Ruminations Galore

Thursday, November 18, 2004

Do people know too much?

Last week a friend emailed me asking me, "How do I add the disappear buttons to the panel in gnome?" Poor fellow was in much pain. Thing was, he had read about the Configuration Editor from somewhere and also heard some guys speak about it in his LUG. So, the bloke tried desperately to find the checkbox in Configuration Editor, under panel and what not. I am told he spent hours at it.

If only the guy had right-clicked on the panel itself and clicked on Properties. There in all its glory is the "Show hide buttons" check box.

Now the question, is it fair for this guy to say that Linux is unfriendly, that it is impossible to customize/configure! I mean, should a guy who refuses to use his brain and puts his limited knowledge to test be heard at all. Think about it.

I believe that it is because of the limited study/research that claims like these are often made. The fact remains, it is very difficult to impress upon newbies the importance for self tutoring. We can have books, we can have wikis, bulletin boards and all, but such clams will always be made until the newbies realize the importance of reading.

Some newbies are hopeless.

Then again, so are some of the Gurus. Visit any bulletin boards on Linux and you never know when you might bump into a RTFM!@#@ post or Google is your friend. Why is it?

Why is it that the Guru feels so sure that the newbie has not already read the man pages? The idea of being rude to a newbie just because you have more than a 1000 posts and he has asked a simple question seems stupid, to say the least.

Open Source evangelists have always given a high priority to the community. Off late, this community has expanded to include google. So it is often expected from the newbie to read all through the man pages, 2-3 pages of the results yielded by google and then a search at the forum boards before asking the question!

Whooh. The question, should a newbie be hanged if he doesn't know/do this? I mean what if the guy is such a noob he doesn't know what the heck man pages are? Then, what is the point of making "RTFM" replies? To him, it's yet another mystery.

The solution to this, maybe, is to include a page with all the distributions that gives the users an idea on things such as Multimedia, Internet, Man pages etc. A little help page on the desktop to get them started might just do the trick.

Think about it.

I rest my case.

Wednesday, November 10, 2004

Update

Hiya. It's been kind of hectic lately. I have to finish off my assignments before I leave for Bangalore. I am flying on the 30th. I am working on designing a whole new CSS template, maybe I'd implement it here, who knows!

As if the CSS coding was not enough, I am also learning perl and going through some localization documents(howtos). And to top it all, my parents just bought me - 'Star trek III The Search for Spock'

So now you know, instead of posting in my free time (breaks), I prefer to read :)

Watch out for some posts later today.

Wednesday, November 03, 2004

Email account registration -- what about bots?

Not too long ago, the procedure to creating an email account used to be easy. Of late, it has become kinda like a test for your eyes. You have to type in the word or number in the image to complete the registration.

Some people wonder why this is and most often say -- 'this is to ensure that there are no computerised registration'. The idea was to differentiate humans from bots. Thus was invented what is now known as captchas (completely automated public Turing tests to tell computers and humans apart).

This procedure can not be tempered with easily as each failed attempt (at typing the word) generates a new word.

There are many such captchas in use now, Gimpy is one, which Yahoo! uses.

This report mentions how smart "spammers" have become. It mentions a certain scam wherein the spammers are manipulating computer users into doing their dirty work.

Quoting from the report:


The bogus emails have the characteristics shown here:

Subject: Automatic Yahoo identifier completion

Body text:

Dear Yahoo! Member,

We must check that your Yahoo! ID was registered by real people. So, to help Yahoo! prevent automated registrations, please click on this link and complete code verification process:

[ URL removed ]

Thank you.


Details

Email filtering firm MessageLabs reports that the scam emails contain a fake Yahoo.com URL which redirect through a Google URL three times, in order to obfuscate the path of the link, before landed surfers on a fake Yahoo! web address. This page loads a real Yahoo! help page with legitimate information explaining the code verification process, followed by a fake pop-up window which shows the user a Yahoo picture ID and asks them to enter a code.


So users, do be very careful and on the highest alert, Red!

Tuesday, November 02, 2004

Gmail and the 'traps'

I am a fan of gamil. I love it. Now, I read all these reports of security holes in gmail, that it's vulnerable to "hacker" attacks and that gets me thinking whether all the people who read such reports actually understand them.

This report actually explains the exploit. The task is very simple. Let me run doen the points for all:
Gmail stores a cookie in the users' computer to identify them. Now whoever has this cookie on his computer can imitate to be the rightful user to Gmail. So "hackers" exploit the security hole in the service's user identification to grab this cookie.

What's interesting is that if a user changes his password later, he is still not safe 'coz the "hacker" still has the same cookie as you. Quoting from the report "The system authenticates the hacker as the victim, using the stolen cookie file. Thus no password is involved in the authentication process. The victim can change his password as many times as he pleases, and it still won't stop the hacker from using his box".


The only thing the "hacker" needs is your userid. Like I explained in my previous post, WWW is saturated with good ids, so it is not a huge task to guess ids.

Google has now said that this threat has ben taken care of and that the "hole" has been shut. Phew. I won't suggest folks to stop using gmail on this account, 'coz look at the bright side, the hole got fixed quickly. But such threats become even more threatening because they provide for easy identity theft.



Get Firefox!

Powered by Blogger

Listed on Blogwise
 
Get Firefox!