Showing posts with label Technology. Show all posts
Showing posts with label Technology. Show all posts

Heartbleed : The most dangerous web security bug, explained in a simple way.


On April 1st last month, Neel Mehta of Google Security discovered a flaw in the OpenSSL cryptographic library, which is an encryption technology used to secure over two-thirds of the internet traffic. (Yes, this is the lock that appears on your browser's address bar indicating the site is safe). Very soon on April 4th, a security team at Codenomicon also discovered this bug and named it Heartbleed and also gave a logo to it.

This bug was later reported on countless sites and media as the most catastrophic vulnerability ever discovered since the flow of internet traffic started. 

What can the bug do?

The flaw in OpenSSL technology meant that any skilled hacker would be exposed to critical information ranging from your username-passwords to your credit card details. And that too without being traceable.

What kind of websites can the bug affect?

According to the official website of Heartbleed, "Your popular social site, your company's site, commerce site, hobby site, site you install software from or even sites run by your government might be using vulnerable OpenSSL". Which is around 66% of today's internet !

What can be affected by Heartbleed?

Popular websites listed below were vulnerable or suspected to be vulnerable to the attack. However they have been quickly fixed to prevent Heartbleed.

  • Google
  • Facebook
  • Twitter
  • Yahoo
  • Gmail
  • Youtube
  • Instagram
  • Pinterest
  • Tumblr
  • Yahoo Mail
  • GoDaddy
  • Dropbox
  • OkCupid

Heartbleed can not only attack websites but applications too. Many of the android 4.1.1 apps are believed to be susceptible to the attack. However, google has a pushed a patch to device manufacturers. There are various tools out there which can tell you whether a site or an app is vulnerable or not.

Is Heartbleed still active?

A patched version of OpenSSL was released on April 7th, the day the bug was disclosed to the public. However, it would be wise for you to change the passwords of websites which you hold dear.

Since when is Heartbleed active?

Heartbleed was found only in version 1.0.1 of OpenSSL which was released on March 14, 2012. And from then until April 1, 2014, nobody detected the bug and websites and apps were susceptible to the attack !

How did Heartbleed appear?

A programmer called Robin Seggelmann created an extension called Heartbeat (hence the name Heartbleed) and submitted the code for review to Stephen N. Henson, a core developer at OpenSSL who failed to notice the bug and integrated it to the source code.

How does Heartbleed work?

Considering the Client-Server model, in a typical Heartbeat scenario, the Client requests information using a Heartbeat message (having a maximum of 64KB memory) from the server. Example, if the client asks for a 7 letter word, say Address, the server replies with a 7 letter word Address, irrespective of whether the word occupied the entire 64KB of memory or not (the bug).

Heartbleed exploits this scenario by asking the client to send a 500 letter word Address, and the server now sends the entire information contained in a memory occupied by a 500 letter word along with Address, say Address, No.21, ABC Lane, Password is 123@XYZ, basically whatever was stored in the active 64KB of memory of the server after Address. 

For more info : heartbleed







The new OnePlus One smartphone - 'Flagship Killer'?


Is it the titan killer? The flagship stopper? The king slayer? But there’s one thing I know for sure: this is one heck of a smartphone.

OnePlus' One Android smartphone has created quite a stir since it was unveiled recently. Featuring top-of-the-line specs at an extremely affordable price, the smartphone is being labeled as "Nexus-Killer" as Google's flagship smartphone was known for featuring high-end specs at cheaper prices. Its manufacturer, OnePlus has labeled the One as the "Flagship Killer". The One's specs at the price of $299 sound to good to be true.

The One has been reported to be FAST! Thanks to its Snapdragon 801 processor coupled with 3GB of RAM and CyanogenMod which makes the phone even more blazing fast. The phone has enough battery and storage size to satisfy any harcore Android user. Having no removable battery or an expandable SD card don't sound like a problem when the phone features a 3100mAh battery and also comes in a 64GB storage variant that costs the same as the 16GB variant of Nexus 5.

Geek.com were lucky enough to get a hands-on with the upcoming smartphone. The site reports that the One features a dual navigation button scheme which means that the usual Android navigation keys can be set to on-screen as well as on the capacitive keys featured on the smartphone even though the layout has been reported to be different.

Comparing the One's performance with the Nexus 5, the publication did a quick boot test of the two phones. OnePlus' One easily beats the Google's flagship smartphone with extremely fast boot time. While the Nexus 5 completely boots up, the reviewer boots up the One twice! Even powering off the smartphone is snappy and the phone switches off in just two seconds. What is interesting to note here though, is that after the complete booting process, the CyanogenMod 11S OS on the One seems to load widgets after it loads the OS which might be the reason of such a fast bootup process. Also, the smartphone takes comparably longer when it is restarted but still faster than other Android smartphones. It seems likely that OnePlus has modded the CyanogenMod 11S to feature some kind of fastboot mode which makes the phone boot and shutdown so fast.

Source - ThinkDigit

How to use Google Drive as a free web server for your blog's Images and generate Image URLs

                          
If you have a blog on Blogger or Wordpress, and you want to provide links to images which are not on the web, then one of the best and easy ways is to upload your images on cloud and then link back to those images.

Google Drive is one of the best free cloud storage providers and gives up to 15GB of space for your files. But, you may not find copy image URL when you right click on an image stored in Drive. However there is a simple trick using which an Image URL can be created and linked to the image for using on your blog as a direct URL.

For example, if you open the image, then the URL in the address bar is this

http://docs.google.com/file/d/FILEID/edit

Change it to 

http://drive.google.com/uc?export=view&id=FILEID

The above syntax can act as a direct URL to your blog's needs.

You can also use:

http://drive.google.com/uc?export=download&id=FILEID

to start a download and this works for file, not just for images.

NOTE : You have to set your image/other files to public access for the above method to work.

JavaScript Vs jQuery : Which is better?


Am sure if you're a developer, at some novice stage of your programming life, you would have wondered about how JavaScript is different from jQuery, and which of the two is more efficient and faster. Your curious doubt has a rather unconvincing answer : none. Well, now it would be my job to convince you.

Javascript:


This is a language which the web browser understands. It was released officially by Microsoft in its IE 3.0 in 1996, at the time when websites were becoming more complex and dynamic. As you would know now, dynamic content (rather flashy content) in websites is the order of the day, and the most popular way to achieve this is using JavaScript. JS is more readable and easier to master in a short span of time.

But initially different browsers interpreted the language in different ways, and developers would spend a lot of their precious time to fix the bugs cased due to that. Hence jQuery was conceived, although in present time, all browsers have begun to implement JS uniformly.

jQuery:


In simple terms, jQuery is a library of JS. In order to make the browsers understand JS in a standard way, developers started building custom frameworks, which simplified HTML document traversing, animation, event handling and AJAX interactions. These frameworks were shared freely in the development world and the concept became so widespread that the birth of jQuery was inevitable. Standard pre-written methods ( .js files) available in the internet are integrated into the project and used by the dynamic content you want to build. Hence jQuery now lets you focus  more on developing the dynamic features and less on cross browser issues. 

Which is better?


Neither. As said, JavaScript forms the basis of jQuery and the two cannot be separated. Most of the times, jQuery uses fewer lines of code, compared to the same features written using JS. However, since jQuery code also interacts with the same DOM methods as JS but in an indirect way, it cannot be said that jQuery is faster than JS.

Most of the effects you require for your project can be achieved easily with jQuery, hence the use of jQuery library today is more than the traditional JS itself. But to understand the client-side scripting from the bottom-up, it would be better to understand the basic working of both JS and jQuery.


How to install external templates to your blogger


           Other than the static and dynamic templates provided by blogger (which are pretty decent enough and ready to use), there are hundreds of third-party themes/templates which you can find on the Internet (like the one on this blog; credits : newbloggerthemes.com ). As it turns out, application of these themes to your blogger blog is a simple process. Yes, content really matters, but if you have a keen eye for the design, it can take your blog to a whole new level.

Here I will show you exactly how to do that.

Step 1: Go to any website which provides free blogger themes.
            Good ones include - newbloggerthemes.com, bestbloggertemplates.net, blogsizzle.com etc

Step 2: Download a nice template package which suits your blog and unzip it.

Step 3: Log in to Blogger account and click on your blog name. Click on "Template".

Click on Template

Step 4: It is important to take a backup of your existing template in case anything goes wrong.
           Click on "Backup / Restore" button.

Click on Backup Restore Button

Step 5: Download your current template using the "Download full template" button. Save it to your hard drive and keep it in a safe place. Because if you face any problem with new template installation, you can upload your old template again.
Download full template

Step 6: Click"Choose File" button to select your new blogger template (you can find it as a .xml file inside unzipped folder in step 2). After that click on "Upload" button.

            Congrats, you have successfully applied the new template to your blog.

Step 7: You may want to take a look at your blog and if you are not satisfied in the arrangement of widgets, you can always go to the "Layout" section of your blogger account and drag and drop the widgets to your preferred position.

Step 8: This is for advanced users who are familar with HTML and CSS, if you don't like the default colors of your new template, you can go to "Template" -> "Edit HTML"  and find any color using Ctrl+F in the code and change the Hex Codes.          
            You can also change the dimensions (height, width etc) of specific elements in the template by using the same process (and similarly other features).
            Note : If you click on "Customise", you may not be able to customise by using the Template Editor provided by Blogger as it does not support changes to external templates.

Important note: If any of the features of your new template are not working, and if these features use external Javascript/jQuery or Stylesheets plug-ins , then the problem might be that your blog is calling the same "some-jquery.js" or "some-stylesheet.css" URL twice, in different places. So make sure that it happens only once.
            Example: "<script src="http://ajax.googleapis.com/ajax/libs/jquery/2.0.0/jquery.min.js"></script>" may be written twice, once in your new template and once in your HTML/Javascript gadget. So you have to remove this line from your gadget (preferably).


A simple animated Back to Top button using jQuery


In lengthy web pages, it is more sensible to have a 'Back to top' button, instead of making the user scroll all the way up again. Below is the code for a simple floating 'Back to top' button using jQuery. You can add an image or you can define a div and style it, and give it the "back-to-top" class.

You can also define the duration in milliseconds in which the page goes to the top and the offset of the document on which the button should appear (and disappear).

HTML:
<script src="http://ajax.googleapis.com/ajax/libs/jquery/2.0.0/jquery.min.js"></script>
<button onclick="href='#'"  class="back-to-top">Back to Top</button>

JAVASCRIPT:

<script type="text/javascript">
            // Code to provide functionality for the 'Back to Top' button
            jQuery(document).ready(function () {
                var offset = 220;
                var duration = 500;
                jQuery(window).scroll(function () {
                    if (jQuery(this).scrollTop() > offset) {
                        jQuery('.back-to-top').fadeIn(duration);
                    } else {
                        jQuery('.back-to-top').fadeOut(duration);
                    }
                });

                jQuery('.back-to-top').click(function (event) {
                    event.preventDefault();
                    jQuery('html, body').animate({ scrollTop: 0 }, duration);
                    return false;
                })
            });
        </script>

CSS:

.back-to-top {
   position: fixed;
   bottom: 2em;
   right: 0px;
   text-decoration: none;
   color: #000000; 
   background-color: rgba(235, 235, 235, 0.80);
   font-size: 12px;
   padding: 1em; 
   display: none; 
}

 .back-to-top:hover { 
   background-color: rgba(135, 135, 135, 0.50); 
}