Alternative Browser AllianceYou may have seen my website, the Alternative Browser Alliance. I put it together in 2005, when flame wars between Opera users and Firefox users were at their height, to show that we shared a common goal: opening the web. The most popular page on the site is a list of web browsers, which is linked as a resource from a number of sites and also gets a steady stream of traffic from people searching for alternative browsers.

Of course, things have changed a lot since 2005, so I’m planning an overhaul of the whole site. Continue reading

One of the great ironies of phishing is that, these days, identity theft via the web tends to work by preying on people’s fear of identity theft. It doesn’t help that most people don’t really understand the technology. The typical phishing message looks something like this:

Dear so-and-so. In order for us to protect your account from identity theft, we need you to give us all the critical information that we already have. Otherwise, your account will be locked.

These typically use actual bank logos and link to a website that imitates the bank’s real site as closely as possible. The days of “Pease entr yore acccccount infomation hear KTHXBYE” are long gone.

But the one I saw in the spamtraps today was just astonishing in its brazen use of buzzwords to add authenticity:

Dear Wilmington Trust Banking Member,

Due to the high number of fraud attempts and phishing scams, it has been decided to implement EV SSL Certification on this Internet Banking website.

First we have the scare tactic (always ironic in a “there are treacherous people about” sense). Throwing in EV SSL certificates makes it seem a bit more authoritative, since it’s something a lot of companies have started doing, and people may have heard about it in the news.

The use of EV SSL certification works with high security Web browsers to clearly identify whether the site belongs to the company or is another site imitating that company’s site.

It has been introduced to protect our clients against phishing and other online fraudulent activities. Since most Internet related crimes rely on false identity, WTDirect went through a rigorous validation process that meets the Extended Validation guidelines.

And here they talk about EV certs and how much safer they’ll make your account!

Please Update your account to the new EV SSL certification by Clicking here.

And here’s where they demonstrate that they figure the typical mark doesn’t actually have a clue what EV SSL certificates are. Various real businesses have converted from standard SSL to Extended Validation SSL, and the users didn’t have to do a thing.

Now, you might need to upgrade your web browser or switch to one that will show you a green bar (Firefox 3, IE7, Opera 9, etc.), but you’d still be able to access your account even if you didn’t. Unless the site started blocking other browsers like PayPal briefly discussed back in April. Even then, there would still be nothing that would require you to log into your account and make a change.

Anyway, let’s continue:

Please enter your User ID and Password and then click Go.

This one’s presumably a simple phish, just obtaining login credentials to give the thief access to the account through the web.

(Failure to verify account details correctly will lead to account suspension)

And of course the implied threat: Do this or you won’t be able to get at your money. Again, a typical phishing tactic.

On a side note: My favorite spam topic of the last week is “Refinance your ARM today.”. Yeah, I know what ARM stands for, but I keep imagining Cyborg, or perhaps the Six Million-Dollar Man, trying to refi a loan that covers the gadgets in his arm.

My desktop computer has been a bit flaky for a few months now. Well, more than that. There’s the problem where it won’t display anything in plain-text mode, but that’s not really a big deal. It was when it stopped running anything higher than 1024×768 that I started getting annoyed.

That turned out, oddly enough, to not be the video card. And not the monitor, since I could display higher resolution from the Windows box perfectly fine. And not my OS, since running a live CD had the same problem.

So I figured it was a motherboard issue. Fine, I’ll upgrade. Eventually. Wait ~4 months, and I’m starting to notice data errors on the hard drive. Great.

You know that old saying about how any project requires at least 3 trips to the hardware store? It applies to computers, too.

I finally got around to looking for a decent mobo/CPU/RAM combo, and a new hard drive. Ordered online. Arrived yesterday. Ran backup last night.

Today I dismantled everything, hampered by the fact that I could not find the box that has all the case components (faceplates so I could remove the ZIP drive which I haven’t used in 3 years, etc.), though I did eventually find the screws. After I installed the motherboard, I started plugging in connectors… only to discover that the power supply didn’t have the right kind of connector.

Off to Fry’s to get a new power supply, after stopping at storage to see if I could find that box with faceplates and stuff. No luck, and power supplies are astonishingly expensive, though I found one that fit my specs and was on sale and had a rebate, so that worked out. (Some of them are 1000-watt monstrosities that cost as much as a cheap computer, and in the words of another customer, “look like they should be in a Chevy.”)

Came back, hooked everything up, moved it back into the bedroom to hook everything up…and couldn’t go into the BIOS to set the boot device. After messing around a bit, determined that the text-mode problem, at least, actually was the monitor. So I’m borrowing Katie’s monitor while I install an actual 64-bit OS. Once it’s at the point where I can let it sit for a while, I’m going to run out to Best Buy for a new monitor. I suspect the resolution problem is different, but at this point I’m no longer inclined to suffer through it.

Still, it’s worth the upgrade (assuming, of course, that everything continues to work once I close up the case), since the old system was single-core, 32-bit, and ran on an IDE drive, and the new system is dual-core, 64-bit, will have more memory, a faster bus, a SATA drive, etc. This should be much faster.

Once it’s done, anyway.

Originally posted at LiveJournal.

Current Mood: 😡frustrated

Now that it’s live, I’ve downloaded the Google Chrome beta on my Windows box at work.  Thoughts so far:

Good:

  • Site compatibility seems to be fine so far, with a couple of minor issues (see the “Bad” section).  Mostly I’ve tested it with a couple of forum sites, LiveJournal, Slashdot, and WordPress.
  • I like the simple settings box, with “Basics,” “Minor Tweaks,” and “Under the Hood.”
  • It does feel fast.
  • Showing the URL of links in the lower left-hand corner is a perfect compromise between the spatial advantages of a permanent status bar and the extra room provided by leaving it out.
  • I like the task manager for the browser itself.  It’ll be good for developers, but it’ll also be good for users: as the comic points out, if your browser starts chewing up all available resources, you’ll be able to tell what page/plugin/program is at fault instead of just blaming the browser.

Bad:

  • Gears support doesn’t seem to work quite right.  WordPress.com doesn’t detect that it’s available.  Local WP installs with Bad Behavior can’t sync completely.  (It doesn’t send an Accept header on the request for one of the TinyMCE files, which causes Bad Bahavior to think it’s a spambot and triggers a 403.)
  • Cookie management is too simplistic.  I like to accept all cookies temporarily, but clear everything when I end my browsing session, with exceptions for sites where I want to stay logged in.  This is easy in Firefox, a little trickier in Opera, and doesn’t seem to be an option in Chrome.
  • I have seen it pause a couple of times, with as few as 5 tabs. [edit: these seem to be related to Flash content]
  • No Incomplete spell-check.
  • I keep hitting the forward-slash key to search within a page, since that’s the shortcut I’m used to in Firefox and Opera.
Debatable:
  • The UI does indeed stay out of your way.  I guess this sort of makes Chrome the Anti-Flock.
  • DNS Pre-Fetching is enabled by default.  This is different from full HTTP pre-fetching in that all it does it look up the IP addresses of the links that you might click on.  It’s not clear at what point it does this — I don’t remember seeing it mentioned in the comic, which (ironically) isn’t searchable.  I suppose it could either hit the domains of all the links on a page, or just those that would trigger HTTP pre-fetching, or even just send the query when you hover over a link (to get a split-second head start before you click). Update Sep. 17: Google has a blog post explaining pre-resolving in detail. Apparently it does check the domains for all the links on the current page.

Google Chrome seems to be a multi-threaded open-source browser based on WebKit (with some code from Firefox as well), focusing on making a browser that will work well with web applications.

It’s got built-in support for the Gears API (not surprising). And, like Firefox 3, IE8, and Opera 9.5, it’ll do full-history search & auto-suggest in the location bar. Interestingly, they’ve adopted a couple of UI elements from Opera, including thumbnails of your most-visited pages when opening a new tab (like Opera’s Speed Dial, though in this case the list is automatically generated from your browsing behavior), and putting the tabs above the main toolbar — something that Opera has taken a lot of flack for.

According to the blog post, the first preview release should be out for Windows tomorrow, with Linux and Mac following.

Oddly enough, I found out about it through comics blogs (A Distant Soil, specifically), not tech blogs, because Google hired Scott McCloud (Understanding Comics) to explain what makes the browser different in comic-book form.

A word to the wise for anyone planning to set up paperless billing: make sure the notices go to the right email address.

Last night, while paying bills, I realized I hadn’t seen a bill for our internet access in quite a while, and noticed that my bank showed the last payment had been sent in June. That didn’t look promising.

I logged onto the U-Verse website, and sure enough, our account was set for paperless billing. I hadn’t gotten the bills because they were being sent to an AT&T address which had been created as part of the setup process, but which I’d never used. So I paid the overdue bill, set up auto-pay so I wouldn’t have to worry about it again, and then set about making sure I’d actually get the statements. I thought about changing the address listed on the U-Verse profile, or forwarding it to my regular address, but settled on just setting up POP access to the account.

The weird thing is, I’m not entirely sure how we ended up with paperless billing. My filing system’s a mess right now, but I distinctly remember getting one bill on paper. (We signed up in May, as soon as we moved in.) I can’t have marked a checkbox on the bill, though, because I paid it through my bank’s website, not by check. My best guess is that I chose it during the setup process and forgot, and they just sent the first bill on paper.

»All pages site-wide with this tag