<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tewha &#187; security</title>
	<atom:link href="http://tewha.net/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://tewha.net</link>
	<description>Links and writings on software development, mostly for iPhone and Mac OS X.</description>
	<lastBuildDate>Sun, 07 Mar 2010 22:57:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Sorry, but accepting Flash is potentially devastating to me</title>
		<link>http://tewha.net/2010/03/sorry-but-accepting-flash-is-potentially-devastating-to-me/</link>
		<comments>http://tewha.net/2010/03/sorry-but-accepting-flash-is-potentially-devastating-to-me/#comments</comments>
		<pubDate>Sun, 07 Mar 2010 09:53:41 +0000</pubDate>
		<dc:creator>Steven Fisher</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Adobe Flash]]></category>
		<category><![CDATA[advertising]]></category>
		<category><![CDATA[Ars Technica]]></category>
		<category><![CDATA[bad ideas]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://tewha.net/?p=1103</guid>
		<description><![CDATA[Ars Technica Why Ad Blocking is devastating to the sites you love:
If you read a site and care about its well being, then you should not block ads or you subscribe to sites like Ars that offer ads-free versions of the site. If a site has advertising you dont agree with, dont go there. I think it is [...]]]></description>
			<content:encoded><![CDATA[<p>Ars Technica <a href="http://arstechnica.com/business/news/2010/03/why-ad-blocking-is-devastating-to-the-sites-you-love.ars">Why Ad Blocking is devastating to the sites you love</a>:</p>
<blockquote><p>If you read a site and care about its well being, then you should not block ads or you subscribe to sites like Ars that offer ads-free versions of the site. If a site has advertising you dont agree with, dont go there. I think it is far better to vote with page views than to show up and consume resources without giving anything in return.</p></blockquote>
<p>Let's be clear here: I don't run an ad blocker. I do run a <a href="http://www.adobe.com/products/flashplayer/">Flash</a> blocker, because <em>Flash</em> is unstable and insecure. And no, I will not white-list you to let you load Flash automatically.</p>
<p>And before you ask, you can't have my root password either.</p>
<p>I also don't keep a list of sites I'm not welcomed at. For the half dozen times a year I read a story on Ars (at most), I'm not going to feel guilty either.</p>
<p>Look, in the comments you have admitted you don't control the content of the Flash:</p>
<blockquote><p>We don't allow ads with non-user initiated sound. So unless you interact with the ad you shouldn't hear a thing. If you ever do then let us know so we can fix it/nuke it.</p></blockquote>
<p>If ads make sound uninvited, <em>tell you</em>?!? <strong>Are you serious?</strong> What if they use some new Flash exploit to root around and steal my private key, or otherwise execute <a href="http://www.adobe.com/support/security/bulletins/apsb09-01.html">arbitrary code</a> on my computer?</p>
<p>Should I tell you then, too?</p>
<p>The first step to getting on my white list is to write your own Flash, not just serve someone else's. Taking people's security that cavalierly probably should be criminal.</p>
<p>You can't just say "Oh, that's on Adobe." By now you know <a href="http://secunia.com/advisories/product/20166/?task=statistics">what an insecure mess Flash is</a>.</p>
<p>If you serve me HTML ads, I'll be happy to view them. I'm not sure if you've heard, but it turns out that you can do <a href="http://html5demos.com/">a lot of cool things with HTML</a>.</p>
<p>Also I just checked, and Javascript <a href="http://www.adobe.com/products/flashplayer/download/detection_kit/">can (indirectly) detect my Flash blocker</a>. There's no reason you should try to blame users like me rather than take the responsibility on yourself. The difference between my Mac and an iPhone is that you're able to detect the latter without much effort, but the former would take a little more effort on your part.</p>
<p>Look, I'm sorry I cost you a fraction of a penny. But the potential pain for me in choosing to run Flash is far, far greater. And if you really cared about your users, you'd know that and have moved on from Flash already. Don't try to lay a guilt trip <em>on me</em>!</p>
<p>I'll see you in six months. Not intentionally, that'll just be the next time I have reason to visit Ars. Maybe you'll have this sorted out by then.</p>
]]></content:encoded>
			<wfw:commentRss>http://tewha.net/2010/03/sorry-but-accepting-flash-is-potentially-devastating-to-me/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Not everyone is ethical</title>
		<link>http://tewha.net/2008/03/not-everyone-is-ethical/</link>
		<comments>http://tewha.net/2008/03/not-everyone-is-ethical/#comments</comments>
		<pubDate>Sat, 08 Mar 2008 17:09:27 +0000</pubDate>
		<dc:creator>Steven Fisher</dc:creator>
				<category><![CDATA[Link]]></category>
		<category><![CDATA[ethics]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Software Development]]></category>

		<guid isPermaLink="false">http://tewha.net/2008/03/not-everyone-is-ethical/</guid>
		<description><![CDATA[Of course, we know this. But it's still a bit shocking to me to see something like this.
John Terry, the apparent creator, hard coded his username and password to his gmail account in source code. All right, not the smartest thing in the world to do, but then I noticed that every time a user [...]]]></description>
			<content:encoded><![CDATA[<p>Of course, we know this. But it's still a bit shocking to me <a href="http://www.codinghorror.com/blog/archives/001072.html">to see something like this</a>.</p>
<blockquote><p>John Terry, the apparent creator, hard coded his username and password to his gmail account in source code. All right, not the smartest thing in the world to do, but then I noticed that every time a user adds their account to the program to back up their data, it sends and email with their username and password to his personal email box!</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://tewha.net/2008/03/not-everyone-is-ethical/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple claims fix to Time Machine security bug</title>
		<link>http://tewha.net/2008/02/apple-claims-fix-to-time-machine-security-bug/</link>
		<comments>http://tewha.net/2008/02/apple-claims-fix-to-time-machine-security-bug/#comments</comments>
		<pubDate>Mon, 11 Feb 2008 22:52:52 +0000</pubDate>
		<dc:creator>Steven Fisher</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[Mac OS X Leopard]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[timemachine]]></category>

		<guid isPermaLink="false">http://tewha.net/2008/02/apple-claims-fix-to-time-machine-security-bug/</guid>
		<description><![CDATA[Apple claims to have fixed the issue where applications could run automatically out of a Time Machine backup. Look for CVE-2008-0038 in Apple's About the security content of Mac OS X 10.5.2 and Security Update 2008-001 .
Thanks to Apple for mentioning me. I certainly would have reported the bug regardless, but it's a nice bonus.
The [...]]]></description>
			<content:encoded><![CDATA[<p>Apple claims to have fixed the issue where applications could run automatically <a href="http://tewha.net/2007/11/mac-os-x-runs-deleted-applications/">out of a Time Machine backup</a>. Look for CVE-2008-0038 in Apple's <a href="http://docs.info.apple.com/article.html?artnum=307430">About the security content of Mac OS X 10.5.2 and Security Update 2008-001 </a>.</p>
<p>Thanks to Apple for mentioning me. I certainly would have reported the bug regardless, but it's a nice bonus.</p>
<p>The only thing I wish had happened differently was an earlier acknowledgement from Apple that they realized what I was describing and agreed it was a security problem. I didn't find out Apple considered it a problem until January 22nd, when they asked how I'd like to be credited for discovery. Most of that time I wondered if I should file more details in an attempt to convince them it really was a problem.</p>
<p>Note: I'm saying "claims" only because I haven't installed the update and verified the fix yet. I have no reason to disbelieve Apple. <img src='http://tewha.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://tewha.net/2008/02/apple-claims-fix-to-time-machine-security-bug/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>iPhone Dev Center forces &quot;challenge-response&quot; system</title>
		<link>http://tewha.net/2007/10/iphone-dev-center-forces-challenge-response-system/</link>
		<comments>http://tewha.net/2007/10/iphone-dev-center-forces-challenge-response-system/#comments</comments>
		<pubDate>Thu, 25 Oct 2007 00:34:51 +0000</pubDate>
		<dc:creator>Steven Fisher</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Hall of Shame]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://pyile.com/2007/10/iphone-dev-center-forces-challenge-response-system/</guid>
		<description><![CDATA[The new iPhone Dev Center forces a challenge response system. This is a problem at the best of times, but it's especially bad when the available questions are so lame.
What is the name of your hometown?
Google will give you this.
What did you study in college?
Google will give you this. Or you could just guess. It [...]]]></description>
			<content:encoded><![CDATA[<p>The new iPhone Dev Center forces a challenge response system. This is a problem at the best of times, but it's especially bad when the available questions are so lame.</p>
<p>What is the name of your hometown?</p>
<p>Google will give you this.</p>
<p>What did you study in college?</p>
<p>Google will give you this. Or you could just guess. It isn't really a mystery.<sup>1</sup></p>
<p>What was your first job?</p>
<p>Google will give you this.</p>
<p>Favorite pet's name?</p>
<p>You can't find this on Google, but you could ask any of my friends.</p>
<p>Name of oldest sibling?</p>
<p>Google will give you this.</p>
<p>I'd rather lose access to an account forever than have someone else get into it. This kind of system needs to remain optional. So whatever's in the iPhone Dev Center? I won't see it. The only impact on me that the reorganization had was locking me out.</p>
<ol class="footnotes"><li id="footnote_0_330" class="footnote">Hint: A lot of other software developers probably studied the same thing.</li></ol>]]></content:encoded>
			<wfw:commentRss>http://tewha.net/2007/10/iphone-dev-center-forces-challenge-response-system/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
