Wednesday, May 17, 2006

It's a game of 10 halves, Binary

Thanks to Satan for this revolutionary pre-match analysis: arsenal.com vs fcbarcelona.com


Environments
-------------------------
Both running on windows, a dull start...
Arse 0 - 0 Barca

Homepage
-------------------------
Both have splash screens before you enter the main site (yawn), the Barca
one has a nice language selection menu, the arse one invites you to gamble
(which we all know is very bad)...
Arse 0 - 1 Barca

HTML etc
-------------------------
Equalizer for the arse as the wisely decide not to use tables, however an
own goal for the over stuffing of keywords (a redundant tag as we all know)
and the use of 7 javasript includes. The arse score again as barca forgot to
declare a doctype and declare backgound colours and widths outside the css!
Another goal for the arse as barca use a spacer gif over 100 times (got
bored counting), and omit both a noscript tag and a separate print style
sheet.
Arse 3 - 2 Barca

Content
-------------------------
Barca equalize due to greater language options, less encouragements to
gamble ('betting' is an option on the arse main menu - very evil) and no
blatant plugs for their own tv channel and less rotating banner ads. The
arse site appears to have a greater range of club related content, history,
stats etc (ladies team - shouldn't that be women's team) and gets quite
nerdy. Visually, I prefer the barca site, it's cleaner and more readable.
Hence:
Arse 3 - 3 Barca .... Penalties it is!!!!

Sunday, May 14, 2006

Product placement 3 - Henderson's Delectable Relish

Owl or blade everyone in Sheffield likes Henderson's and with good reason, it is an excellent condiment, similiar to Worcestershire sauce but a lot nicer. The Weaver picks us up a bottle from Sheffield when we run out, but you can buy online for £10 a litre or just pick up some Henderson's merchandise: interestingly, one of the recipes listed in the recipe book is "Ash, Meat & Potato Pie". I must ask the Weaver what's in it..

Friday, May 12, 2006

Network hardware

I replaced our wireless router and it's a true boiling-frog experience: now everything 'just works' again the contrast is spectacular. Anyone out there struggling with a Linksys BEFW11S4 should just start saving for (or spring for) a new router: they aren't very good.. My cat sat on mine for a year which didn't help.

I bought a Linksys WRT54G for £50 (incl tax & post) and it seems fantastic in comparison because I can upload via FTP again, which is a real boon when maintaining websites! This has been a complete pain for a year or so.

Some protocols fared better with the failing device than others. I expect the situation is analagous to teetering on the fringes of a wireless network: HTTP seemed to manage (with occasional network and page errors), BitTorrent wasn't fussed, SMTP is occasional anyway, but FTP hated it. Something in the connection would fail and FTP uploads would hang: for a while I just did HTTP uploads but they started falling over as well and I couldn't upload any files of any size. HTTP downloads seemed to be unaffected, FTP downloads were less happy, but this is probably a function of browser/client/UA used.

Windows (server 2003) fired TCP/IP errors 4201 and 4202: Network Adapters dis- and re-connected, not necessarily in that order: Mac OS logged "mDNSResponder: Repeated transitions for interface ..[RFC1918IP].. delaying packets by 5 seconds."

I am also seeing another error though: Windows' event log records

The system failed to register host (A) resource records (RRs) for network adapter with settings ... the reason the system could not register these RRs was because the DNS server contacted refused the update request.
Mac OS on the other hand says this:
Wide-Area Service Discovery disabled to avoid crashing defective DNS relay 194.168.4.100
Code
That's one of NTL's DNS servers, I recognise it from setting up static IP addresses on Virtual PCs (it makes things a lot easier - as does activating a base copy of Windows before using it on different virtual machines). No need to ask Yossarian or Occam what's going on here, I think. I could use different DNS servers (I believe you can specify any server, but I would hope my own ISPs traffic was optimized) but everything's working now with my shiny new router so 'errors schmerrors'.

I vowed while driving home on Friday night that I would learn to touchtype: I suppose I should keep myself to it. Wish me luck..

ps I realise this post is somewhat incoherent but I becoming totally consumed with nerves over the upcoming European Cup Final starring Arsenal FC.. wish us luck, thank you

Friday, April 21, 2006

Google Calendar

This link adds my birthday to your Google Calendar.

I tried to use the date format Google suggest - &dates=20061207/20061207 - but I ended out with a birthday that ended the day before it started: what could be more of a bummer than having an invalid birthday?

Using &dates=20061207/20061208 in the URL (currently) properly creates an all day event on the 7 Dec.

Wednesday, April 19, 2006

Once a records clerk..

I have some experience in Public Sector Finance and what has happened with the NHS's overspend comes as no surprise to me. When you introduce new funding into an organization which has been starved of resources and forced to operate in survival mode, the expenditure gathers momentum and the tide won't subside until all the money's gone plus a bit more.

Large organisations are elastic: they can absorb times of hardship, contracting and retreating but protecting the core functionality. When the siege is lifted and new funding is provided, there will be a bounce-back as the tension is released. Each new expenditure stream introduces the possibility of knock-on expenditure especially when the underlying infrastructure has had to be neglected in order to provide core services, as when the covers are removed the rot will need fixing. Everybody knows this, of course, but it isn't possible (bar the omniscient) to precisely quantify the knock-on effects of any new spending. It's only possible to paper over the cracks caused by over-stretched resources until the pressure is released, and the worse the deprivation has been the more damage will have been caused to the infrastructure.

Forcing the Health Authorities to make redundancies and cancel services to recover the deficit is just not helpful, unless you prefer the word "idiotic": the government should bite the bullet and pay up. If finance directors are underperforming then sack them by all means, but a 1% overspend shouldn't qualify as a disaster even on a budget the size of this one. If anything, the Government's own planners should have anticipated this and allowed for it.

The Government prefers to spend our money on a spanking new fleet of submarines stuffed with nuclear weapons. A deterrent of mass destruction, though who or what they deter isn't clear to me.

Friday, April 14, 2006

Something anyway

There are two types of people in this world. The ones who divide people into two groups and the others who don't.
We're back..

Friday, March 24, 2006

Product placement vol 2 - Porky Whites / Encona

I used to be a vegetarian, and I remember that cooking sausages for the kids one Guy Fawkes night was a big contributor to my decision not to be a vegetarian any more a while later. When I started eating meat, though, I found that sausages were like real coffee: cheap ones were disgusting and expensive ones were disappointing even at their best the taste never matched the smell.

Then we stopped shopping in Tesco and went to Asda for staples instead, and in the "local" section we found some sausages: sausages which restored my belief in sausages: Porky Whites. Every time I eat them my faith is re-invigorated, these are the best sausages I have ever had and probably ever will.

After a while I had a look at the back of the packets to see where these Local supersausages are from and .. it's where I grew up! I was born and bred in Ewell, Home of Porky Whites - but I don't remember White's the butchers as I didn't buy much raw meat as a child: the only reason I knew of the Epsom butchers, the Boyts (Epsom and Ewell form a borough) was that one or more of my sisters went out with one or more of them. All I remember of Ewell is The Loose Box Wine Bar which I frequented from opening until 1983: semi-happy days making half-a-lager or a coke last all night unless someone working was buying. I remember Mr Do was the video game du jour, I played it a few times but never realy put the hours in to get good. The boxes were never quite loose enough to let me in either.

We've been getting these every week or so from Asdamart for a couple of years now, you have to search up the aisle for them as they're not even shelved with the regular sausages. We used to wonder if we were the only people that bought them but it turns out Blakers Park cafe, just up the road, has Porky White sausage sandwiches on their menu.. I haven't had one yet.

When you see the ingredients it becomes apparent these aren't the normal sock-and-stuffing sausages:

41% pork shoulder
41% pork belly
honey
lemon
stuff (incl MSG)
natural pork casings

They aren't free range which is a shame and frankly they don't need MSG, but it's hard to believe anything that tastes this good comes from unhappy animals: the thing is, Porky Whites are cheaper than fancy supermarket own-brand sausages, let alone premium brands. We had them tonight: I lost my appetite while cooking and had them cold later with a dab of Encona West Indian Hot Pepper Sauce: absolutely delicious.

Edit: May 25: Said something on our Porky's tonight that they are "Sausage of the year 2005/06" by the Meat Awards. As good as ever. Had pepper sauce with them of course!

Friday, March 17, 2006

product placement vol 1

Brahma beer is brewed in Brazil. The bottle is ergonomically shaped to fit in your hand, and the beer is delicious.

Tuesday, March 07, 2006

irc://jamesfunny

a> Wait for the guy in the red jumper.

a> http://tinyurl.com/n9zcz

i> there's that awful moment when you think he's just the school nerd and it's going to be incredibly embarassing!

Monday, February 27, 2006

::

Adobe seemingly have an online service which will convert any PDF you submit to them into text or HTML. This is a service for visually impaired users [and not a way around the "Selection of Text Not Allowed" restriction] and graphics are discarded. I haven't needed to try it yet though.

Bear in mind Adobe reserve the right to forward your PDFs to other companies it thinks might find them amusing..

Sunday, February 19, 2006

Mister Vista

I'm installing build 5270 of Windows Vista [beta 2] on a virtual PC upstairs, as per the instructions here. So far so good. I tried to install it on VPC/Mac but it borked on lack of ACPI support in the BIOS: a real shame as the Mac has lots more RAM than the PC.

Installing a virtual PC via Remote Desktop is a real challenge: because Remote Desktop doesn't support relative mouse coordinating until Virtual Machine Additions [add-ons for VPC like shared folders from the host OS] is installed, the mouse behaves really strangely: capture takes minutes, and subsequently every tiny mouse movement correlates to a giant leap on the screen. The Windows Vista setup supports keyboard shortcuts almost completely: the "select partition" screen doesn't seem to support shortcuts for each partition. It's been a general trend for installations to ask fewer questions: Vista asks for a product key, a partition to install into (this may be the problem with build 5270 in VPC, if the technique in the link above doesn't work for you try this one) and a NetBIOS name, and then off it goes. I will have to wait to tomorrow to see if it worked though..

Edit: sort of. Running 5308 now which nearly works even better.

Tuesday, February 14, 2006

Chip And Pin

Much of this is based on an originating conversation with Rangor, Father Of George.

Consider a criminal retailer or retail employee whose desire is to obtain people's card details and pins for fradulent use.

The first thing to try will be to subvert or replace the existing card reader: the card readers in shops don't have any kind of identification or authentication from the point of view of the card owner - you put your card in (or you give it to the retailer and they take it away from you and insert in or swipe it or whatever - there's no standardisation there either) - and then that or another machine asks you for your pin. There's no standard interface, although admittedly even if there was it would be trivial to spoof. Unless your card can tell whether it is connected to a genuine card reader, you are more reliant on the honesty of the shopkeeper than you ever were: a spoofed card with a null signature might be used for purchases, but a spoofed card with a known pin can be used to withdraw hundreds of currency units per day from cash machines anywhere, especially ones away from cameras.

Anyway, you don't even need to do anything to the machine, you just need a couple of cameras yourself: one to scan the card numbers on the way to the reader and one to look over the customer's shoulder and record the pin. Or use the inbuilt record of card numbers and use an accomplice who stands in the queue and notes the pins. If the card reader is able to access information about the card holder from the card (date of birth and the like) then Mr Bad doesn't really need the pin: statistical analysis will have been done on the most frequently used pin numbers anyway, patterns like 1234 and the DD-MM of the card holder's date of birth will have significant usage which makes guessing the pin trivial in an economically significant number of cases. If x% of people use a simple combination of the elements of their date of birth as their pin, then all you need is their card number: if you collect a million numbers and try them all once, enough will succeed to make it all worthwhile. The x in x% doesn't need to be very high. If at first you don't succeed, try another. If you do succeed, go crazy.. No notifications of failed authentication attempts are provided to the card holder, even if they're kept: the card issuers will be canny enough to look for authentication failure patterns, but these could be masked by hiding them within enough successful transactions. What are the thresholds? Are small transactions even checked? Is that why sometimes transactions are seemingly randomly declined, because an attempt is being made to brute-force the pin? While I'm asking questions, what encryptiopn is used anyway? What OS are these devices running? Are the keys hardcoded into the device's hardware or software? What is to stop transactions being recorded and replayed?

A classic man-in-the-middle technique would be the "first-fail": the keyboard (which you should remember may not even be the same device that read the card) is presented to the customer to enter their pin. But the device fails the pin and asks the customer to retry. This time it works. In this scenario, the device has been subverted by the retailer: the first pin entry is simply logged, and the second is passed onto the network for authentication: don't tell me that in a world full of people installing linux on toasters this is impossible. A much easier variant of this: a small transaction is recorded by a "device" but the device was cooked up by the retailers evil nephew or niece: it simply reads the card details (all the smart stuff too) and the pin you enter, then it say PIN OK. You never get charged for the transaction, but why would you notice? EFTPOS transactions can take weeks to go through. The card isn't authenticating the reader, so the card holder has no way of knowing where she just put her pin.. The value of card details and pin to our unscrupulous retailer are far greater than the 1.42 currency units of the transaction which the cardholder gets for free. If they ask you to reenter your pin on another machine ("sometimes we have to use the old one") then leave the shop and call the police.

Oh, there are lots more problems with the current implementation of chip 'n' pin. Sometimes you read cash machines are safe - where were they when all the examples of criminals installing fake cash machines or fake covers over existing machines were in the news? These have to be sunken into the wall of a bank before they appear authentic, and they still worked, and cash machines now routinely warn people to watch for spoofed interfaces. The machine in the shop into which you enter your pin is presented to you: it might be on a cord (connected to something you can't see anyway) or wireless, it might have your card in it and it might not: you know nothing about it, and have no means of knowing what it is doing with the pin you enter into it.

An unsubtle but effective approach for criminals too lazy to invest in card-spoofing technology would be to determine the customer's pin using one of the techniques above, and then pickpocket (or mug) the customer. Ouch. Or, if there's a facility to enter the card number manually when the card can't be read (and I think there is) then simply submit transactions using the card reader: open for a month, collect lots of numbers and pins, then spend a week hammering those accounts and disappear with the moolah before the complaints come in.

All the hype about 'identity fraud' ignores the fact that fraud via impersonation is much older than bank accounts, and fully punishable by existing laws. Attempts to make it seem an unchecked menace which can only be solved by chips, pins and ID cards are simply fraudulent themselves. As the shopkeepers are being compliant there must be something in it for them, a reduced charge probably, but there's nothing in it for the cardholders except increased risk: the banks and shops are happy though so nobody cares.

My advice is to always use cash at places like markets, firework shops, and the like where the retailer has only a temporary presence. This doesn't protect against corrupt employees, so if you're worried (you're extremely unlikely to suffer any personal losses from this kind of fraud) then use cash as much as possible, then, except in retailers you trust and where you can visually authenticate the card reader.

There are a lot of other interesting things the banks and retailers keep quiet: automatic reauthentication within a set time, retailer flow rates, and the fact that supermarkets hit the "override pay" button which authenticates the transaction whether you have the money in your account or not: for them it is very bad business to turn customers away leaving checkouts clogged up with their suddenly unwanted shopping, and since they get their money anyway they're happy. The card holder gets charged so the bank is happy. The customer is fucked off, but that's tough..

One of the other consequences of chip 'n' pin is the transference of the liability of fraudulent transactions supported by signature alone from the card issuer to the retailer: this means if the shop lets you sign instead of using your pin then they don't get reimbursed if it's a stolen card. This doesn't apply to chip 'n' signature cards, which the banks are being very quiet about: these tell the retailer to rely on signature alone and intended for groups like blind people. If you're uncomfortable with using chip 'n' pin you might think about asking your bank for one, but banks are insisting that people applying for chip and signature prove that they are registered disabled.

Drafts

Whenever I save a post as a draft, it disappears from the post list in blogger. The first dozen or so times this happened I assumed it was lost forever, but it turns out they still exist and can be accessed by searching for a space (using the search in the "manage posts" page) It must be some obscure bug in my blogger profile.

Friday, February 10, 2006

Note to self

Next time you're in Amsterdam go here.

Sunday, December 04, 2005

The Airline Screening Playset

The biggest departure from reality was that the passenger had a cheery smile on her face
The Airline Screening Playset

Tuesday, November 29, 2005

Are they mad? Or is it me?

Using my Mac I can't download from Microsoft, because I'm not running a genuine copy of Microsoft Windows. Well, *_der_*. The Microsoft MSDN subscriber downloads I can understand, they use the completely ridiculous File Transfer Manager - some crappy "download manager" from 1999 given a tart up and stamped with the MS brand - to restrict access. My employer (who pays for the MSDN subscription) uses a Microsoft proxy server which the file manager won't go through [my irony detector is tingling] so I used to download things at home and burn them onto CD for work. This file transfer software won't work on a Mac of course.

Edit: this includes products like Virtual PC for Mac - you need to be using Windows within Virtual PC on a Mac in order to download Virtual PC on a Mac. As my MSDN subscription comes on DVD and my iBook doesn't have a DVD drive it is annoying not to be able to simply download the item, but as we can all observe the sky is still in place.

Well, if protecting Microsoft's market share was the purpose of this restriction, then it has kind of worked - I will have to keep a PC around still. Not that I am angling to get rid of it - I am looking forward to trying Microsoft Vista, and I read today that I will get the full AquaGlass experience as I have a fancy graphics card I bought to play Doom 3 twice, and I am itching to see how much they have ripped off from OSX. Have to solve the no-monitor-attached problem, though, I suppose. Still, Vista's not going to be out for a long time yet.

But then I was interested in the Vista User Experience guidelines - user interface and design recommendations for the new operating system. Not so fast! I am told: "You are not using Windows. Fuck Off" [paraphrased]

Again I have to use Windows before I can read about Windows? How do they ever expect to win any converts to this new recursive operating system of theirs??

Saturday, November 26, 2005

Even Christ Stumbled

I didn't think I'd care when George Best died - he was Man U, I'm not quite old enough to remember him playing - but I do. He was a fantastic player, and he was brave as fuck on the pitch as well as off. We won't see his like again, he was a man of his time. Waste of a liver though.

Friday, November 25, 2005

He's right, of course

The ID card debate in the U.K. is all about population control - it's about controlling immigration, not terrorism. It is unfortunate that the U.K. isn't having that debate properly.
Bruce Schneier
Perhaps because we are too well controlled already.

Going Postal

Don't bomb Al Jazeera! or his brother Kevin Jazzera.