<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>kallewoof.com &#187; Security</title>
	<atom:link href="http://kallewoof.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://kallewoof.com</link>
	<description>privacy, democracy, and software</description>
	<lastBuildDate>Wed, 17 Aug 2011 19:34:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Tackling spam.</title>
		<link>http://kallewoof.com/2010/05/25/tackling-spam/</link>
		<comments>http://kallewoof.com/2010/05/25/tackling-spam/#comments</comments>
		<pubDate>Tue, 25 May 2010 06:05:18 +0000</pubDate>
		<dc:creator>Kalle</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Blogs]]></category>
		<category><![CDATA[Future]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://kallewoof.com/?p=479</guid>
		<description><![CDATA[Let&#8217;s face it: the spammers are so sophisticated these days it&#8217;s only a matter of years before they&#8217;re identically copying &#8220;real&#8221; people, &#8220;real&#8221; content. One of the simplest ways of doing this is to simply scan for identical blog entries, &#8230; <a href="http://kallewoof.com/2010/05/25/tackling-spam/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Let&#8217;s face it: the spammers are so sophisticated these days it&#8217;s only a matter of years before they&#8217;re identically copying &#8220;real&#8221; people, &#8220;real&#8221; content.</p>
<p>One of the simplest ways of doing this is to simply scan for identical blog entries, or blogs which focus on specific content. The recipe is simple, and if done right, impossible to detect:</p>
<p>1. Find 2+ blog posts about &#8220;chocolate pudding&#8221;.<br />
2. Grab a random comment from each post.<br />
3. Post each comment as your own user to each other blog, so that each comment appears entirely new, and genuine.<br />
4. Put your spam URL in URL field.</p>
<p>There you have it. The only thing that could spoil you is if you accidentally grab a random comment that itself is spam from somebody else.</p>
<p>The way to combat this is to start <em>ignoring</em> the content of messages. In email, in blog entries, everywhere. We need to just give up on the whole idea. Instead our spam filters look at individual sites point to in URLs provided by said spammers.</p>
<p>Because you know what? These sites look almost exactly today, the way they looked 5, 10 years ago. They&#8217;re identical, because once we&#8217;re &#8220;there&#8221;, we either close the browser or we fall for the trap. It&#8217;s incredibly easy to scan for general spammy crap, like &#8220;viagra&#8221; or &#8220;penis enlargement&#8221; etc. Basically doing it the way it&#8217;s been done all this time so far, but applying it to web sites rather than emails or blog comments.</p>
<p>That&#8217;s all I had to say, really.</p>
]]></content:encoded>
			<wfw:commentRss>http://kallewoof.com/2010/05/25/tackling-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;The characteristics of foreigner criminals visiting Japan.&#8221;</title>
		<link>http://kallewoof.com/2008/09/27/the-characteristics-of-foreigner-criminals-visiting-japan/</link>
		<comments>http://kallewoof.com/2008/09/27/the-characteristics-of-foreigner-criminals-visiting-japan/#comments</comments>
		<pubDate>Sat, 27 Sep 2008 07:31:39 +0000</pubDate>
		<dc:creator>Kalle</dc:creator>
				<category><![CDATA[Democracy]]></category>
		<category><![CDATA[FUD]]></category>
		<category><![CDATA[Japan]]></category>
		<category><![CDATA[Life]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Stupid]]></category>
		<category><![CDATA[Racism]]></category>

		<guid isPermaLink="false">http://kallewoof.com/?p=222</guid>
		<description><![CDATA[&#8220;The characteristics of foreigner criminals visiting Japan.&#8221; (&#8220;来日外国人犯罪の特徴&#8221;) A handbook &#8220;sponsored by the Shizuoka-Ken Head Police Station, the Shizuoka-Ken Association for the Prevention of Crime&#8221; Link to Zone81 blog where this masterpiece is printed in its entirety (though without Japanese &#8230; <a href="http://kallewoof.com/2008/09/27/the-characteristics-of-foreigner-criminals-visiting-japan/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<blockquote><p>&#8220;The characteristics of foreigner criminals visiting Japan.&#8221; (&#8220;来日外国人犯罪の特徴&#8221;)<br />
A handbook &#8220;sponsored by the Shizuoka-Ken Head Police Station, the Shizuoka-Ken Association for the Prevention of Crime&#8221;</p></blockquote>
<p><a href="http://www.zone81.com/arch_news/1030420647324">Link to Zone81 blog where this masterpiece is printed in its entirety</a> (though without Japanese you won&#8217;t get much out of it &#8212; the pictures are fun to look at though).</p>
<p>I&#8217;ve been looking around a lot for some form of confirmation on this one, but my Japanese sort of fails me. What I did find was almost as bad though. Practically every prefecture in Japan has a [prefecturename].go.jp (government dot japan) page which lists &#8220;visiting foreigner criminals/crime in Japan&#8221;, divided into racial heritage with cute little diagrams and such.</p>
<p>Before I came to Japan, I knew it would be one of the few places on earth that I could go to and be &#8220;mistreated&#8221; for being a white male. Not a lot of places where you can get that these days. I knew, and I came here anyway, because I am fascinated by the Japanese language, the people who speak it, their culture, and how they came to be as isolated and &#8220;we vs them&#8221; as they appear from the outside (and from the inside as well, to a great extent). If I had wanted good treatment and smiley faces and chirpy birds, Japan would not have been on my list of places to go.</p>
<p>Some days pass and all I am greeted with is friendliness, openness, a willingness to accept each other as brothers across the world, and such floweriness. Today, as I came home from my test-ride to my potentially new school (was timing it to see when I had to get up in the morning) an old lady walked across the street as I was buying a coke from a &#8230; uh &#8230; jidouhanbaiki (the fuck is that in English?). I looked at her and she looked at me for a sec, and then she nodded and smiled and I nodded and smiled back. I realized that the Japanese are big on greetings. Even if you don&#8217;t know a person, you might nod to them if you end up inadvertently trampling into their bubble &#8212; such as looking at them while they happen to be looking at you. I tend to turn my head away and do my thing in those cases, but I think a Japanese might have nodded or something to acknowledge the other&#8217;s presence.</p>
<p>Then other days I am baffled by the blatant racism and ignorance that permeates this place. Such as the above &#8220;handbook&#8221;. I think part of the problem is that 20% of Japan&#8217;s population are all above 65 years of age. Old people tend to forget about equality and understanding cultural differences and such things. Sadly.</p>
]]></content:encoded>
			<wfw:commentRss>http://kallewoof.com/2008/09/27/the-characteristics-of-foreigner-criminals-visiting-japan/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Sophisticated spam.</title>
		<link>http://kallewoof.com/2008/07/25/sophisticated-spam/</link>
		<comments>http://kallewoof.com/2008/07/25/sophisticated-spam/#comments</comments>
		<pubDate>Sat, 26 Jul 2008 04:05:32 +0000</pubDate>
		<dc:creator>Kalle</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://kallewoof.com/?p=179</guid>
		<description><![CDATA[I must say the spam out there is getting more and more sophisticated. The whole &#8220;this forum&#8221; talk of course tipped me off immediately, but still. This was a comment on my &#8220;Cellphone posting in WordPress&#8221; post on this blog. &#8230; <a href="http://kallewoof.com/2008/07/25/sophisticated-spam/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I must say the spam out there is getting more and more sophisticated. The whole &#8220;this forum&#8221; talk of course tipped me off immediately, but still.</p>
<p>This was a comment on my &#8220;Cellphone posting in WordPress&#8221; post on this blog. I&#8217;ve, of course, removed the spam links since I don&#8217;t want to contribute to spam:</p>
<p>&#8220;Hi everybody<br />
Here’s my first thread on this forum . <img class="wp-smiley" src="../wp-includes/images/smilies/icon_smile.gif" alt=":)" /></p>
<p>I just recently purchased a LG cellphone, and now I need to get some hip hop ring tones for it.</p>
<p>Problem is, I am unsure where to start. There are so many ringtones sites out there and a lot of them come across as rip-offs. How will I know my creditcard won’t be charged for something I don’t want? Is it hassle-free to cancel these services? All I really want is to download some free ringtones.</p>
<p>I’m even willing to pay for some ringtones if the service is good. (removed link) appears to be trustworthy but I have never heard of them. Any tips are appreciated. Also, if anyone know of a trick to save MP3s to ringtones, let me know.</p>
<p>Greetings,<br />
Nikolas&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://kallewoof.com/2008/07/25/sophisticated-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>1024-bit encryption.</title>
		<link>http://kallewoof.com/2007/05/21/1024-bit-encryption/</link>
		<comments>http://kallewoof.com/2007/05/21/1024-bit-encryption/#comments</comments>
		<pubDate>Mon, 21 May 2007 17:40:00 +0000</pubDate>
		<dc:creator>Kalle</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://kallewoof.com/2007/05/21/1024-bit-encryption/</guid>
		<description><![CDATA[http://www.schneier.com/blog/archives/2007/05/307digit_number.html Oops. What did I set my encrypted password wallet to again&#8230;? (Sorry for the &#8220;spam&#8221; btw &#8212; the mechanism for discovering changes hiccoughed when I switched servers so the 10-15 or so last entries were suddenly re-submitted to the &#8230; <a href="http://kallewoof.com/2007/05/21/1024-bit-encryption/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.schneier.com/blog/archives/2007/05/307digit_number.html">http://www.schneier.com/blog/archives/2007/05/307digit_number.html</a></p>
<p>Oops. What did I set my encrypted password wallet to again&#8230;?</p>
<p>(Sorry for the &#8220;spam&#8221; btw &#8212; the mechanism for discovering changes hiccoughed when I switched servers so the 10-15 or so last entries were suddenly re-submitted to the globe.)</p>
]]></content:encoded>
			<wfw:commentRss>http://kallewoof.com/2007/05/21/1024-bit-encryption/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Retarded.</title>
		<link>http://kallewoof.com/2006/08/11/retarded/</link>
		<comments>http://kallewoof.com/2006/08/11/retarded/#comments</comments>
		<pubDate>Fri, 11 Aug 2006 16:23:36 +0000</pubDate>
		<dc:creator>Kalle</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Stupid]]></category>
		<category><![CDATA[Sweden]]></category>

		<guid isPermaLink="false">http://kallewoof.com/?p=59</guid>
		<description><![CDATA[So I got a package sent to me from Japan. My neighbour happens to be Chinese. The parcel itself has some Japanese written on it (which includes Chinese characters). The mail main, despite the fact the envelope says &#8220;Mr. Kalle &#8230; <a href="http://kallewoof.com/2006/08/11/retarded/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>So I got a package sent to me from Japan. My neighbour happens to be Chinese. The parcel itself has some Japanese written on it (which includes Chinese characters). The mail main, despite the fact the envelope says &#8220;Mr. Kalle Alm&#8221; and despite my door says &#8220;K. Alm&#8221;, decides to give the envelope to my neighbour.</p>
<p>Gotta love people who take their job seriously.</p>
]]></content:encoded>
			<wfw:commentRss>http://kallewoof.com/2006/08/11/retarded/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Phone phishing.</title>
		<link>http://kallewoof.com/2006/05/15/phone-phishing/</link>
		<comments>http://kallewoof.com/2006/05/15/phone-phishing/#comments</comments>
		<pubDate>Mon, 15 May 2006 06:37:13 +0000</pubDate>
		<dc:creator>Kalle</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Sweden]]></category>

		<guid isPermaLink="false">http://kallewoof.com/?p=40</guid>
		<description><![CDATA[A few months ago, I got a phone call, to my regular phone, around 9 am (2 hours before I get up normally). Kalle. &#8220;Hello?&#8221; Obviously recorded voice. &#8220;Hi! How&#8217;s it going? [silence] Oh, can&#8217;t complain. Hey&#8230; I just wanted &#8230; <a href="http://kallewoof.com/2006/05/15/phone-phishing/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>A few months ago, I got a phone call, to my regular phone, around 9 am (2 hours before I get up normally).</p>
<p>Kalle. &#8220;Hello?&#8221;<br />
Obviously recorded voice. &#8220;Hi! How&#8217;s it going? [silence] Oh, can&#8217;t complain. Hey&#8230; I just wanted to tell you that I wanna have sex with you.&#8221;<br />
Kalle. &#8220;Eeeeeh&#8230;.?&#8221;<br />
Other end hangs up.</p>
<p>This was a prank call, definitely. But I couldn&#8217;t help shake off the feeling that it was more than just a prank call. Today (in fact, about an hour ago), I got another phone call. Same time. Around 9 am.</p>
<p>Kalle. &#8220;Hello?&#8221;<br />
Other end (in Norwegian). &#8220;Good day. I am calling from the IRS [equiv] in Oslo, in regards to your 3 month stay in Oslo. During this 3 month stay you were employed in Oslo, but did not pay taxes. I have reports here that you are due to pay the IRS [equiv] approximately fifty one thousand [some odd number] crowns [approx $6000US].&#8221; Voice continues to speak.<br />
Kalle &#8220;What the hell are you talking about?&#8221;<br />
Voice continues to speak.<br />
Kalle. &#8220;Hey, hello? That&#8217;s bullshit. I&#8217;ve never been there for 3 months.&#8221;</p>
<p>Eventually, the voice stops. It hasn&#8217;t given me an address or anything for which to pay the sum requested. And it begins again. From the start. Now, the first recording was flawed, obviously. I could hear noise in the background and the voice sounded recorded. This one didn&#8217;t. Had I been to Oslo and worked extra (which, I might add, I bet a lot of Swedes do), I have no doubts I would have bought it. The voice did not mention any dates, which means it could be a month ago or 20 years ago. The only thing that it did fall on was the fact the voice looped.</p>
<p>Why would they do that? Well, here&#8217;s my theory.</p>
<p>1. The first phone call was a simple test. They made a low quality recording and didn&#8217;t rig a lot, and called a select number of people from the phone book and recorded their responses.</p>
<p>2. The second call was a more advanced test &#8212; but still a test. They made a high level, believable recording without making any preparations for actually collecting. I don&#8217;t doubt they will make further &#8220;inquiries&#8221; into this tax issue in the future, with bank account numbers and everything set up for a cozy delivery. The second test definitely succeeded on my sake, and I wish in hindsight I&#8217;d have laughed and told them what a bunch of losers they are for even trying.</p>
<p>One question is, though, why me twice? It would&#8217;ve been far more efficient to call different people during the second test, to get a bigger variety of responses. Though of course the first and second tests are incomparable, and the responses in one don&#8217;t really mean a lot. (And I goofed off during the first, thinking it was a buddy playing a joke on me &#8212; until the phone clicked in my ear.) Unless there are two separate organisations doing this? They&#8217;re obviously going for a mass call-out where, they hope, thousands of Swedes pour their savings out into nothingness in order to save their faces. Or save themselves time behind bars. Tax crimes are crimes too.</p>
<p>But my main question is, how widespread is this kind of stuff elsewhere? Recorded voices aimed at imitating human beings so they can do mass-callouts. Has anyone else been exposed to this kind of stuff? How common is it in other countries?</p>
<p>I&#8217;m definitely curious about it. It&#8217;s not been a common thing here and I wonder if the online phishing &#8220;industry&#8221; has inspired another kind of phishing &#8212; or perhaps its success, for I have no doubt there are plenty of dumbfucks in our world who will buy it, inspired the industry itself to move on and expand.</p>
<p><strong>Update Tue 16th:</strong> Got another phone call. Think it was the #2nd recording again but I was too tired and hung up before giving it too much thought. Damn, I have a new alarm clock.</p>
]]></content:encoded>
			<wfw:commentRss>http://kallewoof.com/2006/05/15/phone-phishing/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>File sharing and such.</title>
		<link>http://kallewoof.com/2006/04/23/file-sharing-and-such/</link>
		<comments>http://kallewoof.com/2006/04/23/file-sharing-and-such/#comments</comments>
		<pubDate>Sat, 22 Apr 2006 23:33:33 +0000</pubDate>
		<dc:creator>Kalle</dc:creator>
				<category><![CDATA[Democracy]]></category>
		<category><![CDATA[FUD]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://kallewoof.com/?p=35</guid>
		<description><![CDATA[Interesting article (found at boingboing). It does make you wonder, though. Personally, I&#8217;m doing surprisingly little piracy compared to most of my friends, and their friends, and theirs, and so on. This has more to do with me using linux &#8230; <a href="http://kallewoof.com/2006/04/23/file-sharing-and-such/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://p2pnet.net/story/8603">Interesting article</a> (found at boingboing). It does make you wonder, though. Personally, I&#8217;m doing surprisingly little piracy compared to most of my friends, and their friends, and theirs, and so on. This has more to do with me using linux since a decade ago than anything else. I do wonder though. Will the entertainment industry and the common man meet at some point, and find a common ground where both benefit from the resolution, where neither party feels compelled to become a criminal. Noone likes being a criminal. But almost everyone is. I&#8217;d like to see comments on this blog from anyone reading it, who has never ever committed software piracy in their lives.</p>
]]></content:encoded>
			<wfw:commentRss>http://kallewoof.com/2006/04/23/file-sharing-and-such/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.583 seconds -->

