and people wonder why the change to DST worries me...

In 2005, congress mandated a change to daylight savings time, essentially, starting it three weeks earlier (March 11th, this year) and ending it three weeks later. Our local paper is requesting suggestions for what people will do with their 22 extra hours of daylight. Here’s my suggestion: spend the time fixing all of the computer problems caused by the DST change. Essentially, a change to DST is very similar to a self-inflicted Y2K problem. If you want to get a sense of how time/date issues can affect computer systems that aren’t prepared, take a look at this article regarding the new F-22 Raptor and it’s problems with the International Date Line. I wasn’t worried about Y2K because we knew about the issue for years and most modern operating systems and software had already addressed it. With the DST changes, we haven’t had nearly enough notice or preparation. Now, I’m not stocking up on canned goods, but I’m pretty certain that March 11th is going to bring about extra work.

February 28, 2007 · 1 min · admin

Poindexter

It’s taken me a bit to write about Admiral Poindexter’s visit and the small group talk we had with him. Let me start by reminding folks that here’s a guy who was convicted of lying to congress. The conviction was later overturned on a technicality. He’s also very politically savvy. I once asked my father if he would ever pursue becoming a general in the army. He told me that he was hoping to make full colonel (he later retired as a lt. colonel), but that becoming a general required a literal act of congress and that you needed to become a politician. I would assume the same thing is the case with an admiral and doubly so in the case of Poindexter who managed to become the highest ranking geek in government. All of which is to say take my impressions with a grain of salt. ...

November 24, 2006 · 6 min · admin

Admiral John Poindexter to speak at Duke University

In case you are looking for something interesting to do next week, go to Love Auditorium at Duke University on November 15th at 5pm. Admiral John Poindexter will be giving a talk: “ A Vision for Countering Terrorism Through Information and Privacy Protection Technologies for the 21st Century. It should be an interesting and thought provoking discussion of where Poindexter draws the line between security and privacy. I’ll be meeting with Poindexter and a small group at 3pm – quite the birthday present. ...

November 13, 2006 · 1 min · admin

North Korean nuclear test

Well, it seems that we finally know what happened with the North Korean nuclear test that fizzled. They apparently mistranslated the Arabic documents the U.S. posted online. Okay, so neither of those is really very funny. On the one hand, the U.S. posted a whole host of Arabic documents from Iraq that had never been examined before in the vague hope that someone would be able to find evidence that Iraq had a WMD program before we invaded. This was idiotic. It’s equivalent to my posting an entire database of personal information in the hopes that someone online could determine if there were social security numbers in it. ...

November 7, 2006 · 2 min · admin

Biometrics - fingerprint scanners

I recently had a small argument with a vendor selling biometric fingerprint scanners tied to your credit card number. He said that they were the greatest and most secure thing ever; I said that there weren’t any standards and that the security of the devices was questionable. I wish I had seen this earlier.

October 23, 2006 · 1 min · admin

Thinking about security and usability

IT security (and for that matter, other security concerns too) are often seen as conflicting with usability. There is something to that. If you take any given technology and turn up the level of security it provides, you will almost always decrease the usability of the system. Consider passwords. If people are allowed to choose their own passwords, they will typically choose something very usable for them. They’ll pick their dog’s name, their wife’s name, their userid, etc. These passwords don’t provide much security. To compensate, we often turn up the security knob and require “stronger passwords, e.g., minimum of six characters with no dictionary words and multiple “character classes. ...

October 14, 2006 · 3 min · admin

for the record, Kip Hawley is an idiot

I missed this when it came out last week, but apparently, a gentleman named Ryan Bird was detained at the airport last week for writing “ Kip Hawley is an idiot on his plastic baggie filled with toiletries. Apparently, the security trolls highly educated and diligent TSA employees took the statement to be a threat or at least behavior that they didn’t approve of and detained Mr. Bird – while telling him that he didn’t have 1st Amendment Rights at the TSA checkpoint. ...

October 1, 2006 · 2 min · admin

Presentation

I survived giving my presentation today – in spite of the fact that I showed up to the wrong hotel, in the wrong part of the city. I blame my boss. I mentioned that the talk was at the Sheraton Imperial (although I hadn’t looked to see where that was yet) and he said, oh yeah, the one down on Campus Walk road. Get to the hotel on Campus Walk – oops, that’s the Millenium. Call my administrative assistant, she looks up the location and it’s 15 miles away. ...

September 26, 2006 · 2 min · admin

Oops...

Checking my schedule for tomorrow, I realized that I have to give a talk at a major “human studies conference about security risks in web-based surveys. Unfortunately, I haven’t actually prepared anything. I’ve got my slides from the last time I did the talk, but I really wanted to do something more interesting and interactive this time – preferably with audience volunteers wearing silly hats. I may still try to put something together in the morning. I have an idea – but no sense of the feasibility. ...

September 25, 2006 · 1 min · admin

Stock spam

One of the disadvantages of having so many email accounts is the number of spam you get. Recently, I’ve been noticing an increase in stock spam making it through my spam filters. I’ve been wondering how effective the spam is and whether or not one could make money shorting these stocks. Apparently, I’m not the only one. The local paper carried a NYT article titled “ Many people fall for stock spam. In the article, the author describes the work of Frieder and Zittrain. Frieder and Zittrain found that pink sheet stocks that were heavily touted in spam were significantly more likely to be traded than non-touted stocks. Purchasing these stocks would lead a 5.25% loss within two days. For the most heavily touted stocks, the average loss was almost 8% in two days. ...

September 24, 2006 · 2 min · admin