Alpha woman and the days of sail

Chey at the helm of Alpha, a Bristol Pilot Cutter built 110 years ago.
Although we live just 5 blocks from the Star of India and other fine sailing vessels in San Diego Bay, we do not get out on the water much because of Chey's health. However, 20 years ago Chey was an active sailor, studying for her Yachtmaster on the Isle of Wight and sailing historic wooden sailing ships around Scotland.

Chey's favorite was Alpha, a 52 foot Bristol Pilot Cutter. On one trip she sailed Alpha from Scotland to Portugal and back, straight up through the North Atlantic and around the western side of Ireland. Bear in mind that pilot cutters were the "built for speed" boats of their day, sleak, stripped of deck rails and any other impediments to pace. Why? Because pilots made their money guiding large cargo ships through coastal waters and into port. The pilot who was first to reach an incoming ship got the job!

How to find $168 billion in annual spending cuts while saving the world

Allow me to explain where the U.S. federal government can find $168 billion. That could be a $168 billion cut in annual spending from the current budget, or $168 billion of spending shifted to more worthwhile endeavors. It could even end world hunger while giving us all tax rebates.

Lately, I've been looking at a lot of numbers related to safety and security, like how much money we spend on fighting wars and cyber crime, how many people die from different causes, and so on. I was inspired to research such things by a comment made to the press by my friend and boss, Andrew Lee, CEO of ESET North America, who was asked what he thought of General Keith Alexander's keynote at Blackhat last year. (The General spoke about mass surveillance by the National Security Agency (NSA) as revealed by former federal contractor Edward Snowden.) Andrew said that we should be asking ourselves if the levels of surveillance now being revealed constitute a proportionate response.

Personally, and I stress that this is my personal opinion, I think that the $50 billion my country spends annually on spying is way too much (BTW, for new readers, "my country" = the United States of America, the country of which I have been a citizen for more than 30 years).

To put that $50 billion spend on spying in perspective, it dwarfs the total spend on life-saving health research by the federal government is $30 billion (that's funding for over 300,000 researchers at more than 2,500 institutions). I'm pretty sure that $50 billion is about the same as the operating expenses of Google and Microsoft combined. Aside from the sheer amount, the challenge of oversight and efficiency across multiple agencies is huge, leading to some terrible decision-making, as revealed by some of the Snowden papers.

But let's leave the spy budget aside and consider what we spend to defend our country. Suppose we were to decide that the appropriate annual budget for defending America is twice the total annual military spend of our two closest rivals, China and Russia. Those two countries spend $166 billion and $90 billion respectively, or $256 billion combined; double that is $512 billion, which is $168 billion less than the $680 billion that the U.S. spends.

military-spendingSurely we can adequately defend America by allocating twice what China and Russia spend combined. Still nervous? Want a comfort zone greater than 2X?

Consider the $272 billion annual military spending by our six strongest allies (UK, Japan, France, Germany, Australia, Canada). Figures are from SIPRI Yearbook 2013.

Want more perspective? With our $168 billion savings we could drastically reduce the deficit, lower taxes, and still have enough left over to END WORLD HUNGER (estimated cost of that is $30 billion).

So, let's recap, the Cobb budget plan for America would:

  • Spend more on defense than China and Russia combined

  • End world hunger

  • Reduce the deficit

  • Enable lower tax rates


What's not to love about that?

Happy Blogging New Year 2014!

Happy New Year! While it took me a few days to get around to this, I did want to mark the beginning of the new year with at least one blog post here on Cobbsblog. In fact, I have been doing quite a bit of blogging around the turn of the year.

Over on WeLiveSecurity.com I was privielged to present some of the 2014 security predictions from my fellow researchers at ESET. My colleagues in Latin America shone again this year, producing a 30+ page review of malware trends and predictions.

That report very rightly fingered privacy as a hot topic for 2014 and I am heading for Washington, D.C. in a few weeks to be on a panel about data privacy at a Data Privacy Day event at the Pew Charitable Trusts (January 28 is Data Privacy Day).

Predictions are one thing, but what practical good are they? What advice can they generate for IT security managers? I will try to answer that question in a free webinar happening January 15 on ESET's Brighttalk channel.

I made some information security predictions of my own, over on my security blog: scobb's information security blog. That blog was in fact my first, and lately I have been reviving it. My idea for 2014 is to use Cobbsblog for more personal posts, and put my security related posts on scobb's. Of course, in 2014 I will be writing about security on WeLiveSecurity.com as well, but sometimes I have things to say on the topic that don't quite fit there.

And sometimes my thoughts will migrate to other blogs. For example, Graham Cluley liked my prediction about the persistent misrepresentation of antivirus software, and reprinted it (with my permission) on his very information blog.

I wish you a safe and happy 2014 and pledge to do my best to provide you with informative and thought-provoking content all year long.

Bands to watch in 2014: NO doubt about NO

Warning! The link I am about to lay on you starts to autoplay some great music. It's by a band out of Los Angeles called NO and I think they are very good. Of course, this is an old guy talking, but an old guy who had enough love of good music to spend four days in the cold and rain to catch artists like Santana, Led Zeppelin, Frank Zappa, Pink Floyd, Pentangle, and Fairport Convention at the Bath Festival in 1971.

That said, here is the link to NO. And here is a photo of the band I snapped as they were performing "There's a glow" on the rooftop of the Rio in Las Vegas last summer.


The significance of the setting, high above the Vegas strip, comes partly from the opening of the song that goes:
There's a glow up over the city the city.
There's a glow up over us all.
The other aspect of significance, apart from the amazing view and the electrified atmosphere of the up-close performance, is that the band is playing at a party thrown by my employer, ESET.

And I have to admit this was not my first time seeing the band live. They played an ESET party in 2012 as well. None of which would matter if the band was just okay. But in fact they are awesome when they play live, managing to create a huge sound without it becoming noise, and often generating powerful emotional tension by restraining that big sound until just the right moment.

In February of 2014 the band releases its first LP, with 7 new tracks on top of the 6 you can hear live on the website. Stay tuned to their site for fresh tour dates and try to catch them live. You won't be disappointed.

Free professional security advice for Palestinian hackers

First of all, welcome. I am glad you found this page. Please don't hack it.

Who am I? I am one of many people in the computer security world who have great sympathy for the Palestinian people. We agree with you that the Palestinian people deserve to live in peace. We let our politicians know what we think. We use social media to spread news and awareness of the injustices suffered by the Palestinian people at the hands of Western governments and their allies in the region.

As computer security professionals, we also work hard to protect the privacy and cybersecurity of hundreds millions of individuals around the world. Some of those people are Palestinians. For example, I work at ESET, a company which protects the computers and smartphones of many millions of people in more than 180 different countries. I'm guessing some of them are Palestinian sympathizers.

Recently, some of you have been busy redirecting website traffic AWAY from sites that many people, including some Palestinian sympathizers, rely on for help in protecting their privacy and their data, and TO a page that calls for Palestinian rights. I have to say, I don't think this strategy is helping you, or the Palestinian cause; it hurts law-abiding human beings who use computers and smartphones to make an honest living, to connect with their families, and in some cases, to campaign for peace and justice.

[Note: When I say sympathy with the plight of the Palestinian people, or sympathy with the Palestinian cause, I mean that I think the people of Palestine have been, and are being, treated inhumanely, and that they deserve a secure homeland in which they are free to enjoy the rights and liberties that Americans take for granted. I do not mean that violence against civilians in pursuit of political aspirations is justified: it is not, ever, no matter what side you are on. Yet complacency and apathy in the face of inhumanity and injustice are equally objectionable.]

So, what is my professional advice? Use your computer skills to advance the cause in ways that don't impact innocent digital bystanders. Let me give you an example. This website you are reading right now is hosted on a web server that was hacked a few months ago in the name of freedom for Palestinians. The same web server hosts information about a potentially fatal genetic condition that doctors often fail to diagnose. That website helps a lot of people but it went down because someone thought hacking it would help the Palestinian cause. Did it help? I don't see any evidence that it did. Several kind and generous people had to give up their time to fix the website. Some innocent people in need of helpful information could not get to that information for days.

kdms-palestineDid the hack provide any benefit to anyone? Not really. Security experts already know that websites can be hacked, and it is well known that the DNS servers which direct traffic to websites can be messed with. But the more protection that is applied to protect sites and infrastructure, the more expensive and cumbersome the Internet becomes. And I'm guessing you use the Internet for more things than hacking. How about use of the Internet to organize humanitarian aid for Palestine? How about use of the Internet to raise awareness of, and sympathy for, the Palestinian cause? Why not apply your skills and energy to those efforts? Help the people who are trying, or may be persuaded to try, to help you.

No quest for peace and freedom can prosper without a critical mass of support that comes from many quarters. Annoying people who might otherwise be persuaded to support you just seems counter-productive.

Respectfully...Stephen Cobb, CISSP

Thank you Layla, for all that you gave to us, 2004-2013


A photo snapped in August: Layla Cobb, 2004-2013


This is just a short note to all who knew and loved our Layla.
Earlier this week she ended her journey here in San Diego,
peacefully and with loving hands upon her.


Layla was not only a joy to us and those who met her, she was an enormous comfort to us through some very tough times. She steadfastly refused to leave Chey's side whenever Chey was feeling ill, and faithfully presented me with a retrieved object whenever I came through the front door.

Only recently did we discover that Layla had stoically endured many years of arthritis so severe that the vets, when they got the X-rays, said they were amazed that she was able to walk at all. But Layla has always soldiered on stoically, despite everything, from Florida to New York, and then the long journey out to San Diego. Living out here, Dog Beach became her favorite place. When she stopped wanting to go onto the beach we both knew that we would not have her much longer.

So here's to you Princess Layla, Super Trooper, Snow Dog,
indefatigable source of comfort and joy.


Snow dog Layla

Layla's first snow, New York, 2007


Layla Cobb, 2004-2013

Do I really have to go back inside dad?


 

laylacc2

Hello world, my first portrait, 2004

Electric Car2Go is a Gas!

The all-electrtic Car2Go fleet in San Diego is not why we moved here, but we did sign up for the service as soon as we got here. Now, with nearly two years of experience, what do we think? It's a gas! Just take a look, and then read on...
Not all of these electric Smart Cars come with a highly-skilled driver like the one you see here, but they are all fun, whether you drive or are driven. Okay, we do have some quibbles that I will address in a moment, but basically this is a great service and the car is very impressive.

If I have to run errands involving more miles than I feel like walking then I often choose a Car2Go over our trusty old BMW 323. The iPhone app makes it very easy to locate nearby cars and reserve them.

At first, I tended to avoid Car2Go trips involving freeway miles, then my wife (the highly-skilled driver behind the wheel in the photo above) found the boost switch. You activate it with an extra push on the gas pedal when accelerating and it really helps with highway on-ramps and overtaking.

Of course, like all electric vehicles, the Car2Go can tap maximum torque at zero rpm, so it is always ready to leap off the line at the lights (great way to elicit gob-smacked looks from drivers of big sedans and hot hatches).

As for handling, the word is nimble. You can turn corners and cut U-turns where no other car would dare. I should point out that the ride is a little on the rough side over city streets, but most of the trips that I take in a Car2Go are too short for this to matter. The highway ride is acceptable. I did chat recently with someone who had ridden in her daughter's regular, bought-from-a-dealer, gasoline-powered Smart Car. She reported that it also had a somewhat rough ride on city streets (maybe someone should tell Mercedes Benz that America's city streets are not as well-paved as they used to be, and adjust suspension accordingly).

So far the electric-ness of the Car2Go has not been a problem. I have never run out of power. If the San Diego Car2Go fleet is short of anything it is cars-to-go. We can't always rely on there being one handy, and we live in the densely-populated Little Italy part of town. That would be one niggle. Another would be the length of time it takes to get the support folks on the line in the evenings.

Why would you need to call the support line? Well, it is possible to lock things inside these rentals. Yes, members have an RFID card that opens cars, but cars don't open to you if they are reserved by someone else or if they are out of service. So here's a scenario I encountered: Drove back from the supermarket in a Car2Go. Exited the vehicle with my groceries. Ended the rental. Then noticed that there was one more bag of groceries in the rear storage area. Tapped my card on the card reader but was told car out of service due to low battery. It took about 15 minutes to get through to an agent who could unlock the car.

Another problem I have encountered is missing cars. You see a car on the app, walk to its location, but it is not there. This may not be the fault of the system. Cars left in parking structures can give rise to this issue.

There are some restrictions on Car2Go, like not transporting our dog. I understand this policy: not all dog owners can be relied upon to keep the cars clean of dog hair, etc. And of course, only two people will fit in the car. However, they fit very well. I have a friend who is nearly seven feet tall and he owns a SmartCar. Not only that, his SmartCar was hit by another driver and protected him so well he got another.

So, bottom line: 9.5 times out of 10, my Car2Go experiences are 100% positive. So much so that they have allowed us to give our second vehicle to our daughter. So she likes Car2Go -- without ever driving one.

Sad Car2Go Postscript

At the end of 2016, Car2Go ceased operations in San Diego. Earlier that year it had converted the entire fleet from electric power to gasoline engines but it seems like Uber and Lyft killed it off. So, if you're visiting san Diego and wonder why you aren't see these cute little transport pods, that's why. Somehow this photo of our dog looking for something in the snow seems appropriate.