Showing posts with label microsoft. Show all posts
Showing posts with label microsoft. Show all posts

Tuesday, December 6, 2011

The Personal Computer Is Dead ?


Saying that the personal computer is dead may or may not be premature. However, I just read an article that makes this assertion, and I'd like to suggest that you read it too.


Click here to read The personal computer is dead by Jonathan Zitttrain. He says in conclusion,

"A flowering of innovation and communication was ignited by the rise of the PC and the Web and their generative characteristics. Software was installed one machine at a time, a relationship among myriad software makers and users. Sites could appear anywhere on the Web, a relationship among myriad webmasters and surfers. Now activity is clumping around a handful of portals: two or three OS makers that are in a position to manage all apps (and content within them) in an ongoing way, and a diminishing set of cloud hosting providers like Amazon that can provide the denial-of-service resistant places to put up a website or blog.
"

Wednesday, April 13, 2011

HTTPS, Certificates and Web Security Reconsidered

The Comodo Group, an Internet security company, has been attacked in the last month by a talkative and professed patriotic Iranian hacker who infiltrated several of the company’s partners and used them to threaten the security of myriad big-name Web sites.

But the case is not a problem for only Comodo, which initially believed the attack was the work of the Iranian government. It has also cast a spotlight on the global system that supposedly secures communications and commerce on the Web.

The encryption used by many Web sites to prevent eavesdropping on their interactions with visitors is not very secure. This technology is in use when Web addresses start with “https” (in which “s” stands for secure) and a closed lock icon appears on Web browsers. These sites rely on third-party organizations, like Comodo, to provide “certificates” that guarantee sites’ authenticity to Web browsers.

But many security experts say the problems start with the proliferation of organizations permitted to issue certificates. Browser makers like Microsoft, Mozilla, Google and Apple have authorized a large and growing number of entities around the world — both private companies and government bodies — to create them. Many private “certificate authorities” have, in turn, worked with resellers and deputized other unknown companies to issue certificates in a “chain of trust” that now involves many hundreds of players, any of which may in fact be a weak link.

The Electronic Frontier Foundation, an online civil liberties group, has explored the Internet in an attempt to map this nebulous system. As of December, 676 organizations were signing certificates, it found. Other security experts suspect that the scan missed many and that the number is much higher.

Making matters worse, entities that issue certificates, though required to seek authorization from site owners, can technically issue certificates for any Web site. This means that governments that control certificate authorities and hackers who break into their systems can issue certificates for any site at will.

Experts say that both the certificate system and the technology it employs have long been in need of an overhaul, but that the technology industry has not been able to muster the will to do it. “It hasn’t been perceived to be a big enough problem that needs to be fixed,” said Stephen Schultze, associate director of the Center for Information Technology Policy at Princeton. “This is a wake-up call. This is a small leak that is evidence of a much more fundamental structural problem.”

In the Comodo case, the hacker infiltrated an Italian computer reseller and used its access to Comodo’s systems to automatically create certificates for Web sites operated by Google, Yahoo, Microsoft, Skype and Mozilla. With the certificates, the hacker could set up servers that appear to work for those sites and try to view the unscrambled e-mail of millions of people, experts say. Comodo says it has suspended the Italian reseller and a second European reseller that the hacker also infiltrated.

In a series of online messages teeming with bravado, the hacker described himself as a software-engineering student and cryptography expert and said he worked alone. He suggested he was avenging the Stuxnex computer worm, which was directed at Iranian nuclear installations last year. And he indicated that he intended to use the certificates he created to snoop on opponents of the Iranian regime. “As I live, you don’t have privacy in Internet, you don’t have security in digital world,” he warned.

The certificate system was created at the dawn of e-commerce in the early 1990s before security was a major issue. Security experts say the system is not up to the challenge of today’s immense, commercial and much-attacked Internet. It was designed primarily to let businesses take credit card payments online, and less to confirm the authenticity of Web sites.

The crucial tool available to Comodo and the browser makers — revocation — is ineffective, security experts say. After the Comodo case, Google, Mozilla and Microsoft rushed out patches so their browsers would recognize and reject the bad certificates. But this solution requires many millions of Internet users to update their browser software, which many people never do.

Moreover, because certificate authorities’ servers are seen as unreliable, most browser makers allow users to proceed to an alternative site, and hackers can exploit this weakness, security experts say.

Browser makers have another problem: Faced with a suspicious certificate authority, there is little they can do shy of rescinding it. But if they did that, millions of Web users might encounter troubling error warnings when they visited sites with certificates from that company, causing a cascade of problems for users and site owners. Cutting out a large player like Comodo, which controls at least 95,100 active certificates, could effectively “break the Web,” said Dan Kaminsky, chief scientist at the security firm DKH.

They are effectively “too big to fail,” said Christopher Soghoian, a former Federal Trade Commission technologist who is now a graduate fellow at the Center for Applied Cybersecurity Research at Indiana University. “The problem is that the browser vendors don’t have a small stick, they only have a big stick." He said he could not recall a single instance in which the browser vendors had rejected a certificate authority.

Microsoft and Mozilla said that they would consider removing certificate authority if it was in the best interest of Internet users, and that they remained in talks with Comodo about its security practices. “Participation in Mozilla’s root program is a privilege, not a right,” the company, the nonprofit maker of Firefox, said. Apple, maker of the Safari browser, declined to comment. (Google’s Chrome browser defers to the choices of operating system makers like Microsoft and Apple about which certificate authorities are accepted.)

Mozilla, Microsoft and Google said they would work together and with certificate authorities and the security community on improvements to the system. One approach proposed by Comodo and Google engineers in January would allow Web site owners to specify which certificate authorities may issue certificates for their sites.

An initiative preferred by security experts would overhaul the system more radically. It would give Web sites similar control while securing their certificates within a new encrypted version of the domain name system, the central directory of the Web, making it the de facto central certificate authority through which Web sites could generate their own certificates.

Tuesday, July 13, 2010

Epocrates Mobile Electronic Health Record

Health care delivery is now moving away from a specific location and into a virtual care space, where patient medical records and real-time clinical data will reside.

There has also been a revolution in access to clinical reference material, and physicians and other care providers are moving core scientific knowledge from books to apps. Today’s doctors are no longer what they can memorize.

Throughout this blog, I've been discussing many of the components of Electronic Health Record (EHR) systems that will likely be used in the larger systems installed throughout entire hospitals and regions. However, 50 percent of physicians in the US work in small or solo practices.

The Epocrates EHR is specifically targeting the solo practitioner and the small physician groups, which have different needs from the larger enterprise care facilities that so many EHR providers are pursuing. To that end, Epocrates says that it has "teamed up with a very well known” but still undisclosed practice manager partner, whose software will be integrated into the Epocrates EHR for calendaring, scheduling, appointments, billing and more.

The as-yet-not-released Epocrates EHR app will include the company's drug and safety content and will, they say, meet “meaningful use” and HIPAA compliance requirements.

There are offerings from other vendors such as Microsoft and Symantec too, but I've decided to look at Epocrates Mobile EHR because Epocrates was the first company to introduce a medical app for the iPhone. Furthermore, as seen in the image below, their app is now available for many of the popular hand-held smart devices.











Their fully functioning mobile EHR app will work both when connected and disconnected. It’s not enough to just have a mobile EHR, of course, and it is also a fully featured, web-enabled desktop application, too.

The mobile and desktop versions may have the same functionalities, but the different form factors will likely lead to certain applications being favored on each.

There is a functional parity between their mobile and web interface. The information will be delivered differently and the iPhone version will be used for some use cases more often than the desktop version and vice versa. These two platforms are complementary, so Epocrates is not necessarily "leading" with mobile.

Unlike some mobile “portals” to EHR systems, Epocrates offering is a native app with patient data stored in it.

One differentiator between the Epocrates mobile EHR app and some others is that theirs will be a native app and it will store patient data on the device. Users will interact with the EHR differently from a mobile device vs. a desktop client. The iPhone interface is not ideal for text entry, so they are looking for other ways to get information into the device. The iPhone interface will be used more for things like dictation, while the desktop interface won’t be used for that as much. From a task perspective, though, they are not looking to hobble the handheld interface in any way.

Click here to see new apps from Epocrates

Click here to see the Dragon speech-to-text application on a hand-held device

Epocrates is launching an EHR offering now because of the increase in EHR adoption because of the ARRA deadlines for stimulus fund incentives payments. These external deadlines are encouraging physicians to adopt EHR, making it an ideal time to enter the market.

There are also drivers from the technology perspective as well. It’s a good time to enter the market with a mobile EHR because more clinics have a high penetration of smartphone users. Also, 3G wireless networks now have higher bandwidth – enough to support these kinds of applications. Physicians rarely take note of [mobile] Internet connectivity issues anymore. Note: I've also talked a little about the less-ubiquitous 4G (WiMax) networks in earlier posts.

Epocrates plans to integrate the features of the iPhone, such as the camera, as well as dictation directly into the app, an interesting feature especially in light of the recent announcement by Nuance that they will be shipping a medical transcription application for the iPhone.

Epocrates will also utilize the iPhone’s Push Notification Service to alert doctors of important or timely information (and hopefully not overuse it). Given Epocrates’ depth of knowledge of pharmaceutical formularies, e-prescribing will be built in.

Although the mobile application will synchronize with the web application, it will continue working even when there is no internet connection. Data will be stored on the handheld device in a secure, encrypted manner and synchronize when a connection is available, a real issue for hospitals where there are many “dead” zones. And, there will be condition-based templates for easy entry of clinical information.

There will also be integration with a revenue-cycle platform so physicians can charge and submit codes, through a partnership with a “known” company. Epocrates anticipates they will achieve Certification Commission for Health Information Technology (CCHIT) certification by the time of release. The EHR will be delivered as a software-as-a-service (SAAS) model, meaning the physician will effectively lease, not purchase it.

This could be an attractive low-cost product for solo or small group physicians who do not have complex office staff EHR integration needs. In particular, for the physician who already uses their smart phone for many work activities, the potentially painless transition to using it as the primary interface into their office EHR may be very appealing.

Stay tuned.

Click here to see Epocrates executives at HIMSS 2010

Click here to see Andy Wiesenethal, Kaiser Permanente at HIMSS 2010

As an aside, I'd like to note that when Epocrates Online can be accessed with a browser on which Google's (or other) translation app has been installed, as shown in the image below.

Thursday, April 15, 2010

Apple’s SDK brouhaha explained for non-developers


So what’s up with Apple this week? In short, they are now the dominant platform in a space, and they intend to maintain that dominant position for as long as possible by preventing the ability to write an application once and run it anywhere. Apple’s tactics for maintaining their dominance are: bullying and complexity. They’re the same tactics use by every computer platform dominator (e.g., IBM, AT&T, and Microsoft)
before them. All of this has happened before, and it will happen again. Click here for Brent Noorda's take on Apple’s SDK brouhaha.

An update (5/4/2010):

The Federal Trade Commission and the Department of Justice are exploring whether to open an antitrust inquiry into Apple over its recent actions restricting developers writing apps for its iPhone operating system.

The basis for a potential antitrust probe stems from Apple’s recent changes to its iPhone software developer kit. The changes, which were quietly rolled out during the announcement of the company’s new iPhone 4.0 operating system, made it clear that Apple would no longer allow apps into the iTunes iPhone and iPad store that are built using third-party programs.

The sudden changes to Apple’s rules came just days before Adobe was set to showcase its newest software update to its Flash authoring tools. The feature, called Packager for iPhone, would make it easy for developers to produce iPhone applications using Adobe’s software.