Running on empty.

August 3rd, 2010

I’m home and safe, but still running a little behind. I hope to have the DEFCON 18 Day 3 notes up tonight, along with an after-action report on Las Vegas.

While I was on the road, there were reports that Angela Spaccia, the assistant city manager of Bell and the interim city manager of Maywood, had resigned from the Maywood position. Apparently, that’s not exactly the case; the Maywood City Council didn’t accept Spaccia’s resignation at their meeting Monday night. However, they did accept the resignation of Maywood City Attorney Edward Lee. Curiously enough, Lee is also the city attorney of Bell, and states he needs to resign his Maywood position to focus on the issues in Bell.

Obit watch: Mitch Miller.

Morrie Yohai, inventor of Cheez Doodles.

DEFCON 18 notes: Day 2.

August 1st, 2010

Saturday was kind of a rough day at DEFCON 18. But then, Saturday is always a rough day at DEFCON.

I don’t feel it’d be fair to review or summarize the “Extreme-range RFID Tracking” panel; I came in about 20 minutes late. (We lingered a bit over a very good breakfast at Blueberry Hill.) What I was able to gather is that Padget’s set a new record for long distance RFID reading, and that upping the radio power works for increasing RFID reading range up to a point. (Edited to add 8/10/2010: added link to Black Hat 2010 version of paper. Here’s a link to Paget’s blog entry about the session.)

I was not able to get into “Jackpotting Automated Teller Machines Redux” due to extreme overcrowding. (Edited to add 8/9/2010: The Black Hat website has what purports to be MP4 video of Jack’s version of the presentation at Black Hat 2010. I have not sat down and watched it yet.)

I did attend the “This is not the droid you’re looking for…” panel, mostly because I was camping out for the next talk. This panel turned out to be more interesting than I expected; the presenters demonstrated a proof-of-concept rootkit for Android phones that allows you to do all sorts of fun stuff; grab contact information, grab SMS messages, grab location information (all three of these are stored in SQLite databases on the Android), and even make phone calls from the phone. The presenters haven’t weaponized the attack yet, but claim it should be easy to do so.

“Practical Cellphone Spying“: Another nifty panel. Padget discussed the concepts behind IMSI catching, and gave a live demo of cellphone interception on the AT&T network. The key takeaway here for me was that the same technology used by law enforcement to intercept calls is now coming down to the point where it will be wrapped in a turnkey package and sold to people with more questionable motivations. (Edited to add 8/10/2010: added link to Paget’s blog entry which includes slides.)

“How to Hack Millions of Routers“: I went to this because Lawrence put in a special request. The short version is that a large number of commercially available routers (such as those used by Verizon FIOS) are vulnerable to a clever attack using DNS rebinding and load balancing. Heffner has also released a tool that automates this attack. (This is another Black Hat talk that got a lot of attention in the press; the link above includes a copy of Heffner’s white paper which details the attack vector.)

(Edited to add 8/9/2010: I’ve added a link to Heffner’s Black Hat version of this talk, which as far as I can tell, is pretty similar to the DEFCON 18 version.)

I didn’t attend either “Hacking with Hardware: Introducing the Universal RF Usb Keboard Emulation Device – URFUKED” or “Programmable HID USB Keystroke Dongle: Using the Teensy as a Pen Testing Device“. (Edited to add 8/10/2010: added a link to the Teensy project from the Irongeek website. The bottom of that page has a link to the DEFCON presentation. I’ve also added a link to HackerWarrior.com for the USB Keyboard Emulation Device; that directory appears to contain a copy of the presentation, plus code.)

Instead, I left a little early, had a very nice sake fueled dinner at Shabu-Shabu Paradise in Henderson (a restaurant I enthusiastically endorse), sidecars at the iBar in the Rio (sadly, we did not get to play with the Microsoft Surface), and Penn & Teller.

The three of us saw Penn and Teller back in 2006, and we wondered how much the show had changed since then. Mike the Musicologist estimated that about 50% of the show was new; I think the percentage is a little higher than that, but my memory may be faulty. I was not unhappy that they ended the show with the .357 magnums; the bullet-catching illusion fascinates me, and I’m still trying to figure out how Penn and Teller do it. (Jim Steinmeyer’s The Glorious Deception: The Double Life of William Robinson, aka Chung Ling Soo is a very good history of the bullet-catching illusion, and yet another book I strongly recommend to anyone with even a casual interest in the history of magic.)

The other thing we all noticed is that Penn and Teller’s show has become a bit more explicitly political; in addition to the .357 magnum closer, which has always included 2nd Amendment references (and big kudos to P&T for reciting the Four Rules), the show also included references to flag burning, the Chinese Bill of Rights (“What Chinese Bill of Rights?” Exactly.) and the stupidity of the TSA. Penn and Teller even sell the Security Edition of the Bill of Rights in their gift shop for a lousy $5. (Quote: “We want McCarran Airport to be flooded with these.”) Not that any of us were bothered by the politics; I think all three of us lay claim to at least some form of Libertarianism. And if you’re the kind of person who would take offense at Penn and Teller’s politics, I won’t tell you “don’t go”; I’ll tell you “go, and have your world view challenged”.

(I’d also like to give Penn and Teller kudos for keeping gift shop prices low. Both Andrew and I picked up DVDs of the Teller-directed “Macbeth” for only $10. Teller, if you’re reading this, thanks for signing my copy. And for everything else you do, too.)

Computers. You know, for kids.

August 1st, 2010

We would also like to draw your attention to the Statesman‘s profile of Ken Starks and the HeliOS project.

The HeliOS people take in donated computers, refurbish them, put LINUX on them, and then get them into the hands of poor kids whose families can’t afford to buy computers.

Frequently, these families also can’t afford Internet access, which is the next big problem that the HeliOS people are trying to solve; so far, they haven’t had much luck with that.

Art, damn it, art! watch (#13 in a series).

August 1st, 2010

We take a brief break from DEFCON 18 coverage to bring you the following link, by way of Popehat.

Brandon Bird, the man responsible for “Law and Order: Artistic Intent” (previously mentioned in this space), put together another “Law and Order” themed exhibit in Los Angeles: “These Are Their Stories“. Each of the various pieces in this exhibition, as Bird describes it, “is an artist’s interpretation of a one-line episode summary from the DirecTV program guide”.

We have not had time to go through the entire series of works, but we are particularly taken with “Goren Takes on a Chess Master“, and are tempted to order a print. “Detectives Look for a Racist” also makes us grin.

DEFCON 18 notes: Day 1.

August 1st, 2010

I’m running a little behind, between running around with Andrew and Mike the Musicologist, and some technical issues (DEFCON 18 has a secure wireless network, but it hasn’t been stable), but I’ll post updates when I can. I’ll also add links to the presentations as they go live, or as I find them. If you have questions, I’m willing to try to answer them, but I’d suggest you email the presenter first. If you are a presenter who wants to respond to my comments, I welcome that.

“Build a Lie Detector/Beat a Lie Detector”: This was the first presentation I attended; it was a pretty awful one. The presenters started 15 minutes late and opened with a crappy rap performance (differing tastes in music, fine, but when you’re running 15 minutes behind schedule, the rap should be the first thing to go). Once they actually got going, they spent too much time on a general history of justice systems and of the polygraph. When they did finally get to the technical aspects of their presentation, it amounted to “Oh, yeah, we built this lie detector based on this paper these other guys posted” (with, to be fair, some minor modifications). I walked out of this presentation before the end, which is something I rarely do at DEFCON.

“Build your own UAV 2.0 – Wireless Mayhem from the Heavens!“: On the other hand, Renderman and his partner did an excellent job with this one And not just because they played “Thunderstruck” before the presentation started (playing music is okay, even if I don’t like your choice of music (and I like “Thunderstruck”), as long as you start on time), or because they started on time, or because they actually had video of their UAV launching rockets. (Edited to add 8/10/2010: added link to DEFCON 18 slides and video on Gremlin’s website.)

Key takeaways for me from this one:

  • You have two choices for stabilization systems. Thermopile based systems work in the infrared range and are very cheap, but have problems in certain weather conditions. Inertial based systems are more expensive, but offer all-weather capability, and are rapidly coming down in price.
  • Arduino based control systems dominate at the moment, but there’s some interest in developing systems based on the Beagle Board.
  • There’s off the shelf Zigbee based hardware that can easily be used for telemetry, and offers a 10-12 mile range.
  • You can get cheap and decent video out of board cameras, but transmitting video is a harder problem; for good range, you need to work on frequencies that require an amateur license.
  • GPS systems with a 10 Hz refresh rate are down to $80 or so. Most of the GPS systems I’ve dealt with have a 1 Hz refresh rate, which isn’t good enough for UAV use; it was news to me that faster systems are that cheap now.
  • Foam airframes are cheap and easy to repair.
  • Practical UAV applications, other than launching rockets; warflying with kismet, communications relay (imagine a UAV that could hover on station and serve as a repeater in areas of poor radio coverage), search and rescue (imagine a UAV that could survey a wide area looking for signs of a lost hiker, or recon an area where a search and rescue beacon was picked up), and post-disaster recon. I hadn’t thought much about that last one, but now that Renderman’s brought it up, I find that exciting. The theory here is: you send your UAV into areas that your disaster relief staff haven’t physically visited, and it returns good quality imaging of exactly what the damage is and how accessible the area is (have the roads collapsed? Are they under water?). From that, you can develop priorities (damage in this area doesn’t look too bad, we can hold off for a day; these people look like they need immediate help) and plans to get needed resources into the area.

“Exploiting Digital Cameras”: Another solid presentation. Basically, Isacson and Ortega did some clever banging on the firmware of the Canon Powershot series of cameras, found that these cameras have an embedded interpreter, documented that interpreter, and developed some simple exploits using it. The exploits are somewhat limited; you can’t launch malware on an attached computer, for example, but you can do things like turn on the microphone, display arbitrary images on the camera, and modify EXIF data.

“DCFluX in: Moon-bouncer”: A decent presentation on the theory and practice of radio communication using moon-bouncing, satellites, and other methods. I’m going to gloss over the details of his talk and refer you to the presentation when it goes up, as there was a great deal of technical information in it related to historical and amateur radio usage; I’m not sure the majority of my readers are that interested in ham radio, and those who are would be better served getting their information from the source.

“Black Ops Of Fundamental Defense: Web Edition“: So here’s a high-level summary of Kaminsky’s talk. Now that the DNS root certificates are digitally signed, we have the ability to use DNSSEC and the Domain Keys Infrastructure (DKI) to do all kinds of cool stuff, including end-to-end email authentication (so you can be sure that the email you got from Bank of America is actually from Bank of America, and not from some random Nigerian), and to do these things in a scalable way.

Kaminsky’s new company, Recursion Ventures, is building (and plans to release shortly) a set of tools that will allow for the easy deployment of DNSSEC. Kaminsky also gave a brief overview of how DNSSEC works, and touched on a few interesting points related to his research. (For example, not only is it possible to run DNS over HTTP, but Kamisky’s figures show performance over HTTP is actually better than normal DNS.)

(Edited to add 2: The link above goes to a page on Recursion Ventures web site where you can view the slides from Kamisky’s version of this talk at Black Hat 2010. I did not see the Black Hat version of this talk; I do not believe the DEFCON 18 version was significantly different. It may have been shorter, and there is some Black Hat specific material in those slides. Also, I’m aware the actual title (“Black Ops of Fundamental Defense: Introducing the Domain Key Infrastructure”) differs from the title in the DEFCON 18 schedule; I chose to stick with the DEFCON title to make cross-referencing easier.)

Edited to add: I’m sorry if anyone is disappointed, but I did not go to the “Weaponizing Lady GaGa, Psychosonic Attacks” panel.

Brain, brain, what is brain?

July 30th, 2010

After the jump, and especially for Lawrence, some photos I took last night while running around with Mike the Musicologist.

Read the rest of this entry »

0 Day DEFCON 18 notes.

July 29th, 2010

This year, I got in on Wednesday, which reduced the stress level considerably. Mike the Musicologist met me here; Andrew “Swordfish Trombone” Wimsatt is flying in tonight.

Mike and I had a pretty good (and cheap!) dinner Wednesday night at Four Kegs, which some of you may recognize from “Diners,  Drive-Ins, and Dives“.

DEFCON 18 panels that I may, or may not, attend, but will point out for Lawrence‘s benefit:

“Weaponizing Lady Gaga, Psychosonic Attacks”

I’ve already missed the “Hardware Black Magic: Designing Printed Circuit Boards” and “Go Go Gadget Python: Introduction to Hardware Hacking” panels, but I figure most of the information from those is on the DEFCON 18 CD.

Panels I want to attend:

I’m torn between the annual “Making of the Badge” panel, and the “How To Get Your FBI File (and Other Information You Want From the Federal Government)” panel. If I do get moving that early, I suspect I’ll end up at the latter one.

“Build a Lie Detector/Beat a Lie Detector“. My desire to attend this is mostly based on nostalgia. When I was a young boy, my dad gave me several of the Radio Shack 50-in-1/100-in-1/250-in-1 electronic kits for Christmas. One of the projects in those was always a lie detector, and I always built that project.

“Build your own UAV 2.0 – Wireless Mayhem from the Heavens!” How could anyone not go to that panel?

“Exploiting Digital Cameras“. Another panel that seems designed to push multiple buttons on my user interface at once.

“DCFluX in: Moon-bouncer“. Looks like it could be a fun panel on alternative methods of communication in a critical situation, like moon-bounce (something I’ve heard of from the amateur radio community).

“Black Ops Of Fundamental Defense: Web Edition“. Dan Kaminsky. Again, enough said.

“Extreme Range RFID Tracking“. I haven’t gotten that deep into RFID hacking yet (though I might change that this year), but I’m interested in this long-range low-power radio device stuff. Also, this is one of two Padget talks I want to see.

“Jackpotting Automated Teller Machines Redux” The Black Hat version of this talk is already getting a lot of attention.

I’m having trouble deciding between “This Needs to be Fixed, and Other Jokes in Commit Statements“, which sounds like it could be very funny, and “Insecurity Engineering of Physical Security Systems: Locks, Lies, and Videotape“; I have a lot of respect for Tobias’ work.

“Practical Cellphone Spying” is the other Padget talk I want to see.

“We Don’t Need No Stinkin’ Badges: Hacking Electronic Door Access Controllers“: besides the title reference, this might make good background for that novel. I’m also considering “Wardriving the Smart Grid: Practical Approaches to Attacking Utility Packet Radios” as another possibility; I’d really like to see both.

“Physical Security : You’re Doing It Wrong!” Well, if he’s going to talk about how to get vendors to take you to lunch, sure!

“Physical Computing, Virtual Security: Adding the Arduino Microcontroller Development Environment to Your Security Toolbox“. I’ve been thinking about getting into microcontroller hacking, and this seems like it might be a good introduction to the Arduino (which is one of the environments I’ve considered).

“Hacking with Hardware: Introducing the Universal RF Usb Keboard Emulation Device – URFUKED” and “Programmable HID USB Keystroke Dongle: Using the Teensy as a Pen Testing Device“: it sounds like there could be a lot of overlap between these two panels.

“The Search for Perfect Handcuffs… and the Perfect Handcuff Key“. You never know when you might need to get out of a pair of handcuffs…

I haven’t decided between “Attack the Key, Own the Lock“, which sounds like it may be a rehash of some panels at previous DEFCONs, and “Constricting the Web: Offensive Python for Web Hackers“, which pushes the Python button.

“Electronic Weaponry or How to Rule the World While Shopping at Radio Shack“. Not a lot of information on the DEFCON site; I’ll probably go and leave if I get bored.

“Breaking Bluetooth By Being Bored“. I’m fascinated by Bluetooth attacks, so this is a must-see for me.

Panels I won’t be attending:

“Getting Root: Remote Viewing, Non-local Consciousness, Big Picture Hacking, and Knowing Who You Are“. The usual hippie horse-pucky.

Any suggestions from anyone else who may be attending? Or presenting? Or wanted to go, but couldn’t?

Don’t worry, Gene Weingarten will write an appreciation for him.

July 28th, 2010

I had intended to note the passing of John Callahan, but could not find a good obit while I was compiling last night’s death watch.

Fortunately, Gene Weingarten has a very good appreciation of Callahan and his work in today’s WP.

There’s also a good obit by the reliable Bruce Weber in today’s NYT.

Death watch.

July 27th, 2010

Maury Chaykin, actor. He was Nero Wolfe in the A&E series, I believe, and was in a lot of other stuff. Including “War Games”, “Dances With Wolves”…and, well, “Meatballs III” and “Overdrawn at the Memory Bank” (if anyone remembers that MST3K).

(Hattip to FARK.)

Jack Tatum, safety for the Oakland Raiders, remembered for the hit that paralyzed Darryl Stingley. According to the linked article, Stingley passed away in 2007. (Edited to add: NYT obit.)

(Hattip to Patrick at Popehat.)

I baked you a cake, but I eated it.

July 27th, 2010

I’ll be on the road tomorrow, but I did want to note that it is the one year anniversary of Whipped Cream Difficulties.

I’d like to thank Lawrence, Earl, Mike the Musicologist, the crew at Popehat (especially Ken and Patrick), Jay G., Cranky Prof (who I will pour out a 40 for; seriously, Cranky Prof deserves a much longer thank you from me, and I hope to write that someday. In the meantime, I hope she’s out there somewhere terrorizing the stupid and being the shepherd of lost souls.), the rest of the Friday Night Dinner and Saturday Dining Conspiracy gang, and the members of the Academy. I’m probably forgetting some other folks who also deserve thanks; sorry about that, chief. Drop me a line, and I’ll update.

Edited to add: Joe D., too.

I would tell the Google Ads people what they could do, but my mother has been known to read this blog. Suffice it to say, it involves a rusty fence post, a mile of barbed wire, an uncomfortable place, and no lubricant.

There’s a man who wants to get ahead in the military…

July 27th, 2010

By way of Say Uncle, we learn that a Gurkha private with the 1st Battalion, Royal Gurkha Rifles, is in a spot of trouble.

It seems that his unit was dispatched to take out a Taliban commander, and intelligence wanted proof that they had killed the right man. They accomplished the mission, but came under heavy fire. Rather than lugging back the entire body, our man used his kukri to remove the head. You know, a convenient travel package.

For some reason, this upset his superiors, and various other folks.

This is considered a gross insult to the Muslims of Afghanistan, who bury the entire body of their dead even if parts have to be retrieved.

I have this to say on the subject:

Tiny violin. Let me play it for you.

Another guilty pleasure.

July 23rd, 2010

This FARK thread and this post by Glen reminded me of another guilty pleasure of mine: Bonnie Tyler’s “Total Eclipse of the Heart”.

More specifically, this version:

and this version:

I feel guilty, oh so guilty…

July 23rd, 2010

All the cool kids are doing it, so I thought I’d throw my chapeau into the washing machine. Hence, a list of my guilty pleasures:

  • “Cops” and “America’s Most Wanted”. I actually find AMW to be a kind of a amazing show in the sheer perfection of the idea; put a show on the air that’s impossible to cancel. If Fox ever did try to cancel it (and they did, once. Once.) the howls of outrage from law enforcement would be heard from coast to coast. John Walsh is right at the border of getting on my last nerve, though (especially given his ignorance about guns) so I don’t want to spend a lot of time on the show.

    “Cops”, on the other hand…well, I can’t explain the strange attraction of that show to me. I’d like to think it isn’t a “there but for the grace of God go I” sort of thing; no matter how low my social circumstances go, I don’t think you’ll ever catch me wearing a wife-beater and drinking a Bud Light after thumping some on my woman. It may be that there’s just a dark part of my soul that enjoys seeing stupid people in trouble.

  • The music of the not-so-late C.W. McCall. Especially “Convoy” and “Wolf Creek Pass”. I have fond memories of riding around in our old Chevy Suburban with the 8-track tape player, listening to a Radio Shack tape of trucking songs that included “Wolf Creek Pass”, “Phantom 309”, and “The White Knight”. (Anyone else remember those last two? I’m probably dating myself. But then, no one else will.)

    As for “Convoy”, let’s just say that I used to have a 45-RPM record of that song that I literally wore the grooves smooth on. Yes, it is on my iPod.

  • The “Dirty Harry” movies. At least “Dirty Harry”, “Magnum Force”, and “Sudden Impact”. I’ll actually defend “Dirty Harry” as being a lot more subtle and sophisticated than people like Roger Ebert think. I don’t see it as a fascist film; I see it as a movie about a good man, struggling to do a job, and dealing with a new set of obstacles society has put in his way. Indeed, I think it could be argued that “Dirty Harry” is a modern remake of “High Noon”, right down to the last scene. (I’m pretty sure Harry throwing his badge into the water is a direct homage by Don Siegel.)

    “Magnum Force” I’ll also defend as an answer to the critics who claimed Harry was a vigilante, and the people who said “So what? Maybe we need vigilantes these days.” I see “Magnum Force” as a movie that’s explicitly about the rule of law, and the need for same.

    “Sudden Impact”…well, I really can’t defend that as anything but fun. “Smith…and Wesson…and me.” “Go ahead, make my day.” The dogshit speech. (Another shameful confession: I also have Clint Eastwood and T.G. Sheppard’s duet, “Make My Day”, on the iPod.)

    I won’t defend “The Enforcer”, and I’ve heard so many bad things about “The Dead Pool” that I haven’t watched it yet.

Important safety tip.

July 23rd, 2010

If you’re going to cheat, don’t be stupid about it. Try to show at least a little intelligence.

I draw my example today from the L.A. County Sheriff’s Office, which has a bit of a problem. LACSO wants deputies in the jail to check on the inmates regularly, just to make sure none of them have decided to hang themselves, or are getting beaten to death by Bubba. So they have a system of bar code scanners around the jail; deputies are supposed to use those scanners to scan their assigned bar code as they make their rounds.

But the county Office of Independent Review reported that investigators found some deputies had copies of the codes on sheets of paper. Instead of doing the rounds, the deputies scanned the codes at their desks.

How did they discover this? Well, one of the inmates killed himself, and records showed that a deputy had been making his regular rounds. When the investigators dug a little deeper into the records…

…they discovered that computer records showed the deputy scanned several parts of the jail in 35 seconds — a physical impossibility.

…

As they investigated further, officials found that the deputy who was on duty during the suicide also went to the staff gym and made a “chow run” to a nearby restaurant on the day of the suicide when he should have been making his rounds, the report says.

Ask not for whom the Bell tolls…

July 23rd, 2010

The three top administrators of the city of Bell, California, agreed to resign yesterday.

These are:

  • the city manager, Robert Rizzo, who was pulling down $787,637 a year (leaving at the end of August).
  • the chief of police, Randy Adams, who was making $457,000 a year. (Adams also apparently will stay through August, “after completing an evaluation of the Police Department”.)
  • assistant city manager Angela Spaccia, $376,288, leaving at the end of September. Spaccia was also serving as the acting city manager for the city of Maywood. Remember Maywood?

Yesterday’s LAT also had a survey of recent municipal corruption in the area around Bell. Some high points:

  • the Lynwood City Council, which was indicted in 2007 for using city money for personal ends, including hiring strippers.
  • South Gate, “a reign of governance so flamboyant in its nasty badness that ‘South Gate’ became shorthand for corruption and politicians gone wild.”
  • Vernon, where the city administrator was pulling in $600,000 a year, got hit with a corruption indictment, and retired “with a record-high state pension of $500,000”.

Edited to add: Oh, look! Robert Rizzo also faces drunk driving charges! (Hattip: Reason “Hit and Run”.)