Twitter

    follow me on Twitter

    Wednesday, March 18, 2009

    SOURCE Boston 2009, Part Three




    Later during the first day, two of my friends, Dan Kaminsky and Travis Goodspeed, were presenting at Source, but at the same time! Similar to the only two higher-education talks, either I had to make a tough choice or do a 50/50 split which is what I did—I started with Travis and finished with Dan.


    Belt buckle! When I think of Travis, this is what comes to mind including the word and the philosophy behind “neighborly” which is what Travis truly is. In addition to having established a reputation for the party mode on his belt buckle in the shape of Tennessee (the only neighborly state, he says) and having notable people holding the belt buckle (anywhere BUT as a belt buckle), he’s one of the most brilliant hardware hackers I’ve encountered. If there is a hardware device that can be sniffed or fuzzed, you know that Travis can do it. Want to talk about hacking the Clipper Chip encryption? Travis is probably already working on it.


    His presentation at Source was about how the private sector or governments can use wireless technologies for good applications. One interesting example is having smart land mines that will only turn on during the advance of an enemy and can turn off or be signaled to self destruct after their need is over thus eliminating the danger of live mines. I caught the beginning of his presentation and then ducked out half-way through to hear the end of Dan’s. What I missed was Travis discussing new exploits on the TI chip. I’m eagerly waiting for more info. about this on his blog.


    Dan Kaminsky is best described as a mix of brilliance and “let’s get this party started” when you see those horns thrown up. There are numerous articles describing his DNS vulnerability research and discussions about how he handled it using partial disclosure, but for someone who described how he “broke the Internet”, he is exemplary for giving vendors time to fix it and showing them how. When I describe to my computer science students the kind of hacker that’s actually doing something about making stuff more secure and not just trying to find the next big vulnerability to boost his credibility in the community, Dan is it. Humble, friendly and one of the best public speakers I’ve ever seen, he’s able to engage the audience about something as specific and technical as DNS for a full two + hours. His analogies are also legendary. Seriously, how many technical people do you know who can do all that? If he can describe DNS to his grandmother, he can tell you (the US government, SysAdmins, and your company’s recalcitrant IT guy) why it’s a big deal and you should patch today. No, really yesterday.


    The first day of sessions ended after Dan’s and Travis’ presentations, but the day didn’t end there and went long into the evening. I met a group of other conference attendees at the Atlantic Beer Garden for dinner. From there, we went to the Source party which included techno, strobe lights, and a smoke machine like any good hacker party should! I got to meet some of the other (five, I think!) women at the conference including Stacy Thayer, conference founder and organizer. Dan Guido’s potato made some rounds and got decorated with feathers, signatures, and carvings. When that party wound down, I joined Travis Goodspeed, Dan Kaminsky, Marty Roesch, Jennifer Steffens (from I/O Active) in a quest for a mythical party at MIT, but ended up closing the bar, appropriately, at The Miracle of Science in the MIT vicinity with Dan and Travis.


    (Photos, taken by Travis Goodspeed, is a screen shot of tcp dump output from the network on the OpenOtto Project Land Rover at Source. Right now, it's running on a laptop on the dash, but we're scrambling for cash to buy a touch screen dash mounted monitor.)

    Tuesday, March 17, 2009

    SOURCE Boston 2009, Part Two

    From Dan Guido’s presentation, I went to Marty Roesch’s talk titled, “From NASDAQ to the Garage with Open Source: Sourcefire’s Experience.” Not only is Marty a fantastic speaker, but his experience with open sourcing Snort is the best example I can find answering the question of how a company that embraces sharing code can be successful.


    I am constantly asked by investors: “Where is the money with open source/free software?” Instead of my usual retort which used to be, “RedHat”, I’m now going to say, “Sourcefire!” Marty’s open source release of Snort’s code is a great business model and better in the sense that it’s applicable to companies that do not have as much of a service component to generate revenue but who want to produce a product. There is significant value in putting out a box containing your code that’s akin to a plug and play device as opposed to downloading the open version and having to have more of a technical background to fully make use of all of the features.


    There is is also value and, as Travis Goodspeed would say, a neighborly interest in sharing your code and hardware designs to spark innovative products that will work with your code and, hopefully, foster something akin to an industry standard if you’re lucky. If not that lucky, you still have a product that a lot of people are using which creates a built-in user base, contribution to bug reports (and, I argue, better security because of this) and a reputation based upon a community that cares about quality code and hardware design.


    Later that night at the Source party, I spent at least an hour talking with Marty about other lessons learned about organizing and funding an open source company. One of the most important aspects about which we both agree is the necessity to defensively patent. I know that many in the open source/free software community don’t think that patents are useful and are the antithesis of open/free releases, but if you talk to Marty about how a patent troll almost messed up their IPO, you’ll see how unethical patent attorneys buying up IP at fire sales are part of the problem with the patent system because they inhibit innovation and entrepreneurship. I know of a few companies this happened to and they ended up going out of business as a result of patent trolls. My advice to entrepreneurs with open source/free software: Patent and then license with GPL version 2! Defend yourself against evil trolls.


    (Photo is of Travis Goodspeed doing a demo at SOURCE Boston using hypodermic needles as oscilloscope leads to sniff a Zigbee wireless sensor’s SPI port. Wireless traffic relies upon an encrypted key being sent to the CC2420 radio chip and tapping two pins [see Travis’ detailed photo] exposes the key)


    SOURCE Boston 2009, Part One


    Recently returning from Source Boston 2009, I am still basking in enlightenment and the excitement of meeting brilliant computer security professionals in the relaxed, small atmosphere at the Seaport Hotel. Without fail, I’d sit down at lunch or in the lounge and be discussing computer architecture or be debating how information security professionals can improve their craft.


    After a high speed dash in the snow from Southern Maine to Boston, I just made Joe Grand’s presentation and didn’t regret white-knuckle driving. Joe was a co-host of Prototype This on the Discovery Channel. Who wouldn’t want his job?! Having a hacker space warehouse near the water in San Francisco with a group of buddies making stuff—how cool! However, hearing about the behind-the-scenes difficulties that the viewers didn't see was informative. With only about $13,000. in cash per build which was to take two weeks, after knowing this, I have even more appreciation for the engineering feat with which those guys pulled off those builds. What would you do if you had Joe’s job and the producers wanted things that had never been done before, for a little amount of cash, and in two weeks? Sounds like a lot of stress, but beautiful stress. If I had his job, I think I’d have long days—some frustrating when my stuff didn’t work—but I’d go to bed every night thinking, “Yes…I am paid to tinker with stuff in a workshop that’s every geek’s dream--life is good!” By seeing Joe’s enthusiasm and broad smile when he’d describe the design and build stages and his co-host team, I suspect he feels similarly.


    Right after Joe’s presentation, I went to hear Dan Guido from NYU/Poly present on “So You Want to Train an Army of Ninjas...” The way in which he has added penetration testing into a traditional computer science curriculum is exemplary and a model I hope to adopt for the University of Maine’s computer science curriculum. Teaching about the importance of engineering security from the first line of code to the final testing phase is crucial to providing computer science professionals with the skills they need to compete in this competitive employment environment and to responsibly design better software and hardware products for the market.


    I’m tired of hearing about ridiculous vulnerabilities that were the fault of a lazy software engineering where the most important aspect in the design was, “Does it work?” Going beyond just making the code work is what Dan teaching his students. By hands–on methods teaching students how vulnerable stuff can be broken and then learning how to fix it, he’s not only teaching them about what happens if you design broken crap and its vulnerability is exposed, but consequences if you’re the one who put the crap out there in the first place. Better yet, he has released all of his course materials online to share with anyone interested in creating a better computer science curriculum. Thank you, Dan! As a side note, he has also started something of a crazy tradition at Source Boston (or so he told me!) with a potato being passed around. Dan Kaminsky (in the background in photo) got it next. Ah, the fun of hanging with the techie crowd—it’s funny that after hours the humor is often associated with anything BUT technical things. But I still don’t get it—why a potato?

    Monday, January 19, 2009

    Strong Patent Protection? FTC Public Hearings and the EFF Challenging Patents

    The FTC is holding public hearings on the 11th and 12th of Feb., 2009, in Washington, D.C. The discussion topic will be whether patents and other strong IP protection and licensing stimulates or stifles innovation. Whether or not I attend the hearings, I'm going to submit a comment that will go on the public record.

    The FTC's solicitation for opinions is as follows: "In an announcement, the FTC said: 'Changes and proposed changes in the law, together with evolving business models for buying, selling and licensing IP, could significantly influence a patent's economic value and the operation of the IP marketplace. The hearings will consider the impact of these changes on innovation, competition and consumer welfare.' It added: 'The commission seeks the views of the legal, academic and business communities on the issues to be explored at the hearings.'"

    Other significant IP news is that EFF is getting some great work done by having some patents re-examined and possibly overturned. It's extremely difficult to have a patent reexamined after it has been issued, so I applaud EFF's efforts.

    Tuesday, December 9, 2008

    Discussion with Nick Farr, HacDC

    I was in the D.C. area in late November and couldn’t resist stopping in to meet the HacDC guys and see the space. The evening started with Nick Farr inviting me to a DorkBot presentation at George Washington University. Alden Hart, CTO of Ten Mile Square gave a great presentation about his LED projects. This was one of the most comprehensive technical presentations I’ve seen that encompassed everything from where to buy the parts, where to ship the PCBs for fabrication, to discussing details of the software and hardware designs. I'm thrilled he's going to release his hardware designs as open source.


    From there, we went to Froggy Bottom for sub-par pub food, but like most hacker group outings, the company was what was outstanding. Late—sometime around 11PM—we wrapped up the dinner and a group of us went to Nick Farr’s apartment (he has CASES of Club-Mate!) and then to HacDC. While we were there tapping into his Club-Mate stock (entire fridge full of it, too), out of his closet he pulled out a really old computer with an acoustic coupler. I’d never seen one that old because back in the 80s when we had 30+ phone lines going into our suburban D.C. house, we just had racks of slow modems, but none had couplers. He’d salvaged it for hacDC.


    On the ride over to HacDC, I was able to ask Nick specific questions about the organizational structure, management, and financing the space. Because I was driving, I wasn’t able to take specific notes as I was when I talked to Far of Hacktory, so don’t take this verbatim—especially the costs.


    I first asked Nick about the name. It includes “hac(k)” which, in my experience with some hacker spaces, is a turn-off for some participants. Maine’s hacker space is struggling with this, too. His response: if they don’t like hack, then they don’t really understand what we do here and this might not be the best organization for them to join. He said that “hack” in the name clearly separates the organization from other group work spaces, like co-working. However, he also said that some members solely have numbers assigned to them because of the need to remain anonymous because there are still some businesses that shun associations with anything related to hackers.


    The space was amazing! So far, this is the most complete hacker space I’ve seen. What’s also interesting is their location. A church has rented out space to non-profits and hacDC has a loft space. One side of the space is all shelving for storage and it’s packed. I saw some old payphones, an old PC being used as a ballast for a huge rotating white board, five Geiger counters (which I relished being able to play with), table saws, old modems, and tons of computers. Tables are in the middle of the room to be used for projects and Tim proudly told me, “We even have our own bathroom!” as he gingerly took some drinks out of the fridge.


    We discussed that they only have one fee structure which is about $40/month and have around 40 active members. For a large city and even larger technological suburbanite community, I understand how they can draw so many members. They have also started hacker-theme movie nights and will be offering educational classes. It seems as if they have weekly events which is very cool they can do that. I cannot wait to go back to hacDC during Shmoocon, the next time I’ll be in the D.C. area. That seems like an awesome place to be during the conference evenings. Love it, love it!

    Monday, December 8, 2008

    We Won Venture Capital Pitch Contest!

    The venture capital pitch competition was held last Thursday night at Pace University’s Business School in NYC. What a fun event! I started the pitch about something that most people like, fast cars and computers. I used Knight Rider as a theme for the pitch. I then briefly outlined the technical capabilities about what it can do now and what it will do with some VC money when the prototype is built-out. Slides with more technical info. were shown behind me as I described how the team did it and what we’d like to do with it in the future. During the Q&A, I addressed how much money we’re looking for ($30K just to build-out the prototype).

    The majority of the judges were VCs and one like it. I met with him the following evening along with the President of a car computer company that has related, but not similar, products. They liked the idea and said the market is huge, but didn’t like the reverse engineering and brute forcing the protocols that we’ve done. Although that has been a valid and legal business model in the past (Compaq did it to IBM), the VCs want it done with licenses and defensive patenting. We might be able to do it like that as long as we don’t lose the open source/free software platform. We’re talking.

    Monday, December 1, 2008

    Finalist for Pace University Venture Capital Pitch Contest


    We made it! OpenOtto is a finalist in a competition for venture capital financing of a new product. I'm off to NYC for the Thursday night presentation. I've been busy working on the presentation, but here is the winning pitch that got OpenOtto into the finals:

    "You don’t have to be David Hasselhoff in Knight Rider to have your car talk to you. OpenOtto is a platform for developing vehicle aware products for the consumer and industrial markets. While it will not ask you how you’re doing this evening, most people don’t realize how much information your car’s computer can tell you. OpenOtto consists of a hardware interface to your car's OBD II connector as well as an extensible software platform for communicating with all networked electronic devices in the car. Designed for flexibility and scalability, it is easily expandable to future vehicle capabilities.

    OpenOtto consists of two products targeted to different markets. The first is a car computer that acts as an interface between your car's computer and a 4" x 8" touch screen display that attaches to your dashboard. The interface shows easy to understand graphical output from your car's computer including, but not limited to, standard OBD II output: coolant temperature, engine speed, oxygen sensor readings, and emission related trouble codes. Advanced features include outputting suspension control, anti-lock/traction control, and air bag status.

    Additional safety and security features include a remote start and kill feature for anti-theft or convenience, display warnings to users when the transmission begins to fail, individual wheel speed indicating wheel slippage, and real-time engine performance monitoring.

    The second product is priced lower for the general consumer. It includes the ability to attach any cell phone with GPS to OpenOtto. Once attached, the car's computer will text message someone (e.g., a parent) if the car exceeds a certain speed and GPS coordinates will be texted, and call 911 if airbags deploy (no proprietary subscription necessary).

    Safety and security is important and built into the computer engineering designs. Some features will be access controlled and transmission of all sensitive data transmitted by OpenOtto will be encrypted using industry standard best practices to ensure safety, security, and privacy of the user.

    The software and hardware designs will be released as free and open source designs to encourage adoption and adaptation of the features.

    For consumers, a complete dashboard mounted display with computer will cost between $300-$500.00. The closest product currently on the market costs between $1000.-$5000.000 and does not include open software and hardware platforms, graphical dash board mounted displays, or customizable features. The low cost consumer device will target a retail cost of $100-$200.

    Try getting KITT for that price."