About Me

I ramble about a number of things - but travel experiences, movies and music feature prominently. See my label cloud for a better idea. All comnments and opinions on this blog are my own, and do not in any way reflect the opinions/position of my employer (past/current/future).
Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts

19 December 2016

Amazon Prime Video

The Grand Tour is not the most pirated show ever - but it certainly is one of the most pirated shows ever. That is not too surprising - Top Gear in the days of Clarkson was also one of the most pirated shows. Some years back, I wrote a paper on digital piracy (also related to a presentation at Indicare 2005) where I proposed that a key cause of piracy was availability of media and convenient format of media - and while factors such as price matter, digital piracy would remain an issue if availability in the right format is not solved for. The Grand Tour is the perfect example of this proposal - launching a highly popular show (well at least Top Gear was) but constrained to a few locations instead of the global reach.

Amazon's Prime Video service has now taken the leap of bridging the availability conundrum with its global launch. The key attraction - shown prominently on the web page - is off course The Grand Tour; but it does offer more than that. Amazon's own original series - Mozart in the Jungle, Man in the High Castle - are also on offer; and the price is phenomenal at USD 2.99 for the first 6 months followed by the standard price of USD 5.99. Oh, and there is a free trial also for a month.

However, the breadth of content is quite underwhelming. Starting with Amazon's own content - the content available is not all the content produced by Amazon. Furthermore, not all the seasons are there - I have access Mozart in the Jungle's first season, not the second for example (and the same with Transparent). Outside Amazon's own content - there are very few other top TV series, and the catalogue for movies is equally bare. 

Catalogue of content aside, the other big annoyance is the lack of Apple TV support. At this moment, I am downloading content to my phone and then playing via Airplay (and I am very impressed with its power efficiency). But what I would rather prefer is to queue content download on Apple TV, instead of relying on downloading when I am at home.I have tried the streaming - and have been generally quite impressed with the quality and speed. My Internet connection is flaky so prefer the download approach - but generally I have been impressed by the app.

I expect that the catalogue will grow with time - and there is enough right now to keep me interested and subscribed. I just need the Apple TV app ...

24 January 2015

Yahoo! News Digest

I am a news junkie - and I have tried numerous apps on my iPad and iPhone. Apart from Flipboard, none of these have really stuck for continued usage. I discovered Yahoo! News Digest late last month - and it has become my defacto news app. The concept really works - a set of curated news summaries (multiple editions available), twice a day. The interface is sleek, and for the most part, the additional links (twitter feeds, maps, Wikipedia entries, etc) are a nice touch. For detailed news - Flipboard is still the leader - but this app is best for catching up on the key topics.

26 March 2014

Internet access in Turkey

I was quite impressed with the speed and wide availability of Internet at the hotels. All of them provided free wifi as part of their service, and even in remote Behramkale, the speeds were great. Given the proximity to Europe, the speeds were not surprising, but the ubiquity was.

I am not a great user of Twitter, but I did notice the switch off. On Thursday evening it was working fine, but from Friday morning it was off. There was no error message - it seemed that the DNS queries were simply blocked. I did not try too hard to circumvent - I wasn't that interested; but it seems from news reports that it was easy to circumvent.

22 October 2013

Side Channel Attacks in the Cloud

I saw this paper (by Yinqian Zhang, Ari Juels, Michael K. Reiter and Thomas Ristenpart in ACM CCS 2012) earlier this year, but thought it was a very specific threat model. In a  one line summary - it is possible to recover private keys when they are being used within a virtual machine, through observations of the activity of the virtual machine from the host machine. It is a very complex attack, and requires at least host access for these observations, so my initial thoughts were that this attack could only be carried out by extremely skilled admins of a cloud hosting provider; but the complexity would probably mean that there was no realistic threat in that regard.

With the NSA revelations of the past few months, this is an interesting approach that could be taken by an agency (such as the NSA) to recover private keys from cloud providers, without getting actual access to the servers themselves. Given that PRISM does provide such access to hosts, it is not inconcievable that systems that are hosted on public cloud services such as Amazon's EC2 could be monitored. However, given the description of events relating to Lavabit, it is likely that this type of attack hasn't been operationalised yet - but remains interesting on what could be achieved.

07 October 2013

The Price of Prepaid Mobile Data


The Economist has an analysis of mobile data prices (prepaid), with some surprising results. When the average prices are measured against the country's average income levels, SA prices do not come across as too bad - especially when compared to the US prices; and most of BRICS seem to be on par. With the recent announcement of even further cuts to mobile prices due to reduction in termination rates, the mobile data price should get better!

18 September 2013

NSA and Cryptography Attacks

There have been a few excellent articles on the NSA "breaking encryption", as reported in The Guardian and New York Times. In the talk 2 weeks ago Vint Cerf commented that we should use stronger keys - but as per the articles, key length may not be the issue at all. To summarise there are a few ways encryption can be broken:
  1. Brute force the keys
  2. Bugs in the software/hardware implementation
  3. Bugs in the algorithm
  4. Interception before encryption (in the case of network encryption specifically)
  5. Steal the key
For point 1,  I think the maths of brute forcing the keys still hold out, we may be close - but I don't think we are there yet. But still, the advice of stronger keys always helps.

For point 2, there have been bugs in encryption libraries before and there are potentially still bugs in these libraries. Both Bruce Shneier and Matthew Green comment on the possibility that there are bugs in the Microsoft crypto library (which is closed source) and even Open SSL. Another possible attack vector, as noted by Ed Felten, is buggy components that make up crypto components, such as bad random number generators - which can then lead to weak keys etc. Faulty hardware (including deliberate backdoors) is also a possibility explored by Ed Felten.

For point 3, in most cases the maths in encryption algorithms seem to be right, and strong. But there have been cases were crypto algorithms have been broken (sometimes after years in operation) and cases where weak algorithms have been submitted for consideration in standards. I think most of the modern algorithms, such as AES are strong - but perhaps there are flaws that just haven't been published.

Point 4 raises an interesting attack vector, which I have seen being carried out by pentesters - basically a proxy service where a network call is intercepted at the initiation of a network session, and then network encryption is easily eavesdropped by the middle party. If the NSA is intercepting huge amount of traffic, it is possible to create such an attack - but automating this in a large scale is surely difficult?

The last point, of stealing keys - or rather forcing companies to hand over their keys under Prism is probably the easiest way for the NSA. There is some commentary on the possibility that the NSA had access to compromised keys at certificate authorities - which would assist this type.

Overall, I don't think there has been fundamental break in cryptography - but there has certainly been weak implementations followed by exploitation by the NSA.
 

17 September 2013

The best form of defence is active defence

Over the past couple of years, Dave and I have had numerous discussions on various legal concepts around IT. As a noted privacy expert, and a IT professor at UNISA, the topics have been varied, and often straying to the esoteric.

Over the weekend, Dave and I recorded a podcast with Tony Olivier for the DiscussIT Pubcast on IT Security, covering the concept of active defence/hacking back. Dave and I previously presented the topic at a closed forum? And thought it would make it interesting to make it available to a wider audience. Tony is an excellent host, and managed to steer the discussion to additional points we had previously not covered. The podcast is a bit rough - it picks up a bit of the ambient noise, and is mostly unedited so all the umms and stutters are included for special effect :)

07 September 2013

Vinton Cerf and Re-Imagining the Internet in the 21st Century

WITS Vice Chancellor, Prof. Adam  Habib opened the proceedings of the 62nd Bernard Price Memorial Lecture, with reflections on Dr Bernard Price - a notable engineer and scientist who straddled a number of scientific disciplines and also had significant input into the development of South Africa's electrical infrastructure. In that sense, Prof. Habib concluded that, Vinton Cerf was similar; as someone who has straddled the development in science, most notably in the sphere of Internet protocols; but has also had a profound impact on the development of the world through his contributions.

 Vinton Cerf's talk definitely paid homage to that theme; where he charted the development of the Internet, from the initiation of ARPANET itself, all the way to the modern Internet of things, and inter-planetary Internet. His insights into the development of ARPANET itself was interesting - from the considerations that were needed for satellite and radio inter-connectivity, and to more humourous commentary on how the address-space allocation in IP was derived.

He covered some of the coming challenges of the Internet including privacy concerns (something, he believes will only be addressed through trial and error), the promise of Google glass (which will go on sale next year, apparently) and the policy battle for the control of the Internet. 

It is the first time, I have heard a clear and succinct explanation on why ICANN is better than the ITU - ICANN is a multi-stakeholder body that includes corporations, private persons and governments; whereas ITU is purely a government organisation. Thus, ICANN, being more participatory is more likely to uphold the tenets of the Internet, as opposed to ITU which may make it a political football. He did think that ICANN requires more government engagement, especially with regards to cross-border disputes and crimes - but ultimately it should be run without political interference.

He finished with commentary on the challenges of inter-planetary Internet. I had not considered the challenges to be that difficult, beyond the physical constraints - and the actual deployment of relay points via orbiters, probes etc. is something fairly logical IMO. However, when he threw the discussion to inter-stellar Internet, and the challenges posed by the bending of light via gravity, it did make the challenges far more interesting - although the approach was seemingly still similar.

Vint Cerf is an amazing speaker, and it was a great memorial lecture by one of the great scientists of today. You can see the full video on YouTube, though apparently the slides aren't shown.

20 July 2013

Gmail's Inbox Tabs Suck

I love tags in Gmail - they are a brilliant way to organise and manage emails. This past week, Gmail introduced a new feature - inbox tabs - some sort of an automate sort of emails based on sender/content. 

Normally, I don't have issues with most changes in Gmail - but inbox tabs just didn't work for me. During the week, I mostly use the Gmail app on my phone - and I kept getting notification of emails that I couldn't see - because they were automatically moved to a different tab; unless I went and changed my view. And there were quite a few inconsistencies in how emails popped up in different tabs - some LinkedIn emails went under "social" while others went to "promotional". 

Perhaps I use my Gmail differently - I minimise the number of active emails on my Inbox, and archive and tag everything else. What really annoyed me - unlike tags, in the tabs view, I could only ever have an email in one view; so I ended up trying to find emails across multiple tabs. Eventually, I just switched it off.

11 June 2013

20 Years of Cricinfo

Cricinfo (or now, known as ESPN Cricinfo) is one of the oldest websites, still operational. It started as a community driven initiative, and as far as I know, it is the largest dedicated single-sports website on the net. It has become the defacto repository for cricket knowledge, opinion and journalism. I blogged previously on the facinating history, and as it celebrates 20 years, some of the back story is now being published online.

10 years ago, a lecturer at UCT posed the question - would anyone pay for news content, when there are so many alternative sources for free. I replied then, that I would pay for Cricinfo and Autosport.com. My Autosport subscription has since lapsed - more due to my waning interest in F1 than the content; and Cricinfo has never asked for subscriptions - but yes, I would still pay for Cricinfo. And there is really, no alternative out there.

24 December 2012

" Free" Internet Services

Everyone loves a free service, and there seems to be a certain expectancy that services on the Internet - be it news, games, music or even search - should be free. Most of these services fund their free services through a combination of
  • Advertising revenue - although the one of the most popular plug-in for Firefox (and Chrome I think) blocks advertising
  • Subscription for premier/exclusive content. This works if the content is truly niche - I used to subscribe to Autosport.com because of their exclusive articles on motorsport. My interest waned; so I cancelled the subscription - but it was definitely value for money.
  • Donations and product sales - quite popular with online comics etc. and some people make a living out of it
  • Subsidised by non Internet products - which is quite common with a number of media sites.
In addition to media services that are powered by "paid" employees (i.e. news sites, etc) there are also user generated content sites; which rely on people contributing their own "free" effort to generate and maintain content.

Occasionally, a service provider tries a different approach - and it is always interesting to see the commentary on the resultant changes. Instagram's proposed change in terms and the outcry from the change was quite illuminating in that respect. The terms of service were actually not that different - a number of different service providers, many notably cloud providers have similar clauses - but Instagram made the conditions quite clear and easy to understand unlike a number of other providers, whose terms on reusability of submitted content is buried deep in the legal text.

For example, see YouTube's terms of service (section 8), where the contect uploader gives YouTube royalty free rights to the submitted content to be used in whatever form YouTube wishes. Yes, YouTube doesn't say it can resell the the videos; but the license doesn't restrict it from doing so (after all making money would be consistent in "provision of Service").
8. Rights you licence
8.1 When you upload or post Content to YouTube, you grant:
A. to YouTube, a worldwide, non-exclusive, royalty-free, transferable licence (with right to sub-licence) to use, reproduce, distribute, prepare derivative works of, display, and perform that Content in connection with the provision of the Service and otherwise in connection with the provision of the Service and YouTube's business, including without limitation for promoting and redistributing part or all of the Service (and derivative works thereof) in any media formats and through any media channels; and
B. to each user of the Service, a worldwide, non-exclusive, royalty-free licence to access your Content through the Service, and to use, reproduce, distribute, prepare derivative works of, display and perform such Content to the extent permitted by the functionality of the Service and under these Terms.

In fact, the proposed model has already appeared in practice; though in the example neither the service provider nor the photographer made money. In his keynote at the Virtual Goods Workshop in 2008, Renato Iannella covered a similar case; covering the use of a flickr photo in an advertising campaign half a world away. The photographer had shared the content without restriction, but at the same time did not actually have the right to share the content in the first place! Instagram's proposed terms only addressed one part - the rights of the photographer; forgotten in the commentary was the rights of the subject!

xkcd captured the conundrum and some of the absurdity of the backlash in a brilliant analogy; but Instagram has backed down and the problems with financial models for these seemingly free services remain. So far, only Google has really cracked the code of making money from free services - but as companies like Facebook become accountable to shareholders for making money; maybe we should expect more similar terms?

20 June 2011

Anonymous and Lulzsec Declare war on Corruption

After hacking the sites (and systems) of the CIA, the FBI, various US government departments, various corporations (most notably SONY), Lulzsec, and Anonymous have released a joint call to arms - a Jihad if you will - against corruption. And like many Jihadi movements, many commentators have already labeled it as "cyber-terrorism". Their "press release" is quite impressive, and full of good intentions but some points come to mind.


  • While the announcement itself asks for support for Wikileaks, how the evidence for corruption will be documented is not detailed. One of the standout features for Wikileaks is its impressive documentation, anonymisation and verification process. Simply releasing information is not enough, which leads to ...

  • How will the supposed corruption evidence be proven. It is one thing to break into a "secure" network, and even to retrieve data. But the legitimacy of the data needs to be proven - sufficiently that it will be difficult to label as a fake. Considering the skills of the attackers, there is actually a higher burden of proof to ensure legitimacy of the data.

  • Proving corruption will require a lot of corroborating evidence; and rarely will corruption be highlighted by a single data source. Furthermore, corroboration will require a number of disparate sources - e.g. an instruction via email linked to a bank account statement linked to an email on the success of the scheme. How many sources require infiltration before evidence is sufficient?

  • Inevitably there will be innocent bystanders hurt in the process - either because they are unknowing mules or wrongly targeted. Verification problems yet again?

  • Hacking into networks is illegal - and will remain illegal for the foreseeable future. Good intentions or not, this badly written, but informative article gives a good overview of the moral dilemmas awaiting the prospective hacker.



Given the revelations over the weekend relating to South Africa's own arms deal corruption saga, I am quite keen to see the results of this mass action. And I don't think it is cyber terrorism, yet. And, I do have some grave doubts on whether any real prosecutions or changes to corporate and government activities will actually result from this.

10 April 2011

The fascinating history of CricInfo

I have been using CricInfo (now known as ESPNCricInfo) since the late 1990's. I remember using it at school to follow the world cup in 1999 and other matches before that. It has become a publishing phenomenon as well as a treasure trove of cricket data. During the recently concluded world cup, the site has been running a video series "Running Between the Cricket", and the last video (episode 30) spurned me to look deeper on the history of the website.

CricInfo's own about page is pretty barren, and its Wikipedia page is not as informative as it should be, but there is a link to an alternative Wiki page here, and it is a fascinating story of an Internet phenomenon - a group of people, who contributed their time and energy (and in some cases hard money) to fuel their passion. There are interesting tidbits on the history of the Internet itself, and some naivety in this regard - such as the expectation of a single Unix server to last for 10 years!

23 January 2011

Facebook Valuation

Facebook's recent valuation of 50 Billion USD, has created quite a lot of commentary - mostly centred around it being way too high (from most commentary I have read). The valuation is based on what Russian (and part South African) venture capitalist firm Digital Sky Technologies and Goldman Sachs were willing to pay for a share in Facebook. In essence, most commentators have argued, that they paid too much.

In terms of classical economics, that is true, or at least based on given information. Afterall, Facebook is a private company, and thus its financial results are not public information.

However, valuations can also be based on the net worth of Facebook's assets. And its biggest assets have currently no real means of being objectively evaluated - personal information. Facebook has over 500 million active members; which in turn translates to personal information including likes, dislikes, freinds, connections, activities, photos, and a whole lot more of 500 million people on the planet.

If one ignores Facebooks' traditional assets (servers, datacentres, offices etc) and liabilities, it means that the personal information of 500 million people is worth 50 billion dollars - or 100 dollars an individual.

The resultant question is simple - is the personal information of you, or any other person worth more or less than 100 dollars? In fact, if someone would offer you 101 dollars, would you give them more information than what you have willingly published in Facebook for free?

50 billion dollars? I think Facebook is undervalued ...

03 April 2010

Gmail Cleverness

I was writing an email in gmail, meaning to send an attachment (which I forgot to actually include). However, I did write "I have attached ...", and GMail picked it up, and asked whether I wanted to attach file to the email. Which obviosuly leads to the question - what combinations of the word attach does GMail understand? Investigation is warranted ...

21 January 2010

Chrome and GMail


I have had lots of problems with Chrome and Gmail in the past, especially when the earlier releases seemed to be buggy for proxies. But this error message takes the top prize! For the record, I was not using a proxy, and am on a direct connection to a Tier 1 ISP.

For those who are not inclined to click on the pic, the error states "It seems there is a problem. Please try using Gmail with a supported browser".

26 April 2008

Telecommunication Prices

MyBroadband has an article on the proposed Neotoel consumer pricing info, and in my opinion, it is very competitive. But, as Phathu loves to say, South Africans love to complain.

Reading the forum discussion, it seems what Neotel (or for that matter Telkom) needs to provide is fibre to the premises, uncapped, high speed broadband, and all for less than R500! Sorry - but that is not only unrealistic in the short term - but it is also clear that many people just do not know how expensive it is to roll out telecommunication infrastructure.

As I work for a ICT company in South Africa, I have first hand knowledge of how expensive it is to build infrastructure. Just some raw figures - it costs approximately 1 million rand (if you are lucky) to lay one Km of fibre. That does not even include the costs it will take to process the admin required to dig across numerous roads and pavements. Fibre to the home ... forget it anytime soon. And don't forget the switches ... a low end switch for fibre networks easily costs a few hundred thousand rands. Then, one should not forget the emergency power supplies (always important in South Africa), the security measures and the costs start multiplying very quickly.

I have done the calculations (as part of my job) ... if a company is to roll out telecommunication infrastructure, across all the major cities in South Africa, charge about R1000 per month for a 1 Mbps link, they will need 30 000 subscribers on average over 5 years to just break even. And this would be for a wireless network (like WiMax or iBurst or something similar).

As for international bandwidth - it costs a lot because there is scarcity. Until the new cables come into operation, do not expect Internet prices to drop. And even with new cables, it will take time for prices to drop - under sea cables are expensive to lay and even more expensive to run and maintain.

In one of his early books, the late Arthur C Clarke argued that once there are enough satellites in space covering the globe, global communication would become almost free. What he did not obviously take into account was the price of maintaining global connectivity, and the bandwidth required for YouTube, HD Video or even Web 2.0.

16 December 2007

Offline Blogging Tools (for the Mac)

I have been testing out Qumana, a offline blogging tool that works on Mac OS X (Leopard). Basically, I was looking for a tool that I can use to create posts offline and then upload when I have net connectivity, in particular for my South America trip. This is the only tool that seemed to work when I looked at this issue in Germany, but it has its share of problems: three major ones from my point of view.

Firstly, the title does not seem to be posted. I have tried numerous times and every time, the title is lost.

Secondly, there is no support for Blogger's labeling system. It does have tagging support - but I specifically want to use Blogger's labeling system for consistency.

Lastly, the save posts function sometimes does not work - and no error message is given. And this is the most annoying part of it all - after all, adding labels and titles are a few clicks, rewriting a post can take minutes if not hours.

The spell checker also does not seem to work ...

So all in all, I am looking for other options ... any recommendations?

12 September 2007

Foo Bar

I have always wondered the history of using fooand bar in computer programs. RFC 3092 sheds some light.

RFCs or Request for Comments are one of the key foundations to standards on the Internet, and increasingly standards generally for computer systems. But I came across RFC 1121 by chance, and stumbled onto a set of RFCs that are funny or just plain weird ... inside jokes etc. Quite a big list of them here.

Lots of reading for the bored :P

27 July 2007

Nannying the Internet

This post is primarily motivated by this article. Basically, in an attempt to fight botnets, a US ISP is diverting traffic intended for suspected botnet addresses to "safe" addresses. So far, a noble goal? Except off course, if the suspected botnet address is actually a legitimate address - i.e. a false positive. This is when things get complicated, because customers get angry and companies loose business.

There is a ton of products out there that can be used by ISPs to control network traffic and block access to certain sites. Most of them work at the DNS level (which largely makes sense) by blocking out DNS entries; although others go the extra mile and block out reverse lookups also. Primarily the products cite controlling/blocking porn and phising as the primary motivation, but at an ISP level?

Should any network provider have any control over what the customer wants? Even if it is illegal? Even if it is against the customer's best interest? It is a tough legal question; but it all really revolves around who controls these lists? And can these lists be reviewed by the public?

In the battle for safety, giving the control over safe areas of the network to an ISP, while easier for the general public, is one step closer to Big Brother in many ways. What is the difference between this and the big China firewall? In both cases, if you can't see it - it doesn't exist! "Those Who Sacrifice Liberty For Security Deserve Neither" ... it is equally applicable to virtual world as it is to the real world.