<?xml version="1.0" encoding="UTF-8"?>
<opml version="1.0">
  <head>
    <title>cmdln.net_2008-03-23</title>
    <expansionState>0,1,4,5,21,34,35,41,46,50,60,65,76,94,108,122,123,124,132,138,145,150,160,161,169</expansionState>
  </head>
  <body>
    <outline text="Intro" Offset="00:17">
      <outline text="Out of town end of this week">
        <outline text="No show 3/30"/>
        <outline text="Show as usual, 3/19"/>
      </outline>
    </outline>
    <outline text="Security Alerts" Offset="02:09">
      <outline text="iFrame injection attack" Offset="02:28">
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/253549328/20080318-ongoing-iframe-attack-proving-difficult-to-kill.html"/>
        <outline text="Core attack is an injection against search engines"/>
        <outline text="Adds source for a malicious iframe to cached material sent to engines"/>
        <outline text="This material is served back out on same or similar keyword hits"/>
        <outline text="On security researcher, Dancho Danchev, has been following closely on his blog"/>
        <outline text="Attack originally used to highlight some bogus antivirus software"/>
        <outline text="Also originally only targeted a couple of domains"/>
        <outline text="Has moved on to other domains"/>
        <outline text="Also has evolved to try to download more malware"/>
        <outline text="Can be stopped at the server by simple input validation"/>
        <outline text="Make sure your browser always prompts before opening files"/>
        <outline text="When in doubt, refuse downloads, delete files you don't trust"/>
        <outline text="Launched by a Russian commercial malware outfit, RBN"/>
        <outline text="Many thought RBN had been stopped by filtering its IP addresses"/>
        <outline text="Apparently subdivided and returned"/>
      </outline>
      <outline text="Evading Facebook's new privacy controls" Offset="04:43">
        <outline text="http://www.cnet.com/8301-13739_1-9898098-46.html?part=rss&amp;tag=feed&amp;subj=SurveillanceState"/>
        <outline text="Continuous with their other improvements"/>
        <outline text="Superficially, a good idea"/>
        <outline text="Allows user to exert more fine grained control"/>
        <outline text="Can limit access to profile by types of users"/>
        <outline text="Problem is other users can change their type at will"/>
        <outline text="No verification of user status"/>
        <outline text="So really doesn't improve privacy, any, except against naive attackers"/>
        <outline text="Soghoian also warns this may encourage false sense of security"/>
        <outline text="Facebook cannot really fix this problem short of vetting status"/>
        <outline text="Cost to do so prohibitive for such a simple service"/>
        <outline text="Also, still would not stop determined attacker"/>
      </outline>
    </outline>
    <outline text="News" Offset="06:56">
      <outline text="Investigation of NJ voting irregularities" Offset="07:10">
        <outline text="Union County was to conduct an investigation"/>
        <outline text="After errors in their presidential primary"/>
        <outline text="Clerk Rajoppi asked Felten to help assess Sequoia's machine's security"/>
        <outline text="Sequoia was assessed during the CA audit"/>
        <outline text="It was ES&amp;S that threatened Bowen over possible disclosure"/>
        <outline text="Security researcher preemptively threatened by e-voting vendor">
          <outline text="http://feeds.freedom-to-tinker.com/~r/freedom-to-tinker/~3/253302555/"/>
          <outline text="Felten published the letter he received from a VP at Sequoia"/>
          <outline text="The letter was in response to NJ officials asking Felten to examine a machine"/>
          <outline text="Letter is vague, but threatening"/>
        </outline>
        <outline text="NJ county scared off audit by e-voting vendor">
          <outline text="http://feeds.feedburner.com/~r/boingboing/iBag/~3/254099059/sequoia-voting-syste-1.html"/>
          <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/254928808/20080320-e-voting-blocks-e-voting-security-audit-with-legal-threat.html"/>
          <outline text="Apparently send a more detailed letter to Union County clerk"/>
          <outline text="Same threats as Felten's letter">
            <outline text="License violation"/>
            <outline text="Protection of Sequoia's IP"/>
          </outline>
          <outline text="Threat of suit was apparently more substantial"/>
          <outline text="On the advice of counsel, Rajoppi backed off"/>
          <outline text="She apparently is appealing to the state's AG"/>
          <outline text="Sequoia claims systems already thoroughly tested"/>
          <outline text="Feels government testing less like to risk its IP"/>
          <outline text="One testing lab lost its accreditation last year, however"/>
          <outline text="Ars wonders why the county would acquire machines whose license doesn't allow for independent testing"/>
        </outline>
        <outline text="More details on NJ voting irregularities">
          <outline text="http://feeds.freedom-to-tinker.com/~r/freedom-to-tinker/~3/254316575/"/>
          <outline text="Felten shows direct evidence of errors"/>
          <outline text="Tapes and electronic tally simply do not match"/>
          <outline text="After he posted, acquire more erroneous tapes"/>
        </outline>
        <outline text="Sequoia's response" Offset="3/20/08">
          <outline text="http://feeds.freedom-to-tinker.com/~r/freedom-to-tinker/~3/255064085/"/>
          <outline text="Sequoia has maintained the problem was operator error"/>
          <outline text="By their own explanation, it seems as much an engineering error"/>
          <outline text="Seems odd than an extra button press would cause a flip to opposite ballot rather than an error or a no ballot"/>
          <outline text="Also seems hard to credit that two views would ever be inconsistent except for an error in the code"/>
          <outline text="No reports came in that corroborate Sequoia's explanation"/>
          <outline text="Someone would have noticed"/>
          <outline text="Still, seems more likely an error as an attack would have been harder to detect"/>
          <outline text="Frustrating that vendor doesn't see its own product as flawed"/>
          <outline text="Or even an opportunity to improve, eliminate operator confusion, error"/>
        </outline>
      </outline>
      <outline text="Silicon based, high temperature super conductor" Offset="12:28">
        <outline text="http://www.eetimes.com/rss/showArticle.jhtml?articleID=206904213&amp;cid=RSSfeed_eetimes_newsRSS"/>
        <outline text="New experimental research from join Canadian-German team"/>
        <outline text="Using a silicon, hydrogen compound"/>
        <outline text="Still cooled, but not super cooled"/>
        <outline text="May lead to room temperature superconductors"/>
        <outline text="Based on theoretical work that hydrogen will super conduct if compressed"/>
        <outline text="Material is compressed instead of super cool"/>
        <outline text="Broad applications, mostly where super powerful magnets are needed"/>
        <outline text="Maybe even computing?"/>
        <outline text="Imagine zero resistance transistors, frequency scaling no longer bounded by power or thermal concerns"/>
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/254603363/20080319-room-temperature-superconductors-a-step-closer-with-silane.html"/>
        <outline text="More details"/>
        <outline text="Compound, called silane, combusts in air"/>
        <outline text="Pressures involved are non-trivial but lower than pure hydrogen"/>
        <outline text="Higher temperature superconductivity occurs in critical pressure range"/>
        <outline text="Probably not feasible for too many applications"/>
        <outline text="Still, may point the way to future advances that would bring advantages closer"/>
      </outline>
      <outline text="CBC to experiment with DRM-free BitTorrent" Offset="15:52">
        <outline text="http://www.michaelgeist.ca/content/view/2767/125/"/>
        <outline text="Will be the first North American broadcaster to do so"/>
        <outline text="A new program, Canada Next Great Prime Minister"/>
        <outline text="Cross between reality TV, policy discussion forum"/>
        <outline text="Will release with DRM, via BitTorrent day after broadcast"/>
        <outline text="Geist interprets this as CBC following its mandate"/>
        <outline text="To use most appropriate and efficient means to make programming available"/>
        <outline text="Makes sense for a publicly funded program"/>
        <outline text="CBC has wholly embraced podcasting"/>
        <outline text="Love Quirks and Quarks, Search Engine"/>
        <outline text="Geist also speculates choice of BitTorrent may force discussion of netwrok neutrality"/>
        <outline text="Rogers interfering with P2P traffic may now be seen as interfering with access to information"/>
        <outline text="Seems like a good test case for P4P, if it wasn't still so early days"/>
      </outline>
      <outline text="Teaching a security hacking mind set" Offset="18:36">
        <outline text="http://feeds.wired.com/~r/wired/topheadlines/~3/254686862/click.phdo"/>
        <outline text="Explains security mindset as always consider how things fail"/>
        <outline text="How to attack or misuse something"/>
        <outline text="May be at odds to engineering mindset, how to make things work"/>
        <outline text="While domain expertise, particular skills can be taught"/>
        <outline text="Mindset itself may be innate, may present unique challenges to teaching"/>
        <outline text="Points out a course trying to teach it"/>
        <outline text="Student blog, posts consider security of random things"/>
        <outline text="Thinks this can have benefit beyond IT"/>
        <outline text="Skeptical consumers, citizens more likely to take companies, others to task"/>
        <outline text="Anyone can encourage the mindset, just by being willing to ask the right questions"/>
        <outline text="Goes hand in hand with his other recommendations"/>
        <outline text="If you don't ask security questions, how can you assess the choices you are being asked to make?"/>
      </outline>
    </outline>
    <outline text="tail -f" Offset="20:48">
      <outline text="700MHz spectrum auction conclusion, results" Offset="21:08">
        <outline text="700Mhz spectrum auction winds up">
          <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/253895885/20080318-700mhz-spectrum-auction-wraps-up-tops-19-5-billion.html"/>
          <outline text="Finally tally at 19.5 billion USD"/>
          <outline text="Bidding over the last month was slower, hit 19B in February"/>
          <outline text="C block reserve met, activating open access conditions"/>
          <outline text="D block reserve unmet"/>
          <outline text="This block had emergency services infrastructure built into it"/>
          <outline text="FCC could re-auction with different reserve, structure"/>
        </outline>
        <outline text="Questions about block D of 700MHz spectrum">
          <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/254381549/20080319-questions-about-block-d-linger-in-aftermath-of-auction.html"/>
          <outline text="Promising contender, Frontline, dropped out before the start"/>
          <outline text="May have been because of conditions placed on the block"/>
          <outline text="Public Knowledge showed concerns, asked for investigation"/>
          <outline text="House Subcommittee on Telecommunications and the Internet has promised to look into it in a hearing"/>
        </outline>
        <outline text="Allegations of fraud around 700MHz D block">
          <outline text="http://rss.slashdot.org/~r/slashdot/eqWf/~3/254877274/article.pl"/>
          <outline text="May be due to contractor involved in helping with the auction"/>
          <outline text="Some allegations they spread misinformation that there would be hefty annual fee"/>
          <outline text="D block set up as public-private partnership"/>
          <outline text="Consulting firm representing the public half"/>
          <outline text="Will have to wait until House hearing"/>
        </outline>
        <outline text="Google did not secure any of the 700MHz spectrum">
          <outline text="http://feeds.feedburner.com/~r/GooglePublicPolicyBlog/~3/255174022/end-of-fcc-700-mhz-auction.html"/>
          <outline text="Google congratulated the winners"/>
          <outline text="Focused on the open access"/>
          <outline text="May give some credence they only bid to help meet the reserve"/>
        </outline>
        <outline text="Verizon, AT&amp;T win out in wireless auction">
          <outline text="http://www.eetimes.com/rss/showArticle.jhtml?articleID=206905006&amp;cid=RSSfeed_eetimes_newsRSS"/>
          <outline text="Both will use the new spectrum to supplement existing offerings"/>
          <outline text="No new nationwide, wireless broadband"/>
          <outline text="Some smaller players also secured licenses"/>
          <outline text="Martin things competition was preserved"/>
          <outline text="I rather doubt it"/>
          <outline text="Verzion does seem to be committed to open access, though"/>
          <outline text="Exact conditions of device certification still unclear"/>
          <outline text="Between two of them, accounted for 16B of the bids"/>
        </outline>
      </outline>
    </outline>
    <outline text="Outro" Offset="27:06">
      <outline text="Contact me">
        <outline text="Email to feedback@thecommandline.net"/>
        <outline text="Web site at http://thecommandline.net/"/>
        <outline text="IM to command.line@skype"/>
        <outline text="Listener comment line is 240-949-2638"/>
        <outline text="del.icio.us tag is &quot;for:cmdln&quot;"/>
        <outline text="http://twitter.com/cmdln"/>
      </outline>
      <outline text="I'd like to thank libsyn.com for AAC hosting and Wouter de Bie for MP3 hosting"/>
      <outline text="These notes and the show audio and music are covered by a Creative Commons license">
        <outline text="http://creativecommons.org/licenses/by-nc-sa/3.0/us/"/>
        <outline text="Attribution, non-commercial, share alike"/>
      </outline>
    </outline>
  </body>
</opml>
