Showing posts with label World. Show all posts
Showing posts with label World. Show all posts

SNCF "Europe. It's Just Next Door"

Written By Unknown on Thursday, 7 November 2013 | 21:39

Imagine if you could be connected from one holiday destination to another in real time, well, that’s exactly what SNCF Railways did for their latest campaign.  They placed interactive doors across prominent tourist locations in Europe, where each door hid full-bleed LED Screens, connected live to other parts of Europe, showcasing specific cultural attractions, this is amazing. Video is below:
21:39 | 0 comments | Read More

11M Listening to iTunes Radio After Only One Week

Written By Unknown on Monday, 23 September 2013 | 22:29

Apple’s iTunes Radio has amassed 11 million listeners since its U.S. debut last week.
The free, ad-supported service, which is available through iTunes 11 and iOS 7, is challenging Pandora, the Web’s most popular radio service.
Apple, in its announcement Monday, said the most popular song on iTunes Radio thus far is ‘Hold On, We’re Going Home’ by Drake.
22:29 | 0 comments | Read More

Apple Sells 9M iPhone 5S and 5C Devices Over Opening Weekend


Apple sold a record nine million iPhone 5S and iPhone 5C handsets in 72 hours, surpassing analysts’ expectations for the debut of the first new iPhones in a year.
Demand for the iPhone 5S — which went on sale last Friday along with the 5C — has exceeded Apple’s initial supply, and many online orders will be shipped in the coming weeks, according to a company press release.
22:27 | 0 comments | Read More

Microsoft Announces Windows 8.1 Pricing - SiteProNews Update

Written By Unknown on Thursday, 19 September 2013 | 00:50

Featured Article PictureThere will be no breaks for the majority of Microsoft customers wishing to upgrade to Windows 8.1 when it goes live Oct. 18.
Anyone upgrading from Windows XP, Vista or Windows 7 will have to shell out $119.99 for Windows 8.1 or $199.99 for Windows 8.1 Pro. The price is the same whether a customer downloads from Windows.com or buys a retail-packaged DVD at a store.
Windows 8 customers, however, can upgrade for free.
“One shift to note in Windows 8.1 is that we will be offering ‘full version software’ at retail and online for download that does not require a previous version of Windows in order to be installed,” reads a company blog post.
00:50 | 0 comments | Read More

Paid Content - Should The Government Regulate Paid Content?

Written By Unknown on Tuesday, 17 September 2013 | 23:34

Online advertising has changed. It used to be that Web sites would have a few banner ads or side bar ads to bring in revenue. Then consumers started to use adblockers and other methods to ignore these ads. That’s when sites turned to native advertising, and it’s caught the FTC’s attention.

The Federal Trade Commission announced on Monday that it would be hosting a “native ad” workshop later this year. The Commission says that the workshop will serve to continue its quest of helping consumers “identify advertisements as advertising wherever they appear.”
23:34 | 0 comments | Read More

Mark Zuckerberg’s Account Hacked by Security Researcher To Prove His Exploit Works

Written By Unknown on Tuesday, 20 August 2013 | 03:50

Mark Zuckerberg’s Account Hacked by Security Researcher To Prove His Exploit Works
Screen Shot 2013-08-18 at 3.23.27 PM

Earlier this week, security researcher Khalil Shreateh discovered a Facebook bug that allowed a hacker to post on anyone’s wall — even if they weren’t that person’s friend.

While he was able to prove to Facebook that his bug was legit (despite an initial response that it wasn’t a bug at all), Facebook wasn’t too happy with the way he did it: by using the bug to post on Zuckerberg’s otherwise friends-only wall.

Security research can be a pretty tough balancing act. If you don’t follow a company’s responsible reporting terms to a T, you might be robbing yourself of your fair share of recognition and, if the company is one of many that gives bug bounties, a chunk of cash. Alas, exploiting your way onto Zuck’s timeline… doesn’t exactly comply with Facebook’s reporting rules.

In his initial report of the bug, Khalil demonstrated that he was able to post on anyone’s wall by submitting a link to a post he’d made on the wall of Sarah Goodin (a college friend of Zuck’s, and the first woman on Facebook.)

Unfortunately, the member of the Facebook Security team who clicked the link wasn’t friends with Goodin, whose wall was set to be visible to friends only. As a result, they couldn’t see Khalil’s post. (While Facebook Security can almost certainly over-ride privacy settings to see anything posted on the site, they didn’t seem to do that here)

“I don’t see anything when I click the link except an error”, responded Facebook’s Security team.

Khalil submitted the bug with the same link again, explaining that anyone investigating the link would need to either be Goodin’s friend or would need to “use [their] own authority” to view the private post.

“I am sorry this is not a bug”, replied the same member of the Security team, seemingly failing to grasp what was going on.

Khalil responded by taking his demonstration to the next level; if posting on one of Mark Zuckerberg’s friend’s walls didn’t get his point across, perhaps posting on Zuck’s own wall would?


On Thursday afternoon, Khalil posted a note into Zuckerberg’s timeline. “Sorry for breaking your privacy [to post] to your wall,” it read, “i [had] no other choice to make after all the reports I sent to Facebook team”.

Within minutes, Facebook engineers were reaching out to Khalil. He’d made his point.

Through Facebook’s whitehat exploit disclosure program, security researchers are paid at least $500 for each critical bug they report responsibly. $500 is just the minimum — the size of the bounty increases with the severity of the bug, with no set maximum.

Alas, there would be no bug bounty for Khalil. Amongst other terms, Facebook’s bug disclosure policy requires researchers to use test accounts for their investigations and reports, rather than the accounts of other Facebook users. By posting to Goodin and Zuck’s walls, he’d broken those rules pretty much right out of the gate. His reports also didn’t include enough detail of how to reproduce the bug, says Facebook:

Unfortunately your report to our Whitehat system did not have enough technical information for us to take action on it. We cannot respond to reports which do not contain enough detail to allow us to reproduce an issue. When you submit reports in the future, we ask you to please include enough detail to repeat your actions.

We are unfortunately not able to pay you for this vulnerability because your actions violated our Terms of Service. We do hope, however, that you continue to work with us to find vulnerabilities in the site.

Since Khalil’s initial post went up on Friday, there’s been a healthy debate as to whether or not Facebook should be paying him a bounty. On one hand, he broke their disclosure rules (perhaps unknowingly — as many have pointed out, Facebook’s disclosure terms are only available in English, which doesn’t seem to be Khalil’s first language); on the other, he was seemingly trying to report it responsibly rather than selling it to spammers.

Even Facebook’s own engineers have entered the discussion. On Hacker News, Facebook Security Engineer Matt Jones laid things out as he saw them:

For background, as a few other commenters have pointed out, we get hundreds of reports every day. Many of our best reports come from people whose English isn’t great – though this can be challenging, it’s something we work with just fine and we have paid out over $1 million to hundreds of reporters. However, many of the reports we get are nonsense or misguided, and even those (if you enter a password then view-source, you can access the password! When you submit a password, it’s sent in the clear over HTTPS!) provide some modicum of reproduction instructions. We should have pushed back asking for more details here.

However, the more important issue here is with how the bug was demonstrated using the accounts of real people without their permission. Exploiting bugs to impact real users is not acceptable behavior for a white hat. We allow researchers to create test accounts here: https://www.facebook.com/whitehat/accounts/ to help facilitate responsible research and testing. In this case, the researcher used the bug he discovered to post on the timelines of multiple users without their consent.

What say you? Should Facebook bend the rules and shell out? Would breaking the rules set a dangerous precedent?

Read Original Post: Click Here
03:50 | 0 comments | Read More