Showing posts with label fail. Show all posts
Showing posts with label fail. Show all posts

2012-01-14

Lock Fail 2.0


I wonder what the combination is.


2011-07-24

Lock Fail

Simplex-style pushbutton locks are ubiquitous in the medical industry. They're used on medicine carts, cabinets, lockers and doors. This is a cabinet that is designed to hold a thin-client workstation and/or patient record portfolios, and restrict access to ethernet ports.







Yep. You can open this one by sliding the exposed latch with your finger.


Also: if you happen to shoulder-surf the code for one of these, you can almost guarantee every other cabinet in the same hospital uses the same code.

2009-10-12

On cloud computing

It seems everyone is blaming a general failure of cloud computing for the massive data loss that hit Danger, Microsoft and T-Mobile over the weekend.

From what I've read, a failed storage upgrade occurred without a good, solid backup in place. That sounds a lot more like a failure in backup, planning and design than a failure of cloud computing to me. Had the storage folks at my office made the same mistakes, that's what would have been said -- right before the human resources folks came to "have a talk" with the team.

It just so happens that T-Mobile's sidekick phones rely on a lot of back-end storage, so there's the whole "cloud" element to things. I'm not familiar enough with the Danger platform to know how easy it is to back up your own data, but I'd hope it's possible.

I think it goes for any service where you've entrusted storage of your data to someone else: make sure you back it up yourself, if you think it's important. The difference with the Danger/T-Mo disaster, I think, is that it was a lot less obvious to end-users that the data wasn't all stored permanently on the phone. Clearly, "cloud computing" was collateral damage in the wake of a much more mundane failure. The fact that it was completely avoidable offers little comfort for those affected.

Shifting gears: Along comes this piece on how e-mail is becoming less and less relevant.
The thing that separates e-mail as we know it from other messaging platforms is the fact that e-mail is decentralized. Using information stored in DNS, all Internet-facing e-mail servers can properly send mail to the correct server for a given address. IRC is another decentralized communication protocol. The days of decentralized infrastructure are fading fast, though, being replaced by walled gardens that want your constant attention, and many of them requiring a separate account and password. These walled gardens are supposed to be "the new way" of communicating.

You can't easily backup everything you've received through Twitter or Facebook, and the people who communicate with you there have to have accounts. Sure, anyone can get an account. What about Google Wave? Very few of the people I REALLY want to collaborate with have an account. So, while I do see a lot of value in these services for certain things, I don't think that any of them are quite ready to fill the roll that e-mail currently provides. Chiefly: if I have a local e-mail client running on my system, I don't need to suckle at the teat of the Interwebs in order to rifle through my data. It's right there, on my computer. Web mail has indeed blurred the line, but the good web-mail providers still offer mechanisms to back-up your data or use an offline mail client such as Thunderbird.

OpenID somewhat fixes the need to have multiple accounts and passwords scattered all over the web, but shifting authentication "into the cloud" just means that each OpenID account we have will be more catastrophic if compromised. OpenID is tantamount to using the same username and password everywhere, and we know how well that works for security.

How do you backup your cloud data? Well, for starters, you can try a native-client RSS aggregator such as Liferea. One thing that "Cloud" is doing is making syndication possible through ubiquitous RSS feeds. Backups won't work perfectly on every site, for example: you won't actually download all of the photos from Flickr with RSS, you'll only get links to them. It will nicely archive text content, though. This is good for things such as blog posts, twitter conversations and the like.

2009-09-18

Verizon Wireless customers: Privacy Fail

I got this lovely IED of Privacy Fail in my inbox this morning. See the circled text. It looks like we get opted-in by default! If you don't want to be sold and traded at Verizon's every whim, you should probably try to hunt this down or access the setting in your VZW account.



Update: According to Mike Fratto (@mfratto) it's old news. How long have we been opted in, anyways!? He points out in your account, go to VZW→My Profile→View/Edit Privacy(CPNI) Settings to change

2009-07-09

Not news: smuggling bomb parts into federal buildings

ABC News: Bomb materials smuggled into fed buildings

Federal investigators had no trouble smuggling bomb-making materials past ill-trained and poorly supervised guards at federal buildings, senators were told at a hearing Wednesday.
The thing is that if you poke around the office supply closet and the broom room, you will undoubtedly be able to amass everything that's needed to wreak some serious havoc. 

The article doesn't say whether the GAO agents used credentials or covert entry to get into the compounds with said "bomb supplies". If they were able to enter without credentials, there's a much larger problem. If they used credentials, it really doesn't matter what they can carry in. Through all of history, weapons have been made from seemingly benign objects. 

This is more pedantic security theater: Focusing on one specific threat instead of working to refine and simplify the armor.

2009-04-08

Lock Fail



Actually, there are locks built into the doors of this roadside telecom cabinet (and they are locked), but these two chintzy padlocks have been unlocked like this for the past few days. I'm not sure what the deal is here, but I chuckle every time I pass it.

2009-02-09

Hacking Sleep (or why a 'bedtime' is over-rated)

HiR's response? "Go to bed earlier!"




Most of us  have to be up at a specific time every weekday. Over the winter, it's usually 5:30 daily for me.

Instead of having a "bedtime" just focus on your "wake-up time" and for crying out loud, go to sleep when you feel yourself getting tired. This eliminates those tossing/turning/book-reading/TV-watching moments in bed. It also eliminates those nights where your ass is dragging all night long and you finally see your bedtime on the clock and slog to the bedroom.  Those are the nights that lead to abuse of the snooze button, or worse!  

At first, you might find yourself waking up ahead of schedule. If you feel up to it, try to go back to sleep until your alarm goes off.  Likewise, you may still feel the urge to hit the snooze button at first. After a few days of this, you'll start to get in the groove.  

I occasionally stretch my tired state out, but usually I reward myself on the other end by rolling the alarm forward by a half hour or so, if I can get away with it.  I haven't hit snooze in years, and most mornings, I wake up right before my alarm goes off. I get 5-6 hours of sleep per night.

The temptation might be there to hammer out those last few lines of code, finish post-processing the weekend's photos, push yet another blog post out, or finish up your trigonometry homework. If those are things you really, really must do, you're doing it wrong.

Watch less TV (or Video podcasts, youtube, etc), unsubscribe from some of your RSS feeds, or find ways to combine your leisure activities. You can easily catch up on podcasts or IPTV shows while working out, for example. It beats being stuck watching old Marathon or Tour De France footage.

Sleep is variable, and it's definitely a big time-consumer. Polyphasic sleep definitely isn't for everyone, and it's not wise to cut back on your slumber to make room for fun-time. It destroys your productivity and can leave you dangerously unfocused while performing critical tasks (such as driving or executing commands as root on production servers).

2009-01-27

Fake Hacking: You're doing it wrong

As seen on Fringe this evening. That's supposed to be an IP Address.


At least they could have used an RFC 1918 Non-Routable Address.

2008-12-31

Zune doesn't like leap years

GenesisWave pointed this out on the Cowtown Computer Congress mailing list.




Q: Why did this occur at precisely 12:01 a.m. on December 31, 2008?

There is a bug in the internal clock driver causing the 30GB device to improperly handle the last day of a leap year.


What a riot. Well, your Zune will work tomorrow. In the meantime, check out i-Hacked.com's Zune Fix. They had the first working walk-through I saw.

2008-12-27

You're Doing It Wrong: Whiteboard Security

Smart whiteboards can take what's drawn on them and print them, store them, e-mail them and a whole variety of other fun things. Panasonic is bringing password protection to these features.  [Via Engadget]


Darren Murph (whose snarky writing style I enjoy) says:
...The film and steel boards look pretty traditional at first glance, but underneath of that plain jane facade is a highly advanced security system. You see, each board can accept passwords, which will in turn restrict the ability to transfer information from the board to USB flash memory. For those cleared for access, the whiteboards can transfer on-screen information to a PC via USB, though we suspect you'll have to handle the encryption on your end. 'Course, neither of these will run you cheap, but you know your underground supervisor won't mind shelling out upwards of two large to make sure schematics to rule the world aren't intercepted by meddling rivals.
of course, you can practically hear read the sarcasm.  This is like putting a bank vault door on a 4-foot-tall chain link fence. There's little to keep someone from snapping photos of the whiteboard with a camera phone, or from sketching along with the presentation while stuff is being drawn.

Security. You're doing it wrong.