Tuesday, July 31, 2012

EAS ACCOUNTABILITY

Fine. I get it.

We had a National Emergency Alert System test.

This test was designed to check out the operability of a system that was installed back in 1996, and to date had never been tested for functionality or operability.

Yesterday, at 2:00 PM Eastern, A National Emergency Alert was issued. According to policy, this can only be issued by the President. FEMA and FCC conducted this test under the following scenerio:
1) Normal methods by which other weather and emergency warnings reach us were to be disabled (i.e. EMNET).
2) The Normal test for this, which would have been the NPT (National Periodic Test), was not utilized. Instead, they issued an actual emergency code of EAN (Emergency Action Notification).
3) An EAN is the only code that does not automatically terminate with an EOM (End of Message), as it is intended to keep the system running until it is turned off by an EAT (Emergency Action Termination). There would not be an EAT sent at all.
4) The Washington DC code was sent instead of the national code of 00000.
5) Last minute changes were trickled out to broadcasters via various websites and webinars, but there was no official public forum on this event.
(information can be found at: http://www.nws.noaa.gov/os/NWS_EAS.shtml)

So how did it turn out?

Homeland Security Director Millicent West said there were glitches, but that’s why they run tests.

In reality - it was a disaster of epic proportions.

More than 30,000 communications carriers across the country were involved in the test, to include radio and TV broadcasters, cable operators, satellite operators, and wireline video-service providers. They all cooperated within their limited ability to make the test as successful as possible.

In many places Nationwide, it aired normally. However, in many places, the signal was cut off, garbled, or with major hum in the background. Reports come back from the LP1's of the various states that that is the way they received the signal, and since they were merely repeating what they received, that is what they passed on to others.

What went wrong? Why wasn't it as flawless as it should have been? Lets look at the situation and place the blame squarely where it should go!

THE FEDERAL GOVERNMENT went over 20 years without testing the system. Therefore, in many places - there was 20 year old untested equipment expected to work flawlessly. Right. Like that is going to happen. The Government, at the last minute, changed the rules. THE FEDERAL GOVERNMENT sent a flawed signal (as can be attested to by LP1 entry points across the nation) out into the wild. THE FEDERAL GOVERNMENT changed the rules - using codes that were never intended to be used. THE FEDERAL GOVERNMENT

Thursday, February 23, 2012

Product Review: Santa Cruz Snowdrive USB Flash Drive

Santa Cruz Snowboard USB Flash Drive

There I was, wandering through the isles of another big-box store when what should my eye behold? A techno item I hadn't previously heard about? (and a cool-ish one at that!)

There, hanging off its poorly security protected peg was a flash drive that looked like a snow board! Not just a snowboard, but one with some really rad graphics to boot! Apparently, they also have surf board and skate board models, but there were no skate boards or I would have bought one.

Front Package propoganda included:
"4GB"
"100% Compatible"
"2 Year Warranty"
"Extras - Videos, Wallpapers and More"

Nice! All that and a cool package to boot? My kid will think this is cool even if technically it sucks, so I bought one.

Upon opening the package, I noted that it had a very silky feel to it, and looked to have high quality. Let's take a look at the goodies!

I decided to give it a whirl on my Linux computer - after all - it is 100% Compatible!
Nothing special happened - no fancy videos came up. I was just a little disappointed.

Perhaps it means it is 100% Windows compatible?

One more test - does it autoboot in Windows?
I plugged the snowdrive into my XP computer. Again Nothing special happened. Bummer!


Now that the drive has lost its thrill factor for me - I proceded to look things over.
The "4 GB" drive only had 3.8GB Free Space, which means 200 MB of whatever is filling up my new drive.
What is on the drive that is using up this space?

On the drive were the following 7 files and 5 directories:
Files:
ActionSportsDrives.html
ACTIONSPORTS.ICO
AUTORUN.INF
AUTORUNNOLAUNCH.INF
AUTORUNLAUNCH.INF
Auto Launch ON-OFF Disabler.exe
SCSnow_Splash.jpg

Directories:
Wallpaper Pics
My Files
My Photos
My Music
My Videos

Well, being a movie buff, I went directly to the My Videos folder and to my surprise saw 1 lame, low definition quicktime video of what looks to be one individual doing some less than spectacular moves on a snowboard. No triple backflips. No jumping over a helicopter. No spectacularly bloody crashes. Just one guy on a board. The word "Lame" comes to mind.

Perhaps the backgrounds would be better? So I migrated into the Wallpaper Pics folder.
There I found 10 pics. 2 of which were "Android" backgrounds - My Cell phone doesn't have a "USB Port" I could plug this into. The most spectacular thing I saw here was the snow. Other than that - the pics were nothing short of lame.

In short - Nice packaging, poor implementation. Next time get some guys that can actually snowboard, use a camera crew that knows how to make good videos, and use formats that look good on my high definition screen!

Not a complete loss though. Perhaps if my kid doesn't want to play with it, I can wipe the drive and actually use it for file storage?

Wednesday, October 12, 2011

On Anonymous

Anonymous is a quasi-organized cyberintelligence group with formidable intellectual assets. They have the ability to take down major corporations, as well as government agencies. As a whole - their intent is amicable, however there are rogues with their own agendas.

What most people fail to understand is that software often controls hardware....

What happens if the hardware being controlled by the software is your local electric company, your metro-rail transportation control, or your 911/EMS center?

While I am an affectionado of the concepts and precepts of Anon, I further understand that they are a group wielding a power never before held, and with great power comes great responsibility.

I have visited their forums, their blogs, their community gatherings, and their war rooms. I understand in detail the means and methods by which they are attempting to induce social and economic reform. I am not altogether against their methods (at present) or (at least some of) their present agenda.

However - let it be perfectly clear - Anonymous is not under control. It is at best - quasi organized cyber anarchy. And we all know that there is only one possible outcome from anarchy - revolution. Anarchy promotes civil unrest, which escalates into public protests, which when they are either ignored or suppressed by the government, turn into rioting and civil war/revolution.

But these guys can only cause software and connectivity problems right? Guess again.

In this article (http://www.wired.com/dangerroom/2011/10/drone-virus-kept-quiet/) you will find that SOFTWARE controlling military hardware was hacked via a keystroke virus. A keystroke virus is one that reads the keystrokes of a particular computer system, and broadcasts it to a 3rd party so they can examine it.

This is not dissimilar to the movie "war games" where the kid uses a tape recorder to record the button pushes that open the door, then later plays it back to open the door.

Given enough time, the keystrokes can be examined and new commands created - to control the planes. It can be used by a terrorist group to turn the planes against our own troops. This, of course, is the problem with ANY remotely controlled system - it can be taken over by someone closer with a stronger transmitter.

Am I saying that this virus was the work of Anonymous? Absolutely not. What I am saying, is that many (not all) of the folks in Anon are capable of writing, or using such a program to their advantage. They could take ANY system which is connected to the Internet, tunnel into it, and wipe it out. Most of them are not "cyber-terrorists". Many are teenage/college students, many self trained, with a desire and willingness to promote communal change. Some are more seasoned veterans, but the veterans are not necessarily in charge. They are as a whole, however, determined, intelligent individuals with the skills, abilities, and wherewithal to cause severe damage if they were backed into a corner.

As such - it is IMPERATIVE that ANY sensitive or critical system be completely and totally isolated from the Internet, and that strict protocols be followed in the transferring, updating and/or adding of software to these systems.

They can NOT be connected via a VPN or firewall, which can be breached, or they open themselves up to a host of possible problems. I do not care what your IT person tells you. Theory is great...REALITY WINS! There is no such thing as a completely secure system. If it is in any way, shape, or form connected to the Internet - it is unsafe. Banks, TV Stations, Hospitals, Government Agencies, etc SHOULD have their own connectivity system, not connected to the Internet. They should have an intranet, and an Internet - and at no time should either be allowed to be connected for any reason.

If life and limb depends on it, if you do not want it ever to go down or be compromised - connecting it to the public Internet in any way shape or form is a dire mistake.