1 800 263 0028. Let me write that again: 1 800 263 0028. That’s the number to call if you’re a DirecTV subscriber with HDTV service. It turns out that you can get, at no extra cost, the east or west coast feeds of any network if the network owns the local affiliate station. That’s called an O&O station, for “owned and operated”. In Toledo, WTVG is owned by ABC, so we qualify to get the ABC national feed. I’m still trying to figure out if the Fox station is an O&O or not; I’ve seen conflicting reports.
National HD in O&O markets
Comments Off on National HD in O&O markets
Filed under HDTV and Home Theater
Rushmore
Wow. I never really imagined Rushmore as it was. It’s much more impressive than mere photos suggest. We got up early and drove along US 16A to Rushmore; when we got there, it was overcast and cool, which was great for picture-taking. The pictures do a better job of describing the scene than I can, so here are a couple.
![]() |
|
![]() |
|
![]() |
|
Exchange 2003 SP2 technology preview
Microsoft is making a “community technology preview” (CTP) of Exchange Server 2003 service pack 2. This is pretty cool. Get it from this link (which should be live shortly). I’m particularly interested to see how people put the Sender ID tools to use.
Update: the Exchange team blog has a list of FAQs about the CTP. Note well that the CTP build isn’t supported by PSS and shouldn’t be run on production servers.
Filed under General Stuff, Musings
Center for Internet Security publishes Exchange benchmark
Great news: CIS has finally released their benchmark for Exchange 2003. It’s a fairly comprehensive assessment and hardening guide for Exchange Server 2003 (see these FAQs for more details). It was developed by CIS with input from NSA, MITRE, Microsoft, and various parts of the Exchange community. I think it will be of great benefit to most organizations now running Exchange (of course, I should have asked them to include the book in the bibliography 🙂 )
Comments Off on Center for Internet Security publishes Exchange benchmark
Filed under General Stuff, Musings
Devin’s new DCAR book
Devin Ganger, my cow-orker at 3sharp and coauthor of the Exchange Server Cookbook, is on the scoreboard again– this time with an ebook on discovery, compliance, archival, and retention. The first chapter‘s now available, so go check it out.
Comments Off on Devin’s new DCAR book
Filed under General Stuff, Musings
Disabling removable devices through Group Policy
I’ve been asked several times about ways to disable the use of removable storage devices to protect against pod slurping and related attacks. XP SP2 has a way to prevent writing to USB devices, but there’s another solution that’s described in this MVP-contributed KB article.
Comments Off on Disabling removable devices through Group Policy
Filed under General Stuff, Musings
Massive HDTV recording tip
I wish I’d thought of this: a smart guy came up with the idea of creating a TiVo wishlist with “2004” as the search term to catch all movies released in 2004. That’s not the cool part– now I can create a wishlist for a video type of “HDTV” and have instant access to the list of what’s on in HD. W00t.
Comments Off on Massive HDTV recording tip
Filed under HDTV and Home Theater
A Rocket to Nowhere
Wow. This essay is a stinging, and entirely accurate, assessment of the current state of the Shuttle and ISS programs. Too bad NASA won’t do anything about it. Excerpt:
In the thirty years since the last Moon flight, we have succeeded in creating a perfectly self-contained manned space program, in which the Shuttle goes up to save the Space Station (undermanned, incomplete, breaking down, filled with garbage, and dropping at a hundred meters per day), and the Space Station offers the Shuttle a mission and a destination. The Columbia accident has added a beautiful finishing symmetry – the Shuttle is now required to fly to the ISS, which will serve as an inspection station for the fragile thermal tiles, and a lifeboat in case something goes seriously wrong.
This closed cycle is so perfect that the last NASA administrator even cancelled the only mission in which there was a compelling need for a manned space flight – the Hubble telescope repair and upgrade – on the grounds that it would be too dangerous to fly the Shuttle away from the ISS, thereby detaching the program from its last connection to reason and leaving it free to float off into its current absurdist theater of backflips, gap fillers, Canadarms and heroic expeditions to the bottom of the spacecraft.
Filed under Smackdown!
Christmas in August
Well, not really, but today Microsoft announced the pricing for the Xbox 360. $299 for the base unit, or $399 for the console plus a controller, the hard drive, some cables, and some other goodies. Time to start scouring the sofa cushions for loose change…
Comments Off on Christmas in August
Filed under General Tech Stuff
The man who invented the neutron bomb
BoingBoing has a long profile by Charles Platt of Sam Cohen, the man who invented the neutron bomb. It’s on my reading list, though I won’t get to it for a while. (I downloaded the PDF file, just to be on the safe side).
Comments Off on The man who invented the neutron bomb
Filed under General Tech Stuff
Bulletproof Wireless Security (Chandra)
| “BULLETPROOF WIRELESS SECURITY : GSM, UMTS, 802.11, and Ad Hoc Security (Communications Engineering)” (Praphul Chandra)
I asked for a review copy of this book because I understood it to be a guide to implementing security. The problem is that “implementing” is a loaded term. I wanted a book on how to set up and configure security, and Chandra’s written a book about how to engineer products that implement these solutions. In that light, this is an interesting book because it covers GSM, UMTS, and 802.11 security. The writing style is clear and direct. However, there’s a problem: for a book billed as comprehensive, there’s not enough depth to actually help an implementer build an implementation of any of these protocols. For example, the first 60 pages or so explain some basic security concepts and algorithms, and the next 25 pages cover how security protocols are applied at various OSI layers. There’s a chapter dedicated to GSM and UMTS security, and one on 802.11a/b/g security that (IMHO) pulls some punches about how bad WEP is. In a book targeted at implementation engineers, it would have been helpful for Chandra to go deeper into the reasons why we got stuck with such a crappy security implementation. |
Overall, this book is probably most useful to those who need a quick survey-level introduction to wireless security because they’re working in the wireless industry. It’s pretty much useless for system administrators or developers (particularly because there’s only vestigial coverage of code security/quality issues) except for folks who have a general interest in the topic.
Comments Off on Bulletproof Wireless Security (Chandra)
Filed under Reviews
Bulletproof Wireless Security (Chandra)
| “BULLETPROOF WIRELESS SECURITY : GSM, UMTS, 802.11, and Ad Hoc Security (Communications Engineering)” (Praphul Chandra)
I asked for a review copy of this book because I understood it to be a guide to implementing security. The problem is that “implementing” is a loaded term. I wanted a book on how to set up and configure security, and Chandra’s written a book about how to engineer products that implement these solutions. In that light, this is an interesting book because it covers GSM, UMTS, and 802.11 security. The writing style is clear and direct. However, there’s a problem: for a book billed as comprehensive, there’s not enough depth to actually help an implementer build an implementation of any of these protocols. For example, the first 60 pages or so explain some basic security concepts and algorithms, and the next 25 pages cover how security protocols are applied at various OSI layers. There’s a chapter dedicated to GSM and UMTS security, and one on 802.11a/b/g security that (IMHO) pulls some punches about how bad WEP is. In a book targeted at implementation engineers, it would have been helpful for Chandra to go deeper into the reasons why we got stuck with such a crappy security implementation. |
Overall, this book is probably most useful to those who need a quick survey-level introduction to wireless security because they’re working in the wireless industry. It’s pretty much useless for system administrators or developers (particularly because there’s only vestigial coverage of code security/quality issues) except for folks who have a general interest in the topic.
Cheap Samsung laser printer
Newegg has the Samsung ML-2010 laser printer (review here) at $127.95. Scroll down to “Combo Specials” and pickup a free Rosewill Wireless Keyboard and Mouse combo. Enter promo code “sam2010” during checkout for $40 off the printer. Send for the Newegg-exclusive $50 rebate. Shipping is $14.95. Your net cost: $53 or so.
Filed under Friends & Family
Unbelievable VERITAS security hole
Wow, this is hard to stomach. CERT is reporting TA05-224A: “VERITAS BackupExec Uses Hard-Coded Authentication Credentials”. It’s astonishing that any company could be so stupid as to ship a product that still uses hard-coded credentials; it’s a wonder that it’s taken this long for an exploit to start circulating. (Note that this is different than the vuln-o-rama announced last month.)
According to Symantec’s page on the vuln, only BE versions 8.0, 8.5, and 8.6 have the flaw. I’d bet that’s a significant portion of the installed base, so a) I hope they’re protected and b) I sure would feel more comfortable if the page also said “hey, don’t worry, we fixed the problem in BE 9”. My concern is that BE 9.x and 10.x have the same, or similar, problem but that attackers haven’t found the creds yet.
Update: Symantec updated the vuln page last night with this additional page. Turns out that BE 9.0, 9.1, and 10.0 are vulnerable too. Sheesh. Making things worse, to fix the remote agent you have to uninstall the remote agent, reboot, install the new version of the agent, and reboot again. There’s no hotfix.



