March 2004 Entries

Pigeon Data Transfer Rates Faster Than DSL

So remember a few weeks back when I gave Bill Baxter a hard time about his glacially slow home page, and joked that I could get better throughput using pigeons? Well, umm, turns out pigeon data rates are pretty dang impressive, and in some cases will outperform traditional ADSL service.  Am I allowed a little salt or maybe some tabasco on my crow? I humbly extend my sincere apologies to any pigeon-kind I may have offended with my previous unprovoked and wholly ignorant attack on their capabilities as a data transport infrastructure. But Bill's web site is still slower than molasses in November.  Sorry Bill. ...

Chipotle Mexican Grill

So the fight for burrito dominance in Seattle is continuing to escalate, according to a recent story in the King County Journal.  Seattle-based Taco del Mar currently has the most stores in the area, with 70.  Second place goes to Qdoba, with 10, and Baja Fresh (from OHIO?  WTF?) with 4.  No mention of Acapulco Fresh, oddly, which I happen to like more than any of those (disclaimer:  I have a rule about eating “Mexican“ food from a company based in “Ohio“, so I have not actually patronized a Baja Fresh location).  The most recent entry into the fast Mexican food...

SSH Tunnelling as VPN

Anil John recently started a great thread on doing SSH Tunnelling, which is basically using Secure Shell (SSH) Protocol to encrypt and then forward traffic through ports that are normally unencrypted.  This allows you to run traffic that would normally require blocked or high-risk ports to be opened on the target system's firewall. Anil motivated me to give this a shot at home, since I currently have no VPN or any other way to remotely access my home office network.  Not that I need to, but being able to would be cool!  I haven't had the energy to set up a VPN...

Star Wars Episodes 4-6 Available For Pre-Order

I found out yesterday that Amazon is now taking pre-orders for the new DVD boxed set of Episodes 4-6 of the Star Wars Trilogy (is it still a trilogy if it has 6 movies?).  I do believe that this is the “enhanced“ version that was re-released a few years back. Anyway, Amazon is offering 40% off the retail price if you pre-order now.  They won't ship until sometime in September. Go get one.  You know you want it.

BlueSnarfing at CeBIT 2004

A paper (pdf) was recently published about a field trial conducted at the CeBIT 2004 show in Hannover.  The experiment was aimed at quantifying the exposure of current Bluetooth-enabled devices to BlueSnarfing attacks. Remember what BlueSnarfing is?  Here's a refresher. Up until now, handset manufacturers have considered BlueSnarfing to be a harmless activity.  But I don't want my contacts exposed to strangers, nor do I want them to be able to use my phone to initiate an unauthorized SMS message or a phone call.  It's also possible for BlueSnarfers to overwrite contact information, or even to add entries.  I don't think my wife...

The things that matter

It continues to surprise me, to this day.  You'd think that, as a network security guy writing a blog about mostly network security stuff, my readers would be passionate about security issues, and technology matters.  Yet, by a grand margin, the most popular blog entry on bmonday.com has been... (drum roll please) Eddie Van Halen: #2 Rock Guitarist of all time! That's right folks!  Ahead in all metrics, including direct hits and comments, is my raving about the injustice done to Eddie at the hands of those Beatle-loving wankers at Rolling Stone, and his eventual redemption at the hands of the Seattle...

Jason Nottingham's Blog

Jason dropped me an email to let me know that he's got a blog.  You can find it at http://www.seanet.com/~fulcanelli/  

BSQUARE Alumni Update

Some recent changes to the BSQUARE Alumni Page: Added: Dave Orvis Tom Strange Scott Fintel Todd Olson Updated: Andrew Tucker (Edit:  Added Todd Olson)

Su Casa... Random Sightings

Lately I've been running into a lot of folks at my favorite Mexican eatery in all the world, Su Casa.  While none have topped my Jay Buhner sighting a few months ago, as far as famous personalities are concerned, I have run into a slew of ex-BSQUAREs, and a number of other friends that I knew back in the day and haven't seen in years. Tonight, as my wife and I were finishing dinner, in walked Michael Adcock and John Garnett, one ex-bsquare and the other current.  We had a good time catching up and talking shop.  I really miss the...

Who do we have to bomb to get some cheap gas around here?!??

(Apologies to Fark for jacking their headline, I thought it was perfect) The coalition could completely control Iraq's oil production if it so desired, and yet gasoline prices in America are at an all-time high and we haven't even approached the summer driving months. Are there people still chanting “No blood for oil”?  That's a myth busted, if you ask me. That's all I have to say about that.  Carry on.

BSQUARE Layoffs

Looks like BSQUARE let about another 10 people go today, mostly Maui personnel, including Employee #5.  Efforts to sell the division haven't gone well, I guess.

People are broken

This is one of the most disturbing pictures I've seen in a very long time: The photo, courtesy of Jim Lileks, is from a recent pro-terrorism (I guess) rally in San Francisco.  I won't say anything more because Lileks has pretty much summed it up already.

Alumni Bloggers

I thought it would be useful to start a list of ex-BSQUAREs who have started blogs.  Here are the ones I know of: Steve Makofsky Jeremy Kercheval David Brownell John Hatch Beau Monday (duh!) If you know of other BSQUARE folks writing blogs, please let me know.

BSQUARE Alumni Update

Time for the monthly-ish update of the BSQUARE Alumni Page: Added: Shiney Joseph Updated: John Hatch JT Thomas Kirk Stauffer Mixa Nguyen

Google and the Screening Process

I've been reading a lot about recruiters using Google to screen job applicants lately.  I have to admit to being a little troubled by the process, in all honesty. Google is entirely unregulated, understand.  Through Google, one can discover my political leanings, my marital status, and the fact that I drink copious amounts of Fat Tire.  None of those things would be legal to bring up in an actual job interview, and for good reason.  Yet through Google, recruiters can decide without reprecussion, which candidates fit their moral standard and which do not. I find this practice deeply disturbing. The job I currently...

Math and The Beer Drinker

Quick, what is this formula? Pg = L1   *   R1 + L2   *   R2 + L3   *   R3   +   H   *   0.5 It's the formula to calculate the precise regulator pressure on the CO2 tank in your kegerator.  Duh! The challenge, naturally, is to limit the consumption of the keg's contents until AFTER you have performed the calculations above and set the pressure accordingly. Which is the part I keep forgetting.

The days are a blur

I forgot how much I enjoy what I do for a living.  I'm so heads-down on stuff right now that the days are flying by.  Sometimes I forget to eat.  Which is cool, because I could stand to skip a few meals :) Some random thoughts for my neglected readership: Why is it that Scheduled Tasks, the built-in facility in Windows 2000 and later for automating the execution of scripts, is itself unscriptable?  No amount of WMI or ADSI scripting can cajole any information whatsoever from the Task Scheduler APIs.  I found a perl script that can sometimes do it, but nobody really...

Certified... still!

I got an email from SANS recently that my GSEC certification was about to expire.  But for $125 or something like that, I could take the current test and re-certify for another 2 years.  I paid the money, but I've been dragging my feet on the test, mostly because the curriculum of the certification has drastically changed since I took the training 2 years ago in San Francisco.  Back then, the GSEC certification was about technology and tools.  Now it tracks closely with the CISSP curriculum, which includes a lot of policy, physical security, and law.  Non-technical stuff. But, well, the GSEC...

Due Diligence vs. SLAs

I had a meeting today with the Data Center folks, who I work very closely with (I'm in charge of security at the Data Center, see).  The topic was “Incident Response”.  Now when someone says “incident” to me, I think “security incident”, but to 99.99999999% of the world, it means simply “something unexpected happened”. Now the data center folks have a job to do:  Get the system(s) back online as quickly as possible.  If a system is down for more than 5 minutes, it triggers a slew of customer alerts and sundry other things.  This, among many other things, the DC team...

Parting shot: Local News Sucks

So before I hit the sack, I was trying to find out what happened to the girl who was kidnapped today in our area and triggered an Amber Alert.  The Amber Alert stuck in my head because it's the only time in 6 years the sign above I90 in Eastgate has said anything other than “No Flammable Materials Allowed in I-90 Tunnels“. First I tried the websites of our two(?) local papers, Seattle P-I and the Seattle Times.  Neither one of them mention anything, and instead run the same freaking stories I read in the PAPER while I was eating dinner...

Bill and Liz Baxter's Home Page

A couple people have been asking me about Bill's email address and stuff.  I haven't heard from Bill personally, and don't really expect to, but I think he wouldn't mind if I pointed folks at his web site where they can find out how to get in contact with him (or Liz!). The site is slow as mollases in January though.  Someone tell Bill about “broadband” when they see him next?  The guy could afford to launch his own satellite for crying out loud, and he's limping along on CDPD or something at the house.  Seriously Bill, I could pass more data...

Yeah, I know, I've been quiet

I've been abnormally quiet lately, I know.  It's disturbing to me too, trust me. I started my new security gig this week, and I've been frantically trying to come up to speed on the security posture and countermeasures before something goes horribly wrong.  Luckily everything is redundant, so even if we lose a firewall, the backup steps in and takes over.  Same with the load balancers, the switches, everything.  It's actually a pretty nice data center, and very tightly secured.  You have to have a cardkey to get into the bathrooms.  Seriously. Thankfully the previous security officer left a ton of documentation...

Lord of The Rings News

Couple tidbits about Lord of the Rings: BBC is reporting that Return of the King's theatrical release DVD will ship much earlier than it did for the first 2 installments of the trilogy.  While the first 2 movies were released in the August following their theatrical debut, Return of the King will ship in May.  But I guess we'll still have to wait until late November if we want the extended edition. Peter Jackson has agreed to make The Hobbit!  Jackson will start filming the prequel to the Lord of the Rings trilogy once he finishes with King Kong late next year.  The lawyers...

BSQUARE Alumni Update

A long overdue update has been made to the BSQUARE Alumni Page page: Added:  Edit Marcinkech  Thang Tran Updated:  Mixa Nguyen  Bill Brodd  Bruce Hanson  David Brownell  Beau Monday (*grin*) Sorry for the delays.  As always, you can reach the Alumni page by clicking on “BSQUARE Alumni” in the nav menu on the left, or my RSS readership can click here.

David Brownell Starts A Blog

Steve noted yesterday that ex-BSQUARE colleague David Brownell has started a blog of his own.  Welcome to the blogosphere David! And thanks for your very kind words.  Writing humor has been challenging because it's difficult to add inflection and emphasis to words to make them as funny as the story may be if told verbally.  I'm relieved to know that sometimes it works :)

Best... Spam... Ever!

I got this phishing email in one of my test mailboxes overnight: Your credit card will be billed at $22.95 weekly and free 3 pack of child porn CD is shipping to your billing address. To cancel your membership and CD pack please email full credit card details to dnsadmin@tucows.com Ready to enjoy all types of underage porn? We have the best selection for every taste! Click the secret link below and have fun... www.[obfuscated].com Contact us: http://resellers.tucows.com/contact_service You can order by phone:1- 416-555-5555 (obfuscated) So, in order to avoid getting illegal kiddie porn in the mail, you have to send them...