Thursday, December 11, 2008

#tmbg Undernet Memroids: Booga visits Kelly in some Salty Fishing Villiage

Went to visit Kelly Mendenpants in a tiny upstairs apartment in Bremerton, or some other salty pirate village near Seattle.  I waited at a gas station for him to pick me up, and went inside the convienience store to buy some beef jerky.
Half of my nutrition comes from the jerky.  The other half, lichens.
When Kelly finially arrived, I pretended to be polite and offered him some jerky, hoping he would decline.  He ate some of my jerky.  Rat-bastard.
From then on, I plotted my revenge.
In the drawing above, Booga lunging about a small table and two chairs, and Kelly be having hair.

Friday, October 31, 2008

The Bullshit that is "What Every Programmer Should Know About Memory"

Wired plug board for an IBM 402 Accounting Mac...Image via Wikipedia

This is bullshit. 114 pages! A revision history!
Obviously this is hardly "What Every Programmer Should Know About Memory". This is one guy's "Everything I Can Say about Memory In One Place without Contradicting Myself".
This is the usual "lambda-the-ultimate" "The Society for the Prevention of Programing" circle-jerk.
Fucktards...
For the sake of argument, lets say you refuse to play the "premature optimization" game. For the sake of argument, lets say you are satisfied with the length of your dick.
How do you in fact make programs with good performance?
(Step 1) Straight-forward & correct implementation
(Step 2) Timing tests and timing profiles under real-world loads. (Don't fool yourself, the best you can do is approach reality with profiling - you can never achieve perfect real-world profiling.)
(Step 3) Under Revision Control, hit the place in your code where you sense you will get the biggest bang for your buck
Repeat Steps 2 & 3 until you sense futility, until you sense rapidly diminishing returns.
(Step 4) Roll back some of the improvements! I am not kidding, you have to give back some of your hard won performance. You need to find a balance between Performance (Latency, Throughput, and Resource Use) and:
  • Readability
  • Maintainability
  • Portability
  • Testability
  • Ease of Understanding
  • Predictability/Stability
  • Fewest Lines of Code
  • and Validity is merely the "ticket of admission" - without that, nothing counts for shit.
You won't know what Performance you have to give back, until after you implement it and time and profile it. Sorry, that is the way it works. If your coding is so laborious that you cannot bare to think of throwing away even a single line of code, then the Universe is trying to tell you to stop. Programming is Hard, Let's Go Shopping!
(Step 5) Now that you have Performance, add at least one test of the Performance to your automated testing suite. Or else you will give it all back, and then some, with a single ill-advised change to your code in the future. If you don't care enough to Test It, then you don't really care, Period.
(Step 10000) As you write more code, your instincts improve. Your first 100,000 lines of code will be of poor quality, and your next 100,000 will be slightly better. You have to pay your dues, because nobody else is exploring your exact problem domain. You have to find your own road.

A photo showing refraction of light rays: a so...Image via Wikipedia

Any other approach is just sucking your own cock through a soda straw. While other people are getting results, you are still playing with yourself.
Reblog this post [with Zemanta]

Monday, October 13, 2008

Two Blue Stickie Notes, Two Goats

Pillow/Oily-Hair Induced Diabetes

A non-commissioned portrait of myself.  Someone near and dear drew this.

Monday, September 29, 2008

Roger G. Johnston, Physical Security Maxims

Physical Security Maxims
Roger G. Johnston, Ph.D., CPP
The following maxims, based on our experience with physical security, nuclear safeguards, & vulnerability assessments, are not absolute laws or theorems, but they will be essentially correct 80-90% of the time.
Infinity Maxim: There are an unlimited number of security vulnerabilities for a given security device, system, or program, most of which will never be discovered (by the good guys or bad guys).
Arrogance Maxim: The ease of defeating a security device or system is proportional to how confident/arrogant the designer, manufacturer, or user is about it, and to how often they use words like “impossible” or “tamper-proof”.
Ignorance is Bliss Maxim: The confidence that people have in security is inversely proportional to how much they know about it.
Be Afraid, Be Very Afraid Maxim: If you’re not running scared, you have bad security or a bad security product.
High-Tech Maxim: The amount of careful thinking that has gone into a given security device, system, or program is inversely proportional to the amount of high-technology it uses.
Schneier’s Maxim #1: The more excited people are about a given security technology, the less they understand (1) that technology and (2) their own security problems.
Low-Tech Maxim: Low-tech attacks work (even against high-tech devices and systems).
Father Knows Best Maxim: The amount that (non-security) senior managers in any organization know about security is inversely proportional to (1) how easy they think security is, and (2) how much they will micro-manage security and invent arbitrary rules.
Huh Maxim: When a (non-security) senior manager, bureaucrat, or government official talks publicly about security, he or she will usually say something stupid, unrealistic, inaccurate, and/or naïve.
Voltaire’s Maxim: The problem with common sense is that it is not all that common.
Yipee Maxim: There are effective, simple, & low-cost counter-measures (at least partial countermeasures) to most vulnerabilities.
Arg Maxim: But users, manufacturers, managers, & bureaucrats will be reluctant to implement them for reasons of inertia, pride, bureaucracy, fear, wishful thinking, and/or cognitive dissonance.
Show Me Maxim: No serious security vulnerability, including blatantly obvious ones, will be dealt with until there is overwhelming evidence and widespread recognition that adversaries have already catastrophically exploited it. In other words, “significant psychological (or literal) damage is required before any significant security changes will be made”.
I Just Work Here Maxim: No salesperson, engineer, or executive of a company that sells security products or services is prepared to answer a significant question about vulnerabilities, and few potential customers will ever ask them one.
Bob Knows a Guy Maxim: Most security products and services will be chosen by the end-user based on purchase price plus hype, rumor, innuendo, hearsay, and gossip.
Familiarity Maxim: Any security technology becomes more vulnerable to attacks when it becomes more widely used, and when it has been used for a longer period of time.
Antique Maxim: A security device, system, or program is most vulnerable near the end of its life.
Payoff Maxim: The more money that can be made from defeating a technology, the more attacks, attackers, and hackers will appear.
I Hate You Maxim 1: The more a given technology is despised or distrusted, the more attacks, attackers, and hackers will appear.
I Hate You Maxim 2: The more a given technology causes hassles or annoys security personnel, the less effective it will be.
Shannon’s (Kerckhoffs’) Maxim: The adversaries know and understand the security hardware and strategies being employed.
Corollary to Shannon’s Maxim: Thus, “Security by Obscurity”, i.e., security based on keeping long-term secrets, is not a good idea.
Gossip Maxim: People and organizations can’t keep secrets.
Plug into the Formula Maxim: Engineers don’t understand security. They think nature is the adversary, not people. They tend to work in solution space, not problem space. They think systems fail stochastically, not through deliberate, intelligent, malicious intent.
Rohrbach’s Maxim: No security device, system, or program will ever be used properly (the way it was designed) all the time.
Rohrbach Was An Optimist Maxim: Few security devices, systems, or programs will ever be used properly.
Insider Risk Maxim: Most organizations will ignored or seriously underestimate the threat from insiders.
We Have Met the Enemy and He is Us Maxim: The insider threat from careless or complacent employees & contractors exceeds the threat from malicious insiders (though the latter is not negligible.)
Mission Creep Maxim: Any given device, system, or program that is designed for inventory will very quickly come to be viewed--quite incorrectly--as a security device, system, or program.
We’ll Worry About it Later Maxim: Effective security is difficult enough when you design it in from first principles. It almost never works to retrofit it in, or to slap security on at the last minute, especially onto inventory technology.
Somebody Must’ve Thought It Through Maxim: The more important the security application, the less careful and critical thought has gone into it.
That’s Entertainment Maxim: Ceremonial Security (a.k.a. “Security Theater”) will usually be confused with Real Security; even when it is not, it will be favored over Real Security.
Schneier’s Maxim #2: Control will usually get confused with Security.
Ass Sets Maxim: Most security programs focus on protecting the wrong assets.
Vulnerabilities Trump Threats Maxim: If you know the vulnerabilities (weaknesses), you’ve got a shot at understanding the threats (the probability that the weaknesses will be exploited and by whom). Plus you might even be ok if you get the threats all wrong. But if you focus mostly on the threats, you’re probably in trouble.
Mermaid Maxim:  The most common excuse for not fixing security vulnerabilities is that they simply can't exist.
Onion Maxim:  The second most common excuse for not fixing security vulnerabilities is that "we have many layers of security", i.e., we rely on "Security in Depth".
Hopeless Maxim:  The third most common excuse for not fixing security vulnerabilities is that "all security devices, systems, and programs can be defeated".  (This is typically expressed by the same person who initially invoked the Mermaid Maxim.)
Takes One to Know One Maxim:  The fourth most common excuse for not fixing security vulnerabilities is that “our adversaries are too stupid and/or unresourceful to figure that out.”
Depth, What Depth? Maxim:  For any given security program, the amount of critical, skeptical, and intelligence thinking that has been undertaken is inversely proportional to how strongly the strategy of "Security in Depth" (layered security) is embraced.

Friday, August 15, 2008

Tennis Day Camp Issues

A very little girl drew this. With a Sharpie on a 1.5"x2" stickie note. Dang.

Friday, August 1, 2008

Four ideas, yesterday and today

Morality = emotion + cultural transmission + ability to abstract First, today, was listening to webcast... From EconLog, Arnold Kling:
"Moral Philosophy" "Will Wilkinson and Jesse Prinz. Highly recommended. You could easily spend four years at an Ivy League college and not have a class as interesting as this one."
Webcast on : bloggingheads.tv
  • @13:20 Jesse Prinz, "'Emotions are the middle ground between _action_ and _thought_"
  • @28:38 Jesse Prinz: "morality is inevitable, but morality is not universal
  • @45:00 Morality = emotion + cultural transmission + ability to abstract
OK, "Morality = emotion + cultural transmission + ability to abstract". Then yesterday was thinking about three things: Politics & Societial Prescriptive Morality:
  • what if you list the things that really disturb
  • if you confess that, people will say you are: elitist, practically an enemy combatant, wrong, unreasonable
  • you could lose your: livelyhood, carreer, friends, recognition
  • in Third World countries, you could lose your life, if you are on the wrong side of political conflicts
  • the end result - consider working outside of public politics
Fame & Publicity:
  • what if you contrast who does and who does not deserve positive fame and publicity
  • if you confess that, people will say you are: elitist, wrong, unreasonable
  • the end result - consider working outside of public notoriety
but then I was thinking, if morality is tied to emotion, it is not easy to control.

Mill believed law should create happinessImage via Wikipedia

You owe it to the world to be Progressive, Happy, Effective:
  1. Happy, Effective and Progressive
  2. Unhappy, Uneffective and Progressive
  3. Happy, Effective and Reactive
When we consider people who are Progressive, but also Unhappy and Uneffective, we are supposed to see that they just need help to expand their responses, and not to criticize them, because they are just doing the best they can. But don't people who are Reactive deserve the same understanding?
Reblog this post [with Zemanta]