consultant-speak for "crap"
'This model is showing signs of extreme organic growth,' I said, which
is consultant-speak for 'This model is a heap of @#$%! '
:-)
from http://blogs.computerworld.com/17138/oh_right?source=rss_sharkey
There's a theory that says "if you put a million monkeys in front of a million typewriters, in a few years you can get the collected works of Shakespeare".
There's another theory that says the internet was invented precisely to test this :-)
'This model is showing signs of extreme organic growth,' I said, which
is consultant-speak for 'This model is a heap of @#$%! '
:-)
from http://blogs.computerworld.com/17138/oh_right?source=rss_sharkey
at
16:18
0
comments
http://www.economist.com/blogs/babbage/2010/10/biometrics -- fairly short article, but packed with good stuff. Anyone who has any interest in this field should read it.
Specifically, people involved in the UID project in India should read this. Yes, this article is aimed at more at terrorism prevention than mass-scale UID, but many of the points mentioned still apply. And if you take the problems described in that article, and add in collusion by the operator, which is very, *VERY* likely in India UID, you have the potential for massive fraud and systematic abuse by whoever is in power.
Some quotes:
- But in its rush to judgment, the FBI did more than anything, before or since, to discredit the use of fingerprints as a reliable means of identification.
- What the Mayfield case teaches about biometrics in general is that, no matter how accurate the technology used for screening, it is only as good as the system of administrative procedures in which it is embedded.
- The panel of scientists, engineers and legal experts who carried out the study concludes that biometric recognition is not only "inherently fallible", but also in dire need of some fundamental research on the biological underpinnings of human distinctiveness.
- The body of case law on the use of biometric technology is growing, with some recent cases asking serious questions about the admissibility of biometric evidence in court.
at
04:06
0
comments
kudos to Matt, author of Hg for this: http://lwn.net/Articles/409864/
full text (it's small enough anyway):
On Wed, 2010-10-13 at 11:32 +0800, martin_liu@htc.com wrote:
> Dear Matt:
>
> Recently, I got an oops at pagemap_read(). I've tried to
> searched some patches and found a patch as below link.
> http://kerneltrap.org/mailarchive/git-commits-head/2010/4...
Dear Martin,
Are you from the same HTC mentioned here?
http://www.freedom-to-tinker.com/blog/sjs/htc-willfully-violates-gpl-t-mobiles-new-g2-android-phone
If so, please ask again in 90-120 days. Until then, you're on your own.
at
21:41
0
comments
IIRC the first time is for entering into a patent deal with MS.
Now it's for this:
HTC Willfully Violates the GPL in T-Mobile's New G2 Android Phone
(Freedom to Tinker) -- http://lwn.net/Articles/409548/
at
15:01
0
comments
http://www.f-secure.com/weblog/archives/00002040.html
Very crisp. I didn't know it propagated through USB sticks -- those bozos deserve it if it did.
And screw you, ISRO, if India's INSAT 4B died due to stuxnet -- you guys deserve more like this before you'll come to your senses and stop using Windows.
Honestly, is Linux that hard that ROCKET SCIENTISTS can't use it?
----
Meanwhile, some funny stuff from the first link, since I like their sense of humour so much:
----
Q: Which factory is it looking for?
A: We don't know.
Q: Has it found the factory it's looking for?
A: We don't know.
----
Q: What's the relation between Realtek and Jmicron?
A: Nothing. But these companies have their HQs in the same office park in Taiwan. Which is weird.
----
Q: When did Stuxnet start spreading?
A: In June 2009, or maybe even earlier. One of the components has a compile date in January 2009.
Q: When was it discovered?
A: A year later, in June 2010.
Q: How is that possible?
A: Good question.
Q: Was Stuxnet written by a government?
A: That's what it would look like, yes.
Q: How could governments get something so complex right?
A: Trick question. Nice. Next question.
Q: Was it Israel?
A: We don't know.
Q: Was it Egypt? Saudi Arabia? USA?
A: We don't know.
Q: Was the target Iran?
A: We don't know.
----
Q: What happened on 9th of May, 1979?
A: Maybe it's the birthday of the author? Then again, on that date a Jewish-Iranian businessman called Habib Elghanian was executed in Iran. He was accused to be spying for Israel.
Q: Oh.
A: Yeah.
----
at
17:07
0
comments
Why I Quit "Creepy" Oracle: The Father Of Java James Gosling Speaks
Out -- http://www.eweekeurope.co.uk/interview/why-i-quit-oracle-the-father-of-java-james-gosling-speaks-out-9995/print
Quite a few hard hitting comments on the new villain for the open
source crowd (as if we needed another!).
Well at least he did it after leaving, unlike my old boss, who ranted
against his (then) employer (and my current employer) to a reporter
even *before* he had left -- talk about ethically challenged!
But while it's perfectly fine to talk about Oracle being "ethically
challenged" and "micro-managed", it just doesn't seem proper for a
senior person to talk about salary etc., or to say that the CEO "gives
me the creeps" to the press.
A friend of mine who reads a lot more than I do mentioned that this
was in line with any of Gosling's past writings that he had read --
nothing to learn, nothing to take away -- unlike people like Larry
Wall or Guido van Rossum, where you almost always learn something new
or get a new perspective on something old, etc. (We're talking about
"learn" in the academic sense here, not "I learned that Ellison is a
creep, so isn't that learning?")
And finally, I have to say this. I'm not a big fan of Gosling anyway.
I hate Java -- I call it the "COBOL of the internet", and I think it
has done a lot to remove any fun that programming could have had for
lots and lots of people, and made it a bloody chore. Comments like
this would have had a lot more weight for me if they had come from
Larry or Guido, but they're not the kind to stoop to this, I suspect,
even if they were in that situation.
And even if he felt compelled to, I bet Larry would say it with a heck
of a lot more humour and panache :-)
at
06:59
0
comments
http://lwn.net/Articles/407459/
One of the scariest articles I have seen recently.
The linked PDF is nice too, but the article about it just flows better.
at
11:07
0
comments
"I think part of a best friend's job should be to immediately clear your computer history if you die"
Awesome!
at
12:20
0
comments
http://lwn.net/Articles/405810/
Lovely humour from a lady I'm starting to admire as much as JR (that's Joanna Rutkowska, not the zero-EQ JKR of Harry Potter fame).
There's no need to click the link unless you're a file systems maven though... the funny parts are right here:
----- quote -----
This series is the core mount and lookup infrastructure from union mounts, split up into small, easily digestible, bikeshed-friendly pieces. All of the (non-documentation, non-whitespace) patches in this series are less than 140 lines long. It's like Twitter for kernel patches.
VFS developers should be able to review each of these patches in 3 minutes or less. If it takes you longer, email me and I'll post a video on YouTube making fun of you.
at
15:08
1 comments
I can't recall when was the last time Bruce Schneier said something I did not quite agree with. The last paragraph could have at least hedged a little, instead of making it sound so unequivocal. Oh well...
-------- Original Message --------
If you're a typical wired American, you've got a bunch of tech tools you like and a bunch more you covet. You have a cell phone that can easily text. You've got a laptop configured just the way you want it. Maybe you have a Kindle for reading, or an iPad. And when the next new thing comes along, some of you will line up on the first day it's available.
So why can't work keep up? Why are you forced to use an unfamiliar, and sometimes outdated, operating system? Why do you need a second laptop, maybe an older and clunkier one? Why do you need a second cell phone with a new interface, or a BlackBerry, when your phone already does e-mail? Or a second BlackBerry tied to corporate e-mail? Why can't you use the cool stuff you already have?
More and more companies are letting you. They're giving you an allowance and allowing you to buy whatever laptop you want, and to connect into the corporate network with whatever device you choose. They're allowing you to use whatever cell phone you have, whatever portable e-mail device you have, whatever you personally need to get your job done. And the security office is freaking.
You can't blame them, really. Security is hard enough when you have control of the hardware, operating system and software. Lose control of any of those things, and the difficulty goes through the roof. How do you ensure that the employee devices are secure, and have up-to-date security patches? How do you control what goes on them? How do you deal with the tech support issues when they fail? How do you even begin to manage this logistical nightmare? Better to dig your heels in and say "no."
But security is on the losing end of this argument, and the sooner it realizes that, the better.
The meta-trend here is consumerization: cool technologies show up for the consumer market before they're available to the business market. Every corporation is under pressure from its employees to allow them to use these new technologies at work, and that pressure is only getting stronger. Younger employees simply aren't going to stand for using last year's stuff, and they're not going to carry around a second laptop. They're either going to figure out ways around the corporate security rules, or they're going to take another job with a more trendy company. Either way, senior management is going to tell security to get out of the way. It might even be the CEO, who wants to get to the company's databases from his brand new iPad, driving the change. Either way, it's going to be harder and harder to say no.
At the same time, cloud computing makes this easier. More and more, employee computing devices are nothing more than dumb terminals with a browser interface. When corporate e-mail is all webmail, corporate documents are all on GoogleDocs, and when all the specialized applications have a web interface, it's easier to allow employees to use any up-to-date browser. It's what companies are already doing with their partners, suppliers, and customers.
Also on the plus side, technology companies have woken up to this trend and -- from Microsoft and Cisco on down to the startups -- are trying to offer security solutions. Like everything else, it's a mixed bag: some of them will work and some of them won't, most of them will need careful configuration to work well, and few of them will get it right. The result is that we'll muddle through, as usual.
Security is always a tradeoff, and security decisions are often made for non-security reasons. In this case, the right decision is to sacrifice security for convenience and flexibility. Corporations want their employees to be able to work from anywhere, and they're going to have loosened control over the tools they allow in order to get it.
This essay first appeared as the second half of a point/counterpoint with Marcus Ranum in Information Security Magazine. You can read Marcus's half here.
at
16:21
1 comments