So Facebook put out a post today saying they got hacked last month. Not "your password was leaked" hacked: more like a handful of employee laptops got compromised after someone visited a mobile developer forum that had been rigged to serve malware through a Java hole in the browser. Facebook's line is that no user data was touched, and I believe them, mostly, because this isn't really a Facebook story. It's a "half of Silicon Valley has the same problem" story. Twitter said basically the same thing a couple weeks back, and word is Apple and Microsoft got hit through the identical attack, same booby-trapped site, same Java plugin doing the dirty work.
I want to be annoyed that a browser plugin from a language that peaked in usefulness around 2004 is still the thing quietly torching security teams at four of the biggest tech companies on earth, but honestly I'm just tired. I turned Java off in my own browser something like three years ago after the last "critical, patch now" scare and never noticed a single site break because of it. If you're reading this on a machine where java.com still has a plugin installed and enabled, go kill it in your browser's plugin settings right now. You almost certainly don't need it. The number of legitimate consumer websites still requiring a Java applet to function in February 2013 rounds to zero, and it's been that way for a while.
What gets me is the pattern. This wasn't some brute-force password thing or a phishing email. It was a watering hole attack — you compromise a site your actual targets are known to visit (in this case a forum for iPhone developers, which is a very specific kind of clever, since it tells you exactly who they were after) and you just wait. No mass emailing, no guessing, just patience and a zero-day. Oracle's been shipping Java security patches on this weird, slow cadence for years and every time there's a new hole the advice is the same: disable it, or at least set it to click-to-play so it's not running silently in every tab you open. I don't know why this is still news to people.
Anyway. Not the only thing that happened today, and honestly it's not even close to the biggest thing that happened today: a chunk of rock came apart over Chelyabinsk in Russia this morning and the shockwave blew out windows and hurt something like a thousand people, and there's a completely unrelated asteroid, 2012 DA14, that's supposed to come closer to Earth than our own weather satellites later tonight. Two different rocks, two different orbits, one very unlucky coincidence of timing. I've had three separate people text me asking if they're connected and the answer is no, it's just a wild day for things falling out of the sky.
The thing I keep getting stuck on, watching the footage come in all afternoon, is how much of it is dashcam video. Practically every clip of the fireball is shot from inside a moving car on some Russian highway, shaking around on a windshield mount. Turns out a huge percentage of drivers in Russia run dashcams constantly, not for moments like this but because insurance fraud and bogus accident claims are apparently common enough that a camera running nonstop is just cheaper than losing a dispute later. Nobody installed those cameras thinking they'd catch a meteor. It's a strange kind of accidental infrastructure — a giant, decentralized, never-asked-for camera network that happened to be pointed at the sky at exactly the right second, purely because people don't trust each other on the roads. I don't have a tidy point to make about that, I just think it's a genuinely interesting artifact of what happens when a cheap piece of hardware becomes common for reasons that have nothing to do with what it ends up being useful for.
Going to go find where I put the little travel router I keep meaning to flash with better firmware, because apparently that's what a Friday night looks like now.