USGS Hydrography Seminar Series

High-quality hydrographic data are critical to a broad range of government and private applications. Resource management, infrastructure planning, environmental monitoring, fisheries management, and disaster mitigation all depend on up-to-date, accurate, and high-quality hydrographic data.

The U.S. Geological Survey National Geospatial Program is initiating a new series of virtual seminars to highlight the uses of hydrographic data.  These seminars are intended to share success stories from users who have solved real world problems using hydrographic data, provide information about the National Hydrography Dataset and related products, and provide a virtual forum for users, similar to what might be encountered in a conference setting.

The first seminar will be held on April 9 at 2:00 PM ET.  The topic will be the response to the January 2014 Elk River chemical spill in West Virginia, specifically the use of the NHDPlus, real-time stream flow and velocity information from stream gages and models, and the Incident Command Tool for Drinking Water Protection application to limit effects of the spill on communities downstream.

These seminars will be presented every 6 to 8 weeks, featuring applications and speakers from different disciplines.  Connections are limited and pre-registration is required.

Hydro Seminar 1 – Incident Command Tool for Water
Guest speaker – Dr. William Samuels, Leidos
Thursday, April 9, 2015 – 2:00 PM Eastern Daylight Time
Register here.

After your request has been approved, you’ll receive instructions for joining the meeting.  In case the meeting is full, you will receive information on an alternate date.  For more information see: http://nhd.usgs.gov/HydrographySeminarSeries.html.

Security Vulnerability in Geocortex Viewer for HTML5

If you use Geocortex Viewer for HTML5, update your apps!

From Drew Millen, Geocortex Product Manager at Latitude Geographics Group:

Yesterday we were made aware of a potential security issue affecting all versions of Geocortex Viewer for HTML5, thanks to a vigilant customer contacting our Support team.  While we don’t know of any specific attacks that may have exploited this vulnerability amongst our customers, we take potential security issues very seriously. We’re happy to report that we were able to respond quickly, and a patch will be available for download in the Geocortex Support Center in the coming hours. The patch involves replacing a single JavaScript file and does not require a re-install or that you update Geocortex Essentials.   We recommend customers with applications that use Geocortex Viewer for HTML5 (all versions) apply the patch. Note that the upcoming release of Geocortex Viewer for HTML5 2.4 will not expose this vulnerability. Here’s what you need to know:

  • This issue potentially allows a malicious attacker to craft a viewer URL that loads configuration and code from a domain under their control.
  • This issue is a result of the way viewer configurations have historically been loaded. In the past, attempts to load configurations from other domains were prevented by the browser; however, newer browsers have evolved to support a technology called Cross-Origin Resource Sharing (CORS), which now allows cross-domain requests to be made.
  • An attacker can craft a link to a viewer on a trusted domain, such as http: //trusted/viewer/index.html, that loads their malicious configuration file from a machine that they control. If the attacker’s server is configured correctly, they can serve malicious code to users who have been fooled into clicking the link.
  • An example of a malicious link could be: http: //trusted/viewer/index.html?configBase=http://go.geocortex.com/e/61102/2015-03-26/3qh36/47536401resources/config/default/
  • All browsers supporting CORS — including ones in iOS and Android — are susceptible.

Here’s what we recommend you do:

  • Download the applicable patches we are making available in the Geocortex Support Center. Click the “Geocortex Viewer for HTML5” link and look for Security Update 2015-03-26.zip.
  • Read instructions.txt for notes regarding potential changes to viewer launch links in certain advanced scenarios.
  • Follow instructions.txt for instructions on applying the patch.

We apologize for any inconvenience this issue may cause you. Please get in touch with us if you have any questions or if we can help.

GeoTech PCC Guest Lecture Series

GeoTech PCC Guest Lecture Series Spring 2015
Thursday, April 2, 7-9pm
Pasadena City College, Room E220
More details at http://geotechpcc.eventbrite.com

GeoTech PCC is a new program that just started this semester. We’re fortunate to have Jonathan Robinson and Chandler Sterling from the City of Pasadena give our first guest lectures. We want to make sure that those in the surrounding communities know about it!

California Has One Year of Water Left

According to Jay Famiglietti, the senior water scientist at the NASA Jet Propulsion Laboratory/Caltech and a professor of Earth system science at UC Irvine, California has about one year of water supply left in its reservoirs.  Are you ready to ration?  What is your government agency you work for going to do?  Imagine what this will do to California’s economy … and the way we will live here, or leave for greener pastures.  Check out the LA Times Op-Ed piece.

See also USGS California Drought.