tag:blogger.com,1999:blog-84879618653634996962008-08-27T15:45:40.312-07:00The Osterman Research BlogA blog focused on messaging and collaboration of all types -- email, instant messaging, VoIP, Web conferencing and other technologies that help people communicate more efficiently and effectively.Michael D. Ostermannoreply@blogger.comBlogger42125tag:blogger.com,1999:blog-8487961865363499696.post-59621683789282767792008-08-27T15:24:00.000-07:002008-08-27T15:45:33.674-07:00Messaging-related mergers continueToday's acquisition of PostPath by Cisco for $215 million is the latest in a string of recent messaging-related acquisitions that include McAfee's acquisition of Reconnex, Proofpoint's acquisition of Fortiva, Sophos' acquisition of Ultamico, Symantec's acquisition of PC Tools, MessageLabs' acquisition of Fortium ICA Limited, and Quest's acquisition of Akonix, just to name a few of the recent acquisitions that have taken place. There is even talk of Cisco acquiring McAfee.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-65398015583364349762008-07-29T02:24:00.000-07:002008-07-29T02:28:54.105-07:00A new spam techniqueOn Monday, Commtouch discovered an interesting spammer technique. This new approach sends an email that includes a link to a Flash file, not to an HTML page that includes an embedded Flash file. The .SWF file is hosted on a free image hosting site and, when clicked, simply redirects victims to a Canadian pharmacy spammer site.<br /><br />More information is available on Rebecca Herson's blog at:<br /><br />http://blog.commtouch.com/cafe/spam-favorites/flash-in-the-spam/Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-18236676850054804782008-07-28T18:00:00.001-07:002008-07-28T18:05:29.046-07:00Online threats are more rapid than everIBM will release the Internet Security Systems X-Force report that discusses the speed with which new exploits are released. Among the highlights:<br /><br />- 94% of Web browser exploits are available within 24 hours after flaws are discovered. In 2007, that figure was 79%.<br /><br />- 80% of PC vulnerabilities are exploited within 24 hours of their discovery, up from 70% in 2007.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-37356880800601802262008-06-18T08:17:00.000-07:002008-06-18T08:21:15.545-07:00How do you define "SMB"?I'm currently attending Trend Micro's first Analyst Day in New York. Steve Quane, executive general manager of Trend's SMB Business Unit offered a great way to define the small and mid-sized business market for security solutions: if you ask a decision maker in a company to define "hash" and they respond with either "breakfast" or "controlled substance", they're an SMB customer. :)Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-41181767121551153542008-06-04T09:22:00.000-07:002008-06-04T09:24:24.747-07:00AOTA SummitSitting in the first session of the Authentication & Online Trust Alliance (AOTA) Summit in Seattle as I write this. Fairly well attended and lots of interesting content expected. More to come...Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-66332315826606747452008-05-29T16:54:00.000-07:002008-05-29T17:09:51.149-07:00NemX SecurExchangeNemX announced today SecurExchange for Microsoft Exchange 2007. The company claims to be "the first vendor to offer a full <br />suite of rich, powerful and flexible email compliance functionality for the Exchange 2007 platform."<br /><br />SecurExchange is an important offering, particularly in light of the growing importance of searching email and other electronic content for e-discovery and content scanning purposes. For example, SecurExchange can scan emails for concepts related to certain words instead of just the words themselves. As noted in the company's press release, when searching for the concept of "Confidential", the system will place greater weight on the word when used in the footer of a document than if it is used in the body text. SecurExchange will also scan strings of numbers not only for the presence of a 15- or 16-digit number that might indicate a credit card number being sent in clear text, but will also perform a checksum to verify the validity of that number.<br /><br />Our research has found that email volumes are growing at roughly 30% per year. That means that the volume of email sent or stored will be roughly 3.7 times greater in five years than today. That will make the importance of tools that can intelligently scan email content ever more important.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-75915342890789713002008-05-21T06:23:00.001-07:002008-05-21T06:26:31.528-07:00MER ConferenceI spoke at the Cohasset Associates MER (Managing Electronic Records) Conference in Chicago yesterday and am attending the keynotes today, as well. This is a small conference (about 500 people) focused on records management, but there has been a great deal of discussion on email and electronic content archiving. I would highly recommend this conference to anyone interested in email archiving and the broader implications it has for overall records management practices.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-83490173870481313252008-05-01T17:36:00.001-07:002008-05-01T17:54:21.507-07:00How much money do Italians make?Now you can find out. The Italian government posted the earnings of every Italian on the Web. More information is available here:<br /><br />http://news.bbc.co.uk/2/hi/europe/7376608.stm<br /><br />While this was apparently legal according to Italian law, many were very upset by the decision of the outgoing government to post this data. For those countries in which posting sensitive information or other confidential data isn't legal, it points out the critical nature of deploying data leak protection (DLP) systems that will guard against intentional or inadvertent breaches. Our research shows that these types of systems are seriously underdeployed, making the breach of corporate data all too likely.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-9016369336154110942008-04-17T04:08:00.000-07:002008-04-17T04:13:17.903-07:00IT spending in 2008We have just concluded a large survey on email, Web and IM security among mid-sized and large organizations in North America and will be publishing a report on our findings shortly. One of the questions we asked was about overall IT spending plans in 2008 -- here's what we found:<br /><br />48% of organizations will spend more in 2008 than in 2007<br />18% will spend less<br />28% will spend about the same<br />6% are not sureMichael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-54766425230766595662008-04-08T16:24:00.001-07:002008-04-08T16:33:59.994-07:00Interact 2008I attended Interact 2008 in San Diego today and will be at RSA tomorrow. Interact offers a nice view into what Microsoft is doing in the UM and UC spheres, with lots of good information provided in a number of sessions, including some frank comments on areas in which Microsoft needs to bolster its UM and UC offerings.<br /><br />Some observations:<br /><br />- Microsoft views Exchange as a mature offering that, in some ways, will act as a "mentor" for OCS. OCS will steal some best practices from Exchange, such as the capabilities of Systems Center, improvement of the command line interface in OCS and working with common partners for both platforms. Microsoft's goal is to make both Exchange and OCS "look like they come from the same vendor".<br /><br />- Exchange and OCS share some of the same architectural focus and engineering, but different business pressures force them to be "out of phase" with one another, although Microsoft anticipates coordinating Exchange and OCS to a greater degree in the future.<br /><br />- Saw an impressive demonstration of Exchange UM in action; each server can support about 10,000 users.<br /><br />- There are currently 71,316 users at Microsoft on Exchange UM.<br /><br />In all, Interact 2008 was definitely time well spent even if San Diego was cold and windy today.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-20041329035266807342008-04-01T10:17:00.000-07:002008-04-01T10:21:13.945-07:00More changes in the hosted marketmindSHIFT Technologies has acquired Collaboration Online Limited Company, owner of groupSPARK and AgileWave CRM. mindSHIFT is a managed services provider that offers a variety of managed and SaaS services. The acquisition will expand the company's hosted Exchange, hosted SharePoint and CRM offerings.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-48306930176867273422008-03-31T17:05:00.000-07:002008-03-31T17:48:44.552-07:00Analysts and the Al Gore Keynote Policy at RSA ConferenceFrom the organizers of the RSA Conference, a conference I hold in very high regard:<br /><br />"Dear Michael:<br /><br />For the last 17 years, RSA Conference keynote speakers have brought a wealth of knowledge and experience to Conference attendees. Continuing that tradition, we've recently announced that the closing keynote speaker at RSA Conference 2008 will be former Vice President Al Gore. In accordance with the agreement with Vice President Gore, members of the press will not be permitted to attend his keynote presentation.<br /> <br />RSA Conference offers industry analysts a free, all-inclusive press badge that provides full access to all resources, sessions and the press room while attending the show. Given that industry analysts are provided press badges, you will also be precluded from attending former Vice President Gore's keynote. Anyone with media credentials will be seated in a special press section for The Hugh Thompson Show on Friday afternoon and will be escorted out at its conclusion, prior to former Vice President Gore taking the stage. If Conference staff notices anyone with a press badge is found in the keynote room during Gore's speech, they will ask that person to leave immediately. We apologize for any inconvenience this may cause. <br /> <br />We are looking forward to seeing you next week."<br /><br />Any theories as to why Mr. Gore doesn't want the press -- and anyone outside the live event -- to know what he will say?Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-21486662772687603852008-03-26T13:35:00.000-07:002008-03-26T16:09:58.744-07:00DLP is getting interestingWe've all heard of incidents of data theft from lost laptops, lost backup tapes, hackers getting into email systems, etc. But how safe is your passport information?<br /><br />We heard last week that the confidential passport information of Senators Clinton, McCain and Obama had been breached. Now, there's news that the electronic passport information of perhaps 20 Americans has been breached.<br /><br />I also read today that new US passports contain an RFID chip and an antenna designed to transmit information on the passport during screenings at the border. US passport production is outsourced to a company in the Netherlands that inserts the RFID chips, then passports are sent to another operation of the company in Thailand for the insertion of the antenna, after which the passports are sent to Washington, DC for final assembly. The company that assembles the passports revealed in October 2007 that someone in China had stolen its technology for the RFID chips used in passports.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-80479808322506940722008-03-23T12:13:00.001-07:002008-03-23T12:13:33.897-07:00Presence, corporate culture and personal preferencePresence - the ability to know another's status - is an incredibly useful tool. It allows you to know when someone is at their desk and is likely available for interaction in real time. Presence can serve as a sort of informal time clock that allows you to know when co-workers have arrived in the morning. It can allow you to get questions answered quickly and easily using an instant messaging client, for example.<br /><br />However, unlike store-and-forward technologies like email or voicemail, presence requires the right corporate culture and the right mindset for organizations to derive the greatest value from it. As most users of an instant messaging system will admit, receiving an IM at an inopportune time is usually more irritating than helpful, which has resulted in the ability to selectively provide presence information only to specific individuals or groups in a variety of clients.<br /><br />More importantly, however, is the role of personal preference in the success of presence. For example, do you really want others to know your presence at all times - when you're at your desk, on a mobile device, when you've turned on your laptop, etc.? For those that resist the publication of this data, how do you convince them to embrace the benefits of presence?Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-2150750378731834302008-03-18T08:06:00.000-07:002008-03-18T08:20:53.046-07:00What is the future of Novell?Novell develops some very good technology -- sitting in the Analyst Summit at BrainShare as I write this is testament to what they've done and where they want to go with virtualization, identity management, usability and a host of other initiatives. Plus, anecdotes about the ability to support very large GroupWise environments with very few FTE staff members abound, and downtime is often very low in GroupWise deployments.<br /><br />That said, Novell continues to lose market share to rivals Microsoft and IBM in particular, but also to others. Why? Many have cited Novell's marketing efforts, others focus on Novell's heavy focus on administration and less on user interface design.<br /><br />What's your take, particularly if you've migrated away from GroupWise to some other messaging or collaboration platform? Is it that IT departments are simply forced to migrate because senior, non-IT managers like Outlook and force a move to Exchange? Is there concern about the long term direction of Novell?<br /><br />I'd love to get your feedback.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-19446543278698347012008-03-11T16:32:00.000-07:002008-03-11T16:42:02.473-07:00Disaster recovery plusI was just given a briefing by a company that has developed a very interesting technology that synchronizes Outlook content with the data store of another leading messaging system (I can't be more specific about the identities because the product has not yet been announced). The demo I received demonstrated very good performance, allowing email content, calendar entries, contacts, etc. to be entered into Outlook and then appear within just a couple of seconds in the other messaging system. Synchronization back to Outlook worked equally as well.<br /><br />This client-side product will have a number of uses, but on the short list will be selective disaster recovery for individuals within a company without having to roll out an entire DR system, as well as allowing users to access their email without the Outlook client, OWA or an Exchange Server.<br /><br />The offering is planned for announcement either later this month or in early April and pricing has yet to be determined.<br /><br />I was quite impressed by what I saw.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-10959524924062922862008-02-12T11:24:00.000-08:002008-02-12T11:29:23.036-08:00Two more acquisitions todayThe acquisitions in the messaging space continue:<br /><br />Dell acquired MessageOne for $155 million, continuing Dell's acquisitions designed to make the company a leading provider of SaaS services.<br /><br />TeraCloud acquired startup archiving provider Estorian.<br /><br />These acquisitions point to the growing interest in archiving for a variety of applications, from storage management to legal discovery to regulatory compliance. While there continue to be those who don't believe in the value of archiving, consensus will be coalescing around the growing need to archive messaging and other content.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-24003069581539247522008-02-01T03:39:00.000-08:002008-02-01T03:42:54.283-08:00Microsoft buying Yahoo!Just heard a report that Microsoft is willing to purchase Yahoo! for $44.6 billion. From a messaging pespective, this would give Microsoft a huge addition to its consumer email base and would give Microsoft Zimbra, a very nice offering that includes business-grade email, archiving and other capabilities.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-58030168095439613802008-01-21T15:18:00.002-08:002008-01-21T21:48:06.020-08:00IBM Announces BluehouseAt Lotusphere on Monday, IBM announced Bluehouse, a set of hosted collaborative offerings aimed at the SMB market. The offering is planned for rollout during the next three to four months.<br /><br />More to follow...Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-59891852068049678752008-01-15T22:34:00.000-08:002008-01-16T10:09:07.836-08:00What is 'unreasonable' in the Fourth Amendment?The following is not intended to be partisan in any way, and neither for or against any particular candidate, government official, etc. I don't share my political beliefs in these types of forums, so nothing of a political or partisan nature should be read into this post.<br /><br />The Fourth Amendment to the US Constitution reads as follows:<br /><br />"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."<br /><br />While a case can be made that even a physical search of laptops, luggage, etc. prior to boarding a flight violates the Fourth Amendment, there are few that would want to fly on an airplane whose passengers' luggage was not searched. To me, airport security checks are a 'reasonable' type of search and are consistent with both the text and spirit of the Fourth Amendment.<br /><br />However, the US Federal courts have recently ruled that anyone entering the United States is subject to a search of the files on their laptop computers or other mobile devices. Is this unreasonable? I think so. Such a search, without probable cause, is clearly in opposition to the intent of those who wrote the Fourth Amendment. While the upside of such searches is that they can catch child pornographers, the downside is that your confidential records are now subject to inspection by TSA, customs or other officials without any sort of probable cause, warrants or any other protections that used to protect you.<br /><br />The easy way to avoid this kind of search is not to carry confidential files with you. While this is inconvenient, it does protect your data from searches, as well as from data loss in case you lose your mobile device. You can use hosted services or other remote data stores to house your data while traveling, but this is not always as convenient as having the files stored locally.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-32492948402623855342008-01-04T11:04:00.000-08:002008-01-04T11:10:01.598-08:00The FRCP and the Sub-Prime MeltdownAutonomy, which purchased ZANTAZ for $375 million last year, has just won a $70 million archiving contract with a bank. The deal, which is far bigger than any Autonomy had previously won, seems to be driven primarily by the new amendments to the Federal Rules of Civil Procedure (FRCP) that took effect on December 1, 2006. Some speculate that banks will be a key market for archiving technology directly as a result of the meltdown of the sub-prime market -- many lawsuits will be launched against banks and archiving appears to be a key technology to which banks are looking as they anticipate a wave of litigation resulting from the credit crunch.<br /><br />More detail is available at http://business.timesonline.co.uk/tol/business/markets/article3129335.eceMichael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-59165491990275585752007-12-14T13:42:00.000-08:002007-12-14T17:06:34.039-08:00Growing Interest in the FRCPThe new amendments to the Federal Rules of Civil Procedure (FRCP) were passed about 54 weeks ago and they are starting to have a significant impact on the way that organizations view their electronic assets. However, that impact is still not reaching to all organizations that are at risk of heavy penalties for a failure to archive properly in support of e-discovery. Consider, for example, that Morgan Stanley had to pay a $15 million fine in 2006 for not saving email properly and paid $3 million earlier this year for not providing email and taking appropriate supervisory measure to preserve email content. Wachovia paid a fine of $2.25 million for not fully complying with SEC 17(a). In March 2006, paid a fine of $2.5 million SEC fine for not properly archiving email. In March 2004, Bank of America was fined $10 million by the SEC for its failure to keep email records regarding its recent merger and for taking too long to comply with regulatory requests.<br /><br />While most of the judgments so far have focused on violations of regulations in the financial services space, FRCP will have a much bigger impact for one simple reason: it applies to virtually all companies that might be involved in litigation in the Federal courts. When individual states impose their own version of FRCP, the stakes will get dramatically higher.<br /><br />Bottom line: establish good data retention practices and keep your business records that are contained in email and in your other electronic data stores. Failure to do so will hurt.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-56873852460163624422007-11-16T02:15:00.000-08:002007-11-16T02:34:22.633-08:00On Web conferencing and travelHow much could an organization save if it used a Web conference to replace a four-hour meeting in a city that is a two-hour flight away? Consider the following:<br /><br />Airfare: $250<br />Taxi: $40<br />Meal: $10<br />Time spent driving to and from the airport: 1h 30m<br />Time spent waiting for flights: 2h 30m<br />Time spent in flight: 4h<br />Fully burdened annual salary: $100,000<br />Hours worked per day: 10<br /><br />Even if we conservatively assume that only one hour of the waiting and flight time is unproductive, that means that the total cost of a four-hour meeting in another city based on the assumptions above is $340. Would Web conferencing be a useful replacement for at least some off-site meetings? In many cases, absolutely yes.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-21106099858301631902007-11-08T23:38:00.000-08:002007-11-08T23:59:52.510-08:00Exchange ConnectionsI attended the Exchange Connections conference in Las Vegas this week. I spoke with a large number of vendors, all of whom were quite favorably impressed with the booth traffic and the quality of the leads they were receiving. This may have been due, in part, to the significant number of attendees of the related conferences that were held concurrently, bringing in a larger number of individuals than might otherwise have been the case had the conference been held as a standalone.<br /><br />However, I think it's due more to the very dynamic nature of messaging at this point and the growing uncertainty on a number of fronts: the impact of competing data retention strategies, the potential for migration to new messaging systems, the uncertainty being generated by a variety of vendors, the growing push by hosted and managed messaging vendors, and so forth.Michael D. Ostermannoreply@blogger.comtag:blogger.com,1999:blog-8487961865363499696.post-33523412506815377232007-09-28T01:16:00.001-07:002007-09-28T01:21:53.530-07:00Hosted Lotus NotesWe hear alot about hosted Exchange, but less about hosted Notes/Domino or GroupWise. However, on September 18th, IBM announced a number of new capabilities and services, including a hosted Notes offering. The press release is available at:<br /><br />http://www-03.ibm.com/press/us/en/pressrelease/22327.wssMichael D. Ostermannoreply@blogger.com