Thursday, November 27, 2008

A Connecticut Yankee in Kangaroo Court

Another Thanksgiving Day is upon us and before my wife and I head off to stuff ourselves at an Extended Family gathering, I'm taking a few moments to reflect on the things I'm thankful for.

I'm thankful for my lovely wife, for one thing. Also for our 130-year-old home, even if it is continually in rahab. I'm thankful that my 88-year-old mom can still drive up to our place to join us for dinner. And, of course, I'm really thankful that I don't live in Norwich, Connecticut.

That last one needs a bit of explaining.

Norwich is the small town where, four years ago, substitute teacher Julie Amero was charged with (and eventually convicted on) four counts of “four counts of risk of injury to a minor, or impairing the morals of a child”. Her crime? Between the time the regular teacher, Matthew Napp, left the classroom and the time Ms. Amero entered, one or more of the pupils got to Napp's computer. When Amero entered the room, the PC was displaying pornographic images. Her attempts to close the web browser only resulted in more porn being spewed across the screen. In desperation, she turned the screen away from the class and, during the class break, tried (without luck) to get assistance from other teachers.

Never mind that the computer was directly connected to the Internet without a firewall, that it lacked any anti-spyware software, or that the Symantec software that was installed had never been updated.

Never mind that, at the trial, Detective Mark Lounsbury testified that the computer had never been checked for malware.

Never mind that, as noted by Nancy Willard (M.S., J.D.) of the Center for Safe and Responsible Internet Use, the situation Amero had clearly run into a “porn trap” in which trying to close one browser window spawns others at the same site and effective takes control of that browser.

Never mind that Amero had been specifically instructed not to turn the computer off and apparently didn't know how in any case.

No, somebody had to take the fall and a substitute teacher was clearly a more convenient victim than (say) Mr. Hartz, the school's technology director. Could that be why he didn't bother to tell the cops about the lack of a firewall or outdated software?

Indeed, the fact that Amero's lawyer was not permitted to present evidence about the computer's lack of proper security, coupled with testimony from a police expert that the images could only have appeared if Amero intentionally accessed the sites (testimony which Willard, in masterpiece of understatement, labels “totally inaccurate”), inevitably suggest to me that a backroom deal was made somewhere to prevent Hartz and his superiors from facing the consequences of their own gross negligence and incompetence.

Computer security professionals were understandably outraged at this travesty of justice. Articles were written and lots of cyber-hell was raised. The case was appealed and the original conviction thrown out by a superior court judge (superior in more ways than one, in my view) in New London. The whole sorry mess finally came to an end on November 21st when Amero, obviously worn down by five years of repugnant legal harassment, pled guilty to a disorderly conduct charge (a misdemeanor, as opposed to the original outrageous felony charges), paid a $100 fine and, in a final disgusting act of injustice, had her Connecticut teaching credentials revoked.

So, yes, I'm thankful that I don't live in a town and state in which being the innocent victim of official ineptitude malware malice is a felony. I wish only the best of Ms. Amero and her family and hope she's able to get on which her life. She might want to start by moving to a city and state where truth gets a little more respect than it does in Norwich, Connecticut.

Saturday, August 02, 2008

Partly Cloudy

I’ve looked at clouds from both sides now
From up and down, and still somehow
Its cloud illusions I recall
I really don’t know clouds at all

- Joni Mitchell, “Both Sides Now”

A lot of customers of amazon.com’s much-hyped Simple Storage Service (S3) were probably singing that song back on July 20th when (as reported by Information Week, among others) problems with “internal system communications” took S3 off line for eight hours. Worse yet, this was the third such outage in the company’s flagship “cloud computing” application.

What, you never heard of “cloud computing”? There's a respectable definition on Wikipedia, but essentially it's another form of outsourcing in which traditional corporate IT functions like data storage are made available by a third party as a service. The idea is that your company connects to the provider's network via the Internet - traditionally represented by a cloud graphic on network diagrams and PowerPoint sales presentations - and the provider takes care of all the nuts and bolts for you.

Launched in 2006, S3 was sold as a reliable alternative to big, power-hungry server farms.It was especially attractive to small businesses with big storage needs like SmugMug, ElephantDrive, Jungle Disk and others. Now some of them may be starting to wonder if trusting a critical business function to the vagaries of the Internet and Amazon's internal network was such a great idea after all.

This, of course, is the whole problem with cloud computing - to say nothing of Web 2.0, Software as a Service (SaaS), and all the other trends that involve sending your critical data off into a black box over which you have no control and about which you don't really know all that much. Sure, you've got a service level agreement. But how much does that mean when, as in the case of S3, the only way you can apply for a credit for the outage is via email? And how much is that credit worth, anyway, if your important data was unavailable for an entire business day? Are you really saving money if your storage isn't 100% reliable?

Sometimes you get what you pay for.

Tuesday, July 15, 2008

Four Minute Warning

If you're one of those rare individuals with sufficient taste and intellectual joie de vivre to read this blog on a regular basis, you're probably aware that when I'm not being a propeller beanie type for Really Big Company, I'm a writer, radio broadcaster, theatre critic and actor. This means that in the Green Room, I'm likely to be the only carbon-based life form who knows enough about PCs to troubleshoot them for my fellow thespians. Like the proverbial doctor at the cocktail party, I get a lot of requests for free diagnoses and advice, except that in my case the patient has only artificial intelligence.

One thing I've taken away from these backstage conversations is that - as I noted in a minor jeremiad last year - there are an awful lot of computer users out there who, if they maintained their cars the way they maintain their PCs, wouldn't be allowed out on the street, much less on the (information) highway.

Last month, for example, while appearing in Stray Dog Theatre's production of Paul Osborn's lovely comedy Morning's at Seven, one of the actors complained that her Windows laptop had become so slow that she could hardly stand to use it and was thinking of buying a new one. My first question was, “Do you have anti-virus and anti-spyware software installed and if so, are they up to date?” The blank stare I got was all the answer I needed.

I was reminded of this recently when I saw a post by Lorna Hutcheson on the SANS Institute's Internet Storm Center blog indicating that an unpatched Windows PC connected to the Internet can expect to survive around four minutes before it's probed by a worm or other attack bot.

Four minutes. That's less time than it would take for the PC to download the latest patches from Microsoft. In fact, as Daniel Wesemann noted in a comment on the blog:

“While the survival time measured varies quite a bit across methods used, pretty much all agree that placing an unpatched Windows computer directly onto the Internet in the hope that it downloads the patches faster than it gets exploited are odds that you wouldn't bet on in Vegas.”

I'm guessing that my fellow actor's PC had probably been on the 'net for years without proper protection. It's no wonder it was so slow; when your PC is busy pushing malware and spam to all and sundry, there aren't many processor cycles left for unimportant stuff like reading your email.

I offered to do a Spybot S&D scan on her PC for her but she had already decided to shell out for new PC. A week or two later she had it connected to the unsecured wireless access point that was available backstage, cheerfully logging on to her email server and doing heaven only knows what else without the benefit of encryption. Any bets on how long it takes this one to come to a screeching halt?

Her four minutes are already up, after all.

Thursday, June 19, 2008

Influence Peddlers

I'm not normally a big fan of bumper stickers as a way of getting a message out; most are a waste of time and many are just plain obnoxious. Still there's one that might persuade me to change my mind: the “Hang Up and Drive” sticker that urges cell phone addicts to put the damn thing away and pay attention to the 2,000 pounds or so of metal and plastic they're supposed to be controlling.

I'm not the only person who feels this way. As reported in a recent Computerworld article, many states are taking action to ban cell phone use while driving and researchers are pointing out that other distractions - including MP3 players, internet access devices, GPS and even video players - have the potential to make the problem far worse. It's bad enough that we still have people hurtling down the freeway while intoxicated; now we've got to take into account jokers who are watching TV at the same time.

Unfortunately, legislation aimed at specific sources of distraction misses the main point. An automobile is a big, potentially dangerous machine. The operator of that machine needs to be focused on using it in a matter that is safe both for him/her as well as for other motorists. What really needs to be illegal is, for lack of a better phrase, Driving While Impaired.

Current drunk-driving laws address one form of DWI, but the explosion of technology-based forms of impairment clearly demands modernized legislation that penalizes any form of impairment, regardless of the source. Simply passing more laws targeted at specific sources of distraction (such as cell phones or GPS) is just playing "whack a mole" with the problem; as soon as you ban one, another one will pop up.

Operating a car isn't a right. It's a privilege that carries with it certain responsibilities. That's why we have tests on driving skills and laws as requirements for a license. That's also why we have periodic vision tests at license renewal time. Driving unimpaired is just another one of those responsibilities and, considering the loss of life and limb that results from failing to live up to that responsibility, it's probably the most important one.

Wednesday, June 11, 2008

Sound Bytes

Every now and then I come across an item that spans the divide between my technology blog and my performing arts blog - which is why I'm publishing this little essay in both. Case in point: this interesting item from the New York Times about the use of all-digital orchestras by small companies.

The technology is intended, supposedly, to supplement a small live orchestra. As the author points out, however, there's nothing to prevent it from replacing live musicians entirely.

On the one hand, it might be a boon to small, cash-strapped companies that can't afford to hire many (or any) musicians or community theatres with volunteer orchestras that leave something to be desired in terms of competence. On the other hand, it could make real musicians an endangered species, which is hardly a desirable outcome.

In any case, you'd think it would be an interesting topic for discussion. I expected, therefore, a flurry of responses when I posted the following question to two local theatre email lists: newlinetheatre and stlouistheatre: Would you use an all-digital orchestra for a production?

What I got was a whopping total of one response from New Line Theatre's founder and artistic director Scott Miller, who stated categorically that he would "never do a musical without live musicians". That was hardly surprising, by the way; I've known Scott for some years now and was well aware of his disdain for canned music.

I'm not sure what to make of that. There are a number of musical theatre producers on both lists. Surely at least one of them has an opinion on this. It's not an academic issue, after all. High schools are already using all-digital or mostly-digital orchestras. Surely it's only a matter of time before those small companies referred to above find themselves asking whether or not they should go digital.

So why the silence? Is it because they're all in agreement with Scott? That would be the happier explanation as far as I'm concerned. Or is it because, given the potential cost savings, they wouldn't even bother to think about it before going digital? Could commerce really have trumped art to that degree?

Scary thought, that. Are we facing a future like the one Walter Miller described in his Hugo Award-winning story The Darfsteller? Film extras have already been supplanted by digital animation in big-budget pictures. Could real, live performers of all kinds go the same way?

Will we eventually get to the point where we have made ourselves obsolete?

Monday, June 09, 2008

The Humanoid Boogie

[Thanks to The Bonzo Dog Band for the title.]

A couple years ago, on an internal company blog, I commented on the ways in which the right hand of the information technology industry not only doesn't know what the left hand is dong but often seems unaware that there even is a left hand. Breathless dispatches in technology trades about mashups, Web 2.0 (or is it 2.1.0.5 SP 2 now?) and other ways for everyone to connect to everyone else sit cheek by virtual jowl with sober articles on how we're losing the cyberwar with spammers, malware distributors, identity thieves and other net.swine. Don't the people who write these things ever talk to each other? It's as though they live on different planets.

I had similar When Worlds Collide experience the other day, albeit on a different technological front. It happened as I was listening to NPR's Science Friday talk show. The guest was “futurist” Ray Kurzweil expounding, as he usually does these days, on advances in computer and medical technology that will make us all cheerful cyborgs, living longer and happier lives through the integration of humans with computers. Listening to Kurzweil paint a rosy picture of the posthuman future, it's easy to forget to ask some fairly simple questions about it; questions that host Ira Flatow never thought to bring up.

Questions like: where are we going to get the power for the man/machine hybrid? Or: how much will this wonderful cutting-edge biomedical technology cost? Who's going to pay for it? And, for that matter, who's going to be able to afford it?

Given that in 2005 (the most recent year for which data are currently available), nearly 47 million Americans (just under 16% of the population) had no health insurance - and therefore no access to health care - those are hardly irrelevant questions. Indeed, even Americans with insurance are seeing their out-of-pocket costs increase. Add in the fact that employer-based health insurance is quickly turning into a luxury and you have to wonder how many of us really will get to be posthuman.

This was brought to my attention rather dramatically a few weeks ago when I got a new CPAP machine. A CPAP (Continuous Positive Airway Pressure) device is a fairly simple bit of technology that effectively eliminates snoring and sleep apnea. Those of us who suffer from those conditions know only too well how beneficial these little devices are. Not only are we less tired, but we're also less at risk for serious health conditions in later life, including stroke and cardiovascular disease.

Once the newer machine was delivered, of course, I had no use for the old one. As I'd had it for over six years, my insurance company had long since declared it my property. I therefore decided to give it away on freecycle.org.

What happened next was a stark illustration of the difference between Ray Kurzweil's future and everybody else's present. Within less than five minutes of making the offer on freecycle, I received well over a dozen replies - and kept getting them even after I posted a notice that the machine had been taken. All of them told essentially the same story: they had sleep apnea, they had insurance - and their insurance refused to pay for a CPAP machine.

Bear in mind that this is well-established and relatively inexpensive technology with a proven track record of correcting a condition which, left untreated, can lead to serious illnesses which are much more expensive to treat than sleep apnea. If insurers are so focused on short-tern costs that they won't even cover something this basic, how likely are they to ever cover the kind of Buck Rogers stuff discussed on Kurzweil's web site?

Meanwhile, the millions without any insurance are lucky to get a flu shot.

That doesn't mean the posthuman future won't happen. It will just happen to the shrinking percentage of the population that can afford the latest and greatest nanotechnology. Without drastic reforms to America's health care system - which delivers less care for more money than that of any other first-world nation - Kurzweil's future will be a dystopia of nearly immortal elites governing the destinies of highly mortal masses.

On the other hand, maybe we commoners aren't supposed to have acsess to that stuff. Maybe we're just supposed to buy the high-priced nutritional supplements Kurzweil is hawking on another site.

Wednesday, May 28, 2008

Top Ten Vexes

[With apologies to Lewis Furey for the title.]

Like many of you, I expect, I get a lot of unwanted commercial email, a.k.a. spam. I haven’t taken a count, but I’d say something like 80% of the email sent to me is spam these days.

Only a tiny fraction of it ever makes it to my in box, of course, because I have two levels of spam filtering in place – one at the server level and one at the client level. Over the years I have fine-tuned them so that I get few false negatives (junk that eludes the filters) and even fewer false positives (legit email pegged as junk).

Still, I have to scan the subject lines of my junk mail weed patch daily to remove the occasional flower. When doing so, it’s hard not to notice the sheer idiocy – to say nothing of hallucinatory incoherence - of most of those subject lines. Many of them are random strings of words or letters apparently designed to defeat spam filters. Others, however, are so actively obnoxious that you’d think they’d defeat the entire reason for their existence. Would anyone with two neurons to rub together really open an email with some of these titles, much less follow a link contained therein and, even more incredibly, actually buy something at that link? Apparently P.T. Barnum was right.

So here, for your dining and dancing pleasure, are my (so far) top ten least appealing spam email subjects, in the style of David Letterman. I can’t imagine who is opening these emails. I just hope he or she doesn’t live in my neighborhood. Or in my city. Or on my planet.

Top Ten Least Appealing Spam Email Subjects

10. Top Rated Australians on Sale

9. What They Don't Want You to Know What it Does to Your Body!

8. With this medicine may lead to unconsciousness or death

7. Chuck Norris is looking for you

6. Jessica Alba stares at me

5. Update your Penis

4. Quality Narcotic Support

3. Pimp my ass

2. russian roulette games

And the number one least appealing spam email subject:

Nazi Chat Room

Friday, May 02, 2008

Miami Vice II

Well, dear friends, the latest installment of Mac Wars II: Attack of the Clones is now out. My earlier suspicion that Mac clone maker Psystar might be little more than a hustle notwithstanding, it appears that the Miami-based startup is actually producing a product - or at least a demo product that got a nice review on CNet. Their bottom line:

Its hardware isn't made by Apple's design team, it will likely never work as a full member of the greater Apple ecosystem, and one ill-intended software update could turn it into a $750 brick. Get past all of that, and you'll find Psystar's OS X-based Open Computer a fast and otherwise compelling lower midrange desktop.

Personally, I'd be a lot more concerned that Psystar is a startup, and one that's had a shaky history (see my previous blog post for a summary). The computer may come with a one-year warranty but if you ask me it's even odds as to whether these guys will still be around in one year.

Maybe we should wait for Mac Wars III: Revenge of the Apple.

Sunday, April 20, 2008

Miami Vice

Hey buddy - have you heard the one about the Mac clone?

There are times when it seems like every day is April Fool's Day in the technology news; times when some of the stories are strange enough to make you wonder whether or not somebody isn't having a big laugh at our expense.

Take, for example, the story of the Mac clone maker Psystar. At least, they say they're making Mac clones; so far, nobody has actually seen one despite what the Miami-based company claims is the “incredible response” to the offering of its Open Computer, pre-loaded with Apple's OS X. Shortly after announcing its product line early last week, Psystar's web site went down. In the days that followed, the web site went back up, but the company's business address changed repeatedly (“four times in the matter of a few hours” according to Adrian Kingsley-Hughes' Hardware 2.0 blog at ZDNet).

Then their credit card payment processer, Powerpay, dropped them. According to News.com's Tom Krazit, “Louisa Deluca, vice president of loss prevention for Powerpay, said on Thursday [April 17th, 2008] that her company dropped Psystar because it violated the terms of its agreement with Powerpay”. Psystar switched to Paypal, only to be given the virtual axe by them less than 48 hours later.

The punch line, however, is to be found in a Forbes piece by Brian Caulfield, wherein we learn that Psystar's founder “won't go on the record about his educational background, detail his professional history or name any previous ventures” (THAT'S certainly not suspicious) and acknowledges that the Open Computer “is based on a machine put together by his brother (whom he won't name). Nor will he say how the new computer works.”

“I'm not making this up, you know!” as Anna Russell used to say.

To be fair, it's always possible that Psystar, despite making every possible mistake a start-up can make, might actually cough up a product. They claim it takes around two weeks to turn one out, so by early May we should know whether or not the folks who managed to give them their credit card numbers before everything crashed have been taken to the cleaners. So far the only evidence we have that the machines even exist is some images from Psystar collected by ZDNet.

And that's assuming that Apple doesn't let loose the dogs of law. There's still the inconvenient truth, after all, that Apple's EULA prohibits the installation of OS X on non-Apple hardware. Psystar said they'll challenge that in court, but then Psystar is saying lots of things that raise one's virtual eyebrows.

Given that Open Computer prices start at $399, I'm skeptical. As Larry Dignan noted in his Between the Lines blog, "I’d rather let you trusting souls be the guinea pigs before I pay up for a Mac clone. If it sounds too good to be true it probably is". If I had to make a bet, I'd lay heavy odds that its lawyers who will have the last laugh here.

Thursday, April 10, 2008

Safety Last

The title of the April 9th Computerworld article was interesting: "DHS chief says feds need help to defend Internet against cyberattacks". Given this administration's track record when it come to power grabs, I expected this to be a sales job for Chertoff to claim even more authority.

Looks like I was wrong. Chertoff acknowledges that "[t]here is no question that one of the threats that continues to materialize again and again is the threat to our virtual world of cyberspace," and that a successful attack could have a world-wide "cascading effect". He just doesn't think government can do much about it. Check out this quote:

But defending cyberspace is different from protecting buildings and other physical targets, Chertoff said. The federal government doesn't own the Internet or much of the technical infrastructure on which it runs, he noted. As a result, he declared, it's the shared responsibility of the government and the private sector to guard against cyberattacks.

"We're operating in a domain where traditional military power or the power of government is insufficient to address the full nature of the threat," Chertoff said. "We need to have a networked response to deal with a networked attack."

Translation: "I need to make it look like I'm doing something but I don't want to force the administration's corporate cronies to do anything that would cost them money, so regulation is right out of the question."

Note that this is the same Michael Chertoff who, according to the April 8th New York Times, declares that he has the power to unilaterally invalidate dozens of laws in order to build a fence at the Mexican border (a boondoggle if ever there was one, but that’s another rant). Why not use this same constitutionally suspect dictatorial power to force corporations to secure their network? After all, declaring itself above the law is SOP for this lot.

The answer, of course, is that doing so would annoy the corporations that call the shots in this administration.  They're perfectly happy to have Chertoff sweep away environmental laws that get in the way of the holy pursuit of a fast buck.  Telling them to spend money on security, on the other hand, would be a quick way to an early retirement so he could "spend more time with his family".

Meanwhile, as reported on the very same day at news.com, security experts have demonstrated that gaining control of the systems at a power station via social engineering and malware is a no brainer.  Don't hold your breath waiting for Chertoff to force the power industry to clean up its act. See above.

Thursday, January 24, 2008

Fakin' Care of Business

OK, you already know you can get infected with malware by visiting web sites in the Internet's red light district or by foolishly clicking on links in e-mails promising to decrease your mortgage payments or increase the size of various body parts. So you should be fairly safe, right?

Wrong.

It turns out that avoiding obviously shady web sites isn't enough. According to Websense's Second Half of 2007 review the majority (51%) of malware attacks in the last half of 2007 came from legitimate web sites that had been hacked.

How is this possible? Here's what Websense's vice president of security research, Don Hubbard, had to say in a January 23rd, 2008 article in Computerworld:

Sites are hacked in a variety of ways, said Hubbard, who noted that there is no one method that stands out. "[Compromises are] all over the place, unfortunately, [including] miss-configurations, no patches and so on."

In other words, the companies responsible for the compromised sites aren't taking security seriously. That's because making web sites and applications secure costs money without making any obvious contribution towards profits. Given the choice between making a web site more secure and sticking more bells and whistles on it, corporate America's empty suits will inevitably choose the latter.

And it's not just web sites you have to worry about. The Websense report also notes that 87% of email messages are spam and that 67% of those unwanted emails include links to malicious or spam-producing sites.

In fact, thanks to the proliferation of digital add-on devices, you can get infected without even opening an email or starting up your web browser. As reported in a January 19th product alert, digital picture frames made by Insignia (and sold at Best Buy) "were contaminated with  a computer virus during the manufacturing process." When you use the frame's USB connector to download an image from your PC, the frame reciprocates by uploading an (unspecified) virus.

Insignia doesn't say where the infected frames were made, but given the low prices of their products and some comments in on-line forums, it seems likely that they're made in that hotbed of high product quality, China.

The fact that China is actively engaged in cyberwar with the USA is, of course, just a coincidence.

Wednesday, December 12, 2007

Can't Stop the Music

Sometimes, you've just got to wonder.

In a recent posting on his Recording Industry Vs. the People blog, lawyer Ray Beckerman maintained that the RIAA is now, in the case of Atlantic v. Howell, labeling any copying of music files as copyright violations, whether you share and/or re-sell them or not. ZDNet's Adrian Kingsley-Hughes immediately took issue with him, claiming that the RIAA said the defendant was in violation only when he copied the MP3 files to a shared drive.

In this particular case, Kingsley-Hughes may be right, but it hardly matters. The hostility of both the RIAA the the industries it represents to any copying of music and video files for any purpose at all has a long and shameful history (remember the Sony rootkit fiasco?). For that matter, the RIAA web site (as one of the Talkback responses to the article points out) explicitly states that any copying is unauthorized. And, of course, there are the clueless comments from chairman and CEO of Universal Music Group, Doug Morris, in the latest issue of Wired.

Let's be clear on what this means.

That mix CD you made for your wife's birthday? Bad.

The sound design you did for your local no-budget community theatre? Bad.

The customized Christmas CD you made for your car? Bad.

Let's get real, folks; the RIAA and the industries it represents know they haven't got a snowball's chance in hades of stopping the actual pirates. The entire intent of the various DRM schemes is to force law-abiding consumers to purchase the same material over and over - or to eliminate purchases entirely and make everything a rental. Their model is the software EULA, which basically says that your don't own zip.

So while the RIAA may not be saying all copying is illegal in this particular case, make no mistake: that is their ultimate goal, and they'll pursue it with all the lawyers and lobbyists at their command.

Friday, December 07, 2007

I Fought the Law and the Law Won

Urban Legend has it that when the late Willie Sutton was asked why he robbed banks he replied "because that's where the money is".

If he were around today he'd probably scoff at bank robbery. These days the real money is clearly in spyware.

It shouldn't be news to anyone, of course, that cybercrooks are using spyware to generate big bucks, primarily by stealing credit card and banking information and reselling it to other swine on the 'net. What may be news, however, is the fact that many of the tools used by these characters are completely legal and available at "crazy low prices", if not for free.

The bust of a couple dubbed "the Bonnie and Clyde of identity theft" illustrates the problem. As described in a recent article in Digital Journal (among other places):

Jocelyn Kirsch, 22, and Edward K. Anderton, 25, were living a lavish lifestyle: trips to Paris and London; salon visits costing $1,700 each; a $3,000-a-month apartment in upscale Philadelphia. Kirsch and Anderton didn't earn any of these luxuries – they stole money using a complex identity theft scam.

What's especially interesting about this is that the couple didn't need to invest huge amounts of money or technical expertise to do this. All they had to do was buy a $100 spyware program called Spector Pro (from Spectorsoft). Although widely identified as malware by major anti-virus vendors such as Symantec and Safernetworking.org (the makers of Spybot Search and Destroy, one of the better anti-spyware products around), Spector Pro is also a PC Magazine Editor's Choice award winner and touts itself as a tool for enhancing corporate security by allowing employers to monitor employees' internet activity.

The thing is, the behavior of the program itself is indistinguishable from that of other forms of malware. Here's how Symantec describes it:

Spyware.Spector functions in a manner that is similar to a Backdoor Trojan Horse. When it is installed, it logs all the activity on the system. The person who installed it can then watch all the logged activity.

Spectorsoft president Doug Fowler, of course, disclaims any responsibility for the nefarious use of the product. According to ABC News (where this story originally broke):

"SpectorSoft has never marketed its software as a way to steal from people, to assume another's identity," Fowler wrote in an e-mail. "Any piece of software has the potential to be abused."

If this sounds familiar, it might be because the same justification is offered by anyone who profits from the sale of dangerous and/or deadly items. Be it agribusiness, Big Tobacco, or the NRA, they all insist that it's not their fault if the folks to whom they have aggressively and expensively marketed their products wind up morbidly obese, coughing up a lung, or mowing down a few dozen family members, friends or acquaintances.

Legally, of course, they may be right. Attempts to hold the "Merchants of Death" accountable have largely failed thanks to flotillas of high-priced lawyers and a federal government that never met a corporate lobbyist it didn't like.

Legality and morality are hardly identical, however, and the ethical situation is far less clear. My take on this is that if you are selling a product that you know, beyond a doubt, is going to be used for a moral wrong, you better be certain that said product isn't designed primarily for that purpose and/or that you're serving a greater moral good by offering it.

For example: a hammer can certainly be used to commit murder, but that's not even remotely what it's designed to do. And in any case you're helping someone build something by selling it. Weapons, on the other hand, face a far higher hurdle since their principal purpose is to kill.

By that standard, Spectorsoft is treading on potentially thin ice. Yes, their software can be used by businesses to prevent unethical behavior by their employees, but Spectorsoft doesn't just market to businesses. Indeed, two of their products (the aforementioned Spector Pro and eBlaster) are targeted at individuals who want to spy on each other, including parents who want to spy on their children.

If it walks like a duck, quacks like a duck, and gobbles up your keystrokes like a duck, shouldn't we conclude that it's fair game during Duck Season?

Wednesday, December 05, 2007

Money (That's What I Want)

What would you call a business that secretly spies on its customers, threatens them with massive lawsuits if they refuse to re-purchase a product they've already bought, and generally assumes that they're all crooks out to steal merchandise?

Apparently, you'd call it the music business.

Many of you may already know about Sony's infamous rootkit scandal from 2005, in which the media giant was caught installing spyware on the PCs of everyone who bought their CDs - without, of course, bothering to ask permission first. Cybercrooks quickly figured out how to exploit the malware and Sony was faced with a raft of lawsuits, which are still wending their way through the legal system.

That was bad enough. Around the same time, however, the industry trade group The Recording Industry Association of America, began launching thousands of lawsuits against individuals who had shared songs they had already bought via Peer to Peer (P2P) networks such as Napster. The claim was that this was an effort to combat piracy and claims were made (wildly inflated, in my view) of the amount of revenue lost by the industry - despite the fact that industry profits remained spectacular.

It's an odd claim, considering that the victims of these lawsuits weren't actually making any money from their infringement. If piracy of copyrighted material is an issue why not go after the big international pirates who are selling the stuff for a profit, largely overseas?

The answer - if a recent “Justice” Department ruling is any indication - is that it's cheaper to take every last cent of song sharers here in the USA than it is to go after the big-time international crooks who are really eating your lunch. Taking a couple hundred grand from some poor schlemiel who shared tunes with his buddies is easy money when you already have an army of lawyers on retainer.

Will this have a deterrent effect of P2P music sharing? Probably. Will it have a deterrent effect on the big-money pirates? Almost certainly not. But if you've already decided that suing your customers is a valid business model, maybe you don't want the pirates to stop selling your stuff for $4.00 in Beijing. You've already given up on that, and having them around allows you to continue to make exaggerated claims about how much money you're losing.

Pay no attention to those massive profits behind the curtain. Government of the corporation, by the corporation, and for the corporation shall not perish from this earth.

Thursday, November 29, 2007

Blue Christmas

'Tis the season to be generous. That means lots folks are logging on to the web sites of non-profits like CARE and the Red Cross to make donations, either for themselves or as gifts to friends and family who already have all the electronic gizmos and consumer crud they need.

Unfortunately, some of those good-hearted souls are going to find a lump of coal in their Christmas stockings in the form of stolen email addresses and passwords. As reported in Computerworld on November 28th the FBI is investigating a data breach at Convio Inc., a firm that specializes in recruitment and fund raising software and services for the non-profit sector. According to the report, criminal hackers managed to lift information on 92 non-profit organizations (including The Red Cross and CARE) and were preparing to help themselves to data on another 62 when Convio discovered the leak in their data dike and plugged it.

How did this happen? Here's a Convio spokesperson, as quoted in Computerworld:

The intruder obtained a log-in and password belonging to a Convio employee," wrote Dave Crooke, a company staffer, on a mailing list used by nonprofit professionals. "It appears that their PC was compromised, but we are still investigating".

Those of you who read my earlier blog entry on the importance of keeping your PCs secure will not be surprised to discover that I rolled my eyes as I read that. A chain is only as strong as it weakest link. A company's data is only as secure as its most clueless employee's PC. Your personal data is only as secure as your own PC. Why is it so hard for some people to comprehend this?

The situation isn't going to get any better. Cybercrooks are getting smarter as operating systems become more secure. Windows and OS X are too locked-down to be easily exploited? No problem - there are plenty of individual applications (like QuickTime, Windows Media Player, Firefox and - of course - Internet Explorer) with vulnerabilities. The corporate love affair with outsourcing application development to countries (such as China, Brazil and Russia) that are havens for cyberthieves, combined with the tendency for developers to consider security as less important than bells and whistles, provides fertile ground for a bumper crop of exploits. And, of course, good old-fashioned social engineering, phishing, and other techniques based on the notion that there's a sucker born every nanosecond will continue to be useful to what The Saint referred to as “The Ungodly”.

But don't take my word for it. Take a look at the SANS Institute's Top 20 2007 Security Risks report. According to them, “[t]he number of attempted attacks for some of the large web hosting farms range from hundreds of thousands to even millions every day.” If computer security is an arms race (which it is), the Bad Guys are 'way out in front.

With apologies to The King: You'll be doin' all right with your Christmas of white, but security pros will have a blue, blue Christmas.

Thursday, November 01, 2007

Absolutely Free

Well, it's now official: there will be no free wireless Internet access for the city of St. Louis. Originally conceived as a city-wide service, municipal Wi-Fi (wide-are wireless service) will now be confined to a downtown-only “pilot project”.

In the technology business, “pilot project” is often a euphemism for “consolation prize” - although in this case it might just be a realistic alternative for the near term. Condo developments are sprouting like dandelions in downtown St. Louis right now (see the Urban St. Louis site for some examples ), so a municipal Wi-Fi network there might actually be profitable.

There's no need to go into the gory details behind the failure of the original plan as they're available on line, although it is rather surprising that it took so long for somebody to notice that there's no power running to city street lights in the daytime - thereby killing the plan to mount Wi-Fi antennas on them. Anyone who has spent any time in the city after dark has surely noticed that lights go on or off in blocks rather than individually.

St. Louisans need not feel stigmatized by the evaporation of this particular techno-mirage, though. As The Economist magazine noted in an August 30th article, “many municipal Wi-Fi projects have since been hit by mounting costs, poor coverage and weak demand”. Chicago has killed its muni Wi-Fi project, as has Springfield (IL) and even San Francisco. Meanwhile, existing networks, from Tempe (AZ) to Taipei, have failed to fully live up to expectations.

Some of the problems are technological. The outdoor transmitters don't generally have the power to penetrate walls effectively, or examples, so indoor coverage is spotty. But the main barriers to the spread of municipal Wi-Fi networks appear to be economic.

Building the basic infrastructure that would provide seamless, wireless Internet access is expensive. A 2005 Jupiter Research paper estimated that price at $150,000 per square mile. An October 27th, 2007, article in the St. Louis Post-Dispatch estimated the cost at closer to $200,000. Even in a relatively small geographic area like the city of St. Louis (62 square miles), that's a lot of money invested up front with no real guarantee of a profitable return.

One solution, as municipal WiFi advocate Esme Vos suggests in a recent interview, might be for cities to provide the basic network access infrastructure - the wireless transmitters and related back-end hardware and software - in much the same way they now provide physical infrastructure such as roads and sewer systems. They could open up these networks to the Internet service providers, who would sell the actual Internet access to subscribers just as they do now over existing telephone lines. Cities could pay for the network investment via a combination of taxes and payments from the Internet carriers.

This might also have the advantage of making the hurdles lower for ISPs who might want to sell to the folks connecting to the municipal network. As Vos points out, this is what has happened in “Nordic countries” where this “socalist” approach has actually resulted in more consumer choice than here in the USA, where our options are usually limited to either the cable monopoly or the telecom monopoly.

That's because free-for-all capitalism tends to devolve into a small group of non-competing monopolies. But that, I suppose, is another blog post.

Tuesday, August 14, 2007

Hey Bartender

I'm still not dead yet!

See, there are two ways you can approach this whole blog thing. Way 1 is to write something every day or thereabouts regardless of whether you have anything to say or not. Way 2 is just to write something whenever the mood strikes you.

Way 1 probably gets you more readers, but Way 2 produces better articles. Given that there are already too many bloggers gassing on about too many things, I have chosen Way 2.

Besides, I'm lazy.

So: what vital concern moved me to get off my virtual duff and compose this entry? Is it a dire new threat to the Internet like the latest attack by the "Storm" worm? A cool new technology like the Linux-based iPhone killer? An egregious bit of stupidity like the Wall Street Journal's "Ten Things Your IT Department Won't Tell You" article (a.k.a. "How to Get Yourself Fired and Break the Law in Ten Easy Lessons")?

Nah, none of the above. The Storm worm is just an old threat in a new package, Linux has a long way to go to match iPhone's cachet, and intellectual dishonesty is just business as usual at the Journal.

What got me to finally update this blog is the demonstration, by the folks over at Tom's Hardware, of the value of beer (Molson Canadian, to be exact) as a CPU coolant. According to their test protocol (which, in all fairness, seems to have been devised after imbibing some of the coolant), the only thing that out-performs a brewski is SilverStone Thermal Fluid - and then only by a fraction of a degree.

There's no mention of how Silverstone performs against Molson in a taste test, alas.

Such are the thoughts of an IT geek's fevered brain after three weeks of a killer heat wave.

Tuesday, June 19, 2007

The Dark End of the Street

"I'm not dead yet!"

Yes, despite the fact that I haven't written anything in this blog for a couple of months, I'd not dead yet. I feel happy! I feel like - dancing!

Besides, I haven't been silent. Stage Left, the blog from the other half of my brain, has been pretty lively lately because of all the shows I reviewed in June. And I'm working on a new op-ed piece for the St. Louis Post-Dispatch. It'll be published on July 8th and I'll have a link to it here by the 9tth or thereabouts. My May musings for that publication can be found here. There's a March column as well, but it has been moved to their paid archives. Killjoys.

Still, the main reason there's been nothing here for a while is that there's been so much technology news lately that it's hard to keep up: Apple's iPhone and new MacBook Pros, Microsoft's coffee table computer (which looks suspiciously like the open-source ReacTable, not that I'm suggesting anything) and, of course, the daily flood of malware news.

I'll leave comments on the latest Bright Spaklies for another column. This time I want to expand on some advice from my ten-point Internet safety check. At the time, I advised you to "think before you click" on a link in an e-mail or at a web site. The idea was to avoid sites that were clearly dangerous or which might mimic legitimate sites.

Now, it seems, things have got even more complicated. According to a June 18th article in Computerworld a "phenomenal" number of web sites - mostly in Italy, so far - have been compromised by a gang using a Russian-made exploit kit called MPack. The hacked sites are used to download malware - mostly keyloggers, designed to grab user names and passwords - to unprotected computers that visit these otherwise legitimate web sites.

This is bad news, to say the least. It means that even if you're careful to avoid the dark end of the virtual street, you can still get mugged. Trend Micro network architect Paul Ferguson, quoted in the Computerworld article, puts it this way: "The usual advice we give, 'Avoid the bad neighborhoods of the Web,' just doesn't hold water anymore. Everywhere could be a bad neighborhood now."

Oh, joy.

Could be worse, of course. If you followed my advice back in February and installed multiple anti-virus and anti-spyware products, you're still likely to be protected from hacked sites. But this does ratchet up the paranoia level and raises an unpleasant question: just how risky does doing business on the Internet have to become before large numbers of computer owners decide it's not worth the trouble? And what will the economic impact be if that happens?

Thursday, April 26, 2007

When Will They Ever Learn?

Well, folks, don't say I didn't warn you. In July of 2006, when the Fedabobble Gummint started work on anti-spyware legislation, I expressed my usual curmudgeonly cynicism over the likely results. Among other things, I noted that the FTC had already told Congress it didn't need any additional legislation (a fact reinforced by recent successful actions against spyware offenders) and that at least one major spyware vendor was backing the effort, making it all of questionable value at best.

Comes now blogger Ed Foster at InfoWorld with evidence that my crystal ball was, at least in this case, in good working order. H.R. 964, the so-called Spy Act, carves out major exceptions for ISPs, software vendors, and pretty much anybody else who can claim you're doing business with them. Worse yet, the bill preempts stricter state laws and states that "no person other than the Attorney General of a State may bring a civil action" in such cases.

Had this bill been law when Sony installed its infamous rootkit on the PCs of unsuspecting consumers, there would have been no legal remedy available to individuals. Only a state AG could have taken action, and s/he wouldn't have in any case because the law would have made that rootkit legal.

Time to notify your Congresscritters that they should be spending more time cleaning up Bush Jr'.s mess in Iraq and less time pushing special interest legislation for their corporate cronies.

Wednesday, April 18, 2007

Chinese Rock

When it comes to technology issues, does this country's right hand know what the left hand is doing? Reading the on-line IT trade journals, the only possible answer I can come up with is a resounding “no”.

The latest example: a U.S. House of Representatives probe into hack attacks on government servers that appear to have originated in China.

To anyone following computer security issues, this is about as surprising as the discovery that the sun appeared to rise in the East this morning.

In America's corporate board rooms, however, the sun must be rising somewhere else, because, by an amazing coincidence, the hot new place to which corporate America is shipping IT jobs and company data as fast as it can is - China.

Maybe I'm just old-fashioned, but it strikes me as just a wee bit suicidal to be cheerfully sending confidential data to a country which:

  • Is run by an autocracy that hasn't changed its hostility toward human rights since the Tiananmen Square massacre
  • Has an attitude towards intellectual property protection that is (to say the least) indifferent, and
  • Now appears to be hosting criminal attacks against our infrastructure.

But, hey: why let a little thing like homeland security stand in the way of a quick boost in corporate profits and the resulting hike in executive bonuses? We need to keep our priorities straight, after all!

Of course, the fact that attacks have originated from servers that appear to be in China doesn't necessarily mean that those attacks are orchestrated or condoned by the Chinese government. Indeed, why bother to attack American assets at all when American corporations are giving them away in return for cheap, obedient labor and a political system that makes independent trade unions impossible?