Pages

Thursday, September 19, 2013

19 September 2013

you know, sometimes im not sure people understand how to communicate in this newer technological world.  especially those of us that are getting into middle age.  i suppose this is what our parents felt when we were trolling the BBS boards of the early World Wide Web.  it is so hard to remember a thought process over time, much less communicate it real time.  Yes, I'm talking about Instant Messaging, something started by the very BBS's i spoke about earlier, and brought to the layman user with the venerable AOL.  Todays version though is loaded with features only dreamed about twenty years ago, picture, video, and short audio exchanges as well as VOIP phone calling, group chatrooms where all sorts of intimate things are shared with a wide audience.  Gone are the days of writing out thank you letters for Christmas, or calling someone on the phone because thats the only way you could communicate....no, now its texting (sexting too), in a nearly pure virtual world.  by the next generation, im wondering whether physical contact will be necessary for conception.  "Demolition Man" with Sylvester Stalone actually predicts such a society and targets the year 2032....freaky?!?

i urge everyone towatch "Parental Guidance", a newer movie starring Bette Midler and Billy Crystal that touches on a broader range of similar changes that have taken place.  

Wednesday, September 11, 2013

11 September 2013

Certainly a day to reflect upon the tragedy that is now 12 years in the past.  Those that died upon U.S. soil in New York, Washington DC, and to the fated airliner that our countrymen managed to wrest control away from the terrorists.  Today also marks a few other days to remember personally.  My wife's mother's birthday, my own mother's birthday, and the day I met my current wife.  Yes, today seems to be a focal point in the space time continuum that is a recurring theme in my life.  It is not without some apprehension that I approach this day, one marked with so much significance.  Most certainly a day of reflection.

Tuesday, September 10, 2013

Ruminations

So, I'm watching "The Real Story" on the Smithsonian channel where they are detailing the story behind the Bruce Willis movie, "Live Free Or Die Hard."  As always, my curiosity is peaked for the truisms and sheer possibilities presented.  One question keeps running through my head though.  Why, in all my research, reading, and seeing shows, either fictional or reality, has the United States or it's citizens been portrayed as the victim of cybercrime?  Surely other nations are targets and face the same problems from cyber criminals as the U.S., but for whatever reason, these other nations get secondary billing.  I suppose if there were a story (fictional) about an American hacker attacking another nation, the impression would be far different.  Would the impression be the top nation being a bully?

Saturday, June 22, 2013

New Hobby

So, my fingers are sore....but I'm not complaining.  I decided to take up a new hobby lately, that of learning the guitar.  I've had my eye on the RockSmith bundle package from Sam's Club which comes with the game, both cables, and a Les Paul Jr. electric guitar.  For $80.00, this is a steal, really!  Online reviews of the Les Paul are favorable, given it's a bargain basement beginners guitar, and the Jr designation is not because it's a smaller size, that's just to indicate the model, which is to say that it's a lesser, not as quality manufacture as the prime time Les Paul is.  You may notice that it does not include an amp, more on that later.

I got the package home, unwrapped it all, popped the disk in the PS3, and a half hour later, I was hooked.  I'm really a music person, as anyone who knows me can tell you, although I have not played an instrument in quite some time (about three decades, give or take a couple years).  When I got done though, it wasn't because I wanted to, it was because my fingers on the fretting hand were well on their way to developing a set of bruises, especially the index finger as the game does nothing in the way of finger placement on the strings, so I used that one predominantly.

The next day, I downloaded a few apps to the iPhone and iPad, mainly guitar tuners and chord databases, but I got curious about making my Apple devices into an amp.  Sure enough, a Google search got me to 90% of a solution, as there are plenty of apps as well as commercial cables out there to buy.  Well, the wife put the brakes on my spending much, so I decided to get creative.  A few more searches turned up a guy who described how to build a cable, and a free app for the Apple devices.  After scrutinizing the instructions, I went to the local Radio Shack and picked up the parts I didn't have lying around for only $10.00.  About an hour later, I had the "cable" constructed.  Take a look at the picture below:


Now you see why the word cable above is in quotes...my design was purposeful and meant to be small as well as not have a lot of cables lying around.  My engineers brain has already designed the next phase of the device, but I can't implement it yet.  I did run into a snag, that of the instructions on the internet failed to work the first time.  I enlisted the help of my father, who spent his career with a soldering iron in his hand working on electronics for communications.  Two added components and the next test was successful, although there are still a few minor bugs to work out.  Here are some other pictures, sorry for the blackout.





The idea here is the app provides the functions that an amplifier would normally have in the way of knobs and logic for distortion of the signal and simply takes the input from the guitar and outputs the product to the headphone jack.  In this diagram, I have my computer speaker cord plugged into the speaker jack, but if you have a pair of bluetooth headphones, you can essentially jam out to your own tunes without disturbing anyone.  Furthermore, you could connect to an external bluetooth speaker from the iPhone as well.  In the future, I plan to go completely wireless and plug a wireless transmitter to the guitar jack and a receiver to the input side of this converter box, which will allow me the freedom to move without tripping over wires!

Wednesday, November 21, 2012

Information Security/Cyber Security

http://finance.yahoo.com/news/threat-spectacular-cyberattack-looms-official-185505164.html;_ylt=AotMcHbqlggVcFMe.957QkaiuYdG;_ylu=X3oDMTQ2N2JvbjJxBG1pdANDTkJDIEZlYXR1cmUgMgRwa

Ok, so I put that link in a draft a few weeks ago, fully intending on writing something about it sooner. I haven't gotten back to it until now, in the midst of watching "Live Free or Die Hard" again. For those of you not familiar with this movie, there is plenty to find on the Internet, so I will only say that it's about my line of work. I also checked them out today, and I find something very alarming here. References to the movie, which came out in 2007, cite sources that are even older , some even predate 9/11, and detail concern over an attack vector similar in nature. Fast forward to today, and the article above, and you can clearly see that not much has really changed in the minds of those that have the power to make a difference. Sure, there are good things being done, new government agencies, regulation proposals and updates, but underneath all that is still the same skepticism that was present back then. I'm not as concerned about the government end here, they seem to be on board now, albeit typically slow in getting things moving, no, I'm very concerned about industry here. Within the last year, a cyber security bill has been put forth to protect the nations critical infrastructure, but it has failed to pass. I can only assume that lobbyists and special interest groups are purposely trying to make the bill fail, and that leads right back to the industries that the bill is trying to protect in the first place.

We can read headlines that are indicators that there is a growing threat, the nations leaders are actively saying this, yet the CEO's and senior management of the industries that most certainly will fall first are still resistant. Now let us suppose that the U.S. fails to protect this before an attack happens, what about the other nations? Once a successful attack happens, there is no way that the attacker would stop there. No, just like conventional warfare, they would then take the next step and take down another nation, then another, then another. We, the protectors of networks, have a global responsibility, not just a local one.

Thursday, November 8, 2012

Air travel

I realized something today that I have missed for at least a year and a half. I get anxious about flying, to the point that I am highly sensitive to my emotions. Those that know me would say that I'm normally in control about my emotions. I will have to pay much closer attention to this in the future to see which emotions are most common. This trip I felt extremely lonely and missed my family before I even left the house for the airport.

TSA had their say again. No surprise this time, because I had forgotten about the new pocket knife that I had added to my right pocket with my companies logo on it. Not a big loss, and understandable this time, still, it seems that they are really picky. Maybe that is a sign that they are doing a good job?

Got to my destination, and my rental car company was short on cars, so I got the silver Ford Mustang 5.0 they had left. I've been dreaming about this for a while, because they often give me cars that are upgrades from what I've reserved, but it wasn't the experience I was expecting.

Day 2 was better, actually enjoyed the mustang, and had a productive day at work. Still missed the family, and tried hard not to stress about the flight home. Think it worked, even though the closer I got to flight time, I did notice some unusual behavior.

During the flight I had an episode that concerned me a bit. It had happened only once before, but not quite this bad. Once the plane reached altidute, the right side of my face went completely numb, to the point that I couldn't even close my right eye. I put my head back and tried to relax, but couldn't get any feeling back. I was starting to get a little anxious and concerned, when my stomach started to heave. I grabbed the air sickness bag and punched the attendant call button. It stopped shortly after I regained feeling in my face. After the plane landed, I called the wife and she was able to do a little research online. The most likely explanation is that my sinuses were blocked, causing the pressure to build up at altitude and compress a nerve, making my face numb. My ear had probably also not equalized either, causing the nausea. Throwing up may have caused both to equalize with the altitude and stop the problems, because it immediately got better and I gave no residual effects a day later. Bottom line is I should not ignore allergy medication during trips and be extremely cautious about flying with a stopped up nose.

Friday, September 21, 2012

Mapping Security Control Catalogs

So I have a new project underway in my spare time.  My wife and I are going into business and, as it happens, must comply with not just one, but two sets of information system security control regulations, one industry, and one federal.  Being intimately familiar with DoD 8500 and NIST, I welcomed the challenge that came with this in attempting to translate the other two into a framework that I understood better and immediately ran into an issue.  The two regulations are PCI-DSS and HIPAA, which are not fully developed information system security programs, therefore, it doesn't make sense to show compliance just for compliances sake.  I wanted to do this the right way and adopt a full program and then map the other two standards to it, so chose NIST as I have been impressed with it's flexibility in the control set.  I am not happy with it's security categorization, so instead, chose the CNSSI-1253 to perform this function for my program. 

So far, so good. 

NIST has publised SP 800-66 that maps HIPAA to SP 800-53 Rev 2, but I'm wanting to be on the cutting edge, which meant that I had some updating to do with that map in order to get it into SP 800-53 Rev 3 (and soon Rev 4).  Ok, not too bad, NIST markups and discrepancies aren't too bad to work with and I don't see a big problem with not being specific in the control enhancement area as HIPAA is rather vauge when it comes to stipulating requirements, so the base controls should do fine.  So far, it's a little work to get the HIPAA map updated, but looks fairly easy. 

Then I turned to PCI-DSS to look at that. 

Drastic difference here, as this control set is more specific than the NIST control set in certain areas, and darn it all, no-one seems to have mapped this to NIST.  I did find a few maps that I could reference, but not use or change directly, mainly using yet a third control set that I wasn't interested in at all (ISO 27000, COBIT, and CSA).  In develing deeper into these maps, it seemed that the ISO and COBIT maps weren't all that useful to me, but the CSA seemed to do a wonderful job as it published a map between all the control sets mentioned in this post as well as a few more.  So I grabbed that and really took a good look at it.  Bottom line, it's a good effort on their part, but for my purposes, I can't use it. 

The basic reason is that in order to map control sets, you have to start with a base set, then perform the map to the set you want to use.  In my case, I have to do that twice, once with PCI-DSS, and once with HIPAA.  Once you have it done that direction, you can reference the other two sets from the set you use to show compliance.  Since the maps I had tried before had essentially done this against a set that I wasn't interested in, I was attempting to compare apples to oranges to get it back into the right framework.  Sure, the maps are somewhat useful to narrow down the field, but only when the control set they use is nearly identical to the one you want to use.

Crap, I'm going to have to do this the hard way:  map the sets manually.

Doing it this way has a huge drawback, in that you are entirely dependant upon your own subjectivity, which the entity that you are trying to show compliance with may not agree with.  I didn't want to do this, but in the absence of publically avaliable or official maps, I really have no choice.  Fortunately, I do carry the credentials to make my map more credible to anyone looking at it.

So, I'm just getting started, but already I see a pattern starting to form in that my subjective view is very granular and differs from the maps I've been able to find.