Showing posts sorted by relevance for query open university. Sort by date Show all posts
Showing posts sorted by relevance for query open university. Sort by date Show all posts

Wednesday, January 28, 2009

Matt Miller - The Tyranny of Dead Ideas



Went to Townhall Seattle last night as I mentioned previously. I mixed up the dates and the talk I was going to see is actually tonight, but the cute girl at the ticket stand (and she was very cute)convinced me to stay and see a talk by Matt Miller on his book The Tyranny of Dead Ideas.

Mr. Miller is a former advisor to the Clinton and Bush 41 White Houses and a columnist for Fortune Magazine and the Atlantic magazine so I figured hey he might be worth listening too.

He was.

I didn't agree with most of his contentions, although I could understand his reasoning. (He appears to be a liberal, but doesn't not militantly so). One I did agree with is that the American educational system needs an overhaul although we had a disagreement there too. He believes that it needs to be nationalized from the standpoint of standards and funding. I think it needs to be completely re-evaluated, as I have written many times in the past. (here are two of my more coherent posts on the subject) Mr. Miller said he wanted to hear our suggestions for dead ideas so I wrote him this morning and suggesting the same sort of model that I proposed in my Open University post at the elementary and high school levels.

Speaking of the Open University - I just found out yesterday that Britain has an online program run in connection with the BBC called The Open University, and that an Israeli is proposing to open a free online degree granting university. That should be interesting.

Also in education news - LA teachers are boycotting assessment tests in order to preserve their jobs.

The Los Angeles teachers union and the city's school district are battling over a district practice that, a Times' analysis suggests, contributes to higher scores on state tests.

The practice is "periodic assessments," a bureaucratic name for exams administered by the Los Angeles Unified School District. The goal is to give teachers insight into what students need to learn while there remains time in the current school year to adjust instruction.The union Tuesday directed teachers to refuse to give them to students on the grounds that the tests are costly and counterproductive.

source


Here is another dead idea - Only teachers can teach. Fire 'em all revoke the unions collective bargaining status and start over with a fresh crop.

I have mentioned before that one of the most successful educational institutions in the US is the military. One of the reasons that they are is through the use of assessments. In every course of instruction the instructor reads out the Terminal Objectives, what the overall goal for that course of instruction is, and Enabling Objectives, what the goals of that particular block of instruction are. In most a pretest and a post test are given to evaluate how effective the instruction was.

It works, and that is really what a periodic assessment test is. My personal opinion is that teachers don't like them because they know deep inside that overall the educational system is failing to educate and these tests point that out.

Friday, October 05, 2007

Following up on the "Open University"

A few weeks ago I posted about the failure to utilize all avenues in developing an education system (the open university). It appears I am not alone in this observation:

Countries like China, India, and Korea have invested heavily in education over the last decade. They are now producing more scientists and engineers than we are. It is my concern that as we look to the future, innovation is going to come from the other side of the world.

Lacking a clear and present danger, the American education system is not mobilizing to support science, technology, engineering and math. Today’s generation of kids is the most technology savvy group that this country has ever produced. They are born with an iPod in one hand and a cell phone in another. They’re text messaging, e-mailing, instant messaging. They’re on MySpace, YouTube & Google. They’ve got Nintendo Wiis, Game Boys, Play Stations.

Their world is one of total interactivity. They’re in constant communication with each other, but when they go to school, they are told to leave those “toys” at home. They’re not to be used in school. Instead, the system continues teaching as if these kids belong to the last century, by standing in front of a blackboard.

Education has not changed, and that’s a problem. It was a good system when I came through, but today’s kids have changed, and that’s the part that educators are not realizing. It’s the kids that have changed, and our education system needs to change along with them.

Again, they are the most technologically savvy group of kids we’ve ever had; we’ve got to take advantage of that.


Anyone who knows me knows that I am not an advocate of change for changes sake. I tend to believe that systems evolve and maintain themselves for a reason, but I also know that sometimes inertia will carry something along far past its natural stopping point. We really need to examine if that is the case with our educational system.

Thursday, August 13, 2020

What I am Reading 8/13/2020 - Russia, At It Again and Application Security

The Register - You weren't hacked because you lacked space-age network defenses. Nor because cyber-gurus picked on you. It's far simpler than that -
 The continued inability of organizations to patch security vulnerabilities in a timely manner, combined with guessable passwords and the spread of automated hacking tools, is making it pretty easy for miscreants, professionals, and thrill-seekers to break into corporate networks.
This is according to the penetration-testing crew at Positive Technologies, which pored over the results of its 2019 client audits [PDF] and found that 71 per cent of the time – 20 out of 28 pentest contracts – its red team was able to get into their target using tools and tricks available to script kiddies and newbies.
...
The report shows that performing what some assume is the minimum of effort – timely patching, login monitoring, and network segmentation with access limit policies, for instance – can be rather effective at keeping at least opportunistic crooks out.
ZDNet - RedCurl cybercrime group has hacked companies for three years -
Security researchers have uncovered a new Russian-speaking hacking group that they claim has been focusing on the past three years on corporate espionage, targeting companies across the world to steal documents that contain commercial secrets and employee personal data.
Named RedCurl, the activities of this new group have been detailed in a 57-page report released today by cyber-security firm Group-IB.

SC Magazine - Shadow Code in security’s blind spot, ups risk of attack -
The proliferation of Shadow Code – third-party scripts and open source libraries used in web applications – may help organizations accelerate their digital transformations but it also puts them at higher risk of cyberattack.
Security teams are finding the Shadow Code, the code equivalent to rogue or Shadow IT, remains a blind spot for their organizations, with a mere eight percent of respondents in a PerimeterX/Osterman Research report saying they have complete visibility into the hidden code running on their websites. That’s a drop from 10 percent in 2019.

Related - CSO - The state of application security: What the statistics tell us -
A new report by the Enterprise Strategy Group (ESG), which surveyed 378 application developers and application security professionals in North America, found that many organizations continue to push code with known vulnerabilities into production despite viewing their own application security programs as solid.
Releasing vulnerable code is never good but doing so knowingly is better than doing it without knowing, since the decision usually involves some risk assessment, a plan to fix, and maybe temporary mitigations. Half of respondents said their organizations do this regularly and a third said they do it occasionally. The most often cited reasons were meeting a critical deadline, the vulnerabilities being low risk or the issues being discovered too late in the release cycle (45%).
 Related - CSO - 4 best practices to avoid vulnerabilities in open-source code -
A vulnerable or malicious package that makes its way into popular repositories, and eventually into your software supply chain, can wreak havoc for your customers. Vulnerable and malicious components have been detected in popular open-source repositories such as npm, PyPI, NuGet and Fedora.
Best Practices:
  1. Know your software - i.e Software BOM
  2. Resolve Dependency Issues - 47% of flawed libraries are transitive, pulled in by a library not by the developer
  3. Automate Code Scanning
  4. Beware of Licensing Risks
Related - HelpNet Security - Surge in cyber attacks targeting open source software project -
There has been a massive 430% surge in next generation cyber attacks aimed at actively infiltrating open source software supply chains, Sonatype has found.
The Register - Made in China? Not for much longer, reckons Foxconn boss -
China's days as "the world's factory" are numbered, according to Foxconn chairman Young Liu.
Speaking to investors on a conference call, the Apple supplier's boss predicted local markets would grow their own manufacturing ecosystems, pointing to India and the Americas.

Threatpost - ReVoLTE Attack Allows Hackers to Listen in on Mobile Calls -
Dubbed ReVoLTE, the attack — detailed by a group of academic researchers from Ruhr University Bochum and New York University Abu Dhabi — exploits an implementation flaw in the LTE cellular protocol that exists at the level of a mobile base station. ReVoLTE makes use of a predictable keystream reuse, a scenario in encryption in which stream ciphers, or encryption keys, are vulnerable to attack if the same key is used in a predictable fashion.can allow threat actors to recover the contents of an encrypted VoLTE call.
Cyberscoop - NSA, FBI publicize hacking tool linked to Russian military intelligence -
Hackers working for Russia’s General Staff Main Intelligence Directorate’s 85th Main Special Service Center, military unit 26165, use the malware, which the Russians themselves call “Drovorub,” to target Linux systems, the NSA and FBI said Thursday in a detailed report.
...
While the alert does not include specific details about Drovorub victims, U.S. officials did say they published the alert Thursday to raise awareness about state-sponsored Russian hacking and possible defense sector vulnerabilities. The disclosure comes just months before American voters will conduct a presidential election.

Friday, June 04, 2010

Wal-Mart catches up with Kuru Lounge

Today:  Wal-Mart to Offer Its Workers a College Program

The purveyor of inexpensive jeans and lawnmowers is dipping its toe into the online-education waters, working with a Web-based university to offer its employees in the United States affordable college degrees.

The partnership with American Public University, a for-profit school with about 70,000 online students, will allow some Wal-Mart and Sam’s Club employees to earn credits in areas like retail management and logistics for performing their regular jobs.

“It came out of an awareness that the jobs in our stores are really good jobs,” Tom Mars, executive vice president and chief administrative officer of Wal-Mart U.S. said in an interview, “but if we want to make them great jobs, we really have to do something different to distinguish those jobs and our company from everyone else in retail.”

He added: “We hope in this way to expand the education and employer communities’ knowledge of what works most effectively, so that policy makers, other companies and other stakeholders can continuously improve such offerings.”

Jul 2007:  The Open University

Second the ultimate customer for the project, will have to be heavily involved in the process. For example Boeing needs Aeronautical Engineers. To really get the type of engineer that they want they would need to lay out a set of skills that they feel are important. From there it would be necessary to backtrack to the courses which develop those skills, and a curriculum would need to be developed. From there textbooks would need to be written and labs developed. On and on continuing up the chain until a comprehensive program had been developed.

Wal-Mart, as is their want, has simplified the process a bit by finding a program that fits their needs rather than starting from the ground up but the underlying premise is the same.  It would be better if the cost was reduced a bit more, but that could be coming:  Wal-Mart has a tradition of driving costs down.

I anxiously await the various unions denouncement of the naked exploitation of the worker.

h/t: Memeorandum

Saturday, July 28, 2007

The Open University

One of the nice things about having zero readership is I can float ideas that other people might be afraid to because of fear of ridicule. This is one of those ideas-

One of the major complaints of businesses in this country is a growing lack of qualified college graduates. One of the major complaints of students is lack of opportunity (defined as too expensive, lack of access, insufficient preparation etc.) Other groups have similar complaints but what it boils down to is a breakdown in the higher education delivery system. The sad thing is there is no reason for this breakdown to be occurring.

This moment in time allows us access to the greatest knowledge transfer mechanisms that have ever been developed. The computer and the internet. We just are not utilizing them properly. Well in my opinion that's the case anyway.

To simplify this post I am just going to talk about the goal of delivering a qualified graduate to a consumer, no matter who they are.

First we have to accept that my proposed model won't work in every case. It will be up to the consumer to define their needs and sometimes that may mandate a more traditional college program.

Second the ultimate customer for the project, will have to be heavily involved in the process. For example Boeing needs Aeronautical Engineers. To really get the type of engineer that they want they would need to lay out a set of skills that they feel are important. From there it would be necessary to backtrack to the courses which develop those skills, and a curriculum would need to be developed. From there textbooks would need to be written and labs developed. On and on continuing up the chain until a comprehensive program had been developed.

Once that process has been completed it is necessary to deliver the required knowledge to the student. Most of the pieces are already in place. Lectures can be developed and delivered via pod cast or youtube (The open courseware project and iTunes university are already doing some of this). Reading assignments can be emailed out. Textbooks and other course materials can be placed on Wikibooks. The two major sticking points as I see it are labs and a feedback mechanism.

Feedback is the easiest - IM, Email, Phones, Blog Comments, all those offer a feedback loop. Testing is another method. Here we have to be careful though. We want the test to be both fair and applicable as well relatively secure. In other words we don't want a bunch of multiple choice questions floating around on the internet that a student can memorize to get a passing grade, but we want the test to really measure knowledge. Part of this problem can be solved by the use of adaptive testing.

Adaptive testing is a method of testing that adapts to an examinees knowledge level of a subject.

CAT successively selects questions so as to maximize the precision of the exam based on what is known about the examinee from previous questions.[1] From the examinee's perspective, the difficulty of the exam seems to tailor itself to their level of ability. For example, if an examinee performs well on an item of intermediate difficulty, he will then be presented with a more difficult question. Or, if he performed poorly, he would be presented with a simpler question. Compared to static multiple choice tests that nearly everyone has experienced, with a fixed set of items administered to all examinees, computer-adaptive tests require fewer test items to arrive at equally accurate scores.[1] (Of course, there is nothing about the CAT methodology that requires the items to be multiple-choice; but just as most exams are multiple-choice, most CAT exams also use this format.)


The biggest problem with adaptive testing in this program would be the development of the question pool. One of it's biggest advantages is it's flexibility, allowing a number of different question types including scenario and simulation questions. In addition the report from the exam can be used to pinpoint where a student has mastery or requires work in a subject. One nice thing about this style of testing is the flexibility it places into the program. A student may already have a high level of mastery in a subject. He would be able to prove that by simply taking the test. As this program goes on this method of testing may be defined to an even greater level of granularity so that certain critical skills are tested for mastery at various points.

Of course adaptive testing will not work for all subjects and scenarios so a network of instructors will need to be developed. These can be industry professionals, local educators, retirees, essentially anyone with the required knowledge who can evaluate the work of the student and provide feedback. A quality control mechanism would be needed to insure that the instructors are adequate, but I think that could be handled by evaluations from students, skill set feedback from employers, and evaluations from other instructors or administrators involved in this program.

On the subject of practical exams, labs, and hands on instructions we would use the same local instructors or partnerships with local businesses. For classes such as chemistry it may be necessary to set up a partnership with a local high school or community college. In these cases the students will have to bear some additional cost. In some cases it may be necessary to set up a regional center where a student can come do a block of labs over a weekend again this may require some additional cost. In all these cases participating industry partners should also help with some of the expense. After all the idea is to deliver a more prepared graduate to them.

After completion of this program the student is awarded a certificate that includes the sponsors of his degree track and a breakdown of the didactic and practical skills he has demonstrated mastery of and is off into the world. Hopefully with the goal of delivering relevant, affordable, and convenient education having been met.

One other option that I think would be interesting is if major state universities partnered with this program. That would simplify many of the start up pains and would also give them the opportunity to cherry pick out the best students for an "elite" education.

Anyway just another idea that will never be adopted.

, , , ,

Thursday, November 01, 2007

University of Delaware ends it's indoctrination program. All Whites No Longer Racists By University Fiat

Once again the awesome power of Kuru Lounge has been brought to bear and the malefactors surrender in trembling fear.

OK, may be FIRE had a little bit to do with it.

I'm just glad to know that I am no longer a Racist by definition.

Oh Wait... The University didn't actually say that. They said:

While I believe that recent press accounts misrepresent the purpose of the residential life program at the University of Delaware, there are questions about its practices that must be addressed and there are reasons for concern that the actual purpose is not being fulfilled. It is not feasible to evaluate these issues without a full and broad-based review.


I'm not quite sure how you misrepresent a quote like this though:

"A RACIST: A racist is one who is both privileged and socialized on the basis of race by a white supremacist (racist) system. 'The term applies to all white people (i.e., people of European descent) living in the United States, regardless of class, gender, religion, culture or sexuality. By this definition, people of color cannot be racists, because as peoples within the U.S. system, they do not have the power to back up their prejudices, hostilities, or acts of discrimination."


That doesn't seem to leave much open for interpretation.

,

Thursday, May 14, 2020

What I'm Reading 5/14/2020 - Tesla Making A Power Move and Huawei Is In Trouble Again

NBC - Current and ex-employees allege Google drastically rolled back diversity and inclusion programs -

Since 2018, internal diversity and inclusion training programs have been scaled back or cut entirely, four Google employees and two people who recently left the company told NBC News in interviews. In addition, they said, the team responsible for those programs has been reduced in size, and positions previously held by full-time employees have been outsourced or not refilled after members of the diversity teams left the company.

One well-liked diversity training program at Google called Sojourn, a comprehensive racial justice program created for employees to learn about implicit bias and how to navigate conversations about race and inequality, was cut entirely, according to seven former and current employees. Sojourn offered its last training to Google workers in 2018, four current employees said, and by 2019 it was cut completely.

The county said the automaker could take additional steps ahead of next week after Chief Executive Elon Musk had vowed to defy authorities, saying Monday he was resuming production despite the prohibition. On Tuesday, he also won the backing of President Donald Trump.

In a tweet, Alameda County said that following talks with Tesla it agreed that the electric carmaker can take steps “in preparation for possible reopening as soon as next week.”  

Electric car maker Tesla Inc (TSLA.O) plans to introduce a new low-cost, long-life battery in its Model 3 sedan in China later this year or early next that it expects will bring the cost of electric vehicles in line with gasoline models, and allow EV batteries to have second and third lives in the electric power grid. 
...

With a global fleet of more than 1 million electric vehicles that are capable of connecting to and sharing power with the grid, Tesla’s goal is to achieve the status of a power company, competing with such traditional energy providers as Pacific Gas & Electric (PCG_pa.A) and Tokyo Electric Power (9501.T), those sources said.

The new “million mile” battery at the center of Tesla’s strategy was jointly developed with China’s Contemporary Amperex Technology Ltd (CATL) (300750.SZ) and deploys technology developed by Tesla in collaboration with a team of academic battery experts recruited by Musk, three people familiar with the effort said.  

 
Support for the DNS-over-HTTPS protocol has landed this week in Windows Insiders, Microsoft's experimental version of Windows, where the company tests new features before making them broadly available.
...
By developing a DoH client, Microsoft is bringing this control at the OS level again. This move benefits both system administrators of large corporate networks, but also home consumers, who will be able to benefit from DoH's increased privacy even for apps that don't natively support DoH (as Chrome and Firefox do now).
Social networks and other online content providers will have to remove paedophile and terrorism-related content from their platforms within the hour or face a fine of up to 4% of their global revenue under a French law voted in on Wednesday.  

Federal agents have arrested a NASA researcher for allegedly failing to disclose ties to Chinese government entities, the Justice Department announced on Tuesday.

University of Arkansas-Fayetteville professor Simon Saw-Teong Ang, 63, was arrested on Friday and charged with wire fraud.

“Ang made false statements and failed to report his outside employment to UA, which enabled Ang to keep his UA job as well as obtain [US government] research funding,” an affidavit in the case reads. According to the DOJ, Ang defrauded NASA and UA “by failing to disclose that he held other positions at a Chinese university and Chinese companies.”

A company that pays hackers to submit serious security vulnerabilities says it’s made aware of so many flaws in various Apple operating systems that it will temporarily stop acquiring new attack techniques.

In a tweet Wednesday, Zerodium said it will stop accepting Apple iOS bugs that lead to “local privilege escalation,” which attackers use to dig deeper into an infected device, remote code execution bugs in the the company’s Safari web browser, or “sandbox escape” tools, which enable attackers to move from an app to other areas of a device.

In the news today, European authorities decided a "CISSP was equivalent to a masters degree". I think this news is garbled. Looking into the details, studying things like "UK NARIK RQF level 11", it seems instead that equivalency isn't with master's "degrees" so much as with post-graduate professional awards and certifications that are common in industry. Even then, it places CISSP at too high a level: it's an entry level certification that doesn't require a college degree, and teaches students only familiarity with buzzwords used in the industry rather than the deeper level of understanding of how things work.

Grsecurity is standing by its report that Huawei surreptitiously implemented the vulnerability in the Linux kernel patch with a hope that it is approved and implemented in the next Linux update. They stated that they were contacted by the Huawei PSIRT who forwarded a mail stating “The patchset is not provided by Huawei official but an individual. And also not used in any Huawei devices.”

Grsecurity stated that it found that HKSP repository owner was a Level 20 Principal Security employee in Huawei. Level 20 is the highest technical level within Huawei and it is not possible for such a high ranking official to publish a code without the knowledge of the parent organization. Further, Grsecurity found that the GitHub commit was backdated examining the contents of https://api.github.com/repos/cloudsec/hksp/events proves the commit was actually written to the repo on Monday after all the hell broke loose.

More notable is the continued widespread use of aging or abandoned open source components, with 91% of the codebases containing components that either were more than four years out of date or had seen no development activity in the last two years.

The most concerning trend in this year’s analysis is the mounting security risk posed by unmanaged open source, with 75% of audited codebases containing open source components with known security vulnerabilities, up from 60% the previous year. Similarly, nearly half (49%) of the codebases contained high-risk vulnerabilities, compared to 40% just 12 months prior.

Let’s look instead what’s less obvious. What follows is a collection of ten simple bit powerful tricks and tips that help you stay organized, keep key tools at your fingertips, turn off some notifications to reduce distractions, and generally have a more productive experience with this app. To learn more about Microsoft Teams, read up on how it differs from Slack, as well as some of the alternatives to these two popular messaging apps.

Friday, May 15, 2020

What I'm Reading 5/15/2020 - A New Cold War With China? (Duh!), Improving The Supply Chain, Patch Cisco and Palo Alto, and More Coronavirus Stuff

NY Post - Leaked data suggests China may have 640,000 coronavirus cases, not 80,000   - 

A leaked database from a Chinese military-run university suggests the country may have at least 640,000 COVID-19 cases — a figure substantially higher than Beijing’s dubious claim that it has seen just 80,000 coronavirus infections.

The virus tracker, compiled by China’s National University of Defense Technology and leaked to Foreign Policy magazine, appears to confirm fears that the nation’s Communist government is hiding the true nature of the outbreak that originated in Wuhan late last year.

Cisco Systems and Palo Alto Networks have fixed similar high-risk authentication bypass vulnerabilities in their network security devices that were caused by an oversight in the implementation of the Kerberos protocol. Man-in-the-middle (MitM) attackers could exploit these weaknesses to get administrative control over the appliances.

The article says Patch Now! Seems like a good suggestion to me.

The PrintDemon article authors finish up with the claim that:

So yes, walk to any unpatched system out there […] and just write Add-PrinterPort -Name c:\windows\system32\[REDACTED] in a PowerShell window. Congratulations! You’ve just given yourself a persistent backdoor on the system.

But we agree with the public assessment of Rapid-7 researcher Brendan Watters, who offered the opinion that the authors of the PrintDemon article have overstated the dangers somewhat.

As Watters points out, “this is not a single command to [a] root backdoor. It is more like several thousand lines of code and some well-timed execution gets you a rooted backdoor.”

...

t’s definitely a bug, and it’s a bad one, but:

  • It’s not really just one line of PowerShell to a “persistent backdoor on the system”.
  • The attacker already needs to be logged in to exploit this hole, so it can’t be abused remotely. 

Many supply chains are not just complex, they're brittle – hardened against certain risks, but vulnerable to shocks from other sources. That statement is true for the physical components of a supply chain as well as the supply chain data that IT security professionals are charged with protecting.

Dark Reading turned to a number of security professionals about what it takes to secure a supply chain.

 1.  Consider both upstream and downstream security.  - 
"A simple, practical step is to start making a list of all the organizations you deal with, either as suppliers, clients, or customers," Erlin says. "Ideally, you should be able to identify and categorize the data to which any of the organizations that you deal with have access."
2.   Make sure contracts identify known breach sources and how to respond to them as well as containing language to specify how to deal with new breach types or sources.

3.  Know your data flows - what data is being given to how and who has access to critical assets

4.  Secure your processes -
 it's important to remember that processes can have security implications, too. "Quite often risks have more to do with operational process, such as storing in an exposed database in the cloud, than it does with a flaw or vulnerability in code," Vectra's Morales says.
5.  Annual Audits - any organization that supplies electronics or has remote access to the company.
(IMHO, This is kind of unrealistic for a lot of companies, but regular audits should be conducted on a schedule that resourcing allows. )

6.  Support smaller supplier - focus on real risks and mitigating controls, communicate clearly, share expertise if appropriate. 

7.  Make things easy for management by grouping risks into buckets  they can understand.

8.  Keep an eye on the cloud -

The cloud problem is exacerbated because software and services tend to be built from existing software, services, and modules, making the stack of "dependencies," or nested code products, 10, 20, or more layers deep. "Much of the cloud infrastructure and SaaS applications consist of assembled components and frequently includes open source products," says Sachin Aggarwal, co-founder and CEO of Accurica explains. "For example, Amazon Web Services uses Linux, Java, Kubernetes, Xen, and KVM as components in their cloud. These provide cost benefits but can introduce security risks, which organizations need to mitigate."

This cloudy risk doesn't end with software and services, Aggarwal points out. "There are unique risks introduced when cloud SaaS applications use third-party APIs as components," he says. "Modern cloud applications integrate with several third-party APIs for purposes such as notification, monitoring, data aggregation, and security analytics." 

Additionally it is very easy for a development team to spin up a new environment without every going thru the hardening process thus leaving data exposed.  See Step 4.  

Researchers reported at least some of the monkeys developed antibodies to the virus within 14 days of being vaccinated, and all of the vaccinated animals had evidence of antibodies within 28 days.

The Oxford University vaccine trial is heading into hospitals amid fears that Covid-19 is not prevalent enough in wider society, a leading scientist has revealed.

John Bell, regius professor of medicine at Oxford University, said more than 1,000 people had been vaccinated in the first phase of the project and that, so far, things were going well and the drug looked safe.

Microsoft has detailed how it's changed Windows 10 to wipe out a class of memory bugs called uninitialized memory vulnerabilities using a new security feature that has plagued users of games that employ anti-cheat software.    

Microsoft has been experimenting with Rust for certain Windows components written in C and C++ to weed out memory-related bugs, which make up about 70% of all patches Microsoft has shipped over the past decade.

In a short message posted on its website, the company said the incident only impacted its internal IT network and employee laptops.

The company's email server was also impacted and had been taken down, cutting employees off from crucial communications.

Systems that managed the UK's electricity transit were unaffected, according to Elexon.

Neal Stephenson’s 1992 novel, Snow Crash, is often considered one of the most idiosyncratic and enjoyable cyberpunk fictions ever produced. Its inventive world, tongue-in-cheek humor, and eerily accurate predictions of the information age have made it one of the most renowned American sci-fi novels of the last 30 years. Fans of the book and cyberpunk should be happy to hear that the novel is currently being adapted for a series on HBO Max.

 At the direction of the White House, the Department of Homeland Security has sent recommendations for further restricting legal immigration during the COVID-19 pandemic, according to one former and two current administration officials.

Among the recommendations expected to be considered is the suspension of a program for foreign students to stay in the U.S. to get one or two years of occupational training between secondary education and full-time employment, a move many in the business and university communities are fighting.

How does a Cold War begin? In Washington, an accumulation of anti-Beijing animus hangs like a dark cloud over the capital. Before the pandemic, there was no shortage of experts warning of emergent fault lines between the United States and China. That sense of a looming clash between the 21st century’s heavyweights has only accelerated since the novel coronavirus paralyzed much of the world.

In an interview aired Thursday morning by the right-wing Fox Business Network, President Trump floated the idea that the United States “could cut off the whole relationship” with China in the aftermath of the pandemic, in reference to discussions over the lingering trade differences between both countries. He also argued that the economic toll of the pandemic offered further proof that the United States needed to do more to disconnect itself from global supply chains that thread through China.

China's foreign ministry said on Friday that steady Sino-U.S. bilateral relations serve the interests of both people, responding to U.S. President Donald Trump's comments that he could cut ties with the world's second-largest economy.

The U.S. Commerce Department said it was amending an export rule to “strategically target Huawei’s acquisition of semiconductors that are the direct product of certain U.S. software and technology.”

Reuters first reported the news ahead of the department’s release. The department said its “announcement cuts off Huawei’s efforts to undermine U.S. export controls.” 

The measures include launching investigations and imposing restrictions on U.S. companies such as Apple Inc, Cisco Systems Inc, Qualcomm Inc as well as suspending purchase of Boeing Co airplanes, the report said here citing a source. 
Hackers believed to be operating in the interests of the Chinese government have targeted the air-gapped networks of the Taiwanese and the Philippine military.
...

The malware would infect a system with fewer security protections, then wait for a USB device to be connected, infect the device, and wait to be ferried to other parts of a victim's internal network.

On the new device, USBferry would collect sensitive documents inside the USB device's internal storage, and wait until it was ferried back to another internet-connected device, where it would send the data back to Tropic Trooper's command and control servers.

Interest in antibody tests from employers has fallen in recent weeks as reports have suggested that it is too early to conclude that antibodies to the new coronavirus translate into immunity. The American Medical Association cautioned on Thursday that these tests do not determine an individual’s immunity.

“Many employers ... are realizing that antibody testing isn’t going to be a silver bullet and really isn’t going to bring them any value,” said David Zeig, a lead consultant on clinical services at Mercer. 


Thursday, March 14, 2013

So you know how you can tell your opinion is worth nothing

When you write about an idea, get completely ignored and then a couple years later someone has a break through in thinking and has this amazing idea which is the same one you wrote about so long ago.

Example:
http://pjmedia.com/instapundit/164954/

and my idea proposed back in 2007

http://kurulounge.blogspot.com/2007/07/open-university.html

Monday, August 11, 2014

My Reading List 8/11/2014 - Complex P@$$w0rd$ Suck

Wired - Turns Out Your Complex Passwords Aren’t That Much Safer -
pinning your security on an insanely complex password is a fool’s wager. Just ask the people running the airline, travel and social networking sites that got hacked by Alex Holden’s Russian hackers. “Why are we burdening users with demands to chose stronger and stronger things with the goal of withstanding increasingly sophisticated guessing attacks when 1.2 billion credentials are just spewed from servers that are improperly protected,” says Herley. “That seems like a big waste of effort.”
Any system can be broken.  I believe the proper question is how do you mitigate damage when it is.

The Next Web - Google is backing a new $300 million high-speed internet Trans-Pacific cable system between the US and Japan -
The new cable system will be landed at Chikura and Shima in Japan, but will also feature connectivity to many neighboring cable systems so as to extend the capacity beyond Japan to other Asian countries. Connections in the US will extend the system to major West Coast hubs including the Los Angeles, San Francisco, Portland and Seattle areas.
How about just getting fiber to my door step?  Just saying.

Techcrunch - Gradberry Aims To Bridge The College Grad Skills Gap -
Gradberry works with graduates and employers. The site has jobs listings and courses, so students can take courses to fill in the gaps in order to land a position, or they can be hired and their employer will sponsor them to take a course to learn a required skill for the job. Masood says the majority of its revenue today comes from the latter. The way it works is that a company hires a recent graduate who looks promising, but lacks a requisite skill. For example, a marketing graduate could lack training in social media marketing. They take the online course, get a certificate and they should be better prepared for the job at hand.
Interesting concept.  Udacity is already doing something similar by working with employers to develop courses, and I had a similar idea, at least similar in getting employer input on required skills, a few years ago when I wrote up my plan for "The Open University".  

Gizmodo - 18 High-Tech Warships From the Future That Rule the Seas Today -

Mankind has fought naval battles for thousands of years. And in the 21st century, the navy is still the most important branch of any maritime nation's combat forces. But technology does change, and if you don't live near a navy harbor, there's a chance you've missed all the newest ships being built and launched in the past few years.

The following set of photos will introduce to you the latest, most advanced, sometimes surprisingly futuristic vessels from the largest navies of the world.
From 1800 to the 1920s, inequality increased more than a hundredfold. Then came the reversal: from the 1920s to 1980, it shrank back to levels not seen since the mid-19th century. Over that time, the top fortunes hardly grew (from one to two billion dollars; a decline in real terms). Yet the wealth of a typical family increased by a multiple of 40. From 1980 to the present, the wealth gap has been on another steep, if erratic, rise. Commentators have called the period from 1920s to 1970s the ‘great compression’. The past 30 years are known as the ‘great divergence’. Bring the 19th century into the picture, however, and one sees not isolated movements so much as a rhythm. In other words, when looked at over a long period, the development of wealth inequality in the US appears to be cyclical. And if it’s cyclical, we can predict what happens next.
 An obvious objection presents itself at this point. Does observing just one and a half cycles really show that there is a regular pattern in the dynamics of inequality? No, by itself it doesn’t. But this is where looking at other historical societies becomes interesting. In our book Secular Cycles (2009), Sergey Nefedov and I applied the Phillips approach to England, France and Russia throughout both the medieval and early modern periods, and also to ancient Rome. All of these societies (and others for which information was patchier) went through recurring ‘secular’ cycles, which is to say, very long ones. Over periods of two to three centuries, we found repeated back-and-forth swings in demographic, economic, social, and political structures. And the cycles of inequality were an integral part of the overall motion.
Obviously I don't agree with the articles conclusions, but the argument is fairly well reasoned.


Thursday, March 07, 2013

The Country That Stopped Reading and Other Stuff 3/7/2013

NY Times - The Country That Stopped Reading

 Nowadays more children attend school than ever before, but they learn much less. They learn almost nothing. The proportion of the Xxxxxxx  population that is literate is going up, but in absolute numbers, there are more illiterate people in Xxxxxx now than there were 12 years ago. Even if baseline literacy, the ability to read a street sign or news bulletin, is rising, the practice of reading an actual book is not. Once a reasonably well-educated country, Xxxxxx took the penultimate spot, out of 108 countries, in a Unesco assessment of reading habits a few years ago.

One cannot help but ask the Xxxxxxx educational system, “How is it possible that I hand over a child for six hours every day, five days a week, and you give me back someone who is basically illiterate?”
Guess the country - and no it's not America.  

Read further and you find what the author considers to be the source of the problem described above- Teachers protected by a corrupt union.

Now if I were an education reformer (or a GOP congressman / Senator / President) and I was bumping up against the teacher unions I would think seriously about sending out copies of this article to every parent an elected official in the district with the tagline of "This is why it is dangerous to just give teachers jobs for life with no accountability", but that's me.

http://www.nytimes.com/2013/03/06/opinion/the-country-that-stopped-reading.html?_r=0    

Instapundit - links to an article arguing that there isn't a higher education bubble.  It's a weak argument but it got me thinking about whether there is a higher education bubble.

The bubble argument as it is usually presented bothers me because it always seems to lead to the conclusion that a post secondary education is not needed (usually made by someone with an advanced degree) as someone who has gone through most of his life with just a high school diploma let me tell you, that is crap.  Yes you can find work and often become successful without a college degree but it is much harder and when the axe drops it's always the "uneducated" who are first in line to be shown the door.  

Is that right or fair?  Probably not but it is reality just like it was reality in the era immediately after WWII when suddenly the high school diploma was the piece of paper everyone needed to have.  Times change, and in fact it is speculated that one of the causes of bubbles is a change in societal norms.  The need for a high school diploma was largely driven by the development of an urban industrial workforce, now we are in a post industrial society.  

All that being said it's possible we are in a bubble, defined as trade in high volumes at prices that are considerably at variance with intrinsic value and I am not really arguing that point just the conclusions and plans of action that some are drawing from it.

What the bubble argument as advanced by most people says is that the cost of college is now so high that there is no way to earn back your investment therefore you should avoid college.  My argument is that the people making this argument are arguing from the specific to the general:  They concentrate on private schools and majors like Women's Studies in Pre-Revolutionary French Literature. As an example at the state schools nearest me University of Washington and Washington State University -Vancouver the cost for a degree ranges somewhere between $11,000 and $15,000.  While this is a significant amount of debt it is hardly unsustainable for someone who has chosen their degree wisely, i.e an Electrical Engineering major or Biochemistry or Pharmacolgy, but you get the point.

That brings us to another point in this debate, why are people choosing the wrong degrees.  Well some of it is because when you are 19 and you just read Madame Bovary in the original French and found it to be a life changing experience a degree in French Literature looks like a good idea and part of it is that people were incentivized too.  I linked to a paper by the Economic Policy Institute the other day that made this point using the government's policy papers:

 The H-1B-caused internal brain drain was actually anticipated, if not actually planned, in the government’s central science agency back in 1989. The Policy Research and Analysis (PRA) division of the National Science Foundation (NSF) complained that Ph.D. salaries were too high. In an unpublished report, PRA proposed a remedy in the form of importing a large number of foreign students, stating:
These salary data show that real Ph.D.-level pay began to rise after 1982, moving from $52,000 to $64,000 in 1987 (measured in 1984 dollars). One set of salary projections show that real pay will reach $75,000 in 1996 and approach $100,000 shortly beyond the year 2000. …
[To] the extent that increases in foreign student enrollments in doctoral programs decline or turn negative for reasons other than state or national policies it may be in the national interest to actively encourage foreign students. …
A growing influx of foreign Ph.D.s into U.S. labor markets will hold down the level of Ph.D. salaries. …[The Americans] will select alternative career paths…by choosing to acquire a “professional” degree in business or law, or by switching into management as rapidly as possible after gaining employment in private industry…[as] the effective premium for acquiring a Ph.D. may actually be negative. (Weinstein 1998; emphasis added)

I sent the link and the quote to Instapundit, but either it was lost in the crush of what I am sure is a huge load of emails or ignored.

TL;DR - Chad rambled a whole lot making the point that there is still value in higher education and that while some fields may be in a bubble many are not.  

http://pjmedia.com/instapundit/164544/

The HillHouse bill would require police to obtain search warrant to access emails

Normally I find Zoe Lofgren to be a dink but I agree with this.

http://thehill.com/blogs/hillicon-valley/technology/286599-house-bill-would-require-police-to-obtain-a-warrant-to-search-emails

Gigaom - Coursera credentials today, full Coursera-powered degrees tomorrow?

Of course at some point someone is going to offer a degree powered entirely by massive online open courses the question is just who and when?  I keep telling Western Governor's University to get in front of this but as in so many thing I am being ignored.  

http://gigaom.com/2013/03/06/coursera-credentials-today-full-coursera-powered-degrees-tomorrow/




Tuesday, March 17, 2020

What I'm Reading 3/17/2020 - It's All Coronavirus Economics and Ransomware Today Folks

Books -



Blogs / News -

Al Jazeera - US says 'foreign' cyberattack aimed at sowing coronavirus fears -
 The Trump administration is alleging that a foreign disinformation campaign is under way aimed at spreading fear in the country amid the coronavirus pandemic, United States officials told The Associated Press news agency on Monday.
The United States Department of Health and Human Services suffered a cyberattack on Sunday night on the computer systems related to its coronavirus response, and administration officials believe it was part of a deliberate effort by a foreign entity to sow fear among US residents.
 Reuters - U.S. trade body opens patent probe after complaint by Ireland's Neodron -
The U.S. International Trade Commission said on Monday it would open an investigation into possible patent violations involving touch-controlled mobile phones, computers and computer parts by Apple Inc, Amazon.com Inc and a slew of other companies following a complaint filed by Neodron Ltd of Ireland. 
CBC - Canada to bar entry to most travellers who are not citizens or permanent residents -
Canada is barring entry to all travellers who are not Canadian citizens or permanent residents, Prime Minister Justin Trudeau announced today — one of a set of extraordinary new measures being introduced to stop the spread of COVID-19.
There will be exceptions for air crew, diplomats, immediate family members of citizens and, "at this time," U.S. citizens, Trudeau said.
 New York Times - Some Ask a Taboo Question: Is America Overreacting to Coronavirus? -
As an America desperate to stem the coronavirus outbreak put in place sweeping restrictions last week on every facet of public life, the University of Wyoming economist Linda Thunstrom asked what felt like a taboo question: “Are we overreacting?’’
It helped that Dr. Thunstrom was in her kitchen, drinking coffee with her husband, Jason Shogren, a fellow economist who studies how much Americans are willing to pay to reduce risk of threats like terrorism, food-borne illness and climate change.
ZDNet - Most ransomware attacks take place during the night or over the weekend -
The vast majority of ransomware attacks targeting the enterprise sector occur outside normal working hours, during the night or over the weekend.
...
The reason why attackers are choosing to trigger the ransomware encryption process during the night or weekend is because most companies don't have IT staff working those shifts, and if they do, they are most likely short-handed.
NYTimes - America’s Economy Begins to Shut Down as Pandemic Measures Take Hold -
On Wall Street, brokers and analysts were acting as if an economic collapse were inevitable, despite the Federal Reserve’s emergency moves on Sunday night to stoke economic growth through an aggressive bond-buying program. The S&P 500 fell nearly 12 percent on Monday and global oil prices slid below $30 a barrel, the lowest level in more than four years.
Class Central - 190 universities just launched 600 free online courses. Here’s the full list. -
Of interest to anyone reading this blog would be the Computer Science section.  Particularly the selections from the University of Colorado (Cloud Computing Security and DDoS Prevention courses), Cyber-Physical Networks from KTH Royal Institute of Technology, and all the Palo Alto Networks Courses.
The Atlantic - What If Andrew Yang Was Right? -
As the U.S. is scrambling to deal with the forced shuttering of restaurants, bars, theaters, and other businesses, even some fiscally conservative Republicans agree that giving money directly to people might be the best response. Today, Senator Mitt Romney proposed sending every U.S. adult a $1,000 check to help with short-term obligations—rent, groceries, whatever it may be. The idea sounded familiar to followers of the 2020 Democratic primary race, specifically those who have watched the businessman Andrew Yang—who ran an outsider campaign based on what he sees as the need for universal basic income, or UBI.
Sydney Morning Herald - 'As bad as the Great Depression': top economist's warning on coronavirus impact -
"The US economy is already in a recession - there is almost no doubt about that in my mind.
"Aggregate demand is falling off a cliff; we need to bring out an aggregate demand bazooka. We need to get cash into people's hands."
The Great Depression, which lasted from 1929 until the beginning of World War II, saw the unemployment rate hit 25 per cent in countries such as the US.
Wolfers said the US government should deliver cash payments to unemployed and under-employed workers as well as loans to small businesses to help keep them afloat until the outbreak is under control.
 Infosec Institute - Web server protection: Logs and web server security -
Web server logs are obviously only one tool that security professionals can use to attempt to mitigate the risk of attacks and respond when one does occur. While the practice of reviewing logs has evolved as more and more tools have become available to the security professional, ultimately they can only reveal part of the total picture that describes how and a cyberattack occurred, what may have been affected by it and who carried it out.
However, armed with results from manual and automated log reviews, security professionals can trace back IP addresses, identify which security holes were exploited and the types of information probed and possibly stolen so more advanced incident response activities can continue.
Security Boulevard - Why Traditional Security Is Failing Us -
While it may seem counterintuitive, growing reliance on technology is making companies more vulnerable. Both intruders from outside the network, as well as inside threats, are evolving with our defenses as connected devices proliferate and migration of sensitive data assets to the cloud present a lucrative target. With each technological advancement for business, assaults on our computing resources become more sophisticated as we broaden the attack surface.
...
We need to stop playing catch up after the fact, and get ahead of the game and focus on what the bad actors actually want: the data. By understanding how our data flows, creating and enforcing policies that help to govern that flow while protecting the data in a place when it is not flowing should mean that threats to data can be reduced to nearly zero and digital trust can be restored.
Dark Reading - Many Ransomware Attacks Can be Stopped Before They Begin -
By spending time in a victim environment, malicious actors are often able to identify important assets, like backups and network segments storing valuable data and key systems that can be used to disseminate their ransomware widely. "This more effective targeting and deployment gives the threat actors more leverage against a victim, allowing them to demand higher ransoms and net higher profits," Vanderlee says. Post-compromise reconnaissance also provides attackers with additional opportunities for follow-on activity, like data theft for sale or extortion.
At the same time, though, the dwell time between initial compromise and ransomware deployment gives organizations a chance to neutralize the attack before it even has a chance to unfold,
This article is referencing the same Fireeye report that was talked about above.






Sunday, February 27, 2022

this Week's Reading 2/27/2022

 No Ukraine Stuff - outside the scope

These new hacking groups are striking industrial, operational tech targets: Two of the new groups are sophisticated enough to directly reach ICS/OT networks.

https://www.zdnet.com/article/these-new-hacking-groups-are-striking-industrial-operational-tech-targets/#ftag=RSSbaffb68

This machine-learning model can pinpoint failing or hacked power grid components

https://www.theregister.com/2022/02/26/machine_learning_power/

New Flaws Discovered in Cisco's Network Operating System for Switches

https://thehackernews.com/2022/02/new-flaws-discovered-in-ciscos-network.html

The idea that university degrees don’t matter is a Silicon Valley fantasy

https://techcrunch.com/2022/02/25/the-idea-that-university-degrees-dont-matter-is-a-silicon-valley-fantasy/

A New Cybersecurity “Social Contract”

https://www.schneier.com/blog/archives/2022/02/a-new-cybersecurity-social-contract.html

Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks

https://www.cisa.gov/uscert/ncas/alerts/aa22-055a

In studying tech supply chain, feds cite open source products, device firmware

https://www.cyberscoop.com/supply-chain-risk-homeland-security-commerce-report/

Drop the SBOM

https://www.csoonline.com/article/3649794/drop-the-sbom.html#tk.rss_all

GE SCADA Product Vulnerabilities Show Importance of Secure Configurations

https://www.securityweek.com/ge-scada-product-vulnerabilities-show-importance-secure-configurations

Tuesday, September 15, 2020

What I Am Reading 9/15/2020 - Nothing has really changed 3 years after the Equinox hack and The US has Dropped the Ball On Innovation

 Errata Security - Cliché: Security through obscurity (yet again) -

Obscurity has problems, always, even if it's just an additional layer in your "defense in depth". The entire point of the fallacy is to counteract people's instinct to suppress information. The effort has failed. Instead, people have persevered in believing that obscurity is good, and that this entire conversation is only about specific types of obscurity being bad.

Schneier on Security -  The Third Edition of Ross Anderson’s Security Engineering -

Coming in December 2020

IT Security Guru - Study identifies gaps in corporate cybersecurity systems -

A survey of 13,000 remote workers conducted by Trend Micro has discovered that almost 40% are accessing company data from their personal computers, tablets and phones. 

 Threatpost - Office 365 Phishing Attack Leverages Real-Time Active Directory Validation -

In the phishing attack, access to this immediate feedback “allows the attacker to respond intelligently during the attack,” researchers with Armorblox said on Thursday. “The attacker is also immediately aware of a live compromised credential and allows him to potentially ingratiate himself into the compromised account before any remediation.”

Yahoo - Feds ‘Very Concerned’ About AstraZeneca Vaccine Side Effect -

The Food and Drug Administration is weighing whether to follow British regulators in resuming a coronavirus vaccine trial that was halted when a participant suffered spinal cord damage, even as the National Institutes of Health has launched an investigation of the case.

...

A great deal of uncertainty remains about what happened to the unnamed patient, to the frustration of those avidly following the progress of vaccine testing. AstraZeneca, which is running the global trial of the vaccine it produced with Oxford University, said the trial volunteer recovered from a severe inflammation of the spinal cord and is no longer hospitalized.

BBC -  Ex-Google boss Eric Schmidt: US 'dropped the ball' on innovation -

In the battle for tech supremacy between the US and China, America has "dropped the ball" in funding for basic research, according to former Google chief executive Eric Schmidt.

And that's one of the key reasons why China has been able to catch up.

Dr Schmidt, who is currently the Chairman of the National Security Commission on Artificial Intelligence, said he thinks the US is still ahead of China in tech innovation, for now.

 Threatpost - Feds Warn Nation-State Hackers are Actively Exploiting Unpatched Microsoft Exchange, F5, VPN Bugs

The U.S. government is warning that Chinese threat actors have successfully compromised several government and private sector entities in recent months, by exploiting vulnerabilities in F5 BIG-IP devices, Citrix and Pulse Secure VPNs and Microsoft Exchange servers.

Patches are currently available for all these flaws – and in some cases, have been available for over a year – however, the targeted organizations had not yet updated their systems, leaving them vulnerable to compromise, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said in a Monday advisory. CISA claims the attacks were launched by threat actors affiliated with the Chinese Ministry of State Security.

Related - Cyberscoop - Chinese intelligence-linked hackers are exploiting known flaws to target Washington, US says -

Hackers connected to a Chinese intelligence agency have infiltrated U.S. government and the private sector entities in recent months by exploiting a series of common vulnerabilities, the FBI and Department of Homeland Security’s cybersecurity agency announced Monday.

Attackers tied to China’s civilian intelligence and counterintelligence service, the Ministry of State Security (MSS), have been using phishing emails with malicious links to infiltrate victim organizations, according to the alert. By including malicious software in those messages, hackers are exploiting software flaws in commercial technologies and open-source tools, including services with known fixes. F5 Networks’ Big-IP Traffic Management User Interface, Citrix VPN Appliances, Pulse Secure VPN appliances, and Microsoft Exchange Server are among those affected, says the report from the FBI and DHS’ Cybersecurity and Infrastructure Security Agency (CISA).

 Threatpost - Chinese database detailing 2.4 million influential people, their kids, their addresses, and how to press their buttons revealed -

A US academic has revealed the existence of 2.4-million-person database he says is compiled by a Chinese company known to supply intelligence, military, and security agencies. The academic alleges the purpose of the database is enabling overseas influence operations to be conducted against prominent or influential people outside China.

That company is Shenzhen Zhenhua and the academic is Chris Balding, an associate professor at the Fulbright University Vietnam.

Balding and security researcher Robert Potter have co-authored a paper [PDF] claiming the trove is known as the “Overseas Key Information Database” (OKIDB) and that 10 to 20 per cent of it appears not to have come from any public source of information. The co-authors do not rule out hacking as the source of that data, but also say they can find no evidence of such activity.

SC magazine - What’s really changed three years after Equifax breach?   -

“Unfortunately, not much has changed,” said Greg Foss, senior threat researcher from VMware Carbon Black.

The breach led to significant fines and the retirement of Equifax’s chief executive and chief information officer, congressional probes and proposed legislative and regulatory changes. It also saw the credit monitoring company take a huge hit to its reputation.

But even with lessons from the Equifax breach looming large, organizations still are caught flat-footed by similar threats, in part because those threats continue to evolve and proliferate – and attackers are persistent. 

Threatpost - Critical Flaws in 3rd-Party Code Allow Takeover of Industrial Control Systems -

Six critical vulnerabilities have been discovered in a third-party software component powering various industrial systems. Remote, unauthenticated attackers can exploit the flaws to launch various malicious attacks – including deploying ransomware, and shutting down or even taking over critical systems.

The flaws exists in CodeMeter, owned by Wibu-Systems, which is a software management component that’s licensed by many of the top industrial control system (ICS) software vendors, including Rockwell Automation and Siemens. CodeMeter gives these companies tools to bolster security, help with licensing models, and protect against piracy or reverse-engineering.

 

Sunday, June 14, 2009

15 Quick Fixes Make The World Better

That's what the July /August issue of "the Atlantic" offers or at least claims to offer. Some of the fixes are stupid - Redesign the dollar, End the Vice Presidency, and Pay the artists in my opinion, but most deserve some serious consideration.

Among them:

Rent your own home - Require or strongly encourage banks to banks to allow the current resident to remain in recently foreclosed homes as long as they remain current in fair market rent. The goal is to stop an artificial race to the bottom of home prices.

Privatize the seas - Improve fishery management by auctioning off permits that can be used year round instead of having short open seasons. The concept has already been proven in Alaska's halibut fisheries as well as in Australia and New Zealand and a study by the University of California has shown that fisheries privatized in this manner are much less prone to collapse. (Normally I would link to this study rather than accepting the articles word for it but I can't find it. I have heard the results reported on BBC and I believe CNN previously however)

End all taxes except the property tax and End the corporate income tax - Instead of punishing success by taxing it while rewarding people who happend to buy land in the right place at the right time reverse the formula. Only tax property while eliminating the income tax. If taxes are to remain then stop punishing job creators (corporations) and tax those who recieve the benefits. Different takes on the same issue. Both are worth consideration. According to the author of the property tax proposal Milton Friedman was an advocate of such an approach.

I'll let you read the rest of the suggestions for yourself. Amazingly Andrew Sullivan's suggestion for immediate disclosure of Trig Palin's birth records didn't make the cut in this article. Maybe there is hope for the world after all.

Tuesday, December 29, 2015

Dark Web Drug Lords Beware - The Tax Man cometh - What I am reading 12/29/2015

Dark Reading - 15 Cybersecurity Lessons We Should Have Learned From 2015, But Probably Didn't -
11. Manage Privileged Users Better.
Study, after study, after study this year revealed that privileged accounts need to be better managed. It isn't just that the credentials themselves are too weak but sometimes they're poorly monitored, too widely shared, and they're not efficiently revoked when employees leave an organization.
And more like that, basically a recap of the years stories. 

Boing Boing - TPP is a giftwrapped wealth-transfer to China -
Interestingly, this critique comes from a "Hayekian," right-wing proponent of free market capitalism, who says that by going far beyond trade, this "trade agreement" will cripple the economies of all who sign it.
I am a proponent of trade, but these agreements have now moved far beyond that.  This agreement needs to be killed and renegotiated as a straight up trade agreement.  

NY Times - The Tax Sleuth Who Took Down a Drug Lord -
The work had given Mr. Alford what he believed was the answer to a mystery that had confounded investigators for nearly two years: the identity of the mastermind behind the online drug bazaar known as Silk Road — a criminal known only by his screen name, Dread Pirate Roberts.
When Mr. Alford showed up for work that Monday, he had a real name and a location. He assumed the news would be greeted with excitement. Instead, he says, he got the brushoff.
This seems to be a recurring theme from Internet Drug Lords to Mass Shooters to the 9/11 Hijackers.  Someone pops up on the screen for about 15 milliseconds, the cops look at them dismiss them and X number of months later some horrendous crime is committed.   I have ideas on how some of this could be avoided but it would not be popular.

The Daily Dot - The trials and tribulations of America's chief Internet defender -

Long article, but a fairly interesting read.  Pushes a little bit for the adoption of CISA and pimps EINSTEIN, the governments evil electronic overlord, but overall the director of US-CERT comes off as reasonable and not at all the horrible internet eating monster that we all know she is.  (OK that may be a bit of an exaggeration, but as I wander forums that isn't too far off from what I see a lot of times)

TechDirt - Facebook's Zuckerberg: If You Oppose Our International Power Grab, You're An Enemy Of The Poor -
Except a walled garden is exactly what Facebook is building. And pretending the entire country's poor will somehow be left behind if one doesn't support Facebook's vision of the future isn't just misleading, it's obnoxious. Facebook's zero rated ambitions don't operate in a vacuum; countless citizens, companies and organizations have spent years working to bring real Internet access to India's poor every day. Projects like the open source Freedombox, which manages to encourage connection to the actual Internet while simultaneously supporting concepts like encryption:
OK, I am not a Zuckerberg fan but this criticism is completely off base, at least from what I read of freedombox.  As I look at the wiki entry my first though is how in the name of fuck are people supposed to run a "personal server running a free software operating system, with free applications designed to create and preserve personal privacy." when something like 60% of India doesn't have reliable electric power?  The article criticizes the use of existing telecom infrastructure.  What are they supposed to do?  Shit fiber optic cable and piss gigabit switches?  I agree locking people into Facebook's ecosystem is bad, but the solution proposed in the article is laughable at best.

And the US Power Grid is Vulnerable twofer

Milton Security - U.S. Power Grid vulnerable to attack -
Brian Wallace, a security researcher, was recently tracking a group of hackers who had stolen housing information from an unnamed California university, when he made a far more sinister discovery.  Her found that hackers, possible from Iran, had found a way to infiltrate the U.S. power grid, and had stolen information ranging from passwords to engineering plans.  Wallace believes that the information could easily be used to cut the power on U.S neighborhoods.
SANS - Intruders Gains Access to Dam's Industrial Control System, US Power Grid (December 21, 2015)  -
According to the Wall Street Journal, cyber intruders based in Iran managed to gain access to an industrial control system of a flood control dam near New York City. They found an opening through a cellular modem. While the intruders did not take control of the dam, they did look around inside the system. In a related story, intruders also gained access to networks that operate the US power grid and stole passwords and power plant schematics.
-http://hosted.ap.org/dynamic/stories/U/US_INFRASTRUCTURE_POWER_GRID_CYBERATTACKS_ABRIDGED?SITE=AP&SECTION=HOME&TEMPLATE=DEFAULT&CTIME=2015-12-21-03-
26-40

-http://www.theregister.co.uk/2015/12/21/iranian_hackers_target_new_york_dam/-http://www.bbc.com/news/technology-35151492-http://www.scmagazine.com/american-infrastructures-cybervulnerabilities-again-in
-the-spotlight/article/461043/
The thing I love about these articles is how easy everyone assumes it is to just fix it.  It's not.  The grid is something that grew over a long period of time and some of the equipment has been in place for decades.  It isn't just a rip it out and replace it type of thing either.  This is a problem, one that people are aware of and one that people work on everyday but believe me there is no magic solution.