<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    
    <title>blueblog - by Christian J. Dietrich - TV</title>
    <link>http://blog.cj2s.de/</link>
    <description>on malware, botnets and security by Christian J. Dietrich</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.6.2 - http://www.s9y.org/</generator>
    <pubDate>Mon, 08 Apr 2013 19:23:50 GMT</pubDate>

    <image>
        <url>http://blog.cj2s.de/templates/bulletproof/img/s9y_banner_small.png</url>
        <title>RSS: blueblog - by Christian J. Dietrich - TV - on malware, botnets and security by Christian J. Dietrich</title>
        <link>http://blog.cj2s.de/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Expert Comments on Possible Web Fraud</title>
    <link>http://blog.cj2s.de/archives/22-Expert-Comments-on-Possible-Web-Fraud.html</link>
            <category>TV</category>
    
    <comments>http://blog.cj2s.de/archives/22-Expert-Comments-on-Possible-Web-Fraud.html#comments</comments>
    <wfw:comment>http://blog.cj2s.de/wfwcomment.php?cid=22</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.cj2s.de/rss.php?version=2.0&amp;type=comments&amp;cid=22</wfw:commentRss>
    

    <author>nospam@example.com (Christian J. Dietrich)</author>
    <content:encoded>
    I gave a short interview to Sat.1 today about the technical skills needed in order to implement a system for online bets. The interview was broadcast as part of a short report on a case where maybe online fraud was involved, though this is still to be clarified.&lt;br /&gt;
&lt;!-- The video interview can no longer be found online here: &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.sat1nrw.de/Archiv/Illegales-Gluecksspiel/441d2794/&#039;]);&quot;  href=&quot;http://www.sat1nrw.de/Archiv/Illegales-Gluecksspiel/441d2794/&quot; target=&quot;_blank&quot;&gt;http://www.sat1nrw.de/Archiv/Illegales-Gluecksspiel/441d2794/&lt;/a&gt;. --&gt;&lt;br /&gt;
&lt;!-- s9ymdb:19 --&gt;&lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.sat1nrw.de/Archiv/Illegales-Gluecksspiel/441d2794/&#039;]);&quot;  href=&quot;http://www.sat1nrw.de/Archiv/Illegales-Gluecksspiel/441d2794/&quot; target=&quot;_blank&quot;&gt;&lt;img class=&quot;serendipity_image_center&quot; width=&quot;450&quot; height=&quot;253&quot;  src=&quot;http://blog.cj2s.de/uploads/2011-02-christian-j.-dietrich.sat1.serendipityThumb.png&quot; title=&quot;2011-02-christian-j.-dietrich.sat1.png&quot; alt=&quot;Christian J. Dietrich, SAT.1 interview&quot; /&gt;&lt;/a&gt; 
    </content:encoded>

    <pubDate>Mon, 14 Feb 2011 16:19:00 +0100</pubDate>
    <guid isPermaLink="false">http://blog.cj2s.de/archives/22-guid.html</guid>
    
</item>
<item>
    <title>TV interview on computer security - WDR</title>
    <link>http://blog.cj2s.de/archives/9-TV-interview-on-computer-security-WDR.html</link>
            <category>TV</category>
    
    <comments>http://blog.cj2s.de/archives/9-TV-interview-on-computer-security-WDR.html#comments</comments>
    <wfw:comment>http://blog.cj2s.de/wfwcomment.php?cid=9</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.cj2s.de/rss.php?version=2.0&amp;type=comments&amp;cid=9</wfw:commentRss>
    

    <author>nospam@example.com (Christian J. Dietrich)</author>
    <content:encoded>
    More and more police departments have special investigation teams so called cyber or computer crime units that deal with cyber crime incidents, such as stolen PIN or TANs for Online-Banking accounts or stolen credit card information. One such team was shown in the TV show WDR Lokalzeit where I was interviewed on how Jack Doe can protect himself from such harm.&lt;br /&gt;
&lt;br /&gt;
&lt;a class=&quot;serendipity_image_link&quot; title=&quot;Christian J. Dietrich zu Gast in der WDR Lokalzeit Ruhr, 26.11.2009&quot; href=&#039;http://blog.cj2s.de/uploads/2009-11-26-wdr-lokalzeit-christian-dietrich.jpg&#039; onclick=&quot;F1 = window.open(&#039;/uploads/2009-11-26-wdr-lokalzeit-christian-dietrich.jpg&#039;,&#039;Zoom&#039;,&#039;height=300,width=526,top=382.5,left=584.5,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes&#039;); return false;&quot;&gt;&lt;!-- s9ymdb:12 --&gt;&lt;img class=&quot;serendipity_image_center&quot; width=&quot;450&quot; height=&quot;251&quot;  src=&quot;http://blog.cj2s.de/uploads/2009-11-26-wdr-lokalzeit-christian-dietrich.serendipityThumb.jpg&quot; title=&quot;Christian J. Dietrich zu Gast in der WDR Lokalzeit Ruhr, 26.11.2009&quot; alt=&quot;Christian J. Dietrich zu Gast in der WDR Lokalzeit Ruhr, 26.11.2009&quot; /&gt;&lt;/a&gt; 
    </content:encoded>

    <pubDate>Thu, 26 Nov 2009 21:33:00 +0100</pubDate>
    <guid isPermaLink="false">http://blog.cj2s.de/archives/9-guid.html</guid>
    
</item>
<item>
    <title>Will Conficker destroy the world on April 1st?</title>
    <link>http://blog.cj2s.de/archives/5-Will-Conficker-destroy-the-world-on-April-1st.html</link>
            <category>Botnets</category>
            <category>TV</category>
    
    <comments>http://blog.cj2s.de/archives/5-Will-Conficker-destroy-the-world-on-April-1st.html#comments</comments>
    <wfw:comment>http://blog.cj2s.de/wfwcomment.php?cid=5</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.cj2s.de/rss.php?version=2.0&amp;type=comments&amp;cid=5</wfw:commentRss>
    

    <author>nospam@example.com (Christian J. Dietrich)</author>
    <content:encoded>
    Rumors are that one of the most widespread malware, Conficker (or Downadup) might strike on April 1st, 2009. I gave a short interview to the German TV station ARD that was partly broadcast as part of the ARD Mittagsmagazin (also broadcast on ZDF at the same time). &lt;br /&gt;
&lt;br /&gt;
To me, there is no reason to wait for a specific date such as April 1st, for a malware to become active. This is a bit different if the malware itself spreads via email, such as Storm worm, and is completely based on social engineering. Furthermore, in my eyes, system administrators are fully aware of the danger that Conficker might pose, once its activated and thus look for it with special attention on April 1st. Any other date would then - from the attacker&#039;s point of view - make much more sense.&lt;br /&gt;
&lt;br /&gt;
&lt;!-- You can watch it at the ARD Mediathek at &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.ardmediathek.de/ard/servlet/content/2006500&#039;]);&quot;  href=&quot;http://www.ardmediathek.de/ard/servlet/content/2006500&quot; target=&quot;_blank&quot;&gt;http://www.ardmediathek.de/ard/servlet/content/2006500 - &#039;Conficker&#039;-Großangriff zum 1. April bleibt aus&lt;/a&gt; (only in German). --&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class=&quot;serendipity_image_link&quot; title=&quot;Christian J. Dietrich im ARD Mittagsmagazin zu Conficker&quot; href=&#039;http://blog.cj2s.de/uploads/2009-04-01-christian-dietrich-ard-mittagsmagazin-conficker.jpg&#039; onclick=&quot;F1 = window.open(&#039;/uploads/2009-04-01-christian-dietrich-ard-mittagsmagazin-conficker.jpg&#039;,&#039;Zoom&#039;,&#039;height=415,width=735,top=325,left=480,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes&#039;); return false;&quot;&gt;&lt;!-- s9ymdb:10 --&gt;&lt;img class=&quot;serendipity_image_center&quot; width=&quot;450&quot; height=&quot;250&quot;  src=&quot;http://blog.cj2s.de/uploads/2009-04-01-christian-dietrich-ard-mittagsmagazin-conficker.serendipityThumb.jpg&quot; title=&quot;Christian J. Dietrich im ARD Mittagsmagazin zu Conficker&quot; alt=&quot;Christian J. Dietrich im ARD Mittagsmagazin zu Conficker&quot; /&gt;&lt;/a&gt; 
    </content:encoded>

    <pubDate>Wed, 01 Apr 2009 00:25:00 +0200</pubDate>
    <guid isPermaLink="false">http://blog.cj2s.de/archives/5-guid.html</guid>
    
</item>
<item>
    <title>T-Mobile G1 and Google apps</title>
    <link>http://blog.cj2s.de/archives/4-T-Mobile-G1-and-Google-apps.html</link>
            <category>TV</category>
    
    <comments>http://blog.cj2s.de/archives/4-T-Mobile-G1-and-Google-apps.html#comments</comments>
    <wfw:comment>http://blog.cj2s.de/wfwcomment.php?cid=4</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.cj2s.de/rss.php?version=2.0&amp;type=comments&amp;cid=4</wfw:commentRss>
    

    <author>nospam@example.com (Christian J. Dietrich)</author>
    <content:encoded>
    For the last 1.5 weeks I got a G1 in order to test it for the German TV Show &quot;ServiceZeit Mobil&quot; which is being broadcast on WDR. As this time, the show&#039;s topic was mobile phone security and tracking, I focused on IT security and data protection issues and found some interesting things. &lt;!-- You can watch it at &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.wdr.de/tv/servicezeit/mobil/videos/flashplayer.jsp?mid=24226&#039;]);&quot;  href=&quot;http://www.wdr.de/tv/servicezeit/mobil/videos/flashplayer.jsp?mid=24226&quot; target=&quot;_blank&quot;&gt;http://www.wdr.de/tv/servicezeit/mobil/videos/flashplayer.jsp?mid=24226&lt;/a&gt; --&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class=&quot;serendipity_image_link&quot; title=&quot;Christian J. Dietrich in der WDR ServiceZeit Mobil, 03.03.2009&quot; href=&#039;http://blog.cj2s.de/uploads/2009-03-wdr-servicezeit-christian-dietrich.jpg&#039; onclick=&quot;F1 = window.open(&#039;/uploads/2009-03-wdr-servicezeit-christian-dietrich.jpg&#039;,&#039;Zoom&#039;,&#039;height=535,width=735,top=265,left=480,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes&#039;); return false;&quot;&gt;&lt;!-- s9ymdb:9 --&gt;&lt;img class=&quot;serendipity_image_center&quot; width=&quot;450&quot; height=&quot;325&quot;  src=&quot;http://blog.cj2s.de/uploads/2009-03-wdr-servicezeit-christian-dietrich.serendipityThumb.jpg&quot; title=&quot;Christian J. Dietrich in der WDR ServiceZeit Mobil, 03.03.2009&quot; alt=&quot;Christian J. Dietrich in der WDR ServiceZeit Mobil, 03.03.2009&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
First of all, I captured some packets while using Google Maps Mobile (currently version 3). As you might know there are a couple of techniques available to geolocate a phone. First of all, modern phones have GPS receivers. GPS is probably the most accurate location mechanism. Furthermore, information about nearby &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/en.wikipedia.org/wiki/GSM_localization&#039;]);&quot;  href=&quot;http://en.wikipedia.org/wiki/GSM_localization&quot;&gt;GSM/UMTS base stations&lt;/a&gt; can be used to localize a phone. This may be combined with triangulation on the phone itself. &lt;br /&gt;
&lt;br /&gt;
Most surprising to me was the fact that the G1 also submits information about nearby Wifi base stations. Wifi cells are usually much smaller than GSM/UMTS cells and can provide more accurate results (and once location information is associated, it even provides localization in areas where GPS does not work such as in buildings or tunnels). &lt;br /&gt;
&lt;br /&gt;
But, two important questions arise:&lt;br /&gt;
a) Why does the G1 send information about Wifi and GSM/UMTS base stations, even if GPS is available and enabled?&lt;br /&gt;
b) How does geolocation work with Wifi base stations? After all, one needs to have a database with all the base stations and their corresponding location in order to use it for localization.&lt;br /&gt;
&lt;br /&gt;
I guess, there is one answer to both of them. It seems as if Google builds up its own localization database like so:&lt;br /&gt;
a) Make all users of Google Maps Mobile enable all &quot;sensors&quot;, i.e. GPS, GSM/UMTS and Wifi&lt;br /&gt;
b) Submit information from all of the sensors to Google&lt;br /&gt;
c) If there is a user that can only provide e.g. Wifi base stations around, correlate this with known Wifi base stations in the database and use the GPS or GSM/UMTS information available which was submitted by other people beforehand&lt;br /&gt;
&lt;br /&gt;
Here you can find a wireshark capture with some stuff highlighted.&lt;br /&gt;
&lt;a class=&quot;serendipity_image_link&quot; title=&quot;Wireshark capture of Google Maps Mobile&quot; href=&#039;http://blog.cj2s.de/uploads/2009-02-26-wireshark-google-maps-mobile.jpg&#039; onclick=&quot;F1 = window.open(&#039;/uploads/2009-02-26-wireshark-google-maps-mobile.jpg&#039;,&#039;Zoom&#039;,&#039;height=926,width=1015,top=69.5,left=340,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes&#039;); return false;&quot;&gt;&lt;!-- s9ymdb:8 --&gt;&lt;img class=&quot;serendipity_image_center&quot; width=&quot;450&quot; height=&quot;410&quot;  src=&quot;http://blog.cj2s.de/uploads/2009-02-26-wireshark-google-maps-mobile.serendipityThumb.jpg&quot; title=&quot;Wireshark capture of Google Maps Mobile&quot; alt=&quot;Wireshark capture of Google Maps traffic&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Apart from that, it seems as if any device using Google Maps Mobile acts in the same way as described above for the G1. &lt;br /&gt;
&lt;br /&gt;
My overall impression of the G1 is not very positive (it&#039;s a freak tool). The phone is heavy (my personal impression), however, the touchscreen works fine. All in all, I think it is not fully mature and would not recommend it. The version I tested had Android 1.0, I guess a lot could be improved by changes in the software. 
    </content:encoded>

    <pubDate>Thu, 26 Feb 2009 21:20:00 +0100</pubDate>
    <guid isPermaLink="false">http://blog.cj2s.de/archives/4-guid.html</guid>
    
</item>
<item>
    <title>Safer Internet Day 2009</title>
    <link>http://blog.cj2s.de/archives/3-Safer-Internet-Day-2009.html</link>
            <category>Botnets</category>
            <category>TV</category>
    
    <comments>http://blog.cj2s.de/archives/3-Safer-Internet-Day-2009.html#comments</comments>
    <wfw:comment>http://blog.cj2s.de/wfwcomment.php?cid=3</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.cj2s.de/rss.php?version=2.0&amp;type=comments&amp;cid=3</wfw:commentRss>
    

    <author>nospam@example.com (Christian J. Dietrich)</author>
    <content:encoded>
    On the occasion of today&#039;s Safer Internet Day, Feb 11th, the German radio station SWR broadcast an interview of a couple of IT security researchers, including me. &lt;!-- The program (in German) is available online at &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.swr.de/swr2/programm/sendungen/kontext/-/id=4352076/nid=4352076/did=4362270/lqo6w8/index.html&#039;]);&quot;  href=&quot;http://www.swr.de/swr2/programm/sendungen/kontext/-/id=4352076/nid=4352076/did=4362270/lqo6w8/index.html&quot;&gt;http://www.swr.de/swr2/programm/sendungen/kontext/-/id=4352076/nid=4352076/did=4362270/lqo6w8/index.html&lt;/a&gt; --&gt; 
    </content:encoded>

    <pubDate>Wed, 11 Feb 2009 21:00:00 +0100</pubDate>
    <guid isPermaLink="false">http://blog.cj2s.de/archives/3-guid.html</guid>
    
</item>
<item>
    <title>eBay fraud</title>
    <link>http://blog.cj2s.de/archives/2-eBay-fraud.html</link>
            <category>TV</category>
    
    <comments>http://blog.cj2s.de/archives/2-eBay-fraud.html#comments</comments>
    <wfw:comment>http://blog.cj2s.de/wfwcomment.php?cid=2</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.cj2s.de/rss.php?version=2.0&amp;type=comments&amp;cid=2</wfw:commentRss>
    

    <author>nospam@example.com (Christian J. Dietrich)</author>
    <content:encoded>
    Once more, a novel online auction scam hit eBay users just shortly before Christmas. This time, the fraudster(s) apparently first built up good reputation during some couple hundreds trouble-free auctions, but then duped buyers of (probably fake) watches by not delivering the goods. &lt;br /&gt;
&lt;br /&gt;
Indications of this fraud scheme are:&lt;br /&gt;
a) accept (preferably) payment in advance&lt;br /&gt;
b) long delivery periods by default (such as 2 weeks)&lt;br /&gt;
&lt;br /&gt;
In more detail, the fraudsters opened a whole lot of eBay auctions of watches without delivering. Rumors are that the advance payments summed up to a total amount of about 1.3 million Euros. You, as a customer, can probably best protect yourself by either using an escrow service or PayPal. I have been interviewed on this at WDR Lokalzeit Bergisches Land, today. &lt;br /&gt;
&lt;br /&gt;
&lt;a class=&quot;serendipity_image_link&quot; title=&quot;Christian J. Dietrich in der WDR Lokalzeit, 18.12.2008&quot; href=&#039;http://blog.cj2s.de/uploads/2008-12-wdr-lokalzeit-christian-dietrich.jpg&#039; onclick=&quot;F1 = window.open(&#039;/uploads/2008-12-wdr-lokalzeit-christian-dietrich.jpg&#039;,&#039;Zoom&#039;,&#039;height=445,width=735,top=310,left=480,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes&#039;); return false;&quot;&gt;&lt;!-- s9ymdb:7 --&gt;&lt;img class=&quot;serendipity_image_center&quot; width=&quot;450&quot; height=&quot;269&quot;  src=&quot;http://blog.cj2s.de/uploads/2008-12-wdr-lokalzeit-christian-dietrich.serendipityThumb.jpg&quot; title=&quot;Christian J. Dietrich in der WDR Lokalzeit, 18.12.2008&quot; alt=&quot;Christian J. Dietrich in der WDR Lokalzeit, 18.12.2008&quot; /&gt;&lt;/a&gt; 
    </content:encoded>

    <pubDate>Thu, 18 Dec 2008 20:56:00 +0100</pubDate>
    <guid isPermaLink="false">http://blog.cj2s.de/archives/2-guid.html</guid>
    
</item>

</channel>
</rss>