Showing posts with label web. Show all posts
Showing posts with label web. Show all posts

Saturday, March 21, 2020

David Bowie's Prophecy


BBC Newsnight interview from 1999
David Bowie talks to Jeremy Paxman, and prophecies that the media will be defined by the user, no longer by celebrities.

https://youtu.be/FiK7s_0tGsg


Monday, October 6, 2008

Law Firm Uses Bogus Trademark Claim in Attempt to Silence Online News Site

EFF Urges Judge to Dismiss Baseless Lawsuit San Francisco - The Electronic Frontier Foundation (EFF, see another relevant post )and Public Citizen, joined by Public Knowledge and Citizen Media Law Project, urged a federal judge in Chicago Friday to dismiss a law firm's baseless trademark claims, which were apparently aimed at quashing speech by an online news site. The firm of Jones Day filed the lawsuit against the real estate news site Blockshopper.com, alleging that using its trademark "Jones Day" to refer to the firm in a headline and linking to the Jones Day website could lead to confusion over the sponsorship of the site. In its amicus brief, EFF and Public Citizen argue that these routine references to Jones Day are well-established fair uses of a trademark and clearly protected by the First Amendment. "The claims are absurd -- Blockshopper was simply reporting accurately on the activities of two lawyers who happen to be Jones Day employees," said EFF Staff Attorney Corynne McSherry. "That reporting is protected under trademark and free speech law, and Jones Day should know that. If Jones Day had its way, any trademark holder could use trademark claims to restrict news and commentary related to its business and any of its employees." "Jones Day alleges that the public could be confused by the references to its name and links, but Internet users know that websites generally link to other websites, independent of any official affiliation," said Paul Alan Levy, attorney with Public Citizen. "That's why it's called the World Wide Web." This amicus brief is part of EFF's No Downtime for Free Speech Campaign, which works to protect online expression in the face of baseless intellectual property claims. Robert Libman of Barnhill, Miner & Galland assisted in filing the brief. The full amicus brief is at http://www.eff.org/files/filenode/JDvBlockshopper/JonesDayAmicusBrief.pdf This release is from http://www.eff.org/press/archives/2008/09/19

Sunday, July 13, 2008

State Department seeks out the web savvy

I got hold of the State Department's Foreign Service Exam. It is of 4 parts - but the first part which contains 90 questions on general information, all multiple choice, such as naming Tunisia's two neighboring countries, is the most interesting. Each question had 4 possible answers. There were several questions about computers and the Internet. The first question was really tough. They wanted to know what else you needed to successfully login to your computer with besides your username. Maybe a password? The second question was right up there with the first. They wanted to know what the full name of the symbol was that goes between the username and the domain name in an e-mail address. The third question demanded to know what the acronym ISP meant. One of the choices was Internet Senior Professional! That would be you, I guess. They also had a challenging question asking us to identify the one item from the list that was not a device for storing data. The choices were Zip Drive, Disk Drive, Hard Drive, and CPU. The next question asked us if we knew what "html" was. Finally, the last question wanted to know if we understood the concept of "bookmarking" a website. Thus 6 of 90 questions about high technology and internet and you wonder why the State Department and USofA in general is so behind in technology, and, furthermore, on the recieving end of foreign and industrial espionage implementation.

Monday, July 7, 2008

Mis-nostalgia for dot coms

For all the talk about the Northern/Southern California corporate rivalries (Hollywood versus Silicon Valley), Northern California has its rivalry between Silicon Valley and San Francisco (the centers of which are separated by a one hour automobile drive). January 3-ish 2000, Los Angeles Times Magazine had a bunch of articles on the past and future of Silicon Valley. One article had the following quote from a San Francisco lawyer, which is one sentiment about the Northern California rivalry:
"I can't stand it", cries a lawyer in San Francisco at the mere mention of "the Peninsula", as people in the Bay Area call the valley to the south. "The tech bubble nearly caused the disintegration of our law firm. We had to relocate out of Menlo Park when our lease came up for renewal because E-Trade offered the landlord three times what we were paying. We'd been in that office, never missing a payment, for 14 years, and the landlord met with us for five minutes and then said, 'I don't know why I'm even talking to you.'" "I lost three really promising associates to dot-coms in those years.", he says. "I'd try to talk them into staying and, to a person, they sat across the desk laughing at me. It was all, 'You just don't get it!' And I didn't get it. There were all these 20-year-olds all over the place, going on about 'eyeballs' and 'mindshare' and riding their stupid scooters back and forth to their offices, and I was simultaneously wanting to puke and jealous as hell. It was a complete lack of common sense, and I'm telling you, you talk to those people for more than five minutes, and it's obvious that they haven't changed a bit."

Tuesday, June 17, 2008

Search engine flytrap (dusgusting) patent applied for

A patent search expert has just informed us of a quite abusive patent application filed, the sole purpose thereof is for attracting search engine (read:Google) hits. The patent offices might want to come up with a rule to cancel such fecal matter. The Patent search expert's observation: "Truly disgusting." If you look at this patent you'll see it's designed to be a magnet for hits when using keyword searches. 1376 pages of gibberish. Unless this gets removed many of us are going to be seeing this day after day after day. WO07081519A2: GENIUS ADAPTIVE DESIGN (World Intellectual Property Organization number) 2007-07-19 Abstract: Explore interesting inventions inside, conceived by our genius idea generator. Discover history's most effective method in conceiving novel uses for existing electronic technology. License huge domains of intellectual property from the invention directory our system helped develop. The searcher can find one of our interesting inventions in this patent application via our LicenseItToday.com, etc. Call our California Headquarters 1-707-428-5000. View invention ideas, plus 100+ variations adapted for end user target markets. LicenseItToday.com fills out exclusive international license agreements valid up to December 2026. It saves time and money creative LP. over any other documented creative thinking process. Licensees seek outputted patents using our or their pat attorneys. Royalties can start when profits begin. Or you can buy the affordable I.P. rights. Proof is in trying it out. Discover amazing inventions inside today.

Friday, May 16, 2008

Phishing the phishers

A n enterprising group of fraudsters from Morocco calling themselves Mr-Brain has launched a website that offers easy-to-use phishing site code, email templates and other hacking tools. The website offers phishing kits for many of the most common targets, such as Bank of America, eBay, PayPal and HSBC. The tools and code provided by Mr-Brain are designed to make it extremely easy for other fraudsters to deploy realistic phishing sites. Only a very basic knowledge of programming is required to configure the PHP scripts to send victims' details to the fraudsters' chosen electronic mail address. Deploying one of these fully working kits can be done in as little as one minute – another factor that adds to their appeal.
Phishing the phishers
Mr-Brain's intentions are to encourage as many people as possible to use their phishing kits, for all is not what it seems at first glance. Careful inspection of the configuration script reveals deceptive code that hides the true set of electronic mail addresses that are contacted by the kit – every phisher who uses these kits will unwittingly send a copy of each victim's details back to the Mr-Brain group. The configuration script exploits the case-sensitivity in PHP variable names to disguise Mr-Brain’s electronic mail address as an unrelated but seemingly essential part of the script, encouraging fraudsters not to alter it. The injected electronic mail address is actually contained in a completely separate PHP file, where it is encrypted in a hidden input field named "niarB", or "Brain" backwards. Yet another PHP script reads the value from this input field and decrypts it before supplying it to the configuration script. Most fraudsters are unlikely to notice this level of obfuscation and will assume the script is working normally, as they will also receive a copy of any emails produced by the script. When Netcraft decrypted the contents, the hidden input field revealed one of Mr-Brain's Gmail addresses, which is used to covertly capture details from all of the phishing kits that have been deployed on their behalf by other fraudsters. A comment at the top of one of the scripts aims to deter these fraudsters from examining the script that decrypts the hidden field: Earlier this month, Netcraft also exposed a similar phishing scam targeting Bank of America. This, too, was authored by Mr-Brain and was configured to covertly send harvested credentials to a different Gmail address. Each phishing kit listed on their website is accompanied by a description, showing what kind of information it steals from victims. One page on their website lists a selection of Social Security numbers, credit card numbers and PINs under the heading "Free and Freash [sic!] Credit Card". Mr-Brain claims that all of the scam pages offered on its site are undetected by Mozilla, Opera and Internet Explorer. Netcraft blocks these sites when they are detected by the Netcraft Toolbar community, and propagates the block to all companies which licence the Netcraft Phishing Site Feed.

Tuesday, May 13, 2008

Patenting Wikified

And another site for patent disinformation, images and marketplace is up-and-clicking, www.wikipatents.com. The usual mix of searching, PDF downloading, blogging and patent marketplace (speaking of PDFs, how many more years of lies from PTO management are we going to have to endure on why the PTO refuses to make PDF images available, as opposed to the insane TIFF format they now make available? - seriously, are there children managing the PTO computer systems?)
Anyway, one aspect of the Web site is the WikiPatents Marketplace, where companies can list patents for sale - www.wikipatents.com/marketplace.php - which is highly entertaining for the seriously, or hallucinogenically deluded valuations given by some of the patent owners. I have always thought that patent valuations is a bit of a con job, and this site reinforces my belief. Case in point. One patent available for sale is U.S. Patent 6,868,444, titled "Server configuration management and tracking", basically a set of distributed Web servers, with a May 2000 filing date. Claim 1 A web hosting system comprising: a plurality of geographically separate web hosting facilities associated with a web hosting provider; a plurality of servers located at each of said facilities having internet resources hosted thereon; and a server inventory database remote from at least some of said geographically separate web hosting facilities, said database configured to allow access to a first portion of the database by first user and access to a second distinct portion by a second user. This is nothing more than a distributed database server, technology which dates back to the 1990s, if not earlier. It is a mostly crap patent, made worse by the usual fact that it cites no non-patent prior art. Yet the owner of this patent claims it has an estimated value of: $1,280,904,608 Now I ask, how much drugs do you have to simultaneously sniff/snort/inject to think this piece of crap patent is worth over one billion dollars? And what does this nonsense say about the credibility of the Web site, and the other Estimated Values for patents listed on the Web site? Not much. So if you need a good laugh, definitely visit this Web site.

Friday, May 9, 2008

Clinton-Obama campaign uses XSS as a weapon

While Clinton and Obama are battling it out in the political arena, security researchers are continuing to find vulnerabilities in the candidates' and supporters' websites. Interestingly, while a typical exploit is to redirect one party's site to their opponent's, the reasons for seeking to discover such vulnerabilities are not always politically motivated.

Following the recent cross-site scripting attacks against Obama (see previous post), Finnish security researcher Harry Sintonen has published an example of a cross-site scripting vulnerability on votehillary.org.

Sintonen's example submits a POST request to the Vote Hillary website and injects an iframe, causing the site to display the contents of Barack Obama's website. Unlike the Obama incident, which redirected the user's web browser, Sintonen's method retains the votehillary.org URL in the address bar while displaying the opposing website.

Sintonen told a Netcraft reporter that he was inspired by the recent Obama attacks and first examined Hillary Clinton's official website at www.hillaryclinton.com. Sintonen did not find any cross-site scripting vulnerabilities on this site, adding that it looked quite secure, but subsequently found XSS opportunities available on the Vote Hillary website. Sintonen lives in Finland and has no strong interest in US politics.

While the example exploits have so far been relatively benign (limited to redirecting a user to the opponent's website, for example), future cross-site scripting vulnerabilities found on political candidate sites have plenty of scope to be much more serious. Obama's and Clinton's websites both accept monetary contributions towards their campaigns, so cross-site scripting vulnerabilities could be leveraged to steal money and identities from supporters.

Sintonen told Netcraft he informed the webmasters of votehillary.org about this cross-site scripting vulnerability two days ago, but has not yet received a response.

Thursday, May 8, 2008

Hacker drives Obama visitors to Clinton

A security weakness in Barack Obama's website has been exploited to redirect visitors to Hillary Clinton's website. Visitors who viewed the Community Blogs section of the site were instead presented with Clinton's website as a result of a cross-site scripting vulnerability.

Barack Obama's visitors were redirected to this site.

A user named Mox, from Liverpool, IL, posted an apparent confession in the Community Blogs section on the Barack Obama website yesterday. The subject of the post was, "I am the one who "hacked" Obama's site."

Mox plays down the matter by saying that all he did was exploit some poorly written HTML code before suggesting that it was a cross-site scripting vulnerability that had been exploited. By allowing users to enter characters such as > and " into their blog URLs, JavaScript could be injected into pages in the Community Blogs section and would be executed by subsequent visitors.

A YouTube clip from zennie62 demonstrates the attack. The clip shows a user clicking on the Community Blogs section of the Barack Obama site, which subsequently causes the browser to redirect to hillaryclinton.com. The author speculates that "Senator Clinton's staffers possibly hired someone to hack into the Barack Obama website system." No evidence is offered to back up this statement.

Another vulnerability found on the Barack Obama site.

While Mox states that the original issue has now been fixed, a number of similar vulnerabilities have since been identified and remain unfixed, and are documented on xssed.com, which notes that such vulnerabilities open up opportunities to infect Obama's supporters and site visitors with malware, adware and spyware.

Tuesday, April 29, 2008

SocialCardsters, Web 2.0

Just when we thought the limits to Web 2.0 have been explored, Ben Spark has come up with another idea for social blogging. He even came up with a new buzzword for it, SocialCardSter . Checking out http://www.benspark.com/socialcardsters reveals that it is especially suitable for the bloggers who are on SocialSpark and on Entrecard. The concept is about copying the blog roll and pasting it to a blog. It is also possible to add the SocialCardsters image to under one's Entrecard widget. Ben commits himself to a blogroll by dropping in on participating blogs and clicking on the blogs that are advertising. That serves to improve anyone's EC standing. Ben also tries to comment each week.

Wednesday, April 16, 2008

Just when you thought Google Docs were safe...

Just when you thought you were were safe from Google Desktop exploit, An interesting cross-site scripting (XSS) vulnerability found in the Google Spreadsheets service would have allowed attackers to gain unauthorised access to other Google services, including Gmail and Google Docs.

The vulnerability was discovered by security engineer Billy Rios , and takes advantage of nuances in the way Internet Explorer handles Content-Types for webpages.

Google Spreadsheets XSS

When a spreadsheet is saved and downloaded in CSV format, the Content-Type is set to "text/plain", thereby instructing the client's browser that the document should be treated as plain text. However, if HTML tags are entered into the first cell of the spreadsheet, Internet Explorer detects these tags near the start of the CSV document and instead deduces that it should be treated as HTML. This essentially allowed arbitrary HTML webpages to be served from spreadsheets.google.com, which in turn allowed JavaScript to be executed in the context of the spreadsheets.google.com site. A remote attacker could exploit this weakness by stealing the user's session cookies and hijacking their session.

Rios points out that Google cookies are valid for all google.com sub domains. This means that when a user logs in to Gmail, the Gmail cookie is also valid for other Google services, such as Google Code, Google Docs, Google Spreadsheets, and more. Cross-site scripting vulnerabilities in any of these sub domains can allow an attacker to hijack a user's session and access other Google services as if they were that user.

Google has fixed the vulnerability discovered by Rios and there have been no reports of the vulnerability being exploited by attackers.

Tuesday, April 1, 2008

Last minute sermons: the source

Busy Christian ministers and teachers find that they simply have no time to write sermons, they can always turn to www.lastminutesermon.com, a site started by Bob Austin. He started the site to provide a last-minute service for a clergyman in need of a sound, ready-to-deliver sermon. A typical sermon offered on the site can be preached in between eight to ten minutes, and costs about $12.50 to download. The site’s sample sermon preaches the essence of a Passover in Jerusalem 2000 years ago. Austin goes on to preach that then, Jews awaited the arrival of their messiah, who would, according to Austin, bring in their Golden Age by vanquishing the nations of the world and installing an everlasting kingdom of David. Prior to that Passover, however, Jesus had arrived on a donkey, signifying that he was that messiah but not the military(?) one. The crowds, according to Austin, were bitterly disappointed, and feeling cheated out of the military victories, turned their backs on Jesus and asked the Roman rulers to crucify him. The sample download says that with the destruction of the Temple came the end of animal sacrifices, which was God’s demonstrating his never-changing, unending love for humanity. Romans, maintaining law and order, had to comply with the public sentiment and crucify the troublemaker. After all, they crucified hundreds of Jews years before just to make sure the crowds would learn the lesson and forget the idea of rebelling against the Roman rule. Austin says that preachers are getting bogged down with their shepherding tasks as the writing of sermons is gradually sliding down the list of the daily priorities, leaving the clergyman without a sermon to deliver on Sunday. Sermons downloaded from the site come with a permission to be edited to suit the tastes of the flock. The site has a very simple structure: there is The Author, the FAQ, Free Sample, Contact and How To Buy. Excellent business idea: monetize the church.

Porn-free


Porn-Free.org has successfully addressed the problems associated with cyber pornography, which represents most of web’s domains and traffic. The site’s writer provides a meticulous analysis of Internet pornography’s aspects. There is a detailed study into the psychological stimuli behind viewing pornography, with further analysis of how Internet technology serves to exacerbate the addictive nature of this activity.

For example, the site discusses simple psychological tricks that are used to lure surfers to view newer facets of porn, such as child porn, homosexuality, bestiality, necrophilia, masochism, rape and sadism, with tangential excursions from each of these interests.The Statistics page is full of carefully referenced and compiled data on the business, traffic and history of Internet pornography. There are fascinating insights in the effect that adult sites play on workplace environment, high technology, child education and identity security.

Though the primary writer of the site appears to be an outspoken Christian, adding religious opinion to the site’s otherwise almost academic-like work, the argument against pornography is masterfully presented, rational, and extremely sober while being positive. The positive atmosphere of the analysis also serves to achieve surprising, fresh ideas about tackling problems associated with porn, and offers equally interesting solutions to staying free of the addiction.Again, despite its devotionally Christian tinge, the site provides incredible help for a porn addict, as well as for parents of children exposed to internet porn.

Monday, March 31, 2008

The Tjat marries cellphones to email

Nowadays the flashy new cellphones with all the bells and whistles give someone headaches when they won't let you hook up to one's email account or online address book. Either the special software you need won't install properly, or the emails are only received part of the time. Making the cellphone-to-email hassle go away is a startup company Tjat (pronounced t-jat) - the name coming from Swedish "to heckle." The company's online solution has successfully bridged the gap between your PC and cellphone, without the pain of having to install anything. Compatible with cellphones old and new, the Tjat system is currently being used by over two million people around the world. "In short," says Drori, Tjat's founder, originally from Los Angeles, Internet messaging through the cell phone "is complicated, expensive and hasn't been working for the last five years. Tjat says that our system works on any phone and that we will connect you into your account." Holding no grudges against the companies "that build clients," says Drori, "when you download something through the airwaves, something can go wrong." He estimates that over 65 percent of the time, programs designed to facilitate the email to cellphone capability, simply don't work. He also mentions the problem of cellphone viruses. Yet instant messaging and email remains one of the most popular methods for online communications in America. Tjat's online-based system (accessed through the company's web site) lets people connect directly and efficiently to any email service, including popular ones like Gmail, Yahoo or Hotmail. Using your mobile phone, you can check, send and receive as if you are using your own email account, says the company. On top of that, Tjat subscribers get a personal storage area for uploading or downloading pictures and videos without the need to connect to a PC. Tjat says it can help you share "photographic moments and experiences with anyone, anytime, and more importantly anywhere." How does it do it? Instead of requiring users to download new software, Tjat went around the problem. "We did away with the operating system," says Drori. The online platform opens the door to cellphone users who are not willing to invest money in buying client applications. Based instead on terminal-server architecture, Tjat offers a number of benefits to wireless operators such as low maintenance costs, compatibility with all cellular phones, with no technical support or help-desk costs. Most exciting to cellular operators, notes Drori, is an extremely high usage rate - each subscriber is currently producing about 2 MG worth of traffic each day, whereas the average amount for non-Tjat users is 40 times less, at about 50 KB. Based in Tel Aviv, Tjat was founded in 2004 as a garage startup by young and ambitious computer professionals. In May 2006, the company received an investment that helped it go live. The company has been growing since. Tjat sees itself as an attractive service for cellphone operators. Apparently the largest cellphone operator in the US does too. Drori didn't want to disclose the name, but boasts that his platform can increase revenue (which will be shared with Tjat) with no cost to the phone operator. Spanish-speaking Americans will be happy to know that Tjat is also able to operate and interface with multiple languages such as Spanish - a service that no other company has been able to provide to date, says Drori. Other languages currently available include English Arabic, Hebrew and Russian and about 10 others.

Tuesday, March 18, 2008

eBay buys Fraud Sciences

US online auctioning giant eBay and its subsidiary PayPal will soon be better protected from online fraud. This comes after news that PayPal has purchased Israeli online risk tools startup Fraud Sciences for $169 million. The small privately owned company, which only raised $7 million in investment before the buy-out, has developed verification technology for securing commercial transactions on the Internet. Fraud Sciences' technology is designed to uncover fraudulent credit card purchases by verifying that the customer making the purchase is in fact the cardholder. It uses a technique, known as 'identity proofing', which builds on the behavioral practices already used by many online retailers to detect fraud. Tel Aviv based Fraud Sciences was founded in April 2006 by Shvat Shaked, and Saar Wilf. They will be joining PayPal's technology and fraud management teams alongside Fraud Science's COO Yossi Barak. Other Israeli startups that have made the news recently are Modu and YouFig. Investors in Fraud Sciences include Redpoint Ventures, BRM Capital and entrepreneur Eli Barkat, who acquired a 40% stake in the firm for $5 million. He is set to make 12 times that amount in the exit. Fraud Sciences, which will continue to operate out of Israel, had originally intended to raise $11 million in a two-stage financing round, but in the course of due diligence, PayPal offered to buy the company out. eBay and e-commerce enabler PayPal have been facing an increasing battle against online fraud. They plan to use Fraud Science's risk tools and analytics to expose scams and deceptions targeted at their companies, and to accelerate the development of next generation fraud detection tools. Scott Thompson, president of PayPal, said the acquisition of Fraud Sciences fits into eBay's recently announced plans to significantly improve trust and safety across its sites this year. "Integrating Fraud Sciences' risk tools with PayPal's sophisticated fraud management system should allow us to be even more effective in protecting eBay and PayPal's hundreds of millions of customers around the world," he said. This is the second Israeli purchase for Californian Internet auction company eBay and its first purchase of a security technology company. In 2005, the US giant bought price comparison company Shopping.com, for $634 million.

Monday, March 17, 2008

Jazz festivals patentable; System a vague term

In this post:

· fun at the typical European anti-software-patent nonsense

· Payment issues in the Hollywood script writers’ strike

· Was the first clickable flashy Web ad used in ..... 1981?

· Patent used to confirm paintings are not Pollock’s

· Would jazz festivals be patentable?

· Is “system” a vague term?

ANTI-SOFTWARE-PATENT NONSENSE IN EUROPE UK attorney David Musker has written a satire of anti-software-patent nonsense in Europe: “The great free bear debate, or what ales the patent system?”. Great satire. He should be appointed head of the EPO Board of Appeals - the decisions, if not more rational, will at least be more entertaining. Read here PAYMENT ISSUES IN THE HOLLYWOOD SCRIPT WRITERS’ STRIKE If you are following the script writers’ strike in Hollywood and New York, one main question is what they are actually arguing about, beyond that the writers want more money. The 1 December issue of the New York Times, page B4, has some specific examples: The [writers’ guild] leaders said, for instance that [the new contract] would pay only $250 for a year’s reuse of an hour-long program streamed on the Web, in contrast to the $20,000 currently paid for a network re-run. The producers have offered writers the same residual rate [for downloaded films and shows] they pay for DVDs, which works out to 0.36 percent of wholesale revenues, which amounts to pennies per DVD but tens of thousands of dollars on the millions of copies of even modest hits; writers are seeking a rate of 2.5 percent. [A writers’ guild leader] said guild leaders were “pleased” to know that [entertainment] companies were now offering an economic package they say will add $130 million to the $1.3 billion they already pay writers. $20,000 - multiples of $10,000 - $130 million - $1.3 billion - large amounts of money for the rights to scripts. Why? Because NEW scripts and their DETAILED DESCRIPTIONS OF plot PROCESSES, at these levels of money, ARE very CONCRETE, TANGIBLE and USEFUL. :-) WAS THE FIRST CLICKABLE FLASHY WEB AD USED IN ..... 1981? I recently came across a 1981 book on videotext that mentioned something called Adflashes, which seems to have anticipated flashy Web ads by over 10 years: ”The advertisement flash, or ‘adflash’, technique consists of drawing attention to an advertisement on another page by flashing characters to induce you to request that page ..... The adflash technique attempts to mix editorial and advertising in traditional newspaper fashion. However, the reader/viewer for the first time has to press a button to see advertisements, .... The efficacy of adflashes is questionable at this stage in the development of Prestel.” The first clickable Web ad was sold by GNN in 1993 to a law firm, 12 years after adflashes. Another reminder that much of the innovation in the Internet had to do with marketing, not technology - the eternal legacy of Microsoft. PATENT USED TO CONFIRM PAINTINGS ARE NOT POLLOCK’S Tne 29 November 2007 New York Times, page C16, has an article on the disputed authenticity of some recently discovered paintings attributed to Jackson Pollack. In 2002/2003, the son of artists friends of Pollock found, in a storage locker, 32 paintings supposedly done by Pollock. Art experts have been arguing since then if the paintings are authentic or not. The initial art reviewers said they were authentic, but later art experts said they weren’t. One recent study, done by Richard Newman of the Museum of Fine Arts in Boston, found that for two of the nine paintings Newman looked at, the two paintings contained a pigment first known to have been patented by Ciba-Geigy in 1983. Since Pollock died in 1956, the painting is either not his, or it is one of his painting that has since been altered. There are also mismatches between the paints used in the 32 paintings, and paints found in Pollock’s studio. One for the patent detectives. I remember years ago hearing about a murder case where the murder victim was bound with an unidentifiable type of tape. However there was a number on the tape that detectives realized was a patent number, and used information from the patent in their case. What next - Law and Order - Alexandria? In the first episode, a dead body is found floating in the Potomac with the sign “3(b)” scratched out on the chest by the victim. Oooooooh, sounds mysterious! WOULD JAZZ FESTIVALS, IF NOVEL TODAY, BE PATENTABLE? The November 28 edition of the New York Times, page C12, has an obituary for Elaine Lorillard, a founder of the Newport Jazz Festival, which in turn has inspired jazz festivals around the world. Lorillard was a socialite married to Louis Lorillard, a descendant of Pierre Lorillard, who found the P. Lorillard Tobacco Company in 1760. Here’s the interesting question in light of the questionable illogic of KSR/Graham - if jazz festivals did not exist today (102 novelty for a 101 business method with an easy to create 112 description), would the idea be unobvious enough to be patentable under 103? And if so today, if State Street existed in 1954 (the year of the first Jazz festival), would jazz festivals have been patentable in 1954? First, the motivation for Lorillard to create the jazz festivals. From the obituary: It was a casual remark during intermission at a classical concert in Newport in 1953 that inspired the Lorillards to sponsor the first Newport Jazz Festival. Mrs. Lorillard, already a jazz fan, was seated next to John Maxon, then head of the Rhode Island School of Design Museum. ”It’s too bad we can’t do something like this for jazz.”, he said. “That’s another music form that’s worth a big-time festival.” The Lorillards got in touch with George Wein, then the owner of a jazz club in Boston, and asked him to produce that first festival. A priori, let’s assume that the business method of jazz festivals meets 101 via State Street, 102 via no prior art, and 112 via a good lawyer. One simple question remains: are jazz festivals obvious? The examiner issues an Official Notice rejection with little explanation other than citing the prior art of non-jazz outdoor festivals, “obviously” combined with jazz. Indeed, outdoor music festivals have been around for centuries. The applicant comes back and argues, using KSR, “You can’t make that objection, it’s hindsight analysis. After all, its been 50 years since the invention of Jazz (Buddy Bolden and Jelly Roll Morton in 1905). It’s a clear failure of others to invent. And 50 years is the length of time the Supreme Court felt comfortable with in Goodyear for something to be unobvious.” Who wins? I quote from Goodyear Tire v. Ray-O-Vac, a 1944 Supreme Court case (321 U.S. 275, 278), which KSR rests on via citation chains: ”We think this case is one of the category of inventions which, when viewed after disclosure and explanation by the applicant, seem simple and such as should have been obvious to those in the field. Yet this does not necessarily [negate] invention or patentability.” The next sentence: ”During a period of a half century .....................” The same half century between the invention of jazz and the existence of outdoor music festivals, and the invention of the outdoor jazz festival. An obvious combination (jazz + outdoor music) or not? Obvious combination or not in light of this foundation language for hindsight bias in Goodyear? And thus, patentable to not? I say patentable. There is too much judicial handwaving going on to try to give meaning to the completely vague 35 USC 103. Inventors should not be penalized for the incompetence of Congress and the courts, and their arrogance that they think they understand “obvious” - they don’t. IS “SYSTEM” A VAGUE TERM? A reader sent in the following paragraph from an Office Action, obviously a less-trained examiner: ”Claims 55-66 recite ‘system’ which is vague and indefinite since a system may be one of several different statutory classes of invention (including a method or an apparatus). Applicant must indicate on the record to what statutory class of invention the system claims belong. For the purposes of this examination these claims are considered apparatus.” How do you respond? “Our system claims are for systems that belong to the statutory class of systems.” “System” claims appear in zillions of patent - articles of manufacture (systems are comprised of multiple manufactured apparati). PTO entanglement should shut up about rules changes until it fixes its many current problems, like Peterlin making it easier for Chinese spies to steal American secrets by bugging the homes of her teleworking examiners. See a previous post on claims.

Wednesday, March 12, 2008

YouFig fuses online social networks

Israel's YouFig fuses online social networks (by Karin Kloosterman): Internet applications like Myspace and Facebook have revolutionized the way we socialize. We can reconnect with old flames, share our holiday pictures with the world, play poker with strangers, and share our lives with fans, friends, admirers and co-workers.

With satellite offices sprouting up around the world, and people continually on the go, a new social networking platform built in Israel, and known as YouFig, lets people build ideas and dreams together online. Now in schools in Florida and being tested by a handful of Fortune 500 companies, YouFig creates a virtual community center where people can interact and create online content in a way never before possible.

The company, founded in 2007, says that it is pioneering the evolution of real-time online collaboration. It allows people to mimic classic face-to-face meetings, while taking advantage of networking and group thought."The unique thing about YouFig is that it enables any organization- whether it's a family of a few people or an academic institution - to collaborate any time in real-time on any continent," says YouFig's co-founder Allon Mason.

Now in beta testing mode and set to be released publicly by the end of the year, YouFig provides its members with a virtual workspace. Equipped with tools such as wikis, video conferencing, and instant messaging, YouFig encourages people to work together on any topic and with any type of media such as games, videos, documents, and spreadsheets. YouFig allows people to use and create "widgets," which are small applications that can be easily shared among peers and in other networks.

Funded by ICQ founder Yossi Vardi, an Israeli entrepreneur, and based in Herzliya Pituach, YouFig launched its alpha site last August and its beta site this past January.

"It allows families to create to-do lists together for a camping trip. But it is a great tool for distributed work forces as well," Mason says. "We are talking with news agencies around the world. Our platform could let journalists and editors collaborate and share information in real-time. It's a great way to centralize information on one platform in one organization."

Still in its beta mode, YouFig already has about 60 networking communities, one of which is the London Business School. Its primary target market will be schools in the US however: "The early adopters of technology," says Mason.

The company's business model will be based on an advertising revenue model. In the future, companies and schools will pay to subscribe to private communities that they create, but the cost will be much less than enterprise software, today affordable only to large organizations.

A special edition YouFig for private companies and schools will be called the "White Label." In the meantime, it can be used free of charge.

The nuts and bolts of YouFig is to let people have a space to argue, discuss, collaborate and talk. A user can begin by creating a topic and the application can locate other experts in the field.

Limited to only eight people per discussion group, interaction is intimate and this way the accountability of each member in increased. Users can talk politics, build new video games together, or co-write a script or music video. The sky's the limit, says Mason.

Users may know each other already or seek each other out through YouFig. Collaboration today is limited to wikis and blogs, says Mason. "We think that when people want to collaborate, it can be on any material and medium. Any document, spreadsheet or games... and not limit them.

"YouFig is centralized and fast, and works for organizations of any size," he adds.

Wednesday, January 16, 2008

Google Desktop Exploitability

(As I published on Shvoong): It was a matter of time before someone
realized that Google Desktop has provided an opening into a PC through
which a hacker can get an easy entry. Mattan Gillon, an Israeli hacker,
performed an act of public service by exposing the flaw on his blog.

Exploiting a bug in Microsoft Internet Explorer's processing Cascading
Style Sheets (CSS). The CSS format is commonly used to give a Web
site page a consistent look and navigation properties, and attackers can
target the process by which IE
parses CSS while running Google Desktop. Gillon explains how browsers
usually turn off domain crossing. A specific web
page can direct a browser to another domain, though it may not retrieve
the contents of the page nor run any of its objects. This restriction
feature serves to preclude a site owner using JavaScript from spying on
a user. Additionally, if a user is already logged
on to a web service such as Yahoo, Hotmail or Gmail, a malicious web
page could be used to run a malicious operation in the user account.
This operation can be an opening of an email and the subsequent sending
it to a third party. In IE, these security features are easily broken
when the browser encounters a CSS import.

Mattan Gillon called this attack CSSXSS, or Cascading Style Sheets Cross-Site
Scripting. Using the IE browser's weakness of being fooled by curly
brackets strategically placed in a decoy site's code, and getting hold
of Google Desktop's key found in the application code, a hacker can
easily gain an entry into the target PC already running the Google
Desktop service.For this IE weakness to be
exploited, web surfers must first be tricked into visiting a malicious
Web site. They can protect themselves, however, if they turn off Active
Scripting in the IE's Internet Options menu, Gillon says.