<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DUIERns7eip7ImA9WxJUFko.&quot;"><id>tag:blogger.com,1999:blog-7782260</id><updated>2009-07-15T21:35:07.502+04:30</updated><title>Vitalsecurity.org</title><subtitle type="html">A Revolution is the Solution</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://www.vitalsecurity.org/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>paperghost</name><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>81</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><link rel="self" href="http://feeds.feedburner.com/Vitalsecurity-org" type="application/atom+xml" /><feedburner:browserFriendly>This is Vitalsecurity.org's XML content feed - the below articles do not show the full content of each item. It is intended to be viewed in a newsreader, or syndicated to another site if you would like to take advantage of our regularly updated news reports - reliable content with no hassle.</feedburner:browserFriendly><entry gd:etag="W/&quot;DUIERng4fyp7ImA9WxJUFko.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-249149506059266945</id><published>2009-07-15T21:32:00.002+04:30</published><updated>2009-07-15T21:35:07.637+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-15T21:35:07.637+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="EBay fail" /><title>Write about phishing, get threatened with the FBI</title><content type="html">Some awesome work by Ebay / Paypal yesterday, assuming "writing to someones webhost with lots of threats related to copyright infringement and then running to the FBI all because someone put up a screenshot of a phishing mail with your brand on it" means "awesome" nowadays.&lt;br /&gt;&lt;br /&gt;Which is doesn't.&lt;br /&gt;&lt;br /&gt;Gigantic amounts of fail can be yours for the taking &lt;a href="http://www.ghettowebmaster.com/legal/ebay-paypal-reported-me-to-the-fbi/"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-249149506059266945?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/O0nFxIhedKM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/249149506059266945/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=249149506059266945&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/249149506059266945?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/249149506059266945?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/O0nFxIhedKM/write-about-phishing-get-threatened.html" title="Write about phishing, get threatened with the FBI" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/07/write-about-phishing-get-threatened.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUICQ3Y7eyp7ImA9WxJUFUs.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-7018710806683910571</id><published>2009-07-14T13:55:00.002+04:30</published><updated>2009-07-14T13:56:02.803+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-14T13:56:02.803+04:30</app:edited><title>Some downtime scheduled...</title><content type="html">I'll be messing with things behind the scenes later today, so don't be massively surprised if the site is AWOL for a while. It might even come back online too - bonus...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-7018710806683910571?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/PVzFWSi_R14" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/7018710806683910571/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=7018710806683910571&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7018710806683910571?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7018710806683910571?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/PVzFWSi_R14/some-downtime-scheduled.html" title="Some downtime scheduled..." /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/07/some-downtime-scheduled.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUMHRXwyeip7ImA9WxJUEk8.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-3144067839516420949</id><published>2009-07-10T16:17:00.002+04:30</published><updated>2009-07-10T16:33:54.292+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-10T16:33:54.292+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Epic Fail" /><category scheme="http://www.blogger.com/atom/ns#" term="wtf" /><title>Smacktalk Fail</title><content type="html">&lt;a href="https://www.blogger.com/comment.g?blogID=7782260&amp;amp;postID=3555679640887843836&amp;amp;isPopup=true"&gt;Oh dear&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-3144067839516420949?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/Vj5rq8CovPo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/3144067839516420949/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=3144067839516420949&amp;isPopup=true" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3144067839516420949?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3144067839516420949?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/Vj5rq8CovPo/smacktalk-fail.html" title="Smacktalk Fail" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">4</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/07/smacktalk-fail.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUMFRXY4cSp7ImA9WxJVE0s.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-2381613962846893651</id><published>2009-06-30T16:22:00.005+04:30</published><updated>2009-06-30T16:33:34.839+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-30T16:33:34.839+04:30</app:edited><title>GMail and IP Addresses</title><content type="html">My pals over at Sunbelt have written about a &lt;a href="http://sunbeltblog.blogspot.com/2009/06/useful-gmail-security-feature.html"&gt;feature&lt;/a&gt; of GMail I didn't know existed:&lt;br /&gt;&lt;p&gt;&lt;span style="font-style: italic;"&gt;"Click “Details” and you get an overview of your accounts activity, including whether it’s from POP, a browser, or a mobile phone"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It also gives you IP addresses. Now I'm of the opinion that grabbing the IP address of someone who has hijacked your GMail is an interesting prospect - however, this also means that anybody able to hijack your GMail account has &lt;span style="font-style: italic;"&gt;your&lt;/span&gt; IP address too, and they'll have yours before you have theirs. To be honest, I think the potentially tiny benefit of having an attackers (potentially fake) IP is greatly outweighed by them having &lt;span style="font-style: italic;"&gt;your&lt;/span&gt; IP.&lt;br /&gt;&lt;br /&gt;Call me paranoid, but is it time to break out proxies and VPNs for GMail now? Perhaps there's a way for Google to implement some kind of password protection that's required to be able to access this information - but of course, if that password is tied to GMail itself then presumably the attacker would have access to that too - so how would you do it?&lt;br /&gt;&lt;br /&gt;Suggestions on a postcard to Google, please...&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-2381613962846893651?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/6V-wcjurFgg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/2381613962846893651/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=2381613962846893651&amp;isPopup=true" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2381613962846893651?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2381613962846893651?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/6V-wcjurFgg/gmail-and-ip-addresses.html" title="GMail and IP Addresses" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/gmail-and-ip-addresses.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkQBQXo-fSp7ImA9WxJVE0k.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-3555679640887843836</id><published>2009-06-30T11:06:00.002+04:30</published><updated>2009-06-30T11:15:50.455+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-30T11:15:50.455+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="wtf" /><title>Hackers Target Neopets Users</title><content type="html">&lt;style type="text/css"&gt;.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }&lt;/style&gt;&lt;div class="flickr-frame"&gt; &lt;a href="http://www.flickr.com/photos/paperghost/3674703868/" title="photo sharing"&gt;&lt;img src="http://farm3.static.flickr.com/2621/3674703868_4492894f74.jpg" class="flickr-photo" alt="" /&gt;&lt;/a&gt;&lt;br /&gt; &lt;span class="flickr-caption"&gt;&lt;a href="http://www.flickr.com/photos/paperghost/3674703868/"&gt;Neopets Scam&lt;/a&gt;, originally uploaded by &lt;a href="http://www.flickr.com/people/paperghost/"&gt;Paperghost&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;    &lt;p class="flickr-yourcomment"&gt; &lt;/p&gt;Targeting 12 year old kids with keyloggers?&lt;br /&gt;&lt;br /&gt;Oh Lordy. More &lt;a href="http://blog.spywareguide.com/2009/06/hackers-target-neopets-users.html"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-3555679640887843836?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/dUaQVVUeScQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/3555679640887843836/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=3555679640887843836&amp;isPopup=true" title="20 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3555679640887843836?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3555679640887843836?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/dUaQVVUeScQ/hackers-target-neopets-users.html" title="Hackers Target Neopets Users" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">20</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/hackers-target-neopets-users.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0ABSXs9fCp7ImA9WxJVEE8.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-3463808343949429021</id><published>2009-06-26T17:16:00.009+04:30</published><updated>2009-06-26T17:39:18.564+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-26T17:39:18.564+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="wtf" /><title>Save us from these idiots</title><content type="html">So some old guy who clearly knows nothing about computers - or how many internets you can fit into them - is &lt;a href="http://news.bbc.co.uk/1/hi/uk_politics/8118729.stm"&gt;seriously rubbing me up the wrong way&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;“You need youngsters who are deep into this stuff… If they have been slightly naughty boys, very often they really enjoy stopping other naughty boys,” he said.”&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Wait, what?&lt;br /&gt;&lt;br /&gt;Look out, clueless guy ahoy.&lt;br /&gt;&lt;br /&gt;Apart from the fact that there's something distinctly pervy sounding about calling them "naughty boys" and "enjoyment" at them "getting caught" - we're not in some sort of boarding school here - this is the biggest heap of crap I've heard since the last time some old guy who knows nothing about computers talked a load of old crap.&lt;br /&gt;&lt;br /&gt;Let's go out and hire (nay, REWARD) a bunch of  talentless, idiotic script kiddies who haven't done very much of note to defend a country? Oh yeah, that's genius, that is.&lt;br /&gt;&lt;br /&gt;Except that they&lt;br /&gt;&lt;br /&gt;a) have little to no technical knowledge&lt;br /&gt;b) enjoy cutting and pasting other peoples work (due to the whole lack of knowledge thing) and&lt;br /&gt;c) are idiots, who leave their entire life across ten social networking sites then wonder how come you're waiting outside their house with a baseball bat and a length of cheesewire.&lt;br /&gt;&lt;br /&gt;Last time I checked, the SAS was not full of morons. Nor are the SEALs, or any number of dedicated anti-whatever teams. Why should UK cyber security rather predictably be given the bastard children of a thousand leftover takeaway meals to defend it?&lt;br /&gt;&lt;br /&gt;Idiots commanding idiots, I love it. I'm going to go out and phish six hundred XBox Live accounts, I might be in Whitehall within six months. Let me tell Old Man McGinty something - I have waded through a crapload of script kiddies, and every now and then even convinced them to do the right thing(TM).&lt;br /&gt;&lt;br /&gt;But you know what? In order to get them to do the right thing, more often than not I had to THREATEN THEM WITH HORRIBLE AND EMBARRASSING THINGS. It took time. It took effort. It took pictures of them cavorting with their rather large and thuggish best mates girlfriend. Sometimes &lt;span style="font-style: italic;"&gt;I&lt;/span&gt; did the cavorting.&lt;br /&gt;&lt;br /&gt;It took all of these things and &lt;span style="font-style: italic;"&gt;more&lt;/span&gt;, to get a TINY percentage of people to stop being morons and play good guy for a while - and &lt;span style="font-style: italic;"&gt;only&lt;/span&gt; for a while. Where are these magical script kiddies - who really, &lt;span style="font-style: italic;"&gt;really&lt;/span&gt; want to be good, honest they do - Old Man McGinty is talking about? Can we have some of them to play with?&lt;br /&gt;&lt;br /&gt;Oh, right. Didn't think so.&lt;br /&gt;&lt;br /&gt;I've said it before, and I'll say it again - UK law enforcement tackling cybercrime is like Stevie Wonder playing Dance Dance Revolution. And all these ancient Government type guys who are older than the telephone need to get out of the way and stop talking about computers, technology and (most of all) script kiddies.&lt;br /&gt;&lt;br /&gt;Because they have absolutely no idea what they are talking about.&lt;br /&gt;&lt;br /&gt;Oh, the rage.&lt;br /&gt;&lt;br /&gt;Also: More sensible takes on this &lt;a href="http://countermeasures.trendmicro.eu/would-the-real-cybersecurity-minister-please-stand-up/"&gt;here&lt;/a&gt; and &lt;a href="http://www.sophos.com/blogs/gc/g/2009/06/26/uk-attack-countries-cyberspace/"&gt;here&lt;/a&gt;. I'll just stick with the ranting and cheap insults, for those are my boomsticks and I'm happy to deploy them.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-3463808343949429021?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/mabuj3Z2siA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/3463808343949429021/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=3463808343949429021&amp;isPopup=true" title="7 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3463808343949429021?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3463808343949429021?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/mabuj3Z2siA/save-us-from-these-idiots.html" title="Save us from these idiots" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">7</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/save-us-from-these-idiots.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ck8FRX0_eip7ImA9WxJWEUk.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-2081818526169369160</id><published>2009-06-16T12:44:00.004+04:30</published><updated>2009-06-16T12:56:54.342+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-16T12:56:54.342+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Spam" /><category scheme="http://www.blogger.com/atom/ns#" term="wtf" /><title>Spam of the day</title><content type="html">&lt;style type="text/css"&gt;.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }&lt;/style&gt;&lt;div class="flickr-frame"&gt; &lt;a href="http://www.flickr.com/photos/paperghost/3631275791/" title="photo sharing"&gt;&lt;img src="http://farm4.static.flickr.com/3384/3631275791_faec617e30_o.jpg" class="flickr-photo" alt="" /&gt;&lt;/a&gt;&lt;br /&gt; &lt;span class="flickr-caption"&gt;&lt;a href="http://www.flickr.com/photos/paperghost/3631275791/"&gt;Rohan Crones&lt;/a&gt;, originally uploaded by &lt;a href="http://www.flickr.com/people/paperghost/"&gt;Paperghost&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;    &lt;p class="flickr-yourcomment"&gt; &lt;/p&gt;...Rohan Crones? Are they old women from Lord of the Rings? If so, I'll have two of those and a Russian bride to go, please.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-2081818526169369160?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/Q0NfiFkA4gk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/2081818526169369160/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=2081818526169369160&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2081818526169369160?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2081818526169369160?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/Q0NfiFkA4gk/spam-of-day.html" title="Spam of the day" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/spam-of-day.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkcAQXs5eCp7ImA9WxJWEUk.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-457920311528392949</id><published>2009-06-16T12:41:00.002+04:30</published><updated>2009-06-16T12:44:00.520+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-16T12:44:00.520+04:30</app:edited><title>Remember kids, people lie on the Internet</title><content type="html">&lt;a href="http://forums.xbox.com/27664245/ShowPost.aspx"&gt;Oh dear&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Ten asshole points awarded to the social engineer for decimating an entire gaming clan, I guess.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-457920311528392949?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/i-Eu6PZTcac" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/457920311528392949/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=457920311528392949&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/457920311528392949?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/457920311528392949?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/i-Eu6PZTcac/remember-kids-people-lie-on-internet.html" title="Remember kids, people lie on the Internet" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/remember-kids-people-lie-on-internet.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QGRXg7cCp7ImA9WxJWEEg.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-7495530514674797803</id><published>2009-06-15T14:16:00.002+04:30</published><updated>2009-06-15T14:18:44.608+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-15T14:18:44.608+04:30</app:edited><title>Pastebins and Botnets</title><content type="html">I loves me some Pastebin action, and I loves me some Botnet action too. If someone were to combine the two and toss around an idea where Pastebins could be used to issue commands to Botnets, would I be interested in taking a look?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blog.spywareguide.com/2009/06/pastebin-botnets.html"&gt;You bet&lt;/a&gt;. One of the more interesting things I've come across recently.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-7495530514674797803?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/U_JXL7fLL7Q" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/7495530514674797803/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=7495530514674797803&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7495530514674797803?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7495530514674797803?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/U_JXL7fLL7Q/pastebins-and-botnets.html" title="Pastebins and Botnets" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/pastebins-and-botnets.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0ECQXgzfyp7ImA9WxJXF00.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-8697680657837871083</id><published>2009-06-11T10:53:00.003+04:30</published><updated>2009-06-11T10:57:40.687+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-11T10:57:40.687+04:30</app:edited><title>When will they learn?</title><content type="html">Honestly, when someone waves their arms around in the air and goes "hack me", you can bet someone will turn up minutes later and say "okay".&lt;br /&gt;&lt;br /&gt;So it went with the recent Strongwebmail competition, where Lance James pulled a few &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9133976"&gt;A Team moves&lt;/a&gt; and pocketed a cool $10,000 in return for pwning their supposedly unpwnable CEO email account.&lt;br /&gt;&lt;br /&gt;I really don't know why companies offer themselves up for a public gutting where competitions such as this are concerned, but whatever. You can read an interview with Lance &lt;a href="http://www.fireblog.com/exclusive-interview-with-strongwebmails-10000-hacker/"&gt;here&lt;/a&gt;, although he doesn't say if he's Mr T or Hannibal which is a bit of a letdown.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-8697680657837871083?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/SJlWaZvJubQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/8697680657837871083/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=8697680657837871083&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8697680657837871083?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8697680657837871083?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/SJlWaZvJubQ/when-will-they-learn.html" title="When will they learn?" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/when-will-they-learn.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEUMRH89cSp7ImA9WxJXEk4.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-5162855620310507224</id><published>2009-06-05T23:53:00.007+04:30</published><updated>2009-06-06T00:34:45.169+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-06T00:34:45.169+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="JetKing" /><title>JetKing: They came, they saw, they rocked</title><content type="html">At the height of the "Myspace band hacks" back in &lt;a href="http://www.time.com/time/business/article/0,8599,1683361,00.html"&gt;2007&lt;/a&gt;, I have to confess to being somewhat underwhelmed by reaction to the problems facing the bands on that social networking site. It seemed most bands were puzzled at best and disinterested at worst by the mass hack attempts on their pages.&lt;br /&gt;&lt;br /&gt;However - one band actually took an interest in it, and had been fighting the good fight for some time while I was only just starting to dig into the problem. That band would be &lt;a href="http://www.jetking.info/"&gt;JetKing&lt;/a&gt;, and they really flew the flag for bands that were getting it in the neck from all the phishing &amp;amp; malware spewing that was going on at the time.&lt;br /&gt;&lt;br /&gt;We've kept in touch to this day, and I was flattered when they sent me a copy of their debut album a week or so ago.  I'm happy to report that the album is bloody good and well worth investigating (I've had "Smoke and Mirrors" lodged in my brain for a few days now). It's an interesting mix of guitars and electronica, but what caught my eye (ear?) was that neither element was overloaded or overdone - there's a nice bit of breathing space to the tracks and that appeals to me as a one time orchestral bod. And hey, you can rock out to it so +1 for that.&lt;br /&gt;&lt;br /&gt;You can check out a few of the songs on their &lt;a href="http://www.myspace.com/jetkinguk"&gt;Myspace page&lt;/a&gt;  and there's a review &lt;a href="http://indiemusicuniverse.com/albumreviews/album-review-jetkings-theories-suit-facts/"&gt;here&lt;/a&gt; that pretty much says what I was thinking about the album myself. Cheers for that, album reviewer guy.&lt;br /&gt;&lt;br /&gt;JetKing: flying the flag for music &lt;span style="font-style: italic;"&gt;and&lt;/span&gt; security.&lt;br /&gt;&lt;br /&gt;That's always a good thing, isn't it? Good luck with the album Vaughn, and thanks for being interested in the whole security thing at a time when so many others affected by the same problem weren't. It made a difference :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-5162855620310507224?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/wavy4ehdr7c" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/5162855620310507224/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=5162855620310507224&amp;isPopup=true" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/5162855620310507224?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/5162855620310507224?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/wavy4ehdr7c/jetking-they-came-they-saw-they-rocked.html" title="JetKing: They came, they saw, they rocked" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/jetking-they-came-they-saw-they-rocked.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0UFQX4_cCp7ImA9WxJQFk0.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-6702623778581232865</id><published>2009-05-29T19:10:00.004+04:30</published><updated>2009-05-29T19:30:10.048+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-29T19:30:10.048+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Epic Fail" /><title>If it's not for you, just move on</title><content type="html">It's an unspoken rule of security that anytime a story about something that isn't THE END OF THE WORLD appears, a guy will show up and loudly deride the story / the author / why it isn't important or "newsworthy" or something else he feels like complaining about.&lt;br /&gt;&lt;br /&gt;Case in point, a week or so ago people were coming to me worried that their Playstation consoles were "infected with viruses". I looked into it, saw there was nothing to worry about and wrote about it on &lt;a href="http://www.techradar.com/news/gaming/consoles/guest-column-don-t-fall-for-ps3-virus-alerts-602168"&gt;TechRadar&lt;/a&gt;. Sure enough, the very first comment posted was this:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"I'm sorry but anyone who is fooled by this is a complete moron. A picture of XP My Computer and a reference to ‘your PC’, I suppose he thinks those lovely ladies he speaks to on those ‘Hot Babes’ hotlines are real people and really live just a few blocks away. It certainly isn’t newsworthy for a site dedicated to technology. People have been duped by this stuff for years and will continue to be till the end of the net. It’s dumb enough for a PC user to be duped yet understandable as the messages do, quite successfully at times, simulate the user’s day-to-day PC environment. It’s not virus he should be scared of, its woodworm eating away at his head."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Love it. Wannabe holier-than-thou atttitude where security is concerned, combined with derisive scorn at the people who might actually be worried by something regarding hardware that cost them a lot of money.&lt;br /&gt;&lt;br /&gt;Thank God for angry security commentators, eh? I mean, I would mention stones in glass houses when a quick check for him on twitter reveals his face, his name (hello, Toby) and what's probably his lovely lady &lt;a href="http://twitter.com/tholmewood"&gt;here&lt;/a&gt;, or how his &lt;a href="http://www.facebook.com/people/Toby-Holmewood/277004130"&gt;Facebook page&lt;/a&gt; reveals his location and opens his visible friends up to "fake friend" trolling antics, or how what looks like his &lt;a href="http://myworld.ebay.co.uk/tholmewood/"&gt;EBay page&lt;/a&gt; under the same username used for contemptuous and insulting comments leaves him perilously open to aggrieved parties stalking him by buying an item from him, then returning it with an excuse to grab his home address.&lt;br /&gt;&lt;br /&gt;But hey, people worried by Playstation virus warnings are idiots. Right?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-6702623778581232865?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/Hj9vlS4ZlTA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/6702623778581232865/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=6702623778581232865&amp;isPopup=true" title="8 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/6702623778581232865?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/6702623778581232865?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/Hj9vlS4ZlTA/if-its-not-for-you-just-move-on.html" title="If it's not for you, just move on" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">8</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/if-its-not-for-you-just-move-on.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE8FR3s9eSp7ImA9WxJQFk0.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-8813629428275757235</id><published>2009-05-29T16:58:00.005+04:30</published><updated>2009-05-29T17:43:36.561+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-29T17:43:36.561+04:30</app:edited><title>Look out, it's Angry Apple Guy</title><content type="html">I love a bit of blog rage, but sadly I haven't seen any for a while. As it turns out, you need to simply question the veracity of an Apple Mac advert, retreat to a safe distance and wait for some guy to start going RAAAAARGH RAGE RAGE RAGE all over the place.&lt;br /&gt;&lt;br /&gt;Which he is. Cheap shots, contrived logic, ad hominem attacks and a complete lack of understanding with regards how writing a blog that serves the needs of those with a technical bent, computer savvy reporters, those who have no clue whatsoever about IT but want to stay safe and non technical journos who want to learn more about "the whole security thing" operates on a day to day basis can be yours for the taking &lt;a href="http://countermeasures.trendmicro.eu/apple-macs-no-crashes-or-viruses/comment-page-1/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;All because someone said the word "virus", apparently.&lt;br /&gt;&lt;br /&gt;Also, here's a stupid song I just made up.&lt;br /&gt;&lt;br /&gt;ANGRY APPLE GUY! WOO-OOOO-OOOOO!&lt;br /&gt;HE SAYS A LOT OF STUFF BECAUSE HE'S "IN THE KNOW"!&lt;br /&gt;ANGRY APPLE GUY! WOO-OOOO-OOOOO!&lt;br /&gt;PUTS CANDLES AT YOUR FEET, 'CAUSE WINDOZE BLOWS!&lt;br /&gt;&lt;br /&gt;ANGRY APPLE GUY! WOO-OOOO-OOOOO!&lt;br /&gt;WANTS TO GIVE YOU A CLASSIFICATION TEST!&lt;br /&gt;ANGRY APPLE GUY! WOO-OOOO-OOOOO!&lt;br /&gt;HAS A NERD RAGE ABOUT MAC OS X!&lt;br /&gt;&lt;br /&gt;/ GUITAR SOLO&lt;br /&gt;&lt;br /&gt;OH YES, HE'LL PROVE YOU WRONG!&lt;br /&gt;UNLESS YOU MAKE YOUR COMMENTS &lt;span style="font-weight: bold;"&gt;TWICE&lt;/span&gt; AS LONG!&lt;br /&gt;WATCH OUT FOR HIS MICROSOFT CHEERLEADER BARBS!&lt;br /&gt;CAUSE I'M MARRIED TO BILL GATES, GOD BLESS HIS HEART!&lt;br /&gt;&lt;br /&gt;/ SLOW SECTION&lt;br /&gt;&lt;br /&gt;I ADDED NOTHING TO THE DISCUSSION!&lt;br /&gt;&lt;br /&gt;/ POWER CHORD&lt;br /&gt;&lt;br /&gt;EXCEPT A SAD ATTEMPT AT DIVERSION!&lt;br /&gt;&lt;br /&gt;(Yes, I am using your own words as the basis for my song. Enjoy)&lt;br /&gt;&lt;br /&gt;DOESN'T WANT TO GIVE ME A HUG!&lt;br /&gt;&lt;br /&gt;/ POWER CHORD&lt;br /&gt;&lt;br /&gt;EVEN THOUGH I OFFERED HIM A FREE WINDOWS MUG!&lt;br /&gt;&lt;br /&gt;/ LEATHER PANTS THRUSTING&lt;br /&gt;&lt;br /&gt;ANGRY APPLE GUY! WOO-OOOO-OOOOO!&lt;br /&gt;HAS A BIG THING FOR BLOGGERS AND JOURNALISTS!&lt;br /&gt;ANGRY APPLE GUY! WOO-OOOO-OOOOO!&lt;br /&gt;HE PROBABLY SEES NOW I'M TAKING THE PI -&lt;br /&gt;&lt;br /&gt;.....is this mike still on?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-8813629428275757235?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/yegoPBtvjIs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/8813629428275757235/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=8813629428275757235&amp;isPopup=true" title="10 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8813629428275757235?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8813629428275757235?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/yegoPBtvjIs/look-out-its-angry-apple-guy.html" title="Look out, it's Angry Apple Guy" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">10</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/look-out-its-angry-apple-guy.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkYBQ3Y_fip7ImA9WxJQFU8.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-5332224759685650927</id><published>2009-05-28T15:19:00.005+04:30</published><updated>2009-05-28T20:59:12.846+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-28T20:59:12.846+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Twitter" /><title>Location-based information on Twitter</title><content type="html">From &lt;a href="http://www.readwriteweb.com/archives/twitter_might_start_adding_comments_location-based_info.php"&gt;Readwriteweb&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;"Twitter might soon add location-based information to every tweet. Currently, users can set a location on their profile, but individual tweets are not geo-coded in any way. If Twitter did indeed add a geo-references to every tweet, then that would open up the door to a wealth of new possibilities for developers."&lt;br /&gt;&lt;br /&gt;Well, screw the developers. All I want to know is&lt;br /&gt;&lt;br /&gt;1) Will there be an opt-out and&lt;br /&gt;2) If there IS an opt-out planned, will they apply geolocational technology to all the messages previously posted to Twitter before you get a chance to hit the "opt-out" button? Of course, in an ideal world opt-out would be selected by default (thus making it an opt-in, but it's all getting a bit confusing now so let's just say we don't want it in the first place and take it from there).&lt;br /&gt;&lt;br /&gt;I asked the co-founder and the main Twitter account on, uh, Twitter &lt;a href="http://twitter.com/paperghost/status/1939311795"&gt;here&lt;/a&gt;, but amazingly enough I haven't had a reply back. Hopefully the answer will be what we want to hear, or else I predict an epic security / privacy fail.&lt;br /&gt;&lt;br /&gt;/ Edit - More from Graham Cluley &lt;a href="http://www.sophos.com/blogs/gc/g/2009/05/28/locationbased-twitter-bad-security/"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-5332224759685650927?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/xQ9v_XBZfJw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/5332224759685650927/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=5332224759685650927&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/5332224759685650927?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/5332224759685650927?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/xQ9v_XBZfJw/location-based-information-on-twitter.html" title="Location-based information on Twitter" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/location-based-information-on-twitter.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0ACRngzcSp7ImA9WxJQE0s.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-3813418744828814535</id><published>2009-05-26T23:09:00.007+04:30</published><updated>2009-05-26T23:52:47.689+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-26T23:52:47.689+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Wake up" /><category scheme="http://www.blogger.com/atom/ns#" term="NO2ID" /><title>If you've nothing to hide, you've everything to fear</title><content type="html">&lt;span style="font-style: italic;"&gt;"The government will have a few more records on me, so what?"&lt;/span&gt; Some guy on a forum&lt;br /&gt;&lt;br /&gt;You know, I'm still amazed when I see statements like that one regarding the massive boner the UK Government has for compiling a gigantic set of databases on everything you could imagine. It's clearly a "nothing to hide, nothing to fear" way of thinking.&lt;br /&gt;&lt;br /&gt;The problem is that it doesn't freaking &lt;span style="font-style: italic;"&gt;work&lt;/span&gt; like that.&lt;br /&gt;&lt;br /&gt;There are two &lt;span style="font-style: italic;"&gt;huge&lt;/span&gt; problems with "nothing to hide, nothing to fear".&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1)&lt;/span&gt; It assumes the people in charge (along with the people who have access to the data currently stored on the 11 or so databases with parts of your whole existence stored on them) are all whiter than white.&lt;br /&gt;&lt;br /&gt;They're not, as it &lt;a href="http://www.cnn.com/2009/WORLD/europe/05/11/oakley.uk.mps.expenses/"&gt;turns out&lt;/a&gt;. They're just like you and me, and just &lt;span style="font-style: italic;"&gt;like&lt;/span&gt; you and me, they get up to things they don't want everybody to know about. Fancy that.&lt;br /&gt;&lt;br /&gt;And the more people you open the data up to, the bigger the risk of idiocy taking place. The &lt;a href="http://www.theregister.co.uk/2009/05/17/contactpoint_follow_up/"&gt;ContactPoint database&lt;/a&gt; is a perfect example - 300,000+ people from police, to charities(!) to random boobs in councils and God knows where else, and NONE of those people will try to track a kid down for their mate with an estranged spouse or other such shenanigans?&lt;br /&gt;&lt;br /&gt;Huh, good luck with &lt;span style="font-style: italic;"&gt;that&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;As the desire for databases combining their information grows - and ContactPoint is a big step towards that - so the risk increases for huge chunks of data to be lost and used in horrible and as of yet unthought of ways.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2)&lt;/span&gt; Put down the groundwork for a "Let's watch everybody" State, and its the easiest thing in the world for a party to come in afterwards and use that system to abuse whoever they feel like. It should certainly give pause for thought when considering how many pieces of your life are constantly being stacked up inside ever growing databases. I can tell you this much - whoever gets into power after the current shower of thugs are fired into the heart of the Sun, it will be the &lt;span style="font-style: italic;"&gt;hardest thing in the World&lt;/span&gt; for them to kill off some of these databases and monitoring tactics.&lt;br /&gt;&lt;br /&gt;It'll be like that guy who really, really wants to keep his terabyte of porno on his external HD but doesn't want the wife to find out. Seriously. They will &lt;span style="font-style: italic;"&gt;agonise&lt;/span&gt; over it.&lt;br /&gt;&lt;br /&gt;Oh, and let's not forget the very people constantly telling us how &lt;span style="font-style: italic;"&gt;wonderful&lt;/span&gt; these databases will be, and how you can soon go into Snappy Snaps and "Have your face scanned and fingerprints taken" while &lt;a href="http://news.bbc.co.uk/1/hi/uk_politics/8036536.stm"&gt;shopping&lt;/a&gt; are the very same shower of idiots who've done their level best to &lt;a href="http://www.guardian.co.uk/politics/blog/2009/jan/15/freedomofinformation-houseofcommons"&gt;prevent the public&lt;/a&gt; from seeing how much they've been &lt;a href="http://www.telegraph.co.uk/news/newstopics/mps-expenses/"&gt;screwing over the expenses system&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;It seems like everyone, everywhere is constantly being told to watch people, and report them, for anything and everything. If it's not kids as young as eight trained in the ways of &lt;a href="http://www.telegraph.co.uk/news/uknews/2689996/Children-aged-eight-enlisted-as-council-snoopers.html"&gt;reporting&lt;/a&gt;&lt;a href="http://www.telegraph.co.uk/news/uknews/2689996/Children-aged-eight-enlisted-as-council-snoopers.html"&gt; their neighbours&lt;/a&gt;, its the growing army of "&lt;a href="http://www.guardian.co.uk/politics/2008/aug/27/police.conservatives"&gt;Accredited Persons&lt;/a&gt;", or photography of police becoming &lt;a href="http://www.guardian.co.uk/commentisfree/2009/feb/16/protest-police-liberty-central"&gt;illegal&lt;/a&gt;, or those &lt;a href="http://enduringamerica.com/tag/anti-terrorism/"&gt;stupid posters&lt;/a&gt; issued by the "anti terror hotline" begging you to report anyone and everyone lest they &lt;a href="http://boingboing.net/2009/03/24/london-cops-reach-ne.html"&gt;blow something up&lt;/a&gt;, or tourists stopped in London and having their &lt;a href="http://www.guardian.co.uk/uk/2009/apr/16/police-delete-tourist-photos"&gt;photos deleted&lt;/a&gt; in case they're "terrorists", or schoolchildren having their &lt;a href="http://www.leavethemkidsalone.com/"&gt;biometrics taken at school&lt;/a&gt; without parents permission, or the police posters asking you to report people who wear "&lt;a href="http://www.dailymail.co.uk/news/article-1180911/Polices-latest-brainwave-Report-people-wear-bling-Crimestoppers.html"&gt;too much bling&lt;/a&gt;", or the desire for &lt;a href="http://www.geek.com/articles/news/uk-government-plans-increase-in-remote-computer-searches-2009016/"&gt;State approved spyware&lt;/a&gt;, and on it goes.&lt;br /&gt;&lt;br /&gt;I can say with conviction there is something fundamentally broken with this idea that huge reams of data being piled high magically solves everything. It's clear the Government intends to plough on with as many of these idiotic schemes as possible making it that much more difficult to remove the structure should someone else get into power.&lt;br /&gt;&lt;br /&gt;But hey, you'll be able to get your face scanned and fingerprints taken at &lt;a href="http://news.bbc.co.uk/1/hi/uk_politics/8036536.stm"&gt;Boots and Snappy Snaps&lt;/a&gt;. Great.&lt;br /&gt;&lt;br /&gt;How did we even &lt;span style="font-style: italic;"&gt;reach&lt;/span&gt; the point where people could be going around thinking this is remotely normal?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-3813418744828814535?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/0Q1a8cV5AKc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/3813418744828814535/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=3813418744828814535&amp;isPopup=true" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3813418744828814535?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3813418744828814535?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/0Q1a8cV5AKc/if-youve-nothing-to-hide-youve.html" title="If you've nothing to hide, you've everything to fear" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/if-youve-nothing-to-hide-youve.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0EEQH88cCp7ImA9WxJQEUU.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-1974213602202240378</id><published>2009-05-24T22:55:00.001+04:30</published><updated>2009-05-24T22:56:41.178+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-24T22:56:41.178+04:30</app:edited><title>You must read this...</title><content type="html">"If they can break the law, why can't we"? &lt;a href="http://www.theregister.co.uk/2009/05/24/breaking_the_law"&gt;Link &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-1974213602202240378?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/OyxOH-U3Jv4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/1974213602202240378/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=1974213602202240378&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/1974213602202240378?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/1974213602202240378?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/OyxOH-U3Jv4/you-must-read-this.html" title="You must read this..." /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/you-must-read-this.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0IFSH84eSp7ImA9WxJQEE0.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-2258146329012200864</id><published>2009-05-22T20:53:00.003+04:30</published><updated>2009-05-22T20:55:19.131+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-22T20:55:19.131+04:30</app:edited><title>Playstation 3 virus warnings: don't panic!</title><content type="html">&lt;div class="flickr-frame"&gt; &lt;a href="http://www.flickr.com/photos/paperghost/3553372823/" title="photo sharing"&gt;&lt;img src="http://farm4.static.flickr.com/3653/3553372823_20027651e0.jpg" class="flickr-photo" alt="" /&gt;&lt;/a&gt;&lt;br /&gt; &lt;span class="flickr-caption"&gt;&lt;a href="http://www.flickr.com/photos/paperghost/3553372823/"&gt;PS3 fake virus warning&lt;/a&gt;, originally uploaded by &lt;a href="http://www.flickr.com/people/paperghost/"&gt;Paperghost&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Is there anywhere rogue antispyware popups &lt;span style="font-style: italic;"&gt;don't&lt;/span&gt; cause a problem?&lt;br /&gt;&lt;br /&gt;More &lt;a href="http://www.techradar.com/news/gaming/consoles/guest-column-don-t-fall-for-ps3-virus-alerts-602168"&gt;here&lt;/a&gt; at TechRadar.&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-2258146329012200864?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/PwQxQ-TZigs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/2258146329012200864/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=2258146329012200864&amp;isPopup=true" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2258146329012200864?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2258146329012200864?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/PwQxQ-TZigs/playstation-3-virus-warnings-dont-panic.html" title="Playstation 3 virus warnings: don't panic!" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/playstation-3-virus-warnings-dont-panic.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0ADRH8_eip7ImA9WxJRGE0.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-5661513008763541591</id><published>2009-05-20T12:18:00.000+04:30</published><updated>2009-05-20T12:19:35.142+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-20T12:19:35.142+04:30</app:edited><title>Klingon Antivirus</title><content type="html">This really is &lt;a href="http://www.sophos.com/klingon/"&gt;genius&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-5661513008763541591?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/_U02XVpxSoA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/5661513008763541591/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=5661513008763541591&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/5661513008763541591?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/5661513008763541591?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/_U02XVpxSoA/klingon-antivirus.html" title="Klingon Antivirus" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/klingon-antivirus.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0YCQHk9eSp7ImA9WxJRFUQ.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-8512438176215339929</id><published>2009-05-17T23:36:00.003+04:30</published><updated>2009-05-18T00:42:41.761+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-18T00:42:41.761+04:30</app:edited><title>ContactPoint database goes live despite security fears</title><content type="html">&lt;span style="font-style: italic;"&gt;"The Government has announced plans to push ahead with the next phase in launch of a controversial child protection database, despite ongoing concerns about the security of data held on the system.&lt;/span&gt;  &lt;p style="font-style: italic;"&gt;The delayed ContactPoint system, which is due to include names and addresses on every child under 18 in England, will be accessed by frontline care workers in real-life trials for the first time from this Monday.&lt;br /&gt;&lt;/p&gt;  &lt;div id="article-mpu-container"&gt;  &lt;p&gt;&lt;span style="font-style: italic;"&gt;Security experts contacted by &lt;/span&gt;&lt;em style="font-style: italic;"&gt;El Reg&lt;/em&gt;&lt;span style="font-style: italic;"&gt; remain concerned that information housed on the database might leak out despite ministerial assurances on security provisions that will accompany the roll-out of the directory system."&lt;/span&gt; &lt;a href="http://www.theregister.co.uk/2009/05/17/contactpoint_follow_up/"&gt;Link&lt;br /&gt;&lt;/a&gt;&lt;/p&gt; &lt;/div&gt;The above article is absolutely required reading for anyone concerned with the gradual creep-creep-creep of Government interference in day to day life. I give it six months max before the first "ContactPoint ruined my life" story appears.&lt;br /&gt;&lt;br /&gt;It's no end of amusement to me that the Government that most promoted the "If you have nothing to hide, you've nothing to fear" mantra had an awful lot &lt;span style="font-style: italic;"&gt;they&lt;/span&gt; &lt;a href="http://www.telegraph.co.uk/news/newstopics/mps-expenses/"&gt;wanted to hide&lt;/a&gt;, as it turns out.&lt;br /&gt;&lt;br /&gt;A Revolution is indeed the Solution...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-8512438176215339929?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/oxb1N4VQZhE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/8512438176215339929/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=8512438176215339929&amp;isPopup=true" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8512438176215339929?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8512438176215339929?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/oxb1N4VQZhE/contactpoint-database-goes-live-despite.html" title="ContactPoint database goes live despite security fears" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/contactpoint-database-goes-live-despite.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkIHRnY6eip7ImA9WxJRE0o.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-4153686964687555769</id><published>2009-05-15T13:25:00.004+04:30</published><updated>2009-05-15T13:38:57.812+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-15T13:38:57.812+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Zango" /><category scheme="http://www.blogger.com/atom/ns#" term="A new challenger appears" /><title>Zango: Dead Space</title><content type="html">It seems the good ship Zango has been temporarily abandoned while the new owners clear the decks. Check out Zango.com:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ZOjRj_3HrmA/Sg0uru1VqCI/AAAAAAAAAQA/3si0Shzf9qw/s1600-h/zangd1.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 289px;" src="http://3.bp.blogspot.com/_ZOjRj_3HrmA/Sg0uru1VqCI/AAAAAAAAAQA/3si0Shzf9qw/s400/zangd1.gif" alt="" id="BLOGGER_PHOTO_ID_5335972462344906786" border="0" /&gt;&lt;/a&gt;Click to Enlarge&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Pinballcorp, eh? You know, the amount of restraint I had to show with regards calling this blog entry "Pinball Wizard" was immense. Seriously. Here's their site:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ZOjRj_3HrmA/Sg0ur2MOoUI/AAAAAAAAAQI/vH5QSx8l5nI/s1600-h/zangd2.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 276px;" src="http://1.bp.blogspot.com/_ZOjRj_3HrmA/Sg0ur2MOoUI/AAAAAAAAAQI/vH5QSx8l5nI/s400/zangd2.gif" alt="" id="BLOGGER_PHOTO_ID_5335972464319963458" border="0" /&gt;&lt;/a&gt;Click to Enlarge&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;...and here's how I'm going to be rolling.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/eE1eF-r1Rm0&amp;amp;hl=en&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/eE1eF-r1Rm0&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-4153686964687555769?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/FdCTkMupAEw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/4153686964687555769/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=4153686964687555769&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/4153686964687555769?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/4153686964687555769?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/FdCTkMupAEw/zango-dead-space.html" title="Zango: Dead Space" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_ZOjRj_3HrmA/Sg0uru1VqCI/AAAAAAAAAQA/3si0Shzf9qw/s72-c/zangd1.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/zango-dead-space.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUYMRno6fip7ImA9WxJRE0U.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-4333420350428178890</id><published>2009-05-14T22:24:00.019+04:30</published><updated>2009-05-15T14:56:27.416+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-15T14:56:27.416+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="ASK" /><category scheme="http://www.blogger.com/atom/ns#" term="Foxit" /><title>Why I Flushed Foxit</title><content type="html">Like many people, I've been digging around for alternatives to Adobe Reader in the wake of all those wonderful &lt;a href="http://www.google.co.uk/search?hl=en&amp;amp;safe=off&amp;amp;client=firefox-a&amp;amp;rls=org.mozilla%3Aen-GB%3Aofficial&amp;amp;hs=EPL&amp;amp;q=adobe+reader+exploits&amp;amp;btnG=Search&amp;amp;meta="&gt;exploit related stories&lt;/a&gt; in the press recently.&lt;br /&gt;&lt;br /&gt;Well, I'd heard Foxit mentioned quite a few times so off I went in search of fox-related goodness.&lt;br /&gt;&lt;br /&gt;In case you haven't guessed, IT'S ALL ABOUT TO GO HORRIBLY WRONG.&lt;br /&gt;&lt;br /&gt;See, here's the deal - if at any point during the install I see something I don't like, then I'm going to look for the escape route. You better &lt;span style="font-style: italic;"&gt;provide&lt;/span&gt; me with an escape route, or I'm going to complain about you on the Internet.&lt;br /&gt;&lt;br /&gt;In this case, I get one of these:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_ZOjRj_3HrmA/SgxgcJw1DqI/AAAAAAAAAPI/IjZKy4T3U9Q/s1600-h/foxt1.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 316px;" src="http://4.bp.blogspot.com/_ZOjRj_3HrmA/SgxgcJw1DqI/AAAAAAAAAPI/IjZKy4T3U9Q/s400/foxt1.gif" alt="" id="BLOGGER_PHOTO_ID_5335745695300521634" border="0" /&gt;&lt;/a&gt;Click to Enlarge&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;...and one of these:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ZOjRj_3HrmA/SgxgcCM8vPI/AAAAAAAAAPQ/aboRJmCi4WQ/s1600-h/foxt2.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 302px;" src="http://3.bp.blogspot.com/_ZOjRj_3HrmA/SgxgcCM8vPI/AAAAAAAAAPQ/aboRJmCi4WQ/s400/foxt2.gif" alt="" id="BLOGGER_PHOTO_ID_5335745693270981874" border="0" /&gt;&lt;/a&gt;Click to Enlarge&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;....and finally, I get an "Agree / Disagree to Ye Olde EULA" box. No problems so far, and everything is going swimmingly.&lt;br /&gt;&lt;br /&gt;But then...&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_ZOjRj_3HrmA/SgxrQVIOoKI/AAAAAAAAAP4/iTtnVP6xp24/s1600-h/foxt0.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 312px;" src="http://2.bp.blogspot.com/_ZOjRj_3HrmA/SgxrQVIOoKI/AAAAAAAAAP4/iTtnVP6xp24/s400/foxt0.gif" alt="" id="BLOGGER_PHOTO_ID_5335757586820931746" border="0" /&gt;&lt;/a&gt;Click to Enlarge&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Hey look, it's an ASK Toolbar complete with pre-ticked box things.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;DO NOT WANT.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Imagine my dismay when I look around for the button to cancel the install immediately (or even to back up a step) only to find that IT DOES NOT EXIST.&lt;br /&gt;&lt;br /&gt;Look at the picture - it's simply fallen off the installer and gone MIA despite a "Back / Cancel" button being on every other box I can remember seeing (they're in the first couple of screenshots!)&lt;br /&gt;&lt;br /&gt;Essentially, you're left wondering exactly how to exit out of this install. Also, see the "X" icon in the top right hand corner of the installer? Despite that X being clickable at &lt;span style="font-style: italic;"&gt;every&lt;/span&gt; stage of the install up to this point, you &lt;span style="font-style: italic;"&gt;cannot&lt;/span&gt; click it when you get to the ASK prompt because it suddenly no longer works. Why is this?&lt;br /&gt;&lt;br /&gt;You &lt;span style="font-style: italic;"&gt;can&lt;/span&gt; untick the License Terms box (thus opting out of the Toolbar install) and see the following:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ZOjRj_3HrmA/SgxgcgzKGFI/AAAAAAAAAPg/erK5Dai0v5Q/s1600-h/foxt4.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 54px;" src="http://3.bp.blogspot.com/_ZOjRj_3HrmA/SgxgcgzKGFI/AAAAAAAAAPg/erK5Dai0v5Q/s400/foxt4.gif" alt="" id="BLOGGER_PHOTO_ID_5335745701484304466" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;...but I couldn't care less about not getting typewriter tools and text converters. All I want to do is see the option to leave the install routine &lt;span style="font-style: italic;"&gt;entirely&lt;/span&gt; because I want nothing to do with a program that wants to install ASK products. So why don't I have one, Foxit?&lt;br /&gt;&lt;br /&gt;At this point, I decided to pop open Task Manager and kill the whole thing dead - specifically, I was going to cancel the Foxit Reader install. That's what I &lt;span style="font-style: italic;"&gt;thought&lt;/span&gt; would happen, anyway.&lt;br /&gt;&lt;br /&gt;What happened next momentarily stunned me so much that I was unable to get a screenshot the first time round. Check this out - here I am with the Foxit installer still open and Task Manager to the right of it:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ZOjRj_3HrmA/SgxgckMmsFI/AAAAAAAAAPo/yz1-Y2uO4MA/s1600-h/foxt5.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 187px;" src="http://3.bp.blogspot.com/_ZOjRj_3HrmA/SgxgckMmsFI/AAAAAAAAAPo/yz1-Y2uO4MA/s400/foxt5.gif" alt="" id="BLOGGER_PHOTO_ID_5335745702396342354" border="0" /&gt;&lt;/a&gt;Click to Enlarge&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;What happens the &lt;span style="font-style: italic;"&gt;second&lt;/span&gt; you hit "End Task" in Task Manager? &lt;span style="font-style: italic;"&gt;This&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ZOjRj_3HrmA/SgxiUJkadTI/AAAAAAAAAPw/6rgnsqxQCwQ/s1600-h/foxt6.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 184px;" src="http://1.bp.blogspot.com/_ZOjRj_3HrmA/SgxiUJkadTI/AAAAAAAAAPw/6rgnsqxQCwQ/s400/foxt6.gif" alt="" id="BLOGGER_PHOTO_ID_5335747756832748850" border="0" /&gt;&lt;/a&gt;Click to Enlarge&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;That's right kids, Foxit Reader (&lt;span style="font-style: italic;"&gt;not&lt;/span&gt; the ASK toolbar) INSTALLS ANYWAY.&lt;br /&gt;&lt;br /&gt;In fact, upon further testing I found the desktop icon for Foxit appears on your desktop the &lt;span style="font-style: italic;"&gt;moment&lt;/span&gt; you see the Toolbar installer prompt. In other words, although you THINK the Toolbar prompt is part of the overall install, it's not - the actual Foxit reader has already finished installing and you can happily run it while the ASK prompt is still sitting on the desktop.&lt;br /&gt;&lt;br /&gt;Making a "Back / Cancel" button vanish on an installer page asking me to install unwanted applications is annoying (and momentarily panic inducing) enough, but to discover the Foxit program has actually finished installing itself BEFORE I think the install procedure has completed is outrageous. The "Setup Completed" popup that appears when you think you've killed the install off in Task Manager is the rather grubby icing on an out of date cake.&lt;br /&gt;&lt;br /&gt;Lament your Resurrection within the flames of Hell, or as I like to put it, my Recycle bin.&lt;br /&gt;&lt;br /&gt;You won't be getting out of there anytime soon...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;/ Addendum&lt;/span&gt; - There seems to be a little confusion. The issue here is the way the Foxit installer behaved, the way the cancel install button fell off when I reached the ASK prompt (because as soon as I saw that, I wanted out of the whole deal - unchecking the ASK toolbar wasn't enough, I simply didn't want to have Foxit installed at that point full stop) and how Foxit had actually installed itself when the ASK prompt was still on the screen. The ASK toolbar did &lt;span style="font-style: italic;"&gt;not&lt;/span&gt; install without permission.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-4333420350428178890?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/eGQgRi9Mv4o" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/4333420350428178890/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=4333420350428178890&amp;isPopup=true" title="13 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/4333420350428178890?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/4333420350428178890?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/eGQgRi9Mv4o/why-i-flushed-foxit.html" title="Why I Flushed Foxit" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_ZOjRj_3HrmA/SgxgcJw1DqI/AAAAAAAAAPI/IjZKy4T3U9Q/s72-c/foxt1.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">13</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/why-i-flushed-foxit.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk8FR3w9cCp7ImA9WxJREUw.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-514723582709483994</id><published>2009-05-11T23:04:00.005+04:30</published><updated>2009-05-12T12:23:36.268+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-12T12:23:36.268+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Spywareguide Roundup" /><title>Spywareguide Roundup: Image Stealers and Halo Spam</title><content type="html">In case you don't read my writeups at Spywareguide, here's two quick links to tempt you into doing so. You naughty people, you.&lt;br /&gt;&lt;br /&gt;First up, we have the bizarre occurance of Chain Letter Spam on the XBox Live network - in the form of this rather fetching picture.&lt;br /&gt;&lt;br /&gt;&lt;div class="flickr-frame"&gt; &lt;a href="http://www.flickr.com/photos/paperghost/3522519154/" title="photo sharing"&gt;&lt;img src="http://farm4.static.flickr.com/3397/3522519154_1c6a6a1dcd.jpg" class="flickr-photo" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="flickr-caption"&gt;&lt;a href="http://www.flickr.com/photos/paperghost/3522519154/"&gt;halrec4&lt;/a&gt;, originally uploaded by &lt;a href="http://www.flickr.com/people/paperghost/"&gt;Paperghost&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;No seriously, you really &lt;span style="font-style: italic;"&gt;will&lt;/span&gt; get that armor if you send it to 50 people. Fo realz.&lt;br /&gt;&lt;br /&gt;Read all about it &lt;a href="http://blog.spywareguide.com/2009/05/halo-3-recon-armor-chain-lette.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Next up, we have a rather creepy infection designed to steal the images on your PC then send them via FTP to some pervert who smears himself in butter, or something.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_ZOjRj_3HrmA/Sghxz9n6-7I/AAAAAAAAAPA/n2rtJqPjnew/s1600-h/phuntr5.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 213px;" src="http://4.bp.blogspot.com/_ZOjRj_3HrmA/Sghxz9n6-7I/AAAAAAAAAPA/n2rtJqPjnew/s400/phuntr5.jpg" alt="" id="BLOGGER_PHOTO_ID_5334638896149625778" border="0" /&gt;&lt;/a&gt;Click to Enlarge&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Lovely, isn't it? More &lt;a href="http://blog.spywareguide.com/2009/05/infection-file-steals-images-f.html"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-514723582709483994?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/JxTtgowbaQU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/514723582709483994/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=514723582709483994&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/514723582709483994?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/514723582709483994?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/JxTtgowbaQU/spywareguide-roundup-image-stealers-and.html" title="Spywareguide Roundup: Image Stealers and Halo Spam" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_ZOjRj_3HrmA/Sghxz9n6-7I/AAAAAAAAAPA/n2rtJqPjnew/s72-c/phuntr5.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/spywareguide-roundup-image-stealers-and.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0EHRnYyeCp7ImA9WxJSFko.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-8070122466473341441</id><published>2009-05-07T11:25:00.001+04:30</published><updated>2009-05-07T11:30:37.890+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-07T11:30:37.890+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="It's not just Daily Mail readers complaining anymore is it?" /><title>Entrusting your data to Boots and Snappy Snaps</title><content type="html">&lt;a href="http://www.flickr.com/photos/paperghost/3509058961/" title="photo sharing"&gt;&lt;img src="http://farm4.static.flickr.com/3649/3509058961_84e210ac85.jpg" class="flickr-photo" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I am, of course, refering to &lt;a href="http://news.bbc.co.uk/1/hi/uk_politics/8036536.stm"&gt;this&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;God help us all.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-8070122466473341441?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/nb1RQrqJwfE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/8070122466473341441/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=8070122466473341441&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8070122466473341441?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8070122466473341441?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/nb1RQrqJwfE/entrusting-your-data-to-boots-and.html" title="Entrusting your data to Boots and Snappy Snaps" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/entrusting-your-data-to-boots-and.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkANSHw6eyp7ImA9WxJSGE8.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-7769005209612795863</id><published>2009-05-06T23:15:00.012+04:30</published><updated>2009-05-09T02:43:19.213+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-09T02:43:19.213+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft Live" /><category scheme="http://www.blogger.com/atom/ns#" term="Arkanoid" /><title>When is a "full game" not a full game?</title><content type="html">When it's purchased via Microsoft's XBox Live.&lt;br /&gt;&lt;br /&gt;For those not aware, if you have an XBox Live account you can purchase and download games from Microsoft's "Marketplace" using &lt;a href="http://en.wikipedia.org/wiki/Microsoft_Points"&gt;Microsoft Points&lt;/a&gt;. Generally, the games are of decent quality and the titles cater for most tastes.&lt;br /&gt;&lt;br /&gt;However - today, &lt;a href="http://en.wikipedia.org/wiki/Arkanoid"&gt;Arkanoid&lt;/a&gt; Live became available to purchase. People have fond memories of this game; it's one of the genuine old school classics and I remember playing a variant waaaay back when on the Commodore +4. Awesome fun.&lt;br /&gt;&lt;br /&gt;This is what you see when you come to download / purchase it:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ZOjRj_3HrmA/SgHdC8kaRoI/AAAAAAAAAOg/EkHOs04xcK0/s1600-h/arkand1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://1.bp.blogspot.com/_ZOjRj_3HrmA/SgHdC8kaRoI/AAAAAAAAAOg/EkHOs04xcK0/s400/arkand1.jpg" alt="" id="BLOGGER_PHOTO_ID_5332786476471699074" border="0" /&gt;&lt;/a&gt;Click to Enlarge&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"Full Game - Arkanoid Live: 800 MS Points"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;You couldn't be any clearer about what to expect for your money, or so you would think. Note that Microsoft "do not offer refunds" for their downloads, which they are at great pains to tell you every ten seconds. Despite being able to download demos of games, generally the demos are pretty short and lots of downloadable content is simply not previewable at all on the Marketplace.&lt;br /&gt;&lt;br /&gt;With that in mind, there's a fair amount of trust on the consumers part where these downloads are concerned - people expect MS to give them a fair shake, which I think is reasonable.&lt;br /&gt;&lt;br /&gt;When you fire up the demo, you see how many levels you'll be getting from the Menu screen:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ZOjRj_3HrmA/SgHfwCgR8SI/AAAAAAAAAOo/lZdI0tNbWck/s1600-h/arkand2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://1.bp.blogspot.com/_ZOjRj_3HrmA/SgHfwCgR8SI/AAAAAAAAAOo/lZdI0tNbWck/s400/arkand2.jpg" alt="" id="BLOGGER_PHOTO_ID_5332789450182357282" border="0" /&gt;&lt;/a&gt;Click to Enlarge&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;As you'd expect, Episode 1 is selectable and the others are greyed out. Therefore, if I pay the 800 MS points to unlock the "full game", I should gain access to the "full game" - which would be all four episodes.&lt;br /&gt;&lt;br /&gt;Imagine your dismay, then, when you pay for the game online, download it, expect to get what you've paid for - a "full" game (which, last time I checked, meant the whole thing) but then end up realising you're missing two whole episodes.&lt;br /&gt;&lt;br /&gt;As it turns out, you're primed for this bizarre absence in a wonderful piece of mealy-mouthed doublespeak when you attempt to exit the Demo. On the splash page urging you to buy to unlock the "full game" you see this:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ZOjRj_3HrmA/SgHhZIjpfnI/AAAAAAAAAOw/0yKP8YAS_LE/s1600-h/arkand3.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://1.bp.blogspot.com/_ZOjRj_3HrmA/SgHhZIjpfnI/AAAAAAAAAOw/0yKP8YAS_LE/s400/arkand3.jpg" alt="" id="BLOGGER_PHOTO_ID_5332791255693360754" border="0" /&gt;&lt;/a&gt;Click to Enlarge&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Some things that caught my attention:&lt;br /&gt;&lt;br /&gt;1)&lt;span style="font-style: italic;"&gt; Extremely&lt;/span&gt; interesting method of colouring one set of text white, and the other parts red. Note only does the white practically leap out and bite you, but the red parts are (by comparison) rather muted and fade into the background (they did for me anyway, on both a standard TV and a HDTV).&lt;br /&gt;&lt;br /&gt;Why is this important? Because the white text is essentially meaningless yet prominent (&lt;span style="font-style: italic;"&gt;UNLOCK THE FULL GAME AND CLEAR&lt;/span&gt;), whereas the red text gives the game away that their definition of "full" actually means &lt;span style="font-style: italic;"&gt;half&lt;/span&gt; (&lt;span style="font-style: italic;"&gt;ALL 62 ROUNDS OF EPISODES 1&amp;amp;2&lt;/span&gt;).&lt;br /&gt;&lt;br /&gt;So many people are going to miss this completely. I did, and I'm pretty well known for spotting junk in Adware EULAs and things of a similar nature.&lt;br /&gt;&lt;br /&gt;2) In the same way, the second section of white &amp;amp; red text puts the important bit (that lets you know 3&amp;amp;4 are missing) in red instead of the much more bold white text:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;YOU'LL THEN BE ABLE TO DOWNLOAD A FURTHER / ALL 62 ROUNDS OF EPISODES 3&amp;amp;4.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Curious, isn't it?&lt;br /&gt;&lt;br /&gt;Oh, notice that it doesn't mention anything about paying anything extra to get hold of these additional levels either. The problem with that is this: there is &lt;span style="font-style: italic;"&gt;no indicator anywhere&lt;/span&gt; as to whether or not you're going to &lt;span style="font-style: italic;"&gt;have&lt;/span&gt; to pay for this additional half of your game or not. If it's free content, then great - but why would they offer the second half of the game as a free download if they could have just included it in the first place?&lt;br /&gt;&lt;br /&gt;Many people (&lt;a href="http://forums.xbox.com/27090447/ShowPost.aspx"&gt;here&lt;/a&gt;, &lt;a href="http://majornelson.com/archive/2009/05/06/arcade-arkanoid-live.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://forums.xbox.com/27090899/ShowPost.aspx"&gt;elsewhere&lt;/a&gt;) suspect  that they're going to charge you a "small" fee to get the rest of the game.&lt;br /&gt;&lt;br /&gt;If that turns out to be true, then effectively an 800 point (10$ or £6.80) game just became 1200 points ($14.99 or £10.20).&lt;br /&gt;&lt;br /&gt;Of course, nobody is really going to care, and if / when an announcement is made in a few weeks / months regarding the additional levels costing money people will just treat it as "additional content" and pay up, forgetting that this game was advertised as "full".&lt;br /&gt;&lt;br /&gt;The ball is in your court, Microsoft, and people are already flipping out about this. If it does indeed turn out that you have to pay for the second half of the game, you can expect quite a few people to not want to give you money anymore...&lt;br /&gt;&lt;br /&gt;(By the way, I purchased Space Invaders Extreme today and noticed that too has a "download content" link on the title screen and is apparently made by the same company. If I find half my game is missing, I'm going to stab someone in the face. You have been warned).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-7769005209612795863?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/fLVGXnd6l8c" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/7769005209612795863/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=7769005209612795863&amp;isPopup=true" title="10 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7769005209612795863?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7769005209612795863?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/fLVGXnd6l8c/when-is-full-game-not-full-game.html" title="When is a &quot;full game&quot; not a full game?" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_ZOjRj_3HrmA/SgHdC8kaRoI/AAAAAAAAAOg/EkHOs04xcK0/s72-c/arkand1.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">10</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/when-is-full-game-not-full-game.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUcGRXw_eyp7ImA9WxJSEkU.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-8847244240912771499</id><published>2009-05-02T21:17:00.004+04:30</published><updated>2009-05-02T21:20:24.243+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-02T21:20:24.243+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="InfoSec Europe 2009" /><title>My Top Five Tips For Businesses On Social Networking Sites</title><content type="html">I've come up with a little list of tips I like to break out when talking about businesses jumping onboard the 2.0 train. They had a fair amount of positive feedback at InfoSec Europe, so feel free to &lt;a href="http://blog.spywareguide.com/2009/05/my-top-five-tips-for-businesse.html"&gt;check it out&lt;/a&gt; and also suggest your own hints for preventing too much data spillage on the web.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-8847244240912771499?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/HIgJheW6yZw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/8847244240912771499/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=8847244240912771499&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8847244240912771499?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8847244240912771499?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/HIgJheW6yZw/my-top-five-tips-for-businesses-on.html" title="My Top Five Tips For Businesses On Social Networking Sites" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/my-top-five-tips-for-businesses-on.html</feedburner:origLink></entry></feed>
