<?xml version="1.0" encoding="UTF-8"?>
<opml version="1.0">
  <head>
    <title>cmdln.net_2008-05-18</title>
    <expansionState>0,1,5,6,18,32,33,36,41,59,64,81,88,91,103,118,127,128,140,147,148,156</expansionState>
  </head>
  <body>
    <outline text="Intro" Offset="00:17">
      <outline text="Balticon this coming weekend">
        <outline text="No news show on 5/25"/>
        <outline text="Was originally going to skip this week's feature"/>
        <outline text="Lucked into an interview, will keep that as a surprise for Wednesday"/>
      </outline>
    </outline>
    <outline text="Security Alerts" Offset="02:35">
      <outline text="Debian fixes serious crypto bug" Offset="02:55">
        <outline text="http://go.theregister.com/feed/www.theregister.co.uk/2008/05/13/debian_openssl_bug/"/>
        <outline text="This is a bug in the pseudo random number generator"/>
        <outline text="Results in predictable keys being generated for OpenSSL"/>
        <outline text="In versions starting with 0.9.8c-1, as early as September 2006"/>
        <outline text="Affects anything that uses OpenSSL for key generation, including SSH"/>
        <outline text="Debian has issued a patch"/>
        <outline text="Admins will need to regenerate keys after patching"/>
        <outline text="Open questions whether this is a Debian specific problem"/>
        <outline text="One investigator traced it to a Debian specific attempt to silence a debugger warnng"/>
        <outline text="Another suggests it may be a problem with OpenSSL itself, dating from May 2006"/>
        <outline text="No confirmation of the latter as of yet"/>
      </outline>
      <outline text="Secure PayPal page has been cracked" Offset="05:19">
        <outline text="http://go.theregister.com/feed/www.theregister.co.uk/2008/05/16/paypal_page_succumbs_to_xss/"/>
        <outline text="A serious scripting error has been discovered with PayPal"/>
        <outline text="Could allow more convincing spoofs of their page"/>
        <outline text="This despite using new SSL extensions"/>
        <outline text="This is the feature that turns the address bar green in certain browsers"/>
        <outline text="Finnish researcher Harry Sintonen was able to inject content into such a protected page"/>
        <outline text="Doubly dangerous for those that put too much stock into the SSL extension"/>
        <outline text="eBay has not addressed yet despite fairly comprehensive proof of concept"/>
        <outline text="Article details several demonstrations that could steal a wide variety of data"/>
        <outline text="PayPal has said they are looking into it, don't believe has been exploited yet"/>
        <outline text="This extended validation SSL was at the heart of PayPal saying they wouldn't support Safari"/>
        <outline text="More of a blanket statement about browser support for the extension"/>
        <outline text="Really shows there is no silver bullet, need to be actively securing on many fronts"/>
      </outline>
    </outline>
    <outline text="News" Offset="08:02">
      <outline text="Providing the social aspect of the workplace for remote workers" Offset="08:16">
        <outline text="http://www.theglobeandmail.com/servlet/story/RTGAM.20080509.wgtbizsoftware0512/BNStory/Technology/?page=rss&amp;id=RTGAM.20080509.wgtbizsoftware0512"/>
        <outline text="Researchers implicitly acknowledge value of social interaction"/>
        <outline text="IBM working on new knowledge management system">
          <outline text="At its core, similar to many such projects"/>
          <outline text="Leavened with status updates like Facebook"/>
          <outline text="Ability to post pictures, videos"/>
          <outline text="Help add context to communications"/>
        </outline>
        <outline text="Intel also experimenting">
          <outline text="Started with virtual business cards, rich media in addition to standard info"/>
          <outline text="Looking into virtual worlds, as well"/>
        </outline>
        <outline text="Both companies are large, multinational, with off shored and remote workers"/>
        <outline text="Article talks about virtual spaces filling in implicit communications"/>
        <outline text="Make people feel embedded in space, presence of others"/>
        <outline text="Some also trying to add pure social"/>
        <outline text="IBM has an Inward Bounds, virtual gaming initiative"/>
        <outline text="Also trying to capture ad hoc collaboration used to happen in hallways"/>
        <outline text="Do identify risk of skewed politics"/>
        <outline text="Introverts may be more outspoken in virtual spaces"/>
        <outline text="May exacerbate generation gap"/>
        <outline text="Benefits overall are still hard to quantify"/>
        <outline text="Hints at reputation, trust which may net improved collaboration"/>
        <outline text="Article is also skeptical that need for real meetings will ever be entirely replaced"/>
        <outline text="I think there is real value, here"/>
        <outline text="Modeling popular social apps probably not the best approach"/>
        <outline text="Researching the social aspects and directly modeling will last better"/>
        <outline text="The increasing phenomenon of hyper-connectivity">
          <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/290161426/20080514-no-off-switch-hyperconnectivity-on-the-rise.html"/>
          <outline text="Study reveals a small but growing minority"/>
          <outline text="Coupled with other studies that show problems with multitasking and email stress, this is a trend to watch"/>
          <outline text="Do the efforts of companies to provide virtual connections have the potential to make this worse?"/>
        </outline>
      </outline>
      <outline text="USAF considers building its own botnet" Offset="13:48">
        <outline text="http://feeds.wired.com/~r/wired/topheadlines/~3/288873475/air-force-col-w.html"/>
        <outline text="I put this in the same class as a beneficial worm"/>
        <outline text="Col. Charles W. Williamson III proposing build captive botnet"/>
        <outline text="To use for DDoS attacks"/>
        <outline text="Wrote up idea in Armed Forces Journal"/>
        <outline text="Thankfully, not talking about infecting public at large"/>
        <outline text="Would just install on non-classified government systems"/>
        <outline text="Even restore junked computers to use for this purpose"/>
        <outline text="Article correctly cites problems imposed on route nodes between attackers and target"/>
        <outline text="Also implies resources better spent on more mature, sophisticated capabilities"/>
        <outline text="Silly to build a botnet just because foes have one"/>
        <outline text="How about further research of how to non-permanently disable infrastructure?"/>
        <outline text="Law of unintended consequences seems to indicate a huge downside"/>
        <outline text="Risks of sensitive systems inadvertently getting included"/>
        <outline text="Exploitable vulnerabilities in nodes allowing someone else to subvert"/>
        <outline text="That would allow a direct attack on the militaries internal network"/>
      </outline>
      <outline text="End of analog TV will bring increase in problems" Offset="17:06">
        <outline text="http://feeds.feedburner.com/~r/boingboing/iBag/~3/289531513/analog-switchoff-drm.html"/>
        <outline text="Opinion piece on TidBits"/>
        <outline text="Author reflecting on entertainment options at hotel for CES"/>
        <outline text="Mentions a digital TV education video from CEA"/>
        <outline text="A loaded PSA for digital broadcast, trying to sell as free benefit to consumer"/>
        <outline text="Sets up as foil to exploration of hidden dangers, issues"/>
        <outline text="First is unwanted complexity">
          <outline text="Converter boxes with 100 button remotes"/>
          <outline text="Those most likely to keep old TVs least likely to be prepared to deal"/>
        </outline>
        <outline text="No direct control schemes, yet, but the fact the HD digital is riddled predicts it is likely">
          <outline text="Uses argument of format tax"/>
          <outline text="Don't have to stretch to list out many options, all time limited, all priced arbitrarily"/>
          <outline text="All from existing digital formats"/>
          <outline text="Incentive to keep this going is too great for industry to go back"/>
          <outline text="Defeated the broadcast flag previously, but the potential reward for broadcasters almost guarantees it will return in some form"/>
        </outline>
        <outline text="Main thrust of opinion is that arbitrarily crippling technology is wrong"/>
        <outline text="Admits technologically savvy will not be burdened"/>
        <outline text="Vast minority, though"/>
        <outline text="Dovetails with the argument FSF advocates have been making through the DefectiveByDesign movement, site"/>
        <outline text="Trying to popularize the issues, invite commentary, discussion and action"/>
        <outline text="Highlight that those reader article need to think about the majority"/>
      </outline>
      <outline text="NBC activates broadcast flag" Offset="20:59">
        <outline text="http://arstechnica.com/news.ars/post/20080514-nbc-vista-copy-protection-snafu-reminds-us-why-drm-stinks.html"/>
        <outline text="This appears to only effect Vista Media Center Edition users"/>
        <outline text="The flag was activated Monday night, during prime time"/>
        <outline text="Included in over the air and cable broadcast"/>
        <outline text="Microsoft, NBC looking into it"/>
        <outline text="Similar to Tivo case last year or the year before"/>
        <outline text="Claimed it was &quot;accidental&quot; though that seems unlikely"/>
        <outline text="Tivo and DirecTV customers were unaffected"/>
        <outline text="Serves as an unsettling reminder that content is increasingly not under our control"/>
        <outline text="Outside of outright piracy, this is not right"/>
        <outline text="Sony v. Universal established our right to time shift"/>
        <outline text="This sort of overbearing control will have a blow back"/>
        <outline text="Consumers don't like to be surprised"/>
        <outline text="This is inconsistent with their use of the content, to date"/>
        <outline text="NBC flagging digital content">
          <outline text="http://www.eff.org/deeplinks/2008/05/update-nbc-and-microsoft"/>
          <outline text="Explains the EFF's fight against the broadcast flag"/>
          <outline text="A fight they won"/>
          <outline text="No manufacturer is required to enforce the flag although broadcasters are apparently still free to send it, part of the ATSC digital TV standard"/>
          <outline text="That's the real kicker of this incident"/>
          <outline text="Microsoft is not obligated to respect the flag"/>
          <outline text="So why did they?"/>
          <outline text="EFF is trying to figure out if it is a technical glitch, part of some other DRM scheme or just an accident"/>
        </outline>
      </outline>
    </outline>
    <outline text="tail -f" Offset="24:45">
      <outline text="Cases going against RIAA and reconsider Thomas case ruling" Offset="25:04">
        <outline text="http://techdirt.com/articles/20080515/1228441125.shtml"/>
        <outline text="Court has awarded Tanya Andersen $108K in legal fees from RIAA"/>
        <outline text="This in response to the original suit"/>
        <outline text="After her being proven innocent"/>
        <outline text="Unrelated to her counter suit, trying to stop RIAA suits altogether"/>
        <outline text="Bigger news is in the Jammie Thomas case"/>
        <outline text="The ruling was against a binding precedent in the same circuit"/>
        <outline text="Judge is now admitting he may have made a severe error in jury instructions"/>
        <outline text="The jury instructions were altered at the behest of the RIAA"/>
        <outline text="Made to more closely match the RIAA's desired definition of making available as infringement"/>
        <outline text="May be possible judge will order a new trial"/>
        <outline text="Error of law may result in new trial for Jammie Thomas">
          <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/291051629/20080515-jammie-thomas-likely-to-get-new-trial.html"/>
          <outline text="The problems is exactly because of the binding precedent"/>
          <outline text="Unrelated to Thomas' appeal which is based on the size of the damages"/>
          <outline text="Judge isn't addressing damages at all"/>
          <outline text="A retrial will probably not go in Thomas' favor"/>
          <outline text="However, it will erode the making available theory considerably"/>
        </outline>
      </outline>
    </outline>
    <outline text="Outro" Offset="27:51">
      <outline text="Contact me">
        <outline text="Email to feedback@thecommandline.net"/>
        <outline text="Web site at http://thecommandline.net/"/>
        <outline text="IM to command.line@skype"/>
        <outline text="Listener comment line is 240-949-2638"/>
        <outline text="del.icio.us tag is &quot;for:cmdln&quot;"/>
        <outline text="http://twitter.com/cmdln"/>
      </outline>
      <outline text="I'd like to thank libsyn.com for AAC hosting and Wouter de Bie for MP3 hosting"/>
      <outline text="These notes and the show audio and music are covered by a Creative Commons license">
        <outline text="http://creativecommons.org/licenses/by-nc-sa/3.0/us/"/>
        <outline text="Attribution, non-commercial, share alike"/>
      </outline>
    </outline>
  </body>
</opml>
