cross pond high tech
159.9K views | +8 today
Follow
cross pond high tech
light views on high tech in both Europe and US
Your new post is loading...
Your new post is loading...
Scooped by Philippe J DEWOST
Scoop.it!

Microsoft has developed its own Linux

Microsoft has developed its own Linux | cross pond high tech | Scoop.it
Microsoft has developed its own Linux distribution. And Azure runs it to do networking.

Redmond's revealed that it's built something called Azure Cloud Switch (ACS), describing it as “a cross-platform modular operating system for data center networking built on Linux” and “our foray into building our own software for running network devices like switches.”

Kamala Subramanian, Redmond's principal architect for Azure Networking, writes that: “At Microsoft, we believe there are many excellent switch hardware platforms available on the market, with healthy competition between many vendors driving innovation, speed increases, and cost reductions.”

(Translation: Microsoft partners, we mean you no harm.)

“However, what the cloud and enterprise networks find challenging is integrating the radically different software running on each different type of switch into a cloud-wide network management platform. Ideally, we would like all the benefits of the features we have implemented and the bugs we have fixed to stay with us, even as we ride the tide of newer switch hardware innovation.”

(Translation: Software-defined networking (SDN) is a very fine idea.)

But it appears Redmond couldn't find SDN code to fits its particular needs, as it says ACS “... focuses on feature development based on Microsoft priorities” and “allows us to debug, fix, and test software bugs much faster. It also allows us the flexibility to scale down the software and develop features that are required for our datacenter and our networking needs.”

ACS is designed to use the Switch Abstraction Interface (SAI), an OpenCompute effort that offers an API to program ASICs inside network devices.
Philippe J DEWOST's insight:

So bizarre it might sound, this isn't any surprise if you remember that Microsoft's online services require datacenters with cost equations that cannot afford Dell machines running Windows. Microsoft has been a very early and massive supporter of Open Compute and networking is the next logical step to combine software with bare metal...

No comment yet.
Scooped by Philippe J DEWOST
Scoop.it!

Linux-on-the-desktop pioneer City of Munich now considering a switch back to Windows

The world is still waiting for the year of Linux on the desktop, but in 2003 it looked as if that goal was within reach. Back then, the city of Munich announced plans to switch from Microsoft technology to Linux on 14,000 PCs belonging to the city's municipal government. While the schemesuffered delays, it was completed in December 2013. There's only been one small problem: users aren't happy with the software, and the government isn't happy with the price.

The switch was motivated by a desire to reduce licensing costs and end the city's dependence on a single company. City of Munich PCs were running Windows NT 4, and the end of support for that operating system meant that it was going to incur significant licensing costs to upgrade. In response, the plan was to migrate to OpenOffice and Debian Linux. Later, the plan was updated to use LibreOffice and Ubuntu.

German media is reporting that the city is now considering a switch back to Microsoft in response to these complaints. The city is putting together an independent expert group to look at the problem, and if that group recommends using Microsoft software, Deputy Mayor Josef Schmid of the CSU party says that a switch back isn't impossible.

Schmid describes two major problems. The first is the issue of compatibility; users in the rest of Germany that use other (Microsoft) software have had trouble with the files generated by Munich's open source applications. The second is price, with Schmid saying that the city now has the impression that "Linux is very expensive" due to custom programming. Schmid also appears to be an Outlook fan, bemoaning the loss of a single application to crosslink mail, contacts, and appointments.

Philippe J DEWOST's insight:

Interesting spark in the neverending debate between acquisition, maintenance and usage costs.

No comment yet.
Scooped by Philippe J DEWOST
Scoop.it!

Highly critical “Ghost” allowing code execution affects most Linux systems

Highly critical “Ghost” allowing code execution affects most Linux systems | cross pond high tech | Scoop.it

An extremely critical vulnerability affecting most Linux distributions gives attackers the ability to execute malicious code on servers used to deliver e-mail, host webpages, and carry out other vital functions.

The vulnerability in the GNU C Library (glibc) represents a major Internet threat, in some ways comparable to the Heartbleed and Shellshock bugs that came to light last year. The bug, which is being dubbed "Ghost" by some researchers, has the common vulnerability and exposures designation of CVE-2015-0235. While a patch was issued two years ago, most Linux versions used in production systems remain unprotected at the moment. What's more, patching systems requires core functions or the entire affected server to be rebooted, a requirement that may cause some systems to remain vulnerable for some time to come.

The buffer overflow flaw resides in __nss_hostname_digits_dots(), a glibc function that's invoked by the gethostbyname() and gethostbyname2() function calls. A remote attacker able to call either of these functions could exploit the flaw to execute arbitrary code with the permissions of the user running the application. In a blog post published Tuesday, researchers from security firm Qualys said they were able to write proof-of-concept exploit code that carried out a full-fledged remote code execution attack against the Exim mail server. The exploit bypassed all existing exploit protections available on both 32-bit and 64-bit systems, including address space layout randomization, position independent executions, and no execute protections. Qualys has not yet published the exploit code but eventually plans to make it available as a Metasploit module.

Philippe J DEWOST's insight:

Can't refrain from correlating the announced remake of "Ghostbusters" by Hollywood and this "Ghost" Linux vulnerability story.

No comment yet.