About Me

I ramble about a number of things - but travel experiences, movies and music feature prominently. See my label cloud for a better idea. All comnments and opinions on this blog are my own, and do not in any way reflect the opinions/position of my employer (past/current/future).

19 July 2012

Physical Access Control

South Africans are very aware of their physical security; and given the high levels of crime it is understandable. Beyond the various mushrooms of security estates, corporate parks and gated communities - the differences in physical access controls have fascinated me for some time.

Most places in South Africa has the sign-in book - where the visitor signs some sort of indemnity and declare the possession of laptops etc. Some corporates also feature x-ray machines and metal detectors, but they are in the minority. For companies that have visitor's slips though; what I always find amusing is that the security guards never check the signature from the host - not that I expect them to, it is after all not that easy to verify signatures.

Microsoft's SA head offices have a system where the record the driver's license (and verify the identity). However, when I enquired with Dr Kganyago (Microsoft SA's Chief Security Advisor), who was quite proud of the solution, on the retention period of the collected data and the implications of the solution for personal privacy, he politely sidestepped the question. It is however a neat solution, and at least does authentication properly through the verification.

At another corporate, visitors are only asked to declare laptops and equipment if it is the same make as their corporate standard. I think that is a nice, more efficient implementation - but then they didn't really check anything on my way out, other than reclaim my visitor's badge - so the effectiveness is quite questionable.

On the residential front, CCTVs and intercoms are more or less the standard. There are a few places with biometric systems, which are just difficult to manage; especially with regards to deletion of entries. Then there are gated communities, where there is a security guard and a boom - and not much is required to pass the boom. Those are probably the most ineffective - though the mere presence of security guards has probably reduced the level of crime.

Overall, South Africa spends a lot on physical security - as evidenced in a recent report on the SA business environment. I still maintain that some of the approaches; such as high walls are actually in detriment to overall security. What is also interesting, is that, some other countries/places with comparatively high levels of crime haven't gone to this extreme (I am thinking, for example of Brazil, where crime levels are high, and yes there are security guards, but hardly any electric fencing etc) and also the opposite; such as India where crime levels are comparatively low but people tend to put burglar bars everywhere. Perhaps it is a subject worthy of further research ...

07 July 2012

The Man behind the SKA Bid

A few weeks ago, South Africa won the majority of the bid to host the Square Kilometer Array (SKA) Radio Telescope; after a process that took close to a decade to complete. The Mail & Guardian has a brilliant profile of Dr Bernie Fanaroff; the lead in the bid project. Like many prominent persons in government posts, he has a very interesting profile - a mixture of struggle credentials and true achievements.

01 July 2012

Movie: The Avengers

I finally got round to seeing the culmination of the Marvel universe movies; and in 2D too (yes, I much prefer 2D)!

As to be expected from superhero movies, reality needs to be left at the door. And so is logical reasoning, even taking account of the assumptions made in the movie seem to be thrown out.

That said, The Avengers script is a lot less nonsensical, and does manage to tie the various other superhero movies together quite nicely. The first two thirds is fairly mundane; but as the main battle begins, so does the very impressive action sequences and very slick story telling. It didn't really need the mundane bits to help it stick; so hopefully future renditions just skip that lot.

12 June 2012

Global Peace Index

The Economist has a short article on the "Global Peace Index". Surveyed across 150+ countries, it tallies up a number of factors including murder rates, assault, war etc. South Africa, as it can be expected with our high crime rates does not score as very peaceful - but it doesn't mean that we are less peaceful than other developing countries; with our rating category being the same as countries like India, Mexico, Kenya and Thailand. It is equally interesting to see what countries are considered to be peaceful - with most of Europe and Canada scoring particularly well.

The full range of factors can be viewed on this interactive site.

09 June 2012

iOS Security

iOS's sandbox approach, and the tight control over the access to the sandbox has meant that iOS has experienced lower number of exploits when compared to other mobile operating systems. But the security design of iOS is far more interesting than just the sandbox and the AppStore. A detailed document on iOS security provides interesting reading on how different data types are handled, including some nifty key management techniques. This is not to say that there are no vulnerabilities in the design; or that the security solution adopted is perfect - but it is good to see how much thought has been put in the design. 
 Another interesting byproduct of the Apple approach of managing the entire ecosystem, is how well the security design covers the end-to-end system - from the hardware, to the OS, to the application sandboxing to the app-store. One can achieve the same with Android, but I believe that it will take a lot more customisation of Android to achieve that - similar to what Amazon has done with the Kindle Fire.

03 June 2012

Stuxnet and Cyberwar

The NYTimes has an incredibly detailed analysis of the development of Stuxnet and the cyberwar by the US and Israel against Iran. From the very early analysis of Stuxnet, it was always suspected that a nation-state was behind Stuxnet - but other analysis did not propose such a full scale operation. With the recent revelation of "Flame", it seems that the cyberwar has been escalated a few notches.

It is interesting that cyberwar, (the ones that are known at least) so far has been largely deployed by larger countries against smaller rivals - rivals that would most likely loose a physical war. There was the Russian attacks against Estonia and Georgia and now this. Stuxnet and Flame however are far more impressive technically - while the other two were mostly DDOS attacks. 

Magnificent Beethoven - JPO's 2nd 2012 Season 4th Concert

I haven't been to the JPO for a number of months, mostly due to time constraints. There are a few Sunday concerts every season at the intimate ZK Matthews Hall at the UNISA campus in Pretoria, which are never full, so it was great for a last minute decision. South African Gerard Korsten was the conductor, with two JPO members, Phillip Coetzee and Vladamir Ivanov (clarinet and viola respectively) the soloists.

The first piece of the afternoon was Schubert's Overture to Rosamunde. The music, part of a series for a play (described in the program as a dismal failure), starts of in a dramatic style remnant of a thriller movie. Halfway through it changes to a more jolly and happy piece, a change which is rather abrupt and a lot less interesting.

Bruch's Concerto for the Viola, Clarinet and Orchestra was unique for a number of years (Google search shows a 2008 composition). The viola and clarinet sound very different, but the piece is very interesting. I particularly liked the 1st and 3rd movements, both of which had strong solo parts that linked to each other - the 2nd movement was rather dull in my opinion.

The highlight of the afternoon, was definitely Beethoven's 7th Symphony. The performance was magnificent, thoroughly deserving the standing applause at the end of the performance. It is a very enjoyable piece, and very apt for a Sunday afternoon.

02 June 2012

Diablo 3

I was first introduced to Diablo in high school. There used to be four or five games that were very popular then, and with regular LAN matches after school - Quake, Age of Empires, Starcraft, Diablo and Red Alert. Of the lot, Diablo had the smallest number of players, and I didn't really play the game - but rather watched. I was hooked on the game in 1st year at UCT though, and played through a number of characters (I completed the game with the Warrior and Mage) shortly before the launch of Diablo 2.

Diablo 2 was an addiction. I have completed all the characters through Normal difficulty, playing the Barbarian and Assassin to Hell difficulty. But eventually it became a grind, and bad choices with character builds early in the game had significant impact on Hell difficulty. But it was fun, and the game offered lots of replayability.

So getting Diablo 3 was a no-brainer; but I left it late and missed out the collector's edition. The regret with missing the collector's edition was the loss of the music CD - Diablo 3 has some glorious backing music; although it is a lot more subtle than in Diablo 2. The graphics and design are impressive, with an amazing level of detail; especially in the level design. The subtle environmental effects (setting of traps etc) are fun to play with - especially in the right circumstances, as they can hurt both the player and the enemies. 

I have so far only completed Normal with the Barbarian (only last night), as it gave me the easiest way to compare the differences in skill set up etc. I miss the ability to wield two large swords at one time; but the change in the skill set up is good. The idea of having set skills, with multiple configurations of those skills is good - and a "higher" configuration is not necessarily better. What I did find however, was that I ended up using a particular set of configuration from about middle of Act 2 onwards. I also missed the ability to quickly change between specific configurations; which actually also contributed to me using a specific set.

And no discussion about Diablo 3 will be complete without the always connected requirement discussion. I completely understand why it is there - it is however a big pain. I only play for an hour or two an evening; and to find that the servers are offline is damn annoying. And lag death is not fun - especially when fighting the big bosses. Last night, I died so many times when trying to defeat Izual, due to lag death; that I almost gave up.

There needs to be a better way to play single player without the network - even if it means that there will be no Auction House, or that signing in is required to start the game (like Starcraft 2). Ultimately, physics dictate that South Africans will always have comparatively high ping times to European servers, and unless Blizzard builds servers in South Africa (highly unlikely), I don't see lag death going away ...

01 June 2012

In line

Just waited 45 minutes at ABSA to collect a new card. There were 6 people ahead of me, 3 people serving the line. Something is broken ...

29 May 2012

Liliesleaf Farm

The tagline, "A Place of Liberation", is both ironic and apt at the same time. It is ironic, because the raid on Liliesleaf Farm on 11 July 1963 directly led to the arrest of a number of key ANC leaders, the Rivonia trial and ultimately incarceration for some of the most prominent liberation leaders including Nelson Mandela and Walter Sisulu. It is apt, because the farm was their hiding place, their command centre and the plans set in motion still propelled South Africa's liberation movement.

It is now an easily accessible museum with a wealth of stories and resources. There is more that story of the struggle against apartheid; there is treachery, smuggling, intrigue and prison escapes. It is a testament to what was endured to get liberation; and a testament to true multi-racial cooperative push against injustice. Speaking with the guide afterwards, her views on the present debacles in the ANC was eye opening especially when she contrasted the events at Liliesleaf to events at Polokwane.



It is not as brilliant a museum as Apartheid Museum, but it is a piece of South African history that shouldn't be forgotten; and well worth visiting.

25 May 2012

Conclusion of the FNB Debacle

After my last post, I sent an email to FNB's Paypal department asking about the progress in resolving the problem. 2 Days later, I got an email stating the technical problems have been resolved, and I should try to recreate the account (for the third time).

That doesn't mean the account was immediately active - first they had to reauthorise for FICA (didn't need to send the document, but still an email asking to be authorised - 1/2 a day), then after linking my account wait another day for that to be authorised.

Interestingly enough, I could draw the funds out of my Paypal account, and the process itself is interesting (basically doing a "payment" to FNB) - will still have to wait for it to appear on my bank account ... but at least it's progress.

I am not converting to FNB though ... and their 10 minute promise is vapourware ...

20 May 2012

FNB's Mythical 10 Minutes

Last November, I bought a great T-Shirt from Teefury, which unfortunately never arrived (the first instance of that happening). Given that it was the Christmas season, and I was then away, I contacted Teefury late in March on the matter, who promptly refunded me. However, it did not refund on my credit card, but on my Paypal account (which I used as the mechanism to pay). A week later, I got an email from Paypal, stating that due to SA regulations, I could not spend that money - but rather, I have to withdraw the money. After a quick email and a phone call from the Paypal service desk; it emerged that Paypal only keeps the credit card transaction for 2 months, and thus the need for this convoluted process.

And this is where FNB comes in - even though I don't need a FNB account, I have to deal with FNB to get my money out of Paypal. FNB has blanketed the airways with their "Steve ads" on how great and innovative FNB is, and there is even one ad that claims that opening up a FNB account will take 10 minutes ... so I expected a rather quick and painless process.

Going to the FNB site, typing in my details did take my less than 10 minutes. Although, their forms are rather stupidly put together. For example, the country code for phone numbers defaults to Afghanistan and not South Africa on Firefox, and they still want a "0" in front of the dialling code ... when putting in a phone number in international format; there is no "0"! I even got an SMS (11 Apr, 20h38) confirming that I am registered. But I could not log on; or reset my password, or register another account - I had no email or further instructions on what I needed to do ... so I was a bit lost. I decided to bother with it another day ...

The another day happened to be Friday afternoon (13 Apr), when I called the call centre. After going through the loops (like giving my ID number twice ... where is the consistency in systems?); I was informed that I needed to "verify" my account for RICA purposes; and that the details would be emailed to me in the next hour (notice, 10 minutes has now long gone). After about 2 hours, when I still had no emails from FNB, I sent them an email through the web contact interface ... (13 Apr, 19h22).

The whole weekend passes (who needs banking over the weekend?) - on Monday morning (16 Apr 09h18), I get an email with a list of things to verify. The most amusing was a scanned copy of a "certified copy of my ID". Has anyone thought through this ... how on earth is this more secure and verifiable than just a standard scanned copy of my ID? Due to various reasons (like being out of office on meetings), I only get round to submitting this on Thursday afternoon (19 Apr, 14h01). The verification takes almost a full day, with a confirmation on Friday (20 Apr, 11h56). I try to log in, but cannot - and promptly reply back stating so (20 Apr, 13h54). Before emailing back, I try all the options - resetting my password and even calling the help desk and then hanging up when I am told that a charge of "R50 will be levied" to reset the password (which I know is correct, and the website doesn't work). Try that for service!

There is no response; so on Monday evening (23 Apr, 17h32) I ask again. On Tuesday, I am asked to try again (24 Apr, 11h08) and an email conversation ensues with screenshots showing errors. Still nothing. Finally, someone calls me on 02 May (yes a whole week later), and asks me to re-register (as they have an apparent problem with their wonderfully innovative system). While I do re-register, I can't actually still log on (02 May, 14h53).

2 days later, I get an email (04 May 11h51), I am told that the problem has be escalated ... I haven't heard from FNB since. In the interim, I have lost all interest - my 30 days to withdraw money from Paypal has long passed (it is coming close to 2 months now). It wasn't a lot of money in either case; so it is not a massive loss ... but it is the principle. And FNB's magical 10 minutes? It takes 24 hours to get verification approved - how the hell do they promise 10 minutes to a functional account for a new customer? Their iPad app, and eBucks for fuel really did tempt me to considering switching; but the customer service has shown it is nothing new. In fact, it has shown that they can't really deliver what they promise.

06 May 2012

Cybercrime Hysteria and the Value of Information

There is a NYTimes article on whether there is too much hype around Cybercrime. The argument, made by the authors centres around the extrapolations and the lack of real data backing up the financial harm suffered due to cybercrime. These arguments are not new - the financial harm apparently caused by piracy has attracted similar criticism before; but that argument has been extended further to cover the entire spectrum of cybercrime.

But there is one argument, that this argument doesn't cover - and that currently there is no established mechanism to valuate information. This is a problem I have posed to a number of people, and have looked at researching in my spare time (though I have not gone very far). If we take the physical world analogy - physical objects have a value. That value can be established by one of two ways - you can look at what was paid for the object (i.e. historical price) or what the market is willing to pay for the object (i.e. market value).

But data does not have value as such. There are certain ways to measure certain types of data; but no generic approach. For example, certain types of information - such as credit card numbers - there is an established black market; thus it is possible to valuate the information of having "credit card data". With the recent valuation of Facebook, it can be easy to argue that "personal information" is worth approximately USD 100; if one takes the simple maths of taking Facebook's market valuation and the core asset of Facebook that is embodied in that valuation. But what is the cost of a word document detailing the business strategy? Or a thesis? Or a drug formula? And how does that translate to the value of the bits and bytes?

That is one of the reasons why information security is hard to sell - is the cost of what you are protecting actually worth what you are paying to protect it? And one can argue (as argued partially in the article); when one considers the cost of PCI-DSS compliance; and the cost of the actual credit card information; PCI-DSS just doesn't seem to be worth it. But there are other costs if one does not comply to PCI-DSS; so the true cost is higher than the credit-card information - but it is still difficult to build the actual business case purely on whether the security was worth it ...

01 May 2012

The 4 Commandments of Cities

A recent TED talk, Eduardo Paes, the mayor of Rio de Janeiro gives a talk on how cities should be evolving to the future. He makes some great points - the need to have us able, efficient public transport; the need to seamlessly incorporate parks and the environment; the need to be socially integrated across the board on city services and the use of technology to make everything more efficient. The idea of a centralised operations centre - similar to that of IT operations centre - is quite interesting and I think does have a lot of potential; but off course it needs real direction and quite a lot of investment to make it work.

What is equally fascinating, are the comments to the talk, from Brazilians. While the talk, complete with a live cross over to the operations centre, is impressive - the Brazilian reaction is actually quite negative. The claims are, that what was shown is mostly fake; the city politicians are corrupt, and the showcases (of public health in favelas etc) are too few to really impact actual lives. I went to Rio over 4 years ago; and the city did not have the efficiencies then - but that doesn't mean it hasn't improved since. After all Gauteng, 4 years ago didn't have a high speed train or a bus transit system. What I liked of the talk is the promise that cities can be better; and cities can be more efficient. The talking points are applicable to all cities - we can argue on the effectiveness of the implementation.

 

29 April 2012

Jeremiah Grossman's "Hack Yourself First"

Jeremiah Grossman's RSA Conference Talk this year was an extended version of his TEDx talk from a few weeks earlier. While his RSA talk is not available on the web (as far as I can see), his TEDx talk is. It is centred around the concept that hacking (or breaking) into your own systems, regularly is going to be one of the most effective means of understanding the system vulnerabilities than relying on defence mechanisms only.

Movie: The Iron Lady

It's easy for me to review The Iron Lady in one word: Unfulfilled. Unlike other recent biopics, such as The Queen or The King's Speech, The Iron Lady, offers a lot of snippets but very rarely the full story. While Margaret Thatcher's character as an uncompromising, principled politician is well portrayed by an excellent performance by Meryl Streep, the interweaving stories are too short and sometimes too abrupt. I found it unfocused, and as a biography too simple.

25 April 2012

Stuck Trolley

Spotted this abandoned trolley on an escalator that was switched off, at Cape Town International Airport. It seems that the escalator stopped working while people were on it, and I get an amusing picture of the chaos caused by the stoppage, especially in trying to offload the trolley!

24 April 2012

Movie: The Hunger Games

Jennifer Lawrence reprises a role similar to her role in Winter Bone - the teenage heroine, overcoming the odds, doing the dirty work when needed, to protect her younger siblings. The Hunger Games though is a much more interesting story, really well constructed, and well paced. And it is the story that makes this movie great - the acting is quite good - but the story is impressive. I am not sure how true it is to the book; but like The Game of Thrones, the screen adaptation has made me want to read the book.

16 April 2012

Brin on the threats of Internet Freedom

The Guardian is running a week long set of reporting on "Battle for the Internet", focusing on a number of different topics. The special feature today is based on an interview with Google co-founder Sergey Brin; where Brin sharply criticises Facebook and Apple for their closed, tightly control ed platforms.

Beyond the arguments on the trade-offs between the model adopted by Apple and Google for their respective platforms, Brin's argument only sheds one part of the story. The easy argument - I don't think Google Plus allows for the export of data to Facebook. But there is a wider argument - the fact is, neither Google (or any of its competitors) offer full management of end-user data - such as controlling what data can be processed for ads, how data can be exported and under what circumstances, deletion of data or how data submitted by users (e.g. names, contact details) are managed and maintained. Some of Google's services are better than others, but it is not a universal trait (e.g. contacts can be exported, emails not that easily, but what about YouTube videos).

Some of the difficulty lies in the underlying architecture itself - to make Google's services what they are, data is widely replicated and distributed; some of it lies in the pure volume of data; and some of it lies with the pure legal bureaucracy of it all (with differing laws etc).

Most of what Brin is asking for, is laudable. I don't think it is practically possible - just see whether Google is doing it ...

09 April 2012

The Battle for the Control of the Internet

I came across this great article (via Bruce Schneier's blog) on the battle for regulating the Internet. As the article notes, the Internet was designed to operate without central control; so the very notion of trying to enforce control, 20 odd years after the Internet really took off, is closing the gate after the horse has bolted.

There are a few "battles"; on content, on the underlying infrastructure and off course on snooping and monitoring.

On the content front, this is probably the oldest battle - in the early years (not really focused in the article) there was a lot of focus on unsavory content such as child pornography or bomb manuals. The modern battle is on copyright infringement especially from the large media houses - and this has been very much a loosing battle (so far). This is where SOPA, PIPA etc come in.

Monitoring and snooping, especially in the US, has very much come to the fore post 9-11. Other countries have also jumped into the bandwagon; both democracies like India and autocratic regimes like Saudi Arabia (both examples related to BBM). Technologies that are difficult to snoop on, such as Skype, have attracted numerous academic investigations.

The underlying infrastructure is probably the most politically charged. The Internet was invented in USA, and the underlying control is vested in ICANN, whichm although a non-profit organisation, remains linked to the US government. There has been numerous calls from a number of countries to move ICANN to an international body, such as the ITU. This is one of the main discussion points in the article; but the rationalle on why ITU could be a good move is not really well argued (or well defended by the proposing parties). Other infrastructure propositions such as DNSSEC or IPV6 migration aren't really discussed; although these are mired more in practical issues than political battles.

Ultimately, there are pros and cons for all three "battles" - but ultimately I think a number of these problems will remain intractable. The battle over ICANN will remain politically charged, and not really go anywhere in the near term. Monitoring and snooping has become a lot easier with Facebook and other social media; but at the same time solutions such as Freenet (which has never really taken off) are even easier to implement.

But World War 3? I don't think it's that dire yet.