Tuesday, December 23, 2014

RPX buys Apple-backed Rockstar patents for $900 million

- Patent risk management company RPX Corp said on Tuesday it would buy patents owned by Apple Inc and other firms for $900 million, helping to further scale back lawsuits over smartphone technology.

The sale consists of the more than 4,000 patents still owned by Rockstar Consortium, which was formed from the $4.5 billion purchase of about 6,000 Nortel Network Corp patents in 2011 following its bankruptcy.


The deal puts an end to litigation started last year by Rockstar against several handset manufacturers whose phones operate on Google Inc's Android operating system, which fiercely competes with Apple mobile products.


While the sale price is far less than what Rockstar had paid for the original 6,000 patents, the most valuable 2,000 of them had already been distributed to consortium members, RPX Chief Executive John Amster said.


The deal was partly motivated by the Rockstar owners rethinking their strategy for the patents, Amster said, noting that he expects Rockstar will cease to exist in its current form after the sale.


RPX was formed primarily to buy patents before the sellers can be sued for infringement. The sellers pay RPX a fee that it says is cheaper than the cost of fighting the patents in court.


As part of the deal, RPX also said it will license the patents to more than 30 companies, including Google and Cisco Systems Inc, both of which last November settled patent lawsuits filed against them by Rockstar.


Besides Apple, Rockstar also includes Microsoft Corp, Sony Corp, Blackberry and Ericsson.


"I think they were not thrilled at the litigation and thought there was a more efficient way to get fair value for the portfolio," Amster said. "It could have taken many years more of litigation to get the same value.


Ericsson said the deal was good news for the industry. Microsoft said it "demonstrates our patent system working to promote innovation." Apple, Sony, Google and Blackberry all declined to comment.


The deal is the latest to help calm the protracted smartphone legal battles. Earlier this year, Apple and Google agreed to drop all lawsuits between them, and Apple and Samsung Electronics Co Ltd did the same for litigation outside of the United States.


Top congressional Democrat asks Sony for hack details

A logo is pictured outside Sony Pictures Studios in Culver City, California December 19, 2014. REUTERS/Mario Anzuoni



A logo is pictured outside Sony Pictures Studios in Culver City, California December 19, 2014.


Credit: /Mario Anzuoni






- The top Democrat on the powerful U.S. House Oversight and Government Reform Committee has asked Sony Pictures Entertainment to hand over details of what he describes as the "devastating cyberattack" recently suffered by the Hollywood studio.

In a letter sent to Sony on Tuesday, Elijah Cummings, the committee's ranking minority member, said that Sony's "knowledge, information and experience" would help Congress as it examines federal cybersecurity laws and considers whether they need to be tightened to protect government and consumer data.


Cummings asked Sony to turn over information including detailed descriptions of all data breaches the company has suffered over the past year; the rough number of current and former employees and customers affected by the breaches; and the manner in which victims were notified.


He also asked for the findings of any forensic investigations or analyses conducted into the breaches, as well as assessments as to "why the breaches went undetected for the length of time they did."


In the letter, Cummings also asks Sony for a description of any improvements to data protection mechanisms it has implemented since the breach, a description of the procedures that govern the company's relationships with third-party vendors and service providers, and any recommendations Sony might wish to offer regarding improvements in cybersecurity laws or law enforcement.


Cummings also requests a briefing by Jan. 19 from Sony's chief information security officer or similar top IT executive.


Cummings cited reports indicating that in addition to deploying destructive malware, the hackers who attacked Sony stole "vast quantities" of sensitive information, including unreleased films and the personal information of more than 47,000 current and former employees, including social security numbers and healthcare records.


The FBI has said the cyberattackers on Sony were connected to the government of North Korea.


Alibaba spent $161 million fighting fakes since 2013

The logo of the Alibaba Group is seen inside the company's headquarters in Hangzhou, Zhejiang province November 11, 2014. REUTERS/Aly Song



The logo of the Alibaba Group is seen inside the company's headquarters in Hangzhou, Zhejiang province November 11, 2014.


Credit: /Aly Song






- China's Alibaba Group Holding Ltd, the world's largest e-commerce company, spent over 1 billion yuan ($160.7 million) combating fake goods and for improving customer protection from the beginning of 2013 to the end of November, the firm said Tuesday.

"From Alibaba Group's perspective, we bear a serious responsibility in this fight against counterfeits," said Alibaba Chief Executive Jonathan Lu in a statement.


Alibaba has been tackling counterfeit products with greater aggression in recent years, particularly in the run up to its record-setting $25 billion listing in New York in September.


A prevalence of counterfeits could hurt its ability to win over customers, investors and U.S. retail partners, the company said in its IPO prospectus.


Just a few years ago Alibaba's businesses were listed on the U.S. Trade Representative's list of "notorious markets" for intellectual property (IP) infringement.


But online fakes are still a big problem in China. In November, Chinese e-commerce companies held the annual Singles' Day online shopping festival, created by Alibaba and featuring many discounted products. That day, Alibaba reported more than $9 billion in sales.


The official State Administration of Industry and Commerce (SAIC) conducted an investigation on counterfeits on Singles' Day. It found 10.6 percent of the goods that it bought online from various vendors and platforms were fake or highly suspicious.


South Korea steps up cyber security at nuclear plants

South Korean President Park Geun-hye delivers her speech on 2015's budget bill during a plenary session at the National Assembly in Seoul October 29, 2014. REUTERS/Kim Hong-Ji



South Korean President Park Geun-hye delivers her speech on 2015's budget bill during a plenary session at the National Assembly in Seoul October 29, 2014.


Credit: /Kim Hong-Ji






- South Korea boosted cyber security at the country's nuclear power plants on Tuesday following what President Park Geun-hye described as a series "grave" data leaks, and prosecutors said they were investigating a new online threat.

Korea Hydro and Nuclear Power Co Ltd (KHNP), which runs South Korea's 23 nuclear power reactors, said on Monday its computer systems had been hacked, raising alarm in a country that is still technically at war with North Korea.


Park ordered inspections of safeguards at national infrastructure facilities, including nuclear power plants, against what she called "cyber terrorism".


A government official said authorities had raised the cyber crisis alert by one level for all the state-run companies to "caution" from "attention".


The nuclear operator, part of state-run utility Korea Electric Power Corp, said only non-critical data had been stolen and operations of the nuclear plants were not at risk. South Korea's law enforcement authorities are investigating the leaks.


"Nuclear power plants are first-class security installations that directly impact the safety of the people," Park said at a cabinet meeting, according to her office.


"A grave situation that is unacceptable has developed when there should have been not a trace of lapse as a matter of national security," she said.


Within hours of Park's comments, an online user who claimed to have hacked the nuclear operator posted a new threat and a fresh batch of data on the same Twitter account that was used for previous threats and leaks.


"We are now looking at it ... We believe it was done by the same user," an official at South Korean prosecutors' office investigating the leaks told by telephone.


An official at the nuclear operator said it was working to verify whether the data had been taken from its computers.


Earlier, the investigation team official said Seoul had not ruled out the possibility that North Korea was involved in the cyberattack, although Park did not make any mention of it.


The official added that South Korea had requested Washington's help investigating the matter.


In recent years South Korea has accused the North of a carrying out several cyberattacks on its banks and broadcasters.


The incident at the nuclear operator came after the United States accused North Korea of a serious cyberattack on Sony Pictures and vowed to respond proportionately.


Anti-nuclear activists in South Korea have also protested against the use of nuclear power.


Monday, December 22, 2014

Apple pushes first ever automated security update to Mac users

The Apple logo is illuminated in red at the Apple Store on 5th Avenue to mark World AIDS Day, in the Manhattan borough of New York December 1, 2014. REUTERS/Carlo Allegri



The Apple logo is illuminated in red at the Apple Store on 5th Avenue to mark World AIDS Day, in the Manhattan borough of New York December 1, 2014.


Credit: /Carlo Allegri






- Apple Inc has pushed out its first-ever automated security update to Macintosh computers to help defend against newly identified bugs that security researchers have warned could enable hackers to gain remote control of machines.

The company pushed out the software on Monday to fix critical security vulnerabilities in a component of its OS X operating system called the network time protocol, or NTP, according to Apple spokesman Bill Evans.NTP is used for synchronizing clocks on computer systems.


The bugs were made public in security bulletins on Friday by the Department of Homeland Security and the Carnegie Mellon University Software Engineering Institute. Carnegie Mellon identified dozens of technology companies, including Apple, whose products might be vulnerable.


When Apple has released previous security patches, it has done so through its regular software update system, which typically requires user intervention.


The company decided to deliver the NTP bug fixes with its technology for automatically pushing out security updates, which Apple introduced two years ago but had never previously used, because it wanted to protect customers as quickly as possible due to the severity of the vulnerabilities, Evans said.


"The update is seamless," he said. "It doesn’t even require a restart."


Apple does not know of any cases where vulnerable Mac computers were targeted by hackers looking to exploit the bugs, he added.


North Korea's Internet links restored amid U.S. hacking dispute

A hand is silhouetted in front of a computer screen in this picture illustration taken in Berlin May 21, 2013. REUTERS/Pawel Kopczynski



A hand is silhouetted in front of a computer screen in this picture illustration taken in Berlin May 21, 2013.


Credit: /Pawel Kopczynski






- North Korea, at the center of a confrontation with the United States over the hacking of Sony Pictures, experienced a complete Internet outage for hours before links were restored on Tuesday, a U.S. company that monitors Internet infrastructure said.

New Hampshire-based Dyn said the reason for the outage was not known but could range from technological glitches to a hacking attack. Several U.S. officials close to the investigations of the attack on Sony Pictures said the U.S. government was not involved in any cyber action against Pyongyang.


U.S. President Barack Obama had vowed on Friday to respond to the major cyber attack, which he blamed on North Korea, "in a place and time and manner that we choose."


Dyn said North Korea's Internet links were unstable on Monday and the country later went completely offline.


"We’re yet to see how stable the new connection is," Jim Cowie, chief scientist for the company, said in a telephone call after the services were restored.


"The question for the next few hours is whether it will return to the unstable fluctuations we saw before the outage."


Meanwhile South Korea, which remains technically at war with the North, said it could not rule out the involvement of its isolated neighbor in a cyberattack on its nuclear power plant operator. It said only non-critical data was stolen and operations were not at risk, but had asked for U.S. help in investigating.


South Korean President Park Geun-hye said on Tuesday the leak of data from the nuclear operator was a "grave situation" that was unacceptable as a matter of national security, but she did not mention any involvement of North Korea.


North Korea is one of the most isolated nations in the world, and the effects of the Internet outage there were not fully clear.


Very few of its 24 million people have access to the Internet. However, major websites, including those of the KCNA state news agency, the main Rodong Sinmun newspaper and the main external public relations company went down for hours.


Almost all its Internet links and traffic pass through China, except, possibly, for some satellite links.


"North Korea has significantly less Internet to lose, compared to other countries with similar populations: Yemen (47 networks), Afghanistan (370 networks), or Taiwan (5,030 networks)," Dyn Research said in a report.


"And unlike these countries, North Korea maintains dependence on a single international provider, China Unicom."


NO PROOF, CHINA SAYS


The United States requested China's help last Thursday, asking it to shut down servers and routers used by North Korea that run through Chinese networks, senior administration officials told .


The United States also asked China to identify any North Korean hackers operating in China and, if found, send them back to North Korea. It wants China to send a strong message to Pyongyang that such acts will not be tolerated, the officials said.


By Monday, China had not responded directly to the U.S. requests, the officials added.


In Beijing, the Chinese Foreign Ministry said on Monday it opposed all forms of cyberattacks and that there was no proof that North Korea was responsible for the Sony hacking.


North Korea has denied it was behind the cyberattack on Sony and has vowed to hit back against any U.S. retaliation, threatening the White House and the Pentagon..


The hackers said they were incensed by a Sony comedy about a fictional assassination of North Korean leader Kim Jong Un, which the movie studio has now pulled from general release.


Doug Madory, director of Internet analysis at Dyn Research, said of the outage in North Korea:


"There's either a benign explanation - their routers are perhaps having a software glitch; that’s possible. It also seems possible that somebody can be directing some sort of an attack against them and they're having trouble staying online."


Other experts said it was possible North Korea was attacked by hackers using a botnet, a cluster of infected computers controlled remotely.


"It would be possible that a patriotic actor could achieve the same results with a botnet, however the President promised a proportional response," said Tom Kellermann, Chief Cybersecurity Officer at Trend Micro.


"The real issue here is that nonstate actors and rogue regimes will adopt this modus operandi in 2015. The use of destructive cyberattacks will become mainstream."


China is North Korea's only major ally and would be central to any U.S. efforts to crack down on the isolated state. But the United States has also accused China of cyber spying in the past and a U.S. official has said the attack on Sony could have used Chinese servers to mask its origin.


JPMorgan data breach entry point identified: NYT

A sign outside the headquarters of JP Morgan Chase & Co in New York, September 19, 2013. REUTERS/Mike Segar



A sign outside the headquarters of JP Morgan Chase & Co in New York, September 19, 2013.


Credit: /Mike Segar






- A computer breach at JPMorgan Chase & Co (JPM.N) earlier this year could have been avoided if the bank had installed a simple security fix to an overlooked server in its network, the New York Times reported, citing people briefed on investigations.

In October, JPMorgan Chase revealed that names, addresses, phone numbers and email addresses of the holders of some 83 million accounts were exposed when the bank's computer systems were compromised by hackers, making it one of the biggest data breaches in history.


The weak spot at the bank appears to have been a very basic one – the bank did not use a double authentication scheme, known as two-factor authentication, the paper reported. (nyti.ms/1zdvK32)


JPMorgan's security team had apparently neglected upgrading one of its network servers with the dual password scheme, the newspaper said, citing people who did not want to be identified because the investigation into the attack was incomplete.


Officials at JP Morgan were not immediately available for comment outside regular U.S. business hours.


Earlier this month, U.S. regulators said they were stepping up efforts to examine financial institutions' defenses to ward off cyber attacks, as a top FBI official warned of new "increasingly complex" threats to the financial sector.


North Korea's internet links restored: U.S. monitoring company

A hand is silhouetted in front of a computer screen in this picture illustration taken in Berlin May 21, 2013. REUTERS/Pawel Kopczynski



A hand is silhouetted in front of a computer screen in this picture illustration taken in Berlin May 21, 2013.


Credit: /Pawel Kopczynski






- North Korea's internet links have been restored, but it is not clear how stable they are, the U.S.-based internet monitoring company Dyn said on Tuesday.

"The question for the next few hours is whether it will return to the unstable fluctuations we saw before the outage," Jim Cowie, chief scientist for the company, said in a telephone call.