Archive for the ‘Stupid’ Category

Dumb de dumb dumb.

Thursday, July 19th, 2018

Dumb de dumb dumb…

The stories I am about to link to are true. I haven’t changed any names, because none of these people are innocent.

Dumb: threatening a judge.
Dumber: threatening two judges.
Dumbest: threatening two judges, one of whom was already shot and wounded by another idiot three years ago.

“I have every right to hang your (expletive),” Holgate said in a message according to the affidavit. “You have every goddamn right to be afraid of me. I am the law and you shouldn’t have crossed me.”
In another message, Holgate threatened to kill one of the judges, according to the document.
“I have the right to (expletive) kill you. You understand that?” He said. “…But we will see if we can resolve it. I don’t think we can, I think we are just going to hang your (expletive).”

And by the way…

…his arrest affidavit said he identified himself at the beginning of each of his threatening messages.

Meanwhile, over in Williamson County, the relatively new sheriff and prolific tweeter Robert Chody is in a micturition contest with one of the county commissioners, Dan Gattis.

Sheriff Chody has opinions about how county government is run, especially when it comes to sewage leaks, and does not hesitate to share them. This, in turn, seems to upset Judge Gattis:

“He stuck his finger in my chest — he didn’t actually touch me — and said, ‘Tell that sheriff if he doesn’t quit tweeting, I’m going zero his budget out,’” Chief Deputy Tim Ryle told the American-Statesman on Wednesday. “My comment to him was, ‘Judge, are you sure you want to say that?’ He said, ‘Yes, tell him to stop tweeting about me and my people.’

This little spat wouldn’t be noteworthy to me, except for what happened next:

Gattis’ alleged threat crossed a legal line, say Williamson County prosecutors, who filed a misdemeanor official oppression charge against him. Law enforcement officials issued a summons for Gattis to appear in state District Court in lieu of being arrested.

Yes, you read that correctly: the WillCo DA filed criminal charges against a county commissioner (who, by the way, is not running for re-election this year) because he shot his mouth off.

Personally, I think they’re all idiots: the sheriff’s office and the DA for filing charges over a political disagreement, and Judge Gattis for making empty threats. (“I’m going zero his budget out”. Yeah, Judge, you’re going to zero out the sheriff’s department budget. Call me when the pigs start flying.)

Dumber than a bag of hair.

Tuesday, June 19th, 2018

I missed the first part of this story last week, but I caught the second part when it came across the Hacker News Twitter feed.

There is a company called Tapplock that makes a $99 “smart” padlock. No, this isn’t the same company that makes a “smart” padlock that’s “completely invincible” to anybody that doesn’t have a screwdriver. Different company, different lock.

But it does have a fingerprint scanner and Bluetooth.

Part 1:

Among other features, you can set up multiple fingerprint profiles, so you can enable multiple people to unlock the padlock with their fingerprints.

Except: their protocol doesn’t gracefully handle revocation. The lock communicates over HTTP: there’s no encryption, and…

I could see that a string of “random” looking data was sent to the lock over BLE each time I connected to it. Without this data, the lock would not respond to commands.
But it was also noted that this data did not change, no matter how many times I connected. A couple of lines of commands in gatttool and it was apparent that the lock was vulnerable to trivial replay attacks…
…I shared the lock with another user, and sniffed the BLE data. It was identical to the normal unlocking data. Even if you revoke permissions, you have already given the other user all the information they need to authenticate with the lock, in perpetuity.

But wait, there’s more! It turns out that that random data, that unique key…is derived directly from the lock’s MAC address! The one that’s constantly broadcast by the lock so you can access it over Bluetooth!

I scripted the attack up to scan for Tapplocks and unlock them. You can just walk up to any Tapplock and unlock it in under 2s. It requires no skill or knowledge to do this.

Part 2:

But wait, there’s more! Another security researcher, who didn’t have a Tapplock (“I am out of IoT budget for this month as my wife has -kindly- informed me”), decided to play around with the Tapplock’s cloud based admin tools…

…and discovered that, once you logged in with a valid account, you could access any other account simply by incrementing the account ID.

As a result, Stykas could not only add himself as an authorised user to anyone else’s lock, but also read out personal information from that person’s account, including the last location (if known) where the Tapplock was opened.
Incredibly, Tapplock’s back-end system would not only let him open other people’s locks using the official app, but also tell him where to find the locks he could now open!

References:

The Pen Test Partners initial attack.

The Vangelis Stykas admin interface attack.

Sophos “Naked Security” blog: part 1. Part 2.

Things you may have wondered about. (#6 in a series)

Friday, February 23rd, 2018

Okay, maybe not. But it’s been a while since I did one of these.

Whatever happened to Beanie Babies?

(Spoiler: they’re worthless.)

“If you bring Beanies to me and try to sell them to me in bulk, I’ll give you about 20 cents. That’s me telling you I don’t want them,” said Steve Johnston, the store’s owner. “Give them away.”

Memo from the police beat.

Thursday, March 16th, 2017

The past few days have been busy ones for law enforcement in and around Austin, and not just because of South By So What. Here’s a quick survey of some things that I’ve found interesting.

There’s a new plan for the APD DNA lab: get Texas DPS to run it.

Under a proposed contract, the city of Austin will pay the Texas Department of Public Safety $800,000 a year to manage all aspects of the lab, including procedures for analyzing forensic evidence and the oversight of employees hired by the DPS to work there.
The newly named Department of Public Safety Capital Area Regional Lab will focus exclusively on Austin police cases, Assistant Police Chief Troy Gay said.

I suppose this is better than nothing, or the current state of affairs. And $800,000 sounds like a reasonable amount of money if the new management from DPS is going to fix all the problems and claw through the backlog. But I still think we’d be better off with an independent lab like Houston’s, or making the existing lab am arm of the courts.

Speaking of the DNA lab, here’s a story I haven’t seen reported anywhere else:

In the first legislation of its kind, the lawmaker, State Representative Victoria Neave, a Democrat from Dallas, introduced the bill in February to solicit donations of $1 or more from people when they renew or apply for driver’s licenses. The money would underwrite a grant for the Department of Public Safety to test what are commonly called “rape kits,” which consist of evidence samples including hair, semen, fabric fibers and skin cells.

(Note that the paper of record characterizes this as “crowdfunding”, which I find a bit misleading.)

If adopted, it could generate an estimated $1 million a year, based on similar donations collected for veterans from driver’s license applications, according to a legislative budget document. When administrative costs are deducted, that would leave more than $800,000 every fiscal year that local governments could tap to push through testing of evidence collected from the victims of sexual assault during a physical examination that can take four to six hours.

Where have I heard $800,000 recently? Oh, yeah.

The donations are intended to supplement rather than replace a budget for the testing, which can cost $1,000 to $1,500 for each kit. The Legislature, which is now in budget talks, is also considering allocating $4 million to fund the process, said Rebecca Acuna, Ms. Neave’s chief of staff.

You know what I’d really like to see? A breakdown of where that “$1,000 to $1,500 for each kit” goes. I’m not against rape kit testing – quite the opposite – but I’m curious why it costs that much. I’m also curious if this cost has increased or decreased over time, with improved technology. And are there possibly better, faster, and cheaper ways of testing rape kits without sacrificing accuracy?

Two people shot and killed last night, and a third airlifted with “critical, life-threatening” injuries.

If you look at the Stateman‘s handy Google map, you’ll see this took place not terribly far from the Lake Travis High School/Education Center complex. My mother and I were down there last night with a bunch of other people….attending the Lakeway Police Department’s Citzens Police Academy class. As a matter of fact, right around the time of the shooting, we were out in the parking lot looking at the Lakeway PD patrol cars (Chevy Tahoes. This led someone to ask, “Why the switch to SUVs?” I suspect most of my readers know the answer already, but in case you don’t: “Because Ford stopped making the Crown Vic, the greatest patrol car ever given to us by God.”) and the Lakeway PD police motorcycles (Harley Davidsons). I don’t recall hearing any shots or even the Starflight helicopter.

Even better, we had just finished listening to a presentation from one of the people who does the Lakeway PD statistical analysis about how safe Lakeway was, how many calls for service/stops/arrests there were year to year, and what the major categories were. “Homicide” didn’t even register. (Technically, it’s probably still true that Lakeway is relatively safe, even though the shooter is at large: I believe the shooting happened near, but outside of, the Lakeway city limits, so it would be chalked up as “unincorporated Travis County”.)

The first we knew about it was when we were breaking up for the night: the second in command of the department (who also runs the classes, and who usually jokes around a lot) came in and said “I want everyone to listen to me very closely. Two people have been shot near here and the shooter is still at large. We are going to walk everyone to the parking lot and make sure you all get into your cars safely. I need for you to leave the area as quickly as you possibly can.” That will put some spring in your step.

Reports are that this was “an isolated incident”, possibly a “disgruntled contractor” who shot these people because he didn’t get paid. Which is just stupid: if you shoot people, they can’t pay you.

And speaking of the Lakeway CPA, for reasons: a interesting and contrarian point of view from Grits For Breakfast in opposition to a statewide ban on “texting and driving”.

Important safety tip (#20 in a series)

Thursday, November 17th, 2016

For the love of God, don’t go swimming in a Yellowstone hot spring.

First of all, it will kill you.

Second of all, those springs are acid, and will dissolve your dead body.

We haven’t had a musical interlude in a while. Let’s fix that. Besides, this is a rather catchy little ditty,

From the police blotter.

Thursday, July 14th, 2016

This story has everything: fire, an explosion, strippers (“Willow” and “Breonna”), and a potato.

A 19-year-old Connecticut woman was arrested Tuesday on charges of second-degree arson, third-degree burglary and first-degree criminal mischief for allegedly setting fire to two businesses in September.

The resulting blast was so powerful it knocked Martin through the door, prompting Garguilo to describe it “just like in the movies,” the Courant reported. They fled, only to circle back and watch the fire.

Yes, I’m going to make you click through to the WP if you want to find out how the potato came into play. Hint: Martin is the stripper, Garguilo is the boyfriend (she’s 19, he’s 28: isn’t love grand?) and neither one is terribly bright.

Uncle quickie.

Wednesday, February 24th, 2016

One more quick Leland “Uncle” Yee thought that I didn’t have time for in the previous entry:

Sen. Patricia Bates (R-Laguna Niguel) said Wednesday that the Yee case shows the need for stronger controls of campaign financing. She has introduced a bill aimed at closing a loophole in campaign finance law that was exploited by Yee. Her measure would extend contribution limits that apply to candidates’ campaigns to also apply to ballot measure committees formed by elected officials.

“Today’s sentencing of a former elected official underscores the need to close campaign finance loopholes wherever they exist,” Bates said in a statement. “My bill will help restore the spirit of the Political Reform Act of 1974 that sought to end the culture of corruption that many believe is pervasive in politics.”

Yes, folks, you read that correctly. Campaign finance reform is the only thing standing between you and your elected state senator smuggling guns to Islamic terrorists and rebel groups in the Philippines.

What does it take…

Friday, December 19th, 2014

…to lose your job as a cop?

If you’re the police chief in Phoenix, the answer is “insubordination”. Specifically, calling a press conference and demanding a new contract after the city manager said “Don’t DO that!” seems to be a sure way to get yourself terminated.

If you’re with the Austin Police Department, the answer is “running your mouth to a reporter”. Technically, Andrew Pietrowski “retired”, but it seems like his retirement was just ahead of “being canned by Art Acevedo”.

“Now, stop and think about this. I don’t care who you are. You think about the women’s movement today, [women say] ‘Oh, we want to go [into] combat,’ and then, ‘We want equal pay, and we want this.’ You want to go fight in combat and sit in a foxhole? You go right ahead, but a man can’t hit you in public here? Bulls–t! You act like a whore, you get treated like one!”

The way I read this, it wasn’t like Pietrowski was asked for his opinion; he just walked up to a reporter who was there for another reason and started spouting off.

Random notes: December 5, 2014.

Friday, December 5th, 2014

The 76ers, turning the fundamental belief system of sports on its head, do not mind losing. A lot.

However, they did screw up their chances of going 0-82. Philadelphia is now 1-17.

Anybody out there missing a pony?

Public service announcement: if you get an “order confirmation” email from someplace like Costco or Home Depot, and you didn’t place an online order, and the email doesn’t contain specific details about which store you should pick it up at, FOR THE LOVE OF GOD DON’T CLICK ON THE LINKS!

I’m sure most of my readers are smart enough to figure this out on their own, but I wanted to mention it here for reasons.

Historical video, emphatically NOT suitable for use in schools.

Friday, September 26th, 2014

By way of Ace of Spades: The LA Police Department Skilled Shooting Exhibition Of 1936. (As Maetenloch notes, this is probably from 1938. And although the heading says LAPD, this is actually the LA Sheriff’s Department.)

There’s some good stuff in this:

  • I do love me some nice Thompson work.
  • It is an interesting piece of history, if you want to see how police shot back then. I believe the LAPD was pretty progressive in their pistol training at that time; certainly they were in 1955, when Sterling Walker wrote “How Cops Get Killed” for Guns Magazine. It seems logical to assume that that the LACSD worked the same way. The one-handed shooting stance looks funny in retrospect, but you have to remember the Weaver Stance hadn’t been invented yet. And I suspect that “Combat” range and the practice drills were pretty far out in front of the curve for 1938.
  • I like the course of fire shown at the range. I might try that next time I go out to the range with one of my revolvers.
  • LAPD

  • I wonder if this is where the shooting competition in Magnum Force was staged. IMDB is no help here.

There are also some things I really dislike about this video:

  • The tinkly piano music really gets on my nerves.
  • I wish it were better lit, or in better focus, or both. I can’t tell what guns the shooters are using (except for the one guy with the Thompson, of course). Various sources say LAPD was issuing the S&W K-38 Target Masterpiece and the K-38 Combat Masterpiece until 1988. (The difference between the two is that the Target Masterpiece had a 6″ barrel; the Combat Masterpiece had a 4″.) The Walker article mentioned above says they also used the Colt Officer’s Model Special. The problem I have is that the K-38 in either version didn’t start showing up until post-WWII. I think the guns in the video may be Colts, and there could be a couple of M&P Model of 1905 4th Change revolvers in there; it is just hard to tell. (Again, I’m assuming LACSD and LAPD used the same or similar equipment. Frankly, there weren’t a lot of choices at the time, though I guess they could have issued Registered Magnums…)
  • JESUS JOSEPH AND MARY ON A FREAKING POGO STICK, WERE THESE PEOPLE IDIOTS?! In case you’re wondering why I’m screaming, it should become apparent to you at about 35 seconds into the video. What the frack? What the fracking frack? Was life cheaper back then? Were these guys getting some hefty hazard pay? For my readers at home: DON’T DO THIS, OKAY? Seriously, this has “manslaughter” written all over it.
  • Also, there’s much more effective ear protection out there these days than cigarettes or wads of cotton.

There’s all kinds of stupid.

Wednesday, September 3rd, 2014

Many of which I have written about here.

But forging a court order in an attempt to get content you don’t like removed is a whole new kind of stupid, even for sleazy telemarketers.

(Is “sleazy telemarketer” redundant?)

We have a feeling that Prince Kropotkin would not approve.

Tuesday, December 17th, 2013

anarchy

(Wiki wandering led me to the article on the Big Boys:

Over the years the group played with five drummers in all; Steve Collier, Greg Murray, Fred Shultz, Rey Washam and Kevin Tubb who played only one show (the bands first) because Steve was sick.

Spinal Tap really was a documentary, and we just didn’t know it at the time.)

(Edited to add: Hurrah! The U2/Popmart/giant lemon story is immortalized online! What did I tell you? (Scroll down to “Rock and Roll Creation”.) By the way, I own and enthusiastically recommend This is Spinal Tap: Official Companion.)