Category: Computer

An Interesting Solution to the Problem of Phishing and Hacking:

A web master has come to the conclusion that the first step in managing this sort of activity is to, “block all traffic from China:

I run quite a few few websites and blogs and my solution to this problem was first to BLOCK all traffic from China, I allow nothing, nada, zip from China based IPs. From my personal experience 100% of China’s internet traffic is hacking attempts, email SPAM and phishing. I have never encountered a single China access that could be considered positive.

Blocking China has solved about 80~90% of the problem. The second thing is to block specific domains and IPs from Russia, Romania, Brazil, Taiwan, Korea, Poland and may other ex Soviet Satellites. I can’t block all access to these countries because there is about 90% of legitimate traffic and the 10% left are probably compromised computers being used as proxies/bots for China.

I tried to find the original source for this and a quick google indicates that there are a significant number of web masters who are beginning to consider this as a first step for web security on their sites.

Obviously, I am not a webmaster, but I’m wondering just how wide spread this phenomenon is.

I Love My Wife

But helping her work with her phone and computer makes me f%$#ing crazy.

I am so not a teacher, but I married one, go figure.

I’m showing her how to sync her android phone directly to her Outlook.

(Hint: it uses a PIM called MyPhone Explorer which is actually pretty slick)

I have to have her press all the buttons, because otherwise, she would not get it, and she would be asking me how to do this over, and over, and over, and over again.

Still, getting her over the hump on this drives me buggy.

The Vaporware Beast Has Been Slain!

In 1998, the much delayed sequel to the fantastically popular first person shooter Duke Nukem, Duke Nukem Forever, was declared one of the top pieces of vaporware (promised but not delivered software) of all time.

Well, an era has ended because today, Duke Nukem Forever was released:

Even though his game is finally in stores, Duke Nukem will forever be remembered as the very personification of vaporware.

Wired.com created the Vaporware Awards many years ago to honor products that were hyped, promoted and promised but never released. Tech and gaming companies love to throw smoke and mirrors in our faces and make us think that barely begun (or simply imaginary) products are humming along quite smoothly; the Vaporware Awards attempt to cut through the spin.

Duke Nukem Forever was mentioned in our Vaporware Awards 12 times as the developers of the first-person shooter let years upon years go by without shipping the game.

Released Tuesday for Xbox 360, PlayStation 3 and PC, Duke Nukem Forever doesn’t live up to the years of hype. But simply shipping the unshippable game should be counted as an accomplishment for 2K Games and Gearbox Software, which stepped in last year to get Duke back on track after the collapse of developer 3D Realms.

The reviews are mixed.  The gaming press hates it, but at least one person, Bladesmith on the SP BBS, commented that, “Seriously, the reviewers don’t get the joke. This is a throwback AND an homage to the old school 80s Duke.”

As for me, I won’t be getting it.  I never played the original, so I think that I would not get the humor.

Well, At Least It’s Not My Employer

Lockheed had to locked down its network after it was massively hacked:

By all accounts, Lockheed Martin’s swift detection of the attack helped avert potential disaster. “The good news here is that the contractor was able to detect an intrusion then did the right things to deal with it,” Cringely said. “A breach like this is very subtle and not easy to spot.” Furthermore, he said, the same day that Lockheed Martin detected the attack, all remote access for employees was disabled, and the company told all telecommuters to work from company offices for at least a week. Then on Wednesday, the company informed all remote workers that they’d receive new RSA SecurID tokens and told all 133,000 employees to reset their network passwords.

In a statement released Sunday, EMC said it was “premature to speculate” on the details of the attack. But if attackers did use information stolen from RSA to hack into the SecurID system used by Lockheed Martin, then EMC could be forced to finally reveal, publicly, any risks that the use of its system might now pose to the 40 million users of SecurID hardware token customers and 250 million users of its SecurID software.

I’m a contractor, so even if my employer were hacked in this manner, it would not effect me, since that don’t give mercenaries like me remote access to their networks.

Of course, they should have locked down their system months ago, when RSA, the company that supplies the keys for their VPN systems, and a lot of other companies out there, was hacked.

Anonymous Gets Scalp of HBGary Fedral CEO

Following revelations by Anonymous that HBGary Federal was developing a plan of Nixonian dirty tricks, with false identities, forged documents, and other disinformation, the CEO of HBGary Federal has been fired resigned:

Aaron Barr’s departure as CEO of HBGary Federal represented the latest twist for the company and its Sacramento affiliate, HBGary Inc. A spokeswoman for the Sacramento company confirmed the resignation.

According to numerous reports, Barr’s company, which is based in Colorado and Washington, D.C., proposed conducting a disinformation campaign against critics of the U.S. Chamber of Commerce. The plan was presented to the chamber’s law firm, but the chamber says it wasn’t aware of it.

The plan was aborted after the hacker group Anonymous stole tens of thousands of e-mails from both HBGary and HBGary Federal – and posted many of the messages on the Web.

And now Democratic members of Congress are calling for an investigation of these activities.

Of course, there won’t be an investigation in the House.  The Republicans are busy looking for a blue dress.

Deep Thought

Not blogging tonight, because I am dealing with installing Windows 7, SP 1 on this machine, and installing a new printer/scanner/fax (It was as cheap as a flatbed scanner, but came with a document feed, so even though we won’t be using either the fax or printer, it made sense) on the desktop.

At time like this, I think, “F%$# it, I should get myself a Macintosh.”

But then reality hits, and I realize that I’m already way too arrogant and obnoxious, and if I got a Mac, I’d make Muammar Qaddafi look Mahatma Ghandi.

This is What You Get When You Fist F%$# a Cobra …

Click for full size


Complete PWN463!

I while back, I mentioned 4Chan, I should add the inventive group of people known as Anonymous who ofttimes frequent 4Chan:

Anonymous, the online collective that launched DDoS attacks on Visa, PayPal and others in support of whistle-blowing site WikiLeaks, has brought down the web site of a firm helping the FBI to unmask its members.

Security services firm HBGary Federal had been helping the Feds to track down the individuals behind a number of distributed denial of service (DDoS) attacks on companies including Amazon, PayPal, Visa, MasterCard, Swiss bank PostFinance and Bank of America, after the firms suspended services to WikiLeaks.

In a sophisticated attack, Anonymous members hacked into HBGary’s website and posted an image containing a message explaining their actions. In addition, they downloaded over 60,000 messages from the company’s email servers and posted them on The Pirate Bay.

The Twitter account of HBGary’s CEO, Aaron Barr, was also compromised and used to tweet a number of offensive messages, as well as his home address, social security number and mobile phone number.

(Link to torrent mine, and I make no claims as to the safety or veracity of the data.  I have not downloaded the data myself)

Yeah, and it has also been reported that they deleted HBGary’s backups.

Not only did they pick a fight with Anonymous, but it also appears that they are complete posers as well, who were leaching publicly available names from Facebook and IRC, and trying to sell this to the FBI.

Well, not any more, because, according to the letter that was the HBGary home page (above) they sent the data to the FBI themselves.

What a bunch of complete wankers, Aaron Barr and company that is, I have nothing but the utmost respect for Anonymous.

And so Anonymous is added to my list of People I Do Not Want to Piss Off, and HBGary is added to the likes or Razorfish, to my list of people who I would never trust with anything more complex than a mechanical pencil.

No Posting Tonight

I’m not sick or anything, it’s just that I am up to my elbows in removing a Trojan* from my daughter’s computer, for the 2nd time in a week.

I do not know what she is accessing, but I am looking up her browser history, and trying to find a possible source, in addition to running multiple virus/spyware scans.

The joys of children are without number.

*The computer infection, not the condom.  If it were as condom in her computer, my head would have exploded.

Obscurity is not Security

But this isn’t stopping banks from trying to suppress security research showing that their cards are insecure, as opposed to manning up and fixing the problem:

Cambridge computer scientists have become embroiled in angry exchanges with Britain’s banks and credit card lenders, accusing them of bullying and trying to “censor” a PhD student who was exposing flaws in chip-and-pin machines.

A leading Cambridge academic has now written to bankers’ representatives demanding that they stop pressing for the removal of a student’s doctorate work from the web.

Professor Ross Anderson, from Cambridge University’s Computer Laboratory, has previously researched glitches in chip-and-pin banking that allow withdrawals to be made from accounts without needing to know the holder’s PIN. As part of his thesis work, one of his students, Omar Choudary, exposed how easy it was to make such a withdrawal.

Then the UK Cards Association, a trade body representing leading banking organisations, approached the university asking it to remove the thesis from his website, which is accessible through a university site.

So, the knowledge is out there, and it is public, it has actually been discussed on the BBC, and the banks want to pretend that it never happened.

This is why you cannot rely on market mechanisms for this kind of stuff.

The Good News

The 6th Circuit of Appeals has ruled that law enforcement agencies must secure a warrant before seizing emails from Internet Service Providers.

While I am certain that Barack Obama, Eric “Place” Holder, and their Evil Minions will attempt to get this overturned by the Supreme Court

The full EFF press release is below the break:

Breaking News on EFF Victory: Appeals Court Holds that Email Privacy Protected by Fourth Amendment

News Update by Kevin Bankston

In a landmark decision issued today in the criminal appeal of U.S. v. Warshak, the Sixth Circuit Court of Appeals has ruled that the government must have a search warrant before it can secretly seize and search emails stored by email service providers. Closely tracking arguments made by EFF in its amicus brief, the court found that email users have the same reasonable expectation of privacy in their stored email as they do in their phone calls and postal mail.

EFF filed a similar amicus brief with the 6th Circuit in 2006 in a civil suit brought by criminal defendant Warshak against the government for its warrantless seizure of his emails. There, the 6th Circuit agreed with EFF that email users have a Fourth Amendment-protected expectation of privacy in the email they store with their email providers, though that decision was later vacated on procedural grounds. Warshak’s appeal of his criminal conviction has brought the issue back to the Sixth Circuit, and once again the court has agreed with EFF and held that email users have a Fourth Amendment-protected reasonable expectation of privacy in the contents of their email accounts.

As the Court held today,

Given the fundamental similarities between email and traditional forms of communication [like postal mail and telephone calls], it would defy common sense to afford emails lesser Fourth Amendment protection…. It follows that email requires strong protection under the Fourth Amendment; otherwise the Fourth Amendment would prove an ineffective guardian of private communication, an essential purpose it has long been recognized to serve…. [T]he police may not storm the post office and intercept a letter, and they are likewise forbidden from using the phone system to make a clandestine recording of a telephone call–unless they get a warrant, that is. It only stands to reason that, if government agents compel an ISP to surrender the contents of a subscriber’s emails, those agents have thereby conducted a Fourth Amendment search, which necessitates compliance with the warrant requirement….

Today’s decision is the only federal appellate decision currently on the books that squarely rules on this critically important privacy issue, an issue made all the more important by the fact that current federal law–in particular, the Stored Communications Act–allows the government to secretly obtain emails without a warrant in many situations. We hope that this ruling will spur Congress to update that law as EFF and its partners in the Digital Due Process coalition have urged, so that when the government secretly demands someone’s email without probable cause, the email provider can confidently say: “Come back with a warrant.”

Attachment Size

warshak_opinion_121410.pdf 316.97 KB

(emphasis original)

Sergey Aleynikov Guilty

He is the computer programmer who was charged with stealing Goldman Sach’s high frequency trading software.

Here are the New York Times and Wall Street Journal stories.

The Times version has a video (unfortunately not embeddable) of Fordham University law professor Joel Reidenbert, who basically says that what would ordinarily be a civil matter, a potential breach of confidentiality agreements, was made into a criminal case to make an example of the “US Attorney doing the heavy lifting for Goldman.”

He doesn’t come out and say it, but I infer from his that this was a hit by the US Department of Justice, with the active and aggressive collusion of federal judge Denise Cote, to do the Vampire Squid’s* bidding, as the article notes, “During the two-week trial, Judge Denise L. Cote closed the courtroom to the public several times to protect Goldman’s proprietary source code,” and “Before dismissing the panel, Judge Cote warned them that if they were going to speak about the case, they must not discuss anything related to Goldman’s code.”

It stinks to high heaven.

*Alas, I cannot claim credit for the bon mot describing Goldman Sachs as a, “great vampire squid wrapped around the face of humanity, relentlessly jamming its blood funnel into anything that smells like money.” This was coined by the great Matt Taibbi, in his article on the massive criminal conspiracy investment firm, The Great American Bubble Machine.

Assange Jailed

Note that he has not been charged, and the warrant is for an interview, a British magistrate has ordered Julian Assange held without bail after he turned himself in voluntarily.

Tell me that the fix is not in here.

Of course, the fact that hundreds, perhaps thousands of people, have his ITEOD* file, and some number probably greater than 10 people have the code to decrypt those unredacted files has got to give the people pursuing him cause to pause.

*In The Event Of Death.

Well, This is a Surprise

In the latest twist to the legal travails of Sergey Aleynikov, who is accused of theft of Goldman-Sach’s illegal market front-running high frequency trading software is now arguing that the code in question was open source, so there was no theft:

Sergey Aleynikov, who is accused of stealing Goldman Sachs’ source code used in high-frequency trading, argued that he was standing up to the investment bank’s proprietary claims on open-source code, not trying to steal private codes to use at a competing trading firm.

Mr Aleynikov, a former computer programmer at the bank, is accused of downloading proprietary code related to high-speed trading systems in June 2009 for use at a new job at a competing firm.

While this statement may actually be true, it does strike me as a rather low percentage defense.

Unfortunately, it also implies that we will not be getting any details on how the Vampire Squid and its Wall Street co-conspirators might actually be gaming the system with their co-located high speed trading systems during the trial.