<?xml version="1.0" encoding="UTF-8"?>
<opml version="1.0">
  <head>
    <title>cmdln.net_2007-08-26</title>
    <expansionState>0,1,4,8,9,20,33,34,48,59,71,85,89,94,98,104,105,118,128,132,135,136,144</expansionState>
  </head>
  <body>
    <outline text="Intro" Offset="00:17">
      <outline text="CopyNight on Tuesday">
        <outline text="I won't be there, packing for DragonCon"/>
        <outline text="Still should check out local CopyNight"/>
      </outline>
      <outline text="Dragon*Con 2007">
        <outline text="http://dragoncon.org"/>
        <outline text="No show on 8/29 or 9/2"/>
        <outline text="Maybe a show on 9/5, not sure what"/>
      </outline>
    </outline>
    <outline text="Security Alerts" Offset="02:56">
      <outline text="Debate over XSS flaw with Google hosted apps" Offset="03:15">
        <outline text="http://go.theregister.com/feed/www.theregister.com/2007/08/21/google_modules_security_debate/"/>
        <outline text="Widget hosting domain"/>
        <outline text="Trusted by Google's anti-phishing filter"/>
        <outline text="An XSS flaw, any similar flaw like XSRF, allows exploit"/>
        <outline text="Google's response is that this is not a flaw, despite demo"/>
        <outline text="Researcher's concern goes beyond theft of Google cookies"/>
        <outline text="Phishing has more to do with appearance than reality"/>
        <outline text="Demo appears to legitimately come from gmodules domain"/>
        <outline text="Raises questions of who is responsible when multiple sites, mashup services are involved"/>
        <outline text="Encourages further questions of Google"/>
      </outline>
      <outline text="Trojan breaches Monster" Offset="05:38">
        <outline text="http://go.theregister.com/feed/www.theregister.com/2007/08/21/monster_trojan_steals_millions_of_records/"/>
        <outline text="Requires employer accounts that have already been breached"/>
        <outline text="Trojan doesn't perform breach"/>
        <outline text="Automates extraction of data"/>
        <outline text="Seems to share code with an earlier trojan"/>
        <outline text="Does propagate to stolen accounts, sending copy of binary"/>
        <outline text="1.6 million records estimated to have been stolen"/>
        <outline text="No response from Monster, though Symantec has contacted"/>
        <outline text="Best defense to keep info on such sites to a minimum"/>
        <outline text="Don't open attachments if you are targeted by trojan sending itself onward"/>
        <outline text="This one is tough because this is an essential type of service"/>
        <outline text="Like government database, you cannot reasonably opt out"/>
      </outline>
    </outline>
    <outline text="News" Offset="08:35">
      <outline text="ISP claiming open source, net neutrality as value add" Offset="08:49">
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/145991894/meet-copowi-the-worlds-first-isp-to-guarantee-network-neutrality.ars"/>
        <outline text="Copowi launched a few weeks ago"/>
        <outline text="Possibly a good example of a market response"/>
        <outline text="Do charge more but think customers will be willing to pay"/>
        <outline text="Service limited to the Western US"/>
        <outline text="Plan to go national, even international"/>
        <outline text="How do you verify the neutrality claims?"/>
        <outline text="Will this claim remain when their users start heavy bandwidth use, p2p, video?"/>
        <outline text="Important point, they don't own any copper"/>
        <outline text="In my experience, ISPs can do little when the last mile providers disagree"/>
        <outline text="This drives the price up more than anything"/>
        <outline text="$33.95 for 256Kbps"/>
        <outline text="How is this any different than tiered pricing?"/>
        <outline text="If the telcos change their minds, what power does Copowi have?">
          <outline text="Contracts, sure"/>
          <outline text="How would they know?"/>
        </outline>
        <outline text="How will the grow with such higher rates?  Doesn't bode well for national build out"/>
        <outline text="TOS really let Copowi wriggle out of upstream throttling"/>
        <outline text="Ultimately could drop guarantee"/>
        <outline text="Do show they are community to community goods"/>
        <outline text="Uses volunteers to keep cost down, liability issues?"/>
        <outline text="In practice sounds like a customer referral program"/>
        <outline text="Infrastructure built on open source, gives customers Ubuntu CDs"/>
        <outline text="Want them to succeed but skeptical"/>
      </outline>
      <outline text="Progress on making available case" Offset="16:14">
        <outline text="http://arstechnica.com/news.ars/post/20070820-foundation-on-which-riaa-builds-cases-in-danger-of-being-undermined.html"/>
        <outline text="Copyright law requires a specific act of infringement"/>
        <outline text="RIAA's agent, MediaSentry, cannot prove this specifically"/>
        <outline text="RIAA complaints speak to this, characterizing as continuing or ongoing"/>
        <outline text="Implication of making available as distribution is chilling"/>
        <outline text="Simple links could then be seen as distribution"/>
        <outline text="Seven cases tested this"/>
        <outline text="In six, judges avoided issue of association between making available, distribution"/>
        <outline text="Elektra vs. Barker is the seventh, judge has promised to rule on the issue"/>
        <outline text="A favorable ruling would kill the RIAA's basis for complaints"/>
        <outline text="A reasonable analysis of the issues that make Elektra vs. Barker important"/>
      </outline>
      <outline text="Another discussion of leadership for hackers" Offset="19:00">
        <outline text="http://www.codinghorror.com/blog/archives/000933.html"/>
        <outline text="Following on from discussion of engineering discipline"/>
        <outline text="Admits you cannot use an enforcer, like military discipline"/>
        <outline text="Suggest you need a leader to negotiate consensus"/>
        <outline text="Comments on another post the addresses challenge of not ending up an enforcer"/>
        <outline text="Speaks to humility, discretion, credibility, focus on action"/>
        <outline text="Corresponds well to leading by example"/>
        <outline text="I agree, especially with actions as currency"/>
        <outline text="Demonstrating an answer, providing a code example far better than any kind of discussion"/>
        <outline text="Actually meshes well with my discussion from 1/31"/>
        <outline text="Spoke to some of the same issues"/>
        <outline text="For a change, provides some recommendations for improvement"/>
        <outline text="A couple of book recommendations"/>
      </outline>
      <outline text="Combining nanotechnology, neural networks for computing" Offset="21:34">
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/science/~3/146230313/computing-with-nanotechnology-may-get-a-boost-from-neural-networks"/>
        <outline text="Nano on its own not suitable"/>
        <outline text="Current CPUs are designed top down"/>
        <outline text="Nano works best self assembled, bottom up">
          <outline text="Like an FPGA, high performance and flexible"/>
          <outline text="Random assembly makes functionality hard to predict, though"/>
          <outline text="Not all elements may work the same, if at all"/>
        </outline>
        <outline text="Could be programmed, but not easily or fast"/>
        <outline text="Tools would map out defects, figure out how to implement logic">
          <outline text="Functionality later may change, pieces may stop working"/>
          <outline text="Time to characterize logic design is unknown, may be long"/>
        </outline>
        <outline text="New research proposes use nano processor as a neural network"/>
        <outline text="Overcomes previous limitations by salting elements">
          <outline text="Neural networks don't work well with purely linear elements"/>
          <outline text="Doesn't take many non-linear elements to make workable"/>
          <outline text="Self assembly would seem advantageous, ensure distribution"/>
          <outline text="Interaction of two kinds of elements can allow routing around failed elements"/>
        </outline>
        <outline text="Device would self learn, avoid much overhead of characterization"/>
      </outline>
    </outline>
    <outline text="tail -f" Offset="25:41">
      <outline text="LJ creator talks about road to open social networks" Offset="26:01">
        <outline text="http://feeds.wired.com/~r/wired/topheadlines/~3/146726716/brad-fitzpatric.html"/>
        <outline text="Reinforces what many are saying"/>
        <outline text="Lays out a constructive plan"/>
        <outline text="Claims to have some of the pieces working"/>
        <outline text="Most realistic view, doesn't think one exchange format will work"/>
        <outline text="Networks will have to support many"/>
        <outline text="There will always be holdouts"/>
        <outline text="Actually wants to be an aggregate, free, open, to help enable"/>
        <outline text="Focus on public data, first, to get most of the way"/>
        <outline text="Private data can be done later, no harm done"/>
        <outline text="This is as good a plan as any"/>
        <outline text="More practical than most, least threatening to &quot;walled gardens&quot;"/>
      </outline>
      <outline text="ES&amp;S provided non-certified e-voting machines to CA" Offset="28:32">
        <outline text="http://techdirt.com/articles/20070821/191429.shtml"/>
        <outline text="Also discovered time stamping that allowed recovery of votes"/>
        <outline text="In the last CA election, sold uncertified machines to five counties"/>
        <outline text="One model was certified, sold uncertified model"/>
        <outline text="1000 units, $5M worth of hardware"/>
        <outline text="Automark Phase 2 Model A200 never submitted for certification"/>
        <outline text="CA looking to fine vendor"/>
        <outline text="Up to $10K per unit, plus original $5M"/>
        <outline text="Public hearing, September 20th"/>
        <outline text="Many other complaints">
          <outline text="Refused to turn over sources"/>
          <outline text="When did, send nastygram"/>
          <outline text="Used in FL where votes went missing"/>
        </outline>
        <outline text="Also, just discovered failed to disclose foreign manufacturing partners">
          <outline text="Requirement of certification"/>
          <outline text="Luke warm response as if this is no big deal"/>
        </outline>
      </outline>
    </outline>
    <outline text="Outro" Offset="32:04">
      <outline text="Contact me">
        <outline text="Email to feedback@thecommandline.net"/>
        <outline text="Web site at http://thecommandline.net/"/>
        <outline text="IM to command.line@skype"/>
        <outline text="Listener comment line is 360-252-7284"/>
        <outline text="del.icio.us tag is &quot;for:cmdln&quot;"/>
        <outline text="http://twitter.com/cmdln"/>
      </outline>
      <outline text="I'd like to thank libsyn.com for AAC hosting and Wouter de Bie for MP3 hosting"/>
      <outline text="These notes and the show audio and music are covered by a Creative Commons license">
        <outline text="http://creativecommons.org/licenses/by-nc-sa/3.0/us/"/>
        <outline text="Attribution, non-commercial, share alike"/>
      </outline>
    </outline>
  </body>
</opml>
