Category Archives: Security

Alito takes the stand

Three significant issues stand out after the Alito hearings:

1) He clearly does not think the Constitution protects a woman’s choice (the right to choose, as some might call it), and he indicated that Roe v. Wade is not settled law.

2) He clearly believes in an even more powerful executive branch. In fact he supports the notion of a “unitary executive” in order to give the President broad powers that are not subject to control by Congress. And he even refused to rule out the right of the President, with the absence of imminent threat, invading another country without first getting congressional authorization.

3) He clearly does not believe Congress has the authority under the Constitution to make laws meant to protect families from harm. Even though the Supreme Court ultimately said he was wrong, Alito stood fast by his opinion in the Rybar case that Congress couldn’t ban machine guns. Incidentally, this has provoked the Brady Center to announce their opposition to Alito, the first candidate that they have ever opposed. I believe they referred to his opinions as “right-wing judicial activism”. Pretty harsh stuff coming from a center named after President Reagan’s Press Secretary. Morerover, Alito stood by his opinion that seriously narrowed the Family and Medical Leave Act. I’m sure we all remember when he said there was no evidence for the notion that women are disadvantaged in the workplace when they are not allowed to take family leave. The Supreme Court trounced all over that one as well. Even Rehnquist said in the majority opinion that Alito’s position relative to women in the workplace defies common sense.

So it looks like if you hate women, like automatic weapons, and think executives should be able to operate without oversight…Alito’s your man.

Go big BlueFuel

After all the hubub this past year about the great advances in Bosch fuel injection technology, it is no surprise to hear about

BLUETEC diesel technology, which will make its U.S. debut this fall on the 2007 Mercedes E 320 sedan. DaimlerChrysler says BLUETEC is so clean it can meet emissions regulations in all 50 states, including the five states where diesels aren’t currently sold because they can’t meet emissions standards: California, Massachusetts, Maine, New York and Vermont.

That’s encouraging, but of course Mercedes has some of the most advanced diesel engineering in the world. This isn’t your grandma’s grumbling, smelly clunker, we’re talking about. Personally, I’m curious whether the 2.5L V6 turbo-diesel quattro Audi Allroad will finally be imported — talk about the ultimate active-lifestyle high mpg with comfort road-warrior vehicle, it’s almost enough to make you want to move to Canada, eh? Ok, ok, I never said I was good at marketing.

Back to engineering, the article explains…

…diesels are 30 percent more efficient than gas engines, and unlike gas-electric hybrids, which get better fuel economy in city driving, diesels are equally efficient on the highway.

Silent but deadly And diesel-electric hybrid? Even the HumVee is going to DEH (rebranded the Shadow RST-V), according to military.com. They wax poetic about “going green”, but let’s face it, dependence on fuel is a giant security vulnerability issue — the more efficient a vehicle the less risk to soldiers from a supply chain.

Special Forces are about the only group that bother with any real concept of environmental friendliness since it plays to their favor, whereas Army is about mowing down and establishing control, Sherman style, but I digress.

The AP article about the Mercedes and new diesel technology also mentions:

…a big boost this October, when U.S. diesel retailers are required to begin selling low-sulfur diesel. In the past, diesel could have a sulfur level of up to 500 parts per million; low-sulfur diesel has no more than 15 parts per million.

The real question for the future is whether car manufacturers will start allowing pure-veg-oil to run in their vehicles rather than whether someone can improve petro production by reducing a toxic additive. The additive was introduced in the first place to get rid of the inherent shortcomings of petro-diesel versus the bio alternative.

Of course less sulfur is better and should have been forced years ago, but the real solution is to move away from overly centralized distribution and refinement and proprietary assets that have artificially high (protected) value.

When information started being pushed around on workstations and PCs it exploded the processing market. When fuel creation can be localized in a similar fashion then we will really see advances in energy technology and a drop in risk. It’s like the shift from mainframes (petroleum production) to the PC (bio-diesel refinement), which again creates a whole new set of security issues (more resilience, but need for managing decentralized controls).

Security Slogans: Ctrl-Alt-Del when you leave your seat


Few of us are probably lucky enough to invent something as contagious as a Security-Tubby or a Barney character. Instead, we are stuck with the task of creating “fun” posters with slogans.

One of my more successful ones so far has been based on the saying “Ctrl-Alt-Del when you leave your seat”.

People tell me that no matter how rediculous they might find security slogans at first, eventually this one grows on them and they can’t help but sing it aloud when they leave the office. You know you have won over your users when they start to beg for more effective ways to comply with the “Ctrl-Alt-Del song”.

I usually give them a tip like the following:

Although a screen lock button is already provided in most X distros, including Linux, Windows folks are usually in need of a shortcut. They’re simple to create with the following command:

%windir%\system32\rundll32.exe user32.dll,LockWorkStation

Then change the icon to something that looks like a “lock”. The orange key seems most popular among XP users (consistency helps the helpdesk) and can be found in the following library:

%SystemRoot%\system32\shell32.dll

Lock Workstation Icon

Just put the button wherever convenient (desktop, taskbar, start, etc.) Although the setup is easily scripted and deployed over the network, sometimes it is best to hand it out to all your users like a present during the holiday season — “Security wishes you a safe and secure holiday. We hope you enjoy this new button.”

And believe it or not, people who start using this button will still say “hey, I did the Ctrl-Alt-Del thing, go check my screen”, even though they no longer are touching the keyboard when they step away. Ah, the power of security slogans.

loose lipsUnfortunately not all slogans are as catchy. Messages from security easily get lost in the sea of information users have to process every day and most of the other material they hear is so polished that phrases like “don’t get hooked by phishers” tend to blend right into the wallpaper. Thus, I believe the world of security would be far better off if more wordsmiths and poets were employed to craft our message, perhaps even at the state or federal level. Nothing too fancy would be necessary as the slogans that always seem to do best are the simple ones — “loose lips might sink ships”.

Third-highest priority in the FBI

The CSI/FBI have a famous report released annually called the “Computer Crime and Security Survey”. I was surprised to read today that the FBI also has a lesser-known report called the “Computer Crime Survey”.

The difference is supposedly in the method of gathering data, although it’s not clear that either survey is truly scientific. The larger survey is done with a select group of respondants and has a huge number of paper-based questions (I’ve filled it out at least twice), whereas this “Computer Crime only, hold the Security” survey “was taken by 2,066 organizations in Iowa, Nebraska, New York, and Texas”.

The findings are not particularly surprising, and I actually could spend some time trying to debunk the article’s title “FBI says attacks succeeding despite security investments”, but instead I just want to bring attention to the part of the report I found insightful:

While some individual law enforcement officers are not trained to respond to computer security incidents, local, state, and federal law enforcement agencies have become increasingly equipped to both investigate and assist in the prosecution of such violations. Computer related crime is the third-highest priority in the FBI, above public corruption, civil rights, organized crime, white collar crime, major theft and violent crime.

Not hard to find out what the top two priories are:
1. Protect the United States from terrorist attack.
2. Protect the United States against foreign intelligence operations and espionage.

So there you have it. If you are in the US and believe you are a victim of “cyber-based attacks and high-technology crimes”, contact the FBI.