.

.
Showing posts with label Informatics. Show all posts
Showing posts with label Informatics. Show all posts

Tuesday, 30 August 2011

Buying a TV? Here's What You Should Know

Buying a TV? Here's What You Should Know

Our 32" Sony Bravia LCD TV wasn't really old but felt a bit obsolete. There were no USB ports, the TV wasn't network-capable meaning it cannot connect to the Internet or the home network, the 32" screen looked rather small in the living room and, most important, the TV didn't support full HD.
tvIt was therefore time to upgrade to something bigger and more advanced.
I am no expert to offer you any advice on buying TVs but I'll still try to summarize the key things I learned from the various websites and my Twitter friends while researching for my own purchase.

A Buying Guide for TV

There are several points to consider before buying a TV. What screen size should you choose? Is LED better than LCD or Plasma TVs? Which ports should you look for in a TV? Is it worth paying extra for networking related features? HD (720p) or Full-HD (1080p)? Which TV brand should you go for? And finally, is 3D necessary?
There are basically two types of TVs - LCD and Plasma. The other category, LED, is actually a type of LCD but one that is slimmer (looks matters) and consumes less electricity than regular LCDs. I haven't had a chance to compare the picture quality of equivalent LED, LCD and Plasma HDTVs side-by-side but most online material seem to suggest that Plasmas offer the best picture quality.
The other point in favor of Plasma HDTVs is the viewing angle. LCDs and LEDs are best viewed from the front but if your room's seating arrangement is such that people may have to watch TV while sitting at either sides, Plasmas may be a better option as the have a wider viewing angle. That said, if your TV room is brightly-lit or has too many windows, the Plasma screen may carry glare or reflection. LCDs have a matte screen and thus don't have the reflection problem.
HDTVs are available in various sizes and the one you should choose depends on two factors - the length of your room and obviously your budget.
As a rule of thumb, the ideal size of the TV screen should be anywhere between .3x and .6x where x is the distance between your sofa and the TV. For example, if the viewing distance is 6 feet (or 72 inches), you can go for a 24" - 48" screen.
Most newer TVs have HDMI and USB ports but what's also important is the location of these ports. If you are planning to wall-mount the TV, make sure that there are enough free ports at the sides of the unit because, once you mount the TV, it will be inconvenient, or rather impossible, to use the back ports for connecting your gadgets to the TV.
The next factor is the screen resolution where your choices are 720p, 1080i and 1080p - also known as full HD. Unless you are getting a small screen TV - like 32" - go for 1080p resolution and here's why. More and more TV channels are becoming available in high-definition, the HD picture quality is vastly superior but you need a 1080p TV to experience the difference.
All brands are working hard to sell you 3D-capable TV sets but is 3D worth the extra cost or should you just settle for the good-old 2D? It depends.
We have a joint family and the TV is placed in a common room so we mostly watch it together. In order to enjoy 3D content, one needs to wear 3D glasses. If there are four other people in the room, they also need to wear compatible 3D glasses. The glasses are expensive but cost aside, I highly doubt if folks at home would be willing to wear a pair of glasses for watching a movie or a TV program. Also, there's isn't enough 3D content available anyway – especially in regional languages - so we decided to go with 2D.
The other important feature to consider while deciding a TV is network connectivity. The expensive TV models often have built-in WiFi (or Wireless LAN) while others are WiFi-capable meaning you can attach an extra dongle, always old separately, to connect the TV to the home network or for watching web videos - like YouTube - on your TV wirelessly.
All Internet-ready TVs have an Ethernet port so if you can stretch the LAN cable from the router to the TV, you can go for the WiFi-capable model but without spending on the USB wireless adapter. Also look for DLNA support as it will become easy for you to stream photos, music and videos from your computer and mobile phone to the TV screen.
One more thing. TV vendors like Sony, Panasonic, Samsung and LG bundle various 'apps' to help you watch YouTube videos, Flickr photos and other web content on the HDTV. However, the number of apps offered by these vendors is still small, they have no built-in browsers, no web search and you are thus limited to a very tiny portion of the web.
So what we finally picked is a 50" Panasonic Viera Plasma TV, full HD, lacks 3D, Internet-ready but without built-in Wi-Fi. It is definitely not "razor-thin" but since the unit is mounted on a wall, you rarely notice the thickness. Also, Panasonic offers limited Internet apps but not that we have connected it to Logitech Revue (read review of Google TV), family members can access almost the entire web in the living room.
While all have of us different requirements and there's no such thing as 'perfect' when it comes it to buying gadgets, the above points may help you make a slightly more informed decision and get more value for your money.

Saturday, 5 February 2011

Informatics students discover, alert Facebook to threat allowing access to private data, bogus messaging

http://cdn.physorg.com/newman/gfx/news/informaticss.jpg
A Facebook security vulnerability discovered by a pair of doctoral students at Indiana University Bloomington's School of Informatics and Computing that allowed malicious websites to uncover a visitor's real name, access their private data and post bogus content on their behalf has been repaired, Facebook has confirmed.
The vulnerability discovered by Rui Wang and Zhou Li enabled malicious websites to impersonate legitimate websites, and then obtain the same data access permissions on Facebook that those legitimate websites had received.
Wang and Li said the vulnerability occurred when a user informed Facebook of his or her willingness to share information with popular websites like ESPN.com or YouTube. Whenever a website makes such a request to Facebook via the user's browser, Facebook passes a secret random string called an authentication token back to the requestor for identification. Whoever holds that authentication token can convince Facebook that they are, say, ESPN.com and then gain unfettered access to the shared data.
Facebook confirmed the discovery and in a statement said the problem was repaired and that the belief was that no sites had been compromised.
"Researchers at Indiana University reported a vulnerability in our Platform code to us, and we worked quickly with them to resolve it. It was fixed shortly after it was reported. We're not aware of any cases in which it was used maliciously," the statement said. "We thank the researchers at Indiana University for bringing this to our attention, and for demonstrating the value of responsible disclosure."
The researchers identified a flaw in the way the token was transmitted using two Flash objects: one inside Facebook's iframe passes the token to the second, which in this case would be embedded at ESPN.com. The transfer mode can be selected through "transport='flash'" with the security guarantee being that both flash objects are supposed to come from the same domain (i.e., Facebook) before they can talk.
The researchers found, however, that such a same-domain assumption is not always valid because Adobe Flash allows cross-domain communication with an unpredictable domain name that is prepended by an underscore symbol in the connection name. This allows an attacker website to steal an authentication token by choosing the transport='flash,' replacing the receiver flash with its own and then initiating a cross-domain communication with the flash inside the Facebook-controlled iframe to get the token and send it to the attacker's flash.
"This vulnerability has several implications," Wang said. "Basically, any user with a valid Facebook session loses anonymity and privacy to any website, even one with embarrassing or sensitive content."
Facebook allows some websites like bing.com to directly access a user's public data without explicit consent. This enables the malicious website impersonating that site to do the same. Moreover, if the user has ever granted any website, such as The New York Times, YouTube, Farmville or ESPN, the permission to connect to their Facebook account, further damage can be inflicted, including disclosure of private data that the user does not want to share with others, and impersonation of the user to post bogus news or comments on friends' walls. This form of propagation resembles the famous MySpace worm released in 2005, they said.
"Our attack utilized a feature of Adobe Flash called unpredictable communication, and an important distinction between an unpredictable communication and a normal communication is that the former is done through a connection where the name starts with an underscore symbol," Li said. "Therefore, Facebook could check for this symbol to determine if a potentially malicious website tries to do unpredictable communication."
And that is exactly what Facebook started to do once they were alerted to the problem by Wang and Li, who were working under the supervision of School of Informatics and Computing Associate Professor XiaoFeng Wang and Shuo Chen, a researcher in Microsoft Research's Internet Services Research Center.
XiaoFeng Wang, the students' adviser, said Facebook relies on same-domain communications that allow websites to specify Adobe Flash as the communication mechanism.
"In a normal situation, two flash objects can only do same-domain communications, and, in fact, security of Facebook's authentication crucially depends on same-domain restrictions," he explained. "However, Facebook allowed the Adobe Flash communication mechanism but did not disallow the unpredictable domain names. This is how a malicious website could establish a channel to enable two flash objects in different domains to communicate."
To portray the seriousness of the vulnerability, the team made a video demo that can be viewed here.
Facebook officials noted that a contact form at both the Facebook Help Center and from the "Whitehats" tab on the Facebook Security Page are available in the rare instances in which vulnerabilities are found.
"We also recently rewrote our responsible disclosure policy to make it even easier for researchers to let us know when they find a vulnerability, so we can fix it quickly and before it's exploited. Our new policy was praised by the Electronic Frontier Foundation in a recent blog post here," the statement said.