Friday, April 30, 2010

Terrified by VISA


On many occasions already, I have been "burnt" by one new feature that VISA system is rolling out now: 3DS (3D-Secure). It is also known by name "Verified by VISA".
This feature involves a third-factor authentication - an additional password one should know in order to perform online transactions - but ONLY AT 3DS-ENABLED sites.
Sounds funny, isn't it? Does VISA think that I would 'prefer' to shop at the very sites that give me this nuissance? Here's my recap.
Of the three different sites that had this feature enabled, none of them really worked for me. I opened trouble tickets in all of respective companies' systems.

It took me few rounds to make sure the issue is not pushed into my issuer bank. Obviously, it's easier for a merchant to ask you try contacting your bank - then they don't have to debug the process and interact with different parties themselves.
OK I took that advice - not happy with results though.

The first thing that strikes you as a consumer, that once you enter you card details in a secured merchant's site, once the 3DS-enabled site determines that your card is a subject to that weird security experiment, they redirect you to a third-party site!
Without letting you know what's gonna happen. So, in my case, when I filled the card details and clicked "submit" i was struck by a pop-up window at obscure address (www5.arcot.com) which required me to re-enter my card details PLUS the 3DS password (which I did not have then).

Now, didn't this look exactly like phishing, to my unsuspecting eye?

OK I did some research and found out what that was about. Now, I needed the 3DS password. I called up my bank, and they were able to supply me one.
But still, the system just did not work!

Secondly, why would I need a separate password, when I have my PIN already?!?
Why not use that? Or my online banking password, which would be checked by sending request to my bank, not to a third-party, cloud-based, untrusted-by-me, server.

After some rounds of talking to the parties involved, I decided to
"opt-out" of this 3DS joke and called up my bank to do that.
They were unable to do that, quoting VISA as my contact point.
VISA did not do that favour to me either!

All I could do is switch to my other card. My credit MasterCard.

I am not getting a VISA for me next time.

Thursday, April 22, 2010

iPhone 4G found


I like what I see and I wish they will not re-hash the design just to be original at the intro. I hope Steve jobs will not lose much hair due to the incident.

The new iPhone looks less curved, more metallic, is thinner, has front camera (better be using the new videocall codec I've aspired for!) and ... the style reminds me of a great NOKIA phone, E72.

I am skipping 3GS, going straight for 4G. You?

PS. Cheers to the German beer!

Tuesday, April 13, 2010

Opera strikes a false note

I was an active Opera browser user for about 10 years.
But the time has come for me to stop that practice, and here's why.

To start with, I really like Opera. Or, liked - I should say.
It has pioneered way too many useful features to ignore -

built-in e-mail client with tagging and quick reply (M2)
built-in bookmark sync (Opera Link)
built-in BitTorrent client (although quite limited and slow)
Opera DialPad - replacement for your TV channels
page mini-thumb previews
tabs (yes, way way back before Firefox)
side panes for everything
notes
widgets
Magic Wand - you unobtrusive password helper, even for those site which do not allow to save it
and, lastly, Opera Unite and Opera Turbo (which I don't use)

Opera is a real all-in-one convenience, especially for multiple installations and platforms. It seriously helps achieve unified user experience across separate devices.
I had used it on two PCs, one Mac and two cell phones (S40 and UIQ2.1)
Bookmark sync was a bliss!

But, recent 10.x branch of desktop browser has been less than encouraging.
First off, there's been UI rehash in 10.0 to which one would have to accustom for quite a while. Then, there were some issues with my proxy detection PAC script - while easily processed by IE, it was not always taken well by Opera.
These issues were finally resolved, only to reappear in the latest 10.51.

But Oh, this 10.51 release is something.

The hideous thing is that it installed itself on top of my two 10.10 PC installations! No questions asked, no indication of a process given.
Sneakily and silently it installed itself, so when I reopened a closed Opera browser, the Windows Installer proceeded to set up my user environment and - voila - I had a new shiny un-asked-for release installed.
And guess what - I don't like it.

On one of my PCs, with User Switching enabled, it takes so much time to load. It also makes a simple wake-up operation take up almost 10 minutes with blank screen.
It clearly behaves in a CPU hog manner.
On another PC, it loses connectivity way too often, and I suspect "new and improved" PAC script logic. For instance, taking notebook off the docking station, I am losing Ethernet connection, then I dock it back - and have to restart Opera, because it obviously loses proxy connection, and goes direct.

I hate the new Microsoft-like "O" menu button in the top left.
This is the new Start button for you the netbook generation! :)
Takes one or two clicks more to do same stuff.

Mac version takes too long to start. Although I like the way it scrolls pages.
Smoooth!

So I have taken a look at three more browsers for PC - Apple Safari, Google Chrome, and Mozilla Firefox. And here's what I say.

Apple's Safari was my next turn, obviously, for having it on my Mac.
Once again, I was looking for a unified user experience, a browser I can rely on for both Mac and PC. (I am not using those cell phones anymore)

Safari pros:
- works great on a Mac
- works fast on a PC, too
Safari contras:
- has ugly unnatural looks on PC, trying to achieve mac's look with pc's means
- takes too much space in vertical dimension (three lines for my setup, IE8 takes two)
- bookmark sync is a paid option (mobileme.com costs $100/y)
FAIL (as compared to Opera I'm replacing, and the winner)

Google Chrome is very fashionable now, I see it more and more often, especially at web expos, where most of devs are Google-junkies/wannabes. So I took a spin on it and was not impressed...yet? "Yet" is too, the word which comes to mind when I think of Android. But I digress.

Chrome pros:
- fast
- Google-integrated, HTML5 support
Chrome contras:
- system colors are not respected nor used! I am on XP (Silver theme), do not show me bloody blue Vista-like buttons! WTF? Respect my environment, look and color prefs - do not supplant them!
- WTF with fullscreen (F11) mode? I raise the mouse to top bar - and see no menu, no address line only some useless nag?
FAIL ("yet"?)
By the way, "Chrome" is "lame" in Russian.
Not that I hate it, it's just "not there yet".

And the winner is: Mozilla Firefox

Why?

Firefox pros:
- nice look, respects colors and style
- fast
- has free bookmark sync plug-ins
- does not cause "hanging" when waking up
- does not hog CPU on user-switched setups
- most sites are tested on it (although Opera was also OK in that regard for me)
Firefox contras:
- not the same look on mac - but I guess I don't want it to look like Safari on a PC
- there were problems updating it on a mac, "locked" dynlib files in Trash, even after restart
- popular - could be exploited successfully - will need often updates
Well, I guess it still much better on PC than the rest.

It's not the fist time Opera screwes up. But it's time to change.
Thanks for 9.x-10.10 though, it's been a great ride.

Thursday, April 1, 2010

Cracking RSA SecurID

Yes, I cracked it! Read on for details.

There are surprisingly few hits on Google, if you search the topic.

So I, having the token, decided to take the matter into my own hands.

First of all, you'll need clean well-lit place and a strong knife.
Click over to Picasa and see the slideshow:

Crack RSA with only hands and a knife

For those who are lazy to go there, the most intriguing part is how easily can some circuitry contacts be exposed, and that means one can temporarily gain possession of your token, run some attacks on it, replace the glued-on stub and you will not notice a shit!

Could this be the reason they've obsoleted those?