Thursday, April 10, 2008

OS Smackdown: Linux vs. Mac OS X vs. Windows Vista vs. Windows XP

Computerworld throws together another great article when they asked four experts to lay out their best arguments in support of their desktop operating systems of choice:

Each is of these guys are positive that their choice in operating system is the best and they try their hardest to convince you that they are right. These are not rational, disengaged reviews; these are opinionated essays meant to sway your point of view and I will say they do make some interesting arguments for their side.
When you've read all the arguments, you make the call by voting in their reader poll -- and of course your own arguments or comments are welcome.

New Weapon On Terrorism Hand-held Lie Detector

Move over M16 the U.S. Army soldiers in Afghanistan have a new weapon to fight terrorism, the lie detector. Starting this month U.S. Army soldiers in Afghanistan will be issued hand-held lie detectors pushing the debate over accuracy of the polygraph to the battlefront.

According to MSNBC.com the soldiers will be issued the new device, known by the acronym PCASS, for Preliminary Credibility Assessment Screening System. Which uses a commercial TDS Ranger hand-held personal digital assistant with three wires connected to sensors attached to the hand.

The Defense Department says the portable device isn't perfect, but is accurate enough to save American lives by screening local police officers, interpreters and allied forces for access to U.S. military bases, and by helping narrow the list of suspects after a roadside bombing.

“We're not promising perfection — we've been very careful in that,” said Donald Krapohl, special assistant to the director at the Defense Academy for Credibility Assessment, the midwife for the new device. “What we are promising is that, if it's properly used, it will improve over what they are currently doing.”

At least one prominent scientist says the lie detector will actually put U.S. soldiers in harm's way, because they will put too much faith in a technology that is unreliable.

"I don't understand how anybody could think that this is ready for deployment," said statistics professor Stephen E. Fienberg, who headed a 2003 study by the National Academy of Sciences that found insufficient scientific evidence to support using polygraphs for national security.

How it all works

An interpreter will ask a series of 20 or so questions in Persian, Arabic or whichever language is needed. Intermingled between the actual questions will be some test questions "Are the lights on in this room?", "Do you intend to answer my questions truthfully?", "is the sun shining?" "Are you a member of the Taliban?" ect. The operator will punch in each answer and, after a delay of a minute or so for processing, the screen will display the results: "Green," if it thinks the person has told the truth, "Red" for deception, and "Yellow" if it can't decide.




The PCASS uses two electrodes to attempt to measure stress through changes in electrical conductivity of the skin. It also gauges cardiovascular activity through with a pulse oximeter clipped to a fingertip. Unlike the polygraph, the PCASS does not measure changes in the rate of breathing, and it has no way to detect countermeasures, or efforts to fool the machine, such as by making unusual movements.



Accuracy

Much debate has been made over the device’s accuracy therefore questioning its usefulness and effectiveness.

The Pentagon says the PCASS is 82 to 90 percent accurate. But Pentagon studies obtained by MSNBC.com show a more complicated picture: In calculating its accuracy, the scientists conducting the tests discarded the yellow screens, or inconclusive readings. If you take into account the yellow screens, the PCASS accuracy rate in the three Pentagon-funded tests drops to the level of 63 to 79 percent, a result which is less than effective.

My thoughts

Given the discrepancies in the statistics and the fact that terrorists already know these are being used and are training to combat the effectiveness I don't see much point behind deploying them. You put a lot of lives at risk when you rely on something that is less than effective, or something that is easily circumvented.

Read more of the story from MSNBC.com

Vegas Using RFID To Keep Tabs On Bartenders, Chips And Maybe Even You

Several bars in "sin City" (and probably bars near you) use RFID tracking chips that measure the flow and amount of liquor in each drink poured. Tucked away in the pour spouts are small chips that act as part of the loss-control system. When linked to point-of-sale systems you can produce information on types of drinks poured, amount of alcohol used ect.

According to hospitality industry experts, every year in the United States, over $7 billion is lost due to “liquor shrinkage.” What is “liquor shrinkage?” It happens when bartenders give out free drinks, "overpour" (intentionally making drinks too strong), or make mistakes as they mix cocktails. It also happens when bottles of liquor disappear from bar storage areas due to theft. RFID tracking can dramatically cut those losses.

The drawbacks, at least from the bartenders point of views is that tracking of sales and limiting pours threatens the long-standing practice of giving bartenders generous tips in order to get generous drinks. While not a concern for bar owners, bartenders largely make their livings off of these tips.

RFID inventory control and liquor management systems are hardly revolutionary, however these are just a few uses Vegas has found for tiny RFID tracking devices.


RFID chips are now being placed in some casino chips, and according to a recent Computerworld article the MGM Mirage is looking at room keys that not only open doors, but also keep track of customer preferences and gaming play. This would essentially allow the hotel to monitor every aspect of a gamers stay.

We all know casinos currently film your every last move as well as track every bet but adding RFID tags to the mix would also mean they could track you outside the casino walls. An RFID tag in your room key could be used to pin point your exact location anywhere within range of their service, and with assistance from other casinos they could track any and every activity while in another location.

A scary though to some, a fact of casino life to others, certainly anyone not willing to give up a certain level of privacy shouldn't be in a Vegas casino.

Technology and Vegas seem to go hand in hand and casino are no exception. They are constantly working on new facial recognition technologies to track players as well as potential cheats. The latest in technology can be seen everywhere from the fountains at the Bellagio, to the newest in touchscreen slots.

Some of the newest technology used is algorithms that can predict customer wants. Sending information to systems that will respond to newly arrived hotel guests by automatically turning on lights, adjusting blinds and setting the television to the customer's preferred language. The algorithms will take into account everything you've done, bought, ate and drank and will have that at your finger tips prior to your arrival

"What we want to be able to do is predict the future." Predictive modeling of the hotel's guests' activities and requests makes the algorithms that sit on top of the data warehouse a "killer app for us," says Tom Peck MGM Mirage's senior vice president and CIO.

Yahoo Teaming Up With AOL? Microsoft to Team With News Corp?

Yahoo Inc appears to be running out of alternatives to accepting Microsoft's takeover offer, or is it. According to Reuters Yahoo is closing in on a deal with Time Warner's AOL unit. In the mean time News Corp is reportedly considering joining Microsoft in a bid for Yahoo a combination which would bring together three of the biggest Web site publishers on the Internet: Yahoo, Microsoft's MSN and News Corp's MySpace

Reports on any plans from the Microsoft were sketchy to say the least, so its on exactly how any of the deals might be structured. However the article says the Yahoo's talks with Time Warner are nearing an agreement. The deal would see Time Warner adding AOL's business, excluding its legacy dial-up Internet access operations, into a combined Yahoo company. Yahoo would receive cash from Time Warner in exchange for 20 percent of a combined Yahoo-AOL, the source said.

The Wall Street Journal cited sources saying Yahoo would use the Time Warner cash and other funds to buy back several billion dollars worth of Yahoo stock at a price somewhere in the middle of the range between $30 and $40 a share.

To add yet another wrinkle to the equation Reuters also reports Yahoo is going to begin testing the use of Google search ads. A move which Microsoft claims is anti-competitive. In a statement, Microsoft General Counsel Brad Smith said "Yahoo and Google would consolidate over 90 percent of the search advertising market in Google's hands" thus creating a virtual stranglehold on the advertising market.

Wednesday, April 09, 2008

Turning Great Video Games Into Ok Films

Hollywood has tried several times to turn some of our favorite games into good movies, however most of the time these turn into huge flops. Lets face it some games just aren't meant to be movies. Movie moguls see a widely popular game and dollar signs light up.

While some game to movie projects have turned out to be very successful the majority have not. In general video games aren't written to be live action movies. For the most part the plots, story lines and character development just aren't there. However its not the game producers fault when movies flop. Movie producers, who in my opinion have never played the games, have issues sticking to the very thin story lines and try to take development too far. Scripting/writing for many of the movies is atrocious and casting for many of the roles has been less than stellar.

“Few games have translated well to film,” says Michael Pachter, videogame analyst for Wedbush Morgan Securities. “'Doom' was a flop, as were the second 'Mortal Kombat' and 'Super Mario Bros.' movies. 'Resident Evil' has done well, as have the Lara Croft films, so I’d say it’s hit and miss.”

The next great game to attack the big screen is "Max Payne" which supposedly will be released in Oct, with Mark Wahlberg in the starring role. The film will be directed by John Moore (Behind Enemy Lines, Flight of the Phoenix, and The Omen). Fans have had a mixed reception of some of the casting as well as some of the behind the scenes calls.

John Moore is a less-than-acclaimed director and then there is first-time screenwriter Beau Thorne was hired to pen the script. Add to that the casting of Chris O'Donnell for a major role and the movie starts to slide a little.

MSNBC's article "Turning good video games into great films" explores some of the ins and out of transporting video games into live action films.

Some of the people behind the scenes of "Max Payne" are working hard to see that game to movie porting works out better than in the past.

In June 2007, Hollywood producer Scott Faye, owner of Depth Entertainment; Scott Miller, also head of game developer 3D Realms; and Jim Perkins, former CEO of game developer-publisher Arush Entertainment, formed Radar Group.

Rather than creating a game, then licensing it as a film, or vice versa, Radar will cultivate story lines—“storyverses” in company parlance—that transcend any one medium, whether linear or interactive. From there, they can spin out movies, videogames, comic books, and anything else that might emerge.

“I think that because we’re starting at the outset, both cultures will have an incredibly solid foundation for an ongoing evergreen franchise,” says Faye.

Usually, a movie based on a game gets green-lit only after the game has been released and built an audience. But Depth Entertainment is already shopping Radar’s stories around to studios—even though the games are still a few years away from hitting shelves. Merchandising and expanding an intellectual property from the get-go has been a long-standing Hollywood strategy, but the concept is still new in the game business, where all the focus generally remains on creating the game.

EA & Epic Extend Unreal Engine 3 Agreement

Electronic Arts has announced that it is extending its current licensing agreement with Epic Games for use of their Unreal Engine 3. The new deal will allow EA to use UE3 in more than 5 upcoming games, although specifics on which titles those may be are still unknown.

Electronic Arts originally licensed use of the gaming engine back in 2006 and currently publishes several titles under that license including Medal Of Honor Airborne and Army Of Two.

"With the largest and most talented studio operation in the world, it's critical for us to give our studio teams the best tools they need to make great games," Frank Gibeau, President of the EA Games Label said, "This agreement reflects our commitment to Epic's technology which, in combination with our own cutting-edge systems, allows us to create ground breaking hits."

Tuesday, April 08, 2008

Internet Scams At A New High

According to reports from the Internet Crime Complaint Center (IC3) money lost in Internet crimes reached nearly $240 million.

The 2007 Internet Crime Report compiled by the Internet Crime Complaint Center states they received 206,884 complaints of crimes perpetrated over the Internet during 2007. Of the complaints received, more than 90,000 were referred to law enforcement around the nation, amounting to nearly $240 million in reported losses. This represents a $40 million increase in reported losses from complaints referred to law enforcement in 2006.

The data shows that more men than women were scammed and at a costlier rate. The average loss for men was $765; for women, $552 men lost $1.67 to every $1 lost by women in online fraud.

Age was also a key factor in relation to losses, victims in their 20s lost $385 on average while people over 60 reported lost an average $760 per scam.

Although Internet auction fraud was the most widely reported complaint, others cited in the report include fraudulent activity such as non-delivery of purchases and credit/debit card fraud, and non-fraudulent activity such as computer intrusions, spam/unsolicited e-mail, and child pornography. In an effort to raise public awareness, the report also describes the characteristics of commonly reported scams such as those involving the purchase or sale of pets, check scams, e-mail spam, and online dating fraud.

The Internet Crime Complaint Center (IC3) is a partnership between the Federal Bureau of Investigation (FBI), the National White Collar Crime Center (NW3C), and the Bureau of Justice Assistance (BJA). They serve as the governments clearinghouse for all complaints involving Internet related crimes

Monday, April 07, 2008

Stephen King Speaks Out Against Video Game Legislation

Popular Horror Novelist Stephen King has criticized plans by legislators in Massachusetts to restrict or ban the sale of video games that depict violence, nudity or sexual content to buyers under 18.

HB 1423, is the Massachusetts bill that would seek the restrict or ban the sale of video games that depict violence to buyers under 18. Among other things, it seeks to define "harmful to minors" in terms of whether the game is "obscene".

(1) describes or represents nudity, sexual conduct or sexual excitement, so as to appeal predominantly to the prurient interest of minors; (2) depicts violence in a manner patently offensive to prevailing standards in the adult community, so as to appeal predominantly to the morbid interest in violence of minors; (3) is patently contrary to prevailing standards of adults in the county where the offense was committed as to suitable material for such minors; and (4) lacks serious literary, artistic, political or scientific value for minors.


Mr King spoke out against the ban in his recent Entertainment Weekly column.

"I'm no fan of videogames; pretty much gave them up in the late '70s or early '80s," says King, "so, nope — videogames are not my thing. Nor am I some kind of raving political nutcase. But when I heard about HB 1423, which happens to be a bill pending in the Massachusetts state legislature, I still hit the roof."

''What really makes me insane is how eager politicians are to use the pop culture as a whipping boy. It's easy for them, even sort of fun, because the pop-cult always hollers nice and loud. Also, it allows legislators to ignore the elephants in the living room.''


King's resentment towards government intrusion is one that is shared by many. As are his views on banning the sale of video games to minors. In fact several of these laws have recently been blocked or overturned, including bills in Minneapolis and Louisiana.

In my opinion the government needs to stop the slew of senseless legislation aimed at "parenting". Let parents be parents, they should know by now that they need to be proactive in their children's lives. We don't need government intrusion and bureaucracy telling us how to live.

AMD Announces Job Cuts

amd logoAMD announced this afternoon that it would cut 10 percent of its work force, or about 1,680 jobs.

Citing lower-than-expected sales across its business, AMD estimated revenue for the quarter which ended March 29 at about $1.5 billion, well below the average analyst forecast of $1.62 billion.

AMD has been a strong competitor fighting Intel for a share of the CPU market for years. However their newest products have fallen short of consumer expectation leading to a decline in sales. The recent $5.6 billion acquisition of graphics chip maker ATI Technologies Inc., has pushed the companies even lower. AMD recently said is worth about 30 percent less than when it was acquired.

AMD viewed the acquisition as a key way to attack Intel and incorporate better graphics capabilities into its chips. The reviews of the newly released 780g chipset show great promise, however both Intel and Nvidia have taken strangle holds on the market.

Nvidia's recent introductions, the 9600gt , 9800gtx and 9800gx2 have proven to be better, faster and cheaper than most offerings from Ati.

All the while Intel has seated itself as the top dog with several outstanding dual and quad core cpu's. Their 45 nanometer chips are trumping anything AMD has been able to release so far. Lower power consumption and higher performance are hard to beat.

Its not all roses for Intel however. They also issued warnings about the first quarter profits. In early March, Intel cut its gross margin forecast, citing weaker pricing for NAND memory chips used in consumer electronics, such as digital music players and cell phones. Intel is scheduled to report results on April 15.

Digg Back In Service

One of our favorite news/social sites Digg.com was out of service for several hours this afternoon. The following statement was posted by Digg's Eli White on the Digg Blog

Hey everyone,

We know that we are currently having some issues on Digg at the moment. Submissions, commenting, digging and other actions may sometimes fail. We have a crack team assigned to it and will be making
numerous fixes as soon as possible to get Digg back to 100% for ya.

Please bear with us …

Eli


I'm sure we are all glad to see the Digg staff got things squared away and the site is back up and running smoothly.

Blogging A High Risk Occupation?

According to a recent report from the New York Times the stressful lives that us bloggers lead may put us into the same "dangerous jobs" category as coal miners and Alaskan crab fisherman. The article says the stress accumulated from long exhaustive hours of blogging can lead to serious medical conditions, even death.

Recently well know tech blogger Russell Shaw died at the age of 60 of a heart attack. In December, another tech blogger, Marc Orchant, died at 50 of a massive coronary. A third, Om Malik, 41, survived his heart attack.

Other bloggers complain of weight loss or gain, sleep disorders, exhaustion and other maladies born of the nonstop strain of producing for a news and information cycle that is as always-on as the Internet. I can attest first hand that I often find myself spending hours reading through news and information looking for stories to post however I've never seen the types of stresses they are implying.

The NY Times is quick to point out there is no official diagnosis of death by blogging, and the premature demise of two people obviously does not qualify as an epidemic.

Michael Arrington, the founder and co-editor of TechCrunch is quoted as saying he has gained 30 pounds in the last three years, developed a severe sleeping disorder and turned his home into an office for him and four employees. “At some point, I’ll have a nervous breakdown and be admitted to the hospital, or something else will happen.”

Popular blogger John Chow has a different take on things. He writes "The only thing I have to say about this story is, you got to be kidding me? No wonder the mainstream media is losing ground so badly to the Internet. Some 60 year old has a heart attack. It must be caused by blogging! I guess the fact that Om Malik weighs something like 400lbs has nothing to do with his heart attack, right?"

Travis Hudson, from PC world writes "I'm not too surprised by this report, but it's pretty obvious. Most bloggers have the opportunity to work out of their home, which many would assume is stress-free, but it's quite the opposite. Working from home lets you work all day and all night. There is no way to easily separate yourself from work."

I would in know way put my experiences up there with Pro-Bloggers Michael Arrington or Om Malik, I don't have deadlines, I don't have advertisers breathing down my neck, I don't have any outside influences in the way I blog. The opinions of my readers is the only concern I have.

But work is what you make of it, it doesn't matter if you are at home, in the office or on the road. As John Chow once said "One of the best things about being a blogger is it gives you the option to do it from anywhere in the world." If working from home starts to be stressful find another place. If you need to get out of the office, visit a Starbucks

John made $31k in March so if it works for him it'll definitely work for me.

Friday, April 04, 2008

Your ISP Is Watching Closer Than You Think

Reading that fine print might reveal that you have fewer rights than you realize.

MSNBC.com recently published an Associated Press article that made a few interesting discoveries in the fine print that most of use usually agree to without reading.

By now everyone should be aware that ISPs such as Comcast ad ATT have been watching their users and usage of P2P/file-sharing programs. However you might not be aware that they can go even further, reading your emails, blocking you from sites they deem inappropriate. They even reserve the right to block traffic and, for any reason, cut off a service.

The Associated Press reviewed the "Acceptable Use Policies" and "Terms of Service" of the nation's 10 largest ISPs — in all, 117 pages of contracts that leave few rights for subscribers.

During their review they discovered that AT&T Inc. had a blanket provision that stated their right to block any activity that causes the company "to be viewed unfavorably by others."

Jonathan Zittrain, professor of Internet governance and regulation at Oxford University is quoted as saying, "The idea that they would ever invoke it and point to it is nuts, especially since their terms of service already say they can cut you off for any reason and give you a refund for the balance of the month."

According to the A.P. AT&T removed the "unfavorably by others" after being asked about the reason behind it. Most subscribers wouldn't know that unless they checked the contract word for word. Which more than likely most didn't even know it was there to begin with.

Common clauses of ISP contracts

ISPs can read your e-mail
Practically all ISPs reserve the right to read your e-mails and look at the sites you visit. Yes read your "Terms of service" carefully, their is more than likely a stipulation in there that says they can without warning, probable cause or wiretap order open and read your emails.

Some ISPs, like AT&T Inc., make clear that they do not read their subscriber's traffic as a matter of course, but also that they need little or no excuse to begin doing so.

ISPs can block Web sites you visit

While this may be a difficult task and can certainly be circumvented they do hold the right to try to block the sites you visit. Comcast for one reserves the right to block or remove traffic it deems "inappropriate, regardless of whether this material or its dissemination is unlawful." They can use their sole discretion as to what they feel is "inappropriate".

ISPs can shut you down for too much traffic

For cable ISPs, up to 500 households may be sharing the capacity on a single line, and a few traffic hogs can slow the whole neighborhood down. Most people see the effects of this during "peak usage hours" you'll notice slow downs in service when lots of people are at home using their connections.

But rather than saying publicly how much traffic is too much, some cable companies keep their caps secret, and simply warn offenders individually. If that doesn't work, they're kicked off. And trust me they aren't shy about removing and banning you.

While for the average user it might be difficult to reach these bandwidth caps users that are downloading large amounts of high-quality video from the Internet or downloading larges quantities of files might find themselves reaching that limit. With the advent of high-definition Internet video set-top boxes like the Apple TV and the Vudu this could be a much more common issue.

More bannable offenses

Off course Spam, pornography and hate related content are always going to be on the top of the list. However you might not know that you could be banned and your account removed for simply allowing others to connect and browse the net. There are terms in most contracts that stipulate you and members of your household are the only ones allowed to use your connection.

Another offense many people are unaware of is using your pc and their connection for hosting your own website, mail server or file server. Most ISPs block the ports needed to host your own sites or servers at home, however there are a few that don't. Either way in many cases ISPs have written in clauses that disallow using their bandwidth in that fashion.

The one thing all this does make clear is that we all need to learn to take our time and fully read the contracts we are agreeing to. I know I am a guilty party, I might browse through them but I never read them in full. Then once an issue arises I dig out the contracts and spend hours trying to understand the exact terms.

iPhone Pwnage 1.0 Released

The iPhone Dev Team has released version 1.0 of its Pwnage utility.

Official Press Release
April 03, 2008

The “DevTeam” would like to announce the release of the OS X version of the PwnageTool application.

The team (and especially Wizdaz) have been working hard to bring you this release in as short a time as possible.

The plan (4 weeks ago) was to release a Mac tool only. This was decided because of the lack of reliable Mac filesystem tools on Windows, and the fact that the task of porting them would be too time consuming.

With that in mind the genius that is “cmw” stepped up to the plate and offered his services to the DevTeam. He proposed to provide a tool that would give the same functionality and User Interface as the Mac tool.

cmw has done an almost unthinkable task and ported the almost complete Pwnage Tool to Windows in a little under a week, and we would like to thank him for this unbelievable work. He is currently in the final test stages and hopefully this should be finished within the next 24 hours (but even he needs sleep and family time occasionally!) We'll post a link as soon as the testing has finished.

cmw's site is at http://www.iphonelinux.org

The Mac tool is available at http://www.iphone-dev.org

Thanks to Sal Iovine for the awesome Steve parody image, this is copyrighted material and is provided to the DevTeam under a Creative Commons Attribution No Derivative Works 3.0 Unported license, you can see more of his work at http://www.saliovine.blogspot.com/

ENDS


The Dev Team is a group of dedicated, “white hat” hackers trying to help the regualr folks out there get the most out of their iPhones. Their program Pwnage can do it all, unlocking, activating, and even Jailbreaking.

As you can see from their statement currently Pwnage only runs on OS X Tiger, however they have been working hard on a Windows version.

For more information checkout Crunch Gear's great article.

New Windows Coming Next Year?

Bill Gates said on Friday he expected the new version of Windows operating software, code-named Windows 7, to be released "sometime in the next year or so."

According the Reuters Microsoft has said it expected to release a new version of Windows approximately 3 years after the introduction of Vista. Last month we reported that Microsoft submitted Windows 7 for anti-trust review, that along with Gates' comments would put the numbers right in line.

I think we could probably see beta testing information popping up by the end of the year with full beta trials coming early next year.

Thursday, April 03, 2008

Judge Rules Against RIAA Subponea

Federal court judge Judge Nancy Gertner has dealt a blow to the Recording Industry Association of America, finding that merely exposing music files to the Internet is not copyright infringement.

"Merely because the defendant has 'completed all the steps necessary for distribution' does not necessarily mean that a distribution has actually occurred," wrote Gertner in her order. "As noted above, merely exposing music files to the Internet is not copyright infringement."


The judge did note that an "offer to distribute" is sufficient basis for a copyright infringement claim, which means that the RIAA can continue to make that allegation in its lawsuits. There is, however, a big difference between having evidence for a copyright infringement claim and showing by a preponderance of evidence that infringement actually took place.

More information

  • The full story from Ars Technica

  • The EFF's press release

  • PDF copy of judge Gertner's decision
  • Wednesday, April 02, 2008

    Madden NFL 09 Won't Reach PCs

    EA Sports president Peter Moore confirmed last week that the latest Madden game will not be coming to PC.

    "We knew that our decision to not develop this year's Madden for the PC would be an unpopular decision in some circles," said Moore in a blog post on Tuesday. He continues to say, "But I’ll reiterate what I said a couple of weeks ago in this space…the PC presents some very serious business challenges to us in the sports category, particularly because so many of you all are playing your favorite sports games on the PS3, Xbox 360 and Wii. We are committed to shipping a limited number of our games on the PC this year, but we’ve also had to cut a few of our games from the platform. We do have ideas for how to revitalize the PC for sports games and the types of games that are best suited to the platform, and we’ll continue to explore those."

    Low game sales and rampant piracy have both contributed to waning popularity of the PC platform when it comes to gaming.

    The announcement marks the first time that EA's biggest game will not be coming to PC. The game is set to launch in North America on August 12, and marks the 20th anniversary of the Madden franchise with a special collector's edition called the Madden NFL 09 20th Anniversary Collector's Edition. The special premium priced edition will feature full versions of both Madden NFL 09 and the all-new NFL Head Coach 09, exclusive classic Madden NFL gameplay, and a library of exclusive bonus video content.

    Shane Macaulay Explains Selling PWN 2 OWN Laptop

    PWN 2 OWN contest winner Shane Macaulay listed his Vista equipped Fujitsu U810 laptop on eBay yesterday causing a big stir. Many people first thought it was an April Fool's joke but Shane was serious about selling the very laptop he won during the PWN 2 OWN contest.

    He said that a top-quality hacker could probably examine the machine's hard drive and dig up the unpatched zero-day exploit code he had used to compromise the computer. However he never intended to disclose details of a flaw, at least not before the patch was created.

    In a Tuesday interview with IDG News he explained that Adobe Systems plans to patch his Flash bug on April 8, the day his auction was set to end, and so he would have been practicing responsible disclosure, releasing details of a flaw that had already been patched.

    According to contest rules; any vulnerability that the Zero Day Initiative awards a cash prize for, becomes the property of the ZDI, and therefore the winner can not discuss or disclose details of the 0day until the affected vendor has successfully patched the issue. Any discussion of the bug prior to the public disclosure of a ZDI advisory will result in forfeiting of the prize.

    In an InfoWorld article a hacker who knows Macaulay said that the April 1 listing is "a bit coincidental," but that he may not be worried about forfeiting the $5,000 in prize money TippingPoint paid him for his hack. "He makes good money," said Marc Maiffret, an independent security researcher, in an instant message interview. "It's all just funny to him."

    However eBay thought he was in violation of their user agreement, which says that users may not "distribute viruses or any other technologies that may harm eBay, or the interests or property of eBay users," so they pulled the listing.

    When asked about it Macaulay had some funny answers when asked about these issues.

    On the eBay terms of service problem, he said that he knew "some highups," at the company and was "confident, when I speak with eBay they will grant me a waiver."

    And does TippingPoint know about what he's doing? "I believe at some level," he answered. "I'm sure things might change as the word percolates to the executives. Maybe I shouldn't have sold the [TippingPoint] bag with the laptop!!"

    Read the IGN interview and more about Shane at InfoWorld

    PWN to OWN Sponsors Say Linux Not Immune To Hacking

    PWN to OWN sponsors say it was actually a lack of interest in hacking Ubuntu not its immunity that saved it from falling victim to the hacking contest.

    "There was just no interest in Ubuntu," said Terri Forslof, manager of security response at 3Com Corp.'s TippingPoint. She continued to say, "[Shane Macaulay's] exploit would have worked on Linux. He could have knocked it over. But [the contestants] get a lot more mileage out of attacks on the Mac or Windows."

    Finding vulnerabilities for Mac and Windows are the ones that are going to get the press so obviously those are the ones you'd go after. there isn't a big draw to hack Linux machines, you don't get a lot of notoriety.

    Last week we reported that the MacBook Air was the first victim of the contest. With the Vista equipped laptop falling second. However the Ubuntu equipped laptop could just have easily been the second victim leaving Vista unhacked.

    Everyone has been quick to jump aboard Ubuntu and Linux and say its unhackable. In this case it simply isn't true. No one managed to crack any of the operating systems alone. It wasn't until the attack exposure was expanded that we saw any of the machines breached. First to any client-side application installed by default with the operating system, then to a larger group of third-party applications added to the machines.

    Hacking operating systems is a lot hard to do than attacking applications. For the most part finding those types of vulnerabilities is also going to net you a lot more money than the contest offered. So it was unlikely that even if the contestants knew about any that they'd use them. Using application vulnerabilities found, and exploited, in applications such as Internet Explorer, Microsoft Word, Firefox, Adobe Reader and others is faster and easier.

    According to ComputerWorld Vista Service Pack 1 was a lot tougher to hack than Shane Macaulay first thought.

    "SP1 was a huge challenge to him," said Forslof. "When he walked in, he was strutting, he was going to own [that machine], he was going to break it in two minutes, he was going to wow the crowd."

    Hover it didn't happen that way. Macaulay had prepared an exploit, but had very little time to test it on SP1. So he had to use a few more tricks and tactics to get the ball rolling.

    "Microsoft has built a lot of things into its OS to make exploiting vulnerabilities more challenging," Forslof said, ticking off several defensive technologies, including ASLR (address space layout randomization). "Shane had to use some tricks to get that exploit to work on SP1."

    According to Forslof, the Flash vulnerability Macaulay exploited on the Vista SP1 notebook is multiplatform and is present on both Mac OS X and Linux. So his exploit could have worked to bring down either of those machines as well.

    If you'd like to read more about the contest checkout ComputerWorld's article Linux ignored, not immune, says hacker contest sponsor

    Tuesday, April 01, 2008

    Is Mahalo Having An Identity Crisis?

    According to a recent article by Allen Stern over at CenterNetworks Calacanis and crew have made another change of direction. Now the "human-powered search" is a "research engine".

    The move as I see it can only be a direct response to leaked Google documents regarding spam and the amount of original content per page.

    "Final Notes on Spam
    When trying to decide if a page is Spam, it is helpful to ask yourself this question: if I remove the scraped (copied) content, the ads, and the links to other pages, is there anything of value left? if the answer is no, the page is probably Spam."


    According to CenterNetworks an email was sent to greenhouse workers last week with Jason demanding a few changes. They are now mandating a minimum of 300-400 word guide notes, a direct attempt at adding some of their own content to each page. Jason reportedly stated, "No guide notes, no google/yahoo rankings, and no traffic. No traffic, no money. No money, we all go home."

    Aaron Wall over at SEOBook.com recently used the "Best Computer Speakers" page from Mahalo as a point of reference for his article "Official - Mahalo is Spam, According to Google's Internal Spam Documents" so to be fare we'll take a look at the same page.

    In response to the article Jason defends the page as being "sort of experimental" and adds "Over time I think you’ll see our pages grow to be over 50% original content, 20% links, and 20% UGC (i.e. reviews, votes, comments)."

    Several issues arise here but one is being that they are counting on 20% of their content to be user generated. If you look at the page in question (which has been revised since the article) you'll see there is zero UGC, zero Mahalo generated content on the main context of the page and what little original(ish) (thanks Aaron) content they do have is relatively unrelated to the rest of the page.

    The page is supposed to be about the "best computer speakers" however all we see is a list of 5 speaker sets and where to buy them. Reviews are listed but there is no factual based information provided that tells me why or by whom the speakers were selected. Mahalo generates zero information in relation to what makes these the "best" they simply scrape tid bits.

    Conclusion

    So what makes Mahalo a "research engine"? Clearly it can't be seen in any of their recent pages looking over a few newly created pages listed on the daily serp list shows that. If they are going to scrape content to add to the guides notes to extend them to 400 words then they are missing the point of "original content".

    Aaron Wall said it best, "Scraping content is not just about how many unique words are on the page. It is more about weather or not you add value. If you felt your original content added any *real* value (or was actually *here to help* - as your slogan suggests), I would suggest placing it in the left rail above all the ads."

    Obviously time will tell, I'm sure Jason will will probably shift gears yet again and Mahalo will don a new label before long. The question is what is next? Obviously Mahalo is generating traffic, and even though Jason original said they had enough money to last years without advertising he must be worried about revenue generation. 75% of their traffic comes from Google, fear of loosing that will obviously force the team to get creative and make some changes.

    For more reading I suggest checking out "Jason Calacanis and his human powered spam" from derekville.net and "What Is Going On At Mahalo?" posted on Profy.com by Michael Garrett.


    Some Final Thoughts

    After writing this post I noted a few things that raised some rather interesting questions.

    Search engines don't typically index SERPs from other search engines, you don't get a Yahoo results page in your Google search and vice versa. So why do Google and Yahoo index Mahalo pages? Shouldn't they be excluded in the search results? What will happen to Jason's little pet project once they are excluded, after all 75% of their traffic is Google generated?

    The second thought was the direct correlation between Jason's blog post about the example page and the pages Google ranking. I thought it was rather funny Jason's blog post ranked as high or higher than their SERP. Obviously Jason's not going to "nofollow" his links from his blog to the Mahalo SERPs, he wants to lend his PR to their pages. But that page and Jason's blog post are hardly the best results out there for the subject. Hell I'd go so far as to say Jason's blog post could be considered SPAM, which we all know he loathes so much!

    Software News: Wireshark 1.0, Snort Alpha 3.0 Released

    After ten years two widely popular network tools are finally getting makeovers.

    Wireshark
    After almost 10 years of work the Wireshark team has announced the release of Wireshark 1.0. Wireshark is a very handy, free packet sniffer. It is used for network troubleshooting, analysis and communications protocol development.

    Visit the Wireshark download page to get Wireshark for free.

    Snort 3.0 Alpha

    *Update*
    Snort 3 is now in beta, to try out the new beta release visit the Snort 3 beta site.

    Marty Roesch, who wrote the first version of the software nearly 10 years ago, has rewritten the software from top to bottom in the next-generation Snort 3.0 release, due in beta next month and early next year in its final release.

    Snort is a free and open source Network Intrusion prevention system (NIPS) and network intrusion detection (NIDS) capable of performing packet logging and real-time traffic analysis on IP networks.

    Snort performs protocol analysis, content searching/matching, and is commonly used to actively block or passively detect a variety of attacks and probes, such as buffer overflows, stealth port scans, web application attacks, SMB probes, and OS fingerprinting attempts, amongst other features.

    Snort Security Platform (SnortSP) 3.0 Beta

    We’re pleased to introduce our first beta release built on the new Snort 3.0 architecture. The Snort 3.0 architecture consists of two primary components: a software platform called the Snort Security Platform (SnortSP) 3.0, which is shipping in beta form in this release, and traffic analysis engine modules that plug into SnortSP. This beta test release contains one engine module which contains the Snort 2.8.2 detection engine implemented as a SnortSP engine module. SnortSP is an open-source platform for running packet-based network security applications. It provides many of the common functions required by programs that deal with packet processing such as configuration loading, event generation and traffic logging, data acquisition, protocol decoding and validation, flow management, and more.

    Major features:

    • Shell-based user interface with embedded scripting language
    • Native IPv6, MPLS and GRE support
    • Native support for inline operation
    • More subsystem plugin types such as data acquisition modules, decoders and traffic analyzers
    • Multithreaded execution model - multiple analysis engines may operate simultaneously on the same traffic
    • Performance increases

    The purpose of this beta release is to allow people to get exposure to the technology and to use the code in real-world environments - and as an opportunity to solicit feedback on the design and user experience of the new Snort code.

    More Software News

    Vlite releases 1.1.6 beta 2
    Vlite is the very popular Windows Vista installation customizer, slipstreamer. It can be used for Vista SP1 integration and OS customizations.
    Vista users can download Vlite here, for Windows Xp users we suggest Nlite

    Adobe releases alpha of AIR for Linux
    The alpha of the AIR runtime platform for Linux, and the alpha of the SDK for AIR for Linux, are available as separate links on this page. The public alpha of the Flex Builder 3 environment for Linux is available from this page.