Showing posts with label rant. Show all posts
Showing posts with label rant. Show all posts

2015-12-31

No more "Hacky GNU Year"

I usually kick off every year with the aforementioned greeting, but 2015 will stand as the year I really got sick of what the GNU/Linux ecosystem has become... in pretty much the same way I have been sick of what the Windows ecosystem has become. The mainstream Linux distributions have all become painful to me in ways that I couldn't have imagined just a few years ago. It's been a long, arduous slog. You can ask any of my nerd friends. I've gotten pretty salty over the state of Linux in the past year. And don't get me started on the nightmares of El Capitan and Windows 10, also making 2015 especially brutal.

This evening, though, Linux is weighing especially heavy on my mind.  I'm sure the recent passing of Ian Murdock has something to do with it as well. We really did lose one of the heroes this week.

I will still use Linux and Windows for the tasks that they excel in. I will continue to experiment with and master their secrets in order to figure out how they work -- just as I do with other operating systems.

My new year's resolution is to get more and more of my personal stuff migrated to some kind of BSD.

Best wishes to all of you in 2016 from Ax0n.

2011-05-19

Why I'm coming home to OpenBSD

Although those who know me will tell you I love OpenBSD, I'm generally an operating system agnostic. I enjoy tinkering with OSes, and always have. There have been a few I tried and couldn't enjoy for the life of me (Mac OS versions prior to OS X, PalmOS, HP-UX and plan9 among them) but since 1997, OpenBSD has always felt like home to me, and I've long been a little bit of a fan.


Not long ago, my primary computer was a 13" MacBook that was bought for me by one of my consulting customers in late 2006, and prior to that, I was using OpenBSD on a crappy old Dell desktop and OS X on a G3 PowerBook. OS X is just unixy enough to geek out on. I could get most BSD-type stuff to compile. My MacBook also ran Windows 7 pretty well. I got switched on to it when my wife upgraded to 7 from Vista. It also ran OpenBSD, Backtrack and Ubuntu in VirtualBox like a champ.

When the MacBook started showing its age about 6 months ago, I went to a Toshiba NB305 netbook. It came with Windows 7 Starter edition, which really isn't much of an operating system at all. It's basically a kernel meant to launch Internet Explorer. Not amused. I didn't feel like paying to "unlock" Windows Home Premium.

Figuring that the hardware and all of the funky function keys would probably work best under Ubuntu, I went that route. Webcam aside (I never use it anyway) the hardware worked pretty well. I had to wait around for patches to get the screen brightness keys to work. Power management was always funky right after getting unplugged. Otherwise, Ubuntu worked pretty well for me. I set it up to dual-boot alongside Windows 7 Starter, just so I could use my radio programming software.

3 months ago, Ubuntu managed to corrupt the partition table on the hard drive. Recovery involved spending 4 hours restoring Windows 7 starter edition from the factory media and re-installing Ubuntu. A few days ago, the same thing happened. A co-worker has had similar trouble lately, as well.

There are a bunch of distros out there -- probably too many. Netbook-specific distributions are hot stuff. Frogman's on a Crunchbang kick. More than one person tried to tell me to go to Gentoo, Debian, Arch or some other flavor of Linux. I've used them before. Every few years, Linux has to piss me off, I suppose.

Faced with the prospect of a half-day wasted getting my netbook back to the way I thought I liked it, I decided to see what OpenBSD offered, since I haven't run it on the desktop outside of a VM in several years. The install is always quick, so if anything, it wouldn't be too much of a waste of my time.

Taking the OpenBSD plunge on my NB305. Feels like $HOME again.

As expected, Xorg didn't need any configuring to determine and use my display to its maximum potential. X has come a long way since the late 1990s. I was worried about things like power management (suspend, resume), hardware drivers, support for WPA2 and of course the function keys for display brightness, volume and the like, since they gave me a bit of trouble on Ubuntu.

You know what, though? Everything worked right out of the box. I had to enable apmd in /etc/rc.conf to get suspend to work, but that was it. I also found a pretty neat trick to get most flash videos to play in Firefox, with only open source tools and not actually using anything from Adobe. Youtube, vimeo, blip and even Badgers all work great. Let's face it, life would suck if you couldn't watch Lolcats, Badgers and Mythbusters.

Flash video on OpenBSD

It's way too soon to tell if OpenBSD will be any more reliable than Ubuntu in the long run, but I feel much more at home for the time being.

Moar useful OpenBSD resources I ran across this week:


That reminds me, I'm behind schedule on my OAMP guide for OpenBSD 4.9, but I'm pretty sure the existing instructions haven't changed, save for version numbers.

2011-04-18

The Real Insider Threat

Today, I saw this interesting piece on insider threats posted to CERT, and was somewhat baffled. I stewed on it a bit, but a Google Reader comment by Carnal0wnage spun up my rant engine. Here, people are actually being urged to spy on their peers then name them and shame then, as if it's totally normal to put bear traps in the server room and roll your own ECHELON, lynching in the commons anyone who dares to raise the ire of the great and awesome security team. They titled their session "What's working to stop these attacks?" It's us versus them.

When I was still a student, years before my real career in information security would take hold, it was commonplace to hear that some unfathomable percent of attacks are from malicious insiders. Maybe it was true in the 1990s. After years of leaving corporate workstations and academic lab computers hanging out on the Internet with public IP addresses and no firewalls, administrators were finally getting a clue, NATting workstations and putting up chintzy first-generation port-blocking firewalls. Students and curious employees were suddenly the ones with unrestricted access to internal systems protected -- if you wish to call it that -- by these prototypical security systems. Maybe this logic made sense back then.

Be that as it may, I've seen more data loss from people bypassing draconian security policy than I've seen data loss from the rare disgruntled trade-secret packrat with one hand in the cookie jar and one foot out the door. That's not to say these things don't happen. They do! But they're not the typical modern insider threat.

At my last job, I would occasionally have the option to work remotely for server maintenance, or instead drive 15 miles to the office at 11:00 PM on a Saturday night, and stay there until 4:00 AM Sunday morning. Working from home meant this:

  • Firing up some proprietary piece of VPN software that only ran on Windows.
  • Using a 2-factor authentication token to get into the VPN.
  • Using RDP to access a "secure" sandbox server, which was pretty much the only thing the VPN would let you access remotely. This required the use of the 2-factor token again, but you had to wait to make sure you didn't use the same one-time key twice in a row.
  • Using RDP from that server to get to my desktop, which also ran Windows.
  • SSHing from my workstation to a central administration server that was dual-homed and could actually access the servers I needed to work on.
  • Performing the work on the servers.
Let's say, I usually drove to the office. How much do you want to bet that people in high-level positions were taking sensitive information home with them on external drives instead of trying to navigate that rat-maze of security on a daily basis? What about the CFO that always uses an aircard for his laptop -- even at the office -- mixing business with casual recreational web surfing just because he can't get to the things he "needs" ever since that [expletive] proxy started getting in his way.

That's how data gets lost, and there's your real insider threat.

While security sometimes impacts usability, it doesn't always have to. It's certainly not a linear scale. I could provide dozens of examples where making something harder to use causes people to make poor security decisions, but they're mostly cliché. Security is hard, and the human element of it is the most nuanced and unpredictable part.

Don't force security rhetoric down peoples' throats and try to pass it off as "awareness training." Work with people. Figure out what they want, and work to deliver solutions that provide an adequate level of risk protection while impacting usability as little as possible. Automate or document the hard parts for them. Explain things to them in terms that they can understand. I'd bet your job description called for excellent written and verbal communication skills. Put them to good use!

While threat management and network monitoring are always part of a complete information security breakfast, trusting and empowering your co-workers while providing them with education that meets them where they are will probably go a lot further toward minimizing the insider threat than playing Big Brother ever will.

2010-10-18

The ultimate simple guide to Internet privacy

People are making a big fuss about privacy and how companies are invading it. Without further delay, here is my all-encompassing guide to Internet privacy.

  1. Think about what you're going to post.
  2. If you can concoct any situation in your mind where it would be bad for any one specific person to see it (e.g., your boss, your parents or even the person you're making fun of,) either now or for the foreseeable future, then do not post it on the Internet.
Your mother probably said something along the lines of "If you don't want it on the front page of the newspaper, then don't do it!" She was on to something, you know.

Also, if you're using someone else's bandwidth, server resources and infrastructure for free, then the service they provide to you is not their product. Their product is the data you willingly give them, which they're more than happy to monetize in any number of ways.

2010-10-07

It only happens once every 823 years!

- OR -
Shell Scripting for Pedantry's Sake.


Today's "That can't be true!" moment hit me when I started seeing this making the rounds (in various different paraphrased versions) on Teh Intarwebs:

"This month has 5 Fridays, 5 Saturdays and 5 sundays-Only happens every 823 years!"

Truth be known, I don't really care about how many weekends are in a month except for the fact that I get three paychecks this month. That happens about twice per year, and that's always welcome! Once in a while, though, I just can't help it. I have to disprove something. I figured the easiest way to disprove this particular claim would be to write a shell script that used the "cal" tool, found in every unix variant known to mankind.

For there to be 5 Fridays, Saturdays and Sundays in a single month, there is a basic requirement for a 31-day month that begins on a Friday, and only then will the 31st fall on a Sunday to complete 5 "whole weekends" in one month.

Initially, I was thinking of ways to see what months started on a Friday. That would get me close. It would give me months such as February 2013, which have only 28 days. Then it hit me: Look for any month with a 31st day that falls on Sunday. Using "cal," I can simply roll through the calendar year looking for a line that begins with "31" and guarantee that the month will satisfy the requirements of having five Fridays, Saturdays and Sundays.

So here we go!

#!/bin/sh
ye=2010
mo=1
while true
do
until [ $mo -gt 12 ]
do
cal=`cal $mo $ye | grep ^31`
if [ -z "$cal" ]
then
echo -n ""
else
echo
cal $mo $ye
fi
mo=`expr $mo + 1`
done
mo=1
ye=`expr $ye + 1`
done


Output:

January 2010
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31

October 2010
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31

July 2011
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31

March 2013
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31

August 2014
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31

May 2015
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31


I don't know. It looks like these things happen more than every 823 years. You can rest easy knowing that it will actually happen a total of 825 times in the next 823 years. Yep, I counted them.

One of the derivatives mentioned October specifically, though. Perhaps this only happens once every 823 Octobers?

Slightly modified, we make the script check Octobers...

#!/bin/sh
ye=2010
mo=10
while true
do
cal=`cal $mo $ye | grep ^31`
if [ -z "$cal" ]
then
echo -n ""
else
echo
cal $mo $ye
fi
ye=`expr $ye + 1`
done

Output:

October 2010
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31

October 2021
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31

October 2027
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31

October 2032
Su Mo Tu We Th Fr Sa
1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31



Nope. More than a decade at times, but not 823 years.

2010-07-27

Really, Verisign?

Verisign's latest snail mail spam included a Verisign-branded USB drive with information on their new SSL Certificate features. The package was heavily loaded with all kinds of "Trust" rhetoric. At the request of the guy who officially got it, I threw it into my Macbook to take a look at it. It wasn't on any network and it's not prone to any known vulnerabilities that might allow something to run directly from the USB without any interaction (unlike Windows)


Really, Verisign? REALLY?

Autorun, Verisign? Really? AND Lame Adobe Flash? You honestly expect us to TRUST this kind of crap? To add insult to injury, the USB drive itself is only 64MB. You can't even install BackTrack on it or otherwise put it to any productive use.

2010-02-14

Fraud and Identity Theft are not "Hacking"

[H]ard|OCP: Hacker gets record 13-year sentence for hacking.


Originally a haven for hardware hackers looking for advice on extreme overclocking, system cooling, gaming, and case modifications, you'd figure [H]ard|OCP would "get it", wouldn't you? At least one front page contributor doesn't.

I'm not one of the hopefuls that really thinks society will ever ditch its stigma against "the H word" but this story strikes several nerves for me, and continuing to sensationalize "hacking" like this is only part of it.

Max Butler (now known as Max Vision) got a whopper of a sentence, but it wasn't for "hacking," it was for multiple counts of wire fraud, identity theft, and transfer of stolen identity data. While Max undoubtedly had the mindset of a hacker for most of his life, his ethics (I'll get to that in a moment) made him a criminal. Although he was obviously brilliant and capable as a hacker, Max abused his skills to become a carder, a con man, and a low-life, deceptive criminal. Those are the things that got him into trouble. Criminals with little technical skill get busted for the same things.

More disturbing, though, is how Max came to the center of this vast arena of identity theft. With a troubled past, he emerged as a skilled security consultant with a bit of a naughty streak -- a habit that would get him thrown into the slammer (for computer fraud) after breaching government and military networks with a clever tool that would patch a well-known hole while leaving a back-door for him to use later. This is the kind disruptive mischief that used to be associated with "cyber criminals" years ago, putting him in the same arena as Robert Morris, Adrian "The Homeless Hacker" Lamo , and MafiaBoy, to an extent.

During this 18-month stay in the pokey, he would befriend the hardened career criminals who would eventually conspire with him to create genuine financial havoc, on par with the destructive forces of those responsible for the TJX and Heartland breaches.

What do I make of it? I'm not entirely sure. It's hard telling if Max Vision would have found collaborators outside of prison and ended up on the same path, or whether prison life genuinely corrupted him. I do know, however, that no one gets arrested for "hacking."

2010-02-11

Oh noes! Google Buzz FUD!

Silicon Valley Insider came up with this wonderful sensationalist FUD piece: WARNING: Google Buzz has a huge privacy flaw!


Please.

They recommend shutting off Buzz completely, or un-following your automagically-generated "friends" that Google "chose" for you (i.e. other Google Profiles that you exchange e-mail, Google Reader, or GTalk with). This isn't really a Buzz issue at all, though. It's been a "problem" since Google Profiles came out, it's just a lot more intuitive to see who people interact with in Google Buzz, since it's built into GMail directly now.

UPDATE: It looks like contact sharing *IS* enabled only once you sign up for Buzz. So, shame on Google? If you don't sign up for Buzz, these options won't even show up (and neither will your contacts on your Google Profile) - Thanks, Genesiswave, for pointing this out.

Oh noes! Ph34r!!!

Or, you could think rationally, and simply un-check the option to make public the list of people you interact with. Imagine that?

So, take a deep breath, log in to some google service, then click this link to edit your profile if you're really that worried. Again, this option is only displayed once you opted in to Google Buzz.

Relief. Whew.

Now, the followers/following links are only visible to myself. I verified this through Google Buzz and by looking at my profile page from a different google account.

2010-02-09

Juxtaposition - Subscription-walls

A new paper on Johnny's "I Hack Stuff" blog requires a subscription. Meanwhile, Sensepost is abandoning their "Regwall" for research papers.


I feel the same way about news paywalls, really. They don't force people to pay, nor do they keep people from getting the news. They just make sure they don't get the news from YOU.

By the way, I threw together a Google Reader "Bundle" of my favorite security feeds. If you use Google Reader (and let's face it, why WOULDN'T you?!) you can easily import these. Beware: it's over 200 RSS feeds, and can get awfully noisy at times.

2009-12-08

Flyback transformers and CRT discharge. OF DEATH.

Last week, our friend Mike was attempting to power an ionocraft with the flyback transformer from an old 15" Gateway CRT. There was a bit of fear (or overdeserved respect) for the high voltage source. I gave a little quick lesson on how to discharge the CRT before diving into the project, but I figured it deserved a little more detail, and that you guys would at least find it interesting.


While it's true that you wouldn't want to simply grasp the exposed anode and yank it off of the CRT, it seems there's a lot of misinformation and urban legends around flyback coils, CRT discharge, and sudden death. People make it sound like you'll surely shatter the monitor if you don't electrocute yourself first. Legend has it that CRTs are fragile, and one false step can turn them into a deadly fragmentary grenade.

First, let me state that the "shock" factor of a monitor or CRT comes mostly from the fact that the CRT itself acts as a giant capacitor. A capacitor is simply two conductors separated by a dielectric. It so happens that the mesh grid, thick glass, and other energized components in a CRT make a pretty good capacitor which can hold a charge for a long time, even when it's not powered on. That part is NOT a myth.

Even if you do get bitten (I've been, only once, and yes, it hurt), the chances of a lethal electrocution are slim to none, so long as you're not touching an ENERGIZED HV coil, such as if the power supply for the monitor or TV is turned on.

As for the "explosion" or "implosion" hazard of CRT monitors? All modern monitors are designed with a mesh or metal layer inside that keeps the CRT from rapidly failing. Frogman and I have tried breaking many CRTs of various sizes and we've never seen any spectacular failures before. The glass is very thick, and you're most likely to break the little vacuum seal nub at the CRT's tail, or shatter the narrow neck than any thing else. It'll simply hiss and be done with. It's pretty boring, really. It's not a bad idea to wear safety glasses when handling a CRT, though. They're made of glass, which can chip even if the hazard of implosion is virtually nil.

Still, one should remain careful when handling CRTs or otherwise poking around inside devices that use high voltage transformers. As always, we can't be held responsible for your mishaps, and a live flyback transformer is nothing to treat lightly. Some can put out tens of thousands of volts, and most aren't current-regulated. They can cause harm.

I'll use my Mac SE/30 (the Blackintosh) for an example of how to safely discharge a CRT. First, you want to make sure it's unplugged and powered off before you even open it.

On the left, the large suction cup device is the anode. It runs back to the high voltage flyback transformer seen toward the upper right of the photo. This Mac hasn't been powered on in a few months, but the CRT may still hold a capacitive charge. The HV transformer in this model might put out 10kV when energized, but only a fraction of that charge, if any, may remain in the CRT itself.

The way to discharge it is to take a jumper wire, attach one end to a metal screwdriver with a well-insulated handle, the other end to the chassis ground of the monitor. You can do this with an alligator-clip jumper wire, or just grab any old wire you have, strip the ends, and make sure it's connected to the chassis and to the metal screwdriver shaft.

Gently pry up the edge of the cup.

Pry up until you can see the anode plugged into the body of the CRT.

And then, make sure the screwdriver touches the anode. You're done.

If you must remove the anode, you can keep using the screwdriver to pop the anode out of the CRT housing. At this point, you can touch the anode, the flyback transformer and the CRT without fear of being zapped. Of course, I wouldn't recommend intentionally touching the HV gear unless you absolutely must (for instance, to replace a damaged CRT or flyback transformer). As a matter of practice, you should just leave the HV stuff alone if you don't have a good reason to be working on it. It's pretty well insulated in newer monitors and TV sets and shouldn't cause you much problem.

It's common practice to re-ground the HV anode if you're tinkering with high voltage experiments such as CCCKC's ionocraft. It's not really a requirement though. Chances are, the energy stored between the corona wire and the ground skirt of the ionocraft isn't even noticeable, but better safe than sorry.

2009-12-01

Rant: Hackerspaces do not foster cybercrime!

Two things pissing me off today. First: Vitriolic and audacious comments on this otherwise awesome article about hackerspaces in STL Today. Some excerpts from the comments:

The authorities need to keep a close watch on these people. Perhaps their source of funding will be hacking bank accounts.

Trying to include teenagers can get complicated. Personally, I feel open access to tools for cyber hacking, learning how to steal passwords, and other mischief can be inappropriate at that age. Even university students get caught up trying to make a name for themselves. [ . . . ] I was a founding member of CCCKC but these are reasons I chose to leave the group. I don't want to be labeled a cyber hacker by association.

Fortunately, there's some sanity and fact-checking in the comments, too.

And then there's news about Forskningsavd (a Swedish hackerspace) getting raided for something completely unrelated to the hackerspace. Further, the seizure of property seems completely bizarre given the stated reason for police intervention.

So, I'm feeling ranty. Here's some background on how my local hackerspace deals with "Cyber hacking and other mischief"

Shortly after CCCKC's grand opening, a series of courses were taught on cyber-security. These four sessions were very popular, covering the basics such as understanding the difference between hubs and switches, and eventually covering powerful tools such as nmap, Hamster & Ferret, Metasploit, and Maltego. The courses provided enough demonstration to scare people into being more cautious while teaching them how to avoid being victimized. Nothing was covered that hasn't been hashed over online a thousand times already, but it was very cool to get a guided tour through the maze of cyber-security and to be able to tinker around in a hands-on lab environment.

Around the same time, locksport also took off. A solid-core door got drilled out, had eye-screws put into it, and became a standing board of different locks to play with. The Lock Picks & BBQ series was also a big hit. People would come out, grill some meat, and then learn about the mechanics of simple locks.

Critical thinkers absolutely love to explore dynamic boundaries, and very few boundaries are as controversial and exciting as the enigmatic balance of attack resistance vs. usability in both physical security (locks and surveillance) and information security (firewalls, encryption and vulnerability exploitation). It's no wonder some of the worlds most intelligent people have dabbled in security. Richard Feynman, for example, picked locks at Los Alamos for fun and pranks.

Now, several hackerspaces are uniting with an international VPN that's going to be much like a digital Capture The Flag game. We're calling this effort "The Warzone Project" and it'll give people a safe, isolated environment to practice their skills in information security systems.

The thing is, there's already a lot of very detailed information on the web and in books when it comes to breaking all kinds of security systems. Demonstrating them in a lab environment gives people a safe place to "get it out of their system" much like Grudge Night at the local drag strip gives teenagers a safe place to race their cars so they aren't endangering people on public roads. The lab environment also allows people to legally learn about more aspects than they could in their own homes, and to take a shot at mastery in defense by understanding both sides of an attack.
"Hackerspaces are about learning, sharing and collaboration."
Folks, every hackerspace takes on a personality of its own based on what the members are interested in. Some hackerspaces focus on electronics or take an art, metal/woodworking and maker approach. Some tend to focus on programming microcontrollers or building robots. Others are busy tackling so many eclectic projects that they don't even have a core focus. They all have some things in common, though: Hackerspaces are about learning, sharing and collaboration.

Writing the code and creating the control infrastructure for a botnet takes dedication and lots of work. Poring through source code, looking for bugs and creating a working exploit is no small feat. It can take years to fully master exactly how locks work and how to manipulate the parts inside. Indeed, learning in a lab environment teaches patience. It teaches respect for the systems. Learning is hard, but it's good for you.

Compare that to the modern criminal reality: Right now, anyone in the world can rent a cadre of botnet computers for just a few dollars and use them to send spam, to host fake bank websites, to obscure their attacks or to use in a massive denial-of-service attack. Anyone can look up the latest zero-day exploits and use them for bad things. Anyone can buy a bump key and start opening about 30% of the locks that key will fit into. Subversion is easy.

If subversion is your goal, you would be silly to waste your time learning all the minutiae of systems from hackerspace denizens. Cyber criminals already know this. Apparently, some people still don't get it.

Update
I thought I'd share a quick list of things we've worked on and had talks about lately at CCCKC:
  • Assisting JayDoc, a not-for-profit medical charity for the needy
  • Joined more than a dozen hackerspaces live via webcam for the synchronous hackathon.
  • Projected a game of Tetris onto a wall in downtown KC
  • Building, studying and using the MakerBot
  • Ran tech support and helped make BarCampKC 2009 a success
  • Built a Twitter-bot (that's currently on the fritz)
  • Set up a silk-screen lab for emblazoning logos onto things.
  • Got good press in INK KC
  • Set up a MIDI music workstation
  • Built a compressed air T-shirt cannon
  • Got a bunch of people familiarized with Arduino programming
We also had a few Turbo Talks and demonstrations lately:
  • GPSes, computer interfaces for them, and Geoc... "finding things people hid somewhere"
  • Search engine optimization
  • Robotics
  • Hacking the car-buying process
  • Intro to Craps (the casino game)
  • Server/telecom racks
Finally, people come down to work on their own projects when they have time.
  • Electronics
  • Robotics
  • Radio Controlled Toys
  • Photography
  • Scrapbooking/Crafts
  • E-Textiles (like gloves that work with touchscreens, LED embroidery, etc)
These are some of the things people do at hackerspaces.

2009-11-29

Cyber Monday? How about MAKE some gifts?

This year, I'm planning on building as many gifts as I can. This is why I was so frustrated with Radio Shack earlier this month. So far, I've got three gifts almost completed, all of which are electronic. I start with an experimenter breadboard like the one shown*, then go bananas. Once I have something working the way I like it, I solder it to perfboard.


There are tons of great ideas in books and online. You can always find cool things to assemble yourself at Evil Mad Science, The Maker Shed, Sparkfun or LadyAda.

If you can't solder or don't quite grok electronics, you can try crafts such as woodworking, cooking, leather working, knitting/sewing, or anything else that you put your time, knowledge and heart into. Chances are, it'll mean more to the recipient than a gift card, some clothes, or whatever device you happen to burn your cash on. Maybe donate some of the grip you save to help save lives? Several initiatives are out there to provide clean, drinkable water to those in need. There's local emergency response and hardship relief, hope for cancer patients and a host of other organizations worthy of your help this season.

How about less consumerism and more love? Get excited and make things!

* The circuit on the breadboard is completely bogus. Sorry, peeps. No clues until December 25th!

2009-11-25

Mastery through persistence and gradual learning

Who of us haven't wistfully recalled the scenes in The Matrix trilogy where facts and skills were modularized into chunks of data that could be dropped into the human brain within a matter of seconds?

Real life doesn't work that way. Taking an example from the trilogy: Kung-Fu requires individual neurological paths to be gradually awakened, certain muscle groups to be conditioned, and a particular mindset to be adopted. Mastery of Kung-Fu lies far beyond going through its motions. One may "know Kung-Fu" but one cannot master it without persistence; Mastery involves learning many small things over time while conditioning your body and mind to perform all of the physical and mental tasks necessary to the art.

Shift the subject from Kung-Fu to something many readers of HiR can likely relate to: system administration. It's not an individual skill or a trait. It's a mindset that requires a combination of critical thinking and knowledge of tens of thousands of little facts.

Examples:
  • Locations of hundreds of little pieces of configuration data
  • Names of scores of system commands
  • Hundreds of collective options for those system commands
  • Syntax of aforementioned configuration data and system commands
  • Menu options and other madness for dozens of popular applications and services such as Apache, sendmail, MySQL and ssh to name just a few.
If you work (or play) in a heterogenous environment such as one where AIX, Solaris, Windows, and Linux are all in use, you can see how the system administration mindset can encompass a dauntingly massive array of skills and a mounting behemoth of facts and knowledge. That's where critical thinking comes in. Sysadmins must be resilient and versatile, adopting an attitude of perpetual, gradual learning. Keep this in mind when you decide to meet your challenges with mastery instead of mere performance. No matter what your challenge is, mastery requires the same persistence and gradual learning.

This post was an inevitable one. I've been mulling over the topic for weeks now, and some conversations on Twitter combined with two awesome articles on Staying Sharp and Fake Achievement sealed the deal. Mastery comes only through hard work. It takes practice, dedication, and frequent use of the skills to maintain. Sometimes that maintenance, the "staying sharp" part does seem quite mundane, but it's very important. Use it or lose it.

The person I was talking to admitted lack of command-line skills (hence the reliance on crutch tech), but I happen to know he's got a good head on his shoulders and could choose mastery. Let's say you have a Linux server running Apache and you really want to host 10 different sites on it. You need to use Apache's VirtualHost feature. Will you settle for performing the task with a crutch and move along, or will you put in the effort to truly master Apache (even if only its VirtualHost feature) so that you can do it again easily in the future?

Learning by example is one way to do it. The Twitter conversation that happened yesterday was about the merits of "crutch technology" system management tools such as cpanel, plesk, webmin and virtualmin. By extension, you could include any easy-to-use "wizard" GUI or web app that ultimately makes simple changes to flat configuration files or performs certain changes that could be done by executing system commands: smit (on AIX), Manage Computer (On Windows) and the like.

Crutch tech can be leveraged in the name of learning by example. Tools like smit and virtualmin make changes that can be observed. By simply figuring out what the tools do for a given action, you can extrapolate how the process works. By building on the crutch's examples and reading the documentation, one can master the skill and lose the crutch.

The ones you look up to might make things look easy, but you rarely get to see the years of hard work that went into what they are. This goes for athletes, hackers, racers, physicists and everyone else who has put in the work to master something.

2009-11-20

Hey Radio Shack. It's us, the makers.

Do you remember in the 80s and 90s, when half of your stores' real-estate was dedicated to sliding pegboards of myriad components 3 layers deep, Engineer's (Mini) Notebooks by Forrest M. Mims III, genuinely good electronics experimenter kits, prototyping breadboards (not these) and Tandy/Archer/Heath-branded customer-soldered kits that were genuinely useful?

We want it back. You see, DIY electronics is en vogue again. Guitarists are excited about their stomp boxes. Teenagers are building awesome robots that are more than just cheap plastic toys. The economy is fostering a serious DIY revolution. People are going on MakeCations (staying at home, making things) or doing weekend projects instead of weekend road trips. We are once again learning how to fix our ailing gadgets rather than chucking them into the garbage, and looking for ways to make our own simple and useful electronic gizmos and toys instead of buying them. It's cheaper and a lot more fun. Building and fixing things yourself instills a sense of joy. Who doesn't LOVE a sense of joy!?

Just as the old-school PIC gave way to the easier-to-use BASIC Stamp, the electronics deities have given us the Parallax Propeller and Atmel AVR Microcontrollers, and the easier-to-use pre-packaged versions: SPIN Stamp and Arduino. There are literally thousands of well-documented and useful projects out there for budding electronics engineers and computer scientists, yet we no longer have a good, local source for discrete components to help us finish these projects. That used to be you, Radio Shack, but you've lost your way.

Last night, I was horribly saddened at what your component selection has become: a dozen drawers or so containing only two or three of the most popular values of components, and only a lone 555 timer hanging out with a few different SCRs and op-amps in the IC bin.

We are the makers. We are many. Hear our plea: Lose some of the chintzy, easily-broken children's toys and pare down (or get rid of) your selection of overpriced and useless home theater junk. Other stores do consumer electronics much better than you can with your small, shack-like storefronts. Bring back the big sliding racks full of components, chips, and kits. Bring back the spring-jumpered crystal radios and projects that kids can build with their parents. Bring back the shelf full of electronics project books and experimenter kits. Bring us Arduinos, SPIN Stamps, stepper motors, servos and robotics platforms.

You were once our hyper-local, affordable source for all kinds of DIY electronics hackery. We liked that. We do not like having to beg all of our friends to go in with us on a huge order from the all-encompassing catalog companies.

Also, a bit of a shout out: here in Kansas City, we do have the HMS Beagle store and Electronics Supply. Unfortunately, they lack the ubiquity and convenience of Radio Shack and they still have to special order a lot of things. Mostly, I'm just being a ranty retro-grouch as usual. I'd really like to see "The Shack" return to its roots. The things they currently do, they're doing poorly, and there's a huge niche left behind by their old business model that I feel would probably thrive quite well. I hoarked over $1.49 each last night -- happily, I might add -- for a pair of LM386 Op-Amps. I'm betting Radio Shack made 700% profit on each of them, at minimum.

2009-11-17

Tales from the other side of helldesk

Today, I was having trouble with a web application. I don't often find myself on the other end of a helpdesk call, but lo and behold here I was. I submitted a screen shot of the error, and the response was akin to "I'm sorry, we don't support browsers with toolbar addons."

Excuse me? After going around and around with support, I finally convinced him that the Google search box was not part of some malware suite, but actually comes in every modern browser. IE7, IE8, Safari, Chrome, Opera, and even Firefox.


How much you want to bet the guy is still using IE6?

2009-11-02

Windows 7: Is its success really a surprise?

I've been messing with Windows 7 since the beta, and my wife has the Ultimate edition installed on her laptop (having replaced Vista, for the most part).


Most people agree: Windows 7 is good. But really, when faced with the following choices, how could Windows 7 NOT succeed?
  • Windows XP, a decade-old platform that's been patched to hell
  • Vista, a chubby three-year-old toddler replete with nagging, resource-hogging character flaws
  • Windows 7, the shiny hotness built after pay-to-participate beta testers shook out Vista's worst features and bugs over the course of 3 years
(this post is loosely based on an IM conversation with another friend of mine in the financial IT sector)

2009-10-21

Viral marketing

As seen in my Facebook notifications. Facebook apps in general are shady business, but this just seems downright predatory.


For those who don't know, any application you add potentially gives the author carte blanche access to anything you can see on Facebook. Friends' updates, list of friends' friends, not to mention almost anything you've bothered to fill out about yourself. Think about that before you go handing the keys to the kingdom over to LivingSocial or any of the other application developers.



2009-10-12

On cloud computing

It seems everyone is blaming a general failure of cloud computing for the massive data loss that hit Danger, Microsoft and T-Mobile over the weekend.

From what I've read, a failed storage upgrade occurred without a good, solid backup in place. That sounds a lot more like a failure in backup, planning and design than a failure of cloud computing to me. Had the storage folks at my office made the same mistakes, that's what would have been said -- right before the human resources folks came to "have a talk" with the team.

It just so happens that T-Mobile's sidekick phones rely on a lot of back-end storage, so there's the whole "cloud" element to things. I'm not familiar enough with the Danger platform to know how easy it is to back up your own data, but I'd hope it's possible.

I think it goes for any service where you've entrusted storage of your data to someone else: make sure you back it up yourself, if you think it's important. The difference with the Danger/T-Mo disaster, I think, is that it was a lot less obvious to end-users that the data wasn't all stored permanently on the phone. Clearly, "cloud computing" was collateral damage in the wake of a much more mundane failure. The fact that it was completely avoidable offers little comfort for those affected.

Shifting gears: Along comes this piece on how e-mail is becoming less and less relevant.
The thing that separates e-mail as we know it from other messaging platforms is the fact that e-mail is decentralized. Using information stored in DNS, all Internet-facing e-mail servers can properly send mail to the correct server for a given address. IRC is another decentralized communication protocol. The days of decentralized infrastructure are fading fast, though, being replaced by walled gardens that want your constant attention, and many of them requiring a separate account and password. These walled gardens are supposed to be "the new way" of communicating.

You can't easily backup everything you've received through Twitter or Facebook, and the people who communicate with you there have to have accounts. Sure, anyone can get an account. What about Google Wave? Very few of the people I REALLY want to collaborate with have an account. So, while I do see a lot of value in these services for certain things, I don't think that any of them are quite ready to fill the roll that e-mail currently provides. Chiefly: if I have a local e-mail client running on my system, I don't need to suckle at the teat of the Interwebs in order to rifle through my data. It's right there, on my computer. Web mail has indeed blurred the line, but the good web-mail providers still offer mechanisms to back-up your data or use an offline mail client such as Thunderbird.

OpenID somewhat fixes the need to have multiple accounts and passwords scattered all over the web, but shifting authentication "into the cloud" just means that each OpenID account we have will be more catastrophic if compromised. OpenID is tantamount to using the same username and password everywhere, and we know how well that works for security.

How do you backup your cloud data? Well, for starters, you can try a native-client RSS aggregator such as Liferea. One thing that "Cloud" is doing is making syndication possible through ubiquitous RSS feeds. Backups won't work perfectly on every site, for example: you won't actually download all of the photos from Flickr with RSS, you'll only get links to them. It will nicely archive text content, though. This is good for things such as blog posts, twitter conversations and the like.

2009-09-18

Verizon Wireless customers: Privacy Fail

I got this lovely IED of Privacy Fail in my inbox this morning. See the circled text. It looks like we get opted-in by default! If you don't want to be sold and traded at Verizon's every whim, you should probably try to hunt this down or access the setting in your VZW account.



Update: According to Mike Fratto (@mfratto) it's old news. How long have we been opted in, anyways!? He points out in your account, go to VZW→My Profile→View/Edit Privacy(CPNI) Settings to change

2009-08-04

I need a Kia.

No, not really. It is about time for a new phone, though. My two-year subsidized phone contract is up in a few weeks, and not a moment too soon. I've had a great run of things with my 2nd Generation LG Chocolate VX8550. But it's showing signs of being on its last legs and it's gotten pretty beat up the past few years.

Mine is on the left. My wife's is on the right. Nicks, scratches, a non-working soft-button... Yeah, I am kind of rough on my phones. All that bicycle riding, dumpster diving, and setting the phone down on concrete takes its toll...


When asking for advice on what new phone to get, I put forth the following requirements

  • Decent battery life
  • MMS/SMS ability
  • WAP Browser (gmail's WAP interface is good enough for me)
  • Tethering ability (even if it's under-the-radar like I do with my Chocolate)
  • I'd really like a qwerty keyboard, not required though.
  • Affordable. Like under $100 after renewing my plan.
I wouldn't mind if it can play music or take photos as long as it supports microSD cards, but even those features, I don't really need. I need a Kia of the phone world. Something minimalist. I do not want a smart phone.

Then, it seems the entire world is out to tell me how awesome smart phones are and decide to chastize me for my adamant stance of not needing one. In essence, these folks are preaching about how practical their Ferraris of the phone world are.

The thing is, I carry my laptop most everywhere I absolutely need a computer. Until I can buy a phone that's got 200GB of storage, Wifi AND 3G (or equivalent), and can do some pretty solid web browsing, SSH, and things like that, I really can't justify replacing my laptop with a phone. Therefore, it makes little sense to overlap functionality while spending a lot more on a phone than I need to.

So, I'll put the call out to you, our readers, who might be somewhat enlightened. You might actually understand I want just a phone with a WAP browser, tethering, and maybe a qwerty keyboard, something that I can score for under $100 and use on Verizon's network. I kind of have my eyes on the LG EnV3 (shown left)

Also, you're more than welcome donate a VZW-compatible smart-phone to me if you really, really think I absolutely must be converted. You won't find me bankrolling your experiment, though. I'll do my best to go about my daily grind while using it, and try hard not to completely destroy it. Note: I've busted a few touch-screens in my day. Things like BB Storm wouldn't stand a chance with me.

Serious suggestions wanted. Tell me in the comments.