CSO (“the magazine for the chief security officer”) has a terrific, and well-balanced, article on the difficulty, and necessity, of patch management. I highly recommend it.
New craft gallery
This is what I should have done in the first place: set up a gallery for Arlene’s craft pictures. Here it is.
Comments Off on New craft gallery
Filed under Friends & Family
Home theater blog
Thanks to my pal Rod Montgomery, I now know about the Oasis Home Theater Blog. Now, where did Arlene hide the checkbook….
Filed under HDTV and Home Theater
Word for the day: “low spousal acceptance”
So that’s what they call it. From this story in the New York Times:
Because of wiring problems and general aesthetic concerns, the right and left rear speakers in a surround-sound system suffer from what those in the home-electronics business call low spousal acceptance, which means that at least one household decision-maker vetoes their installation.
So, by that criterion, not only do my rear-channel speakers suffer from LSA, but so do the HD TV set (which also suffers from “low Aunt B acceptance”) and the Xbox (partially compensated by high child acceptance). Fortunately, the TiVo has high spousal acceptance, which sort of makes up for the other two– at least until I get an HDTiVo, if and when they ship.
Comments Off on Word for the day: “low spousal acceptance”
Filed under Musings
Foiled again!
My evil plan to get a Google search rank of #1 for “Stampin’ Up!” has been foiled so far, not least because they maintain their own site for demonstrators: stampinup.net. Unfortuantely, the page throws an error when you load it. They’re apparently offering sites for their demonstrators (example), which I guess makes good business sense. I’ll have to find some other way to achieve world stampin’ domination.
Comments Off on Foiled again!
Filed under Musings
SPEWS/Osirusoft RBL goes away
According to this Slashdot article, the SPEWS real-time block list is no longer operational. A comment-free version of the same basic story is here. The article points to a lot of discussion on news.admin.net-abuse.email, too, which amkes for interesting reading. Osirusoft shut down SPEWS after being the target of an ongoing distributed-denial-of-service (DDos) attack. The manner in which it was shut down caused lots of bounces (including for my friend Bob Thompson and Kent State University, among others). The problem is that when Joe Jared, Osirusoft operator, shut down his service, he did so by telling the server to blacklist every IP address. Sites that rely solely on SPEWS thus dropped all their incoming mail on the floor.
What does this mean to you, the Exchange administrator? As Andy Lester points out, outsourcing your spam protection completely to a third party puts your mail service at the mercy of that third party. Exchange 2003 includes RBL support, and it’s a useful adjunct to heuristic or keyword-based filters. However, RBLs themselves don’t provide a complete solution, and you should choose your RBL provider carefully to make sure that a) they provide support for their service and b) they have the resources to stick out this kind of attack.
Comments Off on SPEWS/Osirusoft RBL goes away
Filed under General Stuff, Musings
Adios, Tablet PC
On Saturday, I took my Acer C102 Tablet PC back whence it came. I bought it in late July, so it had almost a month (including two trips to Redmond and one to Salt Lake) to win me over. The bottom line is that it’s not enough of a laptop for my needs. When in Redmond, I made a point to take it with me to every meeting I attended– but I never used it! The relatively slow CPU and limited RAM had a lot to do with it, too, as did the fact that I can type way faster (and more legibly; just ask my high school English teachers) than I can write. I still think the Tablet PC form factor has a lot of potential, especially as more customized applications like Classroom Presenter and TabletPlanner come out, and I would have liked to try using the Tablet as a presentation machine. However, all was not lost; my spiffy new ThinkPad T40 is almost as thin as the C102, and it’s hella fast, with great battery life and 1GB (expandable to 2GB) of RAM. I guess I’ll keep tabs on the Tablet world and see how it’s doing next summer; by then, there should be machines with better screen resolution and more CPU horsepower.
Comments Off on Adios, Tablet PC
Filed under General Tech Stuff
Several more cards
Wow, my wife’s creativity is endless! I can’t believe no one is posting comments. I guess my techno-nerd stylings have scared away all readers with a taste for rubber stamps and crafty scrapbook stuff. (Hey, maybe if I write “Stampin’ Up!” ten or so times this page will rise to the top of Google’s search. Worth a try, eh? Stampin’ Up !Stampin’ Up! Stampin’ Up! Stampin’ Up! Stampin’ Up! Stampin’ Up!) Note: the cards themselves are here now.
Comments Off on Several more cards
Filed under Friends & Family
Be careful what you ask for
Famous last words: “I want one just like that.” We’re hiring someone new, so I decided to order a new T40 and give my not-so-old T30 to the new guy. This is a time-honored tradition, since John did it with his T30. I asked Peter to order me one just like John’s, never dreaming that it meant “no wireless”. Of course, John a) doesn’t travel much b) doesn’t have a WLAN at home, and c) doesn’t have a WLAN at work. Of course he didn’t order a machine with built-in wireless. I, on the other hand, use it heavily, so now I am facing a dilemma:
- Violate my warranty and slap in an IBM wireless card, which means I could run 802.11a/b (there’s an a/b/g card on their website, but I can’t find it for sale separately)
- Void the warranty and install my own card
- Try to get CDW to help me out in some way
- Suck it up and use my old Cisco PC Card adapter.
In the meantime, a word of advice: spec your own darn notebook. Update: Turns out that IBM sells a combo a/b/g card (part #31P9701 or 91P7301, depending on who you ask) so all I need to do is snag one of those somehow.
Comments Off on Be careful what you ask for
Filed under General Tech Stuff
Need a TiVo? Get one for $90
Everyone should heed High Priestess Julie: get a TiVo. Now, for a pittance, you too can join the TiVolution. (Personal to John: this has your name written all over it.)
Filed under HDTV and Home Theater
More cards
And another one… actually, it’s now in the gallery.
Comments Off on More cards
Filed under Friends & Family
Rock the Boat Audio
Dad’s boat had a radio; I say “had” because someone stole it over the winter, while the boat was in dry storage. This is a little surprising for two reasons: it wasn’t a very good radio, and the thief didn’t take the sleeve that it fits into. For Dad’s birthday, I wanted to get him a replacement, so I went shopping from the comfort of my recliner. First stop was West Marine, where I found a tiny assortment of overpriced, junky-looking radio. Next, I plugged “marine radio” into Google and found Rock the Boat. THis is what I love about the Internet– a niche-focused retailer that concentrates only on one small area and does it really well. They had the radio I wanted, so I ordered it. When I arrived, I found that it was black, despite the website picture that showed a white radio (which was what I wanted, as the boat’s dash is a dazzlingly white expanse of fiberglass). I mailed the Rock the Boat folks, and they quickly dispatched UPS to pick up the black unit while simultaneously sending out the correct unit. It arrived in plenty of time for Dad’s birthday, and they could not have been more friendly or courteous. I would be very happy to do business with them again (as long as it’s not the result of someone stealing this radio…)
Comments Off on Rock the Boat Audio
Filed under Reviews
The other big security story
I figure everyone is sick of hearing about Blaster by now. (Quick recap: 1. Apply patches. 2. Install a firewall. 3. Use up-to-date AV software). There’s another, lesser-known story out there that I think is pretty interesting: the master FTP server for GNU was compromised, and now they’re scrambling to assess the damage and repair it. It’s hard to discuss this without sounding like a fear monger, but I’ll try to explain why this is so important.
ftp.gnu.org, the machine that was compromised, is the official central repository for all FSF software. All of the other FSF distribution points (and there are many) mirror its contents. – usually automatically. If you’ve added an FSF package to your system any time in the last 6 months, chances are that it came from ftp.gnu.org or one of its mirrors. Of course, if you’ve built any Linux distro in the last 6 months, odds are that you used multiple packages from ftp.gnu.org. Heck, the gcc compiler, which all free Linux software is built with, is officially distributed from ftp.gnu.org, so one might argue all software compiled with a compiler in the last 6 months is potentially impacted. (i.e. someone put a trojan in the compiler sources, placed those sources on ftp.gnu.org. Now anyone that builds that compiler has a trojaned compiler, one which outputs only trojaned binaries).
To recap: any FSF package downloaded from any FSF mirror might have been compromised. The FSF hasn’t been cryptographically signing their packages (like Windows Update does) so there’s no way to directly verify their integrity other than taking MD5 hashes, but that in turn depends on finding an “original” version of each pacakge and recomputing the hashes. They’re going to start signing their packages, as explained here, but… well, horse, barn door, shut.
If this same compromise had happened to Microsoft, you can imagine the press firestorm that would have followed. The press reporting on this has been pretty mild; no one seems to think it’s exceptional that an important machine, presumably run by competent admins, was compromised and that no one noticed for four months.
Interestingly, the FSF says that they believe that everything on ftp.gnu.org currently is safe, but they haven’t said anything about any piece of software any time in the last 6 months. Their action thus far has been to wipe everything off of ftp.gnu.org and replace stuff that they feel confident hasn’t been tampered with. This is the right thing to do from a security standpoint, but it doesn’t inspire a lot of confidence in the security of the packages on their server and mirrors.
Comments Off on The other big security story
Filed under General Stuff
As the world turns, airport-lounge style
I’m in the south terminal WorldClub at the Detroit airport. Behind me are two overstressed business travelers. One is arguing with her daughter, who has apparently invited some hussy named Dorothy to sleep over while Mom’s out of town. Mom’s take seems to be that Dorothy should be at her ill father’s hospital bedside, but in any event no one is welcome to sleep over while she’s out of town (and she’s home a lot). Competing with her is a middle-aged man who had a short, angry conversation with what I assume was his wife, muttered (rather loudly, actually) “I need a beer”, and returned to pick up the conversation anew. Someone in his family is ill too, and claims to want to die, but won’t, or isn’t, or something. All I can tell is that he’s very angry about the whole situation. I would move, but then I’d have to give up my chair and, much more importantly, my power outlet. Nothing doing. At least I can drown my angst with some excellent Vermont sharp cheddar, which NWA has thoughtfully provided for those of us who would rather graze than eat aboard their flying spam cans shiny 757s.
Comments Off on As the world turns, airport-lounge style
Filed under Travel
This time it’s scrapbooking
Another note to Pauline: a) please get a faster Internet connection. b) Here’s a scrapbook page for your consideration… actually, it’s in the gallery now.
Comments Off on This time it’s scrapbooking
Filed under Friends & Family
