<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>UNEASYsilence &#187; Privacy</title>
	<atom:link href="http://uneasysilence.com/archive/category/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://uneasysilence.com</link>
	<description></description>
	<lastBuildDate>Sun, 22 Nov 2009 01:52:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Reason 3,423 Why I Don&#8217;t Use Social Networks</title>
		<link>http://uneasysilence.com/archive/2008/03/13094/</link>
		<comments>http://uneasysilence.com/archive/2008/03/13094/#comments</comments>
		<pubDate>Tue, 25 Mar 2008 16:37:33 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://uneasysilence.com/archive/2008/03/13094/</guid>
		<description><![CDATA[<p>Hello, My name is Dan and I do not use &#8220;social networks&#8221;.  I don&#8217;t have a MySpace, Don&#8217;t use &#8220;Facebook&#8221;, Don&#8217;t have an Orkut etc.  Reason being, one of these days something you posted many years ago will bit you in the ass.</p>
<p>Yes, you know who you are.  Remember the picture you posted online of you smoking pot and getting frisky with an inflatable chair?  Yea, thats not gonna go over so well with the new employers.  Regardless if you are posting information on social sites as &#8220;private&#8221; or &#8220;friends only&#8221; information WILL leak out the only question is when.  It&#8217;s &#8220;Dan&#8217;s law of suckness&#8221; (™ and ® UNEASYsilence :P ).</p>
<p>Normally its a friend who thinks its cute to download a picture off your profile and email it to another friend, but now the networks themselves are doing the leaks for you.  Previously <a href="http://uneasysilence.com/archive/2007/01/9244/">MySpace</a> had a bug where anyone (via a special url) could see anybodies private pictures.  Now it&#8217;s Facebooks turn!</p>
<blockquote><p>A security lapse made it possible for unwelcome strangers to peruse personal photos posted on Facebook Inc.&#8217;s popular online hangout, circumventing a recent upgrade to the Web site&#8217;s privacy controls.<br />
The Associated Press verified the loophole Monday after receiving a tip from a Byron Ng, a Vancouver, Canada computer technician. Ng began looking for security weaknesses last week after Facebook unveiled more ways for 67 million members to restrict access to their personal profiles.<br />
But the added protections weren&#8217;t enough to prevent Ng from pulling up the most recent pictures posted by Facebook members and their friends, even if the privacy settings were set to restrict the audience to a select few.<br />
After being alerted Monday afternoon, Facebook spokeswoman Brandee Barker said the Palo Alto-based company fixed the bug within an hour.</p></blockquote>
<p>Next time you want to post evidence of your <a href="http://uneasysilence.com/archive/2007/11/12647/">drunken debauchery</a> or say something really crazy and radical &#8211; you may want to give that a second thought now.</p>
<p><a href="http://ap.google.com/article/ALeqM5ijANq3fmx9AZNNrf7Q1PwCN1cKUAD8VK51UG1">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2007/08/11834/" rel="bookmark">Do you have a Facebook?  The CIA Knows</a></li><li><a href="http://uneasysilence.com/archive/2007/06/11284/" rel="bookmark">Your FaceBook Profile Is/ In Not Private</a></li><li><a href="http://uneasysilence.com/archive/2008/06/13275/" rel="bookmark">The Social Scene Heats Up! Facebook vs MySpace vs Google</a></li><li><a href="http://uneasysilence.com/archive/2008/04/13157/" rel="bookmark">Experiencng Facebook Spam?</a></li><li><a href="http://uneasysilence.com/archive/2006/07/7122/" rel="bookmark">Apple &amp; Facebook partner up</a></li></ul></div><div style="display:block"><small><em><a href="http://uneasysilence.com/archive/2008/03/13094/#comments">Leave A Comment</a></em></small></div>]]></description>
			<content:encoded><![CDATA[<p>Hello, My name is Dan and I do not use &#8220;social networks&#8221;.  I don&#8217;t have a MySpace, Don&#8217;t use &#8220;Facebook&#8221;, Don&#8217;t have an Orkut etc.  Reason being, one of these days something you posted many years ago will bit you in the ass.</p>
<p>Yes, you know who you are.  Remember the picture you posted online of you smoking pot and getting frisky with an inflatable chair?  Yea, thats not gonna go over so well with the new employers.  Regardless if you are posting information on social sites as &#8220;private&#8221; or &#8220;friends only&#8221; information WILL leak out the only question is when.  It&#8217;s &#8220;Dan&#8217;s law of suckness&#8221; (™ and ® UNEASYsilence :P ).</p>
<p>Normally its a friend who thinks its cute to download a picture off your profile and email it to another friend, but now the networks themselves are doing the leaks for you.  Previously <a href="http://uneasysilence.com/archive/2007/01/9244/">MySpace</a> had a bug where anyone (via a special url) could see anybodies private pictures.  Now it&#8217;s Facebooks turn!</p>
<blockquote><p>A security lapse made it possible for unwelcome strangers to peruse personal photos posted on Facebook Inc.&#8217;s popular online hangout, circumventing a recent upgrade to the Web site&#8217;s privacy controls.<br />
The Associated Press verified the loophole Monday after receiving a tip from a Byron Ng, a Vancouver, Canada computer technician. Ng began looking for security weaknesses last week after Facebook unveiled more ways for 67 million members to restrict access to their personal profiles.<br />
But the added protections weren&#8217;t enough to prevent Ng from pulling up the most recent pictures posted by Facebook members and their friends, even if the privacy settings were set to restrict the audience to a select few.<br />
After being alerted Monday afternoon, Facebook spokeswoman Brandee Barker said the Palo Alto-based company fixed the bug within an hour.</p></blockquote>
<p>Next time you want to post evidence of your <a href="http://uneasysilence.com/archive/2007/11/12647/">drunken debauchery</a> or say something really crazy and radical &#8211; you may want to give that a second thought now.</p>
<p><a href="http://ap.google.com/article/ALeqM5ijANq3fmx9AZNNrf7Q1PwCN1cKUAD8VK51UG1">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2007/08/11834/" rel="bookmark">Do you have a Facebook?  The CIA Knows</a></li><li><a href="http://uneasysilence.com/archive/2007/06/11284/" rel="bookmark">Your FaceBook Profile Is/ In Not Private</a></li><li><a href="http://uneasysilence.com/archive/2008/06/13275/" rel="bookmark">The Social Scene Heats Up! Facebook vs MySpace vs Google</a></li><li><a href="http://uneasysilence.com/archive/2008/04/13157/" rel="bookmark">Experiencng Facebook Spam?</a></li><li><a href="http://uneasysilence.com/archive/2006/07/7122/" rel="bookmark">Apple &amp; Facebook partner up</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://uneasysilence.com/archive/2008/03/13094/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>G-Archiver Steals Your Gmail Password</title>
		<link>http://uneasysilence.com/archive/2008/03/13052/</link>
		<comments>http://uneasysilence.com/archive/2008/03/13052/#comments</comments>
		<pubDate>Tue, 11 Mar 2008 18:31:28 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://uneasysilence.com/archive/2008/03/13052/</guid>
		<description><![CDATA[<p>The nifty Gmail backup utility seems to have (possibly maliciously) collected the GMail logins of the programs users.</p>
<blockquote><p>This was discovered when a developer named Dustin Brooks took a look at the code using a decompiler. He discovered a Gmail account name and password embedded in the source code. Brooks logged in and found over 1,700 emails all with user account information — with his own at the top. According to a story in Informationweek, he deleted the emails, changed the account password, and notified Google.</p></blockquote>
<p>The developer of G-Archiver, says the code to collect users GMail logins was debug code that should have been stripped out of the shipping version and a patch will be available shortly.</p>
<p>Sneaky what some programmers are capable of.</p>
<p><a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=206902839">Read More</a> [<a href="http://it.slashdot.org/it/08/03/11/1723206.shtml">via</a>]</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2005/09/4066/" rel="bookmark">How to send e-mails from any address using Gmail's SMTP server</a></li><li><a href="http://uneasysilence.com/archive/2005/08/4017/" rel="bookmark">Sign up for Gmail via SMS</a></li><li><a href="http://uneasysilence.com/archive/2006/05/6519/" rel="bookmark">Encrypt your Gmail messages</a></li><li><a href="http://uneasysilence.com/archive/2006/05/6313/" rel="bookmark">Gmail adds contact pictures to users</a></li><li><a href="http://uneasysilence.com/archive/2005/12/4750/" rel="bookmark">Gmail 'FTP' via Firefox 1.5</a></li></ul></div><div style="display:block"><small><em><a href="http://uneasysilence.com/archive/2008/03/13052/#comments">Leave A Comment</a></em></small></div>]]></description>
			<content:encoded><![CDATA[<p>The nifty Gmail backup utility seems to have (possibly maliciously) collected the GMail logins of the programs users.</p>
<blockquote><p>This was discovered when a developer named Dustin Brooks took a look at the code using a decompiler. He discovered a Gmail account name and password embedded in the source code. Brooks logged in and found over 1,700 emails all with user account information — with his own at the top. According to a story in Informationweek, he deleted the emails, changed the account password, and notified Google.</p></blockquote>
<p>The developer of G-Archiver, says the code to collect users GMail logins was debug code that should have been stripped out of the shipping version and a patch will be available shortly.</p>
<p>Sneaky what some programmers are capable of.</p>
<p><a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=206902839">Read More</a> [<a href="http://it.slashdot.org/it/08/03/11/1723206.shtml">via</a>]</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2005/09/4066/" rel="bookmark">How to send e-mails from any address using Gmail's SMTP server</a></li><li><a href="http://uneasysilence.com/archive/2005/08/4017/" rel="bookmark">Sign up for Gmail via SMS</a></li><li><a href="http://uneasysilence.com/archive/2006/05/6519/" rel="bookmark">Encrypt your Gmail messages</a></li><li><a href="http://uneasysilence.com/archive/2006/05/6313/" rel="bookmark">Gmail adds contact pictures to users</a></li><li><a href="http://uneasysilence.com/archive/2005/12/4750/" rel="bookmark">Gmail 'FTP' via Firefox 1.5</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://uneasysilence.com/archive/2008/03/13052/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>And So It Begins:  Congress Doesn&#8217;t Extend Warrantless Wiretaps and Telcom Immunity</title>
		<link>http://uneasysilence.com/archive/2008/02/12980/</link>
		<comments>http://uneasysilence.com/archive/2008/02/12980/#comments</comments>
		<pubDate>Fri, 15 Feb 2008 19:15:30 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://uneasysilence.com/archive/2008/02/12980/</guid>
		<description><![CDATA[<p>In an interesting turn of events the House did not approve (or even hold a vote on) the FISA Surveillance Law allowing it to expire.</p>
<blockquote><p>The House broke for a week’s recess Thursday without renewing terrorist surveillance authority demanded by President Bush, leading him to warn of risky intelligence gaps while Democrats accused him of reckless fear mongering.</p>
<p>The refusal of Speaker Nancy Pelosi, Democrat of California, to schedule a vote on a surveillance measure approved Tuesday by the Senate touched off an intense partisan conflict over the national security questions that have colored federal elections since 2002 and are likely to play a significant role again in November. [...]</p>
<p>The main sticking point is a provision in the Senate bill that provides legal immunity for telecommunications companies that, at the Bush administration’s request, cooperated in providing private data after the Sept. 11, 2001, attacks. Many House Democrats oppose that immunity.</p>
<p>Surveillance efforts will not cease when the law lapses. Administration intelligence officials said agencies would be able to continue eavesdropping on targets that have already been approved for a year after the initial authorization. But they said any new targets would have to go through the more burdensome standards in place before last August, which would require that they establish probable cause that an international target is connected to a terrorist group.</p>
<p>Intelligence officials also told reporters Thursday that they were worried that telecommunications companies would be less willing to cooperate in future wiretapping unless they were given immunity.</p></blockquote>
<p>I find it hysterical that the law is providing immunity to phone companies for doing something the US refuses to acknowledge that they did.  Meanwhile, the telecom companies have admitted to the fact they broke the law assisting the government with warrantless wiretapping.  Get ready for some real interesting weeks of the House and White House playing chicken.</p>
<p><a href="http://www.nytimes.com/2008/02/15/washington/15fisa.html">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2007/08/11741/" rel="bookmark">Wiretapping Law Expanded</a></li><li><a href="http://uneasysilence.com/archive/2006/09/7756/" rel="bookmark">President Bush: Immunity from "War Crimes"?</a></li><li><a href="http://uneasysilence.com/archive/2006/07/7053/" rel="bookmark">Justice Department, Whats that?</a></li><li><a href="http://uneasysilence.com/archive/2007/01/9097/" rel="bookmark">All Your Mail are Belong to Us</a></li><li><a href="http://uneasysilence.com/archive/2006/06/6649/" rel="bookmark">No Sir Mr.Net Neutrality</a></li></ul></div><div style="display:block"><small><em><a href="http://uneasysilence.com/archive/2008/02/12980/#comments">Leave A Comment</a></em></small></div>]]></description>
			<content:encoded><![CDATA[<p>In an interesting turn of events the House did not approve (or even hold a vote on) the FISA Surveillance Law allowing it to expire.</p>
<blockquote><p>The House broke for a week’s recess Thursday without renewing terrorist surveillance authority demanded by President Bush, leading him to warn of risky intelligence gaps while Democrats accused him of reckless fear mongering.</p>
<p>The refusal of Speaker Nancy Pelosi, Democrat of California, to schedule a vote on a surveillance measure approved Tuesday by the Senate touched off an intense partisan conflict over the national security questions that have colored federal elections since 2002 and are likely to play a significant role again in November. [...]</p>
<p>The main sticking point is a provision in the Senate bill that provides legal immunity for telecommunications companies that, at the Bush administration’s request, cooperated in providing private data after the Sept. 11, 2001, attacks. Many House Democrats oppose that immunity.</p>
<p>Surveillance efforts will not cease when the law lapses. Administration intelligence officials said agencies would be able to continue eavesdropping on targets that have already been approved for a year after the initial authorization. But they said any new targets would have to go through the more burdensome standards in place before last August, which would require that they establish probable cause that an international target is connected to a terrorist group.</p>
<p>Intelligence officials also told reporters Thursday that they were worried that telecommunications companies would be less willing to cooperate in future wiretapping unless they were given immunity.</p></blockquote>
<p>I find it hysterical that the law is providing immunity to phone companies for doing something the US refuses to acknowledge that they did.  Meanwhile, the telecom companies have admitted to the fact they broke the law assisting the government with warrantless wiretapping.  Get ready for some real interesting weeks of the House and White House playing chicken.</p>
<p><a href="http://www.nytimes.com/2008/02/15/washington/15fisa.html">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2007/08/11741/" rel="bookmark">Wiretapping Law Expanded</a></li><li><a href="http://uneasysilence.com/archive/2006/09/7756/" rel="bookmark">President Bush: Immunity from "War Crimes"?</a></li><li><a href="http://uneasysilence.com/archive/2006/07/7053/" rel="bookmark">Justice Department, Whats that?</a></li><li><a href="http://uneasysilence.com/archive/2007/01/9097/" rel="bookmark">All Your Mail are Belong to Us</a></li><li><a href="http://uneasysilence.com/archive/2006/06/6649/" rel="bookmark">No Sir Mr.Net Neutrality</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://uneasysilence.com/archive/2008/02/12980/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Uh Oh.  Google Search Bar Hijacking Server Error Pages!</title>
		<link>http://uneasysilence.com/archive/2008/02/12966/</link>
		<comments>http://uneasysilence.com/archive/2008/02/12966/#comments</comments>
		<pubDate>Tue, 12 Feb 2008 15:48:56 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://uneasysilence.com/archive/2008/02/12966/</guid>
		<description><![CDATA[<p>Seems that users who install the latest version of the Google search bar are finding that Google is hijacking a servers 404 error page.</p>
<blockquote><p>Google grabs the 404 error code returned to the web browser in certain situations and instead of displaying the 404 error page of the website you are on, it creates a custom 404 error page &#8211; made by Google. The “new” 404 error page ‘conveniently’ includes a Google search box and if used by a visitor will drive the visitor away from your website. Even worse &#8211; the search box is pre-populated with data from the initial URL query on your website. Imagine a situation where kind of sensitive data is send to Google that way. Even normal data would make it to Google that way and we all know what Google does with data. For me as a webmaster this is a major intrusion into my own intellectual property.</p></blockquote>
<p>In the wild west of the internet keeps evolving these problems will keep popping up.  Hopefully Google will reverse its decision to hijack error pages, just as Verisign abandoned <a href="http://www.internetnews.com/bus-news/article.php/3080071">Sitefinder</a> (well with a little pressure).</p>
<p><a href="http://seoker.com/2008/02/11/google-hijacking-404-error-pages/">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2006/09/7505/" rel="bookmark">Finally! Useful error pages for Mozilla browsers</a></li><li><a href="http://uneasysilence.com/archive/2008/09/13506/" rel="bookmark">Cablevision Hijacks Error Pages (Verisign Site Finder Redux)</a></li><li><a href="http://uneasysilence.com/archive/2004/08/844/" rel="bookmark">Google Is Run By Pigeons</a></li><li><a href="http://uneasysilence.com/archive/2007/12/12780/" rel="bookmark">Don't let Google mobilize your website, specify Mowser instead</a></li><li><a href="http://uneasysilence.com/archive/2006/02/5471/" rel="bookmark">Google Pages in active beta</a></li></ul></div><div style="display:block"><small><em><a href="http://uneasysilence.com/archive/2008/02/12966/#comments">Leave A Comment</a></em></small></div>]]></description>
			<content:encoded><![CDATA[<p>Seems that users who install the latest version of the Google search bar are finding that Google is hijacking a servers 404 error page.</p>
<blockquote><p>Google grabs the 404 error code returned to the web browser in certain situations and instead of displaying the 404 error page of the website you are on, it creates a custom 404 error page &#8211; made by Google. The “new” 404 error page ‘conveniently’ includes a Google search box and if used by a visitor will drive the visitor away from your website. Even worse &#8211; the search box is pre-populated with data from the initial URL query on your website. Imagine a situation where kind of sensitive data is send to Google that way. Even normal data would make it to Google that way and we all know what Google does with data. For me as a webmaster this is a major intrusion into my own intellectual property.</p></blockquote>
<p>In the wild west of the internet keeps evolving these problems will keep popping up.  Hopefully Google will reverse its decision to hijack error pages, just as Verisign abandoned <a href="http://www.internetnews.com/bus-news/article.php/3080071">Sitefinder</a> (well with a little pressure).</p>
<p><a href="http://seoker.com/2008/02/11/google-hijacking-404-error-pages/">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2006/09/7505/" rel="bookmark">Finally! Useful error pages for Mozilla browsers</a></li><li><a href="http://uneasysilence.com/archive/2008/09/13506/" rel="bookmark">Cablevision Hijacks Error Pages (Verisign Site Finder Redux)</a></li><li><a href="http://uneasysilence.com/archive/2004/08/844/" rel="bookmark">Google Is Run By Pigeons</a></li><li><a href="http://uneasysilence.com/archive/2007/12/12780/" rel="bookmark">Don't let Google mobilize your website, specify Mowser instead</a></li><li><a href="http://uneasysilence.com/archive/2006/02/5471/" rel="bookmark">Google Pages in active beta</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://uneasysilence.com/archive/2008/02/12966/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Useful Free Tool: Use OpenDNS to Block Ads</title>
		<link>http://uneasysilence.com/archive/2008/02/12961/</link>
		<comments>http://uneasysilence.com/archive/2008/02/12961/#comments</comments>
		<pubDate>Mon, 11 Feb 2008 16:29:15 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Geeky]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://uneasysilence.com/archive/2008/02/12961/</guid>
		<description><![CDATA[<p><center><img src='http://uneasysilence.com/media/2008/02/zz4e1eeb82.jpg' alt='zz4e1eeb82.jpg' /></center></p>
<p>Tired of online ads like I am?  I have Firefox&#8217;s <a href="https://addons.mozilla.org/en-US/firefox/addon/1865">Adblock Plus</a> and <a href="http://safariadblock.sourceforge.net/">Safari AdBlock</a> installed on my computer, but it becomes rather annoying to keep installing these applications on my multiple machines as well as every time I format them.  To make ad blocking simpler I opted to use OpenDNS to block ads on the DNS level.</p>
<p>To make this hack work you must configure your router to use OpenDNS&#8217;s servers (trust me you will want to do this anyway &#8211; their servers are FAST!) by following <a href="http://www.opendns.com/support/category/2">the OpenDNS tutorials</a>.  Secondly you must signup for a free <a href="https://www.opendns.com/dashboard/create/">OpenDNS account</a> so you can setup network filters.</p>
<p><center><img src='http://uneasysilence.com/media/2008/02/zz06900456.png' alt='zz06900456.png' /></center></p>
<p>Once that is done navigate to the <strong>Domain Blocking</strong> feature under the <strong>Filtering</strong> category.  Once you click on that add the following domains into the filter:</p>
<p><code>ad.doubleclick.net<br />
adlog.com.com<br />
adservices.google.com<br />
googleadservices.com<br />
googlesyndication.com<br />
pagead2.googlesyndication.com<br />
servedby.advertising.com<br />
view.atdmt.com<br />
mm.chitika.net<br />
ctxt.tribalfusion.com<br />
intellitxt.com</code></p>
<p>These few domains are responsible for a vast majority of the ads on the internet.  For a more comprehensive list you may want to check out all the domains listed on this <a href="http://www.pierceive.com/filtersetg/2007-10-08a-MERGED.txt">directory</a>.</p>
<p>No, OpenDNS is not as good as dedicated AdBlocking applications but for a simple network wide fix this seems to do the trick and I hope in the future OpenDNS offers a true Adblock feature.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2007/06/11069/" rel="bookmark">OpenDNS Does Content Filtering</a></li><li><a href="http://uneasysilence.com/archive/2006/07/7063/" rel="bookmark">OpenDNS friend or enemy?</a></li><li><a href="http://uneasysilence.com/archive/2008/09/13506/" rel="bookmark">Cablevision Hijacks Error Pages (Verisign Site Finder Redux)</a></li><li><a href="http://uneasysilence.com/archive/2008/10/13567/" rel="bookmark">AT&T Offers Free WiFi to iPhone and Blackberry Users... Now Here is How to Use It on Your Laptop</a></li><li><a href="http://uneasysilence.com/archive/2008/03/13078/" rel="bookmark">iPhone Gets Safari Ad Blocking</a></li></ul></div><div style="display:block"><small><em><a href="http://uneasysilence.com/archive/2008/02/12961/#comments">Leave A Comment</a></em></small></div>]]></description>
			<content:encoded><![CDATA[<p><center><img src='http://uneasysilence.com/media/2008/02/zz4e1eeb82.jpg' alt='zz4e1eeb82.jpg' /></center></p>
<p>Tired of online ads like I am?  I have Firefox&#8217;s <a href="https://addons.mozilla.org/en-US/firefox/addon/1865">Adblock Plus</a> and <a href="http://safariadblock.sourceforge.net/">Safari AdBlock</a> installed on my computer, but it becomes rather annoying to keep installing these applications on my multiple machines as well as every time I format them.  To make ad blocking simpler I opted to use OpenDNS to block ads on the DNS level.</p>
<p>To make this hack work you must configure your router to use OpenDNS&#8217;s servers (trust me you will want to do this anyway &#8211; their servers are FAST!) by following <a href="http://www.opendns.com/support/category/2">the OpenDNS tutorials</a>.  Secondly you must signup for a free <a href="https://www.opendns.com/dashboard/create/">OpenDNS account</a> so you can setup network filters.</p>
<p><center><img src='http://uneasysilence.com/media/2008/02/zz06900456.png' alt='zz06900456.png' /></center></p>
<p>Once that is done navigate to the <strong>Domain Blocking</strong> feature under the <strong>Filtering</strong> category.  Once you click on that add the following domains into the filter:</p>
<p><code>ad.doubleclick.net<br />
adlog.com.com<br />
adservices.google.com<br />
googleadservices.com<br />
googlesyndication.com<br />
pagead2.googlesyndication.com<br />
servedby.advertising.com<br />
view.atdmt.com<br />
mm.chitika.net<br />
ctxt.tribalfusion.com<br />
intellitxt.com</code></p>
<p>These few domains are responsible for a vast majority of the ads on the internet.  For a more comprehensive list you may want to check out all the domains listed on this <a href="http://www.pierceive.com/filtersetg/2007-10-08a-MERGED.txt">directory</a>.</p>
<p>No, OpenDNS is not as good as dedicated AdBlocking applications but for a simple network wide fix this seems to do the trick and I hope in the future OpenDNS offers a true Adblock feature.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2007/06/11069/" rel="bookmark">OpenDNS Does Content Filtering</a></li><li><a href="http://uneasysilence.com/archive/2006/07/7063/" rel="bookmark">OpenDNS friend or enemy?</a></li><li><a href="http://uneasysilence.com/archive/2008/09/13506/" rel="bookmark">Cablevision Hijacks Error Pages (Verisign Site Finder Redux)</a></li><li><a href="http://uneasysilence.com/archive/2008/10/13567/" rel="bookmark">AT&T Offers Free WiFi to iPhone and Blackberry Users... Now Here is How to Use It on Your Laptop</a></li><li><a href="http://uneasysilence.com/archive/2008/03/13078/" rel="bookmark">iPhone Gets Safari Ad Blocking</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://uneasysilence.com/archive/2008/02/12961/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>RapidShare To Be Shutdown?</title>
		<link>http://uneasysilence.com/archive/2008/01/12904/</link>
		<comments>http://uneasysilence.com/archive/2008/01/12904/#comments</comments>
		<pubDate>Tue, 29 Jan 2008 16:00:49 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://uneasysilence.com/archive/2008/01/12904/</guid>
		<description><![CDATA[<p>German based RapidShare seems to have a bit of legal troubles on their hands.  German music companies have taken Rapidshare to court and have secured an order to stop its users from downloading infringing music tracks from its servers, or be shut down.</p>
<blockquote><p>Last week we reported on rumors that Rapidshare had, or was about to be, shut down, rumors that now look likely to resurface. The company, one of the world’s largest ‘one-click’ file hosting services, has lost a copyright infringement case against German performing rights outfit, GEMA. Representing a claimed 60,000 members and more than 1 million rights owners worldwide, GEMA has taken an aggressive stance in pursuing legal action against Rapidshare, trying to force it to be accountable for the infringing actions of its users.</p>
<p>For its part, Rapidshare has always insisted that it cannot be held responsible for these actions, such as when users upload copyright works (in this case, music) to their servers for subsequent downloading by others.</p>
<p>On 23 January 2008, the district court in Düsseldorf (Landgericht) disagreed with this assertion after GEMA succeeded in convincing the court that Rapidshare should take responsibility for infringements carried out within its service.</p>
<p>GEMA are trying to imply that as a result of the decision, Rapidshare will be forced to take preventative action to stop GEMA works from even getting onto their servers, rather than a DMCA-style after-the-fact removal. GEMA says that if Rapidshare are forced to filter they will likely end up with a service that’s not worth operating, so they may decide to shut it down completely.</p></blockquote>
<p><a href="http://torrentfreak.com/rapidshare-to-be-forced-to-shut-down-following-court-defeat-080129/">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2005/11/4667/" rel="bookmark">Download DVD Decrypter and DVDShrink</a></li><li><a href="http://uneasysilence.com/archive/2005/10/4446/" rel="bookmark">SNAP! - Apple's Photobooth application has leaked</a></li><li><a href="http://uneasysilence.com/archive/2007/10/12438/" rel="bookmark">Rapidshare1 Searches for Rapidshare Files</a></li><li><a href="http://uneasysilence.com/archive/2005/11/4528/" rel="bookmark">UH OH!  Confessions on a Dance Floor LEAKED!</a></li><li><a href="http://uneasysilence.com/archive/2006/07/6899/" rel="bookmark">RapidShare Premium accounts for free</a></li></ul></div><div style="display:block"><small><em><a href="http://uneasysilence.com/archive/2008/01/12904/#comments">Leave A Comment</a></em></small></div>]]></description>
			<content:encoded><![CDATA[<p>German based RapidShare seems to have a bit of legal troubles on their hands.  German music companies have taken Rapidshare to court and have secured an order to stop its users from downloading infringing music tracks from its servers, or be shut down.</p>
<blockquote><p>Last week we reported on rumors that Rapidshare had, or was about to be, shut down, rumors that now look likely to resurface. The company, one of the world’s largest ‘one-click’ file hosting services, has lost a copyright infringement case against German performing rights outfit, GEMA. Representing a claimed 60,000 members and more than 1 million rights owners worldwide, GEMA has taken an aggressive stance in pursuing legal action against Rapidshare, trying to force it to be accountable for the infringing actions of its users.</p>
<p>For its part, Rapidshare has always insisted that it cannot be held responsible for these actions, such as when users upload copyright works (in this case, music) to their servers for subsequent downloading by others.</p>
<p>On 23 January 2008, the district court in Düsseldorf (Landgericht) disagreed with this assertion after GEMA succeeded in convincing the court that Rapidshare should take responsibility for infringements carried out within its service.</p>
<p>GEMA are trying to imply that as a result of the decision, Rapidshare will be forced to take preventative action to stop GEMA works from even getting onto their servers, rather than a DMCA-style after-the-fact removal. GEMA says that if Rapidshare are forced to filter they will likely end up with a service that’s not worth operating, so they may decide to shut it down completely.</p></blockquote>
<p><a href="http://torrentfreak.com/rapidshare-to-be-forced-to-shut-down-following-court-defeat-080129/">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2005/11/4667/" rel="bookmark">Download DVD Decrypter and DVDShrink</a></li><li><a href="http://uneasysilence.com/archive/2005/10/4446/" rel="bookmark">SNAP! - Apple's Photobooth application has leaked</a></li><li><a href="http://uneasysilence.com/archive/2007/10/12438/" rel="bookmark">Rapidshare1 Searches for Rapidshare Files</a></li><li><a href="http://uneasysilence.com/archive/2005/11/4528/" rel="bookmark">UH OH!  Confessions on a Dance Floor LEAKED!</a></li><li><a href="http://uneasysilence.com/archive/2006/07/6899/" rel="bookmark">RapidShare Premium accounts for free</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://uneasysilence.com/archive/2008/01/12904/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>The Day The Internet Died &#8211; AT&amp;T Considering Mandatory Content Filtering</title>
		<link>http://uneasysilence.com/archive/2008/01/12830/</link>
		<comments>http://uneasysilence.com/archive/2008/01/12830/#comments</comments>
		<pubDate>Wed, 09 Jan 2008 14:32:23 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://uneasysilence.com/archive/2008/01/12830/</guid>
		<description><![CDATA[<p>At CES in a not so smoke filled room AT&#038;T and other ISP&#8217;s are considering filtering copyrighted content on the network level.  Yup, that&#8217;s right.  Your ISP&#8217;s routers will filter content for you.</p>
<blockquote><p>At a small panel discussion about digital piracy here at NBC’s booth on the Consumer Electronics Show floor, representatives from NBC, Microsoft, several digital filtering companies and telecom giant AT&#038;T said the time was right to start filtering for copyrighted content at the network level.</p>
<p>Network-level filtering means your Internet service provider – Comcast, AT&#038;T, EarthLink, or whoever you send that monthly check to – could soon start sniffing your digital packets, looking for material that infringes on someone’s copyright.</p>
<p>“What we are already doing to address piracy hasn’t been working. There’s no secret there,” said James Cicconi, senior vice president, external &#038; legal affairs for AT&#038;T.</p></blockquote>
<p>This is OUTRAGEOUS.  ISP&#8217;s are protected by safe harbor provisions that shield them from their users activities.  Why would they want to burden themselves withe the responsibility to filter content.  How will they know what is legitimate or not legitimate.  What ever happened to net neutrality?  What happened to a users privacy.  Anybody as angered by this as I am.</p>
<p><a href="http://bits.blogs.nytimes.com/2008/01/08/att-and-other-isps-may-be-getting-ready-to-filter/">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2007/06/11069/" rel="bookmark">OpenDNS Does Content Filtering</a></li><li><a href="http://uneasysilence.com/archive/2007/05/10577/" rel="bookmark">Managing WordPress (Akisment) spam is easy with Simple Spam Filter</a></li><li><a href="http://uneasysilence.com/archive/2007/06/11095/" rel="bookmark">AT&amp;T to randomly search personal files</a></li><li><a href="http://uneasysilence.com/archive/2008/03/13101/" rel="bookmark">Comcast Teams Up With BitTorrent, Promises to Be Net Neutral</a></li><li><a href="http://uneasysilence.com/archive/2006/02/5500/" rel="bookmark">The great Internet Extortion</a></li></ul></div><div style="display:block"><small><em><a href="http://uneasysilence.com/archive/2008/01/12830/#comments">Leave A Comment</a></em></small></div>]]></description>
			<content:encoded><![CDATA[<p>At CES in a not so smoke filled room AT&#038;T and other ISP&#8217;s are considering filtering copyrighted content on the network level.  Yup, that&#8217;s right.  Your ISP&#8217;s routers will filter content for you.</p>
<blockquote><p>At a small panel discussion about digital piracy here at NBC’s booth on the Consumer Electronics Show floor, representatives from NBC, Microsoft, several digital filtering companies and telecom giant AT&#038;T said the time was right to start filtering for copyrighted content at the network level.</p>
<p>Network-level filtering means your Internet service provider – Comcast, AT&#038;T, EarthLink, or whoever you send that monthly check to – could soon start sniffing your digital packets, looking for material that infringes on someone’s copyright.</p>
<p>“What we are already doing to address piracy hasn’t been working. There’s no secret there,” said James Cicconi, senior vice president, external &#038; legal affairs for AT&#038;T.</p></blockquote>
<p>This is OUTRAGEOUS.  ISP&#8217;s are protected by safe harbor provisions that shield them from their users activities.  Why would they want to burden themselves withe the responsibility to filter content.  How will they know what is legitimate or not legitimate.  What ever happened to net neutrality?  What happened to a users privacy.  Anybody as angered by this as I am.</p>
<p><a href="http://bits.blogs.nytimes.com/2008/01/08/att-and-other-isps-may-be-getting-ready-to-filter/">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2007/06/11069/" rel="bookmark">OpenDNS Does Content Filtering</a></li><li><a href="http://uneasysilence.com/archive/2007/05/10577/" rel="bookmark">Managing WordPress (Akisment) spam is easy with Simple Spam Filter</a></li><li><a href="http://uneasysilence.com/archive/2007/06/11095/" rel="bookmark">AT&amp;T to randomly search personal files</a></li><li><a href="http://uneasysilence.com/archive/2008/03/13101/" rel="bookmark">Comcast Teams Up With BitTorrent, Promises to Be Net Neutral</a></li><li><a href="http://uneasysilence.com/archive/2006/02/5500/" rel="bookmark">The great Internet Extortion</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://uneasysilence.com/archive/2008/01/12830/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Adobe Formally Speaks About 192.168.112.2o7.net and Spying Concerns</title>
		<link>http://uneasysilence.com/archive/2008/01/12827/</link>
		<comments>http://uneasysilence.com/archive/2008/01/12827/#comments</comments>
		<pubDate>Wed, 09 Jan 2008 02:53:24 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://uneasysilence.com/archive/2008/01/12827/</guid>
		<description><![CDATA[<p>Seems that I set the internet ablaze when I raised the issue that <a href="http://uneasysilence.com/archive/2007/12/12789/">Adobe applications that called home</a>.  During the firestorm, I was able to talk to MANY individuals in Adobe &#8211; specifically John Nack &#8211; who stood on the firing line fiercely defending the company that employs him.</p>
<p>He writes:</p>
<blockquote><p>The welcome screen (screenshot) that’s available in some Adobe CS3 applications (Flash, Fireworks, Dreamweaver, Illustrator, and InDesign) is designed to show fresh, relevant news and information.  For that reason it loads a Flash SWF file that&#8217;s hosted on Adobe.com, just as a Web browser would do.  When the SWF gets loaded, it pings the Omniture server to record the event.  As noted previously, no personal information is uploaded in that exchange. [...]</p>
<p>Q.: Why does Adobe use a server whose name is so suspicious-looking?<br />
A.: I&#8217;m afraid the answer is that we don’t really know.  The fact is that this SWF tracking code already existed on the Macromedia side at the time the companies merged, and it was adopted without change by a number of products for CS3.  The people who wrote the code originally did not document why they used that server name, and we can’t find anyone who remembers.  I&#8217;m sorry we aren’t able to provide a more solid, definitive explanation.</p>
<p>Q.: Follow-on: Given that you can’t give a good reason why Adobe is using a server whose name is so suspicious, are you going to change the name?<br />
A.: Absolutely.  We are working with Omniture on this right now, and will make this change as soon as we can.  (I don&#8217;t know how long this will take, but will post here when I do.)</p>
<p>Longer-term (in future releases), we&#8217;ll do a better job of explaining what the apps are doing of the network and why.  I think we can enable some really amazing user experiences by bringing the desktop &#038; online worlds closer together, and that most people will want to participate in those.  The key thing is that they be given the choice, and that they be made aware of what&#8217;s going on.</p></blockquote>
<p>Kudos, John.  You did a VERY good job at explaining why Adobe apps connect to the Internet.  From this lesson Adobe will hopefully learn to carefully scrutinize WHO they do business with and to give users CHOICE regarding how their applications interact with the internet.  They will now hopefully better disclose better what is ticking in their super secret source code.</p>
<p>After getting to know John I can say that he is profoundly concerned about this issue and will be working hard to achieve all the goals he promised &#8211; he has the power to do it.</p>
<p>ALL programmers take note, we are watching!  You are on notice!  All we ask is that you clearly disclose WHAT information you collect and what you do with it.</p>
<p><a href="http://blogs.adobe.com/jnack/2008/01/adobe_and_omnit.html">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2006/02/5224/" rel="bookmark">Sorry no Adobe for MacTel for some time.</a></li><li><a href="http://uneasysilence.com/archive/2008/02/12994/" rel="bookmark">Video Remixing In Danger? Adobe Messing Around With Flash DRM</a></li><li><a href="http://uneasysilence.com/archive/2007/01/9095/" rel="bookmark">The Photoshop CS3 Serial Number *CAN* be used Cross Platform</a></li><li><a href="http://uneasysilence.com/archive/2007/12/12789/" rel="bookmark">Lies, Lies and Adobe Spies</a></li><li><a href="http://uneasysilence.com/archive/2008/06/13249/" rel="bookmark">The Apple Adobe Spat Continues.   Flash Available for iPhone, but Only in Lab</a></li></ul></div><div style="display:block"><small><em><a href="http://uneasysilence.com/archive/2008/01/12827/#comments">Leave A Comment</a></em></small></div>]]></description>
			<content:encoded><![CDATA[<p>Seems that I set the internet ablaze when I raised the issue that <a href="http://uneasysilence.com/archive/2007/12/12789/">Adobe applications that called home</a>.  During the firestorm, I was able to talk to MANY individuals in Adobe &#8211; specifically John Nack &#8211; who stood on the firing line fiercely defending the company that employs him.</p>
<p>He writes:</p>
<blockquote><p>The welcome screen (screenshot) that’s available in some Adobe CS3 applications (Flash, Fireworks, Dreamweaver, Illustrator, and InDesign) is designed to show fresh, relevant news and information.  For that reason it loads a Flash SWF file that&#8217;s hosted on Adobe.com, just as a Web browser would do.  When the SWF gets loaded, it pings the Omniture server to record the event.  As noted previously, no personal information is uploaded in that exchange. [...]</p>
<p>Q.: Why does Adobe use a server whose name is so suspicious-looking?<br />
A.: I&#8217;m afraid the answer is that we don’t really know.  The fact is that this SWF tracking code already existed on the Macromedia side at the time the companies merged, and it was adopted without change by a number of products for CS3.  The people who wrote the code originally did not document why they used that server name, and we can’t find anyone who remembers.  I&#8217;m sorry we aren’t able to provide a more solid, definitive explanation.</p>
<p>Q.: Follow-on: Given that you can’t give a good reason why Adobe is using a server whose name is so suspicious, are you going to change the name?<br />
A.: Absolutely.  We are working with Omniture on this right now, and will make this change as soon as we can.  (I don&#8217;t know how long this will take, but will post here when I do.)</p>
<p>Longer-term (in future releases), we&#8217;ll do a better job of explaining what the apps are doing of the network and why.  I think we can enable some really amazing user experiences by bringing the desktop &#038; online worlds closer together, and that most people will want to participate in those.  The key thing is that they be given the choice, and that they be made aware of what&#8217;s going on.</p></blockquote>
<p>Kudos, John.  You did a VERY good job at explaining why Adobe apps connect to the Internet.  From this lesson Adobe will hopefully learn to carefully scrutinize WHO they do business with and to give users CHOICE regarding how their applications interact with the internet.  They will now hopefully better disclose better what is ticking in their super secret source code.</p>
<p>After getting to know John I can say that he is profoundly concerned about this issue and will be working hard to achieve all the goals he promised &#8211; he has the power to do it.</p>
<p>ALL programmers take note, we are watching!  You are on notice!  All we ask is that you clearly disclose WHAT information you collect and what you do with it.</p>
<p><a href="http://blogs.adobe.com/jnack/2008/01/adobe_and_omnit.html">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2006/02/5224/" rel="bookmark">Sorry no Adobe for MacTel for some time.</a></li><li><a href="http://uneasysilence.com/archive/2008/02/12994/" rel="bookmark">Video Remixing In Danger? Adobe Messing Around With Flash DRM</a></li><li><a href="http://uneasysilence.com/archive/2007/01/9095/" rel="bookmark">The Photoshop CS3 Serial Number *CAN* be used Cross Platform</a></li><li><a href="http://uneasysilence.com/archive/2007/12/12789/" rel="bookmark">Lies, Lies and Adobe Spies</a></li><li><a href="http://uneasysilence.com/archive/2008/06/13249/" rel="bookmark">The Apple Adobe Spat Continues.   Flash Available for iPhone, but Only in Lab</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://uneasysilence.com/archive/2008/01/12827/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Beware the Fake FireFox Authorization Window</title>
		<link>http://uneasysilence.com/archive/2008/01/12801/</link>
		<comments>http://uneasysilence.com/archive/2008/01/12801/#comments</comments>
		<pubDate>Thu, 03 Jan 2008 17:59:52 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://uneasysilence.com/archive/2008/01/12801/</guid>
		<description><![CDATA[<p><center><img src='http://uneasysilence.com/media/2008/01/image_thumb.png' alt='image_thumb.png' /></center></p>
<p>These crafty hackers just won&#8217;t quit, will they?  The latest ploy hackers are trying is to deceive a user to think they are logging into a secure website, giving up their login credentials.</p>
<blockquote><p>Mozilla Firefox displays an authentication dialog, whenever the visited web server returns 401 status code, and the &#8220;WWW-Authenticate&#8221; header. In order to specify basic authentication, the &#8220;WWW-Authenticate&#8221; header should have the value [Basic realm="XXX"] (without the brackets). The Realm value, which in this case is XXX, will be displayed in the authentication dialog window.<br />
While Firefox does not display the characters in the &#8220;WWW-Authenticate&#8221; header Realm value after the last double-quotes (&#8221;), it fails to sanitize single-quotes (&#8217;) and spaces. This makes it possible for an attacker to create a specially crafted Realm value which will look as if the authentication dialog came from a trusted web site.</p></blockquote>
<p>Just just have to be sooooo aware on the internet these days because it is getting harder and heard to tell what is legitimate and what is fake.</p>
<p><a href="http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspx">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2006/11/8410/" rel="bookmark">How-to: Make OS X save dialog box useful</a></li><li><a href="http://uneasysilence.com/archive/2005/04/2382/" rel="bookmark">REVISITED: Kill those pesky Firefox popups</a></li><li><a href="http://uneasysilence.com/archive/2008/04/13151/" rel="bookmark">Make Your Website Look Spiffy When it is Busy</a></li><li><a href="http://uneasysilence.com/archive/2005/11/4699/" rel="bookmark">FoXpose: ExposÃ© within your Firefox 1.5 window</a></li><li><a href="http://uneasysilence.com/archive/2008/01/12919/" rel="bookmark">MacBook Air in the House, Unboxing Photos</a></li></ul></div><div style="display:block"><small><em><a href="http://uneasysilence.com/archive/2008/01/12801/#comments">Leave A Comment</a></em></small></div>]]></description>
			<content:encoded><![CDATA[<p><center><img src='http://uneasysilence.com/media/2008/01/image_thumb.png' alt='image_thumb.png' /></center></p>
<p>These crafty hackers just won&#8217;t quit, will they?  The latest ploy hackers are trying is to deceive a user to think they are logging into a secure website, giving up their login credentials.</p>
<blockquote><p>Mozilla Firefox displays an authentication dialog, whenever the visited web server returns 401 status code, and the &#8220;WWW-Authenticate&#8221; header. In order to specify basic authentication, the &#8220;WWW-Authenticate&#8221; header should have the value [Basic realm="XXX"] (without the brackets). The Realm value, which in this case is XXX, will be displayed in the authentication dialog window.<br />
While Firefox does not display the characters in the &#8220;WWW-Authenticate&#8221; header Realm value after the last double-quotes (&#8221;), it fails to sanitize single-quotes (&#8217;) and spaces. This makes it possible for an attacker to create a specially crafted Realm value which will look as if the authentication dialog came from a trusted web site.</p></blockquote>
<p>Just just have to be sooooo aware on the internet these days because it is getting harder and heard to tell what is legitimate and what is fake.</p>
<p><a href="http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspx">Read More</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2006/11/8410/" rel="bookmark">How-to: Make OS X save dialog box useful</a></li><li><a href="http://uneasysilence.com/archive/2005/04/2382/" rel="bookmark">REVISITED: Kill those pesky Firefox popups</a></li><li><a href="http://uneasysilence.com/archive/2008/04/13151/" rel="bookmark">Make Your Website Look Spiffy When it is Busy</a></li><li><a href="http://uneasysilence.com/archive/2005/11/4699/" rel="bookmark">FoXpose: ExposÃ© within your Firefox 1.5 window</a></li><li><a href="http://uneasysilence.com/archive/2008/01/12919/" rel="bookmark">MacBook Air in the House, Unboxing Photos</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://uneasysilence.com/archive/2008/01/12801/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Lies, Lies and Adobe Spies</title>
		<link>http://uneasysilence.com/archive/2007/12/12789/</link>
		<comments>http://uneasysilence.com/archive/2007/12/12789/#comments</comments>
		<pubDate>Thu, 27 Dec 2007 01:26:09 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://uneasysilence.com/archive/2007/12/12789/</guid>
		<description><![CDATA[<p><center><img src='http://uneasysilence.com/media/2007/12/zz1a5f0f0c.png' alt='zz1a5f0f0c.png' /></center></p>
<p>Yes, I am a tin foil hat guy.  The sky is falling, the NSA is listening and Adobe is watching how many times you open your programs.  Okay, the first two can&#8217;t be PROVEN but I can show you that Adobe is spying on users application habits.</p>
<p>When you launch a CS3 application the application pings out to what looks like an IP address &#8211; and internal IP address:  192.168.112.2O7.</p>
<p>That makes sense, right?  Adobe wants to be sure you aren&#8217;t running multiple copies of their programs&#8230;. Wait something is wrong here.</p>
<p>The first clue something is fishy is that I don&#8217;t use a 192.168.xxx.xxx numbering scheme in my network.  Secondly, if you look at the address <a href="http://obdev.at/products/littlesnitch/index.html">Little Snitch</a> is displaying, the last &#8220;numbers&#8221; of the IP address (<strong>2O7</strong>) look funny.  Also, IP address don&#8217;t end in any .com/net/org suffix.</p>
<p>Turns out that <a href="http://192.168.112.2o7.net/">192.168.112.2O7.net</a> is owned by <a href="http://www.omniture.com/">Omniture</a>, a huge behavioral analytics firm.  Hmmmmmm, anybody curious why Adobe is doing this?  Anybody care to sniff packets?  I sense an invasion of privacy here!</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2007/03/10079/" rel="bookmark">Amazon Reveals CS3 Details A Day Early</a></li><li><a href="http://uneasysilence.com/archive/2006/12/8792/" rel="bookmark">Adobe announces Photoshop CS3 Beta</a></li><li><a href="http://uneasysilence.com/archive/2006/02/5224/" rel="bookmark">Sorry no Adobe for MacTel for some time.</a></li><li><a href="http://uneasysilence.com/archive/2007/01/9095/" rel="bookmark">The Photoshop CS3 Serial Number *CAN* be used Cross Platform</a></li><li><a href="http://uneasysilence.com/archive/2008/01/12827/" rel="bookmark">Adobe Formally Speaks About 192.168.112.2o7.net and Spying Concerns</a></li></ul></div><div style="display:block"><small><em><a href="http://uneasysilence.com/archive/2007/12/12789/#comments">Leave A Comment</a></em></small></div>]]></description>
			<content:encoded><![CDATA[<p><center><img src='http://uneasysilence.com/media/2007/12/zz1a5f0f0c.png' alt='zz1a5f0f0c.png' /></center></p>
<p>Yes, I am a tin foil hat guy.  The sky is falling, the NSA is listening and Adobe is watching how many times you open your programs.  Okay, the first two can&#8217;t be PROVEN but I can show you that Adobe is spying on users application habits.</p>
<p>When you launch a CS3 application the application pings out to what looks like an IP address &#8211; and internal IP address:  192.168.112.2O7.</p>
<p>That makes sense, right?  Adobe wants to be sure you aren&#8217;t running multiple copies of their programs&#8230;. Wait something is wrong here.</p>
<p>The first clue something is fishy is that I don&#8217;t use a 192.168.xxx.xxx numbering scheme in my network.  Secondly, if you look at the address <a href="http://obdev.at/products/littlesnitch/index.html">Little Snitch</a> is displaying, the last &#8220;numbers&#8221; of the IP address (<strong>2O7</strong>) look funny.  Also, IP address don&#8217;t end in any .com/net/org suffix.</p>
<p>Turns out that <a href="http://192.168.112.2o7.net/">192.168.112.2O7.net</a> is owned by <a href="http://www.omniture.com/">Omniture</a>, a huge behavioral analytics firm.  Hmmmmmm, anybody curious why Adobe is doing this?  Anybody care to sniff packets?  I sense an invasion of privacy here!</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://uneasysilence.com/archive/2007/03/10079/" rel="bookmark">Amazon Reveals CS3 Details A Day Early</a></li><li><a href="http://uneasysilence.com/archive/2006/12/8792/" rel="bookmark">Adobe announces Photoshop CS3 Beta</a></li><li><a href="http://uneasysilence.com/archive/2006/02/5224/" rel="bookmark">Sorry no Adobe for MacTel for some time.</a></li><li><a href="http://uneasysilence.com/archive/2007/01/9095/" rel="bookmark">The Photoshop CS3 Serial Number *CAN* be used Cross Platform</a></li><li><a href="http://uneasysilence.com/archive/2008/01/12827/" rel="bookmark">Adobe Formally Speaks About 192.168.112.2o7.net and Spying Concerns</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://uneasysilence.com/archive/2007/12/12789/feed/</wfw:commentRss>
		<slash:comments>67</slash:comments>
		</item>
	</channel>
</rss>
