You can’t be too careful
- 2007-06-17
-
Write a full post in response to this!
Having a web page is probably the most complex of the ‘simple’ tasks available. The typical process pipeline would begin with DNS, converting a human-friendly name into an IP address, and would be registered through one of the many registrars on the Internet. This IP address would connect, via your ISP’s address block, to your public router or load balancer, routing valid traffic (and only the valid traffic) to the appropriate machine on your network. This machine could be a GNU/Linux box, an embedded device, or an arbitrary, standalone, application that just happens to open a suitable port. This machine relies on the server software and (sometimes) the underlying operating system to determine which files are available to which users.
And at every stage there’s software involved that could be bugged, broken, or suffering planet-sized security flaws. Each configuration file gives an opportunity for human error, opening the holes wider. Every registration service discloses a little more of your private information to the general public. With so many steps involved, is it any wonder that problems exist?
So, there’s a chap in Michigan, let’s just call him “Steve”, who’s into porn. Big time. He likes mature women, black women, and something called “big bubble butt” porn. Whatever that is.
I know his address, phone number, hobbies, the music he likes, and even what his coffee table looks like. This took one step—typing a simple term into Google.
I then typed one piece of information into whois—and I think you all know which this was—and now I have his full name, photograph, work address, and number.
Let’s face it, this was too easy. I’ve done white hat hacking before, and found the security flaws and issues that any self-respecting hacker would know. What is outlined above can found by any self-respecting web surfer without even trying. There’s no attempt on the part of “Steve” to hide it, and as he’s made everything open to the public, it might not even come under computer misuse. It’s akin to looking at his public notice board, rather than breaking down his door to read his diary.
The barrier to entry (pardon the pun) is too low.
So, who’s to blame?
Write a full post in response to this!
Similar articles
Do you like this post?
Vote for it!
Copyright information
This entry is (C) Copyright by its author, 2004-2008. Unless a different license is specified in the entry's body, the following license applies: "Verbatim copying and distribution of this entire article is permitted in any medium without royalty provided this notice is preserved and appropriate attribution information (author, original site, original URL) is included".
Biography
Steven Goodwin: When builders go down to the pub they talk about football. Presumably therefore, when footballers go down to the pub they talk about builders! When Steven Goodwin goes down the pub he doesn’t talk about football. Or builders. He talks about computers. Constantly... He is also known as the angry man of open source. Steven Goodwin a blog that no one reads that, and a beer podcast that no one listens to :)
- Steven Goodwin's posts
- Login or register to post comments
- 1339 reads
- Printer friendly version (unavailable!)




Best voted contents
-
Don't compare GNU/Linux with Windows or MacOS - they are not in the same game
Ryan Cartwright, 2008-07-07 -
GNU/Linux free software tools to preserve your online privacy, anonymity and security
Gary Richmond, 2008-07-07 -
The Bizarre Cathedral - 13
Ryan Cartwright, 2008-07-14 -
Hotwire: a combined terminal/GUI for GNU/Linux
Gary Richmond, 2008-06-24
Similar entries
Buzz authors
All news
Other sites
- The Top 10 Everything (Dave). The good, the bad and the ugly.
- Free Software news (Dave & Bridget). All about free software -- free as in freedom!
- Book Reviews: Illiterarty (Bridget). Book reviews, blogs, and short stories.
Hot topics - last 60 days
-
Don't compare GNU/Linux with Windows or MacOS - they are not in the same game
Ryan Cartwright, 2008-07-07 -
A future without Microsoft
Tony Mobily, 2008-06-08 -
Vienna failed to migrate to GNU/Linux: why?
Tony Mobily, 2008-06-09 -
Free software heroes: from Stallman to Google, a list of inspiring individuals who made everything possible
Tony Mobily, 2008-06-15 -
Do we have a "Vista for Dummies" yet?
Laurie Langham, 2008-07-11
Hot topics - last 21 days
-
Don't compare GNU/Linux with Windows or MacOS - they are not in the same game
Ryan Cartwright, 2008-07-07 -
Do we have a "Vista for Dummies" yet?
Laurie Langham, 2008-07-11 -
The Bizarre Cathedral - 12
Ryan Cartwright, 2008-07-06 -
GNU/Linux free software tools to preserve your online privacy, anonymity and security
Gary Richmond, 2008-07-07
Dedicated server