If you tell enough stories, perhaps the moral will show up.

2008-12-24

Just for reference: this is the contents of the more mad son's Christmas list:
      December 25 2008 Thursday David's Christmas Presents
      Thomas the tank engine Percy and the Signal VHS
      Thomas the tank engine The Runaway VHS
      Thomas the tank engine Escape VHS
      Thomas the tank engine Thomas Gets Bumped Bumper Special VHS
      Thomas the tank engine Thomas's Christmas Party Bumper Special VHS
      Thomas the tank engine Rock n Roll VHS
      Thomas the tank engine Story and Song Collection VHS
      Thomas the tank engine Happy Holidays VHS
      Tots TV Bike Ride Bumper Special VHS
      Fun Song Factory 3 Party time at the Fun Song Factory VHS
      Fun Song Factory 2 VHS
      Tumble Tots Action Song Favourites [1996] VHS
      Tumble Tots The Action-Song Sing-A-Long VHS
      Tweenies Song Time Is Fab-A-Rooney [1999] VHS
      Maisy Maisy's ABC VHS
      Canon Digital Camcorder 35x and 1000x DVD Video
      Nikon Coolpix P50 Digital Camera 8.1 MP 3x optical zoom black (Upgrade with SD)
That's right. Fifteen videos (the "VHS" is not a misconception -- he wants tape cassettes) and two mid-range, top brand cameras.

We got him a Fuji S5700 which is cheap now and has quite a good video function (and is currently the best camera in the house), and Mrs U has had a trawl round the Maidstone charity shops for videos. We'll see how it goes.

2008-12-13

Spam Counter - 2008 December 13: 634

Can't put this on the graph, but one month on from McColo it's still falling.....

2008-11-30

Spam Counter - 2008 November: 852

This month's drop is the the famous McColo effect. It'll be interesting to see how a whole month without McColo looks on 12/12.
The content seems the same as ever.
Two interesting papers about email-delivered nuisances: spam and phishing. Each offers methodologies which finally give realistic estimates for the return from penis spam and phishing. Both agree there's very little profit in it -- mugs and losers are, after all, a limited resource. Which is nice.

2008-11-26

Chinese Hackers are Real, I Tell You...

... And they're planning to flood the world with cheap telephones.

Al sits close to the Head of IT -- a position that reflects his operational centrality, and the affection in which he is held. But he came to me with a puzzle about his Hotmail. It seemed that he'd managed to send himself, and all his contacts, an email advertising http://www.feixiangyu.com -- an electrical distributor.
Well, we looked at things like his spam folder, and whether it was just in fact a particularly artful non-delivery notice. But soon he had replies from his contacts congratulating him on his new business venture.....
Now the beauty of Hotmail is that it's easy to attribute. The X-Originating-IP header gives just that -- the IP address of the originating computer, which is the IP that Hotmail saw as the browser that "got" (GETed?) the send links. This one was 123.53.119.162 and Sam Spade plumps that in the middle of the Middle Kingdom. The ISP is Chinanet, and the PoP is Zhengzhou -- capital of Henan, a respectful distance from the Yellow River -- seven million people in a few square miles, and at least one dodgy marketing guy.
On the whole, I'd rather be hacked by Chinese shopkeepers than the Russian Mafia -- you're less likely to have your bank account emptied. I told Al to change his passwords, check his bank statement, and run an online AV check on his home PC. I sure hope that shows something, otherwise I'm going to have to wonder whether it happened on his office machine, and that's something I just don't want....

2008-11-17

Microclimate (2)

A nice strong frosty morning. When the train went into Sevenoaks tunnel, the double-glazed windows were clear, but when it came out, they were obscured by condensation -- on the outside.

I guess it takes a while for the roots of the North Downs to cool.

2008-11-05

Solving the Wrong Problem (a different one)

Now, listen. Encryption is probably not the solution to your problem. We hear a lot about encryption these days and it seems to be widely imagined as the solution to a problem, or a reason why it's not a problem: "it was encrypted", "we'd better encrypt that". Keep an ear cocked for that sort of thinking, because it is the sounds of someone making a mistake. Encryption doesn't solve any problem, not even access control problems. It replaces access control with a smaller, tougher issue: Key Management. Whether that helps at all depends on the situation. It's late and I'm tired so I'll cut through and state the facts. Encyption only helps when the key management problem can be solved, and the key management problem can only be solved in strict binary situations: When you can cast the problem in terms "everyone in this group gets full access without per-user auditing and no-one else gets anything" then maybe you could try encryption:

  • Access for a single person against the whole world -- keeping personal secrets
  • The same plan for a group small enough to maintain perfect mutual trust. Some of us feel that the maximum size for such a group is one.
  • Shared channel against the world: the VPN and encrypted device
It's Us (or rather Me) and Them. If you have any other problem, don't bother with encryption.

2008-11-02

Voter Insecurity

It hardly matters, but on the whole, and despite even Sarah Palin, I somewhat prefer the idea of President McCain. The other guy is just so -- well -- young. As well as being a lifetime politician.

If McCain loses, well, that's just what the polls were saying. It's easy to accept unsurprising results.

But if he wins, I won't know what to think. The trouble I have is that I just don't believe in the integrity of the US voting system. Why do you need a machine to vote with? It seems as though the sole purpose is to create opportunities to bugger it up, with ballot layouts designed to fit around punch cards, more-or-less functional touch screens and the Dear knows what else.

It seems that some counties actually have voting machines where the votes only exist as totals on a CF card. That's OK for money: You can audit against the books of first entry. But ballot papers -- the petty cash slips of the political world -- are just missing from conventional PC based voting machines.

So I'm hoping for a landslide, because I don't think the USA needs another argument about who truly won.

2008-11-01

The Angry Cyberwarrior

All over the world, we are told, war departments cosset their lists of unpublished vulnerabilities, kept in reserve to get into enemy systems. If that's true, there must have been more than one outburst of tantrums and glum looks when MS published MS08-067. It's a splendid vulnerability and one that would have saved a lot of social engineering and spying.

Now it's worthless.

Spam Counter - 2008 October: 1387

No real change. Penis pills and Russian ladies: Olga and TatianaG want to meet me?

2008-10-28

MS08-067

I think this is the second or third time MS have published an out of cycle patch, and it may be the first proper Windows (as opposed to IE or Office) vulnerability to get this treatment.

It probably deserves it. When I read the notice, my heart sank. I remember staying up thirty-six hours in August 2003 dealing with Nachi/Welchia running through our systems because we didn't suceed in patching MS03-026. It didn't help that I was pissed as a fart for the first six hours or so -- having been hauled out of the pub at 10PM by an aggrieved network engineer watching our traffic heading through the roof -- and my boss had to hide me in the machine room trying to figure out what was going on, while she explained to her boss that she'd sent me home. What did help was that it used ping to explore the network, and it dropped nice clear signature files. That night I experienced the sheer beauty of Cisco VACLs (level 2 filters) when I found we could use them to suppress ICMP, and that left the worm blind enough for us to clean up by hand, though I didn't dare turn it back on for a week, and we left the filter on the link to Group for years....

That vulnerability was in DCOM -- pretty important, but possibly fixable by switching off the service in the registry. This one is SMB, and there's no switching that off. You may as well shut down.  Oh, and a modern malware wouldn't make the same mistakes as nachi, or be so gentle to its hosts. So I was pretty uncompromising all Friday, and reading the increasingly nervy statements from MS, I really don't think I was too rough. We're inserting this patch as a special into the October/September patch cycle that was just starting its route to live on the Friday. We'll have to re-do all the test servers. I hope that's enough.

Real Financial Insecurity

Prostitute's postcard seen today in a phone box in King William Street:

  • A very conventional picture of a youngish woman in partial undress, and
  • A site: "London Bridge" -- in reality that would be far out in the Borough, but never mind...
All ordinary. But what struck me was the caption. It wasn't "Maid for Pleasure." It wasn't "New 19 YO Swedish." It wasn't even that perennial City favourite: "Fully Equipped Dungeon."

No. The caption was: "Kisses and Cuddles." If that isn't the clearest sign of financial calamity, I don't know what would be.

God bless her, though. It's wonderful to imagine that there's a living in snogging.

2008-10-20

Consequences of Solving a Non-problem

http://wvgazette.com/News/200810180251
Whatever was so wrong with marking X's in the boxes with a 3B pencil?
Or is the real problem that people are voting wrong?

2008-10-07

The Current Status of the Pound

I'm writing this on 28/10 but I'm back-posting to the day it happened, right in the middle of the (first?) UK banking turmoil.
I had occasion to use the toilet in the headquarters of a big four bank. As I reached for the paper I noticed a little blemish on the white(ish) sheet. Being unsqeamish about this sort of thing, I gave it a little scratch and a shred of coloured paper came away on my finger nail. I pushed back my specs for a closer look and found a tiny fragment of a £10 Bank of England note -- barely a millimetre across, but the engraving and colour so fine as to be unmistakeable. That bank had been wiping their collective arses on thousands of pounds in fine rag paper -- and they never knew.
I do wonder whether it's co-incidence, or whether support from the BoE comes with an unpublished obligation to help them get rid of their pulp....

2008-10-06

Boot (If You Can) and Nuke.

Endless problems trying to get DBAN to boot reliably off a USB stick for Desktop to erase a bunch of machines with.

The Windows installer never quite managed to make the stick bootable and there isn't an installer for Linux. Eventually I booted into linux and just dd'd the floppy disk image over the raw device (/dev/sdb rather than /dev/sdb1 -- though I'd previously made sdb1 bootable) -- there are no partitions on a floppy, and that seems to boot, but not very happily.

I'd have made a real floppy, but I can't believe that many of those machines would actually manage to read a whole FD without error. What they don't have is CD readers, and I don't know the general process to make an ISO bootable on a USB stick.