2013 technology predictions (Gartner)

As good start of 2013 I’d like to share Gartners top tech predictions for 2013. Some seem true and some seem like a stretch. Happy new year!

(source:http://www.imgrind.com/10-technology-predictions-for-2013-and-beyond/ and http://www.gartner.com/it/page.jsp?id=2209615)

  1. Mobile devices will continue their march towards dominance. Mobile web access will overtake the PC.
  2. The market will shift towards HTML5. Over the next few years, many mobile development tools will remain popular, but eventually, there will be a shift away from native apps to web apps.
  3. The personal cloud will grow, reducing digital content on PCs and it will become the common factor connecting many devices. As a result, mobile security, capability and management will become more important.
  4. Private enterprise App stores will become more common. Companies and groups will deliver apps to workers or members via private stores.
  5. The internet will become more integrated with the physical world. Consumer products, cars, health products, etc will all be connected to the web through sensors, images, NFC technologies and more.
  6. An emergence of an internal cloud services brokerage will occur. Better management of cloud services computing for many users will drive this.
  7. There will be a shift in storing strategic big data. Data will be split into multiple systems consisting of content management, data warehouses, data marts, and other specialized file systems instead of one big data warehouse.
  8. Actionable analytics will drive more decisions in companies. As capabilities grow and costs are reduced, data use in decision making will grow.
  9. In-memory computing will become mainstream, speeding up many processes.
  10. Tech ecosystems will become more integrated. The industry is moving away from loosely coupled approaches and more toward integrated systems for lower costs, ease of use and security.

I’d also like to share this infograf from Cisco showing the huge potential and challenges to integrate the internet with things:

Image

Ten thousands of encryption keys are useless

Article is written by digi.no with my contribution. It is translated directly using google translate. Link to the original article: http://www.digi.no/889897/titusener-av-ubrukelige-kryptonokler. Se also similar Economist article for easier explanation.

Figure: RSA moduli that share zero, one or both of the prime factors. The illustration is described in the report is linked below. (Illustration: Arjen K.Lenstra, etc.)

A group of European and American researchers, led by the Dutch mathematician Arjen K. Lenstra, via scrutiny of millions of public encryption keys concluded that a not insignificant proportion of the keys of the content does not provide any security.

The researchers examined both the 1024-bit RSA moduli-based X.509 certificates and PGP keys. An RSA modulus consists of the product of two large prime numbers, which together with encryption exponent e is the public key. The private key consists of the same RSA modulus and decryption exponent d.

– A constructive and crucial assumption underlying the safety of the infrastructure of public keys is that the previous random selection can not be repeated during the key setup, the researchers wrote in the report (http://eprint.iacr.org/2012/064.pdf)

At least 0.2 percent of the surveyed public keys had a prime factor in common.

– Their secret keys are available to all who take the trouble to reproduce our work. With access a collection of public keys, this is straightforward compared to more traditional ways of obtaining secret RSA keys, the report said.

The method the researchers used, is partly based on Euclid 2400 years Gamel algorithm for finding the greatest common divisor.

– The lack of sophistication in our methods and findings make it difficult for us to believe that what we have presented is new – especially for agencies and groups that are known for their curiosity in such areas, said the report’s conclusion.

The researchers will not have made an opinion about why this lack of despotism occurs, but another research group has.

The group has done a similar study with results that have not yet been disclosed. Here we show that there is little online banking, online stores and other sites that use encrypted HTTPS connections, which are affected by these problems.

Instead we are talking very much about embedded devices that often generates the cryptographic keys on first boot.

Key generation of PCs and servers may use any information from natural sources, such as the movements of the mouse, keyboard and hard drive, as well as networking events or other external sources of unpredictable information. In embedded devices, the possibilities of this often less good, which means that entropy is not sufficiently large to produce truly random factors.

– Problems in terms of getting 100 percent random keys in cryptographic solutions is not new. But the scale shown here, is not negligible (0.4% of the keys in the resulting population would be broken). The weakness is primarily attributable to the hardware firewall, routers, VoIP phones and VPN solutions, and SSL certificates for websites such as banking, shopping, etc., writes Erik Eriksen Holthe and Geir Arild Engh-Hellesvik in an email to digi.no .

Both are employed at KPMG Advisory, where Eriksen is a consultant for information security and Engh-Hellesvik is head of information security services in KPMG.

– Which products containing such flaws, we do not know, but companies should identify the solutions that protect their most sensitive data, such weaknesses and assess whether this is an acceptable risk. The casual user has little to worry about, says the two.

Forskere har funnet feil i krypteringsløsninger vi benytter

Av Erik Holthe Eriksen (KPMG Advisory)

Amerikanske og europeiske matematikere og kryptografikere har oppdaget en svakhet i krypteringsløsninger folk flest bruker som netthandel, nettbank, epost og andre tjenester. Svakheten innebærer at det er en sannsynlighet for at ikke alle nøkler genereres med tilfeldige tall. Tilfeldigheten er del av sikkerheten i seg selv for å gjøre det nærmest umulig for en angriper å dechiffrere meldinger. Risikoen er lav for at folk flest vil oppleve noe som helst, men uansett så er tilliten til sikre forbindelser redusert.

Forskerne fant ut at i meget få tilfeller, drøyt 0,2 prosent, så virket ikke genereringssystemet slik det var designet. Selv om et krypteringssystem er tilnærmet sikkert kan ofte hardware som genererer være en svakhet. Moderne netthandelsystemer er meget avhengig av sikkerheten PKI-løsninger (public key infrastructure) tilbyr.

Problemet med å sende sikre meldinger har bekymret menneskeheten siden sivilasjonens oppstart.

Forskerne annonserte svakheten tirsdag denne uken. Gjennom å se på 7.1 millioner offentlige nøkler i blant annet databaser hos Massachussetts institute of Technology, fant de ved å bruke den Euclediske algoritmen for å granske de offentlige nøklene, at nesten 27.000 ulike nøkler tilbyr vesentlig lavere sikkerhet. Feilen ligger i hvordan primtall har blir valgt og dette kan føre til identiske offentlige nøkler. I denne sammenhengen ble det vurdert av forskerne at innebygde enheter som rutere er de mest utsatte og ikke webservere med nettbank- og nettbutikkløsninger. Drøyt 200.000 slike rutere kan være utsatt.

Det er uvisst om kriminelle parter har kjent til denne svakheten og misbrukt den eller om den har vært ukjent. Forskerne benyttet endog lite sofistikerte metoder, så sannsynligvis har dette vært kjent før, i verste tilfelle ”cyber”-kriminelle eller fremmed etterretning. For den vanlige nettbankbruker og netthandelkunde er ikke dette bekymringsfullt per dags dato, men for utstyrsprodusenter haster det nok. Tilsynelatende lever vi fortsatt med sikre løsninger, eller?

Is mobile payment safe and when do we start using it?

We are on the verge of adopting mobile payments and many are waiting for the market to explode in coming years. We all know how vulnerable we are if we loose our smartphone where many things in our life are already stored. Will users and the banks give trust the system and is it reliable? Mobile apps have all historically focused on user convenience and less on security, e.g. Angry birds app which some say is collecting user data. Since internet banking arrived we have also experienced many incidents of attacks, such as trojans and hi-jacking of sessions. Many rise concerns if the mobile is going to both a security instrument, e.g. authentication, and jammed with apps communicating sensitive data.

Gartner has recently said that this market is growing rapidly, but it is slower than expected, both in modern markets and developing countries. It is expected that the number of users rise with 141 millions i 2011, that is 38% more than in 2010, with a transaction volume of 86 billion dollars. Mobile payments has had many successes in the developing world due to the lack of nearby ATMs, banks and lower internet penetration. In fact mobile penetration is now higher than internet penetration in the least developed countries (LDC – UN). On the contrary, the western world is waiting to embrace the long-awaited NFC – near field communication, which some think is hype which is not adressing the complexity of the service model nor the change in peoples behavior pattern. Gartner thinks we will have to wait until 2015 before mass market adoption.  One key challenge is convincing buyers to switch from card and wallet to their mobile phone. For this to take place security and reliability also has to be in place.

A huge upside with mobile banking and payment is reducing the amount of cash and coins which costs banks lots and this could be an important incentive for adoption. The mobile can be used for many things, not only money but also ticketing. There is always a risk with handling finances and banks are already used to this. For the consumer the case is also about risk in addition to change of behavior. There will most likely be many different business models tested before a dominant design in this field. At the moment we are on the verge of adoption I think.

Soon we are supposed to be able to pay for items such as coffee, tickets and other small payments less than $30. Near field communication (NFC) which may be the most common payment procedure in, e.g. Europe, USA and similar countries, is supposed to be arriving in many consumer stores soon. Many countries have already tested services for paying for a cup of coffee and such by using a NFC terminal that gets paired with a mobile phone integrated with a sim card that works as a credit card. A receipt is then sent to the phone via SMS or email. Sounds easy!

I follow up on this article later with more thoughts and concerns on security in mobile services, payments and look further into compliance, authentication, infrastructure, laws and regulations, telco and bank involvement, and the different services that are presently competing to change the way we will pay in the future.

Simplified stages from idea to growth! What to consider…

There are several innovation phases of a startup before entering market and creating growth; ideas have to be generated, markets analyzed, and models/concepts investigated to decide if profitable. I’d like to share a simplified version of a stage gate model on innovation projects that has been made by Innovation Norway (see figure below).

Phases in an innovation project for startups (Innovasjon Norge, 2008).

Angry Birds will be bigger than Mickey Mouse and Mario. Is there a success formula for apps?

Authored by Erik Holthe Eriksen and Azamat Abdymomunov

Also posted at miter.mit.edu (MIT entrepreneurship review). Translated from article in Dagens Næringsliv.

Angry Birds is the largest mobile app success the world has seen so far. The concept is simple. Angry birds use each other as slingshot ammunition to crush smiling pigs. It captivates people who have never played computer games and brings forward “destruction lust” in even the nicest of people. The success comes from Rovio, a company from Finland. The man behind the success walks into our meeting in a blood-red hooded sweatshirt with the company’s world-famous brand on his chest – an angry bird. “Angry Birds is going to be bigger than Mickey Mouse and Mario” says Peter Vesterbacka.

Success is not easy
But how do you get to a place where you can dare to be so ambitious? Vesterbacka denies that he and Rovio stumbled upon the success, though he admits “shooting a golden bird”. “We did not lack experience. Rovio created 52 games before the success of Angry Bird so had gone through the steps before. Today we have 50 employees, making us relatively small. We came through tough competition and received support. I believe it is important to support entrepreneurs with technology and sales channels,” he said.

Angry Birds received a great deal of free attention through celebrities who announced that they were hooked on the game. The favorite Swedish skier Anja Pärson, for example, said that the game helped her fall asleep at night. Studies show that people are particularly occupied with Angry Birds on the weekends, when they have more leisure time. A scary fact is that Angry Birds is played 200 million minutes a day all over the world. This is 1.2 billion hours a year. How is that for cognitive surplus!

Unpredictability
Angry Birds is not a sophisticated game, but that it is partly the key to its success.
“The simplicity and addiction factor of Angry Birds is somewhat reminiscent of Tetris,” says Vesterbacka, referring to the successful computer game that had its heyday long before the millennium. One of the secrets behind the success is that the game is not completely predictable. You can try the same level many times without success, and then suddenly you are able to complete the level.

But Rovio believes the greatest credit goes to the Apple’s App Store: “It has opened up for innovation and given us a huge market. The game itself is made possible by the touch technology, which hit the market at the right time with the growth of smartphones and the launch of the App Store. The key is to offer it for free and reach volume. You need to get the game out to the masses,” says Vesterbacka.

Being on top is a must
“It is important to continue being number one in the app store. When you manage to do this, the challenge is to build an even greater audience,” says the man who has demonstrated this best of all. Rovio initially focused on the local market in Finland. His goal was to become number one in the domestic market, then expand further. This strategy has certainly showed its success.

Happy Meals and Angry Birds
The game has been downloaded 75 million times and has 200 million followers. They have even started the production of toys and clothes, and will likely launch Angry Birds Happy Meals at McDonalds soon. Now that the birds have become more and more popular all over the world, Rovio is working on the next version planned to come out before the summer. In this version, the pigs have a more active role and can possibly take revenge on the angry birds that have plagued them.

The courage to pursue
Angry Birds has opened the game universe to people who typically do not spend much time or money on these types of activities. The game is available for both iPhone and Android phones. It has also been launched on the IPad, where users can enjoy larger versions of the angry, but funny birds.

Vesterbacka thinks it’s important that people with ideas are brave enough to bet on them. “There are too many people who work for large telecommunications companies today,” said Vesterbacka. “Go do your own thing!” His experience is that entrepreneurs have endless amounts of energy, but that they also need a good dose of patience to succeed.

Analyzing the audience
Entrepreneurs should dare to do new things. “Think about how you can do things differently. Dare to stand out. In the future, people will have more leisure time which creates opportunities for the entertainment industry,” says the gaming guru.  Vesterbacka also recommends future game-makers to analyze their users and continue to improve their product. Vesterbacka knows how important it is to communicate with your audience when you’ve got their attention. “We are good at responding to users and keeping contact with them on Facebook and Twitter. We are developing the game all the time. When the game Cut the Rope (a Russian game) passed us in October, we responded by creating a Halloween version of Angry Birds. It pushed them out of the top spot,” explains the entrepreneur.

Why are the birds so angry?
A final word from the man who hatched the app: “the pigs eat their eggs”.

Do many entrepreneurs execute without thinking enough?

Business model or Business plan? What’s the difference?

Figure 1: Role of the business model (Chesborough and Rosenblom).[1]

A business model is key to determine if profits can be made from an idea or innovation. Many entrepreneurs leapfrog certain subjects in business understanding because they are so sure they have a perfect product offering. Chesborough and Rosenblom wrote a paper called “The role of a business model in capturing value from innovation” where they present a framework for business models. Given complexities like product, market and environment when having an innovation we need different experts in technical and business fields.

Figure 10: Business idea, model, case and plan.

Business idea

–      An idea for a business, or for a way of making a profit. In a sense this is the most basic concept: if you do not have a business idea, you do not have a business! E.g. data only with voip on top.

Business model

–      Describing alternative ways of implementing our business idea, describing the logic of generating a profit with basis in our business idea. Several ‘business models’ may implement the same idea.

Business case

–      A business model contain a number of indeterminate parameters, exact prices, costs, sales volumes, revenue numbers, partnerships, etc.. The ‘business case’ appears by fixing these indeterminate variables to some value, and eventually computing the resultant economic values like net present value, etc.

Business plan

–      A plan for implementing a particular business case, based on some business model for a particular business idea.

It is important to understand that a business idea, model and plan are separate tasks. Ideas can be gathered to create a business model. A business plan tells how we will execute a business model. A business model describes the logic of profitability. Business startups need to answer who we are selling the product to, what problems does it solve, how will customers be reached, how will customers pay, how will product be developed, what is the competitive strategy and who are your partners and competitors? There are several components of a business model and it is important to analyze them and choose a model before starting the business. Chesbourough and Rosenblom identified 6 components of a business model. Osterwalder has created a similar one but has added 3 more components.

Figure 11: Osterwalders components and building blocks of a business model.

  • Value proposition: what is the company offering their customers, which problems are they solving, and why will the customer prefer their offer rather than the competitor(s)
  • Market segmentation and target customer: who are the customers, i.e., the customer segment with needs/ demands the company wants to serve
  • Distribution channel: how the customers are reached, that is, the means to reach and address the customers.
  • Customer relationship: what are the means to reach and address the customers, how to get them and keep them (i.e., reduce churn), and links between the company and the customer segments (see also eco-system)
  • Value configuration and Core capabilities (Competitive strategy and how the company operates and delivers value to customers. Company internal value chain/service platform and delivery system, the key activities and capabilities/resources).
  • Partner network/Eco-system (what are the key partners and suppliers, the business eco-system, resources (beyond internal value chain) necessary to perform in order to deliver service to the customers.
  • Revenue streams: what are the revenues, the pricing models, how money is made through a variety of revenue flows)
  • Cost structure: what are the costs and risks, describe the cost structure) whether the costs are fixed or variable, operational (OPEX) or investments (CAPEX).

Figure 12: Osterwalder business model canvas.