Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts

Sunday, February 28

Geek code - why do I do this, again?

So, it was pointed out to me today that my current Geek Code, shown at the bottom of every page of this blog, is significantly out of date. As I always mention when publishing these updates, version 3.12 of the Code was formulated in 1996, so my available options for the various categories aren't particularly reflective of how things really work in the world these days.

In any case, here's my new Code:

-----BEGIN GEEK CODE BLOCK-----
Version: 3.12
GIT/MU d+@ s:+>: a->+++ C++> ULXB++++$ L+++ M++ w--() !O !V P++ E--- W+++
N o++ K? PS PE+ Y+ PGP++ t !5 X- R- tv+@ b++ DI++++ D--- G++ e*++ h r? y?
------END GEEK CODE BLOCK------


If you really care about knowing what that all means, you either know the code already, or you can get it decoded for you here.

Friday, February 19

More amazingness from Andy Ihnatko

From a recent interview Andy gave to the Tactical Pants Blog:

If you could rename the iPad, what would you call it? Why?

I have no problems with the name. But if I were to rename it, I’d probably go with “Severe Eye Injury” or maybe “Adorable Baby Ducks In Horrible Imminent Danger.” It would be Apple’s ultimate statement of confidence: “Our new tablet computer is so handy and useful that you won’t give a damn _what_ it’s called.”

As usual, he lives up to his signature wit throughout, but this answer exemplifies precisely why I read everything that ever comes out of this man's head and onto a computer screen.

Andy Ihnatko on His Tactical Internet Pants and Apple's iPad | Tactical Pants Blog

Thursday, November 19

On Predictability

I've been thinking a bit lately, and I've come up with this maxim:

Anything predictable is exploitable.

I'm going to confine this to network traffic at this point, since it's the only application for which I've given this much thought, but I'm willing to bet that it holds true in other areas as well.

Keep in mind that exploitability is not, in itself, a bad thing. A Web browser predicts that an http:// server is running on port 80 and exploits that. With that assumption, most people won't have to know what the previous sentence even means. Sometimes you run across sites where you have to enter "dummydomain.net:8080" in your address bar for servers that aren't using port 80 for Web traffic, but the ability to assume and predict a standard port is good.

On the other hand, exploitation can be bad. In old TCP stacks, the sequence numbers always started with 1 and incremented from there. This ability to predict traffic and forge legitimate responses can allow malicious machines to hijack sessions through what's called a "man-in-the-middle attack." More modern implementations of TCP/IP start the sequence number randomly; this prevents prediction and exploitation.

There are many steps in a chain at which predictability can lead to exploitability when it comes to network security, and not all of them are even technological. Take, for instance, the predictability that some percentage of users will click the link in a spam email message. Given that mass amounts of email can be sent at virtually no charge, and there is always some small percentage that will respond positively, there is still a return on investment that makes spam campaigns profitable. [0]

The same thing applies to cryptography. The only way to have a message encrypted well enough in transit to prevent decryption is to create ciphertext that is as close to pattern-free true randomness as possible. If there's any way to detect patterns, and therefore create predictability, exploitation will soon follow.

I can go on, but I think I'll stop here for now. I think, however, that the ability for prediction to beget exploitation is the driving force behind security these days (not limited to computer security). For instance, it's the regulated unpredictability of financial systems like the stock market that keeps people from reliably exploiting them for their own gain!

I might have more thoughts later, but I just wanted to put this out there while it was on my mind.

[0] "Spamalytics: An Empirical Analysis of Spam Marketing Conversion." Chris Kanich, Christian Kreibich, Kirill Levchenko, Brandon Enright, Geoffrey M. Voelker, Vern Paxson, and Stefan Savage. Communications of the Association for Computing Machinery 52(9):99-107, September 2009.

Tuesday, March 17

Apple's new anouncement

First off... this is probably the very first Apple announcement in at least four years that I didn't know about in advance. Seriously, the first time I heard about Tuesday's press event was in the NYT article linked below. I feel this is my first step toward becoming a "cranky geek."

In any case, I've finally been thinking more about getting an iPhone, and this new wave of features (and the speculated cheaper new hardware in the summer) is making it ever more attractive.

The oddest thing to me about this report, though, is the description of their new "pay for program enhancements" feature in the App Store. When I read this, my first reaction was to think, "Cool! People can now offer free trial apps and then charge for an upgrade to the full version, like Mac apps have done for years!" However, they've explicitly stated that any app offered originally for free can't have any paid add-ons, so this model won't be available. If developers want to offer trial software, they'll still have to put separate free and paid apps into the Store.

I also hear that they're upgrading the synchronization of personal information from the Internet to the device in the form of direct CalDAV support. Sounds cool; I'm officially considering this seriously now.

Apple Shows Off Next Version of iPhone Software - Bits Blog - NYTimes.com

Friday, February 27

Geek Code update

Well, I haven't updated my Geek Code in about 18 months, so I was due for a refresh. Of course, everything is horribly dated since the code itself was last updated in 1996, but here's where I am today:

-----BEGIN GEEK CODE BLOCK-----
Version: 3.12
GIT/MU d+() s:+>: a->+++ C++> ULXB++++$ L++ M++ w--() !O !V P++ E--- W++ N
o++ K? PS PE+ Y+ PGP- t !5 X- R tv+ b++ DI++ D--- G++ e*++ h--- r+++ y+++?
------END GEEK CODE BLOCK------


(my geek code decoded)

Saturday, February 7

That "25 Random Things" meme

I don't think I've been "tagged" yet to do a "25 Random Things About Me" list on Facebook, but I've seen a number of them. While I think it's an interesting idea, I dread getting into it since it would probably become a big multi-day project that I'd spend endless hours tinkering with and refining, and then agonizing over the finality of hitting the "Post" button.

The following article from the New York Times takes a sardonic look at the whole phenomenon, and until I get around to writing such a list (if I ever do), please consider Amy Harmon's "generic" contribution to be my own.

25 Random Tips for the Busy Facebook User - The Lede Blog - NYTimes.com

Sunday, May 25

xkcd in NYT

Randall Munroe, creator of the oft-linked-here online comic xkcd, was interviewed by Noam Cohen of the New York Times. The resulting article appeared online today (link below).

Link By Link - This Is Funny Only if You Know Unix - NYTimes.com

Monday, February 18

Goodbye to Google Reader

Well, it turns out that my stint with Google Reader only lasted a couple of months this time. I liked the fact that it was integrated with my other Google services, but the whole time it felt like I was making too many compromises... mostly because I couldn't see the actual post times of items and I couldn't see when items were updated.

It seems like Google Reader is a great solution for somebody who skims lots of RSS, but it just won't cut the mustard for somebody like me who follows all the content in a carefully selected list of feeds. Back to Bloglines I go... and the beta version of that service is getting pretty slick by now, too.

βloglines (Beta)

Monday, December 10

Google Reader, again (UPDATED)

It's been a long time since I last tried using Google Reader to keep track of news and blogs. There have been a lot of new features added since then, so I'm going to give it a go once more.

I imported all my feeds in from Bloglines, and the first thing I noticed is that Reader still timestamps items by when it reads them, not by the post time given in the feed. Since Reader only goes out to check your feeds intermittently, you end up with "clumps" of items posted between checks that are all given the same date and time. There's a great post about why this is bad here.

This was one of the reasons it didn't work out for me last time; hopefully it either doesn't bother me this time or the behavior is fixed to work more intelligently. Anyway, here goes...

UPDATE: I've already seen that the behavior has indeed been fixed to work more intelligently. The issue raised in the post I linked to above has been resolved, keeping items in the correct order even when a group is all grabbed at the same time. However, it would still be nice to see items timestamped with the actual <pubDate> from the feed and not Google's "scrape time." The only other issue I had in previous Reader attempts was seeing how it treats feed items that have updated or changed. There doesn't seem to be a per-feed setting for whether to show the item again when there's a new version (there is in Bloglines, which is a feature I really liked), so I'm still not *quite* sure whether Reader will stick with me this time.

Google Reader

P.S. Mihai Parparita, this one's for you.

Thursday, December 6

Here comes another bubble...

Thanks, Ze... this is great!

Friday, November 30

xkcd... still great

This is from Monday, but despite being a few days old it's still pretty awesome. As usual, the punchline is actually in the mouseover text.

Success

xkcd - Success

Thursday, November 22

Finally...

Well, after three and a half years of running this blog I finally bought a real domain name: augmentedfourth.com. I might have bought it two years ago; however, right when I was considering it, somebody called the Augmented Fourth Brass Quintet bought it and put up a static page that never changed through the entire two years of ownership.

My blog isn't actually hosted at my new domain; going there in your browser just redirects you back here. However, I do keep a server there for files and other miscellaneous personal use... for instance, you can download MP3 files of my college composition recital (I know, it's more than four years old and I should probably record something new) at http://augmentedfourth.com/media/why_not.zip. Also, if you download that, make sure to use your MP3 player to look at the "lyrics" I've embedded in the files; while there aren't really lyrics to most of the pieces, you can see my Program Notes from the original performance in there.

My new URL!

Friday, June 29

The Cult of the Amateur, by Andrew Keen

I have to get a copy of this book (unfortunately it's not in the local library, at least not yet):

“What you may not realize is that what is free is actually costing us a fortune,” Mr. Keen writes. “The new winners — Google, YouTube, MySpace, Craigslist, and the hundreds of start-ups hungry for a piece of the Web 2.0 pie — are unlikely to fill the shoes of the industries they are helping to undermine, in terms of products produced, jobs created, revenue generated or benefits conferred. By stealing away our eyeballs, the blogs and wikis are decimating the publishing, music and news-gathering industries that created the original content those Web sites ‘aggregate.’ Our culture is essentially cannibalizing its young, destroying the very sources of the content they crave.”


The Cult of the Amateur - Andrew Keen - Books - Review - New York Times

Wednesday, May 2

A more "population-based" map of the Web

Randall Munroe already did a "topographic" map of Internet locations here, but today's comic (link below) is a map that actually depicts user population for various Web-based communities. I'd say that I live mostly in the IRC isles, with frequent trips to del.icio.us. I view the rest of the Web with a telescope (i.e. RSS feed subscriptions).

xkcd - Online Communities

Creative Commons License
This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 United States License. Permissions beyond the scope of this license may be available by emailing the author (use the link above).




The Geek Code desperately needs updating, but in any case here's mine (as of 2010-02-28):

-----BEGIN GEEK CODE BLOCK-----
Version: 3.12
GIT/MU d+(-) s:+>: a C++> ULXB++++$ L+++ M++ w--() !O !V P+ E---
W+++ N o++ K? PS PE++ Y+ PGP t !5 X- R- tv+@ b++ DI++++ D--- e*++
h--- r+++ y+++ G+
------END GEEK CODE BLOCK------


If you really care about knowing what that all means, you either know the code already, or you can get it decoded for you here.