Monday, August 19, 2013

Recent news of today in the Washington Post reveals what happened in the Facebook world by an unemployed web developer.


I guess we better watch those web developers. Maybe Zuckerburg will hire this guy since he knows how to hack his Facebook page.



An unemployed Palestinian developer named Khalil Shreateh tried several times to report a bug to Facebook’s security team. When no one got back to him, he took the (dubiously) logical next step: exploited the bug to leave a public comment on Facebook CEO Mark Zuckerberg’s wall.

“First sorry for breaking your privacy and post to your wall,” an apparent screenshot of the hack reads. “I has [sic] no other choice to make after all the reports i sent to Facebook team.”

The break-in, detailed on Shreateh’s blog (and in several agitated posts from Facebook developers on Hacker News), has been more than a little embarrassing for Facebook.

But it’s not exactly newsworthy that Shreateh found a bug — that happens all the time. In fact, Facebook runs a program that encourages white hat hackers to find and report bugs in Facebook infrastructure in exchange for a cash reward. What is unusual is that Facebook didn’t respond to Shreateh’s initial reports about the bug, and that Shreateh then exploited it in violation of Facebook’s policies for white hat hackers.

“The more important issue here is with how the bug was demonstrated using the accounts of real people without their permission,” insisted Matt Jones, a Facebook software engineer, on the forum Hacker News. “Exploiting bugs to impact real users is not acceptable behavior for a white hat.”

So why didn’t Facebook respond right away to Shreateh’s reports? Judging by the e-mail threads with Facebook’s security team that Shreateh posted on his blog, it looks like his bug was lost — iterally — in translation. Shreateh’s English is a little shaky, and the Facebook developer he corresponded with doesn’t seem to understand the report:
Rhe vulnerability allow’s facebook users to share posts to non friends facebook users , i made a post to sarah.goodin timeline and i got success post … of course you may cant see the link because sarah’s timeline friends posts shares only with her friends , you need to be a friend of her to see that post or you can use your own authority .
“I am sorry this is not a bug,” a Facebook employee reportedly fired back.
On Hacker News, Jones explains that they often get reports from “people whose English isn’t great,” and that usually “it’s something we work with just fine.” According to Facebook’s own reports, the company relies heavily on international white hat hackers to keep its system secure — of the 329 legitimate bugs reported by white hats in the past two years, more than 260 came from outside the U.S.

The network joins several other tech companies, including GoogleMicrosoftPayPal and Mozilla, that pay bounties to white hat hackers and rely on them to help keep systems secure.
Shreateh reports he will not, however, receive a bounty for his work — per an e-mail from Facebook, he violated the terms of the program when he hacked Zuckerberg’s account. That has enraged some in the security community, who argue Shreateh exposed an important vulnerability in good faith, using the only means available. The bug has since been fixed, according to Jones’s Hacker News post.
“I can talk hours and hours about facebook security team and their secure style, that may take them down by hackers, that mean iam [sic] not a bad hacker and i never been,” Shreateh posted on his Facebook Sunday night. His current Facebook avatar is a photo of Edward Snowden. “You should know that iam not a hacker.”
 https://www.blogger.com/blogger.g?blogID=1773196631461301668#editor/target=post;postID=7059459557628954228

Thursday, August 15, 2013




SAN FRANCISCO, CA--(Marketwired - Aug 15, 2013) - Cloudwords, the market-leading cloud-based translation management application, today announced the launch of the CloudwordsDeveloper Center, a new developer-centric destination designed to enable easy integration between content management systems (CMS) and the Cloudwords platform. To meet the ever-increasing demand for localized content, Cloudwords is providing new integration capabilities to accelerate the process of multilingual content management by enabling developers to integrate with all major CMS platforms, including Drupal, Adobe CQ, Microsoft Sharepoint, Oracle UCM, and SiteCore, among others.

The Cloudwords Translation Management Automation solution helps companies expand their global presence faster, more easily and with enterprise-class quality. With today's announcement, Cloudwords becomes the most developer-friendly cloud-based translation management solution geared specifically for the enterprise.

"Cloudwords continues to deliver innovations that enable our customers to stay one step ahead when it comes to going to market globally. The Cloudwords Developer Center underscores our commitment to making it even easier and faster for enterprises to manage large amounts of content that need to be translated. By simplifying the integration process behind the scenes, customers can get up and running in the Cloudwords platform even faster, and take advantage of the simplicity of moving content in and out of critical content systems, ultimately delivering increased ROI," said Scott Yancey, CEO and Co-founder of Cloudwords.

The Cloudwords Developer Center features the Cloudwords Sandbox, a unique environment that provides developers a fully automated integration experience. The Cloudwords Sandbox allows developers to quickly build and test Cloudwords integrations with any content system their business users rely on. A simulated end-to-end translation management experience, automated by a translation vendor "robot," means developers can experience the power of Cloudwords in a low-risk environment. Having the ability to test an integration within an environment that mirrors the actual Cloudwords production account allows developers to completely prepare for enterprise roll-out.

The Cloudwords Development Center also includes pre-built integrations for Drupal, Adobe CQ, and others, as well as complete documentation for the company's acclaimed REST-based API, and Software Development Kits (SDKs) for Java, .net, and PHP.

"The ability for companies to easily and efficiently localize their marketing content is mission critical in today's global economy. But this critical enterprise content is locked away inside ungainly content management systems. By leveraging CMS integration capabilities with their translation management application, organizations can finally achieve optimal localization efficiency. If companies aren't streamlining their localization process, they will fall behind their competition when it comes to reaching international markets," said Robinson Kelly, CEO and Co-founder of Clay Tablet Technologies.

"Cloudwords allows ADInstruments to easily integrate our Drupal website with their localization management platform so we can streamline the ongoing process of translating our website content. By integrating with Cloudwords, our content is uploaded, translated and approved within a significantly shorter time frame than the traditional 'cut and paste' approach. Now, we rely on Cloudwords to centralize all our multilingual assets and work with multiple translation vendors to localize content in 13 languages," said Ina Kinski, Hardware and Tools Coordinator at ADInstruments, responsible for website implementation.

Cloudwords' complete cloud-based translation management solution helps companies go global faster by enabling companies to manage the complexity of translation projects from creation to vendor selection to project and billing management. The Cloudwords platform offers easy-to-use, cloud-based project management capabilities so users spend less time manually managing localization projects and complete projects faster.

To learn more about Cloudwords' integration capabilities and the Cloudwords Developer Center, please visit http://developer.cloudwords.com/.

About Cloudwords
Cloudwords revolutionizes the way global companies think about their multilingual content strategy and execution. Through an intuitive customer-centric interface and a secure cloud infrastructure, Cloudwords delivers an application for business users to accelerate their translation process, manage vendors, and leverage data. Created by veterans of the translation industry and high-tech leaders from Salesforce.com, the company is backed by Storm Ventures and Cloud visionaries such as Marc Benioff. For more information on Cloudwords, please visit Cloudwords.com or join the global conversation on Twitter@cloudwordsinc.

http://www.marketwire.com/press-release/cloudwords-announces-faster-easier-integration-capabilities-with-new-cloudwords-developer-1821247.htm

Wednesday, August 14, 2013


pcworld
Amazon web services is now offering mobile developers cross-platform push notifications. Why would developers benefit from this service?

                                                  voxville
                                                          

Amazon pitches Simple Notification Service with Mobile Push as an easier way for developers to add notifications than previously has been possible. Using one API, developers can send notifications to iOS and Android-based devices, including Amazon's own Kindle Fire tablets.

Previously, adding push notifications at a large scale on multiple platforms has been complicated for developers, according to Amazon. That's because each smartphone OS has a different service that delivers notifications. So to support multiple mobile platforms, developers must integrate with each platform, which introduces operational complexity and cost, Amazon said.

Mobile Push is compatible with Amazon's own Device Messaging platform as well as Apple's Push Notification Service and Cloud Messaging from Google. Notification messages sent to a mobile endpoint can appear as message alerts, badge updates, or even sound alerts.

The service can send messages to individual users on specific devices or broadcast identical messages to many subscribers at once. For developers who find themselves with a hit app on their hands, it can scale from a few notifications a day to hundreds of millions, according to Amazon.

Developers can send up to 1 million notifications each month for free. After that, customers pay 50 cents for every million messages published, and 50 cents for every million messages delivered.
 
Mobile Push is built into the existing Simple Notification Service, which is still labelled as a beta and already lets developers send notifications to their users via SMS text message and email.

Tuesday, August 13, 2013







DeepBlue has taken the second place award on 10 Best Design’s list of Best Responsive Web Design Companies. Their use of images, bright color palettes and complex design elements help them stand out in a sea of pre-made templates and cookie-cutter websites. Established in 1999, DeepBlue is a grandfather of modern website design companies yet manages to remain the leader of the pack even as younger firms are born. Standing the test of time, DeepBlue has adapted to each fickle whim technology has thrown at them over the last fourteen years and continues to be an example for longevity in one of the most fast-paced industries on Earth. In that time they have helped over 1000 customers produce the perfect web design for the their product or service, created of 300 e-commerce sites, and completed over twenty-five responsive sites. Based out of both Los Angeles and Atlanta, the DeepBlue team is made up of thinkers, innovators, creatives, strategists, techno-geeks and fanboys who are dedicated to creating memorable brands and high impact websites that stay with the viewer long after the web browser has been closed. Their own website is complex and exhibits animation like features that give users a unique viewing experience. A masterpiece of dozens of minute details and large graphic pieces working together to beget a single vision, their site works as its own portfolio, showing a variety of different options without being messy or over the top. The mobile site is just as impactful despite the fact that many of the details have been toned-down and placed in the background to enhance readability on the smaller screen of a tablet or smart phone. In essence, they build responsive sites that manage to keep their quirks and branding elements regardless of the user’s point of access. Their portfolio is a living, breathing creature full of websites made not only to survive a new format, but to thrive in their new environment. Watching their work morph from the standard website to the responsive mobile website is a treat. Each element is amended to fit the intended platform and keep the company’s individual branding goals in mind. DeepBlue’s unique view of responsive web design has not gone unnoticed. The company has caught the eye of many national and multi-national companies including Mazda, Miramax Films, the United States Courts and even NASA. They’ve been awarded a Webby award and an Addy award. They have also been featured in both Forbes magazine and on CNN. DeepBlue has created a legacy of slick, modern, fun work that integrates all the right elements to make a website unforgettable to consumers. Unlike many companies that have surpassed the ten-year mark, DeepBlue continues to be a leader in pushing the envelope and creating formerly unseen solutions to complicated questions. The company regenerates constantly and learns how to not only keep up with new-fangled companies, but create new technologies and techniques before anyone else. Like a fine wine, DeepBlue’s web design just continues to improve. For the original version on PRWeb visit: http://www.prweb.com/releases/10-best-design/responsive-web-design/prweb11016848.htm

Monday, August 12, 2013

Can you imagine that Apple,the tech giant, had an outage with the their software developer's website?  On Saturday the portal which is essential for developers was back online after 23 days.




                                                                  Business Insider







Apple sent out an email to all registered developers, apologizing for the service outage.

The final restoration comes five days after Apple announced plans to have the portal at full capacity by the end of the week.

Developers now can check the status page via a link on the homepage to confirm that all functions essential for software development are back online.

According to the email sent to developers, to make up for the prolonged outage of some of the services, Apple will extend all memberships, which are usually for a year, by one month.

Apple’s software developer’s website, which also hosts its iOS and OS X beta downloads, went down on July 18 and a few days after, the company acknowledged that there had been a security breach.

No sensitive personal information was accessed, Apple said at the time, but it could not rule out that the intruders had gained access to developers’ names and mailing and email addresses.

The outage caused outrage in the developer community, for many of them were unable to enable new devices to run pre-release versions of Apple's software or test out new apps.

The downtime also came as Apple pushed developers to test and create software for upcoming versions of iOS and Mac OS X, both of which are expected this fall.

Apple began to bring back many key services on July 26, after more than a week of downtime. Essential services for software development on iOS, Mac, and Safari platform, were given the priority in restoration, alongside downloads for upcoming versions of Apple's desktop and mobile software.

Apple has yet to reveal the identity of those responsible for the self-imposed downtime, but one researcher claimed responsibility shortly after the outage began in July, saying that it was just a test for security instead of an intended crime.
 http://www.globaltimes.cn/content/803291.shtml#.UgjprW2HoSI


Friday, August 9, 2013

Why was this redesign needed for MSHA,Electrical Utility Safety, Healthcare and OSHA Compliance?


New design for these industries websites has provided benefits to safety professionals,from safely directors to those workers in the field of their specific industry. The new websites have provided content for education on the benefits of learning technology for safety programs.




“Our goal was to build a scalable and responsive multi-site content platform, that will allow us to easily implement new assets from game-based learning to videos and infographics" said Liz Bormida, Marketing Manager at Vivid Learning Systems. “The result is a new, mobile friendly website for each industry to help students and visitors have access to educational information and resources in an effort to help increase safety awareness in the workplace. Our vision is to bring mobility and convenience to occupational health and safety.”


“Our online visitors and students will now experience a more vibrant and seamless view of safety related content, from online training and best practices, to industry news and regulatory updates,” said Shawn Simon, Utility Manager for Vivid Learning Systems. “In the same way that the creation of Vivid Learning Systems Electrical Training Worker 1910.269 library brought top industry experts for an on-demand training solution for electrical utilities, the redesign of the Utility Safety Online website creates a new home in cyberspace for wide-ranging utility safety resources, making virtual visits to Utility Safety Online more exciting and informative than ever."

View the following websites and see what you think of the new changes made by Vivid Learning Systems.

http://www.utilitysafetyonline.com
http://www.mshatrainingonline.com
http://www.healthecaretrainingonline.com
http://www.complianceatwork.com




Thursday, August 8, 2013





The very popular Google Chrome does not provide the password protection that is needed for your security. Sure it's great that when using Chrome they save your password so when you choose to visit a social media site you do not have to type password again. This service for users comes with security problems.
The security problem is that when another person uses your computer they have access to all of your saved passwords. On August 7th Elliot Kember,a web developer, reported the security problem in a blog post.

To understand how easily it is for anyone can get your passwords in chrome then just follow these directions.

Copy and paste "chrome://settings/passwords" into Chrome and hit "Enter," to see Chrome's page for managing passwords. This window will pop up:


   You should never allow anyone that you do not trust to have access to your computer. We all haveinformation that we want guarded from others.  Being informed  is your saving grace.

ATCG Web Development BlogThe owner of this website is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to Amazon properties including, but not limited to, amazon.com, endless.com, myhabit.com, smallparts.com, or amazonwireless.com.