<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>J. Timothy King&#039;s Blog &#187; True Stories</title>
	<atom:link href="http://blog.jtimothyking.com/category/stories/true-stories/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.jtimothyking.com</link>
	<description>The Life of an Indie Romance Author</description>
	<lastBuildDate>Tue, 07 Sep 2010 15:24:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>God Has an Ironic Sense of Balance</title>
		<link>http://blog.jtimothyking.com/2010/07/23/god-has-an-ironic-sense-of-balance</link>
		<comments>http://blog.jtimothyking.com/2010/07/23/god-has-an-ironic-sense-of-balance#comments</comments>
		<pubDate>Fri, 23 Jul 2010 16:00:27 +0000</pubDate>
		<dc:creator>J. Timothy King</dc:creator>
				<category><![CDATA[About Tim King]]></category>
		<category><![CDATA[Stories]]></category>
		<category><![CDATA[True Stories]]></category>
		<category><![CDATA[car]]></category>
		<category><![CDATA[car repair]]></category>

		<guid isPermaLink="false">http://blog.jtimothyking.com/?p=2960</guid>
		<description><![CDATA[Photo © 2010 Mike Cohen CC 2.0 BY NC ND I apologize for the delay. It&#8217;s been over two weeks since my last post, and I haven&#8217;t replied to anyone&#8217;s comments or emails. Part of the reason is that I billed over 30 hours last week on this new software-development job, a heavy week for [...]]]></description>
			<content:encoded><![CDATA[<div style="float: right; margin: 0 0 1em 1em"><div id="attachment_2961" class="wp-caption alignright" style="width: 310px"><a href="http://www.flickr.com/photos/mike_c/4392609013/"><img src="http://blog.jtimothyking.com/wp-content/uploads/2010/07/2010-Toyota-Corolla-Front-View-Mike-Cohen-300x199.jpg" alt="" title="2010 Toyota Corolla (Front View)" width="300" height="199" class="size-medium wp-image-2961" /></a><p class="wp-caption-text">Photo © 2010 Mike Cohen CC 2.0 BY NC ND</p></div></div>
<p>I apologize for the delay. It&#8217;s been over two weeks since my last post, and I haven&#8217;t replied to anyone&#8217;s comments or emails. Part of the reason is that I billed over 30 hours last week on this new software-development job, a heavy week for an off-site contractor. (I&#8217;ll have to explain to you the math of billed contractor hours versus employee hours sometime.) And I&#8217;ll probably bill about 30 hours this week, too. In between those hours—at least last week—I spent numerous hours taxiing the family around, my Beloved to and from work, my daughter C to and from school. I would get up in the morning, drive around, and get home just in time to start working with the guys at Client Z, out on the west coast.</p>
<p>That&#8217;s because we had one working car, and it wasn&#8217;t even ours.</p>
<p>As you may recall, July 7, our one working car, the Saturn, died. The transmission got stuck in first gear, and the shifter was kinda just loose in the console. In fact, it wasn&#8217;t completely loose, but it also wasn&#8217;t attached to the transmission. I drove the car down the street—in first gear all the way—to Mike and his crew at <a href="http://longlifeautorepair.com/">Long Life Auto Repair</a>, my favorite mechanic and also the favorite of <a href="http://blog.jtimothyking.com/2010/03/03/bamboo-tiki-torch-indie-music-video">my brother and several of our friends</a>. Mike is always busy like you wouldn&#8217;t believe. Apparently, the recession has not diminished his business too much. (Possibly the reverse.)</p>
<p>Mike finally got back to me, told me the cable connecting the shifter to the transmission had broken, and to replace it would cost over $400. We had also asked them to look into why the car tended to overheat in stop-and-go traffic; new radiator fan, over $200. The final bill came to $655 and change, money we didn&#8217;t have.</p>
<p>Fortunately, I have a better relationship with my parents than Lorelai Gilmore has with hers, and I wasn&#8217;t too embarrassed to ask them for a loan. If this had happened next month, after my first invoice had been paid on the software-development contract, I would have had plenty of cash. But writing doesn&#8217;t pay as well as you might imagine (in your dreams), and money has been tight. Mom and Dad opened up their checkbook, and we were able to get the Saturn fixed. Kinda. Sorta.</p>
<p>Skipping ahead in the story, it took several days for them to get the parts in for the shifter repair. And then it still didn&#8217;t quite work right. It still gets stuck in gear, and sometimes out-of-gear, too. Truthfully, shifting has been hit-and-miss for a while, but it&#8217;s always seemed manageable to me. (Maybe it&#8217;s the way I drive.) We imagine that it got stuck in gear, and when my Beloved tried to shift, the cable broke. I finally got the car back, a week and a half after it broke down. And while the shifter does work, I can also reliably make it stick in gear. I also know how to get it unstuck.</p>
<p>(Short description, if your curious: Put the car in first gear or reverse, travel in that gear, then come to a complete stop. The transmission will be stuck in gear. To get it unstuck, put it in neutral while the car is rolling. Or alternatively, turn off the engine; that will also unstick it. Similarly, from other gears, shift into neutral while the car is still rolling, or else you may not be able to get it into first. For example, if you&#8217;re driving in fourth gear, after you come to a stop you&#8217;ll be able to shift into neutral, but then the car will be stuck in neutral. You&#8217;ll need to double-clutch or maybe even turn off the engine in order to unstick it.)</p>
<p>The gang at Long Life Auto thinks it may be the transmission, the clutch, or maybe one of the hydraulic cylinders controlling the clutch (preventing the clutch from fully disengaging). I don&#8217;t know yet how much it would cost to replace the cylinder, but anything else on that list would surely be a pricey bill for a 12-year-old car.</p>
<p>For now, I alone am using the car, and only for occasional, local driving, which is all I needed it for anyhow.</p>
<p>While the Saturn was in the shop, I was prepared to rent a car (using money we did not have). But my friend Tony (not his real name) had an extra vehicle, a small pickup truck he uses in his plastering business. Unfortunately, he had loaned the truck to his daughter, while her car was down at Mike&#8217;s. (Ah! So <em>that&#8217;s</em> why Mike couldn&#8217;t look at my car! &lt;g&gt;) However, Tony&#8217;s daughter&#8217;s husband loaned his car to Tony, so that Tony could loan his SUV to his wife, so that she could loan her car to my Beloved and me for a few days. Somehow, they managed to pull that together within 10 minutes of discussion without getting hopelessly confused. And after the daughter got her car back from the shop, they unwound the chain, and Tony loaned us his pickup over the weekend. So I doubly owe them.</p>
<p>Then Mom and Dad threw a curve ball at us. Apparently, they felt bad that they had bought two cars for my brother during his life, and also paid for his wedding rehearsal. And they helped my other brother and his wife buy a house. And all they had ever done for me and my Beloved was to patiently bear with my snotty teenage independence. Actually, they also helped me out after I had totalled my new <a href="http://en.wikipedia.org/wiki/Geo/Chevrolet_Prizm">Geo Prizm</a> in the winter of 1990. And they&#8217;ve been incredibly supportive of my writing career, such as it is, even though they may not realize how important that support is to me.</p>
<p>(I promise this story is almost over.)</p>
<p>So Mom and Dad threw us a curve ball. Long story short: they bought us a car. It&#8217;s a 2010 Toyota Corolla LE with about 10,000 miles on it, probably a corporate lease before we got it. The car pictured above is not ours, but ours is indeed silver, so it was <em>really</em> easy to find an online photo that looks just like it. Yes, I am now officially part of the lowest common denominator.</p>
<p>I actually haven&#8217;t gotten around to taking a picture of our new Toyota yet, but I understand that it&#8217;s already gotten into an accident with an SUV, in the parking garage at the doctor&#8217;s office. I haven&#8217;t seen the damage (if any), but&#8230; I had my Geo Prizm only a few months before I totalled it on I-95, and if you recall, the Prizm was essentially a rebranded Toyota Corolla. In fact, today&#8217;s Corollas still remind me of my old Prizm.</p>
<p>That&#8217;s why I say, God sometimes has an ironic sense of balance.</p>
<p>-TimK</p>



Share this post:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F23%2Fgod-has-an-ironic-sense-of-balance&amp;title=God%20Has%20an%20Ironic%20Sense%20of%20Balance&amp;bodytext=%0D%0A%0D%0AI%20apologize%20for%20the%20delay.%20It%27s%20been%20over%20two%20weeks%20since%20my%20last%20post%2C%20and%20I%20haven%27t%20replied%20to%20anyone%27s%20comments%20or%20emails.%20Part%20of%20the%20reason%20is%20that%20I%20billed%20over%2030%20hours%20last%20week%20on%20this%20new%20software-development%20job%2C%20a%20heavy%20week%20for%20an%20of" title="Digg"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F23%2Fgod-has-an-ironic-sense-of-balance&amp;title=God%20Has%20an%20Ironic%20Sense%20of%20Balance&amp;notes=%0D%0A%0D%0AI%20apologize%20for%20the%20delay.%20It%27s%20been%20over%20two%20weeks%20since%20my%20last%20post%2C%20and%20I%20haven%27t%20replied%20to%20anyone%27s%20comments%20or%20emails.%20Part%20of%20the%20reason%20is%20that%20I%20billed%20over%2030%20hours%20last%20week%20on%20this%20new%20software-development%20job%2C%20a%20heavy%20week%20for%20an%20of" title="del.icio.us"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F23%2Fgod-has-an-ironic-sense-of-balance&amp;t=God%20Has%20an%20Ironic%20Sense%20of%20Balance" title="Facebook"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F23%2Fgod-has-an-ironic-sense-of-balance&amp;title=God%20Has%20an%20Ironic%20Sense%20of%20Balance&amp;annotation=%0D%0A%0D%0AI%20apologize%20for%20the%20delay.%20It%27s%20been%20over%20two%20weeks%20since%20my%20last%20post%2C%20and%20I%20haven%27t%20replied%20to%20anyone%27s%20comments%20or%20emails.%20Part%20of%20the%20reason%20is%20that%20I%20billed%20over%2030%20hours%20last%20week%20on%20this%20new%20software-development%20job%2C%20a%20heavy%20week%20for%20an%20of" title="Google Bookmarks"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="javascript:AddToFavorites();" title="Add to favorites"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/addtofavorites.png" title="Add to favorites" alt="Add to favorites" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=God%20Has%20an%20Ironic%20Sense%20of%20Balance&amp;body=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F23%2Fgod-has-an-ironic-sense-of-balance" title="email"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.friendfeed.com/share?title=God%20Has%20an%20Ironic%20Sense%20of%20Balance&amp;link=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F23%2Fgod-has-an-ironic-sense-of-balance" title="FriendFeed"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://hellotxt.com/?status=God%20Has%20an%20Ironic%20Sense%20of%20Balance+http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F23%2Fgod-has-an-ironic-sense-of-balance" title="HelloTxt"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/hellotxt.png" title="HelloTxt" alt="HelloTxt" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.kirtsy.com/submit.php?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F23%2Fgod-has-an-ironic-sense-of-balance&amp;title=God%20Has%20an%20Ironic%20Sense%20of%20Balance" title="Kirtsy"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/kirtsy.png" title="Kirtsy" alt="Kirtsy" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F23%2Fgod-has-an-ironic-sense-of-balance&amp;title=God%20Has%20an%20Ironic%20Sense%20of%20Balance&amp;source=J.+Timothy+King%26%23039%3Bs+Blog+The+Life+of+an+Indie+Romance+Author&amp;summary=%0D%0A%0D%0AI%20apologize%20for%20the%20delay.%20It%27s%20been%20over%20two%20weeks%20since%20my%20last%20post%2C%20and%20I%20haven%27t%20replied%20to%20anyone%27s%20comments%20or%20emails.%20Part%20of%20the%20reason%20is%20that%20I%20billed%20over%2030%20hours%20last%20week%20on%20this%20new%20software-development%20job%2C%20a%20heavy%20week%20for%20an%20of" title="LinkedIn"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F23%2Fgod-has-an-ironic-sense-of-balance&amp;t=God%20Has%20an%20Ironic%20Sense%20of%20Balance" title="MySpace"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F23%2Fgod-has-an-ironic-sense-of-balance&amp;title=God%20Has%20an%20Ironic%20Sense%20of%20Balance" title="Reddit"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F23%2Fgod-has-an-ironic-sense-of-balance&amp;title=God%20Has%20an%20Ironic%20Sense%20of%20Balance" title="StumbleUpon"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=God%20Has%20an%20Ironic%20Sense%20of%20Balance%20-%20http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F23%2Fgod-has-an-ironic-sense-of-balance" title="Twitter"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.jtimothyking.com/2010/07/23/god-has-an-ironic-sense-of-balance/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another Car Bites the Dust?</title>
		<link>http://blog.jtimothyking.com/2010/07/07/another-car-bites-the-dust</link>
		<comments>http://blog.jtimothyking.com/2010/07/07/another-car-bites-the-dust#comments</comments>
		<pubDate>Wed, 07 Jul 2010 16:00:16 +0000</pubDate>
		<dc:creator>J. Timothy King</dc:creator>
				<category><![CDATA[About Tim King]]></category>
		<category><![CDATA[Stories]]></category>
		<category><![CDATA[True Stories]]></category>
		<category><![CDATA[car]]></category>
		<category><![CDATA[car repair]]></category>

		<guid isPermaLink="false">http://blog.jtimothyking.com/?p=2955</guid>
		<description><![CDATA[Photo © 2008 David J Laporte CC 2.0 BY &#8220;Why does all this stuff happen to us? It can&#8217;t be bad karma. We never did anything.&#8221; Or so says the Little One. And I think she&#8217;s right. Sometimes shit just happens. And if it could have waiting just another month or two, I wouldn&#8217;t even [...]]]></description>
			<content:encoded><![CDATA[<div style="float: right; margin: 0 0 1em 1em"><div id="attachment_2956" class="wp-caption alignright" style="width: 282px"><a href="http://www.flickr.com/photos/footloosiety/2902005407/"><img src="http://blog.jtimothyking.com/wp-content/uploads/2010/07/Abandoned-car-in-a-Provincial-park-David-J-Laporte-272x300.jpg" alt="" title="Abandoned car in a Provincial park" width="272" height="300" class="size-medium wp-image-2956" /></a><p class="wp-caption-text">Photo © 2008 David J Laporte CC 2.0 BY</p></div></div>
<p>&#8220;Why does all this stuff happen to us? It can&#8217;t be bad karma. We never did anything.&#8221; Or so says the Little One. And I think she&#8217;s right. Sometimes shit just happens.</p>
<p>And if it could have waiting just another month or two, I wouldn&#8217;t even be in a jam. Incredible. It&#8217;s like, just when you think things are looking up and you can breathe easy and ends will finally meet without stretching, the universe is like, &#8220;Uh. Hold on a sec—&#8221; Or as Dad puts it sometimes, &#8220;Cheer up! Things are going to get worse.&#8221;</p>
<p>(My Little One is not so little any more, BTW. But I still call her that. She insists. I don&#8217;t think she wants to grow up.)</p>
<p>Since last week, I&#8217;ve started working this new software-development contract. Last night, I had my first real &#8220;Aha!&#8221; moment. The engineer I&#8217;m working with seems a capable guy and easy to work with. Blessings for a confirmed cynic. Money&#8217;s still a little tight, until I get paid on my first invoice, which should happen in about a month. That&#8217;s how it is in independent contract work. But we can make it. And in the meantime, I&#8217;m keeping track day by day of how much I&#8217;ve earned. Yeah, money is a poor motivator, which is something that people say who already have plenty of money. But as it turns out, this contract looks like it will be bearable anyhow, and maybe even enjoyable. I was actually feeling pretty good about my situation.</p>
<p>And then&#8230;</p>
<p>Then my Beloved is taking my daughter C to her summer-school class, and the stick shift on our Saturn SL1 stops shifting. (That&#8217;s a lot of <em>S</em>&#8216;ssss.) It&#8217;s stuck in first gear, and the shifter feels like it&#8217;s just hanging loose in the console.</p>
<p>My first thought, of course, is &#8220;transmission,&#8221; and once you use the <em>T</em>-word, you&#8217;re potentially talking lots of money. And this car ain&#8217;t worth lots of money. But I wasn&#8217;t planning on buying a new car, and I can&#8217;t afford one. I wasn&#8217;t even planning on buying a new-for-me, used car, not even a cheap one.</p>
<p>A little Googling turned up others who have had <a href="http://www.fixya.com/cars/t1411568-saturn_shifter_linkage">what sounds like the same problem</a>. So if it is the same problem, and if my mechanic can find a reasonably priced replacement for the plastic part that broke, maybe it is still worth fixing.</p>
<p>In the meantime, I&#8217;m scraping together the cash for a tow truck and a rental car. If this had happened a month later, I wouldn&#8217;t need to scrape together the cash. Instead, I have to take time to deal with this, which makes it harder for me to find time for the contract work that will be ultimately pay for the repair.</p>
<p>This sucks. I&#8217;m sick and tired of borrowing against my future to pay for today&#8217;s emergencies. I wish God would just give me a break, just a small one, just 30-60 days in which I can breathe easy and sit back and go through my daily routine and all my needs will be met without a huge amount of stress.</p>
<p>And on that note&#8230; I guess we&#8217;ll have to see whether I&#8217;m buying a car or not.</p>
<p>-TimK</p>



Share this post:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F07%2Fanother-car-bites-the-dust&amp;title=Another%20Car%20Bites%20the%20Dust%3F&amp;bodytext=%0D%0A%0D%0A%22Why%20does%20all%20this%20stuff%20happen%20to%20us%3F%20It%20can%27t%20be%20bad%20karma.%20We%20never%20did%20anything.%22%20Or%20so%20says%20the%20Little%20One.%20And%20I%20think%20she%27s%20right.%20Sometimes%20shit%20just%20happens.%0D%0A%0D%0AAnd%20if%20it%20could%20have%20waiting%20just%20another%20month%20or%20two%2C%20I%20wouldn%27t%20even%20be%20i" title="Digg"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F07%2Fanother-car-bites-the-dust&amp;title=Another%20Car%20Bites%20the%20Dust%3F&amp;notes=%0D%0A%0D%0A%22Why%20does%20all%20this%20stuff%20happen%20to%20us%3F%20It%20can%27t%20be%20bad%20karma.%20We%20never%20did%20anything.%22%20Or%20so%20says%20the%20Little%20One.%20And%20I%20think%20she%27s%20right.%20Sometimes%20shit%20just%20happens.%0D%0A%0D%0AAnd%20if%20it%20could%20have%20waiting%20just%20another%20month%20or%20two%2C%20I%20wouldn%27t%20even%20be%20i" title="del.icio.us"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F07%2Fanother-car-bites-the-dust&amp;t=Another%20Car%20Bites%20the%20Dust%3F" title="Facebook"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F07%2Fanother-car-bites-the-dust&amp;title=Another%20Car%20Bites%20the%20Dust%3F&amp;annotation=%0D%0A%0D%0A%22Why%20does%20all%20this%20stuff%20happen%20to%20us%3F%20It%20can%27t%20be%20bad%20karma.%20We%20never%20did%20anything.%22%20Or%20so%20says%20the%20Little%20One.%20And%20I%20think%20she%27s%20right.%20Sometimes%20shit%20just%20happens.%0D%0A%0D%0AAnd%20if%20it%20could%20have%20waiting%20just%20another%20month%20or%20two%2C%20I%20wouldn%27t%20even%20be%20i" title="Google Bookmarks"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="javascript:AddToFavorites();" title="Add to favorites"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/addtofavorites.png" title="Add to favorites" alt="Add to favorites" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Another%20Car%20Bites%20the%20Dust%3F&amp;body=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F07%2Fanother-car-bites-the-dust" title="email"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.friendfeed.com/share?title=Another%20Car%20Bites%20the%20Dust%3F&amp;link=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F07%2Fanother-car-bites-the-dust" title="FriendFeed"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://hellotxt.com/?status=Another%20Car%20Bites%20the%20Dust%3F+http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F07%2Fanother-car-bites-the-dust" title="HelloTxt"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/hellotxt.png" title="HelloTxt" alt="HelloTxt" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.kirtsy.com/submit.php?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F07%2Fanother-car-bites-the-dust&amp;title=Another%20Car%20Bites%20the%20Dust%3F" title="Kirtsy"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/kirtsy.png" title="Kirtsy" alt="Kirtsy" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F07%2Fanother-car-bites-the-dust&amp;title=Another%20Car%20Bites%20the%20Dust%3F&amp;source=J.+Timothy+King%26%23039%3Bs+Blog+The+Life+of+an+Indie+Romance+Author&amp;summary=%0D%0A%0D%0A%22Why%20does%20all%20this%20stuff%20happen%20to%20us%3F%20It%20can%27t%20be%20bad%20karma.%20We%20never%20did%20anything.%22%20Or%20so%20says%20the%20Little%20One.%20And%20I%20think%20she%27s%20right.%20Sometimes%20shit%20just%20happens.%0D%0A%0D%0AAnd%20if%20it%20could%20have%20waiting%20just%20another%20month%20or%20two%2C%20I%20wouldn%27t%20even%20be%20i" title="LinkedIn"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F07%2Fanother-car-bites-the-dust&amp;t=Another%20Car%20Bites%20the%20Dust%3F" title="MySpace"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F07%2Fanother-car-bites-the-dust&amp;title=Another%20Car%20Bites%20the%20Dust%3F" title="Reddit"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F07%2Fanother-car-bites-the-dust&amp;title=Another%20Car%20Bites%20the%20Dust%3F" title="StumbleUpon"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Another%20Car%20Bites%20the%20Dust%3F%20-%20http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F07%2F07%2Fanother-car-bites-the-dust" title="Twitter"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.jtimothyking.com/2010/07/07/another-car-bites-the-dust/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>If I Die, Please Post This Posthumously</title>
		<link>http://blog.jtimothyking.com/2010/06/30/if-i-die-please-post-this-posthumously</link>
		<comments>http://blog.jtimothyking.com/2010/06/30/if-i-die-please-post-this-posthumously#comments</comments>
		<pubDate>Wed, 30 Jun 2010 17:32:39 +0000</pubDate>
		<dc:creator>J. Timothy King</dc:creator>
				<category><![CDATA[About Tim King]]></category>
		<category><![CDATA[Health]]></category>
		<category><![CDATA[Stories]]></category>
		<category><![CDATA[True Stories]]></category>
		<category><![CDATA[MRI]]></category>

		<guid isPermaLink="false">http://blog.jtimothyking.com/?p=2948</guid>
		<description><![CDATA[Photo © 2005 thomas23 CC 2.0 BY NC SA I&#8217;m sitting here in Dunkin&#8217; Donuts, Wednesday morning, with nothing that I feel like writing about, eating a delicious breakfast sandwich that will probably set my cholesterol and blood pressure back six months, mentally preparing for my MRI, which will take place in about a half [...]]]></description>
			<content:encoded><![CDATA[<div style="float: right; margin: 0 0 1em 1em"><div id="attachment_2949" class="wp-caption alignright" style="width: 243px"><a href="http://www.flickr.com/photos/livenow/66033055/"><img src="http://blog.jtimothyking.com/wp-content/uploads/2010/06/MRI-thomas23-233x300.jpg" alt="" title="MRI" width="233" height="300" class="size-medium wp-image-2949" /></a><p class="wp-caption-text">Photo © 2005 thomas23 CC 2.0 BY NC SA</p></div></div>
<p>I&#8217;m sitting here in Dunkin&#8217; Donuts, Wednesday morning, with nothing that I feel like writing about, eating a delicious breakfast sandwich that will probably set my cholesterol and blood pressure back six months, mentally preparing for my MRI, which will take place in about a half an hour. &#8220;Mentally preparing,&#8221; that&#8217;s the medical term for &#8220;working up anxiety that they actually might find something wrong with me, or that something might go wrong, like I&#8217;ll accidentally bring a steel nail file into the MRI room and the superconducting magnet will stab me to death with it, which I&#8217;m sure you agree would be not very pleasant.&#8221;</p>
<p>Why am I getting an MRI? The same reason I got a new BP prescription. (By &#8220;BP,&#8221; I mean &#8220;blood pressure,&#8221; and even though it does have to do with oil, not <em>that</em> kind of oil.) I&#8217;m getting an MRI, because over the past several months, I&#8217;ve been suffering from headaches, debilitating at times— migraines, we think, probably.</p>
<p>My father also suffered from migraines when he was about my age, and my brother and I were about the same age as my kids are now. Interestingly, as soon as we grew up and moved out of the house, my father&#8217;s migraines disappeared. So my headaches may be partially hereditary. The answer, in any case, seems clear: all I have to is wait until the kids grow up and move out, and then I can have nice things again.</p>
<p>In the meantime, my doctor recommended I try a different blood-pressure medication. I had been taking <a href="http://www.rxlist.com/prinzide-drug.htm">HCTZ/lisinopril</a>, and my BP was about 140/80, on the border of hypertension. Last week, he gave me a prescription for <a href="http://www.rxlist.com/atenolol-drug.htm">atenolol</a>, which partially blocks adrenaline (a β₁ blocker). Other beta-blockers are sometimes prescribed to treat migraines, and one of the side-effects of atenolol is that it sometimes relieves migraines.</p>
<p>So far, its effects on my headaches have been marginal at best. But give it another week.</p>
<p>One thing I did notice, however, is that about an hour after I took my first dose, my BP dropped to about 100/65, leading to another noted side-effect, dizziness. Since then, my BP has partially rebounded (120/75), but it&#8217;s still lower than it was before.</p>
<p>Aside from the new meds, my doctor also asked me to get an MRI. I guess it&#8217;s standard procedure when someone begins having headaches, even though 99 and some-large-number/100&#8242;ths percent of the time, they find absolutely nothing. (Find nothing <em>wrong</em>, that is.) They originally wanted me to have the procedure done, like, on the same day as my doctor&#8217;s appointment. (Ain&#8217;t US healthcare great?!) I had them push it off a week. Even so, I&#8217;m sure the MRI will make my Beloved happy, who worries about horrors like brain tumors.</p>
<p>It&#8217;s almost time for me to go check in at the MRI lab. So let me end this rambling post with one more thought. If I for some reason do not survive the procedure, would my heir please post this to my blog with a note that <strong>I told you so!</strong></p>
<p>-TimK</p>
<p>P.S. I clearly made it through the procedure, without incident, which is how I was able to post this to my blog. Maybe I&#8217;ll be able to get some <em>kewl</em> pictures to show.</p>



Share this post:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F06%2F30%2Fif-i-die-please-post-this-posthumously&amp;title=If%20I%20Die%2C%20Please%20Post%20This%20Posthumously&amp;bodytext=%0D%0A%0D%0AI%27m%20sitting%20here%20in%20Dunkin%27%20Donuts%2C%20Wednesday%20morning%2C%20with%20nothing%20that%20I%20feel%20like%20writing%20about%2C%20eating%20a%20delicious%20breakfast%20sandwich%20that%20will%20probably%20set%20my%20cholesterol%20and%20blood%20pressure%20back%20six%20months%2C%20mentally%20preparing%20for%20my%20MRI%2C%20whi" title="Digg"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F06%2F30%2Fif-i-die-please-post-this-posthumously&amp;title=If%20I%20Die%2C%20Please%20Post%20This%20Posthumously&amp;notes=%0D%0A%0D%0AI%27m%20sitting%20here%20in%20Dunkin%27%20Donuts%2C%20Wednesday%20morning%2C%20with%20nothing%20that%20I%20feel%20like%20writing%20about%2C%20eating%20a%20delicious%20breakfast%20sandwich%20that%20will%20probably%20set%20my%20cholesterol%20and%20blood%20pressure%20back%20six%20months%2C%20mentally%20preparing%20for%20my%20MRI%2C%20whi" title="del.icio.us"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F06%2F30%2Fif-i-die-please-post-this-posthumously&amp;t=If%20I%20Die%2C%20Please%20Post%20This%20Posthumously" title="Facebook"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F06%2F30%2Fif-i-die-please-post-this-posthumously&amp;title=If%20I%20Die%2C%20Please%20Post%20This%20Posthumously&amp;annotation=%0D%0A%0D%0AI%27m%20sitting%20here%20in%20Dunkin%27%20Donuts%2C%20Wednesday%20morning%2C%20with%20nothing%20that%20I%20feel%20like%20writing%20about%2C%20eating%20a%20delicious%20breakfast%20sandwich%20that%20will%20probably%20set%20my%20cholesterol%20and%20blood%20pressure%20back%20six%20months%2C%20mentally%20preparing%20for%20my%20MRI%2C%20whi" title="Google Bookmarks"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="javascript:AddToFavorites();" title="Add to favorites"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/addtofavorites.png" title="Add to favorites" alt="Add to favorites" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=If%20I%20Die%2C%20Please%20Post%20This%20Posthumously&amp;body=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F06%2F30%2Fif-i-die-please-post-this-posthumously" title="email"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.friendfeed.com/share?title=If%20I%20Die%2C%20Please%20Post%20This%20Posthumously&amp;link=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F06%2F30%2Fif-i-die-please-post-this-posthumously" title="FriendFeed"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://hellotxt.com/?status=If%20I%20Die%2C%20Please%20Post%20This%20Posthumously+http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F06%2F30%2Fif-i-die-please-post-this-posthumously" title="HelloTxt"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/hellotxt.png" title="HelloTxt" alt="HelloTxt" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.kirtsy.com/submit.php?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F06%2F30%2Fif-i-die-please-post-this-posthumously&amp;title=If%20I%20Die%2C%20Please%20Post%20This%20Posthumously" title="Kirtsy"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/kirtsy.png" title="Kirtsy" alt="Kirtsy" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F06%2F30%2Fif-i-die-please-post-this-posthumously&amp;title=If%20I%20Die%2C%20Please%20Post%20This%20Posthumously&amp;source=J.+Timothy+King%26%23039%3Bs+Blog+The+Life+of+an+Indie+Romance+Author&amp;summary=%0D%0A%0D%0AI%27m%20sitting%20here%20in%20Dunkin%27%20Donuts%2C%20Wednesday%20morning%2C%20with%20nothing%20that%20I%20feel%20like%20writing%20about%2C%20eating%20a%20delicious%20breakfast%20sandwich%20that%20will%20probably%20set%20my%20cholesterol%20and%20blood%20pressure%20back%20six%20months%2C%20mentally%20preparing%20for%20my%20MRI%2C%20whi" title="LinkedIn"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F06%2F30%2Fif-i-die-please-post-this-posthumously&amp;t=If%20I%20Die%2C%20Please%20Post%20This%20Posthumously" title="MySpace"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F06%2F30%2Fif-i-die-please-post-this-posthumously&amp;title=If%20I%20Die%2C%20Please%20Post%20This%20Posthumously" title="Reddit"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F06%2F30%2Fif-i-die-please-post-this-posthumously&amp;title=If%20I%20Die%2C%20Please%20Post%20This%20Posthumously" title="StumbleUpon"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=If%20I%20Die%2C%20Please%20Post%20This%20Posthumously%20-%20http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F06%2F30%2Fif-i-die-please-post-this-posthumously" title="Twitter"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.jtimothyking.com/2010/06/30/if-i-die-please-post-this-posthumously/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>For a Real Buzz, Touch This Microphone!</title>
		<link>http://blog.jtimothyking.com/2010/04/14/for-a-real-buzz-touch-this-microphone</link>
		<comments>http://blog.jtimothyking.com/2010/04/14/for-a-real-buzz-touch-this-microphone#comments</comments>
		<pubDate>Wed, 14 Apr 2010 16:00:46 +0000</pubDate>
		<dc:creator>J. Timothy King</dc:creator>
				<category><![CDATA[About Tim King]]></category>
		<category><![CDATA[Stories]]></category>
		<category><![CDATA[True Stories]]></category>
		<category><![CDATA[friendship]]></category>

		<guid isPermaLink="false">http://blog.jtimothyking.com/?p=2748</guid>
		<description><![CDATA[Photo © 2010 flickr.com/yhsoj CC BY-ND 2.0 Isn&#8217;t it funny, the snippets of life that our memories recall? Lately, my online buddy and comrade in words, Jim &#8220;Suldog&#8221; Sullivan, has been talking about his days as a garage-band bassist. On Monday, he told a story of how one of his bandmates electrocuted him as a [...]]]></description>
			<content:encoded><![CDATA[<div style="float: right; margin: 0 0 1em 1em"><div id="attachment_2750" class="wp-caption alignright" style="width: 190px"><a href="http://www.flickr.com/photos/yhsoj/4402390657/"><img src="http://blog.jtimothyking.com/wp-content/uploads/2010/04/Shocked-yshoj-180x240.jpg" alt="" title="Shocked!" width="180" height="240" class="size-full wp-image-2750" /></a><p class="wp-caption-text">Photo © 2010 flickr.com/yhsoj CC BY-ND 2.0</p></div></div>
<p>Isn&#8217;t it funny, the snippets of life that our memories recall?</p>
<p>Lately, my online buddy and comrade in words, Jim &#8220;Suldog&#8221; Sullivan, has been talking about his days as a garage-band bassist. On Monday, he told a story of how one of his bandmates <a href="http://jimsuldog.blogspot.com/2010/04/last-stand.html">electrocuted him as a joke</a>. And that reminded me of one of my own stories.</p>
<p>Okay, first of all, I must say one thing, as a fellow musician with experience in electrical engineering: Futzing with the ground wires is not a funny joke, dude. I don&#8217;t think I would have forgiven as readily as Jim did. He&#8217;s clearly a bigger man than I. (Or maybe that shock was simply bigger than either of us suspect.)</p>
<p>About 10 years ago, I was a keyboardist/bassist/guitarist/vocalist in a band called Priority One. Primarily, I played bass. But both D and I switched instruments between songs. So when I was playing keys, for example, he would pick up my bass. On one occasion, we gigged at a venue that had wiring problems. I knew they had wiring problems, because whenever I touched my keyboard&#8217;s metal chassis while also touching the microphone, I got a jolt. Either my keyboard or the mixing board (or both) was not grounded properly. As soon as I discovered the situation, I should have immediately done something about it. Maybe find a foam windscreen to insulate my lips from the mic. Or try plugging my keyboard into a different outlet. Or just run a wire from the microphone to the keyboard. (And if that shorted out the electrical system and blew a circuit breaker—or caught the place on fire—so much the better.)</p>
<p>Instead, I figured I could just avoid touching those two things at the same time. We were performing, after all, only one song where I was singing lead and playing keys. But during that song, I realized I needed to tweak the sound on my keyboard. Without even thinking, right in the middle of a verse, I reached up to move one of the controls. Before I knew it, I had almost blacked out from the current frying my synapses. But ever the professional, I continued with the song. People in the audience noticed a strange glitch in my performance, but they didn&#8217;t know I had just experienced my own version of the homemade defibrillator.</p>
<p>By the way, Jim says in his band, they typically closed the performance with a song called &#8220;Last Stand.&#8221; Interestingly, we frequently closed with a fun, bluesy tune called &#8220;Last Train Out,&#8221; which D had written. Here&#8217;s a recording we did of the song, with even less quality than the old recordings Jim has been posting:</p>
<p><script src="http://app.jtse.com/flowplayer/flowplayer-3.1.2.min.js"></script><br />
<a href="http://www.jtse.com/files/media/PriorityOne/last_train_out.mp3" style="display: block; width: 480px; height: 30px; margin: auto; text-align: center; border: 1px solid gray" id="player">Click here for the audio</a><br />
<script language="JavaScript"> 
flowplayer("player", "http://app.jtse.com/flowplayer/flowplayer-3.1.2.swf", {
    plugins: {
        audio: { url: 'http://app.jtse.com/flowplayer/flowplayer.audio-3.1.2.swf' },
        controls: { fullscreen: false, height: 30 }
    },
    clip: { autoPlay: true }
});
</script></p>
<h3>The Girl Not in the Love-Idiot Book</h3>
<p>In <em>Love through the Eyes of an Idiot</em>, I mentioned a few girls I knew growing up who would have made fine companions, but whom I avoided. And I mentioned some others who would have made fine nemeses, but whom I pursued. I also knew a couple girls who made good friends, but I didn&#8217;t remember many details of our friendships, because they didn&#8217;t manage to screw me up.</p>
<p>One such friend recently contacted me on Facebook. I did remember her, fondly, but I couldn&#8217;t even search for her, because I didn&#8217;t even remember her name until I saw it there on my Facebook page.</p>
<p>We took German together—and maybe Computer Science, too—at about the same time I met Erika (the &#8220;blonde in the pink sweater,&#8221; from chapter 3 of the Love-Idiot Book). I loved that German class, because the teacher did not just have us recite vocabulary—unlike a French class I took after I moved to Massachusetts. Rather, my German teacher played games with us. For example, occasionally, we cleared the desks from a space on the tiled floor, and we played German Scrabble: Giant-Size Edition. The same teacher also taught Comp-Sci, and he encouraged me to enter a state-wide programming competition. I made it to the finals, and I still have the program listings from that project. I also remember writing a program to generate cards for German Bingo, which we also played in his class, and another program that created word-search puzzles (for German Word-Search, of course).</p>
<p>Back to this girl I was friends with, whom I&#8217;ll call &#8220;Bee,&#8221; which is not her real name. I remember Bee being kinda cute, short, and she had a boyfriend. (I don&#8217;t remember him or anything about him. Not that it mattered, because we were strictly just classmates and pals, as you&#8217;ll see in a moment.) Aside from German and Comp-Sci, Bee and I also took a gym class together, and one day they made us do square dancing. (I guess we had to learn it eventually.) Of course, the first thing we had to do for a square dance was to find a partner, a task I absolutely loathed, because I was no good at it. But Bee came to my rescue, and I breathed easier. She told me she wanted to be my dancing partner, because she knew I was &#8220;safe.&#8221;</p>
<p>Now, many boys might have been upset at such an insult. And I vaguely remember rolling my eyes in disdain. But deep down, I remember feeling touched that she would think that highly of me. And that&#8217;s the memory I carry of her.</p>
<p>-TimK</p>



Share this post:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F14%2Ffor-a-real-buzz-touch-this-microphone&amp;title=For%20a%20Real%20Buzz%2C%20Touch%20This%20Microphone%21&amp;bodytext=%0D%0A%0D%0AIsn%27t%20it%20funny%2C%20the%20snippets%20of%20life%20that%20our%20memories%20recall%3F%0D%0A%0D%0ALately%2C%20my%20online%20buddy%20and%20comrade%20in%20words%2C%20Jim%20%22Suldog%22%20Sullivan%2C%20has%20been%20talking%20about%20his%20days%20as%20a%20garage-band%20bassist.%20On%20Monday%2C%20he%20told%20a%20story%20of%20how%20one%20of%20his%20bandmate" title="Digg"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F14%2Ffor-a-real-buzz-touch-this-microphone&amp;title=For%20a%20Real%20Buzz%2C%20Touch%20This%20Microphone%21&amp;notes=%0D%0A%0D%0AIsn%27t%20it%20funny%2C%20the%20snippets%20of%20life%20that%20our%20memories%20recall%3F%0D%0A%0D%0ALately%2C%20my%20online%20buddy%20and%20comrade%20in%20words%2C%20Jim%20%22Suldog%22%20Sullivan%2C%20has%20been%20talking%20about%20his%20days%20as%20a%20garage-band%20bassist.%20On%20Monday%2C%20he%20told%20a%20story%20of%20how%20one%20of%20his%20bandmate" title="del.icio.us"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F14%2Ffor-a-real-buzz-touch-this-microphone&amp;t=For%20a%20Real%20Buzz%2C%20Touch%20This%20Microphone%21" title="Facebook"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F14%2Ffor-a-real-buzz-touch-this-microphone&amp;title=For%20a%20Real%20Buzz%2C%20Touch%20This%20Microphone%21&amp;annotation=%0D%0A%0D%0AIsn%27t%20it%20funny%2C%20the%20snippets%20of%20life%20that%20our%20memories%20recall%3F%0D%0A%0D%0ALately%2C%20my%20online%20buddy%20and%20comrade%20in%20words%2C%20Jim%20%22Suldog%22%20Sullivan%2C%20has%20been%20talking%20about%20his%20days%20as%20a%20garage-band%20bassist.%20On%20Monday%2C%20he%20told%20a%20story%20of%20how%20one%20of%20his%20bandmate" title="Google Bookmarks"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="javascript:AddToFavorites();" title="Add to favorites"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/addtofavorites.png" title="Add to favorites" alt="Add to favorites" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=For%20a%20Real%20Buzz%2C%20Touch%20This%20Microphone%21&amp;body=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F14%2Ffor-a-real-buzz-touch-this-microphone" title="email"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.friendfeed.com/share?title=For%20a%20Real%20Buzz%2C%20Touch%20This%20Microphone%21&amp;link=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F14%2Ffor-a-real-buzz-touch-this-microphone" title="FriendFeed"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://hellotxt.com/?status=For%20a%20Real%20Buzz%2C%20Touch%20This%20Microphone%21+http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F14%2Ffor-a-real-buzz-touch-this-microphone" title="HelloTxt"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/hellotxt.png" title="HelloTxt" alt="HelloTxt" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.kirtsy.com/submit.php?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F14%2Ffor-a-real-buzz-touch-this-microphone&amp;title=For%20a%20Real%20Buzz%2C%20Touch%20This%20Microphone%21" title="Kirtsy"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/kirtsy.png" title="Kirtsy" alt="Kirtsy" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F14%2Ffor-a-real-buzz-touch-this-microphone&amp;title=For%20a%20Real%20Buzz%2C%20Touch%20This%20Microphone%21&amp;source=J.+Timothy+King%26%23039%3Bs+Blog+The+Life+of+an+Indie+Romance+Author&amp;summary=%0D%0A%0D%0AIsn%27t%20it%20funny%2C%20the%20snippets%20of%20life%20that%20our%20memories%20recall%3F%0D%0A%0D%0ALately%2C%20my%20online%20buddy%20and%20comrade%20in%20words%2C%20Jim%20%22Suldog%22%20Sullivan%2C%20has%20been%20talking%20about%20his%20days%20as%20a%20garage-band%20bassist.%20On%20Monday%2C%20he%20told%20a%20story%20of%20how%20one%20of%20his%20bandmate" title="LinkedIn"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F14%2Ffor-a-real-buzz-touch-this-microphone&amp;t=For%20a%20Real%20Buzz%2C%20Touch%20This%20Microphone%21" title="MySpace"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F14%2Ffor-a-real-buzz-touch-this-microphone&amp;title=For%20a%20Real%20Buzz%2C%20Touch%20This%20Microphone%21" title="Reddit"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F14%2Ffor-a-real-buzz-touch-this-microphone&amp;title=For%20a%20Real%20Buzz%2C%20Touch%20This%20Microphone%21" title="StumbleUpon"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=For%20a%20Real%20Buzz%2C%20Touch%20This%20Microphone%21%20-%20http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F14%2Ffor-a-real-buzz-touch-this-microphone" title="Twitter"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.jtimothyking.com/2010/04/14/for-a-real-buzz-touch-this-microphone/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
<enclosure url="http://www.jtse.com/files/media/PriorityOne/last_train_out.mp3" length="1003292" type="audio/mpeg" />
		</item>
		<item>
		<title>Grand Theft Internet (part 5)</title>
		<link>http://blog.jtimothyking.com/2010/04/06/grand-theft-internet-part-5</link>
		<comments>http://blog.jtimothyking.com/2010/04/06/grand-theft-internet-part-5#comments</comments>
		<pubDate>Tue, 06 Apr 2010 21:54:40 +0000</pubDate>
		<dc:creator>J. Timothy King</dc:creator>
				<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[Stories]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[True Stories]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[domain hijacking]]></category>
		<category><![CDATA[domain theft]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[true crime]]></category>

		<guid isPermaLink="false">http://blog.jtimothyking.com/?p=2645</guid>
		<description><![CDATA[This is a true cybercrime story, which hit my friend Tom. Click here to read the story from the beginning. OR Click here to read the whole story as a single page. Chapter 5 Sunday, March 28, 8:06 PM EDT &#8220;They stole vl.com!!!!!!!!!!!!!!!!!!!!!!!!&#8221; By 7:45, Glen had discovered that the attacker had been manipulating the [...]]]></description>
			<content:encoded><![CDATA[<p>This is a true cybercrime story, which hit my friend Tom. <a href="http://blog.jtimothyking.com/2010/03/31/grand-theft-internet-part-1">Click here to read the story from the beginning.</a> OR <a href="http://blog.jtimothyking.com/2010/03/31/grand-theft-internet">Click here to read the whole story as a single page.</a></p>
<h3>Chapter 5</h3>
<p><em>Sunday, March 28, 8:06 PM EDT</em></p>
<p>&#8220;They stole vl.com!!!!!!!!!!!!!!!!!!!!!!!!&#8221;</p>
<p>By 7:45, Glen had discovered that the attacker had been manipulating the DreamHost support people in order to crack into Tom&#8217;s account and steal VL.com, a tactic called &#8220;social engineering.&#8221; Glen discovered this just minutes too late.</p>
<p>Glen immediately promised to gather forensic evidence in order to get back Tom&#8217;s domain, to insist on reforms of DreamHost&#8217;s policies and practices, and to pursue prosecution. He confirmed that there had been a security breach at DreamHost, and that the support people on chat were not supposed to be making changes on customers&#8217; accounts. DreamHost serves as registrar for over a half-million domain names, and hosts close to a million websites, and the attacker could have gone after any of these— and still could. No doubt, the story, as he reconstructed it, stunned and panicked him and everyone else at DreamHost.</p>
<p>In most incidents of stolen domains, once the domain is transferred away, there&#8217;s little the rightful owner can do to get it back. File a police report: check. But aside from the blank stares, you&#8217;re likely to get little response. File a report with the FBI: check. But while the FBI is very interested in being informed, unless there&#8217;s substantial monetary loss, they can&#8217;t justify the resources needed to investigate and prosecute. Challenge the domain on trademark grounds, but that will cost thousands of dollars and take God-knows-how-long. You could even beg with the foreign registrar, but without conclusive evidence of fraud, they won&#8217;t undo the transfer. Most businesses who lose their domains to domain hijacking or domain theft, they simply give up.</p>
<p>The break in the case was perhaps Glen&#8217;s enthusiasm. Many companies would have clammed up in the face of these circumstances— Indeed, many have done so, whether to avoid being sued or just to avoid being bothered. And without DreamHost&#8217;s help, Tom&#8217;s situation would have been as bleak as the rain-soaked skies that week. If Tom had complained to the registrar in the Bahamas, they probably would have dismissed him. But when an official DreamHost representative did so, they listened. They locked down the domain, which at least kept Tom&#8217;s Internet services up and running. They considered the evidence that Glen had dug up, which clearly showed fraud. And they promised to return the domain, once the paperwork had been processed.</p>
<p>Interestingly enough, the cracker refused to give up. He opened a fake Gmail account, impersonating Tom, in an attempt to trick the registrar in the Bahamas into releasing the lock on the domain. And he hit DreamHost support again at about the same time, trying to get them to stop asking for the domain back. Then he attempted again to break in to Tom&#8217;s Google-hosted domain, by trying to trick DreamHost into modifying the domain configuration— using the same MO: claim he tried to make the change himself, make up a story about encountering an error, and ask the support person to make the change for him. This would have allowed him to access all the email stored in all the accounts on that domain. But he probably only wanted to impersonate Tom, in order to call off the investigation. He may have made other attempts as well, attempts that we do not know of yet.</p>
<hr />
<p>But the real question is how to proceed going forward.</p>
<p>This story is not about DreamHost. It&#8217;s about the domain industry. Domain theft happens on the Internet, and social engineering is one of the thief&#8217;s primary tactics. The most famous case is probably the theft of Sex.com, which is probably famous because of the letters S, E, and X. It took Gary Kremen years to get that domain back.</p>
<p>Moving my domains away from DreamHost doesn&#8217;t necessarily solve the problem. Because a cracker can attack any registrar. If I have a diamond necklace worth $100,000, I can keep it in a bank safe-deposit vault. And short of a Mission-Impossible-style heist, I can feel pretty safe that it&#8217;ll remain in my possession. If I have a domain name worth $100,000, there is no safe-deposit vault, and the quality of security at different registrars varies.</p>
<p>Additionally, the law is only beginning to see domain names as &#8220;property,&#8221; even though, of all the things we call &#8220;intellectual property,&#8221; domain names bear the closest similarity to real property. Until the law catches up to modern technology, we have to fend for ourselves.</p>
<p>As a defense, maybe there&#8217;s some value in looking for a registrar who&#8217;s as paranoid as I am. Maybe right now, that&#8217;s still DreamHost, because they&#8217;ve been spooked. And maybe there&#8217;s also some value in a registrar who will come clean when there&#8217;s a break-in, and do their best to set things right. Maybe that, too, is DreamHost. But I find it disheartening that if I go into a crowded room full of IT gurus and ask, &#8220;Where can I register my domain to keep it safe?&#8221; the best I get is, &#8220;Well, I&#8217;ve been happy with such-and-such a registrar, but no one&#8217;s ever tried to rip me off before.&#8221; No one cites any systematic studies of domain registrar security practices, and there&#8217;s no single registrar that comes to the top as <em>the</em> name in domain security for the average business.</p>
<p>Even so, there&#8217;s some value in looking for registrars that offer increased security and services, even at slightly increased prices and with longer waiting times:</p>
<ul>
<li>positively identifying the domain owner before releasing a domain to another registrar, such as with two-factor authentication being offered by some registrars;</li>
<li>confirming domain transfers through phone calls or cellphone text messages, as well as the standard email;</li>
<li>approving domain transfers through multiple, independent means, or multiple, independent accounts, all of which must approve before the transfer goes through;</li>
<li>effective crisis procedures, when a break-in does occur;</li>
<li>effective forensic and recovery procedures, when a theft occurs;</li>
<li>insurability—if a domain name is stolen, the insurance company will pay for recovery or losses.</li>
</ul>
<p>Notice I did not include domain locking in the above list, even though that&#8217;s the first thing most people mention when they talk about protecting your domain. Why not? Because (1) it&#8217;s a standard feature, (2) usually all the cracker has to do to turn it off is to click a button on some administrative panel, and (3) it can&#8217;t protect you from lax security at your registrar or a break-in of your account. However, I might add confirmed domain locking to the list, that is, require approval through an independent email address or cellphone text message before anyone can unlock the domain.</p>
<p>Changes to approval email addresses also should use the same approval process. So for example, no changes should be made to my account email address without affirmative approval via that email address. The current standard system, which at best sends out a &#8220;email address has changed&#8221; message, that&#8217;s inadequate for domain security, because a secure system is only as strong as its weakest link.</p>
<p>Even registrars of high-profile domains such as Amazon.com, BarnesAndNoble.com, and Coke.com don&#8217;t offer services like these. And some high profile domains (such as Comcast.net) have indeed been hijacked. Fortunately, if you&#8217;re Amazon or Coke, you can probably get your domain back pretty quickly with a simple phone call. But if you&#8217;re not, you need a registrar that&#8217;s going to stand up for you, no matter how small you are. And you can expect it to take days at best, or weeks, or months, or years, or forever.</p>
<p>There are some additional safety measures you can take to slow up a thief trying to steal your domain:</p>
<ul>
<li>Use a secret email address for your account email.</li>
<li>Always use a secure computer and encrypted connection to download email.</li>
<li>Use long, random passwords for each email and domain account.</li>
<li>Use secure secrets for any &#8220;secret question,&#8221; obscure facts that no one else can find out.</li>
<li>If you have multiple domain names or web holdings, split them up between multiple registrars and hosting services.</li>
<li>Use low-value domains for daily activities, if possible. (So if someone steals away VL.com, your email will still continue uninterrupted through VentureLogic.com.)</li>
<li>Know how to get in touch with your registrar in an emergency, whether by phone, email, or web form, even if you&#8217;ve been locked out of your account by an attacker.</li>
<li>Establish secure, authenticated communication channels with people you are likely to work with to resolve a crisis: obtain email certificates, exchange public keys, and set up secure IM.</li>
<li>At least ask yourself, &#8220;Will that busty model come to my rescue when I have a problem with my domain?&#8221;</li>
</ul>
<p>Unfortunately, as long as an attacker can trick the registrar to bypass security, neither strong passwords nor two-factor authentication nor double confirmation nor any other security measure will be effective.</p>
<p>Conceptually, you could even test a domain registrar. Try to convince them to shortcut security for you, in order to make legitimate changes to your account. And if they do, bolt. I can&#8217;t comment on whether that&#8217;s legal or not. But as for me, I&#8217;d be interested in a broad-based study of how tight security really is at the Internet&#8217;s top domain registrars.</p>
<p>-TimK</p>
<p>Additional resources:</p>
<ul>
<li><a href="http://www.vtalkradio.com/bjorn.asp">Interview with Bjørn K. Andersen, who had Direction.com stolen.</a></li>
<li><a href="http://www.domainnamenews.com/featured/criminal-prosecution-domain-theft-underway/5675">The story of the theft of P2P.com, and the first ever criminal prosecution of a domain thief.</a></li>
<li><a href="http://www.icann.org/en/announcements/hijacking-report-12jul05.pdf">2005 ICANN SSAC report on domain hijacking.</a></li>
<li><a href="http://www.dyndns.com/support/kb/domain_hijacking.html">DynDNS on domain hijacking.</a></li>
<li><a href="http://www.moniker.com/">Moniker.com, a registrar that advertises a higher than average level of domain security.</a></li>
</ul>
<p>Other mentions of the theft of VL.com:</p>
<ul>
<li><a href="http://domainnamewire.com/2010/04/03/vl-com-domain-name-stolen-too-heres-the-inside-story/">Report on the theft, on Domain News Wire.</a></li>
<li><a href="http://old.nabble.com/Dreamhost-account-hacked-td28062149s24859.html">Boston Linux &#038; Unix users&#8217; group discussion, as the story unfolded</a></li>
<li><a href="http://www.mail-archive.com/boston-pm@mail.pm.org/msg05971.html">Boston PerlMonger&#8217;s discussion</a></li>
<li><a href="http://news.ycombinator.com/item?id=1229247">Hacker News discussion</a></li>
</ul>



Share this post:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F06%2Fgrand-theft-internet-part-5&amp;title=Grand%20Theft%20Internet%20%28part%205%29&amp;bodytext=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%0D%0A%0D%0AChapter%205%0D%0A%0D%0ASunday%2C%20March%2028%2C%208%3A06%20PM%20EDT%0D%0A%0D%0A%22They%20stole%20vl.com%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21" title="Digg"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F06%2Fgrand-theft-internet-part-5&amp;title=Grand%20Theft%20Internet%20%28part%205%29&amp;notes=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%0D%0A%0D%0AChapter%205%0D%0A%0D%0ASunday%2C%20March%2028%2C%208%3A06%20PM%20EDT%0D%0A%0D%0A%22They%20stole%20vl.com%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21" title="del.icio.us"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F06%2Fgrand-theft-internet-part-5&amp;t=Grand%20Theft%20Internet%20%28part%205%29" title="Facebook"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F06%2Fgrand-theft-internet-part-5&amp;title=Grand%20Theft%20Internet%20%28part%205%29&amp;annotation=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%0D%0A%0D%0AChapter%205%0D%0A%0D%0ASunday%2C%20March%2028%2C%208%3A06%20PM%20EDT%0D%0A%0D%0A%22They%20stole%20vl.com%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21" title="Google Bookmarks"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="javascript:AddToFavorites();" title="Add to favorites"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/addtofavorites.png" title="Add to favorites" alt="Add to favorites" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Grand%20Theft%20Internet%20%28part%205%29&amp;body=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F06%2Fgrand-theft-internet-part-5" title="email"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.friendfeed.com/share?title=Grand%20Theft%20Internet%20%28part%205%29&amp;link=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F06%2Fgrand-theft-internet-part-5" title="FriendFeed"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://hellotxt.com/?status=Grand%20Theft%20Internet%20%28part%205%29+http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F06%2Fgrand-theft-internet-part-5" title="HelloTxt"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/hellotxt.png" title="HelloTxt" alt="HelloTxt" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.kirtsy.com/submit.php?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F06%2Fgrand-theft-internet-part-5&amp;title=Grand%20Theft%20Internet%20%28part%205%29" title="Kirtsy"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/kirtsy.png" title="Kirtsy" alt="Kirtsy" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F06%2Fgrand-theft-internet-part-5&amp;title=Grand%20Theft%20Internet%20%28part%205%29&amp;source=J.+Timothy+King%26%23039%3Bs+Blog+The+Life+of+an+Indie+Romance+Author&amp;summary=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%0D%0A%0D%0AChapter%205%0D%0A%0D%0ASunday%2C%20March%2028%2C%208%3A06%20PM%20EDT%0D%0A%0D%0A%22They%20stole%20vl.com%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21%21" title="LinkedIn"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F06%2Fgrand-theft-internet-part-5&amp;t=Grand%20Theft%20Internet%20%28part%205%29" title="MySpace"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F06%2Fgrand-theft-internet-part-5&amp;title=Grand%20Theft%20Internet%20%28part%205%29" title="Reddit"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F06%2Fgrand-theft-internet-part-5&amp;title=Grand%20Theft%20Internet%20%28part%205%29" title="StumbleUpon"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Grand%20Theft%20Internet%20%28part%205%29%20-%20http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F06%2Fgrand-theft-internet-part-5" title="Twitter"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.jtimothyking.com/2010/04/06/grand-theft-internet-part-5/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Grand Theft Internet (part 4)</title>
		<link>http://blog.jtimothyking.com/2010/04/05/grand-theft-internet-part-4</link>
		<comments>http://blog.jtimothyking.com/2010/04/05/grand-theft-internet-part-4#comments</comments>
		<pubDate>Mon, 05 Apr 2010 16:00:40 +0000</pubDate>
		<dc:creator>J. Timothy King</dc:creator>
				<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[Stories]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[True Stories]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[domain hijacking]]></category>
		<category><![CDATA[domain theft]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[true crime]]></category>

		<guid isPermaLink="false">http://blog.jtimothyking.com/?p=2635</guid>
		<description><![CDATA[This is a true cybercrime story, which hit my friend Tom. Click here to read the story from the beginning. OR Click here to read the whole story as a single page. Chapter 4 Sunday, March 28, 2:40 PM EDT Glen, from DreamHost&#8217;s abuse-response team, replied to our support request, saying that Tom should provide [...]]]></description>
			<content:encoded><![CDATA[<p>This is a true cybercrime story, which hit my friend Tom. <a href="http://blog.jtimothyking.com/2010/03/31/grand-theft-internet-part-1">Click here to read the story from the beginning.</a> OR <a href="http://blog.jtimothyking.com/2010/03/31/grand-theft-internet">Click here to read the whole story as a single page.</a></p>
<h3>Chapter 4</h3>
<p><em>Sunday, March 28, 2:40 PM EDT</em></p>
<p>Glen, from DreamHost&#8217;s abuse-response team, replied to our support request, saying that Tom should provide certain billing details, in order to verify that he owned the account. That&#8217;s DreamHost&#8217;s standard procedure. But we believed that someone might be listening in on DreamHost&#8217;s email. How to convince Glen that this issue needs looking into? Tom emailed him back, explaining that he believed that DreamHost&#8217;s email servers had been compromised, asking to talk via phone or to send the data via fax.</p>
<p>Tom said to me, &#8220;I&#8217;m sure they&#8217;ve chalked this up to some customer with sloppy security getting their email compromised.&#8221;</p>
<p>Shortly thereafter, Glen confirmed that suspicion. He said that while he was open to evidence that DreamHost&#8217;s network had been compromised, there hadn&#8217;t been break-ins on any other accounts. He suggested that Tom scan his computer for viruses, to make sure there wasn&#8217;t something installed on it that was listening in on his email.</p>
<p>Tom shot back, &#8220;It&#8217;s a Linux machine with a secure password behind a firewall. I have a clue about security. The <strong>only</strong> place I am seeing any evidence of a breach is with DreamHost. The attacker attempted, and failed, to reset the password on my Google-hosted account. If he had compromised my machine here, he would have been able to intercept that email.&#8221;</p>
<p>That seemed to have been persuasive, as Glen looked at the situation in more detail. Although he didn&#8217;t find any record that Tom&#8217;s account password had been accessed, he accepted that Tom knew enough about security in order to avoid the common mistakes that people usually make. He also restored the account&#8217;s original email address, which gave Tom access again.</p>
<p>At around this time, Tom&#8217;s Google-hosted account received an email that someone was trying to transfer VL.com away to another registrar. Unfortunately, Google thought it was spam. Tom wouldn&#8217;t find the notice until another day had passed.</p>
<hr />
<p><em>Sunday, March 28, 6:09 PM EDT</em></p>
<p>The dark figure had requested that VL.com be transferred away to a registrar in the Bahamas. But by the time the request had gone through, he had been locked out of the DreamHost account. If he could crack back in, however, maybe he could still complete the transfer.</p>
<p>Using a tried-and-true method, he chatted with DreamHost support. &#8220;Need update current email on file, but still not successful,&#8221; he said in his trademark broken English.</p>
<p>He was on the line with Schroder, who tried to walk him through the process.</p>
<p>But that would do the dark figure no good, because he couldn&#8217;t actually log into the account. His goal was to beg, trick, or badger Schroder into making the change for him. &#8220;Can you done it for me?&#8221; he asked.</p>
<p>&#8220;No,&#8221; Schroder replied, &#8220;I&#8217;m sorry. I can&#8217;t change it for you.&#8221;</p>
<p>&#8220;I can verify ownership,&#8221; the dark figure said. He gave Schroder the answer to the security question, which he had set earlier just for this contingency. He also recited the last four digits of the account&#8217;s credit card, which he had gotten from the account&#8217;s control panel and written down.</p>
<p>Schroder said, &#8220;If you can&#8217;t walk me through the method you&#8217;re using to change the info, then, I&#8217;m sorry, but I can&#8217;t help you with this.&#8221;</p>
<p>&#8220;Ok. Thanks,&#8221; the dark figure wrote, resolving to try back later with a different support rep.</p>
<hr />
<p><em>Sunday, March 28, 6:52 PM EDT</em></p>
<p>While Tom waited for his browser to start up, he told me that he had two different contract programming jobs to work on this weekend, and he wanted to upgrade his operating system and switch his MythTV box over to a digital tuner. I guess he wasn&#8217;t going to make any progress on any of those projects.</p>
<p>&#8220;Look on the bright side,&#8221; I said. &#8220;Can&#8217;t think of what that is. But I&#8217;m sure there&#8217;s one there&#8230; somewhere.&#8221;</p>
<p>&#8220;Metaphorical bruises are often good to motivate you to take corrective action against repeating the mistake,&#8221; Tom replied.</p>
<p>He finally got back into his account, changed the account&#8217;s login email address, locked out the attacker, and reset the passwords. He examined his domains. They were all still there. He couldn&#8217;t tell whether VL.com was still locked, but all the domain-name configuration looked correct.</p>
<p>By then, it was at 7:08 PM.</p>
<p>Meanwhile&#8230;</p>
<hr />
<p><em>Sunday, March 28, 7:07 PM EDT</em></p>
<p>The dark figure tried again with DreamHost&#8217;s support chat. This time, he got Jeremy. He explained, impersonating Tom, that he was trying to change the primary address on Tom&#8217;s account.</p>
<p>Within a few minutes, Jeremy had solved his problem.</p>
<p>The dark figure used the automated system to reset the password on Tom&#8217;s account, knowing that as soon as he could get in, he would be able to complete the theft. But before he could lock Tom out, someone had already overridden the request. Clearly, Tom was onto him, logged into the system, and actively fighting with him for control of the account.</p>
<p>Time to switch tactics.</p>
<hr />
<p><em>Sunday, March 28, 7:19 PM EDT</em></p>
<p>Tom was on the DreamHost support chat with Jason. &#8220;Help. My DH account is actively being hacked.&#8221;</p>
<p>&#8220;Unfortunately,&#8221; Jason said, &#8220;any inquiries pertaining to hacked sites or accounts need to be taken care of via email so our abuse/security team can assist you. This isn&#8217;t something I can help you with via Live Chat.&#8221;</p>
<p>&#8220;Glen reset my password about an hour ago,&#8221; Tom explained, &#8220;and the attacker is repeating the attack.&#8221;</p>
<p>&#8220;Okay, you will need to submit a support ticket for this. Thank you!&#8221;</p>
<p>Meanwhile&#8230;</p>
<hr />
<p><em>Sunday, March 28, 7:19 PM EDT</em></p>
<p>The dark figure contacted Seohee via the DreamHost support chat, still impersonating Tom, told him he was having trouble transferring VL.com away, and asked for help.</p>
<p>He was worried that Tom may have already discovered the pending transfer and may have locked down the domain. &#8220;What&#8217;s current status of &#8216;TRANSFER AWAY&#8217;?&#8221; he asked. &#8220;It&#8217;s canceled?&#8221;</p>
<p>No, it wasn&#8217;t canceled. It was still pending. The dark figure told Seohee a story about trying to approve the transfer but receiving an error. &#8220;Please approve it from your admin end. Restarting transfer request taking few days.&#8221; Sadly.</p>
<p>&#8220;Please hold,&#8221; Seohee said.</p>
<p>Within a couple minutes, the dark figure was able to write: &#8220;I can see it&#8217;s approved. And in new registrar.&#8221;</p>
<p>&#8220;Thanks for hanging in there. sorry for the confusion,&#8221; Seohee wrote.</p>
<p>&#8220;Thanks again. Have great day,&#8221; replied the dark figure.</p>
<p>&#8220;You too!&#8221;</p>
<p>Finally, everyone was happy.</p>
<p>(to be concluded, tomorrow)</p>



Share this post:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F05%2Fgrand-theft-internet-part-4&amp;title=Grand%20Theft%20Internet%20%28part%204%29&amp;bodytext=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%0D%0A%0D%0AChapter%204%0D%0A%0D%0ASunday%2C%20March%2028%2C%202%3A40%20PM%20EDT%0D%0A%0D%0AGlen%2C%20from%20DreamHost%27s%20abuse-response%20" title="Digg"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F05%2Fgrand-theft-internet-part-4&amp;title=Grand%20Theft%20Internet%20%28part%204%29&amp;notes=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%0D%0A%0D%0AChapter%204%0D%0A%0D%0ASunday%2C%20March%2028%2C%202%3A40%20PM%20EDT%0D%0A%0D%0AGlen%2C%20from%20DreamHost%27s%20abuse-response%20" title="del.icio.us"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F05%2Fgrand-theft-internet-part-4&amp;t=Grand%20Theft%20Internet%20%28part%204%29" title="Facebook"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F05%2Fgrand-theft-internet-part-4&amp;title=Grand%20Theft%20Internet%20%28part%204%29&amp;annotation=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%0D%0A%0D%0AChapter%204%0D%0A%0D%0ASunday%2C%20March%2028%2C%202%3A40%20PM%20EDT%0D%0A%0D%0AGlen%2C%20from%20DreamHost%27s%20abuse-response%20" title="Google Bookmarks"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="javascript:AddToFavorites();" title="Add to favorites"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/addtofavorites.png" title="Add to favorites" alt="Add to favorites" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Grand%20Theft%20Internet%20%28part%204%29&amp;body=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F05%2Fgrand-theft-internet-part-4" title="email"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.friendfeed.com/share?title=Grand%20Theft%20Internet%20%28part%204%29&amp;link=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F05%2Fgrand-theft-internet-part-4" title="FriendFeed"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://hellotxt.com/?status=Grand%20Theft%20Internet%20%28part%204%29+http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F05%2Fgrand-theft-internet-part-4" title="HelloTxt"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/hellotxt.png" title="HelloTxt" alt="HelloTxt" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.kirtsy.com/submit.php?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F05%2Fgrand-theft-internet-part-4&amp;title=Grand%20Theft%20Internet%20%28part%204%29" title="Kirtsy"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/kirtsy.png" title="Kirtsy" alt="Kirtsy" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F05%2Fgrand-theft-internet-part-4&amp;title=Grand%20Theft%20Internet%20%28part%204%29&amp;source=J.+Timothy+King%26%23039%3Bs+Blog+The+Life+of+an+Indie+Romance+Author&amp;summary=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%0D%0A%0D%0AChapter%204%0D%0A%0D%0ASunday%2C%20March%2028%2C%202%3A40%20PM%20EDT%0D%0A%0D%0AGlen%2C%20from%20DreamHost%27s%20abuse-response%20" title="LinkedIn"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F05%2Fgrand-theft-internet-part-4&amp;t=Grand%20Theft%20Internet%20%28part%204%29" title="MySpace"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F05%2Fgrand-theft-internet-part-4&amp;title=Grand%20Theft%20Internet%20%28part%204%29" title="Reddit"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F05%2Fgrand-theft-internet-part-4&amp;title=Grand%20Theft%20Internet%20%28part%204%29" title="StumbleUpon"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Grand%20Theft%20Internet%20%28part%204%29%20-%20http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F05%2Fgrand-theft-internet-part-4" title="Twitter"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.jtimothyking.com/2010/04/05/grand-theft-internet-part-4/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Grand Theft Internet (part 3)</title>
		<link>http://blog.jtimothyking.com/2010/04/02/grand-theft-internet-part-3</link>
		<comments>http://blog.jtimothyking.com/2010/04/02/grand-theft-internet-part-3#comments</comments>
		<pubDate>Fri, 02 Apr 2010 16:00:19 +0000</pubDate>
		<dc:creator>J. Timothy King</dc:creator>
				<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[Stories]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[True Stories]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[domain hijacking]]></category>
		<category><![CDATA[domain theft]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[true crime]]></category>

		<guid isPermaLink="false">http://blog.jtimothyking.com/?p=2621</guid>
		<description><![CDATA[This is a true cybercrime story, which hit my friend Tom. Click here to read the story from the beginning. OR Click here to read the whole story as a single page. (If you&#8217;re looking for my usual &#8220;Friday Fun&#8221; column, it will return next week.) Chapter 3 Tom and I speculated on how the [...]]]></description>
			<content:encoded><![CDATA[<p>This is a true cybercrime story, which hit my friend Tom. <a href="http://blog.jtimothyking.com/2010/03/31/grand-theft-internet-part-1">Click here to read the story from the beginning.</a> OR <a href="http://blog.jtimothyking.com/2010/03/31/grand-theft-internet">Click here to read the whole story as a single page.</a> (If you&#8217;re looking for my usual &#8220;Friday Fun&#8221; column, it will return next week.)</p>
<h3>Chapter 3</h3>
<p>Tom and I speculated on how the intruder broke into Tom&#8217;s DreamHost account, and what damage he might be doing there. I thought he might trash Tom&#8217;s account, and I was concerned that Tom be able to restore any lost data quickly. But Tom really didn&#8217;t have any data in that account. All of his Internet services were served from elsewhere.</p>
<p>He thought the cracker was probably setting up a phishing site. That is, the guy would put up a fake web page that looked like a real company web page, maybe for a bank. Then he would send people to that fake page, maybe with fake spam emails, and then try to trick people into giving him their bank logins and passwords. Tom even feared the guy might charge up fake domain names on his credit card.</p>
<p>Fortunately, there was no way for the attacker to obtain Tom&#8217;s credit card number, except for the last 4 digits. Nor could he charge up services or domain registrations on the card, because DreamHost&#8217;s system always asks for new credit card information when you make new purchases. So that was good.</p>
<p>Our bigger concern was how he had managed to break in. The email box Tom had been using as a contact email for DreamHost, that account was still secure. Tom was also certain that his Linux desktop computer was secure, and he had found no breaches on his office LAN. He even had been using secure protocols he used to transfer email into the office LAN. That is, even if someone were able to listen in on his Internet connection, the cracker wouldn&#8217;t be able to decode Tom&#8217;s encrypted communications. The only alternative was that someone had cracked into a mail server at DreamHost, or maybe even the DreamHost control panel itself.</p>
<p>I joked that at least I would have something to blog about the following week.</p>
<p>I sent a message to DreamHost support, on Tom&#8217;s behalf, marked urgent. I explained that his control panel account had been cracked into, and that he had been locked out of it, so he could not contact support thereby. I gave them his phone number and told them he wanted them to call him immediately. By then it was almost 2 o&#8217;clock Sunday morning.</p>
<p>&#8220;Sure, self-hosted stuff is more likely to be poorly maintained and easier to breach,&#8221; Tom commented to me, &#8220;but if a problem happens, I can always hit the big red button and halt it.&#8221;</p>
<p>And this was certainly one of those situations. You&#8217;ve just discovered that someone has cracked into your account and locked you out. You want to be ableto scream that your account has been compromised, and before anything else happens, you want your service provider to freeze the account. You can sort it all out later, when the experts can dig up the forensic details. But for now, you just want to stop the attacker from whatever damage he&#8217;s trying to do.</p>
<p>Still no response from DreamHost support. No way I knew of to escalate the request. No way to phone DreamHost. (And as we discovered later, DreamHost&#8217;s policy is not to discuss security breaches over the phone, only via email, because they want a written record of the conversation.) At one point, we also discovered DreamHost&#8217;s chat-support feature, and I tried contacting someone thereby, but no one responded to my chat request at 3:00 in the morning.</p>
<p>In the past, I&#8217;ve defended DreamHost&#8217;s control-panel-based support system, because it&#8217;s more than effective for normal, &#8220;my website&#8217;s not working&#8221; support requests. But this was not that kind of support request. We urgently needed DreamHost to freeze the account, at least temporarily, to keep the attacker from doing any more damage than he&#8217;d already done. Then the normal support mechanism would have been sufficient to pick up the pieces.</p>
<p>&#8220;I&#8217;m not sure it&#8217;d be worth the savings,&#8221; Tom noted, &#8220;to host anything critical at an organization that is effectively unreachable. I get that phone support would be abused, but you have to have a &#8216;break glass when on fire&#8217; option somewhere.&#8221;</p>
<p>At 3:01 AM Sunday morning, Tom realized that there was indeed some real damage the cracker could do. &#8220;vl.com is worth $100K+. So I need to escalate this somehow.&#8221;</p>
<p>We gave up on the non-responsive chat and on the support ticket shortly before 4 AM. We went to bed, long overdue for sleep.</p>
<hr />
<p><em>Sunday, March 28, 11:05 AM EDT</em></p>
<p>&#8220;Hello. Welcome to DreamHost Live Chat. My name is Javier. How can I help you?&#8221;</p>
<p>&#8220;I&#8217;m sent transfer request from new domain registrar for my domain,&#8221; the dark figure posing as Tom typed into his computer. &#8220;Can you see transfer request on your admin end and verify if received request from other registrar? VL.com.&#8221;</p>
<p>He had already unlocked the VL.com domain, worth hundreds of thousands of dollars, and had transferred it to a registrar in the Bahamas. He had done this before, with other domains. Once the domain was out of the US, it would be harder for Tom to get it back, and much more difficult for anyone to prosecute the dark figure or his friends for stealing the domain. International law is a bitch, and that worked to the dark figure&#8217;s favor. At the very least, Tom would have to spend thousands of dollars to arbitrate the case, possibly with nothing to show for it. Some domains may be worth massive amounts of money, but they were not considered &#8220;property&#8221; by most governments. And that too worked in the dark figure&#8217;s favor.</p>
<p>But while the Bahamas were ready to receive VL.com, the dark figure still needed to approve the transfer away from DreamHost, and DreamHost&#8217;s interface didn&#8217;t appear to be cooperating. Indeed, Javier confirmed that DreamHost had not received the transfer request. The dark figure would have to contact the registrar in the Bahamas and have them resend it. Too much time wasted now, but there still was probably time to steal the domain away. Hopefully, no one would know what was happening until Monday morning.</p>
<p>(to be continued, on Monday)</p>



Share this post:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F02%2Fgrand-theft-internet-part-3&amp;title=Grand%20Theft%20Internet%20%28part%203%29&amp;bodytext=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%20%28If%20you%27re%20looking%20for%20my%20usual%20%22Friday%20Fun%22%20column%2C%20it%20will%20return%20next%20week.%29%0D%0A%0D%0AChap" title="Digg"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F02%2Fgrand-theft-internet-part-3&amp;title=Grand%20Theft%20Internet%20%28part%203%29&amp;notes=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%20%28If%20you%27re%20looking%20for%20my%20usual%20%22Friday%20Fun%22%20column%2C%20it%20will%20return%20next%20week.%29%0D%0A%0D%0AChap" title="del.icio.us"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F02%2Fgrand-theft-internet-part-3&amp;t=Grand%20Theft%20Internet%20%28part%203%29" title="Facebook"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F02%2Fgrand-theft-internet-part-3&amp;title=Grand%20Theft%20Internet%20%28part%203%29&amp;annotation=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%20%28If%20you%27re%20looking%20for%20my%20usual%20%22Friday%20Fun%22%20column%2C%20it%20will%20return%20next%20week.%29%0D%0A%0D%0AChap" title="Google Bookmarks"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="javascript:AddToFavorites();" title="Add to favorites"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/addtofavorites.png" title="Add to favorites" alt="Add to favorites" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Grand%20Theft%20Internet%20%28part%203%29&amp;body=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F02%2Fgrand-theft-internet-part-3" title="email"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.friendfeed.com/share?title=Grand%20Theft%20Internet%20%28part%203%29&amp;link=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F02%2Fgrand-theft-internet-part-3" title="FriendFeed"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://hellotxt.com/?status=Grand%20Theft%20Internet%20%28part%203%29+http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F02%2Fgrand-theft-internet-part-3" title="HelloTxt"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/hellotxt.png" title="HelloTxt" alt="HelloTxt" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.kirtsy.com/submit.php?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F02%2Fgrand-theft-internet-part-3&amp;title=Grand%20Theft%20Internet%20%28part%203%29" title="Kirtsy"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/kirtsy.png" title="Kirtsy" alt="Kirtsy" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F02%2Fgrand-theft-internet-part-3&amp;title=Grand%20Theft%20Internet%20%28part%203%29&amp;source=J.+Timothy+King%26%23039%3Bs+Blog+The+Life+of+an+Indie+Romance+Author&amp;summary=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%20%28If%20you%27re%20looking%20for%20my%20usual%20%22Friday%20Fun%22%20column%2C%20it%20will%20return%20next%20week.%29%0D%0A%0D%0AChap" title="LinkedIn"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F02%2Fgrand-theft-internet-part-3&amp;t=Grand%20Theft%20Internet%20%28part%203%29" title="MySpace"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F02%2Fgrand-theft-internet-part-3&amp;title=Grand%20Theft%20Internet%20%28part%203%29" title="Reddit"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F02%2Fgrand-theft-internet-part-3&amp;title=Grand%20Theft%20Internet%20%28part%203%29" title="StumbleUpon"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Grand%20Theft%20Internet%20%28part%203%29%20-%20http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F02%2Fgrand-theft-internet-part-3" title="Twitter"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.jtimothyking.com/2010/04/02/grand-theft-internet-part-3/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Grand Theft Internet (part 2)</title>
		<link>http://blog.jtimothyking.com/2010/04/01/grand-theft-internet-part-2</link>
		<comments>http://blog.jtimothyking.com/2010/04/01/grand-theft-internet-part-2#comments</comments>
		<pubDate>Thu, 01 Apr 2010 16:00:13 +0000</pubDate>
		<dc:creator>J. Timothy King</dc:creator>
				<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[Stories]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[True Stories]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[domain hijacking]]></category>
		<category><![CDATA[domain theft]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[true crime]]></category>

		<guid isPermaLink="false">http://blog.jtimothyking.com/?p=2595</guid>
		<description><![CDATA[This is a true cybercrime story, which hit my friend Tom. Click here to read the story from the beginning. OR Click here to read the whole story as a single page. Chapter 2 Saturday, March 27, 10:23 PM EDT The dark figure waited for DreamHost support to respond to his chat request. He had [...]]]></description>
			<content:encoded><![CDATA[<p>This is a true cybercrime story, which hit my friend Tom. <a href="http://blog.jtimothyking.com/2010/03/31/grand-theft-internet-part-1">Click here to read the story from the beginning.</a> OR <a href="http://blog.jtimothyking.com/2010/03/31/grand-theft-internet">Click here to read the whole story as a single page.</a></p>
<h3>Chapter 2</h3>
<p><em>Saturday, March 27, 10:23 PM EDT</em></p>
<p>The dark figure waited for DreamHost support to respond to his chat request. He had requested the password be reset, eight times since 9:35, since he had tricked them into adding his email address to the account. But he hadn&#8217;t been receiving the password-reset messages in his email.</p>
<p>Brian answered the chat. &#8220;Hi there, how can I help you.&#8221;</p>
<p>Now impersonating Tom, the legitimate owner of the account, he explained his problem as best he could. &#8220;I&#8217;m trying to get login info in my new email address, but not receiving email from DreamHost.&#8221; He gave Brian the account ID and email address.</p>
<p>&#8220;You&#8217;re already logged into the panel, if you&#8217;re talking to me,&#8221; Brian said.</p>
<p>&#8220;Yes,&#8221; the dark figure replied. That was true. He was logged into the administration panel, just not into Tom&#8217;s account. Not yet. But hopefully soon. He told Brian that he had recently updated the email address, and that he needed to use the new address, not the old one.</p>
<p>Brian replied, &#8220;Both are actually listed on your account.&#8221; He explained that Tom could use the administration panel to make any changes he needed.</p>
<p>Yes, the dark figure said, he&#8217;d tried that many times, but it wasn&#8217;t working. He kept getting an error, he said in his typical broken English.</p>
<p>Brian asked him to try it again.</p>
<p>So he did. Of course, he didn&#8217;t actually try anything. His story was a complete fiction, but a believable one. He described the steps he would have gone through, had he actually had access to Tom&#8217;s administration panel. Every value he would type, every checkbox he would check, every button he would click on.</p>
<p>&#8220;Page still pending load,&#8221; he added after another minute.</p>
<p>Brian waited patiently.</p>
<p>&#8220;Now get the page cannot to display error,&#8221; the dark figure wrote, but he knew that wouldn&#8217;t be enough. He knew he needed to make it sound like an insurmountable, unsolvable problem. &#8220;I also tried from Firefox, Safari, and cleared caches. I think it&#8217;s Windows issue with AJAX. Need to re-install windows tomorrow. Please check it.&#8221;</p>
<p>This must have puzzled Brian. Maybe he thought he was dealing with a clueless user. Maybe he thought it was a strange, inexplicable problem that would take too much time to track down. Maybe he just wanted to get &#8220;Tom&#8221; off his back. The exact reason didn&#8217;t matter. What mattered was that he took the bait.</p>
<p>&#8220;That&#8217;s weird,&#8221; Brian said. &#8220;I just tried it, and it worked perfectly. I changed it for you.&#8221;</p>
<p>The dark figure said he would refresh his display and see if it worked. Another fiction, of course. He couldn&#8217;t refresh any display, because he wasn&#8217;t looking at the display. But he could determine whether it worked. He asked for another password reset. He still didn&#8217;t receive the email message, but that might just mean the computer was still processing the. So he tried again, and again, and again, in quick succession. And finally it worked.</p>
<p>He reported to Brian that the data had been updated.</p>
<p>Brian was clearly pleased to have helped.</p>
<p>The dark figure had access to Tom&#8217;s account now, but there was one thing he needed to do before stealing control over the VL.com domain. He needed to cover his tracks, and for that, he needed Tom&#8217;s email passwords. He logged into Tom&#8217;s account and looked up the email box ID&#8217;s. Then he contacted support again.</p>
<p>Unfortunately, he got Brian again. Brian was no doubt tired with him by now, but he gave it a try anyhow. He said he was trying to see the passwords of two users under his account.</p>
<p>Brian replied that &#8220;Tom&#8221; couldn&#8217;t see the passwords, but he could reset them.</p>
<p>Indeed, that was a security precaution that DreamHost had put in place some time ago, in order to stop people from doing what the dark figure was trying to do right now.</p>
<p>Brian suggested not making any more changes right now, just to keep everything working for now. Yup. He was clearly tired of dealing with &#8220;Tom.&#8221;</p>
<p>The email the dark figure was trying to erase was actually being sent to a Google Apps account, but maybe Tom had used the same password on both his DreamHost email accounts and on his Google account. The dark figure also had asked for the Google password to be reset, and he hoped that a password-reset message then might have appeared in one of the DreamHost mailboxes.</p>
<p>So the dark figure waited another half hour and tried again. This time, he got Sam, who was more than happy to help. He was able to get the passwords for the two email boxes, but they appeared to be long strings of random characters. And neither of those email boxes contained the Google reset message.</p>
<p>The dark figure would not be able to crack into Tom&#8217;s email. His best hope was that he could complete the thievery he came here to do, before Tom realized what was going on.</p>
<hr />
<p><em>Sunday, March 27, 1:16 AM EDT</em></p>
<p>Tom instant-messaged me: &#8220;Somebody is trying to break into my Dreamhost account.&#8221;</p>
<p>&#8220;How can you tell?&#8221; I asked.</p>
<p>He had gotten a bunch of email messages telling him that his DreamHost account password had been reset. But it particularly disturbed him that the last of these messages was also sent to an anonymous email address, at HushMail, an email address Tom did not control.</p>
<p>What to do? DreamHost&#8217;s primary means of customer support was via the administration panel, if Tom could still login.</p>
<p>He couldn&#8217;t.</p>
<p>I acutely realized that this is one of the instances in which you really need another means of contacting DreamHost support. Since then, I&#8217;ve discovered that <a href="http://dreamhost.com/contact.cgi">DreamHost&#8217;s public contact form</a>, as well as their abuse email address. Either would probably have worked at least as well as what we ended up doing.</p>
<p>We didn&#8217;t know how the attacker had cracked into Tom&#8217;s DreamHost account. Tom&#8217;s Google-hosted account had not been compromised, as far as we could tell. So the cracker had either found an exploit in DreamHost&#8217;s password-reset form, or else he was listening in on DreamHost&#8217;s or Google&#8217;s network. In any case, it was a scary prospect.</p>
<p>As a fellow DreamHost customer, I contacted support on Tom&#8217;s behalf and relayed his plea for help. It would be almost 13 hours before we received an initial response, and several more hours before we were taken seriously. Not fast enough to prevent the disaster that was to come.</p>
<p><a href="http://blog.jtimothyking.com/2010/04/02/grand-theft-internet-part-3">Click here to read part 3 »</a></p>



Share this post:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F01%2Fgrand-theft-internet-part-2&amp;title=Grand%20Theft%20Internet%20%28part%202%29&amp;bodytext=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%0D%0A%0D%0AChapter%202%0D%0A%0D%0ASaturday%2C%20March%2027%2C%2010%3A23%20PM%20EDT%0D%0A%0D%0AThe%20dark%20figure%20waited%20for%20DreamHos" title="Digg"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F01%2Fgrand-theft-internet-part-2&amp;title=Grand%20Theft%20Internet%20%28part%202%29&amp;notes=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%0D%0A%0D%0AChapter%202%0D%0A%0D%0ASaturday%2C%20March%2027%2C%2010%3A23%20PM%20EDT%0D%0A%0D%0AThe%20dark%20figure%20waited%20for%20DreamHos" title="del.icio.us"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F01%2Fgrand-theft-internet-part-2&amp;t=Grand%20Theft%20Internet%20%28part%202%29" title="Facebook"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F01%2Fgrand-theft-internet-part-2&amp;title=Grand%20Theft%20Internet%20%28part%202%29&amp;annotation=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%0D%0A%0D%0AChapter%202%0D%0A%0D%0ASaturday%2C%20March%2027%2C%2010%3A23%20PM%20EDT%0D%0A%0D%0AThe%20dark%20figure%20waited%20for%20DreamHos" title="Google Bookmarks"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="javascript:AddToFavorites();" title="Add to favorites"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/addtofavorites.png" title="Add to favorites" alt="Add to favorites" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Grand%20Theft%20Internet%20%28part%202%29&amp;body=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F01%2Fgrand-theft-internet-part-2" title="email"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.friendfeed.com/share?title=Grand%20Theft%20Internet%20%28part%202%29&amp;link=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F01%2Fgrand-theft-internet-part-2" title="FriendFeed"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://hellotxt.com/?status=Grand%20Theft%20Internet%20%28part%202%29+http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F01%2Fgrand-theft-internet-part-2" title="HelloTxt"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/hellotxt.png" title="HelloTxt" alt="HelloTxt" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.kirtsy.com/submit.php?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F01%2Fgrand-theft-internet-part-2&amp;title=Grand%20Theft%20Internet%20%28part%202%29" title="Kirtsy"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/kirtsy.png" title="Kirtsy" alt="Kirtsy" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F01%2Fgrand-theft-internet-part-2&amp;title=Grand%20Theft%20Internet%20%28part%202%29&amp;source=J.+Timothy+King%26%23039%3Bs+Blog+The+Life+of+an+Indie+Romance+Author&amp;summary=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20story%20from%20the%20beginning.%20OR%20Click%20here%20to%20read%20the%20whole%20story%20as%20a%20single%20page.%0D%0A%0D%0AChapter%202%0D%0A%0D%0ASaturday%2C%20March%2027%2C%2010%3A23%20PM%20EDT%0D%0A%0D%0AThe%20dark%20figure%20waited%20for%20DreamHos" title="LinkedIn"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F01%2Fgrand-theft-internet-part-2&amp;t=Grand%20Theft%20Internet%20%28part%202%29" title="MySpace"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F01%2Fgrand-theft-internet-part-2&amp;title=Grand%20Theft%20Internet%20%28part%202%29" title="Reddit"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F01%2Fgrand-theft-internet-part-2&amp;title=Grand%20Theft%20Internet%20%28part%202%29" title="StumbleUpon"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Grand%20Theft%20Internet%20%28part%202%29%20-%20http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F04%2F01%2Fgrand-theft-internet-part-2" title="Twitter"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.jtimothyking.com/2010/04/01/grand-theft-internet-part-2/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Grand Theft Internet (part 1)</title>
		<link>http://blog.jtimothyking.com/2010/03/31/grand-theft-internet-part-1</link>
		<comments>http://blog.jtimothyking.com/2010/03/31/grand-theft-internet-part-1#comments</comments>
		<pubDate>Wed, 31 Mar 2010 16:00:50 +0000</pubDate>
		<dc:creator>J. Timothy King</dc:creator>
				<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[Stories]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[True Stories]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[domain hijacking]]></category>
		<category><![CDATA[domain theft]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[true crime]]></category>

		<guid isPermaLink="false">http://blog.jtimothyking.com/?p=2588</guid>
		<description><![CDATA[This is a true cybercrime story, which hit my friend Tom. Click here to read the whole story. Or use this page to read only chapter 1. Illustration © 2009 Michael Molenda Preface This is a true cybercrime story, which hit my friend Tom this past weekend&#8230; a little too close to home. And I [...]]]></description>
			<content:encoded><![CDATA[<p>This is a true cybercrime story, which hit my friend Tom. <a href="http://blog.jtimothyking.com/2010/03/31/grand-theft-internet">Click here to read the whole story.</a> Or use this page to read only chapter 1.</p>
<div style="float: right; margin: 0 0 1em 1em"><div id="attachment_2613" class="wp-caption alignright" style="width: 306px"><a href="http://www.flickr.com/photos/72388119@N00/3164460404/"><img src="http://blog.jtimothyking.com/wp-content/uploads/2010/03/InternetBankRobbery-MichaelMolenda-296x300.jpg" alt="" title="Internet Bank Robbery, by Michael Molenda CC BY-NC-ND 2.0" width="296" height="300" class="size-medium wp-image-2613" /></a><p class="wp-caption-text">Illustration © 2009 Michael Molenda </p></div></div>
<h3>Preface</h3>
<p>This is a true cybercrime story, which hit my friend Tom this past weekend&#8230; a little too close to home. And I realized that this is something that could happen to <strong>me</strong>. Indeed, it could happen to any of us who owns his own business or website domain. Tom wanted this story told, in the hopes that the knowledge will help prevent similar crimes in the future, to encourage other victims also to come forward, and to increase the chances that crimes like this will be prosecuted as a result, and I agree.</p>
<p>I&#8217;ve drawn on chat transcripts, emails, and other forensic evidence, to reconstruct the timeline of events as accurately as I can. Naturally, when I portray the villain&#8217;s activities—and especially his thoughts and motivations—I&#8217;m speculating&#8230; but let&#8217;s call it &#8220;informed speculation.&#8221; The villain, although he may sometimes appear incompetent, never acts out of random whim. His goal is not merely to poke around inside someone else&#8217;s computer and see what he can find. No. He is pursuing a goal, so he has a purpose to everything he does. And I&#8217;ve written his character from this perspective.</p>
<p>I&#8217;ve mentioned DreamHost, our hosting company and domain registrar, by name, in the interests of full disclosure, because I have recommended DreamHost and have published affiliate links to their service, and I no doubt will in the future. Because in the aftermath, I&#8217;m still looking for another company who would have done better, who would have prevented the break-ins that occurred here.</p>
<hr />
<hr />
<h3>Chapter 1</h3>
<p>I expected a typical lazy weekend: read a book, get ready for the Passover holiday, watch a few seasons of Mythbusters with my new Netflix Wii streaming disc. I never expected the weekend to bring me in so close to the world of high-stakes Internet crime.</p>
<p>As you may know, before I wrote books, I programmed software, and before that, I studied Electrical Engineering at Northeastern University. During those days, I met Tom, now one of my oldest friends. Both of us EE students, both electronics hobbyists since we were young, both hired as co-op students by the same local company. Both of us went into developing software. In the mid-1990&#8242;s, Tom registered the Internet domain VL.com for his consulting business, Venture Logic. Shortly thereafter, I started JT Software Enterprises and registered JTSE.com. You can&#8217;t get 2- and 3- and 4-letter domain names anymore. But at the time, the Internet was still an open frontier, and we actually homesteaded these domains, building them from the ground up.</p>
<p>Fast-forward to the year 2010. JTSE.com is still just an arbitrary string of characters to most people. But VL.com could stand for almost any company name, and on the open market, it&#8217;s worth hundreds of thousands of dollars. (I wonder how much Barnes and Noble paid for BN.com.)</p>
<p>When Tom started getting genuine offers to buy his domain, we should have realized that it was like a diamond necklace, and that high-tech cat burglars would soon set their sites on it.</p>
<hr />
<p><em>Saturday, March 27, 9:17 PM EDT</em></p>
<p>A dark figure lurked in the shadows, just outside the glow of the computer monitor. No one knew him. No one even knew he was there. He had been observing his prey, quietly collecting information using false names and stolen ID&#8217;s, and even trial-and-error. Over the Internet, no one could tell he wasn&#8217;t who or what he said he was. And by the time they put together all the pieces—if they ever put together the pieces—he would be long gone, with his quarry, having taken on yet another false identity.</p>
<p>He knew the VL.com domain he wanted was registered with DreamHost; that was a matter of public record. And he knew that DreamHost would have limited resources to deal with a low-profile Internet break-in, especially on the weekend, and that could give him more time. He had also managed to crack into a different DreamHost account. He had asked them to add a credit card to the account, then talked to a different person and used the credit card information to validate that he owned the account. Customer service was always anxious to shortcut security in order to aid a helpless user, and he played the part like a pro. Through a long series of subterfuges, he had also discovered the account under which the domain was held, had even tricked DreamHost into linking it with his current persona. And now he was ready to strike at his true target.</p>
<p>&#8220;How may I assist you?&#8221; asked Dan, the support technician on the other end of the online chat.</p>
<p>&#8220;I having trouble with updating primary email address on my account,&#8221; the dark figure replied, impersonating his last victim. He then explained to Dan how he had tried to change the email address on the VL.com account. The story was a complete fabrication, of course; he didn&#8217;t even have access to that account. But he made sure he sneaked in the name of the account and the email address he wanted to use. He then complained that his computer was acting up, said he needed to reinstall Windows. It added an air of authentic helplessness.</p>
<p>Dan suggested he reset his browser, or try a different browser. A common support-guy fix.</p>
<p>He explained that he had already done that, and had tried Internet Explorer, Firefox, and Safari. It wasn&#8217;t important that Windows users almost never even knew about Safari; it was more important that he hit all the magic keywords, and fast, before Dan began to suspect anything.</p>
<p>Dan asked him to answer his security question. &#8220;What city were you born in?&#8221;</p>
<p>It took a minute for the dark figure to look up the correct answer, but he did find it, and answered correctly.</p>
<p>But Dan did not respond.</p>
<p>&#8220;Are you still there?&#8221; the dark figure asked.</p>
<p>&#8220;Changing, hold on,&#8221; Dan wrote. And finally, &#8220;Done.&#8221;</p>
<p>&#8220;I can see that it&#8217;s updated,&#8221; the dark figure wrote. Another fiction: he did not yet have access to the account, so he could not actually see anything. But it was important for Dan to believe that he <em>could</em> see it, that everything was on the up and up. It was important that no one raise an alarm, not yet.</p>
<hr />
<p>Neither Tom nor I use such weak security questions. Anyone can find out where you were born, or what school you went to, or your mother&#8217;s maiden name, or whatever. This became painfully clear to me after I wrote my romantic memoir (<em>Love through the Eyes of an Idiot</em>). I looked to contact the people from my past that I wrote about, to inform them about the book. In the process of searching for them, I ran across all manner of personal information about them. I wasn&#8217;t even looking for it.</p>
<p>How that security question got set at DreamHost is still a mystery, lost in the memories of time. Maybe it was an old security question, set when Tom first created his account. (Be assured that we&#8217;ve both verified and tightened up security on all our accounts, and no one will be pulling a similar stunt on either of us.)</p>
<p>Over the following hour, Tom would receive a dozen emails from DreamHost&#8217;s computer, telling him someone was trying to reset his password. Each email included the standard calming notice:</p>
<blockquote>
<p>If you didn&#8217;t request this email, don&#8217;t fret, the security of your account has not been compromised. Somebody else must have requested your password. That&#8217;s exactly why we email it to you instead of just giving it out!</p>
</blockquote>
<p>If Tom had been looking at his email inbox just then, he might have been able to cut off the cracker before he did any real damage. Unfortunately Tom wasn&#8217;t reading his email just then.</p>
<p><a href="http://blog.jtimothyking.com/2010/04/01/grand-theft-internet-part-2">Click here to read part 2 »</a></p>



Share this post:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet-part-1&amp;title=Grand%20Theft%20Internet%20%28part%201%29&amp;bodytext=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20whole%20story.%20Or%20use%20this%20page%20to%20read%20only%20chapter%201.%0D%0A%0D%0A%0D%0A%0D%0APreface%0D%0A%0D%0AThis%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom%20this%20past%20weekend...%20a%20little%20too%20close%20" title="Digg"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet-part-1&amp;title=Grand%20Theft%20Internet%20%28part%201%29&amp;notes=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20whole%20story.%20Or%20use%20this%20page%20to%20read%20only%20chapter%201.%0D%0A%0D%0A%0D%0A%0D%0APreface%0D%0A%0D%0AThis%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom%20this%20past%20weekend...%20a%20little%20too%20close%20" title="del.icio.us"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet-part-1&amp;t=Grand%20Theft%20Internet%20%28part%201%29" title="Facebook"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet-part-1&amp;title=Grand%20Theft%20Internet%20%28part%201%29&amp;annotation=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20whole%20story.%20Or%20use%20this%20page%20to%20read%20only%20chapter%201.%0D%0A%0D%0A%0D%0A%0D%0APreface%0D%0A%0D%0AThis%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom%20this%20past%20weekend...%20a%20little%20too%20close%20" title="Google Bookmarks"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="javascript:AddToFavorites();" title="Add to favorites"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/addtofavorites.png" title="Add to favorites" alt="Add to favorites" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Grand%20Theft%20Internet%20%28part%201%29&amp;body=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet-part-1" title="email"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.friendfeed.com/share?title=Grand%20Theft%20Internet%20%28part%201%29&amp;link=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet-part-1" title="FriendFeed"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://hellotxt.com/?status=Grand%20Theft%20Internet%20%28part%201%29+http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet-part-1" title="HelloTxt"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/hellotxt.png" title="HelloTxt" alt="HelloTxt" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.kirtsy.com/submit.php?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet-part-1&amp;title=Grand%20Theft%20Internet%20%28part%201%29" title="Kirtsy"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/kirtsy.png" title="Kirtsy" alt="Kirtsy" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet-part-1&amp;title=Grand%20Theft%20Internet%20%28part%201%29&amp;source=J.+Timothy+King%26%23039%3Bs+Blog+The+Life+of+an+Indie+Romance+Author&amp;summary=This%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom.%20Click%20here%20to%20read%20the%20whole%20story.%20Or%20use%20this%20page%20to%20read%20only%20chapter%201.%0D%0A%0D%0A%0D%0A%0D%0APreface%0D%0A%0D%0AThis%20is%20a%20true%20cybercrime%20story%2C%20which%20hit%20my%20friend%20Tom%20this%20past%20weekend...%20a%20little%20too%20close%20" title="LinkedIn"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet-part-1&amp;t=Grand%20Theft%20Internet%20%28part%201%29" title="MySpace"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet-part-1&amp;title=Grand%20Theft%20Internet%20%28part%201%29" title="Reddit"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet-part-1&amp;title=Grand%20Theft%20Internet%20%28part%201%29" title="StumbleUpon"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Grand%20Theft%20Internet%20%28part%201%29%20-%20http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet-part-1" title="Twitter"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.jtimothyking.com/2010/03/31/grand-theft-internet-part-1/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Grand Theft Internet</title>
		<link>http://blog.jtimothyking.com/2010/03/31/grand-theft-internet</link>
		<comments>http://blog.jtimothyking.com/2010/03/31/grand-theft-internet#comments</comments>
		<pubDate>Wed, 31 Mar 2010 15:59:55 +0000</pubDate>
		<dc:creator>J. Timothy King</dc:creator>
				<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[Stories]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[True Stories]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[domain hijacking]]></category>
		<category><![CDATA[domain theft]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[true crime]]></category>

		<guid isPermaLink="false">http://blog.jtimothyking.com/?p=2670</guid>
		<description><![CDATA[Illustration © 2009 Michael Molenda CC BY-NC-ND 2.0 Like any other small businessman, he assumed his Internet account was basically safe. Instead, he found himself another victim of the latest 21&#8242;st century crime wave, when his valuable domain name, VL.com, was hijacked in a high-tech heist. Told by a first-person witness to the crime, reconstructed [...]]]></description>
			<content:encoded><![CDATA[<div style="float: right; margin: 0 0 1em 1em"><div id="attachment_2613" class="wp-caption alignright" style="width: 306px"><a href="http://www.flickr.com/photos/72388119@N00/3164460404/"><img src="http://blog.jtimothyking.com/wp-content/uploads/2010/03/InternetBankRobbery-MichaelMolenda-296x300.jpg" alt="" title="Internet Bank Robbery, by Michael Molenda" width="296" height="300" class="size-medium wp-image-2613" /></a><p class="wp-caption-text">Illustration © 2009 Michael Molenda CC BY-NC-ND 2.0</p></div></div>
<p>Like any other small businessman, he assumed his Internet account was basically safe. Instead, he found himself another victim of the latest 21&#8242;st century crime wave, when his valuable domain name, VL.com, was hijacked in a high-tech heist. Told by a first-person witness to the crime, reconstructed from forensic evidence compiled in the aftermath, this gripping account takes you inside the mind of the attacker, showing in lay terms how domain thiefs bypass security at Internet registrars, and why domain name theft is a growing problem on the Internet that could strike any of us.</p>
<p>This is the detailed story of how VL.com was stolen. <a href="http://domainnamewire.com/2010/04/03/vl-com-domain-name-stolen-too-heres-the-inside-story/">Click here for Domain Name Wire&#8217;s report on the incident.</a></p>
<p>Also available as a free downloadable eBook:</p>
<ul>
<li><a href="http://s3.amazonaws.com/jtimothyking/short/Grand%20Theft%20Internet.pdf">PDF format</a></li>
<li><a href="http://s3.amazonaws.com/jtimothyking/short/Grand%20Theft%20Internet.html">HTML format</a></li>
<li><a href="http://s3.amazonaws.com/jtimothyking/short/Grand%20Theft%20Internet.epub">ePub/iPad format</a></li>
<li><a href="http://s3.amazonaws.com/jtimothyking/short/Grand%20Theft%20Internet.prc">Mobi/Kindle format</a></li>
</ul>
<p>(Last updated April 3, 2010.)</p>
<hr />
<hr />
<h3>Preface</h3>
<p>This is a true cybercrime story, which hit my friend Tom this past weekend&#8230; a little too close to home. And I realized that this is something that could happen to <strong>me</strong>. Indeed, it could happen to any of us who owns his own business or website domain. Tom wanted this story told, in the hopes that the knowledge will help prevent similar crimes in the future, to encourage other victims also to come forward, and to increase the chances that crimes like this will be prosecuted as a result, and I agree.</p>
<p>I&#8217;ve drawn on chat transcripts, emails, and other forensic evidence, to reconstruct the timeline of events as accurately as I can. Naturally, when I portray the villain&#8217;s activities—and especially his thoughts and motivations—I&#8217;m speculating&#8230; but let&#8217;s call it &#8220;informed speculation.&#8221; The villain, although he may sometimes appear incompetent, never acts out of random whim. His goal is not merely to poke around inside someone else&#8217;s computer and see what he can find. No. He is pursuing a goal, so he has a purpose to everything he does. And I&#8217;ve written his character from this perspective.</p>
<p>I&#8217;ve mentioned DreamHost, our hosting company and domain registrar, by name, in the interests of full disclosure, because I have recommended DreamHost and have published affiliate links to their service, and I no doubt will in the future. Because in the aftermath, I&#8217;m still looking for another company who would have done better, who would have prevented the break-ins that occurred here.</p>
<hr />
<hr />
<h3>Chapter 1</h3>
<p>I expected a typical lazy weekend: read a book, get ready for the Passover holiday, watch a few seasons of Mythbusters with my new Netflix Wii streaming disc. I never expected the weekend to bring me in so close to the world of high-stakes Internet crime.</p>
<p>As you may know, before I wrote books, I programmed software, and before that, I studied Electrical Engineering at Northeastern University. During those days, I met Tom, now one of my oldest friends. Both of us EE students, both electronics hobbyists since we were young, both hired as co-op students by the same local company. Both of us went into developing software. In the mid-1990&#8242;s, Tom registered the Internet domain VL.com for his consulting business, Venture Logic. Shortly thereafter, I started JT Software Enterprises and registered JTSE.com. You can&#8217;t get 2- and 3- and 4-letter domain names anymore. But at the time, the Internet was still an open frontier, and we actually homesteaded these domains, building them from the ground up.</p>
<p>Fast-forward to the year 2010. JTSE.com is still just an arbitrary string of characters to most people. But VL.com could stand for almost any company name, and on the open market, it&#8217;s worth hundreds of thousands of dollars. (I wonder how much Barnes and Noble paid for BN.com.)</p>
<p>When Tom started getting genuine offers to buy his domain, we should have realized that it was like a diamond necklace, and that high-tech cat burglars would soon set their sites on it.</p>
<hr />
<p><em>Saturday, March 27, 9:17 PM EDT</em></p>
<p>A dark figure lurked in the shadows, just outside the glow of the computer monitor. No one knew him. No one even knew he was there. He had been observing his prey, quietly collecting information using false names and stolen ID&#8217;s, and even trial-and-error. Over the Internet, no one could tell he wasn&#8217;t who or what he said he was. And by the time they put together all the pieces—if they ever put together the pieces—he would be long gone, with his quarry, having taken on yet another false identity.</p>
<p>He knew the VL.com domain he wanted was registered with DreamHost; that was a matter of public record. And he knew that DreamHost would have limited resources to deal with a low-profile Internet break-in, especially on the weekend, and that could give him more time. He had also managed to crack into a different DreamHost account. He had asked them to add a credit card to the account, then talked to a different person and used the credit card information to validate that he owned the account. Customer service was always anxious to shortcut security in order to aid a helpless user, and he played the part like a pro. Through a long series of subterfuges, he had also discovered the account under which the domain was held, had even tricked DreamHost into linking it with his current persona. And now he was ready to strike at his true target.</p>
<p>&#8220;How may I assist you?&#8221; asked Dan, the support technician on the other end of the online chat.</p>
<p>&#8220;I having trouble with updating primary email address on my account,&#8221; the dark figure replied, impersonating his last victim. He then explained to Dan how he had tried to change the email address on the VL.com account. The story was a complete fabrication, of course; he didn&#8217;t even have access to that account. But he made sure he sneaked in the name of the account and the email address he wanted to use. He then complained that his computer was acting up, said he needed to reinstall Windows. It added an air of authentic helplessness.</p>
<p>Dan suggested he reset his browser, or try a different browser. A common support-guy fix.</p>
<p>He explained that he had already done that, and had tried Internet Explorer, Firefox, and Safari. It wasn&#8217;t important that Windows users almost never even knew about Safari; it was more important that he hit all the magic keywords, and fast, before Dan began to suspect anything.</p>
<p>Dan asked him to answer his security question. &#8220;What city were you born in?&#8221;</p>
<p>It took a minute for the dark figure to look up the correct answer, but he did find it, and answered correctly.</p>
<p>But Dan did not respond.</p>
<p>&#8220;Are you still there?&#8221; the dark figure asked.</p>
<p>&#8220;Changing, hold on,&#8221; Dan wrote. And finally, &#8220;Done.&#8221;</p>
<p>&#8220;I can see that it&#8217;s updated,&#8221; the dark figure wrote. Another fiction: he did not yet have access to the account, so he could not actually see anything. But it was important for Dan to believe that he <em>could</em> see it, that everything was on the up and up. It was important that no one raise an alarm, not yet.</p>
<hr />
<p>Neither Tom nor I use such weak security questions. Anyone can find out where you were born, or what school you went to, or your mother&#8217;s maiden name, or whatever. This became painfully clear to me after I wrote my romantic memoir (<em>Love through the Eyes of an Idiot</em>). I looked to contact the people from my past that I wrote about, to inform them about the book. In the process of searching for them, I ran across all manner of personal information about them. I wasn&#8217;t even looking for it.</p>
<p>How that security question got set at DreamHost is still a mystery, lost in the memories of time. Maybe it was an old security question, set when Tom first created his account. (Be assured that we&#8217;ve both verified and tightened up security on all our accounts, and no one will be pulling a similar stunt on either of us.)</p>
<p>Over the following hour, Tom would receive a dozen emails from DreamHost&#8217;s computer, telling him someone was trying to reset his password. Each email included the standard calming notice:</p>
<blockquote>
<p>If you didn&#8217;t request this email, don&#8217;t fret, the security of your account has not been compromised. Somebody else must have requested your password. That&#8217;s exactly why we email it to you instead of just giving it out!</p>
</blockquote>
<p>If Tom had been looking at his email inbox just then, he might have been able to cut off the cracker before he did any real damage. Unfortunately Tom wasn&#8217;t reading his email just then.</p>
<hr />
<hr />
<h3>Chapter 2</h3>
<p><em>Saturday, March 27, 10:23 PM EDT</em></p>
<p>The dark figure waited for DreamHost support to respond to his chat request. He had requested the password be reset, eight times since 9:35, since he had tricked them into adding his email address to the account. But he hadn&#8217;t been receiving the password-reset messages in his email.</p>
<p>Brian answered the chat. &#8220;Hi there, how can I help you.&#8221;</p>
<p>Now impersonating Tom, the legitimate owner of the account, he explained his problem as best he could. &#8220;I&#8217;m trying to get login info in my new email address, but not receiving email from DreamHost.&#8221; He gave Brian the account ID and email address.</p>
<p>&#8220;You&#8217;re already logged into the panel, if you&#8217;re talking to me,&#8221; Brian said.</p>
<p>&#8220;Yes,&#8221; the dark figure replied. That was true. He was logged into the administration panel, just not into Tom&#8217;s account. Not yet. But hopefully soon. He told Brian that he had recently updated the email address, and that he needed to use the new address, not the old one.</p>
<p>Brian replied, &#8220;Both are actually listed on your account.&#8221; He explained that Tom could use the administration panel to make any changes he needed.</p>
<p>Yes, the dark figure said, he&#8217;d tried that many times, but it wasn&#8217;t working. He kept getting an error, he said in his typical broken English.</p>
<p>Brian asked him to try it again.</p>
<p>So he did. Of course, he didn&#8217;t actually try anything. His story was a complete fiction, but a believable one. He described the steps he would have gone through, had he actually had access to Tom&#8217;s administration panel. Every value he would type, every checkbox he would check, every button he would click on.</p>
<p>&#8220;Page still pending load,&#8221; he added after another minute.</p>
<p>Brian waited patiently.</p>
<p>&#8220;Now get the page cannot to display error,&#8221; the dark figure wrote, but he knew that wouldn&#8217;t be enough. He knew he needed to make it sound like an insurmountable, unsolvable problem. &#8220;I also tried from Firefox, Safari, and cleared caches. I think it&#8217;s Windows issue with AJAX. Need to re-install windows tomorrow. Please check it.&#8221;</p>
<p>This must have puzzled Brian. Maybe he thought he was dealing with a clueless user. Maybe he thought it was a strange, inexplicable problem that would take too much time to track down. Maybe he just wanted to get &#8220;Tom&#8221; off his back. The exact reason didn&#8217;t matter. What mattered was that he took the bait.</p>
<p>&#8220;That&#8217;s weird,&#8221; Brian said. &#8220;I just tried it, and it worked perfectly. I changed it for you.&#8221;</p>
<p>The dark figure said he would refresh his display and see if it worked. Another fiction, of course. He couldn&#8217;t refresh any display, because he wasn&#8217;t looking at the display. But he could determine whether it worked. He asked for another password reset. He still didn&#8217;t receive the email message, but that might just mean the computer was still processing the. So he tried again, and again, and again, in quick succession. And finally it worked.</p>
<p>He reported to Brian that the data had been updated.</p>
<p>Brian was clearly pleased to have helped.</p>
<p>The dark figure had access to Tom&#8217;s account now, but there was one thing he needed to do before stealing control over the VL.com domain. He needed to cover his tracks, and for that, he needed Tom&#8217;s email passwords. He logged into Tom&#8217;s account and looked up the email box ID&#8217;s. Then he contacted support again.</p>
<p>Unfortunately, he got Brian again. Brian was no doubt tired with him by now, but he gave it a try anyhow. He said he was trying to see the passwords of two users under his account.</p>
<p>Brian replied that &#8220;Tom&#8221; couldn&#8217;t see the passwords, but he could reset them.</p>
<p>Indeed, that was a security precaution that DreamHost had put in place some time ago, in order to stop people from doing what the dark figure was trying to do right now.</p>
<p>Brian suggested not making any more changes right now, just to keep everything working for now. Yup. He was clearly tired of dealing with &#8220;Tom.&#8221;</p>
<p>The email the dark figure was trying to erase was actually being sent to a Google Apps account, but maybe Tom had used the same password on both his DreamHost email accounts and on his Google account. The dark figure also had asked for the Google password to be reset, and he hoped that a password-reset message then might have appeared in one of the DreamHost mailboxes.</p>
<p>So the dark figure waited another half hour and tried again. This time, he got Sam, who was more than happy to help. He was able to get the passwords for the two email boxes, but they appeared to be long strings of random characters. And neither of those email boxes contained the Google reset message.</p>
<p>The dark figure would not be able to crack into Tom&#8217;s email. His best hope was that he could complete the thievery he came here to do, before Tom realized what was going on.</p>
<hr />
<p><em>Sunday, March 27, 1:16 AM EDT</em></p>
<p>Tom instant-messaged me: &#8220;Somebody is trying to break into my Dreamhost account.&#8221;</p>
<p>&#8220;How can you tell?&#8221; I asked.</p>
<p>He had gotten a bunch of email messages telling him that his DreamHost account password had been reset. But it particularly disturbed him that the last of these messages was also sent to an anonymous email address, at HushMail, an email address Tom did not control.</p>
<p>What to do? DreamHost&#8217;s primary means of customer support was via the administration panel, if Tom could still login.</p>
<p>He couldn&#8217;t.</p>
<p>I acutely realized that this is one of the instances in which you really need another means of contacting DreamHost support. Since then, I&#8217;ve discovered that <a href="http://dreamhost.com/contact.cgi">DreamHost&#8217;s public contact form</a>, as well as their abuse email address. Either would probably have worked at least as well as what we ended up doing.</p>
<p>We didn&#8217;t know how the attacker had cracked into Tom&#8217;s DreamHost account. Tom&#8217;s Google-hosted account had not been compromised, as far as we could tell. So the cracker had either found an exploit in DreamHost&#8217;s password-reset form, or else he was listening in on DreamHost&#8217;s or Google&#8217;s network. In any case, it was a scary prospect.</p>
<p>As a fellow DreamHost customer, I contacted support on Tom&#8217;s behalf and relayed his plea for help. It would be almost 13 hours before we received an initial response, and several more hours before we were taken seriously. Not fast enough to prevent the disaster that was to come.</p>
<hr />
<hr />
<h3>Chapter 3</h3>
<p>Tom and I speculated on how the intruder broke into Tom&#8217;s DreamHost account, and what damage he might be doing there. I thought he might trash Tom&#8217;s account, and I was concerned that Tom be able to restore any lost data quickly. But Tom really didn&#8217;t have any data in that account. All of his Internet services were served from elsewhere.</p>
<p>He thought the cracker was probably setting up a phishing site. That is, the guy would put up a fake web page that looked like a real company web page, maybe for a bank. Then he would send people to that fake page, maybe with fake spam emails, and then try to trick people into giving him their bank logins and passwords. Tom even feared the guy might charge up fake domain names on his credit card.</p>
<p>Fortunately, there was no way for the attacker to obtain Tom&#8217;s credit card number, except for the last 4 digits. Nor could he charge up services or domain registrations on the card, because DreamHost&#8217;s system always asks for new credit card information when you make new purchases. So that was good.</p>
<p>Our bigger concern was how he had managed to break in. The email box Tom had been using as a contact email for DreamHost, that account was still secure. Tom was also certain that his Linux desktop computer was secure, and he had found no breaches on his office LAN. He even had been using secure protocols he used to transfer email into the office LAN. That is, even if someone were able to listen in on his Internet connection, the cracker wouldn&#8217;t be able to decode Tom&#8217;s encrypted communications. The only alternative was that someone had cracked into a mail server at DreamHost, or maybe even the DreamHost control panel itself.</p>
<p>I joked that at least I would have something to blog about the following week.</p>
<p>I sent a message to DreamHost support, on Tom&#8217;s behalf, marked urgent. I explained that his control panel account had been cracked into, and that he had been locked out of it, so he could not contact support thereby. I gave them his phone number and told them he wanted them to call him immediately. By then it was almost 2 o&#8217;clock Sunday morning.</p>
<p>&#8220;Sure, self-hosted stuff is more likely to be poorly maintained and easier to breach,&#8221; Tom commented to me, &#8220;but if a problem happens, I can always hit the big red button and halt it.&#8221;</p>
<p>And this was certainly one of those situations. You&#8217;ve just discovered that someone has cracked into your account and locked you out. You want to be ableto scream that your account has been compromised, and before anything else happens, you want your service provider to freeze the account. You can sort it all out later, when the experts can dig up the forensic details. But for now, you just want to stop the attacker from whatever damage he&#8217;s trying to do.</p>
<p>Still no response from DreamHost support. No way I knew of to escalate the request. No way to phone DreamHost. (And as we discovered later, DreamHost&#8217;s policy is not to discuss security breaches over the phone, only via email, because they want a written record of the conversation.) At one point, we also discovered DreamHost&#8217;s chat-support feature, and I tried contacting someone thereby, but no one responded to my chat request at 3:00 in the morning.</p>
<p>In the past, I&#8217;ve defended DreamHost&#8217;s control-panel-based support system, because it&#8217;s more than effective for normal, &#8220;my website&#8217;s not working&#8221; support requests. But this was not that kind of support request. We urgently needed DreamHost to freeze the account, at least temporarily, to keep the attacker from doing any more damage than he&#8217;d already done. Then the normal support mechanism would have been sufficient to pick up the pieces.</p>
<p>&#8220;I&#8217;m not sure it&#8217;d be worth the savings,&#8221; Tom noted, &#8220;to host anything critical at an organization that is effectively unreachable. I get that phone support would be abused, but you have to have a &#8216;break glass when on fire&#8217; option somewhere.&#8221;</p>
<p>At 3:01 AM Sunday morning, Tom realized that there was indeed some real damage the cracker could do. &#8220;vl.com is worth $100K+. So I need to escalate this somehow.&#8221;</p>
<p>We gave up on the non-responsive chat and on the support ticket shortly before 4 AM. We went to bed, long overdue for sleep.</p>
<hr />
<p><em>Sunday, March 28, 11:05 AM EDT</em></p>
<p>&#8220;Hello. Welcome to DreamHost Live Chat. My name is Javier. How can I help you?&#8221;</p>
<p>&#8220;I&#8217;m sent transfer request from new domain registrar for my domain,&#8221; the dark figure posing as Tom typed into his computer. &#8220;Can you see transfer request on your admin end and verify if received request from other registrar? VL.com.&#8221;</p>
<p>He had already unlocked the VL.com domain, worth hundreds of thousands of dollars, and had transferred it to a registrar in the Bahamas. He had done this before, with other domains. Once the domain was out of the US, it would be harder for Tom to get it back, and much more difficult for anyone to prosecute the dark figure or his friends for stealing the domain. International law is a bitch, and that worked to the dark figure&#8217;s favor. At the very least, Tom would have to spend thousands of dollars to arbitrate the case, possibly with nothing to show for it. Some domains may be worth massive amounts of money, but they were not considered &#8220;property&#8221; by most governments. And that too worked in the dark figure&#8217;s favor.</p>
<p>But while the Bahamas were ready to receive VL.com, the dark figure still needed to approve the transfer away from DreamHost, and DreamHost&#8217;s interface didn&#8217;t appear to be cooperating. Indeed, Javier confirmed that DreamHost had not received the transfer request. The dark figure would have to contact the registrar in the Bahamas and have them resend it. Too much time wasted now, but there still was probably time to steal the domain away. Hopefully, no one would know what was happening until Monday morning.</p>
<hr />
<hr />
<h3>Chapter 4</h3>
<p><em>Sunday, March 28, 2:40 PM EDT</em></p>
<p>Glen, from DreamHost&#8217;s abuse-response team, replied to our support request, saying that Tom should provide certain billing details, in order to verify that he owned the account. That&#8217;s DreamHost&#8217;s standard procedure. But we believed that someone might be listening in on DreamHost&#8217;s email. How to convince Glen that this issue needs looking into? Tom emailed him back, explaining that he believed that DreamHost&#8217;s email servers had been compromised, asking to talk via phone or to send the data via fax.</p>
<p>Tom said to me, &#8220;I&#8217;m sure they&#8217;ve chalked this up to some customer with sloppy security getting their email compromised.&#8221;</p>
<p>Shortly thereafter, Glen confirmed that suspicion. He said that while he was open to evidence that DreamHost&#8217;s network had been compromised, there hadn&#8217;t been break-ins on any other accounts. He suggested that Tom scan his computer for viruses, to make sure there wasn&#8217;t something installed on it that was listening in on his email.</p>
<p>Tom shot back, &#8220;It&#8217;s a Linux machine with a secure password behind a firewall. I have a clue about security. The <strong>only</strong> place I am seeing any evidence of a breach is with DreamHost. The attacker attempted, and failed, to reset the password on my Google-hosted account. If he had compromised my machine here, he would have been able to intercept that email.&#8221;</p>
<p>That seemed to have been persuasive, as Glen looked at the situation in more detail. Although he didn&#8217;t find any record that Tom&#8217;s account password had been accessed, he accepted that Tom knew enough about security in order to avoid the common mistakes that people usually make. He also restored the account&#8217;s original email address, which gave Tom access again.</p>
<p>At around this time, Tom&#8217;s Google-hosted account received an email that someone was trying to transfer VL.com away to another registrar. Unfortunately, Google thought it was spam. Tom wouldn&#8217;t find the notice until another day had passed.</p>
<hr />
<p><em>Sunday, March 28, 6:09 PM EDT</em></p>
<p>The dark figure had requested that VL.com be transferred away to a registrar in the Bahamas. But by the time the request had gone through, he had been locked out of the DreamHost account. If he could crack back in, however, maybe he could still complete the transfer.</p>
<p>Using a tried-and-true method, he chatted with DreamHost support. &#8220;Need update current email on file, but still not successful,&#8221; he said in his trademark broken English.</p>
<p>He was on the line with Schroder, who tried to walk him through the process.</p>
<p>But that would do the dark figure no good, because he couldn&#8217;t actually log into the account. His goal was to beg, trick, or badger Schroder into making the change for him. &#8220;Can you done it for me?&#8221; he asked.</p>
<p>&#8220;No,&#8221; Schroder replied, &#8220;I&#8217;m sorry. I can&#8217;t change it for you.&#8221;</p>
<p>&#8220;I can verify ownership,&#8221; the dark figure said. He gave Schroder the answer to the security question, which he had set earlier just for this contingency. He also recited the last four digits of the account&#8217;s credit card, which he had gotten from the account&#8217;s control panel and written down.</p>
<p>Schroder said, &#8220;If you can&#8217;t walk me through the method you&#8217;re using to change the info, then, I&#8217;m sorry, but I can&#8217;t help you with this.&#8221;</p>
<p>&#8220;Ok. Thanks,&#8221; the dark figure wrote, resolving to try back later with a different support rep.</p>
<hr />
<p><em>Sunday, March 28, 6:52 PM EDT</em></p>
<p>While Tom waited for his browser to start up, he told me that he had two different contract programming jobs to work on this weekend, and he wanted to upgrade his operating system and switch his MythTV box over to a digital tuner. I guess he wasn&#8217;t going to make any progress on any of those projects.</p>
<p>&#8220;Look on the bright side,&#8221; I said. &#8220;Can&#8217;t think of what that is. But I&#8217;m sure there&#8217;s one there&#8230; somewhere.&#8221;</p>
<p>&#8220;Metaphorical bruises are often good to motivate you to take corrective action against repeating the mistake,&#8221; Tom replied.</p>
<p>He finally got back into his account, changed the account&#8217;s login email address, locked out the attacker, and reset the passwords. He examined his domains. They were all still there. He couldn&#8217;t tell whether VL.com was still locked, but all the domain-name configuration looked correct.</p>
<p>By then, it was at 7:08 PM.</p>
<p>Meanwhile&#8230;</p>
<hr />
<p><em>Sunday, March 28, 7:07 PM EDT</em></p>
<p>The dark figure tried again with DreamHost&#8217;s support chat. This time, he got Jeremy. He explained, impersonating Tom, that he was trying to change the primary address on Tom&#8217;s account.</p>
<p>Within a few minutes, Jeremy had solved his problem.</p>
<p>The dark figure used the automated system to reset the password on Tom&#8217;s account, knowing that as soon as he could get in, he would be able to complete the theft. But before he could lock Tom out, someone had already overridden the request. Clearly, Tom was onto him, logged into the system, and actively fighting with him for control of the account.</p>
<p>Time to switch tactics.</p>
<hr />
<p><em>Sunday, March 28, 7:19 PM EDT</em></p>
<p>Tom was on the DreamHost support chat with Jason. &#8220;Help. My DH account is actively being hacked.&#8221;</p>
<p>&#8220;Unfortunately,&#8221; Jason said, &#8220;any inquiries pertaining to hacked sites or accounts need to be taken care of via email so our abuse/security team can assist you. This isn&#8217;t something I can help you with via Live Chat.&#8221;</p>
<p>&#8220;Glen reset my password about an hour ago,&#8221; Tom explained, &#8220;and the attacker is repeating the attack.&#8221;</p>
<p>&#8220;Okay, you will need to submit a support ticket for this. Thank you!&#8221;</p>
<p>Meanwhile&#8230;</p>
<hr />
<p><em>Sunday, March 28, 7:19 PM EDT</em></p>
<p>The dark figure contacted Seohee via the DreamHost support chat, still impersonating Tom, told him he was having trouble transferring VL.com away, and asked for help.</p>
<p>He was worried that Tom may have already discovered the pending transfer and may have locked down the domain. &#8220;What&#8217;s current status of &#8216;TRANSFER AWAY&#8217;?&#8221; he asked. &#8220;It&#8217;s canceled?&#8221;</p>
<p>No, it wasn&#8217;t canceled. It was still pending. The dark figure told Seohee a story about trying to approve the transfer but receiving an error. &#8220;Please approve it from your admin end. Restarting transfer request taking few days.&#8221; Sadly.</p>
<p>&#8220;Please hold,&#8221; Seohee said.</p>
<p>Within a couple minutes, the dark figure was able to write: &#8220;I can see it&#8217;s approved. And in new registrar.&#8221;</p>
<p>&#8220;Thanks for hanging in there. sorry for the confusion,&#8221; Seohee wrote.</p>
<p>&#8220;Thanks again. Have great day,&#8221; replied the dark figure.</p>
<p>&#8220;You too!&#8221;</p>
<p>Finally, everyone was happy.</p>
<hr />
<hr />
<h3>Chapter 5</h3>
<p><em>Sunday, March 28, 8:06 PM EDT</em></p>
<p>&#8220;They stole vl.com!!!!!!!!!!!!!!!!!!!!!!!!&#8221;</p>
<p>By 7:45, Glen had discovered that the attacker had been manipulating the DreamHost support people in order to crack into Tom&#8217;s account and steal VL.com, a tactic called &#8220;social engineering.&#8221; Glen discovered this just minutes too late.</p>
<p>Glen immediately promised to gather forensic evidence in order to get back Tom&#8217;s domain, to insist on reforms of DreamHost&#8217;s policies and practices, and to pursue prosecution. He confirmed that there had been a security breach at DreamHost, and that the support people on chat were not supposed to be making changes on customers&#8217; accounts. DreamHost serves as registrar for over a half-million domain names, and hosts close to a million websites, and the attacker could have gone after any of these— and still could. No doubt, the story, as he reconstructed it, stunned and panicked him and everyone else at DreamHost.</p>
<p>In most incidents of stolen domains, once the domain is transferred away, there&#8217;s little the rightful owner can do to get it back. File a police report: check. But aside from the blank stares, you&#8217;re likely to get little response. File a report with the FBI: check. But while the FBI is very interested in being informed, unless there&#8217;s substantial monetary loss, they can&#8217;t justify the resources needed to investigate and prosecute. Challenge the domain on trademark grounds, but that will cost thousands of dollars and take God-knows-how-long. You could even beg with the foreign registrar, but without conclusive evidence of fraud, they won&#8217;t undo the transfer. Most businesses who lose their domains to domain hijacking or domain theft, they simply give up.</p>
<p>The break in the case was perhaps Glen&#8217;s enthusiasm. Many companies would have clammed up in the face of these circumstances— Indeed, many have done so, whether to avoid being sued or just to avoid being bothered. And without DreamHost&#8217;s help, Tom&#8217;s situation would have been as bleak as the rain-soaked skies that week. If Tom had complained to the registrar in the Bahamas, they probably would have dismissed him. But when an official DreamHost representative did so, they listened. They locked down the domain, which at least kept Tom&#8217;s Internet services up and running. They considered the evidence that Glen had dug up, which clearly showed fraud. And they promised to return the domain, once the paperwork had been processed.</p>
<p>Interestingly enough, the cracker refused to give up. He opened a fake Gmail account, impersonating Tom, in an attempt to trick the registrar in the Bahamas into releasing the lock on the domain. And he hit DreamHost support again at about the same time, trying to get them to stop asking for the domain back. Then he attempted again to break in to Tom&#8217;s Google-hosted domain, by trying to trick DreamHost into modifying the domain configuration— using the same MO: claim he tried to make the change himself, make up a story about encountering an error, and ask the support person to make the change for him. This would have allowed him to access all the email stored in all the accounts on that domain. But he probably only wanted to impersonate Tom, in order to call off the investigation. He may have made other attempts as well, attempts that we do not know of yet.</p>
<hr />
<p>But the real question is how to proceed going forward.</p>
<p>This story is not about DreamHost. It&#8217;s about the domain industry. Domain theft happens on the Internet, and social engineering is one of the thief&#8217;s primary tactics. The most famous case is probably the theft of Sex.com, which is probably famous because of the letters S, E, and X. It took Gary Kremen years to get that domain back.</p>
<p>Moving my domains away from DreamHost doesn&#8217;t necessarily solve the problem. Because a cracker can attack any registrar. If I have a diamond necklace worth $100,000, I can keep it in a bank safe-deposit vault. And short of a Mission-Impossible-style heist, I can feel pretty safe that it&#8217;ll remain in my possession. If I have a domain name worth $100,000, there is no safe-deposit vault, and the quality of security at different registrars varies.</p>
<p>Additionally, the law is only beginning to see domain names as &#8220;property,&#8221; even though, of all the things we call &#8220;intellectual property,&#8221; domain names bear the closest similarity to real property. Until the law catches up to modern technology, we have to fend for ourselves.</p>
<p>As a defense, maybe there&#8217;s some value in looking for a registrar who&#8217;s as paranoid as I am. Maybe right now, that&#8217;s still DreamHost, because they&#8217;ve been spooked. And maybe there&#8217;s also some value in a registrar who will come clean when there&#8217;s a break-in, and do their best to set things right. Maybe that, too, is DreamHost. But I find it disheartening that if I go into a crowded room full of IT gurus and ask, &#8220;Where can I register my domain to keep it safe?&#8221; the best I get is, &#8220;Well, I&#8217;ve been happy with such-and-such a registrar, but no one&#8217;s ever tried to rip me off before.&#8221; No one cites any systematic studies of domain registrar security practices, and there&#8217;s no single registrar that comes to the top as <em>the</em> name in domain security for the average business.</p>
<p>Even so, there&#8217;s some value in looking for registrars that offer increased security and services, even at slightly increased prices and with longer waiting times:</p>
<ul>
<li>positively identifying the domain owner before releasing a domain to another registrar, such as with two-factor authentication being offered by some registrars;</li>
<li>confirming domain transfers through phone calls or cellphone text messages, as well as the standard email;</li>
<li>approving domain transfers through multiple, independent means, or multiple, independent accounts, all of which must approve before the transfer goes through;</li>
<li>effective crisis procedures, when a break-in does occur;</li>
<li>effective forensic and recovery procedures, when a theft occurs;</li>
<li>insurability—if a domain name is stolen, the insurance company will pay for recovery or losses.</li>
</ul>
<p>Notice I did not include domain locking in the above list, even though that&#8217;s the first thing most people mention when they talk about protecting your domain. Why not? Because (1) it&#8217;s a standard feature, (2) usually all the cracker has to do to turn it off is to click a button on some administrative panel, and (3) it can&#8217;t protect you from lax security at your registrar or a break-in of your account. However, I might add confirmed domain locking to the list, that is, require approval through an independent email address or cellphone text message before anyone can unlock the domain.</p>
<p>Changes to approval email addresses also should use the same approval process. So for example, no changes should be made to my account email address without affirmative approval via that email address. The current standard system, which at best sends out a &#8220;email address has changed&#8221; message, that&#8217;s inadequate for domain security, because a secure system is only as strong as its weakest link.</p>
<p>Even registrars of high-profile domains such as Amazon.com, BarnesAndNoble.com, and Coke.com don&#8217;t offer services like these. And some high profile domains (such as Comcast.net) have indeed been hijacked. Fortunately, if you&#8217;re Amazon or Coke, you can probably get your domain back pretty quickly with a simple phone call. But if you&#8217;re not, you need a registrar that&#8217;s going to stand up for you, no matter how small you are. And you can expect it to take days at best, or weeks, or months, or years, or forever.</p>
<p>There are some additional safety measures you can take to slow up a thief trying to steal your domain:</p>
<ul>
<li>Use a secret email address for your account email.</li>
<li>Always use a secure computer and encrypted connection to download email.</li>
<li>Use long, random passwords for each email and domain account.</li>
<li>Use secure secrets for any &#8220;secret question,&#8221; obscure facts that no one else can find out.</li>
<li>If you have multiple domain names or web holdings, split them up between multiple registrars and hosting services.</li>
<li>Use low-value domains for daily activities, if possible. (So if someone steals away VL.com, your email will still continue uninterrupted through VentureLogic.com.)</li>
<li>Know how to get in touch with your registrar in an emergency, whether by phone, email, or web form, even if you&#8217;ve been locked out of your account by an attacker.</li>
<li>Establish secure, authenticated communication channels with people you are likely to work with to resolve a crisis: obtain email certificates, exchange public keys, and set up secure IM.</li>
<li>At least ask yourself, &#8220;Will that busty model come to my rescue when I have a problem with my domain?&#8221;</li>
</ul>
<p>Unfortunately, as long as an attacker can trick the registrar to bypass security, neither strong passwords nor two-factor authentication nor double confirmation nor any other security measure will be effective.</p>
<p>Conceptually, you could even test a domain registrar. Try to convince them to shortcut security for you, in order to make legitimate changes to your account. And if they do, bolt. I can&#8217;t comment on whether that&#8217;s legal or not. But as for me, I&#8217;d be interested in a broad-based study of how tight security really is at the Internet&#8217;s top domain registrars.</p>
<p>-TimK</p>
<p>Additional resources:</p>
<ul>
<li><a href="http://www.vtalkradio.com/bjorn.asp">Interview with Bjørn K. Andersen, who had Direction.com stolen.</a></li>
<li><a href="http://www.domainnamenews.com/featured/criminal-prosecution-domain-theft-underway/5675">The story of the theft of P2P.com, and the first ever criminal prosecution of a domain thief.</a></li>
<li><a href="http://www.icann.org/en/announcements/hijacking-report-12jul05.pdf">2005 ICANN SSAC report on domain hijacking.</a></li>
<li><a href="http://www.dyndns.com/support/kb/domain_hijacking.html">DynDNS on domain hijacking.</a></li>
<li><a href="http://www.moniker.com/">Moniker.com, a registrar that advertises a higher than average level of domain security.</a></li>
</ul>
<p>Other mentions of the theft of VL.com:</p>
<ul>
<li><a href="http://domainnamewire.com/2010/04/03/vl-com-domain-name-stolen-too-heres-the-inside-story/">Report on the theft, on Domain News Wire.</a></li>
<li><a href="http://old.nabble.com/Dreamhost-account-hacked-td28062149s24859.html">Boston Linux &#038; Unix users&#8217; group discussion, as the story unfolded</a></li>
<li><a href="http://www.mail-archive.com/boston-pm@mail.pm.org/msg05971.html">Boston PerlMonger&#8217;s discussion</a></li>
<li><a href="http://news.ycombinator.com/item?id=1229247">Hacker News discussion</a></li>
</ul>



Share this post:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet&amp;title=Grand%20Theft%20Internet&amp;bodytext=%0D%0A%0D%0ALike%20any%20other%20small%20businessman%2C%20he%20assumed%20his%20Internet%20account%20was%20basically%20safe.%20Instead%2C%20he%20found%20himself%20another%20victim%20of%20the%20latest%2021%27st%20century%20crime%20wave%2C%20when%20his%20valuable%20domain%20name%2C%20VL.com%2C%20was%20hijacked%20in%20a%20high-tech%20heist.%20Told%20" title="Digg"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet&amp;title=Grand%20Theft%20Internet&amp;notes=%0D%0A%0D%0ALike%20any%20other%20small%20businessman%2C%20he%20assumed%20his%20Internet%20account%20was%20basically%20safe.%20Instead%2C%20he%20found%20himself%20another%20victim%20of%20the%20latest%2021%27st%20century%20crime%20wave%2C%20when%20his%20valuable%20domain%20name%2C%20VL.com%2C%20was%20hijacked%20in%20a%20high-tech%20heist.%20Told%20" title="del.icio.us"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet&amp;t=Grand%20Theft%20Internet" title="Facebook"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet&amp;title=Grand%20Theft%20Internet&amp;annotation=%0D%0A%0D%0ALike%20any%20other%20small%20businessman%2C%20he%20assumed%20his%20Internet%20account%20was%20basically%20safe.%20Instead%2C%20he%20found%20himself%20another%20victim%20of%20the%20latest%2021%27st%20century%20crime%20wave%2C%20when%20his%20valuable%20domain%20name%2C%20VL.com%2C%20was%20hijacked%20in%20a%20high-tech%20heist.%20Told%20" title="Google Bookmarks"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="javascript:AddToFavorites();" title="Add to favorites"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/addtofavorites.png" title="Add to favorites" alt="Add to favorites" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Grand%20Theft%20Internet&amp;body=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet" title="email"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.friendfeed.com/share?title=Grand%20Theft%20Internet&amp;link=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet" title="FriendFeed"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://hellotxt.com/?status=Grand%20Theft%20Internet+http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet" title="HelloTxt"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/hellotxt.png" title="HelloTxt" alt="HelloTxt" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.kirtsy.com/submit.php?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet&amp;title=Grand%20Theft%20Internet" title="Kirtsy"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/kirtsy.png" title="Kirtsy" alt="Kirtsy" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet&amp;title=Grand%20Theft%20Internet&amp;source=J.+Timothy+King%26%23039%3Bs+Blog+The+Life+of+an+Indie+Romance+Author&amp;summary=%0D%0A%0D%0ALike%20any%20other%20small%20businessman%2C%20he%20assumed%20his%20Internet%20account%20was%20basically%20safe.%20Instead%2C%20he%20found%20himself%20another%20victim%20of%20the%20latest%2021%27st%20century%20crime%20wave%2C%20when%20his%20valuable%20domain%20name%2C%20VL.com%2C%20was%20hijacked%20in%20a%20high-tech%20heist.%20Told%20" title="LinkedIn"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet&amp;t=Grand%20Theft%20Internet" title="MySpace"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet&amp;title=Grand%20Theft%20Internet" title="Reddit"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet&amp;title=Grand%20Theft%20Internet" title="StumbleUpon"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Grand%20Theft%20Internet%20-%20http%3A%2F%2Fblog.jtimothyking.com%2F2010%2F03%2F31%2Fgrand-theft-internet" title="Twitter"><img src="http://blog.jtimothyking.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.jtimothyking.com/2010/03/31/grand-theft-internet/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
