Home

bleeter

Recent Entries

Journal Info

Name
bleeter

View

Navigation

Advertisement

Customize

July 13th, 2009

See???

Add to Memories Tell a Friend
16:10 <@Nechckn> bleeter You need a blog
16:10 < bleeter> Nechckn: I got one...

June 19th, 2009

Install time

Add to Memories Tell a Friend
Whoa, I remembered to install Logjam!

January 24th, 2009

More Google hating

Add to Memories Tell a Friend
This URL show me the map of Australia with the location of the Google offices on it.

http://www.google.com.au/support/jobs/bin/static.py?page=about.html&about=locations

The map completely misses my home state, where linux.conf.au was being held this year. I sent a lighthearted email to the guy who did the 'Jobs' talk for Google at the mini-jobs conference asking if there was a job to fix the map. He took in in his stride etc. etc. However, there was another Google staffer who said all the usual disparaging things about Tasmania.

So, Harry - you're a champ. But, that Google guy in a blue shirt - fuck off back to the mainland real soon and never come back. I hope they give you a full cavity search at customs on the way - hell, I might just even try and work out who the fuck you were and ensure this happens. Do not fuck with Tasmanians while you're in the state. Clearly you don't know lesson #1 from your own Google application - It's not what you know, but who you know.

November 29th, 2008

MOAR STUFF QQ

Add to Memories Tell a Friend
Some folks have been asking how I've been getting on with my research and discoveries with regards to a certain major gaming company's security features.

Due to a family illness, I'd ended up rather stressed about a multitude of things, including the research and what I perceived to be a poor response from the company. Anyways, for some reason on Friday morning I woke up and remembered AusCERT, and that one of their employees is a really top chappy who I used to work with when I was employed to blow up casinos and break into banks at the instruction of government regulators. Anyways, passed all my info over to that crowd, and they're going to manage it.

I'll probably end up passing some other less serious issues with said gaming company's security over to the in the coming week as well.

November 26th, 2008

Blizz Authenticator part 3

Add to Memories Tell a Friend
I’ve had a bit more of a play with Blizzard’s attempted fix. It’s still broken in a certain way. I’ve not heard anything back from Blizzard, so I’ll just notify them and invite them to contact me directly. I’d say that security has increased to some degree. It’s a bit late, so haven’t tried evaluating whether the increase is minimal or greater. I’m going to go sleep on it.
It’d appear that the issue that was identified over a month ago with Blizzard’s implementation of the Vasco Digipass Go 6 authenticator system has been rectified in the last 12 or so hours. I’m awaiting further testing, however I’m fairly confident in saying that up until sometime in the past 12 hours, the Blizzard Authenticator offered very little increase in security.

To those people who have had a security issue with your account, and with the Blizzard Authenticator, I can say at this point in time it was not an ‘in game’ attack. Once I have final confirmation from other sources, I will go ‘public’ with the details of what the issue was. Still, if your account *was* compromised since purchasing an Authenticator, I believe you should be within your rights to re-contact Blizzard Accounts so that they may re-evaluate your situation based upon my discovery.

I’d like to thank certain community members for their support while I’ve gone through a very stressful period - you will get credit in my Full Disclosure. Not only has my father almost died (again) this week, I faced the remote possibility that Blizzard and/or Vasco may have decided to litigate and thus I could’ve faced attempted extradition proceedings (remote chance, but possible nonetheless). The total lack of ‘help’ from hacks@ only added to my personal pain and suffering. For that, I give no thanks to Blizzard whatsoever.
(Copy of mail I just sent to Bugtraq)

Notice of intent to fully disclose

I Reference
Title: Blizzard Authenticator implementation does not secure one's World of Warcraft account from keyloggers
URLs:
Blizzard Product
http://www.blizzard.com/store/details.xml?id=1100000182 (Note: This is the US export controlled version of the Authenticator, Blizzard make available non-US controlled versions through other means [I believe by shipping them through the EU] http://www.blizzard.com/store/details.xml?id=1100000222)
Original Manufacturer
http://www.vasco.com/products/product.html?product=70

II Background
Blizzard Entertainment operate the world's most popular MMORPG, World of Warcraft. They have claimed that they have over 11 million subscribers. It is frequently believed that a World of Warcraft account is worth more on the black market that credit card details, as multiple CC details can be fleeced from unsuspecting people when attempting to 'purchase' accounts. To alleviate this issue, Blizzard implemented Vasco Digipass Go 6.

III Description
Blizzard's implementation of the Digipass Go 6 System offers very minimal increased security for a keylogged computer. Only slight modifications to existing keylogging technology would be required to bypass the security methods. The Authenticator system, as implemented by Blizzard, provides only minimal increased security.

Steps to reproduce:
The steps to reproduce the attack will be revealed Soon(TM)*

IV IMPACT
Successful implementation of the attack will render the Digipass Go 6 as sold and implemented by Blizzard Entertainment as next to worthless.

V PRODUCTS AFFECTED
World of Warcraft, World of Warcraft: The Burning Crusade, World of Warcraft: Wrath of the Lich King.

VI REMEDIATION
There are some foreseeable workarounds that might be possible so that Blizzard Entertainment completely nullifies this attack. The attack's discoverer does not have a full working knowledge of Vasco Digipass Go 6, nor how Blizzard have implemented it, so is unsure whether the proposed workarounds would actually be effective.

VII DISCLOSURE TIMELINE (Times are Australian Eastern, apply Summertime if/when appropriate)
(??) Oct 2008 - The attack's discoverer believes he posted to Blizzard WoW US Customer Support Forum, details of post were removed so that only Blizzard staff could see and forward as appropriate (Blizzard staff can read forum post edit/history, permitting sensitive info to be handed around Blizzard internally). Unfortunately, due to thevolume of his posts and the poor search functionality of the WoW forums, confirming this as fact is very difficult. He does have strong recollections of previous discussion of the issue concerned, although not the detail.
24 Oct 2008 - Informal mention of the issue to Blizzard staff member and indication that it should be addressed
25 Nov 2008 - Post on Blizzard Customer Support Forum by a customer that their account was keylogged despite having an Authenticator
25 Nov 2008 - Formal notification to the official Blizzard Hack support team (hacks@blizzard.com) of the discovered attack method

IX Credit
This attack was discovered by Peter Lawler. bleeter@internode.on.net
Peter is a computer gamer who has formerly worked as a systems integration and security engineer for Federal Hotels/Network Gaming (Australia), as well as for Access Gaming Systems (Australia) where worked in a similar role on site at La Française des Jeux, Westlotto, Holland Casino and Austrian Lotteries [customers of Access Gaming Systems (Europe)]. His current interests are in studying virtual economies and the repercussions of laundering virtual/real world monies.

X Acknowledgements: At this point in time, I acknowledge Nicolas Viot for unwittingly providing me with a template for this notice to disclose. Full acknowledgements will come with Full Disclosure.


* Soon: http://www.wowwiki.com/Soon

Developments

Add to Memories Tell a Friend
Some users of the product I was talking about yesterday have come tantalisingly close to the issue I know of. But have yet to reach the same conclusion I have.

Exaile

Add to Memories Tell a Friend
Stupid exaile... no easy way to get the artist and track name out of it on one line...

High Fidelity's by Elvis Costello.

November 25th, 2008

Holy long time no see

Add to Memories Tell a Friend
It's been ages since I posted anything here.

Look like I'll have some 'news' that's worthy of a blog post in the coming week or two. I've ended up in a bit of a moral dilemma, as I stumbled across a security issue in a product and mentioned it in minor ironic amusement passing to some folks in public.

It was only earlier today that I realised the full implications of the problem. I ran it past some folks in the community that it involves, and they are fairly stunned at the issue.

I can't really go the proper 'fair and proper notification and full disclosure later' as my earlier stumble means I believe the info is already 'out there' somewhere.

I've notified those 'concerned', as best as I 'know how' (which is probably very poorly).

What can I say, apart from 'watch this space'. A well known company's implementation of a 3rd party's security system has, in my opinion, been rendered said company's much promoted new security system completely worthless.

September 5th, 2007

Stuff I'm doing

Add to Memories Tell a Friend
I saw a few requests for Chip's maintenance of Planet-IM, so figured I should post something about what I'm doing at the moment. In no particular order

a) Double degree at the local 'clown college' (.au definition)
b) Heading to Brisboring in October to see my brother's band reunion gigue
c) Helping out where/when I can with Norganna's projects, the members of which have to be amongst the coolest Open Source folks I've even had the fortune to stumble across.
d) Hacking in Wine occasionally so I can run the stuff from (c)
e) Still awaiting seanegan's contact with me to help test his Pidgin voice/video stuff.

That's about it, I think.

Cheers,

Me.

April 12th, 2007

Pidgin

Add to Memories Tell a Friend
Woot! Gaim's thrown off the AOL shackles, and is now known as Pidgin. Yippee.

Guess I better post a follow up to my ages old post. Now that libao has gone, and gstreamer is being used instaed *and* the abortive attempt to use (iirc) libspeex has ended, it actually looks promising for stuff *post* 2.0. Sean's said V/V will be a focus then, so I can barely wait to get to that point and start helping out again.

December 30th, 2006

So, here I am now working on new projects, new horizons. I didn't really think the same users would appear here as what I saw in gaim's IRC channel but it appears they did.

Pointless support exchanges are the bane of any developer's life. If one's employed to support programs, there's at least the paycheque to easer the pain of dealing with the seething masses. For us in the open source world, we get the same level of user - just we have no way to ease the pain except for sharing some of the more stupid moments we see.

This exchanged happened recently in the World of Warcraft Auctioneer support IRC channel. Not only did user1 reply to a post not directed at them but they decided to try out the advice for user2 anyway.

(8:45:02 AM) user1: is the wow 2.0 auctioneer out yet?
(8:45:22 AM) user1: been lookin like an idiot for it ^^
(8:45:27 AM) dev1: user1: topic
(8:45:29 AM) user2: still beta i believe user1
(8:45:33 AM) user1: ah ok
(8:45:42 AM) user1: hows the beta workin then?
(8:46:13 AM) user2: ummmmmm it was workin great for me until a few days ago
(8:46:22 AM) user1: ah ok... what happened?
(8:46:31 AM) user2: now it won't load....trying to figure out why right now
(8:46:33 AM) dev1: user2: what happens when you type "/auc"
(8:47:14 AM) user2: no error just won't load
(8:47:19 AM) user1: nothin happens when I typ /auc
(8:47:29 AM) user1: or do you mean ingame?

I suspect user1 typed /auc into their IRC client and expected it would somehow fire up WoW and place them at the Auction House with this mod all installed.

If you're interested in dumb exchanges users have with developers (laugh at knowing someone else's pain!), check out gaim's funniest home convo's file at gaim's funniest home convos This file has been assembled over many years, and features dumb user interaction, as well as the more silly personal moments of the development team.

(no subject)

Add to Memories Tell a Friend
We're still setting up, but Planet-Warcraft.com and Planet Warcraft Blog Hosting are up and running. I'd like to take this opportunity to thank Norgs for giving us the space to bring the blogs of various community members together with news from various sites. One thing that's driven my quite mad is having to jump around 15 websites chasing down news. This is an attempt to 'solve' this problem, and provide the community with greater flexibility than already exists. Here's a list of some of the things we're working on adding soon, in no particular order and in no way is this a 'complete' list:
  • automatically adding the blogs from blog.planet-warcraft.com into the subscription feeds which appear here.*
  • XPlanet display of where our users are (for an example of this in action on another site, see GnomeWorldWide).
Here's some of our long-term goals
  • Separate 'news', 'players' and 'developers' areas for easier browsing once we get real busy.
  • Planet-warcraft subdomains for larger projects (eg, the auctioneer crew would have their own auctioneer.planet-warcraft.com)
  • Xplanet display of where our users would call home in Azeroth
  • Integration to developers' systems such as trac.
  • Blizz's Blue posts (stickies) direct from Blizz in RSS feeds without needing a third party site.
  • Feeds from more sites (eg WoWWiki.com's latest updates).
Whilst we work on these things, we look forward to providing Warcraft users with the most comprehensive Warcraft news service available. ---- edit: *this is now happening. Didn't warrant an entire new blog entry.

December 28th, 2006

Notdead

Add to Memories Tell a Friend
Reports of my demise are greatly incorrect.

I got sidetracked into a certain game, then got bored with the game itself - but interested in the programming languages it uses for it's user interface.

As such, I'm barely active with my IM contacts anymore, and those who I am are also playing the game - and we have ingame chat and Vent/Teamspeak. So I have no crushing need for any voice/video in Gaim anymore. Hence... well, yeah. I ain't done stuff. Or, form a different point of view, I've done other stuff instead.

More news probably next year. Or not.

January 5th, 2006

I'm still playing with doxygen for gaim, although my final aim is to gtkdoc-ize the gaim docs. Either system is rather dependant on having up to date content and the flags I'm playing with in doxy not only give a nicer front end, with a search capability if you throw it on your php enabled webserver, but spits out all the lovely warnings and errors for missing documentation. This is the current focus of my gaim efforts.

Lots of people have been asking about -vv for gaim2beta1, and although there's some code in there, it doesn't really do much, well, anything. I had a brief talk to sean yesterday, and to the farsight guys. Sean seems happy with the idea of speex in gstreamer, and says he'd also need mulaw in gstreamer, but said words to the effect that gst 0.10 seems to be the way to go. Farsight have updated their API, so it won't be quite as 'simple' hackforward as previous attempts, however it's still doable. So yeah, I'm going to start hacking this sometime real soon, right after I've worked out how the heck to get the aforementioned nice docs happening.

In the meantime, right index fingers and Parmesan cheese grating are a dangerous mix, although the results may be tasty it slows down the touch typing.

November 18th, 2005

Copy protected CD's

Add to Memories Tell a Friend
The recent 'furore' over Sony's XCP is further demonstration of the media conglomerates stupid management at work. If I had shares, I'd be demanding people take a jump from Sony HQ.

Yesterday I spent some money in arguably the best CD store in the country (Music Without Frontiers, 147 Collins St Hobart 7000, +61 (03) 6231 5411), and picked up some Jaco Pastorius, some Einsturzende Neubauten and the soundtrack to 24 Hour Party People.

The Pastorius was labelled as Compact Disc CD Audio. Played without problems on my computer. The Neubauten blatantly says 'will not play on computers', yet it played without a problem. The 24 Hour Party People, though. Jumping all over the place like a frog in a blender. Of course, this disc does not claim to be CD-A whatsoever, but neither does it say it may be incompatible with my playback system.

So now I'm forced to three options by Warner Music Group. Anyway, I can either return the disc and give up in disgust and take artist's rightful income away from them. Return the disc and download the tracks off the 'net. Or rip out the old-yet-trust second-generation SCSI 4x CDROM drive I have hear. The thing's probably over ten years old now, however it's yet to face a CD 'protection' scheme it can't play. The thing is, I don't normally run with this drive operating, so I have little option but to rip the disc to a different media, or just straight out copy it.

I find it hard to believe that every band on this album agreed to limit the playability of their art. I think it's a nice classic demonstration of how far music companies still have to go before they understand the revolution that occurred almost 15 years ago when the first CD burners turned up on the market.

To be honest, did they ever really come to grips with the compact cassette?

(Yeah, this has all been said before by others... it's just taken me several years to get around to bitching about it myself)

November 12th, 2005

Gaim-vv redux (I hate me)

Add to Memories Tell a Friend
Thanks to some wonderful feedback from the community and some conciliatory tones from a couple of gaim developers, I've reached the conclusion I'm merely hurting the community more by refusing to continue work on voice and video for gaim. This does not mean I believe it's the best platform for delivering third party IM's voice/video, but it's what we've got now, despite other clients promising steps.

So, out of respect for those who've asked me to fork, asked me not to stop working on it, etc. etc., I'm more than happy to swallow my pride, call myself a stupid idiot (although dolt is my word of the week at the moment, thanks to Ms Grossman and Senor Cervantes), and just shut the fuck up and get back to doing what I enjoy, which is aiming to bring voice and video communications to the masses without the noose of a corporate around your necks.
Nice to see gaim's been updated for FC3 and FC4. Thankfully, it'll be the last of FC users moaning at me about rate limiting errors.

Apologies to Luke

Add to Memories Tell a Friend
OK, so I've taken the time to re-read the IM exchange I had with Luke on the fateful night I called him a liar. It is clear to me now, that he did not lie to me, and that I mis-understood his position.


(11:05:50) LSchiere2: because I don't care about -vv. I don't want it to work, I don't care when it does. But I'm not going to support utter junk if there's a better body of code out there
(11:06:23) bleeter: oh, gee
(11:06:25) LSchiere2: yes, this is dictatorship at work. I'm extending you an offer to reduce _my_ headaches as support. If you can do better than sean has, then I'll break sean's work
(11:06:27) bleeter: tghanks for your vote of support
(11:06:36) bleeter: you don't want me to work on stuff that niterests me
(11:06:53) bleeter: you want me to fix up bad code written by someone for a professional manner? get real
(11:07:42) LSchiere2: I always let people pick their projects. you want to work on -vv? great. do so. you don't? that's great also. I have a HUGE list of other areas that need work. pick one. or don't, find a project that suits you better. again, I'd be sorry to loose a programmer, but the end is that people work best about stuff they care about
(11:07:44) bleeter: you're just a big a liar to me as sean was/is

What is probably a more accurate description would be I believed him at the time to be hypocritical, "I don't want it to work" ... "If (it is worked on...) great!". Luke, I sincerely and humbly apologise to you for any hurt these words may have caused you.

Advertisement

Customize
Powered by LiveJournal.com