Category: Computer

On the Never Ending OOXML Wars

Well, first, and least important is the appearance on Wikileaks of a document on the fast track process which seems to imply that the fast track approval of the Microsoft® OOXML document standard was improper.

Someone with more knowledge than me needs to check it out though, it’s only 2 pages.

Of more note, is that Microsoft® will natively support ODF in Office. The head of Griffin Brown, the organization nominally in charge of maintaining the ODF standard thinks that this will relegate OOXML to second place status, but I’m more inclined to believe that this is an attempt to “embrace and extend” (damage) ODF to the maximum degree possible.

Newest Grant Theft Auto Slams Right Wing

Well, now we know why younger Americans are trending against the Republicans.

Cases in point in GTA IV:

  • A hack news organization, Weasel News…Perhaps representing some other mammal named “fair and balanced” news channel?
  • Bridges closed to the city center (Manhattan) for “unspecified” security threats.
  • A Limbaugh clone who is poorly depicted, “You listeners make the show. All I do is make the money and spend it on face fulls of pharmaceuticals that make me go deaf.”

The vast left wing conspiracy seems to be doing its job.

OK, I Think That This is Wicked Neat

But I’m an engineer, so a lot of the rest of you may not understand why I think that the chemical vapor deposition (CVD) diamond coatings on tools is neat.

It’s been “just around the corner” for some time, and the fact that we are seeing a commercial application (F-35 wing skin cutting), with tool life increasing by a factor of is interesting.

I’m wondering if we’re going to start seeing CVD diamond on heat sinks, as it’s the most thermally conductive substance on earth.

Many Security Exploits Financial, Not Technical Issue

El Reg writes about an academic article that calls for making vendors liable for security exploits.

This is a good idea:

In the real world investment in risk avoidance may not be profitable. Security failures often arise due to perverse incentives rather than the lack of suitable technology. For example, credit card firms can rely on business models that push the cost of fraud onto merchants and consumers rather than investing in reducing the problem themselves. That’s because such investments would place them at a commercial disadvantage to their competitors.

Establishing economic incentives for IT suppliers to produce more secure products is arguably an even greater problem because software publishers are not held liable for the shortcomings of their products. These shortcomings may damage consumer faith in ecommerce but fail to effect sales, so a market-based solution in absence of regulatory pressure is difficult to imagine.

Microsoft would be bankrupt in 6 months.

The MicroFlaccid Clown Show that Is Vista

Yep, their update, Vista SP 1, breaks antivirus and firewall programs, in addition to putting some machines into an endless reboot loop.

A major update to Microsoft’s Windows Vista operating system could leave computers vulnerable to hackers and malware as the service pack prevents several widely used antivirus programs from operating, the company said.

The list of security products that Windows Vista Service Pack 1 blocks includes Zone Alarm Security Suite 7.1, Trend Micro Internet Security 2008, and BitDefender 10. It also blocks the 2008 version of the Jiangmin antivirus product.

I don’t know of anyone who is using Vista who does not regret it.

The First Act of Bush and His Evil Minions&trade Upon Squatting at 1600 Was to Trash the Email Archive System

The Washington Post has a pretty good summary, though they soft pedal the conclusion.

Let’s make this clear, the Clinton administration got into legal trouble with a small problem with backups, the Reagan administration had its email backups used to investigate the Iran-Contra scandal, but somehow these folks, who have a pathological need for secrecy, just screwed up.

Yeah, sure.

Is a Password Protected by the 5th Amendment?

There is a general principal in US law, that one can be compelled to turn over physical evidence, but not the contents of one’s mind, as that is protected by the 5th amendment.

So, you can be compelled to turn over a key to a lock, but not a combination. There is a fairly long legal precedent.

This case asks what it means if the lock is unbreakable, or nearly so.

Case in brief: A Canadian, on crossing the US border, was told to show the contents of his hard drive, which he did, and some of the contents were deemed by the border guard to be likely child porn, though it’s unclear of this was simply random files in the cache, or Manga, or real kiddie porn.

The machine was confiscated, and subsequently turned off.

When it was restarted, its demanded a password, since the contents had been encrypted with PGP, and were inaccessible, and Magistrate Judge Jerome J. Niedermeier has ruled that compelling him to turn over his password violates the 5th amendment.

The prosecutors are appealing saying the standard stuff about terrorism, etc.

I’m with Marc Rotenberg, executive director of the Electronic Privacy Information Center, who has said, “The consequence of this decision being upheld is that the government would have to find other methods to get this information, but that’s as it should be. That’s what the Fifth Amendment is intended to protect.”

He’s right. If you hooked up this guy’s drive to a supercomputer, and ran it for a few months, and maybe less if you brought in some experts from the NSA, at the cost of a few million dollars, you’d probably crack the password, because even the best people don’t choose truly random passwords.

Inconvenient, yes, but inconvenience is not a basis for emasculating the Bill of Rights.

I generally oppose any granting any power to the government to either judge one based on the contents of one’s mind (hate crime laws), or to force revalation of the contents of one’s minds.

See In Child Porn Case, a Digital Dilemma.

Geeky Tech Content: The iPhone Makes Windows Look Like Fort Knox

OMFG!!!! Apple® has come out with a system that is less secure than Windows.

The iPhone®, which runs an Apple® version of Unix® runs everything as root.

1) Every process runs as root. MobileSafari, MobileMail, even the Calculator, all run with full root privileges. Any security flaw in any iPhone application can lead to a complete system compromise. A rootkit takes on a whole new meaning when the attacker has access to the camera, microphone, contact list, and phone hardware. Couple this with “always-on” internet access over EDGE and you have a perfect spying device.

So, unlike your home computer, this is more vulnerable, and it can be set to listen in and photograph you with a remote compromise.

This is the NSA’s wet dream, you’ve bugged yourself.

Intel and Symantec team up Stop You From Using Your PC As You Wish

It appears that the Bobsey Twins of the security worldhave decided to put features into chipset that will prevent users from running the software they choose.

They are not admitting this, but the statement that, “Intel plans to incorporate Trusted Platform Module capabilities, which already ships as separate modules in some of its laptops, into its chipsets next year.” Means that you will not be able to run the programs that you buy on your PC.

Hello AMD.

OH, This Time, and ONLY This Time, I’ll Believe Microsoft

A few days ago, a protype “smart radio” was sent to the FCC for testing. The idea behind such a system is that it can communicate adaptively in the “white space” between TV stations, opening up spectrum. It failed abysmally.

Well, Microsoft is now saying that they sent sent FCC a defective prototype.

So they are now saying that they are complete pratts who could not be bothered to send a working unit.

Normally, I don’t trust Microflaccid enough to throw them, but this time, it rings true to me.

Expanded Surveillance Will Make Our Infrastructure More Vulnerable to Spying and Attacks

Here is a very interesting article by Susan Landau.

Her thesis is that the actions taken by the Bush administration and our state security apparatus have the effect of making us more vulnerable to spying and cyberterrorism.

Her very valid point is that the surveillance society envisioned by Bush and His Evil Minions will require a back door on every phone switch in the country, and once there, it will be significantly easier for state and non state actors to hack into the switches and listen to our communications.

NBC Producer Owned at Def Con.

It appears that an overzealous, and quite frankly not very bright Producer for the NBC program Dateline, Michelle Madigan, got outed at Def Con, the hackers convention.

Reporters are allowed, they are supposed to wear a press badge, and not to photograph or record without the subject’s consent.

Def Con is a bit of an odd bird, it resembles those “Christmas Truces” during the first world war, with white hats, black hats, and law enforcement all mingling in relative peace.

There is a hacking contest, and numerous demonstrations of security holes and hacking tools, which is why law enforcement shows up. This is just as useful to them as it is to the Nigerian spammers who attempt to get you to give them your bank account information.

It appears that the hopefully soon to be unemployed Ms. Madigan was attempting to create a bogus story about law enforcement folks being there.

While probably not factually false, it’s an attempt to create a scandal where none exists. Def Con is as valuable an asset to people combating hackers as it is for hackers, and any security professional who gets his undies in a bunch about people attending should not be in the field.

There is a description, with photos and video, of Ms. Madigan’s flight once she was outed here.

It appears that she was chased from the show by reporters looking for pictures and video once she was outed.

I love the irony.