Monday, April 21, 2008

"Faxing for security"

In this weeks episode, the alien tries to get his credit report from Transunion. (For the non US natives out there: You don't exist without a credit report. That high-tech visa may be good enough for DHS, but not for your landlord!)

I went through the entire online sign up process (did I mention that you need to pay to give them information on yourself, so that they can sell that information to others?). As expected, the online system freaked out and insisted that I call customer support to "confirm my identity". So I called the give number and got on the phone with "Michael", (who's accent I would place somewhere in the Southwest... of Bangelore!) who, in a calm and friendly voice, explained what I needed to do.

It went something like this:

- Please send a copy of your drivers license and proof of address to this fax number...
- I don't have a US drivers license. Would a passport work?
- Eh... Okay... We can accept any government issued ID.
- Any government? Or "US government"?
- Eh....
- Never mind. What's this about proof of address?
- We need a "recent utility bill" to prove your address.
- Ok... Right. I have all that online, available right now. Can I just email it to you?
- No! For your security, you need to fax it to our customer support fax!
- (Sigh) All right then....


Let me re-state some of the background issues here:

  • Companies trust a "utility provider" as legal proof of residence. That includes the phone company, the water, sewage, cable, .... etc... These are the same guys that can't even get my bills right!
  • Most of these providers allow you to sign up online, without any validation.
  • Most of these can be paid and managed completely online, without ever seeing any paper. Which means... there is no address verification!
  • All of them allow you to view and print your bill online, either from a web page or a PDF. This means that if you can hit the "Edit page" button before printing, you can make up your own address!
  • For "my security", I need to login, download a PDF, print it, then stick it into the fax. Not only does this process eat a severe chunk of the quality of the documents (making any supposed verification even harder), it also means that I now have a paper copy of the (supposedly sensitive) documents, that I need to get rid of securely.

Now I know why Skype has the (banghead) emoticon.

Thursday, April 3, 2008

I'm really hot on Myspace!

Just look at my "friend request" page....



If I am being stalked by hordes of sexy looking girls, I must be doing something right, right? Right? And they happen to all have their own webcam service!

But I wonder why they don't ever want to give me their phone number? :(


</SARCASM>

It seems like profile spammers are getting more and more desperate every day. Other food for thought: On myspace, I receive dozens of spam requests every week. On facebook, I have received... zero! Is the facebook system so much more resilient to spam? Or is their demographic much less gullible?

Monday, March 31, 2008

ObiJan Bio Page

I haven't risen (steeped) to the vanity level of blasting people with "About Me" pages (yet), but the geek in me wanted to play with the (now extinct) Google Social API. The OCD-based organizer inside me agreed that it would be neat to have a central page to list all my various "profiles". Even the slob in me liked that, because he keeps forgetting all those links themselves. The other voices in my head were talking about things involving cheesewire and an electric bushcutter, but I kept them sedated.

So here goes...
"About me" on various sites:


  • Google Profile

  • Twitter

  • Facebook

  • LinkedIn : In case somebody has a great job offer :)

  • Plaxo : Part address book organizer, would-be social network

  • Flickr : Not really my favorite photo sharing site
You may find my main "real" experimental site at ObiJan.com

2014 Update: Removed all the extinct links. 
2022 Update: Killed all more extinct links. 

Monday, February 25, 2008

Ponderings on "multi factor authentication" sillyness...

It seems like a disturbing trend:
Banks adding "more security" by adding extra "security questions"...

In short, the alleged idea is make your account more secure then just using your password (which is normally only known by you) by asking "personal trivia questions" related to high school mascots, car brands, maiden names,...

Whats wrong with that?


  • It's insecure by design. Most of this information is public! A potential attacker can guess or google this information. Different sites are also using the same questions.

  • It's extremely error-prone. What was that pet's name again?

  • It adds no extra phishing protection. A fake site can just as easily ask these questions together with your password.

  • Better solutions such as openid are publicly available, and allow the user to choose the level of security they prefer. Which can range from basic user-name password logins, over https client certificates to secure one-time key token-devices.


This (fairly cynical) post explains what I have been trying to get across way better that I did.

What to do when your bank forces you into this "Mickey mouse" scheme?
- Come up with a secondary password (preferable 2 "words")
- Fill it in as the "answer" to each question

This way, you are at least not decreasing the level of security provided.

Sunday, December 30, 2007

iPhone stress test

Picture taken at 3800M, -15C.

Slight discoloring, but nothing major.

I can't believe the things I do just to give accurate reviews!