<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>why not ben</title><link>http://stream.btucker.org/</link><description>Ben Tucker’s virtual life</description><generator>Tumblr (mrben)</generator><item><title>It’s always a good day for a little Carl Sagan.  I love...</title><description>&lt;embed type="application/x-shockwave-flash" src="http://stream.btucker.org/swf/audio_player.swf?audio_file=http://stream.btucker.org/audio_file/34698122/Z49UtQPNi8yha9ih82AdiUiV&amp;color=FFFFFF" height="27" width="207" quality="best"&gt;&lt;/embed&gt;&lt;br/&gt;&lt;br/&gt;It’s always a good day for a little Carl Sagan.  I love this excerpt and his reading is of course amazing.</description><link>http://stream.btucker.org/post/34698122</link><guid>http://stream.btucker.org/post/34698122</guid><pubDate>Tue, 13 May 2008 16:22:29 -0400</pubDate></item><item><title>MUTO a wall-painted animation by BLU
         (via...</title><description>&lt;object type="application/x-shockwave-flash" width="400" height="300" data="http://vimeo.com/moogaloop.swf?clip_id=993998&amp;server=vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=00ADEF"&gt;&lt;param name="quality" value="best" /&gt;&lt;param name="allowfullscreen" value="true" /&gt;&lt;param name="scale" value="showAll" /&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=993998&amp;server=vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=00ADEF" /&gt;&lt;/object&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;MUTO a wall-painted animation by BLU
         (via &lt;a href="http://quotably.com/url/4270578"&gt;Quotably.com/popular&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;This is unbelievably amazing.&lt;/p&gt;</description><link>http://stream.btucker.org/post/34610502</link><guid>http://stream.btucker.org/post/34610502</guid><pubDate>Mon, 12 May 2008 23:19:00 -0400</pubDate></item><item><title>FINISHED!!!!!!!!!!!!!!!!!</title><description>FINISHED!!!!!!!!!!!!!!!!!</description><link>http://stream.btucker.org/post/34569842</link><guid>http://stream.btucker.org/post/34569842</guid><pubDate>Mon, 12 May 2008 14:53:16 -0400</pubDate></item><item><title>Off to my final final!</title><description>Off to my final final!</description><link>http://stream.btucker.org/post/34557134</link><guid>http://stream.btucker.org/post/34557134</guid><pubDate>Mon, 12 May 2008 12:42:51 -0400</pubDate></item><item><title>Last night as a student: Looking like an allnighter. Fitting way...</title><description>&lt;img src="http://media.tumblr.com/Z49UtQPNi8wf36h7deGLoU2I_500.jpg"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;b&gt;Last night as a student:&lt;/b&gt; Looking like an allnighter. Fitting way to end a school career.</description><link>http://stream.btucker.org/post/34519281</link><guid>http://stream.btucker.org/post/34519281</guid><pubDate>Mon, 12 May 2008 05:45:17 -0400</pubDate></item><item><title>Wow, news of the horrible earthquake in China was at the top of http://quotably.com/popular before...</title><description>Wow, news of the horrible earthquake in China was at the top of &lt;a href="http://quotably.com/popular"&gt;http://quotably.com/popular&lt;/a&gt; before CNN even had an alert up.</description><link>http://stream.btucker.org/post/34511524</link><guid>http://stream.btucker.org/post/34511524</guid><pubDate>Mon, 12 May 2008 04:01:51 -0400</pubDate></item><item><title>iTunes not seeing jailbroken iPhone</title><description>&lt;p&gt;This happened to me after I trashed my iPhone as a result of a corrupted SpringBoard.app property list file.  (I think this was Installer.app’s fault, but I can’t say for certain).&lt;/p&gt;

&lt;p&gt;Anyway, to restore the iPhone that iTunes doesn’t see follow these steps:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Connect iPhone to computer&lt;/li&gt;
&lt;li&gt;Power up iPhone if it’s off&lt;/li&gt;
&lt;li&gt;Press and hold down both the power and home buttons at the same time&lt;/li&gt;
&lt;li&gt;The “drag to turnoff” slider will come up, but keep holding down the buttons&lt;/li&gt;
&lt;li&gt;The screen will go black, then the apple logo will appear&lt;/li&gt;
&lt;li&gt;let go of the power button, but keep holding the home button&lt;/li&gt;
&lt;li&gt;iTunes should open and say your iPhone is in recovery mode and offer to restore.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This worked for me, YMMV.&lt;/p&gt;</description><link>http://stream.btucker.org/post/34453208</link><guid>http://stream.btucker.org/post/34453208</guid><pubDate>Sun, 11 May 2008 13:48:00 -0400</pubDate></item><item><title>An update on Hahlo security (it’s improving, but still needs work):...</title><description>An update on Hahlo security (it’s improving, but still needs work): &lt;a href="http://stream.btucker.org/post/34406476"&gt;http://stream.btucker.org/post/34406476&lt;/a&gt;</description><link>http://stream.btucker.org/post/34413555</link><guid>http://stream.btucker.org/post/34413555</guid><pubDate>Sun, 11 May 2008 03:47:33 -0400</pubDate></item><item><title>Hahlo security improving</title><description>&lt;p&gt;Big props to Dean Johnson of Hahlo for improving security of the tool.  &lt;a href="http://groups.google.com/group/twitter-development-talk/browse_thread/thread/0543635177a4c854/f9e4a21716e640b8"&gt;After some discussion&lt;/a&gt; Hahlo no-longer stores your twitter authentication details in the clear in cookies.  This is certainly an incremental improvement, but there are still problems.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;The login page is still not SSL, so for the login request your credentials are still in cleartext for anyone nearby to snoop.  Still much better than them being included with every request as was the previous situation.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Now your credentials are stored unencrypted for the duration of your session (up to 7 days) on the Hahlo server.  This is unfortunate, since it means anyone that gains access to the Hahlo server now knows your twitter username and password. Since &lt;a href="http://www.msnbc.msn.com/id/24162478/"&gt;half the internet&lt;/a&gt; uses the same password for multiple accounts, this would mean that in addition to all Hahlo users from the previous 7 days have their Twitter accounts open to being hijacked, so to would any other online services for which they used the same credentials.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;So at the end of the day, here’s my current advice.  Hahlo is now probably the best choice, security-wise, of the iPhone web-based Twitter clients.  BUT (and that’s a big but), change your twitter password if it’s the same as one you use for another online account, and refrain from logging in to Hahlo at a Tech Conference, College Campus, Coffee Shop, or somewhere else traffic is likely being snooped.&lt;/p&gt;

&lt;p&gt;Hahlo could still completely solve the issue by moving to SSL for the login and encrypted credentials stored in cookies.&lt;/p&gt;</description><link>http://stream.btucker.org/post/34406476</link><guid>http://stream.btucker.org/post/34406476</guid><pubDate>Sun, 11 May 2008 02:13:00 -0400</pubDate></item><item><title>Changing my address at usps.com back to VT, effective a week from Monday. Feels good.</title><description>Changing my address at usps.com back to VT, effective a week from Monday. Feels good.</description><link>http://stream.btucker.org/post/34183909</link><guid>http://stream.btucker.org/post/34183909</guid><pubDate>Thu, 08 May 2008 23:14:03 -0400</pubDate></item><item><title>"Excuse me if a look of bewilderment crosses my face when a surrogate of Sen. Hillary Clinton’s..."</title><description>“Excuse me if a look of bewilderment crosses my face when a surrogate of Sen. Hillary Clinton’s starts off on the “we need hard-working white workers to win in November” mantra.”&lt;br/&gt;&lt;br/&gt; - &lt;em&gt;&lt;a href="http://www.cnn.com/2008/POLITICS/05/08/roland.martin/index.html"&gt;Roland Martin: Democrats need more than working-class whites&lt;/a&gt;&lt;/em&gt;</description><link>http://stream.btucker.org/post/34177335</link><guid>http://stream.btucker.org/post/34177335</guid><pubDate>Thu, 08 May 2008 21:28:06 -0400</pubDate></item><item><title>Online Advertising: News Corp. exec explains why MySpace traffic rose, revenues dropped</title><description>&lt;a href="http://valleywag.com/388447/news-corp-exec-explains-why-myspace-traffic-rose-revenues-dropped"&gt;Online Advertising: News Corp. exec explains why MySpace traffic rose, revenues dropped&lt;/a&gt;: In other news: the banner/text ad model is clearly broken for apps where the user is not searching out something in particular.</description><link>http://stream.btucker.org/post/34139583</link><guid>http://stream.btucker.org/post/34139583</guid><pubDate>Thu, 08 May 2008 13:14:12 -0400</pubDate></item><item><title>This may have limited appeal since it’s a lot of...</title><description>&lt;object width="400" height="336"&gt;&lt;param name="movie" value="http://www.youtube.com/watch?v=3BX7PojrqZY"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/3BX7PojrqZY" type="application/x-shockwave-flash" width="400" height="336" wmode="transparent"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br/&gt;&lt;br/&gt;This may have limited appeal since it’s a lot of “inside jokes”… but I think it’s really funny!  And so well done.</description><link>http://stream.btucker.org/post/34088690</link><guid>http://stream.btucker.org/post/34088690</guid><pubDate>Thu, 08 May 2008 02:49:39 -0400</pubDate></item><item><title>Saw Iron Man last night. ‘was fun, but I was offended by the notion software writes itself. My...</title><description>Saw Iron Man last night. ‘was fun, but I was offended by the notion software writes itself. My friends replied: umm, it’s a superhero movie.</description><link>http://stream.btucker.org/post/34024685</link><guid>http://stream.btucker.org/post/34024685</guid><pubDate>Wed, 07 May 2008 13:24:45 -0400</pubDate></item><item><title>learning just how little I understood about MySQL optimization.</title><description>learning just how little I understood about MySQL optimization.</description><link>http://stream.btucker.org/post/33867810</link><guid>http://stream.btucker.org/post/33867810</guid><pubDate>Tue, 06 May 2008 03:50:05 -0400</pubDate></item><item><title>The twitter client Hahlo is not secure. I recommend thinking twice before using:...</title><description>The twitter client Hahlo is not secure. I recommend thinking twice before using: &lt;a href="http://stream.btucker.org/post/33710515"&gt;http://stream.btucker.org/post/33710515&lt;/a&gt;</description><link>http://stream.btucker.org/post/33711189</link><guid>http://stream.btucker.org/post/33711189</guid><pubDate>Sun, 04 May 2008 14:03:39 -0400</pubDate></item><item><title>Use Hahlo Twitter Client with Caution</title><description>&lt;p&gt;&lt;a href="http://hahlo.com"&gt;Hahlo&lt;/a&gt; is a really nice Twitter client targeted primarily at the iPhone, but also usable from any browser.  Unfortunately, it handles authentication in a completely insecure way, exposing users’ twitter credentials to any third party sniffing packets on the network.&lt;/p&gt;

&lt;p&gt;For starters the &lt;a href="http://hahlo.com"&gt;login page&lt;/a&gt; does not use SSL.  This in and of itself is a problem since for that one login request a user’s login credentials are exposed, but it’s actually much worse.  Hahlo stores a user’s username and password &lt;strong&gt;unencrypted&lt;/strong&gt; in cookies.  This means that every single request to hahlo (even ones for images) includes the user’s username and password completely in the clear.&lt;/p&gt;

&lt;p&gt;This is unacceptable for a production application, especially since it’s undisclosed.  Definitely don’t use it at a coffee shop, tech conference or college campus.  Or if you connect to the internet with a cable modem.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Update:&lt;/em&gt; @hahlo &lt;a href="http://quotably.com/hahlo/statuses/803319244#805143933"&gt;complained&lt;/a&gt; on twitter that I didn’t mention other twitter clients are equally insecure.  This is true (just confirmed PocketTweets has exactly the same vulnerability).  I singled out Hahlo because it was a new release getting a lot of attention.  But this is no excuse not to fix (or at least disclose) that hahlo is so insecure.&lt;/p&gt;

&lt;p&gt;The fix is not hard, either.&lt;/p&gt;

&lt;p&gt;1) buy an SSL cert for $30&lt;br/&gt;
2) setup &lt;a href="https://hahlo.com"&gt;https://hahlo.com&lt;/a&gt;&lt;br/&gt;
3) use 2-way encryption on the cookie so that only with a secret can it be read&lt;/p&gt;

&lt;p&gt;(This is how Quotably handles authentication.)&lt;/p&gt;</description><link>http://stream.btucker.org/post/33710515</link><guid>http://stream.btucker.org/post/33710515</guid><pubDate>Sun, 04 May 2008 13:51:00 -0400</pubDate></item><item><title>It’s really fun to watch other people pitch your stuff...</title><description>&lt;object width="400" height="336"&gt;&lt;param name="movie" value="http://www.youtube.com/watch?v=2iL8ZGPAf4A"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/2iL8ZGPAf4A" type="application/x-shockwave-flash" width="400" height="336" wmode="transparent"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br/&gt;&lt;br/&gt;It’s really fun to watch other people pitch your stuff with even more enthusiasm than yourself!  Thanks Ed!</description><link>http://stream.btucker.org/post/33494578</link><guid>http://stream.btucker.org/post/33494578</guid><pubDate>Fri, 02 May 2008 01:47:56 -0400</pubDate></item><item><title>18 years after shyly entering my first classroom at age 5, today I left my last.</title><description>18 years after shyly entering my first classroom at age 5, today I left my last.</description><link>http://stream.btucker.org/post/33493804</link><guid>http://stream.btucker.org/post/33493804</guid><pubDate>Fri, 02 May 2008 01:34:32 -0400</pubDate></item><item><title>What a great ad!  I’m glad my last contribution went...</title><description>&lt;object width="400" height="336"&gt;&lt;param name="movie" value="http://www.youtube.com/watch?v=ywQKYga6uMY"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/ywQKYga6uMY" type="application/x-shockwave-flash" width="400" height="336" wmode="transparent"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br/&gt;&lt;br/&gt;What a great ad!  I’m glad my last contribution went toward this.  This should serve as a model for political advertising as far as I’m concerned.</description><link>http://stream.btucker.org/post/33391760</link><guid>http://stream.btucker.org/post/33391760</guid><pubDate>Thu, 01 May 2008 01:08:01 -0400</pubDate></item></channel></rss>
