Gadgetry

My friend Fabienne managed to cajole me into writing up what rocked at SIGGRAPH. The resulting manic geekery can be found here on Hackaday. Whoot!

Also cool: I was browsing DAPreview (the site for those addicted to MP3 players…I’m on #15, I think?), and found

Wooden Headsets. As pleasingly Non-Apple-Hipster-White as they are, they’re

transformed into pure awesomeness by the truly awesome cautionary imagery

that accompanies them, and every product on this site. Check it out:

Read the full entry »

Katrina News

DoxparaBot2 on AOL Instant Messenger — send “add” to it and you’ll get all the news WWLTV is putting out on their incredible blog.

(yes, this was KatrinaWWLTV, but they blocked that account…aol really isn’t a great distro mechanism for this sort of thing. Anyone know someone at AOL IM?)

(I give up. AIM repeater down.)

UPDATE: Best comment on the situation I’ve heard yet:

Subground: You know your in deep s**t when Sri Lanka goes “Hey, I think we can help those dudes out.”

YOU LEARN SOMETHING NEW:

One of the most common myths associated with natural disasters is that cadavers are responsible for epidemics. In many cases, the management of cadavers rests on the false belief that they represent an epidemic hazard if not immediately buried or burned. In fact, the health hazard associated with dead bodies is negligible. The collection, disposal, burying and/or cremation of corpses requires important human and material resources which should instead be allocated to those who survived and remain in critical condition.

–World Health Organization

ITS OFFICIALLY GOTTEN WEIRD…

Read the rest of this entry »

14 Year Old Self

I have long believed that consciousness grows more through duplication than modification, meaning our old selves get to rumble around in some sort of execution-constrained mental version control system. It’s one of the things I expect will someday be demonstrated as a purpose of sleep — a given instantiation can only run for so long — and nicely explains a bunch of oddities about the human condition, like regression under extreme stress and the entire sensation of nostalgia.

I bring this up because I’m quite sure I felt my 14 year old self start yelping with joy at Mathomatic. See the examples for details.

(Yes, I know about Mathematica, and the obtuse but brilliant HP48G. This is about a thousand times more straightforward…if someone ever ported this to a SAT-legal calculator, things would really get interesting.)

Read the full entry »

10/6

Blue Hat. Blue Hat was fantastic. Four hundred MS engineers witnessing HD’s VNC injection for the first time — this is not an experience one has every day 🙂 It’s unquestionable that MS has recognized a threat to its continued existence. Spyware has them spooked something fierce, as well it should: Every time I put a Knoppix disc in my system, I get a consistent environment that does almost everything I want. Customization is only a boon if your system gets closer to desired behavior over time. Spyware converges on…well, “complete abject system failure” comes to mind. Not exactly good for the Microsoft value proposition. It’s very nice to see they understand this.

Regarding the two web pages with the same hash:

Note the hashes:


$ curl http://s3.amazonaws.com/dmk/t1.html | md5sum
 % Total % Received % Xferd Average Speed Time Curr.
 Dload Upload Total Current Left Speed
100 40737 100 40737 0 0 224k 0 0:00:00 0:00:00 0:00:00 406k
c0f3adb824590b40944614268e627421 *-
$ curl http://s3.amazonaws.com/dmk/t2.html | md5sum
 % Total % Received % Xferd Average Speed Time Curr.
 Dload Upload Total Current Left Speed
100 40737 100 40737 0 0 150k 0 0:00:00 0:00:00 0:00:00 240k
c0f3adb824590b40944614268e627421 *-

I’ve been showing this at conferences since Shmoocon back in January. The tool that generates the collisions, Confoo, will be on this site shortly, but the technique is fairly straightforward — View Source is your friend. For details, see the MD5 Someday paper or Daum and Lucks’ application of the technique to Postscript.

Incidentally, broke my arm. That sucks. They gave me the raw CT scan data. Rock. Looks like I get to open source my the shattered remnants of my arm… 😉 (It’s not that bad, but they are operating tomorrow. Fun.)

Early imagery, if ya care:

Read the rest of this entry »

The Only Secure IM Client

The architecture of Instant Messaging has for several years been a matter of divergence between theory and practice. In theory, IM should be as distributed just like email — every domain managing its own users. In practice, though…how is email doing with its massively distributed infrastructure? Not so well, with an astonishing number of users ending up at centralized providers that not only just mimic the choose-your-megacorp model used by IM, but are actually run by the same companies.

But what are the security implications of such centralization? Couple years back, AOL had an exploit against their IM client get out. Tens of millions of users were vulnerable…but only a few thousand actually got infected.

Say what you will about centralization — the filters worked. 10M unpatched endpoints stayed safe.

Filtering instead of patching is an interesting question. It’s worth pointing out that, while AOL wasn’t going to let the malicious payload pass, anyone with local access to a user’s unprotected packet stream could inject the centrally filtered payload. And filters have a nasty habit of not encapsulating sufficient logic regarding the nature of all possible exploits — in other words, a slight change in the attack and the filter fails while the broken code remains. But yet the perfect is often the enemy of the good, let us not forget that what would have been a product killing exploit anywhere else fell by the wayside because of an effective centralized filter.

We have to discuss Microsoft for a moment. They actually have people who believe quite strongly in filtering as a first level of defense. I ended up meeting one of the researchers from their Shield project at MSR. Smart lady, interesting ideas on the future of security. Hopefully I’ll get my hands on the Shield code — if there’s one thing that they do right at MSR, it’s make cool code available for download. (And I bet you thought I couldn’t turn another entry into, oh look cool toys.) Now, MSN has been suffering from a serious number of very nasty worms — including those that (um, finally) actively defend themselves against disinfection techniques. The worms were using the MSN IM client’s ability to transfer files. They needed to do something.

What they did was…astonishing. My GF was annoyed to find her friend couldn’t send her an MP3 file. For a while we thought this was a sop to RIAA. A moment of searching showed there was quite a bit more that was being blocked.

Read the rest of this entry »