Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

30 May, 2019

heroes always get remembered, but you know legends never die

Oh, look, the very very bad idea of deliberately breaking cryptological programs has surfaced again. And as the writer of that article says, this is such a staggeringly flawed idea precisely because it demonstrates both a complete misunderstanding of the internet, and a complete misunderstanding of digital security.

But I'll repeat it here: if governments want effective security to protect their own interests, they want that security tight. Insisting that everyone else accept broken security will do two things: first, it will cause general resentment from everyone (if not outright rebellion when corporations say the hell with that nonsense and pull for working security anyway), and second, it will inspire people to break government security. For the value of the information, for spite, just for the hell of it--the why won't matter. The fact that it will happen does.

Moreover, as the writer also pointed out, there is no cryptographic system on the PLANET that hasn't been broken. There are codes that haven't been broken, but as far as digital security goes, the best we can say is "it hasn't been broken yet."

And that really should daunt governments that keep proposing this ridiculousness. Every country who's actually passed something like this has been hacked. And guess what--every country has been hacked anyway, whether they employ broken security or not. Corporations have been hacked. Individuals have been hacked. There is no privacy. And we need to realize that.

The best cryptography on the internet? Is NEVER TO PUT IT ON THE INTERNET.

At the Tres Chic event recently, since it had just opened, I knew it would be lagged; so I turned down my settings and put jellydolls showing up at anything over 24K. And saw this:



Did she really have four arms, or was it just the mesh glitching?



It looked like she had four arms. I admit I was intrigued.



She did have four arms.



Very articulated arms, though I was beginning to wish that most of Tres Chic wasn't so stark white; it occluded much of her outfit, her robotic attachments, and her hair.



I'm pretty sure they were Bento-rigged, because yes, her robotic arms moved with her real ones.



They even changed hand positions.

I was enthralled, to the point that I didn't even try to find out from whence she acquired these marvelous arms. But it was a great look. Really well done, highly impressive.

03 February, 2015

gather up your tears, keep 'em in your pocket

So Massively is shutting down...Which is just odd to me. Forget their Second Life coverage, but I still read that blog. Hells, today I sent out a tweet concerning a Massively article, it's not like my attention wandered five years ago. Why, AOL? Why are you doing this?

Something I think is always worthwhile to pass on every now and then is good password management toolsets. This entry from the Crash Override Tumblr is an excellent article, with multiple links to explore to learn more on why password randomization is a good idea.

In the meantime, Garena ESports have wholly and utterly lost their tiny brainless minds. First, what does it matter if a female play is a lesbian, or a trans woman, or both? Second, why did they feel the need to develop rules for the Iron Solari that would exclude female players from playing in female-only teams? Don't they want players for League of Legends? Isn't that the point of any game?

Also, in a few years (presumably, once we all have mood- and chemical-balancing brain chips) we may be able to press a button and reset our circadian rhythms. I have a few friends who this might work for, and well--assuming the technology tests out in humans. (Right now, they're still studying the effects in mice.)



And goodbye, Mr. Whybrow. I could not come to your official wake; I was too overwrought still to be good company. But I did go to the memorial, and wandered those items which friends had left. You would have approved, I think. Someone finally finished working on a highly ornate musical ornament, because you'd encouraged them to start. There were flowers, cherry trees in full bloom in defiance of the seasons, places where gentles could gather and converse around a fire. Candles, and of course, pictures of your redoubtable shopgirl. It was rather overwhelming in itself, but I am glad I went.

It makes losing you no easier, but knowing how many lives you touched, that does ease the grieving.

21 April, 2013

like Jonah, will be swallowed whole, and spat back teeth and bones

New JIRA going around, and this one is plainly...crackheaded. Here's the text of the complaint (because I can't honestly call this a requested feature):
With the rash of accounts being hacked lately, it still surprises me how easy it is to purchase Lindens through the viewer if you happen to have PIOF. You only need to click in the upper right hand corner and fill in any amount, and as long as it's approved, the transaction will be processed. First off, I no longer see the point of having PIOF in the profile, but can make people more of a target.

Second, what I propose is that when you click on purchase Lindens, a second window will pop up asking you to enter ANOTHER password [separate] from your Second Life password to confirm the order. While it is an extra step, it still doesn't make purchasing Lindens difficult, making your personal info a tad bit more secure.
I realize how frustrating getting our accounts hacked--in any world--can be. It feels invasive, it feels as if we've lost our safe havens, and it is genuinely hurtful and angering. I get that. I've been hacked, so believe me, I get that.

But this won't help. Let me say that again because it sounds vaguely important: THIS. WILL NOT. HELP ANYONE.

In fact, it's only going to make the program worse. Say Ms. Paine actually pushes this through, via some incomprehensible act of Linden. What happens? Everyone gets a second password to choose.

In the interests of public disclosure, the worst password of all time--that's remained on the worst passwords lists for at least two years running, if not longer: password. I'm not even kidding. Past that, the next five worst passwords? 123456, 12345678, abc123 (or its "hipper" variant, abcd1234), querty, monkey, and letmein.

That's not even bringing up the other standards, lower on the list--the ones that start with god and move to sexy and make us all glad we live in a culture where eight-letter passwords are the norm, not three-letter ones.

I'm not saying this to be funny in the least. Some folks on the internet order the extra bushel of dumb to go with their dumb; it happens because not everyone is bright (which includes bright people). In general, people just don't think these things through, and that's not even just an idiot factor--everyone has moments where they react blindly, and rarely in good ways.

To make this personal, I consider myself fairly internet-savvy--but when the Gawker family of blogs was hacked, I had to scramble to protect the rest of my data. Why? Because I used the same damn passwords for about 75% of my accounts.

Even now, years after the incident, I still have my password-protection program of choice yell at me when I choose a password for one site that I've used for something else. Which means yes, I'm still making those bonehead mistakes.

But let's go back to the JIRA--how would having a second password save most people? With programs like Secondlife Money Hack distressingly easy to find, plus people using simplistic--and easily guessed--passwords, how would a second password save anyone? Average Jill or Joe on the grid--or, in the grid's case, average BIGTEXANSTEVE or sexiigirlii9518 on the grid--is going to be told they need two passwords. I guarantee you that at least eighty percent of everyone given this boon will wrack their brains for a solid week before having the a-ha moment--they'll supplement their perfect password--"sexmoneygod111"--with their new protect-everything super-sekrit password--"1234512345"--and everything will be fine!

Tell me again how this solves the problem.

Tell me again how this even addresses the basic problem, which I guarantee you, is not payment info on file. (And if you read that even halfway seriously, from her JIRA description, you realize she's also sidewise saying that payment info on file should be dropped from the SL bio anyway, because of "targeting".)

I fully grant, I don't get a lot of the people out in the world, any world, and I certainly don't always understand the things they view as extreme problems. But this? Even just restricting things to Second Life, alone, this isn't even in the top five problems SL has! It's not even in the top fifty!

You want to know how to stop the rash of hacked accounts? Make the accounts harder to access for the criminals, not the account holders. If you really want to protect account information, attach everything to an individually-generated keyfob account number which rotates every eight days and can only be accessed by the account holder answering three security questions every time they want to make a transaction.

Because that would work. (Though again, I guarantee you people would bitch about it, because most people want things simple. Point; click; access; move on with our lives. But that's the trade-off, innit? We can either have ultimate security systems which are arcane to use, difficult to hack, and impenetrable for non-accountholders...Or we can have the point-and-click world. We seem to want the point-and-click world, and that's fine--we just have to accept that that comes with certain security flaws.)

Come back and talk to me when you figure out a way to protect SL info that doesn't make it harder for people to buy things on the grid, and I'll likely tell you you may have come up with something that will work. Because ultimately, too many of us want the convenience of buying Lindens on a whim, whether that's what we should want or not. And no amount of secondary passwording is going to make it any less easy for criminal types to do criminal things on the net.

26 March, 2011

roll off the grass and let the insects breathe

A few days ago, a column from Shamus Young's Twenty-Sided Tales blog was linked to me that I found extremely relevant, in the wake of the RedZone debate. I highly recommend that everyone reading this, go read that, but I'm doing something I don't normally do and quoting large bits of the original.

First understand that what made Shamus write that column was an unrelated comment to another column entirely, from a reader called Blurr:
"I am very much against Facebook integration on other websites. I know I can't be the only one. I tried a while ago to figure out how to block Facebook when I'm not on the main Facebook website, but couldn't find anything.

"My concern is that because this 'like' link appears on blogs all over the place, Facebook can get a pretty good idea of my browsing habits. I am against this on principle."
Now, I'd heard this before. And even having read the column, the first reaction my brain has to his words is Wau, he's a loony. But then I read on:
"If a page has a Facebook button on it, then Facebook knows you were on that page. We don't know what they do with that info, but we know they have it."
The hell.

From the embedded link originally in that quote:
"But data about the user is sent to Facebook regardless of whether the Like button is actually activated.
Which is all quite scary - but not too surprising, given Facebook's reputation for snooping on its registered users.

What becomes really scary is realising how Facebook can track your movements even if you haven't signed up to its fake-friend collection service for lonely teens and sad divorcees.

Even if you don't have a Facebook account, you are far from immune from prying eyes, as Roosendaal explains:

"When a user does not have a Facebook account, there is no cookie and no user ID available. In this case, an HTTP GET request for the 'Like' button doesn't issue a cookie.

"However, when a site is visited which includes Facebook Connect, this application issues a cookie. From that moment on, visits to other websites which display the 'Like' button result in a request for the Like button from the Facebook server including the cookie."

Which means Facebook has swiped another batch of valuable data without asking for permission."
And that article goes on to mention that, if we aren't assiduous in clearing our cookies, Facebook's cookies have a two year expiration date.

And every time you hit a page that has the Facebook "Like" button as an embed, does that add on another two years to the life of the cookie? Or does it just create a 'later expiration date' for the so-called "new" cookie--which uses the same data/user ID as the previous one? That, I don't know.

From that same link:
We'll assume that, as you're reading this rather than laughing at Lolcats, you know a thing or two about cookies. They are helpful to users and of immense value to marketeers, allowing them to bombard you with targeted advertising based on your browsing history.

But with an increasing proportion of sites turning to the likes of Facebook in order to increase traffic and revenue - and let's face it, 500 million people is a pretty attractive audience for anyone - isn't it time we started putting our collective foot down about the way in which our every move is monitored?
What's really ironic in all of that? That column has a 'Like' button.

Okay, so that's all kinds of unnerving and creepifying, but I should point out again--Google does this, too. They track where they've been to figure out what ads we may be most interested in. And they do it without consent or requiring permission, just like Facebook. So why do we not have just as many personal privacy issues with Google?

First, because they haven't gotten a lot wrong, while Facebook has. Second, the Google CEO has never come right out and called users of Google's services stupid for using the service. That's pretty damning, even if it's from Zuckerberg's immensely younger, Harvard-attending, spoiled self.

But I digress. Back to Young's original column:
"The problem is with web cookies. A cookie is a small text file created by your web browser. It stores 'name / value pairs', which is fancy programmer talk for stuff like this:

username=PresidentSkroob
password=12345
last_visit=March 24, 2011
mobile_user=no"
And before anyone sneers at the password? What we learned from the whole Gawker debacle is that people pick some pretty dumb passwords. The top three on the analyzed list, after all, are "123456", "654321", and "password". Yeah.
"It lets websites store information on your computer. These files are keyed to the domain name. So, Facebook can only read cookies created by your visit to Facebook.com and The Escapist can only see inside of cookies created by your visit to escapistmagazine.com. The information contained in a cookie is sent when you visit a site. So, if I previously visited Facebook on this computer, it will send my Facebook cookie, which will let Facebook have my name and (if I so choose) password. That way I don't have to log in every time I visit the site, and it can know ahead of time if I want the lightweight mobile version of the page or the all-singing, all-dancing, graphic-heavy full version. If I go to another computer, it won't have a Facebook cookie on it, and so I'll have to type in my name & password to log in."
Which, frankly, is as it should be, in my book. But we are creatures of habit. We don't want inconvenience, we want comfort (occasionally, and usually, to our detriment). People (and I am one of these people), when given the prompt to save a username/password combo, will generally choose to do so. (Were I on a shared computer, I might not be so blithe about this, but I'm on my own computer. I have this feeling, false and intangible as it might be, that because it's my home computer, that I'm the only user who will see these saved password prompts. (Which is as may be, depending, but some people forget and hit the save option on shared computers, simply out of habit. But again, I digress.)
"Even if I tell FB not to save my password, it still saves my username. That username gets sent when I load the page, even if I'm not logged in. See, that little button at the bottom of this page is actually a little sub-webpage. It's a little window with a Facebook page inside of it. (Same goes for the ads on the right. That's a sub-window with a Google page inside of it.) When you visited this page, your Facebook.com cookie (assuming you have one) was sent to Facebook. Facebook sees your username, and because of how HTTP headers work, it also sees that you visited from shamusyoung.com. Ergo, Facebook knows you were here. Of course, this only applies to webpages with Facebook features. Facebook has no way of seeing where else you might go."
Except...yeah, they kind of do. Why? Well, assume I went from shamusyoung.com to that UK link...which also has a 'Like' button. Say I went from there to a link a friend sent me, and rather than spawn a new page, I just popped in the URL and went from there. If that one also had a 'Like' button, while in the main three different cookies were created to send back to Facebook, in the specific if anyone's looking at the aggregate data at some point, they will see that my chain went, unbroken, from site 1 to site 2 to site 3.

As long as I am traveling from sites with 'Like' buttons to OTHER sites with 'Like' buttons, Facebook knows everywhere I've been.

And remember, I'm not even sure how my cookies are showing up to Facebook, because you can't kill a Facebook account once opened. (And I opened one for the purpose of getting what is now an incredibly worthless piece in an armor set for Runes of Magic, got creeped out within a scant few hours, waited out my eight days until the I had documented delivery of the piece of armor code, and then got out. And while I've never been back, and have no intention of going back...any cookies generated at sites with the 'Like' button may just track back to my former Facebook account, and not as 'future user' placeholders.

(Which is creepy enough just on its own.)
"It's important to point out that this is not some nefarious new thing Facebook is doing. Everyone uses cookies. This site remembers the name you use in the comments because that stuff is stored in a shamusyoung.com cookie on your computer. Google uses them. Battle.net uses them. Blogger.com. My Space. Youtube. The Escapist. Google. Yahoo. Blogspot. Wikipedia. Twitter. Anywhere that you log in knows at least your username and the last time you visited."
As I said with the Google example, yeah--a lot of places does this. In fact, secondlife.com does this, because I've set it up to remember my username and password. Just like the Second Life forums (or at least the old ones--I haven't sent in a comment on the new system, and...I'm not sure I'm going to). Just like a lot of places I go to...and most of which, to be honest, have Facebook 'Like' buttons.
"The reason people get worked up about Facebook is because it's so ubiquitous. (And because the founder of Facebook is reportedly a complete douche.) Nobody cares about Yahoo cookies because Yahoo isn't lurking in the corner of every page on the web. The problem isn't that Facebook is more hostile to privacy than other sites, it's that Facebook naturally has access to data that other sites don't, because they're less popular."
I hate to have this come down to some sort of popularity contest, but he's right--Facebook goes farther because Facebook has a lot of users. It's akin to CBS getting the highest-rated show on the airwaves in a certain time slot--they can then take those numbers to the advertisers, and say "See? If you buy ad time for this program, more eyes will see your ad."

That's actually kind of the point in marketing and advertising--to get those numbers, so you'll be funded--through advertising, through direct contributions, through users signing up for subscriptions, whatever. In this breakdown, it doesn't matter a whit whether you're secondlife.com, yahoo.com, or chillygirls.com--your job is to get eyes on your work, the best ways you can. (And yeah, before anyone hunts it down? That last one's real. And really NSFW.)
"If you're really concerned about this, there are things you can do. You can set your cookies to be deleted every time you close your web browser. It will make it impossible for Facebook to see where you are, even when visiting sites like this one."
And he's right, we can, save...this is that comfort vs. security thing again. We can set our browsers to delete all cookies saved every time we close our browsers down. (And some people go farther.) But for most of us, we want that comfort and convenience--so we allow the cookies, we allow push messages on our mobile devices, we allow sites to remember our usernames and passwords--because it's just so much bother if we don't, right?
"For a blog like mine, word of mouth is life. You need a stream of new users just to replace the ones that wander off. Some people get mad and leave. Or lose interest when I change focus to something outside of their sphere of interest. Sometimes they just get tired of me. It happens."
Absolutely. Case in point: I adore Girl Genius. I adore Looking for Group. (Hells, I even have a Richard doll sitting in my bookcase.) But have I read either of those strips the last month? No, I have not. Will I get back to them? Absolutely, because I like both strips. But my attention wandered, I got busy, I lost the time for casual webcomics reading...it happens. To everyone.
"There is nothing I can do to directly draw in new readers, short of forum spam and link-begging on more popular sites – which is one of the most labor-intensive ways of wasting one's time. No, I need word of mouth, and the Facebook Like button is the perfect tool for the job. It's governed entirely by readers. People press it when I do something they like. That action will appear on their Facebook page and attract their friends, who probably share a lot of common tastes and interests. It takes my best material and promotes it to people who are most likely to enjoy it. Even if I was willing to pay money for an advertising campaign, I wouldn’t be able to find something as effective as that little button."
Which is Shamus Young's very polite way of saying, That Facebook 'Like' button isn't going away, people. Deal with it.

You can't please everyone all the time, and the truth of the matter is, this is the internet--so you're going to have people you purely can't please, because for whatever reason, their greatest thrills in life are contrarian ones--arguing dubious points, protesting change in any form, and demeaning anyone who doesn't agree with them. (And, save for the last, I fall into that camp, sad to say--because I protest a lot of things that aren't necessarily going to change--for me or for anyone else--and I do love a good argument.) And even counting those people, you're going to make decisions--as individuals, as companies, as corporate entities--that are designed to lose you people, sometimes. (Do I even need to say Dragon Age 2 at this point?)

So for a lot of bloggers, columnists, newspapers, companies, corporations and even world powers--getting those extra eyes in makes all the difference. And one of the best ways for people to get those eyes in? That 'Like' button.

Which is depressing, but I think Shamus Young is also speaking for Second Life by saying that 'Like' button is going to stick around. It's our choice how to deal with it on our end.

I want to mention one more thing before I close this entry, which is Rock Paper Shotgun's "No Oceans" campaign. I don't know if it will go anywhere, but I think it's a worthwhile goal--getting everyone, internationally, on the same page for game releases would cut down a lot of torrenting of games, and, more to the point, get everyone accustomed to playing together, and being able to play together--which would diminish some game piracy (not all, but even a little will help), and hey, while we're at it, maybe foster some stronger international friendships, what the hell. Spread the word.

(And yeah, on that column? There's a 'Like' button.)

heart full of blues, space and time

While I decide if it's too late to back-date posts that contain the last of the Hair Fair pics, I got hit with this when I was listening...