<?xml version="1.0" encoding="UTF-8"?>
<opml version="1.0">
  <head>
    <title>cmdln.net_2008-08-24</title>
    <expansionState>0,2,3,19,32,33,40,59,71,81,99,126,127,138,143,149,162,169,170,178</expansionState>
  </head>
  <body>
    <outline text="Intro" Offset="00:17">
      <outline text="Dragon*Con in a few days"/>
    </outline>
    <outline text="Security Alerts" Offset="03:32">
      <outline text="Clipboard hijacking attack" Offset="03:51">
        <outline text="http://news.bbc.co.uk/2/hi/technology/7567889.stm" Offset="06:37"/>
        <outline text="The attack is Flash based"/>
        <outline text="It puts a link in the user's clipboard"/>
        <outline text="The link leads to a fake security site"/>
        <outline text="The article describes the link as hard to delete"/>
        <outline text="The attack endlessly re-writes the clipboard, replacing whatever the user places there"/>
        <outline text="Affects Windows and Mac users using Firefox"/>
        <outline text="Can be stopped by either killing the browser process or rebooting"/>
        <outline text="Site at the link claims user's machine is riddled with malware"/>
        <outline text="Clearly a scam to get folks to purchase a bogus product or to capture their personal details"/>
        <outline text="Attack is not widespread but has shown up in a variety of spam"/>
        <outline text="Curious about how this works if the page with the Flash is unloaded"/>
        <outline text="Is this a fixable problem?"/>
        <outline text="Further, using an extension like NoScript will protect you"/>
        <outline text="Blocks flash by default"/>
      </outline>
      <outline text="New crypto attack from Adi Shamir" Offset="06:37">
        <outline text="http://www.schneier.com/blog/archives/2008/08/adi_shamirs_cub.html"/>
        <outline text="This is new research from Adi Shamir, the S in RSA"/>
        <outline text="Attack is applicable to a wide variety of the math underpinning crypto"/>
        <outline text="Not just ciphers but also hash functions"/>
        <outline text="Bruce adds further edits that certain algorithms are not susceptible"/>
        <outline text="It seems like if the math in question has a high degree polynomial, it is resistant"/>
        <outline text="This explicitly rules out AES"/>
        <outline text="Also rules out newer block ciphers like DES, Blowfish and Twofish"/>
        <outline text="More on the research after it is published"/>
        <outline text="Reinforces that no math is bullet proof"/>
        <outline text="Given enough time, enough minds, flaws will be found, exposed"/>
        <outline text="Similar to much more aggressive attacks on hash functions, like MD5 and SHA1"/>
      </outline>
    </outline>
    <outline text="News" Offset="09:58">
      <outline text="Questions about cloud computing begged by Google outages" Offset="10:12">
        <outline text="http://www.infoworld.com/article/08/08/15/Google_Apps_admins_jittery_about_Gmail_hopeful_about_future-IDGNS_1.html"/>
        <outline text="Google had a couple of outages this past week"/>
        <outline text="Article details the impacts on some customers"/>
        <outline text="Begs the question of how this will affect the adoption of cloud computing"/>
        <outline text="The article mentions admins using forums, doing trouble shooting"/>
        <outline text="Are there more opportunities to better handle disaster and recovery in the cloud?"/>
        <outline text="Points out a serious downside">
          <outline text="Don't have to worry about hardware, software operations"/>
          <outline text="Lose some visibility that might help predict a problem"/>
        </outline>
        <outline text="Other than the scale, is it that much different than a corporate server losing a disk array or other failure?"/>
        <outline text="Frustrating because there is little an admin can do directly to recover"/>
        <outline text="A two hour turn around is not bad, though"/>
        <outline text="A local admin could re-purpose a spare system to handle 1 organizations email or applications, though"/>
        <outline text="Many in the article had the capability to run their own systems"/>
        <outline text="Some talked about using Google as a backup if outages persist"/>
        <outline text="Google puts all apps in a large bucket"/>
        <outline text="There may be some compartmentalization"/>
        <outline text="Other providers, ones that more clearly expose individual VMs may provide better risk management"/>
        <outline text="Smaller players may have less of a choice"/>
        <outline text="One admin in the article said they might leave Apps, stay away for a few years if outages persist"/>
        <outline text="If competitors are more resilient to outages, that could really hurt the risk averse"/>
        <outline text="Google, others could provide recovery options as part of the service"/>
        <outline text="May already do"/>
        <outline text="But see a real use for Google's appliance, a local node that can keep running minimum services if the cloud instances have trouble"/>
        <outline text="Increasingly, providers will have to address these and other risks that are effected by the nature of cloud computing"/>
      </outline>
      <outline text="New visual search engine for finding infringing uses" Offset="15:24">
        <outline text="http://arstechnica.com/news.ars/post/20080819-tineye-image-search-helps-ferret-out-copyright-ripoffs.html"/>
        <outline text="Service is called TinEye"/>
        <outline text="Requires that you have the image already"/>
        <outline text="This appears to be a hash based search"/>
        <outline text="Article does note it can find matches that have been cropped and even minimally altered"/>
        <outline text="Quote from FAQ makes it sound like it yields similar results as well as exact matches"/>
        <outline text="Article initially focuses in on use to protect rights"/>
        <outline text="How about also using it to find rights holder to seek permission, give attribution?"/>
        <outline text="Ars tried the search engine, their results are worth the read"/>
        <outline text="Service requires registration"/>
        <outline text="Despite quote, results seem biased towards exact match"/>
        <outline text="Author new where one test photo had been used widely">
          <outline text="TinEye find a very small number of hits"/>
          <outline text="CEO explains this as a consequence of a small index as of yet"/>
        </outline>
        <outline text="CEO admits the usage to find a rights holder"/>
        <outline text="Offers additional reasons, such as try to uncover names, info in an unknown photo"/>
        <outline text="Still not necessarily for casual use"/>
        <outline text="Reminds me, though, of a complaint by Alex Curtis of PK about the orphan works problem"/>
        <outline text="In the absence of a registration database, a private search engine could do"/>
        <outline text="A few years ago, there was none"/>
        <outline text="Hopefully TinEye can succeed and fulfill this need"/>
      </outline>
      <outline text="Judge rules fair use should be consider before sending DMCA take downs" Offset="19:33">
        <outline text="http://www.eff.org/deeplinks/2008/08/judge-rules-content-owners-must-consider-fair-use-"/>
        <outline text="This is the so-called dancing baby case, Lenz v. Universal"/>
        <outline text="Plaintiff had posted a 29 second video of a toddler dancing"/>
        <outline text="In the background, a Prince song was playing"/>
        <outline text="Universal sent a DMCA takedown"/>
        <outline text="Plaintiff found out when YouTube informed her they had taken down the video"/>
        <outline text="Lenz sued for misrepresentation under the DMCA, arguing fair use"/>
        <outline text="Universal of course file a motion to dismiss"/>
        <outline text="Judge Fogel agreed with plaintiff"/>
        <outline text="Basically stated that fair use must be part of a consideration of a DMCA violation"/>
        <outline text="Universal argued this was not possible"/>
        <outline text="Judge stated that section 512c already requires a review before sending a notice"/>
        <outline text="Stated that a fair use consideration as part of that review is not too much of a stretch"/>
        <outline text="Fogel also sees this as necessary to help prevent abuse"/>
        <outline text="This was heard in a federal court, neither of the EFF articles say which"/>
        <outline text="Hopefully it helps urge some sanity in other cases of DMCA takedowns"/>
        <outline text="If Universal appeals, could be an even bigger win if a higher court judge agrees with Fogel"/>
      </outline>
      <outline text="Was standardizing on JavaScript a mistake?" Offset="22:13">
        <outline text="http://weblog.infoworld.com/fatalexception/archives/2008/08/was_javascript.html"/>
        <outline text="Neil McAllister, Fatal Exception blog, responds to Harmony project"/>
        <outline text="Quotes Adobe stake holder in ECMAscript 4"/>
        <outline text="Echos my concerns about web applications of scale"/>
        <outline text="McAllister is skeptical that better standards would help in all cases"/>
        <outline text="Thinks smaller applications just as likely to be as ad hoc as always"/>
        <outline text="Generalizes to suggest that a single language, especially designed by committee, is a bad idea"/>
        <outline text="Cites Ada by way of example, that folks fled to C to escape restrictions of Ada"/>
        <outline text="Suggests that we take a page from the MVC pattern"/>
        <outline text="Thinks the current approach welds the control logic to closely with the view, the browser"/>
        <outline text="Highlights the stigma of old approaches, browser plugins"/>
        <outline text="Thinks we've moved past this, that Google Gears for one is well received"/>
        <outline text="Also explains it provides some general facilities many web application can use"/>
        <outline text="Wonders if the stigma against plugins is still valid?"/>
        <outline text="More users have access to broadband instead of dial up"/>
        <outline text="I don't think the security issues have progressed much, though"/>
        <outline text="A small number of plugins could be useful in the way he suggests"/>
        <outline text="Opening things up too much, though, could lead to many headaches"/>
        <outline text="Critics of FireFox cite that with too many extensions, the browser bogs, becomes unstable"/>
        <outline text="Why not develop something like CPAN for JavaScript compatible modules"/>
        <outline text="Design an API for extensions in other languages"/>
        <outline text="Doesn't have to be done by committee, which is part of his point"/>
        <outline text="I do agree with his final point, that a killer app will be the best driver to adopt this approach"/>
        <outline text="So what might be better is JavaScript as a default and a standard way for a page author to hook some other language, technology"/>
        <outline text="We already have some of the pieces like the language attribute of the script tag"/>
        <outline text="Need to make security better, distribution easier"/>
      </outline>
    </outline>
    <outline text="tail -f" Offset="28:55">
      <outline text="Elektra v. Barker case is settled" Offset="29:14">
        <outline text="http://rss.slashdot.org/~r/slashdot/eqWf/~3/368363297/article.pl"/>
        <outline text="This case was notable for the RIAA's use of its making available argument"/>
        <outline text="Barker put forward some interesting active defenses"/>
        <outline text="Questions about size of penalties, investigatory practices"/>
        <outline text="None of that will be tested in a court, now"/>
        <outline text="No reason I can find for why they settled"/>
        <outline text="The settlement is for a bit over $6K, paid $110 a time"/>
        <outline text="Probably a money issue"/>
        <outline text="Surprising given the judge's reversal on making available in the Thomas case"/>
        <outline text="Also surprising given Tanya Andersen's victory"/>
      </outline>
      <outline text="Victory for MIT students against MBTA" Offset="31:05">
        <outline text="http://www.eff.org/deeplinks/2008/08/victory-mit-students-mbta-lawsuit-hearing"/>
        <outline text="Judge O'Toole lifted the injunction on the 19th"/>
        <outline text="Did so on the basis that the MBTA is unlikely to prevail on the merits of the case"/>
        <outline text="Judge decided the computer fraud and abuse act does not in fact govern security researchers talking to people"/>
        <outline text="Judge punts in 1st Amendment question with MBTA v. MIT students">
          <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/369481550/20080819-judge-lifts-gag-order-punts-on-first-amendment.html"/>
          <outline text="Judge did not rule on the free speech concerns raised by the EFF"/>
          <outline text="The case will still go forward"/>
          <outline text="MBTA may appeal the ruling, trying to restore the gag order"/>
          <outline text="Students don't have any plans at this time to discuss their research now that they can"/>
        </outline>
        <outline text="MBTA admits tickets are not secure">
          <outline text="http://www.boston.com/news/local/articles/2008/08/20/mbta_admits_ticket_not_secure/"/>
          <outline text="Looks like the admission came as part of O'Toole's hearing"/>
          <outline text="Was probably key to him ruling against the proposed merits of the MBTA's case"/>
          <outline text="Lawyers for the MBTA say they will now work with the students"/>
          <outline text="I am skeptical, they said that before seeking the original injunction"/>
          <outline text="MBTA is trying to represent this as a win"/>
          <outline text="Claim the research only affects the paper ticket"/>
          <outline text="Students disagree, citing issues with the RFID cards as well"/>
          <outline text="MBTA claims it is already implementing changes to address what they think are limited problems"/>
          <outline text="Also seem to think stopping the Defcon presentation was sufficient"/>
          <outline text="Students still claim they wish to cooperate"/>
          <outline text="Based on my reading last week, seems like that was their attitude throughout"/>
        </outline>
        <outline text="Interview with MIT student hacker, Zack Anderson">
          <outline text="http://www.popularmechanics.com/technology/industry/4278892.html"/>
          <outline text="A more personal recitation"/>
          <outline text="Covers what has been already discussed"/>
          <outline text="Reinforces that Anderson, others, were willing to cooperate all throughout"/>
          <outline text="Were not trying to cause trouble"/>
          <outline text="Also re-iterates that their analysis was broad, not just the ticket technology itself"/>
        </outline>
      </outline>
    </outline>
    <outline text="Outro" Offset="35:01">
      <outline text="Contact me">
        <outline text="Email to feedback@thecommandline.net"/>
        <outline text="Web site at http://thecommandline.net/"/>
        <outline text="IM to command.line@skype"/>
        <outline text="Listener comment line is 240-949-2638"/>
        <outline text="del.icio.us tag is &quot;for:cmdln&quot;"/>
        <outline text="http://twitter.com/cmdln"/>
      </outline>
      <outline text="I'd like to thank libsyn.com for AAC hosting and Wouter de Bie for MP3 hosting"/>
      <outline text="These notes and the show audio and music are covered by a Creative Commons license">
        <outline text="http://creativecommons.org/licenses/by-nc-sa/3.0/us/"/>
        <outline text="Attribution, non-commercial, share alike"/>
      </outline>
    </outline>
  </body>
</opml>
