will return to the workplace. 

IBM unveils on-chip AI accelerator for fraud detection


Bobby Hellard

23 Aug, 2021

IBM has unveiled its long-awaited ‘Telum’ chip, built with AI inference acceleration that will allow for fraud detection while a transaction is occurring.

The new processor was showcased at the annual Hot Chips conference with the first Telum-based system planned for 2022. 

Telum is IBM’s first processor to contain «on-chip» acceleration for artificial intelligence (AI) inference. The tech giant spent three years developing the «breakthrough» hardware, which is designed to help customers across banking, finance, trading, insurance applications and customer interactions. 

The processor is designed to enable applications to run efficiently where the data resides, differentiating it from traditional enterprise AI approaches that tend to require significant memory and data movement capabilities to handle inferencing. With the accelerator in close proximity to mission-critical data and applications, however, IBM suggests that enterprises can conduct high volume inferencing for real time-sensitive transactions without invoking off-platform AI solutions, which could potentially impact performance. 

«Today, businesses typically apply detection techniques to catch fraud after it occurs, a process that can be time-consuming and compute-intensive due to the limitations of today’s technology, particularly when fraud analysis and detection is conducted far away from mission-critical transactions and data,» IBM said. 

«Due to latency requirements, complex fraud detection often cannot be completed in real-time – meaning a bad actor could have already successfully purchased goods with a stolen credit card before the retailer is aware fraud has taken place.»

The chip was built on 7nm extreme ultraviolet tech, created by Samsung, and features eight processor cores that have a «deep-scalar out-of-order instruction pipeline» running with more than 5GHz clock frequency. IBM said that these were optimised for the demands of heterogeneous enterprise-class workloads.

It features a completely redesigned cache and chip-interconnection infrastructure that provides 32MB cache per core that can scale to 32 Telum chips. The dual-chip module design contains 22 billion transistors and 19 miles of wire on 17 metal layers.

Zoom’s new hardware promises the ‘ultimate home office’ experience


Bobby Hellard

20 Aug, 2021

Zoom has announced new services that promise more office-style experiences for remote workers that includes hosting the video conferencing platform on a TV.  

The company has been working with its hardware partners, Amazon and Facebook’s Portal TV, to develop a suite of services that ensure workers have the best experience no matter where they are. The idea is aimed at those who might be tired of using their laptop for all elements of their work and want more options for where in the home they can work. 

«As companies around the world shift toward a hybrid work model, they’ll need to provide remote workers with the same capabilities as on-site workers so they can effectively communicate and collaborate,» Zoom’s head of hardware partner marketing, Gerard Bao, said in a blog post. 

«Last July, we launched our Zoom for Home offering to help organisations make the transition to hybrid work and empower workers. To continue this effort, we’ve worked with our partners to develop solutions that help our users create the ultimate home office setup.»

It starts with Amazon’s second-gen Fire TV Cube, which now has a Zoom app that allows users make calls with the biggest screen in their home (if they also have a compatible webcam). 

For a more immersive experience, Zoom can also be set up through DTEN’s portable console, the DTEN Go. This includes four cameras, 12 microphones and 160 degrees of coverage that can turn your living room into a ‘Zoom Room’. It can also be paired with a DTEN Mate 10-inch tablet that offers more collaborative features, such as a digital whiteboard. 

For those that need to get up and move while working from home, Zoom’s integration with Facebook’s Portal TV could be an ideal solution. The service uses smart camera technology that pans and zooms to keep the user in the frame and also offers the usual features available on normal Zoom services, such as breakout rooms and virtual backgrounds.

Facebook unveils VR remote working experience, Horizon Workrooms


Keumars Afifi-Sabet

20 Aug, 2021

Facebook has launched a fully immersive virtual reality (VR) remote working experience, powered by the Oculus Quest 2 headset, that tries to mimic physically being in a workplace.

With Horizon Workrooms, workers can beam their own comic book-style avatar into a virtual office and perform office-based tasks alongside their colleagues, as they might in a real-world setting. Such activities include working at their terminal, brainstorming, socialising, and listening to presentations.

“Workrooms is our flagship collaboration experience that lets people come together to work in the same virtual room, regardless of physical distance,” Facebook said. 

“It works across both virtual reality and the web and is designed to improve your team’s ability to collaborate, communicate, and connect remotely, through the power of VR – whether that’s getting together to brainstorm or whiteboard an idea, work on a document, hear updates from your team, hang out and socialize, or simply have better conversations that flow more naturally.”

This VR experience, which businesses can sign up for in its beta state, is a logical extension of how collaboration tools have attempted to mimic the in-office experience.

Tech firms, like Microsoft and Google, have made efforts to improve their workplace collaboration tools over the last 18 months after COVID-19 forced the majority of office-based workers into some form of remote working. 

While these efforts have improved the remote working experience, they’ve largely failed to live up to the real deal, whether it’s through advances in video conferencing or iterative improvements to platforms such as Microsoft Teams. This is because of the fundamental physical disconnect that remains with remote and virtual working. 

It’s resulted in a new type of fatigue among many remote workers, with crucial aspects such as the office culture also going amiss.

As such, many businesses have instead opted for hybrid models as we emerge from the pandemic, which delivers a ‘best of both worlds’ scenario for a majority of employees. 

Facebook argues that its horizon Workplace experience, which is currently being used by Facebook employees, “transforms your home office into your new favourite meeting room”, and your desk into a shared table where you can gather with teammates. 

​

Remote workers can also synchronise their computers with the virtual environment, and work on a virtual terminal, take notes, and share their screens with colleagues. 

The technology is powered by spatial audio, expressive avatars and hand tracking, which lets you use your hands to point, type or give a thumbs-up. 

The innovation builds on Mark Zuckerberg’s longstanding vision to build a metaverse that users can readily tap into and out of. 

The Facebook co-founder recently ramped up the rhetoric behind this concept, suggesting in July 2021 that his company’s future, and that of the internet, lied in the “metaverse”, according to Bloomberg. 

It’s something that’s been on the executive’s mind for many years, however, with Oculus hiring the former Google Glass lead engineer Adrian Wong in 2014 for a job as a ‘professional daydreamer’, with the task of “building the Metaverse”.

Microsoft to raise prices for Office 365 and Microsoft 365 in March 2022


Bobby Hellard

20 Aug, 2021

Microsoft has announced price increases for both Office 365 and Microsoft 365 services that will come into effect in March next year.  

The changes will apply to its commercial and business services, with consumer and education subscriptions remaining the same. 

The increase will also apply globally, with local market adjustments for certain regions, however only US pricing is available at present: Microsoft 365 Business Basic is going up from $5 to $6 per user and Microsoft 365 Business Premium will increase from $20 to $22. Office 365 E1 will rise from $8 to $10, Office 365 E3 will jump up from $20 to $23, Office 365 E5 will move from $35 to $38 and Microsoft 365 E3 changes from $32 to $36. 

These are the first «substantive» price increases to Office 365 since it was launched a decade ago, according to Microsoft, with only minor changes to the suites coming in over the last ten years. The reasoning for hiking them up now is partly to do with the higher demand for cloud-based services brought about by the pandemic, according to Jared Spataro, the corporate vice president for Microsoft 365.

«As leaders around the world look to empower their people for a more flexible, hybrid world of work, it’s clear that every organisation will need a new operating model across people, places, and processes,» Spataro wrote in a blog post. «We’re committed to building on the value we’ve delivered over the past decade to continuously provide innovation that helps our customers succeed and thrive today and well into the future.»

The changes follow a period of immense growth for Microsoft and its cloud services; the firm recently surpassed the milestone valuation of $2 trillion and it has more than 300 million paid seats for Office 365. The tech giant has also added more than 20 apps to Office 365 since it originally launched, including Microsoft Teams, OneDrive and SharePoint.

Zoom is no longer compatible with GDPR, Hamburg data watchdog


Bobby Hellard

19 Aug, 2021

A German data protection commissioner has officially warned Hamburg’s Senate Chancellery to avoid using Zoom as it is no longer compatible with GDPR.

Hamburg’s acting Commissioner for Data Protection and Freedom of Information, Ulrich Kühn, said in a press release that the on-demand version of the video conferencing platform does not meet the legislation’s criteria when it comes to data transfers.

He cites the European Court of Justice’s (CJEU) Schrems II decision, announced in July 2020, which invalidated the EU-US data transfer mechanism known as Privacy Shield and required alternative mechanisms to be more rigorous.

«All employees have access to a tried and tested video conference tool that is unproblematic with regard to third-country transmission,» Kühn wrote. «As the central service provider, Dataport also provides additional video conference systems in its own data centres. These are used successfully in other countries such as Schleswig-Holstein. It is therefore incomprehensible why the Senate Chancellery insists on an additional and legally highly problematic system.»

The issue appears to relate to a dispute over the way Zoom has used standard contractual clauses (SCCs) to justify its data transfers. On it’s website, Zoom says its services feature «an explicit consent mechanism for EU users» on its platform and that the firm has implemented «zero-load» cookies for users whose IP address show they are visiting the site from an EU member state. Specifically, the firm states: «we ensure that the transfer is governed by the European Commission’s standard contractual clauses (SCC)».

However, following the Schrems II decision in July 2020, companies are now required to perform additional steps to justify their use of SCCs, including performing additional risk assessments – something that Zoom appears not to have done.

Neil Brown, the director of virtual English law firm decoded.legal, told The Register that the press release was «somewhat oblique» but suggested that the Hamburg Data Protection Authority considers that Zoom does not ensure a level of protection for personal data which is «essentially equivalent» to that afforded by the GDPR.

«Many businesses used to address the international transfers aspect of the GDPR by incorporating the model contract clauses/SCCs into their contracts with organisations in non-adequate jurisdictions,» Brown told The Register. «In Schrems II, the CJEU said that these were not, in themselves, sufficient, and that a transferring controller must do a comprehensive risk assessment, and put appropriate additional measures in place to ensure ‘essentially equivalent’ protection.

«And that came as a shock to a lot of people, since it rather suggested that the model clauses were not fit for purpose. And, lo and behold, there is a new European set, which is a heck of a lot more complicated.»

In a statement, Zoom said it was proud to work with the City of Hamburg and many other leading German organisations, businesses and education institutions.

«The privacy and security of our users are top priorities for Zoom, and we take seriously the trust our users place in us,»  the firm said. «Zoom is committed to complying with all applicable privacy laws, rules, and regulations in the jurisdictions within which it operates, including the GDPR.»