Saturday, July 20, 2013

Lazy Saturday and tech woes

Strangely enough, I find myself this Saturday with some free time and keyboard access. Upon browsing my own blog, I found that my most recent post (The Blonde in the Bar) had been reverted to an out of date draft.

Originally, I had the inspiration for the write up while I was on vacation. As such, the post was created using the Blogger app on my phone and then saved as a draft. When I got home I cleaned up the post on my desktop through Chrome. A few days ago I had reopened the Blogger app on my phone which was still open to the first draft of that write up. Closing the app saved the writing back to the version cached in the phone! Thank you, Google Cache. That was how I had to revert to the correct version.

I would love to write something deep and thought provoking or, better yet, get some coding done but I just heard life calling again.

Wednesday, July 10, 2013

The blonde in the bar

In A Beautiful Mind Russell Crowe plays a brilliant mathematician John Nash. Part way through he has a moment at a bar which inspires him to write. His bar moment gave him insight into his field and he left after thanking the blonde in the bar. I have been inspired to write about what I've recently learned from a night in a bar. To my blonde in the bar, thank you.

At some level, everyone knows that their privacy is at best only as safe as the protect it. People also tend to be really bad at doing that protection. When a gorgeous, dashing gentlemen lonely, bored drunk in the bar asks for a dance can be an awkward moment, since both parties are keeping the physical contact to less than that of a middle school formal. Small talk fills the few minutes of the dance.

What has you in town? School.
Study? Interesting sounding topic.
Prompt for information. Chat, including a brief, slightly bragging mention of a great internship.

Part way through the song her friend cuts in and the dance ends. Part ways, no names given. Anonymous.

How anonymous? Not at all. The school, the program of study, and the internship was all that was given. When searched appropriately online, that tuple points initially to a person. One that just happens to share the same first name which was overheard in the bar, said by the blonde's friends. Even without that tidbit, that first entry contains a full name. Searching for that full name on another site provides a picture along with the results. Match.

The friend that cut in, the only information she ever provided was her face and her association with the blonde. Solid anonymity? No more than the first. The online trail included her full name and even a friendly nickname. Hometown? High school? Interests? All exposed based entirely off a chance meeting with her friend, the blonde in the bar.

What is the appropriate amount of information to share and what is the information that must be held close to the chest? A brief, anonymous chat with a stranger in a bar can potentially have wide rippling effects. How much do you say without thinking about if it exposes you, your friends, or your family? In The Art of Deception, Mitnick poses a challenge which should be trained into employees: "If I gave this information to my worst enemy, could it be used to injure me or my company?" (2002, pg 53) This is a question that should probably be employed by all of us about all our information.

Once again, thank you. I never before had thought as deeply about what information I may be exposing just by chatting away.

I can't not leave you without the clip that I began by discussing...

Sunday, June 30, 2013

Summer Reading List

I was browsing an actual Barnes and Noble yesterday and it was a pretty nice experience. The draw in was that I wanted to grab the new expansion to the deck building game Legendary, (Dark City!) but they didn't have it in stock. Since I had thirty minutes to kill anyway, I used the rest of my time to shop around, though not intending to buy anything.

If it has been a while (for me it has been years since I spent any significant time in a library or bookstore, outside of the SciFi/Fantasy sections) since you explored a brick and mortar book source, I recommend you head back for a bit. Getting to handle the books and look them over was a nice way to shop, rather than the sterile, recommendation filled environment of Amazon. Sure, Amazon is really efficient, but the hands-on nature of the Barnes and Noble was enjoyable.

Anyway, in the Professional Computing section, I found a whole set of books that I want to have.

The book I wound up getting was Art of Deception: Controlling the Human Element of Security by Kevin D. Mitnick. So far it has been a great read. I plan on writing my thoughts about it here.

Also, in making this list I saw I could order The Shellcoder's Handbook for under $7, including shipping. It should arrive in a week or so!

Monday, March 11, 2013

Canned Spam

There are no published comments on this blog because no one has commented. I just read through the spam filter and it is quite full. Annoying, but why bother spamming a blog that apparently has no readers?

Saturday, March 9, 2013

Hiccups and funding

I have not been posting recently, since most of my posts were just dumps of work from my cybersecurity courses. This semester became a break when I encountered a last minute hiccup for my funding. I regret that I have not been posting because this blog is a way to lay out my thoughts permanently.

Upon selecting to learn more about cybersecurity, I was thinking that the field would be computer science with a focus on dangerous coding. That has not been the experience at all. As is encapsulated in my existing posts, cybersecurity is a much more big-picture field. Personnel management, policy development and compliance, physical security, access control, vulnerability discovery, incident response, intrusion detection, cryptography... the list of topics related to cybersecurity goes on and on. All these topics come up in blogs I read and news I see. Both the articles I read and the thoughts I have from them deserve comment, so I should be writing here.

I don't know if there are any repeat readers here or if the visitors are just stumbling on things related to the classes they take, but I said I started this blog to "dump thoughts and archive work." There has been precious little of me just dumping thoughts, so that will have to change since I'm not currently in a class to need to archive the work.

I almost published this as a big blog of text because I nearly left out the HTML. Have a nice weekend!

Wednesday, December 19, 2012

Final Grade

The problem I wrote about last time didn't appear to impact my grade, great!

Finished the semester with a 4.0. Whoo!

Monday, December 17, 2012

Winter break

Well, yesterday marked the end of my most recent semester. I was in charge of putting our paper through TurnItIn, reviewing the report, and submitting to our professor. It went terribly.

First, I ran the paper through TurnItIn and viewed the Similarity report. The web app was telling me the paper scored a 7% similar to its databases, but had nothing flagged in the paper. Commenting on it being weird to my wife, I downloaded the useless report and submitted the papers.

A few hours later, the rest of my team drew my attention back to the useless papers. Prompted by their concerns, I returned to TurnItIn and scanned around the app's interface. As it turns out, you can toggle off the report display so that it just shows what you submitted. Pointless, as I already have the file I submitted. So I toggled it on, downloaded the less useless report and submitted it again.

After a few more hours, the team contacted me concerned that my whole post was missing. Back to the website, attach the files again, and post.

Today, I got home from work and checked my email and the class page. (Note it is now after the submission deadline.) My attention is drawn, at prompting from my team, to the fact that TurnItIn claims a 3% match to www.uspto.gov. This claim is really bizarre, as we don't even have a reference for uspto.gov in our paper. Looking into it, the service is correct and we submitted a paper with two paragraphs ripped nearly word for word from this paper by the United States Patent and Trademark Office. Ridiculous.

In an attempt to save the team from my mistake, I have submitted the following amendment to my Self and Peer Evaluation concerning the paper to the professor.

I need to amend my evaluation.

There are two paragraphs that made it to the submitted TEAMNAME paper which are pulled almost verbatim from http://www.uspto.gov/about/vendor_info/current_acquisitions/sdi_ng/ocio_6016_10q.pdf without citation and without even a reference to www.uspto.gov.

I had felt I was being harsh on TEAMMATE0 in what I turned it, but it was too light.

He did not attend the work planning, threw together a quick, plagiarized section which required significant maintenance to even look passable, and withdrew his support from any of the post-drafting collaboration.

That said, I was the one who ran the paper through turnitin. I did not catch the two paragraphs in time. TEAMMATE1, TEAMMATE2, and TEAMMATE3 attended the planning, communicated often, and carried out their assigned portions of the work. The failure to prevent the plagiarized paragraphs from making it to submission was on me. My first paper had a 10% score overall, and 9% to SCHOOL papers that I never had seen, so it made me lose any faith I had in the turnitin system, so I didn't delve into what the 7% score was. I didn't trust the scanner, so all I concerned myself with was making sure that the paper didn't hit the 15% threshold.

The majority of the TEAMNAME group performed their responsibilities to satisfaction and deserve to have their grade based on the merit of the writing. The blame for the Internet and User Furnished Device Policy sections falls to TEAMMATE0 for submitting it as his section and to me for not catching it during my review.

Thank you for taking the time to read this,

Matthew Molyett