<?xml version="1.0" encoding="UTF-8"?>
<opml version="1.0">
  <head>
    <title>cmdln.net_2008-07-27</title>
    <expansionState>0,2,3,9,17,27,36,45,46,73,83,93,104,109,119,128,145,150,151,157,168,169,177</expansionState>
  </head>
  <body>
    <outline text="Intro" Offset="00:17">
      <outline text="Review of Settlers of Catan"/>
    </outline>
    <outline text="Security Alerts" Offset="04:39">
      <outline text="DNS vulnerability leaked then pulled" Offset="04:59">
        <outline text="http://rss.slashdot.org/~r/slashdot/eqWf/~3/341985322/article.pl"/>
        <outline text="Kaminsky had agreed to defer publication to allow coordinated updates"/>
        <outline text="A reverse engineering expert, Halver Flake was musing about it"/>
        <outline text="Apparently prompted someone who know the flaw to post details"/>
        <outline text="Was quickly pulled though some cache copies can still be found"/>
        <outline text="Interview with Kaminsky on DNS exploit">
          <outline text="http://blog.wired.com/27bstroke6/2008/07/kaminsky-on-how.html"/>
          <outline text="More details about how the problem was discovered"/>
          <outline text="Also how experts were pulled together to discuss how to address"/>
          <outline text="Kaminsky prefers to be constructive about the leak"/>
          <outline text="Had about a week and a half with the patch available before the leak"/>
          <outline text="Also vendors were largely positively, willing to just get to work"/>
          <outline text="Static has come more from security industry, pundits not those responsible for evaluating, producing patches"/>
        </outline>
        <outline text="DNS flaw points out problems with discovery, patching">
          <outline text="http://feeds.wired.com/~r/wired/topheadlines/~3/344036307/securitymatters_0723"/>
          <outline text="Schneier sees this as evidence of need for a more profound change"/>
          <outline text="Has been extolling building in security at the design even before implementing"/>
          <outline text="Re-iterates how that would have helped here"/>
          <outline text="Points out how including a security engineer in projects would be more cost effective than patching after the fact"/>
          <outline text="I think this is even more of a benefit"/>
          <outline text="Even if we reduce the patch treadmill as he calls it I doubt it will ever go away"/>
          <outline text="Having a security stakeholder as part of software all along could speed up evaluating flaw info, patches and the like"/>
          <outline text="Could make designs easier to modify to incorporate new information"/>
        </outline>
        <outline text="DNS attack code published">
          <outline text="http://arstechnica.com/news.ars/post/20080726-new-dns-exploit-now-in-the-wild-and-having-a-blast.html"/>
          <outline text="Exploit is a Metasploit module"/>
          <outline text="The attack involves target upstream DNS servers"/>
          <outline text="Takes advantage of the recursive nature of DNS"/>
          <outline text="If any server cannot find a name, it looks upstream"/>
          <outline text="Currently implementation of that recursive search is too trusting"/>
          <outline text="At the two week mark, patch deployment was estimated at 52%"/>
          <outline text="Live exploit should accelerate uptake of the patch"/>
        </outline>
        <outline text="ISPs dragging feet on DNS patches">
          <outline text="http://go.theregister.com/feed/www.theregister.co.uk/2008/07/25/isps_slow_to_patch/"/>
          <outline text="Surprising how many large ISPs have not patched yet"/>
          <outline text="Article contains a link to Kaminsky's site where he has a test"/>
          <outline text="Can determine if your ISP has patched and is safe"/>
          <outline text="If your has not patched, you can use a secure alternative"/>
          <outline text="Register recommends OpenDNS, I concur"/>
          <outline text="In running the test myself, realized that those with home routers will want to update, as well"/>
          <outline text="Got a warning that my router may need a patch, too"/>
        </outline>
      </outline>
    </outline>
    <outline text="News" Offset="14:05">
      <outline text="Open cloud computing" Offset="14:19">
        <outline text="http://cloudcomputing.sys-con.com/read/613436.htm"/>
        <outline text="Mike Linksvayer sent a link in response to my mention of Autonmo.us on the site"/>
        <outline text="http://lists.canonical.org/pipermail/kragen-tol/2006-July/000818.html"/>
        <outline text="This really makes the group's focus clear"/>
        <outline text="Not about users but about applications"/>
        <outline text="Being able to pick your own provider and move incidentally achieves data portability"/>
        <outline text="In short, applying open source principles to cloud computing"/>
        <outline text="Encountered another article on open cloud computing"/>
        <outline text="Written by David Young, at Joyent"/>
        <outline text="Joyent is his first cloud computing endeavor"/>
        <outline text="Company does some well positioned"/>
        <outline text="Offers application hosting as well as basic office, collaboration web applications"/>
        <outline text="Starts by discussing the definition of cloud computing"/>
        <outline text="Joyent even did a brief industry survey that he links to"/>
        <outline text="Mentions SaaS and PaaS but really can be simply opposed to edge of network applications"/>
        <outline text="In the absence of a firm definition, even a de facto on, starts to speculate on what clouds should be"/>
        <outline text="Starting assumption i they should be open"/>
        <outline text="Then lists nine items to accomplish a truly open cloud"/>
        <outline text="Need to be able to self-serve compute nodes, including creating new ones, moving them and automated/transparent recovering"/>
        <outline text="Talks about state layer interoperability"/>
        <outline text="Mentions BigTable and SimpleDB but is really talking about a common API/protocol for data storage"/>
        <outline text="Implementable by anyone, scalable without impacting applications that use"/>
        <outline text="Use SQL or a SQL-like language to interface so application developers can just think of it as a database"/>
        <outline text="Measures his own services against these criteria, not surprisingly does well"/>
        <outline text="Hints at future development"/>
        <outline text="I like the idea of delegating scalability to a provider but not totally sacrificing control, ease of development, deployment"/>
      </outline>
      <outline text="MPAA interviewed on petition to allow SOC" Offset="20:21">
        <outline text="http://arstechnica.com/news.ars/post/20080720-mpaa-dvr-blocking-about-multibillion-dollar-theft-problem.html"/>
        <outline text="Haven't talked about SOC before"/>
        <outline text="FCC currently restricts broadcasters from using broadcast flags or SOC"/>
        <outline text="Selectable output control means broadcaster could forbid different types of outputs"/>
        <outline text="DVI, HDMI, component, etc."/>
        <outline text="MPAA has made a plea on behalf of studios to waive restriction"/>
        <outline text="They say the waiver is needed for new on-demand business models"/>
        <outline text="Offer new movies between theatrical and disc release"/>
        <outline text="Want to forestall piracy of this new business model, so as not to erode disc sales"/>
        <outline text="Critics find the plea vague">
          <outline text="Doesn't accept or admit any limitations on use"/>
          <outline text="Doesn't clearly defined which devices would be affected and which exempted"/>
        </outline>
        <outline text="Again, seems to be about controlling, preventing innovation by others"/>
        <outline text="MPAA wanted to clarify with Ars, claim it is not about blocking home recording"/>
        <outline text="Discussion didn't seem to clear anything up"/>
        <outline text="MPAA insists this is not about stopping recording"/>
        <outline text="Preventing output on high quality protocols, though, seems to be about stopping production of high quality copies"/>
        <outline text="MPAA folks just kept re-iterating new business model, getting content sooner"/>
        <outline text="Doesn't change that the plea is just too vague as to how studios will use the waiver if they get it"/>
        <outline text="AT&amp;T, DirecTV support MPAA's SOC play">
          <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/343167711/20080722-att-directv-back-mpaas-dvr-blocking-initiative.html"/>
          <outline text="Initial comments conclude"/>
          <outline text="About twenty parties weighed in"/>
          <outline text="A mix of supporters and critics"/>
          <outline text="AT&amp;T and DirecTV don't think it would hurt current consumer choice"/>
          <outline text="Without clear limits in the plea, though, the studios certainly could limit existing programming as well as new"/>
          <outline text="That is the core of the critics comments"/>
          <outline text="National Theater Owners and Independent Film and Television Association also amongst critics"/>
          <outline text="Probably feel it will hurt their current business practices"/>
          <outline text="Some are in the middle, willing to support but with conditions, restrictions"/>
        </outline>
        <outline text="More info from PK on MPAA and SOC">
          <outline text="http://feeds.publicknowledge.org/~r/publicknowledge-fulltext/~3/342928544/1668"/>
          <outline text="Sums up PK's stance well"/>
          <outline text="Written by Jef Pearlman who was a techie before a lawyere"/>
          <outline text="Clear summation of the issues, accessible"/>
        </outline>
      </outline>
      <outline text="USPTO to invalidate many, most software patents" Offset="27:58">
        <outline text="http://www.patentlyo.com/patent/2008/07/the-death-of-go.html"/>
        <outline text="PTO seems to be revising its standards"/>
        <outline text="Based on three cases challenging section 101"/>
        <outline text="Seems to be moving towards requiring clear physical transformation as being patentable"/>
        <outline text="Or if it is tied to a particular machine"/>
        <outline text="Articles interpretation is that a general purpose computer is not a particular machine"/>
        <outline text="Thinks that means we could see a large swath of software patents invalidated"/>
        <outline text="Article considers a couple of specific cases, including Google's PageRank algorithm"/>
        <outline text="Thinks creativity, innovation will be trumped by their interpretation of the PTO's emerging standard"/>
        <outline text="More information on changes at USPTO">
          <outline text="http://www.groklaw.net/article.php?story=20080724202700686"/>
          <outline text="Clarifies the author, Duffy, has filed a brief in one of the key cases"/>
          <outline text="Speculates the article is a bit of advocacy"/>
          <outline text="Meant to sway a judges opinion, may not be a genuine speculation"/>
          <outline text="Offers a contrasting opinion from another lawyer"/>
          <outline text="Even the blog owner of Patently O disagrees with the author"/>
          <outline text="Also questions Duffy's conclusion that elimination of software patents would disrupt innovation industry"/>
          <outline text="Cites views, research in line with anti-patent advocates who think the opposite is true"/>
        </outline>
      </outline>
      <outline text="New foundation to support open web standards efforts" Offset="30:45">
        <outline text="http://www.webmonkey.com/blog/New_Foundation_Wants_to_Bridge_the_Gaps_Between_Open_Web_Tools"/>
        <outline text="Announced by Six Apart's David Recordon, at OSCON"/>
        <outline text="http://openwebfoundation.org/2008/07/announcing-the-open-web-foundation.html"/>
        <outline text="Appears to be modeled after the Apache Foundation"/>
        <outline text="Will provide legal support for open standards, like OAuth and OpenID"/>
        <outline text="Meant to help answer questions potential corporate adopters may have"/>
        <outline text="Mostly questions about liabilities, exposures like patents, privacy, etc."/>
        <outline text="If successful, should make open standards more attractive"/>
        <outline text="Also provide a place for those working on standards, specifications to meet and coordinate efforts"/>
        <outline text="Not much other detail though they have a community site, forum set up for discussion"/>
        <outline text="Founders think it is complementary to Autonomo.us"/>
        <outline text="OWF to concentrate on adoption, other to focus more perhaps on how standards, specs ensure user freedom"/>
        <outline text="For instance, recent post on Autonomo.us site is about Jesse Vincent's Prophet"/>
        <outline text="This is an open source, distributed state layer or data store"/>
        <outline text="Autonomo.us is highlighting specific efforts, principles, not just standards"/>
        <outline text="OWF more open openness for interoperability"/>
        <outline text="Why not W3c or IETF?">
          <outline text="http://www.links.org/?p=351"/>
          <outline text="Discusses organizational differences"/>
          <outline text="Limitations of W3C and IETF that OWF is looking to avoid"/>
          <outline text="Clearly re-inforces focus on developing, advocating standards"/>
        </outline>
      </outline>
    </outline>
    <outline text="tail -f" Offset="34:33">
      <outline text="Code released for cold boot encryption attack" Offset="34:52">
        <outline text="http://feeds.arstechnica.com/~r/arstechnica/BAaf/~3/342170246/20080721-source-code-published-for-cold-boot-exploit.html"/>
        <outline text="Based on researcher by Ed Felten at Princeton and others"/>
        <outline text="Originally released back in February"/>
        <outline text="Code is released from the same researchers"/>
        <outline text="Will hopefully spur vendors to try to come up with practical solutions"/>
      </outline>
      <outline text="Slower than hoped adoption of OpenID" Offset="35:44">
        <outline text="http://feeds.wired.com/~r/wired/topheadlines/~3/341891010/Dear_Open_ID%3A_You_Deserve_Better"/>
        <outline text="Itemizes some of the problems with adoption"/>
        <outline text="Much of the support is one way"/>
        <outline text="Big adopters allow their accounts to be used as OpenIDs"/>
        <outline text="Do not let folks user other OpenIDs to log into them, like Yahoo!"/>
        <outline text="Adopters aren't using all of what is available"/>
        <outline text="Aren't re-using identity data"/>
        <outline text="Forcing users to re-register which defeats much of the point"/>
        <outline text="Points out next stages for adoption, improvement"/>
        <outline text="Is a cute reminder to big services not to rest on laurels"/>
      </outline>
    </outline>
    <outline text="Outro" Offset="37:16">
      <outline text="Contact me">
        <outline text="Email to feedback@thecommandline.net"/>
        <outline text="Web site at http://thecommandline.net/"/>
        <outline text="IM to command.line@skype"/>
        <outline text="Listener comment line is 240-949-2638"/>
        <outline text="del.icio.us tag is &quot;for:cmdln&quot;"/>
        <outline text="http://twitter.com/cmdln"/>
      </outline>
      <outline text="I'd like to thank libsyn.com for AAC hosting and Wouter de Bie for MP3 hosting"/>
      <outline text="These notes and the show audio and music are covered by a Creative Commons license">
        <outline text="http://creativecommons.org/licenses/by-nc-sa/3.0/us/"/>
        <outline text="Attribution, non-commercial, share alike"/>
      </outline>
    </outline>
  </body>
</opml>
