<?xml version="1.0" encoding="UTF-8"?><rss version="2.0">
<channel>
	<title>A Man, Who Does Not Exist , Profy.com</title>
	<link>http://michaelmknight.profy.com</link>
	<description>Profy.com, Blog of user: Michael Knight</description>
		<item>
		<title>Mike2.0</title>
		<link>http://michaelmknight.profy.com/blog/post/41701831</link>
		<guid>http://michaelmknight.profy.com/blog/post/41701831</guid>
		<description>
			<![CDATA[ <p><b><img src="http://www.michaelmknight.co.uk/postimages/mik.PNG" alt="Michael Knight - Meeee" align="right" height="156" width="212">Well, here’s a little about me</b>.</p><br />
<p> I’m a former Microsoft Consultant. I worked in the MSN &amp;  Windows Technical departments providing support to end users and training  internal Microsoft staff. I've been in IT for over 20 years now, I have various certifications from MCSE, MCT, MCDST and more. <br><br />
  <br><br />
  I have since left Microsoft Corporation and now work as a Forensic IT Consultant  and Web / Graphic Designer. One by day, the other by night, (Or whenever I’m  needed). I have been into computers since I got the first ever electronic game  that you plugged into your TV called <a href="http://en.wikipedia.org/wiki/Pong" target="_blank">Pong</a>. Not much later I was bought the Sinclair  <a href="http://en.wikipedia.org/wiki/Sinclair_ZX81" target="_blank">ZX81</a> 1k <b>Home Personal Computer</b>. It was a powerful bit of kit (not). I had a  little tape deck and a <a href="http://en.wikipedia.org/wiki/Image:Sinclair.zx.thermal.printer.jpg" target="_blank">printer</a>, that looked like a till roll. After that I had  a <a href="http://en.wikipedia.org/wiki/Commodore_64" target="_blank">Commodore 64</a>. This was the best thing ever. I had great times with the <b>C64</b>  and have fond memories of playing the games and programming the thing. Mostly  though, you typed in <i>hundreds</i> of lines of code, I typed <b>Run</b> and hit <b>enter</b>, only  to be greeted with:<br><br />
  </p><br />
<p><img src="http://www.michaelmknight.co.uk/postimages/com.PNG" alt="Commodore 64" height="270" width="384"><br><br />
  <br><br />
  I now spent another 3 days looking for what id done wrong.  It was usually a . instead of a , grrr.<br><br />
  With the Commodore, I had my first taste of the Internet. I  had an <a href="http://en.wikipedia.org/wiki/Acoustic_coupler" target="_blank">Acoustic Coupler</a> Modulator/Demodulator (Modem to you). This connected me  to BBS sites (Bulletin Board Service) like <a href="http://en.wikipedia.org/wiki/Prestel" target="_blank">Prestel and Micronet</a>. These were  interactive pages, not much different than the early Teletext pages like Ceefax  and Oracle. <br><br />
  <br><br />
  Anyway, after all this I got a PC in the early 90’s with Windows for DOS on it,  some call it Windows for Workgroups. Then came <a href="http://en.wikipedia.org/wiki/Windows_3.0" target="_blank">Windows 3.x</a> then Windows 95, <a href="http://en.wikipedia.org/wiki/History_of_Microsoft_Windows#Windows_3.1_and_NT" target="_blank">you  know the rest</a>.<br><br />
  Anyway, by this time I was having my name laughed at because  of a cool TV Show called <a href="http://en.wikipedia.org/wiki/Knight_Rider" target="_blank">Knight Rider</a>. 20+ years later and Its still happening,  each person that remembers Knight Rider think that they are the first person to  say ‘hey where’s <a href="http://en.wikipedia.org/wiki/KITT" target="_blank">KITT</a>?’ or &nbsp;‘Not out  crime fighting?’ or doing KITT’s scanner noise whoosh whoosh.<br><br />
  <br><br />
  Anyway, now I’m all grown up and work for myself. I write as much as I can,  listen to just about every piece of music I can. I’m a huge Movie fan and love  <b>Scary Movies</b> and geeky <b>Sci-Fi</b> .<br><br />
  <br><br />
  I try to get out as much as I can, which really isn’t a lot. So, that’s me in a  nutshell. <br><br />
  <br><br />
  Feel free to <b>message me</b>, add me to <a href="skype:Microft?add" target="_self">Skype</a> or contact me anyway you can. I’m  always looking to make new <b>friends</b>. Thanks for reading.</p><br />
<p>Mike<br><br>P.S. For those of you who would like to relive (or try) the Commodore 64, you can download an <a href="http://www.michaelmknight.co.uk/files/WinVICE.exe" target="_self">Emulator Here</a> &amp; and some <a href="http://www.c64.com/" target="_blank">Commodore Games Here</a>.<br><br />
</p> ]]>
		</description>
		<pubDate>Thu, 03 Apr 2008 22:02:00 -0700</pubDate>
		<author>Michael Knight</author>
	</item>
	<item>
		<title>V: The Second Generation</title>
		<link>http://michaelmknight.profy.com/blog/post/41371881</link>
		<guid>http://michaelmknight.profy.com/blog/post/41371881</guid>
		<description>
			<![CDATA[ <br />
<p><img src="http://www.michaelmknight.co.uk/postimages/v.PNG" alt="V: The Second Generation" align="right" height="163" width="128"><b>In 1983, Aliens pretending to be friendly come to Earth and are received openly.  The aliens have masqueraded themselves to look just like humans</b>. When  it is discovered that the aliens' planet is dying and that they have  come to rape the Earth of its natural resources, the war for Earth  begins.</p><br />
<p>In the early 80's I was enthralled with the mini series of V. Nothing came close to the awe that the series had on many people, not even Star Trek. V was totally new and had viewers hooked with its invasion storyline. Not since HG. Wells' The War Of The Worlds radio broadcast had a Sci-Fi series hold its watchers captive.</p><br />
<p>V started as a mini series, spread over 5 night 2 hourly slots. The first 2 episodes saw over 50 giant saucer shaped disks appear through the clouds across most of the major cities in the world. They came in peace, looking for our help, and befriended the most powerful and influential people in government and technical fields.</p><br />
<p>Only a handful of people noticed that something was wrong. Half of the town is going missing, strange things happening that others seem not to notice...</p><br />
<p>The last 3 episodes were called <span style="font-weight: bold;">The Final Battle</span>, and you found out the truth about why the Visitors (aliens) came to our planet. We battle the aliens and win, sending them fleeing with their scaly tails between their legs.</p><br />
<p>After this came a 21 episode series that continued from the original mini-series, but I'm not going to talk about that.</p><br />
<p>Its almost 26 years since the visitors came to earth, but now they are back. 2009 will see <span style="font-weight: bold;">V: The Second Generation</span>. This is a brand new mini-series, again like the 21 part series, will continue the theme of the Visitors on earth.</p><br />
<p>There are a few things I have really looked forward to, like the War of the Worlds Movie, Spiderman 2,3 and 4. Knight Rider the new series and movie (I know my name is Michael Knight, but hey, I can still be interested). But out of all the things that I have waited for, none holds more interest than the new V Mini-Series. I bought the book, but refuse to read it until I have seen the TV series, I want to see if it keeps me as hooked as it did back in 1983. I really can't wait.</p><br />
<p>What's more, quite a few of the Original Cast, Marc Singer, Faye Grant, Robert Englund (Freddy Kruger), Michael Ironside &amp; Blair Tefkin have all signed on to revive their characters from the 83' series. Its just going to be great.<br><br><span style="font-weight: bold;">This is a Fan Made trailer - I will update this when the Official one gets released.</span><br></p><p><object width="425" height="355"><param name="movie" value="http://www.youtube.com/v/thPv5sbjdUo&hl=en"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/thPv5sbjdUo&hl=en" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"></embed></object><br />
</p><br />
 ]]>
		</description>
		<pubDate>Thu, 03 Apr 2008 06:21:00 -0700</pubDate>
		<author>Michael Knight</author>
	</item>
	<item>
		<title>Chain Mail &amp; Hoaxes</title>
		<link>http://michaelmknight.profy.com/blog/post/40841401</link>
		<guid>http://michaelmknight.profy.com/blog/post/40841401</guid>
		<description>
			<![CDATA[ Its simple, Rule No. 1 Don't pass the mails to everyone in your address book... Why? I hear you say, Read on...<br><br />
<br><br />
<b>What Are Internet Hoaxes and Chain Letters?</b><br><br />
<br><br />
Internet hoaxes and chain letters are e-mail messages written with one<br />
purpose; to be sent to everyone you know. The messages they contain are<br />
usually untrue. A few of the sympathy messages do describe a real<br />
situation but that situation was resolved years ago so the message is<br />
not valid and has not been valid for many years. Hoax messages try to<br />
get you to pass them on to everyone you know using several different<br />
methods of social engineering. Most of the hoax messages play on your<br />
need to help other people. Who wouldn't want to warn their friends<br />
about some terrible virus that is destroying people's systems? Or, how<br />
could you not want to help this poor little girl who is about to die<br />
from cancer? It is hard to say no to these messages when you first see<br />
them, though after a few thousand have passed through your mail box you<br />
(hopefully) delete them without even looking.<br><br />
<br><br />
Chain letters are lumped in with the hoax messages because they have<br />
the same purpose as the hoax messages but use a slightly different<br />
method of coercing you into passing them on to everyone you know.<br><br />
<br><br />
Chain letters, like their printed ancestors, generally offer luck or<br />
money if you send them on. They play on your fear of bad luck and the<br />
realization that it is almost trivial for you to send them on. The<br />
chain letters that deal in money play on people's greed and are illegal<br />
no matter what they say in the letter.<br><br />
<br><br />
<b>The Risk and Cost of Hoaxes</b><br><br />
<br><br />
The cost and risk associated with hoaxes may not seem to be that high,<br />
and isn't when you consider the cost of handling one hoax on one<br />
machine. However, if you consider everyone that receives a hoax, that<br />
small cost gets multiplied into some pretty significant costs. For<br />
example, if everyone on the Internet were to receive one hoax message<br />
and spend one minute reading and discarding it, the cost would be<br />
something like:<br><br />
<br><br />
<b>50,000,000 people * 1/60 hour * £50/hour = £41.7 million</b><br><br />
<br><br />
Most people have seen far more than one hoax message and many people<br />
cost a business far more than £50 per hour when you add in benefits and<br />
overhead. The result is not a small number.<br><br />
<br><br />
Probably the biggest risk for hoax messages is their ability to<br />
multiply. Most people send on the hoax messages to everyone in their<br />
address books but consider if they only sent them on to 10 people. The<br />
first person (the first generation) sends it to 10, each member of that<br />
group of 10 (the second generation) sends it to 10 others or 100<br />
messages and so on.<br><br />
<br><br />
As you can see, by the sixth generation there are a million e-mail<br />
messages being processed by our mail servers. The capacity to handle<br />
these messages must be paid for by the users or, if it is not paid for,<br />
the mail servers slow down to a crawl or crash. Note that this example<br />
only forwards the message to 10 people at each generation while people<br />
who forward real hoax messages often send them to many times that<br />
number.<br><br />
<br><br />
Recently, we have been hearing of spammers (bulk mailers of unsolicited<br />
mail) harvesting e-mail addresses from hoaxes and chain letters. After<br />
a few generations, many of these letters contain hundreds of good<br />
addresses, which is just what the spammers want. We have also heard<br />
rumors that spammers are deliberately starting hoaxes and chain letters<br />
to gather e-mail addresses (of course, that could be a hoax). So now,<br />
all those nice people who were so worried about the poor little girl<br />
dying of cancer find themselves not only laughed at for passing on a<br />
hoax but also the recipients of tons of spam mail.<br><br />
<br><br />
<b>How to Recognize a Hoax</b><br><br />
<br><br />
Probably the first thing you should notice about a warning is the<br />
request to "send this to everyone you know" or some variant of that<br />
statement. This should raise a red flag that the warning is probably a<br />
hoax. No real warning message from a credible source will tell you to<br />
send this to everyone you know.<br><br />
<br><br />
Next, look at what makes a successful hoax. There are two known factors that make a successful hoax, they are:<br><br />
<br><br />
(1) technical sounding language.<br><br />
(2) credibility by association.<br><br />
<br><br />
If the warning uses the proper technical jargon, most individuals,<br />
including technologically savvy individuals, tend to believe the<br />
warning is real. For example, the Good Times hoax says that "...if the<br />
program is not stopped, the computer's processor will be placed in an<br />
nth-complexity infinite binary loop which can severely damage the<br />
processor...". The first time you read this, it sounds like it might be<br />
something real. With a little research, you find that there is no such<br />
thing as an nth-complexity infinite binary loop and that processors are<br />
designed to run loops for weeks at a time without damage.<br><br />
<br><br />
When we say credibility by association we are referring to who sent the<br />
warning. If the janitor at a large technological organization sends a<br />
warning to someone outside of that organization, people on the outside<br />
tend to believe the warning because the company should know about those<br />
things. Even though the person sending the warning may not have a clue<br />
what he is talking about, the prestige of the company backs the<br />
warning, making it appear real. If a manager at the company sends the<br />
warning, the message is doubly backed by the company's and the<br />
manager's reputations.<br><br />
<br><br />
Both of these items make it very difficult to claim a warning is a hoax<br />
so you must do your homework to see if the claims are real and if the<br />
person sending out the warning is a real person and is someone who<br />
would know what they are talking about. You do need to be a little<br />
careful verifying the person as the apparent author may be a real<br />
person who has nothing to do with the hoax. If thousands of people<br />
start sending them mail asking if the message is real, that essentially<br />
constitutes an unintentional denial of service attack on that person.<br />
Check the person's web site or the person's company web site to see if<br />
the hoax has been responded to there. Check these pages or the pages of<br />
other hoax sites to see if we have already declared the warning a hoax.<br><br />
<br><br />
Hoax messages also follow the same pattern as a chain letter (see below).<br><br />
<br><br />
<b>Recognizing a Chain Letter</b><br><br />
<br><br />
Chain letters and most hoax messages all have a similar pattern. From<br />
the older printed letters to the newer electronic kind, they all have<br />
three recognizable parts:<br><br />
<br><br />
A hook.<br><br />
A threat.<br><br />
A request.<br><br />
<br><br />
<b>The Hook</b><br><br />
<br><br />
First, there is a hook, to catch your interest and get you to read the<br />
rest of the letter. Hooks used to be "Make Money Fast" or "Get Rich" or<br />
similar statements related to making money for little or no work.<br />
Electronic chain letters also use the "free money" type of hooks, but<br />
have added hooks like "Danger!" and "Virus Alert" or "A Little Girl Is<br />
Dying". These tie into our fear for the survival of our computers or<br />
into our sympathy for some poor unfortunate person.<br><br />
<br><br />
<b>The Threat</b><br><br />
<br><br />
When you are hooked, you read on to the threat. Most threats used to<br />
warn you about the terrible things that will happen if you do not<br />
maintain the chain. However, others play on greed or sympathy to get<br />
you to pass the letter on. The threat often contains official or<br />
technical sounding language to get you to believe it is real.<br><br />
<br><br />
<b>The Request</b><br><br />
<br><br />
Finally, the request. Some older chain letters ask you to mail a dollar<br />
to the top ten names on the letter and then pass it on. The electronic<br />
ones simply admonish you to "Distribute this letter to as many people<br />
as possible." They never mention clogging the Internet or the fact that<br />
the message is a fake, they only want you to pass it on to others.<br><br />
<br><br />
Chain letters usually do not have the name and contact information of<br />
the original sender so it is impossible to check on its authenticity.<br />
Legitimate warnings and solicitations will always have complete contact<br />
information from the person sending the message and will often be<br />
signed with a cryptographic signature, such as PGP to assure its<br />
authenticity. Many of the newer chain letters do have a person's name<br />
and contact information but that person either does not really exist or<br />
does exist but does not have anything to do with the hoax message. As<br />
mentioned in the previous section, try to use other means than<br />
contacting the person directly to find out if the message is a hoax.<br />
Try the person's web page, the person's company web page, or this and<br />
other hoax sites first to see if the message has already been declared<br />
a hoax.<br><br />
<br><br />
For example, the PENPAL GREETINGS! hoax shown below appears to be an<br />
attempt to kill an e-mail chain letter. This chain letter is a hoax<br />
because reading a text e-mail message does not execute a virus nor does<br />
it execute any attachments; therefore the Trojan horse must be self<br />
starting. Aside from the fact that a program cannot start itself, the<br />
Trojan horse would have to know about every different kind of e-mail<br />
program to be able to forward copies of itself to other people. We have<br />
had to modify this statement slightly for the newer html mail readers.<br />
If a mail message is formatted with html and contains scripts, those<br />
scripts will run when the e-mail message is read. Active scripting<br />
should always be turned off for a mail reader so that malicious code<br />
like the KAK worm cannot automatically run.<br><br />
<br><br />
Notice the three parts of a chain letter, which are easy to identify in this example.<br><br />
<br><br />
<b>The Hook</b><br><br />
<br><br />
FYI!<br><br />
<br><br />
Subject: Virus Alert<br><br />
Importance: High<br><br><br />
If anyone receives mail entitled: PENPAL GREETINGS! please delete it WITHOUT reading it. Below is a little explanation of the message, and what it would do to your PC if you were to read the message. If you have any questions or concerns please contact SAF-IA Info Office on 697-5059.<br><br />
<br><br />
<b>The Threat</b><br><br />
<br><br />
This is a warning for all internet users - there is a dangerous virus<br><br />
propogating across the internet through an e-mail message entitled "PENPAL GREETINGS!". DO NOT DOWNLOAD ANY MESSAGE ENTITLED "PENPAL GREETINGS!"<br><br><br />
This message appears to be a friendly letter asking you if you are interested in a penpal, but by the time you read this letter, it is too late. The "trojan horse" virus will have already infected the boot sector of your hard drive, destroying all of the data present. It is a self-replicating virus, and once the message is read, it will AUTOMATICALLY forward itself to anyone<br><br />
who's e-mail address is present in YOUR mailbox! <br><br>This virus will DESTROY your hard drive, and holds the potential to DESTROY the hard drive of anyone whose mail is in your inbox, and who's mail is in their inbox, and so on. If this virus remains unchecked, it has the potential to do a great deal of DAMAGE to computer networks worldwide!!!! Please, delete the message entitled "PENPAL GREETINGS!" as soon as you see it!<br><br />
<br><br />
<b>The Request</b><br><br />
<br><br />
And pass this message along to all of your friends and relatives, and the other readers of the newsgroups and mailing lists which you are on, so that they are not hurt by this dangerous virus!!!!<br><br />
<br><br />
<b>Validating a Warning</b><br><br />
<br><br />
CIAC recommends that you DO NOT circulate warnings without first<br />
checking with an authoritative source. Authoritative sources are your<br />
computer system security administrator, your computer incident handling<br />
team, or your antivirus vendor. Real warnings about viruses and other<br />
network problems are issued by computer security response teams (CIAC,<br />
CERT, ASSIST, NASIRC, etc.) and are digitally signed by the sending<br />
team using PGP. If you download a warning from a team's web site or<br />
validate the PGP signature, you can usually be assured that the warning<br />
is real. Warnings without the name of the person sending the original<br />
notice, or warnings with names, addresses and phone numbers that do not<br />
actually exist are probably hoaxes. Warnings about new malicious code<br />
are also available at the antivirus vendors sites and at the operating<br />
system's vendor site.<br><br />
<br><br />
Companies like Microsoft will not send out mass emails explaining<br />
Bidwieser frog screensavers or possible virus threats and they certanly<br />
do not give out money for Beta Testing.<br><br />
<br><br />
<b>What to Do When You Receive a Warning</b><br><br />
<br><br />
Upon receiving a warning, you should examine its PGP signature to see<br />
that it is from a real response team or antivirus organization. To do<br />
so, you will need a copy of the PGP software and the public signature<br />
of the team that sent the message. The CIAC signature is available at<br />
the CIAC home page: <a rel="nofollow" class="t" href="http://ciac.llnl.gov/" target="_blank">http://ciac.llnl.gov/</a> You can find the addresses of other response teams by connecting to the FIRST web page at: <a rel="nofollow" class="t" href="http://www.first.org/" target="_blank">http://www.first.org</a>.<br />
If there is no PGP signature, check at this and other hoax sites to see<br />
if the warning has already been declared as a hoax. If you do not find<br />
the warning at the hoax sites, it just may mean that we have not yet<br />
seen this particular hoax.<br><br />
<br><br />
See if the warning includes the name of the person submitting the<br />
original warning. If it does, see if you can determine if the person<br />
really exists. If they do, don't send them an e-mail message. It is<br />
likely that they have nothing to do with this hoax and thousands of<br />
people sending them questions will be just as damaging to them as<br />
sending around the hoax message. Instead, check their personal or<br />
company web site. Often if a person has been the brunt of a hoax, that<br />
hoax message will be debunked on the person's company web site. If you<br />
still cannot determine if a message is real or a hoax, send it to your<br />
computer security manager, your ISP, or your incident response team and<br />
let them validate it.<br><br />
<br><br />
<b>When in Doubt, Don't Send It Out</b><br><br />
<br><br />
In addition, most anti-virus companies have a web page containing<br />
information about most known viruses and hoaxes. You can also call or<br />
check the web site of the company that produces the product that is<br />
supposed to contain the virus. Checking the PKWARE site for the current<br />
releases of PKZip would stop the circulation of the warning about<br />
PKZ300 since there is no released version 3 of PKZip. Other useful<br />
virus and hoax sites are listed on our Other Hoax Sites pages. In most<br />
cases, common sense would eliminate Internet hoaxes.<br><br />
<br><br />
<b>Why People Send Chain Letters and Hoax Messages</b><br><br />
<br><br />
Only the original writer knows the real reason, but some possibilities are:<br><br />
<br><br />
To gather Email addresses to go on a Spam List.<br><br />
To see how far a letter will go.<br><br />
To harass another person (include an e-mail address and ask everyone to send mail to, e.g. Michael Knight).<br><br />
To bilk money out of people using a pyramid scheme.<br><br />
To kill some other chain letter (e.g. Make Money Fast).<br><br />
To damage a person's or organization's reputation.<br><br />
<br><br />
<b>History of Virus Hoaxes</b><br><br />
<br><br />
Since 1988, computer virus hoaxes have been circulating the Internet.<br />
In October of that year, according to Ferbrache ("A pathology of<br />
Computer Viruses" Springer, London, 1992) one of the first virus hoaxes<br />
was the 2400 baud modem virus:<br><br />
<br><br />
SUBJ: Really Nasty Virus<br><br />
AREA: GENERAL (1)<br><br />
<br><br />
I've just discovered probably the world's worst computer virus<br><br />
yet. I had just finished a late night session of BBS'ing and file<br><br />
treading when I exited Telix 3 and attempted to run pkxarc to<br><br />
unarc the software I had downloaded. Next thing I knew my hard<br><br />
disk was seeking all over and it was apparently writing random<br><br />
sectors. Thank god for strong coffee and a recent backup.<br><br />
Everything was back to normal, so I called the BBS again and<br><br />
downloaded a file. When I went to use ddir to list the directory,<br><br />
my hard disk was getting trashed again. I tried Procomm Plus TD<br><br />
and also PC Talk 3. Same results every time. Something was up so I<br><br />
hooked up to my test equipment and different modems (I do research<br><br />
and development for a local computer telecommunications company<br><br />
and have an in-house lab at my disposal). After another hour of<br><br />
corrupted hard drives I found what I think is the world's worst<br><br />
computer virus yet. The virus distributes itself on the modem sub-<br><br />
carrier present in all 2400 baud and up modems. The sub-carrier is<br><br />
used for ROM and register debugging purposes only, and otherwise<br><br />
serves no other purpose. The virus sets a bit pattern in one<br><br />
of the internal modem registers, but it seemed to screw up the<br><br />
other registers on my USR. A modem that has been "infected" with<br><br />
this virus will then transmit the virus to other modems that use a<br><br />
subcarrier (I suppose those who use 300 and 1200 baud modems<br><br />
should be immune). The virus then attaches itself to all binary<br><br />
incoming data and infects the host computer's hard disk. The only<br><br />
way to get rid of this virus is to completely reset all the modem<br><br />
registers by hand, but I haven't found a way to vaccinate a modem<br><br />
against the virus, but there is the possibility of building a<br><br />
subcarrier filter. I am calling on a 1200 baud modem to enter this<br><br />
message, and have advised the sysops of the two other boards<br><br />
(names withheld). I don't know how this virus originated, but I'm<br><br />
sure it is the work of someone in the computer telecommunications<br><br />
field such as myself. Probably the best thing to do now is to<br><br />
stick to 1200 baud until we figure this thing out.<br><br />
<br><br />
Mike RoChenle<br><br />
<br><br />
This bogus virus description spawned a humorous alert (even in my own inbox) by Robert Morris III :<br><br />
<br><br />
Date: 11-31-88 (24:60) Number: 32769<br><br />
To: ALL Refer#: NONE<br><br />
From: ROBERT MORRIS III Read: (N/A)<br><br />
Subj: VIRUS ALERT Status: PUBLIC MESSAGE<br><br />
<br><br />
Warning: There's a new virus on the loose that's worse than<br><br />
anything I've seen before! It gets in through the power line,<br><br />
riding on the powerline 60 Hz subcarrier. It works by changing the<br><br />
serial port pinouts, and by reversing the direction one's disks<br><br />
spin. Over 300,000 systems have been hit by it here in Murphy,<br><br />
West Dakota alone! And that's just in the last 12 minutes.<br><br />
<br><br />
It attacks DOS, Unix, TOPS-20, Apple-II, VMS, MVS, Multics, Mac,<br><br />
RSX-11, ITS, TRS-80, and VHS systems.<br><br />
<br><br />
<span style="font-weight: bold;">To prevent the spread of the worm</span>:<br><br />
<br><br />
1) Don't use the power line.<br><br />
2) Don't use batteries either, since there are rumours that this<br><br />
virus has invaded most major battery plants and is infecting the<br><br />
positive poles of the batteries. (You might try hooking up just<br><br />
the negative pole.)<br><br />
3) Don't upload or download files.<br><br />
4) Don't store files on floppy disks or hard disks.<br><br />
5) Don't read messages. Not even this one!<br><br />
6) Don't use serial ports, modems, or phone lines.<br><br />
7) Don't use keyboards, screens, or printers.<br><br />
8) Don't use switches, CPUs, memories, microprocessors, or<br><br />
mainframes.<br><br />
9) Don't use electric lights, electric or gas heat or air-conditioning, running water, writing, fire, clothing or the wheel.<br><br />
<br><br />
I'm sure if we are all careful to follow these 9 easy steps, this<br><br />
virus can be eradicated, and the precious electronic flui9ds of<br><br />
our computers can be kept pure.<br><br />
<br><br />
---RTM III<br><br />
<br><br />
Since that time virus hoaxes have flooded the Internet.With thousands<br />
of viruses worldwide, virus paranoia in the community has risen to an<br />
extremely high level. It is this paranoia that fuels virus hoaxes. A<br />
good example of this behaviour is the "Good Times" virus hoax which<br />
started in 1994 and is still circulating the Internet today. Instead of<br />
spreading from one computer to another by itself, Good Times relies on<br />
people to pass it along.<br><br />
<br><br />
If you need to forward anything to more than 1 person, Please use the<br />
BCC field, thus breaking the chain. I hate getting these mails from<br />
people, and when I tell them they are fake they never beleive me thus<br />
always having to prove it. <br> ]]>
		</description>
		<pubDate>Wed, 02 Apr 2008 07:59:00 -0700</pubDate>
		<author>Michael Knight</author>
	</item>
	<item>
		<title>The Furure Of Identity</title>
		<link>http://michaelmknight.profy.com/blog/post/40838041</link>
		<guid>http://michaelmknight.profy.com/blog/post/40838041</guid>
		<description>
			<![CDATA[ The Internet has shown that reputations are important but don't have to<br />
be tied to specific real individuals. The entire banking system is<br />
built on top of the idea of reputation, but tries hard to tie them to<br />
real identities. The problem of identity theft is likely to break this<br />
connection. We will see a greater disconnect between individuals and<br />
their reputations. <br><br />
<br><br />
Identity theft has been a big hit with the purveyors of fear in recent<br />
years. We all now live in terror of waking up one morning and finding<br />
that someone has stolen our identity, and we can’t even remember who we<br />
are.<br><br />
<br><br />
Well, maybe not. But identity theft is a real problem. If someone<br />
manages to construct a copy of your identity, you don’t stop being you,<br />
you just stop being the owner of all of your money (unless you can<br />
persuade your bank it’s their fault). You might get back from vacation<br />
to find that your house has been stolen...<br><br />
<br><br />
Identity is closely tied to the concept of reputation. We are now<br />
trying to apply ideas from villages of a few hundred people to a global<br />
scale and (not surprisingly) finding that they don’t quite work.<br><br />
<br><br />
In a small community, everyone knows—or knows of—everyone else.<br />
Reputations are very important. If you want to borrow something from a<br />
neighbour, or ask them for a favour, then you will have some idea of<br />
how much you trust them.<br><br />
<br><br />
When banks started, they would use this sort of model. They would be<br />
willing to lend you money based on letters of recommendation from<br />
people they trusted, or based on their prior dealings.<br><br />
<br><br />
Now banks have grown so big that they use a much less personal system, but still deal in the idea of reputations.<br><br />
<br><br />
<b>The Social Security Scam</b><br><br />
<br><br />
Some time ago, the UK and the U.S. governments introduced the concept<br />
of a Social Security number (SSN). This was a unique identifier<br />
assigned to every taxpaying citizen, allowing their tax records to be<br />
connected together.<br><br />
<br><br />
Having a unique identifier for people was useful to a lot of<br />
institutions. It’s pretty hard to know whether you can trust John<br />
Smith, but it’s much easier to find out information about a specific<br />
John Smith.<br><br />
<br><br />
The problem began when people started regarding knowing someone’s<br />
Social Security number as proof (or, at least, strong evidence) that<br />
you were that person.<br><br />
<br><br />
This attitude isn’t limited to SSNs, by the way. One of my banks has an<br />
ultra-secure login where, in addition to my password, they also require<br />
that I tell them the following information:<br><br><ul><li> My mother’s maiden name</li><li> My house number</li><li> My date of birth</li></ul><br>All these responses are public knowledge and can be looked up by anyone who wanted to find them out.<br><br />
<br><br />
The most surreal experience I’ve had with a bank was one based in the<br />
United States. I phoned them to try to set up Internet banking. The<br />
conversation went something like this:<br><br />
<br><br />
   <b> Me</b>: Hi, I’d like to know my password for Internet banking, please.<br><br />
<br><br />
    <b>Them</b>: Certainly. We just need to confirm your identity. Can you tell me the size of the last transaction in your account, please?<br><br />
<br><br />
    <b>Me</b>: No, I want to log into Internet banking to look that up.<br><br />
<br><br />
    <b>Them</b>: Oh, we can tell you that over the phone.<br><br />
<br><br />
    <b>Me</b>: Okay...<br><br />
<br><br />
    <b>Them</b>: £n<br><br />
<br><br />
    <b>Me</b>: Thanks. The answer to your question is £n.<br><br />
<br><br />
    <b>Them</b>: Oh, I can’t ask you things I’ve just told you as a security question.<br><br />
<br><br />
    <b>Me</b>: Well, that’s sensible.<br><br />
<br><br />
    <b>Them</b>: Let me transfer you to someone who can.<br><br />
<br><br />
    <b>Me</b>: !<br><br />
<br><br />
The next person I talked to asked me for the number that the first<br />
representative had given me, and was then happy to pass on my Internet<br />
banking password.<br><br />
<br><br />
The illusion of security seems very popular with banks at the moment. <br><br />
<br><br />
<b>Reputation versus Identity</b><br><br />
<br><br />
Part of the problem with this system is that it associates your<br />
reputation with your identity. If you are going to buy a house and are<br />
looking for a mortgage, then it is not unreasonable for a potential<br />
lender to want to know about the house you are thinking of buying, your<br />
current income, earning potential, outstanding debts, and so on.<br><br />
<br><br />
If, on the other hand, you are looking to take out a credit card with a<br />
£1,000 credit limit, the only thing they need to know is whether you<br />
can service a debt of £1,000.<br><br />
<br><br />
Either do you have £1,000 in liquid assets, or do you have enough<br />
disposable income to service interest payments at the horrendous rates<br />
that credit card companies charge?<br><br />
<br><br />
Unfortunately, the way the system is set up at the moment, there is no<br />
fine-grained control. Someone who uses a £1,000 credit card application<br />
to steal your identity gets enough to take out a £500,000 mortgage<br />
backed by your reputation.<br><br />
<br><br />
A bigger problem is what to do after your identity has been stolen.<br />
Fingerprint locks are pretty cheap now, but most people still prefer to<br />
use pass codes. The reason is, if someone steals a pass code, you can<br />
change it.<br><br />
<br><br />
If someone steals a copy of your fingerprint, it’s very difficult to<br />
grow a new finger. The current situation with identities is similar to<br />
the fingerprint lock. So much of the information associated with your<br />
virtual identity is tied to the real you that building a new one that<br />
the thief does not have access to is very hard. <br><br />
<br><br />
<b>Multiple Personalities</b><br><br />
<br><br />
One solution to this problem would be to have multiple virtual<br />
identities. This is already quite common outside of financial circles.<br><br />
<br><br />
I have an account on <a class="t" href="http://www.slashdot.com/" target="_blank">Slashdot</a>,<br />
for example, where I post under a pseudonym. Someone who cared enough<br />
could probably link that virtual identity to me fairly easily, but most<br />
of the time it can be treated as a separate persona. It has an<br />
independent reputation, based on Slashdot’s karma system.<br><br />
<br><br />
Since I post more informative comments than troll posts (or, at least,<br />
most of my attempts at trolling go unnoticed), that persona has a good<br />
reputation. That reputation, however, is in no way related to the<br />
reputation I have as a result of writings published in other places.<br><br />
<br><br />
The idea of multiple personalities would make sense for financial<br />
markets, too. Going back to the earlier example, if I wanted to apply<br />
for a credit card, then I would not have to use my real identity to do<br />
so. I could create a new identity and have my real identity guarantee<br />
it up to a certain limit that would be sensible for the credit<br />
application.<br><br />
<br><br />
From the credit card company’s perspective, the identity would have a<br />
fixed income of some proportion of my income and a fixed capital of<br />
some proportion of my capital. They would be isolated from my real<br />
identity and only see the subset of my assets that were required to<br />
construct an identity that was a safe risk for lending money to.<br><br />
<br><br />
This kind of game isn’t particularly new. Corporations do it all the<br />
time. They set up shell companies, spin-offs, or joint ventures for a<br />
variety of purposes. Some have to do with combining resources from<br />
different companies; some have to do with shielding the parent<br />
organization from liability.<br><br />
<br><br />
Both of these would be useful for individuals. Couples sharing a house,<br />
for example, might want to create a phantom shared identity rather than<br />
having individual responsibility for various payments. Limiting<br />
liability is the more important one, however.<br><br />
<br><br />
The concept of limited liability has to do with limiting the amount of<br />
money you can lose. In simple terms, if a limited liability company<br />
goes bust, the investors don’t lose any money beyond that which they<br />
had invested already. Banks know this, and will not take the investors’<br />
assets into account when assessing the risk involved with lending the<br />
limited company money.<br><br />
<br><br />
Putting this in terms of identity theft, someone who could pose as the<br />
limited company would be able to do only a small amount of damage to<br />
the investors.<br><br />
<br><br />
This kind of structure would be ideal for limiting the effects of<br />
identity theft. When applying for small loans, you could create a<br />
limited liability identity, and an identity thief who took it would not<br />
gain any more than a thief who took a credit card.<br><br />
<br><br />
<b>Fluidity of Identity</b><br><br />
<br><br />
The Internet has shown time and time again that reputations are<br />
important, but don’t have to be tied to specific real individuals. The<br />
entire banking system is built on top of the idea of reputation, but<br />
tries hard to tie them to real identities.<br><br />
<br><br />
The problem of identity theft is likely to break this connection. We<br />
will see a greater disconnect between individuals and their reputations.<br><br />
<br><br />
Corporations already do this with different branding for different<br />
market segments, and it’s only a matter of time before the facilities<br />
become more widely available.<br><br />
<br><br />
The designers of the Secure Internet Live Chat (SILC) protocol realized<br />
this some years ago. SILC does not provide a mechanism for tying an<br />
online personality to a real person (although you can do this out of<br />
band).<br><br />
<br><br />
Instead, it provides something more valuable; a way of telling whether<br />
a particular online identity corresponds to the same person today as it<br />
did yesterday. This is valuable in an online chat setting, because the<br />
only contact you are likely to have with a particular person in an<br />
Internet chat room is via that chat room. The reputation is based<br />
entirely on their behaviour in that context.<br><br />
<br><br />
The same is true in many other contexts; the behaviour of individuals<br />
in a specific context is important and their actions in others are<br />
misleading. ]]>
		</description>
		<pubDate>Wed, 02 Apr 2008 07:44:00 -0700</pubDate>
		<author>Michael Knight</author>
	</item>
	<item>
		<title>Skype Spam is gettig worse</title>
		<link>http://michaelmknight.profy.com/blog/post/40828001</link>
		<guid>http://michaelmknight.profy.com/blog/post/40828001</guid>
		<description>
			<![CDATA[ &nbsp;How long before <a href="http://www.voip-news.com/vendors/skype/">Skype Ltd.</a> ends up as an item for bid on eBay? Ever since its <a href="http://www.voip-news.com/feature/ebay-skype-split-100207/">acquisition by the Internet auction site</a>,<br />
Skype has been a rudderless boat — and without a captain, following the<br />
departure of cofounder Niklas Zennstrom, who took £2.8 billion of<br />
Skype’s £5.2 billion value with him. Now, after a <a href="http://www.voip-news.com/feature/whats-wrong-with-skype-122707/">wave of complaints</a> regarding Skype’s complete lack of real-time customer service, comes a new trend: Skype spam.<br />
<p>There’s always been some spam on Skype. <a href="http://blog.tmcnet.com/beyond-voip/" target="_blank">Beyond VoIP</a> blogger Marc Robins <a href="http://blog.tmcnet.com/beyond-voip/web-telephony/skype-spam.asp" target="_blank">identified Skype spam</a> as “an alarming trend” nearly a year ago.  Skype <a href="http://forum.skype.com/index.php?showtopic=49841" target="_blank">user message boards</a> devoted to spam go back well into 2006; the spammers back then ranged from online casinos to Chinese jibberish.</p><br />
<p>Robins suggested in February 2007 that Skype should create a Do Not<br />
Spam list with heavily sanctioned fines for offenders, in the model of<br />
the national Do Not Call list for telemarketers. Instead, it seems the<br />
opposite has happened. Skype’s user database has been mined and turned<br />
into a To Call list that includes you.</p><br />
<p>Perhaps it was a desperate gambit by eBay to squeeze some blood from<br />
its costly turnip, or possibly lazy oversight by Skype’s corporate<br />
overlord that’s now <a href="http://www.voip-news.com/feature/worm-attacks-skype-091007/">damaging its product’s good standing</a><br />
in the wired marketplace. What one blogger noted as an “alarming trend”<br />
a year ago is now taking sharper focus, and more people are paying<br />
attention.</p><br />
<p><b>Meet Veronica</b></p><br />
<p>In December Jeremy Wagstaff, a tech columnist for The Wall Street Journal  and blogger at Loose Wire, <a href="http://www.loosewireblog.com/2007/12/meet-veronica-s.html" target="_blank">received his first Skype spam</a><br />
from “Veronica Sexy,” who billed herself as the “REAL MISS WEB CAM” and<br />
couldn’t wait to “get real nasty and show off.” When Wagstaff tried<br />
chatting with Veronica, her sex-bot automation directed him to her<br />
site, SkyperSex, which is headquartered in — you guessed it — Moscow.</p><br />
<p>Andy Melton <a href="http://techbutter.com/2008/01/05/skype-spam/" target="_blank">wrote on his blog TechButter</a><br />
that he’s felt the change recently, too. “What is the deal with all<br />
this Skype spam?” Melton wrote early this month. “I have never been<br />
inundated like this before.” While he had received some calls from<br />
Chinese people in the past, he said lately there was an “influx.”</p><br />
<p>Now not only do the Chinese keep calling, they are leaving him voice<br />
mail. He even received one cryptic spam call that said, “Hello, FBI.”<br />
Melton advised his readers that there isn’t much you can do to avoid<br />
the spam, except to make sure you don’t click the links they send you.</p><br />
<p><span id="more-23"></span>Tech blogger <a href="http://larryborsato.com/blog/2007/11/skypespam.html" target="_blank">Larry Borsato</a><br />
has been receiving similar calls. His Skype spammers tell him that<br />
“Windows Requires Immediate Attention” and that “Security Center has<br />
detected malware on your computer!” These Windows-based scare spams are<br />
even more transparent than usual when they pop up on a Mac (like<br />
Borsato uses) or a PC running Fedora (which Melton has). “Is this how<br />
eBay intends to monetize Skype?” Borsato asked. Apparently so.</p><br />
<p><b>No End in Sight</b></p><br />
<p>Given that Skype spam appears to be a widespread trend, there isn’t<br />
much any one person can do to stop it, other than blocking the<br />
offending user. But that defense is akin to swatting mosquitoes in a<br />
swamp: You’ll run out of swat before the swamp runs out of mosquitoes.</p><br />
<p>You could try using one of these <a href="http://21talks.net/featured/10-skype-alternatives">10 alternatives to Skype</a>.<br />
But, if you’d rather stick it out, you might be forced to batten down<br />
your Skype hatches and only allow messages from people you know. Go to<br />
Preferences &gt; Privacy and set “allow instant messages from” to “only<br />
people whom I have authorized to start.” You won’t get any pleasant<br />
Skype surprises anymore, but maybe you won’t get any unpleasant<br />
surprises either.</p><br />
<p>And of course, like its complete lack of real-time customer service,<br />
Skype has no “report this user” function. So, us Skypers are on our own.</p> ]]>
		</description>
		<pubDate>Wed, 02 Apr 2008 07:03:00 -0700</pubDate>
		<author>Michael Knight</author>
	</item>

</channel>
</rss>
