Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

January 01, 2015

10 New Year's Resolutions (for you) for the Year 2015

A new year is a somewhat arbitrary point in time to mark change. But tradition has it that we do two things when the calendar turns from December to January. We look back on the previous year, either with pride over accomplishments, or dismissal of bad experiences, and we optimistically expect the best for the coming twelve months.

In years past I've put forth fun predictions for the world in tech. And trust me, I have some predictions, but I'll hold those close to the vest. Working at Google makes predicting the future like cheating. And I won't bore you with a list of my own resolutions for 2015. Instead, I'll suggest (with bias) ten resolutions each of you (and often us too) should take this year to make our online and offline lives even better.

1. Protect yourself and your data from the bad guys.

Seemingly every week, we are seeing news about security breaches at major retail stores, or finding online databases have been impacted. And outside the headlines, bad actors are out there trying to harvest your online information. I recommend protecting yourself by using two-factor authentication wherever possible, trying to avoid the reuse of passwords, and setting up automatic alerts that tell you if your credit cards are being used anywhere, or over a certain dollar amount.

In 2014, I managed nearly 6 million steps on Fitbit.

2. Use intelligent data to make yourself a better person.

Seemingly everyone's New Year's resolution is to go to the gym more or lose weight. But those resolutions tend to fade out after a strong month or so. Instead, find a fitness tracker or application that makes sense to track what you already do, and find a way to increase those numbers. My adoption of Fitbit two and a half years ago helped me lose more than 20 pounds, encouraged me to buy a treadmill, and find the way to walk just about everywhere.

3. Use intelligent data to make your home a smarter one.

Once you know to count your data with services like Fitbit, running your home without data is kind of dumb. By adopting Nest and Sunrun to handle our energy costs, and Rachio to manage our smart sprinkler system, we've not only set ourselves up to save money each month, but we can better predict our use, and make changes when necessary.

Our Solar powered home saves money and saves the air too.

4. If you have money, put it in places with long term benefits.

In 2010, we bought our home, putting out more money than I've ever done. But with rising Silicon Valley real estate prices, that looks like a good investment. In 2011, we refinanced. In 2012, we paid off our cars and, with the exception of our home, were debt free. In 2013, we bought a treadmill, to keep us active, even if not leaving the house. And in 2014, we made two big expenditures: The first being our Sunrun solar system, which will save us more than $65,000 in the lifetime of the 20 year contract, and the second, paying off a home equity line of credit, which was taking $300 a month, every month. We paid it off 28 years early. This year, we're hoping to get rid of our external storage unit, and continuing to take costs off the top.


5. Reduce clutter, be it of physical things or your time.

One of our 'first world problems' is the accumulation of stuff that takes up space. But many of things that occupy space where we live are for temporary enjoyment. I made a choice to ditch physical items for digital ones years ago, and I don't have books or DVDs following me around. Similarly, it makes sense to cut out activities, networks, people or habits that are a time suck for you and may have stopped adding value long ago. Whether it's closing accounts, unfriending, unsubscribing, or just walking away... if you truly miss it, you can always add those things back.

6. See things from another person's perspective.

It's easy, especially online, to divide into two directly opposing camps. What you like is amazing, and what the other person likes stinks. But it's often very interesting to see why someone has made a choice, be it where they choose to spend their time, what hobbies they enjoy, what apps they use or what mobile or computer operating system they've selected. It can't hurt to ask and understand before overwhelming them with your bias.

7. Recognize a lack of diversity hurts everyone, and work to solve it.

There is bias everywhere, obvious or unconscious. The results of generations of bias have led to dramatically skewed workplaces, city makeups, perceptions and manufactured realities. 2014 saw many tech companies open up about their own diverse makeups. Recognizing the issue is just the first step, and being comfortable with the status quo isn't acceptable.

8. Don't read the comments. And if you do, don't respond.

There's a bell curve when it comes to quality commentary, and the fringes of that curve are in charge of most active conversations, be it on mainstream media sites, popular discussion boards, or video networks. Practically every time, you lose brain cells by reading them, and engaging just makes you part of the mess.

9. Do something good for people who need the help more than you do.

Not everyone feels like they can give money to charity, but practically everyone has time. 2014 saw many of my friends get cancer. Another friend lost his 11 year old son to heart disease. Close friends suffered job losses, divorces and messy breakups. The world got Ebola. Adult problems can be a real pain. Find a cause or lend an ear to a friend that needs the help and always be there. The time you give is better than money.

10. Evaluate what you've always been taught and consider whether its true.

Much like bias can be taught from one generation to the next, so can half-truths and pure make believe, from pseudoscience to religion, political leanings and the latest version of history, depending on the author. Put two people in a room and ask them a direct question on a challenging topic, and you'll get wildly different answers. Find out why you'd state yours, and see if a little research could make you update your story.

Starting here, even if you can't get to them all, will have a big impact on you - online and offline, with health, with finance, and well being. You could give yourself a crazy goal that sets you up for disappointment, or you could just start with these. I'm working on each one and have a lot more to do. Good luck to you in 2015.

April 05, 2011

Did You Know All Your Emails Were In One Basket?


Prior to this weekend, most of your thoughts around the word Epsilon were probably about Greek fraternities or toga parties, but headlines in the tech and security world over the last few days have us instead associating Epsilon with a company most of probably never heard of before - a massive email marketing company used by many top brands. A major security breach seems to have escorted customer email lists from respected companies many of us interact with every day, and with the names piling up, I have to wonder if we had any idea that this centralization of our relationships with companies was happening, or if we are all the unlucky benefactors of outsourcing gone wrong.

The fun started late Saturday when I first got an email from TiVo saying my email address and first name had been exposed due to unauthorized access to their email service provider.

Of course, if you know me, that's no big deal. Everybody and every spider in the world knows my main email addresses are louisgray@mac.com and louisgray@gmail.com. Tough finding that out and combining it with my mysterious first name. You know I don't have too many issues around sharing my cell phone number either - this being a key focal point of a CNN.com article on the "death of privacy" back in December.

The String of Notification Emails

Modern anti-spam measures from both Apple and Google prevent most garbage from missing my in box. For more insidious emails, that fraudulently pretend to be something they are not, which is made possible from this breach, I am wary enough not to do anything foolish.

But, as many others soon found, the first notification of a breach was followed by a second, a third, a fourth, maybe more. The next two days saw more apologetic emails following the breach, from Best Buy, Hilton Hotels and Chase Bank, to name a few. The issue reminds me a bit of the Gawker hack in December that forced people to change their passwords everywhere, myself included. So now what's exposed is not just my email address and first name, but that many companies passed the buck by putting their customer lists in the hands of a single third party who wasn't prepared for such a responsibility.

(Of course, this single third party shrugged it off as impacting a 2 percent subset of their clients)

In the 8+ years I managed our company newsletter and mailing list, from 2001 to 2009, we used a variety of partners, including Responsys and GotMarketing. Later, we put our data into Salesforce.com, and never once suffered such a breach. But in the last few years, companies have gained the ability to self-manage one's database and marketing tools, and do so independent of other companies. There's no great reason that a single third party's mistake should open up the vault to such a bonanza of brands. What this specific failure does is expose that the type of multiple verification systems and complexity expected from us as consumers isn't followed quite as well at the very companies whom we trust to watch over our personal data.

I don't have any problem with putting my email address out there. I don't mind sharing my data with TiVo and Best Buy. I shrug at Hilton and have to trust Chase, or we're toast. But I have to think we're lucky this time that the type of data accessed was so relatively harmless. People are worried that this will lead to phishing attacks and later successful breaches that get more impactful information, but for now, it seems we'll be more annoyed than ever. But think about whether you knew that all of these companies were putting your data in one basket to be raided by one intelligent hacker...

Does knowing that all these brands stuck your data in one place make you feel less safe or more safe? I think we've got to have an alternative, and self-hosting with self-managed security is looking a lot smarter these days.

December 16, 2010

Gawker's Password Compromise Has Significant Aftershocks


Gawker Media's security breach, exposing user e-mails and passwords for the network's many sites, is a mess. Not only were users' accounts uncovered, but the full database was later posted to the Web for anyone to dive through, for better or for worse, gaining the ability to find out affected users who had been exposed. Assuming that users often adopt the same password across multiple Web services, it is a safe guess many folks are on the list whose accounts elsewhere are now at risk.

It just so happens my e-mail address was included in this breach.

Using a public hashtable lookup and decoder, I found that my louisgray@mac.com e-mail address, and its corresponding Gawker password, was exposed in the attack. Not a good thing. But the good news is that after the late summer's issues of dealing with a fraudster, and changing all my passwords in many places, I'd already protected myself against this particular password escaping.

LinkedIn Forced a Password Reboot

But my work seems to have been in vain in some respects. First, my LinkedIn account was disabled. It turns out in a proactive move, the company forced all users who had accounts that matched the unveiled e-mail addresses to redo their passwords. In parallel, my Mac.com e-mail, used on Gawker, was disabled by Apple. This story hasn't been revealed in the press, so far as I have seen, and it's quite possible Apple similarly proactively disabled accounts named in Gawker's documents.

Apple Reset My Password As Well, Even Though it Was New

So, once again, I found myself changing my password on my main account with Apple, after proving through a set of online hoops that I was actually me. And again, for the second time in a few months, I am reconsidering my password strategy, and wondering if the time has really come to use services like OpenID and OAuth to avoid the obvious problem of creating unique IDs for every site.

I have no clue how many times I've left comments on Gawker sites. I'd bet it's less than five times. And in exchange for this small number of posts, my LinkedIn account and my MobileMe account are sporting new passwords, while I think in my head of other places the old password may still be alive, susceptible to open hackers who want to take over my digital IDs.

From the tech coverage of the breach I have seen, it looks like Gawker got sloppy and they paid for it. More specifically, all of us impacted have paid for it with greater levels of annoyance and needing to reconsider how we approach our online permissions. I've given my user name and password pairs out to so many sites by this point, it's practically guaranteed the bad data is out there somewhere, on servers owned by companies much less aware and proactive than LinkedIn and Apple.

Gawker screwed up and it's a very major, visible mistake which can't happen too often before site users start to turn a blind eye to registrations, and move on to alternatives. If I can't sign in with my Google or Twitter ID at this point, I don't think I want to add yet another ID that may just fall victim to smarter hackers in the future.

October 17, 2010

Life Online: Fraud, Security, Trust, Passwords and Paranoia


Occam's Razor has an intriguing two parter, penned over the last week, about how deceitful people are mining Facebook for your personal data, taking advantage of open networking and random connections to possibly use what they discover, via your open door policy, in nefarious ways. The gist of the articles? Be extremely careful who you connect to, and say no to strangers. (See: Friending Strangers On Fakebook and its follow-up: The Cindy In Your Town)

This approach, as smart as it sounds after reading both pieces, runs contrary to one of the more widely held positions in social media, that the friend connection around the corner could be the one you most want to know. Take Thomas Power's comments on limited networks being 'flawed' as a great example of someone who believes in making as many connections as possible on all networks. Many of us do this. That's one reason why there are autofollow scripts for Twitter, and why many people complain about Facebook only allowing 5,000 friends, when it's unlikely you care about their every coming and going.

I've long taken an extremely trusting approach to the Web. I chose to accept all friend connections in Facebook quite a while ago because I don't want to dictate where people want to find my stuff. If they are more comfortable in Facebook or Twitter or Google Buzz or anywhere else, that data should be there. I've taken to using Foursquare for location, and I share many of my purchases via Blippy. I even have made real photos of my own kids as part of my presence online. There are few secrets.

Some might think this approach stupid - an inevitable march toward a mistake waiting to happen that puts my data, my money or my family in jeopardy. Finally, late this summer, something did happen, but not for the above reasons - try as I might to link them.

The first sign something was wrong was when I received an e-mail from Amazon.com that shut my account outright. You might remember my post on the issue: "To Protect Me, Amazon Has Decided to Kill Me". I had hoped it was a red herring, an oddity that was not to be repeated. But it was just the beginning of a data tug of war that made me somewhat nervous, but mostly frustrated.

At first, only Amazon was impacted, but the very next day, I got another odd order, from Zappos, saying a set of steak knives I had ordered was on its way. I canceled it immediately, and thought that maybe Amazon and Zappos' shared corporate control indicated a database surprise. They told me this was not the case. Then, as I was on the phone with Zappos, discussing the issue, I got an e-mail from TurboTax, saying I had requested the User ID associated with my e-mail.


Nice Try Getting Back Into My E-mail, Jerk


That's a big no. Of course not. So I sighed in defeat, and immediately started changing my passwords everywhere I could think of - starting with TurboTax, a mere 2 minutes later. Like most people, I have a small set of passwords I use for most accounts. I had been careful enough to change it up for the most financially impactful sites, but my most commonly used password hadn't been changed since I first started using it in college - back in 1996.

A few hours later, I got a note from Apple saying too many attempts had been made to answer my security questions on my e-mail account, and therefore, the password could not be changed. This told me that for some time, the hacker had access to my e-mail account, and had correctly guessed my password worked on other sites (like Amazon). When I changed it, I had effectively locked them out. But there was one place I hadn't looked yet, an obvious place... a commerce site directly linked to my Apple account.

I logged into the Apple Store (with my new password) and saw the joker had successfully ordered a Mac laptop and a Canon camera, both shipped overnight by FedEx, using my account. The total damage was just over $2,000. The thief had used my first and last name, and my cell phone number, but not any of my credit cards. In fact, the shipments were even sent to Sunnyvale, the same city where I live, but obviously not to me.


I Hope The Thief Enjoys His Laptop


After setting a fraud alert on my credit cards, I checked all activity on said cards practically every few hours for weeks, and saw no change. My credit score didn't get impacted, and I never heard from the thief again. I called Apple to have them check into a MobileMe breach, and they put a watch on my account. I reported the issue to the FBI's hotline, only to get a form letter saying they probably wouldn't follow up. Even a call to the local Sunnyvale police came up empty, when they said the defrauded merchant had to be a Sunnyvale shop to get any help.

As you can guess, this was completely frustrating. I still have no idea how my e-mail address was compromised, or how the thief got hold of my commonly-used password, which they then leveraged to get into other accounts. The good news is that my identity wasn't truly coopted, and no charges ever hit me directly. But it certainly put some mud on my otherwise clean view of the world.

So think about how we are sharing and possibly oversharing? Our social updates from mobile phones can now track our location down within a few feet. Is that not valuable to people who want to know where we live and where we go? Do we need to give people an extra boost to find data that doesn't belong to them? I believe strongly in trusting people and getting my data on the Web, and am happy to know that none of my use of these networks set the would-be disaster in motion. But Occam's Razor is onto something as well. Are we doomed if we are careful and doomed if we are not?

I don't mind the lesson on keeping my passwords hard to crack and change them often, but should I raise my paranoia meter thanks to this experience?

August 07, 2010

To Protect Me, Amazon Has Decided to Kill Me

For the amount of transparency I put online, combined with my preference to purchase things online wherever possible, I have to count myself lucky that nothing nefarious has ever happened to my data. I have never seen false orders on my behalf, been a victim of identity theft, had to cancel accounts and change passwords everywhere, cut up credit cards, or reverse charges due to anything related to my Web use, so far as I can recall. It's possible that winning streak came to an end this last week, thanks to a flag from Amazon, saying that my account had been suspended immediately, due to suspected fraudulent activity. Rather than take their good advice, I am instead hoping I can prove all is well, and the mistake lies with them. Foolhardy, I know, but worth a shot.

I have e-mail receipts of activity from shopping with Amazon.com spanning for more than a decade. Even though I don't use the site as much as I used to, no longer buying books (as I once did regularly) or CDs (long since replaced by iTunes, Spotify and others), the idea of the account getting zapped, and needing to start over with all-new personalization and buying history, seems odd. I am something of an Internet account packrat, and I like the consistency. And even if it seems naive, I still doubt somebody got enough data to make an order on my behalf - as no other account, anywhere, shows one micron of suspicion.

The odd behavior with Amazon started at the end of last month, I bet. When I moved across town, I changed the address associated with my VISA card. Later, I went to Amazon and changed it there as well, including on my Amazon Wish List, which I typically look at a mere once a year, just before Holidays.

A week later, on August 5th, I got an odd e-mail, which was so text-heavy and non-interesting I almost dismissed it as a phishing scam. Entitled "Account Closure: Please Read", the e-mail explained:
"After careful review of your account, we believe it may have been accessed and used by a third-party to place order(s) without your permission. It seems that someone obtained your personal account and/or financial information elsewhere, and used it on Amazon.com to access your account.

We have closed your Amazon.com account effective immediately because of this possible unauthorized account activity. If this recent account activity (HP Pavilion dv6-3010us 15.6-Inch Laptop) was authorized by you, please reply to this message as soon as possible and we will reactivate your account."
Anybody who knows me knows there is no way I would by an HP laptop. Not for me, not for a friend, not for anyone I actually cared about. So it's obvious something is amiss. After checking the message's details and ascertaining it really had come from Amazon.com, I tried to login to my account, and couldn't get through. It really had been closed after all!

Morbidly curious, I checked activity on the credit card associated with the account, and found nothing weird. Similarly, no other account had a hair of concern associated. Every notification from Blippy could be traced to myself or my wife, and Chase, ETrade and Wells Fargo all came back clean. This only reinforced my thought Amazon goofed somewhere. So I reached out this week to follow up, and there's still a ways to go to finding out the truth.

Amazon makes it hard to reach anybody by phone on their site. Clearly with their scale, they want to avoid inbound calls, if possible. To get there, you have to hit Help, find the Contact Us button, and "Sign In to Contact Us". Of course, I couldn't sign in. Duh. So I clicked to skip sign in and found another set of questions to fill out to describe my story. Again, thwarted by tech, I could only put about 100 characters of description to explain. Try that. It's harder than it sounds.

Needless to say, I made it through and the young woman on the line couldn't solve my issue. There's simply no account assigned the e-mail address any more. After a decade's time purchasing on Amazon with the same ID and having them know me as well as they do, I'm locked out.

I completely understand their wanting to protect me as a customer, and stop problems before they start, but something is amiss. If my credit card data were truly compromised, would I not see spending somewhere else? What do you think? Should I convince Amazon they screwed up and get my account on, or should I start canceling and changing passwords everywhere? Either way, whether it is their fault or not, I don't think I will be shopping at Amazon very often going forward. It's a result of unintended consequences.

April 25, 2010

Why I Trust Blippy, Mint and Others With My Financial Data

In an up and down week for the startup, Blippy gained a huge amount of unwanted attention on Thursday and Friday as it was discovered that four (and eventually five) of the company's users saw their credit card numbers exposed, in full, through creative Google searches (since removed). As somebody who has registered my credit card and debit card with Blippy, you might think my knee-jerk reaction would be to pull out my data, but it's not, and I am just as supportive of the creative site for sharing transactions as I ever have been. I will continue to encourage people who want to share this activity to use the site, and I am not any more shy about putting my data into their product than I was before. Similarly, I will continue tracking all my data on Mint.com and other sites, because these companies and others like them, have proven themselves to be trustworthy and innovative - delivering me real value.

I joined Blippy in January largely because as I have been participating in and advocating sites that tell people what we like for years, Blippy takes the next step and tells people what we actually purchase, going beyond the "like". I have watched Blippy expand its social capabilities, as you can follow friends, have conversations on transactions, and see groupings of similar behavior, seeing who is buying from specific vendors, or even finding out if other friends are buying the same things you are.

My Credit Cards Go to Blippy Automatically. Zero Concerns.

Unlike some users of the site, I opted to go "All in" with Blippy, sharing not just my soft accounts, like Zappos and iTunes, with the service, but all my purchases. That means you see the boring fillups at Chevron on my debit card, my cash withdrawals from the ATM, and yes, even my wife's Teletubbies DVD rentals on Netflix for my kids to watch. I did this because for much of what I do, I am living life in public. I believe in sharing as much as possible, partly demonstrating that there is little to hide. And while some of my transactions are boring, that's just who I am.

When it was reported this week, by VentureBeat, who, from my understanding, worked on the story for a few days before issuing their initial story, that some cards were exposed, it was quickly shown to have been a limited bug, related to early beta users using a specific card from a specific bank - and was completely out of the ordinary. Blippy quickly responded to the issue, and worked publicly with Google to solve the issue, keeping all of us informed, if we were nervous. (I wasn't)

Mashable's Typical Approach to News Reported by Others

Meanwhile, you saw the typical tech press pile-on from people who had done no original research, flocking to the story like youths at a soccer game chasing a ball, as blood in the water can be exciting. But VentureBeat calmly and professionally kept the story updated, while the Blippy blog did the same, open and with considerate remorse.

There is a huge difference between making a mistake and being untrustworthy - and for me, putting my card data in Blippy is not dissimilar to putting my credit card data into Mint.com, having Intuit find my W-2 data come tax time, or entering my credit card information over and over and over from e-commerce site to e-commerce site. In order for Blippy and Mint.com and these other businesses to succeed, they need to ensure the safety of users' private data, and practically without exception, they have done so. The companies' success will come through their amassing a high number of users, and being able to report trend data based on groups and demographics, not on individuals - and thus, it is in their best interest to keep your data safe and secure.

Google Makes Their Role In Fixing the Issue Clear

ReadWriteWeb chronicled some of Blippy's response to the slip-up today, when they said what to do when a PR disaster strikes your startup. Blippy did the right thing by all accounts, apologizing, making full disclosure, and reporting how the issue was being addressed. Meanwhile, Google's Matt Cutts took to Twitter to explain what that company had done to fix the issue also. That's transparency and a closed loop response.

If I had more options to share even more data with Blippy, I would do it, and getting my e-mailed updates from Mint.com is among the highlights of this data-driven geek's week. It benefits the Web at large to get more real data about our purchases and activities public, and Blippy is one of those making the process interesting. I trust them with my information, and won't be changing a thing. You can find all my data here: http://blippy.com/louisgray.

March 17, 2010

Twitter Tightens Security With Encryption Expert Hire

On Tuesday, Twitter added computer security veteran Bob Lord to the company's expanding employee roster as the manager of network and infrastructure security, bringing with him 20 years of experience focused on electronic security systems at large companies, most recently including Red Hat, AOL and Netscape. Highlights in Lord's background include his building security and encryption features into the Netscape browser, iPlanet servers (an alliance with Sun and Netscape) and the AOL Communicator product, which also included Mail, Address Book, Instant Messenger and Calendar. Since leaving AOL, Bob has worked with a team of cryptography experts to add security features to many projects including FireFox, Mozilla Thunderbird and Red Hat Linux.

Bob's LinkedIn profile shows praise from colleagues who gave him credit for ensuring successful releases of complex application suites at AOL, as well as his being recognized as a "visionary" with energy and intensity, while at RedHat. Bob is also a patent-holder for his development of temporary digital certificate proxies that can be used for a specific amount of time.

The Obligatory "First Tweet" from the Mothership.

As Twitter's Web site and activity become more critical in the way the planet is communicating, so to will its need increase for security to protect that which is private to remain private, and enable accounts to be secured. It's also not unexpected that the company's core offerings will get increasingly complex - maybe not to the level of AOL Communicator, but expanding nonetheless.

We should be seeing what Bob will be bringing to the Twitter team over the next few years, or just keep tabs on his updates at @boblord.

November 26, 2009

Is There a Looming Battle Over OAuth's Successor?

The OAuth protocol, used on many popular Web sites and applications to pass your credentials between sites without requiring the entry of your user name and password, including Twitter, is potentially under pressure from a team of techies representing Microsoft, Google and Yahoo!, who have introduced a competing specification interpreted as being aimed to succeed OAuth, called Web Resource Authorization Protocol, or WRAP. Eran Hammer-Lahav, the Director of Standards Development at Yahoo!, who helped coordinate many OAuth contributions, and created a formal specification for the initial OAuth standard, recently panned the move, saying, "The road to hell is paved with good intentions," adding his own proposal for OAuth 2.0, which he hopes will better separate between authentication and authorization.

Today's OAuth standard is known to have its imperfections. Hammer-Lahav notes in his 2.0 proposal that OAuth is essentially "unusable" for mobile devices or installed apps, and also suggests that OAuth "does not adequately support large providers". But he says the move to create WRAP has confused developers' focus, and diverted resources, calling it "just one illustration of the demise of the OAuth community".

But his opinion, unsurprisingly, is not universally accepted. David Recordon of Facebook, also on the boards of the OpenID and Open Web Foundations, states in the comments of the post that Facebook is not supporting OAuth 1.0 as it is simply too heavy - requiring a massive increase in HTTP requests, also adding that other developers find OAuth "too difficult to correctly implement".

David followed on to his initial comments with a post to the IETF mailing list, which you can see here: Facebook, OAuth, and WRAP. In the note, he highlights the belief that the proposed WRAP alternative maps well to the company's current authentication process, adding WRAP simplifies the development community's learning curve.

The discussion, which is ongoing, may end up splintering development communities between sticking with the current version of OAuth 1.0, looking at WRAP as an alternative, or trying to support a new OAuth 2.0, as specified by Hammer-Lahav. But if you have wondered why Facebook Connect acts one way and Twitter OAuth acts another way, it's because they are different approaches entirely. If this discussion is any indication, one can expect there to be continued divergence, rather than a single way to deliver user authentication and authority between sites and applications in the future on the Web.

For another viewpoint on this broad topic, see Jesse Stay's post: The Future Has No Log In Button. Also, DeWitt Clinton of Google, on FriendFeed, says the open discussion "is good".

October 08, 2009

Benchmark Capital's Twitter Gets Hacked to Hawk Plasma TVs

Benchmark Capital had a string of profitable exits earlier this summer, culminating in a big day that saw FriendFeed sold to Facebook and SpringSource acquired by VMware on the same day this August. The firm is among the most respected in Silicon Valley, and a leading name on Sand Hill Road.

That's why I was more than a little surprised tonight to see Benchmark's official Twitter account start to spout promotions for flat-screen TVs. Not only did it look fishy, but it was done "from API", while all updates on the account to date have been "from Web", which indicates that the activity took place automatically, and not by hand.



VCs Typically Promote Their Funds and Portfolio, Not TVs...

Whether one of Benchmark's multiple Twitter users accidentally clicked through to some phishing scam, or if some bot just managed to get lucky, is unknown, but it looks like the damage was undone relatively quickly. That there are malicious characters out there trying to hack into Twitter is no surprise, but it's always eye-opening when a big name gets caught. Maybe it's time they change their password.


To be fair, many other accounts look to also have been compromised by this "Free Plasma" bot. See Twitter Search for many more affected.

April 30, 2009

Twitter Admin Screenshot Leaks Reveal Internal Data

Zee of TheNextWeb relayed a hacker's posting of screenshots ostensibly taken from Twitter's administration interface, available only to select employees within the company. The handful of screenshots display some interesting details in terms of Twitter's internally set limits, the controversial "featured users" lists, and yes, details from some celebrity accounts, including who is blocking who.

The screenshots, which can all be found in the article, Screenshots of Twitter’s Admin. Take a look a look behind the scenes, reveal what user accounts look like from an administration perspective, including a log of dates passwords were changed, when accounts were opened, last used IP, and yes, details on updates, API limits, followers, and direct messages.

Looking at the data shows limits beyond the much-reported 1,000 new users to follow per day, including:
  • A 126 update per day limit
  • A 250 direct messages per day limit
  • A 1,000 favorites per day limit
I question the update per day limit, as I would guess some people do run into that number, but it was consistently labeled across accounts, including those from @britneyspears and @aplusk.

The leaked screenshots also reveal there are, as of the time of publishing, 187 featured users of Twitter, that not only includes celebrities like Shaquille O'Neal and MC Hammer, bloggers Pete Cashmore and Michael Arrington, but Twitter employees, and "Jason Scott's Cat", who can be found at @sockington, with 424,000 subscribers.

Really. A cat has 424,000 subscribers, but you can't follow more than 2,000 if fewer than 1,800 or so are following you. Got it.

On the individual level, the leak shows that the @BarackObama account is blocking nearly 100 users, while Lily Allen and Ashton Kutcher both block Perez Hilton. In contrast, Britney Spears doesn't block anyone, but is blocked by 3,855 Twitter users. Amusing.

Go check out the article at The NextWeb to see all the screen captures.

March 29, 2009

iPhones Can Protect Your Warcraft Account, and Someday Much More

By Daniel J. Pritchett of Sharing at Work (FriendFeed/Twitter)

Two recent iPhone stories highlight some interesting potential for Apple's iPhone and iPod family.  First up is WoW Insider's announcement of a free iPhone Authenticator available in the app store for securing World of Warcraft accounts.  A Battle.net user is typically a World of Warcraft player but the accounts can be tied to any Blizzard game you might own, including their future releases.

As shown in the screen shot on the left, the Authenticator program generates a new string of numbers once every minute or so.  Once a player links the authenticator to an account, these numbers must be supplied along with a user name and password at each login — a two-factor authentication challenge.  This iPhone app is an alternative to the existing solution where gamers can pay Blizzard $7 for a key fob that generates a similar passkey every time its button is pushed.

World of Warcraft characters and items are regularly hijacked via targeted trojans and keyloggers.  They can be stripped bare in a matter of minutes, their contents flipped quickly for tens or even hundreds of dollars on WoW's thriving grey market.  Given the time and effort involved in securing an account rollback from Blizzard customer service, many players will opt for the peace of mind granted them by this new application.

The next iPhone may read fingerprints and retinas

The second tidbit comes from Apple Insider (via Engadget): An Apple patent filling hints at fingerprint and retina scanning potential in future iPhones. Apple is researching the potential for embedding biometric scanning devices (cameras, etc.) behind the touch screen of an iPhone.  Such enhanced iPhones would allow for secure identification in order to unlock the phone itself.  These enhancements would also allow the iPhone to serve as an easily obtainable high-powered authenticator for other systems such as Blizzard's Battle.net.  While we might only imagine such tools as being necessary for sensitive operations like banking or remote logins to corporate intranets, the Blizzard app demonstrates that it can be cost effective to secure our less critical digital holdings.

The Blizzard authenticator is a great example of high-powered security applications that the iPhone family can provide right now, and the recent patent filing by Apple gives us insight into other uses for tomorrow's iPhone.  We'll certainly have the mobile available as an ever-more-secure authentication tool, but we'll also be able to use it as a remote sensor for home and office medical purposes such as the recently promised glucose monitor or a biometrically secured retail barcode scanner.  There are undoubtedly more possibilities than I can come up with on my own, and I look forward to seeing some of them becoming reality in the near future.  If you've got a great example of alternate uses for mobile phones, please share it in a comment!

Read more by Daniel J. Pritchett at Sharing at Work

March 27, 2009

False Alarm on Credit Fraud Solved by My E-mail Hoarding

This evening, my wife handed me the phone, saying "It's Chase bank. They say there is suspicious activity on your account and to call them." Having never run into issues with fraud or identity theft, I've been lucky so far, despite liberally spreading my credit card details all over the Web, in a myriad of e-commerce sites and online services. With our recent travels, and my wife's own activity on the card, I thought there was a good chance this would be a false positive, which it was, but I came extremely close to canceling my card, and would have, had it not been for my often-mentioned e-mail pack rate behavior.

When I called into the fraud center, after identifying myself, the automated voice asked about some "odd" activities - one from a "record store" and another from an online eMarketing firm. Both sounded odd, so I ended up with an operator. As she explained to me, the "record store" was actually Apple's iTunes, to the tune of $.99. No problem. But the other one? It turned out it was based in South Africa, and had charged me $1.07. That was an odd number, but small, and I didn't recognize the firm. It sounded like "Quirky Marketing" or "Quirk iMarketing". Something...

When I said I didn't recognize the name of the service, the operator strongly advised me to cancel the card immediately. But I wasn't so sure. There was still the possibility I had made a mistake, and $1.07 didn't seem like a big deal. She again pushed me to cancel the card, saying if somebody in South Africa had my data, the next purchase could be a big one.

I asked her not to cancel the card, but after asking people on Twitter what they thought I should do, and seeing a near-unanimous response that I should follow the bank's advice, I was feeling like my smug naivete was going to catch up to me.

Searching Google for the firm name I thought she had mentioned found nothing memorable. And the South African connection sounded very weird. But there was one last place I could look - in my e-mail. As mentioned many times, I've saved practically all my useful e-mail going back more than a decade - making it an extremely deep personal database. So I searched for the term the woman had mentioned on the phone: "Quirk".

It turned up an e-mail confirmation from Quirk eMarketing from September 2008, for a product I had checked out called "BrandsEye". BrandsEye I would have remembered, but the "Quirk eMarketing" I'd largely forgotten. Their site left much to be desired, but my e-mail showed I'd signed up to a service that would charge 7 South African Rands a month to monitor online mentions. Depending on the exchange rate, one month's bill would be $1.01, and another would be $1.07. And while that didn't trigger any fraud alerts in September through February, today, it did. (Likely due to some other activity my wife initiated)

When I had gotten the online confirmation of my purchase back on September 28th of 2008, I moved the e-mail to my "Commerce" folder and saved it. I didn't know if I would ever need it again, but today, it came in extremely handy, and I won't be canceling my credit card. Phew!

January 05, 2009

Hey Twitter, It's Not Just a Worm, It's an App

By Jesse Stay of Stay N' Alive (Twitter/FriendFeed)

There's no doubt that the worm making its rounds on Twitter is a nuisance and a huge problem for all. The fact of the matter is, somebody has collected your usernames and passwords, and many of your accounts are now Zombies, spamming each friend on your friends list through direct message, turning more unsuspecting accounts into zombies, and spreading like wildfire. Louis has talked about the worm which has surfaced on Twitter, and the urgency of the situation and potential implications for OAuth and security for Microblogging.

I suggested plain text passwords could be to blame - after all, any application out there that collects your usernames and passwords could theoretically use those passwords to start such a worm, in order to gain access to people with similar bank account passwords and more. That would be the fastest way over, say, a single user trying to amass friends to dm. We're already seeing several of those compromised accounts sending iphone-related spam, so it would appear the worm developers could now be monetizing this, through your friends. At the same time, I keep seeing others criticizing the possibility that OAuth could have prevented this. I'd like to share my thoughts why.

Disclaimer

First of all, let me preface this with the fact that I am not a security expert. I have been developing software since I was 10 (I am now 31), and have plenty of real-world experience writing secure software. I've worked in health organizations requiring software to respect privacy around your health data, with e-commerce protecting your money, and I've written APIs. I understand what it takes to keep software safe. I also run my own business in which I also have to protect my users' data. I also understand that nothing's perfect. While security has not been my sole focus, I hope I can at least make some sense of the matter.

First Things First - This is an App

Let's set things straight here. Now, I could be wrong, but all evidence seems to suggest that this "worm" is actually an application, or possibly multiple applications, running on multiple servers around the world (the IP range also suggests that the same developers have targeted YouTube and Bebo in the past). After all, the only other way to log in on behalf of users and DM others would be to screen-scrape Twitter, simulating a user actually logging in via the Twitter.com interface. This is possible, but I would imagine we would see Twitter very quickly implementing some form of Captcha to slow it down. We haven't seen this yet so the most logical conclusion is that someone has written an App somewhere, which is taking advantage of the fact that you can login via plain text usernames and passwords. The same application is taking those usernames and passwords, and programmatically logging in on behalf of each compromised user and direct messaging their friends to collect more usernames and passwords.

Currently, the Twitter API makes it completely possible for anyone with your username and password to log in on your behalf, programmatically. Essentially, Twitter has given developers the key, and all keys open up the same lock. The only way to shut this down would be to kill the lock, which would shut off all developers. This is why the topic of OAuth continues to be brought up - to start off, OAuth forces any developer to use a protected key or token in order to log in on behalf of the user. The developer never has the user's username or password. The user himself keeps their own keys to Twitter without having to give a copy of those keys to developers.

It's not that simple though.

Why They're Saying OAuth Wouldn't Have Fixed the Problem

Assuming Twitter had implemented OAuth, let's assume no developer has your username or password and your information now feels secure. There is still nothing stopping those users from using those tokens to log in on your behalf. Essentially, while the developer couldn't screen scrape your data to log you in through Twitter with such a key, they could still use the API, just as these current Phishers are probably doing, to continue to send DMs and messages on your behalf. An OAuth token is just like another username and password essentially, intended just for API use.

The other criticism they're giving OAuth is that it still doesn't stop the Phishing. When the end-user authenticates through an OAuth-enabled website, they are taken back to a page on the originating site that, if they aren't logged in, asks them to log in, and that site in turn returns them back to the third party site with an OAuth token that can be used for access. Nice and simple, right? Well, the problem (which I've only seen theorized, but it is definitely possible) is that any third-party developer could create an app that redirects the user back to a page that just looks like the originating site (like Twitter.com, for instance), and pretends the user isn't logged in. The site could then collect the username and passwords of unsuspecting users, just as the current phishing scheme is doing now. The potential is still there to collect usernames and passwords, just as before.

The Advantage People Keep Forgetting

Let's ignore the last paragraph and just focus on the one before it. Even though an application can easily login on behalf of the user via the API, with OAuth, a site like Twitter now has full control over each and every application that runs on the API. OAuth has controls which allow API providers like Twitter to cut off any application using the API. So, assuming Twitter sets up some sort of manual approval process similar to Facebook's (I suggested this to Ev and Biz in the interview I attended with Scoble last year (end of the article), and they said they were working on this) to weed out the sketchy applications, it becomes much easier to just cut off the offending application. They now have record of the exact application sending these DMs, and can cut it off immediately. Currently, they're stuck chasing IP addresses, and trying to block various IP ranges, which are tough to block and easy to switch.

Back to the Problem

So, let's assume Twitter had implemented OAuth. We now have two possible scenarios: Scenario 1, said Phisher signs up to have an app on the API (or buys an app like Twply), and sends out DMs on behalf of users. (Note that the Phisher couldn't start as an individual and collect usernames and passwords in the manner this Phisher did in the current scenario because they couldn't send plain-text usernames and passwords via the API) The Phisher gets users' friends to login via OAuth, he collects the tokens to send out DMs on behalf of other users. Twitter's in-house alarms go off of such activity. Twitter shuts down said Phisher in a matter of minutes, and only a few people even see the worm.

Scenario 2 is a little more difficult, but less motivational for a Phisher on a site like Twitter. In this scenario, a Phisher creates a fake 3rd party app, accumulates a lot of followers somehow, and gets users to somehow think they are going to Twitter to login, and they collect the users plain-text usernames and passwords. The said Phisher can't do anything through the API, because it doesn't allow plain-text usernames and passwords. All they can do with it is screen-scrape Twitter, login on behalf of the user, and go about it that way. They also have to accumulate a decent sized following.

First, let's face it, there's not a ton of information that's not already public a Phisher can gather on such a site as Twitter, other than their username and password, which could also be used on other sites like banking sites. I really think most of these Phishers are more interested in spamming you, trying to make a quick buck off the unsuspecting sending spam to their friends (like the iPhone example above) - selling the data to spammers I'm certain is big bucks (at least $1,200, according to the sale of Twtply). Second, Twitter could easily implement a captcha system in such a case, and by that means they could at least slow down the Phisher or spammer. At that point, if the Phisher or Spammer is still diligent enough to get through, they have a much more controlled system, and they can then play the IP blocking game. Let's face it though - this isn't a banking site, usernames and passwords only go for a meager $1,200 from what we know, so most spammers ought to give up at that point. It's much less of a problem, and much easier of a problem to deal with than what Twitter is seeing now.

The Purpose of Security is to Make it Harder

As I said earlier, no security plan is a perfect plan, but the harder it is for a perpetrator to get through a system, the more secure that system is. Currently, there is no barrier between Twitter and those than can potentially misuse your usernames and passwords, other than you. As I said earlier, Twitter has only one lock for each user, and each developer you share your information with has the same key to that lock as you do.

However, despite the continued risk for phishing OAuth poses, as Lachlan Hardy suggests at the end of his piece here, it is still a step in the right direction, and I think would have prevented this particular worm. OAuth would have given Twitter the capability to revoke the keys of the offending phishers, enabling them to shut the worm down when it happened. After all, this isn't just a worm, it's an app, using the API, like any other developer, but in this case to spread malicious websites. I want to suggest that Twitter stop skirting around this issue, stop pretending OAuth wouldn't have solved the problem, and just implement something, quick.

Read more by Jesse Stay at Stay N' Alive.

January 04, 2009

Twitter's OAuth Target Slipping Amid Increased Security Pressures

Over the weekend, more than one exploit, sent by way of Twitter's Direct Message feature, has made it around the Web. As Twitter's growth has continued, the microblogging service looks to be a new domain for scammers and spammers, previously contained to traditional e-mail. And as the shenanigans gain in momentum, so too does the call for Twitter to implement OAuth, the open protocol that allows for secure API authorization, which has become popular among many Web tools in use today. But Twitter employees' postings in the service's development group, and their own notifications on the site, show a shifting roadmap, while they also try to divert criticsm by separating the need for OAuth from the weekend's incidents.


An example of one Twitter phishing attempt.

Twitter's success has seen a groundswell of applications being developed that require users to enter their user name and password on third party sites. Given Twitter's lack of OAuth support, Twitter users have grown used to posting their data whenever they are asked, and in the rare case a site has been found to malicious, it forces them to once again change their passwords to protect their account.

The OAuth Web site spells out the reason behind the project's development, saying: "If you're storing protected data on your users' behalf, they shouldn't be spreading their passwords around the web to get access to it."

The weekend's activity featured a mock Twitter login page, where users were prompted to enter their credentials. (See: CNet: Twitter phishing scam may be spreading) While this specific attack would not have been solved by OAuth, but instead by users simply paying attention to where they were logging in, you can see Twitter's attitude on the current process.

Alex Payne, a lead developer of Twitter told one user on Saturday: "Right now, you can't see which apps are using your requests. You can change your password, though.", and later told another user, "We're trying to discourage against clicking on the link." Pretty basic stuff.

When pressed on whether Twitter was going to implement OAuth, and reduce users' growing too comfortable with posting their passwords everywhere, Alex said, "OAuth isn't a panacea against phishing and other web security issues. We're still going to support it," and following on, echoed the OAuth site by saying, "A main benefit is that OAuth limits the scope of activities that can be done with a user's credentials," while also linking to a post from April of 2008 that showed how phishing scams could not be stopped by OAuth. See: Phishing Fools?

So, we get that the phishing problem won't get solved through adding OAuth, but we do see more and more applications getting your password. As the New Year came in, Twply managed to get many passwords, and then was sold the same day. (See: Scobleizer: Twitter spam, effective or idiotic?)

Alex mentioned Twitter is going to support OAuth. But when?

In the Twitter Development Talk forum, you can see the target continues to move.
Alex, on November 24th of last year, wrote: "We're currently waiting on our User Experience team to put the final touches on a BETA release of our OAuth support. It's going to have bugs, to be sure, but we should have it out there soon. "
On November 26th, after being pressed for a date, he said, "As I don't know the entire schedule of our UX team, I can't. I would say less than a month and closer to a week by far, but please don't hold me to that."
On December 8th, Alex gave more specific timing: "It won't be available for testing this week, but should be available before the end of the month. I'd definitely encourage you not to launch on it, though, as it will be a beta."
Now more than a month from the first comment, amidst more developer pressure, Alex says the next major version of the API will be OAuth-only, but deflects some of the criticism by pointing fingers at other services that have not yet jumped on the OAuth bandwagon.

This afternoon, January 4th, Alex said:
"Of course, once we offer OAuth, it would be nice to see the same community pressure that's been applied to us put towards companies like Amazon. The Amazon.com iPhone app collects my username and password, and that account is actually tied to my credit card information. Where are the blog posts about their anti-patterns?"
Now, there's no question I'm no security expert. Don't forget that on November 12th, I once wrote, Twitterank Can Have My Password, No Questions Asked, and Alex looks to be feeling the strain of other non-experts, like me, pushing the team to get more robust. He commented on Twitter this evening, "It doesn't help that web folks generally have next to zero security/crypto education," a bucket I'm no doubt in.

The groundswell of demand on Twitter to improve its security measures, to get to OAuth as quickly as possible has no doubt reached a crescendo in the wake of this week's exploits - both those solvable by the project and those that are merely phishing scams. But it looks like Twitter developers' confidence has been shaken by so many promises being out there, and the deadline continuing to move.

September 11, 2008

Google's Suggest And Search: Never Completely Private

By Phil Glockner of Scribkin (FriendFeed/Twitter)

Recently, I have been thinking about a particular feature of Google Chrome. If you haven’t used Chrome or haven’t been following the news about it, it is a new Web browser from Google. The feature I've been mulling over is its almost-magical location bar. Google calls this the address bar, but it is also called the location bar or URL bar.

Apparently, a dedicated open-source Google project team called Chromium came up with this new address bar technology, and they call it the omnibox.

Omnibox

On its face, the omnibox is a great improvement over the more generic location bars of pretty much every other Web browser out there. It’s a URL input field combined with a Google (or user-defined) search engine front-end, and it throws in several other tricks to boot. In my opinion, the only thing that really comes close is Firefox 3’s optimistically-named awesome bar. This is different than the location bar in Firefox 3, which by default only looks through your bookmarks and history to find matching search results. Google actually uses its vast search database, using a technology called Google Suggest.

Google Suggest

However, it’s not just in Chrome. Firefox also employs Google Suggest in the search input field next to the address bar if your search is set to Google. You can also find it on Google’s classic home page (i.e. not iGoogle), and in Google’s mobile application and site (if javascript is supported). On the surface, Google Suggest is great. Just start typing whatever you are looking for, whether it be a Web site or keyword, and Suggest goes off and tries to predict what you are typing with increasing accuracy. This is especially useful on mobile devices where typing can potentially be annoying.

Privacy Concerns

The one big drawback of this technology is that your search terms are transmitted as you type them to Google’s server. They literally know everything you type, including half-finished search terms that you subsequently erase without submitting. And what if you accidentally had copied a lot of text into your cut-and-paste buffer and dropped that in the address bar? The whole buffer would be in Google’s hands immediately.You can see where this could lead to a potential problem. What if an executive of a giant company started to search for an insider-trading tip just prior to dumping a lot of stock? Could these partial search results be requested by subpoena in a resulting civil trial?

Google’s Promise

Earlier this month, Google did in fact consider this issue and updated what and how much they cache from Google Suggest. You can read the details from the official Google blog here. In summary, they promise:
  • 98% of Google Suggest searches are not logged.
  • 2% of these searches are logged with IP addresses.
  • These 2% will have their logs will be ‘anonymized’ within 24 hours of search result, starting late this month or early next month.
Keep in mind that this promise is specifically for Google Suggest searches. If you actually submit your search query, Google’s standard privacy assurance goes into effect, which you can see explained very simply in this YouTube video. It seems reasonable to believe that Google is putting forth a good faith effort to protect your privacy while balancing the needs of their search business.

Another Dynamic to Consider

Google isn’t giving you the whole picture though. Sure, having a cutting edge search engine is what made them the first name in search. However, their business revenue comes from advertising, not search.How does this affect their high-wire balancing act? Well, it’s not completely clear. However, they didn’t become the first name in Web advertising by not involving search. In fact, search is key to the effectiveness of their advertising business.

The Google banner ads you see in your search result pages, and the Web pages with even more targeted advertising when you click on a link in that result page, this is how Google makes its money.You can safely assume that Google is always feeling pressure from their profit center to hand over as much information as possible on search results to help in making their advertising even more clairvoyant.

Traditionally, Google has been clever and has worked within the very simple dynamic of search terms, geographic locations, and statistical results in order to make this advertising highly targeted. However, their brain trust is gigantic. If you can think of something, anything they could possibly use to help their ad business, they probably are developing it in the lab, or are using it on their site. Local, national and international news at the time of the query. Related geographical searches. Platform search is performed on (Windows, Mac, mobile, etc.). Which query result is chosen. Time between search and click-through. Basically, everything.

Getting Back to Privacy

So how does this affect you? Well, the bottom line is, what you do on Google’s search engine will never be completely private. Like throwing a rock in a pond, the ripples are immediately noticeable and quickly die down, but the waves might not hit the opposite shore for a while. Tiny traces will always be left, and it is those traces Google uses to improve its search, and ultimately its search-based advertising.

The Bottom Line

You do have to make a decision if you want to participate in this giant information machine Google has built behind its sleek minimalist Web site. Some people think Google Suggest is going too far. Some may think that Google Chrome’s Incognito mode will keep them safely anonymous.The answer to both of these is: Not quite.
  • Google Suggest does gather more statistical data (such as typing speed, number of corrections, etc) but anonymizes that information quickly.
  • Incognito mode only works on the client side, that is to say, it keeps your audit trail off the books on your end. If you use Google to search for something with this mode turned on, they still get all the same info they would get if you weren’t using it.
The only real privacy solution, the only way to remain out of the grand Google experiment, is to not search online at all.

Read more by Phil Glockner at Scribkin.com.

August 02, 2008

I Got a Mac OS X Trojan and Infected CenterNetworks. Oops.

As a sometimes smug Mac user for the overwhelming majority of my computer-using life, virus warnings, anti-virus software and security updates were always something "those other guys" had to deal with. Using my Mac, I would even have colleagues send me attachments from their Windows machines which they thought were viruses, so I could open them up in a text editor and see what mischief they had intended to cause. But today, I realized my laptop had somehow acquired a rare trojan that does hit Mac OS X, and the results of the bugger were actually more harmful for Allen Stern of CenterNetworks than they were for me. Oops.

This morning, Allen Stern presented a new video following a press conference he held that discussed his take on the "firing" of my son Matthew, who had secured a short-lived position in CenterNetworks' San Francisco bureau. As usual, Stern's tongue-in-cheek humor and deadpan delivery were very good. The conclusion reached by his video was that Matthew would be compensated out of court with the delivery of an "I love New York" t-shirt, and I quickly commented on his site that we agreed to the settlement.

But amusingly, having posted my comment, I noticed that virtually all of the ads on Allen's site were for pills that solved erectile dysfunction, and all the banners were rotating images of Viagra, Cialis and Levitra, which made no sense on Allen's tech blog, and had absolutely zero to do with his story on my kid. So, I made screenshots, and jokingly sent a note to FriendFeed, saying, “I Just Hope the Money from these Ads Keeps CN "Up".


CenterNetworks' Ads Were All In Pill Form for Me

Allen, looking at the pictures and then back at his site, thought I was joking. But I wasn't. When he realized I was serious, this set off a flurry of calls by him to his advertising partners, swapping out of ads, and testing both on his side and mine, as we tried to figure out... was it him, or was it me?

Turns out it was all me, and separated by 3,000 miles, I was causing Allen's blood pressure to rise for no good reason. It turned out that at some point, recently, some file I downloaded hijacked my DNS settings on my MacBook Pro, and selectively overlaid his banner ads from Tribal Fusion, on both CenterNetworks and HTMLCenter, with these stupid Viagra ads. Meanwhile, my wife's laptop was fine, showing normal ads, while I was viewing the world through an odd filter.

So, I did some searching on the Web and found I had likely run into one of the few pieces of known Mac OS X malware out there, a Trojan, which disguised itself as a clean file. So, I decided to finally get some real anti-virus software to take a look at it, and found a solution from Intego called Virus Barrier, which looked a lot more Mac-friendly than dreck the Symantec guys offer. Sure enough, after paying to buy their software, installing, and rebooting, the offending file was found, masquerading as a QuickTime extension. The Intego software let me delete it, and all of a sudden, all was well. Allen's site now shows normal ads, and he doesn't carry the mark of a dope dealer.


Intego Virus Barrier Going Through My Files



Aha! A trojan has been located and destroyed!

Of course, this now raises the question... how did I get this on my machine? Some of the stories I read said the trojan could have been hiding in the form of a fake card game application, and others, as a tool that lets you watch adult videos. So... neither one of those makes sense. But despite that mystery, the good news is that I think it's all resolved. I have a product that will protect my Mac in the future if anything like this happens again, and I still know Allen Stern is on the up and up - a great blogger with a good sense of humor and values as well. It's just disappointing my stupid error somewhere dragged him through the mud through my "learning process".

June 23, 2008

Is Your Web Getting Filtered? What's Blocked or Unlocked?

Entering our third full day here at Lucille Packard Childrens' Hospital with our twins, I have to say I'm impressed with the easy access to high-speed wireless Web. For me, wireless high-speed access is a must, and I don't have much to complain about. Interestingly, the hospital's system, by default, has instituted filters, in theory to protect them legally, and maybe to conserve on bandwidth. This doesn't bother me too much, but as I surf, seemingly with one hand tied behind my back, I find that the sites they've opted to block, and those they've allowed to go through at times have me scratching my head.

I noticed I couldn't log into my Mac Mail via the desktop application right away, but Webmail was fine. I later noticed some sites were blocked when I tried to visit Athletics Nation and follow yesterday's A's game. Safari reported being unable to visit the site. I checked other Sports Blogs Nation sites. Those too, were all down.


A Sample of Approved Sites and Those Blocked


Then, after many on FriendFeed had demanded some early photos of Sarah and Matthew, I tried to take the pictures I had from the last two days and post them to Flickr, feeding the beast. But they were blocked. Then, I tried to log on to my FTP site and upload them to louisgray.com directly. No dice, again.


Sorry, can't upload via FTP!

Luckily, I did find a work-around. By sending the photos via the great Mail2FF program, as attachments, the photos themselves were saved on Amazon's Web Service and archived there. (It's the same way I "cheated" and got FriendFeed to host the graphics in this post for me)

After last night's post on my 10 beliefs in blogging and the Web, I saw someone had posted the story to Hacker News. But I couldn't see who, again, thanks to it being blocked.

IM Blocked: iChat and Google Talk don't get through.

The blocking seems well intended, but random. It makes sense that I shouldn't have access to Fleshbot or AdultFriendFinder (mind you, I just checked them to see if they were filtered), but it makes less sense to have sites like Sports Blogs Nation blocked, when ESPN.com is approved, or to have Hacker News blocked if Techmeme is given a pass.

I'm lucky that I usually don't encounter Web filters. I have free-flowing access at home and at work, and this weekend's experience has been outside the norm. If you are filtered, whether it be at work, at school, or at the library, what sites have you found blocked that you think are wrongly stopped? I'm curious to see if this setup is too aggressive, or in line with your own experience.

April 19, 2008

Banning by Computer, Repairing by Hand, Google KOs TechWag

For many blogs, Google traffic sends the overwhelming majority of visitors. TechWag, a technology blog authored by Dan Morrill, claims Google constitutes upwards of 80 percent of traffic. Or it did... because earlier this week, Google identified his site as harmful, and instead of sending people to his site, would-be visitors are instead warned that by visiting TechWag, their computer could be harmed (See why). As a result, traffic has, as you would expect, evaporated.

Dan walked through his site, contacted his hosting company, and resolved the issue, before April 16th. But by the 19th, the issues still have not been resolved. As he writes in a post today (We are not a Malware Site), "Google is going to take its own sweet time cleaning up the disaster in their index. It does not matter how fast you clean it up... what matters is how fast Google can clear an erroneous flag in their database."


Google Warns Visitors to TechWag.com

Dan estimates it took five hours for Google to block his site, and another five hours to resolve the initial issue. But Google's Webmaster tools claim resolving the block will take "several weeks", and they "unfortunately ... can't reply individually to each request."

Google's not being evil, and was well-intended to steer would-be victims from what could have been seen as untrusted code. But the disparity of time taken to block and that taken to fix is going to have a real toll on Dan and his site. And while I may not be the biggest fan of ads on blogs, Dan does have them, and if he was looking to get any kind of paycheck off this week's activity, he's going to be sorely disappointed.


After Clicking the Link in Google...

As he writes, "Come on Google, if you are going to kill off a web site, at least have the courtesy to respond at Internet speed. Taking two weeks to check to see if we are “ok” is absolutely unacceptable."

Why can I read his site? Because I trust him and TechWag. It's a great blog. (Also I use a Mac, so I'm not too worried...) Too bad most visitors from Google are likely going to be scared away. I dare you to take the risk. Go to www.techwag.com and sign up for his RSS feed. It won't hurt. I promise.