LGF

more options

  

Advertisement

Scary Internet Security Story of the Day

Thu, Aug 7, 2008 at 1:22:56 pm PDT

The serious bug discovered recently in most of the world’s DNS servers has even greater implications, according to security expert Dan Kaminsky: Major Internet security flaw also affects e-mail.

LAS VEGAS - A newly discovered flaw in the Internet’s core infrastructure not only permits hackers to force people to visit Web sites they didn’t want to, it also allows them to intercept e-mail messages, the researcher who discovered the bug said Wednesday. ...

Dan Kaminsky of Seattle-based security consultant IOActive Inc. exposed a giant vulnerability in the Internet’s design that, in one case, allowed hackers to reroute some computer users in Texas to a fake Google.com site loaded with automated advertisement-clicking programs, a scam to generate profits for the hackers from those clicks. The flaw wasn’t in the site itself, it was in the back-end machines responsible for guiding computers to that site.

The vulnerability Kaminsky found is especially insidious because it allows criminals to tamper with machines whose reliability and trustworthiness is critical for the Internet to function properly. ...

While some details leaked out early — security researchers accurately guessed parts of Kaminsky’s discovery — he was able to keep a few juicy bits secret until the talk.

One of those was the susceptibility of many e-mail servers to the DNS vulnerability, an opening that gives criminals a way to plant themselves in the middle of the transmission from the sender to the recipient and redirect messages to their own servers, Kaminsky said. The result: criminals have a way not only to comb through the contents of those messages, but also to gain access to other password-protected Web sites the victims belong to.

That’s because most sites have a feature that allows members to retrieve their passwords by e-mail if they’ve forgotten them. If a criminal has access to the account where that message is sent, he can then begin snooping on the contents of that account, from e-mail, to banking, to retailer sites.

Advertisement

136 comments

  • Comments are open and unmoderated, and do not necessarily reflect the views of Little Green Footballs.
  • Obscene, abusive, silly, or annoying remarks may be deleted, but the fact that particular comments remain on the site in no way constitutes an endorsement of their views by Little Green Footballs.
  • Posts that contain phone numbers, street addresses, email addresses or other personal information will also be deleted, as will posts that consist only of a variation on the word, "First!"
  • Comments that advocate violence will be cause for immediate banning with no appeal.
  • Disagreement and debate are welcome, but insults and abuse are not, and may cause your account to be blocked.
  • REMEMBER: posting comments at LGF is a privilege, not a right. Abuse that privilege, and your account will be blocked.

Hide comments | Jump to bottom

1 eschew_obfuscation  Thu, Aug 7, 2008 1:26:42pm

Aw, just shut down the DNS servers.....make everyone use IP addresses!

Problem solved ;-)

2 Mars Needs Neocons  Thu, Aug 7, 2008 1:26:44pm

OMG, this is a nightmare. How quick will this get patched up?

3 faraway  Thu, Aug 7, 2008 1:26:56pm

Behead those who hack our DNS

4 karmic_inquisitor  Thu, Aug 7, 2008 1:28:23pm

TCP/IP - protocols for the dustbin?

5 reloadingisnotahobby  Thu, Aug 7, 2008 1:28:45pm

Just because your paranoid don't mean they're not hacking you!

6 Kosh's Shadow  Thu, Aug 7, 2008 1:28:53pm

Then there's the "CNN Top Ten" spam that directs you to sites to download malware pretending to be a Flash player.
In plain text, the links are valid; it is only in HTML that the misdirection shows itself, and you have to be able to read HTML and view the source to tell.
And then let it install the fake flash player.
I've found Verizon's spam filter catches it, but I viewed the source anyway, determined what it was, and deleted it. I've since gotten two more; they just get deleted.

7 eschew_obfuscation  Thu, Aug 7, 2008 1:28:54pm

New protest poster:

"DNS IS DEAD"

/disaffected hippie

8 reloadingisnotahobby  Thu, Aug 7, 2008 1:30:26pm

re: #2 Mars Needs Neocons

Guilty conscience there Mars?
LOL

9 NoSubmission  Thu, Aug 7, 2008 1:31:03pm

OT
They call this news?
Obama Orders Pancakes to Go

10 Sharmuta  Thu, Aug 7, 2008 1:31:19pm

I blame al gore. It's his internet after all.

11 Mars Needs Neocons  Thu, Aug 7, 2008 1:32:52pm

re: #8 reloadingisnotahobby

Guilty conscience there Mars?
LOL

LOL
This is not the redirect you are looking for, move along.

Seriously, this means that at present no information is secure as long as it's in transfer.

12 Mars Needs Neocons  Thu, Aug 7, 2008 1:33:38pm

re: #9 NoSubmission

OT
They call this news?
Obama Orders Pancakes to Go

Of course its news. They were out of waffles.

13 Occasional Reader  Thu, Aug 7, 2008 1:33:57pm

re: #9 NoSubmission

OT
They call this news?
Obama Orders Pancakes to Go

Anything involving Obama and hot breakfast foods is news, didn't you know that?

14 karmic_inquisitor  Thu, Aug 7, 2008 1:34:27pm

re: #9 NoSubmission

OT
They call this news?
Obama Orders Pancakes to Go

He could fart and say "excuse me" and it would be "The Political Play of the Day".

15 karmic_inquisitor  Thu, Aug 7, 2008 1:35:03pm

re: #10 Sharmuta

I blame al gore. It's his internet after all.

Good point.

16 Sharmuta  Thu, Aug 7, 2008 1:35:54pm

re: #15 karmic_inquisitor

Taking the credit has it's downside too.

17 looking closely  Thu, Aug 7, 2008 1:36:14pm

Yikes

18 buzzsawmonkey[deleted]  Thu, Aug 7, 2008 1:36:40pm
19 nyc redneck  Thu, Aug 7, 2008 1:36:54pm

re: #9 NoSubmission

OT
They call this news?
Obama Orders Pancakes to Go

it is news. he has flip flopped on waffles.

20 karmic_inquisitor  Thu, Aug 7, 2008 1:36:56pm

re: #11 Mars Needs Neocons

LOL
This is not the redirect you are looking for, move along.

That borders on "That is not the DNS hack that I knew".

21 maddogg  Thu, Aug 7, 2008 1:37:16pm

There is an excellent reason to let the governments control the WWW.


/not

22 Barry the Baptist  Thu, Aug 7, 2008 1:37:41pm

Let's put big govt in charge- they can fix anything!

23 eschew_obfuscation  Thu, Aug 7, 2008 1:38:10pm

re: #19 nyc redneck

it is news. he has flip flopped on waffles.

What'll happen if he has an omelet?

24 NomadOfNorad  Thu, Aug 7, 2008 1:38:18pm

re: #12 Mars Needs Neocons

Of course its news. They were out of waffles.

Uhhhmmm.... They're never out of waffles! :D

25 opinionated  Thu, Aug 7, 2008 1:38:30pm

If it's not Islamics we have to worry about all the time, it's the criminal degenerates on-line.

I'm sick of it.

26 Cygnus  Thu, Aug 7, 2008 1:38:35pm

re: #9 NoSubmission

OT
They call this news?
Obama Orders Pancakes to Go

In memory of Rachael Corrie.

27 Gordon Marock  Thu, Aug 7, 2008 1:38:38pm

How do I know that I am really posting this comment to LGF? Any response "Charles"?

28 Killgore Trout  Thu, Aug 7, 2008 1:38:46pm

re: #9 NoSubmission

Luckily the press was there to record the historic event.

29 karmic_inquisitor  Thu, Aug 7, 2008 1:39:08pm

re: #21 maddogg

There is an excellent reason to let the governments control the WWW.


/not

re: #22 Barry the Baptist

Let's put big govt in charge- they can fix anything!

Most any techie see the wisdom in keeping the internet out of government hands. So why are so many of them Democrats? I have never understood it.

30 buzzsawmonkey[deleted]  Thu, Aug 7, 2008 1:39:13pm
31 Barry the Baptist  Thu, Aug 7, 2008 1:39:33pm

re: #9 NoSubmission

OT
They call this news?
Obama Orders Pancakes to Go

Were the pancakes halal?

32 looking closely  Thu, Aug 7, 2008 1:39:56pm

Making its way around the blogosphere (mentioned here before, of course). And LGF gets mentioned by name:

Liberal blogs ten times as profanity-laden as Conservative blogs.

F'in A!

33 karmic_inquisitor  Thu, Aug 7, 2008 1:40:28pm

re: #28 Killgore Trout

Luckily the press was there to record the historic event.

I will print that photo and treasure it.
/

34 Kosh's Shadow  Thu, Aug 7, 2008 1:40:41pm

re: #22 Barry the Baptist

Let's put big govt in charge- they can fix anything!

A poster about that

35 Cygnus  Thu, Aug 7, 2008 1:40:44pm

Let's hope that Charles has his crack team of Security Hamsters on the case.

36 Opinionated  Thu, Aug 7, 2008 1:41:19pm

re: #9 NoSubmission

OT
They call this news?
Obama Orders Pancakes to Go

He learned his lesson with waffles.

37 nyc redneck  Thu, Aug 7, 2008 1:41:34pm

re: #23 eschew_obfuscation

What'll happen if he has an omelet?

that won't happen.
he'll go for french toast.

38 Gordon Marock  Thu, Aug 7, 2008 1:41:54pm

Literally, as we speak, Russian mobsters could be stealing the wit and wisdom posted at LGF.

ADVISORY- All somments posted by Gordon Marock are copyrighted, trade marked, owned by me, etc. . . .

except those comments I have stolen from others.

39 MandyManners  Thu, Aug 7, 2008 1:42:01pm

Al Gore, you idiot!

40 NoSubmission  Thu, Aug 7, 2008 1:42:01pm

re: #19 nyc redneck

it is news. he has flip flopped on waffles.


I love this part:

"How are we doing? Hope we didn't interrupt anything," the Democratic presidential contender said. He held a baby and told a small girl, "You're almost as good-looking as they get."


'Almost as good looking as they get'? is he saying the girl isn't really good looking?
He's flipping before he flops!

41 Just Another Four-letter Word  Thu, Aug 7, 2008 1:42:19pm

This vulnerability is causing us giant headaches here at F5, and I can just imagine what the "giants" are going through, especially the people that run the top, secondary, and tertiary-level DNS servers.

JAFLW

/calm and unruffled above the surface, but paddling like hell underneath where nobody can see...

42 Cygnus  Thu, Aug 7, 2008 1:43:29pm

re: #40 NoSubmission

'Almost as good looking as they get'? is he saying the girl isn't really good looking?
He's flipping before he flops!

He didn't want his wife to be jealous.

43 Mars Needs Neocons  Thu, Aug 7, 2008 1:43:41pm

AAAGGHH another thread. I'm still four back. I don't know if I can handle 5 at once!

44 Iron Fist  Thu, Aug 7, 2008 1:44:48pm

re: #32 looking closely

They just read Pandagon. Remember her? She was going to blog for John Edwards until someone actually read her drivel.

45 eschew_obfuscation  Thu, Aug 7, 2008 1:44:57pm

re: #27 Gordon Marock

How do I know that I am really posting this comment to LGF? Any response "Charles"?

"There is a fifth dimension beyond that which is known to man. It is a dimension as vast as space and timeless as infinity. It is the middle ground between light and shadow, between science and superstition, and it lies between the pit of man's fears and the summit of his knowledge. This is the dimension where your posts go. It is an area we call the Twilight Zone."

-Charlse-

46 maddogg  Thu, Aug 7, 2008 1:45:13pm

re: #29 karmic_inquisitor

Most any techie see the wisdom in keeping the internet out of government hands. So why are so many of them Democrats? I have never understood it.

They want to control the information you have access to. Thats the main reason they want control. All would-be dictators want to control the information the people have access to, and communists are no different.

47 nyc redneck  Thu, Aug 7, 2008 1:45:15pm

re: #40 NoSubmission

'Almost as good looking as they get'? is he saying the girl isn't really good looking?
He's flipping before he flops!

why would he say that to a little girl?
weird.
he is just plain fcking weird and inappropriate.

48 zombie  Thu, Aug 7, 2008 1:46:09pm

Since this is a tech thread:

I have a really ignorant newbie question about cell phones. (LIke Charles, I got my first one ever by chance recently.)

Someone gave me his old first-generation iPhone that he didn't want any more after he got the new kind. He deactivated the cell phone service associated with the old one through AT&T.

I got the phone. It works in all its other functions except being a cell phone (i.e. wifi, iPod, etc. etc.). I went online and successfully used the program "Ziphone" to "jailbreak" and "unlock" the iPhone. As far as I can tell, it worked.

But now is where my extreme ignorance comes into play. Now that I've jailbroken and unlocked my iPhone, can I use any cell-phone company's services? The iPhone has something called a SIM card, but do all cell companies use SIM cards? How do I find out? Who do I ask? If one walks into a cell phone store operated by a particular company, they'll tell you whatever they can in order to get you to sign up with them.

I specifically want to get "pay-as-you-go" minute-by-minute service with no long-term contracts.

Also, when one gets a cell phone number for one's cell phone, does one have to give out one's name? Or can I just pay cash, get a number somehow, and that's it?

49 Just Another Four-letter Word  Thu, Aug 7, 2008 1:46:20pm

re: #29 karmic_inquisitor

Most any techie see the wisdom in keeping the internet out of government hands. So why are so many of them Democrats? I have never understood it.

Because when it comes to understanding people, much less political processes, these guys are noobs. I see it every day - they don't really have a clue as to how the world really, really works. Once they get age and wisdom (treachery optional), they wake up. Mostly.

JAFLW

50 NoSubmission  Thu, Aug 7, 2008 1:46:42pm

re: #28 Killgore Trout

Luckily the press was there to record the historic event.

THAT is a priceless photo!

51 HoosierHoops  Thu, Aug 7, 2008 1:50:58pm

We installed the patch for the DNS poison cache flaw..
Screwed up and redirected to the wrong circuit on the core router..
Lost Internet for 6 hours and redirected the proxy through Europe just to limp along until we figured out the screw up..
ouch is the understatement of the week..

52 zombie  Thu, Aug 7, 2008 1:52:03pm

Oh, and Charles, Ajax now seems to work ok this iphone, which I'm now using!

53 zombie  Thu, Aug 7, 2008 1:52:43pm

OK on this iPhone.

PIMF

54 reloadingisnotahobby  Thu, Aug 7, 2008 1:52:57pm

re: #32 looking closely
Cause it sounds like Sh&* and doesn't mean fu^%&* thing!

55 NomadOfNorad  Thu, Aug 7, 2008 1:53:12pm

re: #52 zombie

Oh, and Charles, Ajax now seems to work ok this iphone, which I'm now using!

I take it you are reading and posting to LGF via the iPhone right now?

56 NomadOfNorad  Thu, Aug 7, 2008 1:53:41pm

re: #53 zombie

OK on this iPhone.

PIMF

Ah. Answered before I could post the question. :D

57 zombie  Thu, Aug 7, 2008 1:54:23pm

re: #55 NomadOfNorad

I take it you are reading and posting to LGF via the iPhone right now?

Yes.

58 reloadingisnotahobby  Thu, Aug 7, 2008 1:54:51pm

re: #48 zombie

Since your name is"one" and is so common
I wouldn't worry about it too much!
Giggle*

59 noshariaincanada  Thu, Aug 7, 2008 1:54:57pm

all your domains is belong to us

60 NomadOfNorad  Thu, Aug 7, 2008 1:55:05pm

re: #57 zombie

Via wifi, right?

61 zombie  Thu, Aug 7, 2008 1:55:19pm

re: #60 NomadOfNorad

Via wifi, right?

Yup.

62 HoosierHoops  Thu, Aug 7, 2008 1:55:20pm

re: #48 zombie

Bad news Zombie.. AT&T is the only service available for the iphone in the US..
/somebody is going to post that somebody did hack the firmware to allow other phone co. connections..
good luck with that...Unless you are an EE or systems engineer.

63 Mars Needs Neocons  Thu, Aug 7, 2008 1:57:33pm

re: #62 HoosierHoops

Bad news Zombie.. AT&T is the only service available for the iphone in the US..
/somebody is going to post that somebody did hack the firmware to allow other phone co. connections..
good luck with that...Unless you are an EE or systems engineer.

Around here, Cellular One supports Iphone. Of course it's just a local company.

64 zombie  Thu, Aug 7, 2008 1:57:38pm

re: #62 HoosierHoops

Bad news Zombie.. AT&T is the only service available for the iphone in the US..
/somebody is going to post that somebody did hack the firmware to allow other phone co. connections..
good luck with that...Unless you are an EE or systems engineer.

That's the supposed whole point behind "jailbreaking" and "unlocking" -- it allows one to use other carriers on an iPhone. But since I've never had a cell phone before, I don't know how to go about getting a number or signing up, or who I sign up with!

65 NomadOfNorad  Thu, Aug 7, 2008 1:58:46pm

I've got a question about iPhones: Can one connect it to their computer, drag and drop MP3 files onto it like it's an ordinary removable drive, and have them play on the iPhone like normal, or do you have to fly through hoops to get them recognized?

66 HoosierHoops  Thu, Aug 7, 2008 1:59:06pm

re: #63 Mars Needs Neocons

Around here, Cellular One supports Iphone. Of course it's just a local company.

REALLY?
I was under the impression that AT&T has the sole contract..
Gotta google now..

67 Just Another Four-letter Word  Thu, Aug 7, 2008 1:59:19pm

re: #62 HoosierHoops

Bad news Zombie.. AT&T is the only service available for the iphone in the US..
/somebody is going to post that somebody did hack the firmware to allow other phone co. connections..
good luck with that...Unless you are an EE or systems engineer.

Among other things, it has to do with what radio frequencies the phone is capable of utilizing. Bad news for iPhone users that wouold like to switch to some other equally-bad provider...

JAFLW

/For all you techies, I'm keeping the explanation simple, okay?

68 Mars Needs Neocons  Thu, Aug 7, 2008 2:01:17pm

re: #48 zombie

You can call your local cell companies and tell them you have an unlocked Iphone, then they can tell you if it can be connected to their service. Most companies have pay as you go now, but they will require all your info. Tracfone and similar company can only use their proprietary equipment most of the time. This is from my experience at least.

69 Mars Needs Neocons  Thu, Aug 7, 2008 2:01:47pm

re: #66 HoosierHoops

REALLY?
I was under the impression that AT&T has the sole contract..
Gotta google now..

Yep, friend of mine bought one the other day and got it hooked up.

70 Occasional Reader  Thu, Aug 7, 2008 2:02:47pm

re: #57 zombie

Yes.

You're a much more patient typist than I am, if you've done all the posting in this thread on an iPhone!

71 Mars Needs Neocons  Thu, Aug 7, 2008 2:04:35pm

re: #66 HoosierHoops

REALLY?
I was under the impression that AT&T has the sole contract..
Gotta google now..

Another little known fact. As long as you have the correct network (CDMA, GSM 900/1600 etc.) you can hook any unlocked phone with a clean ESM. So find out what network your phone supports and if it matches the cell service you want to use then just bring it to them and get it activated on their service. Just make sure that the phone you get can work on the network type the company uses.

72 zombie  Thu, Aug 7, 2008 2:04:51pm

re: #65 NomadOfNorad

I've got a question about iPhones: Can one connect it to their computer, drag and drop MP3 files onto it like it's an ordinary removable drive, and have them play on the iPhone like normal, or do you have to fly through hoops to get them recognized?

It's just as easy as an iPod: just start iTunes, plug the iPhone into the computer, and one can drag and drop mp3s (and other files I suppose) from one to the other.

I'll try it right now, in fact, and report back in however long it takes.

73 NomadOfNorad  Thu, Aug 7, 2008 2:04:54pm

re: #70 Occasional Reader

Is it possible to connect a bluetooth keyboard to an iPhone? Does an iPhone even use bluetooth?

74 Mars Needs Neocons  Thu, Aug 7, 2008 2:05:02pm

re: #70 Occasional Reader

You're a much more patient typist than I am, if you've done all the posting in this thread on an iPhone!

That's why I prefer my Treo, the keyboard makes all the difference here.

75 Mars Needs Neocons  Thu, Aug 7, 2008 2:06:33pm

re: #73 NomadOfNorad

Is it possible to connect a bluetooth keyboard to an iPhone? Does an iPhone even use bluetooth?

Iphone does have bluetooth, but AFAIK it only works with the wireless headphones.

I however want one of these for my Treo.

76 Occasional Reader  Thu, Aug 7, 2008 2:06:36pm

re: #73 NomadOfNorad

Is it possible to connect a bluetooth keyboard to an iPhone? Does an iPhone even use bluetooth?

iPhone does have bluetooth capacity; I have yet to find a bluetooth keyboard for it, though. There have been rumors floating around about one coming out.

77 NomadOfNorad  Thu, Aug 7, 2008 2:07:47pm

re: #72 zombie

All of my MP3s (and other media, for that matter) is stored on a Network Attached Storage box. And I don't use iTunes, I usually use WinAmp, or whatever other media player I've got on the particular machine I'm accessing the NAS by at that particular moment.

What sort of hoops would I have to fly through to get to the files on my NAS via iTunes...?

78 Occasional Reader  Thu, Aug 7, 2008 2:09:05pm

re: #74 Mars Needs Neocons

That's why I prefer my Treo, the keyboard makes all the difference here.

The keyboard is a drawback to iPhone, no doubt about it. It's the price paid for having a relatively big screen. However; I have little doubt they'll be coming out with bluetooth and/or other funky keyboards for it (like that holographic dealy); there's also an app (free) called WritingPad, which gives you an "intuitive" keypad that seems promising for faster data input (I've only just started playing with it).

79 Sir Napsalot  Thu, Aug 7, 2008 2:10:02pm

So now we get to blame it on Gore?

80 Charles  Thu, Aug 7, 2008 2:11:14pm

re: #72 zombie

It's just as easy as an iPod: just start iTunes, plug the iPhone into the computer, and one can drag and drop mp3s (and other files I suppose) from one to the other.

I'll try it right now, in fact, and report back in however long it takes.

Yes, it's very simple to drag and drop stuff that way, but you have to make sure to enable "Manually manage music and videos" in the Summary tab for your iPhone (in iTunes).

The iPhone User's Guide is a must-have, and it doesn't come with the device. You have to download it from Apple:

[Link: support.apple.com...]

81 Mars Needs Neocons  Thu, Aug 7, 2008 2:11:38pm

re: #78 Occasional Reader

The keyboard is a drawback to iPhone, no doubt about it. It's the price paid for having a relatively big screen. However; I have little doubt they'll be coming out with bluetooth and/or other funky keyboards for it (like that holographic dealy); there's also an app (free) called WritingPad, which gives you an "intuitive" keypad that seems promising for faster data input (I've only just started playing with it).

If it ran on WM5, I know a nice program which gives a nice full screen keyboard that is finger friendly.

82 ssaner  Thu, Aug 7, 2008 2:15:31pm

re: #65 NomadOfNorad

No, you can not mount the iphone as remote filesystem and just drag and drop files onto it. You must use iTunes. Maybe if you jailbreak the iphone you can do it, I don't know. It is pretty easy to import a library of mp3s into iTunes for this purpose, however.

83 zombie  Thu, Aug 7, 2008 2:17:03pm

Gee, I haven't done this in so long, I can't remember how to do it!

I'm still trying to fiddle with iTunes. Scratching my head. Sorry.

84 zombie  Thu, Aug 7, 2008 2:18:03pm

re: #80 Charles

Yes, it's very simple to drag and drop stuff that way, but you have to make sure to enable "Manually manage music and videos" in the Summary tab for your iPhone (in iTunes).

I'm just figuring that out. Weird.

I downloaded the user's manual but haven't had a spare moment to look at it yet.

85 zombie  Thu, Aug 7, 2008 2:21:04pm

Gee, this is getting too complicated at the moment. I'd need to sit down and concentrate for a while. I have too much else to do at the moment to wrangle with iTunes! Sorry. But I know it is possible to drag and drop.

86 Occasional Reader  Thu, Aug 7, 2008 2:22:20pm

re: #84 zombie

I'm just figuring that out. Weird.

I downloaded the user's manual but haven't had a spare moment to look at it yet.

You definitely should read the manual in order to get the iPhone self-destruct sequence down pat. It's based on the sequence for the Nostromo.

87 lifeofthemind  Thu, Aug 7, 2008 2:22:41pm

re: #18 buzzsawmonkey

It shows his elitism, being stack up and all.

"stack up?" is that racist code?

88 Charles  Thu, Aug 7, 2008 2:23:49pm

Plug in the iPhone, go to iTunes and click the iPhone in the Devices list, then make sure the 'Summary' tab is selected. The 'Manually manage music and videos' checkbox is at the bottom, under Options.

89 zombie  Thu, Aug 7, 2008 2:24:20pm

re: #70 Occasional Reader

You're a much more patient typist than I am, if you've done all the posting in this thread on an iPhone!

No, only the short comments are on the iPhone. Most of the comments (like this one) I'm typing on my regular computer! I'm patient, but not that patient!

90 lifeofthemind  Thu, Aug 7, 2008 2:24:38pm

re: #34 Kosh's Shadow

A poster about that

Despair.com is brilliant. I took the tie to read up on who they are.

91 Mars Needs Neocons  Thu, Aug 7, 2008 2:27:36pm

re: #90 lifeofthemind

Despair.com is brilliant. I took the tie to read up on who they are.

There seems to be a distinct anti-idiotarian feel to their blog.

92 zombie  Thu, Aug 7, 2008 2:32:35pm

re: #88 Charles

Plug in the iPhone, go to iTunes and click the iPhone in the Devices list, then make sure the 'Summary' tab is selected. The 'Manually manage music and videos' checkbox is at the bottom, under Options.

I'm doing that, but iTunes give me a persisent annoying message about "erasing this iPhone" and "syncing it with this iTunes library" because it can be synced with only one iTunes at a time. In other words, I can't enable the ability to manually manage the mp3s already on the iPhone until I erase them all first!

93 Conservative in Liberal Hands  Thu, Aug 7, 2008 2:33:17pm

re: #89 zombie

It is, then, possible for lizards to be two places at one time! Clever of Charles to allow for multiple login's from the same user id. I'm not sure that that's good admin policy, but it probably doesn't hurt too much either. Only problem I can see is "That's not the post that I know." or "The secretary will disavow any knowledge of your actions." (I think I got the quote from the show correctly - can anybody guess the show?)

94 Mars Needs Neocons  Thu, Aug 7, 2008 2:35:12pm

re: #93 Conservative in Liberal Hands

It is, then, possible for lizards to be two places at one time! Clever of Charles to allow for multiple login's from the same user id. I'm not sure that that's good admin policy, but it probably doesn't hurt too much either. Only problem I can see is "That's not the post that I know." or "The secretary will disavow any knowledge of your actions." (I think I got the quote from the show correctly - can anybody guess the show?)

It doesn't work that way for me. As soon as I log in somewhere else, my home computer logs off.

95 GeeWiz  Thu, Aug 7, 2008 2:35:58pm

re: #93 Conservative in Liberal Hands

Secret Agent Man?

96 Conservative in Liberal Hands  Thu, Aug 7, 2008 2:36:32pm

re: #95 GeeWiz

No...

97 zombie  Thu, Aug 7, 2008 2:37:43pm

Charles, I think the problem is that all the song files on the iPhone were actually purchased from the iTunes store, and have that digital rights management thingie. Conversely, all the song files on my computer are rights-free old-style mp3s that I either inherited when I bought my used computers, or downloaded off music blogs, or were given to me by friends, or gotten off p2p networks, and so on. I've never actually purchased a song file, so I'm unfamiliar with all these weird rights restrictions.

I'm worried about the wording of the iTunes warning message, because it says "erase this iPhone" and not "erase the iTunes library on this iPhone." I don't want ton erase the whole phone!

98 GeeWiz  Thu, Aug 7, 2008 2:38:39pm

re: #96 Conservative in Liberal Hands

Get Smart?

99 Conservative in Liberal Hands  Thu, Aug 7, 2008 2:38:57pm

re: #93 Conservative in Liberal Hands

(I think I got the quote from the show correctly - can anybody guess the show?)

The answer is "Mission Impossible"

100 zombie  Thu, Aug 7, 2008 2:39:26pm

re: #93 Conservative in Liberal Hands

It is, then, possible for lizards to be two places at one time! Clever of Charles to allow for multiple login's from the same user id. I'm not sure that that's good admin policy, but it probably doesn't hurt too much either. Only problem I can see is "That's not the post that I know." or "The secretary will disavow any knowledge of your actions." (I think I got the quote from the show correctly - can anybody guess the show?)

Yes, I can log in on two different devices simultaneously. This is on the computer...

101 zombie  Thu, Aug 7, 2008 2:39:36pm

and this is on thfe iPhone!

102 Charles  Thu, Aug 7, 2008 2:40:46pm

re: #97 zombie

Charles, I think the problem is that all the song files on the iPhone were actually purchased from the iTunes store, and have that digital rights management thingie. Conversely, all the song files on my computer are rights-free old-style mp3s that I either inherited when I bought my used computers, or downloaded off music blogs, or were given to me by friends, or gotten off p2p networks, and so on. I've never actually purchased a song file, so I'm unfamiliar with all these weird rights restrictions.

I'm worried about the wording of the iTunes warning message, because it says "erase this iPhone" and not "erase the iTunes library on this iPhone." I don't want ton erase the whole phone!

Oh, so you got the phone from someone else, with all those songs already on it? Yeah, then you have DRM issues. Those songs have been locked to the original version of iTunes.

I only rarely buy DRM-protected music now, since the Amazon MP3 store opened. I'll only get a DRM version from iTunes if it's not available anywhere else.

103 zombie  Thu, Aug 7, 2008 2:40:50pm

re: #94 Mars Needs Neocons

It doesn't work that way for me. As soon as I log in somewhere else, my home computer logs off.

I can do it, no problem. I'm logged in now, twice!

I can also log in on two different browsers on the same computer simultaneously.

104 Conservative in Liberal Hands  Thu, Aug 7, 2008 2:40:56pm

re: #94 Mars Needs Neocons

Thanks for the confirmation! I thought that was the way it worked and should work too!

Charles, comments please?

105 GeeWiz  Thu, Aug 7, 2008 2:41:54pm

re: #99 Conservative in Liberal Hands

Shows ya how much I know about tv shows. Never watch any commercial tv, just cable and not commercial re-runs.

106 Charles  Thu, Aug 7, 2008 2:41:55pm

And by the way, I'm pretty sure you won't be able to add new music from iTunes unless you wipe out the non-authorized stuff. DRM sucks.

107 itellu3times  Thu, Aug 7, 2008 2:42:48pm

Um, is this a good idea: RNC toolbar

(from an email sent by RNC)

Dear Republican,

We are excited to announce a revolutionary, yet simple, tool that allows you to stay connected to the GOP and raise valuable contributions, without spending a dime! We are facing one of the most important elections in history, and it shall be our unity that brings us to victory. You can make a difference by downloading and using the new RNC Toolbar. The RNC Toolbar will help you raise money through normal online activities such as searching and shopping! Just a click away, you also will have access to breaking news, updates, and messages from the RNC! Show your support by joining millions of other Party members raising valuable contributions for our Party hassle-free! Track your personal contributions in real time and learn that together we can make a difference!

108 Charles  Thu, Aug 7, 2008 2:43:16pm

re: #103 zombie

I can do it, no problem. I'm logged in now, twice!

I can also log in on two different browsers on the same computer simultaneously.

You might find that some things don't work correctly when you log in twice, because the session cookies can get mixed up. But yeah, I didn't specifically prohibit this in the login code.

109 zombie  Thu, Aug 7, 2008 2:43:24pm

re: #102 Charles

Oh, so you got the phone from someone else, with all those songs already on it? Yeah, then you have DRM issues. Those songs have been locked to the original version of iTunes.

I only rarely buy DRM-protected music now, since the Amazon MP3 store opened. I'll only get a DRM version from iTunes if it's not available anywhere else.

Yes, as I said in comment #48 above, I got the iPhone as a hand-me-down from someone who got a new 3G kind and didn't want his old one anymore. Then I jailbroke and unlocked it, so I could get a pay-as-you-go phone plan.

I've never bought a song, and doubt I ever will. The stuff I want isn't on iTunes anyway!

110 Mars Needs Neocons  Thu, Aug 7, 2008 2:44:19pm

re: #103 zombie

I can do it, no problem. I'm logged in now, twice!

I can also log in on two different browsers on the same computer simultaneously.

I think you have somehow achieved the special "Zombie Code" that lets you have special LGF benefits.

/

111 zombie  Thu, Aug 7, 2008 2:45:20pm

Let me try an experiment. Here we go...

112 Conservative in Liberal Hands  Thu, Aug 7, 2008 2:45:59pm

re: #103 zombie

Zombie -

You've got me confused?! Not only about the issue of multiple logins from a single user id, but also that picture of you at the work table...

113 Mars Needs Neocons  Thu, Aug 7, 2008 2:48:06pm

re: #112 Conservative in Liberal Hands

It was rumored that a restaurant like that was opening here, then it just turned out to be a strip club, boring.

114 Conservative in Liberal Hands  Thu, Aug 7, 2008 2:48:14pm

re: #108 Charles

Thanks Charles for clearing that up! I thought I spotted the variable-sharing from the way the site responds.

115 zombie  Thu, Aug 7, 2008 2:49:28pm

This comment is made on my iPhone, logged in as zombie once!

116 zombie  Thu, Aug 7, 2008 2:49:34pm

This comment is made on FireFox, logged in as zombie twice!

117 zombie  Thu, Aug 7, 2008 2:49:43pm

This comment is made on Safari, logged in as zombie thrice!

118 zombie  Thu, Aug 7, 2008 2:49:52pm

Woo-hoo!

119 MadNachos  Thu, Aug 7, 2008 2:49:57pm

Not really sure why this is making the news today...really nothing new here. If everyone would patch/update their DNS servers everything would be fine. The real story is that many ISP's still have not fixed the hole....

120 Conservative in Liberal Hands  Thu, Aug 7, 2008 2:50:23pm

re: #117 zombie

Mommy, I see zombies... and they all look alike! ;-p

121 zombie  Thu, Aug 7, 2008 2:50:33pm

re: #108 Charles

You might find that some things don't work correctly when you log in twice, because the session cookies can get mixed up. But yeah, I didn't specifically prohibit this in the login code.

Seems to work beautifully -- I just pulled a trifecta.

122 Conservative in Liberal Hands  Thu, Aug 7, 2008 2:51:51pm

re: #119 MadNachos

Most ISP's are fighting the Apaches.
.
.
.
.
.
As in Apache Software that drives most web severs.

123 Conservative in Liberal Hands  Thu, Aug 7, 2008 2:53:12pm

re: #121 zombie

Zom -

If you poke around enough, as in posting two messages at the same time, you may get some "interesting" results.

124 zombie  Thu, Aug 7, 2008 2:53:24pm

the Ajax is even working on my iPhone now too.

125 mossley  Thu, Aug 7, 2008 2:53:41pm

re: #10 Sharmuta

I blame al gore. It's his internet after all.


LOL! I would love to see a reporter have the nerve to ask him about this, why he left such a fault in the system and how he plans to fix it.

In all seriousness, the only thing about this that surprises me is how long it took for this flaw to become exploited. On the other hand, the basic lack of security protocols associated with Internet traffic never ceases to amaze me. The folks that created them falsely assumed that no one within the government/university system would ever abuse the system, and they failed to consider that it would expand commercially.

The fact that the IPv6 folks have been in committee for 12+ years doesn't inspire much confidence that the problems will go away any time soon.

126 lifeofthemind  Thu, Aug 7, 2008 2:57:09pm

Hey zombie, How's the smorgasbord?

127 Thanos  Thu, Aug 7, 2008 2:58:09pm

re: #1 eschew_obfuscation

Aw, just shut down the DNS servers.....make everyone use IP addresses!

Problem solved ;-)

There's a lot of worth behind what you say here. It requires longer IP addresses to implement, and something like the "North American Dialing Plan / International Dialing Plan" schema/standard that phone networks use. What if you couldn't spoof an IP, what if every IP location were known? Would the internet become more civil? Would anonymous death threats and obnoxious slander stop? Could we track down Jihadi websites better? Could we see what countries are donating to US presidential candidates easier?

With some of the new standards proposed it could get there. Privacy advocates will scream over this but if you think about it, the phone company knows where every phone number physically terminates, shouldn't the same be done for IP's?

128 Conservative in Liberal Hands  Thu, Aug 7, 2008 3:00:12pm

re: #125 mossley

In all seriousness, the only thing about this that surprises me is how long it took for this flaw to become exploited. On the other hand, the basic lack of security protocols associated with Internet traffic never ceases to amaze me. The folks that created them falsely assumed that no one within the government/university system would ever abuse the system, and they failed to consider that it would expand commercially.

IMHO, I believe that the kids - yes the twenty-something-year-olds - that first built it were assuming that the network would be based upon trust. And I agree with you, nobody thought - not even ole Eric Allman or Denny Richie - that it would grow to the commercial success it is today...

129 Mars Needs Neocons  Thu, Aug 7, 2008 3:03:24pm

re: #120 Conservative in Liberal Hands

Mommy, I see zombies... and they all look alike! ;-p

We've got our own dawn of the dead here. A complete zombie invasion, thank god it's not a completely dead night, or we'd have nothing but zombies on this thread.

130 NomadOfNorad  Thu, Aug 7, 2008 3:27:00pm

re: #102 Charles

Oh, so you got the phone from someone else, with all those songs already on it? Yeah, then you have DRM issues. Those songs have been locked to the original version of iTunes.

I only rarely buy DRM-protected music now, since the Amazon MP3 store opened. I'll only get a DRM version from iTunes if it's not available anywhere else.

I've been an eMusic.com junkie for a couple of years now... and have bought a couple of MP3 albums off of Amazon.com recently as well...

Both are pure MP3, no DRM infestations at all. :D

131 olderthandirt  Thu, Aug 7, 2008 4:35:57pm

OK, time for a "do over!" Let's start designing the web all over again and this time, do it right! Jeez Louise, what's it going to take, Armageddon or someone messing with my accounts?

132 realwest  Thu, Aug 7, 2008 4:44:30pm

Wonder if this is gonna screw up paypal transactions?!

133 GeeWiz  Thu, Aug 7, 2008 5:31:23pm

Charles, I have been reading this site since the Rathergate dust-up. I became a member in April of '05'. I have used this site the same way I did then. Recently, I have begun to explore the enhancements you have implemented since then. In one word, I am in "AWE". Part of me says WOW and another part of me says that he has wowed me before. Says a lot about ya, coming from this old geek. GOOD ON YA!

134 KSK  Thu, Aug 7, 2008 6:18:07pm

Best protection against this serious NNS thing is Open DNS

[Link: www.opendns.com...]

135 LEGION  Thu, Aug 7, 2008 8:53:04pm

Yeah yeah yeah-- anyway- J-E-T-S JETS JETS JETS get B-R-E-TT BRETT BRETT BRETT. Farve, take us to the promised land- Superbowl here we come! Ahhh haaa haaaa haaaaa.

136 akak  Fri, Aug 8, 2008 2:12:42am

Death to hackers! not Packers....I said hackers....

Jets won't even make the playoffs


This entry has been archived.
Comments are closed.

^ back to top ^

log in
Name:
Pass:

Register Forgot Your Password? My Account Re-send Confirmation (To log in, cookies must be enabled in your browser!)

► LGF Headlines

► Top 10 Comments

► Bottom Comments

► Recent Comments

► Tools/Info

► LGF Hits

► Slideshows

► Resources

► Never Forget

► Statistics

► Tag Cloud

► Contact

You must have Javascript enabled to use the contact form.
Your email:

Subject:

Message:


Messages may be published in our weblog, unless you request otherwise.
Tech Note:
Using the Contact Form

► News/Opinion

Barnes & Noble @ School Collection
Apple iTunes
More Partners

Compare Electricity Prices in your area. Texas Electricity is deregulated; you have the right to choose Texas Electric Rates from among many Texas Electric Companies.

Declear the crudase and be unite.


Tikatok Gift Cards - Capture your child's imagination . . . in a book!
Music 160x600
eBooks for Everyone at Barnes & Noble