It seems everyone is blaming a general failure of cloud computing for the massive data loss that hit Danger, Microsoft and T-Mobile over the weekend.
From what I've read, a failed storage upgrade occurred without a good, solid backup in place. That sounds a lot more like a failure in backup, planning and design than a failure of cloud computing to me. Had the storage folks at my office made the same mistakes, that's what would have been said -- right before the human resources folks came to "have a talk" with the team.
It just so happens that T-Mobile's sidekick phones rely on a lot of back-end storage, so there's the whole "cloud" element to things. I'm not familiar enough with the Danger platform to know how easy it is to back up your own data, but I'd hope it's possible.
I think it goes for any service where you've entrusted storage of your data to someone else: make sure you back it up yourself, if you think it's important. The difference with the Danger/T-Mo disaster, I think, is that it was a lot less obvious to end-users that the data wasn't all stored permanently on the phone. Clearly, "cloud computing" was collateral damage in the wake of a much more mundane failure. The fact that it was completely avoidable offers little comfort for those affected.
Shifting gears: Along comes this piece on how e-mail is becoming less and less relevant.
The thing that separates e-mail as we know it from other messaging platforms is the fact that e-mail is decentralized. Using information stored in DNS, all Internet-facing e-mail servers can properly send mail to the correct server for a given address. IRC is another decentralized communication protocol. The days of decentralized infrastructure are fading fast, though, being replaced by walled gardens that want your constant attention, and many of them requiring a separate account and password. These walled gardens are supposed to be "the new way" of communicating.
You can't easily backup everything you've received through Twitter or Facebook, and the people who communicate with you there have to have accounts. Sure, anyone can get an account. What about Google Wave? Very few of the people I REALLY want to collaborate with have an account. So, while I do see a lot of value in these services for certain things, I don't think that any of them are quite ready to fill the roll that e-mail currently provides. Chiefly: if I have a local e-mail client running on my system, I don't need to suckle at the teat of the Interwebs in order to rifle through my data. It's right there, on my computer. Web mail has indeed blurred the line, but the good web-mail providers still offer mechanisms to back-up your data or use an offline mail client such as Thunderbird.
OpenID somewhat fixes the need to have multiple accounts and passwords scattered all over the web, but shifting authentication "into the cloud" just means that each OpenID account we have will be more catastrophic if compromised. OpenID is tantamount to using the same username and password everywhere, and we know how well that works for security.
How do you backup your cloud data? Well, for starters, you can try a native-client RSS aggregator such as Liferea. One thing that "Cloud" is doing is making syndication possible through ubiquitous RSS feeds. Backups won't work perfectly on every site, for example: you won't actually download all of the photos from Flickr with RSS, you'll only get links to them. It will nicely archive text content, though. This is good for things such as blog posts, twitter conversations and the like.
2009-10-12
On cloud computing
2009-09-18
Verizon Wireless customers: Privacy Fail
I got this lovely IED of Privacy Fail in my inbox this morning. See the circled text. It looks like we get opted-in by default! If you don't want to be sold and traded at Verizon's every whim, you should probably try to hunt this down or access the setting in your VZW account.
Update: According to Mike Fratto (@mfratto) it's old news. How long have we been opted in, anyways!? He points out in your account, go to VZW→My Profile→View/Edit Privacy(CPNI) Settings to change
2009-07-09
Not news: smuggling bomb parts into federal buildings
ABC News: Bomb materials smuggled into fed buildings
Federal investigators had no trouble smuggling bomb-making materials past ill-trained and poorly supervised guards at federal buildings, senators were told at a hearing Wednesday.The thing is that if you poke around the office supply closet and the broom room, you will undoubtedly be able to amass everything that's needed to wreak some serious havoc.
2009-04-08
Lock Fail

Actually, there are locks built into the doors of this roadside telecom cabinet (and they are locked), but these two chintzy padlocks have been unlocked like this for the past few days. I'm not sure what the deal is here, but I chuckle every time I pass it.
Labels: fail, locks, physicalsecurity, wrong
2009-02-09
Hacking Sleep (or why a 'bedtime' is over-rated)
HiR's response? "Go to bed earlier!"
2009-01-27
Fake Hacking: You're doing it wrong
As seen on Fringe this evening. That's supposed to be an IP Address.
At least they could have used an RFC 1918 Non-Routable Address.
2008-12-30
Open Letter from Geeks to IT Recruiters and Hiring Managers
Preface: No, I'm not looking for a job, although I do get the occasional ping from headhunters. I've seen it before, and my friends (some currently unemployed) are seeing it still. My own boss is actually doing pretty good with the below tips.
For the love of all things good in the world, learn how to hire and employ a geek. You're doing it wrong.
Office Politics
Try to measure productivity in output, not in hours.
Geeks automate. Geeks script. Geeks compile. They summon computing power to get things done quickly on their behalf. If your geek seemingly spends all day on Twitter and Fark but somehow manages to still complete tasks ahead of schedule, your geek is multi-tasking. This is normal.
Assign tasks to the geeks who are most interested in them, not the ones with the most experience.
When geeks are interested, they are passionate. When they're passionate, they learn fast. You'll get more productivity out of an interested geek with no prior experience than you will with a bored drone who's been doing the same thing for the past five years. Sometimes, the one with the most experience is the one that's most interested. In those cases, you are a lucky manager!
Segregate the corporate, compensatory hierarchy from the leadership hierarchy.
With a team of geeks under you, one or more will eventually become to go-to guy (or girl) for certain things. You don't usually need to assign a "team lead" - Through meritocracy, the Alpha Geek will emerge. That Alpha Geek may lack seniority, but will have the most influence. It's best to let this occur naturally. It's awkward when the one who best fits the role has to answer to someone else just because they've been around longer. Furthermore, the members of your team will still go to the Alpha Geek because the wrong person has the "Team Lead" label. As Paul Glen puts it: Geeks don't hate hierarchy. They hate your hierarchy.
You'll know you've found the Alpha Geek when you see people from your team (and likely other teams) at said geek's desk getting advice or validation on a frequent basis.
Pre-hiring and interview
Have all screening and profile "paperwork" in one comprehensive online wizard or form.
Geeks do not like pens, pencils, or clip boards. We also despise giving you the same piece of information more than once on fifteen different sheets of paper. We'd rather not be sitting on an uncomfortable chair in a room that's far too brightly lit just so that we can give you the information that you want. It's easy to get the information to you electronically.
Only ask for information you need to make a hiring decision.
W2's, Direct deposit information, full fingerprints, home address and all that crap can be handled during orientation. The only personally identifiable information you need before hiring is a name.
Don't grill us on our resume and work history.
You don't hire a geek for what he or she did two years ago. You hire them for what they will be able to do for you now and in the future. Ask your geek to describe scenarios where problems arose that required them to pick up a new skill set to solve. All geeks worth their salt have stories like that and love telling them.
Instead of asking about skills that qualify them for the position, ask about their interest in the kind of work they think they'll be doing.
Remember: Interested geeks work harder. The above requirement will still let you H.R. types ask that oh-so-predictable question: "What is it that you think this company does?" while offering your candidate a chance to really show he or she will be a good match.
Recommended Reading
I saw Paul Glen speak at IT Security World 2008, and his book, Leading Geeks has a lot more sage advice for those who find themselves leading a technical team.
Labels: rant, readingroom, wrong
2008-12-27
You're Doing It Wrong: Whiteboard Security
Smart whiteboards can take what's drawn on them and print them, store them, e-mail them and a whole variety of other fun things. Panasonic is bringing password protection to these features. [Via Engadget]
...The film and steel boards look pretty traditional at first glance, but underneath of that plain jane facade is a highly advanced security system. You see, each board can accept passwords, which will in turn restrict the ability to transfer information from the board to USB flash memory. For those cleared for access, the whiteboards can transfer on-screen information to a PC via USB, though we suspect you'll have to handle the encryption on your end. 'Course, neither of these will run you cheap, but you know your underground supervisor won't mind shelling out upwards of two large to make sure schematics to rule the world aren't intercepted by meddling rivals.of course, you can practically
2008-12-04
The dangers of proliferation of shared FTP accounts
In a medium sized education organization which shall remain anonymous; FTP and windows file sharing is the file transport of choice for distributing small reports and data chunks. For a long time when a ftp account was needed the person would simply call up the first person who maintained a server that came to mind and had one created. The new ftp account was then fed into a script on the database server (mainframe or AS/400) which then once a day/month/year it spit out a report and uploaded it to the server where (someone/something/every one) picked it up and either loaded it into a different script, or dumped it into a spread sheet, did their business then deleted it and went to lunch.
This has gone on for decades with out some one pointing out that there is something wrong with this process.
Let me count the ways this is wrong:
1. It's not encrypted.
Packet sniffers are very easy to implement even on a switched LAN.
2. There is no way to prove that the remote host is what it says it is.
Server spoofing via DNS or Denial of Service.
3. Access control (in this case) isn't managed.
Static user names and passwords being passed in the clear.
4. Proliferation of potentially sensitive data
Just about every industry is required by law to protect certain kinds of data.
5. Use of old and un-maintainable server for warehousing information.
No warranty, use of old 3rd party software which is unmaintained, End-of-life OS.
It's potential for being 0wned is pretty high.
6. Total disregard of Intranet and Internet facing status of server.
Why? You ask has this issue been allowed to even occur?
Reason #1 Impending retirement. Why would some one who is retiring in 5 or so years would want to learn something new? Ftp and windows file sharing is well known. Ftp has been used on open systems since their inception so everybody supports it. (I mean the standard supports 7 bit file transfers, from the time when bits were expensive, really when is the last time you NEEDED to transfer something using 7 bits as opposed to 8bits?).
Reason #2 Bypassing the chain of command. Why follow protocol and make an official request when you can call the person maintaining the server and have them do it for you.
Reason #3 Maintainers versus dedicated IT staff. In most small and medium organizations, they cant afford dedicated IT staff so they give the position to some one who already does something else. The problem is that the person just puts out fires and performs maintenance. They don't keep up on industry issues and so long as the server limps along everything is fine.
Conclusion:
Because the chain of command is bypassed the Network Administrator isn't aware of it. And the only way he or she will find out about it is either an audit, if it fails or if the server is totally Pwned and now is now selling generic Viagra. Should the latter be the case, a pile of finger pointing ensues and you can guess the rest.
Alternatives:
The solution is finding a suitable replacement technology which is secure and possesses controls on access and availability yet is similar to an existing process so you take advantage of the users existing habits instead of putting them into an uncomfortable situation of learning some "NEW" computer process.
- Pre configuring the email client to use encryption. Email is one of those skills that every one knows or should know.
- Implement Ftp over SSL on a managed file server .(Windows, Linux, Novell ...etc) Most of them have some form of secure drive mapping or mounting which is done transparently to the user. This really is the best choice because most modern server platforms possess some form of auditing features which allow you to track access to resources and or files.
- Secure web application for reports and data. Automate the process and load it into a database then generate the reports on a web page or make it available as a download. A well designed web system can contain all of the controls to keep data safe. Surfing the web is a national pastime, provided you make a usable web interface.
- Controlling movement of data. Prevention of use of external storage devices.
- Encrypting file contents using authentication. Smart cards, public/private keys, hardware keys...etc
Labels: computing, encryption, ethernet, IBM, IP, LOAD OF CRAP, wrong
2008-08-20
2008-01-28
Epoch Fail!

(Bug, via xkcd)
I recently introduced AsmodianX to the somewhat dated "FAIL!" Internet meme. That is, illustrations where something has gone wrong, captioned with the word "FAIL!" This can be a boat full of cargo that's about to fall overboard or a skateboarder doing a face plant. Things of that nature.
Of course, this evolved, and certain tragic situations (such as an entire truckload of beer bottles shattered on the highway) came to be labeled "Epic Fail!"
Epoch Fail is a terribly funny play on words with Epic Fail, obviously. This refers to Epoch time. The current POSIX Epoch started midnight, Jan 1, 1970 and will come to an end (run out of the 32-bit space) sometime in 2038.


