47 stories
·
1 follower

Incapables !

1 Share

Les fuites de données personnelles vont continuer, encore et encore...

Depuis 1997, l'auteur de ces lignes pointe l'inaction des entreprises et des administrations en matière de protection des données personnelles. D'une part la sécurité informatique est délaissée, d'autre part les données sont monétisées. Ces deux points ne sont pas décorrélés. Résultat, les utilisateurs sont plongés dans un cauchemar numérique sans même le savoir, avant même que leurs données ne fuitent.

Avant, ne circulaient que les données que vous vouliez envoyer. Maintenant, on vous vole les vôtres, les plus personnelles. - CC

Lorsque Internet est devenu accessible au grand public, les machines avaient un rôle : faire circuler l'information. Les tuyaux étaient la voie (on les appelait « les autoroutes de l'information »). Les machines faisaient ce qu'on leur demandait. Amener la donnée d'un point A à un point B. Et puis ça s'est gâté.

Les entreprises, très frileuses au début, ont débarqué en masse. Elles ont dépensé ses millions pour des sites Web faits à la va-vite. Tellement à la va-vite que leurs serveurs étaient de véritables passoires. Les données confidentielles des entreprises fuitaient, les données personnelles de leurs clients s'étalaient sur le Net.

L'auteur de ces lignes s'était d'ailleurs fait une spécialité de raconter dans des articles les mésaventures des boites ou des administrations de tous pays qui affichaient côté marketing un message triomphant sur leurs présence sur Internet et de l'autre, les données personnelles de leurs clients ou leurs plans stratégiques les plus confidentiels. Copies d'écran à l'appui, pour le #LULZ...

Chaque année, l'idée de pouvoir trouver des serveurs aussi importants mal configurés semblait à première vue un challenge. La source d'articles allait forcément se tarir au fur et à mesure que ces technologies devenaient mieux connues, que la sécurité informatique se faisait plus présente, que les bugs étaient révélés avec l'apparition du mouvement du « full disclosure » et de...

Read the whole story
juliju
2 hours ago
reply
Share this story
Delete

Info.gouv.fr : attention vos données fuitent, étonnant, non ? (Non)

1 Share

Même si elles ne sont pas piratées vos données personnelles partent vers des boites privées

Nous vous le racontions dans un récent édito, Google en sait plus sur vous que votre moitié ou que vos parents. Même punition avec la plupart des plateformes et les data brokers. Ce qui est particulièrement énervant, c’est que même les sites publics « monétisent » vos visites. Exemple avec le site du gouvernement info.gouv.fr

Nos données personnelles fuyant dans l'immensité du cyberespac, circa 2025 (Allégorie)

Vous pensiez peut-être que lors d’une visite sur le site du gouvernement français, les données personnelles qui accompagnent votre « surf » ne s’éparpillaient pas aux quatre coins de la planète et plus précisément sur des serveurs et dans des lacs de données d’entreprises privées qui les utiliseront peut-être pour gagner de l’argent en les revendant ou qui risquent d'être piratés un jour ? Erreur.

Reprenons. Nous vous racontions dans un édito récent que lorsque vous chargez une page sur le Web, un certain nombre d’informations sont envoyées au serveur que vous consultez.

Par exemple, votre adresse IP qui est généralement géolocalisable, la version exacte de votre système d’exploitation, celle de votre navigateur, l’adresse de la page qui vous a amené là si vous avez cliqué sur un lien, la taille de votre écran (ce qui donne une indication sur votre device) et sa résolution (une information sur vos moyens financiers).

Si le site visité garde ces informations dans ses logs sans rien en faire à part de la mesure d’audience avec un logiciel dédié et hébergé par ledit site, pourquoi pas (c'est ce que nous faisons chez Reflets, et encore, vous pouvez désactiver cela dans votre espace personnel).

Mais que se passe-t-il s’il délègue la mesure d’audience à Google comme 80% des sites. Ou à un autre opérateur privé ? Que se passe-t-il si le site construit ses pages à la volée (lorsque vous la chargez) en utilisant des composants fournis par des entreprises tierces ?

Par...

Read the whole story
juliju
2 hours ago
reply
Share this story
Delete

SPST page 15 et 16

1 Comment


Read the whole story
juliju
72 days ago
reply
Ça change des araignées
Share this story
Delete

A History Lesson

1 Comment and 2 Shares

Read the whole story
juliju
396 days ago
reply
Share this story
Delete
1 public comment
trevorjackson
396 days ago
reply
this is exactly the kind of thing my grandma used to forward me via email
Start, Not Having Passed Go
HandEFood
396 days ago
This is the exception that proves the rule that "Americans will measure by anything other than the metric system."

Classic WTF: The Core Launcher

2 Shares
As our vacation continues, we might want to maybe play some video games. What could possibly go wrong? Original --Remy

“You R haccking files on my computer~!!!” Charles Carmichael read in a newly-submitted support ticket, “this is illigle and I will sue your whoal compiny. But first I will tell every1 nevar to buy youre stupid game agin.”

The bizarre spelling and vague threats were par for the course. After all, when you market and sell a game to the general public, you can expect a certain percentage of bizarre and vague customer communications. When that game is a popular MMPORG (no, not that one), that percentage tends to hover around the majority.

It took a few days to see the pattern, but the string of emails started to make sense. “Uh, when did your game become spyware?” said one email. “Are you doing this just to force us to play more often?” another customer asked. “I know you have a lot of AI and whatnot, so I think it leaked out. Because now my whole computer wants me to play all the time… like my dog bringing me his chew toy.”

As it turned out, the problem started happening a few days after an update to the core launcher was published. The core launcher was one of those terrifically handy executables that could download all of the assets for any single game that was published, scan them for completeness, replace bad or missing files, and then launch the game itself after the user signed in. It’s a must-have for any modern multiplayer online game.

This core launcher could also patch itself. Updates to this executable were fairly rare, but had to be made whenever a new title launched, as was recently the case. Obviously, a large battery of automated and manual testing is done to ensure that there are no problems after publishing, yet something seemed to have slipped through the cracks… at least for some customers.

After a whole lot of back and forth with customers, Chris was able to compile dozens of detailed process lists, startup program launches, newly installed applications, and firewall usage rules. As he pored over the collected information, one program was always there. It was Interfersoft’s fairly popular anti-virus suite.

It took a solid two days of research, but Chris was finally able to uncover the new “feature” in Interfersoft’s Advanced Firewall Protector that was causing the problems. Like many similar anti-virus suites, when a program wanted to use network services, Interfersoft would pop-up a dialog confirming that the program’s operation was authorized. Behind the scenes, if the user allowed the program, Interfersoft would make a hash of that executable file, and would allow its communications to pass through the firewall every time thereafter.

Users who had this antivirus solution installed had, at one time, allowed the launcher through their firewall. The first time they connected to the game server after the launcher patch was released, their executable would download its patch, apply it to itself, and restart itself. But then of course, the executable hash didn’t match any more, and the program was no longer able to go through the firewall.

Rather than asking users if they wanted to allow the program to connect to the internet, in the new version of Interfersoft’s suite, the anti-virus system would rename the executable and move it. The logic being that, if it was changed after connecting to the internet, it was probably malware.

But what did they name the file? Program.exe. Unless that was already taken, then they would name it Progra~1.exe or Progra~2.exe and so forth. And where did they place this file? Well, in the root directory of C of course!

This naming convention, as it turned out, was a bad idea. Back in the very old, Windows 3 days, Windows did not support long file names. It wasn’t until Windows NT 3.5.1 (and then Windows 95 later) that long file names were supported. Prior to this, there were a lot of limitations on what characters could be part of a filename or directory, one of those being a space.

In fact, any space in a shell command execution was seen to be an argument. This made sense at the time so you could issue a command like this:

C:\DOOM\doom.exe -episode 3

That, of course, would start Doom at episode 3. However, when Microsoft switched to Long File Names, it still had to support this type of invocation. So, the way the windows cmd.exe shell works is simple. You pass it a string like this:

C:\Program Files\id Software\Doom\Doom.exe -nomusic

And it will try to execute “C:\Program” as a file, passing it “Files\id Software\Doom\Doom.exe -nomusic” as argument to that executable. Of course, this program doesn’t exist, so it will then try to execute “C:\Program Files\id”, passing it “Software\Doom\Doom.exe -nomusic” as argument. If this doesn’t exist, it will try to execute “C:\Program Files\id Software\Doom\Doom.exe” passing in “-nomusic” as an argument. It would continue this way until a program existed and started, or until the path was depleted and no program was to be found.

And on top of all this, desktop shortcuts on Windows are mostly just invocations of the shell, with the actual location of the executable you want to start (the path) stored in text inside the shortcut. When you click it, it reads this path, and passes it to the shell to start up the program. And this is why Intersoft’s process of moving files to the root directory was the worst decision they could have made.

Most of the programs installed in Windows at this time were installed to the “Program Files” directory by default. This was a folder in the root (C:\) directory. So when you wanted to launch, for instance, Microsoft Word, the shortcut on your Desktop pointed to “C:\Program Files\Microsoft\Office\Word.exe” or Firefox, which was in “C:\Program Files\Mozilla\Firefox\”. But thanks to Program.exe in the root directory, you ended up doing this:

C:\Program.exe “Files\Microsoft\Office\Word.exe”

and

C:\Program.exe “Files\Mozilla\Firefox\”

So, when users were trying to launch their application – applications which resided in the Program Files directory on their C drive – they were getting the launcher instead.

Chris explained all of this in great detail to Interfersoft, all the while explaining to customers how to fix the problem with the firewall. It helped some, but several hundred customers ended up closing their accounts a direct result of the “hacking”.

A few weeks later, Interfersoft started responding to the issues with their customers. Fortunately (for them), they decided to not use their own auto-update process to deliver a new version of the firewall.

[Advertisement] Plan Your .NET 9 Migration with Confidence
Your journey to .NET 9 is more than just one decision.Avoid migration migraines with the advice in this free guide. Download Free Guide Now!
Read the whole story
juliju
438 days ago
reply
Share this story
Delete

One pot Chipolatas

1 Share
Une recette facile et rapide pour réutiliser des restes de chipolatas déjà grillées! #AntiGaspi
Read the whole story
juliju
471 days ago
reply
Share this story
Delete
Next Page of Stories