351 karma · joined October 21, 2010
There's winning and there's crushing the opponents. One shouldn't gloat in the latter case, but this case deserves an exception.
Congratulations Elon and the team on tremendously nice engineering!
* the procedure requires a module produced and sold by the manufacturer() to any garage that can verify its identity and satisfy manufacturer's specified security requirements (e.g. owning a safe and having no history with local police);
each such module is unique. It contains unique public/private keys and its public key is singed by the manufacturer;
* the procedure of adding the key to the list of Authorized Keys requires the car (actually, its ECU) to only accept incoming requests signed by such modules whose public keys are signed by the manufacturer. When the key is added, the ECU stores:
the key info;
the module's unique ID (IMPORTANT);
timestamp + lat/long;
* if there are no old authorized keys present (very rare scenario, since most of the time the owners want to replace just one lost/stolen key, but not both), the ECU requires 15 minute grace period with the module attached at all times, during which the car is flashing its hazard lights and honks. It makes a small nuisance in the garage once in a while, but attracts enough attention in the middle of the night if somebody is stealing it.
Now, if the car is stolen and then recovered, the police would dump the list of authorization requests and identify the module used. If this module was stolen or copied, the garage who owned the module becomes responsible for the damage to the car's owner. The ID of the module is placed on the revocation list. The revocation list is broadcasted via Sirius/XM/FM/BMW Assist/OnStar/Intelsat/etc.
This allows independent garages working on the cars, but places enough responsibility on them for keeping the system secure, with the override mechanism in form of revocation lists.
This method would NOT prevent all types of thefts (thugs can put the car on the flatbed and do the swap in the middle of the desert, or they can swap the ECU unit completely, or do some manipulations with the stolen "good" key), but it makes it significantly more difficult to authorize a new key and drive away.
(*) in case the manufacturer ceases to exist, some other company (another car manufacturer, perhaps) inherits the master key and will be responsible for authorizing garages to do key management.
My layman view is that the first step in principle "fly-navigate-communicate" could be accomplished by placing the aircraft into the "pitch an power" configuration: 5 degrees nose up + TOGA. This didn't happen. But this is my layman view: I'm down here in a comfy chair with a cup of tea, and they were up there, in a thunderstorm with flashing warning lights, frozen pitot tubes and 228 souls behind their back. We shouldn't judge them: we should only learn.
>If the pilots has switched a button to re-enable autopilot, everyone on board would have lived. But they didn’t. One co-pilot made a single, absurd mistake–for twenty full minutes–that brought the plane down.
First factual error: The button they should've switched is not the auto-pilot button (which they operate many times per flight), but the flight mode button (which most pilots never operate in their career). When the plane lost at least two of the three pitot tube readings, it went from the NORMAL "Law" to the ALT "Law", where the airplane doesn't guard itself against many pilot errors. When the pitots de-iced shortly thereafter, the plane did NOT go back to NORMAL "Law": it had to be switched there manually. The pilots did not do that and it seems to be the consensus so far (can't state that for certain before the official report is released) that they did not realize they were flying the plane in ALT and then DIRECT Law.
Second factual error: the "absurd mistake" lasted nowhere near 20 minutes. The first problem appeared at 2:10:03UTC and flying into the ocean occurred at 2:14:28UTC -- 4 minutes 23 seconds in all.
And here is the official (government-provided) results: http://www.izbirkom.ru/region/izbirkom, also in Russian, but Chrome does an OK job translating it.
I did NOT check if the table from the first link is consistent with the data in the official results. Somebody more determined than I should do that. This page: http://eugenyboger.livejournal.com/4514.html publishes the scripts used for composing the csv file from the official results.
an App on my phone which I can use to find the nearest ATM and make a withdrawal. It knows my account credentials. I tell it how much cash I need. The app generates the transaction, encodes it in the QR code. I show the phone screen to the ATM's camera. The ATM dispenses the cash, takes photo of the person receiving the money and attaches it to the transactions log/statement.
No germs exchanged, no risk of skimming, more security (password vs. 4-digit pin code), no need to carry the ATM card around.
Edit: it probably didn't come across like it, but I think that the show is hilarious and it is one of the very few reasons to own a TV. But a car review show (as in, the source of information on the automotive industry) it is not, and is not meant to be.
Also, highly-adapted droid != highly-adaptable droid. There is no need for an amphibious droid in Afghanistan, just like one doesn't use the same apparel in all climate zones. As long as interface/principles are the same (like a PC), various versions of it can be used in (almost) any environment without extensive re-training.
To put it in the familiar context: what you're describing (and what DoD is used to) is a mainfraime. These guys just made a PC.
Worth repeating: they can read ANY page in RAM. Including those which contain user key hashes, session hashes and any password which happens to be stored in clear in memory.
While OS can protect process' memory from all other processes, the DMA is one level closer to the metal. No matter what OS you're running, plugging random devices to your system means the game is over.
(1) HW virtualization mitigates some of these risks: I'm not familiar with the details of it. But since most of the machines are running without the HW virtualization still, they are still vulnerable.
edited for formatting
In space, today, we're in pre-aviation days: we're still using hot air balloons for transportation. We make them lighter than air (i.e. shoot them up in space) and let the wind (i.e gravity) to carry them places.
Imagine the most educated human 120 years ago is being told about planes heavier than air, air transportation over oceans, jet-powered planes, autopilots and fly-by-wire, not to mention people on the moon. He would say it's impossible, due to energy constraints. Today a daily JFK-NRT flight uses more energy than all the horses which lived two centuries ago would be able to produce in their lifetimes, combined (my math may be off by one order of magnitude: it's late here). Today we're this person. Educated enough to have valid arguments against it, but utterly incorrect.
Now, the differences. The idea of storing markup and data in separate containers, at least one of which is XML-based is not something anyone with knowledge of XML can not think of. Let me re-read the patent in question. Yep, I got it right. While I can't turn off my hindsight, I can't also think that CSS doesn't fit into this, as well as many other technologies. BTW, i4i, in case you're reading, I didn't give you this idea and you can't use it, at least because CSS is at least 2 years older than issuing date of patent 5787449. Which reminds me of the prior art arguments, but I digress.
All that is neither here-nor there. You say it's not obvious -- I say it is. What really matters is the goal of the exercise. Patents were created when inventions were _hard_. Coming up with the idea of pumping air out of the glass tube with wolfram wire in it required lots of costly tests, trials and errors. Do you know how many stores stocked wolfram back then? Patents were created to _encourage_ innovation on the assumption that not too many people can afford innovating in the same field at the same time. Fast forward to today. Coming up with software patents today requires a whiteboard, a Word document and a phone to call a lawyer. I know, I have a few of those (equally embarrassingly obvious, I must add). Does it protect me and my invention _today_? Nope, since I can't afford to sue somebody even if I can prove beyond a reasonable doubt that the patent has been infringed on. Big companies plow over individual investors with their army of lawyers. The opposite, however, is not true (the in-app purchasing patent story is the point in case).
Another aspect of patent situation today is the shier vastness of the field. Who can afford doing patent searches for literally every line of code before it is written? So we all are forced to live on the minefield. This serves as an argument against innovation by individuals. And that brings results which are directly opposite to the original goals of the patent system. Which is not a good thing.
Seems like our only hope is if somebody powerful and famous, with a big software patent portfolio, can sacrifice it for the good of the industry and advocate for banning software patents. Steve Jobs and his position against DRM in music comes to mind as a similar move. Wouldn't it be great if leaders of the industry get together and petition/lobby for this change? One can only dream...
* if people are added to the thread, the body of e-mail should start with [adding A and B so they can {do X}];
* if people are removed from the thread, they should be BCCed and the first line of the e-mail should read [BCCing C and D for now to minimize the noise].
Also, can't really agree with the breaking up e-mails point. It's usually costlier to follow extremely branchy thread than to filter the relevant points from a linear thread.
[edited for formatting]
From the user perspective, people need simple access to the following types of content: * real-time (think ESPN, Speed Channel and breaking news) * near real-time content (talk shows, nightly news, first-run TV shows) * archived content (moves on DVDs)
The archived content problem is solved by Netflix. The near-real-time problem is solved by Hulu (some networks, like HBO and Showtime are not there yet but will be once paid subscription becomes relevantly popular). The real-time problem is not solved -- flash-based players on news sites do not count. Apple might be able to to the third one, the way the newspapers are now published on the iPod.
In my view the opportunity is to bring all 3 types of content into one box, under one UI and wrap it into the nice user experience. Add IP-only delivery and a-la-carte subscription (e.g. I want monthly pass to 3 shows from Showtime and one show from HBO, but not the whole network), and users will ditch their $150/month settop boxes in droves.