<?xml version="1.0" encoding="UTF-8"?>
<opml version="1.0">
  <head>
    <title>cmdln.net_2008-02-03</title>
    <expansionState>0,1,12,13,25,36,37,60,82,90,107,129,130,140,150,151,159</expansionState>
  </head>
  <body>
    <outline text="Intro" Offset="00:17">
      <outline text="Men of Tomorrow, Gerard Jones">
        <outline text="I have been reading comics on and off since high school"/>
        <outline text="Only had some peripheral awareness of their history"/>
        <outline text="This books goes all the way back to before their start"/>
        <outline text="Appeals to me for the same reason history of computers does"/>
        <outline text="More than history, explains the culture"/>
        <outline text="Jones does an exemplary job of characterize the original artists, writers"/>
        <outline text="Draws through their experiences into fandom more generally"/>
        <outline text="Paints a compelling picture of why the form endures"/>
        <outline text="Why comic heros are constantly re-invented into newer media"/>
        <outline text="Also why new artists are drawn into the field"/>
      </outline>
    </outline>
    <outline text="Security Alerts" Offset="03:29">
      <outline text="Patch fixes issues with SkypeFind" Offset="03:48">
        <outline text="http://go.theregister.com/feed/www.theregister.co.uk/2008/02/01/skypefind_security_bug/"/>
        <outline text="SkypeFind is some sort of social, recommendation feature"/>
        <outline text="Never used it myself"/>
        <outline text="Problem is an input sanitization flaw"/>
        <outline text="Despite patch, researcher who found issue says it is still vulnerable, Aviv Raff"/>
        <outline text="Other inputs are sanitized correctly, making this more puzzling"/>
        <outline text="Sounds similar to CSS vulnerability or code injection"/>
        <outline text="It is also apparently possible to use the Skype URI protocol handler to create a worm"/>
        <outline text="This bypasses the usual contact request auth"/>
        <outline text="Skype claims that is sufficient protection"/>
        <outline text="Sounds like even better reason not to use SkypeFind"/>
      </outline>
      <outline text="Gmail vulnerability despite SSL" Offset="06:16">
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/227408479/20080201-report-google-mail-vulnerable-to-sidejacking-despite-ssl.html"/>
        <outline text="Issues raised by Robert Graham, research and CEO of Errata Security"/>
        <outline text="Appears to be with public WiFi hot spots"/>
        <outline text="Session cookie interception"/>
        <outline text="Made possible because most portals secure login, but not after"/>
        <outline text="Applications, sites that allow it should be explicitly run through https"/>
        <outline text="Gmail, however, seems to foil this attempt to secure"/>
        <outline text="Uses AJAX, if SSL fails, quietly defaults to plain text"/>
        <outline text="Other sites, applications vulnerable"/>
        <outline text="In order for full SSL to be effective, applications cannot fall back to plain text"/>
      </outline>
    </outline>
    <outline text="News" Offset="09:09">
      <outline text="German government trying to crack Skype encryption" Offset="09:18">
        <outline text="http://techdirt.com/articles/20080127/10382079.shtml"/>
        <outline text="Wikileaks along with German pirate party secured two scanned documents"/>
        <outline text="Details activities of Bavarian police, ministry of just, prosecution office"/>
        <outline text="Talks about cost of software, from Digitask, for interception"/>
        <outline text="One form is an installable client"/>
        <outline text="Also offered a recording proxy, support for real time streaming"/>
        <outline text="Details reveal high cost, hence discussing of office splitting cost"/>
        <outline text="Also vendor suggests malware for delivery onto target system"/>
        <outline text="Tim Lee suggests this is proof Skype encryption is still to costly to break"/>
        <outline text="Admits NSA may not find it so"/>
        <outline text="That was my first thought, that cost may vary based on agency"/>
        <outline text="Encryption may yield short term protection"/>
        <outline text="In the past, laws limited cryptography"/>
        <outline text="I would suggest widespread use of crypto may invite such laws again"/>
        <outline text="Also, admins already blocking Skype because of crypto"/>
        <outline text="Invites liability"/>
        <outline text="Similar issues arise with crypto and net neutrality"/>
        <outline text="Does suggest law enforcers observe similar priorities as attackers"/>
        <outline text="Crypto points out what not to attack"/>
        <outline text="Much malware relies on social tricks or other weaknesses"/>
        <outline text="Law enforcers should follow suit"/>
        <outline text="Don't mean using malware, but studying second order affects, data"/>
      </outline>
      <outline text="Better than free" Offset="14:41">
        <outline text="http://www.kk.org/thetechnium/archives/2008/01/better_than_fre.php"/>
        <outline text="Editorial by Kevin Kelly"/>
        <outline text="Assumes copies are ubiquitous, free"/>
        <outline text="Like Doctorow, doesn't think this will ever reverse"/>
        <outline text="Considers a positive question, on what is value based when copies are free?"/>
        <outline text="What qualities cannot be copied but can be valued?"/>
        <outline text="Immediacy, lie film on opening night, hardcover edition of a book"/>
        <outline text="Personalization, increased cost of learning, tailoring"/>
        <outline text="Interpretation, uses the example of docs, support for free software"/>
        <outline text="Authenticity, a little bit of a credence good"/>
        <outline text="Accssibility, uses the example of music subscription, I would term this more convenience"/>
        <outline text="Embodiment, like a print edition or a live performance"/>
        <outline text="Patronage, a little less tangible but the will of the audience to reward the creator"/>
        <outline text="Findability, I would call this discovery, exists outside the good, though"/>
        <outline text="Uses the last to point of some aspect of traditional distribution will never go away"/>
        <outline text="Trading in attention rather than goods, though"/>
        <outline text="Identifies attention as the new currency"/>
        <outline text="Sees advertising as one form of attention bartering"/>
        <outline text="Sees his eight qualities as critical, regardless"/>
        <outline text="Begs new skill set, I would extrapolate to new business models, too"/>
        <outline text="Gives some positive hints of what form these will take, though"/>
      </outline>
      <outline text="Security vs. privacy, real motivations" Offset="20:05">
        <outline text="http://www.schneier.com/blog/archives/2008/01/security_vs_pri.html"/>
        <outline text="Takes director of national intelligence, Michael McConnell to task"/>
        <outline text="Based on a New Yorker article"/>
        <outline text="Problematic contention is that privacy, security are zero sum"/>
        <outline text="Means you can only improve one at the expense of the other"/>
        <outline text="Points to police states as a counter example"/>
        <outline text="Security only affects privacy when it is based on identity"/>
        <outline text="None of the really effective security measures for air lines after 9/11 are identity based">
          <outline text="Reinforced cockpit doors"/>
          <outline text="Passengers realizing they can and must fight back"/>
          <outline text="Sky marshals posted on random flights"/>
        </outline>
        <outline text="Identity based efforts may even harm security"/>
        <outline text="Reports of success are false or against non-existent threats"/>
        <outline text="Real conflict is liberty versus control"/>
        <outline text="False dichotomy begs a choice that enhances control"/>
        <outline text="&quot;There is no security without privacy. And liberty requires both security and privacy.&quot;"/>
        <outline text="Lots of citations"/>
        <outline text="Clearly explains what I have felt intuitively throughout"/>
        <outline text="Doesn't explain why, though"/>
        <outline text="Control argument may feel conspiratorial, but a better explanation?"/>
        <outline text="Urge for control may not even be conscious"/>
        <outline text="May be a rationalization, dealing with cognitive dissonance"/>
        <outline text="Leaders feel they are in the right, but without a rational basis, hard to justify"/>
        <outline text="Security threats as an after the fact justification"/>
      </outline>
      <outline text="Best examples of programming as art" Offset="24:00">
        <outline text="http://www.iheartchaos.com/2008/01/28/programming-as-an-art-form/"/>
        <outline text="Talking about demos developed by software crackers"/>
        <outline text="Started as graphical calling cards, intros by whoever cracked a program"/>
        <outline text="Became its own standalone program of interest"/>
        <outline text="Because of age, machines at the time were pretty much the same"/>
        <outline text="Differences in programming were more telling"/>
        <outline text="Highly competitive, to show off best skills"/>
        <outline text="Also to highlight differences between classes of machine, like Atari, Amiga"/>
        <outline text="Even with the ability to replicate in 3D art tools, still about efficiency"/>
        <outline text="A render file might be 100s of MB, a demo 100s of KB"/>
        <outline text="General tool may have lots of waste, unneeded parts"/>
        <outline text="The result, the render is the important part, so the waste is not important"/>
        <outline text="A demo has to do all it does as it runs"/>
        <outline text="Links to the programs, all are Windows only"/>
        <outline text="Most of the flash videos are very high quality"/>
        <outline text="Reminds me of film festival quality shorts"/>
        <outline text="Some are not safe for work"/>
        <outline text="All seem to share a taste for electronica, dance music"/>
        <outline text="The fact that there is a small-ish program generating it all adds an additional level of appreciation"/>
        <outline text="Would be nice if some also shared sources"/>
        <outline text="Appreciate the code itself, too"/>
      </outline>
    </outline>
    <outline text="tail -f" Offset="28:17">
      <outline text="Open access reserve met" Offset="28:36">
        <outline text="http://go.theregister.com/feed/www.theregister.co.uk/2008/01/31/700mhz_band_will_be_open/"/>
        <outline text="C block reserve, 4.6B USD has been met"/>
        <outline text="Don't know who triggered the clause"/>
        <outline text="Register bets it is Google"/>
        <outline text="This is consistent with others' speculation"/>
        <outline text="AT&amp;T, Verizon and Google are Register's favored contenders"/>
        <outline text="Open access terms are a compromise, Google, other tech companies wanted more"/>
        <outline text="Not sure when the auction ends, when we'll know who won"/>
        <outline text="Will never know who met the reserve"/>
      </outline>
      <outline text="KODA expands CC licensing support" Offset="30:28">
        <outline text="http://creativecommons.org/weblog/entry/8012"/>
        <outline text="KODA allowed Tone, Urlyd to use CC license while still collecting for radio play"/>
        <outline text="KODA is now offering CC NC licenses to all its members"/>
        <outline text="Second country to do so"/>
        <outline text="The Netherlands did so first, through Buma/Stemra"/>
        <outline text="The Netherlands is definitely very progressive on many fronts"/>
        <outline text="Still, further examples of effective dual licensing"/>
        <outline text="Limited to NC licenses, only"/>
        <outline text="Hopefully more countries will follow"/>
      </outline>
    </outline>
    <outline text="Outro" Offset="32:34">
      <outline text="Contact me">
        <outline text="Email to feedback@thecommandline.net"/>
        <outline text="Web site at http://thecommandline.net/"/>
        <outline text="IM to command.line@skype"/>
        <outline text="Listener comment line is 240-949-2638"/>
        <outline text="del.icio.us tag is &quot;for:cmdln&quot;"/>
        <outline text="http://twitter.com/cmdln"/>
      </outline>
      <outline text="I'd like to thank libsyn.com for AAC hosting and Wouter de Bie for MP3 hosting"/>
      <outline text="These notes and the show audio and music are covered by a Creative Commons license">
        <outline text="http://creativecommons.org/licenses/by-nc-sa/3.0/us/"/>
        <outline text="Attribution, non-commercial, share alike"/>
      </outline>
    </outline>
  </body>
</opml>
