Choose Your Theme
Warren Shea

P@$$words

Wednesday, May 4th, 2011 at 1:37 pm

The recent PSN (Playstation Network) and SOE (Sony Online Entertainment) hacks have been bad. Bad for the average user that uses these things (me), very bad for the users that have purchased things over these channels (me), and very very bad for Sony. But I have little sympathy for them as creating something to hold this information needs the support and security around it to prevent that kind of stuff. While PSN isn’t a paid service (and thus, not directly revenue generating, as opposed to say, XBOX LIVE), I would imagine that they should definitely have had the financial means and resources to prevent against whatever security hole was used.

That said, I work for a large corporation and while we have group(s) dedicated to security, I don’t know how they would fare to the creative hacker. In a recent discussion with a security minded person, he recently told me that he teaches people to hack. My original thought was “as a security expert, why teach people to hack? It seems to enforce what you’re trying to prevent.” but the answer was quite obvious. He said “by teaching how to hack, it helps a developer to develop more secure code”. Duh. Now, I’ve never been one to hack. I mean, truly hack. I can do some creative things with my given skills but I’m not one who knows about <insert what I don’t know about hacking keywords>. I know how SQL Injection works…and thus, I know to code to prevent that type of exploitation. But I don’t know how <hacking method x> works, and thus, can’t code against it.

I’m always up for learning new things, and learning how to hack better is definitely something new on my list. Not to do something malicious, heavens no!. But to become a better developer. Now is a good a time as any to take the first steps towards learning something new.

Anyways, the intention of this post was to discuss passwords. Given the recent exploitation, I’ve been forced to re-evaluate all my passwords. Granted, I’ve been meaning to do this for a while, but this actually gave me a pretty good excuse. While it’s a security risk introducing the following topics, I’ll try to stay vague and not give anything away that could potentially hack me.

I’ve finally made different passwords for everything. I’ve always avoided this because of the obvious limitations to my memory. I used to have about….5-10 passwords which I used for everything. They varied from “password” to “I don’t care if this gets hacked” to “This is my godly, unbreakable password!” but as I sign up for stuff, reusing certain passwords, the passwords blurred. I had “I don’t care if this gets hacked” passwords for important stuff, and “This is my godly, unbreakable password!” for unimportant stuff. This has become a problem.

Up until recently, there was something I hadn’t considered regarding the security around signing up for things. When I would sign up for stuff, I would submit my email, my username, and a desired password. To keep things simple, my desired password would often be my email password. What a ridiculously stupid oversight. Generally, when you sign up to sites, you think they have a secure system. You hope they do. Password hashcodes, security precaution x and y. But what if they didn’t? As the user, you’re no wiser to their infrastructure or security. Suppose they simply had a table with


EMAIL Username Password
warren.shea [ a t ] gmail.com warrenshea password


and what if the system admin or whoever, just viewed the table and BAM!, gets the email and a password. Granted, it’s the email, username and password for the site they’re the admin of. But technically, that person could try that combination of email and password to “hack” in to the email account. Now, I don’t know what the percentage of people that do this is…but I’m fairly paranoid and even I did it. Granted, I’m quite stupid as well…so it’s hard to say. Still, I imagine that you could probably hack in to 10-20% of the emails….and that’s a lower estimate. I would guess you’d get in to 80% of them. People just can’t remember that many passwords so they reuse them. Again, it wasn’t too much of an issue as I would sign up for stuff with my “bad password” while my email had my “good password” but again, sometimes I’d get stupid or careless.

There’s also the problem that my “This is my godly, unbreakable password!” has certain characters that aren’t allowed by sites. A good site will allow dIFFerEnT cAseS, NUMB345, and C#@RACTERS. But some don’t. And I have to use “I don’t care if this gets hacked” passwords for important stuff….because the system won’t allow a good, secure password. In 2004, I actually had an email rant to Rogers because I couldn’t change my password to the one I wanted….they wouldn’t allow special C#@RACTERS. Sh!tty system.

.
.
.

Anyways, that’s gone now. I’ve modified all my passwords to be something different for each and every thing. Getting “PASSWORD A” will not give you any other access except to “SECTION A”. And that’s how it should be, I’ve just been too lazy to realize and change things. But improving your own security is the first step to becoming secure yourself. Better to fix things like this early than get hacked somewhere down the line for signing up with “I just wanted to download this one thing!” site….but obviously you wouldn’t know which site hacked you because you’re a password reusing fool, so it could be a number of them. Also, you’d have more important problems to deal with…figuring out how to fix things rather than figuring out why you were hacked and who did it.

Now, please watch this informative video on safety best practices.

WTB#7 – May 2011 Edition

Monday, May 2nd, 2011 at 10:02 pm

Things I’m expecting in May – Total $600.07


Rebuild of Evangelion Makinami Mari Illustrious 1/6
$177.00 – Price I Paid (total)
Ordered Apr 26, 2011
Purchased at eBay.ca
GUILTY GEAR XX – Dizzy – Alter
$155.98 – Price I Paid (total)
Pre-orderered Feb 22, 2011
Ordered April 30, 2011
Release Date Apr 2011
Purchased at Kid Nemo
Kotobukiya DC Comics: Wonder Woman Bishoujo Statue
$51.99 – Price I Paid (total)
Pre-orderered Feb 22, 2011
Release Date April 2011
Purchased at The Big Bad Toy Store
Roll (Plastic model)
$46.13 – Price I Paid (total)
Pre-Ordered Feb 19, 2011
Release Date May 2011
Purchased at Hobby Search
DCUO: Wonder Woman Statue
$76.99 – Price I Paid (total)
Pre-orderered Feb 22, 2011
Release Date Feb 2011
Purchased at The Big Bad Toy Store
Kotobukiya Marvel Comics: Ms. Marvel Bishoujo Statue
$51.99 – Price I Paid (total)
Pre-orderered Feb 22, 2011
Release Date April 2011
Purchased at The Big Bad Toy Store
D-Arts: Mega Man X
$39.99 – Price I Paid (total)
Pre-orderered Jan 8, 2011
Release Date May 2011
Purchased at The Big Bad Toy Store

Things I received in April – Total $1040.21


Adam Hughes – Wonder Woman Statue
$214.08 – Price I Paid (total)
Ordered Apr 25, 2011
Received Apr 29, 2011
Purchased at eBay.ca
8″ Disney Toy Story 3 Peas in a Pod Bean Bag Plush
$17.37 – Price I Paid (total)
Ordered Apr 14, 2011
Received Apr 27, 2011
Purchased at eBay.ca
Smashing Magazine Book 1 + Book 2
$53.30 – Price I Paid (total)
Ordered Apr 13, 2011
Received Apr 27, 2011
Purchased at Smashing Magazine
Kotobukiya Marvel Comics: Black Cat Bishoujo Statue
$65.78 – Price I Paid (total)
Pre-orderered Feb 22, 2011
Release Date Feb 2011
Received Apr 27, 2011
Purchased at The Big Bad Toy Store
DC Unlimited World of Warcraft Deluxe Collector Figure: The Lich King: Arthas Menethil
$56.68
Preorder – Purchased Feb 18, 2011
Release March 9, 2011
Received April 25, 2011
Purchased at The Big Bad Toy Store
Battle Chasers Anthology S&N Limited Edition HC – 183/250
$103.69 – Price I Paid (total)
Preorder – Purchased Feb 9, 2011
Received Apr 14, 2011
Purchased over Amazon.ca
1 GB WDTV Live Hub
$192.09 – Price I Paid (total)
Ordered Apr 10, 2011
Received Apr 13, 2011
Purchased at Dell.ca
RAH DX Gundam Seed Destiny Lacus Clyne PVC Set
$134.21 – Price I Paid (total)
Ordered Apr 2, 2011
Received Apr 11, 2011
Purchased at eBay.ca
Gundam Seed Destiny RAH DX Lacus Clyne PVC Statue
$137.23 – Price I Paid (total)
Ordered Apr 2, 2011
Received Apr 8, 2011
Purchased at eBay.ca
Kotobukiya DC Comics: Catwoman Bishoujo Statue
$65.78 – Price I Paid (total)
Pre-orderered Feb 22, 2011
Received Apr 4, 2011
Purchased at The Big Bad Toy Store

Accomplishments #7 – May 2011 Edition

Sunday, May 1st, 2011 at 11:33 pm
What I accomplished in April

Shows / Movies
ReBoot (entire series)

Books & Manga
Battle Chaser Anthology

warrenshea.com
Major Updates!

Gaming
Zelda: Ocarina of Time (N64)

Web Development and Design

Other

Notes
One of my better months…not only did I finish a game in which I’d been wanting to play for over a year, but I also did some major updates on warrenshea.com. The only thing that’s missing is some .NET and maybe some reading for some books….

What I want to accomplish in May

Shows / Movies
House (entire series) – In progress – S04E08 and catching up…
Neon Genesis Evangelion (entire series) – In progress – Regular Series, D&R and EOE finished….just have REBUILD left 2/4 movies!

Books & Manga
Azumanga Daioh – To Do

warrenshea.com
Clean up my code a bit
Fix Old Themes

Gaming
Either
– Finish Zelda: Majora’s Mask (N64) – To Do (after House)
or
– Finish Kingdom Hearts (PS2) – To Do (after House)

Web Development and Design
Start Smashing Magazine Book 1
Start Smashing Magazine Book 2
Start ASP.NET 4.0 book
Start my HTML5 book

Other
Learn my Mac OS

Notes
I wouldn’t be surprised if I accomplish very little this month. I’ve got a weekend bachelor party and a wedding….and my birthday….and a whole lotta work….this might be one of my busiest months but I also need to stay healthy and energized, despite recent allergies making me ridiculously tired all the time…anyways, we’ll see how it plays out. I’ll be happy if I can finish a game by end of the month

Solving the mystery killed her

Wednesday, April 27th, 2011 at 10:31 pm


This picture. I loved it for 10 months.

I ordered an iPhone case of it. I got it today, along with 3 other things: Kotobukiya Marvel Comics: Black Cat Bishoujo Statue, Smashing Magazine Book 1 + Book 2, and 8″ Disney Toy Story 3 Peas in a Pod Bean Bag Plush


The Peas in the Pod are so cute! This plushie, which cost about $20 including shipping, used to go for $50 to 80 to 100 right after Toy Story 3 came out. I almost bought it for $50 but thank goodness I didn’t.

Anyways…this girl…after I solved the mystery, after I found a high res. picture, I no longer care for her. It’s no longer my iPhone background as of earlier today. There was something about the mystery of her. Where she came from. The picture I had was LQ so I couldn’t see the details, it was blurry. Not knowing was part of what made her beautiful. Like I said before, regarding the beauty of the Venus de Milo, part of the beauty is the mystery. What were her arms doing? What did they look like? She’s incomplete…and people can’t figure it out which makes it nag on their minds. They think it’s beauty, they think they’re captivated by it…but it’s really just their subconscious trying to put the puzzle together. Okay, that was an over-exaggeration. Maybe there’s a little beauty.

But anyways…sadly, I’ve lost quite a bit of interest in my used-to-be mystery girl. I have a new crush: this chick.

Mari Makinami

She’s got the glasses. She pilots a giant robot. She…um…I don’t know much else except that she’s a new, awesome character from Evangelion 2.0: You Can [Not] Advance Edit: (which has some stellar animation)(which has the best animation I’ve EVER seen…EVER!). She’s taken over my iPhone wallpaper as of today. I ordered this a few days ago…


I CAN NOT wait for it to come… :D

Daily Randomness…a no point post. But good music.

Wednesday, April 27th, 2011 at 7:48 pm


D-Arts Zero became available for pre-order today…so guess what I did ;)

Which led me to start singing this song (also my iPhone ringtone)
Megaman 9 – Intro Theme

Which led me to start singing this song (they’re kinda similar)
BoA – Valenti (JAP)

Which led me to start YouTubing BoA Videos
BoA – Waiting (JAP)

BoA – Jewel Song (JAP)

I used to like BoA so much in early university…her old music still holds up I find….haven’t heard any of her new stuff but I don’t imagine I’d like it. Artists have to evolve to stay current, despite that fans enjoy what made them popular in the first place. People want and expect something new but complain when the style is different from what they’re used to. People are such idiots.

Anyways…will write more tonight…maybe