Sunday, June 16, 2013

Music for Fathers Day

Dad loved this music.  The "Three Tenors" were the top operatic tenors of their day: Placido Domingo, Jose Carreras, and Luciano Pavarotti who toured together in the 1990s and 2000s.  I'm not sure whether Dad was the one who introduced me to Winston Churchill's quote My tastes are simple: I am easily satisfied with the best, but this covers that.




Happy Father's Day to everyone who is a father, or who has one.

Saturday, June 15, 2013

Sad update

Last month I put up a book review of Sergeant Rex, a bomb sniffing Marine Corps dog in the battle of Fallujah.  When I put up that post I hadn't found the sad news that I must report here.  Rex died last Christmas:
A combat dog known as Sgt. Rex who was finally reunited with his ex-Marine handler in Rockland County last spring has died. The German Shepherd died on Saturday at the age of 11, according to Mike Dowling, author of "Sergeant Rex: The Unbreakable Bond Between A Marine and His Military Working Dog."

Sgt. Rex's handler in Iraq, former Cpl. Megan Leavey, was injured with the pup in 2006 while trying to disarm an explosive. Rex is credited with saving lives and uncovering explosives that saved more. Leavey, a Purple Heart recipient, was first denied in her effort to adopt Rex in 2007 because Rex was returned to service after he and Leavey had recovered from their injuries.

When Rex was retired from the military, he and Leavey gained notoriety because she still faced numerous bureaucratic roadblocks as she tried to adopt him.
The story of Rex's last years is quite a ride.  CPL Megan Leavey was Rex's handler on his second tour, and was wounded (along with Rex) in an IED explosion.  Leavy recovered and ultimately left the Corps and when she heard that Rex was going to be retired she started a letter writing campaign to get custody.  After enlisting Senator Schumer (a loathsome toad normally, but who did stand-up work here) and the owners of the New York Yankees (who paid for Rex's travel and all his vet bills), Leavy got Rex.

Bravo, all around, as it gave Rex the chance to live his final year with his former handler.  As a celebrity:
The New York Yankees honored retired Camp Pendleton combat dog Sgt. Rex and his former handler, retired Marine Cpl. Megan Leavey, before Sunday's game against the Seattle Mariners. Cpl. Leavey, a New York resident, adopted Sgt. Rex in April.




And this is entirely endearing to me, a Red Sox fan:

It turns out Sgt. Rex has something in common with my husband. Neither is a big fan of Alex Rodriguez. According to the Associated Press, Sgt. Rex protectively jumped in front of Leavey when Rodriguez approached her with a gift - a heart-shaped charm from Tiffany & Co with ''Rex'' written on it.
Oohrah, Rex, good dog.  Rest in Peace, Devil Dog.

The diary of a sad dog

Well, mystified.  It must be really hard for them to understand us.



And as to the testicles bit, Wolfgang can confirm this truth:


I will pee on the bed for comfort.

Big swingin' and clankin' brass ones

I don't know who's a tougher SOB, the pilot who took this P-38 down to an altitude of 7 feet or the photographer who took the picture.  Holy cow.


Lower Than A Snake's Belly In A Wagon Rut is a delightful post about very low level flying:


Man, that's some scary stuff.  Like this Jug, which flew so low on a strafing run that its propeller hit the ground.  Bird made it home anyway.  Man, that was one tough plane.


And there's a nice shout out to Peter from Bayou Renaissance Man.  You'll spend a most enjoyable half hour on this.  You're welcome.

Bluegrass Beethoven's Fifth Symphony

I had a fabulous German dinner at Alpharetta's Breadtime Bistro and Provisions, which I think is the best German food I've had on these shores other than Gaithersburg's late, lamented Wurtzburg Haus.  The idea of a German couple could end up far from their native land made me think on the cultural flows around us.  We get great food and drink.

They get Country music.  Well, OK - Bluegrass.  Via Saurkraut Cowboys* we find this gem of cultural diffusion, where a Czech bluegrass group plays Beethoven's Fifth Symphony.  Awesome.



* Sturm, Twang, and the imaginary Wild West in Europe.  Awesome, again.

Friday, June 14, 2013

Dogs of War(gaming)

The Call of Duty videogame franchise is coming out with (yet another) new edition, Ghosts.  One of the new "weapons" is a Military Working Dog.  Wolfgang raises a bark of approbation, but some people think that the selection of dogs is somewhat lacking.



Roger Old Yeller, and the Toto demographic is pretty interesting.  But no SGT Rex?

Via #2 Son, who's pretty wired into Videogaming happenings.

Hiding your data transmissions from the NSA

I guess I should start off with a warning here: it's not at all probable that you really can.  However, people have been pinging me, and I don't like any of the suggestions that I've seen so far.  This is a first cut.

The second warning here is that this is not useful for voice or email protection (mostly), and won't help with GPS geolocation tracking.  It's purely a thought experiment on how to transmit decently large quantities of information without NSA being likely to understand the content, or even that information is likely to be transmitted.

That last point is the key.  Traffic Analysis is pretty terrifying, at least to those in the know, and is by far the biggest issue in the whole NSA brouhaha.  I'm not sure that this solves that problem, but it takes some steps in that direction.  Remember, your mileage may vary, void where prohibited, do not remove tag under penalty of law.

The first thing we need to look at is how to hide data in a way that doesn't make people think that there's hidden data.  XKCD captured the problem for the would-be crypto nerd:


This is actually called the Rubber Hose Attack, and is considered generally effective.  So encrypting your hard disk is A Bad Thing, because it tells anyone who looks that the data is encrypted.  More to the point, encrypting your data communications is A Bad Thing for exactly the same reason.

OK, so no encryption.  How do you keep communications confidential from prying NSA eyes, and ideally make traffic analysis less likely?  This is Borepatch, and so that means that we'll start with a history lesson.

People have been trying to keep secrets secret for pretty much as long as there have been people.  Growing up, there was a pretty interesting book in the Borepatch household library, Hidden Images.  It gave a number of historical examples of how people hid images of things that were considered double plus ungood, typically via distorting perspective or some such.


This was a picture of (IIRC) English King Charles I who had been beheaded by Parliament.  It was dangerous for people to have images of the dead King, and so you had to use a reflective cylinder to make the distorted image of the Sovereign comprehensible.  The problem is that you need the cylinder, and you have a pretty suspicious distorted picture.  Either of these if discovered in a search might result in a Rubber Hose Attack.  We'd like to have our data in a normal image (I'll get to how to hide the "cylinder" in a bit).

There's a modern tool available to do this, called Steganography.  It relies on the fact that many of the data formats in comm use today are "lossy" - you can remove a lot of the original data bits without degrading the original message.  Jpeg image format is one example, MP3 is another.  Stego uses this to introduce loss into the picture without degrading the picture (or into an MP3 without degrading the audio).  The "loss" introduced is your secret message, which can be text, image, audio, or whatever you'd like.  I did this once here:


Crash the Wundercat contains a secret message (well, the picture of Crash does; work with me here).  You need a tool that does Stego to embed the message/data, and the person who wants to extract the message/data needs a Stego tool.  I like OpenPuff (even though it's Windows only) which will embed your data in images, audio, video, and Flash.  It will even encrypt the data and add white noise to make it even harder to detect.  It's free and open source.  Steghide is perhaps your best bet for Linux.



And now we have to peel the onion: how do you get your message distributed?  The answer here is to use your regular methods.  I don't like email, as it's pretty direct (you sent it to someone, which is interesting in an of itself).  Social Media is a much bigger haystack to hide in - Facebook, blogs (hello!), Reddit, Flickr - all of these excel as "dead drop" locations for seemingly innocuous pictures of your cat.  The people you want to read your secret message have to know what password you're using in your stego, but there are a lot of ways to do that - for example, everyone has a copy of Gibbon's Decline and Fall of the Roman Empire and uses the 11th word on the page as the password.  Each day, use the next page.

Sure, NSA will see that people are looking at Reddit, but it's an extra layer of indirection that they're looking at what you posted to Reddit.  It's potentially a very large haystack.

Also, you should see why this isn't any good for voice communications, and why it's not ideal (or likely desirable) for email.  And now to the last layer of the onion - reducing the chance of a rubber hose attack.

Remember the mirrored cylinder that was used to view the picture of King Charles?  That was a give away.  Well, so are steganography tools.  If it comes to an investigation and someone finds that you've, say, installed the Ubuntu version of Steghide, there will likely be a lot of questions.  So how do you hide your stego tools?  I think that the best way is via the Purloined Letter approach - hide them in plain sight.

This is a USB drive.  It will hold a ton of data.  Unfortunately, everyone knows that it's a USB drive, including Mr. Fed.  Should the day come where The Man swoops down to investigate your electronic breadcrumbs, they'll look for stuff like this.  What we want are the electronic guts of the drive, in an innocent looking exterior.  Maybe something like this:


This is a Lego toy.  Actually, it was a Lego toy until someone took a box cutter, dremel, and some manual labor to cut it open and embed a USB drive in it:


You can have a whole Operating System with Stego tools on it.  Boot from it when you need to encode/decode, copy the resulting image/MP3/etc to a different (maybe disposable) USB drive to load onto your regular computer for posting to Reddit/etc.  Just keep it with a bunch of other similar figurines in a bucket of toys in the basement.


Or you could just buy a Lego brick USB drive.  Remember to keep it with your other Lego.


Now it's important to point out here that nothing is foolproof.  NSA will be collecting traffic data showing that you're uploading to Reddit and Facebook.  They will see that other people check Facebook and Reddit.  They will build maps of relationships - who knows who.  Someone might take a look at your facebook page.  If they really want to spend the time with the right people analyzing your pictures (or podcasts, or youtube vids) they might very well sniff something fishy. But they'll have to work a lot harder, and the work will be less automated.

And this will give you a close to "Professional Grade" level of paranoia which is a Very Good Thing.  If I seem that way myself, please remember that I was trained to be that way by the finest minds in the Free World.

Snowden smuggled the classified documents out of NSA on a Flash Drive

Not particularly surprising:
Whistleblower Edward Snowden apparently used a USB thumb-drive to smuggle out hundreds of top-secret documents before he blew the lid off the NSA's web-spying project PRISM. This is despite the Pentagon's clampdown on the gadgets.

...

Computer usage at the National Security Agency is tightly controlled. But Snowden was a systems administrator employed by contractor Booz Allan Hamilton to maintain the spooks' network, and thus had sufficient privileges to use flash drives as part of his job.
This is the intersection of easy-to-conceal and critical-for-system-administration is a Catch-22 that won't go away.  Actually, it's worse than that, because users resist security measures that keep them from doing things they want to.  I wrote about that four and a half years ago in How to hack a classified network (currently top Google result for "hack classified network", out of 3 million results).

A Gun Control "hmmmm"

OK, so the EEOC has just issued a rule that it's illegal for an employer to refuse to hire someone simply because they are convicted felons. They say that policies like this are discriminatory because larger numbers are minorities. The EEOC says that this results in "disparate impact" and is presumed to be discrimination.

This seems ridiculous on its face, but let's consider the Second Amendment implications. Felons are prohibited from possessing firearms.

According to the EEOC, this is presumed to be racial discrimination. It would be interesting to see a class action lawsuit on these grounds.

Thursday, June 13, 2013

Power is out

A big storm rolled through and the power is out all over. Lots of trees down - Georgia 400 into Atlanta is blocked by a downed tree. Georgia Power says that 150,000 people don't have power.

Including us. But the storm blew over.




But Sonic is open, so #2 Son has something to eat. Power isn't out everywhere.

- Posted using BlogPress from my iPhone

Lazy summer evening

Wolfgang rescues a stick from the raging flood.




- Posted using BlogPress from my iPhone

Location:Vickery Creek, Roswell GA

Photo history of the NSA

I'm surprised that there's this much stuff out there.  And I can neither confirm nor deny this:


A little before my time, but not too much.  And I'd never heard about the "Miss NSA" pageant.

(via)

The Bank of England is staffed by fools

While this sort of thing would certainly be good business for me personally, color me skeptical:
Hacking attacks present a bigger risk to the operation of UK banks than problems caused by the ongoing eurozone crisis, according to a senior Bank of England director.

Andrew Haldane, the BoE's director of financial stability, told parliament's Treasury Select Committee that representatives of Britain's top banks are telling him that cyber attacks have become their biggest threat over recent months.
Hackers can melt down the banking system?  Really?  Instead of this?
And while the vast majority of readers may be left with the impression that JPMorgan's mindboggling $69.5 trillion in gross notional derivative exposure as of Q4 2012 may be the largest in the world, they would be surprised to learn that that is not the case. In fact, the bank with the single largest derivative exposure is not located in the US at all, but in the heart of Europe, and its name, as some may have guessed by now, is Deutsche Bank.

The amount in question? €55,605,039,000,000. Which, converted into USD at the current EURUSD exchange rate amounts to $72,842,601,090,000....  Or roughly $2 trillion more than JPMorgan's.
Emphasis in the original.  From where I sit, it looks like the financial risks of European insolvency are roughly a million times greater than the financial risks from hackers.  And there's a simple solution to that - the financial sector could simply increase the amount that they spend on computer security by $1 B, and they would suddenly be much, much better funded than the Bad Guys.  A Billion is a lot of money, but compared to 70 Trillion it's the change collected from under the cushions.

I wonder what color the sky is, over on Planet BoE.

When memes collide

Awesome.













Yo, NSA Dawg!  Heh.

Wednesday, June 12, 2013

Corporate reputations are crumbling

Good.


Damn, the NSA spying scandal just got real


I mean, who doesn't?

There's no hiding the decline

2cents emails to point out that Faith is being questioned even in the halls of the New York Times:
The rise in the surface temperature of earth has been markedly slower over the last 15 years than in the 20 years before that. And that lull in warming has occurred even as greenhouse gases have accumulated in the atmosphere at a record pace.

The rise in the surface temperature of earth has been markedly slower over the last 15 years than in the 20 years before that. And that lull in warming has occurred even as greenhouse gases have accumulated in the atmosphere at a record pace. The slowdown is a bit of a mystery to climate scientists.

True, the basic theory that predicts a warming of the planet in response to human emissions does not suggest that warming should be smooth and continuous. To the contrary, in a climate system still dominated by natural variability, there is every reason to think the warming will proceed in fits and starts. But given how much is riding on the scientific forecast, the practitioners of climate science would like to understand exactly what is going on. They admit that they do not, even though some potential mechanisms of the slowdown have been suggested.
This is rank denialism of the worst kind.  Everyone knows that the Science is Settled™.

And so there's a bit of a panic in the Orthodox Science Community.  The models have predicted warming, and we're not seeing it.  The discussion is always around Carbon Dioxide, which quite frankly is there to fool the rubes.  Even the Scientific Establishment will admit that you just don't get much warming from a doubling of CO2.  The real threat, we're told, is from Water Vapor and positive feedbacks: more CO2 gives a little warming, which causes more water vapor, which causes more warming, which causes more water vapor, and so THERMAGEDDON!!!111!eleventy!!

The whole Catastrophic Anthropogenic Global Warming idea is a wet firecracker without this.  The models all include "forcings" due to this positive feedback from water vapor.  It's all very computer source codeish and everything.  Science!

Err, except science is based not on models, but on experiment and especially experiments that validate earlier experiments.  So is there a way to look at water vapor and temperature?  Well, yeah:
If we pick areas of about the same latitude, we can say they are getting about the same sunshine. What varies is how much water vapor is in the arriving air. IMHO, this gives us an “existence proof” of “water vapor feedback”. Looking more north means less sun, more south more sun; so we would expect a “bit north” compared to a “bit south” to give the bias toward a cooler north and warmer south. (That can be seen on the East Coast as a temperature gradient from Main to Florida)

What happens to the dry air when it has sunshine vs the wet air when it gets sunshine? Which one heats up more?

Even a casual inspection of the map shows that the entire dry desert band, from inland Washington state (they have a bit of desert behind their mountains) all the way on down through Nevada ( nice high desert there) and Utah ( I reached 8000 Ft plus elevation at one point) and on into West Texas (known for Mesquite and BBQ using same ;-) are all quite hot. 84 F to 108 F. Now, if “water vapor feedback” is a positive value, we would expect that areas more south, at lower elevations, with even MORE sunshine, would be even hotter.

I can tell you that for most of today in Orlando, the humidity was 100%. It started off very sunny, and was quite hot at noon. A strong tropical (or near tropical) sun. I was out in it. Observing it. Then it clouded up, and began to rain. The formation of tropical thunderstorms is characteristic of hot summer days. They are welcome as they cause a rapid plunge of temperatures. (As I’m typing this, it’s 11 pm and I’m feeling a bit of ‘chill’ from the cool. I’m on the patio again.) Tomorrow morning will be sunny, and then it will get humid and “hot”, and then the rain will come again. Now look at the map.

The midwest is known for humidity, as is Farm Country. Iowa corn puts a lot of water into the air, and I’ve taken a shower in Iowa only to towel off and still be soaking wet as the humidity condenses. Anyone who has been on the Gulf Coast on a sunny day can tell you that 90 F and 99% humidity is brutal. Now look at that map. The high humidity areas are in the 60 F to 70s F range, getting up to 82 F in the far southern tip of Florida. Looking back to the West Coast, it is hot inland where it is dry, but look at the edge of the water. You can see the low and cold coastal temperatures where the cold air comes in from over the water with humidity in it. Then it warms inland where it is dry.

More water vapor makes for colder air temperatures. NOT warmer.
This is quite an interesting post, which basically is an introduction to how water vapor is a conveyor of heat.  The weakness, as the Climate Science Establishment will point out, is that Greenhouse Gas theory says that warming occurs not on the surface, but at high altitude in the Troposphere.  Localized hot (or cold) regions will be all jumbled up together at high altitude, and the heat will then migrate downwards across the whole globe. 
The absorbed energy warms the surface. Simple presentations of the greenhouse effect, such as the idealized greenhouse model, show this heat being lost as thermal radiation. The reality is more complex: the atmosphere near the surface is largely opaque to thermal radiation (with important exceptions for "window" bands), and most heat loss from the surface is by sensible heat and latent heat transport. Radiative energy losses become increasingly important higher in the atmosphere largely because of the decreasing concentration of water vapor, an important greenhouse gas. It is more realistic to think of the greenhouse effect as applying to a "surface" in the mid-troposphere, which is effectively coupled to the surface by a lapse rate.
In other words (they claim), it's Global Warming, not Local Warming.

OK, then.  Here's what it looks like when the goalposts are moved.  A picture is worth a thousand words:

The mass of squiggly lines are the model predictions (73 different models).  The black line is the average of the model predictions.  These show what you've heard over and over - that things are warming up because of CO2 and positive feedback from water vapor.

But look at the blue and green dots.  These are the averages of the satellite and the weather balloon data sets, and these are experimental data recordings, not computer model predictions.  Further, the readings were not taken at ground level, but rather in the Troposphere - you know, that place where Global Warming is supposed be hanging with its homies.  Greenhouse Gas theory needs a "hot" spot in the Troposphere to cycle warming back down to the lower atmosphere, because otherwise it will likely just escape to space and in any case won't effect the climate.

So what does the Climate Establishment say to the newly minted deniers at the NYT?  Their picture looks like this:

Even they're just hanging on my their fingers, but at least they manage to show that the observed data barely within the model projections.  But if you listen, you hear the sound of the goal posts moving:
The period covered in the [second] graph is a decade shorter than that covered by the Spencer-Christy graph and looks suspiciously like cherry-picking.  By starting their graph in 1990, SS can use the Mt. Pinatubo-induced cold period of 1992-93 to tilt the trend to be more positive. The Spencer-Christy graph begins at the start of the satellite record — 1979 — providing a longer and more representative period.

More importantly, SS uses global surface temperature datasets, which do not accurately represent heat content in the bulk atmosphere. In contrast, Spencer and Christy use temperature data from the tropical troposphere — the place where the models project the strongest, least ambiguous, greenhouse warming signal.
If you're going to use surface temperature, why not go back to our original thought experiment that we opened this post with?  Ah, but it's the Troposphere that counts, right?  Then why not show the Troposphere temperatures?

At this point what usually happens is that "rational discourse" breaks out, with accusations of Beastly Denierdom and you're-not-peer-reviewed and the like.  What's interesting is that these "arguments" are not even convincing the New York Times.  It's been quite a rapid change from the monolithic view in the Press to, well, skepticism just in 3 or 4 short years.

If you use Internet Explorer, you need to update

June's Patch Tuesday includes a critical fix for IE that covers all versions of IE on all versions of Windows.  That's just the sort of broad-based vulnerability that the Bad Guys will look for - "write once, pwn everywhere":
The IE update (MS13-047) grapples with 19 vulnerabilities and covers all versions of IE, from IE6 to IE10, on all supported versions of Windows, from XP to RT. It's just the sort of thing that might be latched onto by hackers as part of drive-by-download attacks, based on malicious scripts on compromised websites, and therefore needs to be patched sooner rather than later.
Details are posted on Microsoft's web site.  Microsoft (and I) recommend that you have Windows Update enabled, which will download these automagically each month.

I also recommend (although Microsoft does not) that you look at using Firefox or Chrome browsers.  Internet Explorer's security is a lot better than it used to be, but there's still quite a lot of legacy security fail built into it (*cough* ActiveX *cough*) that isn't in the other browsers.  The Opera browser is also pretty good.

NSA-apalooza

David Brooks is caught admiring the perfectly creased trousers of the NSA:
Edward Snowden isn't the betrayer.  The betrayers are the Bush administration, the Obama administration, the NSA, and the Congress.  For Brooks to claim, with a straight faith, that it is Snowden who betrayed his oaths and the Constitution, that is is Edward Snowden who "betrayed the privacy of us all" when he exposed the NSA's lawless domestic spying program, is to tell a far bigger lie than Joseph Goebbels ever told.
And Charles Krauthammer is an idiot, too.

Lawrence Person fisks Obama's NSA defense.

The NSA has lousy Marketing instincts.  Naming a program "Boundless Informant" sounds both juvenile and creepy, especially when they're spying on us more than they are spying on Russia.

Bruce Schneier: What we don't know about the NSA spying is even scarier than what we do know.

German politician: Boy, this NSA thing sure looks like the Stasi.

FISA Court: You know, this NSA spying is unconstitutional.  NSA: shaddup.

EU Justice Minister to Eric Holder: I thought you wanted to be more like us.  WTF?

The statistics of "You don't have to worry if you have nothing to hide":
One problem with the nothing-to-hide argument is that it assumes innocent people will be exonerated certainly and effortlessly. That is, it assumes that there are no errors, or if there are, they are resolved quickly and easily.

Suppose the probability of a correctly analyzing an email or phone call is not 100% but 99.99%. In other words, there’s one chance in 10,000 of an innocent message being incriminating. Imagine authorities analyzing one message each from 300,000,000 people, roughly the population of the United States. Then around 30,000 innocent people will have some ‘splaining to do. They will have to interrupt their dinner to answer questions from an agent knocking on their door, or maybe they’ll spend a few weeks in custody. If the legal system is 99.99% reliable, then three of them will go to prison.
Ah, but that assumes that the Government Agency is motivated to catch terrorists, rather than to make sure that next year's budget is bigger.  Those 3 convictions will show that "the system is working".

Tuesday, June 11, 2013

You know, I sort of feel sorry for all those NSA employees

Someone has to listen in on all those Verizon calls [language warning]:



No wonder they want computers to do this.  It's inhumane.