Showing posts with label production notes. Show all posts
Showing posts with label production notes. Show all posts

Dec 7, 2011

a teaser clip from the upcoming 'Robot Destroy Club' Game

Helicopter from Jean Pichot on Vimeo.

Short production breakdown teaser for the upcoming Robot Destroy Club game.
Helicopter scene, shot 22, version 3; green grade variation.

C4D, Luxology Modo, AE, soundtrack composed in Ableton Live.

Nov 7, 2011

Oct 3, 2011

Since Autumn is upon us...I feel a little introspection is in order

"And this is what mere humanity always does. It's made up of these inventors or artists, millions and millions of them, each in his own way trying to recruit other people to play a supporting role and sustain him in his make-believe. The great chiefs and leaders recruit the greatest number, and that's what their power is. There's one image that gets out in front to lead the rest and can impose its claim to being genuine with more force than others, or one voice enlarged to thunder is heard above the others. Then a huge invention, which is the invention maybe of the world itself, and of nature, becomes the actual world - with cities, factories, public buildings, railroads, armies, dams, prisons, and movies - becomes the actuality. That's the struggle of humanity, to recruit others to your version of what's real. Then even the flowers and the moss on the stones become the moss and the flowers of a version."
-- Saul Bellow, The Adventures of Augie March, Chapter XIX
Enhanced by Zemanta

Aug 31, 2011

Thoughts on Project Management from someone at Nasa

Every project is implemented under three const...Image via Wikipedia
I was chatting with some co-workers of mine today on Project X and the discussion turned to: Why is our project having so much trouble completing all its goals?The answer that I came up with is structural, and drove this blog post.

In short, here's how to structure a project for failure.

Step 1:  Create a project with goals A, B, and C.   Fund it reasonably to accomplish those goals. 

At this stage, everything is working very well.  Proceed to step 2!

Step 2:  Involve more than one person in the management and direction of the project.

This step takes many forms.  Sometimes it's a committee or board that runs the project, other times it's reporting to multiple bosses and/or centers for guidance.  Either way it's critical to ensure that there are at least two people with differing priorities, all of whom have some sort of say in the project.

Step 3:  One of the managers adds goals D, and E.  No additional funding, or insufficient funding,  is provided.

Eventually as your project is initially successful, someone in the management chain will identify things they'd like done which seem a lot like other things you're successfully doing.  It's awfully tempting to add this to your project, as you already have skilled workforce performing similar tasks, and they DID see you reading Reddit that one time so clearly you're not all 100% working 100% of the time.

This is the critical stage in project failure - because now the staff has insufficient resources to continue the work.

Step 4:  Shoestrings and Duct Tape.
In this stage, the project lacks the resources to fully perform tasks A,B,C,D and E but has no strict prioritization.  They either internally prioritize, fully fulfilling A,B,C while shoestrining D and E or, more often, shoestring all the priorities equally.  Now they're doing all of the jobs, but at least some and most likely all of them poorly.

Step 5:  Management disagrees over prioritization.

In this stage, the project staff have brought up their troubles to management.  They can't proceed with the amount of funding and tasks they have to accomplish, and they either need less tasks or more funding.

However - and this is the critical keystone in the bridge of fail - each of the individual managers begins to insist that their priorities are the reasonable ones, and that no extra funding is needed if you'd cut the other guys' stuff.

Manager1:  You clearly have enough resources for A,B,C.  D and E are unimportant. Therefore, you don't need money.
Manager2:  You clearly have enough resources for A,D,E.  B and C are unimportant.  Therefore, you don't need money.
.... And so on.

The key thing here is that individually each manager is being completely reasonable about their expectations from your project.  But collectively, they're being completely UNresasonable.

Step 6:  Saving throw vs. Morale

At this stage, the staff executing the project begin making monthly saving throws vs morale.  Unless management either provides more resources or less work to do, they stand an increasingly likely chance of having critical staff get fed up and leave for greener pastures.   IF management turns things around at this stage, the project can still be saved.  If not.....

Step 7:  It's too late.

Beyond this step, it's probably too late to save your project.  Even if management gets things turned around with funding and expectations, at this point you've lost too many key staff and your project has too poor a reputation internally to recruit anyone good to come back and work on it.   Project: Failed.

Enhanced by Zemanta

Jul 4, 2011

I'm not sure if this image become an icon....


I just wanted to put that out there. On one hand it's kinda rhetorical. On the other hand- I already know the answer to that question. Feel free to comment or request more information. I just discovered that something weird is going on with my computers right now, which in and of itself is weird but not unexpected, because of  multiple device failures.
[FYI/BTW note the time of this post and my current mental state. It is 3am and I'm tired, but my mind is

[this space was intentionally left blank]
I also wanted to do something for Isaac in this post. I wanted to capture part of a conversation we had earlier this afternoon. I was in process of visualizing what the "goal" or "resultant" would "be" and that's when I this thing (see above) and started blogging. And just now I realized that the thing at the top of this can be identified or defined as: an image or an animation or file. It also all those things. I know, and there's more. I don't know how much longer I can keep at this, but now i'm committed to "this" and even if I pass out blogger has this great autosave feature. So where was I.....I see now. image/animation/file and here is a little preview to my answer-
Enhanced by Zemanta

Jun 5, 2011

The downward spiral of a fortune-cookie writer...

will not be discussed or revealed at this time.


Watch "Hanna" online,  I'm about an hour into it. I like the movie, but I am in awe of what was achieved in post. The sound design and editing in particular. It is hella impressive, and it's old-school. Straight cuts, and quick fades. It's the kind of work I dream about doing- the type the inspires. I completed my system recovery...  No wait. Let me rephrase. I recovered the internal HD on the iMac and I stabilized my "half"-laptop. But I haven't got it working right. And, as a result, haven't done any real work in the last 4 days. I could really, really, really use a system engineer because I know what I have to do. I'm not doing it because I'm in this weird mindset. It's this grey area that is normally easy to identify and clearly labeled- like my LAN. But I'm watching Hanna, and I'm not thinking about why my NAS volumes aren't showing up properly- or the policies and permissions that seem to apply themselves whenever they feel like it . And I am pleased with the fact I will not be generating a report, or gathering statistics on how long it would take DataRescue 3 to recover 1TB of my files. I am also indifferent as to why the built-in ethernet adapter on my HP TX1000 laptop is, isn't sending or receiving packets (despite what the bios, control panel, windows services tell me that it is there and working). This fog is tempting me to research, troubleshoot and resolve these technical "anamolies". It works, after all- but it doesn't flow like it should. I'm gonna finish watching the movie now, then see what happens next. Kinda like my so-called-life.

Apr 13, 2011

WADE




Wade is a creative studio. Working independently and with a range of talented artists, designers, writers and developers, the studio concentrates on communicative image making.
The works currently produced range from commercial to self-initiated and cover mediums of (but not limited to) printed matter, interactive and moving image.
Why the name Wade? Wade (as a verb) is a reminder of how best to travel through the working environment.
To wade is to experience the journey.


Silver Black Cycle from Rhett Dashwood on Vimeo.
Initially created for Asahi Silver + Black exhibition.
http://www.asahibeer.com.au


Mar 14, 2011

Even though my guest has worn out his welcome...

I've been hella productive this afternoon in Oakland. I must praise and acknowledge  Clay Parker Jones and his work with wireframes. After checking out some of the clips on vimeo, I went over to his blog for additional resources and inspiration. Now I'm going to escort my guest to the door and get back to work

How to Wireframe from Clay Parker Jones
Building a little wireframe for a project I'm doing with Mr. Gaffney and Hustlewood: Obama Baton.Watch this if only for the moment when the beat comes in as the page scrolls up. I'd be lying if I said that was intentional.

Enhanced by Zemanta

This actually turned out better than I thought

I made this at http://twitstamp.com and took me about 30min., but after you join and login you have to upload a PNG file before you get into the design/layout functionality. Now it's important to note that this is a free site, and I like to show my support by 1. Using their tools and 2.Help them improve their site functionality and user interface. But whenever I discover a new technology- I sometimes get too involved in making that particular application part of my workflow or creative process

More on this later.

Enhanced by Zemanta

Jan 13, 2011

Who Owns Your Data?

Who Owns Your Data?

Alistair Croll is the co-chair of O’Reilly’s Strata conference, which tackles the convergence of Big Data, ubiquitous computing, and new interfaces. The next Strata event happens in Santa Clara, CA from February 1 to 3.

Jan 3, 2011

And we're off to a new year

Since I still haven't sent my mom the paragraph or so 'summary' for the strickland family newsletter- I have decided to re-post an article by Adam Dachis who wrote

Those important computer tasks—like securing, cleaning, and backing up—are like any other resolution: we all say we're going to do them but rarely keep up with them all year. Here's our simple guide to staying on track in 2011.
Keeping your computer in good shape gets to be tedious and annoying when you have to try to fit it in to your busy schedule. Rather than letting things slip through the cracks and watch your computer slow to a crawl, fall victim to a nasty virus, or crash and burn with no backups, we've put together everything you need to tackle to stay on top of all your computer maintenance tasks. Here are the four things we're going to look at (feel free to click to skip to any of the sections):

Back Up Automatically

Resolved: How to Keep Your Computer Safe, Clean, and Backed Up in 2011
Backing up our data is something we all know is important but many of us do not do. In the past you might've been able to get away with the excuse of inconvenience, but nowadays it's so effortless that if you're not backing up, you should make it your first order of business for the new year.
A good backup system will duplicate your important data in three places. One of them can be your computer, another can be an external hard drive that you keep in your house, but one of those three places should exist outside of your home. Local backups (liking backing up to an external USB drive) protect you if a hard drive dies, but not if your house is robbed, catches fire, or your fall victim to any other incredibly fun disaster you can imagine. While these are rare circumstances, the effects are devastating. Since backup is so easy, there's really no sense in taking the risk. First we'll take a look at backing up to the cloud, which requires essentially no effort at all, and then we'll consider your options for each specific operating system so you can have a local copy on an external drive as well.

Backing Up to the Cloud

Resolved: How to Keep Your Computer Safe, Clean, and Backed Up in 2011
As long as your work doesn't consist of serious data creation, I'm of the opinion that you can use Dropbox for all your backup needs, especially now that it includes selective sync. I used Dropbox toorganize my home folder and sync my iTunes library to multiple computers and it works great. While Dropbox can take care of just about everything I want backed up and synced, it can't handle your applications and system files without causing problems. Also, for reasons I don't entirely understand (aside from the cost), not everyone wants to keep the majority of their stuff in their Dropbox. So, for those of you who aren't sold on Dropbox being the golden egg of cloud backup, your other best bet for off-site backup is Mozy.

Backing Up to a Local Drive
NOTE: While we're not going to get picky about the brand of drive you use, make sure you get one that's a bit bigger than your computer's drive if you want to save multiple backups.
While Mozy can back up to an external drive nicely, you may prefer a backup tool with a larger feature-set that's more tailored to your operating system. Fortunately, there is no shortage of backup software available for every operating system. We've narrowed down the pool and have a few options for Windows, Mac OS X, and Linux, that should cover all your local backup needs.

Windows

Resolved: How to Keep Your Computer Safe, Clean, and Backed Up in 2011
Built into Windows 7 is the Backup and Restore Center, which Microsoft debuted in Windows Vista and has since improved in Windows 7. While it'll take more than a few clicks to set up, you're given a good number of options to control how your data is backed up. You can choose what you want to backup, where you want to back it up (including network locations), and how often you want the backup to occur. While it may not be the perfect solution for all users, it's built into Windows and pretty easy to set up.
Alternatively, you have the classic SyncBack. The SE version is free but you can pay for additional features. Nearly five years ago, Gina used SyncBack SE to set up an automatic backup plan that still works today. If Windows Backup Center doesn't quite cut it for you, SyncBack SE is a great alternative.

Mac OS X

Resolved: How to Keep Your Computer Safe, Clean, and Backed Up in 2011
One nice feature of Mac OS X 10.5 and 10.6 is Time Machine, which lets you plug in a drive and just back up with no effort at all. Once it has a full copy of all your data, it will only backup the files that have changed since that original copy was made. If you want a file you lost, you can activate Time Machine and go back in time to retrieve an earlier copy of that file. Your Time Machine backup drive can also be used to restore lost data and set up a brand new Mac with all your files.
Time Machine pretty much does what it wants to do and that's that, so if you're looking for more control I'd suggest picking up Carbon Copy Cloner. It's a free backup utility that makes a bootable copy of your drive (which Time Machine does not). I use it all the time and love it. It can be as simple as selecting the drive you want to copy, but you can also selectively copy certain files. Carbon Copy Cloner is very straightforward backup software, so you're not going to find the bells and whistles you might with paid software, but if you want something simple that also offers quite a bit of control over your backup, it's an ideal choice.

Secure Your Computer and Your Life Online

Resolved: How to Keep Your Computer Safe, Clean, and Backed Up in 2011
There are a number of ways your computer can get into trouble. Whether you're dealing with viruses, online threats, or physical theft, here are some great tools to help keep you safe.

Antivirus Software

Resolved: How to Keep Your Computer Safe, Clean, and Backed Up in 2011

avast! antivirus software
provides complete virus protection for your computer. Antivirus engine is complemented by anti-spyware, firewall and antispam modules to protect you against phishing schemes, identity theft and internet-distributed web viruses. Automatic updates for greater user convenience and safety. Top user ratings among free antivirus software. The new avast! Free Antivirus 5.0 includes a spyware detection engine. To protect you from identity theft as well as viruses. avast! Pro Antivirus - better protection during web surfing. Full-featured antivirus software. Better than our free antivirus, especially for web surfing, but without the firewall and antispam included in avast! Internet Security. Also if you wish to customize your security, this is the recommended software.


Preventing (and Preparing for) Computer Theft

Resolved: How to Keep Your Computer Safe, Clean, and Backed Up in 2011
Prey is a wonderful, free, open-source tool that can help you track down and (potentially) recover your stolen Mac, Windows PC, or smartphone. If you're like me and you've had your laptop stolen before, you know how devastating it can be. When you lose technology with personal data, the thief doesn't only have access to your expensive hardware but a lot of information about you as well. Coming to this realization is not fun, so be smart and take the necessary steps to protect yourself from a potential theft.
For those of you with iPhones (or other iOS devices), you're lucky enough to have free access to find my iPhone. Set it up and use it! If you're don't have a recent iOS device, we've got you covered. Here's how to set up Find My iPhone on older iOS devices.

Run Regular Maintenance

Resolved: How to Keep Your Computer Safe, Clean, and Backed Up in 2011
With your data backed up and protected, you're going to want a computer that runs smoothly. Performing regular maintenance can play a big role in keeping your machine in tip-top shape. Mac OS X and Windows 7/Vista will take care of defragmenting your drive for you—so no need to take care of it yourself—but if you're running earlier versions of Windows you should check out our guides on setting up a self-repairing hard drive and setting up scheduled tasks to run your favorite cleaning tasks in the background. If you're a fan of CCleaner (the all-in-one crap cleaner for Windows), check out this guide to automating your CCleaner sessions.
For Mac users, maintenance tasks are regularly scheduled by OS X and so, technically, you don't have to do anything yourself. Nonetheless, it's in your best interest to play a hand in your system's upkeep. If you want a look at every possible option you have, definitely check out our guide on cleaning up and reviving your bloated, sluggish Mac. Alternatively, if you want to do a bit less, you can just schedule maintenance tasks in the Terminal and repair disk permissions. If you're not familiar with repairing your disk permissions, all you have to do is go into your Applications —> Utilities folder and open up Disk Utility. Inside of Disk Utility, choose the First Aid tab and then click the Repair Disk Permissions button. It'll take a few minutes and slow down the system a bit, but running this operation will help prevent little errors here and there. Running this once a month (and after any major software installation) will keep your Mac a bit happier and less prone to preventable issues.
Last, if you have a bad habit of letting your Downloads folder or Desktop get out of control, check out our guide to automatically cleaning and organizing your folders with Belvedere (or with Hazel if you're on a Mac).

Create a Tidy, Attractive Desktop

 



This was taken today.  And now I have to get back to work.
However- I should publish a system status overview that includes my network topology and other interesting statistics.

Nov 28, 2010

friday night nonchalance

The other day I was telling Isaac about how and why I decided to title my blog '510 Collection'. And while we were standing in line at McDonald's, I began to tell him. (oh, and you're probably wondering 'what were you doing at McDonald's'? and 'isn't Isaac vegan'? well, I was going to prove to Isaac that they would accept and make change for a $100 bill. And he ordered a medium Orange Juice btw) And now, while waiting for the system to finish the transcode I started an hour ago, I am going to share the motivation, inspiration and evolution behind this blog that carries this name.






Nov 12, 2010

Tried to get cute with cookies, containers and javascript


But I got it anyways. With all due respect to the artist, I am merely creating an alternative resource link so that I may properly bookmark and tag the image above as a favorite on ViSualize.us . I would like to acknowledge how from this single image; fit, form and function achieve balance. And it's simple, cool and I would even speculate would cost you about $100. And I believe that the interior designer should get street cred.

Nov 4, 2010

Why I don't use Facebook, even though I like 'The Social Network'

Tomorrow I'm eagerly anticipating yet another poignant and astute conversation with Isaac.  When he and I spoke earlier this evening, our conversation was just getting to the good part. Which is why i'm posting this entry and postponing my visit with Kado.  I should however, let you know that I'm not going to summarize at this time. Be patient, he hasn't even seen the movie yet. But I have a plan. Tomorrow while I'm doing some tech support on a laptop, I'll sit him down and let him watch 'The Social Network'
(I got a real nice 480p divx version from a DVD Screener, and i can live with myself and sleep just fine knowing that I'm going to do a formal review/critique of the movie in the next couple of days) which brings me to part 2 of the plan: setup Isaac's desktop computer with a webcam and introduce him to podcasting. This is something that he's been wanting to do for awhile, and as soon as i post this, I'm going to get a webcam that will fit/form/function. So since this is my plan, i'm going to go ahead and wrap things up by saying that over the weekend I intend to post the inaugural podcast. I'm going to throw a widget in here because. Think of the songs I posted earlier this evening as a teaser or preview, which isn't accurate or true. I arranged the widget so that the latest uploads are at the top (and are timestamped and tagged because rich metadata matters to me) feel free to comment, or not. Stream, download and share. I'll even post to twitter, and more than likely remain apathetic to facebook, and i'll continue to support and incorporate zemanta (as long as it compliments, not complicate my plan). TO BE CONTINUED  

Enhanced by Zemanta

Oct 27, 2010

what the "Bleet"?!


Just so you know...this post was originally composed by Eric Butler and he has a blog, I've just been cutting/pasting/revising periodically.
 This was certainly an interesting day.Since being released just over a day ago, Firesheep has been downloaded over 129,000 times. Firesheep has consistently been one (if not more) of the “Top Tweets” on Twitter, on top of Hacker News, was at one point the #10 trending search on Google in the US, and is the second suggestion on Bing when you start typing “fire”. Firesheep has been mentioned on countless blogs and news sites in numerous languages, and has received almost universal praise.The first bug reports have started rolling in:
  • "Backend exited with error 1" — This happens on Windows when you stop capturing. This message doesn’t actually indicate a real problem and can be ignored. This was a known issue that I wasn’t able to get to before the ToorCon release.
  • "Run --fix-permissions first" — This problem appears to affect only Mac OS X users who are using FileVault. The current release of Firesheep is unfortunately incompatible with FileVault.
  • "Funky custom tool bar icon explosion." — This one is actually a bit amusing.
All of these issues will be fixed in the next release.
There have also been a few common problems:
  • No results on some Windows systems — Some users have reported that they aren’t seeing any results even when on an open network that has known insecure traffic. This may be because the wrong interface is selected. Click the gear icon at the bottom of the Firesheep sidebar and choose Preferences. From here you’ll be able to change the interface Firesheep listens on.
  • Sidebar not displayed — If you’ve installed Firesheep but don’t see it, click the View menu then select Sidebar then Firesheep.
  • Install error claiming Firesheep is not compatible with your version of Firefox — Several people ran into this problem because they were unknowingly running out of date (and insecure) versions of Firefox. Apparently Mozilla’s auto-update system is leaving some people behind. Currently the latest version of Firefox is 3.6.11. Firesheep is not yet compatible with the 4.0 beta.
  • Compile error on Linux — Firesheep is not currently supported on Linux and will not work. Patches/pull requests gladly accepted!
Keep an eye on this blog as well as my Twitter feed for updates on these issues and other new features.
The real story here is not the success of Firesheep but the fact that something like it is even possible. The same can be said for the recent news that Google Street View vehicles were collecting web traffic. It should not be possible for Google or anybody to collect this data, whether intentional or not. Going forward the metric of Firesheep’s success will quickly change from amount of attention it gains, to the number of sites that adopt proper security. True success will be when Firesheep no longer works at all.

Background on HTTP Session Hijacking

HTTP Session hijacking, as a vulnerability, is nothing new in the year 2010. It is a security vulnerability that people have been aware of for quite some time, with notable tools and papers existing at least since 2004 on this exact subject. OWASP (The Open Web Application Security Project) categorizes the issues responsible for HTTP Session Hijacking in to one of it’s Top 10 Web Security Risks, “A3: Broken Authentication and Session Management”.
Firesheep is by no means the first tool to exploit this issue and raise controversy. "Ferret" and "Hamster" were a pair of tools released by Errata Security in 2007 which let users exploit Sidejacking attacks easily (well, easily for geeks, and undoubtably easy for attackers). In 2008, "Cookie Monster" was released by Mike Perry which lets you again do this same attack. Last year, (around May 2009) Azim Poonawala released the tool FBController which yet again exploited this same issue, though this time specifically targeting Facebook. Very little has changed after each of these tools were released. They got their media hype, and then people forgot or didn’t care. For the most part, the tools were only used by tech-savy people, hackers and geeks.

Firesheep

Firesheep is doing the exact same thing as these other tools, but with a simpler user interface. Firesheep is more generic than FBController, but it still needs to be aware of what sites to target.
Because of its simplicity, Firesheep has already succeeded in demonstrating the risks of insecure websites to a much wider audience than any previous tool, in a single day.

Why is it hard to stay safe?

Websites that don’t have properly designed security architectures and implementations can make it very difficult for users to protect themselves. There’s a few levels of failure here that are worth noting.
  • Complete absence of SSL/HTTPS — This is rare nowadays for popular sites, but it’s not unheard of by any means. Until recently, Foursquare fell into this category. Naturally, if you use such sites you’re exposing everything needed to identify your session with the site, potentially even your password. This is particularly bad when you consider many people use the same password for many different accounts. It’s terrifying to think that something as mundane as a Foursquare password could get you in to that person’s email, or even financial websites.
  • Charging for SSL - GitHub and Evernote are some examples where you must pay to have full-session SSL. We have not confirmed if this is implemented properly once you pony up the cash but can confirm that on GitHub a free account that is associated with a paying organization leaves that entire company at risk. A basic expectation of privacy should not be a premium feature.
  • Forced SSL/HTTPS for posting of Login/Password credentials only - Most big sites are in this bucket. Facebook, Twitter, Github, etc. Years back, people realized that sending usernames and passwords in plaintext was a bad idea, and so everyone started encrypting the transmission of those particular assets, and boasting how secure they were because they use SSL with 128-bit encryption or whatever it may be, and pictures of locks everywhere. These sites may serve other content over HTTPS if you explicitly request it, but they’ll rarely be opportunistic about serving content over HTTPS. These sites fail to protect you because after you’ve authenticated, you’re issued a cookie that identifies you throughout your browsing session, but if you think about it that’s just as good as your username/password for 99% of the time.
  • Full HTTPS for everything — Some sites support full encryption everywhere, but don’t implement it properly by failing to set the “Secure” flag on authentication cookies, negating most of the benefits and leaving users at risk. What that means is that any time you type the URL (e.g. “manage.slicehost.com”) into your web browser (without explicitly typing https:// beforehand, which people rarely do) you will inadvertently leak your cookies with that first request, prior to being redirected to the HTTPS page. Slicehost and Dropbox are good examples of this mistake.
You can’t simply avoid visiting the sites that are being attacked here. There’s an enormous amount of mixed content on the web today, such as the Facebook “Like” button, Digg’s “Digg It” button, twitter widgets, and even embedded images that are hosted on Flickr or other photo sharing sites. Every time you access any web page that includes any of this content, your browser also sends any authentication cookies you have with the request to pull down the widget. TechCrunch is a great example of this, every article has lots of little widgets to share it on numerous social sites.
Even if you’re proactive and think to log yourself out of a website, this rarely does anything but delete the cookies from your web browser - meaning any stolen copies of them are still going to work for accessing the website. Twitter, Amazon, Foursquare, Github, Flickr, Yahoo, Windows Live (Hotmail) and many others do not properly delete your session from their severs when you use their “Logout” features. Facebook, while having other problems, does appear to properly delete sessions on their servers when you “Logout”.
People forget things. It’s easy to be logged in to many of these services, sleep your laptop, and wake it up somewhere where it will instantly associate with an open access point and start spewing your cookies over the air. Hackers even fall victim to this at hacker conferences where everyone knows they shouldn’t be doing anything on the wifi. The DEFCON Wall Of Sheep is a prime example of this.

Suggestions to help protect yourself right now

While companies are implementing fixes (described below) you can do a few things to increase your level of security, but there’s no silver bullet (aside from stopping use of the services which you don’t want hijacked.)
  • HTTPS-Everywhere - This is a Firefox extension created by the Electronic Frontier Foundation which makes Firefox use only HTTPS connections for certain websites. Like Firesheep, it only works on a defined list of websites, so it won’t protect you if you use any websites that it doesn’t support. It does not appear to be immediately simple for users to add sites without some development experience. HTTPS-Everywhere is well respected for doing what it claims to do safely.
  • Force-TLS - As mentioned earlier, some websites support SSL but don’t implement it properly, leaving you at risk. This Firefox extension is similar to HTTPS-Everywhere but allows you to specify your own list of domain names to force encryption on.
  • VPN - In some situations a VPN (or something similar such as an SSH tunnel) can be great. All traffic sent through a VPN is likely secure from your computer to the VPN server. But be aware that this is not a silver bullet and there are potential problems. See below for our warnings on using a VPN.

Things NOT to do (debunking suggestions from other people/sites in response to Firesheep)

Stop using open WiFi

In response to Firesheep, lots of people are quick to say “Don’t use open wifi”. While open wifi is the prime proving ground for Firesheep, it’s not the problem. This isn’t a direct vulnerability in wifi, it’s the lack of security from the sites you’re using. Abundant, free, open wifi is great to have, it can be very useful. Low-risk activities like reading the news, looking up a nearby business or finding a bus route can be done without being logged in to such sites and risking loss of any important sessions, for example.
A password-protected (WPA2) wireless network or even a wired network just requires that attackers perform one more step to carry out this attack. This might be ARP poisoning or DNS spoofing, neither of which are difficult to carry out. Go and download Cain & Abel and try it out on your network, it’s not that much harder than using Firesheep, and it’s been around for nearly a decade. There are other tools that’ve been around longer.
Another problem is that anyone who has your wireless password could set up their own rogue access point. If they have the stronger signal than the “official” access point everyone in the room will automatically connect to it instead and begin sending all their traffic to the attacker. WPA2 Enterprise was designed to solve this problem by allowing clients to verify the authenticity of the access point they are connected to. Unfortunately in addition to being very difficult to configure, a flaw known as "Hole 196" was recently discovered allowing users on the same network to spy on each other.
For these reasons it’s not very helpful to just enable WPA2 and write the password on the wall. Doing so might actually give users a dangerously false sense of security.
Use a VPN/SSH Tunnel (Without known risks) While we metnioned that VPNs and SSH tunnels can be helpful just above this, we want to emphasize that it’s just pushing the problem to that VPN or SSH endpoint. Your traffic will then leave that server just as it would when it was leaving your laptop, so anyone running Firesheep or other tools could access your data in the same way. These are solutions that require at least some understanding of networking and risks at hand. A blind suggestion of “Use a VPN” doesn’t really solve the problem and may just provide a false sense of security.
Another problem with VPNs is that they don’t work all the time. Sometimes they just disconnect, and your traffic is all routed over your normal interface without any notice. The built in VPN clients on OSX, the iPhone, and iPad are particularly bad at this.

How do website operators fix the problem?

The only correct solution to this problem is true end-to-end security. On the web, this is called HTTPS or SSL/TLS. When SSL is used properly, all traffic is encrypted (unreadable by attackers) and integrity checked (can’t be modified by attackers) from your web browser all the way to the website’s datacenter (either their actual web servers, or specialized network equipment such as SSL accelerators/load balancers).
Designing with security as a requirement, rather than bolting it on after the fact, is also important. While it’s not fair to say this is always what happens, it’s not uncommon for sites to be quickly designed and developed while letting security slip by at a lower priority than other things. Design such that when you scale out, you can scale out securely. Adopt and adhere to a Secure Development Lifecycle process to ensure that security is considered at all points during a product/site’s lifecycle.

Reasons operators may say they can’t do the above

  • Typically the response to implementing SSL for everything on your website has been that it’s a big performance hit. There’s an awful lot of debate about this, but there are a number of sites that require HTTPS for everything, most notably Google’s Gmail service went 100% SSL earlier this year. While it’s true Google has an amazing engineering team and impressive resources, they outline a system that should be approachable by many other sites.
  • Lack of IP addresses for SSL hosts. In the past, an SSL service required a dedicated IP address. This isn’t true any more with the advent of Server Name Indication (RFC 3546) and improvements in TLS.
  • Ignorance. Many people believe they are doing things correctly when they simply are not. Forcing HTTPS for everything but not marking cookies as secure is key example.
Many companies make a business, not technical, decision to not implement security due to either perceived or actual costs. It is our opinion that turning a blind eye to customer privacy and security is never good for business, and we hope the people making these decisions will begin to agree.

May 19, 2010

Due to Popular demand (and my uncanny ability to never have it on me or forgetting which flash drive i used or network share password to access it )

I did not create this document. Sonic (though not the one i know from Tipsy) deserves the credit.  but I can tell you three persistent and confirmed facts regarding this file:
  1. It is to scale (1:1) and know what you're doing if you are going to print it out, which includes having enough ink, the right paper, etc. And it needs to be updated right about now.
  2. Anyone who has ever found themselves spending an extended period of time as a developer. programmer or engineer or is in the company of those who do, or are inclined to on their own accord: use/build/repair/dissasemble/retrofit/modify a computer will appreciate this. It's deep geek chic 
  3. And the instructions for the goat, necessary to complete a SCSI chain or Token Ring are not included.

Enhanced by Zemanta