Some potentially nasty browser security vulnerabilities found this weekend in Mozilla and in Safari. Both involve software update mechanisms. The Firefox one tricks the browser into thinking it’s installing from a trusted update site (the maintainers of updates.mozilla.org and addons.mozilla.org—the only trusted sites by default—have made some changes on their server to prevent the exploit from working). The Safari one takes advantage of the Macintosh tradition of automatically opening archives. This one just happens to unzip itself into the location where Dashboard stores its widgets.

IEBlog has weighed in with a balanced (i.e. non-fanboyish) comment on just who “us” vs. “them” should mean: responsible developers & security researchers vs. the malicious ones. It won’t happen—people are too hunkered down in their own trenches—and even with Mozilla, Opera and Apple collaborating on specs, I don’t expect to see much in the way of collaboration on security except in the actual open-source world. (Even then, I suspect there’s too much rivalry between Gecko and KHTML developers to do much collaboration.) Continue reading

Maybe it’s the housing costs, but people in San Francisco need a little extra incentive to give out their computer password than people in Liverpool. Last year a survey found that 71% would reveal their password for a chocolate bar. A similar survey this month in San Francisco found that 66% would give it up for a coffee.

At least Verisign made good on the offer—with a $3 Starbucks gift card.

Too bad it’s the bad guys.

As reported on DailyDave and picked up at SANS, Email Battles and elsewhere, there are phishers out there using a botnet (a network of infected “zombie” computers) not just to send emails, but to host the websites and the DNS for their scam.

Imagine what this technology could do for legitimate sites. It could potentially surpass Akamai’s system of worldwide mirrors. You could set up something like BitTorrent that would automatically mirror sites you’re looking at. Getting Slashdotted would actually improve a site’s response!

Found a couple of comments this morning that consisted of the usual generic phrases:

Please check some relevant pages dedicated to…

You may find it interesting to check the sites about…

The weird thing: No links. No author name, no author URL, no links in the comment itself. Nothing that would clue in content filters to block it…but then nothing that would accomplish anything, either.

And now for something completely different: Hawaiian snow. On our second-to-last day in Hawaii, we took a tour up to the summit of Mauna Kea, the highest mountain in the state at 13,796 feet. And even in early April, they still had snow at the summit.

Hawaiian Snow

We caught a somewhat hazy view of it from the west, in the Kohala area, but our best view of the mountain actually came the day after the tour, on our drive out to Akaka Falls. We’re probably due east of the mountain here:

Mauna Kea seen from the road to Akaka Falls

Continue reading

Apparently wardrivers (people who cruise neighborhoods with a laptop looking for open wireless networks) have been submitting their findings to WiGLE—a searchable database and interactive map of wireless access points.

Already checked—our home network isn’t in there. (As much as I’ve locked it down, it had better not be!) But they do list several in our neighborhood.

As always, the power of the Internet can be used for either good or evil.

(via Aunty Spam’s Net Patrol.)

ยปAll pages site-wide with this tag