This is the highest wisdom that I own;
freedom and life are earned by those alone
who conquer them each day anew.
-Goethe
"... a part of that force which always seeks evil and always does good."
- From "Faust" by Goethe
============================
(this section is a bit light, as I was working in the industry, where I could not say everything I see or think.
I will fill it in more with interesting stuff...)
===================
the objective of security
to protect.
to have some integrity.
to build Trust.
System for Cooperation and Competition.
How to make a secure and fair system, that people can trust and make exchanges and commerce.
protect/guard/patrol, long-term storage, and incresead efficiency/workability.
===============================
the industry publications say:
Security is about Defending System against Attacks. How does the attack works, is that, it start with exploit, then that property is maintained by malware.
=======================
===================
=======================================
* the long story.
With these 2 keywords, we took a look at the civilization dichotomy in general.
civilization is relatively a recent invention. maybe about 5000 years.
lets see how the civilication first started, from the beginning of the time.
in pre-civilation (caveman) era, we had no privacy and no trust.
then, someone thought, it would be nice to have a property right. a sense of ownership.
everyone was relatively separated, by today's standard, that privacy used to be simple enough.
information is one link away from the physically measurables. the private properties right has to be assumed, for a privacy, that deals with a metadata of private properties.
Then, whether it is by accident or not, we discovered the concept of "cooperation".
to achieve a bigger task, that one can do it by onself. this was and is "the break-through" concept of humanity, and probably everything preciding that. and, it had not been understood well up until the adam smith's time.
we name it as a concept of "cooperation",
to make cooperation easier, we made "hunting calls", which grew to be language.
(other animals, they also do cooperate as well. without using language.
some animal hunts together, or swin in a flock.
since they dont have highly evolved language, communication is done via vision, or smell, or sounds. or other chemical trails.)
humans with language,
we became "social animal".
and, built civilization. a main purpose of civilication is to reduce unnecessary conflicts, also called standarization.
we start to build a system.
we build a culture.
a culture became a law system.
a succesful system has a reward/punishiment structure.
sometimes, culture/law is arbitrary. but throughout the history, the really bad system has been eliminated, such as stealing or killing. that is not good.
however, stealing from lower species are allowed, such as taking honey from beehive. or eating plant embryo. it is called harvesting.
in a way, culture is a protocol, that it is no different that TCP/IP protocol.
culture is a system, we are born into. (and, there is some beauty in how TCP/IP protocol resolved conflicts on the wire.)
communicating lead up to trading with others. (*trading is not just trading of goods, but trading of ideas, thus i use "trading" and "communication" in the same sense. this is a very bit-wise digital definition. everythings is just a "bit" of information.)
and, in order to trade without too much paranoia, we needed build a reputation. a history of transaction.
Trust means it is a fair trade, that you would trade again.
while trust is a good thing, trust eats into privacy.
trust is like a data gobbler. trying to gather as much data as possible.
since we cared deeply about economy, which depends on "trust", that we gave up all sorts of privacy.
System is a good thing. in a way, a good system has a tremendous amount of "energy" stored in them. anti-entropy.
if you view that an ordered society will survive longer than a randomly configured society, on average, it means the orderedness is more desired. let say you didn't clean your room, or email box. it clutters and slows down your productivity. by spending time on cleaning the room, and organizing your stuff, you increase efficinecy.
then, over-civilication and over-controlling.
now, we are starting to value the privacy, that we lost on the way.
some balance of "transparancy" and "privacy" needs to be met.
on the digital world, there is no "take backs". once it is out there, it is out there.
no amount of governance can stop this. so, stop relying on the govt or some system, to protect you from prying eyes.
that is the sunny side of civilization. when all we talk about is efficinecy. efficinecy means more output for the whole group
(and, these are usually all the politicians are talking about... united we live, scattered we are weak.)
=========================
In every group, there are 2 general problems. (2 extremes of the specturm)
1)bad boss and 2)nice boss.
in another words, 1) slavery and 2) slackers.
in another another words, 1) impatience 2) laziness
-----------------------------------------------------
the dark side of the civilization is that, a really big civilication is made possible by slavery.
(or a modern version of slavery. it is not strictly slavery, but the benefit is unequal.)
king will sacrifice a pawn, to win a game.
if you are a pawn, tough luck to you. you sacrificed for the group. you did something good. something noble. something the king would not do. yet asks others to do. isnt this a tad bit unfair? (*IMHO, the real evil is the molds of perfunctory mundaneness, that spreads. and, in that aspect, every human is evil, that we do the work just enough, to satisfy our own needs. maybe, that is no so evil. making others to do your dirty work, is evi, but also smart. as in the harversting example. In order to do evil (or be smart), and still feel good about ourselves, we make them into different class. once you can do that, then you are free from all the guilt... and, that is why i like tag structure, rather than folder structure. tag structure complicated thinking for human brain. we are so accustomed to this or that. mutually exclusive. it is either yes, or no. we dont like, maybes and conditionals, and fractional, and probabiliticals. but, machines dont mind that structure, if that is little bit more accurate and flexible. they can calculate millions things with an ease.)
In forming one uniform group (yes, the clothing uniform comes from the fact that everyone in that uniform is the same)
, not everyone is born uniformly. school system might make us more uniform than we used to.
but, we are still not uniform. our thinkings are still vastly different.
that it is neverthelessly difficult to unite everyone's goal into one single goal. we are more complex than that.
maybe simpletons, like ants, can do this.
but, human is just too diverse to act in uniform.
(if any politician say, we are equal, then, let him be just a normal citizen, and let me take his position. if equal, we could swap with no problem. everyone is all little different. we deserve fair oppurtunity. or less severe punishment, for trying new things. but, parenting start with "dont do that. you will get hurt."... )
so, now do you really control people into doing what you like them to do?
in an unwilling relationship, it is done by two ways. "coersion" and/or "deception" (mentioned somewhere in atlas shrugged)
"coercion" uses fear. threat. hunger. needs. money upto $75k. (1.5x GDP per capita)
"deception" uses advertisment. love/lust. wants. desire. money from $75k (1.5x GDP per capita) and upward.
a vast majority of the control is done via "coercion".
when, when it comes to rich people, once people have "fuckyou money", (how much is your fuckyou money??) coercion is powerless. that is when you have to use "deception"
advertisement is a type of a deception, because it is changing the mental perception of a product. even before you get to use the product, you already know how it would work. apple does this really well. and, it is a good thing. non-deception would be, showing people how frustrating sometimes it is, with using a computer.
*fear is a mix of both "coercion" and "deception". that is why it works sooooooo well.
even in a strong group, the system is designed to reward "conformity". a good employee is not the one who does the right thing, but the one who does what is told to do. if the work is easy, this is good. but we are beyond simple working environment. anything mechanical is done by machine ever since industrial revolution and factory automation. and if it is paper work, a simple works are done by computer.
-----------------------------------------------------
by tracking people's history, and by measuring their character.
so, with repuatation system(such as credit scores, and college diplomas), everything about civilization seems swell, and working well.
*did you know that the all the first world country are heavily heavily relying on reputation system, relative to non-first world country?
the problem with the reputation system, is that people start to rig the rep system, instead of making the real thing better.
this is why we are so hung upon a standarized test score. so hung upon making the first impression best. so hung upon making through the initial filter.
this is over-civilization, that we depend too much on the system, and not being able to think on our own.
We need to do 3 things.
-we need to make a bullet-proof reputation system. the system that cannot easily be gamed, so that people actually workin the real stuff, rather than trying to game the system.
-we need to enable people to use their brain. Depend all on the machines for the little stuff, but find out what it is the important stuff, and be able to make the right decision on it. stop listening to others and advertisements. stop thinking about which alliance would be the best. make your goal, and if the intention is the same, people will naturally join force.
-all the money in the world, and in the power, are going for centrality. never for individual privacy. we should protect privacy, for the reasons explained below.
and that was the whole basis of this project, which in turn, is for the better society. and this is what i think is the best social effort ever.
==================================
So far, we have talked about why group works are important.
now, we want to talk about why individualism is MORE important.
a case for the disruptors.
individuality, independence, freedom.
wisdom is not about following the rule.
rules protect you from disasters, but rules prevent you from thinking.
wisdom is knowing when it is okay to break the rule, and how to break the rule.
to define is to limit.
to be chaos is to be limitless.
=================================
*the root of these 2 problems is the difference of the speed and direction of the ruling party and the working party.
so, why cant we all work like ants, in unison?
ants are dumb. so uniformity works.
(why talk about ants so much? because it is another social animal that we should learn from. or aztecs learned from.)
but, we are smarter. the variance is greater.
so, this uniformity is rather a utopian dream.
what if the law is idiotic, or outdated?
the ruling party want people to follow the law blindly.
and, it is the job of the disrupters, to bring it to the surface.
(a job of comedian to find the fine line, and cross it deliberately, yet in a sensible/artful way, so people will think about it.)
not everyone agrees everything with the group.
we have freedom to disagree.
(we have a freedom to agree as well, but no one really gets mad if you agree with them)
just put a group of randomly differtnly people together, they will find a similarity, and make a culture.
just put a group of similar people together, they will find the little difference between them, and develop that furthur and furthur.
this is natural.
becasue it is so hard to make everyone to be exactly the same.
we are naturally genetically programmed to be maximally apart from those around us, that we are different. that we are competitive different.
the disrupters say, "the way we do things... i dont like it. i want to do it in a different way."
some became better than other, some became worse than others.
to be better than others. when the resource isnt enough, we have survive via competition.
it is not the fact of disagree that is bad. or good.
it is what you do with that disruption.
is it destructive? or constructive? creative?
if it is destructive, it is just destructive? or is it a destructive construction? (or is it contructive destruction)
meaning, is it stupid? or smart?
disagreement is not so good thing in a shortterm, but a Survival Necessity in a long run.
if we only have cooperated, then we would have not evolved.
in order to compete, the basis is that we need to disagree on things.
in a fixed time, the winner is the one who is the strongest.
in the longer period of time, the winner is the one who have adapted, and survived.
so, we have disruptors. a global scope disruptor.
the rebel. the one who breaks the system.
terrorists are disruptors of the system.
the rebels in egypt are disruptors.
disrupting the norm, isnt necessarly good or bad.
it all depends on whether the current system is viewed as good or bad.
disruptor is the exploitor of the system. in a good and bad ways.
some call it "hackers"
====================
*cyber-insurance.
is this the new thing?? I don't mean Lifelock. But, actively detecting and protecting by obscuring/manipulating data. minimizing the risk. plausible deniability. active prevention, like pre-cog. if correlated risks get too high, then flood the network, with misinformation slowly... it is like putting an airbag, before it hits the ground. evade bot signature. tracer buster buster buster.
===========================
i am a bit afraid of those web beacons...
how much info do they get? they are like sentinels.. ;)
================================
3 phases of computer technology.
- if a computer does what you tell it to do, it is a secure computer. a good computer.
- if a computer does what you meant to do, it is a smart computer. an intelligent computer.
- if a computer does what is best for you (and it might not be what you want to do), it is a super-smart computer. reaching into the realm on "skynet" (has to be pronounced with a deep voice..) The limit of trust is always that, it should perform better than human. if not, human should be in charge. this is not new, as anti-virus program always superceded the user's mistake.
===========================
would it be a good practice, for outgoing link, to attach the last known IP address into the link, to let you know the someappcompany.com/blah link, last time i saw it, it was at 24.5.220.1. kinda defeats the purpose of DNS. how can we make DNS better??
===================
*Appendix
=================================
Where to look to learn more about security.
this list is outdated.
http://cyberunited.com/wp-content/uploads/2013/03/A-Common-Language-for-Computer-Security-Incidents.pdf
http://labs.idefense.com/
http://mtc.sri.com/
http://www.blackhat.com/html/bh-media-archives/bh-multi-media-archives.html
http://www.cigital.com/
http://www.defcon.org/html/links/defcon-media-archives.html
=================================
=================================
.-- . .----. .-. . / -. --- / ... - .-. .- -. --. . .-. ... / - --- / .-.. --- ...- . / -.-- --- ..- / -.- -. --- .-- / - .... . / .-. ..- .-.. . ... / .- -. -.. / ... --- / -.. --- / .. / .- / ..-. ..- .-.. .-.. / -.-. --- -- -- .. - -- . -. - .----. ... / .-- .... .- - / .. .----. -- / - .... .. -. -.- .. -. --. / --- ..-. / -.-- --- ..- / .-- --- ..- .-.. -.. -. .----. - / --. . - / - .... .. ... / ..-. .-. --- -- / .- -. -.-- / --- - .... . .-. / --. ..- -.-- / .. / .--- ..- ... - / .-- .- -. -. .- / - . .-.. .-.. / -.-- --- ..- / .... --- .-- / .. .----. -- / ..-. . . .-.. .. -. --. / --. --- - - .- / -- .- -.- . / -.-- --- ..- / ..- -. -.. . .-. ... - .- -. -.. / -. . ...- . .-. / --. --- -. -. .- / --. .. ...- . / -.-- --- ..- / ..- .--. / -. . ...- . .-. / --. --- -. -. .- / .-.. . - / -.-- --- ..- / -.. --- .-- -. / -. . ...- . .-. / --. --- -. -. .- / .-. ..- -. / .- .-. --- ..- -. -.. / .- -. -.. / -.. . ... . .-. - / -.-- --- ..- / -. . ...- . .-. / --. --- -. -. .- / -- .- -.- . / -.-- --- ..- / -.-. .-. -.-- / -. . ...- . .-. / --. --- -. -. .- / ... .- -.-- / --. --- --- -.. -... -.-- . / -. . ...- . .-. / --. --- -. -. .- / - . .-.. .-.. / .- / .-.. .. . / .- -. -.. / .... ..- .-. - / -.-- --- ..- / .-- . .----. ...- . / -.- -. --- .-- -. / . .- -.-. .... / --- - .... . .-. / ..-. --- .-. / ... --- / .-.. --- -. --. / -.-- --- ..- .-. / .... . .- .-. - .----. ... / -... . . -. / .- -.-. .... .. -. --. --..-- / -... ..- - / -.-- --- ..- .----. .-. . / - --- --- / ... .... -.-- / - --- / ... .- -.-- / .. - / .. -. ... .. -.. . --..-- / .-- . / -... --- - .... / -.- -. --- .-- / .-- .... .- - .----. ... / -... . . -. / --. --- .. -. --. / --- -. / .-- . / -.- -. --- .-- / - .... . / --. .- -- . / .- -. -.. / .-- . .----. .-. . / --. --- -. -. .- / .--. .-.. .- -.-- / .. - / .- -. -.. / .. ..-. / -.-- --- ..- / .- ... -.- / -- . / .... --- .-- / .. .----. -- / ..-. . . .-.. .. -. --. / -.. --- -. .----. - / - . .-.. .-.. / -- . / -.-- --- ..- .----. .-. . / - --- --- / -... .-.. .. -. -.. / - --- / ... . . / -. . ...- . .-. / --. --- -. -. .- / --. .. ...- . / -.-- --- ..- / ..- .--. / -. . ...- . .-. / --. --- -. -. .- / .-.. . - / -.-- --- ..- / -.. --- .-- -. / -. . ...- . .-. / --. --- -. -. .- / .-. ..- -. / .- .-. --- ..- -. -.. / .- -. -.. / -.. . ... . .-. - / -.-- --- ..- / -. . ...- . .-. / --. --- -. -. .- / -- .- -.- . / -.-- --- ..- / -.-. .-. -.-- / -. . ...- . .-. / --. --- -. -. .- / ... .- -.-- / --. --- --- -.. -... -.-- . / -. . ...- . .-. / --. --- -. -. .- / - . .-.. .-.. / .- / .-.. .. . / .- -. -.. / .... ..- .-. - / -.-- --- ..- / -. . ...- . .-. / --. --- -. -. .- / --. .. ...- . / -.-- --- ..- / ..- .--. / -. . ...- . .-. / --. --- -. -. .- / .-.. . - / -.-- --- ..- / -.. --- .-- -. / -. . ...- . .-. / --. --- -. -. .- / .-. ..- -. / .- .-. --- ..- -. -.. / .- -. -.. / -.. . ... . .-. - / -.-- --- ..- / -. . ...- . .-. / --. --- -. -. .- / -- .- -.- . / -.-- --- ..- / -.-. .-. -.-- / -. . ...- . .-. / --. --- -. -. .- / ... .- -.-- / --. --- --- -.. -... -.-- . / -. . ...- . .-. / --. --- -. -. .- / - . .-.. .-.. / .- / .-.. .. . / .- -. -.. / .... ..- .-. - / -.-- --- ..- / -.--.- --- --- .... --..-- / --. .. ...- . / -.-- --- ..- / ..- .--. -.--.- / -.--.- --- --- .... --..-- / --. .. ...- . / -.-- --- ..- / ..- .--. -.--.- / -. . ...- . .-. / --. --- -. -. .- / --. .. ...- . --..-- / -. . ...- . .-. / --. --- -. -. .- / --. .. ...- . / -.--.- --. .. ...- . / -.-- --- ..- / ..- .--. -.--.- / -. . ...- . .-. / --. --- -. -. .- / --. .. ...- . --..-- / -. . ...- . .-. / --. --- -. -. .- / --. .. ...- . / -.--.- --. .. ...- . / -.-- --- ..- / ..- .--. -.--.- / .-- . .----. ...- . / -.- -. --- .-- -. / . .- -.-. .... / --- - .... . .-. / ..-. --- .-. / ... --- / .-.. --- -. --. / -.-- --- ..- .-. / .... . .- .-. - .----. ... / -... . . -. / .- -.-. .... .. -. --. --..-- / -... ..- - / -.-- --- ..- .----. .-. . / - --- --- / ... .... -.-- / - --- / ... .- -.-- / .. - / .. -. ... .. -.. . --..-- / .-- . / -... --- - .... / -.- -. --- .-- / .-- .... .- - .----. ... / -... . . -. / --. --- .. -. --. / --- -. / .-- . / -.- -. --- .-- / - .... . / --. .- -- . / .- -. -.. / .-- . .----. .-. . / --. --- -. -. .- / .--. .-.. .- -.-- / .. - / .. / .--- ..- ... - / .-- .- -. -. .- / - . .-.. .-.. / -.-- --- ..- / .... --- .-- / .. .----. -- / ..-. . . .-.. .. -. --. / --. --- - - .- / -- .- -.- . / -.-- --- ..- / ..- -. -.. . .-. ... - .- -. -.. / -. . ...- . .-. / --. --- -. -. .- / --. .. ...- . / -.-- --- ..- / ..- .--. / -. . ...- . .-. / --. --- -. -. .- / .-.. . - / -.-- --- ..- / -.. --- .-- -. / -. . ...- . .-. / --. --- -. -. .- / .-. ..- -. / .- .-. --- ..- -. -.. / .- -. -.. / -.. . ... . .-. - / -.-- --- ..- / -. . ...- . .-. / --. --- -. -. .- / -- .- -.- . / -.-- --- ..- / -.-. .-. -.-- / -. . ...- . .-. / --. --- -. -. .- / ... .- -.-- / --. --- --- -.. -... -.-- . / -. . ...- . .-. / --. --- -. -. .- / - . .-.. .-.. / .- / .-.. .. . / .- -. -.. / .... ..- .-. - / -.-- --- ..- / -. . ...- . .-. / --. --- -. -. .- / --. .. ...- . / -.-- --- ..- / ..- .--. / -. . ...- . .-. / --. --- -. -. .- / .-.. . - / -.-- --- ..- / -.. --- .-- -. / -. . ...- . .-. / --. --- -. -. .- / .-. ..- -. / .- .-. --- ..- -. -.. / .- -. -.. / -.. . ... . .-. - / -.-- --- ..- / -. . ...- . .-. / --. --- -. -. .- / -- .- -.- . / -.-- --- ..- / -.-. .-. -.-- / -. . ...- . .-. / --. --- -. -. .- / ... .- -.-- / --. --- --- -.. -... -.-- . / -. . ...- . .-. / --. --- -. -. .- / - . .-.. .-.. / .- / .-.. .. . / .- -. -.. / .... ..- .-. - / -.-- --- ..- / -. . ...- . .-. / --. --- -. -. .- / --. .. ...- . / -.-- --- ..- / ..- .--. / -. . ...- . .-. / --. --- -. -. .- / .-.. . - / -.-- --- ..- / -.. --- .-- -. / -. . ...- . .-. / --. --- -. -. .- / .-. ..- -. / .- .-. --- ..- -. -.. / .- -. -.. / -.. . ... . .-. - / -.-- --- ..- / -. . ...- . .-. / --. --- -. -. .- / -- .- -.- . / -.-- --- ..- / -.-. .-. -.-- / -. . ...- . .-. / --. --- -. -. .- / ... .- -.-- / --. --- --- -.. -... -.-- . / -. . ...- . .-. / --. --- -. -. .- / - . .-.. .-.. / .- / .-.. .. . / .- -. -.. / .... ..- .-. - / -.-- --- ..-
I guarantee that you would not be disappointed. ;)
===========================
Prepare for the worst,
Hope for the best.
===========================