andrewducker: (Default)
[personal profile] andrewducker
So, I got an email from The Student Loans Company.

Well, it _said_ it was from the SLC, but I don't have a student loan any more.

And when I hovered over the link to the website that wanted me to "verify your details", it didn't seem to be pointing to the website that the text would indicate.

Not that it was easy to tell - as the popup with the link text in it only showed 80 characters - the last 80 characters.

So I clicked on it.  On my phone, as I figured that the number of viruses, etc. that target Webkit on a Nokia must be somewhere near zero.

And then discovered that the only way to find out what the actual address of the page you're on under the Nokia Webkit browser is buried in the menu system.

So when I got the page name I decided to visit the root domain and see what that was.

Lo and Behold - a WordPress install, last updated in 2008.  And thus undoubtedly full of holes.

So I used the "contact" form there to drop the owner an email.  Which will probably go to a dead email box that they haven't checked since 2008.

Further checking shows that the Student Loans Company don't have an SPF record set up to prevent people from impersonating them when sending email.  Which means that botnets are free to send email that "comes from" them.

And this is why we can't have nice things.

Date: 2010-04-13 03:27 pm (UTC)
matgb: Artwork of 19th century upper class anarchist, text: MatGB (Default)
From: [personal profile] matgb
One of the biggest drawbacks of Wordpress is the way the default account setup is to create an account username 'admin'. They really need to insist people don't do that, and preferably use email addresses as usernames, etc.

And yes, trying to figure out where I am on the built in Nokia browser did get to me too much, one of the reasons I switched to Opera Mini/Mobile, despite the flaws there, addressbar is clear and easy to sort through.

Date: 2010-04-13 03:43 pm (UTC)
matgb: Artwork of 19th century upper class anarchist, text: MatGB (Default)
From: [personal profile] matgb
Ah, yes, using the built in client would open in the default; I tend to check my email through Gmail web interface, but that's habit, having a built in e client is useful.

You'd have thought it would be possible somewhere, but they're still in early stages of making a usable but open smartphone, it'll likely happen at some point. You saw Apple have licenced Opera Mini for the app store? NEver thought I'd see that happen.

Date: 2010-04-13 04:52 pm (UTC)
matgb: Artwork of 19th century upper class anarchist, text: MatGB (Default)
From: [personal profile] matgb
Heh, see, I love the Gmail threaded view, so much easier for me, one of the reasons I haven't gone back to a client. Especially good on a phone where I want to read a conversation instead of lots of emails each of which takes time to load up.

And yes, restricting what language you code in is just stupid; I barely code at all, but telling people they can only compile from codebase X is daft.

August 2025

S M T W T F S
      1 2
3 4 5 6 7 8 9
10 11 12 1314 15 16
17181920212223
24252627282930
31      

Most Popular Tags

Page Summary

Style Credit

Expand Cut Tags

No cut tags
Page generated Aug. 16th, 2025 09:32 pm
Powered by Dreamwidth Studios