Saturday, 8 March 2014

List Of Torrent Website

  1. kickass(dot)to

  • this site is a favorite with a growing community. The interface is a distinctive earth color, and the search results display in a useful format of columns, including torrent health. The best part of Kick Ass Torrents is their comment and feedback system... 
  • The user community watches the quality of torrents, and offers their recommendations and warnings. The adult advertising can be annoying, but Kickas(dot)to has an excellent library of torrents. 
2.extratorrents(dot)com

  • this site has a Tonga country domain name, but certainly offers plentiful metasearching of movies and music in English and Spanish. There are some popup advertisements that are annoying, but perhaps you might like the framed interface for searching other torrent sites. 


 3. yifi-torrent(dot)com

  • Yifi-torrent is THE BEST WEBSITE for HIGH  RESOLUTION Movie just like as blue-ray, 1080p, 720p. Also they contain a sub-titles for the movie.

 4. seedpeer(dot)me

  • SeedPeer is a very large database of over 3 million torrent files. The search interface is simple, and the keyword cloud map helps as a discovery means to find interesting movies, tv shows, and music artists. Fans speak very highly of SeedPeer, so do consider trying it out.
More List Comming Soon..! Get connected..!

Friday, 7 March 2014

"Girl killed herself" Facebook scam - be aware before you Share!

You know the saying about buses - you don't see one for ages, then three come along at once.
Facebook scams and hoaxes are a bit like that, except for the "you don't see one for ages" part.
But, judging by the most popular articles on Naked Security over the past couple of weeks, large-scale hoaxes and scams do sometimes come in threes.
A perfecta of long-running Facebook falsehoods has topped the charts recently.
Firstly, it was Talking Angela, the chat bot cat that was accused of all sorts ofdubious behavior - including behavior that isn't programmed into the software, couldn't have happened, yet was widely and regularly reported by people claiming "I saw it with my own eyes."
Secondly, it was the annual "Facebook will close from 29-31 February" hoax, circulated presumably as a joke but apparently taken seriously by some.
Now, it's the venerable "Girl killed herself video" bait-and-switch scam, already in its fifth year, that is making a reappearance.
→ Hoaxes and scams aren't the same, but they are similar in how they end up being shared over and over again. Generally, hoaxes are bogus warnings that spread because people forward them on the assumption that it's better to be safe than sorry. Scams are bogus links that spread because people forward them in return for some illusory benefit, such as access to an intriguing-sounding video.
We've written about the "Girl killed herself" video before, right back to 2010.
There are numerous variations on the theme, but the premise is often that a teenager committed suicide in shame after being caught out, perhaps by her own father, in some sort of inappropriate online activity.
There's a video, and you're invited to watch.
Here's how this sort of scam plays out, based on one of the versions circulating right now:
1. One of your friends Shares a link along the lines of "Girl killed herself live on cam."
2. It comes from a friend, so you click the link and arrive at a page that doesn't overtly claim to be affiliated with Facebook, but nevertheless uses visual clues to make it look more official than it is.
3. You're invited to Like the publisher's Facebook page, a request that seems routine and harmless enough:

4. If you take a look, the publisher's page was recently created and might best be described as uninspired and uninspiring, but it seems harmless enough, perhaps leading you into a false sense of safety. (Banality is a surprisingly good cover for scammers, when you think about it.)

5. You can skip past the Like popup, but before you watch the video, you are forced to Share it:
 6. And once you have shared it, you need to answer some questions as a sort of CAPTCHA - one of those tests to prove you're a person, in this case a person who's old enough to watch adult videos:
→ CAPTCHA stands for Completely Automated Procedure for Telling Computers and Humans Apart. CAPTCHAs are challenges that are meant to be reasonably easy for humans to work out, but tricky for computers to process accurately. Examples include reading fuzzy characters against a distracting background, or answering arithmetical questions written out longhand using words, not symbols.
Except that the questions to prove you are illegible are, in fact, pay-per-click surveys or special offer pages that clock up revenue for the scammers every time someone fills them in:

Thursday, 6 March 2014

Receive AdSense Payments using Wire Transfer in India

Being an Indian publisher we have to face the payments problems made by google as there are bad postal conditions and even after receiving that hard worked payment after 2 weeks in form of check we still have to deposit in the local branch to get the amount cleared in 4-5 days depending on the bank you have deposited it too. Well now earlier there were rumors that google will soon launch the another best possible method that EFT (Electronic Finds Transfer) that really fast and easy to be used.

What is EFT (Electronic Funds Transfer) or Wire Transfer

Well now you might be thinking that what is exactly Wire Transfer and why you should actually OPT in for
this feature, well Wire Transfer means getting your payments directly into your bank account, so this saves you from the bank trip to drop your check and then allow it to clear.
Well now with Wire Transfer it won’t take much long as after your payment is released by Google you will receive your payment in your bank account within 2-3 days possibly and now you do not have to think about those postal problems.
Well you have to bear few changes for this service its like Rs.56 – Rs.110 for once transfer, well that really nominal as you are bypassing all those check problem’s for GOD’s SAKE :p so see below how to apply for this feature.

How to Apply for AdSense Wire Transfer Payment Mode

Well still you do not have have any visible option to shift to this awesome feature but there is a little workaround as mentioned on this official announcement, well you need to activate the Self-Hold option before 16th of March 2014 to show AdSense that you are interested in this feature and would surely like to opt in for this feature.
  • Receive AdSense Payments using Wire Transfer in India
  • How to Add Adsense Ad in the Middle of Blogger Post
  • Requirements for becoming Premium AdSense Publisher
  • Make your AdSense Ad Units Responsive for More Clicks
  • Make AdSense Ads Load Faster with Asynchronous Loading
  • How to Change Google AdSense Account's Payee Name Easily
Well as they have said they will make this feature as default in upcoming months, but still they are not forcing everyone to opt in for this feature, so if you are really interested for this ne then you can easily activate this for free.
  1. Open AdSense Account.
  2. Now navigate to your Account Settings.
  3. Now under Payment Settings, click on edit Self-Hold.
  4. Now you need to mark HOLD Payments option and then press on Apply button.
That’s it now you have successfully completed the steps that would activate your feature within in a week or so, but make sure you do this before 16th of March 2014 as that’s the last date for changing your payment mode.

Wednesday, 5 March 2014

5 things that Computer Science Engineering students should focus on


What should students be really focusing on? Somebody asked me this question recently – Imagine students who are in 2nd or 3rd year of their degree course right now. They’ll spend a few years finishing college, and a few years just learning the ropes at their first job. So it will really be about 5 years before their career really starts. What will the software technology world be like at that time, and what are the skills that students can work on acquiring right now to ensure that they are well positioned to thrive?
Of course, 5 years is a long time, and to quote Neils Bohr, prediction is very difficult, especially about the future. Still I think some general trends are clear, and there are some other timeless skills that are worth looking at. Based on that I’m giving my list below.
Let me not bias your thoughts. Before you read my list, skip to the Comment section below, and put down your list. Then read my list and critique it again in the comments. Hopefully we can have a good discussion that will benefit students.But wait!
So, here’s my list of areas students need to be thinking about:

1. The next billion customers


The IT revolution has probably reached a billion people of the world so far. In the next 5 years, it will reach the next billion. These will be a very different set of people. Many of them will be illiterate – so you need to focus on non-text, non-English interfaces – video, animations, voice recognition. Search for “English Seekho” to get an idea of what I mean. Most won’t have money or electricity for computers, so mobile devices will rule – so you need to start playing with mobile platforms like Android. In general, search for the “the next billion” and you’ll find some interesting material put together by the likes of Nokia, and MIT giving you ideas on what to focus on.

2. Usability

As IT touches the lives of more and more people, less and less of them will be “computer savvy”, and less and less of them will view computing devices as something that needs to be learnt. Consequently, the products that will succeed, will be the ones that are easy to use. And making something easy to use is rather difficult. It is a sub-discipline of computer science, and there is a lot of theory, and a bunch of well-defined algorithms and practices you can use to make things easy to use. The whole area is called HCI (Human Computer Interaction), and UCD (User Centered Design) is a part of it. It’s an area that you must be familiar with.

3. Computer Science Fundamentals

This will never go out of fashion, and yes, when I look at students coming out of our colleges, this appears to be a rather neglected area. Far too much emphasis on specific programming languages, and specific “technologies” is a mistake. Whatever the future holds, you will be well served by knowing the basic theory of computer sciences. Learn data-structures and algorithms. If you don’t have a favourite data-structure, and an algorithm that you find beautiful, then your computer science education is incomplete. If, after seeing an algorithm, your first thought is not about the complexity of the algorithm (O(n), O(log n), etc.), then you need to hit your books again. If you’ve only learned Java and C#, and you don’t really understand pointers, heaps, stacks, you will sooner or later be at a disadvantage. Understand the basics. And while you’re at it, also learn mathematics and statistics.

4. Presentation skills:


 This is not a computer science skill, but this is one of the most important skills that computer science students are missing. You must treat presentation as equally important, or more important than your program, design, and algorithms. And you must spend as much time learning presentation (from books, in classes, and in practice) as you spent on programming languages, and computer science subjects. I’m sure you haven’t done that, hence this item in my list. You should know how to write well. Not just papers and documents, but much more importantly, emails, and blog posts, and facebook wall postings, and tweets. You must think about what the user/reader/client wants to know (instead of what you know and want to tell). And of course, you must know how to speak well. How to tell a story instead of listing some arcane facts about your work. How to leave out stuff that you find extremely interesting, but the listener doesn’t.

5. Economics:


 Scott Adams, the creator of Dilbert says: “When you have a working knowledge of economics, it’s like having a mild super power.” Basically, if you understand the fundamentals of economics, you can see and understand what drives people and technologies and success and failure a lot better than people who do not understand it. I hated the fact that I was made to study economics in IIT for my computer science course. It seemed like a complete waste of my time. Now, looking back, I think it was probably the most important course.

Five Tips for Entrepreneurs



Maybe you’ve been dreaming since childhood that one day you would invent something amazing and start your own company. Or you taught yourself code as a teenager, all the while scheming to build the next great web property. Or you’re a secret risk-taker, trapped in a corporate day job — and now you’ve got a chance to start that business you’ve always imagined.
I know you. I’ve met you. In fact — I am you. We’re entrepreneurs.
As someone who has launched five companies, I’ve learned a few things over the years. And like other successful entrepreneurs, I love to encourage and mentor rising startup stars.
So here are my five tips for you — the dreamers, the coders, the risk-takers.

Tip #1

We live in an intense and ever-changing era. Markets have crashed. Jobs have disappeared. Industries have been disrupted and are being remade.
But if you’re an entrepreneur, to a large extent your destiny is in your own hands.
And in the new economy you can achieve financial independence on your own terms. You have the power to be as successful, perhaps even wealthy, as you want to be. This is a key insight for any entrepreneur, and a driving force in my own life. Owning my destiny, particularly my financial destiny, is scary at times — but it’s also empowering. Use the fear to power yourself to new heights.

Tip #2

If you’re a new startup or small business it can be difficult to see why you should invest in your brand and reputation.
It’s expensive and time-consuming. You’re not trying to battle with the big brands — yet. But what about the future? You must keep your eye on that future because, ultimately, reputation is everything in business. Your brand is the shorthand way people think about you.
Yes, you’ll have to miss dance recitals and soccer games. Yes, you’ll lose out on a social life. But if you don’t pay attention to the details — customer service, how you are perceived by the outside world, how your company’s image is perceived — you won’t be successful. Why? Because business success comes from returning customers.

Tip #3

We always teach our kids not to be afraid to fail and to pick themselves up and try again. They can’t know all the answers before they start learning, and neither can you. So listen to your own advice. Don’t be a perfectionist when beginning your adventure in entrepreneurship.

Tip #4

Later on, once you’re established, indulge your perfectionism in your product and customer service. But in the beginning, it’s cheaper and better to try, then try again and again until you get the product right.

Tip #5

Take a risk and just do it.
And also love it. The word “passion” is sometimes overused in business, but when it comes to entrepreneurship, it’s a necessity. You must be passionate about what you build because you will spend most of your time working. That’s the reality of starting and owning a business. It’s also the joy.
Millions of people have listened to Steve Jobs’ 2005 commencement speech at Stanford, and for good reason. He nailed the passion issue: “You’ve got to find what you love… Your work is going to fill a large part of your life, and the only way to be truly satisfied is to do what you believe is great work. And the only way to do great work is to love what you do. If you haven’t found it yet, keep looking. Don’t settle.”
And that’s my most important advice to you: Do it. Love it. Don’t settle for less.

Saturday, 3 August 2013

5 Physical security tips for protecting your Devices





As we read earlier this week, the chances that one or more of your digital devices may get stolen are uncomfortably high. So what would happen if your mobile device falls into the wrong hands? Here are a few tips that will help minimize the damage if it happens to you.

1. Password-protect your computing devices.


While it sounds obvious, if anyone steals your device they will have to defeat your password to get at your data and accounts, which will significantly slow attackers. Although it is not impossible to defeat password protection on a digital device, it adds a useful layer of protection, buying you time to locate and recover the device.

2. Always backup your files.


Why? Even if you can’t recover a stolen device that does not mean you have to lose all your information and software. Regular backups are the ultimate defense against theft of your files. There are plenty of options for backup these days including online backup. (Here’s an example of an online backup service.)

My colleague David Harley has written about backup here on the blog and here is a link to Aryeh Goretsky’s white paper on the subject (.pdf). Taking the time to setup backup really pays off if a device is stolen, helping reduce the pain involved in re-creating the sensitive content.

3. Use tracking software to help get your stolen device back.


Why? Getting your stolen device back is not impossible, particularly if the device itself can tell you where it is and you can communicate with it using a sort of “remote control” via SMS or other methods. You may even be able to communicate with the person who has it. (Here’s an example of how one piece of anti-theft software for PCs.)

4. Don’t tempt thieves with unattended mobile devices, particularly in public places.


Why? Leaving your computer or mobile device unattended in a car, airport or restaurant is akin to asking for it to be stolen. In a recent survey we found that 1 in 5 stolen devices were taken from a car, 12% from an airport, train, bus, or other public transportation, and 11% from a restaurant or coffee shop. (Here’s an example of anti-theft software for Android devices.)

5. Encrypt sensitive data.


Why? Storing sensitive data in encrypted files prevents anyone exploiting your data if your computer is stolen. Note: File encryption is available free on recent version of both the Microsoft Windows and apple Mac OS X operating systems. This step is a lot easier than it used to be, so the pain level is low these days (unlike in years past).
Bonus tip. 

Think about removing sensitive data from your device.


Why? Your computer may interact with sensitive data but it does not need to store all of it right there in one place. Consider using encrypted removable media for sensitive data and carrying that separate from the computer. Maybe leave sensitive work files on the company network and access remotely over a secure connection. This way, if “bad things” happen, you’ll have much lower likelihood that the bad actors got off with critical information.

Tuesday, 30 July 2013

Fasrt secure Protocol


Aspera's fasp transfer technology is an innovative software that eliminates the fundamental bottlenecks of conventional file transfer technologies such as FTP, HTTP, and Windows CIFS, and dramatically speeds transfers over public and private IP networks.

The approach achieves perfect throughput efficiency, independent of the latency of the path and robust to packet losses. In addition, users have extra-ordinary control over individual transfer rates and bandwidth sharing, and full visibility into bandwidth utilization. File transfer times can be guaranteed, regardless of the distance of the endpoints or the dynamic conditions of the network, including even transfers over satellite, wireless, and inherently long distance and unreliable international links. Complete security is built-in, including secure endpoint authentication, on-the-fly data encryption, and integrity verification

In this digital world, fast and reliable movement of digital data, including massive sizes over global distances, is becoming vital business success across virtually every industry. The Transmission Control Protocol(TCP) that has traditionally been the engine of this data movement, however has inherent bottlenecks in performance(fig 1), especially for networks with high round-trip time and packet loss, and most pronounced on high-bandwidth networks. It is well understood that these inherent “soft” bottlenecks are caused by TCP’s Additive. Increase Multiplicative Decrease(AIMD) congestion avoidance algorithm, which slowly probes the available bandwidth of the network, increasing the transmission rate until packet loss is detected and then exponentially reducing the transmission rate.

However, it is less understood that other sources of packet losses due to physical network media, not associated with network congestion equally reduce the transmission rate. In fact, TCP AIMD itself creates losses, and equally contributes to the bottleneck. In ramping up the transmission rate until loss occurs, AIMD inherently overdrives the available bandwidth. In some cases, this self-induced loss actually surpasses loss from other causes (E.g. Physical media) and turns a loss free communication “channel” into an unreliable “channel” with an unpredictable loss ratio. The loss-based congestion control in TCP AIMD has a deadly impact on throughput: Every packet loss leads to retransmission, and stalls the delivery of data to the receiving application until retransmission occurs. This can slow the performance of any network application but is fundamentally flawed for reliable transmission of large “bulk” data, for example file transfer, which does not require in-order (byte-stream delivery).

Shortcomings of TCP Transfer



Transferring large data sets—big files, big collections of files—via inexpensive IP networks, instead of shipping tapes, discs, or film, promises to change fundamentally the economics of content production, distribution, and management. Under ideal conditions, data may be moved quickly and inexpensively using ordinary file transfer methods such as FTP, HTTP, and Windows CIFS copy. However, on real wide-area and high-speed network paths these methods' throughput collapses, failing to use more than a small fraction of available capacity. This is a consequence of the design of TCP, the underlying protocol they all rely on. New TCP stacks and new network acceleration devices are marketed to help, but they fail to fully utilize many typical wide-area network paths. Consequently, conventional FTP, and even new "acceleration" solutions, cannot provide the speed and predictability needed for global file transfers.

 

The TCP bottleneck in file transfer


The transmission control protocol (TCP) that provides reliable data delivery for conventional file transfer protocols has an inherent throughput bottleneck that becomes more severe with increased packet loss and latency. The bar graph shows the maximum throughput achievable under various packet loss and network latency conditions on an OC-3 (155 Mbps) link for file transfer technologies that use TCP (shown in yellow). Transmission rates are defined by rate of the bitstream of the digital signal and are designated by hyphenation of the acronym OC and an integer value of the multiple of the basic unit of rate, e.g., OC-48. The base unit is 51.84 Mbit/s. Thus, the speed of optical-carrier-classified lines labeled as OC-n is n × 51.84 Mbit/s. The throughput has a hard theoretical limit that depends only on the network round-trip time (RTT) and the packet loss. Note that adding more bandwidth does not change the effective throughput. File transfer speeds do not improve and expensive bandwidth is underutilized. OC-3 is a network line with transmission speed of up to 155.52 Mbit/s (payload: 148.608 Mbit/s; overhead: 6.912 Mbit/s, including path overhead) using fiber optics. Depending on the system OC-3 is also known as STS-3 (electrical level) and STM-1 (SDH).

Consequences

TCP file transfers are slow and bandwidth utilization of single file transfers is poor. In local or campus area networks, where packet loss and latency are small but non-negligible (0.1%/10ms), the maximum TCP throughput is 50 Mbps. Typical file transfer rates are lower, 20-40 Mbps (with TCP stack tuning on the endpoints) on gigabit ethernet. Because standard TCP halves its throughput in response to a single packet loss event, at high speeds, even a low loss percentage significantly lowers TCP throughput. Even with an abundance of bandwidth, transfer times are disappointing and expensive bandwidth is underutilized. The bandwidth utilization problem compounds on wide area links where increased network latency combines with packet loss.

A typical FTP transfer across the United States has a maximum theoretical limit of 1.7 megabits per second (Mbps), the maximum throughput of a single TCP stream for 90ms latency and 1% loss, independent of link bandwidth. On typical intercontinental links or satellite networks, the effective file transfer throughput may be as low as 0.1% to 10% of available bandwidth. On a typical global link (3%/150ms), maximum TCP throughput degrades to 500-600 kilobits per second, 5% of a 10 Mbps link. Sometimes network engineers attempt to improve the throughput by "tuning" the operating system parameters used by the TCP networking stack on the file transfer endpoints or applying a TCP acceleration device.

While this technique boosts throughput on clean networks, the improvement vanishes when real packet loss due to channel characteristics or network congestion increases. TCP file transfers over difficult networks (with high packet loss or variable latency) are extremely slow and unreliable. TCP does not distinguish packet losses due to network congestion from normal latency variations or bit errors on some physical channels such as satellite links and wireless LANs, and severely self-throttles. FTP throughput over good satellite conditions is 100 kbps and degrades by more than half during high error periods such as rain fade. Large transfers can be extremely slow and may not complete. TCP file transfer rates and times are unpredictable. As a window-based protocol, TCP can only determine its optimal rate through feedback from the network.

TCP overdrives the network until packets are dropped by intervening routers, and in the best case, oscillates around its optimal rate, causing instabilities in the network for file transfer and other applications. Over commodity Internet links where traffic loads vary, file transfer rates may vary widely with network load. File transfers slow down and may exceed the allotted time window,. TCP acceleration devices may improve throughput and smooth the transfer rate when links are clean, but are also window-based and subject to unpredictable back off.


Complete Security

The fasp protocol provides complete built-in security without compromising transfer speed. The security model, based solely on open standards cryptography, consists of secure authentication of the transfer endpoints using the standard secure shell (SSH), on-the-fly data encryption using strong cryptography (AES-128) for privacy of the transferred data, and an integrity verification per data block, to safeguard against man-in-the-middle and anonymous UDP attacks. The transfer preserves the native file system access control attributes between all supported operating systems, and is highly efficient: With encryption enabled, fasp achieves WAN file transfers of 40-80 Mbps on a laptop computer; 100-150 Mbps on a P4 or equivalent single processor machine; and 200-400 Mbps+ on dual-processor or duo-core workstations.

 Secure endpoint authentication


Each transfer session begins with the transfer endpoints performing a mutual authentication over a secure, encrypted channel, using SSH ("standard secure shell"). SSH authentication provides both interactive password login and public-key modes. Once SSH authentication has completed, the fasp transfer endpoints generate random cryptographic keys to use for bulk data encryption, and exchange them over the secure SSH channel. These keys are not written to disk, and are discarded at the end of the transfer session.

On-the-fly data encryption.


Using the exchanged keys, each data block is encrypted on-the-fly before it goes on the wire. fasp uses a 128-bit AES cipher, re-initialized throughout the duration of the transfer using a standard CFB (cipher feedback) mode with a unique, secret nonce (or "initialization vector") for each block. CFB protects against all standard attacks based on sampling of encrypted data during long-running transfers.

Integrity verification.


fasp accumulates a cryptographic hashed checksum, also using 128-bit AES, for each datagram. The resulting message digest is appended to the secure datagram before it goes on the wire, and checked at the receiver to verify message integrity. This protects against both man-in-the-middle and re-play attacks, and also against anonymous UDP denial-of-service attacks.

 

fasp vs. FTP on gigabit metropolitan and wide area networks


Conventional TCP file transfer technologies such as FTP dramatically reduce the data rate in response to any packet loss, and cannot maintain long-term throughputs at the capacity of high-speed links. For example, the maximum theoretical throughput for TCP-based file transfer under metropolitan area network conditions (0.1% packet loss and 10 ms RTT) is 50 megabits per second (Mbps), regardless of bandwidth. The effective FTP throughput is even less (22 Mbps). In contrast, fasp achieves 100% utilization of high-speed links with a single transfer stream.

Monday, 29 July 2013

Google File System


The great success of Google Inc. is attributed not only to its efficient search algorithm, but also to the underlying commodity hardware and, thus the file system.

As the number of applications run by Google increased massively, Google’s goal became to build a vast storage network out of inexpensive commodity hardware. Google created its own file system, named as Google File System.

Google File System was innovatively created by Google engineers and ready for production in record time in a span of one year in 2003, which speeded Google’s market thereafter. Google File system is the largest file system in operation.

Formally, Google File System (GFS) is a scalable distributed file system for large distributed data intensive applications. In the design phase of GFS, points which were given stress includes component failures are the norm rather than the exception, files are huge in the order of MB & TB and files are mutated by appending data. The entire file system is organized hierarchically in directories and identified by pathnames.

The architecture comprises of a single master, multiple chunk servers and multiple clients. Files are divided into chunks, which is the key design parameter. Google File System also uses leases and mutation order in their design to achieve consistency and atomicity. As of fault tolerance, GFS is highly available, replicas of chunk servers and master exists.


Assumptions


In designing a file system for Google’s needs, they have been guided by assumptions that offer both challenges and opportunities.

• The system is built from many inexpensive commodity components that often fail. It must constantly monitor itself and detect, tolerate, and recover promptly from component failures on a routine basis.

• The system stores a modest number of large files. Usually a few million files, each typically 100 MB or larger in size. Multi-GB files are the common case and should be managed efficiently. Small files must be supported, but need not optimize for them.

• The workloads primarily consist of two kinds of reads: large streaming reads and small random reads. In large streaming reads, individual operations typically read hundreds of KBs, more commonly 1 MB or more. Successive operations from the same client often read through a contiguous region of a file. A small random read typically reads a few KBs at some arbitrary offset. Performance-conscious applications often batch and sort their small reads to advance steadily through the file rather than go back and forth.

• The workloads also have many large, sequential writes that append data to files. Typical operation sizes are similar to those for reads. Once written, files are seldom modified again. Small writes at arbitrary positions in a file are supported but do not have to be efficient.

• The system must efficiently implement well-defined semantics for multiple clients that concurrently append to the same file. The files are often used as producer consumer queues or for many-way merging. Hundreds of producers, running one per machine, will concurrently append to a file. Atomicity with minimal synchronization overhead is essential. The file may be read later, or a consumer may be reading through the file simultaneously.

• High sustained bandwidth is more important than low latency. Most of the target applications place a premium on processing data in bulk at a high rate, while few have stringent response time requirements for an individual read or write


Google File System Architecture

A GFS cluster consists of a single master and multiple chunkservers and is accessed by multiple clients. The basic analogy of GFS is master maintains the metadata; client contacts the master and retrieves the metadata about chunks that are stored in chunkservers; next time, client directly contacts the chunkservers. Figure 1 describes these steps more clearly.



Each of these is typically a commodity Linux machine running a user-level server process. Files are divided into fixed-size chunks. Each chunk is identified by an immutable and globally unique 64 bit chunk handle assigned by the master at the time of chunk creation. Chunkservers store chunks on local disks as Linux files and read or write chunk data specified by a chunk handle and byte range. For reliability, each chunk is replicated on multiple chunkservers. By default, three replicas are stored, though users can designate different replication levels for different regions of the file namespace. The master maintains all file system metadata. This includes the namespace, access control information, the mapping from files to chunks, and the current locations of chunks. It also controls system-wide activities such as chunk lease management, garbage collection of orphaned chunks, and chunk migration between chunkservers.

The master periodically communicates with each chunkserver in HeartBeat messages to give it instructions and collect its state. GFS client code linked into each application implements the file system API and communicates with the master and chunkservers to read or write data on behalf of the application. Clients interact with the master for metadata operations, but all data-bearing communication goes directly to the chunkservers. Neither the client nor the chunkserver caches file data. Client caches offer little benefit because most applications stream through huge files or have working sets too large to be cached.

Not having them simplifies the client and the overall system by eliminating cache coherence issues. (Clients do cache metadata, however.) Chunkservers need not cache file data because chunks are stored as local files and so Linux’s buffer cache already keeps frequently accessed data in memory. Before going into basic distributed file system operations like read, write, we will discuss the concept of chunks, metadata, master, and will also describe how master and chunkservers communicates.

Leases and Mutation:

mutation is an operation that changes the contents or metadata of a chunk such as a write or an append operation. Each mutation is performed at all the chunk’s replicas. Leases are used to maintain a consistent mutation order across replicas. The master grants a chunk lease to one of the replicas, which we call the primary. The primary picks a serial order for all mutations to the chunk. All replicas follow this order when applying mutations. Thus, the global mutation order is defined first by the lease grant order chosen by the master, and within a lease by the serial numbers assigned by the primary.

The lease mechanism is designed to minimize management overhead at the master. A lease has an initial timeout of 60 seconds. However, as long as the chunk is being mutated, the primary can request and typically receive extensions from the master indefinitely. These extension requests and grants are piggybacked on the HeartBeat messages regularly exchanged between the master and all chunkservers. The master may sometimes try to revoke a lease before it expires (e.g., when the master wants to disable mutations on a file that is being renamed). Even if the master loses communication with a primary, it can safely grant a new lease to another replica after the old lease expires.

Write algorithm is similar to Read algorithm, in terms of contacts between client, master, and chunkservers. Google keeps at least three replicas of each chunks, so in Read, we just read from one of the chunkservers, but in case of Write, it has to write in all three chunkservers, this is the main difference between read and write.

Following is the algorithm with related figures for the Write operation.

1. Application originates the request

2. GFS client translates request from (filename, data) -> (filename, chunk index), and sends it to master

3. Master responds with chunk handle and (primary + secondary) replica locations

4. Client pushes write data to all locations. Data is stored in chunkservers’ internal buffers

Conclusion

data processing workloads on commodity hardware. While some design decisions are specific to the unique setting, many may apply to data processing tasks of a similar magnitude and cost consciousness. Google started work on GFS by reexamining traditional file system assumptions in light of current and anticipated application workloads and technological environment. We treat component failures as the norm rather than the exception, optimize for huge files that are mostly appended to (perhaps concurrently) and then read (usually sequentially), and both extend and relax the standard file system interface to improve the overall system.

The system provides fault tolerance by constant monitoring, replicating crucial data, and fast and automatic recovery. Chunk replication allows us to tolerate chunkserver failures. The frequency of these failures motivated a novel online repair mechanism that regularly and transparently repairs the damage and compensates for lost replicas as soon as possible. Additionally, check summing is used to detect data corruption at the disk or IDE subsystem level, which becomes all too common given the number of disks in the system. The design delivers high aggregate throughput to many concurrent readers and writers performing a variety of tasks.

This is achieved by separating file system control, which passes through the master, from data transfer, which passes directly between chunkservers and clients. Master involvement in common operations is minimized by a large chunk size and by chunk leases, which delegates authority to primary replicas in data mutations. This makes possible a simple, centralized master that does not become a bottleneck. GFS has successfully met the storage needs and is widely used within Google as the storage platform for research and development as well as production data processing. It is an important tool that enables Google to continue to innovate and attack problems on the scale of the entire web.

Browser Security



The initial design of internet and web protocols assumed an environment where servers, clients, and routers cooperate and follow standard protocols except for unintentional errors.

However, as the amount sensitivity of usage increased, concerns about security, fraud and attacks became important. In particular, since currently internet access is widely available, it is very easy for attackers to obtain many client (and even host) connections and addresses, and use them to launch different attacks, both on the networking itself and on other hosts and clients.

Today's attackers are more likely to host their malicious files on the web. They may even update those files constantly using automated tools. When you are surfing the Internet, it is easy to visit sites you think are safe but are not. These sites can introduce malware when you click the site itself, when you download a file from the site manually and install it, or worse,

when you are conned into believing the site you are visiting is a real site, but in fact is nothing more than a fake used to garner your personal information. From a network security perspective, a browser is essentially a somewhat controlled hole in your organization’s firewall that leads to the heart of

what it is you are trying to protect.

While browser designers do try to limit what attackers can do from within a browser, much of the security relies far too heavily on the browser user, who often has other interests besides security. There are limits to what a browser developer can compensate for, and browser users will not always accept the constraints of security that a browser establishes.


Open Browser Engineering Issues


Other than the general design of HTTP, HTML, and related mechanisms discussed previously, a handful of browser engineering decisions tend to contribute to a disproportional of day-to-day security woes.

Understanding these properties is sometimes important for properly assessing the likelihood and maximum impact of security breaches, and hence determining the safety of user data. Some of the pivotal, open-ended issues include:


 Relatively unsafe core programming languages:
C++ is used for a majority of code in Internet Explorer, Firefox, Safari, Opera, and Chrome; C is used in certain highperformance or low-level areas, such as image manipulation libraries.

The choice of C and C++ means that browsers are regularly plagued by memory management and integer overflow problems, despite considerable ongoing audit efforts.

 No security compartmentalization:
once control of the process is seized due to common implementation flaws, most browsers provide essentially unconstrained access to the user context they are running in. This means that browser bugs - historically, very common - easily lead to total system integrity loss.

 Inconsistent and haphazard data storage practices:
browsers use a mix of random storage methods to keep temporary files, downloads, configuration data, and sensitive records such as passwords, browsing history, saved cookies, or cache entries. These methods include system registry, database container files, drop-off directories, text-based configs (CSV, INI, tab-delimited, XML), and proprietary binary files.

The data may be stored in user home directories, system-wide temporary directories, or global program installation folders. Controlling the permissions on all these resources and manipulating them securely is relatively difficult, contributing to many problems, particularly in multi-user systems, or when multiple browsers are used by the same user.

 Web technologies are used in browser chrome:
JavaScript, HTML, and XML are all used to a varying degree to implement some browser internals and various diagnostic and error pages in most browsers. This choice contributes to an elevated risk of HTML injection flaws that permit web content to gain elevated chrome privileges, which - depending on the browser - may carry the permission to read or write files, access arbitrary sites on the Internet, or alter browser settings. The problem is particularly pronounced for Firefox, which implements much of its user interface in this manner.

 Inconsistent and overly complex security UIs:
a vast majority of browsers employ highly inconsistent UI elements and security messaging, including several styles of modal prompts, interstitials, icons, color codes, and messages that pop up either on the bottom or on the top of the document window. Usability studies consistently show that at least some of these features are easily misidentified, misunderstood, or trivial to spoof (this is particularly the case for interstitials and notification bars that are not anchored in browser UI). Although a gradual improvement may be observed in certain aspects, further coordinated work in this area seems to be necessary.



Phishing Techniques


 Link manipulation :
Most methods of phishing use some form of technical deception designed to make a link in an e-mail (and the spoofed website it leads to) appear to belong to the spoofed organization. Misspelled URLs or the use of subdomains are common tricks used by phishers. In the following example URL, http://www.yourbank.example.com/, it appears as though the URL will take you to the example section of the yourbank website; actually this URL points to the "yourbank" (i.e. phishing) section of the example website.

Another common trick is to make the anchor text for a link appear to be valid, when the link actually goes to the phishers' site. The following example link, http://en.wikipedia.org/wiki/Genuine, appears to take you to an article entitled "Genuine"; clicking on it will in fact take you to the article entitled "Deception". In the lower left hand corner of most browsers you can preview and verify where the link is going to take you.

 Filter evasion:
Phishers have used images instead of text to make it harder for antiphishing filters to detect text commonly used in phishing e-mails.

 Phone phishing: Not all phishing attacks require a fake website. Messages that claimed to be from a bank told users to dial a phone number regarding problems with their bank accounts. Once the phone number (owned by the phisher, and provided by a Voice over IP service) was dialed, prompts told users to enter their account numbers and PIN.

Vishing (voice phishing) sometimes uses fake caller-ID data to give the appearance that calls come from a trusted organization.

 Website forgery:
Once a victim visits the phishing website the deception is not over. Some phishing scams use JavaScript commands in order to alter the address bar. This is done either by placing a picture of a legitimate URL over the address bar, or by closing the original address bar and opening a new one with the legitimate URL.
How Do We Know?

 Phishers, pretending to be legitimate companies, may use email to request personal information and direct recipients to respond through malicious web sites
/
 Phishers tend to use emotional language using scare tactics or urgent requests to entice recipients
to respond

 The phish sites can look remarkably like legitimate sites because they tend to use the copyrighted images from legitimate sites

 Requests for confidential information via email or Instant Message tend to not be legitimate

 Fraudulent messages are often not personalized and may share similar properties like details in the header and footer

What a Browser Designer should do?

Proactive and reactive developers can generate an endless series of software updates. As a responsible defender, your dilemma is that allowing these updates in to your users without testing may break applications or even introduce security holes, but not allowing them may leave your enterprise open to even more serious attacks. Distributed management provides some help in this area, but all major browsers are weaker than many defenders would like them to be. Microsoft provides the free Internet Explorer Administration Kit, which sets the bar for enterprise browser deployment and management tools, but that bar is lower than many would care for.


FirefoxADM, an open source project for managing collections of Firefox browsers, is far more limited but a step in the right direction. FrontMotion provides a Webbased tool that allows a defender to create packages with approved software, configuration, and plug-ins for Firefox. All are available for Windows platforms only. Firefox and Google's Chrome browser have implemented sandboxes, in which the browser runs code (such as JavaScript or Flash) in a compartmentalized area of the  Program that provides only limited resources for the program and whose design is heavily scrutinized for security flaws. Internet Explorer uses a zone-based security model, in which security features are enabled or disabled depending on the site being accessed.


Under Vista, Internet Explorer runs in what is known as Protected Mode, which limits the operating-system privileges the browser program can exercise. Open source developers especially must be very careful about designing and implementing sandbox systems, because their sandbox source code is available to the attacker for study and testing. This is, of course, no surprise to the sandbox developers and one reason why open source sandboxes tend to improve quickly.
Conclusion
Browsers are at the heart of the Internet experience, and as such they are also at the heart of many of the security problems that plague users and developers alike. As the sensitivity of internet usage increased concerns about security, fraud and attacks became important. There are limits to what a browser developer can compensate for, and browser users will not always accept the constraints of security that a browser establishes. Attack and defense strategies are coevolving, as are the use and threat models. As always, anybody can break into anything if they have sufficient skill, motivation and opportunity. The job of browser developers, network administrators, and browser users is to modulate those three quantities to minimize the number of successful attacks.




























































Mind Reader Computer



Definition of Mind-Reading Computer

Drawing inspiration from psychology, computer vision and machine learning, the team in the Computer Laboratory at the University of Cambridge has developed mind-reading machines - computers that implement a computational model of mind-reading to infer mental states of people from their facial signals.

The goal is to enhance human-computer interaction through empathic responses, to improve the productivity of the user and to enable applications to initiate interactions with and on behalf of the user, without waiting for explicit input from that user. There are difficult challenges:

Using a digital video camera, the mind-reading computer ppt system analyzes a person's facial expressions in real time and infers that person's underlying mental state, such as whether he or she is agreeing or disagreeing, interested or bored, thinking or confused.

Prior knowledge of how particular mental states are expressed in the face is combined with analysis of facial expressions and head gestures occurring in real time. The model represents these at different granularities, starting with face and head movements and building those in time and in space to form a clearer model of what mental state is being represented.

Software from Nevenvision identifies 24 feature points on the face and tracks them in real time. Movement, shape and colour are then analyzed to identify gestures like a smile or eyebrows being raised. Combinations of these occurring over time indicate mental states. For example, a combination of a head nod, with a smile and eyebrows raised might mean interest.

The relationship between observable head and facial displays and the corresponding hidden mental states over time is modeled using Dynamic Bayesian Networks.


Why mind reading?

The mind-reading computer system presents information about your mental state as easily as a keyboard and mouse present text and commands. Imagine a future where we are surrounded with mobile phones, cars and online services that can read our minds and react to our moods.

How would that change our use of technology and our lives? We are working with a major car manufacturer to implement this system in cars to detect driver mental states such as drowsiness, distraction and anger.

Current projects in Cambridge are considering further inputs such as body posture and gestures to improve the inference. We can then use the same models to control the animation of cartoon avatars.

We are also looking at the use of mind-reading to support on-line shopping and learning systems.
The mind-reading computer system may also be used to monitor and suggest improvements in human- human interaction.

The Affective Computing Group at the MIT Media Laboratory is developing an emotional-social intelligence prosthesis that explores new technologies to augment and improve people's social interactions and communication skills.

How does it work?
Futuristic headband

The mind reading actually involves measuring the volume and oxygen level of the blood around the subject's brain, using technology called functional near-infrared spectroscopy (fNIRS).

The user wears a sort of futuristic headband that sends light in that spectrum into the tissues of the head where it is absorbed by active, blood-filled tissues. The headband then measures how much light was not absorbed, letting the computer gauge the metabolic demands that the brain is making.


The results are often compared to an MRI, but can be gathered with lightweight, non-invasive equipment .


Wearing the fNIRS sensor, experimental subjects were asked to count the number of squares on a rotating onscreen cube and to perform other tasks. The subjects were then asked to rate the difficulty of the tasks, and their ratings agreed with the work intensity detected by the fNIRS system up to 83 percent of the time.