<?xml version="1.0" encoding="UTF-8"?>
<opml version="1.0">
  <head>
    <title>cmdln.net_2007-11-11</title>
    <expansionState>0,1,18,19,26,33,48,49,69,90,109,130,131,138,149,150,158</expansionState>
  </head>
  <body>
    <outline text="Intro" Offset="00:17">
      <outline text="Game review, Arkham Horror">
        <outline text="http://www.fantasyflightgames.com/arkhamhorror.html"/>
        <outline text="Board and card game"/>
        <outline text="Based on the writings of H.P. Lovecraft"/>
        <outline text="http://en.wikipedia.org/wiki/Lovecraft"/>
        <outline text="We've played a few times, enough to be hooked"/>
        <outline text="Until recently, core game was out of print"/>
        <outline text="Managed to land our own and two out of three expansions"/>
        <outline text="Third expansion out of print until next month"/>
        <outline text="A lot of mechanics to absorb up front, best to play with at least on experience player"/>
        <outline text="Best with three or more players, highly cooperative"/>
        <outline text="Once you get basic mechanics, game has a nice rhythm"/>
        <outline text="Game does a good job of building tension, accelerating pace"/>
        <outline text="Trick we picked up is to layout multiple decks on board itself"/>
        <outline text="Not as family friendly"/>
        <outline text="Not overtly adult, but probably best for ten and up as box suggests"/>
        <outline text="Also, complexity of mechanics may be too much for any younger"/>
      </outline>
    </outline>
    <outline text="Security Alerts" Offset="06:14">
      <outline text="Federal commission on cyber-security" Offset="06:33">
        <outline text="http://www.freedom-to-tinker.com/?p=1225"/>
        <outline text="Felten participating in commission, will produce report for next president on topic"/>
        <outline text="First concern is government systems being connected with, secured by standards of private parties"/>
        <outline text="Even in ideal world, the needs are different, a single solution would be unsuitable"/>
        <outline text="Goes on to point out market failures of security products, extends risk into higher sensitivity government systems"/>
        <outline text="Thinks we need to fix security in the market"/>
        <outline text="Three means of doing so">
          <outline text="Exhorting better security"/>
          <outline text="Using purchasing power to influence security development"/>
          <outline text="Invest in human capital, improve security research, practice through training"/>
        </outline>
        <outline text="Encourages that Felten is on this commission"/>
        <outline text="New ideas, to me at least, as opposed to licensing and liability suggestions by others"/>
        <outline text="Liability can have a chilling effect, need positive solutions, as well as potentially negative ones"/>
      </outline>
      <outline text="Botmaster owns up to 250K zombies" Offset="10:14">
        <outline text="http://go.theregister.com/feed/www.theregister.co.uk/2007/11/09/botmaster_to_plea_guilty/"/>
        <outline text="Young security consultant, 26, John Schiefer"/>
        <outline text="Used zombies to eavesdrop on banking transactions"/>
        <outline text="Installed at least 250K zombies"/>
        <outline text="Stole banking identities and committed fraud"/>
        <outline text="Charged with four felony counts"/>
        <outline text="Maximum sentence is 60 years, $1.75mm in fines"/>
        <outline text="First time a botnet related crime is being tried under US wiretap statutes"/>
        <outline text="Sounds like a small band of criminals"/>
        <outline text="Schiefer had a day job, not a professional criminal"/>
        <outline text="Did sell some of the appropriate data to others"/>
        <outline text="Didn't say anything about recovering the zombie systems"/>
        <outline text="Worried these will just get picked up by someone else"/>
        <outline text="Really makes clear the leverage a small group of attackers can apply, though in this case there was some non-typical expertise"/>
      </outline>
    </outline>
    <outline text="News" Offset="13:20">
      <outline text="Microsoft launches Google Gears competitor" Offset="13:34">
        <outline text="http://feeds.downloadsquad.com/~r/weblogsinc/downloadsquad/~3/179806625/"/>
        <outline text="Microsoft Sync Framework"/>
        <outline text="First SilverLight, then this"/>
        <outline text="Hugely un-sexy name"/>
        <outline text="Not just a lightweight database and API, like gears"/>
        <outline text="Also sounds like a .Mac competitor, more broad than just browser applications"/>
        <outline text="This is the first test build, an early access developer version"/>
        <outline text="Really does sound like just a framework, with minimal actual implementation"/>
        <outline text="Appears to be part of Sync Services for ADO.net, Microsoft's key data access technology"/>
        <outline text="No doubt this is just usable enough by .NET developers but otherwise lacking in polish"/>
        <outline text="Demonstrates how Microsoft message for developers, consumers, is often diffuse, not very cohesive"/>
        <outline text="Understandable they do not wish to define it solely as a response to gears, but how is this language about syncing supposed to make sense to the average user?"/>
        <outline text="Microsoft used to have some database synch technology in mid to late nineties"/>
        <outline text="Wonder if it is the same stuff re-tooled and re-packaged"/>
        <outline text="Looks like it will be Windows only, not surprisingly, as opposed to Gears which is more portable"/>
        <outline text="Concerned at how this may legitimize the browser as a platform of choice"/>
        <outline text="Especially muddying connected, disconnected operation, may make security decisions harder"/>
        <outline text="Local storage and additional capabilities introduce more opportunities for vulnerabilities, exploits"/>
        <outline text="Emphasis on any protocol seems at odds with thinking about secure communications"/>
      </outline>
      <outline text="Actually doing something about the lack of Java 6.0 on Leopard" Offset="19:06">
        <outline text="http://www.oreillynet.com/onjava/blog/2007/11/initial_attempts_at_porting_fr.html?CMP=OTC-FP2116136014&amp;ATT=Initial+Attempts+at+Porting+FreeBSD+s+1+6+JDK+to+Mac+OS+X"/>
        <outline text="Leopard does not include the latest stable version of Java, 6.0, or the 1.6 JDK"/>
        <outline text="Java developers who already switched to OS X are particularly incensed"/>
        <outline text="I talked with Apple engineers at WWDC '05 about Java support"/>
        <outline text="Has always lacked server optimized version"/>
        <outline text="Apple folks just didn't see enough outside interest to spur full and active Java support"/>
        <outline text="Wrote about the end of life of the Cocoa-Java bridge over two years ago"/>
        <outline text="http://thecommandline.net/2005/07/14/cocoa-java-end-of-life/"/>
        <outline text="Reportage at this year's WWDC around Leopard shows Apple consolidating on Cocoa, even at expense of legacy toolkit, Carbon"/>
        <outline text="Want to say Sun would have supported, but Apple made such a fuss about Aqua integration and had an early commitment"/>
        <outline text="Landon Fuller has committed other fixes where he thinks Apple has failed"/>
        <outline text="Tried to address lmh's month of Apple bugs last year"/>
        <outline text="Has achieved partial success, detailed at the link, based on FreeBSD patches to Sun JDK sources"/>
        <outline text="Extensive notes, seems like addressing remaining issues may be well doable"/>
        <outline text="May have to settle for X11 for graphics instead of Aqua"/>
        <outline text="For web services, other server development, very acceptable"/>
        <outline text="Question is, how many Java programmers who are complaining are system developers?"/>
        <outline text="If the majority are application developers, may be hard to find qualified contributors to take this further"/>
        <outline text="This may also be much more doable under the auspices of OpenJDK"/>
        <outline text="Know quite a few folks who develop on OS X because it is a nicer desktop and deploy to Linux or a commercial Unix"/>
      </outline>
      <outline text="Lego-like building blocks, running Linux" Offset="25:06">
        <outline text="http://rss.slashdot.org/~r/slashdot/eqWf/~3/180229393/article.pl"/>
        <outline text="Set of connectable modules"/>
        <outline text="Open source and open standards"/>
        <outline text="Linux, Java, OSGi"/>
        <outline text="Seems to be about inter-connecting modules to build ad hoc appliances"/>
        <outline text="Bug Labs is looking to provide base unit and a few add on modules"/>
        <outline text="Soliciting others to contribute additional modules"/>
        <outline text="Fact that there is a base unit would seem to root it as an appliance of sorts"/>
        <outline text="Others describing as Lego-like, suggests more open ended purpose"/>
        <outline text="Doesn't sound that flexible to me"/>
        <outline text="The opportunity here seems more about standardizing embedded, appliance development"/>
        <outline text="Hard to predict if this will work"/>
        <outline text="Most of the interconnects consumers care about for appliances are audio, video and/or network"/>
        <outline text="Will consumers mix-and-match?"/>
        <outline text="Or will that be an OEM function but open to power users?"/>
        <outline text="How far does the standard PC architecture comparison carry?"/>
        <outline text="Board layouts in appliances vary considerably, even if they use Linux, the nature of the firmware can be quite different"/>
        <outline text="Does standardization make sense?  Maybe just for a lower level, device to device interconnect"/>
      </outline>
      <outline text="Hushmail decrypts at Canadian court's order" Offset="29:15">
        <outline text="http://feeds.wired.com/~r/wired/topheadlines/~3/181421176/encrypted-e-mai.html"/>
        <outline text="Service claims are perhaps a bit foolish, that not even their own employees can access your email"/>
        <outline text="Hushmail turned over 12 CDs worth of email in response to Canadian court order"/>
        <outline text="Part of an illegal steroid distribution investigation"/>
        <outline text="This instance limited to simpler, web only offering"/>
        <outline text="Their original offering pushed encryption to client, so provider had no knowledge of keys"/>
        <outline text="This offering still web based but used Java applet to drive encryption locally"/>
        <outline text="Idea is they could not reveal emails even if they wanted to"/>
        <outline text="Newer web offering, option without applet, has a small window where provider can decrypt messages, court order forced them to exploit this"/>
        <outline text="CTO admits that compliance would probably come for traditional email service, too"/>
        <outline text="This could be done by modifying the Java applet sent to the client"/>
        <outline text="With applet, code is always loaded from server"/>
        <outline text="Even though client computer does calculation, instructions always come from server"/>
        <outline text="Further, CTO said it would not protected criminals"/>
        <outline text="Won't roll for any request, but will do so for one through proper channels"/>
        <outline text="Not surprised, they are a business, accountable and liable at the end of the day"/>
        <outline text="If they cannot be held accountable in one instances, raises uncomfortable questions about in other circumstances"/>
        <outline text="Would not be entirely fair to vilify them for this"/>
        <outline text="Must understand limits of trusting a third party for your own security"/>
        <outline text="Even your own, self deployed and run encryption is never going to be perfect, can only ever increase cost of getting your data"/>
      </outline>
    </outline>
    <outline text="tail -f" Offset="33:55">
      <outline text="Response to Heise's critic of Leopard's firewall" Offset="34:14">
        <outline text="http://codm.genhex.org/2007/11/macosx-leopards-firewall-is-no.html"/>
        <outline text="More details"/>
        <outline text="The code signing of included versions of net utils, like nc, may have skewed Heise's findings"/>
        <outline text="Points out that interpreted languages are signed, trusted once"/>
        <outline text="This may allow multiple applications to leverage a single decision"/>
        <outline text="Still boils down to a change in the firewall's UI that makes it a bit harder to control"/>
      </outline>
      <outline text="Problems assessing actual outcome of RadioHead experiment" Offset="36:09">
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/183186801/20071111-radiohead-controversy-shows-limits-of-knowledge-in-an-information-age.html"/>
        <outline text="3rd party, comScore claimed to have numbers of album"/>
        <outline text="Band objected, questioning how they could know"/>
        <outline text="comScore revealed less than impressive sample size, methods"/>
        <outline text="Curious that band did not apparently offer its own numbers"/>
        <outline text="Speculation is that bands objections say numbers are better than comScore reported"/>
        <outline text="Answer remains, will band do it again"/>
        <outline text="Fact that interest remains in the question says it was closer to success than not"/>
        <outline text="This despite criticism of just using free to market physical good"/>
        <outline text="Regardless, got attention, some of it seems sticky"/>
      </outline>
    </outline>
    <outline text="Outro" Offset="38:34">
      <outline text="Contact me">
        <outline text="Email to feedback@thecommandline.net"/>
        <outline text="Web site at http://thecommandline.net/"/>
        <outline text="IM to command.line@skype"/>
        <outline text="Listener comment line is 360-252-7284"/>
        <outline text="del.icio.us tag is &quot;for:cmdln&quot;"/>
        <outline text="http://twitter.com/cmdln"/>
      </outline>
      <outline text="I'd like to thank libsyn.com for AAC hosting and Wouter de Bie for MP3 hosting"/>
      <outline text="These notes and the show audio and music are covered by a Creative Commons license">
        <outline text="http://creativecommons.org/licenses/by-nc-sa/3.0/us/"/>
        <outline text="Attribution, non-commercial, share alike"/>
      </outline>
    </outline>
  </body>
</opml>
