About Me

I ramble about a number of things - but travel experiences, movies and music feature prominently. See my label cloud for a better idea. All comnments and opinions on this blog are my own, and do not in any way reflect the opinions/position of my employer (past/current/future).

17 October 2012

Google's Datacentres

Wired has some amazing articles on Google's datacentres and the computing power behind it all. 

Very interesting reading!

15 October 2012

Melting Pot

It had been a long time since my previous visit to London - about 6 years I think. The Olympics hasn't really changed the city - other than the remnants on the billboards. It remains old and grimy in some places; and new and shiny in others. It is a testament to the sheer longevity of the city.

One thing that has noticeably changed, is that it is an even bigger melting pot. The high volume of Indian immigrants is well known, but it is only in this trip that I noticed all the other shades of accents - the Polish (or some other Eastern European) receptionist, the Caribbean assistant at the Tube station, various main stream European languages, Chinese, Malay etc. And these aren't even the tourists. 

I still don't like the weather, but I do love the melting pot.

13 October 2012

Movie: Haywire

It is a spy/action thriller featuring some top notch actors in Michael Fassbender, Ewan McGregor, Michael Douglas and Antonio Banderas, about on a female mercenary who is framed by her employer. It's a nice story, with a fairly realistic story (no amazing gadgets, people get hurt it fights) but nothing spectacular.

Movie: Father of Invention

It has been a while since I have watched a movie featuring Kevin Spacey. The movie features a successful inventor (who makes money from infomercials) who has just got out of prison. It is partly a story about his search to reclaim his mojo as a inventor; but ultimately it becomes a feel good soppy movie about family values. The brilliance of Usual Suspects this ain't.

For the Lack of a Conductor

The Heathrow connect from London made a surprising, last minute cancelation and stopped the station before the airport. At this point there were three options, take the next train, take the bus or take a taxi. The latter two options wouldn't be supported by the train company; and the last minute change was very perplexing.

It was particularly perplexing that the options were not communicated by the train drivers or the station; but rather by a young apprentice of the train company who had just got off and similarly inconvenienced. Apparently, the cause of the delay - the lack of a conductor to check tickets; apparently a requirement for all Heathrow trains. And even more alarming - this is not an irregular occurrence; but something that is quite frequent (the missing conductor and thus the cancelation of a train). Apparently, this is most frequent on early morning trains to and from Heathrow.

So, if you don't have 30 minutes to spare waiting for the next train (and are willing to pay double); get the express. The affliction of missing conductors apparently does not affect the express.

11 October 2012

Hacking Virtual Worlds

Jason Hart had a brilliant talk on different techniques to hack virtual worlds. His key message was, as virtualization had taken off, the CIA principles for security have been completely ignored and many of the old vulnerabilities have not only resurfaced; they are even easier to exploit.

Not all of the talk was specifically focused on cloud. Using a Pineapple he showed how easy it is to intercept and decode passwords (even when they are encrypted). After that, accessing systems, virtual or not, is not a big issue.

But his attack techniques on virtualization platforms were the most illuminating - from accessing VMWare's vCenter via cracking the MD5 password; to exploiting the fact that robot.txt files aren't respected in public cloud services (and thus susceptible to google hacking).

It was not a failure of technology (although the Pineapple did exploit protocol weaknesses), but failure to follow basic principles.

Active Defense

Another buzzword at the conference is Active Defense. Introduced by Francis deSouza in his keynote on day 1, it is based on the idea that wars are not only won by defending, but also by attacking and eliminating threats. The concept is off course controversial and the legal, technical and ethical challenges have been raised by a number of latter speakers.

This morning, Josh Corman raised the idea of resurrecting Letters of Marque as a means of regulating active defense. I am not convinced that this approach will solve the legal and ethical challenges.

Letters of Marque, were granted by European monarchs to sanction specific pirates and allow them to carry out their piracy (usually as long as it was not in their backyard). Effectively, it was state sanctioned criminals; and the idea to enable Letters of Marque for cyber attacks will open a Pandora's box.

Josh Corman's HD Moore's Law

Since yesterday's keynote by Josh Corman, HD Moore's Law has become some sort of a mantra by the other speakers at the conference.

It's a brilliant argument; instead of focusing on compliance as a minimum baseline, the minimum baseline should be, can you get compromised by default/basic settings of Metasploit? The ease of use of Metasploit and since its widely available, it makes it an easily exploited attack vector. It also aligns to the US RSA Conference talk on metrics that commented that the basic metric of security is "hackability", or how easy is it to hack you.

10 October 2012

Live RAT Dissection

Uri Fleyder (RSA) and Uri Rivner (Biocatch)'s presentation yesterday on the use of remote administration tools, coupled with "man in the browser" attacks is probably the most alarming threat exploitation I have seen recently. 

The attack first exploits browser vulnerabilities through drive-by-downloads to infect the target machine. I suppose a drive-by-download is not even necessary - other vectors could also be exploited. Once the target machine is infected, the attacker can make use of a remote administration tool (RAT) to carry out an attack using the target machine. Through the use of "man in the browser" attack, the attacker intercepts browser activities, such as banking (or e-commerce or any other activity), and thus can not only capture data in realtime but can also take control over the browser and show false messages (such as longer login times, false redirections etc). 

The beauty of this attack, is that the attack is completely out of the target user's machine, and tokens are actually also compromised in this attack (through the use of redirections). And there are very few countermeasures ...

09 October 2012

RSA Conference Europe: Day 1 Keynotes

There was an overall theme to the first three keynotes - a need to change the security models from (perimeter) defense based to "intelligence based" model. Art Coviello (Chairman, RSA) introduced the theme, with a focus on changing security to be more agile, contextual, risk based and the need to share and analyse information on scale.

Tom Heisner (President, RSA) followed expanding the themes, with an insightful comment on the Moore's law equivalence in security; the cost of attacks have reduced while the complexity of attacks have increased. Both speakers were hugely critical of compliance based regulatory regimes which are sometimes contradictory, and often provide a false sense of security.

Francis deSouza (Symantec) followed the theme with a focus on the need to be more "militaristic" in IT security. His argument was that you can't win a battle on purely defense, and security strategies and solutions need to consider the whole campaign and not just point vectors. In this regard, defense mechanisms also need to be "great" and not just good to be effective.

Adrienne Hall (Microsoft GM for trustworthy computing) focused mainly on cloud adoption, though was a bit out of sync on the earlier theme. Hugh Thompson, was also out of sync, but did raise a different perspective - security solutions currently are a "one size fits all" solution, and are not catered for individuals, so are either too complex or too simple; and are basically both ineffective. To create a security profile that is really personalized will be difficult, but would be a very interesting approach in becoming more secure.

Chill Man

I caught the slower train from Heathrow to Paddington, which stops at a few local stations along the way. It was surprisingly quick to clear immigrations (last experience at Heathrow, over an hour, yesterday 5 minutes), so I had some time before I could check in to my hotel.

The first stop after Heathrow, two heavily tattooed men dressed in tatty clothes got on, and hung by the door. Shortly thereafter, the conductor came through checking tickets, which these men didn't have. I was quite surprised, as were the two men, on the conductor's reaction. After a hushed (but still audible) chat on why they didn't have tickets, the conductor simply asked the two men to take a seat and relax. The men were so startled, that the conductor had to repeat himself, "chill man".

I am not sure why this small incident should stick in my mind ... are these instances of understanding officialdom so rare?

07 October 2012

Symphonic Rocks 2012

The second year in Jo'burg wasn't as well attended, with a number of free seats. Carnival City, as a venue probably contributes to that, but the crowd did seem a lot more diverse than last year. The combination of the 65 piece Cape Town Pops Orchestra and leading SA pop/rock artists is not only great music, but as Ard Matthews put it so eloquently, a great way to preserve a dying art, an contribute to enhancing our culture.

After a short overture, aKing started the proceedings in rocking style with two of their popular radio hits. It was a good start, though the next singer ChianoSky, didn't continue the momentum. Her dance hits for well with the orchestration, but her squeaky voice just irritated me.

A noticably slimmer Zolani Mahola (of Freshlyground fame) was the best performer of the first half, getting great applause and support from the crowd, and there was even dancing in the stands! Freshlyground's music lends itself to orchestration, and I think it would be great if they released a full album backed by an orchestra!

Van Coke Cartel's Afrikaans metal worked with the orchestra, although at times the electric guitar riffs did overpower the orchestra. They kept the energy going, into the next act, Toya Delazy, whose dance pop hits were more well suited for the orchestra.

Ed Matthews confessed to being a "soppy rocker", and belted out two of his solo love ballads followed by the classic "What he means", which seemed to get the whole audience singing. Tumi & The Volume closed the first half, though I found his voice to be overpowered by the instruments.

The second half started with a medley of theme songs from James Bond franchise (cleverly following a Heineken ad featuring Daniel Craig); which got a rousing applause from the audience. Andy Mac, the organizer behind Symphonic Rocks was next with his band Macstanley. Andy makes a good MC (better than the actual MC) and did a good job in introducing everyone on the stage (and the credit for being the head honcho). I haven't really been a fan of Macstanley (or Flat Stanley in their previous incarnation) and they were certainly blown away by the acts that followed.

Fokofpolisiekar should make a symphonic Afrikaans metal album. More than anyone else in the show, their ballads were perfectly pitched with the orchestra and was a truly amazing result. Their standard, "Hemel op die Plateland"was amazing with the symphony and got everyone headbanging.


Multi SAMA winner Zahara was next, and the success of the show was evident in how all the headbangers just switched to jiving along. She has an amazing voice, and it was a great to see her perform live.

Mi Casa played an interesting set, where there didn't seem to be any break between the songs (as would be expected from a electro-dance group). The trumpet playing of Mo-T was impressive, and fitted well into the arrangements.

Ed Rowland, the lead singer of Collective Soul was the last performer. I have seen Collective Soul before, but I am not really acquainted with their music. It was a great performance and a fitting end to the show.


As a final comment, perhaps future shows should consider reducing the number of artists in favor of giving them longer sets. And move the show closer!

23 September 2012

Movie: Beasts of the Southern Wild

It is a strange movie - but one with an incredible imagination, and absolutely stunning acting performances; and a moral story about the devastating impact of climate change. Set in a poor community near New Orleans, the story revolves around a young girl, Hushpuppy, her eccentric father who is trying to teach her how to survive and some strange events that take place during, what seems to be a hurricane. I don't think I really understood some part of the story (like the aurochs), but the acting performances were incredible.

09 September 2012

Buskaid 2012

This year, Buskaid's annual concert was sold out - the first time in the three years I have been going to Buskaid. It's a good thing I bought tickets early (which ironically meant that I almost forgot about it)! The concerts are an interesting mix - classical music by often less heralded composers interwoven with jazz/pop songs; and finished off with kwela and dancing (with the instruments) - something I doubt you will ever see at other classical music concerts.

The concert started off with pieces from Rameau's opera, Castor et Pollux. The program notes, that Rameau has become somewhat of a tradition with the Buskaid, and it was an energetic start to the concert. Due to a recording malfunction, the pieces were played again at the end - with ample encouragement from the crowd!

The second piece, was one of the highlights of the concert. A previous Buskaid concert, was the first time I had heard a live performance of music from "The Black Mozart", Chevalier de Saint-George. This year, the two senior violinists, Kabelo Monnathebe and Simiso Radebe, in the group (both studying at the Royal Academy of Music in London) performed the Allegro of the Symphony Concertante in G major. It is a stunning piece, especially how the violins feed off the rest of the orchestra, and how they blend into each other; and it was a captivating performance by the soloists.

Czech composer, Leoš Janáček's Idyll for String Orchestra was a bit of a let down after the Symphony Concertante - it felt like a filler piece; and I would have preferred a full performance of the Symphony Concertante instead. It was followed by two vocal pieces (Send in the Clowns, and At Last, both from old musicals), sung by viola player Mathapelo Matabane; who certainly has a voice that complements the style of the songs. The last piece, before the interval was the last movement (Marcia) from Swedish composer Dag Wirén's Serenade for String Orchestra. It is a very lively piece that I haven't heard before (though it is supposed to be very popular). I am not a big fan of Handel, so the first piece after the break (Suite from Terpsichore) wasn't that interesting.

Kabelo Monnathebe's performance of Nigun, by Ernest Bloch was the highlight of the evening for me. Part of a bigger work, Baal Shem, it is a dedication to Bloch's Jewish Roots, and Nigun is itself a religious piece. The piece itself is wonderful - it sounds religious, but it sounds like a story that wants to burst out. A story of triumph, of despair, of happiness and a whole lot more. It is a piece that requires mastery of the violin, and it was a brilliant performance, receiving a rousing applause at the end.

The last "official" piece (before the rerun of the Rameau, and the kwela pieces) was the "world premiere" of Karl Jenkin's Soweto Suite for Strings. It is not a completely new suite - but is rather assembled from Karl Jenkin's two big hits - The Armed Man and Stabat Mater. The pieces work surprisingly well together, and it is interesting to hear them without the choral and other orchestral accompaniments (although there were a few drums).

Beyond showing the musical talent of South Africa, Buskaid is a positive push on how transformation can take place; and a triumph of skill and perseverance over simple affirmative action. However, while it Buskaid has been wildly successful, it is facing a massive financial shortfall should the Lotto money not be renewed. In that it requires support - and support for more than just attending concerts and buying CDs, and I plan to add my pledge to the ring. 

That said, Buskaid is now effectively a thorough bred music school - and perhaps it is time that it also spans its wings. With highly competent performers and teachers, perhaps it should also consider doing lessons that are paid for. After all, while it is true that the vast majority of its students are from disadvantaged backgrounds; there are also students who are from advantaged backgrounds who wishes to learn and improve playing string instruments. Perhaps the solution should also encompass teaching, for profit, to the advantaged students that can afford the lessons? Yes, it may be a different track to how Buskaid started, but it could be an important step to a brighter, and more integrated future ...

22 August 2012

Movie: The Dark Knight Rises

Christopher Nolan's Batman trilogy has to be the finest superhero movie series to date. Across all the spheres, the beautiful cinematography, the great acting, impressive story writing and dialogue; each movie has been a great movie first, before being a great superhero movie. Like a proper trilogy, The Dark Knight Rises, builds upon the earlier stories and characters - not only in the growth of Bruce Wayne/Batman, but also the supporting characters such as Commissioner Gordon and Gotham itself.

The story has a bigger political undertone, especially of Bane's "uprising"; but the ultimate link to why Bane actually targets Gotham is tenuous, at best. It is probably one of the biggest plot holes (next to how Batman gets back to Gotham after his "exile"), especially as Batman has for all intent retired at the beginning of the movie. That aside, the pacing of the story, the characters (especially Bane and Anne Hathaway's Catwoman) and the construct of the "prison" of Gotham City is superb.

I have only two, relatively minor, issues with the film. Firstly, Bane's (and sometimes Batman's) speech was sometimes inaudible - but that could have been to do with the theater (and my hearing). Secondly, the very final scene with the coffee shop - did spoil the overall ending sequence. The entire trilogy has not shrunk away from making bold statements on heroism; the last scene was just unnecessary.

15 August 2012

Movie: Sound of My Voice

It is billed as a psychological thriller, though IMO, the movie misses the mark quite a bit. Similar to the book/movie K-Pax in a way, Sound of My Voice revolves around a documentary filmmaker couple who infiltrate a cult around a woman who claims to be from the future. There is no real proof given on why she should be believed, and the movie sort of devolves into a weird exploration of mysticism. There are some other threads that also take place, but they are not really tied together making the plot even more confusing. In the end, it tries to be interesting, but just fails.

14 August 2012

The Reluctant Fundamentalist

I bought Mohsin Hamid's "A Reluctant Fundamentalist" at the last Exclusive's sale, only because I didn't finish the book while I was "browsing". It is a gripping tale - one of those that you don't want to put down. It is a combination of a great conversational writing style, witty humour and a great plot - of a young Pakistani man, who succeeds in the top echelons of US academia, is highly successful in a competitive financial services but gives it all away as he becomes disillusioned with western politics. It is a highly entertaining read, and at the same time pushes the question on why fundamentalism (of all types) start out in the first place.

13 August 2012

Movie: The Amazing Spiderman

Spiderman gets a reboot, and I suppose it is better than making endless sequels. This reboot has some great things going for it - there is a lot more character building for Peter Parker, the progression from geek to superhero is well paced and better reasoned and the cinematography, especially in the action sequences, is stunning. 

But there are also a number of problems - for one, he keeps on revealing his identity to people. The movie's final action sequence shows a TV camera following him at the beginning - and this camera magically disappears, as he takes his mask off? He has his mask off, in front of a whole crew of policemen; while rescuing a child etc. 

The villain, just doesn't work. Yes, the rationale that he wants to make everyone powerful and strong makes sense altruistically, doesn't make sense as an action that the villain will want to achieve. There are hints of an underlying subplot, but this seems to have been left for another movie. 

Overall, it is a good action movie - but the reboot is not in the same level as the Batman reboot.

Movie: Shame

Last year, Michael Fassbender was nominated at almost every major film award for his acting in Shame. The main character, is an intensely private person who is a sex addict, and the impact in both his personal and professional life. It is an interesting exploration, not only of the addiction itself, but also of why he needs to keep it a secret. It is an "arty" film - beautiful cinematography, lots of long silences with no dialogue, and no real conclusion - and exceptional acting from Michael Fassbender. It's not a movie for everyone, but certainly a though provoking one.

Mogwase

A stone's throw from one of Pilanesberg's gates, and slightly further from Sun City, are probably the only claims to fame for Mogwase. The B & B (Mogwase Guest House) we stayed at was friendly (with a bit of a quirky architecture) and economical - but there isn't much going for the town itself. 

But what was interesting to observe, is the gulf between South Africa's big cities and towns and smaller towns with regards to security. I didn't spot a single electric fence (other than at Pilanesberg), fences were demarcation of property and not prison walls, gates (if present) were welcoming and not foreboding and doors seemed to be kept unlocked. 

Why the difference? I don't know ...

12 August 2012

Oppikoppi: Day 3


The last day promised the most exciting line-up, with some of the top musical acts in the country. Although, we had initially wanted to go fairly early in the day, we decided to go slightly later in the afternoon to make the most of the later acts.


The tribute to a legend in the South African music scene, Vusi Mahlasela, was the first act of the day. He performed a number of his hits (I have heard at his other appearances), together with some amazing guest artists, including Karen Zoid and Albert Frost. It was a great sundowner concert, and highly enjoyable.

I have never heard of "Eagles of Death Metal", but they drew a humongous crowd. It was an energetic performance by the Californian band, though it wasn't exactly death metal. It was good music, though not something that I would go out and buy a CD for (or even download).


Karen Zoid started her show with an apology, to the non Afrikaners, that not all Afrikaners think like Dan Roodt and Steve Hofmeyer. The rousing response from the crowd was a validation of the statement and her general position on the "Afrikaner mentality", from the massive, predominantly Afrikaner crowd. Her show was a mixture of her new songs (all in Afrikaans), some old favorites and an amazing cover of Queen's "The Show Must Go On". It was certainly one of the highlights of the festival, and yet again Karen Zoid nailed a great show.

I didn't spend too much time at Jack Parrow - the little I saw didn't really interest me much; mostly due to the style.


The tipping point in te decision to come to Oppikoppi was to see "Seether", and they didn't disappoint. In front of an absolutely packed stage, they started with the high octane "Gasoline", and finished with the equally high energy "Remedy", and a number of hits in between. The whole crowd singing "Broken" with the band playing the accompanying music was amazing, as were the numerous extended instrumental pieces during the songs. The interaction with the crowd, though minimal compared to some of the other bands was minimal, but felt genuine. The performance was special, and was certainly the highlight of the festival.

The last band of the festival, was British metal band, "Bullet for my Valentine". Although I have heard some of their songs before, I didn't really know their music. Nevertheless, the very high energy show was great, featuring some of the biggest mosh pits I have ever seen. In one of the instrumental solos, the lead guitarist started playing "Nkosi Sikelela Africa", and the amazing thing for me, was the gusto in which the largely white Afrikaner audience sang along; something that underlies the earlier comment made by Karen Zoid. We have truly come far!

Sun City

I have always wondered why Sun City was seen as a holiday destination, but despite driving past a number of times, I have never bothered to find out. So yesterday morning, I went to find out ...

There is a definite theme park vibe, from the gaudy decorations, to the architecture. And while I see the attraction of the Valley of the Waves, the rest of the non hotel areas was rather barren in things to actually do.

As a hotel while going to an evening show, or for a game drive at Pilanesberg, it makes sense; but purely as a holiday destination?

11 August 2012

Oppikoppi: Day 2


Getting to the farm was far quicker, presumably because most people are already there, as evidenced by the general lack of parking space.

The first act we saw was, Jeremy Loops. The main feature was the use of loops, distortions and replays to combine different musical pieces; sort of a DJ with live instruments. It was a very interesting effect, though can't say that I was absolutely awestruck.

Albert Frost brought his blues and rock combo, in front of a packed house. It was an interesting blend of styles, complemented by a number of guest artists. It is easy to understand his popularity and it was a great way to see in the sunset.

BLK JKS came into the fore a few years ago as the all black rock band. When I saw them previously in Cape Town, I was quite unimpressed. Their sound has definitely evolved, a lot more musical but a lot less lyrical. I love the change, though the anthemic lyrics is what draws the crowd to sing a long, and that was mostly missing. That said, their closing song, evoking memories of apartheid protest actions (and now Cosstu strike rallies) was brilliant in both the blend of music and performance.

I didn't stay too long at the very crowded Valiant Swart performance. Country Western doesn't interest me much when in English, and it didn't become more interesting in Afrikaans.


Josie Field's performance at the "Small Stage" was packed, with almost no space to move. She played a number of her folk rock numbers, and it was a pity that this was on such a small stage.

A fairly recent band, Aking has a sizable following in South Africa, as evidenced by the massive crowd. The anthemic numbers however really require the listener to know them; I found it mostly mumbled and unclear - but the crowd around me seemed to be having a ball!


For me, French ska band, Babylon Circus had the best performance of the day. Similar to The Rudimentals in some respects, Babylon Circus combined a number of musical styles and influences into a raucous party. Despite singing mostly in French, they had the whole crowd dancing and even singing along. They had magnificent stage presence, with interesting stage antics (though not as extreme as Knorkator) and wonderful interaction with the crowd.

The wonderfully named, Desmond and the Tutus, were the last band we saw last night. The music was great, as were the lyrics; but the slurry/stoned singing style (or perhaps actual effect) wasn't too endearing. Like Aking, it felt as if one needs to know the songs to actually enjoy their performance.

10 August 2012

Oppikoppi: Day 1


Just a few km outside Northam (about 120km north of Rustenburg), Oppikoppi has become an institution in the South African music scene. Modeled after Glastonbury, Oppikoppi is a multi day, multi stage, multi genre (and South Africa's largest) music festival.

I was first interested in attending, about 10 years ago but being a student with limited resources in Cape Town didn't help. Every year since, I have wanted to come; but never got round to it. This year, it was a bit of a last minute decision, but I decide to take leave and just attend.

M & I are not camping, but rather staying at a B&B in a small town about 40 km away. We arrived last night, but decided to only come through in the late afternoon, and ended up leaving a bit earlier than planned. While, I was aware of the size, but did not expect such a long traffic jam while entering. That said, it is very well organised, though it could do with some sign posting and day visitor's parking is lacking.

Southern Gypsey Queen played pop rock, with a constant revolving door of guest artists, be it musicians from other bands or singers. It was a good collection of songs, though I admit to not knowing any.

The Muffinz, played a combination of reggae/jazz though they didn't seem to have any real lyrics in their songs. Their music was however quote brilliant.

We didn't catch too much of Flash Republic, but they were clearly very popular given the packed stage area. I wasn't sure what to expect, but a live band performing electro dance music wasn't it.

Tidal Waves are promoted as the "hardest working reggae band in the country" in the Oppikoppi program. Their songs were a lot more socially aware, though their little speeches in between probably missed the crowd. Singing in a number of languages (Afrikaans in a Jamaican accent is weird), it was certainly an interesting performance.

Knorkator, was definitely the highlight of the evening. Taking place in one of the smaller stages made the experience more intimate, but a larger venue was probably warranted. A German band, which predominantly sings in German brings its own dynamics; but they amplified this with some brilliant performance art - from their costumes (a man dressed in monk robes, and the lead singer first in a green gimp suit followed by a woman's swimming costume worn in reverse), to the translations, to the crowd interactions - was stunning, and i was glad to be there. The amazing range of the lead singer with an eclectic choice of music (from heavy metal to pop rock to dance) made it the best performance so far. Unfortunately, despite the crowd asking for more, there was no encore :(

Pilanesberg

In my past visit to Pilanesberg, it has usually been in the morning (leaving at an ungodly hour from Jo'burg), so I wasn't expecting to see much on a drive much later in the day. Due to fires, and it being winter, the height of the grass was lower, and it did help, but no predators were spotted.

05 August 2012

Nelson Mandela Capture Monument

50 years ago, Nelson Mandela was captured by the police, about 8km from Howick. It was a significant event; as he would be convicted of treason at the Rivonia trial and the rest is well known.

Yesterday, a monument was unveiled at the spot, with a museum to follow. It is a stunning monument, especially in the still rural environment. It is well worth the detour (about 2km from the freeway); and there is currently no entrance fee; even for parking!

Howick Falls

About 20km outside Pietermaritzburg, it is quite a spectacular sight in a small town. Remarkably, it is not commercialized beyond the obligatory curios and restaurant.

19 July 2012

Physical Access Control

South Africans are very aware of their physical security; and given the high levels of crime it is understandable. Beyond the various mushrooms of security estates, corporate parks and gated communities - the differences in physical access controls have fascinated me for some time.

Most places in South Africa has the sign-in book - where the visitor signs some sort of indemnity and declare the possession of laptops etc. Some corporates also feature x-ray machines and metal detectors, but they are in the minority. For companies that have visitor's slips though; what I always find amusing is that the security guards never check the signature from the host - not that I expect them to, it is after all not that easy to verify signatures.

Microsoft's SA head offices have a system where the record the driver's license (and verify the identity). However, when I enquired with Dr Kganyago (Microsoft SA's Chief Security Advisor), who was quite proud of the solution, on the retention period of the collected data and the implications of the solution for personal privacy, he politely sidestepped the question. It is however a neat solution, and at least does authentication properly through the verification.

At another corporate, visitors are only asked to declare laptops and equipment if it is the same make as their corporate standard. I think that is a nice, more efficient implementation - but then they didn't really check anything on my way out, other than reclaim my visitor's badge - so the effectiveness is quite questionable.

On the residential front, CCTVs and intercoms are more or less the standard. There are a few places with biometric systems, which are just difficult to manage; especially with regards to deletion of entries. Then there are gated communities, where there is a security guard and a boom - and not much is required to pass the boom. Those are probably the most ineffective - though the mere presence of security guards has probably reduced the level of crime.

Overall, South Africa spends a lot on physical security - as evidenced in a recent report on the SA business environment. I still maintain that some of the approaches; such as high walls are actually in detriment to overall security. What is also interesting, is that, some other countries/places with comparatively high levels of crime haven't gone to this extreme (I am thinking, for example of Brazil, where crime levels are high, and yes there are security guards, but hardly any electric fencing etc) and also the opposite; such as India where crime levels are comparatively low but people tend to put burglar bars everywhere. Perhaps it is a subject worthy of further research ...

07 July 2012

The Man behind the SKA Bid

A few weeks ago, South Africa won the majority of the bid to host the Square Kilometer Array (SKA) Radio Telescope; after a process that took close to a decade to complete. The Mail & Guardian has a brilliant profile of Dr Bernie Fanaroff; the lead in the bid project. Like many prominent persons in government posts, he has a very interesting profile - a mixture of struggle credentials and true achievements.

01 July 2012

Movie: The Avengers

I finally got round to seeing the culmination of the Marvel universe movies; and in 2D too (yes, I much prefer 2D)!

As to be expected from superhero movies, reality needs to be left at the door. And so is logical reasoning, even taking account of the assumptions made in the movie seem to be thrown out.

That said, The Avengers script is a lot less nonsensical, and does manage to tie the various other superhero movies together quite nicely. The first two thirds is fairly mundane; but as the main battle begins, so does the very impressive action sequences and very slick story telling. It didn't really need the mundane bits to help it stick; so hopefully future renditions just skip that lot.

12 June 2012

Global Peace Index

The Economist has a short article on the "Global Peace Index". Surveyed across 150+ countries, it tallies up a number of factors including murder rates, assault, war etc. South Africa, as it can be expected with our high crime rates does not score as very peaceful - but it doesn't mean that we are less peaceful than other developing countries; with our rating category being the same as countries like India, Mexico, Kenya and Thailand. It is equally interesting to see what countries are considered to be peaceful - with most of Europe and Canada scoring particularly well.

The full range of factors can be viewed on this interactive site.

09 June 2012

iOS Security

iOS's sandbox approach, and the tight control over the access to the sandbox has meant that iOS has experienced lower number of exploits when compared to other mobile operating systems. But the security design of iOS is far more interesting than just the sandbox and the AppStore. A detailed document on iOS security provides interesting reading on how different data types are handled, including some nifty key management techniques. This is not to say that there are no vulnerabilities in the design; or that the security solution adopted is perfect - but it is good to see how much thought has been put in the design. 
 Another interesting byproduct of the Apple approach of managing the entire ecosystem, is how well the security design covers the end-to-end system - from the hardware, to the OS, to the application sandboxing to the app-store. One can achieve the same with Android, but I believe that it will take a lot more customisation of Android to achieve that - similar to what Amazon has done with the Kindle Fire.

03 June 2012

Stuxnet and Cyberwar

The NYTimes has an incredibly detailed analysis of the development of Stuxnet and the cyberwar by the US and Israel against Iran. From the very early analysis of Stuxnet, it was always suspected that a nation-state was behind Stuxnet - but other analysis did not propose such a full scale operation. With the recent revelation of "Flame", it seems that the cyberwar has been escalated a few notches.

It is interesting that cyberwar, (the ones that are known at least) so far has been largely deployed by larger countries against smaller rivals - rivals that would most likely loose a physical war. There was the Russian attacks against Estonia and Georgia and now this. Stuxnet and Flame however are far more impressive technically - while the other two were mostly DDOS attacks. 

Magnificent Beethoven - JPO's 2nd 2012 Season 4th Concert

I haven't been to the JPO for a number of months, mostly due to time constraints. There are a few Sunday concerts every season at the intimate ZK Matthews Hall at the UNISA campus in Pretoria, which are never full, so it was great for a last minute decision. South African Gerard Korsten was the conductor, with two JPO members, Phillip Coetzee and Vladamir Ivanov (clarinet and viola respectively) the soloists.

The first piece of the afternoon was Schubert's Overture to Rosamunde. The music, part of a series for a play (described in the program as a dismal failure), starts of in a dramatic style remnant of a thriller movie. Halfway through it changes to a more jolly and happy piece, a change which is rather abrupt and a lot less interesting.

Bruch's Concerto for the Viola, Clarinet and Orchestra was unique for a number of years (Google search shows a 2008 composition). The viola and clarinet sound very different, but the piece is very interesting. I particularly liked the 1st and 3rd movements, both of which had strong solo parts that linked to each other - the 2nd movement was rather dull in my opinion.

The highlight of the afternoon, was definitely Beethoven's 7th Symphony. The performance was magnificent, thoroughly deserving the standing applause at the end of the performance. It is a very enjoyable piece, and very apt for a Sunday afternoon.

02 June 2012

Diablo 3

I was first introduced to Diablo in high school. There used to be four or five games that were very popular then, and with regular LAN matches after school - Quake, Age of Empires, Starcraft, Diablo and Red Alert. Of the lot, Diablo had the smallest number of players, and I didn't really play the game - but rather watched. I was hooked on the game in 1st year at UCT though, and played through a number of characters (I completed the game with the Warrior and Mage) shortly before the launch of Diablo 2.

Diablo 2 was an addiction. I have completed all the characters through Normal difficulty, playing the Barbarian and Assassin to Hell difficulty. But eventually it became a grind, and bad choices with character builds early in the game had significant impact on Hell difficulty. But it was fun, and the game offered lots of replayability.

So getting Diablo 3 was a no-brainer; but I left it late and missed out the collector's edition. The regret with missing the collector's edition was the loss of the music CD - Diablo 3 has some glorious backing music; although it is a lot more subtle than in Diablo 2. The graphics and design are impressive, with an amazing level of detail; especially in the level design. The subtle environmental effects (setting of traps etc) are fun to play with - especially in the right circumstances, as they can hurt both the player and the enemies. 

I have so far only completed Normal with the Barbarian (only last night), as it gave me the easiest way to compare the differences in skill set up etc. I miss the ability to wield two large swords at one time; but the change in the skill set up is good. The idea of having set skills, with multiple configurations of those skills is good - and a "higher" configuration is not necessarily better. What I did find however, was that I ended up using a particular set of configuration from about middle of Act 2 onwards. I also missed the ability to quickly change between specific configurations; which actually also contributed to me using a specific set.

And no discussion about Diablo 3 will be complete without the always connected requirement discussion. I completely understand why it is there - it is however a big pain. I only play for an hour or two an evening; and to find that the servers are offline is damn annoying. And lag death is not fun - especially when fighting the big bosses. Last night, I died so many times when trying to defeat Izual, due to lag death; that I almost gave up.

There needs to be a better way to play single player without the network - even if it means that there will be no Auction House, or that signing in is required to start the game (like Starcraft 2). Ultimately, physics dictate that South Africans will always have comparatively high ping times to European servers, and unless Blizzard builds servers in South Africa (highly unlikely), I don't see lag death going away ...

01 June 2012

In line

Just waited 45 minutes at ABSA to collect a new card. There were 6 people ahead of me, 3 people serving the line. Something is broken ...

29 May 2012

Liliesleaf Farm

The tagline, "A Place of Liberation", is both ironic and apt at the same time. It is ironic, because the raid on Liliesleaf Farm on 11 July 1963 directly led to the arrest of a number of key ANC leaders, the Rivonia trial and ultimately incarceration for some of the most prominent liberation leaders including Nelson Mandela and Walter Sisulu. It is apt, because the farm was their hiding place, their command centre and the plans set in motion still propelled South Africa's liberation movement.

It is now an easily accessible museum with a wealth of stories and resources. There is more that story of the struggle against apartheid; there is treachery, smuggling, intrigue and prison escapes. It is a testament to what was endured to get liberation; and a testament to true multi-racial cooperative push against injustice. Speaking with the guide afterwards, her views on the present debacles in the ANC was eye opening especially when she contrasted the events at Liliesleaf to events at Polokwane.



It is not as brilliant a museum as Apartheid Museum, but it is a piece of South African history that shouldn't be forgotten; and well worth visiting.

25 May 2012

Conclusion of the FNB Debacle

After my last post, I sent an email to FNB's Paypal department asking about the progress in resolving the problem. 2 Days later, I got an email stating the technical problems have been resolved, and I should try to recreate the account (for the third time).

That doesn't mean the account was immediately active - first they had to reauthorise for FICA (didn't need to send the document, but still an email asking to be authorised - 1/2 a day), then after linking my account wait another day for that to be authorised.

Interestingly enough, I could draw the funds out of my Paypal account, and the process itself is interesting (basically doing a "payment" to FNB) - will still have to wait for it to appear on my bank account ... but at least it's progress.

I am not converting to FNB though ... and their 10 minute promise is vapourware ...

20 May 2012

FNB's Mythical 10 Minutes

Last November, I bought a great T-Shirt from Teefury, which unfortunately never arrived (the first instance of that happening). Given that it was the Christmas season, and I was then away, I contacted Teefury late in March on the matter, who promptly refunded me. However, it did not refund on my credit card, but on my Paypal account (which I used as the mechanism to pay). A week later, I got an email from Paypal, stating that due to SA regulations, I could not spend that money - but rather, I have to withdraw the money. After a quick email and a phone call from the Paypal service desk; it emerged that Paypal only keeps the credit card transaction for 2 months, and thus the need for this convoluted process.

And this is where FNB comes in - even though I don't need a FNB account, I have to deal with FNB to get my money out of Paypal. FNB has blanketed the airways with their "Steve ads" on how great and innovative FNB is, and there is even one ad that claims that opening up a FNB account will take 10 minutes ... so I expected a rather quick and painless process.

Going to the FNB site, typing in my details did take my less than 10 minutes. Although, their forms are rather stupidly put together. For example, the country code for phone numbers defaults to Afghanistan and not South Africa on Firefox, and they still want a "0" in front of the dialling code ... when putting in a phone number in international format; there is no "0"! I even got an SMS (11 Apr, 20h38) confirming that I am registered. But I could not log on; or reset my password, or register another account - I had no email or further instructions on what I needed to do ... so I was a bit lost. I decided to bother with it another day ...

The another day happened to be Friday afternoon (13 Apr), when I called the call centre. After going through the loops (like giving my ID number twice ... where is the consistency in systems?); I was informed that I needed to "verify" my account for RICA purposes; and that the details would be emailed to me in the next hour (notice, 10 minutes has now long gone). After about 2 hours, when I still had no emails from FNB, I sent them an email through the web contact interface ... (13 Apr, 19h22).

The whole weekend passes (who needs banking over the weekend?) - on Monday morning (16 Apr 09h18), I get an email with a list of things to verify. The most amusing was a scanned copy of a "certified copy of my ID". Has anyone thought through this ... how on earth is this more secure and verifiable than just a standard scanned copy of my ID? Due to various reasons (like being out of office on meetings), I only get round to submitting this on Thursday afternoon (19 Apr, 14h01). The verification takes almost a full day, with a confirmation on Friday (20 Apr, 11h56). I try to log in, but cannot - and promptly reply back stating so (20 Apr, 13h54). Before emailing back, I try all the options - resetting my password and even calling the help desk and then hanging up when I am told that a charge of "R50 will be levied" to reset the password (which I know is correct, and the website doesn't work). Try that for service!

There is no response; so on Monday evening (23 Apr, 17h32) I ask again. On Tuesday, I am asked to try again (24 Apr, 11h08) and an email conversation ensues with screenshots showing errors. Still nothing. Finally, someone calls me on 02 May (yes a whole week later), and asks me to re-register (as they have an apparent problem with their wonderfully innovative system). While I do re-register, I can't actually still log on (02 May, 14h53).

2 days later, I get an email (04 May 11h51), I am told that the problem has be escalated ... I haven't heard from FNB since. In the interim, I have lost all interest - my 30 days to withdraw money from Paypal has long passed (it is coming close to 2 months now). It wasn't a lot of money in either case; so it is not a massive loss ... but it is the principle. And FNB's magical 10 minutes? It takes 24 hours to get verification approved - how the hell do they promise 10 minutes to a functional account for a new customer? Their iPad app, and eBucks for fuel really did tempt me to considering switching; but the customer service has shown it is nothing new. In fact, it has shown that they can't really deliver what they promise.

06 May 2012

Cybercrime Hysteria and the Value of Information

There is a NYTimes article on whether there is too much hype around Cybercrime. The argument, made by the authors centres around the extrapolations and the lack of real data backing up the financial harm suffered due to cybercrime. These arguments are not new - the financial harm apparently caused by piracy has attracted similar criticism before; but that argument has been extended further to cover the entire spectrum of cybercrime.

But there is one argument, that this argument doesn't cover - and that currently there is no established mechanism to valuate information. This is a problem I have posed to a number of people, and have looked at researching in my spare time (though I have not gone very far). If we take the physical world analogy - physical objects have a value. That value can be established by one of two ways - you can look at what was paid for the object (i.e. historical price) or what the market is willing to pay for the object (i.e. market value).

But data does not have value as such. There are certain ways to measure certain types of data; but no generic approach. For example, certain types of information - such as credit card numbers - there is an established black market; thus it is possible to valuate the information of having "credit card data". With the recent valuation of Facebook, it can be easy to argue that "personal information" is worth approximately USD 100; if one takes the simple maths of taking Facebook's market valuation and the core asset of Facebook that is embodied in that valuation. But what is the cost of a word document detailing the business strategy? Or a thesis? Or a drug formula? And how does that translate to the value of the bits and bytes?

That is one of the reasons why information security is hard to sell - is the cost of what you are protecting actually worth what you are paying to protect it? And one can argue (as argued partially in the article); when one considers the cost of PCI-DSS compliance; and the cost of the actual credit card information; PCI-DSS just doesn't seem to be worth it. But there are other costs if one does not comply to PCI-DSS; so the true cost is higher than the credit-card information - but it is still difficult to build the actual business case purely on whether the security was worth it ...

01 May 2012

The 4 Commandments of Cities

A recent TED talk, Eduardo Paes, the mayor of Rio de Janeiro gives a talk on how cities should be evolving to the future. He makes some great points - the need to have us able, efficient public transport; the need to seamlessly incorporate parks and the environment; the need to be socially integrated across the board on city services and the use of technology to make everything more efficient. The idea of a centralised operations centre - similar to that of IT operations centre - is quite interesting and I think does have a lot of potential; but off course it needs real direction and quite a lot of investment to make it work.

What is equally fascinating, are the comments to the talk, from Brazilians. While the talk, complete with a live cross over to the operations centre, is impressive - the Brazilian reaction is actually quite negative. The claims are, that what was shown is mostly fake; the city politicians are corrupt, and the showcases (of public health in favelas etc) are too few to really impact actual lives. I went to Rio over 4 years ago; and the city did not have the efficiencies then - but that doesn't mean it hasn't improved since. After all Gauteng, 4 years ago didn't have a high speed train or a bus transit system. What I liked of the talk is the promise that cities can be better; and cities can be more efficient. The talking points are applicable to all cities - we can argue on the effectiveness of the implementation.

 

29 April 2012

Jeremiah Grossman's "Hack Yourself First"

Jeremiah Grossman's RSA Conference Talk this year was an extended version of his TEDx talk from a few weeks earlier. While his RSA talk is not available on the web (as far as I can see), his TEDx talk is. It is centred around the concept that hacking (or breaking) into your own systems, regularly is going to be one of the most effective means of understanding the system vulnerabilities than relying on defence mechanisms only.

Movie: The Iron Lady

It's easy for me to review The Iron Lady in one word: Unfulfilled. Unlike other recent biopics, such as The Queen or The King's Speech, The Iron Lady, offers a lot of snippets but very rarely the full story. While Margaret Thatcher's character as an uncompromising, principled politician is well portrayed by an excellent performance by Meryl Streep, the interweaving stories are too short and sometimes too abrupt. I found it unfocused, and as a biography too simple.

25 April 2012

Stuck Trolley

Spotted this abandoned trolley on an escalator that was switched off, at Cape Town International Airport. It seems that the escalator stopped working while people were on it, and I get an amusing picture of the chaos caused by the stoppage, especially in trying to offload the trolley!

24 April 2012

Movie: The Hunger Games

Jennifer Lawrence reprises a role similar to her role in Winter Bone - the teenage heroine, overcoming the odds, doing the dirty work when needed, to protect her younger siblings. The Hunger Games though is a much more interesting story, really well constructed, and well paced. And it is the story that makes this movie great - the acting is quite good - but the story is impressive. I am not sure how true it is to the book; but like The Game of Thrones, the screen adaptation has made me want to read the book.

16 April 2012

Brin on the threats of Internet Freedom

The Guardian is running a week long set of reporting on "Battle for the Internet", focusing on a number of different topics. The special feature today is based on an interview with Google co-founder Sergey Brin; where Brin sharply criticises Facebook and Apple for their closed, tightly control ed platforms.

Beyond the arguments on the trade-offs between the model adopted by Apple and Google for their respective platforms, Brin's argument only sheds one part of the story. The easy argument - I don't think Google Plus allows for the export of data to Facebook. But there is a wider argument - the fact is, neither Google (or any of its competitors) offer full management of end-user data - such as controlling what data can be processed for ads, how data can be exported and under what circumstances, deletion of data or how data submitted by users (e.g. names, contact details) are managed and maintained. Some of Google's services are better than others, but it is not a universal trait (e.g. contacts can be exported, emails not that easily, but what about YouTube videos).

Some of the difficulty lies in the underlying architecture itself - to make Google's services what they are, data is widely replicated and distributed; some of it lies in the pure volume of data; and some of it lies with the pure legal bureaucracy of it all (with differing laws etc).

Most of what Brin is asking for, is laudable. I don't think it is practically possible - just see whether Google is doing it ...