<?xml version="1.0" encoding="UTF-8"?>
<opml version="1.0">
  <head>
    <title>cmdln.net_2007-04-15</title>
    <expansionState>0,1,6,9,10,23,32,33,46,60,74,79,83,85,93,99,100,105,110,111,118</expansionState>
  </head>
  <body>
    <outline text="Intro" Offset="00:17">
      <outline text="In this episode">
        <outline text="A long overdue update to Debian is finally release"/>
        <outline text="Debunking the myth of the superhacker"/>
        <outline text="It is linux's turn for a severe and exploitable WiFi flaw"/>
        <outline text="AACS is cracked again"/>
      </outline>
      <outline text="BaltiCon 41">
        <outline text="May 25th-28th"/>
        <outline text="http://balticon.org/"/>
      </outline>
    </outline>
    <outline text="Security Alerts" Offset="02:20">
      <outline text="DNS server flaw" Offset="02:39">
        <outline text="http://go.theregister.com/feed/http://www.theregister.com/2007/04/13/windows_dns_flaw/"/>
        <outline text="Windows specific, not all version vulnerable"/>
        <outline text="Normal DNS traffic is unaffected"/>
        <outline text="This is a problem with Microsoft's RPC interface to their DNS server"/>
        <outline text="Is a typical buffer overrun that takes advantage of DNS running essentially as root"/>
        <outline text="No patch available"/>
        <outline text="The simple workaround is disabling remote access to RPC"/>
        <outline text="Why does Microsoft's server had RPC?"/>
        <outline text="Article doesn't say how many public DNS servers are Microsoft"/>
        <outline text="For large private networks, this may be more of an issue"/>
        <outline text="There are plenty of DNS alternatives out there that may be more secure, certainly don't have RPC"/>
        <outline text="This is like ActiveX, why add more capabilities than are needed?"/>
      </outline>
      <outline text="Linux WiFi flaw" Offset="05:46">
        <outline text="http://www.techworld.com/mobility/news/index.cfm?newsID=8546&amp;pagtype=samechan"/>
        <outline text="http://www.securityfocus.com/bid/23433/discuss"/>
        <outline text="Affects MadWiFi driver, for Atheros chipsets"/>
        <outline text="Example of responsible disclosure and a patch from the driver team is already available"/>
        <outline text="Not all distros have included the patch"/>
        <outline text="When in doubt, patch manually and re-build your kernel"/>
        <outline text="System doesn't have to be on a network but I imagine the transceiver has to at least be on"/>
        <outline text="Discovery of exploit based on Maynor, Ellch fuzzing work on other drivers"/>
      </outline>
    </outline>
    <outline text="News" Offset="08:49">
      <outline text="Debian Etch released" Offset="09:03">
        <outline text="http://www.debian.org/News/2007/20070408"/>
        <outline text="Update to Sarge, too"/>
        <outline text="21 months of development for Etch"/>
        <outline text="New, fully integrated installer"/>
        <outline text="Support for encrypted partitions"/>
        <outline text="Adds security features to APT"/>
        <outline text="Differential update of indices"/>
        <outline text="Brings most of the major packages up to date"/>
        <outline text="Is this too little, too late?"/>
        <outline text="Seems to have been a lot of internecine strife, lately"/>
        <outline text="The features are attractive, but would have been killer a few years ago"/>
        <outline text="May download and find a system to give it a whirl on, was my favorite distribution, though not my first"/>
      </outline>
      <outline text="IBM and another identity offering" Offset="12:51">
        <outline text="http://go.theregister.com/feed/http://www.regdeveloper.co.uk/2007/04/09/ibm_identity_mixer/"/>
        <outline text="Identity mixer, IBM's masking technology"/>
        <outline text="Dick mentioned this in the interview"/>
        <outline text="First code release for the Higgins Trust Framework"/>
        <outline text="http://en.wikipedia.org/wiki/Higgins_trust_framework"/>
        <outline text="Next release will be an identity select, for choosing sources of data"/>
        <outline text="Prototype code, only, not any kind of finished software users can use"/>
        <outline text="There does appear to be a Firefox extension available"/>
        <outline text="http://wiki.eclipse.org/index.php/Higgins_Browser_Extension"/>
        <outline text="Higgins appears to be complementary with Microsoft's InfoCard"/>
        <outline text="Project lead claims compatibility with MS and OpenID is a high priority"/>
        <outline text="Links to a demo"/>
        <outline text="Warns that the UI and API may be a bit more complex than users expect, justified by capabilities"/>
      </outline>
      <outline text="What does AFP settlement say about Google's stance on copyright?" Offset="17:15">
        <outline text="http://www.pcworld.com/article/id,130498-c,google/article.html"/>
        <outline text="Agence France Presse"/>
        <outline text="This actually seems to touch on some of the same issues as library suit"/>
        <outline text="Google's action enhances discovery and does not substitute for AFP's news stories"/>
        <outline text="Why AFP would want to reduce or eliminate this exposure is a bit mind boggling"/>
        <outline text="Article points out we don't know who caved"/>
        <outline text="Some claim Google is becoming more likely to deal"/>
        <outline text="AFP and some news services do not benefit as much from increased exposure"/>
        <outline text="Rely more on service fees than ad placement"/>
        <outline text="Another expert claims the opposite"/>
        <outline text="Cites similar reasons that I suggest"/>
        <outline text="Also believes Google had a strong defense, if it went to trial"/>
        <outline text="Why would Google settle if it opened them to others seeking payment?"/>
      </outline>
      <outline text="Myth of the superhacker" Offset="20:27">
        <outline text="http://volokh.com/posts/chain_1176127892.shtml"/>
        <outline text="Concerned about invoking superhackers instead of genuine empiricism"/>
        <outline text="Cites some examples in security, privacy and DRM"/>
        <outline text="DRM is different because the myth is used by both sides"/>
        <outline text="Explains why claims about super hackers are exaggerated">
          <outline text="Statements are so hyperbolic they are self disproving"/>
          <outline text="Experience suggests more common users committing cybercrimes"/>
          <outline text="Studies and statistics belie the myths"/>
        </outline>
        <outline text="Discusses harms from legislative reaction to myth">
          <outline text="Overboard laws, can make simple activities into felonies"/>
          <outline text="Infringements of civil liberties">
            <outline text="Law enforcers feel the need in order to find these hackers"/>
            <outline text="Silly to assume all criminals are equally sophisticated"/>
          </outline>
          <outline text="Guilt by association"/>
          <outline text="Wasted investigative resources"/>
          <outline text="Wasted economic resources"/>
        </outline>
        <outline text="Concludes with failure of expertise"/>
        <outline text="Curious as to why security experts not as interested in stats and probabilities"/>
        <outline text="Four possible explanations">
          <outline text="Pervasive secrecy, think trade secret and abuse of IP law"/>
          <outline text="Role of expert is dilute, too easy to attain"/>
          <outline text="Self interest, using myth as a stalking horse for other ends"/>
          <outline text="Need for more cooperation across disciplines, too much not my problem going on from IT to criminalist to others"/>
        </outline>
        <outline text="Single recommendation, better data, substantiate claims, be empirical"/>
      </outline>
    </outline>
    <outline text="tail -f" Offset="25:44">
      <outline text="AACS vulnerable despite patches" Offset="26:03">
        <outline text="http://go.theregister.com/feed/http://www.reghardware.co.uk/2007/04/10/aacs_hold_exposed/"/>
        <outline text="Uses Xbox 360's drive with no modification to recover volume IDs"/>
        <outline text="Does not authorize volume keys, so bypasses their revocation"/>
        <outline text="Doesn't necessarily help copying but allows playback of copied titles"/>
      </outline>
      <outline text="BT prefers adding bandwidth to tiered service" Offset="28:42">
        <outline text="http://techdirt.com/articles/20070413/011103.shtml"/>
        <outline text="Good to hear a carrier admit this"/>
        <outline text="Enough detail to find the opinion credible"/>
        <outline text="However, critical of FTTx"/>
      </outline>
    </outline>
    <outline text="Outro" Offset="30:09">
      <outline text="Contact me">
        <outline text="Email to feedback@thecommandline.net"/>
        <outline text="Web site at http://thecommandline.net/"/>
        <outline text="IM to command.line@skype"/>
        <outline text="Listener comment line is 360-252-7284"/>
        <outline text="del.icio.us tag is &quot;for:cmdln&quot;"/>
      </outline>
      <outline text="I'd like to thank libsyn.com for AAC hosting and Wouter de Bie for MP3 hosting"/>
      <outline text="These notes and the show audio and music are covered by a Creative Commons license">
        <outline text="http://creativecommons.org/licenses/by-nc-sa/3.0/us/"/>
        <outline text="Attribution, non-commercial, share alike"/>
      </outline>
    </outline>
  </body>
</opml>
