HN user

themenace

131 karma

d,e,n,y @ nym.hush.com (delete the commas)

Posts8
Comments27
View on HN

This has parallels with the secret groundbreaking military technology that "60 Minutes"[1] was talking about in 2008. When you have unlimited capacity to store data and the processing power to tag objects (or people!) in real-time when you play it back, all kinds of new possibilities arise for software or surveillance (good and evil).

My assumption is that the revolutionary advance was military aerial camera systems (such as Angel Fire) that continuously record movement over an entire city in high resolution. When something happens, you can play it backwards to see who drove or walked where, who met whom, find all the connections between people, and trace events to the beginning.

[1] http://www.cbsnews.com/stories/2008/09/04/60minutes/main4415...

Today we can confidently guess that THIS is the secret groundbreaking military technology that "60 Minutes" was alluding to in 2008.

Reporter Bob Woodward (known for breaking much of the Watergate story that led to President Richard Nixon's resignation) claims that the US military has a new secret technique that's revolutionary. The following is what he said in his interview[1] with Scott Pelley on 60 Minutes in September 2008:

Woodward: This is very sensitive and very top secret, but there are secret operational capabilities that have been developed by the military to locate, target, and kill leaders [in Iraq].

Pelley: What is this? Some kind of surveillance, some kind of targeted way of taking out just the ... leadership?

Woodward: It is the stuff of which military novels are written.

Pelley: Do you mean to say that this special capability is such an advance in military technique and technology that it reminds you of the advent of the tank and the airplane?

Woodward: Yeah.

The bits of info from Woodward, the timeline of the development of military aerial camera systems (such as Angel Fire), the claimed capability to locate people -- it all fits. This is the revolutionary advance in military capability they are talking about.

[1] http://www.cbsnews.com/stories/2008/09/04/60minutes/main4415...

Wikipedia has lots of interesting info about South Korea's RRN number:

http://en.wikipedia.org/wiki/Resident_registration_number

Basically it's a 13-digit number with format yymmdd-sbbbbnc consisting of year, month, and day of birth, sex, birth location, a check digit, and single extra digit to differentiate persons who happen to have the same date and place of birth.

The US Social Security Number (SSN) encodes some personal info too, but not to this degree.

The nature of identity numbers--being permanent or very difficult to change--means that you can expect much confidentiality. But the South Korean design has eliminated all possibility of keeping it private. If you know a person fairly well, or they're a public figure, you can deduce the RRN. Conversely, if you get the RRN, you automatically get a lot of personal info.

I'm not seeing the risk if it's a publicly available address. Analogy:

They tested every door lock in America.

They found that 64,000 door locks are trivially opened.

They put up a website where you can enter your home address to see if you're vulnerable.

If you enter your home address ("123 Maple Street"), they could lie and tell you that you're secure, but then go and rob you.

The thing is that they already knew whether 123 Maple Street was secure or not. They could have robbed you beforehand.

(Also, let's say that they never tested 123 Maple Street, and they tell you arbitrarily that you're secure. In this case, they still haven't gained any new knowledge.)

If you want truly unbreakable encryption, there's always the one-time pad. In that case, the unbreakability is guaranteed by mathematics, an even stronger guarantee than physics.

Certainly, the one-time pad suffers from the need of each pair of parties to exchange keys beforehand. As far as I can see, the problem is just as bad for quantum crypto or this thermodynamic crypto because you have to arrange a fiber optic cable, a laser line of sight, or a copper wire between each pair who want to communicate.

You can't use quantum crypto or this thermodynamic crypto on the Internet for example. You need to set up unshared exclusive-use connections between each of the parties.

If you're going to the trouble of doing that, you might just as well exchange some terrabyte disks of one-time pad data, and you'll achieve the same (or greater) guarantee of security.

While this is good science and I enjoy hearing about it, it needs to be said that "unbreakable" encryption is a solved problem.

The existing public key plus symmetric key infrastructure, with a sufficiently long key, achieves "unbreakable" encryption for any practical purpose, including communications that are a matter of life & death and national security.

There are many ways to compromise existing crypto through implementation errors, bugs, or bad key management, but the same caveat would apply to quantum crypto or this new thermodynamic crypto.

The main unsolved practical problem in crypto is getting it built into every form of communication to happen automatically and transparently. And that would happen if people demanded it. So the main problem is a social one: getting people to care about privacy and secrecy enough that they demand it.

I think Kogan has already stopped supporting IE7 because IE7 hangs if you do visit!

To be clear: I wanted to see this amusing "tax notice" first hand, but when I visit kogan.com using Internet Explorer 7.0 with all default settings using a Windows XP/SP3 system, it shows the front page but it then hangs.

The dichotomy is not "nice to have" vs. "must have" -- it is whether the threat is "visible" vs. "invisible" when it concerns privacy and security for consumers.

Phone calls being massively scanned by a national security organization are an invisible threat. Consumers don't worry about it.

But consumers will pay for anti-virus software because it's in their face.

Another great example is personal shredders. I remember a skit, perhaps it was on Saturday Night Live, where the kids had to throw dad's incriminating papers into the "family shredder", portrayed as a ridiculous appliance for a family to own.

In the years since we started to hear a lot about identity theft, and then Fellowes created a billion dollar market for personal shredders. Is a personal shredder a "must have"? No way. The risk is very low, and there are so many better ways for thieves to get ID info in bulk. But ID theft is highly visible; you hear about constantly.

While I agree that it is hard sell for the consumer market, if it should somehow became highly visible (like a wikileaks dump of millions of recorded calls as another person suggested here), then sales could fly out the door.

I remember news from a few years ago in which brokers and analysts at some company discovered that a particular way of sending emails on BlackBerrys prevented the messages from being archived on their company server. They were using this method so much that the company sent around a memo asking that employees refrain from doing it. My point is that there is demonstrated desire among employees to escape the corporate email archive.

Your use-case would work so long as both sides use general-purpose computers. We've made our app work for Windows, and we believe it can be made to work under Mac OS X and Linux.

There's a big problem getting it to work for sandboxed devices like the iPhone because you can't write an app that reads from or writes into another app's GUI.

I agree with you that short demo video would help explain the operation better. As I haven't done this before, can someone recommend an easy-to-use program that can create a video clip of a Windows/XP app and also supports voice-over?

Original author here. My colleagues and I have been kicking this idea around and we built a proof of concept under Windows. I'd like to hear HN comments. Has this been done before? Would you use it? Is there any chance it could be made to work on sandboxed devices like the iPhone?

150 degrees Fahrenheit (65 C) would exceed the highest surface temperature ever recorded on Earth -- by a wide margin. I can't find a good reference at the moment, but I think 150F would be immediately fatal.

I think the infographic is humorously saying that you can find whatever level of excitement you want by taking the underground. Fishing is a boring 5 degrees, football gets you to body temperature, and music halls are a scorching 150.

"How is believing in your product an excuse for not trying to minimise risk. Especially if you know that most startups fail, there's no good reason not to hedge your bets."

Would you agree that this would not be a good answer even if it is the reason?

Some gentler ways to answer:

- Keeping my house gives me a feeling of security so I can devote all time and energy to the startup.

- My heavily mortgaged house is not nearly enough to fund the startup.

- Keeping my house is not unreasonable when I am already investing an enormous amount of my time and energy and my life into this.

- I might indeed sell my house but I don't think I'll need to. I feel that this startup is a great investment, and I think investors will agree.

Anyone got a better response?

The author, Cringely, mentions that he helped write the business plan for Illustrator, Adobe Systems’ first consumer product. But you never get to see the business plans of super successful products -- that's what I'd like to see.

The one exception is "The Autodesk File" by Autodesk founder John Walker:

http://www.fourmilab.ch/autofile/www/autoframe.html

It has the genuine documents from Autodesk's early years including business plans, finances, stock discussions, etc. I'm actually amazed that he did release it.

Magnetic visualizer sprays are also great fun -- assuming that you can still buy any of them. You can actually see the magnetically recorded data on floppies, the magnetic stripe on ATM cards, hotel card keys, driver's licenses, and analog data on audio tapes. In the case of digital data, it will look like bars and blanks. If you know the encoding format, you can visually figure out what's encoded there.

Some commercial products were Magview, Magcheck, Ferro-see, and Sprague-Mag. I don't know if any of these are still available.

The spray is iron powder suspended in a fluid (like trichlorotrifluoroethane) that evaporates rapidly and leaves magnetic particles oriented according to the magnetic field. The pattern can be made permanent by spraying with a fixative or hairspray, or lifted with cellophane tape.

Cleese talks about how multitasking is destructive to the creative process (at time code 6m:30s):

"But if you're racing around all day, ticking things off on lists, looking at your watch, making phone calls, and generally just keeping all the balls in the air, you are not going to have any creative ideas."

I find it hilariously ironic that immediately after he says this, the camera cuts over to two guys in the audience clicking away on their laptops while ostensibly listening to Cleese's talk.

The article creates the impression of information rather than actually providing any. Just look at the bar chart they give:

49% Failed to make connection... but WHY?

21% Loading or off-loading error... but HOW?

16% Ticketing, tagging error... but WHAT error and HOW was it made?

8% Arrival airport mishandling... but HOW and WHY was it mishandled?

6% Restrictions placed by airport... but WHAT restrictions and WHY wasn't it noticed at check-in?

What we need to know the how's and why's.

I'll give my own example of how my airline lost--by my estimate--about 60 bags on a recent flight out of Toronto. I was inside the plane watching the bags being loaded into the hold when a cargo vehicle pulled up with about 100 plastic bins of mail (Canada Post). After those were loaded, the baggage handlers loaded a few more bags and then I could hear one of them yelling and signaling to the other "no more" and "too heavy". To lighten the load, they even took out a couple bags (but not any of the mail).

The vehicle with the remaining 60 bags simply returned to the terminal and our flight left. I got my bag at the destination but a lot of people didn't, and--not surprisingly--they didn't get a true explanation of why their bags didn't arrive.

If we knew the genuine reasons why luggage gets lost, I think we'd find that this is not so much a technology problem.

Not only is it a bad example, it's cheating! The guy in Tokyo didn't know the target personally; he just looked him up in a register. The origin of "Six degrees of separation" presumes that each individual in the chain knows the next link personally.

Here's how the original experiment worked: "The recipient was asked whether he or she personally knew the contact person described in the letter. If so, the person was to forward the letter directly to that person." ( http://en.wikipedia.org/wiki/Small_world_experiment )

[dead] 18 years ago

> The other blunder that Friendster did at the time, was to allow people see who visited your profile. I bet their pageviews dropped overnight.

Would you explain this a bit more please? Why would it be bad to let users see who's visiting them?

Scarcity 18 years ago

Apple's "botched" shortages get it access to the scarcest medium of all: TV news. All of the TV news broadcasts here in Toronto had a big story about the Canadian iPhone launch because long lines with ecstatic and dejected fans are perfect for TV. Using the Internet to form a queue wouldn't get TV coverage because there's nothing visual or emotional to show.

Let me try to explain the idea with a very concrete example (it should be then clear why EC2 would not accomplish the same thing):

Imagine a company called Online-Spreadsheets.com that makes a spreadsheet as a web application.

Suppose a big corporation, Big-Car-Company, would like its employees to use the web app provided Online-Spreadsheets.com, but they can't bring themselves to trust Online-Spreadsheets.com with their financial data.

That's where I come in. My company, say, Trusted-Web-App-Systems, would make a program called TrustEnv. When you run TrustEnv on a server, it creates a trusted environment into which you can install a web app.

I give TrustEnv to Online-Spreadsheets.com for free. Online-Spreadsheets.com installs TrustEnv on one of its servers; a trusted environment is created. They then install their web app into this trusted environment.

Online-Spreadsheets.com cannot easily extract any customer data being processed within this trusted environment, despite the fact that it's running on their own server.

Big-Car-Company can now connect to Online-Spreadsheets.com's server (the one running TrustEnv) and use the spreadsheet web app with assurance that their financial data is not easily copied, leaked, or spied on.

I would charge a fee to corporate customers like Big-Car-Company to use web sites protected with TrustEnv. My job would be to write TrustEnv, to convince corporate customers that they need it, and to convince web app providers to install TrustEnv because there is corporate demand for it. I would not run any web apps myself.