<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>innismir.net &#187; fail</title>
	<atom:link href="http://www.innismir.net/article/tag/fail/feed" rel="self" type="application/rss+xml" />
	<link>http://www.innismir.net</link>
	<description>Pointless, vapid ramblings of a surly information security engineer</description>
	<lastBuildDate>Mon, 02 Aug 2010 20:06:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>We don’t care. We don’t have to. We’re the MBTA.</title>
		<link>http://www.innismir.net/article/376</link>
		<comments>http://www.innismir.net/article/376#comments</comments>
		<pubDate>Thu, 24 Sep 2009 16:23:30 +0000</pubDate>
		<dc:creator>Ben Jackson</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[mbta]]></category>

		<guid isPermaLink="false">http://www.innismir.net/?p=376</guid>
		<description><![CDATA[In the words of the late, great, Irving Snyder, WA1ETG SK, I have a &#8220;tale of woe.&#8221; As always, as an employee of the fantastic Commonwealth of Massachusetts, the opinions of this website are my own and not the view of my employer or anyone else. Late in August, I was in a rush on [...]]]></description>
			<content:encoded><![CDATA[<p>In the words of the late, great, Irving Snyder, WA1ETG SK, I have a &#8220;tale of woe.&#8221; As always, as an employee of the fantastic Commonwealth of Massachusetts, the opinions of this website are my own and not the view of my employer or anyone else.</p>
<p>Late in August, I was in a rush on a Wednesday and couldn&#8217;t change my five dollar bill for ones to pay for parking. With the MBTA, they have something called an &#8220;honor box&#8221; in which you pay your $4 parking fee into a <a href="http://www.flickr.com/photos/innismir/3025157090/">small slot numbered with your space</a>. &#8220;No worries&#8230;&#8221; I said to myself, &#8220;&#8230;since I am in a rush, I will eat the late fee and just pay them when I get a violation notice.&#8221; A brilliant plan, correct? It was, I&#8217;ve done it before. Also, since I knew I was likely going to face the same problem on Friday I was just going to pay $10 with the Friday violation notice. This plan crashed to earth when I got the Friday violation notice:</p>
<p><a title="One of these things is not like the other... by innismir, on Flickr" href="http://www.flickr.com/photos/innismir/3950752634/"><img class="aligncenter" src="http://farm4.static.flickr.com/3429/3950752634_2f42b99ed3_b.jpg" alt="One of these things is not like the other..." width="442" height="330" /></a></p>
<p>Can you spot the key difference between these two notices? According to the 8/21 notice, I have 8 outstanding violations. This is impressive, as with every violation notice previous to this, including the 8/19 notice, hasn&#8217;t included a peep about any kind of outstanding violations. So, I place an e-mail to LAZ Parking, as they suggested on their voice mail greeting, to ask them how the heck this happened. They politely provided me a spreadsheet showing that I hadn&#8217;t paid my violations numerous times since they took over.</p>
<p>Slight problem: I <em>did </em>pay them.</p>
<p>I&#8217;m no angel. According to the spreadsheet I had 16 violations since December 1st. However, I have been <em>extremely</em> thorough in paying my violations since the parking fee increase, specifically because I knew that $5/pop could add up quick. While I cannot specifically say &#8220;Oh, hey, I paid that violation on June 23rd.&#8221; (Because really, who remembers that?) There were two violations that I was <em>sure </em>I had paid. Also, apparently, I did possibly owe them $2.75 from a violation in December. I won&#8217;t even attempt to remember that.</p>
<p>So, I ask them how I can contest it? Well, simple, I just tell them which spot I parked in during those dates and they can check.</p>
<p>Slight problem: There is not assigned parking at the MBTA.</p>
<p>With the MBTA commuter rail, each spot is numbered and that&#8217;s the number you pay for. However, it&#8217;s first come first serve. Most days I usually get a spot in the between 50 and 100. But really, I now have to keep track of which spot I park in on a daily basis <em>just in case</em> LAZ says I didn&#8217;t pay? What? I explained this to the CSR and after following up a week later asking them if there was any movement on this she reiterated she needed the numbers.</p>
<p><img class="aligncenter" title="/facepalm" src="http://www.innismir.net/etc/facepalm.jpg" alt="" width="339" height="256" /></p>
<p>This brings us to today.</p>
<p>I give up.</p>
<p>That&#8217;s it MBTA, you win. You&#8217;ve created a system where you can tell people they owe money and they have little to no recourse. You have a cash system, someone can have no proof they paid on random dates and in order to contest it, you make them jump through nearly impossible hoops. I give up. I am bending over and taking it.</p>
<p>So, now, in order to cover my ass:</p>
<ul>
<li>I will be paying my outstanding fee with a check, probably hand delivered, and I will get a receipt.</li>
<li>Further violations will be paid with via a check, as suggested by LAZ, and I will be keeping the canceled checks on record.</li>
<li>After I get the canceled check, I will be following up with LAZ to make sure they credited it to my account.</li>
</ul>
<p>Plus, just to add insult into injury halfway through the back and forth with LAZ, I get this on my windshield:</p>
<p style="text-align: center;"><a title="Insult to Injury by innismir, on Flickr" href="http://www.flickr.com/photos/innismir/3950647466/"><img src="http://farm3.static.flickr.com/2477/3950647466_0060da5046.jpg" alt="Insult to Injury" width="442" height="330" /></a></p>
<p style="text-align: left;">A $15 ticket because I was parking in the lot with an &#8220;outstanding balance&#8221;</p>
<p style="text-align: left;">Thanks, MBTA.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.innismir.net/article/376/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>A Series of Small Mistakes&#8230;</title>
		<link>http://www.innismir.net/article/319</link>
		<comments>http://www.innismir.net/article/319#comments</comments>
		<pubDate>Sat, 01 Aug 2009 02:47:00 +0000</pubDate>
		<dc:creator>Ben Jackson</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[infosec]]></category>

		<guid isPermaLink="false">http://www.innismir.net/?p=319</guid>
		<description><![CDATA[Tuesday, work had some training for some $FAIRLY_EXPENSIVE_SECURITY_SOFTWARE. Training required us to install one of the desktop versions of their product (which was passed around on a USB stick. &#60;/facepalm&#62;)  and required a license key. The trainer walked around to my laptop and set up a key. My paranoia is peaked when someone uses an [...]]]></description>
			<content:encoded><![CDATA[<p>Tuesday, work had some training for some $FAIRLY_EXPENSIVE_SECURITY_SOFTWARE. Training required us to install one of the desktop versions of their product (which was passed around on a USB stick. &lt;/facepalm&gt;)  and required a license key. The trainer walked around to my laptop and set up a key. My paranoia is peaked when someone uses an computer with my account, so I watched him log in to the webpage with the key generator (OK, I averted my eyes when he typed his password, that&#8217;s a common courtesy), generate the key, made sure it worked, and moved on the the next laptop.</p>
<p>Did you notice the missing step? Allow me to show you what was still up on my screen behind the software (censored to protect the guilty):</p>
<div class="wp-caption aligncenter" style="width: 370px"><a href="http://www.innismir.net/etc/CensoredKeyGen1_lg.png"><img src="http://www.innismir.net/etc/CensoredKeyGen1_sm.png" alt="Click for Larger" width="360" height="241" /></a><p class="wp-caption-text">Click for Larger</p></div>
<div class="wp-caption aligncenter" style="width: 370px"><a href="http://www.innismir.net/etc/CensoredKeyGen2_lg.png"><img src="http://www.innismir.net/etc/CensoredKeyGen2_sm.png" alt="Click for Larger" width="360" height="241" /></a><p class="wp-caption-text">Click for Larger</p></div>
<p>License Keys anyone?</p>
<p>Being the upstanding citizen I am I took my screenshots and logged out. I could have, however, generated a nice stretch of license keys for the next few months for my own personal use. Considering the amount of money the software costs, these keys would would have saved me a pretty penny.</p>
<p>There were four mistakes here, all small, two of which could have been fixed in the design phase of the application, two of which were the trainer&#8217;s fault.</p>
<ol>
<li>Trainer using a unknown laptop to log in to a secure site. Good thing I didn&#8217;t have a keylogger or something.</li>
<li>Application not having a some kind of system that would allow me to submit for my own key and have the trainer approve it.</li>
<li>Trainer not paying enough attention to log out.</li>
<li>Application not having some kind of oversight so that if I&#8230;. uhhh&#8230; I mean someone&#8230; did compromise the trainers account, I&#8230; er&#8230; he couldn&#8217;t create a bunch of keys.</li>
</ol>
<p>I will give credit to them for some restrictions that kept this from being an epic fail:</p>
<ol>
<li>30 days was the longest period I could generate a key.</li>
<li>It would likely had my fingerprints all over it.</li>
<li>I believe the key could be revoked on their end.</li>
</ol>
<p>That being said, it&#8217;s still an interesting example on how a series of small mistakes can cost an organization. Not that it did in this case, but how often do we hear about a bad system allowing a breach of sensitive data? A secure system requires both proper design and diligence of the users. In this case, unfortunately, they all clicked to allow the possibility of someone making off with the goods.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.innismir.net/article/319/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MBTA Customer Communication Fail</title>
		<link>http://www.innismir.net/article/159</link>
		<comments>http://www.innismir.net/article/159#comments</comments>
		<pubDate>Wed, 12 Nov 2008 15:05:06 +0000</pubDate>
		<dc:creator>Ben Jackson</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[mbta]]></category>

		<guid isPermaLink="false">http://www.innismir.net/?p=159</guid>
		<description><![CDATA[I take the magnificent MBTA Commuter Rail twice a day to get to and from my job in Boston. I pay $250/month for this privilege, plus, the MBTA makes me pay $2 a day to park in order to take the train. Recently the MBTA decided, partially because it can&#8217;t balance a checkbook, to up [...]]]></description>
			<content:encoded><![CDATA[<p>I take the magnificent <a href="http://www.mbta.com/" target="_blank">MBTA</a> Commuter Rail twice a day to get to and from my job in Boston. I pay $250/month for this privilege, plus, the MBTA makes me pay $2 a day to park in order to take the train. Recently the MBTA decided, partially <a href="http://www.bostonherald.com/news/opinion/editorials/view/2008_08_19_MBTA_passengers_taken_for_a_ride/" target="_blank">because it can&#8217;t balance a checkbook</a>, to up the parking rate to $4 a day, a 100% increase. You know, because people are swimming in money right now. Anyway, since I have no choice, <a href="http://risetovotesir.blogspot.com/2008/11/t-woes.html" target="_blank">myself and other riders have ince resigned myself to this fate</a>, and just have thought of doing evil things to the giant banners that appeared at the parking lots at the start of November.</p>
<p>Imagine my surprise this morning when I saw this sign posted above the collection box this morning:</p>
<p style="text-align: center;"><a title="The T does so well communicating with customers... by innismir, on Flickr" href="http://www.flickr.com/photos/innismir/3025157090/"><img class="aligncenter" src="http://farm4.static.flickr.com/3191/3025157090_3a1e785866.jpg" alt="The T does so well communicating with customers..." width="500" height="375" /></a></p>
<p style="text-align: left;">$3! I was in shock! I had heard nothing about this! Had the T had come to its senses and made a more reasonable increase? I was pleased, but my hopes were quickly dashed when I looked 3 feet to the right and saw this sign:</p>
<p style="text-align: center;"><a title="The T does so well communicating with customers... by innismir, on Flickr" href="http://www.flickr.com/photos/innismir/3024328383/"><img src="http://farm4.static.flickr.com/3292/3024328383_ffba47b5ba.jpg" alt="The T does so well communicating with customers..." width="500" height="375" /></a></p>
<p style="text-align: left;">Uhhhh&#8230; What? How much will it be MBTA? You have conflicting signs not even 3 feet apart at this station. Which one is correct? I did some research, and after looking at the <a href="http://www.mbta.com/riding_the_t/parking/">MBTA Parking Increase FAQ</a> I see no mention of a $3 rate at commuter rail spots.</p>
<p style="text-align: left;">What say you, MBTA?</p>
<p style="text-align: left;"><strong>UPDATE</strong> <strong>(11/13)</strong>: As of this morning, the &#8220;$3.00/day&#8221; sign is gone, proving that the MBTA was just playing a cruel joke on half-awake morning commuters. (I keed! I keed)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.innismir.net/article/159/feed</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Things you do not want to wake up to&#8230;</title>
		<link>http://www.innismir.net/article/45</link>
		<comments>http://www.innismir.net/article/45#comments</comments>
		<pubDate>Thu, 04 Sep 2008 14:17:47 +0000</pubDate>
		<dc:creator>Ben Jackson</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[hurricanes]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I make an effort to regularly check out the National Hurricane Center daily to make sure I know where the storms are going. This is what greeted me this morning: Click for larger *sigh* Looks like I&#8217;ll have to make sure everything is charged up Saturday&#8230; C&#8217;mon cone of uncertainty, shift right!]]></description>
			<content:encoded><![CDATA[<p>I make an effort to regularly check out the <a href="http://www.nhc.noaa.gov">National Hurricane Center</a> daily to make sure I know where the storms are going. This is what greeted me this morning:</p>
<p><a href="/etc/badnews_lg.png"><img src="/etc/badnews_sm.png" alt="" /></a><br />
Click for larger</p>
<p>*sigh*</p>
<p>Looks like I&#8217;ll have to make sure everything is charged up Saturday&#8230; C&#8217;mon cone of uncertainty, shift right!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.innismir.net/article/45/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>I don&#8217;t think you thought your cunning plan all the way through&#8230;</title>
		<link>http://www.innismir.net/article/44</link>
		<comments>http://www.innismir.net/article/44#comments</comments>
		<pubDate>Tue, 26 Aug 2008 15:48:14 +0000</pubDate>
		<dc:creator>Ben Jackson</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[From the Boston Globe (Emaphasis Mine) A junior at Needham High School posted students&#8217; schedules and identification numbers and teachers&#8217; classroom rosters on his Facebook account after hacking into an online student information system, school officials said yesterday.]]></description>
			<content:encoded><![CDATA[<p>From the <a href="http://www.boston.com/news/education/k_12/articles/2008/08/26/needham_schools_say_system_was_breached/">Boston Globe</a> (Emaphasis Mine)</p>
<blockquote><p>A junior at Needham High School <em>posted students&#8217; schedules and identification numbers and teachers&#8217; classroom rosters <strong>on his Facebook account</strong></em> after hacking into an online student information system, school officials said yesterday.</p></blockquote>
<p><img src="/etc/kittyballfail.jpg" alt="" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.innismir.net/article/44/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

