<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Bad Penny</title>
	<atom:link href="http://gorrie.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://gorrie.org</link>
	<description>bound to turn up</description>
	<pubDate>Sat, 04 Oct 2008 00:54:38 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
	<language>en</language>
			<item>
		<title>ISSA Puget Sound Sepember meeting</title>
		<link>http://gorrie.org/2008/10/03/issa-sepember/</link>
		<comments>http://gorrie.org/2008/10/03/issa-sepember/#comments</comments>
		<pubDate>Sat, 04 Oct 2008 00:38:37 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
		
		<category><![CDATA[ISSA]]></category>

		<category><![CDATA[Bruce]]></category>

		<category><![CDATA[Lobree]]></category>

		<guid isPermaLink="false">http://gorrie.org/2008/10/03/issa-puget-sound-sepember-meeting/</guid>
		<description><![CDATA[ 
Presentation given to the Puget Sound ISSA in September 2008.

This presentation is not the full story of how to do risk assessments but is the basis or starting point of understanding for those that still use &#8220;Ghosts in the Graveyard&#8221; or FUD (Fear, Uncertainty and Doubt) as their model for convincing management that they [...]]]></description>
			<content:encoded><![CDATA[<p><embed id="VideoPlayback" src="http://video.google.com/googleplayer.swf?docid=-1229013255140099426&#038;hl=en&#038;fs=true" style="width:400px;height:326px" allowFullScreen="true" allowScriptAccess="always" type="application/x-shockwave-flash"> </embed></p>
<p>Presentation given to the <a href="http://www.issa-ps.org">Puget Sound ISSA</a> in September 2008.</p>
<p><span id="more-334"></span></p>
<p>This presentation is not the full story of how to do risk assessments but is the basis or starting point of understanding for those that still use &#8220;Ghosts in the Graveyard&#8221; or FUD (Fear, Uncertainty and Doubt) as their model for convincing management that they need to implement better controls. The intent is to give you the understanding of doing quantitative or monetary risk assessments. It is one thing to preach regulations and requirements as your need for additional controls, but it another thing when you present hard dollar costs and present this as a model similar to the insurance industry. This presentation will also give you a very basic understanding of some of the terminology and tools that you might consider using to achieve your end goal which is convincing your management to spend the money on the controls and tools you need to effectively secure your environment.</p>
<p>Bruce Lobree, CISSP, CISM, CIPP</p>
<p>Mr. Lobree has worked in several industries including Utilities, Financial, Insurance and Software develop and currently works in the Gaming industry. He has worked in many levels of management within organizations from software development, application and network security up to and including executive positions responsible for Security programs for International Corporations. He holds degrees in Mechanical Engineering, Computer Science and Information Systems. He has co-authored books on security including the first CISSP manual and the first CISO manual and has spoken at local and national conferences on various subjects involving IT security and risk management.</p>
<p>Slides are available here:<a href="http://gorrie.org/blog/../uploads/2008/10/business-impact-analysis.ppt"></a></p>
<p><a href="http://gorrie.org/blog/../uploads/2008/10/business-impact-analysis.ppt">business-impact-analysis</a></p>
<p>and his sample Risk Analysis spreadsheet is here:</p>
<p><a href="http://gorrie.org/blog/../uploads/2008/10/blank-ra.xls">blank-ra</a></p>
]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2008/10/03/issa-sepember/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Spore</title>
		<link>http://gorrie.org/2008/09/09/spore/</link>
		<comments>http://gorrie.org/2008/09/09/spore/#comments</comments>
		<pubDate>Wed, 10 Sep 2008 03:34:08 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
		
		<category><![CDATA[Gaming]]></category>

		<category><![CDATA[amazon]]></category>

		<category><![CDATA[authors]]></category>

		<category><![CDATA[drm]]></category>

		<category><![CDATA[Untitled]]></category>

		<guid isPermaLink="false">http://gorrie.org/2008/09/09/spore/</guid>
		<description><![CDATA[It turns out that one of my favorite authors, Walter Jon Williams, wrote the space portion of the game Spore:

&#8220;Spore&#8221; (Electronic Arts)
At the time of my writing this, the Amazon reviews are still abysmal because of the retarded DRM they&#8217;ve put in place.
I&#8217;m sure they&#8217;ll loosen up sometime soon.
In the meantime the reviews are pretty [...]]]></description>
			<content:encoded><![CDATA[<p>It turns out that one of my favorite authors, <a href="http://www.walterjonwilliams.net">Walter Jon Williams</a>, wrote the <a href="http://walterjonwilliams.blogspot.com/2008/09/spore.html">space portion</a> of the game Spore:</p>
<p style="text-align:center"><img src="http://ecx.images-amazon.com/images/I/510CQiYV2bL._SL160_.jpg" /><br />
<a href="http://www.amazon.com/Electronic-Arts-15352-Spore/dp/B000FKBCX4%3FSubscriptionId%3D0PZ7TM66EXQCXFVTMTR2%26tag%3Dbadpen-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3DB000FKBCX4">&#8220;Spore&#8221; (Electronic Arts)</a></p>
<p>At the time of my writing this, the Amazon reviews are still abysmal because of the <a href="http://www.gamespot.com/pages/forums/show_blog_entry.php?topic_id=26385172">retarded DRM</a> they&#8217;ve put in place.</p>
<p>I&#8217;m sure they&#8217;ll loosen up sometime soon.</p>
<p>In the meantime <a href="http://www.amazon.com/review/product/B000FKBCX4/ref=dp_top_cm_cr_acr_txt?_encoding=UTF8&amp;showViewpoints=1">the reviews</a> are pretty hilarious.</p>
<p>
<img src="http://gorrie.org/blog/../uploads/2008/09/firefoxscreensnapz001.jpg" width="421" height="132" alt="FirefoxScreenSnapz001.jpg" /></p>
<p>I should get around to playing it sometime soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2008/09/09/spore/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Wii firmware upgrade and Apple Airport Extreme - unhappy together</title>
		<link>http://gorrie.org/2008/09/09/wii-airport/</link>
		<comments>http://gorrie.org/2008/09/09/wii-airport/#comments</comments>
		<pubDate>Tue, 09 Sep 2008 08:53:05 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
		
		<category><![CDATA[Troubleshooting]]></category>

		<category><![CDATA[airport]]></category>

		<category><![CDATA[wii]]></category>

		<guid isPermaLink="false">http://gorrie.org/2008/09/09/wii-airport/</guid>
		<description><![CDATA[So I hadn&#8217;t given my Wii much love lately, so I turned it on last night to try out the recent Prince of Persia port for a bit. I played for a bit and I turned it off.
Interestingly enough, the normal &#8220;off&#8221; with the Wii, is actually more like &#8220;standby&#8221; and is live on the [...]]]></description>
			<content:encoded><![CDATA[<p>So I hadn&#8217;t given my <a href="http://us.wii.com/">Wii</a> much love lately, so I turned it on last night to try out the recent <a href="http://www.amazon.com/Prince-of-Persia-Rival-Swords/dp/B000KWZ6D4%3FSubscriptionId%3D0PZ7TM66EXQCXFVTMTR2%26tag%3Dbadpen-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3DB000KWZ6D4">Prince of Persia</a> port for a bit. I played for a bit and I turned it off.</p>
<p>Interestingly enough, the normal &#8220;off&#8221; with the Wii, is actually more like &#8220;standby&#8221; and is live on the network, checking for messages, and doing whatever Wiis do. This will be interesting a little later on.</p>
<p>While dorking around with my laptop in the living room doing some of my typical nerd things, I notice that I keep disassociating with my wifi network. There&#8217;s a bunch of competing wifi networks here, so I&#8217;ve become accustomed to a fair amount of fail related to it. Wifi is a convenience, but it was happening so much I thought that someone was using a <a href="http://docs.lucidinteractive.ca/index.php/Cracking_WEP_and_WPA_Wireless_Networks#Deauthentication_Attack">deauthentication attack</a> on my client.</p>
<p>I pulled the logs on my AP and saw this:</p>
<p><img src="http://gorrie.org/blog/wp-content/uploads/2008/09/airport-utilityscreensnapz001.jpg" width="480" height="343" alt="AirPort UtilityScreenSnapz001.jpg" /></p>
<p>Well that looked a little slow for a typical attack. What else was happening?</p>
<p><img src="http://gorrie.org/blog/wp-content/uploads/2008/09/airport-utilityscreensnapz002.jpg" width="480" height="343" alt="AirPort UtilityScreenSnapz002.jpg" /></p>
<p>The key was getting rotated every couple minutes and all the active clients were resetting their connections. What gives? What&#8217;s going on here?</p>
<p><img src="http://gorrie.org/blog/wp-content/uploads/2008/09/airport-utilityscreensnapz003.jpg" width="480" height="343" alt="AirPort UtilityScreenSnapz003.jpg" /></p>
<p>Ok. So I threw laptop in passive mode and snooped on network traffic. So who&#8217;s this guy that&#8217;s flapping it&#8217;s connection every 10 seconds?</p>
<p>
<a href="http://gorrie.org/blog/wp-content/uploads/2008/09/x11screensnapz001.jpg"><img src="http://gorrie.org/blog/wp-content/uploads/2008/09/x11screensnapz001-tm.jpg" width="478" height="262" alt="X11ScreenSnapz001.jpg" /></a></p>
<p>A Nintendo manufacturer MAC prefix? My Wii in suspended mode is breaking my WPA2 network? What the hell?</p>
<p>So apparently the Wii <a href="http://en.wikipedia.org/wiki/UPnP">uPnP</a> requests two <a href="http://en.wikipedia.org/wiki/Transmission_Control_Protocol">TCP</a> and one <a href="http://en.wikipedia.org/wiki/User_Datagram_Protocol">UDP</a> ports on the router repeatedly, while in suspend mode, and the <a href="http://www.amazon.com/Apple-AirPort-Extreme-Station-MB053LL/dp/B000UZCR56%3FSubscriptionId%3D0PZ7TM66EXQCXFVTMTR2%26tag%3Dbadpen-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3DB000UZCR56">Apple Airport Extreme</a> (that&#8217;s an 802.11n AP in mixed g/n mode) freaks out. This is clearly a <em>new feature</em> as I only updated my Wii&#8217;s firmware last week and would have been too annoying for me to miss previously.</p>
<p>In case you were wondering why your Wii was freaking out on your Airport or Airport Extreme network, hopefully you&#8217;ll have been able to find this and can troubleshoot further.</p>
<p>It <em>might</em> be the uPnP support for <a href="http://en.wikipedia.org/wiki/Network_address_translation">NAT</a> <a href="http://en.wikipedia.org/wiki/Port_address_translation">port mapping</a>, but my fix is to turn off the Wii fully when not in use. Hold down the power button until the LED is red instead of orange. I&#8217;m sure more people will complain and one or the other will update their firmware to compensate soon enough.</p>
]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2008/09/09/wii-airport/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The vacation laptop: ASUS EEE PC 901</title>
		<link>http://gorrie.org/2008/08/31/eee-pc-901/</link>
		<comments>http://gorrie.org/2008/08/31/eee-pc-901/#comments</comments>
		<pubDate>Sun, 31 Aug 2008 23:09:58 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
		
		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Technology]]></category>

		<category><![CDATA[asus]]></category>

		<category><![CDATA[eee pc]]></category>

		<category><![CDATA[fedora]]></category>

		<category><![CDATA[ubuntu]]></category>

		<category><![CDATA[xandros]]></category>

		<guid isPermaLink="false">http://gorrie.org/2008/08/31/eee-pc-901/</guid>
		<description><![CDATA[So I went and picked up a 0day piece of hardware. The ASUS EEE PC 901.


Since it&#8217;s so new, it&#8217;s not very well supported. Even the new chipset ethernet drivers (as of the beginning of August &#8216;08) are not yet in the linux kernel, so a simple install is problematic.
If I wanted to hack something [...]]]></description>
			<content:encoded><![CDATA[<p>So I went and picked up a 0day piece of hardware. The <a href="http://eeepc.asus.com/global/901.htm">ASUS EEE PC 901</a>.</p>
<p>
<img src="http://gorrie.org/blog/wp-content/uploads/2008/08/901-a.jpg" width="232" height="216" alt="901-a.jpg" /></p>
<p>Since it&#8217;s so new, it&#8217;s not very well supported. Even the new chipset ethernet drivers (as of the beginning of August &#8216;08) are not yet in the linux kernel, so a simple install is problematic.</p>
<p>If I wanted to hack something all day long, I would likely go with <a href="http://gentoo-wiki.com/Asus_EEE_PC_901">ricer-linux</a>. That&#8217;s not what I want to on a daily basis with a little mobile hackbox.</p>
<p>The default install is a debian variant, and I really distain Debian. Let me not take you to lame distro war forum, so I&#8217;ll just leave it at that. I&#8217;d be happier with a fedora 9 release, but they look like they&#8217;re never going to get it done right.</p>
<p>This leaves me with surprisingly few viable install options, but lots of <a href="http://www.liliputing.com/2008/06/eee-pc-901-is-even-more-hackable-than.html">promising hackability:</a></p>
<blockquote>
<p>There’s an unused PCI-e slot which could be used for a 3G HSDPA card</p>
<p>There’s a space for a SIM card</p>
<p>There’s room for a 1.8 inch hard drive or SS</p>
</blockquote>
<p>First is a <a href="http://www.ubuntu.com/">Ubuntu</a> <a href="http://www.array.org/ubuntu/index.html">EEE variant</a> that supports the idiosyncrasies of the platform. Here&#8217;s the one specifically for the <a href="http://www.array.org/ubuntu/setup901.html">EEE PC 901</a>.</p>
<p>Most of the other linux distributions are broken, poorly supported, or on the slow road to viability. Examples are the <a href="http://en.opensuse.org/OpenSUSE_on_the_EeePC">Suse variant</a>, the <a href="http://wiki.eeeuser.com/howto:eeedora">fedora variant</a>, and <a href="http://eeepc-osx.wikispaces.com/901">901 specific</a> <a href="http://eeepc-osx.wikispaces.com/">hackint0sh builds</a>.</p>
<p>I think a good example of the average user, one who shouldn&#8217;t bother with bleeding edge software, is <a href="http://blog.bangsplatpresents.com/?p=60">here</a>. <a href="http://www.roytanck.com/2008/08/16/asus-eee-pc-901-os-recommendations/">Here&#8217;s another blog posting</a> detailing some available options. Another user experience <a href="http://kunin.wordpress.com/2008/07/05/asus-eee-pc-901/">can be found here</a>.</p>
<p>This should prove to be a good example of what options are available if someone isn&#8217;t served by Windows or the <a href="http://www.xandros.com/">newbie linux distribution</a> that comes installed on the platform when it ships.</p>
<p>So currently, the array.org tweaks to Ubuntu look to be the most usable project available. If you run into me roaming around Seattle, I&#8217;ll be likely to have it with me. By the way, ignore their <a href="https://help.ubuntu.com/community/Installation/FromUSBStick">USB install instructions</a> and use the <a href="http://fedorahosted.org/liveusb-creator">Fedora Project LiveCD Creator</a> to make your USB installation media instead of having the dependancy of another linux system.</p>
]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2008/08/31/eee-pc-901/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Real Estate</title>
		<link>http://gorrie.org/2008/07/28/real-estate/</link>
		<comments>http://gorrie.org/2008/07/28/real-estate/#comments</comments>
		<pubDate>Mon, 28 Jul 2008 12:08:41 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
		
		<category><![CDATA[Business]]></category>

		<category><![CDATA[Economics]]></category>

		<category><![CDATA[housing]]></category>

		<category><![CDATA[real estate]]></category>

		<guid isPermaLink="false">http://gorrie.org/2008/07/28/real-estate/</guid>
		<description><![CDATA[Since I&#8217;m a general know-it-all, and like unlike most people do not have problems managing finances, people ask me about real estate issues a lot.
If they have a decent attention span and live in Seattle, I point them to the Seattle Bubble Blog. It does a great job of debunking a lot of the fluff [...]]]></description>
			<content:encoded><![CDATA[<p>Since I&#8217;m a general know-it-all, and like unlike most people do not have problems managing finances, people ask me about real estate issues a lot.</p>
<p>If they have a decent attention span and live in Seattle, I point them to the <a href="http://seattlebubble.com/blog/">Seattle Bubble Blog</a>. It does a great job of debunking a lot of the fluff that many people with a vested interest in selling something commonly tell prospective clients.</p>
<p>Without talking about market conditions just yet, let me give you my brief outline of why buying real estate might be an ok idea.</p>
<p>First, you the reader, should know that if you live in a nice city, you are likely better off renting. This is a fact unless you live someplace crazy-rural or you make way more money than most. You are better off just saving and investing your money than getting tied up in the never ending cashfest that is home ownership. <a href="http://www.nytimes.com/2007/04/10/business/2007_BUYRENT_GRAPHIC.html?_r=1&amp;oref=slogin">Here</a> is a <a href="http://www.nytimes.com">New York Times</a> calculator to play with that basically proves this if you use it correctly. Give it a try knowing that historical appreciation rates for property is under 5% and for the last two years it has been in negative numbers.</p>
<p>If you&#8217;re one of the few single or combined incomes that could use a large enough deduction from your <a href="http://en.wikipedia.org/wiki/Taxation_in_the_United_States">income taxes</a> and get a little bit of investment from it, lucky you. If you&#8217;re not sure, think about the following:</p>
<ul>
<li>The interest on your mortgage is <a href="http://www.irs.gov/publications/p936/ar02.html#d0e1887">deductible</a></li>
<li>The added property taxes are not</li>
<li>Neither are the costs for upkeep. (Note that repairs are not tax deductible, but improvements to a home are. This is why most people who can afford it add improvements instead of just remodeling.)</li>
</ul>
<p>Basically the money you save by not paying rent needs to be greater than the total amount you pay out in closing costs, taxes, interest, and the amount &#8220;saved&#8221; by not giving it to the taxman. This is not most people. Most people are told that housing is a great investment, so they buy it anyway. This is part of why values of the housing market are falling like a stone right now.</p>
<p>So you&#8217;ve run the numbers. You understand the realities of taxes and financing. You&#8217;re considering that housing is not an investment, but a luxury that may possibly yield a profit in the end if you get lucky. How do you get the best deal? After having personally owned a couple of different residences and been involved in the transactions of several others, I have some suggestion that you may find useful.</p>
<p><strong>1) Ditch your emotions and make the best deal you can.</strong></p>
<p>Most buyers make impulse buys because a kitchen is pretty, the bathrooms have been remodeled, or there is a nice view. Don&#8217;t be that guy. Be critical and see it for what it is. It is a business decision. Make the best deal possible for you. This means buying the most value for the least of your money that you can. The only person with a vested interest in this is you.</p>
<p>Your real estate professional, if you are working with one, is motivated by the sale and the possibility of referral and repeat business. They have other commitments. They only have so much time to give you. Do not make the mistake of thinking that they will find you the best deal. They only want to find you a deal that you are happy with so that they can get paid. Romanticizing ideals past these simple motives does you no good.</p>
<p>Look at a lot of options yourself. Get a sense of what things are worth by yourself. Know how much you are willing to spend and your financial limitations.</p>
<p><strong>2) Get the right tools for the job</strong></p>
<p>If you don&#8217;t know what you&#8217;re doing, you&#8217;ll likely need to work through a full service professional to make sure you don&#8217;t get completely hosed. If you&#8217;re done this dance before, why pay for it? You will understand:</p>
<ol>
<li>The bidding process and what conditions can be put into an offer</li>
<li>Inspection and conditions for sale</li>
<li>Closing details and games people will play with you</li>
<li>What can go wrong</li>
<li>The idiosyncrasies of the area</li>
</ol>
<p>If you can handle these things, think about using a low cost broker or a tool like <a href="http://www.redfin.com">Redfin</a>. The buyer&#8217;s agent commission is usually something like 3% of the value of the property. It can be more of a builder offers incentives because of their greater profit margin they have available to make deals, or less if the seller has stipulated so in the MLS listing. Sellers of moderately priced homes usually offer 3% so that buyers agents will bring prospective buyers to see the property. If the seller was offering 2.5%, the thinking is that they will get less interest because the agent wants their cash. It is perfectly sensible and is one of the many details of the experience that can be misunderstood.</p>
<p>If you use a site like Redfin, they capture about 1% of the deal and issue you a 2% rebate.</p>
<p>So, tools and resources that should be examined include:</p>
<ul>
<li>Brokerage sites such as <a href="http://www.redfin.com">Redfin</a></li>
<li>Appraisal sites such as <a href="http://www.zillow.com/">Zillow</a>, <a href="http://www.eppraisal.com/">Eppraisal</a>, and <a href="http://www.cyberhomes.com/">Cyberhomes</a></li>
<li>Foreclosure information sites if you want to take the added risks involved. These are usually funded by a monthly membership fee.</li>
</ul>
<p><strong>3) Spare no ones feelings</strong></p>
<p>This is not a relationship. You are not dating or paling around with friends. This is a business transaction. Be brutal and fight for your best deal. Make low offers. What you do with your wallet is what a piece of property is worth. It is not your responsibility to fund someone&#8217;s retirement or otherwise give them a fat profit. You have enough to worry about without thinking about the goals on the other side of the table. Big money means that the details count for a lot.</p>
<p><strong>4) The details are gold</strong></p>
<p>Always get an inspection by inspectors that work for you. It is worth the money. Look at the tax records when constructing your deal. Try to know as much as possible as information is your friend.</p>
<p><strong>5) Good luck</strong></p>
<p>When you have done all of your homework and come up with a sound strategy for buying in a particular area, get your pre approval from for financier and start making offers. Finding the best deal on financing is also no simple matter and be aware of how referrals and business relationships may have vested interests.</p>
<p>If I&#8217;ve pointed you to this write-up after you&#8217;ve asked me about &#8220;so what&#8217;s the deal with buying a house,&#8221; let me know if it helped you.</p>
]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2008/07/28/real-estate/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Just what I didn&#8217;t know I needed</title>
		<link>http://gorrie.org/2008/07/25/amazon-text-purchasing/</link>
		<comments>http://gorrie.org/2008/07/25/amazon-text-purchasing/#comments</comments>
		<pubDate>Fri, 25 Jul 2008 11:41:38 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
		
		<category><![CDATA[Business]]></category>

		<category><![CDATA[Gaming]]></category>

		<category><![CDATA[amazon]]></category>

		<category><![CDATA[textbuyit]]></category>

		<guid isPermaLink="false">http://gorrie.org/2008/07/25/amazon-text-purchasing/</guid>
		<description><![CDATA[Because I hate going to a gym in the mornings, I decided I would give Wi Fit a try so that I can supplement my normal training schedule with some extra effective morning mild exercise. I&#8217;ve been checking intermittently to see if Amazon had them, because I really don&#8217;t care enough to go and hunt [...]]]></description>
			<content:encoded><![CDATA[<p>Because I hate going to a gym in the mornings, I decided I would give <a href="http://www.amazon.com/Nintendo-RVLRRFNE-Wii-Fit/dp/B000VJRU44%3FSubscriptionId%3D0PZ7TM66EXQCXFVTMTR2%26tag%3Dbadpen-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3DB000VJRU44">Wi Fit</a> a try so that I can supplement my normal training schedule with some extra effective morning mild exercise. I&#8217;ve been checking intermittently to see if Amazon had them, because I really don&#8217;t care enough to go and hunt a copy down, but would rather it just magically appear in the mail.</p>
<p>Well this time, I saw this:</p>
<p><img src="http://gorrie.org/blog/../uploads/2008/07/textbuyit.jpg" width="480" height="264" alt="textbuyit.jpg" /></p>
<p>I can reply to a text to buy it? Yes please.</p>
<p>Now I can be a Nintendo fanboy without any effort at all. Sweet.</p>
]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2008/07/25/amazon-text-purchasing/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Twitter, Defcon, Geotaging</title>
		<link>http://gorrie.org/2008/07/23/defcon-tweet/</link>
		<comments>http://gorrie.org/2008/07/23/defcon-tweet/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 01:25:59 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
		
		<category><![CDATA[Internet]]></category>

		<category><![CDATA[mobile technology]]></category>

		<category><![CDATA[n95]]></category>

		<category><![CDATA[twibble]]></category>

		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://gorrie.org/2008/07/23/defcon-tweet/</guid>
		<description><![CDATA[So I caved and succumbed to the lameness of Twitter mostly for the purposes of attending and coordinating things at large events. It&#8217;ll be hard to flow of people and places at events like Defcon without it.
Mostly I view twitter as a noise application. It posts &#8220;microblogging,&#8221; a term which people with near zero attention [...]]]></description>
			<content:encoded><![CDATA[<p>So I caved and succumbed to the lameness of <a href="http://twitter.com">Twitter</a> mostly for the purposes of attending and coordinating things at large events. It&#8217;ll be hard to flow of people and places at events like <a href="http://defcon.org/">Defcon</a> without it.</p>
<p>Mostly I view twitter as a noise application. It posts &#8220;<a href="http://en.wikipedia.org/wiki/Micro-blogging">microblogging</a>,&#8221; a term which people with near zero attention spans seem to say a lot, updates everywhere, it uses the @username to respond to things. I view it as the <strong>ALL CAPS</strong> communication medium.</p>
<p>So I&#8217;m not in love, but I will use it via <a href="http://www.twibble.de/twibble-mobile/">Twibble</a> on my <a href="http://www.amazon.com/Nokia-Unlocked-Player-U-S-Version-Warranty/dp/B0014KLFN6%3FSubscriptionId%3D0PZ7TM66EXQCXFVTMTR2%26tag%3Dbadpen-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3DB0014KLFN6">Nokia n95</a> to <a href="http://en.wikipedia.org/wiki/Geotagging">geotag</a> myself and figure out where people I know are having fun when there are a few thousand people milling around.</p>
<p>There will also be flashmob like behavior coordinated by a <a href="http://twitter.com/defcon16">con twitter id</a> during the event itself.</p>
]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2008/07/23/defcon-tweet/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Downtown for Linux</title>
		<link>http://gorrie.org/2008/07/23/gslug-07-12/</link>
		<comments>http://gorrie.org/2008/07/23/gslug-07-12/#comments</comments>
		<pubDate>Wed, 23 Jul 2008 23:05:31 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
		
		<category><![CDATA[Linux]]></category>

		<category><![CDATA[seattle]]></category>

		<category><![CDATA[user group]]></category>

		<guid isPermaLink="false">http://gorrie.org/2008/07/23/gslug-07-12/</guid>
		<description><![CDATA[I had the pleasure of attending one of the GSLUG [Greater Seattle Linux Users Group] on the 12th.
I was really surprised at the quality of the event. Allow me to explain.
I&#8217;m used to these type of occasions being hosted in a filthy classroom or basement of a university or community college and attended by unwashed [...]]]></description>
			<content:encoded><![CDATA[<p>I had the pleasure of attending one of the <a href="http://gslug.org">GSLUG</a> [Greater Seattle Linux Users Group] on the 12th.</p>
<p>I was really surprised at the quality of the event. Allow me to explain.</p>
<p>I&#8217;m used to these type of occasions being hosted in a filthy classroom or basement of a university or community college and attended by unwashed beasts that are fueled entirely by <a href="http://en.wikipedia.org/wiki/High_fructose_corn_syrup">high fructose corn syrup</a> and not really talking about anything of note besides arguing about what distro is better. This has been my past experience.</p>
<p>Thankfully, this was not one of those events.</p>
<p><a href="http://wiki.gslug.org/index.php/Meeting_2008-07-12">This gathering</a> was in a great facility provided by <a href="http://speakeasy.net/">Speakeasy</a>. They even threw down for pizza, salad, fruit and drinks. I&#8217;m in training and had none of it, but I appreciated the gesture.</p>
<p>A couple of the talks were particularly interesting as I haven&#8217;t been a day to day sysadmin for several years. It&#8217;s nice to be able to drop in on things and see some of the recurring problems solved in interesting ways.</p>
<p>First was <a href="http://wiki.gslug.org/index.php/Meeting_2008-07-12#12:35_PM:_Bryan_McLellan_-_Infrastructure_with_puppet.2Ficlassify.2Fcapistrano">a talk</a> by <a href="http://blog.loftninjas.org/">Bryan McLellan</a> about how he runs his infrastructure at <a href="http://www.widemile.com/">Widemile</a>.</p>
<p><a href="http://wiki.gslug.org/index.php/Meeting_2008-07-12#12:45_PM:_John_Locke_-_Git.27ting_your_head_around_git">The second</a> that I found of interest was a demo of <a href="http://git.or.cz/">git</a>, an alternative to code management systems such as <a href="http://subversion.tigris.org/">subversion</a>, by <a href="http://freelock.com">John Locke</a> which showed how the compare, a demonstration of how it functions in routine situations, and a Q&amp;A that focused mainly on what git does well and what subversion does not.</p>
<p>I&#8217;ll make sure to do my best to attend future meetings of this group. They&#8217;re a cool bunch.</p>
]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2008/07/23/gslug-07-12/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The DNS Drama</title>
		<link>http://gorrie.org/2008/07/23/the-dns-drama/</link>
		<comments>http://gorrie.org/2008/07/23/the-dns-drama/#comments</comments>
		<pubDate>Wed, 23 Jul 2008 09:03:31 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
		
		<category><![CDATA[Information Security]]></category>

		<category><![CDATA[Internet]]></category>

		<category><![CDATA[0day]]></category>

		<category><![CDATA[blackops-of-lol]]></category>

		<category><![CDATA[dns]]></category>

		<guid isPermaLink="false">http://gorrie.org/2008/07/23/the-dns-drama/</guid>
		<description><![CDATA[Dan&#8217;s Seattle Toorcon 0day keeps going and going and going and going.
If you&#8217;re looking for details, the details that were leaked, confirmed, retracted, and denied, here&#8217;s a description and a mirror.
So if you run your own DNS, upgrade already as you should have some time ago when you were first told to do so.
Perhaps I [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.doxpara.com/">Dan&#8217;s</a> <a href="http://seattle.toorcon.org/">Seattle Toorcon</a> <a href="http://blogs.zdnet.com/security/?p=1040">0day</a> keeps <a href="http://blog.wired.com/27bstroke6/2008/07/details-of-dns.html">going</a> and <a href="http://blog.invisibledenizen.org/2008/07/kaminskys-dns-issue-accidentally-leaked.html">going</a> and <a href="http://news.cnet.com/8301-1009_3-9996316-83.html">going</a> and <a href="http://www.securityfocus.com/brief/779">going</a>.</p>
<p>If you&#8217;re looking for details, the details that were leaked, confirmed, retracted, and denied, <a href="http://beezari.livejournal.com/141796.html">here&#8217;s a description</a> and <a href="http://thefrozenfire.com/data/dnspoisoning.html">a mirror</a>.</p>
<p>So if you run your own DNS, upgrade already as you should have <a href="http://it.slashdot.org/article.pl?sid=08/07/08/195225&amp;tid=172">some time ago</a> when you were first <a href="http://tech.slashdot.org/tech/08/07/15/0032227.shtml">told to do so</a>.</p>
<p><strike>Perhaps I will switch to <a href="http://www.opendns.com/">OpenDNS</a> after all.</strike> In fact, I should have done this a while ago on most of the nets I deal with routinely.</p>
<p>The commentary in <a href="http://www.doxpara.com/?p=1176#comments">this posting</a> is rather interesting as well. If you don&#8217;t trust OpenDNS, and I can&#8217;t say that I blame you, a comment poses a worthy option:</p>
<ol>
<li>I run a local dns server that randomizes source ports whose network facing NAT does not derandomize source ports.</li>
<li>My local server resolves through the root servers. The queries are sent to a random root.</li>
<li>I limit my dns server to strictly use TCP queries and not to use UDP for queries.</li>
</ol>
<p><strong>Update:</strong></p>
<p>Metasploit code now <a href="http://blogs.zdnet.com/security/?p=1546">jupes entire domains</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2008/07/23/the-dns-drama/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Playstation update: Your ps3 is now a brick</title>
		<link>http://gorrie.org/2008/07/07/ps3brick/</link>
		<comments>http://gorrie.org/2008/07/07/ps3brick/#comments</comments>
		<pubDate>Mon, 07 Jul 2008 10:23:45 +0000</pubDate>
		<dc:creator>Ian Gorrie</dc:creator>
		
		<category><![CDATA[Gaming]]></category>

		<category><![CDATA[playstation]]></category>

		<category><![CDATA[ps3]]></category>

		<category><![CDATA[sony]]></category>

		<guid isPermaLink="false">http://gorrie.org/2008/07/07/ps3brick/</guid>
		<description><![CDATA[I had a gamer friend ask me why I didn&#8217;t have any trophies yet for Super Stardust HD, one of my favorite PS3 games.
I had no idea what she was talking about, so naturally I searched for &#8220;stardust trophies&#8221; and found that the Playstation network has finally added achievements, much like the xbox people have [...]]]></description>
			<content:encoded><![CDATA[<p>I had a gamer friend ask me why I didn&#8217;t have any trophies yet for Super Stardust HD, one of my favorite PS3 games.</p>
<p>I had no idea what she was talking about, so naturally I searched for &#8220;<a href="http://www.scroogle.org/cgi-bin/nbbw.cgi?Gw=Stardust+trophies">stardust trophies</a>&#8221; and found that the Playstation network has finally added achievements, much like the <a href="http://en.wikipedia.org/wiki/Xbox_Live#Xbox_Live_features_.28specific_to_the_Xbox_360.29">xbox people</a> have had for years.</p>
<p>So why hadn&#8217;t I noticed? I had been playing <a href="http://www.amazon.com/Konami-Kojima-Productions-20160-Metal/dp/B000FQ2D5E%3FSubscriptionId%3D0PZ7TM66EXQCXFVTMTR2%26tag%3Dbadpen-20%26linkCode%3Dxm2%26camp%3D2025%26creative%3D165953%26creativeASIN%3DB000FQ2D5E">Metal Gear Solid 4</a> a few times this last week so I should have seen an update. What was going on here?</p>
<p>As it happens, the system update (<a href="http://www.au.playstation.com/support/ps3/faqs/systemupdate240.jhtml;jsessionid=FGIMKM1CSJUBXS3YIXZCFE4LXBC5GIV0">v2.40</a>) enables trophies and the related update to Super Stardust HD had been pulled because of <a href="http://boardsus.playstation.com/playstation/board/message?board.id=ps3&amp;thread.id=3042817">widespread</a> <a href="http://www.computerandvideogames.com/article.php?id=192154">reports</a> of it bricking Playstation 3 consoles.</p>
<p>Amazing.</p>
<p>It <a href="http://boardsus.playstation.com/playstation/board/message?board.id=ps3&amp;thread.id=3075733">is said</a> that v2.41 will be out midweek, but I find it seriously amazing that Sony would release an update that wasn&#8217;t tested enough to know that they would brick tons of consoles. Additionally, issues have been reported across all released hardware profiles, so it&#8217;s a comprehensive bricking update.</p>
<p>Nice work, guys.</p>
]]></content:encoded>
			<wfw:commentRss>http://gorrie.org/2008/07/07/ps3brick/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
