Tuesday, August 14, 2007

Hey Bartender

I'm still not dead yet!

See, there are two ways you can approach this whole blog thing. Way 1 is to write something every day or thereabouts regardless of whether you have anything to say or not. Way 2 is just to write something whenever the mood strikes you.

Way 1 probably gets you more readers, but Way 2 produces better articles. Given that there are already too many bloggers gassing on about too many things, I have chosen Way 2.

Besides, I'm lazy.

So: what vital concern moved me to get off my virtual duff and compose this entry? Is it a dire new threat to the Internet like the latest attack by the "Storm" worm? A cool new technology like the Linux-based iPhone killer? An egregious bit of stupidity like the Wall Street Journal's "Ten Things Your IT Department Won't Tell You" article (a.k.a. "How to Get Yourself Fired and Break the Law in Ten Easy Lessons")?

Nah, none of the above. The Storm worm is just an old threat in a new package, Linux has a long way to go to match iPhone's cachet, and intellectual dishonesty is just business as usual at the Journal.

What got me to finally update this blog is the demonstration, by the folks over at Tom's Hardware, of the value of beer (Molson Canadian, to be exact) as a CPU coolant. According to their test protocol (which, in all fairness, seems to have been devised after imbibing some of the coolant), the only thing that out-performs a brewski is SilverStone Thermal Fluid - and then only by a fraction of a degree.

There's no mention of how Silverstone performs against Molson in a taste test, alas.

Such are the thoughts of an IT geek's fevered brain after three weeks of a killer heat wave.

Tuesday, June 19, 2007

The Dark End of the Street

"I'm not dead yet!"

Yes, despite the fact that I haven't written anything in this blog for a couple of months, I'd not dead yet. I feel happy! I feel like - dancing!

Besides, I haven't been silent. Stage Left, the blog from the other half of my brain, has been pretty lively lately because of all the shows I reviewed in June. And I'm working on a new op-ed piece for the St. Louis Post-Dispatch. It'll be published on July 8th and I'll have a link to it here by the 9tth or thereabouts. My May musings for that publication can be found here. There's a March column as well, but it has been moved to their paid archives. Killjoys.

Still, the main reason there's been nothing here for a while is that there's been so much technology news lately that it's hard to keep up: Apple's iPhone and new MacBook Pros, Microsoft's coffee table computer (which looks suspiciously like the open-source ReacTable, not that I'm suggesting anything) and, of course, the daily flood of malware news.

I'll leave comments on the latest Bright Spaklies for another column. This time I want to expand on some advice from my ten-point Internet safety check. At the time, I advised you to "think before you click" on a link in an e-mail or at a web site. The idea was to avoid sites that were clearly dangerous or which might mimic legitimate sites.

Now, it seems, things have got even more complicated. According to a June 18th article in Computerworld a "phenomenal" number of web sites - mostly in Italy, so far - have been compromised by a gang using a Russian-made exploit kit called MPack. The hacked sites are used to download malware - mostly keyloggers, designed to grab user names and passwords - to unprotected computers that visit these otherwise legitimate web sites.

This is bad news, to say the least. It means that even if you're careful to avoid the dark end of the virtual street, you can still get mugged. Trend Micro network architect Paul Ferguson, quoted in the Computerworld article, puts it this way: "The usual advice we give, 'Avoid the bad neighborhoods of the Web,' just doesn't hold water anymore. Everywhere could be a bad neighborhood now."

Oh, joy.

Could be worse, of course. If you followed my advice back in February and installed multiple anti-virus and anti-spyware products, you're still likely to be protected from hacked sites. But this does ratchet up the paranoia level and raises an unpleasant question: just how risky does doing business on the Internet have to become before large numbers of computer owners decide it's not worth the trouble? And what will the economic impact be if that happens?

Thursday, April 26, 2007

When Will They Ever Learn?

Well, folks, don't say I didn't warn you. In July of 2006, when the Fedabobble Gummint started work on anti-spyware legislation, I expressed my usual curmudgeonly cynicism over the likely results. Among other things, I noted that the FTC had already told Congress it didn't need any additional legislation (a fact reinforced by recent successful actions against spyware offenders) and that at least one major spyware vendor was backing the effort, making it all of questionable value at best.

Comes now blogger Ed Foster at InfoWorld with evidence that my crystal ball was, at least in this case, in good working order. H.R. 964, the so-called Spy Act, carves out major exceptions for ISPs, software vendors, and pretty much anybody else who can claim you're doing business with them. Worse yet, the bill preempts stricter state laws and states that "no person other than the Attorney General of a State may bring a civil action" in such cases.

Had this bill been law when Sony installed its infamous rootkit on the PCs of unsuspecting consumers, there would have been no legal remedy available to individuals. Only a state AG could have taken action, and s/he wouldn't have in any case because the law would have made that rootkit legal.

Time to notify your Congresscritters that they should be spending more time cleaning up Bush Jr'.s mess in Iraq and less time pushing special interest legislation for their corporate cronies.

Wednesday, April 18, 2007

Chinese Rock

When it comes to technology issues, does this country's right hand know what the left hand is doing? Reading the on-line IT trade journals, the only possible answer I can come up with is a resounding “no”.

The latest example: a U.S. House of Representatives probe into hack attacks on government servers that appear to have originated in China.

To anyone following computer security issues, this is about as surprising as the discovery that the sun appeared to rise in the East this morning.

In America's corporate board rooms, however, the sun must be rising somewhere else, because, by an amazing coincidence, the hot new place to which corporate America is shipping IT jobs and company data as fast as it can is - China.

Maybe I'm just old-fashioned, but it strikes me as just a wee bit suicidal to be cheerfully sending confidential data to a country which:

  • Is run by an autocracy that hasn't changed its hostility toward human rights since the Tiananmen Square massacre
  • Has an attitude towards intellectual property protection that is (to say the least) indifferent, and
  • Now appears to be hosting criminal attacks against our infrastructure.

But, hey: why let a little thing like homeland security stand in the way of a quick boost in corporate profits and the resulting hike in executive bonuses? We need to keep our priorities straight, after all!

Of course, the fact that attacks have originated from servers that appear to be in China doesn't necessarily mean that those attacks are orchestrated or condoned by the Chinese government. Indeed, why bother to attack American assets at all when American corporations are giving them away in return for cheap, obedient labor and a political system that makes independent trade unions impossible?

Monday, April 09, 2007

Spies in the Night

In my last post, I went on at some length about that alarming tools available to criminal hackers as revealed at the March 2007 Black Hat Conference.

Shortly after that, I came across something even more alarming, if that's possible: a pre-publication draft of a study by Phil Howard and Kris Erickson of the University of Washington entitled A Case of Mistaken Identity? News Accounts of Hacker and Organizational Responsibility for Compromised Digital Records, 1980–2006. The paper reviews major media reports of 550 security breaches that took place during the period in question and it seems that 60% of them were the result of corporate incompetence. To quote from their abstract: "in terms of incidents, 9 percent were an unspecified type of breach, 31 percent of the incidents involved hackers, and 60 percent of the incidents involved organizational mismanagement: personally identifiable information accidentally placed online, missing equipment, lost backup tapes, or other administrative errors."

So it turns out that, even if you do implement my 10-point security check, your personal information could still end up in the hands of the Russian Mafia because corporations simply don't adequately safeguard their customers' data.

That's no reason to give up the security fight, but it's a darned good reason to insist on more accountability by the companies that hold our personal information. So far, most legislation and public policy has been driven by the companies themselves, and we can see where that has gotten us.

"I think", said Howard in an interview for Computerworld, " it is easier when your company loses a lot of client data to put an immediate spin on it and blame it on a hacker or some external guy using some ingenious hacking technique."

Besides, that money you saved by not investing in proper safeguards in the first place has been earning you some nice interest in the meantime. It's always easier to shell out for PR and spin afterwards.

Monday, March 05, 2007

The Monster Mash

There's some pretty scary stuff on the screens at your local googleplex cinema these days. You've got you choice of serial killers (Zodiac, Hannibal Rising), a nutter with numerical obsessions (The Number 23), and a super-anti-hero in touch with his Inner Satan (Ghost Rider) to name just a few.

But if you're a propeller beanie type who has to deal with computer security issues, you don't need supernatural pyromaniacs or cannibalistic mass murders to keep you awake at night. No, in this business all you need are reports from the Black Hat security conference.

For the benefit of those of you who don't spend your days worrying about things like rootkits and Remote Access Trojans, Black Hat is a company that provides briefings and training on security issues to both private and public sector clients of all sizes. It brings together, according to its web site, “the best minds from government agencies and global corporations with the most respected independent researchers and hackers” to provide state of the art information on how to defend your company from criminal hackers, identity thieves, and related virtual outlaws. The Black Hat conferences, which take place four times a year, provide an opportunity for security professionals to meet, greet, and compare notes.

They also provide the rest of us with fodder for digital nightmares. The latest conference, which concluded March 1st, included briefings on the threat of rootkits, the risks posed by the widespread use of RFID tags, vulnerabilities in the ways databases communicate with each other, various ways that web applications can be hacked (and how to stop those hacks), and a presentation on what's referred to as “data seepage”.

This last one was of particular interest to me, since it touches on an issue I referred to in an earlier blog entry: the foolish and often reckless ways in which the average computer user cruises along the Information Superhighway. Data seepage refers to the little bits of personal information our laptops, handhelds and even smartphones are broadcasting to the world at large – and therefore to criminal hackers – when we use those nifty free wireless networks at the local coffee shop or airport.

The problem, you see, is that those networks are unsecured. That means that anything you do at your laptop can be picked up by others on the same network using “packet sniffers” or other network monitoring applications. They can determine what type of hardware and operating system you're using, what other wireless hotspots you've connected to in the past, what web sites you're visiting and any personal information you've been foolish enough to enter. At the very least, the bad guys can pick up enough information to make you and/or your employer the target of a “spear phishing” attack. At the worst, they might gain the ability to read your e-mail, steal your on-line identity, and even plant spyware on your computer.

This isn't just theoretical. Even at Black Hat conferences – where you'd assume everybody is pretty cyber-savvy – there's a Wall of Shame (actually a large video monitor) displaying, in real time, personal information being sent unencrypted on the conference wireless network. During their presentation on data seepage last week, in fact, experts from Errata Security “were able to use [their network monitoring application] Ferret to intercept an e-mail sent to a reporter working in another conference session. The message included one of her applications' passwords”, according to ComputerWorld columnist Matt Hines' report from the conference.

Fortunately for her, Hines doesn't sniff and tell.

There are ways you can protect yourself from this kind of exposure, of course. You can make sure your laptop is as secure as possible (I refer you to my ten-point safety check for details) and you can subscribe to a VPN (virtual private network) service for those times when you really need to use one of those “free” wireless networks. That old saying “there's no such thing as a free lunch” applies in cyberspace as well, you know.

Look for this data seepage issue to get worse before it gets better, especially with towns and cities rushing to implement municipal WiFi networks. For the well-equipped cybercrook, the only thing more attractive than an airport full of laptops cheerfully leaking personal information is an entire city full of them. It's like shooting phish in a barrel.

Now THAT'S scary!

Friday, March 02, 2007

More Sunday Driving

Lest you think that nobody could be clueless enough to do some of the things I warned you about in my last blog posting, allow me to direct your attention to this recent entry at Shark Bait, Computerworld’s discussion forum focusing on Stupid User Tricks.

Yes, I know, we techie types can lack people skills and come off as a bit arrogant at times, but when faced with behavior this foolish, it’s difficult to by diplomatic.

Shark Bait is well worth reading on a regular basis, by the way. Even the relative beginner in the computer world will find many of the stories reported therein highly amusing, and you technorati will really get a kick out of it.

Sunday, February 25, 2007

Sunday Driving

Are you cruising along the Information Superhighway sober, sane and safe - or drunk, deranged and dangerous? Following these steps won't guarantee you complete immunity from the digital equivalent of a 50-car pileup - the only way to do that is to disconnect your computer from the network and turn it off - but it will make disasters less likely and recovery much easier.

Unless otherwise indicated, all software recommended here is either part of the basic operating system (Windows or Macintosh OS X) or is open source and/or freeware. I'm trying to make this as painless as possible.

I have no association of any kind with any of the web sites or products I'm referring you to here; I've just found them very useful and/or reputable. Think of this as a ten-point safety check for your virtual car.

  1. Use smart passwords
    • Never use the default password that comes with any piece of hardware or software; always create your own.
    • Use passwords that aren't obvious; Cornell University has a guide on creating strong passwords that's worth reading.
    • If you have trouble remembering your various passwords, store them in a secure, encrypted file or program. Macintosh users can use Keychain Access, which is part of Mac OS X. Windows users should check out Password Safe.
  2. Keep your system software updated
    • Windows: make sure Windows Update runs automatically.
    • Macintosh: Set your Software Update utility to check on a daily basis. You'll find it under Preferences - System - Software Update.
  3. Use anti-virus software
    • Windows: Free anti-virus options include ClamWin and AVG. Commercial products are available from McAfee, Norton and Trend Micro, among others.
    • Macintosh: Viruses for OS X are relatively rare, as are free anti-virus programs. ClamXav is the Macintosh version of ClamWin. Commercial products are available from McAfee, Norton, and Intego.
    • No matter what product you use, make sure you have it set to automatically update your virus definition files. Out of date anti-virus software is as bad as none at all.
  4. Use anti-spyware software - Anti-virus packages won't necessarily catch all the bad stuff out there
  5. Practice e-mail safety
    • Don't open a file attached to e-mail unless it's one you're expecting from a trusted sender. Hostile program are often disguised as apparently innocuous documents.
    • Don't reply to or click on links in unsolicited e-mails asking you to verify personal data at financial institutions or on-line merchants. These are likely to be fraudulent.
    • See this article at wiredsafety.org for more solid recommendations on e-mail safety.
  6. Practice safe browsing
    • Think before you click on a link! Hackers will try to sucker you into visiting web sites that will download viruses and spyware to your computer without your knowledge, or con you into entering personal information at a web site that looks (but isn't) legitimate.
    • Secure your web browser. The US Computer Emergency Readiness Team (CERT®) has some good practical advice for both Windows and Macintosh users.
    • Use Mozilla Firefox instead of Microsoft Internet Explorer. We propeller beanie types can debate the reasons why until everyone's eyes glaze over, but the bottom line is that Internet Explorer is the preferred target of the network's bad guys. Download Firefox and make it your default browser.
  7. Use a personal firewall
    • A personal firewall program provides an additional layer of protection from Internet threats, and can alert you if a spyware program is trying to "phone home".
    • Windows: Windows XP has a built-in firewall. See this article from Microsoft on how to make the best use of it.
    • Macintosh: OS X has as built-in firewall. See this article from Apple on how to make the best use of it.
  8. Avoid peer-to-peer file sharing programs
    • Programs such a Kazaa, Grokster, and Limewire are major distribution channels for viruses, worms and spyware - to say nothing of copyright violations.
    • If you must use one of these programs, disable file sharing. Here's an article on how to do that.
  9. Lock your car. Take your keys.
    • Limit access to your computer. Unless you really need to share your files and programs with others, turn off file sharing. Here's information on how to do that in Windows XP, Macintosh OS 8 or 9, and Macintosh OS X.
    • Windows has a guest account enabled by default. Who needs it? Here's how to disable it.
  10. Think before you download
    • Avoid web sites or e-mails offering "cracked" versions of commercial products such as Microsoft Office. You might or might not wind up with the product in question (and if you did, you'd be breaking the law), but you'll almost certainly wind up with a mother lode of spyware, viruses and worms.
    • Freeware downloads are OK (as is shareware IF you do the right thing and pay the shareware fee), but make sure you get them from reputable sites such as download.com.
    • Bottom line: downloading files from questionable web sites is the 'net equivalent of trying to beat a veteran card sharp at three-card Monte - a sucker bet.

Want to know more? Here are some useful web sites:

Thursday, September 21, 2006

Yakety-Yak (Don't Talk Back)

Not long ago, I noted how the IT world, in general, seems to be far more interested in the latest cool new feature than in the risks that often accompany that feature.

You'd have thought that the September 11th attacks here in the US of A and subsequent warnings about our continuing vulnerability to cyber-attacks would have acted as wake-up calls to the IT community. Unfortunately, governments in the USA and elsewhere have simply used the attacks as a pretext for increased surveillance of ordinary citizens while doing little or nothing to actually improve security.

Meanwhile, businesses and consumers continue to gaze at the latest sparkly trinket.

Which brings me to IP telephony, a.k.a.Voice Over IP or VoIP. Gartner says IP phone shipments have jumped 53 percent from last year and I, personally, know folks who now do all their voice communications via Skype or similar products. Never mind that, according to a presentation at the latest Hack in a Box conference, VoIP systems are easily hackable and could be used for identity theft or that hackers can already download tools to attack the protocol used by VoIP handsets.

In fact, as a recent Business Week article bluntly states, "VoIP calling systems are just as susceptible to hacking and digital mischief as any other Internet-based application". That includes worms, viruses, DDOS attacks, and phishing.

That last one is especially scary. Most of you out there are probably familiar with how e-mail phishing works (the rest of you can click here). The VoIP version of this would direct you to a phone number - very possibly the actual phone number of your bank - where you would give your personal information to someone who is allegedly on your bank's customer service staff but who is, in reality, working for someone else entirely. Like, for example, the Russian Mafia. That's because your bank's VoIP system has been hacked in much the same way web sites are hijacked now.

Worse yet, the security tools for VoIP systems are far less well-developed than those for PCs and servers. In this area, unfortunately, the Bad Guys are way out in front.

Friday, September 08, 2006

(My)Space Cowboy

I've been hangin' around the IT Corral fer nigh on to thirty years, pardner, an' I've seen some pretty darn dumb ideas come down the Ol' Checksum Trail. You prob'ly even remember some of 'em, even if y'are jes' a whippersnapper:

Dead, ever' one of 'em, and planted up thar on Reboot Hill. Nights, some of the real old-timers - them UNIX guys with the suspenders and the beards, y'know - they claim they can see their ghosts a-walkin' 'round up thar, tryin' to sell ya stock options. Freeze the blood in yer veins, by cracky!

OK, that's enough of channeling old Gunsmoke re-runs, but you get the picture. In technology, as in any other field of human endeavor, the mediocre or outright stinky ideas always out-number the real winners. My nominee for the latest bad idea: social networking web sites in general and myspace.com in particular.

You've probably heard about myspace.com by now, although what you've heard probably depends on whether you're getting your information from technology news outlets like ZDNet or InformationWeek vs. mainstream media sources or propaganda services like Faux (a.k.a. Fox) News. To hear the latter two tell it, myspace is a hotbed of sexual perverts, child molesters and, for all I know, Yetis and Martians. To most of the Propeller Beanie crowd, on the other hand, it appears to be the Next Big Thing.

You know - like information push.

It's not that the idea of the Internet as a social network is inherently bad. Back before there was even a single web site, like-minded folks exchanged information and opinions and formed various types of personal relationships via e-mail and usenet newsgroups. Social networking sites have just made it easier to do so and therefore more accessible to a wider range of people.

"Aye, there's the rub."

Because the easier it becomes to create something - like, say, a web site on myspace.com - the more likely you are to have incompetent people creating it. Myspace has taken this to its logical extreme, allowing members to stick pretty much anything they want on their pages in any way they want, resulting in some of the worst web sites since the early days of Microsoft FrontPage.

I experienced this on a personal level this past weekend when, in a fit of unaccustomed leisure time, I decided to visit the myspace page of a close friend. She had recently gone through a rather nasty relationship break-up and I was curious to see how she was doing. We hadn't talked in a while and her insane work schedule make phone conversations highly unlikely.

We may have to have that phone call yet, though, since I never was able to locate her page - it seems she's using a nom de net that I didn't know about. I did, however, slog through a number of other myspace pages in the process and, to paraphrase the late Warren Zevon, they ain't that pretty at all. Most were so chaotic and so filled with junk media that they were effectively useless. Huge image files there were in abundance, along with automatic slide shows and, that most obnoxious of all features, music that began playing as soon as the page loaded. I decided that the game was not worth the virtual candle and hit the "close" box.

And let 's not even start on the abusive pop-up and pop-under ad boxes!

Besides, even with a less-cluttered interface, fewer ads, and no spyware cookies, a social networking web site is no substitute for - well - social networking. In person.

Jes' lak in the ol' days, by cracky!

Thursday, August 17, 2006

Leavin' on a Jet Plane, Part Two: The Laptop Strikes Back

In my last post on the future (or lack of it) of air travel, I noted that all personal electronics - including laptops - are being banned from carry-on luggage on the premise that they can be used to remotely trigger bombs. What I didn't mention, since it would have amounted to a major (if not augmented) digression, was the way in which this method of reducing risks on the plane is likely to lead to increase risks after landing.

And no, I'm not talking about the Air Rage likely to result from being stuck, with no form of diversion, on a transatlantic flight in the center seat between a colicky baby with the lungs of a Wagnerian soprano and a chatty insurance salesman from Topeka. What I'm talking about is the risk of damage to or theft of those laptops in the checked baggage.

I'm hardly the first person to think of this (or anything else, for that matter). Computerworld ran an article on the problem back on August 10th, along with some very common-sense advice on how to minimize the fallout from breakage (such as backing up data on a regular basis) and theft (encryption and password protection).

That advice is also, I'm afriad, very timely.

A new survey of 500 information security professionals by Ponemon Institute LLC (reported in Computerworld once again) informs us that "eighty-one percent of companies surveyed reported the loss of one or more laptops containing sensitive information during the past 12 months". Eighty-one percent. Worse yet, 97% of stolen laptops are never recovered.

And this happened before the new restrictions went into force. Anyone care to guess what's going to happen in the next twelve months? Corporate spin machines are probably being primed with a fresh load of excuses, diversions, fabrications, obfuscations and some good old-fashioned hooey even as this is written.

It makes the recent flap over recent laptop losses at the Veterans Administration and the Navy look less like an aberration and more like business as usual - especially when you add in the recent loss of two laptops containing "names, addresses, birthdates and Social Security numbers of about 133,000 Florida residents" as well "fraud case files involving government contracts and grants" by the Department of Transportation. Is it any wonder that identity theft "remains the #1 concern among consumers contacting the Federal Trade Commission", according to the Identity Theft Resource Center?

What we have here, in short, is another instance of the law of unintended consequences. In attempting to reduce the risk of terrorist attacks, we increase the risk of laptop theft. That increases the risk of stolen identities, which can, in turn, be used by terrorists and other criminals to achieve their nefarious ends.

Are there steps we can take to minimize those unintended consequences? Certainly. Are we here in the USA likely to take them? Probably not. But that's a subject for a future blog entry.

Monday, August 14, 2006

Leavin' on a Jet Plane

We put up with the long security check-in lines. We sighed as we surrendered our nail clippers and penknives. We took off every possible metallic item except our fillings and shuffled through metal detectors in our stocking feet.

But we grinned and bore it because we understood the need for security and air travel was still bearable, even if it was coming to increasingly resemble the Greyhound bus experience of thirty years ago.

But now the technological sophistication of the Bad Guys has advanced, as it always does, and the bar has been raised substantially for the rest of us.

No liquids, gels, or anything remotely resembling them. Those Dr. Scholls gel insoles are right out; ditto any child's toy with gel components. Also, no books, laptops, MP3 players, cell phones, or pretty much anything else that might make a transatlantic flight bearable. Even electronic key fobs are banned in Britain.

Has long-distance air travel finally jumped the shark? History suggests that this just might be the case.

Consider: Until the spread of mass, mechanized transit in the last century or so, long-distance travel was, for the vast majority of people, a dangerous and expensive proposition. International travel was even more so, and usually, therefore, the exclusive privilege of the very rich.

Think about it. Before the advent of the ocean liner and then the airplane, overseas travel was risky business, indeed. If the weather or scurvy didn't get you, pirates (we'd call them terrorists now) would. Even on the ground, travel via coach for any distance was slow, unpleasant and, of course, there was always the risk of highwaymen.

For a while we lived in a bubble of relatively safe and inexpensive long-distance travel. As the gap between the technology of travel and the technology of travel disruption closes, that bubble may be about to burst. Safe air travel may soon become so expensive that only the wealthy - with private jets and private security personnel - will be able to afford it. Mass air transit will simply be too dangerous.

We live, alas, in interesting times.

Thursday, August 03, 2006

Who Are the Brain Police?

[With apologies to the late Mr. Zappa]

Who are they? Well, to hear some folks over at Slashdot talk, you'd think that they were the managers of the posh Canoa Ranch Resort condominium/hotel in Tucson. It seems that, along with all the other upscale amenities (salon and spa, resort pool, fitness center and “Village Center” - does No. 6 know about this?) the owners are going to provide you with wireless Internet access as well.

Oh, yeah: they're also going to require you to encrypt access to that wireless access point (WAP).

Well, once the Slashdotters got on to that one, you'd think that Jackooted Thugs were just around the corner. As Paul McNamara relates in his July 24th Buzzblog at Network World, “Silly was the least of the insults tossed at this idea.” The technorati were in High Dudgeon (just down the road from Low Dudgeon) and waxed wroth.

Then Roth waxed them for a while, but that's a topic for another blog - probably the one where I defend stealing jokes from Julius Marx.

Anyway, when asked why all the fuss, Sales Manager Bryan Welch said “We just don't want to see anybody hurt with their wireless system. If someone (unauthorized) were accessing it and an owner's information, there could be damage and a potential lawsuit.”

To which The Technology Curmudgeon can only add: “Well, DUH!”

Despite the fact that one Slashdot poster (as quoted by McNamara) took the position that the decision to provide encryption on your WAP was no different from the decision on whether or not to lock your door, the stakes here are clearly higher. Failure to secure your home can result in loss and misery for you and your family, but that's about as far as it's going to go.

Failure to secure your WAP, on the other hand, is more like driving under the influence in that you create a public nuisance, if not an outright menace. An unsecured WAP is an invitation for war drivers to use that access point for a variety of nefarious purposes, including the dissemenation of spam, worms and viruses - all of which cause damage to the community as a whole.

Cruising the Information Superhighway unsecured, in short, is not that different from cruising the Interstate with a fifth of Jack Daniels in your bloodstream.

So, while nobody is seriously suggesting (yet) that There Oughta Be a Law, I don't think you can say of wireless security (to quote “Fats” Waller in a totally different context) “'tain't nobody's business if I do”.

Wednesday, August 02, 2006

I Can See Clearly Now

Or not. Being a dissertation on the process of making lousy decisions.

Ever wonder how some big-time decision-makers wind up making such lousy decisions? It's easy (and not necessarily wrong) to chalk some of them up to a combination of arrogance, greed, and simple immorality. The Vioxx and FEMA debacles come immediately to mind as examples. In an article in the Harvard Business Review earlier this year, however, Max H. Bazerman and Dolly Chugh suggest that there may be another factor operating. They call it "bounded awareness"; most of the rest of us would probably call it "tunnel vision".

According to the authors, "bounded awareness" happens "when cognitive blinders prevent a person from seeing, seeking, using, or sharing highly relevant, easily accessible, and readily perceivable information during the decision-making process". This can cause decision-makers to miss important information just because it's not readily available or because they don't appreciate its significance. It can also result in a failure to share that information because, again, someone has failed to notice that it is, in fact, important.

In a January 9th interview for Computerworld, Bazerman elaborates on these ideas and offers examples of the phenomenon from the lab of Cornell's Ulric Neisser (a key figure in the study of human perception and the guy who coined the term "cognitive psychology" back in 1967, for those of you keeping score) that involve the use of visual illusions. In one study, subjects asked to focus on one particular aspect of a video - how many times a soccer ball is passed among the players - completely miss another aspect that would be obvious to anyone not focused on that first aspect. In this case, it was a woman holding an umbrella walking right through the middle of the game.

Now, this sort of stuff is fascinating to me because, before I became a Technology Professional (and got my official Propellor Beanie, complete with MP3 player, webcam, 1 gigabyte of VRAM and Windows Beanie Edition), I was, among other things, a psychology grad student specializing in visual and auditory perception and statistics. I was also an amateur magician. Findings like this, therefore, are no big surprise to me. What was a bit of an eye-opener was this quote from the Bazerman interview: "In Neisser's study, only 21% saw her. My experience with executives is closer to 3%".

Yup, that's right: according to Bazerman, the guys making the big decisions at the big corporations/governments/whatever are roughly seven times more likely to succumb to tunnel vision than us ordinary mortals.

Of course, anybody can fall prey to this. I have found myself doing it more than once. Unfortunately, the skill to focus and concentrate on a single task - a vital one, especially in IT - is at war with the ability to step back, take a look at the larger picture, and ask yourself whether or not you might be missing something that's right under your nose.

So we all need to make sure we're not missing the woman with the umbrella. She might be trying to tell us that it's going to rain.

Monday, July 31, 2006

There ain't nobody here but us chickens

There ain't nobody here at all. Honest. Now just look the other way while we write anti-spyware legislation.

Everybody remember the Federal "CAN SPAM" law (official title: Controlling the Assault of Non-Solicited Pornography and Marketing Act) from 2003? It was supposed to stop Evil Spammers dead in their tracks and was signed with much hoo-rah.

Unfortunately, not even the Feds really believed it would help. FTC chairman Tim Muris, in fact, opposed it. Why? Because it would make it easier for the companies who hire spammers to claim ignorance of the spammers' business practices. According to Muris, "the FTC would have to prove that the seller (who hires a spammer to advertise a product or service) knew, or consciously avoided knowing, that the third-party ailer intended to violate the law. This standard requires proof of both the seller's and spammer's level of knowledge...These requirements to prove intent pose a serious hurdle that we do not have to meet to obtain an injunction under our current jurisdiction". It also negated existing state anti-spam laws, many of which were more restrictive.

And, of course, we all know what a significant effect the law had on spam, right?

Never content to let well-enough alone, however, Congress is now out to follow up on its anti-spam success with anti-spyware laws. Never mind that, once again, the FTC told Congress over two years ago that it already has the laws it needs, thanks very much. A new law means new photo ops. Let the games begin!

Cynicism aside, there are good reasons to be more than a little wary of this effort. For one thing, major adware and spyware vendors such as WhenU think Federal legislation a good idea - strongly suggesting that this particular chicken coop will have foxes on the no-bid contractor list. CAN-SPAM overrode stricter state laws. Any bets as to what effect new anti-spyware regulations might have on often-stricter state laws like those in Utah?

Ain't nobody here but us chickens.