My experience on my daily works... helping others ease each other

Sunday, December 18, 2011

Seminar on Applications of Cutting-edge Statistical Methods in Research.


Institute for Mathematical Research (INSPEM), Universiti Putra Malaysia will be organizing Seminar on Applications of Cutting-edge Statistical Methods in Research.
Attached are the latest update of the seminar. Futher information and registration can be obtained from seminar website at at http://einspem.upm.edu.my/aces2012  or contact the seminar secretariat at:
+603-89468459 (Ms Nor Yusniza Ma’arif)
+603-8946 6877( Mr Mohd Rohaizat Abdul Wahab)
+603-89468458 (Mrs Nor Hasmimi)

Best regards,

Publicity Committee
Seminar on Applications of Cutting-edge Statistical Methods in Research
Share:

Public key cryptography and security certificates

Public key cryptography offers ultimate security being based asymmetric keys and is the backbone for popular protocols like security sockets layer (SSL) to be able to communicate securely between web-servers and browsers. However a whole ecosystem is based on passing or exchanging security certificates. (read more)

It is an interesting articles to anyone whom wishes to learn about PK Crypto. It might not be sufficient but it is a good start entry point.
Share:

Internet Society Launches New Website

Extensive redesign features bold visual approach, enhanced features, and focus on story-telling to highlight the importance of the Internet to people around the world [Washington, D.C. USA and Geneva, Switzerland - 15 December 2011] - The Internet Society today announced the launch of its redesigned website with exciting changes to the look, content, and functionality of the entire site.

The Internet Society is a nonprofit organization dedicated to ensuring the open development, evolution, and use of the Internet for the benefit of people throughout the world.

The new Internet Society website, www.internetsociety.org , is IPv6 accessible and features many enhancements, including:
**An emphasis on storytelling with real-life profiles of how the Internet impacts peoples' lives
**Highlighted membership information about the Internet Society's mission and ways to get involved
**New regional pages that underscore the global reach of the Internet Society
**Extensive list of Internet industry events in 2012
**Tweets, content, and pictures to spotlight the activities of the Internet Society's vast membership of more than 55,000 members
**Multilingual content with sections available in English, French, Spanish, Russian, Chinese, and Arabic

"We are very excited about our new website," said Lynn St. Amour, Internet Society President and CEO.

"In 2012, we will celebrate our 20th anniversary and the new website reflects the tremendous breadth of our organization, the global scope of our membership, as well as the importance of protecting the open, global Internet."

As one example of the Internet Society's work, the home page of the new website features a compelling video on the Harlem Internet Access Program.

The Internet Society provided a Community Grant to a member of its New York Chapter to support this program, which is making a tremendous impact on the lives of seniors by providing Internet access and training.

"We worked closely with our global community to develop our website, which provides rich content and photographs to highlight the diverse work across our organization, Chapters, and members," said Scott Hoyt, Internet Society Vice President of Strategic Communications. "In addition to the new visual design, we've added many new features to inform audiences about the broad range of enabling activities to expand access to and encourage participation in the Internet's development."

About the Internet Society

The Internet Society is the world's trusted independent source of leadership for Internet policy, technology standards, and future development. Based on its principled vision and substantial technological foundation, the Internet Society works with its members and Chapters around the world to promote the continued evolution and growth of the open Internet through dialog among companies, governments, and other organizations around the world. For more information, see: http://www.internetsociety.org
Share:

Tips on picking right OSS license

Open source licenses cater to different software needs so companies need to understand purpose of software and monetization plans, among other considerations, to determine which license to use, insiders note. (read the article by Kevin Kwang from ZDNet Asia here)

Based on the author, there are 5 main elements in selecting the OSS license:
1. Free to innovate / distribute
2. Opportunity to generate profit
3. Support from community
4. The engineers / developers behind
5. Clear SDL process

From my perspective, as developers and also researcher, the most important shall be community supports and the engineers behind it. It become more important when dealing with software that can be used as malware or possibly to be exploited such as web server and database. You need to understand all this before decide on which OSS suites you. :)
Share:

Sunday, December 11, 2011

Analysis of ‘Operation Black Tulip’: Certificate authorities lose authority

The Agency releases its analysis of the Diginotar- ‘Operation Black Tulip’ case, where a digital certificate authority suffered a cyber-attack.
In the attack, false certificates were created for hundreds of websites, including Google and Skype. Reports indicate that the cyber-attack started in mid-June, and that for two months, false certificates were used to eavesdrop on users in Iran. In its new analysis, the Agency identifies three major issues, and suggests remedies to these.

Analysis of ‘Operation Black Tulip’: Certificate authorities lose authority
The Agency has analysed the ‘Operation Black Tulip’ cyber attack and issued recommendations on how to mitigate security concerns with certification authorities. 

Share:

Research team finds disk encryption foils law enforcement efforts

(PhysOrg.com) -- A joint U.S./UK research team has found that common encryption techniques are so good that law enforcement, from local to highly resourceful federal agencies, are unable to get at data on a computer hard disk that could be used to prove the guilt of people using the computer to perpetuate crimes. In looking at the current technology, the team, as they describe in their paper published in Digital Investigation, find that if criminals use commonly available hard drive encryption software, law enforcement very often is unable find anything that can be used against them. (read more)
Share:

Friday, December 9, 2011

Advanced Persistent Threats: Are You at Risk?

Security researchers have been talking about Advanced Persistent Threats (APT) for some time. In the past few years we have seen this threat increase. What is APT? Which types of organizations are most at risk? What can be done to defend against APT? This white paper reviews the latest APT attacks and provides answers to these key questions.

DOWNLOAD WHITE PAPER
Share:

Exposing Direct Database SQL Injection Attacks

SQL injection typically leverages non-validated input vulnerabilities to pass SQL commands through a Web application for execution by a backend database. Crafty attackers take advantage of SQL commands with user-provided parameters to execute arbitrary SQL queries and/or commands on the backend database server through the Web application. This video demonstration, however, shows the database being attacked directly by a non-privileged user, not through a Web application, but via direct interaction with the database.

Uploaded by on Aug 13, 2009
Share:

SPIE.org : SPIE Newsroom : Unconditionally secure relativistic quantum key distribution protocol

SPIE.org : SPIE Newsroom : Unconditionally secure relativistic quantum key distribution protocol

Yang and Zhuang shares a new technique making full use of QKD with some adjustment for efficiency.

It seem perfect to defend from eavesdropper or man-in-the-middle attack. But QKD is defensely against one type of attacks. The strongest link is also the weakest link. There are some flaw in current QKD implementation and I wish to share this once I completed my studies :)
Share:

Should we be taming social media?

Kapil Sibal, India's telecom minister, this week appears to have drawn more attention with his proposal to pre-filter the content on social media Web sites than all the publicity he got for some of the good work he did in the area of education. The hashtag #IdiotKapilSibal emerged as one of India's most tweeted on Tuesday. (read more)

I said:
Same goes here. Those top guys and politicians are only looking things from their perspective and propose solutions from their view and what they think it should be after getting advice from so called expert. They had never listen to majority voice down below.

At some point, I do agreed that social media/network need to be controlled or at least there are borders to some extend. However, to go deep until everything being controlled, then the meaning of "internet for everyone" and "open discussion" or "open world" or what ever term called for freedom of internet are no longer applicable. There are always ways to prevent such things without enforcing too much and to detail. You can put many preventive mechanism but the more you put, the more it build interest within people to explore and they start to learn on hacking and search for ways to get through.

Therefore, people up there and politicians, please do go down below and get the best solutions..
Share:

Carrier IQ faces lawsuits, lawmaker seeks FTC probe

Three lawsuits in United States allege privacy-law violations, a congressman asks Federal Trade Commission to investigate, and activists seek Federal Communications Commission and Justice Department probes of mobile data-collection software. (read more)

"Carrier IQ, which programmer Trevor Eckhart alleges records keystrokes from mobile phones and sends all sorts of personal information off the phone. Carrier IQ denies that and says limited data is gathered for diagnostic purposes only"
"Nokia and BlackBerry maker Research in Motion say they do not pre-install Carrier IQ on their phones, while HTC, Samsung and Motorola say they pre-install it at the carrier's request. Google, meanwhile, says it does not use it on Nexus devices." (read more)


I said:

To all friends... you guys better check your phone to see if the apps installed especially when you used lots of mobile banking or browsing through email, etc whereby lots of username and password being entered and pass around :)...
Share:

Malaysian will force IT to be certified.. Is this good move?

OPEN DAT Board of Computing Professionals Malaysia (BPCM)
Adalah dimaklumkan bahawa Kementerian Sains, Teknologi dan Inovasi (MOSTI) telah diberi tanggungjawab bagi mengendalikan penubuhan Lembaga Jurukomputer Malaysia (Board of Computing Professionals Malaysia - BPCM). Sehubungan dengan itu, pihak Sektretariat ingin mendapatkan pandangan dan cadangan daripada orang awam mengenai penubuhan BPCM. Satu sesi 'open day' akan diadakan mengikut ketetapan berikut:

Tarikh : 13 Disember 2011 (Selasa)
Masa : 9.30 pagi – 5.00 petang
Tempat : Dewan Perhimpunan
Aras 1, Blok C4, Kompleks C
Kementerian Sains, Teknologi dan Inovasi


Semua dijemput hadir.

Last Updated ( Friday, 09 December 2011 )
Taken from: http://www.mosti.gov.my/mosti/index.php?option=com_content&task=view&id=3667&Itemid=1

 Translated:
Ministry of Sciences, Technology and Innovation (MOSTI) has been given mandate to manage the formation of Board of Computing Professionals Malaysia (BPCM). For that reason, the secretariat wishes to get input, feedback, or comments from the public regarding BPCM. One open day session is arranged according to below:

Tarikh : 13 Disember 2011 (Selasa)
Masa : 9.30 pagi – 5.00 petang
Tempat : Dewan Perhimpunan
Aras 1, Blok C4, Kompleks C
Kementerian Sains, Teknologi dan Inovasi




What do I think:

1. Are we trying to follow what other professional such as Engineers, Lawyer, Accountant, and Doctors did? What is our purpose?
2. Does that is what currently being done in other countries such as US, UK, Europe, etc which more IT professionals living there? Why are we doing this?
3. How can this help our fresh graduates? Is there any issues causing us to propose such mechanism?

I can only seem more harm to IT professional especially malays IT professional. Believe me, there are many IT expert (malays especially) that does not have any certifications or even specialize training but being referred by many global company. And believe me, there are many expert with lots of certificates but only knows theory and get the certifications through reading but not through experiences. So what is the actual purpose of this body? Beside, I heard that you need to pay some fees to become the member (more fees and money.. not including your CISSP, EC, MVC, MVP, etc.. certificate that you need to maintain to certain extend)... and worst is that you need to be certified by that body before you can provide any IT services to malaysian company. Wow.. if that so, many bumiputera's or local company will definitely close their business.

What ever it is, lets find out next tuesday. Let us go there and share our thought.
Share:

Wednesday, December 7, 2011

Hacking Kindle Fire for Android apps

A good articles teaching on how user of Amazon Kindle Fire be able to use apps from Android Market. :)
check it out here http://www.eetimes.com/electronics-news/4230956/Android-market-hack-for-Kindle-Fire-?cid=NL_Embedded&Ecosystem=embedded
Share:

Monday, December 5, 2011

Russia: Massive DDoS Attacks Against Independent Websites on the Election Day

An unprecedented wave of DDoS attacks [ru] against independent websites on the election day in Russia: sites affected include thenewtimes.ru, echo.msk.ru, novayagazeta.ru, kommersant.ru, publicpost.ru, slon.ru, Bolshoy Gorod (bg.ru), golos.org, ikso.org, ridus.ru, zaks.ru (Saint Petersburg), pryaniki.org (Tula), crowdsourcing platform “Karta Narusheniy” and the LiveJournal platform. Many media organizations are using Facebook and Twitter to continue distributing information. Some of the activities [ru] are taking place in Vkontakte social network. ”Golos” tried to collect reports about falsification with GoogleDocs, but it was also shut down. Anton Nossik from LiveJournal compares [ru] the attack to the Soviet efforts to block foreign radio broadcasting. Despite the attack, RuNet is full of reports and videos about voting violations.

Copied from http://globalvoicesonline.org/2011/12/04/russia-massive-ddos-attacks-against-independent-websites-on-the-election-day/
Again ... known existing and well-documented method of attack was used. This is definitely a strong key-point which clearly indicates that until know, there is NO absolute defense from cyber attacks until we truly understand deeply how they think.
Share:

Sunday, December 4, 2011

Slide for IAS 2011 - Draft Completed

Completed my slide presentation which scheduled to be presented in IAS 2011 @ UTeM, Melaka on 6th December 2011. If you are nearby, please do stop by to see my presentation or we can have a chit-chat session after that. :)

By the way, this time around, I'm going there as UiTM student and will be presenting as UiTM student's since it is much related to my study rather than my work. I'll be sharing the slide and the papers link once I get the link ready :). Meanwhile, if you are interested to view my publications, just click on List of IPs and Publication tab or here.
Share:

About Me

Somewhere, Selangor, Malaysia
An IT by profession, a beginner in photography

Labels

Blog Archive

Blogger templates