Saturday, January 3, 2009

Twitter probably needs an API key generation system to thrive

Good-Luck-Proxies

There's a big bad phish going around on Twitter today. Likely either related to the Twply thing or seriously emboldened by it.


One of the first things I considered when I looked at the Twitter API was that it was wonderfully open, and ripe for abuses. Coupled with a Phishing attack there are a lot of powerful methods to disseminate viruses, malware, and to collect passwords. LOTS of them.


From the Twitter blog:


It looks as though this particular scam sent out emails resembling those you might receive from Twitter if you get email notifications of your Direct Messages. The email said, "hey! check out this funny blog about you..." and then provided a link. That link redirected to a site masquerading as the Twitter front page.


Anyway one thing that might help stem the tide of Phishing attacks, and API-service type attacks (Twply style trust attacks, where they say they're going to do something, and all they really do is take your data), an API key system, or a drastic evolution of the current API method.


It's not like I'm saying anything radical, actually, this is likely in the works at the volcano/skull island that houses Twitter's developers, but it's more the shape of things to come. You'll likely see a slightly more complex and less "impulse buy" friendly API system emerge. Hopefully safer than the seat of the pants insecure method used now.


And as Pete Cashmore says, it might be a sign that Twitter is "for real".

Friday, January 2, 2009

About that password thing...

I re-twitted this alarming post from @JennKim last night regarding a Twitter scam site


@JennKim Think twice before leaving your Twitter password http://tinyurl.com/7wq2gt


From the article linked above...


Twply, the Twitter site that promised to email your replies to your inbox while protecting your password, appears to have tweeted a promotional message for the service on your account even if you opted out of this option. To add insult to injury, the site was sold today on Sitepoint for $1200, just one day after launch. The site, which required you to enter your Twitter password, has now sold that confidential data to the winning bidder - site user worldbuyer.


Sucks! Also I'm sorry if you are reading this and were burned by this service. BUT, yeah, never trust anyone with your passwords.


This is the new face of the electronic security compromise. People don't put the importance of security on their online passwords as they do with, say, the PIN number for their bank cards.


If you spend a lot of time online, you really, really should. Why?

  • People use the same passwords for multiple sites.

    It is unfortunate but it's a reality that won't change as long as we are human. The password system does sort of suck, but it's what we have now until the populace gets comfy with digital keys. You don't have to have a different password for every occasion, but I try to have three or four rotating strong passwords I use at different sites. The bad news on this front is some places (often financial firms) won't let you use strong passwords with characters like @ # $ % or & in them. Dumb but true. So what ends up happening is that people will pick the weakest but most compatible password they can remember and they'll use it everywhere.



    We also use the same login for multiple sites.. more on that below.



    Fix: Generate 3 good passwords and try to use a password manager with your PDA or phone. You don't have to use the password manager every time, but it can help jog your memory when you forget.



  • Website security is always much worse than you think.
    Take it from an insider; if a website wants your username and password so that it can access another website on your behalf, it is going to store that username and password in a database in PLAIN TEXT, no encryption and with the most basic of protections.



    It is only marginally better, often, if you are submitting your username and password to a forum. The passwords might be encrypted, but that encryption can be reversed as well. It's worth it to a hacking group to decrypt a series of passwords, and they always have the horsepower to do it (think Storm Botnet).



    Fix:Don't trust any of these places. Even Facebook! I couldn't believe Facebook wants me to input my GMail username and password so that it can scrape my address book for friends. The audacity... Sure it works, but now your GMail account and password are on record in a Facebook database somewhere, for EVAR. When the Badguys get into that database, they have your account and password info.


  • Badguys will compromise your accounts, even if you think they aren't important.
    So now a website is hacked, let's say via SQL injection or a straight buffer overflow. No matter how, the Badguys now have access to your username and password. What can they do with it?



    1. Cross-reference your username with a domain-name database to see what you have registered. yourname.com is now a target of domain jacking.
    2. Try your username and password combo at places like GMail and Hotmail. If you signed up to twitter as exampledude, and your hotmail account is exampledude@hotmail.com.
    3. They read your e-mail to find out what banks and online financial institutions you use. Paypal, etc. They are now closer to having access to your money.
    4. They scrape your e-mail accounts for users and send them viruses, personalized, from you. They send you viruses from your friend's addresses. Personalized Phishing may be on the horizon as well.
    5. If they have access to your e-mail accounts, they can take your domain. If that domain has e-mail accounts associated with it, they now own those too and the cycle repeats.


    I could keep going like this. tl;dr it's a domino effect. The badguys get one compromise, and they can keep going with that unless you've used good username and password hygiene.


    There's a lot of excitement around social networking and mashups right now. There's a great sense of community and optimism towards anything to do with it. It's refreshing, but I think in that atmosphere people drop their guard a bit in the hopes that everyone intends only good.


    But, this is still the Internet.

  • Sunday, December 28, 2008

    From Tim O'Reilly's Radar: Thoughts on "In Distrust of Movements"

    I wanted to bring attention to this post on Tim O'Reilly's blog about a post on another blog that is a reprint of an essay by Wendell Berry.

    Got all that?

    In any event Tim's post will bring you down a really interesting rabbit hole relating to a huge basket of issues from food sustainability to the current state of the US economy.

    I'm still digesting, and clicking on link after link.

    Saturday, December 27, 2008

    oblique: Dictionary.com Word of the Day

    http://feeds.reference.com/click.phdo?i=1659755b284c5836c3e15694f72ee480


    --
    From the iPod of Simon Carr
    Ineocom Technologies
    http://www.Ineocom.com

    Friday, December 26, 2008

    My Book for my Time Machine


    Western Digital My Book 640 GB

    Spot the Western Digital My Book 640 GB, converted to be used with MacOS X


    Just picked up this WD My Book 640 GB drive for use with Time Machine from Best Buy Canada, before I go all Reuserist in 2009. This is sorta my final call to buy new crap before my experiment kicks in. So a 640GB external for $109.99 is a pretty good deal[1].


    This new drive does serve a vital purpose; acting as my Time Machine backup, replacing the 250GB drive that was starting to do the click of death, and the old drive was technically too small to actually back up the primary drive in my new iMac.. So all things considered I don't feel too bad about the purchase of this new awesome fast external. It also looks like a book. Pretty.


    I ran into some challenges. If you just plug it in to your Mac, it's formatted as an MS-DOS filesystem. That's fine for compatibility because everything in the world can read that, but I'm trying to use it for exclusive Mac Time Machine backups. Opening up Disk Utility, I couldn't manage to remove the partition on the drive, which came up as the device "596.2 GB WD 6400AAV External Media", with the partition "My Book". After doing some digging I found the answer (macosxhints, always, awesome)..


    Warning before you start: This procedure will wipe all the included files on this drive. Personally I had no use for them, but you may want to save them.


    To clarify this URL, here's the visual;


    Picture 5-1


    Image 1:, rather than select the partition on the device, select the device. This will give you the "Partition" tab, between "Erase" and "RAID". Pick Volume Scheme: 1 Partition. Name your partition, pick "Mac OS Extended (Journaled)" if you are going to use it for Time Machine as I am, and then select "Options..."


    Picture 6


    Image 2: Inside options, pick "Apple Partition Map". By default it will have "Master Boot Record" selected, which is where Disk Utility runs into trouble.


    Click ok inside Options, and then Apply, and vavoom, you're off. If you want to feel safe about the change you can always remove the partition again and re-create it. From there you just have to configure your Time Machine.


    This drive is also advertised as 30% more energy efficient than standard systems. I can guarantee that's the case for the drive that it's replacing.



    Points of Interest

  • Disk Utility
  • Time Machine propaganda
  • The sale at Best Buy Canada


    Footnotes
    [1] Oh, yes Internet, I know... if I scoured the dregs of online computer stores I'm sure I could find some better door-smasher deal. I'm not going to weep tears over $15 worth of savings that would cost me a virtual $30 of hassle (and shipping perhaps). /snark_mode OFF :)

    Technorati Tags: , , ,

  • Tuesday, December 23, 2008

    SimCity for the iPhone

    Picture 4-3



    I'm a SimCity freak, and I have been since the Commodore 64 version hit in 1989, but I had no idea that EA had finally released a version for the iPhone. (thanks calebcherry).


    First impressions? Good! I was actually a little skeptical until my first city started building, and bam, my old SimCity addiction kicked in.


    The interface is not as clunky as one would expect considering the small screen size. The menus take advantage of the iPhone interface, and have iPhoneisms, so it jives nicely with the rest of the iPhone platform.


    The music still has that same SimCity, "I'm watching re-runs of Beyond 2000" feel, which I quite enjoy. I haven't heard any tracks I recognize from previous SimCity games yet but I wouldn't doubt that they're in there.


    Advisors aren't blocky sims, which I'll kind of miss. They're oddly "anime" looking as others have noted. I understand that choice though, why render 3D dudes to yell at you when a cartoon will do?


    From a complexity standpoint it sits smack in the middle of the original SimCity and SimCity 3000. In fact it shares a lot of traits with SimCity 3000, and early screens of the iPhone version were dead ringers for the SC3000 interface. The game is not anywhere near as complex as SimCity 4 (of course), but it still has a satisfying number of knobs to tweak.


    In summary, should you pick it up?

  • It's under $10.
  • It's got enough SimCity feel to satisfy.
  • I'd buy it even if I was just going to play it once waiting for a flight.
  • It won't replace SimCity 4, but you can play it while on the can, so, there's that...


    This will certainly be one of the apps that eats up my battery life. Coming soon to this blog: a post about "poor battery life" on the iPod Touch! In no way related to my 8-hour road-planning stints.


    Points of interest


  • SimCity at Wikipedia
  • SimCity for iPhone

  • Technorati Tags: , , ,

    Monday, December 22, 2008

    iBook Nostalgia: (and The Top 8 Stevenote Moments)

    Via Guy Kawasaki's Twitter,

    The Top 8 Stevenote Moments. ..which is a cool article,

    But I want to take a moment to highlight the 1999 keynote where the Clamshell iBook is unveiled.



    Usually there is some (*snicker*) amount of hyperbole in these keynotes, but during this segment I can't help but mostly agree with Steve Jobs on what made the Clamshell iBook so exciting at the time. It really was an amazing portable for someone who did a lot of rough traveling and the specs aren't exaggerated as exciting. Michelle, the author of the article linked above, may disagree. But as a long, long time owner of a blue and white Clamshell (that matched my Perl Cookbook, oh lord I'm a geek) I can safely say that I wasn't let down.

    In fact I'd say the iBook and the Mac OS X Public Beta were two big helpers in my career path. It's possible one of the factors in my hire at Tucows was that I had the audacity to sport the "iPurse" at my interview.

    Early chatter about OS X drove me to experiment with FreeBSD from a Linux user's perspective, which increased my knowledge of both exponentially, and having the iBook itself let me do it anywhere... which, you know, when you're in your early 20's is important because you're never home.

    Time goes by of course and 9 years later you can't help but chuckle at the specs that were pretty hot upon release. I have an iPod Touch sitting on my desk that has a 400MHz Arm processor and 128MB of RAM, and it's smaller than a deck of cards.

    Current laptops and notebooks are obviously much "better" at the present moment, but none of them have inspired me as much as the first generation iBook had. The missing element is charisma.

    Technorati Tags: , ,