Archive 19.1.2005 - 25.1.2005

Internet Explorer Still Vulnerable After Patch

Internet Explorer still vulnerable after patch - which is embarrassing enough in itself. But the Heise editorial recommendation:

In principle, ActiveX is always a gateway for malware and should be disabled if necessary. However, some websites will then no longer function correctly.

is somehow peculiar: I've never really noticed ActiveX as a barrier to visiting any websites. Well, I'm a Mac and Linux user - if websites only worked with ActiveX, I would have noticed it, since it's conceptually impossible for me to run it (not even in IE, because of the wrong processor architecture).

Sure, there are a few Microsoft products that rely on ActiveX - but you really can't claim that it's become widespread out there on the web. So I'd say: disable ActiveX at least for the Internet zone. It has no value there. And in the trusted zones - which I already consider a pretty big euphemism for IE - only enable it if it's really necessary (for example, because an intranet solution unfortunately uses ActiveX). Or install a proper browser for surfing the web. That's the better solution anyway ...

Introducing JSON - another object ASCII notation, this one based on JavaScript syntax. Quite interesting - not as fussy about whitespace as YAML and not as verbose in syntax as XML.

JSch for J2ME - no idea if I'd want to use an SSH client on my phone (text input on a phone is more than annoying), but it would be possible with this...

.: json-rpc.org :. - an RPC library based on JSON.

Young Union invites former CDU politician Hohmann

Young Union invites ex-CDU politician Hohmann - and thereby makes itself (yet again) a laughingstock of the nation. How stupid can you actually be to stage such an action as criticism of the party leader? Sure, the Young Union hasn't overtaken the federal party on the far right for the first time - but then the CDU must surely be asked the question of how it actually intends to actively combat strengthening right-wing extremism if it recruits its people from such political newcomers ...

Ringtone hit parade from April - clear case for Wonko...

MIDI Bagpipe Roundup

MIDI Bagpipe Roundup - if anyone still wants to give me a pointless and overpriced gift: I'd love one of these electronic bagpipes. If only to drive the neighbors crazy.

mit dem Link-Kondom rel="nofollow"

ModSecurity - Web Intrusion Detection And Prevention / mod_security is an Apache module that examines requests and decides based on filters whether a request should be allowed through or whether a filter measure (script, log, etc.) should be triggered. Quite interesting, even though I'm generally skeptical about rule-based filtering against attacks - it only finds known or expected attacks. The real danger lies in the unexpected attacks...

MT-Blacklist -> Hijacked comments.cgi

MT-Blacklist -> Hijacked comments.cgi - anyone using Moveable Type should disable the comment script. The email verification that checks whether the sender address input doesn't contain junk is broken - which allows you to sneak in additional recipient addresses by separating them from the actual sender address with a line feed. And with that you can happily use MT to spam other people.

A real beginner mistake - the email validation is done with a regex that doesn't match the end of the string and uses dotall - so it only goes up to a possible line feed and ignores everything after it. Really stupid.

confused face

Vole Monogamy

Hotel Falckenstein: Wühlmaus-Monogamie - a highly recommended comment on the state of gender equality. And on secret paternity tests. And on voles.

Asymptomatic » New "Secret" Project - something like a peer-to-peer network built on standard technologies like HTTP and DNS. DynDNS for mutual discovery, HTTP for file transfer, and RSS and HTML for file lists. Actually a nice idea.

DNA debate: Müntefering stands behind Schily

DNA debate: Müntefering backs Schily and only incompetence personified (some call her the Federal Minister of Justice, yes, the very one who took away our right to private copying and wants to impose stupid software patents on us) stands against it. That's really alarming...

First Winter Images

First Winter Pictures - 1

Erste Winterbilder - 1

Not particularly impressive what winter has managed so far this year, but this morning there was actually some white powder snow on the ground.

First Winter Pictures - 2

Erste Winterbilder - 2

First Winter Images - 2

First Winter Pictures - 2

First Winter Pictures - 2

First Winter Images - 1

First Winter Pictures - 1

First Winter Pictures - 1

IT&W Reconstructs Mac Video

IT&W reconstructs Mac video - I would link directly, but their server got hammered...

RSS 1.1 and Postal's Law

The RSS 1.1: RDF Site Summary (DRAFT) contains a passage that I only noticed today ( through this posting). This fits well with the topic of developer arrogance. Because here again a developer has easily strayed from the path of reason. Of course, it's important that a standard is cleanly defined and that producers of formats adhere to these standards. It's also okay to require that a consumer of this format checks it and provides messages when deviations occur (though few users can make sense of their aggregator's messages anyway). But it's completely unrealistic to believe that aggregator users are satisfied when their aggregator just spits out an error message and no content. That's just as stupid as the same approach with XHTML - where some browsers actually implement it and don't go into Quirks Mode for broken XHTML, but simply deliver the XML parser error. Sorry, but that's complete nonsense. Every communication protocol has two ends - the producer and the consumer. And Postal's Law - be conservative in what you produce and liberal in what you accept - is simply the most sensible way to approach such communication protocols that transport content intended for humans. Requiring that consumer applications not display existing content due to format errors is simply unrealistic.

Public Prosecutor will not investigate NPD

State prosecutors will not investigate the NPD.

What the NPD wants is not parliamentary democracy, but an ethnic-oriented leadership state with clear parallels to the Nazi regime of the 'Third Reich'.

Rainer Stock, Saxon Constitutional Protection President, from: "Leipziger Volkszeitung"

Thinking Forth

Thinking Forth is now available online. My first Forth book - it really fascinated me with the language back then. Especially because it was much more suitable for the computers that were accessible to me at the time than most other programming languages.

Audioscrobbler :: Development - Last.fm Streaming API - an API to access your last.fm station.

Build me money making website please

Rent A Coder - Build me money making website please - let me quote:

I would like someone to build me a good website that will make me around $1000 a week or more. The website should be useful and not have any popups. I would like you to design the whole entire website. The content as well. Would like the website to have a lot of traffic as well.

Sorry, but if I could build a website that brings in $1000 per week - then I'd just sell it to some idiot like that. Makes sense. Sure. And pigs can fly.

(Found at Paul Tomblin)

A first Python example in Frontier is now online. Looks very interesting - I wish someone would build binaries now, because I still don't have XCode due to 10.2. And I'd really like to play around with it...

First - important - reactions to the NPD tirades in Saxony.

heise online - High fine for student organization due to hyperlinks

High fine for student organization over hyperlinks - so students get used to societal censorship early on. Besides, it's really annoying when these students indulge in the luxury of having a political opinion. And so one learns very early that you only have to accept elected representatives and their actions when it suits you.

But silencing the victims of educational institutions has a tradition - school expulsions for expressing one's own political opinion I still remember from my school days (not from my school - we were fortunate to have a principal with a brain who actually used it).

The fact that in this case the lawsuit also comes from a fellow student who doesn't like the political opinions expressed by the AStA - and that the reaction is a lawsuit instead of a discussion - fits the picture perfectly. After all, the formation of one's own political opinion and engagement with general political topics only distracts from being bred into a specialized idiot in the education factory...

Subway is a Python implementation of the ideas behind Ruby on Rails. So if you're afraid of hurting yourself on all the sharp and curly brackets in Ruby ...

WordPress and rel="nofollow"

On the WordPress hackers list, as expected, there's a heated discussion about rel="nofollow". The trigger: Matt has built rel="nofollow" into WordPress. Part of it is a filter that could be easily disabled. But another part is hardcoded directly into the code (for example, every author link in comments is permanently tagged with rel="nofollow"). And Matt doesn't want to build in an option, but rather force everyone, so to speak, to implement this feature.

What really bothers me about the whole thing is the absurd reasoning. Sorry, but what happens to links in my system is something essential for me as a site operator — nobody tells me what to do there. Okay, fine, I can patch my software — but the attitude toward users on this point is pretty shitty.

The ct and the Trojan Horse

You look at the front cover in the current ct and what do you see? A woman at a computer, an email with a nice Trojan horse on it. And she wants to open the gift right away by double-clicking. And with what? With good reason - because the graphic designer conveniently gave the woman a Claris Emailer Outlook Express on Mac OS Classic instead of Windows. Tsetsetse, the professional trade press, they simply did poor research

Devil's grin

(With which I join the ranks of spiteful and unnecessary "It wouldn't have happened with Mac OS X" commentators)

MDR.DE: NPD refuses minute of silence for Nazi and war victims

NPD refuses minute of silence for NS and war victims - how much longer do we have to put up with this right-wing filth in the Saxon state parliament? Can't this farce please be ended as soon as possible? Given such absurd behavior, I find it incomprehensible how the other parties can accept this and apparently even partially support it. I'm thinking of occasions where NPD representatives have actually received votes from other parties).

Microsoft lays off Windows testers and switches to automated tests instead. Tool worship has struck again. A rarely stupid idea, because automated tests only find what is automated. They lack the intuition that people (at least if they are good testers) have. But Microsoft software has never given me the impression of particularly good testing anyway...

nofollow no do

Shockwave Rider doesn't particularly like rel="nofollow" and it's come up in various other blogs too. The open letter from the S9Y developers to Google on the subject is also interesting.

I'm not particularly enthusiastic about it either - simply because it's the wrong approach. You can't repair a broken system by telling curious people to look away. Comment spammers won't be deterred one bit by the whole thing.

I can only agree with Phil Ringnalda that rel="nofollow" is something like the monster disclaimer of people on the web. Ultimately just as strange as the link distancing that many have on their websites - if you're distancing yourself, why link at all? If you're generally distancing yourself from your commenters, why have a comment function in the first place?

In any case, I won't be using rel="nofollow" - at least not by means of a large bucket that pours over everything just because it's a comment or trackback. Comment spam is addressed differently. If necessary, by putting everything in a moderation queue that then has to be cleared of spam using appropriate means - the same techniques used for email spam apply here. That's a far more worthwhile field of activity.

The Red Alt - WordPress Index Builder is a practical tool for generating a WordPress 1.5 theme online with just a few clicks. It doesn't generate the entire theme, but rather the templates and CSS. Of course, you still have to create the actual design yourself, but the basic code is already generated for you.

Struck wants to spend billions on arms projects - but local public transport is supposed to have a billion shifted to long-distance transport because there's not enough money for both. What a bunch of nonsense.

Virtualization for desktop processors - particularly interesting for server farms. Of course, this can be done today with various VMWare versions, with User-Mode Linux and a few other projects, but support in the CPU naturally makes such solutions more efficient.

Because Greed is Hot...

Deutsche Welle asks in light of the new GVL fee schedules: Goodbye, web radio? I certainly see the need for compensating artists. But what service is the GVL doing for artists when it destroys part of their market by raising fees? Especially the small web radios are known for often playing rarely heard artists.

What also bothers me about this: the fee increase comes without any form of improvement or expansion - quite the opposite, conditions are being restricted, the price raised. Paying more for less service.

So the GVL shouldn't be surprised at negative criticism, because that's normally what you call cartel abuse, price gouging, or rip-off.

WordPress : Tackling Comment Spam is a fairly comprehensive compilation of various approaches to combat comment spam and trackback spam in WordPress.

The Pope and the Rubber Bags

No Church!

The Pope still lives in his dream world: "Chastity helps prevent the spread of AIDS" - which is of course a pretty absurd position when you look at the problems in regions like Africa. There, large parts of the population cannot even engage in the sexual intercourse for procreation that the Catholic Church actually endorses without getting infected...

The Pope's stance on this issue is simply irresponsible. Especially in developing countries, the Church often has far too much influence and should be aware that people there are dying because of their nonsensical statements. You cannot counter the problems of overpopulation in such regions and the danger of AIDS infection with silly references to chastity - only education campaigns and, specifically, the promotion of condom use help.

heise online - EU Council to make another attempt at software patents

heise online - EU Council to make another attempt at software patents and continues to trample on the opinion of the population and parliaments. And our government in Berlin sits on its fat ass, greased by the economy, and does nothing. Never mind if such nonsense will cause problems for the software mid-market, never mind if it only benefits the big software giants, never mind if it's just brown-nosing America. Nobody really cares about the issue, after all it's just a bunch of software nerds making a fuss, who cares about them anyway.

And eventually even the dumbest minister will realize that software patents don't create jobs.

angry face

Despicable Idea of the Day

The Bangkok Hilton is installing cameras in the death row to publicly broadcast the lives of prisoners waiting for execution - it doesn't help that they don't plan to show the execution itself. That convicted criminals also have human rights is unfortunately repeatedly ignored. And in doing so, the state ultimately puts itself on the same level as the criminals. It is therefore not surprising that similar practices in the USA - at least in part - are already commonplace. That capital punishment itself is one of the most inhumane ideas a society can have (unlike all other common punishments, it is not reversible or at least compensable in case of error) is beyond question anyway. I cannot regard states with capital punishment (and thus ultimately a legal system based on ideas of revenge rather than protection of society) as particularly civilized...

Outlook together with Hotmail access for rent - great, so one of the two biggest virus spreaders is spreading even more than it already is.

SCO vs. Linux: SCO Gets More Material

The seemingly strange decision by the judge in the SCO vs. IBM case is — as usual — explained by Groklaw. The judge's role is not to clarify who is right — that's a different judge's job. Her job is only to ensure that all parties put all relevant material on the table. So it's solely about the investigation documents. Still, this is of course the annoying delay tactic by SCO at work. But it's not the big interim victory for SCO as one might possibly see it.

Strange Posture of Planetopia

At Spreeblick, the Planetopia journalist requested removal of the recording of the questions - what fascinates me about it: he had no qualms about publishing his distorted conclusions on air to an audience of millions. But he objects to publishing the questions he asked. Can't he take his own medicine?

The headline State ceremony for flood victims in the Bundestag is a classic proof that the German language urgently needs parentheses to define precedence

Insurance companies want access to genetic test results

Insurers Want Access to Gene Test Results. Was predictable that something like this would come. After all, it's the best way for these rip-off companies to get out of the few remaining situations where they might actually have to pay. And that's exactly what insurance is about: selling people something they're not actually willing to provide in an emergency. It's easy too, politics forces citizens to do it if necessary.

But there are no risks whatsoever in genetic engineering and building gene sample collections, and we're all just way too paranoid not to believe these liars and fraudsters. Yeah. Right. And pigs can fly.

Post 4000

Wow. This here is - in the current database - the 4000th article

erstauntes Gesicht

bigempty.com is a very nice photo blog with a very minimalist design. A nice gimmick: the background color of the footer area is based on the displayed photo - I have no idea if it's calculated automatically, but the idea is nice.

Federal Border Guard will soon be called Federal Police - wasn't there something about a ban on a federal police force for Germany? Anyway, this last line of shame is also falling.

Photos of torturing soldiers in Iraq shock the British - but will they tell their Prime Minister what they think because of it? And more importantly: will Blair finally distance himself from this madness? Or at least learn from it for the future and not participate in the Iran madness that is slowly emerging among the Americans?

Got New Spam Tactic Figured

Asymptomatic » Got New Spam Tactic Figured reports on a new tactic used by blog spammers. Relatively harmless comments appear on blogs that don't contain a single link. When spammers find these comments again via Google, they know they can likely post further comments there—bypassing the filters that automatically approve comments from visitors who have previously had a comment approved under their email address. So it could be that after a "Hey, I think your site is great" comment, a flood of blog spam suddenly appears...

Apparently stricter penalties for tailgaters planned - I think that's urgently needed too. I get upset every time we're on the motorway. It's crazy what some people allow themselves behind the wheel... (and no, we're neither chronic left-lane drivers nor slow crawlers)