<?xml version="1.0" encoding="UTF-8"?>
<opml version="1.0">
  <head>
    <title>cmdln.net_2008-06-01</title>
    <expansionState>0,1,15,16,34,48,49,66,85,103,125,126,137,138,146</expansionState>
  </head>
  <body>
    <outline text="Intro" Offset="00:17">
      <outline text="iPod Touch">
        <outline text="First got to play with one a few months back"/>
        <outline text="Immediately so the potential for a nice net appliance"/>
        <outline text="The 32GB has enough space for my library"/>
        <outline text="Already using it instead of my laptop for trivial things"/>
        <outline text="Checking twitter, occasionally looking things up"/>
        <outline text="At Balticon was able to use it to stay connected everywhere"/>
        <outline text="I have a crappy cell phone"/>
        <outline text="I hate cell phones, this is the most I will buy"/>
        <outline text="As a consequence, doesn't work a lot of places"/>
        <outline text="I like how the touch complements SMS where there is WiFi"/>
        <outline text="The music interface is just different enough it is taking some getting used to"/>
        <outline text="Not all information is available, lost release date, show notes from podcasts"/>
        <outline text="Using touch interface without looking is almost impossible"/>
      </outline>
    </outline>
    <outline text="Security Alerts" Offset="05:38">
      <outline text="Vulnerability in popular cell phone" Offset="05:57">
        <outline text="http://go.theregister.com/feed/www.theregister.co.uk/2008/05/28/razr_security_jpg/"/>
        <outline text="Problem is in the EXIF parser used in supporting JPG"/>
        <outline text="EXIF is embedded metadata in image"/>
        <outline text="An malformed file can be sent to a Motorola RAZR via MMS"/>
        <outline text="Could cause overflow, arbitrary code execution"/>
        <outline text="Problem was originally reported late last year"/>
        <outline text="Motorola just now has issued a new firmware version to address"/>
        <outline text="May be complex to exploit but only requires one person to write automated attack"/>
        <outline text="Not entirely sure of value in attack"/>
        <outline text="Personal data for sure"/>
        <outline text="Could an attack coopt a phone for other use like SMS spam?"/>
        <outline text="Mobile botnet?"/>
        <outline text="Article doesn't entertain speculation"/>
        <outline text="Mobile devices increasingly more attractive with rise in popularity"/>
        <outline text="Not necessarily harder to secure but appearance of being more closed"/>
        <outline text="Phones provide more and more general facilities, though, like email, web browser"/>
        <outline text="Equally capable for attackers to exploit"/>
      </outline>
      <outline text="SSL black list extensions for Firefox detects bum Debian certificates" Offset="08:27">
        <outline text="http://feeds.downloadsquad.com/~r/weblogsinc/downloadsquad/~3/300653302/"/>
        <outline text="Comment on the web site gives more details"/>
        <outline text="http://thecommandline.net/2008/05/18/news_141/#comment-13563"/>
        <outline text="As a system administrator solution is to update, regenerate keys"/>
        <outline text="As a user, what can you do?"/>
        <outline text="Firefox extension helps users identify potentially bad keys"/>
        <outline text="https://bad.codefromthe70s.org/"/>
        <outline text="URL with know bad key for an example"/>
        <outline text="http://codefromthe70s.org/sslblacklist.asp"/>
        <outline text="More details at developers site"/>
        <outline text="Collecting a database of know bad certs"/>
        <outline text="Can report sites through the extension itself when it identifies a bad cert"/>
        <outline text="Based on database released by Ubuntu folks of finger prints of bad keys"/>
      </outline>
    </outline>
    <outline text="News" Offset="11:26">
      <outline text="Formal practice exercises for coding" Offset="11:40">
        <outline text="http://www.hackszine.com/blog/archive/2008/05/code_kata_exercise_for_the_sof.html?CMP=OTC-7G2N43923558"/>
        <outline text="Idea borrowed from martial arts"/>
        <outline text="Preset forms of practice to help improve skill"/>
        <outline text="Site explains also that many programmers have only theoretical knowledge"/>
        <outline text="Learning on the job means making mistakes in production code"/>
        <outline text="Separating practice out allows for improvement not at the expense of live code"/>
        <outline text="Code exercises that are 30 to 60 minutes long"/>
        <outline text="Some are programming, others are open ended thought exercises"/>
        <outline text="There is also benefit in practice without pressure, deadlines"/>
        <outline text="Implication is that trying to learn under pressure is not ideal"/>
        <outline text="I'd have to agree, may not appreciate full nuance when just trying reach a goal quickly"/>
        <outline text="Also emphasizes feedback, focus is on correcting, improving"/>
        <outline text="Incidental learning, too, not just arriving at correct answer"/>
        <outline text="First 21 katas are a good mix of the practical and conceptual"/>
        <outline text="Reviewed a few, these are close to problems I've had to solve"/>
        <outline text="Strongly recommend not only giving these a try but using them to recognize opportunities for learning in your regular work"/>
      </outline>
      <outline text="TJX fires employee for discussing lax security" Offset="14:50">
        <outline text="http://www.theregister.co.uk/2008/05/23/tjx_fires_whistleblower/"/>
        <outline text="From the article, it sounds like this employee tried to work within the system"/>
        <outline text="Problems appear to go back well before the data theft"/>
        <outline text="Very little positive response from the company"/>
        <outline text="A brief period of stronger passwords following a known breach"/>
        <outline text="Some question his actions"/>
        <outline text="Were they the best way to bring attention to the issue?"/>
        <outline text="Others consider him a whistle blower"/>
        <outline text="Given the non-responsiveness of the company, I tend to agree with the latter"/>
        <outline text="Benson, employee, highlights it is not just the company's assets at risk"/>
        <outline text="Employee and customer data also at risk"/>
        <outline text="Arguably the data breach shows this is the bigger risk"/>
        <outline text="What else could Benson do given the lack of action?"/>
        <outline text="Meshes with the question of how to make companies behave more responsibly with consumer data"/>
        <outline text="Consumers not in a position to know security details"/>
        <outline text="If employees are but can be so easily dismissed, how do we expect things to improve?"/>
        <outline text="TJX had an opportunity to turn this into positive PR"/>
        <outline text="Instead, they just received another black eye"/>
      </outline>
      <outline text="Neuros brings VideoLAN into device market" Offset="19:30">
        <outline text="http://rss.slashdot.org/~r/slashdot/eqWf/~3/300128483/article.pl"/>
        <outline text="Will involve maintainers from the VLC project itself"/>
        <outline text="Part of Neuros' efforts around an open hardware platform developing in partnership with TI"/>
        <outline text="VideoLAN will pretty much form the heart of the box"/>
        <outline text="Provides encoding, transcoding and playback"/>
        <outline text="Has a well established plugin design for new codecs"/>
        <outline text="From the article, seems to take good advantage of Linux and the hardware"/>
        <outline text="All porting efforts will be shared back into the VLC project"/>
        <outline text="Neuros is making very good on its promises to popularize open source in this space"/>
        <outline text="VLC is a quiet but strong player"/>
        <outline text="Personally, I have found very little content with which it could not deal"/>
        <outline text="Should by now use it first, but always end up using as a more capable fall back"/>
        <outline text="Curious to see if anyone else makes use of this ARM port"/>
        <outline text="In particular, the port would be a free way to bring Ogg support to new devices"/>
        <outline text="Really want to see if the forthcoming box can deal with digital content"/>
        <outline text="The existing Neuros offering is limited to analog capture, RCA or S-video connection"/>
        <outline text="Will certainly do well with downloaded content of all varieties"/>
      </outline>
      <outline text="MediaDefender attacks legitimate IPTV player, Rev3" Offset="25:46">
        <outline text="http://revision3.com/blog/2008/05/29/inside-the-attack-that-crippled-revision3"/>
        <outline text="Rev3 uses BitTorrent to legitimately distribute its video content"/>
        <outline text="Experienced an outage over the Memorial day weekend"/>
        <outline text="Good explanation of a syn flood attack"/>
        <outline text="Rev3 performed its own investigation to uncover DDoS"/>
        <outline text="Identified Media Defender who had worked for several labels and both MPAA and RIAA in the past"/>
        <outline text="Not to be confused with Media Sentry, which is an investigator"/>
        <outline text="Media Defender pollutes, attacks P2P networks"/>
        <outline text="Was subject of much press, ridicule in wake of an email leak earlier in the year"/>
        <outline text="Execs admitted to attacking trackers over past months"/>
        <outline text="Apparently using a back down in the tracker"/>
        <outline text="Claim flood was initiated by Rev3 corrective action"/>
        <outline text="Doesn't claim a specific attack or any responsibility"/>
        <outline text="Unclear why they were injecting their own torrents except to cause Rev3 problems"/>
        <outline text="Maybe because they automatically identified the server as an open, public tracker"/>
        <outline text="Media Defender claims they will check with operators in the future"/>
        <outline text="Attack took out all of Rev3, not just their tracker"/>
        <outline text="Despite Rev3 CEO's unwillingness to speculate, does think what Media Defender does is wrong, penalizes anyone using protocol regardless of actual use"/>
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/300911949/20080529-revision3-ceo-blackout-caused-by-mediadefender-attack.html"/>
        <outline text="More explanation of what Media Defender does more generally"/>
        <outline text="More details on Media Defender getting caught doing suspicious things"/>
      </outline>
    </outline>
    <outline text="tail -f" Offset="30:26">
      <outline text="NBC, MS claim to have gotten to source of broadcast flag snafu" Offset="30:45">
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/300662814/20080529-concerns-linger-in-wake-of-nbcwindows-mce-recording-snafu.html"/>
        <outline text="NBC still claiming this is an accident"/>
        <outline text="Microsoft has yet to explain why they are obeying the flags"/>
        <outline text="Was apparently a flag for analog, not digital content"/>
        <outline text="Flag in question has three settings, copy never, once or freely"/>
        <outline text="Inadvertently set to copy never"/>
        <outline text="Claim since this is an analog only flag, will never happen after the digital cutover"/>
        <outline text="Microsoft also making noises about preventing error"/>
        <outline text="How about patching the software to eliminate the possibility?"/>
        <outline text="Both are concentrating on procedural or administrative fixes"/>
      </outline>
    </outline>
    <outline text="Outro" Offset="33:20">
      <outline text="Contact me">
        <outline text="Email to feedback@thecommandline.net"/>
        <outline text="Web site at http://thecommandline.net/"/>
        <outline text="IM to command.line@skype"/>
        <outline text="Listener comment line is 240-949-2638"/>
        <outline text="del.icio.us tag is &quot;for:cmdln&quot;"/>
        <outline text="http://twitter.com/cmdln"/>
      </outline>
      <outline text="I'd like to thank libsyn.com for AAC hosting and Wouter de Bie for MP3 hosting"/>
      <outline text="These notes and the show audio and music are covered by a Creative Commons license">
        <outline text="http://creativecommons.org/licenses/by-nc-sa/3.0/us/"/>
        <outline text="Attribution, non-commercial, share alike"/>
      </outline>
    </outline>
  </body>
</opml>
