Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, February 06, 2007

User Account Control

A new security feature in Microsoft Windows Vista is User Account Control, a mechanism that confirms actions that affect the operating system. Microsoft has been criticized for the implementation of this feature. I'm laughing on the inside.

you know why the situation is ironic? Normally Microsoft is criticized for implementing too little security. The tables have turned. Now Microsoft is being criticized for implementing too much.

What's the problem with added security, you might ask? (If you are familiar with the situation, you aren't asking this question.) Well, imagine this situation:

I. Put. A. Period. After. Every. Single. Word. In. This. Sentence. And. I. Make. You. Pause. After. Every. Single. One.

You'd want to punch me in the face for writing my blog like that, right? (Fortunately, currently there is no device that allows people to punch me in the face over the Internet, so I feel safe for the time being.) Well, I don't blame you. I'd punch myself in the face, too. (If I fought back, who would be the winner?)

This is like airport security: No liquids! That's too much security you've got there, Mr. Gates. It's not the wrong kind of security: If programs are making changes to the root of your OS, you'd sure as hell want to be notified beforehand! But it's too much.

For a very funny rendering of this situation (and, from various accounts by Vista users, very accurate), click here:

Quicktime video from Apple's Get A Mac marketing campaign

Saturday, February 03, 2007

The Man is censoring me, or something (I better get my tin foil hat)

Just a note. I finally discovered that I can change the date and time of my posts. Oh, the things you learn when you actually look for the answers.



On Friday, my English class went to the school computer lab to work on research for a persuasive essay. The computer lab consists of approximately 35 or 40 computers running Windows 2000. But who can blame school districts for saving money?

Before I go on, I'd like to talk fondly about breaking Windows 2000 security features. Windows 2000 is more insecure than you think. Although admins can block access to certain drives and folders in Win2000 Professional, it doesn't work as well as it should. At my high school, the C:\ drive, which stores program info, is blocked. The block can easily be bypassed by creating a shortcut. This enables users to install everything from Mozilla Firefox to MapleStory, instances of which have remained on the network for months. The only limitation is that software installed can be accessed only on the computer on which it was installed.

And so now I will relate to you the wonders of bureaucracy. By the end of the period, I had compiled a list of worthwhile weeks that I needed to save. I went to my favorite online word processor, Google Docs, with the intention of creating a document full of links. To my surprise, I was greeted with the WebSense warning that the website I was attempting to access was deemed inappropriate under the category "Personal File Storage and Backup" or something of the same nature. Harrumph! I tried to outsmart the filter by going to Writely.com (now transformed into Google Docs); such an effort was held at bay with the same WebSense Enterprise warning.

Frustrated, I did the only thing I could do: Beat the system with irony. And when you're battling WebSense, you need lots and lots of irony. I went to Zoho Writer, another online word processor with whom I had an account, and as expected, this time WebSense was nowhere in sight. Oh, the irony - the delicious, tragicomic irony. I created a new document and saved the links just as the bell rang, and I made it in time for my next class.

A couple periods later, when I again had to use the computer lab for an individual assignment. It was by chance, I suppose, that not only did I get access twice in one day, but both system administrators were in the same room, as well as one of my friends, who had the same problem as I. I approached the admins, having no time restraints on my assignment, and told them that I believed that WebSense was unnecessarily blocking a useful website. I told them about the situation, and my friend chimed in. They checked the site and found the situation I had detailed.

Next, the real kicker came: They couldn't change anything, because the district was in charge of the filter, and the district had chosen to add a bunch of new websites to to the blacklist that very day. You can just imagine me jumping for joy at learning about the tangled web of bureaucrats.

Naturally, I will have no trouble getting around the useless filter by going to a site that does the same thing as Google Docs - until the filter is removed, but there's little chance of the district actually doing anything useful. The irony is that only one online word processor was touched. Just Google Docs. I suppose it must be evil, and everyone is at risk of contagion when people use it. Or something like that. Come to think of it, I can't imagine a situation where the school district has ever proved to be good at much of anything. Did you know that Arizona is next to last when it comes to spending on public education per student? Just one of the nifty things I learned growing up.

Arizona: Come for the warm weather, stay for the... erm... um... warm weather, I guess

Wednesday, January 31, 2007

Worst. Hiatus. Ever.

Well, I've decided that I'm going to take baby steps. I've decided that I want to focus on the Internet. (Wow, what a commitment.) I'm going to not mention anything that didn't happen on the Internet or anything that doesn't have to do with the Internet. (Really creative, huh?) Any mentions of real life will be practically unintentional. So that means I'm not going to talk about politics. (Unless it's Internet politics.) I'm going to show you just how much of a nerd I am. (I hope you're not worried.) By the way, you might've noticed that my most recent blog posts have been shorter and less informative. That's because I've had the nasty habit of writing blog posts in fifteen minutes and publishing a short time later, because I was basically forcing myself to write. I'm not going to do that anymore. I will still try to publish at least thrice a week, but I won't be pushing myself to the point where quality suffers.



So, guess what? Muslix64 has cracked both HD-DVD and Blu-Ray. Cue the obligatory laugh from Nelson. This sentence is here so that I can quote Wikipedia for the third time in three sentences.

Isn't that funny? AACS is this super-advanced content protection system - two legs up from DVD encryption, which was found to literally be comprised of a few bits, which is pretty weak - and some guy discovers a workaround in eight days. Imagine if it takes you a decade to write this really intricate that's bound to win a Hugo or two, and then some reader discovers this big plot hole in the first chapter of three hundred and you no longer have any credibility. This is only kinda sorta like that. You might be able to fix the hole in later publications (if there are any), but for the present you're screwed. So after bypassing HD-DVD encryption, as an encore Muslix64 went on to bypass Blu-Ray technology.

So you'd expect HD-DVD movie rips to spread across the BitTorrent trackers like wildfire, right? Well, no. For one thing, a high def movie file can be as large as 20 GB. Considering that most hard drives are 200 to 300 GB, no one will be downloading very many HD movie rips. Then there's the fact that most people have Internet connections that don't exceed 11 Mbps - Megabits per second, equivalent to ~1.4 Megabytes per second. Consider that one Gigabyte is 1024 Megabytes. If you were to download a 20 GB - 20,480 Megabytes - file without interruption at 11 Mbps - a speed that few consumers ever experience - it would take you at least five hours (under optimal conditions). And would the quality really be that much better than a 700MB DVD rip? Not enough.

While the AACS bypass won't matter much now, look to the future, let's say five years, in 2012. Imagine that Blu-Ray is, or HD-DVD is, or both are, the dominant high-def video disc formats. One in two Americans has a high def movie player in his or her home. Internet Service Providers - don't forget the Internet - are now offering cheap service packages that are commonly 20 Mbps or even 40 Mbps. (I really think that kind of service will come to America, when in Japan consumers can have packages as fast as 100 Mbps.) At 40 Mbps, or 5 MBps, it'll take you less than three hours (again, under optimal conditions) to download 20 GB. You know what will happen then? The movie industry will, once again, be very concerned about piracy.

In the end, the movie industry will not trounce movie pirates. The Motion Picture Association of America has failed miserably at fighting movie piracy. Content producers will again and again try to combat piracy, but to no avail. There is no perfect defense. Devoted pirates will only find the weak points harder to find, but eventually they will be found. That is a matter of fact. It has been proven through the failure of DVD encryption and AACS encryption. It should be noted that a fix to the current AACS problem is eventual - I should be surprised if it does not come. But that fix will, in the end, be bypassed as well.

Content producers are trying to fight an unwinnable battle against smarter foes. The only way to defeat piracy is to make it impractical. The content producers - the movie studios - will have to compete. The market will change, or the movie studios will lose out. As consumer Internet access becomes faster and home computers become more accessible and monitors show better picture, a market will emerge for watching high definition content. And when your choices for watching that content are using expensive video discs and hardware that requires complex encryption verification or a speedy download that requires only your time, the choice will be clear.

Of course, ask someone more knowledgeable than me. (I may be wrong.)