Skip to main content

Posts

Showing posts from February, 2008

Using TightVNC

Long time no post. Been busy busy! Anyways, this seemed like it may be a helpful tip. I spend my days in office (like most of us) and often have tasks that I'd like my computer at home to be working on while I'm gone. For example, I have large backup files on my web server that I like to download down to my computer at home for safe-keeping. Or sometimes I just want to check email or do other non-work stuff that's easier (and safer) to do at home. This is where tightvnc comes in. It's a free, open-source program that sets up an encrypted connection to another computer, and allows you to see and use that computer as if you were sitting there. You install the server program on the computer you want to monitor, and then use the client program to connect to it over the internet. You'll generally have to do route some ports in your router so that you can connect to the computer, but that's pretty straightforward. This is especially nice for checking email. One thing...

Security Mis-step on Nationalcity Online Banking

Just noticed this today, although it's been like this for a while... Users of National City online banking - at least the personal banking users - might be interested to know that they've actually made their site less secure , while claiming to make it more secure... It used to be a standard login over SSL security - you entered your username and password into a form, and logged in. But now they've broken that into two steps. First you enter your username, and hit enter. Then you enter your password into a specially customized form that I guess is supposed to protect against phishing attacks, because it has a unique background and phrase on it. I guess the theory is that you'd notice if you were trying to login to a fake National City, because the personal background/phrase wouldn't be there, or would be wrong. But here's the problem - an impostor trying to brute-force an account would actually receive feedback from the site if they guessed a correct username! ...