Yahoo Dashboard

Ok, this is just asking for a lawsuit. Does the same thing with apparently the same name. Not sure if the article is just inaccurate with the term “Dashboard” or if that was accurate.

The only complexity is that Apple allegedly got the idea for Dashboard by stealing from Konfabulator.

This will be interesting.

Microsoft pushing Sender ID?

Ok, just when I was starting to think that Microsoft may be changing their ways and trying to act in good faith after them fixing their website the other day. Microsoft starts talking about pushing their sender ID stuff on us. Sender ID is Microsoft’s alternative to the other spam prevention techniques such as Yahoo’s DomainKeys. One problem with Sender ID is the licensing, which has caused organizations like Apache Foundation (who oversee the SpamAssassin project), to nix support for Sender ID. AOL has also also dropped support, and looked towards SPF.

I agree one one of these standards is needed to help prevent spam. Personally I think DomainKeys is the most promising of them all. It’s licensing looks like it will be adequate, and it has a fair amount of backing. Google’s Gmail has apparantly implemented SPF and DomainKeys at this time. I think it’s time for everyone to start looking at following their lead. These two technologies look to be the best. And by implementing them, your mail is more likely to get past spam filters. Microsoft is right, it’s time to start acting. But not with their own proprietary stuff.

Switching to Gaim

I’m not exactly a big Instant Messaging fan, but it seems life forces you to use it these days. The majority of use on AIM, some MSN, Yahoo, and sometimes my favorite Skype. All those clients are clutter. So I don’t use Yahoo much, and keep that one closed. I’ve complained several times about how AOL dropped the ball with AIM. It’s client is about as bloated as Real Player. It’s gotten progressively worse after each release, to get a new feature, or security fix, you need to sacrifice more of your computer. I personally don’t like that concept.

I’m now using Gaim full time, and it seems to work rather well for me, minus a few caveats. Anyone who can help me would be requested to leave a comment:

  • Gaim won’t load with cygwin in the PATH, crashing with no clear error. No clue how to fix this without killing cygwin yet.
  • I could really use a S/MIME encryption plugin so that I’m compatible with those using the official AIM client with security enabled (they use SSL and S/MIME I believe). Anyone know of such a plugin?
  • Way to enforce a minimum font size (windows users tend to use rather small font sizes for things like AIM profiles, I’d love to simply +1 a few off the smaller ones).
  • Not that I use it often, but AIM has somewhat unstable file transfer. Some improvements in that area would be welcome.

Overall, I’m rather satisfied. It’s not perfect, but it’s better than AIM is at the moment. Perhaps Triton will shape up at some point. Until then I think Gaim is the best solution.

Note: Yes, I’ve tried Trillian. It’s a good product, but not good enough to pay for. Sorry Trillian fans. It’s rather ugly (haven’t seen a skin yet that doesn’t fix that), it’s UI is just strange, and it’s just not featured enough for the money. Adium is bliss on my Mac.

Yahoo gives way to identity fraud

Think about it:

  • Marine was over 18 (legal independent adult in the US).
  • Marine didn’t put in writing that he wanted his parents to have access.

Considering this. Why can’t I have access? There is no report of the parents having a DNA test compared to the remains of the soldier to prove a blood relation. For all that’s known, they are just random people. A persons birth certificate in the US doesn’t contain fingerprinting of parent/child (as it should, and has been argued for about 50 years). Only a legal name of the child, and the parent, plus mothers age. Which often isn’t unique (how many John Smith’s are there). This isn’t to say they are cons. But that there’s no true proof unless there’s a DNA test. It’s rather easy in the US to live under an identity that’s not your own. People do it all the time. Most just to escape creditors, or family. Nothing to evil. But of course some ex-cons do as well just to escape the stigma. Stories of people living under fake identities for decades are not at all uncommon. They get drivers licenses, and all benefits under such identities.

Nor is there legal president that just because your a parent you can get such access. Normally that would go to whom ever the deceased designates. Not just “anyone who asks for it” Typically a spouse.

If that soldier’s bank account didn’t have his parent as a cosign on the account. Guess what. That account’s not going to the parents with just a simple legal proceeding.

This is a big win for any identity scammers. Look through death certificates filed at your local municipality, and go after ISP’s to get email accounts. Then use the email account (and it’s data). Can do all sorts of fun things:

  • pretend to be that person and con people
  • extract passwords, data from stored email
  • submit it to websites to get passwords reset on various accounts

It would be rather easy for someone to show a death certificate and say they are the next of kin and deserve the ability to take the persons identity (which is essentially what getting email is).

This is phishing to a whole new level.

This is of course beside the fact that anyone who emailed the person intended for the email to be received by the individual, not whomever files papers with the court for access. At a minimum Yahoo should have contacted all people who corresponded with the individual and asked if they are ok with being included with this. If I were one of them, I would be rather upset. An email sent is intended for the recipient, unless otherwise stated.

Get ready for some serious abuse of this new power. I’m positive were going to see some new phishing attempts designed to exploit this.

I’m curious why it isn’t this easy to get access to someone’s bank account without being a cosign on the account? What’s the difference? There’s a lot less harm in getting access to assume the persons cash then the persons identity.

Credit to yahoo for giving a CD, not the account itself. But it’s still wrong. This makes fraud all to easy. Now you don’t even need to be smart. You just need to have the balls to file some papers with a court who is way to busy to even read them.