Pages

Monday, November 8, 2010

Demanding a More Secure Web

A few weeks ago Eric Butler, a software developer based in Washington, released a free open source Firefox extension that allows the user to hijack other users’ sessions that are on the same wireless network.  When you sit down at a public place and use Facebook or any other social network over a public hotspot, the site sends a cookie (a file with information that identifies you as you) and stores it to your computer.  Another person on the same wireless network could use the extension, called Firesheep, and hijack your session pretending to be you on Facebook or whichever other sites you are logged on to.  This is a widely known problem that has been talked about over and over again, but websites continue to fail at protecting their users.  Many sites use HTTPS to log users in but then return the user to unsecure connections to serve the rest of the their pages.  An easy fix for this problem is to encrypt the network using WEP/WPA, but the extension’s developer is trying to make us aware of how vulnerable sites not using HTTPS are.  He writes “they’ve been ignoring this responsibility for too long, and it’s time for everyone to demand a more secure web. My hope is that Firesheep will help the users win.”  At the end we can expect sites to start using HTTPS over HTTP, instead of users having to change the wireless encryption or manually adding extensions that are supposed to force HTTPS , but that are not always reliable.  An interesting fact is that HTTPS does not produce an overhead on the sites’ servers, which is the reason many companies decide not to offer HTTPS.  HTTPS requires an initial handshake which can be somewhat slow, but the actual amount of data transferred as part of the handshake is about only 5kB. This can be a burden for small requests, but with the high speed internet that we have access to it doesn’t mean much.  Look at gmail, it’s been using HTTPS since January (before it was an option) and the access speed is not slow at all.  Hopefully the message sent by Eric Butler will catch on and companies will start protecting their users’ data using HTTPS.  It is time that we the users who control the internet demand security on the services we depend on.

Wednesday, November 3, 2010

Enforcing Copyright Laws: A Huge Challenge

One of the challenges about copyright laws is that the new generation is growing up thinking that they don’t have to pay for music or other intangible products.  They will pay for clothes and food, but won’t pay for music.
I remember reading an article in the Ensign magazine a couple of years ago.  In the article the author suggested to not distribute music illegally, and to be careful about copyright laws, among other things.  I remember sending the link to the article to one of my friends in a country where piracy is common.  He said that he did not want to read the article because he knew that he was not willing to follow the counsel given there.  That is just how he was brought up; that is how the new generation is brought up.
Companies can sue and go after companies and individuals, but they will not be able to shut down the network or the technology where file sharing operates.  The most effective way to solve this problem of infringement of copyright laws is trying to change how people think.  Just how you can say “no” to someone that is offering you a drug, you can say “no” to someone offering to copy copyright material for you.

Wednesday, October 27, 2010

Civil Disobedience in the Digital Era

Civil disobedience, as defined by Wikipedia, "argues that people should not permit government to overrule or atrophy their consciences, and that people have a duty to avoid allowing such acquiescence to enable the government to make them the agents of injustice".  One of the greatest examples of the benefits of civil disobedience is Gandhi’s campaign for independence from the British Empire.  Like the civil protests that we all have a right to, hacking can be seen as civil disobedience when it shows discontent and opposition, and it ultimately shows a way of doing things better. What are the benefits of hacking?  One benefit of our disobedience is that it gives us more options.  When the iPhone first came out, the options to customize it or doing other productive things, like reading PDF files, or just changing the background, was limited or inexistent.  The hacking community created applications and modified the OS so that we could change those settings and add functionality to the phone, functionality that was already available on other phones.  What did Apple do? They came up with their own implementation of the features introduced by the hacking community, i.e. we now have multi-tasking, we can change wallpapers, will be able to change sms ringtones soon, etc. As someone puts it "we need to keep on hacking so long as we're angry, frustrated, and dissatisfied with the status quo.  We can sit around and complain, or we can do better." It should be a pretty easy choice and as long as someone is willing to "disobey" we all will enjoy the benefits that come with it.

Wednesday, October 20, 2010

"...in us and our seed all generations after us should be blessed"

President Woodruff said: “The eyes of God and all the holy prophets are watching us. This is the great dispensation that has been spoken of ever since the world began.” We live in the dispensation of the fullness of times, indeed, and all the blessings that our ancestors had are available to us.  It is our turn to be grateful for this blessing and to be faithful on helping fulfill the prophecy and bless all generations; the technology available to us helps us speed the process. I remember when my dad used to look at microfilms to extract information to do the work for our ancestors. Years later he started using FamilySearch and his work became much easier.  He found out that he had duplicated the work for a few people, something that with FamilySearch would hardly happen.  And now with the New Family Search the work is a lot easier. I just had to log in and link to my dad to be able to see all my ancestors for whom he has done the work for. He recently found out that there was a man, thousands of miles away from our home, that is also doing the work for his family. He didn't know the man, and he doesn't know if they're related, but they're both working on their families.  What a wonderful blessing it is to have the technology we have and be able to contribute to the Lord's work.  What a blessing it is to live in this last dispensation.

Monday, October 18, 2010

Cyber Attacks and the Cyber Space

Most of us have probably visited a web site that has been down due to a DoS (denial-of-service) attack, but were not aware of the cause for the site being down.  These kinds of attacks are an attempt to make an internet site or service not function as designed. The average internet user has little idea of what's happening behind the screen in being able to communicate with someone on the other side of the world. The knowledge of the average user decreases when we address the threats and security implications of having a network as open as the internet.

One or two decades ago, even an advanced user was little aware of all the holes that are open for people to take over a system. We have come a long way as the Pentagon's Cyber Command was scheduled to be up and running this month. Even though it missed the deadline to be fully operational, we can see that the government is aware of the need for an agency such as this one.  Interestingly enough, the Pentagon's Cyber Command missed the deadline because it was struggling to fill out the rest of the organization which needs more than 1,000 employees.

Even with this new Cyber Command, the rest of the U.S. government is lagging behind, debating the responsibilities of different agencies.  We have heard this before; It might be understandable as many people don't see or understand the tangible consequences of a cyber attack until they experience it firsthand. It would be interesting to know how much authority the Pentagon has to help fend off cyber attacks within the U.S.

An article recently reported that more than 100 countries are currently trying to break into U.S. networks. China and Russia are home of the greatest concentration of attacks. Attacks between different countries have been increasing recently as they are attempting to take down each other’s websites with DoS attacks. Many of the victims are government websites, but many victims also belong to the private sector.  How will the government respond to a call of aid due to an attack on the private sector? Does the Cyber Command have the authority to respond to it?

Government agencies have to catch up with the threats that Cyber Space presents, and they have to come up with a proper response model adaptable to the civilian and private sector. Meanwhile the other countries or organizations, like the U.N., could also have the initiative to help limit and punish cyber attacks. Cyber space and cyber attacks are real.

Wednesday, October 13, 2010

Women and Science

About a year ago I took a Sociology class at Brigham Young University. The main topic in that class was inequality and for a week we discussed gender inequality. Someone brought up the point that there are majors at school where the majority of the students are females and there are other majors where there are almost no females. The professor gave a few ideas, while the discussion leaned towards The Family: A Proclamation to the World. He asked the ladies in the class to give their opinion. Most of them, if not all, were Mormons. Most of them agreed that the reason they chose to study Nursing, Family Science or similar majors was because those majors would help them to better prepare to be mothers. Another reason is that they would be able to work while their children would be at school. They gave other reasons, but their answers focused on the fact that their priority was motherhood. This might be a good reason why many women don't go into Mathematics and Science majors. While this may be a credible reason for LDS girls, it may not necessarily apply non-LDS girls, so what of them? It might be true that our society discourages women to go into science and Math. It might even be true that even if women pursue science or math, they can be pushed into traditional female roles. Is this a bad thing? It can be if it is the solely reason why women don't go into these majors; if they conform to the sexist views of society that scientists and computer nerds are only males.

Tuesday, October 5, 2010

Technology and the Church

 Last week I talked with some people that work at the Church's Information and Communication Systems (ICS) Department. One of them mentioned that he used to think that the Church was full of older, gray-haired people that still programmed in assembly code or other really primitive languages. He then explained that the church is actually using cutting edge technology. He said that the Church doesn't just stay up to date with technology, but that it is always evaluating and implementing the newest technologies to see if they can be used. It is exciting to know that the Church does everything to stay up to date and to facilitate the use of Church systems to make church work easier for members and leaders. We, as members, need to be familiar with these technologies and how they work. There are many websites and systems available to us. I will just give one example. The Employment Resource Services department has a website that is little known (ldsjobs.com). Through this site, the Church uses available resources to help people that have lost a job, gain additional skills to improve their employment situation or hire-ability, which helps return many people to the workforce and helps ward leaders know how to help the less-fortunate members in their wards. The work of the Lord keeps moving forward at a faster pace with the implementation of these technologies and because of it, the work is now easier for Church leaders, members and even missionaries. It is up to us now to learn and utilize these resources to further spread the Gospel and share our testimonies around the world.