Friday, March 25, 2011

Stealing Software Is Too Easy At The Apple Store

When building a secure system, you have to think about all the different ways that it can be attacked or compromised. Unfortunately, that is nearly impossible in today's world.

Defender's Advantage

Historically, defenders have the advantage. While modern military communications and mobility, referred to tactically as "shoot, move, and communicate", have slightly shifted the advantage to an attacker, a good defender will still have the upper hand. Think about how difficult it would be to break into the White House or Fort Knox and you can see how much of an advantage a defender has.

Cyber Security

When dealing with cyber security, the advantage is almost completely turned around since it lies with the attacker. There are so many different ways to launch an attack that a networked computer (including via "sneaker net") can't be fully defended against. It is so difficult to safeguard against all attacks that even industry experts such as HBGary and Steve Gibson are at the mercy of the attackers.

Apple Retail Store

I recently checked out the iPad 2 at an Apple retail store and I noticed it was a special demo unit since I couldn't move the app icons to different locations. Obviously, you don't want customers messing up the demo models. But, this got me thinking about how hard it would be for Apple to wall off the computers in the store which are running Mac OS X.

How To Pull It Off

The first thought experiment I conducted to steal software on the Mac, such as Microsoft Office or Adobe Photoshop, was to drop to the command line to tar and gzip the apps, then scp the apps to one of my servers. Obviously, this isn't a simple operation and anyone sophisticated enough to do it would probably realize they'd leave an audit trail.

MobileMe To The Rescue

As I thought more about it, I realized that each Mac on display in the Apple Store has a subscription to MobileMe. MobileMe comes with iDisk, and iDisk comes with a publicly accessible folder. Unlike a Windows application, which usually requires an installer to update the Windows registry, each Macintosh application's settings are stored under the system and user's preferences folder. If those configuration files don't exist when the application is first launched then they're automatically created. These configuration files usually contain any needed software licenses for basic installations, too.

You can probably see how the rest of this plays out. Simply drag a copy of an application, along with its preferences folders, to the iDisk's public folder and then access it from any other Mac, when you get home, and you now have a copy of Microsoft Office, etc. This is probably a key reason companies like Microsoft and Adobe have moved to a subscription based model


What Did I Steal?

What did I actually steal to test out this theory? Well, even in the name of investigative journalism, I saw an ethical issue with actually stealing anything in this case. Both my ethics training at college and my writing on this subject wouldn't allow it. But, as a test, I took a screen shot of a website, for which I own the copyright, and then dropped it on the iDisk's public folder. That's all there is to it.

Next Steps
For starters, don't actually try conducting the thought experiment that I outlined above. What can Apple do to prevent this? Simply setting the public iDisk folder to require a password would prevent this particular attack. Although, pointing out this vulnerability and its solution to a couple Apple Store employees didn't seem to sink in.


Wednesday, March 23, 2011

Living Without Incandescent Bulbs

As with all new technologies, there's a bit of a learning curve to understand the gotchas. Over the past few months, I've started replacing incandescent bulbs with low-energy light-bulbs, more formally known as compact fluorescent bulbs.


When I first started making the switch, my biggest concern was the color and brightness of the light emitted from these bulbs. I did not like many of the ones I've seen in hotel rooms which were too dim and yellow. A visit to Home Depot solved that problem since they had some on display that you could juxtapose which worked out very nicely.

Once I understood the color terminology such as bright white, soft white, etc, I thought I had the problem licked.

Unfortunately, there's a problem that I can't figure out how to solve which is that some compact florescent bulbs take longer than others to reach full brightness (on the order of a couple minutes).

Here's an example where I installed four GE bulbs of the same power and color with very different results. Although the following photo does not show the true difference, I can tell you that the bulb on the right is much, much brighter than the others for the first two minutes. The three on the left are so dim, when first turned on, that they're truly annoying. But, once they're are warmed up, you can't tell the difference.



In my limited experience with these bulbs, the only thing I've noticed, in common, about the bulbs with the long warm up time is that they're all made by GE. Of course, the irony is that GE is suppose to "bring good things to light." If I could go back, and do it again, I'd look for white LED bulbs instead of compact florescent lights to replace my incandescent bulbs.

Saturday, March 12, 2011

iPad 2 Launch, Part II

Covering the actual iPad 2 launch wasn't as interesting as covering the first person in line, the day before.

Friday, March 11, 2011

San Diego Tsunami a Non-Event

By the time the tsunami traveled from Japan to San Diego, it seemed to have lost all of its power. As spectators flocked to the beaches to see this morning's non-event at Carlsbad, a lone surfer threw caution to the wind as he rode the waves near the very spot where Junior Seau drove his SUV off a cliff. So many people parked along the Coast Highway that the Carlsbad police had to shoo away drivers who parked illegally.



iPad 2 Customers Queue Up in Carlsbad

Last night, I starting gathering some background info for a story that I'm writing on today's iPad 2 launch at the local Carlsbad Apple Store. After interviewing the first person in line, Paul Yorke, he tweeted it out:

I was just interviewed by an AOL news organization called the Carlsbad Patch carlsbadpatch.com #inLine4iPad2less than a minute ago via Twittelator



My editor saw the tweet so we ended up running the story-before-the-story. It was my first real attempt at a video story incorporated into a written article; so the quality should only get better from here.

Monday, March 7, 2011

I Still Don't Get Twitter

"Getting" Twitter isn't really that hard. Most people understand that an e-mail is an online version of a written note or letter. But there are a few short falls of e-mail that don't match how we communicate in the real world.

First, it's difficult to have a real time conversation over e-mail. Second, people usually do not talk to each other by speaking several paragraphs before getting a response during a casual conversation. Third is the fact that you can't easily start a conversation with someone you don't know.

Twitter and Facebook simply take the conversations that we have at parties, cafes, bars and mixers into the online world.

Facebook is the private party or water cooler chat we have with the people we know, whereas Twitter is the place to have a random conversation, in public, usually with strangers. The beauty of Twitter is that you can search the conversations and jump in at any time.

Just like many people don't go to bars or cafes for atmosphere, the same is true for logging onto Twitter or Facebook. You don't have to do it if it doesn't float your boat.

Saturday, February 26, 2011

Craigslist Taxi Service in 11 Minutes or Less.

On Thursday, I drove up to French Valley airport, in Temecula, and flew back home to Carlsbad. While the drive takes about 45 minutes without traffic, the flight is about 15 minutes. The only problem with flying back to Carlsbad was that my car was still at the airport in Temecula.

I considered a couple options to get back to my car including paying for a taxi or a one way car rental. The taxi option would have cost about $120 which made it an easy decision to say, "No, thanks."

A one way car rental could have been a good option if the stars lined up correctly. Some car rental companies charge less than $30/day - the problem was finding one in Carlsbad and and another one Temecula. While I did find a car rental for about $40/day, they told me that they'd add at least another $40 for the one way rental.

Enter Craigslist
After almost giving up, I ran a search on Craigslist and discovered that someone had posted an ad asking for a ride from the San Francisco airport to Palo Alto. While I've never bought or sold anything through Craigslist, I was well aware of how closely people watch it so I posted my ad.


Instant Gratification
I posted the ad at 12:51. Within 11 minutes I had one e-mail and one voice mail from two different people. I called back one of the "bidders", Anthony, who said that this job would help him make ends meet until he received some college money that he was expecting next week. I gave him the address and we set the pickup time for 2 p.m.

I was wondering what he meant when he said that he was expecting some money for college. Two things popped to mind. At first, it sounded like he was expecting money back from the G.I. Bill since the VA pays you back once you've completed a class. I quickly dismissed that remote possibility for a more likely scenario which was that he was waiting for a check from mom and dad.

At 1:55 p.m., he called me to let me know that he had arrived. I walked across the street to the school wondering what my ride to Temecula would be like.



It turns out that Anthony is a former Southern California gangbanger who joined the military. After getting out of the military, a few years ago, he became a born again Christian and began using his G.I. Bill to study theology at a local Christian college.

Military Connection
Since we were both in the armed forces, we had a lot to talk about on our drive. I was impressed with Anthony's military background. He served in Coast Guard from 2002-2006 in their security forces unit which is used for both boarding and securing ships at sea as well as counter-terrorism.

He also knew his Coast Guard history. When I mentioned that the last time I was on a Coast Guard ship was the USCGC Munro in West Africa (Djibouti) he told me that that ship is named after the Coast Guard's only person to be awarded the Medal of Honor. While I knew that, since the ship's captain told us the history of the ship during my visit, what I did not know, which Anthony went on to explain, was that Douglas Munro was posthumously awarded the Medal of Honor for rescuing Marines during the Guadalcanal campaign in WW II.

Finances
While Antony never complained about not having money, I could tell things were tight for him and his wife and kids when we got off the highway and he asked for some of the money, a few miles before the airport, to pay for gas. I felt bad for this guy who had obviously turned his life around. He was now on the straight and narrow to the point that he wouldn't even say "Hell" when he told me, "The Navy guys used to give us heck."

As we pulled up to the airport, he told me that, when he was in high school, he went on a tiger cruise with his father who was in the Navy. A tiger cruise is usually the last week of a six month deployment when the ship picks up civilian dependents so they can get a taste of life aboard a Navy ship. It turns out that his tiger cruise was on the U.S.S. Boxer in 1997 which is the same ship and deployment I was on.

When he dropped me off I couldn't help but give him an extra $20 for the company and conversation.

Thursday, February 24, 2011

Amazon S3 Webinar on New S3 Features

This morning I attended Amazon's Webinar to learn about their new S3 features. Their newest feature, which was launched last week, allows you to set a bucket's default root object (i.e. index.html) and it also allows you set a default HTML error page to return for 4xx HTML status codes. These features make it easier to host a static website on S3.

Actually watching someone walk through the Amazon console was very helpful and I learned a few things to keep in mind.

1. If you set a bucket's default object to index.html, then each bucket's subfolder's default object must have the same name (i.e. index.html). For example, if you want http://www.example.com/subfolder to return a default object then you'll need an object named subfolder/index.html.

2. Don't forget make website objects public so that they can be read by anyone on the Web. You can set a bucket's default upload policy to public and then, later, explicitly set a specific object as private so that it will only be served up to a user after authentication (i.e. a digital signature with expiration, referrer, or specific IP address).

3. The new feature maintains backward compatibility so that the API still returns XML when accessing a bucket directly, yet, it'll return your default object when appropriate. They accomplish this by changing the URL to your bucket's root object using a slightly different end point URL for you default HTML object, such as:
http://pubs.joemoreno.com.s3-website-us-east-1.amazonaws.com
This is a technical issue which will be completely transparent to anyone configuring the new feature using the AWS console and, most importantly, it's elegant in that it fully maintains backward compatibility with their APIs.

Gotcha
Although Amazon S3 still does not allow you to configure an A record so that you can host http://example.com, I got the impression that this feature will be available in the future. Although I'm speculating, today's comment, from Amazon, was, "We're looking at ways that we can do that [host a domain's root without requiring a subdomain]."

Workaround
In the mean time, Donovan Watts showed me his workaround, last night, that he uses with Adjix and CloudFlare. His workaround allows a domain's root domain, which normally must be a DNS A record, to be configured as a CNAME. Although I have't tried his technique, yet, I can see it in action with his short domain name.

Friday, February 18, 2011

Hosting Static Websites on S3: The 99.4% solution

Today, Amazon announced a new feature which allows you to (almost) host a static website entirely on AWS S3. They do this by allowing you to set a default root object for each S3 bucket. Think of the default root object as the equivalent of an index.html default file. This setting tells a web server which file to return to the user when one isn't specifically asked for. For example, when you enter cnn.com in your web browser, CNN's web server automatically returns www.cnn.com/index.html.

Gotcha
In order for this feature to work, you'd have to configure your domain's DNS CNAME (alias) to point to your bucket. But there's a big gotcha and that's the fact that a CNAME record can only be used with subdomains (i.e. www.example.com, blog.example.com, images.example.com) and not the root domain (i.e. example.com). The DNS RFC directs that the root domain must be an A record which can only point to a numeric IP address.

Amazon Permanent Fix
To fix this problem, Amazon would need to set up servers at a single IP address. Load balancing a single IP address is exactly what keeps the entire DNS root servers alive and running. While there may only be 13 different static IP addresses for the world's DNS root servers, each one is supported by many redundant servers located on different continents. In other words, one static IP address can easily map to an unlimited number of physical servers.

Workaround
Since an Amazon fix to this problem may not be in the near future - or it might never come - there is a workaround, but it's not as elegant as it could be.

I've actually been using the following technique for a few years at Adjix. When visiting adjix.com, note that the URL for most of the static web pages at the bottom of the Adjix home page begin with web.adjix.com. As long as things are working, most people never even notice if a URL begins with www, web, blog, or has no subdomain.

1. Create an S3 bucket called www.example.com. Put an index.html file in there along with all of your website's static content and set the index file as the bucket's root object.

2. Configure your DNS CNAME to point to this bucket (i.e. www should point to www.example.com.s3.amazonaws.com.).

3. This final step is unpleasant and inelegant from a technical point. It involves using a third party service where you can configure our domain's root domain to point to a static IP address. I would be more than happy to host this redirect service for your domain's root A record. If you're interested in using this service then please let me know via e-mail.

Nearly anyone who visits your website, by typing the URL directly into their browser, will either enter www.example.com or example.com. Either method will work since they will be redirected to www.example.com/index.html.

While redirects aren't always elegant, you've probably noticed many redirects when logging into your Google account or when accessing a custom domain blog on Posterous. It isn't as clean and quick as it could be, but it doesn't violate any RFCs and it works.

Thursday, February 17, 2011

"Facebooking" immediately after being held up at gunpoint

A local pizzeria was held up at gunpoint and "Facebooked" the incident practically in realtime.


For the details, watch Deanne Goodman's Carlsbad Patch interview.