<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>noted &#187; chuckles</title>
	<atom:link href="http://www.lipstadt.com/noted/archives/category/chuckles/feed" rel="self" type="application/rss+xml" />
	<link>http://www.lipstadt.com/noted</link>
	<description>culled from reality and elsewhere</description>
	<lastBuildDate>Fri, 25 Jun 2010 00:09:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Only half the threat &#8211; and most of the answer.</title>
		<link>http://www.lipstadt.com/noted/archives/120</link>
		<comments>http://www.lipstadt.com/noted/archives/120#comments</comments>
		<pubDate>Thu, 22 Oct 2009 16:33:34 +0000</pubDate>
		<dc:creator>Adam</dc:creator>
				<category><![CDATA[chuckles]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[incidental]]></category>
		<category><![CDATA[notices]]></category>
		<category><![CDATA[product]]></category>
		<category><![CDATA[ruminations]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[tech]]></category>

		<guid isPermaLink="false">http://www.lipstadt.com/noted/archives/120</guid>
		<description><![CDATA[Today, Slashdot posted a story to the front page regarding a widespread SMC 8014 router/modem vulnerability, allowing access to administrative functions.  I would link to the original blog post, but it seems to be slashdotted. (Edit: no longer. I also indulged myself with a comment on the slashdot story and the blog post, both came [...]]]></description>
			<content:encoded><![CDATA[<p>Today, <a href="http://tech.slashdot.org/story/09/10/22/0336246/Time-Warner-Cable-Modems-Expose-Users?art_pos=6" title="/.">Slashdot posted a story to the front page</a> regarding a widespread SMC 8014 router/modem vulnerability, allowing access to administrative functions.  I would link to the original blog post, but it seems to be slashdotted. (Edit: no longer. I also indulged myself with a comment on the slashdot story and <a href="http://chenosaurus.com/2009/10/20/time-warner-cable-modemrouter-major-security-hole/">the blog post</a>, both came late in the game. No, I&#8217;m not selling anything nor do I get ad revenue.)  In any case, this is nothing new.  These and similar SMC routers are common in New York and are identifiable in their use of a four digit hex SSID.  Naturally, all APs broadcast their Wifi adapters&#8217; MAC address in the clear, allowing for identification of the manufacturer (barring spoofing).</p>
<p>These SMC routers were ordered in bulk with a custom firmware, with some &#8220;features&#8221; that were put in place to (presumably) assist in over the phone tech support.  The firmware enables WEP encryption with a preset key on the network and uses Javascript to disable more advanced features, including choosing WPA.  If that wasn&#8217;t problematic enough, <strong>the WEP key is derivable from the MAC address</strong>.  Let me repeat that point as clearly as I can.</p>
<p><strong>The preset WEP key is derivable from the MAC address that is broadcast in the clear</strong>.</p>
<p>That last part is trivial, and I&#8217;m not going to give out (what I hesitate to call) the algorithm.</p>
<p>But wait, there&#8217;s more.  One of the advanced features disabled by the Javascript hack is the ability to change the WEP key.  I was not vulnerable to this (I use a different service with my own hardware), but a friend was -which allowed me to do a bit of work on these routers and their deployment.  We were told (July 2008) by a customer service rep that changing the WEP key was not supported for the end user &#8211; even after I asked my friend to claim that she thought someone had her &#8220;network password&#8221; (which was technically true).</p>
<p>Ironically, the vulnerability mentioned in the Slashdot article is the means to secure the router: by using various techniques (disabling Javascript, Greasemonkey, etc.)  you can restore these functions: changing the mode of encryption, the key, and the administrative values.</p>
<p>SMC is not the only company to have sold these gelded all-in-one routers to bulk telecom customers; nor is Time Warner the only customer to deploy them.  In a private discussion sharing these findings with some westcoasters at Defcon in Aug 2008, I was told there was an L.A. telecom doing exactly the same things &#8211; mass deployed routers with predictable keys and a broken firmware that prevented a fix.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lipstadt.com/noted/archives/120/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Signs of things terribly wrong&#8230; or right&#8230;</title>
		<link>http://www.lipstadt.com/noted/archives/108</link>
		<comments>http://www.lipstadt.com/noted/archives/108#comments</comments>
		<pubDate>Sat, 13 Sep 2008 02:06:40 +0000</pubDate>
		<dc:creator>Adam</dc:creator>
				<category><![CDATA[chuckles]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[incidental]]></category>
		<category><![CDATA[tech]]></category>

		<guid isPermaLink="false">http://www.lipstadt.com/noted/archives/108</guid>
		<description><![CDATA[When a Math/Compsci Professor comes to your apartment, peeks his head around a corner and exclaims - with sarcasm, suprise, and a hint of disgust - &#8220;Oh look. Another computer.&#8221;]]></description>
			<content:encoded><![CDATA[<p>When a Math/Compsci Professor comes to your apartment, peeks his head around a corner and exclaims </p>
<p>- with sarcasm, suprise, and a hint of disgust -</p>
<p>&#8220;Oh look. Another computer.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lipstadt.com/noted/archives/108/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A butterfly clicks on a web page in Florida and causes a storm in New York.</title>
		<link>http://www.lipstadt.com/noted/archives/106</link>
		<comments>http://www.lipstadt.com/noted/archives/106#comments</comments>
		<pubDate>Fri, 12 Sep 2008 05:44:12 +0000</pubDate>
		<dc:creator>Adam</dc:creator>
				<category><![CDATA[chuckles]]></category>
		<category><![CDATA[incidental]]></category>
		<category><![CDATA[open tabs]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[tech]]></category>

		<guid isPermaLink="false">http://www.lipstadt.com/noted/archives/106</guid>
		<description><![CDATA[The UAL story &#8211; as a parable &#8211; is too good to be true. (As fact, it seems patently unfair to UAL.) As a cautionary tale, it got even better &#8211; expanding on the chaotic complexity of interacting state machines: Single Web Hit Led to UAL Glitch, Tribune Says &#8211; WSJ.com]]></description>
			<content:encoded><![CDATA[<p>The UAL story &#8211; as a parable &#8211; is too good to be true. (As fact, it seems patently unfair to UAL.)</p>
<p>As a cautionary tale, it got even better &#8211; expanding on the chaotic complexity of interacting state machines:</p>
<p><a href="http://online.wsj.com/article/SB122109238502221651.html?mod=yahoo_hs&amp;ru=yahoo">Single Web Hit Led to UAL Glitch, Tribune Says &#8211; WSJ.com</a><br />
<blockquote></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.lipstadt.com/noted/archives/106/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>About that trip to Miami&#8230; apparently it was b&#8217;shogeg.</title>
		<link>http://www.lipstadt.com/noted/archives/92</link>
		<comments>http://www.lipstadt.com/noted/archives/92#comments</comments>
		<pubDate>Wed, 03 Oct 2007 10:19:45 +0000</pubDate>
		<dc:creator>Adam</dc:creator>
				<category><![CDATA['keit]]></category>
		<category><![CDATA[chuckles]]></category>

		<guid isPermaLink="false">http://www.lipstadt.com/noted/archives/92</guid>
		<description><![CDATA[How did I miss this?!!? Miami is ASSUR!!]]></description>
			<content:encoded><![CDATA[<p>How did I miss this?!!? <a href="http://www.bangitout.com/articles/viewarticle.php?a=1764">Miami is ASSUR!!</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.lipstadt.com/noted/archives/92/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Amusing and yet ironic&#8230;</title>
		<link>http://www.lipstadt.com/noted/archives/89</link>
		<comments>http://www.lipstadt.com/noted/archives/89#comments</comments>
		<pubDate>Thu, 13 Sep 2007 03:14:20 +0000</pubDate>
		<dc:creator>Adam</dc:creator>
				<category><![CDATA[chuckles]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[tech]]></category>
		<category><![CDATA[wetware]]></category>

		<guid isPermaLink="false">http://www.lipstadt.com/noted/archives/89</guid>
		<description><![CDATA[&#8230;because the page is fairly ugly, poorly categorized (tabs&#8230; controls&#8230; stupidity? These are not like things) and dated navigation tools.&#160; Still, not nearly as bad as the examples contained in the Interface Hall of Shame &#8211; Controls.&#160;&#160; Perhaps the irony is intentional?]]></description>
			<content:encoded><![CDATA[<p>&#8230;because the page is fairly ugly, poorly categorized (tabs&#8230; controls&#8230; stupidity? These are not like things) and dated navigation tools.&nbsp; Still, not nearly as bad as the examples contained in the <a href="http://homepage.mac.com/bradster/iarchitect/">Interface Hall of Shame &#8211; Controls</a>.&nbsp;&nbsp; Perhaps the irony is intentional?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lipstadt.com/noted/archives/89/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>If I knew how to put an upside down A here, I would.</title>
		<link>http://www.lipstadt.com/noted/archives/86</link>
		<comments>http://www.lipstadt.com/noted/archives/86#comments</comments>
		<pubDate>Fri, 24 Aug 2007 08:29:31 +0000</pubDate>
		<dc:creator>Adam</dc:creator>
				<category><![CDATA[XX]]></category>
		<category><![CDATA[XY]]></category>
		<category><![CDATA[chuckles]]></category>
		<category><![CDATA[incidental]]></category>
		<category><![CDATA[ruminations]]></category>
		<category><![CDATA[speaking and tongues]]></category>

		<guid isPermaLink="false">http://www.lipstadt.com/noted/archives/86</guid>
		<description><![CDATA[But I can&#8217;t, nor can I be bothered to figure out how to do so. Let me point out one simple fact&#8230; If that character defines the set of people who find you acceptable, likable &#8211; or rather, you believe this to be so &#8211; you carry the small, small soul of a politician, and [...]]]></description>
			<content:encoded><![CDATA[<p>But I can&#8217;t, nor can I be bothered to figure out how to do so.  Let me point out one simple fact&#8230; If that character defines the set of people who find you acceptable, likable &#8211; or rather, you believe this to be so &#8211;  you carry the small, small soul of a politician, and must deal with the simple fact that I am the backwards E that is bringing your shit down.</p>
<p>Moreover, if you did not understand the above paragraph, nor did you engage in the five minutes of consultation with Google or Wikipedia, or lord forgive us, a book, that might cure you of ignorance &#8211; ignorance not being a crime, sin, or disease, but the total inability to remedy it being all three &#8211; if you did not understand, than you are simply the type that I care to offend, the burden on goodness which allows me to say, &#8220;Well Lord, I am not much, but at least I am not that.&#8221;</p>
<p>More on this later.</p>
<p>For now, a mere thought that has been bothering me.  Many people write.  Some even have some skill.  A select few are truly good.  Whether I belong to the ultimate or penultimate class, I care enough to edit, to read aloud, to avoid reuse &#8211; you know, the basic artisanry of writing.  So why is it, that the bulk of personal writing that even I am willing to put out into the world, is the horrid, horrid, shit that fills many a tower of blog?  Yes, I apologize &#8211; this blog&#8217;s content is tepid, the prose unedited &#8211; and not in a good (i.e. avoid the NC-17) way. Isn&#8217;t it odd that I am not unique in that; of all the things we commit to paper or Word format or HTML, why is it that we choose the least of it to disseminate to the world?</p>
<p>That the answer is clear makes it no less disheartening.</p>
<p>A last point: some TV shows are really good enough to make me consider going outside, buying a pack of smokes, and relighting the habit. Californication seems to be one of those shows &#8211; I can&#8217;t remember laughing so hard, naturally.  It deserves some time and a chance.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lipstadt.com/noted/archives/86/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Laugh, it&#8217;s funny.</title>
		<link>http://www.lipstadt.com/noted/archives/83</link>
		<comments>http://www.lipstadt.com/noted/archives/83#comments</comments>
		<pubDate>Thu, 16 Aug 2007 06:13:35 +0000</pubDate>
		<dc:creator>Adam</dc:creator>
				<category><![CDATA[chuckles]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[tech]]></category>

		<guid isPermaLink="false">http://www.lipstadt.com/noted/archives/83</guid>
		<description><![CDATA[From the POSIX Programmer&#8217;s Guide. How did I miss this on the internet until now?]]></description>
			<content:encoded><![CDATA[<p><a href="http://books.google.com/books?id=rHyMRyDEG3gC&amp;pg=PA110&amp;lpg=PA110&amp;dq=%22in+general+it+is+safe+and+legal+to+kill+your+children%22&amp;source=web&amp;ots=vGungpLT9E&amp;sig=2Gh0kidX9bIwTGfcP6YWGuLsz_c">From the POSIX Programmer&#8217;s Guide</a>.</p>
<p>How did I miss this on the internet until now?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lipstadt.com/noted/archives/83/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.333 seconds -->
