BBC Newsnight interview from 1999
Saturday, March 21, 2020
David Bowie's Prophecy
BBC Newsnight interview from 1999
Monday, October 6, 2008
Law Firm Uses Bogus Trademark Claim in Attempt to Silence Online News Site
Sunday, July 13, 2008
State Department seeks out the web savvy
Monday, July 7, 2008
Mis-nostalgia for dot coms
Tuesday, June 17, 2008
Search engine flytrap (dusgusting) patent applied for
Friday, May 16, 2008
Phishing the phishers
Tuesday, May 13, 2008
Patenting Wikified
Friday, May 9, 2008
Clinton-Obama campaign uses XSS as a weapon
Following the recent cross-site scripting attacks against Obama (see previous post), Finnish security researcher Harry Sintonen has published an example of a cross-site scripting vulnerability on votehillary.org.
Sintonen's example submits a POST request to the Vote Hillary website and injects an iframe, causing the site to display the contents of Barack Obama's website. Unlike the Obama incident, which redirected the user's web browser, Sintonen's method retains the votehillary.org URL in the address bar while displaying the opposing website.
Sintonen told a Netcraft reporter that he was inspired by the recent Obama attacks and first examined Hillary Clinton's official website at www.hillaryclinton.com. Sintonen did not find any cross-site scripting vulnerabilities on this site, adding that it looked quite secure, but subsequently found XSS opportunities available on the Vote Hillary website. Sintonen lives in Finland and has no strong interest in US politics.
While the example exploits have so far been relatively benign (limited to redirecting a user to the opponent's website, for example), future cross-site scripting vulnerabilities found on political candidate sites have plenty of scope to be much more serious. Obama's and Clinton's websites both accept monetary contributions towards their campaigns, so cross-site scripting vulnerabilities could be leveraged to steal money and identities from supporters.
Sintonen told Netcraft he informed the webmasters of votehillary.org about this cross-site scripting vulnerability two days ago, but has not yet received a response.
Thursday, May 8, 2008
Hacker drives Obama visitors to Clinton
A user named Mox, from Liverpool, IL, posted an apparent confession in the Community Blogs section on the Barack Obama website yesterday. The subject of the post was, "I am the one who "hacked" Obama's site."
Mox plays down the matter by saying that all he did was exploit some poorly written HTML code before suggesting that it was a cross-site scripting vulnerability that had been exploited. By allowing users to enter characters such as > and " into their blog URLs, JavaScript could be injected into pages in the Community Blogs section and would be executed by subsequent visitors.
A YouTube clip from zennie62 demonstrates the attack. The clip shows a user clicking on the Community Blogs section of the Barack Obama site, which subsequently causes the browser to redirect to hillaryclinton.com. The author speculates that "Senator Clinton's staffers possibly hired someone to hack into the Barack Obama website system." No evidence is offered to back up this statement.
While Mox states that the original issue has now been fixed, a number of similar vulnerabilities have since been identified and remain unfixed, and are documented on xssed.com, which notes that such vulnerabilities open up opportunities to infect Obama's supporters and site visitors with malware, adware and spyware.
Tuesday, April 29, 2008
SocialCardsters, Web 2.0
Wednesday, April 16, 2008
Just when you thought Google Docs were safe...
Just when you thought you were were safe from Google Desktop exploit, An interesting cross-site scripting (XSS) vulnerability found in the Google Spreadsheets service would have allowed attackers to gain unauthorised access to other Google services, including Gmail and Google Docs.
The vulnerability was discovered by security engineer Billy Rios , and takes advantage of nuances in the way Internet Explorer handles Content-Types for webpages.
When a spreadsheet is saved and downloaded in CSV format, the Content-Type is set to "text/plain", thereby instructing the client's browser that the document should be treated as plain text. However, if HTML tags are entered into the first cell of the spreadsheet, Internet Explorer detects these tags near the start of the CSV document and instead deduces that it should be treated as HTML. This essentially allowed arbitrary HTML webpages to be served from spreadsheets.google.com, which in turn allowed JavaScript to be executed in the context of the spreadsheets.google.com site. A remote attacker could exploit this weakness by stealing the user's session cookies and hijacking their session.
Rios points out that Google cookies are valid for all google.com sub domains. This means that when a user logs in to Gmail, the Gmail cookie is also valid for other Google services, such as Google Code, Google Docs, Google Spreadsheets, and more. Cross-site scripting vulnerabilities in any of these sub domains can allow an attacker to hijack a user's session and access other Google services as if they were that user.
Google has fixed the vulnerability discovered by Rios and there have been no reports of the vulnerability being exploited by attackers.
Tuesday, April 1, 2008
Last minute sermons: the source
Porn-free

For example, the site discusses simple psychological tricks that are used to lure surfers to view newer facets of porn, such as child porn, homosexuality, bestiality, necrophilia, masochism, rape and sadism, with tangential excursions from each of these interests.The Statistics page is full of carefully referenced and compiled data on the business, traffic and history of Internet pornography. There are fascinating insights in the effect that adult sites play on workplace environment, high technology, child education and identity security.
Though the primary writer of the site appears to be an outspoken Christian, adding religious opinion to the site’s otherwise almost academic-like work, the argument against pornography is masterfully presented, rational, and extremely sober while being positive. The positive atmosphere of the analysis also serves to achieve surprising, fresh ideas about tackling problems associated with porn, and offers equally interesting solutions to staying free of the addiction.Again, despite its devotionally Christian tinge, the site provides incredible help for a porn addict, as well as for parents of children exposed to internet porn.
Monday, March 31, 2008
The Tjat marries cellphones to email
Tuesday, March 18, 2008
eBay buys Fraud Sciences
Monday, March 17, 2008
Jazz festivals patentable; System a vague term
In this post:
· fun at the typical European anti-software-patent nonsense
· Payment issues in the Hollywood script writers’ strike
· Was the first clickable flashy Web ad used in ..... 1981?
· Patent used to confirm paintings are not Pollock’s
· Would jazz festivals be patentable?
· Is “system” a vague term?
ANTI-SOFTWARE-PATENT NONSENSE IN EUROPE UK attorney David Musker has written a satire of anti-software-patent nonsense in Europe: “The great free bear debate, or what ales the patent system?”. Great satire. He should be appointed head of the EPO Board of Appeals - the decisions, if not more rational, will at least be more entertaining. Read here PAYMENT ISSUES IN THE HOLLYWOOD SCRIPT WRITERS’ STRIKE If you are following the script writers’ strike in Hollywood and New York, one main question is what they are actually arguing about, beyond that the writers want more money. The 1 December issue of the New York Times, page B4, has some specific examples: The [writers’ guild] leaders said, for instance that [the new contract] would pay only $250 for a year’s reuse of an hour-long program streamed on the Web, in contrast to the $20,000 currently paid for a network re-run. The producers have offered writers the same residual rate [for downloaded films and shows] they pay for DVDs, which works out to 0.36 percent of wholesale revenues, which amounts to pennies per DVD but tens of thousands of dollars on the millions of copies of even modest hits; writers are seeking a rate of 2.5 percent. [A writers’ guild leader] said guild leaders were “pleased” to know that [entertainment] companies were now offering an economic package they say will add $130 million to the $1.3 billion they already pay writers. $20,000 - multiples of $10,000 - $130 million - $1.3 billion - large amounts of money for the rights to scripts. Why? Because NEW scripts and their DETAILED DESCRIPTIONS OF plot PROCESSES, at these levels of money, ARE very CONCRETE, TANGIBLE and USEFUL. :-) WAS THE FIRST CLICKABLE FLASHY WEB AD USED IN ..... 1981? I recently came across a 1981 book on videotext that mentioned something called Adflashes, which seems to have anticipated flashy Web ads by over 10 years: ”The advertisement flash, or ‘adflash’, technique consists of drawing attention to an advertisement on another page by flashing characters to induce you to request that page ..... The adflash technique attempts to mix editorial and advertising in traditional newspaper fashion. However, the reader/viewer for the first time has to press a button to see advertisements, .... The efficacy of adflashes is questionable at this stage in the development of Prestel.” The first clickable Web ad was sold by GNN in 1993 to a law firm, 12 years after adflashes. Another reminder that much of the innovation in the Internet had to do with marketing, not technology - the eternal legacy of Microsoft. PATENT USED TO CONFIRM PAINTINGS ARE NOT POLLOCK’S Tne 29 November 2007 New York Times, page C16, has an article on the disputed authenticity of some recently discovered paintings attributed to Jackson Pollack. In 2002/2003, the son of artists friends of Pollock found, in a storage locker, 32 paintings supposedly done by Pollock. Art experts have been arguing since then if the paintings are authentic or not. The initial art reviewers said they were authentic, but later art experts said they weren’t. One recent study, done by Richard Newman of the Museum of Fine Arts in Boston, found that for two of the nine paintings Newman looked at, the two paintings contained a pigment first known to have been patented by Ciba-Geigy in 1983. Since Pollock died in 1956, the painting is either not his, or it is one of his painting that has since been altered. There are also mismatches between the paints used in the 32 paintings, and paints found in Pollock’s studio. One for the patent detectives. I remember years ago hearing about a murder case where the murder victim was bound with an unidentifiable type of tape. However there was a number on the tape that detectives realized was a patent number, and used information from the patent in their case. What next - Law and Order - Alexandria? In the first episode, a dead body is found floating in the Potomac with the sign “3(b)” scratched out on the chest by the victim. Oooooooh, sounds mysterious! WOULD JAZZ FESTIVALS, IF NOVEL TODAY, BE PATENTABLE? The November 28 edition of the New York Times, page C12, has an obituary for Elaine Lorillard, a founder of the Newport Jazz Festival, which in turn has inspired jazz festivals around the world. Lorillard was a socialite married to Louis Lorillard, a descendant of Pierre Lorillard, who found the P. Lorillard Tobacco Company in 1760. Here’s the interesting question in light of the questionable illogic of KSR/Graham - if jazz festivals did not exist today (102 novelty for a 101 business method with an easy to create 112 description), would the idea be unobvious enough to be patentable under 103? And if so today, if State Street existed in 1954 (the year of the first Jazz festival), would jazz festivals have been patentable in 1954? First, the motivation for Lorillard to create the jazz festivals. From the obituary: It was a casual remark during intermission at a classical concert in Newport in 1953 that inspired the Lorillards to sponsor the first Newport Jazz Festival. Mrs. Lorillard, already a jazz fan, was seated next to John Maxon, then head of the Rhode Island School of Design Museum. ”It’s too bad we can’t do something like this for jazz.”, he said. “That’s another music form that’s worth a big-time festival.” The Lorillards got in touch with George Wein, then the owner of a jazz club in Boston, and asked him to produce that first festival. A priori, let’s assume that the business method of jazz festivals meets 101 via State Street, 102 via no prior art, and 112 via a good lawyer. One simple question remains: are jazz festivals obvious? The examiner issues an Official Notice rejection with little explanation other than citing the prior art of non-jazz outdoor festivals, “obviously” combined with jazz. Indeed, outdoor music festivals have been around for centuries. The applicant comes back and argues, using KSR, “You can’t make that objection, it’s hindsight analysis. After all, its been 50 years since the invention of Jazz (Buddy Bolden and Jelly Roll Morton in 1905). It’s a clear failure of others to invent. And 50 years is the length of time the Supreme Court felt comfortable with in Goodyear for something to be unobvious.” Who wins? I quote from Goodyear Tire v. Ray-O-Vac, a 1944 Supreme Court case (321 U.S. 275, 278), which KSR rests on via citation chains: ”We think this case is one of the category of inventions which, when viewed after disclosure and explanation by the applicant, seem simple and such as should have been obvious to those in the field. Yet this does not necessarily [negate] invention or patentability.” The next sentence: ”During a period of a half century .....................” The same half century between the invention of jazz and the existence of outdoor music festivals, and the invention of the outdoor jazz festival. An obvious combination (jazz + outdoor music) or not? Obvious combination or not in light of this foundation language for hindsight bias in Goodyear? And thus, patentable to not? I say patentable. There is too much judicial handwaving going on to try to give meaning to the completely vague 35 USC 103. Inventors should not be penalized for the incompetence of Congress and the courts, and their arrogance that they think they understand “obvious” - they don’t. IS “SYSTEM” A VAGUE TERM? A reader sent in the following paragraph from an Office Action, obviously a less-trained examiner: ”Claims 55-66 recite ‘system’ which is vague and indefinite since a system may be one of several different statutory classes of invention (including a method or an apparatus). Applicant must indicate on the record to what statutory class of invention the system claims belong. For the purposes of this examination these claims are considered apparatus.” How do you respond? “Our system claims are for systems that belong to the statutory class of systems.” “System” claims appear in zillions of patent - articles of manufacture (systems are comprised of multiple manufactured apparati). PTO entanglement should shut up about rules changes until it fixes its many current problems, like Peterlin making it easier for Chinese spies to steal American secrets by bugging the homes of her teleworking examiners. See a previous post on claims.
Wednesday, March 12, 2008
YouFig fuses online social networks
With satellite offices sprouting up around the world, and people continually on the go, a new social networking platform built in Israel, and known as YouFig, lets people build ideas and dreams together online. Now in schools in Florida and being tested by a handful of Fortune 500 companies, YouFig creates a virtual community center where people can interact and create online content in a way never before possible.
The company, founded in 2007, says that it is pioneering the evolution of real-time online collaboration. It allows people to mimic classic face-to-face meetings, while taking advantage of networking and group thought."The unique thing about YouFig is that it enables any organization- whether it's a family of a few people or an academic institution - to collaborate any time in real-time on any continent," says YouFig's co-founder Allon Mason.
Now in beta testing mode and set to be released publicly by the end of the year, YouFig provides its members with a virtual workspace. Equipped with tools such as wikis, video conferencing, and instant messaging, YouFig encourages people to work together on any topic and with any type of media such as games, videos, documents, and spreadsheets. YouFig allows people to use and create "widgets," which are small applications that can be easily shared among peers and in other networks.
Funded by ICQ founder Yossi Vardi, an Israeli entrepreneur, and based in Herzliya Pituach, YouFig launched its alpha site last August and its beta site this past January.
"It allows families to create to-do lists together for a camping trip. But it is a great tool for distributed work forces as well," Mason says. "We are talking with news agencies around the world. Our platform could let journalists and editors collaborate and share information in real-time. It's a great way to centralize information on one platform in one organization."
Still in its beta mode, YouFig already has about 60 networking communities, one of which is the London Business School. Its primary target market will be schools in the US however: "The early adopters of technology," says Mason.
The company's business model will be based on an advertising revenue model. In the future, companies and schools will pay to subscribe to private communities that they create, but the cost will be much less than enterprise software, today affordable only to large organizations.
A special edition YouFig for private companies and schools will be called the "White Label." In the meantime, it can be used free of charge.
The nuts and bolts of YouFig is to let people have a space to argue, discuss, collaborate and talk. A user can begin by creating a topic and the application can locate other experts in the field.
Limited to only eight people per discussion group, interaction is intimate and this way the accountability of each member in increased. Users can talk politics, build new video games together, or co-write a script or music video. The sky's the limit, says Mason.
Users may know each other already or seek each other out through YouFig. Collaboration today is limited to wikis and blogs, says Mason. "We think that when people want to collaborate, it can be on any material and medium. Any document, spreadsheet or games... and not limit them.
"YouFig is centralized and fast, and works for organizations of any size," he adds.
Wednesday, January 16, 2008
Google Desktop Exploitability
realized that Google Desktop has provided an opening into a PC through
which a hacker can get an easy entry. Mattan Gillon, an Israeli hacker,
performed an act of public service by exposing the flaw on his blog.
Exploiting a bug in Microsoft Internet Explorer's processing Cascading
Style Sheets (CSS). The CSS format is commonly used to give a Web
site page a consistent look and navigation properties, and attackers can
target the process by which IE
parses CSS while running Google Desktop. Gillon explains how browsers
usually turn off domain crossing. A specific web
page can direct a browser to another domain, though it may not retrieve
the contents of the page nor run any of its objects. This restriction
feature serves to preclude a site owner using JavaScript from spying on
a user. Additionally, if a user is already logged
on to a web service such as Yahoo, Hotmail or Gmail, a malicious web
page could be used to run a malicious operation in the user account.
This operation can be an opening of an email and the subsequent sending
it to a third party. In IE, these security features are easily broken
when the browser encounters a CSS import.
Mattan Gillon called this attack CSSXSS, or Cascading Style Sheets Cross-Site
Scripting. Using the IE browser's weakness of being fooled by curly
brackets strategically placed in a decoy site's code, and getting hold
of Google Desktop's key found in the application code, a hacker can
easily gain an entry into the target PC already running the Google
Desktop service.For this IE weakness to be
exploited, web surfers must first be tricked into visiting a malicious
Web site. They can protect themselves, however, if they turn off Active
Scripting in the IE's Internet Options menu, Gillon says.


