<?xml version="1.0" encoding="UTF-8"?>
<opml version="1.0">
  <head>
    <title>cmdln.net_2008-05-04</title>
    <expansionState>0,1,8,15,16,32,49,50,56,60,63,74,81,97,125,142,143,151,159,170,171,179</expansionState>
  </head>
  <body>
    <outline text="Intro" Offset="00:17">
      <outline text="Free comic day">
        <outline text="Rushed because of movie"/>
        <outline text="Kids only picked up a few titles"/>
        <outline text="Returned today for a little more perusing"/>
        <outline text="Shop still had free table out"/>
        <outline text="I picked up Supreme Power, Rising Star"/>
        <outline text="Read first volume of Supreme Power, enjoying"/>
      </outline>
      <outline text="Iron Man">
        <outline text="Ultimate techie hero"/>
        <outline text="Safe for younger kids despite rating"/>
        <outline text="When hero returns to middle east, gets a bit intense"/>
        <outline text="Otherwise, comparable to Transformers"/>
        <outline text="We all enjoyed it thoroughly"/>
        <outline text="For a two hour movie, felt way shorter, very well paced"/>
      </outline>
    </outline>
    <outline text="Security Alerts" Offset="05:48">
      <outline text="EULAs for malware" Offset="06:07">
        <outline text="http://arstechnica.com/news.ars/post/20080428-malware-authors-turn-to-eulas-to-protect-their-work.html"/>
        <outline text="Consistent with increasing commercialization of malware"/>
        <outline text="Researchers discovered this in help section of Zeus malware"/>
        <outline text="Malware with help?"/>
        <outline text="Forbids use with other botnets"/>
        <outline text="Precludes source code examination or sending to antivirus companies"/>
        <outline text="Also claims to lock user into paying for upgrades"/>
        <outline text="Aimed at spammers, others not at the infected system"/>
        <outline text="Enforcement seems to be through withdrawal of technical support"/>
        <outline text="Also threat of author sending code to antivirus makers"/>
        <outline text="Latter seems particular effective, guts the customer's ability to use"/>
        <outline text="Most coverage is laughing off"/>
        <outline text="True cannot legally enforce without getting entrapped"/>
        <outline text="But threats are realistic"/>
        <outline text="May just be copying the form to communicate the threats"/>
      </outline>
      <outline text="Security risks of social networking applications" Offset="08:51">
        <outline text="http://feeds.wired.com/~r/wired/topheadlines/~3/279590114/NOT_SO_PRIVATE"/>
        <outline text="The problem are the third party applications"/>
        <outline text="MySpace has added its own app platform to compete"/>
        <outline text="To use apps, you need to share some or all of your profile"/>
        <outline text="Users are unaccustomed to thinking of these as separate from main provider"/>
        <outline text="Reality is few if any of these applications are built by provider"/>
        <outline text="Means much personal data is being spread, without thought"/>
        <outline text="Providers claim to boot problematic app developers"/>
        <outline text="It is an honor system, though, so not very strict, secure"/>
        <outline text="Reality is both providers, app developers benefit from personal data sharing"/>
        <outline text="Provider gets more apps, draws and keeps more users"/>
        <outline text="Also enhances page views"/>
        <outline text="App developers get to embed own ads, building their own revenue"/>
        <outline text="No one involved has a strong incentive to protect or even react"/>
        <outline text="Problem ultimately is that even though users guard profiles, unaware of how that gets shared"/>
        <outline text="No one has been talking about app developers getting access to data"/>
      </outline>
    </outline>
    <outline text="News" Offset="11:58">
      <outline text="Hans Reiser found guilty" Offset="12:12">
        <outline text="http://blog.wired.com/27bstroke6/2008/04/reiser-guilty-o.html"/>
        <outline text="Wife, Nina, went missing"/>
        <outline text="History of animosity between Hans and Nina"/>
        <outline text="Loads on circumstantial evidence"/>
        <outline text="Small traces of blood in his car, house"/>
        <outline text="Odd behavior">
          <outline text="Removing his passenger seat, hosing out his car"/>
          <outline text="Books on police murder investigation"/>
          <outline text="Using counter surveillance techniques"/>
        </outline>
        <outline text="Reiser's attempts to explain are classic geek">
          <outline text="Disbelieving of why he's suspected"/>
          <outline text="Didn't get that his own internal logic was not self evident to others"/>
        </outline>
        <outline text="Defense tried to use that to their advantage">
          <outline text="Not so unheard of"/>
          <outline text="Asperger is common amongst techies"/>
        </outline>
        <outline text="Jury clearly didn't buy it"/>
        <outline text="By the end, the judge was antagonistic"/>
        <outline text="Complained of Reiser being overly arrogant"/>
        <outline text="Hard to know what the jury saw that we didn't"/>
        <outline text="From second hand, seems like the case was won on circumstantial evidence, Reiser's demeanor"/>
        <outline text="Prosecution did call 60 witnesses, who knows entirely what they said?"/>
        <outline text="Did those witness include anyone else with similar geek personality?"/>
        <outline text="Man is being sent to prison for 25 to life at least partly because he's too much a geek"/>
      </outline>
      <outline text="Implementing JVM and Ruby VM in JavaScript" Offset="15:40">
        <outline text="http://rss.slashdot.org/~r/slashdot/eqWf/~3/279591849/article.pl"/>
        <outline text="Reminds me of story from 11/05, Unix in JavaScript"/>
        <outline text="http://thecommandline.net/2005/11/20/unix-in-javascript/"/>
        <outline text="Japanese project called Orto"/>
        <outline text="Takes compiled byte code and generates JavaScript"/>
        <outline text="Article includes some samples"/>
        <outline text="Shows the output is targeted at being interpreter readable">
          <outline text="Not at all human readable"/>
          <outline text="If Java sources are available, though, idea is probably to regenerate from that"/>
        </outline>
        <outline text="Surprised that it converted threaded code"/>
        <outline text="Author claims the demo was very performant"/>
        <outline text="Suspect this is more than a curiosity"/>
        <outline text="Seems complementary to GWT"/>
        <outline text="GWT compiles Java to JS within the context of a framework"/>
        <outline text="This seems to be a more general solution"/>
        <outline text="Although its Java support is limited, output only relies in JS interpreter"/>
        <outline text="Could easily see this being used for new RIA efforts"/>
        <outline text="Ruby is even more interesting"/>
        <outline text="This is an actual VM in JS, consumes Ruby opcodes"/>
        <outline text="According to article, AJAX call to parse Ruby source to opcodes"/>
        <outline text="This is also surprisingly fast"/>
        <outline text="Would seem to offer the first ability to do GWT like RIA but with Ruby"/>
      </outline>
      <outline text="Tracking down kill switches in ICs" Offset="19:37">
        <outline text="http://spectrum.ieee.org/may08/6171"/>
        <outline text="Stems from an Israel air strike against a Syrian target"/>
        <outline text="Syrian radar system mysteriously failed"/>
        <outline text="System supposedly used off the shelf components"/>
        <outline text="Much speculation that such components had a hidden kill switch or back door"/>
        <outline text="An anonymous source claims a European chipmaker has done such a thing"/>
        <outline text="Thinking by customer, French government, was to have a way to disable if sold on the black market"/>
        <outline text="IEEE Spectrum unable to confirm story"/>
        <outline text="Regardless of truth, there is genuine risk"/>
        <outline text="Much chip manufacture is now done abroad"/>
        <outline text="How do you verify security of critical components?"/>
        <outline text="This is another wrinkle on the secure computing discussion from Penguicon"/>
        <outline text="We hadn't considered remote kill switches, but same single point of failure"/>
        <outline text="DARPA has started a project to assess chips"/>
        <outline text="Early this year, it starts it first live tests with four chips to three contractors"/>
        <outline text="This is a known malicious attack but otherwise real world"/>
        <outline text="This is a vast, combinatorial problem"/>
        <outline text="Article explains how, why it is not feasible to test every element on a chip"/>
        <outline text="Also has a good description of the history"/>
        <outline text="How the industry has gone overseas for cost"/>
        <outline text="Also that DOD used to have its own FAB, shut down in 80s for costs"/>
        <outline text="DOD now likes the cost, feature advantages of off the shelf"/>
        <outline text="Cheaper initiatives, trusted foundries, don't solve problem either"/>
        <outline text="Still possible to slip in bogus design elements, other things that only chip level testing would catch"/>
        <outline text="The severity of this attack is extreme"/>
        <outline text="What is the likelihood?"/>
        <outline text="Even though testing is hugely difficult, the sort of tampering speculated also seems very costly"/>
      </outline>
      <outline text="Missing link circuit developed" Offset="24:43">
        <outline text="http://arstechnica.com/news.ars/post/20080501-maintaining-moores-law-with-new-memristor-circuits.html"/>
        <outline text="Use three components in electronics: capacitor, resistor and inductor"/>
        <outline text="Relate three out of four aspects of electricity"/>
        <outline text="In 1971, Leon Chua at Berkely suggested a fourth may be possible"/>
        <outline text="Manages missing relation between magnetic flux and charge"/>
        <outline text="Math reveals the relationship is not direct, more a function of variable resistance to charge"/>
        <outline text="Group at HP adapted technology for oxygen sensors"/>
        <outline text="Using similar technology, able to store 100 gigabits on a single die in one square centimeter"/>
        <outline text="Surpasses flash and approaches traditional hard disks"/>
        <outline text="Competing with IBM's race track memory"/>
        <outline text="Track memory has unfavorable thermal problems, though"/>
        <outline text="May scale up to terabits per square inch"/>
        <outline text="Memristance, relation between magnetic flux and charge, may improve at smaller scales, higher thermal loads"/>
        <outline text="Possible to build analog processors, like neural nets"/>
        <outline text="May help overcome issues with decreasing die sizes"/>
        <outline text="Not sure what the cost to emulate digital computers on analog processor would be though"/>
      </outline>
    </outline>
    <outline text="tail -f" Offset="28:36">
      <outline text="Judge rejects making available claim in Howell" Offset="28:56">
        <outline text="http://techdirt.com/articles/20080429/125025979.shtml"/>
        <outline text="This was the case where press misinterpreted RIAA statements"/>
        <outline text="Believed RIAA was saying ripping CDs is illegal"/>
        <outline text="Not relevant to the case, not being claimed specifically"/>
        <outline text="RIAA asked for summary judgement based on making available theory"/>
        <outline text="Judge rejected summary judgement, case will proceed to trial later this year"/>
        <outline text="Otherwise, this is a typical, boiler plate file sharing case"/>
        <outline text="Patry on Howell ruling">
          <outline text="http://williampatry.blogspot.com/2008/04/atlantic-recording-corp-v-howell.html"/>
          <outline text="Largely agrees with ruling"/>
          <outline text="Calls judge to task for enabling RIAA's use of MediaSentry"/>
          <outline text="Supports that MediaSentry's downloads alone are sufficient evidence of infringement"/>
          <outline text="Problem is that RIAA authorized downloads, should bar them as evidence of unauthorized use"/>
          <outline text="Burden should rest on RIAA to prove actual infringement by other than its captive investigators"/>
          <outline text="At least judge ruled claims need to be actual transfer"/>
        </outline>
      </outline>
      <outline text="Radiohead won't repeat free experiment" Offset="31:24">
        <outline text="http://go.theregister.com/feed/www.theregister.co.uk/2008/04/30/radiohead_in_rainbows/"/>
        <outline text="Many want to interpret this as a failure of experiment"/>
        <outline text="No such wording in Yorke's statement"/>
        <outline text="Simple seems to be realizing it was a moment in time, hard to reproduce"/>
        <outline text="May also have something to do with solid sales of physical CDs"/>
        <outline text="Article also points at combo offerings like NiN Ghosts"/>
        <outline text="The proof will be what they actually do with next album"/>
        <outline text="Even if Radiohead doesn't repeat, doesn't mean anything for the trend as a whole"/>
        <outline text="Many have and are succeeding"/>
        <outline text="This is just one of the more high profile cases"/>
      </outline>
    </outline>
    <outline text="Outro" Offset="33:19">
      <outline text="Contact me">
        <outline text="Email to feedback@thecommandline.net"/>
        <outline text="Web site at http://thecommandline.net/"/>
        <outline text="IM to command.line@skype"/>
        <outline text="Listener comment line is 240-949-2638"/>
        <outline text="del.icio.us tag is &quot;for:cmdln&quot;"/>
        <outline text="http://twitter.com/cmdln"/>
      </outline>
      <outline text="I'd like to thank libsyn.com for AAC hosting and Wouter de Bie for MP3 hosting"/>
      <outline text="These notes and the show audio and music are covered by a Creative Commons license">
        <outline text="http://creativecommons.org/licenses/by-nc-sa/3.0/us/"/>
        <outline text="Attribution, non-commercial, share alike"/>
      </outline>
    </outline>
  </body>
</opml>
