Oracle may have accumulated a vast array of products, but it has also added value and tightly integrated them, executives said during a keynote address Monday at the OpenWorld conference in San Francisco. One demo showed how Oracle has tied the Primavera project planning products it acquired last year back to its ERP (enterprise resource planning) software. Through a series of demonstrations, Oracle officials seemed intent on answering critics who say the vendor's acquisition spree has resulted in a Frankenstein monster-like mish-mash of components.

Primavera business unit head Joel Koppelman showed how the integrations could be used to balance the availability of skilled workers against project timelines. "The minute you start to delay a project, they're all affected. Another demonstration showcased a product aimed at helping fashion companies maximize their profits. What you really want to be able to do is model those changes," he said. The software uses Fusion middleware to tie together the ProfitLogic retail software Oracle acquired in 2005 with BI (business intelligence) tools and the WebCenter portal. "The pieces matter, but fitting it together is where all the value is," said Oracle president and CFO Safra Catz. The release includes 10 new "cross-industry" packs and six new packs aimed at specific verticals.

Beyond the keynote and demonstrations, Oracle on Monday also announced Application Integration Architecture Release 2.5, the latest installment of its prebuilt packs for tying together processes and applications. Not everyone at the show was buying into Oracle's middleware pitch. Representatives of ActiveVOS, which makes a product that competes with Oracle's SOA Suite, capered on street corners outside the Moscone Center wearing comical black-and-white prisoners' garb, begging passers-by to "free" them from the alleged higher cost and constraints of owning SOA Suite.

Let's be honest – keeping track of your favorite Web sites has become a real pain. Fear not, though, because a little cartoon blob named Digsby is here to help. Slideshow: 13 hot products from DEMOfall '09 Between Twitter, MySpace, Facebook, Gmail and a whole slew of instant messaging protocols, the Internet has become a fragmented mess where you must constantly check for updates and shuttle between tabs and windows.

Digsby, which is the brainchild of the Rochester, N.Y., company dotSyntax, is essentially a mass aggregator of social networking, e-mail and instant messaging sites. At DEMO this week, Digsby announced that it has added Twitter to its already considerable arsenal of integrated social networking sites. But Digsby goes one step further than most aggregation applications because it actively notifies you every time there is an update to one of your e-mail or social networking accounts. However, Digsby didn't just incorporate Twitter into its platform but also made some significant changes to the Twitter format in the hopes of making it more accessible to users. If you can, try to sum up Digsby in 100 words or less. After the DEMO presentation, dotSyntax CEO and founder Steve Shapiro sat down with Network World to discuss how Digsby can make Internet use more efficient and what its designers plan on tackling next.

Digsby helps you manage your instant message, e-mail and social networking accounts from one easy-to-use desktop application. The key is that it serves more as a notifying application than an aggregator, as it gives you a real-time snapshot of e-mails, tweets, status updates and so forth. It helps you save time because you don't have to keep checking for updates. How is Digsby able to integrate all of these IM and social networking sites into one platform? The social networks have published APIs, which is phenomenal from our perspective. It's a lot of work.

For instant messaging, there are multi-protocol IM clients that have been around for a while, so that also helps. When Digsby set out to improve Twitter, what did it identify as the platform's chief strengths and flaws? We haven't tackled Skype yet; that's supposed to be the toughest one to integrate into an application like Digsby. The great thing about Twitter is that it's like a giant chat room where you can choose who you want to listen to in that room. Instead you interact with the whole online community whether they're your personal friends or not. It's not like Facebook where it's a closed social network.

From a weakness standpoint, a lot of people that join Twitter don't get it because it's not like a lot of social networking sites they've used before. To address the issue of people not understanding how Twitter works, we've reframed it more as a chat technology that people have been using for a decade. And the other problem is that once you follow more than 50 or so people, that noise just becomes tremendous and hard to keep track of. So when you use Twitter on Digsby, the most recent tweets appear at the bottom with previous tweets at the top of the screen. The other thing we did was to give you the ability to make subgroups of people on Twitter that you want to listen to a little bit less than your core group of friends.

We thought that making this more like a traditional chat system would make it more accessible for average users. On the Twitter Web site you have main timeline, and with everybody you're following, it starts to get pretty cluttered. So for instance, you can create a group called 'news' where you can place the tweets of journalists you have to be following. So to fix this we let you make different groups. Then those people you've added to this list no longer show up on your main page where you would keep your friends or people whose tweets you really want to read. The next big thing we're doing is adding supports for group chat protocols and also releasing a version of Digsby that works for Mac and Linux computers, since right now Digsby is only available for Windows.

Finally, does Digsby plan on integrating any other IM protocols or social networking sites in the near future?

Another busy week for Google included a Blogger meltdown, Google Voice tweak, word about Social Search, net neutrality lobbying and a dive into the music selling business. Since its launch in March, Google Voice allowed users to post voice mail transcripts on public Web pages, so that they could share the content of the messages with others. Here's a recap of the news from Network World and its sister publications, including IDG News Service.   Keeping Google Voice mail out of search results After transcripts of some voice mail messages from Google Voice users appeared in search results, Google has modified the telephony management service to prevent this from happening, the company.

Google thumbs its nose at SharePoint  Google took the wraps off of more than 10 new features for its Google Search Appliance aimed at the enterprise, including better SharePoint integration. Note the timing of this news though: the news coincided with Microsoft's sold-out SharePoint conference in Las Vegas, where the company was trying to wow customers with search and SharePoint news of its own.   Google's Blogger service suffers widespread outage Google's popular Blogger blog-publishing service crashed early on Friday and remained unavailable to most users for about 90 minutes, the type of broad system outage that Google has been trying to eradicate from its Web-hosted applications. Perhaps the coolest feature is the Self-learning Scorer, which lets the device fine-tune and improve itself. Google acknowledged the crash in brief statements posted to the Blogger Status site and to the Blogger Help Forum. Google will let users stream songs from Lala and iLike.com, which is owned by MySpace, according to a report in the The Wall Street Journal.

Google to offer music sales Google will let users sample and buy songs directly from its search results page via a new service. A Lala link will let users stream a full song once for free and pay about $1 to download a copy, the report said. For Google, this included a deal with Twitter to include Tweets in search results, plus the intro of Google Social Search.   Slideshow: 10 great Google Apps add-ons for the enterprise Google, Verizon make for strange bedfellows on Net Neutrality As usual, Google was at the center of the Net Neutrality discussion last week, pre-empting the official FCC opening of a rule-making process by issuing a joint statement with Verizon outlining their similarities and differences on the issue. Google, Microsoft search battle heats up PC World reported that Google and Microsoft used the Web 2.0 Summit to unveil details about their latest plans to integrate social networking and search results. Their statement begins: "Verizon and Google might seem unlikely bedfellows in the current debate around network neutrality, or an open Internet. For starters we both think it's essential that the Internet remains an unrestricted and open platform-where people can access any content (so long as it's legal), as well as the services and applications of their choice."   "Gone Google" goes global  Google, not known for using conventional marketing to promote its wares, has nonetheless found that such an approach is effective for its enterprise products and will roll out internationally a campaign it launched in the U.S. in August.

And while it's true we do disagree quite strongly about certain aspects of government policy in this area-such as whether mobile networks should even be part of the discussion-there are many issues on which we agree. The "Gone Google" campaign is reaching the U.K., France, Canada, Japan, Australia and Singapore.   Google and Virgin to offer free onboard Wi-Fi  People all over Earth can already access Google's services online. Holiday travelers flying with Virgin America from Nov. 10 through Jan. 15 will get free in-flight Wi-Fi, thanks to a promotional deal with Google. For the next three months, some of them will be able to access those same services from above Earth too.

NASA's space shuttle Atlantis is loaded and ready for takeoff from the Kennedy Space Center in Florida this afternoon. They're scheduled to deliver equipment, including two gyroscopes, to the International Space Station . NASA is focused on building up a reserve of spare parts on the space station in anticipation of the retirement of the space shuttle fleet. "You'll see this theme in some of the flights that are going to come after ours as well," said Brian Smith, the lead space station flight director for the mission, in a statement. "This flight is all about spares. The six-man crew is set to launch at 2:28 p.m. EST today. Basically, we're getting them up there while we still can." The equipment is considered highly critical to the operation of the space station, according to NASA. At this point, there are only six flights left for the space shuttles before they're scheduled to be retired.

Since this is the first mission to deliver what scientists hope will turn into a trove of spare parts, they're taking up the most important pieces. The equipment that needs to go up is being delivered in order of highest priority. The astronauts are expected to make three space walks during the 11-day mission. The equipment being delivered includes two pump modules, two gyroscopes, two nitrogen tank assemblies, an ammonia tank assembly and a high-pressure gas tank. The astronauts will work with the robotic arms onboard the shuttle and the space station to move two platforms loaded with spare parts out of the shuttle's cargo bay to where they'll be attached on either side of the station's truss or backbone. Parts going up for the robotic systems onboard the station include a latching end effector for the station's robotic arm and a trailing umbilical system reel assembly for the railroad cart that allows the arm to move along the station's truss system.

As of 10:30 a.m., a NASA inspection team was studying the exterior of Atlantis , its solid rocket boosters and the external tank for ice or other debris. NASA reports there are 27,250 pounds worth of parts being delivered in this mission. Space agency crews also have loaded the shuttle's external tank with about 535,000 gallons of liquid hydrogen and liquid oxygen, which will power the shuttle's three main engines during launch. NASA forecasts a 70% chance of weather good enough for a launch this afternoon.

Minneapolis-based U.S. Bank has chosen to standardize on IBM Corp.'s Lotus collaboration software, IBM said Tuesday, displacing Microsoft Corp.'s rival SharePoint-based platform. Quickr and Connections provide a file-sharing repository allowing employees to create profiles, wikis and blogs. U.S. Bank plans to roll out the Lotus Quickr and Lotus Connections social Web platform for corporations.

U.S. Bank is also standardizing on the latest Lotus Notes 8.5 client for all 58,000 employees, as well as the Lotus Sametime messaging app, Bob Picciano, general manager of IBM Lotus Software, told Computerworld . "The focus is for them to get everything migrated by 2010," he said. While Quickr and Connections will be new deployments, Notes and Sametime are technically upgrades. U.S. Bank is also looking into IBM's LotusLive cloud collaboration software, said Picciano, and is even considering switching off Microsoft Office to IBM's Lotus Symphony productivity suite. "Discussion for that continues to be under way," he said. U.S. Bank was already using versions 6.5 of IBM Lotus Notes and Domino for most of its employees. According to Picciano, IBM and Microsoft both bid to provide collaboration and messaging for U.S. Bank, which is ranked the sixth-largest American bank with $266 billion in assets. But U.S. Bank was also running 5,000 SharePoint sites - some department level, some much larger, according to Picciano - throughout the bank, which was created out of a number of mergers about 10 years ago.

Despite IBM's apparent incumbent's edge, Picciano said the battle between the two vendors was "largely competitive." "I wouldn't be arrogant enough to call U.S. Bank an IBM shop," he said. Microsoft did not dispute IBM's characterization of its deal with U.S. Bank, but it maintains that it is an exception that proves the rule. "Last year, more than 4.7 million people began the switch to Exchange and SharePoint from Notes," Julia White, director of Exchange product management, said in an e-mail. "We count our switchers in millions, while Notes counts their switchers in tens of thousands." "We expect this trend to accelerate with Exchange 2010 and SharePoint 2010," White said. IBM's win, he said, was the result of superior technology, not heavy discounting. "This wasn't a 'our bundle will beat up your bundle' situation," he said. "Our software was a better choice and fit." Picciano declined to disclose financial terms. "It's a very big deal," he said. Citing large customers such as HSBC, Colgate-Palmolive, Teach for America and others that are deploying the latest Web 2.0 components of the Lotus platform, Picciano says IBM is making a successful counterattack. "We are displacing Exchange, displacing Outlook," Picciano said. "Despite what the people up in Redmond might say, we are taking share."

Force10 Networks is forging deeper into the carrier core by adding MPLS to its high-end Ethernet routing switches. But Force10's ExaScale switch/routers will attain MPLS traffic engineering capabilities to enable the system to perform the same steering and forwarding capabilities as Cisco and Juniper core routers, but at dramatically lower cost, Force10 claims. The company's ExaScale E-Series switch/routers are currently used in the networks of two of the top five global wholesale carriers as Border Gateway Protocol (BGP) peering nodes. The ExaScale system will function as an MPLS Label Switch Router (LSR), a transit router that switches packets based on MPLS labels.

The software, which will be included in updated licenses of the ExaScale operating system, is in beta testing with general availability in December. This is in contrast to a Label Edge Router, which attaches and detaches MPLS labels before and after receiving packets from LSRs. 7 reasons MPLS has been wildly successful MPLS on the ExaScale will allow carriers using the Force10 system to scale core capacity at up to 20% of the cost of traditional core routers, which Force 10 says is about $100,000 per single line-rate 10Gbps Ethernet port. Force10 will face significant challenges in the core router market, however. Also, the core router market has shrunk. Cisco, Juniper and Huawei had a combined 98% share of the $569 million market in the second quarter, according to Dell'Oro Group.

A year ago, it was an $843.5 million market in Q2; this year, it's 33% lower because service providers have reduced investments in large-scale core projects as capacity has met demand, Dell'Oro notes. And vendors that have come into the market long before Force10 - namely Avici Systems and Foundry Networks, which was acquired by Brocade - either failed outright or didn't make a significant dent in the market. The market watcher expects the market to grow less than 5% over the next few quarters. Nonetheless, Force10 is undaunted. This will be especially true, the company says, as the industry migrates to 40G/100G Ethernet. Company officials say they can carve out a niche by offering a compelling proposition built around Ethernet optimization, both in performance and economics.

Products are already emerging, and the standard is expected to be ratified in mid-2010. Also, the growth of multimedia content delivered over the Internet - such as video from Hulu and Youtube, social networking, online gaming and peer-to-peer file sharing and presence applications - to fixed and mobile devices is demanding a new generation of low-cost,capacity-expanding platforms, the company says. "There's no technical reason you couldn't have a switch [like Force10's ExaScale] in the carrier core just transporting packets," says Zeus Kerravala of the Yankee Group. "But there are legacy router architectures there, and changing operator behavior and architectures is hard. And it's not going to start with the Tier 1 [carriers]; it's going to start with the Tier 2s and 3s." Force10 is going to need to build up a beachhead of clients with a compelling price advantage.

In many IT organizations, the WAN does not matter. One of the primary roles of the WAN is to enable acceptable application delivery. What you do with the WAN, however, matters greatly. As will be discussed in this newsletter, we are entering a new ear of application delivery – one that we refer to as Application Delivery 2.0. As will be discussed in the next two newsletters, the challenges of the Application Delivery 2.0 era will be notably more complex and challenging than are those of the current era.

That changed a few years ago when IT organizations began to focus on ensuring acceptable application delivery. While ensuring acceptable application delivery has always been important, it historically was not a top of mind issue for most IT organizations. They did this by deploying a first generation of solutions that were intended to mitigate the impact of chatty protocols such as CIFS (Common Internet File System), to offload computationally intensive processing (for example TCP termination and multiplexing) off of servers, and to provide visibility into the performance of applications. Jim and Steve try to avoid cute marketing clichés. Hence, we are hesitant to use the phrase Application Delivery 2.0 as it sounds so much like just one more marketing cliché. However, we see distinct evidence, both from vendors and from IT organizations that we are indeed entering a second generation of application delivery. Unfortunately, the IT organization of a few years ago typically approached application delivery from a tactical, stove-piped approach. Part of the characterization of Application Delivery 2.0 is that IT organizations are beginning to face a new set of challenges.

As is so often the case in our industry, IT organizations have to support traditional or legacy technologies and challenges at the same time that they have to respond to new technologies and challenges. That does not mean that the traditional challenges of supporting chatty protocols or maximizing the performance of servers have gone away. One of the new challenges facing IT organizations stems from the changing role of the mobile worker. That is no longer the case. A few years ago, there were relatively few mobile workers and the communications needs of the mobile workers of that era were satisfied with simple cell phones. Now it is common to have 25% or more of employees be mobile at any point in time.

This introduces all of the performance and security issues associated with wireless networking into the mix of application delivery challenges. These employees have smartphones or other wireless devices that they routinely use to access business-critical applications. In the next WAN newsletter we will continue to discuss the challenges that are driving Application Delivery 2.0. We will also mention some steps that IT organizations are taking to respond to these challenges.

IBM has expanded its server lineup with a new mainframe system designed just for Linux that may be aimed, in particular, at higher-end x86 systems. It does not use the mainframe operating system z/OS but includes mainframe management software as well as IBM's z/Virtual Machine system. The new system uses IBM's specialty Linux processor and runs either Novell SUSE or Red Hat systems. Together, they constitute the company's latest "solutions edition," or what IBM says are lower-cost, integrated stacks for the mainframe.

This system is intended to be competitive with large multicore systems used for virtualization consolidation. There are two servers in the Enterprise Linux Server line, and the starting price on the lower-end model, with two processors, is $212,000; it scales up from there. The Linux-specific line is IBM's latest effort to reduce the cost of its mainframe. But several years ago, IBM started producing a smaller model, the z10 Business Class , which was initially offered at about $100,000, to compete with a broader range of enterprise servers. It's high-end z10 Enterprise Class system can cost millions. Reed Mullen, the System z virtualization lead product planner, said that potential customers include companies that want to virtualize a lot of systems but aren't necessarily mainframe customers.

IBM expects to upgrade its z10 next year , in keeping with its three-year upgrade cycle. Among the arguments that IBM will make for this system is its ability to dynamically add capacity in a running environment, Mullen said. IBM's mainframe sales have been off 26% in the most recent quarter compared with the same quarter last year, and server sales have been flat across the board. With this new hardware, IBM likely wants to compete with x86 systems with 16 processor cores and above, he said. Brad Day, an analyst at Forrester Research Inc., said IBM has been working to reduce the cost of its mainframe software, which can account for half the cost of a mainframe, including personnel, energy and maintenance. Anything that lowers the life-cycle cost of the system is critical, and by focusing on Linux, IBM is "putting meat to where most of the workloads are going," Day said. "About half of the new growth of applications on mainframe is led by Linux."

Data storage switch maker Brocade Communications Systems Inc. and Thales e-Security Inc. today announced the integration of the Thales Encryption Manager for Storage (TEMS) with the Brocade encryption SAN switches. The new switch centralizes the data encryption process within storage area networks (SANs) by eliminating the need to deploy multiple storage encryption systems in front of primary storage arrays. The combination of TEMS, a standards-based encryption key management appliance for storage, and the Brocade Encryption Switch is aimed at securing enterprise data and addressing regulatory requirements surrounding customer data.

The Brocade Encryption Switch and the Brocade FS8-18 Encryption Blade the rebranded Thales TEMS - are part of a family of SAN-based encryption appliances that target sensitive corporate data with high performance and centralized fabric management for both disk and tape-based storage systems. The TEMS encryption blade supports the draft IEEE P1619.3 key management specification. The new appliance also consolidates and automates the management of encryption keys for storage systems. According to Brocade, subsequent releases will also support the recently announced OASIS KMIP key management standard . Encrypting sensitive information has become a security requirement for organizations across all industries, especially as data breaches continue to make headlines. Pricing for the new appliance was not immediately available.

Establishing standards like IEEE P1619.3 and KMIP is a significant first step toward simplifying encryption key management, but it is up to leading vendors to offer solutions that support these standards, said Jon Oltsik, principal analyst at Enterprise Strategy Group, in a statement.

Led by the late Michael Jackson and the vampire-driven "Twilight" series, Yahoo's Top 10 Searches for 2009 show that penny-pinching consumers are escaping to the Web "to pursue news and their guilty pleasures," according to a Yahoo search trend analyst. Rounding out Yahoo's top ten this year were, in consecutive order, Naruto, American Idol, Kim Kardashian, NASCAR, and Runescape. World Wrestling Entertainment (WWE) came in third on this year's list of Top 10 Overall Searches for 2009, rising celebrity Megan Fox landed in fourth place, and Britney Spears came in fifth. To me, the celebrity orientation of this year's Internet searches seems almost reminiscent of how, during the Great Depression, people found their escapes in movie magazines and lavish musical entertainment But Vera Chen, a Yahoo Search trend analyst, also acknowledges that during the current deep recession, "with economic uncertainty looming, people looked for ways to find stability by searching the Web." Accordingly, Yahoo's "Top 10 Economy-Related Searches for 2009" include coupons, Stimulus Plan, student loans, and foreclosures, for example.

Thus, Yahoo has also put together a list of the Top 10 Mobile Searches for 2009. Some members of the overall Top 10 list - such as Megan Fox and Michael Jackson - also made the mobile list, although others - including WWE and Kim Kardashian - did not. As many of us already know, however, sales of mobile devices stood out as one big bright spot on 2009's bleak economic canvas. "Mobile devices emerged as essential and indispensable to the lives of many Americans," according to a Yahoo press release. Those searching the Web from their mobile phones were also particularly interested in Lady Gaga, the NFL, and - not at all surprisingly - Mobile Games. For one thing, maybe consumers will be able to forego some of their searches for coupons and the like. What will Yahoo's Top 10 list look like for the year 2010? Hopefully, the economy will have turned the corner a bit.

The European Commission has signed an agreement with the online music industry designed to improve consumers' access to online music across the 27-nation European Union, it said Tuesday. The agreement they reached sets out general principles that will underpin the online distribution of music in the future, leading to "improved online music opportunities for European consumers," the participants said in a joint statement. "European consumers want and deserve better online music offerings," Kroes said in a statement, describing the agreement as evidence of "real progress in this direction." This is the first time players involved in the distribution of music have agreed on "a common roadmap," she said. Online music retailers including Amazon.com and Apple, Finnish mobile phone giant Nokia, royalty rights collecting societies, consumer groups and the record labels EMI and Universal Music Group struck the deal with E.U. Commissioner for competition Neelie Kroes.

Apple is optimistic that over the coming year it will be able to make its iTunes online music store available in countries where it doesn't operate at present, the Commission said. The biggest obstacle to creating a fully functioning online marketplace for music until now has been the reluctance of collecting societies to do away with their traditional approach to the European market, which involved each one maintaining a monopoly over rights collection in its national territory. Meanwhile, EMI expects to sign non-exclusive digital licensing agreements with two of the most obstinate collecting societies in Europe - SACEM of France and Spain's SGAE, the Commission said. The Internet's ability to reach across borders makes it harder for online stores to restrict sales to customers in a particular territory.

The Internet Corporation for Assigned Names and Numbers (ICANN) has reached a new agreement with the U.S. Department of Commerce allowing the nonprofit greater independence, while giving more countries oversight of the organization. The DOC will continue to be involved in ICANN's Governmental Advisory Committee, but the new agreement recognizes ICANN as a global "private-sector led organization." The new agreement is a "huge moment not just for ICANN but for the Internet," said Paul Levins, vice president at ICANN. "This really vital resource was being overseen by one government." The U.S. government will have "one seat at the table" for the three-year reviews, ICANN CEO Rod Beckstrom said in a video on the organization's site. "What it really means is we're going global," he said. "All the reviews and all the work done will be submitted for public comment to the world. The new agreement, called an Affirmation of Commitments, sets up reviews of ICANN's performance every three years, with members of ICANN advisory committees, the Department of Commerce (DOC), independent experts and others serving on the review teams. But there's no separate or unique or separate reporting to the United States government.

The new agreement won praise from critics who have complained that the U.S. governmenthas had too much control over ICANN, which manages the Internet's DNS (domain name system). The new agreement should allow ICANN to become more open and accountable to users worldwide, said Viviane Reding, the European Union's commissioner for information society and media. All the reporting is to the world; that's the real change." The new agreement was announced Wednesday, the same day that an 11-year series of memorandums of understanding between ICANN and the DOC expired. The new agreement ends "unilateral" review of ICANN by the DOC and sets up independent review panels, she said in a statement. "I welcome the U.S. administration's decision to adapt ICANN's key role in internet governance to the reality of the 21st century and of a globalized world," Reding said in her statement. "If effectively and transparently implemented, this reform can find broad acceptance among civil society, businesses and governments alike." The challenge, she said, will be to make ICANN's Governmental Advisory Committee more effective, as it has a major role in appointing the review panels. "Independence and accountability for ICANN now look much better on paper," she said. "Let's work together to ensure that they also work in practice." The new agreement commits ICANN to a "multi-stakeholder, private sector led, bottom-up policy development model for DNS technical coordination." It also requires ICANN to "adhere to transparent and accountable budgeting processes, fact-based policy development, cross-community deliberations, and responsive consultation procedures that provide detailed explanations of the basis for decisions." ICANN will publish annual reports that measure the organization's progress and it will provide a "thorough and reasoned explanation of decisions taken, the rationale thereof and the sources of data and information" on which it relied. The Internet Society, a nonprofit organization focused Internet-related standards, education, and policy, also praised the new agreement, saying it emphasizes ICANN's obligation to "act in the public interest as the steward of a vital shared global resource." The new agreement doesn't change the DOC's contract with ICANN to perform the functions of the Internet Assigned Numbers Authority (IANA), which is responsible for the global coordination of the DNS Root, IP addressing, and other Internet protocol resources. While the expiration of the old agreement with the DOC "threatened to open an accountability gap" for ICANN, the new agreement should resolve that concern, added Steve DelBianco, executive director of e-commerce trade group NetChoice. "The Commerce Department has crafted an arrangement here that delivers what the global Internet community has clamored for: permanent accountability mechanisms to guide ICANN in the post-transition world," he said. "These reviews should help ICANN stay focused on security, choice and consumer trust, with an added emphasis on interests of global Internet users - especially those who can't yet use their native language in domain names or e-mail addresses."" The new agreement addresses an issue that's been missing at ICANN, "a balanced way to bring all governments into the oversight process alongside private sector stakeholders, with a sharpened focus on security and serving global internet users," he added. The DOC, in the new agreement, also doesn't endorse ICANN's efforts to allow an unlimited number of new generic top-level domains, such as .food or .basketball.

The controversial plan has met resistance from trademark owners, who say they'd have to register for dozens of new Web sites to protect their brands. "Nothing in this document is an expression of support by DOC of any specific plan or proposal for the implementation of new generic top level domain names or is an expression by DOC of a view that the potential consumer benefits of new gTLDs outweigh the potential costs," the new agreement said.

It's been 10 years since the Apache Software Foundation hung out its feather, creating what has become a series of communities filled with focused project entrepreneurs working on a laundry list of innovative efforts, one of which landed in the White House just a few weeks ago. In its 10 years, ASF has become a shining example of the power of open source development and the group, now with 65 projects operating under its banner, shows no signs of slowing down. The application that now runs the White House Web site is Drupal, but its underpinnings, the Lucene search service, is pure Apache Software Foundation (ASF), an all-volunteer membership that now exceeds 300 people, including some of the most respected talent in the open source community.

Just four years ago, the number of ASF projects stood at 25. ASF will celebrate its 10th anniversary at this week's ApacheCon conference even though the official anniversary date is in June. "I think [ASF] has shown to be successful in that there is a lot of good software that comes out of Apache that is widely used," said Doug Cutting, a member of the ASF board of directors, and the creator of the Lucene project. "We lead by example. In addition, there are 33 projects in the Apache Incubator, and more than two dozen codebases being explored in the Apache Labs. That is something we aspire to do." Cutting's leadership examples include three ASF projects – Lucene, Hadoop and Nutch. It all operates within the Foundation, which is actually a membership-based non-profit corporation registered in Delaware. Unlike other open source organizations, before Apache hosts a project it has to be given to the ASF, which ultimately controls the intellectual property of all its projects. From its beginnings with 21 members and the Apache HTTP Server, still the most popular Web servers in use, the foundation has forged a set of principles that continue to drive it today.

But the projects themselves run as semi-autonomous units within ASF, which provides members with legal protection from suits directed at foundation projects. He says more people are building software today and calling it open source, "but if you look closely they are aiming for vendor lock-in." ASF's structure and strategy avoids that result, Cutting says. "Today, our model is getting stronger and that is bringing more projects into Apache." Cutting says the future should hold more of the same. "We are not seeking to rock the boat and reinvent Apache, but we will continue to guide and scale the Foundation." That effort is one of the tests for ASF as it moves into its second decade. "Part of the design challenge is to build a scalable Foundation that does not require a lot of management," he says. "We don't want a big heavy bureaucracy." While the board works on the future of ASF, Cutting sees the innovation part of the Foundation taking care of itself."Technically what the future brings is anyone's bet," Cutting says. "But I think the future holds room for more and more software that is open source and more and more that is Apache style open source and more and more that is within the Apache Software Foundation." Follow John Fontana on Twitter. New members are by invite only, voted upon by existing members, and prove their value by contributing to a project or projects at the Foundation, which describes itself as a meritocracy. "We build software on its merits, which is a pretty great model," Cutting says. "Hopefully we set a tone, but we don't force the Apache Way on other projects." Cutting says the focus on building software and letting people do what they want to do with it is one of the important roles that ASF plays in the open source movement today.

A massive bot-based attack has been hitting Facebook users, with nearly three-quarters of a million users receiving fake password reset messages, according to security researchers. The messages, which come bearing subject lines such as "Facebook Password Reset Confirmation," include a file attachment that supposedly contains the new password. The attack, which began Monday afternoon, according to e-mail security vendor Cloudmark, targets Facebook users with a spoofed message that claims recipients' Facebook passwords have been reset as a security measure. In fact, the attached .zip file includes a Trojan downloader, dubbed "Bredlab" by some antivirus companies, "Bredolab" by others.

At least 8% of the users who have received one of the fake messages have tagged it as legitimate, going to the trouble of pulling the message from their junk folder - where Cloudmark has placed it - because they think it's real, Tomasello said. The downloader grabs a variety of malware from hacker servers, including fake security software , or "scareware," and installs attack code and rogue antivirus applications on the compromised PCs. Multiple security companies, including Symantec, Trend Micro, MX Lab and Websense, have put out warnings about the attack campaign. "This variant of Bredolab connects to a Russian domain and the infected machine is most likely becoming part of a Bredolab botnet," said Shunichi Imano, a security researcher at Symantec, in a post to the firm's security blog . Jamie Tomasello, Cloudmark's abuse operations manager, said today that her company alone has detected nearly three-quarters of a million phony Facebook messages since Monday, and nearly 250,000 in the last 24 hours. "Our count continues to go up, and is at about 735,000 now," said Tomasello. "It's a pretty high volume." According to Tomasello, both desktop clients and ISPs that use Cloudmark to filter potentially malicious mail have reported receiving the fake Facebook e-mail. Cloudmark has no data on how many users were actually duped into opening the .zip file and running the enclosed .exe that installs Bredolab, however. "The numbers are equal to or higher than other Facebook malware or phishing campaigns," Tomasello claimed. Because of its huge base - last month Facebook said it had more than 300 million users - the site is a frequent target for hackers and identity thieves. She said that Cloudmark is currently revising that 8% estimate upwards.

Last March, for example, the Koobface worm made the rounds on Facebook, as well as other social networking sites such as MySpace and Friendster, infecting large numbers of users. Facebook did not respond to a request for comment on the attacks, or to questions what it is doing, or can do, to stymie the campaign or warn its users.

Microsoft today patched 15 vulnerabilities in Windows, Windows Server, Excel and Word, including one that will probably be exploited quickly by hackers. The 15 flaws fixed in Tuesday's six security updates were less than half the record 34 Microsoft patched last month in 13 separate bulletins. None affect Windows 7, the company's newest operating system. Of today's 15 bugs, three were tagged "critical" by Microsoft, while the remaining 12 were labeled as "important," the next-lowest rating in the company's four-step severity scoring system.

That update, which was ranked critical, affects all still-supported editions of Windows with the exception of Windows 7 and its server sibling, Windows Server 2008 R2. "The Windows kernel vulnerability is going to take the cake," said Andrew Storms, director of security operations at nCircle Network Security. "The attack vector can be driven through Internet Explorer, and this is one of those instances where the user won't be notified or prompted. Experts agreed that users should focus on MS09-065 first and foremost. This is absolutely a drive-by attack scenario." Richie Lai, the director of vulnerability research at security company Qualys, agreed. "Anyone running IE [Internet Explorer] is at risk here, even though the flaw is not in the browser, but in the Win32k kernel mode driver." Both Storms and Lai were referring to the one bug marked critical in MS09-065, which actually patched a trio of vulnerabilities. EOT fonts, however, can also be used in Word and PowerPoint documents. According to Microsoft, the Windows kernel improperly parses Embedded OpenType (EOT) fonts, which are a compact form of fonts designed for use on Web pages. Hackers could also launch attacks by attaching Word or PowerPoint documents to e-mail messages, then duping users into opening those documents.

Because Windows 7 and Windows Server 2008 R2 were not affected by the MS09-065 update, Storms and Lai assumed that Microsoft caught the bug before it wrapped up the final code, or release to manufacturing (RTM) build, of the operating system, and is only now getting around to plugging the holes in Windows 2000, XP and Vista, as well as Server 2003 and Server 2008. "Windows 7 Release Candidate [RC] is probably vulnerable," said Storms, citing Microsoft's policy of not providing security updates for preview versions of an operating system when the final has been released. "That's why you don't see Microsoft patching Windows 7 RC or Beta," said Storms. "For anyone still running RC, they should take heed and upgrade to the RTM." But while Storms speculated that Microsoft knew the EOT font flaw was a security issue - and waited until now to patch older Windows - Lai thought that Microsoft didn't realize until recently that it was also a security vulnerability in editions prior to Windows 7. "I think they fixed this bug as part of the code sanitization during [Windows 7's] development cycle. In lieu of patching the problem, users can easily block the most likely attacks by disabling IE's support for embedded fonts. "That's a low-impact mitigation," Lai said. "The worst that could happen is that some sites might look ugly." His advice would still leave PCs open to attack via malicious Word or PowerPoint documents, a point Microsoft also made in the vulnerability's write-up. It was actually only publicly disclosed recently, and then they patched it in other Windows." Microsoft acknowledged that information about the EOT vulnerability had gone public before today's patch. "While the initial report was provided through responsible disclosure, the vulnerability was later disclosed publicly by a separate party," stated the accompanying advisory. Microsoft also issued critical updates for Vista and Server 2008 , as well as for Windows 2000 Server. Storms expects to see attackers jump on the EOT vulnerability. "This is the one to watch in the coming weeks, not only because of its novelty, but also because it can be exploited through IE, which is the easy route, as well as through Word and PowerPoint documents," he said.

On the latter, which harbors a bug in its implementation of the License Logging Server , a tool originally designed to help customers manage Server Client Access Licenses (CAL), Storms urged users of that aged operating system to apply the patch pronto, even though the machines are probably well-protected. "Windows 2000 Server has the logging server enabled by default, but those systems are likely behind multiple firewalls, and people running [Windows 2000 Server] are pretty cognizant of the fact that it's an older version and will act accordingly." Excel and Word also received patches today. This month's security updates can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services. Eight vulnerabilities were addressed in Excel in MS09-067 and one in Word with MS09-068 . Both updates also affected the Mac editions, Office 2004 and Office 2008. "These are the kind of file format vulnerabilities we've seen many times before," said Storms, noting in a follow-up instant message that the bugs are in the older, binary file formats, not in the newer XML-based formats that Microsoft debuted in Office 2007 for Windows and Office 2008 for Mac.

Sybase is extending its Afaria mobile-device management platform and database software to the Apple iPhone, taking advantage of new enterprise features in Version 3.1 of the iPhone's software to give IT departments more control and capabilities on the popular handset. Going on sale in the middle of this month, Sybase's Afaria 6.5 will finally give administrators the kinds of controls they have had previously for mobile platforms such as Symbian, Microsoft Windows Mobile 6.1, Research In Motion BlackBerry and PalmOS. Apple's recent iPhone 3.1 release added the capability to lock down certain settings on a device so the user can't change them using the phone's configuration utility, said Mark Jordan, senior product manager for Afaria. Though many enterprise employees bring iPhones into the office and rely on them for personal communications, the device originally caught on as a consumer gadget for music, Web browsing and entertainment applications, and has only gradually made inroads as a workplace tool. That allowed Sybase to give enterprise IT departments the power to do things such as block applications, define the required password strength and lock down Wi-Fi and VPN (virtual private network) settings.

With the new Afaria, enterprises can make and change settings on employees' iPhones over the air based on overall policies for certain departments, job descriptions and other criteria. Administrators can now establish a trusted relationship between Afaria and the employee's phone using a certificate, he said. Among other capabilities, they can also require device authentication for access to a corporate directory and set up compliance reporting on the employee's use of the phone. Also on Tuesday, it announced tools for the Sybase SQL Anywhere database to be used for synchronization of data between an iPhone application and a back-end database. Sybase announced Afaria's iPhone capabilities on Tuesday at the iPhone Developer Summit in Santa Clara, California.

Using SQL Anywhere, internal developers and software vendors can build in bi-directional synchronization between an on-device app and relational databases including Sybase, Oracle, SQL Server, DB2 and MySQL. This frees employees from having to depend on the cellular data connection to get work done while on the road, Jordan said. Also on Tuesday, the company's Sybase 365 subsidiary introduced a turnkey system for mobile banking on the iPhone. There is a beta test program now open for SQL Anywhere for iPhone. With it, banks can allow their customers to check balances, transfer funds among accounts, securely communicate with bank representatives, find branches and automatically dial the bank, Jordan said. The Sybase mBanking 365 iPhone platform is available now and is already deployed by BBVA Compass as the BBVA Compass Mobile application.

The mobile phone market globally turned a corner in the third quarter, with shipments by manufacturers increasing by 5.6% over the previous quarter, market research firm IDC reported. In all, 287.1 million cell phones and smartphones were shipped in the third quarter, down 6% from the 305.4 million shipped in the third quarter of 2008. Shipments do not necessarily result in sales to end user customers, but indicate that carriers and other retailers are expecting to make sales by ordering from manufacturers. The results for the third quarter were still down by 6% from the same quarter in 2008, but the quarter-to-quarter growth was taken as the first sign of improvement since the onset of the economic downturn, the analyst firm said Thursday. In the third quarter, various sales channels promoted older devices at lower prices, creating demand that pushed up shipment volumes, said Ramon Llamas, an IDC analyst.

New smartphones, such as the Droid and the Cliq from Motorola which are both based on the Android operating system, are appearing in November in the U.S., for example, IDC noted. Now that we have moved into the fourth quarter, vendors are setting the stage for further gains by launching their flagship devices to meet pent-up demand, he said. Will Stofega, another IDC analyst, said that the economy is expected to make a slower recovery than many predicted a year ago, but mobile phone manufacturers should still increase their spending on research and development to stay competitive. Western Europe showed strong signs of recovery, with increases in all devices year-over-year. IDC assessed market performance in various geographies, noting that North America posted mixed results, with the U.S. showing gains in the quarter, but with Canada declining for the third straight quarter for all mobile phones, even as smartphone shipments increased. IDC did not provide specific numbers for various geographies, however.

Mexico has experienced an increase in taxes for telecom services, personal taxes and value-added taxes, all of which have a negative impact on mobile phone sales. Latin America and Asia/Pacific performed weaker than other areas. Market leader Nokia once again led for all types of mobile phone shipments, with 108.5 million shipped, a decline of 8% over third quarter 2008. The Finnish company took 37.8% share of the market. Samsung finished second with 21% market share; LG Electronics finished third with 11%; Sony Ericsson was fourth with 4.9%; and Motorola was fifth with 4. All other manufacturers combined to account for 59 million mobile phones shipped, or 20.6% of the market.

In a contentious court battle launched by record label EMI, the brazen owner of online retailer BlueBeat has begun complying with a new court order to stop selling Beatles music online, after offering a quirky defense that he owns the copyright to the songs at issue. Risan contended that he authored the songs using "psycho-acoustic simulations." These simulations "are my synthetic creation of that series of sounds which best expresses the way I believe a particular melody should be heard as a live performance," he messaged. In a message sent from his iPhone earlier this week, BlueBeat owner Hank Risan told his attorney that he - rather than EMI or Apple Corps - is the rightful owner of the Beatles tunes for sale on his Web site, according to a report in paidContent.org. But on Wednesday, a Los Angeles judge rejected BlueBeat's assertions that it is selling only re-recorded versions of the songs.

Ruling that BlueBeat hasn't provided enough evidence to back up its claims, the judge came out with an injunction banning the company from streaming or selling tracks from the Beatles and other EMI music artists. Instead, the judge found in favor of EMI, a record label that argued in court that BlueBeat is "thumbing their noses" at EMI and Apple. As of Friday at about 9:15 a.m. Eastern time, BlueBeat has indeed stopped selling the unauthorized downloads of the Beatles tracks, previously hawked at bargain basement pricing of 25 cents a track. Clicking on "Buy" prompts a message that the tracks aren't available for purchase. The tunes are still visible on the site.

Risan's claims rest on a section of the Copyright Act - often applied to music by tribute bands - exempting recordings that "imitate or simulate those in the copyrighted sound recording," according to an account by the BBC. Yet the Beatles tracks might possibly return to BlueBeat at some point, and with court approval. Meanwhile, EMI, the owner of the original Beatles recordings, has been in longtime talks with Apple Corps - the company set up by the Beatles to look after their catalog - about arranging some kind of legitimate deal for selling the tunes online. On a date set for November 20, a court will hear arguments presented by both sides.

Brocade Communications Systems Inc. has hung a "for sale" sign on its door, according to a report today in the Wall Street Journal . Brocade declined to comment on the report. Brocade is said to be valued at about $3.2 billion. Hewlett-Packard Co. and Oracle Corp. have shown interest in buying Brocade, which make switches for routing data storage traffic, according to the report, which added that an agreement is not imminent. The company reported a loss of $21 million on sales of about $493.3 million in the its 2009 fiscal year's third quarter that ended Aug. 1. San Jose-based Brocade has about 2,800 employees.

If true, he added, the timing isn't surprising. Brocade late last year acquired Foundry Networks Inc. whose IP networking technology gives it a leg up in the server networking market, and puts it in a stronger competitive position rival Cisco Systems Inc. "The question is: 'do the server vendors want to increase the competitive pressure against Cisco because Cisco is now in the server business?'" said Brian Babineau, an analyst with the Enterprise Strategy Group in Milford, Mass. "I think that's what makes Brocade more attractive, and you can consider Oracle in the server business as well because they plan to own Sun ." Babineau said he has heard rumors as recently as last week about Brocade putting itself on the block. Over the past seven or so years, switch maker Cisco has added a line of storage switches and routers that make it a heavy player in the storage business. Earlier this year, Cisco, EMC and others said they jointly developed a new storage blade server to be sold by Cisco. Just last month, it was reported that Cisco and EMC Corp. were in talks to create a technology services arm.

Brocade has also been making moves to attract new sales channels by signing reseller agreements with EMC rivals IBM, Hewlett-Packard Co. and quasi-competitor Dell Inc. Dell's acquisition of storage vendor EqualLogic two years ago likely placed a strain on its reseller relationship with EMC. Babineau said Hewlett-Packard may be the most appropriate suitor for Brocade because it has an established networking and a storage portfolio of products, and because Cisco is increasingly competitive with HP . "It's very logical. Dell has increased its presence in business-class data storage systems over the past few years, originally through reseller deals with EMC and recently with its own line of data storage products that are moving from entry-level to midrange. If you look at the timing, it's almost like a perfect storm for Brocade," Babineau said. "Exiting a Foundry integration process, potential uptick in IT spending starting shortly, and big IT companies wanting to compete against Cisco with Brocade being one of the only viable candidates in that market." "This is not about storage, but about networking," he added. Another source, who asked not to be named, said that HP executive Dave Donatelli , who had headed EMC's storage unit until earlier this year, could help HP position Brocade's storage offerings against those of his former firm. "I just think Donatelli has some real institutional knowledge after selling a good portion of Brocade's products when he was with EMC," the source said.

ICANN's approval of non-Latin character domains undoubtedly is a game-changing decision in the history of the World Wide Web. Here are a few pros and cons to consider as we move away from the traditional ASCII based-Web. With scheduled to start popping up in the middle of next year, many people are debating if this digital support for more distinctly international sites balances with potential security threats and fragmentation of the Internet.

Pro: World Wide Web Supporting World Wide Language Let's face it; millions of Internet users speak languages that aren't written using Roman characters. The transition will begin on November 16 when countries can apply for country codes in their own unique character sets. "The first countries that participate will not only be providing valuable information of the operation of IDNs in the domain name system, they are also going to help to bring the first of billions more people online - people who never use Roman characters in their daily lives," ICANN CEO and President Rod Beckstrom said in a statement. Allowing Web sites to have domains that use other characters will make Web addresses more recognizable to some and make the Web more accessible to millions of new users. Con: Country Codes are Only the Beginning Generic domains such as .com, .org and .net aren't open to international characters yet, but could be in the next couple of years. Pro: Country Codes are Only the Beginning If done properly, opening generic domains to international characters could be a good thing. If ICANN decides to open generic domains without extending rights to existing URL holders, international companies and brands might find themselves purchasing URLs in multiple languages to protect the use of their name, points out PC World Tech Inciter writer Tech Inciter David Coursey.

If International corporations were granted rights to the .com URLs they already possess it could spell an end to selecting a region before entering the site. It would also open doors for smaller Web sites that are just interested in serving a particular language group. For instance, going to intel.com could lead to the English version of the site, while using a Japanese, Russian, or Korean suffix would take you to a version of the site with that language. Con: A lesson from 1337 h4ck3r$ Expanding beyond Roman characters also increases potential for site rip-offs that use homoglyphs, characters with identical or indistinguishable shapes. Con and Pro: No Latin Base Emphasis Apparently homoglyphs are drawing some attention at ICANN. Languages that use accented Latin characters aren't being supported at this time, The CBC Reports.

This already occurs to some degree (for instance pointing your browser to google.com takes you to a different site than go0gle.com) but different languages might have characters that are identical to characters in other languages. They attribute the lack of support to security concerns that accented characters could lead to phishing scams because, "internet users might not at first see the difference between, for example, 'google.com' and 'goógle.com.'" This is bad news for French, Spanish, Turkish, and Vietnamese speakers - all four languages use accented characters. As fellow PC World writer Jacqueline Emigh pointed out, it would be next to impossible to produce a keyboard that could support characters from every language under the sun. But, if ICANN is aware of security concerns that would arise from including these languages, maybe they have some sort of anti-homoglyph trick up their sleeve for other languages, (here's looking at you, Cyrillic.) Con: Keyboards and Restrictive Access Adding support for 100,000 international characters would make traditional keyboards insufficient input devices for accessing the entire Internet. Virtual keyboards and language packs could possibly help alleviate the problem for some people, but there wouldn't be an easy fix. ICANN released this video with its announcement, hoping to encapsulate the potential for opening up international character domains.