mukesh

Mobile

Saturday, 28 April 2012

Russian Student Cracks Chrome.


Well, I guess Google Chrome isn't impenetrable after all. A total of $1 million in prizes was recently offered by Google to anyone who could exploit the Chrome browser and, for the most part, people failed. That has now changed. At the Google Pwnium hackathon, a Russian university student has been able to hack his way through the cloud OS and earn himself the top prize.


Sergey Glazunov is now $60,000 richer for having successfully hacked a PC running the Chrome browser. What has prevented earlier attempts is that Chrome has something called a “sandbox” that is designed to stop hackers from accessing user data even if they compromise the browser. Glazunov found an exploit to get around that, bypassing the security and successfully hacking into the PC.
As part of the competition, all successful hackers must tell Google how they did it, effectively giving Google the opportunity to patch up the security flaw before real hackers take advantage of it in real life. Interestingly, a security firm also hacked Chrome at HP’s Pwn2Own event, doing so in just five minutes. Chrome is still pretty secure, but this does show that it’s not invincible.
[Source]

Thursday, 26 April 2012

Google Drive

Computerworld - The long-awaited Google Drive is a simple, useful, straightforward cloud storage and syncing service that offers a full 5GB of online storage for free, with no surprises along the way. Utilitarian rather than flashy, it makes storing files to the cloud and syncing them among multiple devices as simple as saving a file to a local hard drive.
If that's all you've been expecting from Google Drive you'll be pleased. But if you were hoping for a Google Drive/Google Docs combination that would make it easy to edit files in the cloud that you created on a PC or Mac, you'll be disappointed. It may be that Google will get that straight at some point in the future, but for now it's a non-starter.

Easy to install and use

Google Drive currently installs as an app for Windows, OS X and Android. (Note: As of today's date, there are reports that Google Drive has not yet been made available for all users.) A version for iOS isn't yet available, but Google says it will be out soon, although the company hasn't yet given a release date.
Google Drive
Google Drive installs as its own drive in Windows and OS X, and is available via Windows Explorer or Finder.
After you install Google Drive on your PC or Mac, it shows up as another drive in Windows Explorer or the Mac's Finder app. Like rival service Dropbox, you can use it just like a physical drive -- so you can copy or move files to it, and create new files and subfolders inside it. The files and subfolders are uploaded to your Google Drive on the Web and are accessible there. They're also synced to any other devices onto which you've installed Google Drive. So if you edit the files on any device on which you have a Google Drive installed, they're synced to the cloud and all your other Google Cloud-enabled devices.

Google Drive isn't integrated into just Windows Explorer or Finder -- because it looks like a drive, you can save to it and open files from it from any application (or at least every one I tried). So from Microsoft Office, for example, you can save files directly to Google Drive and open them from Google Drive. When you do that, you're saving or opening them on your computer itself, not directly from the Web. Any changes you make are saved to your hard drive, and then automatically synced to Google Drive on the Web and other devices on which you've installed Google Drive.
I found installation and initial use of Google Drive to be exceedingly simple. Working with it on a computer is no different than working with any other drive -- and you don't need to do anything to keep your files in sync, because Google Drive does that for you automatically.
It was simple working with it on an Android smartphone as well. Files are synced to the Android device, and you can easily browse them by tapping My Drive when you run the app. You can also create documents using the Android app.

Wednesday, 25 April 2012

10 Commandments of Windows Security

With the introduction of Windows 7, many PC and notebook users may feel more secure than they did using older versions of the Microsoft operating system. Newer OSs have more security features, offer better out-of-the-box security settings and have closed many of the historical security holes. Windows 7, for example, has changed the default User Account Control level so that it's harder for rogue programs to run without first explicitly gaining the user's permission.

However, feeling too secure can be dangerous. With that in mind, here are 10 tips--commandments, if you will--for ensuring your desktop or notebook computer can be used productively as well as safely. Many of the recommended tools are free, and all are affordable--and certainly less expensive than the potential problems of an unsecured computer. Similarly, many will take you only a minute or two to perform--again, far less time than you'd spend recovering from a security problem.
Yes, Windows 8 is on the way; it'll be many years before that version runs on a majority of the installed base. So these tips are focused at the computers you are actually using today--especially Windows 7 computers, though most of the advice also applies to Windows Vista or XP machines.
1st commandment: Start with new hardware
Today's new hardware--motherboards, BIOS, CPUs, hard drives, and the system as a whole--includes more security "baked in," even before the operating system is installed. Examples include Trusted Platform Modules (TPM), which embed cryptographic security directly into the hard drive or other component, Unified Extensible Hardware Interface (UEFI) firmware instead of the traditional BIOS, and Intel's vPro security and management technologies. For example, machines with UEFI and TPM will, as part of each boot-up, check the computer's firmware and boot-up binaries to confirm they have not been infected with malware.
If you are working with an existing machine, consider doing a fresh install of the operating system, after completing one (or several) full backup. Ideally, the operating system would be the newest version rather than what was previously installed. (Products like LapLink's PC-Mover can reduce the effort of saving and migrating settings and even application software--although applications should be freshly installed if possible, as well.)
Even if you're working with an existing machine, consider swapping in new hard drives that include built-in encryption. Drives that support the OPAL Storage Specification standard enable companies to manage encrypted drives from multiple vendors--and have also helped reduce the extra cost for an encrypted drive from $100 to nearly zero. After-market drives often include migration tools to speed and simplify a drive swap.
If a self-encrypted drive isn't an option, look at using full-disk encryption software, such as Windows' BitLocker (available only on Enterprise or Ultimate Windows Vista, 7 or 8) or a third-party tool.
2nd commandment: Use current OS versions and automatically get OS and application updates
If you aren't using the most current commercial version of the operating system, it's time to upgrade. Additionally, make sure you set the software to automatically apply updates (not just the OS, but all applications) and periodically turn off the computer, which is when many updates are auto-applied. An appalling number of security breaches occur because applications lack important security fixes that have been available for a year or more.
The computer vendor may also include helpful update tools. For example, Lenovo includes an update process that is designed to show all BIOS and driver updates available for that particular model. You can also manually start the update-check apps process. This may take several cycles, particularly for the first time around, if some updates require other updates.
"Third-party software is usually the vector that security intrusions come through, not the operating system," says Ed Bott, a Windows expert and ZDNet blogger. Flash, Adobe Reader and Java are three of the biggest targets, Bott says. While many programs include their own automatic update checker, Bott urges using a tool like Ninite or Secunia Personal Software Inspector, which automate update checking for all the applications on your computer.
3rd commandment: Use Windows' new security tools (and/or third party software)
Windows 7 includes a number of security controls and tools through its Actions Center (which replaces the Security Center), and other tools are available via the Control Panel, including:
  • Windows Firewall: With its basic settings, this wards off basic attacks, and you can use its advanced settings for more specific control. There are also third-party firewall programs available.
  • Microsoft's Microsoft Security Essentials and Windows Defender. These tools secure your computer against viruses, spyware and other malware.
Obviously another option is to invest in third-party security software, like individual anti-virus, anti-spam and other programs, or a security suite, such as Symantec's.
4th commandment: Set up (or remove) user accounts
Historically in Windows, the default account had administrator privileges--meaning that programs capable of taking unwanted insecure actions wouldn't have to first ask the user if they could run. Starting with Vista, Microsoft added User Account Control (UAC), which asked non-administrator users for permission to run certain programs or actions. With Windows 7, UAC still protects systems but less intrusively.
[Can you guess the 15 worst data breaches?]
Even so, managing which user accounts are--and aren't--available contributes to security in the following ways:
  • Establishes non-administrative user account(s) for each user.
  • Disables or removes user accounts that aren't used or shouldn't be there.
  • Disables the "guest" account, unless it's needed. If it is needed, a password should be required for elevating privileges, to prevent unauthorized changes to the system.
Consider renaming the administrator account so that it's not obvious to an intruder. Since this account can't be "locked out," password attacks can be performed indefinitely; changing the name makes the account less of a target.
5th commandment: Set passwords
Set the main Windows password, as well as the Power/Time to lock the system, with a screen saver, and require a password to resume activity.
Also, depending on the sensitivity of information on your system (did someone say "online banking"?), consider password alternatives, such as:
  • Fingerprint reader
  • Smartcard reader (contact or contactless)
  • Biometric facial recognition
  • RSA software and external token
  • Password "gesture" (e.g., Android tablets)
Another option is two-factor authentication, such as requiring both a fingerprint and a password.
6th commandment: Add/activate anti-theft tools
Invest in, install and activate anti-theft tools that can either lock the system; conduct an IP trace; report, take and send pictures; and even wipe the computer when a lost or stolen computer reconnects to the Internet. An example is Absolute Software's Lojack for Laptops.
Vendors like Lenovo are embedding Absolute's CompuTrace Agent into the BIOS, so even if somebody erases or replaces the hard drive, the agent is automatically re-installed.
Computers that include Intel Anti-Theft technology in their hardware let you add additional security services, such as automatically locking the main board until it receives the "unlock" password, lock or wipe if a machine goes too long without connecting to the Internet or if a user fails the login process too many times. Intel Anti-Theft is typically part of third-party security products like CompuTrace, adding perhaps $3/year, and as the anti-theft option on WinMagic's full disk encryption product.
7th commandment: Turn off sharing and other unneeded services
Windows allows you to share resources that are on your computer, like file-sharing (Shared Folders) and print sharing. Your computer's Internet connection management utility (Windows includes one, but many systems have their own) lets you define each network as either Public, Home or Work. If you mis-set a connection, your Shared Folders will be visible to other computers on the network.
Suggested Desktop Security Reading
If you are behind a firewall, when your computer's Internet connection manager tool asks you what kind of location/connect it is, you can call it either a Home or Work network, Bott says. But specify Public network if you are connecting directly to the Internet (e.g., at home or in the office), if you don't have a hardware router but instead are directly connected to the cable modem, or if you are connecting to a public network like a Wi-Fi hotspot or a hotel or conference Ethernet. This will ensure that no local sharing is allowed.
In general, disable any services and remove programs you don't need. For example, if you're sure your applications won't need it, you may want to uninstall Java. If your machine has Internet Information Services (IIS) running but doesn't need it, disable that, as well.
8th commandment: Secure your Web browser and other applications
Web browsers access Web sites that neither you nor your company control (and these sites, in turn, may have ads or link to other content that they don't control). Any of these may try to inject malware onto your computer.
[Also read 10 ways to secure browsing in the enterprise]
Today's browsers include more security, like "private browsing" session modes that prevent any personal information from being stored, or don't save cookies or history for a session. However, this may interfere with productivity.
Check each browser's security options and select the ones that look useful, like Firefox's "Warn me when sites try to install add-ons" and "Block reported attack sites."
Set Microsoft Internet Explorer to have the highest security setting you can tolerate (since higher security often means you have to click more often), suggests Tom Henderson, Managing Director of ExtremeLabs.com, an Indianapolis, Indiana technology testing lab.
Additionally, look for browser "extensions" and add-ons that increase your browser's security, in a more per-tab, per-site or per-tab-session way. For example, the popular NoScript Firefox add-on allows JavaScript, Java, Flash and other plug-ins to be executed only by trusted Web sites of your choice.
PDF readers may also be vulnerable to JavaScript attacks within the documents they're rendering. Make sure your PDF reader is secure; consider disabling JavaScript within it.
9th commandment: Rope in Autorun
AutoRun is a major threat vector for viruses and other malware in Windows XP and Windows Vista. [Editor's note: Simson Garfinkel called Autorun an "OS design flaw" all the way back in 2006.] With this function, the operating system automatically begins executing a program when it sees an autorun.inf file in the root directory of a new drive, such as a network drive, a CD or a flash drive. So, if you haven't yet moved to Windows 7, make sure you've got all the security updates for the OS version you are running. (See MS Security Advisory: Update for Windows Autorun.)
With Windows 7, all the security settings are "No Autorun." When you attach external media like CDs, DVDs, SD cards and USB flash drives, they will give you a dialog box offering to run a program, but by default, nothing happens automatically.
10th commandment: Consider application whitelisting and other controls "Whitelisting" refers to a list of everything you allow on your computer, including e-mail addresses your mail program can accept, Web sites your browser is allowed to connect to and applications the operating system is allowed to run. Whitelisting may not be a match for e-mail or Web browsing, but for preventing unwanted applications from running--such as malware or zero-day attacks--it may be a good additional tool.
Windows 7 includes AppLocker, a whitelisting utility, or you can buy third-party white-listing products for either individual computers or groups of networked computers. For home users, Windows 7 has fairly robust parental controls that can restrict access by time-of-day or by site, and log Web access, Bott says.


Saturday, 21 April 2012

Wirless Led

Definition
Billions of visible LEDs are produced each year, and the emergence of high brightness AlGaAs and AlInGaP devices has given rise to many new markets. The surprising growth of activity in, relatively old, LED technology has been spurred by the introduction of AlInGaP devices. Recently developed AlGaInN materials have led to the improvements in the performance of bluish-green LEDs, which have luminous efficacy peaks much higher than those for incandescent lamps. This advancement has led to the production of large-area full-color outdoors LED displays with diverse industrial applications.

The novel idea of this article is to modulate light waves from visible LEDs for communication purposes. This concurrent use of visible LEDs for simultaneous signaling and communication, called iLight, leads to many new and interesting applications and is based on the idea of fast switching of LEDs and the modulation visible-light waves for free-space communications. The feasibility of such approach has been examined and hardware has been implemented with experimental results. The implementation of an optical link has been carried out using an LED traffic-signal head as a transmitter. The LED traffic light (fig 1 below) can be used for either audio or data transmission.
Audio messages can be sent using the LED transmitter, and the receiver located at a distance around 20 m away can play back the messages with the speaker. Another prototype that resembles a circular speed-limit sign with a 2-ft diameter was built. The audio signal can be received in open air over a distance of 59.3 m or 194.5 ft. For data transmission, digital data can be sent using the same LED transmitter, and the experiments were setup to send a speed limit or location ID information.

The work reported in this article differs from the use of infrared (IR) radiation as a medium for short-range wireless communications. Currently, IR links and local-area networks available. IR transceivers for use as IR data links are widely available in the markets. Some systems are comprised of IR transmitters that convey speech messages to small receivers carried by persons with severe visual impairments. The Talking Signs system is one such IR remote signage system developed at the Smith-Kettlewell Rehabilitation Engineering Research center. It can provide a repeating, directionally selective voice message that originates at a sign. However, there has been very little work on the use of visible light as a communication medium.

The availability of high brightness LEDs make the visible-light medium even more feasible for communications. All products with visible-LED components (like an LED traffic signal head) can be turned into an information beacon. This iLight technology has many characteristics that are different from IR. The iLight transceivers make use of the direct line-of-sight (LOS) property of visible light, which is ideal in applications for providing directional guidance to persons with visual impairments. On the other hand, IR has the property of bouncing back and forth in a confined environment. Another advantage of iLight is that the transmitter provides easy targets for LOS reception by the receiver. This is because the LEDs, being on at all times, are also indicators of the location of the transmitter. A user searching for information has only to look for lights from an iLight transmitter. Very often, the device is concurrently used for illumination, display, or visual signage. Hence, there is no need to implement an additional transmitter for information broadcasting. Compared with an IR transmitter, an iLight transmitter has to be concerned with even brightness. There should be no apparent difference to a user on the visible light that emits from an iLight device.

It has long been realized that visible light has the potential to be modulated and used as a communication channel with entropy. The application has to make use of the directional nature of the communication medium because the receiver requires a LOS to the audio system or transmitter. The locations of the audio signal broadcasting system and the receiver are relatively stationary. Since the relative speed between the receiver and the source are much less than the speed of light, the Doppler frequency shift observed by the receiver can be safely neglected. The transmitter can broadcast with viewing angle close to 180 . The frequency of an ON period followed by an OFF period to transmit information is short enough to be humanly unperceivable; so that it does not affect traffic control. This article aims to present an application of high-brightness visible LEDs for establishing optical free-space links.

Friday, 20 April 2012

Agni V launch





New Delhi:  Now that the initial euphoria of the successful launch of India's longest range missile (call it IRBM, ICBM, doesn't matter) Agni V is over, congratulatory messages from Prime Minister downwards delivered, scientists and India's strategic community must concentrate on the next steps in fully developing and operationalising the strategic deterrent asset.



As the Prime Minister said in a statement: "I congratulate all the scientific and technical personnel of the DRDO and other organisations who have worked tirelessly in our endeavour to strengthen the defence and security of our country. Today's successful Agni V test launch represents another milestone in our quest to add to the credibility of our security and preparedness and to continuously explore the frontiers of science. The nation stands together in honouring the scientific community."


Without doubt, Agni V represents a major technology breakthrough for Indian missile scientists but it will require several more tests before Agni V can be seen as a credible deterrence.

Although the full telemetry data will take some time to be evaluated, scientists have reported excellent results of the missile's maneuverability terminal guidance system. Indian Naval ships, stationed in the path of the missile's trajectory, would have recorded its journey and picked up all the relevant data.



Built at a reported cost of over 25 million dollars, the 17 metres tall, 50-tonne Agni-V's three stages were powered by solid propellants.  It has a capacity to carry a nuclear warhead weighing over one tonne. 


While the missile is at least four years away from full induction in the armed forces, its successful launch has sent out a message to Asia and the world at large that India now has the capacity to manufacture and launch a highly complex system which only five other nations possess.

In Asia, only China has the capability and better arsenal than India.

In any case, India should not aspire to match China missile for missile.
Agni V however will allow India to possess a credible N-deterrence which is what India is looking for given its No-First Use Nuclear doctrine.

Expectedly, Chinese commentators, or least some of them, have mocked the test. Global Times, the English daily from Beijing headlined the News item: "India being swept up by missile delusion" and went on to comment: "India should not overestimate its strength. Even if it has missiles that could reach most parts of China, that does not mean it will gain anything from being arrogant during disputes with China. India should be clear that China's nuclear power is stronger and more reliable. For the foreseeable future, India would stand no chance in an overall arms race with China."

On a day when India has crossed an important technology threshold, these comments are at best ignored.

Nations have national interests and each nation should act and behave by the dictates of its own national interest without bothering what rivals and neighbours are saying.
India should do exactly that.

The Future of Your PC's Software


64-Bit Computing Allows for More RAM
In 1986, Intel introduced its first 32-bit CPU. It wasn't until 1993 that the first fully 32-bit Windows OS--Windows NT 3.1--followed, officially ending the 16-bit era. Now 64-bit processors have become the norm in desktops and notebooks, though Microsoft still won't commit to an all-64-bit Windows. But it can't live in the 32-bit world forever.
What is it? 64-bit versions of Windows have been around since Windows XP, and 64-bit CPUs have been with us even longer. In fact, virtually every computer sold today has a 64-bit processor under the hood. At some point Microsoft will have to jettison 32-bit altogether, as it did with 16-bit when it launched Windows NT, if it wants to induce consumers (and third-party hardware and software developers) to upgrade. That isn't likely with Windows 7: The upcoming OS is already being demoed in 32-bit and 64-bit versions. But limitations in 32-bit's addressing structure will eventually force everyone's hand; it's already a problem for 32-bit Vista users, who have found that the OS won't access more than about 3GB of RAM because it simply doesn't have the bits to access additional memory.
When is it coming? Expect to see the shift toward 64-bit accelerate with Windows 7; Microsoft will likely switch over to 64-bit exclusively with Windows 8. That'll be 2013 at the earliest. Meanwhile, Mac OS X Leopard is already 64-bit, and some hardware manufacturers are currently trying to transition customers to 64-bit versions of Windows (Samsung says it will push its entire PC line to 64-bit in early 2009). And what about 128-bit computing, which would represent the next big jump? Let's tackle one sea change at a time--and prepare for that move around 2025.

Windows 7: It's Inevitable
Click here to view full-size image.
What is it? At this point Windows 7 seems to be the OS that Microsoft wanted to release as Vista, but lacked the time or resources to complete. Besides continuing refinements to the security system of the OS and to its look and feel, Windows 7 may finally bring to fruition the long-rumored database-like WinFS file system. Performance and compatibility improvements over Vista are also expected.
But the main thrust of Windows 7 is likely to be enhanced online integration and more cloud computing features--look for Microsoft to tie its growing Windows Live services into the OS more strongly than ever. Before his retirement as Microsoft's chairman, Bill Gates suggested that a so-called pervasive desktop would be a focus of Windows 7, giving users a way to take all their data, desktop settings, bookmarks, and the like from one computer to another--presumably as long as all those computers were running Windows 7.
When is it coming? Microsoft has set a target date of January 2010 for the release of Windows 7, and the official date hasn't slipped yet. However, rumor has the first official beta coming out before the end of this year.

Google's Desktop OS
Click here to view full-size image.
What is it? It's everything, or so it seems. Google Checkout provides an alternative to PayPal. Street View is well on its way to taking a picture of every house on every street in the United States. And the fun is just starting: Google's early-beta Chrome browser earned a 1 percent market share in the first 24 hours of its existence. Android, Google's cell phone operating system, is hitting handsets as you read this, becoming the first credible challenger to the iPhone among sophisticated customers.
When is it coming? Though Google seems to have covered everything, many observers believe that logically it will next attempt to attack one very big part of the software market: the operating system.
The Chrome browser is the first toe Google has dipped into these waters. While a browser is how users interact with most of Google's products, making the underlying operating system somewhat irrelevant, Chrome nevertheless needs an OS to operate.
To make Microsoft irrelevant, though, Google would have to work its way through a minefield of device drivers, and even then the result wouldn't be a good solution for people who have specialized application needs, particularly most business users. But a simple Google OS--perhaps one that's basically a customized Linux distribution--combined with cheap hardware could be something that changes the PC landscape in ways that smaller players who have toyed with open-source OSs so far haven't been quite able to do.

USB 3.0 Speeds Up Performance on External Devices


USB 3.0 Speeds Up Performance on External Devices
The USB connector has been one of the greatest success stories in the history of computing, with more than 2 billion USB-connected devices sold to date. But in an age of terabyte hard drives, the once-cool throughput of 480 megabits per second that a USB 2.0 device can realistically provide just doesn't cut it any longer.
What is it? USB 3.0 (aka "SuperSpeed USB") promises to increase performance by a factor of 10, pushing the theoretical maximum throughput of the connector all the way up to 4.8 gigabits per second, or processing roughly the equivalent of an entire CD-R disc every second. USB 3.0 devices will use a slightly different connector, but USB 3.0 ports are expected to be backward-compatible with current USB plugs, and vice versa. USB 3.0 should also greatly enhance the power efficiency of USB devices, while increasing the juice (nearly one full amp, up from 0.1 amps) available to them. That means faster charging times for your iPod--and probably even more bizarre USB-connected gear like the toy rocket launchers and beverage coolers that have been festooning people's desks.
When is it coming? The USB 3.0 spec is nearly finished, with consumer gear now predicted to come in 2010. Meanwhile, a host of competing high-speed plugs--DisplayPort, eSATA, and HDMI--will soon become commonplace on PCs, driven largely by the onset of high-def video. Even FireWire is looking at an imminent upgrade of up to 3.2 gbps performance. The port proliferation may make for a baffling landscape on the back of a new PC, but you will at least have plenty of high-performance options for hooking up peripherals.