Showing posts sorted by relevance for query register. Sort by date Show all posts
Showing posts sorted by relevance for query register. Sort by date Show all posts

2009-08-03

how twitter got hacked...

http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/

no technical hacking here; very, very simple stuff; please read (especially K)

Step 1:

When you register a new gmail account you give them a "secondary" email.  If you forget your password you can ask gmail to send a "password reset" link to this secondary email.

In this case, the hacker found that

  - his victim had a "hotmail" address as a secondary
  - he had not used that address for years
  - so hotmail had expired/deleted it (I don't blame them on this; even if it is MS!)
  - so anyone was free to register that address again
  - so the hacker simply registered it himself
  - thus getting the "password reset" email for his victim's gmail account :-)

Step 2:

The second part is even simpler.  He needed to reset the password back to what the owner **currently** uses, otherwise the owner would get suspicious (if he was unable to log in next time).  And he needed to do this very quickly.

  - he looked through all the saved email on the hacked gmail account
  - found a few passwords helpfully sent back by various services to which the victim had subscribed
  - gambled that the victim uses the same password for everything
  - and reset the gmail password to that

Step 3:


Once he was sure everything was OK, he just used that same password to access the victim's **official** twitter email.

Conclusion:

Who needs cryptography, buffer overflows, complicated shellcode, rootkits, and all that techie stuff when users can be this naive :-)  I mean there's not a byte of code or a mangled URL or a malicious Javascript or even a single HEX character in this whole thing!!!

Moral of the story:

  - never use the same password for more than one service.
  - delete registration emails from websites if they contain your password.  Be sure to empty trash (or "delete forever") too
  - in any case, change your passwords once in a while

2006-06-28

(criminal) That explains a lot...

Gates becomes a higher power [printer-friendly] | The Register

"People think of me as this technical guy," Bill Gates once told me. "In fact, the important point to remember about my background is the fact that I was brought up to be a lawyer. My family are all corporate lawyers, and the conversation at every breakfast was always over the latest legal developments in the business space. You might say it's in my blood."

And here's another great quote:

"It's important for a corporate leader to know the difference between what is actually illegal, and what people assume should be illegal."

2006-08-13

(security) India takes on offshoring naysayers

It's not news if the fraud is "onsite", I guess :-( Or, as the article says, our reputation is less valuable than theirs...

India takes on offshoring naysayers | The Register

In June, an Indian worker was arrested for allegedly defrauding £233,000 from the accounts of about 20 HSBC customers. However, the Royal Bank of Scotland lost nearly 100 times that amount of money (£21m) to a man working for the bank in Edinburgh.

The story of his being jailed for 10 years broke almost simultaneously with that of the comparatively minor Indian fraud. But that was not all that was overlooked.

HSBC had insisted that its Indian centres suffered less fraud than those based in the UK. The Financial Services Authority (FSA) said British banks are more reluctant to report or prosecute their inhouse fraudsters, as doing so could tarnish their reputations.

2011-06-24

the new nook (aka Nook second edition, nook simpletouch, etc)

Well I happened to be in the US after many years, and despite being sent a nook 1, (wifi only model) by my brother a couple of months ago I was tempted enough by the reviews of the nook 2 to buy one.

[By the way, the nook 1 (wifi only version) was $150 when my brother bought it for me. A scant few weeks after he sent it to me, they announced the Nook 2 at $139, and dropped the price of the nook 1 to $119! Timing issues like this have been the story of my life, <sigh>...]

So here're the pros and cons of this one compared to the old one.

Summary: lighter and smaller and better navigation make it attractive. But there are lots of negatives to consider, and if I'd known all of them before I bought it I may not have done so. Even now, I'm sorta tempted to attempt returning it but that's only fueled by "righteous indignation" so I will probably just laze around until it's time for my flight home and then claim I didn't have time!

Pros:

  • much better interface -- the main screen is a touch screen now! (For people who're wondering what's the big deal, remember this is e-ink, non-backlit display -- totally different technology to the normal stuff on your Androids!)

  • much smarter navigation. Both because the main screen is touch, as well as the fact that you can reverse the meaning of the top and bottom buttons if the size of your hand makes it so that the upper button is better for your thumb to hit when you hold it. Reading is a real pleasure with this thing!

  • reviews say it has a much better battery life. Sounds believable, because there's no longer a battery draining lighted touchpad! I can only hope, because the old one sucked rocks through a pipette in terms of battery life!

  • no touchpad means it's much smaller and lighter, while having the same actual screen size (800x600)

  • has a built-in dictionary (accessible only from EPUB files, not from PDFs... wonder why)

  • (minor: now actually knows about GMT+0530 in its time zone list! yeaaay!)
Cons:
  • no device password. This is a big problem for someone like me; limits what I can use it for. I can no longer grab a quick PDF of some work document I need to read and take it with me, in case the device gets stolen.

    You may think you can use encrypted PDFs, but that won't work. There's no way to make it "forget" the password short of completely shutting down, so if you opened a document it's now visible to anyone who grabs the device. (In the old nook, the moment you open another document (even an un-encrypted one), the password for the previous one was forgotten. Not great but I was happy enough to use it as a workaround...)

  • no document delete. If you did take along a sensitive file, you can't delete it once you've read it, to limit exposure. The old nook would let you delete documents from its interface; this one needs a PC to do that. This is the worst problem from my point of view because it could have somewhat mitigated the previous one.

  • non-replacable battery. This is the second worst problem as far as I am concerned. For people who live outside the US, like me, this could be a killer. I'm crossing my fingers hoping I don't get burned...

  • mandatory registration. A new nook 2 won't even get to the home screen unless you register. Fortunately, it doesn't insist on a credit card for a new registration, but even so, that's badbadbad(tm)! [And I'm willing to bet some corporate fsckwit at BN will read this and make a note to make the credit card mandatory for nook 3!]

    I have no intention of ever buying any content -- most of my reading is PDFs from work or web pages converted to EPUBs with my own script built around calibre's ebook-convert program. So the question: at $139, do they still have to resort to the razor/blade revenue model?

  • probably for the same reason, only 236 MB for "sideloaded" documents. ["sideloaded" apparently is the phrase to describe docs you install through USB instead of from BN using their interface]. This is barely one-fifth of the 1.3 GB the old nook had. The nook 2 reserves the rest of the free space for BN content, which means in my case it's just sitting idle. To be honest, this is not a big deal, but one does feel somewhat cheated at the forced space wastage.

  • no music. I never used the music on the old nook anyway so I don't care.

  • no browser. Well the browser on the old nook was crap so I don't miss it, but it could actually have been usable on this one, because of the touch screen! Why did they do this?
And finally, here's the biggest WTF: when you start the machine and eventually read the 100-page user manual, it says somewhere toward the end "You can purchase a Nook only if you have a billing address in the United States".

Huh? Why? What earthly logic do you have for this? We're the best customers -- we don't have much opportunity to return it, call your customer complaints, and generally make your life miserable if we don't like it.

More importantly, how the fsck am I supposed to know that before buying it? The sales clerk at BN, Stevens Creek (CA) didn't even ask. Clearly he is smart enough not to lose a sale for crappy reasons, so what's with the corporate stupidity?

And don't tell me it's legal reasons to do with geography specific licensing for books, like DVD region codes. You're not going to let me buy content until I give you a credit card with a US billing address anyway ...



All in all, psychologically very disappointing. So now that I have "pensieve"d all these comments, I will try and purge them from my mind and try and enjoy the damn thing...

2007-10-31

(malware) When antivirus products (and Internet Explorer) fail you | The Register

http://www.theregister.co.uk/2007/10/30/anti-virus_failures/

Good stuff. If any of my readers are actually using IE for routine web surfing, you haven't been reading my blog. Or you don't care about your machine and your data!

"Internet Explorer's interpretation and handling of mangled HTML and supported scripting input certainly contributed to making the Internet accessible to a wider audience, though now it is leading to making the platform more accessible to malware authors (if that was possible)."

2011-03-26

of winks and nooks...

So I finally got myself an ebook reader.  I'd been thinking about it for a while, but when my brother got a "wink" reader, I jumped.  In short order, I'd asked my other brother (currently temporarily in the land of the un-free) to get me a Barnes and Noble Nook.

My only reason was that it has a real browser.  Turns out the browser is more than somewhat crippled -- it can't even manage the redirection from chamarty.net to sitaramc.blogspot.com!

Getting stuff onto the device

It won't let you download anything using the browser either -- the only way to get PDFs and EPUBs on the box is either from B&N or via USB.

The wink, on the other hand, doesn't have a browser, for all practical purposes anyway.  What it does have is an email client, which -- surprise -- lets you download stuff to the device.  So you have two ways to get stuff onto the device, which is nice.

Deleting stuff you already read

The Nook will let you delete content from the device's interface.  The wink won't; you have to do it from a host computer via USB.

Reading oddball stuff

The biggest thing the wink has is that the reader software is much better than on the Nook (gasp!)  Firstly, it actually supports rotated reading for wide text if you want to do that, which is quite useful for some comics and cartoons.  Secondly, it does not force everything into "reflow" mode.  Of course, zooming while not in reflow mode makes a document wider than the screen and you have to pan left to right for every sentence, but at least it allows you to do that (this is important for figures in PDFs, for instance).

The Nook forces reflow on everything so it is crap at PDFs with bulleted lists, indents, tables, and such.

Hardware

Now that i realise the browser isn't that great, about the only thing the Nook has going for it is the hardware quality.  It feels a little better built, and the buttons (there are only 4 by the way) have an "embedded" feel to them.  The wink's keyboard is bad -- sometimes you have to hit twice for a button to register, and sometimes you hit once and it registers twice.  (I guess a statistician would say that on the average the keyboard works fine then!)

I didn't get much of a chance to compare battery life but I suspect the Nook is crap.  I'm getting far, far, less than what the ads and even reviews led me to believe.  I'll have to wait till my usage stabilises somewhat, because the color LCD at the bottom is definitely a huge drain!

Security

Oh yeah -- the other reason I like the nook is it actually has a device password.  There may be ways to get around it, but at least it'll keep out casual snooping...

Summary

Nook: if you absolutely need a password protected device.  And/or you absolutely need a browser, even if it can't do most sites.
Wink: if you want to be able to receive content via email while on the road without your own laptop.  And/or you want a better reader software in general (subjective opinion)

2006-08-18

(criminal,malware) Windows genuine disadvantage

Windows genuine disadvantage [printer-friendly] | The Register

What would you call a computer program that surreptitiously installed itself onto your computer, collected personal information about you without your knowledge or effective consent, was difficult or impossible to remove, installed pop-up banners that constantly harassed you, and presented significant security vulnerabilities?

2004-10-05

(FOSS,malware,security) Does open source software enhance security?

The article is a little old, but it's a good read nevertheless. Explains nicely why Unix is more secure than Windows. Not as funny as usual articles from The Register, although the author clearly tried to redeem that by the time he came to the last para:

Does open source software enhance security?

"So, while openness provides a couple of security advantages in itself, the chief reason why Linux and BSD offer superior security is not so much because they're open source, but because they're not Windows."

2007-11-30

(security) protecting yourself against phishing

[feel free to pass this on to whoever you wish to. This is written at a "user" level]

SImple rules to avoid phishing and such scams, as much as possible:

(1) Do not ever click on any links sent via email. Ever. No respectable bank or money related site will do that anymore. If they do, stick to paper dealings with those banks -- don't do anything online with them!

(2) Typing in the URL yourself everytime is good, but beware of "typo-squatters", who register domains with similar spellings to the legitimate site in the hope that someone will mis-type the URL and come there.

(3) The best method is to type in the full URL once and bookmark it. From then on, use the book mark.

(4) Do not use IE. Even if you are forced to use Windows for whatever reason, at least install Firefox. Get the latest firefox and keep it updated. Firefox does this automatically anyway.

(5) Do not browse to any unknown sites while logged in to the bank site. In fact the best way to access your bank site is to do this:

- close all tabs
- click on "tools", then "clear private data" (or use the Ctrl-Shift-Del shortcut keys)
- in the prompt that comes up, select ALL the boxes except the first one ("Browsing History")
- open the bank site using your bookmark, complete your work, and log out of bank site when done
- (do not open other tabs with any other sites while logged into the bank site)
- once again "clear private data" as above
- surf other sites normally

This will protect you against any (unintentional) Javascript vulnerability in the bank site or malicious (intentional) Javascript in other sites.

Caveats:

All this will still not protect you from any viruses or trojans, or key loggers that may have been installed in your computer without your knowledge, if you're running Windows. A lot of programs that are supposedly "free" (but not open source) and "useful" are actually spyware, and in many cases the user himself has installed it without knowing there is something bad. Such software can track your keystrokes, and mouse movements. Coupled with tracking your web accesses, this kind of software can get your password regardless of what precautions you take. Some examples of spyware are here.

2007-11-12

(security) IndiaTimes website 'attacks visitors' | The Register

http://www.theregister.co.uk/2007/11/10/india_times_under_attack/

The article doesn't mention if using FF makes a difference, but I suspect it will.

This also puts paid to the "I trust this website, since they are so well-known" logic. NOTHING can be trusted.

2005-02-22

(standards,criminal) Opera to MS: Get real about interoperability, Mr Gates

Opera to MS: Get real about interoperability, Mr Gates | The Register

So, Mr. Gates, writes Hakon Lie [CTO of Opera], you say you believe in interoperability. Then why, pray tell, doesn't the web page of your interoperability communiqué conform to the HTML4 standard as it claims to? Why does the W3C validator diagnose 126 errors on your page ?

You say you believe in interoperability. Then why is your document served in different versions to different browsers? Why does your server sniff out the Opera browser and send it different style sheets from the ones you send to Microsoft's own Internet Explorer (WinIE)? As a result, Opera renders the page differently.

You say you believe in interoperability. Why does the Hotmail service deny Opera access to the same scripts as Microsoft's own browser? As a result, Opera users can't delete junk mail .

I guess he only meant interoperating with Microsoft software :-)

2006-07-14

(funny) Crap website? Try feng shui

Crap website? Try feng shui | The Register

Is your website underperforming? Does it lack spiritual balance? Do you have the sneaking suspicion that an inauspicious alignment of html elements may be to blame?

Not funny enough? Here's more:

"Just as the world comprises of the five basic elements, each website has five elements and these need to be in balance with one another. Earth is the layout, fire is the colour, air is the HTML, space is name of the website, and water is the font and graphics."

2006-08-13

(security) Phishers rip 2-factor authentication

Phishers rip into two-factor authentication | The Register

The attack confirms concerns from security expert Bruce Schneier that two-factor authentication schemes have been oversold as a silver-bullet solution to online identity fraud.

2006-06-14

(funny) the perils of aggressive spam blocking

First, if you're offended by stuff like this, my apologies. My first excuse is that I honestly doubt anyone actually visits my site. My second excuse is that this really is a technical issue :-)

Rochdale man fails to prevent neighbour's erection | The Register

A Rochdale man has failed to prevent his neighbour extending his property after the local council's email filtering system blocked two missives containing the word "erection", the BBC reports.

2005-02-11

(WTF,malware) XP must be rebooted daily, says MS blogger

Reboot daily, Tablet users advised | The Register

"There are also other reasons for rebooting XP daily, as Microsoft blogger Robert Scoble explains:

"I shut down my Tablet PC most evenings and start it up from a fresh boot. Why do I do that? Because I've been using computers for 20 years and have learned that's the best way to work."

Correction. He's been using Microsoft operating systems for 20 years. None of the others need to be rebooted daily!

2004-07-06

(funny,security) Not enough of a deterrent!

The following article first struck me as being merely very funny, but -- like in many things funny -- there is an important lesson here, in this case about security:

2007-09-28

(security) Adobe gifts internal file permissions to unwashed masses | The Register

http://www.theregister.co.uk/2007/09/27/adobe_website_leak/

Amazing... :-) It seems they didn't even set the permissions right on their SSL private key file, and a "directory traversal" bug allowed pretty much anyone to get this key out, as the screenshot shows!

2008-06-05

(criminal,malware) hitting people below the belt

...from a company which is pretty famous for such behavior anyway.

I did not realise that the borg had stooped to vilifying IIT Mumbai and similar organisations and their employees/representatives in their mala-fide efforts to get OOXML ratified as an ISO standard. The fact that they tried to paint it as being in India's best interests is fine, but they seem to have well and truly crossed the line into saying that anyone who opposes it is therefore anti-India !!!!

The opening para of his open letter is itself pretty damning, and this long, (albeit sometimes a little dramatic), letter deserves wide dissemination among our peer groups.

With reference to the recent happenings in connection with the ISO standardization process of OOXML, actions by or on behalf of Microsoft have caused me deep pain and hurt. Apart from the personal anguish, these actions have tarnished the name of my Institute along with that of several other organizations represented on our committee. In my opinion, these actions go well beyond the behavioral boundaries for a commercial entity. some of these amount to interference with the governance process of a sovereign country. Luckily, wiser and experienced people are in-charge of governance of the nation. However, as a humble teacher and a proud Indian, I wish to register a strong and visible protest.

http://deepakphatak.blogspot.com/2008/05/this-is.html

2004-10-04

(malware) Windows XP SP2 falls far, far, short...

This is an article from The Register, one of my favourite IT news sites. Their comments are usually acerbic, often hilariously funny, and always on the dot. [ For another example see this article! ]

WinXP SP2 = security placebo?

"Microsoft declined many opportunities to harden Windows XP in a meaningful way"

[....]

"The home user is the one most in need of good security configurations and tools, yet the one least served by SP2"