This is the scariest thing I have read since spring 2018:
https://hackernoon.com/im-harvesting-credit-card-numbers-and-passwords-from-your-site-here-s-how-9a8cb347c5b5
written by @david.gilbertson.
It pretty sure what he describes is actually happening, has been happening before he described it and will be happening going on - just obviously not in the named module. The ecosystem of Node modules is so vast and so unstable that considerable number of project do not do enough to catch behaviour like this.
You know the drill: open browser, new tab, type 'www.facebook.com' and in moment you can see who of your online buddies is up to something interesting. This is exactly what I did. Only I did not end up in well known Facebook page, but on something really fishy:
This is definitely NOT facebook. How come I ended up on 'quiz.us' site when I typed in www.facebook.com. Or did I ? Let's do it again:
no, not because of the memory it takes or CPU cycles burned (does not really matter when you have 4 GB notebook with Core2Duo).
Few days ago, a good friend from old country (well, technically not anymore as he also moved within the EU) made me aware of this presentation "Silver Needle in the Skype" (link points to fairly large PDF file) by Philippe Biondi, & Fabrice Desclaux.
To fully digest and fully comprehend the content requires way more time than I am willing to invest - and to make meaningful arguments for or against conclusions does require much deeper special knowledge. It is interesting view into the deep internals of how Skype works and also provides very interesting references to tools available for this kind of exploration. I am not going to stop using Skype just because there is a chance that Skype could possibly be a backdoor or something not so innocent. There can be after all perfectly honest reason for all the obfuscation and anti-disassembling measures - to protect the IP against competition. Or it can be in order to hide something else ? We will probably never know.
The combination of software allowing anonymous access to the Net, not too competent police officers and laws not quite 21st century ready can be a very dangerous combination. According this story, the operator of the Tor node was arrested by German police ...
I am quite curious how be would situation like this handled in Canada. First of all, would it happen ? Would the RCMP be more technically up to date than Deutsche Polizei ? What defines the responsibility of an operator of server, that moves encrypted content ? I am not crazy enough to try it out just to find out :-) - so no, I will not setup a TOR node (even if I do admire this cleverly designed piece of software).
It's been over 10 months since we have started to seriously use virtualization and run Windows inside virtual machine to ease installation and configuration pain. It starting first as convenient measure of isolation two different development environments (.NET 1.1 based and .NET 2.0 based) and avoid "crosspolination" in the data analytics project. At that time, my expectations what would be the limits of what you can or cannot do in virtual environment were mostly around performance, responsiveness and device support (USB especially). As it turned out, all of that actually worked much better than I have ever expected. With new versions of Parallels, the performance is very good and user experience (user means fellow developer) is barely noticeable difference against developing on host system. Assumed that you have decent dual-core system with 2 GB of RAM, of course. Using Parallels gives you the added benefit of moving the virtual environment between Windows, Mac and Linux hosts, which is very convenient.
Today I have started the walking season 2007. I did some gentle preparation during the week - few short, 4-5 km strolls around the neighbourhood, but it was today when I really started. It was beautiful day in Ottawa - sunny, temperature around 8-10, so I took off and did 12 km loop through Westboro, down south and around Dow's Lake up to downtown. Just fantastic. The companion on the road were Security Now! - I was behind few episodes, but I managed to listen to almost full 3 episodes.
If it ever happens to you that you need to restart old computer which you have not logged on for 2-3 months and you find out you have no clue what the password could be, do not panick. Exactly this happened to me yesterday. Fortunately I have remembered reading something on lifehacker few days ago about bootable CD which contains live Linux distribution with password cracking open source software Ophcrack. It runs from CD only, does not touch your file system, only loads local SAM and tries cracking the hashes. And boy, it works !
Today's topic is dealing with sensitive information - such as logins, passwords, PIN numbers, credit card numbers and so on.
Up to last week, I was using the SplashID software to keep everything worth securing secure. I started to use SplashID back in 2001 when I bought the Palm based Sony Clie SJ30 (as replacement for wonderful Palm IIIxe). The Palm based program came with desktop counterpart that allowed editing of entries. Later in 2004 when I switched to Pocket PC, I simply purchased Windows Mobile version of the same software.