<?xml version="1.0" encoding="UTF-8"?>
<opml version="1.0">
  <head>
    <title>cmdln.net_2008-07-20</title>
    <expansionState>0,4,5,25,42,43,61,67,74,90,111,129,130,140,148,160,161,169</expansionState>
  </head>
  <body>
    <outline text="Intro" Offset="00:17">
      <outline text="Correction on pronunciation of Levy's name"/>
      <outline text="Help with my next promo"/>
      <outline text="Submit application or recommend contributors for OMR"/>
    </outline>
    <outline text="Security Alerts" Offset="03:13">
      <outline text="Demo of direct, remote attack against Intel chips" Offset="03:32">
        <outline text="http://rss.slashdot.org/~r/slashdot/eqWf/~3/335409428/article.pl"/>
        <outline text="Researcher Kris Kaspersky to demonstrate attack"/>
        <outline text="At Hack in the Box in Ocotober"/>
        <outline text="Based on flaw in Intel chips, exploitable with JavaScript or plain TCP/IP packets"/>
        <outline text="Article is a bit confused, mentions JavaScript, then Java"/>
        <outline text="Simply is a demonstration of how to use known errata about chips"/>
        <outline text="Can cause both crashes as well as arbitrary code execution"/>
        <outline text="Since these are flaws in the chip, bypass OS security"/>
        <outline text="Some can even be used to subvert OS security"/>
        <outline text="Researcher is apparently critical of industries handling of errata"/>
        <outline text="Implication is they should be more proactive to use BIOS workarounds"/>
        <outline text="Many do not"/>
        <outline text="Very much reminds me of panel with Vinge"/>
        <outline text="Unintentional breaks but in critical class for computing infrastructure"/>
        <outline text="May seem obscure, but only takes one to write attack"/>
        <outline text="Author doesn't need to deploy, others can use existing code, can even be deployed in self replicating code, worm"/>
        <outline text="Can't exactly upgrade a processor for security fixes"/>
        <outline text="If vendors pay attention to errata, may be able to upgrade BIOS as effective fix"/>
        <outline text="Otherwise, based defense is like any, be careful what you trust, use a router/firewall to foil remote packet attacks"/>
      </outline>
      <outline text="Fall of CAPTCHAs" Offset="06:49">
        <outline text="http://rss.slashdot.org/~r/slashdot/eqWf/~3/336442258/article.pl"/>
        <outline text="Quicky history, developed in 2000 by CMU researchers"/>
        <outline text="Distorted strings of characters, supposedly only decipherable by humans"/>
        <outline text="Quickly and widely adopted"/>
        <outline text="This year, though, the most high profile captchas have failed"/>
        <outline text="Yahoo mail, Gmail, Hotmail"/>
        <outline text="Attacks have been automated so any spammer or attacker can benefit"/>
        <outline text="Many different options, actually, from free to commercial"/>
        <outline text="Targets are too attractive, article highlights examples"/>
        <outline text="In the case of Gmail, not just a trusted email"/>
        <outline text="Clever attackers also using other Google offerings, like Docs to deliver malware"/>
        <outline text="Even newer approach, creation of quick web sites, like Google Sites, etc."/>
        <outline text="Conclusion is captchas are a dead solution"/>
        <outline text="Implication is focus on them has stalled progress"/>
        <outline text="Thinks concept may be valid but clearly needs to be fresh research"/>
        <outline text="Is an arms race, is always going to be a need for next thing"/>
      </outline>
    </outline>
    <outline text="News" Offset="10:41">
      <outline text="Blizzard wins motion against Glider developer" Offset="10:55">
        <outline text="http://virtuallyblind.com/2008/07/14/blizzard-wins-sj-mdy/"/>
        <outline text="MDY created software called glider"/>
        <outline text="Essentially a bot to drive WoW to level a character automatically"/>
        <outline text="Blizzard claimed it infringed copyright by loading a copy into memory"/>
        <outline text="By that reasoning, just playing the game is a violation"/>
        <outline text="Blizzard wanted to establish that user doesn't own game, merely has a license"/>
        <outline text="Really should be a contract claim, violation of license"/>
        <outline text="Blizzard argued copyright gives them control over authorized uses"/>
        <outline text="MDY, backed by Public Knowledge, others tried to argue that Section 117 protects against claims about in memory copies"/>
        <outline text="First sale doctrine, that once a user buys, theirs do with as they see fit"/>
        <outline text="Cited several precedents"/>
        <outline text="Judge ruled in favor of Blizzard"/>
        <outline text="Case still set to go to trial in September, unless they settle"/>
        <outline text="Not likely to go well for MDY since Blizzard won summary judgement"/>
        <outline text="Decision here is probably either to settle for less than awarded damages or appeal"/>
        <outline text="Sets another precedent that others may be able to use"/>
        <outline text="Erodes section 117 a bit but not widely"/>
        <outline text="Patry on Blizzard case">
          <outline text="http://williampatry.blogspot.com/2008/07/strange-copyright-world-of-warcraft.html"/>
          <outline text="Explains there was also a DMCA claim"/>
          <outline text="Based on warden spyware Blizzard uses to detect cheating"/>
          <outline text="Judge dismissed DMCA claims, at least"/>
          <outline text="Critical of the ruling, thinks the judge really stretched to support it"/>
        </outline>
        <outline text="More on Blizzard ruling">
          <outline text="http://feeds.publicknowledge.org/~r/publicknowledge-fulltext/~3/336515994/1657"/>
          <outline text="Explains judge's interpretation of sale as license"/>
          <outline text="Points out problem in thinking that sale and license are mutually exclusive"/>
          <outline text="This is not necessarily true, example provided is owning DVD but needing license for public performance"/>
          <outline text="Points out that the danger it presents is others can craft EULAs modeled after Blizzard to eliminate section 117 protection"/>
          <outline text="Also mentions that MDY will appeal"/>
        </outline>
      </outline>
      <outline text="Android builds released under NDA, not so open" Offset="16:21">
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/336546040/20080715-googles-android-platform-not-so-open-after-all.html"/>
        <outline text="New iPhone has increased awareness of alternatives"/>
        <outline text="FSF is making much hay out of DRM on the iPhone, other concerns"/>
        <outline text="OpenMoko has gotten some attention, though not favorable"/>
        <outline text="UI seems nowhere near finished, too much a hobbyist device"/>
        <outline text="Android seems like a better bet"/>
        <outline text="Backed by Google, a company that seems to get UI, design"/>
        <outline text="Originally committed to open standards, open development"/>
        <outline text="Turns out a Google staffer posted a closed SDK build to the open list"/>
        <outline text="Revealed that public development had stalled but privilege few still getting builds"/>
        <outline text="Select developers signed NDAs to get advance builds"/>
        <outline text="Few other details at this time"/>
        <outline text="No information on the contents of the builds, whether any of the technology has shifted away from open source"/>
        <outline text="Has seriously shaken the open community"/>
        <outline text="No real response from Google, either, explaining its actions"/>
      </outline>
      <outline text="Another next generation P2P effort targeted at IPTV" Offset="20:09">
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/338922629/20080718-major-eu-p2p-research-project-hopes-to-kill-traditional-tv.html"/>
        <outline text="Academic who has studied BitTorrent throughly heading team to build 4G P2P"/>
        <outline text="Group, P2P-Next, is publicly and privately funded"/>
        <outline text="4G P2P is zero server, also sounds like may use network information more intelligently"/>
        <outline text="Reminds me of Pando and stories about P4P"/>
        <outline text="http://arstechnica.com/news.ars/post/20080314-verizon-embraces-p4p-a-more-efficient-peer-to-peer-tech.html"/>
        <outline text="Another attempt to legitimize P2P and make it work well with carriers as opposed to stories of bandwidth hogs, congestion"/>
        <outline text="Specifically working on streaming video"/>
        <outline text="Traditionally requires a server or cluster of servers, can bottleneck"/>
        <outline text="P2P has focused on download only, not suitable for streaming"/>
        <outline text="Lead, Pouwelse, believes P2P and streaming can be melded effectively"/>
        <outline text="One of the projects goals is to replace traditional broadcast TV"/>
        <outline text="Realistic about existing bandwidth, trying to be effective with current and future networks"/>
        <outline text="Building on existing, open source P2P client, Tribler to create new Swarmplayer"/>
        <outline text="Tribler already cross platform--Windows, Linux, OS X"/>
        <outline text="Will support traditional BT downloads as well as new streaming"/>
        <outline text="Researchers are inviting public to use trial version, help work out kinks"/>
        <outline text="Not trying to lock up the technology"/>
        <outline text="Admits pirate use is going to be a problem, doesn't say it is one the researchers will try to solve"/>
        <outline text="Pouwelse thinks research could help with peer production, distribution of open/free content like HD video for Wikimedia's work"/>
      </outline>
      <outline text="Recovering old software from cassette tape" Offset="24:08">
        <outline text="http://rss.slashdot.org/~r/slashdot/eqWf/~3/335941527/article.pl"/>
        <outline text="Software was BASIC for the Apple I"/>
        <outline text="That machine is rare, very few originally produced"/>
        <outline text="Not all came with BASIC"/>
        <outline text="Was the first commercial software Apple sold"/>
        <outline text="Article details the recovery from tape"/>
        <outline text="Others have done before but perhaps not with the same fidelity"/>
        <outline text="If you are curious about analog to digital conversion, this is a great working example"/>
        <outline text="Program was only 4KB"/>
        <outline text="Memory location when loaded was fixed"/>
        <outline text="Contemporary computers either loaded from cartridges, firmware, or casette"/>
        <outline text="Remember using Atari 400/800's at school with carts and cassettes"/>
        <outline text="Next steps would be for assembly hackers to review"/>
        <outline text="Important for how limited systems were used"/>
        <outline text="BASIC was one of the first languages for many hackers of my generation and earlier"/>
        <outline text="As an interpreted language, good for what if experimenting"/>
        <outline text="Glad this has been recovered and will be preserved on the Internet"/>
      </outline>
    </outline>
    <outline text="tail -f" Offset="27:02">
      <outline text="EU considering extending copyright, again" Offset="27:21">
        <outline text="http://techdirt.com/articles/20080715/0101411681.shtml"/>
        <outline text="EU's internal market commissioner pushing for it"/>
        <outline text="Despite Gowers report that found extending would be harmful"/>
        <outline text="Even recommended shortening"/>
        <outline text="Also despite a past attempt in the UK that was foiled"/>
        <outline text="McCreevy seems to think copyright is a welfare system"/>
        <outline text="Wants term extend from 50 to 95 years"/>
        <outline text="Wants to focus on unknown musicians, like session players"/>
        <outline text="Was to be up for vote this past week"/>
        <outline text="EU copyright extension has a use or lost it provision">
          <outline text="http://go.theregister.com/feed/www.theregister.co.uk/2008/07/16/ec_copyright_term_extension/"/>
          <outline text="EC approved the extension"/>
          <outline text="Seems to be a moral rights issue"/>
          <outline text="EC sided with arguments for underpaid musicians"/>
          <outline text="So much so they built in a reversion clause"/>
          <outline text="If labels don't actively use music after fifty years, everts to artist"/>
          <outline text="Not exactly public friendly"/>
        </outline>
      </outline>
      <outline text="ACTA analysis" Offset="29:31">
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/338873723/20080718-abig-wishlist-for-a-scary-secret-anticounterfeiting-pact.html"/>
        <outline text="Draft recommendation was originally leaked"/>
        <outline text="RIAA wishlist was later leaked"/>
        <outline text="Public Knowledge, even USTR itself, have revealed more input from NGOs, others"/>
        <outline text="RIAA wants all unauthorized exchanges criminalized, regardless of profit or intent"/>
        <outline text="Also wants ISP filtering, though doesn't use those words"/>
        <outline text="BSA also wants filtering, objects to EU privacy laws as interfering with copyright enforcement"/>
        <outline text="Some from progressives"/>
        <outline text="Objecting to DRM, use of term piracy as emotionally laden"/>
        <outline text="Also don't think online vs. offline should make a difference in enforcement, penalties"/>
        <outline text="Ars piece concludes with individual comment, PhD student that thinks ACTA should simply be abandoned"/>
      </outline>
    </outline>
    <outline text="Outro" Offset="21:18">
      <outline text="Contact me">
        <outline text="Email to feedback@thecommandline.net"/>
        <outline text="Web site at http://thecommandline.net/"/>
        <outline text="IM to command.line@skype"/>
        <outline text="Listener comment line is 240-949-2638"/>
        <outline text="del.icio.us tag is &quot;for:cmdln&quot;"/>
        <outline text="http://twitter.com/cmdln"/>
      </outline>
      <outline text="I'd like to thank libsyn.com for AAC hosting and Wouter de Bie for MP3 hosting"/>
      <outline text="These notes and the show audio and music are covered by a Creative Commons license">
        <outline text="http://creativecommons.org/licenses/by-nc-sa/3.0/us/"/>
        <outline text="Attribution, non-commercial, share alike"/>
      </outline>
    </outline>
  </body>
</opml>
