Start up: Google eases Project Zero, Xiaomi’s patent woe, Microsoft’s big Office vision, driving helium, and more


“Flash, I love you – but we only have 90 days excluding public holidays and weekends to issue a fix for CVE-2013-6629!” Photo via Tom Simpson on Flickr

A selection of 8 links for you. Use them wisely. I’m charlesarthur on Twitter. Observations and links welcome.

Google amends bug disclosure policy following Apple and Microsoft scuffle » V3

Project Zero courted controversy when it publicly disclosed flaws in Microsoft’s Windows 8.1 and Apple’s Mac OS X operating systems.

Google moved to address these concerns, arguing that it may have applied the policy too rigorously but that public disclosure is effective.

“For example, the Adobe Flash team probably has the largest install base and number of build combinations of any of the products we’ve researched so far,” read the [Google] blog post.

“To date, they have fixed 37 Project Zero vulnerabilities (or 100 percent) within the 90-day deadline. More generally, of 154 Project Zero bugs fixed so far, 85% were fixed within 90 days.

“Furthermore, recent well-discussed deadline misses were typically fixed very quickly after 90 days. Looking ahead, we’re not going to have any deadline misses for at least the rest of February.

I fixed all of my Adobe Flash vulnerabilities in five minutes by removing Flash from my computer. However, Google’s position of playing private security guard to the internet remains discomforting, and I can’t help feeling that it’s going to prove embarrassing in some horrible way – a sort of schadenfreude-in-waiting.


Qualcomm deal sparks China smartphone patent skirmishes » Reuters

From last Friday (I didn’t link to it then), but as Ben Thompson points out, this element of the deal could have big implications – given that Xiaomi became China’s biggest smartphone vendor in 2014:

The settlement has allowed wireless patent holders like ZTE and Huawei Technologies to seek royalties, while introducing a new risk of litigation to China’s younger handset industry at a time when domestic patent law is gaining traction.

“For the first time, the settlement is forcing domestic manufacturers to recognize the value of IP (intellectual property) and consider how to use it strategically, which companies do in the West,” said Wang Yanhui, secretary general of the Mobile China Alliance, an industry consortium. “That’s the real significance of the (Qualcomm) settlement.”

The competitive dynamics are particularly complex in China, the world’s biggest smartphone manufacturer and consumer, as large Chinese telecom equipment makers that hold many essential patents for wireless technology also compete in the phone market against younger, nimbler manufacturers.

The settlement could prove tricky for companies like Xiaomi Inc, a four-year-old Beijing-based smartphone maker whose weak patent position has proved a major vulnerability. In December, a court in India temporarily halted its shipments there after Swedish telecom firm Ericsson complained Xiaomi had not been paying its royalties.

Although Xiaomi has been reported by Chinese media to be one of the handset makers now targeted by ZTE’s lawyers, both companies declined to discuss the issue.

But in response to questions from Reuters, Bin Lin, Xiaomi’s president, said he expects Xiaomi to only attract more patent threats and litigation from rivals in the future, as does any young firm that enjoys explosive growth.


Rembrandt Technologies wins $15.7m jury verdict in patent infringement case against Samsung » PRNewswire

A Texas federal jury has awarded $15.7 million to Rembrandt Wireless Technologies LP after finding that Korean electronics giant Samsung Electronics Co. Ltd. infringed on two Rembrandt patents covering Bluetooth technology.

Jurors deliberated only one hour before issuing the Feb. 13 verdict. The five-day trial focused on two Rembrandt patents, U.S. Patent Nos. 8,023,580 and 8,457,228. In addition to the $15.7 million award, Rembrandt also will receive royalty payments on all Samsung Bluetooth sales for the life of the patents.

Rembrandt, a Pennsylvania-based business technology company, sued Samsung and Blackberry Ltd. in 2013. Blackberry settled before the trial. Rembrandt argued that its patents for Bluetooth “enhanced data rate” inventions were infringed by Samsung in its Galaxy S phones.

That’s a brief deliberation, and a brief trial.


New cloud storage integration for Office » Microsoft Office Blogs

Kirk Koenigsbauer, corporate VP of Office:

We want Office to be the preferred way to work with documents no matter where they’re stored.  In November we announced a special partnership with Dropbox to make it easy to access, edit and share Dropbox files from the Office apps.  And today, in addition to the existing Dropbox integrations, we’re pleased to announce two new integration features for an even broader set of cloud services: First, file picker integration for the iPad and iPhone; and second, Office Online integration for viewing and editing.  While these may seem like small enhancements, these new features represent a big step forward for Office integration into the apps and services that are important to our customers.

This is huge. It’s actually all in that first sentence, which is all you need: “We want Office to be the preferred way to work with documents no matter where they’re stored.” Microsoft wants Office – its most lucrative monopoly – to endure. This is part of how it does that.


May 2012: once deemed evil, Google now embraces “paid inclusion”

Danny Sullivan, in May 2012, noting changes in how Google represented and collated its Flight Search, Hotel Search and Shopping categories so that they became pay-to-play for companies to appear – a reversal of Google’s previous stance:

paid inclusion isn’t necessarily bad, especially if it’s used to solve an otherwise difficult challenge in search, rather than being an excuse to generate revenue. However, it it still feels odd watching Google, having previously attacked the objectivity of its competitors over the practice, quietly adopt paid inclusion now that it’s the search market leader. That doesn’t sit right. At the very least, I kind of want someone at Google to acknowledge that it was wrong those years ago.

Postscript (7:30pm ET): Google, after seeing this article, sent along this statement about paid inclusion:

Paid inclusion has historically been used to describe results that the website owner paid to place, but which were not labelled differently from organic search results.  We are making it very clear to users that there is a difference between these results for which Google may be compensated by the providers, and our organic search results.

I have to disagree.

The reason I’m linking to this now is that it’s pertinent to all the antitrust discussion that’s reopening in Europe over Google and particularly vertical search. Google presents its results as untouched by human hand, but there’s a whole lotta touching really going on. (One point on the headline: Sullivan means that paid inclusion used to be deemed evil, not Google.)


November 2013: Western Digital adds helium to enterprise hard drives » AllThingsD

Arik Hesseldahl:

It turns out that the insides of hard drives are pretty violent places. There’s a lot of high-speed motion, what with the disk platters spinning at several thousand rotations per minute, and the head moving back and forth across its surface. If you’ve ever held your arm out the window of a fast-moving car, you get some sense of the problem…

…The secret sauce to all this is that the drives are built to be hermetically sealed, which means they’re both perfectly airtight and leakproof. While the science behind doing all this has been well understood for a while, Cordan says that Western Digital is the first to figure how to do it in a repeatable manufacturing process. It adds an extra step or two to the manufacturing process, and thus some cost.

It gets more interesting: Hermetically sealed drives don’t let the helium out, but they also don’t let anything else in, including liquid. That makes them good for use in immersion-cooled data centers. These are small, dense collections of IT gear packed into a box the size of a shipping container and filled to the top with nonconductive liquid that keeps everything running at a constant temperature. (If you didn’t know that this was a thing, you’re not alone, because I didn’t, either.)

This came (via @jearle) after I happened across a Digitimes report about helium-filled drives. Presumably vacuum is next, since if a drive can survive being immersed then it must have tough joints.


Intel reportedly to delay launch of 14nm Skylake desktop CPUs » Digitimes

Monica Chen:

Intel reportedly has informed its motherboard partners that it will delay the release of its 14nm Skylake desktop CPUs and corresponding 100-series chipsets to the end of August, compared to its original schedule set for the second quarter of 2015, according to sources in Taiwan’s motherboard industry.

The delay will affect PC makers’ production and shipment plans for Haswell Refresh and Broadwell-U series products and may also delay the development of Broadwell models with a TDP of 65W, the sources noted.

PC makers will also not be able to unveil Skylake-based models during the upcoming Computex 2015 to be held in June in Taipei, thereby affecting PC sales in the second haft of 2015, said motherboard makers.

Intel is saying that it always planned to release Skylake in the second half of the year. For reference, the Pentium 4, introduced in 2000, had transistor sizes of 0.18 micron – or 180nm.


$1.75m in bitcoin stolen from Chinese exchange Bter » The Next Web

Abhimanyu Ghoshal:

Even as Bitcoin is starting to shake things up in the US, all is not well in the cryptocurrency world. China-based Bitcoin exchange Bter was hacked on Valentine’s Day and $1.75m worth of Bitcoin was stolen.

The company hasn’t revealed much about the breach, except that 7,170 BTC was taken from its cold (offline) wallet on February 14 via a single transaction (link) and that the platform is suspending operations until further notice.

I feel like we’re getting so used to this that $1.75m is like “yeah, sure”.


Start up: India blocks Xiaomi, Chinese app habits, Office gets Bing, hacking smartwatches, and more


Refuelling a Toyota Prius. By the time he’s grown up, it might have paid for itself. Photo by Chris Yarzab on Flickr.

A selection of 9 links for you. Slippery when wet. I’m charlesarthur on Twitter. Observations and links welcome.

Breaking News: Delhi High Court grants injunction against Xiaomi >> Spicy IP

[On Monday] the Delhi High Court granted an ex parte injunction order against Chinese operator Xiaomi for infringement of Ericsson’s patents. The patents in question are Standards-Essential Patents (SEPs) which are subject to FRAND (Fair, Reasonable and Non-Discriminatory) terms. However, they may also be the same patents which are the subject matters of litigation Ericsson has mounted against Micromax, Gionee and Intex. As Shamnad Sir noted earlier today, while Ericsson has largely favourable orders against Micromax and Gionee, the same cannot be said for its case against Intex. Therefore, when the same patents are potentially in question under other cases as well, there was no need for the Courts to rush to grant an injunction against a new defendant, namely Xiaomi.

At this juncture, it is more interesting to note the reasons provided for granting the said injunction. One factor that the Court found persuasive was that Xiaomi had not responded to Ericsson’s repeated communications  (6 in number from July 2014). However, it must be questioned whether Xiaomi’s purported laxity in this matter is a sufficient reason to grant an injunction against them. More so, when an alternative remedy in the form of damages is available which is one of the cardinal principles that goes against the granting of injunctions.

This ex parte order injuncts Xiaomi from selling, advertising, manufacturing or importing devices that infringe the SEPs in question. The judge also directed the Customs officials to stop the imports under the IPR Rules, 2007. Moreover, local commissioners have been appointed to visit Xiaomi officers to ensure the implementation of these orders.

This is going to put a whole new complexion on Xiaomi’s expansion – and profitability – outside China, and probably means it won’t be coming to the US any time soon.


Chinese mobile app UI trends >> Dan Grover

Slightly to his surprise, San Francisco native Grover finds himself a product manager on Chinese messaging app WeChat, in Guangzhou; from the photo, it’s Shenzhen, as that’s where WeChat is headquartered. This isn’t the cheesy opener to a TV series, unless you make it so:

Moving to a new country has meant learning how to do lots of things differently: speaking a new language, eating, shopping, getting around. In a few months, I’m surprised at how acclimated I’ve become to what, at first, seemed such an overwhelmingly alien place.

This has applied to my digital life too. I’ve replaced all my apps with those used here, owning both to my keen interest as someone in the tech industry, and to “go native” to the extent I can. Since then, I’ve similarly become blind to the adaptations required there, too.

One day, for the fun of it, I started writing a list in my notebook of all the things that are different between apps here and those I’m accustomed to using and creating back in the US. When I finished, I was surprised by how long the list was, so it seemed fitting to flesh it out into a post.

You’ll look at it and say “oh, that’s why feature X that I never use is in iOS 8”. Plus much more. China may be like Japan – a harbinger of some of the mobile future, but not all. The trouble is figuring out which bits are which.


How the Prisoner’s Dilemma explains the lack of forked Android phones outside China >> Tech-Thoughts

I’ve taken liberties with the headline on Sameer Singh’s article, but that’s basically what he’s doing:

[in the classic minimax game] the best payoff for both prisoners will be achieved if both remain silent. But the best individual payoff requires each to betray the other. So the only rational course for any self-interested party (like profit-generating enterprises) is to betray each other. In the case of Android OEMs, it may benefit the whole industry (from a differentiation and profit standpoint) to fork Android and exclude Google services. But the threat of selling a non-competitive forked device, while others sell devices with Google services is too great for this to ever happen.

The rest is insightful too. Sameer’s been quiet for a while; pieces like this contribute greatly to our understanding of ecosystems:

There are close to 2 billion smartphone users today and that will grow to roughly 4 billion over the next few years. However, the purchasing power of these users will be far lower than that of the existing user base, i.e. they will probably buy $25-$50 devices and not $600 or even $200 devices. How do you monetize a user who can only afford to pay $25-$50 for a phone?

The answer: services, dear boy, services.


PC makers may beat Apple to the punch with new ‘fingerprint ID’ sensors built into notebook touchpads >> Apple Insider

Calling it the “first solution to integrate fingerprint ID technology into the TouchPad,” the Synaptics SecurePad is a 4-by-10-millimeter sensor on the surface of a notebook’s cursor controls. The SecurePad activates with the touch of a finger, and like Apple’s Touch ID, it supports fingerprint detection at any angle.

The Synaptics SecurePad is a Fast Identity Online-ready authenticator supporting the use of password-free security. It will allow PC makers to implement fingerprint scanning technology without the need to duplicate hardware components, allowing for simpler integration into existing notebook designs.

Once a user scans their fingerprint when prompted for a password, SecurePad initiates a cryptographically secure challenge and response with an online service provider. The Synaptics solution does away with storing password databases in the cloud, further improving security with FIDO-compliant partners.

Useful for enterprise PCs; unclear whether there will be much demand for it from consumers (though users of iOS devices with TouchID might like the idea). It all rests on the execution.


Microsoft begins integrating Bing search into Office >> ZDNet

Microsoft is beginning to integrate its Bing search technology into Office, starting with Word Online, company officials announced on December 10.

Microsoft is calling the new embedded search capability “Insights for Office”. Microsoft is rolling out the capability worldwide (everywhere where Bing is available) starting today, December 10. The rollout should be complete within the next few days, officials said.

Users don’t need to do anything to get the new capability; it will just be added to Word Online automatically. The new “intelligent search experience,” as Microsoft officials are calling this, isn’t ad supported. It’s free.

Bill Gates wanted to include Microsoft’s search solution in Office back in 2003, but antitrust concerns, and the Office team’s refusal to help the search team, killed it. (Source: my book, Digital WarsUS version. Just the present for you or someone like you.)


With $2 Gas, the Toyota Prius Is for drivers who stink at math >> Businessweek

It would take almost 30 years of fuel savings from the hybrid Prius to cover its price premium over the little Chevy Cruze, although that doesn’t account for the Chevy buyer marking savvy investments with her savings in the meantime. It doesn’t matter since we will all be flying around in futuristic Teslas before the Prius pays off. The all-electric Nissan gets a lot closer: The all-electric Nissan Leaf, without any gas stops, take just 3.8 years on the road to beat the cheaper sticker price of the Cruze.

The Cruze gets a respectable 30 miles per gallon of combined highway and city driving, but its real strength is relative affordability. Without a second engine and a massive battery, the average Cruze had a $21,322 sticker price last month, compared with almost $31,973 for a Prius and $32,933 for a Leaf. Even after federal tax breaks, Cruze buyers start with an advantage of $8,151 over the Prius and $4,111 over the Leaf. That’s a lot of gas money.

For the 13 states with no hybrid incentives, this is where the equation stops.

This is the real reason why the US hasn’t made any progress on electric cars: the lack of tax incentive. True, the idea that carbon emissions are a problem is relatively new, but the US’s dependence on foreign oil (and hence oil) was seen as a problem as far back as Jimmy Carter’s time in the 1970s.


Eric Young on Twitter: “”I work for 1 of largest credit issuers n world…”

Eric Young quoting a source at “a major [US] bank: “I work for 1 of [the] largest credit issuers n [in the] world. We processed way more Apple Pay transactions than all of Google Wallet since its beginning”.

I’ve calculated there have been 20m Google Wallet downloads (it’s US-only), and people who should know have subsequently suggested that perhaps one-tenth of those are active. Apple Pay is very likely far past Google Wallet for number of active users in the US, even though Google Wallet came out in 2011 – and Apple Pay in September.


Mobile Enterprise Apps >> Apple

The first fruits of the collaboration with IBM, yielding what Apple calls “a new class of apps — entirely reimagined for the mobile enterprise, made for iOS, and designed to empower employees wherever their work takes them”. I was struck by the one for pilots, and this one for law enforcement officers:

With the Incident Aware app, police officers can know each other’s whereabouts with greater insights in emergency situations. When law enforcement officials receive an emergency call, responders can go in with a bird’s-eye view of the scene’s perimeter that includes GPS map data, the location of those involved in the incident, and live video feeds updated in real time on their iPhone devices. This powerful and intuitive app can even access police records to calculate risk, letting other law enforcement stakeholders know where and when other responders will appear.

It relies of course on Apple Maps, which will really up the stakes on getting that right and up-to-date.


Data sent between phones and smartwatches wide open to hackers >> Ars Technica

The growing number of smart devices that interoperates with smartphones could leave text messages, calendar entries, biometric data, and other sensitive user information wide open to hackers, security researchers warn.

That’s because most smart watches rely on a six-digit PIN to secure information traveling to and from connected Android smartphones. With only one million possible keys securing the Bluetooth connection between the handset and the smart device, the PINs are susceptible to brute-force attacks, in which a nearby hacker attempts every possible combination until finding the right one.

Researchers from security firm Bitdefender mounted a proof-of-concept hack against a Samsung Gear Live smartwatch that was paired with a Google Nexus 4 running Android L Preview. Using readily available hacking tools, they found that the PIN obfuscating the Bluetooth connection between the two devices was easily brute forced. From that point on, they were able to monitor the information passing between the watch and the phone.

Trying to feel anxious. Somehow can’t summon up the necessary level of worry about someone seeing a calendar alert.