<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kyle Brady:  Blog &#187; Security</title>
	<atom:link href="http://www.kyle-brady.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kyle-brady.com</link>
	<description>coherent thoughts on diverse topics</description>
	<lastBuildDate>Thu, 18 Mar 2010 21:07:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<atom:link rel='hub' href='http://www.kyle-brady.com/?pushpress=hub'/>
<cloud domain='www.kyle-brady.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>MediaTemple&#8217;s Continued Inadequacy Issues &#91;Expose&#93;</title>
		<link>http://www.kyle-brady.com/2009/11/26/mediatemples-continued-inadequacy-issues/</link>
		<comments>http://www.kyle-brady.com/2009/11/26/mediatemples-continued-inadequacy-issues/#comments</comments>
		<pubDate>Thu, 26 Nov 2009 23:36:02 +0000</pubDate>
		<dc:creator>Kyle Brady</dc:creator>
				<category><![CDATA[Expose]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Failure]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[Hosting]]></category>
		<category><![CDATA[MediaTemple]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.kyle-brady.com/?p=5192</guid>
		<description><![CDATA[[note:  substantial and important updates available]

Almost a month ago, I made MediaTemple, and the world, aware of an attack that seemed to be a large security issue, and they eventually admitted it was their problem to deal with, rather than blaming it on software like hosting companies like to do.  But, weeks later, the problem [...]]]></description>
			<content:encoded><![CDATA[<strong><em>[note:  <a href="#updates">substantial and important updates available</a>]</em></strong><br />
<br />
<a href="http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/">Almost a month ago, I made MediaTemple, and the world, aware of an attack</a> that seemed to be a large security issue, and they eventually admitted it was their problem to deal with, rather than blaming it on software like hosting companies like to do.  But, weeks later, the problem is not yet resolved, and the public is largely still in the dark.<br />
<br />
In the last week, I’ve been notified twice to change my FTP/SSH passwords, and the request yesterday came with an odd statement:  the passwords had been previously stored as plaintext, rather than being encrypted or hashed, and that the attackers somehow had access to this - this was MediaTemple’s sole explanation of the massive security issue.<br />
<br />
Entirely unacceptable.<br />
<br />
After initially making this issue public, <a href="http://www.kyle-brady.com/2009/11/07/wordpress-mediatemple-and-an-injection-attack/">both here</a> and <a href="http://www.inquisitr.com/47860/the-epic-wordpress-mediatemple-failure/">at the Inquisitr</a>, I received a phone call from Andrew Won (VP of Customer Service) and Chris, whose position I can’t remember, on 11/16/2009 saying that they discovered the issue, had patched the necessary software, and had submitted patches to the software’s vendors – but asked me to not say anything because of the “security process”.  They didn’t give me enough details as to what was actually happening for me to matter, but I kept quiet.<br />
<br />
The traffic on my blog, and the comments, continued to mount in the days that followed and it became clear that the issue had not been resolved – people were still being hit with this hack/attack.  On 11/19/2009 I asked for an update from Andrew and received a reply stating:<br />
<blockquote>Unfortunately, we still don't have anything public yet.  We have already resolved all of the issues and this issue will not recur.</blockquote><br />
Well, as the attacks continued for other people’s accounts, even through today (11/26/2009), it’s obvious that they had not resolved the issue.  When I irately called late last night (11/26/2009 early morning PST), the tech had no answers and neither did his supervisor – in fact, I knew more about the situation than they did, and I was given the partyline:  “our engineers are aware of the issue and working to address it.”  Further conversation with Andrew, via email, resulted in nothing but doublespeak and sidestepping my questions.<br />
<br />
It’s obvious, at this point, that they are either incompetent or lazy – I’m not sure which.  They were slow to respond to this in the first place, and have made one misstep after another, which isn’t giving the affected customers much faith in their hosting company, let alone those unaffected that hear the horror stories.  The fact that passwords were stored in such an insecure way might be part of the issue, but there are larger problems:  discovery, point of entry, depth of access, and execution – none of which (mt) is, in any way, addressing.<br />
<br />
When I mentioned this to Andrew, he responded by effectively saying they still have no idea what the problem is or how to fix it:<br />
<blockquote>We are still in the process of investigating this.  Unfortunately, while we have a lot of theories and assumptions, we still do not have anything definitive.  So please bear with us while we investigate this.  We are taking all precautionary measures and locking down many external and internal systems.  We will continue to closely monitor our systems and take appropriate actions.</blockquote><br />
And they even want to dispute the fact that it’s been almost a month, while downplaying the large number of customers affected:<br />
<blockquote>It was not a matter of resolving over the period of 3 weeks.  It was a matter of continuing to take steps, monitor and then take further steps.  The number of sites actually affected is very small, but due to recent events, we decided that we needed to take a more blanket security approach and change all (gs) Grid Service Server Admin passwords as a precautionary measure.</blockquote><br />
The “security protocol”, mentioned above, is essentially a “don’t talk about it until it’s fixed” process, but it assumes that those involved are actually <em>trying</em> to fix it, and (mt) is using this as both a crutch and deflector shield – in addition to assuming unaware customers are happier than aware ones:<br />
<blockquote>Chris and I advised you of security protocol, which is what we were following.  And security protocol states that you do not publish public info until you are absolutely certain that the issue is resolved and that you are reasonably certain that the attacks or hacks have stopped.<br />
<br />
We didn't have much choice in this matter.  As we explained to you before, security is a very sensitive issue and by making information public, you are also feeding information to your attackers.  We also alerted all affected sites and accounts of the issue and informed them of the steps that we have taken at the moment and time.  This issue was still evolving when we last spoke.</blockquote><br />
Finally, when asked about compensation to customers for their utter failure as a semi-secure hosting company, which they haven’t actually fixed yet, Andrew once again sidesteps the issue by choosing to blame the users/customers instead of themselves:<br />
<blockquote>We do encrypt passwords, but there was a separate file that was kept for the purpose of allowing customers to view their FTP and mySQL passwords through their Account Center.  This was a feature many customers asked for in the past.  However, we have decided that this feature comes at a price and we are no longer willing to take that risk.  Yes, we have learned our lesson.  We definitely do understand that this was  a headache for ours customers, it was a huge one for us, so we can only imagine it was a much bigger for our customers.  We will make sure to discuss a concession of some sort for those customers that were actually affected by this issue.</blockquote><br />
In summary:<br />
<ul><br />
	<li>these attacks are the result of MediaTemple’s failure as a hosting company</li><br />
	<li>they chose to wait three weeks to even address the issue publicly</li><br />
	<li>they claimed to have solved the issue long ago, when they hadn’t</li><br />
	<li>they still haven’t solved the security issue, three-or-more weeks on</li><br />
	<li>they continue to not reveal any details to users, while sidestepping most questions</li><br />
	<li>they seem to have no idea of what is truly occurring</li><br />
</ul><br />
They’re going to lose alot of customers over this, especially since they are known for having large-scale problems on a regular basis.<br />
<br />
--- --- ---<br />
<a name="updates"></a><br />
<strong>Update (11/26/2009 5:30pm PST):</strong> I had a lengthy phone conversation with Andrew, and while I can't comment on the details, I feel more confident in MediaTemple's abilities and in what they're doing to solve this large security issue.  More concrete details as they come, but I would suggest that we have more patience with (mt) on this.<br />
<br />
<strong>Update (11/30/2009 4:35pm PST):</strong> MediaTemple is <a href="http://weblog.mediatemple.net/weblog/category/system-incidents/1026-gs-security-advisory/">slowly opening up about this</a>, although the full story doesn't seem to be public yet.  Details as/if they come.]]></content:encoded>
			<wfw:commentRss>http://www.kyle-brady.com/2009/11/26/mediatemples-continued-inadequacy-issues/feed/</wfw:commentRss>
		<slash:comments>21</slash:comments>
		</item>
		<item>
		<title>&#8220;The Epic Wordpress + MediaTemple Failure&#8221; &#91;Self&#93;</title>
		<link>http://www.kyle-brady.com/2009/11/15/the-epic-wordpress-mediatemple-failure/</link>
		<comments>http://www.kyle-brady.com/2009/11/15/the-epic-wordpress-mediatemple-failure/#comments</comments>
		<pubDate>Sun, 15 Nov 2009 21:57:46 +0000</pubDate>
		<dc:creator>Kyle Brady</dc:creator>
				<category><![CDATA[Self]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[MediaTemple]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://www.kyle-brady.com/?p=5147</guid>
		<description><![CDATA[New column at the Inquisitr:
If there’s a security issue floating around, you’d imagine that those behind the problem would be extremely interested in fixing it as soon as possible… right?  Well, apparently not.
Go check it out.]]></description>
			<content:encoded><![CDATA[New column <a href="http://www.inquisitr.com/47860/the-epic-wordpress-mediatemple-failure/">at <em>the Inquisitr</em></a>:<br />
<blockquote>If there’s a security issue floating around, you’d imagine that those behind the problem would be extremely interested in fixing it as soon as possible… right?  Well, apparently not.</blockquote><br />
<a href="http://www.inquisitr.com/47860/the-epic-wordpress-mediatemple-failure/">Go check it out</a>.]]></content:encoded>
			<wfw:commentRss>http://www.kyle-brady.com/2009/11/15/the-epic-wordpress-mediatemple-failure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SJSU Mass Email Failure &#91;Expose&#93;</title>
		<link>http://www.kyle-brady.com/2009/08/21/sjsu-mass-email-failure/</link>
		<comments>http://www.kyle-brady.com/2009/08/21/sjsu-mass-email-failure/#comments</comments>
		<pubDate>Fri, 21 Aug 2009 07:13:41 +0000</pubDate>
		<dc:creator>Kyle Brady</dc:creator>
				<category><![CDATA[Expose]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SJSU]]></category>

		<guid isPermaLink="false">http://www.kyle-brady.com/?p=3627</guid>
		<description><![CDATA[Alternative title:  "How to Publicize 17,000 Private Email Addresses"

Earlier today, I received an email from "Tameka N. Harris" regarding parking permits at San Jose State University for the upcoming semester.  It wouldn't have been an interesting email except for a minor detail:

There were 400 email addresses in the "To:" field, including mine.

Note that it was [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><em>Alternative title:  "How to Publicize 17,000 Private Email Addresses"</em></p><br />
<br />
Earlier today, I received an email from <a href="mailto:Tameka.Harris@sjsu.edu">"Tameka N. Harris"</a> regarding parking permits at <a href="http://www.sjsu.edu">San Jose State University</a> for the upcoming semester.  It wouldn't have been an interesting email except for a minor detail:<br />
<br />
<strong>There were 400 email addresses in the "To:" field, including mine.</strong><br />
<br />
Note that it was an actual email, instead of  an anonymized message through the PeopleSoft-based system that hides any and all email addresses, usually used for such mass-communication.<br />
<br />
After speaking with a friend, who had 700 separate and unique email addresses on his receipt, I discovered it's likely this was a mass email to the entire student body - <strong>over 17,000 people, all with email addresses exposed to each other.</strong><br />
<br />
I responded to the original, 400-person email in "Reply All" fashion, saying:<br />
<blockquote>I would just like to point out to everyone on this list that Tameka N. Harris, the Almighty Beloved of SJSU Parking Services, has exposed your email address to the world, along with hundreds others, all because she couldn't figure out how to use the "BCC:" email property instead of "TO:".<br />
<br />
That's how I'm able to email all of you.<br />
<br />
Way to go, Tameka.</blockquote><br />
I intended, and tried, to email those on my friend's list, but Google prevented me from doing so, and accused me of spamming.  Fair enough.<br />
<br />
It's important to note just how unacceptable such a huge breach of student privacy this is, not to mention the gross administrative ignorance by both Tameka and SJSU - has she never used email before?   "Irresponsible, outrageous, and unintelligent" only begins to describe the situation.<br />
<br />
Her original email, which wasn't worth such a mass-mailing,  is unedited as follows:<br />
<br />
<em>(note:  the email has more color and formatting than <a href="http://www.wordpress.org">Wordpress</a> allowed me to copy-and-paste)</em><br />
<blockquote><span style="font-size: small;"><strong>Please conserve: Think before you print this e-mail.</strong></span><br />
<br />
<span style="font-family: PalatinoLinotype-Bold; color: blue; font-size: large;"><strong>IMPORTANT PARKING NOTICE</strong></span><br />
<span style="font-family: PalatinoLinotype-Bold; color: red; font-size: medium;"><strong>BEWARE: Limited Parking and Heavy Traffic</strong></span><br />
<span style="font-family: PalatinoLinotype-Roman; font-size: small;">During the first few weeks of instruction, traffic is unusually heavy and finding parking is difficult! Please plan accordingly and consider using SJSU Park &amp; Ride or your VTA EcoPass for public transportation. Throughout the semester, the parking garages usually fill to capacity prior to 9:00 am and remain full past noon. </span><span style="font-family: PalatinoLinotype-Bold; font-size: small;"><strong>UPD Officers provide traffic control during the beginning</strong></span><span style="font-family: PalatinoLinotype-Roman; font-size: small;"> </span><span style="font-family: PalatinoLinotype-Bold; font-size: small;"><strong>of each semester. It is important for the safety of everyone that you follow their directions!</strong></span><br />
<br />
<span style="font-family: PalatinoLinotype-Bold; color: red; font-size: small;"><strong>THERE IS NO GRACE PERIOD</strong></span><br />
<span style="font-family: PalatinoLinotype-Roman; font-size: small;">A valid parking permit is required at all times, including the first day of classes.  Parking rules are enforced 24 hours a day/7 days a week. Possession of a permit does not guarantee a space in the main campus garages.  <span style="text-decoration: underline;">Space is always available at the “Park &amp; Ride Lot”</span>.  <strong>There is <span style="text-decoration: underline;">NO</span> free parking on the Main Campus</strong>.</span><br />
<br />
<span style="font-family: PalatinoLinotype-Bold; font-size: small;"><strong>Avoid traffic and parking frustration…</strong></span><br />
<span style="font-family: PalatinoLinotype-Bold; font-size: large;"><strong>Use SJSU PARK &amp; RIDE LOT!</strong></span><br />
<span style="font-family: PalatinoLinotype-Bold; font-size: medium;"><strong><span style="text-decoration: underline;">Only</span> the “Park &amp; Ride Lot” offers </strong></span><span style="font-family: PalatinoLinotype-Bold; color: red; font-size: medium;"><strong>free </strong></span><span style="font-family: PalatinoLinotype-Bold; font-size: medium;"><strong>parking the beginning of each semester (August 24- Sept 3, 2009).</strong></span><br />
<span style="font-family: PalatinoLinotype-Bold; color: red; font-size: small;"><strong>Free </strong></span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">parking is <span style="text-decoration: underline;">only</span> available at the “</span><span style="font-family: PalatinoLinotype-Bold; font-size: small;"><strong>Park &amp; Ride Lot” </strong></span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">August 24 – September 3, 2009. The “Park &amp; Ride Lot” is located 8 blocks south of the main campus on South 7th Street at Humboldt Street across from Spartan Stadium. The parking rate is $4.00 per day (or $96.00 for a semester Park &amp;</span><br />
<span style="font-family: PalatinoLinotype-Roman; font-size: small;">Ride Permit). </span><span style="font-family: PalatinoLinotype-Bold; font-size: small;"><strong>ALL SJSU permits are valid in the “Park &amp; Ride Lot”</strong></span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">.</span><br />
<span style="font-family: PalatinoLinotype-Bold; color: red; font-size: small;"><strong>Free Park &amp; Ride Shuttle </strong></span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">service is available to campus Monday through Thursday. </span><span style="font-family: PalatinoLinotype-Bold; color: red; font-size: small;"><strong>Free Shuttle Service </strong></span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">begins at 6:30 am and runs every 10 minutes (depending on traffic) until 4:00 pm with stops at Park &amp; Ride, Duncan Hall, MLK Library, Engineering Building and Business Tower. After 4:00 pm, Free Shuttle Service runs every 20 minutes until 10:20 pm with stops at Duncan Hall and Park &amp; Ride only. Shuttle Service is </span><span style="font-family: PalatinoLinotype-Bold; font-size: small;"><strong>not </strong></span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">available Friday through Sunday. </span><br />
<span style="font-family: PalatinoLinotype-Bold; font-size: small;"><strong>All Park &amp; Ride Permits are valid in all student areas on the main campus Friday</strong></span><span style="font-family: PalatinoLinotype-Roman; font-size: small;"> </span><span style="font-family: PalatinoLinotype-Bold; font-size: small;"><strong>through Sunday only.</strong></span><br />
<div><span style="font-family: PalatinoLinotype-Bold; font-size: large;"><strong>DON’T WAIT IN LINE!</strong></span><br />
<span style="font-family: PalatinoLinotype-Bold; color: red; font-size: medium;"><strong>Buy Parking Permits or Pay Citations ON</strong></span><span style="color: red; font-size: medium;"><strong>–</strong></span><span style="font-family: PalatinoLinotype-Bold; color: red; font-size: medium;"><strong>LINE!</strong></span><br />
<span style="font-family: PalatinoLinotype-Bold; color: blue; font-size: large;"><strong><a href="http://www.sjsu.edu/parking" target="_blank">www.sjsu.edu/parking</a></strong></span></div><br />
<span style="font-size: small;">.. </span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">No Additional Fees</span><br />
<span style="font-size: small;">.. </span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">No Lines </span><span style="font-size: small;">– </span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">No Waiting</span><br />
<span style="font-size: small;">.. </span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">Print a temporary permit valid for 10 days</span><br />
<span style="font-size: small;">.. </span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">Fast delivery to your home <span style="text-decoration: underline;">without</span> shipping and handling fees</span><br />
<span style="font-family: PalatinoLinotype-Roman; font-size: small;">A limited supply of Student Semester permits are available at the Student Services Center – Bursar’s Office located on the ground level of the North Garage(South 9th</span><span style="font-family: PalatinoLinotype-Roman; font-size: xx-small;"> </span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">and East San Fernando Streets) (Cash or check ONLY). Please expect long waiting times during the first few weeks of school.</span><br />
<br />
<span style="font-family: PalatinoLinotype-Bold; font-size: small;"><strong>Student 1-day</strong></span><span style="font-size: small;"><strong>–</strong></span><span style="font-family: PalatinoLinotype-Bold; font-size: small;"><strong>a</strong></span><span style="font-size: small;"><strong>–</strong></span><span style="font-family: PalatinoLinotype-Bold; font-size: small;"><strong>week, 2-day-a-week and Park &amp; Ride permits </strong></span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">are available </span><span style="font-family: PalatinoLinotype-Italic; font-size: small;"><em>ONLY </em></span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">at the Parking Services’ Office located in the University Police Department (UPD) building at the South Garage (S. 7th and E. San Salvador Sts.) (Cash or Check ONLY)</span><br />
<span style="font-family: PalatinoLinotype-Bold; font-size: small;"><strong>Daily Permits</strong></span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">: Pay stations are available on the 3</span><span style="font-family: PalatinoLinotype-Roman; font-size: xx-small;">rd </span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">floor and above in the North and South Garages and the 1</span><span style="font-family: PalatinoLinotype-Roman; font-size: xx-small;">st </span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">to 4</span><span style="font-family: PalatinoLinotype-Roman; font-size: xx-small;">th </span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">floors of the West Garage (E. San Salvador and S. 4th Streets).</span><br />
<span style="font-family: PalatinoLinotype-Roman; font-size: small;">Daily Rates:</span><br />
<span style="font-family: PalatinoLinotype-Roman; font-size: small;">Each ½ hour $1</span><br />
<span style="font-family: PalatinoLinotype-Roman; font-size: small;">Maximum Daily Rate $8</span><br />
<span style="font-family: PalatinoLinotype-Roman; font-size: small;">Maximum after 5:30 pm $5</span><br />
<span style="font-family: PalatinoLinotype-Roman; font-size: small;">Overnight parking $10 (Expires 8am next day)</span><br />
<span style="font-family: PalatinoLinotype-Bold; color: red; font-size: small;"><strong>THERE IS NO GRACE PERIOD</strong></span><br />
<span style="font-family: PalatinoLinotype-Roman; font-size: small;">A permit is required at all times including the first day of classes. Parking rules are enforced 24 hours a day/7 days a week. Possession of a permit does not guarantee a space in the main campus garages. Space is always available at the Park &amp; Ride Lot.</span><br />
<span style="font-family: PalatinoLinotype-Roman; font-size: small;">For more information or to review the Parking Rules and Regulations, visit our website: </span><span style="font-family: PalatinoLinotype-Roman; color: blue; font-size: small;"><a href="http://www.sjsu.edu/parking" target="_blank">www.sjsu.edu/parking</a></span><br />
<span style="font-family: PalatinoLinotype-Roman; font-size: small;">(408) 924</span><span style="font-size: small;">–</span><span style="font-family: PalatinoLinotype-Roman; font-size: small;">6556</span><br />
<span style="font-family: PalatinoLinotype-Roman; font-size: x-small;">The latest SJSU Safety 101 Uniform Campus Crime and Security Report is available on</span><span style="font-size: x-small;">–</span><span style="font-family: PalatinoLinotype-Roman; font-size: x-small;">line at </span><span style="font-family: PalatinoLinotype-Roman; color: blue; font-size: x-small;"><a href="http://www.sjsu.edu/safetyreport" target="_blank">www.sjsu.edu/safetyreport</a></span><span style="font-family: PalatinoLinotype-Roman; font-size: x-small;">. A pamphlet can be obtained at the University Police Department (call 408 924</span><span style="font-size: x-small;">–</span><span style="font-family: PalatinoLinotype-Roman; font-size: x-small;">2172 or visit the UPD web site at </span><span style="font-family: PalatinoLinotype-Roman; color: blue; font-size: x-small;"><a href="http://www.sjsu.edu/police" target="_blank">www.sjsu.edu/police</a> </span><span style="font-family: PalatinoLinotype-Roman; font-size: x-small;">for more information.</span></blockquote><br />
This issue <a href="http://www.kyle-brady.com/2009/06/10/how-i-won-a-copyfight/">follows on the heels of the "Beeson Debacle" from two and a half months ago</a> (also at SJSU), which is about to be revived in the first issue of the <a href="http://www.thespartandaily.com/"><em>Spartan Daily</em></a> on Monday - 8/24/2009 - the first day of the Fall Semester.<br />
<br />
Good timing, Tameka.]]></content:encoded>
			<wfw:commentRss>http://www.kyle-brady.com/2009/08/21/sjsu-mass-email-failure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The New Era of Spacecleanup? &#91;Old Content&#93;</title>
		<link>http://www.kyle-brady.com/2009/02/13/the-new-era-of-spacecleanup/</link>
		<comments>http://www.kyle-brady.com/2009/02/13/the-new-era-of-spacecleanup/#comments</comments>
		<pubDate>Fri, 13 Feb 2009 14:44:09 +0000</pubDate>
		<dc:creator>Kyle Brady</dc:creator>
				<category><![CDATA[Old Content]]></category>
		<category><![CDATA[Earth]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Space]]></category>
		<category><![CDATA[Trash]]></category>

		<guid isPermaLink="false">http://www.kyle-brady.com/?p=1320</guid>
		<description><![CDATA[When you're a little, wideyed kid, you hear about space.  You see pictures of the Earth from orbit.  You see pictures from, and of, the Moon, and you're enamored.  For some, life goes on, but for others space remains a thought in the back of your mind to one day show itself via a career [...]]]></description>
			<content:encoded><![CDATA[When you're a little, wideyed kid, you hear about space.  You see pictures of the Earth from orbit.  You see pictures from, and of, the Moon, and you're enamored.  For some, life goes on, but for others space remains a thought in the back of your mind to one day show itself via a career in engineering or physics.<br />
<br />
I'm somewhere between the two.<br />
<br />
But what they don't tell you as a little kid is how cluttered both Low and High Earth Orbits are becoming.  As we've seen, <a href="http://www.cnn.com/2009/TECH/02/12/us.russia.satellite.crash/">collisions in space are far too real</a>, and <a href="http://www.time.com/time/health/article/0,8599,1879241-2,00.html">the "space trash" problem is apparently becoming worse</a>, as more and more people send up devices, sometimes only for testing purposes, that largely get left when their creators are done with them.<br />
<br />
The official story is that the American satellite was a Motorola one, but I'm betting that's, at best, only part of the truth, since any number of government organizations have the option to piggyback on your space hardware.  Put this together with the fact that the Russian satellite's collision came as a surprise, when we supposedly track "all objects larger than a football" in orbit...<br />
<br />
And I think you have a recipe for a new era of spacecleanup.  Maybe "cleanup" isn't the right word, but at a time when satellites are destroying each other and <a href="http://www.cnn.com/2008/TECH/space/02/18/satellite.intercept/index.html">being shot down from Earth</a>, I think our military agencies are going to suddenly care more about the spacetrash orbiting our planet.<br />
<br />
The idea of an automated, or semiautomated, orbit debris cleanup system via robots with manuvering capabilities is not new.  <a href="http://www.newscientist.com/blogs/shortsharpscience/2009/01/low-tech-satellite-subterfuge.html">But the realization that we're fixing our own satellites, and, in all reality, disabling others</a>, <em><span style="text-decoration: underline;">is</span></em> new.  If we can manage to fix and destroy satellites from orbit, then wouldn't creating a dumptruck-like manuverable robot be less difficult?<br />
<br />
I can imagine this trash collector orbiting Earth, selecting which debris is trash (based on human-maintained lists), and scooping up the true trash.  After compacting it, ala <em><a href="http://en.wikipedia.org/wiki/WALL-E">Wall-e</a></em>, it could be sent in a proper trajectory to burn up in the atmosphere.<br />
<br />
--- --- ---<br />
<br />
<strong>Further Information</strong>: For some pictures and video check out the coverage on the Inquisitr <a href="http://www.inquisitr.com/17906/space-crash-us-and-russian-satellites-collide-over-siberia/">[1]</a> <a href="http://www.inquisitr.com/17969/satellite-collision-images/">[2]</a>]]></content:encoded>
			<wfw:commentRss>http://www.kyle-brady.com/2009/02/13/the-new-era-of-spacecleanup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook Re-Design FAIL &#91;Expose&#93;</title>
		<link>http://www.kyle-brady.com/2008/07/26/facebook-re-design-fail/</link>
		<comments>http://www.kyle-brady.com/2008/07/26/facebook-re-design-fail/#comments</comments>
		<pubDate>Sat, 26 Jul 2008 21:02:07 +0000</pubDate>
		<dc:creator>Kyle Brady</dc:creator>
				<category><![CDATA[Expose]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Failure]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.kyle-brady.com/?p=471</guid>
		<description><![CDATA[If you haven't heard or noticed by now, Facebook is in the process (or is finished?) rolling out a redesign of ... pretty much everything.  Check out www.new.facebook.com to activate it.  But I'm not here to analyze it like everyone else, even though I think it's a pretty cool update.

I'm here because they screwed up.

I've [...]]]></description>
			<content:encoded><![CDATA[If you haven't heard or noticed by now, Facebook is in the process (or is finished?) rolling out a redesign of ... pretty much everything.  Check out <a href="http://www.new.facebook.com">www.new.facebook.com</a> to activate it.  But I'm not here to analyze it like everyone else, even though I think it's a pretty cool update.<br />
<br />
I'm here because they <em>screwed up</em>.<br />
<br />
I've been keeping an eye on the "applications" page, because I had a feeling that something was going to happen... and it did.<br />
<p style="text-align: center;"><a href="http://www.kyle-brady.com/wp-content/uploads/2008/07/facebookfail.gif"><img class="aligncenter size-medium wp-image-472" title="facebookfail" src="http://www.kyle-brady.com/wp-content/uploads/2008/07/facebookfail-300x206.gif" alt="" width="300" height="206" /></a><br />
<small>Click, because it's relevant.</small><br />
<p style="text-align: left;">See all the things I've circled in red?  Most of those are applications I've <em>never added</em>.  <strong><span style="text-decoration: underline;">Ever</span></strong>.  And in the case of "Bumper Sticker", "friendbinder", and "Top Friends"... those are ones that were added and removed (before the design change) within a 24 hour period.</p><br />
<p style="text-align: left;"><strong>My first question is:  what the hell?</strong></p><br />
<p style="text-align: left;">Is Facebook just randomly letting applications access my data, and decide that I'm now a "user" of them?  Because, if so, that's not only stupid and wasting my time... but it's also a huge privacy concern.</p><br />
<p style="text-align: left;"><strong>My second question is:  what the hell?</strong></p><br />
<p style="text-align: left;">I've tried to remove ALL of the ones that I circled in the screenshot... they won't go away.  They disappear from my profile, and from some of the settings pages... but remain on others.  Which would lead me to believe they're not really gone, they're just pretending to be.</p><br />
<p style="text-align: left;"><strong>My third question is:  what the hell?</strong></p><br />
<p style="text-align: left;">There have long been rumors that Facebook doesn't actually delete any data, they just "delete" it.  Instead of removal, a field is changed to tell the rendering engine "Hey!  Don't show this!" - which might make sense in some cases, but not as an overall policy.</p><br />
<p style="text-align: left;">This is solid proof that they do exactly what people have been whispering about... besides the whole "delete my account" controversy, of course.</p><br />
<p style="text-align: left;"><strong>My fourth question is:  what the hell?</strong></p><br />
<p style="text-align: left;">I'm actually out of "Items for Hell" at this point.</p><br />
<p style="text-align: left;"><strong>Your Mission</strong></p><br />
<p style="text-align: left;">This needs to be fixed immediately.  Check your applications page, see if you've got anything weird going on.  Send them feedback (using the "send feedback" button... obviously), regardless of whether or not you have this problem... they need to know that many people care about this, and it's <em>kind of a big deal</em>.</p><br />
<p style="text-align: left;">p.s. Yes, I'm still using Vista on <a href="http://www.kyle-brady.com/2008/07/14/my-new-computer/">this computer</a>.  But that's because I haven't gotten <a href="http://www.ubuntu.com">Ubuntu </a>running yet... the RAID-1 array and the supersexy, but "too new", combo optical drive are creating major problems.</p><br />
<p style="text-align: left;">--------------</p><br />
<p style="text-align: left;"><strong>Update (7/28/2008 2:30pm PST):</strong> <a href="http://www.sitepoint.com/articlelist/526">SitePoint blogger Josh Catone</a> (formerly of <a href="http://www.readwriteweb.com">RW/W</a>) picked this up, and <a href="http://www.sitepoint.com/blogs/2008/07/29/did-the-facebook-flub-their-redesign/">wrote his own take on it</a>.</p><br />
<p style="text-align: left;"></p>]]></content:encoded>
			<wfw:commentRss>http://www.kyle-brady.com/2008/07/26/facebook-re-design-fail/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
