<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.circleid.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<title type="text">CircleID</title>
	<subtitle type="text">Latest posts on CircleID</subtitle>
	<link rel="alternate" type="text/html" href="http://www.circleid.com/" />
	
	<updated>2010-09-08T14:06:00-08:00</updated>
	<id>tag:circleid.com,2002:master-feed</id>
	<logo>http://www.circleid.com/images/logo_rss.gif</logo>
	<icon>http://www.circleid.com/images/logo_rss_icon.gif</icon>

	
	<feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="cid_master" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://www.circleid.com/rss/all/" /><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Fwww.circleid.com%2Frss%2Fall%2F" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Fwww.circleid.com%2Frss%2Fall%2F" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Fwww.circleid.com%2Frss%2Fall%2F" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.bloglines.com/sub/http://www.circleid.com/rss/all/" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fwww.circleid.com%2Frss%2Fall%2F" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://fusion.google.com/add?feedurl=http%3A%2F%2Fwww.circleid.com%2Frss%2Fall%2F" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Fwww.circleid.com%2Frss%2Fall%2F" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><entry>
		<title>What Does the .CO Launch Mean for New gTLDs?</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/20100908_what_does_the_co_launch_mean_for_new_gtlds/" />
		<id>tag:circleid.com,2010:blogs/1.4952</id>
		<updated>2010-09-08T14:06:00-08:00</updated>
		<author><name>Antony Van Couvering</name></author>
		<category term="domain_names" scheme="http://www.circleid.com/topics/domain_names/" label="Domain Names" /><category term="domain_registries" scheme="http://www.circleid.com/topics/domain_registries/" label="Domain Registries" /><category term="icann" scheme="http://www.circleid.com/topics/icann/" label="ICANN" /><category term="top_level_domains" scheme="http://www.circleid.com/topics/top_level_domains/" label="Top-Level Domains" />
		<content type="html">&lt;p&gt;The .CO top-level domain made over $10 million in just a couple of months. What do the results of the .CO re-launch mean for new gTLDs?
&lt;/p&gt;
&lt;p&gt;
Remember, .CO is the country-code TLD for Colombia. Until this summer, you could only register names under .com.co, .net.co, etc. You couldn't register myname.co. Now anyone in the world can register a .co name, and register it directly under the top level. Remember also that as a country-code TLD, .CO was not constrained by ICANN rules, which means that they were able to (re-) launch their TLD relatively quickly. Even so, their rules and regulations closely hewed to the latest ICANN rules, especially in regard to cybersquatting.
&lt;/p&gt;
&lt;p&gt;
The response to the .CO launch was tremendous. Let's review:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;11,000 names applied for during the Sunrise Period&lt;/li&gt;
&lt;li&gt;28,000 names sold during the Landrush Period (closed July 15, 2010)&lt;/li&gt;
&lt;li&gt;Total paid by applicants for Sunrise and Landrush names: over $10 million&lt;/li&gt;
&lt;li&gt;Total .co names registered as of this writing: 440,000&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;
What do these numbers mean for prospective new gTLDs? Obviously, they prove that there are lots of buyers out there if the value proposition is good, and that's a very good sign. There is no indication (quite the opposite, in fact) that people have anything against new TLDs. Quite the opposite, in fact: if it's a good one, they'll flock to it in droves.
&lt;/p&gt;
&lt;p&gt;
But .CO is somewhat of a special case. There are a few things to keep in mind:
&lt;/p&gt;
&lt;p&gt;
First, although cybersquatting of brand names was dealt with aggressively by the talented .CO team, we have to assume that many of the registrations were done in hopes of getting traffic from people who forgot to add the "m" to a .com URL. No new gTLDs will be able to benefit from similar fat-fingered mistakes, because ICANN is running a "similarity test" to make sure that there aren't such confusions. We won't know how much typo traffic there actually is until it comes time to renew the names. Then, speculative traffic names will either be renewed (if they received typo traffic) or will be dropped (if they didn't). So keep an eye on next July for interesting stats.
&lt;/p&gt;
&lt;p&gt;
Second, the .CO team is really good, and did everything right. They hired smart veterans and spent a fair amount of time and money making sure that brand owners and registrars knew what was happening, what the rules were, how and when to apply, etc. This had the virtuous double effect of almost completely eliminating complaints about the process and also maximizing registrations. New TLD applicants, take note.
&lt;/p&gt;
&lt;p&gt;
Third, .CO had the field to itself. When new gTLDs start launching, it will probably be on a rolling schedule, but nonetheless there is likely to be more than one launch at any given time.
&lt;/p&gt;
&lt;p&gt;
These are the factors giving .CO an edge, but this doesn't mean that new gTLDs won't be able to duplicate or surpass their success. Many of these considerations are double-edged swords. The fact that .CO is a misspelling of .COM also means that fewer real sites will get built, fewer names will be renewed, and cybersquatting problems will be relatively larger than in most new gTLDs. The fact that .CO spent a lot of money means that their profit margin is lower.
&lt;/p&gt;
&lt;p&gt;
Every new TLD launch will have specific considerations and circumstances that will both help and hinder its growth. Several new gTLDs, especially geographical names and communities, will have natural constituencies that will fuel registrations. Others will have worldwide appeal. Many will not measure their success in registrations, but instead on service to their communities.
&lt;/p&gt;
&lt;p&gt;
Overall, the .CO launch should make prospective new gTLD applicants very happy indeed. It is a great proof of the market, and it shows (once again) that intelligent branding and marketing will go a long way to making a project a success.
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/1478/"&gt;Antony Van Couvering&lt;/a&gt;, CEO of Minds + Machines&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/domain_names"&gt;Domain Names&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/domain_registries"&gt;Domain Registries&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/icann"&gt;ICANN&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/top_level_domains"&gt;Top-Level Domains&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=d4KTRUTx9Bg:QCyDQqJ2vOc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=d4KTRUTx9Bg:QCyDQqJ2vOc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=d4KTRUTx9Bg:QCyDQqJ2vOc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=d4KTRUTx9Bg:QCyDQqJ2vOc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=d4KTRUTx9Bg:QCyDQqJ2vOc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=d4KTRUTx9Bg:QCyDQqJ2vOc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=d4KTRUTx9Bg:QCyDQqJ2vOc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=d4KTRUTx9Bg:QCyDQqJ2vOc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=d4KTRUTx9Bg:QCyDQqJ2vOc:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>A Look at How Google, Verizon and the FCC Talks are Playing Out</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/a_look_at_how_google_verizon_and_the_fcc_talks_are_playing_out/" />
		<id>tag:circleid.com,2010:news/6.4951</id>
		<updated>2010-09-08T08:46:00-08:00</updated>
		<author><name>CircleID Reporter</name></author>
		<category term="access_providers" scheme="http://www.circleid.com/topics/access_providers/" label="Access Providers" /><category term="broadband" scheme="http://www.circleid.com/topics/broadband/" label="Broadband" /><category term="net_neutrality" scheme="http://www.circleid.com/topics/net_neutrality/" label="Net Neutrality" /><category term="policy_regulation" scheme="http://www.circleid.com/topics/policy_regulation/" label="Policy &amp; Regulation" /><category term="telecom" scheme="http://www.circleid.com/topics/telecom/" label="Telecom" /><category term="white_space" scheme="http://www.circleid.com/topics/white_space/" label="White Space" /><category term="wireless" scheme="http://www.circleid.com/topics/wireless/" label="Wireless" />
		<content type="html">&lt;p&gt;Sam Gustin &lt;a href="http://www.dailyfinance.com/story/company-news/google-verizon-fcc-war-over-internets-future/19605776/"&gt;reporting in DailyFanance&lt;/a&gt;: "As Apple (AAPL), Amazon (AMZN), Netflix (NFLX) and Google forge ahead with highly publicized new plans to stream high-speed content like movies and TV shows to your living room, smartphone, telecom and cable giants like AT&amp;amp;T, Verizon and Comcast (CMSCA) have been intensely lobbying to maintain control over the broadband pipes they spent billions to build. Comcast is going so far as to buy a rich content factory, NBC Universal, a deal that would create a $35 billion media and delivery juggernaut."
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/access_providers"&gt;Access Providers&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/broadband"&gt;Broadband&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/net_neutrality"&gt;Net Neutrality&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/policy_regulation"&gt;Policy &amp; Regulation&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/telecom"&gt;Telecom&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/white_space"&gt;White Space&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/wireless"&gt;Wireless&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=k-AvRKFh6Tk:8s0Aw0_3rYE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=k-AvRKFh6Tk:8s0Aw0_3rYE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=k-AvRKFh6Tk:8s0Aw0_3rYE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=k-AvRKFh6Tk:8s0Aw0_3rYE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=k-AvRKFh6Tk:8s0Aw0_3rYE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=k-AvRKFh6Tk:8s0Aw0_3rYE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=k-AvRKFh6Tk:8s0Aw0_3rYE:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=k-AvRKFh6Tk:8s0Aw0_3rYE:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=k-AvRKFh6Tk:8s0Aw0_3rYE:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>NIST Issues Smart Grid Cybersecurity Guidelines</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/nist_issues_smart_grid_cybersecurity_guidelines/" />
		<id>tag:circleid.com,2010:news/6.4949</id>
		<updated>2010-09-07T14:49:00-08:00</updated>
		<author><name>CircleID Reporter</name></author>
		<category term="cyberattack" scheme="http://www.circleid.com/topics/cyberattack/" label="Cyberattack" /><category term="security" scheme="http://www.circleid.com/topics/security/" label="Security" />
		<content type="html">&lt;p&gt;The National Institute of Standards and Technology (NIST) &lt;a href="http://www.nist.gov/public_affairs/releases/nist-finalizes-initial-set-of-smart-grid-cyber-security-guidelines.cfm"&gt;issued today&lt;/a&gt; its first Guidelines for Smart Grid Cyber Security, which includes high-level security requirements, a framework for assessing risks, an evaluation of privacy issues at personal residences, and additional information for businesses and organizations to use as they craft strategies to protect the modernizing power grid from attacks, malicious code, cascading errors, and other threats.
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/cyberattack"&gt;Cyberattack&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/security"&gt;Security&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=9jvW1wnec5s:n9ztj_IXXDI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=9jvW1wnec5s:n9ztj_IXXDI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=9jvW1wnec5s:n9ztj_IXXDI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=9jvW1wnec5s:n9ztj_IXXDI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=9jvW1wnec5s:n9ztj_IXXDI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=9jvW1wnec5s:n9ztj_IXXDI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=9jvW1wnec5s:n9ztj_IXXDI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=9jvW1wnec5s:n9ztj_IXXDI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=9jvW1wnec5s:n9ztj_IXXDI:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>DNS Clients Do Request DNSSEC Today</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/20100906_dns_clients_do_request_dnssec_today/" />
		<id>tag:circleid.com,2010:blogs/1.4948</id>
		<updated>2010-09-06T12:04:00-08:00</updated>
		<author><name>Daniel Karrenberg</name></author>
		<category term="dns" scheme="http://www.circleid.com/topics/dns/" label="DNS" /><category term="dnssec" scheme="http://www.circleid.com/topics/dnssec/" label="DNSSEC" /><category term="regional_registries" scheme="http://www.circleid.com/topics/regional_registries/" label="Regional Registries" /><category term="security" scheme="http://www.circleid.com/topics/security/" label="Security" /><category term="top_level_domains" scheme="http://www.circleid.com/topics/top_level_domains/" label="Top-Level Domains" />
		<content type="html">&lt;p&gt;After the DNS root zone was finally signed and a number of Top-Level Domains (TLDs) began signing their zones, we were curious to see how many clients actually request DNSSEC information. We looked at the RIPE NCC server that provides secondary service to several country code top-level domains (ccTLDs).
&lt;/p&gt;
&lt;p&gt;
This server answers around 5,000 queries per second on average. In the image below you can see the percentage of those queries that requested DNSSEC information during August 2010:
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.circleid.com/images/uploads/4948.gif" border="0" width="642" height="476" style="display:block;" /&gt;
&lt;/p&gt;
&lt;p&gt;
More than 50% of all queries request DNSSEC information from this server. This is very encouraging and shows that DNSSEC is being deployed.
&lt;/p&gt;
&lt;p&gt;
Here are some guidelines for configuring your caching resolvers to use the root zone DNSSEC key:
&lt;/p&gt;
&lt;p&gt;
BIND: &lt;a href="https://dnssec.surfnet.nl/?p=402"&gt;https://dnssec.surfnet.nl/?p=402&lt;/a&gt;
&lt;br /&gt;
Unbound: &lt;a href="https://dnssec.surfnet.nl/?p=212"&gt;https://dnssec.surfnet.nl/?p=212&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
For more details on this topic, please refer to RIPE Labs:
&lt;br /&gt;
&lt;a href="https://labs.ripe.net/Members/dfk/dns-clients-do-request-dnssec-today"&gt;https://labs.ripe.net/Members/dfk/dns-clients-do-request-dnssec-today&lt;/a&gt;
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/3167/"&gt;Daniel Karrenberg&lt;/a&gt;, Chief Scientist at the RIPE NCC&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/dns"&gt;DNS&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/dnssec"&gt;DNSSEC&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/regional_registries"&gt;Regional Registries&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/security"&gt;Security&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/top_level_domains"&gt;Top-Level Domains&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=RdmebOHBCKM:TmFzjkdakQs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=RdmebOHBCKM:TmFzjkdakQs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=RdmebOHBCKM:TmFzjkdakQs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=RdmebOHBCKM:TmFzjkdakQs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=RdmebOHBCKM:TmFzjkdakQs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=RdmebOHBCKM:TmFzjkdakQs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=RdmebOHBCKM:TmFzjkdakQs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=RdmebOHBCKM:TmFzjkdakQs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=RdmebOHBCKM:TmFzjkdakQs:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>IPv6: Smart Investments and Smart Grids</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/20100904_ipv6_smart_investments_and_smart_grids/" />
		<id>tag:circleid.com,2010:blogs/1.4947</id>
		<updated>2010-09-04T11:53:00-08:00</updated>
		<author><name>Yves Poppe</name></author>
		<category term="ipv6" scheme="http://www.circleid.com/topics/ipv6/" label="IPv6" /><category term="mobile" scheme="http://www.circleid.com/topics/mobile/" label="Mobile" />
		<content type="html">&lt;p&gt;IPv6 a major catalyst for billions of dollars worth of deals? The Intel &lt;a href="http://www.esecurityplanet.com/features/article.php/3899476/Intel-Buys-McAfee-for-77-Billion.htm"&gt;announcement&lt;/a&gt; of their McAfee purchase for 7.7 billion seems to indicate as much when Dave DeWalt , McAfee CEO is quoted as saying during a conference call; "If we look at the transition from IPv4 to IPv6, we're seeing an explosion of billions of devices and they all need to be secured." Then he continues by saying "The embedded market is a very specific and high-opportunity market for us." His &lt;a href="http://news.cnet.com/8301-1001_3-20014082-92.html"&gt;estimate&lt;/a&gt; is that the number of connected devices will grow from one billion to 50 billion within 10 years.
&lt;/p&gt;
&lt;p&gt;
In the meantime Baltimore Gas and Electricity (BGE) &lt;a href="http://www.marketwatch.com/story/baltimore-gas-and-electric-company-selects-silver-spring-networks-for-smart-grid-initiative-2010-09-01?reflink=MW_news_stmp"&gt;signed a contract&lt;/a&gt; for the provision of IPv6 based smart readers to equip their 1.2 million customers using a 'secure, end-to-end IPv6 platform for BGE to deliver on operational benefits today while also ensuring tomorrow's energy challenges can be met with a scalable and open platform'.
&lt;/p&gt;
&lt;p&gt;
The same day , September 1st, we see Cisco and Itron &lt;a href="http://newsroom.cisco.com/dlls/2010/prod_090110.html"&gt;sign a strategic agreement&lt;/a&gt; to 'develop a standards-based, highly secure technology for full IPv6 implementation of field area communications to support smart metering, intelligent distribution automation and interfaces to the customer premise '.
&lt;/p&gt;
&lt;p&gt;
One day later, september 2nd, Cisco &lt;a href="http://newsroom.cisco.com/dlls/2010/corp_090210.html"&gt;announces&lt;/a&gt; the purchase of &lt;a href="http://www.archrock.com/"&gt;Archrock&lt;/a&gt;, a pioneer of IPv6 implementation for sensor network and smart grids , cofounder of &lt;a href="http://ipso-alliance.org/"&gt;IPSO&lt;/a&gt; , the alliance promoting IP for small objects, and strong proponent of the &lt;a href="http://ipso-alliance.org/wp-content/themes/ipso/downloads/6LoWPAN.pdf"&gt;IETF 6lowpan&lt;/a&gt; recommendation which defines the use of IPv6 for low powered objects.
&lt;/p&gt;
&lt;p&gt;
There is definitely an IPv6 smell in the air these late summer days.&amp;nbsp;
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/2967/"&gt;Yves Poppe&lt;/a&gt;, Director, Business Development IP Strategy&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/ipv6"&gt;IPv6&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/mobile"&gt;Mobile&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=CiKxxZ5gyL4:k3F4tBrM_RY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=CiKxxZ5gyL4:k3F4tBrM_RY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=CiKxxZ5gyL4:k3F4tBrM_RY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=CiKxxZ5gyL4:k3F4tBrM_RY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=CiKxxZ5gyL4:k3F4tBrM_RY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=CiKxxZ5gyL4:k3F4tBrM_RY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=CiKxxZ5gyL4:k3F4tBrM_RY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=CiKxxZ5gyL4:k3F4tBrM_RY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=CiKxxZ5gyL4:k3F4tBrM_RY:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>IPv6 Posing New Security Issues</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/ipv6_posing_new_security_issues/" />
		<id>tag:circleid.com,2010:news/6.4946</id>
		<updated>2010-09-03T13:17:00-08:00</updated>
		<author><name>CircleID Reporter</name></author>
		<category term="dnssec" scheme="http://www.circleid.com/topics/dnssec/" label="DNSSEC" /><category term="ip_addressing" scheme="http://www.circleid.com/topics/ip_addressing/" label="IP Addressing" /><category term="ipv6" scheme="http://www.circleid.com/topics/ipv6/" label="IPv6" /><category term="security" scheme="http://www.circleid.com/topics/security/" label="Security" />
		<content type="html">&lt;p&gt;"The countdown to the saturation of the IPv4 address supply is now down to a matter of months: and along with the vast address space of the next-generation IPv6 architecture comes more built-in network security as well as some new potential security threats. ...its adoption also poses new security issues, everything from distributed denial-of-service (DDoS) attacks to new vulnerabilities in IPv6 to misconfigurations that expose security holes."
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Read full story:&lt;/strong&gt; &lt;a href="http://www.darkreading.com/vulnerability_management/security/perimeter/showArticle.jhtml?articleID=227300083"&gt;Dark Reading&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/dnssec"&gt;DNSSEC&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/ip_addressing"&gt;IP Addressing&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/ipv6"&gt;IPv6&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/security"&gt;Security&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=ZU_n3V9y4i0:H67J7TjXuK0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=ZU_n3V9y4i0:H67J7TjXuK0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=ZU_n3V9y4i0:H67J7TjXuK0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=ZU_n3V9y4i0:H67J7TjXuK0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=ZU_n3V9y4i0:H67J7TjXuK0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=ZU_n3V9y4i0:H67J7TjXuK0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=ZU_n3V9y4i0:H67J7TjXuK0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=ZU_n3V9y4i0:H67J7TjXuK0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=ZU_n3V9y4i0:H67J7TjXuK0:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>ARF is Now an IETF Standard</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/20100901_arf_is_now_an_ietf_standard/" />
		<id>tag:circleid.com,2010:blogs/1.4944</id>
		<updated>2010-09-01T08:57:00-08:00</updated>
		<author><name>John Levine</name></author>
		<category term="email" scheme="http://www.circleid.com/topics/email/" label="Email" /><category term="spam" scheme="http://www.circleid.com/topics/spam/" label="Spam" />
		<content type="html">&lt;p&gt;When a user of a large mail system such as AOL, Yahoo, or Hotmail reports a message as junk or spam, one of the things the system does is to look at the source of the message and see if the source is one that has a feedback loop (FBL) agreement with the mail system. If so, it sends a copy of the message back to the source, so they can take appropriate action, for some version of appropriate. For several years, ARF, Abuse Reporting Format, has been the de-facto standard form that large mail systems use to exchange FBL reports about user mail complaints.
&lt;/p&gt;
&lt;p&gt;
Until now, the only documentation for ARF was a draft spec originally written Yakov Shafranovich (&lt;a href="http://www.circleid.com/members/1108/"&gt;CircleID&lt;/a&gt;) in 2005, and occasionally updated originally by him and later by other people including myself. Earlier this year, the IETF chartered a working group called MARF which took that draft, brought the references up to date, stripped out a lot of options that seemed useful five years ago but in practice nobody ever used, and this week it was finally published as &lt;a href="http://www.rfc-editor.org/rfc/rfc5965.txt"&gt;RFC 5965&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
ARF (or now MARF) is quite simple, a version of the existing Multipart/Report message format that includes information about the report, such as the address of the recipient, descriptive text for a human reader, and a copy of the offending message. Having a standard format for reports, simple though it is, makes them much easier to process. For my tiny system, for example, nearly all of the trickle of reports are about mailing list messages. When a FBL report arrives, an automated script looks at the report and the message, and in the usual case that it's from a mailing list, it creates an unsubscribe request to remove the person from the list. Otherwise, it passes the message along to the human manager so I can decide what, if anything, to do about it. Larger mail systems also use them to collect statistics about their mail-sending customers.
&lt;/p&gt;
&lt;p&gt;
The IETF process works particularly well when it standardizes existing practice, and ARF/MARF is an excellent example of that. The differences between the earlier drafts and the final version make it clearer and more precise, and it's now a proper standard we can cite:
&lt;/p&gt;
&lt;p&gt;
&lt;em&gt;Abuse Reporting Format! Ask for it by name: RFC 5965!&lt;/em&gt;
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/1015/"&gt;John Levine&lt;/a&gt;, Author, Consultant &amp; Speaker&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/email"&gt;Email&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/spam"&gt;Spam&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=DGtBjWyY8PI:6ub-WMCM4ig:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=DGtBjWyY8PI:6ub-WMCM4ig:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=DGtBjWyY8PI:6ub-WMCM4ig:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=DGtBjWyY8PI:6ub-WMCM4ig:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=DGtBjWyY8PI:6ub-WMCM4ig:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=DGtBjWyY8PI:6ub-WMCM4ig:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=DGtBjWyY8PI:6ub-WMCM4ig:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=DGtBjWyY8PI:6ub-WMCM4ig:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=DGtBjWyY8PI:6ub-WMCM4ig:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>Google Voice: Race to the Bottom for Telephony - or Something Else?</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/20100830_google_voice_race_to_the_bottom_for_telephony_or_something_else/" />
		<id>tag:circleid.com,2010:blogs/1.4943</id>
		<updated>2010-08-31T11:26:00-08:00</updated>
		<author><name>Jon Arnold</name></author>
		<category term="email" scheme="http://www.circleid.com/topics/email/" label="Email" /><category term="telecom" scheme="http://www.circleid.com/topics/telecom/" label="Telecom" /><category term="voip" scheme="http://www.circleid.com/topics/voip/" label="VoIP" /><category term="web" scheme="http://www.circleid.com/topics/web/" label="Web" />
		<content type="html">&lt;p&gt;Just when you thought making phone calls couldn't get any cheaper, along comes last week's news from Google about their latest iteration of &lt;strong&gt;Google Voice&lt;/strong&gt;. There have been several steps along the way for Google to get to this point, and there are a host of reasons why this news is of interest to service providers of all stripes. I often write about how certain technologies and disruptive forces change the business of being a service provider, and this is but the latest example.
&lt;/p&gt;
&lt;p&gt;
Ever since Vonage came to market, residential carriers have been faced with declining revenues for landline service, which itself is quickly losing ground to wireless substitution. Then Skype came along and brought desktop VoIP to a whole new level of adoption. Along with that came a new value proposition for voice. Whereas Vonage was offering a lower cost monthly plan, Skype was offering free or near free voice, driving the price down to levels that no conventional service provider could sustain.
&lt;/p&gt;
&lt;p&gt;
Google has its own take on voice, which is why this story should be of interest to service providers. Vonage is marketed primarily as a replacement service for POTS, making it a direct competitor to telcos. Nothing complicated there&amp;#8212;it's really just a price game, but telcos do have more options to bundle telephony with other things&amp;#8212;and of course, even more so for cable operators.
&lt;/p&gt;
&lt;p&gt;
Skype is primarily a Web-based IM/chat service, on top of which they do voice very well, and at low cost to subscribers. As popular as Skype is, their proprietary technology keeps them a bit inside their own sphere. They are still a major threat to telcos, but when positioned a bit differently, they can be a very good complement.
&lt;/p&gt;
&lt;p&gt;
The latest news with Google, though, is something entirely different. Their calling service&amp;#8212;Google Voice&amp;#8212;is mainly an add-on to Gmail, and works a lot like Skype. As such, it's not a pure telephony service like Vonage, and it's not really built off IM/chat like Skype; it's built around email. Of course, Google has all these other tools, but email is ubiquitous, and Google has been successful building a strong user base here. Gmail binds the user more deeply than IM/chat, making it a great platform for both business and personal usage. I'm not alone in noticing these days that when you get a personal email address as a backup for someone you're working with, more often than not it's a Gmail address.
&lt;/p&gt;
&lt;p&gt;
Google already has GTalk, which supports free online calls between Google users&amp;#8212;and is comparable to the free calling Skype users have among themselves. Google Voice is much bolder and is their answer to Skype Out/In, and gives Gmail users a PSTN interface to make calls to the rest of the world. In the short term, this may take a bite out of Skype in that Google Voice calls within the U.S. and Canada will be free until year end (but maybe longer). Longer term - along with Skype - Google Voice is more of a threat to telcos as they accelerate the race to the bottom, bringing the value of a voice call pretty much down to where email is.
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Why are they doing this?&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
In my view, it's not to put the telcos out of business. They're offering domestic PSTN calls for free, in the hopes of subsidizing them by charging two cents a minute for international calls. Fair enough, but I don't see that happening, and Google really doesn't need to make money with this service. Of course, free beats paid any day&amp;#8212;so long as the quality is comparable&amp;#8212;and I see them making the voice pie bigger, much the way Skype has. The key for me is more about how Google Voice interacts with Gmail. By escalating an email message to a free phone call, users will stay longer in the Google environment, and the ability to transcribe voicemail will certainly appeal to some.
&lt;/p&gt;
&lt;p&gt;
However, I think there's more to the story. Am mentioned, Google is coming from a different place than Skype, who depends almost solely on those Skype In/Out minutes for revenues. VoIP service is not expensive to provide, and Google has spent relatively little to get in the game. I would contend that the vast majority of their Google Voice capability comes from three small acquisitions that cost them maybe $150 million. When you think about the annual Capex budget of any incumbent, this really is pocket change. Going back to 2007, they acquired GrandCentral; last year they acquired Gizmo5, and a few months ago, they added Global IP Solutions. Collectively these companies have given them the pieces to offer a very appealing VoIP-to-PSTN service globally, and if they never make a penny from it, so be it.
&lt;/p&gt;
&lt;p&gt;
As mentioned, free beats paid, and there's no better incentive to get people to use your service. Look how long Vonage has been around, and they barely have two million subscribers. Unlike Skype, Google doesn't have to build its user base from scratch, and it won't take long for them to start logging millions of calls. Just consider what happens when school resumes next month, and students will be falling over each other to make free calls home from those super-retro red UK phone booths that will be popping up on college campuses (and solar powered to boot).
&lt;/p&gt;
&lt;p&gt;
As such, Google Voice will be one more reason to cut the cord, and the race to zero just picked up some speed. Thanks to Gizmo5, Google Voice is SIP-based and works nicely on both softphones and hand-held endpoints. Short term, there will be some cannibalization with Android by competing with voice from data plans, but Google will figure out how to make all these pieces fit. This is actually where the GIPS acquisition comes in, with their ability to support both voice and video over mobile devices, which in turn can make Google Voice a great add-on for businesses.
&lt;/p&gt;
&lt;p&gt;
While Google Voice is primarily an outbound telephony service, I think they'll be able to take free calling beyond the desktop, and that's really what service providers need to be thinking about. Free on the desktop is one thing, but when you push out to mobile devices, things get more complicated. If this isn't enough, I think there's a separate agenda at work here, and it's something I've commented about elsewhere for quite some time.
&lt;/p&gt;
&lt;p&gt;
Google is really interested in the voice business, not to make life difficult to telcos, but as a source of raw material&amp;#8212;snippets from voicemail and live calls, if you will&amp;#8212;that can be harvested for search. I'm not sure about the regulatory issues around this&amp;#8212;and apparently Google has been vague here&amp;#8212;but certainly for voicemail, free calls will generate a huge cache of "content" that they can apply speech recognition algorithms to and build an archive of audio-based search prompts. Once those audio cues are transcribed into text, they can become hugely valuable for the next frontier&amp;#8212;mobile search. This sounds a bit on the dark side ("do no evil" as we're told), but it's a far better way to monetize voice than charging a few cents a minute or a few dollars a month. When viewed from this lens, Google Voice is a very different business than Skype, Vonage, or any telco for that matter. Disruption comes in many forms, and we're seeing a new one with Google Voice. Don't let the race to zero fool you; I think it's just a side-show compared to what Google really has in mind.
&lt;/p&gt;
&lt;p&gt;
&lt;em&gt;This article of mine originally ran today on my Service Provider Views column on TMCnet.&lt;/em&gt;
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/2687/"&gt;Jon Arnold&lt;/a&gt;, Principal, J Arnold &amp; Associates&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/email"&gt;Email&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/telecom"&gt;Telecom&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/voip"&gt;VoIP&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/web"&gt;Web&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=JjAT4tKgcP0:H_5q4bjcSrE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=JjAT4tKgcP0:H_5q4bjcSrE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=JjAT4tKgcP0:H_5q4bjcSrE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=JjAT4tKgcP0:H_5q4bjcSrE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=JjAT4tKgcP0:H_5q4bjcSrE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=JjAT4tKgcP0:H_5q4bjcSrE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=JjAT4tKgcP0:H_5q4bjcSrE:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=JjAT4tKgcP0:H_5q4bjcSrE:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=JjAT4tKgcP0:H_5q4bjcSrE:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>Stopping the Flow of Online Illegal Pharmaceuticals</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/stopping_the_flow_of_online_illegal_pharmaceuticals/" />
		<id>tag:circleid.com,2010:blogs/1.4942</id>
		<updated>2010-08-31T08:24:00-08:00</updated>
		<author><name>Terry Zink</name></author>
		<category term="cybercrime" scheme="http://www.circleid.com/topics/cybercrime/" label="Cybercrime" /><category term="domain_names" scheme="http://www.circleid.com/topics/domain_names/" label="Domain Names" /><category term="domain_registries" scheme="http://www.circleid.com/topics/domain_registries/" label="Domain Registries" /><category term="icann" scheme="http://www.circleid.com/topics/icann/" label="ICANN" /><category term="internet_governance" scheme="http://www.circleid.com/topics/internet_governance/" label="Internet Governance" /><category term="spam" scheme="http://www.circleid.com/topics/spam/" label="Spam" /><category term="whois" scheme="http://www.circleid.com/topics/whois/" label="Whois" />
		<content type="html">&lt;p&gt;Reading through Brian Kreb's blog last week, he has an interesting &lt;a href="http://krebsonsecurity.com/2010/08/white-house-calls-meeting-on-rogue-online-pharmacies/"&gt;post&lt;/a&gt; up on the White House's call upon the industry on how to formulate a plan to stem the flow of illegal pharmaceuticals:
&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;The Obama administration is inviting leaders of the top Internet domain name registrars and registries to attend a three-hour meeting at the White House next month about voluntary ways to crack down on Web sites that are selling counterfeit prescription medications.
&lt;/p&gt;
&lt;p&gt;
The invitation, sent via e-mail on Aug 13 by White House Senior Adviser for Intellectual Property Enforcement &lt;strong&gt;Andrew J. Klein&lt;/strong&gt;, urges select recipients to attend a meeting on Sept. 29 with senior White House and cabinet officials, including &lt;strong&gt;Victoria Espinel&lt;/strong&gt;, the Obama administration's intellectual property enforcement coordinator.
&lt;/p&gt;
&lt;p&gt;
"The purpose of this meeting is to discuss illegal activity taking place over the internet generally, and more specifically, voluntary protocols to address the illegal sale of counterfeit non-controlled prescription medications on-line," the invitation states.
&lt;/p&gt;
&lt;p&gt;
Klein did not return calls seeking more information. A spokeswoman for the White House Office of Management and Budget confirmed the event, but declined to offer further details. The meeting appears to be a continuation of the administration's Joint Strategic Plan on Intellectual Property Enforcement, an initiative unveiled in June that promised to "address unlawful activity on the internet, such as illegal downloading and illegal internet pharmacies."
&lt;/p&gt;
&lt;p&gt;
According to the &lt;strong&gt;World Health Organization&lt;/strong&gt;, approximately 8 percent of the bulk drugs imported into the United States are counterfeit, unapproved, or substandard, and 10 percent of global pharmaceutical commerce&amp;#8212;or $21 billion&amp;#8212;involves counterfeit drugs. &lt;strong&gt;LegitScript.com&lt;/strong&gt;, a verification service for online pharmacies, is currently tracking more than 45,000 rogue Internet pharmacies.&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;
It is unclear to me whether or not the goal of this initiative is to stem the flow of online crime in general or to reduce the flow of illegal pharmaceuticals flowing into the United States (since presumably this cuts into the profits of large pharmaceutical companies&amp;#8230; who would naturally want to see their profit margins increased in return for pledging their support for health care reform that was passed earlier this year). Assuming that the target of this are the online pharmaceuticals, there are a few things I can think of. Unfortunately, a three hour meeting really isn't enough to get this off the ground because it is a series of interconnected events that would need to take place. Anyhow, here's a list of things I'd do:
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Stopping illegal pharmaceuticals piggy-backs onto stopping illegal &amp;lt;anything&amp;gt; on the 'net. &lt;/strong&gt;Spammers who advertise illegal software, or fake degrees, or fake enlargement pills, or fake mortgages are all basically doing the same thing. So, any strategy that is aimed at stopping those other things will extend to stopping fake pharmas as well. My point here is that concentrating only on fake pharmaceuticals may exclude strategies that scale to others.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Registrars need to get their act in gear.&lt;/strong&gt; When a website advertising cheap Viagra goes up, somebody somewhere needs to register that site. Whoever registers is needs to do a better job of verification of the identity who registered it. The problem here is that so many of these sites are registered by registrars in foreign countries which is outside the jurisdiction of the US. However, just like in the Wizard of Oz, there's no place like home and the government can pressure domestic ones to do better proactive abuse mitigation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;WHOIS protected services are questionable.&lt;/strong&gt; I don't deny the need for WHOIS-protected services in some cases. However, any time I am looking up a suspicious site and the WHOIS registration is protected, that's pretty much all I need to make the determination that the site is abusive. It doesn't cost much to shield your WHOIS information. If you want to do it, that's fine but there should probably be a stricter set of criteria who shielding your information like this requiring you to jump through a couple of more manual hoops.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Crack downs on spammers will go a long ways.&lt;/strong&gt; One of the chief mechanisms of advertising illegal pharmaceuticals is through the use of spam. We all get it in our inboxes. Of course, there are other avenues of advertisement such as black search engine optimization. However, because it is not particularly difficult to send out a lot of spam and make money off of it, and because there is little chance of repercussion, spammers continue to do it. If law enforcement had more resources dedicated to prosecuting spammers such that it became more de-incentivized, then the supply part of the equation would start to dry up. In other words, putting spammers in prison will help in this regards, and this requires a prioritization of law enforcement resources. Whether or not they are willing to divert resources from one area of law enforcement to another is an open question.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Perhaps walled gardens are a good idea.&lt;/strong&gt; In Australia, some ISPs kick infected computers off of their network if the ISP can detect that the machine connecting to it is infected with malware. Or, they redirect them to a sandbox and alert the user that they cannot continue until they clean their system. If more ISPs made this a policy, then maybe we'd have less malware abuse flowing back and forth in cyber space. I don't think I'd want government to enforce this, but perhaps ISPs might be willing to voluntarily comply with this.&lt;/li&gt;&lt;/ol&gt;
&lt;p&gt;
This is a small list of things that could be done but by no means it is exhaustive. Running up-to-date software is a good idea, and so is running the latest patched version of one's software. What other ideas do you have to cut down on the flow of illegal online pharmaceuticals?
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/2859/"&gt;Terry Zink&lt;/a&gt;, Program Manager&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/cybercrime"&gt;Cybercrime&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/domain_names"&gt;Domain Names&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/domain_registries"&gt;Domain Registries&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/icann"&gt;ICANN&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/internet_governance"&gt;Internet Governance&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/spam"&gt;Spam&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/whois"&gt;Whois&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=aZQjlVKzaT4:tdomFVv7xQA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=aZQjlVKzaT4:tdomFVv7xQA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=aZQjlVKzaT4:tdomFVv7xQA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=aZQjlVKzaT4:tdomFVv7xQA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=aZQjlVKzaT4:tdomFVv7xQA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=aZQjlVKzaT4:tdomFVv7xQA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=aZQjlVKzaT4:tdomFVv7xQA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=aZQjlVKzaT4:tdomFVv7xQA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=aZQjlVKzaT4:tdomFVv7xQA:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>House of Cards</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/20100827_house_of_cards/" />
		<id>tag:circleid.com,2010:blogs/1.4941</id>
		<updated>2010-08-27T17:38:01-08:00</updated>
		<author><name>Earl Zmijewski</name></author>
		<category term="internet_protocol" scheme="http://www.circleid.com/topics/internet_protocol/" label="Internet Protocol" /><category term="security" scheme="http://www.circleid.com/topics/security/" label="Security" />
		<content type="html">&lt;p&gt;Time flies. Although it was over 18 months ago, it seems just like yesterday that a small Czech provider, SuproNet, caused &lt;a href="http://www.renesys.com/blog/2009/02/the-flap-heard-around-the-worl.shtml"&gt;global Internet mayhem&lt;/a&gt; by making a perfectly valid (but extremely long) routing announcement. Since Internet routing is trust-based, within seconds every router in the world saw this announcement and tried to pass it on. Unfortunately, due to the size of this single message, quite a few routers choked&amp;#8212;resulting in widespread Internet instability. Today, over a year later, we were treated to a somewhat different version of the exact same story.
&lt;/p&gt;
&lt;p&gt;
First, let's review the Czech incident from February 2009. There were many positives to take away.
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;It was precipitated by an honest mistake.&lt;/li&gt;
&lt;li&gt;It was an extremely unlikely event, as many stars had to be in exact alignment.&lt;/li&gt;
&lt;li&gt;Most of the Internet's core survived.&lt;/li&gt;
&lt;li&gt;The response from operators was fast and efficient, with the damage largely contained within an hour.&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;
The complete technical details can be found &lt;a href="http://www.renesys.com/blog/2009/02/longer-is-not-better.shtml"&gt;here&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Deja vu all over again&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
Fast forward to today: Friday, 27 August 2010. What do you think would happen if another large and unusual routing announcement was made on the Internet? Do you think all the router vendors have perfected their code in the past 18 months? Do you think the entire planet has upgraded to this new, improved and perfect code base? Do you think it makes sense to use the Internet as your testbed? I doubt you answered "yes" to any of these questions.
&lt;/p&gt;
&lt;p&gt;
We'll begin to describe what happened today with a snippet from a private mailing list. We'll purposely leave out the technical details so that we don't inadvertently contribute to the building of a &lt;a href="http://www.renesys.com/blog/2010/04/how-to-build-a-cybernuke.shtml"&gt;Cybernuke&lt;/a&gt;.
&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;On Friday 27 August, from 08:41 to 09:08 UTC, the RIPE NCC Routing Information Service (RIS) announced a route with an experimental BGP attribute. During this announcement, some Internet Service Providers reported problems with their networking infrastructure.
&lt;/p&gt;
&lt;p&gt;
Immediately after discovering this, we stopped the announcement and started investigating the problem. Our investigation has shown that the problem was likely to have been caused by certain router types incorrectly modifying the experimental attribute and then further announcing the malformed route to their peers. The announcements sent out by the RIS were correct and complied to all standards.&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;
Um, while standards compliance is nice, it is foolhardy to assume that all BGP implementations are perfectly compliant, especially given &lt;a href="http://www.renesys.com/blog/2009/08/staring-into-the-gorge.shtml"&gt;recent history&lt;/a&gt;. Over 3,500 prefixes (announced blocks of IP addresses) became unstable at the exact moment this "experiment" started. Not surprisingly, they were located all over the world: 832 in the US, 336 in Russia, 277 in Argentina, 256 in Romania and so forth. We saw over 60 countries impacted by a "correct" announcement that "complied with all standards". The following graph shows the timeline of the event, followed by a map of the impacted countries by prefix count. Notice that it takes a bit for the Internet to stabilize after RIPE claims to have withdrawn the announcement at 09:08 UTC.
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.circleid.com/images/uploads/4941a.gif" border="0" width="627" height="470" style="display:block;" /&gt;
&lt;br /&gt;
&lt;img src="http://www.circleid.com/images/uploads/4941b.gif" border="0" width="640" height="407" style="display:block;" /&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Conclusions&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
On the positive side, the incident was very brief, the damage was limited to under 2% of the Internet and the responsible parties quickly fessed up, aborting their "experiment". On the negative side, the Internet remains a very fragile place, even if that fragility is highly localized and different in different places. Standards aren't followed, code isn't tested and people make mistakes. That's life with any complex system and, while we can certainly do a better job, we will continue to see these types of events no matter what safeguards we might take. What puzzles me is how anyone thought it might be a good idea to test fate in this way. The end result was completely predictable.
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/3289/"&gt;Earl Zmijewski&lt;/a&gt;, VP and General Manager, Internet Data Services&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/internet_protocol"&gt;Internet Protocol&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/security"&gt;Security&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=0y91tfJbuO8:8X9_67QDvnE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=0y91tfJbuO8:8X9_67QDvnE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=0y91tfJbuO8:8X9_67QDvnE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=0y91tfJbuO8:8X9_67QDvnE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=0y91tfJbuO8:8X9_67QDvnE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=0y91tfJbuO8:8X9_67QDvnE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=0y91tfJbuO8:8X9_67QDvnE:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=0y91tfJbuO8:8X9_67QDvnE:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=0y91tfJbuO8:8X9_67QDvnE:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>White House Calls for a Meeting with Domain Registrars, Registries, and ICANN</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/white_house_calls_for_a_meeting_with_domain_registrars_registries_and_icann/" />
		<id>tag:circleid.com,2010:news/6.4940</id>
		<updated>2010-08-27T11:21:00-08:00</updated>
		<author><name>CircleID Reporter</name></author>
		<category term="cybercrime" scheme="http://www.circleid.com/topics/cybercrime/" label="Cybercrime" /><category term="domain_names" scheme="http://www.circleid.com/topics/domain_names/" label="Domain Names" /><category term="domain_registries" scheme="http://www.circleid.com/topics/domain_registries/" label="Domain Registries" /><category term="icann" scheme="http://www.circleid.com/topics/icann/" label="ICANN" /><category term="internet_governance" scheme="http://www.circleid.com/topics/internet_governance/" label="Internet Governance" />
		<content type="html">&lt;p&gt;Brian Krebs &lt;a href="http://krebsonsecurity.com/2010/08/white-house-calls-meeting-on-rogue-online-pharmacies/"&gt;reporting in Krebs on Secruity&lt;/a&gt;: "The Obama administration is inviting leaders of the top Internet domain name registrars and registries to attend a three-hour meeting at the White House next month about voluntary ways to crack down on Web sites that are selling counterfeit prescription medications..."
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/cybercrime"&gt;Cybercrime&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/domain_names"&gt;Domain Names&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/domain_registries"&gt;Domain Registries&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/icann"&gt;ICANN&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/internet_governance"&gt;Internet Governance&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=oVpu46-pqMs:4ffw8AP_geA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=oVpu46-pqMs:4ffw8AP_geA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=oVpu46-pqMs:4ffw8AP_geA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=oVpu46-pqMs:4ffw8AP_geA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=oVpu46-pqMs:4ffw8AP_geA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=oVpu46-pqMs:4ffw8AP_geA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=oVpu46-pqMs:4ffw8AP_geA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=oVpu46-pqMs:4ffw8AP_geA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=oVpu46-pqMs:4ffw8AP_geA:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>ICANN's Tokyo Meeting Provides a Little More Clarity on the New gTLD Program</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/20100827_icann_tokyo_meeting_more_clarity_on_the_new_gtld_program/" />
		<id>tag:circleid.com,2010:blogs/1.4939</id>
		<updated>2010-08-27T07:44:00-08:00</updated>
		<author><name>Tony Kirsch</name></author>
		<category term="domain_names" scheme="http://www.circleid.com/topics/domain_names/" label="Domain Names" /><category term="domain_registries" scheme="http://www.circleid.com/topics/domain_registries/" label="Domain Registries" /><category term="icann" scheme="http://www.circleid.com/topics/icann/" label="ICANN" /><category term="multilinguism" scheme="http://www.circleid.com/topics/multilinguism/" label="Multilinguism" /><category term="top_level_domains" scheme="http://www.circleid.com/topics/top_level_domains/" label="Top-Level Domains" />
		<content type="html">&lt;p&gt;New gTLDs continue to be a major topic of discussion within ICANN circles, and the regional meeting currently underway in Tokyo has revealed some interesting updates for potential applicants.
&lt;/p&gt;
&lt;p&gt;
ICANN's Chief gTLD Registry Liaison, Craig Schwartz, delivered a great presentation on the progress being made behind closed doors at ICANN and provided the attendees with an insight into a couple of key changes that are likely to be seen in the Final Applicant Guidebook. As many of our readers would be aware, we have been waiting in anticipation for the new gTLD Final Applicant Guidebook to be approved at a previously unconfirmed meeting of the ICANN Board. The date for this meeting was today announced as September 10th.
&lt;/p&gt;
&lt;p&gt;
Like many others in the industry, we'll be actively watching for the outcomes of this Board retreat where the focus will be on the new gTLD program's remaining unresolved issues. In particular, the Board's willingness to address the complicated Vertical Integration topic (given the inability of the VI Working Group to reach consensus) will be of interest to the many applicants likely to be affected by the outcome.
&lt;/p&gt;
&lt;p&gt;
On another interesting note, one very important topic that has been flying under the radar is Registry Transition, namely the current requirement for new gTLD applicants to provide both a backup Registry Services organisation and a financial instrument sufficient to guarantee a minimum of three years of Registry operations in the event of the TLD owner being unable to operate it.
&lt;/p&gt;
&lt;p&gt;
Obtaining a backup Registry Services provider is not particularly difficult. However, for many potential applicants (in particular smaller community-based applicants) the requirement to obtain a letter of credit from a financial organisation is an enormous burden and a significant additional cost.
&lt;/p&gt;
&lt;p&gt;
Acknowledging this today and noting that the protection of the Registrant is paramount to this process, Schwartz said that ICANN had invested significant time and will further expand the recent concept of Emergency Backend Registry Operator (and yet another acronym, EBERO) whereby qualified applicants (i.e. Existing Registry Operators) could tender to ICANN to provide 'temporary' Registry Services in the event of critical failure of the Registry Operator to operate the gTLD.
&lt;/p&gt;
&lt;p&gt;
This is a great initiative and should be welcomed by the community for two key reasons:
&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;a) It has the potential to remove the requirement to name a pre-organised backup Registry Service.
&lt;/p&gt;
&lt;p&gt;
b) It has the potential to reduce the level of financial guarantee to ICANN from applicants.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;
Other interesting points worthy of note from yesterday's session:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Communications Plan &lt;/strong&gt; &amp;ndash; This is being worked on by ICANN currently but won't be rolled out until the Final Applicant Guidebook is approved, almost guaranteeing that the earliest date for applications will be March or April 2011&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;DAGv4 Summary of Analysis&lt;/strong&gt; &amp;ndash; This won't be released to the public until after the Board's retreat, which is a surprise given that the public comment finished quite some time ago&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;IDN ccTLD Fast Track&lt;/strong&gt; &amp;ndash; ICANN have 33 applicants, representing 22 languages, currently under review as this program continues to drive the expansion of the internet across the globe&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;
All in all, these small yet important pieces of information represent yet another positive step forward in the new gTLD process. I for one can't wait to see what the next few months will bring.
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://meetings.icann.org/apregional-2010"&gt;Click here&lt;/a&gt; if you want to see the presentations from the Tokyo meeting as provided by ICANN.
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/3513/"&gt;Tony Kirsch&lt;/a&gt;, Senior Manager - International Business Development, AusRegistry International&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/domain_names"&gt;Domain Names&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/domain_registries"&gt;Domain Registries&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/icann"&gt;ICANN&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/multilinguism"&gt;Multilinguism&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/top_level_domains"&gt;Top-Level Domains&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=DYhrQJ4qjrw:x5Z_jDWYpmc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=DYhrQJ4qjrw:x5Z_jDWYpmc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=DYhrQJ4qjrw:x5Z_jDWYpmc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=DYhrQJ4qjrw:x5Z_jDWYpmc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=DYhrQJ4qjrw:x5Z_jDWYpmc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=DYhrQJ4qjrw:x5Z_jDWYpmc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=DYhrQJ4qjrw:x5Z_jDWYpmc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=DYhrQJ4qjrw:x5Z_jDWYpmc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=DYhrQJ4qjrw:x5Z_jDWYpmc:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>IPv6 Deployed But in Unexpected Places</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/ipv6_deployed_but_in_unexpected_places/" />
		<id>tag:circleid.com,2010:news/6.4938</id>
		<updated>2010-08-26T14:21:00-08:00</updated>
		<author><name>CircleID Reporter</name></author>
		<category term="ipv6" scheme="http://www.circleid.com/topics/ipv6/" label="IPv6" />
		<content type="html">&lt;p&gt;Eric Vyncke reporting in the NetworkWorld: "IPv6 exists for more than 15 years and it is rumored to be deployed extensively in Asia and especially in Japan and China with Africa being the last continent to deploy IPv6. Another place where there should be a lot of deployments is of course in the USA with the US Government IPv6 mandates. But, when it comes to measure where web sites are actually deployed over IPv6, the rumor proves to be just a myth..."
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/ipv6"&gt;IPv6&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=cNnvYR0DAvA:d4Y_5qP_vb0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=cNnvYR0DAvA:d4Y_5qP_vb0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=cNnvYR0DAvA:d4Y_5qP_vb0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=cNnvYR0DAvA:d4Y_5qP_vb0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=cNnvYR0DAvA:d4Y_5qP_vb0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=cNnvYR0DAvA:d4Y_5qP_vb0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=cNnvYR0DAvA:d4Y_5qP_vb0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=cNnvYR0DAvA:d4Y_5qP_vb0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=cNnvYR0DAvA:d4Y_5qP_vb0:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>Ensuring Maximum Resilience to the DNS?</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/20100826_ensuring_maximum_resilience_to_the_dns/" />
		<id>tag:circleid.com,2010:blogs/1.4936</id>
		<updated>2010-08-26T10:34:00-08:00</updated>
		<author><name>Chuck Kisselburg</name></author>
		<category term="cybercrime" scheme="http://www.circleid.com/topics/cybercrime/" label="Cybercrime" /><category term="dns" scheme="http://www.circleid.com/topics/dns/" label="DNS" /><category term="dnssec" scheme="http://www.circleid.com/topics/dnssec/" label="DNSSEC" /><category term="security" scheme="http://www.circleid.com/topics/security/" label="Security" />
		<content type="html">&lt;p&gt;Yesterday &lt;a href="http://www.communitydns.net"&gt;CommunityDNS&lt;/a&gt; noticed a sudden, heavy spike in traffic through its Anycast node in Hong Kong. While comfortably processing queries at 863,000 queries per second for close to 2 hours the occurrence was undeniable. While we can't say the increase in traffic was specifically due to DDoS, its sudden increase is suspicious and reminds us that DDoS is still a popular tool used by the malicious community.
&lt;/p&gt;
&lt;p&gt;
DoS and DDoS attacks are happening throughout each day. Just as &lt;a href="http://www.theregister.co.uk/2009/04/01/ultradns_ddos/"&gt;UltraDNS&lt;/a&gt; was &lt;a href="http://m.theregister.co.uk/2009/12/24/ddos_attack_ultradns_december_09/"&gt;twice&lt;/a&gt; regionally impacted in 2009 by DDoS traffic, Register.com with close to a &lt;a href="http://www.securecomputing.net.au/News/141617,ddos-attacks-hit-major-web-services.aspx"&gt;3 day outage&lt;/a&gt; in 2009, and DNS Made Easy, the recent target creating close to a &lt;a href="http://www.theregister.co.uk/2010/08/09/dns_service_monster_ddos/"&gt;1.5 hour outage&lt;/a&gt; for its users earlier this month, we (enterprise, ISPs, hosting firms, registrars and DNS providers) are not all immune to such malicious antics. While all queries appeared legitimate in yesterday's spike, there is no reason to believe CommunityDNS was the intended target for the sudden increase in traffic. However, it still raises the issue of the impact such malicious activity can have on the general user base as well as online economy.
&lt;/p&gt;
&lt;p&gt;
Last year and earlier this year CommunityDNS worked on a study developed for the EU Commission's office of Directorate-General for Justice, Freedom and Security, regarding the resilience of the DNS for the EU and its member states. The study pointed out the affects such malicious activity has on the confidence of legitimate Internet users. Such affects erode confidence, thus the EU's online economy not able to reach its full potential. The same concept would apply to any online economy. The study also noted how "suspicious" traffic appeared more elevated in some European cities over others. A recent Forrester &lt;a href="http://www.voipforbusiness.biz/business-voip-articles/denial-of-service-attacks-and-their-effect-in-corporate-economy.html"&gt;survey&lt;/a&gt; indicated organizations experienced more than 350,000 DDoS attacks in 2009. Another &lt;a href="http://www.darkreading.com/security/perimeter/showArticle.jhtml?articleID=211201299 "&gt;study&lt;/a&gt;, from Arbor Networks, yielded a statistic of approximately 3% of the Internet's traffic is tied to DDoS, or roughly 1,300 attacks each day.
&lt;/p&gt;
&lt;p&gt;
So as the Internet marches on with the needed ramp up of DNSSEC, the rollout of IDNs and eventually the addition of new gTLDs, the malicious community continues their global activity. Such activity should make us all question, "Are we doing the best we can to ensure maximum resilience for Internet users and online economies?" The best way to ensure maximum resilience for users, businesses and the general online economy is through platform diversity. Where one has an open source-based DNS platform, a non-open source-based platform should be used. A mix of hardware platforms, upon which the open source and non-open source DNS software operates, is also necessary as the hacker community has more tricks up their sleeve than DDoS attacks. Adding hardware and software diversity into an infrastructure with strong security, ample capacity and scalability is the strongest method for ensuring maximum resilience to the DNS.
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/4264/"&gt;Chuck Kisselburg&lt;/a&gt;, Director, Strategic Partnerships&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/cybercrime"&gt;Cybercrime&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/dns"&gt;DNS&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/dnssec"&gt;DNSSEC&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/security"&gt;Security&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=etMAwZgQO5E:K_2OWXimOvA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=etMAwZgQO5E:K_2OWXimOvA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=etMAwZgQO5E:K_2OWXimOvA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=etMAwZgQO5E:K_2OWXimOvA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=etMAwZgQO5E:K_2OWXimOvA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=etMAwZgQO5E:K_2OWXimOvA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=etMAwZgQO5E:K_2OWXimOvA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=etMAwZgQO5E:K_2OWXimOvA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=etMAwZgQO5E:K_2OWXimOvA:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>The Window of Opportunity for ccTLDs</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/20100825_the_window_of_opportunity_for_cctlds/" />
		<id>tag:circleid.com,2010:blogs/1.4930</id>
		<updated>2010-08-25T19:27:00-08:00</updated>
		<author><name>Jon Lawrence</name></author>
		<category term="dns" scheme="http://www.circleid.com/topics/dns/" label="DNS" /><category term="domain_names" scheme="http://www.circleid.com/topics/domain_names/" label="Domain Names" /><category term="domain_registries" scheme="http://www.circleid.com/topics/domain_registries/" label="Domain Registries" /><category term="top_level_domains" scheme="http://www.circleid.com/topics/top_level_domains/" label="Top-Level Domains" />
		<content type="html">&lt;p&gt;The announcement that .co has already achieved over 450,000 new registrations since the opening up of the second level a month ago demonstrates that there is strong demand in the global domain name marketplace for quality new domain spaces.
&lt;/p&gt;
&lt;p&gt;
Though .co is the country code Top Level Domain (ccTLD) for Colombia, the second-level registrations (i.e. company.co) are available on a global basis and it is being pitched as a direct competitor to the dominant .com gTLD. Google has altered its algorithm to increase the relevance of search results in the .co domain by treating .co as a gTLD and allowing .co website owners to specify the geographic regions they are targeting. Though &lt;a href="http://www.cointernet.co/"&gt;.CO Internet&lt;/a&gt; has the freedom enjoyed by all ccTLDs of not having to operate under ICANN's policy framework, they have elected to adopt policies that very closely match that framework, including the Uniform Domain Name Dispute Resolution Policy (UDRP).
&lt;/p&gt;
&lt;p&gt;
The launch of second-level registrations under .co therefore represents, to all intents and purposes, a new gTLD launch, and appears to be a popular alternative to .com for both large corporations and small businesses, at least at this early stage. Overstock's &lt;a href="http://investors.overstock.com/phoenix.zhtml?c=131091&amp;amp;p=irol-newsArticle&amp;amp;ID=1449274&amp;amp;highlight="&gt;purchase of o.co for US$350,000&lt;/a&gt; shows a high degree of confidence in the new .co brand, and Twitter has also joined their list of high-profile anchor tenants, launching &lt;a href="http://www.t.co/"&gt;t.co&lt;/a&gt; as a secure URL shortening service. Anecdotal evidence also suggests that small businesses are taking the opportunity to secure names within this new space that they had been unable to register in .com or other spaces.
&lt;/p&gt;
&lt;p&gt;
The .co launch is just the latest in a long line of examples of the opportunistic repositioning of ccTLDs to compete in the global market against the 'official' gTLDs. Colombia, like Montenegro (.me) and Tuvalu (.tv) and a number of others are simply leveraging their luck in the two-character assignment lottery by opening up their ccTLD to the world. Both Colombia and Montenegro have however tried to maintain the best of both worlds by reserving third-level registrations (such as .com.co and .com.me) for local entities, thereby providing trusted and dedicated domain spaces for the domestic market, while reaping the benefits of having a desirable ccTLD extension by opening up the second level to the world.
&lt;/p&gt;
&lt;p&gt;
Despite the fact that they are globally-focused and effectively gTLDs, the success of .co and .me highlights the market opportunity that currently exists for other ccTLDs that are yet to establish a clear market position.
&lt;/p&gt;
&lt;p&gt;
Of course, the vast majority of countries do not have the opportunity to reposition themselves as gTLDs to chase the global market, and in most cases there will be a clear preference to focus on the needs of the local market.
&lt;/p&gt;
&lt;p&gt;
A &lt;a href="http://www.eurid.eu/files/eu_insights_1.pdf"&gt;report&lt;/a&gt; [PDF] released by Eurid (the .eu Registry) in June highlights the power that well-established and effectively managed ccTLDs can exert in their local markets. In Sweden, for example, the local .se ccTLD scored nearly 100% in terms of awareness and 49% for preference, compared with only 34% for .com. Similar rankings are likely to be enjoyed by other well-established ccTLDs, and we've seen similar numbers in relation to the position of .au in Australia.
&lt;/p&gt;
&lt;p&gt;
Many ccTLDs however face a raft of challenges that are preventing them from achieving anything like this sort of local market position. These challenges can include the absence of local control, legacy systems, inefficient registration processes and restrictive policies, as well as a general lack of local capacity.
&lt;/p&gt;
&lt;p&gt;
When ICANN's new gTLD program finally comes to fruition (likely towards the latter part of 2011), there will be a dramatic increase in choice for prospective domain name registrants across all regions and language groups. Those ccTLDs that are yet to position themselves as the pre-eminent domain space and default choice in their local markets therefore have a finite window of opportunity in which to do so, to ensure that they are not consigned to relative obscurity in the face of dozens of new Top Level Domains.
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/1440/"&gt;Jon Lawrence&lt;/a&gt;, Business Development Consultant, AusRegistry International&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/dns"&gt;DNS&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/domain_names"&gt;Domain Names&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/domain_registries"&gt;Domain Registries&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/top_level_domains"&gt;Top-Level Domains&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=x6gXDhp-fxk:lBdahUFQY_E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=x6gXDhp-fxk:lBdahUFQY_E:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=x6gXDhp-fxk:lBdahUFQY_E:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=x6gXDhp-fxk:lBdahUFQY_E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=x6gXDhp-fxk:lBdahUFQY_E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=x6gXDhp-fxk:lBdahUFQY_E:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=x6gXDhp-fxk:lBdahUFQY_E:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=x6gXDhp-fxk:lBdahUFQY_E:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=x6gXDhp-fxk:lBdahUFQY_E:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>Omnibus Cybersecurity Bill May Not Go Where Original Authors Intended</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/20100825_cybersecurity_bill_may_not_go_where_original_authors_intended/" />
		<id>tag:circleid.com,2010:blogs/1.4935</id>
		<updated>2010-08-25T19:17:00-08:00</updated>
		<author><name>J.D. Falk</name></author>
		<category term="cybercrime" scheme="http://www.circleid.com/topics/cybercrime/" label="Cybercrime" /><category term="law" scheme="http://www.circleid.com/topics/law/" label="Law" /><category term="policy_regulation" scheme="http://www.circleid.com/topics/policy_regulation/" label="Policy &amp; Regulation" /><category term="security" scheme="http://www.circleid.com/topics/security/" label="Security" />
		<content type="html">&lt;p&gt;In &lt;a href="http://www.govinfosecurity.com/articles.php?art_id=2868&amp;amp;rf=2010-08-25-eg"&gt;an interview with GovInfoSecurity&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Thomas_Carper"&gt;Sen. Thomas Carper&lt;/a&gt; said that the U.S. Senate is considering attaching cybersecurity legislation to a defense authorizations bill. Though clearly a ploy to be able to say "we did something about those evil hackers" before the elections, CAUCE applauds the attempt. There can be no doubt that the United States (and many other countries) sorely needs better laws to deal with these threats.
&lt;/p&gt;
&lt;p&gt;
Further, Senate Majority Leader &lt;a href="http://en.wikipedia.org/wiki/Harry_Reid"&gt;Harry Reid&lt;/a&gt; has asked that the cybersecurity bills currently in front of various committees be combined into one single, omnibus bill, which would presumably then be attached to the defense authorizations bill. Here's where we start to get worried.
&lt;/p&gt;
&lt;p&gt;
Each of the bills we've seen (and we surely haven't seen them all yet) have some good points, and some...let's just call them unintended consequences. In every case it's obvious that the authors' intentions were good, but they needed some expert advice from people who understand the technical and legal realities of the internet today.
&lt;/p&gt;
&lt;p&gt;
One such expert, a long-time CAUCE supporter who asked to remain anonymous, shares his review of one of those bills: S. 3742, the "Data Security and Breach Notification Act of 2010." You can read the original and check its current status &lt;a href="http://thomas.loc.gov/cgi-bin/query/z?c111:S.3742.IS:" target="_blank"&gt;here&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
&lt;em&gt;Please note that this is &lt;u&gt;not&lt;/u&gt; legal advice. Our expert is not a lawyer, I'm not a lawyer, and CAUCE did not consult with any lawyers before publishing this article.&lt;/em&gt;
&lt;/p&gt;
&lt;p&gt;
Our expert says it's going to be difficult to construct a single good omnibus cybersecurity bill. The bigger and more complicated it gets, the less likely it is that anyone will actually &lt;a href="http://readthebill.org/"&gt;read the bill&lt;/a&gt; before voting on it&amp;#8212;particularly when they're in a hurry to go home and win an election.
&lt;/p&gt;
&lt;p&gt;
He highlights a few specific items which could be troublesome for just about anyone running a mail server, a web site, or other online services which collect or transit any information:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;em&gt;Page 2, Section 2 (a)(2)(A):&lt;/em&gt; More or less everyone's going to need to have &lt;a href="http://en.wikipedia.org/wiki/Personally_identifiable_information"&gt;personally identifiable information (PII)&lt;/a&gt; security policies&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Page 3, Section 2 (a)(2)(B):&lt;/em&gt; ... and an information security officer&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Page 3, Section 2 (a)(2)(C):&lt;/em&gt; ... and a process for monitoring for PII breaches&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Page 3, Section 2 (a)(2)(D):&lt;/em&gt; ... and a process for mitigating PII vulnerabilities&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Page 3, Section 2 (a)(2)(E):&lt;/em&gt; ... and a process for securely deleting electronic records containing PII&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Page 4, Section 2 (a)(2)(F):&lt;/em&gt; ... and a process for securely destroying paper and other non-electronic records containing PII&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Page 4, Section 2 (b):&lt;/em&gt; If you're an "information broker" (which would include nearly anyone who collects information and shares it with anyone else), you have additional obligations, including needing to submit policies to the FTC, needing to provide consumer access to information, tracking access to information maintained by the broker, etc.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Page 13, Section 3 (a)(1):&lt;/em&gt; Requires notification solely to US citizens and residents in the event of a breach. Of course, that presumes you know the nationality/immigration status of those whose PII data you hold (hmm, I don't think *anyone* I know does, except for HR departments with regard to their own employees). If I were a covered entity, I'd be strongly inclined to begin soliciting that information from everyone I get PII data from, although of course that may trigger a whole different set of issues, particularly in areas where immigration related issues are a hot button topic.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Page 14, Section 3 (b)(2):&lt;/em&gt; Notification by a service provider triggers reporting requirements. This is going to make LOTS of friends for service providers, given the affirmative notification and credit protection obligations that customers accrue after being notified.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Page 19, Section 3 (d)(2)(A):&lt;/em&gt; Alternative notification is available for incidents involving LESS than 1,000 individuals. This is goofy.
&lt;br /&gt;
Normally alternative notification is allowed as an option when the number of covered individuals is very LARGE not very small. For example, some state laws permit alternative notification in cases where costs of providing notice would exceed a quarter million dollars, the affected class of consumers to be notified exceeds 350,000, or the notifying party doesn't have sufficient contact information to provide notice.&lt;br /&gt;There's language on page 22 of the draft bill that may allow regulatory additions to expand when substitute notification is permissible, but the basics for when substitute notification should be permissible should be part of the core statute, not an after-the-fact, maybe-yes, maybe-no regulatory add on by the agency.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Page 25, Section 3 (d)(2)(B):&lt;/em&gt; imposes compliance burdens on entities for a year &lt;em&gt;before&lt;/em&gt; technical compliance guidance is available. Enforcement of the act should be held until the guidance envisioned by 3(d)(2)(B) is available, and realistically it will take probably an additional period after that for sites to deploy the recommended technology (new projects don't happen over night).&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Page 26, Section 3 (h):&lt;/em&gt; Potentially requires notification in polyglot languages. This can be a huge administrative PITA&amp;#8212;consider the "simple" case of the EU, where there are "only" 23 official languages (Bulgarian, Czech, Danish, Dutch, English, Estonian, Finnish, French, German, Greek, Hungarian, Irish, Italian, Latvian, Lithuanian, Maltese, Polish, Portugese, Romanian, Slovak, Slovene, Spanish and Swedish, plus (semi-official) Catalan, Galician, and Basque).
&lt;br /&gt;
This section could be potentially exceptionally burdensome if the FCC suddenly mandates that sites provide notification in multiple foreign languages (I could see an argument for requiring Spanish as well as English, but there are some communities in the United States where other languages are also very common).&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Page 28, Section 4 (b)(1):&lt;/em&gt; It seems unnecessarially combative to define all data security incidents as "unfair or deceptive acts or practices." Data security incidents are not typically something which a covered entity &lt;em&gt;intentionally&lt;/em&gt; does, neither are such breaches typically "unfair" or "deceptive" in the same way that some TV or Internet huckster's "miracle" product or pyramid sales scheme might be.&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;
The most persuasive argument in the other direction is probably that currently most states already have their own PII breach notification laws, and it can be a pain to try to stay in compliance with &lt;a href="http://www.ncsl.org/IssuesResearch/TelecommunicationsInformationTechnology/SecurityBreachNotificationLaws/tabid/13489/Default.aspx"&gt;46 different PII information security and breach notification statutes&lt;/a&gt;. So again, the intention is clearly good, but in practice...it needs some careful review.
&lt;/p&gt;
&lt;p&gt;
So there are the results from &lt;em&gt;one&lt;/em&gt; bill, examined by &lt;em&gt;one&lt;/em&gt; expert. He's one of the best minds in the cybersecurity community, yet he may still have missed something. With legislation as important as this, smushing it all together and rushing to attach it to something unrelated is simply a bad idea. This is a topic which requires careful thought, from multiple people who &lt;em&gt;really do&lt;/em&gt; know what they're doing&amp;#8212;and who can explain it to the Congressional staffers who will write the resulting bill, and then to the Senators and Representatives who will collectively make the decision.
&lt;/p&gt;
&lt;p&gt;
Once that education has occurred, it should quickly become evident that while some of these bills do overlap, others do not. Some will disagree. Some simply contain bad ideas. All of this has to be worked out. Then, finally, it might make sense to combine them&amp;#8212;not now, and not just because they all have the prefix "cyber" in the title somewhere.
&lt;/p&gt;
&lt;p&gt;
&lt;em&gt;This article was originally published by &lt;a href="http://www.cauce.org/2010/08/omnibus-cybersecurity-bill.html"&gt;CAUCE&lt;/a&gt;.&lt;/em&gt;
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/3217/"&gt;J.D. Falk&lt;/a&gt;, Director of Product Strategy at Return Path&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/cybercrime"&gt;Cybercrime&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/law"&gt;Law&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/policy_regulation"&gt;Policy &amp; Regulation&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/security"&gt;Security&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=jiweVmYtzFk:exraKxh1mT0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=jiweVmYtzFk:exraKxh1mT0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=jiweVmYtzFk:exraKxh1mT0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=jiweVmYtzFk:exraKxh1mT0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=jiweVmYtzFk:exraKxh1mT0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=jiweVmYtzFk:exraKxh1mT0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=jiweVmYtzFk:exraKxh1mT0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=jiweVmYtzFk:exraKxh1mT0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=jiweVmYtzFk:exraKxh1mT0:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>Network Neutrality in the Wireless Space</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/network_neutrality_in_the_wireless_space/" />
		<id>tag:circleid.com,2010:blogs/1.4933</id>
		<updated>2010-08-25T14:49:00-08:00</updated>
		<author><name>Brad Templeton</name></author>
		<category term="broadband" scheme="http://www.circleid.com/topics/broadband/" label="Broadband" /><category term="mobile" scheme="http://www.circleid.com/topics/mobile/" label="Mobile" /><category term="net_neutrality" scheme="http://www.circleid.com/topics/net_neutrality/" label="Net Neutrality" /><category term="policy_regulation" scheme="http://www.circleid.com/topics/policy_regulation/" label="Policy &amp; Regulation" /><category term="telecom" scheme="http://www.circleid.com/topics/telecom/" label="Telecom" /><category term="wireless" scheme="http://www.circleid.com/topics/wireless/" label="Wireless" />
		<content type="html">&lt;p&gt;There's been a tremendous amount written about the Google-Verizon joint proposal for network neutrality regulation. &lt;a href="https://www.eff.org/deeplinks/2010/08/google-verizon-netneutrality"&gt;Our commentary at the EFF&lt;/a&gt; offers some legal analysis of the good and bad in this proposal. A lot of commentary has put a big focus on the exemption for wireless networks, since many feel wireless is the real "where it's gonna be," if not the "where it's at" for the internet.
&lt;/p&gt;
&lt;p&gt;
Previously I wrote about &lt;a href="http://ideas.4brad.com/network-neutrality-wireless-space"&gt;support for the principles of a neutral network, but fear of FCC regulation&lt;/a&gt; and decided that the real issue here is monopoly regulation, not network regulation. My feelings remain the same. In wireless we don't have the broadband duopoly, but it is a space with huge barriers to entry, the biggest one being the need to purchase a monopoly on spectrum from the government. I don't believe anybody should get a monopoly on spectrum (either at auction or as a gift) and each spectrum auction is another monopoly bound to hurt the free network.
&lt;/p&gt;
&lt;p&gt;
Most defenders of the exemption for wireless think it's obvious. Bandwidth in wireless is much more limited, so you need to manage it a lot more. Today, that's arguably true. I have certainly been on wireless networks that were saturated, and I would like &lt;em&gt;on those networks&lt;/em&gt; to have the big heavy users discouraged so that I can get better service.
&lt;/p&gt;
&lt;p&gt;
&lt;span style="font-size:85%;color:#666666;padding:0 0 2px 7px;margin:0 0 10px 10px;border-left:1px solid #ddd;width:400px;float:right;line-height:1.4em;"&gt;&lt;img src="http://www.circleid.com/images/uploads/4933.jpg" border="0" width="400" height="311" style="display:block;margin-bottom:5px;" /&gt;With Martin Cooper (Left), former Motorola vice president and division manager who in the 1970s led the team that developed the handheld mobile phone (as distinct from the car phone).&lt;br /&gt;&lt;em&gt;Source: &lt;a href="http://en.wikipedia.org/wiki/Martin_Cooper_%28inventor%29"&gt;Wikipedia&lt;/a&gt;&lt;/em&gt;&lt;/span&gt;As I said, on those networks. Those networks were designed, inherently, with older more expensive technology. But we know that each year technology gets cheaper, and wireless technology is getting cheaper really fast, with spectrum monopolies being the main barrier to innovation. We would be fools to design and regulate our networks based on the assumptions of the year 2000 or even on the rules of 2010. We need to plan a regime for what we expect in 2015, and one which adapts and changes as wireless technology improves and gets cheaper. Planning for linear improvement is sure to be an error, even if nobody can tell you exactly what will be for sale in 2015. I just know it won't be only marginally better or cheaper than what we have now.
&lt;/p&gt;
&lt;p&gt;
The reality is, there is tons of wireless bandwidth&amp;#8212;in fact, it's effectively limitless. Last week I got to have dinner with Marty Cooper, who built the first mobile phone, and he has noticed that the total bandwidth we put into the ether has been on an exponential doubling curve for some time, with no signs of stopping. We were in violent agreement that the FCC's policies are way out of date and really should not exist. (You'll notice that he's holding a Droid X while I have the replica Dyna-Tac. He found it refreshing to not be the one holding the Dyna-Tac.)
&lt;/p&gt;
&lt;p&gt;
Bandwidth is limitless both because we keep improving it, and because we can build picocells anywhere there is demand. The picocells use very high frequencies and won't go through walls. You may think that's a bug, but actually it's a feature, because you can have two picocells in different rooms that don't interfere much with each other, and get gigabits in each individual room. While wireless use is growing quickly, much of that is coming inside buildings.
&lt;/p&gt;
&lt;p&gt;
In the past, having so many cells would be too expensive. But today the electronics for the cells cost a pittance compared to what old thinking predicted. And that's going to continue. This is just one way we know to get more bandwidth for everybody.
&lt;/p&gt;
&lt;p&gt;
The original question was whether it was good for somebody to be soaking up the wireless bandwidth in your area downloading a movie, and whether networks needed to throttle such users. We scream out that they should, but our thinking is short-term. &lt;strong&gt;It is the congestion caused by these heavy users, after all, that drives the innovation and network expansion&lt;/strong&gt;. If we can "solve" our problem with network management rather than putting in more bandwidth, then we don't create as much incentive to make the bandwidth technology cheap. If the only way we can solve the problem is to boost the network capacity to match the wired one, that's how we will solve it.
&lt;/p&gt;
&lt;p&gt;
Some have argued, in fact, that it's cheaper to solve these problems with more bandwidth than it is to solve them with network management. Network management turns out to be pretty hard, and requires lots of work by human beings, and thus it's quite expensive. And it's not getting cheaper, for it is not a problem that Moore's law (or Cooper's law) helps you as much with. Boosting the network is such a problem. And if you solve congestion this way, and drive the creation of better and cheaper products, not only do you get reduced congestion but you also get a nice fast network when it's not congested. It's a huge win for the network and for the world, since everybody gets to buy the new technology, while not everybody needs the network management.
&lt;/p&gt;
&lt;p&gt;
It's been popular to tell Google they are being evil by getting together with Verizon on this deal. I suspect it's more a case of not thinking about the future. Once the FCC encodes rules into law, we'll have them for decades, and even if we're lucky enough to get the right rules today, they won't be the right rules for the future. Alas, they will probably be the rules the lobbyists want.
&lt;/p&gt;
&lt;p&gt;
If the FCC or FTC want to make rules, they should be monopoly busting rules. Let's have better roaming, for example, so our devices can readily and rapidly make use of the small cells. Most new phones have 802.11, so what about a system where any operator of a short-range access point can easily make it a picocell and sell service to the wireless company (now a wireless aggregator) at negotiated or auctioned rates. Most wifi hotspots would be happy to do this at very low rates (they often do it free right now) that can easily be bundled with any plan. A hotspot that wants to charge extra might only get premium customers.
&lt;/p&gt;
&lt;p&gt;
A good roaming system helps enable the ethic I think is right for spectrum sharing&amp;#8212;"&lt;a href="/replacing-fcc-dont-be-spectrum-selfish"&gt;don't be selfish&lt;/a&gt;." Under this regime you are required to use only as much power and spectrum as you need, and if you're inside a building and there is a nice 100 megabit in-room 5ghz wireless, you should not be broadcasting to everybody for a mile around at 850mhz. Doing so is wasteful and doesn't make sense. If the FCC needs to do anything, it should slightly tweak things to encourage such good behaviour.
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/619/"&gt;Brad Templeton&lt;/a&gt;, Electronic Frontier Foundation (EFF) Boardmember, Entrepreneur and Technologist&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/broadband"&gt;Broadband&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/mobile"&gt;Mobile&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/net_neutrality"&gt;Net Neutrality&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/policy_regulation"&gt;Policy &amp; Regulation&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/telecom"&gt;Telecom&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/wireless"&gt;Wireless&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=uXEN4pRDGw4:R_U3e0Q3IKw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=uXEN4pRDGw4:R_U3e0Q3IKw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=uXEN4pRDGw4:R_U3e0Q3IKw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=uXEN4pRDGw4:R_U3e0Q3IKw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=uXEN4pRDGw4:R_U3e0Q3IKw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=uXEN4pRDGw4:R_U3e0Q3IKw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=uXEN4pRDGw4:R_U3e0Q3IKw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=uXEN4pRDGw4:R_U3e0Q3IKw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=uXEN4pRDGw4:R_U3e0Q3IKw:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>Verizon: Advent of 4G LTE, WiMAX-Based Devices Will Only Increase the Need for IPv6</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/verizon_advent_of_4g_lte_wimax_based_devices_ipv6/" />
		<id>tag:circleid.com,2010:news/6.4932</id>
		<updated>2010-08-25T10:30:00-08:00</updated>
		<author><name>CircleID Reporter</name></author>
		<category term="broadband" scheme="http://www.circleid.com/topics/broadband/" label="Broadband" /><category term="ip_addressing" scheme="http://www.circleid.com/topics/ip_addressing/" label="IP Addressing" /><category term="ipv6" scheme="http://www.circleid.com/topics/ipv6/" label="IPv6" /><category term="mobile" scheme="http://www.circleid.com/topics/mobile/" label="Mobile" /><category term="wireless" scheme="http://www.circleid.com/topics/wireless/" label="Wireless" />
		<content type="html">&lt;p&gt;Verizon Business has a message to companies still reluctant to migrate their networks to IPv6: You're better off doing it now than later. William Schmidlapp, Verizon Business's product manager for Internet dedicated access services, says that the advent of 4G LTE and WiMAX-based devices will only increase the need to switch over to IPv6, since each of those devices will require its own IP address&amp;#8230;
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Read full story:&lt;/strong&gt; &lt;a href="http://www.networkworld.com/news/2010/082410-verizon-ipv6.html"&gt;Network World&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/broadband"&gt;Broadband&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/ip_addressing"&gt;IP Addressing&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/ipv6"&gt;IPv6&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/mobile"&gt;Mobile&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/wireless"&gt;Wireless&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=_5OvM4orr2Q:qXerbtegJKk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=_5OvM4orr2Q:qXerbtegJKk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=_5OvM4orr2Q:qXerbtegJKk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=_5OvM4orr2Q:qXerbtegJKk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=_5OvM4orr2Q:qXerbtegJKk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=_5OvM4orr2Q:qXerbtegJKk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=_5OvM4orr2Q:qXerbtegJKk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=_5OvM4orr2Q:qXerbtegJKk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=_5OvM4orr2Q:qXerbtegJKk:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>Russian Cybercrime is Organized / Russian Cybercrime is Not Organized</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/russian_cybercrime_is_organized_russian_cybercrime_is_not_organized/" />
		<id>tag:circleid.com,2010:blogs/1.4931</id>
		<updated>2010-08-25T10:23:00-08:00</updated>
		<author><name>Terry Zink</name></author>
		<category term="cyberattack" scheme="http://www.circleid.com/topics/cyberattack/" label="Cyberattack" /><category term="cybercrime" scheme="http://www.circleid.com/topics/cybercrime/" label="Cybercrime" /><category term="security" scheme="http://www.circleid.com/topics/security/" label="Security" />
		<content type="html">&lt;p&gt;I like to read other people's stories when it comes to spam, and I like &lt;a href="http://boxofmeat.net/"&gt;Box of Meat&lt;/a&gt;. It's always alerting me to interesting stories around the web that deals with cyber security. But the more I read, the more I see conflicting views on the state of the criminal cybercrime world. On the one hand, the Russian criminal cybercrime underworld is a scary, organized place where people are actively trying to do the rest of us harm. On the other hand, there is the position that &lt;em&gt;that&lt;/em&gt; position is an exaggeration of what it is actually like and that it's a bunch of ragtag folks who have some advanced computer skills but they are not formally organized. They trade amongst each other for the highest prices and exchange goods and services like the open market but they are not colluding with each other. I see this very similarly to how I see cyber warfare&amp;#8212;on the one hand there are the hawks who believe national cyber threats are behind every corner, and on the other hand there are the doves (for lack of a better word) who claim there is no national cyber threat, it's all about crime that has moved online.
&lt;/p&gt;
&lt;p&gt;
Consider excerpts from &lt;a href="http://www.nytimes.com/2010/08/24/business/global/24cyber.html?_r=4&amp;amp;ref=technology"&gt;this&lt;/a&gt; article from the New York Times:
&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;MOSCOW&amp;#8212;On the Internet, he was known as BadB, a disembodied criminal flitting from one server to another selling stolen credit card numbers despite being pursued by the United States Secret Service. And in real life, he was nearly as untouchable&amp;#8212;because he lived in Russia. BadB's real name is Vladislav A. Horohorin, according to a statement released last week by the United States Justice Department, and he was a resident of Moscow before his arrest by the police in France during a trip to that country earlier this month.
&lt;/p&gt;
&lt;p&gt;
...
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;The seizing of BadB provides a lens onto the shadowy world of Russian hackers, the often well-educated and sometimes darkly ingenious programmers who pose a recognized security threat to online commerce&amp;#8212;besides being global spam nuisances&amp;#8212;who often seem to operate with relative impunity.&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
Law enforcement groups in Russia have been reluctant to pursue these talented authors of Internet fraud, for reasons, security experts say, of incompetence, corruption or national pride. In this environment, &lt;strong&gt;BadB's network arose as "one of the most sophisticated organizations of online financial criminals in the world," according to a statement issued by Michael P. Merritt, the assistant director of investigations for the Secret Service, which pursues counterfeiting and some electronic financial fraud.&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
...
&lt;/p&gt;
&lt;p&gt;
According to the Secret Service statement, Mr. Horohorin managed Web sites for hackers who were able to steal large numbers of credit card numbers that were sold online anonymously around the globe. Those buyers would do the more dangerous work of running up fraudulent bills. The numbers were exchanged on Web sites called CarderPlanet carder.su and badb.biz&amp;#8212;according to the Secret Service, and payment was made indirectly through accounts at a Russian online settlement system known as Webmoney, an analogue to PayPal.
&lt;br /&gt;
...
&lt;br /&gt;
&lt;strong&gt;Computer security researchers have raised a more sinister prospect: that criminal spamming gangs have been co-opted by the intelligence agencies in Russia, which provide cover for their activities in exchange for the criminals' expertise or for allowing their networks of virus-infected computers to be used for political purposes&amp;#8212;to crash dissident Web sites, perhaps. &lt;/strong&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;
Reading this article, you would come away with the impression that these guys are very good at what they do&amp;#8212;they have extensive computer hacking and social engineering skills, are well educated not to mention being good at money laundering (or being affiliated with people who are good at it). We see terms such as 'sophisticated' being used to describe these people. They are a definitive threat and the odds of actually arresting them are small; when they are arrested, it is seen as the exception and not the norm. In any case, they are not a ragtag bunch of people but instead are well organized and intentional about their behavior.
&lt;/p&gt;
&lt;p&gt;
Worse yet, there are possible collusions between themselves and national intelligence agencies. This makes the general public even more concerned because the not-so-subtle implication is that not only do these people have extensive hacking skills, they could potentially use this to cripple national infrastructure if a hostile government, directed by an intelligence agency, instructed them to do so. The general public isn't entirely clear on what spy agencies do anyway, but in our cultures we are ingrained with the belief that they do some nasty stuff. Just imagine what they could do with a small army of hackers.
&lt;/p&gt;
&lt;p&gt;
However, contrast that article with excerpts from &lt;a href="http://www.eweek.com/c/a/Security/Inside-the-Russian-CyberUnderground-517933/"&gt;this&lt;/a&gt; one in eWeek:
&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;When people think of cyber-crime, the typical image being pushed today is that of highly organized criminal operations. New research, however, suggests the underbelly of cyber-space may be less mafia-like than some think. In an effort to improve the level of understanding of today's black hats, security researchers Fyodor Yarochkin and "The Grugq" have spent several months looking at Russian hacker forums.
&lt;/p&gt;
&lt;p&gt;
"It is an ongoing project that we started about 18 months ago," Grugq told eWEEK. "Originally it started when Fyodor investigated some service offerings from Russian hacker forums for a specific project that I was working on. It turned out to be extremely interesting and amusing, so we discussed doing more long-term monitoring on the forums. It grew from there into what is now a continuous monitoring program."
&lt;/p&gt;
&lt;p&gt;
Their research was presented last month at the Hack in the Box 2010 conference in Amsterdam. &lt;strong&gt;What the two found was that the image of a highly organized cyber-underworld run by hardcore criminals is not the order of the day. Instead, the dozen or so hacker forums they analyzed illustrated that many of the users are "geeks, not gangsters," the researchers said.&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
"Basically, from what we've seen on the forums much of what goes on with the sales of services is much more petty criminal activity, or crimes of opportunity," Grugq said. "Often poor students who like to hack for fun will sell access to a server they've owned. Many don't even realize that this is an illegal activity. This sale will be for $20 or $30, which is a lot of money for a poor student in Russia, but for a hardened criminal mastermind bent on destroying Western civilization&amp;#8212;not so much."
&lt;/p&gt;
&lt;p&gt;
...
&lt;/p&gt;
&lt;p&gt;
"In terms of percentage, there'd be two to three guys working on stuff professionally, versus 10 to 20 hobbyists," he continued&lt;strong&gt;. "Most of the activity is essentially petty criminal activity where guys are trying to make a little extra cash on the side.&lt;/strong&gt; You can think of it as a self-organizing hierarchical system with needs and people able to provide goods and services to satisfy the needs."
&lt;/p&gt;
&lt;p&gt;
...
&lt;/p&gt;
&lt;p&gt;
"From what we can guess," Grugq said, "any [mob] involvement is more along the lines of some people at the very top of the stack have to pay off the real gangsters. ... So, for example, if you are organizing a massive credit card cash-out scam which nets millions of dollars, you'll have to pay protection money to the mob to not get robbed. It doesn't look like the mob itself is organizing these cash-outs though.
&lt;/p&gt;
&lt;p&gt;
"We're not disputing that organized crime is involved with cyber-crime, but the popular conception of leather jacketed thugs running around with firearms and laptops is not in line with what we have observed from the actual communities," he said. "It seems like it is very useful for some companies to popularize the scary idea of Russian cyber-gangsters, but honestly the involvement seems to be much more hands off."&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;
This is quite a bit different than the perspective offered by the first article. Here, we still have perpetrators that are advanced hackers with strong computer skills. However, they are not organized amongst each other and view their craft like a bunch of frat boys. They boast amongst themselves. They argue amongst themselves. They don't even seem to realize that what they are doing is illegal. What makes the problem so widespread is that the cost of technology has dropped so much and Internet access has become so ubiquitous that they can do a lot of damage with limited human resources.
&lt;/p&gt;
&lt;p&gt;
A few weeks ago I wrote about how many hackers who get arrested are arrested because of their own hubris. They do not have their egos in check and therefore end up leading a cyber paper trail straight to their lairs. Their lack of life experience leads to carelessness, and when that occurs they get caught. It is more of a bunch of individual actors doing stuff, trading stuff, trying to make some money. This is hardly the portrait painted by the New York Times.
&lt;/p&gt;
&lt;p&gt;
So which portrait is correct?
&lt;/p&gt;
&lt;p&gt;
Well, to be sure, there are many hackers out there that are hobbyists, and they are the ones that get caught. But it certainly &lt;em&gt;seems&lt;/em&gt; like there are plenty of organized criminal groups out there (such as &lt;a href="http://en.wikipedia.org/wiki/Avalanche_(phishing_group)"&gt;Avalanche&lt;/a&gt;). A conspiracy is often a "nice" way to explain all that's wrong in the world, but most conspiracies rarely hold up to close examination (never attribute to malfeasance what you can simply attribute to incompetence).
&lt;/p&gt;
&lt;p&gt;
My theory is that this is a variant of the &lt;a href="http://en.wikipedia.org/wiki/Pareto_principle"&gt;Pareto principle&lt;/a&gt;. The Pareto principle, also called the 80/20 rule, states that 80% of the effects are from 20% of the causes. In a business, 80% of the revenue comes from 20% of the sales. 80% of the systems crashes are caused by 20% of the bugs. 80% of the movement on the stock market comes on 20% of the days (not sure if this one is true&amp;#8230; it sure feels like it).
&lt;/p&gt;
&lt;p&gt;
In the same way, 80% of the cybercrime is caused by 20% of the cyber criminals. The other 80% of the cyber criminals do some damage and are not so difficult to back trace. They are nuisances and commit online fraud but will always remain small potatoes. By contrast the good ones, the 20%, are very good at what they do. They are smaller and better and cause more damage, and get paid more. The reason they get paid more is because they are more skilled and have the full repertoire&amp;#8212;good computer skills &lt;em&gt;and&lt;/em&gt; good people management skills, that is, the ability to stay anonymous.
&lt;/p&gt;
&lt;p&gt;
People who are good at their craft usually make more money, and in order to stay alive in the criminal underworld (that is, without getting arrested), you need to be good. Not everyone is good at what they do (like the players on my favorite football team which explains their current 2-6 record). The ones who aren't that good browse forums and chat openly about stuff. They don't make too much money. The ones who are good are busy honing their craft, coming up with new ways to separate people from their money and they don't browse forums. They are spending their time getting better at what they do, not raising their profile.
&lt;/p&gt;
&lt;p&gt;
That's why the second article paints a picture of a disorganized structure of hackers. The hackers that they can examined fall into the 80% that just aren't the kingpins of the industry. That's why the first article paints a picture of doom and gloom, they are studying the elite group of hackers that are difficult to catch and more difficult still to profile.
&lt;/p&gt;
&lt;p&gt;
That's my theory.
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/2859/"&gt;Terry Zink&lt;/a&gt;, Program Manager&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/cyberattack"&gt;Cyberattack&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/cybercrime"&gt;Cybercrime&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/security"&gt;Security&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=vKMfmJBJoZY:lKLh0swx7Ko:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=vKMfmJBJoZY:lKLh0swx7Ko:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=vKMfmJBJoZY:lKLh0swx7Ko:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=vKMfmJBJoZY:lKLh0swx7Ko:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=vKMfmJBJoZY:lKLh0swx7Ko:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=vKMfmJBJoZY:lKLh0swx7Ko:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=vKMfmJBJoZY:lKLh0swx7Ko:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=vKMfmJBJoZY:lKLh0swx7Ko:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=vKMfmJBJoZY:lKLh0swx7Ko:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
	<entry>
		<title>IT Risks for Cloud Computing</title>
		<link rel="alternate" type="text/html" href="http://www.circleid.com/posts/it_risks_for_cloud_computing/" />
		<id>tag:circleid.com,2010:blogs/1.4929</id>
		<updated>2010-08-25T07:53:00-08:00</updated>
		<author><name>John Kane</name></author>
		<category term="cloud_computing" scheme="http://www.circleid.com/topics/cloud_computing/" label="Cloud Computing" /><category term="data_center" scheme="http://www.circleid.com/topics/data_center/" label="Data Center" /><category term="dns" scheme="http://www.circleid.com/topics/dns/" label="DNS" /><category term="security" scheme="http://www.circleid.com/topics/security/" label="Security" />
		<content type="html">&lt;p&gt;As the industry-wide paradigm shift to cloud computing and software-as-a-service gradually continues to make the transition from buzz to reality, security and availability continue to emerge as the main barriers to customer adoption. &lt;a href="http://news.cnet.com/8301-1001_3-20001921-92.html"&gt;A recent ISACA survey&lt;/a&gt; of over 1,800 US IT professionals found that only 17 percent believe the benefits of cloud computing outweigh the risks. Only one in 10 respondents said they would consider using software-as-a-service (SaaS) for mission-critical applications.
&lt;/p&gt;
&lt;p&gt;
While some of this hesitance can probably be attributed to an overabundance of caution and the general human tendency to be wary of change, some security concerns are well-founded.
&lt;/p&gt;
&lt;p&gt;
Companies entrusting their sensitive data to a SaaS provider need to be reassured that the data cannot be accessed by unauthorized third parties, such as employees and other customers of the provider, whether at rest or in transit. Data leakage has always been a potential issue at the low end of the hosting market&amp;#8212;budget customers on shared servers&amp;#8212;but the co-tenancy sometimes involved in cloud computing carries the perceived risk of bringing the problem to enterprises. SaaS providers need to be open and transparent with their customers about their security precautions, such as their encryption and access control regimes, as well as their layers of physical security.
&lt;/p&gt;
&lt;p&gt;
There are other concerns, such as distributed denial-of-service attacks. As DNS service providers and others can attest to, when you have many thousands, or millions, of customer accounts running on the same infrastructure, you increase the risk of that infrastructure becoming the target of an attack. It's the old all-your-eggs-in-one-basket problem. To a DDoS-attacker focused on extortion, political retribution or simple vandalism, a broad customer base looks more like a convenient, aggregated attack surface. They can channel their resources on a narrower choke point, getting their message across by attempting to cause maximum collateral damage.
&lt;/p&gt;
&lt;p&gt;
Of course, the opposite case can also be made: securing systems can be an expensive proposition, and companies can actually benefit from the substantial economies of scale that SaaS providers offer in terms of cost and security. Benefits include the availability improvements brought about by consolidated patch management, the economics enabling a much more diverse technology base that is less vulnerable to exploits, and the ability to quickly respond to DDoS attacks by reallocating resources.
&lt;/p&gt;
&lt;p&gt;
It's important that both SaaS providers and their customers do not overlook reliable DNS provision as a key component of their overall security strategy. Companies can often blow their budgets on a super-redundant hosting infrastructure and forget about DNS&amp;#8212;the only way their customers can actually reach it. Far too many times DNS is allowed to become the weak link in the chain, making it an ideal target for would-be attackers. All DNS services must come with a Service Level Agreement (SLA). Accepting anything less than 100% up-time for that SLA means you are accepting downtime for your business.
&lt;/p&gt;
&lt;p&gt;
SaaS customers, however, often forget about DNS. Signing up for Google Apps, for example, is fairly straightforward and free, so it's easy to be quickly lured into a false sense of security, believing that your critical applications now reside on one of the world's largest and most robust data centers. This is of course not completely true. While cloud services such as Google Apps have brought many efficiencies to enterprises, they usually do not natively support DNS resolution. If you've forgotten to effectively provision your DNS, and it goes down, so does your Google Apps.
&lt;/p&gt;
&lt;p&gt;
For a SaaS provider, surveys showing customer reluctance to adopt your services should of course be of some concern. But this hesitance also provides cloud computing companies with excellent opportunities to differentiate their services. When customers make buying decisions with security and availability as their primary concern, there's a clear incentive for SaaS companies to compete on security&amp;#8212;a rising tide that carries all boats with it.
&lt;/p&gt;&lt;p&gt;&lt;em&gt;Written by &lt;a href="http://www.circleid.com/members/4833/"&gt;John Kane&lt;/a&gt;, Vice President of Corporate Services, Afilias&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Follow CircleID on &lt;a href="http://twitter.com/circleid"&gt;Twitter&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More under:&lt;/strong&gt; &lt;a href="http://www.circleid.com/topics/cloud_computing"&gt;Cloud Computing&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/data_center"&gt;Data Center&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/dns"&gt;DNS&lt;/a&gt;, &lt;a href="http://www.circleid.com/topics/security"&gt;Security&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.circleid.com/~ff/cid_master?a=nlZ6hK5wGRI:2_mFVeACJcs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=nlZ6hK5wGRI:2_mFVeACJcs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=nlZ6hK5wGRI:2_mFVeACJcs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=nlZ6hK5wGRI:2_mFVeACJcs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=nlZ6hK5wGRI:2_mFVeACJcs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=nlZ6hK5wGRI:2_mFVeACJcs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=nlZ6hK5wGRI:2_mFVeACJcs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?i=nlZ6hK5wGRI:2_mFVeACJcs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.circleid.com/~ff/cid_master?a=nlZ6hK5wGRI:2_mFVeACJcs:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/cid_master?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>
	</entry>
	
</feed>
