<?xml version="1.0" encoding="UTF-8"?>
<opml version="1.0">
  <head>
    <title>cmdln.net_2007-07-08</title>
    <expansionState>1,2,10,25,26,30,49,53,56,62,68,73,79,82,96,105,117,118,122,132,133,141</expansionState>
  </head>
  <body>
    <outline text="Intro" Offset="00:17"/>
    <outline text="Security Alerts" Offset="01:10">
      <outline text="Talking trojan" Offset="01:29">
        <outline text="http://go.theregister.com/feed/www.theregister.com/2007/07/03/talking_trojan/"/>
        <outline text="Uses Windows text to speech feature to taunt user, explaining it is deleting files"/>
        <outline text="Trojan tries to delete files"/>
        <outline text="Analysis seems to indicate the trojan doesn't execute very well"/>
        <outline text="Spreads via infected web sites and as a trojan file on p2p networks"/>
        <outline text="A throwback to malware written for reputation?"/>
        <outline text="Why else would it act so destructively and taunt the user?"/>
      </outline>
      <outline text="Problems verifying the PoC &quot;Blue Pill&quot; rootkit" Offset="02:58">
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/129818230/20070702-disagreement-surfaces-over-the-state-of-blue-pill-rootkit-development.html"/>
        <outline text="Security research Joanna Rutkowska made claims last year that she could build an undetectable rootkit"/>
        <outline text="Relied on new virtualization technology, particularly AMD's toolkit"/>
        <outline text="Idea is not far fetched, OS typically doesn't know it is being virtualized"/>
        <outline text="Anything at the level of the VM has greater access by definition"/>
        <outline text="Other researchers, developers of a hypervisor rootkit detector, have issued a challenge"/>
        <outline text="Want to test this at Black Hat this year"/>
        <outline text="Rutkowska claims she needs six months with two full time engineers to be ready"/>
        <outline text="Also wants someone to subsidize her development"/>
        <outline text="Left her employer, COSEINC, to found own company"/>
        <outline text="Claims had to start over, reasonable given how IP goes"/>
        <outline text="Challengers are interpreting this as proof she has nothing"/>
        <outline text="Ars thinks this will never be tested"/>
        <outline text="Will she still developer Blue Pill if no one subsidizes it?"/>
      </outline>
    </outline>
    <outline text="News" Offset="06:07">
      <outline text="Intel's strategy for memory hierarchy with multiple cores" Offset="06:21">
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/129630147/cache-mem-many-core.ars"/>
        <outline text="A good explanation of the scaling issues of multiple cores"/>
        <outline text="Points out virtualization can make this worse"/>
        <outline text="Also made worse by Intel's plans of using different kinds of cores">
          <outline text="Heterogenous network on a chip"/>
          <outline text="Would make resource coordination that much harder"/>
          <outline text="Each type has different resource usage patterns"/>
        </outline>
        <outline text="Intel's idea is to use QoS, an older idea, to help ease contention"/>
        <outline text="QoS is just prioritizing different requests differently"/>
        <outline text="QoS tracked at CPU thread level, part of thread state along with some utilization info"/>
        <outline text="OS and VM monitor have to be re-tooled to take full advantage"/>
        <outline text="Responsible for assigning priority, saving QoS data"/>
        <outline text="Hardware unit, dynamic quality monitor, tracks priority usage of resources and adjusts"/>
        <outline text="Discusses in detail how the DQM achieves better memory access for higher priorities"/>
        <outline text="Pretty clever, just seems to re-use existing processing elements and caches, not just data but instruction"/>
        <outline text="Prototype system shows promising improvements but so far only loaded with simple apps"/>
        <outline text="IBM has utilized some of the techniques, Intel is the first to suggest combining all of them"/>
        <outline text="Would only increase programming complexity incrementally"/>
        <outline text="Re-uses what we already know"/>
        <outline text="Does this imply that the improvements are limited?"/>
        <outline text="That is, how well will this really scale, real world?"/>
        <outline text="Is it just a bridging strategy, complementary to RAMP efforts and likely to be superseded?"/>
      </outline>
      <outline text="iPhone hacks" Offset="13:37">
        <outline text="Folks expressing owner override"/>
        <outline text="Phone, network only small part of device's capabilities"/>
        <outline text="Why doesn't Apple allow use without activation?"/>
        <outline text="No response to hacks from Apple">
          <outline text="No press release"/>
          <outline text="No patches"/>
        </outline>
        <outline text="Progress unlocking iPhone">
          <outline text="http://feeds.macworld.com/~r/macworld/all/~3/129971515/index.php"/>
          <outline text="Some background on early efforts"/>
          <outline text="What's most remarkable is how quickly this has gone"/>
          <outline text="Does indicate lock is based on SIM card"/>
          <outline text="Perhaps this means iPhone could be used with another network"/>
        </outline>
        <outline text="DVD Jon unlocks iPhone without activating with AT&amp;T">
          <outline text="http://feeds.feedburner.com/~r/boingboing/iBag/~3/130322432/iphone_dvd_jon_claim.html"/>
          <outline text="Points out a simpler hack, get pre-paid plan then cancel"/>
          <outline text="Jon's hack is Windows only"/>
          <outline text="Still seems to require some implicit knowledge"/>
          <outline text="From comments, reading the source may yield an interpretation of &quot;magic numbers&quot;"/>
        </outline>
        <outline text="Second AT&amp;T-less activation confirmed">
          <outline text="http://feeds.feedburner.com/~r/boingboing/iBag/~3/130546217/iphone_a_second_attl.html"/>
          <outline text="iPhone dev wiki, same as MacWorld article"/>
          <outline text="Relies on &quot;known token&quot; from activated phone"/>
          <outline text="Token believed to contain or be associated with identifying data"/>
        </outline>
        <outline text="Another iPhone hack that exposes more internals">
          <outline text="http://feeds.engadget.com/~r/weblogsinc/engadget/~3/131111251/"/>
          <outline text="iPhoneInterface, a tool for examining internals"/>
          <outline text="Allows changing the phone's file system, running services"/>
          <outline text="Clearly could be used to enable other hacks"/>
          <outline text="At a minimum article suggests copying files to bypass sync"/>
        </outline>
      </outline>
      <outline text="Update on Show Us the Code protest site" Offset="18:32">
        <outline text="http://rss.slashdot.org/~r/slashdot/eqWf/~3/129936983/article.pl"/>
        <outline text="Honestly don't remember this site in the furor over Microsoft's patent claims"/>
        <outline text="Some are drawing slightly off conclusions">
          <outline text="digduality explicitly says his job was never threatened"/>
          <outline text="Also never claims he knows how he was identified to his employer"/>
          <outline text="The Inquirer, however, claims his job was threatened and they spotted his few uploads"/>
          <outline text="This is unfortunate but understandable for those looking to further demonize Microsoft"/>
        </outline>
        <outline text="Did he approach EFF or Public Knowledge or anyone else for help?"/>
        <outline text="Did mention going to Linux vendors, some who have since cut patent deals"/>
        <outline text="Seems like a bit more savvy might have served this better"/>
        <outline text="Should have researched the Forbes journalist"/>
        <outline text="Activism takes more staying power, better knowledge of your rights"/>
        <outline text="Would have also been well served by reading up on bloggers' rights"/>
        <outline text="How did he intend to enforce his original deadline?"/>
        <outline text="Must have a reasonable expectation of effecting change"/>
        <outline text="Not necessarily changing Microsoft, but perhaps reaching someone in USPTO or mobilizing big players in Linux community"/>
      </outline>
      <outline text="Open Knowledge's archive network launches" Offset="22:58">
        <outline text="http://feeds.feedburner.com/~r/boingboing/iBag/~3/130800850/open_knowledge_archi.html"/>
        <outline text="CKAN, Comprehensive Knowledge Archive Network"/>
        <outline text="Similar to CPAN, indexes other open knowledge projects"/>
        <outline text="Open Knowledge is trying to provide other tools, like open source services"/>
        <outline text="KnowledgeForge, mailing lists, wikis and the like specifically to support open knowledge projects"/>
        <outline text="Provide a clear definition of open knowledge--free to use, re-use and distribute"/>
        <outline text="Seem to be defining package, in terms of knowledge, as large, discrete collections"/>
        <outline text="Also seem to view packages as installable in some fashion"/>
        <outline text="FAQ clarifies why this is different from CC discovery tools">
          <outline text="OK doesn't consider &quot;non-commercial&quot; constraint as compatible with &quot;open&quot;"/>
          <outline text="Doesn't mention share-alike, how is it technically any different?"/>
        </outline>
        <outline text="55 packages, so far, not much you can do other than browse the list"/>
        <outline text="Anyone can add a package, like software repositories"/>
        <outline text="Interesting idea of wrapping tools around this"/>
        <outline text="Is this a good idea, though?"/>
        <outline text="With a small list, obvious this is not all inclusive"/>
        <outline text="Does it run the risk of Wikipedia, of users thinking it is more authoritative than it is?"/>
        <outline text="Will providers go along with idea of installable packages?"/>
        <outline text="Where collections are on the web, they may be using secondary means of monetizing, e.g. ads"/>
        <outline text="Re-packaging and allow &quot;installation&quot; may conflict with those trying to expose ads or other offerings"/>
      </outline>
    </outline>
    <outline text="tail -f" Offset="28:13">
      <outline text="UMG response to NYT" Offset="28:32">
        <outline text="http://go.theregister.com/feed/www.theregister.com/2007/07/03/umg_apple_itunes/"/>
        <outline text="Wrote about this on the web site"/>
        <outline text="This confirms that UMG will continue to offer catalog &quot;at will&quot;"/>
      </outline>
      <outline text="SF court gainsaying email right of privacy?" Offset="30:12">
        <outline text="http://news.google.com/news/url?sa=T&amp;ct=us/10-0&amp;fd=R&amp;url=http://www.ktvu.com/news/13635271/detail.html&amp;cid=1117826609&amp;ei=Ja-PRo6jB4f40QGVvK2aDA"/>
        <outline text="Potentially confusing story"/>
        <outline text="Former ruling was in 6th circuit court, story from the 24th"/>
        <outline text="This ruling was made in 9th district court"/>
        <outline text="Article doesn't mention case by name"/>
        <outline text="Does this overturn 6th circuit ruling?"/>
        <outline text="Quotation seems to indicate it is the same case"/>
        <outline text="The 9th circuit ruling seems restricted to addresses, not message content"/>
        <outline text="Does not apparently overturn 6th circuit ruling but not seeing much coverage of this story"/>
      </outline>
    </outline>
    <outline text="Outro" Offset="33:05">
      <outline text="Contact me">
        <outline text="Email to feedback@thecommandline.net"/>
        <outline text="Web site at http://thecommandline.net/"/>
        <outline text="IM to command.line@skype"/>
        <outline text="Listener comment line is 360-252-7284"/>
        <outline text="del.icio.us tag is &quot;for:cmdln&quot;"/>
        <outline text="http://twitter.com/cmdln"/>
      </outline>
      <outline text="I'd like to thank libsyn.com for AAC hosting and Wouter de Bie for MP3 hosting"/>
      <outline text="These notes and the show audio and music are covered by a Creative Commons license">
        <outline text="http://creativecommons.org/licenses/by-nc-sa/3.0/us/"/>
        <outline text="Attribution, non-commercial, share alike"/>
      </outline>
    </outline>
  </body>
</opml>
