Category Archives: Security

Food Expiration Dates and Bolani

I picked up a jar of Bolani Sweet Jalapeno condiment the other day. Instead of the usual expiration warning found on condiments I noticed the label said no refrigeration necessary and that it “keeps for multiple years” with natural preservatives. It has only Bell Pepper, Jalapeno, Pepper, Vinegar, Sugar and Spice. Impressive. My jar is almost empty after just a few days but it still got me thinking about food security again.

The fact is only baby food and infant formula are required by federal law to have expiration dates. Spoiled food is of course a risk but expiration date stamps seems to appear everywhere now in America. This is echoed by sites like Slashfood when they report ketchup will go bad in just one month! It then suggests that high levels of sugar, often found in ketchup, can help preserve a food. Well, which is it? Something doesn’t smell right.

The obvious first counter-point is that sugar does not preserve food; mold and yeast thrive on sugar. Second, restaurants leave their ketchup out for more than a month. How can the usual hamburger and fry shop offer room temperature condiment without starting riots in the streets? Further explanation comes from Answers.com

My name is mike and i have worked for the FDA for 10 years. Rarely do we have someone die from expired ketchup. Normally we get around 50-100 cases of severe food poisoning a year from this food, but only 2 deaths have been linked to expired ketchup, specifically Heinz, over the past 5 years. Both cases were also linked to tomatoes grown in central California. The best way to prevent this is to throw away any food that expires within the same month being used. However, since the acidic properties of tomatoes that have gone bad work directly against the colon, a half cup of vinegar is highly effective in combating any sickness from the expired food product.

The acidity in tomatoes and vinegar are the preservatives. It perhaps can be said that high levels of salt, alcohol and oil were used traditionally to keep food from going bad. In some cultures the condiment was actually meant as the preservative for the food to which it was added. Condiments basically need no refrigeration; yet it still feels like a surprise to see a condiment label in America with so few ingredients also boast it will not spoil.

The bottom line seems to be that refrigeration of condiments is thought to be useful for flavor, not health, but health is an easier pitch. A look at other countries and cultures that do not depend on refrigeration (temperature control) reveals a lot about our own perceptions of security.

< hr / >

Update: Slashfood expired in 2011.

AOL Axes Slashfood, Its Six-Year-Old Food Blog

Rogue Police Officers Attack DJs in San Francisco

Police raids of parties in San Francisco at the end of 2009 started a series of protests and then legal action by the EFF. The EFF site makes the case that police acted in violation of the law.

San Francisco law currently requires after-hours parties with live DJs to get a permit, and failure of those throwing the party to do so can be punished as a misdemeanor. But DJing an unpermitted party is not a crime, and certainly not one for which one’s laptop could be forfeited and held. EFF brought witnesses from the Halloween party and other events to testify that what happened to our clients was part of a pattern of illegal police practices, including rifling through purses and backpacks to find and seize laptops by people who were not even DJing.

They bust into parties and seize random laptops? This sounds like a story from a war-torn or undeveloped country. Perhaps you have the urge to be angry at the San Francisco police. You and the EFF might be right. Note, however, that the story has been boiled down by the SFBG to the actions of just one or two police officers.

Two undercover enforcers have been at the center of just about every recent case of nightclubs or private parties being raided without warrants and aggressively shut down, their patrons roughed up (see “Fun under siege,” 4/21/09) and their money, booze, and equipment punitively seized “as evidence” (see “Police seize DJs laptops,” 11/24/09) even though few of these raids result in charges being filed in court.

Officer Larry Bertrand of the San Francisco Police Department’s Southern Station and Michelle Ott, an agent with the California Department of Alcoholic Beverage Control, are plainclothes partners who spend their weekends undercover, crashing parties, harassing disfavored nightclubs, brutalizing party-goers, and trying to send the unmistakable message that they’re in charge of San Francisco nightlife. Neither responded to our interview requests.

People often ask me how PCI can work if every QSA comes up with a different interpretation of the requirements. I say take a look around (e.g. try being a DJ at a party in SF). We interpret rules every day everywhere we are. A compliance standard is based on interpretations and the resolution of disagreement — it is all part of the process. One QSA opinion does not spoil the standard, just like one nail that bends does not ruin the bag.

My guess is that other police officers not only disagree with Bertrand and Ott’s tactics but also realize that they are generating a backlash that could change the laws (protect the public) regarding seizure of electronic evidence.

Sudo privilege escalation flaw (CVE-2010-2956)

A CVE note that popped up this morning is linked to sudo versions before 1.7.4p4. The CVE record is not complete yet but apparently sudo fails to restrict user access when using Runas groups with group (-g) command line option. Secunia says it is related to the -u option. Sudo.ws puts it all together and explains it’s the -g with the -u.

Beginning with sudo version 1.7.0 it has been possible to grant permission to run a command using a specified group via sudo -g option (run as group). A flaw exists in the logic that matches Runas groups in the sudoers file when the -u option is also specified (run as user). This flaw results in a positive match for the user specified via -u so long as the group specified via -g is allowed by the sudoers file.

In either case a local user could escalate privileges but only as defined for commands in the sudoers file. Examples of how to test the flaw are conveniently listed by Sudo.ws.

Company tries to fire IT admin for 2 cent loss

Yahoo! News says a firm can’t fire a man charged with a 1.8 cent theft

A German company that fired a man for the theft of 1.8 euro cents (two U.S. cents) worth of electricity had no grounds for sacking him, a court ruled, dismissing the firm’s appeal against his reinstatement.

Network administrator Oliver Beel lost his job after charging his Segway, a two-wheeled electric vehicle, at work in May 2009. After he connected the vehicle to the firm’s power source for 1-1/2 hours, his boss asked him to remove it.

Twelve days later Beel found himself without a job.

They might have had a better chance if they had a policy specifically against charging vehicles. Then some kind of violation could have been claimed. Instead the court highlighted that employees charged cell phones and other devices without penalty.