16 June 2008

Challenges and Directions for Monitoring P2P File Sharing Networks –or– Why My Printer Received a DMCA Takedown Notice

This is brilliant:

Q: The title of your paper indicates that you received DMCA complaints for a printer, but printers can't even run P2P software. How is that possible?
Surprisingly, it is possible. We have received DMCA complaints for several printers and even a wireless access point! (Please note that these are printers directly connected to the Internet and have their own IP addresses.) This is possible because some monitoring agencies don't verify that a user reported to be sharing a file actually is sharing that file. This allows a malicious person to frame any device connected to the Internet: whether a printer, a wireless access point, or an innocent user's computer.


I wonder how long it's going to be before some clever people figure out the RIAA, MPAA, MediaSentry, MediaDefender, etc. IP address blocks and "frames" all of them for illegal file sharing?

15 June 2008

It May Be Cliché, But This Post Is About Prof. Randy Pausch

Most of the Internet-speaking world, as well as some of the primarily television-speaking world (thanks to Oprah) are now familiar with Prof. Randy Pausch and his struggle with pancreatic cancer. If for some reason you are not familiar with his story, set aside 90 minutes to view his "Last Lecture" on YouTube (includes personal crying time but allow for more if detailed, introspective analysis and personal priority realignment are things you tend toward):



The Last Lecture Compendium print edition:



and finally his commencement address at CMU last month:



I've never attended CMU, met Pausch or personally dealt with any life-altering situation such as terminal pancreatic cancer. I'm very fortunate, with regard to the last item. I am, however, completely in awe of the way in which he has continued living his life and remaining fully engaged with his family; I can only hope that I would be strong enough to do the same. I feel his love for his three young children everyday with my own kids of similar ages. I hope he is stronger than myself and does not become overcome with grief when imagining life without them - life for the children without a father who so clearly loves them and his spouse.

Randy Pausch may have achieved his childhood dreams but there are so many of us out here who have not done so. Most of us still have the time to do so. Do you remember your dreams? Do they still matter to you? Will you help your children achieve their dreams, knowing that every moment could potentially be your last?

I will.

Space Station Could Beam Secret Quantum Codes by 2014

I've always wanted to open a socket and read from /dev/random on the ISS.

01 June 2008

Delhi (Day 0)

We flew from Newark, NJ to the Indian capital of Delhi. With delays the flight was approximately 16 hours. While the flight was long, the Business/First class seating on Continental Airlines certainly made it bearable.

The New Delhi airport was...interesting. Local temperature was fair at 27° C. Clearing customs was efficient and easy. We were meeting a driver who was to bring us to our hotel in Noida and this is where things got interesting. We found the driver easily enough but then an ever-growing entourage (not the Jeremy Pivin type of Entourage) began "escorting" us and "helping" with out luggage. As the trek to the car attracts more and more helpers and we finally get to the car, everyone suddenly wants to be paid $20 US for their "assistance." This caught us off-guard a bit but we managed to hang onto most of our money (I only had $6 US with me!) and an hour or so later were at our hotel in Noida enjoying a few Kingfisher lagers and unwinding.

Tomorrow is a new day.

30 May 2008

I'm Leaving On A Jet Plane....

Well, it's off to India for ten days or so on a work-related trip. Exciting times ahead! More to follow....

26 May 2008

Boston University Researchers Developing Sign Language Video Dictionary

This is pretty cool (by way of the ACM TechNews):

Boston University doctoral student Joan Nash, who has used American Sign Language (ASL) for most of her life, is part of a team working on an interactive video project that would create a virtual sign language dictionary, allowing someone to demonstrate a sign in front of a camera and have a computer program interpret and explain its meaning. The researchers are working with a three-year, $900,000 grant from the National Science Foundation, and are currently in the early stages of the project, which involves capturing thousands of ASL signs on video. As Nash goes through the hundreds of words in English, Elizabeth Cassidy, a native ASL speaker, signs them in front of four different cameras, three in front of her and one to her right. Two of the cameras in front of her capture close-ups from different angles and one is a wider shot. The goal is to develop a database of more than 3,000 signs, with the meaning of each sign being determined by the shape of the hands, the movement of the hands and arms, and even facial expressions. Eventually, the researchers hope the technology will be used to develop a multimedia ASL dictionary to help hearing parents better communicate with deaf children and to help sign language students.

I've often wondered if groups of people who sign, say from a particular community or geographic location, have an "accent" when they sign? Can a person signing have a "twang" or a "drawl" or something akin to a Boston accent? For instance, German telegraph operators during WWII were sometimes known to have a certain "hand" or touch to their transmission that those intercepting the transmission in Bletchley Park could identify as belonging to a certain operator. Does the same stylization or accent occur in signing?

11 May 2008

F1 in Schools



This is pretty cool. All I had growing up was the Cub Scout's annual Pinewood Derby.

From the US site:

What is F1 in Schools?

It's a competition for teams of three to six school children to design and manufacture miniature CO2-powered racing cars and then race them at regional, national, and international levels. Sounds simple? Not when you consider that these 11- to 18-year old kids use state-of-the-art software programs that enable them to play around with CAD (computer aided design) and CFD (computational fluid dynamics), just like real F1 designers.

Or that they have to manage the whole project from scratch, from drawing up a business plan and raising the sponsorship, to financing it through the design and manufacturing stages, to a presentation in front of a panel of preeminent judges.

.

10 May 2008

Information Security And User Education

I guess after a nice day walking around the Roger Williams Zoo with friends and family, I'm feeling sort of middle of the road and moderate in opinion tonight (or perhaps just lazy). I say this because I just read a post to the recently launched ISC2 blog, in particular, this post by Gary Hinson, titled "Security awareness: a 'How not to do it' guide":

I spent a few hours at the weekend viewing/listening to a series of presentations to accompany the launch of the Information Security Awareness Forum (ISAF) in London. I won't bore you with all the details right now but one item in particular caught my eye/ear. One of the presenters essentially said that security awareness doesn't work, a somewhat curious point to make in support of a security awareness initiative. Anyway, it's not the first time I've heard the argument and I've been mulling it over ever since. My blood having dropped just below boiling point, it's time to respond.

Today I took one of those "online security awareness" things, and came away with a whole case study on How NOT To Do security awareness. I shan't name the organization concerned because my aim is not to embarrass them in any way, and it really doesn't matter - I'm sure these lessons are equally valid for many other security awareness programs.

. . .

(I cut all of the meat out for the sake of space but it's all pithy observation in support of the title of the post)

. . .

OK OK I'm ranting I know, but the reason is to point out that:
(a) with little investment and even less thought, security awareness can be done really badly;
(b) bad security awareness is unlikely to be effective, and in fact could be counterproductive;
(c) the ineffectiveness of badly designed, constructed and delivered awareness programs says nothing about the potential for well designed, well constructed and effectively delivered programs; and
(d) it really doesn't take a genuis to figure out how to improve security awareness, especially when starting from such a low base. A 20 minute team seminar about information security would have achieved so much more than this hour or two of extreme tedium. Almost ANYTHING else would have been better!

I cannot understand why security awareness seems to be stuck in the mold of once-a-year inform-and-test (I used to call it the "sheep dip" approach to awareness, but subsequently found out that sheep are dipped more often than most employees are made to jump through the awareness hoops!). It's high time for a new approach and some fresh ideas.

OK, that doesn't sound unreasonable, right? He seems certainly in favor of "proper" education and a continuous cycle of verification, yes? Why would I be commenting at all? Well, I'm commenting because years ago, Marcus Ranum noted in a rather pithy commentary titled, "The Six Dumbest Ideas in Computer Security", that (#5 - Educating Users):

"Penetrate and Patch" can be applied to human beings, as well as software, in the form of user education. On the surface of things, the idea of "Educating Users" seems less than dumb: education is always good. On the other hand, like "Penetrate and Patch" if it was going to work, it would have worked by now. There have been numerous interesting studies that indicate that a significant percentage of users will trade their password for a candy bar, and the Anna Kournikova worm showed us that nearly 1/2 of humanity will click on anything purporting to contain nude pictures of semi-famous females. If "Educating Users" is the strategy you plan to embark upon, you should expect to have to "patch" your users every week. That's dumb.

The real question to ask is not "can we educate our users to be better at security?" it is "why do we need to educate our users at all?" In a sense, this is another special case of "Default Permit" - why are users getting executable attachments at all? Why are users expecting to get E-mails from banks where they don't have accounts? Most of the problems that are addressable through user education are self-correcting over time. As a younger generation of workers moves into the workforce, they will come pre-installed with a healthy skepticism about phishing and social engineering.

Dealing with things like attachments and phishing is another case of "Default Permit" - our favorite dumb idea. After all, if you're letting all of your users get attachments in their E-mail you're "Default Permit"ing anything that gets sent to them. A better idea might be to simply quarantine all attachments as they come into the enterprise, delete all the executables outright, and store the few file types you decide are acceptable on a staging server where users can log in with an SSL-enabled browser (requiring a password will quash a lot of worm propagation mechanisms right away) and pull them down. There are freeware tools like MIMEDefang that can be easily harnessed to strip attachments from incoming E-mails, write them to a per-user directory, and replace the attachment in the E-mail message with a URL to the stripped attachment. Why educate your users how to cope with a problem if you can just drive a stake through the problem's heart?

When I was CEO of a small computer security start-up we didn't have a Windows system administrator. All of the employees who wanted to run Windows had to know how to install it and manage it themselves, or they didn't get hired in the first place. My prediction is that in 10 years users that need education will be out of the high-tech workforce entirely, or will be self-training at home in order to stay competitive in the job market. My guess is that this will extend to knowing not to open weird attachments from strangers.

Heh. So there it is. In a previous post, I commented on my previous role as an internal InfoSec consultant to a higher education institution. The way I tried to bridge the gap of parochial or specialized knowledge was this:

A few years ago, I led a team of network security staff at a private New England university. One thing I stressed was collaboration with peer groups, visibility to higher decision-makers and a decidedly NON-jackboot thug approach toward requests and assistance; we were to be in the business of analysis of needs (perceived and actual) and distilling them to appropriate security controls that could best support them. I doubt I was successful in this approach as my group largely functioned without mandate but I still to this day try to keep in mind a message I pushed to my staff and to the groups I met with:

I may not know much about medical imaging or financial aid records or your particular area of expertise in computer science, biology, music, etc. What I do know a bit about is data protection and security. We meet and there is a disconnect between us. What is important to you as a researcher or faculty member? What is important to me as a staff member charged with protecting you and your data?

DNA sequencing, firewalls, intellectual property...all of this reduces to knowing and working with your constituents, addressing their needs, listening to their concerns and presenting a common, organizationally based (re: consistent) to risk management and data protection that the groups you ultimately serve can do so in a consistent manner while (hopefully) taking a risk-based approach to assessment, mitigation and remediation.


Is there any middle ground on the topic of user education, with regard to information security concerns? Is it black or white like Hinson or Ranum argue or is there some middle, moderate ground that could work?

27 April 2008

We Bought A Firewall. Isn't That Good Enough?

I've been reading Jon Udell's print and blog pieces for as long as I can remember. I may not always have a personal interest (this is not the same as having a differing opinion) in some of his topics but when I am interested, I typically find myself in 90+% agreement. He's been blogging about the lack of availability to public - specifically at the local or community level - data in an normalized (or reasonably transformable/convertible) format through standard, programmatic "pulls and pushes" (RSS, SOA, etc.).

While the topic is generally interesting to me, three paragraphs of his post are particularly interesting and germane to the information security and data protection world I play in:

"As I meet with intelligent and well-educated professionals in my community, and talk with them about how to synchronize calendar information from a variety of sources, I realize that they simply have no intuition about the difference between a PDF file and an ICS file that contain the same calendar information. Both are computer files, right? Both can be posted to the web, right? Both can be searched, right? Problem solved.

. . .

These are ways of computational thinking unknown to most people. As a school administrator, librarian, city planner, social worker, or retail store owner, nobody expects you to understand and apply these principles.

And yet almost everybody needs to harmonize personal and organizational calendars. And many individuals and organizations need to flow their calendar data into other contexts to promote and coordinate their activities. "


If you substitute file formats for security controls and calendars for security-related procedures, I feel that the same three paragraphs capture the essence of the reason we still have phishing and spam problems, botnets, etc.: people not involved in "the trade" simply do not have the proper background nor the mindset to think properly about data protection.

Sure, some people and organizations may buy themselves a firewall and antivirus software and may ask, "We just bought a firewall. Isn't that good enough?" The answer, clearly, is "more than likely not." And this should never be presented or perceived as simply a push or a bait-and-switch attempt to push more security products or controls - the need for those elements comes from stated organizational objectives and/or policies and detailed risk analysis where the spend on security and protection controls is aligned with the value of assets being protected.

Who is qualified to make these assessments? How many people or groups are qualified (identification and selection, implementation, on-going maintenance, etc.) to handle major electrical, plumbing or construction work in their home or offices? Bad choices could easily lead to bad happenings, to put it rather simply. Viewed through a similar prism we can ask how many people or groups are qualified to properly assess risk to whatever they're trying to protect or hide or what have you? Same general answer: bad choices easily could lead to bad happenings.

Now, my comments emphasis a specialization or expertise necessary to make intelligent data security and protections decisions. We're all interested in protecting our data or at least assuming the firms we interact with do the same but largely, both cases are not true. On the individual side, a majority or people are willing to share their user IDs and passwords with strangers for a chocolate bar and at the company level, those firms who don't see a drop in stock price (consumer confidence and willingness to spend) often do very little.

This has been a bit of a long-winded way of getting back to Jon Udell's three interesting paragraphs. A few years ago, I led a team of network security staff at a private New England university. One thing I stressed was collaboration with peer groups, visibility to higher decision-makers and a decidedly NON-jackboot thug approach toward requests and assistance; we were to be in the business of analysis of needs (perceived and actual) and distilling them to appropriate security controls that could best support them. I doubt I was successful in this approach as my group largely functioned without mandate but I still to this day try to keep in mind a message I pushed to my staff and to the groups I met with:

I may not know much about medical imaging or financial aid records or your particular area of expertise in computer science, biology, music, etc. What I do know a bit about is data protection and security. We meet and there is a disconnect between us. What is important to you as a researcher or faculty member? What is important to me as a staff member charged with protecting you and your data?

DNA sequencing, firewalls, intellectual property...all of this reduces to knowing and working with your constituents, addressing their needs, listening to their concerns and presenting a common, organizationally based (re: consistent) to risk management and data protection that the groups you ultimately serve can do so in a consistent manner while (hopefully) taking a risk-based approach to assessment, mitigation and remediation.

01 April 2008

Google Gears, Part 1

I didn't quite get Google Gears at first. Do I REALLY need to read my blog feeds offline? As it turns out, Google Docs is getting offline support now.

Do I care? Sort of.

When you consider some other Google properties - Blogger, YouTube, News, Book Search, Picasa - you can see how Gears starts to fit into the Google experience. Working on a blog posting? Do it on the train during your commute, it's stored in the Gears database and automatically posts to Blogger when you get an active net connection. Just capture something newsworthy, Mr. Citizen Photojournalist? Dump it from your camera to your laptop running YouTube offline and the video will be stored in the Gears database until it can sync your content with your YouTube account online. Picasa already has a thick client but there's no reason Picasa web albums could not be connected to Gears for offline work.

Interestingly, these ideas aren't what I care about. It's certainly interesting from a usability point of view and allows for greater permeance of Google in your life (if you think that's a good thing) as well as allowing one to publish their virtual lives out to the Googlesphere from anywhere, connected or not.

What I'm truly in is the security controls that are utilized to protect the Gears database and the general security architecture of Gears and all of the Google properties and tools that are becoming offline-enabled. More to follow after I do some research into this.

22 March 2008

Reading List #7

A recipe for success:


Mix thoroughly in a steampunk bowl with a biblical spoon until "His Dark Materials" forms.

After my previous foray into and completion of Neal Stephenson's Baroque Cycle trilogy, I was thrilled that this trilogy - a virtual trifecta of literary quality - found its way to me.




Enjoy!

04 March 2008

Another Use for Second Life


Historical Maps in Second Life

This is great. I've previously posted about some unexpected consequences SL but I think this one - a San Francisco map collector who set-up his own SL island to display his collection - is a great use of SL that (to me at least) was completely unexpected. From the MIT Technology Review:

"A new installation inside Second Life is bringing alive one of the world's largest collections of antique maps. Called the David Rumsey Maps Island (registration required), the Second Life site is San Francisco map collector David Rumsey's latest high-technology plan to share his collection with as large an audience as possible."

29 February 2008

Google Sites

Google Sites looks to be a SharePoint alternative of sorts.

I'm still trying to figure out where Gears fits into it all.

24 February 2008

Google Central (part 1)

Update: Grand Central has become Google Voice

-----

I feel that I'm turning into some sort of Google-watcher these days or have been a Google junkie without realizing it.

A couple of days ago I found an entertaining video on YouTube (how apropos) of interesting sites and places to visit in Google Earth. I recently posted about new Google search functionality and presentation options. Before that it was a brief look at Google's Android mobile phone platform. Last year I was - and will soon be again - looking at Google Trends as a potential prediction tool for the American Idol contest winner.

This is sort of interesting as it brings a set of old school (Groups - Usenet, Scholar - refereed journals, and Glossary - reference sources) content together with new school (YouTube, Blogger, Google News commentary) together in a jumble of seemingly disparate audiences through Google-branded channels. It clearly extends new school functionality (Web 2.0) into old school mediums (proto-web and Web 1.0) while trying to preserve or normalize the presentation, experience and general consumption of content and services. Through this normalization process, Google is able to preserve/build brand recognition (Google TM) Grand Central, "a production of Google." Their info page asks and answers: "What is GrandCentral? Get all the same calls, but in a whole new way." That's all fine and dandy; it's nothing you can't get from existing, consumer VoIP providers. Their feature set is pretty comprehensive which conceptually place it as a virtual voice communication firewall in some regards.

That's kind of cool but it doesn't seem like a Googlesque sort of venture. Until you add other Google services. Now you have an interesting stack supplying different, but converging on, fully integrated services:

This is only a partial analysis (and none too in-depth, by any means) and doesn't take into account relevant issues, such as Google's wireless 700 MHz spectrum bid, which help with the convergence understanding and visualization. I'll post again as it's sort of fun to be an armchair Google strategist.

22 February 2008

Google Earth Fun

Ten minutes of mostly entertaining Google Earth fun.


Secrets Of Google Earth

The PC World staff have some still shots of some of the highlights as well as a Google Earth placemark file you can download and import to explore on your own.

My Coffee Maker...Seg Faulted???



So it's snowing today and I'm working from home for other reasons. Isn't it nice to enjoy a cup of hot, freshly brewed coffee in the morning. It sure is...until your coffee maker decides to dump core.

Crazy.

I haven't tried it again but if I need a new unit it damned well better be able to receive SNMP traps so I can set it to brew while I'm away.

17 February 2008

Useful Kibble

I've been catching-up on some reading and thought I would simply share three sites/feeds that I find to be truly useful. In no particular order:

  • Lifehacker, "an award-winning, daily blog that features tips, shortcuts, and downloads that help you get things done smarter and more efficiently."
  • Wise Bread "is a community of bloggers here to help you live large on a small budget."
  • Parent Hacks "is a collaborative website that collects and publishes parents’ tips, recommendations, workarounds, and bits of wisdom – their hacks – in a single pot so we can all partake."
  • Geekdad, "tech toys, science projects and other nerdy things to do with your kids."

They may not have ground-breaking news, cutting edge technology reviews or deep, theoretical insights but I always manage to extract some useful kibble from them to apply to my daily existence.

03 February 2008

Great Analysis of the World's Under-Sea Fiber Network


"A flotilla of ships may have been dispatched to reinstate the broken submarine cable that has left the Middle East and India struggling to communicate with the rest of the world, but it took just one vessel to inflict the damage that brought down the internet for millions."

02 February 2008

New Google Search Features

Google has introduced some new search features as experimental through Google Labs. They've added
  • right- and left-handed search navigation
  • keyboard shortcuts for search results
  • keyword suggestions
  • alternate views for search results



  • I like the left-handed search navigation and was playing with the layout and widgets a bit myself last summer when playing with Google's Web Toolkit. eBay has been doing some very similar UI work in its eBay Playground site that I've enjoyed. Amazon tends to overwhelm me at times with JSON this and AJAX that and they can't seem to resist the urge to package the search results and product descriptions to the extreme. I guess this shouldn't surprise me so much as they are a self-billed department store. Netflix, on the other hand, strikes the right balance with me through their consistent and concise detail drill-down through the AJAX essentials, XMLHttpRequest object and javascript onmouseover() event.

    I don't particularly care about keyboard shortcuts and search results. This is a personal inconsistency however as I don't use keyboard shortcuts in Gmail either but almost always use the keyboard to navigate between applications, tabs and the OS in general. Maybe this is my unverbalized position that I just don't like the way Google implemented keyboard shortcuts. Maybe I'm just inconsistent after all.

    The keyword suggestions have been available as a Google Labs offering called Google Suggest for a while and the search bar in Firefox provides JSON-enabled search term suggestions.

    The alternative search results are a great move forward with regard to search result presentation, specifically addressing the need for better contextual-based and grouped/ordered search results. I've written about this previously and was eager for new search primitives to address this perceived shortcoming or at minimum search options that accomplished the same thing.

    At least I'm not alone in liking the latest search presentation options. Ars Technica described it simply as "awesome".

14 January 2008

A Brave, New Semester

2nd semester, 2 more classes:
I'm hoping for a less strenuous semester than last.