Saturday, October 8, 2016

John Michael Montgomery - Life's A Dance

Life is change, and the last two years have seen a lot of that for me.  But your choice is to dance to the music of change, or sit things out.  The Queen Of The World and I have been pretty busy up here seeing new places and meeting new people.  It's change, and change is sometimes hard.  But if you take the right partner with you, it's a dance.

This song is the title track from John Michael Montgomery's debut album.  The album went platinum, the first of several.



Life's A Dance (Songwriters: Allen Shamblin, Steve Seskin):
When I was fourteen I was falling fast
For a blue eyed girl in my homeroom class
Trying to find the courage to ask her out
Was like trying to get oil from a waterspout
What she would have said I can't say
I never did ask and she moved away
But I learned something from my blue eyed girl
Sink or swim you gotta give it a whirl

Life's a dance you learn as you go
Sometimes you lead, sometimes you follow
Don't worry about what you don't know
Life's a dance you learn as you go

The longer I live the more I believe
You do have to give if you wanna recieve
There's a time to listen, a time to talk
And you might have to crawl even after you walk
Had sure things blow up in my face
Seen the longshot, win the race
Been knocked down by the slamming door
Picked myself up and came back for more

Life's a dance you learn as you go
Sometimes you lead, sometimes you follow
Don't worry about what you don't know
Life's a dance you learn as you go

Life's a dance you learn as you go
Sometimes you lead, sometimes you follow
Don't worry about what you don't know
Life's a dance you learn as you go
Life's a dance you learn as you go
Sometimes you lead, sometimes you follow
Don't worry about what you don't know
Life's a dance you learn as you go

Life's a dance
Life's a dance
Life's a dance
Take a chance on love
Life's a dance
You learn as you go

Friday, October 7, 2016

No.

Just no.


Was Yahoo looking for Al Qaeda encrypted messages?

Interesting:
What they are likely referring it is software like "Mujahideen Secrets", which terrorists have been using for about a decade to encrypt messages. It includes a unique fingerprint/signature that can easily be searched for, as shown below.
The text string in these sorts of things is not hard to identify at all.  The string is used by programs to know where to start decrypting (all sorts of crypto programs do this).
The obvious "highly unique signature" the FBI should be looking for, to catch this software, is the string:
### Begin ASRAR El Mojahedeen v2.0 Encrypted Message ###
Indeed, if this is the program the NSA/FBI was looking for, they've now caught this message in their dragnet of incoming Yahoo! mail.
It's speculation that this is what Yahoo was looking for, but as Mythbusters would say, "Plausible."

I posted about this a couple years ago, in a post titled How do you say "Hey, NSA!  Look over here!" on the Internet?  In it, I said:
I've been very critical about how NSA is spying on citizens unsuspected of any crime, but this seems to be precisely what they should be doing.  I'm even OK with secret FISA court warrants allowing automated monitoring (and even attacking) anyone using al Qaeda code.  Seems like that falls under "probable cause" to me.
In most jurisdictions possession of lock picking tools is presumptive evidence of wrongdoing (if you're not a locksmith).  It seems plausible that possession of custom Al Qaeda encryption software is also presumptive of wrongdoing.  Sure, there's a First Amendment argument that can be made here, cryptographic research, yadda yadda - but this seems quite narrowly tailored to me.  If this is what Yahoo was looking for, it seems reasonable to me.

There are at least 5 leakers in the US Intel community (that we know)

List.

It's nothing but speculation as to whether the guy arrested the day before yesterday is one of these.  It seems like he may not be.

Thursday, October 6, 2016

Nice translation


I worked for a company that once saved money by using a domestic translator for an ad to be run in Tokyo.  They translated "RISC technology" as "risky technology".  Good times, good times.

1930s video of old Confederate veterans doing the "Rebel Yell"

Rick emails to point to this.  It's pretty cool looking back 150 years.

The Second NSA leaker comes to light

There was buzz around this a couple years ago.  I guess it's possible that this isn't another leaker, in which case there's still another leaker.

Wednesday, October 5, 2016

Roy Book Binder - Mississippi Blues

Happy birthday, Roy!

Words to live by


Hollywood's love affair with fascists

It's quite a history, including cameo appearances in films by no less than Benito Mussolini.
Unmentioned in this write up is that the love affair of Mussolini with Hollywood was reciprocated. At least up until he fell in with Hitler and started banning Jews from positions of authority in the government and military. Note the part that says "at this time Mussolini was a popular hero". That wasn't just in Italy… Note, too, that he invited the Glitterati to visit, but it doesn't mention that they went; or that he came to Hollywood and was celebrated.
Now Hollywood likes their fascists a bit more home grown.

Johnson & Johnson insulin pump vulnerability

Johnson & Johnson has announced a vulnerability in one of their insulin pumps that could allow an attacker to change dosage levels:
Johnson & Johnson is telling patients that it has learned of a security vulnerability in one of its insulin pumps that a hacker could exploit to overdose diabetic patients with insulin, though it describes the risk as low.

Medical device experts said they believe it was the first time a manufacturer had issued such a warning to patients about a cyber vulnerability, a hot topic in the industry following revelations last month about possible bugs in pacemakers and defibrillators.

J&J executives told Reuters they knew of no examples of attempted hacking attacks on the device, the J&J Animas OneTouch Ping insulin pump. The company is nonetheless warning customers and providing advice on how to fix the problem.
Kudos to J&J - this is exactly how this sort of thing should be done.  No stonewalling, just transparency on what the issue is with a fix available.

Tuesday, October 4, 2016

Oops

Well, who didn't see this coming?

Porn displayed on "Internet Of Things" refrigerator.  In Home Depot. (picture safe for work)

I'd say something mocking, but this whole Internet Of Things thing is getting to the self-mocking stage.  Maybe retitle the song "The Internet Of Things Is For Porn" ...

Security: Blaming the user

This sounds about right:
The problem isn't the users: it's that we've designed our computer systems' security so badly that we demand the user do all of these counterintuitive things. Why can't users choose easy-to-remember passwords? Why can't they click on links in emails with wild abandon? Why can't they plug a USB stick into a computer without facing a myriad of viruses? Why are we trying to fix the user instead of solving the underlying security problem?
Traditionally, we've thought about security and usability as a trade-off: a more secure system is less functional and more annoying, and a more capable, flexible, and powerful system is less secure. This "either/or" thinking results in systems that are neither usable nor secure.
The problem is that computers were designed by engineers, who think like engineers.  What makes sense to an engineer looks to mere mortals like, well, bug eyed insanity sometimes.  Just watch The Big Ban Theory for the humorous aspects of this.

As someone who has worked in security for a long time, I muss confess that it's very easy to create a cool new tool that is interesting and useful to a brilliant engineer.  It's a whole different kettle of fish to create one that is useful to the typical IT geek, let alone end users.

Monday, October 3, 2016

Halloween at Castle Borepatch

Wolfgang says "Boo!"


Huh. I would have expected "Schooly McSchoolyface"

But this is pretty good too.


Remember, friends don't let friends use Internet polls to name things.

Why security stinks, part 4,927,831

Linux has a reputation for strong security (which is why I run it on the Castle Borepatch supercomputers).  But even Linux isn't free from boneheaded security problems:
"After running this command, PID 1 is hung in the pause system call. You can no longer start and stop daemons. inetd-style services no longer accept connections. You cannot cleanly reboot the system." According to the bug report, Debian, Ubuntu, and CentOS are among the distros susceptible to various levels of resource exhaustion. The bug, which has existed for more than two years, does not require root access to exploit.
The discussion thread gives a really good overview of why computer security stinks.  Essentially, a simple and secure but basic bouts routine got replaced by a feature-rich but complicated one.  Unsurprisingly, the complicated replacement has a grotesque security problem.

Complexity is the enemy of security, and developers are racing to add complexity.  You can estimate where that will lead us ...

UPDATE 3 October 2016 11:24:  It's actually even worse than I had thought.  System implements the DNS protocol, but never implemented the DNS recommended best security practices.  Idiots.  This sums it up for me, too:
And folks wonder why I hate SystemD with a passion… Designed wrong, implemented badly, doing things it ought not do, in ways that are broken. And that’s just at first glance… now we know that anyone can hang your system in a non-recoverable state and the DNS can be poisoned. Oh Joy. /sarc;
Complexity is not Security's friend.

Why is computer security so bad?

Because software almost doesn't work at all:
It’s hard to explain to regular people how much technology barely works, how much the infrastructure of our lives is held together by the IT equivalent of baling wire. 
Computers, and computing, are broken.
This is absolutely, 100% true.  Years ago I was at a company that found a security bug in the Unix Remote Procedure Call (RPC) routine.  It was bad, allowing J. Random Hacker to remotely take over your server.  It took me weeks to chase down the security team at a large company that really should have known better.  At the end of the day, they didn't fix it.  The reason?

The code is really old and nobody here really understands how it works.  We're afraid that if we fix this we will actually break bigger things.

This is an excellent (if long) article about just how bad things are.  And this has the ring of truth:
For a bunch of us, especially those who had followed security and the warrantless wiretapping cases, the revelations weren’t big surprises. We didn’t know the specifics, but people who keep an eye on software knew computer technology was sick and broken. We’ve known for years that those who want to take advantage of that fact tend to circle like buzzards. The NSA wasn’t, and isn’t, the great predator of the internet, it’s just the biggest scavenger around. It isn’t doing so well because they are all powerful math wizards of doom. 
The NSA is doing so well because software is bullshit.

Hat tip: American Digest.

Sunday, October 2, 2016

Gioachino Rossini - William Tell Overture

Some music becomes so closely associated with something that it loses its own identity and becomes essentially inseparable from it.  The best example of this that I can think of is Gioachino Rossini's overture to the 1829 opera "William Tell".  This was the theme song for the TV show "The Lone Ranger" and many people can't listen to it without the words "Hi yo, Silver - away!" whispering in the back of their heads.  Indeed, when I was young I was told (by a University professor, who laughed as he said it) that the definition of an Intellectual was someone who didn't think of the Lone Ranger when he heard this.

But we usually only hear a small portion of the Overture, which is basically a mini-Symphony of four parts.  The one that we know is the last, "The March of the Swiss Soldiers".  But listen all the way through and you'll recognize more of the overture than just this.



Clayton Moore played the Lone Ranger for 3 of its 5 seasons.  It was ABC's first hit show and became so iconic that Moore is the only actor who has both his name and the name of his character on his star on the walk of fame.

He had an interesting life.  Born in 1914 in Chicago, a circus acrobat at 8 years old, he got into stunt man acting and from that into his iconic TV role.  Serving in the Army Air Corps in the War he leant his celebrity stature to the cause of victory by leading a war bonds campaign.  One of his films was "Target Invisible" about a fictional bomber squadron over Tokyo, and was used during the bond campaign.

He has an autobiography, I Was That Masked Man.  And so you can see that while I may be intellectual, I'm not an Intellectual.



Saturday, October 1, 2016

October Tide - Deplorable Request

Not Country music by any stretch of the imagination, but perhaps a worthy anthem for a basket of Deplorables.


Shut it all down
The facts and the memories
I have been running around inside on this borrowed time
The medical poison
It stabilises and drags me back
Though it is against my will

Locked inside
This suite of flesh and blood
Stranded on clean sheets forever
With the parasites in my veins

I can hear your cries
I can feel your breath to the end
You have been visiting me for so long now

Erase the map of the past

I am fighting with my heart as an enemy
Falling through a black hole for eternity
Caught in an endless sleep with this hollow dreams
Capture the light and pour it over me
A benefactor forbidden to all humanity
Bring me a trail and please let me feel pain

Turn to the next page
Ease your depression
You will find it better when I'm gone
This will lead you insane

I can hear your cries
I can feel your breath to the end
You have been visiting me for so long now