"Hacking" predator drones

This just makes me sad. Two articles, one in the WSJ, the other on CNN, describing how insurgents in Iraq are hacking predator drones and receiving the video feeds that the drones are sending back to U.S. ground stations. First things first, let’s fix the headlines. Both are running something like “Iraqi insurgents hacked Predator drone feeds.” That should more clearly read: “Iraqi insurgents watching the videos that the Predator drone sends out unencrypted.” Or maybe “Iraqi insurgents watch Predator drone feeds on TV.” ...

December 18, 2009 · 3 min · admin

Great moments in . . .

Minor notes, none worth their own post. Traffic management: I get a call from K around 5:30. She’s stuck behind an accident and the cops on the scene, a) don’t tell people to take a detour until they’ve been there for a half hour; and b) once the ambulance has left the scene, don’t direct traffic around the one remaining open lane. So, after waiting a half hour, K has to take a 20+ minute detour home. Memory: Once she gets in, K and I are fixing leftovers for dinner. C: “Hey, where are the mashed potatoes?” K: “Where did you put them?” “In the fridge, but I can’t find them.” “Maybe they’re in the freezer.” “Nope, not there either.” Ten minutes of looking for the potatoes. Did we throw them out on Sunday? Nope, not in the trash. Did C put them in the pantry? Nope. Can’t find ’em, can’t find ’em. Finally, K says, “wait, we fixed rice on Sunday.” There weren’t any potatoes. I would attribute it to getting old, but I’ve always been this way. FUD (fear, uncertainty and doubt): we’re testing some things at the office – will our authentication system (active directory) honor password failure lockouts when using LDAP authentication? I ask our windows consultant to either a) answer the question, or b) enable an account lockout policy so we can test. He responds back that he can do that, but with the warning that “many Linux services aren’t well-designed for this, and repeatedly try a cached or user-provided password, so that users or service accounts may be mysteriously locked out after one attempt or at some future time when passwords change.” Which is complete and utter B.S. Signs that it’s BS? He references Linux services as opposed to open source, i.e. attempted linux dig. And I used to “own” identity management services, including authentication at a large university and if this was the case, things would have blown up within 10 minutes. I thanked him for the advice and noted that I’ve never seen this, but that it’s why we test. OS Performance: we’re looking into some new ideas at the office. Things that could be useful as a preprocessor for a host based intrusion detection system. As part of my testing, I told my laptop to audit all syscalls made to the kernel, by all processes on the system. CPU load spiked, system performance went through the floor, the windowing system became almost completely non-responsive. In the two minutes it took to get access to a terminal, I logged 150 MB of audit logs. On the plus side, all of the information we need can be collected. Now I just need to figure out how to keep a usable system. Self aggrandizement: talking to my technical manager, we need to write up two journal papers based on our recent work. Cool! I hope everyone had a good Veteran’s Day and remembered to thank the veterans in their lives.

November 12, 2009 · 3 min · admin

Facebook security vulnerabilities

and this is why I like cross-posting to facebook from my blog. It’s a healthy reminder that nothing on fb is actually private. If it’s online - it’ll be exposed eventually, whether through a new exploit, or just because you “friend” someone in the future that you had written about in the past. h/t hsarik

November 5, 2009 · 1 min · admin

So, this is important

I’m not a big baseball fan. For that matter, there are few ball sports that interest me. But, this is important. If you recall, a few years ago (2004), there was a big furor over steroids in baseball. The government searched BALCO and found evidence of rampant steroid use by baseball players. Now I hadn’t been paying attention to this, but there has been an ongoing legal dispute over that search and how it was conducted. ...

August 28, 2009 · 6 min · admin

Digital Amway

A few years ago, I was accused of using the word “interesting in subtle ways. Sometimes it means a truly novel idea that I would like to learn more about, other times, it’s a novel idea of which I’m more than a little skeptical. In both cases, I stand by the description, to me, both are interesting – but it can make it a little hard to know what I’m really thinking. So take it with a grain of salt that I just read an interesting article in the February 2008 issue of IEEE Computer on how to turn music lovers (particularly teenagers) into music distributors. ...

March 29, 2008 · 3 min · admin

Who could have guessed?

Gee, nobody could have predicted this I suppose: The FBI improperly used national security letters in 2006 to obtain personal data on Americans during terror and spy investigations, Director Robert Mueller said Wednesday. Admittedly, Mueller goes on to say that the reports were prior to new policies being put into place, but somehow that doesn’t make me feel much better. It’s things like this that have always made me very nervous about partnerships between law enforcement and industry. I’ll try to post something about InfraGard one of these days. It’s a little scary in its own right.

March 6, 2008 · 1 min · admin

Is this thing on?

Is this thing still on? Okay, it’s been about three weeks since I’ve blogged anything. As I’ve stated before, this tends to happen when I’m too involved in living life to actually write about it. Fortunately (unfortunately?) it’s nothing terribly exciting. Let’s see: Guitar: my guitar playing has been scientifically shown to have 10% less suck than it did a month ago. However, with such a large amount of suck to begin with, we’re still not at anything that looks like good. I’m getting more fluent with the open chords and can switch between them reasonably well. I’m just starting to learn barre chords – the E barre chord to start with. There are still vast tracts of untouched suck in the barre chords. Also, I’m actually thinking of picking up some lessons – the ones at jamplay.com seem pretty good. Work: still going well. There’s enough to do. I’m still not entirely used to billing by the (tenth of an) hour. Also, not really looking forward to flying to Ohio next week. I’ll only be gone for a day, but, ugh – who wants a 6am flight to Dayton! Break-in update: nothing much new here. Still looking to make it harder for someone to break in. Had a neighborhood watch meeting last weekend – that’ll be good. Turns out this may be neither contractors nor kids. There are apparently some professional (stretching that word a bit) thieves working this area. There have been some eight different break-ins near by. Non-profit work: I’m convinced that whomever coined the phrase “academic politics are so sorted because the stakes are so small never worked with a non-profit. It’s just amazing the degree to which politics enters into the smallest damned thing. New year’s resolutions: didn’t make any – never do. That said, I am trying to exercise more and cut down on my use of vulgarities. Profanity and cursing can wait until another year 🙂 I think that’s about it for now.

January 16, 2008 · 2 min · admin

Two factor authentication

A couple of weeks ago, Hunter and I were talking about passwords. More to the point, the inadequacy of passwords and why we haven’t moved beyond them yet. This touches on several points that I made last year. Specifically, that a password that is secure enough starts to restrict its usability. In a nutshell, authentication is proving that you are who you claim to be. The standard ways of authenticating yourself are through: something you know (e.g., a password), something you have (e.g., a token) or something you are (e.g., biometrics, facial recognition, etc.). So the claim here is that the human brain is not good enough at remembering things to make “something you know secure. Unfortunately, it’s cheap and easy to implement. Two things which are always important. ...

November 7, 2007 · 4 min · admin

Bob Ross

Created by “ the Robot Economist, and for hsarik, it’s Bob Ross and the Joy of Painting Missiles. Click the picture for the full sized image with rotating scenery.

March 14, 2007 · 1 min · admin

The FBI's national security letters

Sometime in late September or early October of 2001, I received a call from an individual identifying himself as an agent of the FBI and asking for information about the owner of an email account from the place I worked. He stated that he believed the account was relevant to a terrorist investigation. Of course, this was in the immediate aftermath of September 11th and everyone had security concerns, but I was also certain that I didn’t want to give away information to someone who shouldn’t have it. Following a fairly standard procedure, I requested his phone number, badge number and locale so that I could contact the FBI to confirm his identity. The agent gave me a lot of grief about this, noted that I was putting lives at risk by not immediately complying, etc., but I assured him that I would call right back. ...

March 10, 2007 · 3 min · admin