Wednesday, January 15, 2014

Lots of security patches for you

Yesterday saw a bumper crop of security patches from Microsoft, Adobe, and Oracle (Java).  Since of most of all y'all use these, you'll want to top up your security.  Remember, it's like changing the oil in your car - you can put it off, but if you put it off too long then bad things happen to you.

Windows is easiest.  Take Internet Explorer (you need it for this but shouldn't use it for anything else) to http:windowsupdate.microsoft.com.  Simples.  It's a once a month security oil change.

Adobe has important updates to Flash, which drives most video and a ton of ads.  The biggest risk you'll face is malware coming via ads, so go get the update.  Be careful with the update - Adobe packages a bunch of stuff with the patch (like McAfee's horrible Security Scan - not recommended), so pay attention and uncheck the bloatware options.  You'll probably have to install twice - once for the OS and once for your browser.

Adobe also has an update for Reader (the thing you use to read PDF files) that you want to get.  Malware has been embedded in PDFs for several years, so this is a credible threat vector.  Unfortunately, there's no good way to hotlink directly to the update, so go here and search for Reader.

Java has been a sucking chest wound of security fail for a while, and this month is no exception - there are 36 security updates (!).  If you haven't disabled Java in your browser (recommended) then you'll need the update because the Bad Guys are actively exploiting this.  The easiest way to get the update is via the Java Console. - just remember that this will also automatically include crapware (the Ask Toolbar), so make sure you uncheck the crapware boxes.

I will leave for another day the rant about using critical security updates to fob off bloatware on an unsuspecting public ...

Ooh rah, pup!

Sir, Yes Sir!

Sit!  Good dog.

Tuesday, January 14, 2014

The rise and fall of Rome, year by year

Shown as a video.


Err, she rides a metric motorcycle?

I have absolutely no idea what this is, except it looks like she's going out for a ride.


No doubt one of my young gentlemen readers can enlighten me in the comments.

Dwight Eisenhower never served in combat?

Filed under "Things I did not know":
No, Eisenhower had a bad knee from a sports injury.  It initially relegated him to various staff jobs. At which he proved so remarkably competent that the military decided he could not be spared.  There were already plenty of brash young officers willing to charge into the barbed wire. (Three members of the 1915 class died "over there" all as Majors, but one seems to have succumbed to influenza).

I suppose my general theme regarding Presidents is that prior executive success predicts later competence.  And in this respect Eisenhower is a prime exhibit.  Our history is the better for him not stepping in front of a bit of shrapnel in 1918.  He continued to demonstrate the ability to both organize the things under his direct purview and to interact well with those whose independent interests could either help or hinder his tasks.  D-Day in 1944, one of history's biggest organizational challenges was his Supreme accomplishment.

Some people are just better executives than others.  And it is not just a matter of pure intellect.  If you want an example of just how far academic achievement "won't" take you, consider the man who graduated 1st in "The Class the Stars Fell On" [Eisenhower's class at West Point].  It was a certain William E. R. Covell.
Gen. Covell's accomplishments (such as they are) are detailed in this very interesting post.  RTWT.

On the moral superiority of a free economic system

Milton Friedman answers a dumb question with grace and humor, and absolutely obliterates the question.


Monday, January 13, 2014

George Benson - On Broadway

Incredible jazz guitar.


Epic prom picture is epic


JayG, take note.

Our energy infrastructure has Swiss cheese security

I've been posting for something like 4 years that the security of industrial control systems (SCADA) that run our energy and other infrastructure is lousy.  Here's the latest:
Researchers have found vulnerabilities in industrial control systems that they say grant full control of systems running energy, chemical and transportation systems.

The vulnerabilities were discovered by Russian researchers who over the last year probed popular and high-end ICS and supervisory control and data acquisition (SCADA) systems used to control everything from home solar panel installations to critical national infrastructure.

Positive Research chief technology officer Sergey Gordeychik and consultant Gleb Gritsai detailed vulnerabilities in Siemens WinCC software which was used in industrial control systems including Iran's Natanz nuclear plant that was targeted by the US Stuxnet program.

"We don’t have big experience in nuclear industry, but for energy, oil and gas, chemical and transportation sectors during our assessments project we demonstrated to owners how to get full control [of] industrial infrastructure with all the attendant risks," Gordeychik told SC Magazine.
The bad news?  You can make a big boom taking over a refinery.  The good news?  The industry may actually be paying attention now ("we demonstrated to owners ...").

It would actually be a good thing if the NSA monitored these systems.  Do the Country a favor, NSA - focus on an actual threat (i.e. not us).

The futility of the Surveillance State

Quit throwing 9/11 in our faces:
This letter makes me sick at heart. The very people who were supposed to defend our country, who even now parade onto talk shows and give interviews about the NSA scandal like people of authority, stand revealed as corrupt and depraved.

They failed to prevent 9/11. Perhaps even then the volume of data was so great that they simply didn’t notice, or were unable to integrate, the information they had. But they should have been able to learn from their failure, and instead, they covered it up, and their cover-ups and their lies have cost many thousands more lives.

Michael Hayden, Dick Cheney, Robert Mueller, and all the people who have made it so easy for the NSA to lie to us for so long, shame on all of you.

Let me explain. No, there is too much. Let me sum up.
It's a damning indictment, if it's true.  Even without this, it's clear from the NSA's own admissions that they have not stopped any terror attacks (let alone the 56 they originally claimed).  They knew about Maj. Hassan emailing with Jihadi imams in Yemen, and did nothing.  The Russians told us that the soon-to-be Boston bombers were going to Jihadi summer camp in Chechnya, and the NSA did nothing.

Other than to collect all the data they could on you, I mean.

If this is true, it shows the entire bankruptcy of the "we need you to give up freedoms so we can protect you".  Is it true?  I don't know.  But I'm not inclined to put much store in denials from Ft. Meade these days.

Sunday, January 12, 2014

World War II in Europe, day by day

Via Comrade Misfit (you do read her every day, don't you?) comes this very interesting view of the ETO: a day by day map showing each side's gains and losses.  It really highlights just how disastrous July and August 1944 were for the Reich.



Spasibo, tovarich!

Why I love the South

Today's weather: sunny, with a chance of motorcycles.

It's January.

Singalong to Ludwig van Beethoven - Symphony No. 9 "Ode To Joy"

Yes, you.  Don't tell me that you've never wanted to do this.  Turn up the volume, get a cup of coffee, and shake the rafters.



Practice this, and practice it again, until you can sing it from memory auf Deutsch.  Because then you'll be prepared for an Ode To Joy flash mob when you're vacationing in Italy.



You're welcome.  Don't forget to turn the volume up.

Saturday, January 11, 2014

Mary Chapin Carpenter - What You Didn't Say

Nobody sings sad like Mary.  Except maybe Emmylou.


The decline of the West

When did we go from this:


(that's Frank Sinatra getting out of a damn helicopter carrying a damn drink)

To this:


That's some singing punk.  Does he have a helicopter?  Is he old enough to drink?

Bah.  Time to reassess the state of the Res Publica ...


The hour arrives when the mind is ripened

I took Wolfgang for a long walk in the woods.

We went past a small gully that has always been there but which has never been notable.  Last nights torrential rain transformed the place.


There, but never seen until today.
Our eyes are holden that we cannot see things that stare us in the face, until the hour arrives when the mind is ripened; then we behold them, and the time when we saw them not is like a dream. 
- Ralph Waldo Emerson

Ack!

Ack! Ack! Ack!
JETPLOW
(TS//SI//REL) JETPLOW is a firmware persistence implant for Cisco PIX Series and ASA (Adaptive Security Appliance) firewalls. It persists DNT's BANANAGLEE software implant. JETPLOW also has a persistent back-door capability.

(TS//SI//REL) JETPLOW is a firmware persistence implant for Cisco PIX Series and ASA (Adaptive Security Appliance) firewalls. It persists DNT's BANANAGLEE software implant and modifies the Cisco firewall's operating system (OS) at boot time. If BANANAGLEE support is not available for the booting operating system, it can install a Persistent Backdoor (PDB) designed to work with BANANAGLEE'S communications structure, so that full access can be reacquired at a later time. JETPLOW works on Cisco's 500-series PIX firewalls, as well as most ASA firewalls (5505, 5510, 5520, 5540, 5550).
PIX and ASA are probably the most popular firewalls in the world.  These aren't the "firewall" in your cable modem, these are high end professional grade firewalls that go through regular security testing during the development and test cycles (note: I have personal knowledge of this).

Subverting your firewall is probably the worst thing that someone can do to you, security-wise.  Now that this is common knowledge, everyone is at risk - not just from the NSA, but from the Bad Guys who will be reverse engineering this exploit as we speak.

The NSA is making us all much, much less safe.  It's starting to look to me like they're willing to burn the Internet to the water line in pursuit of their Uber Surveillance State.

Via Bruce Schneier  where this comment in particular is very interesting:
Many stories from Der Spiegel over the last eight months; all talkie talk, minimal docs. Suddenly the epochal batch we're looking at now. Pointedly not attributed to Snowden. Following hard upon the German delegation getting the middle finger from Ft. Meade when they asked for Five Eyes no-spy status. Der Spiegel is, shall we say, close to the German government. So blowback maybe happening, but back channel, not how you might think.
I don't think I've ever seen a Charlie Foxtrot this massive.

Billy Joe Shaver - I Been To Georgia On A Fast Train

Image via La Wik
Sometimes the luck of the minute leads to a lifetime.  Billy Joe Shaver lived the life that many young men did, back in post war America.  He served in the Navy, then worked odd jobs, and tried his hand at being a rodeo cowboy.  Nothing clicked.  He lost two fingers in a lumber mill accident, and had to relearn how to play the guitar.

Finally throwing in the towel in Texas, he decided to hitchhike to Los Angeles, but coudn't get a ride headed west.  Instead, he found rides to Nashville where he got a job writing songs.  Waylon Nelson noticed him, and if you've ever listened to Honky Tonk Heros, you've heard Shaver's songs.  There's actually not much else on that album.  It's fair to say that you don't understand Outlaw Country if you don't know Shaver. He may not have sold a lot of albums, but even Elvis recorded his songs. 

Willie Nelson and Charlie Daniels (among others) sang backup on his records.  There's a debate about what the real Country Music is, and while that discussion can get tiresome, there's a case to be made that Billie Joe Shaver didn't just write the purest Country Music, but he lived it.



I Been To Georgia On A Fast Train  (Songwriter: Billie Joe Shaver)
On a rainy, windy morning that's the day that I was born on
In the old sharecroppers one room country shack
They say my mammy left me, same day that she had me
Said she hit the road and never once looked back

And I just thought I'd mention, my Grandma's old age pension
Is the reason why I'm standing here today
I got all my country learning, living and a churning
Pickin' cotton, rasin' hell, and bailin' hay

I've been to Georgia on a fast train honey
I wudn't born no yestday
Got a good Christian raisin' and an eighth grade education
Ain't no need in y'all a treatin' me this way

And now sweet Caroline, I don't guess I'll ever find
Another woman put together like you all
With your wiggle and your walkin', and your big city talkin'
Your brand new shiny Plymouth rag-top car

Yeah it's hurry up and wait, in this world of give and take
Seems like haste makes for waste every time
And I pray to my soul, when you hear those ages roll
You better know I'm gonna get my share of mine

I've been to Georgia on a fast train honey
I wudn't born no yestday
Got a good Christian raisin' and an eighth grade education
Ain't no need in y'all a treatin' me this way

I've been to Georgia on a fast train honey
I wudn't born no yestday
Got a good Christian raisin' and an eighth grade education
Ain't no need in y'all a treatin' me this way

Friday, January 10, 2014

Wiped out

I literally cannot keep my eyes open.  Going to bed,

IETF refuses to remove NSA employee from crypto task force chair

Damn:
An NSA employee who is the co-chairman of a cryptography working group affiliated with the IETF will remain in that position despite calls from members to have him removed. The chairman of the Internet Research Task Force, the body that oversees the research group, rejected requests for the removal of Kevin Igoe of the NSA, saying that his position gave him little real power over the development of cryptographic standards and his removal would set a dangerous precedent.

The request for Igoe’s removal came on Dec. 20, in the aftermath of a fresh set of revelations about the NSA’s surveillance capabilities and efforts to undermine the development of cryptographic standards and algorithms. Throughout autumn, waves of stories about the agency’s  attempts–and perhaps successes–to compromise crypto standards had hit the news, including the allegation that the NSA had deliberately weakened a key NIST standard by inserting the compromised Dual_EC DRBG random number generator as the default choice. Security researchers and cryptographers assessing the damage of these revelations said that the implications may not be known for years to come.

...

On Jan. 5, Lars Eggert, chairman of the IRTF, formally rejected the request to remove Igoe, saying that his employment by the NSA should not disqualify him out of hand, and that his actions in the Dragonfly development process could have been seen as mistakes, but were not enough to support the idea that he was purposely subverting the process.
The next step is for other people to resign in protest.  I don't get the sense that this is over.