Chrome 52 Released

Google released today Chrome 52.0.2743.82, promoting the 52.x branch to the Stable Channel, making it Chrome's official version.

This new release is a little bit light on visible UI features but brings a lot for developers that like to tinker on websites and are, generally, more interested in what's under the browser's hood.

Back in early June, Google engineers had drawn out a plan of what features users should expect in Chrome 52.

New CSS contain property
The team didn't stray much from their plan, and now Chrome features support for CSS containment, via the CSS contain property, which prevents child elements from displaying outside the boundaries of their parent element.

A good reason for developers to implement CSS containment on their websites is to speed up page load times. Google engineers have played around and detailed the advantages of using the contain property in a blog post in June.

CSS contain support is only available in Chrome 52 and Opera 40 (alpha stage). Firefox devs have shown public interest in integrating the property into their browser, but no code to support it has landed in the browser until now.

Simpler and more efficient process for gathering performance metrics
The second big feature Google engineers added is the PerformanceObserver API, a feature that allows Web developers to fine tune the performance metrics gathering process.

Until now, developers that wanted to collect performance metrics had to rely on Chrome's DevTools, which is not a tool specifically designed for such a process.

With the integration of this new API, developers can specify which performance metrics they want Chrome to collect, and avoid situations when the browser gathers information which is never used and wasting memory space. Google devs have explained how this feature works this past June.

VAPID Support and the Streams API
Chrome 52 also supports the VAPID specification (Voluntary Application Server Identification for Web Push).

VAPID allows a site that uses push notifications to authenticate much easier with Web Push services that interact with your desktops or mobile devices.

Play Video
Additionally, the Streams API also introduced with Chrome 52 will allow the browser to start rendering page content even if the entire HTTP request has finished downloading. This basically means that CSS code is already used on the page, even before the entire stylesheet has been downloaded.

As seen in the video above, this improves page loading times, something that which Google engineers will never stop trying to improve.

Deprecations and removals
The first thing you will notice missing from Chrome 52 is the company's Chrome App Launcher that allowed the user to launch Chrome apps even if the browser was closed.

Google announced the deprecation of this feature at the start of the year, but people that love it can still use it inside Chrome OS.

Other things that were removed or deprecated include support for the MediaStream ended event and attribute, the MediaStream onended attribute, overload of postMessage(), X-Frame-Options intags, non-primary button click event, requestAutocomplete(), and the ability to block cross-origin iframes during touch events except during a tap gesture.

Security bugs and other smaller updates
Google's security team didn't slack either, and based on their own audits and reported bugs, the engineers fixed 48 security issues, handing out $21,000 to contributors along the way.

Below is the full list of security bugs, followed by a selection of smaller changes also included in Chrome 52's full changelog.

[$15000][610600] High CVE-2016-1706: Sandbox escape in PPAPI. Credit to Pinkie Pie
[$3000][622183] High CVE-2016-1707: URL spoofing on iOS. Credit to xisigr of Tencent's Xuanwu Lab
[$TBD][613949] High CVE-2016-1708: Use-after-free in Extensions. Credit to Adam Varsan
[$TBD][614934] High CVE-2016-1709: Heap-buffer-overflow in sfntly. Credit to ChenQin of Topsec Security Team
[$TBD][616907] High CVE-2016-1710: Same-origin bypass in Blink. Credit to Mariusz Mlynski
[$TBD][617495] High CVE-2016-1711: Same-origin bypass in Blink. Credit to Mariusz Mlynski
[$TBD][618237] High CVE-2016-5127: Use-after-free in Blink. Credit to cloudfuzzer
[$TBD][619166] High CVE-2016-5128: Same-origin bypass in V8. Credit to Anonymous
[$TBD][620553] High CVE-2016-5129: Memory corruption in V8. Credit to Jeonghoon Shin
[$TBD][623319] High CVE-2016-5130: URL spoofing. Credit to Wadih Matar
[$TBD][623378] High CVE-2016-5131: Use-after-free in libxml. Credit to Nick Wellnhofer
[$1000][607543] Medium CVE-2016-5132: Limited same-origin bypass in Service Workers. Credit to Ben Kelly
[$1000][613626] Medium CVE-2016-5133: Origin confusion in proxy authentication. Credit to Patch Eudor
[$500][593759] Medium CVE-2016-5134: URL leakage via PAC script. Credit to Paul Stone
[$500][605451] Medium CVE-2016-5135: Content-Security-Policy bypass. Credit to kingxwy
[$TBD][625393] Medium CVE-2016-5136: Use after free in extensions. Credit to Rob Wu
[$TBD][625945] Medium CVE-2016-5137: History sniffing with HSTS and CSP. Credit to Xiaoyin Liu

Other features in this release
Chrome now pauses animations while showing modal dialog boxes.
HTTP alternative services allow sites to specify additional origins that can be used to reach a certain resource, enabling easier protocol upgrades and load balancing.
ImageBitmaps can be created more easily using ImageBitmapOptions to specify configurations on construction.
Sites can now free the memory consumed by an ImageBitmap using ImageBitmap.close().
Chrome now supports OpenType small capitals and easier styling of numbers using the font-variant-caps and font-variant-numeric properties.
Touch gestures inside a cross-origin iframe can no longer trigger popups unless they correspond to a tap gesture, preventing accidental pop-ups during scrolling.
Now only secure origins can create or delete secure cookies on Chrome for Android.
The latest version of Chrome supports -webkit-appearance:none which disables the default rendering of HTML5 meter elements and allows easier custom CSS styling.
The unsafe-dynamic Content Security Policy expression allows sites to use single-use or hash-based whitelists to verify script sources, making it easier to protect against cross-origin scripting attacks.
Sites can now use the Fetch API to programmatically set the referrer policy for a request.
CanvasRenderingContext2D now supports the filter attribute, allowing sites to apply effects to primitives drawn to the canvas.
Sites can now test whether or not a key exists within the bounds of an IDBKeyRange using IDBKeyRange.includes().
The HTMLMediaElement.srcObject attribute simplifies associating a MediaStream with a media element.
AudioParam now supports the read-only min and max attributes to simplify introspection.
RTCCertificates can now be stored in IndexedDB.
PannerNode and AudioListener now support automation methods, allowing smooth audio transitions.
Stylesheets can now specify alpha values for colors using eight- and four-bit hexadecimal values instead of the longer rgba() syntax.
Sites can now experiment with persistent storage as an origin trial, allowing a site to disable automatic storage clearing when bookmarked.
Multiple WebVTT tracks will now be presented as user options in the default media controls, enabling language selection for captions and subtitles.
postMessage overrides of the form postMessage(message,transferables,targetOrigin) have been deprecated.
The MediaStream ended event and the corresponding onended attribute have been deprecated.
The web app manifest icons entry no longer supports the density property.
The DynamicsCompressorNode.reduction attribute is now a readonly float instead of an AudioParam.
flexbox children with position:absolute will now be positioned using justify and align if the element does not have a left:, right:, top:, or bottom: position specified.
requestAutocomplete() has been deprecated and removed due to low usage numbers.
X-Frame-Option will no longer be supported in the meta tag to support a more secure implementation.
Invalid values for track-kind are now treated as metadata instead of subtitles to improve media behavior in older user agents.

Microsoft steps up legal pressure against Windows 10 pirates

Microsoft, Files fifth lawsuit since February to stop alleged pirates from illegally activating Windows and Office

Microsoft last week continued its campaign to quash software pirates when it filed the fifth lawsuit in as many months accusing unidentified individuals with illegally activating more than 1,000 copies of Windows, including the newest Windows 10, and Office.

The suit was filed in a Seattle court last Thursday. It was almost identical to others submitted since February, when Microsoft started a string of cases targeting numerous "John Does."

"Microsoft’s cyberforensics have identified over one thousand activations of Microsoft software originating from IP address ('the IP Address'), which is presently assigned to Cable One, Inc.," Microsoft's complaint read.

Microsoft did not identify the culprits, but tagged them as "John Doe" 1 through 10.

"Defendants have activated and attempted to active [sic] copies of Microsoft Windows 10, Windows 8.1, Windows 8, Windows Vista, Windows 7, Office 2013, Office 2010, and Windows Server 2008," Microsoft charged.
As with the previous four John Doe cases of 2016, Microsoft asserted that it tracked the allegedly illegal activations to the IP address, and that the number and pattern of those activation's "make it more likely than not" that they were using stolen product keys or abusing legitimate keys.

The 25-character alphanumeric key codes are a core component of Microsoft's anti-piracy technology. Although the software can be copied an unlimited number of times, the keys individually lock a license to a device. Minus a legitimate key and thus activation, Microsoft's software retreats to a hobbled or even crippled mode.

In a related filing for the same case, Microsoft requested that the latest be assigned to the same federal judge who is overseeing the four others initiated this year because they "are substantially related." Altogether, Microsoft has filed 13 anti-piracy lawsuits since November 2014 with the Seattle court.

Microsoft has been given permission in two of the 2016 cases -- both filed in early June -- to serve subpoenas to internet service providers (ISPs) Comcast and Earth-link. Those subpoenas have demanded that the ISPs identify the alleged software pirates who have been assigned the IP addresses Microsoft had fingered.


Satya Nadella says Microsoft is revising its goals for Windows 10

We all know that Microsoft was having its stakes high on Windows 10.

Microsoft was recently forced to delay its ambitious goal of getting 1 billion devices onto Windows 10 within the next two years, after its collapsing phone business made that an unrealistic milestone.
Instead, CEO Satya Nadella announced Tuesday during the company's quarterly earnings call that Microsoft will change the way it reports the number of Windows 10 installations (currently at over 350 million), reflecting a shift in how it thinks about the operating system.
"We changed how we will assess progress," Nadella says. 
Now, instead of the irregular updates on Windows 10 growth we've been gotten for the last year, mainly at Microsoft conferences and events, Nadella says Microsoft will share monthly active users on the operating system "regularly."
Notably, instead of installations, Microsoft is now tracking monthly active users of Windows 10 — the same kind of metric used to track services like Google's Gmail, which has a billion monthly active users.
And what does "regularly" mean? Who knows? With Windows 10 rapidly approaching its first birthday, maybe it'll become just another line item on the quarterly earnings report. 
Furthermore, Nadella says that Microsoft is measuring the success of Windows 10 on some key benchmarks, which will also be reported on that same "regularly" scale:
"Deliver more value and innovation" — on August 2nd, Microsoft is delivering the Windows 10 Anniversary Update, a free upgrade that brings new stylus and security features. Nadella says new features bring new people into the Windows 10 fold.
"More services" — Nadella has long held that Windows 10 is an excellent sales funnel towards Microsoft's key subscription services, including Office 365 and Xbox Live. Nadella says that Microsoft is focusing on how Windows 10 can push more of that kind of service revenue.
"New device categories" — In the same way that the Surface Pro tablet and Surface Book laptop are incentivizing manufacturers like Dell, HP, and Lenovo to up their games in the hardware market, Nadella says that new-era devices like the HoloLens holographic headset and Surface Hub mega-tablet can inspire new kinds of Windows-powered computers to hit the market, increasing Windows' footprint.
None of this is especially new: The reason Microsoft was angling for a billion devices in the first place was because with Windows 10 everywhere, it gives the crucial software development industry a reason to stick around Windows and not leave for the iPhone or Android.
But by reporting the monthly number, and explicitly making these three points Microsoft's goals, it's demystifying its intentions around Windows 10, while making it more explicit that it plans to keep growing in these areas. 
The Windows 10 free upgrade offer will end on July 30th, meaning people are going to have to pay $130 for the operating system. It'll be really interesting to see, on a more regular basis, how many people are willing to pony up for Nadella's vision of an always-improving Windows.

Microsoft’s Q4 earnings beat Street with $22.6B in revenue

Dear All,
Wall Street expected the company to report earnings per share of $0.58 on revenue of $22.14 billion.

The company’s stock was trading up 3.5 percent right after the earnings were announced.

As Microsoft’s director of investor relations Zack Moxcey told me after the earnings announcement, the GAAP results this quarter still reflect the charges Microsoft took related to its phone business and adjustments for Windows 10 revenue deferrals. He also attributed part of Microsoft’s higher than expected earnings to the company’s lower than expected tax rate.

In the year-ago-quarter, Microsoft’s revenue was $22.2 billion, but earnings per share came to a $0.40 loss because of the $7.5 billion charge Microsoft took related to its acquisition of Nokia. Without the charge, the company’s earnings per share would have been $0.62.

“This past year was pivotal in both our own transformation and in partnering with our customers who are navigating their own digital transformations,” said Satya Nadella, chief executive officer at Microsoft. “The Microsoft Cloud is seeing significant customer momentum and we’re well positioned to reach new opportunities in the year ahead.”

Like in previous quarters, analysts will be especially interested in Microsoft’s cloud revenue. In its Q3 report, Microsoft said revenue from its “Intelligent Cloud” business had grown to $6.1 billion, up 3 percent (or 8 percent in constant currency). Azure revenue had grown 120 percent year-over-year while its server products and cloud services revenue had increased 5 percent.

This quarter, Intelligent Cloud revenue hit $6.7 billion and Azure revenue grew 102 percent year-over-year.
Microsoft has long said that it expects its commercial cloud business to hit a $20 billion run rate by 2018. In Q3, it reported that its run rate was $9.4 billion. With this new report, that number has now hit $12.1 billion, which Microsoft prominently highlighted in its earnings release. Moxcey told me that the company is standing by its plan to reach a $20 billion run rate by 2018.

Sadly, Microsoft doesn’t provide geographic breakdowns of its revenue numbers, but Moxcey attributed some of the growth in the company’s Azure business to Microsoft’s wide geographic footprint with regard to Azure regions.

As far as Intelligent Cloud goes, Moxcey also noted that the company doubled its customer base for its enterprise mobility solutions year-over-year (it now has 33,000 customers), and that the installed base grew nearly 2.5x year-over-year.

Here is a breakdown of Microsoft’s numbers for its other business units:

Productivity and Business Processes (this includes Office, consumer Office and Dynamic, among other products): $7.0 billion, compared to $6.3 billion in revenue in the last quarter. Microsoft attributes this to strong growth across its productivity services and especially the fact that Office 365 commercial revenue grew 54 percent year-over-year and that its Dynamics CRM paid seats are growing at more than 2.5x year-over-year.

More Personal Computing (including Windows, Devices, Gaming and Search): $8.9 billion in revenue, compared to $12.7 billion in the last quarter. Phone revenue, unsurprisingly, declined 71 percent, but the company’s revenue from its Surface line continues to increase and was up 9 percent in the last quarter (mostly driven by the Surface 4 and Surface Book).

Windows OEM consumer revenue grew 27 percent. For the commercial market, it grew 2 percent (which sounds low, but is far better than in previous quarters). Because Microsoft’s revenue in this area is largely driven by new purchases, Microsoft doesn’t expect the end of the free update offer to have a markable influence on next quarter’s results.

Microsoft also announced that Xbox Live now has 49 million monthly active users and that its search advertising revenue was up 16 percent, largely due to the deeper integration of its search tools into Windows 10. During today’s earnings call, Microsoft CEO Satya Nadella also noted that Windows 10 users have now asked Cortana 8 billion questions to date.

For the full year, Microsoft reported $92 billion in non-GAAP revenue and $2.10 in adjusted earnings per share. The company’s operating income was $27.9 billion on a non-GAAP basis.

Hacked Server Marketplace Returns as a Tor Domain

xDedic, a marketplace selling access to hacked servers, has reemerged as a Tor domain after a report that exposed its illicit activity sparked its operators to take it down last month.
After Kaspersky Lab researchers revealed in mid june that they counted over 70,000 hacked servers made available for purchase on xDedic, some for as low as just $6, the marketplace operators closed the virtual shop on June 16. However, with roughly 30,000 users a month, the storefront was too popular to disappear for good, and intelligence firm Digital Shadows saw it re-emerge only a week later, but as a Tor domain now.
In an incident report shared with SecurityWeek, Digital Shadows reveals that a user named xDedic posted on 24 Jun 2016 a link to the new site on the criminal forum exploit[.]in. The user, who “had an established reputation on the forum and has been previously identified as associated with the site,” posted the link on a Russian language forum thread titled “xDedic спалили” (xDedic burned).
The original xDedic site was established in November 2014, and provided detailed information on each of the servers available for purchase on it: price, location, speed, anti-virus installed, and more. Kaspersky Lab researchers discovered 70,000 servers available on the marketplace, but later revealed that these might have been only the items that were the least attractive to buyers.
Several days after the initial report was published, the researchers received information that over 176,000 unique hacked servers were traded on xDedic between October 2014 and February 2016 and that many more might have been traded since February. The hacked servers were located in 173 countries and came from 416 unique sellers. The prices for these servers ranged from $6 to $6,000, though only around 50 servers cost more than $50.
The new xDedic site is identical in design to the previous one, but Digital Shadows researchers say that the marketplace’s operators didn’t import the user accounts from the initial website, meaning that accounts could be freely registered. However, they also discovered that a $50 credit was required after registration for an account to be activated.
Awareness on the new site is low at the moment, but researchers believe that this will change shortly, since the previous site was attracting 30,000 users a month when it closed down. It appears that the new xDedic domain was shared only on said criminal forum and on a French language dark web criminal site, but “with the exception of Tor domain aggregation lists could not be located elsewhere.”
Researchers couldn’t confirm how many users the new site has attracted for the time being, as the domain is hosted on the Tor network and they can’t assess the site's traffic volumes. However, the research into the new xDedic site is still undergoing, Digital Shadows told SecurityWeek.
“The nature of the dark web is naturally very volatile, so keeping a keen awareness of this naturally changing landscape is key for organizations,” said James Chappell, CTO and co-founder of Digital Shadows.
Kaspersky Lab researchers also are monitoring the situation. “We are aware of reports of the return of xDedic and are monitoring the situation. We have a policy to share the findings of cybercriminal research with the relevant law enforcement agencies, and we have already done so in the case of xDedic,” Kaspersky Lab told SecurityWeek via email.

Upgrade to Windows 10 before July 29

You all know that Microsoft had released Windows 10 and you may be wondering to Upgrade to windows 10 or continue with windows 8.1 or windows 7.
So I thought of giving you some points to considering upgrading your windows to windows 10.

. It’s free


Until July 29th, 2016, you are able to upgrade to Windows 10 for free, if your PC hasn’t already done so by itself. That’s a saving of up to £189.99. The Home version of the system costs £99.99 and is enough for most users, however, IT pros and Developers may need the professional version. But why upgrade? Keep reading, as there are many other benefits to upgrading to Windows 10.

2. Live Tiles


At first, they may seem confusing and hard to use, but in reality, you just need to give it five minutes and it feels like second nature. Live tiles are one of the best features the Windows platform has to offer. They show you information even before opening the app. All you need to do is open your Start Menu then glance at the start screen. You already know who commented on your Facebook post, who liked your tweet, who sent you a mail and what that mail is about. The possibilities are endless, and this is something everybody should take a look at in order to be more productive. When you go live tiles, you can’t go back.

3. Automatic Updates


With all the memes about Windows 10’s aggressive update policy floating around the internet, updating may seem like a bad thing, however, this isn’t entirely true because updates provide extra security, performance improvements, bug fixes, and from time to time, even new features. This doesn’t seem all that bad, does it? With Windows 10, Microsoft is changing how they update your system. It does it automatically, both for apps and for the system itself. When a new update is released, your PC downloads it in the background and prompts you to update when you turn it off, at the time you wouldn’t use it anyway. This makes your PC secure and up to date, without you having to do anything.

4. Action Center


With Windows 10, you get the Action Center. If you have a smartphone, which you probably do, this works just like the page you get when you swipe down from the top on your phone. It keeps you up-to-date with information and notifies you about anything that needs your attention. You can reply directly from there, without even opening the app, as part of Actionable Notifications. You also have your Quick Actions that are used to enable or disable different settings of the system, like Bluetooth, WiFi, change brightness, Tablet Mode and more.

5. Tablet Mode


The Tablet Mode is a truly great feature. It optimizes the whole system for touch and pen input. Apps go full screen, split-view changes its behaviour, buttons get bigger, gestures turn themselves on… There is a lot more to that, but writing everything down would require its own article. The feature is something especially useful for 2-in-1 devices like Microsoft’s Surface. Tablet mode turns on automatically when you disconnect the keyboard and turns off when you reconnect it. This helps to keep you productive by seamlessly adjusting your experience to the most appropriate layout.

6. The design


The design language that Windows 10 uses is MDL2, which stands for Microsoft Design Language 2. Windows 10 is often criticised for its inconsistency and unbalanced design, however, this is getting better and better, and Windows 10 is shaping up to be a truly beautiful system. With the Anniversary Update, you’ll also be able to use the built-in dark theme, that is praised among Windows Phone fans that had access to different theme choices since 2010. Many professionals and regular consumers often want their PCs to look elegant and sleek, and that is now possible thanks to Windows 10’s modern and elegant look.

7. It’s part of a whole new platform


Windows 10 is not just a Windows 7 or 8 update. It is a whole new platform. The platform is called the Universal Windows Platform that is shortened to UWP. The platform includes the HoloLens, Tablet, PC, Laptop, Phone, IoT and more It is supposed to be one operating system for all your needs. Take Candy Crush Saga for example. It runs on Microsoft HoloLens, Mobile, PC and Surface Hub. It is the exact same app on all devices, and it scales perfectly. The same goes for Readit and many more apps. Develop once, run everywhere.

8. The Speed


Windows 10 is the most optimized Windows yet. It boots up instantly, opens apps quickly, and browses the web smoothly. It even handles tasks at heavy load better, because of new technologies Microsoft implemented into Windows 10, designed to bring your PCs performance to unfound heights.

9. Cortana


Cortana is a personal assistant, similar to Apple’s Siri. She is supposed to help in managing day-to-day tasks, remember things, find things and more. If you are in one of the supported countries, Cortana will sit on your taskbar, in Edge and appear in several other places, ready to lend a helping hand. She can easily be invoked by simply saying “Hey Cortana”, then commanded by telling her what you want. If you’re using Microsoft’s new Edge browser, she will sometimes give you coupons and codes for shopping websites, take care of flight tickets, find more information on objects and do so much more.

Windows 10 is getting better and better with every update released, and not upgrading to it while you have a chance to do so for free would be a bad idea. These are just some of the reasons for upgrading that we’ve collated, but there are so many more to discover – and with this being a continuously upgraded operating system, it would only improve further. For those who don’t upgrade while it is free, they may regret it at a later point, when their current system becomes archaic.

So I hope you will take a right decision after reading all these reasons..

