Most Depressing Packet Trace…Ever.

There I was, minding my own business, just trying to set up a PPTP VPN (is that a contradiction?) connection, when:

08-05-2001 18:46:16.59 - PPP: Received Control Packet of length: 33
08-05-2001 18:46:16.59 - Data 0000: c2 23 04 01 00 1f 49 20 |.#...^_I
08-05-2001 18:46:16.59 - Data 0008: 64 6f 6e 27 74 20 6c 69 | don't li
08-05-2001 18:46:16.59 - Data 0010: 6b 65 20 79 6f 75 2e 20 | ke you.
08-05-2001 18:46:16.59 - Data 0018: 20 47 6f 20 27 77 61 79 | Go 'way
08-05-2001 18:46:16.59 - Data 0020: 2e 00 00 00 00 00 00 00 |........
08-05-2001 18:46:16.59 - CHAP: Login failed: username, password, or domain was
incorrect.

Once again, SLiRP (“the S stands for Style”) reaffirms its badassness. Some things never change.

Read the full entry »

Always Bet On Black (Hat)

The Black Hat Briefings in Vegas for 2001 are almost over, and its been one hell of a time. This is the first year that I’ve presented(summary: OpenSSH tak en way too far *laugh*), and despite some small technical difficulties, it went well–thanks to DT for giving me the opportunity! I’m finally becoming somewhat of a coder, as slow and painful an experience as it is (but then, I was trying to do flexible string parsing in C, not something trivial like embedding a SOCKS4 server in the OpenSSH client…). About bloody time doesn’t begin to cover it. (Kids–there’s nobody more ignored than an armchair hacker. Remember that.)

As promised, I’m making the slides available — they should be converted to HTML “soon”; I’ve discovered that PowerPoint is alas yet another roach motel of a file format. *sigh* If you missed the talk, hitch a plane to Vegas because it’s happening again on Sunday–though considering it’s the morning after everyone’s last night in Vegas, I expect about three sober people in the audience.

I’ll be making a reasonably major release at Defcon–the proof of concept is done, but I want to port it to a few different platforms and write up an analysis of the attack. In the meantime, enjoy:

  1. Gateway Cryptography: Hacking Impossible Tunnels through Improbable Networks with OpenSSH et al.

Incidentally–anyone who does anything without crypto at Defcon is flat out screwed.

In other news–I’ve been walking around on a pair of wheeled shoes. Damn they’re slick; I just wish I wasn’t still limping from that unfortunate incident with the whiteboard.

Don’t ask.

Read the full entry »

Feeling Used

Now, I do want to say that systems like TellMe Networks, and VoiceXML itself are actually quite cool, if a slight bit non-obvious how to program. TellMe’s systems actually incorporate non-trivial amounts of speech recognition technology, which from what I can tell works on occasion.

But.

Sometimes I want to talk to a travel agent. Sometimes I want to fill in a few web forms. But let me tell you, I’m not optimistic about the future of talking to a web form*. Some analysis to chew on:

  1. Speech Vs. Vision: A quick summary of my information transfer theory.
  2. Deaf and Dumb: A Critique. An application of the previous document to the standard Telephone Registration Systems at many college universities. Send me feedback.

Incidentally: Would someone *please* create a trivial HTML->VoiceXML translator? I can’t wrap my brain around using a document format for a procedural language just quite yet.

Read the full entry »

Deaf and Dumb: A Critique of Telephone Class Registration Systems

DEAF AND DUMB

One of the core laws of information transfer theory is as follows: Humans read faster than they can listen, but speak faster than they can write. Voice mail vs. E-Mail provides an excellent illustration of this asymmetry: It’s quite a bit faster to send twenty voice mails than it is to type out twenty emails – but it’s much faster to read twenty emails than to listen to twenty people’s voice messages, especially if there’s anything important in that message that needs to be subsequently written down.

Visually organized systems, such as documents and web pages, end up being more complex than a simple stream of spoken phrases to generate, but once generated can be skimmed quickly for areas of relevance to the reader which then may be focused on. Notably, the message is not time dependent-the words stay where they were as the reader moves onto another segment.

By sharp contrast, the spoken word is nothing more than a stream of vibrations in the air-the stream might be repeated, but it exists as an understandable entity only because of our short-term memories. As soon as a word is spoken, it disappears, and can only be retransmitted on demand, not simply referred back to with a jump of the eye.

Thus the prime flaw with Interactive Voice Response, or IVR: It must speak everything-slowly, linearly–and IVR is left struggling with a painfully slow method for providing feedback to its users.

And yet, Since telephones are built to carry speech, one might assume. But sound is only the most efficient input to information systems when our spur-of-the-moment phrasings of a specific request, or even our standardized vocalizations of a given demand, can be understood and interpreted among many other possibilities.

Read the rest of this entry »

Chemotherapy

It’s been a while–too long. Following with my standard practices of:

  1. Living a life as annoyingly unpredictable as possible
  2. Doing anything not to go to sleep
  3. Eventually injecting personal information into some manner of technical tour-de-“force” that was once going to remain pure
  4. Cross-pollinating information and argumentation from as many directions as possible.

…I’ve decided to be a bit more open on DoxPara Research(TM)(C)(R)(whatever).

I think the theme of the moment is Chemotherapy. Chemo is generally the standard treatment path taken for cancer patients, and effectively involves ingesting poisons that (hopefully) harm tumors more than healthy tissue. For all the power of modern medicine, one can easily imagine many traditional healing mechanisms operating in a similar manner.

I think of Chemo for several reasons. Years ago, in high school, our principal gained some notoriety for accusing the class below us of being, “the cancer of this school”. Myself, my friends, my roommates, we’ve all experienced the artifically enchanced growth of technology, benefitted from it, grown from it…but one wonders whether our growth was hijacked–or even forged–from the fires of greed, fraud, and simple opportunism.

There are no conspiracies, merely business plans.

Read the rest of this entry »

No Accounting For Taste ;-)

Visitors from my ever-so-illustrious Accounting One class… Version 0.1 of Accounting Notes. Everyone else…I’ve got some pretty interesting plans for creating one of the first environments for massively distributed, universally accessable, true cooperative learning. Got ideas? Want more info? Want to help? Mail me.

Never underestimate the power of thirty people studying the same thing at the same time.

(More on this below)

Read the full entry »

Calm Before The Storm

Question: What do you get when you combine:

  1. Millions of students addicted to Napster
  2. Millions of soon-to-be-college-freshmen itching to join the high speed P2P r evolution–and bitter that they missed so much of it.
  3. Advanced technology to allow decentralized search and retrieval of arbitrary information
  4. Easy to use collaborative environments for building web sites
  5. A dearth of available and highly skilled notetakers for college classes, combined with third party resellers becoming the only source of such notes
  6. A near-complete lack of well-summarized study material to accompany textbooks
  7. Extraordinary textbook costs
  8. Fair Use
  9. Work that’s going to be done anyway…quarter, after quarter, after quarter…that seems to evaporate entirely.
  10. Information Wants To Be Free
  11. Information Wants To Live Forever

Teachster. It’s coming. More on this later.

Read the full entry »

Frustration

One of the classic rules of information security is as follows:

Bad security is worse than no security. With bad security, you think you’re safe. With no security, you know you’re not–and act accordingly.

What’s interesting is how much this applies to user interface concerns as well. Occasionally, Windows will simply fail to execute simple copy-and-paste correctly. It’s not so common that it prevents me from using it entirely (which, incidentally, is a horribly damaging attack against an IT infrastructure–break things so often that people refuse to trust and receive value from *anything* out of IT), but it’s not so rare that I can ignore it as a random bug. It’s essentially stuck in that middle ground, where I have to accept and suffer through it, all the while experiencing much more frustration than if I just consistently retyped the text myself.

This is not just idle chatter. More and more, I’m realizing the effects of user frustration are a key tool in understanding everything from cryptographic deployment(Sporadic SSL vs. Universal IPSec) to Desktop UI’s to the farce of “Secure” Digital Music that breaks on a whim.

More on this another time.

Read the full entry »

There's Content In Them Thar Hills

Given the amount of press that Ye Olde Napster seems to dredge up for its sins, one would thing more attention might be paid to how hyperactively reshared mass media has become. There are still authoritative sources of high quality news, but more and more I’m realizing that the “online experience” of that news might actually be less fulfilling than the “dead tree product”.

After all, it may a pain to dispose of the newspaper, but:

  1. It can’t be ignored(or more accurately, ignore it for a few days and it piles up, reminding you of your own wastefulness).
  2. It can’t be unpublished, and it *will* be archived.
  3. It’s much easier on your eyes(if not your arms), meaning you read more.
  4. There’s an actual profit model. (sigh)

That being said, there are some truly unique things that the net really does enable. Usually, the more domain specific a given piece of work is, the harder it is to acquire(since the generalized stores won’t waste space on what appeals to very few). The net alleviates that, but suffers a different problem: Due to the lack of a profit model, after a certain point, it’s all too easy for a site to simply not scale to large amounts of traffic and to have no way of improving scalability. This was the problem the absolutely incredible ZZZ Online faced, after being temporarily(but repeatedly) raised from a slightly obscure but technically unparalleled journal of upcoming technologies to a “geek mass market” Slashdot destination. They lost their provider as a result of the crushing load–an embarassment of riches, if anyone was actually getting rich!

Honestly, there’s a decent question of whether traditional unicast methodologies(even when multiplied by highly distributed middlemen) actually can or should be made to scale to broadcast-sized audiences. P2P will inevitably be sold to the few remaining VC’s with money to burn as the solution to these problems, and indeed leveraging network locality of one’s clients while maintaining stream integrity is very likely to be an effective strategy…at least until high speed upload at the client side becomes buried by provider centralization and possibly legal challenges(i.e. “why would anyone want to send data that they didn’t steal from us?”).

In the end, it’s going to be Yet Another Battle, with the “Consumer Movement” probably winning more converts from the “Napster Constituen cy” than they ever imagined.

Read the full entry »