Journaling on estrip is easy and free. sign up here

Paul's Journal

paul
My Podcast Link

12/21/2011 20:03 #55784

Android Lync Chat Client - Data Security Danger
Category: mobile
I was playing around with the microsoft lync client for android today when I discovered just how insecure the data from your chats are on your phone. I can't understand how it could be allowed in a very controlled corporate environment like you would find in banking, healthcare, etc.

Microsoft admits freely that the conversation history is stored on the device.

What they don't say is that basically, the client stores all of the chats you have a in sqlite database that is pretty much plain text accessible.

Using the android development toolkit and grep (basic free tools) I was able to locate the lync data store on the phone at /data/data/com.microsoft.office.lync/

You can easily pull it off you adb connected device with this. It will grab the data and put in a directory on your local computer called lync.
adb pull /data/data/com.microsoft.office.lync lync


Say you send someone a message with secure data e.g. "the secret pin for my bank account is 1234"

Then someone steals your phone, adb shell into the phone copy the data over the computer or an sd card for safe keeping.

then they can extract whatever they want.
grep -r -a secret com.microsoft.office.lync/databases/DataStore.sqlite
and two minutes later they find


"the secret pin for my bank account is 1234"

So what that it might have a little binary content on either side.

Not only that but lets say you are the investigative, computer type - the app lets you send off any conversation as an email. So any app that accepts email intent (gmail, mail, text messaging, etc) accepts the content and passes it from that app to the world at large. If you have any special controls over your corporate exchange, like outgoing filters to look for sensitive data, they get bypassed going out through something pretty insecure like plain text email or text messaging.

I can see how they wanted to side with convenience. At the same time I can't understand how this can appeal to the customers they tend to appeal to most (government and big business). Why would they not encrypt this data on the phone at least.

paul - 06/05/13 20:30
Actually reinvestigating this, what is worse is the spell correct suggestion in the android keyboard. I could get it to pretty much retype my conversations as suggestions by just continuously selecting the choice it wanted me to go with, without typing anything. The other day I get the email address and contact info of a top level exec plus my security review of another situation all by just pressing the spelling suggestion over and over.
tinypliny - 12/22/11 10:46
I see a future in world spy-network domination right here.
heidi - 12/22/11 00:07
All chats? gchat? or Lync chat in particular?

12/21/2011 19:44 #55782

Ipad vs andoid ssh client
Category: mobile
The ssh clients on the ipad/iphone have so many less ratings than on android. It makes me wonder if really not that many developers use the ipad/iphone compared to android. I mean the top ssh client on the iphone which also does rdp has less than 100 ratings while the one on android has 23,000+ and over 1,000,000 downloads. The ipad app store doesn't list number of downloads. Hopefully, I can get work to reimburse me.

image

image

The issh app seems to be pretty great. Having all of that extra space to type and have keyboard vs on the iphone/samsung galaxy sii makes a huge difference. Work has disabled my ability to take screenshots on the ipad as a "security precaution" so I have to keep taking pictures of it instead.
image

Here is a video someone did about using issh

paul - 12/21/11 20:05
Yes, that was last week, lol. No seriously I want an android tablet so bad. If my work did those I would have gladly had one of them instead.
tinypliny - 12/21/11 19:56
Is that a surprise? Didn't you resolve, as a developer, never to work on the ipad again because of the arbitrarily large fees?

12/21/2011 12:43 #55781

Wood Dental and the Florida Probe
Category: dentist
I want teeth that look like that.

image

Last year I tried to be cheap and got a regular crown at the regular in network dentist and it ruined like 6 months of my life in pain and infection, as well as, cost me another broken tooth in the process. I wrote about it here (e:paul,54524)

Then I found Wood Dental Associates on Franklin in North in Buffalo and his expensive ($1200+) but awesome cerec tooth milling machine which measures you tooth space with 3d cameras and mills the tooth in the office out of this strong and chemically inert ceramic. I love the new fake tooth. It fits so well, is strong and feels just like a real tooth. To me it was totally worth the money and made me feel confident about my tooth and the dentist.

So I had a couple other fillings done there because they don't use mercury unlike the in network dentists and its right across from my house. They were also expensive in the $600 range but I figured it was worth it not to get more mercury in my mouth. At that point, I signed up for a regular cleaning and thought I would go there as my regular dentist.

I figured how much can a cleaning cost. Today, I found out when I went in for my scheduled 6 month cleaning. When I sat down for the cleaning the hygenist said that they no longer do normal cleanings and that first this Florida Probe machine would check my mouth for any issues. I thought it was some pre-cleaning process but once it was done, she told me instead of the normal cleaning I would need a $1099 3 visit special cleaning with the antibiotic called Arestin implanted because I had stage 4 periodontal disease.

Reading the testimonials is a mixed message. Who is this appealing to, the dentist or the patient.

Our proportion of non-surgical perio revenue jumped 100% since 1999, when we implemented Florida Probe. The real value for the patient is that because he understands his problem earlier and better, he acts (prevents bone loss) earlier."



The overview page makes me even more uncomfortable

This part sounds good and reasonable

Improved Accuracy
The System’s constant-force, computerized probe allows measurements to be consistent between examiners who likely probe with different amounts of force (which could mean different readings for the same patient). Our probe’s precision is 0.2 mm., which also improves the accuracy of measurements and assists the clinician in determining the correct diagnosis and follow-up for the patient.



This part sounds beyond scammy.

Generate New Revenue for Your Practice
Did you know that just 1 more quadrant of scaling and root planning acceptance per day at $250, working a 4-day week, adds $50,000 per year to your bottom line? This is only the beginning: 3-month re-care, adjunctive therapies and diagnostic fees add to this hygiene-driven increase in production. This means an incredible return on investment opportunity. The typical practice will increase hygiene and perio production by $10,000 per month.



Now the weird part is that I was just in to their office in June and they didn't mention anything about gingivitis and then I was at the other dentist twice in the last three months for the geographic tongue and he and his team of student dentists didn't mention anything either. Now I get that maybe the machine is more sensitive and can detect stuff but I can't believe I went from not humanly noticeable to full blown $1099, you need to be on antibiotics, stage 4 periodontal disease. If the machine is really correct, are these dentists so clueless that they could not visually recognize this possibly severe tooth disease in the last 6 months.

My lame GHI dental insurance will only cover like $200 at his office. Although, they would cover the scaling in full at any in service dentist. After my bad experience with two in service dentists I don't know if I want to go back. I know why they cover it in full, its because those other dentists are willing to trade quality for quantity of patients. For example, GHI doesn't really pay them much more, those dentists are just willing to accept $35 as full payment for some procedures.

I want a dentist I trust in so bad. Even more so, I want to trust this dentist so bad. In fact, I trusted him so much more until I read the Florida Probe site. I guess I will get a second opinion. In the mean time I need to brush better. I think one issue is that I was using a medium instead of soft brush which was hurting my gums.

Two things that also bother me about this.
1. I flossed just before I left which could have irritated my gums a bit.
2. The measurement is really not done by the machine, if you watch the video, the hygienist really does makes the decision when to press the floor peddle which sets the depth.



Does anyone have a dentist they really know and trust?

Knowing me, I will probably just go there because it is convenient and immediate. The more I read about gum disease the scarier it is. Check out this crazy info on the NY times site I am saving as PDF for future reference. ::READ PDF::

Here is all my private tooth information for the world to judge me on.
image
image
image
image
paul - 12/21/11 21:07
I updated this with tons more info about the process.
tinypliny - 12/21/11 19:56
Overly white teeth are creepy.

12/21/2011 10:24 #55779

My hair is so scruffy
Category: haircuts
I want to cut it so bad but I am trying to grow it out a but for winter. I hate this middle phase. The only thing that helps is a hat.

image
metalpeter - 12/21/11 16:45
That is the same problem I have but with my Beard.... I would love to have a cool heavy Metal or say Jim The Anvil Niedhart style but there is the middle part that is tough to get through not to mention do metal guys use wax?
flacidness - 12/21/11 16:13
There is no hateration or holleration in this dancery!!!!
tinypliny - 12/21/11 12:58
Don't listen to haters. You are perfect just as you are. :) Love the look!
flacidness - 12/21/11 11:28
Such scruffy sideburns!!!! Makes you look older. I nice trim would be perfect, I wouldn't cut all though.
lilho - 12/21/11 10:57
plantcer.

12/19/2011 13:44 #55772

And this is why fedora rules...
Category: linux
Because only supports and includes free and open source software. No proprietary programs are included in Fedora. That way things like this cannot happen the way they do in ubuntu I would so much rather have openJDK and have to install Sun java myself if I needed it then have it available from the OS vendor and have to worry about license changes removing it on it me. Here is why Fedora does not include specific proprietary software
uncutsaniflush - 12/19/11 22:06
The uninstalling by Ubuntu part is the scariest of all to me.