Category: Computer

Google’s New Motto: “Be Evil”

The search company is now hiring private goons to harass homeless on public streets near their new offices in Los Angeles: (link temporarily public)

How does Google, one of the most cash-rich and innovative companies in the world, propose to deal with the issue of homelessness in America? What’s its 21st century, New Economy solution to disrupt and solve this difficult socio-economic problem once and for all?

In Los Angeles, the company’s fix is brilliantly simple: Hire private security to harass and push the homeless out of sight, and then make sure that the smelly bastards and their tents and carts never come back.

I have seen this solution in action myself. I live just around the corner from Google’s new campus in Venice, LA — two big properties located right off the beach, smack in the middle of Venice’s tiny Skid Row. Los Angeles is in the grips of a homeless population explosion, with an increase of 12 percent just in the last year. And this small two-square-block area used to be one of the last places where homeless people were somewhat tolerated around these parts.

But not any more — not after Google decided to claim sidewalks for itself and cranked up aggressive security patrols in order to drive away the local homeless population.

“Me and my girlfriend got maced by doing nothing,” a man named “Cory” [not his real name] tells me. He has steely blue eyes and shaggy hair, and looks more like an aging surfer than someone who sleeps rough on the streets. He recounts a recent experience he claims to have had with a Google security guard while sitting on a public sidewalk near the company’s campus.

“He wanted us to leave. I had water in both hands so I couldn’t attack. And we’re like, ‘what the f%$#, man?’ And he was just like, pshhhhh,” he continues, reenacting the hissing sound of the mace spray can and explaining that they were given no time to leave or react in any way. “My girlfriend didn’t want to be there. Actually she was terrified of them. Every time Google security came, she said ‘we gotta go, we gotta go.’ We’re not allowed to be on public sidewalks, even though we’re the public.”

I’m talking to him on a sidewalk in the shade of a small tree on 3rd Avenue, which runs between a self-storage business and the backside of Google’s newest property, a giant warehouse that’s currently being remodeled into an expansive new Google office space.

………

“We running a business here. Can’t have homeless people out here like that. We got geeks. They’re scaring folks.”

That’s what I was told — firsthand, no hearsay — by a Google security guard who was patrolling the perimeter. It was a chilly Los Angeles evening in mid-February, and the security guard wore a fleece and baseball cap emblazoned with the cheery Google logo. A Google employee badge dangled at his belt.

The reason he was speaking so freely is that I hadn’t mentioned I was a member of the press — largely because, that evening at least, I wasn’t. I was just another Venice area local, on my way home from the gym, who had stopped to chat to the guard. I certainly hadn’t expected him to so candidly explain how Google employees — and especially Google executives — were freaked out by the homeless people outside its walls. So freaked out that he was hired on as part of a beefed up security presence aimed at clearing the public street that bisects Google’s two properties of any homeless presence.

………

Google’s no homeless on the sidewalk policy may make sense for the company. The catch is that the sidewalks don’t belong to Google: they’re public property, and a federal court had mandated that Los Angeles allow people to sleep there between the hours of 9 pm and 6 am, as long as they leave a little room for foot traffic and don’t block any doors or driveways. This restriction is part of a settlement that has been in place since 2007, and neither police nor a corporate giant like Google has the legal right to determine who can or cannot sleep on any given chunk of sidewalk in LA.

………

“From the point of view of low-income, African-American, and Latino residents of Venice — what does Google mean to us? Pretty much all bad news,” said Bill Przylucki, who heads People Organized for Westside Renewal (POWER), a community organization in West Los Angeles. “They are gonna displace other type of businesses that do pay taxes — they are gonna get tax breaks. That means less money for the local park, the library, the public services that we rely on. They are not gonna provide jobs to our folks. Our folks are not the people they are gonna be hiring. They are gonna drive up rents, put more pressure on our folks, and put more pressure on landlords to displace our members through evictions and demolitions.”

Przylucki says POWER approached Google to see if the company would use its influence and sheer star power to push for low-income housing in Venice and Los Angeles, and to fight against the criminalization of poverty in their neighborhood. But their attempts at cooperation went nowhere.

“They have a shitload of power,” says Przylucki. “But they didn’t show any interest whatsoever in working with that side of the community. And that silence is deafening in terms of their position.”

Google was more than just silent: Community organizations discovered that Google was almost impossible to reach or talk to in any meaningful way on a local level. The company was so centralized and opaque — and so deaf to local requests — that activists say they’ve had more success in getting giant banks and subprime lenders like Countrywide Financial to address community concerns than they’ve had in talking to Google.

This last bit is not surprising, actually.

Google has, as a matter of policy, has made it impossible to reach an actual human being in all of its other endeavors, so being unresponsive to community groups is not a surprise.

The last two paragraphs say it all:

Google’s founders Larry Page and Sergey Brin like to talk about how they want to leverage their company’s resources and immense talent pool to change the world for the better. The company wants to bring Internet connections to the poorest communities around the world and funds efforts to combat human trafficking and gender inequality.

But when confronted at its doorstep with a real societal challenge like homelessness — an issue that truly requires innovation, investment, public service, and political maneuvering — the company simply reverts to the cheapest and meanest solution on the books: hire thugs to push the problem out of sight and force other people deal with it.

Democrats Need to Learn to F%$# the Mouse

The Democratic Party has found a generally friendly reception in Hollywood, and as a result, they have been at least as supportive of draconian and stupid legislation and regulation to increase the profits of Hollywood.

The Obama administration has now taken this to its absurd extreme, and has has filed an amicus brief with the Supreme Court supporting Oracle’s claim that APIs should be copyrightable:

The Justice Department is weighing in on the hot-button intellectual property dispute between Google and Oracle, telling the Supreme Court that APIs are protected by copyright.

The Obama administration’s position means it is siding with Oracle and a federal appeals court that said application programming interfaces are subject to copyright protections. The high court in January asked for the government’s views on the closely watched case.

The dispute centers on Google copying names, declarations, and header lines of the Java APIs in Android. Oracle filed suit, and in 2012, a San Francisco federal judge sided with Google. The judge ruled that the code in question could not be copyrighted. Oracle prevailed on appeal, however. A federal appeals court ruled that the “declaring code and the structure, sequence, and organization of the API packages are entitled to copyright protection.”

Google maintained that the code at issue is not entitled to copyright protection because it constitutes a “method of operation” or “system” that allows programs to communicate with one another.

“That argument is incorrect,” the administration told the justices.

In an amicus brief, computer scientists urged (PDF) the Supreme Court to reverse last year’s appeals court decision. “The Federal Circuit’s decision poses a significant threat to the technology sector and to the public,” they wrote. “If it is allowed to stand, Oracle and others will have an unprecedented and dangerous power over the future of innovation. API creators would have veto rights over any developer who wants to create a compatible program—regardless of whether she copies any literal code from the original API implementation. That, in turn, would upset the settled business practices that have enabled the American computer industry to flourish, and choke off many of the system’s benefits to consumers.”

Does the court really want operating system vendors to pick and choose who can write software, and what sort of software can be written, on their systems.

This is nuts. The purpose of copyright is to, “To promote the Progress of Science and useful Arts,”* and there is no way that expanding copyright in this manner does anything to promote progress.

This is insane, and this sort of  IP extremism is at the heart of much that is wrong with things like the DMCA, the TPP, Evergreening, and the continual extension of copyright because Disney does not want Steamboat Willie to enter the public domain.

This is nuts.

*http://en.wikipedia.org/wiki/Copyright_Clause

I’m Shocked, Shocked to Find That Gambling Is Going on in Here


Cue Captain Renault

A whistle blower at Tiversa is alleging that the company manufactured false evidence of breaches to gin up business:

A bombshell lawsuit is raising eyebrows in the cybersecurity industry.

A former cybersecurity forensic examiner named Richard Wallace is claiming that his former employer — cybersecurity company Tiversa — “would typically make up fake data breaches to scare potential clients,” CNNMoney reports.

Wallace claims that Tiversa would routinely do this then “pressure firms to pay up” by buying its cybersecurity services, according to a federal courtroom transcript obtained by CNNMoney. This came to a head when Tiversa allegedly approached cancer testing services company LabMD about a supposed hack. LabMD refused to buy into Tiversa’s services, so Tiversa allegedly reported the cancer-testing company to the FTC for having a data breach.

………

This lawsuit raises some potentially worrisome issues about practices in the cybersecurity industry.

Gee you think?

It’s the f%$#ing Wild West out there, with no standards of what constitutes a breach, and no meaningful certification of the security firms.

People have been selling cyber Armageddon, with only one concrete example of their horror stories panning out (Stuxnet which was created by the US and Israeli government), why is it a surprise when we discover that people are selling “breaches” that are either non existent or minor.

I guess being a cybersecurity consultant beats working for a living.

I am not so Eager to Fly in a 787

One of the innovations on the aircraft is a move from hydraulic to electric actuators.

The need for higher led to the use of Lithium-Ion batteries, which are more prone to fires, and briefly grounded the aircraft.

It now appears that a counter rolling over could cause a complete loss of electrical power:

A software vulnerability in Boeing’s new 787 Dreamliner jet has the potential to cause pilots to lose control of the aircraft, possibly in mid-flight, Federal Aviation Administration officials warned airlines recently.

The bug—which is either a classic integer overflow or one very much resembling it—resides in one of the electrical systems responsible for generating power, according to memo the FAA issued last week. The vulnerability, which Boeing reported to the FAA, is triggered when a generator has been running continuously for a little more than eight months. As a result, FAA officials have adopted a new airworthiness directive (AD) that airlines will be required to follow, at least until the underlying flaw is fixed.

“This AD was prompted by the determination that a Model 787 airplane that has been powered continuously for 248 days can lose all alternating current (AC) electrical power due to the generator control units (GCUs) simultaneously going into failsafe mode,” the memo stated. “This condition is caused by a software counter internal to the GCUs that will overflow after 248 days of continuous power. We are issuing this AD to prevent loss of all AC electrical power, which could result in loss of control of the airplane.”

………

The memo doesn’t provide additional details about the underlying software bug. Informed speculation suggests it’s a signed 32-bit integer overflow that is triggered after 231 centiseconds (i.e. 248.55 days) of continuous operation.

This is computer programming 101, and it’s bullsh%$ that no one thought of this.

This was something that was present in in Windows 95 and 98 in the last millennium, where the system would crash after 49.7 days (equal to 232 milliseconds).

The embarrassing part for Microsoft was that it took about a decade before it was found, because no one could keep the systems running that long.

Seriously?  New electrics, new actuators, new structures, new manufacturing configuration, all done at the same time ……… I’m waiting for the next shoe to drop.

So, the Flash Crash Was Caused by Some Guy Living in His Parents’ Basement?

The DoJ is attempting to extradite Nav Sarao to the United States because he allegedly caused the “Flash Crash”.

While this might be significant for Mr. Sarao, this is missing the forest for the trees.

If our markets are so unstable as to be tripped into catastrophe by one guy, they are too unstable to exist in their current form:

Everyone on Wall Street has been talking about this week’s arrest of a little-known UK-based trader on allegations that he caused the May 6, 2010 “Flash Crash.”

That’s because the consensus view on the Street is that the arrest itself is absolutely ridiculous. In fact, as one trader put it, it’s “beyond ridiculous.”

Over the past few days, we’ve had several conversations with traders, quantitative analysts, and hedge fund managers. It was the topic of conversation at happy hours and charity events.

What’s more, there wasn’t a single person we spoke to who bought the argument that one guy wiped billions from the market in a matter of minutes by “spoofing” — a practice in which a trader orders a bunch of trades and then cancels them. It creates artificial demand and manipulates the price of a stock.

It’s been almost five years since the “Flash Crash” and regulators are suddenly blaming Navinder “Nav” Sarao, a 36-year-old who trades S&P futures from his mom and dad’s house in a London suburb. Yep, regulators think a guy in saggy sweatpants and Nike Airs trading from his parents’ basement did it.

It also appears that the charges are just plain bogus:

On May 6, 2010, Sarao’s algo started at 10:20:00 ET and turned off at 14:40:12. The flash crash ignition point was at 14:42:44
— Eric Scott Hunsader (@nanexllc) April 22, 2015



Spotting Sarao’s #HFT spoofing algo is like spotting an elephant at a tea party. An eMini chart on 5/6 pic.twitter.com/AN8Ov2VH7u
— Eric Scott Hunsader (@nanexllc) April 22, 2015


Round up the usual suspects!

This prosecution is all about covering up the total vulnerability in the market.

The “Flash Crash” was not a result of actions of one person. It was a result of the profit strategies of dozens, if not hundreds of actors in the markets, and they all are structured in a way that was calculated to maximize, and exploit, volatility.

The “market making” capabilities of high frequency traders is a mirage:  As soon as the market experiences upset, they pull out, and create a crash.

We need to make the markets less responsive, and create greater transaction costs.

Otherwise, instant market panics will become a routine part of our lives, and the lives of the 99% not extracting rents from the financial markets will suck.

So Not a Surprise

You know those “Cybersecurity” bills that are supposed to protect our data and our privacy?

Not so much:

Cybersecurity legislation advancing in Congress could create the first brand-new exemption to the Freedom of Information Act in nearly half a century—a prospect that alarms transparency advocates and some lawmakers.

A bill approved by the Senate Intelligence Committee last month would add a new tenth exemption to FOIA, covering all “information shared with or provided to the Federal Government” under the new measure.

Another provision in the legislation would require that “cyber threat indicators and defensive measures” which companies or individuals share with the federal government be “withheld, without discretion, from the public.” The Senate bill, which is expected to come to the floor soon, also seeks to shut off any access to that information under state or local freedom of information laws.

Two cybersecurity bills are expected to be taken up on the House floor as soon as this week. Both contain similar language about keeping confidential threat and defensive measure information turned over to the government. However, a new FOIA exemption that was in the House Intelligence Committee cyber bill was taken out, a spokesman confirmed Friday.

In an official Senate Intelligence Committee report made public over the weekend, two Democratic members of that panel objected to the new FOIA exemption, which would be the first brand-new exemption added to the landmark transparency legislation since 1967.

“We are unconvinced that it is necessary to create an entirely new exemption to the Freedom of Information Act, or FOIA,” Sens. Martin Heinrich (D-N.M.) and Mazie Hirono (D-Hawaii) wrote in a statement accompanying the panel’s report on the cyber bill. “Government transparency is critical in order for citizens to hold their elected officials and bureaucrats accountable; however, the bill’s inclusion of a new FOIA exemption is overbroad and unnecessary as the types of information shared with the government through this bill would already be exempt from unnecessary public release under current FOIA exemptions.”

………

Critics say the proposed new FOIA exemption could allow companies to block disclosure of virtually any information by anyone in the government simply by submitting that information to the new cybersecurity portal. McDermott said the narrower provisions were also troubling and have mandatory language that could preclude the government from releasing cyber-related information even when needed to warn about a danger to the general public.

McDermott also said it would set a bad precedent if a bill creating an entirely new FOIA exemption made it into law without passing through the panels which oversee that law in each chamber.

“By authorizing a new exemption to the FOIA through a committee other than the committees of jurisdiction….you’ve undermined FOIA,” she warned.

Not surprised that the Obama administration likes this a lot. His history as President is one of being a cheerleader for the overarching security state, and his jihad on whistle blowers is a national disgrace.

Someone Finally Found a Way to Beat the Lottery

Las Vegas makes billions in its casinos with the house have a house edge of 3% to 5%.

State lotteries typically have a house edge of 40% to 50%, so it is a sucker bet, and, as I have told Sharon*, only a fool plays the lottery.

Well my hats off to Eddie Ray Tipton, who has devised a winning strategy for the lottery:


Prosecutors say they have evidence indicating the former head of computer security for a state lottery association tampered with lottery computers prior to him buying a ticket that won a $14.3 million jackpot, according to a media report.

Eddie Raymond Tipton, 51, may have inserted a thumbdrive into a highly locked-down computer that’s supposed to generate the random numbers used to determine lottery winners, The Des Moines Register reported, citing court documents filed by prosecutors. At the time, Tipton was the information security director of the Multi-State Lottery Association, and he was later videotaped purchasing a Hot Lotto ticket that went on to fetch the winning $14.3 million payout.

In court documents filed last week, prosecutors said there is evidence to support the theory Tipton used his privileged position inside the lottery association to enter a locked room that housed the random number generating computers and infect them with software that allowed him to control the winning numbers. The room was enclosed in glass, could only be entered by two people at a time, and was monitored by a video camera. To prevent outside attacks, the computers aren’t connected to the Internet. Prosecutors said Tipton entered the so-called draw room on November 20, 2010, ostensibly to change the time on the computers. The cameras on that date recorded only one second per minute rather than running continuously like normal.

“Four of the five individuals who have access to control the camera’s settings will testify they did not change the cameras’ recording instructions,” prosecutors wrote. “The fifth person is defendant. It is a reasonable deduction to infer that defendant tampered with the camera equipment to have an opportunity to insert a thumbdrive into the RNG tower without detection.”

Tipton has pleaded not guilty to all charges, and his attorney has said the theory about computer tampering isn’t “factually viable.”

On December 23, a little more than a month after Tipton allegedly tampered with the computers, a man at a convenience store was video taped buying a Hot Lotto ticket that later won the $14.3 million payout. Authorities identified the man as Tipton, but as an employee of the association that administered the lottery, he was barred by law from buying lotto tickets or claiming lottery prizes. The winning ticket went unclaimed for almost a year. Hours before it was scheduled to expire, a company incorporated in Belize tried to claim the prize through a New York attorney. In January, Tipton was charged with two counts of fraud. The allegations that he used his insider access to tamper with the RNG were first made in the court documents filed last week.

Seriously, absent a TARDIS, this is about the only way to beat the lottery.

Like I said, it is a sucker bet.

*Love of my life, light of the cosmos, she who must be obeyed, my wife.
To paraphrase Bret Maverick, I do not approve of gambling, I prefer poker.

Headline of the Day

President Obama Declares the Threat to Crappy Sony Movies a National Emergency

—Marcy “Emptywheel” Wheeler

A response to Obama’s new executive order, which is vague enough to allow sanctions against pretty much anyone who publishes the data or provides privacy tools..

It is overarching, irresponsible, and fundamentally anti-democratic, which makes it a typical security policy of Obama and His Evil Minions.

But it gets worse. The EO targets not just the hackers themselves, but also those who benefit from or materially support hacks. The targeting of those who are “responsible for or complicit in … the receipt or use for commercial or competitive advantage … by a commercial entity, outside the United States of trade secrets misappropriated through cyber-enabled means, … where the misappropriation of such trade secrets is reasonably likely to result in, or has materially contributed to, a significant threat to the national security, foreign policy, or economic health or financial stability of the United States” could be used to target journalism abroad. Does WikiLeaks’ publication of secret Trans-Pacific Partnership negotiations qualify? Does Guardian’s publication of contractors’ involvement in NSA hacking?

And the EO creates a “material support” category similar to the one that, in the terrorism context, has been ripe for abuse. Its targets include those who have “provided … material, or technological support for, or goods or services in support of” such significant hacks. Does that include encryption providers? Does it include other privacy protections?

Finally, I’m generally concerned about this EO because of the way National Emergencies have served as the justification for a lot of secret spying decisions. Just about every application to the FISC for some crazy interpretation of surveillance laws in the name of counterterrorism founds their justification neither in the September 17, 2001 Finding authorizing covert actions against al Qaeda nor the September 18, 2001 AUMF, but instead in President Bush’s declaration of a National Emergency on September 14, 2001. I’m not sure precisely why, but that’s what the Executive has long used to convince FISC that it should rubber stamp expansive interpretations of surveillance law. So I assume this declaration could be too.

In other words, the sanctions regime may well be the least of this EO.

Just lovely.

OK, This is an Insanely Great Idea

A company called Openbay has come up with a a device that plugs into your car’s diagnostic port, reads the codes, and gets quotes from local mechanics:

Car maintenance, and the costs associated with auto care, is a pain point and often a total mystery for many car owners. It is also one of the last industries where the consumer has traditionally had no power over negotiations, especially once a car is in an auto repair shop.

This morning at the New York International Auto Show, auto repair marketplace startup Openbay unveiled a new product called OpenbayConnect to give consumers more power in the process of getting work done on their cars. The new device, which Openbay founder and chief executive Rob Infantino says can be installed by anyone, automatically connects a car’s computer system to diagnose problems and find a local repair shop to fix the issue through the company’s automated service recommendation engine.

………

OpenbayConnect further automates this process by diagnosing the problem through a car’s computer system – something I was charged about $70 for at the Subaru dealership – and making the auto repair shops vie for a customer’s business by offering the best deal. The company will be shipping the product to early adopters throughout the spring, but has been testing the device with a few unnamed partners with access to large fleets of cars for a few months now. For a limited amount of time, the OpenbayConnect devices will be free and won’t cost users any data costs or activation fees. Eventually, the company will sell the connected diagnosis components through its partners.

………

One specific target of OpenbayConnect is auto service customers who don’t know very much about their vehicles, see a check engine light go on, and immediately call a auto shop or dealer. Often, that customer will pay just to have their computer system checked. Many times, the problem could be as simple as low tire pressure or a loose gas cap. The automated OpenbayConnect system can diagnose exactly what the problem is and whether it warrants more extensive service, all without having to get mechanics involved.

Even if they just sold the device, so you could plug in and get the codes on your smart phone, this would be f%$#ing brilliant.

Interesting Point

Patrick Durusau makes a very interesting point, which I will reduce to bullet points: (Read the whole thing)

  • The NSA wants to arm up for offensive cyber war.
  • This means that hacking tools are a weapon.
  • If they a weapon, then they are covered by the 2nd amendment.
  • That being the case, join the NRA, and lobby against the NSA taking away our weapons.

The NRA has been a long term and successful advocate for Second Amendment rights. And they have political connections that would take years to develop. When was the last time you heard of the NRA winning symbolic victories for someone after they had been victimized? Or do you hear of victories by the NRA before their membership is harmed by legislation? Such as anti-hacking legislation.

Since the NRA is an established defender of the Second Amendment, with a lot of political clout, let’s work on expanding the definition of “arms” in the Second Amendment to include computers, knowledge of how to break encryption and security systems, etc.

The first step is to join the NRA (like everybody they listen to paying members first).

The second step is educate other NRA members and the public posed by unchecked government cyberpower. Current NRA members may die with their guns in hand but government snoops know what weapons they have, ammunition, known associates, and all of that is without gun registration. A machine pistol is a real mis-match against digital government surveillance. As in the losing side.

The third step is to start training yourself as a hacker. Setup a small network at home so you can educate yourself, off of public networks, about the weaknesses of hardware and software. Create or join computer clubs dedicated to learning hacking arts.

This is f%$#ing brilliant.

Microflaccid, Go Cheney Yourself


Click Image for Larger Popup

In Windows 8, Microsoft implemented UEFI secure boot, which was nominally a system to prevent malicious software from loading a low level, but also has the effect of making it very difficult alternate operating systems.
With Win 8, Microsoft required that the hardware vendors include an option to disable the secure mode, though it was buried in the “BIOS”* setup screen.

It appears that Microsoft will no longer require a switch to disable the lockdown, which means that it could lock out many alternate operating systems:

Those of you with long memories will recall a barrage of complaints in the run up to Windows 8’s launch that concerned the ability to install other operating systems—whether they be older versions of Windows, or alternatives such as Linux or FreeBSD—on hardware that sported a “Designed for Windows 8” logo.

To get that logo, hardware manufacturers had to fulfil a range of requirements for the systems they built, and one of those requirements had people worried. Windows 8 required machines to support a feature called UEFI Secure Boot. Secure Boot protects against malware that interferes with the boot process in order to inject itself into the operating system at a low level. When Secure Boot is enabled, the core components used to boot the machine must have correct cryptographic signatures, and the UEFI firmware verifies this before it lets the machine start. If any files have been tampered with, breaking their signature, the system won’t boot.

This is a desirable security feature, but it has an issue for alternative operating systems: if, for example, you prefer to compile your own operating system, your boot files won’t include a signature that Secure Boot will recognize and authorize, and so you won’t be able to boot your PC.

However, Microsoft’s rules for the Designed for Windows 8 logo included a solution to the problem they would cause: Microsoft also mandated that every system must have a user-accessible switch to turn Secure Boot off, thereby ensuring that computers would be compatible with other operating systems. Microsoft’s rules also required that users be able to add their own signatures and cryptographic certificates to the firmware, so that they could still have the protection that Secure Boot provides, while still having the freedom to compile their own software.

This all seemed to work, and the concerns that Linux and other operating systems would be locked out proved unfounded.

This time, however, they’re not.

At its WinHEC hardware conference in Shenzhen, China, Microsoft talked about the hardware requirements for Windows 10. The precise final specs are not available yet, so all this is somewhat subject to change, but right now, Microsoft says that the switch to allow Secure Boot to be turned off is now optional. Hardware can be Designed for Windows 10 and can offer no way to opt out of the Secure Boot lock down.

If I am a mass market computer maker, there is no upside to allowing a user to disable UEFI secure boot unless you are specifically are targeting power users.

While this may not be a big deal, for anyone who, for example, wants to retask a old or used PC as a firewall, or a print server, etc., it is likely that the choice of operating systems will be severely constrained.

It’s good for the business of PC manufacturers, it means that used machines are less likely to be repurposed or resold, and it is good for Microsoft, because it means that installing many flavors of Linux on an old box becomes problematic.

For the rest of us, it sucks like a thousand Hoovers all going at once.

*Technically, UEFI is not BIOS, it replaces the exclusively 16 bit BIOS, but “BIOS Setup Screen” is a good shorthand for that screen you get when you hold down the F2 key while booting.

Tech Headline of the Day

Nine reasons only a tool would buy the Apple Watch.

While Apple has had its share of failures, the Newton comes to mind, but the Apple Watch is the first time I’ve seen an Apple product reviled as lame pander to “Trustifarian” rich kids.

Since the original MacIntosh, Apple has always sold its products on its chic elegance and its tightly controlled (and intuitive) interface, but it has always had a subtext of Apple producing “The Computer for the rest of us.”

This is not “The Computer for the rest of us”.

What has attracted the most attention is the $17,000 (£13,500) solid gold version, and it casts the entire watch product line as a bloated Veblin good.*

People like status objects, but they do not like to be made fools of, and this product screams, “More money than brains.”

*Named after economist Thorstein Veblin, who in his seminal work The Theory of the Leisure Class, coined the term “Conspicuous consumption”, and detailed how some items, like a solid gold Apple Watch, serve no purpose beyond status markers.

Obama Wants More Dead Aaron Swartzes

At the State of the Union address, Obama will announce plans to increase penalties and increase the penalties and broaden the scope of the already over-broad Computer Fraud and Abuse Act (CFPA):

The Obama administration, currently engaged in a war of words with North Korea over the recent hacking of Sony Pictures Entertainment, is calling on Congress to increase prison sentences for hackers and to expand the definition of hacking.

During next week’s State of the Union address, the president is set to publicly urge increased prison time and other changes to the Computer Fraud and Abuse Act—the statute that was used to prosecute Internet activist Aaron Swartz before he committed suicide in 2013.

The Obama administration, currently engaged in a war of words with North Korea over the recent hacking of Sony Pictures Entertainment, is calling on Congress to increase prison sentences for hackers and to expand the definition of hacking.

During next week’s State of the Union address, the president is set to publicly urge increased prison time and other changes to the Computer Fraud and Abuse Act—the statute that was used to prosecute Internet activist Aaron Swartz before he committed suicide in 2013.

………

Among other things, penalties under Obama’s plan would increase from a maximum five-year penalty to 10 years for pure hacking acts, like circumventing a technological barrier. What’s more, the law would expand the definition of what “exceeds authorized access” means. A hacker would exceed authorization when accessing information “for a purpose that the accesser knows is not authorized by the computer owner.”

So, under Obama’s proposal, if you browse Facebook on a work computer, that’s 10 years in the slam.

Note that Aaron Swartz was driven to suicide by an abusive prosecution using the current (far less broad and far less punitive) version of the CFPA.

The CFPA is already a petri dish for overzealous prosecution, and Obama wants to make it worse.

Seriously, has there been a single case where Obama has not chosen the most authoritarian option?

Shorter FBI: It was da Norks, Trust Us

Yeah.

I haven’t bought that since J. Edgar Hoover bought his first slip:

The director of the FBI has defended his bureau’s claim that the hacking attack against Sony Pictures was the work of the North Korean government – saying skeptics “don’t have the facts that I have.”

Speaking at a cybersecurity conference at Fordham University in New York City on Wednesday, FBI boss James Comey said he has “very high confidence” that Pyongyang was responsible for the comprehensive ransacking of the movie studio’s servers.

When asked why security experts favor a different explanation – that the attack was probably the work of disgruntled insiders or former employees – Comey said, “They don’t have the facts that I have, don’t see what I see.”

That’s true, because the FBI has remained tight-lipped as to the exact evidence that it believes links the Sony incident to North Korea. But on Wednesday, Comey offered the most detailed explanation yet of the government’s reasoning.

When the group calling itself Guardians of Peace sent threatening emails and made other online statements, Comey said, it mostly used proxy servers to disguise the messages’ origins. “But several times, they got sloppy,” he claimed.

On those occasions, he said, the group sent messages from servers with IP addresses “that were exclusively used by the North Koreans,” giving law enforcement a “very clear indication of who was doing this.”

This makes no sense at all.

It’s a pain in the ass to set up this kind of stuff, but once you do, you would have to actively decide to screw this up.

As the article notes:

Public IP network addresses, by themselves, are a poor indicator of the true origin of internet attacks, due to the ease with which traffic can be spoofed or routed through multiple networks. For this reason, infosec professionals remain skeptical the Kim government is responsible for the Sony Pictures hack.

How much do you want to guess that the hackers “got sloppy” only after the DPRK got fingered?

I ain’t buying it.

Given the history of stove-piping by the US state security apparatus, I need something beyond, “If you knew what I do.”

There is Stupid, Wicked Stupid, and US Army Stupid

And in the annals of stupid things said by Generals, it appears that the US Army is considering exempting cyber warfare recruits from combat training:

New US Army cyber warriors could be spared the rigours of combat training to help the Pentagon attract badly needed recruits from the ponytail wearing Google generation, a top American general has suggested.

Lt Gen Robert Brown said the US Army had to recruit people who were not typical candidates for a military career if it was to attract the right skills to wage cyber war.

This is a naked attempt to gbrab cyber security budget dollars.

Some of the proposals listed later in the article, such as not mindlessly rotating soldiers through different responsibilities and allowing them to accumulate technical expertise, make some sense, but if they are not combat trained, they are Pentagon employees, not soldiers.

Don’t Jump to Conclusions on the Sony Hack

Bruce Schneier, perhaps the most prominent security pundit in the world, is dubious about the FBI’s claim that the DPRK is behind the Sony Hack, while Kurt Stammberger, the senior VP Norse, a cybersecurity firm, insists that all evidence points to an internal hack:

Cybersecurity experts are questioning the FBI’s claim that North Korea is responsible for the hack that crippled Sony Pictures. Kurt Stammberger, a senior vice president with cybersecurity firm Norse, told CBS News his company has data that doubts some of the FBI’s findings.

“Sony was not just hacked, this is a company that was essentially nuked from the inside,” said Stammberger.

While Norse is not involved in the Sony case, it has done its own investigation.

“We are very confident that this was not an attack master-minded by North Korea and that insiders were key to the implementation of one of the most devastating attacks in history,” said Stammberger.

He says Norse data is pointing towards a woman who calls herself “Lena” and claims to be connected with the so-called “Guardians of Peace” hacking group. Norse believes it’s identified this woman as someone who worked at Sony in Los Angeles for ten years until leaving the company this past May.

I’m inclined not to believe the official story from the FBI.

The sketchy accounts currently given by the FBI seem to indicate that they worked backward, starting with the guilt of North Korea, and then picking and choosing evidence on that basis.

The Tor Anonymity Network Just Got Hacked by Law Enforcement

Paul Carr at Pando has been writing a lot about potential security issues with TOR, both issues with the ties between the founders and the US state security apparatus, and possible technical issues.

One of the ones that he has mentioned is the compromise of their exit nodes or their directory authorities.

It now appears that a large cluster of exit nodes has been seized by the authorities:

Earlier this week, we reported on an apparent threat by an unnamed agency to disable the Tor anonymity network.

According to founder Roger Dingledine:

The Tor Project has learned that there may be an attempt to incapacitate our network in the next few days through the seizure of specialized servers in the network called directory authorities.

This is not the current problem though,  it appears that some of the exit nodes have been seized by the authorities:

Today, Thomas White who operates “a large exit node cluster for the Tor network and [a] collection of mirrors,” reports that his servers have apparently been compromised.

Tonight there has been some unusual activity taking place and I have now lost control of all servers under the ISP and my account has been suspended. Having reviewed the last available information of the sensors, the chassis of the servers was opened and an unknown USB device was plugged in only 30-60 seconds before the connection was broken. From experience I know this trend of activity is similar to the protocol of sophisticated law enforcement who carry out a search and seizure of running servers.

White warns “Do NOT use my mirrors/services until I have reviewed the situation,” adding:

At this moment in time I am under no gagging orders or influence from external parties/agencies. If no update is provided within 48 hours you may draw your own conclusions.

Needless to say if you rely on TOR for some sort of crucial secure communications, I would suggest that you find some other method, or go dark, over the short term.

I know a guy with a carrier pigeon.

Crap! I Guess that I’m Actually Watch this Damn Film Now

For the 2nd time in my life,* threats of terrorism have pulled a major motion picture from release.

I guess that I

This time it’s for the James Franco and Seth Rogen farce The Interview that has been pulled from screens:

Sony Pictures Entertainment on Wednesday dropped plans for its Christmas Day release of “The Interview,” a movie that depicts the assassination of the North Korean leader Kim Jong-un, after receiving a terror threat against theaters.

Before that, the four largest theater chains in the United States said they would not show the movie, which has been at the center of a devastating hacking attack on Sony over the last several weeks. In a statement, Sony said: “We respect and understand our partners’ decision and, of course, completely share their paramount interest in the safety of employees and theatergoers.”

Sony Pictures Entertainment on Wednesday dropped plans for its Christmas Day release of “The Interview,” a movie that depicts the assassination of the North Korean leader Kim Jong-un, after receiving a terror threat against theaters.

Before that, the four largest theater chains in the United States said they would not show the movie, which has been at the center of a devastating hacking attack on Sony over the last several weeks. In a statement, Sony said: “We respect and understand our partners’ decision and, of course, completely share their paramount interest in the safety of employees and theatergoers.”

Hollywood executives never miss a chance to choose the craven path, I guess.

In a development that should surprise no one, “Senior Administration Officials” have confirmed that the hack originated in the DPRK.

BTW, James Franco had the best tweet about the cancellation:

#Emmastone kills it in @cabaret!!!! #alancumming is so good I started smoking and slapped his ass. 🌲🌲❤️Bye NYC!❤️🌲🌲
— James Franco (@JamesFrancoTV) December 17, 2014

That is so cool.

For the irony impaired, he tweeted this after the film was puled, and he says nothing at all about this.

Epically cool!

*The first time was when the film Mohammad, Messenger of God was pulled as a result of the 1977 Hanafi Siege, where hostages were taken in Washington, DC.