Monday, May 12, 2008

RIAA starts buying laws

This is the courtesy of those who can buy laws: Board of Supervisors of Los Angeles has passed a city ordinance that authorizes civil fines for copyright infringement. If a property in LA is used for copyright piracy (since the RIAA/MPAA bought this legislation, they didn't feel any need to include patent piracy as well), the property can be padlocked for a year and a $1,000 fine slapped for each pirated work produced. See blog.wired.com/27bstroke6/2008/05/los-angeles-say.html
The Board of Supervisors did not agree to add an extra penalty for convicted pirates - having to read one law review article or court decision involving the idea/expression dichotomy for each act of piracy - city lawyers argued that was cruel and unusual punishment.

Saturday, May 10, 2008

Sequence, by Lori Andrews

Last December, I saw an article in Science that badly attacked software patents, written by law professor Lori Andrews of Chicago-Kent. Her article was riddled with nonsense about math algorithms, making her anti-software patent conclusions just as nonsensical. She didn't ask
anyone knowledgable about such stuff for advice, and misinterpreted State Street. Sadly, the Science editors didn't retract her paper for the false science in it. The article is mostly fiction.

So it isn't surprising that she is a good fiction writer. I just finished reading a biotech fiction book she had published last year titled "Sequence". The book is set at the Armed Forces Institute of
Pathology, and involves government scientists using DNA analysis to track down killers, with the usual mix of love affairs, politically intrigue and biotech. It was a good read - I pretty much read in one reading. I am thinking that the main character, Alex Blake, a female biotech scientist, is Lori's alter ego :-) She has a new fiction work coming out, "The Silent Assassin". As long as it avoids software and mathematics, I suspect it will be good as well. But as a bit of advice to Lori, everything in her book is conventional. If you really understand the latest in genetics and ethics, you should be writing orders more intriguing books (my problem as will with Rifkin).

Such as a work coming out next year titled "Their Kisses Kill", a mix of biotech, religion, bioethics, government conspiracies, nuns and knights, and of course, the best setting for anything, the Bay Area.

Friday, May 9, 2008

Clinton-Obama campaign uses XSS as a weapon

While Clinton and Obama are battling it out in the political arena, security researchers are continuing to find vulnerabilities in the candidates' and supporters' websites. Interestingly, while a typical exploit is to redirect one party's site to their opponent's, the reasons for seeking to discover such vulnerabilities are not always politically motivated.

Following the recent cross-site scripting attacks against Obama (see previous post), Finnish security researcher Harry Sintonen has published an example of a cross-site scripting vulnerability on votehillary.org.

Sintonen's example submits a POST request to the Vote Hillary website and injects an iframe, causing the site to display the contents of Barack Obama's website. Unlike the Obama incident, which redirected the user's web browser, Sintonen's method retains the votehillary.org URL in the address bar while displaying the opposing website.

Sintonen told a Netcraft reporter that he was inspired by the recent Obama attacks and first examined Hillary Clinton's official website at www.hillaryclinton.com. Sintonen did not find any cross-site scripting vulnerabilities on this site, adding that it looked quite secure, but subsequently found XSS opportunities available on the Vote Hillary website. Sintonen lives in Finland and has no strong interest in US politics.

While the example exploits have so far been relatively benign (limited to redirecting a user to the opponent's website, for example), future cross-site scripting vulnerabilities found on political candidate sites have plenty of scope to be much more serious. Obama's and Clinton's websites both accept monetary contributions towards their campaigns, so cross-site scripting vulnerabilities could be leveraged to steal money and identities from supporters.

Sintonen told Netcraft he informed the webmasters of votehillary.org about this cross-site scripting vulnerability two days ago, but has not yet received a response.