<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>K-Squared Ramblings &#187; security</title>
	<atom:link href="http://www.hyperborea.org/journal/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hyperborea.org/journal</link>
	<description>Sci-fi, comics, humor, photos...it&#039;s all fair game.</description>
	<lastBuildDate>Sat, 21 Nov 2009 07:49:46 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='www.hyperborea.org' port='80' path='/journal/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Powerless at the Mall</title>
		<link>http://www.hyperborea.org/journal/archives/2009/09/03/powerless-mall/</link>
		<comments>http://www.hyperborea.org/journal/archives/2009/09/03/powerless-mall/#comments</comments>
		<pubDate>Fri, 04 Sep 2009 06:30:00 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Strange World]]></category>
		<category><![CDATA[AppleStore]]></category>
		<category><![CDATA[electricity]]></category>
		<category><![CDATA[mall]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Station Fire]]></category>
		<category><![CDATA[Tweets]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/archives/2009/09/03/line-items-for-2009-09-03/</guid>
		<description><![CDATA[How an outdoor mall dealt with a lunchtime power outage. And some Apple observations.

Power&#8217;s out at mall. No teriyaki bowl for me. Subway it is! (Hmm, and no iced coffee either. *sigh*) #
Near as I can tell, the Apple store is just completely shut down. Hazards of making checkout depend on computer network, I guess. [...]]]></description>
			<content:encoded><![CDATA[<p>How an outdoor mall dealt with a lunchtime power outage. And some Apple observations.</p>
<ul class="aktt_tweet_digest">
<li>Power&#8217;s out at mall. No teriyaki bowl for me. Subway it is! (Hmm, and no iced coffee either. *sigh*) <a href="http://twitter.com/KelsonV/statuses/3740792522" class="aktt_tweet_time">#</a></li>
<li>Near as I can tell, the <strong>Apple store</strong> is just completely shut down. Hazards of making checkout depend on computer network, I guess. <a href="http://twitter.com/KelsonV/statuses/3740874506" class="aktt_tweet_time">#</a></li>
<li>For contrast, Subway just dug out a pad of paper credit card slips &amp; did texture rubbings w/ a pen. <a href="http://twitter.com/KelsonV/statuses/3740919370" class="aktt_tweet_time">#</a></li>
<li>Odd: <strong>muzak</strong> is so omnipresent I didn&#8217;t notice it was still playing. Speakers must be on another circuit from the stores. <a href="http://twitter.com/KelsonV/statuses/3740948736" class="aktt_tweet_time">#</a></li>
<li>Turns out only <em>some</em> buildings have lost power. Including all the coffee except Starbucks. But Jamba Juice has power! <a href="http://twitter.com/KelsonV/statuses/3741393840" class="aktt_tweet_time">#</a></li>
<li>Was weird walking through mall at lunch seeing lighted stores on right &amp; dark on left. Some stayed open, some closed, some adapted. <a href="http://twitter.com/KelsonV/statuses/3741862395" class="aktt_tweet_time">#</a></li>
<li>Coffee Bean mostly closed during the power outage, but set an employee out front with 2 urns of coffee. No ice, though. <a href="http://twitter.com/KelsonV/statuses/3741944828" class="aktt_tweet_time">#</a></li>
</ul>
<h3>Links of the Day</h3>
<ul class="aktt_tweet_digest">
<li>Mac users: if you upgrade to <strong>Snow Leopard</strong>, <a href="http://blogs.zdnet.com/security/?p=4175">be sure to re-update Flash afterward</a>. <a href="http://twitter.com/KelsonV/statuses/3736774449" class="aktt_tweet_time">#</a></li>
<li>Impressive <a href="http://blog.flickr.net/en/2009/09/03/station-fire-los-angeles/">LA fire pix at Flickr</a>. #<a href="http://search.twitter.com/search?q=%23stationfire" class="aktt_hashtag">stationfire</a> <a href="http://twitter.com/KelsonV/statuses/3738222002" class="aktt_tweet_time">#</a></li>
</ul>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2009/09/03/powerless-mall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Vulnerabilities Everywhere</title>
		<link>http://www.hyperborea.org/journal/archives/2009/08/25/line-items-adobe/</link>
		<comments>http://www.hyperborea.org/journal/archives/2009/08/25/line-items-adobe/#comments</comments>
		<pubDate>Wed, 26 Aug 2009 06:30:00 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Computers/Internet]]></category>
		<category><![CDATA[Acrobat]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Tweets]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/archives/2009/08/25/line-items-for-2009-08-25/</guid>
		<description><![CDATA[Uh-oh: 80% of web users running unpatched versions of Flash/Acrobat. These are being exploited, so check your system! #
Copyright &#169; 2009 Kelson Vibber and/or Katherine Foreman. This feed is for personal, non-commercial use only.  The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin. [...]]]></description>
			<content:encoded><![CDATA[<p>Uh-oh: <a href="http://blogs.zdnet.com/security/?p=4097">80% of web users</a> running unpatched versions of Flash/Acrobat. These are being exploited, so check your system! <a href="http://twitter.com/KelsonV/statuses/3540462620" class="aktt_tweet_time">#</a></p>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2009/08/25/line-items-adobe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BOB This Way! &amp; Reality Bytes</title>
		<link>http://www.hyperborea.org/journal/archives/2009/06/08/bob-arrow/</link>
		<comments>http://www.hyperborea.org/journal/archives/2009/06/08/bob-arrow/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 06:30:00 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Music]]></category>
		<category><![CDATA[Signs of the Times]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[theater]]></category>
		<category><![CDATA[Tweets]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/archives/2009/06/08/line-items-for-2009-06-08/</guid>
		<description><![CDATA[
Sign taped to light pole: &#8220;BOB →&#8221; #
This doesn&#8217;t look good: major data breach claimed at T-Mobile. #
One day, someone will take a collection of popular songs from the 1990s and turn it into a nostalgia musical. #

Copyright &#169; 2009 Kelson Vibber and/or Katherine Foreman. This feed is for personal, non-commercial use only.  The [...]]]></description>
			<content:encoded><![CDATA[<ul class="aktt_tweet_digest">
<li>Sign taped to light pole: &#8220;BOB →&#8221; <a href="http://twitter.com/KelsonV/statuses/2078470282" class="aktt_tweet_time">#</a></li>
<li>This doesn&#8217;t look good: major <a href="http://it.slashdot.org/article.pl?sid=09/06/07/2019246">data breach claimed</a> at T-Mobile. <a href="http://twitter.com/KelsonV/statuses/2080423368" class="aktt_tweet_time">#</a></li>
<li>One day, someone will take a collection of popular songs from the 1990s and turn it into a nostalgia musical. <a href="http://twitter.com/KelsonV/statuses/2086642626" class="aktt_tweet_time">#</a></li>
</ul>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2009/06/08/bob-arrow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Malware</title>
		<link>http://www.hyperborea.org/journal/archives/2008/12/08/social-malware/</link>
		<comments>http://www.hyperborea.org/journal/archives/2008/12/08/social-malware/#comments</comments>
		<pubDate>Tue, 09 Dec 2008 07:59:59 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Computers/Internet]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[Tweets]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/archives/2008/12/08/line-items-for-2008-12-08/</guid>
		<description><![CDATA[Malware spreading &#8220;via&#8221; social networking sites? Sounds like it&#8217;s impersonating them phish-like. Worth a look, tho #
Copyright &#169; 2009 Kelson Vibber and/or Katherine Foreman. This feed is for personal, non-commercial use only.  The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If [...]]]></description>
			<content:encoded><![CDATA[<p>Malware <a href="http://www.us-cert.gov/current/index.html">spreading &#8220;via&#8221; social networking sites</a>? Sounds like it&#8217;s impersonating them phish-like. Worth a look, tho <a href="http://twitter.com/KelsonV/statuses/1045668245" class="aktt_tweet_time">#</a></p>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2008/12/08/social-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fall, Spelling, WPA2, Jokes</title>
		<link>http://www.hyperborea.org/journal/archives/2008/11/07/fall-spelling-wpa2-jokes/</link>
		<comments>http://www.hyperborea.org/journal/archives/2008/11/07/fall-spelling-wpa2-jokes/#comments</comments>
		<pubDate>Sat, 08 Nov 2008 06:59:59 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Computers/Internet]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[election]]></category>
		<category><![CDATA[jokes]]></category>
		<category><![CDATA[obama]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SoCal]]></category>
		<category><![CDATA[Tweets]]></category>
		<category><![CDATA[Weather]]></category>
		<category><![CDATA[wifi]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/archives/2008/11/07/line-items-for-2008-11-07-2/</guid>
		<description><![CDATA[
Fall in SoCal = checking the weather report daily to decide between shorts or a heavy jacket. #
I keep seeing pill spam with sensational election-related subjects. Oddly they can spell Obama correctly, but consistently write &#8220;McCane&#8221; #
OK, chicken-and-road jokes are old hat, but this set using (mostly political) celebrities is new to me. #
Time to [...]]]></description>
			<content:encoded><![CDATA[<ul class="aktt_tweet_digest">
<li>Fall in SoCal = checking the weather report daily to decide between shorts or a heavy jacket. <a href="http://twitter.com/KelsonV/statuses/994981121" class="aktt_tweet_time">#</a></li>
<li>I keep seeing pill spam with sensational election-related subjects. Oddly they can spell Obama correctly, but consistently write &#8220;McCane&#8221; <a href="http://twitter.com/KelsonV/statuses/995307149" class="aktt_tweet_time">#</a></li>
<li>OK, chicken-and-road jokes are old hat, but <a href="http://www.jumbojoke.com/why_did_the_chicken_cross_the_road.html">this set using (mostly political) celebrities</a> is new to me. <a href="http://twitter.com/KelsonV/statuses/996054598" class="aktt_tweet_time">#</a></li>
<li>Time to <a href="http://isc.sans.org/diary.html?storyid=5315">upgrade your wireless network security to WPA2</a>. #<a href="http://search.twitter.com/search?q=%23wifi">wifi</a> #<a href="http://search.twitter.com/search?q=%23security">security</a> <a href="http://twitter.com/KelsonV/statuses/996055724" class="aktt_tweet_time">#</a></li>
</ul>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2008/11/07/fall-spelling-wpa2-jokes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Flagging (Non)-Spoofed Mail</title>
		<link>http://www.hyperborea.org/journal/archives/2008/05/01/flagging-non-spoofed-mail/</link>
		<comments>http://www.hyperborea.org/journal/archives/2008/05/01/flagging-non-spoofed-mail/#comments</comments>
		<pubDate>Fri, 02 May 2008 02:32:14 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Computers/Internet]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/?p=2470</guid>
		<description><![CDATA[Following up on the PayPal anti-phishing discussion of a few weeks ago, I see that PayPal is promoting a service called Iconix.  You install the program on your system, and it looks at your inbox for messages that claim to be from one of its customers.  It tries to verify them &#8220;using industry-standard [...]]]></description>
			<content:encoded><![CDATA[<p>Following up on the PayPal anti-phishing discussion of a few weeks ago, I see that PayPal is promoting a service called <a href="http://www.iconix.com/"><strong>Iconix</strong></a>.  You install the program on your system, and it looks at your inbox for messages that claim to be from one of its customers.  It tries to <a href="http://www.iconix.com/faq/index.php?action=artikel&#038;cat=20&#038;id=12&#038;artlang=en">verify</a> them &#8220;using industry-standard authentication technologies such as Sender ID and DomainKeys.&#8221;  Messages that pass get a lock-and-checkbox icon attached to the sender&#8217;s name, and in some cases the name is replaced by the sender&#8217;s logo.</p>
<p>On the tech side, it&#8217;s similar to <a href="http://spamassassin.apache.org/">SpamAssassin&#8217;s</a> whitelist_from_spf and whitelist_from_dkim features.  Both allow you to specify a sender to whitelist, and it will only give a message special treatment if it can verify the sender.</p>
<p>On the user-interface side, it&#8217;s similar to EC certificates, in that it tries to highlight a &#8220;good&#8221; class of messages rather than flag or filter out a &#8220;bad&#8221; class.</p>
<p>It&#8217;s not a bad idea, actually, and now that I&#8217;m surprised I haven&#8217;t seen something similar in other email clients.  It&#8217;s sort of like setting up custom rings or images for images on your cell phone address book </p>
<p>They seem to be <a href="http://www.iconix.com/faq/index.php?action=artikel&#038;cat=11&#038;id=23&#038;artlang=en">focused on webmail and Outlook</a> so far, and only on Windows, but it looks like the <strong>perfect candidate for a Thunderbird extension</strong>.  They do have a sign-up form to notify you when they add support for various programs and OSes, and I was pleased to see not only Thunderbird and Mac&nbsp;OS listed, but Linux as well.  Too often, Linux gets forgotten in the shuffle to ensure compatibility with every Windows variation.</p>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2008/05/01/flagging-non-spoofed-mail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Links: Freedom and Security</title>
		<link>http://www.hyperborea.org/journal/archives/2008/04/24/links-freedom-and-security/</link>
		<comments>http://www.hyperborea.org/journal/archives/2008/04/24/links-freedom-and-security/#comments</comments>
		<pubDate>Fri, 25 Apr 2008 05:01:42 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Comics]]></category>
		<category><![CDATA[Computers/Internet]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[CBLDF]]></category>
		<category><![CDATA[legal]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/?p=2454</guid>
		<description><![CDATA[The CBLDF has issued a press released detailing the victory in the Gordon Lee case.  This was the case in which a comic book store in Rome, Georgia, as part of a 2004 Halloween promotion, was handing out free comics left over from that year&#8217;s Free Comic Book Day.  Among over 2,000 comics, [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://cbldf.org/" title="Comic Book Legal Defense Fund">CBLDF</a> has issued a press released detailing the <a href="http://www.cbldf.org/pr/archives/000355.shtml">victory in the Gordon Lee case</a>.  This was the case in which a comic book store in Rome, Georgia, as part of a 2004 Halloween promotion, was handing out free comics left over from that year&#8217;s <a href="http://www.freecomicbookday.com/">Free Comic Book Day</a>.  Among over 2,000 comics, they accidentally included a copy of <i>Alternative Comics #2</i>, which included a story about Picasso which included him running around his studio in the nude.  And they accidentally gave it to a kid.  The parents wouldn&#8217;t accept an apology, and pressed charges instead. The DA has been determined to make an example out of him, pushing grossly overinflated charges including felonies that would have given him prison time.  3½ years, 3 trial dates, a mistrial for prosecutorial misconduct, and $100,000 in defense costs later, the Rome DA finally agreed to drop the case in exchange for a written letter of apology &#8212; which is exactly what the store owner had offered in the first place.</p>
<p><a href="http://boren.nu/archives/2008/04/24/cookie-security-in-wordpress-25/">Cookie Security in WordPress 2.5</a>.  The latest version of the blogging software has a feature that can make it harder for attackers to grab your login sessions.  It involves setting a pass phrase in wp-config.php, one which you&#8217;ll never have to remember, but which will be unique to your site.  You have to copy the SECRET_KEY section from wp-config-sample.php and add in your passphrase&#8230;or you can generate a random code at <a href="http://api.wordpress.org/secret-key/1.0/">http://api.wordpress.org/secret-key/1.0/</a> (be sure to put it in the middle of the file!)</p>
<p>The Internet Storm Center writes on <a href="http://isc.sans.org/diary.html?storyid=4331">Hundreds of Thousands of SQL Injections</a> &#8212; all websites that have been hacked to host various sorts of malware.</p>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2008/04/24/links-freedom-and-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blocking IE6: You, Me and&#8230;PayPal?</title>
		<link>http://www.hyperborea.org/journal/archives/2008/04/21/blocking-ie6/</link>
		<comments>http://www.hyperborea.org/journal/archives/2008/04/21/blocking-ie6/#comments</comments>
		<pubDate>Tue, 22 Apr 2008 04:35:24 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Computers/Internet]]></category>
		<category><![CDATA[Web Design]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[IE6]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/?p=2448</guid>
		<description><![CDATA[On Thursday I stumbled across a campaign to Trash All IE Hacks.  The idea is that people only stay on the ancient, buggy, feature-lacking, PITA web browser, Internet Explorer&#160;6, because we web developers coddle them.  We make the extra effort to work around those bugs, so they can actually use the sites without [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.microsoft.com/windows/ie/"><img class="alignright" alt="Internet Explorer." border="0"  src="http://www.hyperborea.org/images/cs/ie7_60h.png" width="60" height="60" /></a>On Thursday I stumbled across a campaign to <a href="http://www.webdesignerwall.com/general/trash-all-ie-hacks/"><strong>Trash All IE Hacks</strong></a>.  The idea is that people only stay on the ancient, buggy, feature-lacking, <abbr title="Pain In The *ahem*">PITA</abbr> web browser, Internet Explorer&nbsp;6, because we web developers coddle them.  We make the extra effort to work around those bugs, so they can actually use the sites without upgrading.</p>
<p>Well, yeah.  <strong>That&#8217;s our job.</strong></p>
<p>And a bunch of random websites blocking IE6 aren&#8217;t going to convince people to change.  If I were to block IE6, or only allow Firefox, or only allow Opera, I&#8217;d have to have <strong>seriously compelling content</strong> to get people to switch.  Mostly, people would get annoyed and move on.  Who&#8217;s going to install a new browser just so they can read the history of the Flash?  Or choose an ISP? Or buy a product that they can get from another site?</p>
<h3>Slapping the User in the Face</h3>
<p>It&#8217;s so easy for someone to walk away from your site.  One of the tenets of good web design is to make the user <strong>jump through as few hoops as possible</strong> to accomplish whatever you want him/her to do.  Every hoop you add is an obstacle.  Too many obstacles, and they&#8217;ll just go somewhere else more convenient.</p>
<p>Back when I was following <a href="http://www.spreadfirefox.com/">Spread Firefox</a>, every once in a while someone would suggest blocking IE.  Every time, people like me would shoot it down.  <span id="more-2448"></span> And think about it: what does the average Firefox user (or Opera user, for that matter) do when confronted with a site that will only run in IE?  Fire off a complaint, or move on, unless it&#8217;s something they can&#8217;t live without, like, say, their bank.  Only then will they bring up the site&#8217;s preferred browser&#8230;just long enough to do their business and move on.</p>
<p>Plus it goes against the grain of the concept that a website should be <a href="http://anybrowser.org/campaign/">viewable in any browser</a>.  It offends my sense of&#8230; I don&#8217;t know, egalitarianism.</p>
<h3>Recommend vs. Demand</h3>
<p>My current tactics: I target the latest versions of each browser (or rather, the overlap in their standards support), toss in enhancements where I think something would be nice, but not critical (off-site link icons using generated content, for instance, which works in everything except IE&le;7, or rounded corners, which only work in Gecko and WebKit so far).  And I take that, and make it look <em>reasonably</em> good in IE6.  I don&#8217;t try to make it perfect anymore (case in point, the header of this blog), but I try to make sure it&#8217;s functional and doesn&#8217;t look broken.</p>
<p>Then I include a polite notice recommending that people upgrade to something a little more capable or modern for a better experience, but <strong>I don&#8217;t require them to do so</strong>.  I don&#8217;t pop up anything that moves, or blocks content, or forces them to click through an extra page.</p>
<h3>Enter: PayPal</h3>
<p>Now, remember what I said about banks?  <a href="http://www.eweek.com/index2.php?option=content&#038;task=view&#038;id=47667&#038;pop=1&#038;hide_ads=1&#038;page=0&#038;hide_js=1"><strong>PayPal intends to block &#8220;unsafe&#8221; browsers</strong></a> from accessing their site <small>(<a href="http://it.slashdot.org/it/08/04/18/003226.shtml">via Slashdot</a>)</small>.  They aren&#8217;t technically a bank, but PayPal is actually in a position where they might be able to do it: they&#8217;re the most well known online payment service where two random people can send each other money.  Probably more people will switch browsers and keep PayPal than switch payment services and keep their browser.</p>
<p>They&#8217;ve since <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9079138&#038;intsrc=hm_list" title="ComputerWorld: PayPal: We won't block Safari">indicated</a> that they don&#8217;t intend to block &#8220;current versions of any browsers,&#8221; but will focus on &#8220;obsolete browsers on outdated or unsupported operating systems.&#8221;  <strong>So you IE4 users on Windows&nbsp;98?  Upgrade already!</strong>  (And since you can&#8217;t install IE7, try <a href="http://my.opera.com/community/download.pl?ref=Kelson&#038;p=opera_desktop">Opera</a>.  It still runs on Win98!)</p>
<p>They&#8217;ve also cited such safety features as phishing protection (present in IE7, Firefox&nbsp;2, and Opera&nbsp;9) and support for <a href="http://en.wikipedia.org/wiki/Extended_Validation_Certificate">Extended Validation SSL Certificates</a> (present in IE7 and the upcoming Firefox&nbsp;3 and Opera&nbsp;9.5).</p>
<h3>Hazards of Browser Sniffing</h3>
<p>Of course, once you start actively blocking browsers, you have three choices:</p>
<ul>
<li>Keep track of every single browser out there, and every version.</li>
<li>Let most browsers in, but only block a few problem browsers (similar to Yahoo&#8217;s <a href="http://developer.yahoo.com/yui/articles/gbs/">Graded Browser Support</a>)</li>
<li>Unfairly block browsers that might be perfectly adequate just because you can&#8217;t be bothered to investigate them.</li>
</ul>
<p>The last seems the most prevalent.  Just ask any Opera user today, or any Firefox user of 3 years ago.  (I remember using Firefox and being told to &#8220;upgrade&#8221; to Netscape 6, even though NS6 was based on an older version of the same engine.  Remember: <a href="http://web.archive.org/web/*/http://geckoisgecko.org/">Gecko is Gecko</a>.)</p>
<p>Whitelist approaches to browser detection are, by their nature, either going to require constant updating or block too much.  In this case, issues would include:</p>
<ul>
<li>Less well-known browsers, like <a href="http://www.flock.com/">Flock</a>, which uses the same anti-phishing features as Firefox</li>
<li>Browsers that don&#8217;t do phishing detection themselves, using third-party plugins to do the job.</li>
<li>Changes in status, when browsers add the capabilities required to get on the list.</li>
</ul>
<p>Thankfully, it looks like PayPal is going with the most minimally-intrusive approach: blocking only the most troublesome browsers, and letting the rest connect normally.</p>
<h3>Will it Work?</h3>
<p>There&#8217;s still the question of whether it&#8217;ll actually make users less likely to land on a PayPal phishing site.</p>
<p>For one thing, it&#8217;s not clear whether they&#8217;ll block IE6.  The initial report would definitely have excluded it, since it lacks both EV support and anti-phishing (without an add-on).  But the follow-up statement was focused on Safari.  Does PayPal consider IE6 to be a &#8220;current&#8221; version since Microsoft still supports it?  Or do they consider IE7 to be current, and IE6 to be obsolete?</p>
<p>Certainly, if they <em>don&#8217;t</em> block IE6, this will really only impact the tiny fraction of users running horribly outdated software.  (Well, <em>more</em> horribly outdated.)</p>
<p>The thing to remember is that the features PayPal is promoting <strong>will only help if users switch for general browsing</strong>.  In fact, anti-phishing will make no difference at all on PayPal&#8217;s actual site, unless it gets hacked (at which point the user is screwed anyway.)</p>
<p>So let&#8217;s suppose that they do block IE6.  As much as I&#8217;d <em>like</em> people to switch to Firefox or Opera full-time, I&#8217;m sure there will be some people who only fire up an alternative to use PayPal, and who stick with IE6 the rest of the time.  They&#8217;re just as likely as before to click on a bogus &#8220;Pay with PayPal&#8221; button, or a link in a phishing email.  If they weren&#8217;t going to do that in the first place, the browser requirement wasn&#8217;t needed.  If they were, the browser requirement doesn&#8217;t help.  The <strong>bogus sites won&#8217;t require phishing detection</strong>, or EV certs.  Imagine the user saying, &#8220;Hey, PayPal fixed the problem where it wouldn&#8217;t let me use IE!&#8221;</p>
<p>And of course it won&#8217;t stop someone with a stolen login and password from connecting using an &#8220;approved&#8221; browser.</p>
<p>The ISC has also weighed in re: <a href="http://isc.sans.org/diary.html?storyid=4309">limitations of EV certificates</a>.  Among other things: it may be easier to get an EV cert than suggested, in which case it won&#8217;t indicate any greater degree of trust than a standard SSL certificate.  And it doesn&#8217;t prevent other issues, like keyword loggers or trojans that simply hijack a user&#8217;s session.</p>
<p>I apologize for the rambling nature of this post (yeah, site title and all that).  But I worked on it on a succession of late nights, and decided it was time to just post the thing.  Also, I <del>should</del> have <a href="http://operawatch.com/news/2008/05/whats-a-safe-browser.html">a somewhat more concise post</a> up on <a href="http://operawatch.com/">OperaWatch</a> <del>soon</del> <ins>now</ins>.</p>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2008/04/21/blocking-ie6/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Webbish Links</title>
		<link>http://www.hyperborea.org/journal/archives/2008/02/07/webbish-links/</link>
		<comments>http://www.hyperborea.org/journal/archives/2008/02/07/webbish-links/#comments</comments>
		<pubDate>Thu, 07 Feb 2008 18:52:14 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Web Design]]></category>
		<category><![CDATA[css]]></category>
		<category><![CDATA[IE6]]></category>
		<category><![CDATA[IE7]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webdesign]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/archives/2008/02/07/webbish-links/</guid>
		<description><![CDATA[The WaSP Buzz recently posted several links to CSS resources, including a rather thorough CSS Reference at SitePoint.
The ISC reminds us that IE7 will be pushed out to WSUS next week, which should help get rid of IE6.  Yeah, I&#8217;d rather more people switched to Firefox or Opera, but I&#8217;m at the point where [...]]]></description>
			<content:encoded><![CDATA[<p>The WaSP Buzz recently posted several <a href="http://www.webstandards.org/2008/02/04/community-css-resources-roundup/">links to CSS resources</a>, including a rather thorough <a href="http://reference.sitepoint.com/css">CSS Reference</a> at SitePoint.</p>
<p>The ISC reminds us that <a href="http://isc.sans.org/diary.html?storyid=3946">IE7 will be pushed out to <abbr title="Windows Server Update Services">WSUS</abbr> next week</a>, which should help <a href="http://www.end6.org/">get rid of IE6</a>.  Yeah, I&#8217;d rather more people switched to Firefox or Opera, but I&#8217;m at the point where I&#8217;d love to be able to stop worrying about IE6&#8217;s shortcomings when trying to build sites.  IE7&#8217;s shortcomings are much easier to work around.  (Sorry to keep harping on this!)</p>
<p>The inventor of Norton Antivirus <a href="http://www.darkreading.com/security/perimeter/showArticle.jhtml?articleID=208803838" title="Antivirus Inventor: Security Departments Are Wasting Their Time">talks about computer security</a> and has some rather interesting ideas on what policies are worth pursuing&#8230;and what policies aren&#8217;t.  Long passwords?  Great for protecting a stand-alone machine, but on a 10,000 machine network, they only need to crack one.  Patch everything?  Not every vulnerability gets exploited.  I&#8217;ll have to read the <a href="http://it.slashdot.org/article.pl?sid=08/02/07/1534220">Slashdot thread</a> when I have time; that should be <em>really</em> *ahem* <em>interesting</em>.</p>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2008/02/07/webbish-links/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Net Links</title>
		<link>http://www.hyperborea.org/journal/archives/2008/01/29/net-links/</link>
		<comments>http://www.hyperborea.org/journal/archives/2008/01/29/net-links/#comments</comments>
		<pubDate>Wed, 30 Jan 2008 07:34:04 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Computers/Internet]]></category>
		<category><![CDATA[Web Design]]></category>
		<category><![CDATA[Acid3]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webdev]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/archives/2008/01/29/net-links/</guid>
		<description><![CDATA[ISC on Targeted Attacks
Hixie&#8217;s Natural Log: Come up with the best test for Acid3 Edit: Strike that, Acid3 has been completed.
Spies in the Phishing Underground (via Slashdot)
Copyright &#169; 2009 Kelson Vibber and/or Katherine Foreman. This feed is for personal, non-commercial use only.  The use of this feed on other websites breaches copyright. Permission granted [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://isc.sans.org/diary.html?storyid=3835">ISC on Targeted Attacks</a></p>
<p><s><a href="http://ln.hixie.ch/?start=1200301306&#038;count=1">Hixie&#8217;s Natural Log: Come up with the best test for Acid3</a></s> <b>Edit:</b> Strike that, <a href="http://acid3.acidtests.org/">Acid3</a> has been <a href="http://www.css3.info/acid3-completed/">completed</a>.</p>
<p><a href="http://www.net-security.org/article.php?id=1110">Spies in the Phishing Underground</a> <small>(<a href="http://it.slashdot.org/article.pl?sid=08/01/28/0315242">via Slashdot</a>)</small></p>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2008/01/29/net-links/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Links: Safety Last</title>
		<link>http://www.hyperborea.org/journal/archives/2007/12/26/links-safety-last/</link>
		<comments>http://www.hyperborea.org/journal/archives/2007/12/26/links-safety-last/#comments</comments>
		<pubDate>Wed, 26 Dec 2007 18:08:45 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Humor]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[links]]></category>
		<category><![CDATA[safety]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/archives/2007/12/26/links-safety-last/</guid>
		<description><![CDATA[Forklift Driver Klaus (a.k.a. Staplerfahrer Klaus)- a parody of work safety films in which a forklift driver blunders through his first day on the job, maiming fellow employees left and right.  German with English subtitles.  (via TV Tropes: Scare Em Straight)
And, on a more serious note, the Internet Storm Center is reporting on [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.youtube.com/watch?v=Sdjt6Bl5qdY">Forklift Driver Klaus</a> (a.k.a. <i>Staplerfahrer Klaus</i>)- a parody of work safety films in which a forklift driver blunders through his first day on the job, maiming fellow employees left and right.  German with English subtitles.  <small>(<a href="http://tvtropes.org/pmwiki/pmwiki.php/Main/ScareEmStraight">via TV Tropes: Scare Em Straight</a>)</small></p>
<p>And, on a more serious note, the Internet Storm Center is reporting on people <a href="http://isc.sans.org/diary.html?storyid=3787">finding malware pre-installed</a> on digital picture frames, memory cards, etc.  Something to watch out for with portable devices that can connect to your computer.</p>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2007/12/26/links-safety-last/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox, Kindle(ing) and more</title>
		<link>http://www.hyperborea.org/journal/archives/2007/11/20/fx-kindle-etc/</link>
		<comments>http://www.hyperborea.org/journal/archives/2007/11/20/fx-kindle-etc/#comments</comments>
		<pubDate>Wed, 21 Nov 2007 05:30:21 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Computers/Internet]]></category>
		<category><![CDATA[Entertainment]]></category>
		<category><![CDATA[Mozilla]]></category>
		<category><![CDATA[amazon]]></category>
		<category><![CDATA[Books]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[ebooks]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[kindle]]></category>
		<category><![CDATA[reading]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/archives/2007/11/20/fx-kindle-etc/</guid>
		<description><![CDATA[Firefox 3 Beta 1 is out.  Nice so far.  Oddly enough, it runs better than the current Opera 9.5 previews on my old Linux box at work, though that mostly seems to be the fault of the find-in-history option.
I usually avoid any sort of shopping on the day after Thanksgiving, online included, but [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spreadfirefox.com/?q=affiliates&#038;id=880&#038;t=1"><img class="alignleft" alt="Firefox." border="0" src="http://www.hyperborea.org/images/cs/firefox_60h.png" width="60" height="60" /></a><a href="http://blog.mozilla.com/blog/2007/11/20/firefox-3-beta-1-ready-for-testing/"><strong>Firefox 3 Beta 1 is out</strong></a>.  Nice so far.  Oddly enough, it runs better than the current Opera 9.5 previews on my old Linux box at work, though that mostly seems to be the fault of the find-in-history option.</p>
<p>I usually avoid any sort of shopping on the day after Thanksgiving, online included, but I&#8217;ve been getting email from various online stores that are trying to get into <a href="http://en.wikipedia.org/wiki/Black_Friday_(shopping)">Black Friday</a>.  Amazon is advertising a <a href="http://www.amazon.com/b/?node=384082011&#038;tag=hyperborea-20">Black Friday Sale</a>, and Apple is promoting a &#8220;special one-day <a href="http://store.apple.com/1-800-MY-APPLE/WebObjects/AppleStore.woa/wa/RSLID?nnmm=browse&#038;mco=DB6B68E9&#038;node=campaigns/black_friday_teaser">shopping event</a>&#8221; on their website&#8212;and annoyingly, neither of them is giving any clue as to what sort of deals are involved.  Amazon keeps forwarding me to <em>today&#8217;s</em> deals, and Apple just says something&#8217;s coming. And neither site lists actual hours. Is it midnight to midnight?  What time zone?</p>
<p><a href="http://www.amazon.com/gp/product/B000FI73MA?ie=UTF8&#038;tag=hyperborea-20&#038;linkCode=as2&#038;camp=1789&#038;creative=9325&#038;creativeASIN=B000FI73MA"><img class="alignright" border="0" src="http://www.hyperborea.org/journal/wp-content/uploads/2007/11/21l4uisv3yl_aa_sl110_.jpg" alt="Amazon Kindle"/></a><img src="http://www.assoc-amazon.com/e/ir?t=hyperborea-20&#038;l=as2&#038;o=1&#038;a=B000FI73MA" width="1" height="1" border="0" alt="" style="border:none !important; margin:0px !important;" />Speaking of Amazon, their entire home page is currently taken up by the announcement of their new <strong>eBook reader, <a href="http://www.amazon.com/gp/product/B000FI73MA?ie=UTF8&#038;tag=hyperborea-20&#038;linkCode=as2&#038;camp=1789&#038;creative=9325&#038;creativeASIN=B000FI73MA">Kindle</a></strong>.  At $400 I&#8217;m not going to rush out and buy one, but it looks like they&#8217;ve solved some of the main e-book problems: it&#8217;s small, light and wireless, and they even bring up the reading-in-bed issue in the intro.  The real question is going to be compatibility &#038; openness: It&#8217;ll read plain text, HTML, Word, and a few other document formats (and they&#8217;re promoting its access to <a href="http://en.wikipedia.org/">Wikipedia</a>), so it should be possible for other stores to sell books for the device.  And what about the e-book offerings themselves?  Will they be loaded down with draconian digital rights management like the Adobe ebooks of a few years ago, or are they following the model of <a href="http://www.amazon.com/b/?node=163856011&#038;tag=hyperborea-20">Amazon&#8217;s MP3 store</a>?* In a nice change, their music downloads are entirely <strong>DRM-free</strong> <em>and they use it as a selling point</em>.  <b>Edit:</b> Per Andrea&#8217;s comments and further research, <strong>Kindle ebooks are locked down with DRM.  No, thanks!</strong></p>
<p>The name, however, makes me wonder how soon they&#8217;ll offer <a href="http://www.amazon.com/gp/product/9506440298?ie=UTF8&#038;tag=hyperborea-20&#038;linkCode=as2&#038;camp=1789&#038;creative=9325&#038;creativeASIN=9506440298"><i>Fahrenheit 451</i></a>.</p>
<p>Finally, the <strong>Internet Storm Center</strong> has an insightful response to the statement, <a href="http://isc.sans.org/diary.html?storyid=3672">&#8220;There is nothing on my computer that a hacker would be interested in.&#8221;</a>  Let&#8217;s leave aside the question of your personal data for the moment.  Just the fact that you&#8217;ve got a computer with an internet connection could prove very useful to someone who wants to cover their tracks or just add more power to their own distributed system.</p>
<p><small>* Amazon&#8217;s MP3 store is also surprisingly cheap.  I replaced my old tapes of the original cast recordings of <a href="http://www.amazon.com/gp/product/B000VHPZ7A?ie=UTF8&#038;tag=hyperborea-20&#038;linkCode=as2&#038;camp=1789&#038;creative=9325&#038;creativeASIN=B000VHPZ7A"><i>Les Misérables</i> (Broadway)</a> and <a href="http://www.amazon.com/gp/product/B000V6U6SE?ie=UTF8&#038;tag=hyperborea-20&#038;linkCode=as2&#038;camp=1789&#038;creative=9325&#038;creativeASIN=B000V6U6SE"><i>Phantom Of The Opera</i></a> for $9 each&#8212;they run upwards of $30 on CD.</small></p>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2007/11/20/fx-kindle-etc/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Patch&#8230;Friday?</title>
		<link>http://www.hyperborea.org/journal/archives/2007/09/07/patch-friday/</link>
		<comments>http://www.hyperborea.org/journal/archives/2007/09/07/patch-friday/#comments</comments>
		<pubDate>Sat, 08 Sep 2007 06:28:27 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[apache]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[upgrade]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/archives/2007/09/07/patch-friday/</guid>
		<description><![CDATA[I suppose it&#8217;s best to release the security fixes when they&#8217;re ready, because any time you pick is going to be inconvenient for someone, but lately it seems like Friday is suddenly in style.
Last Friday saw the release of PHP 5.2.4, on the Friday before&#8212;in the US, anyway&#8212;a 3-day weekend.  This morning Apache released [...]]]></description>
			<content:encoded><![CDATA[<p>I suppose it&#8217;s best to release the security fixes when they&#8217;re ready, because any time you pick is going to be inconvenient for <em>someone</em>, but lately it seems like Friday is suddenly in style.</p>
<p>Last Friday saw the release of <a href="http://www.php.net/releases/5_2_4.php">PHP 5.2.4</a>, on the Friday before&#8212;in the US, anyway&#8212;a 3-day weekend.  This morning <a href="http://httpd.apache.org/">Apache</a> released security updates for all three supported branches of their webserver.  And this evening&#8212;yes, Friday evening&#8212;<a href="http://wordpress.org/development/2007/09/wordpress-223/">WordPress 2.2.3 came out</a>.</p>
<p>Which reminds me, I&#8217;m going to have to start looking at the betas for <a href="http://wordpress.org/development/2007/09/wordpress-23-beta-2/">WordPress 2.3</a>.  I think it&#8217;ll be a good time for a redesign.  Maybe pick a new theme and tweak that one, maybe try my hand at actually designing one.  I wonder if the new tagging system can import <a href="http://plugins.trac.wordpress.org/wiki/BunnysTechnoratiTags">Bunny&#8217;s Technorati Tags</a>.</p>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2007/09/07/patch-friday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress 2.1.1 Security Alert</title>
		<link>http://www.hyperborea.org/journal/archives/2007/03/02/wp-211-alert/</link>
		<comments>http://www.hyperborea.org/journal/archives/2007/03/02/wp-211-alert/#comments</comments>
		<pubDate>Sat, 03 Mar 2007 01:13:45 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[upgrade]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/archives/2007/03/02/wp-211-alert/</guid>
		<description><![CDATA[Sometime in the last 3-4 days, someone managed to alter the download for WordPress 2.1.1, adding a remotely exploitable security hole.  The WordPress team has declared the release &#8220;dangerous&#8221; and has issued an update, WordPress 2.1.2, taken from the clean source plus a few fixes.  If you run WordPress 2.1.1, upgrade ASAP!
Things worth [...]]]></description>
			<content:encoded><![CDATA[<p>Sometime in the last 3-4 days, someone <a href="http://wordpress.org/development/2007/03/upgrade-212/">managed to alter the download for WordPress 2.1.1</a>, adding a remotely exploitable security hole.  The WordPress team has declared the release &#8220;dangerous&#8221; and has issued an update, WordPress 2.1.2, taken from the clean source plus a few fixes.  <strong>If you run WordPress 2.1.1, upgrade ASAP!</strong></p>
<p>Things worth noting:</p>
<ul>
<li>The SVN source that the developers use was not altered.</li>
<li>Older versions, such as 2.0, don&#8217;t seem to have been affected.</li>
<li>If you downloaded 2.1.1 when it was first released, it&#8217;s probably okay.</li>
<li>2.1.2 also includes a fix for <a href="http://trac.wordpress.org/ticket/3879">a cross-site scripting vulnerability</a> discovered a few days ago, so it&#8217;s worth updating anyway.</li>
</ul>
<p>I still had the tar archive of 2.1.1 from when I grabbed it the day of the release, so I compared its contents to the 2.1.2 archive.  The two files mentioned in the announcement, feed.php and theme.php, aren&#8217;t any different, confirming that the initial release was unaffected.  That&#8217;s also where I saw the changes for that XSS bug.</p>
<p>*sigh* It&#8217;s always something&#8230;</p>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2007/03/02/wp-211-alert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress 2.0.7 security &amp; feed fix</title>
		<link>http://www.hyperborea.org/journal/archives/2007/01/15/wp-207/</link>
		<comments>http://www.hyperborea.org/journal/archives/2007/01/15/wp-207/#comments</comments>
		<pubDate>Tue, 16 Jan 2007 00:46:34 +0000</pubDate>
		<dc:creator>Kelson</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[upgrade]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.hyperborea.org/journal/archives/2007/01/15/wp-207/</guid>
		<description><![CDATA[Just upgraded to WordPress 2.0.7.  It fixes a security issue with certain versions of PHP, and it also includes the fix for the feed problem in 2.0.6 and a couple other minor fixes.
According to the announcement, WP 2.1 should be out by the end of the month.  Looks like it&#8217;s almost time to [...]]]></description>
			<content:encoded><![CDATA[<p>Just upgraded to <a href="http://wordpress.org/development/2007/01/wordpress-207/">WordPress 2.0.7</a>.  It fixes a security issue with certain versions of PHP, and it also includes the fix for the <a href="http://www.hyperborea.org/journal/archives/2007/01/05/feed-problems/">feed problem</a> in 2.0.6 and a couple other minor fixes.</p>
<p>According to the announcement, WP 2.1 should be out by the end of the month.  Looks like it&#8217;s almost time to see how many of my customizations will work with the new version.</p>
<hr /><small>Copyright &copy; 2009 Kelson Vibber and/or Katherine Foreman.<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. Permission granted to Planet Antispam and LiveJournal syndication feed ksquaredramblin.  If this content is not in your news reader or one of the sites listed above, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint: bc1c453a98ff79bab5c4fca2d890469d (38.107.191.94) )</small> <a href="http://www.hudson-family.co.uk/extremecorticate.php?source=673"></a>]]></content:encoded>
			<wfw:commentRss>http://www.hyperborea.org/journal/archives/2007/01/15/wp-207/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
