Friday, September 9, 2011

Two victories for Randomness

I recently came across two smallish examples of where randomness was the solution to two perplexing problems. That is, rolling the dice seems to help you out of a situation where a planned method was not giving you what you wanted.

The first issue is the problem of how to board passengers on a plane. Finding the best way to board people is actually a well-studied problem, both theoretically and in practice, and you can see some of the work here. At the top of the same page there is a nice simulation program which shows you how different boarding strategies play out, and random boarding (just calling out people to board at random) is better than the usual front-to-back boarding that most of us are familiar with.

image

The reason is that random boarding gives a better utilization of the space in the plane whereas front-to-back boarding piles people into one part of the plane, eventually causing jams in the aisles. The full set of strategies examined are

  • Back-to-front
  • Rotating-zone
  • Random
  • Block
  • Outisde-in
  • Reverse-pyramid

On another topic, a Freakonomics blog post describes how researchers in South Africa are using a randomness trick to get truthful answers from farmers who are suspected of illegally killing leopards and hyenas. The method is called randomized response surveying, where when the farmers are asked potentially incriminating questions they first flip a coin, and based on the result give a yes or no answer to either the incriminating question if it was heads, or a harmless question (do you think the Springboks will win the RWC?) if it was tails. The farmers actually used a die, taking specific actions on which value from 1 to 6 was thrown, but the principle is the same as I have described it.

The trick here is that the person asking the question cannot tell which question the farmer is answering, but the farmer’s answer can be recorded. Statistical methods can then be used to determine the distribution of answers for the two questions, and actually make inferences about the proportion of positive answers to the incriminating question. This method was devised in the 60’s, and by the early 80’s it was being taught at my undergraduate university as part of a first year course.

Sunday, August 7, 2011

Green IT Swiss Data Center presentation

Here is a short presentation on a relatively new data center in the west of Zurich that is designed to be green and secure.  More information at green.ch, and the language can be changed to English in the upper right corner.

US Grade Inflation Study

A recent study has examined the prevalence of grade inflation at US universities over the last 100 years or so, and has found some identifiable patterns. The chart below shows the increase in grades between various types of schools in the primary colors, with the grey representing (unnamed individual schools).

image

What is clear is that there was a huge increase in grade in crease in the 60’s and then a steady increase over  the last 30 years of so. From the study

The rise in grades in the 1960s correlates with the social upheavals of the Vietnam War. It was followed by a decade
period of static to falling grades. The cause of the renewal of grade inflation, which began in the 1980s and has yet to
end, is subject to debate, but it is difficult to ascribe this rise in grades to increases in student achievement. Students’ entrance test scores have not increased (College Board, 2007), students are increasingly disengaged from their studies (Saenz et al., 2007), and the literacy of graduates has declined (Kutner et al., 2006). A likely influence is the emergence of the now common practice of requiring student-based evaluations of college teachers. Whatever the cause, colleges and universities are on average grading easier than ever before.

Further science and engineering students are graded more harshly than their fellow students in liberal arts degrees.

A 10% Tipping Point Threshold

Scientists at Rensselaer Polytechnic Institute have recently published research into social networks which indicates  that when just 10 percent of a network steadfastly holds a given belief, then that belief will eventually be adopted by the majority of the society. These group of 10% “believers” are referred to as a committed minority.

Even though the research has produced quite a bit of press (see here and here for example) it is a little difficult to say how the result was arrived at. The abstract of the paper states that

We show how the prevailing majority opinion in a population can be rapidly reversed by a small fraction p of randomly distributed committed agents who consistently proselytize the opposing opinion and are immune to influence. Specifically, we show that when the committed fraction grows beyond a critical value pc≈10%, there is a dramatic decrease in the time Tc taken for the entire population to adopt the committed opinion. In particular, for complete graphs we show that when p<pc, Tc~exp[α(p)N], whereas for p>pc, Tc~lnN. We conclude with simulation results for Erdős-Rényi random graphs and scale-free networks which show qualitatively similar behavior.

It seems that they are using a model for the spread of opinion overlayed on various network topologies, starting with the complete graph (everyone knows everyone), then scale free, and a simulation of a random graph process. The results are strengthened by finding the 10% threshold present in each topology. Even so, the following graph was not that informative for me.

image

I think I will have to wait get a copy of the paper to make full sense of the result. Reported in Freakanomics.

Friday, August 5, 2011

iPhone Passcode Bias

An informal study from collecting just over 204,000 iPhone passcodes, produced the graphic below on the top ten most common passcodes

image

The author concludes that

Formulaic passwords are never a good idea, yet 15% of all passcode sets were represented by only 10 different passcodes (out of a possible 10,000). The implication? A thief (or just a prankster) could safely try 10 different passcodes on your iPhone without initiating the data wipe. With a 15% success rate, about 1 in 7 iPhones would easily unlock--even more if the intruder knows the users’ years of birth, relationship status, etc.

DIPK Graphic

From Flowing Data

Mark Johnstone uses a cake metaphor to represent data, presentation, and what you gain.

Don’t like the last shot for knowledge. Perhaps lots of smaller cakes?

image

Monday, June 6, 2011

Block Cipher Bible coming

There is a new and authoritative block cipher book soon to be published, by my good friend Lars Knudsen and my respected colleague Matt Robshaw. These are two of the top experts in the field – both veterans of the AES selection process and long time contributors to understanding why and what makes a good - or simply not a bad - block cipher. The book will be available this year and you can pre-order from Amazon right now.

image

A Loch Ness Month

The graph below from Google Analytics shows the reading “humps” of my blog with unusual clarity. Typically readership tapers off on the weekend and picks up as the work week commences. You can see the peaks and valleys for the weekends quite clearly below, and it reminded my of those famous Loch Ness humps. Thanks to the 2000+ visitors in May, even when I am struggling to find the time for meaningful posts.

image

Monday, May 2, 2011

ISACA Risk Assessment Guidelines

I uploaded a 15 page guideline from ISACA for audit risk assessments to my Scribd collections. The document gives a reasonable overview of how a standard IT audit assessment can be enhanced from a risk perspective, taking into account additional factors beyond controls and their gaps.

Thursday, April 14, 2011

No Tricks recently passed 50,000 visitors

Just a short note to say that the number of visitors to the No Tricks blog recently passed the 50,000 mark, which was very satisfying for me. The blog has been running since September 2008, starting out with just a few posts but then building open slowly to around 250 now. You can see the monthly increase in visitors below, and some other statistics from Google Analytics.

image

Tuesday, April 5, 2011

How many users does Twitter have?

A nice power law looking graph from Business Insider on the properties of Twitter users, and about 175 million Twitter accounts have been registered to date. But how many of those accounts are actually active and being used? Hard to say it seems. The article reports on digging into the Twitter API and finding that

Using data that is now just one month old, he found out that…

  • There were 119 million Twitter accounts following one or more other accounts.
  • There were 85 million accounts with one ore more followers.

With these figures, and Twitter's claim of 175 million accounts, a little subtraction shows us that there are 56 million Twitter accounts following zero other accounts, and 90 million Twitter accounts with zero followers.


image

Saturday, March 26, 2011

Freehaven papers on Anonymity

I have not looked at the Freehaven site for some time, but just a reminder that there is a huge collection of research papers sourced, tracing the history of anonymity systems, MIXES and other PETs. The collection was well-attended to up till the end of last year but is missing updates for 2011 so far. I am sure that they will come. BibTeX references for the papers as well.

Trust and security in the cloud

The Register has published a new 16-page whitepaper on trust and security in cloud computing, with the key findings being

  • Many companies could do much better when it comes to in-house security
  • SaaS adoption is limited currently, but there is increasing interest from the business
  • The biggest impediment to SaaS adoption is a perception of security issues
  • Companies with experience of SaaS are positive about provider security
  • SaaS is likely to help with shortcomings of on-premise security capabilities

The whitepaper was written from data gathered in an online survey with over 500 participants. Amongst the many tabulated responses to the survey there is an interesting list of the ways data can exit from corporate boundaries.

image

Saturday, March 12, 2011

iPad Competition is Toast

Business Insider recently reported that the iPad is outselling the competition about 4-to-1. So as security professionals the iPad is the platform to focus on for risk assessments.

image

An example of redundancy in English

After I apologized too often for my bad typing, my sister-in-law sent me the following text to demonstrate that our brain can understand words even if only the first and last letters are correct
Yet aoccdrnig to a sudty at Cmabrigde Uinervtisy, it deosn’t mttaer in waht oredr the ltteers in a wrod are, the olny iprmoetnt tihng is taht the frist and lsat ltteer be at the rghit pclae. The rset can be a ttoal mses and you can sitll raed it wouthit a porbelm. Tihs is bcuseae the huamn mnid deos not raed ervey lteter by istlef, but the wrod as a wlohe.
Apparently this text is well-known to language people!