<?xml version="1.0" encoding="utf-8"?>
<feed
    xmlns="http://www.w3.org/2005/Atom"
    xmlns:at="http://www.sixapart.com/ns/at"
    xmlns:icbm="http://postneo.com/icbm"
    xmlns:rvw="http://purl.org/NET/RVW/0.2/"
    xml:lang="en">
    <title>3 Stations East</title>
    <link rel="self" type="application/atom+xml" title="3 Stations East (Atom)" href="http://paulmcaleer.vox.com/library/posts/2007/08/page/1/atom.xml" />
    <link rel="alternate" type="text/html" title="3 Stations East" href="http://paulmcaleer.vox.com/library/posts/2007/08/page/1/"/> 
    <link rel="service.post" type="application/atom+xml" title="3 Stations East" href="http://www.vox.com/services/atom/svc=post/collection_id=6a00c2251c214c604a00c2251d11598e1d" /> 
    <link rel="service.subscribe" type="application/atom+xml" title="3 Stations East" href="http://paulmcaleer.vox.com/library/posts/2007/08/atom.xml" />   
    <link rel="last" type="application/atom+xml" title="3 Stations East" href="http://paulmcaleer.vox.com/library/posts/2007/08/page/1/atom.xml" />  
    <generator uri="http://www.vox.com/">Vox</generator>
    <updated>2007-08-21T02:52:12Z</updated> 
    <author>
        <name>Paul</name>
        <uri>http://paulmcaleer.vox.com/?_c=feed-atom-full</uri>
    </author> 
    <id>tag:vox.com,2006:6p00c2251c214c604a/2007/08/</id> 
    <subtitle>In which I say little and post even less.</subtitle>  
    
    <entry>
        <title>I felt lucky.</title>   
        <link rel="alternate" type="text/html" title="I felt lucky." href="http://paulmcaleer.vox.com/library/post/i-felt-lucky.html?_c=feed-atom-full" />  
        <link rel="service.post" type="application/atom+xml" title="I felt lucky." href="http://paulmcaleer.vox.com/library/post/i-felt-lucky.html?_c=feed-atom-full#comments" /> 
        <link rel="service.edit" type="application/atom+xml" title="I felt lucky." href="http://www.vox.com/atom/svc=post/asset_id=6a00c2251c214c604a00e3989fa6dc0001" />            <id>tag:vox.com,2007-08-21:asset-6a00c2251c214c604a00e3989fa6dc0001</id>
        <published>2007-08-21T02:52:12Z</published>
        <updated>2007-08-21T02:52:12Z</updated>
    
        <author>
            <name>Paul</name>
            <uri>http://paulmcaleer.vox.com/?_c=feed-atom-full</uri>
        </author>
    
        
        <content type="html" xml:base="http://paulmcaleer.vox.com/?_c=feed-atom-full">
            <![CDATA[
                <div xmlns="http://www.w3.org/1999/xhtml" xmlns:at="http://www.sixapart.com/ns/at">
        
    
    
    

    
    
    
<div at:enclosure="asset" at:xid="6a00c2251c214c604a00e3989fbd7a0003" at:format="large" at:align="right"
    class="enclosure enclosure-right enclosure-large photo-enclosure" 
     style="text-align: center; float: right;">
<div class="enclosure-inner"
    
        style="padding: 9px; border: 1px solid; width: px; margin: 0 0 20px 20px;"
    >
    <div class="enclosure-list">
        <div class="enclosure-item photo-asset last">
    
            <div class="enclosure-image">
        
                <a href="http://paulmcaleer.vox.com/library/photo/6a00c2251c214c604a00e3989fbd7a0003.html"><img src="http://a2.vox.com/6a00c2251c214c604a00e3989fbd7a0003-320pi" alt="Erika &amp; Karl No. 3" title="Erika &amp; Karl No. 3" /></a>
        
            </div>
            <div class="enclosure-meta">
                <div class="enclosure-asset-name"><a href="http://paulmcaleer.vox.com/library/photo/6a00c2251c214c604a00e3989fbd7a0003.html" title="Erika &amp; Karl No. 3">Erika &amp; Karl No. 3</a></div>
            </div>
    
        </div>
    </div>
</div>
</div><!-- end enclosure -->
<p>
Not very long ago Heather Champ started the <a href="http://flickr.com/groups/feelinglucky/">I&#39;m Feeling Lucky</a> group, wherein she distributed 100 rolls of expired Chinese film for free. I felt really sad to miss the boat on the first 100 but when a second batch of 50 made it I signed up instantly. <div><br class="webkit-block-placeholder" /></div><div>I got the film last week and used it this past weekend during my shoot of Erika &amp; Karl. The results? Surprisingly good! The only real issues were photographer error (fuzzy shots, there were a few) and random pink spots on many of the photos. But overall, not bad.</div><div><br class="webkit-block-placeholder" /></div><div>This also gave me a chance to borrow Jeani&#39;s SLR (a real, honest-to-gosh SLR) and it was kind of cool to work with film. Interestingly I also had to borrow her PowerShot A80 - my old camera - for the shoot as... my camera is broken. (welp) It went back to Panasonic for warranty repair today.</div><div><br class="webkit-block-placeholder" /></div><div>In the meantime, though, I&#39;m really happy with these Lucky shots. Thanks again Heather!</div><div><br class="webkit-block-placeholder" /></div><div><br /></div><div><br /></div></p>   <p style="clear:both;"> 
    <a href="http://paulmcaleer.vox.com/library/post/i-felt-lucky.html?_c=feed-atom-full#comments">Read and post comments</a>   |   
    <a href="http://www.vox.com/share/6a00c2251c214c604a00e3989fa6dc0001?_c=feed-atom-full">Send to a friend</a> 
</p>

                </div>
            ]]>
        </content> 
    <category term="photos" scheme="http://paulmcaleer.vox.com/tags/photos/" label="photos" /> 
    <category term="friends" scheme="http://paulmcaleer.vox.com/tags/friends/" label="friends" /> 
    <category term="photography" scheme="http://paulmcaleer.vox.com/tags/photography/" label="photography" /> 
    <category term="film" scheme="http://paulmcaleer.vox.com/tags/film/" label="film" /> 
    <category term="portraits" scheme="http://paulmcaleer.vox.com/tags/portraits/" label="portraits" /> 
    <category term="slr" scheme="http://paulmcaleer.vox.com/tags/slr/" label="slr" /> 
    <category term="luckyfilmproject" scheme="http://paulmcaleer.vox.com/tags/luckyfilmproject/" label="luckyfilmproject" /> 
    </entry> 
    
    <entry>
        <title>A Funny Thing Happened on the Way to the Form</title>   
        <link rel="alternate" type="text/html" title="A Funny Thing Happened on the Way to the Form" href="http://paulmcaleer.vox.com/library/post/a-funny-thing-happened-on-the-way-to-the-form.html?_c=feed-atom-full" />  
        <link rel="service.post" type="application/atom+xml" title="A Funny Thing Happened on the Way to the Form" href="http://paulmcaleer.vox.com/library/post/a-funny-thing-happened-on-the-way-to-the-form.html?_c=feed-atom-full#comments" /> 
        <link rel="service.edit" type="application/atom+xml" title="A Funny Thing Happened on the Way to the Form" href="http://www.vox.com/atom/svc=post/asset_id=6a00c2251c214c604a00e3989c343e0003" />          <id>tag:vox.com,2007-08-09:asset-6a00c2251c214c604a00e3989c343e0003</id>
        <published>2007-08-09T21:02:09Z</published>
        <updated>2007-08-09T21:02:51Z</updated>
    
        <author>
            <name>Paul</name>
            <uri>http://paulmcaleer.vox.com/?_c=feed-atom-full</uri>
        </author>
    
        
        <content type="html" xml:base="http://paulmcaleer.vox.com/?_c=feed-atom-full">
            <![CDATA[
                <div xmlns="http://www.w3.org/1999/xhtml" xmlns:at="http://www.sixapart.com/ns/at">
        <p>It started innocently enough. I <a href="http://www.usabilityisboring.com/2007/08/07/critique-the-new-chicagotribunecom/">wrote a critique of the new Chicago Tribune website</a> and wanted to let the Trib&#39;s web staff know about it. So I headed over to <a href="http://www.chicagotribune.com/about/site/chi-feedback,0,5909681.htmlpage">their feedback form.</a></p><p>Earlier this morning, it wasn&#39;t working. After hitting submit, I was redirected to this URL where I got an XML-based error:</p><p>https://www.quickbase.com/db/bcq7ne93t?act=API_AddRecord&amp;username=chiGen3comments@gmail.com&amp;password=</p><p>...however, see that &quot;password=&quot; part? <strong>The password was in the URL in plain text.</strong> I&#39;ve removed it here because I don&#39;t want to be a jerk (but I&#39;ll mention that it is a tremendously weak password. Like &quot;password&quot;.)</p><p>My first instinct was to let them know, so I sent an email to that Gmail address. No reply yet. I then went to quickbase.com to discover it was an Intuit joint. After navigating down to their support section, I fired off an email:</p><blockquote><p>Hi there,</p><p>The Chicago Tribune has a feedback form on their site at this URL:</p><p>http://www.chicagotribune.com/about/site/chi-feedback,0,5909681.htmlpage</p><p>When I was attempting to submit the form earlier, it was erroring out to this URL (a straight XML dump):</p><p>https://www.quickbase.com/db/bcq7ne93t?act=API_AddRecord&amp;amp;username=chiGen3comments@gmail.com&amp;password=...</p><p>However, you&#39;ll note that the username and password are in CLEAR TEXT in the URL. This is a huge, huge security issue. I trust I could have easily just logged in to QuickBase and mucked with the Tribune&#39;s account.</p><p>That&#39;s unacceptable. I wanted to make you aware of this.</p></blockquote><p>Slightly later, I got this reply:</p><blockquote><p>Hi Paul,</p><p>Thanks for your concern and for creating this case.&#160; I just tried the form on the Chicago Tribune site and it didn&#39;t error out on me.&#160; They must have fixed it.&#160; This form would be set up for an &quot;everyone on the internet&quot; role whereby any anonymous user can write to it.&#160; The API call you saw is most likely an account set up for just the anonymous people to add to the form.&#160; I don&#39;t believe you could have done much to their QuickBase by trying to log in with that.&#160; Regardless, I think this was just an error in how they must have had it set up because it appears to be working fine now.</p><p>Thank you!<br />Jeff<br />QuickBase Support</p></blockquote><p>I&#39;m not at liberty to say if I did in fact log in to QuickBase. However, one could hypothesize that any basic security level would, at least, include the ability to change one&#39;s username and password.</p><p>This is solely QuickBase&#39;s fault. There&#39;s no reason a password should <em>ever</em> be shown in <em>clear text</em> on an URL, ever. Shame on them for having lax security (I mean, the password was upchucked by <em>their</em> system - not the Trib&#39;s form) and shame on them for their security-free reply.<br /></p>   <p style="clear:both;"> 
    <a href="http://paulmcaleer.vox.com/library/post/a-funny-thing-happened-on-the-way-to-the-form.html?_c=feed-atom-full#comments">Read and post comments</a>   |   
    <a href="http://www.vox.com/share/6a00c2251c214c604a00e3989c343e0003?_c=feed-atom-full">Send to a friend</a> 
</p>

                </div>
            ]]>
        </content> 
    <category term="security" scheme="http://paulmcaleer.vox.com/tags/security/" label="security" /> 
    <category term="warning" scheme="http://paulmcaleer.vox.com/tags/warning/" label="warning" /> 
    <category term="tribune" scheme="http://paulmcaleer.vox.com/tags/tribune/" label="tribune" /> 
    <category term="design flaw" scheme="http://paulmcaleer.vox.com/tags/design+flaw/" label="design flaw" /> 
    <category term="intuit" scheme="http://paulmcaleer.vox.com/tags/intuit/" label="intuit" /> 
    <category term="quickbase" scheme="http://paulmcaleer.vox.com/tags/quickbase/" label="quickbase" /> 
    <category term="bad support" scheme="http://paulmcaleer.vox.com/tags/bad+support/" label="bad support" /> 
    </entry> 
    
    <entry>
        <title>That New Apple Wireless Keyboard</title>   
        <link rel="alternate" type="text/html" title="That New Apple Wireless Keyboard" href="http://paulmcaleer.vox.com/library/post/that-new-apple-wireless-keyboard.html?_c=feed-atom-full" />  
        <link rel="service.post" type="application/atom+xml" title="That New Apple Wireless Keyboard" href="http://paulmcaleer.vox.com/library/post/that-new-apple-wireless-keyboard.html?_c=feed-atom-full#comments" /> 
        <link rel="service.edit" type="application/atom+xml" title="That New Apple Wireless Keyboard" href="http://www.vox.com/atom/svc=post/asset_id=6a00c2251c214c604a00e3989bd4770004" />          <id>tag:vox.com,2007-08-08:asset-6a00c2251c214c604a00e3989bd4770004</id>
        <published>2007-08-08T19:12:23Z</published>
        <updated>2007-08-08T19:12:23Z</updated>
    
        <author>
            <name>Paul</name>
            <uri>http://paulmcaleer.vox.com/?_c=feed-atom-full</uri>
        </author>
    
        
        <content type="html" xml:base="http://paulmcaleer.vox.com/?_c=feed-atom-full">
            <![CDATA[
                <div xmlns="http://www.w3.org/1999/xhtml" xmlns:at="http://www.sixapart.com/ns/at">
        <p>Surely I&#39;m not the only one who saw <a href="http://www.apple.com/keyboard/">the new Apple wireless keyboard</a> and thought, &quot;Media center keyboard.&quot;</p><p>Prediction: it&#39;ll interface with the Apple TV in time.<br /> </p>   <p style="clear:both;"> 
    <a href="http://paulmcaleer.vox.com/library/post/that-new-apple-wireless-keyboard.html?_c=feed-atom-full#comments">Read and post comments</a>   |   
    <a href="http://www.vox.com/share/6a00c2251c214c604a00e3989bd4770004?_c=feed-atom-full">Send to a friend</a> 
</p>

                </div>
            ]]>
        </content> 
    <category term="design" scheme="http://paulmcaleer.vox.com/tags/design/" label="design" /> 
    <category term="apple" scheme="http://paulmcaleer.vox.com/tags/apple/" label="apple" /> 
    <category term="keyboard" scheme="http://paulmcaleer.vox.com/tags/keyboard/" label="keyboard" /> 
    <category term="media center" scheme="http://paulmcaleer.vox.com/tags/media+center/" label="media center" /> 
    </entry> 
    
    <entry>
        <title>Alive</title>   
        <link rel="alternate" type="text/html" title="Alive" href="http://paulmcaleer.vox.com/library/post/alive.html?_c=feed-atom-full" />  
        <link rel="service.post" type="application/atom+xml" title="Alive" href="http://paulmcaleer.vox.com/library/post/alive.html?_c=feed-atom-full#comments" /> 
        <link rel="service.edit" type="application/atom+xml" title="Alive" href="http://www.vox.com/atom/svc=post/asset_id=6a00c2251c214c604a00e3989b4bc90003" />            <id>tag:vox.com,2007-08-07:asset-6a00c2251c214c604a00e3989b4bc90003</id>
        <published>2007-08-07T05:02:22Z</published>
        <updated>2007-08-08T15:43:35Z</updated>
    
        <author>
            <name>Paul</name>
            <uri>http://paulmcaleer.vox.com/?_c=feed-atom-full</uri>
        </author>
    
        
        <content type="html" xml:base="http://paulmcaleer.vox.com/?_c=feed-atom-full">
            <![CDATA[
                <div xmlns="http://www.w3.org/1999/xhtml" xmlns:at="http://www.sixapart.com/ns/at">
        
    
    
    

    
    
    
<div at:enclosure="asset" at:xid="6a00c2251c214c604a00e3989b4bb20003" at:format="large" at:align="right"
    class="enclosure enclosure-right enclosure-large photo-enclosure" 
     style="text-align: center; float: right;">
<div class="enclosure-inner"
    
        style="padding: 9px; border: 1px solid; width: px; margin: 0 0 20px 20px;"
    >
    <div class="enclosure-list">
        <div class="enclosure-item photo-asset last">
    
            <div class="enclosure-image">
        
                <a href="http://paulmcaleer.vox.com/library/photo/6a00c2251c214c604a00e3989b4bb20003.html"><img src="http://a2.vox.com/6a00c2251c214c604a00e3989b4bb20003-320pi" alt="Allie No. 2" title="Allie No. 2" /></a>
        
            </div>
            <div class="enclosure-meta">
                <div class="enclosure-asset-name"><a href="http://paulmcaleer.vox.com/library/photo/6a00c2251c214c604a00e3989b4bb20003.html" title="Allie No. 2">Allie No. 2</a></div>
            </div>
    
        </div>
    </div>
</div>
</div><!-- end enclosure -->

 <div>I&#39;ve read more than once that one of the finer criteria of a good photograph is, &quot;Is the photo alive?&quot;</div><div><br class="webkit-block-placeholder" /></div><div>Well, when shooting my pals Allie &amp; Jonathan this past weekend there was one photo that was incredibly, wonderfully alive. Here it is!</div>   <p style="clear:both;"> 
    <a href="http://paulmcaleer.vox.com/library/post/alive.html?_c=feed-atom-full#comments">Read and post comments</a>   |   
    <a href="http://www.vox.com/share/6a00c2251c214c604a00e3989b4bc90003?_c=feed-atom-full">Send to a friend</a> 
</p>

                </div>
            ]]>
        </content> 
    <category term="photo" scheme="http://paulmcaleer.vox.com/tags/photo/" label="photo" /> 
    <category term="friends" scheme="http://paulmcaleer.vox.com/tags/friends/" label="friends" /> 
    <category term="photography" scheme="http://paulmcaleer.vox.com/tags/photography/" label="photography" /> 
    <category term="alive" scheme="http://paulmcaleer.vox.com/tags/alive/" label="alive" /> 
    </entry> 
</feed>


