August 03, 2016

Getting the Critical Role of Data Preparation Right

Self-service data analytics tools are becoming more popular. They require less IT attention and enabling organizations to personalize the experience of working with data through data visualization. Such tools also make it easier for non-IT individuals to work with data. Some of these tools use machine learning, natural language process, and other advanced techniques to suggest data sets and guide users. Equally important – data preparation needs to address data governance. As Stoddard notes, “data governance is often regarded as being primarily about protecting sensitive data and adhering to regulations; indeed, data preparation processes are vital to meeting those priorities. However, data governance is expanding to include stewardship of data quality, data models, and content such as visualizations that users create and share.”


Getting Started with MapReduce

A MapReduce program is composed of a Map() procedure (method) that performs filtering and sorting (such as sorting students by first name into queues, one queue for each name) and a Reduce() method that performs a summary operation (such as counting the number of students in each queue, yielding name frequencies). The "MapReduce System" (also called "infrastructure" or "framework") orchestrates the processing by marshalling the distributed servers, running the various tasks in parallel, managing all communications and data transfers between the various parts of the system, and providing for redundancy and fault tolerance. The key contributions of the MapReduce framework are not the actual map and reduce functions, but the scalability and fault-tolerance achieved for a variety of applications by optimizing the execution engine once.


Web-native mobile app frameworks: How to sort through the choices

Two of the main problems with using the web stack are feature fragmentation in browsers' JavaScript engines and bad performance on old WebVews. The biggest problem is on Android. Apache Cordova relies on the installed WebView on each device, so it’s not going to help in this case. Fortunately for us, there is an open-source project from Intel, called Crosswalk, that lets you embed or install a new Chromium-based WebView for your hybrid application, letting you access new APIs and have better performance even on older devices. It’s compatible with Apache Cordova and available as a free plugin. If performance and latest APIs are important to you, you should consider adding it to your tool chain.


Security Think Tank: Brexit and infosec – for now it’s business as usual

Most information security professionals will be familiar with the difficulties in putting together a business case for spending on IT security. Infosec projects rarely deliver a return on investment and are typically treated as an “insurance policy”. As noted above, Brexit may reduce infosec budgets. Alternatively, nothing sells insurance better than fear and uncertainty, and the political instability that surrounds the UK’s exit from the EU may instead translate into a desire to improve big businesses’ IT security posture. For organisations that take information security seriously and recognise the changing threat landscape, this may result in an increased interest in information security initiatives and demand for the services of infosec professionals.


Encryption's quantum leap: The race to stop the hackers of tomorrow

NIST is exploring preliminary evaluation criteria for quantum-resistant public key cryptography standards, a process that's due to be finalised by the end of this year. NIST will then begin accepting proposals for quantum-resistant public key encryption, digital signatures, and key exchange algorithms, with a deadline in late 2017. This will be followed by three to five years of public scrutiny before they are accepted as standards. So, while new encryption algorithms should protect future communications against attack, what about all that old data secured with existing cryptographic standards? Will it be at risk at some future date? Professor Alan Woodward of the University of Surrey thinks it's unlikely.


Five Strategies for Leading a High-Impact Team

One strategy for managing team size is to consult specialists only when their expertise is required rather than keeping them on full time. Adding some fluidity to team membership can also help with the problem of homogeneity. In team sports, you hear a lot about the importance of team chemistry—that innate understanding that leads to the no-look pass or the intuitive hit-and-run. While building a team of like-minded individuals may create a safe and comfortable environment, it also elicits a narrower vision and less productive friction than a team that is diverse both in personality and function. “We found that changing the membership of a team—taking out one member and putting in a new member while holding everything else constant—actually leads to an increase in creative idea generation,” says Thompson.


Here’s how Law Enforcement and IT Security Companies are Fighting Ransomware

“This collaboration goes beyond intelligence sharing, consumer education, and takedowns to actually help repair the damage inflicted upon victims. By restoring access to their systems, we empower users by showing them they can take action and avoid rewarding criminals with a ransom payment.” Wil van Gemert, Europol Deputy Director Operations, finally: “For a few years now ransomware has become a dominant concern for EU law enforcement. It is a problem affecting citizens and business alike, computers and mobile devices, with criminals developing more sophisticated techniques to cause the highest impact on the victim’s data. Initiatives like the No More Ransom project shows that linking expertise and joining forces is the way to go in the successful fight against cybercrime. ... ”


IBM creates artificial neurons from phase change memory for cognitive computing

"Basically, it operates how the brain operates, with short voltage pulses coming in through synapses exciting neurons," said Tomas Tuma, lead author of the paper and a scientist at IBM Research in Zurich. "So we use [a] short pulse of, say, nanosecond duration...to induce change in the material." The PCM's stochasticity, Tuma said, is of key importance in population-based computing where every neuron responds differently and enables new ways to represent signals and compute. "Normally, people try to hide [stochasticity], or if you want good quality stochasticity you have to induce it artificially. Here, we have shown we have a very nice stochasticity natively because we understand the processes of crystallization and amorphization in phase-change cells," Tuma said.


Facebook's privacy chief insists Facebook is 'a privacy-enhancing platform'

When we think about privacy, we have to think about people's expectations. What do they understand? What are we telling them about our product? On Facebook, people decide whether or not they want to decide to share information. They can decide whether or not they want to make their lives public, whether they want to do something just for their friends, or just do it for a very small group. We've worked very hard over the years on these sharing controls to educate people on them. The same privacy model that applies to what we do with whatever you share, that also applies to Live. Yes, people have to understand what that is. People have to use it and understand it and get it. We have a responsibility to tell people, and we are. But this isn't a new phenomenon.


Infrastructure as destiny — How Purdue builds an IT support fabric for big data-enabled IoT

The worry for any CIO is that the only thing I have that’s mine is my business data. Anything else — web services, network services — I can buy from a vendor. What nobody else can provide me are my actual accounts, if you wish to just choose a business term, but that can be research information, instructional information, or just regular bookkeeping information. When you come into a room of a new solution, you’re immediately looking at the exit door. In other words, when I have to leave, how easy, difficult, or expensive is it going to be to extract my information back from the solution? That drives a huge part of any consideration, whether it’s cloud or on-prem or whether it’s proprietary or open code solution. 



Quote for the day:


"A teacher affects eternity; he can never tell where his influence stops." -- Henry Adams


August 02, 2016

Accenture, Endgame team up to become the Van Helsing of cybersecurity

The digital era has brought with it a number of new tools and technologies. Things like IoT, the cloud, mobility, DevOps and software-defined networks (SDN) were futuristic things a decade ago but are now the norm. While those technologies have enabled businesses to become agile organizations, they also increased the number of attack points to the level where security teams can no longer keep up. The good guys need to protect an increasingly larger number of entry points, while the bad guys simply need to find a single way in. Once the network has been breached, the threat spreads laterally, information is gathered and data is eventually exfiltrated.


5 Ways to Manage an Outsourced Team on a Startup Budget

Getting everyone to work together on a project can become a costly nightmare due to time zones, work habits and deadlines. Rather than resort to spending fees on a massive project management platform that you really do not need, you can work with companies like Wrike, which offers various products to serve your size and budget but offers functionality to get projects done and enhance the collaborative experience in the process. Everything is located in a central hub for my entire team, including files, due dates, tasks and messages about every project that I'm working on. Best thing about them is I can individually track each individual on my team.


Latham on Systems Thinking

John Latham combines experience and research to create flexible frameworks that facilitate the process of reimagining, redesigning, and transforming organizations. Some of the frameworks such as the Design Framework for Organization Architects™ emerged from practice and later tested and refined. Others emerged from research and further developed in practice such as the CEO research that led to the Leadership Framework for Organization Architects™. These two award-winning, peer-reviewed frameworks form the foundation of the Organization Design Studio™ was founded to provide a virtual space for organization architects to learn how to (re)create the organization they really want!


Ready for a hack

Greg Spencer, principal consulting partner from IT consulting firm Beyond Technology, says the cyber threats facing Australian businesses have materially changed over the last 24 months. “Whereas organisations have traditionally taken solace from the understanding that they are not a target, the emergence of the hacker industry has taken this distinction away,” he says. “All organisations are susceptible to ransom attacks, and more and more seemingly harmless mid-tier firms are the focus of deliberate and targeted electronic intrusions seeking to either gain financially from their information or undertake data kidnap and ransoms.” Often hackers are not necessarily seeking information about their immediate target, but about one of their clients.


This Time, Miller & Valasek Hack The Jeep At Speed

Miller and Valasek reverse-engineered the electronic control unit (ECU) firmware, which communicates via the unsecured CAN bus in short messages. In a nutshell, they tricked the Jeep’s controls by impersonating messages. They basically took the ECU offline and impersonated real traffic to force it to follow their instructions, whether it was to accelerate, or turn the steering wheel 90 degrees. Unlike last year’s hack that the two conducted from Miller’s living room while Wired journalist Andy Greenberg drove the Jeep, this time they physically plugged into the diagnostic port of the vehicle to send their phony CAN messages, mainly for expediency reasons. “Last year, we showed you can remotely send CAN messages.


Economics Behind Ransomware as a Service: A Look at Stampado’s Pricing Model

The law of supply and demand also applies to the ransomware business model. In the course of monitoring the various underground markets over time, we noticed a fluctuation in ransomware prices. In 2012, ransomware services in the Russian cybercriminal underground only cost US$10–20. This included a Windows blocker or a piece of malware “that paralyzed a system’s OS.” This didn’t allow the criminals to hold data for ransom though. In addition, ransomware then weren’t as in demand then compared to now, which could explain why they were sold more cheaply. As more users and even organizations succumbed to paying the ransom just to get access to their files and systems back, it was natural for cybercriminals to hike the threat’s price up.


DevOps: The (Absolutely Critical) Cloud Enabler

One of the most fundamental problems that’s part and parcel of a move to reliance on the cloud is that IT orgs want every scrum team to have its own environment, complemented by an individual database instance. Eventually, that leads to creating a distinct database instance for every single developer. You probably can see where this is headed. I’ve used this comparison time and time again, but cloud and database instances become like the wire hangers in your closet you accumulate every time you pick up clothes from the dry cleaner. They multiply over time and, all of a sudden, you seemingly have a million on your hands, with no idea where they came from and no good way to get rid of them. To compound things, once the proliferation begins, it’s hard to stop.


How the Internet of Things (IoT) Will Impact the Logistics Industry

It’s now a given that a parcel can be tracked every step of its journey, from the moment it’s shipped to when it’s finally delivered into the hands of the consumer. But in most cases, it’s still a matter of barcodes being scanned – usually by humans – as the item goes through various distribution points. With the IoT, an RFID tag is placed on the parcel or pallet and the truck or van acts as the ‘reader’, eliminating the need for humans to do anything more than load the vehicle. The delivery vehicle will then connect to the cloud and transmit the RFID-derived information and its location. And it won’t just be the vehicle’s position – temperature data will be available in real-time as well, except in very remote areas.


CIA Cyber Official Sees Data Flood as Both Godsend and Danger

Today “people are putting all their thoughts, their conversations, their movements, their ideas into this digital stream," Roche said July 30 on the sidelines of the annual Aspen Security Forum in Colorado. A career CIA official, Roche joined the agency’s new Directorate for Digital Innovation, which opened in October, after serving as deputy director for science and technology. Roche wouldn’t comment on recent hacking incidents, including breaches of the Democratic National Committee’s system and a data analytics program used by presidential nominee Hillary Clinton’s campaign, attacks that technology experts attribute to Russia. But he said that Russia, China, Iran and North Korea top the list of nations posing cybersecurity threats to the U.S. government and its contractors.


IoT and liability: Who pays when things go wrong?

As one might expect, when monetary values can be assigned to liability claims, the blame game get serious. "The question becomes who is ultimately responsible for the interactions of the product," asks Amodio. "And more importantly to the people in the cybersecurity field, who is responsible if a hacker breaches the security to the device and causes damages in the real world?" ... "Manufacturers of IoT devices, IoT network providers, and IoT software developers need to be aware users may bring claims against one or all of them following a device malfunction or security breach," mentions the post. "It is not clear if the aggrieved IoT user will be required to prove they have suffered damage as a result of an IoT player's actions or if the courts and lawmakers will adopt a 'strict liability' approach."



Quote for the day:


“Business is like a sport where the games never end. I’m always competing.” -- Mark Cuban


August 01, 2016

Ransomware’s Success Causing Evolution of Variants

“Given SamSam’s success, it’s only a matter of time before adversaries introduce faster and more effective propagation methods to maximize its impact and increase the probability of receiving payment,” states the report. “Attackers’ use of JBoss back doors earlier this year to launch ransomware campaigns against organizations in the healthcare industry is a strong reminder that adversaries, when given time to operate, will find new ways to compromise networks and users—including exploiting old vulnerabilities that should have been patched long ago.” The rise of ransomware makes patching long-standing vulnerabilities an urgent imperative, Cisco security researchers say. 


The DAO, Smart Contracts and the Bulletproof Blockchain

Think of a blockchain system as a trust network; Bitcoin just happens to be a successful use of such technology. There are many other examples of trust networks in the world where the blockchain could replace an old-style trust network. For example, eBay is a trust network for buying and selling things. It acts as an intermediary between buyer and seller, assisting the two parties to come to an agreement. Recently, a blockchain alternative called OpenBazaar.org was launched. It provides a direct buyer-to-seller capability with no need for a website or middleman fees. It is made possible by the blockchain. It was with this kind of idea in mind that the DAO was launched, with great fanfare and $$$$s of investment. 


CaptureManager SDK

I had got an idea to write a new solution for working with web-cams on basement of Microsoft Media Foundation while faced with one unusual task. So, the task was not resolved, but I had wrote some code and had decided to continue development of the solution. At beginning the solution included only few classes and allowed to execute only few functions, but after adding of some demands for this solution I had decided to write a simple SDK which allows to make capture configuration for the new tasks easy and to inject a new developed code into it by implementation of the Microsoft Media Foundation's and CaptureManager's interfaces.  As a result, I have got this SDK for capturing, recording and steaming of live-video and audio from web-cams only by Microsoft Media Foundation.


Iterative Prototyping in the Mobile App Development Process

The mobile app development process differs from website development in that lifecycles are much more frequent, and developers have to bear in mind different devices, screen sizes and operating systems, both in the design stages and when user testing. Traditional website development styles, aimed at creating one version of a website, don’t tend to work as well when it comes to mobile app development, which calls for a more agile approach. All of which has, unsurprisingly, led to the adoption of iterative, rapid development processes. Prototypes have a role to play in this agile approach, enabling developers to build, test, iterate, re-test and re-build rapidly and at lower cost. A prototype of your mobile UI design is an essential part of a mobile app’s design process.


Do No Harm: An Oath For Health IT Developers

"Software engineers and physicians need to work together to ensure the health and safety of patients first and the ingenuity of efficient health technology second," said Dr. Andrew Boyd, assistant professor in the department of Biomedical and Health Information Sciences at the University of Illinois at Chicago.  "Algorithms are literally impacting millions of lives, and there needs to be a better way to empower developers to say this might be legal but this isn't doing right by the patient," said Boyd. A strong advocate for developers being held to the same professional standards of ethics as health care providers, Boyd said that security in health IT is a huge concern.


How the Internet of Things Helps Water Management

To begin with, there is the need for level sensors and equipment which are deployed across the reservoirs and overhead tanks. It is to be noted that level sensors are specially- designed sensors which can establish the level of water present in a tank/reservoir. This established water level can then be communicated to the central servers which are deployed for the purpose of effective water conservation as well as management. This information is passed on to the central servers on a regular basis, which further helps in determining the amount of water usage on a daily basis and also indicates the level of water that is present in the reservoirs or tanks.


CIO interview: Gary Steen, chief technology officer, TalkTalk

A big user of outsourcing, TalkTalk’s main suppliers are Tech Mahindra, TCS, Capgemini and Infosys, but the idea is to boost internal capability, especially in areas such as data, security, architecture and design. “Insourcing is about looking at our skills and those at our technology outsourcing partners, and also looking at how we avoid duplication. We are talking about optimisation of what we’ve got and how we can deliver more for the same,” Steen says. “Our outsourcing partners are intrinsically linked to the success of our technology delivery and this will continue. However, we need to ensure that we build up our own intellectual property.”


The Making of a Data Scientist

When it comes to enterprise-level initiatives, data science teams tackle the challenge of identifying and developing ways to produce measureable outputs of value from data of variable quality originating from disparate sources. Decision makers want to see summary numbers presented in an informative and consumable way. In the desire to see whole numbers, users do not always understand the importance of also looking at the statistical certainty around data measurements. It is my team’s job to take statistical validity into account while evaluating metrics for both data quality and for performance benchmarking. The data science team will scour through data in order to create and measure benchmarks for tracking improvement efforts and for identifying trends or opportunities for growth.


Salted Hash: Phishing study reveals frightening password habits

"More often than not, though, people choose simple passwords and number combinations to save time and to prevent getting locked out of an account or using data. What this suggests, however, is that this thinking is much more widespread and dangerous for the average user," she said. Is this a problem the security industry has created over time? Have we conditioned people to use poor passwords? The short answer is yes, according to Per Thorsheim, a security expert who founded PasswordsCon in 2010. "The common knowledge of passwords is based on rather old assumptions, folklore, myths, etc.," he said. Most of the advice people use to create passwords is outdated or irrelevant, and technically or logically wrong.


Anonymous Blockchain Micropayments Advance With 'Bolt' Proposal

Micropayment channel networks, such as the in-progress Lightning Network or Thunder Network, solve the first two problems by moving transactions to a new layer. Instead of recording every transaction on the blockchain, users open up channels, perhaps someday by clicking in an app, settling transactions on the blockchain only when necessary. Proponents argue this solves the scalability issue and allows for many more transactions while still not requiring trust in any third party. Finally, there’s the issue of privacy, which has been partially addressed by Zerocoin and the much-anticipated Zcash, the release of which was delayed last week. This anonymous cryptocurrency, the researchers say, could guard channel openings and closures from revealing information about the customer and merchant.



Quote for the day:


"Testing leads to failure, and failure leads to understanding." -- Burt Rutan


July 31, 2016

Google teaches its car to be nice to cyclists

The autonomous car provides an ample amount of room and won’t overtake if cyclists take the center of the lane. It notices a variety of cyclist signals, such as an indication that the cyclist wants to move into another lane. Google has programmed its software to store the hand signals, which means if the cyclist moves to a new lane two minutes later the car will remember the signal. Google gave two examples of the car being extra cautious around cyclists, the first is if it notices a parallel parked car with the door open, it will slow down to let the cyclist pass without fear of a collision. The second is a video (below), shown at SXSW Interactive 2016, where the Google can instantly recognizes an oncoming cyclist and immediately slaps on the brakes.


The Cloud: What’s UNIX® Got to Do With It?

Cloud Solution/Hosting Providers look to a UNIX Cloud infrastructure to service financial institutions looking to support high transactional environments like online and mobile banking marketplace. Moreover, UNIX Cloud infrastructure provides a cost-effective, secure, and redundant environment. “Verizon serves both customers and employees with a UNIX Cloud infrastructure that implements enhanced agility, superior performance, easy maintainability, and effective cost control,” said Chris Riggin, Enterprise Architect at Verizon. HPE, IBM, and Oracle have expanded their services offerings to deliver UNIX mission-critical cloud and enterprise infrastructure, including their branded systems.


Disaster Recovery in a Virtual World

The cost of failure is expensive. IDC research shows that a medium-sized organization experiences, on average, 15–18 business hours of network, system, or application downtime per year, with each hour of downtime costing approximately $225,000. The result of going digital means businesses cannot tolerate the same levels of planned and unplanned downtime that they could before. In fact, for many businesses, “the window for downtime is close to zero.” In another survey, many organizations (39%) said they now need to restore critical workloads in minutes, not hours, and that meeting this requirement is virtually impossible with outdated data protection methods.


Here's why banks are embracing cloud technology

We’ve entered the most profound era of change for financial services companies since the 1970s brought us index mutual funds, discount brokers and ATMs. No firm is immune from the coming disruption and every company must have a strategy to harness the powerful advantages of the new fintech revolution. The battle already underway will create surprising winners and stunned losers among some of the most powerful names in the financial world: The most contentious conflicts (and partnerships) will be between startups that are completely reengineering decades-old practices, traditional power players who are furiously trying to adapt with their own innovations, and total disruption of established technology & processes


Focus on Security Paves the Way for Expanding Services

Think of it as a piece of fruit, an apple, and you pass it around identifying yourself. Tokenization, and the Stateless Tokenization technology that HPE offers in particular, is that you have an exchange process. The middleman takes your apple, turn it into a pear through a specific algorithm. The reverse process can be applied when someone gives me a pear and ask for an actual apple; the visual is coming back to you. So, every time, every piece of information that is passed along in the message exchange, they go through this process. The key term here is stateless, of course, so that we don’t have a rack of this mapping information stored somewhere, which becomes yet another vulnerability. That makes our operations a lot easier, especially in a multi data-center environment.


One Berlin startup wants to make sharing your data as easy as sharing your money

Jolocom is developing an application that will allow users to share personal information through a secure and decentralized blockchain network. A user’s personal information is tied to them through an individual Web ID generated by the app, allowing them to share information directly with other others in the network. “It’s an extension of hyperlinking,” says Lohkamp. “But instead of linking documents or webpages, you’re linking data.” Say, for example, you wanted to open a new bank account. Instead of going to the bank in person to fill out paperwork and provide different forms of identification, you could just connect to the bank through the Jolocom app. The bank would then request the necessary information, and, with your approval, the data would be automatically transferred to create your account.


Virtual Labor Will Fuel Digital Initiatives

Nevertheless, smart machines and the services they enable are a reality. Hundreds of organizations are adopting smart-machine-enabled services to achieve short- to midterm savings, new revenue sources or profitability structures. Few, however, have fully understood the depth and magnitude of the potential value of the intellectual property (IP) being created. The IP developed alongside smart-machine-enabled services has the potential to add significant revenue, as it may be patentable. Due to the need for speed, business leaders tend to partner with providers to engage them in proofs of concept without involving sourcing executives or their teams, which exposes the organization to long-standing sourcing risks (including selection of the wrong partners, negotiation mistakes and vendor management issues).


How An Agricultural Data Firm Puts The Cloud To Work

In a phone interview with InformationWeek, Sanjay Dayal, CTO and cofounder of Agralogics, said he considered a variety of enterprise integration platforms from companies like MuleSoft, Tibco, and WSO2. Those offerings, he said, would have required more configuration, coding, and maintenance than Built.io Flow. "The whole point was I didn't want to have a very heavy infrastructure," said Dayal. "This is something for which we needed lighter touchpoints." Agralogics functions as an ERP service for the food ecosystem, Dayal said, noting the food industry tends to adopt new technology slowly. Built.io Flow proved appealing because it could connect customers' antiquated systems with AWS, the infrastructure that Agralogics relies upon.


HIT Think How IoT will affect information governance

Gartner defines information governance as the specification of decision rights and an accountability framework to ensure behavior in the valuation, storage, use, archiving and deletion of information. While these are accurate and encompassing definitions, they are built on top of, and rooted in, processes that are being forever changed by IoT. Data defines how you operate your company at a foundational level. Data also impacts how you operate your organization and what you provide as services, as well as how you measure success and failure from your financial reporting. Data is vital to every process in the organization, and the discipline of information governance has become one of the most strategic areas within corporate management to understand and manage data.


Let's build a robot!

We've all seen various household and industrial/commercial robots come to the market. They are generally big budget, expensive things that are mostly out of reach financially, or so limited in their functionality as to be almost useless. Interesting, and indeed fascinating, but quite useless. At the end of May of this year (2016), Asus launched its own first stab at a household robot, and I thought - wow, that's cute, and actually, not that difficult to build... sure, what we might build at home may not be as polished or slick as the cool thing Asus sells, but it sure as heck could have similar functionality, if not more!



Quote for the day:


"Entrepreneurship is neither a science nor an art. It is a practice." -- Peter Drucker


July 30, 2016

The Evolution Of DevOps: The Perfect Storm For Instituting Secure Coding Practices

The sheer volume of software development that DevOps makes possible makes it uncannily intuitive to add secure coding practices without slowing deployments. “The move to CI/CD as part of the agile development process leverages automation in what used to be a manual process, which adds incredible speed. Integrating security tools into that pipeline is now much easier than coordinating across multiple manual steps, involving multiple engineers,” says Kail. With the extreme drought of cyber security engineers, which the industry expects to continue if not broaden, the automation that is native to DevOps is critical to increasing and enforcing secure coding practices, if the industry is going to do it at all, says Kail.


Chrome browser extensions discovered engaging in Facebook click fraud

The suspicious extension allegedly came from the viral content site Viralands.com, and was available in the Chrome store, along with nine other identical programs that collectively amassed over 132,000 users. After analyzing the extension's metadata, Kjaer determined that the age verification pop-up screen was entirely nonfunctional, merely serving as a decoy that concealed the true motives for obtaining such sweeping user permissions. However, another script within the code was more enlightening: this script was coded to download a payload from an external server and execute it. The payload, naturally, was malicious, designed to send links that direct users to a web page containing Facebook tokens, which the extension program can then grab and exfiltrate to the command-and-control server.


Blockchain Can Bring the Unbanked into the Global Economy

Despite the significant headway in recent years made by providers in reaching areas previously untouched by banking services, more than two billion potential financial services customers remain stranded. In an industry characterized by geographic fragmentation, mobile money providers have yet to find a clear path to achieving significant scale required to realize network effect for long-term viability. Among many other uses, the blockchain could bolster these efforts by becoming the backbone to open the closed-loop mobile money services. Right now, certain payments services only work between two parties if they both have accounts. Similarly, mobile money services, often developed by the mobile operators themselves, often didn't allow for consumers to easily pay each other on separate mobile networks.


Ethereum's Two Ethereums Explained

One point Bitcoin Core developers continued to argue during the long-standing debate was that contentious hard forks are dangerous and can have unexpected consequences, such as splitting a blockchain into two competing blockchains. Many in the community, for example BitPay Co-Founder and CEO Stephen Pair, think that ethereum classic’s sudden popularity shows that these were valid concerns. Adding to the debate is that ethereum’s hard fork was immediately branded as a success by many Ethereum developers and others in the bitcoin industry. For example, Coinbase CEO Brian Armstrong tweeted that they’re "not something to be feared that results in multiple coins". But this analysis might have been premature, and he indicated as much in a new blog post.


Sonus’ Kevin Riley Discusses Cloud-Based Communications

Adoption of a microservices architecture will become increasingly important as well. Service providers should be able to monetize their cloud investment by rapidly creating and seamlessly scaling out new services. Microservices serve as the mechanism to get more granular in this scalability by separating network services into functional components. For our SBC SWe, this means signaling, media processing and transcoding can be scaled independently. It also means that technology decisions can be made independently. For example, introducing the use of graphics processing units (GPUs) for media transcoding instead of using CPUs which are not optimized for compute-intensive processing.


Blockchain will eliminate frauds and malpractices in trade finance

In today’s digital world where we can read our newspaper online, we have not been able to digitise documents such as invoices and bill of lading. There has been simply too much inertia and room for fraud with the availability of photo editing software such as Photoshop. If real money can be forged, there is no reason that a bill of lading cannot be forged. However, the availability of Blockchain means that there can only be one accepted bill of lading and other documents from the seller. There can be no fraud or double spending of the bill of trading once the payment has been made. An extension of Blockchain technology is a smart contract. This means that the buyer is forced to pay the seller once he/she has received all the proper documents that include evidence that the goods had been received by the buyer.


Successful cloud migration isn’t about strategy or technology

Where companies are making progress in moving legacy to the cloud, they establish small, cross-functional teams (eight to 15 people) that are equipped and empowered to make changes, whether it’s architecture design or ecosystems. The teams must have cross-functional capabilities, and they should be rewarded on getting to a destination, not uncovering problems in getting there. It’s not that they won’t deal with those problems; they will. But they must have the attitude and capability to resolve them. As a CIO driving change, you must get people to want to change and see their job as finding how to change and getting over or around the hurdles, not pointing out the risks of change. Then you’ll make fast progress.


African bootcamps look to develop next generation coders

“We just don’t take anyone. They have to prove that they are a good fit for the programme,” Cynthia Mumbo the Marketing Lead at Moringa School told IDG Connect. Moringa accepts students once they pass an evaluation stage to determine that they are suited for the programme. She said that the aim of the school was to bridge the long standing gap for quality software in Africa. “There is a really big gap [in terms of tech talent] but also I don’t want to take away from Universities. Skills gained depend on which university you go to,” Mumbo said. ... “Somebody with a degree might not be able to do it [software development]. They would say I studied it but I do not have experience in it,” she said. “Bootcamps are project based so you get in there and your head in knocked around creating solutions.”


In Security, Know That You Know Nothing

There seems to be a false assumption in security that we know what to look for and how to go about it when scanning for threats. But this is not the case. Traditional signature-based security controls just aren’t good enough. Further, threats are constantly evolving and hackers have grown savvy to what organizations are looking for. Ransomware for example, has proven to be a blunt wake up call for enterprises relying solely on static signature based controls. Even when an organization does know what to look for, there are encroaching factors that make this methodology less than optimal. SSL encryption makes knowing signatures pointless. Mobility means that traffic is not always within the scope of an organization’s control. And cloud-based services have created another space organizations don’t always have access to.


Working with Multiple Databases in Spring

When developing enterprise applications we are frequently confronted with the challenge of accessing multiple databases. Perhaps our application must archive data into some data warehouse, or maybe it must propagate data to some third party database. With Spring it is easy enough to define a common data source, but once we introduce multiple data sources it gets a bit tricky. In this article we will demo a technique for accessing multiple databases in Spring Boot applications easily and with minimum configuration, by developing a SpringMVC application using Spring Boot



Quote for the day:


"A good programmer is someone who always looks both ways before crossing a one-way street." - Doug Linder