Showing posts with label just my 2 cents. Show all posts
Showing posts with label just my 2 cents. Show all posts

2012-08-24

The WOW Factor

I remember the first editions of VMworld: technologies like vmotion and FT made you just standing still thinking "WOW!".
That "WOW factor" had faded away in later editions: virtualization technology is now a consolidated thing and I've not seen anything really breathtaking.
The last two editions were really all about the cloud (yawn!) and just some other little incremental improvements.
Finally, I saw something that could bring a revolution in the way virtualization clusters are built:
SimpliVity Omnicube and Nutanix Complete Cluster.
It's WOW time again...

2012-03-18

Who controls the remote control?

Would you click on allow?

The original story is about exploiting free product support by trying to sell premium support on non-existent issues.
Would you allow a complete stranger full control over your PC?

I've made some tests myself with two of the most prominent remote support offering: WebEx and Teamviewer.
WebEx does not allow unattended download of files: each file should be explicitly shared by the owner.
Teamviewer, instead, allows full filesystem access, and a file transfer request from the controlling end, opens a notification window on the remote side with full logging. Sadly that window can be minimized and can be easily ignored by a less expert user.

I'm not saying here that Teamviewer GmbH will exploit your computer, but there's a chance that someone using it, could.

So much for the corporate level support, but there is a whole market for personal connectivity.
I was browsing the appstore for an RDP/VNC app to control my PC, and I saw that there are plenty. Some of them even require you to install an host component on the target PC. Apparently this trend has been fueled by Microsoft, by disabling Remote Desktop on the Home edition of the latest Windows versions.
What kind of guarantee the user has that the host and the remote app don't do anything suspicious?
Most of them, don't even connect directly the client to the server, but use some kind of external gateway, to overcome NAT issues.
This a classic man-in-the-middle scheme.
Do you trust their encryption?
Do they keep a copy of your remote control session?
Nearly all of this remote control apps have file transfer capabilities:
Once you have given full access to your pc, how much it takes for the "man-in-the-middle" to download browser history, password cache, "My Documents" folder?

So, by looking at my cristal ball, I may say that the next wave of phishing malware will come in the form of free remote control tools.

2012-02-26

Behavioural Adaptive Driving



Lately I'm being interested into hybrid cars.
It seems that you can optimize your fuel consumptions with some careful driving, like anticipating an impending slope or recovering energy from braking before a stop.
I think there's some room for improvement: with a GPS, a street map with altitude information also, and by recording usual routes with an onboard computer, the system may suggest actions or even control the engine to cope with incoming kinetic energy demand or surplus.
So, by learning daily commute habits, the system may know that 500 meters from now, you're going to brake at a crossroad, so it may be possible to stop the engine from charging the battery, as it will be charged anyway by the impending brake.

I'm just writing it here now, so I can become a patent troll in the next few years when this idea will be implemented.

2011-12-31

IPv6

The end of the year is time for some balance.
Even though I'm no network admin, knowledge of IP networking is the single most used technical skill in my day-to-day activities.
So, good will for the next year:



2011-12-19

The most influential book from my bookshelf

The UNIX Programming Environment, by Brian Kerningham & Rob Pike.


This is the only book from school I still read from time to time.
It wasn't even a mandatory one: just a suggested reading for the computer science lab back in '89.
The title is somewhat misleading: it's not about programming as much as about philosophy.
I can actually say that this book has somewhat shaped my way of thinking.
It's worth reading even for people that doesn't work on unix machines: the Bladelogic Network Shell is based on these concepts as well.

2011-10-29

The most important lesson from Steve Jobs

I've stayed well away from all this Steve Jobs mourn-mania, but there's one thing I owe him.
He showed us that you can do business without wearing a tie.



Sure, you have to wear a big personality instead.

2011-10-15

Pioneer One

Sense of wonder and food for thought.
This is what good Science Fiction should be all about.
Pioneer One is a web-only TV show that's worth watching.

2011-10-13

Dennis Ritchie (1941 - 2011)

One of those obscure heroes that might will never receive the recognition they deserve.
I've found this little gem on slashdot

main()
{
    printf("Goodbye, World");
}

He may not have been glamorous and "visionary", but indeed he shaped our world to a great extent.

2011-10-08

The zip lockscreen

Look at this Android lockscreen:


it may be stylish and minimalist, but do you think that your grandma could understand that she need to touch the circle and drag it around?
This is a geek oriented lockscreen, not one targeted at the mass market.

The iphone lockscreen is lightyears ahead:


I've seen children unlocking the phone the first time they've seen it without anyone telling them how.

I think Android needs an equally strong UI metaphor to appeal to a broad user base.
What can you use to convey the sliding action?
Take a look at this (badly) photoshopped (actually GIMPed) proof-of-concept:


I bet even the most techno-phobic can understand that he needs to pull and slide the zip.

Note: at the first try I've used the image of a zip from a blue jeans, but the risk of a two-way joke was too high, and that's not the spirit of this post.

2011-10-06

Ubuntu Unity

While I like the bravery of trying something new in the GUI field, I think there's some overshooting in Ubuntu Unity.
Merging the menu bar with the title bar can save some screen estate in full screen applications:
look at this maximized terminal window.
A full row is gained by merging the menu and the title, and the menus are accessible as before: by going up and pressing the right mouse button.


Problems arise when using the terminal at its native size and get worse if you put the window in the lower half of the screen: to access the menu you have to travel up half the screen with the mouse.


I'd propose to keep the menu bar attached to the window while not in maximized mode.

2011-10-03

Bad Design


Look at this sign:


Warning: wet floor.

But if one does not understand italian, what would he see? A string puppet? Or a man who's falling, but not because of the water on the floor: because he's beeing pulled from his feet with ropes.
In comics, the movement effect is done with lines that follow the subject in his motion, they don't trail it.

Look at this one, courtesy of http://www.chumpysclipart.com/


This one is really falling.

2011-09-10

Doom Architecture

An ex-colleague/ex-classmate of mine has coined the term "doom architecture" looking at real world places that seem to be designed with a game level editor.
I support his "pursuit of ugliness" with this evidence.
It might belong to the technogothic Quake 1 style.

2011-09-04

Keymap-independent passwords

On my job I have to remotely administer a lot of servers, using every kind of access method: VNC, rdp, avocent, vmware remote console, PC Anywhere, even one nested into another.
Every server might have a different keyboard, based on the country it's in.
Nested remote consoles and tools that gives access to the physical console of a server often misbehave the caps lock key.
Pair a faulty caps lock with an unknown keymap and a rigid lockout account policy and one more try to enter the correct password may result in a locked account.
Sometimes, even trying the password before in the clear-text username field is not an option, because of people that might see the console at the remote site.
So I've begun thinking about passwords that are unchanged between different keymaps.
Rules are:
1) you can't use keys that are different from one keymap to another
2) only lowercase letters, because the shift and caps lock keys can't be trusted

I've checked all the most used european keyboards (Italy, Germany, UK, Spain), plus the default US keyboard (here Wikipedia is our friend: http://en.wikipedia.org/wiki/Keyboard_layout)

The invariant keys are:
!$%
1234567890
QWERTUIOP
ASDFGHJKL
XCVBNM,.

If you add the France keyboard to the mix, the list will be even shorter, as french people like to distinguish themselves:
1234567890
ERTUIOP
SDFGHJKL
XCVBN


But how much security do you give up by using keymap-independent passwords?
A commonly used policy of 8 chars password, using all the standard ASCII characters (32-126 for a total of 94) leads to 6.095689385×10¹⁵ different passwords.
Using the reduced charset of the non-french keyboard mix you have only 39 chars: to obtain a similar complexity you will have to use a 10 chars password, with 8.140406085×10¹⁵ different words.

2011-08-23

Playo Android

This could be an interesting piece of hardware: an android phone, minus the phone, with HDMI output and USB ports.
If, as they say, it will be sold for less than 200€, and it won't have a locked firmware, it could become the ultimate living room geek toy.
It has a full keyboard, while others don't, and by installing a full linux distribution on it (like some android phones) you could have your own miniserver.
I assume that, given its phone roots, power consumption is still as little as a phone.