More bad news on the phishing front

Situation is not looking good for the good-guys combatting phishing.

Various toolbars and browser plug-ins were the heralded solution against the plague of emails arriving from Eastern Europe, urging unsuspecting users in badly mangled English to visit a random website and provide personal information. At first it even appared to be working. Then came the signs that not all was well.

One study commissioned by MSFT showed that IE7 was best-of-breed among existing solutions. (Full disclosure: this blogger is employed by Microsoft.) Not to be outdone, the Mozilla foundation, the non-profit organization behind the open source Firefox web browser, conducted its own study and not surprisingly crowned the anti-phishing feature of Firefox 2.0 as the winner. Either study would have been easy to dismiss based on the funding/affiliation.

But then academia took interest in the problem and a group at Carnegie Mellon published a study showing that in effect none of the technologies were very good. Even the best one missed 15% of confirmed phishing pages at least 24 hours into the life of the scam. (Because the average site stays up 4.8 days according to the Anti-phishing Working Group, most of the damage is done very quickly and it is imperative for defenses to kick into action promptly.) Surprisingly the best toolbar in this study was 2004 vintage, an open-source solution developed at Stanford University which relied purely on heuristics and without the benefit of a costly-to-maintain blacklist of known phishing sites. Unfortunately SpoofGuard had its own Achilles heel: it had a very high false positive rate, or classifying legitimate websites as phishing. This is equally damning because a security warning that cries wolf all the time is the one that will get ignored when it is justified.

But there is hope, the optimists could argue. After all the CMU study only considered phishing filters that integrate into popular web browsers and attempt to warn the user when they are lured to a phishing website. That’s not the only paradigm for combatting phishing: a more promising approach gaining popularity involves personalizing legitimate websites for each user. For example, users can choose an image that will appear on their login page, allowing them to recognize whether a given site is the correct one at a glance. PassMark was one of the first companies to commercialize this approach, now use by Yahoo! in SiteKey, as well as Bank Of America and Vanguard.

At least that was the theory. A new paper from Harvard/MIT team appropriately titled “The Emperor’s New Security Indicators” suggests that it does not work very well as deployed. As reported by the New York Times (the fact that this is even covered in NYT suggests how main-stream internet security has become) the researchers found that the majority of users were happy to ignore missing images and provide their credentials anyway.

cemp

TiVo angling for a Big Brother award

“I promise with my hand on a Bible that your data is not being archived and sold, […] We don’t know what any particular person is watching,” he said. “We only know what a random, anonymous sampling of our user base is watching.”

So says the CEO for Tivo, according to a recent article in San Francisco Chronicle. The data in question is whether subscribers are skipping commercials. This is a classic case of having to place blind faith in hardware, or at least in the marketing proclamations of the vendor. The TiVo device sitting in the consumer’s living room certainly has visibility into what is being watched and how often the commercial skip feature is used to avoid going postal over that lame beer commercial again. But what is not clear is whether this information is shipped off the box to headquarters, for data mining purposes and if it is, to what extent it is sanitized to strip identifying information about the original user.

Problem is only Tivo engineers can know for sure– and even they may not have it right. One person’s “anonymized data-set” is another’s treasure find of personal data waiting to be correlated against just the right database to reveal the identity behind each record. For everyone else Tivo is a blackbox. The only sources of information are:

  • Vendor claims, to the extent they are complete and accurate
  • Third-party claims, such as privacy advocates assuming they have better sources of information
  • Information gathered by reverse engineering the device. This is costly and returns on investment can be low. Often vendors intentionally obfuscate their protocol in order to protect their intellectual property. (Conspiracy theorists would argue obfsucation only serves to hide nefarious purpose.)

Tivo is neither unique or particularly significant. The question of whether a device owned by the user is acting against their interests comes up all the time. A deceptive short-cut is that open source software is better because anybody can verify it is working as intended. MythTV instead of Tivo? True– in the trivial sense that, if you went over every line of code and built it from scratch yourself. (Otherwise you are at the mercy of the authors, download sites etc.) That approach does not scale and better trust mechanisms are called for. Marketplace reputation of an established company in principle serves as a check: too many eggregious data collection practices equates to lost revenue. But such dynamics can only operate when there is transparency and competition: when users know exactly how 2 different PVR vendors use their data, and factor this into their purchasing decision. We are far from that level of awareness.

cemp

Mobile USB computing on the cheap (part II)

An earlier post here pointed out examples of companies commercializing mobile USB computing, which promises to roam the entire computing environment, applications, data, settings and all, on a portable USB drive ready for work anywhere. Each one is predicated on use of special software on the USB device and sometimes custom/versions of apps tweaked for roaming. In this second installment, we’ll discuss getting 90% of that functionality with freely available software and zero modifications to apps for roaming.

Key ingredient is virtualization. That term is ambiguous because VT can exist at any level, but in this case we are referring to machine-level virtualization a la VMware, Virtual PC and Xen. These systems create the appearance of multiple, completely independent PCs (called “guests”) on top of a single computer (called the “host”) This has been a very active field in recent years, with lion’s share of commercial R&D efforts focused on server consolidation in the enterprise. Because managed IT environment costs are often directly related to number of physical servers, having one beefy server run multiple virtual machines to replace a handful of dedicated servers translates into directly measurable savings. But virtualization has broad implications and mobility is an obvious scenario. Because a virtual machine is represented by an ordinary file, no different than a Word document or a photograph (albeit a very large one), roaming this file amounts to roaming the computer. Any machine with the compatible VMM can run the virtual machine, which contains all the applications and data the user needs.

As for implementing this in practice:

  1. Grab one of the free virtualization solutions. This author recommends Virtual PC for consumer scenarios, although VMware‘s excellent VMware Player is a second-best, limited by the fact that it can not create new machines. (VMware Server and Virtual Server R2 are also free, but they are more aimed at server/enterprise scenarios.)
  2. Create a new virtual hard disk, type “dynamically expanding” default size is generally sufficient. Use the mobile drive for storing this file.
  3. Create a new virtual machine, also saved on the mobile drive and attach the virtual disk image created in step #2.
  4. Boot the VM and install a new operating system from CD or ISO image. This is the tricky step becuase depending on the conditions of purchase, the new OS may require an additional license. If the idea of worrying about OS licensing and activation frustrates you, there is always a great selection of open source distributions such as Ubuntu variants.
  5. Install virtual machine additions. This allows seamless integration of mouse and keyboard between guest/host.
  6. Install applications in the VM, configure settings as you would on any PC and copy over data. (See earlier point about licensing.)

The mobile environment is ready. Any other PC running Virtual PC– or for that matter VMware Player, which has the impressive feature to import VPC images– can recreate the machine. Since these are both free downloads, that is not setting a very high bar. As backup option, the installers for VPC and VMware Player can be carried around the USB drive as well, just in case. VPC allows working with the machine in full-screen mode where the guest takes up full screen, creating the illusion of dedicated PC. One can even “hibernate” the machine by saving its state on the USB drive on one PC and restoring from saved state on a different PC.

There are a number of limitations to this approach, some of which apply to any roaming solution. The final post in the series will cover these challenges.

cemp

Secret to being “cutting edge” in IT

… is having 5% of market share.

Apple has proven this axiom time and again, by being a marginal niche product with the Mac but successfully maintaining the cutting edge, hip image verses the mainstream PC. (Latest example being the series of hilarious commercials where Tonight Show contributor John Hogman plays the stody PC characters against a hipster Macintosh.) In an interview with Newsweek, Gates railed against the over-simplifed comparison, perhaps for the first time not sparing any words about Apple. Quote:

“I don’t think the over 90 percent of the [population] who use Windows PCs think of themselves as dullards, or the kind of klutzes that somebody is trying to say they are.”

Aside from the inevitable questions about the Mac/PC cultural divide, most of the interview focuses on actual comparisons of Vista verses available functionality in Mac OS X. Predictably the comments drew heavy fire on Slashdot and elsewhere on the blogosphere.

cemp

Searching for database pioneer Jim Gray

Turing award winner Jim Gray disappared off the coast of San Francisco last Sunday and has been missing for 5 days.

Attempts by the Coast Guard to locate him so far have been unsuccessful. A large online community of people from different organizations is trying to help. The blog Tenacious Search coordinates one such effort. Another series of independent efforts center around capturing imagery of the area, both satellite and planes, including Microsoft’s Virtual Earth service which Gray contributed to in his career at MSFT Research.

According to news reports, NASA chipped in by having a civilian version of the U2 spy plane alter its route to provide new pictures of the area. There is also satellite imagery provided by Digital Globe service, which has been uploaded to Amazon’s Mechanical Turk service. Visitors are asked to examine images and mark those that may indicate the presence of an unusual object on the ocean surface, for further examination. Image resolution is about 1M/pixel and the boat would be 10 by 4 pixels.

cemp

Vista, energy and ecological impact of computers

UK Green Party is not happy about Vista.  According to this article from Treehugger, they criticize the hardware upgrade cycle (required to get full benefits) will lead to millions of perfectly usable PCs being discarded in land-fills, complete with their toxic internals.This follows a recent trend of heightened awareness of the impact of IT, an industry that one does not generally think of polluting. After all we are not leaching gold in cyanide pits, anxious to drill the Arctic National Wildlife Refuge or trying to convince consumers they need a 8000lb SUV to remain safe on the road.

But this is not the first time the issue of greenness has been raised. Andrew Shapiro, a law professor at Harvard’s Berkman Center made this point, of all places at an invited talk at Microsoft campus. Pointing out that Linux can run on less powerful hardware than Windows (and therefore achieve better utilization of existing computing resources) he posed the question of whether that makes it a greener operating system.

There is another, recently emerging area where IT has clear impact on the environment: energy consumption in data-centers. With the rise of large scale web-based services, companies have taken to setting up data centers packed with thousands of servers. A server looks nothing like the PC sitting on the typical end-users desk; in order to save space, they are typicall in very compact “rack-mounted” form factor. (Example from Dell website.) This means not only is each server hungry for power, the close proximity places significant demands on the HVAC system to prevent the whole assembly from going up in smoke. Roughly 50% of electricity in the US generated from coal, so the data-center is one example of how straightforward it can be to translate the scale (and efficiency) of a service to its carbon emissions.

cemp

$150: Sony’s price for 0wning a computer

That’s what FTC appeared to be doing when they finally settled with  Sony BMG over the rootkitted-CD incident. (Or as the proponents of DRM might say, “aggressive copyright protection” technology.)

According to one version of the story from Information Week, Sony did not admit to any wrong-doing– standard operating procedure for these deals– but will replace any infected CDs purchased before 2007 and also agreed to compensate customer upto $150 for damages caused by the malicious software. By one measure of market pricing, this is a hefty penalty for root-kitting a machine, considering that PCs by the thousands can be purchased for remote control botnets at better price points in the underground economy. (And at least Sony did not “exploit” the rootkitted machines the way bot-herder will.) On the other hand, one could argue Sony got off the hook too easy considering that a reputable company should never have engaged in practices that exposed users’ computers to risk. It is not clear what consumers will have to do to claim damages. Some users may have receipts from tech support services, others may have wasted hours of their own time trying to uninstall the rootkit and mitigate the vulnerability it creates. How can that loss of productivity be quantified?

cemp

Mobile USB computing– and they are charging what for this?

Mobile computing with USB devices seems to be all the rage these days. The premise is simple: instead of lugging around a laptop/PDA or other general purpose computing device, users only need to carry around a small portable drive which will contain their data and even applications. This drive can be attached to any PC they run into, to recreate the same environment from any machine. Since many people carry around an iPod or other portable media player that doubles as USB drive in any case, the past objection around having to carry around one more gadget is disappearing.

Three commercial examples of this concept in action:

But a closer look at the options raises some questions.
U3 is best characterized as a new application development model, to allow Windows apps to run from a USB drive instead of requiring installation. This is easier said then done because a lot of Windows apps depends on having various resource located on the host PC– for example the registry is used to store configuration. When a random USB drive is attached to the PC and an application tries to run, the components it is looking for will not be there.  (Simply carrying around the installer isn’t going to work necessarily; aside from requiring adminstrator rights on the host PC, it will not port the user preferences.) So there is sizable amount of work required and some componentized applications may not work correctly this way at all. This is one of the reasons list of “supported applications” in U3 is very limited. Don’t look for any of the major productivity applications here. With the exception of Firefox, most are substitutions / replicas.

Ceedo looks very similar. In the basic version, the applications that can be installed this way have to be checked for compatibility one-by-one with the vendor and tweaked as necessary.  This is a closed-ended selection in the “Ceedo Programs Directory” according to FAQ on the website. But there is an “InstallAnything” add-on which promises to allow installation of any application, using the ordinary installer. (No details on how this works.)

Mojopac has a different paradigm: instead of trying to get applications to cooperate with Windows it creates the appearance of machine-within-a-machine, to run all the user applications in a different environment. Because these machine images are large, Mojopac is specifically targetted at using an iPod or iPod mini/nano as the storage device. That works around space requirements but on the downside hard-drive based iPod will be slower than flash drive. Virtualization provides for greater flexibility including full freedom in choice of applications to install on this mobile environment. Of course the customer still needs to have a license for the operating system and any apps they plan on installing in the guest. Interesting enough Mojopac FAQ points out the limitations in the approach used by Ceedo and U3:

“Why do I need MojoPac to install and run applications from a USB Device? Can’t I just do it without MojoPac?
No, this is not possible. You can use a standard USB storage device only to carry data (files and folders). But standard storage devices cannot be used to carry applications. MojoPac uses a lot of Mojo Magic to add portability to off-the-shelf Windows applications… Secret Mojo Sauce!”

And the problem is, this secret sauce is not exactly a well-kept secret. It is called virtualization. It is unlikely that MojoPac is doing whole machine virtualization (a la VMware, Virtual PC/Server or Xen) because the space requirements list 30MB for the base app. But the fact remains that 90% of this functionality is available for free using existing off-the-shelf software.

A follow-up post will discuss exactly how.

cemp

LiveJournal statistics

Most websites dependent on advertising do not disclose detailed information about their userbase. The demographics, number of active users etc. is arguably a key indicator of the business.

LiveJournal takes  the opposite approach with being completely transparent:

http://www.livejournal.com/stats.bml

On this page for example, everybody can learn that out of a total of 12M accounts only about one-sixth are “active” (not defined) and of that fraction only about one-third have updated within the past 7 days. They can also learn that LJ has a very young audience, the distribution peaking at 19-20, women outnumber men two to one, and US residents outnumber bloggers from every other country. For advertisers trying to decide if this is a good way to reach their target demographic, this is very useful peek at the audience.

cemp