<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2659416969867866171</id><updated>2012-01-06T10:31:01.182-08:00</updated><category term='Natural Catastrophe'/><category term='GPU'/><category term='Social Media'/><category term='Tipping Point'/><category term='Course'/><category term='Research'/><category term='Whit Diffie'/><category term='DNS'/><category term='AES'/><category term='Risk Management'/><category term='Fault Injection'/><category term='Probability'/><category term='Spreadsheet'/><category term='Vulnerabilities'/><category term='Windows'/><category term='whitepaper'/><category term='uncertainty'/><category term='scribd'/><category term='RSA'/><category term='Skype'/><category term='One Way Hash Arguments'/><category term='NIST'/><category term='Trends'/><category term='Retrospective'/><category term='Wikileaks'/><category term='Black Swan'/><category term='OWASP'/><category term='web 2.0'/><category term='Brute Force'/><category term='AV'/><category term='Privacy'/><category term='Mind mapping'/><category term='Entropy'/><category term='Factoring'/><category term='Fibonnaci'/><category term='Elliptic Curves'/><category term='Video'/><category term='statistical tests'/><category term='FireFox'/><category term='Zero Knowledge Proof'/><category term='Green IT'/><category term='IBM'/><category term='FreeMind'/><category term='R Programming Language'/><category term='IEEE'/><category term='VeriSign'/><category term='WPA'/><category term='controls'/><category term='roundup'/><category term='Charting'/><category term='CAPTCHA'/><category term='policy'/><category term='Half Life'/><category term='VaR'/><category term='Hashing'/><category term='trojan'/><category term='Border Search'/><category term='Prezi'/><category term='USB'/><category term='Cold Boot'/><category term='Biometric'/><category term='iPhone'/><category term='Threat Modeling'/><category term='FSA'/><category term='A5/1'/><category term='Conficker'/><category term='ssl'/><category term='GPS'/><category term='Bruce'/><category term='Risk Factors'/><category term='Weapons of Math Instruction'/><category term='framework'/><category term='coincidences'/><category term='Data Breach'/><category term='Business Insider'/><category term='Birthday Paradox'/><category term='Turing'/><category term='Excel'/><category term='Gambling'/><category term='Wireless'/><category term='SOX'/><category term='education'/><category term='Encrypted search'/><category term='GSM'/><category term='Wisdom of Crowds'/><category term='Twitter'/><category term='DDoS'/><category term='cryptography'/><category term='Email'/><category term='FUD'/><category term='Statistics'/><category term='NodeXL'/><category term='IT'/><category term='New School of Information Security'/><category term='Project Risk'/><category term='Power Laws'/><category term='Awareness'/><category term='Encryption'/><category term='Buffer Overflow'/><category term='Security'/><category term='Security Management'/><category term='IT Risk'/><category term='Rainbow Tables'/><category term='Redundancy'/><category term='Quantum Computing'/><category term='SUN'/><category term='Interesting'/><category term='Block Cipher'/><category term='Language'/><category term='SDL'/><category term='DES'/><category term='Estimation'/><category term='Certificates'/><category term='Randomness'/><category term='Passwords'/><category term='Koobface'/><category term='Presentation'/><category term='TMTO'/><category term='Spam'/><category term='ISACA'/><category term='ENISA'/><category term='Facebook'/><category term='Whitelisting'/><category term='Data Center'/><category term='CISO'/><category term='Key Lengths'/><category term='renegotiation attack'/><category term='HP'/><category term='NSA'/><category term='Worm'/><category term='cloud computing'/><category term='Visualization'/><category term='Predictions'/><category term='Reputational Damage'/><category term='RC4'/><category term='Social Engineering'/><category term='Online transactions'/><category term='Lottery'/><category term='Data Centric Security'/><category term='games'/><category term='business models'/><category term='YouTube'/><category term='PowerPoint'/><category term='Humour'/><category term='Infographic'/><category term='Key Management'/><category term='re-keying'/><category term='IEP'/><category term='BP'/><category term='ToR'/><category term='Google'/><category term='Scenario Driven Risk Analysis'/><category term='Open Source'/><category term='Blogging'/><category term='Long Tail'/><category term='faraday'/><category term='Random Graph Theory'/><category term='X509'/><category term='ICANN'/><category term='Quantitative'/><category term='phishing'/><category term='Browser'/><category term='Malware'/><category term='DoD'/><category term='Data'/><category term='PKI'/><category term='PageRank'/><category term='SSD'/><category term='microsoft'/><category term='IE'/><category term='RFID'/><category term='Star Wars'/><category term='TLS'/><category term='quantum cryptography'/><category term='iPad'/><category term='Anonymity'/><category term='P2P'/><category term='TED'/><category term='Analysis'/><category term='Metrics'/><category term='Books'/><title type='text'>No Tricks</title><subtitle type='html'>Risk, Security, Math, Crypto</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default?start-index=101&amp;max-results=100'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>286</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3678625254622406153</id><published>2011-10-07T11:57:00.001-07:00</published><updated>2011-10-07T11:58:30.685-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cryptography'/><category scheme='http://www.blogger.com/atom/ns#' term='Books'/><title type='text'>Crypto from Tesco</title><content type='html'>&lt;p align="justify"&gt;You can now &lt;a href="http://www.tesco.com/tescobooks/block-cipher-companion-the/6S5-V3SZ.prd?skuId=6S5-V3SZ&amp;amp;pageLevel=sku&amp;amp;pdpSellerId=1000001&amp;amp;PageName=list&amp;amp;PageType=landing&amp;amp;PLPToPDPFlag=true"&gt;order&lt;/a&gt; the new &lt;a href="http://lukenotricks.blogspot.com/2011/06/block-cipher-bible-coming.html"&gt;Block Cipher Companion&lt;/a&gt; book from Tesco’s, just published this month. I have seen an earlier draft and the text is very detailed and comprehensive, as you would expect from authors of this caliber. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3678625254622406153?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3678625254622406153/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3678625254622406153' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3678625254622406153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3678625254622406153'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/10/crypto-from-tescos.html' title='Crypto from Tesco'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6001619236219462416</id><published>2011-10-04T08:29:00.001-07:00</published><updated>2011-10-04T08:29:26.233-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Email'/><title type='text'>Xobni becomes Smartr</title><content type='html'>&lt;p align="justify"&gt;I recently &lt;a href="http://lukenotricks.blogspot.com/2011/10/150000-reads-of-my-scribd-documents.html"&gt;posted&lt;/a&gt; about the reads on my Scribd collection, and one of the most frequently read is the master’s thesis by the founder of Xobni (inbox spelt backwards) called &lt;a href="http://www.scribd.com/doc/25161724/How-to-Organize-Email"&gt;How to Organize Email&lt;/a&gt;. There is a new version of this software called Smartr for Gmail and you can watch a &lt;a href="http://vimeo.com/29351194"&gt;video&lt;/a&gt; on its features. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6001619236219462416?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6001619236219462416/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6001619236219462416' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6001619236219462416'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6001619236219462416'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/10/xobni-becomes-smartr.html' title='Xobni becomes Smartr'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3411007767255108484</id><published>2011-10-02T15:31:00.001-07:00</published><updated>2011-10-02T15:31:22.540-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Visualization'/><category scheme='http://www.blogger.com/atom/ns#' term='Star Wars'/><title type='text'>Yoda Pie Chart - there is no Try</title><content type='html'>&lt;p&gt;Love it, from &lt;a href="http://flowingdata.com/2011/09/18/yoda-pie-chart/"&gt;Flowing Data&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/-jY5LIE4SFqg/TojmMmwIfpI/AAAAAAAABJE/30O1RgyRQlo/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/-fd6gmP5lYpo/TojmNm6bu0I/AAAAAAAABJI/-1k2SLramNo/image_thumb%25255B1%25255D.png?imgmax=800" width="361" height="278" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3411007767255108484?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3411007767255108484/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3411007767255108484' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3411007767255108484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3411007767255108484'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/10/yoda-pie-chart-there-is-no-try.html' title='Yoda Pie Chart - there is no Try'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/-fd6gmP5lYpo/TojmNm6bu0I/AAAAAAAABJI/-1k2SLramNo/s72-c/image_thumb%25255B1%25255D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-8417296125955643224</id><published>2011-10-02T09:15:00.001-07:00</published><updated>2011-10-02T13:27:40.667-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='scribd'/><title type='text'>150,000 reads of my Scribd documents</title><content type='html'>&lt;p align="justify"&gt;I have uploaded about 200 documents to Scribd over the last few years and the number of reads has just passed 150,000. You can see the categories &lt;a href="http://lukenotricks.blogspot.com/p/scribd-collections.html"&gt;here&lt;/a&gt;. The top 5 documents, each with over 3000 reads each are&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://www.scribd.com/doc/10175233/A-Data-Centric-Security-Model"&gt;A Data Centric Security Model&lt;/a&gt; (almost 6,000 reads)&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/doc/9793125/The-Core-Components-of-the-Entrust-PKI-v5"&gt;The Core Components of the Entrust PKI v5&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/doc/17065431/BA-IT-Security-Awareness-presentation"&gt;BA IT Security Awareness presentation.&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/doc/25161724/How-to-Organize-Email"&gt;How to Organize Email&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/doc/12723043/How-much-is-enough-A-Risk-Management-Approach-to-Computer-Security"&gt;How much is enough? A Risk Management Approach to Computer Security&lt;/a&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-8417296125955643224?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/8417296125955643224/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=8417296125955643224' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8417296125955643224'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8417296125955643224'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/10/150000-reads-of-my-scribd-documents.html' title='150,000 reads of my Scribd documents'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-1587482750599932794</id><published>2011-09-29T16:12:00.001-07:00</published><updated>2011-09-29T16:12:03.219-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Humour'/><title type='text'>The Other Binomial Expansion</title><content type='html'>&lt;p&gt;From this &lt;a href="http://www.scribd.com/doc/13649407/Funny-Exam-Answers"&gt;collection&lt;/a&gt; of creative exam answers. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-yYHVHzOjHc8/ToT7PlGngVI/AAAAAAAABI8/pHZVB6UTfIw/s1600-h/image%25255B4%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/-8lnsgTZsDhs/ToT7QuznijI/AAAAAAAABJA/Vw2M0bIa3pc/image_thumb%25255B2%25255D.png?imgmax=800" width="335" height="317" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-1587482750599932794?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/1587482750599932794/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=1587482750599932794' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1587482750599932794'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1587482750599932794'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/09/other-binomial-expansion.html' title='The Other Binomial Expansion'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/-8lnsgTZsDhs/ToT7QuznijI/AAAAAAAABJA/Vw2M0bIa3pc/s72-c/image_thumb%25255B2%25255D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-993593617708134427</id><published>2011-09-26T15:47:00.001-07:00</published><updated>2011-09-26T15:47:11.664-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><title type='text'>SHA post as SPAM magnet</title><content type='html'>&lt;p align="justify"&gt;Don’t ask me why but a lot of SPAM has accrued, and keeps accruing, at this &lt;a href="http://lukenotricks.blogspot.com/2009/05/cost-of-sha-1-collisions-reduced-to-252.html"&gt;May 2009 post on SHA-1&lt;/a&gt;. Apart from the common penis enlargement references, some of the other SPAM is quite long and seems to be playing on some quirk of SEO. Fine. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-993593617708134427?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/993593617708134427/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=993593617708134427' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/993593617708134427'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/993593617708134427'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/09/sha-post-as-spam-magnet.html' title='SHA post as SPAM magnet'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-5772710424833395152</id><published>2011-09-25T08:49:00.001-07:00</published><updated>2011-09-25T08:49:58.058-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fibonnaci'/><category scheme='http://www.blogger.com/atom/ns#' term='Humour'/><title type='text'>Fibonacci Pigeons</title><content type='html'>&lt;p&gt;This just made me laugh.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-aVIgpY9G6j0/Tn9No8a5leI/AAAAAAAABI0/U7OUd1S7Czo/s1600-h/image%252520%2525287275%252529%25255B4%25255D.jpg"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px; padding-top: 0px" title="image (7275)" border="0" alt="image (7275)" src="http://lh4.ggpht.com/-AoW2u4Rd2Lw/Tn9NpVrjBFI/AAAAAAAABI4/gGiXDwWs23w/image%252520%2525287275%252529_thumb%25255B2%25255D.jpg?imgmax=800" width="377" height="235" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-5772710424833395152?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/5772710424833395152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=5772710424833395152' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5772710424833395152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5772710424833395152'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/09/fibonacci-pigeons.html' title='Fibonacci Pigeons'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/-AoW2u4Rd2Lw/Tn9NpVrjBFI/AAAAAAAABI4/gGiXDwWs23w/s72-c/image%252520%2525287275%252529_thumb%25255B2%25255D.jpg?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-7497521201741765120</id><published>2011-09-22T08:15:00.001-07:00</published><updated>2011-10-02T15:31:55.464-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IEEE'/><category scheme='http://www.blogger.com/atom/ns#' term='cryptography'/><category scheme='http://www.blogger.com/atom/ns#' term='Key Management'/><category scheme='http://www.blogger.com/atom/ns#' term='Presentation'/><category scheme='http://www.blogger.com/atom/ns#' term='Star Wars'/><category scheme='http://www.blogger.com/atom/ns#' term='PowerPoint'/><title type='text'>These aren’t the key management systems you are looking for</title><content type='html'>&lt;p align="justify"&gt;&lt;a href="http://storageconference.org/2010/Presentations/KMS/9.Stieber.pdf"&gt;This&lt;/a&gt; is a nice presentation on enterprise key management issues from Anthony Stieber given at the &lt;a href="http://storageconference.org/2010/Presentations/KMS/Videos-HD.html#2"&gt;2nd IEEE (KMS 2010) Key Management Summit&lt;/a&gt;&lt;font size="2"&gt;&lt;font style="font-weight: normal"&gt;. The main message is that KMS is tricky and don’t roll your own. By the way if you are looking for examples of Powerpoint that breaks all the rules for good presentations, then you will find them here. &lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-t6-mBC9H8Wk/TntRHjiWiWI/AAAAAAAABIk/dIx8eRu2BZg/s1600-h/image%25255B10%25255D.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto; padding-top: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/-4LGt2y-OV5I/TntRIbwBCSI/AAAAAAAABIo/fnfdebHfck8/image_thumb%25255B6%25255D.png?imgmax=800" width="360" height="275" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align="justify"&gt;Also there is a very polished and informative &lt;a href="http://storageconference.org/2010/Presentations/KMS/12.Kostick.pdf"&gt;presentation&lt;/a&gt; from Chris Kostick of E &amp;amp; Y on an enterprise key management maturity model, and below is a comprehensive diagram on the life-cycle management of keys. &lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh4.ggpht.com/-RCv5UpxzXAI/TntUydKzEJI/AAAAAAAABIs/KPcs6WV8IFQ/s1600-h/image%25255B11%25255D.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto; padding-top: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/-s9VCiD0eRxE/TntUy_8w2hI/AAAAAAAABIw/-dCMrc-LjV0/image_thumb%25255B7%25255D.png?imgmax=800" width="383" height="259" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-7497521201741765120?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/7497521201741765120/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=7497521201741765120' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7497521201741765120'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7497521201741765120'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/09/these-arent-key-management-systems-you.html' title='These aren’t the key management systems you are looking for'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/-4LGt2y-OV5I/TntRIbwBCSI/AAAAAAAABIo/fnfdebHfck8/s72-c/image_thumb%25255B6%25255D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-5918153397982770803</id><published>2011-09-22T07:10:00.001-07:00</published><updated>2011-09-22T07:10:16.224-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Risk Management'/><category scheme='http://www.blogger.com/atom/ns#' term='Natural Catastrophe'/><category scheme='http://www.blogger.com/atom/ns#' term='Predictions'/><title type='text'>Liability for Risk Decisions</title><content type='html'>&lt;p align="justify"&gt;&lt;a href="http://lh6.ggpht.com/-jZDC5X4zyGw/TntBxHYG3II/AAAAAAAABIU/8lrRiNRQplM/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px 6px 0px 0px; padding-left: 0px; padding-right: 0px; display: inline; float: left; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" align="left" src="http://lh6.ggpht.com/-G9Qa0uFLj18/TntBx7UvHQI/AAAAAAAABIY/SkoJ3JkBm2A/image_thumb%25255B1%25255D.png?imgmax=800" width="121" height="182" /&gt;&lt;/a&gt;I am currently in-between positions, somewhat happily, and are casting my net of interest a bit wider than my traditional roles in IT Security and Risk. One position that caught my eye from a global reinsurer in town was the role of &lt;a href="http://www.scribd.com/doc/65899032/Job-description-for-an-Earthquake-Analyst"&gt;Earthquake Expert&lt;/a&gt; within their Natural Catastrophe department (or Nat Cat in insurance lingo). I really don’t have any specific background in this area but I sometimes entertain the idea that I can transfer hard-learnt crypto math skills into a numerate role like this one which calls for extensive modeling and prediction. You also think that this might be a nice and cozy niche area to ply your trade as a specialist, holding something of a privileged position. &lt;/p&gt;  &lt;p align="justify"&gt;Well I was disabused of any such notion this week when I &lt;a href="http://www.bbc.co.uk/news/world-europe-14981921"&gt;read&lt;/a&gt; this week of six Italian scientists and a former government official are being put on trial for the alleged manslaughter of the 309 people who died in the 2009 L'Aquila earthquake in Italy.&lt;/p&gt;  &lt;p align="justify"&gt;The seven defendants were members of a government panel, called the Serious Risks Commission (seriously), who were asked to give an opinion (or risk statement) on the likelihood that&amp;#160; L'Aquila would be struck by a major earthquake, based on an analysis of the smaller tremors that the city was experiencing over the previous few months. The panel verdict delivered in March stated that there was &amp;quot;no reason to believe that a series of low-level tremors was a precursor to a larger event&amp;quot;. A week later the city suffered an earthquake of magnitude 6.3 on the &lt;a href="http://en.wikipedia.org/wiki/Richter_magnitude_scale#Richter_magnitudes"&gt;Richter Scale&lt;/a&gt;, denoting a “strong quake”.&lt;/p&gt;  &lt;p align="justify"&gt;The crux of the case against the scientists is that they did not predict the strong quake coming to L'Aquila to allow a proper evacuation of its inhabitants. The defense rebuttal is simply that such a prediction is impossible, and they cannot be held accountable for this unreasonable expectation. The scientists cannot be expected to function as a reliable advanced warning system. The international scientific community has weighed in to support the defendants with &lt;a href="http://www.aaas.org/news/releases/2010/media/0630italy_letter.pdf"&gt;a one-page letter&lt;/a&gt; from the American Association for the Advancement of Science, which supported the scientists by saying that there is no reliable scientific process for earthquake prediction, and they should not be treated as criminals for adhering to the accepted practices of their field.&lt;/p&gt;  &lt;p align="justify"&gt;Recently people were evacuated from New York City as precaution to the impact of &lt;a href="http://en.wikipedia.org/wiki/Hurricane_Irene_%282011%29"&gt;Hurricane Irene&lt;/a&gt;. The hurricane passed by New York causing far less extensive damage than expected, and yet there were still complaints from residents about being asked to leave their homes “unnecessarily”. It seems that authorities cannot win in these matters unless they can predict the future accurately. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-5918153397982770803?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/5918153397982770803/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=5918153397982770803' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5918153397982770803'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5918153397982770803'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/09/liability-for-risk-decisions.html' title='Liability for Risk Decisions'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/-G9Qa0uFLj18/TntBx7UvHQI/AAAAAAAABIY/SkoJ3JkBm2A/s72-c/image_thumb%25255B1%25255D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-1382207485209922240</id><published>2011-09-14T18:38:00.001-07:00</published><updated>2011-09-17T01:51:27.266-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Blogging'/><category scheme='http://www.blogger.com/atom/ns#' term='PageRank'/><title type='text'>PageRank Increment for No Tricks</title><content type='html'>&lt;p align="justify"&gt;&lt;a href="http://lh4.ggpht.com/-dERIhcXOIEU/TnFXGgjgHGI/AAAAAAAABHo/iubjIsbdV6w/s1600-h/image%25255B7%25255D.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; margin: 0px 9px 0px 0px; padding-left: 0px; padding-right: 0px; display: inline; float: left; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" align="left" src="http://lh5.ggpht.com/-BvBHNAox77A/TnFXHFmfBHI/AAAAAAAABHs/pFgQ7dofSoQ/image_thumb%25255B2%25255D.png?imgmax=800" width="108" height="111" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align="justify"&gt;Every now and again I run this blog through the free &lt;a href="http://websitegrader.com/"&gt;Website Grader&lt;/a&gt; tool which measures your site on a variety of criteria, hoping to lure you for a more thorough paid analysis. The tool used to report a PageRank value, and No Tricks seemed to be stuck at 3 for quite a few years. The site now uses there own page ranking metric, which reported a value higher than 3. I was overjoyed and eagerly confirmed that the “true” PageRank metric had also increased from 3 to 4, representing some form of “exponential” improvement since the scale is logarithmic. I can now claim that the No Tricks site has gone from being of “low importance” to being of “medium importance”. Fine, I’ll take it. &lt;/p&gt;  &lt;p align="justify"&gt;Incidentally, I &lt;a href="http://lukenotricks.blogspot.com/2008/10/wisdom-of-random-crowd-of-one.html"&gt;wrote&lt;/a&gt; a short introduction to the mathematics of PageRank a few years back, with a security spin. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-1382207485209922240?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/1382207485209922240/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=1382207485209922240' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1382207485209922240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1382207485209922240'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/09/pagerank-increment.html' title='PageRank Increment for No Tricks'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/-BvBHNAox77A/TnFXHFmfBHI/AAAAAAAABHs/pFgQ7dofSoQ/s72-c/image_thumb%25255B2%25255D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-5363424615206275172</id><published>2011-09-14T07:10:00.001-07:00</published><updated>2011-09-14T15:56:52.703-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Visualization'/><title type='text'>Jesus and spending a trillion dollars</title><content type='html'>&lt;p align="justify"&gt;&lt;a href="https://profiles.google.com/amit.labnol"&gt;Amit Agarwal&lt;/a&gt; at Digital Inspiration has put together some &lt;a href="http://www.labnol.org/internet/visualize-numbers-how-big-is-trillion-dollars/7814/"&gt;information&lt;/a&gt; on just how big the number one trillion actually is, in human-sized terms. We have heard a lot about trillions of dollars in the context of credit crisis and, more recently, in the debate over the US budget deficit. Not to mention that Facebook recently &lt;a href="http://lukenotricks.blogspot.com/2011/09/all-eyes-on-facebook.html"&gt;reported&lt;/a&gt; that their total number of page views has passed the one trillion mark. &lt;/p&gt;  &lt;p align="justify"&gt;Agarwal started by reporting the following Biblical metaphor&lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;If you start spending a million dollars every single day since &lt;a href="http://www.biblequestions.org/Archives/BQAR373.htm"&gt;Jesus was born&lt;/a&gt;, you still wouldn't have spent a trillion dollars by today.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p align="justify"&gt;And in terms of a diagram, Agarwal starts with takes a single 100 dollar US bill, and represents larger values as&lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh5.ggpht.com/-dK9f2qRy0pM/TnC12ZcbUtI/AAAAAAAABHE/u5znn7t-ZdM/s1600-h/image%25255B6%25255D.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/-wlDseL1exs0/TnC12vBSBjI/AAAAAAAABHI/Xt2OvHXV7dY/image_thumb%25255B2%25255D.png?imgmax=800" width="240" height="226" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align="justify"&gt;Extending further, a trillion dollars then requires a football field of space, as shown below, with our human-sized man dwarfed in the bottom left corner. &lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh3.ggpht.com/-Z0GsfsHUC_g/TnC13VupnmI/AAAAAAAABHM/cTTj63xtZfY/s1600-h/image%25255B7%25255D.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/-XPDzkJshQG0/TnC13h0WvXI/AAAAAAAABHQ/6Vd5fRb3LPc/image_thumb%25255B3%25255D.png?imgmax=800" width="240" height="110" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-5363424615206275172?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/5363424615206275172/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=5363424615206275172' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5363424615206275172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5363424615206275172'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/09/jesus-and-spending-trillion-dollars.html' title='Jesus and spending a trillion dollars'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/-wlDseL1exs0/TnC12vBSBjI/AAAAAAAABHI/Xt2OvHXV7dY/s72-c/image_thumb%25255B2%25255D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-7831737185136221767</id><published>2011-09-14T02:20:00.001-07:00</published><updated>2011-09-19T15:16:37.740-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Gambling'/><category scheme='http://www.blogger.com/atom/ns#' term='Randomness'/><category scheme='http://www.blogger.com/atom/ns#' term='Lottery'/><title type='text'>Can you win the lottery too many times?</title><content type='html'>&lt;p align="justify"&gt;Last year I posted on &lt;a href="http://lukenotricks.blogspot.com/2010/03/fabled-25-sigma-event.html"&gt;The Fabled 25 Sigma Event&lt;/a&gt;, referring to a quote from &lt;a href="http://en.wikipedia.org/wiki/David%20Viniar"&gt;David Viniar&lt;/a&gt;, then CFO of &lt;a href="http://www.gs.com/"&gt;Goldman Sachs&lt;/a&gt;, who was attempting to describe the magnitude of the movements in the financial markets. Mr. Viniar probably did not fully understand the implications of what he was saying, since a 25 sigma event translates into a phenomenon occurring once every 10^{135} years - a period of time that we have yet to see even a fraction of. Several researchers at the business school of the &lt;a href="http://maps.google.com/maps?ll=53.3083333333,-6.22222222222&amp;amp;spn=0.01,0.01&amp;amp;q=53.3083333333,-6.22222222222%20%28University%20College%20Dublin%29&amp;amp;t=h"&gt;University College Dublin&lt;/a&gt; gave another interpretation of how unlikely this event was by stating that it equates to winning the UK lottery more than 20 times in a row. &lt;/p&gt;  &lt;p align="justify"&gt;Winning the lottery 20 times does seem very unlikely. Recently a woman won the Texas lottery for the fourth time in the last 10 years or so, accumulating prize money of&amp;#160; just over 20 million USD, and is being scrutinized by the press for potential fraud. There is a lot of suspicion about the luck of Joan Ginther (pictured below) and her winning streak. Googling on “4 time lottery winner” produces pages of articles on Ginther’s supposed luck. &lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh5.ggpht.com/-1jWnEyfQszk/TnCPdHb8K4I/AAAAAAAABGs/Tjvcvccmssg/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto; padding-top: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/-icNvNZraTEw/TnCPeAXd0CI/AAAAAAAABGw/8TlxNf4_a3g/image_thumb%25255B1%25255D.png?imgmax=800" width="244" height="182" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align="justify"&gt;Nathaniel Rich ran an interesting &lt;a href="http://www.scribd.com/doc/60495831/Nathaniel-Rich-The-Luckiest-Woman-on-Earth-Three-Ways-to-Win-the-Lottery"&gt;4-page story&lt;/a&gt; in the August issue of Harper’s magazine, where he visits the small Texas town of Bishop to look at the lone town store where three of the winning tickets were purchased. Rich spoke to enough mathematics professors beforehand to determine that the odds of an individual winning four times by pure luck are extremely low indeed, about 10^{-24}, or a practical impossibility (still “far more likely” than a 25 sigma event though). The alternate scenarios are (1) an inside job potentially amongst the state lotteries and their suppliers (2) cracking the parameters of the psuedo-random number generator for selecting the winners, and (3) dumb luck, or increasing your odds of winning by buying many tickets. The most likely answer seems to be a combination of (2) and (3). &lt;/p&gt;  &lt;p align="justify"&gt;The local town people are going with scenario 3 or just ascribing it to pure luck outright, as there is a strong (American) belief that everyone can be a winner. Getting back to those 25 sigma events, it seems then that no one would actually be able to win the UK lottery over 20 times as they would be suspected of foul play, and likely to find themselves arrested way before that many wins. Perhaps Mr. Viniar should have been arrested for his remarks.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-7831737185136221767?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/7831737185136221767/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=7831737185136221767' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7831737185136221767'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7831737185136221767'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/09/can-you-win-lottery-too-many-times.html' title='Can you win the lottery too many times?'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/-icNvNZraTEw/TnCPeAXd0CI/AAAAAAAABGw/8TlxNf4_a3g/s72-c/image_thumb%25255B1%25255D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-769549328624037232</id><published>2011-09-13T04:48:00.001-07:00</published><updated>2011-09-14T14:49:43.670-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='games'/><category scheme='http://www.blogger.com/atom/ns#' term='business models'/><title type='text'>An unexpected business model for Angry Birds</title><content type='html'>&lt;p align="justify"&gt;Rovio, the company that developed Angry Birds, recently &lt;a href="http://www.businessinsider.com/rovio-is-selling-1-million-angry-birds-t-shirts-and-plush-toys-every-month-2011-9"&gt;announced&lt;/a&gt; at the Techcrunch Disrupt conference that they are now selling more than one million Angry Birds T-shirts and toys each month. That’s after 350 million downloads of the game. What a business model, if they were intending it, and a movie deal is apparently in the works as well. Oh yes, and a theme park. So it seems it is possible to use a mobile game as the basis to leverage the creation of real world profits. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-769549328624037232?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/769549328624037232/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=769549328624037232' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/769549328624037232'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/769549328624037232'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/09/unexpected-business-model-for-angry.html' title='An unexpected business model for Angry Birds'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-9129794762652609741</id><published>2011-09-13T01:09:00.001-07:00</published><updated>2011-09-13T01:24:34.242-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='Visualization'/><title type='text'>All Eyes on Facebook</title><content type='html'>&lt;p align="justify"&gt;A recent social media &lt;a href="http://blog.nielsen.com/nielsenwire/social/"&gt;report&lt;/a&gt; from Nielsen’s shows, amongst other things, that Facebook dominates our attention on the Internet, larger in terms of minutes of face time than the four next most popular social media sites. Business Insider produced the following &lt;a href="http://www.businessinsider.com/chart-of-the-day-facebook-time-2011-9"&gt;chart&lt;/a&gt; based on Nielsen’s data&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh5.ggpht.com/-sSj1QEi2P20/Tm8PoElBVOI/AAAAAAAABGc/-p9wmfc76MU/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh4.ggpht.com/-f9bVzNSsaK8/Tm8Polf2KWI/AAAAAAAABGg/D7ce-eVtu_s/image_thumb%25255B1%25255D.png?imgmax=800" width="343" height="264" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align="justify"&gt;It was &lt;a href="http://venturebeat.com/2011/08/24/facebook-trillion-pageviews/"&gt;recently&lt;/a&gt; (and widely) reported that the number of page views on Facebook passed the 1 trillion mark, but that figure has been &lt;a href="http://www.pcmag.com/article2/0,2817,2391959,00.asp"&gt;disputed&lt;/a&gt;. In any case, all internet path seems to lead to Facebook one way or the other. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-9129794762652609741?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/9129794762652609741/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=9129794762652609741' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/9129794762652609741'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/9129794762652609741'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/09/all-eyes-on-facebook.html' title='All Eyes on Facebook'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/-f9bVzNSsaK8/Tm8Polf2KWI/AAAAAAAABGg/D7ce-eVtu_s/s72-c/image_thumb%25255B1%25255D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-2003998609172681898</id><published>2011-09-11T04:47:00.001-07:00</published><updated>2011-09-11T04:47:06.948-07:00</updated><title type='text'>A short touching remark on 9/11</title><content type='html'>&lt;p align="justify"&gt;I am stepping out more of late, meeting new people and doing new things, which has seen more doing far less blogging over the last year. One of the site I use to find things to do is &lt;a href="http://www.meetup.com/"&gt;Meetup&lt;/a&gt; in the Zurich locality. I received the following email from the founder today who relates how the origin of the service was 9/11, and his intention was to “use the internet to get people off the internet”,&lt;/p&gt;  &lt;p&gt;Fellow Meetuppers,   &lt;br /&gt;I don't write to our whole community often, but this week is    &lt;br /&gt;special because it's the 10th anniversary of 9/11 and many    &lt;br /&gt;people don't know that Meetup is a 9/11 baby.    &lt;br /&gt;Let me tell you the Meetup story. I was living a couple miles    &lt;br /&gt;from the Twin Towers, and I was the kind of person who thought    &lt;br /&gt;local community doesn't matter much if we've got the internet    &lt;br /&gt;and tv. The only time I thought about my neighbors was when I    &lt;br /&gt;hoped they wouldn't bother me.&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;When the towers fell, I found myself talking to more neighbors    &lt;br /&gt;in the days after 9/11 than ever before. People said hello to    &lt;br /&gt;neighbors (next-door and across the city) who they'd normally    &lt;br /&gt;ignore. People were looking after each other, helping each    &lt;br /&gt;other, and meeting up with each other. You know, being    &lt;br /&gt;neighborly.&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;A lot of people were thinking that maybe 9/11 could bring    &lt;br /&gt;people together in a lasting way. So the idea for Meetup was    &lt;br /&gt;born: Could we use the internet to get off the internet -- and    &lt;br /&gt;grow local communities?&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;We didn't know if it would work. Most people thought it was a    &lt;br /&gt;crazy idea -- especially because terrorism is designed to make    &lt;br /&gt;people distrust one another.    &lt;br /&gt;A small team came together, and we launched Meetup 9 months    &lt;br /&gt;after 9/11.&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;Today, almost 10 years and 10 million Meetuppers later, it's    &lt;br /&gt;working. Every day, thousands of Meetups happen. Moms Meetups,    &lt;br /&gt;Small Business Meetups, Fitness Meetups... a wild variety of    &lt;br /&gt;100,000 Meetup Groups with not much in common -- except one    &lt;br /&gt;thing.&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;Every Meetup starts with people simply saying hello to    &lt;br /&gt;neighbors. And what often happens next is still amazing to me.    &lt;br /&gt;They grow businesses and bands together, they teach and    &lt;br /&gt;motivate each other, they babysit each other's kids and find    &lt;br /&gt;other ways to work together. They have fun and find solace    &lt;br /&gt;together. They make friends and form powerful community. It's    &lt;br /&gt;powerful stuff.&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;It's a wonderful revolution in local community, and it's thanks    &lt;br /&gt;to everyone who shows up.    &lt;br /&gt;Meetups aren't about 9/11, but they may not be happening if it    &lt;br /&gt;weren't for 9/11.&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;9/11 didn't make us too scared to go outside or talk to    &lt;br /&gt;strangers. 9/11 didn't rip us apart. No, we're building new    &lt;br /&gt;community together!!!!&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;The towers fell, but we rise up. And we're just getting started    &lt;br /&gt;with these Meetups.&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;Scott Heiferman (on behalf of 80 people at Meetup HQ)    &lt;br /&gt;Co-Founder &amp;amp; CEO, Meetup    &lt;br /&gt;New York City    &lt;br /&gt;September 2011&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-2003998609172681898?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/2003998609172681898/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=2003998609172681898' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2003998609172681898'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2003998609172681898'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/09/short-touching-remark-on-911.html' title='A short touching remark on 9/11'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-8541229765217288842</id><published>2011-09-10T13:30:00.001-07:00</published><updated>2011-09-19T15:14:03.836-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Power Laws'/><category scheme='http://www.blogger.com/atom/ns#' term='Half Life'/><category scheme='http://www.blogger.com/atom/ns#' term='Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='Data'/><title type='text'>The “Half-life” of a bitly link is about 3 hours</title><content type='html'>&lt;p align="justify"&gt;&lt;a href="http://www.hilarymason.com/"&gt;Hilary Mason&lt;/a&gt;, Chief Scientist at &lt;a href="http://bit.ly"&gt;bit.ly&lt;/a&gt;, a large link shortening service, has done an analysis on some of their link data to get an idea of how long links remain “alive” or “popular”. The measure was to look at 1,000 links and graph the number of hits that a link receives over 80,000 seconds (almost a day), and then determine the point over that period where half of the total number of hits were received. From the &lt;a href="http://blog.bitly.com/post/9887686919/you-just-shared-a-link-how-long-will-people-pay"&gt;post&lt;/a&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;So we looked at the half life of 1,000 popular &lt;a href="http://bit.ly/"&gt;bitly&lt;/a&gt; links and the results were surprisingly similar. The mean half life of a link on twitter is 2.8 hours, on facebook it’s 3.2 hours and via ‘direct’ sources (like email or IM clients) it’s 3.4 hours. So you can expect, on average, an extra 24 minutes of attention if you post on facebook than if you post on twitter.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p align="justify"&gt;Running the data yielded the following graph, showing a strong power law for Facebook, Twitter and direct links (links shared via email, and instant messengers), but a delayed curve for YouTube.&lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh3.ggpht.com/-toBevkv6AyQ/TmvI-kaVagI/AAAAAAAABGM/gcxtXPTznM4/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/--FPauS4ayxM/TmvI_F_hKAI/AAAAAAAABGQ/WCjCJ4YELFM/image_thumb%25255B1%25255D.png?imgmax=800" width="396" height="234" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align="justify"&gt;What Mason computed would more accurately be called the &lt;a href="http://en.wikipedia.org/wiki/Median"&gt;median&lt;/a&gt; rather than the &lt;a href="http://en.wikipedia.org/wiki/Half_life"&gt;half-life&lt;/a&gt;, since she is interested in the first point in time that divides the total number of hits for the period into two roughly equal sets. More discussion on this point is given in the comments to the post. The conclusion from the post&lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;In general, &lt;strong&gt;the half life of a bitly link is about 3 hours&lt;/strong&gt;, unless you publish your links on youtube, where you can expect about 7 hours worth of attention. Many links last a lot less than 2 hours; other more sticky links last longer than 11 hours over all the referrers. This leads us to believe that the lifespan of your link is connected more to what content it points to than on where you post it: on the social web it’s all about what you share, not where you share it!&lt;/p&gt; &lt;/blockquote&gt;  &lt;p align="justify"&gt;A while back I &lt;a href="http://lukenotricks.blogspot.com/2009/05/half-life-of-vulnerabilities-is-still.html"&gt;posted&lt;/a&gt; on the half-life of patching vulnerabilities being 30 days and there we probably have confusion with the sample median as well. I also noted the attrition for my own links in &lt;a href="http://lukenotricks.blogspot.com/2010/05/shark-fin-posts.html"&gt;Shark Fin posts&lt;/a&gt;. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-8541229765217288842?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/8541229765217288842/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=8541229765217288842' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8541229765217288842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8541229765217288842'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/09/half-life-calculation-for-internet.html' title='The “Half-life” of a bitly link is about 3 hours'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/--FPauS4ayxM/TmvI_F_hKAI/AAAAAAAABGQ/WCjCJ4YELFM/s72-c/image_thumb%25255B1%25255D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-595362622850161118</id><published>2011-09-09T10:10:00.001-07:00</published><updated>2011-09-11T02:41:32.388-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Randomness'/><category scheme='http://www.blogger.com/atom/ns#' term='Statistics'/><title type='text'>Two victories for Randomness</title><content type='html'>&lt;p align="justify"&gt;I recently came across two smallish examples of where randomness was the solution to two perplexing problems. That is, rolling the dice seems to help you out of a situation where a planned method was not giving you what you wanted. &lt;/p&gt;  &lt;p align="justify"&gt;The first issue is the problem of how to board passengers on a plane. Finding the best way to board people is actually a well-studied problem, both theoretically and in practice, and you can see some of the work &lt;a href="http://leeds-faculty.colorado.edu/vandenbr/projects/boarding/boarding.htm#section4"&gt;here&lt;/a&gt;. At the &lt;a href="http://leeds-faculty.colorado.edu/vandenbr/projects/boarding/boarding.htm#section1"&gt;top&lt;/a&gt; of the same page there is a nice simulation program which shows you how different boarding strategies play out, and random boarding (just calling out people to board at random) is better than the usual front-to-back boarding that most of us are familiar with. &lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh6.ggpht.com/-axbzytovK0Y/TmpIim8FC_I/AAAAAAAABGE/8qcoALpha-U/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/--24kxjCpxJI/TmpIjqJIc7I/AAAAAAAABGI/R0nE4n_8sQM/image_thumb%25255B1%25255D.png?imgmax=800" width="209" height="157" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align="justify"&gt;The reason is that random boarding gives a better utilization of the space in the plane whereas front-to-back boarding piles people into one part of the plane, eventually causing jams in the aisles. The full set of strategies examined are&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Back-to-front &lt;/li&gt;    &lt;li&gt;Rotating-zone &lt;/li&gt;    &lt;li&gt;Random &lt;/li&gt;    &lt;li&gt;Block &lt;/li&gt;    &lt;li&gt;Outisde-in &lt;/li&gt;    &lt;li&gt;Reverse-pyramid &lt;/li&gt; &lt;/ul&gt;  &lt;p align="justify"&gt;On another topic, a Freakonomics blog &lt;a href="http://www.freakonomics.com/2011/08/10/how-rolling-dice-helps-save-leopards/"&gt;post&lt;/a&gt; describes how researchers in South Africa are using a randomness trick to get truthful answers from farmers who are suspected of illegally killing leopards and hyenas. The method is called &lt;a href="http://en.wikipedia.org/wiki/Randomized_response"&gt;randomized response&lt;/a&gt; surveying, where when the farmers are asked potentially incriminating questions they first flip a coin, and based on the result give a yes or no answer to either the incriminating question if it was heads, or a harmless question (do you think the Springboks will win the RWC?) if it was tails. The farmers actually used a die, taking specific actions on which value from 1 to 6 was thrown, but the principle is the same as I have described it. &lt;/p&gt;  &lt;p align="justify"&gt;The trick here is that the person asking the question cannot tell which question the farmer is answering, but the farmer’s answer can be recorded. Statistical methods can then be used to determine the distribution of answers for the two questions, and actually make inferences about the proportion of positive answers to the incriminating question. This method was devised in the 60’s, and by the early 80’s it was being taught at my undergraduate university as part of a first year course. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-595362622850161118?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/595362622850161118/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=595362622850161118' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/595362622850161118'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/595362622850161118'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/09/two-victories-for-randomness.html' title='Two victories for Randomness'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/--24kxjCpxJI/TmpIjqJIc7I/AAAAAAAABGI/R0nE4n_8sQM/s72-c/image_thumb%25255B1%25255D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-4053150632522497574</id><published>2011-08-07T14:36:00.001-07:00</published><updated>2011-08-07T16:08:01.900-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Green IT'/><category scheme='http://www.blogger.com/atom/ns#' term='Data Center'/><title type='text'>Green IT Swiss Data Center presentation</title><content type='html'>&lt;p align="justify"&gt;&lt;a href="http://www.green.ch/LinkClick.aspx?fileticket=jAU9RTXh16A%3d&amp;amp;tabid=224&amp;amp;mid=1713"&gt;Here&lt;/a&gt; is a short presentation on a relatively new data center in the west of Zurich that is designed to be green and secure.&amp;#160; More information at &lt;a href="http://www.green.ch/deCH/Privatkunden.aspx"&gt;green.ch&lt;/a&gt;, and the language can be changed to English in the upper right corner. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-4053150632522497574?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/4053150632522497574/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=4053150632522497574' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4053150632522497574'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4053150632522497574'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/08/green-it-swiss-data-center-presentation.html' title='Green IT Swiss Data Center presentation'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3835206837670992865</id><published>2011-08-07T13:11:00.001-07:00</published><updated>2011-08-07T13:11:05.984-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='education'/><category scheme='http://www.blogger.com/atom/ns#' term='Analysis'/><title type='text'>US Grade Inflation Study</title><content type='html'>&lt;p align="justify"&gt;A recent &lt;a href="http://www.gradeinflation.com/tcr2010grading.pdf"&gt;study&lt;/a&gt; has examined the prevalence of grade inflation at US universities over the last 100 years or so, and has found some identifiable patterns. The chart below shows the increase in grades between various types of schools in the primary colors, with the grey representing (unnamed individual schools).&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/-zGL_MCDc02A/Tj7xUyiJCHI/AAAAAAAABFk/Toj2DVUPiNU/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/-rG5HkfDeh58/Tj7xWVldGVI/AAAAAAAABFo/BCgSjx3OT9Q/image_thumb%25255B1%25255D.png?imgmax=800" width="382" height="234" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align="justify"&gt;What is clear is that there was a huge increase in grade in crease in the 60’s and then a steady increase over&amp;#160; the last 30 years of so. From the study&lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;The rise in grades in the 1960s correlates with the social upheavals of the Vietnam War. It was followed by a decade     &lt;br /&gt;period of static to falling grades. The cause of the renewal of grade inflation, which began in the 1980s and has yet to      &lt;br /&gt;end, is subject to debate, but it is difficult to ascribe this rise in grades to increases in student achievement. Students’ entrance test scores have not increased (College Board, 2007), students are increasingly disengaged from their studies (Saenz et al., 2007), and the literacy of graduates has declined (Kutner et al., 2006). A likely influence is the emergence of the now common practice of requiring student-based evaluations of college teachers. Whatever the cause, colleges and universities are on average grading easier than ever before.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p align="justify"&gt;Further science and engineering students are graded more harshly than their fellow students in liberal arts degrees. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3835206837670992865?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3835206837670992865/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3835206837670992865' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3835206837670992865'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3835206837670992865'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/08/us-grade-inflation-study.html' title='US Grade Inflation Study'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/-rG5HkfDeh58/Tj7xWVldGVI/AAAAAAAABFo/BCgSjx3OT9Q/s72-c/image_thumb%25255B1%25255D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3906329172780477828</id><published>2011-08-07T12:49:00.001-07:00</published><updated>2011-08-07T12:51:31.397-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tipping Point'/><category scheme='http://www.blogger.com/atom/ns#' term='Random Graph Theory'/><title type='text'>A 10% Tipping Point Threshold</title><content type='html'>&lt;p align="justify"&gt;Scientists at Rensselaer Polytechnic Institute have recently &lt;a href="http://pre.aps.org/abstract/PRE/v84/i1/e011130"&gt;published&lt;/a&gt; research into social networks which indicates&amp;#160; that when just 10 percent of a network steadfastly holds a given belief, then that belief will eventually be adopted by the majority of the society. These group of 10% “believers” are referred to as a committed minority. &lt;/p&gt;  &lt;p align="justify"&gt;Even though the research has produced quite a bit of press (see &lt;a href="http://www.sciencedaily.com/releases/2011/07/110725190044.htm"&gt;here&lt;/a&gt; and &lt;a href="http://www.sciencedaily.com/releases/2011/07/110725190044.htm"&gt;here&lt;/a&gt; for example) it is a little difficult to say how the result was arrived at. The abstract of the paper states that&lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;We show how the prevailing majority opinion in a population can be rapidly reversed by a small fraction p of randomly distributed committed agents who consistently proselytize the opposing opinion and are immune to influence. Specifically, we show that when the committed fraction grows beyond a critical value p&lt;sub&gt;c&lt;/sub&gt;≈10%, there is a dramatic decrease in the time T&lt;sub&gt;c&lt;/sub&gt; taken for the entire population to adopt the committed opinion. In particular, for complete graphs we show that when p&amp;lt;p&lt;sub&gt;c&lt;/sub&gt;, T&lt;sub&gt;c&lt;/sub&gt;~exp[α(p)N], whereas for p&amp;gt;p&lt;sub&gt;c&lt;/sub&gt;, T&lt;sub&gt;c&lt;/sub&gt;~lnN. We conclude with simulation results for Erdős-Rényi random graphs and scale-free networks which show qualitatively similar behavior.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p align="justify"&gt;It seems that they are using a model for the spread of opinion overlayed on various network topologies, starting with the complete graph (everyone knows everyone), then scale free, and a simulation of a &lt;a href="http://en.wikipedia.org/wiki/Random_graphs"&gt;random graph&lt;/a&gt; process. The results are strengthened by finding the 10% threshold present in each topology. Even so, the following graph was not that informative for me.&lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh3.ggpht.com/-unI-KNAOLek/Tj7sRxwdvQI/AAAAAAAABFc/HWI6MvxbgWE/s1600-h/image%25255B4%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh4.ggpht.com/-DE8d8NIGwhk/Tj7sSh17faI/AAAAAAAABFg/0-22er7IWPY/image_thumb%25255B2%25255D.png?imgmax=800" width="389" height="268" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;I think I will have to wait get a copy of the paper to make full sense of the result. Reported in &lt;a href="http://www.freakonomics.com/2011/07/28/minority-rules-why-10-percent-is-all-you-need/"&gt;Freakanomics&lt;/a&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3906329172780477828?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3906329172780477828/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3906329172780477828' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3906329172780477828'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3906329172780477828'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/08/10-tipping-point-threshold.html' title='A 10% Tipping Point Threshold'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/-DE8d8NIGwhk/Tj7sSh17faI/AAAAAAAABFg/0-22er7IWPY/s72-c/image_thumb%25255B2%25255D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3577139302060607629</id><published>2011-08-05T16:06:00.001-07:00</published><updated>2011-08-05T16:06:36.056-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='iPhone'/><title type='text'>iPhone Passcode Bias</title><content type='html'>&lt;p&gt;An informal &lt;a href="http://amitay.us/blog/files/most_common_iphone_passcodes.php"&gt;study&lt;/a&gt; from collecting just over 204,000 iPhone passcodes, produced the graphic below on the top ten most common passcodes&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-ZmSaasIUwUU/Tjx3eKjPYFI/AAAAAAAABFU/Y1kwW-Wkaik/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh4.ggpht.com/-mn3ApMfHvDk/Tjx3eixVdYI/AAAAAAAABFY/KOtdqH4rRAE/image_thumb%25255B1%25255D.png?imgmax=800" width="379" height="301" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The author concludes that&lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;Formulaic passwords are never a good idea, yet &lt;strong&gt;15% of all passcode sets were represented by only 10 different passcodes&lt;/strong&gt; (out of a possible 10,000). The implication? A thief (or just a prankster) could safely try 10 different passcodes on your iPhone without initiating the data wipe. With a 15% success rate, about 1 in 7 iPhones would easily unlock--even more if the intruder knows the users’ years of birth, relationship status, etc.&lt;/p&gt;&lt;/blockquote&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3577139302060607629?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3577139302060607629/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3577139302060607629' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3577139302060607629'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3577139302060607629'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/08/iphone-passcode-bias.html' title='iPhone Passcode Bias'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/-mn3ApMfHvDk/Tjx3eixVdYI/AAAAAAAABFY/KOtdqH4rRAE/s72-c/image_thumb%25255B1%25255D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-628512984231882561</id><published>2011-08-05T15:42:00.001-07:00</published><updated>2011-08-05T15:42:37.901-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Visualization'/><category scheme='http://www.blogger.com/atom/ns#' term='Data'/><title type='text'>DIPK Graphic</title><content type='html'>&lt;p&gt;From &lt;a href="http://flowingdata.com/2011/07/28/open-thread-data-as-cake-and-frosting/"&gt;Flowing Data&lt;/a&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Mark Johnstone &lt;a href="http://epicgraphic.com/data-cake/"&gt;uses a cake metaphor&lt;/a&gt; to represent data, presentation, and what you gain.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Don’t like the last shot for knowledge. Perhaps lots of smaller cakes?&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-ulsNtc7iIks/TjxxzhIr0mI/AAAAAAAABFM/ZcoTMoTgY60/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh4.ggpht.com/-eejRCgBnvCw/Tjxx2keJ-PI/AAAAAAAABFQ/yWS9WSTFQwc/image_thumb%25255B1%25255D.png?imgmax=800" width="396" height="381" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-628512984231882561?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/628512984231882561/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=628512984231882561' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/628512984231882561'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/628512984231882561'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/08/dipk-graphic.html' title='DIPK Graphic'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/-eejRCgBnvCw/Tjxx2keJ-PI/AAAAAAAABFQ/yWS9WSTFQwc/s72-c/image_thumb%25255B1%25255D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3332273766697316249</id><published>2011-06-06T09:26:00.001-07:00</published><updated>2011-06-06T15:54:41.710-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Block Cipher'/><category scheme='http://www.blogger.com/atom/ns#' term='Books'/><title type='text'>Block Cipher Bible coming</title><content type='html'>&lt;p align="justify"&gt;There is a &lt;a href="http://www.amazon.com/Cipher-Companion-Information-Security-Cryptography/dp/3642173411/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1307377114&amp;amp;sr=1-1"&gt;new&lt;/a&gt; and authoritative block cipher book soon to be published, by my good friend &lt;a href="http://www2.mat.dtu.dk/people/Lars.R.Knudsen/"&gt;Lars Knudsen&lt;/a&gt; and my respected colleague &lt;a href="http://crypto.rd.francetelecom.com/people/robshaw/"&gt;Matt Robshaw&lt;/a&gt;. These are two of the top experts in the field – both veterans of the AES selection process and long time contributors to understanding why and what makes a good - or simply not a bad - block cipher. The book will be available this year and you can pre-order from Amazon right now. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-dVn_ENL170w/Tez_vgTtIEI/AAAAAAAABB0/2L0MXFhkYzQ/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto; padding-top: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/-2tS2PUVKyH8/Tez_wNll4NI/AAAAAAAABB4/bRMMAGM_OMY/image_thumb%25255B1%25255D.png?imgmax=800" width="240" height="240" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3332273766697316249?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3332273766697316249/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3332273766697316249' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3332273766697316249'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3332273766697316249'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/06/block-cipher-bible-coming.html' title='Block Cipher Bible coming'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/-2tS2PUVKyH8/Tez_wNll4NI/AAAAAAAABB4/bRMMAGM_OMY/s72-c/image_thumb%25255B1%25255D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6161383875774044440</id><published>2011-06-06T06:14:00.001-07:00</published><updated>2011-06-06T06:15:08.454-07:00</updated><title type='text'>A Loch Ness Month</title><content type='html'>&lt;p align="justify"&gt;The graph below from Google Analytics shows the reading “humps” of my blog with unusual clarity. Typically readership tapers off on the weekend and picks up as the work week commences. You can see the peaks and valleys for the weekends quite clearly below, and it reminded my of those famous &lt;a href="http://en.wikipedia.org/wiki/Loch_Ness_Monster"&gt;Loch Ness humps&lt;/a&gt;. Thanks to the 2000+ visitors in May, even when I am struggling to find the time for meaningful posts.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh5.ggpht.com/-MDqivux-31U/TezSm8dReII/AAAAAAAABBs/B_mrlJbvDMA/s1600-h/image%25255B4%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh4.ggpht.com/-Q15tAVUjwcw/TezSnVH6TNI/AAAAAAAABBw/a6zMzJeqOJM/image_thumb%25255B2%25255D.png?imgmax=800" width="411" height="104" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6161383875774044440?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6161383875774044440/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6161383875774044440' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6161383875774044440'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6161383875774044440'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/06/loch-ness-month.html' title='A Loch Ness Month'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/-Q15tAVUjwcw/TezSnVH6TNI/AAAAAAAABBw/a6zMzJeqOJM/s72-c/image_thumb%25255B2%25255D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-8508582728319062377</id><published>2011-05-02T08:40:00.001-07:00</published><updated>2011-05-02T08:41:13.975-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Risk Management'/><category scheme='http://www.blogger.com/atom/ns#' term='ISACA'/><title type='text'>ISACA Risk Assessment Guidelines</title><content type='html'>&lt;p align="justify"&gt;I uploaded a &lt;a href="http://www.scribd.com/doc/54162137/ISACA-Audit-IT-Risk-Assessment-guidelines"&gt;15 page guideline&lt;/a&gt; from ISACA for audit risk assessments to my &lt;a href="http://www.scribd.com/my_document_collections"&gt;Scribd collections&lt;/a&gt;. The document gives a reasonable overview of how a standard IT audit assessment can be enhanced from a risk perspective, taking into account additional factors beyond controls and their gaps. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-8508582728319062377?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/8508582728319062377/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=8508582728319062377' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8508582728319062377'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8508582728319062377'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/05/isaca-risk-assessment-guidelines.html' title='ISACA Risk Assessment Guidelines'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3294776077724305591</id><published>2011-04-14T23:54:00.001-07:00</published><updated>2011-04-14T23:54:31.256-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Blogging'/><title type='text'>No Tricks recently passed 50,000 visitors</title><content type='html'>&lt;p align="justify"&gt;Just a short note to say that the number of visitors to the No Tricks blog recently passed the 50,000 mark, which was very satisfying for me. The blog has been running since September 2008, starting out with just a few posts but then building open slowly to around 250 now. You can see the monthly increase in visitors below, and some other statistics from Google Analytics. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Wom5eMghH20/TafrpeQGb2I/AAAAAAAABBA/MN5ErFQ_6PY/s1600-h/image%5B3%5D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/_Wom5eMghH20/Tafrpti3njI/AAAAAAAABBE/pBRV8HqN1L8/image_thumb%5B1%5D.png?imgmax=800" width="408" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3294776077724305591?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3294776077724305591/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3294776077724305591' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3294776077724305591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3294776077724305591'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/04/no-tricks-recently-passed-50000.html' title='No Tricks recently passed 50,000 visitors'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_Wom5eMghH20/Tafrpti3njI/AAAAAAAABBE/pBRV8HqN1L8/s72-c/image_thumb%5B1%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-4179108556416066947</id><published>2011-04-05T05:45:00.001-07:00</published><updated>2011-04-05T13:19:34.995-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Power Laws'/><category scheme='http://www.blogger.com/atom/ns#' term='Twitter'/><title type='text'>How many users does Twitter have?</title><content type='html'>&lt;p align="justify"&gt;A nice power law looking graph from &lt;a href="http://e.businessinsider.com/view/2wk1.81q/f46bd4f2"&gt;Business Insider&lt;/a&gt; on the properties of Twitter users, and about 175 million Twitter accounts have been registered to date. But how many of those accounts are actually active and being used? Hard to say it seems. The article reports on digging into the Twitter API and finding that &lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;Using data that is now just one month old, he found out that… &lt;/p&gt;    &lt;ul&gt;     &lt;li&gt;       &lt;div align="justify"&gt;There were 119 million Twitter accounts following one or more other accounts.&lt;/div&gt;     &lt;/li&gt;      &lt;li&gt;       &lt;div align="justify"&gt;There were 85 million accounts with one ore more followers.&lt;/div&gt;     &lt;/li&gt;   &lt;/ul&gt;    &lt;p align="justify"&gt;With these figures, and Twitter's claim of 175 million accounts, a little subtraction shows us that there are 56 million Twitter accounts following zero other accounts, and 90 million Twitter accounts with zero followers.&lt;/p&gt;&lt;p align="justify"&gt;&lt;br /&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Wom5eMghH20/TZsPAA_KRlI/AAAAAAAABA4/GVXBDkhjQD8/s1600-h/image%5B4%5D.png"&gt;&lt;img style="background-image: none; border: 0px none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px;" title="image" alt="image" src="http://lh5.ggpht.com/_Wom5eMghH20/TZsPAlIXBaI/AAAAAAAABA8/QX_f6hnVrfo/image_thumb%5B2%5D.png?imgmax=800" border="0" height="307" width="396" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-4179108556416066947?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/4179108556416066947/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=4179108556416066947' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4179108556416066947'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4179108556416066947'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/04/how-many-users-does-twitter-have.html' title='How many users does Twitter have?'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_Wom5eMghH20/TZsPAlIXBaI/AAAAAAAABA8/QX_f6hnVrfo/s72-c/image_thumb%5B2%5D.png?imgmax=800' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-153793822315713651</id><published>2011-03-26T06:01:00.001-07:00</published><updated>2011-03-26T06:01:44.998-07:00</updated><title type='text'>Freehaven papers on Anonymity</title><content type='html'>&lt;p align="justify"&gt;I have not looked at the Freehaven &lt;a href="http://freehaven.net/anonbib/date.html"&gt;site&lt;/a&gt; for some time, but just a reminder that there is a huge collection of research papers sourced, tracing the history of anonymity systems, MIXES and other PETs. The collection was well-attended to up till the end of last year but is missing updates for 2011 so far. I am sure that they will come. BibTeX references for the papers as well.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-153793822315713651?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/153793822315713651/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=153793822315713651' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/153793822315713651'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/153793822315713651'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/03/freehaven-papers-on-anonymity.html' title='Freehaven papers on Anonymity'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-9140370127909083559</id><published>2011-03-26T05:33:00.001-07:00</published><updated>2011-03-26T05:42:55.508-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud computing'/><title type='text'>Trust and security in the cloud</title><content type='html'>&lt;p align="justify"&gt;The Register has &lt;a href="http://whitepapers.theregister.co.uk/paper/view/1950/reg-research-trust-and-security-in-the-cloud.pdf"&gt;published&lt;/a&gt; a new 16-page whitepaper on trust and security in cloud computing, with the key findings being&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;     &lt;div align="justify"&gt;Many companies could do much better when it comes to in-house security&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;SaaS adoption is limited currently, but there is increasing interest from the business&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;The biggest impediment to SaaS adoption is a perception of security issues&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;Companies with experience of SaaS are positive about provider security&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;SaaS is likely to help with shortcomings of on-premise security capabilities&lt;/div&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;p align="justify"&gt;The whitepaper was written from data gathered in an online survey with over 500 participants. Amongst the many tabulated responses to the survey there is an interesting list of the ways data can exit from corporate boundaries. &lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh4.ggpht.com/_Wom5eMghH20/TY3fSwiPeKI/AAAAAAAABAY/ecCPXCE5k2o/s1600-h/image%5B3%5D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/_Wom5eMghH20/TY3fTthriwI/AAAAAAAABAc/vSmC3Hox7rw/image_thumb%5B1%5D.png?imgmax=800" width="402" height="256" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-9140370127909083559?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/9140370127909083559/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=9140370127909083559' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/9140370127909083559'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/9140370127909083559'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/03/trust-and-security-in-cloud.html' title='Trust and security in the cloud'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_Wom5eMghH20/TY3fTthriwI/AAAAAAAABAc/vSmC3Hox7rw/s72-c/image_thumb%5B1%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-8789240792458289223</id><published>2011-03-12T05:45:00.001-08:00</published><updated>2011-03-12T05:45:53.509-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iPad'/><category scheme='http://www.blogger.com/atom/ns#' term='Visualization'/><title type='text'>iPad Competition is Toast</title><content type='html'>&lt;p align="justify"&gt;Business Insider recently &lt;a href="http://e.businessinsider.com/view/2emo.gkb/32937784"&gt;reported&lt;/a&gt; that the iPad is outselling the competition about 4-to-1. So as security professionals the iPad is the platform to focus on for risk assessments.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh5.ggpht.com/_Wom5eMghH20/TXt5DjJHu6I/AAAAAAAAA_8/axUTw7Lowno/s1600-h/image%5B3%5D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/_Wom5eMghH20/TXt5EKs29aI/AAAAAAAABAA/m6J_4U55PLA/image_thumb%5B1%5D.png?imgmax=800" width="412" height="324" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-8789240792458289223?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/8789240792458289223/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=8789240792458289223' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8789240792458289223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8789240792458289223'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/03/ipad-competition-is-toast.html' title='iPad Competition is Toast'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_Wom5eMghH20/TXt5EKs29aI/AAAAAAAABAA/m6J_4U55PLA/s72-c/image_thumb%5B1%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6665376482751549569</id><published>2011-03-12T05:37:00.001-08:00</published><updated>2011-03-12T16:51:20.887-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Redundancy'/><category scheme='http://www.blogger.com/atom/ns#' term='Language'/><title type='text'>An example of redundancy in English</title><content type='html'>&lt;div align="justify"&gt;After I apologized too often for my bad typing, my sister-in-law sent me the following text to demonstrate that our brain can understand words even if only the first and last letters are correct&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Yet aoccdrnig to a sudty at Cmabrigde Uinervtisy, it deosn’t mttaer in waht oredr the ltteers in a wrod are, the olny iprmoetnt tihng is taht the frist and lsat ltteer be at the rghit pclae. The rset can be a ttoal mses and you can sitll raed it wouthit a porbelm. Tihs is bcuseae the huamn mnid deos not raed ervey lteter by istlef, but the wrod as a wlohe.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;Apparently this text is well-known to language people!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6665376482751549569?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6665376482751549569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6665376482751549569' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6665376482751549569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6665376482751549569'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/03/example-of-redundancy-in-english.html' title='An example of redundancy in English'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-2255291000421073341</id><published>2011-01-29T14:49:00.001-08:00</published><updated>2011-01-29T14:58:41.668-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Interesting'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><title type='text'>24 minutes with Bill Gates on career choices</title><content type='html'>&lt;p align="justify"&gt;In April last year Bill Gates &lt;a href="http://alumni.harvard.edu/stories/gates-giving-getting-sharing"&gt;addressed&lt;/a&gt; a collection of students at Harvard for 24 minutes on the topic of where to devote your talents. It is well-known that Gates dropped out of Harvard in the mid 70’s to develop his fledgling software company. He was returning as a philanthropist on this occasion, armed with the following question “Are the brightest minds working on the most important problems?”. And clearly he does not think so, as it appears many of top minds in the US are going into sports, entertainment or finance. In fact, “The allocation of IQ to Wall Street is higher than it should be.” You can find the video of the talk &lt;a href="http://alumni.harvard.edu/stories/gates-giving-getting-sharing"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-2255291000421073341?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/2255291000421073341/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=2255291000421073341' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2255291000421073341'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2255291000421073341'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2011/01/24-minutes-with-bill-gates-on-career.html' title='24 minutes with Bill Gates on career choices'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-7336432724748552564</id><published>2010-12-23T07:59:00.000-08:00</published><updated>2010-12-23T14:45:50.450-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Risk Management'/><category scheme='http://www.blogger.com/atom/ns#' term='education'/><category scheme='http://www.blogger.com/atom/ns#' term='TED'/><title type='text'>Calculus vs. Probability</title><content type='html'>&lt;p align="justify"&gt;I am trying out listening to podcasts on my – yes – iPod, during what was figuratively described to me as my “downtime”.  In Zurich for me this means being on trams and trains, and walking between them or to them. So I went looking for captivating podcasts and of course ended up at the &lt;a href="http://www.ted.com/"&gt;TED&lt;/a&gt; site, where you can download any number of interesting speakers and topics. I came across a short and poignant &lt;a href="http://www.ted.com/talks/lang/eng/arthur_benjamin_s_formula_for_changing_math_education.html"&gt;talk&lt;/a&gt; by mathematician Arthur Benjamin's on his formula for changing math education. &lt;/p&gt;  &lt;p style="text-align: center;"&gt;&lt;a href="http://lh4.ggpht.com/_Wom5eMghH20/TRPQl385crI/AAAAAAAAA-s/8wH6XpbPphc/s1600-h/image%5B4%5D.png"&gt;&lt;img style="background-image: none; border: 0px none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px;" title="image" alt="image" src="http://lh5.ggpht.com/_Wom5eMghH20/TRPQmshv2wI/AAAAAAAAA-w/cZNfNjQxkzA/image_thumb%5B2%5D.png?imgmax=800" border="0" height="157" width="244" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align="justify"&gt;His simple approach is to switch from calculus being the pinnacle of math education to actually probability and statistics, because while the former is beautiful yet little used, the latter two topics are in fact very practical and in high demand. In short we need to better understand risk. Below is the full text of his short talk, where I have highlighted a few phrases in bold&lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;Now, if President Obama invited me to be the next Czar of Mathematics, then I would have a suggestion&lt;/p&gt;    &lt;p align="justify"&gt;The mathematics curriculum that we have is based on foundation of arithmetic and algebra. And everything we learn after that is building up towards one subject. And at top of that pyramid, it's calculus. And I'm here to say that I think that that is the wrong summit of the pyramid ... that &lt;strong&gt;the correct summit&lt;/strong&gt; -- that all of our students, every high school graduate should know -- &lt;strong&gt;should be statistics: probability and statistics&lt;/strong&gt;. (Applause)&lt;/p&gt;    &lt;p align="justify"&gt;I mean, don't get me wrong. Calculus is an important subject. It's one of the great products of the human mind. The laws of nature are written in the language of calculus. And every student who studies math, science, engineering, economics, they should definitely learn calculus by the end of their freshman year of college. But I'm here to say, as a professor of mathematics, that very few people actually use calculus in a conscious, meaningful way, in their day to day lives. &lt;strong&gt;On the other hand, statistics -- that's a subject that you could, and should, use on daily basis. Right? It's risk. It's reward. It's randomness. It's understanding data.&lt;/strong&gt;&lt;/p&gt;    &lt;p align="justify"&gt;I think if our students, if our high school students -- if all of the American citizens -- knew about probability and statistics, we wouldn't be in the economic mess that we're in today. Not only -- thank you -- not only that ... [but] if it's taught properly, it can be a lot of fun. &lt;strong&gt;I mean, probability and statistics, it's the mathematics of games and gambling. It's analyzing trends. It's predicting the future. Look, the world has changed from analog to digital.&lt;/strong&gt; And it's time for our mathematics curriculum to change from analog to digital. From the more classical, continuous mathematics, to the more modern, discrete mathematics.&lt;strong&gt; The mathematics of uncertainty, of randomness, of data&lt;/strong&gt; -- and that being probability and statistics.&lt;/p&gt;    &lt;p align="justify"&gt;In summary, instead of our students learning about the techniques of calculus, I think it would be far more significant if all of them knew what two standard deviations from the mean means. And I mean it. Thank you very much. (Applause)    &lt;br /&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p align="justify"&gt;I could not agree more. The world is discrete for me, and very few of the problems that I encounter succumb to integration.    &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-7336432724748552564?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/7336432724748552564/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=7336432724748552564' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7336432724748552564'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7336432724748552564'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/12/calculus-vs-probability.html' title='Calculus vs. Probability'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_Wom5eMghH20/TRPQmshv2wI/AAAAAAAAA-w/cZNfNjQxkzA/s72-c/image_thumb%5B2%5D.png?imgmax=800' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-2242462018431117368</id><published>2010-12-23T07:38:00.000-08:00</published><updated>2010-12-23T07:50:50.406-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Data Breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Wikileaks'/><title type='text'>Protecting Your Information in the Age of WikiLeaks</title><content type='html'>&lt;div style="text-align: justify;"&gt;This is the title of a webcast invitation that I recently received from Symantec. The Wikileaks saga is quickly impacting the infosec landscape, probably because the issue is so visible to all levels of senior management. The webcast is described as follows&lt;br /&gt;&lt;/div&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;&lt;/span&gt;&lt;blockquote  style="font-family:georgia;"&gt;&lt;span style="font-size:100%;"&gt;In the wake of the intense media attention around the WikiLeaks disclosures, you may be asking yourself, "What steps can I take to help my company avoid this same fate?"&lt;br /&gt;&lt;br /&gt;Symantec has been working with customers who are concerned about preventing these same issues and we’ve developed a set of best practices that can help defend against these types of breaches. We’d like to share with you some of the techniques that might be useful to help you uncover similar activity on your own systems. In this live webcast we’ll: &lt;/span&gt; &lt;ul&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Discuss the threat agents and modes of data loss you should be most concerned about&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Recommend counter-measures to protect your critical information against these risks&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:100%;"&gt;To learn more about how your organisation may be at risk and steps you can take to defend your information, &lt;a href="https://symantecevents.verite.com/theageofwikileaks"&gt;register today&lt;/a&gt;. &lt;/span&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-2242462018431117368?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/2242462018431117368/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=2242462018431117368' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2242462018431117368'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2242462018431117368'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/12/protecting-your-information-in-age-of.html' title='Protecting Your Information in the Age of WikiLeaks'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3005541941285444039</id><published>2010-12-23T07:22:00.000-08:00</published><updated>2010-12-23T07:35:56.033-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Trends'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Predictions'/><title type='text'>2011 InfoSec Predictions from Zscaler Labs</title><content type='html'>Its not only the season of giving and but forecasting as well, and I recently received the following Information Security Predictions from Zscaler Labs&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b style="color: rgb(0, 0, 0);"&gt;Flash mob hacktivism&lt;/b&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;  – we’ll see more attacks similar to Operation Payback, where  like-minded strangers quickly organize and attack corporations or  government entities in the name of a cause&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;Niche malware&lt;/b&gt; designed to harvest confidential information from IP-connected devices such as printers and SCADA systems will grow&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;Cloud-hosted botnets&lt;/b&gt; will grow&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We’ll hear about more &lt;b&gt;indirect data breaches&lt;/b&gt;, where not it’s the company affected that was breached, but rather a third-party vendor or organization&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;Social networks&lt;/b&gt; will become the main communication medium for attackers&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;The&lt;b&gt; Information security market&lt;/b&gt; will continue to shrink&lt;/li&gt;&lt;/ul&gt;An interesting list - more about trends than fundamentals - and you can find more details on the &lt;a href="http://research.zscaler.com/2010/12/2011-security-predictions.html"&gt;Zscaler blog&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:hyphenationzone&gt;21&lt;/w:HyphenationZone&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if !mso]&gt;&lt;object classid="clsid:38481807-CA0E-42D2-BF39-B33AF135CC4D" id="ieooui"&gt;&lt;/object&gt; &lt;style&gt; st1\:*{behavior:url(#ieooui) } &lt;/style&gt; &lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-parent:"";  mso-padding-alt:0cm 5.4pt 0cm 5.4pt;  mso-para-margin:0cm;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman";} &lt;/style&gt; &lt;![endif]--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3005541941285444039?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3005541941285444039/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3005541941285444039' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3005541941285444039'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3005541941285444039'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/12/2011-information-security-predictions.html' title='2011 InfoSec Predictions from Zscaler Labs'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6727279329454705982</id><published>2010-12-23T07:01:00.000-08:00</published><updated>2010-12-23T07:18:58.503-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Blogging'/><category scheme='http://www.blogger.com/atom/ns#' term='AES'/><title type='text'>Over 1,000 visits this month to old AES-256 post</title><content type='html'>&lt;div style="text-align: justify;"&gt;Just a note to say that my &lt;a href="http://lukenotricks.blogspot.com/2008/07/are-aes-256-bit-keys-too-large.html"&gt;Are AES 256-bit keys too large?&lt;/a&gt; post from July 2008 has been visited over 1,000 times this month. For the last few years it has been my most popular post by far, and I once referred to it as one of my &lt;a href="http://lukenotricks.blogspot.com/2008/12/on-bottom-of-things-reflections-on-year.html"&gt;Pareto posts&lt;/a&gt;. Probably what happened this month is a link to the post found its way onto some social channel, like Twitter, and just mushroomed from there. It just shows that content really has no use-by date in Web 2.0.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6727279329454705982?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6727279329454705982/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6727279329454705982' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6727279329454705982'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6727279329454705982'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/12/over-1000-visits-this-month-to-aes-256.html' title='Over 1,000 visits this month to old AES-256 post'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6306917073088750258</id><published>2010-12-14T08:48:00.000-08:00</published><updated>2010-12-14T23:28:24.769-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Buffer Overflow'/><title type='text'>Tutorial on Buffer Overflows</title><content type='html'>&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Nice&lt;/span&gt; &lt;a href="http://www.infsec.ethz.ch/people/schapatr/BOtutorial.pdf"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;tutorial&lt;/span&gt;&lt;/a&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;on&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;this&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;perennial&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;security&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;problem&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;from&lt;/span&gt; &lt;a href="http://www.infsec.ethz.ch/people/schapatr"&gt;Patrick &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;Schaller&lt;/span&gt;&lt;/a&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;of&lt;/span&gt; ETH, Zurich.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6306917073088750258?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6306917073088750258/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6306917073088750258' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6306917073088750258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6306917073088750258'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/12/tutorial-on-buffer-overflows.html' title='Tutorial on Buffer Overflows'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3273421654485774976</id><published>2010-12-07T11:47:00.001-08:00</published><updated>2010-12-07T11:47:18.678-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Visualization'/><category scheme='http://www.blogger.com/atom/ns#' term='Privacy'/><title type='text'>Internet Privacy as a Venn diagram</title><content type='html'>&lt;p&gt;From &lt;a href="http://flowingdata.com/2010/10/22/privacy-and-the-internet/"&gt;Flowing Data&lt;/a&gt;:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Wom5eMghH20/TP6PQ9AZOaI/AAAAAAAAA-c/VJAUPcZPRug/s1600-h/image%5B8%5D.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/_Wom5eMghH20/TP6PRQxd1tI/AAAAAAAAA-g/X7wmJP_AVeo/image_thumb%5B6%5D.png?imgmax=800" width="260" height="182" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3273421654485774976?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3273421654485774976/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3273421654485774976' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3273421654485774976'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3273421654485774976'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/12/internet-privacy-as-venn-diagram.html' title='Internet Privacy as a Venn diagram'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_Wom5eMghH20/TP6PRQxd1tI/AAAAAAAAA-g/X7wmJP_AVeo/s72-c/image_thumb%5B6%5D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-2869206738377712384</id><published>2010-12-06T13:34:00.001-08:00</published><updated>2010-12-07T12:41:09.020-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Risk Management'/><title type='text'>Snakes in Suits – the risks from psychopaths in the workplace</title><content type='html'>&lt;p align="justify"&gt;A telling &lt;a href="http://www.scribd.com/doc/44756645/Snakes-in-Suits"&gt;presentation&lt;/a&gt; from Holly Andrews at a recent IRM meeting on dealing with psychopaths in the workplace (and yes the boardroom), derived from the 2006 book &lt;a href="http://en.wikipedia.org/wiki/Snakes_in_Suits"&gt;Snakes in Suits: When Psychopaths Go to Work&lt;/a&gt;. The presentation describes how workplace psychopaths burrow into positions of power, and amongst other things, assume more risk than is sensible. There is a wonderful process chart which shows how such people operate&lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh6.ggpht.com/_Wom5eMghH20/TP1W40EV-iI/AAAAAAAAA-M/e9UBaS1P7G8/s1600-h/image%5B4%5D.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/_Wom5eMghH20/TP1W5yYiqWI/AAAAAAAAA-Q/1GkrF766Lxk/image_thumb%5B2%5D.png?imgmax=800" width="400" height="240" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align="justify"&gt;Transitional organisations can be seen as ideal “feeding grounds” for psychopaths since   &lt;br /&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;There are fewer constraints and rules allow the psychopath freedom in acting out their psychopathic manipulation&lt;/li&gt; &lt;/ul&gt;  &lt;ul&gt;   &lt;li&gt;The fast changing environment provides stimulation for the psychopath whilst serving to cover up their failings&lt;/li&gt; &lt;/ul&gt;  &lt;ul&gt;   &lt;li&gt;There is the potential for large rewards in terms or money, power, status and control     &lt;br /&gt;      &lt;br /&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh6.ggpht.com/_Wom5eMghH20/TP1W40EV-iI/AAAAAAAAA-M/e9UBaS1P7G8/s1600-h/image%5B4%5D.png"&gt;     &lt;br /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-2869206738377712384?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/2869206738377712384/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=2869206738377712384' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2869206738377712384'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2869206738377712384'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/12/snakes-in-suits-dealing-with.html' title='Snakes in Suits – the risks from psychopaths in the workplace'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_Wom5eMghH20/TP1W5yYiqWI/AAAAAAAAA-Q/1GkrF766Lxk/s72-c/image_thumb%5B2%5D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3231136558725263314</id><published>2010-10-28T08:48:00.001-07:00</published><updated>2010-10-28T08:48:30.535-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='scribd'/><title type='text'>Just over 100,000 reads of my Scribd documents</title><content type='html'>&lt;p align="justify"&gt;Just a note to say that the total number of read of my documents on Scribd just passed 100,000! The categories are given below,&amp;#160; mostly PDFs and a few PowerPoint presentations.&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://www.scribd.com/my_document_collections/2324532"&gt;Cryptography&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/my_document_collections/2324648"&gt;Data Breach&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/my_document_collections/2310118"&gt;General Risk&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/my_document_collections/2310117"&gt;IT Risk&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/my_document_collections/2313894"&gt;Malware&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/my_document_collections/2310119"&gt;Passwords&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/my_document_collections/2310521"&gt;Privacy and Anonymity&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/my_document_collections/2321342"&gt;Quant Reasoning&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/my_document_collections/2310116"&gt;Security&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/my_document_collections/2312593"&gt;Whitelisting&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.scribd.com/my_document_collections/2310087"&gt;Written By Me&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;div class="zemanta-related"&gt;&lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3231136558725263314?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3231136558725263314/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3231136558725263314' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3231136558725263314'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3231136558725263314'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/10/just-over-100000-reads-of-my-scribd.html' title='Just over 100,000 reads of my Scribd documents'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-4051065884713375782</id><published>2010-09-14T15:35:00.001-07:00</published><updated>2010-09-14T17:36:00.731-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='web 2.0'/><category scheme='http://www.blogger.com/atom/ns#' term='New School of Information Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Reputational Damage'/><category scheme='http://www.blogger.com/atom/ns#' term='BP'/><category scheme='http://www.blogger.com/atom/ns#' term='Black Swan'/><category scheme='http://www.blogger.com/atom/ns#' term='PageRank'/><title type='text'>BP and Trial by PageRank</title><content type='html'>&lt;p align="justify"&gt;Over at the NSIS, Alex has a &lt;a href="http://newschoolsecurity.com/2010/09/the-lumbering-ogre-of-enterprise-governance-is-no-replacement-for-real-quality-management/"&gt;post&lt;/a&gt; (downgraded to a rant?) which begins with berating &lt;a href="http://www.gideonrasmussen.com/article-22.html"&gt;Gideon Rasmussen&lt;/a&gt; for calling the BP Deepwater incident a Black Swan, and ends up discussing flaws in corporate governance. Alex correctly describes the incident as a “tail event”, both low probability and high impact but still “on the curve”. True Black Swans are events for which prior distributions are “completely uninformative”, and they belong on a totally different curve to expectations and models. &lt;/p&gt;  &lt;p align="justify"&gt;Even so, for me a Black Swan aspect of the incident has been the subsequent reputational damage to BP. This has not been a trial by public media, but trial by social media and ultimately, trial by PageRank. In web 2.0 there is no such thing as yesterday’s news, or yesterday’s newspapers wrapping up today’s fish and chips. Links are just as good today as they were yesterday, and continue to remain search-worthy far into the future as long as PageRank deems them to be so. Holding steady at approximately two thirds of the search market, Google via PageRank has become the default arbiter of Internet truth.&amp;#160; &lt;/p&gt;  &lt;p align="justify"&gt;A recent article called &lt;a href="http://adage.com/digital/article?article_id=145720"&gt;What Big Brands are spending on Google&lt;/a&gt; from Advertising Age showed that BP’s spending on Google Ads increased dramatically, to almost $3.6 million dollars in June, up from its regular budget of less than $60,000.&amp;#160; &lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh5.ggpht.com/_Wom5eMghH20/TI_4kVNsNCI/AAAAAAAAA98/Tk99R7u8cUQ/s1600-h/image%5B4%5D.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/_Wom5eMghH20/TI_4lAkWUsI/AAAAAAAAA-A/qySekRWKLKY/image_thumb%5B2%5D.png?imgmax=800" width="319" height="299" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p align="justify"&gt;That’s almost a 6000% increase in spending at the height of the BP counter-PageRank campaign, and such unpredictable jumps are the calling cards of Black Swans.&amp;#160; From the article&lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;Before BP could stem the oil gusher at the bottom of the Gulf of Mexico, it unleashed $100 million in ad spending, largely on network TV, to stem the damage to its image. But it also started spending heavily where it had never spent much before: buying ads in Google's search results. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p align="justify"&gt;BP was essentially paying Google AdWords to distract Google PageRank - trial by PageRank and forgiveness by AdWords. What’s that saying about judges and juries again?&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-4051065884713375782?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/4051065884713375782/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=4051065884713375782' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4051065884713375782'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4051065884713375782'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/09/bp-and-trial-by-pagerank.html' title='BP and Trial by PageRank'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_Wom5eMghH20/TI_4lAkWUsI/AAAAAAAAA-A/qySekRWKLKY/s72-c/image_thumb%5B2%5D.png?imgmax=800' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-7720136572808477544</id><published>2010-09-10T14:20:00.001-07:00</published><updated>2010-09-10T14:20:40.366-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Infographic'/><title type='text'>Keyword Spamming with Infographics</title><content type='html'>&lt;p align="justify"&gt;Infographics have become more popular, and BuzzFeed has produced an &lt;a href="http://www.buzzfeed.com/awesomer/the-truth-about-infographics"&gt;infographic&lt;/a&gt; describing how infographics are used to generate keyword spam. The trick to stopping the spam appears to be adding a NO FOLLOW tag in the html code of the embedded infographic. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.buzzfeed.com/awesomer/the-truth-about-infographics"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/_Wom5eMghH20/TIqhFyAPBkI/AAAAAAAAA94/-xVFiFaj3kQ/image%5B5%5D.png?imgmax=800" width="112" height="377" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-7720136572808477544?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/7720136572808477544/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=7720136572808477544' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7720136572808477544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7720136572808477544'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/09/keyword-spamming-with-infographics.html' title='Keyword Spamming with Infographics'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_Wom5eMghH20/TIqhFyAPBkI/AAAAAAAAA94/-xVFiFaj3kQ/s72-c/image%5B5%5D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-2154816601156345858</id><published>2010-09-10T14:01:00.001-07:00</published><updated>2010-09-10T14:01:34.502-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Encrypted search'/><title type='text'>References to Homomorphic Encryption</title><content type='html'>&lt;p align="justify"&gt;&lt;a class="zem_slink" title="Homomorphic encryption" href="http://en.wikipedia.org/wiki/Homomorphic_encryption" rel="wikipedia"&gt;Homomorphic encryption&lt;/a&gt; is the basis of Craig Gentry’s recent &lt;a href="http://lukenotricks.blogspot.com/2010/03/in-search-of-encrypted-search.html"&gt;breakthrough&lt;/a&gt; in encrypted search. &lt;a href="http://research.cyber.ee/~lipmaa/"&gt;Helger Lipmaa&lt;/a&gt; has a large collection of papers on homomorphic encryption &lt;a href="http://research.cyber.ee/~lipmaa/crypto/link/public/homomorphic.php"&gt;here&lt;/a&gt;, as well as other cryptographic topics. Knock yourself out.&lt;/p&gt;  &lt;div style="margin-top: 10px; height: 15px" class="zemanta-pixie"&gt;&lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-2154816601156345858?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/2154816601156345858/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=2154816601156345858' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2154816601156345858'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2154816601156345858'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/09/references-to-homomorphic-encryption.html' title='References to Homomorphic Encryption'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-5585702538127497166</id><published>2010-09-10T13:37:00.001-07:00</published><updated>2010-09-10T13:37:47.614-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Course'/><category scheme='http://www.blogger.com/atom/ns#' term='Anonymity'/><title type='text'>Five Lectures on Anonymous Communications</title><content type='html'>&lt;p align="justify"&gt;&lt;a href="http://www.google.ie/search?q=george-danezis"&gt;George Danezis&lt;/a&gt; has put together a great series of lectures on modern anonymous communications, available from his Conspicuous Communication blog &lt;a href="http://conspicuouschatter.wordpress.com/2010/09/10/5-lectures-on-anonymous-communications/"&gt;here&lt;/a&gt;. The lectures cover&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Basic definitions &amp;amp; unconditional anonymity with DC-networks. &lt;/li&gt;    &lt;li&gt;Long-term attacks on anonymity systems (Statistical / Disclosure) and their Bayesian formulation. &lt;/li&gt;    &lt;li&gt;Mix networks and anonymity metrics. &lt;/li&gt;    &lt;li&gt;The Bayesian traffic analysis of mix networks. &lt;/li&gt;    &lt;li&gt;Low-latency anonymity with onion routing and crowds. &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;About 150 slides of material.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-5585702538127497166?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/5585702538127497166/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=5585702538127497166' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5585702538127497166'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5585702538127497166'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/09/five-lectures-on-anonymous.html' title='Five Lectures on Anonymous Communications'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-1228189329230287804</id><published>2010-09-05T13:45:00.001-07:00</published><updated>2010-09-05T13:46:27.591-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Video'/><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><category scheme='http://www.blogger.com/atom/ns#' term='ssl'/><title type='text'>How to render SSL Useless – video version</title><content type='html'>&lt;p align="justify"&gt;A while back I &lt;a href="http://lukenotricks.blogspot.com/2010/02/how-to-render-ssl-useless.html"&gt;posted&lt;/a&gt; on the&amp;#160; &lt;a href="http://www.scribd.com/doc/26552212"&gt;How to render SSL Useless&lt;/a&gt; deck from &lt;a href="http://blog.ivanristic.com/2010/01/how-to-render-ssl-useless.html"&gt;Ivan Ristic&lt;/a&gt; of SSL Labs (now with Qualys) on common mistakes in the deployment of SSL. There is now a &lt;a href="http://threatpost.com/en_us/blogs/how-render-ssl-useless-081810"&gt;video&lt;/a&gt; of Ivan presenting this deck at a recent OWASP conference, available at &lt;a href="http://threatpost.com/en_us"&gt;ThreatPost&lt;/a&gt;.&lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://threatpost.com/en_us/blogs/how-render-ssl-useless-081810"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/_Wom5eMghH20/TIQBUtK-q1I/AAAAAAAAA9s/ddI0YKGsc-o/image%5B6%5D.png?imgmax=800" width="404" height="234" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-1228189329230287804?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/1228189329230287804/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=1228189329230287804' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1228189329230287804'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1228189329230287804'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/09/how-to-render-ssl-useless-video-version.html' title='How to render SSL Useless – video version'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_Wom5eMghH20/TIQBUtK-q1I/AAAAAAAAA9s/ddI0YKGsc-o/s72-c/image%5B6%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-250806196832077472</id><published>2010-09-05T13:01:00.001-07:00</published><updated>2010-09-05T13:01:12.827-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Social Engineering'/><title type='text'>HeadHacker Social Engineering site</title><content type='html'>&lt;p align="justify"&gt;I just came across &lt;a href="http://www.headhacker.net/"&gt;HeadHacker&lt;/a&gt;, a site devoted to social engineering, run by a former colleague &lt;a href="http://www.headhacker.net/about/"&gt;Dale Pearson&lt;/a&gt;. The site looks great and Dale will be a speaker at the upcoming &lt;a href="https://www.hashdays.ch/venue-travel.html"&gt;hashdays&lt;/a&gt; conference in Lucerne this November. &lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh4.ggpht.com/_Wom5eMghH20/TIP3BQQzPsI/AAAAAAAAA9k/qvp7RmMYD_Q/s1600-h/image%5B4%5D.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/_Wom5eMghH20/TIP3B_5j3wI/AAAAAAAAA9o/v8Zc4puBgmI/image_thumb%5B2%5D.png?imgmax=800" width="290" height="100" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-250806196832077472?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/250806196832077472/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=250806196832077472' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/250806196832077472'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/250806196832077472'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/09/headhacker-social-engineering-site.html' title='HeadHacker Social Engineering site'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_Wom5eMghH20/TIP3B_5j3wI/AAAAAAAAA9o/v8Zc4puBgmI/s72-c/image_thumb%5B2%5D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6416836633950470181</id><published>2010-09-05T11:39:00.001-07:00</published><updated>2010-09-05T11:41:48.887-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Risk Management'/><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><category scheme='http://www.blogger.com/atom/ns#' term='Presentation'/><title type='text'>Will there be an IT Risk Management 2.0?</title><content type='html'>&lt;p align="justify"&gt;This is the title of a short &lt;a href="http://www.scribd.com/doc/36931010/Will-There-by-an-IT-Risk-Management-2-0"&gt;talk&lt;/a&gt; I gave recently at an OWASP chapter meeting in Zurich. The audience was small but engaged, and I went over time by quite a bit.&amp;#160; I need to develop the talk further but it is a decent v1.0. &lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://www.scribd.com/doc/36931010/Will-There-by-an-IT-Risk-Management-2-0"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/_Wom5eMghH20/TIPkbF8q4vI/AAAAAAAAA9g/CEkXlLWsM6Q/image%5B7%5D.png?imgmax=800" width="306" height="229" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6416836633950470181?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6416836633950470181/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6416836633950470181' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6416836633950470181'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6416836633950470181'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/09/will-there-be-it-risk-management-20.html' title='Will there be an IT Risk Management 2.0?'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_Wom5eMghH20/TIPkbF8q4vI/AAAAAAAAA9g/CEkXlLWsM6Q/s72-c/image%5B7%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-7209021690692379300</id><published>2010-08-28T11:58:00.001-07:00</published><updated>2010-08-28T12:30:42.412-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Books'/><category scheme='http://www.blogger.com/atom/ns#' term='Black Swan'/><title type='text'>The Blank Swan</title><content type='html'>&lt;p align="justify"&gt;There is&amp;#160; a new book, published in April, called &lt;a href="http://http://www.amazon.com/Blank-Swan-End-Probability/dp/0470725222"&gt;The Blank Swan: The End of Probability&lt;/a&gt;. This is a clever title and the front photo is wonderful as well. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Wom5eMghH20/THlcRG5gFiI/AAAAAAAAA9I/FD9btE12iSE/s1600-h/image%5B6%5D.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/_Wom5eMghH20/THlcRYDf1kI/AAAAAAAAA9M/mAuQFcyr5xo/image_thumb%5B2%5D.png?imgmax=800" width="137" height="204" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align="justify"&gt;The book seems to be saying that financial market processes simply cannot be captured using the conventional notions of probability. The author writes in summary&lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;The current crisis has led us to a conceptual impasse regarding the financial market. No prediction model can apply to the market …&lt;/p&gt;    &lt;p align="justify"&gt;Probability has to be discarded and a new category has to emerge instead, which will mediate contingency …&lt;/p&gt;    &lt;p align="justify"&gt;In fact, the market has nothing to do with Wall Street or with the investment banks. Market-making is a creative activity. The market is a category of thought that is independent of ideology. It replaces probability altogether and discarding the market, like the philosophers of the radical change claim we should do, is like discarding probability!&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p align="justify"&gt;Not a very positive &lt;a href="http://readingthemarkets.blogspot.com/2010/08/ayache-blank-swan-end-of-probability.html"&gt;review&lt;/a&gt; from Reading the Markets, who found the book quite hard to read. There is some &lt;a href="http://www.wilmott.com/messageview.cfm?catid=11&amp;amp;threadid=76822"&gt;discussion&lt;/a&gt; on a Wilmott mailing list as well.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-7209021690692379300?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/7209021690692379300/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=7209021690692379300' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7209021690692379300'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7209021690692379300'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/blank-swan.html' title='The Blank Swan'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_Wom5eMghH20/THlcRYDf1kI/AAAAAAAAA9M/mAuQFcyr5xo/s72-c/image_thumb%5B2%5D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-5912639949496452005</id><published>2010-08-28T07:58:00.001-07:00</published><updated>2010-09-11T16:09:25.117-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Encrypted search'/><category scheme='http://www.blogger.com/atom/ns#' term='cloud computing'/><title type='text'>Searching an Encrypted Cloud</title><content type='html'>&lt;p align="justify"&gt;There is a &lt;a href="http://www.enterprisesearchblog.com/2010/05/searching-an-encrypted-cloud.html"&gt;post&lt;/a&gt; over at the Enterprise Search blog with some pointers to encrypted search, including my own &lt;a href="http://lukenotricks.blogspot.com/2010/03/in-search-of-encrypted-search.html"&gt;overview&lt;/a&gt;. There is a link to a &lt;a href="http://www.infoq.com/news/2010/01/Cloud-Searchable-Encryption"&gt;whitepaper&lt;/a&gt; from &lt;a href="http://research.microsoft.com/en-us/people/senyk/"&gt;Seny Kamara&lt;/a&gt; and &lt;a href="http://research.microsoft.com/en-us/people/klauter/"&gt;Kristin Lauter&lt;/a&gt; of the &lt;a href="http://research.microsoft.com/en-us/groups/crypto/"&gt;Microsoft Research Cryptography Group&lt;/a&gt;, proposing an architecture for a virtual private storage service which supports the following properties&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;confidentiality&lt;/li&gt;    &lt;li&gt;integrity &lt;/li&gt;    &lt;li&gt;non-repudiation&lt;/li&gt;    &lt;li&gt;availability&lt;/li&gt;    &lt;li&gt;reliability&lt;/li&gt;    &lt;li&gt;efficient retrieval&lt;/li&gt;    &lt;li&gt;data sharing&lt;/li&gt; &lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-5912639949496452005?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/5912639949496452005/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=5912639949496452005' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5912639949496452005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5912639949496452005'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/searching-encrypted-cloud.html' title='Searching an Encrypted Cloud'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-4146679407657787749</id><published>2010-08-28T04:18:00.001-07:00</published><updated>2010-08-28T13:50:48.771-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='A5/1'/><category scheme='http://www.blogger.com/atom/ns#' term='Visualization'/><title type='text'>Cool A5/1 back-clocking graphic</title><content type='html'>&lt;p align="justify"&gt;Below is part of a &lt;a href="http://reflextor.com/trac/a51/wiki/BackclockA51"&gt;graphic&lt;/a&gt; which depicts the A5/1 state space generated when checking if the correct key has been determined from a rainbow table lookup. Once a key candidate has been found using the rainbow tables, the A5/1 cipher needs to be advanced (forward clocked) and undone (back-clocked) to verify that the candidate key is correct.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://reflextor.com/trac/a51/attachment/wiki/BackclockA51/a51map.png"&gt;&lt;img style="border: 0px none; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" alt="image" src="http://lh5.ggpht.com/_Wom5eMghH20/THjwmvx6KeI/AAAAAAAAA84/teQa4t_e_UY/image%5B11%5D.png?imgmax=800" width="403" border="0" height="193" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p align="justify"&gt;The grey paths represent states that are not accessible through forward clocking, and the green paths have many ancestor states leading to the same key stream. Red paths have few ancestor states leading to the same key stream. The graphic is from the A5/1 rainbow table generation project led by &lt;a href="http://lukenotricks.blogspot.com/2010/03/last-days-of-a51.html"&gt;Karsten Nohl&lt;/a&gt;. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-4146679407657787749?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/4146679407657787749/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=4146679407657787749' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4146679407657787749'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4146679407657787749'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/cool-a51-back-clocking-graphic.html' title='Cool A5/1 back-clocking graphic'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_Wom5eMghH20/THjwmvx6KeI/AAAAAAAAA84/teQa4t_e_UY/s72-c/image%5B11%5D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6477454669422803678</id><published>2010-08-27T14:55:00.001-07:00</published><updated>2010-08-27T14:55:28.110-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='GPU'/><title type='text'>GPU Judgement Day for short Passwords</title><content type='html'>&lt;p align="justify"&gt;Researchers from the Georgia Tech Research Institute have &lt;a href="http://www.gtri.gatech.edu/casestudy/Teraflop-Troubles-Power-Graphics-Processing-Units-GPUs-Password-Security-System"&gt;announced&lt;/a&gt; that the power of &lt;a class="zem_slink" title="Graphics processing unit" href="http://en.wikipedia.org/wiki/Graphics_processing_unit" rel="wikipedia"&gt;GPU&lt;/a&gt; processors now poses a real threat to password security, and by implication, to the security of critical IT infrastructure. Top of the line GPU devices now process at the rate of 2 Teraflops second, which is around 30% of the computing power the fastest computing cluster could muster 10 years ago for a price tag of over $100 million. Given that the main GPU manufacturers have made their devices programmable through standard C libraries, &lt;a href="http://www.engadget.com/2010/08/16/gpus-democratize-brute-force-password-hacking/?icid=zemanta"&gt;password cracking has become democratized&lt;/a&gt;. &lt;/p&gt;  &lt;p align="justify"&gt;The researchers state that 7 character passwords are now totally insecure against exhaustive attacks and recommend 12 characters, drawn from the full 94 printable keyboard characters. GPU processors can also be used to generate rainbow tables for offline password cracking, which was the approach taken &lt;a href="http://lukenotricks.blogspot.com/2010/03/last-days-of-a51.html"&gt;recently&lt;/a&gt; by Karsten Knol to building rainbow table using &lt;a class="zem_slink" title="CUDA" href="http://www.nvidia.com/object/cuda_home.html" rel="homepage"&gt;CUDA&lt;/a&gt; nodes. &lt;/p&gt;  &lt;p align="justify"&gt;Of course, applying GPU devices to password creaking is not new, and &lt;a href="http://www.elcomsoft.com/"&gt;Elcomsoft&lt;/a&gt; has made a name for itself using high-end gaming chips to recover and benchmark passwords. I am a little surprised that the researchers did not mention this. In any case, Elcomsoft has a great &lt;a href="http://blog.crackpassword.com/"&gt;blog&lt;/a&gt; and you can find a good presentation on GPU password cracking &lt;a href="http://blog.crackpassword.com/2009/04/gpu-assisted-password-cracking-at-troopers-2009/"&gt;here&lt;/a&gt;. &lt;/p&gt;  &lt;p align="justify"&gt;From my post &lt;a href="http://lukenotricks.blogspot.com/2008/12/spin-on-passwords-and-aes.html"&gt;The spin on passwords for AES&lt;/a&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;Adding spin to password-based computations is a workaround to the unpleasant fact that human habits and memory are vastly outmoded in today's IT environment. Everything is getting faster, better and cheaper - except us. Passwords remain the most toxic asset on the security balance sheet, but don't expect a bailout any time soon.&lt;/p&gt; &lt;/blockquote&gt;  &lt;div style="margin-top: 10px; height: 15px" class="zemanta-pixie"&gt;&lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6477454669422803678?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6477454669422803678/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6477454669422803678' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6477454669422803678'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6477454669422803678'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/gpu-judgement-day-for-short-passwords.html' title='GPU Judgement Day for short Passwords'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6311331199347342384</id><published>2010-08-27T13:59:00.001-07:00</published><updated>2010-08-28T17:15:16.768-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RC4'/><category scheme='http://www.blogger.com/atom/ns#' term='Skype'/><title type='text'>De-obfuscating the RC4 layer of Skype</title><content type='html'>&lt;p align="justify"&gt;Sean O'Neil, a security developer (or at least an amateur one), has &lt;a href="http://www.enrupt.com/index.php/2010/07/07/skype-biggest-secret-revealed"&gt;posted&lt;/a&gt; code that is binary-compatible with an obfuscated version of RC4 that is used to protect Skype control traffic (user searches, profiles, contact lists). O’Neil says that the obfuscated version of RC4 is keyless and serves no useful security purpose, but its presence is intended to render Skype incompatible with other messaging clients, effectively making it a proprietary system. Even though Skype was &lt;a href="http://techcrunch.com/2010/06/22/skype-skypekit-sdk/"&gt;intending&lt;/a&gt; to open its APIs to all desktop clients soon enough, O’Neil sees himself as buster of Skype’s 10 year monopoly.&lt;/p&gt;  &lt;p align="justify"&gt;The story is being widely reported in the press (see links below), and it is easy to assume that the general security of Skype has been compromised, especially when O’Neil’s own post carried the title &lt;a href="http://www.enrupt.com/index.php/2010/07/07/skype-biggest-secret-revealed"&gt;Skype’s Biggest Secret Revealed&lt;/a&gt;. But the secret was disentangling the modified version of RC4 from Skype’s operation. User privacy remains protected since full strength versions of AES-256, RSA-1024 and RSA-2048 are used to encrypt session traffic. The &lt;a href="http://skyperc4.pastebin.com/g1xFFFcr"&gt;code&lt;/a&gt; itself is surely obfuscated since the source is over 2800 lines of C, when 50 or so is enough to implement RC4. &lt;/p&gt;  &lt;p align="justify"&gt;The full implications of the discovery are still playing out, and whether losing their biggest secret poses a serious issue for Skype. O’Neil is promising to release more details at the Chaos Communication Conference in Berlin this December.&lt;/p&gt;  &lt;div class="zemanta-related"&gt;   &lt;h6 style="font-size: 1em;" class="zemanta-related-title"&gt;Related articles by Zemanta&lt;/h6&gt;    &lt;ul class="zemanta-article-ul"&gt;     &lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://voipsa.org/blog/2010/07/09/skype-encryption-partially-cracked/"&gt;Skype encryption partially cracked?&lt;/a&gt; (voipsa.org) &lt;/li&gt;      &lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://techcrunch.com/2010/07/08/skypes-innermost-security-layers-claimed-to-be-reverse-engineered/"&gt;Skype's Innermost Security Layers Claimed To Be Reverse-Engineered&lt;/a&gt; (techcrunch.com) &lt;/li&gt;      &lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://techie-buzz.com/tech-news/hacker-cracks-skypes-proprietary-voip-protocol.html"&gt;Hackers Crack Skype's Proprietary VOIP Protocol&lt;/a&gt; (techie-buzz.com) &lt;/li&gt;      &lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://arstechnica.com/tech-policy/news/2010/08/encrypted-and-obfuscated-your-p2p-protocol-can-still-be-ided.ars"&gt;Encrypted and obfuscated? Your P2P protocol can still be IDed&lt;/a&gt; (arstechnica.com)&lt;/li&gt;      &lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://go.theregister.com/feed/www.theregister.co.uk/2010/07/09/skype_crypto/"&gt;Reverse engineer extracts Skype crypto secret recipe&lt;/a&gt; (go.theregister.com)&lt;/li&gt;   &lt;/ul&gt; &lt;/div&gt;  &lt;div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"&gt;&lt;img style="border-style: none; float: right;" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=091f3a2b-9fa9-4034-91f9-11643f70a804" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6311331199347342384?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6311331199347342384/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6311331199347342384' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6311331199347342384'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6311331199347342384'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/de-obfuscating-rc4-layer-of-skype.html' title='De-obfuscating the RC4 layer of Skype'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-317750484272597268</id><published>2010-08-26T02:18:00.000-07:00</published><updated>2010-08-26T04:53:41.385-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DDoS'/><category scheme='http://www.blogger.com/atom/ns#' term='FreeMind'/><title type='text'>Uno, dos, DDoS</title><content type='html'>&lt;div style="text-align: justify;"&gt;Here is a &lt;a href="http://freemind.sourceforge.net/wiki/extensions/freemind/flashwindow.php?initLoadFile=/wiki/images/3/3c/Steinnon_and_DDOS.mm&amp;amp;startCollapsedToLevel=5&amp;amp;mm_title=Steinnon%20and%20DDOS.mm"&gt;Flash rendering&lt;/a&gt; of a FreeMind map I made from the excellent post &lt;a href="http://information-security-resources.com/2009/11/22/surviving-cyber-war-a-primer-on-ddos/"&gt;Surviving Cyber War: A Primer on DDoS&lt;/a&gt; by Richard Stiennon, which appeared last November. The post traces the history of DDoS, looks at the people and technologies involved, and tells the story of the unlikely (then) 25-year-old hero &lt;a href="http://en.wikipedia.org/wiki/Barrett_Lyon"&gt;Barrett Lyon&lt;/a&gt;.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-317750484272597268?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/317750484272597268/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=317750484272597268' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/317750484272597268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/317750484272597268'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/uno-dos-ddos.html' title='Uno, dos, DDoS'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6899315035816840800</id><published>2010-08-25T14:38:00.001-07:00</published><updated>2010-08-25T14:47:57.543-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Trends'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='FreeMind'/><title type='text'>IT Security Trends FreeMind map from 2008</title><content type='html'>&lt;p align="justify"&gt;I recently &lt;a href="http://freemind.sourceforge.net/wiki/extensions/freemind/flashwindow.php?initLoadFile=/wiki/images/d/d3/IT_Sec_2008_Trends.mm&amp;amp;startCollapsedToLevel=5&amp;amp;mm_title=IT%20Sec%202008%20Trends.mm"&gt;uploaded&lt;/a&gt; a large FreeMind map that I collected over 2008, in an effort to get a handle on the stream of security articles, reports and incidents taking place back then. In short there was a torrent and it remains much the same today. I think you might  find the &lt;em&gt;ad hoc&lt;/em&gt; classification of material useful, as well as the groups of sources. &lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://freemind.sourceforge.net/wiki/extensions/freemind/flashwindow.php?initLoadFile=/wiki/images/d/d3/IT_Sec_2008_Trends.mm&amp;amp;startCollapsedToLevel=5&amp;amp;mm_title=IT%20Sec%202008%20Trends.mm"&gt;&lt;img style="border: 0px none; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" alt="image" src="http://lh5.ggpht.com/_Wom5eMghH20/THWNZg35apI/AAAAAAAAA8U/0QA1fCMldLw/image%5B9%5D.png?imgmax=800" width="398" border="0" height="209" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p align="justify"&gt;Note that links to items from FIRST (Forum of Incident Response and Security Teams) are now broken since their once excellent news service has been discontinued. &lt;/p&gt;  &lt;p align="justify"&gt;All sources for my security and risk FreeMind maps are available &lt;a href="http://sites.google.com/site/lukeoconnorsite/Home/it-security-and-cryptography/freemind-security-maps"&gt;here&lt;/a&gt;. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6899315035816840800?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6899315035816840800/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6899315035816840800' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6899315035816840800'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6899315035816840800'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/it-security-trends-freemind-map-from.html' title='IT Security Trends FreeMind map from 2008'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_Wom5eMghH20/THWNZg35apI/AAAAAAAAA8U/0QA1fCMldLw/s72-c/image%5B9%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-876982207039154144</id><published>2010-08-25T03:08:00.000-07:00</published><updated>2010-08-28T14:50:41.153-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='Entropy'/><category scheme='http://www.blogger.com/atom/ns#' term='Wireless'/><title type='text'>12 bits of default entropy for Speedport WPA routers</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;The&lt;/span&gt; &lt;a href="http://www.h-online.com/security/news/item/WPA-key-of-Speedport-routers-too-simple-1063308.html"&gt;H&lt;/a&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;has&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;reported&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;that&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;the&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;default&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;WPA&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;key&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;settings&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;for&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;the&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;Speedport&lt;/span&gt; W 700V ADSL &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;Wi&lt;/span&gt;-&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;Fi&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;routers&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;are&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;weak&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;since&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;at&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;most&lt;/span&gt; 4096 &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;guesses&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;are&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;required&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;to&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;recover&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;the&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_26"&gt;key&lt;/span&gt;. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_27"&gt;The&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_28"&gt;key&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_29"&gt;is&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_30"&gt;mostly&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_31"&gt;populated&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_32"&gt;with&lt;/span&gt; a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_33"&gt;collection&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_34"&gt;of&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_35"&gt;fixed&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_36"&gt;fields&lt;/span&gt; (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_37"&gt;for&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_38"&gt;example&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_40"&gt;keys&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_41"&gt;always&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_42"&gt;begin&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_43"&gt;with&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_44"&gt;the&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_45"&gt;prefix&lt;/span&gt; "&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_46"&gt;SP&lt;/span&gt;-") &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_47"&gt;and&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_48"&gt;other&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_49"&gt;public&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_50"&gt;information&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_51"&gt;such&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_52"&gt;as&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_53"&gt;the&lt;/span&gt; MAC &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_54"&gt;address&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_55"&gt;of&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_56"&gt;the&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_57"&gt;router&lt;/span&gt;. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_58"&gt;The&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_59"&gt;devices&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_60"&gt;are&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_61"&gt;apparently&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_62"&gt;supported&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_63"&gt;by&lt;/span&gt; all &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_64"&gt;major&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_65"&gt;German&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_66"&gt;Telecoms&lt;/span&gt;, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_67"&gt;and&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_68"&gt;presumably&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_69"&gt;popular&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_70"&gt;amongst&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_71"&gt;the&lt;/span&gt; 26 &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_72"&gt;million&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_73"&gt;or&lt;/span&gt; so &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_74"&gt;German&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_75"&gt;households&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_76"&gt;that&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_77"&gt;have&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_78"&gt;wireless&lt;/span&gt;.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_79"&gt; Of&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_80"&gt;course&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_81"&gt;the&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_82"&gt;owners&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_83"&gt;of&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_84"&gt;the&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_85"&gt;routers&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_86"&gt;can&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_87"&gt;change&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_88"&gt;the&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_89"&gt;default&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_90"&gt;WPA&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_91"&gt;key&lt;/span&gt;, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_92"&gt;but&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_93"&gt;its&lt;/span&gt; a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_94"&gt;safe&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_95"&gt;bet&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_96"&gt;to&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_97"&gt;assume&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_98"&gt;that&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_99"&gt;most&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_100"&gt;people&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_101"&gt;probably&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_102"&gt;need&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_103"&gt;to&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_104"&gt;be&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_105"&gt;reminded&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_106"&gt;of&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_107"&gt;this&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_108"&gt;precaution&lt;/span&gt;. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_109"&gt;Germany&lt;/span&gt;'s &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_110"&gt;top&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_111"&gt;criminal&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_112"&gt;court&lt;/span&gt; &lt;a href="http://www.msnbc.msn.com/id/37107291/ns/technology_and_science-security/"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_113"&gt;recently&lt;/span&gt;&lt;/a&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_114"&gt;made&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_115"&gt;it&lt;/span&gt; illegal &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_116"&gt;to&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_117"&gt;offer&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_118"&gt;wireless&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_119"&gt;services&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_120"&gt;that&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_121"&gt;are&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_122"&gt;not&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_123"&gt;protected&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_124"&gt;by&lt;/span&gt; a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_125"&gt;password&lt;/span&gt;, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_126"&gt;which&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_127"&gt;is&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_128"&gt;not&lt;/span&gt; a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_129"&gt;good&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_130"&gt;sign&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_131"&gt;that&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_132"&gt;strong&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_133"&gt;passwords&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_134"&gt;are&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_135"&gt;the&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_136"&gt;norm&lt;/span&gt;. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-876982207039154144?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/876982207039154144/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=876982207039154144' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/876982207039154144'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/876982207039154144'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/weak-default-keys-for-wpa-routers.html' title='12 bits of default entropy for Speedport WPA routers'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-5365676921288437788</id><published>2010-08-25T02:01:00.000-07:00</published><updated>2010-09-01T15:13:39.250-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Risk'/><title type='text'>How to reason about IT Security Risks</title><content type='html'>&lt;div style="text-align: justify;"&gt;I have been meaning for some time to post a &lt;a href="http://blog.noticebored.com/2007/12/top-information-security-risks-for-2008.html"&gt;link &lt;/a&gt;to this wonderful paper from late 2007 on the top information security risks for the then coming year. The paper was a collaborative work from several groups of security professionals, led by Gary Hinson, keeper of the fantastic &lt;a href="http://blog.noticebored.com/"&gt;NoticeBored&lt;/a&gt; site of security awareness material. The paper is excellent in that it clearly separates threats, vulnerabilities and impacts, and then creates risks as scenarios from the interplay of these three collections, with controls coming as final recommendations. The whole approach just seems so clean and sensible, and demonstrates the distinctions amongst risk terms which sometimes get lost in our daily language.&lt;br /&gt;&lt;br /&gt;Now added to my &lt;a href="http://www.scribd.com/my_document_collections/2310117"&gt;IT Risk collection&lt;/a&gt; on Scribd, thanks to Gary Hinson for removing the copyright protection.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-5365676921288437788?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/5365676921288437788/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=5365676921288437788' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5365676921288437788'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5365676921288437788'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/how-to-reason-about-it-security-risks.html' title='How to reason about IT Security Risks'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-1244204975710889125</id><published>2010-08-24T13:30:00.001-07:00</published><updated>2010-09-05T06:19:30.913-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IT Risk'/><category scheme='http://www.blogger.com/atom/ns#' term='Research'/><title type='text'>Recent PhD Thesis on IT Risk Management</title><content type='html'>&lt;p align="justify"&gt;The 2008 PhD thesis of Domenico Salvati from the &lt;a href="http://www.lsa.ethz.ch/index_EN"&gt;Laboratory for Safety Analysis&lt;/a&gt; at ETH, Zurich, on the Management of Information System Risks is &lt;a href="http://www.lsa.ethz.ch/people/former/Mgmt_of_IS_Risks_ETH-Diss_18132.pdf"&gt;available online&lt;/a&gt;. Salvati presents a structured approach to the IT risk management process which has some novel differences as compared to the more familiar frameworks. The thesis contains a long examples on computing the risk of a brute force password attack, and the risk of phishing attacks. The work has a very practical flavour as Salvati was sponsored by Credit Suisse for the thesis, as part of &lt;a href="http://www.zisc.ethz.ch/"&gt;ZISC&lt;/a&gt;. &lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh5.ggpht.com/_Wom5eMghH20/TIOY37323fI/AAAAAAAAA9Y/QenoqpuCANE/s1600-h/image%5B3%5D.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/_Wom5eMghH20/TIOY4SEO5HI/AAAAAAAAA9c/yC4pTmyVXPM/image_thumb%5B1%5D.png?imgmax=800" width="89" height="107" /&gt;&lt;/a&gt;&amp;#160;&lt;/p&gt;  &lt;p align="justify"&gt;You can find a short bio on Domenico as part of the upcoming &lt;a href="https://www.hashdays.ch/about.html"&gt;hashdays&lt;/a&gt; security and risk conference in Zurich.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-1244204975710889125?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/1244204975710889125/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=1244204975710889125' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1244204975710889125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1244204975710889125'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/recent-phd-thesis-on-it-risk-management.html' title='Recent PhD Thesis on IT Risk Management'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_Wom5eMghH20/TIOY4SEO5HI/AAAAAAAAA9c/yC4pTmyVXPM/s72-c/image_thumb%5B1%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-8119540707555948859</id><published>2010-08-19T15:15:00.001-07:00</published><updated>2010-08-19T15:15:48.826-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cryptography'/><category scheme='http://www.blogger.com/atom/ns#' term='Quantum Computing'/><category scheme='http://www.blogger.com/atom/ns#' term='Factoring'/><title type='text'>Evidence that the McEliece Cryptosystem is resistant to Quantum Computing Attacks</title><content type='html'>&lt;p align="justify"&gt;A &lt;a href="http://arxiv.org/abs/1008.2390"&gt;paper&lt;/a&gt; was posted on the preprint server &lt;a href="http://arxiv.org/"&gt;Physics arXiv&lt;/a&gt; showing that the &lt;a href="http://en.wikipedia.org/wiki/McEliece"&gt;McEliece public key cryptosystem&lt;/a&gt; is resistant to efficient quantum algorithms based on the ideas of &lt;a href="http://en.wikipedia.org/wiki/Shor%27s_algorithm"&gt;Shor’s algorithm&lt;/a&gt;, which famously yielded an efficient method for factoring integers. From the abstract&lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;Quantum computers can break the RSA and El Gamal public-key cryptosystems, since they can factor integers and extract discrete logarithms. If we believe that quantum computers will someday become a reality, we would like to have post-quantum cryptosystems which can be implemented today with classical computers, but which will remain secure even in the presence of quantum attacks. In this article we show that the McEliece cryptosystem over rational Goppa codes resists precisely the attacks to which the RSA and El Gamal cryptosystems are vulnerable---namely, those based on generating and measuring coset states. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p align="justify"&gt;Shor’s algorithm is a general method for computing the period of certain functions, and it can be applied to computing the orders of elements modulo a composite number for example (see my post &lt;a href="http://lukenotricks.blogspot.com/2008/07/quantum-computing-are-you-shor.html"&gt;Quantum Computing: are you Shor?&lt;/a&gt; for some details). Shor’s algorithm is not directly applicable to the McEliece cryptosystem since it is based on a hard problem from coding theory, and is not obviously solvable by computing periods of functions. The new paper seems to demonstrate that no connection will be found. &lt;/p&gt;  &lt;p align="justify"&gt;However the authors caution that there may be another quantum approach distinct from the principles of Shor’s algorithm that efficiently breaks the McEliece cryptosystem. On the other hand, there is a growing consensus that &lt;a href="http://en.wikipedia.org/wiki/NP-complete"&gt;NP-complete&lt;/a&gt; problems do not have efficient quantum algorithms (see the diagram in this &lt;a href="http://lukenotricks.blogspot.com/2010/08/short-cryptography-lecture.html"&gt;post&lt;/a&gt;), and the McEliece cryptosystem is based on an &lt;a href="http://en.wikipedia.org/wiki/NP-hard"&gt;NP-hard&lt;/a&gt; problem (which means it is at least as hard as an NP-complete problem).&lt;/p&gt;  &lt;p align="justify"&gt;There is also a nice background &lt;a href="http://www.technologyreview.com/blog/arxiv/25629/"&gt;post&lt;/a&gt; on the &lt;a href="http://www.technologyreview.com/blog/arxiv/"&gt;physics arXiv blog&lt;/a&gt;.&lt;/p&gt;  &lt;div class="zemanta-related"&gt;   &lt;h6 style="font-size: 1em" class="zemanta-related-title"&gt;Related articles by Zemanta&lt;/h6&gt;    &lt;ul class="zemanta-article-ul"&gt;     &lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://science.slashdot.org/story/10/08/18/1958226/1978-Cryptosystem-Resists-Quantum-Attack"&gt;1978 Cryptosystem Resists Quantum Attack&lt;/a&gt; (science.slashdot.org)&lt;/li&gt;      &lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://gizmodo.com/5615939/thirty+year+old-encryption-formula-can-resist-quantum+computing-attacks-that-defeat-all-common-codes"&gt;Thirty-Year-Old Encryption Formula Can Resist Quantum-Computing Attacks That Defeat All Common Codes [Encryption]&lt;/a&gt; (gizmodo.com)&lt;/li&gt;   &lt;/ul&gt; &lt;/div&gt;  &lt;div style="margin-top: 10px; height: 15px" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"&gt;&lt;img style="border-bottom-style: none; border-right-style: none; border-top-style: none; float: right; border-left-style: none" class="zemanta-pixie-img" alt="Enhanced by Zemanta" src="http://img.zemanta.com/zemified_e.png?x-id=0ef37d05-13e7-42fa-9eff-5db1a5fc8996" /&gt;&lt;/a&gt;&lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-8119540707555948859?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/8119540707555948859/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=8119540707555948859' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8119540707555948859'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8119540707555948859'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/evidence-that-mceliece-cryptosystem-is.html' title='Evidence that the McEliece Cryptosystem is resistant to Quantum Computing Attacks'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3161982172670509553</id><published>2010-08-17T04:38:00.001-07:00</published><updated>2010-08-17T16:38:27.891-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><title type='text'>Password preferences of Spanish speakers</title><content type='html'>&lt;p align="justify"&gt;Imperva recently &lt;a href="http://blog.imperva.com/2010/08/spanish-password-security.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+SecurityBloggersNetwork+%28Security+Bloggers+Network%29&amp;amp;utm_content=Google+Reader"&gt;announced&lt;/a&gt; an update to their analysis of the 32 million passwords that were &lt;a href="http://www.nytimes.com/2010/01/21/technology/21password.html?_r=1"&gt;exposed&lt;/a&gt; by the RockYou site earlier this year. The update is concerned with a specific analysis of the spanish passwords included in the breach, of which there were just over 2 million. Imperva together with Spanish marketing firm &lt;a href="http://www.aguamarketing.com/"&gt;Agua Marketing&lt;/a&gt; found the following breakdown of password preferences – note that almost half of the passwords are based on personal names.&lt;/p&gt;  &lt;p align="justify"&gt;&lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh6.ggpht.com/_Wom5eMghH20/TGp0slWJ5bI/AAAAAAAAA8A/UO17Hs-q3jw/s1600-h/image%5B6%5D.png"&gt;&lt;img style="border: 0px none; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" alt="image" src="http://lh6.ggpht.com/_Wom5eMghH20/TGp0tGYHkOI/AAAAAAAAA8E/TwirEmgxd00/image_thumb%5B4%5D.png?imgmax=800" width="373" border="0" height="211" /&gt;&lt;/a&gt;The full report in Spanish is &lt;a href="https://www.imperva.com/ld/contrasenas.asp"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3161982172670509553?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3161982172670509553/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3161982172670509553' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3161982172670509553'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3161982172670509553'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/some-password-preferences-of-spanish.html' title='Password preferences of Spanish speakers'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_Wom5eMghH20/TGp0tGYHkOI/AAAAAAAAA8E/TwirEmgxd00/s72-c/image_thumb%5B4%5D.png?imgmax=800' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-5464207451850665777</id><published>2010-08-15T14:16:00.001-07:00</published><updated>2010-08-15T14:20:29.926-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cryptography'/><category scheme='http://www.blogger.com/atom/ns#' term='Course'/><title type='text'>Short cryptography lecture from Scott Aaronson</title><content type='html'>&lt;p align="justify"&gt;Here is a short cryptography &lt;a href="http://scottaaronson.com/democritus/lec8.html"&gt;lecture&lt;/a&gt; from &lt;a href="http://www.scottaaronson.com"&gt;Scott Aaronson&lt;/a&gt;, delivered as part of his &lt;a href="http://www.scottaaronson.com/democritus/"&gt;Quantum Computing Since Democritus&lt;/a&gt; course given at the University of Waterloo, Fall 2006. The lecture gives a short text-based overview of crypto from mainly a complexity point of view, and discusses some of the implications of the “P = NP?” question for crypto. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Wom5eMghH20/TGhZIpFQ3MI/AAAAAAAAA7g/JkgCcaxJb18/s1600-h/image%5B5%5D.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/_Wom5eMghH20/TGhZJFTyrzI/AAAAAAAAA7k/ZuwuLQ25ZDE/image_thumb%5B3%5D.png?imgmax=800" width="370" height="251" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-5464207451850665777?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/5464207451850665777/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=5464207451850665777' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5464207451850665777'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/5464207451850665777'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/short-cryptography-lecture.html' title='Short cryptography lecture from Scott Aaronson'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_Wom5eMghH20/TGhZJFTyrzI/AAAAAAAAA7k/ZuwuLQ25ZDE/s72-c/image_thumb%5B3%5D.png?imgmax=800' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6988119628252893201</id><published>2010-08-03T04:29:00.001-07:00</published><updated>2010-08-05T06:28:51.515-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AES'/><title type='text'>Recent spike in reads of AES posts</title><content type='html'>&lt;div style="text-align: justify;"&gt;Just a note to say that over the last few days there has been a jump in reads on a few of my AES posts, in particular for &lt;a href="http://lukenotricks.blogspot.com/2008/07/are-aes-256-bit-keys-too-large.html"&gt;Are  AES 256-bit keys too large?&lt;/a&gt; and &lt;a href="http://lukenotricks.blogspot.com/2009/05/aes-256-and-reputational-risk.html"&gt;AES-256  and Reputational Risk&lt;/a&gt;. I can't find any obvious reason why, however these posts do appear amongst the top google search results for "aes 256" or "aes-256".&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6988119628252893201?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6988119628252893201/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6988119628252893201' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6988119628252893201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6988119628252893201'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/08/recent-spike-in-reads-of-aes-posts.html' title='Recent spike in reads of AES posts'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-7940797439348963476</id><published>2010-06-11T15:26:00.001-07:00</published><updated>2010-06-12T16:53:23.356-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='renegotiation attack'/><category scheme='http://www.blogger.com/atom/ns#' term='TLS'/><category scheme='http://www.blogger.com/atom/ns#' term='ssl'/><title type='text'>Detecting SSL/TLS legacy session Renegotiation</title><content type='html'>&lt;div align="justify"&gt;Back in November I posted on  &lt;a href="http://lukenotricks.blogspot.com/2009/11/tls-renegotiation-attack-for-impatient.html"&gt;The TLS Renegotiation Attack for the Impatient&lt;/a&gt;, which I hoped was a plain English explanation of this new weakness in SSL and TLS (at the end of the post you can find less plain explanations and links). The weakness was quickly &lt;a href="http://lukenotricks.blogspot.com/2010/02/plugging-authentication-gap-in-ssl.html"&gt;addressed&lt;/a&gt; by the IETF a few months later. There is a new &lt;a href="http://blog.ncircle.com/blogs/vert/archives/2010/06/detecting_tls_legacy_session_r.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+SecurityBloggersNetwork+%28Security+Bloggers+Network%29&amp;amp;utm_content=Google+Reader"&gt;review&lt;/a&gt; of the attack from nCircle and also a &lt;a href="http://blog.ncircle.com/blogs/vert/detecting_tls_legacy_renegotiation.pdf"&gt;link&lt;/a&gt; to the detailed steps that can be taken to specifically detect servers which still run legacy versions of the protocols susceptible to the attack. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-7940797439348963476?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/7940797439348963476/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=7940797439348963476' title='18 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7940797439348963476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7940797439348963476'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/06/detecting-ssltls-legacy-session.html' title='Detecting SSL/TLS legacy session Renegotiation'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>18</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3115108613546978563</id><published>2010-05-29T03:35:00.001-07:00</published><updated>2010-08-19T16:31:07.420-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='YouTube'/><category scheme='http://www.blogger.com/atom/ns#' term='Business Insider'/><title type='text'>The half-life of a YouTube video is 6 Days</title><content type='html'>&lt;div style="text-align: justify;"&gt;A very interesting chart from &lt;a href="http://www.businessinsider.com/chart-of-the-day-the-lifecycle-of-a-youtube-video-2010-5?utm_source=Triggermail&amp;amp;utm_medium=email&amp;amp;utm_campaign=SAI_COTD_052710"&gt;Business Insider&lt;/a&gt; which shows that a YouTube video gets half its views in the first 6 days of it being published, down from 14 days in 2008. By way of comparison, computer vulnerabilities have a half-life closer to &lt;a href="http://lukenotricks.blogspot.com/2009/05/half-life-of-vulnerabilities-is-still.html"&gt;30 days&lt;/a&gt;, meaning that our video attention span is much shorter than our patching cycles.&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Wom5eMghH20/TANdHz_cbRI/AAAAAAAAA6U/tTOX18sIHfY/s1600/chart-of-the-day-youtube-video-lifecycle-may-2010.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 240px;" src="http://1.bp.blogspot.com/_Wom5eMghH20/TANdHz_cbRI/AAAAAAAAA6U/tTOX18sIHfY/s320/chart-of-the-day-youtube-video-lifecycle-may-2010.gif" alt="" id="BLOGGER_PHOTO_ID_5477323960609434898" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The data is provided by &lt;a href="http://tubemogul.com/"&gt;TubeMogul&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3115108613546978563?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3115108613546978563/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3115108613546978563' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3115108613546978563'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3115108613546978563'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/half-life-of-youtube-video-is-6-days.html' title='The half-life of a YouTube video is 6 Days'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Wom5eMghH20/TANdHz_cbRI/AAAAAAAAA6U/tTOX18sIHfY/s72-c/chart-of-the-day-youtube-video-lifecycle-may-2010.gif' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3999274349226101664</id><published>2010-05-27T05:43:00.000-07:00</published><updated>2010-08-06T14:08:25.426-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Encrypted search'/><title type='text'>An advance in Encrypted Search</title><content type='html'>&lt;div style="text-align: justify;"&gt;I recently posted in &lt;a href="http://lukenotricks.blogspot.com/2010/03/in-search-of-encrypted-search.html"&gt;The Search for Encrypted Search&lt;/a&gt; an overview of the breakthrough last year made by &lt;a href="http://domino.research.ibm.com/comm/research_projects.nsf/pages/security.homoenc.html"&gt;Craig Gentry&lt;/a&gt; of IBM to search data while it is in encrypted form. The breakthrough was largely theoretical since the required computational overhead to support encrypted search is huge, which for example would increase the time for a Google search by roughly a factor of a trillion.&lt;br /&gt;&lt;br /&gt;In such cases, it is always an open question as to whether the breakthrough will stand as an unimprovable milestone, or be the beginning of series of improvements towards a practical solution. We now have the first evidence that we are dealing with the latter case for encrypted search.&lt;br /&gt;&lt;br /&gt;A &lt;a href="http://www.bristol.ac.uk/news/2010/7030.html"&gt;press release&lt;/a&gt; from the University of Bristol in the UK reports that&lt;br /&gt;&lt;p&gt;&lt;a href="http://www.cs.bris.ac.uk/%7Enigel/"&gt;&lt;/a&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;a href="http://www.cs.bris.ac.uk/%7Enigel/"&gt;Nigel Smart&lt;/a&gt;, Professor of Cryptology in the &lt;a href="http://www.cs.bris.ac.uk/"&gt;Department of Computer Science&lt;/a&gt; at the University of Bristol, will present a paper in Paris this week [Friday 28 May],  which makes a step towards a fully practical system to compute on encrypted data.  The work could have wide ranging impact on areas as diverse as database access, electronic auctions and electronic voting.&lt;/p&gt; &lt;p&gt;Professor Smart said: “We will present a major improvement on a recent encryption scheme invented by IBM in 2009.”&lt;/p&gt; &lt;p&gt;“Our scheme allows for computations to be performed on encrypted data, so it may eventually allow for the creation of systems in which you can store data remotely in a secure manner and still be able to access it.”&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Together with Frederik Vercauteren, from the Katholieke University Leuven in Belgium, Smart has simplifed Gentry’s scheme so that it becomes more practical - not totally so, but an improvement. More information should be available after the paper is published.&lt;br /&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3999274349226101664?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3999274349226101664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3999274349226101664' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3999274349226101664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3999274349226101664'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/advance-in-encrypted-search.html' title='An advance in Encrypted Search'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-719326016393534853</id><published>2010-05-26T08:40:00.001-07:00</published><updated>2010-05-27T01:20:49.205-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Retrospective'/><title type='text'>A look back at posts in May 2009</title><content type='html'>&lt;p align="justify"&gt;This time last year I made some of my favourite posts. First I &lt;a href="http://lukenotricks.blogspot.com/2009/05/two-monthly-blogging-milestones.html"&gt;celebrated&lt;/a&gt; that I had reached about 1,000 visits and 2,000 page views a month, and now I am about double that.&lt;/p&gt;  &lt;p align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/05/rethinking-thresholds-for-account.html"&gt;Rethinking Thresholds for Account Lockouts&lt;/a&gt; was a simple post asking if the 3-strikes-your-out password policy makes sense. I posted my second &lt;a href="http://lukenotricks.blogspot.com/2009/05/password-roundup-2.html"&gt;Password Roundup #2&lt;/a&gt;, and reviewed from Qualys their study on  &lt;a href="http://lukenotricks.blogspot.com/2009/05/half-life-of-vulnerabilities-is-still.html"&gt;The Half-life of Vulnerabilities is still 30 Days&lt;/a&gt;. &lt;/p&gt;  &lt;p align="justify"&gt;I also developed some thoughts why web app bugs don’t get fixed in &lt;a href="http://lukenotricks.blogspot.com/2009/05/28000-question-project-vs-production.html"&gt;The $28,000 Question: Project vs. Production Risk&lt;/a&gt;, after Jeremiah Grossman estimated that 28,000 well-spent dollars could fix the bugs at many sites. &lt;/p&gt;  &lt;p align="justify"&gt;On the crypto side I broke some news about &lt;a href="http://lukenotricks.blogspot.com/2009/05/cost-of-sha-1-collisions-reduced-to-252.html"&gt;The cost of SHA-1 collisions reduced to 2^{52}&lt;/a&gt;, and took a look at &lt;a href="http://lukenotricks.blogspot.com/2009/05/aes-256-and-reputational-risk.html"&gt;AES-256 and Reputational Risk&lt;/a&gt;. The AES post is now on the first page of a Google search for “aes 256” and has brought a steady flow of visits since last May, 1346 in total. I also asked if anyone could verify that the  &lt;a href="http://lukenotricks.blogspot.com/2009/05/total-internet-computational-power-285.html"&gt;Total Internet computational power = 2^{85} operations&lt;/a&gt;, a statement I read in an &lt;a href="http://www.ecrypt.eu.org/ecrypt1/documents/D.SPA.28-1.1.pdf"&gt;ECRYPT report&lt;/a&gt;. I ended up contacting the authors and nope, no one knows where is came from. Sounds possible though.&lt;/p&gt;  &lt;p align="justify"&gt;I also posted &lt;a href="http://lukenotricks.blogspot.com/2009/03/sub-time-crisis-in-web-20.html"&gt;The Sub-Time Crisis in Web 2.0&lt;/a&gt;, my thoughts on information overload in Web 2.0. I only used half the text I typed in from my written notes.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-719326016393534853?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/719326016393534853/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=719326016393534853' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/719326016393534853'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/719326016393534853'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/look-back-at-posts-in-may-2009.html' title='A look back at posts in May 2009'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-584115641225703709</id><published>2010-05-26T08:15:00.001-07:00</published><updated>2010-05-26T08:15:21.107-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><category scheme='http://www.blogger.com/atom/ns#' term='USB'/><title type='text'>How To Password Protect Your Pen Drive</title><content type='html'>&lt;p align="justify"&gt;A nice how-to &lt;a href="http://www.itechmag.com/how-to-password-protect-pen-drive/"&gt;article&lt;/a&gt; on protecting USB drives with a password and encryption using Windows Vista or 7 and Bitlocker. &lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;Do you carry sensitive data in your pen drive? Then you should carefully keep your pen drive. Oh! You mean you are not that careful too. Then I would suggest that you should password protect your pen drive. Yes folks, you can do this by a simple method. This is an added advantage to Windows Vista and Windows 7 users that they can easily password protect their pen drives with the help of &lt;a class="zem_slink" title="BitLocker Drive Encryption" href="http://technet.microsoft.com/en-us/windowsvista/aa905065.aspx" rel="homepage"&gt;BitLocker Drive Encryption&lt;/a&gt;. Its an inbuilt feature of both of these operating systems.&lt;/p&gt;    &lt;p align="justify"&gt;&amp;#160;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p align="justify"&gt;&lt;a href="http://lh5.ggpht.com/_Wom5eMghH20/S_07Bf5eMAI/AAAAAAAAA5s/oYtgLAGpso0/s1600-h/image%5B4%5D.png"&gt;&lt;img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="image" border="0" alt="image" src="http://lh4.ggpht.com/_Wom5eMghH20/S_07Bq4owZI/AAAAAAAAA5w/O9Xzvx4ThBk/image_thumb%5B2%5D.png?imgmax=800" width="240" height="150" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="zemanta-related"&gt;   &lt;h6 style="font-size: 1em" class="zemanta-related-title"&gt;Related articles by Zemanta&lt;/h6&gt;    &lt;ul class="zemanta-article-ul"&gt;     &lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://technologizer.com/2010/03/02/zonealarms-datalock-bitlocker-for-the-rest-of-us/"&gt;ZoneAlarm's DataLock: BitLocker for the Rest of Us&lt;/a&gt; (technologizer.com)&lt;/li&gt;      &lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://seattletimes.nwsource.com/html/businesstechnology/2011482324_ptmrsh03.html?syndication=rss"&gt;BitLocker, USB drives not at fault - it's BIOS&lt;/a&gt; (seattletimes.nwsource.com)&lt;/li&gt;   &lt;/ul&gt; &lt;/div&gt;  &lt;div style="margin-top: 10px; height: 15px" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/c1a747b8-2bd1-4d54-90b2-9ca1249c5091/"&gt;&lt;img style="border-bottom-style: none; border-right-style: none; border-top-style: none; float: right; border-left-style: none" class="zemanta-pixie-img" alt="Reblog this post [with Zemanta]" src="http://img.zemanta.com/reblog_e.png?x-id=c1a747b8-2bd1-4d54-90b2-9ca1249c5091" /&gt;&lt;/a&gt;&lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-584115641225703709?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/584115641225703709/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=584115641225703709' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/584115641225703709'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/584115641225703709'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/how-to-password-protect-your-pen-drive.html' title='How To Password Protect Your Pen Drive'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_Wom5eMghH20/S_07Bq4owZI/AAAAAAAAA5w/O9Xzvx4ThBk/s72-c/image_thumb%5B2%5D.png?imgmax=800' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6081280568754548592</id><published>2010-05-26T08:02:00.000-07:00</published><updated>2010-05-26T08:02:32.758-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Humour'/><title type='text'>iPhone, iPad, iBoard, iMat</title><content type='html'>&lt;a href="http://www.dula.tv/blog/wp-content/uploads/2010/02/iEvolution1.jpg"&gt;This&lt;/a&gt; is just great.&lt;br /&gt;&lt;a href="http://lh3.ggpht.com/_Wom5eMghH20/S_hcokLcnCI/AAAAAAAAA5M/gEOfVlTwqrI/s1600-h/image%5B6%5D.png"&gt;&lt;img alt="image" border="0" height="446" src="http://lh5.ggpht.com/_Wom5eMghH20/S_hcpHswk_I/AAAAAAAAA5Q/y8V9Oe0KNVs/image_thumb%5B4%5D.png?imgmax=800" style="border: 0px none; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" width="167" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6081280568754548592?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6081280568754548592/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6081280568754548592' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6081280568754548592'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6081280568754548592'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/iphone-ipad-iboard-imat.html' title='iPhone, iPad, iBoard, iMat'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_Wom5eMghH20/S_hcpHswk_I/AAAAAAAAA5Q/y8V9Oe0KNVs/s72-c/image_thumb%5B4%5D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6032364203717629782</id><published>2010-05-26T08:01:00.000-07:00</published><updated>2010-08-16T02:55:58.338-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Blogging'/><title type='text'>Shark Fin Posts</title><content type='html'>&lt;div align="justify"&gt;I have been making daily posts this month, partly to see what people read on a given day, and what they keep on reading. Quite a few of the posts turn out to have a hit graph that looks like a shark fin. Here is the one for &lt;a href="http://lukenotricks.blogspot.com/2010/05/what-is-linpack-rating-of-conficker.html"&gt;What is the LINPACK rating of Conficker?&lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://lh6.ggpht.com/_Wom5eMghH20/S_hhS9NW8PI/AAAAAAAAA5U/dTfE0XfF24w/s1600-h/image%5B5%5D.png"&gt;&lt;img alt="image" src="http://lh6.ggpht.com/_Wom5eMghH20/S_hhTDplVUI/AAAAAAAAA5Y/EC5DISFDN74/image_thumb%5B3%5D.png?imgmax=800" style="border: 0px none ; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="80" width="398" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div align="justify"&gt;&lt;br /&gt;What the graph shows is that there are no hits before the post is published (of course!), then a spike when it first appears and for a few days after, ending in just a few hits by a week later or so. After that it’s up to Google, industrious visitors or self-referential posting to raise the hits again. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6032364203717629782?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6032364203717629782/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6032364203717629782' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6032364203717629782'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6032364203717629782'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/shark-fin-posts.html' title='Shark Fin Posts'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_Wom5eMghH20/S_hhTDplVUI/AAAAAAAAA5Y/EC5DISFDN74/s72-c/image_thumb%5B3%5D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3730281797495242532</id><published>2010-05-26T01:00:00.001-07:00</published><updated>2010-05-26T05:19:12.807-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Wireless'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><title type='text'>Google could help enforce new German wireless protection law</title><content type='html'>&lt;div align="justify"&gt;A German court has &lt;a href="http://www.msnbc.msn.com/id/37107291/ns/technology_and_science-security"&gt;ruled&lt;/a&gt; that home users are responsible for creating password-protected home wireless networks, and failing to do so could result in a fine a 100 euros. The rulings stems from a case where a musician sued the owner of a home WiFi network for illegally downloading his music, but since the network owner was away on holiday, the open network was being used by another third party. &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;The maximum fine of 100 euros (or about $120) is about the same as a hefty speeding ticket, and with 26 million WiFi enabled German households, that could add up. All those Google Street View &lt;a href="http://www.theregister.co.uk/2010/05/14/google_street_view_cars_were_collecting_payload_data_from_wifi_networks/"&gt;spycars&lt;/a&gt; could help out with enforcement of the law, since they have been collecting wireless information anyway.&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://lh4.ggpht.com/_Wom5eMghH20/S_hokkwVK-I/AAAAAAAAA5c/F9Y9-SvTEuE/s1600-h/image%5B4%5D.png"&gt;&lt;img alt="image" src="http://lh4.ggpht.com/_Wom5eMghH20/S_holFDrccI/AAAAAAAAA5g/95MtP-Kgb8k/image_thumb%5B2%5D.png?imgmax=800" style="border: 0px none ; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="183" width="240" /&gt;&lt;/a&gt;     &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;Related articles by Zemanta&lt;/div&gt;&lt;div class="zemanta-related"&gt;&lt;ul class="zemanta-article-ul"&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://news.bbc.co.uk/go/rss/-/2/hi/technology/10116606.stm"&gt;Fine for lax home wi-fi security&lt;/a&gt; (news.bbc.co.uk) &lt;/li&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://www.v3.co.uk/v3/news/2263084/german-man-fined-poor-wi"&gt;German man fined for poor Wi-Fi security&lt;/a&gt; (v3.co.uk)&lt;/li&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://go.theregister.com/feed/www.theregister.co.uk/2010/05/13/open_wifi_fines_germany/"&gt;German Wi-Fi networks liable for 3rd party piracy&lt;/a&gt; (go.theregister.com)&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div class="zemanta-pixie" style="height: 15px; margin-top: 10px;"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/cdc0791d-d7c1-4202-853d-ab6c70edae81/" title="Reblog this post [with Zemanta]"&gt;&lt;img alt="Reblog this post [with Zemanta]" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=cdc0791d-d7c1-4202-853d-ab6c70edae81" style="border-style: none; float: right;" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3730281797495242532?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3730281797495242532/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3730281797495242532' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3730281797495242532'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3730281797495242532'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/google-could-help-enforce-new-german.html' title='Google could help enforce new German wireless protection law'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_Wom5eMghH20/S_holFDrccI/AAAAAAAAA5g/95MtP-Kgb8k/s72-c/image_thumb%5B2%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-7060589175500389376</id><published>2010-05-25T01:00:00.001-07:00</published><updated>2010-05-25T01:00:02.112-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ICANN'/><category scheme='http://www.blogger.com/atom/ns#' term='Whit Diffie'/><title type='text'>Whit Diffie does the Can Can</title><content type='html'>&lt;div align="justify"&gt;In &lt;a href="http://lukenotricks.blogspot.com/2009/11/not-so-sunny-for-whit-diffie.html"&gt;Not so sunny for Whit Diffie&lt;/a&gt; I briefly posted on his unexpected exit from Sun soon after their acquisition by Oracle, and taking up a visiting academic position in the UK. Computerworld recently &lt;a href="http://www.computerworld.com.au/article/346694/crypto_guru_whit_diffie_takes_icann_security_job/"&gt;reported&lt;/a&gt; that Diffie has now landed a new position as vice president at ICANN, managing the security of their networks.&amp;nbsp;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;It seems he was just a bit too late to give his blessing to the recent &lt;a href="http://www.computerworld.com.au/article/346694/crypto_guru_whit_diffie_takes_icann_security_job/"&gt;commissioning&lt;/a&gt; of DNSSEC on each of the 13 authoritative names servers of the Internet. However there will be a formal &lt;a href="http://www.root-dnssec.org/wp-content/uploads/2010/02/draft-icann-dnssec-ceremonies-00.txt"&gt;key ceremony&lt;/a&gt; in June which may require a cryptographic high priest, or he may yet bag one of the coveted 14 &lt;a href="http://www.root-dnssec.org/wp-content/uploads/2010/04/ICANN-TCR-Proposal-20100408.pdf"&gt;crypto officers&lt;/a&gt; roles, to whom key recovery shares will be entrusted.&amp;nbsp;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;He also does a good impression of Gandalf the Brown.&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="zemanta-related"&gt;&lt;a href="http://lh5.ggpht.com/_Wom5eMghH20/S_RS8FYE5CI/AAAAAAAAA5E/9ja5FwhqgnQ/s1600-h/image%5B3%5D.png"&gt;&lt;img alt="image" border="0" height="244" src="http://lh4.ggpht.com/_Wom5eMghH20/S_RS81eUruI/AAAAAAAAA5I/ojSJC1n8EC0/image_thumb%5B1%5D.png?imgmax=800" style="border-width: 0px; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" width="165" /&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class="zemanta-related"&gt;&lt;h6 class="zemanta-related-title" style="font-size: 1em;"&gt;Related articles by Zemanta&lt;/h6&gt;&lt;ul class="zemanta-article-ul"&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="https://infosecurity.us/?p=14491"&gt;Diffie Named ICANN VP, Information Security and Cryptography&lt;/a&gt; (infosecurity.us) &lt;/li&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://www.v3.co.uk/v3/news/2263089/encryption-guru-joins-icann"&gt;Encryption guru joins Icann&lt;/a&gt; (v3.co.uk)&lt;/li&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://techdailydose.nationaljournal.com/2010/05/icann-hires-cryptography-pione.php"&gt;ICANN Hires Cryptography Pioneer&lt;/a&gt; (techdailydose.nationaljournal.com)&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div class="zemanta-pixie" style="height: 15px; margin-top: 10px;"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/324a1b8d-f361-4a2f-b8a1-29d0b9307007/" title="Reblog this post [with Zemanta]"&gt;&lt;img alt="Reblog this post [with Zemanta]" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=324a1b8d-f361-4a2f-b8a1-29d0b9307007" style="border-style: none; float: right;" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-7060589175500389376?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/7060589175500389376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=7060589175500389376' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7060589175500389376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7060589175500389376'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/whit-diffie-does-can-can.html' title='Whit Diffie does the Can Can'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_Wom5eMghH20/S_RS81eUruI/AAAAAAAAA5I/ojSJC1n8EC0/s72-c/image_thumb%5B1%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-1189861561321074081</id><published>2010-05-24T14:50:00.001-07:00</published><updated>2010-05-25T01:01:02.623-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Security Bloggers Network under attack?</title><content type='html'>&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Update: This is a hoax mail leading to a rogue site, so please don't click it. Check out the Lijit blog for details (via &lt;/span&gt;&lt;span style="text-decoration: underline; font-weight: bold;"&gt; &lt;/span&gt;&lt;a style="font-weight: bold;" href="http://www.ashimmy.com/"&gt;Alan&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;).&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Just got this from Lijit, the hosting firm for SBN&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Wom5eMghH20/S_r0s8X5scI/AAAAAAAAA5k/CoE2UvHrCXQ/s1600-h/image%5B3%5D.png"&gt;&lt;img style="border: 0px none ; display: inline;" title="image" alt="image" src="http://lh6.ggpht.com/_Wom5eMghH20/S_r0teTWOXI/AAAAAAAAA5o/R4pJRcIOvk8/image_thumb%5B1%5D.png?imgmax=800" border="0" height="197" width="351" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-1189861561321074081?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/1189861561321074081/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=1189861561321074081' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1189861561321074081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1189861561321074081'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/security-bloggers-network-under-attack.html' title='Security Bloggers Network under attack?'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_Wom5eMghH20/S_r0teTWOXI/AAAAAAAAA5o/R4pJRcIOvk8/s72-c/image_thumb%5B1%5D.png?imgmax=800' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6084301401707369934</id><published>2010-05-24T01:00:00.000-07:00</published><updated>2010-05-24T11:44:40.871-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='Black Swan'/><category scheme='http://www.blogger.com/atom/ns#' term='Privacy'/><title type='text'>Facebook juggernauts towards 500 million users</title><content type='html'>&lt;div align="justify"&gt;&lt;a href="http://www.allfacebook.com/2010/05/facebook-working-on-tool-to-block-all-third-party-services/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+allfacebook+%28Facebook+Blog%29"&gt;AllFacebook.com&lt;/a&gt; has &lt;a href="http://www.allfacebook.com/2010/05/facebook-prepares-to-announce-500-million-users/#more-14403"&gt;observed&lt;/a&gt; that, based on linear projections of current sign-up rates, Facebook will pass the 500 million user milestone by the end of June. Using population data &lt;a href="https://www.cia.gov/library/publications/the-world-factbook/rankorder/2119rank.html"&gt;published&lt;/a&gt; by the CIA, we will therefore soon have the situation where only China and India as countries will have more people than Facebook (1.33 and 1.56 billion respectively). Projecting further, Facebook will have twice as many people as the US by year end (around 600 million), and approximately a billion dollars in revenue as well.     &lt;br /&gt;    &lt;br /&gt;&lt;/div&gt;  &lt;div align="justify"&gt;It remains to be seen whether the current privacy &lt;a href="http://www.wired.com/epicenter/2010/05/facebook-rogue/"&gt;backlash&lt;/a&gt; against Facebook introduces unpleasant non-linearities into these projections. A recent informal poll taken by &lt;a href="http://www.sophos.com/blogs/gc/g/2010/05/19/60-facebook-users-quitting-privacy/"&gt;Graham Cluley&lt;/a&gt; of Sophos, found that almost two thirds of the 1588 respondents are considering leaving Facebook. If we round up the respondents to an even 1600, and noting that Facebook has more than 320 million users currently, the survey represents a sample of less than 0.0005% of all users (that’s just 5% of 1% of 1% of the total). Even so, PC World has reported the survey under the headline &lt;a href="http://www.pcworld.com/article/196861/"&gt;Study: 60 Percent of Facebook Users Mulling to Quit&lt;/a&gt; which, I hope you will agree, is a bit grandiose. This is an example of how the non-linearities of reputational risk start accruing against a company with widespread and sustained bad press - and more will follow.     &lt;br /&gt;    &lt;br /&gt;Privacy may yet be the &lt;a class="zem_slink" title="Black Swan" href="http://en.wikipedia.org/wiki/Black_Swan" rel="wikipedia"&gt;Black Swan&lt;/a&gt; of Facebook.&lt;/div&gt;  &lt;div style="margin-top: 10px; height: 15px" class="zemanta-pixie"&gt;&lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6084301401707369934?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6084301401707369934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6084301401707369934' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6084301401707369934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6084301401707369934'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/facebook-juggernauts-towards-500.html' title='Facebook juggernauts towards 500 million users'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-8131562505104006171</id><published>2010-05-23T01:00:00.000-07:00</published><updated>2010-05-23T01:00:01.931-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='Infographic'/><title type='text'>Password Strength Infographic</title><content type='html'>&lt;div align="justify"&gt;Interesting &lt;a href="http://www.cxo.eu.com/media/media-news/infographics/passwords.jpg"&gt;password graphic&lt;/a&gt; from &lt;a href="http://www.cxo.eu.com/media/media-news/infographics/passwords.jpg"&gt;CXO&lt;/a&gt;. I am not quite sure what the people axis is meant to show, or exactly what social class is represented by a Douche. In any case, the examples were verified by Google’s password strength meter, and give a good visual the password spectrum (click to enlarge).&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://www.cxo.eu.com/media/media-news/infographics/passwords.jpg"&gt;&lt;img alt="image" border="0" height="430" src="http://lh4.ggpht.com/_Wom5eMghH20/S_MYg4g9muI/AAAAAAAAA5A/5cJ28J_ZHBA/image%5B10%5D.png?imgmax=800" style="border: 0px none; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" width="337" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-8131562505104006171?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/8131562505104006171/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=8131562505104006171' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8131562505104006171'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8131562505104006171'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/password-strength-infographic.html' title='Password Strength Infographic'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_Wom5eMghH20/S_MYg4g9muI/AAAAAAAAA5A/5cJ28J_ZHBA/s72-c/image%5B10%5D.png?imgmax=800' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-7303061517181733259</id><published>2010-05-22T01:00:00.000-07:00</published><updated>2010-08-17T07:11:51.273-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Humour'/><title type='text'>Y2Gay: gay marriage from the database perspective</title><content type='html'>&lt;div align="justify"&gt;This is a quite interesting &lt;a href="http://qntm.org/gay"&gt;post&lt;/a&gt; which the author describes as a “stream of consciousness about equal parts nuptial rights and Structured Query Language”. The author is actually taking a serious look at how to redesign your database to accommodate gay (same sex) marriages, with quite a few amusing digressions. After outlining 14 detailed steps to follow for the transformation, the conclusion is that &lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Perhaps the simplest solution would be to ban marriage outright. Or, better yet, to declare everybody as married to everybody else. But then what would the database engineers do all day?&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;There are 145 comments as well.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-7303061517181733259?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/7303061517181733259/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=7303061517181733259' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7303061517181733259'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7303061517181733259'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/y2gay-gay-marriage-from-database.html' title='Y2Gay: gay marriage from the database perspective'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-621714756815537077</id><published>2010-05-21T01:00:00.001-07:00</published><updated>2010-05-22T18:14:46.627-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Natural Catastrophe'/><category scheme='http://www.blogger.com/atom/ns#' term='Risk Factors'/><title type='text'>Why have there been so many Natural Catastrophes of late?</title><content type='html'>&lt;div align="justify"&gt;The Freakanomics blog &lt;a href="http://freakonomics.blogs.nytimes.com/2010/04/21/the-world-probably-isnt-ending/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+FreakonomicsBlog+%28Freakonomics+Blog%29&amp;amp;utm_content=Google+Reader"&gt;reports&lt;/a&gt; that &lt;i&gt;Foreign Policy&lt;/i&gt; magazine has &lt;a href="http://www.foreignpolicy.com/articles/2010/04/19/why_have_there_been_so_many_geological_catastrophes_lately"&gt;responded&lt;/a&gt; to concerns that we are living in particularly harrowing times, experiencing more than our share of natural disasters. But FP reports that we are not. What we actually have is a heightened awareness that these events are occurring thanks to rapid and  prolonged media coverage.&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;Based on &lt;a href="http://www.usgs.gov/newsroom/article.asp?ID=2439"&gt;&lt;u&gt; U.S. Geological Survey&lt;/u&gt;&lt;/a&gt; records dating back to 1900, the Earth experiences 16 major earthquakes per year on average, where a major quake is one whose magnitude is 7.0 or more. There were only 6 major quakes in 1986 but 32 in 1943. And this year? 6 so far, so we might be headed for an above average year, but not an extreme year. However there is an increase in the loss of life from earthquakes (650,000 people last decade) due to the expansion of urban sites into fault zones. This is another factor which increases media coverage of these tragedies. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-621714756815537077?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/621714756815537077/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=621714756815537077' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/621714756815537077'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/621714756815537077'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/why-have-there-been-so-many-natural.html' title='Why have there been so many Natural Catastrophes of late?'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-1578840151808127063</id><published>2010-05-20T01:00:00.000-07:00</published><updated>2010-05-20T01:30:05.695-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RSA'/><category scheme='http://www.blogger.com/atom/ns#' term='Conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='RC4'/><title type='text'>Conficker, RSA and RC4</title><content type='html'>&lt;div align="justify"&gt;&lt;span style=";font-family:Georgia,&amp;quot;;font-size:small;"  &gt;I was reading the excellent paper &lt;/span&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://mtc.sri.com/Conficker/" style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;An Analysis of Conficker's Logic and Rendezvous Points&lt;/a&gt; from SRI and was surprised to learn that Conficker botnet updates are distributed at its rendezvous points as encrypted and signed binaries using RC4 and RSA (the “R” in both cases here stands for Ron Rivest). Both the A and B variants of Conficker use these checks to ensure that the updates have been created by the Conficker authors – just like any other software vendor issuing updates and patches. The paper depicts the update process as follows&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://lh5.ggpht.com/_Wom5eMghH20/S-8di9yiF3I/AAAAAAAAA44/322oZs2PhS4/s1600-h/image5.png"&gt;&lt;img alt="image" src="http://lh6.ggpht.com/_Wom5eMghH20/S-8djncgcyI/AAAAAAAAA48/qnSh97SxkQY/image_thumb3.png?imgmax=800" style="border-width: 0px; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="257" width="369" /&gt;&lt;/a&gt; &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;So each Conficker client carries an RSA public key E for signature verification. A Windows binary file F is encrypted and signed as follows&lt;/div&gt;&lt;ul&gt;&lt;li&gt;     Hash F to produce a 512-bit hash M &lt;/li&gt;&lt;li&gt;     Encrypt F with RC4 using M as the key &lt;/li&gt;&lt;li&gt;     Sign M using private key D &lt;/li&gt;&lt;/ul&gt;&lt;div align="justify"&gt;A Conficker client authenticates the encrypted binary as follows&lt;/div&gt;&lt;ul&gt;&lt;li&gt;     Using the embedded public key E, compute the signature verification to recover M &lt;/li&gt;&lt;li&gt;     Decrypt the encrypted binary using RC4 and M as the key &lt;/li&gt;&lt;li&gt;     Verify that the hash of F is in fact M &lt;/li&gt;&lt;/ul&gt;&lt;div align="justify"&gt;For Conficker A, the RSA key is 1024-bits and 2048-bits for Conficker B, both of which are listed in the paper. That’s a large public key for Conficker B but it is dwarfed by the 512-bit symmetric key used in RC4.  Yes RC4 can support such huge key sizes, and I will explain in a future post how this is possible.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-1578840151808127063?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/1578840151808127063/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=1578840151808127063' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1578840151808127063'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1578840151808127063'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/conficker-rsa-and-rc4.html' title='Conficker, RSA and RC4'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_Wom5eMghH20/S-8djncgcyI/AAAAAAAAA48/qnSh97SxkQY/s72-c/image_thumb3.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-512068030198324918</id><published>2010-05-19T01:00:00.000-07:00</published><updated>2010-05-19T01:00:04.540-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ICANN'/><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><title type='text'>Phishing and scamming in the new Top Level Domains</title><content type='html'>&lt;div align="justify"&gt;Earlier this month was the historic event of non-Latin domain names being &lt;a href="http://news.bbc.co.uk/2/hi/technology/10100108.stm"&gt;introduced&lt;/a&gt; on the Internet by &lt;a class="zem_slink" href="http://www.icann.org/" rel="homepage" title="ICANN"&gt;ICANN&lt;/a&gt;. While half the global internet population does not have a Latin language as their mother tongue, sites can now have Arabic names for example and eventually Chinese, Thai and Tamil.&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;At the blog of security company &lt;a href="http://www.beskerming.com/commentary/2010/05/09/509/New_Top_Level_Domains_Open_a_Broader_Internet_for_All?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+beskermingcombined+%28Sunnet+Beskerming+Combined+Feed%29&amp;amp;utm_content=Google+Reader"&gt;Sûnnet Beskerming&lt;/a&gt;  they have a post which points out some security risks associated with the new non-Latin names&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;A risk, which isn't immediately obvious, is that this opens up a new world of opportunity for scammers and phishers to register domains that will visually appear very similar to legitimate sites in the address bar, but which will have a base address significantly different, thanks to being registered in a non-Latin script. By relying on alternate character rendering, this could cause problems for users who may not be able to determine the slight differences between otherwise similar looking characters. It also means that software and tools designed to help detect phishing or XSS attacks will have to expand their repertoire significantly to interpret and assess a much broader range of character and rendering sets.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;The opportunities for typosquatting will probably multiply, and the Register recently &lt;a href="http://www.theregister.co.uk/2010/02/18/google_typosquatting_study/"&gt;reported&lt;/a&gt; this market to be worth almost half a billion dollars annually now. You can read more about this market in &lt;a href="http://www.lightbluetouchpaper.org/2010/02/17/measuring-typosquattings-perpetrators-and-funders/"&gt;Measuring Typosquatting Perpetrators and Funders&lt;/a&gt; by Tyler Moore from Cambridge University.&lt;/div&gt;&lt;div class="zemanta-pixie" style="height: 15px; margin-top: 10px;"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/cf0c998c-7796-4160-ba8b-8b4fc1b0af67/" title="Reblog this post [with Zemanta]"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-512068030198324918?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/512068030198324918/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=512068030198324918' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/512068030198324918'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/512068030198324918'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/phishing-and-scamming-in-new-top-level.html' title='Phishing and scamming in the new Top Level Domains'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-6123478236804009228</id><published>2010-05-18T01:00:00.000-07:00</published><updated>2010-05-18T04:14:49.062-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='cloud computing'/><category scheme='http://www.blogger.com/atom/ns#' term='Privacy'/><title type='text'>Two universities rethink Gmail migration plans</title><content type='html'>&lt;div align="justify"&gt;The University of California at Davis (UCD) and Yale University were considering moving their email systems onto Gmail, but both have put those plans on hold for the moment. The CIO of UCD, Peter Siegel, &lt;a href="http://mashable.com/2010/05/05/uc-davis-gmail/"&gt;said&lt;/a&gt; that he was not prepared to risk the security or privacy of the school’s 30,000 faculty and staff.&lt;br /&gt;&lt;br /&gt;Yale has &lt;a href="http://mashable.com/2010/03/30/yale-delays-switch-to-google-apps/"&gt;delayed&lt;/a&gt; a more general migration to Google apps, including Gmail, citing security and privacy concerns over cloud-based management of their data. Michael Fischer, a computing professor, &lt;a href="http://www.yaledailynews.com/news/university-news/2010/03/30/its-delays-switch-gmail-community-input/"&gt;said&lt;/a&gt; that&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;&lt;span style="font-weight: bold;"&gt;Google stores every piece of data in three centers randomly chosen from the many it operates worldwide&lt;/span&gt; in order to guard the company’s ability to recover lost information — but that also makes the data subject to the vagaries of foreign laws and governments, Fischer said. He added that Google was not willing to provide ITS with a list of countries to which the University’s data could be sent, but only a list of about 15 countries to which the data would not be sent.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;So there is a concern that the personal data of students and faculty is being stored outside US jurisdictions. However neither UCD or Yale ruled out migrating to Google cloud applications once there was adequate transparency for the protection of data.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-6123478236804009228?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/6123478236804009228/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=6123478236804009228' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6123478236804009228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/6123478236804009228'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/two-universities-rethink-gmail.html' title='Two universities rethink Gmail migration plans'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-2779116681090984533</id><published>2010-05-17T01:00:00.000-07:00</published><updated>2010-05-17T01:00:00.749-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IE'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='Browser'/><title type='text'>10 Reasons Why Microsoft's Internet Explorer Dominance is Ending</title><content type='html'>&lt;div align="justify"&gt;It has been widely &lt;a href="http://www.eweek.com/c/a/Application-Development/Google-Chrome-Share-Hits-67-Through-April-766664/"&gt;reported&lt;/a&gt; recently that Microsoft’s share of the global browser market has fallen below 60% for the first time. If this trends continues then Firefox is &lt;a href="http://lukenotricks.blogspot.com/2010/05/projection-firefox-overtakes-ie-by.html"&gt;forecasted&lt;/a&gt; to overtake IE by Christmas 2012. Don Resinger at eWeek has &lt;a href="http://www.eweek.com/c/a/Enterprise-Applications/10-Reasons-Why-Microsofts-Internet-Explorer-Dominance-is-Ending-541588/"&gt;given&lt;/a&gt; his reasons why IE is losing market share (and also mind share) as follows &lt;/div&gt;&lt;ol&gt;&lt;li&gt;     The European Union &lt;/li&gt;&lt;li&gt;     Microsoft's complacency &lt;/li&gt;&lt;li&gt;     Internet Explorer's security &lt;/li&gt;&lt;li&gt;     Rebounding from IE 6 &lt;/li&gt;&lt;li&gt;     The features aren't there &lt;/li&gt;&lt;li&gt;     The Google conundrum &lt;/li&gt;&lt;li&gt;     The united fight against Microsoft &lt;/li&gt;&lt;li&gt;     The educated user &lt;/li&gt;&lt;li&gt;     No-names are actually doing well &lt;/li&gt;&lt;li&gt;     Microsoft is still lost on the Web &lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-2779116681090984533?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/2779116681090984533/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=2779116681090984533' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2779116681090984533'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2779116681090984533'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/10-reasons-why-microsoft-internet.html' title='10 Reasons Why Microsoft&amp;#39;s Internet Explorer Dominance is Ending'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-2870142823468408530</id><published>2010-05-16T01:00:00.000-07:00</published><updated>2010-05-16T14:19:41.883-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Quantitative'/><title type='text'>Numerical Palindromes</title><content type='html'>Someone at work put up the following pattern on a whiteboard&lt;br /&gt;&lt;br /&gt;1 x 1 = 1  &lt;br /&gt;11 x 11 = 121   &lt;br /&gt;111 x 111 = 12321   &lt;br /&gt;1111 x 1111 = 1234321   &lt;br /&gt;11111 x 11111 = 123454321   &lt;br /&gt;111111 x 111111 = 12345654321   &lt;br /&gt;1111111 x 1111111 = 1234567654321   &lt;br /&gt;11111111 x 11111111 = 123456787654321   &lt;br /&gt;111111111 x 111111111 = 12345678987654321&lt;br /&gt;&lt;br /&gt;&lt;div align="justify"&gt;So squaring a number that is all 1’s gives a numerical &lt;a href="http://en.wikipedia.org/wiki/Palindrome"&gt;palindrome&lt;/a&gt;. Why? &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;Well there is a nice simple visual answer&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://lh5.ggpht.com/_Wom5eMghH20/S-21eS5KcPI/AAAAAAAAA4s/ca7Dxa8OLk8/s1600-h/image%5B4%5D.png"&gt;&lt;img alt="image" src="http://lh4.ggpht.com/_Wom5eMghH20/S-21eurYWJI/AAAAAAAAA4w/8uImE4hFCE8/image_thumb%5B2%5D.png?imgmax=800" style="border: 0px none; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="150" width="187" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;More on such patterns &lt;a href="http://members.fortunecity.com/jonhays/palindromes.htm"&gt;here&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-2870142823468408530?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/2870142823468408530/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=2870142823468408530' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2870142823468408530'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2870142823468408530'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/numerical-palindromes.html' title='Numerical Palindromes'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_Wom5eMghH20/S-21eurYWJI/AAAAAAAAA4w/8uImE4hFCE8/s72-c/image_thumb%5B2%5D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-2143469867185964399</id><published>2010-05-15T08:33:00.000-07:00</published><updated>2010-05-15T15:58:15.874-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='whitepaper'/><title type='text'>Great Security white papers and briefs from Damballa</title><content type='html'>Security provider Damballa has a great collection of what papers and briefs for &lt;a href="http://www.damballa.com/solutions/downloads.php"&gt;download&lt;/a&gt;. I have listed a few below, most of which have already been uploaded to Scribd&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.damballa.com/downloads/r_pubs/Opt-In_Botnets.pdf"&gt;The Opt-In Botnet Generation&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.damballa.com/downloads/r_pubs/Aurora_Botnet_Command_Structure.pdf"&gt;The Command Structure of the Aurora Botnet: History, Patterns, and Findings&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.damballa.com/solutions/advanced-persistent-threats.php"&gt;Advanced Persistent Threats: A Brief Description&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.damballa.com/downloads/r_pubs/WP_Malware_Samples_Botnet_Detection.pdf"&gt;Extracting CnC from Malware: The Role of Malware Sample Analysis in Botnet Detection&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.damballa.com/downloads/r_pubs/WP_SerialVariantEvasionTactics.pdf"&gt;Serial Variant Evasion Tactics: Techniques Used to Automatically Bypass Antivirus Technologies&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.damballa.com/downloads/r_pubs/WP_Botnet_Communications_Primer.pdf"&gt;Botnet Communication Topologies: Understanding the intricacies of botnet Command-and-Control&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.damballa.com/downloads/d_pubs/WP_Botnet_vs_Malware.pdf"&gt;The Botnet vs. Malware Relationship: The One-to-One Botnet Myth&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.damballa.com/downloads/d_pubs/WP%20Update%20on%20the%20Enemy%20%282009-05-13%29.pdf"&gt;Update on the Enemy: A Deconstruction of Who Profits from Botnets&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.damballa.com/downloads/d_pubs/WP%20Anatomy%20of%20a%20Targeted%20Attack%20%282008-12-03%29.pdf"&gt;Anatomy of a Targeted Attack&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.damballa.com/downloads/d_pubs/WP%20Layer%208%20%282008-11%29.pdf"&gt;Layer 8: How and Why Targeted Attacks Exploit Your Users&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.damballa.com/downloads/d_pubs/WP%20Technology%20Comparison%20%282008-11%29.pdf"&gt;A Technology Comparison: AV, IDS/IPS and Damballa's Response to Targeted Attacks&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.damballa.com/downloads/d_pubs/WP%20Targeted%20Attacks%20for%20Fun%20and%20Profit%20%282008-10-13%29.pdf"&gt;Targeted Attacks for Fun and Profit: An Executive Guide to A New and Growing Enterprise Threat&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div align="justify"&gt;Also don’t forget the &lt;a href="http://lukenotricks.blogspot.com/2009/06/technical-overviews-at-compass-security.html"&gt;recommendation&lt;/a&gt; I made on the technical overview at Compass Security, a Swiss company, about a year ago.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-2143469867185964399?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/2143469867185964399/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=2143469867185964399' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2143469867185964399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2143469867185964399'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/great-security-white-papers-and-briefs.html' title='Great Security white papers and briefs from Damballa'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3983634018091159510</id><published>2010-05-15T01:00:00.000-07:00</published><updated>2010-05-15T16:00:46.749-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>6 Hot And Sought-After IT Security Skills</title><content type='html'>&lt;div align="justify"&gt;Dark Reading has &lt;a href="http://www.darkreading.com/vulnerability_management/security/government/showArticle.jhtml?articleID=224701863"&gt;reported&lt;/a&gt; a short list of desirable skills in IT Security, partly because the “IT security job market is booming”.  Apparently you’re quite marketable (particularly in the US) if your resume includes&lt;/div&gt;&lt;ol&gt;&lt;li&gt;Incident-handling/response&lt;/li&gt;&lt;li&gt;Compliance know-how&lt;/li&gt;&lt;li&gt;Risk management&lt;/li&gt;&lt;li&gt;Business acumen&lt;/li&gt;&lt;li&gt;Government security clearance&lt;/li&gt;&lt;li&gt;Leadership experience&lt;/li&gt;&lt;/ol&gt;&lt;div style="text-align: justify;"&gt;Frankly, I think if you had a sufficient quantity of skill number 4 you would not be in IT Security.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3983634018091159510?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3983634018091159510/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3983634018091159510' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3983634018091159510'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3983634018091159510'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/6-hot-and-sought-after-it-security.html' title='6 Hot And Sought-After IT Security Skills'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-7678826082658825989</id><published>2010-05-14T14:02:00.001-07:00</published><updated>2010-05-14T14:04:54.184-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='Privacy'/><title type='text'>Privacy degradation at Facebook</title><content type='html'>&lt;div align="justify"&gt;The EFF has an &lt;a href="https://www.eff.org/deeplinks/2010/04/facebook-timeline"&gt;article&lt;/a&gt; on the changes to the privacy policy at Facebook over the last few years noting five significant changes (downgrades) since 2005. In short Facebook has flipped from a private social network to one where your data is largely public by default, mainly since Facebook can profit by selling this information to advertisers and business partners.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;Here is the 2005 privacy language&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;No personal information that you submit to Facebook will be available to any user of the Web Site who does not belong to at least one of the groups specified by you in your privacy settings.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;and the April 2010 version&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;When you connect with an application or website it will have access to General Information about you. The term General Information includes your and your friends’ names, profile pictures, gender, user IDs, &lt;a href="https://www.eff.org/deeplinks/2010/04/handy-facebook-english-translator#connections"&gt;connections&lt;/a&gt;, and any content shared using the Everyone privacy setting. ... The default privacy setting for certain types of information you post on Facebook is set to “everyone.” ... Because it takes two to connect, your privacy settings only control who can see the connection on your profile page. If you are uncomfortable with the connection being publicly available, you should consider removing (or not making) the connection&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;Quite a change. Matt McKeon has &lt;a href="http://mattmckeon.com/facebook-privacy/"&gt;produced&lt;/a&gt; an interesting interactive infographic to depict privacy erosion on Facebook over the last 5 years&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://mattmckeon.com/facebook-privacy/"&gt;&lt;img alt="image" src="http://lh3.ggpht.com/_Wom5eMghH20/S-26ZFpJ7rI/AAAAAAAAA40/ErTU6ZsCJis/image%5B6%5D.png?imgmax=800" style="border: 0px none; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" width="396" height="332" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-7678826082658825989?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/7678826082658825989/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=7678826082658825989' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7678826082658825989'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7678826082658825989'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/privacy-degradation-at-facebook.html' title='Privacy degradation at Facebook'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_Wom5eMghH20/S-26ZFpJ7rI/AAAAAAAAA40/ErTU6ZsCJis/s72-c/image%5B6%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-1883810694918224471</id><published>2010-05-13T16:38:00.000-07:00</published><updated>2010-05-13T16:42:12.208-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><title type='text'>1733 default vendor passwords now online</title><content type='html'>&lt;div align="justify"&gt;&lt;a href="http://cirt.net/passwords"&gt;cirt.net&lt;/a&gt; has made 1733 default passwords for almost 400 vendors available online as a searchable database, complete with a &lt;a href="https://addons.mozilla.org/en-US/firefox/addon/58786"&gt;FireFox plugin&lt;/a&gt;. Changing default passwords is security basics but its not always followed. Last year an Australian student wrote a &lt;a href="http://www.abc.net.au/news/stories/2009/11/09/2737673.htm"&gt;worm &lt;/a&gt;which compromised jailbroken iphones with &lt;a href="http://en.wikipedia.org/wiki/Secure_Shell"&gt;SSH&lt;/a&gt; installed where the default password had not been changed. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-1883810694918224471?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/1883810694918224471/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=1883810694918224471' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1883810694918224471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1883810694918224471'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/1733-default-vendor-passwords-now.html' title='1733 default vendor passwords now online'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-2343599306297147430</id><published>2010-05-13T01:00:00.000-07:00</published><updated>2010-05-13T01:00:00.618-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>The Swan Song of Mark Curphey</title><content type='html'>&lt;div align="justify"&gt;About two months ago Mark Curphey (&lt;a href="http://securitybuddha.com/"&gt;Security Buddha&lt;/a&gt;), in a confessional &lt;a href="http://securitybuddha.com/2010/03/05/farewell-security-buddha-hello-curphey-2-0/"&gt;post&lt;/a&gt;, informed us all of his intentions to move on from IT Security, and reinvent himself 2.0-style into web technology, agile development, social software and user experience. He gave his reasons for moving on as follows&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;For the last few years I have grown increasing disillusioned with the security industry to the point where after nearly two years of thinking and talking about it I have decided that it’s time for me to move on. There is a long list of frustrations and I have seriously thought about a last detailed shot over the bow with some home truths as I see them. The reality is it will probably not be productive. I had commentary about the security circus and the clowns, ring masters and performance artists that play in the big top; commentary about the lack of genuine computer science that finds its way into security; commentary about the lack of business science that is being adopted (why aren’t security people obsessed by Freakonomics?);  commentary about the sad fact that for the most part we are still doing “the same old shit” 15 years after I first started (the definition of insanity is to do the same thing twice and expect a different result); commentary about the farce of PCI (and related standards) and people caring about trivial issues (easy to understand and sensationalist in nature) when looming holes that could have major impacts go unnoticed …….I could go on. People thinking they need “purple dinosaur” features in their security software because some marketing spin says so and commentary about the sheer FUD being pumped out by the marketeers. I have watched an industry spin out of control largely paying lip service to the term risk and watched sectors of it become largely irrelevant outside of their own self-fulfilling set of prophesies. When things go right no one notices (at least outside of security) and when things go wrong everyone points fingers. That’s a tough place to be impactful and remain positive.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;A tough place to be impactful and remain positive. Mark’s new blog is &lt;a href="http://www.curphey.com/"&gt;here&lt;/a&gt;, and he still seems to have a few comments to make on security yet.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-2343599306297147430?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/2343599306297147430/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=2343599306297147430' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2343599306297147430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2343599306297147430'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/swan-song-of-mark-curphey.html' title='The Swan Song of Mark Curphey'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-7224061031699569676</id><published>2010-05-12T01:00:00.001-07:00</published><updated>2010-05-12T01:24:14.798-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Retrospective'/><title type='text'>Some quotes from my first 200 posts</title><content type='html'>&lt;div align="justify"&gt;My 200th post was sent the No Tricks blog yesterday, and to celebrate here are 30 or so quotes I quickly selected out of those posts.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://lukenotricks.blogspot.com/2007/10/no-tricks-name.html"&gt;The No Tricks Blog Name&lt;/a&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;The American basically asked "Why are you guys doing so much better than us?". The Japanese businessman is shown extending his fingers and counting off as he says "Your managers are greedy, your workers are lazy, and ...". But before he can finish even just the most obvious reasons, the American interrupts impatiently and says "I know, I know! But what's the trick?"&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/01/does-it-security-matter.html"&gt;Does IT Security matter?&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Excel is your new best friend&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/06/goodbye-yellow-brick-road.html"&gt;Goodbye Yellow Brick Road&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;We can also stop beating ourselves up on the point that the weakness of IT Risk is the absence of data - the real weakness is poor modelling, and the decisions based on the output of such models.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/03/anonymity-at-edge.html"&gt;Anonymity at the Edge&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Mr. Egerstad has stated that there is no security flaw with Tor - the real threat comes from user expectations that their message contents are being protected end-to-end by Tor, when in fact encryption is only applied to internal Tor network communication.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/07/blackish-swan-for-debian-crypto.html"&gt;A Blackish Swan for Debian Crypto&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Flaws related to encryption always make good copy, and on occasion, strike at the heart of our fundamental beliefs in security. When encryption falters the whole edifice of security seems shaken.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/07/are-aes-256-bit-keys-too-large.html"&gt;Are AES 256-bit keys too large?&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;This may seem an odd question given that since the mid 70's discussions about cryptographic keys have been mainly concerned about their potential shortness.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/03/encryption-back-on-prime-time.html"&gt;The Cold Boot Attack&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;The Princeton team asked Nature the simple question of whether DRAM is cleared on power loss, and the simple answer is no.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/08/long-tail-of-vulnerability-for-a51.html"&gt;Long Tail of Vulnerability for A5/1&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;A5/1 has operated unchanged for the last 21 years but it has now reached its cryptographic end-of-life, engulfed by the march of Moore's Law.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/07/quantum-computing-are-you-shor.html"&gt;Quantum Computing: are you Shor?&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Intel's leading chip line, the x86, has steadily progressed from 286, 386, 486, Pentium and so on, but quantum computers will not be "1000-86" devices - unimaginably faster versions of what we have today.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/10/risk-factors-for-av-scanning.html"&gt;Risk Factors for AV Scanning&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Kapersky has decided to make AV scanning more efficient not by making it faster but by doing less, as determined by risk-based criteria.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/07/some-black-swans-in-it-security.html"&gt;Some Black Swans in IT Security&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;It is common that once the torch of enterprise risk management is kindled in the higher corporate echelons, it is passed down the ranks and settles with IT Security people to assume responsibility for the management of IT Risk. And these people are ill-equipped to do so.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/12/spin-on-passwords-and-aes.html"&gt;The spin on passwords for AES&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Perhaps this reasoning prevailed at Adobe when they recently upgraded their document encryption scheme from AES-128 in v8 to AES-256 in v9. However Adobe later had to &lt;a href="http://blogs.adobe.com/security/2008/12/acrobat_9_and_password_encrypt.html"&gt;announce&lt;/a&gt; that v9 in fact offers &lt;i&gt;less&lt;/i&gt; security against brute force attacks as compared to v8. What went wrong? They forgot about the spin.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/03/woc.html"&gt;Not One in a Million, but a Million and One&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Risk management is about making decisions today that will protect us from the uncertainty of the future. We are not looking for one in a million (the expert) but rather a million and one (the power of many).&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/01/moore-lore-and-attention-crash.html"&gt;Moore's Lore and Attention Crash&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;We feel more informed, more empowered, and more enamoured with the promise of the omnipotent web. The web 2.0 narrative has worked its magic and we tacitly commit into a seemingly virtuous circle of information inflation.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/01/twitter-as-your-personal-content-proxy.html"&gt;Twitter as your Personal Content Proxy&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Navigation and search are just for people who don't have any friends.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/01/scoble-law-of-twitter.html"&gt;Scoble's Law of Twitter&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Disconnect from Twitter when you are receiving more than one tweet per second.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/03/positive-trust-model-and-whitelists.html"&gt;The Positive Trust Model and Whitelisting&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;The AV blacklisting industry has reached a point of diminishing returns - the marginal value of producing additional signatures is minimal, but the underlying model can offer no more advice than to simply keep doing exactly that.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/10/wisdom-of-random-crowd-of-one.html"&gt;The Wisdom of a Random Crowd of One&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;It could be said that PageRank is one part brilliance and two parts daring.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/04/one-way-hash-arguments.html"&gt;“One Way Hash” Arguments&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Often business has the “snappy intuitively appealing arguments without obvious problems” - plus Excel … Snappy and plausible usually wins out over lengthy, detailed and correct.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/04/security-as-non-functional-requirement.html"&gt;The Relegation of Security to NFR Status&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;The observation here is that the security function is no longer called upon to critically underwrite the security risks of a project, with the option to reject.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/04/marcus-ranum-and-point-of-no-return.html"&gt;Marcus Ranum and the Points of No Return&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Compound this disconnect between management and technical people over hundreds of thousands of projects at the corporate, national and international levels, spanning the last 3o years, and you have the disaster Ranum is describing (and lamenting).&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/03/sub-time-crisis-in-web-20.html"&gt;The Sub-Time Crisis in Web 2.0&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;The worst case scenario for Web 2.0 is that we are heading for a singularity, precipitated by dividing our attention into informational units effectively rated at zero content.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/05/aes-256-and-reputational-risk.html"&gt;AES-256 and Reputational Risk&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Imagine you posed the following question to a group of top physicists. You asked them to present you with ideas for new research projects where they could assume that the budget included all the money that we have, all the money that has ever been, and the total financial assets of the world for the next 10 million years. Would the resulting proposals be credible?&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;AES-256 puts cryptanalysts on the same research agenda.&lt;/div&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/06/risk-analysis-of-risk-analysis.html"&gt;A Risk Analysis of Risk Analysis&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;So for complex decisions that potentially have the greatest impact in terms of costs and/or reputation, in exactly the circumstances where a thorough risk assessment is required, transparency rather than rigour is the order of the day.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/07/how-will-my-loved-ones-break-my.html"&gt;How will my loved ones break my password?&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Doctorow remarks that the surprising outcome of this process was the realisation that we are missing a well-known service for handling key escrow in an era of military grade encryption being available to home users.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/09/thoughts-on-cult-of-schneier.html"&gt;Thoughts on the Cult of Schneier&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;I don’t really think that there is a cult in operation over Bruce Schneier, but rather a hero was found when security as an industry needed to believe in heroes.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/10/size-of-our-security-world.html"&gt;The Size of our Security World&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;When I look back at crypto now it seems of similar consequence to the proportions of the Sun and Antares - not merely because my professional interests have changed, but in the vast equation that constitutes ERM, crypto is a variable with minor weighting. Its gravitational force is largely exerted on specialists, and rapidly declines (much faster than the inverse square law) beyond that sphere. It's just a pixel on the football-field sized collage of ERM.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/11/how-big-is-2128.html"&gt;How big is 2^{128}?&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;So that’s 1,000 years of computation by a cluster that would envelope the earth to a height of one metre.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/11/tls-renegotiation-attack-for-impatient.html"&gt;The TLS Renegotiation Attack for the Impatient&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;There are many posts and news articles of late on the TLS Renegotiation Attack. I had hoped that just by skimming a large number of these that some process of web osmosis would magically transfer an understanding of this vulnerability to me.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/11/not-so-sunny-for-whit-diffie.html"&gt;Not so sunny for Whit Diffie&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;In the short term (and maybe the longer term as well) Diffie sees the cloud as a matter of trust. He advises to pick your supplier like you pick your accountant.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/11/internet-repetition-code.html"&gt;The Internet Repetition Code&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;For each of us the web is a noisy channel, which we express through the need to search, subscribe, aggregate, recommend, post, tweet – in short a great cull of what finds its way onto our screens.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2009/11/security-muggles.html"&gt;Security Muggles&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;And while the traits of detail, accuracy and correctness are necessary for IT activities, they are fundamentally at odds with the type of messages and opinions that senior managers are expecting.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2010/02/usb-password-vulnerability.html"&gt;The USB Password Vulnerability&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Some  articles and posts have focussed on verifying passwords in software as the culprit, which is partly true, but the real issue is not software but insecure programming of software.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2010/03/in-search-of-encrypted-search.html"&gt;In Search of Encrypted Search&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;Gentry has estimated that building a circuit to perform an encrypted Google search with encrypted keywords would multiply the current computing time by around 1 trillion.&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-7224061031699569676?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/7224061031699569676/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=7224061031699569676' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7224061031699569676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7224061031699569676'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/some-quotes-from-my-first-200-posts.html' title='Some quotes from my first 200 posts'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-87779405988884863</id><published>2010-05-11T01:00:00.000-07:00</published><updated>2010-05-11T04:15:24.599-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Power Laws'/><category scheme='http://www.blogger.com/atom/ns#' term='FireFox'/><category scheme='http://www.blogger.com/atom/ns#' term='Browser'/><title type='text'>The Tab Power Law for Firefox</title><content type='html'>&lt;div align="justify"&gt;Mozilla has &lt;a href="http://blog.mozilla.com/metrics/2010/03/31/mozillas-q1-2010-analyst-report-state-of-the-internet/"&gt;released&lt;/a&gt; its 2010 Q1 analyst &lt;a href="https://wiki.mozilla.org/images/e/ed/Analyst_report_Q1_2010.pdf"&gt;report&lt;/a&gt; on the state of the internet. The report was created to "provide a high-level view of key metrics on an ongoing basis and to share some interesting insights". Well, its a little short at 12 well-spaced pages, and the summary bullets are not that exciting&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Firefox’s worldwide market share hovering near 30%&lt;/li&gt;&lt;li&gt;Firefox adoption is growing most dramatically in Russia&lt;/li&gt;&lt;li&gt;People start their work day earliest in Hawaii and Wyoming; latest start to the day is in New York&lt;/li&gt;&lt;li&gt;People in South American like applying Personas (themes) to their browser; people in Antarctica love add-ons&lt;/li&gt;&lt;/ul&gt;&lt;div align="justify"&gt;For me the most interesting observation was the number of open tabs people work with in FireFox, as shown in the graph below.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://lh3.ggpht.com/_Wom5eMghH20/S928xMk1A6I/AAAAAAAAA3Q/0-j-IqAiCgc/s1600-h/image%5B5%5D.png"&gt;&lt;img alt="image" src="http://lh3.ggpht.com/_Wom5eMghH20/S928yBnpn1I/AAAAAAAAA3U/sO5Mgo62wdc/image_thumb%5B3%5D.png?imgmax=800" style="border: 0px none ; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="384" width="394" /&gt;&lt;/a&gt; &lt;/div&gt;&lt;div align="justify"&gt;Most people use 2 to 3 tabs, however the maximum observed value was over 600! Also, since the median is 2.9, over half the people use almost 3 or more tabs. The graph above clearly has a power law structure, and in this case, quite a long tail.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-87779405988884863?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/87779405988884863/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=87779405988884863' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/87779405988884863'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/87779405988884863'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/tab-power-law-for-firefox.html' title='The Tab Power Law for Firefox'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_Wom5eMghH20/S928yBnpn1I/AAAAAAAAA3U/sO5Mgo62wdc/s72-c/image_thumb%5B3%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-4270409682104112126</id><published>2010-05-10T01:00:00.000-07:00</published><updated>2010-05-10T01:30:18.276-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cryptography'/><category scheme='http://www.blogger.com/atom/ns#' term='Elliptic Curves'/><category scheme='http://www.blogger.com/atom/ns#' term='NSA'/><title type='text'>Elliptic Curves in ASCII</title><content type='html'>&lt;div align="justify"&gt;There is a new Internet draft on &lt;a href="http://tools.ietf.org/html/draft-mcgrew-fundamental-ecc-02"&gt;Fundamental Elliptic Curve Cryptography Algorithms&lt;/a&gt; by D. McGrew of CISCO and K. Igoe of the NSA.  The NSA author might seem out of character for that particular 3-letter agency, but it's no secret that &lt;a class="zem_slink" href="http://en.wikipedia.org/wiki/Elliptic_curve" rel="wikipedia" title="Elliptic curve"&gt;elliptic curves&lt;/a&gt; are the NSA’s preferred form of public key system over RSA. It is somewhat impressive that the authors would even attempt to write up such a complex mathematical topic using the &lt;a class="zem_slink" href="http://en.wikipedia.org/wiki/ASCII" rel="wikipedia" title="ASCII"&gt;ASCII&lt;/a&gt; formatting that the Internet Society has insisted on for several decades now. ASCII used to be the lowest common denominator for formatting in the 70’s, but surely now it is HTML or PDF.&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;Be that as it may, the document is well written and builds up elliptic curves from the basics of modular arithmetic, groups, finite fields before defining elliptic groups. Of course not all types of curves are examined – the document would need to be much longer than 20 pages – but it is self-contained. The section on the security of elliptic curves is a quite short however. After developing the required terminology and background, the authors focus on defining a method for elliptic curve signatures based on the work of two Japanese researchers Koyama and Tsuruoka. This signature variant was probably chosen to avoid any intellectual property issues with more well-known methods that are heavily patented, particularly with respect to efficient implementations. &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;An interesting read as long as you can handle sustained Courier font. If you are looking for some more background on elliptic curves for security please take a look at Luther Martin’s posts at Voltage, and 4 are listed below ASCII girl&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://lh5.ggpht.com/_Wom5eMghH20/S93Tvd4uH1I/AAAAAAAAA3Y/dt6j79_4EDg/s1600-h/image12.png"&gt;&lt;img alt="image" src="http://lh5.ggpht.com/_Wom5eMghH20/S93TwKnX65I/AAAAAAAAA3c/TSt2QJaIpfg/image_thumb6.png?imgmax=800" style="border-width: 0px; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="240" width="151" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="zemanta-related"&gt;&lt;h6 class="zemanta-related-title" style="font-size: 1em;"&gt;Related articles by Zemanta&lt;/h6&gt;&lt;ul class="zemanta-article-ul"&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://superconductor.voltage.com/2010/04/the-jinvariant-of-an-elliptic-curve.html"&gt;The j-invariant of an elliptic curve&lt;/a&gt; (superconductor.voltage.com) &lt;/li&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://superconductor.voltage.com/2010/02/an-example-of-bad-reduction-mod-p.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%253A+voltage%252FVDQg+%2528Superconductor%2529"&gt;An example of bad reduction mod p&lt;/a&gt; (superconductor.voltage.com) &lt;/li&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://superconductor.voltage.com/2010/03/divisors-on-elliptic-curves.html"&gt;Divisors on elliptic curves revisited&lt;/a&gt; (superconductor.voltage.com) &lt;/li&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://superconductor.voltage.com/2010/04/isomorphic-elliptic-curves.html"&gt;Isomorphic elliptic curves&lt;/a&gt; (superconductor.voltage.com) &lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div class="zemanta-pixie" style="height: 15px; margin-top: 10px;"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/0f98fff2-5c38-42e2-9ca0-18141166694d/" title="Reblog this post [with Zemanta]"&gt;&lt;img alt="Reblog this post [with Zemanta]" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=0f98fff2-5c38-42e2-9ca0-18141166694d" style="border-style: none; float: right;" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-4270409682104112126?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/4270409682104112126/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=4270409682104112126' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4270409682104112126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4270409682104112126'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/elliptic-curves-in-ascii.html' title='Elliptic Curves in ASCII'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_Wom5eMghH20/S93TwKnX65I/AAAAAAAAA3c/TSt2QJaIpfg/s72-c/image_thumb6.png?imgmax=800' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-8352057310746180921</id><published>2010-05-09T08:58:00.000-07:00</published><updated>2010-05-09T08:58:38.548-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CISO'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Management'/><title type='text'>What are the CISO's most useful instruments?</title><content type='html'>&lt;div style="text-align: justify;"&gt;Matthew Hackling, provider of outlandish security punditry from an Australian perspective, has &lt;a href="http://www.infamousagenda.com/2010/05/what-are-cisos-most-useful-instruments.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+SecurityBloggersNetwork+%28Security+Bloggers+Network%29&amp;amp;utm_content=Google+Reader"&gt;posted&lt;/a&gt; a suggested list of artefacts that a CISO should have to act as the conduct of the information security symphony in an organisation,&lt;/div&gt;&lt;ol&gt;&lt;li&gt;Audit issue register (lead violin, sometimes a bit too screechy) &lt;/li&gt;&lt;li&gt;Enterprise risk register &lt;/li&gt;&lt;li&gt;Significant business unit risk registers &lt;/li&gt;&lt;li&gt;Compliance requirement register (the timpani) &lt;/li&gt;&lt;li&gt;Mapping of compliance requirements to your Information Security Management System (&lt;a class="zem_slink" href="http://en.wikipedia.org/wiki/Information_security_management_system" rel="wikipedia" title="Information security management system"&gt;ISMS&lt;/a&gt;) &lt;/li&gt;&lt;li&gt;Control testing management reports and database &lt;/li&gt;&lt;li&gt;Management reporting template &lt;/li&gt;&lt;li&gt;Existing enterprise security plan and perhaps security plans of significant business units &lt;/li&gt;&lt;li&gt;List of business units by criticality &lt;/li&gt;&lt;li&gt;List of business processes by criticality within business units &lt;/li&gt;&lt;li&gt;List of business applications by criticality with function descriptions &lt;/li&gt;&lt;li&gt;Current security budget &lt;/li&gt;&lt;li&gt;Business case template and submission procedures &lt;/li&gt;&lt;li&gt;Document map of ISMS with status of documents within it (approved, under review, drafted, not started) &lt;/li&gt;&lt;li&gt;Organisation chart &lt;/li&gt;&lt;li&gt;List of security projects with budget and status &lt;/li&gt;&lt;li&gt;List of business projects by criticality to business success &lt;/li&gt;&lt;li&gt;Enterprise security architecture ( well at least the "zone model" with zones mapped to examples in the existing environment ) &lt;/li&gt;&lt;li&gt;Data classification scheme&lt;/li&gt;&lt;/ol&gt;&lt;div class="zemanta-pixie" style="height: 15px; margin-top: 10px;"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/a666cba0-4b5e-43ea-8d49-2769c9d7a440/" title="Reblog this post [with Zemanta]"&gt;&lt;img alt="Reblog this post [with Zemanta]" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=a666cba0-4b5e-43ea-8d49-2769c9d7a440" style="border-style: none; float: right;" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-8352057310746180921?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/8352057310746180921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=8352057310746180921' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8352057310746180921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/8352057310746180921'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/what-are-ciso-most-useful-instruments.html' title='What are the CISO&amp;#39;s most useful instruments?'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-1175767093334852201</id><published>2010-05-08T15:50:00.000-07:00</published><updated>2010-05-10T01:42:17.245-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Prezi'/><category scheme='http://www.blogger.com/atom/ns#' term='Visualization'/><category scheme='http://www.blogger.com/atom/ns#' term='Infographic'/><title type='text'>Infographic on Afghan scenarios with Prezi</title><content type='html'>&lt;div align="justify"&gt;I, like quite a few other people, &lt;a href="http://lukenotricks.blogspot.com/2010/05/when-we-understand-that-slide-well-have.html"&gt;posted&lt;/a&gt; on the recent NYT article which showed a horrendously complex PowerPoint slide created to depict the situation in Afghanistan, and the challenges facing US military decision makers. &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;Another more informative view of the Afghan predicament can be found at a German site called &lt;a href="http://www.theafghanconflict.de/"&gt;The Afghan Conflict&lt;/a&gt;, which appears to be the result of collaboration between &lt;a href="http://www.flickr.com/photos/marctiedemann/"&gt;Marc Tiedemann&lt;/a&gt; and several colleagues to produce a visual map of possible scenarios in the conflict. From the site&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;When we started researching this topic we very quickly saw, that the debate whether to pull out the troops, staying or even enforcing is not too much about arguments, it’s a battle of possible scenarios. Every side seems to have their own positive and negative visions of how things will happen in the future if certain steps are done. The resulting map The Afghan Conflict - A Map of Possible Scenarios is the attempt of a summary of the most popular possible scenarios around the afghan conflict, according to a pullout or stay of the Allied troops. And is based on interviews with journalists, politicians and political foundations.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;The resulting scenario map is quite large and the authors have not tried to compress it onto a single PowerPoint slide for convenience of presentation (double click the image below to see a larger version).&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://www.theafghanconflict.de/img/AC_hiRes.jpg"&gt;&lt;img alt="image" src="http://lh4.ggpht.com/_Wom5eMghH20/S-Xnd_njunI/AAAAAAAAA4g/mZPrFjWv60Q/image%5B24%5D.png?imgmax=800" style="border: 0px none ; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="152" width="385" /&gt;&lt;/a&gt; &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;The scenario map is available as a poster but also as a &lt;a href="http://prezi.com/"&gt;Prezi animation&lt;/a&gt; which allows you to navigate across the scenarios and zoom in and out of detail (I cannot find a way to link to the Prezi animation directly so you will have to view it from the  &lt;a href="http://www.theafghanconflict.de/"&gt;The Afghan Conflict&lt;/a&gt; site). I will have more to say about Prezi in future posts, and it appears to be a good navigation tool for complex “infoscapes” like the Afghan situation. In the meantime please take a look at the showcase presentations at the Prezi site.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-1175767093334852201?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/1175767093334852201/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=1175767093334852201' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1175767093334852201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1175767093334852201'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/infographic-on-afghan-scenarios-with.html' title='Infographic on Afghan scenarios with Prezi'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_Wom5eMghH20/S-Xnd_njunI/AAAAAAAAA4g/mZPrFjWv60Q/s72-c/image%5B24%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3228714055620426140</id><published>2010-05-08T01:00:00.000-07:00</published><updated>2010-05-08T01:00:01.399-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><category scheme='http://www.blogger.com/atom/ns#' term='Spreadsheet'/><title type='text'>OpenSAMM Assessment Spreadsheet v0.4 available</title><content type='html'>&lt;div align="justify"&gt;OWASP has a project called  &lt;a href="http://www.owasp.org/index.php/Category:Software_Assurance_Maturity_Model"&gt;OpenSAMM&lt;/a&gt;, or the Open Software Assurance Maturity Model (SAMM). There is an audit framework for OpenSAMM, implemented as a spreadsheet with about 80 questions, grouped into collection of business functions and security practices. You can get the spreadsheet &lt;a href="http://un-excogitate.org/archives/2010/04/04/opensamm-assessment-spreadsheet/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://lh3.ggpht.com/_Wom5eMghH20/S9xyHI5-LZI/AAAAAAAAA24/bZK99_JXy5E/s1600-h/image%5B6%5D.png"&gt;&lt;img alt="image" border="0" height="141" src="http://lh6.ggpht.com/_Wom5eMghH20/S9xyHspv3gI/AAAAAAAAA28/vaKtxzi0cxY/image_thumb%5B4%5D.png?imgmax=800" style="border: 0px none; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" width="408" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3228714055620426140?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3228714055620426140/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3228714055620426140' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3228714055620426140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3228714055620426140'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/opensamm-assessment-spreadsheet-v04.html' title='OpenSAMM Assessment Spreadsheet v0.4 available'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_Wom5eMghH20/S9xyHspv3gI/AAAAAAAAA28/vaKtxzi0cxY/s72-c/image_thumb%5B4%5D.png?imgmax=800' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-4692513950873798193</id><published>2010-05-07T04:00:00.000-07:00</published><updated>2010-05-07T04:45:04.935-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud computing'/><title type='text'>Cute Cloud Computing graphic</title><content type='html'>&lt;a href="http://lh4.ggpht.com/_Wom5eMghH20/S9xAapA5jiI/AAAAAAAAA1w/qQQywOSh8nY/s1600-h/image%5B5%5D.png"&gt;&lt;img alt="image" src="http://lh4.ggpht.com/_Wom5eMghH20/S9xAbgppmvI/AAAAAAAAA10/KOCOB8tFdt8/image_thumb%5B3%5D.png?imgmax=800" style="border-width: 0px; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="241" width="360" /&gt;&lt;/a&gt;&lt;br /&gt;(&lt;a href="http://www.scribd.com/doc/30774717/Cloud-Computing-for-Criminals"&gt;source&lt;/a&gt;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-4692513950873798193?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/4692513950873798193/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=4692513950873798193' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4692513950873798193'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4692513950873798193'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/cute-cloud-computing-graphic.html' title='Cute Cloud Computing graphic'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_Wom5eMghH20/S9xAbgppmvI/AAAAAAAAA10/KOCOB8tFdt8/s72-c/image_thumb%5B3%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-7949644932340669528</id><published>2010-05-07T01:00:00.001-07:00</published><updated>2010-05-08T12:09:46.618-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IE'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='Browser'/><title type='text'>Projection: Firefox overtakes IE by Christmas 2012</title><content type='html'>&lt;div align="justify"&gt;It has been &lt;a href="http://news.bbc.co.uk/2/hi/10095730.stm"&gt;widely reported&lt;/a&gt; that the global market share for Microsoft’s Internet Explorer has fallen below 60%. While pundits, commentators and technologists discuss the future of IE, &lt;a href="http://www.zdnet.com/blog/igeneration/internet-explorer-market-share-at-all-time-low-time-to-give-up/4888"&gt;Zack Whittaker at ZDNet&lt;/a&gt;  has done “a bit of maths” and produced the following extrapolation, showing FireFox passing IE market share around December 2012.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://lh5.ggpht.com/_Wom5eMghH20/S-M53MgN3UI/AAAAAAAAA4Y/SKNdSZYcIQ0/s1600-h/image%5B5%5D.png"&gt;&lt;img alt="image" src="http://lh4.ggpht.com/_Wom5eMghH20/S-M53j8KILI/AAAAAAAAA4c/LYrvFAehEnE/image_thumb%5B3%5D.png?imgmax=800" style="border: 0px none; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="185" width="367" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div align="justify"&gt;Assuming Zack has done his Excel sums correctly,  the prediction is still pure data extrapolation. The last year has been extremely unfavourable for IE with its security flaws and the playing out of the European anti-trust case against Microsoft. Redmond may still be able to turn the prediction around. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-7949644932340669528?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/7949644932340669528/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=7949644932340669528' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7949644932340669528'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/7949644932340669528'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/projection-firefox-overtakes-ie-by.html' title='Projection: Firefox overtakes IE by Christmas 2012'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_Wom5eMghH20/S-M53j8KILI/AAAAAAAAA4c/LYrvFAehEnE/s72-c/image_thumb%5B3%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-4685484826450201354</id><published>2010-05-06T01:00:00.000-07:00</published><updated>2010-05-06T01:00:05.415-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Visualization'/><category scheme='http://www.blogger.com/atom/ns#' term='PowerPoint'/><title type='text'>When we understand that slide, we’ll have won the war</title><content type='html'>&lt;div align="justify"&gt;The title is a comment &lt;a href="http://www.nytimes.com/2010/04/27/world/27powerpoint.html"&gt;reported&lt;/a&gt; in the NYT by Gen. Stanley A. McChrystal, the leader of American and NATO forces in Afghanistan, when shown the PowerPoint slide below (see a larger version &lt;a href="http://msnbcmedia.msn.com/i/MSNBC/Components/Photo/2009/December/091202/091203-engel-big-9a.jpg"&gt;here&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://lh6.ggpht.com/_Wom5eMghH20/S9yBjyc-cjI/AAAAAAAAA3A/m0mlG29FSyo/s1600-h/image%5B5%5D.png"&gt;&lt;img alt="image" src="http://lh6.ggpht.com/_Wom5eMghH20/S9yBknqLNAI/AAAAAAAAA3E/IlILhAXSwEs/image_thumb%5B3%5D.png?imgmax=800" style="border: 0px none ; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="234" width="403" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div align="justify"&gt;&lt;br /&gt;The slide was meant to depict  the complexity of American military strategy in Afghanistan, and it seems to  have over-succeeded. Apparently PowerPoint is not just an obsession with business managers but also with senior military commanders as well. But behind all the PowerPoint jokes are "serious concerns that the program [PowerPoint] stifles discussion, critical thinking and thoughtful decision-making”. The following observation is quite insightful&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;[PowerPoint] slides impart less information than a five-page paper can hold, and that they relieve the briefer of the need to polish writing to convey an analytic, persuasive point. Imagine lawyers presenting arguments before the Supreme Court in slides instead of legal briefs.&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;But even with mounting reservations over the ability of PowerPoint to usefully represent military situations, no one is forecasting any change – it is just too embedded in the military, as it is elsewhere. And while  “no one is suggesting that PowerPoint is to blame for mistakes in the current wars”, it takes a great deal of time with PowerPoint to keep a war going, let alone end it.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-4685484826450201354?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/4685484826450201354/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=4685484826450201354' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4685484826450201354'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/4685484826450201354'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/when-we-understand-that-slide-well-have.html' title='When we understand that slide, we’ll have won the war'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_Wom5eMghH20/S9yBknqLNAI/AAAAAAAAA3E/IlILhAXSwEs/s72-c/image_thumb%5B3%5D.png?imgmax=800' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3444577740729055684</id><published>2010-05-05T01:00:00.001-07:00</published><updated>2010-08-16T07:48:02.921-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud computing'/><title type='text'>The power limit of Cloud Computing</title><content type='html'>&lt;div align="justify"&gt;In February I &lt;a href="http://lukenotricks.blogspot.com/2010/02/lews-law-it-expenses-converge-to-cost.html"&gt;posted&lt;/a&gt; on Lew’s law, a prediction by former SUN CTO &lt;a class="zem_slink" href="http://www.crunchbase.com/person/lew-tucker" rel="crunchbase" title="Lew Tucker"&gt;Lew Tucker&lt;/a&gt; stating that IT expenses will increasingly track to the cost of electricity. Tucker gave a keynote presentation on &lt;a href="http://www.cloudconnectevent.com/2010/presentations/free/50-lew-tucker.pdf"&gt;The Ultimate Cost of Computing&lt;/a&gt; at the recent &lt;a href="http://www.cloudconnectevent.com/"&gt;Cloud Connect&lt;/a&gt; conference, where he gives some more insights into his views on the evolving cost model for cloud computing.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;Tucker begins by stating that the driving forces of cloud computing are technology and the market, symbolised by &lt;a class="zem_slink" href="http://en.wikipedia.org/wiki/Gordon_Moore" rel="wikipedia" title="Gordon Moore"&gt;Gordon Moore&lt;/a&gt; and &lt;a class="zem_slink" href="http://en.wikipedia.org/wiki/Adam_Smith" rel="wikipedia" title="Adam Smith"&gt;Adam Smith&lt;/a&gt; (the author of the &lt;a class="zem_slink" href="http://en.wikipedia.org/wiki/Invisible_hand" rel="wikipedia" title="Invisible hand"&gt;invisible hand&lt;/a&gt; of the market). He shows that &lt;a class="zem_slink" href="http://en.wikipedia.org/wiki/Moore%27s_law" rel="wikipedia" title="Moore's law"&gt;Moore’s law&lt;/a&gt;, the doubling of computing power every 1 – 2 years, continues to be achieved by the microprocessor industry as a whole, with computing power increasing by a factor of one million over the last 40 years.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://lh6.ggpht.com/_Wom5eMghH20/S9xsgkBHE0I/AAAAAAAAA2Q/r0xh_SGGMuY/s1600-h/image%5B17%5D.png"&gt;&lt;img alt="image" src="http://lh5.ggpht.com/_Wom5eMghH20/S9xsg99lbsI/AAAAAAAAA2U/D286cajTXS0/image_thumb%5B9%5D.png?imgmax=800" style="border-width: 0px; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="205" width="306" /&gt;&lt;/a&gt; &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;In the last few years these gains have been supported by multi-core processors, issues with power consumption, chip cooling and production costs invalidate the assumption that smaller components are the most cost effective strategy to increase processing capability.  The future probably then lies with more chips of a given complexity rather than with chips of increased complexity. So Moore's Law may actually be maintained but not for the reasons that Moore predicted (increased chip density).&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;A key question for Lew is whether cloud service providers can pass on the benefits of Moore’s law to customers. Already the cost per hour of a CPU (instance) has dropped from $1 to less than two hundredths of a cent over the last 15 years.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://lh3.ggpht.com/_Wom5eMghH20/S9xshTEVAdI/AAAAAAAAA2Y/NZNjNTaFioQ/s1600-h/image%5B11%5D.png"&gt;&lt;img alt="image" src="http://lh6.ggpht.com/_Wom5eMghH20/S9xshuMLULI/AAAAAAAAA2c/3Aycgr2-e3g/image_thumb%5B5%5D.png?imgmax=800" style="border-width: 0px; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="152" width="315" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;But what are the real costs of cloud computing? Are faster computers the deciding factor? Apparently not - it's administration and power consumption.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://lh6.ggpht.com/_Wom5eMghH20/S9xsiIr582I/AAAAAAAAA2g/VpSRyiqOeyo/s1600-h/image%5B23%5D.png"&gt;&lt;img alt="image" src="http://lh4.ggpht.com/_Wom5eMghH20/S9xsid6yuKI/AAAAAAAAA2k/1hvdGcyiSZU/image_thumb%5B13%5D.png?imgmax=800" style="border-width: 0px; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="195" width="291" /&gt;&lt;/a&gt; &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;Cloud computing wins by leveraging automation, virtualization, dynamic provision, massive scaling and multi-tenancy, which all lead to power becoming the dominant cost (mainly for scaling and cooling). And data centre power consumption has already doubled in the last 5 years&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://lh5.ggpht.com/_Wom5eMghH20/S9xsi27Vh0I/AAAAAAAAA2o/fJYpk4Tr3tM/s1600-h/image%5B35%5D.png"&gt;&lt;img alt="image" src="http://lh4.ggpht.com/_Wom5eMghH20/S9xsjEpbMNI/AAAAAAAAA2s/KrYW2D7ITVc/image_thumb%5B21%5D.png?imgmax=800" style="border-width: 0px; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="177" width="327" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;So Lew’s law can now be started as&lt;/div&gt;&lt;blockquote&gt;&lt;div align="justify"&gt;&lt;i&gt;In the cloud, the cost of computing will continue to fall bounded only by cost of energy&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div align="justify"&gt;Being an ex-SUN man, Lew must take some delight in this final slide&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://lh4.ggpht.com/_Wom5eMghH20/S9xsj6UIt6I/AAAAAAAAA2w/84w1E23a62Q/s1600-h/image%5B41%5D.png"&gt;&lt;img alt="image" src="http://lh5.ggpht.com/_Wom5eMghH20/S9xskCWcjyI/AAAAAAAAA20/sLrzqUyyi2I/image_thumb%5B25%5D.png?imgmax=800" style="border-width: 0px; display: block; float: none; margin-left: auto; margin-right: auto;" title="image" border="0" height="148" width="317" /&gt;&lt;/a&gt; &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="zemanta-pixie" style="height: 15px; margin-top: 10px;"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/0c71928a-e338-4b96-97ab-16781d0d655e/" title="Reblog this post [with Zemanta]"&gt;&lt;img alt="Reblog this post [with Zemanta]" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=0c71928a-e338-4b96-97ab-16781d0d655e" style="border-style: none; float: right;" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3444577740729055684?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3444577740729055684/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3444577740729055684' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3444577740729055684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3444577740729055684'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/power-limit-of-cloud-computing.html' title='The power limit of Cloud Computing'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_Wom5eMghH20/S9xsg99lbsI/AAAAAAAAA2U/D286cajTXS0/s72-c/image_thumb%5B9%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-2274643881714077463</id><published>2010-05-04T01:00:00.000-07:00</published><updated>2010-05-04T04:54:17.930-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='USB'/><title type='text'>Conficker and your health</title><content type='html'>&lt;a href="http://lh3.ggpht.com/_Wom5eMghH20/S9xbjdzFieI/AAAAAAAAA14/ZfWcSWSYpfA/s1600-h/image%5B3%5D.png"&gt;&lt;img alt="image" src="http://lh5.ggpht.com/_Wom5eMghH20/S9xbkI1cmFI/AAAAAAAAA2A/g034sL35rIA/image_thumb%5B2%5D.png?imgmax=800" style="border: 0px none ; display: inline; margin-left: 0px; margin-right: 0px;" title="image" align="left" border="0" height="66" width="91" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div align="justify"&gt;A USB stick inserted into a terminal in one of its car parks is being &lt;a href="http://www.stuff.co.nz/waikato-times/news/3434167/Health-chaos-blame-a-stick"&gt;blamed&lt;/a&gt; for a  massive Conficker infection of Waikato hospital in New Zealand that broke out last December. Over a 3 day period this incident infected 3,000 computer on the hospital network, impacting around 5,000 hospital staff. A full report on the incident is still forthcoming, but a USB-borne strain of Conficker is expected to be named as the culprit. A similar &lt;a href="http://www.theregister.co.uk/2010/02/09/conficker_nhs_outbreaks/"&gt;incident&lt;/a&gt; occurred in the server of the NHS in Leeds earlier in the year.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-2274643881714077463?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/2274643881714077463/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=2274643881714077463' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2274643881714077463'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/2274643881714077463'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/conficker-and-your-health.html' title='Conficker and your health'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_Wom5eMghH20/S9xbkI1cmFI/AAAAAAAAA2A/g034sL35rIA/s72-c/image_thumb%5B2%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-1399240028210766250</id><published>2010-05-03T01:00:00.001-07:00</published><updated>2010-05-03T01:16:23.297-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Retrospective'/><title type='text'>A look back at posts from April 2009</title><content type='html'>As April has just passed by, let’s take a quick review of what I was blogging about in that month last year&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;There were a couple of posts on entropy, the first &lt;a href="http://lukenotricks.blogspot.com/2008/03/nist-passwords-and-entropy.html"&gt;NIST, Passwords and Entropy&lt;/a&gt; a review of NIST’s approach to specifying password policies based on entropy and the second &lt;a href="http://lukenotricks.blogspot.com/2009/04/on-entropy-of-fingerprints.html"&gt;On the Entropy of Fingerprints&lt;/a&gt;, which found some research to indicate that password entropy is much lower than fingerprint entropy.&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;I also had a bit to say about a “rant” in &lt;a href="http://lukenotricks.blogspot.com/2009/04/marcus-ranum-and-point-of-no-return.html"&gt;Marcus Ranum and the Points of No Return &lt;/a&gt;where Ranum stated that the cumulative effect of many business-driven IT decisions taken over the last three decades have rendered a grand IT failure all but inevitable. I followed that post up with &lt;a href="http://lukenotricks.blogspot.com/2009/04/security-as-non-functional-requirement.html"&gt;The Relegation of Security to NFR Status&lt;/a&gt; which examined the weakened position of security, and IT in general, in decision-making processes.&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;There was a wonderful post by Julian Sanchez on his &lt;a href="http://www.juliansanchez.com/2009/04/06/climate-change-and-argumentative-fallacies/"&gt;Climate Change and Argumentative Fallacies&lt;/a&gt; blog where he coins the term “one way hash” arguments, by which he means the asymmetric amount of effort required to pose a plausible argument as opposed to the effort required to debunk it. I think we face the same problem in IT risk and security as I said in &lt;a href="http://lukenotricks.blogspot.com/2009/04/one-way-hash-arguments.html"&gt;“One Way Hash” Arguments.&lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;I also reposted  &lt;a href="http://lukenotricks.blogspot.com/2007/09/data-centric-security-model.html"&gt;The Data Centric Security Model (DCSM)&lt;/a&gt; with a link to the full document on Scribd, as the old link stopped working.  The document remains very well read with about 3,000 views in total today. &lt;a href="http://lukenotricks.blogspot.com/2009/04/some-security-documents-on-scribd.html"&gt;Some security documents on Scribd&lt;/a&gt; gave links to other documents I uploaded, and you can see all the categories &lt;a href="http://lukenotricks.blogspot.com/p/scribd-collections.html"&gt;here&lt;/a&gt; (called collections by Scribd). &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;I announced in &lt;a href="http://lukenotricks.blogspot.com/2009/04/enisa-and-security-awareness.html"&gt;ENISA and Security Awareness&lt;/a&gt; that I would be speaking at an upcoming ENISA conference, which was a very successful get together. My slides can be found &lt;a href="http://lukenotricks.blogspot.com/2009/06/my-enisa-awareness-presentation.html"&gt;here&lt;/a&gt; and let me point you to a great awareness presentation &lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;from Robert Hadfield of British Airways, which has just over &lt;a href="http://www.scribd.com/doc/17065431/BA-IT-Security-Awareness-presentation"&gt;1700 views on Scribd&lt;/a&gt;.&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://lukenotricks.blogspot.com/2008/06/zero-knowledge-proofs.html"&gt;Zero Knowledge Proofs&lt;/a&gt; was a longish non-technical introduction to this complex topic, and it has remained one of my posts that has a steady number of readers. I also started &lt;a href="http://lukenotricks.blogspot.com/2009/04/password-roundup-1.html"&gt;Password Roundup #1&lt;/a&gt;, with my intention to create a series of posts on password issues, which always figure regularly in security news. I got around to a &lt;a href="http://lukenotricks.blogspot.com/2009/05/password-roundup-2.html"&gt;second round-up&lt;/a&gt; about a month later but have stalled since then – not due to lack of material. Instead of waiting for me, please take a look at the &lt;a href="http://reusablesec.blogspot.com/"&gt;Reusable Security&lt;/a&gt; blog by Matt Weir which is devoted to password issues and analysis.&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;Finally, I started to post some of the FreeMind maps I create to gather my thought son more detailed posts in  &lt;a href="http://lukenotricks.blogspot.com/2009/04/some-mindmaps-for-security-incidents.html"&gt;Three Security maps in FreeMind and Flash&lt;/a&gt;. Since then I have &lt;a href="http://sites.google.com/site/lukeoconnorsite/Home/it-security-and-cryptography/freemind-security-maps"&gt;published&lt;/a&gt; all my FreeMind maps, including some that don’t relate directly to articles. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-1399240028210766250?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/1399240028210766250/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=1399240028210766250' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1399240028210766250'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1399240028210766250'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/look-back-at-posts-from-april-2009.html' title='A look back at posts from April 2009'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-1585270217882250177</id><published>2010-05-02T01:00:00.000-07:00</published><updated>2010-05-02T15:33:41.073-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CAPTCHA'/><title type='text'>Crowdsourcing CAPTCHA cracking</title><content type='html'>&lt;p align="justify"&gt;The NYT has &lt;a href="http://www.nytimes.com/2010/04/26/technology/26captcha.html?hpw"&gt;reported&lt;/a&gt; on the practice of outsourcing the breaking of captchas to people in Bangladesh, India and China. The work is neither glamorous nor well-paid at 80 cents to $1.20 per 1,000 solved captchas, however there seem to be enough takers nonetheless. The work is farmed out through online exchanges like &lt;a href="http://freelancer.com/"&gt;Freelancer.com&lt;/a&gt;, where for example an operator in Bangladesh runs an operation turning out &lt;a class="zem_slink" title="CAPTCHA" href="http://en.wikipedia.org/wiki/CAPTCHA" rel="wikipedia"&gt;captcha&lt;/a&gt; solutions 24 hours a day, seven days a week.&lt;/p&gt;  &lt;p align="justify"&gt;Macduff Hughes, an engineering director at Google says that “Our goal is to make mass account creation less attractive to spammers, and the fact that spammers have to pay people to solve captchas proves that the tool is working.” So we should see captchas as a deterrent rather than a foolproof way of distinguishing people from malware. In fact if people are being employed to break these little authentication puzzles then they are working as intended – to make sure that a person is behind the answer – unfortunately malware is masking a &lt;a href="http://en.wikipedia.org/wiki/The_Turk"&gt;mechanical turk&lt;/a&gt;. The inventors of captchas probably did not expect that solving these puzzles could be farmed out so easily using Web 2.0 technology.&lt;/p&gt;  &lt;p align="justify"&gt;The bigger threat probably comes from the direct computer solution to captchas, which can be scaled and provide solutions in real time. I recently &lt;a href="http://lukenotricks.blogspot.com/2010/02/dissection-of-koobface.html"&gt;posted&lt;/a&gt; on the very thorough analysis of the Koobface botnet at &lt;a title="abuse.ch" href="http://www.abuse.ch/?p=2103"&gt;abuse.ch&lt;/a&gt;, including a section on its captcha breaking network. The captchas are broken in at most 3 minutes, and in many cases just a few seconds. There is also &lt;a href="http://blog.webroot.com/2010/03/22/pushu-variant-spams-hotmail-cracks-audio-captchas/"&gt;evidence&lt;/a&gt; presented by Webroot that audio captchas are also being broken in real time by automated means. &lt;/p&gt;  &lt;div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/0c71928a-e338-4b96-97ab-16781d0d655e/"&gt;&lt;img style="border-style: none; float: right;" class="zemanta-pixie-img" alt="Reblog this post [with Zemanta]" src="http://img.zemanta.com/reblog_e.png?x-id=0c71928a-e338-4b96-97ab-16781d0d655e" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-1585270217882250177?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/1585270217882250177/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=1585270217882250177' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1585270217882250177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/1585270217882250177'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/crowdsourcing-captcha-cracking.html' title='Crowdsourcing CAPTCHA cracking'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-9207467027674712385</id><published>2010-05-01T13:57:00.000-07:00</published><updated>2010-05-03T03:22:46.634-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><title type='text'>1-in-300 Facebook accounts hacked, and now for sale</title><content type='html'>&lt;div align="justify"&gt;There are &lt;a href="http://www.metro.co.uk/tech/823330-1-5m-facebook-accounts-put-up-for-sale-on-russian-hacking-forums"&gt;several&lt;/a&gt; &lt;a href="http://www.zdnetasia.com/1-5m-facebook-accounts-up-for-sale-62062829.htm"&gt;reports&lt;/a&gt; stating that one and half million Facebook accounts are for sale on an underground forum by a hacker calling himself Kirllos, which equates to about 1 account in 300 being up for grabs. VeriSign's iDefense group estimates that almost half of the accounts have been sold already.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;  &lt;div align="justify"&gt; &lt;/div&gt;  &lt;div align="justify"&gt;Kirllos' is asking $25 for 1,000 users with less than 10 friends or $45 for those with eleven or more. This is quite cheap given that e-mail IDs and passwords typically go for between $1 and $20 per account, and credit card and bank account credentials can go up to $30 for credit cards and $850 for bank accounts.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;  &lt;div align="justify"&gt; &lt;/div&gt;  &lt;div align="justify"&gt;As usual, Facebook users should check their passwords.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-9207467027674712385?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/9207467027674712385/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=9207467027674712385' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/9207467027674712385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/9207467027674712385'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/1-in-300-facebook-accounts-hacked-and.html' title='1-in-300 Facebook accounts hacked, and now for sale'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2659416969867866171.post-3066167239592097408</id><published>2010-05-01T07:46:00.001-07:00</published><updated>2010-05-02T15:13:23.467-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='cloud computing'/><title type='text'>What is the LINPACK rating of Conficker?</title><content type='html'>&lt;p align="justify"&gt;Rodney Joffe, senior vice president and senior technologist at the infrastructure services firm &lt;a href="http://www.neustar.biz/"&gt;Neustar&lt;/a&gt;, gave a &lt;a href="http://www.cloudconnectevent.com/2010/presentations/free/49-rodney-joffe.pdf"&gt;keynote presentation&lt;/a&gt; on Cloud Computing for Criminals at the recent &lt;a href="http://www.cloudconnectevent.com/"&gt;Cloud Connect&lt;/a&gt; conference. Joffe presents some figures which show that the computational size of the Conficker botnet dwarfs the current commercial offerings, based on measuring the number of systems, the number of CPUs and available bandwidth. For Conficker these values are given (estimated?) as &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;     &lt;div align="justify"&gt;6,400,000 systems&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;18,000,000+ CPUs&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;28 Terabits of bandwidth&lt;/div&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;p align="justify"&gt;These corresponding measures for Google are 500,000 systems, 1,500,000 CPUs and 1,500 Gbps of bandwidth, with Amazon and Rackspace providing significantly less resources. So Conficker is a massive &lt;em&gt;ad hoc&lt;/em&gt; computational structure. But is Conficker really like a cloud service? Joffe says yes because&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;     &lt;div align="justify"&gt;It’s available for rent&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;Choose your geographies&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;Choose your networks&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;Choose your bandwidth&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;Choose your OS Version&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;Choose your specialty (DDoS, Spam, Data Exfiltration)&lt;/div&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;p align="justify"&gt;and further the vendor has good qualifications&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Much more experience (1998) &lt;/li&gt;    &lt;li&gt;Larger footprint (Millions of systems) &lt;/li&gt;    &lt;li&gt;Unlimited new resources (New malware) &lt;/li&gt;    &lt;li&gt;No costs &lt;/li&gt;    &lt;li&gt;No moral, ethical, or legal constraints&lt;/li&gt; &lt;/ul&gt;  &lt;p align="justify"&gt;This all reminds me of a mail post by Peter Gutmann from 2007 called, &lt;a href="http://seclists.org/fulldisclosure/2007/Aug/520"&gt;World's most powerful supercomputer goes online&lt;/a&gt;, referring to the &lt;a class="zem_slink" title="Storm botnet" href="http://en.wikipedia.org/wiki/Storm_botnet" rel="wikipedia"&gt;Storm botnet&lt;/a&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;This doesn't seem to have received much attention, but the world's most powerful supercomputer entered operation recently. Comprising between 1 and 10 million CPUs  (depending on whose estimates you believe), the Storm botnet easily outperforms the currently top-ranked system, BlueGene/L, with a mere 128K CPU cores. Using the figures from Valve's online survey&lt;/p&gt;    &lt;p align="justify"&gt;&lt;a href="http://www.steampowered.com/status/survey.html"&gt;http://www.steampowered.com/status/survey.html&lt;/a&gt;&lt;/p&gt;    &lt;p align="justify"&gt;for which the typical machine has a 2.3 - 3.3 GHz single core CPU with about 1GB of RAM, the Storm cluster has the equivalent of 1-10M (approximately) 2.8 GHz P4s with 1-10 petabytes of RAM (BlueGene/L has a paltry 32 terabytes). In fact this composite system has better hardware resources than what's listed at &lt;a href="http://www.top500.org/"&gt;http://www.top500.org&lt;/a&gt;.&lt;/p&gt;    &lt;p align="justify"&gt;This may be the first time that a top 10 supercomputer has been controlled not by a government or megacorporation but by criminals. The question remains, now that they have the world's most powerful supercomputer system at their disposal, what are they going to do with it? &lt;/p&gt;    &lt;p align="justify"&gt;And I wonder what the LINPACK rating for Storm is?&lt;/p&gt; &lt;/blockquote&gt;  &lt;p align="justify"&gt;And I wonder what the &lt;a href="http://en.wikipedia.org/wiki/Linpack"&gt;LINPACK&lt;/a&gt; rating is for Conficker?&lt;/p&gt;  &lt;div class="zemanta-related"&gt;   &lt;h6 style="font-size: 1em;" class="zemanta-related-title"&gt;Related articles by Zemanta&lt;/h6&gt;    &lt;ul class="zemanta-article-ul"&gt;     &lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://r.zemanta.com/?u=http%3A//www.infoworld.com/d/security-central/1-in-10-windows-pcs-still-vulnerable-conficker-worm-879%3Fsource%3Drss_infoworld_news&amp;amp;a=16121967&amp;amp;rid=0c71928a-e338-4b96-97ab-16781d0d655e&amp;amp;e=8c63930dcf89b8d94452ba62d4bb924e"&gt;1-in-10 Windows PCs still vulnerable to Conficker worm&lt;/a&gt; (infoworld.com) &lt;/li&gt;      &lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://techrights.org/2010/04/26/conficker-major-problem/"&gt;Quote of the Day: Conficker Still a "Loaded Gun, Waiting to be Fired."&lt;/a&gt; (techrights.org)&lt;/li&gt;      &lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://viewfromthebunker.com/2010/03/29/downadupconficker-one-year-later/"&gt;Downadup/Conficker One Year Later&lt;/a&gt; (viewfromthebunker.com)&lt;/li&gt;   &lt;/ul&gt; &lt;/div&gt;  &lt;div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/0c71928a-e338-4b96-97ab-16781d0d655e/"&gt;&lt;img style="border-style: none; float: right;" class="zemanta-pixie-img" alt="Reblog this post [with Zemanta]" src="http://img.zemanta.com/reblog_e.png?x-id=0c71928a-e338-4b96-97ab-16781d0d655e" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2659416969867866171-3066167239592097408?l=lukenotricks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lukenotricks.blogspot.com/feeds/3066167239592097408/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2659416969867866171&amp;postID=3066167239592097408' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3066167239592097408'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2659416969867866171/posts/default/3066167239592097408'/><link rel='alternate' type='text/html' href='http://lukenotricks.blogspot.com/2010/05/what-is-linpack-rating-of-conficker.html' title='What is the LINPACK rating of Conficker?'/><author><name>Dr. Luke O'Connor</name><uri>http://www.blogger.com/profile/16153635896554944056</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp3.blogger.com/_Wom5eMghH20/R87vGUESxGI/AAAAAAAAAF4/RTmbx0Q74fI/S220/DSC_4515.JPG'/></author><thr:total>1</thr:total></entry></feed>
