After several years of inactivity and a quiet relaunch earlier this year, the Dillo web browser has finally released Dillo 2.0.

The open-source project started in 1999 with the goal of creating a small, fast, highly efficient graphical web browser that could run well even on low-end hardware and software. It’s a UNIX application, and runs on Linux, BSD, Solaris, etc. Things stagnated when it became clear that GTK1 was going to vanish, and GTK2 would not fit the project goals, and eventually the browser was ported to the Fast Light Toolkit (FLTK).

If you’ve used Dillo before, some of the improvements in this release are multiple character set support (the old versions were Latin-1–only), tabbed browsing, HTTP compression, anti-aliasing, improved rendering and UI, and smaller(!) memory usage.

It does have its limitations, and a few major items stand out as missing when compared to other modern browsers:

  • No CSS stylesheet support.
  • No scripting.
  • No plug-ins.
  • Limited SSL support.

That said, it’s useful to keep around on an old/slow system, or for situations where speed is more important than rendering, or to test how a website works without styles, scripts, and plugins.

I started building RPMs of Dillo for my own use back in 2002, and became the official RPM packager for the project the following year. I’ve posted Dillo RPM packages for Fedora 9, RHEL 3, RHEL 4, and RHEL 5. Other distros will have to wait until I get my build system out of storage or figure out how to convince mock to let me build two packages together.

I was just commenting on The Comic Treadmill’s 5-year anniversary, and I realized: K-Squared Ramblings turned six last month. (September 14, to be exact.) I’ve been so busy with Speed Force that I haven’t posted much here, and didn’t even notice the milestone.

Let’s run the numbers:

  • 6 years and not-quite 1 month
  • 1708 posts including this one
  • 2,863 comments including pingbacks and replies
  • 52 categories
  • 9 convention reports (6 San Diego Comic Cons, 2 Wizard World LA, 1 WonderCon)

Top-viewed posts for the year:

Last month I finally got around to a major rebuild of my computer, something I’d been meaning to do since May when I traced some display problems to the motherboard*. I finally bit the bullet when I started seeing signs of disk errors, and dragged the machine into the present day. (64-bit, dual-core, 2 GB RAM, SATA drive, faster everything.)

Then I discovered that some of the display problems actually were the fault of the monitor.

So I went out and bought a new monitor while Fedora was installing, and I took the opportunity to go widescreen.

My criteria were simple: The resolution and physical size both had to be as big or bigger than the old one (17″, 1280×1024), and it had to be under $300. That meant at minimum a 22″ display at 1680×1050, and I found a Hannspree 229HBP for about $190.

There was a Dell right next to it, same size & resolution and comparable specs, and the Best Buy employee had been talking both of them up. The Dell was on sale for $290. I asked what the difference was. He thought about it for a few seconds. “Well, this one [the Hannspree] does run a little bit hotter. But mostly it’s just the name.” Thank you, Best Buy employee whose name I’ve forgotten, for helping me save $100.

The biggest difference, aside from actually having room to show both the toolbox and document windows on GIMP, is that I don’t maximize windows anymore. Not that I maximized apps that often before, not counting the stuck-in-low-res period. I’ll occasionally run a video or slideshow fullscreen, but the only program I regularly maximize is my email client, and that’s because I can put it in three-column mode (Folder tree on the left, mailbox listing in the middle, message content on the right).

Something to watch out for: At first I left the monitor off-center, because there wasn’t enough room on my desk for it. I figured as long as I worked mostly on the right part of the screen I’d be fine. But I ended up having neck problems shortly afterward, and Katie suggested I check the placement of the monitor. I shifted things around so I could center it, then set it on top of an Amazon box to raise it a couple of inches, and the sore neck cleared up.

I’ve only run into two problems (not counting the placement): There’s one dead pixel, but it’s off in a corner so that it’s not really an issue. I almost didn’t notice it at first when I was still setting things up, because the default GNOME layout has a Mac-style ever-present menu bar, and it falls right on the edge. Usually it ends up either on the edge of a window border or lost in the wallpaper noise.

The other problem: the built-in speakers pretty much suck, but I had external speakers already, so again: no big deal.

* It stopped displaying any resolution past 1024×768. I could tell it wasn’t the monitor because it was perfectly happy to show another computer at 1280×1024. And not the drivers or OS because I had the same problem booting from a LiveCD. And not the video card because plugging in another one didn’t solve it. This was particularly frustrating since it was an LCD monitor, so running at less than native resolution made everything blurry. Still, I put off replacing the mobo for months since it’s such a pain to do.

We’ve been testing Barracuda’s new BRBL spam block list at work. This involves flagging but not actually blocking messages, then me looking through the logs for potential false positives. I’ve found several, including the Star Wars Fan Club (I subscribed myself just to verify that it was really sent by a server at lucas-online.info) and a senator’s mailing list.

There’s also a lot of definite spam, and a lot of stuff that I just can’t tell. It’s marketing, certainly, but I have no idea whether the particular users actually subscribed or not.

Anyway, this subject showed up several times on the list:

Stimulate your bottom line with Microsoft Financing and the 2008 Economic Stimulus Act

Naturally, when I first skimmed the list only the first three words were visible. 😯

A couple of messages recently fell into the spamtraps with the subject, “Someone sent you Snickers Candy,” offering lots of free candy and exhorting, “Don’t resist temptation! Sign-up now to get started.”

One of the throwaway addresses used? dietsthatwork2008 (dot) com.

Obviously, that one doesn’t!

Alternative Browser AllianceYou may have seen my website, the Alternative Browser Alliance. I put it together in 2005, when flame wars between Opera users and Firefox users were at their height, to show that we shared a common goal: opening the web. The most popular page on the site is a list of web browsers, which is linked as a resource from a number of sites and also gets a steady stream of traffic from people searching for alternative browsers.

Of course, things have changed a lot since 2005, so I’m planning an overhaul of the whole site. Continue reading

One of the great ironies of phishing is that, these days, identity theft via the web tends to work by preying on people’s fear of identity theft. It doesn’t help that most people don’t really understand the technology. The typical phishing message looks something like this:

Dear so-and-so. In order for us to protect your account from identity theft, we need you to give us all the critical information that we already have. Otherwise, your account will be locked.

These typically use actual bank logos and link to a website that imitates the bank’s real site as closely as possible. The days of “Pease entr yore acccccount infomation hear KTHXBYE” are long gone.

But the one I saw in the spamtraps today was just astonishing in its brazen use of buzzwords to add authenticity:

Dear Wilmington Trust Banking Member,

Due to the high number of fraud attempts and phishing scams, it has been decided to implement EV SSL Certification on this Internet Banking website.

First we have the scare tactic (always ironic in a “there are treacherous people about” sense). Throwing in EV SSL certificates makes it seem a bit more authoritative, since it’s something a lot of companies have started doing, and people may have heard about it in the news.

The use of EV SSL certification works with high security Web browsers to clearly identify whether the site belongs to the company or is another site imitating that company’s site.

It has been introduced to protect our clients against phishing and other online fraudulent activities. Since most Internet related crimes rely on false identity, WTDirect went through a rigorous validation process that meets the Extended Validation guidelines.

And here they talk about EV certs and how much safer they’ll make your account!

Please Update your account to the new EV SSL certification by Clicking here.

And here’s where they demonstrate that they figure the typical mark doesn’t actually have a clue what EV SSL certificates are. Various real businesses have converted from standard SSL to Extended Validation SSL, and the users didn’t have to do a thing.

Now, you might need to upgrade your web browser or switch to one that will show you a green bar (Firefox 3, IE7, Opera 9, etc.), but you’d still be able to access your account even if you didn’t. Unless the site started blocking other browsers like PayPal briefly discussed back in April. Even then, there would still be nothing that would require you to log into your account and make a change.

Anyway, let’s continue:

Please enter your User ID and Password and then click Go.

This one’s presumably a simple phish, just obtaining login credentials to give the thief access to the account through the web.

(Failure to verify account details correctly will lead to account suspension)

And of course the implied threat: Do this or you won’t be able to get at your money. Again, a typical phishing tactic.

On a side note: My favorite spam topic of the last week is “Refinance your ARM today.”. Yeah, I know what ARM stands for, but I keep imagining Cyborg, or perhaps the Six Million-Dollar Man, trying to refi a loan that covers the gadgets in his arm.

»All pages site-wide with this tag