<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/rss-style.xsl" type="text/xsl"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	    xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	     xmlns:dc="http://purl.org/dc/elements/1.1/"
	   xmlns:atom="http://www.w3.org/2005/Atom"
	     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	  xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>
<channel>
	<title>journalism &#8211; Terence Eden’s Blog</title>
	<atom:link href="https://shkspr.mobi/blog/tag/journalism/feed/" rel="self" type="application/rss+xml" />
	<link>https://shkspr.mobi/blog</link>
	<description>Regular nonsense about tech and its effects 🙃</description>
	<lastBuildDate>Thu, 27 Feb 2025 10:15:53 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://shkspr.mobi/blog/wp-content/uploads/2023/07/cropped-avatar-32x32.jpeg</url>
	<title>journalism &#8211; Terence Eden’s Blog</title>
	<link>https://shkspr.mobi/blog</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title><![CDATA[Huffington Post UK XSS Flaw (Disclosed & Fixed)]]></title>
		<link>https://shkspr.mobi/blog/2014/02/huffington-post-uk-xss-flaw-disclosed/</link>
					<comments>https://shkspr.mobi/blog/2014/02/huffington-post-uk-xss-flaw-disclosed/#respond</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Thu, 27 Feb 2014 12:14:09 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[journalism]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[xss]]></category>
		<guid isPermaLink="false">http://shkspr.mobi/blog/?p=9979</guid>

					<description><![CDATA[The UK version of the Huffington Post was vulnerable to an XSS flaw.  This allowed any malicious user to inject images, video, text, and JavaScript into the page.    Although the above image show a very silly use of XSS, it could quite easily be used to craft a page to encourage journalists and readers to enter their passwords - and then send them off to criminals.  What&#039;s unusual is that it…]]></description>
										<content:encoded><![CDATA[<p>The UK version of the Huffington Post was vulnerable to an XSS flaw.  This allowed any malicious user to inject images, video, text, and JavaScript into the page.</p>

<p><a href="http://ow.ly/tOPEK"><img src="https://shkspr.mobi/blog/wp-content/uploads/2014/02/Huff-Po-UK-XSS.jpg" alt="Huff Po UK XSS" width="720" height="796" class="aligncenter size-full wp-image-9980"></a></p>

<p>Although the above image show a very silly use of XSS, it could quite easily be used to craft a page to encourage journalists and readers to enter their passwords - and then send them off to criminals.</p>

<p>What's unusual is that it appears to be powered by Google Custom Search - which should really be robust against this source of attack.</p>

<p>I <strong>strongly encourage</strong> people to read and understand the <a href="https://wiki.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet">OWASP Guide to XSS</a> - and their other fine guides.</p>

<p>It will save a lot of heartache later on.</p>

<h2 id="timeline"><a href="https://shkspr.mobi/blog/2014/02/huffington-post-uk-xss-flaw-disclosed/#timeline">Timeline</a></h2>

<ul>
    <li>20th February 2014 - Disclosed via their "technical problems with the website" form.</li>
    <li>21st February 2014 - No response, so escalated to the Executive Editor.</li>
    <li>26th February 2014 - <a href="https://web.archive.org/web/20200927043946/http://huff.to/1fHxnQt">Confirmed fixed</a>.</li>
</ul>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=9979&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2014/02/huffington-post-uk-xss-flaw-disclosed/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Should Journalists Bother Checking Sources?]]></title>
		<link>https://shkspr.mobi/blog/2013/10/should-journalists-bother-checking-sources/</link>
					<comments>https://shkspr.mobi/blog/2013/10/should-journalists-bother-checking-sources/#respond</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Thu, 17 Oct 2013 13:38:11 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[journalism]]></category>
		<guid isPermaLink="false">http://shkspr.mobi/blog/?p=8804</guid>

					<description><![CDATA[OMG WE&#039;RE ALL GOING TO DIE!!!!111!!  (Subsequently deleted but still available at Fadah Jassem&#039;s tweet)  Let&#039;s take a look at the article and see if we can determine if this is a trustworthy source...   Hmmm... I see &#34;9/11 Truth&#34;, &#34;Bilderberg&#34;, &#34;Chemtrails&#34; right next to the image.  There&#039;s a conspiracy corner in the top right.  We haven&#039;t even got below the fold yet.  Now, that&#039;s not to say that …]]></description>
										<content:encoded><![CDATA[<p>OMG WE'RE ALL GOING TO DIE!!!!111!!
<img src="https://shkspr.mobi/blog/wp-content/uploads/2013/10/Fukushima-fs8.png" alt="Fukushima-fs8" width="567" height="770" class="aligncenter size-full wp-image-8808">
(Subsequently <a href="http://twitter.com/AlexiMostrous/status/390824824181764096">deleted</a> but still available at <a href="https://mobile.twitter.com/FadahJassem/status/390815234031902720" title="Fadah Jassem's tweet">Fadah Jassem's tweet</a>)</p>

<p>Let's take a look at <a href="https://web.archive.org/web/20131002020217/http://www.thesleuthjournal.com/radioactive-water-from-fukushima-is-systematically-poisoning-the-entire-pacific-ocean/">the article</a> and see if we can determine if this is a trustworthy source...
<a href="https://shkspr.mobi/blog/wp-content/uploads/2013/10/Sleuth-fs8.png"><img src="https://shkspr.mobi/blog/wp-content/uploads/2013/10/Sleuth-fs8.png" alt="Sleuth-fs8" width="896" height="749" class="aligncenter size-full wp-image-8806"></a></p>

<p>Hmmm... I see "9/11 Truth", "Bilderberg", "Chemtrails" right next to the image.  There's a conspiracy corner in the top right.  We haven't even got below the fold yet.  Now, that's not to say that sites like these don't occasionally break news - but I'm not sure I'd rely on it for accuracy.</p>

<p>The story is, of course, a hoax.  <a href="http://www.snopes.com/photos/technology/fukushima.asp">Snopes has an excellent write-up demonstrating quite clearly that this is a map of wave height following a tsunami</a>.  They even link to primary and secondary sources.</p>

<p>In fact, if the "journalists" had bothered scrolling to the comments, they would have seen many people debunking this story.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2013/10/Snopes-fukushima-fs8.png" alt="Snopes fukushima-fs8" width="600" height="548" class="aligncenter size-full wp-image-8809">
...along with an advert telling people that water, salt, and milk are killing children.</p>

<blockquote class="social-embed" id="social-embed-390829404365926400" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/AlexiMostrous" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRhACAABXRUJQVlA4IAQCAAAQCwCdASowADAAPrFGnUmnI6KhLjgOYOAWCWQArDlBVF525jZcUVlKTqda1WWlpmGjUFlCAUzj+ookWI9kcG+0W+WKYEwwhq9yNxMneI8Df/Pe8NMpoY/fB7sLxuQmS2JAAP703RU3OExj2xtMgI8Fbi7r43UIrAddSINaY+fYfSrYrzyTyrwianYootRSRlerNSd+peUgteoGeU4piy42Q+jN1IwxQNwskIs8i2RS3gsp2CuycuQ4mjFCMVm4hAIIPiCHTpXzU1UDLdBdJWhvbiZuY2sYX3dM88ZUFmu6DVd185uNT+4VWVZdBzCX/gBs+rIqExq/J+xvFsjOJqcMLa8KjCeiz3wsdNma1vTg4J80+r6mVxgEN4C5il7Ku/yQ7xHZPwX7IrFvZmEUyyJpM8cINwJoKbp5L5tmrNEOo/dEA8YV1yvx5/rBuoM1CpxktOFJU7bqQA/DGhEh78/orZ91eoZ+HN7tRQx1//Nsa+0lqeZCbDbsJIEoGkaxvh8L+CodawJTI5bTCrCPmsMTQTEOwXw410LnY4xVXB581Q+c9MDx9A5b0oG7VgDy17iFZwo0Yyvif+A+rv9k39kS7Sxk1vsp/oF4w5LBETW1PJk9xGDWAJDGB+WxDtNzSzRCd8lUAb71JvVMrqa/mptIMxE9DkvXuI/5bLqWEACYzuiAAAA=" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Alexi Mostrous</p>@AlexiMostrous</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody">Looks like that stupid Fukishima radiation picture was a stupid fake</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/AlexiMostrous/status/390829404365926400"><span aria-label="1 likes" class="social-embed-meta">❤️ 1</span><span aria-label="2 replies" class="social-embed-meta">💬 2</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2013-10-17T13:19:25.000Z" itemprop="datePublished">13:19 - Thu 17 October 2013</time></a></footer></blockquote>

<p>The thing is, it's not a "stupid fake".  It's a couple of stupid journalists who fell for an obviously dubious source.  Take a look at the image, notice the scale on the right hand side? It is in centimetres which - for those of you without a physics GCSE - isn't a measure of radiation.</p>

<p>Citizen Journalism gets a bad name. But compared with two actual card-carrying journalists, it's not that much worse.</p>

<p>Journalists have a great opportunity to connect with their readers on social media - Alexi Mostrous has over 10,000 followers - but journalists obviously still need the filter of a good editor. Or just some common sense.  That is, unless they want to become mere rumour-mongers and let their readers do their fact checking for them.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=8804&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2013/10/should-journalists-bother-checking-sources/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
