Monday, September 26, 2022

Do we live in a simulation?

 Nah, really. Read this first ...

Do we live in a simulation? Here's why we may never know. (msn.com)

Pretty radical idea. But not really.

First of all, there is some pretty compelling 'evidence' in the apparent quantization of many physical things, at least in theory. For some phenomena we know a lot (electron states) and for others we know little (entanglement).

Simulations, at least as we know them, are digital and ruled by mathematics.  Physics, essentially, is ruled by what can and cannot be. Things that cannot be proven to be impossible are therefore possible.

Now here comes the interesting problem, at least in my mind. Many people believe in a God or Spirit of some sort. I am that way also but more Universalist. Is that not possibly a translation of a longing for the programmer of the simulation?

Now before I get into the metaphysical, let me drop one more bombshell. Maybe the illusion of self and reality that each of us has (even animals and plant) constitute the many worlds? Perhaps this is how the simulation works out?  

Now this is of course just conjecture. But an interesting thought experiment. Is such a thing possible to know and so what?


Saturday, September 24, 2022

I see a bad Moon rising ...

 Hi all. We are 3 days from a hurricane that may, or may not, be really nasty.

The real bad scenario of security is when something goes wrong and you do not know what to do and it keeps getting worse.  This was the case at Chernobyl and 3-Mile-Island.  Interestingly all blamed on a control interface that was too complex for humans to handle.

I mean, part of the idea of security is to have secure systems that are very difficult to mess up.

So, this upcoming hurricane leaves us with something of an opportunity.

I am from Pennsylvania.  The worse that can happen there is a bad snow storm every 3-4 years. Worse if you live in the mountains like I did.  But 3/4 of the year it is not good for being out riding a motorcycle, so Suzi and I decided to move to tropical SW Florida, where one can ride 9/10 of the year. Its a plan!

OK, back to security. Friends would joke about hurricanes to me. I would laugh it off. I had come down in 2005 just in time to rent a Harley in Orlando and ride in the beginnings of Hurricane Charley in 05.  Admittedly I hated it but I was single, unhappy, and willing to ride the edge.

But we figured, all in all, it would be best for us. I LOVE warm, and HOT? I don't LOVE it but i LIKE it.

The Gulf is really peaceful although ironically, I cannot get in it. More specifically I cannot get out of it, due to my deteriorated lower back. LOL

So security - You know a potential disaster, one documented many times. Is coming. You know the time frame. Your data is 'spaghetti models' which are inaccurate but overall a hell of a lot better than nothing and better as time diminishes.

The answer, given everything we know, is to evacuate. But that is not possible.

So first, stay informed. A few of you MAY have to evacuate. Have a plan for that, put important papers and such on the cloud. Have SSD backup. Take laptop with you. Unplug everything else!!!  Take battery backups for phones. Have a special box with papers, IDs, ammo, whatever needed.

If you have a pet be sure to take care of them. Food, leash, muzzle, water bowl, etc.  Most animals do really well for a few days. And have some idea where to go. Believe it it not there are a few instances where one in my position (Rotonda) will have the best chances by going south.

BTW - Treat this like a camping trip although you may be camping in your vehicle.  If you have to find a safe place for the night.  There will likely be others there. Do not waste gasoline. Share info from battery phones. Don't be a jerk, there will be a lot of scared people with families.

Point is - we now have the ability to create scenarios and evaluate them. You bet your arse the govt. is doing this. I would. Help each other! Cooperate.  I do not want to evac but will if ordered to. But I will take my pets.

We are cleaning the house/yard and taking lots of pictures just in case needed for insurance.  Murphys law says that the more we prepare for disaster the less likely disaster is to strike.

So to conclude, this is exactly what every security analyst should do.  Run the scenarios. Assume different starting variables from worse to best. Know what you will do ahead of time. Revise your plan as data changes.  A hurricane is a lovely example of a natural disaster that can absolutely decimate a companies IT infrastructure.









Monday, September 19, 2022

Rise of the Help Desk - 70s through 90s

 I would always tell my students that the best kind of training they can get is by working at an IT help desk.  Most of us have bad memories from interacting with a Help Desk.  I understand that because Customer Resource Managers (CRM)   otherwise known as "press 1 for ... "  are universally disdained.

I first encountered a small Help Desk at Penn State, where visionaries such as Bill Verity were hired as systems analysts to help faculty and graduate students use the computing resources on the IBM mainframes. Those old guard, Bill, Dan Bernitt, Chet Smith and others, came from various disciplines. It was a time full of potential.

When I worked at Pitts Comp Center from 76 to 83, the latter part of that as a manager. They were also mainframe based and everyone had to put in 1 or 2 days a week at the User Consultant desk at Old Engineering Hall on the Oaklland campus.  Those were fun times as I would get a sausage dog at the Original.  I spent a lot of my youth on Oakland.

The Help Desk was an amazing training ground. One had to be aware of a broad range of things, not only programming.

Saturday, September 17, 2022

What do you do if there is widespread cyber-warfare?

 In 2015, Dr Pete Forster and I developed a class for the MS Program in Homeland Security tentatively named SRA-404.  It was focused on cyber-espionage and cyber-warfare.  It was one of the first classes of its kind.  Peter is an expert on the political and espionage scene. My expertise was in the technology of cyber crime, espionage and warfare.

One of the bigger things, IMHO, to come out of the class was an exercise on what to do if this happens or how to prepare. In this posting I present the suggestions. I cannot say they are complete. A lot depends on specifics.

Direct attacks.

By these I mean worms, viruses, and such. They could conceivably be deployed for activation later.  Mainly we are talking about home and small-business systems. Of course you have good anti-virus and firewall protection. Make sure you have backups stored on a non-electronic media - such as CD or DVD. A low nuke could put off an EMP and potentially fry solid-state or magtape backups.  If you have access to a safe or faraday cage use it for your backups.  I bought a home safe and a home UPS for under $200. I also have multiple backups on CD and DVD (also SSD ) all of which goes in the safe with my pistols.

Attacks on servers and networks

I would create a doc with all of your PWs and IDs on it and print that a few times.  Also maybe encrypt it and put it somewhere on the cloud.  Having encrypted docs on the cloud is great if you know what you ae doing.  I will post more about that later.

Do not expect that any of your online services will be working under a cyberattack.  Therefore have a backup plan for paying bills, etc.  In the old days we used to write checks. I would also keep about 2K in cash (20s) just in case. Should hold you over for a week or more.

Now the bad stuff. I learned a lot living in a Hurricane zone.  Prepare as if a disaster were coming. Esp your meds, water, canned food, peanut butter, etc. In PA we had the occasional blackout during a blizzard. We used a wood stove to stay warm.

I am not suggesting becoming a survivalist, but the potential for damage from a cyberattack is too great to ignore. And BTW, a cyberattack can come from the Sun as well. More on that later.

Friday, September 16, 2022

Relauching the Blog

 Hi Yinz'all,

I am gonna try re-launching my blog, but as a slight twist from the traditional science/ security blog.

Yeah, it will have some of that. It will also have some of the memories of a city kid who followed his dreams and became a scientist.

but I refer you to the following:

Apple Steve Jobs Heres To The Crazy Ones - YouTube

The stories I tell will be mostly true, as true as I can remember them. But I will NOT say anything bad about anyone. Not my place. Watch for a few posts each week.

gerry