Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletter Hub
Free Learning
Arrow right icon
timer SALE ENDS IN
0 Days
:
00 Hours
:
00 Minutes
:
00 Seconds

Tech News

3711 Articles
article-image-qt-creator-4-9-0-released-with-language-support-qml-support-profiling-and-much-more
Amrata Joshi
16 Apr 2019
2 min read
Save for later

Qt Creator 4.9.0 released with language support, QML support, profiling and much more

Amrata Joshi
16 Apr 2019
2 min read
Yesterday, the team behind Qt released the latest version, Qt Creator 4.9.0, a cross-platform software development framework for embedded and desktop applications. This release comes with programming language support, changes to UI, QML support and much more. What’s new in Qt Creator 4.9.0? Language support Qt Creator 4.9 comes with added support for document outline, find usages, and also for code actions that allow the language server to suggest fixes at a specified place in the code. The team has changed the highlighter. It is now based on the KSyntaxHighlighting library, which is used in KDE for this purpose. Changes to UI In this release, the UI for diagnostics from the Clang analyzer tools have been improved as they now are grouped by file now. Diagnostics from the project’s header files are now also included. QML Support The team updated their QML parser to Qt 5.12 that added support for ECMAScript 7. Profiling This release comes with perf, which is a performance profiling tool for software that runs on a Linux system. The integration in Qt Creator is available for applications that run on a local Linux system, and for applications that run on a remote Linux system from a Linux or Windows host. Generic Projects Users can now add a QtCreatorDeployment.txt file to their generic project for specifying the necessary information about where to deploy and which files to deploy. Support for OS For Windows, the team has added support for MSVC (Microsoft Visual C++) 2019. For macOS, a Touch Bar has been added so that users can run Qt Creator on a MacBook. And for Linux, the team has added OpenSSH tools. To know more about this news, check out the Qt blog post. Qt Creator 4.9 Beta released with QML support, programming language support and more! Qt team releases Qt Creator 4.8.0 and Qt 5.12 LTS Qt creator 4.8 beta released, adds language server protocol  
Read more
  • 0
  • 0
  • 12615

Matthew Emerick
15 Oct 2020
1 min read
Save for later

Offer your apps for pre-order even earlier from News - Apple Developer

Matthew Emerick
15 Oct 2020
1 min read
Now you can let customers pre-order your app up to 180 days before it’s released for download on the App Store. Take advantage of this longer lead time to build more excitement for your app’s features, services, and content, and to encourage more pre-orders. Once your app is released, customers will be notified and it will automatically download to their device within 24 hours. Learn more about pre-orders
Read more
  • 0
  • 0
  • 12613

article-image-microsoft-employees-raise-their-voice-against-the-companys-misogynist-sexist-and-racist-acts
Amrata Joshi
22 Apr 2019
4 min read
Save for later

Microsoft employees raise their voice against the company’s misogynist, sexist and racist acts

Amrata Joshi
22 Apr 2019
4 min read
In this era where technologies are advancing and innovation is booming, issues like racism, ageism sexism, patriarchy and misogyny still prevail. Tech industries have also been in light because of these reasons. In 2014, Microsoft CEO, Satya Nadella’s comments on women made news as he suggested that women shouldn’t be asking for a raise. In 2016 Microsoft came up with an AI chatbot called Tay, that got racist by learning from the negative conversations on Twitter. And recently one of the female employees at Microsoft complained about sexual harassment. They shared their frustrations about discrimination and sexual harassment, which was ranging from sexist comments during work trips to being told to sit on a coworker’s lap in front of a human resources leader. She mentioned that an employee from a partner company threatened to kill her if she did not perform implied sexual acts during a work trip.  “I raised immediate attention to HR and management.” She further added, “My male manager told me that ‘it sounded like he was just flirting’ and I should ‘get over it’. HR basically said that since there was no evidence, and this man worked for a partner company and not Microsoft, there was nothing they could do.” It’s disheartening how giant tech companies like Microsoft have a lot of things going on inside and women employees suffer due to baseless responses from the management. According to Microsoft's recent diversity report, 87% of Microsoft employees are white or Asian and more than 73% are men. Employees are questioning the company over its diversity and employee policies. They have now started discussing on Yammer, Microsoft’s internal message board. A female engineer asked, "Does Microsoft have any plans to end the current policy that financially incentivizes discriminatory hiring practices?" In the same post she added, "To be clear, I am referring to the fact that senior leadership is awarded more money if they discriminate against Asians and white men." Similar posts on Yammer related to discriminatory hiring which read, “Women are less suited for engineering roles” received more than 800 comments where few agreed to the statement and few criticized it. A female program Manager commented on the post, “I have an ever-increasing file of white male Microsoft employees who have faced outright and overt discrimination because they had the misfortune of being born both white and male. This is unacceptable.” According to Quartz, a member of Microsoft’s employee investigations team replied to a post related to discrimination, “The company does not tolerate discrimination of any kind.” Employees are not satisfied and they feel that there have been no steps taken so far in this regard. In a statement to Quartz, an employee said, “HR, Satya, all the leadership are sending out emails that they want to have an inclusive culture, but they’re not willing to take any action other than talk about it. They allow people to post these damaging, stereotypical things about women and minorities, and they do nothing about it.” With all sorts of discrimination and harassment at the workplace, it is high time that tech industries introduce major policy changes to encourage a fair, open and comfortable environment for the employees especially women. And for this few have already taken a stand against such issues and are coming together for a transition. https://twitter.com/aprilwensel/status/1119372644418068480 To know more about this news, check out the post by Quartz. Microsoft Bling introduces Fire: a Finite state machine and regular expression manipulation library Microsoft reveals certain Outlook.com user accounts were hacked for months Microsoft makes the first preview builds of Chromium-based Edge available for testing
Read more
  • 0
  • 0
  • 12604

article-image-the-first-release-candidate-of-rails-6-0-0-is-now-out
Vincy Davis
25 Apr 2019
2 min read
Save for later

The first release candidate of Rails 6.0.0 is now out!

Vincy Davis
25 Apr 2019
2 min read
The first release candidate for Rails 6.0.0 was out yesterday. Rails 6.0.0 rc1 is the polished version of all the previous beta releases. Main features include Action Mailbox, Action Text, multiple database support, parallel testing, and Webpacker handling JavaScript by default. The latest  beta release, Rails 6.0.0.beta3 was released last month. In early January, the first release of Rails 6 was announced. Two new major frameworks are added in Rails 6.0 called Action Mailbox and Action Text. There are also two scalable upgrades in the form of multiple database support and parallel testing. Action Mailbox guides incoming emails to controller-like mailboxes in order for processing to take place in Rails. Action Text brings rich text and enables editing such files in Rails. Though the team at Rails couldn't meet their aspirational release schedule, they did manage to include around 1000 commits in Rails 6.0.0 rc1. The crew at The Pragmatic Programmers, particularly Sam Ruby, David Bryant Copeland have also come up with beta of Agile Web Development with Rails 6  to coincide with the release of rc1. For more information on the release, check out their official announcement. GitLab considers moving to a single Rails codebase by combining the two existing repositories Uber releases AresDB, a new GPU-powered real-time Analytics Engine Niantic, of the Pokemon Go fame, releases a preview of its AR platform
Read more
  • 0
  • 0
  • 12598

article-image-ibm-launches-blockchain-backed-food-trust-network-which-aims-to-provide-greater-transparency-on-food-supply-chains
Richard Gall
09 Oct 2018
2 min read
Save for later

IBM launches blockchain-backed Food Trust network which aims to provide greater transparency on food supply chains

Richard Gall
09 Oct 2018
2 min read
Food supply chains have become a contentious topic in recent years, with question marks over standards, safety and the environmental impact of modern farming and manufacturing. IBM, however, would seem to have found a solution - blockchain. The tech multinational yesterday (October 8) launched its Food Trust system, a ledger that will give stakeholders at every point in the supply chain improved transparency over where food has come from and how it has been produced. IBM has been working on its Food Trust system for 18 months. With its launch, it has revealed a number of organizations taking part in the pilot scheme, such as French food giant Carrefour and Walmart. Laurent Vallée, Carrefour's General Secretary, said: "Being a founding member of the IBM Food Trust platform is a great opportunity for Carrefour to strongly accelerate and widen the integration of blockchain technology to our products in order to provide our clients with safe and undoubted traceability." Why blockchain could be a game-changer for the food industry The advantages of using IBM's blockchain-backed technology is clear - it offers transparency for everyone. Because a ledger offers a single view for all stakeholders, every transaction that takes place is observable - this means that bad practices, such as a vendor going to a different supplier from the one agreed, to, say, cut costs, can be easily identified. Walmart's Frank Yiannas, VP for food safety, explained that Walmart wants to "create the equivalence of FedEx tracking for food," so everyone involved in a supply chain has full visibility. Obviously, from a safety perspective, this could be huge, and should, in time at least, discourage bad practice. The success of IBM's Food Trust system remains to be seen. It is, however, a sharp riposte to blockchain sceptics. It might also turn out to be an important victory for tech optimists. At a time when technology appears hell bent on eroding trust, perhaps this is a vital example of technology helping to reassert the importance of trust in the public realm. Read next: How far will Facebook go to fix what it broke: Democracy, Trust, Reality
Read more
  • 0
  • 0
  • 12591

article-image-microsoft-acquires-citus-data-with-plans-to-create-a-best-postgres-experience
Melisha Dsouza
25 Jan 2019
3 min read
Save for later

Microsoft acquires Citus Data with plans to create a ‘Best Postgres Experience’

Melisha Dsouza
25 Jan 2019
3 min read
Yesterday, Microsoft announced that it has acquired Citus Data- a startup that specializes in big data and analytics.Citus  is an extension to the open source database management system PostgreSQL, which transforms PostgreSQL into a distributed database. The start-up was founded in 2011 and apart from their Citus extension, 'Citus Cloud' database as a service powers billions of transactions every day giving rise to the world’s first horizontally scalable relational database which can be run on premises, and as a fully-managed service on the cloud. Citus has varied applications ranging from SaaS companies who run their core applications on Citus Cloud scaling their business on-demand to businesses using Citus to power their real-time analytics dashboards. Citus also states that they have been able to help many Fortune 100 companies migrate to an open, horizontally scalable Postgres ecosystem and have improved developer performance while providing them with scalability to power their workloads without re-architecting their applications. In a blog post, Umur Cubukcu, Ozgun Erdogan, and Sumedh Pathak; co-founders of Citus Data said that as part of Microsoft, “we will stay focused on building an amazing database on top of PostgreSQL that gives our users the game-changing scale, performance, and resilience they need.” Adding to this point, Microsoft admits that “Both Citus and Microsoft share a mission of openness, empowering developers, and choice. And we both love PostgreSQL. We are excited about joining forces, and the value that doing so will create: Delivering to our community and our customers the world’s best PostgreSQL experience.” Acquiring Citus is a step towards Microsoft’s commitment to Open Source technologies as well as enhancing Azure PostgreSQL performance and scalability as customer workloads keep expanding. Earlier this month, DB-Engines conferred the title of DBMS of the Year on PostgreSQL. Microsoft and Citus Data have committed themselves to enable customers in scaling complex multi-tenant SaaS applications and accelerate the time to insight with real-time analytics over huge amounts of data, all with the familiar PostgreSQL tools. Developers have received this news well. Twitter saw many users commenting on the decision being a smart once, since PostgreSQL is well used among developers. https://twitter.com/izotov/status/1088563182006923264 https://twitter.com/satyanadella/status/1088578781663571975 The price of the acquisition was not disclosed. To know more about this announcement, head over to Microsoft's official blog. NYT says Facebook has been disclosing personal data to Amazon, Microsoft, Apple and other tech giants; Facebook denies claims with obfuscating press release Microsoft urgently releases Out-of-Band patch for an active Internet Explorer remote code execution zero-day vulnerability Citus Data to donate 1% of its equity to non-profit PostgreSQL organizations    
Read more
  • 0
  • 0
  • 12587
Unlock access to the largest independent learning library in Tech for FREE!
Get unlimited access to 7500+ expert-authored eBooks and video courses covering every tech area you can think of.
Renews at $19.99/month. Cancel anytime
article-image-gitlab-11-0-released
Savia Lobo
25 Jun 2018
2 min read
Save for later

GitLab 11.0 released!

Savia Lobo
25 Jun 2018
2 min read
GitLab recently announced the release of GitLab 11.0 which includes major features such as the Auto DevOps and License Management; among other features. The Auto DevOps feature is generally available in GitLab 11.0. It is a pre-built, fully featured CI/CD pipeline that automates the entire delivery process. With this feature, one has to simply commit their code and Auto DevOps does the rest. This includes tasks such as building and testing the app; performing code quality, security, and license scans. One can also package, deploy and monitor their applications using Auto DevOps. Chris Hill, head of systems engineering for infotainment at Jaguar Land Rover, said, “We’re excited about Auto DevOps, because it will allow us to focus on writing code and business value. GitLab can then handle the rest; automatically building, testing, deploying, and even monitoring our application.” License Management automatically detects licenses of project's dependencies such as, Enhanced Security Testing of code, containers, and dependencies: GitLab 11.0 has an extended coverage of Static Analysis Security Testing (SAST) and  includes Scala and .Net. Kubernetes integration features: If one needs to debug or check on a pod, they can do so by reviewing the Kubernetes pod logs directly from GitLab's deployment board. Improved Web IDE:  One can view their CI/CD pipelines from the IDE and get immediate feedback if a pipeline fails. Switching tasks can be disruptive, so the updated Web IDE makes it easy to quickly switch to the next merge request, to create, improve, or review without leaving the Web IDE. Enhanced Epic and Roadmap views : GitLab 11.0 has an updated Epic/Roadmap navigation interface to make it easier to see the big images and make planning easier. Read more about GitLab 11.0 on its GitLab’s official website. GitLab’s new DevOps solution GitLab open sources its Web IDE in GitLab 10.7 The Microsoft-GitHub deal has set into motion an exodus of GitHub projects to GitLab
Read more
  • 0
  • 0
  • 12584

article-image-core-cpython-developer-publishes-a-post-analyzing-his-phones-silent-connections
Natasha Mathur
25 Feb 2019
4 min read
Save for later

Core CPython developer unveils a new project that can analyze his phone's ‘silent connections’

Natasha Mathur
25 Feb 2019
4 min read
Kushal Das, a staff member at Freedom of the Press Foundation, privacy advocate, and a CPython core developer published a post earlier this month, titled, ‘Tracking my phone’s silent connections’. In the post, Das talks about the new system that he has built using the existing open source projects and tools, to track what his phone does, what servers it connects to and to look deeper into the network traffic from the phone. How did he start? Das mentions that his initial trial involved creating a wifi hotspot at home using a Raspberry Pi. He then started to capture all the packets from this device with the help of standard tools (dumpcap) and via the logs using Wireshark, a network protocol analyzer. This procedure, however, was only capable of capturing the data when connected to the network at home. So, to take the procedure further ahead, Das took a different approach where he chose ‘algo’ to create a VPN server. He then made use of WireGuard, a modern VPN tunnel, to connect his iPhone to the VPN. This process allowed capturing all the traffic from the phone easily on the VPN server. Analyzing the data post one week Das captured the data initially for only one week. He then started to capture pcap files into his computer, where he also wrote Python code to put the data into an SQLite database. This allowed him to query the data very fast. Das plotted a graph with all the different domains that got queried at least 10 times in a week where he observed that his phone was trying to find servers from Apple as it is an iPhone. He also noted many queries related to Twitter as he uses the Twitter app frequently. Then it was Google, for which the phone queried many other Google domains (although he only sometimes browsed through YouTube). He also observed queries to Akamai CDN service and Amazon AWS related hosts. Many data analytics related companies were also queried including dev.appboy.com. Tracking the data flow After looking at the DNS queries, Das wanted to look deeper into the actual servers that his phone communicates with. Das put together a graph of all the major companies that his phone communicates to, here’s the graph:                                                                   Major Companies Das discovered that Apple is the leading firm that takes about 44% of all the connections in his phone, and the number is 495225 times. Twitter earns the second place, with Edgecastcdn taking the third. He noticed that his phone communicated with Google servers 67344 number of times i.e. 7 times less than Apple. He then further removed big firms such as Google and Amazon from the graph and observed that the analytics companies such as nflxso.net and mparticle.com make up about 31% of the connections. The 3 other CDN companies are Akamai, CloudFront, and Cloudflare that make up 8%, 7%, and 6% each. Das mentions that he doesn’t have information about the things that these companies track on his phone which he finds scary. “Do I know what all things are these companies tracking? Nope, and that is scary enough,” said Das. Future work Das mentions that he’s looking into creating a set of tools in the future that can: Be deployed on the VPN server are user-friendly and easy to monitor block/unblock traffic from their phone. “The major part of the work is to make sure that the whole thing is easy to deploy, and can be used by someone with less technical knowledge”, states Das. For more information, check out the official blog post by Kushal Das. OpenAI team publishes a paper arguing that long term AI safety research needs social scientists China’s Huawei technologies accused of stealing Apple’s trade secrets, reports The Information UK lawmakers publish a report after 18 month long investigation condemning Facebook’s disinformation and fake news practices
Read more
  • 0
  • 0
  • 12583

article-image-plotly-4-0-popular-python-data-visualization-framework-releases
Fatema Patrawala
23 Jul 2019
3 min read
Save for later

Plotly 4.0, popular python data visualization framework, releases with Offline Only, Express first, Displayable anywhere features

Fatema Patrawala
23 Jul 2019
3 min read
Yesterday the Plotly team announced the release of Plotly.py 4.0 version which is now available for download from PyPI. This version includes some exciting new features and changes, including a switch to “offline” mode by default, the inclusion of Plotly Express as the recommended entry point into the library, and a new rendering framework compatible with not only Jupyter notebooks but other notebook systems such as Colab, Azure and Kaggle notebooks, as well as popular IDEs such as PyCharm, VSCode, Spyder and others. To upgrade to the latest version, you can run pip install plotly==4.0.0 or conda install -c plotly plotly==4.0.0. More details can be found from the page Getting Started and Migrating to Version 4 guides. Let us check out the key features in Plotly 4.0 Offline Only Prior versions of plotly contained functionality for creating figures in both “online” and “offline” modes. In “online” mode, figures were uploaded to an instance of Plotly’s Chart Studio service and then displayed, whereas in “offline” mode figures were rendered locally. This duality was a common source of confusion for several years, and so in version 4 the team made some important changes to help clear this up. In this version, the only supported mode of operation in the plotly package is “offline” mode, which requires no internet connection, no account, no authentication tokens, and no payment of any kind. Support for “online” mode has been moved into a separately-installed package called chart-studio. Express First Earlier this year the team released a standalone library called Plotly Express aimed at making it significantly easier and faster to create plotly figures from tidy data—as easy as a single line of Python. Plotly Express was extremely well-received by the community and starting with version 4, plotly now includes Plotly Express built-in which is accessible as plotly.express. Displayable anywhere In addition to “offline” mode, the plotly.offline package has been reimplemented on top of a new extensible renderers framework which enables Plotly figures to be displayed not only in Jupyter notebooks, but just about anywhere, like: JupyterLab & classic Jupyter notebook Other notebooks like Colab, nteract, Azure & Kaggle IDEs and CLIs like VSCode, PyCharm, QtConsole & Spyder Other contexts such as sphinx-gallery Dash apps (with dash_core_components.Graph()) Static raster and vector files (with fig.write_image()) Standalone interactive HTML files (with fig.write_html()) Embedded into any website (with fig.to_json() and Plotly.js) In addition to the above new features, there are other changes like a new default theme available in Plotly.py 4.0. The team has introduced a suite of new figure methods for updating figures after they have been constructed. It also supports all subplot and trace types: 2D, 3D, polar, ternary, maps, pie charts, sunbursts, Sankey diagrams etc. Plotly.py 4.0 is also supported by JupyterLab 1.0. To know about these feature updates in detail, check out the Medium post by the Plotly team. Plotly releases Dash DAQ: a UI component library for data acquisition in Python plotly.py 3.0 releases Python in Visual Studio Code released with enhanced Variable Explorer, Data Viewer, and more!
Read more
  • 0
  • 0
  • 12579

article-image-amazon-faces-increasing-public-pressure-as-hq2-plans-go-under-the-scanner-in-new-york
Natasha Mathur
05 Feb 2019
3 min read
Save for later

Amazon faces increasing public pressure as HQ2 plans go under the scanner in New York

Natasha Mathur
05 Feb 2019
3 min read
Andrea Stewart-Cousins, majority leader of the New York State Senate, and the senate democrats, nominated the New York State Senator, Michael Gianaris of Queens to serve on the five-member Public Authorities Control Board (PACB), yesterday. The news, first reported by the NY Times, has stirred up a worry among those who support Amazon’s HQ2 proposal to build a 25,000-person office in New York City (announced last year in November).  This is because Gianaris has been a vocal opponent of Amazon HQ2, and if selected, can veto the state actions on the project. “My position on the Amazon deal is clear and unambiguous and is not changing. It’s hard for me to say what I would do when I don’t know what it is I would be asked to opine on”, said Gianaris. The Amazon HQ2 deal for Long Island City was negotiated by Gov. Andrew Cuomo back in November 2018. “With Amazon committing to expand its headquarters in Long Island City, New York can proudly say that we have attracted one of the largest, most competitive economic development investments in U.S. history,” said Cuomo. He now has a final say over whether to refuse or approve the Senate’s selection. The day after Amazon announced its plans to build its 1.5 million square foot corporate headquarters in Long Island City, Queens, New York City, Gianaris started a protest against Amazon. Gianaris was joined by other New Yorkers who protested against the company’s plan, asking it to be abandoned.   https://twitter.com/SenGianaris/status/1062787029761753088 https://twitter.com/SenGianaris/status/1062693588457394176 Amazon’s new campus is supposed to be located along Long Island City’s waterfront, across the East River from Manhattan’s Midtown East neighborhood. Amazon has promised 50,000 jobs and will take in 25,000 employees with an average wage of $150,000 a year. Moreover, the company will receive at least $2.8 billion in incentives from the state and city and if it passes the goal of 25,000 workers in Long Island City, it could also receive state tax breaks. Gianaris does not approve of this as he believes that spending $2.8 billion in state and city incentives to Amazon is a “bad deal”. https://twitter.com/SenGianaris/status/1063066018694737920 He even went ahead to call it a ‘#Scamazon deal’. https://twitter.com/SenGianaris/status/1090632342719381504 Many people are in favor of Gianaris. According to Stuart Applebaum, President, Retail, Wholesale, and Department Store Union, Gianaris, has “proven himself to be a champion of workers’ rights”: https://twitter.com/RWDSU/status/1092536178073653248 Dani Lever, a spokeswoman for Cuomo, said that the recommendation of Gianaris “puts the self-interest of a flip-flopping opponent of the Amazon project above the state’s economic growth. Every Democratic Senator will now be called on to defend their opposition to the greatest economic growth potential this state has seen in over 50 years”. Amazon launches TLS Termination support for Network Load Balancer Sally Hubbard on why tech monopolies are bad for everyone: Amazon, Google, and Facebook in focus Rights groups pressure Google, Amazon, and Microsoft to stop selling facial surveillance tech to government
Read more
  • 0
  • 0
  • 12575
article-image-have-i-been-pwned-up-for-acquisition-troy-hunt-code-names-this-campaign-project-svalbard
Savia Lobo
12 Jun 2019
4 min read
Save for later

‘Have I Been Pwned’ up for acquisition; Troy Hunt code names this campaign ‘Project Svalbard’

Savia Lobo
12 Jun 2019
4 min read
Yesterday, Troy Hunt, revealed that his ‘Have I Been Pwned’(HIBP) website is up for sale, on his blogpost. Hunt has codenamed this acquisition as Project Svalbard and is working with KPMG to find a buyer. [box type="shadow" align="" class="" width=""]Troy Hunt has named Project Svalbard after the Svalbard Global Seed Vault, which is a secure seed bank on the Norwegian island of Spitsbergen. This vault represents the world’s largest collection of crop diversity with a long-term seed storage facility, for worst-case scenarios such as natural or man-made disasters.[/box] Commercial subscribers highly depend on HIBP to alert members of identity theft programs, enable infosec companies, provide services to their customers, protect large online assets from credential stuffing attacks, preventing fraudulent financial transactions and much more. Also,  governments around the world and the law enforcement agencies use HIBP to protect their departments and also for their investigations respectively. Hunt further says he has been handling everything alone. “to date, every line of code, every configuration and every breached record has been handled by me alone. There is no “HIBP team”, there’s one guy keeping the whole thing afloat”, he writes. However, in January, this year he discovered Collection #1 data breach which included 87 GB worth of data in a folder containing 12,000-plus files, nearly 773 email addresses, and more than 21 million unique passwords from data breaches going back to 2008. Hunt uploaded all of these breached data to HIBP and since then he says the site has seen a massive influx in activity, thus, taking him away from other responsibilities. “The extra attention HIBP started getting in Jan never returned to 2018 levels, it just kept growing and growing,” he says. Hunt said he was concerned about burnout, given the increasing scale and incidence of data breaches. Following this, he said it was time for HIBP to “grow up”. He also believed HIBP could do more in the space, including widening its capture of breaches. https://twitter.com/troyhunt/status/1138322112224083968 “There's a whole heap of organizations out there that don't know they've been breached simply because I haven't had the bandwidth to deal with it all,” Hunt said. “There's a heap of things I want to do with HIBP which I simply couldn't do on my own. This is a project with enormous potential beyond what it's already achieved and I want to be the guy driving that forward,” Hunt wrote. Hunt also includes a list of “commitments for the future of HIBP” in his blogpost. He also said he intended to be “part of the acquisition - that is some company gets me along with the project” and that “freely available consumer searches should remain freely available”. Via Project Svalbard, Hunt hopes to enable HIBP to reach out to more and more people and play “a much bigger role in changing the behavior of how people manage their online accounts.” A couple of commenters on the blog post ask Hunt whether he’s considered/approached Mozilla as a potential owner. In a reply to one he writes,“Being a party that’s already dependent on HIBP, I reached out to them in advance of this blog post and have spoken with them. I can’t go into more detail than that just now, but certainly their use of the service is enormously important to me.” To know more about this announcement in detail, read Troy Hunt’s official blogpost. A security researcher reveals his discovery on 800+ Million leaked Emails available online The Collections #2-5 leak of 2.2 billion email addresses might have your information, German news site, Heise reports Bo Weaver on Cloud security, skills gap, and software development in 2019
Read more
  • 0
  • 0
  • 12573

article-image-google-releases-a-fix-for-the-zero-day-vulnerability-in-its-chrome-browser-while-it-was-under-active-attack
Melisha Dsouza
07 Mar 2019
3 min read
Save for later

Google releases a fix for the zero day vulnerability in its Chrome browser while it was under active attack

Melisha Dsouza
07 Mar 2019
3 min read
Yesterday, Google announced that a patch for Chrome released last week was actually a fix for an active zero-day discovered by its security team. The bug tagged as CVE-2019-5786, was originally discovered by Clement Lecigne of Google's Threat Analysis Group on Wednesday, February 27th and is currently under active attack. The threat advisory states that this vulnerability involves a memory mismanagement bug in a part called ‘FileReader’ of the Chrome browser. The FileReader is a programming tool that allows web developers to pop up menus and dialogs asking a user to choose from a list of local files to upload or an attachment to be added to their webmail. The attackers can use this vulnerability to execute a Remote Code Execution or RCE. ZDNet states that the bug is a type of memory error that happens when an app tries to access memory after it has been freed/deleted from Chrome's allocated memory. If this type of memory access operation is mishandled, it can lead to the execution of malicious code. Chaouki Bekrar, CEO of exploit vendor Zerodium, tweeted that the vulnerability allegedly allows malicious code to escape Chrome's security sandbox and run commands on the underlying OS. https://twitter.com/cBekrar/status/1103138159133569024 Not divulging in any further information on the bug, Google says: “Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.” Further, Forbes reports that Satnam Narang, a senior research engineer at Tenable has said that it is a "Use-After-Free (UAF) vulnerability in FileReader, an application programming interface (API) included in browsers to allow web applications to read the contents of files stored on a user's computer." Catalin Cimpanu, a security reporter at ZDNet, suggests that there are malicious PDF files in the wild that are being used to exploit this vulnerability. "The PDF documents would contact a remote domain with information on the users' device --such as IP address, OS version, Chrome version, and the path of the PDF file on the user's computer", he added. The fix for this zero-day Users are being advised to update Chrome across all platforms. https://twitter.com/justinschuh/status/1103087046661267456 Check out the new version of Chrome for Android and the patch for Chrome OS . Mac, Windows, and Linux users are advised to manually initiate the download if it is yet to be pushed to a device. Head over to chrome://settings/help to check the current version of Chrome on your system. The URL will also do an update check at the same time, just in case any recent auto-updates have failed. Google Chrome developers “clarify” the speculations around Manifest V3 after a study nullifies their performance hit argument Google’s new Chrome extension ‘Password CheckUp’ checks if your username or password has been exposed to a third party breach Hacker duo hijacks thousands of Chromecasts and Google smart TVs to play PewDiePie ad, reveals bug in Google’s Chromecast devices!
Read more
  • 0
  • 0
  • 12573

article-image-visual-studio-2019-new-features-you-should-expect-to-see
Richa Tripathi
12 Jun 2018
3 min read
Save for later

Visual Studio 2019: New features you should expect to see

Richa Tripathi
12 Jun 2018
3 min read
Microsoft announced Visual Studio 2019, the next major version of its signature IDE (Integrated Development Environment) for software design. This exciting news has come right on the heels of Microsoft’s acquisition of GitHub. According to Microsoft, the company is still in the "early planning phase" for Visual Studio 2019 and Visual Studio for Mac. Release timing will be shared “in the coming months,” with the company simply promising “to deliver Visual Studio 2019 quickly and iteratively.” Along with general improvements to make the developer tool more reliable and more productive, Microsoft has some concrete goals in mind. Last month at Build 2018 developers conference, Microsoft demonstrated two new Visual Studio previews: IntelliCode and Live Share. The former uses AI to offer intelligent suggestions that improve code quality and productivity, and the latter lets developers collaborate in real time with team members who can edit and debug directly from Visual Studio and Visual Studio Code. Specific features that will be delivered in VS2019 are not provided, rather Microsoft lists various themes that the project will address. Here are the major new features Microsoft will bring in Visual Studio 2019 in coming days : It will continue to explore connected capabilities such as Live Share, for users to collaborate in real time on the same code base worldwide. It wants to investigate making cloud development situations, such as working with online source repositories, smoother. Enhancements for AI-assisted development via IntelliCode and use of the Azure cloud to deliver AI-powered assistance to developers. Operational enhancements such as additional refactoring, quicker application load, faster builds, improved navigation, and improved debugging. The release date for VS2019 is not available yet, but VS2017 was released in March 2017 and was preceded by several preview builds throughout 2016. Similarly, one would expect the first preview build of VS2019 in late summer / early autumn this year.  Fortunately VS2019 is being designed to install side-by-side with existing VS2017 builds, so it will be easy to try out the new release when it is available. A key fact about this next release, according to Microsoft, is that it will remain a 32-bit application and will support Windows 7. Initial developer reactions indicate there are concerns about the unresolved issues and code quality problems with VS2017, and that it is premature to shift to VS2019.  Microsoft does not offer specifics, but does indicate that they are working to improve this with the development team. Microsoft is going to acquire GitHub Unit Testing in .NET Core with Visual Studio 2017 for better code quality What’s new in Visual Studio 1.22  
Read more
  • 0
  • 0
  • 12562
article-image-grafana-6-0-beta-is-here-with-new-panel-editor-ux-google-stackdriver-datasource-and-grafana-loki-among-others
Natasha Mathur
04 Feb 2019
4 min read
Save for later

Grafana 6.0 beta is here with new panel editor UX, google stackdriver datasource, and Grafana Loki among others

Natasha Mathur
04 Feb 2019
4 min read
Grafana, data visualization & analytics platform, released the beta version of Grafana 6.0, last week. Grafana 6.0 beta explores new features such as Explore, Grafana Loki, Gauge Panel, New panel editor UX, and Google stackdriver datasource among others. Grafana is an open source data visualization and monitoring tool that can be used on top of a variety of different data stores but is commonly used together with Graphite, InfluxDB, Elasticsearch, and Logz.io. Let’s discuss the key highlights in Grafana 6.0 beta. Explore Explore is a new feature in Grafana 6.0 beta that allows you to create a new interactive debugging workflow and helps integrate metrics and logs. The Prometheus query editor in Explore has improved autocomplete, metric tree selector, and integrations with the Explore table view. This allows easy label filtering and offers useful query hints that can automatically apply functions to your query. Also, there is no need to switch to other tools for debugging purposes, since Explore allows you to dig deeper into your metrics and logs to find the bug related cause. Grafana’s new logging datasource, called, Loki is also tightly integrated into Explore, enabling you to correlate metrics and logs by viewing them side-by-side. Explore supports splitting the view, allowing you to easily compare different queries, datasources, metrics and logs. Grafana Loki The log exploration and visualization features in Explore are available in any data source but have been currently implemented only by the new open source log aggregation system from Grafana Lab, called Grafana Loki. Grafana Loki is a horizontally-scalable, highly-available, and multi-tenant log aggregation system inspired by Prometheus. It is very cost effective as it does not index the contents of the logs but a set of labels for each log stream. The logs from Loki gets queried in a similar way to querying with label selectors in Prometheus. Loki makes use of labels to group log streams which can be made to match up with your Prometheus labels. New Panel Editor Grafana beta 6.0 has a new, redesigned UX around editing panels. The new panel editor lets you resize the visualization area in case the user wants more space for queries and options. It also allows you to change visualization (panel type) from within the new panel edit mode, hence, eliminating the need to add a new panel to try out different visualizations. Azure Monitor Datasource The Grafana team worked on developing an external plugin for Azure Monitor last year and it is now being moved into Grafana to be one of the built-in datasources. As a core datasource, the Azure Monitor datasource will be getting the alerting support for the official Grafana 6.0 release. The Azure Monitor datasource integrates four different Azure services with Grafana, namely, Azure Monitor, Azure Log Analytics, Azure Application Insights, and Azure Application Insights Analytics. Other changes Grafana 6.0 beta comes with a new and separate Gauge panel. Gauge Panel contains a new threshold editor that the team plans to refine and use in other panels. Built-in support for Google Stackdriver has been officially released in Grafana 6.0 beta. Grafana 6.0 beta comes with newly added support for provisioning alert notifiers from configuration files. This feature allows operators to provision notifiers without using the UI or the API. A new field called uid (string identifier) has been added that the administrator can set themselves. The ElasticSearch datasource in Grafana 6.0 beta now supports bucket script pipeline aggregations. This allows it to do per bucket computations such as the difference or ratio between two metrics. The color picker has been updated in Grafana to show named colors and primary colors. This will improve accessibility and will make colors more consistent across dashboards. For more information, check out the official Grafana 6.0 beta release notes. Grafana 5.3 is now stable, comes with Google Stackdriver built-in support, a new Postgres query builder Cortex, an open source, horizontally scalable, multi-tenant Prometheus-as-a-service becomes a CNCF Sandbox project Tumblr open sources its Kubernetes tools for better workflow integration
Read more
  • 0
  • 0
  • 12559

article-image-these-robot-jellyfish-are-on-a-mission-to-explore-and-guard-the-oceans
Bhagyashree R
24 Sep 2018
3 min read
Save for later

These robot jellyfish are on a mission to explore and guard the oceans

Bhagyashree R
24 Sep 2018
3 min read
Earlier last week, a team of US scientists, from Florida Atlantic University (FAU) and the US Office of Naval Research published a paper on five jellyfish robots that they have manufactured. The paper is titled Thrust force characterization of free-swimming soft robotic jellyfish. The prime motive of the scientists to build such robotic jellyfish is to track and monitor fragile marine ecosystems without causing unintentional damage to them. These soft robots can swim through openings narrower than their bodies and are powered by hydraulic silicon tentacles. These so-called ‘jelly-bots’ have the ability to squeeze through narrow openings using circular holes cut in a plexiglass plate. The design structure of ‘Jelly-bots’ Jelly-bots have a similar design to that of a moon jellyfish (Aurelia aurita) during the ephyra stage of its life cycle before they becoming a fully grown medusa. To avoid the damage to fragile biological systems by the robots, soft hydraulic network actuators are chosen. To allow the jellyfish to steer, the team uses two impeller pumps to inflate the eight tentacles. The mold models for the jellyfish robot were designed in SolidWorks and subsequently, 3D printed with an Ultimaker 2 out of PLA (polylactic acid). Each jellyfish has varying rubber hardness to test the effect it has on the propulsion efficiency. Source: IOPScience What this study was about? These jelly robots will help the scientists in determining the impact of the following factors on the measured thrust force: Actuator material Shore hardness Actuation frequency Tentacle stroke actuation amplitude The scientists found that all three of these factors significantly impact mean thrust force generation, which peaks with a half-stroke actuation amplitude at a frequency of 0.8 Hz. Results The material composition of the actuators significantly impacted the measured force produced by the jellyfish, as did the actuation frequency and stroke amplitude. The greatest forces were measured with a half-stroke amplitude at 0.8 Hz and a tentacle actuator-flap material Shore hardness composition of 30–30. In the test, the jellyfish was able to swim through the narrow openings than the nominal diameter of the robot and demonstrated the ability to swim directionally. The jellyfish robots were tested in the ocean and have the potential to monitor and explore delicate ecosystems without inadvertently damaging them. One of the scientists, Dr. Engeberg said to Tech Xplore: "In the future, we plan to incorporate environmental sensors like sonar into the robot's control algorithm, along with a navigational algorithm. This will enable it to find gaps and determine if it can swim through them." To know more in detail about the jellybots, read the research paper published by these scientists. You may also go through a  video showing jellybots functioning in deep waters. Sex robots, artificial intelligence, and ethics: How desire shapes and is shaped by algorithms MEPs pass a resolution to ban “Killer robots” 6 powerful microbots developed by researchers around the world
Read more
  • 0
  • 0
  • 12556
Modal Close icon
Modal Close icon