Friday, September 19, 2025

Software Security

Security is an essential part of software construction. It may become harder to retrofit security in a developed software. There are fantastic resources to learn software security from. Please find list of resources I stumbled upon:
 

Introduction to Software Security by Elisa Heymann and Barton P. Miller

https://research.cs.wisc.edu/mist/SoftwareSecurityCourse/

A second one is Software Security On-line Course, https://mhicks.me/software_security_course/

 

A great read for a book, Software Security: Principles, Policies, and Protection (SS3P, by Mathias Payer), https://nebelwelt.net/SS3P/

 

For practical perspectives we can choose to follow OWASP Development Guide from  

https://devguide.owasp.org/

 

Professional certification related to software security is the ISC2 Certified Secure Software Lifecycle Professional (CSSLP)

https://www.isc2.org/certifications/csslp

 

Tuesday, August 19, 2025

How to prepare for ITEE Examination

The Information Technology Engineers Examination (ITEE) is a set of vendor neutral international IT examinations held in multiple Asian countries. These examinations are held by the government of each participating country as their national IT certification through the international IT Professionals Examination Council (ITPEC). These are comprehensive exams related to computer science or IT combined with expected skills for jobs. ITEE is an international certification based on Japanese IT standards and also is a national certification of the Bangladesh Government. 

The examination has multiple levels:

  • Level 1: IT Passport Examination (IP)
  • Level 2: Fundamental IT Engineer Examination (FE)
  • Level 3: Applied IT Engineer Examination (AP)
  • Level 4: Advanced Examination (AE)

In Bangladesh, level 1 and level 2 exams are organized by Bangladesh IT Examination Council (BDITEC) under Bangladesh Computer Council (BCC), Bangladesh Government.

Syllabus:

The exam has no negative marking. Level 1 and 2 have multiple choice questions (MCQ) only. The level 2 (FE) exam has two parts: subject A: morning and subject B: afternoon. Regardless of the performance in the morning exam/subject A, please still attend the afternoon exam/subject B in full. Passing in any part, will help in attending the remaining part during the next two times if required. The exam is held two times a year. Dates and past questions are available at the ITPEC website: https://itpec.org/

CS/CSE students in their 6th semester and onwards are strongly encouraged to register for Level-2: FE Exam (Subject A Morning & Afternoon) from http://registration.bditec.gov.bd/

Students from any department or study program in their 1st to 5th semesters are encouraged to register for Level-1: IT Passport Exam (IP) from http://registration.bditec.gov.bd/
 

I would recommend starting to practice with Bismillah from the past few exam questions:

Good support is available via the Facebook group, ITEE FE(level-2) Candidate only: https://www.facebook.com/groups/itee.fe

Anybody posting a question or its picture there usually gets quick responses. It is a good place to network with past passers as well. Its files sections have some practice materials too: https://www.facebook.com/groups/itee.fe/files/files

Registration and preparation/practice books are at https://registration.bditec.gov.bd/

Free training/e-learning materials are available at Lightboat: https://lightboat.lightworks.co.jp/en-promotion


In-person trainings are organized by BCC in some universities and sometimes at BCC almost every year around the registration month. 

Analysis of some past questions maybe available at the translated website fe-siken.com: https://www-fe--siken-com.translate.goog/?_x_tr_sl=ja&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp

Further recommended reading:


Cloud/Utility/Service computing
Slide: https://www.usenix.org/legacy/events/lisa09/tech/slides/fox.pdf

Report: https://www2.eecs.berkeley.edu/Pubs/TechRpts/2009/EECS-2009-28.pdf






URL spec 

Cybersecurity

LinkedList item removal: 

Floating point guide: 

SQL query join types

References:

Sunday, November 24, 2024

Changing default browswer on RedHat

Default Firefox browser on RedHat was last updated to 115.7.0esr (Extended Support Release), titled Mozilla Firefox for Fedora, Fedora - 1.0 (?)

As obvious, this browser is not supported by many web-applications. There is difficulty in YouTube playbacks as well.

An alternative was to use Flatpak (https://en.wikipedia.org/wiki/Flatpak) based Firefox. However, the default firefox was set as

[user@localhost ~]$ xdg-settings get default-web-browser
firefox.desktop

However, the desktop file for the Flatpak based Firefox is located at /var/lib/flatpak/exports/share/applications/org.mozilla.firefox.desktop

To change to the Flatpak based Firefox,

[user@localhost ~]$ xdg-settings set default-web-browser org.mozilla.firefox.desktop
 

The change can be verified using 

[user@localhost ~]$ xdg-settings check default-web-browser org.mozilla.firefox.desktop
yes


It worked! 


Credits:

https://unix.stackexchange.com/questions/614899/setting-a-flatpak-app-as-the-default-web-browser

Wednesday, June 19, 2024

Data Visualization

 Seeing is believing! Having proper visualization is a key part of communication skills. Understanding data, reports, news depends on how well the information was visualized. There are many tools and techniques for data visualization. Some are listed below:

Tools

Books:

Study topics:

  • Descriptive and inferential statistics
  • Exploratory Data Analysis (EDA)
  • Color science

Tuesday, February 27, 2024

Websites for learning

 E-learning has become an essential part of self development to upgrade ourselves. Some websites provide both training and certifications that we can add to our CV or LinkedIn profile. Other website websites allow skilling up for free. Let's learn something for fun or for potential future benefit. It may be beneficial to have and not need than need and not have. Let us learn as much as possible so that when the opportunities arrive, we can utilize them. Let's learn something ...

General:

 

AI

 

Statistical Learning:

Cybersecurity:

 

Web

 

Creative

  

Finding courses across multiple websites

 

Getting started with key courses

Monday, October 9, 2023

Recommendation Letter or Reference Letter for Higher Education or Jobs

Recommendation or reference letters are often required for higher education or job opportunities. If the teachers are provided with correct information about ourselves, like student ID, courses, semesters, etc. where they had the opportunity to observe or supervise us, it would be convenient for them to help us by providing a Letter of Recommendation (LoR). A teacher may have taught multiple students having the same full name! It is recommended to approach teachers at least one month before it is needed, sometimes even more.

This blog post is not just a heads-up for the related processes but also tries to provide a guideline for the students. It may be helpful for us so that we can start preparation in our freshmen years. Hopefully, by the time we graduate, we can confidently approach a teacher or supervisor as a potential recommender, insha'Allah!

Some teachers may prefer supplementary information as email attachments. Others may prefer that everything be in an online cloud drive folder, which is recommended. It could be Dropbox, Google Drive, OneDrive, etc. However, in addition to remembering to provide view access, we should ensure that it is downloadable by the recommender without requiring a login. We can verify this through the incognito or private browsing mode of the web browser.

The folder should be well organized. An example of such file organization or directory/folder structure could be like this:

File 1) Transcript/grade sheet in PDF (ensure good image quality)

File 2) Detailed CV with photo in a DOC or PDF file

File 3) Our official full name and other student Information in an editable DOC. This file may contain different segments, as suggested below:

3A) All of our university student ID numbers and email addresses, in case we had multiple student IDs and used multiple email addresses, and optionally primary and secondary mobile/cell phone numbers..

3B) Since which calendar year, semester, and month, the teacher or supervisor knows the student or supervisee? Also the year and month of last contact.

3C) In which semesters er took which courses with the teacher, received what grade, and what was the teacher's role (theory or lab or research/project/RA/TA supervision/advisor)? How did we do in those courses, including teamwork, challenges, strengths, recovery, contribution to learning, etc.?

3D) Highlight your study, teaching, and research related interactions/skills.

3E) A short summary of all co or extracurricular or voluntary/self-learning activities that we attended, participated in, organized, volunteered, etc. If we are from the Computer Science (CS) department or applying for CS or IT-related opportunities, it might be helpful to highlight the Computer Club, the CS department, or science and technology-related events.

3F) Mention our skills in leadership and networking, personal, intellectual, and interpersonal qualities, communication skills, academic and research abilities, our special administrative abilities, ability to complete a demanding academic program, time management skills, ability to handle pressure, failure, or rejection, etc. Provide examples where we demonstrated those skills and abilities as proof, where appropriate. Have we ever struggled in life? How have we managed or recovered, or are doing so?

File 4) Institution Details:
In case we are applying to multiple institutions, for every university and program that we are applying to, we may wish to prepare and include a table or link to a spreadsheet containing the following columns:
  • Name of the university and campus
  • University and campus URLs
  • What is our applicant or student ID?
  • Session name
  • Degree type (MS/PhD or B.Sc. in the case of credit transfer)
  • Department and program name,
  • Application Deadline
  • Recommendation Letter Deadline
  • Link to the application portal
  • Sent the recommendation letter request to the teacher? (yes/no)
  • Date we sent the recommendation letter request, or when should the teacher expect the email?
  • Sender university email domain (e.g., gradadmission.mars.stanford.edu)
  • Completed application from our side? (yes/no)
  • Submission procedure (they will email the teacher directly or we as a student will upload PDF)
  • Why do we think we are a match for that university? (It is recommended to apply to universities matching your profile, as well as higher level to be ambitious and lower level to be failsafe)


File 5) It might be helpful for the teacher if we could include an editable draft DOC containing a list of facts about your past interactions and exposure for the purpose of the detailed letter of recommendation (LOR) or job reference. Do NOT write/draft the letter itself. Boasting or inaccurate details might hamper negatively. Admissions committees are experienced enough to find inconsistencies in an applicant's profile. Moreover, admission is not everything; surviving a demanding program requires a lot of background preparation as well. So, prepare early in real life, not just in the letter. Universities or institutions would NOT like drafts prepared by applicants or any involvement during the submission process. So, let us not expect our teacher to cover all the areas mentioned in the list or even take help from our list at all. It could simply be skimmed by teachers' to cross-check if anything went missing in their version. While preparing this list, do NOT blindly copy LOR from others or internet samples to avoid adverse effects. Take ideas, learn the structure, but draft your own unique one to make it stand out to the teacher. If we are sending the draft to multiple teachers, it should be separate and unique for each teacher, personalizing it to the point how we interacted with that teacher and demonstrated performance or stood out. Ideally, it should be unique for each university as well. Highlight how we would be a match (good fit) for the selected universities and the selected programs/degrees. Additionally, may wish to highlight how we, our country, the university, the country it is located in, all would be mutually benefited in the short and the long.


Some examples of LOR:

Examples of job references or recommendations:


File 6)  In an editable DOC, include a draft of our Statement of Purpose (SOP) or Statement of Interest (SOI), Letter of Intent (LoI), job cover letter, or motivation letter.

SOP:

Cover Letter or Job Motivation Letter:


For additional information,
We might wish to create one folder containing certifications, international exam results, independent projects or even how others who are studying/studied at the same university inspired you. If we wish to add additional information, we can create additional folders. So, our Google Drive will contain six files and one or more folders mentioned above.


For filling out the online forms, we might need the following details:

  • Full name of the teacher, or the first name and last name separately.
  • Current designation (please avoid remembering and look up the latest one)
  • Official email address.
  • Office Phone number
  • Personal cell or mobile number
  • Mailing address with post code and country

It might be helpful to notify and regularly follow up with the teacher using the email thread after applying to each university or company until we receive each one. Perhaps gentle reminders once a week followed by an in-person visit to confirm if anything else is needed.

No matter how curious we are to know what the teacher wrote about us, we may wish to waive our right to view the recommendation letter during your application. It may improve the quality of your application. Some institutions may not consider “not waiving the right to view or FERPA rights” positively as discussed by:

In addition to using the same email thread instead of composing new emails every time, following some email etiquette may make a difference. For details, please read:
http://annajiat.blogspot.com/2021/07/dos-and-donts-of-academic-emails.html

While writing the drafts or even the email, please review our writing style with different tools. Some are listed at https://sites.google.com/site/annajiat/writing-style

Please see if we can try to notify the teacher of each job or university acceptance letter that you receive via this email thread. Teachers will be glad to see that their contribution made a difference in your life.

What questions do we have? Let's not hesitate. Email our teacher right away be it for queries or letter! 

May Allah bless everyone with success and ease.
Jazak Allahu Khayran

Tuesday, August 29, 2023

Cybersecurity as a study field, hobby, and as a profession

Cybersecurity has been gaining popularity among the students and researchers from various disciplines as a study field. There are many international vendor certificates are available in addition to bachelors, masters, and, of course, PhD and post doc fellowships. The job market also looks promising as there has been a shortage of qualified technical personnel. Though the profession may take a lot of commitment and dedication, however it certainly could start as a hobby.

  

Certifications:

 

Example of research papers, projects, articles, blogs:

Saturday, October 8, 2022

Islamic or Hijri or Hegira calendar

The support for Islamic or Hijri or Hegira calendar in software and standards has improved a lot. The followings provide some references which might be helpful to implement various calendar support, which is crucial if the software or service is to have an international user base.


Unicode Common Locale Data Repository (CLDR) project:


Java Documentation:


USNO Intro to Calendars: 


 UK Hydrographic Office: 


Wikipedia:


Unicode Locale Data Markup Language (LDML):


Saturday, September 17, 2022

Research Training: What trainings are available for researchers?

There are some free courses available from different publishers related to research training. Please see if you can complete those courses and earn the certificates, if any:


With a certificate or not, there are many free courses are available online on different research skills including quantitative/qualitative/mixed-research methodology, writing, other parts of research

 

Writing:



Monday, August 15, 2022

Changing email address used in a Google group

Say we have two email addresses:

  • existing_email@gmail.com
  • new_email@gmail.com


We are receiving emails in existing_email@gmail.com from a Google group, say called "bucc"

We would like to change the email address to "new_email@gmail.com"


How can we do so?


Step 1)

 Add your other email address, new_email@gmail.com as your alternate email address to your existing google from

https://myaccount.google.com/alternateemail


Step 2)

Go to the google group and click "my membership settings"

https://groups.google.com/g/<group name here>/membership

and change email address to that alternate email address, new_email@gmail.com


Sunday, July 11, 2021

DOs and Don'ts of Academic Emails / Email Etiquettes / Manners

Writing a proper email increases our chance of getting a reply. Especially including a proper email subject, proper identification, background, etc. For example, in case of a student, official full name, student ID, course, section, etc. Even though this blogpost uses examples from academic scenario, some parts may be applicable to other environments as well. 

We should not be expecting a reply from our email recipients within a very short time. We may choose to wait at least a day before following up or longer as appropriate.  

On the other hand, depending on the volume of emails we receive, we might decide to check emails at least five times a day.

There is a difference between "compose" and "reply".

We should compose new emails with a different and appropriate subject, only while we are talking about a new topic / subject.

When talking about a different topic, then we may decide to click "compose" and write the email with a proper subject.

When talking about an older and same topic, please open the last email that was exchanged about the same topic and click reply and then write there.

For example, when talking about makeup midterm exams, the steps could be
a) find/open the last email that was exchanged about makeup midterms
b) click reply
c) delete email body (quote only relevant lines / clauses)
d) delete everything from TO field and ensure that only the email
address (or the address of intended recipient) is written there
e) do not touch the subject field

We need to separate our paragraphs in an email instead of combining everything into one paragraph.

Repeated characters like ...., ????, !!!!!!!! should be avoided.

In short, we should not use any sentence structure that we would not find in any formal and non-literary academic text book.

Other email etiquette:
1. Email should include details about the sender, e.g., full name, id, course, section and additional details so that the email recipient does not have to ask for it.


2. Punctuations (!, ?, etc) may be used only once.
CAPITAL/UPPERCASE words should be avoided
Informal/chat language should be avoided.

Here are some examples:
Correct: Please, find the java files attached and help me.
Incorrect: PLZZ u nid 2 hlp meh, fnd progs att.

Correct: I don't know!
Incorrect: I don't know!!!!

Correct: How to contact the Student Tutor?
Incorrect: How to contact Student Tutor????

Correct: Need help on flowchart
Incorrect: HELP FLOWCHARTS, NOT UNDERSTANDING


3. Use proper and short subject: do not leave it empty or make it too long
Examples of proper  email subjects:
  • Facing problem in Input/Output
  • Need help on Array
  • Urgent: Need B negative blood donors

urgent
emergency
very important
(blank)
please read
Need help
help
problem
mail
about a problem
query
question
I actually need help please my query badly


4. Read the mail several times before sending, correct spelling, grammar, tone.
We might wish to enable the spell and grammar checking options (if any) in our favorite web browser or utilize add-ons/extensions or other software. For example:
5. If we are telling about a problem, we should tell in details, what question or problem
we tried to solve,  how we tried, along with detailed error message,
steps to reproduce the problem. Just like doctors cannot give medicine
to people who says "i'm not feeling well" only, we need to mention
specific symptoms with as much details as possible.


6. Attach proper files
Attach PY / IPYNB / relevant files.
Attach only JAVA files, NOT java~ or class files.

More details are available at
http://sites.google.com/site/bucse110/correctjavafile


7. Why not learn more? Here are some more resources,

How to ask questions?

Alternative Desktop Shell for Windows

Windows shell from Microsoft is not the only desktop shell available for Windows. You might wish to try the alternative Desktop Shell for Windows like Cairo Desktop, Blackbox for Windows (xoblite), etc. These shells provides their own start menu, taskbar, desktop, an overall different experience while using Windows. For those who would like to try out if using a different shell increases your productivity or not, this could be the time to check those out.

Here are the links for two choices mentioned above that were found to be working in Windows 10 at the time of writing this blog post.

Cairo Desktop 
Preview/screenshots are from its homepage. Please visit that page to find the most updated screenshots/previews.










Blackbox for Windows (xoblite)

Download       Update       Homepage      Preview

Preview/screenshots are from its homepage/forums. Please visit those page to find the most updated screenshots/previews.





Can anyone suggest alternatives that are in active development?


Disclaimer: Copyright of all the images and software belong to the respective owners.

Sunday, May 16, 2021

Bandwidth friendly teaching and learning

For those of us who are facing bandwidth issues, we may try (and remember to undo if we face additional problems) the followings for low bandwidth teaching and learning

  • using different devices: may be PC for sharing screen and phone for audio
  • reducing number of devices that are using the shared internet bandwidth
  • keeping the video off, at least while not speaking
  • unmuting only while speaking

  • summarizing things that we are saying to the chat during the section to manage intermittent audio problems for some participants

  • posting a summary at the end of each session so that those who could not attend can still have some discussion notes

  • offering additional office timings if the situation permits

  • reducing our own resolution and window size while presenting

  • sharing screen or staying in the collaborative workspace, only when necessary.

  • closing other browser tabs

  • closing other background apps, cloud drive syncing apps, specially the ones visible near the clock e.g., One Drive, Google Drive, DropBox, etc.

  • using incognito or private-browsing mode to temporarily avoid potentially interfering browser extensions or temporarily disabling all browser extensions, specially adblockers

  • restarting computer / device

  • restarting browser

  • reloading the browser page

  • temporarily turning OFF browser's "sync" option for settings

  • if using Google meet, setting send and receive resolution to 360p and turning on Closed Captioning (CC)

  • if using Zoom, disabling HD and other tips, turning ON free zoom live captioning, and disabling profile pictures

  • if using Spacial Chat, please see SpatialChat-Recommended-System-Settings

  • stopping the recording (if any) by (co)host(s)

  • rejoining the meeting might help with intermittent problems e.g., missing shared screen/audio

  • if on Windows, temporarily


Additional resources: