It wasn't me. You can't prove anything.


2017-05-23

Need coffee.


2017-05-17

INSANE NEW BAFFLE-FREE SUPPRESSOR IS AS BADASS AS IT LOOKS,IT BLOWS ALL ...


2017-05-14

Pulling out bushes with a pickup

Walk in the woods, kind of


2017-05-13

Duck pond

Hole


2017-05-09

Trying so hard to be pretty


2017-05-07

Question

Exactly what are my privileges and responsibilities being "it"?


2017-05-04

Today I envy the ditch diggers.


2017-05-01

Why I hate Ubuntu (am sick of it anyway)

First light


2017-04-30

Last light of a lovely day

Watching


2017-04-26

.38 Special vs Prince Ruperts Drop at 170,000 FPS - Smarter Every Day 169


2017-04-16

taking an old light apart


2017-04-08

Urban exploration by an old fat guy


2017-04-04

Earphones

Trying wireless headphones for the first time. Ask me how I like them after the battery runs out.


2017-04-02

Software update day


2017-04-01

8309 steps


2017-03-30

Dump next to my house and a light holster mod


2017-03-25

I've decided to drink more.


2017-03-23

Lunch time


2017-03-22

Ain't technology grand?


2017-03-21

The best part of my lunch walk.


2017-03-19

I await my coffee drone delivery


2017-03-18

Walk

My thoughts on Quantum


2017-03-17

Im going to die fat.


2017-03-15

This guy is a bit shady.


2017-03-14

Can't complain


2017-03-13

Why is the bus doing 7 mph?


2017-03-11

Week worth of boiled eggs


2017-03-10

Wonder when the lawn guys are coming.


2017-03-02

It begins

Morning

Sleep


2017-02-27

Nice weather, walking around work


2017-02-22

Morning


2017-02-21

Homeward bound


2017-02-18

So, laundry day.


2017-02-16

Waiting on a ride.


2017-02-15

Rant about had drive passwords


2017-02-12

Water flow and walking home


2017-02-10

Quick run home


2017-01-28

Getting cut off and talking about it

Week and some of clips


2017-01-22

WARNING! Political vlog


2017-01-18

#houston commute problems.


2017-01-14

Friends carlots and a crazy bus ride.


2017-01-13

One more reason no oone walks in #Houston

Sunrise out the car window


2017-01-12

Phones

I remember a day not that long ago when we fought over phones. Now several collect dust.


2017-01-07

A walk to a park


2017-01-05

Light is slow


2017-01-04

My meetings most days


  • Meeting 1
    • In Conf B
    • I don’t go to the room because there are so many people. I lurk on the phone.
  • Meeting 2
    • Online only
    • People all over the planet
    • High level decision making
    • Only on Tuesdays and Thursdays
  • Meeting 3
    • In Conf B
    • I usually do go to this one
    • Not nearly as many people.
    • Low level nuts and bolts
  • Meeting 4
    • The burn in lab walk through
    • I have to go, but it only lasts 15 minutes or so
    • Me and two other folks.
    • Me getting yelled at for the state of the lab
    • Ended up getting canceled
  • Our weekly all hands is usually hit or miss on what information you get. There are new people introductions and basic heading information. However, sometimes you get a vast amount of information in a dramatic pause of the head honcho. That happened today. There was applause after. That is how telling it was.

Security Disconnect

My sources for this post are purely tech journals and web pages like SlashDot and Wired. None of this is based on my employer’s information or practices. (Really, I’m not in security or anything like it.)

In the beginning, there were developers. All was well. Then some of the developers decided they wanted to be bad guys and they used their skills to cheat and steal. This was not good, but it was inevitable. Developers are people after all.

The result of this was an arms race between good and evil for the better technology to thwart the other side. Every time the bad guys come up with a trick, the good guys counter. Every time the good guys defend something valuable, the bad guys come up with more tricks. It is the way of nature. It has run for a life time and gotten very complex.

Something is happening in the technology industry that may not be a good thing. There is a separation between the public sector and ultra secure entities. For a very long time the ultra secure have taken off the shelf devices, tweaked them and made them more secure. This tech trickled back to the community and you had a positive feedback loop that accelerated security development.

I’m sure a lot of this is still going on, but is seems the industry that developed purely for the ultra secure is booming. The links between the ultra secure and mondain development seem to be withering. Security on so many public software projects just seems to be a box to tick in a PowerPoint presentation. The goal is to get people to click on in game purchases and rent virtual hotel rooms. Security is something you put in after a billion user files are stolen (Yahoo!)

My experience is companies telling developers to pay very close attention to security and then setting deadlines that allow very little time for dedicating thought to security. We do it anyway. We make it work, we make it secure, and we tick the box on the PowerPoint slide. It just isn’t easy.

That loss of feedback is going to slow forward movement of secure development. The ultra secure people are not going to provide last year's tech to the mundanes. The mundanes are not going to provide an army of people poking and prodding the software and indeed hardware to find weaknesses. You cannot automate lucky. Some mediocre programmer might find the loose tile in the wall that all the automation missed that brings down the castle. You have to know their is a problem before you can automate looking for it.

The Iranian nuclear development team air gapped (physically separated) all the development systems for their nuclear systems. They thought that this was a very good idea. It was really. It is not impervious to human error. One of the people who had access to the secure network put an infected USB drive in a secure computer and all the very expensive material separators ran too fast and burned out. This was a targeted attack. Someone knew what was going on at the facilities and exploited several weaknesses to slow the Iranian development of nuclear fuel.

The solution here is to keep the channels open. Don’t give away the family cow for magic beans, but talk to people on the other side of the isle. Learn motives, tools, intentions, drives, and accomplices. Root out bad things and talk about failures. Find the things that work and test the hell out of them.


2017-01-03

First posted sunset of 2017 for me

Out the window