I hope this doesn't happen to Sprint's WiMax plans...

Municipal wireless has been a failure. The City of Tempe projected 32,000 users, but only had 600 at its last published count, which was back in April 2006. It’s also failing in Philadelphia, Minneapolis, Portland, Chicago, and Taipei. (Also see Technology Liberation Front, which makes the same point.) UPDATE (November 8, 2007): Sprint and Clearwire have scrapped a plan to jointly build out their WiMax networks, and it looks like Sprint may scale back its own WiMax plans, as well. ...

September 21, 2007 · 1 min

Lessons for information security from Multics

Bruce Schneier brings attention to a 2002 paper by Paul Karger and Roger Schell (PDF) about lessons learned from Multics security that are still relevant today, and Multicians come out of the woodwork in the comments. Karger and Schell were part of the Air Force “tiger team” that ran penetration attacks against Multics in the 1970s. They were successful, which ultimately led to a Multics security enhancement project, the result of which was that Multics was the first commercial operating system to obtain a B2 security rating from the National Computer Security Center. I played a small part in that project, fixing some bugs and helping to run tests of Multics’ Trusted Computing Base (TCB).

September 19, 2007 · 1 min

Mirrors without glass

Daniel Rozin’s Weave Mirror uses 768 motorized C-shaped prints in what appears like a basket weave patterned screen, each of which can rotate independently to change its shade, producing a grayscale image of whatever is in front of it. Photos and video at Engadget. This reminds me of Julius Popp’s Bitfall, which draws images with falling water drops.

September 19, 2007 · 1 min

Microsoft updates Windows XP and Vista without user permission or notification

Microsoft has admitted that it has updated nine executable files in XP and Windows on users’ machines even when they have turned off automatic updates. These files are part of the Windows update feature itself. Corporate users who use SMS rather than Windows update for OS patches are not affected. Bruce Schneier raises the question of whether this ability to force updates could be exploited by a third party. I would hope that such updates are digitally signed, so that they can only come from Microsoft, but a commenter at Schneier’s blog notes that even if that is the case there is a potential vulnerability created: There may be an attack vector, even if the updates are signed by Microsoft. The signed updates would always be silently accepted. If Microsoft ever signs an update which later turns out to be vulnerable to some attack (this has happened before with signed activeX components), an attacker could re-push this vulnerable update and introduce a known vulnerability into the target system.Another commenter notes that this feature could be used by law enforcement to install a keylogger on a machine, if Microsoft agreed to do it.

September 17, 2007 · 1 min

Anti-P2P company suffers major security breach

MediaDefender, a company that attempts to disrupt the sharing of copyrighted material owned by its clients on peer-to-peer filesharing networks, has suffered an embarassing security breach–the leaking of 700 MB of emails from senior employees in the company. The leak allegedly occurred because one senior employee was forwarding company email to his Gmail account, and he used the same password for his Gmail account that he used to register for a P2P service of some kind. This breach demonstrates the importance of adhering to corporate policies about use of external mail providers and using good password security–anything really important should have a unique password, not the same one used for accessing a variety of online websites and services. UPDATE: It’s now being claimed that MediaDefender’s phone systems have also been compromised for the last nine months, and a 25-minute phone call between MediaDefender and the New York Attorney General’s office is circulating, as well as a transcript. The transcript indicates that the AG’s office was concerned (rightly so, apparently) about a possible mail server compromise at MediaDefender; the MediaDefender representative states at one point that he is speaking over a VoIP connection. UPDATE: It seems the record companies are using information about P2P downloads collected by MediaDefender to make marketing decisions. Here’s a quote from one of the leaked emails (quoted from SlashDot): Subject: Nicole Scherzinger Date: Fri, 24 Aug 2007 15:14:31 -0700 Nicole from pussy cat dolls has a single called “whatever u like”. It’s not selling well on itunes or playing that great on radio. A song called “Baby Love” just leaked (I don’t know how long ago). Interscope wants to know if Baby Love is picking up steam on p2p. They need to make a decision by early next week on whether they should switch to this song as the single. Please get me a score comparison on Monday for these two tracks. Also, please put beyonces, fergie, gwen, and nelly furtado singles as comparisons.UPDATE (September 17, 2007): Ars Technica has a good summary of the breach and what the leaked information shows about what MediaDefender has been up to with its video upload service (apparently designed to encourage the upload of copyrighted content as a sort of sting operation), MiiVi. MediaDefender says it was an “internal project” that was supposed to be password protected but was inadvertently made public. CNet has a story on MediaDefender which notes: ...

September 16, 2007 · 3 min

Lomborg, global warming, and opportunity costs

I’ve not read Bjorn Lomborg’s new book (nor his previous one), but I have read enough of what he has written to suspect that some of those who are ridiculing one of his arguments don’t understand it. For example, Bob Park of the American Physical Society’s “What’s New” writes: Bjorn Lomborg’s “Cool It: The Skeptical Environmentalist’s Guide to Global Warming” is out. Well, yes it is getting warmer he finds, but aside from polar bears, it just means more beach weather. We’ve got bigger problems, he says. Instead of spending all that money trying to prevent warming, let’s focus on making everyone rich so they can all buy air conditioners.P.Z. Myers at Pharyngula writes: He also has a bad argument about relative spending: he suggests that spending on climate change would reduce spending on other pressing issues, like the fight against malaria. It’s a bad choice. Malaria research is already underfunded — it’s a third-world disease, don’t you know, one that mainly affects those tropical countries, so the wealthy western nations typically don’t prioritize it very highly. We don’t take our big pots of money and allocate it into aliquots appropriate to the world’s needs already, so for an economist to sit there and pretend that climate research is a drain on tropical disease research is comical. Especially since he seems unaware of how one feeds into the other. Hey, if the world warms up, tropical diseases will creep northward into Europe and North America, and then we’ll be fighting the economic effects of both direct effects of climate change and new diseases.But as I understand it, Lomborg is making a simple point about opportunity costs–that money spent on climate change mitigation can’t be spent on other things, and that it would be better off spent on things like fighting malaria (which I’m sure he would agree with Myers is underfunded, since it’s #4 on the Copenhagen Consensus 2004 list of “very good projects” to spend money on), because the amount of benefit received for each dollar spent is so much greater. To make the same point–I have looked into putting solar cells on my house, both to reduce my carbon footprint and my long-term energy costs, but I’ve decided against it because even with the tax incentives and my power company’s willingness to subsidize half the cost, it’s still not cost-effective. (I’m hoping new solar cell technologies will improve efficiency and lower cost so that I will be able to become less dependent upon the electrical grid). Instead, I’ve spent much smaller amounts of money that have had far more bang for the buck, replacing my incandescent lights with CFLs (though LEDs and other new promising technologies are on the way as better sources of light), adding insulation, and improving the efficiency of my air conditioning units through regular maintenance. These things I’ve done not only have an impact on my energy use and climate change, they are things which provide me with direct economic benefit as well–thus these are things that rational people will be doing independently of government regulation and spending. Lomborg–or at least the Copenhagen Consensus–is not saying that climate change deserves no attention. The premise of the Copenhagen Consensus is that if the world spent an additional $50 billion over the next five years to address ten categories of global challenges (one of which is climate change), how would that money best be spent to provide the greatest net benefit. That seems to me to be an entirely worthy effort, and this kind of cost-benefit calculation should be given greater weight in public policy decisions. Instead, however, most politicians like to make arguments based on the assumption that any law, regulation, or government spending that saves even one life (or prevents one child from seeing something offensive) is worth doing, whether or not that generates enormous opportunity costs. My personal behavior–and I suspect that of those criticizing Lomborg on this point–demonstrates that I don’t consider climate change my number one priority. In my case, I live in a large house that uses a lot of electricity, I travel frequently by plane, I drive a car instead of using public transportation, I eat meat instead of being a vegetarian like my wife. Each of these things causes, directly or indirectly, an increase in carbon dioxide emissions over the alternatives. UPDATE (December 16, 2008): I just came across this description of Lomborg’s overall behavior with respect to the climate change debate, which I think is likely accurate. ...

September 15, 2007 · 7 min

Another Sony rootkit

F-Secure announced yesterday that it has found another Sony product that installs a rootkit and hidden directory on Windows machines. Last time it was the copy protection associated with music CDs, this time it’s software associated with a fingerprint reader for the Sony MicroVault USM-F memory stick, which Sony says is now no longer for sale. The use of the memory stick causes files to be installed into a hidden directory on your hard drive which is hidden from the operating system, including antivirus scanning. This means that, like the hidden directory created by the CD copy protection scheme, the directory can be used by other malicious software to hide itself.

September 5, 2007 · 1 min

Time travel investment strategies

Long or Short Capital takes a look at a few investment strategies available to the time traveler, including “groundhog maximization,” “terminator option protection,” and “alien/squid technology asset allocation.”

August 21, 2007 · 1 min

Lying at the Weekly Standard

Julian Sanchez points out the staggering misrepresentation by those arguing that the recent increase in wiretapping power amounts to nothing more than an update of FISA procedures to reflect current technology. (Hat tip to Tim Lee at the Technology Liberation Front.)

August 17, 2007 · 1 min

Bruce Schneier interviews Kip Hawley

Bruce Schneier has posted all five parts of his interview with Transportation Security Administration head Kip Hawley: Part 1, Part 2, Part 3, Part 4, Part 5.

August 16, 2007 · 1 min
Mastodon Verification