Sunday, 23 February 2014

Hey Microsoft, where's the next Mac Office?

Microsoft's suite for OS X is overdue when compared to past development benchmarks

Where is the next Office for the Mac?

Microsoft is behind the schedule it used for the last several iterations, and has not breathed a word about its Mac intentions. In fact, the blog kept by the California-based development team that works on Office for Mac hasn't been updated since Aug. 5, 2013, more than seven months ago.

That's what those in the trade call stealth mode.
The last time Microsoft launched a new Office for OS X was October 2011, when it rolled out Office for Mac 2011. Prior to that, Microsoft issued upgrades in January 2008 (Office for Mac 2008), May 2004 (Office for Mac 2004) and November 2001 (Office v. X).

The average spread between Office for Mac editions -- going back as far as Office v. X -- has been 1,088 days. But as of Thursday, it had been 1,213 days since the launch of Office for Mac 2011.

Historically, Microsoft has hewn to a three-year development cycle for both Office on the Mac and the far-more-popular Office suite for Windows, with a new version of the former following the newest of the latter by several months at a minimum.

Office for Mac 2011, for instance, followed Office 2010 on Windows by 134 days, or just over four months. Office for Mac 2008, however, came 351 days, or nearly a year, after the debut of its Windows sibling, Office 2007. But even the longer lag time of the latter has now been exceeded: Office 2013 for Windows launched Jan. 29, 2013, 13 months ago.

The development team responsible for Office on the Mac, dubbed Macintosh Business Unit (MacBU), requires the lag time to incorporate changes that other engineering groups made to the Windows predecessor. The Windows and OS X Office development teams don't work in tandem, but in sequence, with Windows taking the lead and OS X following.

What odd is Microsoft's silence about the next Office for the Mac. The last cycle -- for Office for Mac 2011 -- the company was comparatively loquacious, announcing its intentions to craft the suite about 14 months before shipping the software, and it gave semi-regular updates on its MacBU blog.

News of the next Office for Mac? Nothing.
There's no chance that Microsoft will pull Office for the Mac from its portfolio: The company has touted Office 365, the rent-not-own subscription plans for both consumers and businesses, as providing up to five licenses for either Windows or OS X editions of the suites' desktop applications. To dump the Mac suite, even though its sales are Lilliputian in comparison to that for Windows, would be an embarrassment at least, and seen as a betrayal by those who committed to subscriptions rather than buy traditional "perpetual" licenses.

Still, Microsoft looks out over a different landscape than 40 months ago when it launched Office for Mac 2011.

Last fall, Apple set free its rival suite, iWork, giving away the three OS X applications of Pages, Numbers and Keynote to every new Mac buyer. In households -- but not businesses -- with multiple Macs, that effectively means all the machines can be equipped with iWork for free.

How Microsoft will deal with a free iWork is unknown. Currently, Microsoft charges $140 for the single-license Home & Student edition, $220 for a one-license copy of Home & Business, and $100 annually for an Office 365 subscription. Even that third option, with its five licenses, may seem pricy to Mac owners used to the free iWork and satisfied with its fewer features.

Also important is the ticking clock on Office for Mac 2011.
Microsoft supports Mac editions of Office for just five years, half the support lifecycle of the Windows' suite, and Office for Mac 2011's retirement date is not that far away: Jan. 12, 2016. Microsoft could extend support for Office for Mac 2011 -- it did that for Office for Mac 2004 -- but if it does not, it needs to provide a replacement soon to give customers time to migrate.

In the past, Microsoft has used the Macworld trade show and conference to demo its upcoming Office for Mac. This year, Macworld, now called "Macworld/iWorld," is slated to run March 27-29 in San Francisco. (The Macworld/iWorld conference is run by IDG, the parent company of Computerworld and its sister publication and website, Macworld.) However, Microsoft is not on this year's exhibitors' list for the trade show.

The next Office for Mac is already overdue by Microsoft's past practice of following the latest version for Windows within a year.



Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Tuesday, 18 February 2014

Microsoft sets Oct. 31 as stop date for Windows 7 consumer PC sales

But extends end-of-sales date for business PCs running Windows 7 ProfessionalMicrosoft has set Oct. 31 as the end of sales of new consumer-grade Windows 7 PCs, but for now has left open the do-not-sell-after-this-date for business machines.

On the site where it posts such policies, Microsoft now notes that Oct. 31, 2014, is the end-of-sales date for new PCs equipped with Windows 7 Home Basic, Home Premium or Ultimate. All three are consumer-oriented versions of Windows 7; Home Premium has been the overwhelming choice of OEMs (original equipment manufacturers) for consumer systems.

Microsoft's practice, first defined in 2010, is to stop selling an older operating system in retail one year after the launch of its successor, and halt delivery of the previous Windows edition to OEMs two years after a new version launches. The company shipped Windows 8, Windows 7's replacement, in October 2012.

The setting of a deadline for consumer Windows 7 PCs followed a glitch last year when Microsoft named the same Oct. 31 date for all Windows 7 PCs, but then quickly retracted the posting, claiming that the notification had been posted "in error."

Some OEMs, notably Hewlett-Packard, have made headlines for marketing consumer-grade Windows 7 PCs, a sign of the fragmentation of the once-dominant Windows oligarchy, which always pushed the newest at the expense of older editions.

But while it has established an end-of-sales date for consumer PCs with Windows 7 pre-installed, Microsoft has yet to do the same for business PCs.

Microsoft will give a one-year warning before it demands that OEMs stop selling PCs with Windows 7 Professional, the commercial-quality version. Under that rule, Microsoft will allow computer makers such as Lenovo, HP and Dell to continue selling PCs with Windows 7 Professional until at least February 2015.

It's likely that the extension will be much longer.

Windows 7 has become the standard version for businesses, which have spurned Windows 8, largely because of its two-user interface (UI) model, which they consider disruptive to productivity and a needless cost that would require employee retraining.

Most analysts believe that Windows 7 will remain the most popular Microsoft operating system deployed by companies for years to come.

"There's a good chance that enterprises will stay on Windows 7 as long as possible," said Gartner analyst Michael Silver in an October 2013 interview. If his prediction turns out to be accurate, Windows 7 may reprise the stubborn persistence of Windows XP, the nearly-13-year-old OS that Microsoft will retire in April.

Even after Windows 8's launch, Windows 7's user share, a rough measurement of the prevalence of the OS on operational machines, has continued to grow. From October 2012 to January 2014, Windows 7's user share increased nearly 3 percentage points, representing a 6% gain during that period, according to data from analytics company Net Applications.

Some of Windows 7's gains certainly came at the expense of Windows XP, which has fallen more than 11 percentage points, a 28% decline, since October 2012 as users abandoned the old OS.

By making Windows 7 available, Microsoft and its OEMs not only continue to serve customers who want the OS, but make sure that new PC sales do not slump even more dramatically than they have already.

Consumer PC sales have plummeted -- last month Microsoft said sales of consumer-grade Windows licenses fell 20% in the December quarter compared to the same period the year before -- while the Redmond, Wash. company's business line of operating systems grew 12% year-over-year. In effect, enterprise spending kept PC shipments from tanking even more than the 10% contraction the industry experienced in 2013.

Extending Windows 7 Professional's availability on new hardware will also give Microsoft breathing room to continue its retreat from Windows 8's radical shift to a touch-first, tile-based UI, and to roll out a successor that caters even more to customers who rely on keyboard and mouse.

Microsoft is expected to unveil an update to Windows 8.1 this spring, perhaps in April, that will restore several desktop-oriented features and tools. Some reports based on leaked builds of this Windows 8.1 Update 1 have noted that on non-touch devices, the boot-to-desktop option will be enabled by default; if accurate, most users of traditional PCs will skip the colorful, tile-style Start screen. Windows 9 may appear as early as April 2015.

Retail sales of Windows 7 by Microsoft to distributors and customers were officially halted as of Oct. 31, 2013, but that deadline has been meaningless, as online retailers have continued to sell packaged copies, sometimes for years, by restocking through distributors who squirreled away older editions.

As of Saturday, for example, Amazon.com had a plentiful supply of various versions of Windows 7 available, as did technology specialist Newegg.com. The former also listed copies of Windows Vista and even Windows XP for sale through partners.

Even after Microsoft pulls the plug on Windows 7, there will be ways to circumvent the shut-down. Windows 8.1 Pro, the more expensive of the two public editions, includes "downgrade" rights that allow PC owners to legally install an older OS. OEMs and system builders can also use downgrade rights to sell a Windows 8.1 Pro-licensed system, but factory-downgrade it to Windows 7 Professional before it ships.

And enterprises with volume license agreements will never be at risk of losing access to Windows 7, as they are granted downgrade rights as part of those agreements, and so will be able to purchase, say, Windows 8.1 or Windows 9 PCs in 2015 or 2016, then re-image the machines with Windows 7.

The end-of-sales dates for Windows 7 are not linked in any way to the support schedule for the 2009 operating system. Microsoft will provide free non-security bug fixes and vulnerability patches for Windows 7 until Jan. 13, 2015 -- called "mainstream support" -- and follow that with a five-year stretch of "extended support" during which it will ship free security updates until Jan. 14, 2020.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Monday, 3 February 2014

How to easily encrypt email with Virtru for free: Gmail, Hotmail, Outlook, Yahoo

How to easily encrypt email, Gmail, Hotmail, Outlook, Yahoo; Virtru is free, protects your digital privacy, and is so super easy to use that even your non-techie grandma could and should use it.

I believe privacy is a fundamental right, so what better way to celebrate Data Privacy Day than to show you how to encrypt email easily and keep those emails both private and secure?

Meet Virtru, an email security app that encrypts your email before it leaves your device; it includes fine-grained privacy controls so only you and the person to whom you sent the email can access it...meaning government snoops, third parties, advertisers, ISPs and even cybercrooks can't access your email messages. Thanks to Virtru's Chrome and Firefox browser extensions, you can keep your Gmail, Outlook or Yahoo email accounts and still have secure and private email. And you can protect your digital privacy for the low, low price of FREE! Virtru is so super easy to use that even your non-techie grandma could and should use it.

Before we jump to the how-to, let me introduce the founders of Virtru: brothers Will and John Ackerly. When Will worked at the NSA as a cloud security architect, he invented the Trusted Data Format (TDF) that Virtru, and intelligence agencies, use. "After serving eight years at the NSA, he came away from the experience entirely convinced that users need to take action to preserve their own privacy." John, who served as associate director of the National Economic Council and director of the Office of Policy and Strategic Planning at the Commerce Department under President George W. Bush, said of Virtru, "The fundamental motivator here is...the need to give individuals practical tools to exercise their fundamental right to privacy."

How to encrypt email with Virtru
For webmail, Virtru currently offers a Chrome extension and Firefox add-on to encrypt Gmail, Outlook, Hotmail or Yahoo. There's also a mobile app for Apple, with the Android app, as well as plugins for Outlook and Mac Mail programs, and extensions for Internet Explorer versions 10 and up, and Safari coming in the future. Although I've tested both Chrome and Firefox add-ons for Gmail, Hotmail and Yahoo, the following examples are primarily screenshot captures from Gmail and Hotmail. Email addresses have been redacted.

First, go get the add-on for Firefox and/or Chrome. After it is installed in your browser, simply click to activate Virtru for your webmail.

Virtru app permissions in Outlook:

Virtru app permissions in Outlook

Virtru in Outlook first look:

Virtru in Outlook first look

Virtru activate message if you send encrypted Gmail to a person not using Virtru:

Virtru activate message if you send Gmail to person not using Virtru

Virtru security bar

Virtru security bar new in Hotmail, Gmail, Outlook, YahooYou will then receive a message notifying you about the Virtru security bar.

You can easily turn Virtru on and off. If it's grayed-out, then it's off. It's blue when you turn on Virtru protection.

Easily turn Virtru security bar off and on

When Virtru is on in Outlook, Hotmail, Gmail or Yahoo, your "send" button Example of Virtru send secure buttonbecomes a "send secure" button as seen in this Outlook example.

Drafts on Yahoo are not encrypted by Virtru

As a side note of caution regarding the cloud, if you use Yahoo, then know that Yahoo drafts are not currently encrypted by Virtru. Try to avoid such drafts; it's fodder for the mass surveillance powers-that-be if you've become a target.

Every email protected by Virtru is secured with the most Advanced Encryption Standard available, AES-256. The Virtru software, either installed via browser add-on or mobile app, encrypts your email before it leaves your device. When you hit send, Virtru protects the encryption keys with perfect forward secrecy. Only you and the person to whom you sent the email can access the content.

The TDF format controls access privileges for "all file types (ie, emails, text messages, Office files, pdfs, photos, videos)." When you send a Virtru-protected email, "your content is encrypted and secured inside a TDF wrapper. When your receiver attempts to open it, the wrapper communicates with the Virtru server to verify that the receiver is eligible to see the information."

When you have installed Virtru and you receive an encrypted email, the decryption happens quickly when you open it.

Virtru decrypting email

Disable forwarding and set email expiration date

On the right-side of the Virtru security bar, you have options to disable email forwarding and to set up an expiration date for how long your recipient has access to your sent email.

Virtru disable email forwarding; set email expiration time

If you disable email forwarding, then if Alice sent email to Bob, and Bob forwarded Alice's email to Mallory, Mallory would not be able to open it. Regarding The Register's claim that a person can defeat Virtru by copying and pasting from the email, the fix for that is coming.

"On the copy/paste front, we have a technical solution, but we haven't yet rolled it out," Will told me. "Our main focus is on protecting the emails as they go from sender to recipient, as well as when stored on servers and your devices, but use after decryption isn't our first 'privacy' concern."

Revoke or reauthorize email messages
Virtru "thinks everyone deserves real privacy and control over their data, even after hitting the send button," so sent email comes with an option to revoke access.The red hand icon allows you to revoke email; this is especially handy if you sent an unwise, angry email in haste.

Virtru revoke message

Below is what the recipient sees if you revoke access to a sent email:

Virtru revoked access message

Virtru, reauthorize revoked email

If you change your mind again, such as if the revoke access was due to a lover's spat, then you click on the blue eye to reauthorize your recipient's access to your sent email.

Virtru Secure Reader

If you want to send Virtru encrypted email to a person at work, who maybe does not have the admin rights to install browser add-ons, no problem. Virtru also has a web-based Secure Reader.

Virtru redirects to you have secure mail via browser add-on or install nothing and use web-based reader

When you send your first email to a person not using Virtru, if they choose the Virtru Secure Reader option, then they will be asked to verify their identity; this insures that only the recipient you intended can open the email. By using OpenID and OAuth protocols, the recipient does not need to setup a new account or yet another password. Instead, they can verify their identity via their existing Gmail, Microsoft or Yahoo email provider.

Virtru Secure Reader, verify your identity to use service where you received secure Virtru email

If your recipient forwards an email that you protected with "disable forwarding," this is what the non-authorized person sees via Virtru Secure Reader.

Virtru secure reader, attempt to read forwarded email protected by disabled forwarding

Virtru wanted to make encryption easy for absolutely everyone to use without sacrificing security; the creators believe in your fundamental right to have digital privacy and provided a tool that combines strong encryption with granular privacy controls. They claim Virtru will change the way we use email, and it surely could. The purpose of all these screenshots was to show you every aspect of how easy it is to use Virtru.

For people who would like more in-depth details of how Virtru works, then I encourage you to go read more. Virtru also has an open source strategy, which includes making a collection of open source Virtru components available on GitHub.

Although it's only in beta right now, I still highly recommend that you try Virtru. There is no reason Virtru should not be widely accepted by the masses to escape mass surveillance. Please do give it a try. Happy International Data Privacy Day! Why don't you celebrate by taking back control of your email and digital privacy?


Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Monday, 20 January 2014

Skype’s Impressive Growth, Sonus Updates SBC Portfolio

Skype Traffic Grew 36% in 2013

Market research firm TeleGeography reports that Skype’s international traffic volume continues to grow significantly. TeleGeography estimates that Skype’s on-net (Skype to Skype) international traffic grew 36% in 2013, to 214 billion minutes. By comparison, International telephone traffic from fixed and mobile phones continues increasing by 7 % in 2013, to 547 billion minutes. While international PSTN traffic still carries most international traffic, Skype’s minutes are growing more rapidly: in 2013, Skype added 50 percent more than the combined international growth of every telco in the world.

Commenting in a statement on the trend, TeleGeography analyst Stephan Beckert said, “The rapid spread of OTT services is making life ever more challenging for international service providers, but the PSTN will not disappear anytime soon. No other network comes close to matching the global reach of the PSTN. While Facebook has approximately 1.2 billion monthly users, at year-end 2013, the PSTN connected to just over 8 billion fixed and mobile subscribers worldwide.”

In other news, Sonus has introduced new software enhancements to the Sonus SBC 1000 and SBC 2000 Session Border Controllers. Release 3.1 is designed to improve Microsoft Lync Enterprise Voice environments and more easily manage and scale enterprise Unified Communications (UC) networks. The upgrades by Sonus enable media quality monitoring for the entire Lync call, including the SIP trunk portion, providing information about delay, jitter and packet loss so network engineers to proactively monitor and troubleshoot call quality of experience issues for the entire session. With its latest upgrade, Sonus can also dynamically monitor available bandwidth over the back-up link and direct calls over either the public switched telephone network (PSTN) or, depending on bandwidth availability, a 3G/4G, digital subscriber line (DSL) or other alternate connection.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Tuesday, 14 January 2014

How to rescue your PC from ransomware

Don't negotiate with e-terrorists. Be a hero and rescue your hostage PC.

With the nasty CryptoLocker malware making the rounds--encrypting its victims' files, and then refusing to provide the unlock key unless a payment of $300 is made via Bitcoin or a prepaid cash voucher--ransomware is back in the spotlight.

You can remove many ransomware viruses without losing your files, but with some variants that isn't the case. In the past I've discussed general steps for removing malware and viruses, but you need to apply some specific tips and tricks for ransomware.A The process varies and depends on the type of invader. Some procedures involve a simple virus scan, while others require offline scans and advanced recovery of your files. I categorize ransomware into three varieties: scareware, lock-screen viruses, and the really nasty stuff.

+ ALSO ON NETWORK WORLD What to do if ransomware takes over your PC +

Scareware

The simplest type of ransomware, aka scareware, consists of bogus antivirus or clean-up tools that claim they've detected umpteen issues, and demand that you pay in order to fix them. Some specimens of this variety of ransomware may allow you to use your PC but bombard you with alerts and pop-ups, while others might prevent you from running any programs at all. Typically these invaders are the easiest type of ransomware to remove.

Lock-screen viruses

Next is the ransomware variety I call lock-screen viruses, which don't allow you to use your PC in any way. They display a full-size window after Windows starts up--usually with an FBI or Department of Justice logo--saying that you violated the law and that you must pay a fine.

The really nasty stuff

Encrypting malware--such as CryptoLocker--is the worst variant, because it encrypts and locks your personal files until you pay up. But even if you haven't backed up your files, you may have a chance to recover your data.

Removing ransomware

Before you can free your hostage PC, you have to eliminate the hostage taker.

If you have the simplest kind of ransomware, such as a fake antivirus program or a bogus clean-up tool, you can usually remove it by following the steps in my previous malware removal guide. This procedure includes entering Windows' Safe Mode and running an on-demand virus scanner such as Malwarebytes.

If the ransomware prevents you from entering Windows or running programs, as lock-screen viruses typically do, you can try to use System Restore to roll Windows back in time. Doing so doesn't affect your personal files, but it does return system files and programs to the state they were in at a certain time. The System Restore feature must be enabled beforehand; Windows enables it by default.

To try System Restore, shut down your PC and locate the F8 key on your PC's keyboard. Turn the PC on, and as soon as you see anything on the screen, press the F8 key repeatedly. This action should bring up the Advanced Boot Options menu; there, select Repair Your Computer and press Enter. Next you'll likely have to log on as a user; select your Windows account name. (If you don't have a password set, leave that blank.) Once logged on, you'll find shortcuts to a few tools; click SystemRestore.

If you don't see the Repair Your Computer option on the Advanced Boot Options menu, you can use your Windows disc (if you have that) to access the recovery tools. Click Repair your computer on the main menu before proceeding with the installation. Alternatively, you can create a Windows System Repair Disc on another PC running the same Windows version, and then boot to that disc on the infected PC to reach the same recovery tools.

If System Restore doesn't help and you still can't get into Windows to remove the ransomware, try running a virus scanner from a bootable disc or USB drive; some people refer to this approach as an offline virus scan. My favorite bootable scanner is fromA Bitdefender, but more are available:A Avast, AVG, Avira, Kaspersky, Norton, and Sophos all offer antivirus boot-disk software, as we mentioned in PCWorld's recent roundup of the best boot-drive programs.

If you still have no luck after trying Safe Mode and an on-demand scanner, performing a System Restore, and running an offline virus scanner, your last resort is likely to perform a factory restore. Most ransomware isn't that tenacious, however.

Recovering hidden and encrypted files

With that out of the way, it's time to repair the damage. If you're lucky, your PC was infected by malware that didn't encrypt your data, but merely hid your icons, shortcuts, and files.

You can easily show hidden files: Open Computer, press the Alt key, select Tools, and click Folder Options. On the View tab, select Show hidden files, folders, and drives, and then click OK.

If your data reappears after you elect to show hidden files, that's great--it means there's an easy fix for your woes. Open Computer, navigate to C:\Users\, and open the folder of your Windows account name. Then right-click each folder that's hidden, open Properties, uncheck the Hidden attribute, and click OK.A Boom! Done.

If you still can't find your data, and your files really have been malware-encrypted, you're in trouble: Usually it isn't possible to just decrypt or unlock your hostage files, because the decryption key is typically stored on the cybercriminal's server. Some victimized users have reported that some pieces of malware will keep their promise, decrypting and returning your files once you pay (in particular, CryptoLocker's handlers have been diligent about releasing the files of infected users who pay the ransom demand), but I don't recommend paying.A

This is why we constantly tell you to back up your PC on a regular basis.

If you previously set and created backups, scan them for viruses on another PC (one that is not infected) if at all possible. If all of your important files are backed up, you can proceed in removing the malware and then simply restoring your backed-up files.

If you don't have a backup system in place, you might be able to recover some files from Shadow Volume Copies--if the malware hasn't deleted them. Shadow Volume Copies is part of Windows' System Restore feature. Either right-click Select files/folders and open Properties to view the Previous Versions list, or use a program called Shadow Explorer to browse the snapshots.

But don't rely on that. Start backing up your PC today, and do it regularly.

Preventing ransomware and malware infections

Avoiding ransomware is much the same as avoiding other types of other malware.

Always run a good antivirus utility and keep Windows and browser-related components (Java, Adobe, and the like) updated. Keep your browser clean to prevent adware invasions that could lead to malware infections. Always, always be wary of unexpected email attachments and spam. (CryptoLocker spreads via .zip files sent as email attachments, for example.)

And just to beat this dead horse one more time: Always have a good backup system in place, just in case your PC does become infected and you can't recover your files. Yes, it's that important.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Thursday, 9 January 2014

Triple hop issue with ASP.NET delegation Part I: Our Windows XP Pro desktops

Last Friday we had an issue in production: we have a very simple web application with one single page on our intranet that consumes an array of web services. These web services talk to a back end SQL Server.

All in all this is a very typical scenario and like most companies with .NET technology we have web applications using ASP.Delegation in the intranet, the only particular point regarding this web page is that it is called inside an old legacy windows application (not a .NET app). For remote users, this old legacy application is used via Terminal Services.

For our remote users also, the application didn’t work and our DBA was registering a bunch of anonymous requests coming from the web server box…

On the other hand we set up our web services tracing to debug and were able to see the end user credentials on each HTTP request, so the end user had managed to authenticate using Integrated Windows Security on our web box and the web service trying to open a SQL connection to the back end.

We used impersonation and Integrated Windows Authentication on our web application and web services (this is an intranet after all). ASP.NET impersonation gave us the chance to restrict the access on the back end based on AD groups and at the same time gave us the ability to audit the user’s actions to a very fine grained degree (user name).

The PROBLEM with our Windows XP Pro desktop users

The application worked for our desktop users if and only if they had logged off and on their desktops in the past 48 hours. If the desktops users hadn’t logged on for a while, like me, that I lock my computer instead of logging myself off, the application didn’t work either and the sql box passed an anonymous login attempt back to our web tier. The web services then passed a SOAP Exception with the NT Service/Anounymous user error message to our web app…

System.Web.Services.Protocols.SoapException: Server was unable to process request. —> System.Data.SqlClient.SqlException: Login failed for user ‘NT AUTHORITY\ANONYMOUS LOGON’.

At first we thought it was the same problem, but it turns out the TS users couldn’t use the application even when they logged of and back on, not even when the TS server was restarted, hrm….

By dividing and conquering we applied the kerbtray.exe tool on our web server and one of the desktops and enabled Kerberos logging on both boxes. We noticed that when the application worked the user logged in the web server box used Kerberos, but after a few days the logging defaulted to NTML.

SOLUTION for the Windows XP Pro Desktops
It turns out this was a bug in the kerberos.dll running on Windows XP SP2, SP3 has this problem solved. More information can be found on this MSDN thread. Also the hotfix for Windows XP Professional SP2 can be found on this Microsoft Knowledge Base article. Although this article describes a different problem the hotfix provided here contains the fixed kerberos dll.

There are quite a bit of articles regarding ASP.NET delegation

And quite a few MSDN forum threads, like this one I initiated and has a heated discussion with the moderator, my fault most of it.

The best resources I have found so far, and I hope this digested summary will help you if you have the same double/triple hop issue, are:

Ken Schaefer’s blog post regarding IIS and Kerberos Part 5 – Protocol Transition, Constrained Delegation, S4U2S and S4U2P.

Keith Brown’s article on MSDN: Credentials and Delegation
and
nunos’s Blog: Concerning the credentials double hop issue

and the best of all is a webcast by Yung Chou *all kudos to his explanation of Protocol Transition*

MSDN Webcast: Getting Delegation to Work with IIS and ASP.NET:
The Ins and Outs of Protocol Transition (Part 1 of 2) (Level 300)

This webcast specifically helped us troubleshooting and fixing the second part of our problem, our failed connection when the end users connected remotely via terminal servers.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Saturday, 4 January 2014

Data scientists: IT's new rock stars

Data scientists: IT's new rock stars
These days, just showing up to work as a data scientist will get you attention.

The evolution of the data scientist role is making even those who are successful in IT wish they could go back.

In an interview with Network World last month, Robert Stroud, a member of ISACA’s Strategic Advisory council and vice president of innovation and strategy at CA Technologies, called the data scientist a “hard sought-after role” and compelled those entering the technology job market target that field.

"If I were starting my career again, I’d be going into this space," Stroud says.

The hype for data scientists was given some weight in American Journalism Review’s recent profile of Buzzfeed’s director of data science, Ky Harlin. Buzzfeed's growth has been massive in the past few years, reaching an average of 55.2 million uniquely visitors, according to September 2013 numbers from Quantcast. That's more than Craigslist and AOL, and within reach of Yahoo and Amazon.com. Essentially, Buzzfeed has made a business out of viral content, and Harlin is responsible for sustaining that.

RELATED: What it takes to be a data scientist

Who's hiring data scientists?
image alt text

According to the AJR profile, Harlin created his own algorithms that identify when and why specific pieces of web content will go viral.

"There are many variables we look at, both quantitative and descriptive,” Harlin told AJR. “Quantitative factors are things like the amount of times something’s been shared on Facebook, while descriptive factors are things like what’s contained in the text of the article. We employ machine learning algorithms that help us map out the relationship between those variables and shareability."

What's more interesting is where Harlin developed those skills – a medical imaging company. According to AJR, Buzzfeed's founder and CEO Jonah Peretti sought out Harlin while he was working in the medical imaging field, and brought him in for an interview about what data science could do for his media company. In the interview, Peretti found just how versatile data science skills can be.

"There are actually a lot of similarities between medical imaging and content publishing on a purely mathematical level," Peretti told AJR. "Both fields are looking for patterns in vast data sets. And during the interview, [Harlin] was clearly more interesting in understanding how content spreads than medical imaging, so I knew he would be good."

The rest of the details on Harlin's role and how he became the company's "secret weapon," as AJR described him, are available in that article, which is an interesting peak behind the curtains at the fastest-growing media company in the world.

However, the mere fact that a technology employee would be the center of a lengthy profile in the American Journalism Review should be an eye-opener. The kind of attention it’s been gathering has sent experts in the field out to start spread the word. In a June 2012 interview with Network World, Laura Kelley, Houston vice president for IT staffing and consulting firm Modis, advised those with MBAs to seek out certifications for statistical software programs, and those with computer science degrees to pursue an MBA. Facebook and Google have both been looking to bring on data scientists for years. In October 2012, the Harvard Business Review called data scientist “the sexiest job of the 21st century.” Data scientists like Harlin can go from work in the medical imaging field to a high-profile job at a media startup, and even though, like most tech workers, his day-to-day job rarely changes, they'll get press coverage. It seems the Harvard Business Review was right.

It all makes sense. Data scientists represent the new age of IT, where employees will not only contribute to a company’s business goals, but help identify them in the first place.

"This is where you add real business value," he says. "Where an IT person is not just running machines anymore, but fundamentally taking good information and helping the business make true business decisions so that they can adjust the business in real time based on this information. If used well, you’ll be able to spot trends and opportunities far faster than you could in the past."

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com