Tuesday, November 08, 2005

After Criticism, Sony Issues Fix for Hidden Rootkits

No comments:
Upping the ante yet again in the ongoing war of the recording industry vs. the rest of the world, Sony recently released several audio CDs that automatically (and secretly) install copy-protection software on any Windows PC they are inserted into.

After some very embarrassing reports, they quickly backpedaled and released a program to undo the damage. You can download it here.

Sony, and others, have a long history of experimenting with copy protection schemes. The most recent attempts involve distributing a "multi-session" CD, containing audio tracks and a data track. When inserted into a Windows PC, the "autorun" file in the data track installs a software wedge that hides the audio tracks. This forces you to play DRM-protected versions of the songs, contained as data files.

This is nothing new. Sony's latest version, however, takes steps to hide the existence of the wedge. And it installs itself in such a way that removal will permanently cripple Windows' ability to play any audio CDs. As far as I'm concerned, this is no different from a virus.

Fortunately, there are plenty of workarounds, if you're careful. The easiest way is to not use Windows. All other operating systems (Linux, Mac OS, etc.) will not auto-run the installer, and is incapable of being run manually. Without the software wedge, the same programs that play/rip normal audio CDs will work on the protected disc.

If you're forced to use Windows, the thing to do is make sure the auto-run facility doesn't run. Holding down the SHIFT key whenever you insert the disc will do it. You can also disable this permanently in several different ways, depending on what version of Windows you are using. This will have the side effect of preventing all your data discs from auto-running, but IMO, this is a good thing.

Thursday, November 03, 2005

An explanation of gas price fluctuation

No comments:
This article is very informative. It explains, in simple language, why gas prices rise quickly, but fall slowly. At least as far as the retailers go. A superbrief summary is:
  • When oil prices go up, the manufacturers raise their price, and retailers must pass the increase along to customers.
  • When oil prices go down, retailers do not usually lower their prices until competition forces them to. Which means it will be some time after the oil company's price goes down. Depending on the local market, there may be a fairly large delay.

What the article doesn't discuss, however, is what the picture looks like from the point of view of the oil companies. They have the same problem (rising prices must be passed along, competition causes prices to go down), but they have an additional complication - futures trading.

Oil, like all commodities, is deeply involved in futures trading. A future is like a stock option. You pay a premium up front and get a locked-in price (for a maximum amount, for a time limit, of course). You can exercise your future to buy (or sell) oil at that price, if you want to.

Futures are used by speculators to leverage investments. Instead of buying and selling oil (where you need to pay for it all and store it somewhere), you instead buy and sell futures. If you buy a future for buying oil, and the price later goes up, you can exercise the future and immediately sell the oil at market prices and take a profit. If the price later goes down, however, you've lost the premium you paid for that future. Similarly for futures for selling oil - if you buy one and the price goes down, you buy oil at the market price and exercise your future to sell it. If the price goes up, you've lost the premium.

As for the other side of the equation, people sell futures to buy and sell. When you do that, of course, you are bound to buy/sell oil at the future's price if the future is later exercised.

Oil companies use futures in order to make their finances more predictable. In addition to buying oil on the open market, they also buy futures for buying oil. If the price goes up, they can exercise these futures and buy at the price they've budgeted for. It doesn't keep the price down, because new futures will be at a higher exercise-price, but it does allow them to keep their budget predictable.

When the price of oil goes down, however, they abandon the futures and just buy on the open market - because that price will be lower. But they have to eat the cost of buying the now-abandoned futures - those premiums are not refundable. So their costs can't come down immediately, which is why the prices they charge won't come down immediately either. When prices stabilize, they will once again resume buying oil with their futures, and the prices they charge will lower to the new equilibrium point.

In brief: prices go up immediately because the price of futures goes up immediately. Although the prices of futures will come down immediately, the oil companies have to absorb the cost of the abandoned futures, which introduces a delay when prices come down.

Is there an alternative?

If using futures creates this problem, why do they do it? Why not just buy oil at market prices and avoid all this nonsense?

The answer is that oil prices fluctuate daily, and often unpredictably. If every shipment of oil is a different price, it creates a lot of uncertainty in the budget. Companies would have to compensate for this by either keeping a stockpile of oil (to buffer out supply fluctuations) or take a higher profit margin (to buffer out price fluctuations.) These would cause prices to go up (to pay for storage or to make the higher margin). And unlike what happens with futures trading, these price increases would be affecting consumers all the time, not just when commodity prices are on the downswing.

Wednesday, November 02, 2005

I've got an iBook!

No comments:
I finally decided it was about time to own a laptop computer of my own. And since I've been very happy with my Macintosh desktop system for more than the past three years, I decided that I will have to get a Macintosh laptop.

After careful consideration of the various available models, I chose the iBook. More specifically, the small model with the 12" screen.

The 12" model was a most important to me, because I want a laptop small enough and light enough to carry with me wherever I go. Small enough to be useful on my lap while a passenger in a car, bus or airplane. Although I'd prefer a higher resolution display, that is not available without moving up to a 15" or 17" PowerBook, which is both larger and more expensive than what I'd like.

I bought my iBook with a few upgrades. An 80G hard drive (for an extra $100) and 1.5GB of memory (for an extra $300). I could have upgraded the memory myself for $200, but I decided that $100 is not an unfair price to pay to have the memory installed and tested at the factory. And if there's ever a problem with the computer, Apple won't be able to tell me that it was because of third-party memory.

Anyway, I haven't had too much time to do too much with it yet, since it only arrived today, but so far everything has been working as expected. As expected, I was not able to copy my Emacs installation from my other computer, forcing me to download sources and compile it myself. This went smoothly, since I've had to do this several times before on my other Mac. Other applications (Thunderbird, Firefox, Microsoft Office, etc.) all installed without problem.

Friday, September 23, 2005

Researchers recover typed text using audio recording of keystrokes

2 comments:
Holy cow! This is a bit disturbing, even to someone like myself.

I'm sure the truly paranoid will never be able to sleep at night knowing this little tidbit.

Thursday, September 22, 2005

Freakonomics, abortions and crime

No comments:
Orson Scott Card discusses Freakonomics the discovery of correlations, causes and effects that completely disagree with what is usually considered common knowledge. He uses correlations between crime rates, abortion and promiscuity as a prime example.

Even if you disagree (and I'm sure most people will, because the conclusions are quite disturbing), it's extremely thought provoking and should be read by as many people as possible.

Tuesday, September 13, 2005

Common sense security

No comments:
This is based on a comment I made in the MacBytes forum. It was in response to an article about Mac OS security, but is equally valid for everybody.
All security for all operating systems must start and end with the user. If the user is knowledgeable and vigilant, then most security products are unnecessary. If he is not, then no amount of add-ons will protect him.

I use a wide variety of computers at home and at work, running a wide variety of operating systems, including Windows. I employ the following security measures for all of them:

  • The networks (home and work) are behind hardware firewalls. The home LAN is behind a Linksys router with NAT turned on and all but one inbound port (SSH) blocked. The corporate LAN has its own firewall, administered by the IT department.
  • Operating system software is kept up to date with all the latest patches. I use the auto-update facilities to inform me of updates, but not auto-install them. (I want to know what and when I'm installing these patches, even if I end up installing them all.
  • I keep my applications (especially internet-using ones) up to date with the latest patches from their respective vendors.
  • I only install software that I purchase or download from well-known sites. This is almost always the publisher's own site or a genuine not-pirated CD.
  • I do not trade "warez"
  • I do share my disk volumes over the LAN, but with some restrictions. At home, all volumes are exported as read-only (if I need to put a file on another computer, I log-in locally to that computer and use the network to fetch it from the file's source computer, which also exports its volumes as read-only.) At work, I use our network's domain-level security so that only my personal account can mount one of my volumes read-write - other domain users are read-only, and guest-access is blocked.
  • I disable auto-installation in all programs, including web browsers, games, and the OS itself. I will let apps notify me when updates are available, but I must always give approval before download or installation. When stuff has certificates (like Windows updates), I review them to make sure the files come from where they are supposed to be coming from.
  • I never run a program e-mailed to me. Never. Even if the message is expected and comes from someone I know, I won't trust it. If I want someone to give me a program (which happens very very infrequently), I'll have him put it on a known web server and send me a URL to it, or (even better) snail-mail me a CD or load it into a flash drive I always carry with me.
  • I don't use known-insecure programs (like Outlook)
  • I configure my e-mail program (Thunderbird) to disable plugins, Java and JavaScript. Remote images are blocked.
  • Whenever possible/practical, I work from non-administrator accounts. Unfortunately, this usually isn't practical for Windows systems, but it is no big deal on other systems (including Linux and Mac OS.)
Note that none of these procedures require the purchase of any special software and none require the overhead of background software.

I do keep a virus scanner (provided by my employer) running on the Windows PC's just in case something should slip by my procedures. (The scanner updates itself every day at 1:00am and scans the local hard drives every day at 2:00am.) To date, I have gotten exactly one virus over the entire time I've had computers attached to the internet (which is as long as the internet has existed.) And this virus arrived via Microsoft's own Office Update server.

I also run AdAware and SpyBot S&D to scan for spyware on the PC's. I run these scans infrequently, but they have never found anything more intrusive than tracking cookies in my web browsers. (Which I make no attempt to block - I don't consider cookies a serious threat.)

I run the Microsoft software firewall on my Windows XP boxes, but I do not normally run software firewalls on any other computers, preferring to rely on the LAN's hardware firewall. I do keep a copy of Zone Alarm installed, but disabled on Windows laptops - I enable it when traveling in case other networks don't have proper firewalls in place.

Sometimes people ask if I should run antivirus software on my Mac. I tell them what I just wrote above. With proper security procedures, a virus scanner should not be necessary. If the Mac should ever become a target of intense malware activity (like Windows is), I will probably invest in antivirus software "just in case" it should be needed, but I intend on waiting until then.

Monday, September 05, 2005

Pizza to prevent cancer?

No comments:
This weekend, I saw excerpts from this (July 2003) Reuters article posted in the window of a pizza parlor. I found it rather fascinating. There appears to be a link between regular consumption if Italian pizza and reduced cancer risk.

Follow the link for the details.

Thursday, September 01, 2005

Orson Scott Card: Gaza and the Israeli Settlers

No comments:
Card analyzes the current Israeli political situation. Specifically, Sharon's move to forcibly remove all Jewish settlers from Gaza.

His analysis (which I won't repeat, because it is somewhat involved - go read the article) seems solid, but it does not leave me with a good feeling about the man.

While Card's analysis may make perfect sense from a global-politics point of view, ultimately, this policy boils down to forcing people out of their homes in order to create a PR campaign. This is especially disgusting and hypocritical when you note that Sharon (who was not Prime Minister at the time) was one of those trying to convince as many Jews as possible to move into Gaza.

My prediction (which is far from mine alone) is that this policy is not going to change a thing. The terrorists will continue to use Gaza as a base of operations for attacks against Israel. They will now start demanding more land, including Jerusalem (and based on recent reports of attacks there, this may already have begun.) And what is Israel going to do? They're either going to have to wage an all-out war (destroying any sympathy from the press) or they'll sit back and let their people be murdered (which seems to have been their policy up until now.)

PR stunts may work fine for drumming up global sympathy, but they won't do squat for bringing about peace. When you're dealing with an enemy that sincerely believes in victory-or-death, and victory means your complete annihilation, you only have one option - to give them death. Until Israel (regardless of who is in charge) faces this reality, every action they take is just another euphemism for surrender and suicide.

Maybe I'm being far too pessimistic here. I certainly hope I am. But so far, those who disagree with me can only point to wishful thinking to back up their arguments.

Tuesday, August 30, 2005

Why corporate IT is melting down

No comments:
This week, Winn Schwartau writes in his Security Awareness blog about why Windows is such a mess and why it has to fail:

http://securityawareness.blogspot.com/2005/08/mad-as-hell-xiii-reprise.html

In a comment on this article, I wrote about what happens when corporate idiocy is then combined with the WinTel problem of cheap PC's and bug-ridden software.

I think this comment is worthy of an article in its own right, so here it is, in an expanded form, since I can write more here than on a comment page.


It is human nature to not want to admit error. It is the nature of bureaucracies to flat out refuse to admit error, no matter what the cost. They would rather run the entire corporation into bankruptcy than do something that would be an admission of error. And this is with good reason. The one who admits a mistake gets blamed for everything that goes wrong, even if the mistake wasn't his decision and even if the things going wrong have nothing to do with the decision. People get fired from their jobs for admitting mistakes. People get blacklisted from whole industries if they admit mistakes in public.

This, in itself, is a disaster that affects most corporations. Now guess what happens when you get an IT department involved, an aging infrastructure, and a budget crunch.

Initially, everything is running smoothly. The corporation is using big iron for everything important. This is probably some combination of mainframes, minis, workstations, etc. PC's are used, but not for anything more critical than as terminals for accessing the equipment in the machine room. The equipment works well. Partly because very expensive equipment is designed better, partly because it is easier to design and test software when the hardware configuration is carefully controlled, and partly because the number of computers is small enough for the IT department to be able to support.

This all works great until the big iron starts costing too much money. Maybe the electric bills are too high (some old mainframes draw a LOT of power!) Maybe some parts have broken and need replacement. Maybe the annual maintenance contracts are getting too expensive. Maybe the manufacturer is dropping support for the old equipment. It could even be something as trivial as needing more hard drives.

At this point, the IT department is doomed. They would like to buy more of the same. Add more memory/disk to the mainframe. Replace one cluster of minis with the newest model. Move to the latest system software. Ideally, they want to keep everything exactly the way it is. But their bosses won't stand for this. They know an upgrade is needed, but they don't want to spend the money on new big-iron. They look through the latest Dell/Gateway/HP catalog and see that PC's cost $500 each, and PC servers cost $5000 each. They order the IT group to replace the mainframes with a network of PC's.

Sometimes, an IT manager can fight this. Most of the time, he doesn't dare. He can be fired and replaced with someone who will tow the corporate line. The decision has already been made, and made by people with absolutely no expertise.

So the PC's are installed everywhere. The IT managers get bonuses for saving money (if they can make their bosses believe the move to PC's was their idea), and the executives consider the case closed. Everybody pats themselves on the back for a job well done (except for the IT people who know exactly what's about to happen - usually the help desk staff.)

Soon, the PC's start failing, or other weird problems start happening. Users have random system crashes. Unwanted programs (spyware, viruses, worms, etc.) start installing themselves all over the place. Users bring programs in from home, even though there may be a policy forbidding it.

The IT help desk does their best to keep everything running smoothly. They patch, clean, upgrade, and reinstall the PC's as necessary. But the problem doesn't ever go away. This is partly because the hardware is cheap junk. Partly because individual (usually untrained) users are doing their own system maintenance (even possibly against corporate policy). Partly because hackers and script kiddies attack Windows far more often than any other system. Partly because the IT staff has not been properly trained to transition from mainframe maintenance to Windows maintenance. And partly because Windows really is very insecure and very expensive to maintain in a large networked environment.

So the users start complaining a lot. The IT help desk gets swamped with calls. There is never enough money in the budget to hire more help desk staff. Help desk staff burn out and quit and have to be replaced with new staff that don't have sufficient training. This forces the help desk to start using handbooks instead of analysis in order to keep up with the calls, degrading the quality of support and making users even more angry.

IT clamps down on security by installing draconian firewalls and proxies throughout the network. They lock users out of their own PC's in order to restrict who upgrades what. They download and test/review every patch from Microsoft and push the updates onto user's computers over the network.

But this isn't fast enough. Soon a virus arrives and trashes the network. It takes weeks to fully recover. Word gets around that Microsoft actually had a patch available to fix the security hole that the virus used, but it wasn't deployed across the corporate network. Because IT hadn't yet tested the patch against all the corporate software. Those users who had hacked their way around IT's restrictions and installed the update anyway, of course, weren't damaged by the virus.

In order to prevent this from happening again, IT turns on Windows' auto-update facility, where patches are automatically downloaded from Microsoft and installed. This prevents a recurrence of the problem, but it also eliminates any semblance of control over the network. IT no longer knows what system software is running on the PC's. Some patches will break applications, and IT won't find out until after users complain about the broken apps.

The situation spirals further and further out of control. Ultimately, the entire IT department is little more than a group of highly paid errand-boys. All of the real system maintenance is being done by the software vendors through automatic updates. The IT people will run cables and replace broken hardware, but they end up powerless to do anything else. The help desk tries valiantly to make the best of the situation, but ultimately, they are powerless to do anything more than chase down symptoms, read scripts, and apologize a lot.

Some people in IT see this happening and they know exactly why. They know that they need to get rid of the PCs and consolidate control back in the machine room. But the reasons for getting rid of the big iron (high cost) still exist, and executives refuse to include in-house support as part of the cost of running a PC-based network. And he who admits an error gets blamed for it. And users won't want to give up the freedom they were given, even if that freedom is clobbering their ability to do their jobs.

And, of course, the executives will say something like "Everybody else has switched over to PC's and they're doing fine, so the problem must be with you and your staff." Completely ignoring the fact that everybody else is also melting down and refusing to admit it.

Which is where we are today.

Monday, August 29, 2005

... and so it begins ...

No comments:
Remember the Rio? The first commercial MP3 player? Originally made by Diamond Multimedia, most recently made by D&M Holdings.

Well, D&M has decided to drop the Rio line of music players. Apparently they decided that they could not profitably compete against Apple's iPod.