Wednesday, January 25, 2017

Encryption backdoors are still a bad idea

It was a bad idea under the Obama administration, and it's still a bad idea:
US President Donald Trump's pick for his Attorney General and head of the FBI will have security specialists nervous, since both believe breaking encryption is a good idea. 
Senator Jefferson Beauregard "Jeff" Sessions III (R‑AL) is Trump's pick for the top legal job in the US. In congressional testimony, he outed himself as a committed backdoor man when it comes to encryption. In the written testimony [PDF] to Senator Patrick Leahy, (D‑VT) he laid out his position. 
"Encryption serves many valuable and important purposes," Sessions wrote. "It is also critical, however, that national security and criminal investigators be able to overcome encryption, under lawful authority, when necessary to the furtherance of national security and criminal investigations." 
That's going to be bad news for people who favor strong encryption. The finest minds in cryptography have repeatedly pointed out the impossibility of building a backdoor for law enforcement into secure encryption, since there's no way to stop others from finding and exploiting the Feds-only access.
The Federales have been pushing for crypto backdoors since the early 1990s (remember the Clipper chip?) and it has always floundered on the rock of "there's no way to keep the bad guys from learning the backdoor".



The choice for the Fed.Gov is this:  live with crypto that they can't (easily) break, or destroy encryption (and the Internet economy that depends on it).

I know that they want a backdoor that only they know about.  I want a unicorn that farts 93 octane into my gas tank.  And remember: they would ask us in the security community to trust them after the Snowden revelations showing how we can't trust them.

Tuesday, January 24, 2017

Another passes

Another World War II veteran joins the final muster:
During World War II, Lt. Col Masters flew 28 B-17 bombing missions and 25 fighter scout missions, in which he flew a P-51 fighter plane to scout targets for bombers. He flew for the 551st Squadron of the 8th Army Air Corps and the 385th Bomb Group. He reached the rank of lieutenant colonel and was awarded numerous medals for his service in the war which include the Distinguished Flying Cross, Silver Star, and the French Legion of Honor medal. 

After the war, he returned to his native California and entered medical school at Stanford University. Dr. Masters moved to Athens in the early 1970’s and helped form the women’s clinic at UGA. He retired from UGA in the mid 1990’s and then continued to work part time for the nest 10 years for the Clark County Health Department.
That's quite a man.  Rest in peace.

Monday, January 23, 2017

Day out

I went to Antietam National Battlefield yesterday.  It was America's single bloodiest day, and a lot of that was here.


There's quite a nice (but small) museum, and the battlefield is small enough to walk.  I hadn't realized just how close it is to the Potomac river and Harper's Ferry.  This is definitely worth a detour if you're in the Washington D.C. area.

Sunday, January 22, 2017

OK, now that's just funny


I guess that's what they call a "Rebel Alliance" ...

John Philip Sousa - Presidential Polonaise

Chester Arthur didn't much care for "Hail To The Chief" and so asked Sousa to write a replacement.  This is what he came up with in 1886 - it is said that it was intentionally upbeat to keep people moving in the White House reception line.

But Hail To The Chief was traditional - dating to the 1820s in its use for the President - and so Sousa's replacement was soon gone.

Friday, January 20, 2017

Ray Charles - America The Beautiful

The Mormon Tabernacle Choir sang this today, but nobody does it like Ray did.



"Biker for Trump" attacked by rioter

Stay classy, Progressives.


Remember how people were talking about "violent Trump supporters" and how everyone who supported him was part of that?  Well, you made the rules, jerks.

Souvenirs, marked down

Drastically marked down.

Thursday, January 19, 2017

Quote Of The Day: Class Warfare edition

The Archdruid is simply on fire lately.  Today he gives a Field Guide to Trump opponents:
As Donald Trump becomes the forty-fifth president of the United States and begins to push the agenda that got him into the White House, it may be useful to have a convenient way to sort through the mix of signals and noise from the opposition. When you hear people raising reasoned objections to Trump’s policies and appointments, odds are that you’re listening to the sort of thoughtful dissent that’s essential to any semblance of democracy, and it may be worth taking seriously. When you hear people criticizing Trump and his appointees for doing the same thing his rivals would have done, or his predecessors did, odds are that you’re getting the normal hypocrisy of partisan politics, and you can roll your eyes and stroll on. 

But when you hear people shrieking that Donald Trump is the illegitimate result of a one-night stand between Ming the Merciless and Cruella de Vil, that he cackles in Russian while barbecuing babies on a bonfire, that everyone who voted for him must be a card-carrying Nazi who hates the human race, or whatever other bit of over-the-top hate speech happens to be fashionable among the chattering classes at the moment—why, then, dear reader, you’re hearing a phenomenon as omnipresent and unmentionable in today’s America as sex was in Victorian England. You’re hearing the voice of class bigotry: the hate that dare not speak its name.
This is a (typically) long and thoughtful exposition of class bigotry as currently practiced in the "classless" US of A.  Highly recommended.

Rule 2 violation

It applies to Light Sabers too.


Wednesday, January 18, 2017

The problems with Technocracy

Well, one of the problems:
For those who are unfamiliar with the term, technocracy is, in essence, rule by technical elites. For instance, your media would be run by trained, credentialed journalism experts. Politicians would be groomed and educated to be leaders from an early age. You could not, for instance, be President if you did not attend the proper schools, earn the proper certifications, and demonstrate a certain set of requirements, like IQ, or perhaps an impressive set of grades in your debating classes.
Climate scientists would run the departments dealing with weather and climate change. Rocket scientists would own NASA, and determine how it should be funded in consultation with the banking experts. The bankers, of course, would run the monetary system and determine appropriate levels of taxation and redistribution.
... 
Naturally, none of these technical elites would need to consult with you and I on these matters. If you are not one of the elite, you would need to be quiet and accept the rulings of your superiors.
The flaws in technocracy are very obvious, to any who care to see them. First and foremost is the matter of trust. Even if we were to concede that the trained, technically-minded elites were better than the hoi polloi, how could one be assured that they were not pulling the wool over the people and taking advantage of them? After all, just because you’re intelligent doesn’t mean you’re honest.
Man, that's a simple way to put things.

Another critique, of course, is that technocrats are increasingly isolated from the negative consequences of their decisions.  Climate Scientists propose policies that impoverish Appalachia due to dodgy computer models and over-confident projections?  They don't lose their houses.  Politicians craft an "Affordable Care Act" that raises the cost of health insurance and the deductibles in the policies?  They don't feed their kids Ramen for dinner.

And so, our own eyes tell us that technically-minded elites are not better at governance than the hoi polloi.  Buckley's dictum that he would rather be governed by the first 2,000 people in the Cambridge telephone directory than by the faculty of Harvard shows us that these problems have been endemic.  The last election shows that the hoi polloi are waking up to this.

Tuesday, January 17, 2017

Infinite loop

n.  See "Loop, infinite"


MIT Wizz Kid: his "Smart" gun design is "relatively reliable"

Buried deep in a glowing review of MIT freshman Kai Kloepfer's "Smart gun" startup, the reporter unexpectedly stumbles onto why this has for decades been a technology in search of a buyer:
“Good intentions don’t necessarily make good inventions,” said Stephen Sanetti, president of the National Shooting Sports Foundation. They’re the main trade group for companies that make and sell guns.

Sanetti expressed concern about the reliability of any firearm that depends on battery power.

“The firearm has to work. And a firearm is not the same as a cell phone,” Sanetti said. “The consequences of a cell phone not working are inconvenience. The consequences of a firearm not working could be someone’s life.” 
Kloepfer said his gun is “relatively reliable.” 
“I know, like, when I’m using it, when I’m testing it, it functions almost every single time,” Kloepfer said.

But not every time, as we saw firsthand when Kloepfer’s prototype -- a modified Glock .22 – failed. 
Other than the minor detail of the gun not working, this solution is awesome.

The only thing new about this is that CBS News is reporting both sides of the debate.  But Mr. Kloepfer scored a sweet $50,000 to dust this idiocy off.

Monday, January 16, 2017

I hope that the Brady Campaign doesn't find out about this

They'll want background checks for sure.


Probably has the shoulder thing that goes up in there, too ...

(Seen on the Book of Faces by the Queen Of The World)

Don't want to get hacked?

Don't use "123456" as a password:
The security industry's ongoing efforts to educate users about strong passwords appears to be for naught, with a new study finding the most popular passwords last year were 123456 and 123456789. 
Keeper Security wonks perused breached data dumps for the most popular passwords when they made the despondent discovery. 
Some 1.7 million accounts used the password "123456", or 17 per cent of the 10 million hacked accounts the firm studied.
Dad used to say that the reason that history repeats itself is that nobody listens the first time.

You want a good password that's hard to crack and easy to remember?  Use a "passphrase" where you take the first letter of each word in an easy to remember sentence.  For example, if you take the first character of each word in "123456 is a lousy password and will get you PWNED!" you get a password of "1ialpawgyP!" which is pretty dang strong.  It's also pretty easy to remember.

Me, I haven't used a password in over 15 years.  Instead, I use this technique and I recommend it to anyone who thinks that "123456" is a bad password.

Sunday, January 15, 2017

John Bull - music for the Elizabethan Court

John Bull was an English musical genius, sometimes compared to Bach for his contrapuntal virtuosity.  While he never composed music for Good Queen Bess' coronation (crowned this day 457 years ago), he was one of the most famous musicians of his day and in fact Court Organist.  It seems that he was sent by the Queen on spying missions to the Continent.

He was also a lot of trouble.  He lost his job because he had a child out of wedlock and finally had to flee England, charged with adultery by no less than the Archbishop of Canterbury and pursued by King James' men.  He spent his final decade uncharacteristically quiet in Antwerp where he died in 1628.

Saturday, January 14, 2017

Old Dominion - Song for Another Time

Image via Rolling Stone
What is "real Country music"?  That's a question that is evergreen, and like sports rivalries will get the debate going hotter than a hoochie coochie.  Long time readers here will know that I tend to fall on the traditional to middle of the road side of things: Waylon, Travis Tritt, Today Keith.

But sometimes I wander into the brambles of the current over-produced Nashville pop.  A while back I posted a mashup of 5 top Country hits which showed that they're really the same song.  You can just see Pistolero rolling his eyes now.

But every now and then I run across one that I like.  I like this one a lot.  Old Dominion got their start writing songs for other artists (The Band Perry and Chris Young, for example).  They started touring with bigger names singing their songs.  When they were opening for Kenny Chesney, they had the idea for a breakup song where they lyrics told the story with a bunch of song titles.  The way they take these titles and knit the together to paint a picture is something that I think is very clever; add in a catchy upbeat rock tune and you have what really can only be described as the best of the modern Nashville.  It's just plain fun.

Even if it hit #1 on the Billboard Country chart.

And as a note to Pistolero - there's a Hank Sr and a Willie song in here, so shake not thy gory locks at me ...


Song For Another Time (Songwriters: Brad Tursi, Matt Jenkins, Matthew Ramsey, Trevor Rosen)
Right now we both know
We're Marina Del Ray
Planes gonna fly away
And you'll be on it
And by this time tomorrow
I'll be singing yesterday
The sunshine's gonna fade
And we can't stop it
So before we turn in
I can't make you love me
Let's be brown eyed girl sweet Caroline
Free fall small town Saturday night
Before you lose that loving feeling
Let's go dancing on the ceiling
Keep on living that teenage dream
Paradise city where the grass is green
Pretty soon I'll be so lonesome I could cry
But that's a song for another time
Just for one more day what do you say
Baby be my pretty woman
'Cause we know Sunday morning's coming down
Let's take a drive you and I down some old country road
Talk about growing old in one of those pink houses
Yeah we might be a candle in the wind
But let's pretend we're
Brown eyed girl sweet Caroline
Free fall small town Saturday night
Before you lose that loving feeling
Let's go dancing on the ceiling
Keep on living that teenage dream,
Paradise city where the grass is green
Pretty soon you will be always on my mind
But that's a song for another time
So before we're singing I will always love you
Let's sing
Brown eyed girl sweet Caroline
Free fall small town Saturday night
Before you lose that loving feeling
Let's go dancing on the ceiling
Keep on living that teenage dream,
Paradise city where the grass is green
Pretty soon I'll be so lonesome I could cry
But that's a song for another time
Yeah, that's a song for another time (brown eyed girl sweet Caroline)
Yeah, that's a song for another time (free fall small town Saturday night)
Yeah, that's a song for another time

Friday, January 13, 2017

Wednesday, January 11, 2017

Backsliding

Damn.


Seen on Facebook by the Queen Of The World.

Beware of Amazon's Alexa

Alexa is a device that listens for voice commands and can tell you the weather, order you pizza, and other Jetsonsesque living in the future things.  But it looks like the system is either too perfect or not perfect enough:
Which is exactly what happened today during CW6 in the morning when Jim Patton and Lynda Martin were talking about a child who accidentally bought a dollhouse and four pounds of cookies 
“I love the little girl, saying ‘Alexa ordered me a dollhouse,’” said Patton. 
As soon as Patton said that, viewers all over San Diego started complaining their echo devices had tried to order doll houses.
I can see spammers using malware executing .WAV files to have Alexa order stuff.  If you want to take a walk on the bleeding edge of technology with Alexa, forewarned is forearmed.

Tuesday, January 10, 2017

Or read a book, for crying out loud


Remember that CEO who said he would pay all his employees $70,000 a year?

Remember how everyone said how awesome he was, paying people a "living wage"?  Well, you can drive nature out with a pitchfork but she always returns:
Back in April we told you about Dan Price, CEO of Gravity Payments, who said he would pay every single one of his employees $70,000 annually. 
Every single one, from the lowest skilled workers on up. 
Now, as expected, Price has fallen on hard times financially, even having to rent out his own home. 
Employees who work for Gravity are now leaving the company, “spurred in part by their view that it was unfair to double the pay of some new hires while the longest-serving staff members got small or no raises.”
In other news today, water is wet and it's dark at night.  Pictures at 11.

Monday, January 9, 2017

So, about that "the Russians hacked the emails" story

I went and read the government report so that you don't have to.  The report claims that the Russians hacked the DNC (the title of the report is "Russia-Hack-Report.pdf" so there's no question).

First, some computer security background from a very long and detailed analysis:
For Hillary we have a Hacker in custody who said he [hacked] it, where there is evidence he did it, where a law enforcement agency caught him in the act and where he was hauled in by the FBI. He said it was a trivial hack technique based on knowing personal details to make a custom dictionary (names, family and pet names, addresses, place of birth, etc.) then using it in a Dictionary Attack on some folks or in a “I forgot my password / Tell me your last name and DOB and I’ll send it to you.” spoof. There is also evidence (weak, but extant) that many TLAs (Three Letter Agencies) and other actors had hacked into her home brew server by other means.
Given what I’ve heard of the set-up, it would be a nearly open book to anyone with skilz. First off, it was built on PRISM infested equipment (so the NSA was in, and potentially the CIA), second, it was Microsoft, so if you didn’t patch daily, you were hacked with known zero-days, and if you DID patch daily, you were hacked by ‘non-fixable’ hacks. 
 ... 
So at this point, we can largely dispose of Hillary’s Hack. It was an open book to all comers and at least one was Romanian (and sharing with friends) and not Russia.  However, I’d say it was almost certain that at some time a Russian intrusion happened. The name of the server was obvious. The location insecure. The operating system and protective layers a joke. Frankly, I’d expect them to be “in” the same day they first looked at it. Which means something like 8 years ago. So why didn’t things leak then?
Because the Russians Are Not Stupid. A fundamental of spycraft is you don’t expose sources and methods, you use them to collect intel for your use, not publication. I suspect they enjoyed a near real time email feed from the Secretary Of State for years, in silence. This argues for email dump to be someone other than them. My personal muse would be an NSA guy, aghast at what was in evidence. Like a Snowden, but not willing to give up the $1/4 Million salary… He (or she…) would have all the requisite skilz to pull it off and leave no finger prints, access to PRISM, and lots of neat toys to work with. Though more likely would be the underpaid I.T. guy Hillary had set it up who was making a backup one day and dropped a load… But I digress.
The bottom line on Hillary is we know she kept a full copy (found on Huma’s Laptop with the Wiener…) and that it was around until she had her lawyers erase it. We know it surfaced in full at the time the laptop went to the FBI, and in parts before that. We know at least one of her hackers was found (though he had likely not leaked it) and that he said he had a doomsday copy for safety. He wasn’t a very good hacker, so that shows lots of good ones walked right in and snagged copies. Assigning source of any Hillary leaks is going to be an exercise is “ME ME MEE!!! PICK MEEE!” with a dozen hands up in the room…
For the DNC:
We know Podesta fell for a phish. That, alone, is enough. Yet we also have evidence that the box wasn’t that well run and secured, and ample evidence that the privilege escalation path once in was easy. Privilege escalation is when you get in with weak powers, you find ways to raise your powers. Moving from “user” to “admin” to “root”.
How many others fell for a phish? How many other bugs, holes, unpatched zero-days? Was it PRISM? Were they on Microsoft? (Almost certainly…though I haven’t bothered to verify).
Once you are this far into the pants-down party, you know you will never know which of the hundreds of actors trying to get in, made it in. You may never even know how many made it.
So the starting point is that the systems were compromised, and almost certainly compromised by several different intruders, all of whom but one (Guccifer) remain unnamed in the unclassified report claiming that the Russians did it.  In other words, there is no uncertainty as to the compromise other than who did it, and enormous uncertainty as to that.

And so, on to the report.  It is a 27 page PDF, so it's actually a quick read.  It's quicker even than you might think based on its thickness when you consider that 18 pages are things like cover sheets, table of contents, background about the investigation (Yay FBI! Yay Intelligence Community!), discussions about how they don't disclose sources and methods, a long discussion of open source Russian media (especially RT television programming), and "This page intentionally left blank".

So there are only 4 pages that you need to read.  Three are "Summary/findings", and so do not have anything got back up their claims.  The meat of the report, therefore, are the pages numbered 2-5.  From a computer/network security perspective, these are entirely unpersuasive that the Russians (and more specifically, Vladimir Putin) was behind the hacks.  Here are the topics that those pages discuss:

  • Putin ordered campaign to influence US election (likely true, although may not have been Putin himself)
  • Russian campaign was multifaceted (you'd certainly think so)
  • Cyber espionage has been going on against US political organizations (well, duh)
  • Public disclosures of Russian-collected data says that the GRU (Russian Military Intelligence) ran the "Guccifer 2.0" persona and gave the data to Wikileaks.  No evidence is given to support this.
  • Russian intrusions into State and local electoral boards did not access vote tallying computers.
  • Russia has a propaganda effort and uses Russian media (especially RT) to get its message out (again, duh)
  • Influence effort was "boldest yet" in US (whatever)
  • Election operation signals "new normal" in Russian influence efforts (whatever)
And so of the eight topics discussed in the 5 pages that are the meat of the report, the only one that counts is "The GRU ran the Guccifer 2.0 collection effort and gave the data to Wikileaks".  There's simply no way to verify this because they don't give us their sources and methods.  Basically, it's "trust us".


And so, back to the second link in this post which discusses how things work in the real world:
Really good hackers get in with a set of warz, immediately start changing any log files and IDS systems to erase evidence of the attack, and exfiltrate what is highly interesting, erase those logs, then lay low with long duration backdoor kit. If possible, picking up additional bits over long periods of time. This is a skill set that takes years to understand, so I’m not going into it here. If you want to know more, attend one of the many hacker conferencesfor a few years. 
Excellent hackers leave indirection evidence that is hard to find (so either you don’t find it and don’t know you were hacked or if you DO find it, since it was hard to find, think yourself sooo smart it must be real…) and deflect any search elsewhere. IMHO, that’s the hardest to properly find. All the real evidence was erased, and what you are working from is the McGuffin. (Thing in a story line everyone is searching to find, that may not be real. See The Maltese Falcon as example.)
So what we know publicly about the investigation is that it was a postmortem, it found some forensic evidence, that evidence was an old Russian warz, and thus the conclusion is:
“Russia Did It!”
The flaws in this are many.
The BIGGEST flaw
You don’t know how many hacks happened. It may well be that the Russians hacked in 6 or 8 years ago and have been sniffing data ever since. That does not at all prevent an Admin dumping a tape and leaking it. It does not at all prevent a Chinese team sucking out the data and erasing their tracks. It does not at all prevent an NSA guy from dropping a USB drive on Wikileaks. It does not at all prevent the local ISP Night Shift Operator, who is bored silly, from piping a router feed of email to their laptop as it goes by and collecting a set (though good ISPs have systems to prevent that). It does not at all prove that only Russia is to blame for the hack / leak, and not some Fat Bastard in the basement of his Mom’s house using downloaded Russian warz (commonly available) to do the hack.
Assigning the Data Public Dump to the Russian Hack is a leap of faith.
Assigning the hack with Russian Warz to Russia proper is a leap of faith.
Assigning the Data Exfiltration to the Russian Warz is a reasonable, but still, leap of faith.
Now there may be classified evidence that is compelling but which is suppressed to protect sources and methods.  These wouldn't be IP address metadata from NSA, because the hop into Russia will almost certainly not be the final leg (indeed, it might be a hop before one to China,or Israel, both of whom have excellent cyber exploit capabilities).  It might be CIA intel from inside the Russian government, but that is unlikely to have detailed information on GRU technical operations (or maybe it does, in which case it's very classified and nobody will tell us about this, maybe ever).

And so we're back to trust us.  That's pretty weak.

My take is that several state actors certainly hacked Hillary's email server for years and years, and silently read all her communications.  Probably more than one state actor penetrated the DNC email system for several years.  It's plausible than an insider leaked the DNC emails - some BertieBro IT Admin type who saw how the sausage was being made and who was smart enough to cover his tracks while pointing clues towards Russia.

Bottom line, this is a tale told by an idiot; full of sound and fury and signifying nothing.  We know that something happened, but we don't know who did it, and what they say in the report doesn't change that.

If you're interested in the topic, I recommend that you click through to this analysis, and particularly the conclusion.

A new (to me) motorcycle blog

I Just Want To Ride is a motorcycle blog I just discovered over the weekend, run by a guy in the local HOG chapter.  It has a wide ranging set of topics, including the latest post on weird motorcycles:


I know that some of all y'all ride, so check it out.

Saturday, January 7, 2017

Hank Williams Jr - Secret Agent Man

So the Intelligence Community has released their report on "Russian hacking of the election", and it's quite unimpressive.  But since it's wall to wall coverages of Russians under beds everywhere, here's Hank Junior's cover of Johnny Rivers' 1966 classic.



Secret Agent Man (Songwriters: P.F. Sloan, Steve Barri)
There's a man who leads a life of danger
To everyone he meets he stays a stranger
With every move he makes another chance he takes
Odds are he won't live to see tomorrow
Secret agent man, secret agent man
They've given you a number, I know they've take away your name
Beware of pretty faces that you find
A pretty face can hide an evil mind
Ah, be careful what you say
Or you'll give yourself away
Odds are you won't live to see tomorrow
Secret agent man, secret agent man
They've given you a number, I know they've take away your name
Secret agent man, secret agent man
They've given you a number, oh they've taken away your name
Swingin' on the Riviera one day
And then layin' in the Bombay alley next day
Oh, don't you let you let the wrong word slip
While kissing persuasive lips
Odds are you won't live to see tomorrow
Secret agent man, secret agent man
They've given you a number, oh they've take away your name
Secret agent man

Thursday, January 5, 2017

On understanding the problem

It mystifies me why some people simply can't understand this.  None so blind as those who will not see, I guess.


Seen on Facebook by the Queen Of The World.

OK, this is really funny

In a very security geeky way.  UK company registers company name as ; DROP TABLE "Companies"; --

If you're interested in learning more about this sort of security fun and games, I have an old post that goes into this in a humorous way.

Wednesday, January 4, 2017

How credible is the "Russians hacked the DNC" report from the Intelligence community?

In this corner, the "You l4mers need to up your game" argument:
[The Administration] had the DHS and US-CERT issue the "GRIZZLY-STEPPE" report "attributing those compromises to Russian malicious cyber activity". It does nothing of the sort. It's full of garbage. It contains signatures of viruses that are publicly available, used by hackers around the world, not just Russia. It contains a long list of IP addresses from perfectly normal services, like Tor, Google, Dropbox, Yahoo, and so forth.

Yes, hackers use Yahoo for phishing and malvertising. It doesn't mean every access of Yahoo is an "Indicator of Compromise".

For example, I checked my web browser [chrome://net-internals/#dns] and found that last year on November 20th, it accessed two IP addresses that are on the Grizzley-Steppe list:
No, this doesn't mean I've been hacked. It means I just had a normal interaction with Yahoo. It means the Grizzley-Steppe IoCs are garbage.
The summing up:
If your intent was to show technical information to experts to confirm Russia's involvement, you've done the precise opposite. Grizzley-Steppe proves such enormous incompetence that we doubt all the technical details you might have. I mean, it's possible that you classified the important details and de-classified the junk, but even then, that junk isn't worth publishing.
In the other corner, the "Russia uses non-state hackers all the time" argument:
That source, who won’t be named here because it would compromise his current position and create legal problems for him, said he routinely saw Russian intelligence services recruiting hackers on cybercrime forums — particularly for research into potential vulnerabilities in the software and hardware that powers various national power grids and other energy infrastructure.
“All these guys had interest in hacking government resources, including Russian [targets],” my source told me. “Several years ago I got to know one of these hackers who worked for Russian government, [and] he operated his [cybercrime] forum as a government honeypot for hiring hackers. They were hiring hackers to work in official government organizations.”
Initially, he said, the hackers targeted U.S. military installations and U.S. news media outlets, but eventually they turned their attention to collecting government and corporate secrets full-time. The source said the teams routinely used botnets for foreign intelligence gathering and counterintelligence, and frequently sought to infiltrate botnets that were suspected of being co-opted for the same purposes by other countries.
My take is that both of these are plausible.  The Russian government has at least loose connections to a whole community of Black Hats who live on their soil (as do other governments, especially China, Iran, and Israel).  Influence is absolutely plausible, though the Grizzley-Steppe report is unconvincing here.  Motivations vary from country to country - China and Iran likely would have preferred Hillary, Israel almost certainly would have preferred Trump.

Does it make a difference?  Not really, as long as DNC bigwigs use an email password of "password".  What is clear is that the DHS report should be taken with a huge grain of salt.  But both of these linked articles do a very good job covering the landscape - if you are interested in this topic, you should click through.

Why the Elites are not fit to govern

Offered for your consideration: John Podesta's email password was "password".

But we're constantly told that the Elites should govern us because they are so very clever and highly trained, and us poor rubes will screw everything up without them.

Hat tip: Rick, via email.

Tuesday, January 3, 2017

Intelligence Agency "The Russians Hacked The Election" report is incredibly weak

Man, it seems like the report is really weak:
Sadly, the JAR, as the Joint Analysis Report is called, does little to end the debate. Instead of providing smoking guns that the Russian government was behind specific hacks, it largely restates previous private-sector claims without providing any support for their validity. Even worse, it provides an effective bait and switch by promising newly declassified intelligence into Russian hackers' "tradecraft and techniques" and instead delivering generic methods carried out by just about all state-sponsored hacking groups.
"This ultimately seems like a very rushed report put together by multiple teams working different data sets and motivations," Robert M. Lee, CEO and Founder of the security company Dragos, wrote in a critique published Friday. "It is my opinion and speculation that there were some really good government analysts and operators contributing to this data and then report reviews, leadership approval processes, and sanitation processes stripped out most of the value and left behind a very confusing report trying to cover too much while saying too little."
It's larded with basic n00b errors:
The sloppiness, Lee noted, included the report's conflation of Russian hacking groups APT28 and APT29—also known as CozyBear, Sandworm, Sednit, and Sofacy, among others—with malware names such as BlackEnergy and Havex, and even hacking capabilities such as "Powershell Backdoor." The mix up of such basic classifications does little to inspire confidence that the report was carefully or methodically prepared. And that only sows more reasons for President elect Donald Trump and his supporters to cast doubt on the intelligence community's analysis on a matter that, if true, poses a major national security threat.
It also doesn't discuss that while there are many linkages between these groups and the Russian government, the links are loose.
As Errata Security CEO Rob Graham pointed out in a blog post, one of the signatures detects the presence of "PAS TOOL WEB KIT," a tool that's widely used by literally hundreds, and possibly thousands, of hackers in Russia and Ukraine, most of whom are otherwise unaffiliated and have no connection to the Russian government.
All in all, this does not seem at all convincing.  It's not clear what exactly was hacked, it's very unclear who was behind the hack(s), and it is murky indeed whether this was state sponsored or just run of the mill Black Hat activity.

What IS interesting is that the Intelligence community would issue such Security Kabuki.  Your speculation is as good as mine on the motivations of those involved.

Sunday, January 1, 2017

Happy New Years everybody

I hope that your celebration was measured and safe.


Saturday, December 31, 2016

Stay frosty, my friends

Getting ready for the HOG chapter "Frosty Balls" ride tomorrow.



Actually not too bad if you bundle up, even at 37°.

My New Years' resolution

I resolve to eat more salads.


How Trump can pound the final nail into the Global Warming coffin

There's something floating around about how "100% of warming is due to data tampering".  It's worth your time to read it.

Long time readers know that I've been posting about climate science for quite a long time.  Newer readers who are interested in a condensed view of my opinions can read it here (it's sort of a "Climate Science 101" post for the educated layman).  Readers who want more depth and background (or who are gluttons for punishment) can get a list of climate posts here.

But everyone is familiar with the Global Warming scare machine which pumps out a never ending stream of ZOMGTHERMAGEDDON!!!11!!!ELEVENTY!!!  The climate science establishment feeds a stream of "hottest year ever" press releases to a media that is fully on board and which pushes this narrative.  Government funding to the tune of $100 Billion feeds the whole machine.

And yet the public is (rightly) skeptical of the whole thing.  Trump is making some right moves appointing skeptics to positions like head of the EPA.  Some have proposed cutting funding of climate science research by 80% or more.  These are good ideas, but won't directly address the problem of corrupted research and bureaucratic pushback.  Immodestly, I believe that I have something that will stop the global warming machine in its tracks in the space of a month, and keep it derailed for good.  And there's nothing that the bureaucracy and the scientists can do about it.

And it would be 100% scientific, which is why it would be so easy and why it would stick.  You clean up the climate databases:
If you look closely at climate data, you will find that all the major data sets consist of two parts:

Raw Data, which is the instrument reading: satellite, thermometer, or proxy (tree ring, ice core, etc). This is data straight from the sensor.

Adjustments, which are corrections applied to raw data to adjust for inconsistencies. For example, it is important to read the thermometer temperature at the same time every day. If the hottest time of the day is, say, 2:30 PM, but you read the thermometer at 10:00 AM, then the day's reading will be low. Adjustments are also made when weather stations are re-sited, and for other reasons.

An interesting question is how much of the 20th Century's warming came from adjustments, rather than from raw data?
Spoiler alert: according to the scientists themselves, over 85% of reported warming comes from adjustments to the data.  Re-stated, the data as recorded only show 15% of the ZOMGTHERMAGEDDON!!!11!!!eleventy!!! that is being fed to us.  Or all of it, if you believe the new post that's going around.

Now maybe these adjustments are actually correct, but it seems that the scientists should provide very solid and compelling reasons when and why they adjust the data.  Quite frankly, there are some good reasons to think that they are not doing this:
Anyway, lets look at the specific adjustments.  The lines in the chart below should add to the overall adjustment line in the chart above.
Ushcn_corrections2
  • Black line is a time of observation adjustment, adding about 0.3C since 1940
  • Light Blue line is a missing data adjustment that does not affect the data much since 1940
  • Red line is an adjustment for measurement technologies, adding about 0.05C since 1940
  • Yellow line is station location quality adjustment, adding about 0.2C since 1940
  • Purple line is an urban heat island adjustment, subtracting about 0.05C since 1950.
Let's take each of these in turn.  The time of observation adjustment is defined as follows:
The Time of Observation Bias (TOB) arises when the 24-hour daily summary period at a station begins and ends at an hour other than local midnight. When the summary period ends at an hour other than midnight, monthly mean temperatures exhibit a systematic bias relative to the local midnight standard
0.3C seems absurdly high for this adjustment, but I can't prove it.  However, if I understand the problem, a month might be picking up a few extra hours from the next month and losing a few hours to the previous month.  How is a few hour time shift really biasing a 720+ hour month by so large a number? I will look to see if I can find a study digging into this.  
I will skip over the missing data and measurement technology adjustments, since they are small.
The other two adjustments are fascinating.  The yellow line says that siting has improved on USHCN sites such that, since 1900, their locations average 0.2C cooler due to being near more grass and less asphalt today than in 1900.  
During this time, many sites were relocated from city locations to airports and from roof tops to grassy areas. This often resulted in cooler readings than were observed at the previous sites.
OK, without a bit of data, does that make a lick of sense?
Not to me it doesn't, and it shouldn't make sense to the Trump Administration, either.  And so my proposal:

Remove all adjustments from the climate databases and then allow them back only when justified for a single day at a single weather station.  If an adjustment is needed, then have NOAA specify why.  And report the last 100 years without any adjustments.

And this will basically kill the global warming movement.  It will reveal to the public that the data have been manipulated.  Those who complain about this will have to justify why unspecified and unjustified changes should be allowed to the data.  They will have to explain how that is scientific.  Quite, I don't see how the climate science establishment can effectively push back against this without confirming the skeptics' worst accusations.  I mean, do you want honest science or not?

And suddenly all the scientists who use that data set will have a data set without an artificial warming signal.  There will suddenly be a "97% consensus" that no warming is seen.

And this can all be done in a week.  No Congressional action needed, just the stroke of Trump's pen.  And then he can tell the EPA to justify all their new carbon rules ...

Brad Paisley - Welcome To The Future

New Year's is an occasion to think on what the new year will bring.  It's also an occasion to think on where we've been and what's changed.  Life is change, whether we like it or not, and we exist in a time machine heading into the future at a speed of one second per second.



Welcome to the future.

Friday, December 30, 2016

If only we could replace that cowboy George W Bush as President

America would no longer be mocked by the rest of the world.


Wednesday, December 28, 2016

Damn


It was a silly movie, but she was really good in it.  She was only 20.  That was 64 years ago.  Debbie Reynolds, mother of Carrie Fisher, dead at 84.

Sunday, December 25, 2016

Merry Christmas from Wolfgang


He hopes you got a frisbee, too.

J. S. Bach - Christmas Oratorio

It's Christmas by J.S. Bach.  Not sure how much more needs to be said, other than Merry Christmas to all!

Saturday, December 24, 2016

Thurl Ravenscroft - You're A Mean One Mr. Grinch

The Queen Of The World thinks that I need to post something for all y'all who are grinches this year.  And you know who you are ...



I always thought that this was sung by Boris Karloff, but he narrated the TV show.  Ravenscroft  sang the song.  He also looked looked just like Clark Gable.  Who knew?

Martina McBride - O Holy Night

It is the night tonight.

Friday, December 23, 2016

90 years of movies Frederick, MD

The Queen Of The World and I are at the Weinberg Theater in Frederick, Maryland which is celebrating its 90th birthday by showing the first movie ever shown here. It's the silent film "The Strong Man", with a live accompaniment on the original pipe organ (as was done 90 years ago).

Right now (before the show), he's playing Christmas carols. He's very good, and the organ sounds spectacular.

Bing Crosby - Mele Kalikimaka (with Mickey Mouse)

The cartoon is classic Mickey.

How the New York Times knows it's wrong about Russian hacking

And how we know that they know.  A detailed analysis about how scraps of information are woven into a narrative to support the Democrats:
Here's a trick when reading New York Times articles: when they switch to passive voice, they are covering up a lie. An example is this paragraph from the above story [*]:
The Russians were also quicker to turn their attacks to political purposes. A 2007 cyberattack on Estonia, a former Soviet republic that had joined NATO, sent a message that Russia could paralyze the country without invading it. The next year cyberattacks were used during Russia’s war with Georgia.
Normally, editors would switch this to the active voice, or:
The next year, Russia used cyberattacks in their war against Georgia.
But that would be factually wrong. Yes, cyberattacks happened during the conflicts with Estonia and Georgia, but the evidence in both cases points to targets and tools going viral on social media and web forums. It was the people who conducted the attacks, not the government. Whether it was the government who encouraged the people is the big question -- to which we have no answer. Since the NYTimes has no evidence pointing to the Russian government, they switch to the passive voice, hoping you'll assume they meant the government was to blame.
There's a lot more.  All I can add is that (a) the line that "the Russians hacked the DNC to help Trump" is really weak from a facts and proof point of view, and (b) the only people who will believe it are Democratic Party supporters (like the Times) who don't care about facts and proof.  Oh, and (c) the people in (b) are entirely convinced that they are smarter and better thinkers than you and me, despite their utter lack of interest in thinking this one through.

The New York Times: All the news that confirms our bias is fit to print.

Thursday, December 22, 2016

It's beginning to look a lot like Christmas

Father-In-Law has Christmas decorations up.

Wednesday, December 21, 2016

Joe Bonamassa - Santa Claus Is Back In Town

And it's a $400 fine for the second offense


Why I'm not posting about the "the Russians hacked the election" nonsense

Because it's nonsense, and quite shockingly low caliber nonsense at that:
Then there is the persistent incredibly STUPID story that “The Russians Did It!!”. First off, you can’t know if they did the hack, or not. (As pointed out several times already, I’m a computer security guy who had to deal with this stuff professionally for a couple of decades… it’s ‘my business’ and I’m good at it.) My first encounter with The Russians was in about 1986, so call it 30 years ago. To think that only this year they woke up and started hacking is just dumb. They are about 1/4 as active as the Chinese, so anything they have, or did, the Chinese had more of and sooner. Now look at what ‘the hack’ was (and was not): It was NOT a changing of the vote. Recounts and paper ballot States show that. (In fact, they show a little fudging by the Democrats in places like Chicago…but not enough to change the outcome since they are concentrated in places like California where the Dims already run the table). It WAS a publishing of the criminal and completely immoral actual acts and crimes of the DNC, Clinton, Media like CNN and MSNBC and ‘papers of record’ in burning Bernie and going ‘all in’ on biasing the debates (and worse). So at most, it was exposing the truth. Golly, being truthful, such a crime… /sarc
Remember, the Democrats think that you're stupid, and will fall for this drivel.

Tuesday, December 20, 2016

What's the cost of cybercrime?

$1 - $2 Billion a year for one botnet:
New research suggests that an elaborate cybercrime ring is responsible for stealing between $3 million and $5 million worth of revenue from online publishers and video advertising networks each day. Experts say the scam relies on a vast network of cloaked Internet addresses, rented data centers, phony Web sites and fake users made to look like real people watching short ad segments online.
[blink] [blink]

Wow.

UPDATE 21 December 2016 14:01: Fixed an autocorrect-induced typo.

What does a Climate Scientist say to climate scientists freaking out over the impending Trump Administration?

Dr. Judith Curry runs the school of Earth Sciences at Georgia Tech, and is a peer-reviewed climate scientist.  She is also a "like warmer" - she believes that the climate has been warming (as do I) and that mankind is somewhat responsible (as do I).  However, she does not see things as a crisis, and has repeatedly spoken (including before Congress) on the large uncertainties in climate science.  Her paper The Uncertainty Monster is required reading for anyone interested in the state of the science.

So what does she say to the scientists who are freaking out over Donald Trump?
Get over it, your side lost.  Changes of Presidential administrations occur every 4 or 8 years, often with changes in political parties.
Get busy and shore up your scientific arguments; I suspect that argument from consensus won’t sway many minds in the Trump administration.
Overt activism and climate policy advocacy by climate scientists will not help your ’cause’; leave such advocacy to the environmental groups.
Behave like a scientist, and don’t build elaborate conspiracy theories based on vague conflicting signals from the Trump administration.  Stop embarrassing yourselves; wait for the evidence.
Be flexible; if funding priorities change, and you desire federal research funding, work on different problems.  The days of needing to sell all research in terms of AGW are arguably over.
'Tis a consummation devoutly to be hoped, that right there.

Sunday, December 18, 2016

Bing Crosby - White Christmas

One of the Queen Of The World's favorites - the original from the film, 'natch.  This one that is dubbed into German is pretty funny ...



Of if Deutsche is nicht sehr gut fur sie, Perry Como's version is perhaps more gemütlich:

Just between you and me, I have my doubts


The oldest Christmas Carol - Corde Natus Ex Parentis

This was written by the roman poet Prudentius in the late fourth or very early fifth century, although there is some argument that Veni Redemptor Gentiuma carol by Ambrose (Bishop of Milan and one of the Church Fathers) was the first.  Interestingly, both are still performed today over 1600 years after they were written.



Corde natus ex parentis
Ante mundi exordium
A et O cognominatus,
ipse fons et clausula
Omnium quæ sunt, fuerunt,
quæque post futura sunt.
Sæculorum sæculis.

Of the Father's heart begotten,
Ere the world from chaos rose,
He is Alpha, from that Fountain
All that is and hath been flows;
He is Omega, of all things,
Yet to come the mystic Close,
Evermore and evermore.

Saturday, December 17, 2016

Michael Buble & Thalia - Feliz Navidad

Love this song.

Travis Tritt - Christmas In My Hometown

Country music can get pretty sentimental sometimes, and there's no time for sentimental like Christmas.  Travis Tritt does an old school country version of Sonny James' 1966 holiday classic.



Christmas In My Hometown (songwriters: Sonny James, John Skye)
There's a white Christmas in my hometown
Where the streets are snowy, shinin' bright
And the lights on all the Christmas trees are burning
For old Santa's sure to come this very night 
There are jingle bells and Christmas carols singin'
By the children who are walking in the street
Folks are smiling and they're sayin' merry Christmas
For there's joy in their hearts as they meet 
Oh, the Christmas chimes are ringing in the tower
Jingle bells can be heard all around
Time for all to go and wait for Santa's comin'
'Cause it's merry Christmas here in my hometown 
I can hear the reindeer in the distance
All the sleigh bells are ringing loud and clear
Little eyes are closed in their slumber
They are waiting for old Santa to appear