Microsoft: Windows 10 is hardened with these fuzzing security tools now they’re open source – ZDNet

Microsoft has released a new open-source security tool called Project OneFuzz, a testing framework for Azure that brings together multiple software security testing tools to automate the process of detecting crashes and bugs that could be security issues.

Google's open-source fuzzing bots have helped it detect thousands of bugs in its own software and other open-source software projects. Now Microsoft is releasing its answer to the same challenge for software developers.

Project OneFuzz is available on GitHub under an open-source MIT license like Microsoft's other open-source projects, such as Visual Studio Code, .NET Core and the TypeScript programming language for JavaScript.

SEE: Hiring Kit: Python developer (TechRepublic Premium)

Microsoft describes Project OneFuzz as an "extensible fuzz testing framework for Azure".

Fuzzing essentially involves throwing random code at software until it crashes, potentially revealing security issues but also performance problems.

Google has been a major proponent of the technique, pushing coders and security researchers towards fuzzing utilities and techniques. Its open-source fuzzers include OSS-Fuzz and Cluster Fuzz.

OSS-Fuzz is available for developers to download from GitHub and use on their own code. It's also available as a cloud service for select open-source projects.

Microsoft previously announced that it would replace its existing software testing toolset known as Microsoft Security and Risk Detection with the automated, open-source fuzzing tool.

The Redmond company also says it's solving a different and expensive challenge for all businesses that employ software developers, and gives credit to Google for pioneering the technology.

OneFuzz is the same testing framework Microsoft uses to probe Edge, Windows and other products at the company. It's already helped Microsoft harden Windows 10, according to Microsoft.

"Fuzz testing is a highly effective method for increasing the security and reliability of native code it is the gold standard for finding and removing costly, exploitable security flaws," said Microsoft Security's Justin Campbell, a principal security software engineering lead, and Mike Walker, a senior director, special projects management.

"Traditionally, fuzz testing has been a double-edged sword for developers: mandated by the software-development lifecycle, highly effective in finding actionable flaws, yet very complicated to harness, execute, and extract information from.

"That complexity required dedicated security engineering teams to build and operate fuzz-testing capabilities making it very useful but expensive. Enabling developers to perform fuzz testing shifts the discovery of vulnerabilities to earlier in the development lifecycle and simultaneously frees security engineering teams to pursue proactive work."

As Microsoft notes, "recent advancements in the compiler world, open-sourced in LLVM and pioneered by Google, have transformed the security engineering tasks involved in fuzz testing native code".

SEE: Open-source security: This is why bugs in open-source software have hit a record high

These advances make it cheaper for developers to handle what was once attached and instead bake these processes into continuous build systems, according to Microsoft. This includes crash detection, which was previously attached via tools such as Electric Fence. Now they can be baked in with asan.

It also addresses previously attached tools such as iDNA, Dynamo Rio, and Pin that are now built in with sancov.

"Input harnessing, once accomplished via custom I/O harnesses, can be baked in with libfuzzer's LLVMFuzzerTestOneInput function prototype," Campbell and Walker note.

Microsoft has also been adding experimental support for these features to Visual Studio so that test binaries can be built by a compiler, allowing developers to avoid the need to build them into a continuous integration (CI) or continuous development (CD) pipeline. It also helps developers scale fuzzing workloads in the cloud.

View original post here:
Microsoft: Windows 10 is hardened with these fuzzing security tools now they're open source - ZDNet

Girls on the Run of Snohomish County launches virtual fall season – My Edmonds News

Girls on the Run virtual programming will include physical activity and social-emotional learning. (Photo courtesy Girls on the Run)

Girls on the Run of Snohomish County (GOTRSnoCo) has announced the launch of a special virtual fall season.

GOTRSnoCo is a leader in delivering evidence-based, life skills curriculum to girls of all abilities through a program that creatively integrates running and movement. With more than 45 sites across the county, the organization has served more than 1,600 girls since it was founded in 2015. For the 2020 fall season, GOTRSnoCo is offering 100% virtual programming for girls in 3rd-8th grades to accommodate the changing and unpredictable school schedules due to the pandemic. Registration for the eight-week season is now open at http://www.GirlsontheRunSnoCo.org.

Our staff and coaches are ready to bring critical social-emotional programming to girls at a time when they need it the most, said Megan Wolfe, Executive Director of GOTRSnoCo. We have adapted based on the recommendations of local health officials and decisions of local governments and school districts. Our virtual programming makes it possible for girls to stay active and connected despite the pandemic.

Virtual fall programming is delivered by trained coaches in a safe virtual space, with lessons that mirror the in-person Girls on the Run for younger girls or Heart & Sole program for older girls. Virtual programming will include physical activity and social-emotional learning, providing girls with an opportunity to still build meaningful connections with their peers and caring adult role models.

Volunteer coaches will receive the training and materials required to provide girls a safe, trauma-sensitive space to learn valuable life lessons and be active.

Added Wolfe, Together, we will find a way to motivate girls to nurture their physical and emotional health, no matter the circumstances.

Sign Up for Our Daily Edmonds Newsletter

Follow this link:
Girls on the Run of Snohomish County launches virtual fall season - My Edmonds News

The Local Audience Is the Central Audience: As Tourism Tanks Across the US, Museums Pivot to the Visitors in Their Own Backyards – artnet News

Before the shutdown hit New York City museums in March, 70 percent of the Metropolitan Museum of Arts visitors traveled to it from other cities and countries. Now, since the museums August 29 reopening, that number has dwindled to just 20 percent, leading the Met, and institutions across the globe, to grapple for the first time with what it means to run a museum without tourists.

As social distancing shrinks visitor capacities, ticket sales are down and museums are feeling the financial hit. They are also having to retool programming for their newly local audiences.

Before the shutdown, the Met welcomed anywhere from 15,000 visitors to 25,000 (on a peak summer day). Now, capacity is 14,000, and the Met is currently using its timed ticketing system to generate audiences of about 5,000 visitors per day.

With loans and traveling shows curtailed, the museum will be relying heavily on its own collection to create exhibitions, Met director Max Hollein said. Overall, programming will be sharply reduced for the next 17 to 24 months, prompting the museum to explore new juxtapositions and new ways of contextualizing objects in its collection, said Hollein.

The museums current 150th anniversary exhibition, Making the Met 1870-2020, was already in the works long before the current crisis, but its nonetheless a good example of the kind of show that can be done from drawing on the museums own resources.

A view of the Metropolitan Museum of Art in April. Photo by Rob Kim/Getty Images.

We also became more local in the lockdown, Hollein said. Were focusing on what we have to energize and galvanize us in that direction. To that end, the museum is adding a modern spin to its period rooms display that represents a local New York story. Detailsabout the new installation will be revealed in coming months, but, for now, Its time we start to imagine a period room not of the past but of today that can reflect our current time and challenge contemporary issues, Hollein said.

Hollein expects that it could be two to three years before tourism approaches its pre-pandemic levels. The local audience is really the central audience, he said. Its an audience that has grown up with the institution and comes to you again and again. They have a much closer connection because they enjoy and notice constant changes within the institution. Their level of expectation is higher, than, for example, a tourist who comes once every few years.

Two friends in face masks sit in front of Claude Monets paintings at the Metropolitan Museum of Art during its first day open to members since March on August 27, 2020. Photo by Taylor Hill/Getty Images.

It appears the Met has plenty of company on this path. In June, Vastari, a digital platform that helps arts and cultural institutions source individual objects or entire exhibitions from peer institutions and private collectors, conducted a multiple-choice survey with its members about programming strategy through the end of 2021.

The majority of the 50 respondents were art museums, and 26 of them were based in the US. From this cohort, 52 percent replied that they would focus on organizing shows with their own permanent collections. Another 38 percent said budget restrictions would compel them to book only small exhibitions. Among the museums who responded other to the question, the most frequent explanation written in was an intent to focus on their local audiences.

Vastari CEO Bernadine Brcker Wieder told Artnet News that activity on the platform in the months since the survey has reinforced its findings. Although a few major institutions are planning to move ahead with blockbuster shows under the belief that they can still tempt sufficiently largeyet still socially distantcrowds from a newly local pool of potential visitors, others are pivoting to more modular programming: smaller, nimbler shows devised to directly engage the communities in their immediate surroundings.

Rather than hire whole touring exhibitions on Vastari, many institutions are now interested in paying for just a few objects from another museum that they can build a marketing campaign around, says Brcker Wieder. They still get the draw of a big touring show without the cost of a big touring show.

Vastari is even in the midst of changing its policies and capabilities in response. Prior to the shutdown, the platform only allowed member institutions to offer complete exhibitions to other member institutions, while private collectors could offer individual objects for show. But it is now working to give museums the same flexibility to hire out as little as a single work to their peersa practical acknowledgment of the new normals shifting priorities.

Its nottourism versus local, in many cases its audience versus curatorial interest, said Adrian Ellis, founder of AEA Consulting, which tracks spending and strategy in the cultural industries. The financial pressure of the past few months will lead to a more considered approach to programming generally, driven more on balance by considerations of audience than curatorial agendas.

Striking that balance is not exactly a new phenomenon, but Ellis predicts it will likely tip toward market and toward cost consciousness.As a result, small exhibitions that draw more heavily on permanent collections and less on borrowed objects may become more frequent. There will also of course be exhibitions exploring the current momentand our national preoccupations with race and social justice will clearly affect thinking about exhibitions. There will be continuing efforts to broaden audience demographics, he says.

Visitors walk through an exhibition at the newly reopened Whitney Museum. Photo by Angela Weiss/AFP via Getty Images.

Of course the situation is different for each institution. The Whitney Museum, like the Met, says the overwhelming majority of visitors are New Yorkers. The museum reopened with a month of pay-what-you-wish admission to welcome back New Yorkers while engaging and supporting the local community. Notably, it is one of the few museums that has not yet had a major disruption in programming. It was able to keep exhibitions on view that were installed before the shutdown, includingVida Americana: Mexican Muralists Remake American Art, 19251945, Cauleen Smith: Mutualities, and Agnes Pelton: Desert Transcendentalist, as well as its two collection installations which were on view prior to the museums closure.

We kept these shows installed for the duration of the closure so that they would be on view to welcome visitors back following the reopening, said a museum representative, adding that previously planned exhibitions remain on the schedule as well. Our programming has not been impacted by the shift in visitor composition.

Jackson Pollock, Mural (1943). University of Iowa Stanley Museum of Art, Gift of Peggy Guggenheim, 1959.6 2020 The Pollock-Krasner Foundation/Artists Rights Society (ARS), New York.

Another emergent trend in the museum sectors new normal is geographic disparity. The nations disjointed public-health response to the coronavirus has left the most popular institutions on the East Coast in vastly friendlier scenarios than their counterparts on the West Coast.

When the Guggenheim Museum reopens on October 3 with new exhibitions of Jackson Pollocks famedMural(1943) and related sculptures, all of New Yorks flagship arts institutions will once again be operational. Caveats apply, of course. According to a Guggenheim spokesperson, the museum will only accommodate a quarter of its normal capacity, with timed tickets and observance of other safety measures required. The Guggenheim also anticipates a 25 percent year-over-year decline in overall attendance in 2020, meaning the institution would host only about 900,000 total visitors by years end versus roughly 1.2 million in 2019.

The composition of its audience will also change substantially. Annual visitorship at the museum typically breaks down as roughly half international and half domestic, with nearly 40 percent of US visitors (meaning about 20 percent of all visitors) being New Yorkers. Although the museum does not have a projection for how much more of its overall attendance locals will comprise, it is safe to say that this year will deviate from the usual demographic trend.The Guggenheim is adjusting its communications strategy accordingly by featuring content aimed towards New York audiences on its social-media and digital platforms, the spokesperson said.

This approach harmonizes with the one already in practice at the Art Institute of Chicago. Since reopening on July 30, three-quarters of visitors to the encyclopedic museum have been local residents, according to a representative. Normally, this constituency makes up only about 50 percent of attendees. The Art Institute has responded by eliminating advertising targeted to tourists for the time being, as well as shifting the emphasis further toward the Chicago element of the campaigns for its current exhibition Monet and Chicago. The shows layout was also modified during the shutdown to optimize traffic flow through the galleries for a socially distanced world.

While the wildly popular art museums above undoubtedly wish their situations were better, their peer institutions in the west would likely love to have the same problems. The Getty Center and the Getty Villa will not welcome visitors until January 2021, according to a spokesperson. A representative for the Los Angeles County Museum of Art, whose website simply designates the campus as temporarily closed amid the pandemic and its controversial architectural overhaul, declined to comment for this story. Multiple email inquiries to the Museum of Contemporary Art Los Angeles went unanswered; alsotemporarily closed, the institution is scheduled to debut two new major exhibitions in October, but as of publication time, opening dates had yet to be announced.

The atrium of the new Kinder Building at the Museum of Fine Arts, Houston. Photo by Peter Molick, courtesy of MFAH.

To the extent that any institution can operate as it did pre-shutdown, the Museum of Fine Arts, Houston has been remarkably consistent. It reopened to the public a full three months ahead of most New York institutions, on May 23. The date set bymuseum leaders followed three weeks after that set by the states governor for museums to reopen.

Social distancing protocols are in place, including mask requirements, and timed ticket entries, and the museum is currently operating below 25 percent capacity, which is 900 visitors across the 14-acre main campus. A representative said the museum does not expect programming to be impacted as 90 percent of our audience has been and continues to be from the greater Houston area.

One pandemic-related delay is the opening of its newNancy and Rich Kinder Building, now set for November 21, about three weeks delayed. The Kinder Building will present works from the museums international collections of modern and contemporary art, opening with the first comprehensive installation drawn from the collections of Latin American and Latino art.

Still the Houston museums experience remains an outlier at this stage. As the conditions on the ground continue to evolve in the months ahead, the only certainty is that arts institutions will need to keep their creative problem-solving skills sharp. The crisis and its effect on the museum-going public have already forced several of the USs best-attended public collections to reappraise everything from programming, to communications, to operations. And asBrcker Wieder of Vastari sees it, in some cases this soul-searching was overdue.

I grew up in a country with a lot of hurricanes, shesays. After a hurricane, everything is chopped down. Maybe this is time for a spring cleaning in museums.

Continue reading here:
The Local Audience Is the Central Audience: As Tourism Tanks Across the US, Museums Pivot to the Visitors in Their Own Backyards - artnet News

Youve Heard Of Computer-Aided Design. What About Computer-Aided Biology? – Forbes

Virus

In the early days of the semiconductor industry, integrated circuits were designed by one or two engineers with slide-rules, hand-drawn on paper, and then given to a lithographer to print onto silicon wafers. As circuits became more complex, blueprints gave way to software. These digitally represented designs were much more than a reproduction of a pencil sketch: productivity, design quality, and communication all improved rapidly thanks to softwares ability to codify desired behaviors into actionable layouts, while also allowing for easy, iterative design improvements.

Today, large teams of engineers design circuits using high-level languages that automate the process, and chip layouts more detailed than a street map of the entire U.S. can be generated automatically. The result has been a revolution in engineering and design, manifesting itself as Moores Law and the Information Age itself.

Today, a similar revolution is happening in biology, most notably in the field of synthetic biology. And comparisons between computer-aided design (CAD) and computer-aided biology (CAB) are hardly accidental.

In recent years, automation has revolutionized how we do biology: driving down the cost of sequencing, facilitating open-source science, and pushing screening and many other processes towards higher throughput. In parallel, this trend has pushed biological experimentation into the realm of big data, where the inherent complexity of biology is finally beginning to be codified in the form of large datasets from increasingly optimized experimentation.

However, the engineering and synthetic biology world has not quite been able to harness and systematize these developments into a sustainable positive feedback loop. Single-factor experiments, such as the one described above, remain the norm because of how this automation has scaled in the form of liquid handling robots or electronic lab notebook technology, for example, but not at the foundational level of expanding and enhancing experiments to enable effective data integration and iterative design which effectively captures the multivariate complexity of biology.

Tim Fell, CEO of Synthace

It takes weeks and weeks to program robots, and its not good for a different combination of factors with a completely different experiment the next day, says Tim Fell, CEO of Synthace and member of the United Kingdoms Synthetic Biology Leadership Council. Its important to look at manufacturing holistically so we simultaneously can bring wonderfully flexible automation to inflexible hardware and enter this new frontier of computer-aided biology.

Synthace is a bioprocess-turned-software company founded in 2011, and it wants to accelerate the inevitable equivalent shift in biology by making high-throughput experiments easy and ubiquitous. For Fell, automating biology and silicon chip production, at their highest levels, are essentially the same thing.

These shifts are both about making the physical digital and the manual automated, he says. Theyre both digital tooling to help these processes along. And its digital tooling we need to leverage tools such as machine learning to unravel biological complexity faster, and with that better insight, to close loops of iterative design, he posits.

The cornerstone of Synthaces engineering biology endeavors is Antha, a cloud-based software platform for automating and improving the success rate, efficiency, and scalability of biological processes by connecting together all the hardware in a lab. Unlike most other platforms that digitize biology, Synthace still has a lab a key differentiating factor that facilitates essential validation of new workflows.

To Fell, this is the key to ensuring everything from easily tweakable out-of-the-box protocols for processes as simple as PCRs (the same technique used for COVID-19 testing) and automated data aggregation creating structured datasets for high-dimensional statistical learning to iterative multifactorial experiments and optimization of protein and gene-based bioprocessing. Our customers dont want software, he explains. They want a biological outcome that produces reliable biological outputs.

This technology is the framework of the companys two white papers: Computer-Aided Biology: The Metadata Responsibility, which highlights the crucial responsibility to define, capture, and combine metadata at the point of creation to facilitate deeper analysis downstream, and Computer-Aided Biology: Delivering biotechnology in the 21st century. This philosophy has not gone unnoticed: Synthaces major partners and customers include Merck, Oxford Biomedica, Dow, Microsoft Station B, Tecan, and Syngenta, with work ranging from vectors for CAR-T cancer therapies to optimization of liquid handling robots.

The value of such a mindset becomes apparent when considering the myriad intertwined pathways that accompany most any biological phenomena there is seldom just one protein involved. Multiple proteins and pathways need to be screened and understood against the backdrop of innumerable other cellular components. That kind of experimental design requires intense scalability and organization.

We can only do this if we codify biological experiments in an unambiguous way, akin to standards of CAD, Fell explains. To do that, you have your examples of what needs to be defined, then you build experimental blocks, and then you pass your parameter set. That gives you the structure and context to be able to use your data downstream.

Synthaces approach has gained notable traction within a variety of communities, drawing on its own team with broadly interdisciplinary skillsets to push the technology forward. Multifactoring [screening beyond just one variable] turns cynics into evangelists in one experiment, Fell remarks. Theres no going back. You need these higher-order interactions to extra true insights.

Judging by the investing team behind Synthace, many agree. Chairman of the Board Bob Widerhold, integrated circuit veteran from Bell Labs and later Cadence, is incredibly optimistic about the future of computer-aided biology. Cadence turned out to be the leader in the [integrated circuit] space and a multi-billion dollar company. I see the exact same scenario playing out 40 years later in biology with the formation of a computer-aided biology industry, and I hope to help Synthace be the Cadence of the Biology industry, he says.

Widerhold sees this change as not only inevitable but also crucial. The same shift that happened in the early '80s in the semiconductor industry, designing every aspect of a microprocessor on a computer to handle increasing complexity, needs to happen in the biology industry, he asserts. I believe this shift will usher in a period of incredible exponential progress in biology and enable biology to reach its full potential to change the world in a very positive way.

Herman Houser, Co-Founder of Amadeus Capital Partners

Hermann Hauser, co-founder of Amadeus Capital Partners with successes including acquisitions by Microsoft, Illumina, and Nvidia, emphatically agrees on biologys potential and the progress needed to make a promising future reality. Synthetic biology is the future of biology, Hauser suggests, but biology needs standardized lab procedures to produce replicable results the way microprocessors standardized instruction sets for programming. This will make it possible to program biology.

These are grand visions of where the engineering biology industry is headed next, but many moving parts will need to mature to realize these visions. Everyone has a part to play in this ecosystem, Fell declares, and ours is in experiment execution. While Synthace hopes to find enthusiastic advocates in other companies to evangelize their overarching missions, the company will continue to drive the field forward and its most basic, foundational level: automating and abstracting biology to scale experimentation into the next frontier.

Subscribe to my weekly synthetic biology newsletter. Thank you to Aishani Aatresh for additional research and reporting in this article. Im the founder of SynBioBeta, and some of the companies that I write about are sponsors of the SynBioBeta 2020 Global Synthetic Biology Summit.

Continued here:
Youve Heard Of Computer-Aided Design. What About Computer-Aided Biology? - Forbes

WhatsApp Users To Get Radical New Update: Heres Why You Need It – Forbes

getty

There was an awkward twist to last weeks news that WhatsApp users are being targeted with text bomb messagescrafted character strings that crash the app. An awkward twist for WhatsApp, that is, quite apart from the pain for impacted users. The Facebook-owned messaging platform has assured that the vulnerability is being fixed, that updates will be rolled out to users worldwide.

But its not that simplethere are two serious issues with WhatsApp, both of which make this text bomb attack more serious than it need be, both of which are reportedly being fixed, both of which will be a radical update for 2 billion WhatsApp users.

The warning about this latest spate of dangerous messages has been widely covered in the media. The coded messages throw WhatsApp into an infinite crash cycle that requires a user to delete and reinstall the app. The text strings cannot be rendered by the appit crashes each time it tries. So, as soon as you receive and open the message, its game over. The only get-out is to use something other than your smartphone to delete the message and block the sender. And here we find problem number one.

WhatsApp doesnt have an independent desktop appits just a scrape of your smartphone app. Thats why you need to keep your smartphone app connected. If your smartphone app cannot open, then the desktop app is useless. All of which means you need to realize youve been attacked with a text bomb message, and turn to your desktop app to delete it and block the sender, without using your smartphone app until thats done. Thats both inconvenient and impracticalbut its the only way.

WhatsApp now has linked devices in late-stage development. This is critical for WhatsApp as it plays catch up with the features already offered by competitors such as Signal, iMessage and even Facebook Messenger. Once released, this will mean you should be able to delete the message and block the sender and then reopen the apppushing it into the background, which should be able to sync its database without trying to render the dangerous message. Linked devices are not yet available, which means that if you throw your smartphone app into an infinite crash you have no option but to delete and reinstall the app. And that leads to problem number two.

If you want to restore your chat history and media when you reinstall WhatsApp, you need to use the cloud backup available from within the app itself. WhatsApp gives iPhone and Android users the option to send a daily, weekly, or monthly backup to Apple AAPL or Googles GOOGL respective cloud services. The problem is that those backups undermine the entire basis for WhatsApps trademark security.

WhatsApp/iOS

Were talking about end-to-end encryption, of course. This means that the key to decrypt your messages is held only by you and the person or people youre messaging. As WhatsApp itself says, some of your most personal moments are shared with WhatsApp, which is why we built end-to-end encryption into our app. When end-to-end encrypted, your messages, photos, videos, voice messages, documents, and calls are secured from falling into the wrong hands.

According to WhatsApps owner, Facebook, such encryption not only mitigates the risk of messages being intercepted in transit, but also the compromise of server and networking infrastructure, their own included. Thats somewhat ironic, given that Facebook Messenger is not currently end-to-end encrypted, except where users elect to send secret messages, albeit it plans to rectify this at some point.

All of which leads to that problemWhatsApp is end-to-end encrypted, but those cloud backups are not. Media and messages you back up, it warns iPhone users, are not protected by WhatsApp end-to-end encryption while in iCloud. The same issue impacts Android users backing up to Googles cloud. Your device hosts a decrypted messaging database, that is then backed up from your device to the cloud service, wrapped by standard (not end-to-end) encryption, nothing more than that.

Signal, the best alternative to WhatsApp, does not offer a cloud backup of any sort. Letting the data out of a users control, it says, is a material security risk and one it does not enable. Whereas a WhatsApp user transitioning to a new phone does so by way of the cloud backup, restoring to the new device, Signal offers a direct, wireless device to device transfer or a specially encrypted backup file, one that can be copied onto the new device and then used to restore the messaging history.

U.S. lawmakers are currently pushing for warranted access to encrypted messaging platforms, to enable investigators to access user content, something that is blocked when only the sender and recipient have those decryption keys. Clearly, when the data is on a cloud backup service, without that end-to-end encryption, then law enforcement and security agencies can access that data through the cloud providerApple or Googlewhen a jurisdictional warrant allows them to do so.

Just as with linked devices, WhatsApp appears to be developing an extension to its end-to-end encryption, enabling this protection to extend to these cloud backups. Until then, thoughand theres no confirmed timing on any release, users will have to make a choice between protecting their apps, in case they lose their phone or fall victim to a text bomb type attack, or to protect their data from the risk that it becomes exposed without the encryption it enjoyed when transmitted.

If the thought of exposing years of messages to potential scrutiny by others, stripping it of the encryption it enjoys in WhatsApp worries you, then perhaps you should trust that this latest text bomb issue will be patched by WhatsApp. Thats what were being told. But there was a similar issue raised by the cyber research team at Check Point last year, one that manipulated message metadata to send the app into an infinite crash in the same way, one that was apparently fixed, and yet here we are again.

As now, part of the advice to mitigate such threats is to prevent your number being added to groups by those you do not know. You can make that change within the apps privacy settings. You should limit all privacy settings to your contacts.

WhatsApp/iOS

Ive commented before that of all the new functionality reportedly coming from WhatsApp, it is linked devices and encrypted backups that trump all others for their importance. Hardly a coincidence then, that this latest issue with the so-called travazap crash code messages that originated from Brazil would highlight both those issues. WhatsApps 2 billion users need to be given these updates. And fast.

Go here to read the rest:
WhatsApp Users To Get Radical New Update: Heres Why You Need It - Forbes

WeChat is getting banned: Here are the best messaging app alternatives – CNET

Getty/SOPA Images

ByteDance's TikTok and Tencent's WeChat apps will be banned from US app stores starting Sunday, the Trump administration said Friday, as part of the president's campaign to protect American consumers and businesses from "the threats of the Chinese Communist Party," according to a statement from US Commerce Secretary Wilbur Ross.

If you've already downloaded WeChat, you can still use the messaging, social media and mobile payment app without penalty, according to a US Justice Department court filing. However, the US servers carrying your data will no longer work, so sending a message or a photo will have to go through one overseas -- meaning it will take a lot longer to send or receive anything. It's not a complete shutdown, but it'll likely make your experience much more frustrating.

Subscribe to the Mobile newsletter, receive notifications and see related stories on CNET.

While WeChat isn't a household name in the US, it's a massive social network with more than 1.2 billion monthly active users. Because it's such a widely used app, many Americans use WeChat to keep in touch with friends and family overseas -- particularly in China. People often turn to the app because it gets around pricey international fees for traditional phone calls and text messages.

Until the legal situation is sorted out, here are a few WeChat alternatives that you can switch to for your messaging needs -- many of which have a strong presence internationally. A caveat: Most of these apps, including Facebook Messenger, Line, WhatsApp and Telegram, are banned in China.

Sina Weibo -- China's equivalent to Twitter -- may be the closest you can get to a WeChat replacement in China. You can sign up for an account in the US and several other countries, too. On Weibo, you can post messages publicly or send them privately to other users (though these messages are not encrypted), and livestream videos or post short videos, similar to Instagram Stories.

The Facebook-owned WhatsApp is a chat app that lets you share messages, pictures and videos with others on the platform from your phone or desktop. You can also video chat with up to eight people. A big privacy plus to using WhatsApp is that all messages and calls are end-to-end encrypted, and Facebook says that "no one else can view or listen to your private conversation, not even WhatsApp."

WhatsApp is available in several countries and territories, including the US, Singapore, Malaysia and Hong Kong.

The Japanese-based messaging app Line offers free messaging, voice and video calls across iPhones, Androids, PCs and Macs. You can also livestream video, post videos and photos to your timeline, add photo filters, search through the daily news and, in some countries, join groups. You can also enable Line's end-to-end encryption feature, called Letter Sealing.

Telegram is a messaging app available on Android, iOS, Windows and Mac, as well as through a web browser. It recently added one-on-one video calls (which are end-to-end encrypted), and plans to roll out group video calling in the coming months. There's also a "secret chat" option for encrypted messages, too.

For more, you can read our explainer about what's been going on with TikTok in the US. You can also check out our list of the best free video chat apps.

Now playing: Watch this: TikTok expert says whoever buys it is playing with fire

15:18

See the original post:
WeChat is getting banned: Here are the best messaging app alternatives - CNET

WhatsApp: How to Protect Your Privacy and Stay Secure on the Popular Chat App – Techweez

WhatsApp is a really popular chat app they recently crossed the 2 billion user mark. The Android app also crossed the 5 billion install mark on the Google Play Store and follows in the footsteps of its owner, Facebook its the tenth app to reach that spot.

Facebook had bought it for $19 billion when it had 450 million users.

WhatsApp has had it fair share of security issues with the recent and major one that Jeff Bezos phone was hacked through an infected WhatsApp file.

The app isnt the safest among its peers such as Telegram whose founder, Pavel has openly said is dangerous to use.

For encryption, WhatsApp uses the Signal Protocol that was developed by Open Whisper Systems -an open-source software ran by entrepreneur, security researcher and cryptographer Mathew Rosenfield(he goes by the pseudonym Moxie Marlinspike)

He was a former head of the security team at Twitter.

This same protocol is used by Signal, another privacy-focused messaging app, Allo, Facebook Messenger and Skype.

Facebook cant read your WhatsApp messages thanks to this end-to-end encryption.

WhatsApp collects alot of data and this includes information users provide, information the app collects and third-party information.

Its worth stressing that WhatsApp doesnt store your messages, only the undelivered ones that are stored in their servers for up to 30 days as they try to deliver them.

Information you provide includes your account information, your messages, your connections and customer support. Information WhatsApp collects automatically include usage and log information, transactional information, device and connection information, cookies and status information.

Third-party information inlcude information other people provide about you, third-party providers and third-party services.

Facebook, the company that owns WhatsApp has come under intense scrutiny now that they intend to merge its messaging platforms between WhatsApp, Instagram messaging and Facebook Messenger.

The European Union recently fined Facebook after it told regulators that it couldnt share WhatsApp phone numbers and Facebook data and they went ahead and did it.

Cloud backups are allowed on the app and are helpful when you get a new phone and want to keep your previous chats.

The reason why youd want to disable cloud backups either on Google Drive on Android or Apple iCloud on iPhones is that these cloud services can handover your data when law enforcement request for it.

Its unclear if WhatsApp informs a user when their account is being searched its parent company Facebook lets know their account is being searched unless when theyre ordered not to.

These backups arent encrypted very well and thus your messages can easily be read.

There is no middle ground: if law enforcement is allowed to circumvent encryption, then anybody can, said Amnesty International in an open letter to Facebook.

Its worth noting that WhatsApp doesnt have open law enforcement guidelines like Facebook. WhatsApp can be ordered to install a pen device that provides metadata which WhatsApps encryption doesnt keep private. Other pen registers can collect more information such as device identifiers and IP addresses.

The metadata WhatsApp collects is enough to help federal agencies figure out the behavior of a person of interest.

Signal doesnt store any such metadata however, contact numbers are shared with Signal servers. Signal then uses hash encryption algorithms to bruteforce these hashes.

The best practise is to purge this information(metadata),said Neema Singh Guliani, legislative counsel with the American Civil Liberties Union (ACLU).

Early this year, it was revealed that WhatsApp was working on password protected backups.

Two-factor authentication is a very important feature that you should not only enable on WhatsApp but also on all your online accounts.

You can either choose text based, app based or hardware based(physical security key) 2FA methods.

SMS based is easiest to setup and more adaptable for most users.

Each time you want to verify your phone number on WhatsApp, youll be required to create a six-digit pin created with two-step verification on the app.

Simply, open WhatsApp then head to Settings>Account>Two-step verification>Enable.

You can then opt to add your email address so that WhatsApp sends you link via email to disable two step verificatuon in case you forget your PIN.

Once setup, WhatsAp will irregularly prompting you to reenter the PIN. These prompts will come in handy especially if another perosn is trying to add your number to a new device without your knowledge.

One of the first steps is to disable read receipts. Heres a handy guide on how to do that for WhatsApp and other social media apps.

Control who adds you to Groups by heading to Settings > Account & Privacy > Groups and then opt out of the Everyone option which has been enabled by default to either All of your Contacts or All of your contacts except the people youve blocked.

This ensures that people who want to add you to groups randomly will have to send you a text message for your consent.

You can also limit who sees your profile photo, about section, last seen, live location and the about section too.

Another step you can take is disable notifications for both that appear on the lockscreen or the notification shade so nobody reads the message preview without having to open the phone or the app itself.

Heres a step by step guide on how to do that.

You should do this on per app basis and not just WhatsApp only.

Heres how to protect your privacy and stay secure on:

See original here:
WhatsApp: How to Protect Your Privacy and Stay Secure on the Popular Chat App - Techweez

Miny.CC Innovation in the Cryptocurrency Mining Sphere | Press release Bitcoin News – Bitcoin News

Aberdeen, Hong Kong, September 16, 2020. More than 10 years after the first cryptocurrency was successfully mined, the mining space is more controversial than ever. The process was created to be democratic; to allow any PC with spare computing resources to contribute the surplus to help maintain the cryptocurrency network and earn rewards in return.

The prospects of the mining prize mentioned here led entrepreneurs to innovate ways to make mining more profitable. In the process, they have fabricated specialized mining devices that do not only do the activity faster, but also improves the profitability of the exercise while at it. The said changes now mean that anyone who wants to earn from Bitcoin and cryptocurrency mining must put in a colossal amount of capital to afford the expensive devices. Besides, the cost of electricity required to sustain the process is extortionate.

The incredible pace of change in the industry, notwithstanding, an innovative entrepreneur and his unique startup are prepping the industry for major changes. The individual, Thomas Norberg, is a Russian-born businessman with a vision to make Bitcoin and cryptocurrency mining more user-friendly and less costly to join.

Thomas was born in Russia. After attaining elementary education in his native country, he set sail for oversees, landing in Sweden where he enrolled for a Masters degree in International Business Management, which he completed successfully.

Upon completing his graduate studies, Thomas joined the corporate world earnestly. It was while here that he stumbled upon the novel blockchain technology. Having been in the industry for more than 8 years, he can now talk authoritatively about the successes of the space as well as the issues and challenges ailing the industry.

Thomas has seen it all, or at least most of it. He started as a crypto trader back when not many people knew about virtual currencies. Between 2016 and 2018, when initial coin offerings (ICOs) were all the rage, Thomas dived in and backed several projects with the proceeds from his trading days.

However, technology is dynamic and there is no space where this statement is truer than the blockchain industry. Watching the comings and goings of the space, it did not take Thomas long to see the folly and lopsided aspect of the industry that crypto mining had become. Baffled by the cost of hardware and the runaway power tariffs, Thomas joined hands with some entrepreneurs he came to know in the industry. Together, they came up with the idea of a cloud mining platform that has a unique yet friendly approach to the undertaking. And, the process gave forth to Miny.cc.

Miny is primarily a cryptocurrency wallet infrastructure. If a user creates an account on the platform, he or she also gets a secure cryptocurrency wallet by default. The multi-coin wallet can store Bitcoin, Ethereum, Litecoin, and MINY tokens.

However, the platforms shining star is its cloud mining plan. The plan is simple and easy to use. All a user needs to do is create an account, deposit crypto into the wallet provided and convert the virtual currency into MINY tokens. Once the platform verifies the deposit, the user will be included in the mining pool where he or she will begin getting a share of the platforms mining proceeds. Overall, the platform pays out between 10% and 19% of the amount a user invests, per month.

Aside from cloud mining, users can make money on the platform through several means. The platforms native token, MINY, for instance, is a revenue earner. The cryptocurrency is made such that for every successful transaction completed on the platform, a portion of it burns. In doing so, the platform ensures that the number of MINY tokens in circulation reduces over time.

Since the demand for the coins is set to increase over time while the amount in circulation reduces, the value of the coin, as such, will appreciate. Users who hold the coins for an extended period can exchange them for other cryptocurrencies or cash them as fiat and enjoy their profits.

Still, users who have extensive following online can cash in on this resource. The platform has an elaborate affiliate program that pays commissions for the referrals a user brings up to the 20th downline.

The above narrative shows that Thomas Norberg is in the game for more than just profits. The Russian entrepreneur and his band of associates want to make Bitcoin mining worth considering again. Besides, they want to see it become an undertaking that is environment friendly and Sustainable. This reason is why Minys mining farm is located in Hong Kong. The regions endeavor to go green makes its power cheap and attractive.

More information about Thomas Norberg and his unique project is available here.

Press Contact Email Addressinfo@miny.cc

Supporting Linkhttps://www.youtube.com/watch?v=zlocB2BEKNg

This is a press release. Readers should do their own due diligence before taking any actions related to the promoted company or any of its affiliates or services. Bitcoin.com is not responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in the press release.

Image Credits: Shutterstock, Pixabay, Wiki Commons

Read the original post:
Miny.CC Innovation in the Cryptocurrency Mining Sphere | Press release Bitcoin News - Bitcoin News

Ditching Dinars: Will the Balkans Take to Cryptocurrency? – Balkan Insight

Knowledge and experience are not enough, however. Regulations are required to ease the burden on companies working in the field, experts say.

Several companies from this area are working on top notch cryptocurrency projects: like in DeFi, second layer protocol solutions for scaling of payment networks, blockchain based protocol for tokenisation of assets, but again it is hard to keep them here, said Kamberi.

We would need proactive, positive regulation in order to ease the burden of such start-ups and IT companies.

One success story that others might try to emulate is Slovenia.

Slovenia implemented crypto friendly regulations and this boosted the industry and the use of cryptocurrencies, said Kamberi. The country now has more than a thousand places in which you can spend cryptocurrencies including major retailers like Tu or Burger King Slovenia.

Serbia also seems ready and willing to adopt a set of crypto-regulations which would address cryptocurrency trading.

Belgrade-based Electronic Currency District, ECD, is a Bitcoin exchange that launched in 2012. Since then, their service has evolved and also opened branches across the region, the company told BIRN.

We have added five new cryptocurrencies, we set up a network of Crypto ATMs in Serbia, developed application for bitcoin payments and opened branches in [North] Macedonia and Montenegro, said co-founder and CEO Aleksandar Matanovic.

Currently the greatest potential in is remittances, Matanovic told BIRN.

Remittances are probably the biggest chance for crypto to be used as money. The Balkans is a huge remittance market and sending money internationally is both faster and cheaper if you use crypto.

With a supportive regulatory framework, I really believe this industry could flourish, beneffiting not only those directly involved but also society as a whole.

Unlike Slovenia, Croatia, or Bulgaria, countries like North Macedonia are lagging behind, mostly due to the lack of any regulations whatsoever. And for those in the country looking to do business in cryptocurrency, its not straightforward.

Trading mainly works through several crypto exchanges, most often Binance, and there are no obstacles here. Profit and exchange in denars usually goes through intermediaries, EU or Bulgarian residents, said Petar Grujoski, a Skopje-based cryptocurrency enthusiast.

Until recently, Macedonian citizens were not allowed to have accounts abroad, and we still do not have PayPal and Amazon for the same reason, Grujoski told BIRN.

Cryptocurrency mining, on the other hand, can prove highly profitable in North Macedonia, not least because of cheap electricity supplies. The same applies to the rest of the region. But sometimes, when it comes to cryptocurrency mining and the rest of the infrastructure that can support the use of this technology, there are still some doubts.

Regarding the infrastructure, if we look at the mining industry, electricity is in abundance and still quite cheap in some areas, Kamberi said. But mining can be a real environmental threat and the focus should be moved away from incentivising such an industry.

Regarding the use and payments infrastructure, the Internet coverage is still an issue in some areas. Anyhow, the ability to access the cryptocurrency payment networks using mobile devices and 3G connection makes it easier for users even in the most remote parts of the region.

See original here:
Ditching Dinars: Will the Balkans Take to Cryptocurrency? - Balkan Insight

Report: Blockchain Patents ‘Skyrocket’ in 2020, Alibaba Owns the Most Crypto Patents – Bitcoin News

A study from the team at Kisspatent shows that Alibaba Group is the largest blockchain patent holder in 2020 capturing 10x the number of patents held by IBM. The report notes that blockchain patents are skyrocketing this year and so far in 2020, theres been more distributed ledger technology and cryptocurrency patents published than all of 2019.

It seems distributed ledger technology and cryptocurrency solution patents are becoming a thing again in 2020. A few years ago various reports said that Bank of America (BoA) and the firm Nchain were gobbling up all the patents applied to digital assets and blockchain technology.

Times have changed in 2020, and both companies have slid down the ranks as far as top blockchain holders are concerned this year.

Kisspatents latest study shows that Alibaba Group was the top company this year with successful blockchain patent filing and IBM jumped significantly. Alibaba Group is the top blockchain patent holder while the Chinese multinational technology company is followed by the financial institution BoA.

While Alibaba and IBM were the top two blockchain patent filing contenders in 2020, Alibaba outpaced IBM by 10x the number of patents. Moreover, this year has already seen 3 times more blockchain patents published than in 2018.

Behind IBM, is Mastercard, Nchain, and Walmart respectively in terms of blockchain patents held. The Kisspatent research noted that the list of top blockchain patent holders was not really represented by distributed ledger-specific firms.

Blockchain-only companies are not filing for patents, Fortune500 companies are, Kisspatent researcher Dr. Dvorah Graeser notes. Interestingly, the firm Nchain, the infamous company that the self-proclaimed Bitcoin inventor Craig Wright works for, is a the only pure blockchain company.

Kisspatent highlights that Nchains claims are based on numbers said in a press release, but [the number] could include many that havent published yet, plus they may be counting international applications filed in multiple countries as separate patent application filings, Graeser says.

Graesers list seems incomplete as it does not include firms like Reechain, Webank, and Tencent. Chinadaily.com shows that these three Chinese firms are top blockchain patent holders.

According to the regional publications estimates, IBM has 240 blockchain patents, Rechain 279, Webank 282, and Nchain has 402 patents total. Chinadaily.coms list shows Tencent has a significant number of distributed ledger patents with 724 to-date. Alibaba Group is still king with a whopping 1,505 blockchain patent filings.

What do you think about the top blockchain patent holders in 2020? Let us know what you think in the comments section below.

Image Credits: Shutterstock, Pixabay, Wiki Commons, Kisspatent

Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.

The rest is here:
Report: Blockchain Patents 'Skyrocket' in 2020, Alibaba Owns the Most Crypto Patents - Bitcoin News