<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>forkb0mb.org - Articles</title>
    <link>http://forkb0mb.org/content/</link>
    <description>Still Watching Bits in a Terabyte World</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.4.1 - http://www.s9y.org/</generator>
    
    

<item>
    <title>Belkin Helps Cisco Exit Consumer Space by Acquiring its Home Networking Division, Including Linksys</title>
    <link>http://forkb0mb.org/content/index.php?/archives/388-Belkin-Helps-Cisco-Exit-Consumer-Space-by-Acquiring-its-Home-Networking-Division,-Including-Linksys.html</link>
            <category>Articles</category>
            <category>Cisco</category>
            <category>Networking</category>
            <category>News</category>
            <category>Technology</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/388-Belkin-Helps-Cisco-Exit-Consumer-Space-by-Acquiring-its-Home-Networking-Division,-Including-Linksys.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=388</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=388</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://thenextweb.com/insider/2013/01/24/belkin-helps-cisco-exit-consumer-space-by-acquiring-its-home-networking-division-including-linksys/&quot; title=&quot;http://thenextweb.com/insider/2013/01/24/belkin-helps-cisco-exit-consumer-space-by-acquiring-its-home-networking-division-including-linksys/&quot;&gt;Belkin Helps Cisco Exit Consumer Space by Acquiring its Home Networking Division, Including Linksys&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Belkin on Thursday &lt;a href=&quot;http://www.marketwatch.com/story/belkin-announces-intent-to-acquire-ciscos-home-networking-business-unit-2013-01-24&quot; title=&quot;http://www.marketwatch.com/story/belkin-announces-intent-to-acquire-ciscos-home-networking-business-unit-2013-01-24&quot;&gt;announced&lt;/a&gt; plans to acquire Cisco’s Home Networking Business Unit, including its products, technology, employees, and even the well-known Linksys brand. Belkin says it plans to maintain the Linksys brand and will offer support for Linksys products as part of the transaction, financial details for which were not disclosed.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Anyone who has spent any time designing, maintaining, securing, or even implementing an Enterprise-grade network already knows that Cisco is the de facto standard.  Cisco has ruled the Enterprise-grade market for decades, and will continue to do so into the foreseeable future.  What hasn&#039;t been so obvious is where/how Cisco will benefit from it&#039;s recent (the past, say, 5 - 10 years) interest in the consumer market.  &lt;br /&gt;
&lt;br /&gt;
Entering the consumer-grade market was their first mistake.&lt;br /&gt;
&lt;br /&gt;
Cisco, it&#039;s R&amp;D &quot;group&quot; long-consisting of a can of spray-paint and bridge stencil, decided to buy it&#039;s way into the consumer market through the purchase of Linksys.   Instead of doing it&#039;s own R&amp;D, creating it&#039;s own consumer-grade hardware and software, and entering the market with nothing more than it&#039;s &quot;good name,&quot; (the Cisco brand); they chose to use some of their huge cache of cash (pun intended), result of corporate hoarding as is the norm in Fortune 500 these days, to buy them some assurance of success upon entering the consumer market.&lt;br /&gt;
&lt;br /&gt;
Their entry into the consumer-grade market with re-branded equipment was their second mistake.   The Linksys name has always been synonymous with &quot;piece of shit&quot; to anyone familiar enough to properly design and implement a network starting with the Visio diagram and ending with a fully-functional network passing traffic.  Cisco first had to change the market perception that Linksys was most definitely sub-par equipment.  They made modest attempts at this with the packaging of their gear with the Cisco logo, references to &quot;Linksys powered by Cisco&quot;, etc.   Some credit must be given to Cisco for at least purchasing the best of the consumer-grade brands on the market.  I&#039;m at a loss to think of any other company they could have bought, with an established market presence, at any cost, that would have given them a better starting-point (in reference to quality and technology) than Linksys.&lt;br /&gt;
&lt;br /&gt;
One can only assume that Cisco&#039;s entry into the consumer space was an attempt to &quot;own the stack,&quot; as Oracle successfully did with it&#039;s acquisition of Sun Microsystems a few years back.  With Oracle now owning Sun; it&#039;s hardware, operating system, Java software, and all of their intellectual property, they (Oracle) can, and do, provide every piece of the puzzle when deploying a wide array of systems and services.  They can provide the hardware (servers, network-based storage, clustering-oriented network gear, etc), the software (Solaris, ZFS, Oracle Application Server, Oracle database, etc), licensing, and support from the absolute top to bottom of the &quot;stack.&quot;  In Cisco&#039;s case, being that it&#039;s related to networking as opposed to, say, services-based web applications, there is much less benefit to be derived from &quot;owning the stack,&quot; and it is much, much more difficult to position a company as such in the network world.&lt;br /&gt;
&lt;br /&gt;
Cisco&#039;s third mistake was in over-estimating the benefit to &quot;owning the stack,&quot; and under-estimating the cost to do so.  Largely due to the fact that there are so many standards (IEEE, RFCs, etc) that a piece of networking gear must adhere to, there are many other competitors in any particular market segment.  Oracle doesn&#039;t have to provide open APIs and documentation on most of it&#039;s products.  It&#039;s often to their benefit to do so, but not strictly required.  With Cisco, and networking equipment in general, the standards (such as TCP/IP) are &quot;open&quot; standards and visible to anyone.  Let&#039;s say that Cisco did manage to replace every other consumer-grade NAT router on every at-home desktop with their own Linksys-derived gear; what, &lt;em&gt;really&lt;/em&gt;, has it gained them?  Sales of equipment?  Sure.  The level of vendor lock-in that Oracle hopes to achieve with it&#039;s Sun-derived gear?   Not even close.&lt;br /&gt;
&lt;br /&gt;
Cisco&#039;s upper management should well have known that the money they&#039;d make, even with a successful entrance into the consumer-grade market, from selling routers and switches to &quot;mom and pop&quot; would be minimal, at best.  That&#039;s assuming that income from sales outpaces the cost of supporting the equipment.  Cisco has long made a good portion of it&#039;s money on support contracts from larger corporations who will not purchase from an OEM that doesn&#039;t/can&#039;t provide that engineering-level of support as necessary.  Home and small-business consumers cannot afford that level of support.  That type of customer is used to free, or nearly free, support provided by the vendor.&lt;br /&gt;
&lt;br /&gt;
The last thing that I&#039;ll add to this has to do with security.  I realize that Cisco has been looking to dump Linksys for some time (IOW, the only part of this article that is &lt;em&gt;news&lt;/em&gt; is that they have found their buyer), but I can&#039;t help but wonder if the recently-disclosed vulnerability in &lt;em&gt;all&lt;/em&gt; models of Linksys gear didn&#039;t cause Cisco to go ahead and accept some concessions on their part to hurry up and get rid of Linksys.  Stated differently, I think that the vulnerability might have caused Cisco to, for instance, accept a lower price-per-share selling price to go ahead and rid themselves of the whole Linksys debacle sooner rather than later.&lt;br /&gt;
&lt;br /&gt;
REFERENCE:  &lt;a href=&quot;http://www.defensecode.com/article/upcoming_cisco_linksys_remote_preauth_root_exploit-33&quot; title=&quot;http://www.defensecode.com/article/upcoming_cisco_linksys_remote_preauth_root_exploit-33&quot;&gt;Cisco Linksys Remote Preauth 0day Root Exploit&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Sat, 26 Jan 2013 08:34:51 -0500</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/388-guid.html</guid>
    
</item>
<item>
    <title>U.S. Census Bureau Offers Public API for Data Apps</title>
    <link>http://forkb0mb.org/content/index.php?/archives/386-U.S.-Census-Bureau-Offers-Public-API-for-Data-Apps.html</link>
            <category>Articles</category>
            <category>News</category>
            <category>Programming</category>
            <category>Software</category>
            <category>Technology</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/386-U.S.-Census-Bureau-Offers-Public-API-for-Data-Apps.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=386</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=386</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://slashdot.org/topic/bi/u-s-census-bureau-offers-public-api-for-data-apps/&quot; title=&quot;http://slashdot.org/topic/bi/u-s-census-bureau-offers-public-api-for-data-apps/&quot;&gt;U.S. Census Bureau Offers Public API for Data Apps&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
For any software developers with an urge to play around with demographic or socio-economic data: the U.S. Census Bureau has launched an API for Web and mobile apps that can slice that statistical information in all sorts of nifty ways.&lt;br /&gt;
&lt;br /&gt;
The API draws data from two sets: the 2010 Census (statistics include population, age, sex, and race) and the 2006-2010 American Community Survey (offers information on education, income, occupation, commuting, and more). In theory, developers could use those datasets to analyze housing prices for a particular neighborhood, or gain insights into a city’s employment cycles.&lt;br /&gt;
&lt;br /&gt;
The APIs include no information that could identify an individual.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
For those itchin&#039; to get to the the &lt;a href=&quot;http://www.census.gov/developers/&quot; title=&quot;http://www.census.gov/developers/&quot;&gt;APIs&lt;/a&gt;, click the link.   There&#039;s also an &quot;&lt;a href=&quot;http://www.census.gov/developers/apps/&quot; title=&quot;http://www.census.gov/developers/apps/&quot;&gt;app gallery&lt;/a&gt;.&quot;&lt;br /&gt;
&lt;br /&gt;
I, for one, am looking forward to the unique and useful ways in which this data will tell us new things about ourselves.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Mon, 30 Jul 2012 23:55:01 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/386-guid.html</guid>
    
</item>
<item>
    <title>CRTC Tells Rogers to Stop Slowing Down the Speed of Online Games</title>
    <link>http://forkb0mb.org/content/index.php?/archives/383-CRTC-Tells-Rogers-to-Stop-Slowing-Down-the-Speed-of-Online-Games.html</link>
            <category>Articles</category>
            <category>Networking</category>
            <category>News</category>
            <category>Routing</category>
            <category>VoIP</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/383-CRTC-Tells-Rogers-to-Stop-Slowing-Down-the-Speed-of-Online-Games.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=383</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=383</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.calgaryherald.com/life/CRTC+tells+Rogers+stop+slowing+down+speed+online+games/5415963/story.html&quot; title=&quot;http://www.calgaryherald.com/life/CRTC+tells+Rogers+stop+slowing+down+speed+online+games/5415963/story.html&quot;&gt;CRTC Tells Rogers to Stop Slowing Down the Speed of Online Games&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Canada&#039;s telecommunications regulator on Friday gave Rogers Communications Inc., mere days to come up with a plan to solve a problem that could be unfairly slowing down the speed of online games.&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
Rogers now has until Sept. 27 to present a plan to the regulator to deal with the issue.&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
While Internet service providers have said &lt;em&gt;they need to manage online traffic to deal with network congestion during peak hours&lt;/em&gt;, the CRTC has instituted a policy stipulating that the noticeable degradation of time-sensitive Internet traffic requires prior commission approval under Canada&#039;s Telecommunications Act.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Emphasis is my own.  This is my entire point:&lt;br /&gt;
&lt;br /&gt;
If they&#039;re having bandwidth issues during peak-usage, then they are over-subscribing their bandwith ( and/or maxing out the capabilities of their network infrastructure ) and customers notice.  Customers also tend to vote with their dollars.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Fri, 16 Sep 2011 21:56:41 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/383-guid.html</guid>
    
</item>
<item>
    <title>Opa</title>
    <link>http://forkb0mb.org/content/index.php?/archives/382-Opa.html</link>
            <category>Articles</category>
            <category>JavaScript/AJAX</category>
            <category>News</category>
            <category>Programming</category>
            <category>Software</category>
            <category>Tools</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/382-Opa.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=382</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=382</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://lambda-the-ultimate.org/node/4336&quot; title=&quot;http://lambda-the-ultimate.org/node/4336&quot;&gt;Opa&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://opalang.org/&quot; title=&quot;http://opalang.org/&quot;&gt;Opa&lt;/a&gt; is a new member in the family of languages aiming to make web programming transparent by automatically generating client-side Javascript and handling communication and session control. Opa is written in OCaml. A hierarchical database and web server are integrated with the language. The distribution model is based on a notion of a session, a construct roughly comparable to process definitions in the join-calculus or to concurrent objects in a number of formalisms.&lt;br /&gt;
&lt;br /&gt;
A good place to start is &lt;a href=&quot;http://doc.opalang.org/index.html#_introducing_opa&quot; title=&quot;http://doc.opalang.org/index.html#_introducing_opa&quot;&gt;here&lt;/a&gt;. And &lt;a href=&quot;http://opalang.org/see.xmlt&quot; title=&quot;http://opalang.org/see.xmlt&quot;&gt;here&lt;/a&gt; you can find several example programs with accompanying source code.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
This looks interesting.   Although I don&#039;t know OCaml, it might be worth learning it to use this.  The automatic creation of the client-side JavaScript for maintaining sessions and communication sounds pretty slick.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://opalang.org/learn.xmlt&quot; title=&quot;http://opalang.org/learn.xmlt&quot;&gt;Here is the link to the documentation&lt;/a&gt;, which looks to be pretty decent.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Sun, 28 Aug 2011 00:34:01 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/382-guid.html</guid>
    
</item>
<item>
    <title>Coordinated ATM Heist Nets Thieves $13M</title>
    <link>http://forkb0mb.org/content/index.php?/archives/381-Coordinated-ATM-Heist-Nets-Thieves-13M.html</link>
            <category>Articles</category>
            <category>Data Theft</category>
            <category>Exploits</category>
            <category>News</category>
            <category>Vulnerabilities</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/381-Coordinated-ATM-Heist-Nets-Thieves-13M.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=381</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=381</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://krebsonsecurity.com/2011/08/coordinated-atm-heist-nets-thieves-13m/&quot; title=&quot;http://krebsonsecurity.com/2011/08/coordinated-atm-heist-nets-thieves-13m/&quot;&gt;Coordinated ATM Heist Nets Thieves $13M&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
An international cybercrime gang stole $13 million from a Florida-based financial institution earlier this year, by executing a highly-coordinated heist in which thieves used ATMs around the globe to cash out stolen prepaid debit cards, KrebsOnSecurity has learned.&lt;br /&gt;
&lt;br /&gt;
Jacksonville based &lt;strong&gt;Fidelity National Information Services Inc.&lt;/strong&gt; (FIS) bills itself as the world’s largest processor of &lt;a href=&quot;http://www.fisglobal.com/products-card-prepaidcards&quot; title=&quot;http://www.fisglobal.com/products-card-prepaidcards&quot;&gt;prepaid debit cards&lt;/a&gt;; FIS claims to process more than 775 million transactions annually. The company disclosed the breach in &lt;a href=&quot;http://www.investor.fisglobal.com/phoenix.zhtml?c=180304&amp;p=irol-newsArticle&amp;ID=1558344&amp;highlight=&quot; title=&quot;http://www.investor.fisglobal.com/phoenix.zhtml?c=180304&amp;p=irol-newsArticle&amp;ID=1558344&amp;highlight=&quot;&gt;its first quarter earnings statement&lt;/a&gt; issued May 3, 2011. But details of the attack remained shrouded in secrecy as the FBI and forensic investigators probed one of the biggest and most complex banking heists of its kind.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Ed. Note: Emphasis and links are from original article.&lt;br /&gt;
&lt;br /&gt;
This sounds a lot like the attack on RBS WorldPay back in 2008.  What I can&#039;t seem to figure is how they increase/remove the daily withdrawal limits.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
FIS said it had incurred a loss of approximately $13 million related to unauthorized activities involving one client and 22 prepaid cards on its Sunrise, Fla. based eFunds Prepaid Solutions, formerly WildCard Systems Inc., which was acquired by FIS in 2007.&lt;br /&gt;
&lt;br /&gt;
FIS stated: “The Company has identified that 7,170 prepaid accounts may have been at risk and that three individual cardholders’ non-public information may have been disclosed as a result of the unauthorized activities. FIS worked with the impacted clients to take appropriate action, including blocking and reissuing cards for the affected accounts. The Company has taken steps to further enhance security and continues to work with Federal law enforcement officials on this matter.” The disclosure was &lt;a href=&quot;http://www.americanbanker.com/issues/176_84/fidelity_national_information_earnings-1036985-1.html&quot; title=&quot;http://www.americanbanker.com/issues/176_84/fidelity_national_information_earnings-1036985-1.html&quot;&gt;scarcely noted&lt;/a&gt; by news media.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
So, approximately $13,000,000 on 22 cards.  That works out to over $590,000 per card.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
Apparently, the crooks were able to drastically increase or eliminate the withdrawal limits for 22 prepaid cards that they had obtained. The fraudsters then cloned the prepaid cards, and distributed them to co-conspirators in several major cities across Europe, Russia and Ukraine.&lt;br /&gt;
&lt;br /&gt;
Sources say the thieves waited until the close of business in the United States on Saturday, March 5, 2011, to launch their attack. Working into Sunday evening, conspirators in Greece, Russia, Spain, Sweden, Ukraine and the United Kingdom used the cloned cards to withdraw cash from dozens of ATMs. Armed with unauthorized access to FIS’s card platform, the crooks were able to reload the cards remotely when the cash withdrawals brought their balances close to zero.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
This explains how they were able to pull this off in such a short amount of time.   With cloned cards in at least 6 different countries, the totals could add up rather quickly.  It appears that they obtained the cash over about 36 hours.&lt;br /&gt;
&lt;br /&gt;
$13,000,000 / 36 hours = $361,111/hour&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
It’s still not clear who was responsible for this attack on FIS. The company declined comment. The FBI would neither confirm nor deny that it is investigating. But the breach is eerily similar to an intricate 2008 attack against &lt;strong&gt;RBS WorldPay&lt;/strong&gt;, an Atlanta-based unit of the Royal Bank of Scotland. In that heist, crooks obtained remote access to RBS’s systems and used 44 counterfeit prepaid cards to withdraw more than $9 million from at least 2,100 ATM terminals in 280 cities worldwide. The attack was so sophisticated and alarming that &lt;strong&gt;President Obama&lt;/strong&gt; referred to it in &lt;a href=&quot;http://www.whitehouse.gov/the_press_office/Remarks-by-the-President-on-Securing-Our-Nations-Cyber-Infrastructure/&quot; title=&quot;http://www.whitehouse.gov/the_press_office/Remarks-by-the-President-on-Securing-Our-Nations-Cyber-Infrastructure/&quot;&gt;a landmark cybersecurity speech&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Considering that these &quot;cloned&quot; cards have to be inserted into an ATM to obtain cash, I would figure that there are ATM images of the (guilty) people withdrawing money.  It&#039;s likely only a matter of time before some/all of these guys are identified.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Sat, 27 Aug 2011 23:42:18 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/381-guid.html</guid>
    
</item>
<item>
    <title>How Linux mastered Wall Street</title>
    <link>http://forkb0mb.org/content/index.php?/archives/380-How-Linux-mastered-Wall-Street.html</link>
            <category>Articles</category>
            <category>Linux</category>
            <category>News</category>
            <category>Operating Systems</category>
            <category>Unix</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/380-How-Linux-mastered-Wall-Street.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=380</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=380</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.itworld.com/open-source/193823/how-linux-mastered-wall-street&quot; title=&quot;http://www.itworld.com/open-source/193823/how-linux-mastered-wall-street&quot;&gt;How Linux mastered Wall Street&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
When it comes to the fast-moving business of trading stocks, bonds and derivatives, the world&#039;s financial exchanges are finding an ally in Linux, at least according to one Linux kernel developer working in that industry.&lt;br /&gt;
&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
As an alternative to traditional Unix, Linux has become a dominant player in finance, thanks to the operating-system kernel&#039;s ability to pass messages very quickly, Lameter said in an interview with IDG. In fact, the emerging field of high-frequency trading (HFT) would not be possible without the open-source operating system, he argued. Lameter himself was hired as a consultant by one exchange -- he won&#039;t say which one -- based on his work in assembling large-scale Linux clusters.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
An interesting read regarding the use of Linux in high-frequency trading applications.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Tue, 16 Aug 2011 23:06:09 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/380-guid.html</guid>
    
</item>
<item>
    <title>Tunneling nmap through Tor</title>
    <link>http://forkb0mb.org/content/index.php?/archives/378-Tunneling-nmap-through-Tor.html</link>
            <category>Articles</category>
            <category>Cryptography/Privacy</category>
            <category>Networking</category>
            <category>Network Security</category>
            <category>News</category>
            <category>Operating Systems</category>
            <category>Routing</category>
            <category>Software</category>
            <category>Technology</category>
            <category>Tools</category>
            <category>Unix</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/378-Tunneling-nmap-through-Tor.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=378</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=378</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.commondork.com/2009/06/26/tunneling-nmap-through-tor/&quot; title=&quot;http://www.commondork.com/2009/06/26/tunneling-nmap-through-tor/&quot;&gt;Tunneling nmap through Tor&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
I looked at how to reduce your exposure using Tor earlier in the week. We installed Tor and Privoxy and configured our system to browse the Internet anonymously. We can use Tor and another great program called proxychains to Torify our network scans with nmap.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
I checked this out and it seems to work well.  Other than the fact that Tor doesn&#039;t seem to carry UDP traffic (other than DNS) or ICMP traffic, you&#039;re limited to TCP traffic alone, which isn&#039;t too much of a limitation.&lt;br /&gt;
&lt;br /&gt;
It is a little slow getting your scan results back - especially if you don&#039;t pass -p&amp;lt;port1&gt;,&amp;lt;port2&gt; to nmap(1), but it&#039;s certainly more secure than just trying to use an open proxy server out on the &#039;net.&lt;br /&gt;
&lt;br /&gt;
All in all, a neat trick.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Thu, 28 Jul 2011 12:11:34 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/378-guid.html</guid>
    
</item>
<item>
    <title>Two /8s allocated to APNIC from IANA</title>
    <link>http://forkb0mb.org/content/index.php?/archives/375-Two-8s-allocated-to-APNIC-from-IANA.html</link>
            <category>Articles</category>
            <category>Networking</category>
            <category>News</category>
            <category>Routing</category>
            <category>Technology</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/375-Two-8s-allocated-to-APNIC-from-IANA.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=375</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=375</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;https://www.apnic.net/publications/news/2011/delegation&quot; title=&quot;https://www.apnic.net/publications/news/2011/delegation&quot;&gt;Two /8s allocated to APNIC from IANA&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
APNIC received the following IPv4 address blocks from &lt;a href=&quot;http://www.iana.org/&quot; title=&quot;http://www.iana.org/&quot;&gt;IANA&lt;/a&gt; in February 2011 and will be making allocations from these ranges in the near future:&lt;br /&gt;
&lt;br /&gt;
&lt;li&gt;39/8&lt;br /&gt;
&lt;li&gt;106/8&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
The allocation of these blocks left the IANA with 5 /8 blocks left; which triggers a clause saying that when the pool gets down to 5 remaining blocks, each of the 5 *NICs get one of the remaining blocks.   It&#039;s just unfortunate that 2 of the last 6 or 7 blocks are completely wasted by being routed to what essentially amounts to an Internet cesspool (APNIC).   I regularly pull down the IANA assignments, parse out the netblocks assigned to APNIC, and then null-route them all.&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Note&lt;/em&gt;:  The aforementioned clause is stated in the &quot;&lt;a href=&quot;http://www.icann.org/en/general/allocation-remaining-ipv4-space.htm&quot; title=&quot;http://www.icann.org/en/general/allocation-remaining-ipv4-space.htm&quot;&gt;Global policy for the allocation of the remaining IPv4 address space&lt;/a&gt;.&quot;&lt;br /&gt;
&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Here&#039;s a ticker, from &lt;a href=&quot;http://www.he.net/&quot; title=&quot;http://www.he.net/&quot;&gt;Hurricane Electric&lt;/a&gt;, that estimates the eventual exhaustion of IPv4 addresses from the regional registries.&lt;br /&gt;
&lt;br /&gt;
You might take this time to &lt;a href=&quot;http://tunnelbroker.net/&quot; title=&quot;http://tunnelbroker.net/&quot;&gt;register for a block&lt;/a&gt; of IPv6 addresses - It&#039;s free!&lt;br /&gt;
&lt;br /&gt;
&lt;script type=&quot;text/javascript&quot; src=&quot;http://ipv6.he.net/v4ex/sidebar.js&quot;&gt;&lt;/script&gt;&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Thu, 10 Feb 2011 08:26:53 -0500</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/375-guid.html</guid>
    
</item>
<item>
    <title>Common Threads:  OpenSSH Key Management, part One</title>
    <link>http://forkb0mb.org/content/index.php?/archives/374-Common-Threads-OpenSSH-Key-Management,-part-One.html</link>
            <category>Articles</category>
            <category>Cryptography/Privacy</category>
            <category>IBM DeveloperWorks</category>
            <category>Networking</category>
            <category>Network Security</category>
            <category>News</category>
            <category>SSL</category>
            <category>Tools</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/374-Common-Threads-OpenSSH-Key-Management,-part-One.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=374</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=374</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.ibm.com/developerworks/library/l-keyc.html&quot; title=&quot;http://www.ibm.com/developerworks/library/l-keyc.html&quot;&gt;Common Threads:  OpenSSH Key Management, part One&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Many of us use the excellent OpenSSH [...] as a secure, encrypted replacement for the venerable telnet and rsh commands. One of OpenSSH&#039;s more intriguing features is its ability to authenticate users using the RSA and DSA authentication protocols, which are based on a pair of complementary numerical keys. As one of its main appeals, RSA and DSA authentication promise the capability of establishing connections to remote systems without supplying a password. While this is appealing, new OpenSSH users often configure RSA/DSA the quick and dirty way, resulting in passwordless logins, but opening up a big security hole in the process.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Yet another of the DeveloperWorks! series.  I love these articles.&lt;br /&gt;
&lt;br /&gt;
The vulnerability in question has to do with pub-key (RSA/DSA) authentication and leaving a null/blank passphrase on the keypair.  This article describes how to configure ssh-agent to cache the decrypted private keys so you only have to type the passphrase once per session.  This has the benefit of allowing you to use scripted SSH logins without being prompted for a password, but also means that the keypair is still relatively secure even if someone else manages to compromise them via the filesystem.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
OpenSSH&#039;s RSA and DSA authentication protocols are based on a pair of specially generated cryptographic keys, called the private key and the public key. The advantage of using these key-based authentication systems is that in many cases, it&#039;s possible to establish secure connections without having to manually type in a password.&lt;br /&gt;
&lt;br /&gt;
While the key-based authentication protocols are relatively secure, problems arise when users take certain shortcuts in the name of convenience, without fully understanding their security implications. In this article, we&#039;ll take a good look at how to correctly use RSA and DSA authentication protocols without exposing ourselves to any unnecessary security risks. In my next article, I&#039;ll show you how to use ssh-agent to cache decrypted private keys, and introduce keychain, an ssh-agent front-end that offers a number of convenience advantages without sacrificing security.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
A more in-depth description of what I mentioned above.  &lt;br /&gt;
&lt;br /&gt;
Highlights include:&lt;br /&gt;
&lt;li&gt; What is RSA/DSA authentication?&lt;br /&gt;
&lt;li&gt; How RSA/DSA keys work&lt;br /&gt;
&lt;li&gt; Two observations&lt;br /&gt;
&lt;li&gt; ssh-keygen up close&lt;br /&gt;
&lt;li&gt; The quick compromise&lt;br /&gt;
&lt;li&gt; RSA key pair generation&lt;br /&gt;
&lt;li&gt; RSA public key install&lt;br /&gt;
&lt;li&gt; DSA key generation&lt;br /&gt;
&lt;li&gt; DSA public key install&lt;br /&gt;
&lt;br /&gt;
For those already familiar with ssh-agent(1) - which you should be - then you can skip ahead to &lt;a href=&quot;http://www.ibm.com/developerworks/library/l-keyc2/&quot; title=&quot;http://www.ibm.com/developerworks/library/l-keyc2/&quot;&gt;Part Two&lt;/a&gt; and &lt;a href=&quot;http://www.ibm.com/developerworks/library/l-keyc3/&quot; title=&quot;http://www.ibm.com/developerworks/library/l-keyc3/&quot;&gt;Part Three&lt;/a&gt;.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Sun, 16 Jan 2011 16:03:46 -0500</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/374-guid.html</guid>
    
</item>
<item>
    <title>Secret Forum Reveals Oz Firewall Backroom Dealing</title>
    <link>http://forkb0mb.org/content/index.php?/archives/371-Secret-Forum-Reveals-Oz-Firewall-Backroom-Dealing.html</link>
            <category>Articles</category>
            <category>Cryptography/Privacy</category>
            <category>Firewall</category>
            <category>Networking</category>
            <category>Network Security</category>
            <category>News</category>
            <category>Routing</category>
            <category>SSL</category>
            <category>Technology</category>
            <category>VPN</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/371-Secret-Forum-Reveals-Oz-Firewall-Backroom-Dealing.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=371</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=371</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.theregister.co.uk/2010/05/10/australia_firewall_forum/&quot; title=&quot;http://www.theregister.co.uk/2010/05/10/australia_firewall_forum/&quot;&gt;Secret Forum Reveals Oz Firewall Backroom Dealing&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Circumvention legal, but you can&#039;t tell anyone how&lt;/strong&gt;[.]&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Emphasis is theirs. &lt;br /&gt;
&lt;br /&gt;
Now say what?  It will be legal to circumvent (technical details at the bottom), but illegal to explain to someone else how to perform this perfectly legal configuration.   I wonder how this might affect a corporate or ISP helpdesk perform VPN connectivity setup?&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
Australia’s plans for a firewall to protect its population from smut on the internet are rapidly evolving from farce to total chaos. Weekly revelations on bulletin boards suggest that &lt;strong&gt;Stephen Conroy&lt;/strong&gt;, the man behind the big idea, does not know what forthcoming legislation on the topic will say, when it will be introduced or how the firewall will work in practice.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
This time, emphasis is mine.  I want to continue to point out how big of an asshat this particular Australian politician is.  He is the &quot;Minister for Broadband, Communications and the Digital Economy.&quot;  He&#039;s the one that floated the idea of this nation-wide &quot;firewall&quot; (which is technically a proxy since it will be filtering at layer 7 - hence the technical problems) to &quot;protect&quot; citizens from illegal, immoral, or &quot;dangerous&quot; content.  This is nearly the same thing the Chinese and Iranians are doing, just using layer 7 proxy devices instead of what&#039;s assumed to be basic layer 3 IP filtering of destination hosts.  Skip to the very end of the post for the technical details behind this.&lt;br /&gt;
&lt;br /&gt;
To say this whole thing began as a farce is hitting the nail right on the head.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
Meanwhile, it turns out that the Minister’s own Department of Broadband, Communications and the Digital Economy (DBCDE) has been hosting a secret forum for discussions with ISPs likely to be affected by proposals. Along the way it floated the idea of making it a crime to advise surfers on how to do things that are perfectly legal to do. Confused? You will be.&lt;br /&gt;
&lt;br /&gt;
First up is the time scale for plans to introduce the new firewall. As &lt;a href=&quot;http://www.theregister.co.uk/2010/05/04/aus_net_filter_law_delay/&quot; title=&quot;http://www.theregister.co.uk/2010/05/04/aus_net_filter_law_delay/&quot;&gt;already reported&lt;/a&gt;, the question of when legislation will be introduced has now been bouncing between the offices of Prime Minister Kevin Rudd and Communications Minister Stephen Conroy. Severe wriggling from Conroy’s office suggests that plans for an early introduction of legislation have been put on the back burner for now.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
&lt;a href=&quot;http://en.wikipedia.org/wiki/Stephen_Conroy&quot; title=&quot;http://en.wikipedia.org/wiki/Stephen_Conroy&quot;&gt;Conroy&lt;/a&gt; wants to shelve the legislation until after the elections.  He&#039;s technically incompetent, but he&#039;s smart enough to realize that this is going to be a screw-up of biblical proportions and it will likely cost him the election.  It&#039;s &quot;on the back burner for now,&quot; but it&#039;s by no means dead.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
Meanwhile further digging inside this forum revealed that departmental officials appear to have been discussing the possibility of making it a criminal offen[s]e to advise individuals of means that would enable them to circumvent the filter – even where the means themselves were perfectly legal.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
I would say that this equates to information being illegal.  In a way, that&#039;s in the same league as banning books.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
As the EFA suggests, this answer raises more issues than it addresses, and relies on the degradation of the Australian network being gradual, rather than catastrophic. It does appear, however, that the government has no plans to deal with a possible overload of its firewall bringing the Australian internet to its knees – beyond setting up a review when such an event actually happens.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
Why should there be any degradation of bandwidth at all?  I suspect that if this goes through, there&#039;s going to be a noticeable difference in download speeds and initial access to websites.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
&lt;strong&gt;Details:&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Circumvention:&lt;/em&gt;&lt;br /&gt;
Circumvention of these filters will be trivial; you can wrap your request in SSL (such as https:// if the website supports it), &lt;a href=&quot;http://filesharefreak.com/2008/10/18/total-anonymity-a-list-of-vpn-service-providers/&quot; title=&quot;http://filesharefreak.com/2008/10/18/total-anonymity-a-list-of-vpn-service-providers/&quot;&gt;by using&lt;/a&gt; &lt;a href=&quot;http://www.yourprivatevpn.com/?q=en&quot; title=&quot;http://www.yourprivatevpn.com/?q=en&quot;&gt;a&lt;/a&gt; &lt;a href=&quot;http://en.wikipedia.org/wiki/Virtual_Private_Network&quot; title=&quot;http://en.wikipedia.org/wiki/Virtual_Private_Network&quot;&gt;VPN&lt;/a&gt; &lt;a href=&quot;http://torrentfreedom.com/&quot; title=&quot;http://torrentfreedom.com/&quot;&gt;provider&lt;/a&gt; &lt;a href=&quot;http://www.perfect-privacy.com/&quot; title=&quot;http://www.perfect-privacy.com/&quot;&gt;outside&lt;/a&gt; &lt;a href=&quot;http://vpngates.com/&quot; title=&quot;http://vpngates.com/&quot;&gt;Australia&lt;/a&gt; (many more found on the link for the word &quot;using&quot;), by using &lt;a href=&quot;https://www.torproject.org/&quot; title=&quot;https://www.torproject.org/&quot;&gt;Tor&lt;/a&gt; (which uses a technique known as &lt;a href=&quot;http://en.wikipedia.org/wiki/Onion_Routing&quot; title=&quot;http://en.wikipedia.org/wiki/Onion_Routing&quot;&gt;Onion Routing&lt;/a&gt;), or even by viewing blocked pages via the &lt;a href=&quot;http://googlesystem.blogspot.com/2007/01/browsing-web-using-google-cache.html&quot; title=&quot;http://googlesystem.blogspot.com/2007/01/browsing-web-using-google-cache.html&quot;&gt;Google cache&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Technical Considerations:&lt;/em&gt;&lt;br /&gt;
This filtering is to take place with proxies (at the Application [7] layer) as opposed to the traditional large-scale deployments of firewalls (at the Network [3] and Transport [4]) layers).  The deeper you have to inspect a packet, the more CPU and memory required to process the filters.  It costs - in many ways, from actual dollars for the hardware and software, to performance impact, to configuration complexity to man-hours of maintenance - considerably more to filter at layer 7 with a proxy than layers 3/4 with a firewall.&lt;br /&gt;
&lt;br /&gt;
The one benefit to filtering at layer 7 is that you block only what is intended to be blocked.  In today&#039;s world (where we&#039;ve been running out of IPv4 space for a dacade now) a lot of websites are configured using &lt;a href=&quot;http://en.wikipedia.org/wiki/Virtual_host&quot; title=&quot;http://en.wikipedia.org/wiki/Virtual_host&quot;&gt;virtual hosts&lt;/a&gt;.   This allows web hosting providers to host a virtually unlimited number of websites on a single IP address.  Let&#039;s say there are two websites, both hosted on the same virtual host IP address, where one is banned and the other is not:&lt;br /&gt;
&lt;br /&gt;
www.bannedwebsite.co.au (banned)&lt;br /&gt;
www.momsrecipies.co.au (allowed)&lt;br /&gt;
&lt;br /&gt;
With a layer 7 proxy, when the user attempts to reach a website, the proxy intercepts the request, checks the request (including hostname and URI), and then either blocks the request, or requests the page on behalf of the end-user and returns her the requested webpage.  So your mom can still access www.momsrecipes.co.au while nobody can access www.bannedwebsite.co.au.  With a proxy, you can return HTML to the end-user explaining why access to this particular website is blocked and possibly a method of contact to dispute the denial of access.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Pros:&lt;/u&gt;&lt;br /&gt;
() Finer-grained control of what&#039;s filtered&lt;br /&gt;
() Less &quot;false positives&quot;&lt;br /&gt;
&lt;u&gt;Cons:&lt;/u&gt;&lt;br /&gt;
() Expensive in many aspects (mentioned above)&lt;br /&gt;
() Complex configuration&lt;br /&gt;
() Considerable service impact due to use of &lt;a href=&quot;http://en.wikipedia.org/wiki/Deep_Packet_Inspection&quot; title=&quot;http://en.wikipedia.org/wiki/Deep_Packet_Inspection&quot;&gt;DPI&lt;/a&gt; at Application [7] layer&lt;br /&gt;
() Slightly easier to circumvent; using https is the only circumvention measure mentioned that does not tend to work with the firewall approach - the rest should work against both types&lt;br /&gt;
&lt;br /&gt;
With a layer 3/4 firewall, access to the virtual host IP address (or even the subnet it&#039;s part of) will be blocked.  When anyone tries to go to www.bannedwebsite.co.au, they are unable to, which is the intended result.  They will get a different error; the browser will just report that website was unreachable.  End of explanation.  If anyone tries to go to www.momsrecipies.co.au, they will also be denied with the same uninformative unreachable error.  Since both websites are on the same IP address, the firewall has no way of knowing which website you&#039;re looking for, so it blocks everything.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Pros:&lt;/u&gt;&lt;br /&gt;
() Cheaper to deploy&lt;br /&gt;
() Simpler configuration - hundreds of hosts/subnets vs. thousands of hostnames&lt;br /&gt;
() Can often be implemented on existing hardware - edge or core routers utilization IP ACLs&lt;br /&gt;
() Faster, more responsive access to allowed websites; less service impact&lt;br /&gt;
&lt;u&gt;Cons:&lt;/u&gt;&lt;br /&gt;
() Collateral damage - legitimate sites on the same virtual host as banned site are also blocked&lt;br /&gt;
() Slightly more difficult to circumvent (a websites https site will likely be in the same blocked subnet)&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Comparison with Other Instances of State-Controlled Internet Access:&lt;/em&gt;&lt;br /&gt;
I see three major differences in the Australian proposal as opposed to the other major regimes implementing state-wide filtering of websites (China and Iran).  They are as follows:&lt;br /&gt;
&lt;br /&gt;
  &lt;li&gt; The use of layer 7 proxies instead of layer 3/4 firewalls and route filtering&lt;br /&gt;
&lt;br /&gt;
  &lt;li&gt; In China and Iran the responsibility of implementing and maintaining the filters rests on the tier-1 to tier-2 network providers who bring capacity into the country.  By filtering at this level, you are enforcing that ISPs block these sites along with everyone else in the country.  By placing the responsibility on the ISP, who provides the access to the end-user, you are going to find that ISPs (a) will add/remove entries from the blocked list to fit their own agendas; (b) will suffer varying performance impact and quality of service based on their investment in the filtering technology and correctness of the implementation; (c) will raise prices to pay for increased hardware/software components, man-hours maintaining the systems, and extra capacity required to maintain a reasonable quality of service; and (d) some will become popular with a certain customer base due to being lax in their filter list updates and tendency to allow some banned content.&lt;br /&gt;
&lt;br /&gt;
Another side effect of this proposal, from an economic standpoint, is that it is likely to put smaller ISPs out of business.  Instead of putting the smaller burden on the backbone providers, with considerably more capital, it will place a more expensive burden on ISPs with less resources at their disposal.  If these filters become legally mandatory, this will likely put smaller ISPs out of business.  A smaller provider may not have access to the resources (money, manpower, and know-how) to meet these requirements and will thus have to shut down operations.&lt;br /&gt;
&lt;br /&gt;
  &lt;li&gt; The third difference is in the legality and enforcement of the filters.  In the Australian proposal, it will be legal to circumvent the filters provided you know how.  In China, they are known for randomly allowing then blocking then allowing access to certain websites and enforcement is relatively low.  Occasionally they will decide to make an example of someone, and they will end up in prison.  In Iran, enforcement is rather strong, with penalties ranging from prison time to possibly &quot;disappearing&quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Other Thoughts:&lt;/em&gt;&lt;br /&gt;
There is one other somewhat commonly used filtering technique involving DNS.  The ISP or corporate gateway will transparently route all DNS requests by the end-user to DNS servers under their control.  The DNS servers will be configured as authoritative for the blocked domains; typically configured to return an IP address that connects you to a website telling you that your access is blocked and possibly why.  This is similar to the &lt;a href=&quot;http://en.wikipedia.org/wiki/Walled_garden_%28technology%29&quot; title=&quot;http://en.wikipedia.org/wiki/Walled_garden_%28technology%29&quot;&gt;Walled Garden&lt;/a&gt; approach.&lt;br /&gt;
&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Mon, 17 May 2010 00:56:52 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/371-guid.html</guid>
    
</item>
<item>
    <title>Rough Justice for Terry Childs</title>
    <link>http://forkb0mb.org/content/index.php?/archives/369-Rough-Justice-for-Terry-Childs.html</link>
            <category>Articles</category>
            <category>Cisco</category>
            <category>Networking</category>
            <category>Network Security</category>
            <category>News</category>
            <category>Routing</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/369-Rough-Justice-for-Terry-Childs.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=369</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=369</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://infoworld.com/t/insider-threat/rough-justice-terry-childs-066&quot; title=&quot;http://infoworld.com/t/insider-threat/rough-justice-terry-childs-066&quot;&gt;Rough Justice for Terry Childs&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
A San Francisco jury found Terry Childs guilty of one count of felony denial of service yesterday. The count carries a maximum sentence of five years in prison. Considering that he&#039;s already served nearly two years to date, he may actually be released on parole at his June 14 sentencing hearing, or he may be facing another three years behind bars. His lawyers stated that they will appeal.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
This ruling brings a chill to my spine.  While Childs could have handled the situation with a little more grace, I don&#039;t believe that any crime was actually committed.  I&#039;ve worked under some pretty shoddy conditions before - lack of procedures, lack of accountability - but this sets precedent for criminal prosecution.&lt;br /&gt;
&lt;br /&gt;
Knowing firsthand how difficult this would be, I&#039;d have just let the lackluster-at-best management sink.  I would have turned over the passwords along with my resignation.  Anyone with a CCIE can find another job, even in this economy.  If it comes down to risking my freedom and clean criminal record because my boss is a moron, then it&#039;s time to move on.  I can&#039;t imagine how painful it would have to be to create such a complex, intricate system, only to have to turn it over to inept cretins who will undoubtedly destroy it.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Wed, 28 Apr 2010 17:58:46 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/369-guid.html</guid>
    
</item>
<item>
    <title>RIM Buys QNX to Tie Phones to Cars</title>
    <link>http://forkb0mb.org/content/index.php?/archives/368-RIM-Buys-QNX-to-Tie-Phones-to-Cars.html</link>
            <category>Articles</category>
            <category>Microkernels</category>
            <category>News</category>
            <category>Operating Systems</category>
            <category>Software</category>
            <category>Technology</category>
            <category>Unix</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/368-RIM-Buys-QNX-to-Tie-Phones-to-Cars.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=368</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=368</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.pcmag.com/article2/0,2817,2362455,00.asp&quot; title=&quot;http://www.pcmag.com/article2/0,2817,2362455,00.asp&quot;&gt;RIM Buys QNX to Tie Phones to Cars&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Research in Motion said Friday (04/09/2010) that it had signed a deal with Harman International to acquire its QNX Software Systems unit to help tie its BlackBerry smartphones to car navigation systems.&lt;br /&gt;
&lt;br /&gt;
Terms of the deal were not announced. It is expected to close within 30 to 45 days if it passes regulatory approvals. &lt;br /&gt;
&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
QNX designs a real-time embedded OS, that it has tied to ARM, MIPS, PowerPC and other processors and embedded designs.&lt;br /&gt;
&lt;br /&gt;
&quot;The car is going to become the first-class citizen of the cloud, where inside the car you&#039;re going to have access to all the connected media, all the social services that are out there, and it will truly revolutionize the driving experience, the experience of the automotive makers making those cars, the ecosystem of people that are going to make applications for those cars,&quot; said Dan Dodge, the chief executive of QNX, in a recent video made with Alcatel-Lucent to retrofit a Toyota car with a cloud-connected entertainment system networked via the wireless LTE standard. &quot;It&#039;s probably one of the most exciting times in automotive history.&quot;&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
I wouldn&#039;t have named QNX as the software to buy if you&#039;re looking to get into car navigation systems, but they&#039;re certainly a good choice.  I&#039;ve used QNX here and there, but it&#039;s been quite a few years back.  The software was always really neat looking (&lt;a href=&quot;http://en.wikipedia.org/wiki/File:QNX_6.4.1_screenshot.png&quot; title=&quot;http://en.wikipedia.org/wiki/File:QNX_6.4.1_screenshot.png&quot;&gt;Photon&lt;/a&gt; is a beautiful GUI), was blazing fast, tiny footprint, and as stable as anything I&#039;ve ever encountered.&lt;br /&gt;
&lt;br /&gt;
For those unfamiliar, QNX is a Real-Time Operating System (RTOS) that&#039;s a perfect example of a &lt;a href=&quot;http://en.wikipedia.org/wiki/Microkernel&quot; title=&quot;http://en.wikipedia.org/wiki/Microkernel&quot;&gt;microkernel&lt;/a&gt; architecture.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Sun, 25 Apr 2010 00:02:49 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/368-guid.html</guid>
    
</item>
<item>
    <title>Cisco's New Router: Trouble for Hollywood</title>
    <link>http://forkb0mb.org/content/index.php?/archives/367-Ciscos-New-Router-Trouble-for-Hollywood.html</link>
            <category>Articles</category>
            <category>Cisco</category>
            <category>Networking</category>
            <category>News</category>
            <category>Technology</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/367-Ciscos-New-Router-Trouble-for-Hollywood.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=367</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=367</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.time.com/time/business/article/0,8599,1972540,00.html&quot; title=&quot;http://www.time.com/time/business/article/0,8599,1972540,00.html&quot;&gt;Cisco&#039;s New Router: Trouble for Hollywood&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Cisco&#039;s CRS-3 router made a bit of a splash when it was announced on March 9, but the power of this new device hasn&#039;t yet sunk in. Consider: The CRS-3, a network routing system, is able to stream every film ever made, from Hollywood to Bombay, in under four minutes. That&#039;s right — the whole universe of films digested in less time than it takes to boil an egg. That may sound like good news for consumers, but it could be the business equivalent of an earthquake for the likes of Universal Studios and Paramount Pictures.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
I&#039;m not sure that the comparison of streaming the entire Hollywood movie collection in less than 4 minutes is completely accurate; I&#039;d like to know how many movies they&#039;re estimating, how big each DVD image is (4.7GB vs. 9.4GB, for instance), and what Layer 1/2 technologies they&#039;re talking about (is this ethernet over fiber?).  If you&#039;re just talking about passing the data across the 322 Tb/sec backplane, then it might be possible; but if you&#039;re talking about carrying all that data across multiple hops, each connected by, say, a 10 Gbps ethernet-over-fiber link, it&#039;s just not doable.  The 10 Gbps link would definitely be a bottleneck.&lt;br /&gt;
&lt;br /&gt;
I also have my doubts as to the likelihood of a piece of networking equipment meaning the end of the world for any sector of business.  Sure, as internet connections get faster more people will start downloading/streaming their content; so, unless the people running the MPAA and RIAA are complete morons (which I&#039;m not ruling out), all they have to do is change their business model to incorporate downloads.  That&#039;s not exactly an overnight change, but it&#039;s entirely possible.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
But routers are not the only cause of bottlenecks, and Cisco is not alone in working to maximize the Internet&#039;s full potential. Google is also concerned about the speed limitations imposed by wires that run to the home. Last month, Google, best known for its search engine, announced plans to test ultra-high-speed broadband networks that would deliver Internet content to residential subscribers at speeds of 1 gigabit per second — 100 times as fast as the top speed available today. This would allow consumers to complete a PC download of a Hollywood blockbuster like Avatar in about 72 seconds.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
I don&#039;t understand the phrase, &quot;100 times as fast as the top speed available today.&quot;  That would seem to indicate that a 10Mb/sec connection is the fastest available today.  I&#039;m currently on a 15 Mb/sec connection as I write this, and my ISP offers at least 20 Mb/sec.&lt;br /&gt;
&lt;br /&gt;
Downloading a movie at full-speed on a 1 Gbps connection, over 72 seconds, results in 8,640 MB of data.  That&#039;s almost a full double-layer DVD.   We&#039;ll assume 120 MB/sec (bytes) over the 1 Gbps link, which is right about the theoretically maximum without figuring in the overhead and framing (for brevity); times 72 seconds = 8,640MB.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
The ability to download albums and films in a matter of seconds is a harbinger of deep trouble for the Motion Picture Association of America (MPAA) and the Recording Industry Association of America (RIAA), which would prefer to turn the clock back, way back.&lt;br /&gt;
&lt;br /&gt;
Consider that the MPAA, whose members include Disney and Universal, attacked the VCR in congressional hearings in the 1980s with a Darth Vader–like zeal, predicting box-office receipts would collapse if consumers were allowed to freely share and copy VHS tapes of Hollywood movies. A decade later, the MPAA fought to block the DVD revolution, mainly because digital media could be copied and distributed even more easily than videocassettes.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
&quot;Fair Use&quot; has held up in court many times that as a consumer we are allowed to make 1 archival copy in case our normal store-bought copy gets scratched/lost/stolen.  It&#039;s also been proven in several instances where customers are more likely to pay, and pay more, for DRM-free movies and music and more likely to pirate any &quot;restricted&quot; content.  If I pay for a CD, I damn well expect to be able to listen to it at home in my stereo, in my car&#039;s CD player, and to be able to rip the tracks to my iPod.  If I&#039;m not allowed to do those things, there&#039;s no point in me buying the music...it&#039;s not like any new music has come out in the last 10 - 15 years worth raising a stink about, anyway.  The more difficult it is for someone like me to rip their store-bought copy of an album onto their iPod, the more likely they are to go out and pirate a &quot;cracked&quot; copy that will let them transfer it with relative ease.&lt;br /&gt;
&lt;br /&gt;
To quote the Borg:  &quot;Resistance is futile.&quot;&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
The hard fact is that the latest developments at Cisco, Google and elsewhere may do more than kill the DVD and CD and further upset entertainment-business models that have changed little since the Mesozoic Era. With superfast streaming and downloading, indie filmmakers will soon be able to effectively distribute feature films online and promote them using social media such as Facebook and Twitter.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
This is probably the best part of the article.  The idea of taking the RIAA out of the picture just makes me smile.  The sooner they&#039;re gone, the sooner we can stop being spoon-fed this pop-formula Nickelback type shit.  If independents can start their own online market and promote/sell their music without the need for a label, then music might actually be worth saving.  As it stands, I say let the music industry dry up and never press or sell a single CD again.  Sure, we&#039;d be losing some of the greats, but there is so much crap out there that those rare gems make up a tiny fraction of 1% of the albums out there.  Now if music is readily available from the independents, there might actually be some music not only worth listening to, but worth buying.  I know there are bands out there much better than Nickelback, but they haven&#039;t been &quot;discovered&quot; or &quot;signed&quot; -- that&#039;s why they&#039;re still playing the local dive bar.  But if they could market themselves, this might drastically change the landscape of the music industry, and for the better.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Wed, 17 Mar 2010 13:10:16 -0400</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/367-guid.html</guid>
    
</item>
<item>
    <title>FCC to Propose Faster Broadband Speeds</title>
    <link>http://forkb0mb.org/content/index.php?/archives/366-FCC-to-Propose-Faster-Broadband-Speeds.html</link>
            <category>Articles</category>
            <category>Networking</category>
            <category>News</category>
            <category>Technology</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/366-FCC-to-Propose-Faster-Broadband-Speeds.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=366</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=366</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.ibtimes.com/articles/20100216/fcc-to-propose-faster-broadband-speeds.htm&quot; title=&quot;http://www.ibtimes.com/articles/20100216/fcc-to-propose-faster-broadband-speeds.htm&quot;&gt;FCC to Propose Faster Broadband Speeds&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
The U.S. Federal Communications Commission unveiled a plan on Tuesday that would require Internet providers to offer minimum home connection speeds by 2020, a proposal that some telecommunications companies panned as unrealistic.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
It&#039;s &quot;unrealistic&quot; if they wish to keep their huge profit margins.  With the average broadband speed in the U.S. being under 4 mbit (mentioned later in the article), they will be receiving approximately 1/25th the amount of profit per megabit that they&#039;re currently making.  Internet providers in Asia and other parts of the world that are subject to more regulation, or even state-run, have been providing 100Mbps - 1Gbps for several years.  It&#039;s more than technical possible, and financially feasible; you just have to be in a market where the monopolistic telecoms aren&#039;t allowed to gouge you at-will.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
The FCC wants service providers to offer home Internet data transmission speeds of 100 megabits per second (Mbps) to 100 million homes by a decade from now, Commission Chairman Julius Genachowski said.&lt;br /&gt;
&lt;br /&gt;
Industry estimates generally put average U.S. Internet speeds at below 4 Mbps.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
I suppose I&#039;ve been fortunate; I&#039;ve had access to somewhat reasonably priced connectivity at 10Mbps - 15Mbps.  I do, however, know several people with connectivity well below the 4Mbps mark.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
The proposal is part of the FCC&#039;s National Broadband Plan, due next month. It comes a week after Google Inc rattled Internet service providers with its plan to build a super-fast Internet network.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
I&#039;ve already nominated the city I live in.  With the high population density, diversity of professionals represented, and easy access to large amounts of bandwidth nearby, I think there&#039;s a fair chance that my city may be one of the chosen.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
&quot;A 100 meg is just a dream,&quot; Qwest Communications International Inc Chief Executive Edward Mueller told Reuters. &quot;We couldn&#039;t afford it.&quot;&lt;br /&gt;
&lt;br /&gt;
&quot;First, we don&#039;t think the customer wants that. Secondly, if (Google has) invented some technology, we&#039;d love to partner with them,&quot; Mueller added.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
&quot;...we don&#039;t think the customer wants that.&quot;  Excuse me?  That is the most ridiculous argument I&#039;ve ever heard.  Bandwidth is like RAM, you can never have too much.  If you&#039;ve got a connection faster than you&#039;re using at this very moment, you haven&#039;t lost anything.  If you don&#039;t have enough bandwidth for what you&#039;re planning on doing, then your experience will suffer.&lt;br /&gt;
&lt;br /&gt;
Google has not &quot;invented&quot; any new technology for what they plan to roll out, they&#039;re simply willing to spend the capital to build-out a fiber-to-the-home network (at least in select markets, initially).  As far as Qwest being willing to &quot;partner&quot; with Google on such projects, I&#039;m sure they&#039;ll be happy to let Google spend the capital to build out the fiber network and then try to make money through advertising or other avenues, not requiring them to spend a dime on the infrastructure side.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
Verizon, the third-largest provider, and one that has a more advanced network than many competitors, said it has completed successful trials of 100 Mbps and higher through its fiber-optic FiOS network.&lt;br /&gt;
&lt;br /&gt;
&quot;(One gigabit per second) as discussed in current news reports is a lot of signal; typically enough for many massive business operations,&quot; Verizon said in a statement that referred to Google&#039;s plan to test a network with those speeds. &quot;But we could make it happen over the FiOS network without much trouble, should a market for it develop.&quot;&lt;br /&gt;
&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
One analyst questioned whether the FCC&#039;s proposal could lead to a sustainable business model.&lt;br /&gt;
&lt;br /&gt;
&quot;In order to earn a return for investors, you have to be conscious of what consumers will pay. I don&#039;t know this is something consumers will pay for,&quot; Piper Jaffray analyst Christopher Larsen said. &quot;It&#039;s a nice goal, but it&#039;s a little on the over ambitious side.&quot;&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
It&#039;s been proven to be a sustainable business model in many parts of the world.  Nobody is more starved for bandwidth, as far as users go, than the U.S.  &lt;br /&gt;
&lt;br /&gt;
I doubt that the FCC proposal requires that the providers provide no less than 100Mbps to every customers, just that it&#039;s an affordable (to the majority of people) option.  If a customer doesn&#039;t want to pay, say, $80/month for a 100Mbps connection, then offer a 50Mbps option at $50/month.  That&#039;s incentive for the customer to pay the less than double price for the double bandwidth, and you&#039;re still meeting your obligation of providing 100Mbps service to those who want it.  I don&#039;t know of any network technology that will carry 100Mbps that won&#039;t let you throttle it back to 30, 50, 75 Mbps or any other arbitrary speed.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
The United States ranked 19th in broadband speed, trailing Japan, Korea and France, according to a 2008 study by the Organization for Economic Co-operation and Development.&lt;br /&gt;
&lt;br /&gt;
Data shows that about 64 percent of U.S. households used a high-speed Internet service in 2009, the Commerce Department said on Tuesday. That is a 25 percent increase from 51 percent two years earlier.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
This is truly sad.  We&#039;re the world leader in technological development, but due largely to greed, we&#039;re 19th in the world in terms of broadband speed.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Wed, 17 Feb 2010 22:07:21 -0500</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/366-guid.html</guid>
    
</item>
<item>
    <title>20 Years of Adobe Photoshop</title>
    <link>http://forkb0mb.org/content/index.php?/archives/365-20-Years-of-Adobe-Photoshop.html</link>
            <category>Articles</category>
            <category>News</category>
            <category>Software</category>
            <category>Tools</category>
    
    <comments>http://forkb0mb.org/content/index.php?/archives/365-20-Years-of-Adobe-Photoshop.html#comments</comments>
    <wfw:comment>http://forkb0mb.org/content/wfwcomment.php?cid=365</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://forkb0mb.org/content/rss.php?version=2.0&amp;type=comments&amp;cid=365</wfw:commentRss>
    

    <author>nospam@example.com (TJE)</author>
    <content:encoded>
    &lt;a href=&quot;http://www.webdesignerdepot.com/2010/02/20-years-of-adobe-photoshop/&quot; title=&quot;http://www.webdesignerdepot.com/2010/02/20-years-of-adobe-photoshop/&quot;&gt;20 Years of Adobe Photoshop&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
One of the most impressive things about the company is the fact that one gifted family, consisting of an engineering prof, a PHD engineering student, and a talented special effects whiz working at Industrial Light and Magic came up with the core idea of Photoshop.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Thomas Knoll&lt;/strong&gt;, the PHD student, is still heavily involved with Photoshop years later.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Glen Knoll&lt;/strong&gt; was a college professor with two sons and two hobbies; computers and photography.&lt;br /&gt;
&lt;br /&gt;
He had a darkroom in his basement, and an Apple II Plus that he was allowed to bring home from work.&lt;br /&gt;
&lt;br /&gt;
Thomas Knoll adopted his father’s photography habit throughout high school, while his brother, &lt;strong&gt;John Knoll&lt;/strong&gt;, purchased one of the first Macs available to the public.&lt;br /&gt;
&lt;br /&gt;
Fast forward to 1987: Thomas Knoll was a PHD student studying Engineering at the University of Michigan. His brother was working at Industrial Light and Magic.&lt;br /&gt;
&lt;br /&gt;
Thomas Knoll wrote a subroutine for a program to translate monochrome images on his monitor to grayscale.&lt;br /&gt;
&lt;br /&gt;
The successful subroutine led Knoll to create more and very soon he had a number of processes for achieving photographic effects on digital images.&lt;br /&gt;
&lt;br /&gt;
After his brother John saw what Thomas was doing, he recommended that Thomas turn what he was doing into a full-featured image editor.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
And lo, the world&#039;s most powerful - and likely most used - image editing software was born.&lt;br /&gt;
&lt;br /&gt;
It&#039;s hard to believe it&#039;s been 20 years.  I started tinkering with Photoshop 3.0, around 1995.  I&#039;ve had access to versions 3.0, 4.0, 5.0, 5.5, 6.0 and 7.0 over the years.  I definitely do not have the eye for graphics design, but it&#039;s fun tinkering around.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;font size=&quot;+1&quot;&gt;1994 – Photoshop 3.0&lt;/font&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The big story for Adobe Photoshop 3.0 was layers. Layers were and are a lifesaver for any marginally complex design.&lt;br /&gt;
&lt;br /&gt;
Prior to their introduction, designers would save different versions of designs so that they could go back and grab them if needed; layers made this practice redundant.&lt;br /&gt;
&lt;br /&gt;
Layers are individual slices of the image that go together to make the final “sandwich” of the image. Different images, such as those used in the image above in the 3.0 splash screen, are assigned their own layers, making it easy to work on those images without tampering with other areas of the image.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
This is the first version I tried.  The layers feature is a life-saver.&lt;br /&gt;
*/&lt;br /&gt;
&lt;br /&gt;
Thomas Knoll, the original creator of the program, was responsible for their development. Other engineers made improvements in the program’s performance with Power Mac chips and bringing the Windows version up to the same level as the Mac version. Tabbed palettes also had their debut in 3.0.&lt;br /&gt;
&lt;br /&gt;
Adobe engineers included Adobe Transient Witticisms (ATW) with this version. They were little Easter Egg funny one-liners that would appear only when you pressed obscure combinations of keys.&lt;br /&gt;
&lt;br /&gt;
/*&lt;br /&gt;
&lt;a href=&quot;http://www.peachpit.com/articles/article.aspx?p=30163&amp;seqNum=10&quot; title=&quot;http://www.peachpit.com/articles/article.aspx?p=30163&amp;seqNum=10&quot;&gt;Here&lt;/a&gt; is a &lt;a href=&quot;http://www.peachpit.com/articles/article.aspx?p=30163&amp;seqNum=10&quot; title=&quot;http://www.peachpit.com/articles/article.aspx?p=30163&amp;seqNum=10&quot;&gt;small list&lt;/a&gt; of known &quot;Easter Eggs&quot; contained within Photoshop.  They&#039;re a huge waste of code, CPU, and memory, but usually worth checking out.&lt;br /&gt;
*/ 
    </content:encoded>

    <pubDate>Wed, 17 Feb 2010 20:05:51 -0500</pubDate>
    <guid isPermaLink="false">http://forkb0mb.org/content/index.php?/archives/365-guid.html</guid>
    
</item>

</channel>
</rss>