Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

April 12, 2017

D Language's Official Compiler is Open Source

Long held back by proprietary licensing issues, the D language's official compiler is now open source for all, a first step toward broadening its user base.


The D language, long an underdog among programmers, got a significant boost this past week when its developers received permission to its reference compiler as an open source project.

DMD, the reference compiler for D, has been encumbered by legacy licensing, courtesy of Symantec. The license made it problematic to distribute the compiler in conjunction with other open source software -- for instance, in a Linux distribution -- and often sparked confusion about what it permitted.

[ Get started with functional programming, including examples in F#.  Attack of the one-letter programming languages.  Keep up with hot topics in programming with Info World's App Report newsletter. ]

All that changed when Symantec finally gave permission to allow DMD to be under the highly permissive Boost License.

Two other open source D compilers exist, GDC and LDC, but both have typically lagged in terms of their feature support for the language.

DMD's licensing is one likely reason why the D language, originally created as an evolutionary expansion of C/C++, has not enjoyed wider adoption. Most other recently created languages, such as Go and Rust, have their reference implementations available as open source projects.

Supporters of D cite many features that put it in the same class as Rust and Go in terms of convenience and safety: fast compilation times, garbage-collected memory management (with manual memory management also available), and strong interoperation with C/C++. But it stands out thanks to its static introspection functions and code-generation features, which allow compile-time optimizations that would be difficult in other languages.

Freeing up DMD means one fewer obstacle to wider acceptance of D, but not automatically so. D co-creator Andrei Alexandrescu has cited three key obstacles D would need to overcome: How its use of garbage collection by default alienated many C/C++ programmers, its "historical lack of vision," and the fact that it remains minimally used though it's been around for years. Relicensing DMD can address the first of those by allowing a broader base of developers to build more standard-library additions that don't depend exclusively on D's garbage-collected memory management.

But D also faces strong competition from other languages. Much of the potential user base for D may already have made commitments to Rust and Go, and newcomer languages like Nim are seeking their own comfort zones between security, speed, and convenience. Still, D can potentially make a case for itself in the face of those odds, and it has now added one more way to do so.

March 7, 2012

Takeaway Points from Google Privacy Changes

Google is coming up with a comprehensive privacy policy that governs how the company employs user data. Which is a consolidate of around 60 privacy policies for different services.



Privacy Policy
The company says that this step is being taken in the interest of the users, lawmakers and regulators to make its policies easier to understand. Also, it is an attempt by the company to enhance user experience by making information from one Google service available to other Google services that might benefit from that data reports Thomas Claburn in InformationWeek

Jules Polonetsky, co-chair and director of the Future of Privacy Forum said "Google's privacy policy consolidation slated to become effective in a few days has captured the lion's share of attention, but it is Apple that has been the most effective at linking consumer data across every aspect of its services,” adding further he siad "European regulators have proposed a privacy law that seeks to put the data genie back in his bottle, but consumers have voted by expressing delight in Steve Jobs vision by making Apple the most valuable company in the world."


If Google's privacy consolidation has been freaking you out, here are a few steps to take that may make you feel better about your privacy level.


A quick dash to Google Dashboard: Google provides a single control panel for Google services on its google account dashboard. Here users have the options and can take steps like disabling the Web History.


Visit Google's Ad Preferences Page: Google allows users to block specific advertisers and also the advantage to opt-out of personalized advertising which can be beneficial if you're not already blocking them at the browser level.


NAI Opt-Out Page: Make a point to visit the Network Advertising Initiative's Opt-Out page it is a list about advertisers offering a tool in the hope of avoiding regulation than it is about preventing behavioral tracking. But users can go ahead and check "Select All" and opt-out.


Install Counter-Advertising Software: Try AdBlock Plus, No Script, Disconnect, and Ghostery. With this users will not have to complain if the Web doesn't work right anymore.


Check with other Competitors: Google insists that competition is only a click away. So click over to an alternative like Bing or Yahoo and look out for a search engine that insists it doesn't track users. You'll be back.

Dangerous Malware Security trends

Data breaches and anti-social activities are on rise which is one of the significant concerns of IT leaders and security researchers who are constantly at work to curb these issues. Hackers, crackers and online criminals continually find new security gaps to exploit, and new ways to get at your personal data. This year at the RSA security conference several companies explored new ways to deal with these issues in coming months reports Nick Mediati in pcworld.com.


Take a glimpse of some of the dangerous new malware trends to watch for in 2012.


Invisible and Irremovable

Invisible And Irremovable

Unlike the traditional malware and viruses this new category malware infects your pc and you may not even realize it. While older malware could be identified on the PC, newer forms of may not even have an interface, and they may not seriously impact your PC's performance. Although they may not lead to awful consequences, but they run in the background, seemingly invisible to you.


This invisible and hard-to-spot malware can also be extremely hard to remove. For example, a relatively new rootkit called ZeroAccess effectively kills any program that tries to access it and makes extremely difficult to disable it as it buries itself deep into your system hence the name ZeroAccess.


Site Specific Malware

Site Specific Malware

Super targeted malwares a new kind of malware are also on the rise. These baddies can get into your browser history and moreover check to see and infect you when you've visited certain sites. For instance, a malware to steal your online banking related information might check to see if you visited a particular bank's website. Mediati says one can expect more malware in near future that would be designed to go after certain groups of people or specific bits of information.


Mobile Malware

Mobile Malware

Android specific malware are on rise which was a big story last year. A recent report by McAfee revels that 2011 was by far the busiest periods during which mobile malware increased exponentially with Android phones being the number one target for writers of mobile malware. Cyber-criminals earn significant amount of money by spreading common type of Android malware.


Pay off and Deal with malware

Pay off
 
Some fake antivirus software won't go away unless you pay up likewise there are malware that take nothing less than a ransom. The team at security software company Malwarebytes sees it as a increasing problem. The company gave an example where a piece of malware would lock you out of your computer entirely unless you pay up.


Ransomware means you are likely at the risk of getting hit twice: When you pay to remove the infection, you end up giving your credit card information to criminals who might go on to use your account deceitfully.


SSL not so secure

SSL

The Secure Sockets Layer (SSL) is a commonly-used protocol for managing the security of a message transmission on the Internet.  Most of the users think that their data is safe and securely transmitted over the internet when they see the padlock icon but hackers have found ways to get retrieve this information even before it is sent.


These newly discovered malwares attack the information which is to sent be through the internet even before it is encrypted and protected with SSL, these malwares can snatch you username and password before the encryption process kicks in.



March 1, 2012

Change Your PIN Now; Here’s How to Remember Your New, Secure PIN

If a new study by the Cambridge University Computer Laboratory is correct, most of your ATM or debit card PINs are either "1111" or "1234." You may think it's okay because someone would need physical access to your card to use the PIN, right? Wrong. Here's why you should change your PIN right away, and some hacks to help you can remember your new one.
You Should Probably Change Your PIN Now; Here’s How to Remember Your New, Secure PIN
Pin No

Why You Need to Change Your Pin

Mashable reports (and the study confirms) that the issue of simple, repetitive, and easy-to-guess PINs is so widespread that if a thief managed to steal enough cards they would be able to walk up to an ATM or go to a store and use every 18th card like cash with the correct PIN. Sure, if you lose your wallet you can just call the bank to have your card canceled and a new one issued to you, but in an age of card skimming, where the thief doesn't need your physical card to make a copy of it for themselves, you may not notice that your account has been compromised until it's too late and your money's been withdrawn. Photo by Cory Doctorow.
The Cambridge University study affirms that most of us are terrible at picking passwords and PINs, especially when they're things we know we'll have to remember, and when they're in the confines of a narrow system like "four digits only." The study also pointed out that we're not terribly private about our PINs either, and close to 50% of the people who participated admitted to sharing their PINs with others freely, and a third of the participants used the same PIN for all of their cards—which is about as bad as using the same password for all of the web sites you log in to. Others thought they were more secure because they used their birthdate as their PIN, forgetting that if their wallet is lost, there's likely some document also in the wallet with their birthdate printed on it.
So whether it's using the same PIN, using your birthdate, writing the PIN down and keeping it in your wallet, or giving out your PIN to other people, you can see why it's time to change it. Even if you know how to keep physical control over your wallet and your ATM and credit cards, it's still more likely that your wallet will be lost or stolen than it is someone breaks into your computer and takes all of your passwords.
 Make a sentence from your PIN
You Should Probably Change Your PIN Now; Here’s How to Remember Your New, Secure PIN
PIN
How to Remember Your New PIN
When you're ready to change your PIN, come up with four new numbers, and steer clear of numbers that can easily be mapped to information that's readily available about you—or worse, may be in your wallet if it's stolen. Try to avoid pet names mapped out on the keypad, or picking numbers that line up on the keypad and are easily guessed, like "1472" or "3692." Try to avoid the last four digits of your social security number, or your phone number, as well. Once you have a sufficiently random series of digits, here are some tips to help you remember.
  • Spell out a word with your PIN. Use a site like Phone Spell to find out what words your PIN spells on a phone or ATM keypad. Alternatively, if you're still trying to come up with a PIN, type in a word that's easy for you to remember, and the site will give you a PIN from the numbers each letter corresponds to on a numpad.
  • Make a sentence from your PIN.Mind Your Decisions suggests you pick a random series of numbers, and then take the first letters of each word for each number, and then build a mnemonic around those letters. For example, if my PIN is 5642, the words are "Five, Six, Four, Two." I take the FSFT first letters, and come up with a sentence to help me remember, like "First Standing, First Toppled" to lead me back to the PIN. That way any random series of numbers is suddenly easy to remmeber.
  • "Encrypt" your PIN in your phone, or on paper. Most banks will tell you never to write your PIN down, and especially not to keep your PIN somewhere it could be lost with your ATM or credit card. Mind Your Decisions also notes that you can "encrypt" your PIN by injecting useless numbers and then writing it down. For example, if my PIN is 5642, I could jot down 05060402 on an index card and keep it in my wallet. That's easy to guess, so to make it more difficult, I could use the numbers next to the ones in my PIN, like 56674523, or another four digits, where only I know that every other digit is meaningless. Take it a step further and add your PIN as a contact in your mobile phone, complete with this "encryption," and you'll never forget your PIN again. It's not bulletproof, but if you're the type who needs to write down your PIN anyway, it's better than no obscurity.
  • Pick a number that means something to you but nothing to anyone else. If you have a private, personal series of numbers that you can remember and cannot be easily tied to some other readily available information about you then go for it. You're still stuck with four digits, so if they're four digits you'll remember but no one will guess, you're all set. If it's something like your dog's birthday, the last four digits of your best friend's call phone number, or any other series of digits highly unlikely to be in your wallet and equally unlikely information to be easily available to a thief, it's fair game.
  • Use math to conceal your PIN. Another, more advanced suggestion is to use Modular Arithmetic to secure your PIN. Here's how it works: you know how difficult it is to fool yourself into getting up earlier because you set your clock back 5 minutes? You'll always look at the clock and know to subtract 5 minutes to get the real time, right? The same principle applies to your PIN. Take a random PIN, like 5642, and then add 5 (mod 10) to each digit: 101197. Then, drop the excess numbers, and your result is 0197. (Thanks for the correction, area_educator!) It's a simple code, but it works, and the key is in your head.
  • Get the bank to reset your PIN. If doesn't preclude any of the tips above, but one way to make sure your PIN is a random series of digits is to make the bank reset it, mail you the new PIN, and then force yourself to use whatever they assign you. You can use the mnemonic trick to make it easier to remember, or you can just brute force the number into memory and call it a day. Painful, but it works.
In the end, the method you use to remember your PIN is best decided by how likely you are to embrace the technique and eventually remember the numbers without having to write them down or fall back on something that's easily guessed or otherwise obtained. Regardless of what you choose, if your PIN is "1111" or "1234" or even some variation on the theme, pick a new PIN, for your bank account's sake.