Victor's Blog about the Web, Security and Life

The web for me is a hobby where standards and best practices are daily bread. Security is a concern that everybody must be aware of its details for IT in general, and the web in particular, to be a safer place. My life, on the other hand, is that of a regular Lebanese citizen where politics and social issues are discussed on a daily basis. I hope you enjoy reading my blog and make sure to drop me a comment about any topic you find interesting.

Bird Flu Abuse: A Broken Trust Chain Problem

Printable Version

victor | 10 February, 2006 19:20

As the bird flu problem gets closer and closer to Lebanon, I have been informed of some people making use of the safeless state that people are going through to achieve success in other illegal actions such as theft, drug abuse, rapes, etc.

This message is of two parts:

The first is humanitarian and simply asks you NOT to open the door to anyone who claims to be from the Ministry of Health in Lebanon to give you Bird Flu vacancies. These people simply drug victims and rob appartments!

The second part is related to security and serves as a valid up-to-date example of how a broken trust-chain can be misused by criminals. In this type of security attacks, criminals are pretending to be from the Ministry of Health. People, driven by the search for being safe of this lethal disease, simply forget to ask for a proof of authenticity. The "doctor" simply goes in, takes out a needle, puts some "trojaned-drug" in it, and "vaccinates" the victim. Trojaned because the drug that is supposed to protect from Bird Flu is actually putting the victim into a deep sleep.

In this simple example, while taking into consideration how tragic the result can be, we find a simple proof of how broken trust chains can be easily used to bypass authenticity.

A lesson to the Lebanese Government, in general, and to the Ministry of Health, in particular, from this fact is that the minimum required proof of authenticity is to have an identity card (Yes a simple card similar to the ones that the Police use in Western Movies, it is that simple I know ;). This identity card must show the picture, name and job title of the person working for the ministry. A stamp, as well, must be provided as a proof of trust.

Firefox Replies Back

Printable Version

victor | 02 February, 2006 10:44

In reply to Internet Explorer having a hidden egg related to Mozilla, the Firefox team introduced an egg into Mozilla as a reply.

To check these in sequence, do the following:

In Internet Explorer: type About:Mozilla in the Address Bar and you will get the blue screen.
In Mozilla Firefox: type About:Mozilla and you will get a verse from the book of Mozilla.

The cold war is back ;)
 
Accessible and Valid XHTML 1.0 Strict and CSS