January 21, 2007

Truth in advertising --or-- Archer Farms Margherita pizza dissapoints

Ok, I know frozen pizza is frozen pizza, but this is totally ridiculous. I LOVE margherita pizzas, but will *NEVER* buy this one again unless Archer Farms decides to improve the recipe and quality of this product.

Yeah, the picture and product really look close...

January 05, 2007

Post #100 - Protecting yourself (and your company)

Sadly, there are bad people out in the world and the virtual world. Many coffee shops and bars offer free (read:unencrypted) WiFi to their patrons. This service is very convienent and fun; hey, who wants to work in an office setting when you could be hoisting a frothy beverage (coffee or beer, your choice) in the comfortable setting with your laptop and a few friends???

The problem is, no one believes there is a bad person lurking at a coffee shop, just waiting for you to enter your domain username and password to access corporate email/intranet/eBay/PayPal/Hotmail/your bank...

Are you protecting yourself and your company? I ran across an article titled How to protect yourself at wireless hot spots which offers some simple tips and techniques on protecting your data. Here are the highlights from this article:

1. Disable ad-hoc mode -- PLEASE PLEASE do this; it is so simple and the cost of using ad-hoc mode far outweigh the benefits from a security standpoint.
2. File Sharing -- many people doen't even know much about this, so if you don't know how to use it, reduce your attack surface and TURN IT OFF! Even if you think you know how to use it, make sure you are only sharing what you intend to share with the world. I know, your mom always told you to share, but if she would have known about unencrypted WiFi, she would have put on the disclaimer!!! :)
3. Turn off network discovery (Vista only) - I have not fired up Vista yet, so I have nothing intelligent to add here....
4. Carry an encrypted USB flash drive - I like this one; I don't own one of these yet, but suspect I will be picking one up very soon; not so much for storing my OS on it, but strictly for data...
5. Protect yourself with a virtual private network - VPN == goodness; 'nuff said
6. Disable your wireless adapter - ok, this maybe is not a reality, but it *IS* a possibility
7. Watch out for shoulder surfers - The security mantra of "Social engineering trumps most security systems" applies here!

Happy new year and 'safe' surfing!!

jk

Stock touting and a cute little HTML trick

Stock Touting


While reading an artcile about how stock-spammers make money (you know, the emails saying a particular stock is going to be hot), I followed the research link to a Harvard web page titled Spam Works: Evidence from Stock Touts and Corresponding Market Activity. I enjoyed playing with the stock simulator at the harvard site also which simulates the scenario from both spammer and spam recipient point-of-view. It is hard to believe that this kind of social engineering works, but the facts don't lie. :) The only thing I could even *remotely* consider doing on these would be to buy short!!!!!!



A cute little HTML trick


While reading the Harvard page, I noticed this text: "If the email addresses are unreadable, click here. They cannot be copied/pasted directly from this page." which naturally made me try to highlight the authors' email address and copy them. As advertised, it appeared to mangle the email address. After looking into it a bit more, I figured out the little trick: the web page author used a combination of the PRE tag along with a STYLE attribute. I'll show this below: first with no 'style' attribute so you can see the 'real' text and then with the style attribute of "line-height: 0px" to see the obfuscated text. (I will change the email addresses of the real authors to protect their addresses...). They used the 2 line technique, multiple lines also works (as shown below).



Un-Obfuscated


r b t p o m i . o
o o @ o k a l c m


Obfuscated (2 lines)


r b t p o m i . o
o o @ o k a l c m


Obfuscated (3 lines)


r o p k i c
o t o m l o
b @ o a . m




Wrapup



1. If spammers can't make money (by stock touting and every other nefarious ploy, they'll stop spamming.
2. Try out this fun little HTML trick! It should help slow down unsophisticated email collectors, and if nothing else, it is like a little parlour trick to impress your geeky friends :)




jk

January 04, 2007

Not even PDFs are safe - Security hole in Acrobat Plugin

A plugin for Acrobat Reader has a major security hole, so please, please, please be careful and only open trusted PDFs for a while until a patch is available.

from: http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9007051&source=NLT_SEC&nlid=38

"January 03, 2007 (IDG News Service) -- Security researchers are poring over what one vendor has called a "breathtaking" weakness in the Web browser plug-in for Adobe Systems Inc.'s Acrobat Reader program used to open files in the popular Portable Document Format. "


Browse safely!
jk

December 13, 2006

C00D2EEF Unable to locate the media server. The operation timed out.

While toting my laptop between home and my client, I need to change the internet settings for proxy server and automatic configuration script. I had accidentally left my proxy server checked when I got home and then installed the Zune software. Naturally the Zune media player took the settings from Internet Explorer (you *ARE* on IE 7.0, right? :) ).

Becuase of this, I was able to view and search in Zune Marketplace, but could not connect to the media server. These settings are located under Options -> Playback -> More Options... -> Network tab, and then find HTTP in the listview and configure the proxy properly.

Hopefully no one else runs into this, but if you do....

jk

Zune, Baby!

I'm sitting here listening to Sour Girl by STP on my new Zune (this year's fabulous Holiday gift from Magenic). I'm on the 14 day pass right now and will definitely be doing some exploring! :)

More to come on the Zune experience...


jk

November 12, 2006

.NET 3.0 links

We're all excited that .NET 3.0 is here. Here are a few links and comments to help you out...


If you have previous versions of .NET 3.0, PLEASE PLEASE PLEASE do yourself and your friends a huge favor and run the Pre-released Microsoft .NET Framework 3.0 Uninstall Tool.


Once you've installed, the RTM link to .NET 3.0 is: here


UPDATE: 11/30/2006 : 3:11pm
Apparently i'm not the only one happy about .NET 3.0 shipping.  Aaron Skonnard just posted a link of Doug and Don dancing and singing on channel 9


jk

Code Camp 2006 - What a great day

The inaugural Twin Cities Code Camp was yesterday at New Horizons of Minnesota in Edina, MN.  I don't have the exact stats, but I heard there about 140 attended!


The facilities were first rate, Magenic provided plenty of pizza and soda for lunch, and the camaraderie was excellent.  I saw .Net people talking to Ruby people talking to Java people; it really warmed the heart :)


I attended the following sessions:



  • Neil Iversen's SharePoint as a Development Platform
  • Jason Bock's State of Languages in the CLR
  • Robert Boedigheimer's Utilizing .NET Cryptography
  • Andy Morrison's Building Reusable Business Processes in BizTalk
  • (my session) Securing Web Serivces in WCF
  • Scot Yokiel's Intro to WCF

Being a security enthusiast, Robert's session was one of my favorites. It distilled the essence of hashing and crypto into very tidy, bite-sized pieces to digest. Grab the slides/code and check it out. Robert has a really nice demo on how to tamperproof querystrings, which Schwans.com has implemented.


The content was first rate, I got to meet a lot of people, see a lot of old friends, learned a lot (technical and about presenting) and the post-event speaker party was good clean fun as well.


Thanks again to Jason Bock for getting this started.  Thanks to all of you who attended, presented and sponsored food/prizes.  I'm looking forward to the next one (April 2007???)!


jk

November 07, 2006

Some Halloween pairing wisdom from Mr. Fowler

I was catching up on some blogs this afternoon and ran across this one from Martin Fowler's posted on 10/31/2006...


http://martinfowler.com/bliki/PairProgrammingMisconceptions.html


From my experience, XP/Agile has a lot to do with doing what makes sense in development and getting rid of the stuff that doesn't and if something is 'Agile', very little is mandated or else it wouldn't be very 'Agile', right? :)


I've been on teams where pairing is done.  One particular project we did a lot of pair programming which turned out very nice IMHO.  There were few bugs, we hit our estimates and the code was clean and well-factored.  Most importantly, the client loved it and it solved a real business problem!!!


Another pairing benefit (which Mr. Fowler alludes to in his final point) is in the area of code reviews (you *ALL* do code reviews, right?).  Just like documentation, security, and testing, code reviews are sadly one of the first qualities to go when a project gets behind because “there's not time to do it”, even when the reality is that “there's not time not to do it”.  I see too much poor quality code get written and developers spending too much time firefighting because of hastily constructed in “heroic code“.


The final point in Mr. Fowler's post is about code smell; I have nothing to add except “RIGHT ON”!  Developers constantly raise the layer of abstraction to raise productivity which is why we don't write business apps in assembly anymore.  Duplicated code stinks, espically when there is a bug in it and it gets copied throughout the organization...grrr...


I think developers should give pairing more thought; if for no other reason than to reduce the chance of carpal tunnel syndrome by 50% :) 


jk