Thursday, January 29, 2009

Gmail to work offline

You can now create Gmail, or browse your inbox, without a connection to the internet - but the new feature comes tacked with a warning.

In an upgrade announced on its Gmail house blog today, Google says its web mail service can now be used with Gears – the company’s technology for synchronising on and offline content.

Instructions on upgrading your Gmail settings to accommodate Gears are here (see also the one-minute video below).

Once you’re set-up, Gears downloads a copy of your Gmail inbox to your PC’s hard drive. Gmail defaults to this cached version if you’re offline or if you’re encountering a ropey connection - "Like when you're 'borrowing' your neighbour's wireless", as a Google engineer writes on the blog, with studied zaniness.

However, like everything to do with Gmail, and with Labs, the new offline feature is in beta and Google warns on its blog: "Offline Gmail is still an early experimental feature, so don't be surprised if you run into some kinks that haven't been completely ironed out yet."

As the correspondent writes, the kinks include Offline Gmail not actually showing up under Gmail's Labs tab yet. A rep for Google tells NBR that Gmail Offline "is being rolled out progressively over the next few days, so there may be a slight delay in it appearing".

Friday, January 23, 2009

Massive Job Cuts even at Microsoft

I have been hearing the word “job cuts” almost everywhere I turn to. With falling revenue from sales and income taxes, and property-tax declines looming, states, cities and towns have already to lay off tens of thousands of government employees (believable?) though sad, it’s happening. Everyone seems to be firing rather than hiring. With just over 5 minutes of research I was able to find articles everywhere about thousands and thousands of job cuts, and not only that, it seems to be the fastest growing headlines on some of the more popular news sites now.

There were so many organizations that have announced job cuts. And now, its the turn of IT Major Microsoft. Overlooked in the Microsoft announcement about its layoffs of 5,000 people over the next 18 months is this startling revelation: The company's revenue decline is due, in large part, to the growth in the sales of Netbooks.

In a statement, Microsoft announced that because of the economic meltdown and slowing IT spending, it will lay off 5,000 people. Overall it reported a 2% increase in revenue compared to the same quarter last year. It had a total of $16.63 billion in revenue for the second quarter this year.

While overall growth was 2%, Microsoft took a big hit with its client software, and a big reason for that was netbooks. Here's what the company said:

“Client revenue declined 8% as a result of PC market weakness and a continued shift to lower priced netbooks.”

That's an astonishing admission. It means that people are forgoing higher-priced laptops, and instead buying netbooks --- and many of those netbooks are powered by Linux. So Microsoft loses out not only on sales of Windows, but also sales of Microsoft Office as well. Estimates are that 30% of all netbooks ship with Linux.  This is all the more reason why Microsoft needs to ship Windows 7 quickly, and will most certainly do it before the announced 2010 ship date. Windows 7 has been designed to work with netbooks, and Microsoft hopes it will be a Linux-killer.

If you want to read the full Microsoft announcement about layoffs, you can get it here.)

Tuesday, January 20, 2009

What we don’t usually see.

Blogspot (blogger) has a nice selection of hidden links that are very helpful to users. Finding help to seeing updates–these links are a nice list to bookmark in case you should ever need them.

The blogger help pages:
http://help.blogger.com/?page=help

A list of the blogs that have been updated in the last five minutes:
http://www.blogger.com/changes10.g

The XML feed of the blogs that have been updated in the last five minutes:
http://www.blogger.com/changes10.xml

Current bugs in blogger:
http://help.blogger.com/bin/answer.py?answer=42108

Bugs in the beta version of blogger:
http://help.blogger.com/bin/answer.py?answer=44251

Reset your blogger password:
http://www.blogger.com/forgot.g

Blogger Terms of Service:
http://www.blogger.com/terms.g

Hope this information is useful to you :) Happy Blogging.

Thursday, January 15, 2009

Beware : Adwords Phishing email in circulation

From: Google Adwords-noreply [mailto:adwords-noreply@google.com]
Sent: Saturday, Jan 10, 2009 9:40 AM
To: XXXXXXXXXXXX
Subject: [Released by Allow List] Please Update Your Billing Information
————————
Dear Google AdWords Customer!

In order to update your billing information, please sign in to your AdWords account at https://adwords.google.com , and update your billing information. Your account will be reactivated as soon as you have entered your payment details. Your ads will show immediately if you decide to pay for clicks via credit or debit card. If you decide to pay by direct debit, we may need to receive your signed debit authorization before your ads start running, depending on our location. If you choose bank transfer, your ads will show as soon as we receive your first payment. (Payment options vary by location.)

Thank you for choosing AdWords. We look forward to providing you with the most effective advertising available.

Sincerely,

The Google AdWords Team
————————
This message was sent from a notification-only email address that does not accept incoming email. Please do not reply to this message. If you have any questions after following the steps above, please visit the Google AdWords Help Center at https://adwords.google.com/support/bin/topic.py?topic=8336>

The actual destination login URL hidden under the display URL: http://adwords.google.com.fr4ck.cn/select/Login

Clearly, this isn’t from Google.

It is phishing attack designed to steal your billing information. Beware!

Here’s Google’s response to this:

From: XXXXX [mailto:XXXXXXXXX@google.com]
Sent: Monday, Jan 12, 2009 3:16 PM
To: XXXXXXXXXXXXX
Subject: Re: [#255928689] [Released by Allow List] Please Update Your Billing Information

Hi XXXXXXXX,

This appears to be a ’spoofing’ email sent to some AdWords advertisers recently. ‘Spoofing’ refers to the act of fraudulently altering certain properties of an email to make it appear as though it originated from a legitimate source. The email can then lead to a deceptive website which collects sensitive personal information. In this case, the email may have appeared to be from Google AdWords, asking for your account login information. Please do not respond to these emails.

Google is not responsible for nor are we able to monitor the actions of other parties. However, we are very committed to ensuring the safety and security of our users and our advertisers, and we take issues of fraud seriously. Moreover, we’ve dedicated a number of resources towards preventative measures, such as the Google Safe Browsing extension for Firefox. You can find more information about this feature at http://www.google.com/tools/firefox/safebrowsing/.

Here are some steps you can take to ensure the security of your account:

* Be wary of unsolicited messages. Google will never send unsolicited messages asking for your password or other sensitive information. If you need to change your account information, such as your billing details or your password, always sign into your AdWords account from https://adwords.google.com and make the changes directly within your account.

* Check the message headers. The ‘From:’ address and the ‘Return-path’ should reference the same source.

* Make sure the URL is legitimate. The AdWords homepage URL will always be https://adwords.google.com.

* Change your Google Account password frequently. To learn how, visit https://adwords.google.com/support/bin/answer.py?answer=24828.

* Report suspicious messages to adwords-charge@google.com.

* Keep your computer’s antivirus and spyware protections up to date and regularly run system scans.

If you believe your Google AdWords account may have been compromised, please let us know so that we can initiate an investigation.

Best,

XXXXXXXXXX

——————
XXXXXX
Account Associate
National Agency Team

Wednesday, January 14, 2009

In-session Phishing

A bug found in all major browsers could make it easier for criminals to steal online banking credentials using a new type of attack calledPhishing "in-session phishing," according to researchers at security vendor Trusteer.

In-session phishing gives the bad guys a solution to the biggest problem facing phishers these days: how to reach new victims. In a traditional phishing attack, the scammers send out millions of phony e-mail messages disguised to look like they come from legitimate companies, such as banks or online payment companies.

Those messages are often blocked by spam-filtering software, but with in-session phishing, the email message is taken out of the equation, replaced by a pop-up browser window.

Here's how an attack would work: The bad guys would hack a legitimate Web site and plant HTML code that looks like a pop-up security alert window. The pop-up would then ask the victim to enter password and log-in information, and possibly answer other security questions used by the banks to verify the identity of their customers.

For attackers, the hard part would be convincing victims that this pop-up notice is legitimate. But thanks to a bug found in the JavaScript engines of all the most widely used browsers, there is a way to make this type of attack seem more believable, says Amit Klein, Trusteer's chief technology officer.

By studying the way browsers use JavaScript, Klein said he has found a way to identify whether or not someone is logged onto a Web site, provided they use a certain JavaScript function. Klein wouldn't name the function because it would give criminals a way to launch the attack, but he has notified browser makers and expects the bug will eventually get patched.

Until then, criminals who discover the flaw could write code that checks whether Web surfers are logged onto, for example, a predetermined list of 100 banking sites. "Instead of just popping up this random phishing message, an attacker can get more sophisticated by probing and finding out whether the user is currently logged into one of 100 financial institution Web sites," he said.

"The fact that you're currently in-session lends a lot of credibility to the phishing message," he added.

Security researchers have developed other ways to determine whether a victim is logged onto a certain site, but they are not always reliable. Klein said his technique doesn't always work, but it can be used on many sites including banks, online retailers, gaming and social networking sites.

Source : CompuWorld