Search

Loading

Newsletters



Sign up for technology and financial newsletters

Browse by Topic

March, 2006



FrontBridge was one of the top four hosted or "managed" email security services. Microsoft acquired FrontBridge in August 2005, yet the company has been reserved about its plans … until now.

In April, Microsoft will rebrand FrontBridge as "Exchange Hosted Services." It has just introduced version 5.3, which it claims is faster, more usable, has expanded network capacity, and adds support for speakers of Dutch, Portuguese (standard and Brazilian), Mandarin, and Korean.

The product structure and pricing model are now simplified, with a main license plus three options:

  • Archive — Keep a copy of all mail, either inbound, outbound, or internal. End-users have access to the archive via an OWA-like Web interface.
  • Continuity — Keep a rolling 30-day archive as above, permitting redelivery of messages in case of disaster.
  • Encryption — A licensed version of Voltage’s IBE system (Identity Based Encryption).

Expect a 6.0 release at the same time as the release of Exchange 12. This may include Exchange-specific features.

Richi Jennings, with thanks to Eron Kelly of Microsoft

Many email security products or services will warn you if they detect a virus in an incoming message. You’ll receive a Virus Alert message in your inbox that either includes the original plain text message with the attachment stripped out, or has just a simple notification that "so-and-so sent you a virus, and click here to read the message in the quarantine." The intention is that you can contact and notify the sender that there is a virus on his or her PC.

The problem is that these days, most virus-infected email is sent not by users, but by other viruses. It’s effectively spam, except the motivation is to take over your computer, not to sell you … things. The viruses will often use the same lists of recipients as spammers do. And there’s no point in contacting the "sender" of the message — it’s probably forged.

The upshot is that these virus alert messages are now just as bad as spam. Only a tiny proportion of them are of any use. Email security solutions should be more selective of which messages they warn about.

Richi Jennings, with thanks to Stephen Canale of OnlyMyEmail

This report details the problems that organizations face in maintaining a Microsoft Exchange solution, and the impact of downtime when Exchange is not available.

For further information, see here.

Note:

  • Subscribers to Ferris Research’s information service can download the report directly, from here. If you have forgotten your login and password, email gabriel.golden@ferris.com for help
  • Journalists interested in the report should contact david.ferris@ferris.com

If you have any questions, please email david.ferris@ferris.com or call him on +1 415 367 3436.

SASL (Simple Authentication and Security Layer) is an Internet standard that enables the Internet messaging protocols and LDAP (Lightweight Directory Access Protocol) to use a wide range of authentication mechanisms. Last week, an updated version was approved to replace RFC 2222.

SASL is an important, but less well known, member of the Internet messaging and directory protocol family. It is generally thought of as a way to use alternate authentication mechanisms, but there is another feature of SASL that is also important.

Many applications, and in particular custom Web applications, use LDAP as an authentication mechanism to verify the user name and password provided by the application. Working in this way is a very sensible approach for many organizations, as it allows a simple centralized authentication mechanism. This is achieved by the application binding to the directory as the user. As LDAP binds require use of the full directory name of the user, the application will generally first make an anonymous bind to the directory and then search the directory for the user name supplied by the application in order to determine the directory name needed for the second bind that does the actual authentication.

Use of SASL in conjunction with LDAP offers a much better solution. SASL enables use of authentication with the user name supplied by the application, and performs the mapping to the directory name on the server side. This has the advantage of avoiding anonymous — i.e., insecure — directory operations. It also has a big operational advantage, as the algorithm to map from user name to directory name is managed in one place (on the directory server) rather than needing to be maintained in every application that works in this manner.

Using SASL in this way is currently unusual, but will become increasingly common.

Steve Kille (editor: Richi Jennings)

SurfControl released an updated version of Enterprise Threat Shield, its Internet security solution. Adds capability to target and remove the Skype application when found on the company network as well as prevent its installation and use within a restricted company environment. Available immediately. More

To operate Skype, you need to have your PC turned on, and you probably talk via a connected headset.

That’s a pain if your PC isn’t on, or if your PC isn’t beside you, for example.

So a number of vendors are working on phones that have Skype embedded within them. An example is NETGEAR’s WiFi Phone. This looks like a cell phone, and connects over WiFi. Expect such products to become available late summer.

David Ferris, with thanks to ActionTec’s Gunjan Bhow


Download Files:
/?file_id=2006/03/1144_Today.htm

Proofpoint announced that the company has closed $20 million in financing from Bridgescale Partners, Benchmark Capital; Inventures Group, Meritech Capital Partners, Mohr, Davidow Ventures and RRE Ventures. More

No one wants to go through the hassle of having their mobile device lost, stolen, attacked by viruses, or harvested for confidential data. Fortunately, two security features now available on some devices provide additional protection:

  • A threshold of unsuccessful PIN/password attempts can be set. If exceeded, the device will automatically lock itself and erase local memory.
  • The organization’s help desk can send a specially formatted SMS command — a remote device wipe — which forces the device to automatically delete all information.

This functionality is quite beneficial unless the user merely misplaced the device — in which case it’s as useful as a pet rock. Users need to be aware of these issues — preferably before they need to call the help desk. Companies should add the security of mobile devices to their policies and inform both their new and existing users. Here are some of the issues that messaging managers should think about:

  • Which mobile devices and OS platforms are supported.
  • Mandatory use, complexity, and timeout of a PIN.
  • Thresholds for unsuccessful PIN entries.
  • Specific information that will be deleted.
  • Delay between issuing the wipe command and actual deletion.
  • Disabling SD cards that cannot be wiped.
  • Locking out the insertion of new SD cards.
  • Re-provisioning of the mobile device and user profile after a wipe.
  • Who is permitted to perform remote wipes and under what circumstances.

Nancy Cox (editor: Richi Jennings)

Sometimes, we make life very difficult for spam filters. I was reminded of this today when checking the quarantine for the mailbox that we use for our weblog.

Caught in the quarantine were several messages generated by the blog software, which warned us of some spammy activity — spammers abusing the blog’s comments and trackbacks facilities. Of course, the warning messages included the spammy text of the comments and trackbacks, which caused our spam filter to quarantine the warnings.

Naturally, a quick addition to the whitelist prevented the problem from happening again, but it’s food for thought.

Richi Jennings

Open Text announced an updated version of Livelink ECM Email Monitoring, its email management solution. Adds tools for capturing samples of inbound and outbound emails from daily messages, administering review processes and managing audits for regulators. More

The Teneros Application Continuity Appliance offers instant failover for Microsoft Exchange in a managed appliance that provides exceptionally high availability. This report summarizes the product and comments on its industry context.

For further information, see here. There is no charge for the report.

If you have any questions, please email david.ferris@ferris.com or call him on +1 415 367 3436.

The Teneros Application Continuity Appliance offers instant failover for Microsoft Exchange in a managed appliance that provides exceptionally high availability. This report summarizes the product and comments on its industry context.

For further information, see here. There is no charge for the report.

If you have any questions, please email david.ferris@ferris.com or call him on +1 415 367 3436.

On February 6, 2006, Ferris Research held a roundtable webinar on email archiving, with participants from two dozen large organizations, including Bank of America, Bristol-Myers Squibb, Deutsche Bank, Eli Lilly, F. Hoffmann-LaRoche, the U.S. General Services Administration, The Goldman Sachs Group, Lockheed Martin, Merrill Lynch, Siemens Business Services, Texas Instruments, Unilever, and The World Bank. This Ferris brief discusses the issues raised in that roundtable, focusing on project implementation and regulatory concerns.

For further information, see here.

Note:

  • Subscribers to Ferris Research’s information service can download the report directly, from here. If you have forgotten your login and password, email gabriel.golden@ferris.com for help
  • Journalists interested in the report should contact david.ferris@ferris.com

If you have any questions, please email david.ferris@ferris.com or call him on +1 415 367 3436.

If you are a subscriber to our Analyzer Information Service, please log in to view subscriber attachments.Webinar held March 22, 2006. One hour duration.
With thanks to our co-sponsors:

Increasing regulations, storage constraints and productivity concerns continue to raise the level of interest in email archiving among messaging managers. This [...]