Friday, August 5, 2011

PRIVACY - Facial Recognition Technology and Social Networking

"Profile pics on social media sites pose privacy risk, researcher warns" by Jaikumar Vijayan, ComputerWorld 8/5/2011

Excerpt

Facial recognition tech makes it easier to combine offline, online identities

Imagine walking down a street and having a total stranger being able to instantly pull up your name, date of birth, Social Security number, your last blog item and other data on their smart phone.

That could soon happen, said Alessandro Acquisti, associate professor of IT and public policy at Carnegie Mellon University's Heinz College.

In a presentation at the Black Hat conference here this week, Acquisti demonstrated how it's becoming easier for strangers to identify people and infer detailed information about them from their publicly available images on sites such as Facebook and LinkedIn.

The trend has "ominous implications for privacy," Acquisti said. "I'm here to raise awareness of what I feel is going to happen."

Acquisti detailed the results of a series of experiments he conducted in which he applied off-the-shelf facial recognition tools to publicly available Facebook profile images to uniquely identify individuals. In one of the experiments, Acquisti and his team of researchers attempted to glean the true identities of individuals who had posted their images under assumed names on an online dating site

First, they used a search engine and an API they developed to automatically extract about 275,000 publicly available profile images of Facebook members in a particular city.

They then did the same with publicly available images of individuals in the same city who had posted on the dating site. Acquisti used a facial recognition tool called Pittsburgh Pattern Recognition (PittPatt) developed at CMU to see whether he could find matches between the dating site images and the Facebook profile pictures.

In all, about 5,800 dating site members also had Facebook profiles. Of these, more than 4,900 were uniquely identified. The numbers are significant because a previous CMU survey showed that about 90% of Facebook members use their real name on their profiles, Acquisiti said. Though the dating site members had used assumed names to remain anonymous, their real identities were revealed just by matching them with their Facebook profiles.

In another experiment, Acquisti's team took webcam photos of nearly 100 students and tried to match those images with the pictures on each student's Facebook profile.

Students were asked to pose for three photos and then fill out a short survey. While the surveys were being filled out, the webcam images were run against PittPatt to see whether a match could be found on Facebook.

In that experiment, about 31% of the students were correctly matched with their Facebook profiles -- in about 3 seconds.

CYBERSECURITY - Massive Spying Campaign

"Massive Campaign of Cyber Spying Uncovered" PBS Newshour 7/4/2011

Excerpts from transcript

MARGARET WARNER (Newshour): For at least five years, a high-level hacking campaign infiltrated the computer systems of more than 70 governments, corporations and public and private organizations in 14 countries. So says the Internet security firm McAfee, which uncovered the massive campaign and dubbed it Operation Shady RAT.

A summary released by McAfee yesterday identified -- identified the perpetrator only as one specific state actor.
----
MICHAEL JOSEPH GROSS, Vanity Fair: This is an unprecedented campaign of cyber-espionage, demonstrates with absolute clarity now that there are just two kinds of organizations, those that have been compromised and those that haven't, as Dmitri Alperovitch, the guy who discovered this campaign, has often said.

What happened is, they went into more than 70 organizations, everything from the International Olympic Committee to giant corporations, to tiny nonprofits, in 30 different organizational categories in 14 countries. They took out government secrets, design schematics, legal contracts, negotiation plans for business deals, every kind of sensitive information you can think of.

In many cases, these organizations were compromised for at least a year, in some cases, more than two years. And there's a really interesting pattern to the evolution of the attacks that suggest where they may have come from.

MARGARET WARNER: And that is?

MICHAEL JOSEPH GROSS: That is China.




"Revealed: Operation Shady RAT" by Dmitri Alperovitch, McAfee Labs 8/2/2011

Excerpt

For the last few years, especially since the public revelation of Operation Aurora, the targeted successful intrusion into Google and two dozen other companies, I have often been asked by our worldwide customers if they should worry about such sophisticated penetrations themselves or if that is a concern only for government agencies, defense contractors, and perhaps Google. My answer in almost all cases has been unequivocal: absolutely.

Having investigated intrusions such as Operation Aurora and Night Dragon (systemic long-term compromise of Western oil and gas industry), as well as numerous others that have not been disclosed publicly, I am convinced that every company in every conceivable industry with significant size and valuable intellectual property and trade secrets has been compromised (or will be shortly), with the great majority of the victims rarely discovering the intrusion or its impact. In fact, I divide the entire set of Fortune Global 2000 firms into two categories: those that know they’ve been compromised and those that don’t yet know.

McAfee Global Threat Intelligence

Thursday, July 28, 2011

SECURITY - Cybercrime, Attacker Arrested

"British Police Make Arrest in Net Attacks" by SOMINI SENGUPTA, New York Times 7/27/2011

Excerpt

The British police announced the arrest on Wednesday of a 19-year-old man who they said was the spokesman of the online vigilante group Lulz Security, which has claimed responsibility for a string of attacks on the Web sites of government agencies and private corporations.

In a statement, the police said the man used the online alias Topiary and had been picked up during a raid on a residence in the Shetland Islands, the rugged archipelago off the northeastern coast of Scotland. The police said they were also questioning a 17-year-old but had not arrested him.

On Twitter, Topiary described himself as a “simple prankster turned swank garden hedge.” His missives were often facetious, suggesting the handiwork of someone who relished playful language.

Lulz Security, the offshoot of a larger and more amorphous hacker group called Anonymous, has said it was responsible for attacks on the sites of PBS, the Senate, the Arizona Department of Public Safety and a company associated with the F.B.I.

Friday, July 15, 2011

LINUX - Opinion, Mint vs Ubuntu

"Is Linux Mint a Better Choice than Ubuntu?" by Matt Hartley, Datamation 7/12/2011

Excerpt

Could the rapidly growing, user-friendly Linux distro attract converts away from the mighty Ubuntu?

For many advanced Linux enthusiasts reading this, I doubt that any recent changes to the Ubuntu desktop swayed you very much. Most of you already have had plenty of time to select alternative distros -- from Fedora to Arch Linux -- should you decide you want to.

Each distribution has its own set of advantages and differences. But for those people who cannot bear to part with some features that are considered to be unique to Ubuntu, Linux Mint might be a viable option to look into.

Linux Mint is perfect for new users

I've used Linux Mint GNOME edition off and on for a few years now. I have mostly used it in testing, as I'm really not the target audience for this distribution. Yet I continue to be impressed with how simple and user-friendly this desktop is. In addition, there are other factors that I think give Linux Mint a huge edge over Ubuntu for the casual user.

When running the Linux Mint software updating tool, you'll find things are numbered from 1 to 5. Packages numbered with a 1 are from Linux Mint developers while those packages with a "2" or higher come from Ubuntu or a third-party.

This numbering system all but guarantees that you won't hose a system with a bad set of updates from a rogue repository you added and forgotten about.

The next big thing with Linux Mint is how concisely the menu layout is presented. Unlike the old Gnome menus or even Unity, everything in Linux Mint is tightly laid out to make the entire experience as logical as possible. This menu setup makes migrating from another operating system much less overwhelming for newer users. For "old hat users" such as myself, I enjoy finding everything within reach. And if it's not visible, the provided search box takes care of anything that's missing.

Another huge push in the right direction for newcomers would have to be the introduction screen that appears on the first boot. Documentation, support, and so forth is presented right away. From there, items that I think should have been provided by Ubuntu out of the box are a given with Linux Mint.

Gufw (Easy to use Ubuntu Firewall) is installed and ready to go. There is a Mintbackup utility that not only offers the same functionality as SimpleBackup on Ubuntu, but it even backs up your application titles. This means you can take this list to another PC, run the program and install the same software list as before. That’s always been possible via the command line, and now it's nice to see this functionality provided for newer users with a friendly GUI.

Without any doubt, the biggest reason for me to love Linux Mint is that I can install software by name from the control panel -- with greater speed than I could have with apt-get.

Plus I can avoid all the package managers and directly type in the application's name, which presents me with the option to install it. Best of all, it's done very quickly and without the bloat of the software center. It's almost like being able to run the terminal without needing to know how. I love it!

It feels like Ubuntu

One of the biggest reasons I still rely on Ubuntu is because of the huge number of software packages available for it. If there's software for Linux, then there's an Ubuntu package somewhere for that application title.

Luckily, these same applications also work well for Linux Mint as it offers a release based on Ubuntu. This means that should Ubuntu's direction force me to drop it completely I can stick with the same applications.

Below is my laptop's Linux Mint-10 Desktop.

(click for better view)


NOTE: The calendar shown is Rainlendar which has Windows and Linux versions. Rainlendar Lite is freeware, Rainlendar Pro (allows calendar network sharing and MS Outlook sync) is shareware license-fee.

What I run on both my WinXP Pro desktop and Mint laptop is Rainlendar Lite.

SECURITY - Department of Defense 'Cyber Command'

"Is the U.S. Prepared for Battle in Cyberspace?"
PBS Newshour 7/14/2011


"Pentagon Gears Up for the Digital Battlefield"
PBS Newshour 7/14/2011

Monday, July 11, 2011

MALWARE - Rootkit Threat to NTFS Loader

I'm posting this because of the high danger of this type of malware.

"New Rootkit Infects NTFS Loader" by Lucian Constantin, Softedia 7/6/2011

Security researchers from Kaspersky Lab have identified a new piece of malware which writes malicious code to the NTFS boot loader.

The threat which Kaspersky detects as Cidox, features two rootkit drivers, one for 32-bit versions of Windows and one for 64-bit ones.

As part of its infection routine Cidox determines the version of the operating system and copies the relevant driver to the empty sectors at the beginning of the drive.

It only infects NTFS partitions and determines the active one by looking at the MBR code. It then proceeds to replace the Extended NTFS IPL (Initial Program Loader) code. The original one is encrypted and saved at the end.

This is part of a special technique that leverages Windows kernel features to load the malicious driver into the system.

The driver has the purpose of hooking into several processes including svchost.exe, iexplore.exe, firefox.exe, opera.exe and chrome.exe via a special DLL.

"This library modifies any browser output, substituting it with its own. As a result, the user sees a browser window displaying an offer to renew the browser due to some malicious programs allegedly detected on the system," Kaspersky's Vyacheslav Zakorzhevsky explains.

This threat is effectively a form of scareware, as the user is asked to pay for the browser renewal by sending an SMS message to a premium rate number.

In order to appear more convincing, there are custom pages for each browser borrowing design elements from other official ones displayed by their developers.

This is one of the most sophisticated scareware threats currently in the wild, but at the moment it only appears to target Russian-speaking users.

It seems that malware authors are increasingly using advanced techniques. One of the most dangerous threats at the moment, the TDL4 rootkit, infects the MBR (master boot record) in order to hide itself.

NOTE: Although I could NOT find the exact references to "Trojan-Dropper.Win32.Cidox" stated in the Zakorzhevsky article, Microsoft Malware Protection Center had the following references:

Note the Softedia article says "new" but I found references to NTFS Loader threats, at several virus sites, back in 2009.

Wednesday, June 29, 2011

HARDWARE - A New Type of Mouse

This is so evolutionary I had to post it

Celluon evoMouse - the evolution of the mouse

Thursday, June 16, 2011

SOFTWARE - MiniTool's Partition Wizard Pro

This is about a hard drive management tool form MiniTool, Partition Wizard Pro.

In the past (long, long time ago; in a galaxy far, far away) I used Partition Magic from Symantec. Problem, Symantec no longer supports it, AND it does not work with today's large hard drives. In fact it can screw-up your hard drive if you [OK] at the message when you launch Partition Magic (sees a non-existing problem with the drive).

I had to find an alternative because I had replaced my old HD0 (C: & D:) with a larger one and had to resize the partitions after recovering the image backups of each drive.

The answer is MiniTool's Partition Wizard Pro. The screenshot below is of my home system with my larger HD0 (aka Disk 2), C: highlighted, after resizing.

(click for better view)

For those that notice, the "Disk" order is what Windows sees after boot. "Disk 1" (H:Games4) is a Firewire drive and Windows sees that first.

CAUTION: You should run CHKDSK on the drive after your done. Example = chkdsk c: /f/v

List of features:
  • Resize/Move Partition: Easily resize/move partition without data loss

  • Create, Format, Delete Partition

  • Convert Partition format from FAT to NTFS

  • Hide and Unhide Partitions, set active partition, label drive letter

  • Merge Partition

  • Hot Extend Partition without reboot

  • Change cluster size without data loss

  • Support Linux Ext2, Ext3, Ext4 (file systems)

  • Partition Copy: Copy entire partition to unallocated space with high performance file-by-file, moving technology; backup or move data without any data loss

  • Partition Recovery: Scan disk to restore deleted or damaged partitions

  • Hard Disk Copy: Copy an entire disk to a different diskquickly and easily with data clone technology. Backup disk data without data loss

  • Support Windows 32/64 bit Operating Systems

  • Visually demonstrate your disk/partition configuration to preview changes before apply

  • Support RAID

  • Support single disks or partitions larger than 2 TB

  • Support up to 32 hard disks within one system

  • Set partition as primary

  • Set partition as logical

  • Rebuild MBR (must use if you copy a boot partition)

  • Convert Dynamic Disk to Basic Disk

  • Disk Surface Test

  • Partition Surface Test

  • Change Partition Serial Number

  • Change Partition Type ID

Friday, June 10, 2011

INTERNTE - IPv6 World Test

"World Tests IPv6: Why 4.2 Billion Internet Addresses Just Weren't Enough"
PBS Newshour 6/8/2011

What I've discovered:
  1. First and foremost, most of us desktop/laptop users will not have to worry about this, WEB sites you use today can still be accessed WHEN IPv6 becomes the world standard

  2. Most major OS are IPv6 ready (examples WinXP, Vista, Win7, Linux, Mac)

  3. Your ISP will have to implement IPv6, I found out that my ISP, AT&T will be doing that in the future and will notify me when they roll it out

  4. The hardware you use to connect to your ISP (DSL/Cable Modems, routers, etc) will also have to be IPv6 capable; some hardware MAY be able to upgrade firmware or you'll have to buy a new model

  5. The U.S., and most of the developed world, are IPv6 ready when it comes to the WEB as a whole

IPv6 is an extension of the IPv4 we use today, which is why most of us will not have to worry.

The industry I see as implementing IPv6 the fastest is the hand-held-devices; your iPad, Blackberry, new-gen cell phones, etc. This is the industry that is expanding the fastest and needs more IP addresses.

As for PC industry, newer products in the future will include IPv6 capable hardware.

Here's a link to Test Your IPv6 (from Netgear forums).

Tuesday, June 7, 2011

INTERNET - Apple's iCloud and Mac OS X Lion

"Apple Unveils New iCloud Music Service, but Privacy Issues May Lurk"
PBS Newshour 6/6/2011


Excerpt from transcript, security

RAY SUAREZ (Newshour): If I put my stored and accumulated content on the cloud, is it private?

CECILIA KANG, The Washington Post: Well, that's a good question.

The -- the devices will be encrypted. And that's what Apple said in passing. But there's a lot of questions as to your privacy and the security of cloud-based applications, Internet-based services. We have seen a lot of attacks on information, hacking attacks into Sony, Nintendo, PBS. You have seen a lot of these -- this -- the vulnerability of information that resides on the Internet.

And when I say it resides on the Internet, I mean that it resides on servers. You don't know where they are, but there are large data farms all over the country around the world, where bits -- your bits and pieces, the bits, I should say, of the music that you have, the videos that you have, the bits, the actual digital packets, they reside in these places that you don't really as much control of.

So, when you make this decision to switch to cloud-based applications, it's much easier, more convenient and often much cheaper. But there often is the -- there is the consideration of a tradeoff, perhaps, in that there may be less security involved. It's much safer when you have your information on your own computer that only you can access than on the Internet.

And your privacy is also perhaps in -- in question, in that more people, more companies have access to what you're doing. And they can see what you're doing online.


ALSO

As mentioned in video Mac OS X Lion (Wikipedia) (Apple) (links open in new page)

Thursday, June 2, 2011

CYBERCRIME - Latest on Hacker Attacks

"Gauging the Impact, Motivations of Today's Hackers"
PBS Newshour 6/1/2011


This is the related story mentioned in video

"Google Says Hackers in China Stole Gmail Passwords" by JOHN MARKOFF and DAVID BARBOZA, New York Times 6/1/2011

Excerpt

Google said Wednesday that hundreds of users of Gmail, its e-mail service, had been the targets of clandestine attacks apparently originating in China that were aimed at stealing their passwords and monitoring their e-mail.

In a blog post, the company said the victims included senior government officials in the United States, Chinese political activists, officials in several Asian countries, military personnel and journalists.

It is the second time Google has pointed to an area of China as the source of an Internet intrusion. Its latest announcement is likely to further ratchet up the tension between the company and Chinese authorities.

Tuesday, May 17, 2011

SECURITY - Global Cybersecurity

"U.S. Calls for Global Cybersecurity Strategy" by HELENE COOPER, New York Times 5/16/2011

The Obama administration on Monday proposed creating international computer security standards with penalties for countries and organizations that fell short.

While administration officials did not single out any countries in announcing the strategy, several officials said privately that the hope was that the initiative would prod China and Russia into allowing more Internet freedom, cracking down on intellectual property theft and enacting stricter laws to protect computer users’ privacy.

“The effort to build trust in the cyberspace realm is one which should be pushed in capitals around the world,” said Commerce Secretary Gary Locke, who will soon be taking over as President Obama’s ambassador to China.

The strategy calls for officials from the State Department, the Pentagon, the Justice Department, the Commerce Department and the Department of Homeland Security to work with their counterparts around the world to come up with standards aimed at preventing theft of private information and ensuring Internet freedom. A fact sheet released by the White House also promised that the United States would respond to attempted hacking “as we would to any other threat to our country.”

Attorney General Eric H. Holder Jr. called it a “historic strategy,” adding that “the 21st-century threats that we now face to both our national and international security really have no borders.”

Last week the administration released the domestic component of its new computer security strategy, increasing and clarifying the penalties for computer crimes, and giving the domestic security agency a clear mandate for the protection of the government’s own networks. That effort was intended to reverse a growing perception that penalties for attacks on government, corporate and personal computers had been relatively small.

In addition to giving the Homeland Security Department new authority over federal computer systems, the legislation calls for the agency to work with energy companies, water suppliers and financial institutions to rank the most serious threats and find ways to counter them. The law would also require each business to have an independent commercial auditor assess its plans and, in the case of financial firms, report those plans to the Security and Exchange Commission.

About time. We have international law enforcement agreements, and military security agreements, why not this one? While nations like China or North Kora will ignore this, that should not prevent the majority of nations to come up with a plan. It would protect national interests as well as individual people.

Thursday, April 28, 2011

SECURITY - Cybercrime With World-Wide Impact

"Sony PlayStation System Hacking Incident Highlights Web-Security Gaps" PBS Newshour Transcript 4/27/2011 (includes video)

Excerpt

RAY SUAREZ (Newshour): The latest episode involved millions of people around the world who use Sony's PlayStation video game system and who may have had their credit card information stolen in a hacking incident.

The intrusion caused the company to shut down PlayStation's Internet network a week ago. It provides access to online gaming, music, movies, sports and TV shows. Seventy-seven million user accounts were disconnected worldwide. But it wasn't until yesterday that Sony disclosed a hacker obtained information, including players' names, addresses, birth dates, email addresses, passwords and log-in names.

And on the company's blog, Sony spokesman Patrick Seybold said, "While there is no evidence at this time that credit card data was taken, we cannot rule out the possibility."

Near Sony headquarters in Tokyo, some said the breach may stop them from using PlayStation.

KAZUNORI SANO, resident of Tokyo (through translator): I will be afraid of playing with the game machine after hearing of this. I don't want my credit card information to be leaked out somewhere else in the world.

RAY SUAREZ: And in Australia, police urged PlayStation users to be vigilant.

DETECTIVE SUPERINTENDENT COL DYSON, New South Wales State Police Force: It would appear that the risk in relation to credit cards may be low. But if people have concerns, they should be talking to their banks and watching for unauthorized usage of the cards.

RAY SUAREZ: Some industry experts say the scale of the breach could cost the company billions of dollars.

THOMAS PUHA, "Pelaaja": This is going to have a very negative impact on a business that they have built up, because I think a lot of -- obviously, a lot of consumers will really be very wary of putting their credit card information back online or even buying anything.

RAY SUAREZ: Sony said it expects the PlayStation Network to be restored in a week. In the meantime, an outside security firm has been hired to investigate what Sony deems the malicious intrusion.

For a closer look at all this, we turn to Kevin Poulsen, senior editor at Wired.com. A former hacker himself, he's also author of a new book, "Kingpin: How One Hacker Took Over the Billion-Dollar Cybercrime Underground."

And, Kevin, for those people who aren't gamers, why would you have to load personal information into a game console in the first place?

KEVIN POULSEN, Wired.com: Well, a lot of gaming takes place now online. You have multiplayer games where you could play with or against opponents live in real time.

And, of course, a game console isn't just a game console anymore. You want to be able to download movies and other content. And all -- you pay for all of that, which means you have to give up this information.

RAY SUAREZ: Sony says it has no direct evidence that credit card numbers were taken, but it says -- quote -- "We cannot rule out the possibility."

When you have had a breach, when someone has been rifling around in your files electronically, can you tell what they have seen and what they haven't?

KEVIN POULSEN: There are usually -- there's usually some kind of trail left, yes. But if the hacker is good and took steps to cover his or her tracks, then it could -- it could take a while to extract that.

I imagine that's why Sony took so long to announce this. They were probably hoping to find better news. They were probably hoping to find evidence that the -- that information wasn't accessed. Now that they have brought in an outside company, I expect they will know a lot more than they do now, eventually. Of course, they -- they may know more than they're telling us now.

RAY SUAREZ: The PlayStation system has been down for over week, disappointing a lot of people who are frequent users.

Does that long-term shutdown tell you something about the seriousness of the breach, that they're not patching it, but rebuilding the whole network?

KEVIN POULSEN: Absolutely.

It's a really radical measure to take. And it's surely going to cost them a lot of money and a lot of fan loyalty. There are people that aren't even going care about the breach itself who are just going to be extremely angry that they were denied access to the PlayStation Network for so long. So, it's bad news all around.

If this had just been a casual intruder, a recreational intruder, some kid working from his bedroom, I doubt they would have taken this measure. So, they probably have some indication that this was a serious, focused attack.

RAY SUAREZ: Well, as we reported earlier, they got user names, passwords, various other kinds of personal information. What's the risk to account holders at this point?

KEVIN POULSEN: You know, the biggest risk is probably with the personal information, especially the passwords, because a lot of people use the same passwords everywhere.

So, that, coupled with your email address and your real name and your date of birth, the hackers will, if this was done for profit, then, all of that could wind up being sold on the black market, probably for a nice sum of money.

And then, whoever buys it, other computer intruders could use the information to try and hack into other accounts held by these PlayStation Network users. It could be anything from Facebook to online banking. You could use it to stage scams targeting the users in other ways.

So, it could be -- it could wind up that this becomes the first stage in a lingering problem that haunts users for a long time, if, in fact, that that was the nature of the breach.

Stress this quote, "You know, the biggest risk is probably with the personal information, especially the passwords, because a lot of people use the same passwords everywhere."

HINT, do not use the same password for all your online accounts.

Thursday, April 7, 2011

SECURITY - Vulnerability of Internet Certificates

"An Attack Sheds Light on Internet Security Holes" by RIVA RICHMOND, New York Times 4/6/2011

Excerpt

The Comodo Group, an Internet security company, has been attacked in the last month by a talkative and professed patriotic Iranian hacker who infiltrated several of the company’s partners and used them to threaten the security of myriad big-name Web sites.

But the case is a problem for not only Comodo, which initially believed the attack was the work of the Iranian government. It has also cast a spotlight on the global system that supposedly secures communications and commerce on the Web.

The encryption used by many Web sites to prevent eavesdropping on their interactions with visitors is not very secure. This technology is in use when Web addresses start with “https” (in which “s” stands for secure) and a closed lock icon appears on Web browsers. These sites rely on third-party organizations, like Comodo, to provide “certificates” that guarantee sites’ authenticity to Web browsers.

But many security experts say the problems start with the proliferation of organizations permitted to issue certificates. Browser makers like Microsoft, Mozilla, Google and Apple have authorized a large and growing number of entities around the world — both private companies and government bodies — to create them. Many private “certificate authorities” have, in turn, worked with resellers and deputized other unknown companies to issue certificates in a “chain of trust” that now involves many hundreds of players, any of which may in fact be a weak link.

The Electronic Frontier Foundation, an online civil liberties group, has explored the Internet in an attempt to map this nebulous system. As of December, 676 organizations were signing certificates, it found. Other security experts suspect that the scan missed many and that the number is much higher.

Making matters worse, entities that issue certificates, though required to seek authorization from site owners, can technically issue certificates for any Web site. This means that governments that control certificate authorities and hackers who break into their systems can issue certificates for any site at will.

Experts say that both the certificate system and the technology it employs have long been in need of an overhaul, but that the technology industry has not been able to muster the will to do it. “It hasn’t been perceived to be a big enough problem that needs to be fixed,” said Stephen Schultze, associate director of the Center for Information Technology Policy at Princeton. “This is a wake-up call. This is a small leak that is evidence of a much more fundamental structural problem.”

In the Comodo case, the hacker infiltrated an Italian computer reseller and used its access to Comodo’s systems to automatically create certificates for Web sites operated by Google, Yahoo, Microsoft, Skype and Mozilla. With the certificates, the hacker could set up servers that appear to work for those sites and try to view the unscrambled e-mail of millions of people, experts say.

Wednesday, March 30, 2011

HARDWARE - New nVidia GeForce GTX 590

nVidia GeForce GTX 590

Page includes demo shows and videos.

Here's the YouTube video
(suggest let full download before viewing)


One caution, when viewing the video pay attention to the requirements to get top performance for this video card. It is NOT for your common desktop system. Also, note the spec for DirectX 11 = this is intended for a Win7 system, PCIe.

Also, you may want to look at EVGA Precision Utility.

It's free and took me just minutes to get working to display what I choose (screen shot below). Just remember to enable the EVGA Precision On-Screen Display Server which allows OSD during game-play AND add your game EXE to list in the server dialog.

(click for better view)

INTERNET - Broadband Access in U.S.

(click for better view)

NOTE: In the full article, this is an interactive map

"Broadband Access: Exploring Internet Connectivity by U.S. Community Type" by Dante Chinni, PBS Newshour 3/28/2011

The federal government wants you to have access to a broadband connection. Badly. The Federal Communications Commission has held dozens of workshops and filed away more than 23,000 comments on its National Broadband Plan.

"High-speed wireless service is the next train station, the next off-ramp," President Obama said in February. "It's how we'll spark new innovation, new investments and new jobs."

That's an important set of goals for an economy that is still trying to climb out of the last recession, and most experts would argue an accurate one. It's one reason why more than $7 billion of the 2009 stimulus plan was dedicated to broadband expansion.

If broadband is indeed key to all those elements, how close is the United States to achieving a goal of universal access to broadband? Well, in some of Patchwork Nation's 12 county types, availability seems to be very close to reality. In others, however, much work remains to be done, according to data collected by Connected Nation and analyzed by Patchwork Nation.

In the counties holding the nation's most-urban areas, the Industrial Metropolis, more than 99 percent of the population has access to a broadband connection - figured here at three megabytes per second. But in more sparsely populated areas, the numbers are much lower. In the Mormon Outposts, largely located in the Mountain West, the broadband connection rates average about 80 percent.

But the story of broadband coverage is complicated.

Who's Plugged In?

Looking county-by-county on the map you can see the communities that are well positioned for the Web-based economic/cultural/political future. Places like the New York City metro area are saturated with broadband, while places like rural Arkansas have much spottier coverage.

When you dig further into the numbers, however, you see they are about more than just income or population density. Education plays a role, as you might imagine. The counties with the second-best connectivity rate are the collegiate Campus and Career locales. Nearly 97 percent have access to broadband there even though in terms of population density and income levels the Monied Burbs would seem likely to have better connectivity. They about $10,000 richer per household on average. The Burbs have a broadband access score of about 95 percent.

And while the exurban Boom Towns have a higher median household income than the aging Emptying Nests by about $5,000, the places are roughly look similar in their access to broadband - 93.57 percent versus 93.30 percent respectively. That may because some of those more removed Boom Town communities, newly sprouted towns, are harder to wire.

There are even differences among the most far-flung of our county types - the Service Worker Centers and Tractor Country counties. Tractor Country, which is less-wealthy and less-populated than the Service Worker Centers, is slightly better connected.

Why? As we have noted previously, Tractor Country communities in particular seem to show a stronger streak of civic pride than other communities. People in those places may tend to dislike the federal government, but they seem believe strongly in doing things for the community itself. That certainly is something we have witnessed in Sioux Center, Iowa, a Tractor Country community we visit.

So if you were to sit down with a mathematician and try to figure out a formula for connectivity - admittedly a very difficult challenge - it might look something like population density, plus education, plus income, plus civic engagement equals better access to broadband.

More to the Picture

Wiring far-flung places will not be cheap. Getting an exact cost is difficult, but the Web is littered with stories of ridiculous expenditures aimed at bringing small, rural locales fully into the digital age.

And access is only one part of the issue, the other is the ability to afford an actual connection. Some of the least-wealthy counties we look at are among those listed above that have the least access - Tractor Country, the Service Worker Centers, the Evangelical Epicenters. And while the cost of wiring those places certainly plays an issue, it may be they are less wired precisely because they are less wealthy. There may be less interest in broadband there.

The costs of broadband service vary by community and service provider, of course, but, on average the cost is about $41 a month, according to a survey from the Pew Internet & American Life Project done last August. That's about $11 a month higher than dial-up access the survey found - or over the course of the year an extra $150. That's not astronomical, of course, but it may feel like a lot in some communities that are struggling with the effect of the recession as well as long-term economic woes.

Patchwork Nation has not yet explored Internet usage by community type, but we have looked at issues like social media use in our book. And we looked at broadband access versus adoption in Ohio on our site, where we found sharp differences. The Emptying Nests were below 50 percent for adoption, even with their well-wired communities. And the Service Worker Centers and Evangelical Epicenters were at about 40 percent and 26 percent, respectively.

That means even if the broadband network is fully built out - not an inexpensive proposition - there will still be the challenge of helping those who cannot afford it and, along with that, there will be the challenge of convincing those who aren't as interested in life online that broadband is critical to their future - the key to that national transformation President Obama has outlined.

That may be the toughest sell in some communities where times are tight.

COMPUTERS - IBM's Light-Driven Computer

IBM's Light-Driven Processor Courtesy IBM
(click for better view)

"How It Works: The Light-Driven Computer" by Valerie Ross, PopSci 3/24/2011

The speed of light is as fast as it gets, and IBM researchers are exploiting that fact to give supercomputers a boost. They’ve made the smallest-yet silicon chips that use light to transmit information.

Most parts of the chip resemble those found on any other commercial chip. The parts that process or transform information—in other words, the parts that do the actual computing—still deploy electrons moving through semiconductor gates. But the interconnects, the lines that shuttle information between different areas within a chip, are drastically different. Instead of shuttling electrons, which can slow down significantly when the interconnects heat up, they shuttle light. That’s because light is easy to contain and loses less information as it travels. The researchers hope that this quick communication will make possible the first exascale computers—that is, computers that can perform a billion billion computations per second, 1,000 times as fast as today’s speediest systems.

One other benefit, says IBM engineer Will Green: The optical interconnects use significantly less power, making them cheaper to run. That’s particularly important given that supercomputers typically consume megawatts of power during operation. IBM, which has already made a working prototype, says a commercial version of the chip will debut in a supercomputer in around 2018.

Article includes interactive Light-Driven Computer demo.

Wednesday, March 2, 2011

SECURITY - Vicious Trojan, "System Tool"

This post it about a particularly vicious Trojan (malware) called System Tool on his Win7 PC.

This is a FAKE virus scanner. DO NOT buy it, that is what the hacker is trying to do, get your money and/or credit info.

What makes this one "vicious" is:
  • You cannot uninstall it normally

  • It is NOT listed in Add/Remove Programs

  • Prevents execution of normal antivirus and other utilities

  • Hides where it is installed

See screenshots of System Tool below:

Main Dialog
(click for better view)


It also replaces your normal background with a fake like example below or a blue background.

Fake Background (example)
(click for better view)


I found how to fix it at RemoveVirus.org which provides removal guides and links to legitimate removal software or sites.

The biggest help they provide are videos on how to remove a threat. One video was how to remove System Tool on a Win7 system.




Note that on the Win7 PC I fixed the desktop link and file location were not what is shown in the video. It was a link to a "program" (not System Tool) that my client did not install.

Suggest you add RemoveVirus.org to your Favorites.

Also, many antivirus utilities, like McAfee, provide Online Virus Removal services for a fee. So if you have an account, you can consider using the service if you can afford it.

Thursday, February 24, 2011

SECURITY - It's Not Just Your PC Anymore

"Security to Ward Off Crime on Phones" by RIVA RICHMOND, New York Times 2/23/2011

Excerpt

More consumers are buying smartphones. So more criminals are taking aim at those devices.

Criminals still prefer PCs for stealing personal data, bank and credit card account numbers as well as for running frauds. However, most PC attacks focus on Microsoft’s decade-old Windows XP operating system, which is slowly being replaced by the more secure Windows 7. Over the next few years, hackers will have to find new targets.

With smartphones outselling PCs for the first time — 421 million of the hand-held computers are expected to be sold worldwide this year, according to market analysts at IDC — the long-predicted crime wave on hand-held devices appears to have arrived. According to the mobile-security firm Lookout, malware and spyware appeared on 9 out of 100 phones it scanned in May, more than twice the 4-in-100 rate in December 2009.

In fact, the most practical rule for protecting yourself is to start thinking of the smartphone as a PC.

Most malicious incidents on mobile devices involve bogus phone or text-message charges or rogue mobile applications, of which there are now more than 500 varieties, according to F-Secure, a Finnish security firm. All these ruses require users to take some kind of action, like clicking to accept or install a program, so caution while using mobile devices can prevent most problems. (However, experts warn that automated attacks are possible and could emerge in the future.)

Most attacks happen in Eastern Europe and China. An overwhelming number — 88 percent, according to F-Secure — have singled out devices running Nokia’s Symbian operating system. Symbian is the world’s most commonly used smartphone platform, but Nokia said this month that it would be replacing it over the next few years with Microsoft’s Windows Phone operating system.

Early attacks, like the Cabir and Commwarrior worms in 2004 and 2005, caused little damage. But since 2009, attacks have grown more menacing. In September, hackers trying to steal money from accounts at a Spanish bank installed malicious applications on Symbian devices when they synced to home PCs infected with a version of the ZeuS malware. The application enabled criminals to reply to security codes sent by the bank to validate cash transfers.

Such assaults could be a preview of what is to come for devices popular in the United States. Criminals have attacked phones running on Google’s Android, Research In Motion’s BlackBerry, Apple’s iPhone and Microsoft’s Windows Mobile operating system software, suggesting that more is ahead.

Tuesday, February 15, 2011

COMPUTERS - Watson Who?

"A: This Computer Could Defeat You at 'Jeopardy!' Q: What is Watson?"
PBS Newshour 2/14/2011

Excerpt from transcript for techies:

MILES O'BRIEN, Newshour science correspondent: That's David Ferrucci, Watson's proud papa.

DAVID FERRUCCI, Watson Project, IBM: So, you're looking at 10 racks of power 750. So, there's 10 racks. There's 90 what they call power 750 servers.

MILES O'BRIEN: He introduced me to his silicon progeny.

DAVID FERRUCCI: So, overall, there's about 2,880 cores in that system, about 15 terabytes of RAM.

MILES O'BRIEN: For those of us who don't have a doctorate in computer science, Watson is equivalent to about 6,000 high-end home computers. But the secret sauce is the software that gives Watson the ability to understand language like no computer ever has.

NOVA - Smartest Machine on Earth (full show)

Friday, February 11, 2011

SECURITY - NSS Labs Report

Anti-Virus Utilities will never stop all malware. It's a race between protection software/hardware and publishers of malware.

The reason I'm posting this old article reference, there is a Newsnet post that quotes an Inquirer article, but the article did NOT provide links to NSS Labs source. Which is why The Inquirer is NOT a creditable source on this subject.

"NSS Labs Finds Most Endpoint Security Products Lack Vulnerability-Based Protection" Report NSS Labs 3/12/2010

Excerpt

NSS Labs, Inc., the leading independent security testing organization, today announced the results of its evaluation of seven popular consumer endpoint security products in protecting the vulnerability exploited in the recent “Operation Aurora” attack conducted against Google and at least 30 other organizations. This test—the first of its kind in the industry—was designed to identify which products truly shielded the underlying Microsoft Windows Internet Explorer vulnerability (CVE-2010-0249) against additional attack variants. Products that defended the vulnerability versus simply stopping a single variant or its malicious payload are considered to have a more effective security model.

In its Austin, Texas facility, NSS Labs created variants of the Operation Aurora attack and tested the anti-malware software to see which of the seven products stopped the exploits and malicious code payloads. Given the level of visibility of the attack and the time that has passed since its initial discovery, it was thought that most, if not all, of the products would cover the vulnerability. However, only one out of seven tested products correctly thwarted multiple exploits and payloads, demonstrating vulnerability-based protection (McAfee).

"Generally, there are multiple ways to successfully exploit a vulnerability," said Rick Moy, president of NSS Labs. “This test case underscores the need for IT security vendors to provide greater vulnerability-based protection. Rather than reactively blocking individual exploits or malware, vendors should focus on minimizing their customers’ risk of exposure by insulating the vulnerability.”

Products tested included:
  • AVG Internet Security, version 9.0.733

  • ESET Smart Security 4, version 4.0.474.0 (see caution below)

  • Kaspersky Internet Security 2010, version 9.0.0.736

  • McAfee Internet Security 2010 with SecurityCenter, version 9.15.160

  • Norton Internet Security 2010, version 17.0.0.136

  • Sophos Endpoint Protection for Enterprise - Anti-Virus version 9.0.0

  • Trend Micro Internet Security 2010, version 17.50.1366.0000

A full report of the test and its findings is available here. Additionally, Vikram Phatak, CTO of NSS Labs will be discussing the test and demonstrating the Operation Aurora exploit on March 13, 2010 at BSidesAustin, to be held at Norris Conference Centers.

COMMENT:
  • I do NOT recommend "Security" nor "Internet" suites for home users because they tend to be resource hogs

  • I DO recommend a good Antivirus, that is not part of a suite

  • At home on my WinXP SP3 desktop system I use ESET NOD32 Antivirus 4, which is very fast, uses little resources; and includes Antivirus, anti-Trojan, anti-spyware protection.

CAUTION: ESET recently came out with ESET NOD32 Antivirus 5 and since I could "upgrade" for free, I tried it. In the next 5 days after upgrading I had problems I never had before, and my system became unstable. I was using the same settings I had for NOD32 Av 4. I did try changing settings. But after 5 days of instability, I uninstalled NOD32 Av 5 and reinstalled NOD32 Av 4. My system is back to being stable.

With NOD32 Av 5 I noted from its look-and-feel, that is likely written with Win7 in mind. I suspect that ESET did not fully test Av 5 on a Win XP system.

Tuesday, January 25, 2011

LINUX - Linux Mint

Being the techie I am, I recently changed my laptop from Ubuntu to Linux Mint. In fact, I'm using it as we "speak."

Screenshot of my customized desktop (not their default):

(click for better view)

Why? The ONLY reason is the upcoming Ubuntu 11 is changing the environment to UNITY, which I do not like.

Why Mint? Click the desktop pic for the better view and see. Nice?

The other reason, a Usenet post pointed me to Mint and stated his experience. He is a high school teacher and is converting the class lab systems to Linux Mint. He reported that his students (WinXP users) took only 15min average to become familiar with, and use Mint, without assistance.

You can see from the desktop screenshot that it is almost identical to WinXP. Click [Menu] (aka Start) and you get a WinXP-like menu.

In my short experience it boots slightly faster than Ubuntu did.

And it has all the features that Ubuntu had. One of Mint's Software Manager many sources is Ubuntu's Repositories.

The only issue I had with installation was enabling fileshare. But this was just me having a memory issue. Linux installs do NOT automatically install the Windows filesharing service SAMBA. This is done whenever you attempt ANY function that requires fileshare.

If you are thinking of going Linux, take a look at Linux Mint.


GENERAL LINUX ISSUE:

I've been using Linux (Ubuntu now Mint) for some time and no OS is without its I-don't-like issues. One of my personal grips is the File Browser (aka Nautilus).

See screenshot below:

(click for better view)

Note the File Browser sidebar. You drag-drop what you want displayed from the main pane. This is important because what is displayed in any Save in folder drop-down list shows ONLY what is in the sidebar.

See screenshot of the typical save dialog. Note manual entry of the filename.


(click for better view)


I prefer a 2-pane File Manager, which IS available via Mint's Package Manager (aka Synaptic Packaging Manager). See screen shot of Gnome-Commander below:

(click for better view)


Well that's it for now.

Friday, January 14, 2011

WORLD WIDE WEB - Wikipedia's 10th Year

"Wikipedia – an unplanned miracle" by Clay Shirky, Guardian UK 1/14/2010

Every day since its birth 10 years ago, Wikipedia has got better. Yet it's amazing it even exists.

Wikipedia is the most widely used reference work in the world. That statement is both ordinary and astonishing: it's a simple reflection of its enormous readership; and yet, by any traditional view about how the world works, Wikipedia shouldn't even exist, much less have succeeded so dramatically in the space of a single decade.

The cumulative effort of Wikipedia's millions of contributors means you are a click away from figuring out what a myocardial infarction is, or the cause of the Agacher Strip war, or who Spangles Muldoon was. This is an unplanned miracle, like "the market" deciding how much bread goes in the store. Wikipedia, though, is even odder than the market: not only is all that material contributed for free, it is available to you free; even the servers and system administrators are funded through donations. That it would become such a miracle was not obvious at its inception and so, on the occasion of its 10th birthday, it's worth retelling the improbable story of its genesis.

Ten years ago today, Jimmy Wales and Larry Sanger were stuck trying to create Nupedia, an online encyclopedia with a seven-step publishing process. Unfortunately, that also meant seven places where things could grind to a halt. However, after nearly a year of work, almost no articles had actually been published.

So, 10 years ago tomorrow, Wales and Sanger decided to try a wiki, as a way of cutting through some of that process. Sanger sent an email to Nupedia collaborators about this new way of working, saying: "Humor me. Go there and add a little article. It will take all of five or ten minutes."

The "Humor me" bit was necessary because the wiki is social media at its most radical. Invented in the mid-90s by Ward Cunningham, a wiki has at its core only one technical function: edit. You don't need permission to add, alter, or delete text, and when you are done, you don't need permission to publish.

More remarkably, though, a wiki also has at its core only one social operation: I care. The people who edit pages are the ones who care enough to edit them. Putting the people who care in charge, rather than anointing experts or authorities, was so radical that Wales and Sanger didn't propose replacing Nupedia with a wiki. Instead, they proposed using the wiki to generate raw material for Nupedia.

The participants, however, had other ideas. The ability to create an article in five minutes, and to make an existing article a little better in less, was so infectious that in a matter of days there were more articles on the nascent wiki than on Nupedia. The wiki was so good, and so different from Nupedia, it was soon moved to its own site. Wikipedia was born. (Nupedia was shut down a few months later; Sanger also left the project.)

That process continues today, making Wikipedia an ordinary miracle for more than 250 million people a month. Every single day for the last 10 years Wikipedia has got better because someone – several million someones in all – decided to make it better. Sometimes that meant starting a new article. Mostly it meant editing an existing one. Occasionally it meant defending Wikipedia against vandalism. Always it meant caring. Most participants care a little, editing only one article. A handful care a lot, contributing hundreds of thousands of edits, across thousands of articles, over years. Most importantly, taken together, all of us have contributed enough to make Wikipedia what we have today. What looks like a stable thing is in fact a result of ceaseless attempts to preserve what is good, and to improve what isn't. Wikipedia is best understood not as a product with an organization behind it, but as an activity that happens to leave an encyclopedia in its wake.

That shift, from product to activity, has involved the most amazing expansion of peer review ever: Wikipedia's editor-in-chief is a rotating quorum of whoever is paying attention. Many of Wikipedia's critics have focused on the fact that the software lets anyone edit anything; what they miss is that the social constraints of the committed editors keep that capability in check. As easy as the software makes it to do damage, it makes it even easier to undo damage.

Imagine a wall where it was easier to remove graffiti than add it: the amount of graffiti on such a wall would depend on the commitment of its defenders. So with Wikipedia; if all its passionate participants were to stop caring, the whole thing would be gone by next Thursday, overrun by vandals and spammers. If you can see Wikipedia right now, it means that again, today, the good guys won.

Wikipedia isn't perfect, of course. Many mediocre articles need improvement. The editors are not diverse enough in age, gender or ethnicity. Biographies of the living remain a persistent site of mischief. Defenses erected against vandals and spammers also see off novices and exhaust old-timers. But Wikipedia isn't just an activity at the level of the articles; from the individual edits all the way up to the culture of the whole, Wikipedia is a public good created by the public, so it falls to the people who care to try to take on these problems as well. As long as that culture continues to embrace "be bold" as a core value, its status as one of the largest cumulative acts of generosity in history will persist. So happy 10th birthday to Wikipedia, and ardent thanks to the millions of people who have added and altered and argued and amended, the people who have created the most widely used reference work in the world. Thanks for telling us the story of the Stonewall riots and how Pluto got demoted to "dwarf planet"; about the Great Rift Valley and the Indian Ocean tsunami; about lion fish and tiger teams and bear markets. And along with the birthday wishes, here's hoping enough of us keep caring enough to be able to greet you again, in rude good health, for your 20th.

Thursday, January 6, 2011

TECHNOLOGY - Better Wired Brains?

"Is Technology Wiring Teens to Have Better Brains?"
PBS Newshour 1/5/2011

Excerpt from transcript

MILES O'BRIEN (Newshour): It is seductive, no matter what the age, but is it efficient? Can we really multitask?

Well, yes, with a caveat.

MARCEL JUST, Carnegie Mellon University: We can do it, but at tremendous cost. You can't do two tasks as well as you can do each one separately.

MILES O'BRIEN: Neuroscientist Marcel Just is doing some groundbreaking research on the human brain at Carnegie Mellon University.

So, we pay a big penalty for doing more, two things at once?

MARCEL JUST: That's right. There's only so much brain capability at any one time, throughput. And you can divide it down as much as you want to, but the price will be even higher then.

MILES O'BRIEN: Like driving and talking on the phone. A few years ago, Just did a study on this. His conclusion? Even an idle conversation takes a 40 percent bite out of your brainpower. You might as well be drunk.

So, multitasking is not a myth, but efficient multitasking might be?

MARCEL JUST: Yes. Multitasking with no cost is a myth. I think there's no free lunch there.

Tuesday, December 21, 2010

NETWORK - Internet Access, NET Neutrality

"F.C.C. Is Set to Regulate Net Access" by BRIAN STELTER, New York Times 12/20/2010

Excerpt

The Federal Communications Commission appears poised to pass a controversial set of rules that broadly create two classes of Internet access, one for fixed-line providers and the other for the wireless Net.

The proposed rules of the online road would prevent fixed-line broadband providers like Comcast and Qwest from blocking access to sites and applications. The rules, however, would allow wireless companies more latitude in putting limits on access to services and applications.

Before a vote set for Tuesday, two Democratic commissioners said Monday that they would back the rules proposed by the F.C.C. chairman, Julius Genachowski, which try to satisfy both sides in the protracted debate over so-called network neutrality. But analysts said the debate would soon resume in the courts, as challenges to the rules are expected in the months to come.

Net neutrality, broadly speaking, is an effort to ensure equal access to Web sites and cutting-edge online services. Mr. Genachowski said these proposed rules aimed to both encourage Internet innovation and protect consumers from abuses.

“These rules fulfill a promise to the future — to companies that don’t yet exist, and the entrepreneurs that haven’t yet started work in their dorm rooms or garages,” Mr. Genachowski said in remarks prepared for the commission’s meeting on Tuesday in Washington. At present, there are no enforceable rules “to protect basic Internet values,” he added.

Many Internet providers, developers and venture capitalists have indicated that they would accept the proposal by Mr. Genachowski, which Rebecca Arbogast, a regulatory analyst for Stifel Nicolaus, a financial services firm, said “is by definition a compromise.”


UPDATE

"F.C.C. Approves Net Rules and Braces for Fight" by BRIAN STELTER, New York Times 12/21/2010

Excerpt

Want to watch hours of YouTube videos or sort through Facebook photos on the computer? Your Internet providers would be forbidden from blocking you under rules approved by the Federal Communications Commission on Tuesday. But if you want to do the same on your cellphone, you may not have the same protections.

The debate over the rules, intended to preserve open access to the Internet, seems to have resulted in a classic Washington solution — the kind that pleases no one on either side of the issue. Verizon and other service providers would prefer no government involvement. Public interest advocates think the rules stop far short of ensuring free speech.

Sunday, December 19, 2010

WINDOWS - Fix-It Solution Center

Due to a problem on my home system I was reminded of a site for fixing Windows problems.

Microsoft Fix it Solution Center

(click for better view)

For example, what I used to fix my problem was the top option (screenshot):
Diagnose and repair Windows File and Folder Problems automatically

The downloaded file installed PowerShell and ran the tool. I selected Other from the checkbox list and continued. The tool found that my Recycle Bin was corrupted (my problem) AND fixed it. Then I rebooted.

Have a Windows problem? Try it.

Thursday, December 16, 2010

COMPUTERS - Air Force Supercomputer

"Air Force Uses PS3 Game Consoles to Build Supercomputer" by Brian Kalish, NextGov 12/16/2010

Video game consoles are now more than just for fun. An Air Force supercomputer, built from off-the-shelf components, includes 1,716 PlayStation 3 game consoles.

The machine, known as the Condor Cluster, is estimated to be one of the greenest computers in the world. And if that wasn't enough, it also is the 35th or 36th fastest computer in the world, said Mark Barnell, director of high performance computing and the Condor Cluster project at the Air Force Research Laboratory, reported Government Computer News.

One of the main reasons to use PS3 processors was cost. Condor cost about $2 million to build, compared to $50 million to $80 million for a similar supercomputer, the Air Force said in a news release.

The computer also can read 20 pages of information per second, which makes it about 50,000 times faster than the average laptop, CNET reported.

Initial tasks for the machine, located in Rome, N.Y., include neuromorphic artificial intelligence research, in which programmers will teach the computer to read symbols, letters, words and sentences so it can fill in human gaps and correct human errors, CNET reported.

Tuesday, December 14, 2010

SECURITY - User's Bad Habits

"Gawker Hacking Exposes Some Web Users' Bad Password Habits"
PBS Newshour 12/13/2010

Excerpts from transcript

JEFFREY BROWN (Newshour): All right, we talk about this group called Gnosis. How much do we know about what -- who they are? And what did they do to Gawker?

HARI SREENIVASAN, staff writer, Wired.com: Well, a lot of these sort of hacker groups are very shadowy in nature, in the sense that they -- there's no card-carrying membership that says, I'm part of this club. I'm the one who did this, and here is my address and phone number.

So, really, what they did to Gawker was come in behind the scenes in the past few weeks, past few months, figure out vulnerabilities, and essentially start to take the keys to the kingdom. Everything that Gawker held dear, most important, the user information, they took all of that out and splayed it out across the Internet.

They didn't hide the information for themselves for some sort of kind of nefarious means. They said, here, take it, because this is really -- they're the crown jewels for a website.
----
JEFFREY BROWN: Now, how are those people affected, in what ways?

HARI SREENIVASAN: Well, so, the thing -- it kind of gets back to a little bit of social engineering.

So a lot of times people don't make separate passwords and separate usernames for different websites. Sometimes, they use the same website or same e-mail address that I have for work on to a site like Gawker, and then maybe that's the same password that gets me into Facebook, and then it's also connected to Twitter.

So, as we see all of these different kind of communities that we participate in during the day, people aren't very good at keeping these walls separate. So, that's where the real influence is.

Bold-blue emphasis mine

Thursday, December 9, 2010

SOFTWARE - More on Open Office

"The Legacy of OpenOffice.org" from Open Source 11/7/2010

When I hear the word “fork”, I reach for my gun. OK. Maybe it is not that bad. But in the open source world, “fork” is a loaded term. It can, of course, be an expression of a basic open source freedom. But it can also represent “fighting words”. It is like the way we use the term “regime” for a government we don’t like, or “cult” for a religion we disapprove of. Calling something a “fork” is rarely intended as a compliment.

So I’ll avoid the term “fork” for the remainder of this post and instead talk about the legacy of one notable open source project, OpenOffice.org, which has over the last decade spawned numerous derivative products, some open source, some proprietary, some which fully coordinate with the main project, others which have diverged, some which have prospered and endured for many years, others which did not, some which tried to offer more than OpenOffice, and others which attempted, intentionally, to offer less, some which changed the core code and other which simply added extensions.

If one just read the headlines over the past month one would get the mistaken notion that LibreOffice was the first attempt to take the OpenOffice.org open source code and make a different product from it, or even a separate open source project. This is far from true. There have been many spin-off products/projects, including:
  • StarOffice (with a history that goes back even further, pre-Sun, to StarDivision)

  • Symphony

  • EuroOffice

  • RedOffice

  • NeoOffice

  • PlusOffice

  • OxygenOffice

  • PlusOffice

  • Go-OO

  • Portable OpenOffice

  • and, of course, LibreOffice
I’ve tracked down some dates of various releases of these projects and placed them on a time line above. (see full article)

So before we ring the death knell for OpenOffice, let’s recognized the potency of this code base, in terms of its ability to spawn new projects. LibreOffice is the latest, but likely not the last example we will see. This is a market where “one size fits all” does not ring true. I’d expect to see different variations on these editors, just as there are different kinds of users, and different markets which use these kinds of tools. Whether you call it a “distribution” or a “fork”, I really don’t care. But I do believe that the only kind of open source project that does not spawn off additional projects like this is a dead project.

Minor edit of list mine

Thursday, December 2, 2010

SECURITY - FTC Changes Stance on Internet Privacy

"F.T.C. Backs Plan to Honor Privacy of Online Users" by EDWARD WYATT and TANZINA VEGA, New York Times 12/1/2010

Excerpt

Signaling a sea change in the debate over Internet privacy, the government’s top consumer protection agency on Wednesday advocated a plan that would let consumers choose whether they want their Internet browsing and buying habits monitored.

Saying that online companies have failed to protect the privacy of Internet users, the Federal Trade Commission recommended a broad framework for commercial use of Web consumer data, including a simple and universal “do not track” mechanism that would essentially give consumers the type of control they gained over marketers with the national “do not call” registry.

Those measures, if widely used, could directly affect the billions of dollars in business done by online advertising companies and by technology giants like Google that collect highly focused information about consumers that can be used to deliver personalized advertising to them.

While the report is critical of many current industry practices, the commission will probably need the help of Congress to enact some of its recommendations. For now, the trade commission hopes to adopt an approach that it calls “privacy by design,” where companies are required to build protections into their everyday business practices.