Diablo III a lesson in system requirements. . .

Diablo III logo
When I preordered Diablo III, I knew it required an internet connection.  I figured this was for additional online content, updates, etc.  What i was not prepared for was the harsh reality that if battle.net is down, i cannot play.  This is not a MMORPG, this is a single player game and the entire game is stored on my laptop.  Years ago, i remember playing Diablo II on my laptop at school, airport terminals, and even in airplanes.  (these were the days before in flight wifi)  It is unfortunate that Blizzard’s fear of piracy has lead them down a path of poor user experience for their paying customers (in this case prepaying).  Better still is the fact that it is very doubtful that this will even stop piracy of the game.  Already users of bootlegged versions of this game are able to play without purchase, authorization, or even network connectivity.

The truth is that today is launch day, and there are undoubtably piles of problems to be resolved with the game.  Hordes of users log on to play, the servers can get overwhelmed.  I just feel that users should be able to enjoy most of the game without connecting to battle.net.  Game makers need to understand that sometimes people want to play offline. My favorite example, what can you play when the internet is down?  The list is getting shorter every year.  Wake up Blizzard.  If you cannot provide an excellent user experience with copy protections, you may want to rethink your priorities.  Is it more important to continually infuriate customers or temporarily frustrate pirates?

Update Java. Seriously, do it right now.

20120405-000044.jpg
Another Java privilege escalation exploit spotted in the wild. Trojans and web based java classes are already installing remote access tunnels into Macs across the globe. Apple finally updated their java binaries and you should too! Protect yourself! Just run Software Update from the Apple menu.

Apple Info:
http://support.apple.com/kb/HT5228

More info (including a AppleScript test for infection):
http://mashable.com/2012/04/05/mac-flashback-trojan-check/

Updates keep the SSL boogiemen at bay.

all the ssl blacklists are updates. we can return to thinking we are safe. Apple included the patches in a Security Update, Firefox updated to 6.0.2. Jailbroken iOS users can update or install “sslfix” in Cydia to get the protections that apple has yet to release.

After watching Moxie’s BlackHat talk, we seriously need to fix SSL. It is holding up too many technologies to be this insecure.

LulzSec Declares War on Obama’s Hacking Crackdown!

lulzsec ascii logoTheir recents exploits include hacking FBI affiliate Infragard (Atlanta Chapter).  They defaced the website, stole account information, and messed with their users.  Particularly Karim Hijazi of Unveillance.  LulzSec alleges that Karim (in a chat on IRC) offered them money and information to hack and his competition in the security industry.  This kind hypocritical behavior is specifically deplored by hackers.  Hijazi’s company email was posted online and in LulzSec’s official statement they threaten the release of his personal email as well.  LulSec started taking donations with BitCoin.  They used some of the money to pay for servers and their “lulzsecurity.com” domain which appears at present to be down.

Mac Defender is annoying users trusting enough to type their passwords!

A bit of ransom-ware by the name of Mac Defender is exploiting a default setting in safari that will automatically launch any installer package that you download. It still requires the user to go through the steps of installing the software including entering their administrator password. Apparently this hasn’t prevented hundreds of users from installing the bogus software. It seems to do nothing but pop up ads and messages to lure the user to pay $79.99 to remove the infection. Easy, free removal instructions are available here. But let this be a lesson. Don’t type your password if you don’t know why it is asking for it. Don’t install things you didn’t know you downloaded.

anonops.net Hacked! Users Unmasked!

anonymous doesn't like to be unmaskedyesterday, anonymous’s irc server was hacked and user’s ip addresses and private messages were posted here. Looking at the logs, it is clear to me that many of their users use proxies, VPNs, or some other way to obscure their actual address. It is doubtful that any serious hacktivists were actually unmasked. With rumors of an internal conflict within anonymous ablaze online, it is still unclear who was responsible or when their operations will be back online.

UPDATE:
here was https://sites.google.com/site/lolanonopsdead/ and it’s since offline.