Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, January 20, 2008

...and while we are on the topics of identity...

If you don't feel like watching the your criminal-TV-show-of-choice, go read a breathtaking thriller, that happens in RL.

Saturday, December 15, 2007

Miscreants Live! tonight on SL

Ok, after reading this post, I figure I would write something up about Celine Ballinger and those other criminals that follow their paths.

It's amusing how fast-paced SL is. It took the RL more than 2005 years to get to the file encryption extortion worms, and it took SL - how much ? 5 years ? To get to the human-powered land grabbing extortion worms with a slightly cynical flavour. Criminals you can talk to.

All this junk about "Not a lot of people give land back where they can make easy $450"... There are even easier ways to make even bigger money. Put a web server, make it look like a bank website, let people stumble on it and ask for their credit card information. This easy avenue of getting money is called "Phishing". Luckily, at least sometimes those creative individuals go to jail. Although I think they should be put onto the life-long community work of fixing the PCs damaged by the malware. And no cheating - the reinstalls are not allowed!

The usability drawbacks of the SL interface should not be an excuse to "teach" the others in such an ugly way.

Of course, there are a few very easy ways to fix this:

1) if the land is set on sale to anyone at significantly below the market value, to put a captcha.

2) by default, ask if the land is being sold to someone specific - and make the targeted sale the default modus operandi.


Indeed, technically (disclaimer: IANAL), this might be "within the bounds". But if you went into a shop owned by a mom and pop, and noticed that a very expensive thing had its pricing sticker mis-placed such that it reads 1/10th of the price, and the college kid just went ahead and charged you that 1/10th of the price - would you be happy with your new buy, knowing that mom, pop and the college kid will have to repay what you "saved" ?

And for the victims of such an event - after hearing the suggestions about ransom, I would suggest to send all the logs to LL immediately, and request the suspension/termination of the said account. And when the miscreants will suggest to tone it down with LL - indeed you can do it. *After* they return the land *and* pay *you* for their behaviour. Don't be greedy, L$1000 will be enough of an amount. Afterwards you can donate the money to some good cause - and those guys maybe can go and buy a laptop to some child in a poorer country.

If anyone with a professional lawyer background happens to read this - would be very interesting to know whether this kind of activity can indeed be classified legally as a computer crime.

If yes - this can be a very effective way to control this mess.

Sunday, November 4, 2007

Getting rid of an UFO over the parcel...

Yesterday I had some quite interesting experience which I would like to share - maybe it helps someone.

There's a piece of land where I can do some stuff, but I do not have the ownership of it. The permissions on land are quite relaxed - scripting is enabled, building is enabled as well, however, to avoid the littering-by-ignorance, the land is set to autoreturn in 120 minutes.

Note, that as I am a member of the group the land is set to - so the autoreturn does not affect my stuff. (It's mostly only me who plays around on that plot, anyway).

I've not been spending the time on SL for quite a while, and last time noticed there was some strange particle effect over the parcel. "Hmmm... I've set it to autoreturn! Let's check..."

Indeed the land is set to autoreturn, and yet the small blue clouds of smoke are directly over the parcel. Not catastrophic at all, but a little bit annoying - somehow the autoreturn has been circumvented...

Selecting my object which sits in the corner of the parcel, and then extending the selection over the area reveals the secret - there's a flying transparent ball, which has the particle effects inside.

And, on each cycle, it flies *outside* of the parcel, so the autoreturn timer gets reset. Amusingly clever, I say. Although probably it is just a result of a random ignorance. From my experience, when the other people seem evil, it's about 1% of the time they are really evil, all the rest 99% they're just happily ignorant. But, let's see what we can do.

The first thought is to try to build a hollow cube to contain the movements of this little evil thing. Alas - the little evil thing, besides being transparent, is also physical and phantom, so it flies through the cube without any trouble.

Next lazy thing is to try to IM the owner - well, no reply... Writing angry blog about griefers putting the junk over my parcel ? that wouldn't help at all... filing an AR ? That's too boring. Let's be creative and think...

Ahha! I remember, that when this UFO was selected, it *stopped* moving. So, the plan is clear: select the object while it is over "my" parcel, and patiently wait for 2 hours :)

First part was very easy, the second part proved to be a bit more difficult - as I did not login to SL for quite a while, there were a couple of friends willing to show their new stuff, so I lost the focus. Nonetheless, finally I told myself "I am not moving until 2 hours elapses. Let me sacrifice myself for the sake of science".

Then I left the SL for a while "editing" that object, then a good friend IMed me and we spent quite some time discussing the geeky stuff. So the 2 hours had passed. The object does not disappear. Bummer. The friend tells it is a nice known feature. Well, after more thinking this feature indeed seems logical - you would not like the object to disappear from your nose in the sandbox or such.

So, let's try the luck - and release the edit... and - puff.

The UFO vanishes from the airspace above the parcel - maybe gets returned to owner, maybe decides to fly back to the stars.

Great. The goal is achieved, and no martians have been hurt in the process.

Sunday, September 30, 2007

Password stealing is about to become simpler...

Just read on Nicholaz's blog about the upcoming change to the way authentication is done in SL.

Let's put it short and simple: implementing it this way in the context of SL would be the most serious mistake, if the goal was to improve security.

D'oh... I'm speechless.

Tuesday, June 12, 2007

Simple thing which improve your security, that frequently get overlooked...

While the others are promising the blue skies, free cookies (free browser cookies, I mean), here's some basic practical advice for you on behalf of the Grid Democracy Party, that you can put to use regardless of your SLpolitical SLpreferences. While being a *very* basic thing, I've seen it overlooked quite a few times. If you know all this - then I am glad for you :-)

This short note will talk about your "private" land mostly - not necessarily the clubs or other public places - there the settings might be slightly different to ensure the maximum comfort of the visitors, and these settings do not fit well.

1) Have a "visitor group", with which you set the land:

safesettings-1

2) Minimize the potential dangerous activities on the land by "strangers":

safesettings-2

What this does ?

First, about the options that should be unchecked:


  • Edit Terrain. You do not want others to tweak your carefully made landscaping.
  • Create objects: All residents. You do not really want random object creation on your private land ?
  • Object entry: All residents. Same goes about the objects from non-group entering from other parcels.
  • Run scripts: All residents. While this setting only works on small heights, it at least covers that area, if you want to be safe.


Now, about those that we have checked


  • Safe (no damage). Unless you are planning to turn your land into a battlespace, you most probably would not need this :-)
  • Restrict pushing. This will help against some very basic forms of griefing (again, why would you want to push someone except if it is a boxing ring ?)

  • Create objects: group. You trust your friends to create the objects and clean up later, right ? If no - why would they be in your guest group ?
  • Object Entry: group. Even though your friends did not necessarily rez the objects on the other plots, no harm in turning this on if you did turn the other one on.
  • Run scripts: group. Same remark as in previous scripts (that was disabled) - useful for the areas just above ground to allow your friends' AO and other gadgets to work.


Then, the teleport point. If you would like to have people that teleport to your land, to land on a certain point - set this point, so they do not get into the middle of your kitchen or some more private place (yeah I would consider my kitchen private, if only I had it! :)

I guess that's it for this simple post - hope it helps someone to avoid some troubles.

I do have some more creative (and a *bit* more complex :) ideas in mind, stay tuned...