skip to main |
skip to sidebar
Todd Schriber is US Rep Rehberg's press aide (he has since been fired). He contacted attrition.org (of all places) to try to solicit a hacker to change his GPA. What follows is a truly classic piece of social engineering. It includes a reference to the Avian Network Protocol (RFC 1149), pictures of squirrels, and has the best movie-style hacker-babble I've ever seen.
Shouldn't need anything else. Have had a chance to set up a couple of IDS/IPS evasion bots, perimeter scanning came up clean. Small SQL injection issue merged with XSS shows that the backend database may be either 768-bit encrypted or a simple 3DES matter, but a little more time should take care of that issue. Once the tables are writable to sa, should be ready to jump in and jump out with no problem. One of their systems caught an early sniff, but was shut down with a smurf.
For the non-technical: trust me, the above makes absolutely no sense whatsoever. Which makes it funny, because good old Todd swallows it hook, line, and sinker.
This is a pretty interesting article about robotics, intelligence and inherent rights.
Robots and machines are now classed as inanimate objects without rights or duties but if artificial intelligence becomes ubiquitous, the report argues, there may be calls for humans’ rights to be extended to them.
It seems they think around 2056 we will have seen the birth of self aware synthetic intelligence. While their report raises some tricky ethical and moral questions, I have to wonder just how optimistic they are being with their estimates. Remember, we were supposed to have conquered this realm by now.
I suppose I cannot fault them for their predictions (and looking past those predictions to the impact on society). There is a school of thought that intelligence is emergent. That is, interactions between simple mechanisms become more and more complex as the scale increases. At some threshold of scale, the level of complex behavior appears to self organize and produce resultant interactions that cannot be predicted by extrapolating the behavior of its fundamental parts. Typically, this is called Strong Emergence (it's hard to see how Weak Emergence could give rise to intelligence). And as we can all testify, our computers, phones, entertainment systems are becoming more and more complex every day. So there is something to be said for this becoming a possibility due to the seemingly geometric increases we see happening.
Materialists (in the most broad sense) say our brains are purely algorithmic in nature and the mind is simply an artifact of an extremely complex machine. Forget free will. There is no such thing here. Everything is ruled by stimulus/response. Even our innermost thoughts. Hell, even this little essay has been determined by past experience and external stimulus. And every word could have been accurately predicted given a complete mathematical model of my brain.
This is called Biological Naturalism. At its core, it's a rejection of the duality of the mind and body. Given a sufficiently complex model a simulation will in essence no longer be a model but an independent, self-aware consciousness. Of course, the creation of this kind of system would make accurate weather modeling (still out of our grasp) seem simple by comparison. In essence we would be building a brain.
There's another idea in the materialist camp. That the form is much more complex than we can ever hope to understand. That intelligence is intrinsically wedded to quantum mechanics. Roger Penrose goes on about this in some of his writings. With a clever application of Gödel's Incompleteness Theorem and the halting problem (knowing when a series of equations is infinite or unsolvable), he posits that while consciousness ultimately arises due to structure, it is beyond what we will ever be able to deduce due to the fact that we can never have a complete and consistant model. The ability to understand, much less create, self-awareness will forever be out of reach thanks to Gödel. This idea is very controversial and I'm not touching it with a ten-foot pole. Plus the math is way beyond me (and I'm talking many light-years beyond).
I'm going to touch on simulation in this case. Barring any major breakthroughs in nueroscience, our understanding of chaos, and fast analog, multi-state computers (or quantum computers), simulations will most likely be pale imitations of homo sapiens sapiens.
But, if a simulation is convincing enough to pass a Turing Test, we start moving out of the shallows of epistemology and into the deep scary waters of existentialism. Here, we question the validity of robotic rights. Would the concept even apply for pure simulations? Or would we be using these simulated beings as a mirror, trying to put limits and restrictions on our seemingly inherent brutality and callousness?
These are questions that will most likely never be answered. Nor should they, really. It is the searching --the blind groping --that make it worthwhile. It's what we trip over and discover, in our own ineffable, blundering way, while trying to answer the unanswerable. What we discover there --those are the real treasures of humanity.
However, there are greater, more pressing questions that we should begin to ask ourselves before it becomes moot. How will we relate to a created intelligence? What common ground can we have, given the wildly different environments?
And even more fundamental: Would we even be able to recognize the existence of an intelligence that would be so completely different from our own?
My day job is in Information Security. Normally, I don't talk so much about that here. I get more than enough of that topic during work and with my off-hours research.
That being said, I would like to address an article that was linked to in one of the myriad of security related mailing lists I belong to. The article in question is by Greg Meckbach in IT Business titled There are only two IT network security issues.
Just from the title alone I could see I was going to have issues with this article. Some of the points are valid, such as the fact that physical security is not the domain of Information Security. Except he talks about IT managers not specifically Information Security (which is an entirely different beast). What follows is a post I sent to the security mailing list I got the link from. I have changed it somewhat, due to the fact that I am grammar impaired and I have had more time to think on this topic. However, the primary point I was trying to make is unaltered.
I agree with some of what Mr. Meckbach said, but a couple statements he made struck me as wrong (or perhaps mislabelled).
If a criminal could steal something as a result of hacking into a network, that again is a management problem. It's the manager's job to make sure sensitive information is not stored on accessible drives.
Wouldn't this fall under the category of "spying", which he specifically names as one of the two concerns?
Anyway, what does he recommend "management" do? (and which management? Operations, IT, HR?) Reduce the distribution of sensitive business information to sneaker-net? Create a secondary network which would require multiple NICs and custom config to guarantee one network cannot see another (even then, comprise a dual homed host and even that's useless), or require users to have a separate workstation for each isolated network?
The fifth issue - compliance with securities regulations - is supposedly one of the security problems with instant messaging, because some IM programs do not have an archiving capability, which would allow investigators to check every record of an employee's correspondence.
While this may be a problem, it's not a security problem. Letting employees communicate, without monitoring that communication, is the business manager's problem, not the IT manager's problem.
Mr Meckbach seems to be confusing IT management with Information Security. Yes, the decision to archive and monitor IM may ultimately be an executive-level decision, but the implementation is most definitely the communications group's responsibility (which would fall under IT). The actual risk assessment and use of mitigating controls in an attempt to pro-actively prevent or limit the type of information transmitted using IM, without a doubt, is an IS concern.
For any business that is concerned about these things, risk assessment is a major part of the security framework. And a company's Information Security team plays a large part in risk assessment and mitigation. IS's primary function is to allow the business to conduct it's day-to-day operations with as little risk as necessary. IS involves more than just securing a network and attached hosts.
Information Security is about information. While the majority of IS does involve technological systems and solutions, it also involves things like standards and practices, security policies, compliance, and risk assessment. I have seen the attitude expressed in this article before, but usually it comes from people that don't seem to understand the security is not an end unto itself. It is the means in which a company can conduct its business with relative safety.
While I do believe a line to be has to be drawn somewhere (unless we want to drown in unnecessary work), Mr. Meckbach seems to have a too strict a definition of what IS should encompass.
Dear Santa,
I've been a... relatively good boy all year.
Please send me:
One of these.
And one of these.
Oh, and one of these, as well.
And I better get them, fat man. Or do you want Mrs. Claus to hear about the after-Christmas party at Scores, Chicago. Or the special present you gave to Brandi-with-an-"i"?
Just a quick roundup of tech news.
New Releases
Firefox 2.0 is scheduled for release later today. Not sure on the exact time, but keep checking the site.
Fedora Core 6 (Zod) was released today. It appears the Fedora Project site is down for the count right now. I'm guessing it got hammered by everyone trying to be the first to download the installation image.
Ubunutu Linux 6.10 (Edgy Eft) is scheduled for release on October 26, 2006.
Expect An Uptick In Epileptic Seizures
Here's a raincoat that has flickering lights activated by rain hitting sensors embedded in the nylon.
Quantum Malware
It appears people are already thinking about ways to infect the new breed of computers. Still conceptual, but hell, so are quantum computers.
This has got me a little concerned.
On October 17, 2006, an Islamist website posted a message titled "You Can Spy on the Enemies' Airports Directly by Controlling the Cameras' Direction." The message contains a link to a screen showing what it claims to be a live view of various areas within Anchorage International Airport via several cameras (http://209.193.48.89/view/index.shtml). The message gives directions for how to control the cameras and promises to provide links in the future for other airports as well.
The sample screen-shots on that page are from "Ted Stevens Anchorage International Airport". I thought one of the requirements of having a place named after you was being dead (or is it for his father?)
The TSA and Homeland Security like to tout their initiatives to prevent unlikely movie-style terrorist plots and waste time foiling unlikely binary explosives. How about they spend just a teeny amount on securing our nation's airport computer networks?
The new arena of war and agression is the Internet. And the new special forces in this theater are the hackers (for good or ill).
And if you don't beleive that Islamic terrorists do not have people actively attacking our network infrastructures... well, I have a bridge in Alaska I want to sell you.
Well, ended up having to restore my computer last night. I was running FC5, just playing with some VMs and... well, I'm not sure what it was, all I know is it disappeared. I had installed it a couple of weeks ago over an Ubuntu Dapper install. Mostly because I have had a love/hate with Red Hat way back since the (in)famous Halloween release v0.9* (remember the bat?). I just had to try it out. I'm used to the hierarchy in /etc (although debian-style is not all that different), and the artwork in the default GNOME theme and icon set is fantastic.
Fedora 5 is just... sluggish. I'm not sure why. I had the same network drivers, the same kernel version, the same Nvidia drivers as my Dapper install. It just seemed slow. And there were packages Fedora used to have that it phased out. There was also a lot more manual configuration than I remember. Everything was stable (or so I thought), but I just couldn't squeeze anymore speed. GNOME acted like it was on Valium. Anyway, it died.
Thank god I back up /home.
So I decided to switch back to Ubuntu. That was a bit more pain than I wanted. I have never had a problem installing Ubuntu on either my desktop or my laptop.
Last night it decided to be contrary. Of course the first part was my fault. I though I'd give Edgy Eft a shot, even though it has not been officially released. Well there's a reason it's not released yet. It started complaining that the modules it was trying to load off the DVD did not match the kernel the DVD booted with. Huh? Screw it. I'll just do Dapper Drake, the latest official release.
Everything went fine. Added my extra apt repositories without a problem. Got my wireless up and working with WPA2. Synced my Firefox bookmarks and cookies using this great extension. Got my win32 codecs, libdvdcss2, mp3 support. Everything I like to have on my machines.
And then, we get to the Nvidia card. Something I have never had a problem with before. For some reason, the nvidia driver in the repository kept thinking my card was an ATI (but it still tried to load the nvidia Xorg driver). Weird. At one point I was going to manually install the driver, but then realized what a PITA that would be when I tried to update either the Kernal or X. Plus, one of the reasons I went with Ubuntu is so I don't have to muck around with config files and kernel modules.
Finally got it working around 1 AM so all is well in the world.
*Holy crap! I just looked up the exact date of the Halloween release. 12 years ago... I've been messing with Linux that long. I'm getting old.