26
Apr

Will I Get that Nokia E61, Smart?

Now that Tina’s about to get her Nokia 6233 from Smart, should I get my hopes up? Will I get that Nokia E61 from Smart?

In my frustration for that retention nonsense, I began looking for a laptop. Mid-to-high spec’d laptops are expensive, so I began hunting for a Dopod 838 Pro. Yikes, Dopod costs like a very decent laptop (Php 47k is the cheapest price I found). So I told myself I should get a laptop instead.

And while looking, I found that Nokia E61i is now released. I was ready to get one that time, only that the stores that had dummy units don’t have stocks yet (silly).

Cmon, Smart. I’m waiting. I’ve been waiting. For two months.

26
Apr

McAfee Avert Labs Blog “Breaks It Down”

McAfee Avert Labs Blog is currently having a series of blog posts. Entitled Breakdown/Breaking It Down (the branding is not yet established), the series attempts to explain security applications, how-things-work style. The posts are clear, using easy-to-understand analogies.

Here are the latest posts in the series:

Breaking It Down: What’s a Firewall, and Why Do I Care?

Breakdown: How Does AV Software Deal With Software Exploits?

Monitor the series. The blog URL is http://www.avertlabs.com/research/blog/. If you have questions, you can leave a comment there, or ask and I will try to clarify.

25
Apr

Romulo Makalintal is So Overrated

Speaking of lawyers, I think Romulo Makalintal is overrated.

Sure, he has a radio DJ voice, but on some things, his arguments are at best, always a stretch of the truth.

Before the Hello Garci controversy, Makalintal was already busy defending his client, filing motions upon motions to have FPJ’s electoral protest dismissed. Of course, FPJ died and the protest was dismissed.

Now, tell him that his client had cheated in 2004, and he would always say that the Presidential Electoral Tribunal has already spoken. Here‘s that handwashing decision, read it, and tell me where in that decision it is said that Gloria Arroyo won fair and square.

Overrated, indeed.

Now, he is up to his news grabbing comments.

In COMELEC Resolution No. 07-0724 (which is not available at this site at the moment), the Comelec has prohibited the release of party list nominees; the said list of nominees will only be released immediately after the voting is over. Claiming that some party list groups are just administration fronts, several quarters have petitioned the Supreme Court to compel the Comelec to release the list.

Now here is Makalintal, again showing how overrated he is (from ABS-CBN News):

“Walang karapatan ang sinuman na pilitin ang anumang ahensya ng pamahalaan na mag-publish ng kung anumang bagay na nasa kanilang control and supervision, subalit kapag hiningi mo sa kanila ang listahan at hindi ibinigay, doon magkakaroon ng kaso (Nobody has the right to force any government agency to publish [documents] under their control and supervision, but if you ask [COMELEC] the list [of party-list nominees] and it did not accede, a case can be filed],” Macalintal said.

He added: “Asking COMELEC to publish [the names] is different from requesting COMELEC for a list.”

xxx

“Ikaw ay may karapatang kunin ang pangalan na ‘yan at kung makuha mo ay maaari mong gamitin ‘yan sa anumang paraang legal na magagawa mo, i-publish mo ngayon sa mga diyaryo (You have the right to get those names and after getting the names you can use them in any legal way, publish the names in newspapers),” he said.

How can you request the Comelec to have such list published when it has passed a resolution banning such release/publication?

24
Apr

Google Hunts for Talent at Hackers Conf, World Domination on Track

In its quest for world domination, Google is looking for talent (read: employees) at a highly-unlikely place: a hackers conference.

CNet’s Tech News blog reports about Google looking for talent at CanSecWest, a conference concentrating on applied digital security.

Google was also present at Shmoocon last month. Shmoocon is “an annual East coast hacker convention hell-bent on offering three days of an interesting atmosphere for demonstrating technology exploitation, inventive software and hardware solutions, and open discussions of critical infosec issues.”

Google looking for haxors?

PS: I am using Trend Micro’s Trend Protect, and it seems that the SchmooCon Web site is marked as unsafe.


(Click image to enlarge)

24
Apr

Microsoft to Release Client Security Software

Microsoft is now ready to take on software security giants like Symantec and McAfee on its way to world domination.

Steve Ballmer has announced that its Forefront Client Security software is ready for final release in a few weeks.

Money quote from CNet News.com report:

Microsoft is ramping up its efforts to convince businesses that it’s the solution to, and not the source of, their security woes.

There was a joke, circulating when Microsoft announced OneCare, that comes to mind. Microsoft will earn money from security software; after all, its operating system is the source of majority of security woes in the world. With monthly patches to Windows (with the latest vulnerability being exploited in the wild), the joke is not that unfounded.

Sure, most security software have their own problems. But with Windows installed on loads of machines everywhere, the holes in the OS are security headaches. Microsoft’s entry in the security business was met with raised eyebrows.

As for me, as long as WGA remains (which is a spyware in my opinion), Microsoft is a nobody at the security business.

23
Apr

Correcting a Sloppy Report at ABS-CBN News

I am quoting in full this sloppy news report from ABS-CBN News:

Caloocan bets’ pals figure in rumble

Fighting broke out between the supporters of Caloocan congressional candidates Nilo Divina and Mitch Cajayon Monday morning.

ABS-CBN News reported that the brawl took place in Barangay 129’s San Jose community while Divina’s group was posting campaign materials. The area is a known bailiwick of Cajayon.

Dong Reyers, Cajayon’s campaign coordinator, said the supporters of Divina threatened them by brandishing firearms and a Japanese katana.

Cajayon declined to comment on the incident, saying it was small issue. He, however, advised Divina’s supporters to stop from posting campaign materials in his area to avoid similar incidents in the future.

Divina’s supporters denied that they started the fight. Arnold Divina, the candidate’s brother, said they would never act like the neighborhood toughie especially in the territory of their rival.

The rumble resulted in injuries for Divina supporter Jun Lumanog, who was beaten up with a wooden plank and had to undergo a medical treatment.

Divina, meanwhile, requested Caloocan Archbishop Deogracias Yñiguez to initiate the signing of an covenant to ensure peace and order in the city elections.

Aside from Divina and Cajayon, Councilor Tinong Bagos and Bebong Muñoz, the boyfriend of singer Jolina Magdangal, are also in the second district’s congressional race.

Corrections:

1. Mitch Cajayon, incumbent councilor in district II, is a she (paragraph 4 refers to Cajayon as a he).
2. Caloocan has a bishop, not an archbishop.
3. It should be Tino Bagus, not Tinong Bagos.
4. Dong Reyers is probably misspelled.

20
Apr

Deliver Us from Raul Gonzalez

One of the sins of Gloria Arroyo is appointing Raul Gonzalezs as Secretary of Justice in an acting capacity for seven years running. He should have been appointed as Presidential Assistant for Bad Propaganda.

Known for saying stupid things, the latest idiocy from him stems from the apparent murder of US Peace Corps volunteer Julia Campbell.

From the Inquirer:

She was careless and irresponsible. She took a lonely walk by herself in [that] deserted area.

We can learn a few things from this idiocy:

1. The Philippines is not safe for foreigners and for Filipinos, too. Imagine, you cannot take a lonely walk in a deserted area. Strong Republic huh?

The US should issue a travel advisory on the Philippines. After all, the Acting Secretary of Justice himself has told the entire world that our country is not safe for foreigners.

2. If you are walking with someone, is it a lonely walk?

3. You should not comment on something when you don’t have sufficient information. Apparently, Julia Campbell was not alone, she was with the probable killer when she took that walk.

4. As I had said in a comment in the previous post, evil is necessary for us to know what is good. Atty. Theodore Te says it more forcefully than I could.

How much more must we endure from him?

If you have learned anything from Gonzales’ words of wisdom, please share them in the comments.

19
Apr

Microsoft to Offer Cheap Software – World Domination in One Year

In a speech in Beijing today, Microsoft’s Bill Gates announced (CNet News, New York Times) its plan to further its way to world domination.

Earning an average of US$45 billion per year, Microsoft is aiming to corner the five billion people who are not using MS products by offering a so-called Student Innovation Suite, a US$3 bundle of MS Windows XP Starter Edition, Office Home and Student 2007, and other utilities.

Don’t get your hopes high, you of stingy nature: this bundle will only be available through partner governments, who must shoulder at least 50% of the cost of the computer where the bundle is to be installed.

With open source alternatives out there, I wonder why governments should be interested.

Those who are itching for less costly MS apps should be contented by finding free and open source alternatives. Or go to their friendly pirate stores. Ooops.

(This is the beginning of a series of posts that will monitor the attempts of big software companies to dominate the world.)

19
Apr

McAfee VirusScan On-Access Scanner Vulnerability

iDefense has released a report about a vulnerability in McAfee VirusScan. This vulnerability manifests itself when the On-Access Scanner component scans a file with a long file name that contains multibyte characters, and only on computers with East Asia language files installed, and the Unicode default codepage is set to multibyte language character set.

When the vulnerability is succesfully exploited, the On-Access Scanner component of the app is disabled or remote code execution happens.

This vulnerability is hard to exploit, as there are lots of conditions that must be fulfilled:

1. The file must have a long file name
2. The file name contains multibyte characters
3. East Asia language files must be installed on the target computer and Unicode codepage is set to multibyte character language
4. The attacker must be able to place the file in the target computer (as an attachment to an email message, probably, but the user has to save the attachment first)
5. The file must be opened or the user hovers the mouse over the file

There is no workaround for this vulnerability, so McAfee VirusScan users are advised to install Patch15. View the McAfee Security Bulletin.

18
Apr

Cheating Will Be Local

A lot of things are bothering me about this May elections.

The general consensus is that the cheating for this coming elections will be minimal. Yet, there are several facts that trouble me. One, the Comelec had ordered extra 1 million ballots printed. Second, the Comelec has purged the voters list; around a million names were removed. So what’s the use of the extra ballots?

Third, the administration is not bothered by the strong showing of the opposition in the senatorial race. Heck, it was even nonchalant when reacting to surveys. However, when a survey result showing that the voters will vote opposition in the local polls was released, the administration almost went ballistic.

Fourth, the administration hacks keep on harping about machinery delivering Team Unity to victory; one drunk hack even predicted a 12-0 sweep by the administration, survey results to the contrary notwithstanding. What machinery they are talking about? Is the Maguindanao governor’s enticement part of that machinery?

Fifth, the Comelec refuses to disclose the nominees of the party lists participating in this year’s elections. The Comelec did so in 2001 and in 2004, why can’t they do that this year? Is it because of the accusations that some party list groups are just administration fronts?

Taking all of these into consideration, and the fact that the people is now aware of the cheating mechanisms available, the question now is this: will there be cheating? And if yes, in what form?

I think it will help if we know what is the goal of the administration for this year’s elections. It is actually very simple, and very obvious. It has been their goal since 2004 – the survival of Gloria Arroyo’s hold in the Fortress by the Pasig.

So the goal this year is to prevent the opposition from gaining enough seats in the House of Representatives. The goal is to make another impeachment impossible.

Knowing the goal, we can now answer some questions. Will there be cheating this year? Probably. In what form? In a way that is localized in nature.

Let me explain. It seems that the administration has already conceded the senatorial race; all those things that administration hacks were saying are all bravado. Cheating on this level will be too obvious. (It is still possible, in order to insert a candidate or two, but that’s the most they can do.)

The administration has placed its bets on the local races. There are races where administration candidates are running unopposed, so scratch those. What to watch out for are the races that are perceived to be close or where the opposition is strong.

If there will be cheating, it will in the local polls. This is where the administration cannot afford to lose.