I am at the 66th IETF and so it is time to ask 'why does WiFi have ad hoc mode?'
As near as I can make out the only use for ad hoc mode in WiFi is to provide a ready means of performing a denial of service attack. If you have a lot of laptops in a small space together running off a common access point (or two) they usually get along pretty well. If you have someone running in ad hoc mode they are chewing up as much bandwidth as the access point.
So the usual pattern at these events is the room fills up, the network gets a little slow. At some point some dweeb decides for whatever reason that the speed of the network is intollerably slow. They start fiddling with their network settings trying to make the thing faster. At some point they ask 'what does ad hoc mode do'. They try it out and in the process cause some folk to loose their connection to the access point.
So then they start to fiddle and they see the ad hoc network being advertised 'what is this' they ask and they try to connect. So now we have two ad hoc networks, then three and four. And each time more of the bandwidth gets gobbled up and more people start to fiddle and the situation gets worse.
Eventually the point is reached when the meeting chair has to ask people to shut down their computers if they are using ad hoc mode before the sheer volume of microwave radiation in the concentrated space starts to slowly cook people from the inside out.
Tuesday, July 11, 2006
Why Does WiFi have Ad Hoc mode?
0
comments
Linkworks:
FARK
del.icio.us
StumbleUpon
reddit
Sunday, July 09, 2006
Clueless dotcom business models
Imagine that you are an investor in a startup planning to spend $4bn to develop an infrastructure. The startup is entering the market over a decade later than the incumbent who gives their product away for free. In this situation the security of your encryption codes should probably not be your first concern.
If there was no GPS system available for civilian use Gallileo would be a fantastic idea: establish a system of global positioning satelites and charge device manufacturers a fee for making use of it.
With GPS in place and the signal being made available for free the only value in Gallileo is either insurance against the US withdrawing service for the system or to provide positioning data that is somehow 'better'.
It may be logical for the European Union to invest $4 billion to ensure that they are not dependent on the US for such a critical infrastructure. It is utterly illogical for me as a private individual to do the same to protect the value of by in car GPS unit.
The value of Gallileo lies in the ability to claim a seat at the negotiating table if there is a realistic possibility of turning the signal off. There is a small probability that the result of the discussion would be a situation where more information was available on Gallileo than GPS but it is not very significant. If this does happen it is most likely to be a temporary annoyance I can live with. There is a much higher probability of either my machine breaking or the Gallileo project folding like Iridium and Telestra.
The investors in Gallileo must know this as well. What is it that we do not know? The only way Gallileo makes sense is if makers of GPS units are required to license the Gallileo technology to sell them in Europe.
0
comments
Linkworks:
FARK
del.icio.us
StumbleUpon
reddit
Saturday, July 08, 2006
XenSource
I have been looking at virtualization as a mechanism for defeating rootkit technology and other types of Trojan for some time.
Microsoft has been working on this type of scheme for some time. It is likely to be the only way to manage the transition from entirely unrestricted consumer O/S to a system where Winnie the Pooh Treehous game cannot insist on having full root privileges to run. One of the open questions has been how to get this technology adopted into the Linux mainstream. The OSS world is great at developing niche technologies to support ultra security for a few. It is much less good than it thinks in deploying state of the art security to the masses.
That is why XenSource is so interesting. Xen is not a full virtual machine implementation, it is a para-virtual machine. Instead of pre-empting instructions at the CPU level this takes place at a different layer in the stack. The architecture ends up looking remarkably like Butler Lampson's security monitors.
0
comments
Linkworks:
FARK
del.icio.us
StumbleUpon
reddit
Thursday, July 06, 2006
Interview in Investors Business Daily
I did an interview with IDB last week, it came out this week.
0
comments
Linkworks:
FARK
del.icio.us
StumbleUpon
reddit
Wednesday, July 05, 2006
NYT on phishing crook
The NYT article on the activities of an 'identity theif' (i.e. a pishing scammer) raises some interesting points:
First Sharma was caught after he bought an ID card printer on a stolen credit card and had it delivered to himself. This strikes me as a pretty rookie mistake. If there is a single transaction that would set off alarm bells it would be the purchase of equipment used to make credit cards.
Most cases if a merchant gets a chargeback on a credit card they just eat it. Cops are not that interested in investigating individual credit card frauds. When the goods bought are clearly tools for financial fraud then heaven and earth will be moved if necessary.
Second, his screen name, sniper5984 was his birthday! Of all the rookie mistakes immaginable that is pretty crass.
Third, probably the most important. It may be true that the cops only catch the stupid criminals but they only need to be stupid once (buying the printer) and smart criminals who associate with stupid criminals put themselves at risk.
That is the reason why organized crime is rare. It is very hard to establish the necessary discipline and critical mass. Organized crime can make real money but the centrifugal forces are always pulling the organization apart. It takes a very strong centripetal force to keep everything pulled together.
It only took one weak link in the chain to bring down Shaddowcrew and Carder planet. Shama's prison sentence of 2 to 4 years is remarkably short for someone who stole $150,000 on their third conviction. He clearly provided a lot of cooperation.
Looking through the backups of carder portal, sniper5984 had a bad reputation even amongst the carders. He was notorious as a 'ripper' (someone who takes money but does not deliver the goods). On one occasion he put out a message asking for 'donations' to a legal fund for a fellow carder 'greywolf' who turned out not to even be in jail (public archive)
0
comments
Linkworks:
FARK
del.icio.us
StumbleUpon
reddit
Tuesday, July 04, 2006
Reliable WiFi boxes, do they exist?
The WiFi is on the fritz again. I just had to switch in the backup box as our latest router begins to show the now familiar symptoms of the WiFi pox. It works well for a while until the WiFi part stops working without notice. After a reboot the box is fine for a while but the time between freezes steadily declines until it needs a reboot every hour.
Lucent, Linksys, Netgear, I have tried all the brands. My older netgear box still works but it is only 802.11b and the firmware does not support VPN passthrough (says it does but it does not work with our checkpoint VPN).
It is quite possible that part of the problem is caused by overheating. The older Netgear device has a nice metal case with plenty of ventilation holes. The new ones are pieces of plastic crap. Nobody seems to make a wireless router that has a built in power supply, they all have those obnoxious mains adapter plug things.
When the Linksys started to die the wireless service just shut down at random intervals. The Netgear has developed a similar but somewhat less critical problem, the DNS proxy shuts down and won't restart. This would not be a problem if there was a way of configuring the built in DHCP server so that it didn't tell machines connecting to it to use it as a DNS proxy. The only options provided are to turn DHCP on or off.
So now I have to turn on my VPN to surf the Internet and K's machine has the Comcast DNS server addresses hard coded. We can both surf the net fine at home but her machine has to be reconfigured to work outside the hose. The geniuses who wrote the Windows WiFi support code did not anticipate the need to store the TCP/IP settings as part of the connection profile.
The answer might be to get two of the new MIMO/pre-N routers which are meant to provide greater coverage in addition to greater bandwidth. I need two since the machines in my office run off an wifi to ethernet bridge. In principle it should be easy to configure any WiFi router to work this way. In practice only a few do it and those that do often don't say. My linksys travel router works that way but I only found out after I had bought it.
Online reviews are pretty useless as they are all of the 'open box, use it for a week, return' variety. The reviews are not long enough to demonstrate the reliability of the hardware.
0
comments
Linkworks:
FARK
del.icio.us
StumbleUpon
reddit
Monday, July 03, 2006
The dangers of explanation
Ted Stevens (R-Alaska) got into trouble describing the Internet recently. Its a good example of why explaining technical issues to lay people is so hard.
The explanation he gives is not completely crazy and the points he is trying to make are somewhat valid. The problem is that he clearly does not understand the technology he is trying to explain.
Even people who do not understand electronics should know that mentioning 'tubes' is an unfortunate choice of language. If I hear the word tube I think of 1930s era valve radios. Vint Cerf or Tim Berners-Lee can get away with that type of analogy, nobody has any doubt about their technical knowledge. The starting assumption for a politician is that their understanding of the technical issues is superficial at best.
Net neutrality is not a technical issue, it is a political and economic issue. If there was a free market in telecommunications services the problem of net neutrality would be solved through the normal processes of competition. The problem with the Internet is that the free market ends roughly a three miles from the consumer's house. The 'last mile' has its name because it is the last mile to get built. We already have a fibre optic high speed Internet capable of providing 100 mb/sec to every house in the country. The problem is that today's last mile is provided by legacy cable and telco hookups. In most communities both are effective local monopolies.
Here in Medford I have a choice of getting my Internet from Verizon or from Comcast. As a result the effective price is $60 either way. To get that $19.99 Verizon DSL deal I have to have a Verizon phone line first. Same deal with the cable hookup, broadband is only cheap if it is bundled with another service.
Stevens makes a more powerful case than he intended. His clumsy analogy illustrates the best argument for not making regulations to require Net Neutrality at this point in time: the regulators do not understand the issues themselves yet.
The obvious rebuttal to this argument is that regulators should understand the issues they are trying to address. If Stevens does not understand the modern world it is time for someone else to carry out the task of legislating for it.
In the long term the outcome is more or less certain. Constituents have votes, corporations do not. Just as the telcos and cable companies ended up being regulated the ISPs will end up regulated if they outrage public decency.
In the short term Net Neutrality will continue to be a messy battle. It is unlikely that the campaign for Net Neutrality will gain fire outside the blogosphere until actual examples of monopoly abuse become more frequent.
The key to winning the battle is to develop technologies that open up the local loop monopoly. WiMax may be the answer. Fix a WiMax transmitter to every tenth utility pole and you have ubiquitous wireless networking.
Another approach would be to develop low cost methods of stringing optical fibre to the house. The raw materials required to make copper cable are vastly more expensive than the raw materials used to make fibre. Copper Coax cable currently costs $100 for 1000' vs $380 for fibre. Fibre optic is the material of choice in the developing world because its scrap value is zero.
Perhaps some cobination of these technologies is the answer.
0
comments
Linkworks:
FARK
del.icio.us
StumbleUpon
reddit
Sunday, July 02, 2006
The US Coastguard says: F*** You
A member of the US coastguard responds to the evil genius post.
FUCK YOU ASS GROW UP
Actually the message was in 32pt Ariel but that is the text of the message. The point is that the message came from a uscg.mil address and it appears to be genuine.
This is an example of a problem a customer once described to be as 'emails too stupid to write'. Email is a powerful medium, an idea can be communicated across the world in less than a second. The problem is that many people put no more than a second's thought into the emails that they write.
The above memo being a case in point. If the person who sent it had realized that what he just sent is an official government communication from the Department of Homeland Security he probably would have thought twice before sending a message which sent to the wrong person could well be a career ending move.
Some people treat email like instant messaging but the recipients don't necessarily share the casual approach of the sender. The end result is that the company or in this case the service looks ill-disciplined and unprofessional.
Various approaches to fixing this have been considered, the latest fashion is for what amounts to an outbound spam filtering service to trap mail with expletives or other evidence of unprofessional conduct. They work about as well as you would expect them to, they reduce the nuisance value but don't stop the occasional atrocity slipping through the net.
I am a skeptic when it comes to user education, people are remarkably hard to educate. In this case though the goal has to be to change people's behavior. If people are writing emails with an Internet chat room mentality that attitude is going to be reflected in the rest of their work as well.
This is where I think Secure Internet Letterhead might help, or at least we should look to see if we can measure an effect. People might be less inclined to write unprofessional emails if they thought they were writing on company letterhead. They might even spend less time doing personal email on company time. Perhaps its wishful thinking but it is certainly worth checking.
0
comments
Linkworks:
FARK
del.icio.us
StumbleUpon
reddit
Saturday, July 01, 2006
Evil genius seeks henchmen
Ever wonder how evil Geniuses like Dr No or Ernst Stavro Blofeld hired all those henchmen willing to be shot in the course of their plans for world domination? Wonder no longer, Craigslist!
Evil genius seeks henchmen
--------------------------------------------------------------------------------
Reply to: job-177591484@craigslist.org
Date: 2006-07-01, 10:37PM EDT
Must be expendable, physically fit, follow orders without question and wear uniform (provided). Previous experience with rockets, telecommunications and/or excavating the inside of volcanoes highly desirable.
Job location is various
Compensation: Monthly stipend (negotiable), room, board, ammunition, generous death benefits
yes -- OK for recruiters to contact this job poster.
no -- Please, no phone calls about this job!
no -- Please do not contact job poster about other services, products or commercial interests.
yes -- Reposting this message elsewhere is OK.
OK, I admit that I posted this myself. The point is that real criminals are recruiting people through the Internet to be mules for package reshipping and carding schemes. My post is obviously a spoof, their scams are much easier to fall for.
As with drugs trafficers, mules are expendable. The only difference is that an Internet money mover or package reshipper is certain to be caught. You could almost call it their job description. The carding ring does not want the goods they buy on Amazon with stolen credit card numbers shipped to their own address, too easy to be caught. So they have them sent to a package reshipper who forwards them by freight courier to the type of address Amazon would never ship goods to, like the West Africa or Eastern Europe, often the address is a loading dock of a warehouse.
When the mule gets caught the face a real risk of going to jail. Often the carding rings use the details they collected when they recruited the mule to perform an identity theft, that is taking out large loans in their name. In the case of money movers the transfers of stolen money into their account are fraudulent and are reversed. The transfers of money out of their account were properly authorized though and the banks will demand repayment.
Being an Internet mule is the job from hell: you end up with a tripple whammy of wrecked credit, a huge debt and likely jail time.
Update: We have our first applicant!
Update: Number of applicants is up to 3 in first hour!
0
comments
Linkworks:
FARK
del.icio.us
StumbleUpon
reddit
6th Workshop on Privacy Enhancing Technologies
Adam and EKR have already blogged the paper on evading the great firewall of china, but there is plenty of interesting stuff in the rest of the agenda at the 6th Workshop on Privacy Enhancing Technologies
The firewall paper is likely to create the most interest because it describes the design of the Great Firewall of China and gives some insight into the thinking behind it. I have always thought that the GFC is more a question of face than a real attempt to prevent dangerous Western thoughts in. After all they already have Karl Marx and they don't get more dangerous than that. Besides which there are a billion people inside the firewall and they are the ones who know the information that is really damaging to the regime. They know about the corrupt local bureaucrats, the disasters, the repression. The only way anyone outside the country knows what is going on is that people inside tell them, and that includes the dissidents as well.
EKR discusses how to subvert the GFC by suppressing/ignoring RST signals. These are meant to tell the ends of a TCP/IP conection that the connection is over and there is no need to send additional data. In practice they are kinda redundant since the application protocols are designed so they don't rely on them.
A better way to circumvent the GFC would be to turn on encryption, or at least obfustication. The GFC uses IDS technology to detect sites that contain 'objectionable' strings such as FA-L!U-N+G. As my example shows it does not take a lot of effort to bypass systems of that sort. There are plenty of sites that obfuscate email addresses, why not have an IIS/Apache plug in that filters a site so that keywords known to trigger the GFC get encoded?
Reading between the lines is an old tradition in repressive regimes.
0
comments
Linkworks:
FARK
del.icio.us
StumbleUpon
reddit
