I'm the Lover of Earthlings now, because the Lover of Mankind is politically incorrect
Wednesday, September 23, 2009
Robot Love, "A Cinderella Story"
Saturday, May 30, 2009
Day 1.5
I started off being so pissed about someone taking my grill off my backporch that I didn't eat well. So I just drank a lot of Fiberwise, green super food, and protein shake to prep myself for the Master Cleanse. But I think I got the wrong type of sea salt because I didn't have any eliminations last night. But I woke this morning and have my normal scheduled one. So I tried a lit bit of Epson salt and water, and I think it works a lit better for me but that stuff is sooooo nasty.
Sunday, March 22, 2009
Saturday, March 21, 2009
Friday, March 20, 2009
Thursday, March 19, 2009
Tuesday, March 17, 2009
Monday, March 16, 2009
Sunday, March 15, 2009
Saturday, March 14, 2009
Friday, March 13, 2009
Thursday, March 12, 2009
Monday, March 9, 2009
Sunday, March 8, 2009
Saturday, March 7, 2009
Thursday, March 5, 2009
My Focus Tip of the day
Expanding my home network has been on my mind for about two months now. Sooner or later, I knew I would have to get another computer, but just didn't know which means to go by for just an extra desktop upstairs. Pawn shop? Ebay? I'm not into anything new at the moment.
So, I make good time getting to class today. Trying to get into the swing of things and improving my writing this semester. I go to the café to get some more coffee and maybe a turkey sandwich, and low and behold….
Computer liquidation sale, everything must go!
Yep, DeVry got new computers, extended classrooms, and other network remodeling. Great, I thought, I could at least get a decent CPU to run LinuxOS on for experience and expand my network.
"How much for one of these professor?" (one of the IT instructors is assisting to run the show) and I pointed to the line up on the table. Some of them looked disassembled.
"$10. But these are just for parts." and as I was beginning to get dismayed, and thinking of the experience of working inside a CPU and before completely the thought of, Well it's only 10 buck… he said, "But these models over here at the end are completely build for $50." What? Only $50.. Ok, I'm gonna get one, but he interrupts my thoughts again, "Or you can get 2 for $80" So, thinking rapidly, Oo I could use one for a desktop and one as a file server.. Sold
Comes with no OS, completely cleaned out. After I loaded up the car and went back to class, I was thinking of all the extras I need and what to bid on ebay. Then I went back downstairs, thinking well, I should at least try to find some of the accessories I need.
"I'm back" I announced. "I need accessories, how much are the keyboards?"
"$1"
"Mouse?"
"$2"
"Power cords?"
"You have to go through that box in the back row"
So, I went through it, found 2 power cords, 2 printer cords, 2 monitor cords, and ethernet cable.
"Ok, how much for these cords and cables?"
"Um….I'll give em to ya for $1"
So, I got two keyboards, mouse, and cords for $5.
They didn't give up monitors, but that's ok, I have an extra at home. Plug everything in, start it up, and I my monitor is acting all weird. I bet my son did something to it. It's been in my closet for months. Before I pickup BJ, I better try to find a monitor at the pawn shop. Got a decent Panasonic for $25 and I was good to go.
Get home, hook it up, and the regular "no boot disk…restart with boot disk" warnings came up so I'm ready to roll. I have to find a good LinuxOS. The last thing I want to do is waste money on proprietary software with 2004 CPUs. I'm just happy I have two 80GB of storage to add stuff. Something is wrong with my DVD-Rom drive on my laptop, (BEEEEJAAAY), so I can't create an image CD for Ubuntu or other LinuxOS systems, so I just had to order from Amazon for 1cent and wait. Once I add the OS and the CPUs to my wireless network, I can begin the Twilight Hack for the Wii, then I will be satisfied with my home network.
Then I remember posting a funny comment to Chris Pirillo about "FreeNAS" because I said, "You're gonna have NAS fans thinking he got locked up, and is now free. Ha"
http://ping.fm/4VguT
Wednesday, March 4, 2009
Tuesday, March 3, 2009
Sunday, March 1, 2009
Saturday, February 28, 2009
Friday, February 27, 2009
Thursday, February 26, 2009
Wednesday, February 25, 2009
Monday, February 23, 2009
Saturday, February 21, 2009
Friday, February 20, 2009
bling_bling_browser
Bling,
Bling for your Web Browser
Bling, Bling for Your Web Browser
Google
Chrome Security Issues: Style vs. Safety
By
Philena
Rush
Introduction
to Scripting and Database with Lab
DeVry:
Comp230 Security Research Paper
February 20, 2009
Table of
Figures
Figure 1 Tech Terms Searched Dec.
08 2
Figure 2 Task Manager: Local
Processing Example 5
Figure 3 Error Image in Vista &
Google Chrome 6
Table of Contents
Table of Figures i
Introduction 1
Web browser
Security Issues 2
Updates and
Patches 3
Cross Site
Scripting (XSS) 4
No browser is perfect 6
Password
Security 7
Future Problems 7
Third party
extensions 8
Conclusions 9
References 10
Introduction
Google Chrome is
Google’s newest application that was build for streamlining
complex web applications for simplicity, safety, and speed. (Google)
I've been experimenting with Google Chrome for almost 4 months now,
and love the speed. But does this speed cause security risks? This
paper will explore the many features of Google Chrome and discuss
these new trends of web development. These comparisons will also
examine common security issues and how Google Chrome handles them.
Web browser Security Issues
Many users have
experience malicious software some time or another. Usually after
losing important data, or having your computer completely locked down
due to a pop-up ad to...”How I made $10,000 in 10 days!"
and next thing you know, your browser and computer is rendered
useless. Brett Burney from the Legal Tech newsletter agrees,
stating: “We've
all been warned that simply visiting a Web site can immediately
compromise the security of our computer -- along with the
confidential data that it stores.”
(Burney, 2009) The default
settings for web browsers are Javascript enable. The problem with
malicious scripts is browsers cannot tell the difference between
scripts generated by the website versus scripts generated by users,
for example, comments on a blog or a forum. Google Chrome has been a
popular topic and search team recently posted in eWeek, (Figure 1)
Figure
1 Tech Terms Searched
Dec. 08
Note:
From eWeek "In Search Of…" eWeek (2009),
volume 26 (1), p. 13-13.
Updates and Patches
With new patches and
versions to address these security issues, our web browsers need to
be consistently updated. Not long ago, updates needed to be done
manually, or you had to create your own script to check for updates.
But many programs come with auto-updates build in the application.
“Another
interesting concept is Chrome's virtual JavaScript machine, called
V8. Google's Chromium team built its own virtual environment for all
JavaScript execution.”
(Grimes, 2009) The Chief Information Officer’s community
and website has written numerous articles and white papers about the
Google chrome because of its innovative team up with Chromium.
(Chromium) Since Chromium has come up with their
own virtual Javascript machine, this minimizes the risk of malicious
scripts being executed.
Cross Site Scripting
(XSS)
When you surf a
site, a common attack is cross site scripting. JavaScripts are
scripts for the user interface to extract information about user's
activity from browser cookies and the information is used for related
links, content or events. You get an email notification from a social
network like Myspace and Facebook, and you click on the link and it
looks just like the site. Unfortunately, you may not notice the URL
of the network is slightly different or extremely long compared to
your regular reference link to check messages. Once you enter
personal information on these “phishing” sites, malicious
script now has your login information, and if it's a financial
company like Paypal, they can begin using your account information to
make thousands of dollars worth of purchases in less than 60 seconds.
Google came up with
a different solution called the sandbox. The new IE browser 8 beta
version, also has similar capacities. (Fierce, 2009)
Sylvain from the Google Chrome Browser website explains the sandbox
as follows: “If
an attacker is able to exploit the browser in a way that lets him run
arbitrary code on the machine, the sandbox would help prevent this
code from causing damage to the system. The sandbox would also help
prevent this exploit from modifying and even reading your files or
any information on the system”
(Sylvain, 2008)
In other words, the
sandbox is like a separator for website processes. If you go to your
Task Manager (Figure 2), you can click on the processes tab, look at
each application you have running on your computer, and how much
memory the processes are using. What Google chrome does differently
is separating all of these processes in their own sandbox, like the
URL bar, tabs, access tokens, plugins, etc. Then Chrome will share
the common processes between websites which will increase the browser
speed and add extra security.
Figure
2 Task Manager: Local
Processing Example
The more javascript
on a website, the more local processing is required to load the page.
That's why many dynamic websites that have javascript takes longer
to load.
This will prevent an
attacker from going any further than the original application its
hiding under. Because according to Google chrome, it's already in
its own sandbox. Once I do have a process go down, I have the
familiar image of a dead puzzle piece on my Vista (Figure 3), but
only for that tab. Other tabs that are open within the browser are
not affected, while with other browsers, the whole application could
freeze up.
.
Figure
3 Error Image in Vista &
Google Chrome
No browser is perfect
But even with the
sandbox, Google Chrome doesn't have robust security options. And I'm
use to my Firefox adblocker, which increases the speed of firefox
browser by blocking scripts. Chrome does not give you the option to
disable Javascript like other browsers. The primary reason Google
doesn't condone disabling scripts is because that is their primary
source of revenue, Google Adsense and Adwords. While looking at
YouTube videos of my favorite computer geeks, I found a comment about
this issue, and it was suggested to use privoxy. Privoxy is a web
proxy that acts as my adblocker for Google Chrome. I was very happy
it works with Google Chrome, because now the speed is increased even
more with the sandbox. Now you can compare the two browsers with an
adblocker on both of them, and Google chrome still comes out on top.
Even without additional plug-ins. (JunkBusters)
“Sites
you visit during a private session generally won't be able to access
cookies, history, or other browser data created or saved before you
entered the session” (Larkin,
2008)
p. 50
Incognito mode
is a feature of Google Chrome that offers these features as many
other web browsers. I would definitely use the Incognito mode in
public access terminals. For example, I'm surfing the web at my
local public library, and using IE to check my emails and check my
social network status. Usually, I'm asked if I would like to "save
my password" of course, I always check, “Not now”,
or “never”. But if I was in a private session, I don't
have to worry about this issue. Larkins in the PC World article,
also realize that private web sessions can be considered misleading
because an average user may see this feature as an added security
stating: “Just keep in mind that they're not a panacea, and
that they're for secrecy, not additional safety”
(Larkin, 2008) p.50. The security this may add is for a
multi-users network to prevent seeing each other private information,
especially if users use the same computer like home networks. You
may also install Google Chrome without requiring Administrator-level
access. (Metz, 2008)
Password Security
You can't protect
the password manager like other browsers.
“Chrome allows the current user to reveal
the saved log-on names and passwords in plaintext with a few clicks
of the mouse” (Grimes,
2009).
At first, I thought this feature was very cool, especially when using
another browser and you may forget a password, or need to have text
file for passwords. Hopefully, Google will see this oversight and
let users secure their passwords. This may be overconfidence on
Google's security features. But this doesn't prevent someone copying
your info once you walk away from the computer.
Future Problems
There are many sites
I cannot access with Google Chrome. An example, of course, is the
DevryU website. There are other know issues that the Google support
(Team) knows about. Here are some of their
security flaws:
Google Chrome
does not support SSL client authentication
Does
not support the embedding of ActiveX
controls (I can't use Microsoft Outlook module for Igoogle in
chrome)
Google Chrome
doesn't work with NTLM authentication
Third party extensions
Google is starting
registration for developers to create extensions for Google Chrome.
Since Google used Chromium, they have strict guidelines for
extensions. “Extension components will typically be
implemented using web technologies like HTML, JavaScript and CSS with
a few extra extension APIs that we design. Extensions will run in
their own origin, separate from any web content, and will run in
their own process”. (Chromium) Some of
their requirements for security include:
It must not be possible for third-party code to get access to
privileged APIs because of the extension system.
Extensions
should be given only the privileges they require, not everything by
default.
Extensions
should run in sandboxed processes so that if they are compromised,
they can't access the local machine.
It
should be trivial for authors to support secure auto-updates for
extensions.
We must be able to blacklist extensions across all Chromium
installations.
Conclusions
Google Chrome a
great browser for social networking and streaming media. But without
added security features, and expansions of utilities with 3rd-party
development, the Google chrome browser still needs a lot of work, as
its recent development for Mac’s OS and Linux, are recent
releases, it is not recommended to make it your default browser until
you know what you’re doing. Remember, Google Chrome is still in
beta, and it may take months, or even years, for a stable release.
Incognito mode is recommended with multi-user workstations and shared
computers. Finally, I recommend a proxy should be used “Under
the Hood” of Chrome’s browser management settings to
prevent malicious scripting activities.
References
Burney, B. (2009,
February 10). Can Google Chrome Power Your Browser? Retrieved
February 10, 2009, from Legal Tech Newsletter:
http://www.law.com/jsp/legaltechnology/pubArticleLT.jsp?id=1202428125776&pos=ataglance
Chromium. (n.d.).
Extensions. Retrieved February 15, 2009, from Chromium
Development Documentation:
http://dev.chromium.org/developers/design-documents/extensions
eWeek. (2009). In
Search Of... eWeek , 26 (1), 13-13. From Database ESBCO
# 36025648
Fierce, D. (2009,
January 27). Internet Explorer 8 RC1 Released. Retrieved
February 10, 2009, from Efluxmedia:
http://www.efluxmedia.com/news_Internet_Explorer_8_RC1_Released_33967.html
Google. (n.d.). Google
Chrome. Retrieved February 15, 2008, from Google:
http://www.google.com/chrome
Grimes, R. A. (2009,
January 26). How Secure is Google Chrome? Retrieved February
10, 2009, from CIO:
http://www.cio.com/article/477895/How_Secure_is_Google_Chrome_
JunkBusters, I.
(n.d.). Privoxy. Retrieved December 2008, from Privoxy:
http://www.privoxy.org
Larkin, E. (2008,
December). How Private--or Secure--Is So-Called Private Browsing? PC
World , 26 (12), pp. 50-50. From Database ESBCO #
35200700
Metz, R. (2008,
September 5). Google's Chrome Browser Prompts Privacy Concerns.
Retrieved February 10, 2009, from Associated Press:
http://www.law.com/jsp/legaltechnology/pubArticleLT.jsp?id=1202425790725
Sylvain, N. (2008, 10
2). A new approach to browser security: the Google Chrome Sandbox.
Retrieved February 10, 2009, from Google Chrome Browser:
http://google-chrome-browser.com/new-approach-browser-security-google-chrome-sandbox
Team, G. C. (n.d.).
Known Issues. Retrieved February 10, 2009, from Google Chrome
Help:
http://www.google.com/support/chrome/bin/static.py?page=known_issues.cs
Thursday, February 19, 2009
Wednesday, February 18, 2009
Monday, February 16, 2009
President's Day Salute
Sunday, February 15, 2009
Saturday, February 14, 2009
Thursday, February 12, 2009
Wednesday, February 11, 2009
Tuesday, February 10, 2009
Friday, February 6, 2009
Thursday, February 5, 2009
Wednesday, February 4, 2009
Tuesday, February 3, 2009
Monday, February 2, 2009
Sunday, February 1, 2009
Saturday, January 31, 2009
Friday, January 30, 2009
Thursday, January 29, 2009
Wednesday, January 28, 2009
Saturday, January 24, 2009
Friday, January 23, 2009
Thursday, January 22, 2009
Wednesday, January 21, 2009
Tuesday, January 20, 2009
Monday, January 19, 2009
Sunday, January 18, 2009
Money matters improve
Well, it should, I haven’t had a chance to spend too much. With this weather you stand indoors for awhile.
Ideas.
Hmm.. I have an idea for a google gadget, but I still have to work on my XML skills.
Visionary.
I had a vision of doing something really important in a dream, but now I can’t remember. It should come to me like devaju.
Good day for business.
Time to update my status for the Just Lose it Contest.
Be generous.
I do feel good about being the meaning of my name.
Romance shaky.
That figures, I’m not a romantic type, and definitely not in the mood today.
Honesty in communication is important
I haven’t lost weight yet, only inches. I tend to gain muscle pretty quickly, so it’s not so bad right now.
Saturday, January 17, 2009
January 17) Contemplation and meditation.
Mental strength.
Perfect for finishing assignments.
Insight.
And finish them quickly.
Distractions at work.
Hope I don’t surf too much today.
Need for patience.
I have been a little impatient with weight loss lately.
Relax.
Great, I’ve been tense this week.
Avoid emotional confrontations.
Ok, I will not give my 2cents to a friend, and let it go.
Friday, January 16, 2009
Thursday, January 15, 2009
Sunday, January 11, 2009
Saturday, January 10, 2009
Great week, but weekend sucks
This weekend is not going the way I wanted to though. I'm having some technical issues for school, and it's really frustrating. So much in fact, that I'm in a bad mood. Can't get out of this funk, because this problem has been ongoing for the past three days. I will get back into the swing of things, and try to pull an allnighter with my readings and study. I'm falling behind on making appointments as well (personal not business) and I have to get things together. My son has way to much energy today and getting into things, so that doesn't help my mood.
It's very slippery outside, so driving in those conditions on a weekend is not what I call fun, no matter how much I want to get out. *sigh*
Also having problems with an order from ebay, and the seller is not responding. I hope I haven't been had.
So much to do.. so little time. Don't you hate those moments, even though time has not changed, you let things get kinda crazy at the last minute, and you do you best, but your mood can make it better or worse.
http://philena.biz