Friday, October 16, 2009

Is Paypal a Bank?

An open letter to Paypal:

As I understand it:

1. Paypal banned Moxie Marlinspike, a well known information security researcher, because he wrote some online security tools that could be used against Paypal and accepted donations using Paypal systems.
(More information can be found here)
2. Paypal has a policy banning writing software that can be used against it. I have not verified this.
3. Paypal held $500 of Mr. Marlinspike's money until he removed the Paypal link from his web site

This is just my unsolicited opinion, but I think this should be addressed at the highest levels at the company since it addresses some fundamental questions:

1.Can Paypal confiscate people's money for breaking its terms of service?
2.Is Paypal a bank?
3.Should the United States government step in and regulate Paypal as an interstate bank?

Regardless of whether my understanding of Mr Marlinspike's situation is correct, it appears that Paypal thinks the answer to question #1 is “yes”.

I don't know the answers to these questions, but I think Paypal would want the answer to question #3 to be “no”. If this is so, and I were them, I'd be concerned that this has the attention of the US Government

Perry Engle
Stratham NH

Thursday, September 17, 2009

Don't get fooled by Free Antivirus!

There are some scams out there trying to peddle free antivirus software, just say no!

You'll go to a web site, and it does all kinds of things to say you're infected, and to load their software. There's a technical description here.

Right now, suffice to say Norton and Mcafee are the best but co$t, and there's a free one I like called Avast.

Trend, ClamAV are OK too, I guess, but I haven't tried them.

Don't use any others

Perry

Monday, August 3, 2009

*Important* Update Adobe Products Now!

I'm back from Blackhat, and Adobe is now sharing the spotlight as a company *we like to make fun of*.

Don't worry, Microsoft, you still have the top of the heap, but with at least 3 zero-days in 2 months, Adobe is getting their share of abuse.

There is evilness out there, and all 3 of the usual suspect Adobe products need updating, Flash, Shockwave, and Reader. Mine didn't update automatically, so I had to go to the following 3 places:

http://get.adobe.com/flashplayer/

http://get.adobe.com/shockwave/

http://get.adobe.com/reader/

It's kind of a pain, but pretty quick on broadband, do reader last, and a reboot at the end, and if you're using firefox (update that too from "about") , and you should be pretty safe .

Happy end-of-summer
Perry

Tuesday, March 31, 2009

Is Conficker an April Fools Joke?

Update 4/9/2009: Obviously, the Internet didn't melt down, but some of of the information security people around were waiting for the other shoe to drop. According to this article, Conficker has woken up, and started moving files. We're still looking.


Original Post:

If you've been paying attention to media, you've probably heard about the Conficker worm. It really is a big thing, and has been a problem to corporate IT staffs since last October.

If you're a home user, there's not much you can do about it, except make sure your virus signatures are up to date, and run a virus scan.

If you would like a quick sanity check to see if you have conficker - click on one of these two links:
Symantec , or F-Secure.

You should see Symantec and F-Secure, two network security companies. If you had the Conficker worm, you'd get something else, and should immediately run a full security scan.

The reason it's come up now to the mass media is that researchers have found a reference to April 1 in the Conficker code, and they're not sure what it does. Conficker might wake up and do something, and it also might be part of a bigger event, so we're keeping alert.

You can find lots more about it at the Honeynet project and SANS (Extreme technical content on these sites )

Perry

Sunday, March 22, 2009

What's the benefit of signing my email?

My brother, Pete, asked a great question when I used a digital signature to sign a message to him: "So what's the benefit of signing? Is it something I could/would/should do frequently?"

He's referring to using a Digital Signature to electronically "sign" an email message. The digital certificate is impossible to forge, and proves that the message was really sent by the person who claimed to send the message.

When people habitually use these signatures, then it prevents someone else (like a spammer, or worse) from impersonating them.

In this case, I signed my message to him, which sent both my digital certificate and a code at the end of the message. This code was created by mathematically processing all the contents of the message and the certificate. The email program on his end compared the code to the contents of the message, and the certificate, and found that they matched. It also checked the certificate against the signature of the company that issued the certificate, to be sure the certificate itself wasn't forged. This meant that not even one letter in the message was changed between my computer and his.

If Pete then saved my signing certificate into his email program, he could also encrypt the messages he sent to me, and no one could read them except me.

Pete also has a "confidentiality notice" on his email - legalese saying that misdirected mail should be deleted. Lots of people use these, my work recommends this sometimes, too. If people encrypted all their confidential information, they wouldn't need the notice, misdirected mail would be unreadable by any unintended recipients.

Signed and encrypted messages are widespread in the DoD and somewhat in the geek community

In fact, messages containing attachments or links won't even go through the US Air Force mail system unless they're signed. Yes, this is a pain in the neck when we work with external organizations who don't have digital certificates.

I used Comodo for my free certificate at home, in Mozilla thunderbird

Apparently it's only valid for a year - I had forgotten that ( oh look, good until 5/24/2009 ) - I'll be interested to see what happens on May 30 - I think it'll die and I have to get another one. I'll pay for it then, I think.

The fact that Pete is pretty savvy in computers, and digital certificates are wildy useful to prevent identity theft, shows the problem.

Digital Certificates are not widespread use enough to make a difference right now. Why? That's another post.

Maybe someday.

Perry

Saturday, February 21, 2009

Do you know what TTFN means?

It's "ta ta for now". I knew that, but there are tons I don't know. I was googling for one, and found this page. It's kind of interesting.

The national center for missing and exploited children has a dictionary of kids phrases , or chat abbreviations up on the web.

http://www.missingkids.com/adcouncil/pdf/lingo/onlinelingo.pdf

Perry

Friday, February 20, 2009

What is Phishing?

Phishing is when a criminal sends an email that they forge to look like a trusted company like your bank. They make up some story and ask you to clink a link that looks a place you trust, but goes to them instead. If you log in with your username and password, you've given them keys to your kingdom.

Here's an example from SANS

Dear email account owner,

This message is from somewhere email administration center to all email account owners. We are currently upgrading the email securities of our database and email account center. We are also conducting a routine check by deleting all unused accounts to create more space for new accounts. To prevent your email account from being closed, you will have to update it below by providing us with the below mentioned so that we can ascertain that your account is prensently in use.
CONFIRM YOUR EMAIL IDENTITY BELOW

Email Username:....................
Email Password:....................
Date of Birth:.....................
Country or Territory:.............

Warning!!! Account owner that refuses to update his or her account within Seven days of receiving this warning will lose his or her account permanently.

Regards,
Admin Team

Thank you for using somewhere email account

If you ever get an email like this, just ignore it, or call your financial institution directly, using the number on your regular card or bill NEVER THE PHONE NUMBER IN THE EMAIL!

(This goes for phone calls and texts too!)

Perry