Mozilla had announced the beta version of its long running web-scale identity system, Persona (formerly code-named BrowserID), which is aimed at entrenching privacy and secured web experience by utilizing authentication through existent email as against actual username and password.

Mozilla Persona differs from other authentication systems like OpenID in that it uses email address as identifier and fully integrated into the browser.

Persona takes precedence from the Verified Email Protocol system, which involves only the browser and compliant website.  It relies on public key cryptography on the browser-side without invoking the identity provider in the actual authentication process.

However, users will need create and verify an account on Persona.org by defining a password and adding one or more email addresses to their account. Thereafter, "Persona Authentication" would only take a two click process for already logged in users, while those not already logged in will need to enter their Persona details in the process.

Persona is built to naturally eliminate users tracking, which provides rest of mind for privacy conscious users, and at the same time ensuring secured access.

On the contrary, if users disclose their Persona details it can be used against them and to access all connected services. Mozilla, however, have iterated its plan to introduce two-factor authentication in later versions to beef-up security.

Developers have been called upon to contribute to the open source project. Whilst, Mozilla have promptly made available an extensive tutorial on What is Persona and How it Works.

Mozilla Persona: Browser-side Authentication System

Google mid-week announced new updates to the Google Apps service which will take effect starting October 1. Google is dropping support for the older Microsoft Office (Office 97 - 2003) formats: .doc (Word), .xls (Excel), and .ppt (PowerPoint)  on the Google Docs.

The Google Docs to Microsoft Office exporting feature will only allow user download documents in the new Office formats: .docx, .xlsx, and .pptx. However, the ability to import Office files of any format to Google Docs remains unchanged.

Google Docs users who are still running the old Office 97 - 2003 versions have been afforded a free compatibility plugin by Microsoft which will allow them to open newer Office files.

And users of the Consumer Productivity Suite of Google Docs will continue to be able to export documents in the old Microsoft Office format, whereas support for the Commercial Productivity Suite have been discontinued.

Office document collaborator using the old Office format, being backward compatible, need not concern themselves whether a collaborator is using the new Office version, as the latest versions of the Suite is compatible to the old formats. But, the older version of the Suite is not compatible.

Google Apps Drop Old Office Formats

Microsoft's Internet Explorer got a handful of critical exploitations earlier in the week. The zero-day vulnerabilities affects IE9 and older versions of the browser, the exploit allows remote code execution which could enable an attacker take control of a compromised system.

The exploit takes advantage of a "use-after-free" vulnerability, a vulnerability affecting mshtml.dll component of Internet Explorer.

The company has now provided a one-click work-around to the vulnerabilities, termed "Fix it for me", which affords an automatic fix to the vulnerabilities without requiring rebooting. The one-click automatic system does not affect browser sections while being implemented.

The "fix it" tool works by protecting the system from memory corruption, which security researchers have identified as the major entry mechanism for the exploits.

Microsoft has also scheduled an out-of-cycle security update to permanently fix the glitches for Friday. And users will be able to get the security patch through the Windows Update, while it will be automatic for those who have enabled automatic update.

IE Vulnerability: Microsoft one-click Fix It

The privacy policy proposal has now been embraced by virtually all leading internet technology vendors, with Microsoft even assuming a heightened dimension to it, purporting to making the do-no-track command the default setting on the next version of its browser IE10. Now, Chrome developers build released yesterday featured the revolutionary privacy option.

Google had earlier made known its decisions to bring comparative privacy options to users and implement a solution on its advertising systems as well. The "Do Not Track" feature, albeit, helpful in targeted advertising, appears exploitative to some segment of internet users, who maintains that choice to opt-out needed to be provided.

Advertisers, however, have expressed concern as to the actual implementation of the tracking restrictions, citing that it will thwart efforts to target advertising.

Before now, Google Chrome had remained the only major browser that did not implement the "Do Not Track" command. Mozilla first introduced the privacy mechanism in Firefox early 2011, with Opera and Internet Explorer later joining the train.

The privacy settings have been implemented in the Chromium developers channel and will be available in subsequent versions of Chrome.

Chrome "Do Not Track" Compliance

Microsoft has issued deadline about the necessary changes to Windows' certificate requirements in line with its scheduled automatic security update. Starting October 9, minimum key length for digital certificate supported by Microsoft must be at least 1,024 bits.

RSA digital certificate with key less than 1,024 bits will not be supported on the Microsoft platforms, hence administrators are required to update for the minimum certificate key length. Windows ActiveX Control would be blocked for any website without the required security certification level.

Microsoft Security Response blog noted that the changes will help improve security across the Windows platforms.

The company have made available a knowledge-base help in updating for the minimum certificate key length and detailed technicalities.

Microsoft effort to secure the Windows platform is paramount following the recent security breaches targeting the system. The company hopes the update to certificate key length requirements will help strengthen the Windows ecosystem.

Certificate Key Deadline Issued by Microsoft

Microsoft cloud-storage offshoots have heralded new changes in the company's terms of service. Before now, Microsoft service agreement as regards its cloud offerings stated vividly that "Your files are not just bits to be synced, and certainly would not be scanned to serve advertising".

The new changes in the Microsoft service agreement read thus:

"When you upload your content to the service, you agree that it may be used, modified, adapted, saved, reproduced, distributed and displayed to the extent necessary to protect you and provide, protect and improve Microsoft product and services."

The above statement clearly portrays that the company intends full access to users data and rights to serve ads based on the available information thereby. Microsoft is perhaps treading Google's path, which have reserved the rights to allow it share users data across its cloud offerings.

Further more, Microsoft new service agreement terms explicitly acknowledged:

"For example, we may occasionally use automated means to isolate information from emails, chats, or photos in order to help detect and protect against spam and malware, or to improve the services with new features that make them easier to use."

The new changes in Microsoft terms of service also bears on actual word-rendering under "Privacy", the old stance on "Privacy" stated, that "Microsoft may access and disclose information about you"; whereas under the new heading, it clearly reads, "Microsoft may access, disclose, or preserve information associated with your use of the services, including (without limitation) your personal information and content, or information Microsoft acquires about you through your use of the services".

Also effected are changes in the legal rights, especially as it concerns U.S. users, the new agreement reads: "If you live in the United States, section 10 contains a binding arbitration clause and class action waiver. It affects your rights about how to resolve any dispute with Microsoft".

What this statement means is that Microsoft cloud services users in the U.S. cannot sue the company by a class action lawsuit, that is, any legal dispute with Microsoft must be resolved before a neutral arbitrator.

The new Microsoft terms of service will take effect starting October 19, 2012. Therefore, any user who does not find the above information comfortable must have to do away with the service now or leave the rest to Microsoft's whims.

New Microsoft Terms of Service: Privacy Twist?

Twitter has announced changes in the upcoming version 1.1 of the Twitter Application Programming Interface (API), with stricter guidelines on how third-party applications connect to the service. Michael Sippey, Group Product Manager at Twitter, in the Twitter Developers blog described the move as means to restore consistency in the Twitter experience.

The new changes in the Twitter API includes: requirement of authentication on all API endpoint, a new rate-limiting methodology, and Developer Rules changes for apps that serve as traditional Twitter clients.

Twitter had earlier warned on the new changes, albeit, the actual nature of the turn was shrouded in non-details. However, critics have termed the move rather too drastic and detrimental to further expansion of Twitter ecosystem.

Per-Endpoint Rate Limiting on the API, means that application that only accesses one endpoint may be more restricted, while application that uses multiple endpoints will run into rate limiting issues less frequently. The Twitter API current version 1.0 served a "one size fits all approach", limiting the number of authentication requests an application can make to 350 calls per hour, regardless of the nature of the information concerned. Whilst the new changes will present most individual endpoints at the rate limit of 60 calls per hour restricted to 100,000 individual users token, which according to Twitters own calculation is well above the needs of most applications built on Twitter API, stressing that it will help protect its system from abusive applications. Though high-volume endpoints relating to Twitter display, profile display, look-up and users search will be able to make up to 720 calls per hour per-endpont.

However, if your application already has more than 100,000 individual users tokens, you will still be able to maintain and add new users to your application up to 200% of your current tokens.

Also, developers that are building client applications pre-installed on mobile phones, or SIM components will be required to have their applications certified by Twitter. And Twitter reserve the rights to revoke non-certified applications.

The changes in Developers Rules of the Road implies Display Guidelines will serve as Display Requirements to ensure consistency in the Twitter experience across board.

The new Twitter API v1.1 migration will simultaneously be announced with the deprecation of the current version 1.0, and developers will be given six months to migrate from v1.0 to v1.1.

Twitter users, especially those that are using third-party applications to access the service will experience less error messages, as apps refresh stream becomes more frequent without running up the rate limit. But, as to how the overall changes will affect future users experience remains to be seen.

Twitter Hits Developers with API Restrictions

Facebook has launched a reporting channel to fight phishing attacks targeting its users, comprising attempts to steal users data and login details, by providing an email service whereby users can forward any suspicious email they receive on the platform.

The email service is to compliment its already running phishing detection system, an internal service that notifies its security team on possible phishing threats and its connected websites.

According to an official release note, "Facebook intends to gather more information on phishing sites so as to be able to take them offline" through browser backlisting or actual site takedown where appropriate. Facebook is thereby requesting that users should forward any suspicious email to the provided address: phish@fb.com.

Generally, social networking sites have been the bait of identity scams, a development which has engaged the better part of social networks security concerns over the past months, coupled with the incessant privacy issues. And with the rising influx of fake accounts on popular networking portals, the case of unsolicited emails and phishing threats is the order of the day.

Augmenting existing security mechanisms working at the background to protect users has been the call by security experts, which implementation may well serve the much needed identity theft issues. Facebook is sure on the right footing with the new notification service. 

Facebook Tackles Phishing Attack

Microsoft has clearly decamped to web application and open services even as it demos Outlook Client Email service, Tuesday. The new webmail service will be replacing Hotmail, and represents the next generation of messaging system according to the Outlook blog.

The new Outlook.com, dubbed "modern email designed for the next billion mailboxes", is Microsoft answer to Gmail and Google Enterprise services.

Microsoft Oultlook desktop application  for PC and Mac is perhaps the most popular enterprise application for email and office collaboration, with the Outlook web application, connecting Organizations Exchange Server. The company by the new service intends offering Outlook as an email service for modern browsers and devices.

Outlook.com is built with social networking in mind, instead of only the conventional inbox, users have the option to view updates from popular social networking sites, which includes: Facebook, Twitter, Google+ and Linkedin. Also, it includes free web-based versions of Word, Excel, PowerPoint and OneNote, with additional storage space through Microsoft's cloud service, SkyDrive. The Skype messaging capabilities is also featured in the new webmail service.

It automatically sorts your messages from contacts, newsletters, shipping updates, and social updates, and with the "Sweep" features you can move, delete and set up powerful rules.

Hotmail users who want to upgrade to Outlook.com preview simply need to go to option menu of Hotmail and click on "upgrade". While, email address, password, contacts, old email, and rules will remain unchanged, and you can send or receive email from your @hotmail.com or @msn.com or @live.com address.You can also add an @Outlook.com email address to your account.

Microsoft Web-based Outlook Email Service

Microsoft launch of the consumer preview of the next generation Office 2013 suite which media event took place in San Francisco on Monday has perhaps presented the most remarkable architectural departure, inline with the Windows 8 technologies, aimed at positioning the company in the cloud computing and enterprise collaboration space.

Microsoft Office had been criticized for lack of data portability and seamless experience as the case on the Google Docs service, leading to the need for the company to setup Office 365 to address the critical enterprise challenge.

Now, Microsoft intends pushing users of both Office services into its cloud-based offering, SkyDrive, which will enable users to store data in the cloud with the ability to sync files across different platforms. The company has lately set a keen eye on the mobile market, and thereby have effected the necessary changes to embracing mobile with the latest Office suites.

What that means is that Microsoft has taken desktop programs and its web-based office equivalent and unified them into a product that feels more simplified without altering the traditional Office motto.

However, MS Office 2013 and Office 365 update will not support older Windows versions like XP and Vista. It will only run on Windows 7 and Windows 8 PCs and Tablet devices. And the actual product launch date is yet to be fixed by Microsoft.

Google had earlier tried to woo MS Office users into joining the Google Docs train by offering Cloud Connect, which afforded Microsoft Office users the syncing option and accessibility of files on the go. But, with Microsoft full footing on the cloud-storage space and the revolutionary technology drivers put in place, definitely, the cloud computing battle-line has just been drawn.

MS Office 2013 Intensifies The Cloud Wars