Skip to content

Category: Uncategorized

Ishkur’s Guide

Ishkur's Guide to Electronic Music v2.0, via MeFi.

Not bad at all! It actually has 2 Congo Natty tracks listed -- even if it gets the name wrong for one of them ;) I'll nitpick, though; the categories around drum and bass, ragga jungle, jungle, and breakbeat are a bit randomly-connected together; they didn't really tie together that way at all IMO. And he randomly decided that hardcore should be renamed 'breakcore', created a new category for all that gabba shite, then called it hardcore. But hey... if you're going to try to make some kind of sense out of it, you have to break some eggs, and never mind -- there's lots of nice samples!

BTW I can't believe he lists Rob Hubbard's theme music to Zoids in the Techno/VGM category. Has someone really released that?

And in passing, I should note, the description for 'Not Trance' under 'Trance' is spot on. As are many of the other recent trance/house-related categories. And, alright, some of the recent d'n'b categories too...

Happy 20th birthday, GNU!

20 years ago tomorrow, on 27th September 1983, the GNU project was announced:

Free Unix!

Starting this Thanksgiving I am going to write a complete Unix-compatible software system called GNU (for Gnu's Not Unix), and give it away free to everyone who can use it. Contributions of time, money, programs and equipment are greatly needed. ......

So that I can continue to use computers without violating my principles, I have decided to put together a sufficient body of free software so that I will be able to get along without any software that is not free.

Thanks to Ciaran O'Riordan for pointing this out!

I Say Risbubh

I keep getting this one, with a question about whether spammers can use it to get past filters:

Aoccdrnig to rceent rsceearch at an Birtsih uinervtisy, it deosn't mttaer in waht oredr the ltteers in a wrod are, the olny iprmoetnt tihng is taht frist and lsat ltteer is at the rghit pclae. The rset can be a toatl mses and you can sitll raed it wouthit porbelm. Tihs is bcuseae we do not raed ervey lteter by it slef but the wrod as a wlohe.

Firstly, it's a crock. That text is incomprehensible! Plus, it's not entirely truthful in its message -- try this variant, which really does make the 'rset' a 'toatl mses':

Aidnroccg to rceent rrceesah at a Biitsrh usvitrneiy ...

Or maybe it's just me who has to spend about 10 times as long trying to comprehend it. (Or maybe my font's too small. whatever...)

Secondly, every 'trick' that results in spammers embedding large up-front blocks of readable text in their mails, scrambling letters around like that, using l33t-sp3ak, i n s e rt i n gs p ac e s, 92384 adding lsdjfgk random foo words to viagra confuse filters, etc. etc. will do nothing but hurt them.

Bear in mind they make money from spam by making sales -- if they have to increasingly obfuscate their message to get through, their would-be 'customers' will not be able to read the messages, their sales will go down, and spamming will become unprofitable.

Remember: if the costs of spamming goes up (through effective filters, increasing complexity to evade detection, and legislation to prosecute them), and the returns go down, the spamming becomes unprofitable and more spammers will give up.

Good news on software patents

Great news from the European Parliament -- the good amendments have been passed and it looks a lot better. James Heald of FFII is quoted as saying 'the directive text as amended by the European Parliament clearly excludes software patents. It hangs together incredibly cohesively.'

Congratulations to our MEPs who grasped the highly technical nuances of the issue, and voted the right way, and to the groups who advised them so well. No congrats to me who went on holidays just before this vote. ;)

Now, all that remains is to ensure that the Council of Ministers also do the right thing; unfortunately FFII note that 'in the past, the Council of Ministers has left patent policy decisions to its patent policy working party, which consists of patent law experts who are also sitting on the administrative council of the European Patent Office (EPO). This group has been one of the most determined promoters of unlimited patentability, including program claims, in Europe.' Not encouraging.

Meta: still catching up and getting through the jetlag...

Back

Back from a great week-and-a-half in Ireland. Lots of fun (and Guinness) was had, Luke and Lean were successfully married, Ireland is officially the most beautiful country in the world, weather was amazing, got to meet up with virtually everyone, and I'm now back at the computer catching up.

Of course, some git has joe-jobbed both myself and a mailing list I'm on, so there's thousands of bounce messages as a result and the server is slow as a wet week. Argh. But at least the SoBig onslaught has died down a bit.

Interestingly, I reported some spam to SpamCop a week or two before the joe-job. I wonder if the two really are connected -- ie. report spam, and the spammers will decode the listwashing tokens from their mails, figure out your email address, and add you to their 'enemies list'?

This is the first time I've reported spam to SpamCop in a long time, and the first joe-job I've been victim of. It seems like more than a coincidence, IMO.

On hols

I'm in Ireland for my friends' wedding for the next week and a half, so blogging will be infrequent. ;)

Ireland or Iraq?

In this article by Salam Pax, about how he got into weblogging, he says:

While the world was moving on to high-speed internet, we were being told it was overrated.

Heh, sounds like an Eircom quote ;)

Leni Riefenstahl, suing 12-year-olds and FFB

Leni Riefenstahl dead at 101 (CNN). Riefenstahl's Triumph of the Will, the 1934 Nazi propaganda film, is rightly famous -- it's technically excellent -- but became a millstone around her neck for the rest of her life. To my mind, this lesson illustrates that an artist (or scientist) can never divorce the work one does from that work's implications to society.

Music: 12-year-old sued for downloading music. ' 'I got really scared. My stomach is all turning,' Brianna said last night at the city Housing Authority apartment where she lives with her mom and her 9-year-old brother.' Way to go, RIAA.

Spam: Paul Graham: a spam filter that fights back. Basically auto-spidering URLs found in spam messages as a form of anti-spam DDoS.

Microtution spam warning

Just received a mail from a bunch called 'microtution', looking to write a collaborative political weblog. More details here.

But hold on there -- this was an out-and-out spam, sent via an open proxy, using a spam tool, with faked headers, to a spamtrap address they scraped from one of my sites. Anyone considering helping out on this collaborative weblog might like to consider who they're helping.

The mail was sent from 213.176.81.230, direct to my MX, from 'Fredericka' <promiseman@promiseman.com>, Subject 'need help with political blog'.

Penguinitis

Good interview with Samba's Tridge. He explains where the penguin mascot came from -- I never knew the linux penguin was in fact a fairy penguin! All those trips bringing visitors to Phillip Island while I was in Melbourne were not wasted then. ;)

Some time later Linus was looking for a mascot for Linux, and apparently the incident at the National Aquarium helped influence him towards choosing a penguin. If you go there now you will see a little plaque commemorating the fateful day when Linus caught 'penguinitis' from one of the fairy penguins in the enclosure (the 6ft one, of course).

ha ha ha ha

ThisIsLondon: 'David Blaine thought he was ready for anything. The US illusionist suspended in a glass box over London had prepared himself for 44 days of starvation, loneliness and boredom.

But there was one thing he had not planned for - Londoners.

... the prize for invention went to golfers who teed up with clubs on Tower Bridge and tried hitting the box with golf balls.'

Back again

So I'm back -- I was up in Sunnyvale last week, on a work trip. Met up with Dan Kohn for the first time, which was great, and also had an impromptu SpamAssassin summit with Craig and Dan Quinlan -- and got to meet the newest arrival in the Hughes family, the very cute Evan Alice.

I was hoping to meet up with a few more people, but didn't quite organise it in the limited time there. Maybe next visit!

ObLAvBayAreaComment: Amazing how much better the drivers are up there, too. ;)

Still averaging about 68 SoBig.F virus mails, at about 100Kb each, for a total of about 7Mb per hour. That means my 'reject' mailbox is at 412 megs since Friday afternoon. Beats Charlie Strosser's figures ;)

It's all getting quietly bitbucketed, but the side-effects are still nasty. Take a look at this, for example; someone at adjv503ry3ec.ab.hsia.telus.net (142.59.69.220) has been spewing SoBig.F's at the FoRK list, using my address, non-stop for weeks. Argh.

Patents: Richard Allen MP tackles the thorny software patents issue. It's great being able to follow his thinking on these lines -- more politicians should consider starting a weblog along these lines. True transparency.

Much better than Arlene McCarthy's railing against 'The Misinformation Campaign ... by the Free Software Alliance', whoever they are... I particularly like this statement from her PR:

If we were to follow the demands of these lobbyists then we would be handing over inventions to US multinationals and getting no return on our R&D investments in the field of computer implemented inventions. This will sound the death knell for our brightest and best European inventors, whilst the US and Japan will demand licence fees from European companies for the use of their patents. Without patent protection there will be no financial incentive for our most creative industries to develop genuine inventions.

... but -- given that (a) software patents cannot currently be enforced in Europe, and (b) that 77% of the (currently-unenforceable) EPO software patents are registered already to non-EU companies, the only way for the US and Japan to 'demand licence fees from European companies for the use of their patents' would be if McCarthy's proposed directive was passed, allowing those patents to be enforced in the EU. Oops -- own goal!

VR: so I don't lose this, Jaron Lanier's 11 reasons why Virtual Reality has not yet become commonplace.

History: Came across the original SpamAssassin pre-release 'try it out' mail:

after quite of while of thinking about it, I've finally rewritten the spam filter I've been using for a while, and released it as free software.

It's called SpamAssassin, and it's a mail filter to identify spam using text analysis. Using its rule base, it uses a wide range of heuristic tests on mail headers and body text to identify spam, which it then tags for later filtering using the user's own mail user-agent application.

Urban Design and Vogon Poetry

via Boing Boing, Stating the bleeding obvious: if you drive instead of walk, you get fat. Well, duh!

But the alternative is, if you walk or cycle instead of drive, you'll get killed. 'American pedestrians are roughly three times more likely to be killed by a passing car than are German pedestrians - and more than six times more likely than Dutch pedestrians. For bicyclists, Americans are twice as likely to be killed as Germans and more than three times as likely as Dutch cyclists.'

However, Irvine has some of the best cycling infrastructure (and weather) I've ever seen -- except nobody uses it, apart from the weekender recreational cyclists.

Can't figure out why -- I guess it's just a cultural thing; everyone drives, and people cycling or walking near some cars seems to give the drivers heart attacks. (Seriously. The other night, a driver honked and slowed to a crawl after spotting myself and Catherine walking along -- on the sidewalk, 10 feet from the roadway. And not making any sudden movements, either.)

As Kasia said, s/Connecticut//:

You can do all sorts of weird things in Connecticut suburbs, from walking your cat on a leash to painting tiger stripes on your car -- but strap a camera to your back and take out the two wheeler for a spin and you're the weirdest thing since the Keebler elves.

The EU Software Patent protest makes Indymedia. interesting intersection!

But I think they could have looked into the translation issues a bit more; 'software patents kill efficient software development' isn't exactly urgent enough ;) Also -- is the idea of the software patents song and mime a sort of 'stop patents through Vogon poetry' thing?

Baghdad Burning scraped RSS, via Sitescooper RSS feeds.

Decent C String APIs

meanwhile, back in C-land...

strlcpy() - a replacement for strcpy() and strncpy(), with some very nice performance figures.

I usually use snprintf() to do this, but even that has differint semantics between platforms which needs workarounds. Plus the perf numbers regarding strlcpy() are nice. Plus it's BSD-licensed. (Found via Linux Weekly News.)

In passing, it's worth noting that strncpy() imposes a pretty hefty performance hit (4x - 10x in tests there), due to a wierd specified behaviour; it NULs out unused parts of the buffer! ouch.

See also MS' strsafe APIs. However, the code for that is available only on Windows, which makes it pretty much useless for most C code I'd be writing, and they note 'performance hits'.

Vendor liability in US spam law proposal

Good presentation by Anne Mitchell, ex-Habeas CEO, now of ISIPP -- 'False Positives: the Baby in the Bathwater' and 'Putting the Responsibility for Spam where it Belongs: The Case for Vendor Liability' (PDF, 317KiB). Note this bit:

  • In June of 2003, ISIPP's Anne Mitchell worked closely with Senator John McCain's office to help develop and draft legislation which would hold vendors liable for advertising in spam.

  • This legislative draft was introduced as an amendment to the Burns-Wyden CAN-SPAM Act, and adopted by committee as part of the bill. Vendor liability is now part of the Burns-Wyden bill.

  • The proposed legislation makes liable any vendor who advertises in spam which violates the general provisions of the law.

  • Exceptions are made if the vendor truly did not know, and could not have been reasonably expected to know, that their information would go out in spam.

That could be interesting.

Time Traveller Spammer caught

Wired: Turn Back the Spam of Time. An article about the time-travel spammer, now fingered as Robert 'Robby' Todino:

The anonymous e-mail offered $5,000 to any vendor capable of promptly delivering a collection of far-fetched gadgets for conducting time travel. Among the mysterious devices sought by the message's author were an 'Acme 5X24 series time transducing capacitor with built-in temporal displacement' and an 'AMD Dimensional Warp Generator module containing the GRC79 induction motor.'

He's genuinely interested, it seems -- but has a few psychological difficulties. (Thanks to Gary Stock for spotting it.)

Brehon Law, Pepys’ rival, and some really bad food

2 history lessons today: Dervala writes about the Brehon Laws of ancient Ireland. Dervala's weblog has become a great source of smart reading material, and is firmly on my daily list.

History: The Electronic Telegraph: Code-breaker reveals a diarist to rival Pepys (via forteana). Not quite as saucy as old Sam, though; he was a Puritan. Shame.

mmm, brains Food: The World's Worst Food, courtesy of Joe McNally via NTK. A bit short of the traditional brain/tongue/tripe dishes however. (Relevant: low grade meat products, urgh.)

SCOvEveryone: Economist interview with Darl McBride of SCO. Interestingly, it notes 'in 1998, Mr McBride himself won what he calls a 'seven-figure settlement' by suing his employer at the time, IKON Office Solutions (who, he says, had breached contract by urging him to move to an office outside Utah).' Nice! However, the SCO management page doesn't mention that, for some reason... (Link)

Date: Fri, 29 Aug 2003 09:45:13 +0100
From: "Martin Adamson" (spam-protected)
To: (spam-protected)
Subject: Code-breaker reveals a diarist to rival Pepys

The Electronic Telegraph: Code-breaker reveals a diarist to rival Pepys

(Filed: 29/08/2003)

A Puritan's journal written in cryptic shorthand to foil the King's men paints a vivid picture of 1600s London, reports Will Bennett

A remarkable million-word account of life in late 17th century England which is as vivid as Samuel Pepys's diary has been transcribed by experts after lying largely forgotten for more than three centuries.

A specialist code-breaker was brought in to crack the shorthand that Roger Morrice, a Puritan minister turned political journalist, used in part of the diary to stop the King's agents reading it.

While Pepys's often hedonistic diary was long regarded as the most detailed record of life in Restoration England, Morrice's more strait-laced Entring Book gathered dust in a little-known British library.

The Entring Book was acquired by Dr Williams's Library in London, which specialises in the history of English Nonconformist churches, in the early 18th century and it remained there until a few years ago.

Then a team of academics based at Cambridge University launched a project to transcribe the diary, which covers the years 1677 to 1691 and presents an entirely different view of late 17th century England from that of Pepys.

Now the transcription has been completed and six volumes of Morrice's well-informed account of a turbulent period during which England was ruled by three different monarchs will be published in 2005.

About 40,000 words of the diary were in code and the team, led by the Cambridge academic Dr Mark Goldie, brought in an expert in 17th century shorthand to reveal for the first time what Morrice had written.

"At that time you could be arrested for sending newsletters and information around the country and so he did not want Charles II's and James II's agents to see what he had written," said Dr Goldie.

The shorthand expert, Dr Frances Henderson, from Oxford, not only cracked the code but discovered the names of some of Morrice's contacts, whose names he had written in cipher to protect their identities.

Then, as now, journalists had government sources, and Dr Henderson found that Morrice got much of his information from a man called Collins, an official at the Privy Council who was prepared to leak information to him.

As a convinced Puritan, Morrice was extremely critical of what he saw as the moral laxity of Restoration England. He described Tunbridge Wells, then a fashionable spa patronised by royalty, as "the most debauched town in the kingdom".

With evident approval, he reported the reaction of Ben Haddi Mor, the Moroccan ambassador to London, when some Englishmen urged the diplomat to "receive a whore into his bed".

"He said to our great rebuke and shame, 'My religion forbids whores, does not yours?'," wrote Morrice. "He said 'that when I come home I shall then be counted a liar in my own country for my master will not believe me that so many ladies came open-faced with bare breasts to see me'."

In the winter of 1683-84 the Thames froze so hard that coaches travelled across the ice, an ox was roasted and bullbaiting and other sports were held on the river's surface.

"The concourse and all manner of debauchery upon the Thames continued upon Lord's day and Monday the 3rd and 4th of this instant," wrote Morrice disapprovingly.

Morrice used one of his sources to get information about the birth of James Stuart, the Catholic heir to James II and later the Old Pretender.

"The child was a large full child in the head and the upper parts but not suitably proportioned in the lower parts," wrote Morris scathingly, appalled by the prospect of another Catholic monarch.

However, just a few months later Prince William of Orange's troops marched into London and installed the Protestant Dutchman as William III.

Morrice wrote that women "shook his soldiers by the hand as they came by and cried, 'Welcome, welcome, God bless you, you came to redeem our religion, laws, liberties and lives' ".

Voight-Kampff and Plugins

an SF free-sheet has applied the one test that really matters to the current SF mayoral candidates:

Is a particular candidate human or an insidious replicant, possessed of physical strength and computational abilities far exceeding our own, but lacking empathy and possibly even bent on our destruction as a species?

It's the Voight-Kampff Test. No, not the band, this one. The results are hilarious:

TW: You're in a desert walking along in the sand when all of the sudden you look down, and you see a tortoise, Tom, it's crawling toward you. You reach down, you flip the tortoise over on its back, Tom. The tortoise lays on its back, its belly baking in the hot sun, beating its legs trying to turn itself over, but it can't, not without your help. But you're not helping. Why is that, Tom?

Tom Ammiano: That's interesting. I don't know. I'm a republican?

(thanks Ben!)

Patents: The W3C has set up a new list to evaluate ways to work around the Eolas patent on plugins, which, after all, are part of the HTML specification.

Good. I never liked plugins anyway, always playing loud music, halting the browser while they start up, or crashing the lot with their buggy spyware code. Good riddance! Now we can get back to the sensible 'helper application in a separate window' paradigm ;)

Download Caps: Pay To Receive Viruses

Many non-US-based broadband systems impose a download cap -- a limit on how much data a customer can download in one month. In some of the Irish ISPs' cases, it's 3Gb of data per month, with hefty per-Mb charges after that.

Well, here's something. I filter my mail for viruses and spam on my server, and divert the viruses off to a side folder. I just checked, and that folder contains 1 gigabyte of virus data, received since SoBig.F started up last week.

Given that most users don't have a colocated server to divert their viruses on, and therefore would have had to download that 1 gigabyte of virus mail before their virus scanner got to take a look -- that's a hefty third of the download cap gone, due to a virus.

I wonder if Eircom, Telstra down under, and the other capping ISPs, will be giving their customers refunds as a result?

(BTW, by contrast, I only received 10 megs of spam.)

McCarthy report withdrawn

Apparently, the McCarthy report -- which would have legalised software patents in Europe -- has been withdrawn from debate for this EuroParl session.

'It's been sent back to the committee stage to be fixed because there was too much contraversy or too many amendments requested. It will go to plenary again after JURI do some more work on it. Possibly september 22nd, probably early October.'

And you thought it couldn’t get crazier

This is absolute insanity. Let's say you're buying a car, and you're checking out what will work out best, between an SUV and a fuel-efficient hybrid, money-wise. Let's check the options:

Unbelievable.

But don't worry -- there'll be plenty of gas to run the SUVs, since the US is checking the possibility of pumping oil from Iraq to Israel. (That's assuming the entire Arab world doesn't turn into a seething pit of 'told you so' hatred as a result, but hey....)

As Yoz says, 'How To Blow Up The Middle East In One Easy Step':

yozlet: They saved the game before they did this, right? Right?

Bilskirnir: Two US senators responsible for MPAA regulation may be up for lucrative $US1.15 million jobs as lobbyists with the same organisation:

'It's obscene for Tauzin and Breaux to be in the running for the MPAA, the fattest media lobbying job in Washington, while advocating in Congress on behalf of companies that control the MPAA,' said Robert McChesney, Professor of Communications at the University of Illinois at Urbana-Champaign. 'It tends to confirm what the vast majority of Americans have suspected - relaxed media ownership rules are an X-rated exercise in power and influence.'

As Nathan points out, an analogue of non-compete agreements, for would-be politicians-turned-lobbyists, would be a good way to deal with this one.

Tech: in more calming news: Dell Patents 'Reboot and See If That Fixes It' Technical Support Process (BBSpot via Craig).

Wow

BBC to create the BBC Creative Archive. This is insanely cool. Danny O'Brien has written a fantastic overview, so read that for more details. But check out this quote:

I believe that we are about to move into a second phase of the digital revolution, a phase which will be more about public than private value; about free, not pay services; about inclusivity, not exclusion.

In particular, it will be about how public money can be combined with new digital technologies to transform everyone's lives.

That's BBC Director General Greg Dyke totally 'getting it'. So cool.

Italy now opt-in-only, SoBig.F phones home

Heads up for all the businesses out there sending mail to European customers -- the EU E-Privacy Directive is now coming into force. Italy is the latest country to implement it; so businesses mailing Italian customers or prospects may wish to make sure that they abide by these rules:

  • Companies may send direct marketing email only to customers and subscribers who have given their prior consent to receiving such, either by subscribing explicitly or by providing their details during a prior transaction, such as a purchase.

  • Forged headers and other means of disguising or concealing the sender's identity is illegal.

  • All messages must bear opt-out details as well.

  • Apparently, in the Italian rendition, senders may also 'collect' addresses but must immediately give the user a clear opportunity to opt-out at that point -- but as far as I know this isn't in the core EU directive.

Similar laws will be coming in all over Europe, so USian senders should really pay attention: opt-in -- it's not just a good idea, it's the law (in Europe at least ;).

Malware: It sounds like SoBig.F is about to call home for new code (scroll down to 'Downloading Functionality'). This is not good. :( Block port 8998/udp.

SoBig.F, the assorted bounce messages from forged SoBig.F mails, the assorted replies from autoresponders and list admin software from forged SoBig.F mails, and (of all things) user complaints about the forged mails (argh! surely they know they're forgeries by now!) are really driving me up the wall. As I check my mail, there's at least 400 of these messages this morning alone.

IP: Lessig lays into USPTO director: 'If Lois Boland said this, then she should be asked to resign.' ... 'That someone who doesn't understand them is at a high level of this government just shows how extreme IP policy in America has become.'

Slammer crashed nuke power plant safety systems for 5 hours

Slammer worm crashed nuclear power plant safety systems for 5 hours (SecurityFocus).

Humour: BBspot: SpamAssassin Unveils New HomeAssassin Product for Unwelcome Visitors.

Aside: I wonder if the team behind NPR's Day to Day program realise how close that name is to the classic Chris Morris/Armando Ianucci UK fake news programme, The Day Today. Hopefully there'll be less sports reports from Alan Partridge on the NPR version...

More SCO: the Vegas show in full

a must-read: Bruce Perens posts and then demolishes the Las Vegas slideshow comprehensively, demonstrating that one of the code snippets SCO showed did in fact date from 1973, not 1979; and the other snippet was a clean-room reimplementation based on the published specification for the Berkeley Packet Filter, and the SCO code most likely came from the BSD-licensed implementation.

That raises two points: 1. the SCO 'pattern-recognition team' need to go back to Google school; 2. why didn't the SCO implementation of the BPF code maintain the legal copyright attribution text it was supposed to include, so they would have noticed this when out 'recognising' 'patterns'?

I'm looking forward to this getting to court eventually...

Open source not welcome – USPTO

USPTO seeks to block WIPO open source meeting.

(WIPO) is not the place for discussions about 'open source' software (...) a senior U.S. official argued on Monday. Reviewing the original mission of the World Intellectual Property Organization (WIPO), said Lois Boland, the U.S. Patent and Trademark Office (PTO) acting director of international relations, it is 'clearly limited to the protection of intellectual property. To have a meeting whose primary objective is to waive or remove those protections seems to go against the mission.'

Boland was referring to a July request by a group of scientists, academics, open-source advocates and others for a meeting at WIPO on 'open and collaborative projects,' including open-source software. The WIPO secretariat initially replied favorably to the idea.

Well, that's a shame. Let's hope WIPO reconsider, because it really would be an interesting idea to have everyone involved talking about this stuff.

Holidays

Did you know that George W has spent more days of his presidency on vacation than any president in recent history, and is currently in the middle of a month-long extravaganza worthy of a French public sector worker?

Don't mind me, I'm just jealous and missing Eurohols. (factoid via the SFGate morning fix)

I am speechless yet again.

Malware: The SOBIG.F deluge continues. No, not the virus itself; the various AV scanners around the world, telling me that some machine on the internet forged a message with my address. Accordingly, here's a set of SpamAssassin rules to catch them; write a procmail rule to detect that in the resulting X-Spam-Status header and divert.

The Irish 419 scam

FROM: UNIVERSAL STAKES LOTTERY, IRELAND. (forwarded by Rick Kleffel on the forteana list)

SCOvEveryone: so SCO showed some 'evidence' of code-copying from SCO to Linux -- problem is, it's code from UNIX v7, written around 1978/79; the code was released in BSD UNIX, rereleased by SCO/Caldera themselves under a BSD license later, and versions appear in textbooks under public domain. In other words, the SCO 'pattern analysis' team who found this 'copied code' didn't realise that this source had been released long ago -- even by their own company, no less. ho hum, good luck prosecuting based on that. next!

Blogs: Malte, one of the SpamAssassin dev team, now has a weblog too -- and with a better translation of the 'W32.Blaster caused the blackout' theory too. ;)

From: "James" (spam-protected)
Date: Mon Aug 18, 2003 4:15:40 AM US/Pacific
To: (spam-protected)
Subject: Congratulation! ( Please acknowledge this mail asap)

FROM: UNIVERSAL STAKES LOTTERY
IRELAND. REF NUMBER: 014/060/532 BATCH NUMBER: 762901-PCD03

Sir/Madam,

We are pleased to inform you of the result of the Lottery Winners International programs held on the 3rd of July, 2003. Your e-mail address attached to ticket number 27522465896-6453 with serial number 3772-554 drew lucky numbers 7-14-18-23-31-45 which consequently won in the 2nd category, you have therefore been approved for a lump sum pay out of 2,000,000 (EUROS ) (TWO MILLION EUROS)

CONGRATULATIONS!!!

For security purpose and clarity, we advise that you keep your winning information confidential until your claims have been processed and your money remitted to you. This is part of our security protocol to avoid double claiming and unwarranted abuse of this program by some participants. All participants were selected through a computer ballot system drawn from over 20,000 companies and 30,000,000 individual email addresses and names from all over the world. This promotional program takes place every year. This lottery was promoted and sponsored by eminent personalities like the Sultan of Brunei. We look forward to your active participation in our next year USD50 million slot. You are requested to contact our clearance office to assist you with the claim and transfer of your winnings fund into your instructed account by acknowledging the receipt of this mail with the email address below.

Email address: (spam-protected)

Note that, all winnings must be claimed not later than one month. After this date all unclaimed funds will be null and void.

Please note in order to avoid unnecessary delays and complications, remember to quote your reference number and batch numbers in all correspondence. Furthermore, should there be any change of address do inform our agent as soon as possible. Congratulations once more and thank you for being part of our promotional program. NOTE: YOU ARE AUTOMATICALLY DISQUALIFIED IF YOU ARE BELOW 18 YEARS OF
AGE.

Sincerely yours,

James Clark.

(Lottery Coordinator)

Top Firebird tip

Mozilla Firebird has this feature that obviously seemed like a good idea, but unfortunately isn't really -- automatic image resizing.

Well, while surfing about looking at the next-gen Bluecurve screenshots, I came across a screenshot with a link to linuxart.com, which had a top tip:

  • type 'about:config'
  • scroll down to browser.automatic_image_resize, double click, change to 'false'

Hey presto!

Monday morning quickies – gifts patented

FFII have discovered that Amazon.com have received a patent from the EPO 'which covers all computerised methods of automatically delivering a gift to a third party'. It seems to cover Amazon's 'One-Click' ordering system, as well.

Wierd: Tiny town to reek of sex. Don't get excited -- it's only moth pheromones. (via Peter Darben on the forteana list.)

Medical slang, including:

  • ATS: Acute Thespian Syndrome
  • Departure lounge -- Geriatric ward
  • DBI: Dirtbag index (calculated by the number of tattoos on the body multiplied by number of recent missing teeth, to estimate days without a bath)
  • NFN: Normal for Norfolk
  • Pumpkin positive: When you shine a penlight into the patient's mouth and his brain is so small his whole head lights up
  • PFO: Pissed, fell over
  • Scepticaemia: What doctors develop with experience

And -- finally! -- an explanation for that ER term:

  • Stat: Immediately, shortened from the Latin statim

Linux: GrokLaw on SCO and Sun's Linux indemnification FUD. Well worth a read -- especially the bit where Mr. GrokLaw finds an old SCO contract that does include indemnification terms. Indemnification, that is, with some pretty serious get-out clauses and stings in the tail.

Weather: Mont Blanc closed due to record heatwave. 'This year, for the first time since its conquest in 1786, the heatwave has made western Europe's highest peak too dangerous to climb. Mont Blanc is closed. The conditions have been so extreme, say glaciologists and climate experts, and the retreat of the Alps' eternal snows and glaciers so pronounced, that the range -- and its multi-billion-pound tourist industry -- may never fully recover.'

Food: Cooking for the Mafia. 'Conrad Gallagher was the highest flier in the gaudy firmament of New Ireland. A Michelin star at the age of 26, and a swank restaurant, called Peacock Alley'. Not too long afterwards, things had not gone so well -- he was in the Brooklyn Detention Centre. Pretty terrifying article -- a US jail is not one of the nicest places in the world...

Spam: The Howard Dean election campaign ran into a wrinkle last week -- and pretty soon was apparently 'joe-jobbed'. This one is going to get interesting, if the Dean campaign follow up, as joe-jobbing an election campaign is in violation of federal election law, and is apparently taken quite seriously.

Reminder: keep an eye on Spamvertized.Org for the latest news in political spam!

NY weblog blackout coverage

The NY weblogs have really come through with incredible street-level views of the blackout. Highlights:

Fantastic reading. It actually sounds like fun to me -- shades of 'no school due to bad weather' days when I was a kid ;)

‘Who Wants to be a Millionaire’ walkthrough

Wow -- this guy won $250,000 on WWTBAM, and blogged it up, in excruciating detail. (His 'Phone a friend' friend also details his experiences, too). It sounds terrifying...

Hacking: Real-life UNIX disaster recovery.

Commuting: Guardian: A Life Inside meets commuter hell. The author of 'A Life Inside' is a convicted felon, undergoing a gradual release from prison; recently he's been permitted to commute to a day job outside the big house.

'I've had a good run, I suppose. More than a year of almost incident-free commuting.' -- until this episode, where one of those space invaders -- the type who is perfectly happy to push you out of the way to make themselves comfortable -- arrives...

I leaned farther away. Soon my back was hurting. Hang on a minute, I thought. I've paid the same as him for this seat. I was entitled to sit up straight. So I did. Back came the elbow. I wasn't budging. And so battle commenced.

A glance at his computer revealed little activity. He was obviously too preoccupied with trying to make me budge. I was determined to resist this blatant act of aggression. I couldn't help thinking it would never happen in prison - not without ensuing combat. I thought about my pal Toby Turner. This laptop lout was lucky he wasn't sitting next to him in his heyday. I could just imagine Toby's reaction to the elbow treatment.

Paying no heed to the mass of silent bystanders, my shaven-headed friend would have been on his feet in a flash. 'Do you know how many fuckin' anger management courses I've done?'

'Er, no,' his startled tormentor would stutter.

'Six fuckers!' Toby would yell, 'and I still ain't passed!'

Flash Mobs hit Ballyhoo

The latest interweb craze, 'Flash Mobs', have hit Ballyhoo, according to The Ballyhoo Examiner:

'There was about 15 of them, and they went around the shop muttering 'carriages' or 'cabbages', I'm not quite sure which' .... Brendan says he himself would be 'game on' to take part in the next one, as long as it isn't in his own employers' this time, or a bank.

Art: Size does matter, Jamaicans decide (Guardian):

Two naked 7ft-high bronze figures - a male and a female - looking skywards on a dome-shaped fountain embossed with Bob Marley's lyrics 'None but ourselves can free our minds'. But according to the statue's critics the artist is too light-skinned, the male figure is too generously endowed, and both are, well, too naked. .... Another writer ridiculed Renaissance sculptors for being not generous enough. 'Just because Europe's classical statues had small penises, ... does not mean Jamaica must follow suit.'

SCOvEveryone: Groklaw forwards an interesting theory: Does SCO Unixware 7.1.3 contain substantial portions of SuSE Linux Enterprise Server 8 -- including the GPL'd device drivers? The author writes:

It is my belief and opinion that SCO has indeed borrowed engineering concepts and methods from their association with UnitedLinux. Many of these new features and the remarkable similarity with SLES 8 did not occur until after they started to participate in UnitedLinux and since these features were available to SuSE customers before SCO's involvement I am inclined to believe that SCO's engineering team has been influenced or tainted by the Linux development process. I cannot say if UnixWare 7.1.3 or SLES 8 share common code; as I said I am not a source licensee. I feel these issues need to be investigated further.

Referrer Spam Again

More referrer spam stuff. As Mark states in the comments here, it seems that the referrer-spamming is using real browsers run by real people -- no bots, no proxies.

The spammers create HTML pages which contain an IMG tag, using one of our pages in the SRC attribute. This causes the user's browser to attempt to download the page -- giving the correct referrer URL -- but it's not particularly visible to the user -- since it's a HTML page, not an image. All they're likely to see is a 'broken image' icon, and more likely the image is hidden anyway using a hidden div or width=0 height=0 attributes.

Anyway, I took a look at the HTML for those sites. Interestingly, all of them use a distinctive HTML style, with a redirecting frame and some Javascript to load the following pop-up ad:

http: //pb. xxxconnex. com/pb.phtml? d=aporndomain.net &sc=EXPN &ip=9999999999 &c=preview

Where 'aporndomain.net' is a porn domain, not necessarily always the same one as you're viewing, and '9999999999' is a 10-digit number. This then loads a frameset containing another random popunder ad from a load of domains. It also throws a few hidden ones into the corner, loads them as pop-unders, loads a javascript timer to open new ones occasionally, etc. etc. etc. As you close 'em, new ones open, and so on. Glad I don't run IE ;)

I would bet these guys, xxxconnex.com -- or one of their customers -- are the ones behind the referrer-spamming as a result. Their WHOIS info states they are:

Admin, Domain  info@webfinity.net
1E Braemar Ave
Unit 19
Kingston 10, WI N/A
JM
876-357-8404

Interestingly, that phone number and address also shows up in ROKSO as well, listed under domain registrations controlled by the 'Dynamic Pipe / Webfinity / Python Video' spam gang, ie. one of the biggest sources of porn spam out there. They're diversifying it seems!

Based on some suggestions on Kasia's weblog, I think I now have a good comeback -- still working on this though.

The Cluetrain List

Chuq van Rospach has a great idea -- instead of a do not spam list, an I am your customer, not your asset, and quit treating me like one list:

Where do-not-spam lists are useful (and ought to be mandatory) are third party sales and rentals. Any time someone buys or rents a list, that list has to be filtered against the do-not-spam list. If you're on it, you fall out of the transfer. that would include any time that information moves from one company to another, the do-not-spam restrictions apply. (ditto, IMHO, for phone and other personal information. I'll go further, actually. I think there ought to be a generic 'do not sell me as an asset' list, preventing transfer of personal information of any kind without permission. Or more correctly, a I am your customer, not your asset, and quit treating me like one list.

Great idea. Really, the resale of contact information for marketing purposes sounds fantastic to marketers -- but as The Story of Nadine demonstrates, it only takes two years for the contact information to be sold (via a chain of increasingly dodgy operators) from DeliverE, a subsidiary of Excite to horse bestiality porn spam.

Involuntary Park at Porton Down

Amazing! Porton Down is the UK's center for research into chemical and biological weapons, and has been since 1916. Not the nicest place you could think of -- by a long shot.

Well, it turns out that the massive no-go buffer zone around Porton Down, existing for 87 years, has preserved 'the largest remaining continuous tract of chalk downland in Britain'. 'The farming revolution of the 20th century, the development, the tourism, have all passed it by.' 'The disrupters are the large-scale inputs of chemicals, the pesticides, herbicides and artificial fertilisers that are the essence of intensive farming. At Porton Down, these have never arrived.'

As a result, it's now an amazing wildlife heritage site. Quite hard to get to see it -- but good to know it's there! Thanks to Bruce Sterling for forwarding this along the Viridian list.

Reminds me of something I heard about Chernobyl -- since the area around it is heavily irradiated, and therefore a no-go area for humans, it's become a de-facto wildlife refuge (even if half of the animal inhabitants are sterile as a result.)

‘International blacklists’ absurdity

OK, this is very stupid.

----- Transcript of session follows -----
... while talking to mail.(elided).com.:
>>> RCPT To:
<<< 591  The mail server you are SENDING FROM is listed on an
international blacklist. Send your questions to
blacklist-admin@(elided).net
554 5.0.0 Service unavailable

The mailserver in question is dogma.slashnull.org, 212.17.35.15. It's never been on a blacklist. However, it does live outside the US -- in Ireland, to be exact.

So it appears (from the wording) that someone is actually filtering their mail feed and blocking all mail from Ireland. Hello!? It's worth noting, in passing, that I strongly doubt that blocking all mail from Ireland (a) reduces your spam load one iota or (b) accomplishes anything apart from pissing off Irish people. Ah well, not my problem...

SCO: In other news, Ben sends on this Pinky and The Brain rendition of the SCO-vs-the-world saga from Nicholas Petreley -- worth a titter. Given that SCO are now sending invoices to Linux users, including charging 32 bucks for embedded developers -- who almost definitely are not using Read-Copy-Update and that kind of absurdly-high-end code -- it's pretty accurate.

Malware: The latest Windows worm, coming to a system near you; make sure ports 135-139, 445 and 593 are blocked, if you really have to run Windows for some reason. The worm's author includes this notable text string: billy gates why do you make this possible ? Stop making money and fix your software!!

Iraq: Amazing postmortem of the Iraq war. Summary: absolutely inept on the Iraqi side. 'The only order I got was to dismantle my airplanes -- the most idiotic order I ever received.'

Monday Morning Quickies

The Dublin Flash Mob. All went off very well, from the sounds of it. However, this picture contains some wierdness -- who the hell is that guy, second from the left, who's stolen my haircut circa 2 years ago?! Those are my sideburns, give 'em back!

(ObSoCalJoke: they tried to organise a flash mob in southern CA, but couldn't find anywhere with a big enough parking lot for all those single-occupant SUVs. Ba-dum-tish!)

Telecoms: The Communications Workers of America union have released some figures on Verizon's profit margins etc. Interesting to note some figures -- like they charge 4 dollars for call waiting, a service which costs them 0.82 of a cent to provide -- that works out at a 48,680% profit margin, which must be nice. In addition, Verizon use 'splitters', which result in a copper pair being unusable for DSL -- just like Eircom do in rural Ireland. Interesting to note that, even after deregulation, LLU and general introduction of competition, the same problems still arise.

Science: BBC: Scientific research put under spotlight. Terrible article from the Beeb, who should know better.

Basically the article pins some of the blame for recent absurd claims of scientific breakthroughs, like the Raelian's claims they cloned a human, on the peer review process.

What they're missing is that, in most cases of these absurd claims, the research had not been peer reviewed -- instead a press release was put out in advance. Peer review remains the most effective way to demolish bad science. However, the news media shows no sign of being willing to sit around and wait for other scientists to analyse the latest claims, before publishing them.

Spam: Salon: Meet The Spam Nazi. More on the bizarre story of the Jewish leader of a Nazi party, who now peddles 'make penis fast' pills.

Politics: Ian 'Freenet' Clarke says he's leaving the US.

Linux: I've given up on blogging the SCO-v-everyone thing, it's getting too absurd. GrokLaw is covering it much better than I could anyway. Plus: You say po-TAY-to, I say po-TAH-to.

Movies: I concur with Waider -- Pirates of the Caribbean is great. Best summer blockbuster in years; Hollywood can still pull off a good big movie now and again (by using young directors it seems). Buckle those swashes! Aarrr!

Long-chain Monomers

PR-otaku -- I've just got to buy Pattern Recognition, it looks amazing.

Just finished Nickled and Dimed: On (Not) Getting By in America, by Barbara Ehrenreich; a great read, although pretty grim. (thanks mum!)

New Favourite Band

Music: I've just stumbled across Ladytron on EMusic a couple of weeks ago, and they've totally taken over my playlist.

They're kind of over-cool electro stuff in the style of Air, but with much more in the way of 80s-style synth noises. Massively over-cool: it seems the name is from a tune from Roxy Music's first album, this interview has them namechecking 'The Andromeda Strain' and 'Logan's Run', and virtually every tune is heavily Kraftwerky.

Still, I'm hooked... one note though: IMO, the first album, 604, is much better than the difficult second. AudioGalaxy seems to have a copy of ' Play Girl' from 604 -- give it a listen.

Recommended tracks: I'm With The Pilots and Discotraxx -- Paco! is worth a listen too, it includes the theme tune to Are You Being Served, believe it or not. ;)

X-ray specs

NYT: What's in Iraq rumor mill?

BAGHDAD As a U.S. soldier peered out of a passing tank, a young engineering student and a retired accountant contemplated one of the more common questions on the streets of Baghdad: Did the soldier's wraparound sunglasses give him X-ray vision?

'With those glasses, he can definitely see through women's clothes,' said the engineering student, Samer Hamid. 'It makes me angry. We are afraid to take our families out on the street.'

Date: Thu, 07 Aug 2003 16:07:41 +0100
From: "Martin Adamson" (spam-protected)
To: (spam-protected)
Subject: What's in Iraq rumor mill? X-ray vision and air-conditioned

vests


> >From the New York Times

What's in Iraq rumor mill? X-ray vision and air-conditioned vests

John Tierney/NYT The New York Times

Thursday, August 7, 2003

BAGHDAD As a U.S. soldier peered out of a passing tank, a young engineering student and a retired accountant contemplated one of the more common questions on the streets of Baghdad: Did the soldier's wraparound sunglasses give him X-ray vision?

"With those glasses, he can definitely see through women's clothes," said the engineering student, Samer Hamid. "It makes me angry. We are afraid to take our families out on the street."

The retired accountant, Hekmet Tinber Hassan, smiled and said it was a baseless rumor, just like the widespread story that Saddam Hussein had been secretly working for America and was now at a CIA safe house. "I do not believe Saddam is in America," Hassan said. "I heard he went to Tel Aviv."

Just as truth is the first casualty of war, urban legends seem to be the first creation of a military occupation, especially when the cultural gap is as wide as it is here. After life under Saddam, people here are accustomed to conspiracy theories and ready to believe the worst about anyone in power.

Of course, Americans have been circulating their own kinds of legends, starting with the fantasies a few months ago that the occupying troops would be peacefully welcomed by a country of grateful flower-waving citizens. There have been more guns than flowers.

In the urban legends flourishing here, the soldiers triumphed thanks to Saddam's treachery and to U.S. technology. The legend about the X-ray sunglasses may have evolved from reports about the soldiers' night-vision goggles, or maybe just from the imposing Terminator image of the soldiers.

Compared with the residents, who cope with the fierce heat by staying in the shade and dressing in light clothes and sandals, the soldiers have the look of robotic aliens as they patrol in the midday sun wearing combat boots, helmets and armored vests.

Some Iraqis say the troops take special pills that keep them cool, but the most common theory is that they have portable air-conditioners - usually said to be inside the vests, but sometimes placed in the helmet or even the underwear.

"There is fluid circulating throughout the underwear," said Hamid, the engineering student. "I am not sure of the exact mechanism, but we all know the Americans have very sophisticated technology."

Aadel Delli, the owner of a food market in central Baghdad, said he did not believe the air-conditioned-uniform stories, which he attributed to popular doubts about Americans' capacity for discomfort. "Most Iraqis thought the American soldiers would be gone by now because they could never stand the summer in Iraq," he said.

Soldiers have tried dispelling the myths about their gear by letting Iraqis touch their vests and try on their glasses, but some legends will not die.

"I let a kid put on my sunglasses, and he was still convinced they had X-ray vision," said Sergeant Stephen Roach, a soldier from Lufkin, Texas "He kept saying to me, 'Turn it on, turn it on."'

When they are not peering through women's clothes, the male soldiers are said to be groping underneath the clothes during searches at checkpoints, supposedly provoking some of the attacks on soldiers. (Never mind the absence of evidence for this theory.)

Other versions of the ugly-American stories have the soldiers drinking beer inside their tanks near mosques. They have been accused in the Arab press of using pages from the Koran for toilet paper and of giving children candy packets containing pornography.

The rumors became so numerous that Al Sabah, a new daily paper run by Iraqis with financial backing from the Coalition Provisional Authority, the U.S.-run administrative organization, printed a supplement debunking them. "It will take awhile for people to reject the conspiracy theories," said its editor, Ismael Zayer. "Under Saddam, people had to depend on rumor because they could not trust the media."

Frustration seems to feed many of the rumors. Why would the builders of smart bombs and X-ray sunglasses take longer to restore power than Saddam did after the 1991 Gulf War? The Americans must be withholding electricity as revenge for the attacks on soldiers.

For all the frustration, there remains some admiration for the occupiers, as seen on teenagers like Zahra Thaer, 13, who was wearing a new pair of wraparound sunglasses. "These are the latest style," she said. Did she believe the soldiers' glasses gave them X-ray vision?

"I am not so sure about their sunglasses," she said. "But I know about the helmet. Inside each helmet is a map showing the soldier the location of every house in Iraq. My friends at school told me about it."

The New York Times

DE Technology’s patent hits Oz

Nathan Cochrane writes in The Age: 'Opponents of a Canadian company's patent to tax online transactions believe they can stop it before it is granted by the Australian patents office.' This is the DE Technologies patent I blogged about before, which they hope to license under some hefty terms; 'annual licence fees of $US10,000 ($A15,324) each, plus 1.5 per cent a transaction and $0.11 cents each time a document, such as an invoice, is generated.'

At FightThePatent.co.nz, they note that the NZ government plans to amend its patent law to make it much harder to file such patents in future. They also link to another Age article which says the patent has already been granted in Oz as of 'February of this year, according to IP Australia'.

An Aussie tech executive called Matthew Tutaki is planning to try and have it quashed. The situation can be followed on FightThePatent.co.nz. Unfortunately, in turn it seems DE Technologies are planning to fight back.

Who buys stuff from spammers?

Good Wired article on the subject:

A security flaw at a website operated by the purveyors of penis-enlargement pills has provided the world with a depressing answer to the question: Who in their right mind would buy something from a spammer? An order log left exposed at one of Amazing Internet Products' websites revealed that, over a four-week period, some 6,000 people responded to e-mail ads and placed orders for the company's Pinacle herbal supplement. Most customers ordered two bottles of the pills at a price of $50 per bottle.

And check this out for bizarre:

An investigation ... last month revealed that Bournival's mentor and business partner is Davis Wolfgang Hawke, a chess expert and former neo-Nazi leader who turned to the spam business in 1999 after it became public that his father was Jewish.

Stone circles

A good day for North Atlantic Skyline; Glebe stone circle, a massive wind farm in Mayo supplying 7% of Ireland's total energy needs, and some photos from the old Marconi station in Clifden. Recommended.

filtering Mailman’s admin queue with SpamAssassin

Several MailMan mailing lists I run have been really painful to admin, due to spam overload combined with Mailman's pretty crappy 'pending messages' admin interface, which goes like this: scroll down to each message, select 'discard' radio button, scroll to next, select 'discard' radio button, repeat until wrists hurt.

Thankfully, waider has saved my lists from oblivion. this script, given the list URL and the admin password, will log in to the admin interface, get the list of pending messages in the queue, scan each one using Mail::SpamAssassin (of course ;), and ditch the spam.

It just cleaned out 182 spams from one list, leaving all of 7 valid requests in the queue. Beautiful!

Dublin: Stefan Geens posts an IrishBroadband success story. See, it really works!

SCO suggestion

Derek has an interesting suggestion for IBM:

Grab a controlling interest, tell the senior management to sod off, tell the employees to clear out their cubicles, and clear up any hint of IP confusion by selling to IBM for $1 all intellectual property, and then dissolve the corporation entirely with their 50.1% voting share.

IBM has to be careful not to actually buy the company, but strictly be a majority shareholder, making decisions that are in the majority of the shareholders' interests, even if the other 49.9% of the shareholders vehemently oppose them. :-)

Golden parachutes for senior execs? Good luck getting them from that non-existent corporation, and since IBM never actually 'bought' the corporation, it's not liable for any contracts/debts/etc. SCO may have incurred. It gets all the benefit of running SCO and none of the downside.

Gotta say, I like it. ;)

Drop bears and Subgenii

The fearsome Drop Bear is detailed in this forwarded snippet from the forteana list.:

Drop bears are often mistaken for koalas, and to all but a trained naturalist, the differences are minor. They have even been reported to imitate the sleepy demeanor of their genetic cousins, probably as a sort of behavioural camouflage, and roughly one third of all drop bear related fatalities occur when a well-meaning tourist tries to pose with one for a souvenir photograph.

More here. Thankfully I managed to avoid these creatures while camping through Victoria last year -- only just about though.

In other news: a great SFWeekly feature on Hal Robins, aka. Dr. Howland Owll of the CotSG.

Date: Wed, 06 Aug 2003 07:42:52 +1000
From: Peter Darben (spam-protected)
To: Forteana List (spam-protected)
Subject: The secret is finally out

While ploughing through the rapidly growing pile of Dungeon/Polyhedron magzines on my desk I found this little gem

----- (for the d20 Modern Gaming System from Dungeon/Polyhedron June, 2003)

Drop Bear

Although the Australian government officially denies the drop bear's existence, these bloodthirsty relatives of the peaceful koala are the bane of Australia's parks and forests. Named for their preferred of attack - hurtling down from the shelter of trees onto the heads of unsuspecting prey

  • drop bears are responsible for dozens of deaths each year, and the number

climbs with each passing year.

Drop bears are often mistaken for koalas, and to all but a trained naturalist, the differences are minor. They have even been reported to imitate the sleepy demeanor of their genetic cousins, probably as a sort of behavioural camouflage, and roughly one third of all drop bear related fatalities occur when a well-meaning tourist tries to pose with one for a souvenir photograph.

The internal government conspiracy to disavow the existence of drop bears relates to Australia's recent tourism marketing. They certainly can't sell visitors on the idea of coming to Australia if the visitors knew they were going to be savaged by vicious wild animals masquerading at cuddly koalas. Though the Australians themselves are aware that certain chemical repellents such as Aeroguard are effective in discouraging drop bear attacks, forestry service rangers are forbidden by law from explaining exactly why they so heartily recommend it. But as the drop bears' natural food source, rabbits, are gradually reduced in population, it is only a matter of time before the drop bears turn to more plentiful prey : man.

[nerdish gaming stats omitted]

-----

peter

SCO, etc., etc. (fwd)

Someday, Ben will set us up the blog, and there will be much rejoicing. In the meantime, I can only quote this one in full, as he hits it on the head:

OK, I know you find this the most boring thing ever and would prefer to find new ways of air-conditioning your chipsets, but, come on! The human drama is nigh Shakespearean.

This guy is pretty good:

http://radio.weblogs.com/0120124/

But, really, RHAT's filing stands alone. It's a thing of beauty, as 27-page legal filings go. They give them both barrels; failing business, FUD, insider stock dumping ...

http://lwn.net/images/ns/rh-complaint.pdf

ben

Trustic is down

Trustic: 'We regret to inform you that we are no longer taking registrations and will soon be closing the service. We have determined that the system as it currently is designed will not achieve the level of accuracy that we require, and an inaccurate system is worse than no system.'

'The DNS blocklist will remain for a couple of weeks, but it has been configured to never return a match. Please reconfigure your mail servers to not query the blocklist.'

That's a shame...

P2P and open proxies

Joe St. Sauver's excellent presentation on open proxies has been updated. Interesting snippet: Morpheus 3.2 -- the filesharing app -- is shipping with proxy support. P2P Networks Try to Throw RIAA Off Their Trail (AtNewYork.com):

Morpheus will offer its users the option of connecting to its network via a public proxy server (define). A proxy server acts as an intermediary between two Internet users so that one user does not know the identity of the other. Morpheus won't be hosting the proxy servers but will instead direct users to a 'worldwide network' of public proxies.

iMesh apparently may also include this support, too, in an upcoming version.

press! and a whole load of quickies

Wired: Finding Bad Spam Delights Geeks:

When freelance Web developer Joe Stump first installed the e-mail filtering program SpamAssassin, he and a friend started a competition. Each day, the two would look through their junk e-mail and try to find the missive that SpamAssassin had assigned the highest score.

'It was always a little contest between the two of us,' says Stump. 'We were always trying to tweak and modify the settings to get it just right. I finally won the contest when I got a spam with a score of 43.'

The points system has really been popular -- as Joe Stump says -- 'geeks love numbers'. Screengrabs of the SpamAssassin website on Sky News, ABC, and now this! (thanks to Tim Schutte for the pointer.)

Linux: Wonder what the Ximian guys are blogging about? Ha ha, very funny.

Mark Pilgrim: How to install Windows in 5 hours or less.

Tim O'Reilly on parallels between OSS and the mainframe days. 'We so often trace our antecedents back simply to the Unix heritage, or the Lisp hacker heritage. But when I've talked to IBM old-timers, they make clear just how many of the social dynamics and collaborative software development paradigms of the early mainframe era resemble the open source tradition.' Interesting...

Humour: Chris recently set us up the blog -- and kicks it off with this SCO 419 parody: 'I AM MR. DARL MCBRIDE CURRENTLY SERVING AS THE PRESIDENT AND CHIEF EXECUTIVE OFFICER OF THE SCO GROUP, FORMERLY KNOWN AS CALDERA SYSTEMS INTERNATIONAL, IN LINDON, UTAH, UNITED STATES OF AMERICA. I KNOW THIS LETTER MIGHT SURPRISE YOUR BECAUSE WE HAVE HAD NO PREVIOUS COMMUNICATIONS OR BUSINESS DEALINGS BEFORE NOW.' On the roll!

C64 demos

ah, Donncha reminisces about the Commodore 64 demo scene.

I was involved too, around 1987, coding demos as 'Mantis' for XS -- a pretty little known group. I wrote 2 really great demos, Rhaphanadosis, and another name I can't quite remember ;), but they don't seemed to have survived, which is a shame...

Excellent hoaxing lads

So it seems that P45.net were behind some classic hoaxes in the Irish media recently, including the Monaghan-Iraq story:

The New York Monaghan Association has issued a strong statement of support for the US military campaign against Iraq. This is despite being unable to carry their usual banner in the New York St Patricks Day Parade because of similarities between an outline map of Monaghan and Iraq.

Busaras comes clean, and Daev kindly remembers to provide 1 page that links to 'em all ;)

Techie tip: cooling Athlon XP CPUs

so Athlon XP CPUs run pretty hot at full speed all the time, and my PC makes lots of noise as a result. I have a temperature-sensitive CPU fan, so reducing the CPU temp will reduce noise, too.

A while back, I came across this doc, the Athlon Powersaving HOWTO, which contains a great tip -- namely a way to put the processor in 'STPGNT Mode' (Stop Grant Mode), which disconnects it from the FSB and turns off parts of the CPU when not in use.

It works perfectly, in most respects, although the Ensoniq 5880 onboard sound chip goes crazy when it's active, as it can't deal with the changed timings from the CPU. But when I'm playing music, I can't hear the fans anyway ;)

The details -- to keep it brief, just take a look at the commands for my chipset as described here. I'm using ACPI in the kernel anyway, since I'm using software suspend-to-disk as well.

Lessons from history

I've been reading Crooked Timber recently; a good literate weblog. Today's interesting post, from Kieran Healy: Frustration is not a Strategy. Well worth a read for some context on today's Middle East, and the fundamental problem with those 'kill 'em all' proposals that keep cropping up from the hawks.

Blogs: Nathan Cochrane, Aussie journalist for The Age and writer of a very interesting weblog -- has won quite a lot of money on a TV gameshow! I think the term is 'goodonyamate', if I recall correctly ;)

(Pity he couldn't have fixed the BlogShares listing first though.)

Clueless spam quotes and free transport

NYT: Diverging Estimates of the Costs of Spam. The article points out how the analyst company estimates of the cost of spam widely diverge. That's reasonable -- in fact, that's analysts for you. Some great data in there, too.

But then we get to this glorious quote:

Peter S. Fader, a marketing professor at the Wharton School who has studied e-mail, says the research firms' estimates vastly overstate the actual cost of spam. ... He also argues that the computers and networks that are being installed to deal with spam will be a powerful resource for processing legitimate e-mail, once spam filters and economic Darwinism tame the spam epidemic.

'Spam, although it is a bad thing per se, is fostering the growth of the e-mail infrastructure,' he said.

Yeah -- in the same way that arson 'fosters the growth' of the firefighting infrastructure. Wow.

Ireland: I've just heard about the 'no fares' day of protest by CIE's unions. It seems the unions, rather than closing up shop for the day as would be traditional, decided to take a much more consumer-friendly approach; instead of shutting down the normal public transport services, they ran them for free. Genius.

RTE reported that 'tens of thousands of people' travelled for free, and Iarnrod Eireann said that 'there has been a notable rise in passenger numbers on some inter-city trains to Dublin as people take advantage of free travel.' Now that's an effective way to strike...

Referrer spam not via proxies

So a little more investigation shows that the massive numbers of IPs spamming my referrer logs (like 1000 different IPs every day), are not open proxies as I at first thought; I tested 130, and none had any of the well-known proxy ports open.

My current guess is that they're malware, such as those 'ad banner spyware' programs, and the makers of that software must be doing deals with spam companies to set up the spyware to periodically load URLs in order to referrer-spam for the spam bureau's customers.

In this case, all the spammed URLs are owned and registered by one porn operation, which is either operating from Switzerland (according to the tech contact info) or Los Angeles (according to the DNS info in whois). (More likely the latter.)

All the IPs doing the spam page loads, are running on Windows XP and Windows 2000 systems as far as I can see, with ports 1025 and 5000 open, so alternatively, maybe they're trojaned... but there doesn't seem to be any good evidence indicating that. (those ports are reasonably innocuous.)

Anyone got any ideas? Here's some sample access_log lines for 100 IPs, gzipped, if anyone wants to check them out.

open proxy referrer spam again

Googlebot using open proxies? Somehow, I doubt it. An interesting snippet from the access logs again. (Some details rewritten to avoid boosting PageRank.)

220.73.165.14 - - [25/Jul/2003:04:42:14 +0100] "GET /someurl/foo HTTP/1.0" 2147483647 0 "http://www dot gay-sex-men dot net/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
220.73.165.14 - - [25/Jul/2003:09:04:17 +0100] "GET /someurl/foo HTTP/1.0" 2147483647 0 "http://www dot gay-sex-men dot net/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
220.73.165.14 - - [25/Jul/2003:09:15:28 +0100] "GET /someurl/foo HTTP/1.0" 2147483647 0 "http://www dot baitbus dot ws/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
220.73.165.14 - - [25/Jul/2003:09:18:11 +0100] "GET /robots.txt HTTP/1.0" 200 130 "-" "GoogleBot"
220.73.165.14 - - [25/Jul/2003:09:27:57 +0100] "GET /someurl/foo HTTP/1.0" 2147483647 0 "http://www dot blowjobs-cumshots dot net/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
220.73.165.14 - - [25/Jul/2003:13:18:04 +0100] "GET /someurl/foo HTTP/1.0" 2147483647 0 "http://www dot hot-legs dot info/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Win 9x 4.90)"

Some Fortean snippets

Some excellent 'oddly enough' stories:

  • Giant dog-eating catfish dies: a story mourning the death of Kuno, a 5-foot-long catfish living in the lake at Volksgarten Park in Moenchengladbach, Germany. It's presumed he died due to a local heatwave and the resulting low water level. 'Kuno became a local celebrity in 2001 when he sprang from the waters of the lake to swallow a Dachshund puppy whole.' I had a run-in with giant catfish before; mind you, a bit nearer to their natural habitat, and with less pet ingestion involved.

    Catfish are in the news it seems; this NYT editorial is relevant, if a bit depressing. 'The next time a ... delegation sets off to preach the dogma of free trade abroad, poor nations would be within their rights to thumb their noses.'

  • Yahoo! India: Holding severed head in place, he defied death: van driver has road accident, then: 'His head almost severed, blood oozing and eyes popping out, Balram was in a dazed state when the accident took place... He, however, kept his head attached to his body with some cloth. When no one came to help him, he drove his own vehicle for 30 km to reach a nursing home in Agra.' Now that's grit!

  • More sex than splendour on academy's Aztec holiday: 'When Andrew Humphrey entered a competition run by the venerable Royal Academy to win a week experiencing Aztec culture first-hand, he might have expected a genteel tour of the ruins around Mexico City, perhaps taking in the famous floating gardens of Xochimilco. Instead, he found himself tasting contemporary Mexican culture at a notorious adults-only resort with nudity, a 'sexy pool' and 'adult' shows.'

(All picked up via the forteana mailing list BTW.)

Soldiers in Iraq, and Vipul

The Killer Elite (Rolling Stone):

The twenty-two-year-old driver, Cpl. Joshua Ray Person, and the vehicle team leader, twenty-eight-year-old Sgt. Brad Colbert -- both Afghan War veterans -- have already reached a profound conclusion about this campaign: that the battlefield that is Iraq is filled with 'fucking retards.'

Later on:

Captain America, the platoon commander who is almost universally disrespected by the enlisted men, seems to deal with the stress by rising to a state of jabbering incoherence. Up by the bridge there are four enemy dead scattered under the eucalyptus trees, along with piles of munitions -- RPGs, AKs and hand grenades. Captain America runs back and forth, picking up their weapons, hurling them into the nearby canal and screaming at the top of his lungs. No one knows what he's screaming about or why, but as another officer who came upon this scene later concluded, 'Whatever he was doing, he was not being in command.'

Fantastic series of articles, well worth a read. (Found on stuff.) Similar to this, here's an unauthorized weblog from a soldier on duty in Iraq -- the inside story.

Spam: Good article by Vipul on spam filtering, at MIT Tech Review:

Here's a list of three rules (created after the most important features of e-mail) that anti-spam software should strive to follow:
  • 1) Ability to send and receive e-mail from a stranger. (Whitelisting, payment systems, and challenge/response break this rule.)

  • 2) Ability to send and receive pseudo-anonymous e-mail. (Domain-based authentication breaks this rule.)

  • 3) E-mail should be free. (Payment systems break this rule.)

He said it. Killing off several useful legit uses of email, just to fix spam, is no good. Looks like he's started writing his blog-like thing too, again, so I'll be adding that to my 'roll (assuming it stays updated! ;) No RSS yet though...

Great paper on Diebold e-voting systems

Great report auditing the security features of the Diebold e-voting systems. Summary: what security?

  • despite using relatively 'smart' smartcards, they don't actually get those cards to perform an authentication task; they're just used as 'dumb' memory cards, and there's no central online database of valid card IDs. Plus, the same write password is used for all smartcards.

    So they really might as well have used formatted floppy disks ;) Duplicating cards (a card is a voting opportunity, 'vote early, vote often') would be pretty easy, from the sounds of it.

  • amazingly, the software does not record the 'voter serial number' that appears on the card, when a voter casts a vote. So again, duplicating the cards is trivial. Bizarre.

  • all that is required to extract the PIN from an administrator card is a smartcard reader; the PIN is immediately sent in the clear as soon as the card is inserted and the terminal-card protocol initiates.

  • for storage on the internal writable media, between voting and the final upload operation, the logs and votes are encrypted using single DES in CBC mode, with a single shared initialization vector. IMO this is not a big deal as far as I can see, as that's only stored on the hardware; and if someone can read/write to that, they can subvert the WinCE OS anyway.

Then the kicker:

  • the votes are then decrypted before being sent in the clear over a dialup internet connection.

The mind boggles.

Nathan Barley v. Chris Morris

The Guardian reports that fake-news genius Chris Morris is collaborating on a new show with Charlie Brooker:

This has led to persistent rumours on internet talkboards and gossip sites that the show will be based around TVGoHome's character Nathan Barley.

Barley, the star of a fictional TVGoHome docusoap, is a loathsome public school educated, Hoxton-dwelling new media type, obsessed with gadgets and extreme sports.

But given Morris's fondness for windups and spoofs, this could just as easily be a red herring.

Apparently, Morris and Brooker have collaborated before on smaller segments. Whatever it is, I'm all for it. Fact times Importance equals News!

Gross: The Indian 'fly boy' has doctors baffled. 'Doctors carried out a cystoscopy to clear the boy's urinary tract, but the treatment has failed because two more flies emerged out of his penis on Monday.' (aaargh)

Referrer Spam Gets Smarter

So, it seems the referrer-log spamming is getting worse. The earlier attempts all used a limited set of IPs; probably the real source machines.

However, the latest crop are now relaying through open proxies. Out of a sample size of 10 random IPs, every one was a proxy listed in the OPM blacklist.

The URLs being spamvertised are all pr0n; lots of .ws and .biz hits with pretty colourful names. Take a look here, under any of the top 5 hits. They're outnumbering the legit hits by about 20 to 1.

BTW, it's now pretty clear the practice of referrer-spamming is intended to gain Googlejuice; plenty of other sites have noticed it too. It's worth noting that in my case, it won't work -- my log pages are all off-limits to the Googlebot for quite a while, but the referrer spammers haven't figured this out yet...

Some notes:

  • the spamvertized URLs include perlcoders.com, openproxies.com,
    • cgifactory.net, so steer clear of those sites.
  • the User-Agents are randomised, similar to spamware's randomised X-Mailer headers. Some samples include:
    • Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; MSN 6.1; MSNbMSFT; MSNmen-ca; MSNc00; v5m)

    • Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SC/5.10/1.14/Telenor; .NET CLR 1.1.4322)

    • Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)

    • Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Wanadoo 5.6)

      My guess is they just took a large list of legit user agents, and used that.

  • I've now left them a few little surprises ;)

Spam Gallery, and Fusors

The Field Guide To Spam, by Dr. John Graham-Cumming of POPFile; seems to be a continuation of his 'Spammer's Compendium' talk at the Spam Conference. Lots of examples of filter-evasion tricks used in spam, with a brief description, example, and categorization.

Worth noting some SpamAssassin dogma here: these may seem to be a good way to evade filters. However, since they are tricks that spam uses, and non-spam mail does not, they then make excellent spam signatures -- and the spammers effectively just give us yet another way to identify their spam. ;)

Hacking: Fusor.net is a community of mad scientists amateur fusion researchers, building nuclear fusion devices in their garages and basements. They're not quite self-sustaining yet, but they're definitely working on it.

In the meantime, some pretty pictures of poissors, buggle jets, and fusion stars here. Thanks to Mr. FoRK for posting a link to this... amazing.

Missing the point

Gary Robinson points to an announcement of a new music service, BuyMusic.com -- the announcement notes 'users of the service will not necessarily have the freedom afforded customers of ... iTunes ... to transfer the music purchased to multiple computers and portable devices, or to burn it to compact discs.'

How do companies like this get funding? Surely it's obvious that people are not going to sign up for services where they are stuck with crippled DRMware, and don't actually get to own what they buy. 'Here's a car. Oh BTW -- you're only permitted to drive this within 5 miles of your home, it'll conk out if you go any further.'

I suppose it's hardly surprising, but BuyMusic.com informs me that my browser and OS are not welcome, in a surreal throwback to 1999. Ho hum, I'll stick with EMusic, thanks...

In other news, I've just signed up for a mailing list called geowanking. Official: best name ever!

Clay Shirky’s latest

A Group Is Its Own Worst Enemy. Clay Shirky does a fantastic job of wrapping up pretty much every important social software site on the 'net in the last 15 years, all into one neat, tidy paper, then making a few comments that make sense. recommended...

GTLD Nameserver has corrupt data – again

There were some reports on the SpamAssassin-talk mailing list today, that all queries to the now-defunct orbs.dorkslayers.com DNSBL zone are now returning a true result.

Thomas Mechtersheimer pointed out the culprit: it turns out that b.gtld-servers.net, one of the top-level DNS global TLD servers ( run by Verisign, as far as I can see), is returning 65.246.50.11 for every query for a name that does not exist under the .com and .net zones. That includes second-level names, and anything under a nonexistent second-level name.

Take a look. a.gtld-servers.net is returning the correct NXDOMAIN results, b.gtld-servers.net is blissfully sending all this traffic to some poor UUnet dialup ;)

dig 242.110.40.68.orbs.dorkslayers.com. @a.gtld-servers.net.
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 27661
dig 242.110.40.68.orbs.dorkslayers.com. @b.gtld-servers.net.
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 52998
242.110.40.68.orbs.dorkslayers.com. 15 IN A     65.246.50.11
dig 4905893958xc98gdf9g8945.com @a.gtld-servers.net.
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 9454
dig 4905893958xc98gdf9g8945.com @b.gtld-servers.net.
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 42344
4905893958xc98gdf9g8945.com. 15 IN      A       65.246.50.11

Update: It's been fixed, as of about 1200 PDT.

Linux and MS: WinCE now customizable

Whoa: 'This spring, Microsoft dropped the price of Windows CE and completely opened its embedded operating system to developers, allowing them for the first time to not only view and modify CE, but also sell products that incorporated the customized code.'

Really? So WinCE developers can modify and then rebuild and sell WinCE with code changes? That's a big deal. It's kind of unavoidable, though. That close to the metal is virtually impossible without source IMO.

Most-mailed story ever?

this story has been mailed 120 times since it was posted on Yahoo! UK at 11:30 AM GMT yesterday. Which is it? Yep, it's 'masturbating may protect against prostate cancer', premiered at New Scientist. Most mailed/blogged story ever, I'd guess!

For some reason I didn't post this to the blog on Wednesday when it came out, instead posting it to another list. But talking about it with some mates last night, they noted this snippet:

The team speculates that infections caused by intercourse may increase the risk of prostate cancer. 'Had we been able to remove ejaculations associated with sexual intercourse, there should have been an even stronger protective effect of other ejaculations,' they suggest.

Interesting!

Arlene McCarthy letter analyzed on patents list

In case you're trying to reconcile Arlene McCarthy's public words, about how the proposed EU legislation helps block software and bizmeth patents, and the FFII's public words saying the opposite, here's a helpful email thread cross-posted between the Patents list at AFUL.org and the free-sklyarov-uk list.

Also, Hartmut Pilch notes a prior letter which as yet remains unanswered; 'All she has until now ever done is to send out standard answers to unspecific letters from concerned (and possibly naive-sounding) software developpers. Whenever someone tries to ask her more specific questions, there is no response at all. However documenting the fact that there is no response may also help. So please remember the public letter and point demand a response at every opportunity.'

The Financial Times has an article (paying subscribers only, but that link excerpts a part) which makes clear the difficulties. 'oftware protection regulations across EU member states should be harmonized while also allowing software developers to carry on without the threat of patent searches and litigation hanging over their heads. He argues that the EU directive's wording is opaque: The proposal lists computer implemented inventions as patentable, but this definition fails to establish whether it refers to software algorithms or inventions whose usability is dependent on software. Cane also notes that it is harder to see parallels in software invention and physical invention, and argues that there are few truly novel software inventions because most software is based upon prior work carried out by other people.' (thanks to Gary Robinson for the link)

I Hate Windows

So I had to edit a Word doc. Left it for a few minutes, the network connection died, so I tried to save it somewhere else.

Foolishly, I did this by hitting File->Exit, knowing (ha!) that I could save it on the way out. All well and good -- until something in Word decided it required the old copy of the doc to save the new one -- even though that was in memory, since I could scroll around it etc. (it wasn't a very long doc).

So it refused to let me save until I restored the network connection. I couldn't be bothered doing that, so I hit Cancel on that 'please restore the net connection' dialog, assuming it'd let me just cut and paste the text, which is all I wanted. Guess what it did? That's right, it just exited, taking the unsaved doc with it. Argh.

I've learned my lesson. Next time, I'll stick with trusty (and sane) Vim. At least it knows how to do an Edit File UI, even if it's not quite as pretty (or featureful).

Over-zealous spam filters, pt. xxix

Neil Gaiman writes about how, for several months, mail to his publishers, DC Comics, was intermittently disappearing into a black hole. Eventually, the culprit was found: AOL-TW's spam/virus filters. Any mail containing the word 'Sandman' -- ie. the name of the comic he writes for DC Comics -- was being filtered silently, without notifying either the sender or recipient. Wow. His editor's computer guy reported:

I've been informed that the reason why there was a delay in the delivery of this message was because one of several keywords were found within the message. In particular, the word 'SANDMAN' was found several times. This has been a telltale sign of one or more computer viruses, so the message was set aside to be investigated by a WB security person.

(Via Crypto-Gram)

‘Outside the Master Plan’

A good OCWeekly article about Irvine Meadows West -- UC Irvine's trailer park. The trailer park brings a little grit to UCI, and -- bonus! -- is apparently a good, fun place to live. Super-cheap too, at 130 dollars a month.

Unfortunately it's going to be closed and replaced with a parking lot:

To the students, many completing their doctoral theses, the trailer park is their private refuge from the master-planned sterility beyond. They see the housing department's decision to raze the park not as a bow to parking pressures, but a calculated strategy to destroy something 'outside the master plan'--a phrase that's become the residents' motto.

NZ e-commerce sites getting business-method patent shakedown

<

p>The New Zealand Herald reports that 'internet retailers nationwide are banding together to fight a Canadian company's demands for them to pay up or be shut down.' A Montreal-based company called DE Technologies has 'written to several e-commerce operators demanding licensing fees for use of international e-commerce processes.'

<

p> The affected ISPs and e-commerce companies are banding together to fight the patent. The NZ Ministry of Economic Development is quoted as saying 'This is a commercial matter. If people wish to dispute the validity of the patent there are mechanisms in the Patents Act (1953) for them to seek to have the patent revoked'. However, one company has received legal advice indicating that an attempt to have the patent overturned could cost up to NZ$150,000, and some background on the FightThePatent site indicates that there may also be only 12 days (or so) from today to do so.

<

p> DE Technologies' news page gives an interesting angle on their activities in NZ. It seems Ed Pool, the CEO of DET, believed in 2001 that it was 'an insult to call it a business process. To this day, no one has been able to duplicate this design.' However, it seems that by 2003, at least 40 NZ-based e-commerce outfits have now figured out the details, because that's how many legal letters his lawyers have reportedly sent. One such letter demanded a $US10,000 signing fee, a 'royalty rate' of 1.5% on every transaction, and 11 US cents for each document generated.

Worth noting that the patent has also been granted in Singapore and the US -- where it apparently caused a public outcry and was raised on the Senate floor as an example of a 'bad patent', before it was granted anyway.

Giant NYC Cube Becomes Giant NYC Rubik’s Cube

Astor Cube: 'One of the most prominent landmarks in the East Village in Manhattan is a statue of a giant steel cube. The cube was built at Astor Place in 1968, and has stood there ever since. (jm: apparently it's called 'The Alamo' by Tony Rosenthal.) .... in true All Too Flat style, we decided the plain black cube would look nicer as the world's largest Rubik's Cube!' (link via MemeFirst)

Evan Alice Hughes

Congrats to Craig and Erica! Sounds like there was quite a lot of work involved for Erica -- ouch -- but the end result looks very cute.

Good choice of name, too -- my friends Tom and Colette will be tickled by this one, given that they've named their son 'Evan', and their daughter 'Alice' ;)

Quick Links

Tube Rules -- lessons in London Underground etiquette. My favourite: don't wear massive backpacks.

Dave Malone on broken time-sync software. It seems Tardis, the popular Windows time-syncing software, used HTTP to get a trustworthy timestamp. OK, that's pretty bad -- using TCP/IP against a webserver to try and get a usable time -- it'll be several seconds off in most cases, and is pretty suboptimal in general.

But at least they set up their own server, instead of glomming off someone else's bandwidth and CPU, right? Nope -- they used a server at maths.tcd.ie, along with only 2 others worldwide. And they used GET. And they didn't send a User-Agent header. And the server wasn't even a public time server since 1996 anyway.

All seems well now -- Dave instituted a policy of returning '1999' as the date, and hopefully everyone has noticed by now. ;)

Finns Scratch Heads Over N.Korea Porn Claim

Yahoo!: Finns Scratch Heads Over N.Korea Porn Claim:

HELSINKI (Reuters) - Finnish officials were at a loss to explain an allegation made on Thursday by a U.S. official that North Korea has been caught trying to sell pornography in the small Nordic country. 'It sounds strange. It sounds wild,' an official at the Foreign Ministry told Reuters.

U.S. Ambassador to Australia Tom Schieffer made the comments earlier on Thursday to the National Press Club in Canberra, saying North Korea was using a 'mafia-like' business model to make up a revenue shortfall when the Soviet Union collapsed in the early 1990s.

Found on MemeFirst, which looks like a pretty nifty site. Now to see if I can rig up RSS for it. One of the MemeFirst culprits seems to be Stefan Geens, who also has a blog; he reviews 'How The Irish Saved Civilization' in fine style, comparing the annotations of the medieval Hibernian monks to blogging. hmm...

He's stuck in Dublin, right now, trying to figure out a way to get hold of some bandwidth. I wish him luck.

Techie Details on The Reverse-Proxy Spam Trojan

Scary stuff -- the techie details of the trojan discussed in the NYT article today -- Reverse-Proxy Spam Trojan - Migmaf (LURHQ):

LURHQ was able to obtain a copy of the trojan - detected from suspicious activity originating from a VPN user on a firewall on a network we monitor. What we found was the trojan was not a webserver at all, but instead: a reverse proxy server. Instead of hosting the content on the victim's computer, the spammer instead maintained a 'master' webserver. We have dubbed this trojan 'Migmaf'.

Snopes: Urban Legends Urban Legend

Brilliant. From this week's b3ta newsletter via the forteana list comes this work of one-liner UL genius:

Snopes conspiracy: ' Snopes was set up in early 1995 by the CIA as a way to debunk popular conspiracy theories, Companies and individuals can now pay to have their urban legend denied on the site, a prime beneficiary being Richard Gere.'

Spam: Hackers Hijack PC's for Sex Sites (NYT). Good article about a (suspected) Russian spam ring using hijacked PCs and reverse proxies to host spamvertized websites.

Ceramics: Anyone who's been following the IRTF's Anti-Spam Research Group mailing list recently, will have come across Mark McCarron's 'proposal' regarding an anti-spam system that has something to do with everyone paying 5,000 UKP, ditching end-to-end SMTP, stopping any non-human-initiated e-mail, and energy from the Pyramids of Giza (I think).

Surprisingly enough, The Reg wrote some unkind words, and now Mark exercises his right to reply. Unmissable, mainly for the details of his reign of terror during school and his 'jack of all trades' abilities.

Great fun, in a kind of 'watching a car-crash' way.

PI vs IP, and FIT

Nathan Cochrane meets the Aussie Privacy Commissioner:

We're talking about a serious privacy vs piracy debate. On the piracy debate we're talking about management of Intellectual Property (IP). I am a person with Personal Information (PI) and if that is taken away, it is an invasion of my privacy. I would like to hear these people (IP owners) making such a lot of noise about piracy of IP talk about the protections of PI -- then they would have some credibilty. There's a pretty ugly asymmetry in the debate. Both sides need to grow up a bit and be a bit more respective of both sides of the argument.

(Nathan:) For my part, I chipped in that I think it hypocritical that IP owners will kick in my door if they suspect I am stealing their IP, but to steal my PI is just a 'business case'.

I like the 'PI' concept. Perfect timing, given this report on the new ATTBI/Comcast 'Transition Wizard'. Check out this insanity:

Any Comcast user that actually installed the Transition Wizard has given Comcast permission to do the following;
  • 1) arbitrarily open and read your email without your knowledge and/or consent

  • 2) perform a credit check on you and then share that info with whomever they choose

  • 3) Perform firmware upgrades to your cable modem at their discretion, regardless of who owns it.

    You also agreed not to participate in any future class action suits that may be brought against Comcast for whatever reason. You agreed to this and more when you clicked on the 'I Agree' button during the initial installation phase.

Mind you, the actual text isn't posted, so take it with a grain of salt.

Code: Danny's notes on the FIT testing OSCon talk -- that's running a test suite as a Wiki. Interesting, but I have to think about how practical it is in general. Demo here, more complex demo here.

Good tech-politics blog

Nathan Cochrane has a weblog. He's a clueful journo who writes about technology for The Age, the Melbourne newspaper -- thumbs up for that; I read plenty of The Age during my sojourn in Melbourne, it's the best newspaper in Oz. (Plus it recommends using Sitescooper and Plucker in their Handheld Howto page, so that's always going to get a +1 from me ;)

But anyway, a very clueful weblog; lots of good journalism straight from the source. Recommended.

LinMagAU.org: Integrating SpamAssassin with MailMan. I really must get around to getting our server upgraded to MailMan 2.1 so we can apply this; I have one list that's getting about 5-10 spams a day, and even with 'subscriber posting only' set, MM 2.0's admin interface is very clunky for dealing with that.

Does anyone know if there's a usable tool to automate Mailman admin BTW? Or give it a good UI?

Corn Syrup, Paid-For RSS, and P45.net

When you move from one country to another, you often notice some details of the taste and texture of the local foodstuffs. For example, pretty much everything in Thailand tasted slightly fishy to my western tastebuds, due to their widespread use of nam pla, a fermented-fish sauce seasoning.

In the US, there's a very definite gooey texture and strong sugary flavour which crops up in lots of foodstuffs -- right down to salad dressings and soft drinks. Eventually I figured it out -- it's corn syrup, which isn't really used at all in Europe. According to this review of Fat Land, here's why it's everywhere:

According to Critser, a leading journalist on health and obesity, America about 30 years ago went crazy sowing corn. Determined to satisfy an American public that 'wanted what it wanted when it wanted it,' agriculture secretary Earl Butz determined to lower American food prices by ending restrictions on trade and growing. The superabundance of cheap corn that resulted inspired Japanese scientists to invent a cheap sweetener called 'high fructose corn syrup.' This sweetener made food look and taste so great that it soon found its way into everything from bread to soda pop. Researchers ignored the way the stuff seemed to trigger fat storage.

The book's thesis seems to be that corn syrup and palm oil are largely to blame for the obesity epidemic. A quick google shows up this LA Times story which covers the book in more detail:

'High-fructose corn syrup is a really low quality, really cheap sugar,' the 38-year-old (Robyn) Landis says dismissively. The syrup starts out as cornstarch, which is then made sweeter by converting some of its glucose to fructose; the more fructose in the end product, the sweeter it is. 'It is not something our bodies should be dealing with. It's completely unnatural.' She also objects to the fact that high-fructose corn syrup turns up in unlikely places, such as ketchup, baby food and baked beans. 'Even chocolate tastes more like sugar than chocolate when it is sweetened with high-fructose corn syrup,' says Landis ...

... Dr. George A. Bray, an obesity researcher and professor of medicine at Louisiana State University Medical Center, also singles out high-fructose corn syrup because the meteoric rise in its consumption closely parallels the jump in obesity rates. 'Nothing else in the food supply does this. It's a very, very striking relationship.'

... Ironically, fructose, which is also known as fruit sugar, was once considered a healthier, 'more natural' alternative to sucrose, that is, old-fashioned table sugar, because of its presence in fruit. In addition, diabetics thought it was healthier for them because it does not raise insulin or blood sugar levels as high as glucose does. However, animal studies and preliminary human studies have found that a high-fructose diet leads to some of the same health problems that are rampant among overweight Americans, including insulin resistance and elevated triglyceride levels, a marker for heart disease.

(I still plan to get my teeth into a corn dog pretty soon though ;) Gotta get that low-grade meat product fix!)

RSS: Ben Hammersley points at this really wierd posting from Adam Curry. Points and laughs, in fact.

As far as I can see, AC wants development of (N)echo to stop, because he dropped 10,000 dollars getting a year's paid placement in the Radio Userland aggregator, or something like that. Well, that was a smart investment. I'm sure all the people thinking about (N)echo are dropping tools right now, accordingly. ;)

Ireland: P45.net now has MT blogs. Cool.

RID-Spam, The Grauniad, E-Voting

The RID-Spam Act chugs through Congress. This one's very much toothless; according to CAUCE, it's not actually anti-spam really -- CAUCE says:

(it is) 'a gross misnomer to call them 'anti-spam.' 'Anti-consumer,' sure. 'Pro-spam,' even. But not 'anti-spam.''

Amazingly, DMcC notes that it may even de-fang the stronger state laws if it gets passed. Wow.

And check out this quote from the CNet story:

Rep. Bob Goodlatte, R-Va., defended the bill's opt-out approach. Goodlatte said that of the physical junk mail he gets, 'maybe 10 percent of it is something that I have some interest in. For that reason alone I think an opt-out approach is the best solution here.'

Good for him. The way he's talking there, he's looking forward to receiving 700,000 mails per year that 'he has some interest in'. Earth calling Goodlatte -- direct email is not the same as physical junk mail. There's a fundamental economic difference -- with email, the recipient pays. That means you cannot compare the volumes so simplistically. Just say no to One Bite Of The Apple!

US Politics: Rod notes this story: The Guardian coming to the US. Excellent! I think that's a fantastic idea, and they'll clean up.

Consider this -- the only large-circulation print media that (a) people over here read, and (b) had the nerve to really treat the war in Iraq critically, as far as I know, are those two flaming-red anarchosyndicalist rags, the Economist and the Financial Times. (Not only are they not even written in the US, they're quite conservative by Euro standards.) The US media needs more liberal voices.

Actually, I'm exagerrating heavily here. As Craig has pointed out before, the Christian Science Monitor is a pretty good paper, with some critical journalism -- and one with a great story behind it's provenance to boot.

But the Guardian has a pretty much wide open field all the same -- here's hoping they can get the distribution side sorted out.

E-Voting: Some good comments on this Slashdot story regarding e-voting systems.

  • The Brazilian legislature mandated a retrofit 'of 3% (some 12,000 machines) to produce a paper ballot that the voter could peruse and deposit in a box for recount (the first large-scale use of the 'Mercuri Method').'

  • Georgia noted that the e-voting systems 'were all very flashy and glitzy, but all had severe problems with security and/or usability. We eventually decided to run a pilot program in last year's off-year election and try out 5 of the most promising machines in a real-world election. The final winner will be used across the state in 2004. No more hanging chad, but I think we are going to have a whole new set of problems to deal with.'

the melting-pot that is blogs.linux.ie

Just taking a look around blogs.linux.ie to see who's set us up the blog recently; here's the results:

  • unfortunately quite a few folks seem to have got bored and left off around mid-April. Ah well.

  • Quite a few lively blogs to add to the blogroll.

  • There's also a burgeoning population of teenage Malaysian blogs, bizarrely enough! planet_aiie, whoelse and corexified. Big slipknot fans it seems.

  • Malaysia's not alone in this -- here's a Jamaican guy. Must be the flag on the favourites icon; green and gold on a black background -- that's more linux.jm than linux.ie. ;) Unfortunately for my patois, he stopped updating in April. Sufferation! Oh well, I'll just have to stick with the Sizzla for my lessons.

  • a Phillipino blog, too!

Just figuring this one -- it seems linux.ie is free and easy to set up a blog at, doesn't have ads, and does decent RSS with full <content:encoded> blocks. All in all, that makes it a pretty good blog platform when you think about it. Fair enough!

Consumer groups, open source etc. call on WIPO to discuss open projects

WIPO DG asked to convene meeting on open and collaborative projects to create public goods:

In recent years there has been an explosion of open and collaborative projects to create public goods. These projects are extremely important, and they raise profound questions regarding appropriate intellectual property policies. They also provide evidence that one can achieve a high level of innovation in some areas of the modern economy without intellectual property protection, and indeed excessive, unbalanced, or poorly designed intellectual property protections may be counter-productive. We ask that the World Intellectual Property Organization convene a meeting in calendar year 2004 to examine these new open collaborative development models, and to discuss their relevance for public policy.

I hope this gets somewhere; it'll be interesting to see what the World Intellectual Property Organization has to say officially about open source, the Human Genome Project, the world wide web, and other unencumbered projects of this type.