By Jonathan + December 6th, 2007
Back in January, I blogged about the security holes in the ePass system, the online application that allows you to login to Canadian government websites. It all started when I noticed some fundamental flaws in the Canadian passport website after Chris had already exposed last April how generally frustrating it is to use.
Developers from [...]
By Jonathan + June 21st, 2007
If you’re wondering why WhyYouShould is responding very slowly (if at all) tonight, it looks like my hosting provider DiscountASP is experiencing a denial-of-service attack. They’re working on it and hopefully WYS will be back soon
From Discountasp.net:
Dear Customer,
We experienced a network-wide outage Thursday morning and late evening as the result of a distributed [...]
By Jonathan + March 7th, 2007
A couple of months ago, I blogged about the security holes in the ePass system, the online application that allows you to login to Canadian government websites. It all started when I noticed some fundamental flaws in the Canadian passport website after Chris had already exposed last April how generally frustrating it is to [...]
By Jonathan + February 16th, 2007
As I was misrepresenting this news story on Digg as a story about Colin Farrell (it turns out, the guy just looks like him), it came to me that this would be a cool way to manipulate Digg.
Say your site, and another site, were competing with the same content to get digged first/the most. [...]
By Jonathan + February 10th, 2007
Feel like logging into my blog with your Yahoo! account for no particular reason? Then please feel free to login here: https://login.yahoo.com/config/login?&.done=http://www.keebler.net. Don’t worry, I’m not stealing your password or anything; you’re using the real Yahoo!.
I’m been noticing lately how much information web developers applications are giving away in the query string. [...]
By Jonathan + January 12th, 2007
If you’re Canadian and have recently tried filing your taxes online, ordering a passport, or changing your address, you’re familiar with the ePass Canada system. Chris and I have already detailed how frustrating it is to use, but my experience has also revealed that the system is fundamentally unsecure. Obviously I’m not willing [...]