IBM, Novell join forces

At the opening of the LinuxWorld/Next Generation Data Center trade show in San Francisco, IBM and Novell announced a new agreement to join forces to capture a larger piece of the growing open source application server market. Under the agreement, Novell will deliver and support WebSphere Application Server Community Edition as part of SUSE Linux Enterprise Server, making it the industry’s most comprehensive open source-based server offering.

The agreement comes on the heels of the one millionth distribution of WAS CE, IBM’s open source-based application server, which is based on Apache Geronimo and free to download and use. IBM and Novell will offer support and migration tools to help customers using JBoss to quickly and easily move to WAS CE. Combining WAS CE with SUSE Linux Enterprise Server from Novell provides an unbeatable combination for the small and medium-size business market, where Novell excels, and a compelling offering for enterprise customers with distributed computing environments, specifically in the retail and financial services industries. IBM and Novell will team on joint marketing and sales campaigns targeting customers around the world.

Posted on: August 7, 2007 9:00 am

PistolStar enables Domino SSO

PistolStar, an authority in password management integrating Microsoft Active Directory, has introduced the Password Power Plug-In for Lotus Domino Single Sign-On via Kerberos, the latest addition to PistolStar’s framework of plug-ins for optimizing authentication to multiple enterprise applications.

The Plug-In for Lotus Domino Single Sign-On via Kerberos allows users connecting to Domino to achieve single sign-on to all Domino HTTP servers using the Kerberos network authentication protocol to Active Directory, which uses secret-key cryptography. Administrators remove the need to manage separate passwords for their Domino HTTP servers and enhance overall password security. No passwords are sent over the network and the end-user and server are mutually authenticated, preventing server attacks and malicious programs that try to impersonate the server to get the user’s private information.

Posted on: August 7, 2007 9:00 am

Mozilla vows to patch flaws

A Mozilla executive has vowed that his company can patch any critical vulnerability in its software within 10 days, a sign that Mozilla may intend to step up its efforts to improve security.

Mozilla executive Mike Shaver backed up his claim by scrawling it on a business card at the Black Hat security conference in Las Vegas and handing it to Robert Hansen, CEO of SecTheory.com, who also runs the ha.ckers.org Web site. Hansen posted a photo of Shaver’s business card, including the claim "Ten [expletive] days."

Posted on: August 7, 2007 9:00 am

Blade does data integration

For years IBM has doggedly pursued the massive problem of pulling data strewn across the enterprise into an integrated, harmonious whole. At LinuxWorld, the company introduced IBM Information Server Blade, an appliance-like bundle intended to make the Herculean task of enterprise data integration faster and easier.

IBM Information Server Blade includes an IBM BladeCenter HS21 with Dual-Core Intel Xeon processors running Red Hat Linux, on top of which sits Information Server–a suite of data cleansing, information management, and data profiling tools built around a metadata repository. With the aid of IBM Workload Manager, the blade setup is configured as a grid, which IBM says is ideal for data integration tasks.

Posted on: August 7, 2007 9:00 am

Immunity exploit tool

Immunity, a company already well-known for making pen testing easy, has released a new tool to make writing exploits near-automatic.

Immunity released the tool, called Debugger, at the Defcon hackers convention. Debugger is free for download, with its revenue being driven by paid ads from companies looking to hire the pen testers who use such a tool. One of the first help-wanted ads taken out by such companies includes Application Security.

Posted on: August 6, 2007 9:00 am

Interns face fierce competition

IBM internships: If there is one word that could be used to sum up summer internships at IBM, it would be "competitive." For some, this is a dream-come-true, for others it is just draining. Just ask Kenneth Bratland, a three-time IBM intern.

"When working at [my second IBM internship] there was a little bit more competition amongst interns. This may have been at least partially because it was a more high-profile summer internship at a leading industrial research lab. I was also there among a larger group of students, many of whom were interested in the possibility of full-time employment with IBM after graduation," said Bratland.

Posted on: August 6, 2007 9:00 am

Lenovo to offer Linux on laptops

Lenovo, one of the world’s biggest PC manufacturers, is to start selling laptops to business and consumers with Linux pre-installed on the machines.

Linux is a free, open source operating system developed as an alternative to systems such as Microsoft’s Windows. Novell will provide the Linux software on the laptops, which are due to go on sale at the end of the year.

Posted on: August 6, 2007 9:00 am

A field guide to office politicos

Every workplace has its share of good guys and bad, solo artists and team players. To get ahead–or even just survive–you need to know them all: the good eggs who can become your allies, and the bad apples to avoid (or occasionally placate). Here’s a handy guide to the 10 most common types of office politicians, with tips on how to manage them.

Posted on: August 6, 2007 9:00 am

A field guide to bosses

The office is a jungle. That’s why intrepid employees need a field guide to help them spot and identify the most powerful creature in the workplace: the boss. Here are ten common examples of the species, along with care and feeding tips should you encounter a manager in the wild. [Ed.–With the exception of "Our Hero," I’ve worked for just about every one of these types.]

Posted on: August 6, 2007 9:00 am

Pay up, or feel the pain

An upstart security research firm with a controversial business model is at the center of a debate over how software bugs should be disclosed. Vulnerability Discovery and Analysis Labs, founded in April by Jared DeMott, notifies software vendors of security bugs found in their software, as do many other security researchers. But as part of VDA’s business model, vendors are asked to pay for the bugs it discovers, or its consulting services, otherwise VDA threatens to sell the bug to a third party or make the details of the security flaw public.

DeMott, who has done work for the National Security Agency among other places, describes his business model as "edgy," while other security researchers see it as more akin to "extortion." The practice, in either case, veers from the more traditional ways bug hunters have worked with software vendors and security firms.

Posted on: August 6, 2007 9:00 am