* Posts by Old Handle

1602 publicly visible posts • joined 4 Mar 2011

Oh snap! Yap app WhatsApp chaps zap .BAT trap in hack flap

Old Handle

Are you still sure?

I did read that, in fact. But it turns out there's something even more important that we both failed to read:

The original attack description

As I suggested, someone more skilled in batch found a better way to hide it. It turns out there's no need for folding, escaped backslashes or any of that. All you need is the & sign.

FN:John Doe & msg * Hacked

So there you have it. And please, if you're going to claim this is also invalid vcard format and "trivially discovered", explain why and how this time.

Old Handle

Re: Yes, I'm sure.

So now you're saying they have to not only check that it's a valid vcard, but modify before delivery?

Old Handle

Re: Yes, I'm sure.

How exactly? Aside from the fact the "C" isn't a recognized property (as we discussed earlier), it's perfectly valid vCard format. It is schoolboy stuff though, I agree. I'm sure someone more skilled with batch could find a more devious way to hide it.

Old Handle
Facepalm

Are you sure?

BEGIN:VCARD

VERSION:2.1

N:Gump;Forrest

FN:Forrest Gump

ORG:Bubba Gump Shrimp Co.

TITLE:Shrimp Man

PHOTO;GIF:http://www.example.com/dir_photos/my_photo.gif

TEL;WORK;VOICE:(111) 555-1212

TEL;HOME;VOICE:(404) 555-1212

C:\\windows\\system32\\msg.exe * Thunderstruck

ADR;WORK:;;100 Waters Edge;Baytown;LA;30314;United States of America

LABEL;WORK;ENCODING=QUOTED-PRINTABLE:100 Waters Edge=0D=0ABaytown, LA 30314=0D=0AUnited States of America

ADR;HOME:;;42 Plantation St.;Baytown;LA;30314;United States of America

LABEL;HOME;ENCODING=QUOTED-PRINTABLE:42 Plantation St.=0D=0ABaytown, LA

30314=0D=0AUnited States of America

EMAIL;PREF;INTERNET:forrestgump@example.com

REV:20080424T195243Z

END:VCARD

Old Handle

But legit vcards could easily have unrecognized fields in them. I would imagine simply ignoring these is a fairly common implementation. Sloppy maybe, but rejecting the whole thing isn't that good either.

Old Handle

It doesn't say, but they're both text format, so it should be possible to make a file that is valid as either... at least for a somewhat lax definition of valid.

Handing over emails in an Irish server to the FBI will spark a global free-for-all, warns Microsoft

Old Handle
Big Brother

Do the words "Parallel Construction" mean anything to you? Perhaps a foreign court wouldn't be quite as willing to accept that they totally got their lead from a trivial traffic stop (or whatever the internet equivalent is).

Yahoo! won't! fix! emoticon! exploit! in! death! row! Messenger!

Old Handle

Re: Ummm

Not totally clear, but I think he's saying those files would be changed automatically when a user installed an emoticon pack. Or maybe replacing one of those files is how you install an emoticon pack. Either way, it's bad since this isn't something people would realize could be dangerous.

I hope that by now people understand that they shouldn't install EXEs unless they trust the source (and if not, they kinda of deserve what they get), but if you write your application in such a way that a file they would think of as "content" can pwn them, you've broken an unwritten rule of how computers are supposed to work.

America's crackdown on open-source Wi-Fi router firmware – THE TRUTH

Old Handle
Thumb Down

Re: What's mine is mine and what is your's is mine too.

But where's the evidence this has been a problem with open source firmware? I can't say it doesn't happen, but I've never heard of a problem. If there is one, punish the people who cause trouble (severely if on purpose, mildly if through carelessness) but don't just lock everybody out when the vast majority of them are playing nice.

Reg reader shares AshMad blackmail email about which he gives 'zero f***s'

Old Handle

Re: So this person

The odd fraction is different for every customer which helps to identify which customers have paid up.

Not according to the previous story. They used a unique address for each "customer" (as is the normal practice with bitcoin payments) so there would be no need for the amounts to be unique. Not to mention it sounds like they were bluffing and so didn't need to keep track of who paid anyway.

Wikipedia’s biggest scandal: Industrial-scale blackmail

Old Handle
Joke

Re: [Citation needed]

It's OK, the register is a reliable source so everything they say is automatically true.

Old Handle

Re: web content and Version control...

I assume you're aware that Wikipedia does show a detailed history of each article, including exactly what was changed by whom. I'm not that familiar with source code browsers, but I'm curious exactly what you think they should do better.

Watch this cartoon on proposed new EU data rules – or you’re DOOMED. Maybe

Old Handle
Thumb Up

I think they raise legitimate points, there's always the possibility of over-regulation. We all want the laws to reflect "common sense" but that's so much easier said than done. Just look at how the cookie rules turned out. That was silly. It would have made more sense to say a session cookies required for normal operation could be used without asking but then insist on active positive consent for long term tracking. Instead they found a "compromise" that maximized annoying messages while minimizing protection.

Feeling sweary? Don't tell Google Docs

Old Handle

I'm a little surprised, because my Android tablet seems to love transcribing the word "pussy" at inappropriate times.

Turkey cites crypto software find in terror charges against TV crew

Old Handle
Joke

Re: PKK are not "Jihadists" and why is there an image of the local ISIS dance club?

I think that's called irony. See, a reasonable person would understand that it's ridiculous to label Vice News reporters as terrorists, and readers of this site in particular would be expected to agree that labeling anyone a terrorist for for using encryption is especially laughable. So so posting a picture of actual terrorists (or a wannabe terrorist dance troop) should be taken as poking fun at anyone who confuses journalists with people like those in the picture.

FORKING BitcoinXT: Is it really a coup or just more crypto-FUD?

Old Handle

Re: @ nuclearstar Unsurprisingly, it seems someone has

Assuming the blockchain is duplicated in each online wallet and assuming it hits 1TB at some point then an online repository with 1000 users would require 1PB storage.

Sure, but there would be no need for that. If we're talking about general purpose "cloud" hosting being used for bitcoin, than I guess it would work out like you said (unless they used dedupe). But a purpose built bitcoin service would certainly not work that way. A "wallet" is really just a collection of private keys used to prove ownership of an address when spending coins from it. Mine weighs in at 96kb. Since the blockchain is the same for everybody, all the users could share one copy.

Associated Press sues FBI for impersonating its site to install spyware

Old Handle

I donno, as federal spyware goes this is about as benign as it gets. I can't say I'd be particularly happy they chose my company for the scheme, but I think they had a legitimate reason to make it as realistic as possible. I a non-working link would have potentially make him suspicious, and I'm sure they wanted to grab him before he realized he'd been identified.

Google tells iOS 9 app devs: Switch off HTTPS if you want that sweet sweet ad money from us

Old Handle
Thumb Down

There's nothing "unsafe" about embedding HTTP content in an HTTPS page (at least compared to a pure HTTP page) but in another shining example of their stupidity, some browsers don't allow it. You hear that, Mozilla (and anyone else doing this crap)? Your silly decision is actually stopping websites from using encryption.

Vote now: Who can solve a problem like Ashley Madison?

Old Handle
Thumb Down

Name Calling

I don't think it's fair to call Ashley Madison Tinder-for-cheaters. Tinder has female users.

Cisco's RAT-catchers spot sysadmin-targeted phish

Old Handle

It seems to me it would be simpler to report this as "malware (or RAT) written in AutoIt.", since they ran it as an interpreter, I guess technically accurate to say the malware used AutoIt... but it's not like they tricked or hacked it. They simply wrote a nasty program in that language and used it normally.

The most annoying thing about all this is it can easily result in useful harmless programs getting flagged as viruses. This has happened before.

The most tragic thing about the Ashley Madison hack? It was really 1% actual women

Old Handle

Re: How Many Men Actually used AM?

How about what percent of male accounts were paid?

The Onion Router is being cut up and making security pros cry

Old Handle

Re: Makes sense

Depends on the type of business and how bad you want a shot at another million or so users. Facebook evidently decided it was worth it.

Court rules FTC can prosecute companies over lax online security

Old Handle

Re: "Reasonable"

I'm sure they're bring in expert witnesses to argue that point, but the really it doesn't require too much technical understanding. The fact that they were hacked at least twice using the same method is enough information to say they didn't take reasonable precautions. If your customers get robbed because you left a certain door unlocked, it's reasonable to lock that door so it won't again, isn't it?

I'm not saying "get hacked twice and it's automatically your fault", but when you allow exactly the same thing to happen again, yeah I'd say that's unreasonable.

What's Russia smoking? Kremlin bans Wikipedia for dopey article

Old Handle
Thumb Down

Re: You what?

I could be wrong, but I would assume most of Wikipedia's million+ Russian articles were written by Russians. It wouldn't surprise me if it has a somewhat Western slant, but if you want to learn a few quick facts about something uncontroversial like frogs or the rings of Saturn I'm sure it's a very useful resource just like the English version.

Even 'super hackers' leave entries in logs, so prepare to drown in data

Old Handle
Joke

Re: Super hackers might leave entries in logs

But don't the super hackers have a nifty trace tracker utility that lets them log off just in time before you find their location?

Twenty years since Windows 95, and we still love our Start buttons

Old Handle
Windows

One detail overlooked in the question of why people accepted the new interface in Windows 95 is that Windows 95 actually came with Program Manager. I think it even persisted into early versions of Windows XP. It wasn't particularly publicized, but it was there if you looked for it. And nobody did. I'm guessing that's, because the Start Menu system was actually better.

I remember when I found progman.exe I got a little nostalgic, but had very little temptation to actually use it for anything. If Windows 8 had a startmenu.exe, do you think the reaction would have been the same?

Ashley Madison hack – Tory MP Green denies registering account

Old Handle

Only if he paid. I imagine lots of people sign up but decide the site isn't worth spending money on.

Old Handle

Re: Optional

As I mentioned in a previous AM thread, someone recently signed up for a match.com account using my email address. As far as I could tell it was a legitimate mistake, but my attempts to unsubscribe using the link in the messages had little if any effect. So yeah, it was an easy way to be an annoying bastard.

Though in this case I feel kind of bad for him. I finally had to access the account using password reset and close it down. Somewhere a middle aged divorced guy with two kids and the same first initial and last name as me is wondering why his dating site account doesn't work anymore.

Now Ashley Madison hackers reveal 'CEO's emails and source code'

Old Handle

I wonder, do their databases contain any information on how "successful" users were? I would think they would at least have records of which users exchanged messages, and quite possibly their content as well. If so, there's probably have enough dirt to keep tabloids busy for the test of the year at minimum.

Enjoy vaping while you still can, warns Public Health England

Old Handle

Re: Ban them!! Ban them all!!!

Don't forget coffee and tea, those are recreational drugs too.

Ashley Madison keeps calm, carries on after hackers expose lives of millions of its users

Old Handle

Re: I feel sorry for one or two women on there.

By my math that would be 3.6 million women... or "women" at least. I won't hazard to guess what fraction of accounts are real.

Boffins raise five-week-old fetal human brain in the lab for experimentation

Old Handle

Re: This is just wrong

It's somewhat confusing, since it's already 15 weeks old, but apparently grew slower than normal, being only as large as the brain of a 5-week-old fetus. So yeah, I think they only meant grow it to the size of a 12 weeks gestation fetal brain, but it did say "possibly longer" which leaves the door open for getting into creepy territory.

OpenOffice project 'all but dead upstream' argues prominent user

Old Handle

Re: That Weird Sound You Hear

While I'm sure they love to see infighting in the open source world, I don't think MS has much to laugh about on this one. LibreOffice is has been one of the most successful open source projects in terms of replacing proprietary software on ordinary users' desktops. Second only to Firefox, I would guess.

Adulterers antsy as 'entire' Ashley Madison databases leak online

Old Handle

Re: True - but unlikely

Oddly enough, just yesterday I got a whole bunch of emails from match.com (not quite as scandalous, I know), which I definitely never signed up for.I unsubscribed right away, but I suppose that didn't actually delete the account. So if they ever get hacked my email will be in there.

Anti-botnet initiatives USELESS in sea of patch-hating pirates

Old Handle

Maybe if Microsoft didn't push out DRM disguised as security updates this wouldn't happen. It's sort of a tricky issue though. Even I wouldn't argue that Microsoft has any duty to support pirate copies of Windows, but on the other hand, if pirates kept their systems up to date it would keep legitimate users safer as well.

Mozilla-Microsoft spat latest: Firefox yanks Cortana away from Bing

Old Handle
Facepalm

That's what you call ironic

Mozilla talks about protecting user choice while plotting to take away user choice when it comes to installing browser extensions.

Indian carriers forced to send TXT for every 10 megabyte download

Old Handle

This would be a whole lot more reasonable if they made 10MB the default warning level but allowed customers to easily change it (by sending a text, of course). I'll trust the government knows what they're doing enough that for the majority of mobile users there, 10MB is a large amount, but surely this doesn't apply to everyone. I mean parts of India do have 4G service.

IWF shares 'hash list' with web giants to flush out child sex abuse images online

Old Handle

Hashes

The MD5 and SHA-1 hashes will be totally useless if the image is changed, but the PhotoDNA version is apparently designed to resist this. Of course that kind of fuzzy matching will necessarily have a greater chance of false positives.

Facebook unleashes mighty data trove to learn how you laugh

Old Handle
Facepalm

Vaguely Apropos

My father, the only Facebook user I associate with, recently mentioned that he'd received the message "Ha!" from another user... and Facebook offered to translate it. Looks like their laugh detector needs work.

Borg blacklist assimilates Cryptolocker domain name generators

Old Handle

False Positive Rate

So to clarify, based on the Cisco article linked above, they're not looking for domains made out of random words, but rather domains that aren't made of words. Apparently the false positive rate (out of the Alexa top 10,000) was 0.42% (42 domains). These include some that a human would have been able to recognice as non-random, such as plsdrct2, xxeronetxx, adstrckr, 1c-bitrix, isif-life and vecteezy. Others appear to be genuine nonsense or perhaps transliterated foreign words.

So all in all, not too bad. Although it seems inevitable that if people start blocking nonsense domains, malware makers will just start making domains out of random words instead, e.g. correcthorsebatterystaple.com (which incidentally is a massage training program, how odd). And detecting that will be much harder.

A close shave: How to destroy your hard drives without burning down the data centre

Old Handle
Boffin

It does seem like he could have pursued degaussing options. I'm thinking perhaps the kind of electromagnet people use to shrink coins, only bigger. If you could do the same thing to the platters, I think it'd be pretty safe to say the data is irrecoverable.

Though the "safe for a data center" criterion might become an issue again.

Clueless do-gooders make Africa's conflict mineral mines even more dangerous

Old Handle

Just to play devil's advocate, doesn't the fact that warlords have turned to looting prove this is working, in a way? One could argue that although it caused more violence in the short term, if they've lost a stable source of funding, in the long run it will inevitably weaken them, which is a good thing.

McAfee tells El Reg: 'My shootout with the police was highly exaggerated'

Old Handle

Re: The Donald Trump of the AV world

He should run for president. He may not quite have the name recognition (though "his" AV software is known and feared world wide), but he's certainly has the crazy.

W3C's bright idea turned your battery into a SNITCH for websites

Old Handle

Not to imply this was ever a good idea, but in Firefox at least you can turn it off by going to about:config. The setting is "dom.battery.enabled".

Old Handle

I miss the blink tag

The good news is blink, and even marquee can be recreated using CSS animations. Plus even more annoying things like text that spins upside down.

Old Handle

Re: Solution?

I was going to suggest three levels: "Good" (mains power or battery nearly full), "Poor" (less than 30% or one hour remaining) and "Average" for all other cases. But however you slice it, they clearly don't need nearly as much information as this thing gives them. I can't seriously imagine any website using that much detail for the intended purpose. In fact, given how much they love to shove crap in your face nowadays skeptical that any sites would use it for the intended purpose, at all, ever.

Windows 10 Start menu replacements shifting like hot cakes

Old Handle
Trollface

Re: The Start Menu is the LEAST of Windows 10's problems!

You have to manually opt in to being reported to the government?

Obsolescence of food is complete: Soylent now comes in bottles

Old Handle

Re: How well does it mix with...

Apparently.

What balls! India blocks 0.00008 per cent of web in anti-pr0n move

Old Handle

So this could be great news for the smaller porn sites.

UK.gov wants to stop teenagers looking at tits online. No, really

Old Handle

Re: "Voluntary"

I'm not sure about "most sites", but honestly there are loads that give it away for free (with ads) including a number of large sites with "porn" and/or "tube" in their name.