Silicon Valley Technology Commentary & Archives · Est. 2006 3,045 Posts · 2006–2026
Showing posts with label Security (28 posts). Show all posts

January 1, 2015

January 1, 2015 · 5 MIN READ · BY LOUIS GRAY

10 New Year's Resolutions (for you) for the Year 2015

10 New Year's Resolutions (for you) for the Year 2015

A new year is a somewhat arbitrary point in time to mark change. But tradition has it that we do two things when the calendar turns from December to January. We look back on the previous year, either with pride over accomplishments, or dismissal of bad experiences, and we optimistically expect the best for the coming twelve months.

In years past I've put forth fun predictions for the world in tech. And trust me, I have some predictions, but I'll hold those close to the vest. Working at Google makes predicting the future like cheating. And I won't bore you with a list of my own resolutions for 2015. Instead, I'll suggest (with bias) ten resolutions each of you (and often us too) should take this year to make our online and offline lives even better.

1. Protect yourself and your data from the bad guys.

Seemingly every week, we are seeing news about security breaches at major retail stores, or finding online databases have been impacted. And outside the headlines, bad actors are out there trying to harvest your online information. I recommend protecting yourself by using two-factor authentication wherever possible, trying to avoid the reuse of passwords, and setting up automatic alerts that tell you if your credit cards are being used anywhere, or over a certain dollar amount.

In 2014, I managed nearly 6 million steps on Fitbit.

2. Use intelligent data to make yourself a better person.

Seemingly everyone's New Year's resolution is to go to the gym more or lose weight. But those resolutions tend to fade out after a strong month or so. Instead, find a fitness tracker or application that makes sense to track what you already do, and find a way to increase those numbers. My adoption of Fitbit two and a half years ago helped me lose more than 20 pounds, encouraged me to buy a treadmill, and find the way to walk just about everywhere.

3. Use intelligent data to make your home a smarter one.

Once you know to count your data with services like Fitbit, running your home without data is kind of dumb. By adopting Nest and Sunrun to handle our energy costs, and Rachio to manage our smart sprinkler system, we've not only set ourselves up to save money each month, but we can better predict our use, and make changes when necessary.

Our Solar powered home saves money and saves the air too.

4. If you have money, put it in places with long term benefits.

In 2010, we bought our home, putting out more money than I've ever done. But with rising Silicon Valley real estate prices, that looks like a good investment. In 2011, we refinanced. In 2012, we paid off our cars and, with the exception of our home, were debt free. In 2013, we bought a treadmill, to keep us active, even if not leaving the house. And in 2014, we made two big expenditures: The first being our Sunrun solar system, which will save us more than $65,000 in the lifetime of the 20 year contract, and the second, paying off a home equity line of credit, which was taking $300 a month, every month. We paid it off 28 years early. This year, we're hoping to get rid of our external storage unit, and continuing to take costs off the top.


5. Reduce clutter, be it of physical things or your time.

One of our 'first world problems' is the accumulation of stuff that takes up space. But many of things that occupy space where we live are for temporary enjoyment. I made a choice to ditch physical items for digital ones years ago, and I don't have books or DVDs following me around. Similarly, it makes sense to cut out activities, networks, people or habits that are a time suck for you and may have stopped adding value long ago. Whether it's closing accounts, unfriending, unsubscribing, or just walking away... if you truly miss it, you can always add those things back.

6. See things from another person's perspective.

It's easy, especially online, to divide into two directly opposing camps. What you like is amazing, and what the other person likes stinks. But it's often very interesting to see why someone has made a choice, be it where they choose to spend their time, what hobbies they enjoy, what apps they use or what mobile or computer operating system they've selected. It can't hurt to ask and understand before overwhelming them with your bias.

7. Recognize a lack of diversity hurts everyone, and work to solve it.

There is bias everywhere, obvious or unconscious. The results of generations of bias have led to dramatically skewed workplaces, city makeups, perceptions and manufactured realities. 2014 saw many tech companies open up about their own diverse makeups. Recognizing the issue is just the first step, and being comfortable with the status quo isn't acceptable.

8. Don't read the comments. And if you do, don't respond.

There's a bell curve when it comes to quality commentary, and the fringes of that curve are in charge of most active conversations, be it on mainstream media sites, popular discussion boards, or video networks. Practically every time, you lose brain cells by reading them, and engaging just makes you part of the mess.

9. Do something good for people who need the help more than you do.

Not everyone feels like they can give money to charity, but practically everyone has time. 2014 saw many of my friends get cancer. Another friend lost his 11 year old son to heart disease. Close friends suffered job losses, divorces and messy breakups. The world got Ebola. Adult problems can be a real pain. Find a cause or lend an ear to a friend that needs the help and always be there. The time you give is better than money.

10. Evaluate what you've always been taught and consider whether its true.

Much like bias can be taught from one generation to the next, so can half-truths and pure make believe, from pseudoscience to religion, political leanings and the latest version of history, depending on the author. Put two people in a room and ask them a direct question on a challenging topic, and you'll get wildly different answers. Find out why you'd state yours, and see if a little research could make you update your story.

Starting here, even if you can't get to them all, will have a big impact on you - online and offline, with health, with finance, and well being. You could give yourself a crazy goal that sets you up for disappointment, or you could just start with these. I'm working on each one and have a lot more to do. Good luck to you in 2015.

April 5, 2011

April 5, 2011 · 3 MIN READ · BY LOUIS GRAY

Did You Know All Your Emails Were In One Basket?

Did You Know All Your Emails Were In One Basket?


Prior to this weekend, most of your thoughts around the word Epsilon were probably about Greek fraternities or toga parties, but headlines in the tech and security world over the last few days have us instead associating Epsilon with a company most of probably never heard of before - a massive email marketing company used by many top brands. A major security breach seems to have escorted customer email lists from respected companies many of us interact with every day, and with the names piling up, I have to wonder if we had any idea that this centralization of our relationships with companies was happening, or if we are all the unlucky benefactors of outsourcing gone wrong.

The fun started late Saturday when I first got an email from TiVo saying my email address and first name had been exposed due to unauthorized access to their email service provider.

Of course, if you know me, that's no big deal. Everybody and every spider in the world knows my main email addresses are louisgray@mac.com and louisgray@gmail.com. Tough finding that out and combining it with my mysterious first name. You know I don't have too many issues around sharing my cell phone number either - this being a key focal point of a CNN.com article on the "death of privacy" back in December.

The String of Notification Emails

Modern anti-spam measures from both Apple and Google prevent most garbage from missing my in box. For more insidious emails, that fraudulently pretend to be something they are not, which is made possible from this breach, I am wary enough not to do anything foolish.

But, as many others soon found, the first notification of a breach was followed by a second, a third, a fourth, maybe more. The next two days saw more apologetic emails following the breach, from Best Buy, Hilton Hotels and Chase Bank, to name a few. The issue reminds me a bit of the Gawker hack in December that forced people to change their passwords everywhere, myself included. So now what's exposed is not just my email address and first name, but that many companies passed the buck by putting their customer lists in the hands of a single third party who wasn't prepared for such a responsibility.

(Of course, this single third party shrugged it off as impacting a 2 percent subset of their clients)

In the 8+ years I managed our company newsletter and mailing list, from 2001 to 2009, we used a variety of partners, including Responsys and GotMarketing. Later, we put our data into Salesforce.com, and never once suffered such a breach. But in the last few years, companies have gained the ability to self-manage one's database and marketing tools, and do so independent of other companies. There's no great reason that a single third party's mistake should open up the vault to such a bonanza of brands. What this specific failure does is expose that the type of multiple verification systems and complexity expected from us as consumers isn't followed quite as well at the very companies whom we trust to watch over our personal data.

I don't have any problem with putting my email address out there. I don't mind sharing my data with TiVo and Best Buy. I shrug at Hilton and have to trust Chase, or we're toast. But I have to think we're lucky this time that the type of data accessed was so relatively harmless. People are worried that this will lead to phishing attacks and later successful breaches that get more impactful information, but for now, it seems we'll be more annoyed than ever. But think about whether you knew that all of these companies were putting your data in one basket to be raided by one intelligent hacker...

Does knowing that all these brands stuck your data in one place make you feel less safe or more safe? I think we've got to have an alternative, and self-hosting with self-managed security is looking a lot smarter these days.

December 16, 2010

December 16, 2010 · 3 MIN READ · BY LOUIS GRAY

Gawker's Password Compromise Has Significant Aftershocks

Gawker's Password Compromise Has Significant Aftershocks


Gawker Media's security breach, exposing user e-mails and passwords for the network's many sites, is a mess. Not only were users' accounts uncovered, but the full database was later posted to the Web for anyone to dive through, for better or for worse, gaining the ability to find out affected users who had been exposed. Assuming that users often adopt the same password across multiple Web services, it is a safe guess many folks are on the list whose accounts elsewhere are now at risk.

It just so happens my e-mail address was included in this breach.

Using a public hashtable lookup and decoder, I found that my louisgray@mac.com e-mail address, and its corresponding Gawker password, was exposed in the attack. Not a good thing. But the good news is that after the late summer's issues of dealing with a fraudster, and changing all my passwords in many places, I'd already protected myself against this particular password escaping.

LinkedIn Forced a Password Reboot

But my work seems to have been in vain in some respects. First, my LinkedIn account was disabled. It turns out in a proactive move, the company forced all users who had accounts that matched the unveiled e-mail addresses to redo their passwords. In parallel, my Mac.com e-mail, used on Gawker, was disabled by Apple. This story hasn't been revealed in the press, so far as I have seen, and it's quite possible Apple similarly proactively disabled accounts named in Gawker's documents.

Apple Reset My Password As Well, Even Though it Was New

So, once again, I found myself changing my password on my main account with Apple, after proving through a set of online hoops that I was actually me. And again, for the second time in a few months, I am reconsidering my password strategy, and wondering if the time has really come to use services like OpenID and OAuth to avoid the obvious problem of creating unique IDs for every site.

I have no clue how many times I've left comments on Gawker sites. I'd bet it's less than five times. And in exchange for this small number of posts, my LinkedIn account and my MobileMe account are sporting new passwords, while I think in my head of other places the old password may still be alive, susceptible to open hackers who want to take over my digital IDs.

From the tech coverage of the breach I have seen, it looks like Gawker got sloppy and they paid for it. More specifically, all of us impacted have paid for it with greater levels of annoyance and needing to reconsider how we approach our online permissions. I've given my user name and password pairs out to so many sites by this point, it's practically guaranteed the bad data is out there somewhere, on servers owned by companies much less aware and proactive than LinkedIn and Apple.

Gawker screwed up and it's a very major, visible mistake which can't happen too often before site users start to turn a blind eye to registrations, and move on to alternatives. If I can't sign in with my Google or Twitter ID at this point, I don't think I want to add yet another ID that may just fall victim to smarter hackers in the future.

October 17, 2010

October 17, 2010 · 5 MIN READ · BY LOUIS GRAY

Life Online: Fraud, Security, Trust, Passwords and Paranoia

Life Online: Fraud, Security, Trust, Passwords and Paranoia


Occam's Razor has an intriguing two parter, penned over the last week, about how deceitful people are mining Facebook for your personal data, taking advantage of open networking and random connections to possibly use what they discover, via your open door policy, in nefarious ways. The gist of the articles? Be extremely careful who you connect to, and say no to strangers. (See: Friending Strangers On Fakebook and its follow-up: The Cindy In Your Town)

This approach, as smart as it sounds after reading both pieces, runs contrary to one of the more widely held positions in social media, that the friend connection around the corner could be the one you most want to know. Take Thomas Power's comments on limited networks being 'flawed' as a great example of someone who believes in making as many connections as possible on all networks. Many of us do this. That's one reason why there are autofollow scripts for Twitter, and why many people complain about Facebook only allowing 5,000 friends, when it's unlikely you care about their every coming and going.

I've long taken an extremely trusting approach to the Web. I chose to accept all friend connections in Facebook quite a while ago because I don't want to dictate where people want to find my stuff. If they are more comfortable in Facebook or Twitter or Google Buzz or anywhere else, that data should be there. I've taken to using Foursquare for location, and I share many of my purchases via Blippy. I even have made real photos of my own kids as part of my presence online. There are few secrets.

Some might think this approach stupid - an inevitable march toward a mistake waiting to happen that puts my data, my money or my family in jeopardy. Finally, late this summer, something did happen, but not for the above reasons - try as I might to link them.

The first sign something was wrong was when I received an e-mail from Amazon.com that shut my account outright. You might remember my post on the issue: "To Protect Me, Amazon Has Decided to Kill Me". I had hoped it was a red herring, an oddity that was not to be repeated. But it was just the beginning of a data tug of war that made me somewhat nervous, but mostly frustrated.

At first, only Amazon was impacted, but the very next day, I got another odd order, from Zappos, saying a set of steak knives I had ordered was on its way. I canceled it immediately, and thought that maybe Amazon and Zappos' shared corporate control indicated a database surprise. They told me this was not the case. Then, as I was on the phone with Zappos, discussing the issue, I got an e-mail from TurboTax, saying I had requested the User ID associated with my e-mail.


Nice Try Getting Back Into My E-mail, Jerk


That's a big no. Of course not. So I sighed in defeat, and immediately started changing my passwords everywhere I could think of - starting with TurboTax, a mere 2 minutes later. Like most people, I have a small set of passwords I use for most accounts. I had been careful enough to change it up for the most financially impactful sites, but my most commonly used password hadn't been changed since I first started using it in college - back in 1996.

A few hours later, I got a note from Apple saying too many attempts had been made to answer my security questions on my e-mail account, and therefore, the password could not be changed. This told me that for some time, the hacker had access to my e-mail account, and had correctly guessed my password worked on other sites (like Amazon). When I changed it, I had effectively locked them out. But there was one place I hadn't looked yet, an obvious place... a commerce site directly linked to my Apple account.

I logged into the Apple Store (with my new password) and saw the joker had successfully ordered a Mac laptop and a Canon camera, both shipped overnight by FedEx, using my account. The total damage was just over $2,000. The thief had used my first and last name, and my cell phone number, but not any of my credit cards. In fact, the shipments were even sent to Sunnyvale, the same city where I live, but obviously not to me.


I Hope The Thief Enjoys His Laptop


After setting a fraud alert on my credit cards, I checked all activity on said cards practically every few hours for weeks, and saw no change. My credit score didn't get impacted, and I never heard from the thief again. I called Apple to have them check into a MobileMe breach, and they put a watch on my account. I reported the issue to the FBI's hotline, only to get a form letter saying they probably wouldn't follow up. Even a call to the local Sunnyvale police came up empty, when they said the defrauded merchant had to be a Sunnyvale shop to get any help.

As you can guess, this was completely frustrating. I still have no idea how my e-mail address was compromised, or how the thief got hold of my commonly-used password, which they then leveraged to get into other accounts. The good news is that my identity wasn't truly coopted, and no charges ever hit me directly. But it certainly put some mud on my otherwise clean view of the world.

So think about how we are sharing and possibly oversharing? Our social updates from mobile phones can now track our location down within a few feet. Is that not valuable to people who want to know where we live and where we go? Do we need to give people an extra boost to find data that doesn't belong to them? I believe strongly in trusting people and getting my data on the Web, and am happy to know that none of my use of these networks set the would-be disaster in motion. But Occam's Razor is onto something as well. Are we doomed if we are careful and doomed if we are not?

I don't mind the lesson on keeping my passwords hard to crack and change them often, but should I raise my paranoia meter thanks to this experience?

August 7, 2010

August 7, 2010 · 4 MIN READ · BY LOUIS GRAY

To Protect Me, Amazon Has Decided to Kill Me

To Protect Me, Amazon Has Decided to Kill Me

For the amount of transparency I put online, combined with my preference to purchase things online wherever possible, I have to count myself lucky that nothing nefarious has ever happened to my data. I have never seen false orders on my behalf, been a victim of identity theft, had to cancel accounts and change passwords everywhere, cut up credit cards, or reverse charges due to anything related to my Web use, so far as I can recall. It's possible that winning streak came to an end this last week, thanks to a flag from Amazon, saying that my account had been suspended immediately, due to suspected fraudulent activity. Rather than take their good advice, I am instead hoping I can prove all is well, and the mistake lies with them. Foolhardy, I know, but worth a shot.

I have e-mail receipts of activity from shopping with Amazon.com spanning for more than a decade. Even though I don't use the site as much as I used to, no longer buying books (as I once did regularly) or CDs (long since replaced by iTunes, Spotify and others), the idea of the account getting zapped, and needing to start over with all-new personalization and buying history, seems odd. I am something of an Internet account packrat, and I like the consistency. And even if it seems naive, I still doubt somebody got enough data to make an order on my behalf - as no other account, anywhere, shows one micron of suspicion.

The odd behavior with Amazon started at the end of last month, I bet. When I moved across town, I changed the address associated with my VISA card. Later, I went to Amazon and changed it there as well, including on my Amazon Wish List, which I typically look at a mere once a year, just before Holidays.

A week later, on August 5th, I got an odd e-mail, which was so text-heavy and non-interesting I almost dismissed it as a phishing scam. Entitled "Account Closure: Please Read", the e-mail explained:
"After careful review of your account, we believe it may have been accessed and used by a third-party to place order(s) without your permission. It seems that someone obtained your personal account and/or financial information elsewhere, and used it on Amazon.com to access your account.

We have closed your Amazon.com account effective immediately because of this possible unauthorized account activity. If this recent account activity (HP Pavilion dv6-3010us 15.6-Inch Laptop) was authorized by you, please reply to this message as soon as possible and we will reactivate your account."
Anybody who knows me knows there is no way I would by an HP laptop. Not for me, not for a friend, not for anyone I actually cared about. So it's obvious something is amiss. After checking the message's details and ascertaining it really had come from Amazon.com, I tried to login to my account, and couldn't get through. It really had been closed after all!

Morbidly curious, I checked activity on the credit card associated with the account, and found nothing weird. Similarly, no other account had a hair of concern associated. Every notification from Blippy could be traced to myself or my wife, and Chase, ETrade and Wells Fargo all came back clean. This only reinforced my thought Amazon goofed somewhere. So I reached out this week to follow up, and there's still a ways to go to finding out the truth.

Amazon makes it hard to reach anybody by phone on their site. Clearly with their scale, they want to avoid inbound calls, if possible. To get there, you have to hit Help, find the Contact Us button, and "Sign In to Contact Us". Of course, I couldn't sign in. Duh. So I clicked to skip sign in and found another set of questions to fill out to describe my story. Again, thwarted by tech, I could only put about 100 characters of description to explain. Try that. It's harder than it sounds.

Needless to say, I made it through and the young woman on the line couldn't solve my issue. There's simply no account assigned the e-mail address any more. After a decade's time purchasing on Amazon with the same ID and having them know me as well as they do, I'm locked out.

I completely understand their wanting to protect me as a customer, and stop problems before they start, but something is amiss. If my credit card data were truly compromised, would I not see spending somewhere else? What do you think? Should I convince Amazon they screwed up and get my account on, or should I start canceling and changing passwords everywhere? Either way, whether it is their fault or not, I don't think I will be shopping at Amazon very often going forward. It's a result of unintended consequences.

April 25, 2010

April 25, 2010 · 4 MIN READ · BY LOUIS GRAY

Why I Trust Blippy, Mint and Others With My Financial Data

Why I Trust Blippy, Mint and Others With My Financial Data

In an up and down week for the startup, Blippy gained a huge amount of unwanted attention on Thursday and Friday as it was discovered that four (and eventually five) of the company's users saw their credit card numbers exposed, in full, through creative Google searches (since removed). As somebody who has registered my credit card and debit card with Blippy, you might think my knee-jerk reaction would be to pull out my data, but it's not, and I am just as supportive of the creative site for sharing transactions as I ever have been. I will continue to encourage people who want to share this activity to use the site, and I am not any more shy about putting my data into their product than I was before. Similarly, I will continue tracking all my data on Mint.com and other sites, because these companies and others like them, have proven themselves to be trustworthy and innovative - delivering me real value.

I joined Blippy in January largely because as I have been participating in and advocating sites that tell people what we like for years, Blippy takes the next step and tells people what we actually purchase, going beyond the "like". I have watched Blippy expand its social capabilities, as you can follow friends, have conversations on transactions, and see groupings of similar behavior, seeing who is buying from specific vendors, or even finding out if other friends are buying the same things you are.

My Credit Cards Go to Blippy Automatically. Zero Concerns.

Unlike some users of the site, I opted to go "All in" with Blippy, sharing not just my soft accounts, like Zappos and iTunes, with the service, but all my purchases. That means you see the boring fillups at Chevron on my debit card, my cash withdrawals from the ATM, and yes, even my wife's Teletubbies DVD rentals on Netflix for my kids to watch. I did this because for much of what I do, I am living life in public. I believe in sharing as much as possible, partly demonstrating that there is little to hide. And while some of my transactions are boring, that's just who I am.

When it was reported this week, by VentureBeat, who, from my understanding, worked on the story for a few days before issuing their initial story, that some cards were exposed, it was quickly shown to have been a limited bug, related to early beta users using a specific card from a specific bank - and was completely out of the ordinary. Blippy quickly responded to the issue, and worked publicly with Google to solve the issue, keeping all of us informed, if we were nervous. (I wasn't)

Mashable's Typical Approach to News Reported by Others

Meanwhile, you saw the typical tech press pile-on from people who had done no original research, flocking to the story like youths at a soccer game chasing a ball, as blood in the water can be exciting. But VentureBeat calmly and professionally kept the story updated, while the Blippy blog did the same, open and with considerate remorse.

There is a huge difference between making a mistake and being untrustworthy - and for me, putting my card data in Blippy is not dissimilar to putting my credit card data into Mint.com, having Intuit find my W-2 data come tax time, or entering my credit card information over and over and over from e-commerce site to e-commerce site. In order for Blippy and Mint.com and these other businesses to succeed, they need to ensure the safety of users' private data, and practically without exception, they have done so. The companies' success will come through their amassing a high number of users, and being able to report trend data based on groups and demographics, not on individuals - and thus, it is in their best interest to keep your data safe and secure.

Google Makes Their Role In Fixing the Issue Clear

ReadWriteWeb chronicled some of Blippy's response to the slip-up today, when they said what to do when a PR disaster strikes your startup. Blippy did the right thing by all accounts, apologizing, making full disclosure, and reporting how the issue was being addressed. Meanwhile, Google's Matt Cutts took to Twitter to explain what that company had done to fix the issue also. That's transparency and a closed loop response.

If I had more options to share even more data with Blippy, I would do it, and getting my e-mailed updates from Mint.com is among the highlights of this data-driven geek's week. It benefits the Web at large to get more real data about our purchases and activities public, and Blippy is one of those making the process interesting. I trust them with my information, and won't be changing a thing. You can find all my data here: http://blippy.com/louisgray.

March 17, 2010

March 17, 2010 · 1 MIN READ · BY LOUIS GRAY

Twitter Tightens Security With Encryption Expert Hire

Twitter Tightens Security With Encryption Expert Hire

On Tuesday, Twitter added computer security veteran Bob Lord to the company's expanding employee roster as the manager of network and infrastructure security, bringing with him 20 years of experience focused on electronic security systems at large companies, most recently including Red Hat, AOL and Netscape. Highlights in Lord's background include his building security and encryption features into the Netscape browser, iPlanet servers (an alliance with Sun and Netscape) and the AOL Communicator product, which also included Mail, Address Book, Instant Messenger and Calendar. Since leaving AOL, Bob has worked with a team of cryptography experts to add security features to many projects including FireFox, Mozilla Thunderbird and Red Hat Linux.

Bob's LinkedIn profile shows praise from colleagues who gave him credit for ensuring successful releases of complex application suites at AOL, as well as his being recognized as a "visionary" with energy and intensity, while at RedHat. Bob is also a patent-holder for his development of temporary digital certificate proxies that can be used for a specific amount of time.

The Obligatory "First Tweet" from the Mothership.

As Twitter's Web site and activity become more critical in the way the planet is communicating, so to will its need increase for security to protect that which is private to remain private, and enable accounts to be secured. It's also not unexpected that the company's core offerings will get increasingly complex - maybe not to the level of AOL Communicator, but expanding nonetheless.

We should be seeing what Bob will be bringing to the Twitter team over the next few years, or just keep tabs on his updates at @boblord.

November 26, 2009

November 26, 2009 · 2 MIN READ · BY LOUIS GRAY

Is There a Looming Battle Over OAuth's Successor?

Is There a Looming Battle Over OAuth's Successor?

The OAuth protocol, used on many popular Web sites and applications to pass your credentials between sites without requiring the entry of your user name and password, including Twitter, is potentially under pressure from a team of techies representing Microsoft, Google and Yahoo!, who have introduced a competing specification interpreted as being aimed to succeed OAuth, called Web Resource Authorization Protocol, or WRAP. Eran Hammer-Lahav, the Director of Standards Development at Yahoo!, who helped coordinate many OAuth contributions, and created a formal specification for the initial OAuth standard, recently panned the move, saying, "The road to hell is paved with good intentions," adding his own proposal for OAuth 2.0, which he hopes will better separate between authentication and authorization.

Today's OAuth standard is known to have its imperfections. Hammer-Lahav notes in his 2.0 proposal that OAuth is essentially "unusable" for mobile devices or installed apps, and also suggests that OAuth "does not adequately support large providers". But he says the move to create WRAP has confused developers' focus, and diverted resources, calling it "just one illustration of the demise of the OAuth community".

But his opinion, unsurprisingly, is not universally accepted. David Recordon of Facebook, also on the boards of the OpenID and Open Web Foundations, states in the comments of the post that Facebook is not supporting OAuth 1.0 as it is simply too heavy - requiring a massive increase in HTTP requests, also adding that other developers find OAuth "too difficult to correctly implement".

David followed on to his initial comments with a post to the IETF mailing list, which you can see here: Facebook, OAuth, and WRAP. In the note, he highlights the belief that the proposed WRAP alternative maps well to the company's current authentication process, adding WRAP simplifies the development community's learning curve.

The discussion, which is ongoing, may end up splintering development communities between sticking with the current version of OAuth 1.0, looking at WRAP as an alternative, or trying to support a new OAuth 2.0, as specified by Hammer-Lahav. But if you have wondered why Facebook Connect acts one way and Twitter OAuth acts another way, it's because they are different approaches entirely. If this discussion is any indication, one can expect there to be continued divergence, rather than a single way to deliver user authentication and authority between sites and applications in the future on the Web.

For another viewpoint on this broad topic, see Jesse Stay's post: The Future Has No Log In Button. Also, DeWitt Clinton of Google, on FriendFeed, says the open discussion "is good".

October 8, 2009

October 8, 2009 · 1 MIN READ · BY LOUIS GRAY

Benchmark Capital's Twitter Gets Hacked to Hawk Plasma TVs

Benchmark Capital's Twitter Gets Hacked to Hawk Plasma TVs

Benchmark Capital had a string of profitable exits earlier this summer, culminating in a big day that saw FriendFeed sold to Facebook and SpringSource acquired by VMware on the same day this August. The firm is among the most respected in Silicon Valley, and a leading name on Sand Hill Road.

That's why I was more than a little surprised tonight to see Benchmark's official Twitter account start to spout promotions for flat-screen TVs. Not only did it look fishy, but it was done "from API", while all updates on the account to date have been "from Web", which indicates that the activity took place automatically, and not by hand.



VCs Typically Promote Their Funds and Portfolio, Not TVs...

Whether one of Benchmark's multiple Twitter users accidentally clicked through to some phishing scam, or if some bot just managed to get lucky, is unknown, but it looks like the damage was undone relatively quickly. That there are malicious characters out there trying to hack into Twitter is no surprise, but it's always eye-opening when a big name gets caught. Maybe it's time they change their password.


To be fair, many other accounts look to also have been compromised by this "Free Plasma" bot. See Twitter Search for many more affected.

April 30, 2009

April 30, 2009 · 1 MIN READ · BY LOUIS GRAY

Twitter Admin Screenshot Leaks Reveal Internal Data

Twitter Admin Screenshot Leaks Reveal Internal Data

Zee of TheNextWeb relayed a hacker's posting of screenshots ostensibly taken from Twitter's administration interface, available only to select employees within the company. The handful of screenshots display some interesting details in terms of Twitter's internally set limits, the controversial "featured users" lists, and yes, details from some celebrity accounts, including who is blocking who.

The screenshots, which can all be found in the article, Screenshots of Twitter’s Admin. Take a look a look behind the scenes, reveal what user accounts look like from an administration perspective, including a log of dates passwords were changed, when accounts were opened, last used IP, and yes, details on updates, API limits, followers, and direct messages.

Looking at the data shows limits beyond the much-reported 1,000 new users to follow per day, including:
  • A 126 update per day limit
  • A 250 direct messages per day limit
  • A 1,000 favorites per day limit
I question the update per day limit, as I would guess some people do run into that number, but it was consistently labeled across accounts, including those from @britneyspears and @aplusk.

The leaked screenshots also reveal there are, as of the time of publishing, 187 featured users of Twitter, that not only includes celebrities like Shaquille O'Neal and MC Hammer, bloggers Pete Cashmore and Michael Arrington, but Twitter employees, and "Jason Scott's Cat", who can be found at @sockington, with 424,000 subscribers.

Really. A cat has 424,000 subscribers, but you can't follow more than 2,000 if fewer than 1,800 or so are following you. Got it.

On the individual level, the leak shows that the @BarackObama account is blocking nearly 100 users, while Lily Allen and Ashton Kutcher both block Perez Hilton. In contrast, Britney Spears doesn't block anyone, but is blocked by 3,855 Twitter users. Amusing.

Go check out the article at The NextWeb to see all the screen captures.

March 29, 2009

March 29, 2009 · 2 MIN READ · BY LOUIS GRAY

iPhones Can Protect Your Warcraft Account, and Someday Much More

iPhones Can Protect Your Warcraft Account, and Someday Much More

By Daniel J. Pritchett of Sharing at Work (FriendFeed/Twitter)

Two recent iPhone stories highlight some interesting potential for Apple's iPhone and iPod family.  First up is WoW Insider's announcement of a free iPhone Authenticator available in the app store for securing World of Warcraft accounts.  A Battle.net user is typically a World of Warcraft player but the accounts can be tied to any Blizzard game you might own, including their future releases.

As shown in the screen shot on the left, the Authenticator program generates a new string of numbers once every minute or so.  Once a player links the authenticator to an account, these numbers must be supplied along with a user name and password at each login — a two-factor authentication challenge.  This iPhone app is an alternative to the existing solution where gamers can pay Blizzard $7 for a key fob that generates a similar passkey every time its button is pushed.

World of Warcraft characters and items are regularly hijacked via targeted trojans and keyloggers.  They can be stripped bare in a matter of minutes, their contents flipped quickly for tens or even hundreds of dollars on WoW's thriving grey market.  Given the time and effort involved in securing an account rollback from Blizzard customer service, many players will opt for the peace of mind granted them by this new application.

The next iPhone may read fingerprints and retinas

The second tidbit comes from Apple Insider (via Engadget): An Apple patent filling hints at fingerprint and retina scanning potential in future iPhones. Apple is researching the potential for embedding biometric scanning devices (cameras, etc.) behind the touch screen of an iPhone.  Such enhanced iPhones would allow for secure identification in order to unlock the phone itself.  These enhancements would also allow the iPhone to serve as an easily obtainable high-powered authenticator for other systems such as Blizzard's Battle.net.  While we might only imagine such tools as being necessary for sensitive operations like banking or remote logins to corporate intranets, the Blizzard app demonstrates that it can be cost effective to secure our less critical digital holdings.

The Blizzard authenticator is a great example of high-powered security applications that the iPhone family can provide right now, and the recent patent filing by Apple gives us insight into other uses for tomorrow's iPhone.  We'll certainly have the mobile available as an ever-more-secure authentication tool, but we'll also be able to use it as a remote sensor for home and office medical purposes such as the recently promised glucose monitor or a biometrically secured retail barcode scanner.  There are undoubtedly more possibilities than I can come up with on my own, and I look forward to seeing some of them becoming reality in the near future.  If you've got a great example of alternate uses for mobile phones, please share it in a comment!

Read more by Daniel J. Pritchett at Sharing at Work

March 27, 2009

March 27, 2009 · 3 MIN READ · BY LOUIS GRAY

False Alarm on Credit Fraud Solved by My E-mail Hoarding

False Alarm on Credit Fraud Solved by My E-mail Hoarding

This evening, my wife handed me the phone, saying "It's Chase bank. They say there is suspicious activity on your account and to call them." Having never run into issues with fraud or identity theft, I've been lucky so far, despite liberally spreading my credit card details all over the Web, in a myriad of e-commerce sites and online services. With our recent travels, and my wife's own activity on the card, I thought there was a good chance this would be a false positive, which it was, but I came extremely close to canceling my card, and would have, had it not been for my often-mentioned e-mail pack rate behavior.

When I called into the fraud center, after identifying myself, the automated voice asked about some "odd" activities - one from a "record store" and another from an online eMarketing firm. Both sounded odd, so I ended up with an operator. As she explained to me, the "record store" was actually Apple's iTunes, to the tune of $.99. No problem. But the other one? It turned out it was based in South Africa, and had charged me $1.07. That was an odd number, but small, and I didn't recognize the firm. It sounded like "Quirky Marketing" or "Quirk iMarketing". Something...

When I said I didn't recognize the name of the service, the operator strongly advised me to cancel the card immediately. But I wasn't so sure. There was still the possibility I had made a mistake, and $1.07 didn't seem like a big deal. She again pushed me to cancel the card, saying if somebody in South Africa had my data, the next purchase could be a big one.

I asked her not to cancel the card, but after asking people on Twitter what they thought I should do, and seeing a near-unanimous response that I should follow the bank's advice, I was feeling like my smug naivete was going to catch up to me.

Searching Google for the firm name I thought she had mentioned found nothing memorable. And the South African connection sounded very weird. But there was one last place I could look - in my e-mail. As mentioned many times, I've saved practically all my useful e-mail going back more than a decade - making it an extremely deep personal database. So I searched for the term the woman had mentioned on the phone: "Quirk".

It turned up an e-mail confirmation from Quirk eMarketing from September 2008, for a product I had checked out called "BrandsEye". BrandsEye I would have remembered, but the "Quirk eMarketing" I'd largely forgotten. Their site left much to be desired, but my e-mail showed I'd signed up to a service that would charge 7 South African Rands a month to monitor online mentions. Depending on the exchange rate, one month's bill would be $1.01, and another would be $1.07. And while that didn't trigger any fraud alerts in September through February, today, it did. (Likely due to some other activity my wife initiated)

When I had gotten the online confirmation of my purchase back on September 28th of 2008, I moved the e-mail to my "Commerce" folder and saved it. I didn't know if I would ever need it again, but today, it came in extremely handy, and I won't be canceling my credit card. Phew!