Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Monday, May 7, 2012

No Free Speech on Facebook

If your boss is an elected official, free speech allows you to express support for their opponent in an election. If, however, you "like" your boss' opponent's facebook page you can be fired.


Judge Raymond Jackson in Virginia okayed the firing of a deputy by the sheriff because the deputy "liked" the sheriff's opponent's facebook page. Since clicking a "like" button is not verbal, clicking a button is not speech. Hence, not protected.

Well, by extension of "verbal" to "speech" logic, Virginia is paving the way to oppress the deaf and the mute. Isn't that nice?

Tuesday, April 3, 2012

Do Not Try This!

Again. Do not actually try this. If the video is real and you try this, you are knowingly involving yourself in fraud!

Let the proper authorities investigate this situation.

[Click for Fraud Video]

The video never did confirm that money was actually charged to the credit card. This could mean that there was never any actual fraud. There could be an after-transaction confirmation from the credit card company. I do not know if there is such a thing, but I will not actually say that fraud has been committed.

If the video does demonstrate a true security weakness you might be thinking "So what. I can use incorrect information to make a donation with my credit card." The truth is so can anyone else.

The following is for informational purposes only. It is intended to describe how criminals think and why you need to secure your websites and transactions.

You can not steal money for yourself, but you could donate someone else's money to Obama.

What you need and what to do:
  1. A scriptable browser
  2. A proxy or set of proxies in the cloud to surf the web with
  3. Use a script to scrape the web and harvest email addresses
  4. ( optional step ) Use a script to scrape the web and harvest real addresses
  5. Run a script to use this information to automatically fill out and submit donations. Script will need:
    • Credit Card number generator
    • Cookie clearing between donations
    • ( optional ) Proxy switching
    • Access to the data harvested
Basically, someone might guess your credit card number and successfully make a donation using it.

I know there are other methods that can be used and the above method does not guarantee you will not get caught. This is just a simple glossed over explanation of how it is done.

NOTE: If any comments are submitted on better trade craft, "how to," tools, etc., I will have to deny the comment.

Twitter Trending to Announce Release of Private Information

!!CORRECTION!!

Ancestory.com is paying for the hash tag! I was wrong when I said the government paid for it!
Ancestory.com is highlighting the release of personal information from the government.
I was totally going to ignore this blog posting on the Dept. of Commerce blog because I thought it would be bad to highlight this. Unfortunately I was on twitter and saw something that became a "wtf" moment. It was in the trending box when I saw this:
Can you see that promoted hashtag? #1940census

What is this about? Releasing private information from the 1940 census.

Census Bureau Director Robert M. Groves gushes on what a treasure trove of information this is for genealogy. He is the genealogist of the family and only has family history ranging from 1670 through 1930. He can't wait to get his hands on the information to help complete the family tree.

What? A lot of families have their family tree recorded in a Bible. Many families track this in some way as people are born. Limited family trees usually go from the present back 100 years, not back 300 years with a gap from the present to 70 years back. I'm sure he must know who his parents and grandparents are, but his post says he doesn't. The post is just disingenuous.

Is it possible that something bad can happen from releasing this information? That is unknown. Information by itself can be harmless, but tying together bits of information becomes intelligence. What's the worst that could happen? Paranoia at the tilt here, someone distantly related to you in a "blood feud" has a nut job foe that tracks you down. Fantasize your own nightmare scenario. Maybe even identity theft can get involved.

So why is this a "wtf" moment? A promoted hashtag is an advertisement. A hope for viral marketing paid for by your tax dollars in hopes that everyone will know the government is releasing personal data. Aren't you glad the government taxes you?