Wednesday, May 23, 2012    
Home My Books Blog ColdFusion About Me Back    

Calendar
<< Mar 2009 >>
S M T W T F S
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30 31        

Search

Categories
 • Acrobat (5) [RSS]
 • Adobe (117) [RSS]
 • AdobeMAX06 (45) [RSS]
 • AdobeMAX07 (59) [RSS]
 • AdobeMAX08 (66) [RSS]
 • AdobeMAX09 (39) [RSS]
 • AdobeMAX10 (34) [RSS]
 • AdobeMAX11 (28) [RSS]
 • AdobeMAX13 (1) [RSS]
 • AIR (299) [RSS]
 • Appearances (217) [RSS]
 • Books (86) [RSS]
 • CFEclipse (15) [RSS]
 • Cloud (1) [RSS]
 • ColdFusion (1483) [RSS]
 • ColdFusion Builder (23) [RSS]
 • Data Services (43) [RSS]
 • Fish Tank (5) [RSS]
 • Flash (368) [RSS]
 • Flex (565) [RSS]
 • Home Automation (5) [RSS]
 • HTML5 (36) [RSS]
 • JavaScript (3) [RSS]
 • Jobs (133) [RSS]
 • jQuery (15) [RSS]
 • JRun (14) [RSS]
 • Labs (63) [RSS]
 • LiveCycle (37) [RSS]
 • MAX (285) [RSS]
 • Mobile (257) [RSS]
 • PhoneGap (17) [RSS]
 • Regular Expressions (19) [RSS]
 • RIA (21) [RSS]
 • SQL (45) [RSS]
 • Stuff (554) [RSS]
 • Tips (CF Studio) (80) [RSS]
 • Tips (CF) (795) [RSS]
 • Tips (Dreamweaver) (91) [RSS]
 • Tips (Flex Builder) (2) [RSS]
 • Using CF (167) [RSS]

Other BLOGs
 • Charlie Arehart
 • Lee Brimelow
 • Ray Camden
 • Christophe Coenraets
 • Sean Corfield
 • Mihai Corlan
 • Cornel Creanga
 • Mark Doherty
 • John Dowdell
 • Danny Dura
 • Enrique Duvos
 • Steven Erat
 • Kevin Hoyt
 • Serge Jespers
 • Adam Lehman
 • Duane Nickull
 • Miti Pricope
 • Andrew Shorten
 • Ryan Stewart
 • James Ward
 • Greg Wilson
 • Full As A Goog

RSS Feeds
 • Feed
 • Subscribe

Join my mailing list and find out about new books and other topics of interest.

Thoughts, ideas, tips, musings, and pontifications (not necessarily in that order) by Ben Forta ...
NOTE: This is my personal blog, and the opinions and statements voiced here are my own.

Viewing By Entry / Main
March 10, 2009

Flex Helps Catch A Thief!

Last week, Adobe Platform Evangelist James Ward, attended the Java Posse Roundup 2009 conference in Colorado. James just wrote up a report on this trip, and I just had to share the following excerpt (this is a straight copy and paste, no editing):

The highlight of the trip was a lightning talk about how one of the attendees used a Flex app to recover a friend's stolen laptop. The presenter discovered that the friend's stolen laptop was signed into Skype so he sent a message to the thief pretending to think that he was sending a message to his friend. The message asked him to click on a link which took him to a Flex app that started up the webcam and recorded the thief's face for a few minutes using Red5. They sent the video to the police who recognized the thief and apprehended him and recovered the stolen laptop. That couldn't have been done with Silverlight, JavaFX, or Ajax!

Comments
Howdy Ben, do we know how the webcam was activated without throwing up a permissions dialog? (More info: http://kb.adobe.com/selfservice/viewContent.do?ext... )

tx, jd/adobe
# Posted By John Dowdell | 3/10/09 5:44 PM
Good news. But I'm just curious. How did the thief login to the OS?
# Posted By Shigeru | 3/10/09 7:00 PM
JD, I wondered that too. Would be a good question for James.

--- Ben
# Posted By Ben Forta | 3/10/09 8:32 PM
Probably used the privacy settings panel or FP settings manager... and had previously granted permissions for the website to access the camera.

http://www.macromedia.com/support/documentation/en...
# Posted By Rick Winscot | 3/10/09 10:05 PM
It did throw up the webcam security dialog but some clever social engineering helped to convince the thief to click the allow button.

I think the laptop was a Mac so there wasn't a login required when the lid was opened.

Just a warning to all the laptop thieves out there: I require a password on my computer when it boots, when it comes out of suspend, and when the screensaver is deactivated. :)
# Posted By James Ward | 3/10/09 10:52 PM
Glad you got your laptop - but this is a double edged sword. If apps can be made so insecure that a camera can be remotely activated - then this is just ripe for misuse.
# Posted By Jack Wong | 3/11/09 4:50 PM
Jack,

The camera was not remotely activated. The thief had to click the "Allow" button but the presenter used some clever social engineering to convince the thief it was ok to click the button.

-James
# Posted By James Ward | 3/12/09 1:37 PM
Hey James - I'd be interested in knowing what the "Social Engineering" aspect of your ruse was . What could pique a thief's interest?

Cheers,

David
# Posted By David | 3/13/09 11:24 AM
The thief thought that he was going to get some money by clicking "Allow". And since the text asking the thief to click the button was much bigger than the text in the button itself the thief didn't bother to actually read what he was allowing.
# Posted By James Ward | 3/13/09 1:43 PM
Thanks for your post.
# Posted By rose | 3/15/09 11:17 PM

  © Copyright 1997-2009 Ben Forta, All Rights Reserved