SyncCrypt: Neue Ransomware lauert in JPG-Dateien

heise online Newsticker - 23. August 2017 - 9:30
Um AV-Software auszutricksen, verbirgt sich die Ransomware SyncCrypt in Bilddateien. Einmal auf dem System, wird sie per Skript extrahiert und ausgeführt. Kostenlose Entschlüsselungs-Tools gibt es bislang nicht.

Amazee Labs: Tour de DrupAlps - Cycling the Alps to DrupalCon Vienna

Planet Drupal - 23. August 2017 - 9:14
Tour de DrupAlps - Cycling the Alps to DrupalCon Vienna

As per the extreme version of Tour de Drupal, my plan is to cycle from Switzerland to DrupalCon Vienna by crossing the Alps 6 times. The tour will take me over some of the most challenging Alp passes using my road cycle.

Josef Dabernig Wed, 08/23/2017 - 09:14

I’ll visit 5 different countries, including: Switzerland, Italy, Germany, Slovenia and Austria. Overcoming the Alps with the bicycle has been one of my long term dreams... Inspired by the sport achievements of my uncle, I am taking this challenge to see if I can make it from Switzerland to DrupalCon Vienna by taking some scenic and challenging detours over the Alps.

The final destination is DrupalCon Vienna which serves as the perfect goal because it’s my favorite conference and my hometown at the same time.

#DrupAlps in numbers

  • Days: 31
  • Distance: 2361 km
  • Total elevation gain: 57864 meters


Here is how I planned out the route so far

Depending on weather and physical conditions, I will adapt the route along the way while riding.


Over the last months, I have been riding various passes to get ready for the tour. Longer rides included St. Moritz - Splügenpass - Chur, Erstfeld - Oberalppass - Chur, and  Zurich - Vierwaldstättersee - Lucerne. In 2015, we cycled the Pyrenees as part of #TourDeDrupal Barcelona(1, 2, 3), early 2016 we cycled Sierra Nevada(1, 2) and later summer 2016 I cycled the biggest mountain of Austria on the Großglocknerstrasse.

Until now, I have no experience in cycling more than 3 consecutive days,  so I am really looking forward to seeing how it will go while being in the saddle for so many days in a row.

For DrupalCon Barcelona we cycled along the Pyrenees.

Amazee Extreme Challenge

“After three years of fulltime employment, our employees get one month off to free their mind and do something really extreme.”

I would like to thank Amazee for giving me this unique chance. Find out about what my colleagues are planning or have already accomplished at the Amazee Labs Extreme page.

DrupalCon Vienna

DrupalCon is the biggest Drupal conference, organized by the Drupal Association and will take place in Vienna from 26-29 September this year. I am especially looking forward to this one in my home town!

On Monday, there will be sprints, training sessions & summits organized by Drupal Austria.

Tuesday to Friday is packed with the official conference program and I am particularly excited about the site-building track, which I am a track chairing this year. Check out my blog post about what to expect from this week at DrupalCon.

Join Tour de Drupal

If you’d like to join my for the last few days of cycling, the last days are planned to be flat along the Danube river. For example, we plan to cycle from Linz to Krems on Saturday, 22nd of September. On Sunday, 23rd of September we go from Krems to Tulln where we will have a lunch break at the webshapers office. After that, we’ll cycle towards Vienna to arrive on Sunday afternoon.

Sign-up here and see my blog post for further details.

Follow me

Along the route, I will post regular updates about the ups and downs of the Tour de DrupAlps. To stay tuned, you can follow me here:

Ben's SEO Blog: A Drupal SEO Expert and a Drupal Developer Hit the Mat

Planet Drupal - 23. August 2017 - 9:01

[Photo credits: Ben Finklea, Jan 2017. Photos captured from iPhone video shot at Texas Grappling Challenge Brazilian Jiu-Jitsu tournament in Cedar Park, Texas.]

My Drupal developer friends and I (like any friendship) don’t always see eye-to-eye. While we have much in common—we both want stylish, high-performing websites—in some areas our goals are different. This can create the appearance of conflict. However, after working through the issues (or hitting the mats, as they say in Brazilian Jiu-Jitsu), we can find common ground and mutual respect.

In Drupal 8 SEO, I lay out a list of modules that should be installed on your Drupal website to enhance SEO. I wrote this book for marketers and provide the step-by-step details you need to increase Google ranking, website traffic... Read the full article: A Drupal SEO Expert and a Drupal Developer Hit the Mat

DLR und NASA suchen Flugzeug der Zukunft: Hybrid, leise und umweltfreundlich

heise online Newsticker - 23. August 2017 - 8:30
Das Deutsche Zentrum für Luft- und Raumfahrt suchte frische Ideen für die Luftfahrt der Zukunft.

Playerunknown's Battlegrounds: Xbox-Version kommt, 8 Millionen Verkäufe

heise online Newsticker - 23. August 2017 - 8:30
Der Multiplayer-Hit Playerunknown's Battlegrounds hat sich mehr als 8 Millionen mal verkauft. Nun haben die Entwickler eine Xbox-One-Version angekündigt.

Chinesischer Messagingriese will durch die Hintertür US-Markt erobern

heise online Newsticker - 23. August 2017 - 8:00
WeChat ist in China die Nummer eins, in Europa und den USA aber noch weit hinten. Bei der Markteroberung sollen nun chinesische Touristen helfen.

Netzwerkspeicher für zu Hause: Einplatinenrechner Odroid HC-1

heise online Newsticker - 23. August 2017 - 8:00
Günstige und leistungsstarke NAS- und Cluster-Lösungen verspricht der Hersteller Hardkernel mit der Einführung der neuen Modelle HC-1 und MC-1. Im Gegensatz zum Modell XU4 kommen die beiden ohne HDMI-Ausgang, USB-3-Ports und GPIO-Pins aus.

G20-Akkreditierungsentzug: Journalistenverbände beklagen Versagen und Willkür der Behörden

heise online Newsticker - 23. August 2017 - 7:30
Verwechslungen und Jugendsünden haben nach ersten Entschuldigungsschreiben der Bundesregierung dazu geführt, dass Zugangsberechtigungen von Pressevertretern für den G20-Gipfel aufgehoben wurden.

Sicherheitsupdate: Angreifer könnten Thunderbird lahmlegen

heise online Newsticker - 23. August 2017 - 7:00
In Thunderbird klaffen mehrere als kritisch eingestufte Sicherheitslücken. Die jüngst erschienene Version ist abgesichert.

Chrome Enterprise: Google will mit Chromebooks ins Unternehmen

heise online Newsticker - 23. August 2017 - 6:30
Google ist mit Chromebooks im US-Ausbildungsbereich erfolgreich und will nun auch Unternehmen erobern. Dabei soll das neue Lizenzprogramm Chrome Enterprise helfen. Eine der wichtigsten Neuerungen ist die Integration in Microsoft Active Directory.

Rundfunklizenzen für Streamer: "Medien sind keine Schraubenfabrik"

heise online Newsticker - 23. August 2017 - 6:30
Der Frage der Rundfunklizenzen sorgt für Beunruhigung bei YouTube- und Twitch-Streamern. Auch der Chef der Landesmedienanstalt NRW würde gerne die Vorschriften lockern, sieht aber seine Hände gebunden. Die Politik zeigt sich willig, ist aber langsam.

Programmiersprache: Ceylon-Projekt landet bei Eclipse Foundation

heise online Newsticker - 23. August 2017 - 6:30
Red Hat will die JVM-Sprache auf unabhängigere Beine stellen und ist mit der Eclipse Foundation übereingekommen, dass das Projekt zur Entwicklung von Ceylon ein neues Dach unter den Fittichen der Open-Source-Organisation bekommt.

Robotik- und KI- Experten warnen vor autonomem Kriegsgerät

heise online Newsticker - 23. August 2017 - 6:00
Seien autonome Waffen einmal in die Welt gesetzt, sei die Büchse der Pandora geöffnet, meinen Robotik- und KI-Experten. Die Zeit sei knapp, sich dagegen zu wehren.

Dries Buytaert: Reservoir, a simple way to decouple Drupal

Planet Drupal - 22. August 2017 - 22:52

Decoupled Drupal seems to be taking the world by storm. I'm currently in Sydney, and everyone I talked to so far, including the attendees at the Sydney Drupal User Group, is looking into decoupled Drupal. Digital agencies are experimenting with it on more projects, and there is even a new Decoupled Dev Days conference dedicated to the topic.

Roughly eight months ago, we asked ourselves in Acquia's Office of the CTO whether we could create a "headless" version of Drupal, optimized for integration with a variety of applications, channels and touchpoints. Such a version could help us build bridges with other developer communities working with different frameworks and programming languages, and the JavaScript community in particular.

I've been too busy with the transition at Acquia to blog about it in real time, but a few months ago, we released Reservoir. It's a Drupal-based content repository with all the necessary web service APIs needed to build decoupled front-end applications, be it a React application, an Ember front end, a native application, an augmented reality application, a Java or .NET application, or something completely different. You can even front-end it with a PHP application, something I hope to experiment with on my blog.

API-first distributions for Drupal like Reservoir and Contenta are a relatively new phenomenon but seem to be taking off rapidly. It's no surprise because an API-first approach is critical in a world where you have to operate agnostically across any channel and any form factor. I'm convinced that an API-first approach will be a critical addition to Drupal's future and could see a distribution like Reservoir or Contenta evolve to become a third installation profile for Drupal core (not formally decided).

Decoupled Drupal for both editors and developers The welcome screen after installing Reservoir.

The reason decoupled Drupal is taking off is that organizations are now grappling with a multitude of channels, including mobile applications, single-page JavaScript applications, IoT applications, digital signage, and content driven by augmented and virtual reality. Increasingly, organizations need a single place to house content.

What you want is an easy but powerful way for your editorial team to create and manage content, including administering advanced content models, content versioning, integrating media assets, translations, and more. All of that should be made easy through a great UI without having to involve a developer. This, incidentally, is aligned with Drupal 8's roadmap, in which we are focused on media management, workflows, layouts, and usability improvements through our outside-in work.

At the same time, you want to enable your developers to easily deliver that content to different devices, channels, and platforms. This means that the content needs to be available through APIs. This, too, is aligned with Drupal 8's roadmap, where we are focused on web services capabilities. Through Drupal's web service APIs, developers can build freely in different front-end technologies, such as Angular, React, Ember, and Swift, as well as Java and .NET. For developers, accomplishing this without the maintenance burden of a full Drupal site or the complexity of configuring standard Drupal to be decoupled is key.

API-first distributions like Reservoir keep Drupal's workflows and editorial UI intact but emphasize Drupal's web service APIs to return control to your developers. But with flexible content modeling and custom fields added to the equation, they also give more control over how editors can curate, combine, and remix content for different channels.

Success is getting to developer productivity faster Reservoir includes side-by-side previews of content in HTML and JSON API output.

The goal of a content repository should be to make it simple for developers to consume your content, including digital assets and translations, through a set of web service APIs. Success means that a developer can programmatically access your content within minutes.

Reservoir tries to achieve this in four ways:

  1. Easy on-boarding. Reservoir provides a welcome tour with helpful guidance to create and edit content, map out new content models, manage access control, and most importantly, introspect the web service APIs you'll need to consume to serve your applications.
  2. JSON API standard. Reservoir makes use of JSON API, which is the specification used for many APIs in JSON and adopted by the Ember and Ruby on Rails communities. Using a common standard means you can on-board your developers faster.
  3. Great API documentation. Reservoir ships with great API documentation thanks to OpenAPI, formerly known as Swagger, which is a specification for describing an API. If you're not happy with the default documentation, you can bring your own approach by using Reservoir's OpenAPI export.
  4. Libraries, references, and SDKs. With the Waterwheel ecosystem, a series of libraries, references, and SDKs for popular languages like JavaScript and Swift, developers can skip learning the APIs and go straight to integrating Drupal content in their applications.
Next steps for Reservoir API documentation auto-generated based on the content model built in Reservoir.

We have a lot of great plans for Reservoir moving forward. Reservoir has several items on its short-term roadmap, including GraphQL support. As an emerging industry standard for data queries, GraphQL is a query language I first highlighted in my 2015 Barcelona keynote; see my blog post on the future of decoupled Drupal for a quick demo video.

We also plan to expand API coverage by adding the ability to programmatically manipulate users, tags, and other crucial content elements. This means that developers will be able to build richer integrations.

While content such as articles, pages, and other custom content types can be consumed and manipulated via web services today, upstream in Drupal core, API support for things like Drupal's blocks, menus, and layouts is in the works. The ability to influence more of Drupal's internals from external applications will open the door to better custom editorial interfaces.


I'm excited about Reservoir, not just because of the promise API-first distributions hold for the Drupal community, but because it helps us reach developers of different stripes who just need a simple content back end, all the while keeping all of the content editing functionality that editorial teams take for granted.

We've put the Reservoir codebase on GitHub, where you can open an issue, create a pull request, or contribute to documentation. Reservoir only advances when you give us feedback, so please let us know what you think!

Special thanks to Preston So for contributions to this blog post and to Ted Bowman, Wim Leers, and Matt Grill for feedback during the writing process.

Noch 10 Tage iX-Awareness-Wettbewerb

heise online Newsticker - 22. August 2017 - 20:00
Um kreative Lösungen bei der Stärkung des Sicherheitsbewussteins geht es beim iX-Awareness-Wettbewerb. Bis zum 31. August kann man noch Beiträge einreichen.

Smhax: Hacker dringen weiter in Spielkonsole Switch vor, Nintendo hält dagegen

heise online Newsticker - 22. August 2017 - 19:30
Eine jüngst entdeckte Sicherheitslücke könnte zur Übernahmen der Konsole führen. Nintendo hat die Schwachstelle bereits gepatcht.

DrupalEasy: How do I learn Drupal?  Let me count the ways.

Planet Drupal - 22. August 2017 - 18:22

Resources to learn Drupal are many and certainly vary in delivery, focus and quality. When you are trying to figure out the best way to train up, considerations like schedules, learning styles, and trainer reputations play pretty heavily. You also need to look at the program and compare it to what you already know, what you need to know, and what you should know to get into practice as quickly possible. One of the biggest obstacles is often finding, and then choosing the training program(s) that are right for you, and perhaps your team. But what if you didn’t have to choose?

Drupalize.Me and DrupalEasy are proud to announce that we are making it easier to get trained up in Drupal in a way that helps overcome challenges, meets needs, and addresses the different ways people learn. We are bundling our training programs and resources beginning with DrupalEasy’s Fall 2017 session of Drupal Career Online. The DCO will include access to all of the thousands of tutorials during the 12-week course, and a deeply discounted subscription after graduation. Current Drupalize.Me subscribers will also receive a special Drupalize.Me tuition rate for this and any future sessions of the DCO.

Drupalize.Me’s Addison Berry came up with the partnership idea as a way to help the community grow by helping along the learning process of people who can more quickly become solid developers.  Addi says, “Any way we can make it easier, and better for people to get quality training to become developers is good for the community, and good for all of us.”  In addition to providing comprehensive Drupal training that focuses on best practices, Drupalize.Me and DrupalEasy share a love of building the Drupal talent base across the world.

Drupalize.Me provides a premium, membership-based training library of thousands of tutorials divided into specific pathways according to your learning goals.  It is trusted by users around the world, and backed by Lullabot, one of the top open source strategy, design, and development companies.

DrupalEasy has been offering instructor-led comprehensive Drupal career technical education (the first of its kind) programs since 2011, launching the 12-week, 132 hour Drupal Career Online program in 2015. The DCO ensures individuals and teams can rely on expert live instruction, office hours and mentorship, expansive learning resources, and a curriculum that thoughtfully stacks skills and emphasizes best practices to ensure graduates have the best possible foundation to become practicing Drupal developers.

The first session of Drupal Career Online that includes unfettered access to the Drupalize.Me’s tutorials in the Site Building, Theming and Development learning pathways begins October 2, with an application deadline of September 26th.  To learn more and get an idea of the DrupalEasy learning platform, sign up for one of two Taste of Drupal free information sessions in August and September or contact DrupalEasy.    




Abgas-Skandal: Ingenieur belastet Audi-Vorstand

heise online Newsticker - 22. August 2017 - 18:00
Ein verhafteter Audi-Mitarbeiter hat die Konzernführung schwer belastet: Frühere und jetzige Vorstände des Autohersteller sollen von der Dieselproblematik gewusst haben – manche Spitzenmanager auch von Softwaremanipulationen.

AMD-Grafikkarte Radeon RX Vega 64 teurer als erwartet

heise online Newsticker - 22. August 2017 - 17:00
Die meisten Testberichte der seit einer Woche verkauften Radeon RX Vega gingen von einem Preis um 500 US-Dollar beziehungsweise Euro aus, tatsächlich sind es 650 Euro.

Reingeschaut: POV-Fidget-Spinner

heise online Newsticker - 22. August 2017 - 17:00
POV-Fidget-Spinner vereinen zwei Trends: Trägheitsbilder erzeugen, um dem Auge eine geschlossene Fläche vorzugaukeln, und einen Zeitvertreib für nervöse oder unruhige Mitmenschen. Wir haben in ein Billigmodell reingeschaut.