Archive for RB

Follow the Open Source Money

 Matt Asay at Infoworld recently pointed out some interesting data on who really contributes to open source. Wikipedia, the most well-known open-source project, defines open-source software as software whose source code is published and made available to the public, enabling anyone to copy, modify and redistribute the source code without paying royalties or fees. Open-source code can evolve through community cooperation. These communities include individual programmers as well as large companies.

Open sourceAdobe developer Fil Maj used the GitHub REST API to pull public profile information from GitHub users. The REST API is a low-bandwidth protocol used on the internet that allows two software programs to communicate with each other. Using the API, Mr. Maj collected the company field from all 2,060,011 GitHub user profiles who were active in 2017 (“active” meaning ten or more commits to public projects). Using that data, Mr. Maj was able to pull the total number of corporate contributors to GitHub, with results that might surprise you.

Here are the ranking of GitHub contributors, with their total number of employees actively contributing to open source projects on GitHub:

RankCompanyEmployees Contributing
1Microsoft4,550
2Google2,267
3Red Hat2,027
4IBM1,813
5Intel1,314
6Amazon.com881
7SAP747
8ThoughtWorks739
9Alibaba694
10GitHub676
11Facebook619
12Tencent605
13Pivotal591
14EPAM Systems585
15Baidu584
16Mozilla469
17Oracle455
18Unity Technologies414
19Uber388
20Yandex351
21Shopify345
22LinkedIn343
23Suse325
24ESRI324
25Apple292
26Salesforce.com291
27VMware271
28Adobe Systems270
29Andela259
30Cisco Systems233

The author points out, this is not a perfect measure, but it is a much richer, more accurate data set for figuring out total contributors for any company. Even with that caveat in mind, we end up with many more corporate open source contributors than previous data suggested.

Microsoft’s contributions to open source

Microsoft's contributions to open sourceThe new data shows Microsoft (MSFT) is the number 1 open source contributor. Redmond has twice the number of contributors compared to its next nearest competitor. Remember Steve Ballmer‘s developers! developers! developers! meltdown?  For those of us that were around when Mr. Ballmer, the Microsoft CEO called open source as a “cancer” and “anti-American,” this is a remarkable change of heart for MSFT.

Red Hat

Red Hat (RHT) Mr. Maj’s data puts the open source leader among the top contributors. Red Hat has dramatically fewer engineers on its payroll than Google (GOOG) or Microsoft. As such, it’s doubly impressive that Red Hat would place so highly. Pretty much every engineer in the company works on open-source projects.

Amazon

 

Amazon logoAmazon (AMZN) Often considered an open source ne’er-do-well, Amazon comes in at No. 6 in the rankings. AMZN has nearly 900 open source contributors on staff. The article points out that Amazon has perhaps not publicly led the open source effort in the same way as Google and Microsoft have, but it remains a strong contributor to the projects that feed its developer community.

China is a net consumer of open source

Chinese companies like Baidu, Tencent, and Alibaba, which have long been perceived to be net consumers of open source, actually contribute quite a bit according to the new data.

Legacy firms

Legacy firms like Intel (INTC), Oracle (ORCL), Adobe (ADBE), and Cisco (CSCO) rank among the top 30 open source contributors reports InfoWorld.

rb-

Color me suspicious, but have these firms really embraced open source. Have they just adapted their business model to usurp elements of open source to lay their proprietary code on top of it? This saves them the bother of writing new code and yet they can charge proprietary costs for software where they have reduced their development costs.

Tom Brady hanging high fiveAfter all, numbers don’t lie. Stats say that in 2014, half of the companies said they use open source in their product. Just one year later, the number grew to 78%. Consequently, as long as open source continues to enjoy its place in the sun, we should expect the Microsoft-open source bromance to continue.

Related article

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

MIMO Antennas Explained

MIMO Antennas ExplainedWave 2 of the IEEE 802.11ac Wi-Fi standard has been out for a while now. Wave 2 Wi-Fi can support speeds up to 2.3 Gbps. One of the techniques used to generate the increased speeds of the 802.11ac networks is multi-spacial streams or several streams of the same Wi-Fi signal radiating out from several antennas. The multiple antennas are the most noticeable indicator that an access point is 802.11ac capable, especially in the consumer market.

Multiple-Input Multiple-Output

The technology behind using several antennas is called Multiple-Input Multiple-Output (MIMO). MIMO antennas have two or more antennas in a single physical package and are designed for use in IEEE 802.11n/ac Wi-Fi networks. MIMO makes antennas work smarter by utilizing multiple antennas to combine data streams arriving from different paths and at different times to increase data throughput and range compared to a single antenna using the same radio transmit power. By transmitting multiple data streams at the same time, wireless capacity is increased.

Additionally MIMO antennas improve link reliability and experience less fading than a single antenna system. MIMO antennas use spatial diversity technology, which puts surplus antennas to good use. When there are more antennas than spatial streams, the antennas can add receiver diversity and increase range.

Radio-wave multipath

Asus AC5600 routerMIMO technology takes advantage of a natural radio-wave phenomenon called multipath to improve wireless performance. In the past, multipath caused interference and slowed down wireless signals. With this iteration, Wi-Fi takes advantage of multipath. With multipath transmitted information bounces off walls, ceilings, and other objects, reaching the receiving antenna multiple times via different angles and at slightly different times

MIMO technology takes a single data stream and breaks it down into several separate data streams and sends it out over multiple antennas. This technique provides redundancy. The receiving MIMO antenna will “look” at each stream being sent to determine the strongest one to choose.

Legacy wireless devices use Single-Input Single-Output (SISO) technology. These devices cannot take advantage of multipath, and can only send or receive one spatial stream at a time.

802.11ac Wave 2 MIMO

A new version of MIMO has been developed. TechHive reports that Multi-user multiple-input, multiple-output (MU-MIMO) technology, enables AP’s to transmit and receive data from multiple Wi-Fi devices at the same time. Although the devices must also support MU-MIMO to utilize it, they aren’t required to have multiple antennas.

MU-MIMO was introduced with 802.11ac Wave 2. Wave 2 MU-MIMO support is required on both the access point and client device to work. It operates in the downstream direction, access point to the client, and allows an access point to transmit to multiple client devices simultaneously. This means networks with a dense number of users in an area, such as public Wi-Fi hotspots, could be able to handle more Wi-Fi devices.

TechHive warns the biggest caveat of MU-MIMO is it doesn’t directly improve the wireless speeds of uplink connections.

Only a handful meet the criteria today

MU-MIMO technologyIt’s also important to note that the only way to gain the full benefit of MU-MIMO is when the technology is supported on both the access point and the device that’s connecting to the AP. So in addition to having an 802.11ac adapter onboard, the client must explicitly support MU-MIMO—there are only a handful of adapters that meet that criteria today.

Finally, TechHive says MU-MIMO works best with stationary Wi-Fi devices. If users are walking around while watching a video on a smartphone or tablet, they are not going to get the full benefit of MU-MIMO even if that device supports it. Your router might even limit that connection to using SU-MIMO, so that the connection doesn’t negatively impact stronger MU-MIMO connections.

rb-

The client issue is the main reason 802.11ac Wave 2 will not be widely used in the enterprise. it is a big issue to keep the clients up to date to match the AP version. In fact, Zeus Kerravala at NetworkWorld points out that many of the high-volume manufacturers, such as Apple and Samsung, are skipping 802.11ac Wave 2 and plan to support IEEE 802.11ax in the future.

So skip Wave 2 devices in the enterprise and stick to an 802.11ac Wave 1 AP, and get exactly the same performance as its higher-priced Wave 2 counterpart.

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Switch Sales Stalled

Switch Sales StalledThe stats for sales of network switches are in for Q4 2017. Only one of the top 5 networking vendors was able to squeeze out a small gain in switch sales. The data comes from New York-based NPD. NPD tracks monthly network switch sales data from the sales channel, distributors, and resellers in North America.

The article on CRN notes that the total number of switches sold through the channel in the quarter was 514,095. The number is up slightly from 510,822 in the fourth quarter of 2016, according to NPD. Here are the five vendors that sold the most switches through the channel in the fourth quarter, according to NPD.

D-Link Systems

D-Link logoTaiwan-based D-Link Systems (2332:TT) sold 25,259 switches during the fourth quarter, according to NPD statistics. That total kept the company steady with the same period in 2016 when it sold 25,277. D-Link did not have a switch model among the top 10-selling units during the quarter. Its market share was unchanged at 4.9%, CRN said.

TP-Link switch sales

According to NPD’s data, of all the five best-selling switch brands, TP-Link saw the steepest decline during this period. The company based in Shenzhen, China sold 26,023 switches in Q4 ’17 compared with 29,798 in Q4 ’16. That’s a 12.7 percent year-over-year decrease. There is one bright spot for the firm, the article reports that the company’s TLSF1005D Ethernet switch was the third-best-selling unit during the quarter. But that was not enough to prevent a market share decline from 5.8 percent in 2016 to 5.1 percent in 2017.

Hewlett Packard Enterprise switch sales

HPE LogoThe news from NDP is not good for former networking giant Hewlett Packard Enterprise (HPE) either. The Palo Alto, CA-based firm saw a 1.8 percent decline in switches sold from 55,923 in Q4 ’16 to 54,941 switches in Q4 ’17. The quarter’s total was enough for a 10.7 percent market share, down slightly from the year-ago period. No HPE switch models were among the top 10 for the quarter, according to NPD.

Netgear sales

CRN reports that sales also slipped for Netgear. The number 2 switch company saw its market share dip from 18.3% to 17.9% year over year. The California-based firm sold 92,274 switches through the channel in the fourth quarter, down slightly from the 93,531 it sold in the same period a year ago, NPD said. Netgear had four switches in the top 10-best-selling switches during the quarter, including the top two models, the FS105 and GS105NA five-port models.

Cisco switch sales

Cisco (CSCO) was able to hold on to the #1 switch vendor position according to NDP. It sold 225,051 units during the period, a 5.7 percent increase that boosted the company’s market share to 43.8 percent from 41.7 a year earlier. Six of the top 10 best-selling switches in the quarter were Cisco Catalyst‘s led by the WS-C2960X 24– and 48-port models.

rb-

What happened to the network switch market? It’s still reeling from the 2007/08 recession and the Wi-Fi takeoff. Other than the Cisco switches, most of the top switch models sold were unmanaged, desktop switches limited to 100 Mbps uplinks. These types of switches make it OK to randomly add an unauthorized switch at the desktop and POOF there does your data. These desktop switches with their limited feature set don’t include Spanning Tree, so users can create a network loop and take down the whole network segment.

Not much to shout about.

Where are the vendors? Brocade? Extreme? Juniper? Dell? I am old enough to remember when switch manufacturers had a #2 strategy. 3Com, Lucent, Bay/Nortel all came into my office and said they wanted to #2 – now they are gone.

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Worst Passwords – 2017

Worst Passwords - 2017Today is “Safer Internet Day” which is needed. Despite the spate of well-publicized hacks, attacks, ransoms, and even extortion attempts, millions of people continue to use weak, easily guessable passwords to protect their online information. SplashData, provider of password management applications has released its annual Worst Passwords of the Year (NSFW) list. The seventh annual report was compiled from more than five million passwords leaked during 2017.

FSplashData logoor the fourth consecutive year, “123456” and “password” held on to the number 1 and #2 spots on the SplashData list. Variations of each, either with extra digits on the numerical string or replacing the “o” with a “0” in “password,” make up six of the top 10 most often used passwords. Morgan Slain, CEO of SplashData warns, “Hackers know your tricks, and merely tweaking an easily guessable password does not make it secure.

Star Wars is popular

Star Wars fans were so excited by the recent premiere of “Star Wars: The Last Jedi“, that they moved “starwars” up to #16 on the most frequently used bad passwords list. SplashData’s Slain observed that it is not a good password.

Unfortunately, while the newest episode may be a fantastic addition to the Star Wars franchise, ‘starwars’ is a dangerous password to use … Hackers are using common terms from pop culture and sports to break into accounts online because they know many people are using those easy-to-remember words.

Another problem with many of these bad passwords, they are simply a straight row of characters across the keyboard making them easy for attackers to guess. Pattern passwords in the bad list include:

  • Password12345
  • 123456
  • 1234567
  • 12345678
  • 123456789
  • qwerty
  • qazwsx
  • 1qaz2wsx

SplashData’s 25 worst passwords of 2017:

1 – 123456
2 – password
3 – 12345678
4 – qwerty
5 – 12345
6 – 123456789
7 – letmein
8 – 1234567
9 – football
Sisyphus10 – iloveyou
11 – admin
12 – welcome
13 – monkey
14 – login
15 – abc123
16 – starwars
17 – 123123
18 – dragon
19 – passw0rd
20 – master
21 – hello
22 – freedom
23 – whatever
24 – qazwsx
25 – trustno1

SplashData estimates almost 10% of people have used at least one of the 25 worst passwords on this year’s list, and nearly 3% of people have used the worst password, 123456.

SplashData offers these tips to be safer from hackers online:

1. Use passphrases of twelve characters or more with mixed types of characters including upper and lower cases.
2. Use a different password for each of your website logins. If a hacker gets your password they will try it to access other sites.
3. Protect your assets and personal identity by using a password manager to organize passwords, generate secure random passwords, and automatically log into websites.

rb-

Sighs – I covered this again and again ……

One older report I’ve seen says that attackers were able to crack open 254,776 of 499,556  (51%) hashed passwords within 24 hours and 439,610 (88%) within two weeks. The same report says that it can only take one day to crack an eight-character password, while it takes an average of 591 days to crack a 10 character password. 

Another report on password hacks points out the value of each additional character in a password.

  • A 6-character password with only letters has 308,915,776 possible combinations.
  • An 8-character password with only letters has 208,827,064,576 possible combinations.
  • An 8-character password with letters (upper & lower case) and includes numbers and symbols has 6,095,689,385,410,816 possible combinations.

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Browser Security Updates

Browser Security UpdatesIf you bank, shop, or work on the Intertubes your security is changing. Your browser Security is changing because Symantec is selling its Website Security and related PKI business to PKI encryption solutions to DigiCert for nearly $1 Billion.

SSL and TLS logoExperts estimate that Symantec (SYMC) owns 40% of the SSL certificate market. SSL/TLS certificates are used to encrypt the connections between browsers and HTTPS-enabled websites. The certificates are used to verify that users are actually visiting the websites they intended to and not spoofed versions. Certificates are issued by organizations known as certificate authorities that are trusted by default in browsers and operating systems.

As a result of the sale, many firms are going to have to reissue SSL/TLS server certificates. The reissued certs will ensure browser security and make sure there is no impact on your online experiences. These certificates are essential to ensure secure, encrypted communication for user interaction on the Intertubes.

Google Chrome browser security

Google (GOOG) has led the effort to decrease the disruption that could come along with this change. Google posted a plan back in July of 2017 regarding Symantec-issued SSL/TLS server certificates.

• In March 2018 Google Chrome (Chrome 66 Beta) will show a warning for sites secured with SSL/TLS certificates issued before June 1, 2016. Your security is at risk and data encryption will function normally, but your transactions will be disrupted by a warning in Chrome.
• Google has also stated that all SSL/TLS certificates that had been issued by Symantec before December 1, 2017, will not be trusted starting in September 2018 (Chrome 70 Beta). Doing transactions at sites that have not been updated will put your security at risk, and you will get a warning in Chrome.

Mozilla Firefox

Mozilla, publisher of the Firefox web browser says that it intends to follow the same timeline proposed by Google.

rb-
This change is a normal procedure for typical certificate renewal. There should be no service disruption when the new certificates are issued as long as your web browser is up to date. There is no reason to have an out-of-date browser anymore. All three major browsers will auto-update. Other keys to staying safe online include:

  • Always check for HTTPS when you plan on providing personal data to a website. Always check for HTTPS
  • Pay attention to any security warnings you receive when you visit a website. Although you can almost always trust the HTTPS you see in your browser URL, any additional warnings from your browser should show that there may be a problem with the connection, so you should proceed with caution.

Nearly 54% of all U.S. web browsers will be affected by these changes. Statista says that Chrome held almost 50% of the browser market share and Firefox held over 5% of the share in December 2017. 41% of Internet users are not covered by this change (Safari 32.7% and IE/Edge 9%).

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.