Security

Virus hidden as Facebook Application?

A friend complained on facebook today about an application called PicDoodle that she had installed.

It was supposed to give her a way of drawing fancy things on images and share that fun with her friends.

Instead, she got one of her images with a roughly scrawled heart on the corner and it automatically has been taking names from her friends list and "tagging" the image with their names.

another big lie: obscurity == security

I was doing some research today, keeping up on new developments in HIPAA compliant software. (HIPAA is U.S. law which regulates the portability, privacy and security of healthcare information)

On the site of a software company that is selling a "secure email system" that they claim is HIPAA compliant, I found the following completely ignorant statement about the relationship between security and free/open source software

"Why does SafetySend use Proprietary Code and Technology?
Because any code or technology that can be purchased is vulnerable.

blocking the google hive mind

In an online discussion today, Matt pointed out to me that google analytics is less than useful because it is so easy for people to block the google javascript file via the firefox adblock add on.

Yet another reason to tell clients and friends to avoid getting hooked on google analytics.

So, everyone follow along:

Step one: get firefox ( http://getfirefox.com )
Step two: get the ad block plus addon ( https://addons.mozilla.org/en-US/firefox/addon/1865 )
Step three: open the ad block plus preferences
Step four: click "add filter" and put http://www.google-analytics.com/* in the field; click save

Done, you have no protected yourself (a bit) against the intrusion of google in your life.

A small rant about Google Analytics and Privacy Statements

This week I once again had the debate with a site's legal team about how using google analytics violates the privacy of a site's users.

This is not a huge issue for many sites, but if your site has a privacy statement, you are legally bound to adhere to it -- and many privacy statements are explicitly violated by the use of google analytics.