Diberdayakan oleh Blogger.

Popular Posts Today

Will iWork for iCloud work for you?

Written By Unknown on Sabtu, 24 Agustus 2013 | 16.00

Apple has made iWork for iCloud available to the masses. It's technically still in beta, but now anyone can use the cloud-based versions of Pages, Numbers, or Keynote from an iCloud account. The question is whether or not iWork is the right suite of tools for you to use.

Apple trumpeted iWork for iCloud at its WWDC event a few months ago. The tools provide Web-based equivalents to Apple's iWork apps, and join Mail, Contacts, Calendar, Notes, Reminders, and Find My iPhone on Apple's iCloud.

Pages, Numbers, and Keynote join the iCloud ranks.

Apple provides iCloud accounts with 5GB of storage for free. This is slightly less than the 7GB Microsoft provides by default for SkyDrive accounts, and only a third of the 15GB Google supplies for Google Drive customers.

The tools themselves are capable. They look and feel very close to the experience provided by the desktop and mobile versions of the iWork tools. In general, the iWork tools are not as comprehensive or capable as their Microsoft Office counterparts, but they are more than adequate for most users' needs.

You can drag iWork or Microsoft Office files from your desktop into the browser window to upload them to iCloud. One of the benefits of using the iWork tools is all the data is synced through iCloud. Any changes you make in the iWork for iCloud apps is automatically reflected in the desktop and app versions, if you have them.

The iWork suite of tools is less expensive than its Microsoft rival. Pages, Numbers, and Keynote cost $20 each in the Mac App Store, and the mobile equivalents are $10 each. The iOS apps work for both iPhone and iPad, but it will still set you back $90 to get all three apps for Mac OS X and iOS.

The advantages of iWork for iCloud are intertwined with Mac OS X and iOS. The tools are available for Windows users or those who choose a mobile platform other than iOS, but the value of using them is a function of how well everything in the Apple ecosystem plays together. Those in the Google/Android world are better off sticking with Google Docs, and those in the Windows/Windows Phone environment should use Office Web Apps and Office Mobile Apps.

It's this simple: If you are Apple-centric, iWork for iCloud makes sense. You will appreciate the way things sync and the consistent experience from one device or platform to the next.

One caveat, though, is that iWork only has equivalents for Word, Excel, and PowerPoint. If you abandon Microsoft Office entirely, you'll have to embrace Apple Mail, Calendar and Contacts as well, or find some other alternative for the functions of Outlook. If you need other Microsoft Office tools like Access or Publisher, you'll need to buy them a la carte, or find suitable replacements.


16.00 | 0 komentar | Read More

Samsung’s ridiculous ad for the 840 EVO SSD will live forever in Web infamy

While the Reddit community usually eschews complaining and mocking things they find on the Internet, they decided to throw their usual constraints aside to pile on a new Samsung Web ad for the company's newly released 840 EVO solid state drive.

Reddit made the correct decision. All the actors in the slickly produced ad speak in a close approximation of what you might expect a typical consumer to sound like—if you've never met an actual human before. So, what's the deal here, Samsung?

Apparently this ad, which, despite its inclusion of English speaking, American-born actors, was never meant to actually be seen by US consumers. That's likely because the ad will strike US consumers as absolutely insane (not to mention patronizing, as the only actress in the spot describes how she enjoys using her computer in-between chores and becomes anxious at the thought of installing a new drive). The ad was purportedly meant only for use as an in-house marketing tool to be shown at expos throughout Asia.

At least, that's the take according to a Redditor by the name Damienf1 who claims to have played the businessman frustrated by his slow computer. The Seoul-based actor chalks the ad's overall strangeness to cultural mistranslation, as he describes in a since-deleted comment (saved for posterity here).

They ask us to exaggerate since many Korean people feel thats how we 'naturally' act (most people here are not very expressive). the script is brutal. written by non-native english speakers, and sometimes the PD or director won't even take our suggestions to change some parts so they sound like something a normal native english speaker would say. [I]ts a promotional video, not a tv commercial, meaning it will be shown at conventions and expos and in-house. most of the people watching it are korean and thats why they make us do all of the above.

Apparently Samsung did not take too kindly to being called out, and called the actor's agency to pull down his comments as he described later:

im just as shocked as you at this turn of events. this whole day i was dealing with the agency i did that job through. they are being heavily pressured by samsung. not 2 hours after the post went to the front page, my manager literally called me in tears begging me to delete my comments.

i know that sounds ridiculous, but its true.

Samsung, you have created the Sharknado of SSD Web ads that has managed to get far more people talking about your apparently pretty spectacular SSD drive than otherwise ever would have.

Embrace it, you accidental marketing geniuses.

Follow TechHive on Tumblr today.


16.00 | 0 komentar | Read More

Tech firms' responses to latest NSA disclosures cloud the truth, experts say

Technology companies may be hiding behind legal jargon to avoid being more forthcoming in their responses to new documents on government surveillance that were disclosed Friday, some experts say.

Internet and software companies including Microsoft, Yahoo, Google and Facebook "are legally compelled to lie," said security expert Bruce Schneier, citing national security letters that companies are prohibited from disclosing.

Some similar statements were made in interviews with the IDG News Service following a report published Friday in The Guardian alleging that the National Security Agency paid millions of dollars to companies such as Google and Facebook to cover costs involved in surveillance.

The tech companies incurred these costs in fulfilling tighter certification requirements after a 2011 court ruling said the government's data collection was unconstitutional, according to documents obtained by The Guardian.

That ruling, which was handed down by the Foreign Intelligence Surveillance Court and was made public on Wednesday, said that the way the NSA collected data violated the Fourth Amendment because the agency did not effectively design its collection efforts to target only foreigners of interest to national security.

The NSA was "misusing its authority" by collecting the digital communications of U.S. citizens for years, the ruling said.

The documents revealed Friday describe the problems that the agency experienced after that ruling and the resulting efforts required to bring companies into compliance, according to The Guardian. The list of involved companies includes Google, Yahoo, Microsoft and Facebook, its report said.

The documents were passed on to The Guardian by former NSA contractor Edward Snowden, the man behind the original leaks of various government surveillance programs such as Prism. The documents provide the first evidence of a financial relationship between technology companies and the NSA, the Guardian report said.

The FISA court is required to sign annual certifications that provide the legal framework for surveillance operations, the report said. After the 2011 ruling, those certifications were only being renewed on a temporary basis as the NSA worked to fix its data collection methods that the court deemed unconstitutional.

This adjustment process entailed huge costs, according to a 2012 NSA newsletter entry, excerpts of which were published by The Guardian. "Last year's problems resulted in multiple extensions to the certifications' expiration dates which cost millions of dollars for Prism providers to implement each successive extension," the newsletter said.

The Guardian did not give an exact figure for the costs.

The latest disclosure raises serious questions around the use of taxpayer money to finance government surveillance, the Guardian said. But another issue is the growing discrepancy between the information contained in leaked government documents and technology companies' responses to it.

Snowden's original leaks revealing Prism described a program aimed at the mass collection of data owned by U.S. citizens through direct access to company servers. Google and other tech companies have denied cooperating with the NSA to allow the mass collection of data.

They gave similar denials on Friday in response to questions from the IDG News Service.

"Facebook has never received any compensation in connection with responding to a government data request," a Facebook spokeswoman said.

"We think the continued misreporting on this matter by The Guardian and others is troubling," she added in an email.

Google said it has "not joined Prism or any government surveillance programs."

"We do not provide any government with access to our systems and we provide user data to governments only in accordance with the law," a spokeswoman said.

Both Yahoo and Microsoft offered more legalistic, complicated responses. Their responses make it clear that the companies' deals for government compensation are more complicated than something they can simply confirm or deny.

"Microsoft only complies with court orders because it is legally ordered to, not because it is reimbursed for the work," a spokesman said. "We could have a more informed discussion of these issues if providers could share additional information, including aggregate statistics on the number of any national security orders they may receive," he said.

Microsoft asked for permission in June to aggregate statistics about the number of requests for data it receives under the U.S. Foreign Intelligence Surveillance Act.

Currently, companies can reveal the number of FISA requests they receive only if they lump them together with all other requests from U.S. law enforcement agencies.

Yahoo said it had nothing to add beyond the statement that the company supplied to The Guardian, which said "federal law requires the U.S. government to reimburse providers for costs incurred to respond to compulsory legal process imposed by the government."

"We have requested reimbursement consistent with this law," the company said.

Semantics are at play in companies' responses, experts said.

Friday's leaked documents "say that these companies cooperate with bulk NSA data collection," said Schneier. "The companies deny it, but their denials are precisely worded with a lot of wiggle room," he said.

Also, if companies are compelled by a National Security Letter to comply, they are prohibited from talking about their compliance, Schneier said.

In its response Friday, Google said it continues to await the government's decision on the company's petition to publish more national security request data, "which will show that our compliance with American national security laws falls far short of the wild claims still being made in the press today."

Roger Kay, an IT analyst and founder at Endpoint Technologies Associates, said he was not surprised by the documents that were revealed Friday. Though the companies don't say whether they provided information to the government, the legalistic language in some of their responses suggests they did, he said.

Also, companies' responses to the growing number of leaks, whether they are flat-out denials, chock full of complicated legalese, or just plain vague, are probably damaging some users' trust in the companies, Kay argued.

But for Internet users with short attention spans, disclosures like the ones revealed Friday may just blow over, he added.

Still, many questions remain about the type of data collection that was paid for in the millions of dollars in compliance costs that companies reportedly incurred.

It's not clear how the NSA gathers data from companies, Kay said. "Is it like a direct stethoscope into the main artery, or a broader snapshot?"

Getting answers to those kinds of questions may also boil down to semantics. "Perhaps different people mean different things by 'direct access,'" said Seth Schoen, senior staff technologist at the Electronic Frontier Foundation.

In another new development, The Guardian and The New York Times announced on Friday that they would work as partners to give the U.S. paper access to other documents leaked by Snowden. Both papers will be working together to publish more stories tied to the documents.


16.00 | 0 komentar | Read More

Mozilla 'Plug-n-Hack' project aims for tighter security tool integration

Written By Unknown on Jumat, 23 Agustus 2013 | 16.00

Mozilla is developing a protocol that aims to let security tools and Web browsers work better together.

Configuring a web browser to work with a security tool involves writing platform and browser-specific extensions, a non-trivial process that discourages people with less experience, wrote Simon Bennetts, a security automation engineer with Mozilla, on Thursday.

The proposed standard, called "Plug-n-Hack," will define how security extensions can work with a browser in a more usable way, Bennetts wrote. PnH will allow the security tool to "declare the functionality that they support which is suitable for invoking directly from the browser."

Under the current arrangement, if a user wants to, for example, intercept HTTPS traffic, a user must configure proxy connections through the tool and browser correctly and import the tool's SSL (Secure Sockets Layer) certificate, Bennetts wrote.

"If any of these steps are carried out incorrectly then the browser will typically fail to connect to any website -- debugging such problems can be frustrating and time-consuming," Bennetts wrote.

Users may also have to switch often between the tool and their browser to intercept an HTTPS request.

"PnH allows security tools to declare the functionality that they support which is suitable for invoking directly from the browser," Bennets wrote. "A browser that supports PnH can then allow the user to invoke such functionality without having to switch to and from the tool."

The PnH protocol is being designed to be browser and tool independent. The implementation for Firefox has been released under the Mozilla Public License 2.0 and can be incorporated into commercial products for free, Bennetts wrote.

The next phase of the project is being planned, but it is expected it will allow browsers to "advertise their capabilities to security tools," he wrote.

"This will allow the tools to obtain information directly from the browser, and even use the browser as an extension of the tool," Bennetts wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


16.00 | 0 komentar | Read More

Copyright guru claims 'fair use' to fight YouTube takedown notice

Creative Commons co-founder Lawrence Lessig has filed a complaint in a U.S federal court after he was forced to take down a YouTube video of his lecture which included clips that depicted groups of people dancing to a copyrighted song.

The complaint filed by Lessig with help from digital rights group Electronic Frontier Foundation is likely to be a high-profile test of the "fair use" doctrine in the reuse of copyrighted material online.

Creative Commons is a nonprofit organization that has created a variety of liberal licenses to promote the sharing of copyrighted material.

Lessig, a professor at Harvard Law School, delivered a lecture on the present and future of cultural and technological innovation in June 2010, at a Creative Commons conference in Seoul, South Korea. The lecture included clips of amateur music videos, which depicted groups of people dancing to the song Lisztomania, by a French band Phoenix, according to the complaint filed Thursday in U.S. District Court for the District of Massachusetts.

The Lisztomania copycat video phenomenon started when a YouTube user, called "avoidant consumer," posted on YouTube a video combining scenes from several movies, with the Lisztomania song as the soundtrack to the video, the complaint said. YouTube users in other parts of the world created their own versions of the video, with real people playing the roles of the actors in the original movies, and again with Lisztomania as the soundtrack, it added.

Lessig included the clips in the lecture to "illustrate how young people are using videos and other tools to create and communicate via the Internet."

The video of the lecture was posted on YouTube in June this year, and by June 30, Lessig received a notice from YouTube that the video posting of the lecture had been identified and blocked as having content owned or licensed by Viacom in line with YouTube's filtering procedures. YouTube restored access to the video after Lessig filed a notice disputing the block, according to the complaint.

Around June 30, Liberation Music in Melbourne, Australia, also submitted a takedown notice to YouTube under the Digital Millennium Copyright Act, demanding the removal of the video as it allegedly infringed a copyright owned or administered by Liberation Music. On June 30, Lessig was sent an email by YouTube, informing him that the video had been removed. He filed a counter-notice to YouTube who forwarded it to Liberation Music, who in turn threatened to sue him in the Massachusetts court if he did not retract his counter-complaint, which Lessig did.

The EFF on behalf of Lessig has argued that "use of the clips in question, particularly in the context of a public lecture about culture and the Internet, is permitted under the fair use doctrine and, therefore, does not infringe the defendant's copyright." The use of the copyrighted material by Lessig was minimal and for non-commercial purposes and was also transformative as the purpose was no longer entertainment but educational. The lecture video did not cause any market harm as it was "not a market substitute for a sound or video recording of the song 'Lisztomania' and the lecture did not harm any market for the song," according to the complaint.

Liberation Music did not immediately respond to a request for comment. Its automated reply to email states, among other things, that YouTube's Music Match service creates copyright claims automatically based on its copyright ownership. "Unless you're advertising a product or using our music for something we wouldn't reasonably agree to, this automated claim will not have any negative effect on your account !" It adds that if an automatic claim is disputed, it will cause removal of the video.

Lessig has asked the court for a declaration that the publication of the lecture video is protected under the fair use doctrine, and also asked for damages.

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com


16.00 | 0 komentar | Read More

Samsung refused retrial over 'overscroll bounce' patent in Apple dispute

Samsung Electronics was denied Thursday a retrial over the "overscroll bounce" patent in its dispute with Apple in a federal court in California.

The South Korean company had in a filing asked for a retrial as it said that Apple had advocated an "entirely new and far narrower interpretation" of Claim 19 of U.S. Patent no. 7,469,381 ('381 patent), to avoid having the claim cancelled by the U.S. Patent and Trademark Office.

The USPTO in June confirmed four claims of Apple's patent, including claim 19 of the patent. The claim played a crucial part in Apple's US$1.05 billion dollar lawsuit against Samsung.

Judge Lucy H. Koh of the U.S. District Court for the Northern District of California, San Jose Division, said in her ruling Thursday that the court had denied Samsung's motion for a new trial based on the '381 Patent.

Samsung asked for a retrial based on "newly discovered evidence" with regard to 18 of its products for which the jury found infringement of the '381 patent and awarded damages.

The patent refers to "list scrolling and document translation, scaling and rotation on a touch-screen display," and is popularly known as Apple's overscroll bounce patent.

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com


16.00 | 0 komentar | Read More

NSA collected thousands of domestic communications in 2011, court document shows

Written By Unknown on Kamis, 22 Agustus 2013 | 16.00

The National Security Agency was acquiring thousands of digital communications from Americans as of 2011, according to a declassified document from the Foreign Intelligence Surveillance Court.

The glimpse of the NSA's surveillance on people in the U.S. was revealed Wednesday in an 86-page court assessment of the constitutionality of agency's data collection methods. It was released by the Office of the Director of National Intelligence.

The 2011 assessment was based on NSA's own review of what the document refers to as "a statistically representative sample" drawn from the intelligence agency's collection of upstream data. "Upstream data" refers to Internet communications, such as email, as they transit, rather than to acquisitions directly from Internet service providers, the court document said.

The review revealed that NSA acquired roughly 2,000 to 10,000 "multi-communication transactions," or MCTs, each year that contain at least one wholly domestic communication. An MCT refers to the capture of multiple different communications at once, such as emails within a single webmail service, one staff member at the Electronic Frontier Foundation said. EFF has been fighting for the federal court to release the review for over a year.

The document also said that the NSA had been acquiring more than 250 million Internet communications in total each year.

The numbers help to shed new light on the scope of government surveillance into people's online communications in the name of national security.

Kurt Opsahl, senior staff attorney with the Electronic Frontier Foundation, called the figures "very significant."

"It shows that the NSA was misusing its authority for years and scanning the content of communications to do so," he said in an email.

The review also revealed a deception. Until NSA's manual review, "the government asserted that NSA had never found a wholly domestic communication in its upstream collection," the court opinion said.

The court expressed reservations throughout the document over the constitutionality of the NSA's data collection methods. Specifically, the procedures that the NSA used to target and minimize its data collection efforts among only foreigners who are of interest to national security issues "are inconsistent with the requirements of the Fourth Amendment," the document said.

The court also lamented a lack of information about the NSA's methods in its review. "The practical implications of NSA's acquisition of Internet transactions through its upstream collection for the Court's statutory and Fourth Amendment analyses are difficult to assess," the document said.

The document was released in response to a Freedom of Information Act lawsuit from the Electronic Frontier Foundation. The digital rights group called its release a victory, partly because it will help to encourage a public debate on the issue of government surveillance.

"Disclosing this opinion -- and releasing enough of it so that citizens and advocates can intelligently debate the constitutional violation that occurred -- is a critical step in ensuring that an informed debate takes place," EFF staff attorney Mark Rumold said in a statement.

The document's release comes just weeks after President Obama announced some sweeping reforms designed to limit data collection by the NSA under the Patriot Act.

Much of the issue of government surveillance has been pushed into the public consciousness following leaks made by former NSA contractor Edward Snowden.

Zach Miners covers social networking, search and general technology news for IDG News Service. Follow Zach on Twitter at @zachminers. Zach's e-mail address is zach_miners@idg.com


16.00 | 0 komentar | Read More

Poison Ivy, used in RSA SecurID attack, still popular

A malicious software tool perhaps most famously used to hack RSA's SecurID infrastructure is still being used in targeted attacks, according to security vendor FireEye.

Poison Ivy is a remote access trojan (RAT) that was released eight years ago but is still favored by some hackers, FireEye wrote in a new report released Wednesday. It has a familiar Windows interface, is easy to use and can log keystrokes, steal files and passwords.

Since Poison Ivy is still so widely used, FireEye said it is harder for security analysts to link its use to a specific hacking group.

For its analysis, the company collected 194 samples of Poison Ivy used in attacks dating to 2008, looking at the passwords used by the attackers to access the RATs and the command-and-control servers used.

Three groups, one of which appears to be based in China, have been using Poison Ivy in targeted attacks going back at least four years. FireEye identified the groups by the passwords they use to access the Poison Ivy RAT they've placed on a target's computer: admin338, th3bug and menuPass.

The group admin388 is believed to have been active as early as January 2008, targeting ISPs, telecoms companies, government organizations and the defense sector, FireEye wrote.

Victims are usually targeted by that group with spear-phishing emails, which contain a malicious Microsoft Word or PDF attachment with the Poison Ivy code. The emails are in English but use a Chinese character set in the email message body.

Poison Ivy's presence may indicate a more discerning interest by an attacker, since it must be controlled manually in real-time.

"RATs are much more personal and may indicate that you are dealing with a dedicated threat actor that is interested in your organization specifically," FireEye wrote.

To help organizations detect Poison Ivy, FireEye released "Calamine," a set of two tools designed to decode its encryption and figure out what it is stealing.

Stolen information is encrypted by Poison Ivy using the Camellia cipher with a 256-bit key before it is sent to a remote server, FireEye wrote. The encryption key is derived from the password the attacker uses to unlock Poison Ivy.

Many of the attackers simply use the default password, "admin." But if the password has changed, one of Calamine's tools, the PyCommand script, can be used to intercept it. A second Calamine tool can then decrypt Poison Ivy's network traffic, which can give an indication of what the attacker has been doing.

"Calamine may not stop determined attackers that use Poison Ivy," FireEye warned. "But it can make their criminal endeavors that much more difficult."

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


16.00 | 0 komentar | Read More

Nginx Web server goes commercial with new release

Nginx is releasing a commercial edition of its namesake open source Web server software, called Nginx Plus, which it will market as a software alternative to application delivery controllers (ADCs).

"The features that have been added are very similar to what you'd find in hardware-based ADCs," said Gus Robertson, CEO of Nginx. "We're an alternative to Apache, but I think we're also an alternative to hardware-based application delivery controllers."

Robertson said that the software will provide functionality similar to that of ADC appliances from F5 Networks or Citrix, which are used to speed delivery of high traffic websites through techniques of load balancing and caching.

Nginx has already made a name for itself as a Web server able to very efficiently handle large amounts of traffic.

Russian system administrator Igor Sysoev released the first version of Nginx in 2004 under a BSD open source license, after becoming frustrated by what he felt were the limitations of the market-leading Apache Web server software.

Sysoev specifically designed Nginx (pronounced "Engine X") for handling large volumes of traffic, up to 10,000 concurrent connections per server. It includes advanced traffic management features often found in ADCs, such as load balancing, edge caching and reverse proxy services.

According to the company, Nginx is now the most widely used Web server software among the world's 1,000 busiest sites. Web heavyweights such as Netflix, Hulu, Pinterest, AirBnB, WordPress.com, GitHub, SoundCloud, Zynga, Eventbrite and Zappos have all used Nginx to serve their sites.

The software now runs about 100 million websites overall, or about 14.55 percent of the Web, according to the latest Internet survey from Netcraft.

Sysoev founded Nginx the company in 2011, and took the role of chief technology officer. Nginx attracted US$3 million in first-round venture capital funding. Currently, it employs about 15 people. Robertson took over as CEO in April; formerly, he was the vice president of global business development for Red Hat, another open source software company.

Heretofore, Nginx, the company, has chiefly offered subscription support services for the open source software, around configuration and performance tuning, performance optimization and technical account management. Nginx Plus is the company's first commercial product.

Under a dual license, the commercial version of Nginx will offer additional features over the freely available open source version.

"The advanced functionality enhances the capabilities of Nginx in regards to load balancing, request routing, health monitoring and general control and monitoring of Nginx instances in mission critical environments," said Andrew Alexeev, Nginx co-founder and head of business development.

One of the most significant new features is the ability to make configuration changes to a running copy of Nginx, without the need to restart the software for the changes to take affect. Typically configuration changes to Web server software, such as Nginx or Apache, require the software to be stopped and then restarted, which can momentarily disrupt operations.

"Even graceful restarts can affect the operation, and adds slight overhead. [Users] want to change aspects of Nginx on the fly," Alexeev said.

With monitoring, the commercial package provides metrics of a running copy of Nginx, in the JSON (JavaScript Simple Object Notation) format. "You can import these metrics into any standard commercial or open source monitoring system, or you could use your own template through HTML or JavaScript," Alexeev said. The software package also comes with its own metrics dashboard as well.

The health check can alert an administrator when a back-end component of a Web application has failed, such as the database. It does this by comparing the size of a new Web page with the size it should be. It can also automatically take out of service those servers relying on the failing components. Nginx has also collaborated with New Relic to integrate the data generated by health checks to show up in New Relic's application performance management (APM) software.

Other features of the commercial edition include additional load balancing capabilities, and advanced media streaming for Adobe HDS and Apple HLS video formats.

Although Nginx Plus should run on any standard Linux distribution, Nginx has certified that the software runs on Amazon Linux, Red Hat, CentOS, Ubuntu, and Debian distributions.

Nginx Plus will cost $1,350 per instance per year and is available now.

Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is Joab_Jackson@idg.com


16.00 | 0 komentar | Read More

'Instagram for PC' application is a marketing scam

Written By Unknown on Rabu, 21 Agustus 2013 | 16.00

An advertisement circulating on Facebook and Twitter for a desktop version of the photo-sharing application Instagram is a scam, according to security vendor Symantec.

Instagram, which is owned by Facebook, is only available for mobile devices. Its popularity, however, makes it attractive for spammers and scammers, wrote Satnam Narang, a security response manager with Symantec, on Tuesday.

"Both of the supposed versions of Instagram for PC do not deliver as promised," Narang wrote. "This is just another vehicle for the scammers to convince users to fill out surveys, so they earn money through shady affiliate programs."

Luckily, Narang wrote that "there was no malicious functionality bundled with the software, such as a keylogger or backdoor." Such ploys are typically wrapped up with malicious software.

The scammers offer what is purportedly an emulator that allows Instagram to run on a desktop computer. Clicking on a link initiated two downloads, one of which is a large ".rar" compressed archive and the other a bundle of dynamic link library files, Narang wrote.

Running the program launches a login screen. If a user logs in, an error message is displayed along with a dialog asking if the user wants to download another file that is supposedly needed.

The program then implores people to "click a variety of social sharing options before trying the download again," Narang wrote. Finally, the user is lead to a survey.

Another version of Instagram for PC asks the user to activate the program that then displays a pop-up window, which leads to another survey.

The dodgy program has gained a bit of traction. Narang wrote more than 4,000 people have posted about the application on Twitter and Facebook. Another 2,000 have shared it on Google+.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


16.00 | 0 komentar | Read More
techieblogger.com Techie Blogger Techie Blogger