Sunday, February 2, 2014

Foresight

So I'm reading The Forsyte Saga just now.  Lovely little piece.  But that's not what I want to talk about.

In a single paragraph, Galsworthy uses both the word Bismillah and Nirvana. And Jumping Jesus.

For Jolly was forming himself unconsciously on a set whose motto was:
'We defy you to bore us. Life isn't half long enough, and we're going to talk faster and more crisply, do more and know more, and dwell less on any subject than you can possibly imagine. We are "the best"—made of wire and whipcord.' And Val was unconsciously forming himself on a set whose motto was: 'We defy you to interest or excite us. We have had every sensation, or if we haven't, we pretend we have. We are so exhausted with living that no hours are too small for us. We will lose our shirts with equanimity. We have flown fast and are past everything. All is cigarette smoke. Bismillah!' Competitive spirit, bone-deep in the English, was obliging those two young Forsytes to have ideals; and at the close of a century ideals are mixed. The aristocracy had already in the main adopted the 'jumping-Jesus' principle; though here and there one like Crum—who was an 'honourable'—stood starkly languid for that gambler's Nirvana which had been the summum bonum of the old 'dandies' and of 'the mashers' in the eighties. And round Crum were still gathered a forlorn hope of blue-bloods with a plutocratic following.
I had always assumed that Bismillah in the English-speaking public consciousness was a by-product of Bohemian Rhapsody and Freddy Mercury's Indian background (though I admit I don't know if the concept of Bismillah is relevant to Parsis).  And Nirvana...well...I guess I'd assumed it had made its way into the modern English speaking world via the Hare Krishna folks in the 60s.  Seems like, at least among the educated, they were out there a bit earlier.

Wednesday, January 1, 2014

2013 books

As I did last year, and the previous few before that, I'm posting the books I read this year.  Lot of good stuff this year, as well as a few fairly awful phone books that I can't quite explain why I felt compelled to plow through.

* = Recommended
X = Stay Away

  • Please Look After Mom (Audiobook):  Kyungsook Shin - This one was very interesting, structurally, if a bit melodramatic and... ummm... yearning for a return to... well... the closest character to "Mom" that I can think of is O-Lan from The Good Earth.  Kind of Harriet Lerner meets Pearl Buck in Korea.
  • Best of Jack London Short Stories (Audiobook):  Jack London - What can I say?  It's Jack London. Each story has a different reader, and the quality varies considerably.  I enjoyed many of them
  • Sense and Sensibility:  Jane Austen
  • *The Prisoner of Heaven (Audiobook):  Carlos Ruiz Zafon
  • Several short stories by Saki
  • * The Hunger Games:  Suzanne Collins - started it with Sidharta who quickly got bored (I don't know why - I think he just went in prejudiced against it)
  • X Freedom (Audiobook):  Jonathan Franzen - Oy...Really???  Another one of those "Why didn't I just give up at page 75, as I wanted to, rather than wade through the other 500 pages?"   So much tell.  So much summary.  So few interesting people.  (Not that he doesn't tell us how interesting they are.  To each other.)  Lots of melodrama.  Lots of exposition on the politics of ecological conservation that would make a perfectly pleasing essay but draggy fiction.  I seriously don't understand all the positive reviews it got - is this a case of I'm dumb, or the reviewer has no clothes?  I'll accept either answer, so long as you explain it to me.
  • * Broken Ballots:  Will Your Vote Count:  Douglas W. Jones and Barbara Simons (My review here)
  • The Phantom of the Opera:  Gaston Leroux -- Fluff, but I enjoyed it a lot  Ah, yes, we must needs pity the Opera Ghost.
  • * A Kiss Before Dying (Audiobook):  Ira Levin
  • * The Immortal Life of Henrietta Lacks (Audiobook):  Rebecca Skloot - fascinating history of one of the most ubiquitous tools in modern biology, the HeLa cell, originated from Henrietta Lacks' tumor, circa 1950.  Skloot weaves the story of Henrietta and her family with the history of tissue culture and the breathtaking discoveries that have been enabled by these "immortal" cells, while raising many profound and intertwined ethical questions about the use and economics of human tissue, access to medical care and informed consent
  • Of Human Bondage (Audiobook):  W. Somerset Maugham - I can't totally put my finger on why I liked this one and hated Freedom.  
  • * The Emperor of All Maladies (Audiobook):  Siddhartha Mukherjee - some interesting underscoring of themes from The Immortal Life of Henrietta Lacks, but more sciency and less human-interesty.  Lot of good history of science and illustration of the culture of scientific investigation.
  • The Trial (Audiobook):  Franz Kafka - gosh, how much it sounded like things that are reported in the news
  • The Jungle (Audiobook):  Upton Sinclair
  • * Death of a Salesman:  Arthur Miller - surprisingly, I'd never read this before.  Very strange little piece, with very interesting technique in portraying simultaneous internal and external dialogue of a single character, without the use of monologue.
  • Romancing Miss Bronte (Audiobook):  Juliet Gael - I'd like to put this as an X...the writing is fairly annoying, but the story is somewhat interesting.
  • Camilla:  Fanny Burney - I liked Cecilia a lot, but I think you could safely skip Camilla.  While the plots of both are driven by social conventions of that period and their heroines' internal conflicts are not very relevant to a modern audience, somehow I felt it less in Cecilia.  Camilla felt much more contrived and repetitive - same three or four gags repeated over and over.  Evelina falls somewhere in the middle for me - also irrelevant and contrived, but more natural (and shorter) than Camilla.
  • Lolita (Audiobook):  Vladimir Nabokov - narrated by Jeremy Irons...oh, what a narration!
  • Carrie (Audiobook):  Stephen King - disappointing narration by Sissy Spacek
  • Scat:  Carl Hiassen - not with Sidharta, but inspired by Sidharta - as always with Hiassen, a sweet book about nutty characters motivated by environmental issues, appropriate for the PG-13 crowd.
  • Lady Windermere's Fan:  Oscar Wilde
  • A Woman of No Importance:  Oscar Wilde - Silly Oscar!  Thinking Americans are so sensible and meritocratic!
  • The Pickwick Papers(Audiobook):  Charles Dickens - I started reading this a number of years ago and found it rather insufferable - decided to try again.  I think I'd still think it was fairly insufferable if it weren't for the excellent narration.  So obsessed with sex, for a Victorian novel :-)
  • And this year I'm going to claim the equivalent of at least one novel in the form of short stories and excerpts of works by members of my very talented writing group and Sharpening the Quill writers' workshop.  I'm sure it's been at least 150-200K words.
Started
  • The Teaching Company's course Peloponnesian War (Audiobook):  Kenneth Harl
  • Catching Fire:  Suzanne Collins
  • * Remix:  Lawrence Lessig - interesting book...just suffered from being a paper copy
  • House of the Spirits:  Isabel Allende - physical copy got taken away from me in the middle, by Annapurna, who was reading it for school
  • The Autobiography of Mark Twain - Volume 1 (Audiobook): Mark Twain - I had to drop off after about disk 7 (of about 20)...apparently one of Mark Twain's reservations about writing an autobiography was that he was afraid he wouldn't be able to bring himself to tell the truth, the whole truth and nothing but the truth. "Any journal that is intended for publication – even in 100 years' time – is probably in some way compromised. The only person I can think of who got close to an unexpurgated truth is Samuel Pepys, and that's because his diaries were never meant to be read." Well...all I can say is...he was right, at least in his own case. The bits I read were pretty self-aggrandizing, veiled in a false modesty. Also, it seems that Twain made many attempts at autobiography, which the editors have tried to compile in a single authoritative collection, liberally doused with their commentary. The end result, in my opinion, is a choppy, unreadable mish-mosh that is more like a PhD thesis than autobiography. It's got a lot of Twain's entertaining writing, but it's no Huck Finn. And it bothers me that I can't even tell if I actually got to "the" autobiography, or if everything I was listening to was introductory/related text. I think I didn't get to the main corpus, but I can't be sure.
  • Shirley:  Charlotte Bronte - still working on it - it's no Jane Eyre, but there's some interesting historical context
  • The Reason I Jump:  Naoki Higashida/translation by David Mitchell of Cloud Atlas fame - sweet book by a 13 year old autistic boy, explaining his thought process, and a plea for patience and understanding
  • The Island of Dr. Moreau:  H.G. Wells - read this mostly at the gym :-)  Gonna have to read it with Sidharta, next :-D
  • The Angel's Game (audiobook):  Carlos Ruiz Zafon - I think this is going to be a *:  lovely writing, metafiction, tormented author as protagonist - what could be bad?  It came before The Prisoner of Heaven, but it doesn't seem to matter that I read them out of order, though I am having some maddening moments trying to remember details from the other one.
And with Sidharta:
  • The Pinhoe Egg:  Diana Wynne Jones (started)
  • The Pilgrims of Rayne (Book 8 of the Bobby Pendragon series):  D.J. Machale (Parts - he read a bunch of it himself and then got Bobby Pendragoned out, I think)
  • Lots of Calvin & Hobbes (no year would be complete without this)
  • Some Grimm's Fairy Tales
  • Flush:  Carl Hiassen (part - he finished it himself)
  • Hoot:  Carl Hiassen (part - he finished it himself)
  • Biography of a Grizzly:  Ernest Seton-Thompson
  • Things Not Seen:  Andrew Clements (started...he got bored...I don't know why...seems like a great story)
  • The Prince and the Pauper:  Mark Twain - I was very surprised he allowed us to finish this one, but he really seemed to enjoy it.
  • Alice's Adventures in Wonderland:  Lewis Caroll (started)
  • The Adventures of Huckleberry Finn:  Mark Twain (Can't believe we got through this, but he loved it.  What can I say? He's a man of good literary taste.)
  • The Adventures of Tom Sawyer:  Mark Twain (started - still working on it.)

Thursday, September 19, 2013

When I'm right, I'm right

The punchline of a shaggy dog story that tormented my childhood was "Patience, jackass, patience." Words I continue to aspire to live by.

As I predicted (alas, over a month ago...I have been very negligent lately), NSA has, indeed, been collecting credit card data, through a program called...wait for it..."Follow the Money" capturing data in a system called "Tracfin". It was just a matter of time and patience until such a system was uncovered.

According to one presentation, the NSA sought to access Visa transactions for customers in Europe, the Middle East and Africa. In a statement, Visa said it was not aware of unauthorized access to its network.....The NSA's Tracfin data also contained information from the Society for Worldwide Interbank Financial Telecommunication, or SWIFT. SWIFT, a cooperative owned by around 8,000 financial institutions, runs a messaging service that enables worldwide financial transactions between banks.
This one was so bad that even GCHQ balked:
Snowden also revealed documents from GCHQ that showed that the UK intelligence agency had misgivings about the NSA’s Follow the Money program. The GCHQ questioned the legality of monitoring bulk data of personal financial information that didn’t necessarily pertain to national security risks.
Apparently "Der Spiegel reported that SWIFT was a target of spying by the NSA's "tailored access operations" division" The tailored access operations division, as I understand it, is responsible for the "good" kind of surveillance - more technically challenging, more labor intensive, more expensive, and therefore much more targeted at individuals we actually have some reason for suspecting. I predict that there will be further revelations of systems bulk collecting credit card data, outside of the scope of TAO.

I will continue to hope for vindication in my earlier prediction that Snowden will produce evidence of misuse of collected information to the detriment of American security.  So far, the speculateddocumented and derided misuse has been limited to...um...horny agents.

Thursday, August 1, 2013

More hypotheses about Snowden's information

Well, so far, my last prediction about where the Snowden leaks might lead hasn't come to pass.  But undaunted, I forge ahead with new predictions.

So far, the information that's been released only relates to phone and internet traffic data.  That's all very well and good for the NSA, but I am astounded that as yet there has been no talk of credit card information. I cannot imagine that purchases by targeted individuals would not be of interest.  In a certain sense, the purchases themselves are metadata (where, when, how much spent, etc.)  I also imagine the "content" would be of interest, as well -- what is the target purchasing?  Fertilizer?  Pressure cookers?  One way plane tickets?  Contributions to political candidates?  And it's not like that information isn't available -- all those marketing analytics spyware thingies and databases are already out there, and the NSA would just have to make some secret deal with those companies (nah!) to access that sort of data.  But we haven't heard about it, so far.  I have to assume (a) that Glenn Greewald just hasn't released those documents yet or (b) Snowden was only supporting telecom-based systems, and there are different staff who support the credit card data systems used by NSA.

I predict we will eventually hear about the NSA groping masses of credit card data.

Sunday, July 21, 2013

Ice cream maker recipes

Last year, Sidharta talked me into getting an ice cream maker.  We had some good success, but didn't really push the envelope.  This year we took it up a notch.

We've had fantastic success, so far, with Raspberry Sorbet, Peach Sorbet and Papaya Ice Cream.  If you have an ice cream maker...you can try the below.  If you don't:  get one!  It's pretty cheap, and there's just no comparison.  The annoying part is finding space in the freezer for the bowl.

Black Raspberry Sorbet - I was stupid enough not to write the recipe down, but I got it off the internet, so I trust to finding it again.  It's mostly a question of finding the right ratio of raspberries to sugar and water.  And removing the seeds (a major pain, but worth it).  I don't think I put anything else in, though I thought about some cardamom.  It goes wonderfully with a little chocolate ice cream.

Peach Sorbet - my own recipe:
- 10 smallish-medium peaches - very ripe, on the verge of overripe
- 1 stick of cinnamon
- 3/4 cup simple syrup (made from equal parts sugar and water)
- juice from 1/2 lime
- strawberry chunks (optional)

I made the simple syrup by using 3/4 cup sugar and 3/4 cup water and boiling with the cinnamon stick.  I used 3/4 cup of the resulting syrup.

I peeled the peaches, chopped them to remove the pits and threw them in the blender to puree them.  Then threw in the syrup and lime juice and blended some more.  This batter should probably be chilled (but I don't remember if I did or not).

Then into the ice cream maker.  When it's done you can throw in some pieces of strawberry for texture.  I threw them in  the ice cream maker when it wasn't quite done, and the strawberries got slightly mashed into the sorbet.

I don't know exactly how much this produced but probably around 3 cups.

Papaya Ice Cream - my own recipe (warning, hi fat special):
I decided I wanted papaya ice cream while I was out shopping for fruits and vegetables and saw some nice papayas.  So I bought a papaya and some cream, but had no idea of what was needed.  When I got home I searched the internet for recipes and found surprisingly few, so I made it up.

- Papaya - 2 cups of puree - I don't know how to tell you how much to buy - I bought one of the large Mexican papayas that was probably about 2 pounds and used maybe about 1/3 of it.  I know I used 2 cups of puree
- 1/2 cup sugar
- 2 tablespoons unsweetened finely grated coconut
- zest of about 1/2 lime
- 2 cups heavy cream
- chocolate chips (optional)

I pureed the papaya first, and then added the sugar and coconut and lime in the blender and then added the cream. And blended until it was nice and even.  Again, it should probably be chilled, but I didn't.  Straight into the ice cream maker.  It makes a lovely color.

Again...not sure how much this made, especially after extensive sampling, but I'll guess around 3  or 4 cups.

I threw some chocolate chips into part of the ice cream, and kept some without.  I like it both ways, though you can never really taste chocolate chips well in ice cream.

I think a bit of cardamom would be nice here, too, instead of chocolate chips.  I didn't try it.  And I saw some recipes on the internet that involved use of a can of coconut milk which I didn't have, but they sounded nice.

Thursday, June 27, 2013

The origin of evil genius

I guess I always assumed that the term "evil genius" was a Batman or James Bond kind of term, a reflection of the deranged excesses of 20th Century greed and technology.  Perhaps in the cartoon usage it is.  But I ran across a much older use of this phrase.

I am currently reading (make that slogging through) Camilla by Fanny Burney.  In it, the sweet young heroine, Camilla, in love with the wealthy, but apparently indifferent Edgar Mandelbert, is trying to fend off the advances of the wealthy and somewhat annoying Sir Sedley Clarendel, who is being egged on in his suit by their mutual friend Mrs. Arlbery.
'O, Mrs. Arlbery!' she cried, 'lend me, I beseech you, some aid, and spare me, in pity, your raillery! Sir Sedley, I fear, greatly mistakes me; set him right, I conjure you....' 
'Me, my dear? and do you think if some happy fatality is at work at this moment to force you to your good, I will come forth, like your evil genius, to counteract its operations?'
Wiktionary provides this sense as its first definition of evil genius: The spirit each person is believed to have in attendance, according to certain religious or mythological traditions, which tries to negatively influence him, and is opposed by one's good genius; loosely, someone who is a bad influence.

Tuesday, June 11, 2013

Snowden's next step?

Wanna know how the Snowden story can get more interesting than it already is?

Mr. Snowden has enumerated the vast breadth of secret intelligence data that he had access to as a systems administrator.  No surprises there.  Systems administrators are inherently the most trusted of insiders, and in general, take their trust extremely seriously.  A sysadmin is kind of like your gynecologist...you want your GYN to check you thoroughly for the purposes of keeping your privates healthy, but you kind of have to take it on faith that they don't have hidden cameras in the examination room taking pictures of your privates to post on Women-I-Have-Seen.com.

But that's where the analogy ends.

Because a sysadmin also has access to a second kind of information that may be even more interesting in this case.  That would be the forensic metadata.

Yup.  Just as the NSA appears to have been collecting metadata about you (who you called, when you called, and possibly where you were physically calling from), so any system worth its salt will log information about who accessed it, what they accessed, when they accessed it and where they accessed it from.  This is an important fraud and abuse prevention feature, especially in systems that maintain highly sensitive data. For example, if your medical insurance records got posted on a public website, you'd want some way to go back to your provider and demand accountability about how your records got there.  You'd want them to be able to track down the person who accessed your records and fire them.  Along with giving you a $27 million settlement.

Normal system users aren't interested in the logging information.  They just want to get at the main information that the system manages (in Snowden's case, the actual surveillance information).  An intelligence analyst normally doesn't care what subject the guy in the next cubicle is tracking, just get me information about my subject.

Snowden, however, as part of his sysadmin job, would have been expected to assist with forensic examinations of system logs if fraud or misuse were ever suspected (or if they wanted to nail some analyst for any reason).  So he would almost certainly have had access to all sorts of log metadata (and systems for analyzing the metadata) about which analysts accessed what when.

Now if things at NSA are anything like they were at State during Bradley Manning's time, I think we can reasonably expect that WAY, WAY more people have access to more sensitive data than they should.  Which means that it's quite likely that Snowden's not the only one leaking information.  He's just the only one to come out and talk about it in the public interest.

Now, if he really wanted to muddy the waters and confuse the people who are inclined to call him a traitor, here's what he'd do.

Before he left, he would examine the log files and identify a few bad actors who had clearly accessed information they could have no work-related reason for accessing.  Things like analyst Jimmy Jones, (assigned to the Africa desk) downloading a report on the calling history of the US ambassador to Russia (which happens to include numerous calls to his Chinese mistress, who lives in Thailand).  And Jimmy's access of reports on several prominent US businessmen who have been trying to set up businesses in Russia.  And Jimmy's access of data on members of Pussy Riot.  Suddenly, it's starting to look like maybe Jimmy's helping out some Russian contacts, even though he's supposed to be focusing on the Congo.

If Snowden is smart (and he seems to be a bright young man, capable of thinking more than one move ahead), he will have assembled a certain number of cases like this.  He will hand the documentation about these cases (log files, analysis of them, etc.) to Glenn Greenwald & Co. The journalists will then publish a sanitized version of them (removing names of targets, etc.), clearly demonstrating that this data is being actively used to harm American interests, while not showing any demonstrable benefit in hunting terrorists.  They will also send the unsanitized analysis to trusted members of the NSA/intelligence community, so they can take action on the rogue elements.  If there is anyone un-corrupt enough to do so.

If it's potentially so easy for random analysts to access stuff they shouldn't, you might wonder what is to stop any analyst from accessing the records of Kim Kardashian or Sergey Brin or Obama or the annoying neighbor next door.  Since I am not privy to the technical details of the NSA systems, I cannot answer that with any certainty, but I can guess at some of the controls.

First of all, even though the analysts are not interested in viewing the log metadata, they are almost certainly aware of its existence.  They know, better than anyone, that Big Brother is watching, and if they are caught with their hands in the cookie jar, they will get in trouble, possibly to the extent of jail time.  There may even be the equivalent of a burglar alarm built in to the systems, such that if an analyst does something naughty, an alarm goes off somewhere, and somebody investigates what's going on and fires/prosecutes the analyst who's peeking at stuff they shouldn't be.

HOWEVER, there are a couple of problems with relying on this.  Think about getting an alarm system installed in your house.  ADT charges a fair amount for their alarm monitoring services.  And they don't respond to every alarm.  If your alarm goes off and it looks like you opened your door without turning off the system, they don't bother.  An alarm system has two choices:  make sure to react to all the naughty accesses, but in the process also react to many, many things that look like they might be naughty but are actually legitimate OR don't bother unless you're fairly sure that the access is naughty, but potentially miss a bunch that look like they might be legitimate but are actually naughty.  Similarly, in NSA's system, the vast majority of accesses would be legitimate.  Sometimes an analyst may raise an alert as they legitimately access data for an unusual connection to their case.  Less often (we hope) they may raise an alert as they access data about their annoying neighbor.  The question is...who's going to respond to all the alerts (mostly false alarms) generated by hundreds or thousands of analysts working for the NSA?  System logs work much better AFTER an abuse has been discovered, and you need to track down/document whodunit.  They don't prevent the abuse (except by fear), and they don't work at all if nobody looks at them much.  Which a rogue analyst would also know.

This country is frankly not in the mood to address this issue.  Americans want to catch all the bad guys (terrorists and people abusing the intelligence systems), but don't want to pay for the effort.

We are told there are more bombshells to come.  I predict that revelations of data misuse or that sort of thing will be included.

Friday, June 7, 2013

The first person to march to a different drummer

I've always been a fan of Frost's poem "The Road Not Taken."  It suggests an approach to life that I aspire to:

Two roads diverged in a wood, and I,
I took the one less traveled by,
And that has made all the difference.
A traveler down that road would undoubtedly be marching to her own drumbeat.  And as I recently discovered, that image comes to us, courtesy of the Transcendentalist Henry David Thoreau.  I'm no authority on Thoreau, but from what I know of him, I'd have to guess that this quote from Walden probably expresses his quintessence:
"If a man does not keep pace with his companions, perhaps it is because he hears a different drummer. Let him step to the music which he hears, however measured or far away."
So Sidharta!  I like an extended version of that passage, as well:
"Why should we be in such desperate haste to succeed and in such desperate enterprises? If a man does not keep pace with his companions, perhaps it is because he hears a different drummer. Let him step to the music which he hears, however measured or far away. It is not important that he should mature as soon as an apple tree or an oak. Shall he turn his spring into summer? If the condition of things which we were made for is not yet, what were any reality which we can substitute?"
Food for thought in our Race to Nowhere culture.

Saturday, March 23, 2013

Review of "Broken Ballots: Will Your Vote Count"

Broken Ballots: Will Your Vote Count?,” by Douglas W. Jones and Barbara Simons, is a tour de force review of the history and current state of voting technology security. The authors (who were key players in security reviews of a number of electronic voting systems, as well as in voting technology policy discussions at the local and national level) provide us with unique insights into the technical, procedural, policy, and even political difficulties of assuring election integrity.

The central challenge in voting systems, from a security perspective, is the absolute requirement for ballot secrecy (to prevent coercion or vote-buying) while ensuring that all eligible voters are allowed to vote, but no more than once per election. The notion of an eligible voter implies some sort of authentication system, while secrecy demands that in spite of authentication, ballots not be linkable to individual voters. Requirements for massive scalability, efficient vote tabulation, usability, accessibility for voters with a range of disabilities, ballots containing multiple races, and cost-effectiveness impose additional complexity on voting systems. This book explores how technology has attempted to achieve these conflicting goals, and how the complexity has often created vulnerabilities that threaten election integrity, which in turn, has required technology to evolve.

“Broken Ballots” documents a large number of case studies of security concerns on a variety of electronic voting technologies, including Direct Recording Electronic (DRE) and Internet-based systems. An entire chapter is devoted to the missteps of Diebold, “the poster child of much that is wrong with DREs”, including overt partisanship suggesting vote rigging, hiding poor coding and deployment practices behind a screen of “trade secrecy”, circumventing the voting software Independent Testing Authority and certification process, use of programmers who had previously been convicted of computer-based fraud, and harassment of independent researchers who disclosed the existence of vulnerabilities. Another chapter is devoted to risks associated with Internet voting, quite similar to those characteristic of e-commerce, including server-based attacks, client-side malware, phishing, counterfeit sites, man-in-the-middle attacks, DDoS, the loss of ballot secrecy (a risk specific to voting).

Lest we be tempted to return to simpler times before touch screens and the Internet, the authors provide a fascinating history of voting technologies and attacks on them, from voice vote to ballot boxes to punch cards. (Who knew that lever voting machines were susceptible to jammed gears?)

The authors describe the challenges associated with developing meaningful voting standards and critique a number of failed attempts (such as the 2002 Help America Vote Act and several of its revisions.) They leave us with a number of concrete recommendations for improving the integrity and transparency of elections, including:
• Development of uniform election standards (technological as well as procedural requirements)
• Technological support for audits and mandatory post-election audits
• Greater vendor accountability
• Revamping voter enfranchisement laws
• Explicitly forbidding Internet (as well as fax and phone) voting until significant security breakthroughs have been achieved

“Broken Ballots” should be largely accessible to a non-technical audience, but those with IT experience will respond more viscerally to the cringe-worthy practices it documents. The CISSP will appreciate the thoroughness of the analysis, as it touches on practically every domain of the CBK, from physical security to secure coding practices to governance. The case studies it cites are primarily (though not exclusively) US-based, but the principles these illustrate are universal. It is not a quick read, and at times feels a bit shopping-listy, but it is well-worth working through it, and should be of interest to every adult citizen of any country that conducts elections.


This review appears on the ISC2 book review section.

Monday, March 11, 2013

Inquiring minds want to know

So don't ask me why...really don't...I have no idea...but I was struck this morning by the similarity between the words "require" and "quiero" (Spanish for "I want"). Perhaps I've been working on requirements too much lately. In any case, what is a requirement, after all, but something I want?

In such intriguing cases, I generally resort to my handy dandy Random House College Dictionary (acquired when I was in Grad School) which often provides helpful etymological information. Paydirt!

Unsurprisingly, Require, Acquire, Inquire, Query, Quest, Question all originate from the Latin quaerere, to seek, ask.

That's as distinguished from Quarry, which, according to Merriam Webster Online (now that I've put away my dictionary) is derived from the French cuir (skin, hide), which, itself, is derived from the Latin corium (which also gives us Excoriate). Which is weird because if you'd asked me, I'd have said that a lot of hunters seek quarry. In fact one of the definitions that Merriam Webster offers for quarry is "one that is sought or pursued." And then there's the stone quarry, which is totally unrelated and comes from the Latin quadrus meaning square (as in a square block of stone).

Who gets to decide the official etymology, anyway?