Aug. 31st, 2007

jducoeur: (Default)
Well, that’s ruefully amusing. When I went to sign into Facebook a bit ago, IE gave me a warning that the security certificate was from an untrusted signing authority. When I actually dig into the details, the cert has been signed by “cybervillains.com” – which doesn’t have much information, but which *claims* to be an imprint of iSEC Partners (www.isecpartners.com), a security firm.

So I *think* what’s happened here is that Facebook hired iSEC to test their security perimeter, and they found that it’s actually pretty weak – iSEC was able to break into the site and substitute their own cert in place of Facebook’s authentic one. Which makes me happy that Facebook is conducting this sort of security test, but less happy that they appear to publicly failed it…

[ETA: Having already gotten one friend request from posting this, I should note that I don't actually *use* Facebook except for work -- we're doing some sample apps in Facebook. So you're welcome to friend me, but don't expect anything interesting there...]

[ETA 2: I got a note from the fellow who actually wrote the tool in question, which *is* a security tool, but it's intended for interception and monitoring of SSL traffic. His take on it is that Zing is probably being attacked, fortunately by someone too stupid to hack the credentials on the program to something plausible-sounding -- the "Cybervillains" moniker was specifically to alert anyone who gets it that it's fake. So the moral of the story is, pay attention to certs that are presented to you, and if it sounds suspicious, refuse it...]
jducoeur: (Default)
Well, that’s ruefully amusing. When I went to sign into Facebook a bit ago, IE gave me a warning that the security certificate was from an untrusted signing authority. When I actually dig into the details, the cert has been signed by “cybervillains.com” – which doesn’t have much information, but which *claims* to be an imprint of iSEC Partners (www.isecpartners.com), a security firm.

So I *think* what’s happened here is that Facebook hired iSEC to test their security perimeter, and they found that it’s actually pretty weak – iSEC was able to break into the site and substitute their own cert in place of Facebook’s authentic one. Which makes me happy that Facebook is conducting this sort of security test, but less happy that they appear to publicly failed it…

[ETA: Having already gotten one friend request from posting this, I should note that I don't actually *use* Facebook except for work -- we're doing some sample apps in Facebook. So you're welcome to friend me, but don't expect anything interesting there...]

[ETA 2: I got a note from the fellow who actually wrote the tool in question, which *is* a security tool, but it's intended for interception and monitoring of SSL traffic. His take on it is that Zing is probably being attacked, fortunately by someone too stupid to hack the credentials on the program to something plausible-sounding -- the "Cybervillains" moniker was specifically to alert anyone who gets it that it's fake. So the moral of the story is, pay attention to certs that are presented to you, and if it sounds suspicious, refuse it...]
jducoeur: (Default)
So we are *still* unpacking from our move -- or, more precisely, we're dealing with the crap that had been building up for decades in the old house, and which we don't want to leave sitting in the new one.

One of those projects is The Great CBG Cut-Up. I had subscribed to the Comics Buyer's Guide for a number of years, and We being an Us, had never thrown any of them out. And let me tell you, ten years of a 100-page weekly tabloid takes up quite a bit of volume. So I've been slowly going through them and slicing them up, keeping just the articles that I really care about and chucking the rest.

In the course of this, I happened across the original interview that [livejournal.com profile] teriwood gave, back when her comic book Wandering Star was the best thing being published. Knowing that she'd lost a great deal in a flood some while back, I checked with her and confirmed that she didn't have a copy of the article. So I put that in an envelope and sent it off to her, since it was clearly the correct destiny for that particular bit of newsprint.

Well, today the envelope came back in the mail, containing not the article, but an original piece of art from her. It's simply gorgeous, and in color even! (It's the first time I've seen her work in color -- her comics are all inked black and white.) The development of the piece can be seen on her website, although honestly it looks much nicer up-close. I'm thoroughly tickled: it's one of the best presents I've gotten in some time, a piece of real Art.

Time to go find a frame of the right dimensions. It's one of the prettiest pieces we have, and is clearly going up on the wall ASAP...
jducoeur: (Default)
So we are *still* unpacking from our move -- or, more precisely, we're dealing with the crap that had been building up for decades in the old house, and which we don't want to leave sitting in the new one.

One of those projects is The Great CBG Cut-Up. I had subscribed to the Comics Buyer's Guide for a number of years, and We being an Us, had never thrown any of them out. And let me tell you, ten years of a 100-page weekly tabloid takes up quite a bit of volume. So I've been slowly going through them and slicing them up, keeping just the articles that I really care about and chucking the rest.

In the course of this, I happened across the original interview that [livejournal.com profile] teriwood gave, back when her comic book Wandering Star was the best thing being published. Knowing that she'd lost a great deal in a flood some while back, I checked with her and confirmed that she didn't have a copy of the article. So I put that in an envelope and sent it off to her, since it was clearly the correct destiny for that particular bit of newsprint.

Well, today the envelope came back in the mail, containing not the article, but an original piece of art from her. It's simply gorgeous, and in color even! (It's the first time I've seen her work in color -- her comics are all inked black and white.) The development of the piece can be seen on her website, although honestly it looks much nicer up-close. I'm thoroughly tickled: it's one of the best presents I've gotten in some time, a piece of real Art.

Time to go find a frame of the right dimensions. It's one of the prettiest pieces we have, and is clearly going up on the wall ASAP...

Profile

jducoeur: (Default)
jducoeur

June 2025

S M T W T F S
12 34567
891011121314
15161718192021
22232425262728
2930     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags