Nobody Special 's Techdirt Comments

Latest Comments (59) comment rss

  • Feds' Edict To Encrypt Hard Drives Gets — You Guessed It — Ignored

    Nobody Special ( profile ), 18 Jul, 2007 @ 12:49pm

    The point of my 2nd example is that because of the encryption edict, what used to be a half-hour service interruption is now a minimum 1.5 day downtime for a laptop user. Now consider the human-error factor on the technician's part, because not only is he juggling 7-8 calls a day, he has 3-4 laptops on his desk in various states of decryption/encryption.

  • Feds' Edict To Encrypt Hard Drives Gets — You Guessed It — Ignored

    Nobody Special ( profile ), 18 Jul, 2007 @ 12:45pm

    In your first post you implied a custom solution for every laptop/user, or at least that's how I read it. Quadruple costs are more likely in that scenario, not double.

    Your second post actually gets a little closer to reality, but still doesn't make much sense - wouldn't it be easier/cheaper/more reliable to just have one single image? At least in my org (not TSA), we only issue laptops to users that actually have a strong need - not just to anyone who asks. Perhaps if every user had a laptop multiple images would make more sense, but not if every laptop user handles sensitive data by definition.

    Since I deal with drive encryption issues every day, a couple 'simple' real-world examples came to mind that I'd like to share:

    1) email - laptop users are far more likely to use offline email storage in the form of local PST files (Exchange + Outlook). A big problem we see is the bad habit of CC:'ing unnecessary people - like a revised drawing or tech-spec PDF. How do you encrypt live PST files and still have Outlook recognize it? I haven't given it much thought, but my first guess is you can't - unless Outlook.exe and all it's req'd files are also contained on the same encrypted store. Fragmentation, bad sectors, etc, and you've got a nightmare.

    2) the actual drive encryption process - takes a LONG time. The encryption solution we use (and shall remain nameless) can encrypt the volume in the background during normal use, but any hiccup during that week-long process (running in the background during normal use) and the data is toast. So before issuing a laptop to the user, we use the vendor's admin utility to fully encrypt the drive and at 100% utilization it still takes overnight. Decryption is the same but far more costly. Now on even routine service calls the first thing we have to do is manually decrypt the drive in case anything goes wrong during diagnosis or a component needs replacement (the software keys on an UID it generates based on the ID's gathered from the components, so the HD can't just be placed in another PC and brute-forced).

    Again, "encrypting all gov't laptops" sounds peachy, but is a total PITA to implement. Unless of course you have a budget set aside for it and ample test/lab lead-time.

  • Feds' Edict To Encrypt Hard Drives Gets — You Guessed It — Ignored

    Nobody Special ( profile ), 18 Jul, 2007 @ 10:00am

    small clarification

    Something worth noting: when I speak of 'costs', I mean 'support costs'. Again, something easily taken for granted by most readers of this blog who are able to provide their own support.

    In any large org, licensing costs are barely negligible. In any project, labor costs account for 70-80% of the total. In the civilian contractor world, all the costs are factored into the service contract - which in most cases was tallied long before edicts such as this come down.

  • Feds' Edict To Encrypt Hard Drives Gets — You Guessed It — Ignored

    Nobody Special ( profile ), 18 Jul, 2007 @ 09:23am

    SailorRipley

    COE - common operating environment = all of our laptops and PC's are essentially the same eqpt running the same image. You see that in every large organization. If you treat every machine on a case by case basis, you just doubled the cost (and my staff).

    Why do you need a fully encrypted drive? Ask the NIST, not me. I believe "ease of use" is the primary factor (from my point of view at least, I'm sure those 4 levels above me would differ). It's much easier to explain to a user that they now need to log in one extra time when the PC boots than it is to train them to use encrypted stores. Not to mention what data needs to be encrypted and what doesn't. One note- none of our users have personnel data, I'm talking about sensitive/proprietary design data for ships and weapons systems (and not classified data - that has it's own policy universe)

    One thing I think we all take for granted here is user savvy (or the lack of it). If all the users were computer experts, I'd be out of a job. For the majority of my users (3000+ at last count), all they really know is their next deadline and how they'll never meet it if they experience even a small glitch.

    It's

  • Feds' Edict To Encrypt Hard Drives Gets — You Guessed It — Ignored

    Nobody Special ( profile ), 17 Jul, 2007 @ 07:05pm

    not as easy as it sounds

    Those who will say funding is irrelevant have never worked in IT. Cost is only a small problem tho.

    I am a civilian contractor for the Navy, and we've been encrypting our laptops since last summer. They jumped right in with zero thought given to the consequences, and now security is WORSE.

    First, we're talking volume encryption (it's pointless if you can mount the drive in linux and bypass the free crap suggested above), and I've never seen a free solution that easily lets you boot into XP with a fully encrypted HD. The options that do are actually pretty dangerous from my experience. The ATA standard makes allowances for bad sectors, etc, and the encryption breaks that - at least to the point where it would take 2 years for an emergency decryption. Oh yeah, warranties don't cover a HD that died due to a bad sector + encryption... Free?

    Long story short, word has gotten around that if you have even a minor HD problem, your data is gone forever. So now we're fighting users who "back up" their data on unencrypted, personal USB devices. Turns out those things are FAR more easily/likely to be lost and/or stolen.

    It's a joke - however I blame most of the problem on the lack of user education. Zero training is offered on any of this crap.

  • E-Voting Company Agrees To Let California See Its Source Code… But Includes Angry Threats

    Nobody Special ( profile ), 29 Jun, 2007 @ 02:03pm

    Re: Re: Re: Re: Voting Machines

    "market data gathered by these machines would be exceptionally valuable. They could easily determine voting tendancies of specific districts. They could determine how long a person took to vote on a topic or candidate. They could use data to determine effectiveness of campaign efforts."

    Already freely available! Voter registration, and how often you vote are available for 2.5 cents per name at voterlistsonline.com

    If you want to harvest WHOM I voted for, then I suggest you have a good lawyer. Voting Rights section of Civil Rights Bill (among many many others) if I remember correctly.

    "Furthermore, opening the code to the public only adds risk that the system security."

    Again, a fundamental misconception. Security through obscurity is dangerous. Ever hear of peer review? Science mags do it. Imagine a scientist claiming he achieved cold-fusion but couldn't say how because of the security risk to his idea. Wait, that happens and those guys get laughed at...

    "Releasing the source code to the public would have put these vendors out of business"

    How??? These ppl shouldn't be selling the SOFTWARE! The value they bring is in their HARDWARE: nice touchscreens with a tape-roll. Competition should depend on ease-of-use, reliability, ergonomics, life-span, etc. Again, how many different ways can you count 1+1+1+1? Maybe the interfacing with components might be proprietary but if this ia vased on GNU Linux in the first place they ARE BREAKING THE LAW by not sharing the derivative code.

    Of all the arguments for free software, the code THAT COUNTS OUR VOTES should be free and open to ANYONE to inspect. You want to sell the State a fancy box that runs the code, go for it!

  • E-Voting Company Agrees To Let California See Its Source Code… But Includes Angry Threats

    Nobody Special ( profile ), 29 Jun, 2007 @ 01:52pm

    open = secure

    "to point out that just because Linux is an open architecture that does not mean it is secure"

    Linux is secure PRECISELY because it is open. Anyone can audit the code for flaws, and plenty do.

  • E-Voting Company Agrees To Let California See Its Source Code… But Includes Angry Threats

    Nobody Special ( profile ), 29 Jun, 2007 @ 11:37am

    trade secrets?

    "for any prohibited disclosure or use of ES&S' trade secrets and related confidential and proprietary information."

    This has ALWAYS killed me about the election machine fools. What, exactly, is the trade secret they are trying to protect? This isn't rocket science, esentially just a 1+1+1+1+1+1+1=? problem.

    I could understand if this was a highly sophisticated system, but it isn't. For instance, right now I am working on the design of a new 911 integration system that link to displays in patrol cars. This was a HIGHLY competitive contract, and those we beat would love to see how our stuff works. If California wants to look at our code, they'd have to sign all sorts of stuff.

    But this is fundamental code and fundamental to our continued liberty. They are hiding something.

  • How Would You Write A Computer Lemon Law?

    Nobody Special ( profile ), 25 May, 2007 @ 09:26am

    "Lemon" clauses already exist

    I manage large-scale deployments (2000-3000+ PC's, 1000+ printers, etc), and all of this eqpt is under 2-4 year lease. "Lemon" clauses are already in the contracts clearly defining processes for how to handle a piece that constantly break down with no clear cause. They even use the word "lemon".

    When I present scenarios, vendors like to throw probabilities: "what you suggest is a one in a thousand likelihood", etc. But in an environment with 5000 units, you'll see 5???

  • The End Of The Security Industry Not So Unrealistic

    Nobody Special ( profile ), 03 May, 2007 @ 11:16pm

    Not only is it needed, it's the only IT-related field with any job security left.

    The vast majority of 1st-level support remote-admin jobs are already outsourced overseas. That leaves grunt-level break/fix duties for those lucky enough to find them, and even their days are numbered. 5-10 years ago it made perfect sense to pay a technician $30-40/hr to repair/maintain your $2500 computer, but how much sense does it make when today's equivalent only costs $400? How long before that box is in the "disposable" range (sub-$100)? Maybe 3-4 years?

    InfoSec, however, will always remain local. No threat of obsolescence either, at least in the sense that there will always be a demand.

  • High Copper Prices Have Some Shocking Consequences

    Nobody Special ( profile ), 11 Apr, 2007 @ 07:59am

    My story wins!

    I win. Nobody's going to beat this copper-theft story, and it's recent!

    http://www.nola.com/newslogs/tpupdates/index.ssf?/mtlogs/nola_tpupdates/archives/2006_12_14.html#215784

    ...just a teaser paragraph:

    "Addison also said he didn’t get the urns directly from the cemetery. Instead, he told deputies he took them from Delaune, who grabbed them from the cemetery"
    (in other words, he's not a grave-robber. He's just a thief. Grave-robbing would be wrong.)

  • Microsoft's Own X-Prize For Xbox Games

    Nobody Special ( profile ), 05 Mar, 2007 @ 09:46am

    Quack--

    The ppl that would go after this probably aren't after the $10g (tho some will). It's more the feather in the cap. They aren't targeting established devs, but rather the undiscovered 'talent' locked in mom's basement.

    I'm just saying if I had such ambitions, this sounds like a nice way to get noticed. Hell, even 3rd-place in such a competition would look nice on a resume...

  • Microsoft's Own X-Prize For Xbox Games

    Nobody Special ( profile ), 05 Mar, 2007 @ 09:42am

    what's there to lose?

    It'll be fun to watch the anti-MS crowd try to criticize this move. Personally I'm surprised MS did this, but glad they did. Of course the devil is always in the details, so there may be a catch in the XNA license...

    I know very little about XNA, but I thought access to it was closed. At least closed to the point that homebrew sites were afraid to link to tools made with components of XNA... Been a long time tho...

  • Proposal For Creating 911 Websites For Emergency Information, Communication

    Nobody Special ( profile ), 19 Feb, 2007 @ 12:15pm

    In case my original point wasn't clear, the first sentence of the story is ridiculous:

    "Whenever there are disasters, such as earthquakes or hurricanes, many people quickly go online "

    -it should read:

    "Whenever there are disasters, such as earthquakes or hurricanes, many people WHO AREN'T EFFECTED BY THE DISASTER BUT WISH TO BE ENTERTAINED BY IT quickly go online "

  • Proposal For Creating 911 Websites For Emergency Information, Communication

    Nobody Special ( profile ), 19 Feb, 2007 @ 12:04pm

    Since my first post, I've been trying to think of an answer to my own question: what emergency would make this useful?

    I can think of a couple: maybe a biological attack, chemical spill, etc... i.e. an event that doesn't disrupt electricity, but one in which you'd want to stay indoors until you had alot of info.

    Then it occurred to me that we already have such a system in place, and it's already FAR more efficient than anything web-based could ever be: EBS (Emergency Broadcast System). This wonderous EBS is what allowed me to flip on the TV last week at 2:36am and immediately see that I had 6 minutes to run. EBS worked so well that I didn't even realize I had used it until just now...

    Not only that, but in the case of radiation or a biologic, I have a feeling Homeland Security just might be able to put up a quick info page that I'd trust far more than any commercial 911.com site...

  • Proposal For Creating 911 Websites For Emergency Information, Communication

    Nobody Special ( profile ), 19 Feb, 2007 @ 10:28am

    don't get it

    Somebody please give an example of an emergency situation where a web site can help you. Seriously.

    I'm in New Orleans. All the websites in the world wouldn't have helped anyone during Katrina. Who had electricity? ISP? It was almost 4 weeks before my electricity came on, and another week before my cable was restored. Battery-operated radio was all there was, period.

    The tornados last week missed my house by about 50 feet. Amazingly, I never lost electricity in that event. Logging onto a web site was the last thing on my mind at 2:36am when the sirens sounded - flipped on the TV and saw that I had 6 minutes before the first one hit my block.

    What I fear from such an idea is exactly what killed us during the immediate Katrina response: unverified, exaggerated rumors being repeated as fact by the Nat'l Media simply to pump up ratings. That killed people, pure and simple. Citizens were prevented from launching their own boats to rescue people because of the vast (absurd) reports of rescuers being shot at, attacked, etc...

    Here's a suggestion: let's mandate that any such 911 site can have no advertising whatsoever. No profit can be made by anyone from such a site. Then see how many people are left proposing this nonsense.

  • Weather Insurance Market Demonstrates The Importance Of Gambling

    Nobody Special ( profile ), 03 Jan, 2007 @ 01:08pm

    Wrong, Jesus plays bingo!

    Unless you count those worshipping the almighty dollar, current US gambling policy has zippy to do with religion... . What would a US-based church be without the fund-raising raffles, the fund-raising casino nights, the fund-raising bingo, etc... Isn't "speculating on the stock market" the most basic of all wagers? The Religious Right has no tolerance for Wall Street.

    As has been pointed out [over and over and over], the recent regulation that made online gambling "illegal" actually didn't. It restricted how financial institutions (not you or I) can transfer money to-and-from such establishments... Taking a risk for the chance at reward is still perfectly legal. Even online.

    Anyway, US-based gambling-providers make lots of money... F'ing truckload after truckload after truckload of money, and online gambling is a serious threat to that revenue. A real and serious threat (similar to the fate of the Theater owner after we got our big-screen TV's... Not just the mobster-types either - think of all the recent billionaire Tribal Leaders.

    Yeah I ramble, but at least I killed this last hour in the office!

    It's worse. One could argue that the fiscal security of many State economies and a large chunk of the Fed'l Gov't is funded by the truckloads of taxes generated by the domestic casinos (lottery, etc...).

    I'm willing to bet that if an easy/enforceable mechanism existed to tax (a.k.a. "regulate") the online gambling industry, the US Gov't would probably encourage the practice. Hell, I'd rather bet a portion of my Social Security fund on the Superbowl than stock market.

  • Thomas Jefferson's Estate Curators A Bit Behind On Thomas Jefferson's Views On Intellectual Property

    Nobody Special ( profile ), 29 Nov, 2006 @ 08:17am

    Wild guess: Monticello has a no-flash photo policy. The tour guide knew the policy but not it's basis, and mistakenly offered her own speculation...

    Unacceptable!!! You know what this calls for??? Another Techdirt rant against the patent system, that's what! And since there's a natural Jefferson tie-in here, Mike gets to simply imply the absurd notions stated elsewhere on his site that Jefferson was anti-Patent. Although I must admit enjoying myself while arguing this one: http://www.techdirt.com/articles/20060831/144251.shtml

    Really want a headache? Try deciding if Jefferson would approve of Monticello's no-photo policy...

    Irony? http://www.inventors-world.com/pc-172-3-eastman-and-the-box-film-camera-patent.aspx

  • Another Reason For Authors To Fear Google Book Search: It Will Reveal Plenty Of Plagiarists

    Nobody Special ( profile ), 23 Nov, 2006 @ 12:55am

    apologies rockfan

    My post as "mockman" was purely meant to satire plagiarism. In no way was I criticizing you - I simply changed a few of your words while keeping your original thought to demonstrate plagiarism. I'm responsible for posts #6 and #8, so take a look at those before accusing me of being the grammar-Nazi.

    The comedic value depended on my post appearing immediately after yours, so that explains why my edits tapered toward the end (clock was ticking). "Mockfan" simply being a convenient play off your handle + plagiarism.

    Seriously folks, lets get over ourselves already...

  • Another Reason For Authors To Fear Google Book Search: It Will Reveal Plenty Of Plagiarists

    Nobody Special ( profile ), 22 Nov, 2006 @ 06:48am

    ... so who wants to donate to my spell-checker fund? ;)

Next >>