Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

November 30, 2010

Security Flaw on MySpace affects one million users

After waiting for a resolution (which didn't happen) and ranting online about it (which had no effect), at the 25th of November I sent this bug report on MySpace:

According to Wikipedia[1], more than 1% of web users use a resolution of 800x600 or less on their web browsers. If those users come to MySpace, they'll be able to log in, but not to sign out (because the "Sign Out" button will be always not visible).

As you can understand, this is an huge security flaw, which MySpace must solve as soon as possible. As it is, it would better not let them log in than forcing them sto stay logged in.

[1] - http://en.wikipedia.org/wiki/Display_resolution#Current_standards

Since until now I've got no reply, I'm posting this in the hopes that the issue gets more exposure. Wanna help? Please send yourself a similar bug report, and spread the word!

May 15, 2008

The SSH/SSL vulnerability: what you should know

I wasn't going to post about this, but it seems that, for my own sanity, I must. As you might know by now, a Debian Security Advisory came out, talking about a problem that affected the OpenSSL package, not only for Debian but for its derivatives too, like Ubuntu.

My first two remarks, and probably the most important ones for my thoughts about this issue:
  • If what you know about this issue is what you read on Slashdot, YOU'RE WRONG. Even the news itself is wrong, and the comments are clueless, written by people that don't know shit about what are they talking about. Worse than useless, that story on /. is disinformative.
  • If you think that this issue only affects users of Debian and Debian-derivatives, think twice. Any Linux/Unix/*BSD system is vulnerable that grants access to a key that was generated on an affected Debian or Ubuntu system. Erich has a simple yet good explanation on why.


Now, my stand on the issue: if you really feel the need to mock, criticize or otherwise comment about this issue, make yourself and me a favour, and avoid making a fool of yourself. In other words, find out what really happened, what is this all about and make your own oppinion based on facts, instead of just falling into the absurdity that spreaded over, saying silly stuff like "Debian does not contribute to upstream" (what a joke, did you ever read the Debian Social Contract?), or "Debian shouldn't make security fixes". As a matter of fact, John Goerzen wrote an interesting article about some of those things and why they are wrong.

So, to help you a little, here's a small list of articles you might want to read about the issue:


Yes, it was an unfortunate thing to happen. So, go fix your stuff and leave me alone.

April 30, 2007

Quickies

We7 is a music sharing website where you can get DRM-free music for free and artists still get payed. The trick? A small add in the beginning of each mp3 file.

See what you can do to try to convince Warner Music to drop DRM.

Article about Security Concerns in Web 2.0.

February 14, 2007

Links

So, I've been kind of busy lately, so I didn't post anything lately. To avoid having one more day without posts, here is what I have in my browser tabs:

Have a nice reading time.