Claiming the blog on Technorati

Interesting security problem that Technorati is trying to solve: how do you prove that a blog belongs to you? (In general, how do you prove that a web page belongs to you?) This is an analog of the standard email validation problem. Only email is a “write-only” media– given the email address of a person you can only write to that address. URLs are generally speaking “read-only” in that you can only view the page contents, although the web also allows more interactive content where in principle the viewer could also submit input.

Technorati has 3 options:
1. OpenID. This is natural, because the protocol was motivated by the need for having authenticated comments across blogs and URLs are used as the identifier instead of email addresses. OpenID is supported by a number of significant players including LiveJournal and AOL, and has recently received a boost after MSFT announced a way to leverage CardSpace for stronger authentication. Downside: this only works if your blogging service implements the spec as identity provider.

2. Provide username/password. Technorati signs into your blog on your behalf. Another straightforward proof, only this one requires an awful degree of trust in Technorati: you have to hope they do not publish your credentials on the Internet or use them for posting 100 spam entries. (And you did not use the same password at your bank, did you?) More sophisticated authorization systems would have the notion of “delegation” where Technorati is temporarily granted access without credentials, and may even be restricted to read-only for example. On the web, identity management is very much a V1 concept, with the exception of Windows Live ID.

3. Creating a new post with special link provided by Technorati. This is email validation in reverse: instead of sending users an email containing a link with embedded identifier, URL validation requires the “prover” to put some content with unique ID on their page, the content being chosen by the “verifier.”
And that is the purpose this article serves.

Technorati Profile

cemp

Internet jurisdiction attempt, the Istanbul way

Not the finest hour for Turkey in its continued efforts to defend national identity.

1. Turkish court banned YouTube on Wednesday, March 7th. Turk Telecom, the largest ISP in the country enforced the ban, by  what appears to be at the network level by blocking any traffic to the website.

2. It then lifted the ban two days later on Friday, but not before the story had been picked up widely in the Western press.

cemp

Sad state of credit-card disputes (part II)

(Continuing earlier post about American Express)

Since the customer support representative claimed that recurring charges could not be stopped until the merchant got their act together, the next step was escalation: “In that case, I’d like to cancel this card.”

This is where the AmEx rep uttered the incredible lines: “You can do that, Sir. But it is not going to help you, because they can still continue to charge your card and you will be responsible for the charges.”

Let’s pause and re-parse that: this person working at the out-sourced call center for American Express claims that companies can continue to bill recurring charges to your account, even after you have cancelled the credit card. There are 2 possibilities:

  • (Likely) AmEx support is making a false representation, in order to avoid customer churn.
  • (Unlikely) It is possible to bill charges to a credit card that has been cancelled. This is unexpected because past experience suggests that when a card expires, all subscriptions set to bill regularly on that payment instrument throw up errors and companies send email along the lines of “there is a problem with your payment, please update your credit card information.” It would also mean that once a credit card is lost due to theft, the legitimate owner is still in trouble even after he/she calls the company to close the account and receive a new card.

cemp

Inconvenient living: eco-wisdom from the Academy Awards

It was an encouraging sign that An Inconvenient Truth won the Academy Award for Best Documentary, which allowed its protagonist to bask in the limelight and re-iterate his message from a forum with unprecedented reach. For all its runaway success, it is likely that more people have tuned in to watch the ceremony than have showed up at the local cineplex to see the movie itself. Granted Hollywood does have a reputation for being on the cutting edge when it comes to environmentally friendly messaging. It was not out of character when Mr. DiCapprio announced that the academy awards web-site would feature tips for greener living.

Unfortunately a quick peek at the recommendations shows how unrealistic expectations can be, compared to the average life-style in America:

Reconsider extra features such as automatic transmission and 4-wheel drive — they are often unnecessary and eat into gas mileage.

True enough, but how many manufacturers today even offer a standard transmission as option? And for that matter how many drivers could drive one? (And this advice is dated: sequential manual-gearboxes are just as efficient but still controlled automatically. Not to be confused with a standard automatic transmission, these use gears but the clutch is not operated by the driver.)

Leave the car at home. Get in the habit of riding buses or trains as often as you can (just think of all the new people you’ll meet!). For short distances, ride a bike or walk whenever possible.

Unfortunately public transportation is dysfunctional in most of the US, owing to suburban sprawl. The architecture of suburbia, predicated on car ownership, is outright hostile to pedestrians. There are no sidewalks and nothing within walking distance, no bike lanes and only inconsiderate drivers to share the road. This would only work in dense urban cores.

In the winter, set your thermostat at 68° in the daytime and 55° at night. In the summer, keep it at 78°.

That one is not going to be a popular measure. Certainly not in retail, considering that in the early 20th century movie theaters used air conditioning to attract crowds and recently New York Times found an inverse correlation between prices and temperature of the store. Homeowners will likely balk and leaving office spaces the only chance for such drastic climate alteration, where it would make for a new Dilbert episode.

Let the sun shine in. The cheapest and most energy-efficient light and heat source is often right outside your window.

Try explaining that one to Seattlites.

If you must water your lawn, water early or late in the day or on cooler days to reduce evaporation.

Cookie-cutter suburban houses with manicured lawns would not be possible without wasting tons of water, a practice helped along by the real-estate bubble which guarantees the better landscape house enjoys a premium, since they are all identical and have no character to distinguish them otherwise.

Not all the suggestions are such exhortations for austere, spartan living. For example, the use of compact fluorescent lamps is a clear winner. But the Academy seems to have forgotten why CFLs have become that unstoppable idea whose time has come: because they provide clear, easily articulated benefits without requiring that consumers give up on something they are used. This is the hallmark of progress in efficiency:  doing more with less. Whether it is measured in watts, lumens or total cost of ownership, CFLs edge out the older generation technology– there is no trade off in giving up one factor to maximize another. Asking people to learn to operate a clutch, not water their lawn and put on more layers at home does not have the same ring.

cemp

State of the art in credit-card antifraud

Let’s start the day by recounting a recent encounter with American Express’s finest customer service.

This is not the first time that AmEx has engaged in dubious practices when it comes to protecting user information. For a very long time their login page did not use SSL, instead trying to make up for that by placing an ersatz padlock icon on the page, no doubt playing to the confusion in users’ minds about the meaning of web browser security indicators. Their latest exploit involved the pioneering of RFID chips in credit cards– perfect time, considering these new Blue cards came out around the same time as news stories about the ease of cloning RFID chips and skimming information from RFID devices carried by unsuspecting victims.

The incident in question started out as a simple unauthorized charge from DirectTV, a satellite provider. Considering that this blogger has cable at home, this was clearly a case of mistaken customer. At least in the US such errors are easy to dispute. Onus is on the merchant to prove that the charge did take place. After a cordial phone conversation with a representative, the charge was suspended pending investigation.

Fast forward one month. Another charge from DirectTV, about the same amount. Clearly this is set up as recurring charge, one of those auto-payment options where the company bills subscribers every month after the user provides their credit card number once. Another call, another dispute, charge placed on hold again. Only this time the conversation is less cordial. The customer service rep claims that American Express has no way to block payments from a merchant. In other words, until DirecTV wises up to the error, they will continue billing every month and this dispute charade must continue each time.

That’s right: for all the sophisticated fraud detection algorithms, designed to cry foul when a bachelor used to buying beer starts purchasing diapers on his card, the credit card networks can’t implement a simple rule along the lines of: “block all charges to this account from this merchant.”

(continued)

cemp

Another full-disclosure debacle at Black Hat

Here we go again. It’s almost as if the lessons from 2005 Michael Lynn incident were completely forgotten. Granted the conference has changed ownership but the challenges to full-disclosure from over eager companies remain the same.

In this case Kim Zetter of Wired News reports that a demonstration of weaknesses in RFID proximity cards by Chris Paget of research firm IOActive was scuttled after some legal scare-mongering by HID, a vendor that produces such cards. Quote:

IOActive says it offered a few compromises after hearing from HID, including allowing an HID representative to appear on stage with Paget to discuss its product — but HID wouldn’t agree not to sue.

The incredible part of this is that the vulnerability was already demonstrated at another conference (RSA 2007) earlier in February. And just like the remote code execution in Cisco routers that the company tried to suppress in 2005 (ever wondered why the conference proceedings are missing an entire section of pages from that year?) the incident only served to increase awareness of the problem and draw more attention.

cemp

Netflix vs. McDonalds vs. iTunes

McDonalds likes to boast about its billions of burgers served. According to a BusinessWeek article it took slightly more than 8 years for the franchise to hit the first billion mark. But Netflix reached the same milestone in seven months less, which is the main point of the article. At its current pace of 1.5M DVDs in the mail every week, the projected time for next billion is another two-and-half years. Even more telling is the growth rate which promises to cut down that time drastically: Netflix added over 2 million customers last year to reach 6M+ total subscribers and expects to reach 20M by 2012.

While entertaining, this comparison between making burgers and mailing out DVDs falls flat for many reasons. First is relative population: McDonalds started in 1955, when US population stood at less than 200M. Today in the wake of crossing 300M, Netflix has a much larger customer base to draw on. In relative terms, McDonalds expansion in its earlier years was faster. On the other hand a single Netflix DVD could mean multiple views, since the average family of 4+ individuals will all watch the same single disc. Burgers are not exactly intended for sharing. Netflix also does not face the same geographical challenges. While the company operates warehouses around the country for receiving and shipping DVDs, its reach within the continental US is a function of the postal service. No physical presence is required. By contrast proximity to customers is crucial in retail and the Golden Arches depends on a relentlessly following suburban sprawl to build new franchises.

A better comparison may be iTunes, which recently crossed the 2B threshold. A creature of the technology industry, free from any geographic limitation or even the problem of transporting stuff around by mail, its meteoric rise has been hailed as a sign that traditional music distribution is obselete. (A cautionary second opinion points out that online sales are still a tiny fraction of all music purchases and news of the RIAA dinosaur extinction may have been slightly exaggerated.)  It shows similar exponential growth pattern: hitting half billion on July 2005, one billion in February 2006 and two billion recently in January 2007.

cemp

Past anniversary of congressional hearings: US companies and China

“I do not understand how your corporate leadership sleeps at night”

(Rep. Tom Lantos, democrat CA)

You might think that Rep Lantos had been grilling representatives from oil, energy or tobacco companies. But this harsh criticism on Feb 15th 2006 was aimed at the technology giants Yahoo, Google, Cisco and Microsoft, over their business operations in China. On that day the House Subcommittee on Africa, Global Human Rights and International Operations called the three online giants and the networking hardware vendor on the carpet over their impact on online freedom in China.

One full year passed since that day, but there is still no compelling solution to the problem of doing business worldwide while grappling with questions of different jurisdictions, rooted in values that are fundamentally at odds with each other.

Link to full transcript of the hearing.

cemp

Back in the USA

After one week in Istanbul, arrived in snow-covered Chicago yesterday afternoon, via Munich complements of the always punctual and efficient Lufthansa.

A series of blog posts will cover the differences in basic parts of life in Istanbul that stood out for this blogger, who had last seen the city in April 2004.

cemp

Environmentally friendly spam

This must be the reductio ad absurdum of eco-consciousness. After organic-this, Energy-star that here comes unsolicited email extolling the benefits of biofuels. AutoBlogGreen reports a bizarre incident where one of the bloggers received 2 copies of the same message singing the praises of biodiesel. Quote:

“Biodiesel is a safe alternative fuel. Biodiesel has a higher flash point than regular diesel. It is classified as non-flammable by the NFPA, and is not required to carry a Hazardous Material label when being shipped.”

All true and this is where the standard spam message would urge the reader (“hurry, only for short time!”) to snatch up shares in some dubious enterprise ready to capitalize on the said great technology. Except the mail quoted in its entirety does not name a single company or website. Hopefully spammers have not taken to distributing public service announcements for free.

cemp