Archive for the 'Snark' Category

Absurd Correspondence with some Corporation

Sunday January 3 2010 @ 2:59:53 pm
Message by you on Thu, 3rd Dec 2009 2:16 am
I recently noticed that my Tripod web site had been suspended “because of a phishing attack and or possible identity theft attempt”. I don’t have much more to say about because a casual glance at the site should make apparent that this claim is patently false: for one, I’m pretty sure the site was last touched before the term “phishing” was even coined, and at no point has it ever contained any content that could possibly be construed as a phishing attack.

This both astonishes and bemuses me, since it should be immediately obvious to anyone who so much as glances at the site that it’s not masquerading as any kind of business or requesting any kind of personal information at all. That said, I’m mostly curious as to what kind of response this will get me, and whether anyone will be able to illuminate the doubtlessly ludicrous grounds for the suspension. I would like to see the site put back up since, after all, I didn’t take it down myself, and the idea that it facilitated any sort of identity theft is so laughable a claim that I can’t possibly believe any human could have investigated it.

Message by our staff on Fri, 11th Dec 2009 1:33 pm
Hello and thank you for contacting Lycos support. I apologize for the delayed response.

If you have an old site and the script is not up to date, it will be very vulnerable to attacks. In this case it appears as though your account had malicious code inserted, which is not always obvious when browsing the site as it is the site code itself that is the source of the problem. Unfortunately this is the case with your account which is why we have closed it.

If you would like to bring your site online again simply sign up a new account and upload a backup your web files.

I do understand your frustration in this matter but we have no choice but to close any hacked accounts as they threaten the security of all accounts on our server, as well as cause a number of other obvious problems.

If you have any further questions or concerns, please let us know.

[name redacted]
Lycos Customer Service
http://help.lycos.com

Message by you on Fri, 11th Dec 2009 2:15 pm
Hi [name redacted],

I appreciate your response, but I must confess that I’m confused. For starters, I was not using any server-side scripts of my own on my site. (To be sure, I would have liked to, but the particular scripts I had wanted to use were unable to run on Tripod’s servers because of—ironically enough—security concerns.) The closest anything on the site came to that, as I recall, were some pages created with FrontPage that would have used extensions installed on your servers—but those would have been maintained by Lycos, not me, as I had no access to those server-side components. Thus if there were any malicious code inserted on my site by “the script,” it would have had to have been caused by security vulnerabilities in code that was neither uploaded nor maintained (nor maintainable) by me.

Second, the notion that you must “close any hacked accounts as they threaten the security of all accounts on our server” reads like a weak excuse—I’m not sure whose policy that is, but whoever approved it appears to not understand basic principles of security. Any reasonable server configuration would isolate the security of other users’ accounts from that of my own; else there would be nothing stopping me from intentionally adding malicious code to my own site so that I could maliciously subvert the security of other accounts on your server. I don’t imagine that that would be possible, and if it is, that’s again indicative of security vulnerabilities of your own that are entirely outside my own control. If I am somehow mistaken in the assumption that my site could not actually pose any security vulnerabilities to other accounts on your servers, I would encourage you to forward my comments to whoever would be in the best position to audit your own security practices.

Furthermore, your suggested remedy that I create a new account from a backup is fundamentally flawed: if I were running vulnerable scripts on the first account, they would obviously still be on the second account, since I’ve been given no indication as to how this malicious code (which I haven’t even been able to look at myself) was allegedly added to my site. (Throw in the fact that I wasn’t running any scripts at all and it makes matters doubly confusing.) In addition, creating a new account necessitates using a new web address; since Lycos would still be hosting the site, it’s unclear to me how hosting a potentially vulnerable site at a different address would be anything other than an inconvenience for me and whatever visitors I may have had while providing no benefits to Lycos or “the security of all accounts on [your] server”. Lycos’ policy in this regard seems as though its biggest advantage is that it rewards the efforts of malicious hackers by permanently rendering their victims’ sites inoperable.

Thanks for your time.

I guess “thanks for your time” is more or less synonymous with “I have no desire to continue this discussion despite all of the words I just typed,” since they closed my support ticket (and I get the sense that reopening it would be, to say the least, unproductive). But I guess it’s kind of amusing.

Comments (0) | Geekish,Snark

How to take over the State Senate

Tuesday June 9 2009 @ 7:29:08 pm

Austin Shafran, a spokesman for Smith, who says he remains the majority leader, told an Albany radio show a lawsuit was definitely a possibility. The GOP broke Senate rules by not submitting their leader-changing bill to a committee or gaining Smith’s consent, he said.

Control of NYS senate in dispute, deadline looms | Markets | Markets News | Reuters.

Silly Republicans. Didn’t you know you need the majority leader’s permission before you can replace him?

Comments (0) | Snark,Sophisticated Commentary

Food Literacy: not the same thing as actual literacy

Saturday April 25 2009 @ 3:32:21 pm

So HUDS sells this “93 Gallon Canteen” that’s supposed to deter people from using disposable containers, like paper cups or bottled water. I bought one yesterday since I had over 100 bucks still burning a hole in my BoardPlus account, and as any good Harvard student knows BoardPlus is worthless unless you spend it by years’ end. Apparently the Food Literacy Project is also involved in producing these canteens to some degree, since they have their logo stamped on the thing. So I find it particularly amusing–and, well, somewhat embarrassing–that the blurb on the canteen (about how exactly you’re saving 93 gallons of… various things?) reads, in part, like this:

ensuring it's everyday safety

The EPA regulates tap water, ensuring it’s [sic] overall safety.

“It’s”? “It’s”? Are you kidding me? I think Strong Bad said it best, so I’m just going to leave this one to him.

Comments (0) | College,Snark

On McCain’s VP Pick

Friday August 29 2008 @ 4:09:20 pm

Obama campaign spokesman Bill Burton released this statement earlier today on John McCain selecting Barack Obama as his Vice Presidential candidate:

Today, John McCain put a former state senator with zero foreign policy experience a heartbeat away from the presidency. Senator Obama shares John McCain’s commitment to warrantless surveillance programs, the agenda of gun manufacturers and increasing our military presence abroad — that’s not the change we need, it’s just more of the same.

Comments (0) | Snark,Sophisticated Commentary

Wikipedia: Friend or Foe?

Thursday August 28 2008 @ 5:04:44 pm

While I was pleased to hear of this decision in the Veoh case, I couldn’t just let this tidbit slide by without mentioning it:

(The judge also consulted Wikipedia to better understand what “Flash” might be, and he concluded that it is “the name of a file format used to transmit videos over the Internet.” Remember, kids, Wikipedia is only good enough for the federal judiciary to make precedent-setting legal decisions, not for your term papers.)

Veoh Safe Harbor ruling could help YouTube in Viacom battle

Comments (0) | Geekish,Snark,Sophisticated Commentary