Skip to main content

Home/ Open Web/ Group items tagged weight

Rss Feed Group items tagged

Paul Merrell

The Million Dollar Dissident: NSO Group's iPhone Zero-Days used against a UAE Human Rig... - 0 views

  • 1. Executive Summary Ahmed Mansoor is an internationally recognized human rights defender, based in the United Arab Emirates (UAE), and recipient of the Martin Ennals Award (sometimes referred to as a “Nobel Prize for human rights”).  On August 10 and 11, 2016, Mansoor received SMS text messages on his iPhone promising “new secrets” about detainees tortured in UAE jails if he clicked on an included link. Instead of clicking, Mansoor sent the messages to Citizen Lab researchers.  We recognized the links as belonging to an exploit infrastructure connected to NSO Group, an Israel-based “cyber war” company that sells Pegasus, a government-exclusive “lawful intercept” spyware product.  NSO Group is reportedly owned by an American venture capital firm, Francisco Partners Management. The ensuing investigation, a collaboration between researchers from Citizen Lab and from Lookout Security, determined that the links led to a chain of zero-day exploits (“zero-days”) that would have remotely jailbroken Mansoor’s stock iPhone 6 and installed sophisticated spyware.  We are calling this exploit chain Trident.  Once infected, Mansoor’s phone would have become a digital spy in his pocket, capable of employing his iPhone’s camera and microphone to snoop on activity in the vicinity of the device, recording his WhatsApp and Viber calls, logging messages sent in mobile chat apps, and tracking his movements.   We are not aware of any previous instance of an iPhone remote jailbreak used in the wild as part of a targeted attack campaign, making this a rare find.
  • The Trident Exploit Chain: CVE-2016-4657: Visiting a maliciously crafted website may lead to arbitrary code execution CVE-2016-4655: An application may be able to disclose kernel memory CVE-2016-4656: An application may be able to execute arbitrary code with kernel privileges Once we confirmed the presence of what appeared to be iOS zero-days, Citizen Lab and Lookout quickly initiated a responsible disclosure process by notifying Apple and sharing our findings. Apple responded promptly, and notified us that they would be addressing the vulnerabilities. We are releasing this report to coincide with the availability of the iOS 9.3.5 patch, which blocks the Trident exploit chain by closing the vulnerabilities that NSO Group appears to have exploited and sold to remotely compromise iPhones. Recent Citizen Lab research has shown that many state-sponsored spyware campaigns against civil society groups and human rights defenders use “just enough” technical sophistication, coupled with carefully planned deception. This case demonstrates that not all threats follow this pattern.  The iPhone has a well-deserved reputation for security.  As the iPhone platform is tightly controlled by Apple, technically sophisticated exploits are often required to enable the remote installation and operation of iPhone monitoring tools. These exploits are rare and expensive. Firms that specialize in acquiring zero-days often pay handsomely for iPhone exploits.  One such firm, Zerodium, acquired an exploit chain similar to the Trident for one million dollars in November 2015. The high cost of iPhone zero-days, the apparent use of NSO Group’s government-exclusive Pegasus product, and prior known targeting of Mansoor by the UAE government provide indicators that point to the UAE government as the likely operator behind the targeting. Remarkably, this case marks the third commercial “lawful intercept” spyware suite employed in attempts to compromise Mansoor.  In 2011, he was targeted with FinFisher’s FinSpy spyware, and in 2012 he was targeted with Hacking Team’s Remote Control System.  Both Hacking Team and FinFisher have been the object of several years of revelations highlighting the misuse of spyware to compromise civil society groups, journalists, and human rights workers.
Paul Merrell

YouTube To Censor "Controversial" Content, ADL On Board As Flagger - 0 views

  • Chief among the groups seeking to clamp down on independent media has been Google, the massive technology company with deep connections to the U.S. intelligence community, as well as to U.S. government and business elites.
  • Since 2015, Google has worked to become the Internet’s “Ministry of Truth,” first through its creation of the First Draft Coalition and more recently via major changes made to its search engine that curtail public access to new sites independent of the corporate media.
  • Google has now stepped up its war on free speech and the freedom of the press through its popular subsidiary, YouTube. On Tuesday, YouTube announced online that it is set to begin censoring content deemed “controversial,” even if that content does not break any laws or violate YouTube’s user agreement. Misleadingly dubbed as an effort “to fight terror content online,” the new program will flag content for review through a mix of machine algorithms and “human review,” guided by standards set up by “expert NGOs and institutions” that are part of YouTube’s “Trusted Flagger” program. YouTube stated that such organizations “bring expert knowledge of complex issues like hate speech, radicalization, and terrorism.” One of the leading institutions directing the course of the Trusted Flagger program is the Anti-Defamation League (ADL). The ADL was initially founded to “stop the defamation of the Jewish people and to secure justice and fair treatment to all” but has gained a reputation over the years for labeling any critic of Israel’s government as an “anti-Semite.” For instance, characterizing Israeli policies towards the Palestinians as “racist” or “apartheid-like” is considered “hate speech” by the ADL, as is accusing Israel of war crimes or attempted ethnic cleansing. The ADL has even described explicitly Jewish organizations who are critical of Israel’s government as being “anti-Semitic.”
Paul Merrell

Here comes Google TV - Google TV Blog - 0 views

  • It’s been almost five months since we introduced Google TV to the world at Google I/O, and today we’re happy to give you an update on our progress. For those who haven’t yet heard of it, Google TV is a new way to think about TV: it’s a platform that combines your current TV programming and the open web into a single, seamless entertainment experience.One of our goals with Google TV is to finally open up the living room and enable new innovation from content creators, programmers, developers and advertisers. By bringing Google Chrome and access to the entire Internet, you can easily navigate to thousands of websites to watch your favorite web videos, play Flash games, view photos, read movie reviews or chat with friends—all on the big screen. Since our announcement, we’ve been overwhelmed by interest from partners on how they can use the Google TV platform to personalize, monetize and distribute their content in new ways. Most of these partner sites already work with Google TV, but many are choosing to further enhance their premium web content for viewing on the television.
  • You can get a sneak peek of some of these apps in the video below:
  • Today we also launched a new website that provides more information about these apps and all of the other great features of Google TV.We’re really excited about the enthusiasm surrounding the platform and can’t wait for it to reach your living room. Devices powered by Google TV will launch this month, so look out for more information in the next few weeks from Sony on its Internet TV and Blu-Ray player, and Logitech on its companion box.
Paul Merrell

Social Media Giants Choking Independent News Site Traffic to a Trickle - 0 views

  • Several prominent figures, including Web inventor Tim Berners-Lee, warned the EU Parliament that its proposed censorship measure would begin transforming the Internet from an open platform for sharing and innovation, into a tool for the automated surveillance and control of its users.
  • For much of the year, independent media has felt the sting of increased social media censorship, as the “revolving door” between U.S. intelligence agencies and social-media companies has manifested in a crackdown on news that challenges official government narratives. With many notable independent news websites having shut down since then as a result, those that remain afloat are being censored like never before, with social media traffic from Facebook and Twitter completely cut off in some cases. Among such websites, social media censorship by the most popular social networks is now widely regarded to be the worst it has ever been – a chilling reality for any who seek fact-based perspectives on major world events that differ from those to be found on well-known corporate-media outlets that consistently toe the government line. Last August, MintPress reported that a new Google algorithm targeting “fake news” had quashed traffic to many independent news and advocacy sites, with sites such as the American Civil Liberties Union, Democracy Now, and WikiLeaks, seeing their returns from Google searches experience massive drops. The World Socialist Website, one of the affected pages, reported a 67 percent decrease in Google returns while MintPress experienced an even larger decrease of 76 percent in Google search returns. The new algorithm targeted online publications on both sides of the political spectrum critical of U.S. imperialism, foreign wars, and other long-standing government policies. Now, less than a year later, the situation has become even more dire. Several independent media pages have reported that their social media traffic has sharply declined since March and – in some cases – stopped almost entirely since June began. For instance, independent media website Antimedia – a page with over 2 million likes and follows – saw its traffic drop from around 150,000 page views per day earlier this month to around 12,000 as of this week. As a reference, this time last year Antimedia’s traffic stood at nearly 300,000 a day.
Paul Merrell

Was Destructive 'Slingshot' Malware Deployed by the Pentagon? | The American Conservative - 0 views

  • Earlier this March, cyber-security firm Kaspersky Labs released information on a newly discovered, highly advanced piece of malware dubbed Slingshot. The malware targeted Latvian-made Internet routers popular in the Middle East, Africa, and Southeast Asia. Kaspersky’s reports reveal that the malware had been active since at least 2012, and speculates that it was government-made, owing to its sophistication and its use of novel techniques rarely seen elsewhere. Those investigating the matter further have drawn the conclusion that Slingshot was developed by the U.S. government, with some reports quoting former officials as connecting it to the Pentagon’s JSOC special forces. For those following the cyber security and malware sphere, this is a huge revelation, putting the U.S. government in the hot seat for deploying cyber attacks that harm a much greater range of innocent users beyond their intended targets. Kaspersky’s own findings note that the code was written in English, using a driver flaw to allow the implanting of various types of spyware. Among those mentioned by Moscow-based Kaspersky was an implant named “GOLLUM,” which notably was mentioned in one of the leaked Edward Snowden documents. Further findings suggest that Slingshot had common code with only two other known pieces of software, both malwares, which were attributed to the NSA and CIA, respectively, by analysts. Though various U.S. agencies are all denying comment, things are clearly pointing uncomfortably in their direction.
Paul Merrell

A New Era of Mass Surveillance is Emerging Across Europe | Just Security - 0 views

  • The world was a different place when, in October 2015, the Court of Justice of the European Union (CJEU) struck down the “Safe Harbour” data-sharing agreement that allowed the transfer of European citizens’ data to the US. The Court’s decision concluded that the indiscriminate nature of the surveillance programs carried out by U.S. intelligence agencies, exposed two years earlier by NSA-contractor-turned-whistleblower Edward Snowden, had made it impossible to ensure that the personal data of E.U. citizens would be adequately protected when shared with American companies. The ruling thus served to further solidify the long-standing conventional wisdom that Continental Europe is better at protecting privacy than America. However, Europe’s ability to continue to take this moral high ground is rapidly declining. In recent months, and in the wake of a series of terrorist attacks across Europe, Germany, France and the United Kingdom — Europe’s biggest superpowers — have passed laws granting their surveillance agencies virtually unfettered power to conduct bulk interception of communications across Europe and beyond, with limited to no effective oversight or procedural safeguards from abuse.
Paul Merrell

Mobile Data Surpasses Voice Traffic For First Time - HotHardware - 0 views

  • Total mobile data traffic topped mobile voice traffic in the United States last year, for the first time.In fact, globally, data traffic (that includes SMS text messaging) topped voice traffic on a monthly basis last year and the total traffic across the world exceeded an exabyte for the first time in 2009, according to a report just released by Chetan Sharma Consulting, a leading strategist in the mobile industry (clients include AT&T and China Mobile).
Paul Merrell

IE Drops Like a Rock, Eroded by Chrome and Firefox - No end in sight to IE's fall - Sof... - 1 views

  • Internet Explorer’s dominance on the browser market has been weakening constantly since Mozilla’s open source browser started getting traction with users. And with the advent of Google Chrome, IE’s share loss only became steeper. Statistics offered by Janco Associates reveal that in February 2010, Internet Explorer has dropped under 65%. Over the past four years, the release of Internet Explorer 7 and Internet Explorer 8 did nothing to halt IE’s crumbling market share.
  • Janco notes that from February 2009 to February 2010, IE dropped 6.21%, from 70.99% to 64.78%. “The major findings are that in the last 12 months Microsoft's browser market share has continued to erode - Microsoft lost over 6% in the last 12 months; Firefox's market share is unchanged for the last 12 months; Google Desktop and Chrome now have just under 6%; and Netscape is no more,” reads an excerpt from the Browser and Operating System Market Share White Paper.
  •  
    Janco notes that from February 2009 to February 2010, IE dropped 6.21%, from 70.99% to 64.78%. "The major findings are that in the last 12 months Microsoft's browser market share has continued to erode - Microsoft lost over 6% in the last 12 months; Firefox's market share is unchanged for the last 12 months; Google Desktop and Chrome now have just under 6%; and Netscape is no more," reads an excerpt from the Browser and Operating System Market Share White Paper.
Gary Edwards

The Lowdown: Technology and Politics of HTML5 vs. Flash | Hidden Dimensions | The M... - 0 views

  •  
    Excellent but light weight and breezy review of the Flash-Silverlight-Open Web HTML5 battle for the future of the Web. excerpt: At the top of the org chart, Apple's deprecation of Flash technology is all about politics. Apple doesn't want its mainstream video delivery system controlled by a third party. So Mr. Jobs backs up his politics with tidbits of technical truths. However, discovering the real truths about HTML5 and Flash is a bit harder, as this survey shows. On February 11th, I wrote an editorial, "What Should Apple Do About Adobe?" Part of the discussion related to Adobe's Flash Player on the Mac, updates and security. Inevitably, the comments escalated to a discussion of Steve Job's distaste for and blocking of Flash on the iPhone and iPad. The question is: is Apple's stance against Flash justified? Of course, any political argument needs only the barest of idealogical arguments to sustain itself. More to the point is, can Apple fight this war and win based on the state-of-the-art with HTML5? Again, Apple's CEO must believe he can win this war. There has to be some technical basis for that, or the war wouldn't be waged.
Paul Merrell

White House tells agencies to use same framework to exchange information - Nextgov - 0 views

  • The White House is requiring federal agencies to consider using a standard configuration developed by the Justice and Homeland Security departments to share information across the public and private sectors. More than a month ago, the Office of Management and Budget issued guidance to agencies on the website of the National Information Exchange Model, a joint DOJ-DHS program. The OMB document, which is not posted on its website, includes instructions for assessing the framework's merits by May 1. "All agencies shall evaluate the adoption and use of the National Information Exchange Model as the basis . . . of reusable cross-boundary information exchanges," said an enclosed memo from Kshemendra Paul, the federal chief architect. "The Office of Management and Budget is working jointly with the NIEM Program Management Office to provide guidance and the tools necessary to help you meet this requirement."
  • NIEM launched in 2005 with the goal of linking jurisdictions throughout the country to better respond to crises, including terrorist attacks, natural disasters, large-scale crime and other emergencies handled by Justice and Homeland Security. The standards are intended to expedite the secure exchange of accurate information.
  •  
    See also the NIEM coverage map at http://www.niem.gov/organizationsMap.php Progress on government information sharing in the U.S. 
Gary Edwards

Mary Meeker: Mobile Internet Will Soon Overtake Fixed Internet: Tech News and... - 0 views

  •  
    what does Meeker see in her crystal ball this year? Two overwhelming trends that will affect consumers, the hardware/infrastructure industry and the commercial potential of the web: mobile and social networking. Such a conclusion is hardly earth-shattering news to GigaOM readers, for we have been following these trends over the past year or two, but Meeker puts some pretty large numbers next to those trends, and looks at the shifts that will (or are likely to) take place in related industries such as communications hardware. She also compares where the rest of the developed world is in terms of mobile communications and social networking with Japan. Again, not a radically different approach to the one many tech forecasters take, but Meeker has the weight of some considerable research chops on her side. The Morgan Stanley analyst says that the world is currently in the midst of the fifth major technology cycle of the past half a century. The previous four were the mainframe era of the 1950s and 60s, the mini-computer era of the 1970s and the desktop Internet era of the 80s. The current cycle is the era of the mobile Internet, she says - predicting that within the next five years "more users will connect to the Internet over mobile devices than desktop PCs." As she puts it on one of the slides in the report: "Rapid Ramp of Mobile Internet Usage Will be a Boon to Consumers and Some Companies Will Likely Win Big (Potentially Very Big) While Many Will Wonder What Just Happened."
Gary Edwards

WYMeditor - web-based XHTML editor - Home - 2 views

  •  
    WYMeditor is a web-based WYSIWYM (What You See Is What You Mean) XHTML editor (not WYSIWYG). WYMeditor's main concept is to leave details of the document's visual layout, and to concentrate on its structure and meaning, while trying to give the user as much comfort as possible (at least as WYSIWYG editors). WYMeditor has been created to generate perfectly structured XHTML strict code, to conform to the W3C XHTML specifications and to facilitate further processing by modern applications. With WYMeditor, the code can't be contaminated by visual informations like font styles and weights, borders, colors, ... The end-user defines content meaning, which will determine its aspect by the use of style sheets. The result is easy and quick maintenance of information. As the code is compliant to W3C XHTML specifications, you can for example process it using a XSLT (at the client or the server side), giving you a wide range of applications. ...................... Great colors on this Web site!  They have mastered the many shades of Uncle Ten's (the Chinese Brush Master, James Liu) charcoal blue
Gary Edwards

Cloud computing, virtualisation top Gartner CIO survey - 0 views

  • It is these constrained budgets that will drive enterprise adoption of cloud services and virtualisation, McDonald said."These technologies were selected by CIOs the most often and are the top-two technologies for 2011, and are well-suited for this budget reality," he commented. "They offer similar service levels at lower budget costs."
  • rise to 43% over the next four years
  •  
    Cloud computing and virtualisation are the top two technology priorities for CIOs in 2011, according to the results of a survey published on Friday by Gartner that revealed global IT budgets are likely to remain largely flat this year. Networking, voice and data communications - traditionally the domain of telcos - ranks sixth in the research firm's study. "New lighter-weight technologies - such as cloud computing, software as a service (SaaS), and social networks - and IT models enable the CIO to redefine IT, giving it a greater focus on growth and strategic impact," said a statement from Mark McDonald, group vice president and head of research for Gartner Executive Programs (EXP). Indeed, Gartner's survey also found that CIOs expect Internet service-based technologies will allow them to divert more resources - up to 50% of their budgets - away from day-to-day operations and towards transforming their business strategies, which could prove significant in the wake of the recession.
commonpromo

Quanto Fit - Lose weight and Boost Energy - 0 views

  •  
    People suffering from ?#?MorbidObesity? are at a greater risk of acquiring diabetes, cardiovascular diseases, high blood pressure, and certain types of cancer as compared to others. Buy ?#?QuantoFit? now!
Paul Merrell

Cisco Visual Networking Index: Forecast and Methodology, 2012-2017  [Visual N... - 0 views

  • This forecast is part of the Cisco® Visual Networking Index (VNI), an ongoing initiative to track and forecast the impact of visual networking applications. This document presents the details of the Cisco VNI global IP traffic forecast and the methodology behind it.
Paul Merrell

Another judge upholds NSA call tracking - POLITICO.com - 0 views

  • A federal judge in Idaho has upheld the constitutionality of the National Security Agency's program that gathers massive quanities of data on the telephone calls of Americans. The ruling Tuesday from U.S. District Court Judge B. Lynn Winmill leaves the federal government with two wins in lawsuits decided since the program was revealed about a year ago by ex-NSA contractor Edward Snowden. In addition, one judge handling a criminal case ruled that the surveillance did not violate the Constitution. Opponents of the program have only one win: U.S. District Court Judge Richard Leon's ruling in December that the program likely violates the Fourth Amendment. In the new decision, Winmill said binding precedent in the Ninth Circuit holds that call and email metadata are not protected by the Constitution and no warrant is needed to obtain it.
  • "The weight of the authority favors the NSA," wrote Winmill, an appointee of President Bill Clinton. Winmill took note of Leon's contrary decision and called it eloquent, but concluded it departs from current Supreme Court precedent — though perhaps not for long. "Judge Leon’s decision should serve as a template for a Supreme Court opinion. And it might yet," Winmill wrote as he threw out the lawsuit brought by an Idaho registered nurse who objected to the gathering of data on her phone calls. Winmill's opinion (posted here) does not address an argument put forward by some critics of the program, including some lawmakers: that the metadata program violates federal law because it does not fit squarely within the language of the statute used to authorize it.
  •  
    A partial win for the public. The judge makes plain that he disagrees with pre-Snowden disclosure precedent and recommends that the Supreme Court adopt the reasoning of Judge Richard Leon's ruling that finds the NSA call-metadata violative of the Fourth Amendment. The judge says his hands are tied by prior decisions in the Ninth Circuit Court of Appeals that gave an expansive reading to Smith v. Maryland.
Paul Merrell

HTML5: Getting to Last Call - W3C Blog - 0 views

  • We started to work on HTML5 back in 2007 and have been going through issues since then. In November 2009, the HTML Chairs instituted a decision policy, which allowed us to close around 20 issues or so. We now have around 200 bugs and 25 issues on the document. In order to drive the Group to Last Call, the HTML Chairs, following the advice from the W3C Team, produced a timeline to get the initial Last Call for HTML5. The W3C team expresses its strong support to the chairs of the HTML Working Group in their efforts to lead the group toward an initial Last Call according to the published timeline. All new bugs related to the HTML5 specification received after the first of October 2010 will be treated as Last Call comments, with possible exceptions granted by the Chairs. The intention is to get to the initial Last Call and have a feature-complete document. The HTML Chairs will keep driving the Group forward after that date in order to resolve all the bugs received by October 1. The expectation is to issue the Last Call document at the end of May 2011. I encourage everyone to send bugs prior to October 1 and keep track of them in order to escalate them to the Working Group if necessary.
  •  
    Get your HTML 5 bug reports filed *before* October 1.  See http://lists.w3.org/Archives/Public/public-html/2010Sep/0074.html for more details.
Paul Merrell

christine varney - Programming Blog - 0 views

  • Consumer Watchdog today called on the Justice Department to guarantee that its ongoing antitrust probe of Google’s business practices include an investigation into if the company is manipulating its search results to favor its own products. The nonprofit advocacy group said it sent a letter to Christine Varney, Assistant Attorney General for Antitrust Division, after news that the European Commission had received three complaints against Google alleging the company manipulated search engine results in an anticompetitive way. Also this week U.K. based price comparison site Foundem filed papers with the Federal Communications Commission with examples of how Google products were allegedly favored in its search results.
  • ongoing antitrust probe of Google’s business practices include an investigation into if the company is manipulating its search results to favor its own products. The nonprofit advocacy group said it sent a letter to Christine Varney, Assistant Attorney General for Antitrust Division, after news that the European Commission had received three complaints against Google alleging the company manipulated search engine results in an anticompetitive way. Also this week U.K. based price comparison site Foundem filed papers with the Federal Communications Commission with examples of how Google products were allegedly favored in its search results.
  •  
    If the evidence supports the allegations, this is a plausible antitrust theory, a company with a dominant market position leveraging that position into new markets via integration. In essence this is the same theory as that applied against Microsoft's bundling and integration of Windows, Internet Explorer, and Windows Media Player.  
Paul Merrell

Applause For Finland: First Country To Make Broadband Access A Legal Right - 0 views

  • Kudos to the Finnish government, which has just introduced laws guaranteeing broadband access to every person living in Finland (5.5 million people, give or take). This is reportedly a first worldwide.
Paul Merrell

Google Says Website Encryption Will Now Influence Search Rankings - 0 views

  • Google will begin using website encryption, or HTTPS, as a ranking signal – a move which should prompt website developers who have dragged their heels on increased security measures, or who debated whether their website was “important” enough to require encryption, to make a change. Initially, HTTPS will only be a lightweight signal, affecting fewer than 1% of global queries, says Google. That means that the new signal won’t carry as much weight as other factors, including the quality of the content, the search giant noted, as Google means to give webmasters time to make the switch to HTTPS. Over time, however, encryption’s effect on search ranking make strengthen, as the company places more importance on website security. Google also promises to publish a series of best practices around TLS (HTTPS, is also known as HTTP over TLS, or Transport Layer Security) so website developers can better understand what they need to do in order to implement the technology and what mistakes they should avoid. These tips will include things like what certificate type is needed, how to use relative URLs for resources on the same secure domain, best practices around allowing for site indexing, and more.
  • In addition, website developers can test their current HTTPS-enabled website using the Qualys Lab tool, says Google, and can direct further questions to Google’s Webmaster Help Forums where the company is already in active discussions with the broader community. The announcement has drawn a lot of feedback from website developers and those in the SEO industry – for instance, Google’s own blog post on the matter, shared in the early morning hours on Thursday, is already nearing 1,000 comments. For the most part, the community seems to support the change, or at least acknowledge that they felt that something like this was in the works and are not surprised. Google itself has been making moves to better securing its own traffic in recent months, which have included encrypting traffic between its own servers. Gmail now always uses an encrypted HTTPS connection which keeps mail from being snooped on as it moves from a consumer’s machine to Google’s data centers.
  • While HTTPS and site encryption have been a best practice in the security community for years, the revelation that the NSA has been tapping the cables, so to speak, to mine user information directly has prompted many technology companies to consider increasing their own security measures, too. Yahoo, for example, also announced in November its plans to encrypt its data center traffic. Now Google is helping to push the rest of the web to do the same.
  •  
    The Internet continues to harden in the wake of the NSA revelations. This is a nice nudge by Google.
1 - 20 of 20
Showing 20 items per page