2014-05-06

Unsubscribing from LinkedIn (without having ever subscribed)

LinkedIn is going down, and one of the symptoms of its despair is the fact that it's spamming people which are not even its users.

This is known for quite a while, but well, since they bothered me, why not restate the fact that they suck in terms of respect of the users?

Note: real names and addresses have been modified, but everything else is legitimately LinkedIn®.

I've received this message a few times, ignoring it at first, but they kept annoying me:


John Doe souhaite rejoindre votre réseau sur LinkedIn. Que souhaitez-vous répondre [John Doe wishes to join your network on LinkedIn. What do you want to reply]?

John Doe
Employee at Example

Ok, so a typical message (in French) asking me to add John Doe to my LinkedIn account. But wait, the e-mail address in question is not in my LinkedIn account! So LinkedIn actually wants to "convert" me. Notice the tone: John Doe wants and not LinkedIn wants. This would be mostly OK, except that... they keep spamming me again and again, every week!

If John Doe really wanted to join my network, he would at least know that I have one, right? Nice way to blame the user there.

If I click on the link, they take me to the registration page:


A nice touch here: the Email field is readonly, which means you cannot change your mind and put another e-mail. Why? Well, they confirmed the e-mail exists when you clicked on the link anyway, so they are just making sure you don't change your mind... but without disabling the field, if you just happen to prefer another address (say, Professional.Full.Name.email@example.com), you spend your time trying to understand why Backspace and Delete suddenly stopped working. Nothing in the UI indicates it is read-only.


So, I suppose I'm fair game since someone just sent my e-mail address to LinkedIn. Notice the small text below the message:

Vous recevez des e-mails de rappel concernant vos invitations en attente. Se désabonner. [You receive e-mail reminders about pending invitations. Unsubscribe.]

Oh, cool, so I can unsubscribe. But wait, I never actually subscribed to anything in the first place! So all it takes is a random user to add me to LinkedIn's server, and voila, they just triggered a spam machine which will either force me to admit "OK, I'm weak, I admit this e-mail address is actually being read by a human being by clicking on your Unsubscribe link for something I never subscribed", or I have to actively treat their messages as spam. Either way, it surely looks like LinkedIn is so desperate they are resorting to spammy ways... but this is not new anyway, so why am I complaining...?

This is what the unsubscription page looks like:


They are honest here, but still blaming the user: you are receiving these emails because a [bastard evil goddamn] LinkedIn member invited you....
No, wait, I'm receiving it because you want to spam me and just found a stupid justification to do so. Don't blame the user, LinkedIn, he didn't spend his time writing and sending me the e-mail, you did it!



Bonus points for those who find the e-mails of LinkedIn's CEO's family members and spam invite them to join their network! Maybe that way they'll actually realize the crappy way it works...

2014-04-29

Flashblock and Vimeo

A long time ago, Vimeo started having problems with Flashblock... as indicated in this thread.

The solution? To whitelist their domain on Flashblock.

I know that Vimeo developers already have many things to do, and managing how an external plug-in deals with their code is probably not how they want to spend their time.

But still, other players usually don't have this problem. And it only started happening after some code has been modified on Vimeo.

Now, it's very unlikely someone will be able to inject Flash malware using Vimeo's website and profit from the whitelist. And I didn't see any Flash ads on their website, which might make them earn money. So the most probable cause is indeed just an accident. Unfortunately, most security problems come from such inoffensive accidents...

I wonder how the next generations will look to the past and judge these mistakes. That is, if they can actually find out when things have actually happened. Without Carbon-14 or physical evidence, they'll have to rely on timestamps. Luckily, these are much more precise and foolproof than some ancient technology...
 

2014-03-25

Google synonyms a bit too far off

For quite some time, Google has been using synonyms and variants (e.g. singular versus plural) in search results to help the user.

But recently, it's been going a bit too far in its "inferences" about what constitutes a synonym.

The double-quotes operator used to mean exact match, but either Google Scholar ignores it completely, or Google is simply ignoring the user:


I looked for flexibility, but is only matches results with angioplasty, as if it were a synonym. I put "flexibility" between quotes for an exact match, but it didn't work.

If Google Scholar couldn't find anything with "flexibility", it should at least say so, as it usually does in Google Search: no matches found for term X, searching with Y instead.

This is completely unintuitive and provides a bad user experience. Let's hope Google fixes this soon.

2014-03-21

France reimburses your (expensive) sugar bill

France's healthcare system is great in many aspects...

... but reimbursing expensive sugar is not one of them.

I find it appalling that such a developed and modern country, where reason is so highly valued (or used to be), allows homeopathic pills to be reimbursed.

This is, essentially, financing a scam.

I went to the pharmacy the other day, due to a minor flu, and talked to the pharmacy clerk:

- I have the flu. Symptoms A, B, C, no fever, nothing too worrysome. What do you recommend?

- Oscillococcinum.

Let me show you what she recommended me:


- Wow, what a great scientific-sounding name. Looks like some kind of bacteria, so... it must be some kind of antibiotics, right? Oh wait, I don't want such powerful medication, it's just a small flu.

- Oh, no, don't worry, it's homeopathy.

Wait. A pharmacy clerk is telling me to buy industrialized homeopathy? Like this, in public, without shame? What is wrong with these people? Have they never heard of the scientific method? But she works at a pharmacy, she has at least some kind of technical diploma! She should know better, she who works at the place!

Well, maybe "placebo" a new kind of hype these days?

Oh, wait, look at the price. 54,55 €, that explains it all.
Ok, just cold business principles trampling over reason and concerns about the actual health of the client.

No, not really: after politely refusing it, she indicated me the cheapest medicine she could find:


Good old paracetamol. As a bonus, some added C vitamin. And cheap as hell (for French living wages, that is) - this site indicates 2.30 €, but for mine I paid 1.55 €.

(Granted, I cannot compare them directly, because these prices do not come from the same website, and do not correspond to equivalent quantities. But in the pharmacy, the price difference was about the same: 20x. Also, if you intend to spend 30 days sick with flu-like symptoms, then you have got bigger problems...)

Now, I don't know what's more worrisome: if the pharmacy clerk is just trying to make more profit, or if she really believes homeopathy works. I guess the former would worry me less: it is evil, but at least rational.

In the end, science triumphed for me: I got the best of both worlds, spent little money and got better. But for the French healthcare system, it's the scammers who got the upper hand. But few people actually seem to care.

Note: some people are wondering, what does this have to do with "user experience"? Well, that's what placebo is all about... "If I spent 55€ on this, it's OBVIOUSLY going to work!" And it does, because placebo does work... a bit. But hardly when you are really sick.

Note 2: Guess what's inside Oscillococcinum? Duck liver! Yes, it's the foie gras of the sugar pills! That would explain the price, and why French use it... Now if they just made a pill based on wine...

2014-03-18

Could a weird Blogspot URL behavior lead to phishing?

Unusual behavior leads to security risks

Google's Blogspot domains (Blogger blogs) behave somewhat strangely.

The blogspot.com domain looks just fine:
However, every other domain than .com (such as blogspot.co.uk, blogspot.ru, etc.) behaves in a less intuitive way:
  • Visiting http://blogspot.co.uk returns a 302 redirect to... http://www.google.com. Arguably less useful than blogger.com's redirect, but still an official Google page;
  • Visiting http://www.blogspot.co.uk, on the other hand, lands in the blog of a specific user.

What would prevent this "www" page from being modified to mimic Google's login and capture some identifiers?

Ideally, Google would quickly be noticed by users about a phishing attack coming from this page and would disable the blog, but until then, several users might have their credentials stolen.

I do not understand why Google treats the .com domain in a different way than every other domain. Has someone in the US complained about it?

No history in the Internet Archive


This behavior seems so uncommon that, when I tried to see the Internet Archive's history on the www.blogspot.co.uk webpage, I noticed that - due to a bug or a deliberate feature - the archived pages for http://www.blogspot.co.uk actually refer to the http://blogspot.co.uk page (that is, Google's homepage)!

In other words, this website's history is hidden from the archive, even though any other Blogger blog is indexed just as expected.

Am I being paranoid, or could this website be used to phish users while looking like a legitimate version of Blogger's homepage? Is there something else protecting Blogspot users from a potential attack?

2014-03-14

Forfait bloqué Bouygues

Mise à jour du 17/03/14 : Bouygues a corrigé la présentation sur sa page web. D'après l'interlocuteur via Twitter, c'était une "coquille". Actuellement la page affiche bien "Engagement 12 mois". Je trouve assez étrange que cela ait resté aussi longtemps (je l'avais remarqué le 2 mars ; l'Internet Archive a une dernière version le 9 février, qui semble indiquer "Engagement 12 mois"), maisau moins cela a été corrigé. D'après le message Twitter, ceux qui ont opté pour ce forfait avant aujourd'hui auront bien droit à un abonnement sans engagement. Je n'ai pas voulu m'aventurer, mais au moins ceux qui ont été "victimes" pourront se défendre.



Bouygues Télécom nous propose un forfait bloqué intéressant : il est sans engagement, mais avec un engagement de 12 mois !

Ce n'est pas moi qui le dit, voici ce que propose leur page sur le forfait bloqMise à jour du 17/03/14 :ué (je n'ai capturé dans l'image que la moitié inférieure de la page) :

Capture d'écran de la page d'accueil du forfait bloqué Bouygues Télécom, qui est sans engagement mais avec engagement de 12 mois.

En haut, juste après l'option "SIM seule", on lit très clairement : "Sans Avantage Smartphone" et "Sans engagement". A contraster avec l'option "Avec un nouveau mobile", où il est bien écrit "Engagement 24 mois".

Sauf que, juste en bas, dans le lien "AFFICHER LES MENTIONS LEGALES", la première phrase est : "Engagement 12 mois, Version éco (carte SIM seule)"

WTF Bouygues ? C'est de l'incompétence pure et simple ? Non, je refuse de le croire, car vous avez quand même bien essayé de cacher le message ! Il faut cliquer sur les mentions légales pour le voir !

Franchement, si ce n'est pas de l'arnaque pure et simple, je ne sais pas comment quelqu'un pourrait arriver à une contradiction aussi flagrante ! Personne ne relit ces pages avant qu'elles ne soient mises en ligne ?

J'étais prêt à aller chez vous, mais après cela, niet ! Je resterai avec SFR, qui vend mon numéro de téléphone à des spammeurs, mais... OK, alors j'irai chez Virgin Mobile, qui cache les arnaques dans les conditions de vente (et enlève des fonctionnalités de base, comme l'accusé de réception des SMS)... Ou sinon j'irai chez Orange, qui empêche ses clients de partir en inscrivant sans raisons les clients chez Préventel... Ou chez Free, qui limite le débit de sites comme Youtube...

Franchement, en matière de télécom, il n'y a pas d'opérateur honnête !

2014-03-11

Possible phishing via www.blogspot.fr

Google ne semble pas très soucieux de son domaine blogspot (qui a été française de Blogger)...

Déjà, quand on essaie d'accéder à http://blogspot.fr, on finit par retomber sur la homepage de Google, après une redirection 302 :

$ curl -I http://blogspot.fr/

HTTP/1.1 302 Found
Location: http://www.google.com/


Ce n'est pas très normal, surtout car la version américaine (blogspot.com) redirige bien vers le site www.blogspot.com, qui lui demande une connexion au compte Google pour ensuite afficher le dashboard.
C'est moche (on s'attendrait à au moins une page d'accueil, pour expliquer ce que c'est que Blogger, au lieu de tout simplement nous jeter un écran de login sur la figure), mais c'est correct. La version française (et la version blogspot.co.uk aussi, et sans doute d'autres) ne fait que rediriger vers la recherche Google. Ce qui est assez impoli...

Le pire, c'est que le domaine blogspot n'a même pas de contrôle sur le sous-domaine www ! Cela veut dire qu'un pauvre malheureux qui essaie de visiter www.blogspot.fr (ou www.blogspot.co.uk, etc.) finit par retomber sur le blog personnel d'un utilisateur (qui, en occurrence, s'appelle inne et qui n'a pas mis grand chose sur sa page) :


(Pour les curieux, Google Traduction dit que c'est de l'indonésian.)

Heureusement que cette personne ne cherche pas à faire du phishing avec cette page, car ce serait très facile de tromper plein d'utilisateurs, en les faisant croire que c'est la page "officielle" de Blogger pour leur demander de se loguer et récupérer leur mot de passe.
Bien sûr, Google fermerait le compte peu après, mais le temps de le faire, la personne aurait sans doute le temps de profiter des identifiants. Ou sinon, une personne moins malveillante pourrait tout simplement mettre de la publicité sur cette page, en récoltant de l'argent gratuit grâce au manque d'attention de Google !

Comment ça se fait que Google s'en fiche d'une attaque aussi facile ? Le seul domaine qui agit comme attendu est www.blogspot.com. Pour le reste du monde, Google laisse un trou de sécurité énorme. Je me demande si cet utilisateur www ne fait qu'attendre le bon instant pour attaquer/vendre son site...