<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Keebler/Blog &#187; Security</title>
	<atom:link href="http://www.keebler.net/blog/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.keebler.net/blog</link>
	<description></description>
	<lastBuildDate>Sat, 21 Nov 2009 06:07:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Just 6 days until telemarketers leave me alone&#8230;</title>
		<link>http://www.keebler.net/blog/2008/09/24/just-6-days-until-telemarketers-leave-me-alone/</link>
		<comments>http://www.keebler.net/blog/2008/09/24/just-6-days-until-telemarketers-leave-me-alone/#comments</comments>
		<pubDate>Wed, 24 Sep 2008 20:36:41 +0000</pubDate>
		<dc:creator>Jonathan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[telemarketers]]></category>

		<guid isPermaLink="false">http://www.keebler.net/blog/?p=2570</guid>
		<description><![CDATA[
On September 30th, the National Do Not Call List (DNCL) in Canada comes into effect.  I can&#8217;t wait!  It&#8217;s like frik&#8217;n Christmas!  Working from home, I get the full brunt of the stupid telemarketing-assholes.  Today, alone, I&#8217;ve been called by the Toronto Sun and the Toronto Star asking if I want [...]


Related posts:<ol><li><a href='http://www.keebler.net/blog/2009/10/04/its-like-28-days-later-in-t/' rel='bookmark' title='Permanent Link: It&#8217;s like &#8220;28 Days Later&#8221; in T&#8230;'>It&#8217;s like &#8220;28 Days Later&#8221; in T&#8230;</a> <small>It&#8217;s like &#8220;28 Days Later&#8221; in Toronto this morning after...</small></li><li><a href='http://www.keebler.net/blog/2005/12/11/26-days-until-battlestar-galactica-returns/' rel='bookmark' title='Permanent Link: 26 Days Until Battlestar Galactica Returns'>26 Days Until Battlestar Galactica Returns</a> <small> I&#8217;ve been resisting the urge to start counting down...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>
On September 30th, the <a href="http://www.lnnte-dncl.gc.ca/">National Do Not Call List (DNCL) in Canada</a> comes into effect.  I can&#8217;t wait!  It&#8217;s like frik&#8217;n Christmas!  Working from home, I get the full brunt of the stupid telemarketing-assholes.  Today, alone, I&#8217;ve been called by the Toronto Sun and the Toronto Star asking if I want to get a free trial of their newspaper.  &#8220;I didn&#8217;t want your crappy newspaper last month, why would I want one now?  And also, I asked to be taken off your list before so don&#8217;t you have to legally do that?&#8221;  Oh shit, that&#8217;s it, isn&#8217;t it?  The DNCL is going to be just as useless isn&#8217;t it?  Crap!
</p>
<p>
It&#8217;s time for Plan B: mash-up Canada411 with the DNCL. Feed every single number in the phonebook into the DNCL and starve those bastards out.  That&#8217;s probably a crime though, so I&#8217;ll probably just get call display <img src='http://www.keebler.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />
</p>
<p><a href="http://www.lnnte-dncl.gc.ca/"><img src="http://www.keebler.net/blog/wp-content/images/2008/09/picture-19-400x206.png" alt="" title="Canada National Do Not Call List" width="400" height="206" class="alignnone size-medium wp-image-2569" /></a></p>


<p>Related posts:<ol><li><a href='http://www.keebler.net/blog/2009/10/04/its-like-28-days-later-in-t/' rel='bookmark' title='Permanent Link: It&#8217;s like &#8220;28 Days Later&#8221; in T&#8230;'>It&#8217;s like &#8220;28 Days Later&#8221; in T&#8230;</a> <small>It&#8217;s like &#8220;28 Days Later&#8221; in Toronto this morning after...</small></li><li><a href='http://www.keebler.net/blog/2005/12/11/26-days-until-battlestar-galactica-returns/' rel='bookmark' title='Permanent Link: 26 Days Until Battlestar Galactica Returns'>26 Days Until Battlestar Galactica Returns</a> <small> I&#8217;ve been resisting the urge to start counting down...</small></li></ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.keebler.net/blog/2008/09/24/just-6-days-until-telemarketers-leave-me-alone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Passport Canada security breach: I told you almost a year ago</title>
		<link>http://www.keebler.net/blog/2007/12/06/passport-canada-security-breach-i-told-you-almost-a-year-ago/</link>
		<comments>http://www.keebler.net/blog/2007/12/06/passport-canada-security-breach-i-told-you-almost-a-year-ago/#comments</comments>
		<pubDate>Thu, 06 Dec 2007 05:31:35 +0000</pubDate>
		<dc:creator>Jonathan</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.keebler.net/blog/2007/12/06/passport-canada-security-breach-i-told-you-almost-a-year-ago/</guid>
		<description><![CDATA[
Back in January, I blogged about the security holes in the ePass system, the online application that allows you to login to Canadian government websites.  It all started when I noticed some fundamental flaws in the Canadian passport website after Chris had already exposed last April how generally frustrating it is to use.


Developers from [...]


Related posts:<ol><li><a href='http://www.keebler.net/blog/2007/01/10/passport-canada-is-error-500d-to-hell/' rel='bookmark' title='Permanent Link: Passport Canada is Error 500&#8242;d to Hell'>Passport Canada is Error 500&#8242;d to Hell</a> <small>Great, just great Passport Canada. Way to let me fill...</small></li><li><a href='http://www.keebler.net/blog/2009/10/26/air-canada-told-my-bro-that-ov/' rel='bookmark' title='Permanent Link: Air Canada told my bro that ov&#8230;'>Air Canada told my bro that ov&#8230;</a> <small>Air Canada told my bro that over-the-ear earphones are now...</small></li><li><a href='http://www.keebler.net/blog/2007/03/07/epasscanada-revenue-agency-online-tax-filing-suspended/' rel='bookmark' title='Permanent Link: ePass/Canada Revenue Agency Online Tax Filing Suspended'>ePass/Canada Revenue Agency Online Tax Filing Suspended</a> <small> A couple of months ago, I blogged about the...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>
Back in January, I <a href="http://www.keebler.net/blog/2007/01/12/epass-canada-is-not-secure/">blogged about the security holes in the ePass system</a>, the online application that allows you to login to Canadian government websites.  It all started when <a href="http://www.keebler.net/blog/2007/01/10/passport-canada-is-error-500d-to-hell/">I noticed some fundamental flaws in the Canadian passport website</a> after <a href="http://www.postal-code.com/mrhappy/blog/?p=884">Chris had already exposed last April how generally frustrating it is to use</a>.
</p>
<p>
Developers from the Passport Canada office (their IPs point right back to them) started leaving nasty comments on my blog:</p>
<blockquote><p>
Now, now. Everybody must live with the frustration of a world not as perfect as our own little person.</p>
<p>If the Passport application system was able to handle a sudden increase (what? 500% maybe? thanks to USA) without a glitch, it would mean that for many years this system had been running with way too much bandwidth and server muscles. Who would be crying then? Chris, Jonathan, Clay and their friends would be crying to the world that the government was wasting money all these years running such a system! (<a href="http://www.keebler.net/blog/2007/01/10/passport-canada-is-error-500d-to-hell/">source</a> &#8211; &#8220;Jo Blo&#8221;)
</p></blockquote>
<p>And on my friend&#8217;s blog:</p>
<blockquote><p>
do you know anything about security… whiner</p>
<p>if you can’t even figure out who built it you must be a simpleton.. oh yeah u use a mac … (<a href="http://www.postal-code.com/mrhappy/blog/?p=884">source</a> &#8211; &#8220;dl&#8221;)
</p></blockquote>
<p>
Well this week, <a href="http://www.theglobeandmail.com/servlet/story/RTGAM.20071205.wpassport05/BNStory/National/home">Passport Canada had to be completely shutdown for two days</a> when someone noticed that they were saving login credentials in a browser cookie.  That is egregious error by a web-developer, and shows a completely disregard for security practices.  Now, after two days, they are back online and saying, &#8220;Now the Internet site of Passport Canada is one of the most secure&#8221; (<a href="http://www.theglobeandmail.com/servlet/story/RTGAM.20071205.wpassport05/BNStory/National/home">source</a>).
</p>
<p>
Are you serious?!  Firstly, how are you determining that?  Put your site on HTTPS all you want; you cannot repair application security holes through anything but a complete line-by-line examination of your code-base.
</p>
<p>
Secondly, <strong>the security hole I found is still there</strong>.  You may have found and patched one hole, but <strong>the entire system is still open to exploit</strong>.
</p>
<p>
In the end, as a citizen myself, these websites are trying to protect my information and I want to help.  I emailed Passport Canada and the <a href="http://www.cra-arc.gc.ca/menu-e.html">CRA</a> to try to get in touch with someone that way.  Please, if you read this, drop me a line in the comments.  I will do whatever I can to help you close these holes.  Even if you don&#8217;t believe me that there are some, what do you have to lose?</p>


<p>Related posts:<ol><li><a href='http://www.keebler.net/blog/2007/01/10/passport-canada-is-error-500d-to-hell/' rel='bookmark' title='Permanent Link: Passport Canada is Error 500&#8242;d to Hell'>Passport Canada is Error 500&#8242;d to Hell</a> <small>Great, just great Passport Canada. Way to let me fill...</small></li><li><a href='http://www.keebler.net/blog/2009/10/26/air-canada-told-my-bro-that-ov/' rel='bookmark' title='Permanent Link: Air Canada told my bro that ov&#8230;'>Air Canada told my bro that ov&#8230;</a> <small>Air Canada told my bro that over-the-ear earphones are now...</small></li><li><a href='http://www.keebler.net/blog/2007/03/07/epasscanada-revenue-agency-online-tax-filing-suspended/' rel='bookmark' title='Permanent Link: ePass/Canada Revenue Agency Online Tax Filing Suspended'>ePass/Canada Revenue Agency Online Tax Filing Suspended</a> <small> A couple of months ago, I blogged about the...</small></li></ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.keebler.net/blog/2007/12/06/passport-canada-security-breach-i-told-you-almost-a-year-ago/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Discountasp.net being DOS attacked</title>
		<link>http://www.keebler.net/blog/2007/06/21/discountaspnet-being-dos-attacked/</link>
		<comments>http://www.keebler.net/blog/2007/06/21/discountaspnet-being-dos-attacked/#comments</comments>
		<pubDate>Fri, 22 Jun 2007 04:02:03 +0000</pubDate>
		<dc:creator>Jonathan</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.keebler.net/blog/2007/06/21/discountaspnet-being-dos-attacked/</guid>
		<description><![CDATA[
If you&#8217;re wondering why WhyYouShould is responding very slowly (if at all) tonight, it looks like my hosting provider DiscountASP is experiencing a denial-of-service attack.  They&#8217;re working on it and hopefully WYS will be back soon 


From Discountasp.net:

Dear Customer,
We experienced a network-wide outage Thursday morning and late evening as the result of a distributed [...]]]></description>
			<content:encoded><![CDATA[<p>
If you&#8217;re wondering why <a href="http://whyyoushould.org">WhyYouShould</a> is responding very slowly (if at all) tonight, it looks like my hosting provider <a href="http://www.discountasp.net">DiscountASP</a> is <a href="http://www.stevetrefethen.com/blog/BlogOutageCausedByHostingProviderDOSAttack.aspx">experiencing a denial-of-service attack</a>.  They&#8217;re working on it and hopefully WYS will be back soon <img src='http://www.keebler.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />
</p>
<p>
From Discountasp.net:</p>
<blockquote><p>
Dear Customer,</p>
<p>We experienced a network-wide outage Thursday morning and late evening as the result of a distributed denial of service attack. You can read details related to the outage here: <a href="http://community.discountasp.net/default.aspx?f=6&#038;m=18216&#038;p=1">http://community.discountasp.net/default.aspx?f=6&#038;m=18216&#038;p=1</a><br />
&#8230;
</p></blockquote>
<p><a href="http://whyyoushould.org/not/DOS/wys"><img src="http://whyyoushould.org.nyud.net:8090/SyndicateImage.aspx?thread=/not/DOS/wys" width="404" height="403" alt="Why You Should not DOS wys" title="Why You Should not DOS wys"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.keebler.net/blog/2007/06/21/discountaspnet-being-dos-attacked/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>ePass/Canada Revenue Agency Online Tax Filing Suspended</title>
		<link>http://www.keebler.net/blog/2007/03/07/epasscanada-revenue-agency-online-tax-filing-suspended/</link>
		<comments>http://www.keebler.net/blog/2007/03/07/epasscanada-revenue-agency-online-tax-filing-suspended/#comments</comments>
		<pubDate>Wed, 07 Mar 2007 15:36:17 +0000</pubDate>
		<dc:creator>Jonathan</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.keebler.net/blog/2007/03/07/epasscanada-revenue-agency-online-tax-filing-suspended/</guid>
		<description><![CDATA[
A couple of months ago, I blogged about the security holes in the ePass system, the online application that allows you to login to Canadian government websites.  It all started when I noticed some fundamental flaws in the Canadian passport website after Chris had already exposed last April how generally frustrating it is to [...]


Related posts:<ol><li><a href='http://www.keebler.net/blog/2007/01/12/epass-canada-is-not-secure/' rel='bookmark' title='Permanent Link: ePass Canada is not Secure'>ePass Canada is not Secure</a> <small> If you&#8217;re Canadian and have recently tried filing your...</small></li><li><a href='http://www.keebler.net/blog/2005/10/25/tamiflu-sales-suspended-in-canada/' rel='bookmark' title='Permanent Link: Tamiflu Sales Suspended in Canada'>Tamiflu Sales Suspended in Canada</a> <small> I guess so many Canadians read my blog that...</small></li><li><a href='http://www.keebler.net/blog/2007/12/06/passport-canada-security-breach-i-told-you-almost-a-year-ago/' rel='bookmark' title='Permanent Link: Passport Canada security breach: I told you almost a year ago'>Passport Canada security breach: I told you almost a year ago</a> <small> Back in January, I blogged about the security holes...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>
A couple of months ago, I <a href="http://www.keebler.net/blog/2007/01/12/epass-canada-is-not-secure/">blogged about the security holes in the ePass system</a>, the online application that allows you to login to Canadian government websites.  It all started when <a href="http://www.keebler.net/blog/2007/01/10/passport-canada-is-error-500d-to-hell/">I noticed some fundamental flaws in the Canadian passport website</a> after <a href="http://www.postal-code.com/mrhappy/blog/?p=884">Chris had already exposed last April how generally frustrating it is to use</a>.
</p>
<p>
Developers from the Passport Canada office started leaving nasty comments on my blog:</p>
<blockquote><p>
Now, now. Everybody must live with the frustration of a world not as perfect as our own little person.</p>
<p>If the Passport application system was able to handle a sudden increase (what? 500% maybe? thanks to USA) without a glitch, it would mean that for many years this system had been running with way too much bandwidth and server muscles. Who would be crying then? Chris, Jonathan, Clay and their friends would be crying to the world that the government was wasting money all these years running such a system! (<a href="http://www.keebler.net/blog/2007/01/10/passport-canada-is-error-500d-to-hell/">source</a> &#8211; &#8220;Jo Blo&#8221;)
</p></blockquote>
<p>And on my friend&#8217;s blog:</p>
<blockquote><p>
do you know anything about security… whiner</p>
<p>if you can’t even figure out who built it you must be a simpleton.. oh yeah u use a mac … (<a href="http://www.postal-code.com/mrhappy/blog/?p=884">source</a> &#8211; &#8220;dl&#8221;)
</p></blockquote>
<p>
Well today a &#8220;situation&#8221; popped-up that &#8220;in order to safeguard existing systems and to maintain the integrity of CRA&#8217;s taxpayer information holdings, Mr Dorais ordered tax filing processes halted.&#8221; (<a href="http://www.cra-arc.gc.ca/newsroom/releases/2007/march/nr070306-e.html">source</a>).  From the CRA commissioner, &#8220;The security of taxpayer information remains paramount as we strive to understand and correct this situation&#8221; (<a href="http://www.citynews.ca/news/news_8515.aspx">source</a>).  Maybe they finally got it through their heads that ePass is <em>not</em> secure.
</p>
<p>
It&#8217;s a difficult situation since a rewrite of their system would take months, and tax season is upon us.  But I&#8217;m not sure how safe I, or anyone else, should feel if we&#8217;re using <del>their</del> our fundamentally flawed system to file our taxes this year.
</p>
<p>
A final note, although the <a href="http://www.cra-arc.gc.ca/">CRA website</a> turned off their ePass component, <a href="http://www.pptc.gc.ca/can/pol_on-line_form.aspx?lang=e">Passport on-line</a> is still up-and-running (and open to exploit).
</p>
<p>
<strong>UPDATE:</strong> Looks like they might have just taken the site down because of some <a href="http://www.thestar.com/News/article/189175">&#8220;computer work done on the weekend&#8221;</a>.  *sigh*  I&#8217;m sure it&#8217;ll be back soon, and just as crap-tas-tic <img src='http://www.keebler.net/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  (Thanks for the update, <a href="http://tinfoilhattery.wordpress.com/">Mike</a>)
</p>
<p>
<strong>UPDATE #2:</strong> To add insult to injury:</p>
<blockquote><p>
&#8220;<strong>The security and integrity of taxpayer data has not been compromised</strong>. This problem is not the result of illegal activity, computer hackers or a virus.</p>
<p>We have now traced the source of the problem to software maintenance conducted on March 4, 2007. We are currently working to bring all systems back online gradually.&#8221; (<a href="http://www.cra-arc.gc.ca/newsroom/factsheets/2007/march/fs070307-e.html">source</a>)
</p></blockquote>


<p>Related posts:<ol><li><a href='http://www.keebler.net/blog/2007/01/12/epass-canada-is-not-secure/' rel='bookmark' title='Permanent Link: ePass Canada is not Secure'>ePass Canada is not Secure</a> <small> If you&#8217;re Canadian and have recently tried filing your...</small></li><li><a href='http://www.keebler.net/blog/2005/10/25/tamiflu-sales-suspended-in-canada/' rel='bookmark' title='Permanent Link: Tamiflu Sales Suspended in Canada'>Tamiflu Sales Suspended in Canada</a> <small> I guess so many Canadians read my blog that...</small></li><li><a href='http://www.keebler.net/blog/2007/12/06/passport-canada-security-breach-i-told-you-almost-a-year-ago/' rel='bookmark' title='Permanent Link: Passport Canada security breach: I told you almost a year ago'>Passport Canada security breach: I told you almost a year ago</a> <small> Back in January, I blogged about the security holes...</small></li></ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.keebler.net/blog/2007/03/07/epasscanada-revenue-agency-online-tax-filing-suspended/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Diggbaiting</title>
		<link>http://www.keebler.net/blog/2007/02/16/diggbaiting/</link>
		<comments>http://www.keebler.net/blog/2007/02/16/diggbaiting/#comments</comments>
		<pubDate>Fri, 16 Feb 2007 19:50:55 +0000</pubDate>
		<dc:creator>Jonathan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://www.keebler.net/blog/2007/02/16/diggbaiting/</guid>
		<description><![CDATA[
As I was misrepresenting this news story on Digg as a story about Colin Farrell (it turns out, the guy just looks like him), it came to me that this would be a cool way to manipulate Digg.


Say your site, and another site, were competing with the same content to get digged first/the most.  [...]


Related posts:<ol><li><a href='http://www.keebler.net/blog/2006/08/23/mod-swarm/' rel='bookmark' title='Permanent Link: Mod Swarm'>Mod Swarm</a> <small>moderation swarm [mod-uh-rey-shuhn swawrm] -noun Commonly called: mod swarm Interactive...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>
As I was misrepresenting <a href="http://www.citynews.ca/news/news_7927.aspx">this news story</a> on <a href="http://digg.com/celebrity/Colin_Farrell_Arrested_in_Toronto">Digg as a story about Colin Farrell</a> (it turns out, <a href="http://www.citynews.ca/images/2007-02/feb1607-carsuspect-12.jpg">the guy just looks like him</a>), it came to me that this would be a cool way to manipulate <a href="http://www.digg.com">Digg</a>.
</p>
<p>
Say your site, and another site, were competing with the same content to get digged first/the most.  This is often the case with news organizations since they cull most of their news off the syndication feeds.
</p>
<p>
If you wanted to make sure your competition&#8217;s story didn&#8217;t rise on Digg, you could just make sure that the moment it is posted, you digg it first with an incorrect title and description (something no one would ever click on).  Since you can&#8217;t submit the same URL twice to digg, it wouldn&#8217;t be possible for anyone to correct the reference.  Then you can digg your own story on the same topic, and if you can get the diggs, you will rise to the top of the digg <a href="http://www.keebler.net/blog/2006/08/23/mod-swarm/">mod swarm</a>.
</p>
<p>
Anyhow, I&#8217;m not suggesting anyone take advantage of Digg in this way, but it looks like there is a slight crack in their moderation scheme.  I think I&#8217;ll have to coin the term &#8216;diggbaiting&#8217; to describe this exploit <img src='http://www.keebler.net/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />
</p>
<p>
<strong>UPDATE:</strong> <a href="http://www.kuro5hin.org/story/2007/2/14/131127/709">Here&#8217;s an article</a> toting the end of Digg, partly because of the factors I&#8217;ve mentioned.  Oh, Digg.  Everyone is teaming up on you today.  Time to cache out, Kevin (Rose) <img src='http://www.keebler.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>


<p>Related posts:<ol><li><a href='http://www.keebler.net/blog/2006/08/23/mod-swarm/' rel='bookmark' title='Permanent Link: Mod Swarm'>Mod Swarm</a> <small>moderation swarm [mod-uh-rey-shuhn swawrm] -noun Commonly called: mod swarm Interactive...</small></li></ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.keebler.net/blog/2007/02/16/diggbaiting/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Log-in to my blog with your Yahoo! account</title>
		<link>http://www.keebler.net/blog/2007/02/10/login-to-my-blog-with-your-yahoo-account/</link>
		<comments>http://www.keebler.net/blog/2007/02/10/login-to-my-blog-with-your-yahoo-account/#comments</comments>
		<pubDate>Sat, 10 Feb 2007 05:29:21 +0000</pubDate>
		<dc:creator>Jonathan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Development]]></category>

		<guid isPermaLink="false">http://www.keebler.net/blog/2007/02/10/login-to-my-blog-with-your-yahoo-account/</guid>
		<description><![CDATA[
Feel like logging into my blog with your Yahoo! account for no particular reason?  Then please feel free to login here: https://login.yahoo.com/config/login?&#038;.done=http://www.keebler.net.  Don&#8217;t worry, I&#8217;m not stealing your password or anything; you&#8217;re using the real Yahoo!.


I&#8217;m been noticing lately how much information web developers applications are giving away in the query string.  [...]


Related posts:<ol><li><a href='http://www.keebler.net/blog/2006/03/12/yahoo-ui-library/' rel='bookmark' title='Permanent Link: Yahoo! UI Library'>Yahoo! UI Library</a> <small> I don&#8217;t know if I trust this company called...</small></li><li><a href='http://www.keebler.net/blog/2005/11/09/yahoo-maps-beta/' rel='bookmark' title='Permanent Link: Yahoo! Maps Beta'>Yahoo! Maps Beta</a> <small> It looks like Yahoo! Maps is coming along nicely....</small></li><li><a href='http://www.keebler.net/blog/2007/04/27/unfortunate-placement-of-yahoo-ad/' rel='bookmark' title='Permanent Link: Unfortunate placement of Yahoo ad'>Unfortunate placement of Yahoo ad</a> <small>If you don&#8217;t get this, you probably shouldn&#8217;t be on...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>
Feel like logging into my blog with your Yahoo! account for no particular reason?  Then please feel free to login here: <a href="https://login.yahoo.com/config/login?&#038;.done=http://www.keebler.net">https://login.yahoo.com/config/login?&#038;.done=<strong>http://www.keebler.net</strong></a>.  Don&#8217;t worry, I&#8217;m not stealing your password or anything; you&#8217;re using the real Yahoo!.
</p>
<p>
I&#8217;m been noticing lately how much information web <del>developers</del> applications are giving away in the query string.  In this case I can&#8217;t really do anything besides redirect to my site, but holes like these make it really easy for <a href="http://en.wikipedia.org/wiki/Phishing">phishers</a> to look legit, and trick people into giving them personal information (or worse).
</p>
<p>
For example, what if you went to a URL starting with <strong>https</strong>://login.yahoo.com, entered your correct username/password, then we taken to another <em>fake</em> page, that looks just like the &#8220;Incorrect password&#8221; screen from Yahoo!, where you are asked for your username/password again.  Would you really be sure to check the URL again?  I think 99% of people would offer up their username/password to the hacker.
</p>
<p>
Anyhow, you get my point <img src='http://www.keebler.net/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />   Security good.  Phishing bad.  Yahoo! vulnerable.  *grunt*
</p>
<p><a href="https://login.yahoo.com/config/login?&#038;.done=http://www.keebler.net"><img src="http://www.keebler.net/blog/wp-content/images/2007/02/YahooLogin.png" width="300" height="188" alt="Yahoo Login Window" /></a></p>


<p>Related posts:<ol><li><a href='http://www.keebler.net/blog/2006/03/12/yahoo-ui-library/' rel='bookmark' title='Permanent Link: Yahoo! UI Library'>Yahoo! UI Library</a> <small> I don&#8217;t know if I trust this company called...</small></li><li><a href='http://www.keebler.net/blog/2005/11/09/yahoo-maps-beta/' rel='bookmark' title='Permanent Link: Yahoo! Maps Beta'>Yahoo! Maps Beta</a> <small> It looks like Yahoo! Maps is coming along nicely....</small></li><li><a href='http://www.keebler.net/blog/2007/04/27/unfortunate-placement-of-yahoo-ad/' rel='bookmark' title='Permanent Link: Unfortunate placement of Yahoo ad'>Unfortunate placement of Yahoo ad</a> <small>If you don&#8217;t get this, you probably shouldn&#8217;t be on...</small></li></ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.keebler.net/blog/2007/02/10/login-to-my-blog-with-your-yahoo-account/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ePass Canada is not Secure</title>
		<link>http://www.keebler.net/blog/2007/01/12/epass-canada-is-not-secure/</link>
		<comments>http://www.keebler.net/blog/2007/01/12/epass-canada-is-not-secure/#comments</comments>
		<pubDate>Fri, 12 Jan 2007 05:59:32 +0000</pubDate>
		<dc:creator>Jonathan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Development]]></category>

		<guid isPermaLink="false">http://www.keebler.net/blog/2007/01/12/epass-canada-is-not-secure/</guid>
		<description><![CDATA[
If you&#8217;re Canadian and have recently tried filing your taxes online, ordering a passport, or changing your address, you&#8217;re familiar with the ePass Canada system.  Chris and I have already detailed how frustrating it is to use, but my experience has also revealed that the system is fundamentally unsecure.  Obviously I&#8217;m not willing [...]


Related posts:<ol><li><a href='http://www.keebler.net/blog/2007/03/07/epasscanada-revenue-agency-online-tax-filing-suspended/' rel='bookmark' title='Permanent Link: ePass/Canada Revenue Agency Online Tax Filing Suspended'>ePass/Canada Revenue Agency Online Tax Filing Suspended</a> <small> A couple of months ago, I blogged about the...</small></li><li><a href='http://www.keebler.net/blog/2007/12/06/passport-canada-security-breach-i-told-you-almost-a-year-ago/' rel='bookmark' title='Permanent Link: Passport Canada security breach: I told you almost a year ago'>Passport Canada security breach: I told you almost a year ago</a> <small> Back in January, I blogged about the security holes...</small></li><li><a href='http://www.keebler.net/blog/2005/09/26/free-secure-email-certificate/' rel='bookmark' title='Permanent Link: Free Secure Email Certificate'>Free Secure Email Certificate</a> <small> Never a bad idea to sign or encrypt your...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>
If you&#8217;re Canadian and have recently tried filing your taxes online, ordering a passport, or changing your address, you&#8217;re familiar with the ePass Canada system.  <a href="http://www.postal-code.com/mrhappy/blog/?p=884">Chris</a> and <a href="http://www.keebler.net/blog/2007/01/10/passport-canada-is-error-500d-to-hell/">I</a> have already detailed how frustrating it is to use, but my experience has also revealed that the system is fundamentally unsecure.  Obviously I&#8217;m not willing to demonstrate exactly how a hack could be executed against the system (I&#8217;m not <em>that</em> stupid) but I can outline the secure risk in broad-terms.
</p>
<p>
If you&#8217;re a web-developer and you&#8217;ve never head of <a href="http://en.wikipedia.org/wiki/Cross_site_scripting">cross-site scripting</a>, take an hour and read up on it.  It&#8217;s probably the number one open exploit on the web, and if you haven&#8217;t heard of it, it&#8217;s probably open on your site.  In its simplest form, it allows malicious hackers to put up fake login forms (or anything else they want) on a legitimate website and trick visitors into giving away sensitive information.
</p>
<p>
For example, they could make a page on the government domain <a href="http://www.gc.ca">gc.ca</a>, secured by SSL, that looks exactly like the ePass login form  and trick you into giving the hacker your username and password (a process known as <a href="http://en.wikipedia.org/wiki/Phishing">phishing</a>).  They can even make it look like you&#8217;ve logged in successfully, and if you trust the ePass system, would you really have a second thought to giving them your social insurance number, credit card number, or any other document?
</p>
<p>
So I ask, why is this big, gaping hole (sorry for the goatse imagery) in the ePass Canada system?!  Millions of tax dollars were spent on this program, and it&#8217;s completely open to exploit by the lowliest of hackers.  We have (and I have to admit that I had to google this one) a <a href="http://www.psepc.gc.ca/prg/em/ccirc/index-en.asp">Canadian Cyber Incident Response Centre (CCIRC)</a> that is documenting <a href="http://www.psepc.gc.ca/prg/em/ccirc/2006/av06-035-en.asp">every security hole in Firefox</a> but they aren&#8217;t analyzing the government&#8217;s own online system?  <a href="http://www.futureshop.ca">FutureShop.ca</a> is more secure than the ePass system!
</p>
<p>
In the end, it&#8217;s up to you whether you use the ePass system or not.  There&#8217;s no way I&#8217;d file my taxes on paper, so I&#8217;ll probably continue using it myself.  But rest-assured that someone (whose a much better &#8220;hacker&#8221; than I) has also seen these same security holes, and if they haven&#8217;t exploited them already, it&#8217;s just a matter of time.  If they already had, would we even know about it? <img src='http://www.keebler.net/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /></p>


<p>Related posts:<ol><li><a href='http://www.keebler.net/blog/2007/03/07/epasscanada-revenue-agency-online-tax-filing-suspended/' rel='bookmark' title='Permanent Link: ePass/Canada Revenue Agency Online Tax Filing Suspended'>ePass/Canada Revenue Agency Online Tax Filing Suspended</a> <small> A couple of months ago, I blogged about the...</small></li><li><a href='http://www.keebler.net/blog/2007/12/06/passport-canada-security-breach-i-told-you-almost-a-year-ago/' rel='bookmark' title='Permanent Link: Passport Canada security breach: I told you almost a year ago'>Passport Canada security breach: I told you almost a year ago</a> <small> Back in January, I blogged about the security holes...</small></li><li><a href='http://www.keebler.net/blog/2005/09/26/free-secure-email-certificate/' rel='bookmark' title='Permanent Link: Free Secure Email Certificate'>Free Secure Email Certificate</a> <small> Never a bad idea to sign or encrypt your...</small></li></ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.keebler.net/blog/2007/01/12/epass-canada-is-not-secure/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
