Tuesday, October 25, 2011

Time to End the Wikleaks Banking Blockade


This tweet just in from Wikileaks:
Support WikiLeaks - you can now donate with an SMS | http://shop.wikileaks.org/donate#dmobile (check it works where you live using dropdown menu)
It works fine in South Africa, and I donated R20 for now. Will donate more soon. Watch the video and fight back at Visa, MasterCard, PayPal and the entire wunch of bankers trying to blockade Wikileaks.

What Does it Cost to Change the World? from WikiLeaks

See: Broke Wikileaks Halts Publication to Raise Money at Gizmodo.

Monday, October 24, 2011

No News is Bad News for AlJazeera English


AlJazeera English is my primary source of TV news. Sometimes I can even watch it online, depending on the availability of bandwidth. This morning I noticed that something was going wrong: there was no news coming out of their Doha studio. Was AJE under attack? Was the staff on strike or being censored? All kinds of scenarios went through my mind.
After all, the station is owned by the state of Qatar, and they recently changed senior management, so anything was possible. What strikes me as most odd is that they, as a news outlet, did not see fit to tell their audience what was going on. This is bad news, especially for a company that has numerous twitter accounts and Facebook pages. It's bad for credibility.
On the one hand the fact that their primary studio isn't working may not count as "news", but there wasn't even an explanation on their web site, and tweets to their twitter news account went unanswered. A tweet to their @AJStream account, supposedly their flagship social media program, wasn't addressed directly. Weird.
I eventually got a reply from Alan Fisher, one of their best journalists: "significant tech issues I believe". Why couldn't the station itself say that? Why is it afraid of admitting it is having a technical hitch? It's not like you aren't going to notice if you switch on the TV looking for a 30 minute news program and you get a documentary instead. Instead of getting my "morning news fix" at 9am (News Live Doha), I eventually got it at 3pm (Newshour from London) instead. That's when I got the clue that the Doha centre was having difficulties.
Note to AJE: Just put a note on your program schedule when you cancel programs. Viewers will appreciate your honesty and trust you more. Hiding stuff doesn't build trust or credibility.

Friday, October 14, 2011

ESET's Not-So-Smart Security Failure - Fixed


Resolved: I remain a NOD32 fan, particularly after the amazing response from Shaun Norris and his team. They have fixed the problem locally, and making sure the ESET engineers improve their download process in future releases.

Original Post 10/14/11: I have been a NOD32 fan for a long time, but recently I have been questioning my loyalty, particularly in the light of their very dodgy virus definition update policies. It seems they are perfectly happy to allow a PC to run with definition files that are 448 days old. Or 105 days. Or whatever. What kind of security is that!?
Take a look at the screen shot at the top of the page (click on the image) to see how the software is lying to me. I installed the software two weeks ago on this Windows 7 32 bit PC, and at the time the virus definitions were updated backwards from version 6364 (20110809) to 5307 (20100723) and then later to 6516 (20111004). OK, so it had a glitch. It came right. Wrong!
This morning I returned to the machine, after leaving it running by itself for 10 days. The virus definitions are back to 5307. No amount of cajoling can persuade the machine to download the correct version and not mislead me:

Other versions of the software have experienced similar problems. This PC was using version 4.2.71.2 and it had an issue with the definitions, so I removed the software and installed version 50.93,0. The same thing happened on a brand new Windows 7 machine I was setting up from scratch. Other PCs running Windows 98 and version 2.7 are reverting back to July 2011.
So my question is this: how can the software allow the definitions to roll backwards? How can the servers still have definition files that are 448 days old? Are they insane? They are supposed to be a security company. Yet they issue software with bugs in it, and have a policy that doesn't remove old virus definitions, giving careless users a false sense of security. That's worse than no security at all.
ESET CEO Richard Marko is still blissfully unaware of this problem

Update Mon 17th Oct: I have been assigned a bug report number #TICKET 57298
Update Tues 18th Oct: ESET requested the configuration file and SysInspector log that I sent on Friday 14th. I am starting to get annoyed as well as alarmed. In the meantime the definition files are now over 450 days old! And they want me to run WireShark to capture all the packets. WTF?!
Update Wed 19 Oct: Posted an update to the Wilders Security Forum.
Update Thu 20 Oct: Definitions are now 454 days old, i.e. 64 weeks. After making enquiries this morning I discover the ESET engineers are waiting for a log that I have already sent them. I sent the following reply:
Yes, I am on M-Web but the problem also occurs when using ISDSL which is what most of the [customer] connections use.
Yes, I sent you the event log. TWICE. Here it is: [I have removed duplicates]

14/10/2011 03:24:54 PM ESET Kernel The program modules have been updated.
14/10/2011 03:24:52 PM Update module Updater: retval = 0x0000, failures: 0 NT AUTHORITY\SYSTEM
14/10/2011 02:59:19 PM Update module Updater: Switch DEVEL modules retval = 0x00005007 [NOT NEED] NT AUTHORITY\SYSTEM
14/10/2011 01:43:30 PM ESET Kernel The program modules have been updated.
14/10/2011 01:43:28 PM Update module Updater: retval = 0x0000, failures: 0 NT AUTHORITY\SYSTEM
14/10/2011 01:43:23 PM Update module Updater: Switch DEVEL modules retval = 0x00005007 [NOT NEED] NT AUTHORITY\SYSTEM
14/10/2011 01:42:56 PM ESET Kernel The program modules have been updated.
14/10/2011 10:56:12 AM ESET Kernel The program modules have been updated.
11/10/2011 06:53:02 PM Update module An error occurred while downloading update files. NT AUTHORITY\SYSTEM
11/10/2011 04:53:00 PM Update module An error occurred while downloading update files. NT AUTHORITY\SYSTEM
05/10/2011 08:51:06 PM Update module An error occurred while downloading update files. NT AUTHORITY\SYSTEM
05/10/2011 03:46:12 PM ESET Kernel Virus signature database successfully updated to version 6519 (20111005).
05/10/2011 11:46:10 AM ESET Kernel Virus signature database successfully updated to version 6518 (20111005).
04/10/2011 09:46:01 PM ESET Kernel Virus signature database successfully updated to version 6517 (20111004).
04/10/2011 06:06:00 PM ESET Kernel Virus signature database successfully updated to version 6516 (20111004).
04/10/2011 06:05:57 PM Update module Updater: retval = 0x0000, failures: 1 NT AUTHORITY\SYSTEM
04/10/2011 04:46:44 PM ESET Kernel The program modules have been updated.
04/10/2011 12:49:52 PM ESET Kernel The program modules have been updated.

This is clearly an ESET issue because it is ESET software doing the download, and ESET software that is lying to me about the result, and ESET software that is allowing is virus definition files to go backwards.

I understand that transparent proxies may be involved, but then please explain why two adjacent computers on the same connection can have different results? One works fine and the other doesn’t update.

I really think that ESET is not taking this matter seriously. If your engineers have any further requests or questions, please ask them to contact me directly.
Update 2: Thu 20 Oct 2011: I got a call from Shaun Norris at ESET South Africa, who assured me that they are not ignoring the problem, and have requested further info from me. This is most reassuring. In the meantime I think I have figured out how things are going wrong: their update mechanism is broken. It is vulnerable to faulty proxy servers (such as those used by M-Web) and doesn't use https. It also has no check to see if the version it is updating is older than the existing version. WTF!?
Update: Fri 21 Oct 2011: Shaun Norris set up an alternate proxy for me to try, and also contacted M-Web to get them not to cache the ESET virus definitions. Last night I tried a new installation, which worked flawlessly. I'm waiting to be able to connect to the "afflicted" PC (the office opens on Monday) to see whether these changes will help.
Update: Monday 24 Oct 2011: The virus definitions have updated to the correct version, and appear to be stable. I have sent the logs through to Shaun Norris. All is well for now, and hopefully the ESET Engineers will fix this bug before it endangers other customers.
Update: Tuesday 5 June 2012: Version 5.2.9.1 was just released. It addresses some of these issues, according to the release notes.

Thursday, September 15, 2011

Beware the "Windows Service Centre" phone call scam

Why is it that crooks are so ingenious? This is a social engineering scam, where a person calls you and tells you that there is something wrong with your computer, and offers to fix it. They then convince you with a whole load of misleading technical information, and even get you to run remote control software like support.me or ammyy.com so they can connect to your computer to "fix" the problem.
Do not allow anyone to control your computer unless you know exactly who they are and what they are about to do. Do not type in commands into your PC unless you fully know and trust the person issuing the commands. Not only will you save yourself a lot of hassle, and probably preserve your data, but you will not be conned into parting with your money. (You think they are doing it for free?)
Fact: Microsoft is not "monitoring" your computer, and certainly does not randomly call users if they are experiencing problems. If you agree to send error logs to Microsoft, these are collected for statistical reasons, and cannot be used to identify an individual user or machine. They would be in violation of a ton of privacy laws if they did otherwise.
Question: why don't the remote control companies like support.me and ammyy.com have big warning signs on their web pages:
Warning: do not install this software if requested by unknown call centre operators. Only allow remote control from people you know and trust.
This would protect many innocent and gullible users and protect the brand of the software. (Update: ammyy.com has done so.)
Update: Ammyy.com has posted a warning on their site. Well done to them!

Monday, September 05, 2011

Who says Hollywood never has an original movie trailer?

Thanks to the Listening Post for this one, and Jerm for finding it.
Also, coming soon to this blog: the true story of a building contractor and the customer who finally had enough. I have all the relevant court documents and will post them in WikiLeaks style, but with names redacted to protect the guilty from themselves.

Thursday, September 01, 2011

I just screwed up my blog!

I was fiddling around with some new blog settings and I totally wiped out all my carefully constructed blog settings.
Sorry folks! It's going to take a while to get it all back. Some of the items will take some time to figure out too. Please bear with me.
Update Friday 2 Sept: Not everything is fixed, but at least the site is usable again. I guess it was ready for a redesign, but not like that! I really must stop fiddling and get back to work.

Wednesday, August 31, 2011

CNN's WikiWars is shoddy journalism


I used to think CNN was pretty good at news coverage. Unfortunately now it is just a broadcaster, rather than a news organisation. It hasn't stooped quite as low as Fox News, but it's definitely heading in that direction.
CNN Presents is supposed to be one of their premier documentary shows, where they show "serious" documentaries. This piece falls far short, with inaccuracies and misleading information galore. What's worse is that it is obviously pro-Military and pro-America and borders on being a hatchet job on Julian Assange. The entire show playlist is available here, and the full transcript is available on the CNN web site.






The sad thing about this "documentary" is that the parts it leaves out are quite serious. And the whole "Collateral Murder" segment tries to justify the gunning down of civilians in a civilian neighbourhood by claiming that it was a "combat situation".
The video shows yet another US Military f*** up: they do it all the time. Of course the "general" and the "marine" won't admit that on TV: I think they have lost the plot. Here is another report, this time by AlJazeera English:

Compare the poor quality of the CNN program with this one, which is about the same length but contains far more detail and useful insights:



If you want to know more about Wikileaks, Iraq and Afghanistan, read "Obama's Wars" by Bob Woodward; "WikiLeaks: Inside Julian Assange’s War on Secrecy" by David Leigh et al; "The Longest War: America and Al-Qaeda Since 9/11" by Peter Bergen; and "Bradley Manning - Truth and Consequences" by Greg Mitchell. Only the last book is not available in audiobook format.




Update: Unfortunately WikiLeaks used a previously disclosed password when they released their "insurance" file. So now anyone can read all those cables in unredacted form. That is monumentally stupid, and was obviously a serious security error. Assange cannot blame it on the Guardian because the data file was released to the public by WikiLeaks, not the Guardian. Relying on journalists to understand computer security or keep a secret is never a clever move.
Update 2 Sept: WikiLeaks has now posted all the unredacted cables. This is an act of monumental stupidity, endangering the lives of activists around the world, not to mention making the case against Bradley Manning much worse. I think its a desperate act, but it is totally irresponsible.

SARS is making me sick

Take the Eish out of Tax{eish}ion
I woke up suddenly at 2.10am feeling sick, and I've spent the last 2 hours or so on the toilet, sharing my dinner with the plumbing system. Yes, it could be a bad pie, but I doubt it. It's just nerves, brought on by the glorious monstrosity bureaucracy called the South African Revenue Service.
I'm told with great earnestness by friends that one should never criticise SARS in public, or complain to the media about them. They could get really nasty and make my life a misery with tax audits and stuff. But no one can explain to me what to do about the trifling amount of R246,231.46 that they claim I owe them.
To put that into perspective, it's 118% of my taxable income for 2011, or 55% of my gross annual turnover. R113,344.31 of this amount is interest, and it is growing by R1,168.39 per month. At one stage the interest rate of 15% meant the amount grew at R2,316.87 per month. Any way you look at it, it's a daunting amount of money. My body reacts to this stress by making me sick. It's kept me awake for the last 2 hours.
The sad thing about this whole deal is that it should have been sorted out in 2008 when I was granted amnesty by the "Small Business Tax Amnesty" legislation. This was supposed to write off all the taxes payable for the 2003-2005 tax years. However they failed to inform me of the decision, and then on top of that decided that these tax years were not covered by the amnesty because the tax forms had not been filled in, or some such nonsense. Ever since then I have been getting "Final Demands" (I've had several) from the tax collection section of SARS. Each time I get one it makes me sick for a few days.
Yesterday I went to see them because (surprise, surprise) they had lost an objection I filed in May 2010 and now that they were looking at the copy I resubmitted they decided that I should have signed it and not the accountants that did it on my behalf. This little delay has cost me R16,000 in interest, not to mention time wasted with the accountants, plus the accountants' fees. In order to pay this amount I have to earn R22,900 so that I can pay 30% tax on that to be left with R16,030 in order to pay this tax. And I'm still no closer to paying off the capital that generated the interest in the first place. I feel like a hamster in a wheel.

South African Revenue Service