Monday, February 27, 2006

::

Adobe seemingly have an online service which will convert any PDF you submit to them into text or HTML. This is a service for visually impaired users [and not a way around the "Selection of Text Not Allowed" restriction] and graphics are discarded. I haven't needed to try it yet though.

Bear in mind Adobe reserve the right to forward your PDFs to other companies it thinks might find them amusing..

Sunday, February 19, 2006

Mister Vista

I'm installing build 5270 of Windows Vista [beta 2] on a virtual PC upstairs, as per the instructions here. So far so good. I tried to install it on VPC/Mac but it borked on lack of ACPI support in the BIOS: a real shame as the Mac has lots more RAM than the PC.

Installing a virtual PC via Remote Desktop is a real challenge: because Remote Desktop doesn't support relative mouse coordinating until Virtual Machine Additions [add-ons for VPC like shared folders from the host OS] is installed, the mouse behaves really strangely: capture takes minutes, and subsequently every tiny mouse movement correlates to a giant leap on the screen. The Windows Vista setup supports keyboard shortcuts almost completely: the "select partition" screen doesn't seem to support shortcuts for each partition. It's been a general trend for installations to ask fewer questions: Vista asks for a product key, a partition to install into (this may be the problem with build 5270 in VPC, if the technique in the link above doesn't work for you try this one) and a NetBIOS name, and then off it goes. I will have to wait to tomorrow to see if it worked though..

Edit: sort of. Running 5308 now which nearly works even better.

Tuesday, February 14, 2006

Chip And Pin

Much of this is based on an originating conversation with Rangor, Father Of George.

Consider a criminal retailer or retail employee whose desire is to obtain people's card details and pins for fradulent use.

The first thing to try will be to subvert or replace the existing card reader: the card readers in shops don't have any kind of identification or authentication from the point of view of the card owner - you put your card in (or you give it to the retailer and they take it away from you and insert in or swipe it or whatever - there's no standardisation there either) - and then that or another machine asks you for your pin. There's no standard interface, although admittedly even if there was it would be trivial to spoof. Unless your card can tell whether it is connected to a genuine card reader, you are more reliant on the honesty of the shopkeeper than you ever were: a spoofed card with a null signature might be used for purchases, but a spoofed card with a known pin can be used to withdraw hundreds of currency units per day from cash machines anywhere, especially ones away from cameras.

Anyway, you don't even need to do anything to the machine, you just need a couple of cameras yourself: one to scan the card numbers on the way to the reader and one to look over the customer's shoulder and record the pin. Or use the inbuilt record of card numbers and use an accomplice who stands in the queue and notes the pins. If the card reader is able to access information about the card holder from the card (date of birth and the like) then Mr Bad doesn't really need the pin: statistical analysis will have been done on the most frequently used pin numbers anyway, patterns like 1234 and the DD-MM of the card holder's date of birth will have significant usage which makes guessing the pin trivial in an economically significant number of cases. If x% of people use a simple combination of the elements of their date of birth as their pin, then all you need is their card number: if you collect a million numbers and try them all once, enough will succeed to make it all worthwhile. The x in x% doesn't need to be very high. If at first you don't succeed, try another. If you do succeed, go crazy.. No notifications of failed authentication attempts are provided to the card holder, even if they're kept: the card issuers will be canny enough to look for authentication failure patterns, but these could be masked by hiding them within enough successful transactions. What are the thresholds? Are small transactions even checked? Is that why sometimes transactions are seemingly randomly declined, because an attempt is being made to brute-force the pin? While I'm asking questions, what encryptiopn is used anyway? What OS are these devices running? Are the keys hardcoded into the device's hardware or software? What is to stop transactions being recorded and replayed?

A classic man-in-the-middle technique would be the "first-fail": the keyboard (which you should remember may not even be the same device that read the card) is presented to the customer to enter their pin. But the device fails the pin and asks the customer to retry. This time it works. In this scenario, the device has been subverted by the retailer: the first pin entry is simply logged, and the second is passed onto the network for authentication: don't tell me that in a world full of people installing linux on toasters this is impossible. A much easier variant of this: a small transaction is recorded by a "device" but the device was cooked up by the retailers evil nephew or niece: it simply reads the card details (all the smart stuff too) and the pin you enter, then it say PIN OK. You never get charged for the transaction, but why would you notice? EFTPOS transactions can take weeks to go through. The card isn't authenticating the reader, so the card holder has no way of knowing where she just put her pin.. The value of card details and pin to our unscrupulous retailer are far greater than the 1.42 currency units of the transaction which the cardholder gets for free. If they ask you to reenter your pin on another machine ("sometimes we have to use the old one") then leave the shop and call the police.

Oh, there are lots more problems with the current implementation of chip 'n' pin. Sometimes you read cash machines are safe - where were they when all the examples of criminals installing fake cash machines or fake covers over existing machines were in the news? These have to be sunken into the wall of a bank before they appear authentic, and they still worked, and cash machines now routinely warn people to watch for spoofed interfaces. The machine in the shop into which you enter your pin is presented to you: it might be on a cord (connected to something you can't see anyway) or wireless, it might have your card in it and it might not: you know nothing about it, and have no means of knowing what it is doing with the pin you enter into it.

An unsubtle but effective approach for criminals too lazy to invest in card-spoofing technology would be to determine the customer's pin using one of the techniques above, and then pickpocket (or mug) the customer. Ouch. Or, if there's a facility to enter the card number manually when the card can't be read (and I think there is) then simply submit transactions using the card reader: open for a month, collect lots of numbers and pins, then spend a week hammering those accounts and disappear with the moolah before the complaints come in.

All the hype about 'identity fraud' ignores the fact that fraud via impersonation is much older than bank accounts, and fully punishable by existing laws. Attempts to make it seem an unchecked menace which can only be solved by chips, pins and ID cards are simply fraudulent themselves. As the shopkeepers are being compliant there must be something in it for them, a reduced charge probably, but there's nothing in it for the cardholders except increased risk: the banks and shops are happy though so nobody cares.

My advice is to always use cash at places like markets, firework shops, and the like where the retailer has only a temporary presence. This doesn't protect against corrupt employees, so if you're worried (you're extremely unlikely to suffer any personal losses from this kind of fraud) then use cash as much as possible, then, except in retailers you trust and where you can visually authenticate the card reader.

There are a lot of other interesting things the banks and retailers keep quiet: automatic reauthentication within a set time, retailer flow rates, and the fact that supermarkets hit the "override pay" button which authenticates the transaction whether you have the money in your account or not: for them it is very bad business to turn customers away leaving checkouts clogged up with their suddenly unwanted shopping, and since they get their money anyway they're happy. The card holder gets charged so the bank is happy. The customer is fucked off, but that's tough..

One of the other consequences of chip 'n' pin is the transference of the liability of fraudulent transactions supported by signature alone from the card issuer to the retailer: this means if the shop lets you sign instead of using your pin then they don't get reimbursed if it's a stolen card. This doesn't apply to chip 'n' signature cards, which the banks are being very quiet about: these tell the retailer to rely on signature alone and intended for groups like blind people. If you're uncomfortable with using chip 'n' pin you might think about asking your bank for one, but banks are insisting that people applying for chip and signature prove that they are registered disabled.

Drafts

Whenever I save a post as a draft, it disappears from the post list in blogger. The first dozen or so times this happened I assumed it was lost forever, but it turns out they still exist and can be accessed by searching for a space (using the search in the "manage posts" page) It must be some obscure bug in my blogger profile.

Friday, February 10, 2006

Note to self

Next time you're in Amsterdam go here.

Sunday, December 04, 2005

The Airline Screening Playset

The biggest departure from reality was that the passenger had a cheery smile on her face
The Airline Screening Playset

Tuesday, November 29, 2005

Are they mad? Or is it me?

Using my Mac I can't download from Microsoft, because I'm not running a genuine copy of Microsoft Windows. Well, *_der_*. The Microsoft MSDN subscriber downloads I can understand, they use the completely ridiculous File Transfer Manager - some crappy "download manager" from 1999 given a tart up and stamped with the MS brand - to restrict access. My employer (who pays for the MSDN subscription) uses a Microsoft proxy server which the file manager won't go through [my irony detector is tingling] so I used to download things at home and burn them onto CD for work. This file transfer software won't work on a Mac of course.

Edit: this includes products like Virtual PC for Mac - you need to be using Windows within Virtual PC on a Mac in order to download Virtual PC on a Mac. As my MSDN subscription comes on DVD and my iBook doesn't have a DVD drive it is annoying not to be able to simply download the item, but as we can all observe the sky is still in place.

Well, if protecting Microsoft's market share was the purpose of this restriction, then it has kind of worked - I will have to keep a PC around still. Not that I am angling to get rid of it - I am looking forward to trying Microsoft Vista, and I read today that I will get the full AquaGlass experience as I have a fancy graphics card I bought to play Doom 3 twice, and I am itching to see how much they have ripped off from OSX. Have to solve the no-monitor-attached problem, though, I suppose. Still, Vista's not going to be out for a long time yet.

But then I was interested in the Vista User Experience guidelines - user interface and design recommendations for the new operating system. Not so fast! I am told: "You are not using Windows. Fuck Off" [paraphrased]

Again I have to use Windows before I can read about Windows? How do they ever expect to win any converts to this new recursive operating system of theirs??

Saturday, November 26, 2005

Even Christ Stumbled

I didn't think I'd care when George Best died - he was Man U, I'm not quite old enough to remember him playing - but I do. He was a fantastic player, and he was brave as fuck on the pitch as well as off. We won't see his like again, he was a man of his time. Waste of a liver though.

Friday, November 25, 2005

He's right, of course

The ID card debate in the U.K. is all about population control - it's about controlling immigration, not terrorism. It is unfortunate that the U.K. isn't having that debate properly.
Bruce Schneier
Perhaps because we are too well controlled already.

Going Postal

Don't bomb Al Jazeera! or his brother Kevin Jazzera.

Thursday, November 17, 2005

Rachel North

A bomb was detonated on my London Underground carriage on 7/7/2005, killing 26 people behind me...
Read what she says about civil liberties.

Wednesday, November 16, 2005

Hmm

Remote needs new batteries.

Meet Crypto Cat™ and Decipher Dog™

NSA 4 kids. Woh looc si taht!

ACAB

I was coming home once on holiday with a stolen hotel towel, which was discovered by customs (I recall myself as wearing a stetson at the time, which was the fashion. In my house anyway)

The airport copper said something to me I have never forgotten:

I'll let you go, if you promise me something in return: if you ever see a copper getting his head kicked in, you'll help him [presumably by phoning for more police..]


So the police want to know what the public want? Here's my list.

  • Don't carry guns. Resist efforts to arm police. Make drawing a gun the last resort (let alone using one). Routinely suspend officers who draw their guns, let alone use them. Don't carry them at airports, train stations, party conferences, *anywhere*. Try and learn the lesson of Jean-Charles de Menezes, essentially by making sure it never happens again. Random executions of innocents makes us feel very uneasy.

  • Don't ask for internment [detaining suspects without trial] or similar police state powers. Resist any attempts to impose such injustices. If your suspects don't confess after a fortnight, why should they after three months? Do you think they might get bored? Or are we going to take up torture, like the US?

  • Don't try to scare us with this "threat" crap. We're not Americans, we grew up with terrorism and bombs and carnage and "don't-go-up-west-to-do-your-XMAS-shopping-cos-the-IRA-are-going-to-bomb-Oxford-Street" which we heard every fucking year in life.

  • The role of the police is not, and never has been, to fight terrorism. That's the job of CI5 or MI6. Try catching criminals, you seem to find that hard enough anyway.. We won't blame you when terrorist actions occur now, any more than we blamed you for Guildford, Birmingham etc. While I'm at it - please make a point to aim in future to try and convict the actual perpetrators of the crime, instead of some people who simply match an ethnic profile.

  • Oppose ID cards.


Simply, you need to champion the rights of the public, and to minimise the powers of the Force (how aptly named..) to the minumum needed to do the job we pay you to do. Then we might grow to trust you again.

See, it's not just about how we the public define you the police - it's really about how you define yourselves. Do you [like John Self in Money on reading 1984], see yourselves as "ambitious young corporals in the Thought Police" or do you see yourselves as the guardians of public liberty? I wonder.

And while I'm on the subject, I justify the title of this post with memories of Orgreave and the Battle of the Beanfields. Bastards. And I still think Ian Blair should resign.

Friday, November 11, 2005

Don't feed the monkeys

"Protect the airspace and homeland" with the Sky Posse. Idiots.

out-geeking rangor

Hide files in TinyURLs with TinyDisk.

Edit: From the faq:

Q: This damn thing doesn't work on large files! #@%& You!
A: Did you not read the manual? Man I wish I could punch you in the face over TCP/IP!
FAQ
he says what we're all feeling..

There were 150 of us living in a shoebox in t' middle o' road

If you're after an Oculas then look no further - have to have a Mac keyboard fitted, mind.

Friday, November 04, 2005

The Asian earthquake that didn't result in a Tsunami

Eid is a time for giving to charity, DEC is the place to do it. Given the choice between saving lives and not saving lives, what can you do?

Thursday, November 03, 2005

Have you got news for me?

Jon "My Ace Blog" and Shirley got tickets for tonight's recording (at the ITV London Studios on Upper Ground, SE1) of Have I Got News For You [a topical TV program featuring the current Funniest Living Englishman, Mr Paul Merton] and were kind enough to invite us to go with them. The tickets are free but they overissue them to ensure a full house..

The London orbital was jammed anti-clockwise (we dropped LO off with her Aunt Margaret & Family who live a couple of junctions clockwise) so we had to detour through the shithole I grew up in, which was as jammed with traffic as it's been every day for the last 30 years. Gripped with loathing, I followed the signs like a drone instead of striking out and looking for a clearer route.

Still, we got in in the end, and London was just totally rammed full of traffic, as if giant hydraulic presses were forcing cars where it seemed no more cars could go. As if that wasn't bad enough, I was discombobulated and missed a couple of turns. At one point I turned right when I should have gone straight on and had to redrive some of the Mitcham one-way system - not a big deal, but another delay. I remarked something like "Sorry about that one more minute of delay more but in the scheme of things it won't make any difference".

We got to the ITV London Studios at door opening time, seven o'clock - we had planned to arrive at six, everone else got there at five by the sound of it - and joined the end of the long queue. Some poeple joined the end after us, but they were queuing to see Parkinson, and scuttled off. At that point, we were warned that we may not get in by an employee of the production company who had counted the queue. The thing is, you never know, you _might_ get in.. maybe some people in the queue would change their mind, leave their tickets at home, feel ill, spontaneously combust.. and then some poeple joined the queue after us, a dozen or so, so we felt better.

We queued for about half an hour, until 7.30 came which is No Further Admittance time. We weren't in, but we were close. At this point we were next to the bronze cast handprints of ITV's A-list - Davina McCall and Beck's mum's old boyfriend Des Lynam (_big_ hands) were the one's I've heard of.

We were at the very very front of the queue, our noses pressed to the glass of ITV's warm cheesy lustrousness, when the bad news eventually came that they were full. The compensating good news was to follow rapidly - we would receive priority tickets "with a dot on" for a forthcoming recording, which means none of this queuing lark, straight to the front and into the best seats. It was a relief to be told that the last seats available have extremely limited views - "You'd only see Paul Merton [FLE] walk on and you'd see him walk off, you're better off watching it on TV".

We went to a cavernous diagonal Pizza Express across the road. We did recall the Mitchum redrive incident, but everyone was kind enough to represent it as the difference between seeing the recording while separated singly through the audience wherever the view was worst, versus going back to London in a couple of weeks time and seeing it from the best seats, with no queuing. If we drive again - the studios are close to Blackfriars, which is easily accessible by train from Brighton - I can take my car, which is currently having a new cylinder head gasket fitted. That should be much more comfy for the overall journey, Becky's is a town car, albeit one with a rocket for an engine.