Tuesday, October 31, 2006

Tuesday 8:00 Buzz - 10/31/2006

This continues my effort to chronicle the guests and topics covered on the Stan Woodard's Tuesday 8:00 Buzz on WORT-FM

Next Tuesday (11/7/2006) is election day!! Exercise your rights and get out and vote! You can Register at the polls - Click for details

Today's Show

First Guest: Johnny Winston, Jr School board members, call-in discussing the upcoming referendum. More information: Madison Community and Schools Together (CAST).

Second Guest: Gerald Horne John J. and Rebecca Moores Professor of History and African American Studies at the University of Huston and Author of The Final Victim of the Blacklist - John Howard Lawson, Dean of the Hollywood Ten (Non-Fiction).

Announcements
  • Anti-Racism Workshop - A six-week workshop led by Groundwork to examine how racism and white supremacy impact our lives, institutions and movements for social justice. Discuss the history, hear stories of resistance and analyze how white privilege plays out in our communities, working spaces and organizations. For More Information: Terry Ross 608-279-2710 or trtrtr@charter.net WNPJ story.

Tuesday, October 24, 2006

Tuesday 8:00 Buzz - 10/24/2006

This continues my effort to chronicle the guests and topics covered on the Stan Woodard's Tuesday 8:00 Buzz on WORT-FM

Special Program Note:

It's a pledge drive! Call 608-256-2001, 866-899-WORT or pledge online at wort-fm.org.

Today's Show

First Guest: Karen Cerulo Professor of Sociology at Rutgers University and Author of Never Saw It Coming: Cultural Challenges to Envisioning the Worst (Non-Fiction)

Second Guest: Bayo Ojikutu Author of Free Burning (Fiction).

Announcements
  • Anti-Racism Workshop - A six-week workshop led by Groundwork to examine how racism and white supremacy impact our lives, institutions and movements for social justice. Discuss the history, hear stories of resistance and analyze how white privilege plays out in our communities, working spaces and organizations. For More Information: Terry Ross 608-279-2710 or trtrtr@charter.net WNPJ story.
  • The African Presence in Mexico is showing at The Mexican Fine Arts Center Museum in Chicago.

Tuesday, October 17, 2006

Tuesday 8:00 Buzz - 10/17/2006

This continues my effort to chronicle the guests and topics covered on the Stan Woodard's Tuesday 8:00 Buzz on WORT-FM

Special Program Note:

It's a pledge drive! Call 608-256-2001, 866-899-WORT or pledge online at wort-fm.org.

Today's Show

First Guest: Earl Ofari Hutchinson Author of The Emerging Black GOP Majority (Non-Fiction)

Second Guest: Thomas Schaller Author of Whistling Past Dixie: How Democrats Can Win Without the South (Non-Fiction).

Announcements
  • Saturday, Oct 21st Starting at 10AM in Beloit - The Black Star Project in Beloit presents a funeral service for the "N word". Schedule: 10AM at Bethel AME Church 1314 Athletic Ave, Noon rally at Summit Park, Funeral Service 2PM at New Zion Baptist Church, 1905 S Mound Ave followed by a funeral procession and repast with food, music and fellowship.
  • Anti-Racism Workshop - A six-week workshop led by Groundwork to examine how racism and white supremacy impact our lives, institutions and movements for social justice. Discuss the history, hear stories of resistance and analyze how white privilege plays out in our communities, working spaces and organizations. For More Information: Terry Ross 608-279-2710 or trtrtr@charter.net WNPJ story.
  • The African Presence in Mexico is showing at The Mexican Fine Arts Center Museum in Chicago.

Wednesday, October 11, 2006

Torture Bill as C Code

Having made this coding error several times myself, this makes me laugh.

Schneier on Security: Torture Bill as C Code

Kevin boils down the new terrorist (and others) arrest/detainment/torture bill into a small piece of C code:

if (person = terrorist) {
     punish_severely();
} else {
     exit(-1);
}

There's one obvious error, but there are other problems with the code. Anyone care to comment? (BoingBoing commentary.)

(Torture Bill as C Code via Schneier on Security.)

Tuesday, October 10, 2006

Tuesday 8:00 Buzz - 10/10/2006

This continues my effort to chronicle the guests and topics covered on the Stan Woodard's Tuesday 8:00 Buzz on WORT-FM

Special Program Note: Today's Show

First Guest: Kim Williams - Associate Professor at Harvard's Kennedy School of Government and Author of Mark One or More: Civil Rights in Multiracial America (Non-Fiction)

Second Guests: Phyliss Hill and Lloyd Mageed from The Black Star Project in Beloit - Burying the "N word". Saturday, Oct 21st Starting at 10AM in Beloit - A funeral service for the "N word". Schedule: 10AM at Bethel AME Church 1314 Athletic Ave, Noon rally at Summit Park, Funeral Service 2PM at New Zion Baptist Church, 1905 S Mound Ave followed by a funeral procession and repast with food, music and fellowship.

Third Guest: David Callahan - Co-founder of Demos and Author of The Moral Center: How We Can Reclaim Our Country from Die-Hard Extremists, Rogue Corporations, Hollywood Hacks, and Pretend Patriots (Non-Fiction).

Announcements
  • Saturday, Oct 14th 8PM - Memorial Union - Death Penalty: Wrong for Wisconsin poetry slam.
  • Friday, Oct 13th 7PM - Rainbow Bookstore Cooperative - The Clarence Kalin Chapter of Veterans for Peace present a book signing for their new book Long Shadows: Veterans Paths to Peace.
  • Saturday, Oct 21st Starting at 10AM in Beloit - The Black Star Project in Beloit presents a funeral service for the "N word". Schedule: 10AM at Bethel AME Church 1314 Athletic Ave, Noon rally at Summit Park, Funeral Service 2PM at New Zion Baptist Church, 1905 S Mound Ave followed by a funeral procession and repast with food, music and fellowship.
  • Anti-Racism Workshop - A six-week workshop led by Groundwork to examine how racism and white supremacy impact our lives, institutions and movements for social justice. Discuss the history, hear stories of resistance and analyze how white privilege plays out in our communities, working spaces and organizations. For More Information: Terry Ross 608-279-2710 or trtrtr@charter.net WNPJ story.
  • The African Presence in Mexico is showing at The Mexican Fine Arts Center Museum in Chicago.

Thursday, October 05, 2006

Dying with your Passwords

Schneier on Security: Dying with your Passwords

Interesting story on the risks of dying without telling anyone your computer passwords.

(Dying with your Passwords via Schneier on Security.)

Tuesday, October 03, 2006

Tuesday 8:00 Buzz - 10/3/2006

This continues my effort to chronicle the guests and topics covered on the Stan Woodard's Tuesday 8:00 Buzz on WORT-FM

Special Program Note: Today's Show

First Guest: Nomi Prins - journalist and Senior Fellow at Demos and Author of Jacked: How "Conservatives" Are Picking Your Pocket -- Whether You Voted for Them or Not (Non-Fiction)

Second Guest: Kitty Dukakis and Larry Tye - Authors of Shock: The Healing Power of Electroconvulsive Therapy (Non-Fiction).

Announcements
  • Anti-Racism Workshop - A six-week workshop led by Groundwork to examine how racism and white supremacy impact our lives, institutions and movements for social justice. Discuss the history, hear stories of resistance and analyze how white privilege plays out in our communities, working spaces and organizations. For More Information: Terry Ross 608-279-2710 or trtrtr@charter.net WNPJ story.
  • The African Presence in Mexico is showing at The Mexican Fine Arts Center Museum in Chicago.

Tuesday, September 19, 2006

Ya know what's disgusting?

Someone eating a peach.

I makes a really disgusting sound.

And I don't like it.

Tuesday, September 12, 2006

Tuesday 8:00 Buzz - 9/12/2006

This continues my effort to chronicle the guests and topics covered on the Stan Woodard's Tuesday 8:00 Buzz on WORT-FM

Special Program Note:

In two weeks (September 19th), we will have a special 10th anniversary broadcast with a live studio audience at the WORT Studios, 118 S Bedford St in Madison. If you have been on the show or been involved in the show in any way in the last 10 years or just want to see what we look like, please come down!

Today's Show

It's Primary Day! Get out and vote! You can Register at the polls - Click for details

First Guest: Juan Williams - Senior Correspondant for National Public Radio and Anchor and Commentator on Fox News Author of Enough: The Phony Leaders, Dead-End Movements, and Culture of Failure That Are Undermining Black America--and What We Can Do About It (Non-Fiction).

Second Guest: Norm Stockwell - WORT Operations Coordinator, Call-in discussing 9/11 and more.

Announcements

Tuesday, September 05, 2006

Tuesday 8:00 Buzz - 9/5/2006

This continues my effort to chronicle the guests and topics covered on the Stan Woodard's Tuesday 8:00 Buzz on WORT-FM

Special Program Note:

In two weeks (September 19th), we will have a special 10th anniversary broadcast with a live studio audience at the WORT Studios, 118 S Bedford St in Madison. If you have been on the show or been involved in the show in any way in the last 10 years or just want to see what we look like, please come down!

Today's Show

Special call-in program featuring the two Democratic candidates running for the State's 81st Assembly District

First Guest: State Rep. David Travis - Incumbent Democratic State Representitive

Second Guest: Henry Sanders, Jr - Democratic Challenger

Tonight: Public debate between the two candidates, 7PM at the Warner Park Community Center

Announcements

Tuesday, August 29, 2006

Tuesday 8:00 Buzz - 8/29/2006

This continues my effort to chronicle the guests and topics covered on the Stan Woodard's Tuesday 8:00 Buzz on WORT-FM

First Guest:

Demetric Mercandel - New Orleans resident, talking about the one-year anniversary of hurricane Katrina

Second Guest:

Fred Clark - Talking about Move Forward Not Out rally, Saturday 9/2 at the Boys and Girls Club on Allied Drive.

Third Guest:

Dr. Earl Ofari Hutchinson Author of many books, he writes The Hutchinson Report as well as for The Huffington Post.

Announcements

Tuesday, August 22, 2006

Tuesday 8:00 Buzz - 8/22/2006

This continues my effort to chronicle the guests and topics covered on the Stan Woodard's Tuesday 8:00 Buzz on WORT-FM

First Guests:

Nathan Larson and Students Andrea J, Clay Y, David W and Maddy V from Troy Gardens - A North-Madison community gardening project.

Second Guest:

Elaine Meryl Brown Author of Playing By The Rules (Fiction).

Announcements

Monday, August 21, 2006

Nice Delivery

So, I'm riding my bike down the street, minding my own business....

When I come across a Glass Nickel Pizza delivery car double-parked, blocking an entire lane of traffic. Now, I'm all for pizza delivery being the top priority users of the road, and Glass Nickel is one of the best pizza places in Madison (it may be the best -- depends on my mood) BUT in this case, he was completely blocking one direction, and he wasn't even as close to his destination as possible!

You'll note the destination house on the left, with ample parking immediately in front. Even if he didn't want to turn around or park illegally the wrong way, he could park one car length further down the street in his direction of travel.

That is all.

Tuesday, August 15, 2006

Tuesday 8:00 Buzz - 8/15/2006

This continues my effort to chronicle the guests and topics covered on the Stan Woodard's Tuesday 8:00 Buzz on WORT-FM

First Guest:

Flores A. Forbes - Former Black Panther, Currently Chief Strategic Officer, Abyssinian Development Corporation, and Author of Will You Die with Me? My Life and the Black Panther Party (Non-Fiction)

Second Guest:

Shauna Anderson "The Queen of Chitlins," Author of OFFAL GREAT, A Memoir from Shauna Anderson, The Queen of Chitlins (Non-Fiction). Order Chitlins or the book online: chitlinmarket.com or 1-866-436-9381

Announcements

Wednesday, August 09, 2006

Amnesty International launches global campaign against internet repression

Amnesty International is launching a campaign to "free" the internet from repression. See Their Press Release or go straight to the campaign's website, irrepressible.info.

For those of you reading this via the web, you'll see their infobox on the right-hand column. For those of you reading this via RSS, stop by the site. I can't figure out how to get an example in here. :)

Tuesday, August 08, 2006

Tuesday 8:00 Buzz - 8/8/2006

This continues my effort to chronicle the guests and topics covered on the Stan Woodard's Tuesday 8:00 Buzz on WORT-FM

First Guest:

Mary-Wynne Ashford - Author of Enough Blood Shed: 101 Solutions to Violence, Terror and War (Non-Fiction)

Second Guest:

Johnny Winston, Jr - Madison School Board President. Coming up this weekend: Johnny Winston, Jr Streetball and Block Party - Saturday Aug 12 Noon-7PM, Penn Park in South Madison (Corner of Fisher and Buick Streets). Basketball, Flag Football, Bingo, Music and more. For More Information: 608-441-0224 or 608-347-9715 Email: johnnywinstonjr@hotmail.com

Third Guest:

Steven Salaita - Author of Anti-Arab Racism in the USA: Where it Comes From and What it Means for Politics Today (Non-Fiction)

Announcements
  • Johnny Winston, Jr Streetball and Block Party - Saturday Aug 12 Noon-7PM, Penn Park in South Madison (Corner of Fisher and Buick Streets). Basketball, Flag Football, Bingo, Music and more. For More Information: 608-441-0224 or 608-347-9715 Email: johnnywinstonjr@hotmail.com
  • MATC is considering increasing their presence in South Madison and would like input. Open community forum on Monday Auth 17 7 - 9PM at Centro Hispano, 810 Badger Road. For more information contact Erika Mader at 255-0426 or Maria G Bañuelos at 246-6460
  • The African Presence in Mexico is showing at The Mexican Fine Arts Center Museum in Chicago.

Sunday, August 06, 2006

What To Do With Your Butts...

My friend Tom Jordan always used to point out that "all signs are there for a reason" -- Someone once did the thing mentioned on the sign.

This post (theoretically) starts a new series for this blog of signs that I think are so incongruous I have to post them before I explode.

In this case, a sign at the Select Inn in Waukesha noting where we should not place our garbage.

Tuesday, August 01, 2006

Tanner's new plate

Hooray! Phone blogging! This probably only cost me about $300!

Tuesday 8:00 Buzz - 8/1/2006

This begins my effort to chronicle the guests and topics covered on the Stan Woodard's Tuesday 8:00 Buzz on WORT-FM

First Guest:

Sasha Abramsky - Author of CONNED - How Millions Went to Prison, Lost the Vote, and Helped Send George W. Bush to the White House (Non-Fiction)

Second Guest (no-show):

E. Lynn Harris - Author of I Say A Little Prayer (Fiction)

Announcements
  • Lanterns for Peace - Sunday Aug 6th 6-9PM, Tenny Park Shelter. For More Information: 608-262-9232 mail@psrmadison.org
  • Johnny Winston, Jr Streetball and Block Parry - Saturday Aug 12 Noon-7PM, Penn Park in South Madison (Corner of Fisher and Buick Streets). Basketball, Flag Football, Bingo, Music and more. For More Information: 608-441-0224 or 608-347-9715

Wednesday, April 19, 2006

Abortion manual for the women of South Dakota

kottke.org: Abortion manual for the women of South Dakota

In reaction to the South Dakota Senate passing an abortion ban bill, a woman named Molly has posted an abortion manual for the women of South Dakota:

In the 1960s and early 1970s, when abortions were illegal in many places and expensive to get, an organization called Jane stepped up to the plate in the Chicago area. Jane initially hired an abortion doctor, but later they did the abortions themselves. They lost only one patient in 13,000 -- a lower death rate than that of giving live birth. The biggest obstacle they had, though, was the fact that until years into the operation, they thought of abortion as something only a doctor could do, something only the most trained specialist could perform without endangering the life of the woman.

They were deceived -- much like you have probably been deceived. An abortion, especially for an early pregnancy, is a relatively easy procedure to perform. And while I know, women of South Dakota, that you never asked for this, now is the time to learn how it is done. There is no reason you should be beholden to doctors -- especially in a state where doctors have been refusing to perform them, forcing the state's only abortion clinic to fly doctors in from elsewhere.

(via cyn-c)

(Abortion manual for the women of South Dakota via kottke.org.)

Tuesday, April 18, 2006

Feynman Problem Solving Algorithm

Since a certain someone who is obsessed with drawing everything on a board, even when it isn't needed decided to erase this from my white board, I'm posting this here, because I feel like it.

The Feynman Problem Solving Algorithm:
  1. Write down the problem.
  2. Think very hard.
  3. Write down the answer.

None of these steps may be skipped, especially the first one. Which, BTW, is about the most common mistake I see around here -- often perpetrated by our mysterious white-board eraser.

Has The Boss lost his mind?!?

Per this press release:

Bruce Springsteen's album doesn't hit stores until April 25th but listeners have an exclusive opportunity to listen to the album in its entirety on-demand beginning today. Clear Channel Radio is the only place to catch a "Sneak Peek" of Bruce Springsteen's latest album, We Shall Overcome: The Seeger Sessions. This online exclusive will be available on 390 Clear Channel Radio station Web sites!

Yes, you're reading that correctly. Bruce Springsteen (the blue collar hero and the working man's friend) has teamed up with 17 folk musicians to put out an album of Pete Seeger (counter-culture icon, blacklisted socialist, anti-war and environmental activist) songs. And it's being released (initially) only to Clear Channel Stations.

It seems clear that The Boss has lost his mind (to say nothing of his working man roots and, perhaps, credibility). I hereby move that we start a fundraising effort to get The Boss the help he so desperately needs.

Tuesday, April 04, 2006

Nothing

Sorry, no new content in like, a long time. Been busy, been stupid. I've got so many rants floating around my head, I really should just post them. jon

Saturday, February 11, 2006

Memo To NBC, Re: Olympic Coverage.

  1. We want to see it live. We don't care if it's at 3AM or noon. I don't want to see highlights of events that feature Americans at 7PM. I want to see everything, and I want it live. I know you don't have that many networks, but you are filming the events, so put them on Digital Cable/Dish/Internet. Sure, show (live) the popular sports on the common channels. And sure, at 7PM Eastern (1AM in Turin), show packaged bits about Americans.
  2. I don't care about the hardship this athlete faced. If I want to know that, I'll look it up. As stated above, I want to see the competition, not 5-minute sappy-music-accompanied human interest fluff.

I'm sure I'll have more, I've only watched a few hours of the Olympics so far.

Technorati Tags: ,

Friday, February 03, 2006

Security Problems with Controlled Access Systems

Schneier on Security: Security Problems with Controlled Access Systems

There was an interesting security tidbit in this article on last week's post office shooting:

The shooter's pass to access the facility had been expired, officials said, but she apparently used her knowledge of how security at the facility worked to gain entrance, following another vehicle in through the outer gate and getting other employees to open security doors.

This is a failure of both technology and procedure. The gate was configured to allow multiple vehicles to enter on only one person's authorization -- that's a technology failure. And people are programmed to be polite -- to hold the door for others.

SIDE NOTE: There is a common myth that workplace homicides are prevalent in the United States Postal Service. (Note the phrase "going postal.") But not counting this event, there has been less than one shooting fatality per year at Postal Service facilities over the last 20 years. As the USPS has more than 700,000 employees, this is a lower rate than the average workplace.

(Security Problems with Controlled Access Systems via Schneier on Security.)

Technorati Tags: ,

Thursday, February 02, 2006

Risks of Losing Portable Devices

Schneier on Security: Risks of Losing Portable Devices

Last July I blogged about the risks of storing ever-larger amounts of data in ever-smaller devices.

Last week I wrote my tenth Wired.com column on the topic:

The point is that it's now amazingly easy to lose an enormous amount of information. Twenty years ago, someone could break into my office and copy every customer file, every piece of correspondence, everything about my professional life. Today, all he has to do is steal my computer. Or my portable backup drive. Or my small stack of DVD backups. Furthermore, he could sneak into my office and copy all this data, and I'd never know it.

This problem isn't going away anytime soon.

There are two solutions that make sense. The first is to protect the data. Hard-disk encryption programs like PGP Disk allow you to encrypt individual files, folders or entire disk partitions. Several manufacturers market USB thumb drives with built-in encryption. Some PDA manufacturers are starting to add password protection -- not as good as encryption, but at least it's something -- to their devices, and there are some aftermarket PDA encryption programs.

The second solution is to remotely delete the data if the device is lost. This is still a new idea, but I believe it will gain traction in the corporate market. If you give an employee a BlackBerry for business use, you want to be able to wipe the device's memory if he loses it. And since the device is online all the time, it's a pretty easy feature to add.

But until these two solutions become ubiquitous, the best option is to pay attention and erase data. Delete old e-mails from your BlackBerry, SMSs from your cell phone and old data from your address books -- regularly. Find that call log and purge it once in a while. Don't store everything on your laptop, only the files you might actually need.

EDITED TO ADD (2/2): A Dutch army officer lost a memory stick with details of an Afgan mission.

(Risks of Losing Portable Devices via Schneier on Security.)

Technorati Tags: ,

Tuesday, January 31, 2006

Dutch Biometric Passport Cracked

Schneier on Security: Dutch Biometric Passport Cracked

There's a good write-up from The Register.

Two points stand out. One, the RFID chip in the passport can be read from ten meters. Two, lots of predictability in the encryption key -- sloppy, sloppy -- makes the brute-force attack much easier.

But the references are from last summer. Why is this being reported now?

(Dutch Biometric Passport Cracked via Schneier on Security.)

Technorati Tags: , ,

Friday, January 27, 2006

I don't know..

I often hear people say I don't know. I realize that not everybody knows everything, that's impossible. Therefore, like the proverbial stupid question, there' no shame in admitting that you don't know.

Or is there?

My good friend Tom pointed out to me today that there are two places in a sentence where I don't know can be placed, and it makes a big difference:

I don't know is totally acceptable in the first half of a sentence, but never at the end Here's a classic example:

I don't know, but I'll look into it is a fine answer, as would "I don't know yet, thanks for calling it to my attention.

Implied, of course, is that I don't know as the answer to a question, say:

Why are we getting errors?

I don't know.

As was given to me is not appropriate, at least, when the question is addressed to a person who should know the answer.

Technorati Tags:

Thursday, January 26, 2006

How to Survive a Robot Uprising

Schneier on Security: How to Survive a Robot Uprising

It's Friday, so why not somthing a little silly?

This is a good start:

i'm reading about how to survive a robot uprising. i'm not gonna give away all the secrets, but i'll share a few...
  • choose a complex environment. waterfalls, street traffic, and places with lots of ambient noise confuse the robots.
  • lose your heat signature. smear yourself with mud and leaves and sit real still.
  • use uncommon words to suss out robots on the phone. robots do not know how pronounce supercalifragilisticexpealidocious.
  • find a blunt weapon. serrated edges won't work on robo exo-skeletons. nope.
  • alter your stride. robots can judge gait and injury, even height and intention, by stride, so put some rocks in your shoes and mix things up a bit. doing some ministry of silly walks stuff goes even further towards confusing them.
  • pretend that everything is normal. to forstall a mechanized killing spree, you must pretend that nothing is amiss.

Surely we can do better. Any other suggestions?

(How to Survive a Robot Uprising via Schneier on Security.)

Technorati Tags: ,

The Doghouse: Super Cipher P2P Messenger

Schneier on Security: The Doghouse: Super Cipher P2P Messenger

Super Cipher P2P Messenger uses "unbreakable Infinity bit Triple Layer Socket Encryption for completely secure communication."

Wow. That sure sounds secure.

(The Doghouse: Super Cipher P2P Messenger via Schneier on Security.)

Technorati Tags: ,

Wednesday, January 25, 2006

Nothing

Just a Test

Technorati Tags:

Tuesday, January 24, 2006

Using Attributes Appropriately

A week ago, I started hearing complaints that people with Thunderbird 1.5 were having problems searching our LDAP directory. I ignored it at first, as I was busy, and figured it was a configuration problem, and I'm not responsible for mail client configurations.

In the last few days, it's turned in to a torrent of complaints, and it definitely isn't a configuration problem. So, what could it be?

It seems that the Thunderbird folks decided that the perfectly legitimate search filter

(|(cn=first*last*)(mail=first*last*)(sn=first*last*))
used by previous version was far too, uhm, correct. They changed it to:
(|(mail=*first last*)(displayname=*first last*)(givenname=*first last*)(sn=*first last*))
because searching on DisplayName seems like a good use of an attribute meant for the display version of a name.

This may seem innocuous enough, but it isn't. CN is Common Name, which we (and other people, I'm sure) specially handle to provide nickname searching. So, searching for cn=john miner will find me, whereas displayname=john miner doesn't (even though my first name is misspeeled..

In this case, I was able to fix it using the same custom plugin I wrote to do the nickname lookups to translate searches on displayname in to searches on cn. If not for this, it would be up to us to change user.js on every Thunderbird client, because Michael Layde found that

user_pref("ldap_2.servers.default.attrmap.DisplayName", "cn,commonname");
changes what Thunderbird uses for DisplayName. Boy, that would be fun.

Please, people, use attributes the way they are intended!

Technorati Tags: ,

Thursday, January 19, 2006

Foiling Counterfeiting Countermeasures

Schneier on Security:

Great story illustrating how criminals adapt to security measures.

The notes were all $5 bills that had been bleached and altered to look like $100 bills, sheriff's investigators said. They passed muster with the pen because it determines only whether the paper used to manufacture the currency is legitimate, Bandy said.

As a security measure, the merchants use a chemical pen that determines if the bills are counterfeit. But that's not exactly what the pen does. The pen only verifies that the paper is legitimate. The criminals successfully exploited this security hole.

Technorati Tags: ,

Wednesday, January 18, 2006

Wine: Barefoot Cabernet Sauvignon

WineryBarefoot Cellars
TypeCabernet Sauvignon
YearUnknown. No date on label.
LocationModesto, California

Overall: A bit fruity for me. Not a strong Cabernet Sauvignon, seems almost a bit watery. I'm a fan of an ass-kicking Cab, which this isn't.

This wine was actually recommended to me by a friend, and came highly rated. Unfortunately, it falls way short of expectations. The lack of a vintage date on the label should have been a clue, perhaps. The label itself is ©2003, so maybe it's a recent vintage. (Then again, it isn't too recent, is it? 2003 is now three years ago.)

If you like a fruity, less dry Cab, this is for you. It's a cheap buy, and definitely beats many others in it's price-class.

Technorati Tags:

Tuesday, January 17, 2006

If You're Going To Read The News in English, Speak English

I'm all for diversity. I'm all for different voices reading the news. But, if you're reading the news in english, please be able to understandably speak english.

It's one thing if the person is a source, or the only person available, but just because you're looking for diversity, don't put unqualified people on the air. Adding a disabled person or a speaker who is not understandable* simply makes the news less accessible, especially to non-native english speakers who may have problems understanding other thick accents and/or difficult speech patterns.

All this does is make me change the channel. Even when it's my favorite station, one I happen to volunteer my time to.

So, how do we help people get better at speaking? Good question, and I don't have an answer. Hopefully there are smarter people out there who do.

*OK, well, what standard do we use? That's a good question that I don't know the answer to. I use the standard of what I can understand while not paying complete attention (driving, working, writing this blog entry).

Technorati Tags:

Getting Away with Punching

I used to be incensed over the fact that celebrities could literally kill people, then go to court and get away with murder. Then I became a minor celebrity and my opinion started to change.

I’m not famous enough to get away with premeditated murder, but it’s my ultimate goal. At my current level of fame I figure the most I could get away with is maybe a vigorous bludgeoning, or perhaps some high spirited groping. Those free passes could come in handy someday, but it’s not the same as knowing you can whack someone if you feel like it.

I once considered getting a teardrop tattoo so I’d look like an ex con and people would fear me. But with the Three Strikes law, being an ex con isn’t the panacea it used to be. Celebrities are the new bullies. That’s why I carry around my magazine covers just in case I get in a “situation.” When the shoving starts, I just whip out the January issue of Fortune magazine – the one with Dilbert on the cover – and say something like, “Do you know who drew that? Well DO you, punk?”

Then I go into my cage fighting stance and hope no one notices that my entire body is made of peanut brittle.

(Getting Away with Punching via The Dilbert Blog.)

Technorati Tags: ,

Wednesday, January 11, 2006

Copyright: Ownership?

The media giants have been very clear in their position. You don't own your content, you have a license to view/use it from them. In their eyes, you're not allowed to make a backup copy, install it on your iPod, watch it on a device built for a foreign region, etc., because the license they set all the terms for doesn't cover that.

This isn't fair in any eyes but theirs, of course, but let's say, for the purposes of argument, that it's all true.

Now, take one of those shiny discs, with the content you've licensed. Gaze at it warmly. Fondle its smooth digital surface. Hold it up to the light and marvel at the way the light refracts. Take out a key, and put a big scratch across it. Try to play it in your device. Go ahead, I'll wait.

Doesn't work anymore, right? But you paid good money for the license to view that content. Call the content owner up, and ask for a replacement. Patiently explain that since you already paid your $25 for a license to use the content, and they said you couldn't back it up, that you should be entitled to a new copy for the $1 or $2 cost of the media alone.

Did they say no? Fancy that. Where is all the convoluted language about licensing and right-to-view now? Is it possible that when the media is intact, you license the content, but as soon as it's scratched, you own it? Looks like it to me.

Could it be, in the end, that the huge quest to control your ability to copy content you buy, all in the name of preventing piracy, is really all about selling you the same thing over and over again?

(Copyright: Ownership? via Glenn's Junk Chest.)

Technorati Tags: ,

Monday, January 09, 2006

Open Letter to Those Who Call Me for Help:

It doesn't matter if it's via email or a voice mail, when you ask me a long, detailed question, include an example.

I don't want to reply to your long email with "can you give me an example?" Even more so, if you insist that I call, I don't want to call you up and say "can you give me an example?" and then spend the next few minutes figuring out what is happened, while you are on the line. I can do it more efficiently when I'm not cradling the phone, and you're not breathing in my ear.

That is all.

Technorati Tags:

Friday, January 06, 2006

Stupid Band Names

Be careful what you write in your journal:

An airline passenger with the words "suicide bomber" written in his journal was arrested when his plane arrived in San Jose, California, on Wednesday, but the words appeared to refer to music and he was later released, officials said.

..."Preliminary, what we believe is that that was the name of either a band or a song," Quy said.

I'm not sure I want "Suicide Bombers" displayed on my iPod. I certainly wouldn't want to be in a band with that name, flying around the country with crates of gear marked "Suicide Bombers." That would be asking for trouble.

On the other hand, it's pretty sad what is enough to get you arrested these days:

"A male was observed by his fellow passengers as having a journal and handwritten on the journal were the words 'suicide bomber,'" FBI spokeswoman LaRae Quy said.

"That, combined with the fact that he was clutching a backpack, and then finally he was acting a little suspiciously" prompted law enforcement to act.

My guess is that it wouldn't matter how he held his backpack; once the jittery passenger saw the words everything else was interpreted suspiciously.

(Stupid Band Names via Schneier on Security.)

Wednesday, January 04, 2006

ID Cards and ID Fraud

Unforeseen security effects of weak ID cards:

It can even be argued that the introduction of the photocard licence has encouraged ID fraud. It has been relatively easy for fraudsters to obtain a licence, but because it looks and feels like 'photo ID', it is far more readily accepted as proof of identity than the paper licence is, and can therefore be used directly as an ID document or to support the establishment of stronger fraudulent ID, particularly in countries familiar with ID cards in this format, but perhaps unfamiliar with the relative strengths of British ID documents.

During the Commons ID card debates this kind of process was described by Tory MP Patrick Mercer, drawing on his experience as a soldier in Northern Ireland, where photo driving licences were first introduced as an anti-terror measure. This "quasi-identity card... I think—had a converse effect to that which the Government sought... anybody who had such a card or driving licence on their person had a pass, which, if shown to police or soldiers, gave them free passage. So, it had precisely the opposite effect to that which was intended."

Effectively - as security experts frequently point out - apparently stronger ID can have a negative effect in that it means that the people responsible for checking it become more likely to accept it as conclusive, and less likely to consider the individual bearing it in any detail. A similar effect has been observed following the introduction of chip and PIN credit cards, where ownership of the card and knowledge of the PIN is now almost always viewed as conclusive.

(ID Cards and ID Fraud via Schneier on Security.)

Thursday, December 29, 2005

A Timely Start

Perl.com has an excellent article on speeding up Perl programs: what we can and can't help with:

tile imageA well-written Perl program should, in theory, beat a shell script, right? In theory. In practice, sometimes the details of your Perl installation have more to do with why your program is slow than you might believe. Jean-Louis Leroy recently tracked down a bottleneck and wrote up his experiences with making Perl programs start faster.

(A Timely Start via Perl.com.)

Wednesday, December 28, 2005

Are Computer-Security Export Controls Back?

Schneier on Security: Are Computer-Security Export Controls Back?:

I thought U.S. export regulations were finally over and done with, at least for software. Maybe not:

Unfortunately, due to strict US Government export regulations Symantec is only able to fulfill new LC5 orders or offer technical support directly with end-users located in the United States and commercial entities in Canada, provided all screening is successful.

Commodities, technology or software is subject to U.S. Dept. of Commerce, Bureau of Industry and Security control if exported or electronically transferred outside of the USA. Commodities, technology or software are controlled under ECCN 5A002.c.1, cryptanalytic.

You can also access further information on our web site at the following address: http://www.symantec.com/region/reg_eu/techsupp/enterprise/index.html

The software in question is the password breaking and auditing tool called LC5, better known as L0phtCrack.

Anyone have any ideas what's going on, because I sure don't.

(Via Schneier on Security.)

Tuesday, December 27, 2005

Identity Information Theft versus Identity Theft

Kim Cameron's Identity Weblog: Identity Information Theft versus Identity Theft:

Dave Kearns'still has a'bee in his bonnet about'my use of the phrase "Identity Theft".' He takes Sun's Sara Gates and me to task in a surrealistic'portrait of'us as'dopplegangers mezmerized by opinion polls.'''

If I understand'him right,'he is arguing'that'"identity theft" sensationalizes something banal and inevitable.' We should'drop'the phrase'and talk in terms of'property theft.' Property theft being as old as the hills, why should theft of information stored on computers surprise anyone?''Dave seems to think that'attempting'to'eliminate theft'of any kind'is about as likely to succeed'as'attempts to eliminate sex, drugs or rock and roll.' So why waste effort?

Similarly, he wants us to'return to the notion of good old fashioned'fraud, perhaps not as'venerable as pure property theft, but still an activity with a long past and clearly unrelated to what we, as technologists, might do or not do:

"Only once we're past the discussion of property theft mis-named as identity theft can we get to the real problem - identity fraud and how to combat it. But identity fraud happens one instance at a time, so it isn't as sexy for the budding Pulitzer Prize winner to write about."

As usual with Dave Kearns, there is an undeniable truth to what he says.' We have to admit that it is not actually "an identity" which is stolen in a data breach, but rather identity information which might potentially be used for phraud.' But so what?' The words don't matter as much as the underlying phenomena.

Apparently to underline his point Dave links to a press release from'ID Analytics, Inc.' When I went to their site I found this:

"The findings detailed in the cornerstone 'National Data Breach Analysis' indicate that different data breaches pose different degrees of risk. In fact, certain types of data breaches may not present a high degree of risk to your customers.

Wow!' That's a relief.' But wait.' Bad news:

"If your organization has suffered a data breach, the implications are serious:

  • Erosion of customer trust
  • Undesirable publicity
  • Legal/regulatory liability
  • Added financial obligations or responsibility

Ah.' But maybe good news:

"Realities of a Data Breach

"After conducting the first-ever post-breach data analysis into a series of separate data breaches, ID Analytics is in an unprecedented position to help organizations truly asses the degree of risk associated with a breach they have experienced. While data breaches can be the first and most serious issue facing an organization, the findings detailed in the cornerstone "National Data Breach Analysis" indicate that different data breaches pose different degrees of risk. In fact, certain types of data breaches may not present a high degree of risk to your customers.

Scientists can help me!

"ID Analytics Services

"ID Analytics Breach Analysis Services involve a series of rigorous analytical assessments made possible only through the use of ID Analytics' patented Graph Theoretic Anomaly Detection (GTAD®) technology and the membership-based ID Network™.

  • Isolate Data Breach.'' Following an initial confidential briefing, ID Analytics fraud experts will help determine which customer identities must be analyzed for risk of identity theft.
  • Identity Risk Assessment. ID Analytics' scientists, leveraging the power of the ID Network, will employ GTAD technology to determine if the isolated customer data set has been misused in an organized fashion. Organized misuse is a reliable indication of the potential for ongoing identity theft. If no organized misuse is detected, ID Analytics will deliver documented certification that the customer data set, as of that date, shows no indications of being misused in a suspicious or fraudulent manner.
  • Victim Action List. If organized misuse is detected, ID Analytics will produce a list of impacted identities, allowing the breached organization to deliver victim assistance directly to those that need it.
  • Ongoing Monitoring. ID Analytics will continually monitor the entire breached customer data set to detect any further misuse of sensitive identity information, both for previous and new victims.

"Benefits

  • Receive reliable indication of whether or not breached data is being used to perpetrate identity fraud or identity theft.
  • Determine the risk of harm associated with a data breach and devise risk-adjusted actions.
  • Deliver effective and specific communications to impacted customers regarding anticipated harm and remedies pursued.
  • Ensure a conclusion to the breach episode through ongoing protection and certification.

"Data breaches are an unfortunate reality in the information age. Even organizations that have invested enormous sums in security are not immune to the threat.

"ID Analytics can discretely assist organizations in understanding the true impact of a data breach to its customers, which can lead to informed and appropriate decisions about how to manage the aftermath."

Sorry -'I forget why the existence of a company paying "scientists" to discreetly "ensure a conclusion to breach episodes"'really proves'Dave's point that all we are dealing with here is a glitch on the PR machine.

I'think'our systems are being attacked more methodically, from more directions, more often and by a more professional'enemy than has ever been the case, and I think these attacks will, if nothing else changes, get progressively worse over the next couple of decades.' This leads me to think it's time to ring the alarm bells and act.''Who cares if we say "identity theft" or "identity information theft", as long as the alarm bells sound?'

Whatever we call it,'our systems are being breached, and we need to work to make them qualitatively more resiliant.' The proposals for an identity metasystem for the Internet are intended to'bring about'a'holistic alternative to the current ad hoc environment.

In the meantime, there will be more breaches, and those writing about them will not be Chicken Littles yelling that the sky is falling.

[tags: , , , ]


(Via Kim Cameron's Identity Weblog.)

Internet Explorer Sucks

Schneier on Security: Internet Explorer Sucks:

This study is from August, but I missed it. The researchers tracked three browsers (MSIE, Firefox, Opera) in 2004 and counted which days they were "known unsafe." Their definition of "known unsafe": a remotely exploitable security vulnerability had been publicly announced and no patch was yet available.

MSIE was 98% unsafe. There were only 7 days in 2004 without an unpatched publicly disclosed security hole.

Firefox was 15% unsafe. There were 56 days with an unpatched publicly disclosed security hole. 30 of those days were a Mac hole that only affected Mac users. Windows Firefox was 7% unsafe.

Opera was 17% unsafe: 65 days. That number is accidentally a little better than it should be, as two of the upatched periods happened to overlap.

This underestimates the risk, because it doesn't count vulnerabilities known to the bad guys but not publicly disclosed (and it's foolish to think that such things don't exist). So the "98% unsafe" figure for MSIE is generous, and the situation might be even worse.

Wow.

(Via Schneier on Security.)

Idiotic Article on TPM

Schneier on Security: Idiotic Article on TPM:

This is just an awful news story.

"TPM" stands for "Trusted Platform Module." It's a chip that may soon be in your computer that will try to enforce security: both your security, and the security of software and media companies against you. It's complicated, and it will prevent some attacks. But there are dangers. And lots of ways to hack it. (I've written about TPM here, and here when Microsoft called it Palladium. Ross Anderson has some good stuff here.)

In fact, with TPM, your bank wouldn’t even need to ask for your username and password -- it would know you simply by the identification on your machine.

Since when is "your computer" the same as "you"? And since when is identifying a computer the same as authenticating the user? And until we can eliminate bot networks and "owned" machines, there's no way to know who is controlling your computer.

Of course you could always “fool” the system by starting your computer with your unique PIN or fingerprint and then letting another person use it, but that’s a choice similar to giving someone else your credit card.

Right, letting someone use your computer is the same as letting someone use your credit card. Does he have any idea that there are shared computers that you can rent and use? Does he know any families that share computers? Does he ever have friends who visit him at home? There are lots of ways a PIN can be guessed or stolen.

Oh, I can't go on.

My guess is the reporter was fed the story by some PR hack, and never bothered to check out if it were true.

(Via Schneier on Security.)

Monday, December 19, 2005

The Military is Spying on Americans

Schneier on Security: The Military is Spying on Americans:

The Defense Department is collecting data on perfectly legal, peaceful, anti-war protesters.

The DOD database obtained by NBC News includes nearly four dozen anti-war meetings or protests, including some that have taken place far from any military installation, post or recruitment center. One "incident" included in the database is a large anti-war protest at Hollywood and Vine in Los Angeles last March that included effigies of President Bush and anti-war protest banners. Another incident mentions a planned protest against military recruiters last December in Boston and a planned protest last April at McDonald's National Salute to America's Heroes -- a military air and sea show in Fort Lauderdale, Fla.

The Fort Lauderdale protest was deemed not to be a credible threat and a column in the database concludes: "US group exercising constitutional rights." Two-hundred and forty-three other incidents in the database were discounted because they had no connection to the Department of Defense -- yet they all remained in the database.

The DOD has strict guidelines (.PDF link), adopted in December 1982, that limit the extent to which they can collect and retain information on U.S. citizens.

Still, the DOD database includes at least 20 references to U.S. citizens or U.S. persons. Other documents obtained by NBC News show that the Defense Department is clearly increasing its domestic monitoring activities. One DOD briefing document stamped “secret” concludes: "[W]e have noted increased communication and encouragement between protest groups using the [I]nternet," but no "significant connection" between incidents, such as “reoccurring instigators at protests” or "vehicle descriptions."

Personally, I am very worried about this increase in military activity inside our country. If anyone should be making sure protesters stay on the right side of the law, it's the police...not the military.

And it could get worse.

EDITED TO ADD (12/16): There's also this news :

Months after the Sept. 11 attacks, President Bush secretly authorized the National Security Agency to eavesdrop on Americans and others inside the United States to search for evidence of terrorist activity without the court-approved warrants ordinarily required for domestic spying, according to government officials.....

Mr. Bush's executive order allowing some warrantless eavesdropping on those inside the United States including American citizens, permanent legal residents, tourists and other foreigners is based on classified legal opinions that assert that the president has broad powers to order such searches, derived in part from the September 2001 Congressional resolution authorizing him to wage war on Al Qaeda and other terrorist groups, according to the officials familiar with the N.S.A. operation.

And:

....officials familiar with it said the N.S.A. eavesdropped without warrants on up to 500 people in the United States at any given time. The list changes as some names are added and others dropped, so the number monitored in this country may have reached into the thousands over the past three years, several officials said. Overseas, about 5,000 to 7,000 people suspected of terrorist ties are monitored at one time, according to those officials.

This is a very long article, but worth reading. It is not overstatement to suggest that this may be the most significant violation of federal surveillance law in the post-Watergate era.

EDITED TO ADD (12/16): Good analysis from Political Animal. The reason Bush's executive order is a big deal is because it's against the law.

Here is the Foreign Intelligence Surveillance Act. Its Section 1809a makes it a criminal offense to "engage in electronic surveillance under color of law except as authorized by statute."

FISA does authorize surveillance without a warrant, but not on US citizens (with the possible exception of citizens speaking from property openly owned by a foreign power; e.g., an embassy.)

FISA also says that the Attorney General can authorize emergency surveillance without a warrant when there is no time to obtain one. But it requires that the Attorney General notify the judge of that authorization immediately, and that he (and yes, the law does say 'he') apply for a warrant "as soon as practicable, but not more than 72 hours after the Attorney General authorizes such surveillance."

It also says this:

"In the absence of a judicial order approving such electronic surveillance, the surveillance shall terminate when the information sought is obtained, when the application for the order is denied, or after the expiration of 72 hours from the time of authorization by the Attorney General, whichever is earliest. In the event that such application for approval is denied, or in any other case where the electronic surveillance is terminated and no order is issued approving the surveillance, no information obtained or evidence derived from such surveillance shall be received in evidence or otherwise disclosed in any trial, hearing, or other proceeding in or before any court, grand jury, department, office, agency, regulatory body, legislative committee, or other authority of the United States, a State, or political subdivision thereof".

Nothing in the New York Times report suggests that the wiretaps Bush authorized extended only for 72 hours, or that normal warrants were sought in each case within 72 hours after the wiretap began. On the contrary, no one would have needed a special program or presidential order if they had.

According to the Times, "the Bush administration views the operation as necessary so that the agency can move quickly to monitor communications that may disclose threats to the United States." But this is just wrong. As I noted above, the law specifically allows for warrantless surveillance in emergencies, when the government needs to start surveillance before it can get a warrant. It explains exactly what the government needs to do under those circumstances. It therefore provides the flexibility the administration claims it needed.

They had no need to go around the law. They could easily have obeyed it. They just didn't want to.

(Via Schneier on Security.)

Wednesday, December 14, 2005

Bill Will Keep New Drivers Off Phones

The Wisconsin Legislature is considering Assembly Bill 120, which would ban new drivers from using their cell phones while driving. In related news, AB 121 will ban parents from driving with children; AB 122 bans driving while listening to music; and AB 123 bans driving while not staring bug-eyed at the road.

Weakest Link Security

Schneier on Security: Weakest Link Security:

Funny story:

At the airport where this pilot fish works, security has gotten a lot more attention since 9/11. "All the security doors that connect the concourses to office spaces and alleyways for service personnel needed an immediate upgrade," says fish. "It seems that the use of a security badge was no longer adequate protection.

"So over the course of about a month, more than 50 doors were upgraded to require three-way protection. To open the door, a user needed to present a security badge (something you possess), a numeric code (something you know) and a biometric thumb scan (something you are).

"Present all three, and the door beeps and lets you in."

One by one, the doors are brought online. The technology works, and everything looks fine -- until fish decides to test the obvious.

After all, the average member of the public isn't likely to forge a security badge, guess a multidigit number and fake a thumb scan. "But what happens if you just turn the handle without any of the above?" asks fish. "Would it set off alarms or call security?

"It turns out that if you turn the handle, the door opens.

"Despite the addition of all that technology and security on every single door, nobody bothered to check that the doors were set to lock by default."

Remember, security is only as strong as the weakest link.

(Via Schneier on Security.)

Friday, December 09, 2005

Planet Perl: Leon Brocard: Open source zealots: ...

Planet Perl: Leon Brocard: Open source zealots:

This is something I've seen on other projects, but never experienced myself before until now: open source zealots. These are people who will complain for months that if project Y were open source, then they would hack on it and improve it. To get them to stop whining, you open source the project and of course all the people who said they would contribute code do not. A month a whining and no code! As pointed out in the London.pm meeting yesterday, it's not a total loss: at least they've stopped whining ;-)

The fog effect in RealLife looks particularly good today - almost as good as in the latest Harry Potter film. Here's hoping that no dragons come swooping out of this fog...

ObPerl: Image::Imlib2 doesn't support blending two images together, so I had to use Image::Magick yesterday, erk!

(Via Planet Perl.)

Schneier on Security: E-Hijacking:

The article is a bit inane, but it talks about an interesting security problem. "E-hijacking" is the term used to describe the theft of goods in transit by altering the electronic paperwork:

He pointed to the supposed loss of 3.9-million banking records stored on computer backup tapes that were being shipped by UPS from New York-based Citigroup to an Experian credit bureau in Texas. “These tapes were not lost – they were stolen,” Spoonamore said. “Not only were they stolen, the theft occurred by altering the electronic manifest in transit so it would be delivered right to the thieves.” He added that UPS, Citigroup, and Experian spent four days blaming each other for losing the shipment before realizing it had actually been stolen.

Spoonamore, a veteran of the intelligence community, said in his analysis of this e-hijacking, upwards of 15 to 20 people needed to be involved to hack five different computer systems simultaneously to breach the electronic safeguards on the electronic manifest. The manifest was reset from “secure” to “standard” while in transit, so it could be delivered without the required three signatures, he said. Afterward the manifest was put back to “secure” and three signatures were uploaded into the system to appear as if proper procedures had been followed.

“What’s important to remember here is that there is no such thing as ‘security’ in the data world: all data systems can and will be breached,” Spoonamore said. “What you can have, however, is data custody so you know at all times who has it, if they are supposed to have it, and what they are doing with it. Custody is what begets data security.”

This is interesting. More and more, the physical movement of goods is secondary to the electronic movement of information. Oil being shipped across the Atlantic, for example, can change hands several times while it is in transit. I see a whole lot of new risks along these lines in the future.

(Via Schneier on Security.)

Friday, December 02, 2005

EFF: Breaking News: Diebold Attempts to Evade Election Transparency Laws:

EFF Goes to Court to Force E-voting Company to Comply With Strict New North Carolina Law

Raleigh, North Carolina - The Electronic Frontier Foundation (EFF) is going to court in North Carolina to prevent Diebold Election Systems, Inc. from evading North Carolina law.

In a last-minute filing, e-voting equipment maker Diebold asked a North Carolina court to exempt it from tough new election requirements designed to ensure transparency in the state's elections. Diebold obtained an extraordinarily broad order, allowing it to avoid placing its source code in escrow with the state and identifying programmers who contributed to the code.

On behalf of North Carolina voter and election integrity advocate Joyce McCloy, EFF asked the court to force Diebold and every other North Carolina equipment vendor to comply with the law's requirements. A hearing on EFF's motion is set for Monday, November 28.

"The new law was passed for a reason: to ensure that the voters of North Carolina have confidence in the integrity and accuracy of their elections," said EFF Staff Attorney Matt Zimmerman. "In stark contrast to every other equipment vendor that placed a bid with the state, Diebold went to court complaining that it simply couldn't comply with the law. Diebold should spend its efforts developing a system that voters can trust, not asking a court to let it bypass legal requirements aimed at ensuring voting integrity."

On November 4, the day that voting equipment bids to the state were due, Diebold obtained a temporary restraining order from a North Carolina superior court, exempting it from criminal and civil liability that could have resulted from its bid. EFF, with the assistance from the North Carolina law firm of Twiggs, Beskind, Strickland & Rabenau, P.A., intervened in the case on behalf of McCloy, the founder of the North Carolina Coalition for Verified Voting. In a brief filed Wednesday, EFF argued that Diebold had failed to show why it was unable to meet various new election law provisions requiring source code escrow and identification of programmers. North Carolina experienced one of the most serious malfunctions of e-voting systems in the 2004 presidential election when over 4,500 ballots were lost in a voting system provided by Diebold competitor UniLect Corp. The new transparency and integrity provisions of the North Carolina election code were passed in response to this and other documented malfunctions that have occurred across the country.

The North Carolina Board of Elections is scheduled to announce winning voting equipment vendors on December 1, 2005.

For the brief filed in the case:
http://www.eff.org/Activism/E-voting/20051117_Diebold_v_NC_Motion.pdf

Contact:

Matt Zimmerman
Staff Attorney
Electronic Frontier Foundation
mattz@eff.org

(Via EFF: Breaking News.)

Schneier on Security: FBI to Approve All Software?:

Sounds implausible, I know. But how else do you explain this FCC ruling (from September -- I missed it until now):

The Federal Communications Commission thinks you have the right to use software on your computer only if the FBI approves.

No, really. In an obscure "policy" document released around 9 p.m. ET last Friday, the FCC announced this remarkable decision.

According to the three-page document, to preserve the openness that characterizes today's Internet, "consumers are entitled to run applications and use services of their choice, subject to the needs of law enforcement." Read the last seven words again.

The FCC didn't offer much in the way of clarification. But the clearest reading of the pronouncement is that some unelected bureaucrats at the commission have decreeed that Americans don't have the right to use software such as Skype or PGPfone if it doesn't support mandatory backdoors for wiretapping. (That interpretation was confirmed by an FCC spokesman on Monday, who asked not to be identified by name. Also, the announcement came at the same time as the FCC posted its wiretapping rules for Internet telephony.)

(Via Schneier on Security.)

Schneier on Security: The Human Side of Security:

A funny -- and all too true -- addition to the SANS Top 20:

H1. Humans

H1.1 Description:

The species Homo sapiens supports a wide range of intellectual capabilities such as speech, emotion, rational thinking etc. Many of these components are enabled by default - though to differing degrees of success. These components are implemented by the cerebral cortex, and are under the control of the identity engine which runs as me.exe. Vulnerabilities in these components are the most common avenues for exploitation.

(Via Schneier on Security.)