Posts Tagged ‘irish’

Protect yourself from CryptoLocker

Over the years the nature of computer viruses has seen a change in focus. When the earliest reported example, Creeper, first appeared back in 1971 its sole purpose was to gain access to a system and display the message ‘I’m the Creeper, catch me if you can!’. Now, with so much valuable information about us stored on our computers and web services, something far darker has emerged. Ransomware is a new class of virus / trojan horse that has begun to appear on PCs in the last few years, and it is something you should be very concerned about.

The principle of Ransomware is simple. Usually it sneaks into a system disguised as an email attachment and, if opened, then proceeds to encrypt the files on your machine. When this has completed the virus deletes itself and tells the user that their data has been taken hostage and will only be released if they pay the demanded ransom for a key. These style of attacks were first reported in Russia back in 2004, with the Gpcode trojan horse. Security analysts at Kapersky labs were able to crack the hold Gpcode had over data by exploiting mistakes the author had made in the code.

Now it’s back and this time the encryption is rock solid.

Cryptolocker

CryptoLocker is the latest Ransomware virus to strike unsuspecting users, and so far it’s proven impossible to crack. What’s more, it doesn’t just take all the data on your hard drive.

“It also searches for files on all drives,” reported Steve Gibson on the Security Now podcast, “and in all folders it can access from your computer: including workgroup files shared by colleagues, resources on company servers, and more. Anything within its reach it encrypts…so if you have hot online backups they’re victims of this. Essentially the more privileged your account is, the worse the overall damage will be.”

When all of this is completed, Cryptolocker puts up its money demand page, complete with options of payment (Bitcoins or MoneyPak), usually for around three hundred Euros. There’s also a badly worded message telling you that your files have been encrypted and that any attempt to remove the software will destroy the only key that could possibly decrypt it. In a James Bond-style moment of drama the authors place a countdown clock, normally set for 72 hours, which immediately begins to tick down to the moment your data will be destroyed forever. Photos, videos, documents, music, pretty much anything at all that is on your hard drive, all gone.

The structure of the virus is such that it’s not actually possible to create a key for the encryption, because the data needed to do so is held only by the originators of the virus.

“The RSA encryption algorithm uses two keys: a public key and a private key.” explains Kapersky lab expert VitalyK on the Securelist website.  “Messages can be encrypted using the public key, but can only be decrypted using the private key. And this is how Gpcode works: it encrypts files on victim machines using the public key which is coded into its body. Once encrypted, files can only be decrypted by someone who has the private key – in this case, the author or the owner of the malicious program.”

The removal of the virus itself is of little use to the victim, and shutting down the server that holds the key will only result in the loss of the decryption tool, plus this is difficult because the servers switch location on a weekly basis. So most people who suffer a CryptoLocker attack are given the simple advice of either paying the ransom or losing the data, but like in any hostage situation you can never guarantee that the criminals will honour their terms.

Such is the increase of the CryptoLocker attacks in the UK that the National Crime Agency released a statement from its Cyber Crime unit in which it warned:

“The emails may be sent out to tens of millions of UK customers, but appear to be targeting small and medium businesses in particular. This spamming event is assessed as a significant risk.”

The complexity and sophistication of a program such as Cryptolocker is in itself an unsettling precedent. It suggests more than a simple bedroom hacker with impressive coding skills and little conscience, but instead has traces of the fast growing underworld of professional cyber criminals.

“Something of this size…is a well organised group.” says Stephen Doherty, Senior Threat Intelligence Analyst at Symantec. “There’d be dedicated segments to this, because its such a large and focussed operation. The distribution of Cryptolocker in recent weeks is as high, or higher, than most trojans you’d see out in the wild.”

The need for resources to actually run the scam is also a clue to size of the proponents.

“There’s a lot of stages to this,” Stephen continues, “to infect so many machines on an ongoing basis, and try to process all the money in the background. You’d want a well organised team behind you.”

How to protect yourself from a Cryptolocker attack

The rise of the interconnected digital world has brought with it problems that previously existed in the physical realms. From chancers who play on the innocence of victims, up to serious organised crime that has money, skills, cruel intentions and the willingness to use them on the unsuspecting public.

Take solace though, that we do have ways to protect ourselves from these evil spectres of the web.

The first, and most obvious, is to regularly run full backups of your valuable data and then remove the drive from your computer, preferably storing it off-site. See also: How to back up your PC and laptop

Another is to create several online backups via free services such as Dropbox, Google Drive, Skydrive, etc., which usually offer versioning – and thus a way to roll back to older versions of your files.

The most important though is to never, ever open a file or link in an email or on a social website unless you’re sure it was deliberately sent by the person themselves. It may seem interesting at the time, but the results could be utterly catastrophic.

This article appeared on PC Advisor

Irish Web Design – Protect yourself from CryptoLocker

java logo drawn

Bumper security update for Java released

Bumper security update for Java released

oracle java logo

Oracle has released a bumper update package for Java that closes lots of security holes in the software.

The update fixes 51 separate security bugs in Java, which owner Oracle says is used on billions of devices.

About a dozen of the bugs were serious enough to allow attackers to take remote control of a compromised system, researchers said.

Java is one of the most popular targets for cyber-thieves and malware writers seeking to hijack home computers.

In its advisory about the update, Oracle urged customers to patch the software as soon as possible “due to the threat posed by a successful attack”.

Programming language Java has proved popular because software written with it can easily be made to run on many different types of computer.

Twelve of the holes in Java addressed by the update topped the table that ranked the severity of security weaknesses in software, wrote Qualys security expert Wolfgang Kandek in a blogpost.

If these bugs were exploited, attackers could bypass ID controls and take over a target system, he added.

He said those seeking to exploit Java would probably seed web pages with booby-trapped links in a bid to catch vulnerable machines.

Security glitches in Java are favourites among those that write and run so-called “exploit kits” that seek to compromise vulnerable websites and other systems.

Security blogger Brian Krebs said if people needed to run Java, it was well worth taking time to apply the update.

Those that did not need the software should consider disabling it altogether, he said.

“This widely installed and powerful program is riddled with security holes, and is a top target of malware writers and miscreants,” he wrote.

The update is available via the main Java website and has prompted follow-up action from other electronics firms. Apple has released an update to the version of Java that runs on its computers. This update points people towards the official version of Java from Oracle instead of that supplied by Apple.

In the past, Apple has faced criticism over the speed with which it updated its version of Java.

This article originally appeared on the BBC News website

Irish Web Design – Bumper security update for Java released

black hole

Suspected Malware Criminal Arrested

Blackhole malware exploit kit suspect arrested

Russian police have reportedly arrested a man on suspicion of masterminding two infamous hacking tools.

He is suspected of being the man behind the alias Paunch – the nickname used by the creator of the Blackhole and Cool exploit kits, sold to cybercriminals to infect web users with malware.

The Russian authorities have not confirmed the details.

But security firms said they had already detected a decline in the programs’ use.

A spokesman for the law enforcement agency Europol told the BBC: “Europol and the European Cybercrime Centre has been informed that a high-level suspected cyber criminal has been arrested.

“We can only refer you to the Russian authorities, they are the ones who should speak about this topic.”

The Russian police’s press office said it had nothing to add at this time.

However, Alexander Gostev, chief security expert at the Moscow-based internet protection provider Kaspersky Lab, said the arrest had been confirmed to him by “anonymous sources”.

Blackhole software The Blackhole kit offered an interface used to manage malware attacks

 

Spreading malware

The Blackhole kit, released in 2010, dominated the crimeware market throughout 2012 and the start of 2013, according to Fraser Howard, a researcher at the anti-virus company Sophos.

He said the code had been sold for an annual licence of $1,500 (£940) or could be rented from its creator for $200 (£125) for one week’s use, among other price plans.

The software targeted a range of vulnerabilities in the Java programming language, Adobe’s Flash media player, Windows software and PDF files.

It had two ways of doing this:

  • adding malicious code to hundreds of thousands of legitimate websites, which then copied malware to visitors computers
  • creating links in spam messages to specially created sites that infected PCs
Blackhole email
Sophos said that Blackhole was used to send links that directed users to sites that downloaded malware

Among the malware downloaded was:

  • fake anti-virus software that falsely claimed the PC was infected and urged the user to pay a fee to remove viruses
  • Trojans that attempted to steal financial records stored on the PC
  • the ZeroAccess rootkit, which downloaded other software that hijacked the PC for use in a botnet – a facility used to overwhelm websites with traffic and force them offline
  • key loggers that took a record of what was typed on the PC
  • ransomware that attempted to blackmail the PC owner

Although Mr Howard said Blackhole was once the biggest threat of its kind, he added that in recent months it had been overshadowed by rival kits, including Sweet Orange and Neutrino.

According to the researcher, the Blackhole and Cool kits put together were only involved in about 4% of all malware detected by Sophos in August, down from 28% the previous year.

The figure had since dropped to 2% in recent days, he added.

Another independent security blogger stressed that the arrest was still significant.

“If it’s true that the brains behind the Blackhole has been apprehended it’s a very big deal – a real coup for the cybercrime-fighting authorities, and hopefully cause disruption to the development of one of the most notorious exploit kits the web has ever seen,” said Graham Cluley.

“However, it’s worth remembering that nature abhors a vacuum, and there would surely be other online criminals waiting to take their place, promoting their alternative exploit kits and malicious code.”

Mikko Hypponen, chief research officer at F-Secure, agreed.

“If indeed it is Paunch that they arrested, that is a major arrest – he is a big deal,” he told the BBC.

“He was clearly the biggest player in providing exploit kits – not just by selling them, but also renting and leasing them to online criminals.

“Both Blackhole and its successor Cool have been very popular.

“Users didn’t have to be very technical to operate them – there was a manual that came with them – they just had to get them running and be able to break into a high-profile website, or create a new one from scratch, to install something bad on your computer.”

This story appeared on the BBC News Technology Section

Suspected Malware Criminal Arrested – Irish Web Design

silk road caravan

Clandestine Silk Road online marketplace closed

The value of bitcoins has dropped after the closure of the clandestine Silk Road online marketplace.

The FBI seized bitcoins worth approximately $3.6m (£2.2m) on Tuesday.

The price of a bitcoin, a virtual currency for use online, fell steeply after the arrest of suspected website administrator Ross Ulbricht.

Investor confidence may have been shaken by the association of bitcoins with illegal activity, according to a security expert.

silk-road-marketplace-seized
Visitors trying to access the Silk Road are now presented with a seizure notice

“When there’s a big bust, that’s going to knock people’s confidence in investing,” said Rik Ferguson, a senior researcher at security company Trend Micro.

“The more a currency is associated with illegal activity, the more people will be nervous about using it,” he said.

Silk Road, which allowed users to trade in illegal drugs, required transactions to be made using the virtual currency.

silk road closed down

US authorities believe that 29-year-old Ross William Ulbricht, arrested on Wednesday, is Dread Pirate Roberts (DPR) – the administrator of the notorious Silk Road online marketplace.

 

It was an underground website where people from all over the world were able to buy drugs.

In the months leading up to Mr Ulbricht’s arrest, investigators undertook a painstaking process of piecing together the suspect’s digital footprint, going back years into his history of communicating with others online.

The detail of how the FBI has built its case was outlined in a court complaint document published on Wednesday.

The search started with work from Agent-1, the codename given to the expert cited in the court documents, who undertook an “extensive search of the internet” that sifted through pages dating back to January 2011.

The trail began with a post made on a web forum where users discussed the use of magic mushrooms.

In a post titled “Anonymous market online?”, a user nicknamed Altoid started publicising the site.

“I came across this website called Silk Road,” Altoid wrote. “Let me know what you think.”

The post contained a link to a site hosted by the popular blogging platform WordPress. This provided another link to the Silk Road’s location on the so-called “dark web”.

Records obtained by Agent-1 from WordPress discovered, unsurprisingly, that the blog had been set up by an anonymous user who had hidden their location.

But then Altoid appeared in another place: a discussion site about virtual currency, bitcointalk.org.

Altoid – who the FBI claimed is Mr Ulbricht – was using “common online marketing” tactics. In other words, he was trying to make Silk Road go viral.

Months later, in October, Altoid appeared again – but made a slip-up, granting investigators a major lead.

In a post asking seeking to find an IT expert with knowledge of Bitcoin, he asked people to contact him via rossulbricht@gmail.com.

With a Gmail address to hand, Agent-1 linked this address to accounts on the Google+ social network and YouTube video site. There he discovered some of Mr Ulbricht’s interests.

Among them, according to the viewing history, was economics. In particular, Mr Ulbricht’s account had “favourited” several clips from the Ludwig von Mises Institute, a renowned Austrian school of economics.

Years later, on the Silk Road discussion forums, Dread Pirate Roberts would make several references to the Mises Institute and its work.

Covering tracks

According to the court complaint document, it was the discovery of the rossulbricht@gmail.com email address that gave investigators a major boost in their search.

Through records “obtained from Google”, details of IP addresses – and therefore locations – used to log into Mr Ulbricht’s account focused the search on San Francisco, specifically an internet cafe on Laguna Street.

Furthermore, detailed analysis of Silk Road’s source code highlighted a function that restricted who was able to log in to control the site, locking it down to just one IP address.

As would be expected, Dread Pirate Roberts was using a VPN – virtual private network – to generate a “false” IP address, designed to cover his tracks.

Google Streetview image of Hickory Street, San Francisco
Mr Ulbricht said to have been running Silk Road from Hickory Street in San Francisco

However, the provider of the VPN was subpoenaed by the FBI.

While efforts had been made by DPR to delete data, the VPN server’s records showed a user logged in from an internet cafe just 500 yards from an address on Hickory Street, known to be the home of a close friend of Mr Ulbricht’s, and a location that had also been used to log in to the Gmail account.

At this point in the investigation, these clues, investigators concluded, were enough to suggest that Mr Ulbricht and DPR – if not the same person – were at the very least in the same location at the same time.

Fake IDs

The court complaint went into detail about further leads that followed.

In July of this year, by coincidence, a routine border check of a package from Canada discovered forged documents for several fake identities all containing photographs of the same person.

It was headed to San Francisco’s 15th Street. Homeland security visited the address, and found the man in the photographs – Mr Ulbricht.

He told officers that the people he lived with knew him simply as Josh – one housemate described him as being “always home in his room on the computer”.

Around the same time, investigators working on the Silk Road case later discovered, DPR had been communicating with users privately to ask for advice on obtaining fake IDs – needed in order to purchase more servers.

Further activity attributed to Mr Ulbricht took place on Stack Overflow – a question-and-answer website for programmers – where a user named Frosty asked questions about intricate coding that later became part of the source code of Silk Road.

In another apparent slip-up, one of Frosty’s messages initially identified itself as being written by Ross Ulbricht – before being quickly corrected.

“I believe that Ulbricht changed his username to ‘frosty’ in order to conceal his association with the message he had posted one minute before,” lead prosecutor Christopher Tarbell wrote in court documents.

“The posting was accessible to anyone on the internet and implicated him in operating a Tor hidden service.”

HOW BITCOINS WORK

Bitcoin is often referred to as a new kind of currency.

But it may be better to think of its units as being virtual tokens that have value because enough people believe they do and there is a finite number of them.

Each bitcoin is represented by a unique online registration number.

These numbers are created through a process called “mining”, which involves a computer solving a difficult mathematical problem with a 64-digit solution.

Each time a problem is solved the computer’s owner is rewarded with bitcoins.

To receive a bitcoin, a user must also have a Bitcoin address – a randomly generated string of 27 to 34 letters and numbers – which acts as a kind of virtual postbox to and from which the bitcoins are sent.

Since there is no registry of these addresses, people can use them to protect their anonymity when making a transaction.

These addresses are in turn stored in Bitcoin wallets, which are used to manage savings. They operate like privately run bank accounts – with the proviso that if the data is lost, so are the bitcoins contained.

Price drop

News of the closure was followed by a rapid drop in the price of bitcoins, according to figures from the Mt. Gox bitcoin exchange.

The going rate for the virtual currency dropped from more than $140 (£86) to around $110, before climbing back up to $123 (£75).

Investors may have been concerned about the FBI’s ability to confiscate bitcoins, said Mr Ferguson.

“Knowing that a currency could be seized or shut down could pressure people to look for alternative investment vehicles,” he said.

The FBI seized the virtual currency by getting hold of encryption keys for the bitcoins, according to Jerry Brito, George Mason University’s technology policy director.

The keys were made available through seized computer equipment, Mr Brito said in a blog post.

The FBI then transferred the bitcoins to an address controlled by the US government, according to the seizure order.

The content of this article originally appeared on the BBC News website and BBC News Technology

Clandestine Silk Road online marketplace closed – bitcoin seized – Irish Web Design

Royal Baby Nursery

Royal Baby Malware Attacks

Scammers wasted little time after Prince William and his wife, the former Kate Middleton, announced the birth of their son, who’s now third in line to the British royal throne.

Royal Baby

“Because it is such big news, it didn’t take long for malicious elements to misuse it,” said Kaspersky Lab security researcher Michael Molsner in a Wednesday blog post, noting that the company’s spam traps had already intercepted an email promising regular “Royal Baby” updates.

The message also included a “watch the hospital-cam” link, which appeared to resolve to a legitimate site that had been compromised.

Although the site appears to have since been cleaned, it was serving malicious JavaScript files designed to infect browsers with the Blackhole infection kit.

Irish Web Design –  Royal Baby Malware Attacks

This story appeared on the Information Week Website

kimberley cookies

Irish Cookie Regulations

Irish Cookie Regulations – Update

This article was writted by Philip Nolan, Head of Commercial Law Department and Partner MH & C and Oisin Tobin, trainee, MH & C. Philip Nolan is a Partner in the Commercial Contracts and Outsourcing Department at Mason Hayes & Curran.

kimberley biscuits cookies

The Irish Regulations transposing the new European rules on cookies have come into force. While website operators will need to exercise care to ensure that they are complying with the new regime, these new rules are less onerous and disruptive than originally anticipated.

Cookies, or small items of code placed on a user’s computer by a website, are vital to the functioning of the modern web. Cookies allow website operators to determine how users browse their sites and are a technical prerequisite for the operation of more advanced websites, such as those which require their users to log-in. Cookies can also be used, more controversially, to monitor user behavior for the purpose of targeting advertisements.

The rules governing cookies are being overhauled across Europe at present due to an EU Directive adopted in 2009. While all Member States are obliged to implement the Directive, they are given a certain degree of freedom as to the exact manner in which they chose to do so. The Irish measures which implement the Directive, and which have just come into force, seem to minimize the potential negative impact of the Directive for websites and web businesses based in Ireland.  As a result, it would seem that the new Irish regime may prove to be an additional attraction to international web based businesses considering Ireland as their EU base.

Under the new regime, all websites must have user consent before they place a cookie onto the user’s computer.  The Irish rules do not require that this consent be explicit and therefore, it would seem that consent may be implied.  In addition, they must provide the user with clear, comprehensive, prominently displayed and easily accessible information about the cookie, particularly as to its purpose. While this regime is somewhat tougher than the previous rules, which required that websites give a user the ability to “opt-out” of the cookie being used, these new rules contain a number of provisions which should ensure that websites can become compliant without having to radically overhaul their design.  The regulations note that the methods of providing information and giving consent should be as user friendly as possible. In certain circumstances users may be able to give consent via their browser settings and many consider that the use of browser settings for consent may become a popular means of managing consents. Cookies which are technically required to operate the site are exempt from these new rules.

Notably, a provision in an earlier draft of the Irish regulations, prohibiting the current practice of providing the relevant disclosures about cookie use in a privacy policy, has not made it into the final regulations.   This means that privacy policies may continue to be used, once user friendly and prominently displayed, to provide information about cookies in compliance with the new rules.

In summary, it would seem the Minister for Communications has struck quite an effective balance between the privacy concerns of web users in relation to the use of cookies and the concerns of industry in relation to over-regulation of the internet.

Attribute to Philip Nolan, Head of Commercial Law Department and Partner MH & C and Oisin Tobin, trainee, MH & C. Philip Nolan is a Partner in the Commercial Contracts and Outsourcing Department at Mason Hayes & Curran. For more information, please contact Philip at pnolan@mhc.ie or + 353 1 614 5000. The content of this article is provided for information purposes only and does not constitute legal or other advice. Mason Hayes & Curran (www.mhc.ie) is a leading business law firm with offices in Dublin, London and New York. © Copyright Mason Hayes & Curran 2011. All rights reserved.

Irish Web Design – Irish Cookie Regulations

Gremlins poster

The dreaded Blackhole Exploit Kit is back

The dreaded Blackhole Exploit Kit is back!

Gremlins attack websites

The last week has seen a resurgence of this malicious software appearing on websites around the globe.

Visitors to the sites who have AVG Anti Virus software installed on their systems receive a warning about the infection.

Website owners who do not act quickly to deal with the infection and clean up their websites may find Google blocking access to their websites.

The Blackhole Exploit Kit and it’s many variations was developed by some of the most skilled computer criminals in the world.

It is thought that these gangs originate in Russia or Eastern Europe.

The Blackhole exploit kit is now the most prevalent web threat globally.

The criminals make the software available as a kit on an outright sale or licence basis and each version is tweaked to suit the ‘end user’ criminal’s particular purposes.

In general, the kit uses hidden code to analyse the software on the computer it attacks to find any vulnerabilities.

When it finds some software which can be exploited, it will then run another piece of software, which often in the form of a pop up window.

This appears to be a warning about a malware or virus infection when in point of fact, it is a malware!

The  computer is now under ‘remote control’ by the hackers, who can return and take over running the machine at any time.

What is particularly worrying about this infection is that there is at present no ‘magic bullet’ or simple cure.

Irish Web Design – the dreaded Blackhole Exploit Kit is back AKA Black hole exploit kit.

microsoft logo as medallions

FBI and Microsoft move in on Internet Criminals

FBI and Microsoft move in on Internet Criminals

american fbi logo

American FBI and Microsoft shut down the €375m theft botnet known as Citadel

The American FBI and Microsoft have cooperated in order to break up a massive network of hijacked home computers that have been responsible for stealing more than €375m from bank accounts around the globe.

The Citadel network was set up by a group of criminal gangs who remotely installed a keylogging program on upwards of five million machines in order to steal data.

About 1,000 of the 1,400 or so networks that made up the Citadel botnet are believed to have been shut down.

Co-ordinated action in 80 countries by police forces, tech firms and banking bodies helped to disrupt the network.

“The bad guys will feel the punch in the gut,” Richard Boscovich, a spokesman for Microsoft’s digital crimes unit said.

Control code

The cybercriminals behind Citadel cashed in by using login and password details for online bank accounts stolen from compromised computers.

This method was used to steal cash from a huge number of banks including American Express, Bank of America, PayPal, HSBC, Royal Bank of Canada and Wells Fargo.

Citadel emerged after core computer code for a widely used cybercrime kit, called Zeus, was released online.

Underground coders banded together to turn that code into a separate cybercrime toolkit that quickly proved popular with many malicious hackers.

In a blogpost detailing its action, Microsoft said Citadel had also grown because malicious code that could take over a PC had been bundled in with pirated versions of Windows.

The millions of PCs in the criminal network were spread around the globe, but were most heavily concentrated in North America, Western Europe, Hong Kong, India and Australia.

Despite the widespread action, which involved seizures of servers that co-ordinated the running of Citadel, the identity of the botnet’s main controller is unknown.

However, Microsoft has started a “John Doe” lawsuit against the anonymous controller, believing him to use the nickname Aquabox and be based in Eastern Europe.

In addition, the FBI is working with Europol and police forces in many other countries to track down and identify the 81 “lieutenants” that helped Aquabox keep Citadel running.

Microsoft has also started action to help people clean up an infected computer.

Typically, it said, machines compromised by Citadel were blocked from getting security updates to ensure those computers stayed part of the botnet.

With the network disrupted, machines should be free to get updates and purge the Citadel malware from their system.

FBI and Microsoft move in on Internet Criminals – Irish Web Design From an article on BBC News

Captcha Security Check Image 2

Is Captcha security a good idea?

Captcha security test questioned

Is Captcha security a good idea? is a question has been raised as a result of problems with a White House petition.

The fact that Ticketmaster dumped the Captcha from their website casts further doubt on the need for this security measure.

 

Captcha Security Check Image Is Captcha security a good idea?
Captchas can be used in a graphic and in an audio form but both can be difficult to interpret

Is Captcha security a good idea?

The National Federation for the Blind in the USA has stated that its members are unable to sign an e-petition which is collecting support for demands that printed material should be more accessible to those who are visually impaired because of “Captcha” security on the website.

A Captcha is a graphic of a random word or numbers users must key in to show that they are human.

There is an equivalent audio version on most websites that feature the Captcha.

Captcha comes from ‘Completely Automated Public Turing Test to Tell Computers and Humans Apart’, so one could argue its two or three t’s short of an accurate Acronym.

The White House Washington USA Logo

The White House Washington USA Logo

The White House whose website it is says that it complies with official US accessibility standards although it has received just 8,200 signatures.

Chris Danielsen of the American Federation for the Blind said “We had asked people to sign the petition and we’re getting these emails saying that people can’t”

He told the Politico website that he realised there was a problem after he began publicising the petition.

The editor of the BBC’s ‘Ouch’ blog (for people with disabilities) Damon Rose said that “Captcha graphics are a nightmare – visually impaired people use screen readers to interpret their computer rather than their eyes and the screens can’t manage them.

“Ironically if I see an audio capture I tend not to bother with it because it’s usually such a poor experience… some of them sound like aliens talking and they put weird background noises over them. They are a bit of a joke in the blind community. I’ve spent half an hour on some and had to give up.”

Mr Rose added that a result of this was that many visually impaired people found that, on messageboards and blogs they could not contribute to discussion and debate.

ticketmaster logo

ticketmaster logo

Earlier the year Ticketmaster the international event ticket service removed the Captchas from its sales website.

Aaron Young of Bunnyfoot, the user experience consultancy said “It is generally speaking the one of the most hated pieces of user interaction on the web,”

In the view of Irish Web Design it is worth weighing up the value of the added security versus the irritation to users that Captcha causes.

Your business may be losing customers who simply give up when confronted with the frustration of a difficult to read Captcha.

So in response to the question: ‘Is Captcha security a good idea?’ Irish Web Design feels that in many cases it is not necessary, and therefore is not a good idea.

Captcha Cartoon Is Captcha security a good idea?

Captcha Cartoon

This article uses material that originally appeared on the BBC News Website

Is Captcha security a good idea? – Irish Web Design

American Cowboy

Your Domain Name Robbed

Irish Web Design issued a warning this week as yet another client had his preferred domain name robbed from under his nose.

highwayman stand and deliver

We were in the process of securing the preferred .ie, .net and .com domains our client had settled on. It came as a nasty surprise to discover that the rather unusual  .com domain name had been registered just days previously.

It transpired the client had been checking possible names for his new website some days previously and checked the preferred option on one of the many sites that appear at the top of Google.

There are many stories on the internet where people claim that the giant American company godaddy.com engage in this practice.

It appears that as soon as he logged out of the site automated software registered the domain name he was searching for.

The company who registered the site have no use for it, but they now own the name the client wanted.

The domain is available but first the client would need to appoint a company to negotiate for him, which is $69 to start with. Then he has to state in advance how much he is willing to pay. It is not uncommon for companies to demand thousands of Euro in order for them to hand over “your” name. If successful the ‘agent’ then adds another 10% on  top

Back in the days of the James brothers you knew you were dealing with robbing low-life bandits, but this form of robbery is corporate extortion on a massive scale.

You have no idea what the connections are between the agent, the company who registered the site and the company on whose site you first carried out the search.

The only thing you can be certain of is that you have been well and truly screwed.

The moral of the story?

Under no circumstances should you check the availability of domain names unless you know exactly what you are doing.

If you fail to heed this advice it may end up costing you thousands of Euro as you are subjected to information highway robbery.

american bandits

Your Domain Name Robbed an article by Irish Web Design

 

Visit Us On TwitterVisit Us On FacebookCheck Our Feed