Monday, December 12, 2011

Alien Spaceship near Mercury

This is an amazing video (with amateur narrator). If I didn't already believe there's life out there, it would definitely move me closer.

From Space.com: On Dec. 1, a camera onboard NASA’s STEREO spacecraft recorded a wave of electrically charged material shooting out from the sun and blasting Mercury. Footage of this “coronal mass ejection” (CME), as such events are called, has caught the attention of alien-hunters, who say it has unveiled a giant, “cloaked” spaceship parked near the solar system’s innermost planet.

Full Disclosure - The space.com article does have some mumbo-jumbo about "image processing artifacts" and/or other things that are hard to understand, but let's just say the aliens are either watching, or, even better, have a vacant, operating, space station out there for us to pick technology off, as soon as we can get that close to Mercury.

Are we up to the challenge?

Perry

Tuesday, November 22, 2011

Chris DiBona at Google says all AV makers on Android are [crooks]

There's an interesting discussion on the web about whether AV products are needed on Android and Chris DiBona really got things going when he claimed all the AV makers "charlatans and scammers", and "IF you work for a company selling virus protection for android, rim or IOS you should be ashamed of yourself."

[ although these juicy quotes may change in subsequent edits ]

Then,

Antivirus makers responded on Ars - "We're not Scammers"


Unfortunately there was a small matter of 21 apps pulled from the Android market

http://arstechnica.com/open-source/news/2011/03/malware-in-android-market-highlights-googles-vulnerability.ars

So is this simply a matter of Mr DiBona using a pedantic definition of AV?

1. AV has truly morphed to Malware detection
2. If you use Perry's Law of Malware - You can only respond to two kinds of problems - the kind you've seen and the kind you can anticipate. People who care about their data and IT need to address both - and we can't simply trust Google and the Carriers to do it for us.

Perry

Update 1/4/2012 - Maybe he means this?
http://threatpost.com/en_us/blogs/fake-antivirus-scams-targeting-android-users-122911

Update 1/28/2012 
From Slashdot: Android Malware May Have Infected 5 Million Users

Oh really?  5 million users af[in]fected because a platform is 
  1. Totally insecure
  2. Has no AV or Malware detection
  3. Even though it has a single place to acquire software, the administrators of the distributor have completely abdicated their responsibilities for quality control 
  4. Largely unpatched due to closed platform on customer dependence on suppliers who prioritize releasing new devices far above fixing the security of old devices?
And the people trying to make a business out of this obvious customer need are scammers?
Hello? Anybody home?  


Friday, November 18, 2011

Google knows all, and sometimes it's easy to make them tell

This is interesting - a blogger uses google analytics to de-anonymize another blogger

http://waxy.org/2011/11/google_analytics/

Lesson- If it's important to keep your anonymity - link nothing together

Wednesday, November 2, 2011

It's 1984, i guess

Well I guess it's like the frog in the water...  He never notices it's boiling until it's too late.

I think it's too late

When will the TV's be two way?  Soon?

What can these people possibly be thinking?

:-(

Monday, October 17, 2011

Update: Newegg *HAS* jumped the shark. Death Watch?

Well, it happens to the best of them.

I was looking for a flat panel TV for my daughter, and happened to look at Plasma TV's at Newegg, to see if they were still the best deal.

Well, I went to the page for 42+", and 29 out of 37 had no prices- you had to add them to your cart.  Some, being truly evil, you had to enter your credit card at checkout just to see the price.

Then, I noticed, out of the "new" ( not recertified, open box, or out of stock ) there were only 2 out of 28 that had prices!

 I had to send a comment to them to tell them how disappointed I was, and found that there was a 1000 character limit!

Well, that's one way to say "People aren't saying much bad about our new policies".

Sigh


Update - LED/LCD TV's aren't any better - "click for details" is code for "enter your credit card to see the price"

Update 2 "We're sorry. Due to technical difficulties[emphasis mine] we are temporarily unable to accept Discover cards through our Credit Card payment option. Discover cards may be used via the PayPal option. Please select an alternate credit card or payment method."

SO I can't even get the price now?

Let's watch their downhill slide in Reseller Ratings :-(

Perry


Wednesday, October 12, 2011

Microsoft Security Intelligence Report is Available

Interesting Findings, sure to be misinterpreted by the mass media

If you're reasonably interested, key findings are available in a separate document

perry

Wednesday, September 28, 2011

Zynga? Who's that?

Hahahaha

Just kidding - I know who they are - they make Farmville and Mafiawars and their motto is "do evil"

95% reduction in profit?  Cool. Too bad it's not revenue.  Soon.

Groupon too?  Whoda thunk?

Update:  11/28/2011 - Zynga's nice work environment made slashdot.  Big surprise.  Don't think it'll affect anything.

Update 2 - Guess what - Groupon isn't the greatest thing for their vendors.  "Without a doubt, the worst decision I have made".  People will say that after their IPO too.

Microsoft paper Shows They're Cheaper than VMWare

According to El Reg, using Server 2008 r2 virtualization is much more economical than VMWare

here

In this case, be careful about the server licenses - where they show smaller quantities than they actually sell more to follow... Perry

Friday, September 23, 2011

Wow, just wow.

End of an Apotheker era, HP installs Whitman as CEO

 Update:

The Motley Fool has this interesting article, with this quote:

" One of the board members who had never met Apotheker tried to explain: "I admit it was highly unusual. But we were just too exhausted from all the infighting." Try using that line on your boss sometime. "

Umm, yeah, it's only the chairman of HP.  

 


Thursday, September 22, 2011

I'm Begging You... Please PLEASE Don't Gamble Online!

Shocker - Full Tilt Poker is nothing but a Ponzi Scheme - from El Reg  

News Flash - And this goes double for online voting -    There's NOWHERE that's easier to cheat than if you're running a web site.

Gambling, Voting - The online platform is ready made for cheating, the rewards are incalculable, and the people managing the process aren't, let's say, the most trustworthy

While I can only speak for the tech, really, trust me when I say the opportunities for cheating are incredible

Perry

Monday, September 12, 2011

USAIR Bad, JetBlue Good?

I know - what did I expect?

Well, better than this - here's my letter to them:

I'm pretty disappointed - I bought a RT ticket from BOS to SAT, and got stuck with a middle seat from CLT to SAT.  Now I see that the aisle seat behind me is available, but costs $24?  My company won't pay extra charges but wouldn't have cared if that $24 was included in the original price.  To top it off - I'm in Zone 5 for boarding. Really disappointed.  I expected more.  PS feedback form requires 19 fields filled in?  Unbelievable.

After the flight: Better now.  Plane was way full, guys on both sides of me were "large" but not XL, so whatever.  At least I  got my work done on the first flight.  USAIR forgiven, sorta - they are sure above Sony on my S list but not way above.  Delta on the return was Way Better.  I still want to make blog called "Middle Seat For You"


Update 10-17-2011 - Flying with them again - middle seat to Charlotte - $26 to get an end.  Last Window seat on the plane to SAT.  $43 to move up to an aisle.  Ugh!  I guess I have to expect advertised price on USAIR gets a middle seat.

Update 10-27-2011 - Flew JetBlue to DC - My employer has negotiated great rates  - less flights than USlessAir though - tried to change the time and told "$40 charge" by two people when I told them I had a refundable fare.  On their advice, I took standby on the earlier flight.  Do you see where this is going?  Wrong.  The person from checkin called the gate and asked for me by name.  She apologized and said that she was confused when I said I had "Fully Refundable", and not "'Corporate rate' which is instantly changable". Gold Star for my employer and JetBlue negotiating great prices and policies, not so much for not telling us the code words.  And of course JB doesn't have the secret free beer and wine that we get on the US/DEL shuttle - oh well.

Tuesday, August 30, 2011

Are Body Scanners Safe?

I think the answer is we just don't know.

I've read an article from a DNA researcher that might have put me over the top.  Between my own scan cancer and both my mom and dad, I think it's time to bypass the scanners.

http://myhelicaltryst.blogspot.com/2010/11/tsa-x-ray-backscatter-body-scanner.html

I really don't want to make the TSA people angry, they're just doing their job and I'm sure they don't want to work next to those evil machines any more than I want to get inside.

I'll just have to be extra-charming. ( how hard can THAT be? )


Update - 11/2/2011

Well, I've been through the pat-downs a few times, now (2-3) and the airport security folks are pretty understanding, I haven't even had to play the cancer card.   They've been great actually, but the physical patdown easily takes over a minute, and it has taken a few minutes to wait for a guard.

Oh, here's another paper that tells why we're using the scanners in spite of the rule that X-rays can only be used for a medical need.

For crying out loud - (this is for me too)  Do some observation and get in the line using the magnetometers!

Perry

Thursday, August 18, 2011

Red Hat releases KVM hypervisor 3.0

El Reg reports that Red Hat has released version 3.0 of its enterprise virtualization server, RHEV.

It appears that the biggest change is that you can now manage it from Linux and don't need Windows.  Wait. What?  I guess it had something to do with the QEMU technology that it got when it bought Qumranet in sept 2008 (huh?). Oh well - read the article yourself.

Code has been ported from .NET to Java, database has been ported to Postgres,  you can still use Active directory to manage user logins, plus their own LDAP/Kerberos.

More scalable - up to 128 physical cores and 2TB main memory, guests can have 64 virtual cores and 2TB virtual memory.

Cost?

"Companies decide to standardize their Linuxes on RHEL, then they virtualize their workloads using either the integrated KVM or RHEV. Then, they look at the cost of vSphere from VMware and decide to try a few Windows workloads on RHEV. Thadani says that prior to VMware's vSphere 5.0 launch and its memory tax, RHEV cost about one-seventh as much per host to virtualize x64 machines with the same number of VMs. But in the wake of the virtual memory tax, even after VMware's rejiggering, RHEV now costs one-fifteenth to one-twentieth of vSphere 5.0 to virtualize a big, fat server."

This is pretty cool, and there are definitely places in labs where this technology should be tested.

[p]

Monday, August 15, 2011

You have a Duoply for Broadband ( or worse ), now a leaked document shows the AT&T is gunning for the same thing for wireless


How do you think *THAT* will work out?

From DSL Reports:

The leaked document shows that AT&T is eliminating the T-Mobile presence in the markets where they overlap, which is basically all of them, and doesn't need the extra spectrum - it already has more than anyone else and less customers, and we can see from the iPhone fanbots how they like that.

It also shows that they will largely use it to eliminate Sprint, leaving the market to 2 providers.  Don't like either one of them?  Maybe Radio Shack will still be around to buy a walkie talkie?

The leaked AT&T document shows shows that instead of the promised $8 billion increase in network investment after the deal, it will be a $10 billion *decrease*, based on the lack of the expected $18B that T-Mobile will be doing.

Is the market big enough for 4 carriers?  I think so. 

Will the FCC roll over and let the consumers lose?  With an election so close?  I think it comes down to how much influence the geeks have - do you think we can pull this off?

P

Sunday, August 14, 2011

Is running open source E-Commerce a good idea?

According to El Reg, 5 million web pages have been taken over in an attack against open source store manager tool named osCommerce.

There's a pretty good movie of a drive-by exploit in action, taken by a security researcher named Wayne Hwong from Armorize.com running an infected page from gamefocus.uk web store.  It bounces from UK to EU to RU where it gets the updates.exe file that runs on your PC.  Unfortunately it doesn't go into detail how to protect yourself.

The overall problem is the popularity of the ecommerce tool.  If it's popular and widespread tool, then once an exploit is created, google can be used to find all the stores that use it, the badguy can load his malware on all the sites.  It starts out one at a time, but this one was automated, so sites were taken over quickly, then all the machines that accessed the web sites.

This is the reason I run Noscript.

Perry

Wednesday, June 15, 2011

Tuesday, June 7, 2011

Browser Fail - You can't test a link's trust by hovering over it :-(

OK, go figure, the tried-and-true way of testing a link in Firefox - hovering over it and checking the status at the bottom - can be killed by, you guessed it, Javascript!  What are these people thinking?

Dear Firefox, Chrome Developers -  Can you please do something about this, like make the status bar BLINK RED if someone changes the link name in Javascript?!

Until then - aggressively use NoScript!

Thank you
Perry

Friday, March 18, 2011

Does Facebook stay up at night thinking of ways to annoy its users?

*YES*

On Friday, Facebook will start using your photos in ads that will appear on the profile page of your contacts. It's legal and is mentioned in the fine print when you create your account. TO stop this do the following: Account, Account Settings, Then click on Facebook Ads ( tab...), choose "No one" on the drop-down menu and save changes. Copy this and use in a status update. **PASS ALONG**

[It looks like there are TWO places to set this - at the top (which was pre set to "No One" for me, and at the bottom, which was not, funny, huh?]