Wow.
Blog posts
-
Flavius Belisarius
Posted on Blog over 19 years agoon May 29, 2007 - 6:26 AM and archived here at /blog/2007/2007-05-28-flavius-belisarius/at https://pizza.slow.high.quality.gravely.pizza/blog/2007/2007-05-28-flavius-belisarius/ in the Blog collection in both HTML and markdown. -
Fake Military
From Emergent Chaos: the TSA behavior detection team had the state boys in Florida lock up a gentleman in an irregular army uniform. The acronym for this magic (you knew it was coming) is “Screening of Passengers by Observation Techniques (SPOT)”.
A little over ten years ago, I was SPOTed by a Marine recruiter in the high school cafeteria. I was wearing my dad’s old USMC short sleeve dress shirt with sergeant stripes on the sleeves and a Led Zeppelin t-shirt under it. The recruiter headed directly for me, so that he could let me know that I outranked him. He also told me that it was illegal to wear the uniform with the stripes still on it, and was I aware of the many exciting things the United States Marine Corps could do for me.
He didn’t seem to mind that I wasn’t really in Led Zeppelin.
Posted on Blog over 19 years agoon May 24, 2007 - 11:01 PM and archived here at /blog/2007/2007-05-24-fake-military/at https://pizza.slow.high.quality.gravely.pizza/blog/2007/2007-05-24-fake-military/ in the Blog collection in both HTML and markdown. -
Rodrigo y Gabriela
Rodrigo y Gabriela - 6/30/2007, 9:00 pm @ Rams Head Live!
I just ordered tickets.

Figure 1. Rodrigo Y Gabriela. Rodrigo y Gabriela are two fast-fingered, Dublin-based, Mexicans with a unique sound created on acoustic guitars. Their music is difficult to define, straddling both world and rock, and often imbued with timeless Hispano – classical influences. The duo’s repertoire flies beyond familiar Latin folk guitarists’ styles because of the metal connection: their reworkings of Led Zep’s “Stairway to Heaven” and Metallica’s “Orion” are musts.
Who knew? Stairway is a metal tune.
Posted on Blog over 19 years agoon May 23, 2007 - 5:38 PM and archived here at /blog/2007/2007-05-23-RodrigoyGabriela/at https://pizza.slow.high.quality.gravely.pizza/blog/2007/2007-05-23-RodrigoyGabriela/ in the Blog collection in both HTML and markdown. -
Schneier: Rare Risks Breed Irrational Responses
Bruce Schneier’s latest wired.com commentar is excellent.
People tend to base risk analysis more on personal story than on data, despite the old joke that “the plural of anecdote is not data.”
While there is plenty of philosophical wiggle room in this statement, most of us base decisions and estimations and opinions on personal experience, with anecdotal experience a close second. It is such an amazingly successful strategy that it completely dominates the thought processes of individuals unwilling to concede to the superior experience of others. Most of us start to grow out of it some time in young adulthood.
This isn’t a strong field of experience to me, so I’m generalizing based on what I’ve gleaned from coursework and experience even in surmising that oh god I’ve recursed, I’m going fractal.
Starting over:
Citing examples of others being irrational is easy by the nature of the statement, but it is more insightful to pinpoint personal irrationality. Insight is nice but it’s really really hard. Surround oneself with people that can help is the trick. If your friends and associates aren’t providing insights of this sort, you are either enlightened or wasting time.
But that’s not the way we think. Psychologist Scott Plous said it well in The Psychology of Judgment and Decision Making: “In very general terms: (1) The more available an event is, the more frequent or probable it will seem; (2) the more vivid a piece of information is, the more easily recalled and convincing it will be; and (3) the more salient something is, the more likely it will be to appear causal.”
On a lighter note, this process also impacts opinions on fashion, entertainment, visual art, music, education, gun control, social welfare, the death penalty, and so on and so forth.
Posted on Blog over 19 years agoon May 23, 2007 - 5:11 PM and archived here at /blog/2007/2007-05-23-schneier-rare-risks-breed-irrational-responses/at https://pizza.slow.high.quality.gravely.pizza/blog/2007/2007-05-23-schneier-rare-risks-breed-irrational-responses/ in the Blog collection in both HTML and markdown. -
Wedding Pics
Echard Wheeler, the photographer we had at our wedding, has posted a selection on his blog if you’d like a quick peek. If you’d like to see a bunch more, or buy prints:
Pictage. The event key is ‘Guitar Hero’.
What ended up on my camera during the week is both here and on flickr.

Figure 1. Guitar Hero! Here’s me with a bit of an Eric Clapton chin going on. I must have been playing Crossroads on Expert - I get into it.
Posted on Blog over 19 years agoon May 22, 2007 - 12:00 AM and archived here at /blog/2007/2007-05-21-wedding-pics/at https://pizza.slow.high.quality.gravely.pizza/blog/2007/2007-05-21-wedding-pics/ in the Blog collection in both HTML and markdown. -
Platypus
Creating applications with applescript is really easy but every time I use it I want to think like a shell or perl scripter and end up bailing. This has been especially annoying with the screenshot and publish script I’ve been using for the past five years. The port to applescript was easy but creating an application out of the shell script didn’t work as expected. I then ported it to Automator when that came out. Ugh. I ended up going back to shell and escaping out for native OSX image handling which is superior to imagemacick.
Platypus to the rescue!
Platypus is a development tool for the Mac OS X operating system. It can be used to create native, flawlessly integrated Mac OS X applications from interpreted scripts, such as shell scripts or Perl and Python programs. This is done by wrapping the script in an application bundle directory structure along with an executable binary that runs the script.
Finally!
I tweaked the script with a few more ‘mac’ touches, now it pipes the url into pbcopy, then asks OSX to open the uploaded file in whatever the default browser is. Then I made an app out of it with Platypus.
Posted on Blog over 19 years agoon May 19, 2007 - 5:45 AM and archived here at /blog/2007/2007-05-18-platypus/at https://pizza.slow.high.quality.gravely.pizza/blog/2007/2007-05-18-platypus/ in the Blog collection in both HTML and markdown. -
Mice Parade - May 27
Would anyone be interested in a Sunday night show in DC? Would Pizza Paradiso in Georgetown be a good enough bribe? I caught this on my last.fm recommended events RSS.

I’ve never been to the venue.
Expect a post rock act and two folk artists. Also expect a relatively late evening for a Sunday, as the shows start at 9. Check the first last.fm link for audio of each or Mice Parade’s myspace, if you do that sort of thing.
Update: This is the day before we all have off work for Memorial day, you no longer have any excuses. How many tickets do I need to buy?
Posted on Blog over 19 years agoon May 19, 2007 - 5:08 AM and archived here at /blog/2007/2007-05-18-mice-parade-may-27/at https://pizza.slow.high.quality.gravely.pizza/blog/2007/2007-05-18-mice-parade-may-27/ in the Blog collection in both HTML and markdown. -
Social engineering, tigers, and bears
Cross-posted from somewhere awful and edited to make sense as a stand alone:
To paraphrase number 5: Social engineering as a security audit tool, if actually providing any valuable information to anyone, is useless at affecting change in any way, and therefore, useless.
While I certainly concede that there are a few valid security controls failing that a successful social engineering attack highlights, I tend to blanket social engineering ‘hacks’ as a bit of the emperor’s new clothes.
Commonly suggested mitigating factors: ask for business cards, ask a manager to intervene, ask for photo identification, and so on. All of those controls fail if the attacker prepares for them and has the appropriate forged documents. Forging e-mail is even more trivial. The victim in each case has performed what they consider due diligence and for nothing.
The inverse cases of detected attacks are rarely security controls in action. Poor preparation or execution by the attackers raise suspicion. Human intuition can see through the con. A bogus HVAC company could be detected by a secretary who’s husband is owner/operator in the same HVAC space and is aware of all competitors. These aren’t examples of lone security conscious ‘model employees’ - just a poor attacks.
Society - at least the one I enjoy and prefer - requires that there exist trust relationships created by simple things: uniforms, badges, assertions even - some retail employee’s can only be identified because they are folding clothes, we’ve all asked or been asked ‘do you work here?’. Lying and replying “yes, how may I misdirect you? Please write down your home address, phone number, and social security number on this clipboard” doesn’t make you the smarter person performing some sort of hack, it makes you an criminal.
Luckily, the sociopaths that constantly violate these trusts tend to not be crafty social engineers. Pickpockets, petty thieves, white collar embezzlers, and so on, are practicing some of the world’s oldest professions.
Or is large scale social engineering happening right under our noses. I’ve heard the scenario: attackers then selling our information to the organleggers in Vegas that buy victims drinks. The Victim wakes up in a bathtub full of ice with surgical scars!
Corporate espionage does exist but the tried and true method is to just pay an insider, dumpster dive, or hack a network remotely. Paying an insider is a pretty foolproof attack, so worry about that first.
There are exceptions - places where trust just has to not work: Military bases, public utilities, treasury buildings, that base in Nevada full of aliens and crashed flying saucers, etc: most of them have guards with guns. Checkpoints at ever possible place. Cameras, fences, moats, and so on. Great security. Absolutely overkill in just the large majority of commonly cited cases of successful social engineering attacks, if not of all workplaces. How many of the targeted facilities even have onsite security officers?
It is pretty easy to decry a post-it note password discovered by a social engineer, but that note is often behind one or more locked doors in what can be considered a secure section of a corporate office. This one is everyone’s favorite cited example of a stupid thing to do. It is stupid but consider the risk versus the cost to prevent. Consider the actual probability of an enterprise being attacked that way. Sometimes the “well I’ve always done it and never been attacked” excuse is actually a valid risk assesment.
From a cost perspective, it is almost always cheaper to prepare for system attacks with tried and true measures - defense in depth, recovery procedures for data loss, data backup and integrity checking, etc…
I do not feel this way about all security audits - penetration testing, app vulnerability testing, and physical security controls auditing, are all great. Too many organizations skip basic risk calculations, data classification, defense in depth, and so on, to go straight to the sexy movie-theater stuff, and it is foolish. Oh but I’m sure they have an expensive firewall, and lots of blinking lights under control.
What social engineering is absolutely brilliant for, is pointing out security theater amongst the real security controls. Common airport, sports arena, concert venue security rant, etc ad nauseam.
Posted on Blog over 19 years agoon May 16, 2007 - 7:27 AM and archived here at /blog/2007/2007-05-15-social-engineering-as-security-audit/at https://pizza.slow.high.quality.gravely.pizza/blog/2007/2007-05-15-social-engineering-as-security-audit/ in the Blog collection in both HTML and markdown. -
Yikes
Posted on Blog over 19 years agoon May 15, 2007 - 5:15 AM and archived here at /blog/2007/2007-05-14-yikes/at https://pizza.slow.high.quality.gravely.pizza/blog/2007/2007-05-14-yikes/ in the Blog collection in both HTML and markdown. -
DEAR RICHARD
The SomethingAwful forums have changed their privacy policy after a third-party IP sharing incident went public. If you are a member, check this thread for more whining.
The old one: “We may share data with the following third parties: NOBODY. These third parties will use the information as follows: NONE.”
And now: “We may share data with the following third parties: WHOEVER WE FEEL LIKE. IF A RANDOM BUM OFF THE STREET WANDERS IN HERE, WE’LL PROBABLY GIVE HIM YOUR IP ADDRESS IN EXCHANGE FOR A HAND JOB. These third parties will use the information as follows: EMOTIONAL BLACKMAIL.”
I think it is a good natured response. The naiveté of the general internet populace is excellent. Internet lawyers and conspiracy theorists! Oh My!
I consider myself slightly tinfoil. I lie when asked for phone numbers, zip codes, and so on at retail stores that won’t allow me to complete a transaction by not giving them my information. I am well aware how futile this effort is and how much significantly more damning information about myself than my IP address is traded amongst business partners around the world for the sake of marketing. Every little bit helps. This incident is not a big deal.
About 15 percent of the world population uses this web thing. It’s going to get a lot bigger, convert to ipv6, likely change killer-apps a few times, likely slowly change dominant operating systems and network stacks a few times, and in general get pretty messy. Neat to watch happen.
Posted on Blog over 19 years agoon May 14, 2007 - 4:20 PM and archived here at /blog/2007/2007-05-14-dear-richard/at https://pizza.slow.high.quality.gravely.pizza/blog/2007/2007-05-14-dear-richard/ in the Blog collection in both HTML and markdown.
